Chinese Army Unit Is Seen as Tied to Hacking Against U.S.
Interesting article for the New York Times technology section:
On the outskirts of Shanghai, in a run-down neighborhood dominated by a 12-story white office tower, sits a People’s Liberation Army base for China’s growing corps of cyberwarriors.
The building off Datong Road, surrounded by restaurants, massage parlors and a wine importer, is the headquarters of P.L.A. Unit 61398. A growing body of digital forensic evidence — confirmed by American intelligence officials who say they have tapped into the activity of the army unit for years — leaves little doubt that an overwhelming percentage of the attacks on American corporations, organizations and government agencies originate in and around the white tower.
To read more from this article click here:
Thoughts on Shmoocon 2013 by Hans Bosch (@hans_bosch)
Bags are packed, lobby is clear, goodbyes are said and the knowledge transfer is complete. The curiosity level is so high I feel my blood flowing from the back of my neck down to my fingers. I haven’t stopped coding and checking my notes on all this new stuff I just learned. I’m a senior computer professional but tonight I feel like a kid with a new toy, the toy of learning something new. Years of formal training have kept me employed, but cons keep me young and excited about my profession. At Shmoocon I was alive again, curiously eager to learn something new.
My dear friend and colleague Kevin Figueroa (@KevinFigueroa) summed up his thoughts on the con by reminding me of the Panel discussion on Friday. It was the last talk of the day, but the first to ignite passion, of why I’m a con junkie. It left everyone present engaged on the simple topic of research. Kevin’s take on this is “The community needs to be diligent in sighting other contributions to ones work and grow”. Dave Marcus (@DaveMarcus) insisted, “What hackers do is not research”. His point is that hackers tend to reinvent the wheel and never grow the knowledge in the community. An academic approach to hacking research may never take hold but who is to say that we need such stringent measures. I find that hackers do apply research where they target specific problems with awesome effectiveness. Like the courses I took for my associate degree. Each class was intended for me to get a programming job, at the time in JCL and COBOL, yes COBOL!
As a kid I wanted to be a scientist, a rocket scientist at that. From the window in my dad’s apartment, I could see parts of the East river and Brooklyn. I imagine each rooftop with a spaceport where we could hop on a rocket and sail to the stars.
This year I sailed to the stars, not in a space ship but rather in the euphoric high I felt form being greeted by friends I only see a few times a year and the curiosity their talks inspire. To quote (rest in peace Brad http://www.bradthenurse.com/) aka Nurse “this is a family reunion with the family you like”. His words are so true; I was in need of a barcode and was content in chilling at yet another lobby con. Instead before all my change got sucked up in the parking meter I got a barcode. One, which Marcus graciously offered to buy, but I came prepared and purchased it at face value from another buddy I meet via another buddy. Gee what a great family. This is the kind of brotherhood I find endearing at these cons, especially Shmoocon.
The talks where well balanced from technical to patriotically inspiring, making me feel proud to be an American! So you must surmised that one of my favorite talks was Hardy’s “Hacking as an act of war” but I also liked “Paparazzi over IP” by Mende and Turbing, “OpenStack Security Brief” by Joyce and “Generalized Single Packet Authorization for Cloud Computing Environments” by Rash. Sighs I can go on and on, be sure that I will spend more time watching the talks I missed online when they become available.
I leave you with one final thought everyone I meet thinks I’m 10 to 20 years younger, they “ax” me how I do it? I tell them I Shmooz a lot!
ShmooCon 2013 Conference Summary
ShmooCon 2013 started this past Friday, February 15, 2013 at 2:30 pm EST with opening remarks from Bruce Potter (@gdead) and ended on Sunday February 17, 2013.
Although at a new venue this this year (Hyatt Regency Washington), the presentations were still of high quality with talks such as Generalized Single Packet Authorization for Cloud Computing Environments by Michael Rash. Michael discussed that even with the benefits of clouding computing, the recent Microsoft RDP vulnerability (CVE-2012-0002) still points to security issues in the cloud environment and presented techniques to generalize Single Packet Authorization (SPA). Other talks such as Malware Analysis: Collaboration, Automation & Training by Richard Harman and Crypto: You’re doing it wrong by Ron Bowes were also very popular and had many attendees continuing discussions about those topics in the halls.
Additionally, Hacking as an Act of War by G. Mark Hardy and Attacking SCADA Wireless Systems for Fun and Profit and Fixing by Atlas to name a few more interesting and very informative briefings were presented.
In fact, the only negative aspect associated with the conference was the party at the Ibiza Night Club. Through various conversations with, I heard stories ranging from having to wait up to 30 minutes to get in, being grouped by the club security, unprofessional staff and a slow open bar service (I’m not sure if I missed anything, too many stories to remember).
ShmooCon 2013 had many interesting events; one in particular that caught my attention was the “Train the Trainer”. This event provided tips, techniques and materials to technical instructors to help enhance their training program. In addition, traditional events such as Lockpick Village, Ghost in the Shellcode, FireTalks and Hack Fortress we also well received.
I had the opportunity to speak with some of the vendors such as Sondra from SecurityUniversity and Rapheal Mudge from CobaltStrike as well as the folks at Silent Circle about their products and services.
This year charities were the Electronic Frontier Foundation (http://eff.org); they are the leading civil liberties group defending your rights in the digital world and Hackers for Charity (http://ihackcharities.org), which provides hackers with job experience while leveraging their skills for charities that need those skills. These are some commendable charities with impactful missions, I ask you check them out.
I would like to thank Bruce (@gdead), Heidi (@heidishmoo), Chris (@ChrisJohnRiley) as well as the conference staff for a wonderful and well-organized event, and as always, we look forward to next year’s conference.
Please share your experiences with us by commenting below
About ShmooCon:
ShmooCon is an American hacker convention organized by The Shmoo Group. There are typically about 35 different talks and presentations, on a variety of subjects related to computer security and cyberculture.
ShmooCon 2013 Officially Starts Today
ShmooCon 2013 officially starts today, Friday, February 15, 2013 at 2:30 pm EST with opening remarks from the founder of The ShmooCon Group, Bruce Potter (@gdead). Other talks that are scheduled to follow today are WIPE THE DRIVE!!! – Techniques for Malware Persistence
By Mark Baggett and Jake Williams, as well as Bringing The Sexy Back To…Defense In Depth
By Martin Fisher. A full schedule of events can be access at their website located at:
http://www.shmoocon.org/schedule
The event is being held at:
Hyatt Regency Washington
400 New Jersey Avenue, NW
Washington, District of Columbia
United States 20001
Tel: 1-202-737-1234
Fax: 1-202-737-5773
Hotel Website
Google Maps
It is expected to be another well hosted security conference and plenty of valuable information by some of the leading security experts and hackers in the game.
If you are one of the unlucky ones that cannot make it, we have good news for you. The event will be streamed at the following links below and on the SecurityOrb.com site. Enjoy…
Build It: http://www.ustream.tv/channel/build-it-2013
Belay It: http://www.ustream.tv/channel/belay-it-2013
Bring It On: http://www.ustream.tv/channel/bring-it-2013
About ShmooCon:
ShmooCon is an American hacker convention organized by The Shmoo Group. There are typically about 35 different talks and presentations, on a variety of subjects related to computer security and cyberculture.
ShmooCon 2013 Security Conference Streaming Information
If you are one of the unlucky ones that cannot make it, we have good news for you. The event will be streaming at the following links below and on the SecurityOrb.com site. Enjoy…
Build It: http://www.ustream.tv/channel/build-it-2013
Belay It: http://www.ustream.tv/channel/belay-it-2013
Bring It On: http://www.ustream.tv/channel/bring-it-2013
