UPDATE: The source repository for all this code is hosted here: https://github.com/antitree/bsidesroc2017ctf
Check out the previous 1, 2, 3 and 4 for the other CTF challenges.
Rebound Attack I admit this this was the …
Check out the previous 1, 2, and 3 for the other CTF challenges.
Hop Till You Drop The original plan for this one was to show how you can setup an exit node to allow single hop circuits – in other words, you …
This is a continuation of the previous posts talking about BSidesROC onion related CTF challenges.
Port of Onion (PoO) I don’t think anyone got this one mostly because I think they were expecting that it was going …
This is a continuation of the previous post talking about BSidesROC onion related CTF challenges.
Double Ontonion One team figured this one out. The point of this challenge is to exemplify a common problem with onion …
Now that BSidesROC is over and the CTF is closed, I can share some of the details about the Onions CTF category that I made. I think the feedback was that a lot of the challenges were too hard or they were …
Our little hacker conference that usually draws about 400 people is happening again on 4-21 and 4-22. If you want the song and dance about all the things we have planned, you can check out the website. I want to cover …
It’s another year of BSidesROC, a local hacker con that we put together. Our sixth year actually. Not everyone really cares about how BSidesROC has changed over the years but it’s hard not to at least mention them for …
This post on hackernews got my attention. It’s a IoT based visualization showing your activities and health metrics. It’s very flashy and interesting looking, like you’re going to see it in an episode of CSI Cyber. The …
I don’t remember the exact conversation, but Jason Ross inspired me to buy DRWND.com, as in Drone + PWND = DRWND. I’ve owned it for a bit waiting for some specific data so that I could use it as an informational site …
BSidesROC is over. I thought it might be interesting to give a behind-the-scenes look at some of the stuff that makes BSidesROC run.
OPs We have “Ops”. A few years ago we decided to try to organize BSides like an IRC …
Rochester’s version of a Security B-Sides is coming up next week. There’s a rush to finalize everything and there might be a question about this new event I’ve referenced as “Privacy Workshop”, “OPSEC Training”, or just …
For a few years now, I’ve been stating my plans for the rest of the year, and reviewing how the previous year went. Here’s the review:
Last Year Major Con Presentation One of my goals was to be accepted into a “Major …
Halloween time again. Last year I tried to do a simple little hardware project to make my emoticon pumpkins glow. That’s cute and all but not very difficult.
This year, I decided to work on this idea I’ve had for more …
These links are meant to go along with my recent OSINT presentation. They’re provided to get you started if you wanted to start learning the craft.
Meta Giant list of OSINT tools and methodology Iron Geek’s OSINT class …
This Friday, I’ll be presenting a weird presentation at BSides Detroit. It’s titled “Corporate Intelligence: Lisbeth Salandar vs James Bond” and it’s on a subject that has been stuck in my head for a while. It’s a talk …
Another year, another ISTS. For those that haven’t heard the Information Security Talent Search (ISTS) is a yearly event run by RIT’s SPARSA group — a student run organization. This isn’t your run-of-the-mill hacking …
This is a presentation I gave about embedded security at the last 2600 meeting. This mostly just referencing other people’s work like Joe Grand and Travis Goodspeed who are embedded security gods.
Pentesting embedded …
I’ve been putting some time into trying to improve my intelligence gathering capabilities. Normally we would call this recon during a pen test or OSINT gathering. But I’ve been thinking about it from the perspective of …
Quick blog post — thought it would be funny to make an Instagram script that will download all the locations of a user account. You can find the details on how to use it on Github. Pretty straightforward:
./instagram.py …
Last year, I wrote a post outlining some of my focus points for the rest of the year. This is a review of those tasks and an updated perspective for the next year.
Last Year Hardware Security Projects Last year, I …
Spicy Mango is a project that Chris Centore started and presented on at Derbycon this year. It’s difficult to describe completely but in essence, it is an intelligence collection and analysis engine that helps you parse …
BSidesROC is over. There’s no reason to really give you a blow by blow but I think it might be entertaining to see some of the feedback we received from attendees. Both years that we’ve done BSidesROC we’ve sent out a …
BSidesROC is this Saturday at 8am. Holy crap. I wanted to give a final post before the con so you can figure out what to expect the day of the event. If you haven’t signed up, you should get a ticket right now. Do so on …
There’s only a few days left for this years BSidesROC on 5/12/12. “Rochester’s first and only hacker con”. « Do you know why we say that? Not because we’re the only computer security conference, and not because we …
The first official meeting of the Rochester TOOOL chapter happened this last Thursday. Jason Ross, the organizer of the group, you may have met at 2600 meetings, BSidesROC, seen present at BlackHat, or whatever infosec …
Here is a brain dump of what happened this weekend at ISTS 9, SPARSA’s Information Security and Talent Search. A bunch of the people from 2600, Raphael Mudge, Punkrokk, Joe, Gerry, and others were part of the Red Team. …
Every month we do the 2600 meetings. Lately I send out this ridiculous email to my circles and social networks explaining a theme of the meeting. It looks something like the one I did for January:
Only 12 months away …
This is just an update that will 1) fill the home page with something and 2) to mark down some of this years plans.
At the annual Interlock meeting, I presented a list of things that I’d like to work on at the space this …