Sunday, June 12, 2011

Security BSides St John's 2011 in photos

I'll be writing up a more detailed recap of the events surrounding the Security BSides St John's 2011 conference, but thought I'd share some of the moments with you as a photo essay.
Before the conference could begin conference attendees arriving from out of province were made honorary Newfoundlanders.
The conference attendees arriving early Friday morning.
The stage is set, and the conference is ready to start!
Nobert Griffin welcomes the near 140 conference attendees and delivers the keynote address.
Travis Barlow started the talks by telling the audience some of his experiences in penetration testing (see "Chasing Turkeys").
Mark Nunnikhoven then provided his in depth analysis of the security issues involved with iOS devices on your network (see "iPads: Love'm, Hate'em, You're going to have to deal with'em"). 
Ajay Sood brought the attendees up to date on the latest trends in malware (see "Modern Malware Exposed!").
Jean-Pier Talbot provided a hands on example of cross site scripting vulnerabilities.
After this hands on talk the conference braked for lunch on site at ClubOne. This gave all of the audience a chance to meet up with the presenters one on one to further discuss the issues they presented during the morning session.
Jon Anstey delivered a talk aimed towards application developers using Apache Camel. To anyone familiar with implementing EIPs this was a great introduction to handling data in a secure manner (see "How to secure your Apache Camel Deployment").  
Kellman Meghu was in the right city to talk about the cloud, seeing that St John's likes to keep the clouds firmly at ground level ;) (see "Virtually Safe?") 
Tim Newell provided a nuanced discussion on the challenges we face providing remote access to our system users (see "Having your cake and eating it - Remote Access Security").
Adam Mosher ended the talks with his review of Anti-forensics (see "Evasion with anti-forensics").
After all of the talks had been delivered the attendees were invited over to Dusk Lounge to continue discussing the presented talks, network, and enjoy getting to know our peers. 

I'd like to take a moment to thank Norbert Griffin, Travis Barlow, and Victoria Vuong for all of their hard work to make this BSides possible. I hope that next year the organizers of this BSides conference will be willing to put together another event - this whole event was so much fun! 

Tuesday, June 7, 2011

Security B-Sides St John's Schedule!


Friday June 10th, 2011 Track 1
8:30 AM - 9:00 AM Coffee and Muffins Served
9:00 AM - 9:10 AM Opening Remarks Early Bird Prize Give away
(Arrive before 9:00 AM to be entered for a chance
to win a Netbook)
9:10 AM- 9:50 AM Name: Travis Barlow
Talk: Chasing Turkeys
10:00 AM - 10:20 AM Name: Mark Nunnikhoven
Talk: iPads: Love’em, Hate’em, You’re Going to Have
to Deal With’em
10:30 AM - 11:20 AM Name: Ajay Sood
Talk: Modern Malware Exposed!
11:30 AM - 12:20 AM Name: Jean-Pier Talbot
Talk: The Web is a Battlefield
12:30 PM - 1:30 PM LUNCH
1:30 PM - 2:20 PM Name: Jon Anstey
Talk: How to Secure your Apache Camel Deployment
2:30 PM - 3:20 PM Name: Kellman Meghu
Talk: Virtually Safe?
3:30 PM - 4:20 PM Name: Tim Newell
Talk: Having Your Cake and Eating it - Remote Access
Security
4:30 PM - 5:20 PM Name: Adam W. Mosher
Talk: Evasion with anti-forensics
5:30 PM - 6:00 PM Grand Prize (TBD) Give Away
6:00 PM - Onwards Finger Foods\Drinks and Social Gathering

Monday, June 6, 2011

Reasons to attend Security BSides St John's 2011 (part 8)

So you've heard about the Security BSides St John's 2011 event and wonder if you'll sign up to attend? Well if you do you'll be able to take in a variety of information security talks from leaders in the field, while  having the opportunity to meet other information security practitioners, and researchers. In this week's 'Reasons to attend Security BSides St John's 2011' I'm highlighting Mark Nunnikhoven's talk entitled "iPads: Love’em, Hate’em, You’re Going to Have to Deal With’em":

iPads: Love’em, Hate’em, You’re Going to Have to Deal With’em
Mark Nunnikhoven, Security Architect

It’s shiny.

All the other executives have them!

But...I want it.

The iPad currently owns the tablet market. Because of that dominance—and whatever your organizations motivation—sooner or later you’re going to have to figure out how to secure iPads (and iPhones) within your environment.

From connectivity, to data storage, to apps, to support, to media management, and beyond there’s a mountain of issues to deal with. You’re going to have to figure out how to address these issues, and the sooner the better.

This talk will help get you started. Together we’ll walk through some of the pitfalls, problems, and challenges associated with these (and similar) devices.

With the right approach is it possible to minimize the risks these devices pose without significantly altering the great user experience they provide.