DEFCON 20: Owning Bad Guys {And Mafia} with Javascript Botnets

Ғылым және технология

Conference delivered by Chema Alonso ( mypublicinbox.com/ChemaAlonso ) in Defcon 20 about How to own bad guys {and mafia} using Javascript Botnets created by a Rogue "Anonymous" Proxy Server. White Paper at: www.slideshare.net/chemai64/ow...

Пікірлер: 176

  • @IdoruFalls
    @IdoruFalls9 жыл бұрын

    Chema is great, very impressive that he can get through a 40 minute talk with pretty broken English and still remain not only perfectly coherent but very funny.

  • @MrSpiderman1321

    @MrSpiderman1321

    9 жыл бұрын

    his english is actually very good but he has such a strong accent

  • @BanAaron

    @BanAaron

    9 жыл бұрын

    Mr Wednesday Broken English? He speaks English more properly than most english people :P

  • @Kakerate2

    @Kakerate2

    9 жыл бұрын

    Aaron Barratt lol more properly

  • @GamerShock

    @GamerShock

    9 жыл бұрын

    Paul Ahrenholtz not only does he make a great point, he reinforces it. well done.

  • @Freakschwimmer

    @Freakschwimmer

    9 жыл бұрын

    +Mr Wednesday unfortunatiringtly his accent is extremly strong. Kinda makes listening to him quite tiring :/

  • @SomeInfo-ib3wz
    @SomeInfo-ib3wz9 жыл бұрын

    This guy is a legend, great talk. Equal parts comedy and information. And he's multilingual...respect.

  • @igrewold

    @igrewold

    7 жыл бұрын

    He is the real Mr. Robot ;D

  • @chrisdab-

    @chrisdab-

    4 жыл бұрын

    English is the only language needed,. what?

  • @shoegum7362
    @shoegum73627 жыл бұрын

    Came for the topic stayed for the dude

  • @konic40
    @konic407 жыл бұрын

    thumbs up for the guy that loves his country

  • @boo24998

    @boo24998

    7 жыл бұрын

    Another way of being patriotic

  • @boo24998

    @boo24998

    7 жыл бұрын

    I love that he still is willing to make fun of his country.

  • @knowmad1919

    @knowmad1919

    7 жыл бұрын

    He is not patriotic, just likes and show some things in his country.

  • @misterchief5378
    @misterchief53787 жыл бұрын

    chema is actually a legend in spain, he is so awesome.

  • @igrewold

    @igrewold

    7 жыл бұрын

    He is great and I like his free style and jokes in the presentation but I find it weird that he never thought of using virtualization (VMware, VirtualBox, Qemu..etc.) as a solution at the end!

  • @Albinorama

    @Albinorama

    7 жыл бұрын

    no he is not.

  • @dk0money
    @dk0money8 жыл бұрын

    I like this, it illustrates the fact that at the end of the day you are going have to trust the administrator of the proxy machine, be that a company or your trusted hacking buddy who sets it up.

  • @Hexecutable
    @Hexecutable9 жыл бұрын

    Wow this guy was amazing. Even though his english wasnt that clear he made it very easy to understand him. I hope to attend this event some time soon.

  • @quranalone5824

    @quranalone5824

    8 жыл бұрын

    +ultimash00ter5 It's hold in America. Near Las Vegas. It's called DefCon.

  • @yam2050

    @yam2050

    7 жыл бұрын

    ultimash00ter5 have you been there yet???

  • @yomocy
    @yomocy9 жыл бұрын

    fucking modern day inigo Montoya right here

  • 8 жыл бұрын

    This was... quite simple.

  • @arsaeterna4285
    @arsaeterna42856 жыл бұрын

    50% awesome presentation 50% awesome accent

  • @fred.flintstone4099
    @fred.flintstone40999 жыл бұрын

    In modern browsers with modern JavaScript you can do interesting things. Such as run code in the background in WebWorkers, and connect to a C&C with bidirectional communication using WebSockets. Then you can perform denial-of-service attacks using loops with Ajax calls or looping the loading of images. Your C&C could also push code over WebSockets to be evaluated on the client-side with eval(), before the evaluation it could be decrypted.

  • @boxbox6290

    @boxbox6290

    9 жыл бұрын

    Ill be bsrnybif u teach me n intro helder

  • @Elyx0

    @Elyx0

    9 жыл бұрын

    ***** Ajax might be less powerful indeed because of cross domain, even if a lot of ressources (ie:robots.txt & such) are still "ajaxable." (Cf the IE seclists.org/fulldisclosure/2015/Feb/0 )

  • @FuckitnFightit
    @FuckitnFightit8 жыл бұрын

    i want to e'stay in e'spain sometime. Looks e'beautiful.

  • @tho207

    @tho207

    8 жыл бұрын

    haha don't make fun of us, we don't have words that start with s it's kind of unnoticeable if nobody tells us the first time or we don't realize

  • @FuckitnFightit

    @FuckitnFightit

    8 жыл бұрын

    +TH it's all good brotha, I was just messing around.

  • @tho207

    @tho207

    8 жыл бұрын

    +LocChokingVMorningG I know I know, just commenting humorously ;)

  • @tho207

    @tho207

    4 жыл бұрын

    A C H my bad, I meant double closed consonants. and when we have we tend to relax them. consonants would become consonans. it's simply consonantes for us

  • @tho207

    @tho207

    4 жыл бұрын

    A C H yeah kinda the same. you can think of it as a more flexible version of the japanese pronunciation. obviously a trained spaniard would perfectly speak English, but there are almost no opportunities for that in the day to day life. yup, that's the magic of human languages and culture. it'd be interesting to see if a more complex language really correlates to anything valuable for the culture at issue.

  • @RiDankulous
    @RiDankulous9 жыл бұрын

    Entertaining! The humor helps a lot for technical presentations.

  • @dom252
    @dom2526 жыл бұрын

    I haven't seen that many, but this is my favourite Defcon talk so far :)

  • @TheTurlututuchapeaup
    @TheTurlututuchapeaup8 жыл бұрын

    Great video, injecting JS payload is a simple way to get over HTTPS, but nothing mentionned about the fact to add a Content-Security-Policy in response header from webapp (if CORS not required). It should prevent from this kind of JS payload.

  • @99devops63
    @99devops638 жыл бұрын

    Hacker who was hacking was hacked.. nice...

  • @shareb1t

    @shareb1t

    5 жыл бұрын

    And that guy was me lol

  • @michaellewis4750
    @michaellewis47507 жыл бұрын

    this guy is so cool. I imagine he's a fun guy to chill with

  • @mysticx0
    @mysticx07 жыл бұрын

    what a genuine guy. absolutely great talk!!

  • @TheFatlazyguy
    @TheFatlazyguy7 жыл бұрын

    Favorite defcon talk. Guy was hilarious and English wasn't even his first language.

  • @boo24998
    @boo249987 жыл бұрын

    I love this guy

  • @tzisorey
    @tzisorey8 жыл бұрын

    I wonder what results you'd have if you put a .JS file online, downloaded it again using various proxy services, and compared them to the original.

  • @coooooooooool1000

    @coooooooooool1000

    7 жыл бұрын

    the result would be that is slightly bigger

  • @SamJakob

    @SamJakob

    6 жыл бұрын

    Tzisorey Tigerwuf that's actually a cool hypothesis

  • @kevinflorenzdaus
    @kevinflorenzdaus9 жыл бұрын

    Your a good speaker! Awesome presentation man!

  • @spydergs07
    @spydergs077 жыл бұрын

    This is why if I ever need to connect to anonymously I use TOR and proxies. Also always runs on a live linux USB :) After you are down, shut down and boot back into the live USB and it's like a whole new clean system.

  • @mishevi3071
    @mishevi30719 жыл бұрын

    Congrat's !!..Great show...Thank you!!! Greetings from Macedonia!!!

  • @Prydestalker

    @Prydestalker

    9 жыл бұрын

    Prejak show ima Chema. :D

  • @SoftDatCLS
    @SoftDatCLS8 жыл бұрын

    Good Job !! Thanks for your video Conference Chema

  • @iii-ei5cv
    @iii-ei5cv8 жыл бұрын

    bro I love this!! quite hilarious!

  • @0one1zero
    @0one1zero10 жыл бұрын

    this guy is hilarious :D

  • @josemariarodriguez3226

    @josemariarodriguez3226

    9 жыл бұрын

    yeha, but ikd

  • @MichaelBerthelsen
    @MichaelBerthelsen7 жыл бұрын

    I love how he can't say Spain without putting the 'E' in front... =D

  • @gevanlappido1304
    @gevanlappido13044 жыл бұрын

    Hod did you zoom in on a windows machine that nicely??

  • @thejohnmcduffie
    @thejohnmcduffie9 жыл бұрын

    I'm a bit late, but so what? This was interesting. I was hooked from, "you only have to run faster than the bulls." While off topic, the topic was interesting also.

  • @007mrthomas
    @007mrthomas7 жыл бұрын

    great talk, great guy

  • @bcassol
    @bcassol10 жыл бұрын

    Awesome!

  • @GrantWill
    @GrantWill7 жыл бұрын

    They were using proxies and not vpns?

  • @Blxckmxtt3r
    @Blxckmxtt3r2 жыл бұрын

    maestro!

  • @SheikhAltijdGezeikhh
    @SheikhAltijdGezeikhh9 жыл бұрын

    I cried at 'linke-ding' x'D

  • @quranalone5824

    @quranalone5824

    8 жыл бұрын

    +SheikhAltijdGezeikhh LOL.

  • @TheJeorgen

    @TheJeorgen

    6 жыл бұрын

    Just when i red it he said it HAHAHA

  • @Sacre0493
    @Sacre049310 жыл бұрын

    Magic Alonso!!!

  • @TheCrystalon
    @TheCrystalon7 жыл бұрын

    After listening to this, I am reading all of the comments in his voice. I can't help it, I hear his voice in everything now. XD

  • @arpitrohela1596
    @arpitrohela15968 жыл бұрын

    this guy is legend......

  • @fanenthusiast3802
    @fanenthusiast38027 жыл бұрын

    Cool vid bro

  • @GAFO777
    @GAFO7777 жыл бұрын

    his jokes are just awesome hahah xD

  • @tehKap0w
    @tehKap0w8 жыл бұрын

    So fucking simple, too. Thanks Chema, for a great talk.

  • @dannyphehe
    @dannyphehe8 жыл бұрын

    Spain has good heroin.

  • @tecmedimagen

    @tecmedimagen

    7 жыл бұрын

    dannyphehe 😂😂

  • @Reth_Hard
    @Reth_Hard8 жыл бұрын

    Very nice talk! I always suspected anonymous proxy servers. You know, when it's too good to be true... Also, people tend to under-estimate the Javascript exploits's potential. Javascript is Evil! :D

  • @ismaelkababasmillah1690
    @ismaelkababasmillah16908 жыл бұрын

    I love his voice and he is slick

  • @undergroundcentral
    @undergroundcentral6 жыл бұрын

    Legend

  • @asderamen
    @asderamen7 жыл бұрын

    el chema se ha sacado la ciberpolla

  • @tarikahmed5795
    @tarikahmed57959 жыл бұрын

    So amusing.

  • @eprofessio
    @eprofessio3 жыл бұрын

    I had a dream I was showing someone a dvd player that used to run on java that I hacked into a mini pc.

  • @FranciscoSoteloWeb
    @FranciscoSoteloWeb10 жыл бұрын

    8:35 con los protagonistas de bricomanía llevando camisetas de foca juajuajua

  • @mattw2135
    @mattw21359 жыл бұрын

    what botnet was he using and what bots will work with this?

  • @svenhoek

    @svenhoek

    9 жыл бұрын

    Matt W If you had to ask, you need not know

  • @TerryTheTutor

    @TerryTheTutor

    9 жыл бұрын

    +Conky Jr And if you know, you need only ask.

  • @quranalone5824

    @quranalone5824

    8 жыл бұрын

    +Terry The Tutor Ask, Know.

  • @Infinity-wf3my
    @Infinity-wf3my8 жыл бұрын

    grate

  • @Carlomanization
    @Carlomanization10 жыл бұрын

    Eh, tío, pero cuelga el código!

  • @imshaunnurse
    @imshaunnurse5 жыл бұрын

    i know this was suggested to me because ive been watching def con but I also play a game called brown dust and its the tomatina even where they want you to spend money and sure enough.... boom he talks about tomatina

  • @conductive13
    @conductive1311 жыл бұрын

    I hope your crops are going well....

  • @herreroarriero
    @herreroarriero7 жыл бұрын

    Topicazos..

  • @sayamqazi
    @sayamqazi5 жыл бұрын

    It sucks to see that the ID cards of people getting scammed with UK job were from my country.

  • @reboureyn139
    @reboureyn1396 жыл бұрын

    he says cookie very funny. i love it. coo key

  • @pissfiss
    @pissfiss4 жыл бұрын

    Gansta

  • @theeyenzier8190
    @theeyenzier81903 жыл бұрын

    its not mr.robot its Señor robot

  • @reformCopyright
    @reformCopyright6 жыл бұрын

    Volkswagen probably can help you detect when your DNS is being tested.

  • @BusinessWolf1
    @BusinessWolf12 жыл бұрын

    Remember when that ceo guy said to hire lazy people? This is why.

  • @ericsbuds
    @ericsbuds8 жыл бұрын

    wow.. those Microsoft tiles... I thought that was a new thing LOL

  • @lakas1tos
    @lakas1tos11 жыл бұрын

    Eres un crack Chema, WE ARE SPANIARDS!!!!

  • @IMredesMMIX
    @IMredesMMIX11 жыл бұрын

    ahí ahí, fomentando el turismo para combatir la crisis xD

  • @MegaTroy12
    @MegaTroy128 жыл бұрын

    he is cool,want to visit spain,

  • @inwencja2009
    @inwencja20099 жыл бұрын

    Oh... I know Javascript! :3

  • @quranalone5824

    @quranalone5824

    8 жыл бұрын

    +Magdalena Bartosiewicz Lol.

  • @inwencja2009

    @inwencja2009

    8 жыл бұрын

    Old comment.

  • @quranalone5824

    @quranalone5824

    8 жыл бұрын

    LOL, even more now XD. What are you going got do with basic js skills XD. This swizzle is complex XD.

  • @inwencja2009

    @inwencja2009

    8 жыл бұрын

    I made a functional text editor in JavaScript.

  • @quranalone5824

    @quranalone5824

    8 жыл бұрын

    Magdalena Bartosiewicz Nice. How did you do that?

  • @SRFColonel
    @SRFColonel9 жыл бұрын

    Great talk, but seriously, anybody know the name of the girl at 18:40? It's for academic purposes.

  • @solux3324

    @solux3324

    8 жыл бұрын

    +Marcus Romul No, sorry we can not help your _academic_ purposes. ;)

  • @quranalone5824

    @quranalone5824

    8 жыл бұрын

    +Marcus Romul Lol you really sound like those creeps in the show.

  • @NatiiixLP

    @NatiiixLP

    8 жыл бұрын

    +Marcus Rommul, FAP = For Academic Purposes

  • @SamJakob

    @SamJakob

    6 жыл бұрын

    M Romul axionqueen 😉

  • @BlasterTheMaster
    @BlasterTheMaster7 жыл бұрын

    I wish I knew hacker language. This seems super interesting.

  • @skypeon1

    @skypeon1

    7 жыл бұрын

    Grantastic this is not hacker speech, more like programming basics used a little bit malicious, start from html, and other basic scripting languages, learn about proxyes and youll get it

  • @BlasterTheMaster

    @BlasterTheMaster

    7 жыл бұрын

    Thanks, I appreciate it

  • @hate2009

    @hate2009

    7 жыл бұрын

    Pionell Winters so if I learned computer programming , is this what hackers learn ?? I always wanted to know what background do the have??

  • @skypeon1

    @skypeon1

    7 жыл бұрын

    yes, hacking is mostly knowing programming and it's various languages and in that way you know the weaknesses of code that you can use in various ways. Learn programming, if you will - you will learn hacking somewhere down the line

  • @SamJakob

    @SamJakob

    6 жыл бұрын

    Grantastic Nono you misunderstood, he speaks Spanish

  • @kinglouie8554
    @kinglouie85547 жыл бұрын

    thats a funny guy

  • @jayl5628
    @jayl56288 жыл бұрын

    That's not Ibiza dude... it's "sao tome and principe"...

  • @semiruu

    @semiruu

    8 жыл бұрын

    Have you been to Ibiza? Probably not, otherwise you wouldnt have made that comment :p

  • @jayl5628

    @jayl5628

    8 жыл бұрын

    It turns out that I'm from Barcelona and I've been working in Ibiza MANY summers, and I know pretty well all the locations (calas, beaches, discos, etc). So... NO, that's not Ibiza. A simple reverse lookup of the image in images.google.com can confirm you the correct location.

  • @kyebrewer563

    @kyebrewer563

    7 жыл бұрын

    Yeah, It is listed on many sites as Ibiza, but it is clearly Thailand. Looks like Koh Phi Phi

  • @tRuStThEsCiEnCeBiGoT
    @tRuStThEsCiEnCeBiGoT5 жыл бұрын

    "No good, I've known too many Spaniards..."

  • @cmdrhighwarlord6304
    @cmdrhighwarlord63046 жыл бұрын

    Espain

  • @WakeMister
    @WakeMister6 жыл бұрын

    Young Clooney :D

  • @richcohen5936
    @richcohen59363 жыл бұрын

    LMAO he literally sounds like Brüno!!!

  • @prodKossi
    @prodKossi6 жыл бұрын

    Amazing talk, but ads every 10 minutes is annoying as hell..

  • @jameseverett4372

    @jameseverett4372

    4 жыл бұрын

    adblockplus.org/

  • @jesushimself00
    @jesushimself007 жыл бұрын

    /* FIXME: add subtitles

  • @ProNoobDev
    @ProNoobDev7 жыл бұрын

    LMAO ! respect

  • @bastianlv1653
    @bastianlv16535 жыл бұрын

    5:06 es very difficult sin internet

  • @davidgjam7600
    @davidgjam76006 жыл бұрын

    He looks like parrappa the rappa

  • @Zhak7
    @Zhak78 жыл бұрын

    11:10 XD

  • @kennethwhite9720
    @kennethwhite97208 жыл бұрын

    Because Spaniards.....

  • @quranalone5824

    @quranalone5824

    8 жыл бұрын

    +The Mad-Mapper You just created an infinite loop in PHP. lol.

  • @shareb1t
    @shareb1t5 жыл бұрын

    its was me and friend who hack the website back in years and watching this video 6 years later seeing this lmao

  • @Berberetxo
    @Berberetxo7 жыл бұрын

    La diapositiva de los de Bricomanía xD De verdad se pusieron vuestra camiseta o es fotomón? La referencia es cojonuda, cola blanca y tubillones..ez

  • @MrQuickPro
    @MrQuickPro5 жыл бұрын

    vpn's

  • @Zei33
    @Zei3310 жыл бұрын

    10000th :P

  • @Smart.Potato
    @Smart.Potato9 жыл бұрын

    MBP = Macbook Pro.

  • @quranalone5824

    @quranalone5824

    8 жыл бұрын

    +tejas_jj Or Media BOOZER Piew

  • @zxcxx
    @zxcxx11 жыл бұрын

    LMAO.. :p

  • @elguezj
    @elguezj7 жыл бұрын

    What should of gave away that the girl's dating profile was fake was that she was from Keller, Texas hahahahahaha

  • @beto154yetc5
    @beto154yetc52 жыл бұрын

    ajjajaja...

  • @aarenskov
    @aarenskov5 жыл бұрын

    he eentendido mejor tu ingles que el de un estadounidense nativo lol

  • @scottcombs3254
    @scottcombs32549 жыл бұрын

    If I have to watch this mexican cowboy ad one more time...

  • @boxbox6290

    @boxbox6290

    9 жыл бұрын

    Adblock. comnthnk me later with a pic of your wife

  • @nonameplsno8828
    @nonameplsno88287 жыл бұрын

    it sounds as if he has an acorn up his nose

  • @aequabit
    @aequabit8 жыл бұрын

    First thought: Micrososft Windows Tech Support

  • @hackinfo2488

    @hackinfo2488

    8 жыл бұрын

    you mean non-microsoft tech scammers...

  • @nescius2
    @nescius27 жыл бұрын

    atrocious pronunciation! still fun

  • @Secretforest100
    @Secretforest1008 жыл бұрын

    guy turned out to be a turkish

  • @semiruu

    @semiruu

    8 жыл бұрын

    he isnt, thats a spanish-english accent, also the way how he pronnounced Ibiza made it clear :p

  • @igrewold

    @igrewold

    7 жыл бұрын

    +SEMIRU interesting remark.

  • @jsmithnevinsky
    @jsmithnevinsky6 жыл бұрын

    Are his coding skills as broken as his language skills?

  • @alextwist8
    @alextwist87 жыл бұрын

    His accent really bothers me. I would rather hear this in spanish.

  • @chasgiver1258
    @chasgiver12588 жыл бұрын

    Suggest speaking more slowly, deeper, clearer and get English speaking training. I had to stop listening it hurt so much.

  • @FuckitnFightit
    @FuckitnFightit8 жыл бұрын

    i want to e'stay in e'spain sometime. Looks e'beautiful.

  • @ANGRYmuffin9000

    @ANGRYmuffin9000

    8 жыл бұрын

    I have never seen a Spaniard that at least tries to improve their accent

  • @tomb2623

    @tomb2623

    8 жыл бұрын

    +LocChokingVMorningG Much profit!

Келесі