Showing posts with label security conference. Show all posts
Showing posts with label security conference. Show all posts

Monday, August 08, 2011

10 year old girl hacker CyFi reveal her first zero-day in Game at #DefCon 19


Another awesome day at DefCon 19 . Today a 10 year old Girl hacker - pseudonym CyFi revealed her zero-day exploit in games on iOS and Android devices that independent researchers have confirmed as a new class of vulnerability. The 10-year-old girl from California first discovered the flaw around January 2011 because she "started to get bored" with the pace of farm-style games.

About CyFi :
She is cofounder of DEFCON Kids. CyFi is a ten-year-old hacker, artist and athlete living in California. She has spoken publicly numerous times, usually at art galleries as a member of “The American Show,” an underground art collective based in San Francisco. CyFi’s first gallery showing was when she was four. Last year she performed at the SF MOMA Museum in San Francisco. DEFCON Kids will be her first public vulnerability disclosure. CyFi’s has had her identity stolen twice. She really likes coffee, but her mom doesn’t let her drink it.

CyFi said, "It was hard to make progress in the game, because it took so long for things to grow. So I thought, 'Why don't I just change the time?'" Most of the games she discovered the exploit in have time-dependent factors. Manually advancing the phone or tablet's clock forced the game further ahead than it really was, opening up the exploit.

CyFi said that she discovered some ways around those detections. Disconnecting the phone from Wi-Fi made it harder to stop, as did making incremental clock adjustments. CyFi's mother, who must remain anonymous to protect her daughter's identity, told at the end of CyFi's presentation at DefCon Kids that they would offer a $100 reward to the young hacker who found the most games with this exploit over the following 24 hours. The reward is sponsored by AllClearID, a identity protection company that is also sponsoring the DefCon Kids.

CyFi revealed that she was only a little bit nervous about having to speak in front of the 100 or so expected attendees. She admitted that while it was probably different publicly speaking about a topic with such a specific focus, it would be hard for her to imagine what those differences might be. "Well, I haven't done it yet," she said.

Source: The Hacker News


ROOTCON is managed by like minded InfoSec professionals across the Philippines.
All rights reserved. Designated trademarks, brands and articles are the property of their respective owners.

Read More

Department of Defense tries to court hackers

Las Vegas, Nevada (CNN) -- Dear hackers: The U.S. government wants you.

Or, at the very least, the Department of Defense's research wing wants to pay you to help it block cyber threats, a project manager at the Defense Advanced Research Projects Agency said Thursday.

Former hacker Peiter Zatko announced the start of a fund-the-hackers program, called Cyber Fast Track, in a keynote talk at the Black Hat conference, which is aimed at hackers and computer security experts. The program began officially late Wednesday, he said.

Experts say the government has done a lousy job in the past of getting money to security researchers quickly enough for them to actually help mitigate cyber threats. Or the feds have avoided dealing with hackers entirely.

"One of the ways I see fixing it is bridging the gap between the government and the hacker community," said Zatko, who goes by the handle "Mudge."

By "hacker," he doesn't mean criminal. He's referring to people who try to break computer systems with the goal of making them more secure. These people are sometimes referred to in the security industry as "white hats," as opposed to nefarious "black hats."

"We have all sorts of other criminals, be it in politics or finance, and those elements may be bigger than the criminal element in the hacker community," he said.

Other wings of the government appear to be courting the hacker community as well. The Federal Bureau of Investigation and the Internal Revenue Service both have booths set up on the expo floor here at Caesars Palace. Federal agents are so commonplace at this hacker conference -- and at another, called DEF CON, which happens later this week -- that some of the hackers have held a "Spot the Fed" contest, with T-shirts as prizes.

Law enforcement and hackers don't always play well in these arenas. Speakers at past Black Hat and DEF CON conferences have been threatened with injunctions aimed at stopping them from explaining how to hack into certain systems.

The hackers say they're making public such exploits for the public's own good. If they can find the bugs, then bad guys who want to steal information and make money could, too.

In an interview after his talk, Zatko declined to say how much money DARPA will put into the new program, or how big the individual grants will be.

The goal is to fund independent security researchers, who currently do much of their work on nights and weekends without pay, in hopes that they will help make the Internet safer.

One of those hacker-researchers is Dino Dai Zovi, who says his girlfriend gets annoyed that he spends almost all of his free time on his computer.

"Look at the bags under my eyes -- I never stop working," he said.

Dai Zovi said the DARPA program will help hackers actually get paid for their work.

The stakes for the new program are also high.

Zatko, the hacker-turned-DARPA official, said the number of malware attacks continues to increase even as government agencies spend more money to stop them.

In 2000, he said, there were about 1,400 "incidents of malicious cyber activity." Nine years later, that number had jumped to more than 71,000.

Current computer systems are needlessly complicated, he said, which leaves them more open to malicious hacking. He suggested that researchers work, for example, to simplify Microsoft Word with its list of 3,000 fonts and many potential exploits.

Zatko, whose notable life as a hacker has been the inspiration for fictional characters, said he's trying to change how the government works from the inside.

"I hope the old Mudge of 1999 is looking at the current Mudge of 2011 and saying, 'Yeah, you're wearing a pocket square and you don't have long hair,' " he said, " 'but, yeah, you're still remaining true to the cause.' "


Source: CNN


ROOTCON is managed by like minded InfoSec professionals across the Philippines.

All rights reserved. Designated trademarks, brands and articles are the property of their respective owners.

Read More

DEF CON trains 8-year-olds in hacking

Las Vegas, Nevada (CNN) -- Joseph Horman already had seen the lock-picking videos on YouTube. But it was a different thing entirely for the 13-year-old puzzle-lover to get lessons in lock picking and computer hacking at an event sanctioned by adults.

The world's largest gathering of computer hackers -- DEF CON, which is happening this weekend at the Rio Hotel and Casino in Las Vegas -- held its first-ever hacking classes for kids this year, at an event appropriately called DEF CON Kids.

Sessions in hacking were designed for kiddos ages 8 to 16.

A common parent's reaction to something this might be: They're teaching them what?! But hear these hackers out. Their intentions are good.

Take Horman's uncle, Adam Steed, a computer security professional in Salt Lake City, Utah, who brought his nephew to these training sessions because he already was fascinated with games and coding. (He actually has written his own computer game, called "Blooks," in which players "try to build as many buildings as you can while avoiding enemies," he said.)

"You can watch lock-picking videos on YouTube, but where do you hear the ethical side of this?" said Steed, the uncle. "Not on YouTube."

He added: "I would rather someone learn in a controlled environment. They're going to learn it anyway."

Horman, the video game-writing nephew, sat attentively in the second row of a small classroom on Saturday, fiddling with a Rubik's Cube during sessions with titles like "Secrets Revealed," "Meet the Feds" and "Google Hacking."

That last class title is a bit misleading, since instructor-hacker Johnny Long focused more on non-technical hacking -- looking at people's laptops over their backs in airports; picking locks with toilet paper rolls and pen caps; and digging social security numbers out of corporate trash bins -- instead of actual search-engine hacking.

Long went to great lengths to remind the kids in attendance that the point of the class was to teach them what bad guys might be doing -- and how to avoid breaches in their own security or privacy.

"Don't let me catch you guys stealing toilet paper and breaking locks," he said. "If you do, it's not my fault."

Horman said he would only pick a lock if his family got locked out of their own house or car. That's happened before, he said, so that skill might be handy.

"Our family has had some trouble with locks," he said, smiling. "Let's say the younger ones love playing with the key and slipping them under the door."

In the "Meet the Feds" session, representatives from NASA, the Department of Homeland Security, the National Security Agency and the Navy told the kids they were smart to pick up hacking skills early because the government needs employees who can hack.

Several kids raised their hands to ask about hacking as a career path.

Part of the potential confusion about DEF CON Kids comes from the very term "hacker," which people here use to refer to anyone who has the skills needed to modify computer software and hardware. Some hackers extend the domain further, to locks and such.

Those skills could be used for criminal activity, but quite a few DEF CON attendees are actually computer security professionals -- the "good guys" trying to make the Internet less vulnerable to attacks by computer criminals.

Still, all this talk about malicious hacking made 10-year-old Dennis Mikhaylov a bit nervous.

"I'm getting a locker next year," he said after one of the class sessions. He's about to start middle school. "I thought it was cool, but now I'm afraid someone might open it."

Mikhaylov said he'd deal with this by keeping any valuables, which he defined as anything with his address on it; textbooks; and his Nook e-reader, which he apparently carries around all the time, out of that school locker.

The DEF CON Kids event also included a competition, where kids went around the hacker conference trying to break codes and solve puzzles.

Isabel Holland, 10, made up one-half of a team called "Sonic Death-Monkeys," a name she says is "weird" but went with because the boy who was her partner chose it.

"You have to, like, find people, and it's really hard because they're all over the place," she said of one piece of the challenge which required her to search out hackers.

Her dad, Bo Holland, from Austin, Texas, said it's cool for kids to get a chance to see how the technology and video games they use all the time actually work.

Ultimately, it will make the kids safer, he said, especially in this age of social networking, when the collective memory of the Internet has no expiration date.

"You're building up your reputation and it's not going to go away. If you do bad things, that's going to stick with you," he said.He added: "You can say, 'Oh, we don't want to hear how this (hacking) stuff works and that's scary ... but it's really important kids know how to protect themselves."


Source: CNN


ROOTCON is managed by like minded InfoSec professionals across the Philippines.
All rights reserved. Designated trademarks, brands and articles are the property of their respective owners.

Read More

Monday, July 04, 2011

Missed the Early Bird Discount for ROOTCON 5?

Dear Friend,

We are happy to inform you that the Early Bird rates for “ROOTCON: 5th
Philippine Hacker Conference and Information Security Gathering”
happening on September 9 – 10, 2011 at Parklane International Hotel,
Cebu City is extended until July 20, 2011 (Wednesday).

Here’s the list of companies and universities who registered to
participate ROOTCON 5:

- Aboitiz Equity Ventures
- Secure DNA
- TrendMicro
- Hewlett-Packard
- GFI Software, Inc.
- InfoWeapons
- iComm International Inc.
- Pilmico Foods Corporation
- Academic Taking Forward
- National Computer Center
- Department of Science and Technology Region XI
- Yoshii Software Solutions Philippines Corporation
- PhilWebServices Global Solutions, Inc.
- Blue Blade Technologies
- University of San Jose Recolletos
- Global Reciprocal Colleges
- St. Paul University Manila
- Alliance Software, Inc.
- Golden Prince Hotel & Suites
- Voice Fidelity Technologies
- Advanced World Systems, Inc.
- Alphasys PTY LTD
- Logica
- Top Shelf Solutions


and more to mention!


REGISTER NOW!!! because we certainly value your presence to advance your
career, socialize with other professionals and help reshape (enhance)
the security policy within your organization.

Complete synopsis of our topics and speaker’s bio can be viewed at:

http://www.rootcon.org/xml/rootcon5/tracks
http://www.rootcon.org/xml/rootcon5/speakers

Follow our fine tradition with expert speakers, top-notch technical
sessions and an overall outstanding unique security conference
different from any ICT events you attended in the past.

This is your EVENT you don’t want to miss!

Read More

Sunday, June 19, 2011

ROOTCON Ad on “The Freeman” Cebu newspaper

ROOTCON 5 published on "The Freeman" Cebu newspaper, dated June 19, 2011 (page 5)

Finally. We were able to publish our first advertisement on “The Freeman” Newspaper, dated June 19, 2011.

Thanks to our sponsors and partners:


- Mozcom Inc.

- Infosec Philippines

- Trend Micro

-
InfoWeapons
- Parklane International Hotel

-
Global Interactive Solutions, Inc.
- Third Team Media

-
NodeZero
- DitoNa.com


In every newspaper ad on "The Freeman" (Cebu newspaper) we will TRY to come up with different design concepts for "ROOTCON: 5th Philippine Hacker Conference and Information Security Gathering" which will be held on September 9 and 10, 2011, Parklane International Hotel, Cebu City, Philippines.

Newspaper Ad #1 (June 19, 2011 - page 5)
"Let's Talk About Security"

Newspaper Ad #2 (June 2011)
Hackers love technology, but crackers love to break it. Which one is he?"

Newspaper Ad #3 (July 2011)
"Hackers Coming to a Website Near You"

Newspaper Ad #4 (July 2011)
"If only I have the source code, I could change the world!"

Newspaper Ad #5 (August 2011)
"P495,740,890.00 money transferred and counting..."

Newspaper Ad #6 (August 2011)
"Pinoy Hackers: They Do Exist!"

Newspaper Ad #7 (September 2011)
"Warning: You've been hacked!"

If you have whacky yet funny tag lines, post it here or email us at info@rootcon.org. What we posted above from newspaper ad #3 - 7 are not yet final. So you still have a chance to contribute or suggest a funny yet a bit serious tag line. :)

You want to volunteer for ROOTCON? Email us at info@rootcon.org. We love to hear you!


Don''t forget, early bird discount is until June 30, 2011.



About the Contributor:
A self-confessed blogger minus the coffee. He maximizes his skills in consultancy, project management, professional networking, social media campaigns and very active in conceptualizing things. To date he already conducted several IT / Information Security events as his passion since 2007. Currently he's working as a Technical Support Specialist in a local company.



ROOTCON is managed by like minded InfoSec professionals across the Philippines.
All rights reserved. Designated trademarks, brands and articles are the property of their respective owners.
Read More

Monday, June 13, 2011

What you can expect for the 2 days ROOTCON 5 security convention?

ROOTCON 4 participants in Manila, October 10, 2010

I’ve been receiving a lot of inquiries on what to expect during this 2 days security convention on September 9 – 10, 2011, Parklane International Hotel, Cebu City, Philippines.

So here it goes:

1) Carefully selected and approved topics from our experts who submitted their entries for our “Call for Papers”.

2) Things you want to know about the latest security concepts and tools for hacking (tools of the trade). This is to help you better equipped and up to date. After all, you hack to learn how to defend your own network. You will witness hacking at its finest by a group of security enthusiasts or IT security professionals.

3) These talks will cover demonstrations, examples and overviews of attacks, technologies used or trends. These are technical issues all security practitioners (and business owners / managers) should be aware of.

4) This event will help management decide what to do about all the technical issues surrounding security.

5) Other topics will bring to light the security and mis-configuration problems confronting organizations, network administrations, system admin and web developers to name a few who are mostly pre-occupied where security gets put off due to constant network growth and workloads.

6) ROOTCON is not a marketing event or another "That's Entertainment" security gathering. This is unique from other conferences you attended in the past.

7) Fun and interesting event that you will always remember.

8) A chance to socialize and connect with other professionals. Foster camaraderie among the attendees.

9) Affordable – high quality without the high price. Keep in mind that space is limited.

10) Offers an interesting atmosphere for demonstrating technology exploitation, software / hardware solutions and with open discussions of critical information security issues.

...and more to expect during the CON!

Join us and register now! Early bird discount is until June 30, 2011.

ROOTCON security convention only happens once a year.


About the Contributor:
A self-confessed blogger minus the coffee. He maximizes his skills in consultancy, project management, professional networking, social media campaigns and very active in conceptualizing things. To date he already conducted several IT / Information Security events as his passion since 2007. Currently he's working as a Technical Support Specialist in a local company.


ROOTCON is managed by like minded InfoSec professionals across the Philippines.
All rights reserved. Designated trademarks, brands and articles are the property of their respective owners.


Read More

Saturday, June 11, 2011

Let me say Thank You to Ms. T for supporting ROOTCON


Since the start of our campaign for ROOTCON 5, we’ve met several people whom I believe supports ROOTCON as the Philippine’s Leading Information Security Conference that is not a marketing event but a unique technical gathering for professionals. Meet ups here in Cebu and another meet ups in Manila – yeah!

So who is Ms. T?

Ms. T is originally from Cebu and obtained her BSECE from USC-TC. She moved to the US shortly thereafter, obtained her MBA there and has worked abroad for many years mainly in the US and Japan.

Currently she’s based in San Francisco, CA and she’s here in the Philippines for a short vacation and at the same time share what she know and give back – “Pay It Forward”.

She spearheaded and co-founded “Tech Talks”. She’s glad to see our talented folks and she hopes that we can all work together to foster start-ups and do what’s necessary to become globally competitive in our industry.

She’s an independent consultant doing business development and international recruitment for clients in the tech industry – in the areas of business continuity, disaster recovery, data storage, information security and related fields.

Ms. T is one of our sponsors and she’ll be in Manila on June 13 onwards to attend another event and meet up with other InfoSec professionals .

Thank you!


Related Blog:
Networking is essential to your career advancement and professional success


About the Contributor:
A self-confessed blogger minus the coffee. He maximizes his skills in consultancy, project management, professional networking, social media campaigns and very active in conceptualizing things. To date he already conducted several IT / Information Security events as his passion since 2007. Currently he's working as a Technical Support Specialist in a local company.

ROOTCON is managed by like minded InfoSec professionals across the Philippines.
All rights reserved. Designated trademarks, brands and articles are the property of their respective owners.

Read More

Sunday, May 15, 2011

What makes ROOTCON different?

Determining what really sets ROOTCON apart from others and communicating it effectively is not an easy thing to do. Considering that ROOTCON was molded through our collective efforts, volunteers from across the country, invited guest speakers and seeking sponsors to support the whole event is and will always be a learning adventure.

Technically speaking, like what I said in my previous post - ROOTCON is not associated with any of the businesses or companies in the country. Thus we make it a point from the very beginning that all the topics in our seminar tracks are not disguised as a marketing tool.

Topics that we have in every convention are not recycled. These are topics approved by our committee through our "Call For Papers". We scrutinize our speakers and so with their topics if they are obsolete or updated. Now you know that our speakers are “The Experts” with solid experience on security.

Hacking contest is also available during the conference but the targets are local NOT public servers or your production network. We set up our own private network at the venue. We also put up an FAQ section for you to review.

When asked to support ROOTCON privately, my basic question was – “What makes ROOTCON different?” My discussion with the founder was a lengthy one and I guess by now you know why I’m giving my full support. We discussed about his plans, how to share that same passion to a bigger audience and change the security mindset in the country.

Being different gets you noticed and it's undeniably true. But creating value is another thing.

If we build ROOTCON around one company or one person, then it may not last – build ROOTCON around YOU and what we can offer to people who join us in any gatherings, then it will gain the credibility for all the fantastic trainings and support we can bring to everybody and your organization (and of course, you need to make sure that you do!)

To your success! Be it on personal level or career wise!

“Hackers love technology, but crackers love to break it. Which one are you?”


About the Contributor:

A self-confessed blogger minus the coffee. He maximizes his skills in consultancy, project management, professional networking, social media campaigns and very active in conceptualizing things. To date he already conducted several IT / Information Security events as his passion since 2007. Currently he's working as a Technical Support Specialist in a local company.


ROOTCON is managed by like minded InfoSec professionals across the Philippines.
All rights reserved. Designated trademarks, brands and articles are the property of their respective owners.

Read More