Twitter Tweets about Blackhat as of September 2, 2008
September 02, 2008 | John Lessnau | Comments 0
AussieWebmaster: @mattcutts so if I were to do – and you know I won’t – blackhat stuff through chrome you won’t see it
devbasu: Open ports scare the guy who attended the blackhat conference.
danperry: First Q & A question: Porn, Blackhat, and Anonymous browsing. This is great!
rsseo: http://OnYourWeb.com New Products, 1000 Visitors a day! BlackHat Technique http://bit.ly/1ZKqqm
shaond: @ChrisGatford Sensei, how was Blackhat/Defcon?
sirclown82: Tom, one of the creators of MySpace, was a blackhat hacker. He was part of California’s largest ever computer crimes investigation.
raesene: Yay booked return flight for next years blackhat/defcon !!
identicaupdates: crmseo: http://5ver.com/7nlp New Products, 1000 Visitors a day! BlackHat Technique http://is.gd/2.. http://tinyurl.com/57lfkq
billbilano: Dan says he is smarter then you. #blackhat
rcheyne: #blackhat stop using MD5 for certs!
agent0×0: #blackhat dan says banks and financial sites are improving contrary to the university of Mich report. Old data in the report.
quine: I’m sense that anything I post to Twitter over the next 1.5 days will just get buried in the BlackHat tweets.
Viss: @rocknrollgeek never been to blackhat. Need to find a sugardaddy^H^H^H^H^Hcorporation to bankroll it for me
rcheyne: #blackhat browsers are making secure/insecure msg more difficult to notice.
agent0×0: #blackhat don’t mix secure and insecure in the browser.
rcheyne: #blackhat other 58% not necessarily signed by trusted CA.
ggee: out of 327k ssl certs scanned, over half were self signed #blackhat
agent0×0: #blackhat self signed certs big problem.
rcheyne: #blackhat 42% of SSL certs self-signed.
agent0×0: #blackhat let’s talk about SSL
chabuhi: ’scuse me … I meant @dakami #blackhat dns talk. Either way, I’m still more intrigued by the mystery guy who shit himself
vrsj: I know how SSL VPNs work so I’m not getting much value from Zusman’s talk so far. #blackhat.
agent0×0: #blackhat talking about evilgrade and issues with auto upgrade.
rcheyne: #blackhat There are many things game devs are trying to do. Filtering arbitrary garbage not necessarily one of them.
agent0×0: #blackhat gaming is the next overlooked security hole
rcheyne: #blackhat “Welcome to the 3rd age of hacking.” 1) servers, 2) browsers, 3) everything else.
Gillis57: Im glad the #dontgo discussion got ramped up, so that I am not eaten up with jealous at not being at #Blackhat. I can haz ticket to defcon?
agent0×0: #blackhat SIP not looking to good…
rcheyne: #blackhat “There’s always another way to get screwed by bad DNS.”
agent0×0: #blackhat Dan talking about why attack DNS.
ggee: redirect webservers like banks or google. mitm email just like th nsa #blackhat
agent0×0: #blackhat MX intercept: its not just for the NSA anymore!
ggee: dk on how to be evil when doing dns poisoning #blackhat
rcheyne: #blackhat “Why to attack DNS is a much more interesting question than how.”
agent0×0: #blackhat idle scanning oh?
chriseng: #blackhat transponder IDs can be reprogrammed OTA, how convenient
BlackHatUSA2008: Retweet @mediaphyter: following the @dakami DNS talk at #blackhat @ryanaraine will be posting his recap at http://blogs.zdnet.com/security/
agent0×0: #blackhat amit’s bug description.
jack_daniel: Google for inurl: sslvpn #blackhat
toomasr: monitor #blackhat
agent0×0: #blackhat what about the client? Oh?
agent0×0: #blackhat djb was right – not perfect
rcheyne: #blackhat this is essentially a brute force race condition kicked off by a polluted bailiwick referral.
camilux: Para seguir twitts de blackhat medio en tiempo real: http://is.gd/1hff
agent0×0: #blackhat many many ways to exploit this vuln. Dan going through a ton of info
billbilano: Some guy just ran out of the room crying with his pants around his feet. Whats going on here! #blackhat
rcheyne: #blackhat The ‘fix’ raises the odds of the race condition working considerably.
tkrpata: Following live tweets from Blackhat. It’s almost like being there… almost.
jjx: #BlackHat in Dans talk. No need to tweet since snout a dozen peeps around me are…
vrsj: The Zusman talk is lacking a bit because we can’t see the demo and what he’s doing on the screen. #blackhat
rcheyne: #blackhat Enumerating all the ways to trigger DNS lookups. Hint: many.
ggee: mail servers do a bunch of dns lookups when sending mail #blackhat
sigsegfalt: now we’re getting more to the point… #blackhat
chriseng: #blackhat oops fastrak forgot to set jtag fuse on old transponders
jack_daniel: DNS can be validated with SSL, but we can’t really trust SSL. CAs will occasionally sell bad people good certs #blackhat
agent0×0: #blackhat extending the attacks. Dan talking about bailiwicks now.
k8em0: #blackhat getting a load off my feet at the Microsoft booth.
chriseng: #blackhat validation code of fastrak transponder is just hex version of tag ID
rcheyne: #blackhat DNSRake -> named for lockpick rake. Works against BIND 8/9, MSDNS, nominum.
agent0×0: #blackhat DNSRake overview
chriseng: #blackhat overview of transponder modulation and packet framing used by title 21 spec
phy_bsdaemon_be: In Vegas and no ticket for BlackHat … that’s even worse than sitting at home
rcheyne: #blackhat Forgery resilience: time x ttl = security. A dare to the security industry.
agent0×0: #blackhat dan going over forgery resilience
Clear2Go: Listening to Dan Kaminsky’s DNS vulnerability announcement at blackhat. Palace 1 room is packed. No standing room.
Techdulla: Dan is giving a tutorial on basic dns workings…..shouldn’t everyone here understand this part already? #blackhat
al3x: Reading about what’s going on at Blackhat in near-realtime: http://tinyurl.com/56qwej
chiefmonkey: Lots of technical glitches at BlackHat this year. Weird. Mics fuzzing, presentations crashing… WTH?
chriseng: #blackhat In Nate Lawson’s talk on toll systems
KyleFlaherty: settling in to watch the tweets from #blackhat and probably help update our @breakingpoint feed if anything is of interest
rcheyne: #blackhat Giving the quick DNS overview.
sigsegfalt: trustwave shoutout at dan’s talk.
#blackhat
rcheyne: #blackhat 70% of Fortune 500 are patched & tested.
agent0×0: #blackhat 15% of fortune 500 sample not patched.
rcheyne: #blackhat badass world map showing patch uptake over time.
ggee: neat dns patching video by clarified networks #blackhat
agent0×0: #blackhat cool patching video being played of DNS servers being patched.
McGrewSecurity: (not at blackhat) it was possible to figure out what the vulnerability was by what kaminsky *wouldn’t* talk about vs. would
ggee: tons of people at dans dns talk #blackhat
agent0×0: #blackhat many others found the bug and emailed Dan.
sweetums: I wonder what @dakami is going to be talking about… I’m sitting in the front left of hacking toll systems talk. #blackhat
securitytwits: RT mediaphyter “For those not at #blackhat it appears that @rcheyne @agent0×0 @billbilano and @ebellis are live tweeting @dakami’s DNS talk”
agent0×0: #blackhat Dan has cookies!
securitytwits: RT @BreakingPoint: “looks like we have some live tweeting from DNS talk at #blackhat: @rcheyne, @agent0×0 and others. Hat tip @mediaphyter”
BreakingPoint: looks like we have some live tweeting from DNS talk at #blackhat: @rcheyne, @agent0×0 and I’m sure some others. Hat tip @mediaphyter
sigsegfalt: @billbilano i just made five bucks by selling some lap space #blackhat
mediaphyter: For those not at #blackhat it appears that @rcheyne @agent0×0 @billbilano and @ebellis are live tweeting @dakami’s DNS talk in about five.
security4all: Got home, catching up on Blackhat tweets as it seems to get started. Then rss feeds…. then some food. Life is all about priorities.
SecurityBarbie: #blackhat who is not in DNS now?
rcheyne: #blackhat lol. They just announced that speakers are not allowed to skip their sessions if no one shows up. That’s how full this talk is.
sigsegfalt: They should have just left the keynote space open for the dns talk. This room is neck-deep in geeks. #blackhat
ittoolbox: BlackHat 2008 LiveBlog: Day 1 http://tinyurl.com/5ahdxp
agent0×0: #blackhat wow. People sitting everywhere at Dan’s talk! They want people to sit in front.
SecurityBarbie: DNS talk craziness #blackhat http://twitpic.com/6r3d
billbilano: Oh no! Someone offered me sexual favors for my seat at the dan is the devil talk. #blackhat
billbilano: I think that i saw steven segal doing security for the dan hates the world talk. #blackhat
adaviel: at BlackHat, Las Vegas. palace 3
jack_daniel: Not even trying the DK talk, I’m staying here for the SSL VPN talk. #blackhat
rcheyne: #blackhat Damn. Dan’s talk is already packed. Get in here now or you’re standing.
I appreciate your many visits
to The Lessnau Lounge. You probably should subscribed to my RSS
feed. Thanks again for stopping by and see you soon!
If for some reason you don't want me to post your RSS feed excerpt with a link back to your post crediting your website just let me know and I would be happy to remove you from the Technorati feed I use.
Filed Under: Tweets

