Wicked Clown's blog / rants!

 

I know I don't update this.. but story so far

Yeah, I know I don't update this.. That is because no body reads it :) LOL! Anyway just incase
you are one of the very few who do.. well, lets update:

1) I am now a full time member on the Eurotrash Security Podcast

2) After my success at BruCON I decided to give an extended version of my talk at Bsides London

3) I have been mention on the pauldotcom website about my some of my vid's

4) I am getting ready to attend DefCON and Blackhat next week in Vegas

----------------------------------------------------------------------------------------------------

Leaving Brussels,
I am on my way home (well, I am actually home) and I just want to say what a bunch of friendly
and great guys and girls the entire BruCON team are. They made me feel very welcome.
Cheers again and I look forward to seeing you guys next year!!

----------------------------------------------------------------------------------------------------

BruCON – Talk

Ok, I done me talk.. and what can I say but a big THANK you to everybody for the warm reception.
I honestly didn’t think it would go that well. I was shitting myself so much,
I know I must of looked and sounded like a nervous wreck. Lucky I just had something people
actually found really interesting in. I am actually very shocked I won the best lighting talks!

I would like to say a thank you to the EuroTrash team for sorting out the lighting talks
and helping me with my nerves with the talk.

----------------------------------------------------------------------------------------------------

BruCON

Just finished doing my lighting talk, I decide to do it on my RDP issue I found
This is my first SOLO!! talk, talk about shitting yourself :) On the plus side I am
struggling getting it down to 5 mins, so that means if it goes well I am thinking about
doing a longer one for DC4420. Then maybe BSides LONDON !!
Downside is I will have to find a new thing to talk about next year!! I better start thinking :)

----------------------------------------------------------------------------------------------------

In Vegas baby

Meeting great people, enjoying great talks and awesome parties!!

----------------------------------------------------------------------------------------------------

PuriFile

Is CRAP!! it doesn't detect embedded images, you can easily bypass the white on white hint: white on ivory
It doesn't detect VBCode.. even better it thinks a HTML file is a standard txt file.. it's really bad!

----------------------------------------------------------------------------------------------------

DefCon + Blackhat Booked

Just booked my trip to Vegas. Staying at Treasure Island, halfway between the two places
so I don't have to walk as far!! HAHA! Nothing worst walking in the heat with a hangover :)
It should be a good trip hoping to meet up with peeps over!

----------------------------------------------------------------------------------------------------

Off to Salt Lake City, Utah

I am off on a training course in Salt Lake for 5 days, a flying visit but should be good.
Planning to meet up with some of the guys on the EL message board

----------------------------------------------------------------------------------------------------

Shout out to me!!

LMAO! I nearly spat out my cider (not fucking now with the stupid cunting budget putting it up by 10%)
ANYWAY, I got a shout out from Eurotrash on ep 8.. LOL!! Awesome, I feel I made it to the big time!
You should check out the podcasts!! Awesome information and a great team!
:)

----------------------------------------------------------------------------------------------------

Not sure whats happening!

Not too sure why, but I found another possible 0 day with RDP. Not with RDP itself, but how you can
publish your RDP. If you google filetype:rdp you will find a bunch of RDP clients but some will let you log in
and access the application which is protected by username and password so this gives you a false sense of
security, now if you modify the RDP file you can get the server to run ANY application that is allowed by the policy
you can see this example in my video section.

----------------------------------------------------------------------------------------------------

On a roll

I found another 0 day. This is for a hard disk protection that prevents anything to be modified.
There was a challenge to see if anybody is able to deface the website which is protected by this software,
I was able to log onto the server and upload a webfile, rename the old index.html and rename my NEW file
to index.html. Challenge won!! LMAO! :) I was the first person in 2 years to beat this challenge!

----------------------------------------------------------------------------------------------------

I found my first 0 Day.

I found my first every 0 day, I can't tell you any thing about as it a product I support. A patch has been released so its all fixed now!

----------------------------------------------------------------------------------------------------

Passed my SANS 504 exam

I passed my SANS 504 Incident Handling exam, I got 91% which I am pretty proud off. I recommend anybody to do the course, the course is main ethical hacking.

----------------------------------------------------------------------------------------------------

My first real security talk

I just gave my first hackers / IT security talk last week, I loved it. I have to give most credit to Boris who helped me. Well to be honest he gave the talk I just help but I did some live demos of using Metasploit.. I still enjoyed it and looking forward to the next one :)

----------------------------------------------------------------------------------------------------
Defcon / Blackhat.

Yo, I attended both Blackhat and Defcon this year. It was totally awesome, I learnt some cool stuff. I preferred DefCon over Blackhat as I felt Blackhat was a little too corporate. Don’t get me wrong I deffo go again but DefCon was a bit more hardcore and it is impossible to get the full benefit out of DefCon. Also there is more of a party atmosphere at DefCon.

I have defiantly got the bug to do more of these types of events, just have to save my pennies to go. 

----------------------------------------------------------------------------------------------------
My definition of hackers!

Ok, there are a bunch of people out there who pigeon hole hackers with terms. So I decide I write what I view these pigeon holes are :)

Hacker: A hacker has extremely good programming skills, some who can manipulate code to do what they want. Can write their own exploits and exploiting systems.

Cracker: A cracker is someone who has the skill to bypass security and decrypting encryption. Cracking codes etc.

Hacktivist: Basically is some who hacks or exploit system for political gain.

Cyber Punk: A cyber punk is someone who has a passion for high tech, everything from exploiting software to hardware.   

I view myself as a cyber punk as I can’t code, well not very well anyway even though I have done coding. I would love to learn but I finding it confusing and every time I try to learn it always goes wrong. But I still refer to the subject as ‘Hacking’or ‘IT security’ HAHA!! Sounds safer :).