Showing posts with label DefCon. Show all posts
Showing posts with label DefCon. Show all posts











 





 DEFCON 18 is a hacker conference 
 (from Defcon at 7-6-2010) 
 DEF CON at its core is a hacker conference sometimes though we forget the true meaning of that. Adam Laurie shared with me the DEF CON ethos. "If you know something, share it. If you learn something, learn more. When you really know your stuff, teach it." That is what a hacker conference should be all about. This also brings to mind another question we tend to ask ourselves in the INFOSEC/Hacking community.... read more» 
   
 





 DEF CON 18 Hacking Conference 
 (from Defcon at 7-6-2010) 
 Here's another great batch of talks for DEF CON 18! Stay tuned, we got tons of last minute submissions, so there's a bunch more more coming down the pipe in the next couple of weeks! Connection String Parameter Attacks This session is about Parameter Pollution in Connection Strings Attack. Today, a lot of tools and web applications allow users to configure dynamically a connection against a Database server. This session will demonstrate the high risk in doing this insecurely. This session ... read more» 
   
 





 Black Hat USA 2010 
 (from Blackhat at 7-6-2010) 
 Dynamic malware analysis is an important method to analyze malware. The most important tool for dynamic malware analysis is debugger. However, because debuggers are originally built by software developers to debug legitimate software, they have some significant flaws against malware. First of all, malware can easily detect the presence of debugger with various tricks. Another fundamental problem is that because malware run in the same security domain with debugger, they can potentially tamper wi... read more» 
   
 


Reblog this post [with Zemanta]

Posted by John B. Frank Monday, June 7, 2010 0 comments











 





 DEFCON 18 is a hacker conference 
 (from Defcon at 7-6-2010) 
 DEF CON at its core is a hacker conference sometimes though we forget the true meaning of that. Adam Laurie shared with me the DEF CON ethos. "If you know something, share it. If you learn something, learn more. When you really know your stuff, teach it." That is what a hacker conference should be all about. This also brings to mind another question we tend to ask ourselves in the INFOSEC/Hacking community.... read more» 
   
 





 DEF CON 18 Hacking Conference 
 (from Defcon at 7-6-2010) 
 Here's another great batch of talks for DEF CON 18! Stay tuned, we got tons of last minute submissions, so there's a bunch more more coming down the pipe in the next couple of weeks! Connection String Parameter Attacks This session is about Parameter Pollution in Connection Strings Attack. Today, a lot of tools and web applications allow users to configure dynamically a connection against a Database server. This session will demonstrate the high risk in doing this insecurely. This session ... read more» 
   
 





 Black Hat USA 2010 
 (from Blackhat at 7-6-2010) 
 Dynamic malware analysis is an important method to analyze malware. The most important tool for dynamic malware analysis is debugger. However, because debuggers are originally built by software developers to debug legitimate software, they have some significant flaws against malware. First of all, malware can easily detect the presence of debugger with various tricks. Another fundamental problem is that because malware run in the same security domain with debugger, they can potentially tamper wi... read more» 
   
 


Reblog this post [with Zemanta]

Posted by John B. Frank 0 comments

Last August I wrote a couple posts (Sorry Charlie...Youve Been Hacked and Sorry Charlie...The Cat's Outta the Bag) about the three MIT students that hacked into Boston's subway payment card system. (CharlieCard)

They had planned to present their findings at Defcom, but instead were sued by the Massachusetts Bay Transit Authority. The MBTA took legal action just before the students were scheduled to discuss: "generating fare cards","reverse-engineering magnetic stripes", and "hacking the RFID technology in the cards".

Instead, a judge issued an injunction ordering them to refrain from doing so. Now they've been "hired" by the MBTA. Ironically, yesterday I wrote a post entitled "Who Says Crime Doesn't Pay" and today, I saw this article that the MBTA had "hired" the three hackers who broke into their system.

So apparently it also pays to hack into a system and threaten to publicly share the results in a presentation at a hack convention.

It's a different world out there...the only "Hack" I ever heard of as a kid was "Hack Wilson" who set the record for most RBI's in a season (191) in 1930 for the Chicago Cubs.

Anyway, it's been an interesting turn of events so here's a follow up on the Sorry Charlie series from Yahoo news.

SAN FRANCISCO - A trio of Massachusetts Institute of Technology students who found a way to hack into the Boston subway system's payment cards have agreed to partner with transit officials there to make the system more secure.

The Electronic Frontier Foundation announced the agreement Monday, two months after the Massachusetts Bay Transportation Authority dropped a lawsuit against the students, who were represented for free by the EFF, a civil-liberties group that frequently takes up cases involving security researchers and computer hackers. The transit agency had sued to stop the students from presenting findings at a computer-security conference.

The students — Zack Anderson, R.J. Ryan and Alessandro Chiesa — have argued all along they were trying to help the MBTA by giving it advance notice of their planned talk last summer and keeping specific details of their hack secret. But the MBTA worried of widespread fare fraud if students discussed how they were able to add hundreds of dollars in value to MBTA's two primary payment cards — CharlieCard and CharlieTicket.

Before they could take the stage at the DefCon hacker conference in Las Vegas in August, the students were slapped with a lawsuit and a restraining order preventing them from giving the talk. Everyone found out what they were going to say anyway: All 87 slides of the students' presentation were already online, having been given out to conference attendees on CDs before the lawsuit was filed.

The MBTA argued it needed time to fix the problems, but the issue touched off a legal battle about whether the students' free-speech rights were violated and prompted the EFF to take up the students' case.

The judge eventually lifted the gag order and the transit agency dropped its lawsuit in October. The two sides have been working since then on how they would collaborate to make the fare system more secure and have the students' work taken seriously, said Jennifer Granick, the EFF's civil liberties director.

Reblog this post [with Zemanta]

Posted by John B. Frank Tuesday, December 23, 2008 0 comments

Payments Industry News Blog

Search the PIN Debit Blog by Subject

Kapersky Calls for Mass Adoption of Card Readers

Kapersky Calls for Mass Adoption of Card Readers