Saturday, October 01, 2016
Thank you from semprix
This years conference was an epic one.
The topics delivered were highly technical and we thank our speakers for that! The trainings were jam-packed, we are looking into expanding our trainings with different cutting-edge topics by next year. The games were well participated, receiving feedbacks that they enjoyed our Capture The Flag this year makes us to do more of it. The newly introduced Semprix’ Mysterybox didn’t gain much players, maybe it was too difficult I will try to adjust the difficulty next year.With the newly introduced multiple tracks, the Capture The Flag had it’s dedicated area so players can focus more on the game with comfortable table and seats. The chill-out area was another best decision we had, through out the two day conference we consumed 70 liters of beer, awesome right?
The post-con party was pretty epic as well! We consumed 20 bottles of hard-drinks from Jack Daniels, Bacardi, to Mojito, 120 bottles of beer were served not to mention Smirnoff Mule sponsored us 400 bottles!
Right after the conference the goons were already brain-storming what more cool stuffs we can add to next year. Here are some stuffs to watch-out for next year.
1. We will introduce Fort ROOTCON, an area around the conference were tools and exploits have demos.
2. Hacker Jeopardy will be rescheduled for everyone to be able to attend.
3. Day 1 party and movie night will be held at the conference hall.
4. Capture the Flag will be extended from 10:00am to 11:00pm in-conjunction with the day 1 party and movie night.
Some pre-con activities we are brewing up.
1. Campus tour with student Capture The Flag.
2. Hackerspace in January
3. ROOTCON Kids will be introduced as mini-event around the month of May.
ROOTCON will continue to serve the hacking community specially in the Philippines, where hackers, geeks, pros will meet old and new friends, enjoy and of course learn from each other. With that said it wouldn't be possible without our awesome attendees, you rock!
Again I would like to say THANK YOU SO MUCH!
All the best,
semprix
Wednesday, February 06, 2013
ROOTCON 7 Details
Activities and Workshops
This year our very own NexSquare Inc. are kind enough to organize workshop on the first day of the conference. Some of the pre-final workshops are as follows:
WiFu - Introduction to Wireless Security
Hacking 101 - Introduction to Hackery
Lockpick 101 - Introduction to LockPicking
Metasploit-Fu - Ninja training on Metasploit
Web App Security - Introduction to Web Application Penetration Testing
These workshops are introductory to trainings offered by NexSquare Inc. with a very reasonable price to CON-Goers.
We also have our pre-con activities; activities like:
WiFi Shootout
Pre-con gathering (H4xor BBQ)
Pricing
We wanted ROOTCON to stay the cheapest and yet the best hacker conference in town; we were able to maintain the price of Php2800.00 for two consecutive years; however economically our materials and logistics costs increased so in order to cover all of our expenses such us speakers airfare and accommodation, badges, swags, meals and venue we came up with a slight price increase, this is also in parallel to the price our venue is giving us. The price for this year's conference are as follows:
Early Pro Registration: Php3300.00
Early Student Registration: Php2800.00
Group of 5 Registration: Php14025 (less 15%)
Late Pro Registration: Php4300.00
Late Student Registration: Php3800.00
Stay tuned for regular updates on the following
Facebook: https://www.facebook.com/rootcon
Twitter: https://www.twitter.com/_rootcon_
Forum: http://forum.rootcon.org
Main Site: https://www.rootcon.org
We hope to see everyone at ROOTCON this year!!!!
Hackers Unite
All the best,
-semprix
Tuesday, July 17, 2012
RC6 Ticket Sale
Regular rate registration is now open until August 17, 2012, since we want you to come!!! we are still giving away discounts get our group of 5 package and get 10% off.
What are you waiting for REGISTER NOW!!!!
http://rootcon6.eventbrite.com/
https://www.rootcon.org/xml/rootcon6/register
Saturday, July 14, 2012
The Secrecy (New Game)
Let the cracking begin!!!
Game Mechanics
The objective of this game is to reach the top-most level which is level 10. In order to achieve that you need to pass each level and get the secret / hidden phrase or word.
The Rules
1. NO DIRECT DDoS on the game servers.
2. NO Physical Coercion on players and crew.
3. Spies works on their own, this is a single player game. You can however have a handler to coach you throughout the game.
4. Spies are resourceful breaking codes, so be like one ;-)
5. Bring your own spy gears, laptop, AP, GPS tracking, whatever you think you will need.
Who Can Play
Any ROOTCON attendee (except for the ROOTCON Goons).
When
Start of the conference
Prizes Shining UberH4x0r Badge, which entitles you to be put up on the ROOTCON Hall of Fame, free entrance on the next ROOTCON Conference.
Crew / Agents / Handlers
Encrypted84 Semprix (The Fork Meister)
More details at https://www.rootcon.org/xml/rootcon6/activities#secrecy
Monday, June 11, 2012
ROOTCON 6 SpeedTalks
The mechanics is pretty straight forward.
1. Avail one of the Major Sponsors of ROOTCON 6
- Platinum
- Gold
- Silver
3. Sponsoring companies are given a blazing 10 minutes for their product demo / presentation and product updates.
4. SpeedTalks will be given on Day 1 and Day 2.
5. ROOTCON will align all schedules to the sponsoring company representatives.
6. NO QUESTIONS should be entertained during the SpeedTalk, the allotted 10 minutes is purely presentation / demo / talk. All questions should be addressed on the sponsors booth.
What are you waiting for? Contact our sponsorship liaison.
-Semprix
Thursday, May 31, 2012
ROOTCON 6 Call For Papers Now Close
Tuesday, April 03, 2012
We want you to come!!!
Download the Letter Of Approval
Call For InfoSec Celebs
ROOTCON 6 Registration Now Live!!!
Our updated tracks (here) updated real time
Our awesome speakers (here)
This year's venue (here)
Last year we had two Registration methods: Paypal and Offline payment (manually sending out email to registration [at] rootcon dot org). The tagging of attendees was pretty hard for the ROOTCON crew, thus, this year we opted to have a new registration system which is EventBrite. You will still have the option to pay offline or pay through PayPal but the up-side for us is that tagging of attendees and slots is much more precise, so we won't be re-opening the registration over and over again after we recount our available slots.
On the new registration system there will still be offline payments through direct deposit and there will also be PayPal payments. You will still receive an e-ticket for the event marked as payment-not-received, however, your reservation will stay on the system for 48 hours, FAILURE OF PAYMENT WITHIN 48 HOURS WILL FORFEIT YOUR RESERVATION. If you deposited your payment already, send us a copy of the scanned deposit slip to registration [at] rootcon dot org with subject [ROOTCON 6 REGISTRATION - YOUR NAME] and we will be sending you another e-ticket marked as payment-received. For Paypal payment you will receive your e-ticket right away after you purchase them.
PRINT YOUR E-TICKET and BRING THEM TO THE CONFERENCE CHECK-IN DESK TO RECEIVE YOUR BADGE AND OTHER FREEBIES
What our you waiting for GRAB YOUR TICKET NOW!!!!
See you at the CON
Semprix and the ROOTCON Crew
Sunday, August 21, 2011
Reminiscing the Hacker’s Manifesto
Have you guys heard of the Hacker’s Manifesto?


The Hacker’s Manifesto
Shipcode is an InfoSec enthusiast from Cebu. During his high school days he was just an ordinary script kiddie. He loves to search for web exploits and other issues concerning network / wireless security.
ROOTCON is managed by like minded InfoSec professionals across the Philippines. All rights reserved. Designated trademarks, brands and articles are the property of their respective owners.
Thursday, August 18, 2011
Cool Ubuntu Shell Account

But there are some flaws in their project because they allow too much background which could possibly be used for illegal activities. We could not deny the fact that some users may tend to abuse their privileges as a user like using it for udpflooding, tcpflooding, hosting botnets, scanning SSH, etc. because of allowing too much background processes. Maybe next time they should put some limit to prevent abuses in their server.
About the Contributor:
Shipcode is an InfoSec enthusiast from Cebu. During his high school days he was just an ordinary script kiddie. He loves to search for web exploits and other issues concerning network / wireless security.
ROOTCON is managed by like minded InfoSec professionals across the Philippines. All rights reserved.Designated trademarks, brands and articles are the property of their respective owners.
Tuesday, August 16, 2011
Thoughts on the Operation Shady Rat
Let it be known that the year 2011 is best described as the Year of the Hackers. And I know, one way or another you will agree or disagree with me. But hey! The media publicized these sophisticated security attacks targeting CIA, US Senate, Sony, PBS, Philippine Congress and the list continues. All of these attacks are attributed to hacker groups such as AntiSec, Anonymous and LulzSec.
I have been quiet for a couple of days because of constant research of this unprecedented cyber-espionage campaign which was discovered in the year 2006 because of the logs which was discovered by McAfee. In fact, some people blame China and Russia behind this espionage but it should be noted that McAfee disclaimed that China or Russia is responsible for this and that they also declined to reveal the source where the “Shady RAT” came from.
I’m not really sure who suggested that China should be blamed for this but I think they blamed some of the Chinese hackers because of the recent information gathering they made. It is said that in the past years, they have stolen highly confidential information that is kept secret in supercomputers in the US. But the Chinese government denied its involvement of the said campaign.
Some people may also say that it’s the Russian government because of the unforgotten Cold War between the US but then again it is really unfair to point our fingers to Russia and China because of insufficient evidence against them. All countries are innocent until proven guilty.
I guess McAfee has unleashed a new media storm because of their discovery since 2006. Their rival company, Symantec also posted its own analysis of the campaign and was skeptical of its impact. "Is the attack described in Operation Shady RAT a truly advanced persistent threat? I would contend that it isn’t, especially when you consider the errors made in configuring the servers and the relatively non-sophisticated malware and techniques used in this case," Symantec's Hon Lau wrote in a blog post.
"Sure the people behind it are persistent but no more than the myriad of other malware groups out there such as Zeus, Tidserv, and others like them," said Lau.
Although, it is highly controversial and questionable why McAfee discovered this campaign before any antivirus company or government agency; but could it be possibly an excuse to put blame on China? That I’m not sure of and I lay my hands off regarding this case.
To our valuable readers, I’ll give you a room for your opinions and views regarding this campaign. If you ask me, I have 60% trusts on this revelation. Whether this is true or not, there are questions that will cloud up our minds. So are we ready for this cyber espionage and cyber terrorism?
ROOTCON is managed by like minded InfoSec professionals across the Philippines. All rights reserved.Designated trademarks, brands and articles are the property of their respective owners.
Monday, August 08, 2011
ROOTCON 5 Parteh and etc...etc...
The first thing to look forward are the talks, ROOTCON has gathered several cool talks, the next thing to look are the games hosted at ROOTCON, if you are into hacking, wargaming, then this is your place, ROOTCON Folks crafted some cool Capture The Flag games for the CON, from WiFi, Web to Shell breaking we have it all, and its all free for ROOTCON attendees.
And the coolest part being at a Hacker CON are the Partehs, yes you heard it right, Partehs. After Day 1 there will be a Geek-Up and Ninja/Pirate/Geek Parteh that will be held, right after Day 2 there will be a post-con parteh as well. Hacker CON is the best time to socialize with our fellow G33ks and H4x0rs. This is the best part of the CON that you don't want to miss at all.
At the time of writing we are already planning these Partehs, you can even plan with us!!! Be updated with our Twitter (@_rootcon_) and our Facebook (https://www.facebook.com/rootcon). Our brainstorming and planning will be put to public at our ROOTCON 5 Google Groups (rootcon5@googlegroups.com)
Let the Partheh and the Hacking begins..........
Department of Defense tries to court hackers

Las Vegas, Nevada (CNN) -- Dear hackers: The U.S. government wants you.
Or, at the very least, the Department of Defense's research wing wants to pay you to help it block cyber threats, a project manager at the Defense Advanced Research Projects Agency said Thursday.
Former hacker Peiter Zatko announced the start of a fund-the-hackers program, called Cyber Fast Track, in a keynote talk at the Black Hat conference, which is aimed at hackers and computer security experts. The program began officially late Wednesday, he said.
Experts say the government has done a lousy job in the past of getting money to security researchers quickly enough for them to actually help mitigate cyber threats. Or the feds have avoided dealing with hackers entirely.
"One of the ways I see fixing it is bridging the gap between the government and the hacker community," said Zatko, who goes by the handle "Mudge."
By "hacker," he doesn't mean criminal. He's referring to people who try to break computer systems with the goal of making them more secure. These people are sometimes referred to in the security industry as "white hats," as opposed to nefarious "black hats."
"We have all sorts of other criminals, be it in politics or finance, and those elements may be bigger than the criminal element in the hacker community," he said.
Other wings of the government appear to be courting the hacker community as well. The Federal Bureau of Investigation and the Internal Revenue Service both have booths set up on the expo floor here at Caesars Palace. Federal agents are so commonplace at this hacker conference -- and at another, called DEF CON, which happens later this week -- that some of the hackers have held a "Spot the Fed" contest, with T-shirts as prizes.
Law enforcement and hackers don't always play well in these arenas. Speakers at past Black Hat and DEF CON conferences have been threatened with injunctions aimed at stopping them from explaining how to hack into certain systems.
The hackers say they're making public such exploits for the public's own good. If they can find the bugs, then bad guys who want to steal information and make money could, too.
In an interview after his talk, Zatko declined to say how much money DARPA will put into the new program, or how big the individual grants will be.
The goal is to fund independent security researchers, who currently do much of their work on nights and weekends without pay, in hopes that they will help make the Internet safer.
One of those hacker-researchers is Dino Dai Zovi, who says his girlfriend gets annoyed that he spends almost all of his free time on his computer.
"Look at the bags under my eyes -- I never stop working," he said.
Dai Zovi said the DARPA program will help hackers actually get paid for their work.
The stakes for the new program are also high.
Zatko, the hacker-turned-DARPA official, said the number of malware attacks continues to increase even as government agencies spend more money to stop them.
In 2000, he said, there were about 1,400 "incidents of malicious cyber activity." Nine years later, that number had jumped to more than 71,000.
Current computer systems are needlessly complicated, he said, which leaves them more open to malicious hacking. He suggested that researchers work, for example, to simplify Microsoft Word with its list of 3,000 fonts and many potential exploits.
Zatko, whose notable life as a hacker has been the inspiration for fictional characters, said he's trying to change how the government works from the inside.
"I hope the old Mudge of 1999 is looking at the current Mudge of 2011 and saying, 'Yeah, you're wearing a pocket square and you don't have long hair,' " he said, " 'but, yeah, you're still remaining true to the cause.' "
Source: CNN
ROOTCON is managed by like minded InfoSec professionals across the Philippines.
All rights reserved. Designated trademarks, brands and articles are the property of their respective owners.
DEF CON trains 8-year-olds in hacking

Las Vegas, Nevada (CNN) -- Joseph Horman already had seen the lock-picking videos on YouTube. But it was a different thing entirely for the 13-year-old puzzle-lover to get lessons in lock picking and computer hacking at an event sanctioned by adults.
The world's largest gathering of computer hackers -- DEF CON, which is happening this weekend at the Rio Hotel and Casino in Las Vegas -- held its first-ever hacking classes for kids this year, at an event appropriately called DEF CON Kids.
Sessions in hacking were designed for kiddos ages 8 to 16.
A common parent's reaction to something this might be: They're teaching them what?! But hear these hackers out. Their intentions are good.
Take Horman's uncle, Adam Steed, a computer security professional in Salt Lake City, Utah, who brought his nephew to these training sessions because he already was fascinated with games and coding. (He actually has written his own computer game, called "Blooks," in which players "try to build as many buildings as you can while avoiding enemies," he said.)
"You can watch lock-picking videos on YouTube, but where do you hear the ethical side of this?" said Steed, the uncle. "Not on YouTube."
He added: "I would rather someone learn in a controlled environment. They're going to learn it anyway."
Horman, the video game-writing nephew, sat attentively in the second row of a small classroom on Saturday, fiddling with a Rubik's Cube during sessions with titles like "Secrets Revealed," "Meet the Feds" and "Google Hacking."
That last class title is a bit misleading, since instructor-hacker Johnny Long focused more on non-technical hacking -- looking at people's laptops over their backs in airports; picking locks with toilet paper rolls and pen caps; and digging social security numbers out of corporate trash bins -- instead of actual search-engine hacking.
Long went to great lengths to remind the kids in attendance that the point of the class was to teach them what bad guys might be doing -- and how to avoid breaches in their own security or privacy.
"Don't let me catch you guys stealing toilet paper and breaking locks," he said. "If you do, it's not my fault."
Horman said he would only pick a lock if his family got locked out of their own house or car. That's happened before, he said, so that skill might be handy.
"Our family has had some trouble with locks," he said, smiling. "Let's say the younger ones love playing with the key and slipping them under the door."
In the "Meet the Feds" session, representatives from NASA, the Department of Homeland Security, the National Security Agency and the Navy told the kids they were smart to pick up hacking skills early because the government needs employees who can hack.
Several kids raised their hands to ask about hacking as a career path.
Part of the potential confusion about DEF CON Kids comes from the very term "hacker," which people here use to refer to anyone who has the skills needed to modify computer software and hardware. Some hackers extend the domain further, to locks and such.
Those skills could be used for criminal activity, but quite a few DEF CON attendees are actually computer security professionals -- the "good guys" trying to make the Internet less vulnerable to attacks by computer criminals.
Still, all this talk about malicious hacking made 10-year-old Dennis Mikhaylov a bit nervous.
"I'm getting a locker next year," he said after one of the class sessions. He's about to start middle school. "I thought it was cool, but now I'm afraid someone might open it."
Mikhaylov said he'd deal with this by keeping any valuables, which he defined as anything with his address on it; textbooks; and his Nook e-reader, which he apparently carries around all the time, out of that school locker.
The DEF CON Kids event also included a competition, where kids went around the hacker conference trying to break codes and solve puzzles.
Isabel Holland, 10, made up one-half of a team called "Sonic Death-Monkeys," a name she says is "weird" but went with because the boy who was her partner chose it.
"You have to, like, find people, and it's really hard because they're all over the place," she said of one piece of the challenge which required her to search out hackers.
Her dad, Bo Holland, from Austin, Texas, said it's cool for kids to get a chance to see how the technology and video games they use all the time actually work.
Ultimately, it will make the kids safer, he said, especially in this age of social networking, when the collective memory of the Internet has no expiration date.
"You're building up your reputation and it's not going to go away. If you do bad things, that's going to stick with you," he said.He added: "You can say, 'Oh, we don't want to hear how this (hacking) stuff works and that's scary ... but it's really important kids know how to protect themselves."
Source: CNN
ROOTCON is managed by like minded InfoSec professionals across the Philippines.
All rights reserved. Designated trademarks, brands and articles are the property of their respective owners.











