TOORCON9 - OSSIR · 2009. 5. 4. · Crash course in penetration testing. 19/10 : Séminaires Linux...

10
TOORCON9 Résumé de la conférence Jérôme ATHIAS www.JA-PSI.fr

Transcript of TOORCON9 - OSSIR · 2009. 5. 4. · Crash course in penetration testing. 19/10 : Séminaires Linux...

Page 1: TOORCON9 - OSSIR · 2009. 5. 4. · Crash course in penetration testing. 19/10 : Séminaires Linux kernel rootkit detection Continuous prevention testing Crypto boot camp

TOORCON9

Résumé de la conférence

Jérôme ATHIASwww.JA-PSI.fr

Page 2: TOORCON9 - OSSIR · 2009. 5. 4. · Crash course in penetration testing. 19/10 : Séminaires Linux kernel rootkit detection Continuous prevention testing Crypto boot camp

whoami

➲ Jérôme ATHIAS, alias JA➲ Consultant sécurité➲ www.ja-psi.fr➲ www.securinfos.info (FR/EN)➲ www.metasploit.com (EN)➲ www.metasploit.fr (site FR NON officiel)➲ www.freerainbowtables.com (EN)➲ www.frameip.com (FR)➲ www.authsecu.com (FR)➲ Msf, Bugtraq, Ossir... mailinglists

Page 3: TOORCON9 - OSSIR · 2009. 5. 4. · Crash course in penetration testing. 19/10 : Séminaires Linux kernel rootkit detection Continuous prevention testing Crypto boot camp

Toorcon9: Où? Quand?

➲ San Diego, Californie, Etats-Unis➲ San Diego Convention Center➲ 18-21 Octobre 2007

Page 4: TOORCON9 - OSSIR · 2009. 5. 4. · Crash course in penetration testing. 19/10 : Séminaires Linux kernel rootkit detection Continuous prevention testing Crypto boot camp

18/10 : Workshops

➲ Penetrating the Epoxy curtain➲ Building/Hacking open source embedded

wireless routers➲ Crash course in penetration testing

Page 5: TOORCON9 - OSSIR · 2009. 5. 4. · Crash course in penetration testing. 19/10 : Séminaires Linux kernel rootkit detection Continuous prevention testing Crypto boot camp

19/10 : Séminaires

Linux kernel rootkit detection Continuous prevention testing➲ Crypto boot camp➲ AppArmor profile sharing portal, Crispin

Cowan➲ Real world fuzzing, Charles Miller

Page 6: TOORCON9 - OSSIR · 2009. 5. 4. · Crash course in penetration testing. 19/10 : Séminaires Linux kernel rootkit detection Continuous prevention testing Crypto boot camp

20/10: Keynotes

➲ Wolverine, yo' mama, spooks, and Osama, Beetle

➲ Black ops 2007, Dan Kaminsky

Page 7: TOORCON9 - OSSIR · 2009. 5. 4. · Crash course in penetration testing. 19/10 : Séminaires Linux kernel rootkit detection Continuous prevention testing Crypto boot camp

20/10: Talks➲ 2 salles en parallèle: Attaque & Défense➲ Interventions de 50 minutes

Page 8: TOORCON9 - OSSIR · 2009. 5. 4. · Crash course in penetration testing. 19/10 : Séminaires Linux kernel rootkit detection Continuous prevention testing Crypto boot camp

21/10: Talks

➲ 20 minutes➲ Supports des présentations (et bientôt

vidéos) disponibles sur www.toorcon.org

Page 9: TOORCON9 - OSSIR · 2009. 5. 4. · Crash course in penetration testing. 19/10 : Séminaires Linux kernel rootkit detection Continuous prevention testing Crypto boot camp

Remerciements & Questions

➲ Merci à vous ;-)➲ MERCI à l'OSSIR➲ Salutations aux guys du Toorcon➲ Des questions?

Page 10: TOORCON9 - OSSIR · 2009. 5. 4. · Crash course in penetration testing. 19/10 : Séminaires Linux kernel rootkit detection Continuous prevention testing Crypto boot camp

MSF eXploit Builder

➲ Point, click, shoot, pwn!➲ Package of tools➲ Graphical User Interface➲ Local opcodes database➲ Complete built-in programming langage➲ 'Automatic' exploit code generation➲ Metasploit Framework killer coding ninjas'

katana➲ Free! :-) www.securinfos.info