Yo I really like this guy, he is a breath of fresh air to all the other people that talk on the stage.
@Rajivrocks-Ltd.9 жыл бұрын
yeah but I feel like he does it better though/
@Rajivrocks-Ltd.9 жыл бұрын
Yeah, not enough serious talks about real interesting stuff too much nonsense.
@nicolek40769 жыл бұрын
+Rajivrocks Ltd. This guy's presentation style is one of the worst of this conference. He has too many verbal tics, he's tiring to listen to - his delivery is staccato, too many wrong choices of word, too much laughing at his own (unfunny) jokes. The content is pretty mundane and he underestimates his audience. This symbol "#" is NOT a "pound". It's a hash or octothorpe. A pound sign looks like this "£".
@Rajivrocks-Ltd.9 жыл бұрын
That is really your own opinion, who are you to judge a performance of someone? and jokes are funny in the eye of the beholder its not the same for everyone. and that useless comment at the end. are you really that pretentious? seems like you're just commenting for no reason other then letting people know that you have a somewhat larger vocabulary then the average user on the internet (at least that's what you think). I might be wrong but that is my take on your comment.
@nicolek40769 жыл бұрын
Rajivrocks Ltd. My comments are result of many years technical training and training trainers.
@darkdancerman9 жыл бұрын
I like this guy.
@POM4R4NC9 жыл бұрын
very good speaker, pleasure to listen to
@disk0__7 жыл бұрын
Z
@BrianDixonFTM9 жыл бұрын
Dennis Maldonado, I have watched many many DEFCON videos, yours was awesome. I was cracking up and you had my attention the entire time. Good job man! I am sure being in front of all those people is nerve racking all on its on. I enjoyed it!
@bQ5rL3m6D7 жыл бұрын
He doesn't remember what happened after he got off the stage lol Such a great talk, so informative AND entertaining. True young professional. Love it man, need more people like this. Confident, tech savvy, clever, and organized, a few jokes, and you got a great DEFCON talk. Love this community
@tobiashenriksen70688 жыл бұрын
One of the best presentations I have seen yet - nice job Dennis. :)
@jaroslavhromatka32577 жыл бұрын
Great talk, man. Nice to see somebody comming out and pointing at the flaws of access control systems. These devices are developed without any thought going into securing the control mechanisms that messing with them almost doesn't qualify as hacking.:D You are just using it's features... :D (not trying to undermine this talk, just stating that developers of ACS should really get their s**t together)... And yeah, until then, guys, use just serial connection for this - don't use serial-to-ethernet - doing so means inviting anyone in...
@9000fail9 жыл бұрын
So funny. great talk
@RoSi4You9 жыл бұрын
Gooooooooood speaker! Hoping to see You @24
@hellterminator9 жыл бұрын
Wow. He really got drunk from that shot. :D
@P4ulyAnon9 жыл бұрын
Great speaker, interesting and easy to understand topic! Hope to hear more of this guy and I'm going to download his tool asap.
@rogerwilco29 жыл бұрын
I liked this talk and the speaker.
@Uneke4 жыл бұрын
With those 500s and 1000s If you call the box’s phone line while dialing it out, it’ll auto pick up your incoming call and you can press 9 on you phone and it’ll open it. This method tricks it into thinking it’s called up and a tenant has answered
@renakunisaki6 жыл бұрын
Note, his Twitter is @DennisMald, not @DennisMaid.
@d74g0n9 жыл бұрын
moar defcon!
@ShesSometimesDoubleChocolate7 жыл бұрын
"Moar"? Huh, what?
@itzSpoke9 жыл бұрын
Dude, this open bottle of water stresses the heck out of me...
@thewatcher_4769 жыл бұрын
+Spoke same. Like "dude don't put an opened bottle of water next to your computer!"... XD
@qtpie26306 жыл бұрын
you have ocd
@rolfs21656 жыл бұрын
The way he's placed the bottle, it will fall away from his laptop. I did some amateur theatre tech and was taught this on the first day, to always put my drink behind the mixer. So if it falls over, you'll get some wet cables, but don't drown the expensive stuff.
@jav20a9 жыл бұрын
Awesome talk, plus I think this guy got drunk with that shot lol
@timkennedy63589 жыл бұрын
This was an amazing speech, super fun to listen to and try out haha.
@vladotos9 жыл бұрын
Great speaker :D
@xapemanx9 жыл бұрын
This guy is great lol
@jodelboy8 жыл бұрын
Great talk(er)!
@SnapcrackerzTeam9 жыл бұрын
good talk
@jackkraken38889 жыл бұрын
Dennis was great, and that access system really sucks a**.
@TimHoekstra9 жыл бұрын
So secure it makes hacknet look like a simulator. Good work!
@kaceesavage3 жыл бұрын
Has any of this changed up till now?
@irae92 жыл бұрын
I wonder how much of this is still relevant. Espec the part about connecting these devices to the internet..since there's still a lot of people connecting things to the internet willy nilly without thinking about the security implications of that. Plugging access control systems to the internet when they already have the ability to be directly managed by a PC seems pointless? Just connect it via serial to a PC on-site, then set up remote access to that management PC. That way you get much better options for access control, since then you're looking at securing access to a regular PC, rather than just some basic device designed to do one thing.
@sbsftw42324 жыл бұрын
Why don't the devices have the ip kit installed by default? Just have an Ethernet port as part of the existing boards in the box.
@sbsftw42324 жыл бұрын
I'm just here cuz I'm a delivery driver and I'm sick of customers not giving me gate codes.
@leechowning27122 жыл бұрын
Look up Deviant This is your key here on YT. It is a whole discussion on master keys, and you will get a lot done.
@agustindelanda57917 жыл бұрын
Good presentation, question, did you try using a connection through the Phone Line ?
@NolePTR7 жыл бұрын
The data is reversed because it's in Little-Endian 14:00 .. But why they store ASCII strings as "little-endian" is beyond me. Hell, why do they even store numbers-only passwords as strings?
@ruzaesp90239 жыл бұрын
25:48 What is the python code? I mean the script
@dennismaldonado98309 жыл бұрын
github.com/linuz/Access-Control-Attack-Tool Still needs lots of work!
@ruzaesp90239 жыл бұрын
Dennis Maldonado Thanks!
@BimbusBucklenuts8 жыл бұрын
Nortek has an older panel called Max 3 and it uses Hub Manager Pro (8.1) as the PC head end software. it is also password protected to log into the program, but you can replace the password files with a default password file and it leaves the fob and user databases in-tact. When you're done, you can replace the password files with the one you don't know the password to. The default password is HUBMAN.
@kkeithf Жыл бұрын
This is the kind of kid that should be president
@HDReMaster9 жыл бұрын
I FREAKIN' LOVE DEFCON!!!!! SCIENCE BITCH
@ShesSometimesDoubleChocolate7 жыл бұрын
What's the name of your science bitch, Schwaa?
@oetken0078 жыл бұрын
How is it possible that some piece of shit like this can be on the market? Does nobody else a kid test these devices? Is no official certification needed for security devices in the US? Unbelievable! Edit: Great talk Dennis, thank you!
@jaroslavhromatka32577 жыл бұрын
Companies that develop ACS hardly look at securing the device itself and usually don't even have any network guys. And as Mr. Maldonado said during the presentation - customers usually look for the lowest bidding contractor and those usually don't know s**t about network security either... they are just random guys thinking:"yeah, this is so easy to install, let's sell it to anyone..."
@christianbarnay24996 жыл бұрын
Problem is even if you hire the best contractor who will change the password and physical lock, the stupid firmware will cancel all that work when it decides to run unauthenticated commands (just not giving feedback but still doing the job) to change back the password to default, allow new devices or access codes, or just simply direct door control commands. This "security" firmware is flawed by design. And the company that makes it and uses it in costly "security solutions" needs to face a class action from fooled customers.
@MarkTillotson6 жыл бұрын
It seems that every single decision they made about securing the device they took the wrong path. Not fit for purpose. Anything about that isn't piss-awful? Security theatre only.
@stumm3r6 жыл бұрын
until recently most access control units weren't networked onto main network systems they would sit alone on there own network ,As things have changed no one seems to have taken this into account, its embarrassing
@nikanj7 жыл бұрын
How are these security systems so flawed? Why do they hire people who don't care to design them then hire competent people to pen test them. Why not just hire the competent people to design them in the first place?
@MorbusSchmorbus7 жыл бұрын
even some random sps and being crafty could do a better job...
@MarkTillotson6 жыл бұрын
The reason is some company that makes solenoids and door locks thinks they are a software company with security expertese on the basis of someone they hire can write code and someone else is an EE. Hey we can make a door entry system! How hard can it be??! No research, no hiring security consultants (or if they do the managers just ignore the report because they are plonkers (not uncommon?)). Probably never even heard of pen-testing...
@asroneightyseven38545 жыл бұрын
Anyone notice the fastest DefCon speaker is wearing a sloth shirt? He's easily one of my top 5 five DefCon speakers. I hope to see him there for 2019.
@renzohernandez35968 жыл бұрын
wtf happen to the audio???
@ShesSometimesDoubleChocolate7 жыл бұрын
You tripped on your speaker cable.
@TinKoRlol9 жыл бұрын
So you can earn money by developing security mechanisms which aren't secure. Hilarious. Loved your talk, keep going!
@ShesSometimesDoubleChocolate7 жыл бұрын
They would not make me take that alcoholic drink!
@brashcrab Жыл бұрын
benson & hedges
@chrisk26737 жыл бұрын
He did well, It would be such a feat to perform as he did the first time. For me at least.
@WhoWantsToKnow816 жыл бұрын
When he said the password can only be 6 numbers (and only numbers), and additionally that there is an unlimited number of tries, I nearly blew my load
@adrenaline198 жыл бұрын
That's fucking hilarious
@joblessalex6 жыл бұрын
I can confirm shapeways steel key is about $15
@zefftrus98252 жыл бұрын
What was the name of the key
@kd1s7 жыл бұрын
Oh access control systems are fun. They're similar in many ways to alarm systems and as such use a cheap ass processor like a Z80 or a 6502.