Day 2 • July 28, 2005 |
08:00 - 09:00 |
Registration and Continental Breakfast: Fourth Floor Palace Tower Promenade |

Location & Times |
Application Security |
Computer Forensics & Log Analysis
Privacy & Anonymity
Zero Day Defense
Turbo Talks
Roman Ballroom
Third Floor
Palace Salon II
Fourth Floor
Palace Salon III
Fourth Floor
Palace Salon I
Fourth Floor
Emperor's Ballroom
Fourth Floor
09:00 - 09:50 |
The Art of File Format Fuzzing
Michael Sutton & Adam Greene
GEN III Honeynets: The birth of roo
Allen Harper and Edward Balas
Building Robust Backdoors In Secret Symmetric Ciphers
Adam L. Young
Stopping Injection Attacks with Computational Theory
Robert J. Hansen & Meredith L. Patterson
BlackHat Standup: “Yea I’m a Hacker…”
James C. Foster
09:00 - 09:20 |
Shakespearean Shellcode
Darrin Barrall
09:30 - 09:50
09:50 - 10:00 |
Break |
10:00 - 11:00 |
CaPerl: Running Hostile Code Safely
Ben Laurie
The Defense Cyber Crime Center
Jim Christy
The Unveiling of My Next Big Project
Philip R. Zimmermann
Rogue Squadron: Evil Twins, 802.11intel, Radical RADIUS, and Wireless Weaponry for Windows
Beetle and Bruce Potter
Using Causal Analysis to Establish Meaningful Connections between Anomalous Behaviors in a Networking Environment
Ken Hines
10:00 - 10:20
Rapid Threat Modeling
Akshay Aggarwal
10:30 - 10:50
11:00 - 11:15 |
Coffee Service: Fourth Floor Palace Tower Promenade |

11:15 - 12:30 |
The Art of SIP fuzzing and Vulnerabilities Found in VoIP
Ejovi Nuwere & Mikko Varpiola
Performing Effective Incident Response
Kevin Mandia
Google Hacking for Penetration Testers
Johnny Long
Checking Array Bound Violation Using Segmentation Hardware
Tzi-cker Chiueh
Owning the C-suite: Corporate Warfare as a Social Engineering Problem
Shawn Moyer
11:15 - 11:35
A Dirty BlackMail DoS Story
Renaud Bidou
11:45 - 12:05
SPA: Single Packet Authorization
MadHat Unspecific & Simple Nomad
12:15 - 12:35
12:30 - 13:45 |
Lunch: Pavilion at Caesars
sponsored by
Book Signing with J0hnny Long and his newly released book "Google Hacking for Penetration Testers"
13:45 - 15:00 |
NX: How Well Does It Say NO to Attacker’s eXecution Attempts?
David Maynor
Catch Me If You Can: Exploiting Encase, Microsoft, Computer Associates, and the rest of the bunch…
James C. Foster & Vincent T. Liu
The Future of Personal Information
Joseph Ansanelli, Richard Baich, Adam Shostack, Paul Proctor
A New Hybrid Approach For Infrastructure Discovery, Monitoring and Control
Ofir Arkin
Toolkits: All-in-One Approach to Security
Kevin Cardwell
13:45 - 14:05
Injection Flaws: Stop Validating Your Input
Mike Pomraning
14:15 - 14:35
Shatter-proofing Windows
Tyler Close
14:45 - 15:05
15:00 - 15:15 |
Break |
15:15 - 16:30 |
Advanced SQL Injection in Oracle Databases
Esteban Martínez Fayó
Beyond Ethereal: Crafting A Tivo for Security Datastreams
Greg Conti
The National ID Debate
David Mortman, Dennis Bailey, Jim Harper, Rhonda MacLean
Ozone HIPS: Unbreakable Windows
Eugene Tsyrklevich
Building Self-Defending Web Applications: Secrets of Session Hacking and Protecting Software Sessions
Arian J. Evans & Daniel Thompson
15:15 - 15:35
Demystifying MS SQL Server & Oracle Database Server Security
Cesar Cerrudo
15:45 - 16:05
Advance SQL Injection Detection by Join Force of Database Auditing and Anomaly Intrusion Detection
Yuan Fan
16:15 - 16:35
16:30 - 16:45 |
Coffee Service: Fourth Floor Palace Tower Promenade |

Book Signing with Dennis Bailey and his book "The Open Society Paradox: Why The 21st Century Calls For More OpennessNot Less"
16:45 - 18:00 |
Circumvent Oracle’s Database Encryption and Reverse Engineering of Oracle Key Management Algorithms
Alexander Kornbrust
The Art of Defiling: Defeating Forensic Analysis
Routing in the Dark: Scalable Searches in Dark P2P Networks
Ian Clarke & Oskar Sandberg
Preventing Child Neglect in DNSSEC-bis using Lookaside Validation
Paul Vixie
The Jericho Challenge - Finalist Architecture Presentations and Awards
Paul Simmonds
16:45 - 17:05