Home

Advertisement

de la defcon, homenaje a kachakil

  • Aug. 19th, 2008 at 3:00 PM
dragon

Esto salió en el blog que tiene ZDNet

Habla de un resumen de la defcon, y pone links de los speakers, de algunos, no de todos
pero aparece alguno que conocemos y no figura en la lista de speakers

Es el 3º de la lista, un cráneo que gana varios retos hacking, muy ingenioso

Reto 1
www.kachakil.com/Retos/I64_Reto_1.pdf
Reto 2
www.kachakil.com/Retos/I64_Reto_2.pdf
http://elladodelmal.blogspot.com/2007/04/solucin-al-2o-reto-hacking-web-por.html
Reto 4
yoire.com/downloads/solucion_i64_rh4_dani.pdf
http://elladodelmal.blogspot.com/2008/02/solucionario-reto-hacking-vi-por-dani.html
Reto 8
http://elladodelmal.blogspot.com/2008/08/solucionario-reto-hacking-viii-ii-de-ii.html
de paso a ver si me sirve para arreglar mi disco rígido
Los tengo todos impresos, los leo en el bondi, a ver si aprendo algo.....

y resulta que K está ahí, en esa lista, porque trabajó en la herramienta Marathon Tool, que hablaba Chema.....
Ver en su blog.
ey chemax, por qué no poner un "Buscar" en tu blog? ya se ha hecho muy grande y hay mucha info.....

Bueno que no se enojen los demas cráneos como Romansoft, Palako, Mandingo, y otros que no recuerdo ahora
;-)


Guest editorial by Rob Fuller

Defcon 16 tools and utilities

DEFCON, the 9000+ attendee hacker conference in Vegas has become a sort of hydra conference. It has become more like a global fair than what most people think of conferences; even the badge is highly unique.

I say this because there are so many things to do at DEFCON, other than going to talks, that you could spend your whole weekend looking at the “World’s Largest Boar!”, so to speak. One of the CTF (Capture the Flag) contest winners this year actually exclaimed that he only made it to 2 talks in 12 years! I am also one of those individuals who barely get a chance to go to talks and now that the speaker pool is so diverse, it’s hard to find all of the “stuff” they release.

Before anyone has a chance to post “it’s all on the DEFCON CD dummy,” I want to challenge them to try. After a weekend of googling (which came back with few results) and making contact with some of the speakers, I provide you with a mostly accurate list of “stuff” that was released at DEFCON this year. If any of the information is inaccurate, or a tool is missing, please contact me and I will update this post.


Beholder – by Nelson Murilo and Luis Eduardo


The Middler – by Jay Beale

ClientIPS – by Jay Beale


Marathon Tool – by Daniel Kachakill

  • Description: A Blind SQL Injection tool based on heavy queries
  • Download Link: DEFCON 16 CD. No online link found.
  • Email Address: dani@kachakil.com


The Phantom Protocol – by Magnus Brading


ModScan – by Mark Bristow


Grendel Scan – by David Byrne

  • Description: Web Application scanner that searches for logic and design flaws as well as the standard flaw seen in the wild today (SQL Injection, XSS, CSRF)
  • Homepage Link: http://grendel-scan.com/


iKat – interactive Kiosk Attack Tool  (This site has an image as a banner that is definitely not safe for work! – You have been warned) by Paul Craig


DAVIX – by Jan P. Monsch and Raffael Marty


CollabREate – by Chris Eagle and Tim Vidas


Dradis – by John Fitzpatrick


Squirtle – by Kurt Grutzmacher


WhiteSpace – by Kolisar

  • Description: A script that can hide other scripts such as CSRF and iframes in spaces and tabs
  • Download Link: DEFCON 16 CD


VoIPer – by nnp

  • Description: VoIP automated fuzzing tool with support for a large number of VoIP applications and protocols
  • Homepage Link: http://voiper.sourceforge.net/


Barrier – by Errata Security


Psyche – by Ponte Technologies

* Rob Fuller is a security researcher and pen-tester. He can be found on Twitter and in Room 362.

Ryan Naraine is a journalist and social media enthusiast specializing in Internet and computer security issues. He is currently security evangelist at Kaspersky Lab, an anti-malware company with operations around the world.

See his full profile and disclosure of his industry affiliations. Send tips, ideas and feedback to naraine SHIFT 2 gmail.com

For daily updates on Ryan's activities, follow him on Twitter.


 

se olvidaron de poner el link de la herramienta

http://www.codeplex.com/marathontool

aunque lo puse arriba acá está, y ya les escribo para decirles

;-)

 

Tags:

busca en alexa's blog