Down the Rabbit Hole: Uncovering a Criminal Server

DEF CON 17

Presented by: Matt Fiddler
Date: Sunday August 02, 2009
Time: 10:00 - 10:50
Location: Track 4
Track: Track 4

In this talk I'll cover the research efforts done when we managed to come across a criminally operated server running the latest Neosploit (and other goodies).

During the research there have been several crucial points of interest such as the discovery of compromised credentials, getting into the applications used by the criminals to manage the infections, and the infection channels, as well as a few hairy moments of being logged in to the server while "someone" else was also logged in (from a notorious location that has been brought down after an article at the Washington Post - McColo...).

Iftach Ian Amit

With more than 10 years of experience in the information security industry, <strong>Ian (Iftach) Amit</strong> brings a mixture of software development, OS, network and Web security expertise as a Managing Partner of the top-tier security consulting and research firm Security-Art. Prior to Security-Art, Ian was the Director of Security Research for the Content Security Business Unit at Aladdin Knowledge Systems, where he created the AIRC (Attack Intelligence Research Center). Prior to joining Aladdin, Amit was Director of Security Research at a global Internet security company, leading its security research while positioning it as a leader in the Web security market. Amit has also held leadership roles as founder and CTO of a security startup in the IDS/IPS arena, developing new techniques for attack interception, and director at Datavantage responsible for software development and information security, as well as designing and building a financial datacenter. Prior to Datavantage, he managed the Internet application and UNIX worldwide. Amit holds a Bachelor's degree in Computer Science and Business Administration from the Interdisciplinary Center at Herzlya.


KhanFu - Mobile schedules for INFOSEC conferences.
Mobile interface | Alternate Formats