Premium Sponsors
For more info on all sponsors, click here.
For Sponsorship Opportunities, click here.
Premium Sponsors
For more info on all sponsors, click here.
For Sponsorship Opportunities, click here.
888.hacker0
questions ( at ) chicagocon.com

Chicago's Own Hacker Con Set for May, Teaches Human Hacking to Corporations

Webcast: Modern Social
Engineering Part II: Top 5 Ways to Manipulate Humans Over the Wire
with Nickerson & Murray
April 30, 2009 @ Noon Central

Webcast: Modern Social
Engineering - A Vital
Component of Pen Testing
with Nickerson & Murray
Entire Video Now Online @ EH-Net
|
|
|
Friday May 8 - 7:00 PM
Video Entertainment in Auditorium (It's a surprise and may just be audience determined)
Saturday May 9 - Additional Check-In Starting at 8:00 AM
Saturday May 9 - Keynote 9:00 AM
Marcus K. Rogers, Ph.D., CISSP, CCCI
Director of the Cyber Forensics Program in the Dept. of Computer and Information Technology at Purdue University
The Evolution of Social Engineering: From Persuasion to Social Malware
The presentation will examine how social engineering (SE) in the InfoSec domain has developed in the past decade. The historical roots, present day context, and possible future manifestation of SE will be discussed. The talk will also look at how the synergy between malware, the new culture of social networks, anonymity and virtual trust relationships will influence the evolution of SE and what if anything can be done to mitigate SE's current and future impact.
Marc Rogers is a Professor, Faculty Scholar and a research faculty member at the Center for Education and Research in Information Assurance and Security (CERIAS). Dr. Rogers is a member of the quality assurance board for (ISC)2's SCCP designation, the International Chair of the Law, Regulations, Compliance and Investigation Domain of the Common Body of Knowledge (CBK) committee, Chair - Ethics Committee Digital & Multimedia Sciences Section - American Academy of Forensic Sciences, and Chair - Certification Committee Digital Forensics Certification Board. Dr. Rogers is the Editor-in-Chief of the Journal of Digital Forensic Practice and sits on the editorial board for several other professional journals. He is also a member of other various national and international committees focusing on digital forensic science and digital evidence. Dr. Rogers is the author of numerous book chapters, and journal publications in the field of digital forensics and applied psychological analysis. His research interests include applied cyber forensics, social engineering, psychological digital crime scene analysis, and cyber terrorism.
Saturday May 9 - 10:00 AM
Chris Gates (CG) & Vince Marvelli (g0ne)
Full Scope Security
Attacking Layer 8: Client Side Penetration Testing
Do you have good perimeter security keeping bad guys from coming in the front door? Unfortunately for you, there are other ways of gaining access. Specifically, having your untrained users browse to places they shouldn't, open emails they shouldn't, and downloading and executing things they shouldn't. This presentation will address some of those issues and and describe why and how to go about testing your environment for this very likely vulnerability. Client Sides are the new remote exploit. If you aren't allowing client side attacks during your vulnerability assessments or penetration tests your are ignoring a huge attack vector and the current attack method. You are also failing to exercise your internal and host based exploitation countermeasures (HIDS/HIPS), you ability to test and respond to client side attacks and internal attackers and missing a valuable opportunity for user awareness training. This talk will focus on justifying why you should be allowing client side penetration testing, giving penetration testers a basic methodology to conduct client side attacks during their penetration test, and give (mostly real-world) examples we used during client side penetration tests to go with our methodology.
Chris Gates (CG) - Founder Full Scope Security performing full scope penetration testing and security engineering. Previous jobs includes full scope penetration tester for one of the DoD Red Teams and Army Signal Officer spending gobs of time in layer 2 and layer 3 land. EthicalHacker.net columnist and security blogger.
http://carnal0wnage.blogspot.com
Vince Marvelli (g0ne) - Founder Full Scope Security performing full scope penetration testing and security engineering. Previous jobs includes full scope penetration tester for one of the DoD Red Teams, SOC architect and principal engineer, IDS architect and analyst, general IT security analyst and security blogger.
https://g0ne.wordpress.com
Saturday May 9 - 11:00 AM
Craig Heffner & Derek Yap
SourceSec Research Group
Hacking The Network Inside Out
Despite numerous known vulnerabilities, direct attacks against SOHO routers are largely ignored, either due to their percieved impracticality, or a lack of tools/skills. This talk will address the current state of security in SOHO routers, and how router vulnerabilities can provide outside attackers with access to the LAN that the router was designed to help protect. Router reconnaissance, as well as remote, WiFi, and physical attacks will be discussed, and several new tools will be released. Specific topics include: router fingerprinting tools & techniques, methods for hacking internal administrative interfaces from the Internet, cracking WPA/WPA2 encryption keys with HTML images, and how to build simple hardware backdoors for SOHO routers.
Craig Heffner and Derek Yap are security researchers and developers with the SourceSec Research Group. Their expertise covers a wide range of topics, from programming to reverse engineering, malware to Web hacking. They have released numerous vulnerabilities and white papers to the security community, and Craig a columnist at The Ethical Hacker Network.
Saturday May 9 - 12:00 Noon
Ryan Linn & Brian Wilson
Columnists, The Ethical Hacker Network
Cain BeEF Hash: Snagging Passwords without Popping Boxes
Chaining exploits and abusing trust are two heavily discussed topics in security today. This presentation will talk about abusing both types of opportunities in order to show how hosts can be targeted and passwords can be retrieved without ever directly exploiting a machine. These attacks are not directly being used against the target and take approaches where exploitation may not be obvious or detectable, even by Intrusion Detection Systems or Anti-Virus Programs. Using BeEF, Metasploit, and a handful of other tools, we will explore the possibilities available, utilize some new tools that can be used to leverage these types of vulnerabilities, and we'll show you how to apply these tools in actual network pen tests. And it's not all talk... we will be doing a live demo of this attack!
Ryan Linn is currently an Information Security Engineer at SAS Institute
. Employed in the computer industry since 1997, he has held positions ranging from web developer to Unix Systems Programmer at a large university to his current position in Information Security. Ryan has been responsible for working with large scale deployments of various flavors of *nix, high availability web and database clusters, as well as for application programming in high availability environments. In the past few years, Ryan has incorporated Windows security into his responsibilities, and is now part of the team responsible for information security globally in one of the largest privately held software companies in the world.
Brian Wilson, now of Cisco Systems, has over 14 years experience in IT starting with a tour in the United States Army. This Ethical Hacker Network Columnist has worked in and out of the US Government in many different organizations and technical roles including a stint as a Cisco Certified Instructor. Currently he works for an industry leading vendor supporting millions of customers of broadband & VoIP services (ISPs). He has attained a number of industry credentials covering many aspects of IT including CISSP, CCNA, CCSE, CCAI, MCP, JNCIA, Network+, Security+, and many DoD Certifications. He also uses his knowledge of IT to benefit a number of charitable organizations.
Lunch will be provided Hewlett-Packard
Saturday @ 1:00 PM!!
Saturday Afternoon Extra-Curriculars
|
Workshop: Hacking the Web 2.0 with HP's Rafal Los Come hear a fun, workshop-oriented talk about the evolving world of "Web 2.0" focused on AJAX and Flash "deconstruction." Optional hands-on lab. Rafal Los has over 13 years experience in network and system design, security policy and process design, risk analysis, penetration testing and consulting. In the last 8 years his focus has been on Information Security and Risk Management, leading security architecture teams and managing successful enterprise security programs in the small companies and large enterprises such as General Electric. Rafal was responsible for security architecture at GE Consumer Finance for over 3 years, leading strategic efforts to understand the business goals and mitigate enterprise risk through technology, process and education. Going beyond the technology and implementing programs that succeed in a variety of environments combined with a wealth of knowledge on business process and risk management makes Rafal an industry veteran from both a business and IT Security angle. Today Rafal is working with the HP Application Security Center as a Web Application Security Evangelist and subject-matter expert. Working with large customers to build, implement and maintain world-class application security programs, he provides guidance from his extensive experience in computer security.
Lock Picking 101 Short presentation on the art of lockpicking and then an open lab with locks galore and instruction from expert and Defcon veteran, Karen Maeda. Karen holds a degree in Information Systems and has been heavily involved with the professional security community for over 8 years. A veteran of Blackhat and Defcon, Karen has co-taught multiple classes around the world in lockpicking, no-tech hacking, and various other methods to expose risk. Her long term assistance with the "Lockpick Village" has helped accelerate the growth of the physical security community and taught 1000's of people the art of defeating lock mechanisms. Currently, she is a Security Engineer at Lares, where her daily tasks range from education to active engagements with clients. If involved in the security community, you may better know her as Miss DJ Jackalope, the resident DJ of Defcon and other security conferences in the United States. The Doctor Is In Career counseling, advice and general discussions in an open format on personal growth in the field of InfoSec by industry veteran and respected career speaker and coach Mike Murray. He will work with the attendees of ChicagoCon to discuss the fundamental skills needed, and put the audience of this breakout session through exercises that will help clarify that plan, and move forward toward their ultimate career goals. As Mike puts it, "Information security is one of the most difficult industries to navigate a career in. The industry is new, and the skills are ever-changing. The nature of the industry is that the biggest threats are always in the newest technologies, which means that if you're not actively running, you're falling behind. Not to mention that there's no industry standard for certification, for knowledge, or even for what "security" actually is. It's confusing at the best of times. And this isn't the best of times." |
Exotic Liability LIVE in the Auditorium!!
Sick of the podcasts that are telling you stuff you already know? Tired of the same old "read the sheet" presentation skills of most podcasts? Looking for fresh content and expert outlook? Bleeding edge and beyond.... Exotic Liability will push you into the new generation of Security. On your own or by force, we will be bringing you the best content from the TOP of the Security industry. No more firewall admins speculating about how attacks happen, these are the pros. These are the people that make Security tick. If you are tired of the old solutions and rhetoric, join in. This special edition of Exotic Liability will feature not only the speakers from ChicagoCon but also the attendees in an open discussion on the security landscape as the experts in the field see it. Also look for Chris Nickerson and Mike Murray to give you an update on the Social Engineering Master Class and the ghorry details of their hot new class. |
Saturday May 9 - 6:00 PM
Closing Remarks
Donald C. Donzal, ChicagoCon & The Ethical Hacker Network
| < Prev |
|---|