Thursday, July 30, 2015

ROOTCON officially launches ROOTCON Campus Tour


import rootcon
rootcon.print("Hello University Students!")

Ahem! Yes, ROOTCON in partnership with with De La Salle University - College of Computer Studies officially launches ROOTCON Campus Tour and the great thing about this event is that it is 100% Free.



ROOTCON Campus Tour is the first ever inter-university Capture the Flag (CTF) and infosec gathering for university students that aims to bring the ambience of the premier hacking conference in the Philippines, ROOTCON. The event is 100% FREE and covers topics like Information Security 101, Information Security Career 101, Introduction to Hacking, Exploit Development, Malware Analysis, Debugging, etc. 

The Capture the Flag event is the main highlight of this event wherein the champion could secure a FREE pass to ROOTCON 9. 

ROOTCON Campus Tour's CTF is not your ordinary hackathon or codefest because it is really an inter-university hacker cup that has intermediate to advance challenges like reverse engineering, return oriented programming, packet sniffing, debugging, web exploits, and many more to mention. 

ROOTCON Campus Tour wouldn't be a reality without the help of Isaac Sabas of Pandora Security Labs and De La Salle University - College of Computer Studies. Thank you for the help and we totally salute you guys!

You don't wanna miss this event! Stay tuned for more updates @ http://campustour.rootcon.net/
Read More

Saturday, July 25, 2015

ROOTCON 9 Speakers Lineup: Yes 1337 Speakers Are Here

Still doubtful that we are the premier hacking conference in the Philippines? Then check out our awesome lineup of speakers plus the 1337ness:











Carlos Tingson

Carlos Tingson is currently a student pursuing an MSc in Information Security here at the Information Security Group, Royal Holloway University of London under a British Chevening Scholarship. He specialized in Cyber Security and Cyber Crime. Carlos Tingson is an Army Captain by profession, his latest assignment is with the Presidential Security Group, based in Malacanang Park, Manila. he previously served with the Army's Special Operations Command and the 2nd Infantry Division. He graduated from the Philippine Military Academy with a degree in Information Systems. He also hold a Postgraduate Diploma in Research and Development Management from the University of the Philippines. A Certified Ethical Hacker (v. 7), Computer Hacking Forensics Investigator (v. 8), and EC-Council Certified Security Analyst. Carlos Tingson have been a regular Rootcon attendee since RC6. Not a pirate, Not a ninja, but had his fair share of ass kicking.











Christopher Elisan

Christopher Elisan is a seasoned reverse engineer and malware researcher. He is currently the Principal Malware Scientist at RSA. He has a long history of digital threat and malware expertise, reversing, research and product development. He started his career at Trend Micro as one of the pioneers of TrendLabs. This is where he honed his skills in malware reversing. After Trend Micro, he built and established F-Secure's Asia R&D where he spearheaded multiple projects that include vulnerability discovery, web security, and mobile security. After F-Secure, he joined Damballa as their resident malware subject matter expert and reverse engineer. Aside from speaking at various conferences around the world, he frequently provides expert opinion about malware, botnets and advance persistent threats for leading industry and mainstream publications. Christopher Elisan is also a published author. He authored "Advanced Malware Analysis" and "Malware, Rootkits and Botnets." He co-authored "Hacking Exposed: Malware and Rootkits." All books are published by McGraw-Hill. 











Jason Haddix

Jason is the Director of Technical Operations at Bugcrowd. Jason trains and works with internal analysts to triage and validate hardcore vulnerabilities in mobile, web, and IoT applications/devices. He also works with Bugcrowd to improve the security industries relations with the researchers. Jason’s interests and areas of expertise include mobile penetration testing, black box web application auditing, network/infrastructural security assessments, cursory mainframe security analysis, cloud architecture reviews, wireless network assessment, binary reverse engineering, and static analysis. He is also a frequent player on the Shellphish CTF team. Jason lives in Santa Barbara with his wife and two children. 











JIM

JIM is not just one entity. As much as we want to introduce them to you guys, I'm sorry but for now they are marked as CLASSIFIED and shouldn't be disclosed yet. All we know is that ninjas p4wn teh n1gh7.











John Menerick

John works on Security at NetSuite. John’s interests include cracking clouds, modeling complex systems, developing massive software-defined infrastructures, and is the outlier in your risk model.











Jose Ramon Palanco 

Jose Ramon Palanco is currently CTO of Drainware, Inc., a security company with offices in U.S and Spain: Palo Alto (California) and Madrid. In the past he has worked at Deloitte CyberSOC, managing incidents response (Tier 3). He studied Telecommunications Engineering at the University of Alcala de Henares and Master of IT Governance at the University of Deusto. He has been speaker at OWASP, ROOTEDCON and MALCON. 











Lu Zhao

Lu Zhao got his Ph.D. in Computer Science with specialties in trusted computing, abstract interpretation, formal verification and program logic. He worked in designing and developing static analyzers for security at HP Fortify for three years, during which he gave talks about analyzing programs to find vulnerabilities in conferences and filed two patents in the security analysis area. He is now a principal application security engineer at NetSuite Inc. His primary job is building security features for NetSuite cloud services including securing data accesses, eliminating vulnerabilities, and preventing attacks. He also works on security reviews and automated security testing. He has a wide range of interests in computing, including security, programming languages, abstract interpretation, program analysis, formal verification, and automated constraint solving. 











Markku Kero

Currently Markku Kero is the CEO of Eqela and Job and Esther Technologies. He also serves as Chief Software Architect for both companies. Over the last 15 years, Markku has been the driving force behind some of the most compelling technologies that have consistently been ahead of their time, overseeing the implementation of a 2G-compatible mobile voice over IP technology implementation, a mobile messaging system unifying email, SMS and instant messaging, a multi-device operating system and now automated programming language translation technology. He has founded and managed several companies in this field, previously Inceptions, Inc. and Kolipri Communications, currently Job and Esther Technologies and Eqela. 











Mon Nunez

Mon has more than more than 14 years experience in network management and security, specializing in computer security, large-scale network deployment, system administration, and network forensics. He has been a consultant to international organizations such as WHO and NEC, is the Co-Head Security Architect of DOST-ICTO for the Integrated Government Project (iGov), the Network Infrastructure and Security Consultant of the UP Computer Center, and is currently the Director for Security at Chikka Philippines. 

A member of Team Manila, Mon, with Paul Prantilla, has competed in the DEFCON 22 in Las Vegas this 2014. The team participated in multiple contests achieving 4th out of 264 teams for the Network Forensics Puzzle Contest (NFPC), and also 4th at the Capture the Packet Contest (CTP) championship round. They also competed in the 2014 Capture The Flag contest at Hack In The Box, Kuala Lumpur -- making them the first and only team from the Philippines to ever compete in an international CTF event. 

As an advocate for continuous learning, Mon got his Masters Degree in Computer Science from UP Diliman and is now taking up his PhD in Computer Science in the same university, researching on hypervisor security and software defined networks. Believing in the importance of knowledge sharing, he teaches Network Security to graduate students in UP. 











Paul Prantilla

Paul Prantilla got his masters in Computer Science from UPLB and currently is working on his PhD on Computer Security in UP Diliman. After a brief stint teaching graduate school, Paul became the first IT Director of UPLB, worked in the United Nations Population fund, and then in Chikka Philippines. While in Chikka, Paul worked with Mon Nunez to launch groundbreaking IT services in Smart - including Smart PowerApp and Internet for All. During this time, they became regular attendees of DEFCON and consistently attained a top 4 finish in multiple DEFCON contests. Currently, Paul works as the Director of Planning and Strategic Roadmapping in Globe's IT Division. 











Paul Sabanal

Paul Sabanal is a Security Researcher on IBM Security's X-Force Advanced Research Team. He has more than a decade of experience in the Information Security industry, mainly focusing on reverse engineering and vulnerability research. He has previously presented at several conferences such as Blackhat and Hack In The Box, primarily on the topics of reverse engineering, sandbox vulnerabilities, and mobile security. His main research interests these days are in protection technologies, mobile malware, and IoT security. When not in front of a computer, he enjoys Disney movie nights with his daughter, playing weird instruments in a band, and pajama wrestling. 











Philippe Z Lin

Philippe Lin is a staff engineer in Trend Micro. He works in data analysis, machine learning, fast prototyping and threat research. He was a BIOS engineer in Open Computing Project. Active in open source communities, he is a hobbyist of Raspberry Pi / Arduino projects and the author of Moedict-Amis, an open source dictionary of an Austronesian language. 











Ray Torres

Ray Torres is an IT Security enthusiast and practitioner. He likes to read daily updates of security-related topics and tries to maintain a white-hat mentality at all times when he sees a new CVE. *wink wink*. He graduated from the University of the Philippines Diliman and has a bachelor’s degree in Computer Science (he doesn’t like to brag but he graduated as Magna Cum Laude from the said university *wink*). Currently he is taking his postgraduate studies in the same university. He also goes to the gym 3 times a week and tries to maintain a healthy lifestyle. On his leisure time, he reads legal-thriller books by John Grisham or looks for open wifi access points (for free internet of course). 











Steve Miller

Steve Miller is an incident response professional and the Security Strategist for FireEye in Asia-Pacific and Japan. Steve has over 10 years of experience in areas such as computer forensics, communications signals analysis and intelligence program management. 

Steve's background includes work for the U.S. Army, the National Security Agency, Cornell University, the U.S. Department of State, and the U.S. Department of Homeland Security. 

As a part of FireEye's 24x7 incident response service, Steve leads security operations in APJ and also contributes to threat research and detection management. In his spare time, he rides a totally rad BMW F800GS motorcycle.

Read More

RC9 Schedule Live


ROOTCON 9 schedule now live

Day 1:

8:00 - 8:45 Registration - Check-in
8:45 - 9:00 Opening Remarks
9:00 - 9:45 How to Shot Web: Better Web Hacking in 2015 (Keynote) by: Jason Haddix
9:45 - 10:30 BackDooring Git by: John Menerick
10:00 Games Opening (Capture The Flag, Badge Hacking, WiFi Warrior)
10:30 - 11:15 How safe is my system from reverse engineering by: Markku Kero
11:15 - 12:00 Unmasking Malware by: Christopher Elisan
12:00 - 13:00 Break
13:00 - 13:45 Fixing CSRF Vulnerabilities Effectively by: Lu Zhao
13:45 - 14:30 Hacking Time by: Carlos Tingson
14:30 - 15:30 What Hacker Sees by: JIM
15:15 - 16:00 Break / SpeedTalk
16:00 - 16:45 Panel Discussion


Read More

Tuesday, July 21, 2015

Pandora Security Labs at RC9


ROOTCON would like to welcome our newest sponsor this ROOTCON 9. 

Pandora Security Labs is formed through the combined expertise of security analysts from leading IT security companies and researchers from the academe world. Our founder firmly believes that the combination of industry experience, education and continuous research is the best formula for providing innovative best quality products and services.


Visit them at https://www.pandoralabs.net/
Read More

Monday, July 20, 2015

ROOTCON 9 Sponsors: We Salute You!


ROOTCON would like to highlight and thank the sponsors for this incoming hacker conference and information security gathering:



Netsuite is an American software company based in San Mateo, California, that sells a group of software services used to manage a business's operations and customer relations. Customers access these services over the internet paying a periodic subscription fee. Netsuite | Security provides a host of advanced functionality to secure the application including role-based access, strong encryption, robust password policies and more. NetSuite adds further layers of security such as application-only access and restricting access to only certain IP addresses to provide complete confidence and peace of mind.


Rapid7's IT security solutions deliver visibility and insight that help you make informed decisions, create credible action plans, and monitor progress. They simplify compliance and risk management by uniquely combining contextual threat analysis with fast, comprehensive data collection across your users, assets, services and networks, whether on premise, mobile or cloud-based. Rapid7 has been recognized as one of the fastest growing security companies by Inc. Magazine and as a "Top Place to Work" by the Boston Globe. Rapid7 currently maintains the Metasploit Framework and other security tools.



Kaspersky Lab is an international software security group operating in almost 200 countries and territories worldwide. The company is headquartered in Moscow, Russia, with its holding company registered in the United Kingdom. Kaspersky Lab currently employs over 2,850 qualified specialists. It has 31 representative territory offices in 30 countries and its products and technologies provide service for over 300 million users and over 250,000 corporate clients worldwide. The company is specially focused on large enterprises, and small and medium-sized businesses. Kaspersky Lab offers consumer security products, such as anti-virus, anti-malware and firewall applications, in addition to security systems designed for small business, corporations and large enterprises. Corporate solutions include protection for workstations, file servers, mail servers, payment gateways, banking servers, mobile devices, and internet gateways, managed through a centralized Administration Kit. 



Hewlett Packard Fortify on Demand is part of HP Enterprise Security Products in the HP Software business, providing application security products and services for enterprise customers to assess, assure and protect enterprise software and applications from security vulnerabilities. Fortify offerings included Static Application Security Testing and Dynamic Application Security Testing products, as well as products and services to support Software Security Assurance, or repeatable and auditable secure behaviors, over the course of a software application's life cycle. 


Netpoleon Solutions Pte Ltd was established in 2000 in Singapore. It is a leading regional VAD (Value-Added Distributor) in IT Network and Security. The company serves  a wide range of industries and customers across Singapore, Philippines, Malaysia, Thailand, Indonesia and Vietnam, , spearheading emerging technologies and delivering future-proofed solutions built for consolidation, virtualization, big data analytics, security operations centre and cloud computing. 



iSecure Networks, Inc. is a software vendor company whose strength revolves around selling, marketing and implementation of thoroughbred IT products, coupled with the ability to support and adapt to the constant changes and advances brought about by information technology. The company provides a full suite of networking and security products that gives leverage to companies, big or small, to stay afloat in today's competitive business environment. It has forged alliances with the world's most recognized brands such as Astaro Corporation, Kasperlsy Labs., Aep Networks, eEye Technologies Inc., Pheenet Technologies. 




Citibank Philippines is the Philippines chapter of Citibank established in 1902. It started when when the International Banking Corporation opened its first branch in Manila. Currently, it is one of the largest commercial banks in the Philippines. Citibank has been involved with financial mergers and acquisitions. One of the largest investments in the country is the site building in Bonifacio Global City, Taguig City. 




SecurityMatters™ is the first and only security magazine in the Philippines that provides in-depth insights and helpful tips for physical and IT security, fire and life safety, protection professionals and anyone who is interested in understanding how to prevent risky situations, accidents and any form of danger. The magazine covers relevant security issues that impact the practitioners’ professional growth, social networking activities and career development. 



The Philippine Daily Inquirer was a daily newspaper founded on 9 December 1985 by publisher Eugenia Apóstol, columnist Max Solivén, together with Betty Go-Belmonte (wife of House Speaker Feliciano "Sonny" Belmonte) during the last days of the regime of the Philippine dictator, Ferdinand Marcos, becoming one of the first private newspapers to be established under the Marcos regime. It is popularly known as the Inquirer, is the most widely read broadsheet newspaper in the Philippines,with a daily circulation of 260,000 copies. It is one of the Philippines' newspapers of record. It is a member of the Asia News Network.

Want to sponsor ROOTCON? It is never to late to be part of its success. We want you to be in this exciting event.

Why sponsor? Sponsoring ROOTCON event provides you the unique opportunity to connect with the greater Info Sec community, to build brand awareness and show your company’s support of an important cause: Security Awareness.

It is definitely a WIN-WIN situation!!!

Download the sponsorship package  or visit the sponsorship section 


Read More

RC9 Promo Code


We always want everyone to come and join us, ROOTCON is giving away 10% discount from regular rate. Just type-in the promo code "hackallthethings" and get that discount!

What are you waiting for? Register now at https://www.rootcon.org/xml/rc9/register

credits to the owner of the photo

Read More

Sunday, July 19, 2015

ROOTCON Price Update

We received a lot of inquiries with regards to our price update this year.


Q: Why is there a price increase?
A: As much as we wanted to stick with the previous RC event prices we cannot, we need to adjust it according to our venue and logistics expenses 

Q: Why is the price increase high?
A: We adjusted the price according to the venue rates and logistic expenses. 

Q: Why not bring back RC event in Cebu for cheaper price?
A: We can do that, but its likely will going to increase as hotels are increasing their prices as well. 

Q: How much is RC9? early registration
A: Our price for RC9 will be P7450.00 

Q: How much is RC9 regular rate
A: Our price for RC9 regular rate is P8550.00 

Q: Is there still a group discount?
A: Yes, group discount is based on the regular rate, group price is P7700.00 

Q: Is there a student rate?
A: Yes, student rate is based on regular rate, student rate is P7500.00 

Q: How about the inclusions?
A: Our inclusions are still the same, official RC9 badge (electronic), lunch buffet, 2 day access to conference, and other swags. 

If you do the math, the expenses are still the same, if the event is in Cebu you will spend air-fare, hotel expenses, etc...etc... 

ROOTCON is dedicated to giving the best conference experience for our con-goers, the price will be worth-it compared to other infosec conferences in the country.

Read More

Wednesday, February 06, 2013

ROOTCON 7 Details

Date and Venue
The largest annual hacker conference in the country ROOTCON will celebrate its 7th year this coming September 12-14, 2013. The first day which is September 12 will be packed with workshops and training organized by our very own NexSquare Inc. followed by the con proper on September 13th and 14th.  After a considerable days of negotiating our venue to cater more attendees we came up with a verdict that we will be returning to Parklane International Hotel in Cebu City.

Activities and Workshops
This year our very own NexSquare Inc. are kind enough to organize workshop on the first day of the conference. Some of the pre-final workshops are as follows:

WiFu - Introduction to Wireless Security
Hacking 101 - Introduction to Hackery
Lockpick 101 - Introduction to LockPicking
Metasploit-Fu - Ninja training on Metasploit
Web App Security - Introduction to Web Application Penetration Testing

These workshops are introductory to trainings offered by NexSquare Inc. with a very reasonable price to CON-Goers.

We also have our pre-con activities; activities like:

WiFi Shootout
Pre-con gathering (H4xor BBQ)

Pricing
We wanted ROOTCON to stay the cheapest and yet the best hacker conference in town; we were able to maintain the price of Php2800.00 for two consecutive years; however economically our materials and logistics costs increased so in order to cover all of our expenses such us speakers airfare and accommodation, badges, swags, meals and venue we came up with a slight price increase, this is also in parallel to the price our venue is giving us. The price for this year's conference are as follows:

Early Pro Registration: Php3300.00
Early Student Registration: Php2800.00
Group of 5 Registration: Php14025 (less 15%)

Late Pro Registration: Php4300.00
Late Student Registration: Php3800.00

Stay tuned for regular updates on the following

Facebook: https://www.facebook.com/rootcon
Twitter: https://www.twitter.com/_rootcon_
Forum: http://forum.rootcon.org
Main Site: https://www.rootcon.org

We hope to see everyone at ROOTCON this year!!!!

Hackers Unite

All the best,
-semprix

Read More

Saturday, December 01, 2012

Sulit.com.ph hacking incident

Around 15:00 while upgrading the ROOTCON systems one of the ROOTCON Goons reported that there was a hacking incident on Sulit (an online buy and sell portal http://www.sulit.com.ph) the incident was claimed by ROOTCON.ORG and ANONYMOUS.


The Sulit website was replaced by the homepage of Ayosdito.ph, another classified ads portal in the country. Also, the title of the hacked page states: “ROOTCON.ORG We are anonymous. We are Legion. We do not forgive. We do not forget.” 
Sulit.com.ph temporarily shut down its site, and issued an advisory to the public via Twitter @sulit:“A relatively simple attack was made against us. We should be back online and back to normal in a few minutes. To be clear, only a 3rd-party vendor was compromised; our data, application, and servers were unaffected and are intact.”   source: http://infolikes.com/internet/sulit-com-ph-website-hacked/

The ROOTCON core group is composed of high level security professionals, we always ensure we observe proper ethics through responsible full-disclosure if given one of our members found a serious vulnerabilities on certain web application or network. The internet is a free world to live anyone can easily tag and use the name ROOTCON as part of their hacking adventure. ROOTCON is not an underground group we are a legitimate group registered under Security and Exchange Commission, we only provide neutral venue where enterprise, government and underground share best practice, latest trends and cutting edge security techonologies.

On behalf of ROOTCON and its Goons I would like to inform everyone that ROOTCON and its crew does not condone illegal activities like this and we are not part of the hacking incident that occurred. The attack was acknowledged by certain group which is NOT part of ROOTCON. This incident is another heads-up to our security professionals and system administrators to take information security seriously; its a crazy world out there.


Check out the Official Sulit Press Release


semprix (The Fork Meister)

Read More

Tuesday, July 17, 2012

RC6 Ticket Sale

Early Registration for ROOTCON 6 ended yesterday July 16, 2012 at exactly 12 midnight.

Regular rate registration is now open until August 17, 2012, since we want you to come!!! we are still giving away discounts get our group of 5 package and get 10% off.

What are you waiting for REGISTER NOW!!!!

http://rootcon6.eventbrite.com/
https://www.rootcon.org/xml/rootcon6/register


Read More

Saturday, July 14, 2012

The Secrecy (New Game)

This year we introduce to you "The Secrecy" is composed of 10 levels, each levels has a secret / hidden phrase or word that you need to find for the players to proceed to the next levels.

Let the cracking begin!!!

Game Mechanics 
The objective of this game is to reach the top-most level which is level 10. In order to achieve that you need to pass each level and get the secret / hidden phrase or word.

The Rules 
1. NO DIRECT DDoS on the game servers.
 2. NO Physical Coercion on players and crew.
 3. Spies works on their own, this is a single player game. You can however have a handler to coach you throughout the game.
 4. Spies are resourceful breaking codes, so be like one ;-)
 5. Bring your own spy gears, laptop, AP, GPS tracking, whatever you think you will need.

Who Can Play 
Any ROOTCON attendee (except for the ROOTCON Goons).

When 
Start of the conference

Prizes Shining UberH4x0r Badge, which entitles you to be put up on the ROOTCON Hall of Fame, free entrance on the next ROOTCON Conference.

Crew / Agents / Handlers 
Encrypted84 Semprix (The Fork Meister)

More details at https://www.rootcon.org/xml/rootcon6/activities#secrecy
Read More

Monday, June 11, 2012

ROOTCON 6 SpeedTalks

At ROOTCON we value everyone....CON-Goers, Sponsors and Partners. This year we are giving away our sponsors the opportunity to talk about what they do, this year we introduced "SpeedTalks". SpeedTalks is available to all major participating sponsors for ROOTCON 6.

The mechanics is pretty straight forward.

1. Avail one of the Major Sponsors of ROOTCON 6

  • Platinum
  • Gold
  • Silver
2. Sponsoring company will send a delegate for their entry on SpeedTalks.
3. Sponsoring companies are given a blazing 10 minutes for their product demo / presentation and product updates.
4. SpeedTalks will be given on Day 1 and Day 2.
5. ROOTCON will align all schedules to the sponsoring company representatives.
6. NO QUESTIONS should be entertained during the SpeedTalk, the allotted 10 minutes is purely presentation / demo / talk. All questions should be addressed on the sponsors booth.

What are you waiting for? Contact our sponsorship liaison.

-Semprix
Read More

Sunday, June 10, 2012

Checking out BackTrack Linux 5r2-PenTesting Edition Lab!


What's a BackTrack Linux 5r2-PenTesting Edition Lab? What's with the edition thingy? Isn't BackTrack 5 a pentesting distro already? Why make a pentesting edition?

Maybe these are some of the questions you have in your mind after reading the title and because of that, I would like to give some few points about this edition.

BackTrack Linux 5r2-PenTesting Edition Lab is still the same BackTrack 5 r2 with the same pentesting tools pre-installed in the distribution and has KDE as its Desktop Environment although in backtrack-linux.org you can also choose if you want Gnome or KDE. The only difference is that it includes all of the hosts, network infrastructure, tools, and targets necessary to practice penetration testing for the CPLT or Certified PenTest Laboratory course which is brought to you by PenTest Laboratory and the guys behind PenTest Magazine. 

This edition is a modified version of NETinVM which has a predefined User-mode Linux (UML) based penetration testing targets. When started, this builds an entire network of machines within the VMware virtual machine. The BackTrack Linux distribution is used to provide the tools necessary for completing the lab scenarios. Thus, It is an an all-in-one penetration testing lab environment that pre-configured with:

- A master (base) host utilizing BackTrack Linux 5r2
- A DMZ network with two hosts (targets)
- An “internal” network with one host (target)
- A pre-configured firewall

This pentesting lab is available for free to non-CPLT course students which can be downloaded here

Here are some of targets you can attack or play with:

- 10.5.0.1
- 10.5.0.254
- 10.5.1.10
- 10.5.1.254


About the Contributor:
Shipcode is a prolific blogger of ROOTCON and at the same time an InfoSec enthusiast from Cebu. He was inspired to join ROOTCON as part of the core team to share his knowledge in information security.  He encourages other like minded individuals to come forward and share their knowledge through blogging right here at ROOTCON Blog section.

ROOTCON is managed by like minded InfoSec professionals across the Philippines.  All rights reserved. Designated trademarks, brands and articles are the property of their respective owners.
Read More

Monday, June 04, 2012

8 Hacking and Information Security Magazines You Might Wanna Read

As a programming student, security researcher and a blogger; I always keep up to date about what is happening in cyber space by reading infosec articles and magazines. Magazines I usually read have niches or themes like Information Security, Cyber Warfare, Cyber Espionage, Penetration Testing and Hacking. And so here are 8 Hacking and Information Security Magazines that I like to share to all of you guys:


1. Hakin9 - Hakin9 Magazine is a payable magazine devoted to IT security and covers techniques of breaking into computer systems, defense and protection methods, tools and latest trends in IT Security. It has 4 different editions every month: Hakin9 – main issue, Hakin9 Extra – every issue is devoted to one topic only, Exploiting Software magazine – Partition Analysis, Stack Overflow and many more, and Mobile Security – hacking and securing of mobile systems and applications.



2. PenTest Magazine - PenTest Magzine is a payable magazine which focuses on Penetration Testing. It features articles by penetration testing specialists, enthusiasts, and experts in vulnerability assessment and management. The PenTest Magazine features 48 issues in a year – 4 issues in a month. Different title is published every week; PenTest Regular, Auditing & Standards PenTest, PenTest Market, and Web App Pentesting. Their team is also behind the Certified PenTest Laboratory Tester (CPLT) Certification.



3. ClubHack Magazine - ClubHack Magazine or CHmag is India's 1st Hacking Magazine and one of the media partners of ROOTCON. Their magazine is free to download and is divided into the following sections: Tech Gyan,  Legal Gyan, Tool Gyan, Mom's Guide, Matriux Vibhag, and Code Gyan. I also contributed one article to this magazine which is about Decoding ROT using the Echo and Tr Commands in your Linux Terminal. They are also the organizers of ClubHack Conference.


4. (IN)SECURE Magazine - (IN)SECURE Magazine is a free digital security publication discussing  information security topics by Help Net Security which has been a prime resource for information security news since 1998.. They also accept guest authors and has a lot of subscribers.


5. Phrack Magazine - Nothing beats the old school! Nobody messes with the Phrack Magazine which is an online ezine for hackers and by the hackers. Phrack was first released on November 17, 1985 which until now became the largest computer underground ezine. In fact, The Hacker’s Manifesto was also published in this online ezine on the 7th issue. Truly an old yet awesome archive which takes you to the old days of the hacker culture in the 80′s. The current issue is 68 and I thought it will end on issue number 63 but the good thing is it is still alive and kicking.



6. 2600: The Hacker Quarterly - 2600: The Hacker Quarterly is a publication that focuses in publishing information about subjects like phreaking, infosec, hacking, the computer underground, anarchist issues, and many more. 2600 has established the H.O.P.E. (Hackers On Planet Earth) conferences as well as monthly meetings in some countries.



7. Hacker5 - Hacker5 is a monthly magazine from India which provides you with some of the latest happenings in the Cyber world. Their team is composed of journalists and ethical hackers. Some of their magazines are free to download and some are payable. In their website, they also have a dedicated page for the hackers, security professionals and developers that they interviewed.



8. Hacker Monthly - Hacker Monthly is the print magazine edition of Hacker News which is a known social bookmarking news website and popular among programmers, SEO Specialists, Link Builders, developers, geeks and startup founders.Every month they select from the top voted articles that are bookmarked on Hacker News website and print them in magazine format but it is not for free anymore.


About the Contributor:
Shipcode is a prolific blogger of ROOTCON and at the same time an InfoSec enthusiast from Cebu. He was inspired to join ROOTCON as part of the core team to share his knowledge in information security.  He encourages other like minded individuals to come forward and share their knowledge through blogging right here at ROOTCON Blog section.

ROOTCON is managed by like minded InfoSec professionals across the Philippines.  All rights reserved. Designated trademarks, brands and articles are the property of their respective owners.
Read More

Thursday, May 31, 2012

ROOTCON 6 Call For Papers Now Close

ROOTCON 6 Call For Papers is now close, we would like to thanks everyone who submitted. For those who were not accepted you can still enjoy the fun at ROOTCON by registering, socialize, network, learn and have fun.

Pre-final tracks can be found here

Get to know our ub3r4w3s()me speakers here

We will be posting ROOTCON 6 schedule soon.

What are you waiting for? Register now (Early Registration closing on June 30, 2012) and witness the fun and educational event this coming September 7-8, 2012.

Hope to see you all at the CON.
Read More