Posts tonen met het label blackhat. Alle posts tonen
Posts tonen met het label blackhat. Alle posts tonen

woensdag 15 april 2009

BlackHat Europe drinks anyone?

Who's there? I know I am, I know Craig Balding is and Roelof Temmingh & Chris Bohme are, but will you?

This action packed and kick ass conference will show you where the community is at and what to expect in the [not so] near future. A -must- for IT [security] people who take their jobs serious.

Not just the presentations but the informal meeting opportunities in & out side bars and rooms make BlackHat Europe so special. It's much smaller and more intimate then Los Vegas etc. This is one important reason speakers like it here so much. Not to mention the opportunity to explore this magical city with is struck by a wave of the best weather in a loooong time.

vrijdag 28 maart 2008

In the end, Joe 6-pack decides...

More later.

"It's better to ask for forgivenes then to ask for permission" anon

"We do not want our _users_ to break the EULA" Roelof Temmingh

"We rely on the inteligence of our router to play nice. Even if we know hop 5 is not playing "nice" with our packets, there is nothing we can do but stop... that sounds like DoS to me" FX

"Nobody uses the latest version of IOS. It is "banana" software: it ships green, and after it lays a long time at the customer, it gets yellow and eatable :P"

"In 12.4 they create heap logs in the data section, since it has space after loading"

"Uncompressing data in READ ONLY memory & writing it back.. because we can!"

"A problem with IOS is that you can not find what was wrong 5 minutes ago, if the processes start behaving good again"

CIR is a cool tool under development.

"Law-full interception: the government snooping IOS, what do you know about it?"

"It enabled us to see if & what is wrong, or that we have plenty time to replace everything with Juniper boxes :D"

"Software that needs to parse large numbers of formats are potentialy dangerous [think AV, Indexing software, media players]"

"Media parsing should be done sandboxed"

"Media files|streams are as dangerous as any other zip file"

dinsdag 25 maart 2008

BlackHat: hacking by numbers

So, two guys from sensepost are doing this training on hacking by numbers.

Interesting stuff, it basically boils down to: get as much as possible information on your target. Do this by utilizing public sources [think google [link:], netcraft, ARIN, msn.livesearch.com [ip:], kartoo.com and the likes] and reverse the pointers you find there. See what else is hosted on these IP addresses, see what other domains are registered and|or linked. Check for 'backlinks' that might indicate strong ties between companies.

And keep doing the:
:start
Single domain
Expand
Lots of domains
Reduce
Find what we really need
goto start

Both Nick & Jeremy keep saying: "Remember, domain names are IP addresses and IP addresses are points of attack"

Last but not least:
Find out private information of key individuals for social engineering.

Oh and for our hosts, this is for you :D


Peeps & posts [from] here:
Nathan McFeters
Petko D. Petkov
PortSwigger & Marcus
Mikko Hyykoski
Sandro

And some who are not:
Dimitri Sklyarov

woensdag 19 maart 2008