Yashartha Chaturvedi | 18 Mar 15:23
Picon

c0c0n 2012 - Call For Papers and Call For Workshops

___ ___ ____ ___ _ ____ ___ / _ \ ___ / _ \ _ __ |___ \ / _ \/ |___ \ / __| | | |/ __| | | | '_ \ __) | | | | | __) | | (__| |_| | (__| |_| | | | | / __/| |_| | |/ __/ \___|\___/ \___|\___/|_| |_| |_____|\___/|_|_____| ################################################### c0c0n 2012 - Call For Papers and Call For Workshops ################################################### August 2-4, 2012 - Cochin, India Buenos días from the God’s Own Country! We are extremely delighted to announce the Call for Papers and Call for Workshops for c0c0n 2012 <http://www.is-ra.org/c0c0n/>, a 3-day Security and Hacking Conference (1 day pre-conference workshop and 2 day conference), full of interesting presentations, talks and of course filled with fun! The conference topics are divided into four domains as follows: >> Info Sec - Technical >> Info Sec - Management >> Digital Forensics and Investigations >> Cyber Laws and Governance. We are expecting conference and workshop submissions on the following topics, but are not limited to: >> New Vulnerabilities and Exploits/0-days >> Open Source Security&Hacking Tools >> Antivirus/Firewall/UTM Evasion Techniques >> Software Testing/Fuzzing >> Network and Router Hacking >> Malware analysis & Reverse Engineering >> Mobile Application Security-Threats and Exploits >> Advanced Penetration testing techniques >> Web Application Security & Hacking >> Browser Security >> Hacking virtualized environment >> WLAN and Bluetooth Security >> Lockpicking & physical security >> Honeypots/Honeynets >> Exploiting Layer 8/Social Engineering >> Cloud Security >> Critical Infrastructure & SCADA networks Security >> National Security & Cyber Warfare >> Cyber Forensics, Cyber Crime & Law Enforcement >> IT Auditing/Risk management and ISO 27001 ##################### CFP Review Committee: ##################### 0x01 - Armando Romeo 0x02 - Dinesh O Bareja 0x03 - Peter Giannoulis 0x04 - Simon Bennetts (a.k.a. Psiinon) 0x05 - Vahan Markarov For more details about the Review Committee, visit - http://is-ra.org/c0c0n/cfp.html ##################### Submission Guidelines: ##################### Email your submission to: cfp [at] is-ra [dot]org Email subject should be: CFP c0c0n2012 - <Paper Title> Email Body: Personal Information: ===================== >> Speaker Name: >> Job Role/Handle: >> Company/Organization: >> Country: >> Email ID: >> Contact Number: >> Speaker Profile: (max 1000 words) >> If there is additional speaker please mention it here following the above format. Presentation Details: ===================== >> Name/Title of the presentation: >> Paper Abstract: (max 3000 words) >> Presentation Time Required (20, 30, 50 Minutes) >> Is there any demonstration? Yes or No >> Are you releasing any new tool? Yes or No >> Are you releasing any new exploit? Yes or No Other Needs & Requirements: =========================== >> Do you need any special equipment? >> We will be providing 1 LCD projector feed, 2 screens, microphones, wired and/or wireless Internet. >> If you have any other requirement, Please mention it here and the reason. ##################### Remember these Dates! ##################### >> CFP Opens: 16th Mar 2012 >> CFP Closing Date: 30th Apr 2012 >> Speakers list online: 21th May 2012 >> Workshop Dates: 02nd Aug 2012 >> Conference Dates: 03rd and 4th Aug 2012 *NOTE:* We should not promote vendor/product oriented submissions hence it will be rejected. ################## Speaker Benefits: ################## >> Complimentary Conference registration. >> Complementary Accommodation for 2 nights. >> Complementary conference passes. >> Invitation to c0c0n-Blast (The Networking Lungi party). >> Travel Reimbursement - The selected speaker will receive travel reimbursement, to the extent available with existing ISRA /conference funds. >> Only one speaker will be eligible for the benefits in case there are two or more speakers for a talk.

Thanks and Regards,

  -c0c0n Team-

http://is-ra.org/c0c0n/
_______________________________________________
firewall-wizards mailing list
firewall-wizards <at> listserv.icsalabs.com
https://listserv.icsalabs.com/mailman/listinfo/firewall-wizards
rahul sharma | 17 Feb 15:36
Picon

How MSRPC flow is handled? How to delete the flows after successful transfer of data

Hi All,

I am trying to get details about MSRPC and its working. So far I have come to know that when a Client requests for a particular service, first it comes to End Point Mapper. Then in response to Map Request, the Port and IP address are sent to client in Response's Tower id 4 and 5 respectively. Now I have the port and IP address.  I simply connect to that service. Now suppose I am firewalling it. Now if I allowed the MSRPC packets, then I will create an embryonic flow for that connection, and then the firewall will allow those packets.

Now my problem is how I will detect for how long I need to keep that flow open? If the communication on that port has finished, then how should I make sure that now its exited and I need to delete the flow ID? Can anyone help me how should I go for this or how is this actually implemented??

Thanks and Regards
Rahul Sharma

_______________________________________________
firewall-wizards mailing list
firewall-wizards <at> listserv.icsalabs.com
https://listserv.icsalabs.com/mailman/listinfo/firewall-wizards
cfp | 15 Aug 12:53
Picon

Ruxcon 2011 Final Call For Papers

Ruxcon 2011 Final Call For Papers

The Ruxcon team is pleased to announce the final call for papers for the seventh annual Ruxcon conference.

This year the conference will take place over the weekend of 19th and 20th of November at the CQ Function
Centre, Melbourne, Australia.

The deadline for submissions is the 15th of October.

* What is Ruxcon?

Ruxcon is the premier technical computer security conference in the Australia-Pacific region. The
conference aims to bring together the individual talents of the best and brightest security folk in the
region, through live presentations, activities and demonstrations.

The conference is held over two days in a relaxed atmosphere, allowing attendees to enjoy themselves
whilst networking within the community and expanding their knowledge of security.

Live presentations and activities will cover a full range of defensive and offensive security topics,
varying from previously unpublished research to required reading for the security community.

For more information, please visit http://www.ruxcon.org.au

* Presentation Information

Presentations are set to run for 50 minutes, and will be of a formal nature, with slides and a speech.

* Presentation Submissions

Ruxcon would like to invite people who are interested in security to submit a presentation.

Topics of interest include, but are not limited to:

    o Mobile Device Security
    o Virtualization, Hypervisor, and Cloud Security
    o Malware Analysis
    o Reverse Engineering
    o Exploitation Techniques
    o Rootkit Development
    o Code Analysis
    o Forensics and Anti-Forensics
    o Embedded Device Security
    o Web Application Security
    o Network Traffic Analysis
    o Wireless Network Security
    o Cryptography and Cryptanalysis
    o Social Engineering
    o Law Enforcement Activities
    o Telecommunications Security (SS7, 3G/4G, GSM, VOIP, etc)

Submissions should thoroughly outline your desired presentation subject.

If you have any enquiries about submissions, or would like to make a submission, please send an e-mail to
presentations () ruxcon org au

The deadline for submissions is the 15th of October.

If approved we will additionally require:

i.  A brief personal biography (between 2-5 paragraphs in length).
ii. A description on your presentation (between 2-5 paragraphs in length).

* Contact Details

Presentation Submissions:  presentations () ruxcon org au
Chris | 11 Aug 13:45

Re: Securing email by inhibiting urls

I'll check out Ironport.  We looked at this earlier but there was something about it at the time that caused us
to not buy it.  Time to revisit...

Thanks

-----Original Message-----
From: Kaas, David D [mailto:David_D_Kaas <at> RL.gov] 
Sent: Thursday, August 11, 2011 12:06 AM
To: 'chughes <at> l8c.com'; 'Firewall Wizards Security Mailing List'; 'firewall-wizards <at> listserv.cybertrust.com'
Subject: RE: [fw-wiz] Securing email by inhibiting urls

The ironport email appliane can do this.  You can strip HTML or modify URLs.  Outlook tries to be friendy bt
atutomativally making www. Any.com clickable.

 -----Original Message-----
From: 	Chris [mailto:chughes <at> l8c.com]
Sent:	Wednesday, August 10, 2011 08:46 PM Pacific Standard Time
To:	firewall-wizards <at> listserv.cybertrust.com
Subject:	[fw-wiz] Securing email by inhibiting urls

A company I work for has been having great difficulty in securing against email attacks.  So far we have
disabled access to webmail, implemented  rules and processes to block freemail services like hotmail etc
until the sender registers the address and of course a spam filter (BrightMail).  Attachment filtering is
pretty strict as well.

The threat that presents the biggest challenge is url links in emails.  The common method of attack is an
email from somedomain.com where they change one character or otherwise make the address look valid (ie:
joe <at> s0medomain.com or j0e <at> somedomain.com etc).

I was looking for a way to spot and block hyperlinks but it looks like the only option I have is to filter on
these and send them to a spam bin.  I’d rather yank the offending hyperlink and replace it with a message of
some sort.  Unfortunately BrightMail doesn’t offer that capability.

Any products that do this or ideas on a solution?

Thanks

_______________________________________________
firewall-wizards mailing list
firewall-wizards <at> listserv.icsalabs.com
https://listserv.icsalabs.com/mailman/listinfo/firewall-wizards
Chris | 1 Aug 20:46

Securing email by inhibiting urls

A company I work for has been having great difficulty in securing against email attacks.  So far we have disabled access to webmail, implemented  rules and processes to block freemail services like hotmail etc until the sender registers the address and of course a spam filter (BrightMail).  Attachment filtering is pretty strict as well.

 

The threat that presents the biggest challenge is url links in emails.  The common method of attack is an email from somedomain.com where they change one character or otherwise make the address look valid (ie: joe <at> s0medomain.com or j0e <at> somedomain.com etc).

 

I was looking for a way to spot and block hyperlinks but it looks like the only option I have is to filter on these and send them to a spam bin.  I’d rather yank the offending hyperlink and replace it with a message of some sort.  Unfortunately BrightMail doesn’t offer that capability.

 

Any products that do this or ideas on a solution?

 

Thanks

_______________________________________________
firewall-wizards mailing list
firewall-wizards <at> listserv.icsalabs.com
https://listserv.icsalabs.com/mailman/listinfo/firewall-wizards
Papers, Call For | 24 Jul 16:47

CFP Securitybyte India

Hi All,
The first round of speakers have been selected for Securitybyte, please follow us on twitter <at> securitybyte to get the latest updates on speakers and event.
 
Deral Heiland, From Printer to Owned: Leveraging Multifunction Printers During Penetration Testing
Nithya Raman, Security threats on social networks
Alexander Polyakov, A Crushing Blow At the Heart of SAP J2EE Engine
Bishan Singh, Enabling Un-trusted Mashups
Krzysztof Kotowicz, HTML5: Something Wicked This Way Comes
John McColl, Hacking Corporate Telephony
Aseem Jakhar, Runtime thread injection and execution in Linux processes
George Nicolaou, Alternative Exploitation Vectors (A study of CVE-3333)
Michele Orru, Securing the Browser
Kanwal K. Mookhey, The Data Theft Epidemic in India
Vivek Ramachandran, Enterprise Wi-Fi Worms, Backdoors and Botnets for Fun and Profit
 
The 2nd round of CFP is out
 
CFP/CTP
 
Securitybyte is proud to announce its Second Annual International Information Security Conference, "Securitybyte 2011" in Bangalore, India. This 4-day event features two days of conferences and two days of post-conference hands-on Trainings & Certifications covering every aspect of Information Security. The Securitybyte conference features some of the most respected names in the Security space and is focused around new research and innovation. The Securitybyte Conference 2011 is planned for Sept 6th through 9th, 2011 at The Taj Hotel in Bangalore, India.
 
The two-day conference (Sept 6th & 7th) will have the following three tracks:
 
    Deep Technical
   Government & Governance
    Management
 
Submission Deadline: The first round of submission of papers for conference talks and trainings should be done no later than August 5th, 2011. Please send all your submissions to cfp <at> securitybyte.org, keeping subject line as "SB 2011 CFP Submission".
 
TOPICS
 
Got a new attack against any technology or device? We want to see it.
 
Topics of interest include, but are not limited to, the following:
 
Management
                Case studies around any of the topics above of how the implementation was done and what were some of the lessons learned.
 
Technology-Focused
 
                Cloud Security
                Electronic Device Security (Cell Phones / PDA's)
                Defeating Biometrics
                WLAN, RFID and Bluetooth Security
                Data Recovery and Incident Response
                Virtualization Security
                Database Security
                Forensic & Cyber security
 
Regulatory & Law
 
                Copyright infringement and anti-copyright infringement enforcement technologies
                Critical infrastructure issues
                Data security and privacy issues
                Identity theft, identity creation & identity fraud
                Corporate Espionage
 
               
National Security
 
               Cyber forensics
               Cyber warfare
               Cyber Espionage
               Next hyphenGen Cyber threats
               Critical Infrastructure protection
    Surveillance & counter-surveillance
 
Speaker Submission:
 
Please use the following submission form template to respond:
 
    Name, title, address, email, and phone/contact number
    Short biography, qualifications, occupation, achievements, and affiliations (limit 250 words.)
    Summary or abstract of your presentation (limit 1250 words.)
    Technical requirements (video, internet, wireless, audio, etc.)
    References (Contact name, title, and email address of two conferences you have spoken at or comparable references.)
 
**Please note, product or vendor pitches are not accepted. If your talk involves an advertisement for a new product or service your company is offering, please do not submit a proposal.

 
Regards
SecurityByte

_______________________________________________
firewall-wizards mailing list
firewall-wizards <at> listserv.icsalabs.com
https://listserv.icsalabs.com/mailman/listinfo/firewall-wizards
Rocker Feller | 25 May 10:04
Picon

CISCO ASA 7.0(8) - internal users cannot browse.

Hi all,

I am a newbie and would like assistance on an asa.

I have a cisco asa factory default that i configured.

this is my configuration,  thank you.


1. I cannot ping the gw ip when connected on console though from teh gw which is a cisco router i can pick the asa mac address.

2. I have the two acls 101 and cmd  icmp permit any outside which should enable me to ping from any outside host to the outside interface of the asa to no avail.

3. public ip and gw are public ips.

Q. Any assistance to get this working so that i can configure an ra vpn will be appreciated.



SA Version 7.0(8)
!

domain-name ciscoasa.co.ke

names
dns-guard
!
interface Ethernet0/0
 description Link to Service Provider
 nameif outside
 security-level 0
 ip address publicip 255.255.255.252
!
interface Ethernet0/1
 description Link to Local LAN
 nameif inside
 security-level 100
 ip address 192.168.168.11 255.255.255.0
!
interface Ethernet0/2
 shutdown
 no nameif
 no security-level
 no ip address
!
interface Management0/0
 nameif management
 security-level 100
 ip address 192.168.1.1 255.255.255.0
 management-only
!
ftp mode passive
access-list ANY extended permit ip any any
access-list ANY extended permit icmp any any echo-reply
access-list ANY extended permit icmp any any time-exceeded
access-list ANY extended permit icmp any any unreachable
access-list ANY extended permit icmp any any
access-list OUT extended permit icmp any any echo-reply
access-list OUT extended permit icmp any any echo
access-list 101 extended permit icmp any any echo-reply
access-list 101 extended permit icmp any any source-quench
access-list 101 extended permit icmp any any unreachable
access-list 101 extended permit icmp any any time-exceeded
pager lines 24
logging asdm informational
mtu outside 1500
mtu inside 1500
mtu management 1500
icmp permit any outside
asdm image disk0:/asdm-508.bin
no asdm history enable
arp timeout 14400
global (outside) 1 interface
nat (inside) 1 192.168.168.0 255.255.255.0
access-group ANY in interface inside
route outside 0.0.0.0 0.0.0.0 gw 1
timeout xlate 3:00:00
timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 icmp 0:00:02
timeout sunrpc 0:10:00 h323 0:05:00 h225 1:00:00 mgcp 0:05:00
timeout mgcp-pat 0:05:00 sip 0:30:00 sip_media 0:02:00
timeout uauth 0:05:00 absolute
http server enable
http 192.168.1.0 255.255.255.0 management
no snmp-server location
no snmp-server contact
snmp-server enable traps snmp authentication linkup linkdown coldstart
crypto ipsec security-association lifetime seconds 28800
crypto ipsec security-association lifetime kilobytes 4608000
telnet timeout 5
ssh timeout 5
console timeout 0
dhcpd address 192.168.1.2-192.168.1.254 management
dhcpd lease 3600
dhcpd ping_timeout 50
dhcpd enable management
!
class-map inspection_default
 match default-inspection-traffic
!
!
policy-map global_policy
 class inspection_default
  inspect dns maximum-length 512
  inspect ftp
  inspect h323 h225
  inspect h323 ras
  inspect rsh
  inspect rtsp
  inspect esmtp
  inspect sqlnet
  inspect skinny
  inspect sunrpc
  inspect xdmcp
  inspect sip
  inspect netbios
  inspect tftp
  inspect icmp
!
service-policy global_policy global
Cryptochecksum:6f78bb9efb6b013ce7eb3cf8d77268ae

Rocker

_______________________________________________
firewall-wizards mailing list
firewall-wizards <at> listserv.icsalabs.com
https://listserv.icsalabs.com/mailman/listinfo/firewall-wizards
ArkanoiD | 23 May 22:30
Favicon

obscure email address formats

Is there any good reason to allow email addresses (in smtp, imap and alikes)
in any format different from mailbox <at> fqdn ?

There is plenty of other stuff defined in RFCs and I wonder if anyone really uses it so
I should *not* just filter it out.
cfp | 17 May 08:37
Picon

Ruxcon 2011 Call For Papers

Ruxcon 2011 Call For Papers

The Ruxcon team is pleased to announce the call for papers for the seventh annual Ruxcon conference.

This year the conference will take place over the weekend of 19th and 20th of November at the CQ Function
Centre, Melbourne, Australia.

The deadline for submissions is the 30th of July.

* What is Ruxcon?

Ruxcon is the premier technical computer security conference in the Australia-Pacific region. The
conference aims to bring together the individual talents of the best and brightest security folk in the
region, through live presentations, activities and demonstrations.

The conference is held over two days in a relaxed atmosphere, allowing attendees to enjoy themselves
whilst networking within the community and expanding their knowledge of security.

Live presentations and activities will cover a full range of defensive and offensive security topics,
varying from previously unpublished research to required reading for the security community.

For more information, please visit http://www.ruxcon.org.au

* Presentation Information

Presentations are set to run for 50 minutes, and will be of a formal nature, with slides and a speech.

* Presentation Submissions

Ruxcon would like to invite people who are interested in security to submit a presentation.

Topics of interest include, but are not limited to:

    o Mobile Device Security
    o Virtualization, Hypervisor, and Cloud Security
    o Malware Analysis
    o Reverse Engineering
    o Exploitation Techniques
    o Rootkit Development
    o Code Analysis
    o Forensics and Anti-Forensics
    o Embedded Device Security
    o Web Application Security
    o Network Traffic Analysis
    o Wireless Network Security
    o Cryptography and Cryptanalysis
    o Social Engineering
    o Law Enforcement Activities
    o Telecommunications Security (SS7, 3G/4G, GSM, VOIP, etc)

Submissions should thoroughly outline your desired presentation subject.

If you have any enquiries about submissions, or would like to make a submission, please send an e-mail to
presentations () ruxcon org au

The deadline for submissions is the 30th of July.

If approved we will additionally require:

i.  A brief personal biography (between 2-5 paragraphs in length).
ii. A description on your presentation (between 2-5 paragraphs in length).

* Contact Details

Presentation Submissions:  presentations () ruxcon org au
ArkanoiD | 14 May 15:02
Favicon

Solsoft NSM still alive?

I was surprised to find it is!

It is now called HAL-GK (Hybrid Application Layer Gatekeeper) and being developed by Edenwall
(there appears to be a commercial appliance based on it and NuFW).

I checked the sources, but it looks like most interesting parts are missing -- no SQL and Netbios proxies anymore.
Does anyone still have old NSM source tarball? I cannot find it.
Greg Marcom | 10 May 23:01
Picon
Gravatar

Cyberoam Firewalls

Has anyone had any experience with these? My company was using
SnapGears and since McAfee stopped making them, we had to switch.
Anybody else have any other good makes and models that they use?

Gmane