DEFCON 20: Owning Bad Guys {And Mafia} with Javascript Botnets

  Рет қаралды 273,714

Jose Maria Alonso

Jose Maria Alonso

11 жыл бұрын

Conference delivered by Chema Alonso ( mypublicinbox.com/ChemaAlonso ) in Defcon 20 about How to own bad guys {and mafia} using Javascript Botnets created by a Rogue "Anonymous" Proxy Server. White Paper at: www.slideshare.net/chemai64/ow...

Пікірлер: 176
@IdoruFalls
@IdoruFalls 9 жыл бұрын
Chema is great, very impressive that he can get through a 40 minute talk with pretty broken English and still remain not only perfectly coherent but very funny.
@MrSpiderman1321
@MrSpiderman1321 9 жыл бұрын
his english is actually very good but he has such a strong accent
@BanAaron
@BanAaron 9 жыл бұрын
Mr Wednesday Broken English? He speaks English more properly than most english people :P
@Kakerate2
@Kakerate2 9 жыл бұрын
Aaron Barratt lol more properly
@GamerShock
@GamerShock 9 жыл бұрын
Paul Ahrenholtz not only does he make a great point, he reinforces it. well done.
@Freakschwimmer
@Freakschwimmer 8 жыл бұрын
+Mr Wednesday unfortunatiringtly his accent is extremly strong. Kinda makes listening to him quite tiring :/
@SomeInfo-ib3wz
@SomeInfo-ib3wz 9 жыл бұрын
This guy is a legend, great talk. Equal parts comedy and information. And he's multilingual...respect.
@igrewold
@igrewold 7 жыл бұрын
He is the real Mr. Robot ;D
@chrisdab-
@chrisdab- 3 жыл бұрын
English is the only language needed,. what?
@misterchief5378
@misterchief5378 7 жыл бұрын
chema is actually a legend in spain, he is so awesome.
@igrewold
@igrewold 7 жыл бұрын
He is great and I like his free style and jokes in the presentation but I find it weird that he never thought of using virtualization (VMware, VirtualBox, Qemu..etc.) as a solution at the end!
@Albinorama
@Albinorama 7 жыл бұрын
no he is not.
@konic40
@konic40 7 жыл бұрын
thumbs up for the guy that loves his country
@boo24998
@boo24998 7 жыл бұрын
Another way of being patriotic
@boo24998
@boo24998 7 жыл бұрын
I love that he still is willing to make fun of his country.
@knowmad1919
@knowmad1919 7 жыл бұрын
He is not patriotic, just likes and show some things in his country.
@shoegum7362
@shoegum7362 7 жыл бұрын
Came for the topic stayed for the dude
@Hexecutable
@Hexecutable 9 жыл бұрын
Wow this guy was amazing. Even though his english wasnt that clear he made it very easy to understand him. I hope to attend this event some time soon.
@quranalone5824
@quranalone5824 8 жыл бұрын
+ultimash00ter5 It's hold in America. Near Las Vegas. It's called DefCon.
@yam2050
@yam2050 7 жыл бұрын
ultimash00ter5 have you been there yet???
@dk0money
@dk0money 8 жыл бұрын
I like this, it illustrates the fact that at the end of the day you are going have to trust the administrator of the proxy machine, be that a company or your trusted hacking buddy who sets it up.
@yomocy
@yomocy 9 жыл бұрын
fucking modern day inigo Montoya right here
8 жыл бұрын
This was... quite simple.
@FuckitnFightit
@FuckitnFightit 8 жыл бұрын
i want to e'stay in e'spain sometime. Looks e'beautiful.
@tho207
@tho207 8 жыл бұрын
haha don't make fun of us, we don't have words that start with s it's kind of unnoticeable if nobody tells us the first time or we don't realize
@FuckitnFightit
@FuckitnFightit 8 жыл бұрын
+TH it's all good brotha, I was just messing around.
@tho207
@tho207 8 жыл бұрын
+LocChokingVMorningG I know I know, just commenting humorously ;)
@tho207
@tho207 4 жыл бұрын
A C H my bad, I meant double closed consonants. and when we have we tend to relax them. consonants would become consonans. it's simply consonantes for us
@tho207
@tho207 4 жыл бұрын
A C H yeah kinda the same. you can think of it as a more flexible version of the japanese pronunciation. obviously a trained spaniard would perfectly speak English, but there are almost no opportunities for that in the day to day life. yup, that's the magic of human languages and culture. it'd be interesting to see if a more complex language really correlates to anything valuable for the culture at issue.
@fred.flintstone4099
@fred.flintstone4099 9 жыл бұрын
In modern browsers with modern JavaScript you can do interesting things. Such as run code in the background in WebWorkers, and connect to a C&C with bidirectional communication using WebSockets. Then you can perform denial-of-service attacks using loops with Ajax calls or looping the loading of images. Your C&C could also push code over WebSockets to be evaluated on the client-side with eval(), before the evaluation it could be decrypted.
@boxbox6290
@boxbox6290 9 жыл бұрын
Ill be bsrnybif u teach me n intro helder
@Elyx0
@Elyx0 9 жыл бұрын
***** Ajax might be less powerful indeed because of cross domain, even if a lot of ressources (ie:robots.txt & such) are still "ajaxable." (Cf the IE seclists.org/fulldisclosure/2015/Feb/0 )
@arsaeterna4285
@arsaeterna4285 6 жыл бұрын
50% awesome presentation 50% awesome accent
@TheTurlututuchapeaup
@TheTurlututuchapeaup 8 жыл бұрын
Great video, injecting JS payload is a simple way to get over HTTPS, but nothing mentionned about the fact to add a Content-Security-Policy in response header from webapp (if CORS not required). It should prevent from this kind of JS payload.
@tzisorey
@tzisorey 8 жыл бұрын
I wonder what results you'd have if you put a .JS file online, downloaded it again using various proxy services, and compared them to the original.
@coooooooooool1000
@coooooooooool1000 7 жыл бұрын
the result would be that is slightly bigger
@SamJakob
@SamJakob 6 жыл бұрын
Tzisorey Tigerwuf that's actually a cool hypothesis
@michaellewis4750
@michaellewis4750 7 жыл бұрын
this guy is so cool. I imagine he's a fun guy to chill with
@dom252
@dom252 6 жыл бұрын
I haven't seen that many, but this is my favourite Defcon talk so far :)
@RiDankulous
@RiDankulous 9 жыл бұрын
Entertaining! The humor helps a lot for technical presentations.
@TheFatlazyguy
@TheFatlazyguy 7 жыл бұрын
Favorite defcon talk. Guy was hilarious and English wasn't even his first language.
@mysticx0
@mysticx0 7 жыл бұрын
what a genuine guy. absolutely great talk!!
@spydergs07
@spydergs07 7 жыл бұрын
This is why if I ever need to connect to anonymously I use TOR and proxies. Also always runs on a live linux USB :) After you are down, shut down and boot back into the live USB and it's like a whole new clean system.
@99devops63
@99devops63 7 жыл бұрын
Hacker who was hacking was hacked.. nice...
@shareb1t
@shareb1t 5 жыл бұрын
And that guy was me lol
@boo24998
@boo24998 7 жыл бұрын
I love this guy
@kevinflorenzdaus
@kevinflorenzdaus 9 жыл бұрын
Your a good speaker! Awesome presentation man!
@mishevi3071
@mishevi3071 9 жыл бұрын
Congrat's !!..Great show...Thank you!!! Greetings from Macedonia!!!
@Prydestalker
@Prydestalker 9 жыл бұрын
Prejak show ima Chema. :D
@gevanlappido1304
@gevanlappido1304 4 жыл бұрын
Hod did you zoom in on a windows machine that nicely??
@SoftDatCLS
@SoftDatCLS 7 жыл бұрын
Good Job !! Thanks for your video Conference Chema
@thejohnmcduffie
@thejohnmcduffie 9 жыл бұрын
I'm a bit late, but so what? This was interesting. I was hooked from, "you only have to run faster than the bulls." While off topic, the topic was interesting also.
@iii-ei5cv
@iii-ei5cv 8 жыл бұрын
bro I love this!! quite hilarious!
@0one1zero
@0one1zero 10 жыл бұрын
this guy is hilarious :D
@josemariarodriguez3226
@josemariarodriguez3226 9 жыл бұрын
yeha, but ikd
@MichaelBerthelsen
@MichaelBerthelsen 7 жыл бұрын
I love how he can't say Spain without putting the 'E' in front... =D
@GrantWill
@GrantWill 7 жыл бұрын
They were using proxies and not vpns?
@TheCrystalon
@TheCrystalon 7 жыл бұрын
After listening to this, I am reading all of the comments in his voice. I can't help it, I hear his voice in everything now. XD
@007mrthomas
@007mrthomas 7 жыл бұрын
great talk, great guy
@SheikhAltijdGezeikhh
@SheikhAltijdGezeikhh 9 жыл бұрын
I cried at 'linke-ding' x'D
@quranalone5824
@quranalone5824 8 жыл бұрын
+SheikhAltijdGezeikhh LOL.
@TheJeorgen
@TheJeorgen 6 жыл бұрын
Just when i red it he said it HAHAHA
@Blxckmxtt3r
@Blxckmxtt3r 2 жыл бұрын
maestro!
@Reth_Hard
@Reth_Hard 8 жыл бұрын
Very nice talk! I always suspected anonymous proxy servers. You know, when it's too good to be true... Also, people tend to under-estimate the Javascript exploits's potential. Javascript is Evil! :D
@Sacre0493
@Sacre0493 10 жыл бұрын
Magic Alonso!!!
@tehKap0w
@tehKap0w 8 жыл бұрын
So fucking simple, too. Thanks Chema, for a great talk.
@bcassol
@bcassol 9 жыл бұрын
Awesome!
@GAFO777
@GAFO777 7 жыл бұрын
his jokes are just awesome hahah xD
@fanenthusiast3802
@fanenthusiast3802 7 жыл бұрын
Cool vid bro
@arpitrohela1596
@arpitrohela1596 8 жыл бұрын
this guy is legend......
@ismaelkababasmillah1690
@ismaelkababasmillah1690 8 жыл бұрын
I love his voice and he is slick
@dannyphehe
@dannyphehe 8 жыл бұрын
Spain has good heroin.
@tecmedimagen
@tecmedimagen 7 жыл бұрын
dannyphehe 😂😂
@FranciscoSoteloWeb
@FranciscoSoteloWeb 10 жыл бұрын
8:35 con los protagonistas de bricomanía llevando camisetas de foca juajuajua
@Carlomanization
@Carlomanization 10 жыл бұрын
Eh, tío, pero cuelga el código!
@asderamen
@asderamen 7 жыл бұрын
el chema se ha sacado la ciberpolla
@imshaunnurse
@imshaunnurse 5 жыл бұрын
i know this was suggested to me because ive been watching def con but I also play a game called brown dust and its the tomatina even where they want you to spend money and sure enough.... boom he talks about tomatina
@undergroundcentral
@undergroundcentral 6 жыл бұрын
Legend
@mattw2135
@mattw2135 9 жыл бұрын
what botnet was he using and what bots will work with this?
@svenhoek
@svenhoek 9 жыл бұрын
Matt W If you had to ask, you need not know
@TerryTheTutor
@TerryTheTutor 9 жыл бұрын
+Conky Jr And if you know, you need only ask.
@quranalone5824
@quranalone5824 8 жыл бұрын
+Terry The Tutor Ask, Know.
@tarikahmed5795
@tarikahmed5795 9 жыл бұрын
So amusing.
@eprofessio
@eprofessio 3 жыл бұрын
I had a dream I was showing someone a dvd player that used to run on java that I hacked into a mini pc.
@conductive13
@conductive13 11 жыл бұрын
I hope your crops are going well....
@sayamqazi
@sayamqazi 5 жыл бұрын
It sucks to see that the ID cards of people getting scammed with UK job were from my country.
@ericsbuds
@ericsbuds 8 жыл бұрын
wow.. those Microsoft tiles... I thought that was a new thing LOL
@reboureyn139
@reboureyn139 6 жыл бұрын
he says cookie very funny. i love it. coo key
@reformCopyright
@reformCopyright 6 жыл бұрын
Volkswagen probably can help you detect when your DNS is being tested.
@Infinity-wf3my
@Infinity-wf3my 8 жыл бұрын
grate
@herreroarriero
@herreroarriero 7 жыл бұрын
Topicazos..
@theeyenzier8190
@theeyenzier8190 3 жыл бұрын
its not mr.robot its Señor robot
@SRFColonel
@SRFColonel 8 жыл бұрын
Great talk, but seriously, anybody know the name of the girl at 18:40? It's for academic purposes.
@solux3324
@solux3324 8 жыл бұрын
+Marcus Romul No, sorry we can not help your _academic_ purposes. ;)
@quranalone5824
@quranalone5824 8 жыл бұрын
+Marcus Romul Lol you really sound like those creeps in the show.
@NatiiixLP
@NatiiixLP 8 жыл бұрын
+Marcus Rommul, FAP = For Academic Purposes
@SamJakob
@SamJakob 6 жыл бұрын
M Romul axionqueen 😉
@MegaTroy12
@MegaTroy12 8 жыл бұрын
he is cool,want to visit spain,
@IMredesMMIX
@IMredesMMIX 11 жыл бұрын
ahí ahí, fomentando el turismo para combatir la crisis xD
@pissfiss
@pissfiss 4 жыл бұрын
Gansta
@BlasterTheMaster
@BlasterTheMaster 7 жыл бұрын
I wish I knew hacker language. This seems super interesting.
@skypeon1
@skypeon1 7 жыл бұрын
Grantastic this is not hacker speech, more like programming basics used a little bit malicious, start from html, and other basic scripting languages, learn about proxyes and youll get it
@BlasterTheMaster
@BlasterTheMaster 7 жыл бұрын
Thanks, I appreciate it
@hate2009
@hate2009 7 жыл бұрын
Pionell Winters so if I learned computer programming , is this what hackers learn ?? I always wanted to know what background do the have??
@skypeon1
@skypeon1 7 жыл бұрын
yes, hacking is mostly knowing programming and it's various languages and in that way you know the weaknesses of code that you can use in various ways. Learn programming, if you will - you will learn hacking somewhere down the line
@SamJakob
@SamJakob 6 жыл бұрын
Grantastic Nono you misunderstood, he speaks Spanish
@bastianlv1653
@bastianlv1653 4 жыл бұрын
5:06 es very difficult sin internet
@tRuStThEsCiEnCeBiGoT
@tRuStThEsCiEnCeBiGoT 5 жыл бұрын
"No good, I've known too many Spaniards..."
@Berberetxo
@Berberetxo 7 жыл бұрын
La diapositiva de los de Bricomanía xD De verdad se pusieron vuestra camiseta o es fotomón? La referencia es cojonuda, cola blanca y tubillones..ez
@inwencja2009
@inwencja2009 8 жыл бұрын
Oh... I know Javascript! :3
@quranalone5824
@quranalone5824 8 жыл бұрын
+Magdalena Bartosiewicz Lol.
@inwencja2009
@inwencja2009 8 жыл бұрын
Old comment.
@quranalone5824
@quranalone5824 8 жыл бұрын
LOL, even more now XD. What are you going got do with basic js skills XD. This swizzle is complex XD.
@inwencja2009
@inwencja2009 8 жыл бұрын
I made a functional text editor in JavaScript.
@quranalone5824
@quranalone5824 8 жыл бұрын
Magdalena Bartosiewicz Nice. How did you do that?
@BusinessWolf1
@BusinessWolf1 2 жыл бұрын
Remember when that ceo guy said to hire lazy people? This is why.
@davidgjam7600
@davidgjam7600 6 жыл бұрын
He looks like parrappa the rappa
@richcohen5936
@richcohen5936 3 жыл бұрын
LMAO he literally sounds like Brüno!!!
@jesushimself00
@jesushimself00 7 жыл бұрын
/* FIXME: add subtitles
@cmdrhighwarlord6304
@cmdrhighwarlord6304 6 жыл бұрын
Espain
@jayl5628
@jayl5628 8 жыл бұрын
That's not Ibiza dude... it's "sao tome and principe"...
@semiruu
@semiruu 8 жыл бұрын
Have you been to Ibiza? Probably not, otherwise you wouldnt have made that comment :p
@jayl5628
@jayl5628 8 жыл бұрын
It turns out that I'm from Barcelona and I've been working in Ibiza MANY summers, and I know pretty well all the locations (calas, beaches, discos, etc). So... NO, that's not Ibiza. A simple reverse lookup of the image in images.google.com can confirm you the correct location.
@kyebrewer563
@kyebrewer563 7 жыл бұрын
Yeah, It is listed on many sites as Ibiza, but it is clearly Thailand. Looks like Koh Phi Phi
@lakas1tos
@lakas1tos 11 жыл бұрын
Eres un crack Chema, WE ARE SPANIARDS!!!!
@WakeMister
@WakeMister 6 жыл бұрын
Young Clooney :D
@shareb1t
@shareb1t 5 жыл бұрын
its was me and friend who hack the website back in years and watching this video 6 years later seeing this lmao
@kinglouie8554
@kinglouie8554 7 жыл бұрын
thats a funny guy
@ProNoobDev
@ProNoobDev 7 жыл бұрын
LMAO ! respect
@elguezj
@elguezj 7 жыл бұрын
What should of gave away that the girl's dating profile was fake was that she was from Keller, Texas hahahahahaha
@Zhak7
@Zhak7 8 жыл бұрын
11:10 XD
@prodKossi
@prodKossi 6 жыл бұрын
Amazing talk, but ads every 10 minutes is annoying as hell..
@jameseverett4372
@jameseverett4372 4 жыл бұрын
adblockplus.org/
@MrQuickPro
@MrQuickPro 5 жыл бұрын
vpn's
@kennethwhite9720
@kennethwhite9720 8 жыл бұрын
Because Spaniards.....
@quranalone5824
@quranalone5824 8 жыл бұрын
+The Mad-Mapper You just created an infinite loop in PHP. lol.
@scottcombs3254
@scottcombs3254 9 жыл бұрын
If I have to watch this mexican cowboy ad one more time...
@boxbox6290
@boxbox6290 9 жыл бұрын
Adblock. comnthnk me later with a pic of your wife
@Zei33
@Zei33 9 жыл бұрын
10000th :P
@aarenskov
@aarenskov 5 жыл бұрын
he eentendido mejor tu ingles que el de un estadounidense nativo lol
@Smart.Potato
@Smart.Potato 8 жыл бұрын
MBP = Macbook Pro.
@quranalone5824
@quranalone5824 8 жыл бұрын
+tejas_jj Or Media BOOZER Piew
@zxcxx
@zxcxx 11 жыл бұрын
LMAO.. :p
@beto154yetc5
@beto154yetc5 2 жыл бұрын
ajjajaja...
@nonameplsno8828
@nonameplsno8828 7 жыл бұрын
it sounds as if he has an acorn up his nose
@aequabit
@aequabit 8 жыл бұрын
First thought: Micrososft Windows Tech Support
@hackinfo2488
@hackinfo2488 8 жыл бұрын
you mean non-microsoft tech scammers...
@Secretforest100
@Secretforest100 8 жыл бұрын
guy turned out to be a turkish
@semiruu
@semiruu 8 жыл бұрын
he isnt, thats a spanish-english accent, also the way how he pronnounced Ibiza made it clear :p
@igrewold
@igrewold 7 жыл бұрын
+SEMIRU interesting remark.
@nescius2
@nescius2 7 жыл бұрын
atrocious pronunciation! still fun
@jsmithnevinsky
@jsmithnevinsky 6 жыл бұрын
Are his coding skills as broken as his language skills?
@alextwist8
@alextwist8 7 жыл бұрын
His accent really bothers me. I would rather hear this in spanish.
@chasgiver1258
@chasgiver1258 8 жыл бұрын
Suggest speaking more slowly, deeper, clearer and get English speaking training. I had to stop listening it hurt so much.
@FuckitnFightit
@FuckitnFightit 8 жыл бұрын
i want to e'stay in e'spain sometime. Looks e'beautiful.
@ANGRYmuffin9000
@ANGRYmuffin9000 8 жыл бұрын
I have never seen a Spaniard that at least tries to improve their accent
@tomb2623
@tomb2623 8 жыл бұрын
+LocChokingVMorningG Much profit!
Defcon 21 - Forensic Fails - Shift + Delete Won't Help You Here
47:10
HackersOnBoard
Рет қаралды 636 М.
DEFCON 17: That Awesome Time I Was Sued For Two Billion Dollars
31:28
Christiaan008
Рет қаралды 1,6 МЛН
Cat Corn?! 🙀 #cat #cute #catlover
00:54
Stocat
Рет қаралды 16 МЛН
УГАДАЙ ГДЕ ПРАВИЛЬНЫЙ ЦВЕТ?😱
00:14
МЯТНАЯ ФАНТА
Рет қаралды 3,6 МЛН
마시멜로우로 체감되는 요즘 물가
00:20
진영민yeongmin
Рет қаралды 32 МЛН
SEC-T 2012: Owning bad guys {and Mafia} with JavaScript botnets
59:58
Jose Maria Alonso
Рет қаралды 1,7 М.
Defcon 21 - The Secret Life of SIM Cards
42:36
HackersOnBoard
Рет қаралды 695 М.
DEFCON 19: The Art of Trolling (w speaker)
41:32
Christiaan008
Рет қаралды 527 М.
DEFCON 16: Toying with Barcodes
44:26
Christiaan008
Рет қаралды 370 М.
Defcon 21 - Social Engineering: The Gentleman Thief
41:55
HackersOnBoard
Рет қаралды 370 М.
Лазер против камеры смартфона
1:01
NEWTONLABS
Рет қаралды 525 М.
Сколько реально стоит ПК Величайшего?
0:37
Xiaomi SU-7 Max 2024 - Самый быстрый мобильник
32:11
Клубный сервис
Рет қаралды 327 М.
Новые iPhone 16 и 16 Pro Max
0:42
Romancev768
Рет қаралды 106 М.
АЙФОН 20 С ФУНКЦИЕЙ ВИДЕНИЯ ОГНЯ
0:59
КиноХост
Рет қаралды 1,1 МЛН
iPhone, Galaxy или Pixel? 😎
0:16
serg1us
Рет қаралды 1,1 МЛН