<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>NovaInfosecPortal.com &#187; the shmoo group</title>
	<atom:link href="http://www.novainfosecportal.com/tag/the-shmoo-group/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.novainfosecportal.com</link>
	<description>News, events, &#38; resources for infosec professionals in NoVA, DC, &#38; MD</description>
	<lastBuildDate>Tue, 27 Jul 2010 15:00:27 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=abc</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>ShmooCon 2010 Firetalks &#8211; Update 5 (aka &#8211; the Wrap-Up)</title>
		<link>http://www.novainfosecportal.com/2010/02/24/shmoocon-2010-firetalks-update-5-aka-the-wrap-up/</link>
		<comments>http://www.novainfosecportal.com/2010/02/24/shmoocon-2010-firetalks-update-5-aka-the-wrap-up/#comments</comments>
		<pubDate>Wed, 24 Feb 2010 16:00:17 +0000</pubDate>
		<dc:creator>grecs</dc:creator>
				<category><![CDATA[Infosec Conferences]]></category>
		<category><![CDATA[conference]]></category>
		<category><![CDATA[dc]]></category>
		<category><![CDATA[event]]></category>
		<category><![CDATA[firetalks]]></category>
		<category><![CDATA[md]]></category>
		<category><![CDATA[nova]]></category>
		<category><![CDATA[shmoocon]]></category>
		<category><![CDATA[the shmoo group]]></category>

		<guid isPermaLink="false">http://www.novainfosecportal.com/?p=3355</guid>
		<description><![CDATA[So I&#8217;m finally getting around to getting this post out&#8230; I just wanted to close this whole series by announcing the winners and again thanking everyone for helping make it a success.
As you can see below, I&#8217;ve only gotten links to a few presentations. If you still need to post your presentation, please let me [...]]]></description>
			<content:encoded><![CDATA[<p>So I&#8217;m finally getting around to getting this post out&#8230; I just wanted to close this whole series by announcing the winners and again thanking everyone for helping make it a success.</p>
<p>As you can see below, I&#8217;ve only gotten links to a few presentations. If you still need to post your presentation, please let me know via <a href="/contact-us/">Contact Us</a> or mention @<a href="http://twitter.com/grecs">grecs</a> on Twitter and I&#8217;ll update this post as I get them.</p>
<h2>Presentation Summaries</h2>
<p>First, I like to put up some short synopses of the talks written by Justin  Monroe and Chris Wheeler. They were a tremendous help both nights  paying attention to the actual content while I coordinated everything.</p>
<h3>Social Engineering Toolkit v0.4 Overview (David “ReL1K” Kennedy)</h3>
<p><em>ReL1K released the newest version of his &#8220;Social Engineer&#8217;s Toolkit.&#8221; Version 4, codenamed &#8220;Pink Pirate&#8221; was released Saturday in the  BackTrack4 repository as well as his website, <a href="http://www.secmaniac.com/">secmaniac.com</a>. The framework is a  python driven open source suite which makes use of Metasploit Framework&#8217;s  client-side attacks (PDF, Aurora, etc), and has the ability to auto-target a client operating system. It also integrates with G-Mail and sendmail to  streamline sending phishing e-mails to targets.</em></p>
<h3>SHODAN for Penetration Testers (Michael “theprez98&#8243; Schearer)</h3>
<p><em><a href="http://shodan.surtri.com">SHODAN</a>,  a meta-data search engine for application banners was presented by theprez98, who showed several demonstrations of  its usefulness. The engine stores OS version, country, open ports (currently  only 21, 22 and 80), and makes the data easily searchable. As the engine  stores banners from each service, it is not uncommon to find default  configuration information in the header (such as a default password), as well as the  version information of the service. At the time of the presentation, there were apparently 136 machines still running Windows NT 3.9.</em> (<a href="http://www.scribd.com/doc/26526911/SHODAN-for-Penetration-Testers">slides</a>)</p>
<h3>Influencing Security (Marcus J. Carey)</h3>
<p><em>In a presentation about influencing security, Marcus J. Carey took a philosophic approach to solving security issues. Likening the decrease in HIV infections in Thailand by means of peer pressure, he suggested that security professionals persistently teach users about information security, instead of doing training once a year. He also stressed a non-adversarial role with the people the policy is designed to protect, and instead of treating them poorly when the policy was broken.</em></p>
<h3>Funnypots and Skiddy Baiting (Adrian “IronGeek” Crenshaw)</h3>
<p><em>IronGeek presented some of his endeavors in &#8220;Funny Pots and Skiddy  Baiting,&#8221; loosely defined as &#8220;messing with the people trying to break into your  machines.&#8221; He suggested mapping loopback addresses (127/8) to a subdomain on your  network, and then encouraging them to break into the machine at that hostname.  If they manage to get in, they may own their own machine. Other fun endeavors  included mapping your hostname to that of another website (say, 12.120.54.169), &#8220;lemon&#8221; wiping a drive with an arbitrary pattern of data for forensic investigators to find (coined from the &#8220;lemon party&#8221; shock site). He  also demonstrated a robots.txt redirect, where snooping users would get  redirected to shock sites when they visited the &#8220;Disallow&#8221; directories. His final  and perhaps most humorous website involved using php-ids to detect attacks  against a website and have Clippy pop up to help with their failed attempts.</em> (<a href="/wp-content/uploads/2010/02/skiddybaiting.pdf">slides</a>)</p>
<h3>Browser Fingerprinting Using a Stopwatch (Nicholas “aricon” Berthaume)</h3>
<p><em>Aricon demonstrated how to more accurately fingerprint browsers based on more than the user-agent, HTTP headers, and Javascript. WebApp scanners  often spoof headers, making it useless to fingerprint an attack. The timing  and download order of images can be used to accurately fingerprint a browser  using some custom mod_security rules. Differences start to show with basic  HTML, but adding images and more content gives a much more accurate result. He did  mention that plugins such as Greasemonkey, AdBlock Plus, and NoScript skew the  results, as do VPNs, SSH tunnels and other proxies. He plans to release the  mod_security ruleset and his fingerprinting scripts on his website.</em> (<a href="https://www.bordergatewayprotocol.net/aricon/presentations/Browser_fingerprinting_with_a_stopwatch.pdf">slides</a>)</p>
<h3>Pentoo (Zero Chaos)</h3>
<p><em>Zero Chaos, a Pentoo developer, was met with a barrage of Shmoo balls at   the start of his presentation. Pentoo is a lightweight penetration  testing  distro based on Gentoo. It can be run from a Live CD and uses  only 200MB of  RAM. Pentoo is updated with the latest utilities and  kernel configurations.  Pentoo also has 13 users worldwide ( <img src='http://www.novainfosecportal.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' />  ), and began  development before BackTrack.</em></p>
<h3>Sleephacking 101 – How to Stay Awake for 20 Hours a Day without Turning into a Zombie (Benny “security4all” ???)</h3>
<p><em>@Security4All gave a presentation on &#8220;sleep hacking,&#8221; discussing human  sleep cycles and how to get more energy out of sleep. Although monophasic,  humans are better suited to a polyphasic sleep cycle. Biphasic sleep involves  getting 6-7 hours of sleep per night, and a nap at noon. Spain has  institutionalized this cycle through siestas. For those who wish to get more out of their  day, the everyman cycle provides 4 thirty minute naps, and a 2-3 hour block  of sleep at night. Those looking to gain a sickening about of extra time in their  day can try the uberman, characterized by 6 twenty minute naps per day, and separated by a four hour period of being awake. Also, for those who need  the extra kick, drinking coffee before taking a nap increases the nap&#8217;s effectiveness, so long as the nap is kept to twenty minutes. There are  also sleep cycle apps in the iTunes store to help adjust to the different  sleep cycles.</em> (<a href="http://www.slideshare.net/security4all/sleephacking-101">slides</a>)</p>
<h3>Payment Application – Don’t Secure Sh!t (PA-DSS) (Christian “cmlh” Heinrich)</h3>
<p><em>Christian Heinrich gave a presentation entitled &#8220;Payment Application &#8211; Don&#8217;t Secure Sh!t.&#8221; The presentation characterized the differences  between the PA-DSS, PCI-DSS and PCI-PTS standards, focusing primarily on the  strengths and weaknesses of PA-DSS. Visa has mandated compliance of all machines with  this standard by 12 July 2012. The PA-DSS standard also depends on the  PCI-DSS standard, as there is no sense in reinventing the wheel. It does contain  a sunset clause for securing wireless data with WEP, as the newest  revision mandates WPA, as well as mandates secure remote software updates through  a system like SSL, although the most recent attacks on SSL have not been considered.</em> (<a href="http://www.slideshare.net/cmlh/padss">slides</a>)</p>
<p>Wow, excellent summaries from Justin and Chris. Thanks again guys! Additionally, every one of the speakers should have gotten a parting gift sponsored by <a href="http://trustedsignal.com/">Trusted Signal</a>. And if you want to relive the excitement of the Firetalks, be sure to check out IronGeek&#8217;s <a href="http://www.irongeek.com/i.php?page=videos/shmoocon-firetalks-2010">FireTalks from Shmoocon 2010</a> page. One of the things you may notice in the videos is the beautiful fireplace that helped cozy up this event. Mrs. Rybolov was kind enough to make this piece from scratch &#8230; and speaking of <a href="http://www.guerilla-ciso.com/">Rybolov</a>, he himself provided a tremendous amount of coordination throughout both nights. Before moving on to announcing the winners, I&#8217;d also like to thank the ShmooCon team (go Heidi &amp; Bruce and the rest of <a href="http://www.shmoo.com/">The Shmoo Group</a>!) for allowing us to host this event in conjunction with ShmooCon and providing space, a projector, and audio!</p>
<h2>Prize Winners</h2>
<p>Now on to the prize winners &#8230;</p>
<h3>3: Sleephacking 101 – How to Stay Awake for 20 Hours a Day without Turning into a Zombie</h3>
<p>security4all won at $75 Think Geek Gift Certificate from <a href="http://nvisiumsecurity.com/">nVisium Security</a>.</p>
<h3>2: Social Engineering Toolkit v0.4 Overview</h3>
<p>ReL1K received a 32GB Kanguru e-Flash brought to you by <a href="http://nvisiumsecurity.com/">nVisium Security</a>.</p>
<h3>1: SHODAN for Penetration Testers</h3>
<p>thePrez98 won the grand prize of a Acer Aspire One D250 Netbook provided by <a href="http://www.hurricanelabs.com/">Hurricane Labs</a>.</p>
<p>Congrats to everybody!</p>
<p style="text-align: center;">///</p>
<p>For all information regarding this year&#8217;s Firetalks and links to related posts, see the <a href="/2010/01/06/shmoocon-2010-firetalks/">ShmooCon 2010 Firetalks master post</a>. On a personal note I had a lot of fun pulling this whole thing together and it was great to meet so many awesome people that I&#8217;ve only previously chatted with on mailing lists, Twitter, etc. I look forward to trying to keep up with everyone throughout the year and maybe (if  I get lucky in the ShmooCon ticket lottery <img src='http://www.novainfosecportal.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> ) next year at ShmooCon. See ya!</p>
]]></content:encoded>
			<wfw:commentRss>http://www.novainfosecportal.com/2010/02/24/shmoocon-2010-firetalks-update-5-aka-the-wrap-up/feed/</wfw:commentRss>
		<slash:comments>10</slash:comments>
		</item>
		<item>
		<title>ShmooCon 2010 Firetalks &#8211; Update 4</title>
		<link>http://www.novainfosecportal.com/2010/02/03/shmoocon-2010-firetalks-update-4/</link>
		<comments>http://www.novainfosecportal.com/2010/02/03/shmoocon-2010-firetalks-update-4/#comments</comments>
		<pubDate>Wed, 03 Feb 2010 16:00:10 +0000</pubDate>
		<dc:creator>grecs</dc:creator>
				<category><![CDATA[Infosec Conferences]]></category>
		<category><![CDATA[conference]]></category>
		<category><![CDATA[dc]]></category>
		<category><![CDATA[event]]></category>
		<category><![CDATA[firetalks]]></category>
		<category><![CDATA[md]]></category>
		<category><![CDATA[nova]]></category>
		<category><![CDATA[shmoocon]]></category>
		<category><![CDATA[the shmoo group]]></category>

		<guid isPermaLink="false">http://www.novainfosecportal.com/?p=3307</guid>
		<description><![CDATA[Not too much has happened since last week &#8230; just tons of small stuff. We are still looking for some &#8220;prop&#8221; sponsors as well as alternate speakers. Also there are a few logistical changes we wanted to announce. Read on for all the details&#8230;
Sponsors
Most of the sponsorship opportunities have been covered however we are still [...]]]></description>
			<content:encoded><![CDATA[<p>Not too much has happened since last week &#8230; just tons of small stuff. We are still looking for some &#8220;prop&#8221; sponsors as well as alternate speakers. Also there are a few logistical changes we wanted to announce. Read on for all the details&#8230;</p>
<h2>Sponsors</h2>
<p>Most of the sponsorship opportunities have been covered however we are still looking for a few of the props. Specifically, there is  a <strong>Countdown Timer</strong>, <strong>Gong</strong>, and <strong>Logo</strong> (see the <a href="/2010/01/06/shmoocon-2010-firetalks/">master ShmooCon 2010 Firetalks</a> post for more information on these items). Out of these, I&#8217;d say the most important one is a Countdown timer. So if you don&#8217;t have a big budget but would like to help out, you can always volunteer to bring one of the above items. If you are interested,  either <a href="/contact-us/">contact us</a> or mention @<a href="http://twitter.com/grecs">grecs</a> on Twitter.</p>
<h2>Speakers</h2>
<p>Although all the official speaking spots are full as <a href="/2010/01/13/shmoocon-2010-firetalks-update-1/">reported three weeks ago</a>, we are <em>still </em>seeking people to add to our <strong>Alternates List</strong> just in case any of the confirmed presenters are unavailable. If any of the speakers are not present, we’ll just start calling people from the top of the list. At a minimum you&#8217;ll get some PR with your name and presentation title on the <a href="/2010/01/06/shmoocon-2010-firetalks/">master ShmooCon 2010 Firetalks</a> post.</p>
<p>To submit a talk, use the <a href="/contact-us/">Contact Us</a> link above. Enter your <strong>name </strong>as you want it to appear and use <strong>FireTalks </strong>as the subject. In the Message area please include the <strong>title </strong>of your talk as well as a <strong>one paragraph summary</strong> of your presentation. You can also include a <strong>link to your website</strong> or preferred social networking profile and we’ll link your name off to this site/profile.</p>
<h2>General Logistics</h2>
<p>CapSecDC is organizing a <strong>Bar Crawl</strong> for sometime on Friday night. Based on discussions with them, they&#8217;ll probably be starting before the Firetalks. Instead of having to choose between the Firetalks and the Bar Crawl,  we are working with them so FireTalk attendees can easily join up with the crawl midway. The general idea would be that they would be at a specific location around 10:30. That way anyone from the Firetalk session could just meet up with them to continue to enjoying the evening.</p>
<p>CapSecDC aren&#8217;t the only ones we&#8217;ve been working with. It just so happens that the <strong>Podcasters Meetup</strong> was originally scheduled to start the same time as the Firetalks on Saturday at 8:00 PM. After a few email exchanges we&#8217;ve realigned our start times to benefit all! The new plans are that the Podcasters Meetup will start at 7:30 instead of 8:00 and the Firetalks will start at 8:30. This will allow attendees to take part in both events. It does push the Firetalks a bit far into the Saturday night party &#8230; but you should still have plenty of time to enjoy it (assuming you can make it there with all the snow <img src='http://www.novainfosecportal.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> ).</p>
<p>In other logistical news we&#8217;ll be having several helpers run the Firetalks. <a href="http://www.guerilla-ciso.com/">Mike &#8220;rybolov&#8221; Smith</a> will be assisting us as well as a pair of interns, Justin Monroe and Chris Wheeler. Thanks guys! Additionally, we are still finalizing the exact location but we previously heard we&#8217;ll be in one of the Wilson rooms.</p>
<p>And the big news is that <a href="http://dualcoremusic.com/">Dual Core</a> will be providing some entertainment to get the Firetalks started as well as playing some good nerdcore in-between the speakers on Friday. We&#8217;ll have to spin our own on Saturday as they&#8217;ll be getting ready at Heaven &amp; Hell. Any volunteers?</p>
<p style="text-align: center;">///</p>
<p>This will be our final post &#8230; so from here on out, please check the <a href="/2010/01/06/shmoocon-2010-firetalks/">ShmooCon 2010 Firetalks master post</a> for the most up to date information or follow @<a href="http://twitter.com/grecs">grecs</a> on Twitter looking for the #<a href="http://search.twitter.com/search?q=&amp;ands=&amp;phrase=&amp;ors=&amp;nots=&amp;tag=shmoocon&amp;lang=all&amp;from=&amp;to=&amp;ref=&amp;near=&amp;within=15&amp;units=mi&amp;since=&amp;until=&amp;rpp=15">shmoocon</a> and #<a href="http://search.twitter.com/search?q=&amp;ands=&amp;phrase=&amp;ors=&amp;nots=&amp;tag=firetalks&amp;lang=all&amp;from=&amp;to=&amp;ref=&amp;near=&amp;within=15&amp;units=mi&amp;since=&amp;until=&amp;rpp=15">firetalks</a> tags. As usual, we’d like to thank the community for getting the word out and can&#8217;t wait to see everyone on Friday.  See ya!</p>
]]></content:encoded>
			<wfw:commentRss>http://www.novainfosecportal.com/2010/02/03/shmoocon-2010-firetalks-update-4/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>ShmooCon 2010 Cheat Sheet</title>
		<link>http://www.novainfosecportal.com/2010/02/03/shmoocon-2010-cheat-sheet/</link>
		<comments>http://www.novainfosecportal.com/2010/02/03/shmoocon-2010-cheat-sheet/#comments</comments>
		<pubDate>Wed, 03 Feb 2010 05:41:45 +0000</pubDate>
		<dc:creator>grecs</dc:creator>
				<category><![CDATA[Infosec Conferences]]></category>
		<category><![CDATA[conference]]></category>
		<category><![CDATA[dc]]></category>
		<category><![CDATA[event]]></category>
		<category><![CDATA[md]]></category>
		<category><![CDATA[nova]]></category>
		<category><![CDATA[shmoocon]]></category>
		<category><![CDATA[the shmoo group]]></category>

		<guid isPermaLink="false">http://www.novainfosecportal.com/?p=3322</guid>
		<description><![CDATA[With ShmooCon only a few days away and things getting announced left and right, we thought we&#8217;d put together a little plan of what we wanted to focus on. It didn&#8217;t take long to figure out that since there was just so much going on, we should probably create a little one page cheat sheet [...]]]></description>
			<content:encoded><![CDATA[<p>With ShmooCon only a few days away and things getting announced left and right, we thought we&#8217;d put together a little plan of what we wanted to focus on. It didn&#8217;t take long to figure out that since there was just so much going on, we should probably create a little one page cheat sheet for the conference. Now this isn&#8217;t anything too amazing but we find it useful and thought we&#8217;d share it out with everyone else.</p>
<p>We started with a simple matrix and then populated it with the different talks and other official activities. Then we hit Twitter and some mailing lists and pulled together a good little list of &#8220;Side Activities.&#8221; As part of this we also found some other interesting things going on, so we created an area called &#8220;Interesting Things.&#8221; We also came across a bunch of various Twitter users or tags being used for certain events so we threw them in and provided some structure.  I&#8217;m sure you get the point by now.</p>
<p>Anyway, check it out here &#8211; <a href="http://www.novainfosecportal.com/wp-content/uploads/2010/02/shmooconcheatsheet.pdf">ShmooCon 2010 Cheat Sheet</a>.</p>
<p>I&#8217;m sure we missed a bunch of things so please comment below for updates we should make. We are in particular need of information pertaining to other &#8220;Side Activities,&#8221; &#8220;Vendor Contests,&#8221; &#8220;Interesting Things,&#8221; and &#8220;Suggested Twitter Tags.&#8221; Also, there is also a lot white space left &#8230; so let us know of any new areas we should add. See ya!</p>
]]></content:encoded>
			<wfw:commentRss>http://www.novainfosecportal.com/2010/02/03/shmoocon-2010-cheat-sheet/feed/</wfw:commentRss>
		<slash:comments>20</slash:comments>
		</item>
		<item>
		<title>We Haz Sponsors (a.k.a., Firetalks &#8211; Update 3)</title>
		<link>http://www.novainfosecportal.com/2010/01/27/we-haz-sponsors-a-k-a-firetalks-update-3/</link>
		<comments>http://www.novainfosecportal.com/2010/01/27/we-haz-sponsors-a-k-a-firetalks-update-3/#comments</comments>
		<pubDate>Wed, 27 Jan 2010 16:00:57 +0000</pubDate>
		<dc:creator>grecs</dc:creator>
				<category><![CDATA[Infosec Conferences]]></category>
		<category><![CDATA[conference]]></category>
		<category><![CDATA[dc]]></category>
		<category><![CDATA[event]]></category>
		<category><![CDATA[firetalks]]></category>
		<category><![CDATA[md]]></category>
		<category><![CDATA[nova]]></category>
		<category><![CDATA[shmoocon]]></category>
		<category><![CDATA[the shmoo group]]></category>

		<guid isPermaLink="false">http://www.novainfosecportal.com/?p=3254</guid>
		<description><![CDATA[Well our call for sponsors last week was a huge success! Again we&#8217;d like to thank everyone for RTing or otherwise getting the word out. In the meantime if you are a sponsor or know of people still looking to get involved in ShmooCon, check out the Podcasters Meetup&#8217;s latest post.
Now on to the big [...]]]></description>
			<content:encoded><![CDATA[<p>Well our <a href="/2010/01/19/call-for-shmoocon-firetalk-sponsors-a-k-a-update-2/">call for sponsors</a> last week was a huge success! Again we&#8217;d like to thank everyone for RTing or otherwise getting the word out. In the meantime if you are a sponsor or know of people still looking to get involved in ShmooCon, check out the <a href="http://www.podcastersmeetup.com/">Podcasters Meetup&#8217;s</a> <a href="http://www.podcastersmeetup.com/updates/2010/1/22/attendance.html">latest post</a>.</p>
<p>Now on to the big news at hand &#8230; the announcement of the ShmooCon 2010 Firetalk sponsors!!!</p>
<h2>Sponsors</h2>
<p>First I&#8217;d like to mention the many folks that&#8217;ll be helping out in the props area.</p>
<ul>
<li>Projector/Space: <a href="http://www.shmoocon.org/">ShmooCon Team</a></li>
<li>Session Recordings: <a href="http://www.irongeek.com/">Adrian &#8220;IronGeek&#8221; Crenshaw</a> (<a href="http://www.grmn00bs.com/">Georgia Weidman</a> for backup)</li>
<li>Fake Cardboard Fireplace: <a href="http://www.guerilla-ciso.com/">Mike &#8220;rybolov&#8221; Smith</a></li>
</ul>
<p>Note that we are still looking for a <strong>Countdown Timer</strong>, <strong>Gong</strong>, and <strong>Logo</strong> (see the <a href="/2010/01/06/shmoocon-2010-firetalks/">master ShmooCon 2010 Firetalks</a> post for more information on these items). So if you don&#8217;t have a big budget but would like to help out, you can always volunteer to bring one of the above items. As noted before, either <a href="/contact-us/">contact us</a> or mention @<a href="http://twitter.com/grecs">grecs</a> on Twitter if you&#8217;re interested.</p>
<p>Now on to the participant give-aways and prizes&#8230;</p>
<h3>Participant Give-Aways</h3>
<p>All of the below items are being brought to you by <a href="http://trustedsignal.com/">Trusted Signal</a>.</p>
<ul>
<li>Wi-Fi Detector Shirt (2)</li>
<li>RFID Blocking Wallet (2)</li>
<li>Autoloader &#8211; Screwdriver Tool (2)</li>
<li>Phantom Keystroker V2 (2)</li>
</ul>
<p><img class="alignnone size-medium wp-image-3285" title="trusted_logo" src="http://www.novainfosecportal.com/wp-content/uploads/2010/01/trusted_logo-300x93.jpg" alt="trusted_logo" width="300" height="93" /></p>
<h3>2nd Runner-Up</h3>
<p>$75 Think Geek Gift Certificate from <a href="http://nvisiumsecurity.com/">nVisium Security</a><br />
<img class="size-medium wp-image-3273 alignnone" title="nvisium_logo" src="http://www.novainfosecportal.com/wp-content/uploads/2010/01/nvisium_logo-300x103.png" alt="nvisium_logo" width="300" height="103" /></p>
<h3>1st Runner-Up</h3>
<p>32GB Kanguru e-Flash (eSATA &amp; USB2.0 Flash Drive) courtesy <a href="http://nvisiumsecurity.com/">nVisium Security</a><br />
<img class="size-medium wp-image-3273 alignnone" title="nvisium_logo" src="http://www.novainfosecportal.com/wp-content/uploads/2010/01/nvisium_logo-300x103.png" alt="nvisium_logo" width="300" height="103" /></p>
<p>And finally &#8230; (drum roll please) &#8230;</p>
<h3>Grand Prize</h3>
<p>Acer Aspire One D250 Netbook brought to you by <a href="http://www.hurricanelabs.com/">Hurricane Labs</a>.</p>
<p><img class="alignnone size-full wp-image-3274" title="hurricanelabs_logo" src="http://www.novainfosecportal.com/wp-content/uploads/2010/01/hurricanelabs_logo.gif" alt="hurricanelabs_logo" width="189" height="112" /></p>
<h2>Speakers</h2>
<p>Although all the official speaking spots are full as <a href="/2010/01/13/shmoocon-2010-firetalks-update-1/">reported two weeks ago</a>, we are <em>still </em>seeking people to add to our <strong>Alternates List</strong> just in case any of the confirmed presenters are unavailable. If any of the speakers are not present, we’ll just start calling people from the top of the list. At a minimum you&#8217;ll get some PR with your name and title on the <a href="/2010/01/06/shmoocon-2010-firetalks/">master ShmooCon 2010 Firetalks</a> post.</p>
<p>To submit a talk, use the <a href="/contact-us/">Contact Us</a> link above. Enter your <strong>name </strong>as you want it to appear and use <strong>FireTalks </strong>as the subject. In the Message area please include the <strong>title </strong>of your talk as well as a <strong>one paragraph summary</strong> of your presentation. You can also include a <strong>link to your website</strong> or preferred social networking profile and we’ll link your name off to this site/profile.</p>
<p style="text-align: center;">///</p>
<p>Well it&#8217;s been a great week with getting most of the sponsor stuff taken care of. As usual, we’d like to thank the community for getting the word out! We really appreciate all the RTs and mentions. And if you&#8217;d like to RT this post, we wouldn&#8217;t mind that at all. See ya!</p>
]]></content:encoded>
			<wfw:commentRss>http://www.novainfosecportal.com/2010/01/27/we-haz-sponsors-a-k-a-firetalks-update-3/feed/</wfw:commentRss>
		<slash:comments>13</slash:comments>
		</item>
		<item>
		<title>Call for ShmooCon Firetalk Sponsors (a.k.a. Update 2)</title>
		<link>http://www.novainfosecportal.com/2010/01/19/call-for-shmoocon-firetalk-sponsors-a-k-a-update-2/</link>
		<comments>http://www.novainfosecportal.com/2010/01/19/call-for-shmoocon-firetalk-sponsors-a-k-a-update-2/#comments</comments>
		<pubDate>Tue, 19 Jan 2010 16:00:57 +0000</pubDate>
		<dc:creator>grecs</dc:creator>
				<category><![CDATA[Infosec Conferences]]></category>
		<category><![CDATA[conference]]></category>
		<category><![CDATA[dc]]></category>
		<category><![CDATA[event]]></category>
		<category><![CDATA[firetalks]]></category>
		<category><![CDATA[md]]></category>
		<category><![CDATA[nova]]></category>
		<category><![CDATA[shmoocon]]></category>
		<category><![CDATA[the shmoo group]]></category>

		<guid isPermaLink="false">http://www.novainfosecportal.com/?p=3205</guid>
		<description><![CDATA[Not much has changed from last week&#8217;s update&#8230; All the speaker slots are still full&#8230; We still have 2 alternative talks&#8230; Got space and support from the ShmooCon organizers&#8230; Everything is going to get recorded&#8230; And we are getting tons of support from the infosec community &#8211; thanks again to everyone&#8230; As you can tell [...]]]></description>
			<content:encoded><![CDATA[<p>Not much has changed from last week&#8217;s update&#8230; All the speaker slots are still full&#8230; We still have 2 alternative talks&#8230; Got space and support from the ShmooCon organizers&#8230; Everything is going to get recorded&#8230; And we are getting tons of support from the infosec community &#8211; thanks again to everyone&#8230; As you can tell by the title of this post, the big focus this week is sponsors.</p>
<h2>Sponsors</h2>
<p>We&#8217;ve gotten various support for some of the logistical props in terms of a projector and space from <a href="http://www.shmoocon.org/">the ShmooCon team</a> and recording of the sessions by <a href="http://www.irongeek.com/">Adrian &#8220;IronGeek&#8221; Crenshaw</a>. However we are still in desperate need for sponsors of the <strong>prizes and participant give-aways</strong>. Although I would rather focus more on the the non-money aspects of the event, some have asked for general guidelines on the cost of the different prize levels so I&#8217;ve included suggested values below. Ideally, the prizes would most likely be geek toys from vendors valued at these suggestions.</p>
<ul>
<li>Grand Prize: $250</li>
<li>1st Runner-Up: $125</li>
<li>2nd Runner-Up: $75</li>
<li>5 Participant Give-Aways: $100 (or $20 each)</li>
</ul>
<p>Additionally, there are still several props we are looking for including <strong>Fake Cardboard Fireplace</strong>, <strong>Countdown Timer</strong>, <strong>Gong</strong>, and <strong>Logo</strong>. So if you don&#8217;t have a big budget but would like to help out, you can always volunteer to bring one of the above items.</p>
<p>If you know any companies willing to support prizes, please have them <a href="/contact-us/">contact us</a> or mention @<a href="http://twitter.com/grecs">grecs</a> on Twitter and point them to the Sponsors section in our <a href="/2010/01/06/shmoocon-2010-firetalks/">master post</a> for more details on the different options. You can pass along this longish bit.ly link we created to point to the main Firetalks post – <a href="http://bit.ly/nipshmoocon2010firetalks">bit.ly/nipshmoocon2010firetalks</a>.</p>
<h2>Speakers</h2>
<p>Although all the official speaking spots are full, we&#8217;d like to take this opportunity to encourage others to continue submitting their ideas. As <a href="/2010/01/13/shmoocon-2010-firetalks-update-1/">mentioned last week</a> we have an <strong>Alternates List</strong> just in case any of the presenters are unavailable. If any of the speakers are not available, we’ll just start calling people from the top of the list. At a minimum you&#8217;ll get some PR with your name and title on the <a href="/2010/01/06/shmoocon-2010-firetalks/">master ShmooCon 2010 Firetalks</a> post.</p>
<p>To submit a talk, use the <a href="/contact-us/">Contact Us</a> link above. Enter your <strong>name </strong>as you want it to appear and use <strong>FireTalks </strong>as the subject. In the Message area please include the <strong>title </strong>of your talk as well as a <strong>one paragraph summary</strong> of your presentation. You can also include a <strong>link to your website</strong> or preferred social networking profile and we’ll link your name off to this site/profile.</p>
<h2>General Logistics</h2>
<p>We&#8217;ve been looking at the schedule and decided that we&#8217;ll probably have to <strong>extend the length of the event</strong> a little so things run a bit smoother. With this in mind we will be adding 20 minutes for a 5 minute introduction and 5 minute breaks between each of the talks. That brings our total running time to about <strong>1 hour and 20 minutes</strong> each night.</p>
<p style="text-align: center;">///</p>
<p>Well a slow week with a little progress &#8230; but progress nonetheless. Again, we’d like to thank the community for getting the word out! We really appreciate all the RTs and mentions. And if you&#8217;d like to RT this post, we wouldn&#8217;t mind that at all. Here&#8217;s even a nice link you can RT out &#8211; <a href="http://bit.ly/nipshmoocon2010firetalks">bit.ly/nipshmoocon2010firetalks</a>.  See ya!</p>
]]></content:encoded>
			<wfw:commentRss>http://www.novainfosecportal.com/2010/01/19/call-for-shmoocon-firetalk-sponsors-a-k-a-update-2/feed/</wfw:commentRss>
		<slash:comments>17</slash:comments>
		</item>
		<item>
		<title>ShmooCon 2010 Firetalks &#8211; Update 1</title>
		<link>http://www.novainfosecportal.com/2010/01/13/shmoocon-2010-firetalks-update-1/</link>
		<comments>http://www.novainfosecportal.com/2010/01/13/shmoocon-2010-firetalks-update-1/#comments</comments>
		<pubDate>Wed, 13 Jan 2010 16:00:27 +0000</pubDate>
		<dc:creator>grecs</dc:creator>
				<category><![CDATA[Infosec Conferences]]></category>
		<category><![CDATA[conference]]></category>
		<category><![CDATA[dc]]></category>
		<category><![CDATA[event]]></category>
		<category><![CDATA[firetalks]]></category>
		<category><![CDATA[md]]></category>
		<category><![CDATA[nova]]></category>
		<category><![CDATA[shmoocon]]></category>
		<category><![CDATA[the shmoo group]]></category>

		<guid isPermaLink="false">http://www.novainfosecportal.com/?p=3109</guid>
		<description><![CDATA[Based on last year&#8217;s series of posts, we came up with an ingenious naming scheme of Update 1, Updated 2, etc. for update posts related to this year&#8217;s Firetalks.   These posts will just contain the new stuff and all this information will be incorporated back into the master ShmooCon 2010 Firetalks post we [...]]]></description>
			<content:encoded><![CDATA[<p>Based on last year&#8217;s series of posts, we came up with an ingenious naming scheme of Update 1, Updated 2, etc. for update posts related to this year&#8217;s Firetalks. <img src='http://www.novainfosecportal.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' />  These posts will just contain the new stuff and all this information will be incorporated back into the <a href="/2010/01/06/shmoocon-2010-firetalks/">master ShmooCon 2010 Firetalks post</a> we put out last week.</p>
<h2>Speakers</h2>
<p>First off, I&#8217;d like to put out a <strong>HUGE &#8220;Thank You&#8221;</strong> to the infosec community for spreading the word on this year&#8217;s Firetalks. And I&#8217;m excited to say that because of everyone&#8217;s support, we&#8217;ve filled <strong>all of the presentation slots</strong>! Here is a quick list of the topics and the presenters.</p>
<p>Friday</p>
<ul>
<li><strong>Social Engineering Toolkit v0.3 Overview</strong> <em>(David “ReL1K” Kennedy)</em></li>
<li><strong>SHODAN for Penetration Testers</strong> <em>(Michael &#8220;theprez98&#8243; Schearer)</em></li>
<li><strong>Influencing Security</strong> <em>(Marcus J. Carey)</em></li>
<li><strong>Funnypots and Skiddy Baiting</strong> <em>(Adrian “IronGeek” Crenshaw)</em></li>
</ul>
<p>Saturday</p>
<ul>
<li><strong>Browser Fingerprinting Using a Stopwatch</strong> <em>(Nicholas &#8220;aricon&#8221; Berthaume)</em></li>
<li><strong>Pentoo</strong> <em>(Zero Chaos)</em></li>
<li><strong>Sleephacking 101 – How to Stay Awake for 20 Hours a Day without Turning into a Zombie</strong> (<em>Benny </em>&#8220;security4all&#8221; <em>???)</em></li>
<li><strong>Fuzzing Web Applications with Nymf</strong> <em>(Jack Mannino)</em></li>
</ul>
<p>The <a href="/2010/01/06/shmoocon-2010-firetalks/">master post</a> contains additional details on each talk. But even if you didn&#8217;t make the above list, you still might get to present your idea! Because there&#8217;s been such a great response, we&#8217;ve decided to open up an <strong>Alternates</strong> <strong>List </strong>just in case any of the presenters are unavailable. As an alternate you&#8217;ll have to be present and ready to speak. If one of the speakers is not available, we&#8217;ll just start calling people from the top of the list. And so far we have two additional submissions!</p>
<h2>Sponsors</h2>
<p>On the sponsor front Adrian has stepped up to record the audio and video (split screen even) for both sessions! For an example of what to expect, see his test over at <a href="http://vimeo.com/8598742">Vimeo</a>. Additionally, the ShmooCon team has offered to hold a space for us as well as lend us a projector. Beyond these two additions, we are <strong>still in need for other <span style="text-decoration: underline;">sponsors</span></strong>, especially for the prizes. If you know any companies willing to support this effort, please have them <a href="/contact-us/">contact us</a> and point them to the Sponsors section in our <a href="/2010/01/06/shmoocon-2010-firetalks/">master post</a> for the different options. You can pass along this longish bit.ly link we created to point to the main Firetalks post &#8211; <a href="http://bit.ly/nipshmoocon2010firetalks">bit.ly/nipshmoocon2010firetalks</a>.</p>
<p>Speaking of sponsors &#8230; Adrian also came up with the great idea of having a <strong>Firetalks logo</strong>. I have no design skillz so if someone out there has any artisic ability, this is another way you can help us out. The logo at a minimum would be embedded in the videos that Adrian will be creating. If we have time, we hope to create a banner or something.</p>
<h2>General Logistics</h2>
<p>Beyond getting speakers and sponsors we&#8217;ve also been working with the ShmooCon team to coordinate Firetalks fitting nicely into the overall conference schedule. As mentioned above they are already supporting us in several ways however they would like us to move the start of the talks to 8:30 on Friday night so it won&#8217;t interfere with the end of the keynote. So we&#8217;ve made this change on the <a href="/2010/01/06/shmoocon-2010-firetalks/">master post</a> as well.</p>
<p style="text-align: center;">///</p>
<p>Filling all speaker slots as well as getting the sessions recorded and support from the ShmooCon team &#8230; Its been a great first week! Again, we&#8217;d like to thank the community for getting the word out! As you known, you can never have too much PR &#8230; so we&#8217;d appreciate any continued efforts to spread the word! Just pass along the link to our <a href="/2010/01/06/shmoocon-2010-firetalks/">master post</a> or our &#8220;easy-to-remember&#8221; <a href="http://bit.ly/nipshmoocon2010firetalks">bit.ly/nipshmoocon2010firetalks</a> link.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.novainfosecportal.com/2010/01/13/shmoocon-2010-firetalks-update-1/feed/</wfw:commentRss>
		<slash:comments>23</slash:comments>
		</item>
		<item>
		<title>ShmooCon 2010 FireTalks</title>
		<link>http://www.novainfosecportal.com/2010/01/06/shmoocon-2010-firetalks/</link>
		<comments>http://www.novainfosecportal.com/2010/01/06/shmoocon-2010-firetalks/#comments</comments>
		<pubDate>Wed, 06 Jan 2010 16:00:57 +0000</pubDate>
		<dc:creator>grecs</dc:creator>
				<category><![CDATA[Infosec Conferences]]></category>
		<category><![CDATA[conference]]></category>
		<category><![CDATA[dc]]></category>
		<category><![CDATA[event]]></category>
		<category><![CDATA[firetalks]]></category>
		<category><![CDATA[md]]></category>
		<category><![CDATA[nova]]></category>
		<category><![CDATA[shmoocon]]></category>
		<category><![CDATA[the shmoo group]]></category>

		<guid isPermaLink="false">http://www.novainfosecportal.com/?p=3063</guid>
		<description><![CDATA[We really enjoyed the FireTalks that took place last year. It was the first chance we really got to meet a lot of the online friends we made up to that point. Now with the completion of the third round of tickets we started thinking about how we could take more of an active part [...]]]></description>
			<content:encoded><![CDATA[<p>We really enjoyed the FireTalks that took place last year. It was the first chance we really got to meet a lot of the online friends we made up to that point. Now with the completion of the third round of tickets we started thinking about how we could take more of an active part in the conference. Since we really don&#8217;t have any budget beyond what&#8217;s in @<a href="http://twitter.com/grecs">grecs</a>&#8216; dwindling bank account (hint, hint, hint &#8211; NovaInfosecPortal.com is always looking for <a href="/general/help-us-help-you/">subscribers</a> and <a href="/general/advertise-with-us/">advertisers</a>), being a cash sponsor was a little out of the question for us. So the next best thing was to sponsor our time &#8230; and so this we did by volunteering to run the ShmooCon 2010 FireTalks. I don&#8217;t know how it will turn out but hopefully it will be as good as last year!</p>
<p>For all the latest happenings, check back to this post periodically. It will be the home for any and all information relating to the ShmooCon 2010 FireTalks. You may want to use a service like <a href="http://www.changedetection.com/">ChangeDetection.com</a> to get email alerts of any updates. Alternatively, you can subscribe to our <a href="http://feeds.feedburner.com/novainfosecportalblog">main RSS feed</a> or follow us on Twitter at @<a href="http://twitter.com/novainfosec">novainfosec</a> since we&#8217;ll put out short &#8220;update&#8221; posts with just the new information and a pointer back to this &#8220;master&#8221; post. And as usual &#8230; I&#8217;ll be regularly updating my Twitter stream at @<a href="http://twitter.com/grecs">grecs</a> with all the information and will be using the #<a href="http://search.twitter.com/search?q=&amp;ands=&amp;phrase=&amp;ors=&amp;nots=&amp;tag=firetalks&amp;lang=all&amp;from=&amp;to=&amp;ref=&amp;near=&amp;within=15&amp;units=mi&amp;since=&amp;until=&amp;rpp=15">firetalks</a> tag. If you need to quickly refer back to this post, you can also use the longish bit.ly link we create at <a href="http://bit.ly/nipshmoocon2010firetalks">bit.ly/nipshmoocon2010firetalks</a>.</p>
<p>Anyway &#8230; here are the logistics for this year&#8217;s FireTalks in traditional NovaInfosecPortal.com form:</p>
<ul>
<li><strong>Who:</strong> ShmooCon/PodcastersMeetup/NovaInfosecPortal.com (and anyone else we&#8217;re missing)</li>
<li><strong>What:</strong> ShmooCon 2010 FireTalks</li>
<li><strong>When:</strong> 2/5, 8:30 &#8211; 9:50 &amp; 2/6/2010, 8:30 &#8211; 9:50 PM EST</li>
<li><strong>Where:</strong> <a href="http://www.marriott.com/hotels/travel/wasdt-washington-marriott-wardman-park/">Wardman Park Marriott</a> (<a href="http://maps.google.com/maps?f=q&amp;source=s_q&amp;hl=en&amp;geocode=&amp;q=2660+Woodley+Road+NW+Washington+DC+20008&amp;sll=37.0625,-95.677068&amp;sspn=38.092988,67.675781&amp;ie=UTF8&amp;hq=&amp;hnear=2660+Woodley+Rd+NW,+Washington,+District+of+Columbia,+20008&amp;z=16">2660 Woodley Road NW, Washington, DC 20008</a>; Wilson A/B/C)</li>
</ul>
<p>Now onto what this whole FireTalks thing is and how to get involved&#8230;</p>
<h2>History</h2>
<p>Instead of reinventing the wheel to explain things, we just went back and took a look at what was done last year. The idea of Firetalks seemed to originate with Michael Santarcangelo. The post titled &#8220;<a href="http://www.podcastersmeetup.com/updates/2009/1/8/podcasters-meetup-shmoocon.html">Podcaster&#8217;s Meetup @ ShmooCon</a>&#8221; by @<a href="http://twitter.com/mubix">mubix </a>on PodcastersMeetup.com seemed to be the first place that this idea came up. As part of several announcements, one of them was this interesting idea from Michael.</p>
<p style="padding-left: 30px;"><em>&#8220;Michael Santarcangelo, the Security Catalyst community and the Security Twits have come up with a group that will be doing after hours presentations. So, if you were declined, didn&#8217;t submit but have a talk, or just want to learn to speak by watching the critiques that go on, please come out an join us. The main goal of these after hours talks is to foster the development of the speaker in a less imposing environment than a ShmooCon track. Depending on the responses we get, we may be doing these talks all three nights. &#8230;&#8221;</em></p>
<p>This idea was followed up with a more focused definition in an update post aptly titled &#8220;<a href="http://www.podcastersmeetup.com/updates/2009/1/21/podcasters-meetup-shmoocon-update-1.html">Podcaster&#8217;s Meetup @ ShmooCon Update 1</a>&#8221; again by @<a href="http://twitter.com/mubix">mubix</a>. Here is where the term &#8220;Firetalks&#8221; was first used as far as I can tell.</p>
<p style="padding-left: 30px;"><em>&#8220;Have a talk that didn’t get accepted? Want the chance to share a project that you are working on? Think of FireTalks as a verbal blog post. The human experience is built on the ability to tell and learn from stories. At SchmooCon 2009, “FireTalks” is a supportive environment in which to either share insights or learn from others. Whether polishing a presentation (story) for conferences, meetings or training, FireTalks are the way to share, learn and improve. The inaugural FireTalks take place Friday night — following the Podcasters Meetup. Talks are limited to 10-15 minutes with four (4) scheduled talks and four (4) open slots. Open slots will be filled on a first come, first serve basis. Saturday night will be more relaxed. Come join us and present, listen and learn.&#8221;</em></p>
<h2>Speakers</h2>
<p>We will have four 15-minute speaking slots each night and as noted above these have been filled on a first-come-first-serve basis. If needed each speaker must have their own laptop to connect to a standard projector.</p>
<p>Because there’s been such a great response, we’ve decided to open up this <strong>Alternates List</strong> just in case any of the presenters are unavailable. As an alternate you’ll have to be present and ready to speak. If one of the speakers is not available, we’ll just start calling people from the top of the list.</p>
<p>To submit an alternate talk, use the <a href="/contact-us/">Contact Us</a> link above. Enter your <strong>name</strong> as you want it to appear below and use <strong>FireTalks</strong> as the subject. In the Message area please include the <strong>title</strong> of your talk as well as a <strong>one paragraph summary</strong> of your presentation. You can also include a <strong>link to your website</strong> or preferred social networking profile and we&#8217;ll link your name off to this site/profile.</p>
<table border="1">
<tbody>
<tr>
<td></td>
<td><strong>Name </strong></td>
<td><strong>Title</strong></td>
<td><strong>Description</strong></td>
</tr>
<tr>
<td><strong>Friday</strong></td>
<td>David &#8220;ReL1K&#8221; Kennedy</td>
<td>Social Engineering Toolkit v0.4 Overview</td>
<td>The Social-Engineer Toolkit v0.4 (SET) Codename &#8220;Pink Pirate&#8221; will be released at the firetalk exclusively on BackTrack 4. SET is a security professionals most valuable tool when it comes to social engineering attacks and incorporates some heavily advanced and complicated attacks. The new version is one of the biggest releases yet and incorporate new methods for attacking the clients and some super top secret stuff being released during the talk.</td>
</tr>
<tr>
<td></td>
<td><a href="http://twitter.com/theprez98">Michael &#8220;theprez98&#8243; Schearer</a></td>
<td>SHODAN for Penetration Testers</td>
<td>SHODAN is a computer search engine. But is is unlike any other search engine. While other search engines scour the web for content, SHODAN scans for information about the sites themselves. The result is a search engine that aggregates banners from well-known services. For penetration testers, SHODAN is a game-changer, and a goldmine of potential vulnerabilities.</td>
</tr>
<tr>
<td></td>
<td><a href="http://www.saecur.com/">Marcus J. Carey</a></td>
<td>Influencing Security</td>
<td>This talk compares information security and health epidemics such as HIV/AIDS. I&#8217;ll discuss critical behavior changes which have reduced HIV/AIDS in some countries and what information security can learn from the same approach.</td>
</tr>
<tr>
<td></td>
<td><a href="http://www.irongeek.com/">Adrian &#8220;IronGeek&#8221; Crenshaw</a></td>
<td>Funnypots and Skiddy Baiting</td>
<td>Ever wanted to screw with those that screw with you? Honeypots might be ok for research, but they don’t allow you to have fun at an attacker’s expense the same way funnypot and skiddy baiting does. In this talk I’ll be covering techniques you can use to scar the psyche or to have fun at the expense of attackers or people invading your privacy. Some of the topics to be covered are: Fun with DNS and Loopback, SWATing for Packets, Lemonwipe your drive, Robots.txt trolling, And more&#8230;</td>
</tr>
<tr>
<td><strong>Saturday</strong></td>
<td><a href="http://twitter.com/nberthaume">Nicholas &#8220;aricon&#8221; Berthaume</a></td>
<td>Browser Fingerprinting Using a Stopwatch</td>
<td>There are number of methods for fingerprinting a user&#8217;s browser. Most of the commonly employed methods are poor at best and can be spoofed. I believe that a another approach is needed. Using mod_security and standard deviation to detect rendering engine nuances for accurate browser and patch level detection server-side. When using JavaScript, header analysis and CSS implementations are not enough.</td>
</tr>
<tr>
<td></td>
<td><a href="http://www.pentoo.ch/">Zero Chaos</a></td>
<td>Pentoo</td>
<td>Ever wish you could carry around your favorite pen-testing distribution on a cd, or a usb stick? Tried popular offerings but feeling like they pander to a different segment? Come hear about Pentoo. At Pentoo we pander to experienced linux users who are more likely to use their gpu for cracking passwords than &#8220;teh cubez&#8221; and fancy window makers. Come see what all the fuss it about.</td>
</tr>
<tr>
<td></td>
<td><a href="http://twitter.com/security4all">Benny &#8220;security4all&#8221; ???</a></td>
<td>Sleephacking 101 &#8211; How to Stay Awake for 20 Hours a Day without Turning into a Zombie</td>
<td>Everyone of us has busy periods or just too many things todo. You start sleeping less and drinking loads of coffee. Both of which are not good for your health. This talk will talk about why our body and mind actually need sleep and how you can hack it. We will discuss some methods on how to enable yourself to stay awake for 20 hours a day without turning into a zombie (and without the use of drugs).</td>
</tr>
<tr>
<td></td>
<td><a href="http://twitter.com/cmlh">Christian  &#8220;cmlh&#8221; Heinrich</a></td>
<td>Payment Application &#8211; Don&#8217;t Secure Sh!t (PA-DSS)</td>
<td>Considering a majority of PCI related presentations focus on the  &#8220;benefit&#8221; and &#8220;increase&#8221; to &#8220;security&#8221; are delivered by consultants and  vendors whose sole agenda is their financial benefit in implementing  PCI-DSS, the failures and their root causes within the lesser known  Payment Application Data Security Standard (PA-DSS) will be explored.</td>
</tr>
</tbody>
</table>
<p><strong>Alternates List</strong></p>
<ul>
<li><a href="http://www.secanalysis.com/">Michael Montejam Montecillo</a>: Profiling and Tracking in 15 Minutes
<ul>
<li>Whether seeking information about a company for employment purposes or figuring out exactly who is flooding your IPS/IDS, tracking and profiling can be valuable skills for any security professional. This talk will discuss tools and techniques for profiling companies, tracking hacker activity, and identifying potential threats through Open-Source Intelligence (OSINT). There will be a particular focus on applying the hacker mindset to make determinations based on available data.</li>
</ul>
</li>
<li>Ralph &#8220;ralphbroom&#8221; Broom: TBD
<ul>
<li>TBD</li>
</ul>
</li>
</ul>
<h2>Prizes/Sponsors</h2>
<p>Awards will be based on a 3-person panel scoring each presentation from 1 to 10. In case of a tie, we&#8217;ll maybe have a forth person pick the final winner.</p>
<p>Most of the sponsorship opportunities have been covered however we are still looking for a <strong>Countdown Timer</strong>, <strong>Gong</strong>, and <strong>Logo</strong>. So if you don&#8217;t have a big budget but would like to help out, you can always volunteer to bring one of these items.</p>
<table border="1">
<tbody>
<tr>
<td><strong>Prizes<br />
</strong></td>
<td><strong> Sponsors</strong></td>
</tr>
<tr>
<td>Grand Prize (~$250) &#8211; <a href="http://www.amazon.com/Acer-AOD250-1842-10-1-Inch-Black-Netbook/dp/B002MUCC7K/ref=sr_1_3?ie=UTF8&amp;s=electronics&amp;qid=1265592714&amp;sr=8-3">Acer Aspire One D250 Netbook</a></p>
<p><img class="alignnone size-full wp-image-3348" title="acernetbook" src="http://www.novainfosecportal.com/wp-content/uploads/2010/01/acernetbook.png" alt="acernetbook" width="156" height="123" /></td>
<td>Brought to you by <a href="http://www.hurricanelabs.com/">Hurricane Labs</a><br />
<img class="alignnone size-full wp-image-3274" title="hurricanelabs_logo" src="http://www.novainfosecportal.com/wp-content/uploads/2010/01/hurricanelabs_logo.gif" alt="hurricanelabs_logo" width="189" height="112" /></td>
</tr>
<tr>
<td>1st Runner-Up Prize (~$125) &#8211; <a href="http://www.amazon.com/Kanguru-Solutions-KEFL-32G-E-flash-USB2-0/dp/B001O2JC7U/ref=sr_1_1?ie=UTF8&amp;s=electronics&amp;qid=1264631457&amp;sr=8-1">32GB Kanguru e-Flash (eSATA &amp; USB2.0 Flash Drive)</a></p>
<p><img class="alignnone size-medium wp-image-3304" title="kanguru" src="http://www.novainfosecportal.com/wp-content/uploads/2010/01/kanguru-300x95.jpg" alt="kanguru" width="184" height="58" /></td>
<td>Courtesy <a href="http://nvisiumsecurity.com/">nVisium Security</a><br />
<img class="size-medium wp-image-3273 alignnone" title="nvisium_logo" src="http://www.novainfosecportal.com/wp-content/uploads/2010/01/nvisium_logo-300x103.png" alt="nvisium_logo" width="300" height="103" /></td>
</tr>
<tr>
<td>2nd Runner-Up (~$75) &#8211; <a href="http://www.thinkgeek.com/">$75 Think Geek Gift Certificate</a></p>
<p><img class="alignnone size-full wp-image-3305" title="thinkgeeklogo" src="http://www.novainfosecportal.com/wp-content/uploads/2010/01/thinkgeeklogo.gif" alt="thinkgeeklogo" width="201" height="74" /></td>
<td>From <a href="http://nvisiumsecurity.com/">nVisium Security</a><br />
<img class="size-medium wp-image-3273 alignnone" title="nvisium_logo" src="http://www.novainfosecportal.com/wp-content/uploads/2010/01/nvisium_logo-300x103.png" alt="nvisium_logo" width="300" height="103" /></td>
</tr>
<tr>
<td>Participant Give-Aways (~$100 or $20 each) &#8211;  Open</p>
<ul>
<li>Wi-Fi Detector Shirt (2)</li>
<li>RFID Blocking Wallet (2)</li>
<li>Autoloader &#8211; Screwdriver Tool (2)</li>
<li>Phantom Keystroker V2 (2)</li>
<li>[plus other stuff I can't mention <img src='http://www.novainfosecportal.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> ]</li>
</ul>
</td>
<td>Brought to you by <a href="http://trustedsignal.com/">Trusted Signal</a><br />
<img class="alignnone size-medium wp-image-3285" title="trusted_logo" src="http://www.novainfosecportal.com/wp-content/uploads/2010/01/trusted_logo-300x93.jpg" alt="trusted_logo" width="300" height="93" /></td>
</tr>
<tr>
<td><strong>Props</strong></td>
<td></td>
</tr>
<tr>
<td>Projector/Space</td>
<td><a href="http://www.shmoocon.org/">ShmooCon Team</a></td>
</tr>
<tr>
<td>Session Recordings</td>
<td><a href="http://www.irongeek.com/">Adrian &#8220;IronGeek&#8221; Crenshaw</a> (<a href="http://www.grmn00bs.com/">Georgia Weidman</a> for HD backup version)</td>
</tr>
<tr>
<td>Fake Cardboard Fireplace</td>
<td><a href="http://www.guerilla-ciso.com/">Mike &#8220;rybolov&#8221; Smith</a></td>
</tr>
<tr>
<td>Countdown Timer with Large Red Numbers</td>
<td>Open</td>
</tr>
<tr>
<td>Gong (this could be fun)</td>
<td>Open</td>
</tr>
<tr>
<td>Firetalks Logo</td>
<td>Open</td>
</tr>
</tbody>
</table>
<p>For all our illustrious sponsors, you get your logo placed here and several mentions during the event. If you are lending any of the stage props above, feel free to include your logo on it as well. We are open to other suggestions (e.g., some small signs you can post up around the event) but this will depend on what ShmooCon will and will not let us do.</p>
<p>Use the <a href="/contact-us/">Contact Us</a> link above or mention @<a href="http://twitter.com/grecs">grecs</a> on Twitter to get in touch with us if you are interested in sponsoring.</p>
<h2>Related Posts</h2>
<ul>
<li><a href="/2010/01/13/shmoocon-2010-firetalks-update-1/">ShmooCon 2010 Firetalks – Update 1</a></li>
<li><a href="/2010/01/19/call-for-shmoocon-firetalk-sponsors-a-k-a-update-2/">Call for ShmooCon Firetalk Sponsors (a.k.a. Update 2)</a></li>
<li><a href="/2010/01/27/we-haz-sponsors-a-k-a-firetalks-update-3/">We Haz Sponsors (a.k.a., Firetalks – Update 3)</a></li>
<li><a href="/2010/02/03/shmoocon-2010-firetalks-update-4/">ShmooCon 2010 Firetalks – Update 4</a></li>
</ul>
]]></content:encoded>
			<wfw:commentRss>http://www.novainfosecportal.com/2010/01/06/shmoocon-2010-firetalks/feed/</wfw:commentRss>
		<slash:comments>38</slash:comments>
		</item>
		<item>
		<title>Typos Hinder ShmooCon Ticket Sales But Still &#8220;Sale&#8221; Out</title>
		<link>http://www.novainfosecportal.com/2010/01/01/typos-hinder-shmoocon-ticket-sales-but-still-sale-out/</link>
		<comments>http://www.novainfosecportal.com/2010/01/01/typos-hinder-shmoocon-ticket-sales-but-still-sale-out/#comments</comments>
		<pubDate>Fri, 01 Jan 2010 20:39:27 +0000</pubDate>
		<dc:creator>grecs</dc:creator>
				<category><![CDATA[Infosec Conferences]]></category>
		<category><![CDATA[conference]]></category>
		<category><![CDATA[dc]]></category>
		<category><![CDATA[event]]></category>
		<category><![CDATA[infosec]]></category>
		<category><![CDATA[md]]></category>
		<category><![CDATA[nova]]></category>
		<category><![CDATA[registration]]></category>
		<category><![CDATA[room share]]></category>
		<category><![CDATA[shmoocon]]></category>
		<category><![CDATA[slug]]></category>
		<category><![CDATA[the shmoo group]]></category>
		<category><![CDATA[twitter]]></category>

		<guid isPermaLink="false">http://www.novainfosecportal.com/?p=3051</guid>
		<description><![CDATA[Although I was lucky enough to get a barcode in the first round, I was logging on this time to try to snag one for fellow NovaInfosecPortal.com contributor @nathiet. Apparently due to some typos, it turned out to be an ad-hoc hacking contest this time. Those who could successfully hack the system were the ones [...]]]></description>
			<content:encoded><![CDATA[<p>Although I was lucky enough to get a barcode in the first round, I was logging on this time to try to snag one for fellow NovaInfosecPortal.com contributor @<a href="http://twitter.com/nathiet">nathiet</a>. Apparently due to some typos, it turned out to be an ad-hoc hacking contest this time. Those who could successfully hack the system were the ones that got tickets.</p>
<p><strong>Challenge #1 &#8211; Find the Link:</strong> The first part of the challenge was to find the link. Unlike the last two rounds, the link was at the top this time. Clicking on it usually brings you to the first page of the registration process however this time it resulted in a 403 Forbidden error page as shown below.</p>
<p><img class="aligncenter size-full wp-image-3058" title="ShmooCon 403 Forbidden Error" src="http://www.novainfosecportal.com/wp-content/uploads/2010/01/shmoocon403error.png" alt="ShmooCon 403 Forbidden Error" width="583" height="142" /></p>
<p><strong>Challenge #2 &#8211; Guess the URL:</strong> I guess you had to do some information gathering and figure out the cart system they were using. Armed with this data, you knew that &#8220;/cart/&#8221; needed a little more info. Specifically you had to append &#8220;reserve.cgi&#8221; to it. So the whole URL would have been:</p>
<p style="text-align: center;">https://www.shmoocon.org/cart/reserve.cgi</p>
<p>Several  tweeps in Twitterland seemed to figure this out before I did; I saw tweets from @<a href="http://twitter.com/bbaskin">bbaskin</a>,  @<a href="http://twitter.com/KPOsborn">KPOsborn</a>, and @<a href="http://twitter.com/joerussbowman">joerussbowman</a> echoing this suggestion. Congrats to them for being the first to figure it out and post about  it. I&#8217;m sure others discovered this too but keeping it to themselves has its advantages in cut-throat hacking contests like this one. <img src='http://www.novainfosecportal.com/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' />  Several others (@<a href="http://twitter.com/ryancnelson">ryancnelson</a>) reported that restarting your browser also worked. And there were some complaints about a bad ticket link on a &#8220;cacheable&#8221; page that prevented some early risers from accessing valid codes.</p>
<p>Overall, I was guessing the initial link they posted was wrong and either typing it it manually or restarting your browser (only after they fixed the link) to clear the cache worked. The cache part doesn&#8217;t make sense though because I was doing a hard refresh (i.e., Shift- or Ctrl-Refresh) in both Firefox and Safari. Apparently, it wasn&#8217;t &#8220;hard&#8221; enough as compared to restarting your browser. For me the story ended after tons of refreshing and the site stating the following message.</p>
<p><img class="aligncenter size-full wp-image-3059" title="ShmooCon Tickets Sold Out" src="http://www.novainfosecportal.com/wp-content/uploads/2010/01/shmooconsoldout.png" alt="ShmooCon Tickets Sold Out" width="600" height="441" /></p>
<p><strong>Challenge #3 &#8211; Enter the Captcha:</strong> As you know the next challenge was to entry the  Captcha correctly. I could go on about this but 1) I never got there and 2) you can read about my Captcha horror stories in &#8220;<a href="/2009/12/02/ticket-buying-war-story/">Ticket Buying War Story</a>.&#8221;</p>
<p><strong>The Rest of the Story</strong></p>
<p>Well that&#8217;s about it for the first 15 minutes or so. After an hour the ShmooCon folks posted a nice message to explain what happened.</p>
<p style="padding-left: 30px;"><em>&#8220;2010-01-01 17:52:20 : That was fast&#8230;</em></p>
<p style="padding-left: 30px;"><em>Another round of ticket sales, another adventure. The good news is the new server has way more capacity than the last and the webpage was responsive the entire time. The bad news is we inadvertently redirected the reservation code page to an insecure page (which the webserver won&#8217;t allow). We updated the landing page with the right link once we realized the mistake, but at that point we were already so close to selling out that the majority of you were still effected.</em></p>
<p style="padding-left: 30px;"><em>The good news is we have logs and have already sent an email to everyone who made it through the reservation process. If you haven&#8217;t received an email by now, please try again next year &#8211; but also please check back in the weeks leading up to the con as we have more surprises up our sleeves. No not more tickets, but good things none-the-less.</em></p>
<p style="padding-left: 30px;"><em>Happy New Year everyone. Our resolution? Do everything we can for a successful ticket sales experience for ShmooCon 2011.&#8221;</em></p>
<p>Yes, the server had WAY more capacity this time; it barely slowed down. Great job!!! Of course the second statement is off some from the little bit of research I did. In the above message, I think they are talking about the page AFTER you successfully choose your tickets and entered the Captcha. It does not address a potential second bad link typo on the <a href="http://shmoocon.org/registration.html">Registration</a> page that resulted in the initial  403 Forbidden error I described above.</p>
<p>What do you think happened regarding the bad link on the Registration page? Yadda, yadda, &#8230; comment below &#8230; and all that. <img src='http://www.novainfosecportal.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
<p>Regardless, the ticket sales phase is finally over and I imagine that those who wanted tickets either got them or will acquire them through other means. Now it&#8217;s on to doing con prep and all the surrounding excitement. See you all in February!!!</p>
]]></content:encoded>
			<wfw:commentRss>http://www.novainfosecportal.com/2010/01/01/typos-hinder-shmoocon-ticket-sales-but-still-sale-out/feed/</wfw:commentRss>
		<slash:comments>6</slash:comments>
		</item>
		<item>
		<title>ShmooCon Ticket Sales Eve and Other Updates</title>
		<link>http://www.novainfosecportal.com/2009/12/31/shmoocon-ticket-sales-eve-and-other-updates/</link>
		<comments>http://www.novainfosecportal.com/2009/12/31/shmoocon-ticket-sales-eve-and-other-updates/#comments</comments>
		<pubDate>Thu, 31 Dec 2009 16:00:55 +0000</pubDate>
		<dc:creator>grecs</dc:creator>
				<category><![CDATA[Infosec Conferences]]></category>
		<category><![CDATA[conference]]></category>
		<category><![CDATA[dc]]></category>
		<category><![CDATA[event]]></category>
		<category><![CDATA[infosec]]></category>
		<category><![CDATA[md]]></category>
		<category><![CDATA[nova]]></category>
		<category><![CDATA[registration]]></category>
		<category><![CDATA[room share]]></category>
		<category><![CDATA[shmoocon]]></category>
		<category><![CDATA[slug]]></category>
		<category><![CDATA[the shmoo group]]></category>
		<category><![CDATA[twitter]]></category>

		<guid isPermaLink="false">http://www.novainfosecportal.com/?p=3027</guid>
		<description><![CDATA[Well, it&#8217;s that time of the month again &#8230;  ShmooCon ticket sales eve. The only difference is that this time it&#8217;s New Years Eve as well as your last shot to snag a barcode. We don&#8217;t really have anything new to say regarding getting tickets that we haven&#8217;t blogged before but a lot has [...]]]></description>
			<content:encoded><![CDATA[<p>Well, it&#8217;s that time of the month again &#8230;  ShmooCon ticket sales eve. The only difference is that this time it&#8217;s New Years Eve as well as your last shot to snag a barcode. We don&#8217;t really have anything new to say regarding getting tickets that we haven&#8217;t blogged before but a lot has happened over the past month since our last post.</p>
<p>But first to get things started, here is a summary of ticket buying lessons learned in case you missed  our earlier posts.</p>
<ul>
<li><strong>Read and Become Familiar with the ShmooCon Purchase Instructions</strong></li>
<li><strong>Carefully Enter those Captches</strong></li>
<li><strong>Look at the Bottom of the Page for the Link to Make Reservations</strong></li>
<li><strong>Keep Refreshing to Buy Tickets Even if You Get a Sold Out Message</strong></li>
<li><strong>Keep Trying to Buy Early Bird Tickets Even if You Were Only Able to Get Open or I Love ShmooCon Tickets</strong></li>
<li><strong>Never, Never, Never Buy ShmooCon Tickets Through a Hungry Work Proxy</strong></li>
</ul>
<p>All I can say is that I will be at home with a non-proxied Internet connection this time! For all the details on these lessons learned, check out &#8220;<a href="/2009/11/30/buying-shmoocon-tickets-top-5-lessons-learned/">Buying ShmooCon Tickets – Top 5 Lessons Learned</a>&#8221; and &#8220;<a href="/2009/12/02/ticket-buying-war-story/">Ticket Buying War Story</a>&#8220;. Also head over to PaulDotCom.com for  more ShmooCon ticket buying advice in their &#8220;<a href="http://pauldotcom.com/2009/11/the-quest-for-a-shmoocon-barco.html">The Quest for a Shmoocon Barcode</a>&#8221; post.</p>
<p>And here&#8217;s a direct link to the <a href="http://www.shmoocon.org/registration.html">ShmooCon Registration</a> page. Now on to some updates&#8230;</p>
<p>Over the past month the conference has really started to  take form. We&#8217;ve had official updates like the wrap-up of the second round of tickets, several speaker announcements, and a listing of the organized contests (can you say Hack-or-Halo, Hacker Arcade, Barcode Shmarcode, TF2 Lan Party, and ShmooBall Launcher Contest?). The good news is, as usual,  the community is pitching in to support the conference in many different ways.   The following is a short list of some of the contributions we&#8217;ve come across.</p>
<ul>
<li><strong>ShmooCon Slugs:</strong> Can&#8217;t find a way to get to the conference? Check out the <a href="http://shmooslugs.pbworks.com/">ShmooCon Slugs site</a> for connecting with people from your local area who are also heading to DC. Not sure what &#8220;slugging&#8221; is? This nice <a href="http://en.wikipedia.org/wiki/Slugging">Wikipedia article</a> comes to the rescue.</li>
<li><strong>Room Shares:</strong> Now once you get to DC, you&#8217;ll need a place to stay. The Wardman Park Marriott is running at $180 a night. And that&#8217;s the conference rate. I&#8217;m guessing they are probably sold out by now so you may even be looking at more. Enter the <a href="http://lists.shmoo.com/mailman/listinfo/shmoocon-roommates">ShmooCon Room Shares list</a>. This is a simple mailing list with the purpose of helping you connect with others looking to split the cost of a room.</li>
<li><strong>Twitter Speaker List:</strong> What is a con without @<a href="http://twitter.com/mubix">mubix</a> helping out in some way? This time he&#8217;s pulled together all the announced speakers and made a <a href="http://twitter.com/mubix/shmoocon2010-speakers">corresponding Twitter list</a>. This is a great way to quickly find out what the speakers are up to while at the conference.</li>
</ul>
<p>And for all the official happenings, be sure to visit the <a href="http://www.shmoocon.org/news.html">ShmooCon 2010 &#8211; Latest News</a> page. Beyond these posts, ShmooCon is also getting talked a lot about on many of the security podcasts. For information from the source, we&#8217;d recommend taking a listen to <a href="http://securityjustice.com/archives/104">Security Justice Episode 20</a>. It  includes an interview with Bruce Potter himself. And for the basics be sure to review  our <a href="/2009/10/30/shmoocon-infosec-conference-event/">ShmooCon announcement post</a> for the regular Who, What, When, Where info.</p>
<p>Well as usual that is all we have for now&#8230; Is there anything we missed? Please let us know by commenting below or tweeting this post with your addition. See ya!</p>
<p style="text-align: center;"><em>///</em></p>
<p style="text-align: center;"><em>Be safe in your celebrations this evening, good luck to everyone tomorrow, and follow @<a href="http://twitter.com/grecs">grecs</a> for last minute ticket reminders and other ShmooCon updates.</em></p>
]]></content:encoded>
			<wfw:commentRss>http://www.novainfosecportal.com/2009/12/31/shmoocon-ticket-sales-eve-and-other-updates/feed/</wfw:commentRss>
		<slash:comments>7</slash:comments>
		</item>
		<item>
		<title>Ticket Buying War Story</title>
		<link>http://www.novainfosecportal.com/2009/12/02/ticket-buying-war-story/</link>
		<comments>http://www.novainfosecportal.com/2009/12/02/ticket-buying-war-story/#comments</comments>
		<pubDate>Wed, 02 Dec 2009 15:00:52 +0000</pubDate>
		<dc:creator>grecs</dc:creator>
				<category><![CDATA[Infosec Conferences]]></category>
		<category><![CDATA[conference]]></category>
		<category><![CDATA[dc]]></category>
		<category><![CDATA[event]]></category>
		<category><![CDATA[infosec]]></category>
		<category><![CDATA[md]]></category>
		<category><![CDATA[nova]]></category>
		<category><![CDATA[shmoocon]]></category>
		<category><![CDATA[the shmoo group]]></category>

		<guid isPermaLink="false">http://www.novainfosecportal.com/?p=2814</guid>
		<description><![CDATA[Ok &#8230; so my own Top 5 lessons learned didn&#8217;t even help me.   Anyway, I tried to buy tickets at work this time and a very slow proxy definitely hindered my changes of getting anything this round. I was lucky enough to get a ticket last time &#8230; but nothing yet for NovaInfosecPortal.com [...]]]></description>
			<content:encoded><![CDATA[<p>Ok &#8230; so my own <a href="/2009/11/30/buying-shmoocon-tickets-top-5-lessons-learned/">Top 5 lessons learned</a> didn&#8217;t even help me. <img src='http://www.novainfosecportal.com/wp-includes/images/smilies/icon_sad.gif' alt=':(' class='wp-smiley' />  Anyway, I tried to buy tickets at work this time and a very slow proxy definitely hindered my changes of getting anything this round. I was lucky enough to get a ticket last time &#8230; but nothing yet for NovaInfosecPortal.com contributor <a href="http://twitter.com/nathiet">@nathiet</a>.</p>
<p>Here&#8217;s a time line of my 10 minutes on the ShmooCon site&#8230;</p>
<p><strong>12:00:</strong> They started up right on time &#8230; and guess what &#8230; the link to the reservation page is  at the bottom again. I clicked the link and patiently waited for the page to load. The response wasn&#8217;t fast  however after a minute the page finally came up and I filled everything in. There was still one field left though &#8230; the fateful Captcha .. but the image was no where to be found. Looking up I found the browser still chugging away downloading a few more items.</p>
<p><strong>12:03:</strong> After another 2 minutes the Catpcha finally decided to appear. So I quickly entered and rechecked it. Unfortunately, I wasn&#8217;t sure if the thing that looks like an &#8220;i&#8221; between the &#8220;m&#8221; and &#8220;n&#8221; in the image below was something I was supposed to enter or not. I guessed it was an &#8220;i&#8221; and decided to include it. The site squirmed away for another 2 minutes.</p>
<p style="text-align: center;"><img class="alignnone size-full wp-image-2815" title="1entercaptcha" src="http://www.novainfosecportal.com/wp-content/uploads/2009/12/1entercaptcha.png" alt="1entercaptcha" width="550" height="311" /></p>
<p><strong>12:05:</strong> I finally got a response I didn&#8217;t want to get as you can see below.  <img src='http://www.novainfosecportal.com/wp-includes/images/smilies/icon_sad.gif' alt=':(' class='wp-smiley' />  So I went back to the registration page to try again and waited&#8230;</p>
<p style="text-align: center;"><img class="alignnone size-full wp-image-2816" title="2captchafailed" src="http://www.novainfosecportal.com/wp-content/uploads/2009/12/2captchafailed.png" alt="2captchafailed" width="550" height="246" /></p>
<p><strong>12:08:</strong> After a few minutes the website informed me that  all tickets were reserved. So what does any good ShmooCon ticket-buying fool do &#8230; rinse and repeat.</p>
<p style="text-align: center;"><img class="alignnone size-full wp-image-2817" title="3tryingagain" src="http://www.novainfosecportal.com/wp-content/uploads/2009/12/3tryingagain.png" alt="3tryingagain" width="550" height="175" /></p>
<p><strong>12:10:</strong> After a few more tries I was still getting a message that all the tickets were reserved. At this point I went back to main registration page and got the fateful message. A <a href="http://www.shmoocon.org/news.html">ShmooCon blog post</a> and <a href="http://twitter.com/shmoocon/status/6240648060">tweet</a> confirmed everything.</p>
<p style="text-align: center;"><img class="alignnone size-full wp-image-2818" title="4allshucks" src="http://www.novainfosecportal.com/wp-content/uploads/2009/12/4allshucks.png" alt="4allshucks" width="550" height="249" /></p>
<p><strong>Lessons Learned #6:</strong> <span style="text-decoration: underline;">Never, Never, Never Buy ShmooCon Tickets Through a Hungry Work Proxy</span></p>
<p>Of course the saddest news of all is that <a href="http://twitter.com/nathiet">@nathiet</a> wasn&#8217;t able to snag a ticket either. Well, there is still one more round left at least. And guess what&#8230;  it&#8217;s on January 1 &#8212; a non-work day! No slow lunchtime company proxy to minimize my chances next time.  <img src='http://www.novainfosecportal.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
]]></content:encoded>
			<wfw:commentRss>http://www.novainfosecportal.com/2009/12/02/ticket-buying-war-story/feed/</wfw:commentRss>
		<slash:comments>7</slash:comments>
		</item>
	</channel>
</rss>
