Table of Contents
Introduction
This was the second DEF CON I have ever attended. This year I met with a college friend and hung out with him during the day. Also this year, unlike last year, I actually attended more than one talk. We stayed in the same hotel, which was really nice because it was a short but hot walk across the street to the con.
Talks
Stalking the Wily Hacker … 40 years later
I went to this talk 15 minutes ahead of the start of the talk and they were already out of headphones. The goon said that they would put it on YouTube. I cannot wait to watch it.
I read his book multiple times in college. I would go to the cafe and get something to eat, a glass of Mountain Dew, and read the book on my phone.
They even mentioned the Rome Lab, which was down the road from the college. The book is named The Cuckoo’s Egg. If you pay for Spotify, they have an audio book where you can listen to as well.
In the 2600 chat, a member was able to get into the talk, and he said that “Cliff is quite the animated speaker”
Election Integrity and Technology
This talk was given by Matt Blaze. It was a very interesting talk. It did a great job of leaving politics out of it and focused on the technology and facts. Some of the more interesting points can be seen below.
Notes
- There is no legal way of redoing an election if fraud was found.
- There is no credible evidence that a vulnerability has actually been exploited in elections.
- Web voting is unwarranted Optimism. Very messy and could be abused.
- Some people have the idea that “if you bank on mobile, why can’t we vote on a smartphone. … Experts think this is dangerous and can be abused.
- One way to increase election integrity is to become a poll helper.
- Every aspect of the election is big and complex. Complex tech is inherently unreliable. CS ( computer scientists ) have worked on it.
- Not enough states use RLA ( risk-limiting audit ) but progress is improving.
Improv – Creator Event / Activity
While I don’t have much experience with social engineering, I do have experience with Improv.
There is a wonderful small local improv place near my house that I have taken classes and open night.
The whole idea of Improv is celebrating failure. I recommend going for an open night or taking classes. It is a lot of fun. I can definitely see how Improv can be used for social engineering. You want the target to keep talking, but you have to know when you are being suspicious, found out, or when to call it quits after getting the information you need.
Notes
- Perform OSINT and research to understand the target BEFORE attempting anything.
- Build the reality together. ( the “victim” & you )
- “no but…” -> harder
- “yes and … ” -> easier
- Let he “victim” vent.
- Active Listening… Given respect by paying attention.
- During the engagement “rock the boat”.
- Uninteresting is good, you need them more than they need you. Know when to stop and end the call.
- Relate to their emotions. – yes and their emotion… Validation their emotions. – Matchings Candence as well.
- De-escalate their emotion don’t agree with them .
- The person on the other end does not know you are collaboration … But they are apart of it.
Web3 Security: Hacks, Scams, and Exploits
This very interesting talk was given by Philip “AlepNull” Werlau and Kennashk DeSilva.
Notes
- North Korean hackers stole 1.5 billion dollars worth of crypto.
- Stole Session tokens. Injected JS into S3 bucket to steal money from a routine cold-to-hot transfer.
- Shortly after stealing the 1.5 billion of crypto, they removed the malicious JS they put on the S3 bucket.
- The project dev was the weak leak, had malware on their computer.
Villages
Payment Village
The payment village had a cool demonstration where they used special ink or some type of liquid. I did not write down the name of the ink, but once applied, it showed a bar code-like design in the area where you swipe.
I also listened to a talk about how a dev was battling fraudsters testing credit cards.
Call Center Village

This was another cool village. They had a telephone booth and a bunch of call center items like older types of phones. They also had technology that can clone your voice and say anything the operator wants.
First, they had me read a passage. Then the person demonstrating ran his program and had the program repeat the lyrics to Smash Mouth’s famous song “All Star”.
It was pretty cool and scary at the same time how realistic it sounded. It still sounded a bit robotic with a few words.

Blacks In Cyber Village

This was a cool village; they had free candy and games. I played some cornhole by myself. I even got holes in one a couple of times. The Cornhole board was really good-looking and custom-made. They also had a really cool CTF that I have not seen before.
There were many different challenges that you had to solve before the end of a certain song.
I picked a SQL injection challenge with a Snoop Dogg song. I was able to get a SQL error, but I could not get any farther by the time the song ended.

Malware Village
I saw on Twitter days before the conference that vx-underground.org was giving out free bracelets with the name vx-underground on it. I picked one up with some stickers.
Sadly, the bracelet was too small for my fat wrists. So I can’t wear it. I also stayed for two very interesting talks.
One was about how malware admins are using the blockchain to make it tougher for their C&C to get taken down. Also, they talked about malware that used Telegram for a C&C.
Physical Security Village
The physical Security Village did not disappoint this year! I was able to learn how to shimmy older car doors. They had an old door that you could practice with.
They had these mini doors where you could practice some of the techniques and the tools. I am planning on building some of my own to practice safely and legally. Sadly, I did not get any images of the mini doors.
Latch Slipping
This technique works great if they installed the door backwards. This method of door bypass could be used with a piece of plastic that it cut a certain way or a thin metal that slides the door latch that will open the door. More information can be obtained here.

Controlling Shopping Wheels with Sound

This one was very cool; they had different types of shopping cart wheel locks. These are used so that people can’t steal shopping carts. You visit a site on your phone that uses your phone’s speaker to unlock the cart wheel or even to lock it.
Under The Door Tool


I was able to use the Under the Door Tool. It can be used to put the thing under the door, grab the handle on the other side, and open the door by pulling. It is really tricky because you can’t really see where the hook is.
Jim Tool

Another cool thing I did was use a jim tool to put within the gap between the door frame and the door, and you push the edge bore, and you can open the door.
The person manning the booth said that a lot of times this works because whoever installed the door did so incorrectly. Which can be a common occurrence.
J Tool

Another cool tool I got to use was called the “j Tool”. It is an item that you can put in between the door and the door frame and try to turn the deadbolt.
You have to hook it and then use your fingers to spin it at the bottom, which twists the J tool and the bolt, which allows you to open the door.
At least for me, it was giving my fingers cramps. It’s pretty hard to get the metal point at the door bolt. But don’t fret! It can be done.

Bypassing EnterPhone

An enterphone are those devices that, if you live in an apartment and you want to buzz someone in, or it could be the device that you put a badge against that will open the gate to enter the complex.
This was very interesting; the guy said that almost every enterphone has a common lock that you could either pick or buy a key.
You can use the key to open the box, and then you take a certain wire and move it down, and it will short the connection, allowing you access to the complex.
Another fact that I found interesting was that first responders have a tool where they can connect to the device, which will allow them to bypass the lock and open the gate.
Voting Village
This village was pretty cool, I was able to mess with and touch older voter machines.

Food
Don Tortaco
After we got to Nevada, we were hungry and were trying to find a place to eat before we went to Walmart. You can’t shop on a hungry stomach.
We stopped at Don Tortaco; we had never been. I got a chicken quesadilla, smoothie, and a beverage. The food was great, and the service was great. You could tell that the food ingredients were fresh and that the quesadilla was homemade and not processed food. The smoothie was also great. It actually tasted like strawberries.
Food Truck Pizza

One of the days we had some downtime around noon and decided to get some food. The cafe was packed. So we went outside where there were two food trucks.
One was foreign food, and the other was homemade pizza. I chose to get a homemade pizza. They did not have drinks, so I went to the building and got an overpriced soda from a vending machine.
The soda was not cold, which at this point I did not care about because I was so hungry that I was shaking and my blood sugar felt low.
The pizza was amazing. It came in a box; I chose to have pepperoni. The wait was not that bad. After ordering, I went inside to go to the restroom and get a soda, and I returned, and my pizza was ready.
We decided to eat inside as there were no benches outside and it was crazy hot outside. Inside, all the tables or desks were filled, so we found empty chairs near a door and ate our food on the chair.
Toxic BBQ
The Toxic BBQ is a great time. But it is hot as heck in Nevada. The food was great, and the people who put on the event made sure that everyone had sunscreen and stayed hydrated.
A lot of different people brought different items, like beer, water, grapes, and chips. It is a great time to meet new people and hang out. I met other humans that were interested in the same topics.
This year I sat with an older man who gave great insights for jobs in the field. He said that he would hire someone with a lab or who does stuff in their free time rather than someone who does not do that.
Parties
KevOps Sellout Pool
This party was a lot of fun. Before going in, they checked my bag and had me show my ID. Once inside, I went to these really cool couches in the middle of the room. They had free tacos, which I ate two soft tacos with cheese and meat. They were really good.
This year at the party, they had a big board that contained a QR code that, once scanned, brings you to a site where you can enter a text that will be shown on the big board. They had some type of moderation so you could not post stuff that should not be posted.
It was cool; a lot of partners declared their love for their other partner on the board. It was also entertaining seeing what people wrote, and even funny at times.
Adventures
Penn & Teller
Every year we do something fun. Last year we went to the Pawn Stars Pawn shop, and I bought some silver.
This year we decided to go to Penn & Teller. It was a really good time. Before we went to see the show, we ate in the cafe of the Hotel.
I got a cheeseburger and the best onion rings ever! What was also cool was that the food places allowed people to put stickers on the wall. I loved seeing the stickers.
The show was great, very funny and amazing, with the different tricks that were done. We had awesome seats in the front of the house.
The place was very clean and nice. One of the people that I was with got chosen to participate in one trick. Before the show, I purchased a deck of cards and a 50th anniversary coin.
Conclusion
This year I focused more on talks rather than just the villages. Next year I want to go to red teaming villages, Adversary village, and Recon Villages.
I also want to try more of the Physical Security Village demos where you can actually perform the attacks in a safe, legal way.
I am also designing and want to build my own mini doors to practice different attacks on. I am going to either purchase an under-the-door tool or maybe just make one myself.
Join a couple of contests like the sticker-creating contest. I also want to watch the social engineering contest; hopefully next time they will iron out the bugs or just remove the AI part of the challenge.
Next year I also want to go to more parties, not just the pool party. I am also going to design and make more stickers in the year before the conference to give out.
Next year I also need to read the schedule better and more in advanced. I missed some really interesting sounding talks like Pickpocketing for Red Teamers: A hand-on Experience. I really hope they put that talk on YouTube.

Leave a Reply