Monday, March 10, 2008

HITBSecConf 2008

HITBSecConf 2008 Dubai

Even security conference aku sik pat pegi.. sekda sponser mok spon.. bila cita pasal tok semua takut, macam threatening ajak.. anyway this information bagus pakei sidak semua understand apa kejadah benda tok..

Registration dah close dah...
14th – 15th April 2008 event
Date:
Item: 5-Tracks Hands-On Technical Training Sessions
Time: 9am to 5pm
16th – 17th April 2008
Date:
Item: Security Conference and Exhibition
Time: 9am to 5pm
16th – 17th April 2008
Date:
Item: Capture The Flag and Zone-H Hacking Challenge
Time: 9am to 5pm
Venue: Sheraton Dubai Creek
Dubai,
U.A.E.

Sepa patut hadir : Anyone who is responsible for the security and privacy of information should attend including: CEO, CIOs, CTOs, VPs of Technology and Network Systems, Directors of IT, Directors of Technology, Systems Architects, Network Administrators, Network Security Officers, ISOs, Financial Managers, System Developers, Network Security Specialists, Security Consultants, Risk Managers, and System Administrators.

p/s tambahan.. dan orang yang minat wakakaka... ops.. sory no wakaka agik la.. :-)

Speakers nok datang molah speak or lecture or bla bla or merapu...

1. Adrian ‘pagvac’ Pastor (Senior Security Researcher)
2. Alessio ‘mayhem’ Pennasillico (Security Evangelist, Alba S.T. s.r.l.)
3. Alexander Kornbrust (Founder, Red Database Security GmbH)
4. Anthony Zboralski (Founder, HERT & PT. Bellua Asia Pacific)
5. Cesar Cerrudo (Founder, ArgenISS)
6. David Houlton (Independent Network Security Researcher)
7. Dino Covotsos (Managing Director, Telspace Systems)
8. Domingo Montanaro (Manager of Research & Development, Scanit Middle East)
9. Ero Carrera (Reverse Engineering Automation Researcher, zynamics GmbH)
10. Fetri Miftach (Principal Consultant, PT. Bellua Asia Pacific)
11. Jamie Butler (Coauthor of Rootkits: Subverting the Windows Kernel)
12. Marc Weber Tobias (Investigative Attorney and Security Specialist)
13. Michael Thumann (Chief Security Officer, ERNW GmbH)
14. Petko D. Petkov [pdp] (The Architect)
15. Raoul Chiesa (Board of Directors Member @Mediaservice.net, ISECOM Group & TSTF)
16. Rodrigo Rubira Branco (Lead Security Researcher, Scanit Middle East)
17. Shreeraj Shah (Director, BlueInfy)
18. Skyper (ex-Phrack Magazine Editor in Chief / Member, THC)

TECHNICAL TRAINING TRACK 1:
ADVANCE WEB APPLICATION & SERVICES HACKING
Trainer: Shreeraj Shah, Director, BlueInfy

TECHNICAL TRAINING TRACK 2:
WIRELESS & BLUETOOTH SECURITY
Trainer: Dino Covotsos, Director, Telspace Systems

Introduction to Wireless Hacking
Wireless Protocols and Architecture
Network Mapping and Wardriving
Methodology for securing wireless networks
Wireless hacking tools and attacks
Defending against wireless hacking
Introduction to Bluetooth
Bluetooth vulnerabilities overview
Bluetooth hacking tools and techniques
Defending against Bluetooth attacks

Aku rasa module training tok maybe banyak dapat sambutan.. banyak dah orang effort laptop ngan smart phone or pda phone. :-) 3.5G pun sik lamak agik implement maybe dalam bulan 10 2008 tok.. WLan and wiwi bila agik? mesia kan ada full coverate satellite, bagilah orang local pakei, iboh disewa deh... mok buat revenue ajak... lelah jak undi sari ya T_T;

TECHNICAL TRAINING TRACK 3:
STRUCTURED NETWORK THREAT ANALYSIS AND FORENSICS
Trainers: MelingMudin (spoonfork) & Lee Chin Sheng (geek00l)

mm memang rasanya OnDemand juaklah digital forensic kinek tok, macam ada attention jak kat mesia sejak dua menjak tok, maybe banyak kes kot.. sebelum tok pun banyak kes, sebab banyak orang sik merepot ajak.. apa sidak madah tek... sik kuasa bah... so far okey lah. maybe datang in handy untuk incoming kerajaan pun projek dalam bidang bioinformatic... dengar - dengar dah ada peruntukan buat R&D kat universiti.. well maybe info aku optimistic ngan sik betul, someone check it out la..

TECHNICAL TRAINING TRACK 4:
TELECOMMUNICATIONS FRAUD

Topics Covered:
  • Introduction to fraud
  • Fixed Network Fraud
  • Mobile Network Fraud
  • Subscription Fraud
  • Partnership fraud
  • Content & Added value services fraud
  • Fraud detection & prevention
Fraud, real thing to make money.. so far untuk 2008, apa jak fraud aku kenak oleh sidak frauder...

1. aku terimak sms dari petronas madah dapat hadiah berupa $$$ best nya.. sangsi juak aku... macam ne nya tauk nombor telefon aku, last thing aku buat pasal petronas, aku ada register ajak lah... now macam leak ajak information ya.. mmmmm muskil - muskil. sik patut kebetulan... nevermindlah.. buat lah apa sidak suka.. bukan senang dunia akhirat pun... bukan petronas, tapi kepada orang nok molah fraud ya lah., nok terimak rasuah, nok sik amanah. kat petronas.com ada announce ada pasal sms fraud tok juaklah FYI....
2. ahhh email aku kenak spam.. mala jak kenak invite mok molah connect back lah ya...mok curi cookie, mok curri session, mok redirect ke phising site.. mmmm rajin juak kerja sidaknya.. ada ka patut aku nok sekda sen, cuba lah molah kat orang nok ada sen ya ada lah pedahnya...

so far seingat aku lah 2 benda tok dalam 2008 lah.. ya pun dalam tempoh 3 bulan.

TECHNICAL TRAINING TRACK 5:
HACKING & HARDENING ORACLE

Trainer: Alexander Kornbrust, Founder, Red Database GmbH

  • Introduction
  • Oracle Basics (Oracle Architecture, Oracle Products, Oracle Features) -> Exercise: connect to the database, use sqlplus, sqldeveloper
  • Passwords -> Exercise: Find passwords, crack Oracle database passwords
  • SQL-Injection (Web, Database, C/S) -> Exercise: Privilege Escalation via SQL Injection, Information Retrieval via SQL Injection
  • Hacking mod_plsql -> Exercise: Hack mod_plsql Apps
  • Google Hacking for Oracle -> Exercise: Find vulnerable websites with Google
  • Hardening Oracle 10g R2
  • PL/SQL Programming Basics (Execute programs, read/write files) -> Exercise: Create files, read files, execute programs, ...
  • PL/SQL-Source-Code Analysis -> Exercise: Find Security bugs in PL/SQL code
  • Oracle Client attacks -> Exercise: modifying startup files, finding passwords, ...
  • IDS Evasion -> Exercise: Bypass Snort and other Oracle IDS
  • Oracle Rootkits& Backdoors -> Install and detect RK
  • Oracle Forensics ->Excercise: Analysis Logfiles, Audit-log
  • Oracle Capture-The-Flag
sik abis - abis jak pasal sql tok? pkq dah lenyap tek...dapatkan patch terkini kat oracle.com mmm i think la... so far exploit ada disclose nok makei oracle version 9, check out lattest oracle product pakei updates available...

reference :
http://conference.hitb.org/hitbsecconf2008dubai/confkit.pdf

Aik dah abis ka? blum.. ada agik, incoming base kat malaysia agik, jeng jeng jeng....

HITBSecConf 2008 Malaysia - Student CtF


Incoming kat Malaysia... yeee.. maybe dapat pergi lah waktu tok.. lagikpun dekat... mok kolek duit form team pasya try register dapat shortlisted ka sik join comp tok...

Event Date: October 2008 * maybe lar.. macam dah comfirmed ajak tarikh tok..ada kata julai ada kata september .. tengoklah.. bila ada info agik, check url nya

Venue: Westin Hotel, KL
URL: http://conference.hitb.org/

Student Capture the Flag Details: 0_o?, kenak mok CTF, kenak sik CT$$$ :-)

Objective:

  • To provide a secure environment for students that have interests in network/computer security to test their skills againsts each other.
  • Cost per team: Fee Structure: MYR1000 / team of 3 students. Universities / Colleges that takes up a booth (MYR 10,000) are entitled to send in 1 team FOC. Maximum of 2 teams per University / Colleges.
  • Prizes: 3 months Internship with some of the world's leading Fortune 500 IT companies - Listing to be announced by June / July
@===)(//////h/3/4/d/|-|/u/n/t/3/r////////>

kamekorang mok form headhunter team eh for this hitb challenge this October 2008... sik kan orang sawak tanam pokok ajak, mok juak ada celik technology yo juak!!

Well rata - rata apa jak related dalam pembelajaran untuk conference 2008 tok, boleh lah dikompilasikan macam ya.. rasanya kat KL kelak pun lebih kurang sama module mok dipresent para speaker. Sepa jak speaker datang kat mesia kelak? wait for next blog lah bila dah nak dekat2 hari ya kelak...

Anyone nok ada experinces dalam ngekot comp tok, sila - sila lah share info ngan knowledge by leaving something kat comment k, thx