<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Day-Con on Insinuator.net - Bold Statements</title>
    <link>https://insinuator.net/tags/day-con/</link>
    <description>Recent content in Day-Con on Insinuator.net - Bold Statements</description>
    <generator>Hugo</generator>
    <language>en-us</language>
    <lastBuildDate>Wed, 04 Oct 2017 00:00:00 +0000</lastBuildDate>
    <atom:link href="https://insinuator.net/tags/day-con/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>Daycon X1</title>
      <link>https://insinuator.net/2017/10/daycon-x1/</link>
      <pubDate>Wed, 04 Oct 2017 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2017/10/daycon-x1/</guid>
      <description>&lt;p&gt;This is my short write up on &lt;a href=&#34;http://day-con.org/styled/&#34;&gt;Daycon X1&lt;/a&gt;, 2017.  The summit was held at Dayton, the land where &lt;a href=&#34;https://en.wikipedia.org/wiki/Wright_brothers&#34;&gt;Wright brothers&lt;/a&gt; were born. Apart from being my first US trip, I also gave my first training on Hacking 101 also called the Bootcamp.&lt;/p&gt;&#xA;&lt;p&gt;The Daycon X1  bootcamp started on 18th September. Ahmad, my colleague focused on web security, network scanning and metasploit exercises. I mainly handled classes on reversing and binary exploitation along with some pcap anaylsis and network attacks. It was highly fulfilling  experience to give a workshop. Teaching is definitely the best way to learn any topic by digging deep into it.The simpler you can explain, the more clarity you have on the topic. But I must say that it was indeed exhausting by the end of three days.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Day-Con X Recap</title>
      <link>https://insinuator.net/2016/10/day-con-x-recap/</link>
      <pubDate>Thu, 27 Oct 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/10/day-con-x-recap/</guid>
      <description>&lt;p&gt;Just a few days ago I had the pleasure of visiting &lt;a href=&#34;http://day-con.org/&#34;&gt;Day-Con X&lt;/a&gt;. I listened to some great talks in the closed and public sessions. Since the first day was the security summit (closed session) I will just name a few titles with some brief words.&lt;/p&gt;&#xA;&lt;p&gt;Captivating Security – Safety versus Passion (Josh More):&lt;br&gt;&#xA;Was quite interesting to compare the IT-World with zoos.&lt;/p&gt;&#xA;&lt;p&gt;Beyond Embedded (Brittany Postnikoff):&lt;br&gt;&#xA;Robots are fun soon :).&lt;/p&gt;</description>
    </item>
    <item>
      <title>A Quick Insight Into the Mirai Botnet</title>
      <link>https://insinuator.net/2016/10/a-quick-insight-into-the-mirai-botnet/</link>
      <pubDate>Thu, 20 Oct 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/10/a-quick-insight-into-the-mirai-botnet/</guid>
      <description>&lt;p&gt;As you might have read, &lt;a href=&#34;https://insinuator.net/2016/10/how-to-become-part-of-an-iot-botnet/&#34;&gt;I recently had a closer look at how easy it actually is to become part of an IoT Botnet&lt;/a&gt;. To start a further discussion and share some of my findings I gave a quick overview at the recent &lt;a href=&#34;http://day-con.org/&#34;&gt;Dayton Security Summit&lt;/a&gt;. The Mirai Botnet was supposed to be one of the case studies here. But the way things go if one starts diving into code…I eventually gave an overview of how the Mirai Bot actually works and what it does. As such: Here a quick summary of the Mirai Botnet bot.&lt;br&gt;&#xA;As described in my previous post, &lt;a href=&#34;https://krebsonsecurity.com/2016/09/krebsonsecurity-hit-with-record-ddos/&#34;&gt;KrebsonSecurity.com was attacked by a major DDoS attack&lt;/a&gt;. Reaching between 620Gbps and 660Gbps it was the largest documented DDoS attack so far. The attack seemingly resulted from a Botnet called Mirai. Shortly after the attack, a &lt;a href=&#34;https://krebsonsecurity.com/2016/10/source-code-for-iot-botnet-mirai-released/&#34;&gt;post on hackforums&lt;/a&gt; claimed to contain the actual source code of just this botnet.&lt;br&gt;&#xA;The &lt;a href=&#34;https://github.com/jgamblin/Mirai-Source-Code&#34;&gt;source code&lt;/a&gt; consists of three projects: The bot itself with its CnC server and a loader component.&lt;/p&gt;</description>
    </item>
    <item>
      <title>A Visual Guide to Day-Con 9</title>
      <link>https://insinuator.net/2015/11/a-visual-guide-to-day-con-9/</link>
      <pubDate>Mon, 09 Nov 2015 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2015/11/a-visual-guide-to-day-con-9/</guid>
      <description>&lt;h2 id=&#34;welcome-to-dayton&#34;&gt;Welcome to Dayton&lt;/h2&gt;&#xA;&lt;p&gt;In mid-October our friend Bryan Fite aka Angus Blitter invited the community for the ninth edition of &lt;a href=&#34;http://day-con.org/&#34;&gt;Day-Con&lt;/a&gt;. Bryan’s annual security summit, which we regard as the sister event of TROOPERS, is a pretty good reason to visit lovely Dayton, Ohio.&lt;/p&gt;&#xA;&lt;p&gt;&lt;a href=&#34;http://www.insinuator.net/wp-content/uploads/2015/11/IMG_2144.jpg&#34;&gt;&lt;img src=&#34;http://www.insinuator.net/wp-content/uploads/2015/11/IMG_2144.jpg&#34; alt=&#34;Day-Con Summit&#34;&gt;&lt;/a&gt;&lt;/p&gt;&#xA;&lt;p&gt;And so we did… ERNW sent in five delegates. Delegates is &lt;em&gt;Day-Con-speak&lt;/em&gt; for all attendees and speakers and such a subtle choice of wording sets the tone for the whole event. People seemed to be really focused and the roundtable-like setting during the talks (see above) provided a cozy atmosphere for in-depth expert chatting.&lt;/p&gt;</description>
    </item>
    <item>
      <title>DayCon VII</title>
      <link>https://insinuator.net/2013/09/daycon-vii/</link>
      <pubDate>Thu, 26 Sep 2013 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2013/09/daycon-vii/</guid>
      <description>&lt;p&gt;Some of us had the pleasure to participate in this year’s &lt;a href=&#34;http://www.day-con.org&#34;&gt;Daycon VII&lt;/a&gt;, three days of Real Hacking and Relevant Content, in Dayton, OH. The event began on September 16th with the Packetwars bootcamp. We had the chance to teach some really promising young students and to prepare them for the Packetwars battle that was scheduled four days later. The students had to go through topics like Windows security, network security and web application security both practical and in theory.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Back from DayCon VI</title>
      <link>https://insinuator.net/2012/11/back-from-daycon-vi/</link>
      <pubDate>Thu, 01 Nov 2012 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2012/11/back-from-daycon-vi/</guid>
      <description>&lt;p&gt;Two weeks ago we had a great time at &lt;a href=&#34;http://www.day-con.org&#34; title=&#34;DayCon&#34;&gt;Day-Con VI&lt;/a&gt;. Enno, Matthias, Rene, Frank and me traveled to Dayton, OH to give workshops and presentations. We started a tough week full of  &lt;a href=&#34;http://day-con.org/POOH.html&#34;&gt;workshops&lt;/a&gt; on Tuesday where Rene gave a deep inside look into the world of security on current mobile platforms. Matthias discussed security problems and possible design patterns of cloud environments in his Cloud &amp;amp; Virtualization Security Workshop before he gave a first insight into the world of reverse engineering on Wednesday. Frank and me taught the basics of hacking and pentesting in the &lt;a href=&#34;http://www.packetwars.com&#34;&gt;PacketWars&lt;/a&gt; bootcamp (comparable to the one at &lt;a href=&#34;https://www.troopers.de/troopers12/agenda/hacking-101-workshop/index.html&#34;&gt;TROOPERS&lt;/a&gt;), preparing the participants for the &lt;a href=&#34;http://packetwars.com/&#34; title=&#34;packetwars&#34;&gt;PacketWars&lt;/a&gt; on Saturday. Obviously we were not the only ones having a &lt;a href=&#34;http://msdaisysramblings.blogspot.de/2012/10/packetwars-and-daycon-exploding-my.html&#34;&gt;great time&lt;/a&gt; 😉&lt;/p&gt;</description>
    </item>
    <item>
      <title>DAY-CON VI</title>
      <link>https://insinuator.net/2012/07/day-con-vi/</link>
      <pubDate>Sat, 21 Jul 2012 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2012/07/day-con-vi/</guid>
      <description>&lt;p&gt;As &lt;a href=&#34;http://www.insinuator.net/2011/10/packetwars-sun-skills/&#34;&gt;every year&lt;/a&gt;, we will be attending &lt;a href=&#34;http://day-con.org&#34;&gt;Day-Con&lt;/a&gt;, a one-day security summit in Dayton, OH — this year for its VIth edition. Even though the actual conference comprises “only” one day full with talks and discussions (please find the agenda &lt;a href=&#34;http://day-con.org/SCHEDULE_%26_SPEAKERS.html&#34;&gt;here&lt;/a&gt;), the overall event consists of &lt;a href=&#34;http://day-con.org/pooh2012.pdf&#34;&gt;trainings&lt;/a&gt; before the conference and &lt;a href=&#34;http://packetwars.com/&#34;&gt;PacketWars&lt;/a&gt; battles (including an infamous party) afterwards. Since we will be leading and attending some of the training sessions, those might be of particular interest for people who missed our &lt;a href=&#34;http://www.troopers.de/archives/troopers12/agenda/&#34;&gt;Troopers workshops&lt;/a&gt; — so you don’t have to wait a whole year but get another chance in October 😉&lt;/p&gt;</description>
    </item>
    <item>
      <title>Packetwars, Sun &amp; Skills</title>
      <link>https://insinuator.net/2011/10/packetwars-sun-skills/</link>
      <pubDate>Sun, 16 Oct 2011 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2011/10/packetwars-sun-skills/</guid>
      <description>&lt;p&gt;During the last days, some of our guys (including me) had some great days in Dayton. Rene, Christopher, Hendrik, Sergej, and me flew in to give workshops and presentations at &lt;a href=&#34;http://day-con.org/&#34; title=&#34;daycon&#34;&gt;Day-Con&lt;/a&gt; as well as to compete in the infamous &lt;a href=&#34;http://www.packetwars.com&#34;&gt;PacketWars&lt;/a&gt; game. While Day-Con is a one day event, the two days before the conference comprised workshops on &lt;a href=&#34;http://www.hmtrainingsolutions.com/en/home/85-ios-security-sichere-integration-von-iphone-a-ipad.html&#34;&gt;secure iOS integration&lt;/a&gt; (given by Rene) and &lt;a href=&#34;http://www.hmtrainingsolutions.com/en/home/91-ipv6technologie-und-integration.html&#34;&gt;IPv6 security&lt;/a&gt; (given by Christopher). Since the overall topic of the conference was trust, Rene gave a &lt;a href=&#34;http://www.ernw.de/publikationen/DayConV_ERNW_Broken_Trust_v025.pdf%20&#34;&gt;keynote&lt;/a&gt; on broken trust which was based exemplary trust analysis, development of a trust metric, and different trust factors. Those trust factors were also used in my talk about evaluation methodologies for &lt;a href=&#34;http://www.ernw.de/publikationen/do_they_deliver.pdf%20&#34;&gt;cloud service providers&lt;/a&gt; (regular followers will recognize some of the content of both talks from &lt;a href=&#34;http://www.insinuator.net/2011/10/broken-trust-part-2-applying-the-approach-to-dropbox/&#34;&gt;different&lt;/a&gt; &lt;a href=&#34;http://www.insinuator.net/2011/07/the-key-to-your-datacenter/&#34;&gt;posts&lt;/a&gt; 😉 ). There were also talks from Sergey Bratus, Graeme Neilson and Angus Blitter. While Sergey proposed a sound (not to say academic 😉 ) definition on the classification of vulnerabilities and their connection to &lt;a href=&#34;http://www.wolframalpha.com/input/?i=turing+completeness&#34;&gt;turing complete input languages&lt;/a&gt;, Angus gave an introduction to &lt;a href=&#34;http://grouper.ieee.org/groups/1901/&#34;&gt;PowerLine technologies&lt;/a&gt; and laid out, that these technologies still suffer from naive assumptions about trusted networks (he also refered to &lt;a href=&#34;http://www.blackhat.com/presentations/bh-europe-09/Rey_Mende/BlackHat-Europe-2009-Mende-Rey-All-Your-Packets-slides.pdf&#34;&gt;this&lt;/a&gt;). The day after the conference, the ERNW Allstars had to defend their championship title in PacketWars. Since the first battle was scheduled for 10AM, we had quite some time to tan in the sunny 30°C weather, recover from the conference and prepare the expected victory celebration (some of you might remember some “Champagne tradition” from &lt;a href=&#34;http://www.troopers.de&#34;&gt;Troopers&lt;/a&gt;). In face of this motivation, we rushed through the 3 battles and were able to score first place second year in a row. At this point, kudos to the two other participating teams who gave us a tough battle, especially during the reversing challenges.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Back from Day-Con</title>
      <link>https://insinuator.net/2010/10/back-from-day-con/</link>
      <pubDate>Sat, 30 Oct 2010 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2010/10/back-from-day-con/</guid>
      <description>&lt;p&gt;… which was, as in the years before, an awesome &lt;a href=&#34;http://www.day-con.org&#34;&gt;event&lt;/a&gt;. Great talks, great people, great fun.&lt;br&gt;&#xA;Bruce Potter gave a &lt;a href=&#34;http://www.ernw.de/download/DayCon-10-Keynote.pdf&#34;&gt;keynote&lt;/a&gt; which did exactly what a good keynote should do: make the audience think and entertain it at the same time.&lt;br&gt;&#xA;[Those readers familiar with ERNW’s security model will certainly notice that we do not necessarily agree with everything he said. We still think that – in particular in times where infosec resources are scarce anyway – putting your bets on prevention provides a better cost/[security] benefit ratio than going for extensive detection capabilities.&lt;br&gt;&#xA;Fix the doors first, then think about installing a CCTV.&lt;br&gt;&#xA;Still, human nature tends to exchange “good security with low visibility” for “poor security with potentially good visibility” quite easily… as can be noted every day in many environments.]&lt;/p&gt;</description>
    </item>
  </channel>
</rss>
