home meetings mailing list projects contacts
meeting topics we encourage members to be active and contribute to the group. if you have a meeting topic or idea, propose it on the mailing list or contact mantis directly.
where meetings are held at tivoli student center, lower level courtyard / food court area
when 3rd friday of every month, 7:00 - 10:00 PM
   
future meetings:
2010-08-20 mantis => hands-on binary (updated) subversion on Linux
   
past meetings:
2010-07-16 july meeting will be at the ongoing SANS conference at The Westin Tabor Center, 1672 Lawrence Street, Denver, CO 80202 map
2010-06-18 Aaron Pratt => Wifi triangulation
2010-05-21 meeting cancelled due to Defcon CTF qualification round
2010-04-16 mantis => some challenges...
bring IDA/GDB and some scripting skills. file is here
2010-03-26 (was postponed by weather) Don Bailey => DECT sniffing (+ war driving). This meeting will be in the North Classroom Building, room 2002, building #3 (top, center) on the map.
2010-02-19 David Fifield => nmap scripting engine
2010-01-15 mantis => client reversing challenge
2009-12-17 (various) => turbo talks... show us some cool stuff
2009-11-20 Darel Griffin => objective C, debugging and reversing

Equipment: a mac or hackintosh or a *nix machine/VM with GNUstep installed (if you have windowmaker, it is probably already installed)

Tools: OTX (osx) and/or IDA, hex editor, gdb, binutils

Some links for gnustep: http://gnustep.org/
Guide for installing on Linux
2009-10-16 lucipher => win32 challenge: hacking game servers

You will be provided with a win32 game client that talks to a server daemon running remotely. The easy objective will be to insert a fake high score on the server. The hard objective will be to exploit a flaw in the server code running in a Windows virtual machine. You are advised to bring the following so you don't waste time getting your tools setup:

1) windows operating environment (98, 2000, XP, Vista it shouldn't matter)
2) a windows disassembler/debugger: ida pro or ollydbg
3) a network sniffer: tcpdump or wireshark
4) a tool for sending network traffic: netcat, ncat, perl, python
5) a hex editor (frhed, xvi32, hexdump)
6) some shellcode for owning windows XP (hard challenge only)
7) network cable
8) power strip
2009-09-18 mantis => CTF network/binary defense
CTF daemons/binaries (1.7 MBytes)
CTF (Vegas) packet capture (1.5 GBytes)
2009-08-21 syndrowm => radare - good time binary analysis
http://radare.nopcode.org/new/
http://news.nopcode.org/summer.tar.gz
2009-07-17 syndrowm => hacking with python (and 2 challenges)
2009-06-19 no meeting
2009-05-15 mantis => writing shellcode
source and binary
2009-04-24 Luke Arntson => DLL injection (Windows)
presentation
executables
source
2009-03 don bailey => exploiting null pointer derefence bugs: pptx
2009-02 syndrowm => reverse engineering challenge
challenge
2009-01 mantis => reverse engineering challenge
challenge
source with answers
2008-12 no meeting
2008-11 ctf from defcon 2008
2008-?? we had some meetings focused on the defcon ctf competition
2007-?? we had some meetings focused on the defcon ctf competition
2006-12 don.bailey => freebsd rootkits
2006-11 mdmonk => ossec hids
2006-10 mantis => hands-on reversing binaries (part 2)
2006-09 mantis => hands-on reversing binaries
2006-08 no meeting - vegas!
2006-07 ctf preparation
2006-06 ctf preparation
2006-05 mantis => insecure programming
2006-04 no meeting
2006-03 no meeting
2006-02 Nicholas Albright => nepenthes
2006-01 no meeting
2005-12 OSIX security games
2005-11 NGSEC security games
2005-10 mantis => snort backorifice buffer overflow exploit demonstration
2005-09 magictao => scapy packet generation
2005-08 no meeting - vegas!
2005-07 no meeting - vegas!
2005-06 honeywall cdrom 'roo'
2005-05 no meeting
2005-04 magictao => web application security
2005-03 magictao => database encryption product: Vormetric
2005-02 digitalmedix.com => forensics and data recovery
2005-01 johan hybinette => windows rootkits (part 2)
2004-12 no meeting
2004-11 johan hybinette => windows rootkits
2004-10 mantis => linux rootkits
2004-09 magictao => network assessment techniques
2004-08 mantis => metasploit
2004-07 magictao => ActiveScout
2004-06 commercial stego detection tools