DEF CON 23 CVE Closing Ceremonies
This is a modal window.
The media could not be loaded, either because the server or network failed or because the format is not supported.
Formal Metadata
Title |
| |
Title of Series | ||
Number of Parts | 109 | |
Author | ||
License | CC Attribution 3.0 Unported: You are free to use, adapt and copy, distribute and transmit the work or content in adapted or unchanged form for any legal purpose as long as the work is attributed to the author in the manner specified by the author or licensor. | |
Identifiers | 10.5446/36410 (DOI) | |
Publisher | ||
Release Date | ||
Language |
Content Metadata
Subject Area | ||
Genre | ||
Abstract |
|
DEF CON 2325 / 109
12
19
20
23
24
29
32
33
36
51
58
60
62
66
67
68
69
70
71
77
82
84
85
88
89
92
98
99
103
104
107
00:00
Metropolitan area networkMultiplication signDemo (music)Event horizonClosed set
00:41
Computer animation
01:02
Slide ruleRoundness (object)Event horizonComputer animation
01:32
Event horizonSelf-organizationRoundness (object)Order (biology)WhiteboardLevel (video gaming)Moving averageDemo (music)Process (computing)Alphabet (computer science)Event horizonTable (information)Computer animation
02:55
Vulnerability (computing)RoboticsSoftwareRobotLaserOrder (biology)2 (number)CuboidShooting methodAlphabet (computer science)Communications protocolMessage passingMoving averageComputer hardwareRoundness (object)Computer animation
04:21
Social classSign (mathematics)Roundness (object)Category of beingComputer animation
05:53
Point (geometry)Office suiteSelf-organizationQuicksortGame theoryMatching (graph theory)Event horizonPoint (geometry)Shooting methodHydraulic jumpComputer animation
07:22
Boss CorporationHill differential equationRoundness (object)Boss CorporationMaizeDatabase transactionHill differential equationINTEGRALGame theoryRoboticsComputer animation
08:23
SpacetimeSoftware developerGroup actionCore dumpDatabaseTable (information)TupleGame theoryLevel (video gaming)Insertion lossDrop (liquid)Computer animation
09:12
Prime idealHash functionComputer-assisted translationPasswordRippingBeta functionMultiplication signOrder (biology)Boom (sailing)Computer animation
10:21
Point (geometry)MaizePoint (geometry)Projective planeInteractive televisionOrder (biology)MaizeGame theoryAlphabet (computer science)2 (number)Representation (politics)RobotDemonNumberComputer animation
11:24
Hacker (term)Level (video gaming)Goodness of fitHacker (term)Computer animation
12:21
PlastikkarteConnected spacePhysical lawAnalogyComputer animation
13:35
Hacker (term)Hacker (term)WhiteboardGame theoryLattice (order)LeakProcess (computing)Amenable groupComputer animation
14:45
RobotOverhead (computing)Binary fileBuilding
16:27
Level (video gaming)Computer networkComputer forensicsSoftwareMetropolitan area networkCommunications protocol2 (number)Mobile appLevel (video gaming)Open setComputer animation
17:59
Point (geometry)Range (statistics)Right angleReflektor <Informatik>Information securityCybersexRange (statistics)BitComputer animation
19:06
Game theoryLevel (video gaming)Matching (graph theory)CodeComputer animation
19:40
Metropolitan area networkAreaComputer animation
20:20
Social classMultiplication signInformationInternet forumSoftware testingDatabaseNumberSystem callSign (mathematics)Level (video gaming)StatisticsComputer animation
21:56
Grand Unified TheoryHacker (term)Disk read-and-write headRight angleTotal S.A.CuboidThomas BayesGoodness of fitInformationHacker (term)NumberComputer animation
23:32
Data acquisitionInternet der DingeTrailFlagInternet der DingeVulnerability (computing)Metropolitan area networkWindowTouch typing2 (number)Email
24:51
Multiplication signMotion captureHacker (term)CircleSinc functionWhiteboardEvent horizonRootTable (information)FlagGame theoryMUDStandard deviationRoundness (object)Metropolitan area networkWireless LANComputer animation
26:53
Closed setMUDEvent horizonComputer animation
Transcript: English(auto-generated)
00:00
So welcome to the contest and events, closing ceremonies. I'm Grifter. This is Panadera over here. We're the new leads for CNE. It's actually this year we're over contests, events, villages, parties and the demo labs. So not a lot. Just like
00:22
a couple things. We're kind of lazy. Thanks, man. So thank you guys for putting up with us, all you organizers, while we figured out how to get things right this year. New venue, new leads. But yeah, let's roll. We don't have a ton
00:40
of time. So I'm just going to go through the deck and whenever ‑‑ oh! Magic. It's still ‑‑ we're almost there. It's okay. What? I'm not worried about it. Before
01:02
we didn't have a slide. This is ‑‑ all right. So first off we just want to say thank you to these fine folks over here, our contests and events goons. So please give them a round of applause. I want to say that you guys saw us running around
01:23
like crazy or whatever, but we were just sitting on the couches over there. Couches were nice this year, right? Couches. Who knew? All right. So this year, again, thanks to all of the organizers and the contestants. Huge, huge round of
01:41
applause for those guys. Seriously, you have no idea how early these guys start planning. We do now. Yeah, it's crazy. It's like February and they're like all right, let's roll. I'm like what? They're like sorry we're late.
02:01
Usually we start in January. We're like please stop. Is this what this is going to be like? So 29 contests, 16 events, 12 villages, you know, multiple parties and all the other stuff. We had this year new, if you guys were here on Saturday, these tables out here were the demo labs. There were people showing off tools. One of the things we were
02:22
doing there was we get a lot of submissions to the CFP, like the submission process, and the review board goes through things and we're like oh, that sounds really cool, but I don't know if it's an hour long talk like on a stage in a giant room, but we want to make sure that content gets out there so we put them out and let people come up and see what they
02:42
were doing and talk to them. So it seemed like people liked it, so we'll be bringing it back next year. Let's roll straight into it. This is kind of in alphabetical order and then I'll say that and immediately go to something with the letter D. But organizers, please keep this brief because
03:01
we've got to roll. So DEF CON bots, yeah, and if ‑‑ so it's going to be ‑‑ like I said, kind of alphabetical order, so beard and mustache get ready to roll and if you want to start kind of getting ready as you see the letters approaching where your contest is going to be at, that would be awesome.
03:22
Okay, DEF CON bots is ‑‑ DEF CON bots is autonomous robots that shoot lasers at moving targets. It's really hard to do and these guys build robots to do that, all the software, the hardware. This year they had to encode messages in their lasers that they're shooting at the targets and actually one of
03:41
the teams went from the qualifier third place to second place in the finals by exploiting a security hole in the laser protocol. So these are first, second, third, team monkey business, team pew pew monkey business slaughtered everyone, hit like almost 45 targets in 90 seconds in the
04:06
final round and we have the DEF CON bots really dark, dark, gray badge addendum that goes on the badge. So that goes to first place. Thanks. Where's my beard and mustache at?
04:28
Anyone? Anyone? Anyone? Jack, jack, jack, jack, jack. Those people had beards. Cool. Beverage cooling. He's coming.
04:48
So beard chilling was a thing again this year, ten years. I took it over. We coded this year. I think we're going to continue doing that. We had two categories, the unlimited
05:01
and the hacked together which ended up being really quite effective. Our biggest challenge this year was we were through a hole in the wall and nobody really was like, hey, there's this guy with a cardboard sign saying free beer. People were like, that's not real. Totally was. So, yeah. So this year we had team Hebrew. They won the
05:23
unlimited challenge with a truly fantastic device. It was amazing. And then array of not won the hacked together. Guy found a bunch of junk lying around the hotel and built something. It was amazing. So round of applause to them. And I would like to thank these two guys for putting up
05:43
with our super late submission. We didn't start in January. But they still got us out there. So thanks a lot, guys. So, yeah, black bag, for those of you who don't know,
06:06
is a sort of lock picking and penetration game. You got to break into a virtual office. You got to pick a bunch of locks while you're in there. There's getting data. There's a lot of dick picks. You know, it's my kind of contest. And this is the last year I'm ever running it because there's
06:21
not enough throughput. Def Con is so big you can only run so many teams and we're going to do something better and bigger and faster. But this year from Salt Lake City, Utah topped it out. Yellow 37 did great. Just barely getting ahead of surprise butt plugs. But a lot of these people, and I encourage you, if any of you are contest organizers, do this shit. For our scoring, we give a 10% point bump off the
06:44
top of the score for anyone who participates in charity stuff. So if you bomb in and you're like, hey, I just got a mohawk or I just gave blood, like, bang, score, score, like it's going up. But I let people do that until the end of the contest. So there's a whole team that's like watching their score and then they jump to second and then they run over and all give blood and they come back
07:01
with bandages. They're like, boom, give us bonuses. Yeah, sex slut crushed it because they all gave blood. Two guys got mohawks. They did like be the match. And fusion between the contest and events is awesome. So try to do that and come to the Def Con shoot next year because we blow shit up in the desert. Thank you. Next up, coin droids. And schema verse. So coin droids is a
07:34
robot battle game but played entirely through Def coin. So you battle each other by sending transactions at each other,
07:43
trying to steal each other's money, et cetera, et cetera. This year, oh, I have notes. We had 240 players which was ridiculous. 88,000 attacks took place with a lot of Def coin. We had two different battles. One was king of the hill and that was won by freak. That got a little
08:02
intense for a couple people. And the other battle which was the boss battle, I agree. The best thing to do with our contest is to kind of integrate with a bunch of them so we had bosses all over the place and someone managed to find three of them and that was moon doggy. That was pretty much it. Coin droids.com runs all year round though so you can still keep playing. Schema verse is a
08:28
space battle game written inside a postgres database. So select star for my ships, insert into my ships, drop Bobby tables, et cetera, it's all there. This year we had 71
08:41
trillion tuples returned for those database nerds in the room. That's 2.5 million actions. And no one hacked it this year so that was kind of boring. Our prize this year was a schema verse cup which was actually created by a core developer of postgres for this competition. So I'd like to
09:01
welcome sis fix quickly, run on stage for being the champion this year. Crack me if you can. In here. In here. Yes. Boom. Oh, you're right there. Literally sitting right
09:23
there. Crack me if you can is the password cracking contest, our sixth year. So this year team hashcat pretty much destroyed all the other pro teams. It's the first time we've had a back to back winner so they were out for blood and they did it. They get $600 assuming they do a
09:41
write up describing everything they did and release updates to all their tools and we require all the pro teams to do that in order to get paid. So in a week or two there will be new betas of John the Ripper and hashcat and everything that's out there for everybody. Just real quick,
10:03
the big trick this year was it's all UTF 8 so none of it was in English, it was Japanese, it was Mandarin, it was all these other things and so most of the updates are going to be updated for UTF support in the majority of the tools and that's it. Thank you. I see you. There you go. Alphabetical order
10:29
guys. Darknet project is an interactive puzzle contest
10:41
based on Daniel Suarez's book demon. We put up puzzles run by an interactive jabber bot across defcon to help people learn how to do things in other villages, other contests. We integrated with coin droids to help people get over there. You can learn to solder, learn to crack Wi-Fi, learn how to use
11:01
GPG and Tor. We had three winners this year. Silk was our first place winner. Got a tremendous number of points. He also won last year. Nolan was our second place winner and tilted kypers was our third place winner and we got prizes for you all. See me afterwards. Thank you very much. So drunk
11:30
actor history was a new competition this year. And it was a story telling competition with a twist. We prepared the eight contestants with five liters of vodka, a
11:42
liter of bourbon and half a liter of rum and got in stage and got five minutes to tell a story. So what was on paper sounded like a really good idea, ended up being a shit show of epic proportions. So we have some prizes. Jack Daniel, we actually don't have his prize because one of the contestants
12:01
stole it. And then pyro, if you're here, we have a flask for you. And then the first place winner was Katie. And here's Katie's prize. EFF badge hacking. Anybody? Anybody?
12:28
Anybody? Anybody? Is that? Here he comes. He's coming. We're all judging your stride. He could be a lot more effective if you just shorten that up a little. Take that
12:42
advice to heart. Thanks. This is the first year we did the badge hacking pageant. Thanks to judges Joe Grand, Lost and Zoz. We saw lots of participation for a first year thing. So the digital winner was a loather with a DC22 badge. He made a quadrocopter out of it. He did two flights. The
13:02
first flight, came back around and clipped him in the calf. Saw a lot of actually a surprising amount of blood there. So great thing that he won that. For the analog winner, it was rainbow unicorns bite with a knit koozie around this year's human badge. Kind of looked like a tire was pretty sick. And for the wildcard badge was
13:20
Mike and Mikey with amazingly detailed counterfeit uber badges which they used to get into DEF CON this year, I think. So, thanks everyone. We'll be back and better get next year.
13:45
At the end, you couldn't leave us in a cheer, but hacker Jeffery, the oldest contest at DEF CON, 21 years running. This year was won by Win Job, their third consecutive victory, beating Leet Meat, Effin Ward, and We Fucked It Up, who actually went all or nothing and mellowed out in the finals in the middle of the game. That wasn't too
14:01
bright. Jeff Moss, guest speaker, Win Schwarto came on and played, well, Win Schwarto as a contestant. And so did really well. My understanding is we had a couple firsts. We went through our first streaker, male unfortunately, so maybe next year we'll do better, at least for the guys. Ladies, I hope you enjoyed the show. 140 beers, so we're definitely doing our best we can to drive
14:23
up the cost of DEF CON. And so the ref will now lead us in a prayer. Fuck it up! Don't fuck it up! Until next year! Amen. We still got a couple of shirts left. Come see me
14:41
afterwards if you want a Hacker Jeopardy shirt. Thank you. RoboCalls. There they are. Okay, so amazingly, the FTC last
15:05
year did a RoboCall honeypot building contest. And more amazingly, this year they decided to come back. I was one of the judges. Everybody hates RoboCalls. It's like the safest thing in the world to be against. And if you tell
15:23
people you're working on a contest against RoboCalls, everybody says, yeah, that's great. So this was a lot of fun. We had two finalists this year competing for these incredibly valuable trophies that will be very easy to fit
15:40
into an overhead bin. Our best in, and also if they're declared official winners through the federal bureaucracy, substantial cash prizes. So our best in show was Team RoboKiller, which did an amazing amount of work. Are you ready? And our first runner up was Hemant Sanger. Come on up
16:05
and claim your very easy to fit in an overhead bin trophy.
16:34
He said that's next year's badges. Intel CTF. You're dead
16:46
to us. Network forensics. So we come from the small town of
17:05
Missoula, Montana every year and we put on the network forensics puzzle contest. What it is, it's a bunch of PCAPs that we put together showing different things through the networks with the TCPIP protocol. It went all the way until very late slash early in the morning, I guess,
17:24
yesterday. So we have threat level pancakes that came in first. They won a Fitbit surge. Second place was just one man, Tom Pohl, wherever he is, he's the best. And then third is Blue Squirrel, and they finished a couple hours after Tom Pohl, so congratulations. You guys are
17:41
awesome. And anything from DEFCON for them? Yeah, I did. Maybe? Fine. Open CTF, where you at? There's Pyro. We were
18:05
looking for you before. They're going to Maine? All right. Tamper evident. We are powering through. Also dead to us. These guys are gone, right? No, the secure ninja
18:25
cyber range. Cool, cool. Apparently there are prizes. So for a secure ninja cyber range, Maximus Blackborne came in first. We have prizes up here for you guys. They had to
18:41
take off. So if you are in here, head on up. No? We're keeping the shit. Come find me later for smoothies. I'm not
19:02
going to. Come find us in the DC 801 penthouse. Warlock games, they're main stage as well. All right. So now we'll get into just some of the cool stuff. So be the match had
19:20
126 signups this year, which is awesome. I love that that's still going. Is somebody here from that? Do you want to say anything? Yeah. Yeah, there were 20,000 people here and 126 signed up. Yeah, I guess that's whoops. So blood code 84,
19:45
blood donations made this year. So thanks to deviant for probably getting half of those. It might be all of them. Man, those guys look wrecked in there, too. Like somebody came over and they're like holy shit. Is that like
20:04
the medical area? Like people are just freaking passing out at Def Con? They're donating blood. I thought that was where you went when you got hurt. Ham radio exams. You
20:24
guys can talk about it. So DC 408 took their hand at running ham radio exams for the first time this year. Thank you to all our volunteers. Everyone who came out and took a test
20:40
gave a shot. Not everybody passed, but it's great to see the enthusiasm, hope you study and try again somewhere else. There are dice that we gave away to everyone who passed. If you didn't get yours or maybe if you're just a technician and you can come find me, you can have one. So as you can see, we had 124 exams taken this year. 65 of
21:04
those were the technician class, which is your basic entry level. Gets you started in it. You can start transmitting as soon as your name and call sign show up in the FCC database. There were 11 people who upgraded from technician up to the general class. Nine people who went up to their amateur extra, which is the highest class that
21:22
you can achieve. We also had a couple of people who, let's see, the actual number for people who tried to do two tests at once was 42. One person attempted to do all three, however, they fell short on the last test, but they will be back. And that's the stats I have.
21:41
Thank you all. If you're interested in your ham radio license, we'll have information posted on the forums as well as being back next year. Thank you. Mohawks. There she is. Give it my badge back.
22:09
Hello, I'm Ed. That's Lexi. We do this whole MohawkCon thing, shaving heads. I see a good amount of Mohawks out there, but of course, never enough. This year, let's see, we have
22:29
new numbers. Let me pull those up. Because when I sent in the information at noon, like I was supposed to, we were still cutting heads and getting huge amounts of even more
22:41
donations. Cutting heads. Yes. Haven't you seen all the blood running around? You know the medical bay? Final total for the EFF was $2,575. For Hackers for Charity, $1,049.
23:04
The donation box raised $67 just printing out stickers. It was only here for a day and a half and it got $67. And we shaved a total of 153 heads. And so this year, grand total
23:22
raised $3,691 for charity. IOT Village. We didn't do
23:42
anything nice for charity, so that sucks for us. But good for them. This is the first year of the Internet of Things Village. As you can see, we have two contests based off our
24:01
so hopelessly broken challenge. The zero day track, we found 25 new vulnerabilities and just learned that our smart fridge was man in the middle of their email. That just happened, so don't get a smart fridge. Going over the scoring and stuff, so if you participated in that track, we're going to reach out to you via email and get you your
24:21
prizes. Our capture the flag contest, we have team first place was froggy style, second was ad hoc. Froggy style, where are you? Of one wolf or something that I can't see down there. One man wolf. We are going to be given over $5,000 in
24:41
cash prizes, so we'll be in touch with the winners. Thanks for having us this year, guys. It was a lot of fun. It's good to be here. I'm going to waste as much
25:04
time as possible. So Wireless Village this year, we had a whole bunch of contest events, but we mostly rebuilt the entire capture the flag game. We built an entire fake town including a nuclear power plant, hospital transmitting, broken pock sag, as well as all the standard Wi-Fi stuff. So it was really a lot of fun. We had 15 teams with 10
25:23
tables, so it got a little tight and competitive. We had three winners, Raging Pwners, been here. They got almost half the flags on the board. So they're as awesome as it gets. You guys better try harder next year. We also acquired and last placed. Last place did quite a bit better
25:42
than last place as it was, but good for them. We gave away about $5,000 in high end radio gear to the winners, so I want to thank Black Phone Guys, Silent Circle, as well as Hacker F, Hacker Warehouse, Nuon for donating so much really expensive gear, and No Starts Press, and Hack 5 for giving away a whole bunch of gear for us. I'd also like to
26:03
say that this has been, I don't even know how many years of the wireless village, but our fearless leader, our father, our grandfather, has been working on this village since Def Con 15, and he's been running the village since three years ago, I suppose. Five years ago. He's
26:21
been running the village for five years. I'm not even old enough to stand here, but somehow he's decided that the rest of us losers can probably hack it on our own. He told us after all this time he's going to retire and make us do all the work. So a big round of applause for the man who's been running this forever. Thanks, everybody.
26:44
And I am leaving it in some very young and capable hands. All right, we stomped a mud hole in that, so thanks everybody. Again, the main closing ceremonies will take place over on the Paris side of the house, so if you're
27:02
interested, head on over that way. So thanks, and we'll see you next year. Also, if you're interested in running a contest or event next year, hit us up. You can reach me at grifter at DefCon.org. Seriously, we want to see cool
27:23
shit. Make it happen.
Recommendations
Series of 109 media
Series of 93 media
Series of 322 media
Series of 112 media
Series of 122 media