« Home | Poll machines prone to hacking -- IT expert » | SILICAQ Released » | Sulit.com.ph Hacking Incident » | BDO ATM Cmd Shell » | I.T. Security Bootcamp 2009 » | Defconph.org's Bloggers Conference Meeting » | Globe Network Hacking » | The 0day will cost you.... » | Mail8 Vulnerability » | Put Up OR Shut Up (PUORSU) Conference »

Defconph BeerTalk II (Manila)

Where:
Grilla Paseo De Roxas Avenue Branch, Makati
Near Greenbelt

When:
April 24, 2009 @ 1900 HRS PHT

Who Should Attend:
Everyone can attend not just IT enthusiasts. We mean everyone, humans on different fields like Feds, Lawyers, Salesman, anyone who are willing to learn what is going on with information security these days.

Registration Fee:
Early Php800.00 / Late Registration Php1500.00 includes DEFCONPH Official T-shirt, 2 Bottle of Booze and 2 Slice of Pizza

NOTE: Early Registration closes on April 12, 2009

DEFCON Philippines BeerTalk II(Manila) Full Track
7:00PM - 7:10PM Welcome Address
7:10PM - 7:30PM Introduction to DEFCON Philippines
7:30PM - 8:20PM Unconventional Privilege Escalation
8:20PM - 8:30PM Q&A
8:30PM - 9:20PM Penetration Testing, A Structured Approach: Conducting Penetration Tests in a business environment
9:20PM - 9:30PM Q&A
10:30PM - 11:20PM The Waledac Botnet
11:20PM - 11:30PM Q&A
11:30PM - 12:30PM Games - Hackista 2009 (Øpen Hack Challenge)
12:30PM - 12:45PM Closing Remarks / Awards and Recognition
12:45PM - onwards More BEER .... ..... .... Drink til you Drop


Unconventional Privilege Escalation

Speaker: Tikbalang

Synopsis: Conventional privilege escalation deals with vulnerabilities and acquiring root level in the system. Is there a way of escalating privilege (unconventionally) without having the root level? Up to what extent can the escalations go? Is it really a threat to consider? Are people affected by this?

Penetration Testing, A Structured Approach: Conducting Penetration Tests in a business environment

Speaker: theStare

Synopsis: Recent developments concerning regulatory requirements, the current financial turmoil and rising security threats to organizations have opened the doors of business for various security service providers. Organizations are looking for service providers who understand their business and its associated risks, capable of assessing their current security posture, identify any gaps, and provide cost-effective recommendations that can reasonably address these gaps. They are searching for professionals who can perform these services in an organized manner, using a sound approach and a proven methodology. This talk deals with the details of managing penetration testing engagements, right from proposal preparation up to report delivery.

The Waledac Botnet

Speaker: Bullsh!t

Synopsis: Botnet technology and techniques are continuously evolving, and currently, the Waledac botnet is probably the most advanced botnet out there.

In this presentation, we will give a brief overview on botnet evolution, the technical aspects of Waledac, the botnet, what it does, and how the bot masters are raking in cash out of this.

Hackista 2009 (Øpen Hack Challenge)

Mechanics: The goal of this challenge is to obtain administrative level privileges on a windows 2000 server with no security patches by exploiting vulnerabilities in the RPC/LSASS Services on the target machine. The target machine IP address will be announced prior to the start of the challenge. Upon successful compromise, create a text file with your name on the target machine's desktop and notify any of the the goons for verification. The first one to compromise the machine after verification will be considered the winner and gets a change to do a demo on the methods he used. The first one to create their HANDLE.txt on the desktop of the compromised machine wins the game.

Tools: Any hacking tools are allowed, Metasploit, Nessus, Nmap etc..

Rules: No direct DoS on the server, anyone caught DoSing the server will automatically disqualify you from the game.

Price: The first one to create handle.txt will be getting black badge, black badge entitles you for lifetime access to the DEFCON Philippines event.