Dirty Little Secrets Part 2

DerbyCon 2.0 - The Reunion

Presented by: Rob Fuller (mubix), Chris Gates, Raphael Mudge
Date: Friday September 28, 2012
Time: 19:00 - 19:50
Location: Track 1
Track: Break Me

This talk (hopefully) provides some new pentesters tools and tricks. Basically a continuation of last year’s Dirty Little Secrets they didn’t teach you in Pentest class. Topics include; OSINT and APIs, certificate stealing, F**king with Incident Response Teams, 10 ways to psexec, and more. Yes, mostly using metasploit.

Chris Gates

Chris Gates: Chris joined LARES in 2011 as a Partner & Principal Security Consultant. Chris has extensive experience in network and web application penetration testing as well as other Information Operations experience working as an operator for a DoD Red Team and other Full Scope penetration testing teams (regular pentesting teams too). Chris holds a BS in Computer Science and Geospatial Information Science from the United States Military Academy at West Point and holds his… redacted…no one cares anyway. In the past, he has spoken at the United States Military Academy, BlackHat, DefCon, Toorcon, Brucon, Troopers, SOURCE Boston, OWASP AppSec DC, ChicagoCon, NotaCon, and CSI. He is a regular blogger carnal0wnage.attackresearch.com and is also a regular contributor to the Metasploit and wXf Projects. http://twitter.com/carnal0wnage

Rob Fuller

Rob Fuller: Mubix is a Senior Red Team member for a Fortune 500. He is a cast member of the video podcast Hak.5 and is very active in the open source community as a thought provoker, reviewer and sometimes even a coder. He has worked on projects like Metasploit, Jasager, and the Hak5 USB Rubber Ducky. His professional experience start from his time on active duty as United States Marine. He has worked with devices and software that run gambit in the security realm. He has the Security+, C|EH, and Offensive Security Certified Professional certifications. But the titles that he holds above the rest is FATHER, HUSBAND and United States Marine

Raphael Mudge

Raphael Mudge is the founder of Strategic Cyber LLC, a Washington, DC based company that creates software for red teams. He created Armitage for Metasploit, the Sleep programming language, and the IRC client jIRCii. Previously, Raphael worked as a security researcher for the US Air Force, a penetration tester, and he even invented a grammar checker that was sold to Automattic. His work has appeared in Hakin9, USENIX ;login:, Dr. Dobb’s Journal, on the cover of the Linux Journal, and the Fox sitcom Breaking In. Raphael regularly speaks on security topics and provides red team support to many cyber defense competitions.


KhanFu - Mobile schedules for INFOSEC conferences.
Mobile interface | Alternate Formats