0x1338.blogspot.com
atom
0x1338
0x1338.blogspot.com · English
One Step Ahead Of The Average Nerd
atom gd openSearch thr
http://0x1338.blogspot.com/feeds/posts/default
- Last post
- Mar 18, 2019
- Posts in 24 h · 7 days · 30 days
- 0 · 0 · 0
- Our last check
- Answering
- Served from
- United States
- Format
- atom
- Features in the feed
- gd, openSearch, thr
Posts
What our queue read from this feed. Open one to read it here, or go to the site that published it.
- BlackHoodie comes back to San Francisco
Mar 18, 2019 · original
I promised we’d be back! So here we roll again, BlackHoodie is coming back to San Francisco, this time filling the Google campuses in downtown with a crowd of dedicated hackerettes. The bootcamp will take place in San Francisco downtown, on April 25 th and 26 th this year. Just like other BlackHoodie events, the classes will be free, women only, and crazy challenging. And as usual, all we want is your everything ;) TL;DR facts: What: Classes on code security, application security, x86, and ARM and Android native reverse engineering When: April 25 th & 26 th , 2019; 8.45am - 5pm; 25th 3-5pm networking event Where: Google campus, 345 Spear St, San Francisco, CA, 94105, 7th floor Who: Women Prerequisites Track 1: Experience in C/C++ development, notebook capable of hosting/running a VM Prerequisites Track 2: notebook capable of hosting/running a VM Registration: Use our form :) Registration - BlackHoodie Bay Area 2018
Jul 10, 2018 · original
Years ago I was listening to a talk at the CCC Congress in Hamburg, where a hackerette explained to us how she managed to exploit a Tamagotchi . I was starstruck, at the time I didn't even quite understand what single stepping means. Role models gonna role model, and recently this same hackerette agreed to do an offensive security workshop, along with a number of other awesome women. The workshop will be held in Mountain View, CA on September 7th and 8th this year. Just like other BlackHoodie events, the event will be free, it will be women only, and it will be crazy challenging. TL;DR facts: What: Workshops on offensive security, application security, firmware reverse engineering When: September 7th & 8th, 2018; 10am - 5pm Where: Google campus, Mountainview, CA Who: Women Prerequisites: Some form of education or solid experience in computer science, but don’t be shy, we welcome security - BlackHoodie #3 - Staring assembly to death
Jul 7, 2017 · original
I am happy to announce BlackHoodie #3, a free reverse engineering workshop for women, taking place the 25th and 26th of November in the beautiful city of Luxembourg. :D The first two editions rocked my socks off, quite literally; I got to meet the most stunning crowd of engineers on both occasions. The workshop will be held at the offices of CIRCL, the Computer Incident Response Center Luxembourg, whose fine people kindly offered space and support. Also, this year there will again be one or two or more travel grants, to be given out to participants who cannot afford the trip on their own. Please note, the grants will be distributed by random selection. I will post more details, as soon as I figured them out :) Finally, I'm insanely thrilled this will be happening again. I'm looking forward to the next most wonderful workshop, with oh so many inspiring participants, who then walk out and - The Mighty Superpowers Of A Well-Established "Us"
Apr 20, 2017 · original
Late in 2016 I was honored to deliver a keynote at Hamburgsides , a neat'n'boutique side event of CCC. The talk was titled 'The Magic Superpowers of a well-established "Us"' . Naturally, it was all sparkly fairies and we are hackers expect us hugging the community fuss. Not ;) A well-established "us" is a team or a group of people who stick together and work together no matter what, who have recognized a shared goal and support one another on the way there. The "us" I have seen on plenty of occasions, it helps CTFers capturing their Fs, it helps incident responders in staying awake for 48 hours, it gets projects done cheaper err quicker I mean, than what the plan was. It is magic. Last year in November I have witnessed an "us" I had not been aware was there. Indirect base of the Hamburgsides talk is a workshop I organized two years in a row, an event named BlackHoodie. It's a women-only - BlackHoodie #2 – We roll again :)
Jul 29, 2016 · original
Last year I held a free reverse engineering workshop for women, mainly in the not entirely un-selfish interest to see more of them around in the whole security field. More about the motivations, the why's and obstacles and how it turned out you can read up here , here and here . Looking back, I'm super happy with this little project and, leaning out the window a bit further, call it a big success. That said, I gleefully announce BlackHoodie #2, the next women-only reversing workshop, to take place in Bochum, Germany the weekend of 19th + 20th of November 2016. This edition will be held in cooperation with Katja Hahn, a splendid binary analyst herself, and Priya Chalakkal, an up-and-coming hacker of all things; and comply to the same principles as last year. It will be free of charge, no strings attached, and aim to help femgineers entering a field thats not easily accessible. Moreover, i - That thing with rocking harder and the BlackHoodie story
Jun 14, 2016 · original
Last year in September I realized an idea that had manifested in my brains quite some months before. I had wanted to do a workshop with a handful of friends. It should have been a weekend, where I spend time on teaching four ladies the thing I do for a living; reverse engineering malware. Those four had come up to me at different hacker events, telling me yo its cool what you do, how can I learn that? This, in general, is great, but trying to explain the how-to-RE in a few sentences is frustrating, at best. So much for the idea; lets meet somewhere, have a fun weekend, and look at a binary, I said. And this idea, in the end, turned out to be.. a thing. I had planned to write about the workshop long ago, actually right after; then was super busy, postponed, postponed more, thought now is the time, then realised I might just as well wait a bit more and keep watching what happens. And a lot - BlackHoodie - Reversing Workshop for Women at UAS St. Pölten
Jul 1, 2015 · original
Normal 0 21 false false false DE X-NONE X-NONE In the past year at every other event a girl came up to me, telling me how cool she thinks that is what I do. I’ve had that conversation with each of them, reversing is fun, there are too few women, stuff is scary and hard to learn and good sources of comprehensible knowledge are hard to find. Thus, I thought it’d be a good idea to sit down with them and help them get their head around reverse engineering malware. The idea is, we do a workshop on how to take binaries apart. I've been teaching exactly that at UAS St. Pölten in the past, and be happy to do it once again in a women-only class. Why women only? Because a girl-to-girl conversation is so much more fruitful than a full classroom with only one or two women hiding in the corners. I've done so many things in my life where I was the *only* girl among X other participants, and I promise - Mourning The Last SyScan
Apr 5, 2015 · original
Normal 0 21 false false false DE-AT X-NONE X-NONE An ode to the tiny ones *sniff* There are a number of happenings that crashed my life since the last blog post like.. oh lets say, like an elephant crashing a porcelain store. The malware clan, calling it clan as it is multiple families, so the clan I've been following since last year’s Hack.lu turned out to be most likely nation-statey, believed to be operated by French intelligence. Who would have thought. Last week I presented on the most interesting furries out of the 'Animal Farm' or Cartoon Malware as I'd rather call it. This presentation was given at SyScan'15 in Singapore, which, for me personally, is something like the mothership of all cons. I have done a hell lot of conferences the past two years. Now how that happened is a hell lot of stories, but let me tell you, I had a hell lot of fun. Hell. Maybe we agree, more than anythi - Hunting Bunnies
Nov 20, 2014 · original
A month ago I gave a talk titled TS/NOFORN at an exquisite boutique conference named Hack.lu in Luxembourg. Some people also named it keynote. I had been talking about a set of extravangant malware samples, which all seemed to be related yet different in the deep of their dark souls. One of these samples stuck out, namely the fourth sample of the analyzed species; thus entitled suspect #4. Suspect #4 is a huge evil beast, sophisticated, if one does not take the typos in its string constants into account. The malware presents itself as 'bunny', invades the system, evades sandboxes and presents an execution platform for Lua scripts a C&C would inject to the malware. As I have promised to various fellow researchers, I sat down to document this very same miscreant. Having typed my fingers wound throughout numerous long nights, I can now happily present you with the final version of the bunny - Predictive Research: Malware, You're Doing It Wrong
Sep 28, 2014 · original
I sat down this weekend to document the inspiring thoughts behind a talk I gave at Next Generation Threats last week in Stockholm. The initial idea was to outline how today's threat detection systems work and how they are bound to fail in specific situations. Slides are pretty and contain cat pictures: How would you find what you can't see? from pinkflawd Yet, they do not express all the ideas which popped up in my head even only after the event. As researchers are constantly mocking Anti-Virus solutions these days, let me point out what crap the malware authors themselves are actually doing wrong at the same time. 98% of malware (numbers not based on empirical research) we see today is not exceptionally good software. More even, as long as we see today’s malware it can’t quite be genius, no? 98% of malware (numbers not based on empirical research) has evil intentions, and, it works – no - Yes, you can!
Aug 1, 2014 · original
long time no write.. i have been busy with starting a lot of different things, finished only some and never sat down to put anything here. today is the day - find below the latest tech stuff i worked on and some thoughts that had to get out. STUFFZ THAT HAPPENED - Troopers video out https://www.youtube.com/watch?v=s_7Cy2w2dCw - talk at Area41 Zürich on VB6 runtime analysis together with Jurriaan Bremer, write up here http://www.cyphort.com/blog/analyzing-vb6-malware-cyphort-area41-switzerland/ - talk at SSTIC Rennes about a fun collection of anti-analysis tricks of all sorts, write ups spread all over - Sazoora anti-analysis close up http://www.cyphort.com/blog/sazoora-dissecting-bundle-evasion-stealth/ - VirusBulletin article on VB6 runtime packers https://www.virusbtn.com/virusbulletin/archive/2014/07/vb201407-VB6 - a Havex.RAT risk assessment, cause that thing wasn't so sophisticated - Yet Another Security Tool @Troopers14
Mar 29, 2014 · original
TROOPERS14 i read 'boutique conference' somewhere recently, and that term actually nails it. occupying the print media complex in heidelberg for an entire TROOPERS manages to provide two days of workshops, two more of conference and a day of roundtable discussions as well as various side events like an IPv6 security summit or an SAP security track or a telco sec day or.. did i miss anything? guess so. there is a soldering station to fiddle with your.. batch, because it comes with an arduino attached. troopers provides food & coffee & mate nearly around the clock. AND, well not that i'm anything like picky about clothing at all, BUT they have conference shirts available for girls. no one goes to cons just for collecting shirts.. but this industry is moaning about the lack of females, no? so when they finally show up it is really nice when this kind of events actually acknowledges beforeha - The Mystery of Anti-Debug by HeapAlloc
Mar 20, 2014 · original
first of all, a big thank you to my friend moti who actually provided the final hints to solve that mystery and saved me A LOT of time googling heap structures. i wish everyone of you would have a moti when getting stuck in RE questions :) to the story: meanwhile, in a zeus trojan. last week i peeked into a zeus just to really quickly stumble over an anti-debug trick. SURPRISE! kidding. that anti-debug is really easy to pass by, but wasn’t that trivial to explain; or at least that is what it seems like because i couldn’t find any suitable documentation. and this while the interwebz is full of malware reverser’s write ups.. kidding again. so here we go... in a nutshell: the malware would allocate heap memory and use the header of the heap entry as an indicator for an attached debugger. simple, after all. is that frequently used? i don’t know. but, lets start at the end. the debugger would - Bright Future Ahead
Mar 11, 2014 · original
some weeks ago i was invited to talk at an austrian highschool, to a class of 18 year olds, about.. me. odd right? thing is, it were mostly girls in there and their teacher thought it would be a good idea to present them a -kindof- different perspective of future. and honestly, before that i didn't think i would ever serve as example for others. i'm not usually stepping up and taking a stage unless i'm asked to do so. then having all these big eyes on me.. unsettling. but not only after the talk i understood what it was actually about. never i was like 'i am a woman and can do cool stuff'. it was 'i do cool stuff. you should too.' you can figure out later that this is unusual for a girl, if you need to. it in fact is easy to talk passionately about something you seriously think is cool. so thinking back that was the most fun talk i've given so far. about how i decided to study computer s - Dissection Is My Hobby: Upatre Insights
Feb 22, 2014 · original
i found the biggest problem to face with actual all my projects is not necessarily that i lack the idea of what i want to do, but that i lack documentation on how to do it and then go and have to figure out myself. would that be nice if someone had just mounted a page like.. malware reverser's frequently asked questions, arrrr well never happened. now im not going to start a FAQ page, but in order to help that situation i produced detailed documentation of my latest reversing project if you read this because you want to know about malware you will be a bit disappointed probably. mainly because the purpose of that malware itself is not so exciting at all. it just downloads.. stuff. but also because i myself focused not directly on the final executable but on the stony path it takes to get there. it is just awkwardly fascinating to watch malware shift bytes around in memory and trying to e - Taming Dragons On A Daily Basis
Feb 8, 2014 · original
hello world, happy you found here :] welcome to some new blog on tech, travel, fun and $cool_things. wait.. new blog.. does the world seriously need another blog? ah no i didn't ask that question for real. don't quite care about the answer actually - i got my reasons. first of all, i like to write and i like to share. so a blog is the perfect symbiosis :) pro practical approaches. second, and virtually most important, my grandma still hasn't seen my awesome pictures of singapore, las vegas and seoul :( err.. long story short: last year i spent a lot of time on international conferences, but since i started work 24/7/365 my family has barely seen more of me than postcards. meh.. can't even remember sending postcards. so i want to compensate a bit by putting my globetrotter impressions in words and pictures. poor compensation? yes i know. but i also heard some university is already working
Discovered by the rss-feed-index crawler, which checks each feed at most once a month.
Same record as JSON: https://api.agentalog.com/api/feeds/fd_0x1338_blogspot_com_4eb23c7980614175. More from this site: 0x1338.blogspot.com in the Feeds tab.