Pre-DEFCON 17 News

DefCon 17 is in startup mode. Here’s the low-down:

They are out of badges and are issuing temp badges. Why does this happen EVERY year?

EDIT: More badges at 11AM tomorrow. Keep your temp badge! You’ll need it!

The swag store has a new system where you give your order to a goon and you’re given a number. After 15 mins or so your number is called and you can buy your swag.

I’ve been dodging in and out of the pre-talks. The intro to lockpicking is very cool - DefCon 1

Live Blog: Blackhat 2009 Day 2

Day 2 of BlackHat is here, and another early morning. *yawn* *rubs eyes*

Keynote was given by DoD CSO Robert Lenz.

===CHIEF IS IN: ATTACKING SMS ===

Demoing attack in SMS. Sending a message as a trusted carrier number (like 611). Nice impersonation attack - shows SMS message asking victim to enter credentials into an evil web page. Interested in the code behind this.

Going over three different attacks: implementatino, configuration and architecture.

Dealing with SMS in the G

Live Blog: BlackHat 2009 Day 1

An early good morning *yawn*

If I’ve learned one thing by attending so many BlackHats, it’s that the key to just about everything is be there early. Those rooms fill up fast.

I began my day with a visit to the Payard coffee shop for some real coffee and a very small breakfast. After scarfing that down, I quickly located the keynote address and found a seat with a panoramic view.

The brochure has the speaker listed as “TBA”. Who could it be? Hmmmm…

Follow me on twitter! See p

BlackHat / DefCon Secure Communication Tip

Here’s some early feedback for the folks connecting to wireless networks around BlackHat (and soon to be at DefCon).

Y’all aren’t taking this whole secure-communications thing too seriously.

Clear-text POP3/IMAP e-mail credentials are getting plucked out of the air by *cough* individuals *cough*. Some of these are coming from phones that folks are configuring to use the wireless LANs. Not a good idea.

Easy PRO-TIPS:

1) Don’t use the wireless networks. Go cellular if possible.

Live Blog: Day Before BlackHat 2009

It is time.

It is time for me to begin my trip to Mecca. To climb into a plane, and venture to the arid lands of Las Vegas for BlackHat 2009 and DefCon 17!

I’m going to attempt to live blog just about everything I do these next 5 days thanks to the portability of my lastest field toy: Dell Mini 10v, running a *cough* customized *cough* version of Ubuntu 9 Linux. I say customized because it resembles nothing of a default install. It’s packed with docs, tools, and mindless entertainment.