Security/BlackHat 2012: Difference between revisions

From MozillaWiki
Jump to navigation Jump to search
 
(12 intermediate revisions by 3 users not shown)
Line 10: Line 10:
=== Black Hat sessions ===
=== Black Hat sessions ===


'''''[https://www.blackhat.com/html/bh-us-12/schedule/briefings-25.html July 25]'''''
'''''[https://www.blackhat.com/html/bh-us-12/schedule/briefings-25.html Wednesday, July 25]'''''


10:15  
10:15  
* [https://www.blackhat.com/html/bh-us-12/bh-us-12-briefings.html#Ridley Advanced ARM Exploitation] (Palace I) - ''kang''
* [https://www.blackhat.com/html/bh-us-12/bh-us-12-briefings.html#Ridley Advanced ARM Exploitation] (Palace I) - ''kang''
* [https://www.blackhat.com/html/bh-us-12/bh-us-12-briefings.html#Amit SexyDefense - Maximizing the home-field advantage] (Palace II) - ''joes''
* [https://www.blackhat.com/html/bh-us-12/bh-us-12-briefings.html#Amit SexyDefense - Maximizing the home-field advantage] (Palace II) - ''joes''
* WORKSHOP: Advanced Chrome Extension- Leveraging API Powers for The Better Evil ''Who is attending, if anyone? Name here'' For Gaia/WebAPI folks some attacks on Chrome extensions that may have relevance to types of attacks we face on apps.
* WORKSHOP: Advanced Chrome Extension- Leveraging API Powers for The Better Evil ''Who is attending, if anyone? Name here''  
 
For Gaia/WebAPI folks some attacks on Chrome extensions that may have relevance to types of attacks we face on apps.


11:45
11:45
* [https://www.blackhat.com/html/bh-us-12/bh-us-12-briefings.html#Rohlf Google Native Client - Analysis Of A Secure Browser Plugin Sandbox] -''Who is attending, if anyone? Name here'' For the B2G folks there are a couple that might help us with our phone designs. If nothing else they may inform our testing.
* [https://www.blackhat.com/html/bh-us-12/bh-us-12-briefings.html#Rohlf Google Native Client - Analysis Of A Secure Browser Plugin Sandbox] -''Al''  
* [https://www.blackhat.com/html/bh-us-12/bh-us-12-briefings.html#Argyroudis Exploiting the jemalloc Memory Allocator: Owning Firefox's Heap] -''Who is attending, if anyone? Name here''
 
For the B2G folks there are a couple that might help us with our phone designs. If nothing else they may inform our testing.
 
* [https://www.blackhat.com/html/bh-us-12/bh-us-12-briefings.html#Argyroudis Exploiting the jemalloc Memory Allocator: Owning Firefox's Heap] - ''gkw''
* [https://www.blackhat.com/html/bh-us-12/bh-us-12-briefings.html#Weinmann "Scaling Up Baseband Attacks: More (Unexpected) Attack Surface"] -''Who is attending, if anyone? Name here''
* [https://www.blackhat.com/html/bh-us-12/bh-us-12-briefings.html#Weinmann "Scaling Up Baseband Attacks: More (Unexpected) Attack Surface"] -''Who is attending, if anyone? Name here''
* [https://www.blackhat.com/html/bh-us-12/bh-us-12-briefings.html#Kaminsky BlackOps] - ''joes''
* [https://www.blackhat.com/html/bh-us-12/bh-us-12-briefings.html#Kaminsky BlackOps] - ''joes''
Line 29: Line 34:
* [https://www.blackhat.com/html/bh-us-12/bh-us-12-briefings.html#Serna "The Info Leak Era on Software Exploitation"] (an example of one he wrote up on Flash is http://seclists.org/bugtraq/2012/Apr/63 ) -''Who is attending, if anyone? Name here''
* [https://www.blackhat.com/html/bh-us-12/bh-us-12-briefings.html#Serna "The Info Leak Era on Software Exploitation"] (an example of one he wrote up on Flash is http://seclists.org/bugtraq/2012/Apr/63 ) -''Who is attending, if anyone? Name here''
* [https://www.blackhat.com/html/bh-us-12/bh-us-12-briefings.html#Wroblewski ModSecurity as Universal Cross-Platform Web Protection Tool] (Augustus I + II) - ''joes, kang''
* [https://www.blackhat.com/html/bh-us-12/bh-us-12-briefings.html#Wroblewski ModSecurity as Universal Cross-Platform Web Protection Tool] (Augustus I + II) - ''joes, kang''
** [https://www.blackhat.com/html/bh-us-12/bh-us-12-briefings.html#Soler HTExploit Bypassing Htaccess Restrictions ] (Augustus I + II) - ''joes, kang''
* [https://www.blackhat.com/html/bh-us-12/bh-us-12-briefings.html#Soler HTExploit Bypassing Htaccess Restrictions] (Augustus I + II) - ''joes, kang''
* [https://www.blackhat.com/html/bh-us-12/bh-us-12-briefings.html#Bertacco Torturing OpenSSL] - ''Al''


15:30
15:30
* For the privacy geeks -- decloaking "private browsing" among other ways to track people. [https://www.blackhat.com/html/bh-us-12/bh-us-12-briefings.html#Fleischer "Web Tracking for You"]
* [https://www.blackhat.com/html/bh-us-12/bh-us-12-briefings.html#Fleischer "Web Tracking for You"] - ''Al''
* A wildcard... Math.random() isn't crytographically secure, could we be vulnerable to anything like these PHP issues? If you go bring your open mind and wear your brainstorming hat. * [https://www.blackhat.com/html/bh-us-12/bh-us-12 briefings.html#Argyros "PRNG: Pwning Random Number Generators (in PHP applications)"]
 
For the privacy geeks -- decloaking "private browsing" among other ways to track people.
 
* A wildcard... Math.random() isn't crytographically secure, could we be vulnerable to anything like these PHP issues? If you go bring your open mind and wear your brainstorming hat.  
* [https://www.blackhat.com/html/bh-us-12/bh-us-12 briefings.html#Argyros "PRNG: Pwning Random Number Generators (in PHP applications)"]
* [https://www.blackhat.com/html/bh-us-12/bh-us-12-briefings.html#Flynn Intrusion Detection Along the Kill Chain: Why Your Detection System Sucks and What to do About It] (Palace II) - ''joes, kang''
* [https://www.blackhat.com/html/bh-us-12/bh-us-12-briefings.html#Flynn Intrusion Detection Along the Kill Chain: Why Your Detection System Sucks and What to do About It] (Palace II) - ''joes, kang''


17:00
17:00
* [https://www.blackhat.com/html/bh-us-12/bh-us-12-briefings.html#Alonso Owning bad guys and mafia with javascript botnets] - who doesn't love a botnet that uses javascript?
* [https://www.blackhat.com/html/bh-us-12/bh-us-12-briefings.html#Alonso Owning bad guys and mafia with javascript botnets] - who doesn't love a botnet that uses javascript?
* New defensive features of Win8 we should consider using. Some may be compiler/linker features that will help on other versions of windows, too. [https://www.blackhat.com/html/bh-us-12/bh-us-12-briefings.html#Miller2 "Exploit Mitigation Improvements in Win 8"]
* [https://www.blackhat.com/html/bh-us-12/bh-us-12-briefings.html#Miller2 "Exploit Mitigation Improvements in Win 8"]
* Backdoors in a B2G device?  Here Be Backdoors: A Journey Into the Secrets of Industrial Firmware https://www.blackhat.com/html/bh-us-12/bh-us-12-briefings.html#Santamarta
 
New defensive features of Win8 we should consider using. Some may be compiler/linker features that will help on other versions of windows, too.  
 
* [https://www.blackhat.com/html/bh-us-12/bh-us-12-briefings.html#Santamarta Backdoors in a B2G device?  Here Be Backdoors: A Journey Into the Secrets of Industrial Firmware]
* [https://www.blackhat.com/html/bh-us-12/bh-us-12-briefings.html#Stamos The Myth of Twelve More Bytes: Security on the Post-Scarcity Internet] (Augustus III + IV) - ''joes, kang''
* [https://www.blackhat.com/html/bh-us-12/bh-us-12-briefings.html#Stamos The Myth of Twelve More Bytes: Security on the Post-Scarcity Internet] (Augustus III + IV) - ''joes, kang''


'''''[https://www.blackhat.com/html/bh-us-12/schedule/briefings-26.html July 26]'''''
'''''[https://www.blackhat.com/html/bh-us-12/schedule/briefings-26.html Thursday, July 26]'''''
 
10:15
* [https://www.blackhat.com/html/bh-us-12/bh-us-12-briefings.html#Schneier Trust, Security, and Society] (Augustus III + IV) - ''joes''
 
11:45
 
14:15
* Turbotalks - Enterprise Intrigue (Palace I)
** [https://www.blackhat.com/html/bh-us-12/bh-us-12-briefings.html#Holeman Passive Bluetooth Monitoring in Scapy] - ''joes''
** [https://www.blackhat.com/html/bh-us-12/bh-us-12-briefings.html#Steele SYNful Deceit, Stateful Subterfuge] - ''joes''
** [https://www.blackhat.com/html/bh-us-12/bh-us-12-briefings.html#Reynolds Stamp Out Hash Corruption, Crack All The Things] - ''joes''
 
15:30
* [https://www.blackhat.com/html/bh-us-12/bh-us-12-briefings.html#Aldridge Targeted Intrusion Remediation: Lessons From The Front Lines] (Augustus III + IV) - ''joes''
 
17:00
*[https://www.blackhat.com/html/bh-us-12/bh-us-12-briefings.html#Philput Hacking the Corporate Mind: Using Social Engineering Tactics to Improve Organizational Security Acceptance] (Augustus III + IV) - ''joes''
 
* [https://www.blackhat.com/html/bh-us-12/bh-us-12-briefings.html#Shekyan Hacking with WebSockets] -''Who is attending, if anyone? Name here''
* [https://www.blackhat.com/html/bh-us-12/bh-us-12-briefings.html#Shekyan Hacking with WebSockets] -''Who is attending, if anyone? Name here''
* [https://www.blackhat.com/html/bh-us-12/bh-us-12-briefings.html#Shah HTML5 Top 10 Threats – Stealth Attacks and Silent Exploits] -''Who is attending, if anyone? Name here''
* [https://www.blackhat.com/html/bh-us-12/bh-us-12-briefings.html#Shah HTML5 Top 10 Threats – Stealth Attacks and Silent Exploits] -''Who is attending, if anyone? Name here''
Line 48: Line 79:
* [https://www.blackhat.com/html/bh-us-12/bh-us-12-briefings.html#Purviance "Blended Threats and JavaScript: A Plan for Permanent Network Compromise"] -''Who is attending, if anyone? Name here''
* [https://www.blackhat.com/html/bh-us-12/bh-us-12-briefings.html#Purviance "Blended Threats and JavaScript: A Plan for Permanent Network Compromise"] -''Who is attending, if anyone? Name here''
* [https://www.blackhat.com/html/bh-us-12/bh-us-12-briefings.html#Sabanal "Digging Deep Into The Flash Sandboxes"] -''Who is attending, if anyone? Name here''
* [https://www.blackhat.com/html/bh-us-12/bh-us-12-briefings.html#Sabanal "Digging Deep Into The Flash Sandboxes"] -''Who is attending, if anyone? Name here''
* [https://www.blackhat.com/html/bh-us-12/bh-us-12-briefings.html#Philput Hacking the Corporate Mind: Using Social Engineering Tactics to Improve Organizational Security Acceptance] - Makes sense for security folks


=== DEFCON Sessions ===
=== DEFCON Sessions ===
Line 114: Line 144:


  8:30 PM ??
  8:30 PM ??
* Joe Stevensen
* Gary Kwong
* Gary Kwong
* Ben Kero
* Ben Kero
Line 121: Line 150:
* Jorge Villalobos
* Jorge Villalobos
* Marshall Moutenot
* Marshall Moutenot
* Guillaume Destuynder


=== Friday Night Dinner Sign Up ===
=== Friday Night Dinner Sign Up ===


  8:30 PM ??
  8:30 PM ??
* Joe Stevensen
* Gary Kwong
* Gary Kwong
* Ben Kero
* Ben Kero
* Brian Hourigan
* Brian Hourigan
* Anthony Hughes
* Anthony Hughes
* Jorge Villalobos
* Marshall Moutenot
* Marshall Moutenot
* Raymond Forbes
* Raymond Forbes
* Guillaume Destuynder


=== Sat Night Dinner Sign Up ===
=== Sat Night Dinner Sign Up ===
Line 170: Line 195:
|2012-07-30
|2012-07-30
|-
|-
|Joe Stevensen
|Joe Stevensen :joes
|Yes
|Yes
|Yes
|Yes
Line 201: Line 226:
|-
|-
|Michael Henry :tinfoil
|Michael Henry :tinfoil
|No (going to BSidesLV)
|No
|Yes
|Yes
|2012-07-24
|2012-07-24

Latest revision as of 03:55, 27 July 2012

Black Hat & DEFCON 2012

This is to track organization and attendees for Black Hat and DEFCON 2012 security conferences this coming Summer. Black Hat is at Caesars Palace and DEFCON is at the Rio.

Dates

Black Hat is from July 21 through 26, 2012. DEFCON 20 is from July 26 through 29.

Sessions to be covered

Black Hat sessions

Wednesday, July 25

10:15

For Gaia/WebAPI folks some attacks on Chrome extensions that may have relevance to types of attacks we face on apps.

11:45

For the B2G folks there are a couple that might help us with our phone designs. If nothing else they may inform our testing.

14:15

15:30

For the privacy geeks -- decloaking "private browsing" among other ways to track people.

17:00

New defensive features of Win8 we should consider using. Some may be compiler/linker features that will help on other versions of windows, too.

Thursday, July 26

10:15

11:45

14:15

15:30

17:00

DEFCON Sessions

July 27

July 28

July 29

dinners/meetups

Tuesday Night Dinner Sign Up

Confirmed Rao's 8:30 PM 14 reservations - let me know if you want to be added and I'll try to fit you in -chofmann

1 Joe Stevensen
2 Eric Parker
3 Guillaume Destuynder
4 Gary Kwong
5 Adam Muntner
6 Ben Kero
7 Brian Hourigan
8 Anthony Hughes
9 Kevin Brosnan
10 John Morrison
11 Al Billings
12 Raymond Forbes
13 Chris Hofmann
14

Wed Night Dinner Sign Up

Confirmed Mesa Grill 8:30 PM - 15 reservations. - contact chofmann to be added beyond that.

1 Joe Stevensen (/me wonders if can we do dinner at 7:30 PM instead?)
2 Michael Herny :tinfoil
3 Gary Kwong
4 Ben Kero
5 Brian Hourigan
6 Anthony Hughes
7 Jorge Villalobos
8 Kevin Brosnan
9 Marshall Moutenot
10 John Morrison
11 Al Billings
12 Raymond Forbes
13 Chris Hofmann
14 Jesse Ruderman
15 Guillaume Destuynder

Thurs Night Dinner Sign Up

8:30 PM ??
  • Gary Kwong
  • Ben Kero
  • Brian Hourigan
  • Anthony Hughes
  • Jorge Villalobos
  • Marshall Moutenot

Friday Night Dinner Sign Up

8:30 PM ??
  • Gary Kwong
  • Ben Kero
  • Brian Hourigan
  • Anthony Hughes
  • Marshall Moutenot
  • Raymond Forbes

Sat Night Dinner Sign Up

8:30 PM ??
  • Joe Stevensen
  • Gary Kwong
  • Ben Kero
  • Brian Hourigan
  • Anthony Hughes
  • Jorge Villalobos
  • Raymond Forbes
  • Guillaume Destuynder

Attendees

Enter your name below if you plan on attending one or both conferences.

Name Black Hat? DEFCON? Arrival Date Departure Date
Al Billings Yes Yes ? ?
Raymond Forbes Yes Yes 2012-07-24 2012-07-30
Joe Stevensen :joes Yes Yes 2012-07-24 2012-07-29
Gary Kwong Yes Yes 2012-07-24 2012-07-29
Guillaume Destuynder Yes Yes 2012-07-24 2012-07-29
Jorge Villalobos Yes Yes 2012-07-24 2012-07-29
Adam Muntner Yes Yes 2012-07-24 2012-07-29
Michael Henry :tinfoil No Yes 2012-07-24 2012-07-30
Jesse Ruderman Yes Yes 2012-07-24 2012-07-30
Anthony Hughes Yes Yes 2012-07-24 2012-07-30
John Morrison :jrgm Yes No 2012-07-24 2012-07-27
Kevin Brosnan :kbrosnan Yes Yes 2012-07-24 2012-07-29
Ben Kero :bkero Yes Yes 2012-07-24 2012-07-29
Brian Hourigan :digi Yes Yes 2012-07-24 2012-07-29
Marshall Moutenot :mmoutenot Yes Yes 2012-07-24 2012-07-29

Conference registration numbers for attendees

hotel reservation confirmations

Flight planning

Name Outbound Flight Return Flight Notes
Joe Stevensen VX906 Arrives 7/24 14:55 VX905 Departs 7/29 11:00
Guillaume Destuynder VX906 Arrives 7/24 14:55 VX905 Departs 7/29 11:00
Kevin Brosnan VX906 Arrives 7/24 14:55 VX901 Departs 7/29 09:20
Al Billings VX260 Arrives 7/24 13:35 VX915 Departs 7/29 17:30
Jorge Villalobos UA1608 Arrives 7/24 22:01 UA1254 Departs 07/29 01:16
Ben Kero AS620 Arrives 7/24 20:06 AS621 Departs 7/29 20:50
Anthony Hughes WJ1788 Arrives 7/24 12:53 WJ1789 Departs 7/30 13:45
Marshall Moutenot SW1797 Arrives 7/24 21:25 SW2352 Departs 7/29 16:05