Showing posts with label DefCon17. Show all posts
Showing posts with label DefCon17. Show all posts

2009-08-06

DefCon 17 Video

I threw together this video of my Vegas trip. It's a bunch of photos (sorry for all the Ken Burns zooms) and some video clips from DefCon 17 in Las Vegas. I took almost all of these, but owe a tip of the hat to Dan Spisak as well as Axel Taferner & Amber Baldet for some of these, because they captured some things at DefCon I missed. Check out their photo streams as well.

This was my 6th time going to DefCon in the last 11 years. I tried to capture the spirit of DefCon with this. I feel this video represents the things you can expect to see there.

I hope to make it out there again next year, and hopefully I can bring my wife along!

DefCon 17 from Noah on Vimeo.

2009-08-03

Ax0n's DefCon 17 Wrap-Up

It's Monday, and I'm surprisingly spry considering the weekend I had. It might have something to do with the Infosec recharge I got. I'll let Asmodian X put together his own thoughts, as we rarely were at the same events and talks, for good reason. There were a lot of great talks overlapping one nother! I can't possibly upload every photo I took, so I'll just post a few here, and I'll make a slide show video later on when I have time.

Thursday

Due to family matters, I had to hit the airport a whopping FOUR hours before my 6:40AM flight to Las Vegas via Denver International. That meant leaving home around 2:00 AM Thursday. This would pretty much set the pace for the weekend.

Dawn takeoff from MCI


I arrived at McCarran International a little after 9:00 AM and waited for Tom and his wife to show up. We rented a limo to get to our respective hotels. Yeah, we could have caught a cab. We should've, actually. But hey, it's Vegas.

I found out my roommates at Circus Circus wouldn't be in town for quite a while, so I spent most of Thursday dragging everything around with me.

I dropped by a few of Thursday's talks, but didn't stay through any of them. Lee Kushner was giving a similar "Infosec career" talk to the one I heard last year, the Intro to lockpicking was just that: an intro, and the talk on FPGAs was half-way finished and over my head by the time I got to it. The Apple TV talk/demo seemed like it would be interesting... if you have an Apple TV. I don't have one, nor do I even intend to. DefCon 101 and Defense? After attending DefCon for 11 years off and on, I didn't feel compelled to check them out. Yes, I'm elitist like that.

Actually, I just wanted a place to set my bags down and veg and an excuse to do it without feeling like I'm wasting half a day worth of talks to check out. That meant that after I got the badges and swung through some of the talks, I spent most of my time in the Chillout room at the Riv, messing with people.

I had Evil Wifi up and running pretty much everywhere on Thursday and determined a few things:
1) 6x 1.2v/2650mAh NiMH batteries run the Fonera for well over 4 hours
2) La Fonera WILL overheat and lock up after an hour or so in a backpack
3) There are a lot of suckers at airports. Even at 5:00 AM at Kansas City International.
4) There are even more suckers at DefCon. I snarfed well over 1,000 Session IDs and cookies from more than 100 people at DefCon on Thursday alone. The wall of sheep has nothing on me.

Before: Jasager overheating in the backpack at McCarren International Airport.


After: Jasager lashed to the outside of the backpack so it can breathe.


I got accused of "DoSing the wireless" by a pair of perplexed kids who couldn't get onto their MySpace or something, but the fact was I had blacklisted the DefCon and DefConA network from Jasager, so they had tried joining something else. They were probably just angry at getting schooled. At no point did I re-use any of the session IDs, but it was fun to go back and look at the gigantic list of accounts I could've potentially laid to waste. This is DEFCON, folks. Wise up.


Thursday Night, several of us pooled our funds and rented a tandem-axle F650 Limo to get to Toxic BBQ. At the end of everything, the Limo worked out to $8 per person including the Chauffeur tip.




Just about the polar opposite from the stretch F650, I caught a ride back the Riv on the HackBus with a bunch of other people. This Relic was having a hard time getting moving with all of us on board, but it was a fun ride all the same, if a bit uncomfortable.


After Toxic BBQ, I hung out for a few hours talking to some folks. After Asmodian X landed, we geeked out with the badges for a bit, trying to figure out what all they were up to. I weeded through some of the source code to find some interesting tidbits, but they'd all been spoiled already, as I soon found out.

Friday
After a quick breakfast at Denny's (it was PACKED), Asmo and I split. I hit the Opening keynote with Joe Grand to learn a little bit more about the badges. Again, it was mostly a "this is why we had to issue paper badges to a bunch of you yesterday" apology session. He also disclosed that next year's badges will likely be using the same processor and development environment as he had to double-order parts this year. This year's badge featured an RGB LED and a microphone. It was cool sitting in the chillout room watching it pulsate to the music! Scroll down to the hardware hacking village section for information about inter-badge communication.
[Slides not online yet. Here's a link to Make:Online]

I stuck around for Schneier's Q&A session. Schneier can come off like a know-it-all a-hole sometimes, but he seemed to be quite personable at this session. When you're a polymath such as Schneier, I suppose you're allowed to hold court without too much social backlash, though. As I've been following Schneier's work for quite some time, I can say that the vast majority of the answers to his questions were basically torn from his prior writings. Funny, then, that so many people flooded the room to see his talk while being so clueless about where he stands on most of the issues.
[No slides presented. Go read Schneier On Security, as almost all his answers are there.]

The DefCon Security Jam panel was funny, mostly a Fail Rant by a few of the industry's more prominent characters. It was enjoyable for a few good laughs yet unremarkable. I don't have much more to say about it.
[No Slides Presented]

Jason Scott from textfiles.com (who STILL archives stuff HiR was writing 12 years ago!) talked about what it's like to be sued for more than two billion (with a B) dollars, and provided sound advice to those who find themselves on the business end of a real life lawsuit. He also differentiated between real lawsuits and silly settlement offers and mundane legal threats. His advice: Talk to your friends, don't be scared, get a lawyer (the EFF is your friend), and don't cave if you think the litigation is unfair.
[Slides Not Online Yet]

I tried to get into Johnny Long's talk, Three Point Oh. No slides were to be found, but judging from the Schedule, it was THE talk to see. Given Johnny's story, I'm really hoping the video for this one leaks out to the Internet somewhere. I caught part of "Stealing Profits From Stock Market Spammers" - I had the idea of trying to get the early jump on stock market pump-and-dumps, but since it's hard to tell when they started, it's even harder to tell when to dump them.
[Slides Not Online Yet]

On Friday, I noticed that the blue element in my RGB LED wasn't lighting up anymore. I decided to swing by the Hardware Hacking Village to see if anyone had an RGB LED for sale or some spare parts to hack the badge with. I'm glad I showed up when I did, because a crew of hardware hackers was there putting the finishing touches on the DefCon 17 Badge puzzle. In his badge presentation, Joe said that the different badge classes (Human, Speaker, Press, Vendor, Contest, Goon, and Uber) fit together to form a circular disc. From there, you can wire them up over I2C to network them together. With the default firmware, the LEDs will synchronize, which looks pretty cool.

This team gathered badges from volunteers (including a DefCon-supplied Uber for the center) and wired it up in front of a crowd of excited people, including Joe and DT. Talk about timing!


As far as the blue LED goes, Joe Grand told me my battery was dying and that Blue is always the first one to stop responding. I verified it by hooking up the badge to a CR123A I had in the hotel room. Blue came back. Battery life on the DC17 badge: totally lame. Maybe Parallel button cells next year?

Friday night, several of us took a trip across town to the iDefense event, 52 stories in the air offering a fantastic view of Las Vegas at dusk. By the time the open bar shut down, I'd had my fill of partying for the night. Asmo and I called it a night. Some kept partying until well into the morning. I didn't have it in me. I got some shots of Las Vegas from high up, though. I haven't had a view like this since DefCon 9 when we were staying at the Stratosphere. Wait. is that an In-and-Out down there?! NOM NOM NOM!





Saturday
I saw Joe Grand talk about electronic parking meters (just like everyone else). This was somewhat of a derivative of his talk given at InfoSec World 2008, but more focused on one type of device. Methodologies used in hardware hacking were covered in a case-study fashion with some very useful information presented in an entertaining fashion. Definitely check out the link below.
[slides and info]

Being a guy who is interested in emergency preparation, I headed over to see Renderman talk about Hackers and Disasters and Personal Survival Preparedness. Unfortunately, both of them were not what I was expecting. Renderman's a great guy, but the talk was too general and diluted. Personal survival preparedness felt like an intro crash-course to situational awareness, once the speaker's computer problems got sorted out. I left early to hit the skyboxes.
[You don't need to see the slides]

In skybox 207/208, video from Track 1 was being fed into the monitors. This let me catch the last part of the RFID Mythbusting track (wish I could have caught the whole thing!) and then I watched Adam Savage talk about how Failure affects all of us, how we can embrace failure, how to spot it coming and how to mitigate it before it ruins projects. Adam's a great speaker and seemed to be really enjoying the crowd's energy. It has me wondering if he wasn't disguised, lurking among us prior to his talk.
[Adam needs no slides. Adam needs to present at TED sometime.]

I snagged a not-so-quick Chipotle burrito with Chris from Securabit, then enjoyed watching Ricky Lawshae's talk on using TCP/IP sequence prediction to launch replay attacks against electronic prox-card door locks. You need to see the video for this one.
[Slides aren't online yet. Wired Article]

Easily the most entertaining presentation of the weekend for me was Sniffing Keystrokes with Voltmeters and Lasers. While voltmeters won't work (you really need a good O-scope), the attacks presented hold merit. One relies on data-to-ground leakage and unique clock frequencies in PS/2 Keyboards that allows you to compare electrical ground to true earth ground. This often discloses keyboard scancodes, but doesn't work on USB keyboards. The other method is a derivative of using lasers and photo-diodes for remote audio surveillance. This builds onto other work on statistical analysis of letter frequency, since each key will make a somewhat unique and repeatable sound when pressed (supposedly), they liken the analysis to a wheel of fortune puzzle.
[Slides from a similar presentation at a different convention] (pdf)

I helped set up for the podcaster's meetup after that, and then sat through the broadcast and Q&A Session. That was, as usual, a great time where I got to catch up with a few SecurityTwits.


Afrer that, the i-Hacked/PaulDotCom party took over and DOMINATED. i-Hacked set up a Liquid Sky display (oddly enough, an inch off the ground, give or take, not up in the air, which was a prismatic line-level green laser combined with a fog machine. The end result was a green, eerie swirling plane just off the floor.


Ulysses got a mohawk at the party next door.


I'm not sure how Mick Douglass ended up piloting the Hacker News Network news wagon.


I headed over to the Fireside lounge well after midnight to check out the event being put on by HiR's premiere sponsor, Edgeos. I finally caught up with Jay Jacobson (Founder/CEO) and enjoyed a few drinks on the house while chatting it up with a few of Edgeos' other employees. I've got a lot more information about Edgeos for you coming this month. Yes, it's powered by Nessus (and some other slick software) but they've done a great job with the UI, internal scanning engine and private label branding features. I'll stop there and show you some cool stuff in the coming weeks.

I didn't sleep Saturday night at all. A good chunk of my fellow Kansas City hackers were lounging at Kady's after throwing a successfully epic bash, so I kicked it with them and enjoyed a few cups of coffee. At about 4:30, I took off to the airport and made my way homeward.

Landing at DEN


I spotted a FED on my way home.

2009-07-29

Final preparations for DefCon

Asmodian X and I are finishing up the screenprinting for the HiR / CCCKC / DefCon 913/816 shirts we'll be wearing.



I'm also making sure things are patched and backed up, and packing my bags. I fly out tomorrow morning (Thursday) and land in Las Vegas a little after 9:00 AM.

Tom from Security Justice and I will be renting a limo from LAS to the Riv, Circus Circus, and Hilton area where many Defcon-goers have rooms reserved. If you get into town somewhere in the 9:00-10:30 range and you'd like to hitch a ride with us and split the fare, let me know. Same goes for if you just want to hang out.

Voice mail: +1-913-259-4HiR
Twitter: @ax0n
Email: ax0n [at] h-i-r [dot] net

2009-07-24

Social Stalking: Try Brightkite for DefCon



Brightkite is a service that focuses on short messages (much like Securitytwits' beloved Twitter) but it integrates photo hosting, threaded comments and location-awareness while allowing you to push updates, location check-ins and photos to Twitter, Facebook and Flickr (while automatically geo-tagging your photos).

The AJAX Web UI is clean and intuitive. The WAP and iPhone web interfaces are also easy to use and there are SMS/MMS and email interfaces that make it a snap to update from pretty much any device.

To top it off, several Brightkite applications are coming out for different smart-phone platforms. In fact, ReadWriteWeb gave a scathing review to Google's own location-aware Latitude, throwing in a bid for iPhone users to try Brightkite.

I personally use Brightkite to start my conversations since the threaded conversations there are intuitive AND my content can be sent to other popular platforms where my friends and family are. There are a lot more people on the other services (for now) but at the same time, I always have the brightkite feelers out for people who check in nearby.

For these reasons, I figure it's an easy and cool way to augment the social experience that goes with big conventions like Blackhat and Defcon. At the same time, you see photos from people and parties nearby and you get to keep tabs on where your brightkite friends are, assuming they want you to know.


Privacy is kind of a big deal -- especially among us paranoid security-types. Brightkite offers privacy controls for people you trust, people you befriend, and the public space. It also allows you to be as granular or as general as you wish with your location information. I could check in at "Kansas" or "Japan", or I could check in at "2901 Las Vegas Blvd, 89109" - I usually check in NEAR (but not specifically at) sensitive locations such as my home or office, then check in at a specific address if I'm somewhere that people might want to catch up with me (DefCon, for example). I even got them to set up a placemark specifically for DefCon (when you type "DefCon" in the place search, you see the Riviera)

If nothing else, keep an eye on the Brightkite Wall during DefCon. You don't even need to sign up to make that one work! I know a few other BrightKiters who will be there so the DefCon "wall" should be pretty interesting.

2009-07-20

Gentlemen, start your badge-hacking engines!

Last week, I asked Joe Grand if he'd be willing to give HiR Readers a sneak peek of the DefCon 17 Badges, kind of like Wired covered last year. Concerns of counterfeiting and unfair advantages for would-be badge hackers were cited as reasons why he couldn't disclose any info to me (orders actually coming from Dark Tangent himself).

He promised that as soon as he got clearance to do so, he'd be posting info to the DefCon forums. This way, badge hackers could at least get their IDEs installed and bring the supplies needed to interface with the microcontroller.

That day has come.

Attendees from both HiR and i-Hacked had a blast hacking the DefCon 16 badges together last year. Go read up and get prepared.

Abbreviated from Kingpin's post... highlights for the new badge:

  • The processor this year is a Freescale MC56F8006 Digital Signal Controller.
  • The development environment is Freescale CodeWarrior for DSCs. It's a similar IDE to previous badges (sorry, still Windows only AFAIK, but works fine in a VM) (Free Download)
  • There will a serial bootloader on-board to enable you to easily load your own firmware onto the badge (simply requiring a terminal program, like HyperTerminal, and the hex file). You need something like this to interface the board.
Still no photos yet. I'm looking forward to seeing what the new badge does and what it can be made to do!

2009-07-17

Friday Musings: Defcon

Just to keep my finger on the pulse of all things DefCon, I imported a Twitter Search feed for "defcon" into my Google Reader list. I figure it will be a good way to see who's planning on going, what talks are generating all the buzz, and maybe find out about some unofficial defcon events.


While that's been quite successful, I also encountered something unexpected: people who still use "defcon" as a tongue-in-cheek panic word. Side-note: many of them don't realize that the higher numbers mean LESS panic. But whatever. At least this guy almost got it right.

The truth is that DEFCON 1 has likely never been used. It doesn't specifically mean nuclear war, but any time that the US is on the defensive end of a serious and imminent attack by foreign military. The 9/11 incident took us to DEFCON 3. [Wikipedia]

At any rate, I've got almost everything ready for DefCon (the conference, not our Defense Condition). I don't quite have all my talks picked out, but I did find it odd that a speaker shares my last name -- which is an unusual last name to begin with. I may have to sit in on that talk.

2009-07-09

DefCon 17

Asmodian X and I will once again make our annual pilgrimage to Las Vegas over the last weekend of July-into-August.


I haven't picked the talks I'm attending yet, but you'll be able to find me at the Podcaster's Meetup and probably a SecurityTwits meetup, if there is one.  Otherwise email me (ax0n ! h-i-r , net) - I'll probably be checking my mail frequently.

Any readers attending?