CanSecWest 2009 Speakers and Dojo courses (Mar 14-20)

Dragos Ruiu <[email protected]> Sun, 15 Feb 2009 18:50:55 -0800
Newsgroups gmane.comp.security.linux
Organization All Terrain Ninjas
Message-ID <[email protected]>
=46inal Speaker Lineup for CanSecWest 2009 (March 18-20):
=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=
=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D

The Smart-Phones Nightmare - Sergio 'shadown' Alvarez

Getting into the SMRAM: SMM Reloaded - Lo=EDc Duflot

Network design for effective HTTP traffic filtering - Jeff "rfp" =20
=46orristal, Zscaler

Ninja Scanning - Fyodor, Insecure.org

On Approaches and Tools for Automated Vulnerability Analysis - Tanmay =20
Ganacharya & Nikola Livic & Abhishek Singh & Swapnil Bhalode & Scott =20
Lambert, Microsoft

Kicking It Old School: No DNS Packets Were Harmed In The Making Of =20
This Presentation - Dan Kaminski, IOActive

Binary Clone Wars: Software Whitelisting for Malware Prevention and =20
Coordinated Incident Response. - Shane Macaulay, Sean Comeau, and =20
Derek Callaway, Security Objectives

=2ENET Rootkits - Erez Metula

The Evolution of Microsoft's Exploit Mitigations - Matt Miller and Tim =20
Burrell, Microsoft

An overview of the state of videogame console security. - Victor Mu=F1oz

A Look at a Modern Mobile Security Model: Google's Android - Jon =20
Oberheide

Bug classes we have found in *BSD, OS X and Solaris kernels - Christer =20
Oberg and Neil Kettle, Convergent Network Solutions

Multiplatform Iphone/Android Shellcode, and other smart phone =20
insecurities - Alfredo Ortega and Nico Economou, Core

Platform-independent static binary code analysis using a meta-assembly =20
language - Sebastian Porst & Thomas "halvar" Dullien, zynamics

Persistent BIOS Infection - Anibal Sacco & Alfredo Ortega, Core

Decompiling Dalvik and other JavaFX - Marc Schoenefeld

Automated Real-time and Post Mortem Security Crash Analysis and =20
Categorization - Jason Shirk & Dave Weinstein, Microsoft

SSL, The Sequel: MD5 collisions and EV certificates - Alexander =20
Sotirov & Mike Zusman

Exploiting Unicode-enabled software - Chris Weber

Chinese Infosec & Malware Overview - Wei "icbm" Zhao, 365menshen

Hacking Macs for Fun and Profit - Dino Dai Zovi & Charlie Miller

=2E..and a variety of lightning talks...


Security Masters Dojo courses (March 14-17):
=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=
=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D

Metasploit: Asymmetric Warfare - H D Moore, BreakingPoint Systems

Advanced Honeypots - Thorsten Holz

IPv6 Network Security - Nico Fishbach & Guillaume Valadon, COLT & CNRS

Ultimate Web Hacking (One Day Edition) - Mike Andrews, Foundstone

TCP/IP Network Security In Depth - Andrea Barisani, inverse path

Effective Fuzzing using the Peach Fuzzing Platform - Michael =20
Eddington, Leviathan Security

Secure Java Programming and Auditing - Marc Schoenefeld

Practical 802.11 WiFi (In)Security - C=E9dric Blancher, EADS

Q/SSE Qualified/ Software Security Expert Certification Bootcamp - =20
Security University

Q/SA Qualified Security Analyst Penetration Tester - Security University

Advanced Linux Hardening - Andrea Barisani & Jay Beale, inverse path & =20
Intelguardians

Physical Security and Lock Technology - Deviant Ollam

The Exploit Laboratory - Advanced Edition - Saumil Shah, Net-Square

Mastering the Network with Scapy - Phillipe Biondi, EADS


Pwn2Own Contests:
=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D

There will be TWO Pwn2Own contests this year.
Generous cash prize(s) for exploits will be sponsored by Tipping Point,
and  a Sony VAIO P fresh from Japan and a new loaded Apple Macbook
will be amongst the prizes.

The targets this year will be mobile smart-phones, and browsers.

Mobile targets:
        iPhone
        Android
        Symbian
        RIM/BlackBerry
        Windows Mobile

Browser Targets:
        IE8
        FF3
        Safari
        Opera

The contest will like in previous years feature a progressively =20
expanding attack surface over the three day duration of the=20
conference. Final prizes and rules will be announced shortly.

Post-Conference Whistler Expedition:
=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=
=3D=3D=3D=3D

We have secured some rooms at good rates at the Westin in Whistler=20
and reserved a cluster of four, 3-5 bedroom, cabins for the weekend=20
after the conference. Contact [email protected] if you wish to be included=20
in the planning, final accommodation rates will be announced shortly.

Conference Hotel Block:
=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D

The room rates at the Sheraton Wall Center hotel where the conference
is being held have been reduced from $183 to $169, and still includes
a waived $15/day free internet access in the rate.


Tenth Anniversary Gala Event:
=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D

Since this is our tenth anniversary for the conference, we will=20
be having a party on Thursday night. Venue TBD. We're pretty=20
sure there will be a cake. No word yet on whether there will=20
be dancers inside it. ;-)


Day-Care Facilities will be available:
=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=
=3D=3D=3D=3D

As a nod to the shifting demographic of early gen. security
researchers we will be trying a new experiment this year=20
and we will be providing day-care facilities for those=20
traveling with kids. We will try to arrange some group
discounts with our provider once we know how many=20
kids and what ages and times will have to be=20
accommodated. If you are interested in this service
please send a note to [email protected] and let=20
her know ages and times.

We will try to get them started on exploit writing=20
courses for pre-schoolers :-). Does this mean=20
we are all grown up now?


It promises to be another fun conference again this=20
year. See you all there.

cheers,
=2D-dr

=2D-=20
World Security Pros. Cutting Edge Training, Tools, and Techniques
Vancouver, Canada =A0March 16-20 2009 =A0http://cansecwest.com
pgpkey http://dragos.com/ kyxpgp