Downloads
Downloads
Downloads Home » Presentations
DocumentsDate added
-
Blackhat Europe 2005 - Google Hackinghot!
- 01.08.2005
- Google Hacking For Penetration Testers slides from Blackhat 2005. Updated version of the Shmoocon 2005 talk. Added more examples, and a section or two. Don't download this and Shmoocon. This one's newer.
- Hits: 16323
-
2005 Shmoocon Presentation, Feb. 2005hot!
- 20.02.2005
- Google Hacking for Penetration Testers, presented on Feb 2005 at Shmoocon. This is a much newer (I think improved) version of the talk I gave at Blackhat Vegas/Japan 2004. The tail end of this presentation (credit cards/SSNs) is the only content from those earlier talks. In this presentation, I walk through several chapters of the Google Hacking book, demonstrating how Google can be used for things like network mapping, email trolling, locating network devices, and more. I highlight many entries in the GHDB, and show how to locate (and potentially abuse) firewalls, IDS systems, IP telephones, PBX systems, routers, switches, credit card databases, social security number caches, private government documents, and more! This is an 18MB pdf document, consisting of over 170 slides!
- Hits: 25110
-
Analyzing 0day Hacker Toolshot!
- 03.02.2005
- This presentation walks through the process of analyzing a never-before (publically) seen Windows backdoor/rootkit program. I show that the analysis process does not necessarily take programming skills or hardcore technical knowledge, but can be performed adequately with a handful of public tools and a decent amount of time and patience. Suited for any audience, I designed this presentation with most skill levels in mind.
- Hits: 14669
-
15 minute windows security guidehot!
- 24.06.2004
- This is a checklist for securing a Windows XP Workstation developped by Scott Granneman. I liked his checklist so much that I made it into a presentation that can be digested in about 15 minutes. In addition, I demonstrate what a hacker's attacks might look like against many of the proposed fixes. This presentation assumes no prior knowledge about Windows security.
- Hits: 22480
-
Attack/Defend 1: DCOM, WebDAV, TTYPROMPThot!
- 14.08.2003
- The first in perhaps a series of presentations which show common attacks along with detailed, annotated network traces. This gives a perspective on both sides of a network intrusion. The attacks are shown step-by-step, and the network traces are examined and explained at a high level. This zip file includes the actual ethereal log files and explains how to use filters to isolate important data from those log files. I try to remain technically agnostic in this presentation so technical and non-technical readers can benefit. This first installment of Attack-Defend looks at quiet and noisy nmap scans, a high-end vulnerability scanner (www.heatscanner.com), the Solaris TTYPROMPT telnet bypass (tool-less!), the Microsoft Webdav overflow, and the Microsoft RPC DCOM overflow (the attack used in the August 2003 LoveSan/Msblaster/DCOM worm!)
- Hits: 13568