<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>I Am Security &#187; defcon</title>
	<atom:link href="http://www.iamit.org/blog/tag/defcon/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.iamit.org/blog</link>
	<description>Security news and research</description>
	<lastBuildDate>Mon, 26 Jul 2010 09:20:36 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=abc</generator>
<cloud domain='www.iamit.org' port='80' path='/blog/?rsscloud=notify' registerProcedure='' protocol='http-post' />
		<item>
		<title>Upcoming Conference Schedule</title>
		<link>http://www.iamit.org/blog/2010/05/upcoming-conference-schedule/</link>
		<comments>http://www.iamit.org/blog/2010/05/upcoming-conference-schedule/#comments</comments>
		<pubDate>Wed, 05 May 2010 17:23:10 +0000</pubDate>
		<dc:creator>iamit</dc:creator>
				<category><![CDATA[Opinion]]></category>
		<category><![CDATA[blackhat]]></category>
		<category><![CDATA[conference]]></category>
		<category><![CDATA[defcon]]></category>
		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://www.iamit.org/blog/?p=447</guid>
		<description><![CDATA[I have been fortunate enough to be picked up by several CFP of great conferences, which basically gave me the opportunity to participate at conferences I wanted to go to anyway, as well as to present some of the research in the CyberCrime/CyberWar field. After BlackHat Europe (see related post), I will be speaking at: [...]


Related posts:<ol><li><a href='http://www.iamit.org/blog/2009/11/excaliburcon-summary-and-general-china-notes/' rel='bookmark' title='Permanent Link: ExcaliburCon summary and general China notes'>ExcaliburCon summary and general China notes</a></li>
<li><a href='http://www.iamit.org/blog/2010/06/cloud-security-alliance-conference-israel-cfp/' rel='bookmark' title='Permanent Link: Cloud Security Alliance Conference (Israel) &#8211; CFP'>Cloud Security Alliance Conference (Israel) &#8211; CFP</a></li>
<li><a href='http://www.iamit.org/blog/2010/01/cybercrime-cyberwarfare-and-2010/' rel='bookmark' title='Permanent Link: CyberCrime, CyberWarfare, and 2010'>CyberCrime, CyberWarfare, and 2010</a></li>
</ol>]]></description>
			<content:encoded><![CDATA[<p>I have been fortunate enough to be picked up by several CFP of great conferences, which basically gave me the opportunity to participate at conferences I wanted to go to anyway, as well as to present some of the research in the CyberCrime/CyberWar field.</p>
<p>After BlackHat Europe (see <a href="http://www.iamit.org/blog/2010/04/cybercrimewar-connecting-the-dots-blackhat-eu-2010/">related post</a>), I will be speaking at:</p>
<p><img class="alignnone" src="http://ph-neutral.darklab.org/images/ph_head.gif" alt="" width="436" height="71" /></p>
<p><a href="http://ph-neutral.darklab.org/talks.html">ph-neutral</a> &#8211; Basically the real deal&#8230; If you are FoFX (Friends of FX) expect to rub shoulders with some of the world&#8217;s best security experts</p>
<p><img class="size-medium wp-image-448 alignnone" title="AthCon" src="http://www.iamit.org/blog/wp-content/uploads/2010/05/AthCon-300x89.png" alt="" width="300" height="89" /></p>
<p><a href="http://www.athcon.org/">AthCon</a> &#8211; A new regional conference in Greece, close to home, sponsored by some great guys from encode, and a very interesting lineup of speakers.</p>
<p><img class="alignnone size-full wp-image-449" title="FIRST2010-Sunset-SPEAKER" src="http://www.iamit.org/blog/wp-content/uploads/2010/05/FIRST2010-Sunset-SPEAKER.gif" alt="" width="255" height="260" /></p>
<p><a href="http://conference.first.org/">FIRST Conference</a> &#8211; If you have ever dealt with incident handling, CSIRT, CERT, and alike, this is the conference to be at. A whole day workshop, and 5 full days packed with great talks in sunny Miami. Can&#8217;t go wrong&#8230;</p>
<p><img class="alignnone size-full wp-image-455" title="1" src="http://www.iamit.org/blog/wp-content/uploads/2010/05/1.jpg" alt="" width="128" height="128" /></p>
<p><a href="http://brucon.org/">BruCON</a> &#8211;  Brussel&#8217;s local security conference. Last year has been EPIC (so I&#8217;ve  heard from authoritative sources <img src='http://www.iamit.org/blog/wp-includes/images/smilies/icon_smile.gif' alt=':-)' class='wp-smiley' />  ) and this year is shaping up to  exceed the expectations!</p>
<p>These are the confirmed ones for now&#8230;</p>
<p>Also check out the following conferences which I plan to attend (i.e &#8211; are cool and have great content):</p>
<p>DefCon, BlackHat US, BSidesLV &#8211; you better know these by now&#8230;</p>
<p><a href="http://www.newcamelotcouncil.com/eng/index.asp">ExcaliburCon</a> &#8211; THE security conference in China. Held at WuXi (not far from Shanghai), and offers a great mixture of local (Chinese) hackers and international ones. Spoke there last year, if you are looking to expand to the Chinese market this is the conference to be at (and sponsor!).</p>


<p>Related posts:<ol><li><a href='http://www.iamit.org/blog/2009/11/excaliburcon-summary-and-general-china-notes/' rel='bookmark' title='Permanent Link: ExcaliburCon summary and general China notes'>ExcaliburCon summary and general China notes</a></li>
<li><a href='http://www.iamit.org/blog/2010/06/cloud-security-alliance-conference-israel-cfp/' rel='bookmark' title='Permanent Link: Cloud Security Alliance Conference (Israel) &#8211; CFP'>Cloud Security Alliance Conference (Israel) &#8211; CFP</a></li>
<li><a href='http://www.iamit.org/blog/2010/01/cybercrime-cyberwarfare-and-2010/' rel='bookmark' title='Permanent Link: CyberCrime, CyberWarfare, and 2010'>CyberCrime, CyberWarfare, and 2010</a></li>
</ol></p>]]></content:encoded>
			<wfw:commentRss>http://www.iamit.org/blog/2010/05/upcoming-conference-schedule/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>It&#8217;s all about the money</title>
		<link>http://www.iamit.org/blog/2010/03/its-all-about-the-money/</link>
		<comments>http://www.iamit.org/blog/2010/03/its-all-about-the-money/#comments</comments>
		<pubDate>Thu, 18 Mar 2010 10:00:47 +0000</pubDate>
		<dc:creator>iamit</dc:creator>
				<category><![CDATA[Opinion]]></category>
		<category><![CDATA[Security Research]]></category>
		<category><![CDATA[conference]]></category>
		<category><![CDATA[cybercrime]]></category>
		<category><![CDATA[cyberwarfare]]></category>
		<category><![CDATA[defcon]]></category>
		<category><![CDATA[eCrime]]></category>
		<category><![CDATA[research]]></category>
		<category><![CDATA[technology]]></category>

		<guid isPermaLink="false">http://www.iamit.org/blog/?p=417</guid>
		<description><![CDATA[Coverage of the latest developments in the ZeuS botnet software licensing, and fighting the botnet internet connectivity.


Related posts:<ol><li><a href='http://www.iamit.org/blog/2010/04/cybercrimewar-connecting-the-dots-blackhat-eu-2010/' rel='bookmark' title='Permanent Link: Cyber[Crime|War] &#8211; connecting the dots &#8211; BlackHat EU 2010'>Cyber[Crime|War] &#8211; connecting the dots &#8211; BlackHat EU 2010</a></li>
<li><a href='http://www.iamit.org/blog/2009/11/excaliburcon-summary-and-general-china-notes/' rel='bookmark' title='Permanent Link: ExcaliburCon summary and general China notes'>ExcaliburCon summary and general China notes</a></li>
<li><a href='http://www.iamit.org/blog/2010/03/new-post-on-fudsec-com-cyberfudfare/' rel='bookmark' title='Permanent Link: New post on fudsec.com &#8211; CyberFUDfare'>New post on fudsec.com &#8211; CyberFUDfare</a></li>
</ol>]]></description>
			<content:encoded><![CDATA[<p>In my recent coverage of CyberCrime and CyberWar, I have neglected my old &#8220;friends&#8221; at the criminal world and gave them a little less attention (at least on their consumer business). It&#8217;s time to take a look back and see what are they up to.</p>
<p>Well &#8211; it might seem as non-news for readers of this blog (or people who were in my presentations at <a href="http://www.blackhat.com/html/bh-europe-08/bh-eu-08-archives.html#Amit">BlackHat</a>, <a href="http://defcon.org/html/links/dc-archives/dc-17-archive.html#Amit">DefCon</a>, <a href="http://hackerhalted.com/Conference/Speakers/IftachIanAmit/tabid/114/Default.aspx">HackerHalted</a>, <a href="http://www.newcamelotcouncil.com/SpeakersEN.html">ExcaliburCon</a>, <a href="http://technet.microsoft.com/en-us/security/cc748656.aspx">BlueHat</a>, or in other venues), but a couple of interesting sound-bytes may catch your eye:</p>
<p><img class="  alignright" title="That's how $205M look like..." src="http://www.justice.gov/dea/photos/operations/205million_fig1.jpg" alt="" width="300" height="225" /></p>
<p>1. ZeuS (good ol&#8217;e friend, how I missed debugging thou) has implemented licensing schema. The schema enforces that the licensed software be only used on licensed machines. News? yes, kind&#8217;a. Remember Neosploit (another personal pet-peeves)? Then you must remember the licensing scheme there as well. Pretty close to what ZeuS just introduced. And they say that the world has stopped sharing. pffff. And you can quote me on that. As anyone who ever took more than a brief look at how these things operate, the only takeaway possible is simple: It&#8217;s all about the money (hence &#8211; license enforcement is key. Ask Microsoft <img src='http://www.iamit.org/blog/wp-includes/images/smilies/icon_smile.gif' alt=':-)' class='wp-smiley' />  )</p>
<p>2. Staying with ZeuS, there has been quite a lot of effort in the past few months to take down one of the main autonomous systems providing upstream for some of the biggest C&amp;C&#8217;s hosting ZeuS. You can read more about it <a href="http://blogs.zdnet.com/security/?p=5761">here</a>, and <a href="http://www.theregister.co.uk/2010/03/11/zeus_botnets_resurrected/">here</a>. Notable effort indeed, as TORYAK-AS has been on the hit list for ZeuS tracking researchers for a long time. Only thing is &#8211; there&#8217;s money here again. Which means that even taking down the entire AS won&#8217;t really take down the botnet as it relies on bulletproof hosting which means that there will ALWAYS be alternate routes leading to it. That&#8217;s how things work. Just like trying to fight trafficking and drug trade. As long as there is demand, there will be supply. You dry out one supplier, the economy will just pop out another one. It&#8217;s all about the money.</p>
<p>So, I&#8217;ll finish up with a couple of reassuring words. We are not done yet. We like fighting the technical battle (I&#8217;ll admit that I had my fun doing so, and still have fun when called to duty), but the real battle won&#8217;t be won in that playing field. Remember Al (Capone) &#8211; it didn&#8217;t take the DEA or FBI to take him down. It was the IRS&#8230;</p>


<p>Related posts:<ol><li><a href='http://www.iamit.org/blog/2010/04/cybercrimewar-connecting-the-dots-blackhat-eu-2010/' rel='bookmark' title='Permanent Link: Cyber[Crime|War] &#8211; connecting the dots &#8211; BlackHat EU 2010'>Cyber[Crime|War] &#8211; connecting the dots &#8211; BlackHat EU 2010</a></li>
<li><a href='http://www.iamit.org/blog/2009/11/excaliburcon-summary-and-general-china-notes/' rel='bookmark' title='Permanent Link: ExcaliburCon summary and general China notes'>ExcaliburCon summary and general China notes</a></li>
<li><a href='http://www.iamit.org/blog/2010/03/new-post-on-fudsec-com-cyberfudfare/' rel='bookmark' title='Permanent Link: New post on fudsec.com &#8211; CyberFUDfare'>New post on fudsec.com &#8211; CyberFUDfare</a></li>
</ol></p>]]></content:encoded>
			<wfw:commentRss>http://www.iamit.org/blog/2010/03/its-all-about-the-money/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>DefCon 17 talk video available!</title>
		<link>http://www.iamit.org/blog/2009/11/defcon-17-talk-video-available/</link>
		<comments>http://www.iamit.org/blog/2009/11/defcon-17-talk-video-available/#comments</comments>
		<pubDate>Sun, 15 Nov 2009 07:13:33 +0000</pubDate>
		<dc:creator>iamit</dc:creator>
				<category><![CDATA[Opinion]]></category>
		<category><![CDATA[Security Research]]></category>
		<category><![CDATA[conference]]></category>
		<category><![CDATA[defcon]]></category>
		<category><![CDATA[eCrime]]></category>
		<category><![CDATA[malweb]]></category>
		<category><![CDATA[predictions]]></category>
		<category><![CDATA[research]]></category>
		<category><![CDATA[technical]]></category>

		<guid isPermaLink="false">http://www.iamit.org/blog/?p=379</guid>
		<description><![CDATA[DefCon 17 talk video of my talk


Related posts:<ol><li><a href='http://www.iamit.org/blog/2010/03/its-all-about-the-money/' rel='bookmark' title='Permanent Link: It&#8217;s all about the money'>It&#8217;s all about the money</a></li>
<li><a href='http://www.iamit.org/blog/2007/08/post-blackhat-pre-defcon/' rel='bookmark' title='Permanent Link: Post BlackHat, pre DefCon'>Post BlackHat, pre DefCon</a></li>
<li><a href='http://www.iamit.org/blog/2010/01/cybercrime-cyberwarfare-and-2010/' rel='bookmark' title='Permanent Link: CyberCrime, CyberWarfare, and 2010'>CyberCrime, CyberWarfare, and 2010</a></li>
</ol>]]></description>
			<content:encoded><![CDATA[<p>For your viewing pleasure &#8211; if you happened to miss out on DefCon 17 earlier this year, the full video and slides of my talk &#8220;<a href="https://media.defcon.org/dc-17/video/DEFCON%2017%20Hacking%20Conference%20Presentation%20By%20Iftach%20Ian%20Amit%20-%20Down%20the%20Rabbit%20Hole%20Uncovering%20a%20Criminal%20Server%20-%20Video%20and%20Slides.m4v">Down the Rabbit Hole &#8211; uncovering a criminal server</a>&#8221; have been uploaded to the DefCon archive page.</p>
<p>The slides and audio are also available in my section on the DefCon17 archives: <a href="http://defcon.org/html/links/dc-archives/dc-17-archive.html#Amit">http://defcon.org/html/links/dc-archives/dc-17-archive.html#Amit</a></p>
<p>Have fun!</p>


<p>Related posts:<ol><li><a href='http://www.iamit.org/blog/2010/03/its-all-about-the-money/' rel='bookmark' title='Permanent Link: It&#8217;s all about the money'>It&#8217;s all about the money</a></li>
<li><a href='http://www.iamit.org/blog/2007/08/post-blackhat-pre-defcon/' rel='bookmark' title='Permanent Link: Post BlackHat, pre DefCon'>Post BlackHat, pre DefCon</a></li>
<li><a href='http://www.iamit.org/blog/2010/01/cybercrime-cyberwarfare-and-2010/' rel='bookmark' title='Permanent Link: CyberCrime, CyberWarfare, and 2010'>CyberCrime, CyberWarfare, and 2010</a></li>
</ol></p>]]></content:encoded>
			<wfw:commentRss>http://www.iamit.org/blog/2009/11/defcon-17-talk-video-available/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
	</channel>
</rss>
