Thursday, March 10, 2016
Pick a card: Playing Cards as Trust Tokens
While preparing for my Bsides: Seattle presentation I met a guy who showed me an idea for the coolest 2nd factor of authentication I think I have ever seen. Anyone who knows me even a little bit knows I have a love of close up magic, sleight of hand, and anything generally dealing with card and coin magic. So when the guy pulled out a deck of cards I was instantly intrigued. When he told me it was his password I had to see it to believe it.
Sunday, February 21, 2016
BSides Seattle
First, let me say: to the organizers, supporters, participants, and my fellow presenters, Thank you for having me out. I had an excellent time and I learned tons. To the guys from TOOOL and Locksport, a special thank you. You sparked a love of locks and picking in my son. He spent well over half his time learning from you, and he hasn't been able to stop since.
If you are coming here after my presentation for slides and code they will be up by the end of this week. The code will be on my github https://github.com/dreilly369 . The issue with the demo was local (and due solely to my pre-talk jitters). The code is thankfully in good working order still. I will post my examples for:
HTTPS w/ STS
DNS Tunneling
Stegonagraphic embedding
CherryPy Server
Several Example bots to show possible uses
Thank you for you patience. I know a talk is always more fun with a live demo and I truly wish I had delivered on that front. Still, aside from the Demos above not happening, I hope you enjoyed yourself and learned something about Botnet Architecture!
EDIT: Slides have been given to the organizers and the code has been posted to the GitHub as promised. Please feel free to leave any comments below
If you are coming here after my presentation for slides and code they will be up by the end of this week. The code will be on my github https://github.com/dreilly369 . The issue with the demo was local (and due solely to my pre-talk jitters). The code is thankfully in good working order still. I will post my examples for:
HTTPS w/ STS
DNS Tunneling
Stegonagraphic embedding
CherryPy Server
Several Example bots to show possible uses
Thank you for you patience. I know a talk is always more fun with a live demo and I truly wish I had delivered on that front. Still, aside from the Demos above not happening, I hope you enjoyed yourself and learned something about Botnet Architecture!
EDIT: Slides have been given to the organizers and the code has been posted to the GitHub as promised. Please feel free to leave any comments below
Friday, January 22, 2016
Another speaking date announced
I have added another presentation to my schedule of upcoming events. If you will be attending the BSides Seattle Event February 20th, 2016
Sunday, January 10, 2016
Coding the Vigenère Square Cipher
Since I was a young boy, one of my favorite things to play around with has always been ciphers. Although they have largely fallen out of use I still enjoy studying different ciphers and trying to break them down into python algorithms. Today I will share one such project. The Advanced Vigenère Square Cipher.
Friday, January 1, 2016
Speaking date announced
I have recently confirmed my acceptance to speak at the Security BSides: Tampa Bay event later this year. I am excited to be presenting a topic on Bot Net Architectures.
Sunday, November 29, 2015
Here Hold This: Loading malware with legitimate Win32 applications
I do not often talk about OS specific topics. Even more rarely is that OS Windows. I am, after all, an OS agnostic with a "slight" lean towards Linux. Sometimes though, there is a method that is just too good to pass up writing about. "Here, Hold This" is the name I gave to a tactic for Windows post-exploitation persistence in which you cause a legitimate program run at boot to call your Malware startup routine. The exact method has been around pretty much since the inception of the Windows NT model. It takes advantage of the Windows DLL location search order to trick the program into loading a malicious DLL it believes to be legitimate.
Friday, November 6, 2015
Station to Station Encryption in Python
Alice and Bob are looking for a more secure way to communicate than HTTPS. Sure, HTTPS is good for securing their messages against basic eavesdroppers. However, they want to secure their communication, even if someone steals their server's private key. Furthermore, Alice and Bob want to make sure that if an encryption key for any communication is broken it does not compromise the rest. The method they settle on is called the "Station To Station Protocol".
Subscribe to:
Posts (Atom)