home meetings mailing list projects contacts
meeting topics we encourage members to be active and contribute to the group. if you have a meeting topic or idea, propose it on the mailing list or contact mantis directly.
where meetings are held at denhac space: 975 E. 58th Avenue, Unit N, Denver CO 80216; BRING $5 (or more) as a donation to pay utility costs for denhac
when 3rd friday of every month, 7:00 - 10:00 PM
   
future meetings:
2012-01-20 mantis => game/challenge
possible future topics metasploit
video game console hacking
SIM card hacking
intro to IDA Pro
x86 assembly 101
arduino fun
local security bypass with firewire or USB
executable file formats
stegonagraphy for fun and profit
cracking wireless 101
current tech in password cracking
rainbow tables
malware analysis 101
wikto for webapp pentests
burp for webapp pentests
forensics tools
removing malware/spyware on windows
   
past meetings:
2011-12-16 none
2011-11-18 tilver => Burp Suite (download Java files here: http://portswigger.net/burp/)
2011-10-21 syndrowm => buffer overflows 101
2011-09-16 tilver => sqlmap
2011-08-26 (4th Friday) Defcon recap
2011-04-15 syndrowm => ROP exploitation against Windows with ASLR
2011-02-11 Brad Arndt => Tedroo Spambot Analysis; Olldbg, IDA, Python writeup
2011-01-21 andy => IDA Pro scripting with IDC/IDAPython
2010-12-16 (thursday) luke => Wii console hacking
2010-11-19 group (Scott, Chuck, MAT, Tuska) => IPv6
2010-10-15 syndrowm => fuzzing with peach
2010-09-17 meeting cancelled - no room available
2010-08-20 mantis => hands-on binary (updated) subversion on Linux
2010-07-16 july meeting will be at the ongoing SANS conference at The Westin Tabor Center, 1672 Lawrence Street, Denver, CO 80202 map
2010-06-18 Aaron Pratt => Wifi triangulation
2010-05-21 meeting cancelled due to Defcon CTF qualification round
2010-04-16 mantis => some challenges...
bring IDA/GDB and some scripting skills. file is here
2010-03-26 (was postponed by weather) Don Bailey => DECT sniffing (+ war driving). This meeting will be in the North Classroom Building, room 2002, building #3 (top, center) on the map.
2010-02-19 David Fifield => nmap scripting engine
2010-01-15 mantis => client reversing challenge
2009-12-17 (various) => turbo talks... show us some cool stuff
2009-11-20 Darel Griffin => objective C, debugging and reversing

Equipment: a mac or hackintosh or a *nix machine/VM with GNUstep installed (if you have windowmaker, it is probably already installed)

Tools: OTX (osx) and/or IDA, hex editor, gdb, binutils

Some links for gnustep: http://gnustep.org/
Guide for installing on Linux
2009-10-16 lucipher => win32 challenge: hacking game servers

You will be provided with a win32 game client that talks to a server daemon running remotely. The easy objective will be to insert a fake high score on the server. The hard objective will be to exploit a flaw in the server code running in a Windows virtual machine. You are advised to bring the following so you don't waste time getting your tools setup:

1) windows operating environment (98, 2000, XP, Vista it shouldn't matter)
2) a windows disassembler/debugger: ida pro or ollydbg
3) a network sniffer: tcpdump or wireshark
4) a tool for sending network traffic: netcat, ncat, perl, python
5) a hex editor (frhed, xvi32, hexdump)
6) some shellcode for owning windows XP (hard challenge only)
7) network cable
8) power strip
2009-09-18 mantis => CTF network/binary defense
CTF daemons/binaries (1.7 MBytes)
CTF (Vegas) packet capture (1.5 GBytes)
2009-08-21 syndrowm => radare - good time binary analysis
http://radare.nopcode.org/new/
http://news.nopcode.org/summer.tar.gz
2009-07-17 syndrowm => hacking with python (and 2 challenges)
2009-06-19 no meeting
2009-05-15 mantis => writing shellcode
source and binary
2009-04-24 Luke Arntson => DLL injection (Windows)
presentation
executables
source
2009-03 don bailey => exploiting null pointer derefence bugs: pptx
2009-02 syndrowm => reverse engineering challenge
challenge
2009-01 mantis => reverse engineering challenge
challenge
source with answers
2008-12 no meeting
2008-11 ctf from defcon 2008
2008-?? we had some meetings focused on the defcon ctf competition
2007-?? we had some meetings focused on the defcon ctf competition
2006-12 don.bailey => freebsd rootkits
2006-11 mdmonk => ossec hids
2006-10 mantis => hands-on reversing binaries (part 2)
2006-09 mantis => hands-on reversing binaries
2006-08 no meeting - vegas!
2006-07 ctf preparation
2006-06 ctf preparation
2006-05 mantis => insecure programming
2006-04 no meeting
2006-03 no meeting
2006-02 Nicholas Albright => nepenthes
2006-01 no meeting
2005-12 OSIX security games
2005-11 NGSEC security games
2005-10 mantis => snort backorifice buffer overflow exploit demonstration
2005-09 magictao => scapy packet generation
2005-08 no meeting - vegas!
2005-07 no meeting - vegas!
2005-06 honeywall cdrom 'roo'
2005-05 no meeting
2005-04 magictao => web application security
2005-03 magictao => database encryption product: Vormetric
2005-02 digitalmedix.com => forensics and data recovery
2005-01 johan hybinette => windows rootkits (part 2)
2004-12 no meeting
2004-11 johan hybinette => windows rootkits
2004-10 mantis => linux rootkits
2004-09 magictao => network assessment techniques
2004-08 mantis => metasploit
2004-07 magictao => ActiveScout
2004-06 commercial stego detection tools