<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet type="text/css" href="/css/feed.css"?>
<rss xmlns:googleplay="http://www.google.com/schemas/play-podcasts/1.0" xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd" version="2.0">
<channel>
<title>DEFCON 17 [Slides] Speeches from the Hacker Convention.</title>
<link>//podcastplus.net/feed/defcon-17-slides-speeches-from-the-hacker-convention~9da06a09</link>
<description>Past speeches and talks from DEF CON hacking conferences in an iTunes friendly M4v format. The DEFCON series of hacking conferences were started in 1993 to focus on both the technical and social trends in hacking, and has grown to be world known event. Video, audio and supporting materials from past conferences will be posted here, starting with the newest and working our way back to the oldest with new content added as available!</description>
<pubDate>Fri, 18 Sep 2026 11:13:18 +0000</pubDate>
<item>
<title>Tony Flick - Hacking the Smart Grid - Slides</title>
<link>https://media.defcon.org/dc-17/video/DEFCON%2017%20Hacking%20Conference%20Presentation%20By%20Tony%20Flick%20-%20Hacking%20the%20Smart%20Grid%20-%20Slides.m4v</link>
<description>Hacking the Smart Grid  Tony Flick   The city of Miami and several commercial partners plan to rollout a "smart grid" citywide electrical infrastructure by the year 2011. This rollout proceeds on the heels of news that foreign agents have infiltrated our existing electrical infrastructure and that recent penetration tests have uncovered numerous vulnerabilities in the proposed technologies. Simultaneously, the National Institute for Standards in Technology (NIST) has recently released a roadmap for producing Smart Grid standards. In this Turbo Talk, I will discuss the flaws with the current guidelines and map them to the criticisms of similar regulatory mandates, including the Payment Card Industry Data Security Standard (PCI DSS), that rely heavily on organizations policing themselves.   Tony Flick has been working in the Information Security field for more than 6 years. As a security consultant, Mr. Flick has assisted numerous organizations in achieving compliance with federal regulations and industry stand...</description>
<pubDate>Thu, 19 Nov 2009 22:12:07 +0000</pubDate>
<guid>https://media.defcon.org/dc-17/video/DEFCON%2017%20Hacking%20Conference%20Presentation%20By%20Tony%20Flick%20-%20Hacking%20the%20Smart%20Grid%20-%20Slides.m4v</guid>
<enclosure url="https://media.defcon.org/dc-17/video/DEFCON%2017%20Hacking%20Conference%20Presentation%20By%20Tony%20Flick%20-%20Hacking%20the%20Smart%20Grid%20-%20Slides.m4v" type="audio/mpeg" length="1"/>
</item>
<item>
<title>Pedro hkm Joaquin - Attacks Against 2wire Residential Gateway Routers - Slides</title>
<link>https://media.defcon.org/dc-17/video/DEFCON%2017%20Hacking%20Conference%20Presentation%20By%20Pedro%20hkm%20Joaquini%20-%20Attacks%20Against%202wire%20Residential%20Gateway%20Routers%20-%20Slides.m4v</link>
<description>Attacks Against 2wire Residential Gateways  Pedro "hkm" Joaquin   Some time ago there was a vulnerability in 2wire residential routers that allowed DNS Poisoning via Cross Site Request Forgery, this was widely exploited in Mexico where this router is most commonly used.   The patch actually contained an Authentication Bypass vulnerability that made things worse, and now, after the patch got patched, there are still many public unpatched vulnerabilities that plague this device.   Pedro "hkm" Joaquin was born in Cozumel island in the Caribbean, currently he is an independent security researcher living in Mexico City. Pedro used to be a forensic investigator, malware analyst and antimalware software vendor for banks in Mexico.   8 years ago Pedro created a community called "Mexican Underground Community" (underground.org.mx) which focuses on hacking and phreaking, They are the largest hacking community in Mexico and have done many public and private meetings all over Mexico including some 2600 ones.   Over the p...</description>
<pubDate>Thu, 19 Nov 2009 22:11:52 +0000</pubDate>
<guid>https://media.defcon.org/dc-17/video/DEFCON%2017%20Hacking%20Conference%20Presentation%20By%20Pedro%20hkm%20Joaquini%20-%20Attacks%20Against%202wire%20Residential%20Gateway%20Routers%20-%20Slides.m4v</guid>
<enclosure url="https://media.defcon.org/dc-17/video/DEFCON%2017%20Hacking%20Conference%20Presentation%20By%20Pedro%20hkm%20Joaquini%20-%20Attacks%20Against%202wire%20Residential%20Gateway%20Routers%20-%20Slides.m4v" type="audio/mpeg" length="1"/>
</item>
<item>
<title>Nicholas Percoco and Jibran Ilyas - Malware Freak Show - Slides</title>
<link>https://media.defcon.org/dc-17/video/DEFCON%2017%20Hacking%20Conference%20Presentation%20By%20Nicholas%20Percoco%20and%20Jibran%20Ilyas%20-%20Malware%20Freak%20Show%20-Slides.m4v</link>
<description>Malware Freak Show  Nicholas J. Percoco Vice President of SpiderLabs, Trustwave  Jibran Ilyas Senior Forensic Investigator, SpiderLabs, Trustwave   We see a lot of compromised environments every year. In 2008 alone, we performed full forensic investigations on over 150 different environments ranging from financial institutions, hotels, restaurants and even some casinos not too far from DEFCON. This presentation will show the inner workings of three very interesting pieces of malware, ranging from somewhat simple to very complex. Each sample was actually used to steal confidential data that resulted in significant fraud and business loss for the organizations we found them at. Many of the pieces of malware we have been running across are very advanced pieces of software written by very skilled developers. The complexity in their propagation, control channels, and data exporting properties will be very interesting to anyone interested in this topic.   Nicholas J. Percoco is the head of SpiderLabs -- the advance...</description>
<pubDate>Thu, 19 Nov 2009 22:06:24 +0000</pubDate>
<guid>https://media.defcon.org/dc-17/video/DEFCON%2017%20Hacking%20Conference%20Presentation%20By%20Nicholas%20Percoco%20and%20Jibran%20Ilyas%20-%20Malware%20Freak%20Show%20-Slides.m4v</guid>
<enclosure url="https://media.defcon.org/dc-17/video/DEFCON%2017%20Hacking%20Conference%20Presentation%20By%20Nicholas%20Percoco%20and%20Jibran%20Ilyas%20-%20Malware%20Freak%20Show%20-Slides.m4v" type="audio/mpeg" length="1"/>
</item>
<item>
<title>Matt Richard and Steven Adair - 0-day gh0stnet and the Inside Story of the Adobe JBIG2 Vulnerability - Slides</title>
<link>https://media.defcon.org/dc-17/video/DEFCON%2017%20Hacking%20Conference%20Presentation%20By%20Matt%20Richard%20and%20Steven%20Adair%20-%200-day%20gh0stnet%20and%20the%20Inside%20Story%20of%20the%20Adobe%20JBIG2%20Vulnerability%20-%20%20Slides.m4v</link>
<description>0-day, gh0stnet and the inside story of the Adobe JBIG2 vulnerability  Matt Richard Malicious Code Researcher, Raytheon  Steven Adair Researcher, Shadowserver   This talk is the story of 0-day PDF attacks, the now famous gh0stnet ring and the disclosure debacle of the Adobe JBIG2 vulnerability in January and February 2009. This is the story of international cyber-espionage using 0-days and the fierce debate over how to defend networks in the face of prolonged periods of exposure to unpatched vulnerabilities.   We seek to answer the following questions in this talk:   * Who was behind the early 0-day attacks and are they the same as the gh0stnet report published in April 2009?  * Did disclosure of the Adobe JBIG2 vulnerability have an impact on targeted attacks?  * How effective were post-disclosure protections such as AV signatures, IDS signatures and workarounds?   Throughout the talk we dissect the 0-day artifacts and other events leading up to the partial disclosure of the JBIG2 vulnerability on February 1...</description>
<pubDate>Thu, 19 Nov 2009 22:00:25 +0000</pubDate>
<guid>https://media.defcon.org/dc-17/video/DEFCON%2017%20Hacking%20Conference%20Presentation%20By%20Matt%20Richard%20and%20Steven%20Adair%20-%200-day%20gh0stnet%20and%20the%20Inside%20Story%20of%20the%20Adobe%20JBIG2%20Vulnerability%20-%20%20Slides.m4v</guid>
<enclosure url="https://media.defcon.org/dc-17/video/DEFCON%2017%20Hacking%20Conference%20Presentation%20By%20Matt%20Richard%20and%20Steven%20Adair%20-%200-day%20gh0stnet%20and%20the%20Inside%20Story%20of%20the%20Adobe%20JBIG2%20Vulnerability%20-%20%20Slides.m4v" type="audio/mpeg" length="1"/>
</item>
<item>
<title>Joey Calca and Ryan Anguiano - Hadoop Apaches Open Source Implementation of Googles MapReduce Framework- Slides</title>
<link>https://media.defcon.org/dc-17/video/DEFCON%2017%20Hacking%20Conference%20Presentation%20By%20Joey%20Calca%20and%20Ryan%20Anguiano%20-%20Hadoop%20Apaches%20Open%20Source%20Implementation%20of%20Googles%20MapReduce%20Framework-%20%20Slides.m4v</link>
<description>Hadoop: Apache's Open Source Implementation of Google's MapReduce Framework  Joey Calca Hacked Existence Team  Ryan Anguiano Hacked Existence Team   This presentation will begin with a brief overview of Google's Map/Reduce Framework. Map/Reduce is built to analyze extremely large datasets. We will first look at what a Mapper and Reducer are, the inputs they take and the outputs they generate. From there, we will look at the open source java based implementation of the Map/Reduce Framework by the Apache Team's Hadoop Project. Since Hadoop is Java based, we will then look at using the Hadoop framework in order to build Mappers and Reducers in Python, as well as running Mappers written in the AWK scripting language. A brief comparison of compile times and efficiencies between the three will be shown, as well as the results from running our code on ASU's Saguaro Cluster. After that, we will brush over HBase, the Hadoop equivalent to Google's BigTable, a non-relational database for Map/Reduce. Finally, we will loo...</description>
<pubDate>Thu, 19 Nov 2009 22:00:15 +0000</pubDate>
<guid>https://media.defcon.org/dc-17/video/DEFCON%2017%20Hacking%20Conference%20Presentation%20By%20Joey%20Calca%20and%20Ryan%20Anguiano%20-%20Hadoop%20Apaches%20Open%20Source%20Implementation%20of%20Googles%20MapReduce%20Framework-%20%20Slides.m4v</guid>
<enclosure url="https://media.defcon.org/dc-17/video/DEFCON%2017%20Hacking%20Conference%20Presentation%20By%20Joey%20Calca%20and%20Ryan%20Anguiano%20-%20Hadoop%20Apaches%20Open%20Source%20Implementation%20of%20Googles%20MapReduce%20Framework-%20%20Slides.m4v" type="audio/mpeg" length="1"/>
</item>
<item>
<title>Edward Zaborowski - Doppleganger The Webs Evil Twin - Slides</title>
<link>https://media.defcon.org/dc-17/video/DEFCON%2017%20Hacking%20Conference%20Presentation%20By%20Edward%20Zaborowski%20-%20Doppleganger%20The%20Webs%20Evil%20Twin%20-%20Slides.m4v</link>
<description>Doppelganger: The Web's Evil Twin  Edward Zaborowski Senior Security Engineer, Apptis   Users and administrators alike surf the web assuming that, for the most part, what they are looking at is what the website served to their browser; however, an attacker can deploy a malicious proxy, altering responses and requests, as well as potentially stealing sensitive data, all without a user being aware.   In this presentation I will discuss some of the attacks that a hacker can use when deploying a malicious proxy. Additionally, I will discuss Doppelganger, a tool that I've written to expedite some of the discussed techniques, its current capabilities, future additions, and more.   Edward Zaborowski started working in the computer security field when he enlisted in the US Air Force. During his enlistment he had the opportunity to help provide a wide array of security services such as intrusion detection, penetration testing, and incident response. He separated from the USAF in 2001 to continue his career in computer...</description>
<pubDate>Thu, 19 Nov 2009 21:47:14 +0000</pubDate>
<guid>https://media.defcon.org/dc-17/video/DEFCON%2017%20Hacking%20Conference%20Presentation%20By%20Edward%20Zaborowski%20-%20Doppleganger%20The%20Webs%20Evil%20Twin%20-%20Slides.m4v</guid>
<enclosure url="https://media.defcon.org/dc-17/video/DEFCON%2017%20Hacking%20Conference%20Presentation%20By%20Edward%20Zaborowski%20-%20Doppleganger%20The%20Webs%20Evil%20Twin%20-%20Slides.m4v" type="audio/mpeg" length="1"/>
</item>
<item>
<title>Danny Quist and Lorie Liebrock - Reverse Engineering by Crayon - Slides</title>
<link>https://media.defcon.org/dc-17/video/DEFCON%2017%20Hacking%20Conference%20Presentation%20By%20Danny%20Quist%20and%20Lorie%20Liebrock%20-%20Reverse%20Engineering%20by%20Crayon%20-%20Slides.m4v</link>
<description>Reverse Engineering By Crayon: Game Changing Hypervisor Based Malware Analysis and Visualization  Danny Quist CEO, Offensive Computing  Lorie M. Liebrock New Mexico Tech Computer Science Department   Recent advances in hypervisor based application profilers have changed the game of reverse engineering. These powerful tools have made it orders of magnitude easier to reverse engineer and enabled the next generation of analysis techniques. We will also present and release our tool VERA, which is an advanced code visualization and profiling tool that integrates with the Ether Xen extensions. VERA allows for high-level program monitoring, as well as low-level code analysis. Using VERA, we'll show how easy the process of unpacking armored code is, as well as identifying relevant and interesting portions of executables. VERA integrates with IDA Pro easily and helps you to annotate the executable before looking at a single assembly instruction. Initial testing with inexperienced reversers has shown that this tool pro...</description>
<pubDate>Thu, 19 Nov 2009 21:45:57 +0000</pubDate>
<guid>https://media.defcon.org/dc-17/video/DEFCON%2017%20Hacking%20Conference%20Presentation%20By%20Danny%20Quist%20and%20Lorie%20Liebrock%20-%20Reverse%20Engineering%20by%20Crayon%20-%20Slides.m4v</guid>
<enclosure url="https://media.defcon.org/dc-17/video/DEFCON%2017%20Hacking%20Conference%20Presentation%20By%20Danny%20Quist%20and%20Lorie%20Liebrock%20-%20Reverse%20Engineering%20by%20Crayon%20-%20Slides.m4v" type="audio/mpeg" length="1"/>
</item>
<item>
<title>Dan Kaminsky - Something about Network Security - Slides</title>
<link>https://media.defcon.org/dc-17/video/DEFCON%2017%20Hacking%20Conference%20Presentation%20By%20Dan%20Kaminsky%20-%20Something%20about%20Network%20Security%20-%20Slides.m4v</link>
<description>Something about Network Security  Dan Kaminsky IOActive    Dan Kaminsky is the Director of Penetration Testing for Seattle-based IOActive, where he is greatly enjoying having minions. Formerly of Cisco and Avaya, Dan was most recently one of the "Blue Hat Hackers" tasked with auditing Microsoft's Vista client and Windows Server 2008 operating systems. He specializes in absurdly large scale network sweeps, strange packet tricks, and design bugs.</description>
<pubDate>Thu, 19 Nov 2009 21:45:35 +0000</pubDate>
<guid>https://media.defcon.org/dc-17/video/DEFCON%2017%20Hacking%20Conference%20Presentation%20By%20Dan%20Kaminsky%20-%20Something%20about%20Network%20Security%20-%20Slides.m4v</guid>
<enclosure url="https://media.defcon.org/dc-17/video/DEFCON%2017%20Hacking%20Conference%20Presentation%20By%20Dan%20Kaminsky%20-%20Something%20about%20Network%20Security%20-%20Slides.m4v" type="audio/mpeg" length="1"/>
</item>
<item>
<title>Antony Rucci - Protecting Against and Investigating Insider Threats A Methodical Multi-Pronged Approach to Protecting Your Organization - Slides</title>
<link>https://media.defcon.org/dc-17/video/DEFCON%2017%20Hacking%20Conference%20Presentation%20By%20Antony%20Rucci%20-%20Protecting%20and%20Investigating%20Insider%20Threats%20A%20Methodical%20Multi-Pronged%20Approach%20to%20Protecting%20Your%20Organization%20-%20Slides.m4v</link>
<description>Protecting Against and Investigating Insider Threats (A methodical, multi-pronged approach to protecting your organization)  Antonio "Tony" Rucci Program Director, Technical Intelligence and Security Programs, Oak Ridge National Laboratory   This presentation will focus on indicators of insider threats and how to detect them. I’ll primarily focus on specific hiring practices to minimize risk to your organization. We’ll take a deep dive look into open source searches you should be doing on the internet that may expose someone who could potentially be a liability to you and your company. I’ll talk about the importance of security awareness training and education to thwart opportunistic individuals. And Finally, we’ll wrap things up with some interesting, relevant case studies that illustrate the key indicators and what their status is today.   Antonio "Tony" Rucci With more than 25 years of counterintelligence and security experience, Tony Rucci currently serves as the Program Director, Technical Intell...</description>
<pubDate>Thu, 19 Nov 2009 21:44:51 +0000</pubDate>
<guid>https://media.defcon.org/dc-17/video/DEFCON%2017%20Hacking%20Conference%20Presentation%20By%20Antony%20Rucci%20-%20Protecting%20and%20Investigating%20Insider%20Threats%20A%20Methodical%20Multi-Pronged%20Approach%20to%20Protecting%20Your%20Organization%20-%20Slides.m4v</guid>
<enclosure url="https://media.defcon.org/dc-17/video/DEFCON%2017%20Hacking%20Conference%20Presentation%20By%20Antony%20Rucci%20-%20Protecting%20and%20Investigating%20Insider%20Threats%20A%20Methodical%20Multi-Pronged%20Approach%20to%20Protecting%20Your%20Organization%20-%20Slides.m4v" type="audio/mpeg" length="1"/>
</item>
<item>
<title>Antione Gademer and Corentin Cheron - Low cost Spying Quadrotor for Global Security Applications - Slides</title>
<link>https://media.defcon.org/dc-17/video/DEFCON%2017%20Hacking%20Conference%20Presentation%20By%20Antione%20Gademer%20and%20Corentin%20Cheron%20-%20Low%20cost%20Spying%20Quadrotor%20for%20Global%20Security%20Applications%20-%20Slides.m4v</link>
<description>A Low Cost Spying Quadrotor for Global security Applications Using Hacked Commercial Digital Camera  Antoine Gademer  Corentin Chéron   Accessing centimetric georeferenced images is crucial for local military or civil intelligence, reconnaissance and surveillance applications. When classical satellite or aerial imagery is not available the Unmanned Aircraft Systems (UAS) are often a very interesting solution. But having an operational UAS for spying operations implies to solve the following practical problems:   * design and realize a reliable flying micro-UAS  * develop efficient tools for real-time navigation to ensure that the UAS will cover all target points  * merging all trajectory data for real-time georeferencing of high resolution imagery  * design appropriate software for optimal data exploitation   We present in this article our practical solutions to these different points.   The first section starts by presenting our Vertical Take Off and Landing quadrotor solution. This quadrotor is highly mane...</description>
<pubDate>Thu, 19 Nov 2009 21:42:23 +0000</pubDate>
<guid>https://media.defcon.org/dc-17/video/DEFCON%2017%20Hacking%20Conference%20Presentation%20By%20Antione%20Gademer%20and%20Corentin%20Cheron%20-%20Low%20cost%20Spying%20Quadrotor%20for%20Global%20Security%20Applications%20-%20Slides.m4v</guid>
<enclosure url="https://media.defcon.org/dc-17/video/DEFCON%2017%20Hacking%20Conference%20Presentation%20By%20Antione%20Gademer%20and%20Corentin%20Cheron%20-%20Low%20cost%20Spying%20Quadrotor%20for%20Global%20Security%20Applications%20-%20Slides.m4v" type="audio/mpeg" length="1"/>
</item>
</channel>
</rss>
