cons Archive

Pen-Testing is Dead, Long Live the Pen Test


Finally got around to uploading and converting my DEFCON 16 presentation with co-presenter Carric, entitled “PenTesting is Dead, Long Live the PenTest!”
Part problem dissection, part solution discussion, part political rant, peppered with a bit of humor and wit.
This talk explores the death and subsequent re-birth of the penetration test. Comprised of conclusions drawn from [...]

ShmooCon: Bad Guys Gone Good?


I generally attend no less than 3 security conferences each year (though there are ~5 on my wishlist), and Shmoo has steadfastly claimed one of those spots, alongside Black Hat / Defcon and RSA.I’ve been going to technology and security conferences since about 1990, and while I truly miss the biannual Comdex in Atlanta, ShmooCon has quickly become one of my favorite to attend…. While the Shmoo Group describe themselves as: “a non-profit think-tank comprised of security professionals from around the world who donate their free time and energy to information security research and development,”their work on notable security projects such as AirSnort and Rainbow Tables has demonstrated their knack for developing tools that appeal to the “Ambiguously Off-White Hat” segment of the professional information security community otherwise known as “hackers.”