<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>NovaInfosecPortal.com &#187; Infosec Conferences</title>
	<atom:link href="http://www.novainfosecportal.com/category/events/infosec-conferences/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.novainfosecportal.com</link>
	<description>News, events, &#38; resources for infosec professionals in NoVA, DC, &#38; MD</description>
	<lastBuildDate>Mon, 06 Feb 2012 18:30:33 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=</generator>
		<item>
		<title>ShmooCon 2012 FireTalks – Update 8 (Videos from Saturday)</title>
		<link>http://www.novainfosecportal.com/2012/02/06/shmoocon-2012-firetalks-%e2%80%93-update-8-videos-from-saturday/</link>
		<comments>http://www.novainfosecportal.com/2012/02/06/shmoocon-2012-firetalks-%e2%80%93-update-8-videos-from-saturday/#comments</comments>
		<pubDate>Mon, 06 Feb 2012 18:30:33 +0000</pubDate>
		<dc:creator>grecs</dc:creator>
				<category><![CDATA[Infosec Conferences]]></category>
		<category><![CDATA[NoVA Meetups]]></category>
		<category><![CDATA[conference]]></category>
		<category><![CDATA[contest]]></category>
		<category><![CDATA[firetalks]]></category>
		<category><![CDATA[firetalks2012]]></category>
		<category><![CDATA[infosec]]></category>
		<category><![CDATA[shmoocon]]></category>
		<category><![CDATA[videos]]></category>

		<guid isPermaLink="false">http://www.novainfosecportal.com/?p=7822</guid>
		<description><![CDATA[To follow up with Friday&#8217;s post re getting a lot of the other awesome ShmooCon Firetalks out there, here is the complete line up from Saturday night. And if you are interested in seeing all the talks from each night, IronGeek has just put out a post with two longer videos from each evening. I again wanted to thank The Shmoo Group and our generous sponsors. Lastly, thanks to our awesome volunteers that made this year&#8217;s Firetalks the best so far. Thanks! CFP Review: @jack_daniel, Sarah “@dystonic” Clarke, @jasonmoliver, Nathi “@nathiet” Thwala Judges: @DaKahuna2007, Rob “@mubix” Fuller, Nicolle “@rogueclown” Neulist, @soapturtle Streaming/Recording: @georgiaweidman, Adrian “@irongeek_adc” Crenshaw Security: Boris “@JadedSecurity” Sverdlik, Casey “@caseydunham” Dunham, @judykavuo And finally be sure to check back to the master Firetalks post. It provides the core content as well as quick links to all update blog posts.  Well on to the videos&#8230; &#8220;Cracking WiFi Protected Setup For Fun and Profit&#8221; by Craig Heffner This talk will detail the recently disclosed vulnerability in WiFi Protected Setup which allows wireless attackers to recover plain text WPA/WPA2 pass phrases in just a few hours, as well as my WPS brute force attack tool, Reaver. &#8220;Passive Aggressive Pwnage: Sniffing the [...]]]></description>
			<content:encoded><![CDATA[<div class="tweetthis" style="text-align:left;"><p> <a target="_blank" rel="nofollow" class="tt" href="http://twitter.com/intent/tweet?text=ShmooCon+2012+FireTalks+%E2%80%93+Update+8+%28Videos+from+Saturday%29+http%3A%2F%2Fj.mp%2FzhPjeb" title="Post to Twitter"><img class="nothumb" src="http://www.novainfosecportal.com/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro4.png" alt="Post to Twitter" /></a> <a target="_blank" rel="nofollow" class="tt" href="http://www.facebook.com/share.php?u=http://www.novainfosecportal.com/2012/02/06/shmoocon-2012-firetalks-%e2%80%93-update-8-videos-from-saturday/&amp;t=ShmooCon+2012+FireTalks+%E2%80%93+Update+8+%28Videos+from+Saturday%29" title="Post to Facebook"><img class="nothumb" src="http://www.novainfosecportal.com/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro4.png" alt="Post to Facebook" /></a></p></div><p><img class="alignright size-full wp-image-7991" title="Saturday Night Fever" src="http://www.novainfosecportal.com/wp-content/uploads/2012/02/SatNightFever.jpg" alt="Cover from Saturday Night Fever" width="113" height="151" />To follow up with <a href="/2012/02/03/shmoocon-2012-firetalks-%E2%80%93-update-7-videos-from-friday/">Friday&#8217;s post</a> re getting a lot of the other awesome ShmooCon Firetalks out there, here is the complete line up from Saturday night. And if you are interested in seeing all the talks from each night, IronGeek has just put out a post with <a href="http://www.irongeek.com/i.php?page=videos/shmoocon-firetalks-2012">two longer videos from each evening</a>.</p>
<p>I again wanted to thank <a href="http://www.shmoo.com/">The Shmoo Group</a> and our <a href="/2012/01/06/yes-its-been-awhile-since-last-update-re-shmoocon-2012-firetalks-sorry-for-the-wait/">generous sponsors</a>. Lastly, thanks to our awesome volunteers that made this year&#8217;s Firetalks the best so far. Thanks!</p>
<ul>
<li><strong>CFP Review:</strong> @<a href="http://twitter.com/jack_daniel">jack_daniel</a>, Sarah “@<a href="http://twitter.com/dystonic">dystonic</a>” Clarke, @<a href="http://twitter.com/jasonmoliver">jasonmoliver</a>, Nathi “@<a href="http://twitter.com/nathiet">nathiet</a>” Thwala</li>
<li><strong>Judges:</strong> @<a href="http://twitter.com/DaKahuna2007">DaKahuna2007</a>, Rob “@<a href="http://twitter.com/mubix">mubix</a>” Fuller, Nicolle “@<a href="http://twitter.com/rogueclown">rogueclown</a>” Neulist, @<a href="http://twitter.com/soapturtle">soapturtle</a></li>
<li><strong>Streaming/Recording:</strong> @<a href="http://twitter.com/georgiaweidman">georgiaweidman</a>, Adrian “@<a href="http://twitter.com/irongeek_adc">irongeek_adc</a>” Crenshaw</li>
<li><strong>Security:</strong> Boris “@<a href="http://twitter.com/JadedSecurity">JadedSecurity</a>” Sverdlik, Casey “@<a href="http://twitter.com/caseydunham">caseydunham</a>” Dunham, @<a href="http://twitter.com/judykavuo">judykavuo</a></li>
</ul>
<p>And finally be sure to check back to the <a href="/2011/12/13/shmoocon-2012-firetalks/">master Firetalks post</a>. It provides the core content as well as quick links to all update blog posts.  Well on to the videos&#8230;</p>
<h2 style="text-align: center;">&#8220;Cracking WiFi Protected Setup For Fun and Profit&#8221;</h2>
<p style="text-align: center;">by Craig Heffner</p>
<p>This talk will detail the recently disclosed vulnerability in WiFi Protected Setup which allows wireless attackers to recover plain text WPA/WPA2 pass phrases in just a few hours, as well as my WPS brute force attack tool, Reaver.</p>
<p>    <iframe src="http://player.vimeo.com/video/35980306" width="576" height="324" frameborder="0" webkitAllowFullScreen mozallowfullscreen allowFullScreen></iframe></p>
<h2 style="text-align: center;">&#8220;Passive Aggressive Pwnage: Sniffing the Net for Fun &amp; Profit&#8221;</h2>
<p style="text-align: center;">by John Sawyer</p>
<p>There has been very little public research into passive fingerprinting over the last few years, and the best and most well-known tool for that (p0f) hasn’t been actively developed in 6 years. While a recent a project is using the clever technique of identifying OS’s through DHCP options, it isn’t looking beyond simple OS identification. Why not? If you’ve ever been responsible for IDS monitoring in a large environment, you know there’s a huge amount of juicy data waiting to be snarfed up–interesting information that could be collected passively to identify vulnerable targets in a pen test. Some commercial solutions have these passive vulnerability detection capabilities already, but it’s never trickled down into the free, open source world.</p>
<p>In this presentation, we will look at some of the data that can be gleaned passively, how it can be used for offensive (and defensive) purposes, and announce a new project designed to use existing open source IDS engines (Snort &amp; Suricata) and IDS rules to enhance penetration tests through passive fingerprinting. The project will utilize existing rules from projects like Emerging Threats, develop new rules to address gaps in detection, and give back to the community by contributing newly developed rules back to similar projects. A focus will be on identifying bleeding edge devices, vulnerable applications, and passively gathering sensitive information (SSNs, CCNs, passwords, etc.).</p>
<p>    <iframe src="http://player.vimeo.com/video/35984709" width="576" height="324" frameborder="0" webkitAllowFullScreen mozallowfullscreen allowFullScreen></iframe></p>
<h2 style="text-align: center;">&#8220;Ressurecting Ettercap&#8221;</h2>
<p style="text-align: center;">by Eric Milam</p>
<p>In December 2011 Ettercap had its first official release in almost 6 years. This talk will discuss how I went from the creation of a simple bash script to taking over one of the world most loved penetration testing tools. Topics will include, easy-creds, communications with Alor &amp; Naga and the new team charged with moving the project forward.</p>
<p>    <iframe src="http://player.vimeo.com/video/35989154" width="576" height="324" frameborder="0" webkitAllowFullScreen mozallowfullscreen allowFullScreen></iframe></p>
<h2 style="text-align: center;">&#8220;Security Onion: Network Security Monitoring in Minutes&#8221;</h2>
<p style="text-align: center;">by Doug Burks</p>
<p>Traditional Intrusion Detection Systems (IDS) can be costly, difficult to install, and may not provide all the capabilities that you need to defend your network. Network Security Monitoring (NSM) combines traditional IDS alerts with additional data to give you a more complete picture of what’s happening on your network. This presentation will demonstrate how to deploy NSM in just a few minutes using a free Linux distro called Security Onion.</p>
<p>    <iframe src="http://player.vimeo.com/video/35993348" width="576" height="324" frameborder="0" webkitAllowFullScreen mozallowfullscreen allowFullScreen></iframe></p>
<h2 style="text-align: center;">&#8220;Remotely Exploiting the PHY Layer&#8221;</h2>
<p style="text-align: center;">by Travis Goodspeed</p>
<p>Packet-in-Packet injections are a new type of in-band signalling attack, one which allows a packet to be injected into a remote wireless network through the body of any other type of packet. The attacker never needs a radio, and no software or hardware bugs are necessary for the injection to occur. The attack works on perfectly standard-compliant implementations of 802.15.4, 802.11B, and most other wireless protocols.</p>
<p>    <iframe src="http://player.vimeo.com/video/35998128" width="576" height="324" frameborder="0" webkitAllowFullScreen mozallowfullscreen allowFullScreen></iframe></p>
<p style="text-align: center;">#####</p>
<p style="text-align: center;"><em>This will be the final ShmooCon 2012 FireTalks post. It&#8217;s been a blast! See ya&#8230;Today&#8217;s post image is brought to you from <a href="https://en.wikipedia.org/wiki/Saturday_Night_Fever_%28musical%29">Wikipedia.org</a>.</em></p>
<div class="tweetthis" style="text-align:left;"><p> <a target="_blank" rel="nofollow" class="tt" href="http://twitter.com/intent/tweet?text=ShmooCon+2012+FireTalks+%E2%80%93+Update+8+%28Videos+from+Saturday%29+http%3A%2F%2Fj.mp%2FzhPjeb" title="Post to Twitter"><img class="nothumb" src="http://www.novainfosecportal.com/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro4.png" alt="Post to Twitter" /></a> <a target="_blank" rel="nofollow" class="tt" href="http://www.facebook.com/share.php?u=http://www.novainfosecportal.com/2012/02/06/shmoocon-2012-firetalks-%e2%80%93-update-8-videos-from-saturday/&amp;t=ShmooCon+2012+FireTalks+%E2%80%93+Update+8+%28Videos+from+Saturday%29" title="Post to Facebook"><img class="nothumb" src="http://www.novainfosecportal.com/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro4.png" alt="Post to Facebook" /></a></p></div>]]></content:encoded>
			<wfw:commentRss>http://www.novainfosecportal.com/2012/02/06/shmoocon-2012-firetalks-%e2%80%93-update-8-videos-from-saturday/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Life as a Shmooby &#8211; My First ShmooCon</title>
		<link>http://www.novainfosecportal.com/2012/02/06/first-time-as-a-shmoonooby/</link>
		<comments>http://www.novainfosecportal.com/2012/02/06/first-time-as-a-shmoonooby/#comments</comments>
		<pubDate>Mon, 06 Feb 2012 15:30:50 +0000</pubDate>
		<dc:creator>judykavuo</dc:creator>
				<category><![CDATA[Infosec Conferences]]></category>
		<category><![CDATA[NoVA Meetups]]></category>
		<category><![CDATA[conference]]></category>
		<category><![CDATA[firetalks]]></category>
		<category><![CDATA[infosec]]></category>
		<category><![CDATA[shmoocon]]></category>

		<guid isPermaLink="false">http://www.novainfosecportal.com/?p=7805</guid>
		<description><![CDATA[I had the great opportunity to attend ShmooCon 2012 two weekends ago. As most of you know, the con offered various hacker models and infosec discussions. Friday and Saturday night activities concluded with a series of 15-minute sessions known as Firetalks in which the presenter cuts to the chase and discuses the core content of their presentation. Here are some of my lessons learned for the next Shmooby&#8230; Program Confusion: As a first timer, I was obviously confused about the whole program. It took me a while to figure out what I needed to do first and the different locations of the various activities and talks. Talk Overload: It&#8217;s ok &#8230; you do not have to attend all the talks. This is extremely exhausting and you miss all the other fun stuff like lock picking, Hack Fortress, and so forth. The sessions are usually recorded so you can always catch-up on what you missed later. Stressful Commute: If you are a local, I recommend staying at the hotel if possible as it ensures you do not get burned out with the commute each day. This also gives you extra cycles to network with others in the evening as well as [...]]]></description>
			<content:encoded><![CDATA[<div class="tweetthis" style="text-align:left;"><p> <a target="_blank" rel="nofollow" class="tt" href="http://twitter.com/intent/tweet?text=Life+as+a+Shmooby+%E2%80%93+My+First+ShmooCon+http%3A%2F%2Fj.mp%2FwkFb5O" title="Post to Twitter"><img class="nothumb" src="http://www.novainfosecportal.com/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro4.png" alt="Post to Twitter" /></a> <a target="_blank" rel="nofollow" class="tt" href="http://www.facebook.com/share.php?u=http://www.novainfosecportal.com/2012/02/06/first-time-as-a-shmoonooby/&amp;t=Life+as+a+Shmooby+%E2%80%93+My+First+ShmooCon" title="Post to Facebook"><img class="nothumb" src="http://www.novainfosecportal.com/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro4.png" alt="Post to Facebook" /></a></p></div><p><a href="http://www.novainfosecportal.com/2012/02/06/first-time-as-a-shmoonooby/shmoocon-2012/" rel="attachment wp-att-7806"><img class="alignright size-medium wp-image-7806" src="http://www.novainfosecportal.com/wp-content/uploads/2012/01/ShmooCon-2012-300x111.png" alt="" width="252" height="163" /></a>I had the great opportunity to attend <a href="/event/shmoocon-conference-2/">ShmooCon 2012</a> two weekends ago. As most of you know, the con offered various hacker models and infosec discussions. Friday and Saturday night activities concluded with a series of 15-minute sessions known as <a href="/2011/12/13/shmoocon-2012-firetalks/">Firetalks</a> in which the presenter cuts to the chase and discuses the core content of their presentation.</p>
<p>Here are some of my lessons learned for the next Shmooby&#8230;</p>
<p><strong>Program Confusion:</strong> As a first timer, I was obviously confused about the whole program. It took me a while to figure out what I needed to do first and the different locations of the various activities and talks.</p>
<p><strong>Talk Overload:</strong> It&#8217;s ok &#8230; you do not have to attend all the talks. This is extremely exhausting and you miss all the other fun stuff like lock picking, Hack Fortress, and so forth. The sessions are usually recorded so you can always catch-up on what you missed later.</p>
<p><strong>Stressful Commute:</strong> If you are a local, I recommend staying at the hotel if possible as it ensures you do not get burned out with the commute each day. This also gives you extra cycles to network with others in the evening as well as adequate time to get ready for talks in the morning.</p>
<p><strong>Unintelligible Content:</strong> Don’t feel bad if you attend a talk and don&#8217;t understand the content. We all have our strengths and weaknesses when it comes to the different subjects in the infosec world.</p>
<p align="center"><em>#####</em></p>
<p align="center"><em>That&#8217;s it for now. Do you have any more advice for the next Shmooby? Please let us know in the comments below. Today’s post image is from the <a href="https://www.eff.org/">EFF.com</a>.</em></p>
<div class="tweetthis" style="text-align:left;"><p> <a target="_blank" rel="nofollow" class="tt" href="http://twitter.com/intent/tweet?text=Life+as+a+Shmooby+%E2%80%93+My+First+ShmooCon+http%3A%2F%2Fj.mp%2FwkFb5O" title="Post to Twitter"><img class="nothumb" src="http://www.novainfosecportal.com/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro4.png" alt="Post to Twitter" /></a> <a target="_blank" rel="nofollow" class="tt" href="http://www.facebook.com/share.php?u=http://www.novainfosecportal.com/2012/02/06/first-time-as-a-shmoonooby/&amp;t=Life+as+a+Shmooby+%E2%80%93+My+First+ShmooCon" title="Post to Facebook"><img class="nothumb" src="http://www.novainfosecportal.com/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro4.png" alt="Post to Facebook" /></a></p></div>]]></content:encoded>
			<wfw:commentRss>http://www.novainfosecportal.com/2012/02/06/first-time-as-a-shmoonooby/feed/</wfw:commentRss>
		<slash:comments>4</slash:comments>
		</item>
		<item>
		<title>ShmooCon 2012 FireTalks – Update 7 (Videos from Friday)</title>
		<link>http://www.novainfosecportal.com/2012/02/03/shmoocon-2012-firetalks-%e2%80%93-update-7-videos-from-friday/</link>
		<comments>http://www.novainfosecportal.com/2012/02/03/shmoocon-2012-firetalks-%e2%80%93-update-7-videos-from-friday/#comments</comments>
		<pubDate>Fri, 03 Feb 2012 15:30:17 +0000</pubDate>
		<dc:creator>grecs</dc:creator>
				<category><![CDATA[Infosec Conferences]]></category>
		<category><![CDATA[NoVA Meetups]]></category>
		<category><![CDATA[conference]]></category>
		<category><![CDATA[contest]]></category>
		<category><![CDATA[firetalks]]></category>
		<category><![CDATA[firetalks2012]]></category>
		<category><![CDATA[infosec]]></category>
		<category><![CDATA[shmoocon]]></category>
		<category><![CDATA[videos]]></category>

		<guid isPermaLink="false">http://www.novainfosecportal.com/?p=7812</guid>
		<description><![CDATA[Last night we put out a post with the ShmooCon 2012 FireTalks winners so this morning we thought we&#8217;d follow up with a quick article on some of the other talks that occurred last weekend. This post is dedicated to the talks on Friday night. Thanks to Bulb Security and IronGeek for recording and processing the videos so fast! And finally be sure to check back to the master Firetalks post. It provides the core content as well as quick links to all update blog posts.  Well on to the videos&#8230; &#8220;Exploiting PKI for Pentesters&#8221; by Thomas Hoffecker Based upon my hour long talk presented at DerbyCon and HackerCon. This 15 minute version is specifically aimed at pentesters. PKI provides a large source of information to pentesters. Signed and encrypted email establishes a level of trust. Many organizations employ PKI but do not provide much public information about it. Pentesters are already trained to find this information using the recon phase of pentesting. Analysis of public PKI certificates can provide information on the internal infrastructure of the target. While the target may have deployed a split DNS architecture many times only a single PKI system is deployed. If public certificates [...]]]></description>
			<content:encoded><![CDATA[<div class="tweetthis" style="text-align:left;"><p> <a target="_blank" rel="nofollow" class="tt" href="http://twitter.com/intent/tweet?text=ShmooCon+2012+FireTalks+%E2%80%93+Update+7+%28Videos+from+Friday%29+http%3A%2F%2Fj.mp%2Fx9C1Zf" title="Post to Twitter"><img class="nothumb" src="http://www.novainfosecportal.com/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro4.png" alt="Post to Twitter" /></a> <a target="_blank" rel="nofollow" class="tt" href="http://www.facebook.com/share.php?u=http://www.novainfosecportal.com/2012/02/03/shmoocon-2012-firetalks-%e2%80%93-update-7-videos-from-friday/&amp;t=ShmooCon+2012+FireTalks+%E2%80%93+Update+7+%28Videos+from+Friday%29" title="Post to Facebook"><img class="nothumb" src="http://www.novainfosecportal.com/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro4.png" alt="Post to Facebook" /></a></p></div><p><img class="alignright size-medium wp-image-7895" title="Yes ... I Went There." src="http://www.novainfosecportal.com/wp-content/uploads/2012/02/rebecca-black-friday-300x250.jpg" alt="Picture of Rebecca Black" width="143" height="120" />Last night we put out a post with the ShmooCon 2012 FireTalks winners so this morning we thought we&#8217;d follow up with a quick article on some of the other talks that occurred last weekend. This post is dedicated to the talks on Friday night. Thanks to <a href="http://www.bulbsecurity.com/">Bulb Security</a> and <a href="http://www.irongeek.com/">IronGeek</a> for recording and processing the videos so fast!</p>
<p>And finally be sure to check back to the <a href="/2011/12/13/shmoocon-2012-firetalks/">master Firetalks post</a>. It provides the core content as well as quick links to all update blog posts.  Well on to the videos&#8230;</p>
<h2 style="text-align: center;">&#8220;Exploiting PKI for Pentesters&#8221;</h2>
<p style="text-align: center;">by Thomas Hoffecker</p>
<p>Based upon my hour long talk presented at DerbyCon and HackerCon. This 15 minute version is specifically aimed at pentesters. PKI provides a large source of information to pentesters. Signed and encrypted email establishes a level of trust. Many organizations employ PKI but do not provide much public information about it. Pentesters are already trained to find this information using the recon phase of pentesting. Analysis of public PKI certificates can provide information on the internal infrastructure of the target. While the target may have deployed a split DNS architecture many times only a single PKI system is deployed. If public certificates are be accessed then potential servers and other interesting equipment can be identified since the PKI cert will contain the fully qualified domain name. While phishing success rates remain high, utilizing encrypted or signed email makes an email that much more trust worthy. It also ensures that spam and virus scanners at the mail server cannot read the email contents. Encrypting the email provides assurance that only the targeted subject can open and read the email. User security awareness training teaches users that signed and encrypted email is absolutely safe. Beyond my existing talks&#8217; content I will demonstrate means to find information of specific corporate PKI implementations. Provide examples to obtain PKI email certificates from public sources for those that do not publish or otherwise distribute PKI email certificates. I will also discuss recently publicly revealed attack against smartcards that store PKI certificates, examples of these smart cards include the DoD CAC and the HSPD-12 PIV cards.</p>
<p>    <iframe src="http://player.vimeo.com/video/35860021" width="576" height="324" frameborder="0" webkitAllowFullScreen mozallowfullscreen allowFullScreen></iframe></p>
<h2 style="text-align: center;">&#8220;Bending SAP Over &amp; Extracting What You Need!&#8221;</h2>
<p style="text-align: center;">by Chris John Riley</p>
<p>At the heart of any large enterprise, lies a platform misunderstood and feared by all but the bravest systems administrators. Home to a wealth of information, and key to infinite wisdom. This platform is SAP. For years this system has been amongst the many “red pen” items on penetration tests and audits alike… but no more! We will no longer accept the cries of “Business critical, out-of-scope”. The time for SAP has come, the cross-hairs of attackers are firmly focused on the soft underbelly that is ERM, and it’s our duty to follow suit. Join me as we take the first steps into exploring SAP, extracting information and popping shells. Leave your Nessus license at the door! It’s time to scrub this SAP system clean with SOAP!</p>
<p>    <iframe src="http://player.vimeo.com/video/35863379" width="576" height="324" frameborder="0" webkitAllowFullScreen mozallowfullscreen allowFullScreen></iframe></p>
<h2 style="text-align: center;">&#8220;ROUTERPWN: A Mobile Router Exploitation Framework&#8221;</h2>
<p style="text-align: center;">by Pedro Joaquin</p>
<p>Routerpwn is a mobile exploitation framework that helps you in the exploitation of vulnerabilities in network devices such as residential and commercial routers, switches and access points. It is a compilation of ready to run local and remote web exploits. Programmed in Javascript and HTML in order to run in all “smart phones” and mobile Internet devices, including Android, iPhone, BlackBerry and all tablets. You can even store it off line for local exploitation without Internet connection.</p>
<p>    <iframe src="http://player.vimeo.com/video/35884179" width="576" height="324" frameborder="0" webkitAllowFullScreen mozallowfullscreen allowFullScreen></iframe></p>
<h2 style="text-align: center;">&#8220;Security Is Like An Onion, That’s Why it Makes You Cry&#8221;</h2>
<p style="text-align: center;">by Michele Chubirka</p>
<p>Why is the security industry so full of fail? We spend millions of dollars on firewalls, IPS, IDS, DLP, professional penetration tests and assessments, vulnerability and compliance tools and at the end of the day, the weakest link is the user and his or her inability to make the right choices. It’s enough to make a security engineer cry. The one thing you can depend upon in an enterprise is that many of our users, even with training, will still make the wrong choices. They still click on links they shouldn’t, respond to phishing scams, open documents without thinking, post too much information on Twitter and Facebook, use their pet’s name as passwords, etc…. But what if this isn’t because users hate us or are too stupid? What if all our complaints about not being heard and our instructions regarding the best security practices have more to do with our failure to understand modern neuroscience and the human mind’s resistance to change?</p>
<p>    <iframe src="http://player.vimeo.com/video/35932909" width="576" height="324" frameborder="0" webkitAllowFullScreen mozallowfullscreen allowFullScreen></iframe></p>
<h2 style="text-align: center;">&#8220;Five Ways We’re Killing Our Own Privacy&#8221;</h2>
<p style="text-align: center;">by Michael Schearer</p>
<p>At DEFCON, I talked about how our privacy rights are under attack. Our sea of liberty is drying up due to the ever-encroaching power of the government. A litany of abuses continue to chip away at the historical foundations of privacy: administrative searches as pretexts to avoid search warrants, national security letter, and suffocating public surveillance just to name a few. Yet the government alone is not the only source of our ever-diminishing privacy. In this talk, I turn my attention…to you. Yes, believe it or not, you (and me) and the other 310 million of us in this country are also responsible for our diminished expectation of privacy. Why are we responsible? Who wants our information, and why is it so valuable? Is there anything we can do to stem the tide?</p>
<p>    <iframe src="http://player.vimeo.com/video/35933179" width="576" height="324" frameborder="0" webkitAllowFullScreen mozallowfullscreen allowFullScreen></iframe></p>
<h2 style="text-align: center;">&#8220;How Do You Know Your Colo Isn’t &#8216;Inside&#8217; Your Cabinet, A Simple Alarm Using Teensy&#8221;</h2>
<p style="text-align: center;">by David Zendzian</p>
<p>As everyone knows, the security of your equipment starts with securing it physically. To accomplish that many will lease cabinet or cage space within the a commercial colo. However, all colos require access to your equipment (in case of fire, or other emergency). Even withstanding the emergency access I have seen colo’s enter cages and cabinets to run cables or to shorten their walk around a row in the facility. Other than installing a commercial alarm or a motion sensor camera, both of which are expensive solutions, what can be done to monitor access into your cabinet or cage. This talk will show how we have used a Teensy board from PJRC to build a simple alarm system that can be easily integrated into whatever host / network monitoring system already configured for your network.</p>
<p>    <iframe src="http://player.vimeo.com/video/35933398" width="576" height="324" frameborder="0" webkitAllowFullScreen mozallowfullscreen allowFullScreen></iframe></p>
<p style="text-align: center;">#####</p>
<p style="text-align: center;"><em>An interesting thing happened this year &#8230; none of the talks on Friday night won. Maybe this gave the Saturday presenters time to pay the judges off. <img src='http://www.novainfosecportal.com/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' />  This post&#8217;s featured image is from <a href="http://blogs.babble.com/famecrawler/2011/03/25/rebecca-black-friday-genius-lady-gaga-million-dollars-teen-sensation/">Babble.com</a>. See ya&#8230;</em></p>
<div class="tweetthis" style="text-align:left;"><p> <a target="_blank" rel="nofollow" class="tt" href="http://twitter.com/intent/tweet?text=ShmooCon+2012+FireTalks+%E2%80%93+Update+7+%28Videos+from+Friday%29+http%3A%2F%2Fj.mp%2Fx9C1Zf" title="Post to Twitter"><img class="nothumb" src="http://www.novainfosecportal.com/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro4.png" alt="Post to Twitter" /></a> <a target="_blank" rel="nofollow" class="tt" href="http://www.facebook.com/share.php?u=http://www.novainfosecportal.com/2012/02/03/shmoocon-2012-firetalks-%e2%80%93-update-7-videos-from-friday/&amp;t=ShmooCon+2012+FireTalks+%E2%80%93+Update+7+%28Videos+from+Friday%29" title="Post to Facebook"><img class="nothumb" src="http://www.novainfosecportal.com/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro4.png" alt="Post to Facebook" /></a></p></div>]]></content:encoded>
			<wfw:commentRss>http://www.novainfosecportal.com/2012/02/03/shmoocon-2012-firetalks-%e2%80%93-update-7-videos-from-friday/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>ShmooCon 2012 FireTalks – Update 6 (Winners)</title>
		<link>http://www.novainfosecportal.com/2012/02/02/shmoocon-2012-firetalks-%e2%80%93-update-6-winners/</link>
		<comments>http://www.novainfosecportal.com/2012/02/02/shmoocon-2012-firetalks-%e2%80%93-update-6-winners/#comments</comments>
		<pubDate>Fri, 03 Feb 2012 03:00:09 +0000</pubDate>
		<dc:creator>grecs</dc:creator>
				<category><![CDATA[Infosec Conferences]]></category>
		<category><![CDATA[NoVA Meetups]]></category>
		<category><![CDATA[conference]]></category>
		<category><![CDATA[contest]]></category>
		<category><![CDATA[firetalks]]></category>
		<category><![CDATA[firetalks2012]]></category>
		<category><![CDATA[infosec]]></category>
		<category><![CDATA[shmoocon]]></category>

		<guid isPermaLink="false">http://www.novainfosecportal.com/?p=7828</guid>
		<description><![CDATA[Well you&#8217;ve probably already heard by now but just in case you didn&#8217;t &#8230; here are the winners for this year&#8217;s ShmooCon 2012 Firetalks. Also, be sure to check back to the master Firetalks post. It provides the core content as well as quick links to all update blog posts. Well on to the winners&#8230; Win: &#8220;Remotely Exploiting the PHY Layer&#8221; by Travis Goodspeed Packet-in-Packet injections are a new type of in-band signalling attack, one which allows a packet to be injected into a remote wireless network through the body of any other type of packet. The attacker never needs a radio, and no software or hardware bugs are necessary for the injection to occur. The attack works on perfectly standard-compliant implementations of 802.15.4, 802.11B, and most other wireless protocols. Travis won a Parrot AR.Drone Quadricopter along with an iPod Touch to control it. Thanks to Milton Security Group supplying this awesome prize! Place: &#8220;Cracking WiFi Protected Setup For Fun and Profit&#8221; by Craig Heffner This talk will detail the recently disclosed vulnerability in WiFi Protected Setup which allows wireless attackers to recover plain text WPA/WPA2 pass phrases in just a few hours, as well as my WPS brute force [...]]]></description>
			<content:encoded><![CDATA[<div class="tweetthis" style="text-align:left;"><p> <a target="_blank" rel="nofollow" class="tt" href="http://twitter.com/intent/tweet?text=ShmooCon+2012+FireTalks+%E2%80%93+Update+6+%28Winners%29+http%3A%2F%2Fj.mp%2FzgCcvB" title="Post to Twitter"><img class="nothumb" src="http://www.novainfosecportal.com/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro4.png" alt="Post to Twitter" /></a> <a target="_blank" rel="nofollow" class="tt" href="http://www.facebook.com/share.php?u=http://www.novainfosecportal.com/2012/02/02/shmoocon-2012-firetalks-%e2%80%93-update-6-winners/&amp;t=ShmooCon+2012+FireTalks+%E2%80%93+Update+6+%28Winners%29" title="Post to Facebook"><img class="nothumb" src="http://www.novainfosecportal.com/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro4.png" alt="Post to Facebook" /></a></p></div><p><img class="alignright size-medium wp-image-7532" title="The Prizes" src="http://www.novainfosecportal.com/wp-content/uploads/2012/01/prize-263x300.gif" alt="Girl Holding Up Trophy" width="86" height="99" />Well you&#8217;ve probably already heard by now but just in case you didn&#8217;t &#8230; here are the winners for this year&#8217;s ShmooCon 2012 Firetalks. Also, be sure to check back to the <a href="/2011/12/13/shmoocon-2012-firetalks/">master Firetalks post</a>. It provides the core content as well as quick links to all update blog posts.</p>
<p>Well on to the winners&#8230;</p>
<h2 style="text-align: center;">Win: &#8220;Remotely Exploiting the PHY Layer&#8221;</h2>
<p style="text-align: center;">by Travis Goodspeed</p>
<p><a href="http://www.miltonsecurity.com/"><img class="alignright size-full wp-image-7499" title="Milton Security Group" src="http://www.novainfosecportal.com/wp-content/uploads/2012/01/milton.png" alt="Milton Security Group Logo" width="186" height="62" /></a>Packet-in-Packet injections are a new type of in-band signalling attack, one which allows a packet to be injected into a remote wireless network through the body of any other type of packet. The attacker never needs a radio, and no software or hardware bugs are necessary for the injection to occur. The attack works on perfectly standard-compliant implementations of 802.15.4, 802.11B, and most other wireless protocols.</p>
<p>Travis won a <a href="http://www.amazon.com/Parrot-AR-Drone-Quadricopter-Controlled-Android/dp/B003ZVSHB0">Parrot AR.Drone Quadricopter</a> along with an iPod Touch to control it. Thanks to <a href="http://www.miltonsecurity.com/">Milton Security Group</a> supplying this awesome prize!</p>
<p>    <iframe src="http://player.vimeo.com/video/35998128" width="576" height="324" frameborder="0" webkitAllowFullScreen mozallowfullscreen allowFullScreen></iframe></p>
<h2 style="text-align: center;">Place: &#8220;Cracking WiFi Protected Setup For Fun and Profit&#8221;</h2>
<p style="text-align: center;">by Craig Heffner</p>
<p><img class="alignright size-medium wp-image-7513" title="Lars Consulting, Leverage Consulting &amp; Associates, &amp; Dirty Security" src="http://www.novainfosecportal.com/wp-content/uploads/2012/01/larslevdirty-300x228.png" alt="Combined Logos for Lars, Leverage, &amp; DirtySec" width="129" height="99" />This talk will detail the recently disclosed vulnerability in WiFi Protected Setup which allows wireless attackers to recover plain text WPA/WPA2 pass phrases in just a few hours, as well as my WPS brute force attack tool, Reaver.</p>
<p>Craig picked up a netbook with the latest version of BackTrack pre-installed. Thanks to <a href="http://dirtysec.org/">Dirty Security</a>, <a href="http://lares.com/">Lares Consulting</a>, and <a href="http://www.myleverage.org/">Leverage Consulting &amp; Associates</a> for supporting this prize. [Oh and Craig ... please <a href="/contact-us/">contact us</a> so we can arrange to ship the netbook to you.]</p>
<p>    <iframe src="http://player.vimeo.com/video/35980306" width="576" height="324" frameborder="0" webkitAllowFullScreen mozallowfullscreen allowFullScreen></iframe></p>
<h2 style="text-align: center;">Show: &#8220;Ressurecting Ettercap&#8221;</h2>
<p style="text-align: center;">by Eric Milam</p>
<p><img class="alignright size-medium wp-image-7502" title="Liquidmatrix Security Digest" src="http://www.novainfosecportal.com/wp-content/uploads/2012/01/liquidmatrixlogo-300x39.png" alt="Liquidmatrix Logo" width="307" height="40" />In December 2011 Ettercap had its first official release in almost 6 years. This talk will discuss how I went from the creation of a simple bash script to taking over one of the world most loved penetration testing tools. Topics will include, easy-creds, communications with Alor &amp; Naga and the new team charged with moving the project forward.</p>
<p>Eric took home the &#8220;Sad Trombone&#8221; award, basically one of <a href="https://www.apple.com/ipodtouch/">Apple&#8217;s new iPad Minis</a>. <img src='http://www.novainfosecportal.com/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' />  Thanks to <a href="http://www.liquidmatrix.org/blog/">Liquidmatrix Security Digest</a> for supplying the third place prize!</p>
<p>    <iframe src="http://player.vimeo.com/video/35989154" width="576" height="324" frameborder="0" webkitAllowFullScreen mozallowfullscreen allowFullScreen></iframe></p>
<p style="text-align: center;">#####</p>
<p style="text-align: center;"><em>Congratulations to all the winners! Today’s featured image is from <a href="http://sasatien.blogspot.com/2011/03/prizes-awaiting-creative-photo-contest.html">Sasatien.Blogspot.com</a>. See ya!</em></p>
<div class="tweetthis" style="text-align:left;"><p> <a target="_blank" rel="nofollow" class="tt" href="http://twitter.com/intent/tweet?text=ShmooCon+2012+FireTalks+%E2%80%93+Update+6+%28Winners%29+http%3A%2F%2Fj.mp%2FzgCcvB" title="Post to Twitter"><img class="nothumb" src="http://www.novainfosecportal.com/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro4.png" alt="Post to Twitter" /></a> <a target="_blank" rel="nofollow" class="tt" href="http://www.facebook.com/share.php?u=http://www.novainfosecportal.com/2012/02/02/shmoocon-2012-firetalks-%e2%80%93-update-6-winners/&amp;t=ShmooCon+2012+FireTalks+%E2%80%93+Update+6+%28Winners%29" title="Post to Facebook"><img class="nothumb" src="http://www.novainfosecportal.com/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro4.png" alt="Post to Facebook" /></a></p></div>]]></content:encoded>
			<wfw:commentRss>http://www.novainfosecportal.com/2012/02/02/shmoocon-2012-firetalks-%e2%80%93-update-6-winners/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Fight Club Rules for ShmooCon 2012</title>
		<link>http://www.novainfosecportal.com/2012/01/27/shmoocon-2012-fight-club-rules/</link>
		<comments>http://www.novainfosecportal.com/2012/01/27/shmoocon-2012-fight-club-rules/#comments</comments>
		<pubDate>Fri, 27 Jan 2012 15:30:58 +0000</pubDate>
		<dc:creator>grecs</dc:creator>
				<category><![CDATA[Infosec Conferences]]></category>
		<category><![CDATA[NoVA Meetups]]></category>
		<category><![CDATA[fightclub]]></category>
		<category><![CDATA[firetalks]]></category>
		<category><![CDATA[infosec]]></category>
		<category><![CDATA[lockpick]]></category>
		<category><![CDATA[shmoocon]]></category>
		<category><![CDATA[twitter]]></category>

		<guid isPermaLink="false">http://www.novainfosecportal.com/?p=7788</guid>
		<description><![CDATA[Yes, the day is finally upon us &#8230; ShmooCon there will be! I&#8217;ve been lucky enough to attend the past five or six years of this awesome conference. You could almost call me a veteran attendee &#8230; and as such I wanted to pass on a bit of advice for anyone heading down to DC today. In honor of the movie Fight Club I present to you the &#8230; &#8220;The Rules of ShmooCon&#8221; 1st RULE: You do not talk about SHMOOCON. &#8230; unless it&#8217;s on Twitter and you use the #shmoocon hashtag &#8230; 2nd RULE: You DO NOT talk about SHMOOCON. (see the 1st Rule for details) 3rd RULE: Only three talks to a day. And on a bit more serious side&#8230; The first time I attended ShmooCon, I over-scheduled myself by focusing too much on the scheduled talks. Overall, I probably attended about 20 talks. At the end each day, I was exhausted and just headed home to recover. What I hadn’t realized was that I only took part in a small portion of what the conference had to offer. Instead I&#8217;m suggesting that you attend just three talks each day (no cheating here) and spend the rest of [...]]]></description>
			<content:encoded><![CDATA[<div class="tweetthis" style="text-align:left;"><p> <a target="_blank" rel="nofollow" class="tt" href="http://twitter.com/intent/tweet?text=Fight+Club+Rules+for+ShmooCon+2012+http%3A%2F%2Fj.mp%2FwGydUy" title="Post to Twitter"><img class="nothumb" src="http://www.novainfosecportal.com/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro4.png" alt="Post to Twitter" /></a> <a target="_blank" rel="nofollow" class="tt" href="http://www.facebook.com/share.php?u=http://www.novainfosecportal.com/2012/01/27/shmoocon-2012-fight-club-rules/&amp;t=Fight+Club+Rules+for+ShmooCon+2012" title="Post to Facebook"><img class="nothumb" src="http://www.novainfosecportal.com/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro4.png" alt="Post to Facebook" /></a></p></div><p><img class="alignright size-full wp-image-7796" title="Fight Club" src="http://www.novainfosecportal.com/wp-content/uploads/2012/01/FightClub.jpg" alt="Pink Soap with Fight Club Written on It" width="160" height="113" />Yes, the day is finally upon us &#8230; ShmooCon there will be! I&#8217;ve been lucky enough to attend the past five or six years of this awesome conference. You could almost call me a veteran attendee &#8230; and as such I wanted to pass on a bit of advice for anyone heading down to DC today. In honor of the movie Fight Club I present to you the &#8230;</p>
<p style="text-align: center;"><strong>&#8220;The Rules of ShmooCon&#8221;</strong></p>
<p><strong>1st RULE:</strong> You do not talk about SHMOOCON.</p>
<p style="padding-left: 30px;">&#8230; unless it&#8217;s on Twitter and you use the #<a href="https://twitter.com/#!/search/%23shmoocon">shmoocon</a> hashtag &#8230;</p>
<p><strong>2nd RULE:</strong> You DO NOT talk about SHMOOCON.</p>
<p style="padding-left: 30px;">(see the 1st Rule for details)</p>
<p><strong>3rd RULE:</strong> Only three talks to a day.</p>
<p style="padding-left: 30px;">And on a bit more serious side&#8230; The first time I attended ShmooCon, I over-scheduled myself by focusing too much on the scheduled talks. Overall, I probably attended about 20 talks. At the end each day, I was exhausted and just headed home to recover. What I hadn’t realized was that I only took part in a small portion of what the conference had to offer.</p>
<p style="padding-left: 30px;">Instead I&#8217;m suggesting that you attend just three talks each day (no cheating here) and spend the rest of the time taking in everything else ShmooCon has to offer &#8230; Firetalks, Hack Fortress, Lockpick Village, Shmooganography, &#8230; and most of all &#8230; networking with other hackers and just enjoying yourself.</p>
<p><strong>4th RULE:</strong> If there is a party in the executive suite and someone breaks the genitalia-shaped vase, the party is over.</p>
<p style="padding-left: 30px;">&#8230; or maybe not.</p>
<p><strong>5th RULE:</strong> Turn off what you don&#8217;t need.</p>
<p style="padding-left: 30px;">Remember &#8230; this is a hacker conference so be cautious with our usual array of electronic goods we carry around. You need to be very careful of how your devices will interact with anything at the conference. With that in mind, I recommend that you disable any and all connections to your devices (Bluetooth, WiFi, NICs, USB ports, etc.) and only turn them on when needed.</p>
<p><strong>6th RULE:</strong> Don&#8217;t f*ck with the con&#8217;s secure wifi, local ATMs, or the hotel&#8217;s information kiosks.</p>
<p style="padding-left: 30px;">We want the good folks at the Hilton to have us back next year (and maybe improve cellular coverage for us) so please don&#8217;t ruin it for the rest of us. Of course as I write this late Thursday night, I see we&#8217;ve already broken the kiosks part of this rule.</p>
<p><strong>7th RULE:</strong> Always wear a cheap &#8220;Hello I am &#8230;&#8221; sticker with your your Twitter name and avatar.</p>
<p style="padding-left: 30px;">This is not so people recognize you &#8230; but for you to recognize others. I know &#8230; most of us are pretty introverted but this is a great time to get out from behind our computers and meet many of those we regularly interact with online. Here&#8217;s the magic move to start a conversation with anyone at the con. Find someone with a familiar avatar and say, &#8220;Hi, I&#8217;m [name] from [location]. How&#8217;d you get your ShmooCon ticket?&#8221;</p>
<p><strong>8th RULE:</strong> Talks will go on as long as they have to.</p>
<p style="padding-left: 30px;">&#8230; unless it&#8217;s a Firetalks &#8230; those only last 15 minutes. For all other talks you might risk getting pelted by a barrage of spongy darts from modded Nerf guns if you go over time. Of course that could happen at the Firetalks too.</p>
<p><strong>9th RULE:</strong> Always connect securely.</p>
<p style="padding-left: 30px;">If you absolutely need to connect to the Internet, the secure ShmooCon network is a good start but it&#8217;s probably better to use a cellular network. Of course cellular signal is another issue as I mentioned above so you may want to invest in two or three other mifi pay-as-you-go access points. I&#8217;ve heard Virgin Mobile/Sprint, T-Mobile and Clear usually work well. And just to be safe you might want to VPN out as well (think the DEFCON allegations we had back in August). For those that don&#8217;t have VPNs provided through their company, I&#8217;ve <a href="/2010/07/20/starbucks-vpn-options-for-wifi-security/">looked at a few options before</a> (see the comments there for other suggestions too).</p>
<p><strong>10th RULE:</strong> If this is your first time attending SHMOOCON, you HAVE to get on your buddy&#8217;s shoulders during the opening or closing ceremonies and yell &#8220;Bow to my firewall!&#8221; at the top of your lungs.</p>
<p style="text-align: center;">#####</p>
<p style="text-align: center;"><em>Well that&#8217;s all I got&#8230; Can you think of any additional &#8220;Rules of ShmooCon?&#8221; Let us know in the comments below. Today&#8217;s image came from <a href="http://www.diggingforfire.net/FightClub/">DiggingForFire.net</a> (and they also have the original Fight Club rules reprinted there).</em></p>
<div class="tweetthis" style="text-align:left;"><p> <a target="_blank" rel="nofollow" class="tt" href="http://twitter.com/intent/tweet?text=Fight+Club+Rules+for+ShmooCon+2012+http%3A%2F%2Fj.mp%2FwGydUy" title="Post to Twitter"><img class="nothumb" src="http://www.novainfosecportal.com/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro4.png" alt="Post to Twitter" /></a> <a target="_blank" rel="nofollow" class="tt" href="http://www.facebook.com/share.php?u=http://www.novainfosecportal.com/2012/01/27/shmoocon-2012-fight-club-rules/&amp;t=Fight+Club+Rules+for+ShmooCon+2012" title="Post to Facebook"><img class="nothumb" src="http://www.novainfosecportal.com/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro4.png" alt="Post to Facebook" /></a></p></div>]]></content:encoded>
			<wfw:commentRss>http://www.novainfosecportal.com/2012/01/27/shmoocon-2012-fight-club-rules/feed/</wfw:commentRss>
		<slash:comments>6</slash:comments>
		</item>
		<item>
		<title>ShmooCon 2012 FireTalks – Update 5 (Schedule)</title>
		<link>http://www.novainfosecportal.com/2012/01/25/shmoocon-2012-firetalks-%e2%80%93-update-5-schedule/</link>
		<comments>http://www.novainfosecportal.com/2012/01/25/shmoocon-2012-firetalks-%e2%80%93-update-5-schedule/#comments</comments>
		<pubDate>Thu, 26 Jan 2012 04:30:10 +0000</pubDate>
		<dc:creator>grecs</dc:creator>
				<category><![CDATA[Infosec Conferences]]></category>
		<category><![CDATA[NoVA Meetups]]></category>
		<category><![CDATA[conference contest firetalks]]></category>
		<category><![CDATA[firetalks2012]]></category>
		<category><![CDATA[infosec]]></category>
		<category><![CDATA[schedule]]></category>
		<category><![CDATA[shmoocon]]></category>

		<guid isPermaLink="false">http://www.novainfosecportal.com/?p=7734</guid>
		<description><![CDATA[Well &#8230; we are withing two days of ShmooCon and the first night of Firetalks and I&#8217;m actually a little ahead this year. I don&#8217;t think I got last year&#8217;s schedule out until late Thursday night! Anyway, below you&#8217;ll find the schedule for the talks. Also some people might have heard that you can attend the Firetalks without a ShmooCon badge. Unfortunately, this is not true. You MUST have a badge to attend due to all those contracts, insurance, and other fun biz stuff associated with holding an event as big as ShmooCon. If you want to keep up with all the Firetalks going-ons throughout the weekend, you might want to check back to the master Firetalks post or subscribing to one of our “feeds” (@novainfosec on Twitter, our FaceBook Page, or RSS). But given the craziness of cons I&#8217;d recommend just following my tweets (@grecs) or the #firetalks tag. Finally, I want to put out one last reminder for the ShmooCon Epilogue event that is being held the Monday after ShmooCon. If you are from out of town and can still grab one of the free tickets, why not extend your stay an extra day and get another dose of [...]]]></description>
			<content:encoded><![CDATA[<div class="tweetthis" style="text-align:left;"><p> <a target="_blank" rel="nofollow" class="tt" href="http://twitter.com/intent/tweet?text=ShmooCon+2012+FireTalks+%E2%80%93+Update+5+%28Schedule%29+http%3A%2F%2Fj.mp%2FwD7CN9" title="Post to Twitter"><img class="nothumb" src="http://www.novainfosecportal.com/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro4.png" alt="Post to Twitter" /></a> <a target="_blank" rel="nofollow" class="tt" href="http://www.facebook.com/share.php?u=http://www.novainfosecportal.com/2012/01/25/shmoocon-2012-firetalks-%e2%80%93-update-5-schedule/&amp;t=ShmooCon+2012+FireTalks+%E2%80%93+Update+5+%28Schedule%29" title="Post to Facebook"><img class="nothumb" src="http://www.novainfosecportal.com/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro4.png" alt="Post to Facebook" /></a></p></div><p><img class="alignright size-medium wp-image-7752" title="Hopefully We Can Follow One of These" src="http://www.novainfosecportal.com/wp-content/uploads/2012/01/schedule-300x300.jpg" alt="Schedule Book, Pencil, &amp; Clock" width="126" height="126" />Well &#8230; we are withing two days of ShmooCon and the first night of Firetalks and I&#8217;m actually a little ahead this year. I don&#8217;t think I got last year&#8217;s schedule out until late Thursday night! <img src='http://www.novainfosecportal.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' />  Anyway, below you&#8217;ll find the schedule for the talks.</p>
<p>Also some people might have heard that you can attend the Firetalks without a ShmooCon badge. Unfortunately, this is not true. <strong>You MUST have a badge to attend</strong> due to all those contracts, insurance, and other fun biz stuff associated with holding an event as big as ShmooCon.</p>
<p>If you want to keep up with all the Firetalks going-ons throughout the weekend, you might want to check back to the <a href="/2011/12/13/shmoocon-2012-firetalks/">master Firetalks post</a> or subscribing to one of our “feeds” (@<a href="http://twitter.com/novainfosec">novainfosec</a> on Twitter, our <a href="http://www.facebook.com/novainfosec">FaceBook Page</a>, or <a href="http://feeds.feedburner.com/novainfosecportalblog">RSS</a>). But given the craziness of cons I&#8217;d recommend just following my tweets (@<a href="http://twitter.com/grecs">grecs</a>) or the #<a href="http://twitter.com/#%21/search/%23firetalks">firetalks</a> tag.</p>
<p>Finally, I want to put out one last reminder for the ShmooCon Epilogue event that is being held the Monday after ShmooCon. If you are from out of town and can still grab one of the free tickets, why not extend your stay an extra day and get another dose of great talks and networking with fellow hackers. See the <a href="http://novahackers.blogspot.com/2011/12/shmoocon-epilogue.html">NoVA Hackers post</a> for all the details.</p>
<p>Well and onto the schedule&#8230;</p>
<h2>Friday</h2>
<p><em><strong>Note 1:</strong> The times for Friday are currently tentative as we noticed the regular con schedule will probably push these times back. I&#8217;ll be keeping this post updated so please check back or follow me (@<a href="http://twitter.com/grecs">grecs</a>) or the official #<a href="http://twitter.com/#%21/search/%23firetalks">firetalks</a> tag on Twitter.</em></p>
<p><em><strong>Note 2:</strong> Updated the times below&#8230;</em></p>
<p>8:30: Opening</p>
<p>8:40: &#8220;How Do You Know Your Colo Isn’t “Inside” Your Cabinet, A Simple Alarm Using Teensy&#8221; by David Zendzian</p>
<p>9:00: &#8220;Bending SAP Over &amp; Extracting What You Need!&#8221; by Chris John Riley</p>
<p>9:20: &#8220;ROUTERPWN: A Mobile Router Exploitation Framework&#8221; by Pedro Joaquin</p>
<p>9:40: &#8220;Security Is Like An Onion, That’s Why it Makes You Cry&#8221; by Michele Chubirka</p>
<p>10:00: &#8220;Five Ways We’re Killing Our Own Privacy&#8221; by Michael Schearer</p>
<h2>Saturday</h2>
<p>6:30 Opening</p>
<p>6:40 &#8220;Cracking WiFi Protected Setup For Fun and Profit&#8221; by Craig Heffner</p>
<p>7:00 &#8220;Passive Aggressive Pwnage: Sniffing the Net for Fun &amp; Profit&#8221; by John Sawyer</p>
<p>7:20 &#8220;Ressurecting Ettercap&#8221; by Eric Milam</p>
<p>7:40 &#8220;Security Onion: Network Security Monitoring in Minutes&#8221; by Doug Burks</p>
<p>8:00 &#8220;Remotely Exploiting the PHY Layer&#8221; by Travis Goodspeed</p>
<p>If you are a speaker and cannot make the scheduled slot, please let me know ASAP via mentioning it to me at @<a href="http://twitter.com/grecs">grecs</a> on Twitter. Also if you are an alternate you&#8217;ll need to be present both nights. And just to make things run smoothly, we ask that all speakers be present at least two talks prior to your scheduled time slot. We will have reserve seats for you in to the first row to the left of the podium if you are facing the stage.</p>
<p style="text-align: center;">#####</p>
<p style="text-align: center;"><em>Can&#8217;t believe ShmooCon is almost here! See ya all on Friday&#8230; Today&#8217;s post picture is from <a href="http://www.eecs.harvard.edu/~uribraun/schedule/">Harvard.edu</a>.</em></p>
<div class="tweetthis" style="text-align:left;"><p> <a target="_blank" rel="nofollow" class="tt" href="http://twitter.com/intent/tweet?text=ShmooCon+2012+FireTalks+%E2%80%93+Update+5+%28Schedule%29+http%3A%2F%2Fj.mp%2FwD7CN9" title="Post to Twitter"><img class="nothumb" src="http://www.novainfosecportal.com/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro4.png" alt="Post to Twitter" /></a> <a target="_blank" rel="nofollow" class="tt" href="http://www.facebook.com/share.php?u=http://www.novainfosecportal.com/2012/01/25/shmoocon-2012-firetalks-%e2%80%93-update-5-schedule/&amp;t=ShmooCon+2012+FireTalks+%E2%80%93+Update+5+%28Schedule%29" title="Post to Facebook"><img class="nothumb" src="http://www.novainfosecportal.com/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro4.png" alt="Post to Facebook" /></a></p></div>]]></content:encoded>
			<wfw:commentRss>http://www.novainfosecportal.com/2012/01/25/shmoocon-2012-firetalks-%e2%80%93-update-5-schedule/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>ShmooCon 2012 FireTalks – Update 4 (Second Round Speaker Announcements)</title>
		<link>http://www.novainfosecportal.com/2012/01/20/shmoocon-2012-firetalks-%e2%80%93-update-4-second-round-speaker-announcements/</link>
		<comments>http://www.novainfosecportal.com/2012/01/20/shmoocon-2012-firetalks-%e2%80%93-update-4-second-round-speaker-announcements/#comments</comments>
		<pubDate>Fri, 20 Jan 2012 15:30:41 +0000</pubDate>
		<dc:creator>grecs</dc:creator>
				<category><![CDATA[Infosec Conferences]]></category>
		<category><![CDATA[NoVA Meetups]]></category>
		<category><![CDATA[conference]]></category>
		<category><![CDATA[contest]]></category>
		<category><![CDATA[firetalks]]></category>
		<category><![CDATA[firetalks2012]]></category>
		<category><![CDATA[infosec]]></category>
		<category><![CDATA[prize]]></category>
		<category><![CDATA[shmoocon]]></category>

		<guid isPermaLink="false">http://www.novainfosecportal.com/?p=7725</guid>
		<description><![CDATA[Just a short post to announce the second round speakers for this year&#8217;s ShmooCon Firetalks&#8230; With several more submissions between our last post and the CFP due date, the selection committee has been hard at work trying to pull together a diverse program with the most interesting talks combined with a good mix of established and new speakers. But before we get on to the talks I just wanted to thank the selection committee for all the hard work they put in over the last few weeks. Since some may not want their full names out there, I&#8217;ll just list them all by their Twitter handles &#8230; @dystonic, @jack_daniel, @jasonmoliver and @nathiet. And I would again like to thank our generous sponsors for not only providing some awesome prizes but also other contributions that are going to make this year&#8217;s Firetalks the best so far. Thanks! Milton Security Group Dirty Security Lares Consulting Leverage Consulting &#38; Associates Liquidmatrix Security Digest Bulb Security And finally if you want to keep up with all the Firetalks going-ons, be sure to check back to the master Firetalks post periodically. It is the home for any and all information relating to the ShmooCon 2012 FireTalks. [...]]]></description>
			<content:encoded><![CDATA[<div class="tweetthis" style="text-align:left;"><p> <a target="_blank" rel="nofollow" class="tt" href="http://twitter.com/intent/tweet?text=ShmooCon+2012+FireTalks+%E2%80%93+Update+4+%28Second+Round+Speaker+Announcements%29+http%3A%2F%2Fj.mp%2FzUoqSZ" title="Post to Twitter"><img class="nothumb" src="http://www.novainfosecportal.com/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro4.png" alt="Post to Twitter" /></a> <a target="_blank" rel="nofollow" class="tt" href="http://www.facebook.com/share.php?u=http://www.novainfosecportal.com/2012/01/20/shmoocon-2012-firetalks-%e2%80%93-update-4-second-round-speaker-announcements/&amp;t=ShmooCon+2012+FireTalks+%E2%80%93+Update+4+%28Second+Round+Speaker+Announcements%29" title="Post to Facebook"><img class="nothumb" src="http://www.novainfosecportal.com/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro4.png" alt="Post to Facebook" /></a></p></div><p><img class="alignright size-medium wp-image-7397" title="Call for Presentations" src="http://www.novainfosecportal.com/wp-content/uploads/2011/12/megaphone-225x300.jpg" alt="Person Calling into Megaphone" width="111" height="147" />Just a short post to announce the second round speakers for this year&#8217;s ShmooCon Firetalks&#8230; With several more submissions between our last post and the CFP due date, the selection committee has been hard at work trying to pull together a diverse program with the most interesting talks combined with a good mix of established and new speakers.</p>
<p>But before we get on to the talks I just wanted to thank the selection committee for all the hard work they put in over the last few weeks. Since some may not want their full names out there, I&#8217;ll just list them all by their Twitter handles &#8230; @<a href="http://twitter.com/dystonic">dystonic</a>, @<a href="http://twitter.com/jack_daniel">jack_daniel</a>, @<a href="http://twitter.com/jasonmoliver">jasonmoliver</a> and @<a href="http://twitter.com/nathiet">nathiet</a>. And I would again like to thank our generous sponsors for not only providing some awesome prizes but also other contributions that are going to make this year&#8217;s Firetalks the best so far. Thanks!</p>
<ul>
<li><a href="http://www.miltonsecurity.com/">Milton Security Group</a></li>
<li><a href="http://dirtysec.org/">Dirty Security</a></li>
<li><a href="http://lares.com/">Lares Consulting</a></li>
<li><a href="http://www.myleverage.org/">Leverage Consulting &amp; Associates</a></li>
<li><a href="http://www.liquidmatrix.org/blog/">Liquidmatrix Security Digest</a></li>
<li><a href="http://www.bulbsecurity.com/">Bulb Security</a></li>
</ul>
<p>And finally if you want to keep up with all the Firetalks going-ons, be sure to check back to the <a href="/2011/12/13/shmoocon-2012-firetalks/">master Firetalks post</a> periodically. It is the home for any and all information relating to the ShmooCon 2012 FireTalks. You can also subscribe to receive these updates through any of our “feeds” if you wish (@<a href="http://twitter.com/novainfosec">novainfosec</a> on Twitter, our <a href="http://www.facebook.com/novainfosec">FaceBook Page</a>, or <a href="http://feeds.feedburner.com/novainfosecportalblog">RSS</a>) to keep up with things. And as usual … I’ll be regularly updating my Twitter stream at @<a href="http://twitter.com/grecs">grecs</a> with all the information using the <a href="http://twitter.com/#%21/search/%23firetalks">#firetalks</a> tag.</p>
<p>And without further ado … we are pleased to announce the second round speakers!!!</p>
<p><strong>Cracking WiFi Protected Setup For Fun and Profit</strong></p>
<p>by Craig Heffner</p>
<p>This talk will detail the recently disclosed vulnerability in WiFi Protected Setup which allows wireless attackers to recover plain text WPA/WPA2 pass phrases in just a few hours, as well as my WPS brute force attack tool, Reaver.</p>
<p><strong>Passive Aggressive Pwnage: Sniffing the Net for Fun &amp; Profit</strong></p>
<p>by John Sawyer</p>
<p>There has been very little public research into passive fingerprinting over the last few years, and the best and most well-known tool for that (p0f) hasn&#8217;t been actively developed in 6 years. While a recent a project is using the clever technique of identifying OS&#8217;s through DHCP options, it isn&#8217;t looking beyond simple OS identification. Why not? If you&#8217;ve ever been responsible for IDS monitoring in a large environment, you know there&#8217;s a huge amount of juicy data waiting to be snarfed up&#8211;interesting information that could be collected passively to identify vulnerable targets in a pen test. Some commercial solutions have these passive vulnerability detection capabilities already, but it&#8217;s never trickled down into the free, open source world.</p>
<p>In this presentation, we will look at some of the data that can be gleaned passively, how it can be used for offensive (and defensive) purposes, and announce a new project designed to use existing open source IDS engines (Snort &amp; Suricata) and IDS rules to enhance penetration tests through passive fingerprinting. The project will utilize existing rules from projects like Emerging Threats, develop new rules to address gaps in detection, and give back to the community by contributing newly developed rules back to similar projects. A focus will be on identifying bleeding edge devices, vulnerable applications, and passively gathering sensitive information (SSNs, CCNs, passwords, etc.).</p>
<p><strong>Remotely Exploiting the PHY Layer</strong></p>
<p>by Travis Goodspeed</p>
<p>Packet-in-Packet injections are a new type of in-band signalling attack, one which allows a packet to be injected into a remote wireless network through the body of any other type of packet. The attacker never needs a radio, and no software or hardware bugs are necessary for the injection to occur. The attack works on perfectly standard-compliant implementations of 802.15.4, 802.11B, and most other wireless protocols.</p>
<p><strong>Ressurecting Ettercap</strong></p>
<p>by Eric Milam</p>
<p>In December 2011 Ettercap had its first official release in almost 6 years. This talk will discuss how I went from the creation of a simple bash script to taking over one of the world most loved penetration testing tools. Topics will include, easy-creds, communications with Alor &amp; Naga and the new team charged with moving the project forward.</p>
<p><strong>Security Onion: Network Security Monitoring in Minutes</strong></p>
<p>by Doug Burks</p>
<p>Traditional Intrusion Detection Systems (IDS) can be costly, difficult to install, and may not provide all the capabilities that you need to defend your network. Network Security Monitoring (NSM) combines traditional IDS alerts with additional data to give you a more complete picture of what&#8217;s happening on your network. This presentation will demonstrate how to deploy NSM in just a few minutes using a free Linux distro called Security Onion.</p>
<p>Beyond the formally announced talks we also chose a few alternates that just missed getting selected. These speakers should be ready to present either night.</p>
<ul>
<li><strong>Georgia Weidman:</strong> Stopping Android Permission Leak</li>
<li><strong>Thomas Hoffecker:</strong> Exploiting PKI for Pentesters</li>
</ul>
<p style="text-align: center;">#####</p>
<p style="text-align: center;"><em>Look for the final schedule to be posted early next week. See ya!<br />
</em></p>
<div class="tweetthis" style="text-align:left;"><p> <a target="_blank" rel="nofollow" class="tt" href="http://twitter.com/intent/tweet?text=ShmooCon+2012+FireTalks+%E2%80%93+Update+4+%28Second+Round+Speaker+Announcements%29+http%3A%2F%2Fj.mp%2FzUoqSZ" title="Post to Twitter"><img class="nothumb" src="http://www.novainfosecportal.com/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro4.png" alt="Post to Twitter" /></a> <a target="_blank" rel="nofollow" class="tt" href="http://www.facebook.com/share.php?u=http://www.novainfosecportal.com/2012/01/20/shmoocon-2012-firetalks-%e2%80%93-update-4-second-round-speaker-announcements/&amp;t=ShmooCon+2012+FireTalks+%E2%80%93+Update+4+%28Second+Round+Speaker+Announcements%29" title="Post to Facebook"><img class="nothumb" src="http://www.novainfosecportal.com/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro4.png" alt="Post to Facebook" /></a></p></div>]]></content:encoded>
			<wfw:commentRss>http://www.novainfosecportal.com/2012/01/20/shmoocon-2012-firetalks-%e2%80%93-update-4-second-round-speaker-announcements/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>ShmooCon 2012 FireTalks – Update 3 (First Round Speaker Announcements)</title>
		<link>http://www.novainfosecportal.com/2012/01/11/omg-was-it-freakin-hard-or-what-to-select-these-talks/</link>
		<comments>http://www.novainfosecportal.com/2012/01/11/omg-was-it-freakin-hard-or-what-to-select-these-talks/#comments</comments>
		<pubDate>Wed, 11 Jan 2012 16:16:36 +0000</pubDate>
		<dc:creator>grecs</dc:creator>
				<category><![CDATA[Infosec Conferences]]></category>
		<category><![CDATA[NoVA Meetups]]></category>
		<category><![CDATA[cfp]]></category>
		<category><![CDATA[contest]]></category>
		<category><![CDATA[firetalks]]></category>
		<category><![CDATA[firetalks2012]]></category>
		<category><![CDATA[prize]]></category>
		<category><![CDATA[shmoocon]]></category>
		<category><![CDATA[volunteer]]></category>

		<guid isPermaLink="false">http://www.novainfosecportal.com/?p=7569</guid>
		<description><![CDATA[After pushing the team to do some reviews over the last few days we have finally come up with the first round of speaker announcements for the ShmooCon 2012 Firetalks! It&#8217;s been a painful process trying to rate all of the awesome submissions but I think the team did a great job at finding a nice mix of talks up to this point. Before continuing on I would like to let everyone know that there are still five additional slots available and the CFP is open through this Friday at 5:00 PM EST. So if you have a topic and are contemplating whether or not to submit &#8230; don&#8217;t hesitate much longer. To get started head on over to the EasyChair SC2012FT portal. We are still looking for a few volunteers, specifically someone to create and hang some poster-sized signs so people can easily find where the sessions will be (usually in Track 3, which is typically held a bit off the beaten track). Also since the sessions are being recorded and streamed, we need someone to coordinate with the ShmooCon and hotel AV teams (audio/video &#8230; not anti-virus ) so we can hopefully get direct audio feeds for better [...]]]></description>
			<content:encoded><![CDATA[<div class="tweetthis" style="text-align:left;"><p> <a target="_blank" rel="nofollow" class="tt" href="http://twitter.com/intent/tweet?text=ShmooCon+2012+FireTalks+%E2%80%93+Update+3+%28First+Round+Speaker+Announcements%29+http%3A%2F%2Fj.mp%2FwFRMmy" title="Post to Twitter"><img class="nothumb" src="http://www.novainfosecportal.com/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro4.png" alt="Post to Twitter" /></a> <a target="_blank" rel="nofollow" class="tt" href="http://www.facebook.com/share.php?u=http://www.novainfosecportal.com/2012/01/11/omg-was-it-freakin-hard-or-what-to-select-these-talks/&amp;t=ShmooCon+2012+FireTalks+%E2%80%93+Update+3+%28First+Round+Speaker+Announcements%29" title="Post to Facebook"><img class="nothumb" src="http://www.novainfosecportal.com/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro4.png" alt="Post to Facebook" /></a></p></div><p><img class="alignright size-medium wp-image-7571" title="Yeah, I Had to Go There..." src="http://www.novainfosecportal.com/wp-content/uploads/2012/01/winning-base-300x300.png" alt="That Guy from the Whole Winning Thing" width="126" height="126" />After pushing the team to do some reviews over the last few days we have finally come up with the first round of speaker announcements for the ShmooCon 2012 Firetalks! It&#8217;s been a painful process trying to rate all of the awesome submissions but I think the team did a great job at finding a nice mix of talks up to this point.</p>
<p>Before continuing on I would like to let everyone know that there are still <strong>five additional slots</strong> available and the CFP is open through <strong>this Friday at 5:00 PM EST</strong>. So if you have a topic and are contemplating whether or not to submit &#8230; don&#8217;t hesitate much longer. To get started head on over to the <a href="http://bit.ly/nispsc2012ft">EasyChair SC2012FT portal</a>.</p>
<p>We are still looking for a few volunteers, specifically someone to create and hang some <strong>poster-sized signs</strong> so people can easily find where the sessions will be (usually in Track 3, which is typically held a bit off the beaten track). Also since the sessions are being recorded and streamed, we need someone to <strong>coordinate with the ShmooCon and hotel AV teams</strong> (audio/video &#8230; not anti-virus <img src='http://www.novainfosecportal.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' />  ) so we can hopefully get direct audio feeds for better quality. There are also some other smaller roles (e.g., a timer) so please check out the <a href="/2011/12/13/shmoocon-2012-firetalks/">master post</a> for all the available volunteer positions. And if you have a cool idea to help make FireTalks better and are willing to volunteer to coordinate it, let us know&#8230; Also don&#8217;t worry about volunteering interfering with you dinner plans &#8230; we&#8217;ll be providing a<strong> free dinner</strong> for all those helping out thanks in part to our <a href="/2012/01/06/yes-its-been-awhile-since-last-update-re-shmoocon-2012-firetalks-sorry-for-the-wait/">sponsors</a> &#8211; <a href="http://www.miltonsecurity.com/">Milton Security Group</a>, <a href="http://dirtysec.org/">Dirty Security</a>, <a href="http://lares.com/">Lares Consulting</a>, <a href="http://www.myleverage.org/">Leverage Consulting &amp; Associates</a>, <a href="http://www.liquidmatrix.org/blog/">Liquidmatrix Security Digest</a>, and <a href="http://www.bulbsecurity.com/">Bulb Security</a>. Oh and by the way &#8230; could someone volunteer to coordinate the dinner thing. <img src='http://www.novainfosecportal.com/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' /> </p>
<p>And don&#8217;t forget &#8230; for all the latest happenings, check back to the <a href="/2011/12/13/shmoocon-2012-firetalks/">master Firetalks post</a> periodically. It is the home for any and all information relating to the ShmooCon 2012 FireTalks. You can also subscribe to receive these updates through any of our &#8220;feeds&#8221; if you wish (@<a href="http://twitter.com/novainfosec">novainfosec</a> on Twitter, our <a href="http://www.facebook.com/novainfosec">FaceBook Page</a>, or <a href="http://feeds.feedburner.com/novainfosecportalblog">RSS</a>) to keep up with things. And as usual &#8230; I&#8217;ll be regularly updating my Twitter stream at @<a href="http://twitter.com/grecs">grecs</a> with all the information using the <a href="http://twitter.com/#!/search/%23firetalks">#firetalks</a> tag.</p>
<p>And without further ado &#8230; we are pleased to announce the first round speakers!!!</p>
<p><strong>Bending SAP Over &amp; Extracting What You Need!</strong></p>
<p>by Chris John Riley</p>
<p>At the heart of any large enterprise, lies a platform misunderstood and feared by all but the bravest systems administrators. Home to a wealth of information, and key to infinite wisdom. This platform is SAP. For years this system has been amongst the many &#8220;red pen&#8221; items on penetration tests and audits alike&#8230; but no more! We will no longer accept the cries of &#8220;Business critical, out-of-scope&#8221;. The time for SAP has come, the cross-hairs of attackers are firmly focused on the soft underbelly that is ERM, and it&#8217;s our duty to follow suit. Join me as we take the first steps into exploring SAP, extracting information and popping shells. Leave your Nessus license at the door! It&#8217;s time to scrub this SAP system clean with SOAP!.</p>
<p><strong>Five Ways We&#8217;re Killing Our Own Privacy</strong></p>
<p>by Michael Schearer</p>
<p>At DEFCON, I talked about how our privacy rights are under attack. Our sea of liberty is drying up due to the ever-encroaching power of the government. A litany of abuses continue to chip away at the historical foundations of privacy: administrative searches as pretexts to avoid search warrants, national security letter, andsuffocating public surveillance just to name a few. Yet the government alone is not the only source of our ever-diminishing privacy. In this talk, I turn my attention&#8230;to you. Yes, believe it or not, you (and me) and the other 310 million of us in this country are also responsible for our diminished expectation of privacy. Why are we responsible? Who wants our information, and why is it so valuable? Is there anything we can do to stem the tide?</p>
<p><strong>How Do You Know Your Colo Isn&#8217;t &#8220;Inside&#8221; Your Cabinet, A Simple Alarm Using Teensy</strong></p>
<p>by David Zendzian</p>
<p>As everyone knows, the security of your equipment starts with securing it physically. To accomplish that many will lease cabinet or cage space within the a commercial colo. However, all colos require access to your equipment (in case of fire, or other emergency). Even withstanding the emergency access I have seen colo&#8217;s enter cages and cabinets to run cables or to shorten their walk around a row in the facility. Other than installing a commercial alarm or a motion sensor camera, both of which are expensive solutions, what can be done to monitor access into your cabinet or cage. This talk will show how we have used a Teensy board from PJRC to build a simple alarm system that can be easily integrated into whatever host / network monitoring system already configured for your network.</p>
<p><strong>ROUTERPWN: A Mobile Router Exploitation Framework</strong></p>
<p>by Pedro Joaquin</p>
<p>Routerpwn is a mobile exploitation framework that helps you in the exploitation of vulnerabilities in network devices such as residential and commercial routers, switches and access points. It is a compilation of ready to run local and remote web exploits. Programmed in Javascript and HTML in order to run in all &#8220;smart phones&#8221; and mobile Internet devices, including Android, iPhone, BlackBerry and all tablets. You can even store it off line for local exploitation without Internet connection.</p>
<p><strong>Security Is Like An Onion, That&#8217;s Why it Makes You Cry</strong></p>
<p>by Michele Chubirka</p>
<p>Why is the security industry so full of fail? We spend millions of dollars on firewalls, IPS, IDS, DLP, professional penetration tests and assessments, vulnerability and compliance tools and at the end of the day, the weakest link is the user and his or her inability to make the right choices. It’s enough to make a security engineer cry. The one thing you can depend upon in an enterprise is that many of our users, even with training, will still make the wrong choices. They still click on links they shouldn’t, respond to phishing scams, open documents without thinking, post too much information on Twitter and Facebook, use their pet’s name as passwords, etc…. But what if this isn’t because users hate us or are too stupid? What if all our complaints about not being heard and our instructions regarding the best security practices have more to do with our failure to understand modern neuroscience and the human mind’s resistance to change?</p>
<p style="text-align: center;">#####</p>
<p style="text-align: center;"><em>Don&#8217;t forget &#8230; you still have time to submit your talk! The CFP closes this Friday at 5:00 PM EST. Today&#8217;s image is from <a href="http://1caseycolette.blogspot.com/2011/08/perfect-calm-bestpricenutritioncom.html">1CaseyColette.blogspot.com</a>.</em></p>
<div class="tweetthis" style="text-align:left;"><p> <a target="_blank" rel="nofollow" class="tt" href="http://twitter.com/intent/tweet?text=ShmooCon+2012+FireTalks+%E2%80%93+Update+3+%28First+Round+Speaker+Announcements%29+http%3A%2F%2Fj.mp%2FwFRMmy" title="Post to Twitter"><img class="nothumb" src="http://www.novainfosecportal.com/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro4.png" alt="Post to Twitter" /></a> <a target="_blank" rel="nofollow" class="tt" href="http://www.facebook.com/share.php?u=http://www.novainfosecportal.com/2012/01/11/omg-was-it-freakin-hard-or-what-to-select-these-talks/&amp;t=ShmooCon+2012+FireTalks+%E2%80%93+Update+3+%28First+Round+Speaker+Announcements%29" title="Post to Facebook"><img class="nothumb" src="http://www.novainfosecportal.com/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro4.png" alt="Post to Facebook" /></a></p></div>]]></content:encoded>
			<wfw:commentRss>http://www.novainfosecportal.com/2012/01/11/omg-was-it-freakin-hard-or-what-to-select-these-talks/feed/</wfw:commentRss>
		<slash:comments>19</slash:comments>
		</item>
		<item>
		<title>ShmooCon 2012 FireTalks – Update 2 (Sponsors &amp; Prizes)</title>
		<link>http://www.novainfosecportal.com/2012/01/06/yes-its-been-awhile-since-last-update-re-shmoocon-2012-firetalks-sorry-for-the-wait/</link>
		<comments>http://www.novainfosecportal.com/2012/01/06/yes-its-been-awhile-since-last-update-re-shmoocon-2012-firetalks-sorry-for-the-wait/#comments</comments>
		<pubDate>Fri, 06 Jan 2012 20:00:21 +0000</pubDate>
		<dc:creator>grecs</dc:creator>
				<category><![CDATA[Infosec Conferences]]></category>
		<category><![CDATA[NoVA Meetups]]></category>
		<category><![CDATA[cfp]]></category>
		<category><![CDATA[contest]]></category>
		<category><![CDATA[firetalks]]></category>
		<category><![CDATA[firetalks2012]]></category>
		<category><![CDATA[prize]]></category>
		<category><![CDATA[shmoocon]]></category>
		<category><![CDATA[sponsor]]></category>
		<category><![CDATA[volunteer]]></category>

		<guid isPermaLink="false">http://www.novainfosecportal.com/?p=7425</guid>
		<description><![CDATA[Well it&#8217;s been a few weeks since our last update. We hope everyone had a nice holiday break and at least a few people lucked out with the final round of ShmooCon tickets sales. Over the past several weeks @jack_daniel has been hard at work gathering sponsors to support the prizes and other fun stuff we have planned. So at this point we would like to announce the prizes and sponsors for this year&#8217;s Firetalks! But before we get into the prizes and sponsors I did want to make a few announcements regarding some of our upcoming activities. We&#8217;ve received a record number of submissions this year and will be announcing the first set of talks on Monday or Tuesday next week. If you have been thinking of submitting and haven&#8217;t yet, please do &#8230; the more topics we get, the better we can provide a balanced program. As before &#8230; just head on over to the EasyChair SC2012FT portal. The RFP will be closing at 5:00 PM on Friday the 13th. I am also happy to announce is that the NoVA Hackers Association will be running a ShmooCon Epilogue conference/meetup following ShmooCon on Monday the 30th. If you haven&#8217;t [...]]]></description>
			<content:encoded><![CDATA[<div class="tweetthis" style="text-align:left;"><p> <a target="_blank" rel="nofollow" class="tt" href="http://twitter.com/intent/tweet?text=ShmooCon+2012+FireTalks+%E2%80%93+Update+2+%28Sponsors+%26+Prizes%29+http%3A%2F%2Fj.mp%2FwpnHXZ" title="Post to Twitter"><img class="nothumb" src="http://www.novainfosecportal.com/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro4.png" alt="Post to Twitter" /></a> <a target="_blank" rel="nofollow" class="tt" href="http://www.facebook.com/share.php?u=http://www.novainfosecportal.com/2012/01/06/yes-its-been-awhile-since-last-update-re-shmoocon-2012-firetalks-sorry-for-the-wait/&amp;t=ShmooCon+2012+FireTalks+%E2%80%93+Update+2+%28Sponsors+%26+Prizes%29" title="Post to Facebook"><img class="nothumb" src="http://www.novainfosecportal.com/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro4.png" alt="Post to Facebook" /></a></p></div><p><img class="alignright size-medium wp-image-7532" title="The Prizes" src="http://www.novainfosecportal.com/wp-content/uploads/2012/01/prize-263x300.gif" alt="Girl Holding Up Trophy" width="158" height="180" />Well it&#8217;s been a few weeks since our last update. We hope everyone had a nice holiday break and at least a few people lucked out with the final round of ShmooCon tickets sales. Over the past several weeks @<a href="http://twitter.com/jack_daniel">jack_daniel</a> has been hard at work gathering sponsors to support the prizes and other fun stuff we have planned. So at this point we would like to announce the prizes and sponsors for this year&#8217;s Firetalks!</p>
<p>But before we get into the prizes and sponsors I did want to make a few announcements regarding some of our upcoming activities. We&#8217;ve received a record number of submissions this year and will be announcing the first set of talks on Monday or Tuesday next week. If you have been thinking of submitting and haven&#8217;t yet, please do &#8230; the more topics we get, the better we can provide a balanced program. As before &#8230; just head on over to the <a href="http://bit.ly/nispsc2012ft">EasyChair SC2012FT portal</a>. The <strong>RFP will be closing at 5:00 PM on Friday the 13th</strong>.</p>
<p>I am also happy to announce is that the <a href="http://novahackers.blogspot.com/">NoVA Hackers Association</a> will be running a <strong>ShmooCon Epilogue conference/meetup</strong> following ShmooCon on Monday the 30th. If you haven&#8217;t locked in your travel plans yet, you may want to push them out a day or two to attend this event. It will feature talks from many of the local infosec pros as well as some of the ShmooCon presenters. They are still in the planning stages at this point, so please head on over to the official <a href="http://novahackers.blogspot.com/2011/12/shmoocon-epilogue.html">ShmooCon Epilogue</a> post to find out how to participate.</p>
<p>Lastly, we are still in need of several <strong>more FireTalk volunteers</strong>. If you&#8217;ve volunteered previously and I haven&#8217;t contacted you, please hit me up again via @<a href="http://twitter.com/grecs">grecs</a> on Twitter. Right now we are looking for someone to coordinate the judging panel, some muscle at the door (i.e., security), an AV coordinator, a timer (I&#8217;d really love a big red countdown clock if anyone has one), and someone to create and hang poster signs for leading people from the main conference area over to where the Firetalks will be held.</p>
<p>Thanks for putting up with those few announcements and now on to the good stuff &#8230; this years Firetalk prizes and sponsors!</p>
<h2><a href="http://www.miltonsecurity.com/"><img class="alignright size-full wp-image-7499" title="Milton Security Group" src="http://www.novainfosecportal.com/wp-content/uploads/2012/01/milton.png" alt="Milton Security Group Logo" width="201" height="67" /></a>1st Place</h2>
<p><a href="http://www.miltonsecurity.com/">Milton Security Group</a> will be bringing us a Parrot AR.Drone Quadricopter controlled WITH an iPod Touch to control it. Now that is one cool prize! Hopefully, I can get my hands on it before Sunday&#8217;s closing ceremonies.</p>
<p><a href="http://www.amazon.com/Parrot-AR-Drone-Quadricopter-Controlled-Android/dp/B003ZVSHB0"><img class="aligncenter size-full wp-image-7497" title="Parrot AR.Drone Quadricopter Controlled with iPod Touch to Control" src="http://www.novainfosecportal.com/wp-content/uploads/2012/01/parrot.jpg" alt="Picture of the Parrot Drone" width="265" height="169" /></a></p>
<h2><img class="alignright size-medium wp-image-7513" title="Lars Consulting, Leverage Consulting &amp; Associates, &amp; Dirty Security" src="http://www.novainfosecportal.com/wp-content/uploads/2012/01/larslevdirty-300x228.png" alt="Combined Logos for Lars, Leverage, &amp; DirtySec" width="210" height="160" />2nd Place</h2>
<p>No one sponsor came out with a dedicated 2nd place prize so we are combining some of the cash contributions together to get the ultimate hacking platform &#8211; a netbook with the latest version of BackTrack pre-installed (maybe even pre-p0wned <img src='http://www.novainfosecportal.com/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' />  ). Ok &#8230; well maybe not the &#8220;ultimate&#8221; but at least something light and portable. To the right you see my best effort at creating some kind of collage that represents all the sponsors for this prize. They are also linked below for quick reference.</p>
<ul>
<li><a href="http://dirtysec.org/">Dirty Security</a></li>
<li><a href="http://lares.com/">Lares Consulting</a> via Chris &#8220;@<a href="http://twitter.com/indi303">indi303</a>&#8221; Nickerson</li>
<li><a href="http://www.myleverage.org/">Leverage Consulting &amp; Associates</a> via Mike &#8220;@<a href="http://twitter.com/theprez98">theprez98</a>&#8221; Schearer</li>
</ul>
<p><img class="aligncenter size-full wp-image-7514" title="Netbook" src="http://www.novainfosecportal.com/wp-content/uploads/2012/01/netbook.jpg" alt="Generic Netbook Image" width="216" height="190" /></p>
<h2><img class="alignright size-medium wp-image-7502" title="Liquidmatrix Security Digest" src="http://www.novainfosecportal.com/wp-content/uploads/2012/01/liquidmatrixlogo-300x39.png" alt="Liquidmatrix Logo" width="300" height="39" />3rd Place</h2>
<p>Lastly, <a href="http://www.liquidmatrix.org/blog/">Liquidmatrix Security Digest</a> brings us the &#8220;Sad Trombone&#8221; award, basically one of Apple&#8217;s new iPad Minis. <img src='http://www.novainfosecportal.com/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' /> </p>
<p><a href="https://www.apple.com/ipodtouch/"><img class="aligncenter size-full wp-image-7501" title="iPod Touch" src="http://www.novainfosecportal.com/wp-content/uploads/2012/01/ipodtouch.jpg" alt="Picture of iPod Touch" width="177" height="232" /></a></p>
<h2>Other Support</h2>
<p>Beyond the prizes there are several other ways that people are helping out.</p>
<ul>
<li><a href="http://www.bulbsecurity.com/"><img class="alignright size-full wp-image-7516" title="Bulb Security" src="http://www.novainfosecportal.com/wp-content/uploads/2012/01/bulb.jpg" alt="Bulb Security Logo" width="95" height="128" /></a><a href="http://www.miltonsecurity.com/">Milton Security Group</a> will also be offering some cool swag to toss out during the event.</li>
<li>The remaining contributions from the <a href="http://dirtysec.org/">DirtySec</a>/<a href="http://lares.com/">Lars</a>/<a href="http://www.myleverage.org/">Leverage</a> consortium will be used for speaker gifts and maybe a few surprises.</li>
<li><a href="http://www.bulbsecurity.com/">Bulb Security</a> via @<a href="http://twitter.com/georgiaweidman">georgiaweidman</a> will be providing live streaming and filming of the event. There&#8217;s an interesting story behind this company&#8217;s name. Be sure to ask Georgia about it.</li>
</ul>
<p style="text-align: center;">#####</p>
<p style="text-align: center;"><em>And that&#8217;s about it. Again please tweet a big thanks to @<a href="http://twitter.com/jack_daniel">jack_daniel</a> for pulling together some awesome sponsors. Today&#8217;s featured image is from <a href="http://sasatien.blogspot.com/2011/03/prizes-awaiting-creative-photo-contest.html">Sasatien.Blogspot.com</a>. See ya!<br />
</em></p>
<div class="tweetthis" style="text-align:left;"><p> <a target="_blank" rel="nofollow" class="tt" href="http://twitter.com/intent/tweet?text=ShmooCon+2012+FireTalks+%E2%80%93+Update+2+%28Sponsors+%26+Prizes%29+http%3A%2F%2Fj.mp%2FwpnHXZ" title="Post to Twitter"><img class="nothumb" src="http://www.novainfosecportal.com/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro4.png" alt="Post to Twitter" /></a> <a target="_blank" rel="nofollow" class="tt" href="http://www.facebook.com/share.php?u=http://www.novainfosecportal.com/2012/01/06/yes-its-been-awhile-since-last-update-re-shmoocon-2012-firetalks-sorry-for-the-wait/&amp;t=ShmooCon+2012+FireTalks+%E2%80%93+Update+2+%28Sponsors+%26+Prizes%29" title="Post to Facebook"><img class="nothumb" src="http://www.novainfosecportal.com/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro4.png" alt="Post to Facebook" /></a></p></div>]]></content:encoded>
			<wfw:commentRss>http://www.novainfosecportal.com/2012/01/06/yes-its-been-awhile-since-last-update-re-shmoocon-2012-firetalks-sorry-for-the-wait/feed/</wfw:commentRss>
		<slash:comments>6</slash:comments>
		</item>
		<item>
		<title>ShmooCon 2012 FireTalks &#8211; Update 1 (CFP / Sponsor Support)</title>
		<link>http://www.novainfosecportal.com/2011/12/19/we-need-talks-and-money-for-this-whole-firetalks-thing/</link>
		<comments>http://www.novainfosecportal.com/2011/12/19/we-need-talks-and-money-for-this-whole-firetalks-thing/#comments</comments>
		<pubDate>Tue, 20 Dec 2011 03:57:08 +0000</pubDate>
		<dc:creator>grecs</dc:creator>
				<category><![CDATA[Infosec Conferences]]></category>
		<category><![CDATA[NoVA Meetups]]></category>
		<category><![CDATA[cfp]]></category>
		<category><![CDATA[contest]]></category>
		<category><![CDATA[firetalks]]></category>
		<category><![CDATA[firetalks2012]]></category>
		<category><![CDATA[shmoocon]]></category>
		<category><![CDATA[sponsor]]></category>

		<guid isPermaLink="false">http://www.novainfosecportal.com/?p=7385</guid>
		<description><![CDATA[Although many of the details are still being worked out we wanted to put out a quick post to announce the ShmooCon 2012 FireTalks CFP and solicit sponsors. CFP This year we are planning on having up to five 15-minute speaking slots each night depending on the final discussions the ShmooCon team is having with the conference hotel. We are hoping to accommodate many of the awesome submissions that ShmooCon was not able to accept due to the finite number of speaking slots. If you are already speaking at ShmooCon, please be considerate and leave submissions open to others. Other than that … the only thing we are looking for is a nice mix of established and new speakers. To ease our submission load, we will be using the free EasyChair Conferencing System. We used it to handle submissions in the past and it worked nicely. It just requires that you create an account, login, and select New Submission from the top menu. From there just fill out as much information as you can and hit the Submit button. To get started head on over to the EasyChair SC2012FT portal. Call for Sponsors Similar to last year we will have [...]]]></description>
			<content:encoded><![CDATA[<div class="tweetthis" style="text-align:left;"><p> <a target="_blank" rel="nofollow" class="tt" href="http://twitter.com/intent/tweet?text=ShmooCon+2012+FireTalks+%E2%80%93+Update+1+%28CFP+%2F+Sponsor+Support%29+http%3A%2F%2Fj.mp%2Fvnb0oC" title="Post to Twitter"><img class="nothumb" src="http://www.novainfosecportal.com/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro4.png" alt="Post to Twitter" /></a> <a target="_blank" rel="nofollow" class="tt" href="http://www.facebook.com/share.php?u=http://www.novainfosecportal.com/2011/12/19/we-need-talks-and-money-for-this-whole-firetalks-thing/&amp;t=ShmooCon+2012+FireTalks+%E2%80%93+Update+1+%28CFP+%2F+Sponsor+Support%29" title="Post to Facebook"><img class="nothumb" src="http://www.novainfosecportal.com/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro4.png" alt="Post to Facebook" /></a></p></div><p><img class="alignright size-medium wp-image-7397" title="Guy with No Mouth Speaking into Megaphone ... Really?" src="http://www.novainfosecportal.com/wp-content/uploads/2011/12/megaphone-225x300.jpg" alt="Person Calling into Megaphone" width="126" height="168" />Although many of the details are still being worked out we wanted to put out a quick post to announce the ShmooCon 2012 FireTalks CFP and solicit sponsors.</p>
<h2>CFP</h2>
<p>This year we are planning on having up to five 15-minute speaking slots each night depending on the final discussions the ShmooCon team is having with the conference hotel. We are hoping to accommodate many of the awesome submissions that ShmooCon was not able to accept due to the finite number of speaking slots. If you are already speaking at ShmooCon, please be considerate and leave submissions open to others. Other than that … the only thing we are looking for is a nice mix of established and new speakers.</p>
<p>To ease our submission load, we will be using the free EasyChair Conferencing System. We used it to handle submissions in the past and it worked nicely. It just requires that you create an account, login, and select New Submission from the top menu. From there just fill out as much information as you can and hit the Submit button. To get started head on over to the <a href="http://bit.ly/nispsc2012ft">EasyChair SC2012FT portal</a>.</p>
<h2>Call for Sponsors</h2>
<p>Similar to last year we will have prizes for the top 3 presentations and are looking for sponsors willing to put forward some awesome contributions (maybe a few iPads … one for the organizer too <img src='http://www.novainfosecportal.com/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' />  ). You’ll get your logo placed on the master ShmooCon 2012 Firetalks post, some of the update posts, and several mentions during the two night event.</p>
<p>Based on the last few years we are looking for three sponsors at around the $500, $300, and $200 levels. If you are interested in sponsoring, please contact @<a href="http://twitter.com/jack_daniel">jack_daniel</a>. If you have any problems contacting Jack, just mention it to me (@<a href="http://twitter.com/grecs">grecs</a>) on Twitter or email us using our <a href="/contact-us/">Contact Us</a> form.</p>
<p style="text-align: center;">#####</p>
<p style="text-align: center;"><em>Stay tuned for more info on the ShmooCon 2012 Firetalks. And check out the <a href="/2011/12/13/shmoocon-2012-firetalks/">master post</a> with all the consolidated details. Today&#8217;s feature image is courtesy of <a href="http://www.rochestersecurity.org/speakers/call-for-presentations.html">RochesterSecurity.org</a>. See ya!</em></p>
<div class="tweetthis" style="text-align:left;"><p> <a target="_blank" rel="nofollow" class="tt" href="http://twitter.com/intent/tweet?text=ShmooCon+2012+FireTalks+%E2%80%93+Update+1+%28CFP+%2F+Sponsor+Support%29+http%3A%2F%2Fj.mp%2Fvnb0oC" title="Post to Twitter"><img class="nothumb" src="http://www.novainfosecportal.com/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro4.png" alt="Post to Twitter" /></a> <a target="_blank" rel="nofollow" class="tt" href="http://www.facebook.com/share.php?u=http://www.novainfosecportal.com/2011/12/19/we-need-talks-and-money-for-this-whole-firetalks-thing/&amp;t=ShmooCon+2012+FireTalks+%E2%80%93+Update+1+%28CFP+%2F+Sponsor+Support%29" title="Post to Facebook"><img class="nothumb" src="http://www.novainfosecportal.com/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro4.png" alt="Post to Facebook" /></a></p></div>]]></content:encoded>
			<wfw:commentRss>http://www.novainfosecportal.com/2011/12/19/we-need-talks-and-money-for-this-whole-firetalks-thing/feed/</wfw:commentRss>
		<slash:comments>8</slash:comments>
		</item>
	</channel>
</rss>

