<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	>
<channel>
	<title>Comments on: ShmooCon &#8216;08</title>
	<atom:link href="http://isisblogs.poly.edu/2008/02/18/shmoocon-08/feed/" rel="self" type="application/rss+xml" />
	<link>http://isisblogs.poly.edu/2008/02/18/shmoocon-08/</link>
	<description>Information Systems and Internet Security</description>
	<pubDate>Sat, 17 May 2008 12:12:56 +0000</pubDate>
	<generator>http://wordpress.org/?v=</generator>
		<item>
		<title>By: Dan Guido</title>
		<link>http://isisblogs.poly.edu/2008/02/18/shmoocon-08/#comment-117</link>
		<dc:creator>Dan Guido</dc:creator>
		<pubDate>Mon, 25 Feb 2008 06:00:28 +0000</pubDate>
		<guid isPermaLink="false">http://isisblogs.poly.edu/2008/02/18/shmoocon-08/#comment-117</guid>
		<description>Hey, Hope is planning their conference this year through this forum. Let's keep an eye on it.

http://talk.hope.net/</description>
		<content:encoded><![CDATA[<p>Hey, Hope is planning their conference this year through this forum. Let&#8217;s keep an eye on it.</p>
<p><a href="http://talk.hope.net/" rel="nofollow">http://talk.hope.net/</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Aleksey Fateev</title>
		<link>http://isisblogs.poly.edu/2008/02/18/shmoocon-08/#comment-103</link>
		<dc:creator>Aleksey Fateev</dc:creator>
		<pubDate>Fri, 22 Feb 2008 09:28:37 +0000</pubDate>
		<guid isPermaLink="false">http://isisblogs.poly.edu/2008/02/18/shmoocon-08/#comment-103</guid>
		<description>We should mention the Syn Phishus talk, "Unauthorized Phishing Awareness Exercise". Blog.phishme.com also mentions it, but I want to say a few more things.

Interesting details in terms of Social Engineering:
1- He setup a server on his laptop.
2- He connected to the company network using the company VPN client, so connecting was easy, but so was tracing him.
3- Wrote out an official-looking email to the security mailing list! (around 200 people)
4- The company recently had a SS theft (I believe). Syn used that as the story in his email and asked the list to sign up with the companies ID theft insurance vendor. This reminds me of Storm Worm's Tactics - use of recent events to play on people's emotions.
5- People who followed the link were displayed a box that prompted to log in using domain credentials. Whether they hit submit or cancel, they were directed to a page that explained that this was a phish and gave various advice. This was the only awareness-raising part, as the company kept the incident down, and made no mention of it at all after everything was over. 
6- Result: Syn estimates that 10% of the email recipient followed the link. Of course, there is no knowing how many people faked the credentials just to see what the server is.
7-His downfall: one of the managers was on the list and raised an alarm after an hour.

Why such a high success rate? He made it convincing - possession of the VPN client, knowledge of the security mailing list, knowledge of current events, pretext of trying to help the recipients with their troubles and good writing skills helped him pull it off.

Background:
Syn is a security contractor at some company. He is not satisfied with the security and enforcement policies in place (specifically the fact that they do not sign their email), so he provides education by phishing their credentials. He does not warn anyone. He makes it easy for IT to trace him by putting comments in html code of the phishing site and by using corporate VPN. He does not get fired.</description>
		<content:encoded><![CDATA[<p>We should mention the Syn Phishus talk, &#8220;Unauthorized Phishing Awareness Exercise&#8221;. Blog.phishme.com also mentions it, but I want to say a few more things.</p>
<p>Interesting details in terms of Social Engineering:<br />
1- He setup a server on his laptop.<br />
2- He connected to the company network using the company VPN client, so connecting was easy, but so was tracing him.<br />
3- Wrote out an official-looking email to the security mailing list! (around 200 people)<br />
4- The company recently had a SS theft (I believe). Syn used that as the story in his email and asked the list to sign up with the companies ID theft insurance vendor. This reminds me of Storm Worm&#8217;s Tactics - use of recent events to play on people&#8217;s emotions.<br />
5- People who followed the link were displayed a box that prompted to log in using domain credentials. Whether they hit submit or cancel, they were directed to a page that explained that this was a phish and gave various advice. This was the only awareness-raising part, as the company kept the incident down, and made no mention of it at all after everything was over.<br />
6- Result: Syn estimates that 10% of the email recipient followed the link. Of course, there is no knowing how many people faked the credentials just to see what the server is.<br />
7-His downfall: one of the managers was on the list and raised an alarm after an hour.</p>
<p>Why such a high success rate? He made it convincing - possession of the VPN client, knowledge of the security mailing list, knowledge of current events, pretext of trying to help the recipients with their troubles and good writing skills helped him pull it off.</p>
<p>Background:<br />
Syn is a security contractor at some company. He is not satisfied with the security and enforcement policies in place (specifically the fact that they do not sign their email), so he provides education by phishing their credentials. He does not warn anyone. He makes it easy for IT to trace him by putting comments in html code of the phishing site and by using corporate VPN. He does not get fired.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: PhishMe &#187; Shmoocon 2008 wrap-up: The Non-Moose Stuff</title>
		<link>http://isisblogs.poly.edu/2008/02/18/shmoocon-08/#comment-101</link>
		<dc:creator>PhishMe &#187; Shmoocon 2008 wrap-up: The Non-Moose Stuff</dc:creator>
		<pubDate>Thu, 21 Feb 2008 19:41:41 +0000</pubDate>
		<guid isPermaLink="false">http://isisblogs.poly.edu/2008/02/18/shmoocon-08/#comment-101</guid>
		<description>[...] presentations were very hit or miss this year, with unfortunately a bit more of the latter.  I felt a lot of presentations would have [...]</description>
		<content:encoded><![CDATA[<p>[&#8230;] presentations were very hit or miss this year, with unfortunately a bit more of the latter.  I felt a lot of presentations would have [&#8230;]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Brad Schonhorst</title>
		<link>http://isisblogs.poly.edu/2008/02/18/shmoocon-08/#comment-98</link>
		<dc:creator>Brad Schonhorst</dc:creator>
		<pubDate>Thu, 21 Feb 2008 01:59:40 +0000</pubDate>
		<guid isPermaLink="false">http://isisblogs.poly.edu/2008/02/18/shmoocon-08/#comment-98</guid>
		<description>I was sitting next to Dan at Simple Nomad's overview of cryptography and wished I had a few balls to toss as well.  (SHMOO BALLS are a Shmoocon tradition to call out a presenter who may need to check their facts.)  The presentation attempted to put modern crypto implementations into layman's terms but was clearly thrown together the day of the conference through a haze of the previous nights festivities.  It was a bit of a let down to spend an hour listening to basic pros and cons of crypto tools and the merits of a one time pad, considering the audience was made up of people who presumably have strong security backgrounds.

Overall the line up of speakers was hit or miss.  I suppose thats to be expected from most conferences, however, I do think there were some good original presentations.

Although the keynote speaker couldn't make it, his graduate student Alex Halderman presented on work done at Princeton regarding an electronic voting machine.  They were able to demonstrate exploiting the system to alter votes which is scary considering how many of these machines are still in use.

H1kari's talk on GSM exploits was frightening.  Guess I will have to trade in my iPhone if the new 3G version ever comes into existence, or better yet, how about a 700Mhz phone.

I caught Tim Vidas's talk on Solaris shellcode.  For those of you who took part in CSAW, Tim was the forensics winner this year.  He did a great job presenting at Shmoocon and demonstrating how to create shellcode on x86.

I always enjoy layer 2 talks as well.  Enno Rey and Daniel Mende presented on layer 2 protocol fuzzing and found some issues with some of the newer protocols that should keep some Cisco engineers busy for a while.     

Josh Wright and Brad Antoniewicz gave a dynamic talk on Protected EAP and some new attacks to reveal authentication information.  While the discussion was technically solid, their energy on stage definitely kept the crowds attention.

I do agree with you guys, this was probably my least favorite of the 3 Shmoocons I've attended.  It won't stop me from returning next year to hear Mr. Guido's talk though!</description>
		<content:encoded><![CDATA[<p>I was sitting next to Dan at Simple Nomad&#8217;s overview of cryptography and wished I had a few balls to toss as well.  (SHMOO BALLS are a Shmoocon tradition to call out a presenter who may need to check their facts.)  The presentation attempted to put modern crypto implementations into layman&#8217;s terms but was clearly thrown together the day of the conference through a haze of the previous nights festivities.  It was a bit of a let down to spend an hour listening to basic pros and cons of crypto tools and the merits of a one time pad, considering the audience was made up of people who presumably have strong security backgrounds.</p>
<p>Overall the line up of speakers was hit or miss.  I suppose thats to be expected from most conferences, however, I do think there were some good original presentations.</p>
<p>Although the keynote speaker couldn&#8217;t make it, his graduate student Alex Halderman presented on work done at Princeton regarding an electronic voting machine.  They were able to demonstrate exploiting the system to alter votes which is scary considering how many of these machines are still in use.</p>
<p>H1kari&#8217;s talk on GSM exploits was frightening.  Guess I will have to trade in my iPhone if the new 3G version ever comes into existence, or better yet, how about a 700Mhz phone.</p>
<p>I caught Tim Vidas&#8217;s talk on Solaris shellcode.  For those of you who took part in CSAW, Tim was the forensics winner this year.  He did a great job presenting at Shmoocon and demonstrating how to create shellcode on x86.</p>
<p>I always enjoy layer 2 talks as well.  Enno Rey and Daniel Mende presented on layer 2 protocol fuzzing and found some issues with some of the newer protocols that should keep some Cisco engineers busy for a while.     </p>
<p>Josh Wright and Brad Antoniewicz gave a dynamic talk on Protected EAP and some new attacks to reveal authentication information.  While the discussion was technically solid, their energy on stage definitely kept the crowds attention.</p>
<p>I do agree with you guys, this was probably my least favorite of the 3 Shmoocons I&#8217;ve attended.  It won&#8217;t stop me from returning next year to hear Mr. Guido&#8217;s talk though!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Aleksey Fateev</title>
		<link>http://isisblogs.poly.edu/2008/02/18/shmoocon-08/#comment-93</link>
		<dc:creator>Aleksey Fateev</dc:creator>
		<pubDate>Tue, 19 Feb 2008 08:00:22 +0000</pubDate>
		<guid isPermaLink="false">http://isisblogs.poly.edu/2008/02/18/shmoocon-08/#comment-93</guid>
		<description>It's the "new" missing from "new and interesting research" that was presented. The highlight for me were talks like "Virtual Worlds - Real Exploits" and "VoIP Penetration Testing: Lessons Learned". These were examples of excellent personal effort. Even in these talks, there were always people in the room who did research on the same or similar topic. But you know you are in real trouble when you have a presenter (Forensic Image Analysis to Recover Passwords, David Smith) talking about new and creative ways to of using strings.

HOPE 7 is this summer, lets make it exiting</description>
		<content:encoded><![CDATA[<p>It&#8217;s the &#8220;new&#8221; missing from &#8220;new and interesting research&#8221; that was presented. The highlight for me were talks like &#8220;Virtual Worlds - Real Exploits&#8221; and &#8220;VoIP Penetration Testing: Lessons Learned&#8221;. These were examples of excellent personal effort. Even in these talks, there were always people in the room who did research on the same or similar topic. But you know you are in real trouble when you have a presenter (Forensic Image Analysis to Recover Passwords, David Smith) talking about new and creative ways to of using strings.</p>
<p>HOPE 7 is this summer, lets make it exiting</p>
]]></content:encoded>
	</item>
</channel>
</rss>
