Hands down my favorite musical talent of the weekend was DJ Great Scott. I didn't get to hear his set at the White Ball but the set he laid down at the i-Hacked Skybox Party was absolutely insane. Both mixes are available online at the links above. Feel free to share, mirror, torrent and otherwise disseminate them.
2008-08-17
Some of the best music from DefCon 16 now online
2008-08-13
Finally got the Badge working...
I know, you're sick of hearing about the DefCon Badge, most likely. I couldn't get it working on my Parallels Win2K Virtual Machine. I decided to clean up the solder joints a bit to see if that helped. Yes, I usually prefer my butane soldering iron when working on electronics.
That didn't help, unfortunately. I decided to take over my wife's older workstation still running Win2K. Driver detected off the CD (just like it did under Parallels) and so I fired up Hyper Terminal... Success!
Here's what it dumped out:
DEFCON 16 Badge by Joe Grand (Kingpin)
I might be growing up, but I'm never backing down
From corporate greed
And authority
From fighting for what I believe
From my enemies
And my family
From society's pressure of responsibility
From church and state
And blind belief
From those trying to rewrite history
From backstabbing friends
And snake oil fiends
From those in my past with no integrity
You
can't
silence
me.
Goto www.kingpinempire.com
Welcome to the debug terminal...
Entering TRANSMIT mode.
File name: AX0N-NFO.HTM
File size: 0000002239 ytes
Starting IR file transmit.
CRC16 = 0xBB4E
CRC16 = 0xC6C1
CRC16 = 0x598F
CRC16 = 0x14FD
CRC16 = 0xCCE6
CRC16 = 0x0000
IR file transmit successful!
Entering RECEIVE mode.
* Press Mode Button *
Entering TRANSMIT mode.
File name: AX0N-NFO.HTM
File size: 0000002239 bytes
Starting IR file transmit.
* Press Mode Button *
Going to SLEEP.
* Remove SD Card *
* Press Mode Button *
Entering RECEIVE mode.
* Press Mode Button *
Entering TRANSMIT mode.
Seending TV-B-Gone power off codes.
Power off code list complete. Repeating!
* Press Mode Button *
Going to SLEEP.
So you can see it transmitting the file and working as a TV-B-Gone from the serial console, all from the USB connection. Nice!

For anyone who's interested, this is the file my badge transmits.
I'll bring it along to CCCKC tomorrow so we can all play with them, if anyone else brings theirs along.
I am having trouble downloading the freescale software, but I do intend on tinkering with the firmware on the badge as soon as I figure out what I'm doing.
Labels: dc16badge, DefCon16, Electronics
2008-08-12
Post-DefCon
Wow. I'm still on the mend from the crazy weekend. Even though it's already Tuesday, I lived through today with a serious case of the Mondays. The arid environment in Las Vegas combined with lack of proper water intake, lack of sleep, lack of food, excess of alcohol consumption and some travel woes really put a damper on my week so far.All that said, I come home from DefCon with a renewed passion for security, a huge list of new contacts that I hope to keep in touch with, and a pile of notes, schwag, books, CDs and DVDs I have to wade through eventually.
At the end of my airport post last Thursday, I made a reference to an article I was writing in regards to smuggling lockpicks in my carry-on luggage. Also, I've been promising the guys at i-Hacked that I'd be willing to write some stuff for their site on occasion.
I delivered on both promises yesterday with my first i-Hacked guest post: Sneaking Lockpicks past the TSA in carry-on luggage. Within half a day, it already got the attention of Security Monkey and was posted on IT Toolbox. Then, it got submitted to Digg, although it's still a far cry away from hitting the front page. Feel free to Digg it up. Today, Network Security Podcaster/Blogger Martin McKeay posted his own take on getting lockpicks back home safely and his technique (used last year coming home from ShmooCon) is pretty similar to the one I came up with. I guess I wasn't expecting this much buzz about it.
In other news: while at DefCon, I was talking to Jur1st. He's the founder of Cowtown Computer Congress, a group that is striving to unite all the small yet talented cliques of hackers, geeks, and user-group-goers in Kansas City. Meetings are held every Thursday. More info can be found on their site. The current big project is establishing a hackerspace in Kansas City. Hackerspaces are buildings that members can use for user group meetings, collaborative projects, lab testing and social events. Every hackerspace is unique to suit the needs of its patrons, so it should be interesting to see how this one plays out.
I find it fascinating that the 2600 meeting that most of the HiR guys have attended since the mid-90s (I've attended regularly since '93) actually has a little bit of stigma attached to it. Our little "splinter cell" (as other Kansas Citians are calling us) has remained consistently small for the last 5 or 6 years, with 5 religiously regular Attendees (Frogman, Asmodian X, c0g, Dan and myself) and as many as 5 visitors per meeting who we see infrequently. Average age is mid-30s but only because c0g is fucking up our average. :P
I'm pretty stoked to start taking part in the Congress. There's actually a lot of talent in KC. We're just too jaded and cliquey to see the others. I really hope CCCKC fixes that.
I promise to start posting some details on the talks I went to as soon as I start feeling more like a human.
Labels: DefCon16, lockpicking, meetings, news, physicalsecurity
2008-08-10
Ax0n's DefCon Day 2 Recap
Talks:
Labels: computer hacker, DefCon16, hack, photography
2008-08-09
Ax0n's DefCon Day 1 Recap
This is what I did yesterday:
Saw Asmo get stomped on by a giant circus circus clown. Notice the Circus Circus billboard in the background is seriously on the fritz.
At McDonalds for breakfast, we saw this guy.
Close-up of amusing Solaris code (kernel driver for the hme* ethernet interface) -- Apropriate.
Saw some talks:
Jeff Moss's Introduction
Kingpin's discussion on the badge
Shawn Moyer' and Nathan Hamiel's talk on pwning social networks
Marc Weber Tobias's "Open in 30 Seconds" Medeco talk
Eric Schmiedl's "Advanced Physical Attacks"
After that, Asmodian X and I went to eat sushi with some of the Security Twits.
ggee - Taking pictures of people taking pictures of people taking pictures. His photos of the SecTwit's Dinner are here.
Photo I took walking to the bus stop
When we got back to the convention, we had a nice talk with Shawn Moyer and got some more in-depth on the SocNet problem.
I wound down the night at the Black Ball and a few other parties put on by other groups here at the Riviera.
I'm currently in Kingpin's talk about the BSODomizer, an in-line VGA Dongle that fakes a windows (or MAC) crash with a BSOD... and a little surprise... (ASCII Art Goatse anyone?) I'm not sure what's up next for me, there are some really interesting tracks today!
Labels: computer hacker, dc16badge, DefCon16, hack, photography
2008-08-08
One more badge post for the night
Sorry, guys. I've been obsessed with this thing all day, and while I don't plan on entering the badge hacking contest (I have NO developer skills at all), I would like to get as much info out there as possible. I hope that when the next wave of badges gets released, this helps some people get up and running ASAP. In theory, you should be able to read this and get your SD card ready ahead of time.
My last post had a bit of speculation to it when it came to the file transfer part. With some black-box testing between Shawn Moyer's badge and my own, and some help from Ryan Russell looking at the source code that Joe Grand put on the DefCon CD, I finally have some more solid information on how the file transfer feature works with the SD card inserted.
- When you push the button on the back, it will power the badge on. The LEDs will scan (and remain in "look at me, for I am glitzy" mode)
- When you push the button again, the LEDs will sweep from the center out, then the IR will try to handshake while a progress meter sweeps.
- If a handshake is initiated, the LED bar will briefly alternate one LED on, one LED off, then as the transfer happens, the progress bar appears.
- The SD Card has to be formatted FAT16
- The file you wish to transfer must be named in 8.3 (README.DOC, 12345678.TXT, AUTOEXEC.BAT, etc)
- The file you wish to transfer must be read-only
- The file you wish to transfer must be smaller than 128k. There's a limit in the code for this (likely easy to remove) which supposedly minimizes the possibility of a transfer error. Ryan seems to think that's also a way to protect badge-to-badge exploits.
- The files are transferred at speeds not unlike those used by a TV Remote. In other words: It's very slow. The files are read, written, and transmitted byte-by-byte in a loop. Simple but effective.
- There's a hand-written FAT16 driver in the default code, and it will walk through the FAT and transmit only the first file (per the allocation table) which meets the criteria.
- If the filename exists on the target SD card, it will replace the last character with a number (0-9)
- The file that's created on the recieving end will NOT be marked read-only and this will never be re-transmitted without manipulation.
I must really give it up to KingPin this year. Just tinkering with this badge has made today a really social day for me and I've hung out with some people who I was really hoping to get to meet. It's been an ice-breaker of a project already. If you see me, I'll send you my goodies. :)
Keep an eye on the HiR Twitter page if you aren't following it already. I'll be live-blogging more Badge stuff in the morning from the keynote, and probably from other events as well. I'll attempt to stitch the mess of tweets together into coherent full HiR posts for some of the talks if time (or content) allows.
2008-08-07
More DefCon 16 Badge infoz
In the factory state, the DefCon badge works as follows.
When you attach the battery, there are three modes selectable from the pushbutton switch on the back:
Sleep (no scanning LEDs)
On (LEDs scan side to side)
TV-B-Gone - Turns almost any TV on or off (LEDs scan from center outward for a while, then ALL illuminate at the end of the cycle. Cycle re-starts)
You can verify that the IR Transmitter is actively sending data by looking at the Ninja's eye through a CCD element - Camcorder, camera phone, most digicams.
When you put an SD card in, there are three modes:
Sleep (no scanning LEDS)
Recieve (scanning side to side)
Transmitting (Scanning outward)
The SD Card needs to be formatted as FAT. The files you wish to share must be in the root directory of the SD Card, must be less than 128kb and the read-only attribute MUST be set. Then, you can share files! Hint: Give your files a fairly unique name because it won't likely overwrite files of the same name with the read-only bit set. According to the flyer, the LEDs will form a transfer status bar when a transfer is initiated. High-res shot of the (hard to read) badge documentation linked below:
If you solder the miniUSB jack onto the badge and hook it up to a Windows computer, the DefCon16 CD will have a valid driver for the badge. I don't know where to go from there yet, I'm just divulging this as I find out what's going on. Obviously, removing the 128kb limit would be a start. Perhaps more POV fun with the status LEDs and who knows what else is possible once you can upload custom firmware to the thing.
So, out of the box, I'm thinking of sharing GPG public keys and maybe some bookmarks. That's what mine will be transmitting!
DefCon16 Badge Hacking
We got our DC16 badges pretty early in the game. Hevnsnt brought along some mini-USB headers and soldering supplies, we got started hacking early on
Lots of fun stuff
The badge has a TV-B-Gone built-in. You can see the dim IR transmitter on the right side.
Hacking Phoenix Sky Harbor Int'l Airport
My flight out of Kansas City got delayed. I arrived at PHX at around 10:00 PM -- about an hour after my flight to Vegas was supposed to leave. Next flight out of here? 7:30 AM or so.
Decisions, Decisions... Do I take US Failways up on their offer of a hotel room? It's only a 9 hour wait. No. I set up camp.
First, there's a seriously annoying problem with my MacBook. For some reason, it refuses to connect properly to Cisco captive-portal access points. It'll get a DHCP address and route, but when it goes to load the "I accept" page, it can't get to it. This happens EVERYWHERE I run into "Cisco Web Authentication". That happens to include the free WiFi at PHX airport.
But... we have another wonderful captive portal as well, the private one for US Failways and America West (now merged).
How lame is this login screen? Would you pay $120 for 90 days or $315 per year to get access to this super-elite traveler's club? I would kick someone in the nuts if I paid that kind of cash and got this as the login screen.
Every page you try to load, even via https, brings this page up.
Oddly, I fired up my proxy script that simply launches an SSH session to my house (with a few ports forwarded to tunnel web proxy, instant message and IRC traffic) and told it to connect to port 443 (https) of my home firewall. I have an SSH listener on port 443 since I have no use for SSL at home.
It worked like a charm.
So, here I sit, abusing US Airways Club's wifi. Stranded in Phoenix for a few more hours, and I think I've successfully skirted boredom... for now...
Next: How to smuggle sharpened metal (lock picks) through airport security in your carry-on luggage. I think I'm going to wait until I get back into Kansas City before I expose that one, though. ;)
DefCon is less than a day away. Hope I run into some of you.
2008-08-06
Ax0n's DefCon Agenda so far...
I'll be updating my Google Calendar as I figure out what all is happening. This is subject to change, so I figure I'll just embed an iFrame. You'll have to view this post on HiR Information Report because I'm pretty sure most RSS readers don't like iframes. If you're trying to catch up with me at DefCon, just tag me via Twitter - Preferably via dm, but I'll check my @ replies too, if I'm not following you for some reason. I'll be around all day Thursday without a whole lot to do. If you're in town, find me and we'll talk shop or geek out.
2008-08-05
DefCon Paranoia?
I've heard rumblings and full-on details of the lengths people are going to secure their data and laptops whilst at DefCon.
- Back. Up. Your. Data. You never know when your laptop will get lost, stolen, infected, or permanently damaged. Your best bet is to make sure you have current backups and that those backups are usable.
- Don't store private data in the clear. Encrypt proprietary business information, your personal identification information, bank records, and other private data that you'd rather not make its way into the hands of everyone in the world. I recommend TrueCrypt for Mac, Linux and Windows. Part of what makes encryption work is PROTOCOL. Just using the software isn't good enough. Guard your data and use encryption sensibly.
- Use Strong Passwords. And use them properly. Make sure your screen saver makes you authenticate, make sure the system isn't set to log on automatically, and choose a password that's hard to guess and resistant to dictionary attacks.
- Keep your software and anti-virus up-to-date, and beware of Evilgrade.
- Shut down services and features you don't need. This includes bluetooth, etc.
- Use out-of-band communication. Find another hotel or use a CDMA wireless card (wireless EDGE/EV-DO broadband). While this is no guarantee of security, it does pull you off of the hacker-trodden DefCon network.
- Tunnel everything. Set your system-wide proxy to a localhost port (for your IM and other services as well) and then tunnel port 3128 to a remote squid server on another network (such as at your home). This will likely slow stuff down a bit, but it'll all go over SSH.
- Set up firewall rules to block anything that won't go through the proxy. On Mac OS X, I installed the following rules. I love BSD's IPFW:
Chimera:~ axon$ sudo ipfw list01000 allow tcp from any to any established
02000 allow ip from any to any via lo*
03000 allow icmp from any to any icmptypes 8
04000 allow icmp from any to any icmptypes 0
05000 allow log tcp from any to any dst-port 22 out06000 reject log ip from any to any
2008-08-01
BlackHat / DefCon Meetup Thursday Aug 7

A bunch of BH/DC-attending SecurityTwits (and some other DefCon attendees, likely) are wondering if there'll be anything going on for those who arrive Thursday. I'll actually get into Vegas late Wednesday night, and I will be checking my Twitter (twitter.com/ax0n) frequently. You can tag me there pretty much any time on Thursday. While you're scoping out Twitter, be sure to add the official HiR Information Report Twitter Feed. I'll be live-tweeting from DefCon.
I'm proposing meeting at Kady's Coffee Shop between 7pm and 9pm Thursday evening. Kady's is inside The Riviera (where DefCon is being held this year). This should be an all-ages venue, because I know there are plenty of under-21 folks that plan on attending. After 9:00PM, those of us who wish to partake in alcohol or gambling can make plans to do so. Kady's is 24/7 so the meetup there might go later than 9pm. It may also scatter (or get kicked out?!) before that. All I can say is watch Twitter - I'll post any updates to the meetup to both feeds.
Hope to see you there!
Labels: BlackHat2008, DefCon16, meetings, twitter
2008-07-24
Black Hat USA 2008 Briefings and Training
Looks like HiR will be present at Black Hat USA 2008 Briefings and Training. Asmodian X will be there getting a brain full of knowledge. I, on the other hand, will be crack-a-lacking in my cubicle then packing my bags for Vegas.
Looks like August will be a great month. Hopefully we come away with lots of fun stuff to share!
Held at Caesar's Palace in Las Vegas, NV.
Training: August 2-3 (Weekend) & August 4-5 (Weekday)
Briefings: August 6-7
Labels: BlackHat2008, DefCon16, meetings