Showing posts with label hacking. Show all posts
Showing posts with label hacking. Show all posts
Saturday, October 01, 2016
Thank you from semprix
In-behalf of the goons and volunteers of ROOTCON I would like to personally say THANK YOU!
This years conference was an epic one.
The topics delivered were highly technical and we thank our speakers for that! The trainings were jam-packed, we are looking into expanding our trainings with different cutting-edge topics by next year. The games were well participated, receiving feedbacks that they enjoyed our Capture The Flag this year makes us to do more of it. The newly introduced Semprix’ Mysterybox didn’t gain much players, maybe it was too difficult I will try to adjust the difficulty next year.
With the newly introduced multiple tracks, the Capture The Flag had it’s dedicated area so players can focus more on the game with comfortable table and seats. The chill-out area was another best decision we had, through out the two day conference we consumed 70 liters of beer, awesome right?
The post-con party was pretty epic as well! We consumed 20 bottles of hard-drinks from Jack Daniels, Bacardi, to Mojito, 120 bottles of beer were served not to mention Smirnoff Mule sponsored us 400 bottles!
Right after the conference the goons were already brain-storming what more cool stuffs we can add to next year. Here are some stuffs to watch-out for next year.
1. We will introduce Fort ROOTCON, an area around the conference were tools and exploits have demos.
2. Hacker Jeopardy will be rescheduled for everyone to be able to attend.
3. Day 1 party and movie night will be held at the conference hall.
4. Capture the Flag will be extended from 10:00am to 11:00pm in-conjunction with the day 1 party and movie night.
Some pre-con activities we are brewing up.
1. Campus tour with student Capture The Flag.
2. Hackerspace in January
3. ROOTCON Kids will be introduced as mini-event around the month of May.
ROOTCON will continue to serve the hacking community specially in the Philippines, where hackers, geeks, pros will meet old and new friends, enjoy and of course learn from each other. With that said it wouldn't be possible without our awesome attendees, you rock!
Again I would like to say THANK YOU SO MUCH!
All the best,
semprix
Read More
This years conference was an epic one.
The topics delivered were highly technical and we thank our speakers for that! The trainings were jam-packed, we are looking into expanding our trainings with different cutting-edge topics by next year. The games were well participated, receiving feedbacks that they enjoyed our Capture The Flag this year makes us to do more of it. The newly introduced Semprix’ Mysterybox didn’t gain much players, maybe it was too difficult I will try to adjust the difficulty next year.With the newly introduced multiple tracks, the Capture The Flag had it’s dedicated area so players can focus more on the game with comfortable table and seats. The chill-out area was another best decision we had, through out the two day conference we consumed 70 liters of beer, awesome right?
The post-con party was pretty epic as well! We consumed 20 bottles of hard-drinks from Jack Daniels, Bacardi, to Mojito, 120 bottles of beer were served not to mention Smirnoff Mule sponsored us 400 bottles!
Right after the conference the goons were already brain-storming what more cool stuffs we can add to next year. Here are some stuffs to watch-out for next year.
1. We will introduce Fort ROOTCON, an area around the conference were tools and exploits have demos.
2. Hacker Jeopardy will be rescheduled for everyone to be able to attend.
3. Day 1 party and movie night will be held at the conference hall.
4. Capture the Flag will be extended from 10:00am to 11:00pm in-conjunction with the day 1 party and movie night.
Some pre-con activities we are brewing up.
1. Campus tour with student Capture The Flag.
2. Hackerspace in January
3. ROOTCON Kids will be introduced as mini-event around the month of May.
ROOTCON will continue to serve the hacking community specially in the Philippines, where hackers, geeks, pros will meet old and new friends, enjoy and of course learn from each other. With that said it wouldn't be possible without our awesome attendees, you rock!
Again I would like to say THANK YOU SO MUCH!
All the best,
semprix
Tuesday, April 05, 2016
ROOTCON 10 Call For Papers Now Open!
Posted by
Shipcode
at
5.4.16
Labels:
Call For Papers,
hacking,
hacking conference,
rootcon,
ROOTCON 10,
rootcon speakers
Last year at ROOTCON IX, we had some awesome lineup of talks from 31337 speakers:
Read More
- How to Shot Web: Better Web Hacking in 2015 by Jason Haddix
- BackDooring Git by John Menerick
- Open Source Internet Infrastructure Insecurity by John Menerick
- Unmasking Malware by Christopher Elisan
- Hacking Time by Carlos Tingson
- Hiding Behind ART by Paul Sabanal
- Building Automation and Control: Hacking Energy Saving System by Philippe Z Lin
- Detecting Indicators of a Compromise Using an SDN-Based Network Access Control Implementation by Mon Nunez & Paul Prantilla
- Incident Response for Targeted attacks by Jose Ramon Palanco
- How safe is my system from reverse engineering by Markku Kero
- Fixing CSRF Vulnerabilities Effectively by Lu Zhao
- Once more unto the data breach by Steve Miller
- Oh My Honey: Honeypots (or honeynets) by Ray Torres
- Understanding HTTP/2 by Nathan LaFollette
Now what about this year? Well, we need the crowd of researchers and 31337 hackers again to submit your talks since ROOTCON X's CFP (Call for Papers) has been opened for this year!
It's time to show off those fresh and sizzling new hacks on September 22-24, 2016 at the Taal Vista Hotel, Tagaytay, Philippines. What are you waiting for? Email cfp [at] rootcon [dot] org and follow the instructions here: https://www.rootcon.org/xml/rc10/cfp
Topics of interest but not limited to:
- Real-life hack (responsible disclosure)
- Non-tech hacking
- New tool release
- Exploit Development
- Reverse Engineering
- Web Application Attacks
- Tools 101 (Metasploit, Nmap, etc…etc…)
- Wireless Attacks (3G, 4G, 802.11(x))
- Cloud Security
- Vulnerability Discovery
- OS Level Vulnerabilities
- Physical Security (Lock picking – Digital Locks or Digital Safes)
- SQL Injections
- Vendor Appliance Vulnerabilities
- Exploitation Techniques
- Mobile Security
- Internet of Things (IOT)
Saturday, April 14, 2012
ClubHack Magazine April 2012 Issue Released!
Posted by
Shipcode
at
14.4.12
Labels:
april 2012,
CHmag,
Clubhack,
hacking,
India,
magazine,
tech gyan,
XSS
India's 1st Hacking Magazine which is ClubHack or CHmag has just released their April 2012 Issue. CHmag happens to be our media partner and that CHMag is one of the hacking/infosec magazines I'm currently following because of the good contents from various authors and for this issue I also contributed an article for the Mom's Guide. Here are the topics for this month's issue:
-Decoding ROT using the Echo and Tr Commands in your Linux TerminalThe new burner for this issue is the new section which is the Code Gyan that started with a new topic entitled Local File Inclusion.
-How to enable WiFi on Matriux running inside VMWare
-Local File Inclusion
-Poster of the Month
-Provisions of Sec. 66B
-Sysinternals Suite
-XSS – The Burning issue in Web Application
You can download the PDF File here or you could check out the archives for their previous issues in their official website.
About the Contributor:
Shipcode
is a prolific blogger of ROOTCON and at the same time an InfoSec
enthusiast from Cebu. He was inspired to join ROOTCON as part of the
core team to share his knowledge in information security. He encourages
other like minded individuals to come forward and share their knowledge
through blogging right here at ROOTCON Blog section.
ROOTCON is managed by like minded InfoSec professionals across the Philippines. All rights reserved. Designated trademarks, brands and articles are the property of their respective owners.
Friday, August 05, 2011
Kids have ‘Angel’ in Net to guard vs sex predators

There’s an angel watching over your child on the Internet.
“Project Angel Net,” a 24/7 operation center and website aimed at fighting online sex predators and cyber bullies, was launched on Thursday by the Criminal Investigation and Detection Group (CIDG) of the Philippine National Police (PNP).The CIDG head, Director Samuel D. Pagdilao Jr., said Angel Net sought to protect children from cyber criminals involved in online pornography, gambling, and identity theft, as well as ordinary netizens who bully or take advantage of others.
The launch of the website www.cidgangelnet.ph coincided with the opening of the CIDG’s anticyber crime operation center, Pagdilao said.
The website, officials said, will serve as a complaint center where people can directly report incidents of child abuses related to the Internet.
As of Thursday, however, the “contact us” section did not yet have a mechanism where people could just type in their complaints. It only had the addresses and phone numbers of the operation center.
Tips to parents
The website will also feature warnings about the dangers of Internet addiction among underage kids, as well as tips for parents about keeping their children safe online.
At the launch, Pagdilao noted that even his 8-year-old son was addicted to computer games. “When I return home from work, I notice he’s still glued to the computer screen,” he said.
“As a parent, first, I have to orient him on the old way of disciplining children, which is imposing time and limits,” Pagdilao said in an interview.
“Second, we have to encourage him to engage in other activities; take him to some other place; and third, you have to point out those sites that he should visit safely,” he told reporters.
20 million users
The Philippines is ranked 17th among the nations with the highest number of Internet users, according to the CIDG’s Anti-Transnational Crime Division chief, Senior Supt. Gilbert Sosa.
Records compiled by the CIDG showed that Internet users in the Philippines went up to 20 million in 2010 out of a population of 99 million, representing a 29.7-percent penetration share and a startling 1,385-percent increase from 2000.
“Accordingly, more than 50 percent of Internet users are minors aged 17 years old and below,” the CIDG said.
“Apparently, every house that has a computer is a potential victim of Internet crime. At present, abuses through social networking media are increasing at an alarming scale,” Sosa said.
Tracking predators
Felino Castro V, the director of the Management Information Service of the Department of Social Work and Development, said the 1,000-fold increase in Filipino Internet users from the last decade had amplified the need to protect children.
“We have received complaints of children being sold online… There are children being bullied… and eventually, if we look at our laws, we just have to coordinate among our law enforcers and they will be able to curb this trend,” he said.
The operation center at Camp Crame is equipped with computers and manned by trained technical operatives. It is seen to enhance the capability of the CIDG to monitor and track cyber predators. A walk-in complaint desk will be run by the Women’s and Children Protection Division.
Pagdilao noted that in spite of several incidents of crimes committed through the Internet, “these crimes have been hardly reported and acted upon” because there was no specific PNP unit to accommodate reports on cybercrimes.
Digital tracking
“Adding to that is the fact that law enforcers have limited resources and ability to confront Internet-related crimes,” he said.
“Confronting crimes of this nature cannot be dealt with traditional anticriminality operations, especially with the kind of situation law enforcers find themselves in,” Pagdilao said.
“It is for this reason that the CIDG is exploring other avenues beyond common investigative and detective work to properly address the problem that is bounded by the intricacies of Internet,” he added.
According to the CIDG chief, Angel Net will involve “24/7 digital tracking, collating, collecting, archiving, investigating and interdicting activities that will identify Internet predators.”
The result would be “the proper documentation of their corresponding illegal activities leading to their subsequent arrest,” Pagdilao said.
Angel Net will coordinate and cooperate with other stakeholders, such as the media, Internet service providers, schools, nongovernmental organizations, rehabilitation centers, youth groups, social welfare offices, and telephone companies, as well as the Interpol and the United Nation Children’s Fund.
Site of choice
In June, the CIDG noted an apparent upward trend in general computer crimes in the first half of the year, particularly identity theft, libel, estafa (fraud), harassment and hacking.
Walk-in complaints to the agency about computer crimes from Jan. 1 to June 14 numbered 56, just 26 cases short of the total for the entire 2010.
Of the complaints, Facebook was the social networking site of choice of most of the perpetrators, with six cases each of estafa and libel, three each of harassment and hacking, and five identity theft cases for the first six months.
Two complaints for pornography were also registered in that period.
There were also complaints involving personal e-mail (five complaints), the microblogging site Twitter and Multiply (one each), and the online auction site eBay.
Eleven complaints for threat involving cellular phone use were also recorded during the same period, up from the four cases recorded the whole of last year.
On the other hand, only two credit card fraud cases were recorded in the first six months, compared to six in 2010.
But the figures covered only the walk-in cases directly reported to the CIDG. The agency will have to coordinate with other units and the local police to collect other data.
Source: Inquirer
ROOTCON is managed by like minded InfoSec professionals across the Philippines. All rights reserved. Designated trademarks, brands and articles are the property of their respective owners.
Wednesday, July 27, 2011
Linux 3.0 Kernel Released! Linux 3.0.c Kernel Exploit also Released!
Posted by
Shipcode
at
27.7.11
Labels:
Cross,
exploit,
hacking,
Linux 3.0 Kernel,
Linux 3.0.c,
Perl,
rootcon,
rooting,
ROOTWORM,
vulnerability

It was in the evening of July 22, 2011 when Linus Torvalds posted on Google+ about the new 3.0 kernel version which marked the end of 2.6.x series of kernel versions. After which, the initial plans of 3.1 were then a big issue to his followers because its exploit was released a few days after it was announced officially.

A guy named Dan Rosenberg compiled a C code entitled the “DEC Alpha Linux 3.0 local root exploit” which points out the vulnerability of the new 3.0 kernel version. Then also, a guy named Cross from ROOTWORM also published his Perl script entitled “2011 Linux Auto Rooter Beta 1.0” which includes the kernel versions 2.6.18 series to 3.0 kernel version exploits. The Perl script of Cross was also posted in most of the underground websites.
For those of you who are not familiar of a kernel exploit, a kernel exploit is written in C and its objective is to root a Linux box. With this exploit, a normal user of a certain machine can become a super user of a certain box which gives him more privileges like installing more repositories, installing other softwares, hosting malicious codes, hosting an ssh scanner, etc. Thus it’s a big, big trouble.
As of now, The Linux team is still fixing some of the current kernel’s bugs and issues. We hope to see the release of the 3.1 kernel version soon.
About the Contributor:
Shipcode is an InfoSec enthusiast from Cebu. During his high school days he was just an ordinary script kiddie. He loves to search for web exploits and other issues concerning network / wireless security.
ROOTCON is managed by like minded InfoSec professionals across the Philippines. All rights reserved.Designated trademarks, brands and articles are the property of their respective owners.
Thursday, June 16, 2011
Hacker defaces Customs website amid gov't warning vs hacking
Amid a looming review of the security of Philippine government websites, another government website fell victim to a hacker who defaced its news section.

Visitors to the Bureau of Customs website's news section as of 7 a.m. were greeted with several lines of text in an unfamiliar font.

The lines of text were superimposed on the news section of the Customs Bureau website. The links on the news section also appeared to be disabled.
On the other hand, the hacker left behind a web address that led to an "anonymous text hosting service."
In the hacker's page, the hacker claimed to be "inactive" starting June 15 onwards.
However, the supposed hacker's page also contained what appeared to be usernames and passwords taken from websites of several Philippine government agencies and private firms.
"I will not decrypt the hash for you, unless you make contract with me," the hacker said.
Among the government sites listed in the hacker's page were:
- www.bsp.gov.ph (Bangko Sentral ng Pilipinas)
- www.bas.gov.ph (Bureau of Agricultural Statistics)
- www.customs.gov.ph (Bureau of Customs)
- www.pbs.gov.ph (Philippine Broadcasting Service)
Review of govt websites' security looms
On Tuesday, MalacaƱang said the security of government website may be reviewed soon, a day after a "Filipino" hacker group hinted at more attacks on Philippine government websites.
Presidential spokesman Edwin Lacierda indicated National Security Adviser Cesar Garcia is studying creating a task force to do the review.
Among the most recent attacks on government websites was the defacing last May 31 of the Department of Interior and Local Government's site.
Last Monday, a more "serious" group managed to hijack the site of the Philippine Nuclear Research Institute (PNRI).
The group, calling itself "Philker," redirecting visitors to the PNRI site to a separate website that bore a "warning" from the "Philker" group.
"We are not trying to damage you. We only want to help protect our country's cyberspace by doing what seems to be the most efficient way to get everyone's attention. May this deface serve as a reminder that you always have to look out for intruders. No matter how intelligent and competent your computer personnel are, there will be unethical hackers that are constantly working on breaking in your security," the hackers said in their message in the redirected site.
Philker said that while it and online "thieves and terrorists" are "cut from the same cloth," its difference is that "we have good intentions."
It added it aims to elevate the Philippines' cyber culture and to "point out and correct the vulnerabilities of Philippine websites," to "protect them from unethical hackers, fraud, false propaganda and other people with malicious intent."
It also hinted at future break-ins of other sites, leaving behind a note similar to the international hacktivist group Anonymous. — LBG, GMA News
Source: GMA News
Related News:
PHL gov't to assess website security in response to hacking
PHL hackers deface PNRI website, hint at more attacks
Talk Back
Please comment on this news article at our ROOTCON Forum. We all learn from each other when your views and opinions are shared.
Read More

A day after the government announced a review of government websites' security, the Bureau of Customs' website was defaced with several lines of text and the address of the supposed hacker's website. The defaced page was still online as of 7 a.m.
Visitors to the Bureau of Customs website's news section as of 7 a.m. were greeted with several lines of text in an unfamiliar font.

As of 7:21 a.m. Wednesday, the webpage referred to by the hacked Customs website lists supposed usernames and passwords taken from websites of government agencies and private firms.
The lines of text were superimposed on the news section of the Customs Bureau website. The links on the news section also appeared to be disabled.
On the other hand, the hacker left behind a web address that led to an "anonymous text hosting service."
In the hacker's page, the hacker claimed to be "inactive" starting June 15 onwards.
However, the supposed hacker's page also contained what appeared to be usernames and passwords taken from websites of several Philippine government agencies and private firms.
"I will not decrypt the hash for you, unless you make contract with me," the hacker said.
Among the government sites listed in the hacker's page were:
- www.bsp.gov.ph (Bangko Sentral ng Pilipinas)
- www.bas.gov.ph (Bureau of Agricultural Statistics)
- www.customs.gov.ph (Bureau of Customs)
- www.pbs.gov.ph (Philippine Broadcasting Service)
Review of govt websites' security looms
On Tuesday, MalacaƱang said the security of government website may be reviewed soon, a day after a "Filipino" hacker group hinted at more attacks on Philippine government websites.
Presidential spokesman Edwin Lacierda indicated National Security Adviser Cesar Garcia is studying creating a task force to do the review.
Among the most recent attacks on government websites was the defacing last May 31 of the Department of Interior and Local Government's site.
Last Monday, a more "serious" group managed to hijack the site of the Philippine Nuclear Research Institute (PNRI).
The group, calling itself "Philker," redirecting visitors to the PNRI site to a separate website that bore a "warning" from the "Philker" group.
"We are not trying to damage you. We only want to help protect our country's cyberspace by doing what seems to be the most efficient way to get everyone's attention. May this deface serve as a reminder that you always have to look out for intruders. No matter how intelligent and competent your computer personnel are, there will be unethical hackers that are constantly working on breaking in your security," the hackers said in their message in the redirected site.
Philker said that while it and online "thieves and terrorists" are "cut from the same cloth," its difference is that "we have good intentions."
It added it aims to elevate the Philippines' cyber culture and to "point out and correct the vulnerabilities of Philippine websites," to "protect them from unethical hackers, fraud, false propaganda and other people with malicious intent."
It also hinted at future break-ins of other sites, leaving behind a note similar to the international hacktivist group Anonymous. — LBG, GMA News
Source: GMA News
Related News:
PHL gov't to assess website security in response to hacking
PHL hackers deface PNRI website, hint at more attacks
Talk Back
Please comment on this news article at our ROOTCON Forum. We all learn from each other when your views and opinions are shared.
ROOTCON is managed by like minded InfoSec professionals across the Philippines.
All rights reserved. Designated trademarks, brands and articles are the property of their respective owners.
All rights reserved. Designated trademarks, brands and articles are the property of their respective owners.
Subscribe to:
Posts (Atom)
Subscribe to:
Posts (Atom)

