This is a presentation called Uncovering ZeroDays and Advanced Fuzzing. It has one PDF of the presentation and one of the full script used during the presentation. This was presented at AthCon 2012.
8812c3bbcb41fdcdf442c0a5cee60b06These are the slides for the presentation "Recent Advances in IPv6 Security" that was given at Hackito Ergo Sum 2012.
e5b550d077bc205c2d3aab2bbb5bbac6This is a brief presentation that touches on various elements of attacks used to cause computer security issues. It is very high level.
34f4f122d7199b20bb266a1772100939These are the presentation slides from a talk called Threat Modeling Cloud Applications: What You Don't Know Will Hurt You as presented at the OWASP AppSec USA 2011 conference.
aec85350a0579220e6c4bbbde678b383These are the presentation slides from a talk called Behavioral Security Modeling: Eliminating Vulnerabilities by Building Predictable Systems as presented at the OWASP AppSec USA 2011 conference.
c36253247578a295c1280708a98db91bThese slides are from the Trustwave Global Security Report as presented at the OWASP AppSec USA 2011 conference.
031dbd61e5b28d76d75b184b9a5442a9These are the slides from the Ghost of XSS Past, Present, and Future presentation given at the OWASP AppSec USA 2011 conference.
517646ea949f5315bdc4f5baacb04b24These are the slides from the Web Application Security Payloads presentation given at the OWASP AppSec USA 2011 conference.
b88f1d7627f70f665f2eef2edb18b829These are the slides from the Hacking Hollywood presentation given at Ruxcon 2011. It documents vulnerabilities that the researcher discovered in various pieces of software in use by large Hollywood studios. Be sure to check out the related files for this presentation as there are multiple proof of concept exploits and advisories.
312ad3c5b5dbc495b7789bb12a1e8b75These are the slides from a presentation called Results of a Security Assessment of the Internet Protocol version 6 (IPv6). It was presented at H2HC 2011.
d07e41f43379026ab674eb6e151d845aThis is a set of slides from the talk Hacking Your Droid - Android Malwares.
9a3b3eece91fc4149fd434d8122a0df4Microsoft Patch Analysis presentation slides from Confidence 2010.
6741c59fe262770fe82fc016e0f3aadcThis file contains slides for the "Hacking IPv6 Networks" training provided at Hack in Paris 2011. They contain quite a few insights about IPv6 security, along with a number of practical examples.
af9084e0f7f6d96d006da7ee6e4665e1Presentation slides from "SCADA Trojans: Attacking the Grid" as it was presented at RootedCon'11 in Madrid.
03bf99a42d0af2409634999d4ede25dfWhitepaper called Forgotten World - Corporate Business Application Systems. This paper will describe some basic and advanced threats and attacks on Enterprise Business Applications – the core of many companies. Both the paper and Blackhat DC presentation are included in this archive.
749bcfc8f3e2ab51464f7114af8ae6c4Presentation called Mastering Trust in Security Assessments.
af4e19aa868295ae4562e983e41fab16This is the Next Generation Web Scanning Presentation. It includes a methodology to scan the webspace of an entire nation using some new tools and techniques. WhatWeb, bing-ip2hosts, gggooglescan and basedomainname are open source security tools developed by MorningStar Security that were published during the first presentation of this at the KIWICON III conference in December, 2009.
090485e6b4862cdca4def67149177914Presentations slides from HAR2009 for a talk on deep silicon analysis.
dfac441510986fe1e16680d086de3926Presentations slides from HAR2009 for a talk on breaking Hitag2 RFID systems. Two pdfs are included.
80c0a2ce0b00473c14a0760743e634ccPresentations slides from HAR2009 for a talk on cracking A5 GSM encryption.
8db6241199c8190f30e062bbe6922b7aThis is a presentation called HTTP Parameter Pollution that focuses on manipulation and injection of HTTP GET/POST parameters.
c7bb70cc65ee5220083c5e6fcc81de7aThis is a presentation called Discussing Secure Input Solutions for Web Applications.
f4d2fceacfef398b533e15fd513c0039Whitepaper discussing token kidnapping on Microsoft Windows.
fc55befe4d486f4b668dc6a4ebf1f79cThis whitepaper discusses the security exposures that can occur due to the manner in which access tokens are implemented in the Microsoft Windows Operating System. A brief overview of the intended function, design and implementation of Windows access tokens is given, followed by a discussion of the relevant security consequences of their design. More specific technical details are then given on how the features of Windows access tokens can be used to perform powerful post-exploitation functions during penetration testing, along with a basic methodology for including an assessment of the vulnerabilities exposed through tokens in a standard penetration test.
3db61250e4b375fb5b3216cd0316f311Dissection of an Oracle Attack in the Absence of Auditing. Presentation slides from Black Hat 2007 as presented by David Litchfield.
e225252d82c76279d7942bb0a47624dc