Archive

Archive for July, 2009

Talks I’m Trying to Make at Defcon 17

July 16th, 2009

Just a quick post of some of the talks I hope to make during Defcon 17.

Friday

  • if (alive @ 10:00) {Welcome to Defcon 17 with Dark Tangent and the Making of & Hacking the DC17 Badge with Joe “Kingpin” Grand, The Dark Tangent} elsif (alive sometime after Welcome to Defcon 17 && time < 11:00) {Binary Obfuscation from the Top-Down: Obfuscating Executables Without Writing Assembly Sean Taylor “Frank2″}
  • 13:00 // Maximum CTF: Getting the Most Out of Capture the Flag with Psifertex
  • 14:30 // Advanced MySQL Exploitation with Muhaimin Dzulfakar
  • 15:00 // Head over to catch the end of ‘Making Fun of Your Malware’ with Michael Ligh & Matthew Richard
  • if ((beer + food) < comedy){ 16:00 Three Point Oh. with Johnny Long }

Saturday

  • Metasploit Track All Day

Sunday

  • 10:00 // Maybe up?  // Managed Code Rootkits – Hooking into Runtime Environments with Erez Metula
  • 11:00 // Win at Reversing: Tracing and Sandboxing through Inline Hooking with Nick Harbour
  • 14:00 // Slight of Mind: Magic and Social Engineering with Mike Murray and Tyler Reguly
  • 15:00 // Confidence Game Theater with cough

community ,

Defcon 17 Prep

July 9th, 2009

It looks like I’ll be out at Defcon 17 coming up, so if you’re down for a beer or whatever let me know.  We don’t have to make out or anything.  I should be getting into town on Thursday night. Several other DC405 members will be out there as well.

Defcon is always a good time, particularly when your boys have mad hookups with the party scene ;)

If you don’t have the hookup, some interesting items related to Defcon XVII that I’ve seen lately:

community ,

Meterpreter Script Rehack – search_dwld.rb

July 4th, 2009

The search_dwld.rb Meterpreter script is fairly cool.  Noisy (noted in script heading), but cool.  It basically recursively works the directory structure looking for filenames that match a given filter pattern.  When it finds one, it downloads it.

Recently I had the need to incorporate some search and download functions of my own.  The only difference being that I wanted to download files based on content and not on filename.  I also wanted to pull this off without having to upload anything, grep/etc.,  to the exploited machine.  I started looking at the ‘findstr’ command for Windows. Read more…

Code , ,