Saturday, August 16, 2008

Defcon 16

It was a pleasure seeing several of you at Defcon this year. I ran into Steven Adair from Shadowserver and Brian Krebs from Washington Post. They get honorable mention because both promised me a beer, and never paid up - guess I'll have to collect next year with interest. :) In all seriousness, it was great to see old friends and make new ones.

I'd like to extend a special thanks to StillSecure and IOActive for hosting a wonderful party on Saturday Night.

A few new tools were released at Defcon this year. Among my favorites are Grendel Scan and The Middler.

Grendel-Scan is an open-source web application security testing tool. It has automated testing module for detecting common web application vulnerabilities, and features geared at aiding manual penetration tests.

Grendel was written by a fellow penetration tester, David Byrne. David's skills are exceptional and he claims to use this tool during the initial phases of a penetration test. I was granted an early release of this tool, which I used on several recent vulnerability assessments, and I was thrilled with the results. While its not yet perfect, it certainly makes my job much easier, and identifies points of weakness that I can focus my attacks on. Since the scans can be throttled, the tool is perfect for use in production and development environments alike.

The Middler was written by Jay Beale with help from his friends at Intelguardians. The Middler allows an attacker with no web application hacking experience to launch attacks that previously required substantial time and skill. The Middler is still pending official release, but Jay promised in his talk to release it as soon as he fixed one critical bug.

These two tools serve very different purposes. Jay's tool is focused more on exploitation and attacks. David's tool is a weakness identification aid, and does not make any attempt to compromise a host. Both tools look promising and should be added to your toolbox.

This is my fourth Defcon. I'd like to challenge the presenters to step it up a notch. Several presentations this year were recycled from previous years.

Labels: , , ,

Thursday, July 12, 2007

DISOG at Defcon -- its raining storm emails.

DISOG will be present at Defcon 15 in Las Vegas August 2nd through August 5th.
At least three people from DISOG will be there. We are trying to get our colleges from Shadowserver to join us as well.
We are not presenting this year, but will be happy to answer any botnet questions behind closed doors.
If you'll be there and would like to meet up with us, please send me an email!

--

The storm worm is gathering power for its next round of spam. Just a quick reminder not to click on links in email. I recently cleaned the system of a neighbor who had over 100 pieces of malicious code on her system, all related to Storm. She knew the computer was infected, because the code made her system so unstable it would crash after running for 30 seconds.
Prepare for another wild round soon!

Labels: , , , ,