Re: Boot loader uses INT 13h [WAS BIOS call fallback]

2015-12-24 Thread Dragos Ruiu
>>Returning back to the discussion where I suggested it would be nice to >>build OS kernels that would fail deliberately when virtualized to close >>off that class of malware, especially on the new Intel Skylake chips >>that have fixed so many virtualization bugs that they can (reportedly) >>run

Re: Boot loader uses INT 13h [WAS BIOS call fallback]

2015-12-24 Thread Dragos Ruiu
The right link to PacSec slides (sorry): Mickey's and Jesse's slides from PacSec: http://goo.gl/Rgcwud -Original Message- From: owner-m...@openbsd.org [mailto:owner-m...@openbsd.org] On Behalf Of Dragos Ruiu Sent: December 23, 2015 8:24 PM To: 'Tinker' <ti...@openmailbox.org&

Re: Boot loader uses INT 13h [WAS BIOS call fallback]

2015-12-23 Thread Dragos Ruiu
>On 2015-12-23 10:04, Dragos Ruiu wrote: >> Ok let me short circuit this meta discussion by saying that AFAIK now >> that the new Intel Skylake chips fixed many virtualization bugs > >Curious, where can I read about this, URL? The canonical reference is still (and I looked

Re: Boot loader uses INT 13h [WAS BIOS call fallback]

2015-12-23 Thread Dragos Ruiu
...@openbsd.org] On Behalf Of Peter Kay Sent: December 23, 2015 12:37 AM To: Dragos Ruiu <d...@kyx.net>; 'Read, James C' <jcr...@essex.ac.uk>; 'Theo de Raadt' <dera...@cvs.openbsd.org>; Dragos Ruiu <d...@kyx.net>; 'Read, James C' <jcr...@essex.ac.uk>; 'Theo de Raadt' <dera

Re: Boot loader uses INT 13h [WAS BIOS call fallback]

2015-12-22 Thread Dragos Ruiu
Ok let me short circuit this meta discussion by saying that AFAIK now that the new Intel Skylake chips fixed many virtualization bugs and it's possible to efficiently nest VMs there might not be a way to discover if you are running on bare metal. I too would find it useful to be able to lock a

Re: can't boot from USB3.0 flash memory

2015-11-26 Thread Dragos Ruiu
It might also be a bios setting issue. (Many BIOS have settings for which systems are enabled by the BIOS code) Try enabling "Legacy USB Support" or similar. Cheers, --dr -Original Message- From: owner-m...@openbsd.org [mailto:owner-m...@openbsd.org] On Behalf Of Nick Holland Sent:

Reminder, today is the deadline for CanSecWest CFP submissions, (conf March 18-20)

2014-12-30 Thread Dragos Ruiu
So send something in very soon if you want it considered. Hope all of you have a Happy New Year. Cheers, --dr

EUSecWest 2012 - Amsterdam, Sept 19/20 featuring Mobile PWN2OWN - CFP Deadline June 15

2012-06-04 Thread Dragos Ruiu
EUSecWest 2012, Amsterdam, September 19/20, Featuring Mobile PWN2OWN CALL FOR PAPERS - Deadline June 15 2012 AMSTERDAM, Nederland -- The seventh annual EUSecWest applied technical security conference - where the eminent figures in the international security industry get together share

CanSecWest 2012 Mar 7-9; 2nd call for papers, closes next week, Monday. Dec 5 2011

2011-12-01 Thread Dragos Ruiu
So after a dozen years or so organizing conferences, you get the urge to pull levers and try experimenting with things. So this year I sent out the CanSecWest CFP only over Twitter, and G+ publicly. Just curious as to the adoption and information dispersion rate, and some estimate of the attention

Final Penultimate last Call for Papers for CanSecWest 2011 (deadline Jan. 17th, conf March 9-11)

2011-01-13 Thread Dragos Ruiu
First they ignore you, then they ridicule you, then they fight you, then you win. -- Mahatma Ghandi. Well if Fox's new comedy show Breaking In is any indication, infosec has now entered Ghandi's second stage. http://goo.gl/ZpLDp [youtube] (hat tip to Adam O'Donnell for this humorous find, and Sam

EUSecWest 2010 MiniCFP (conf Jun 16/17) and PacSec 2010 CFP (conf Nov 10/11, deadline July 30)

2010-05-27 Thread Dragos Ruiu
-- World Security Pros. Cutting Edge Training, Tools, and Techniques Amsterdam, Netherlands, June 16/17 2010 http://eusecwest.com Tokyo, Japan, November 10/11 2010 http://pacsec.jp Vancouver, Canada, March 9-11 2011 http://cansecwest.com pgpkey http://dragos.com/ kyxpgp EUSecWest 2010 MiniCFP

EUSecWest Amsterdam 2010 Call For Papers (short deadline May 5 - conf June 16/17)

2010-04-30 Thread Dragos Ruiu
EUSecWest CALL FOR PAPERS AMSTERDAM, Nederland -- The sixth annual EUSecWest applied technical security conference - where the eminent figures in the international security industry will get together share best practices and technology - will be held in downtown Amsterdam at the the

EUSecWest 2009 (May27/28) London Agenda and PacSec 2009 (Nov 4/5) Tokyo CFP deadline: June 1 2009

2009-05-06 Thread Dragos Ruiu
EUSecWest 2009 Speakers Efficient UAK Recovery attacks against DECT - Ralf-Philipp Weinmann, University of Luxembourg A year in the life of an Adobe Flash security researcher - Peleus Uhley, Adobe Pwning your grandmother's iPhone - Charley Miller, Independent Security

EUSecWest 2009 CFP (May 27/28, Deadline April 7 2009)

2009-04-01 Thread Dragos Ruiu
Call For Papers The EUSecWest 2009 CFP is now open. Deadline is April 7th, 2009. EUSecWest CALL FOR PAPERS LONDON, U.K. -- The third annual EUSecWest applied technical security conference - where the eminent figures in the international security industry will get together

CanSecWest 2009 Speakers and Dojo courses (Mar 14-20)

2009-02-15 Thread Dragos Ruiu
Final Speaker Lineup for CanSecWest 2009 (March 18-20): === The Smart-Phones Nightmare - Sergio 'shadown' Alvarez Getting into the SMRAM: SMM Reloaded - Lomc Duflot Network design for effective HTTP traffic filtering - Jeff rfp Forristal, Zscaler

CanSecWest 2009 CFP (March 18-20 2009, Deadline December 8 2008)

2008-11-24 Thread Dragos Ruiu
Call For Papers The CanSecWest 2009 CFP is now open. Deadline is December 8th, 2008. CanSecWest CALL FOR PAPERS VANCOUVER, Canada -- The tenth annual CanSecWest applied technical security conference - where the eminent figures in the international security industry will get

BA-Con 2008 CFP - Buenos Aires Sept. 30 / Oct. 1 (closes July 11 2008)

2008-06-27 Thread Dragos Ruiu
BA-Con 2008 CALL FOR PAPERS BUENOS AIRES, Argentina -- The first annual BA-Con applied technical security conference - where the eminent figures in the international and South American security industry will get together and share best practices and technology - will be held in

Final EUSecWest 2008 Speakers London May 21/22

2008-05-08 Thread Dragos Ruiu
The selected papers for EUSecWest 2008 are: * PhlashDance, discovering permanent denial of service attacks against embedded systems - Rich Smith, HP Labs * Attacking Near Field Communications (NFC) Mobile Phones - Collin Muliner, trifinite * Abusing X.509 certificate features - Alexander

EUSecWest CFP Closes April 14th (conf May 21/22 2008)

2008-04-10 Thread Dragos Ruiu
(We've moved the conference this year to the a club in Leicester Square in the heart of London and SoHo. We'll be putting speakers up across the square at the Radisson Edwardian Hampshire, but there are lots of hotels in the region there in the center of London for those who want to attend (the

CanSecWest 2008 PWN2OWN - Mar 26-28

2008-03-20 Thread Dragos Ruiu
Calendar Notes: === PacSec 2008 will be on November 12/13 in Tokyo at Aoyama Diamond Hall. EUSecWest 2008 will be on May 21/22 at a fun new venue in central London. (We cooked this schedule up so it will enable people to fly to Berlin on the 23rd and make FX's ph-neutral on Saturday the

CanSecWest 2008 Mar 26-28

2008-02-22 Thread Dragos Ruiu
CanSecWest 2008 Presentations Snort 3.0 - Marty Roesch, Sourcefire Cross-Site Scripting Vulnerabilities in Flash Authoring Tools - Rich Cannings, Google Proprietary RFID Systems - Jan starbug Krissler and Karsten Nohl, CCC Media Frenzy: Finding Bugs in Windows Media Software - Mark Dowd and

CanSecWest 2008 CFP (deadline Nov 30, conf Mar 26-28) and PacSec Dojo's

2007-11-08 Thread Dragos Ruiu
I'd like to congratulate Adam Laurie for winning the second Powerbook from the Pwn_to_Own contest as the prize for the best speaker rated by the audience for his presentation on RFID at CanSecWest 2007. We will have a similar prize for the best speaker at CanSecWest 2008, prize TBD (but we promise

In Memoriam: Jun-ichiro Hagino

2007-10-30 Thread Dragos Ruiu
With great sadness, I regret to inform you that Itojun will not be presenting his great knowledge of IPv6 at PacSec. I have been informed by several sources that he passed away yesterday. Funeral services will be held on Nov 7th at Rinkai-Saijo in Tokyo. There aren't many details of his

PacSec 2007 Agenda (Tokyo 11-29/30)

2007-10-21 Thread Dragos Ruiu
Talk selections for PacSec 2007 - November 29 and 30 - Aoyama Diamond Hall --- - Programmed I/O accesses: a threat to virtual machine monitors? - Loic Duflot, - Developing Fuzzers with Peach - Michael Eddington, Leviathan Security - Cyber Attacks Against Japan - Hiroshi Kawaguchi, LAC -

Really, really, penultimate, PacSec CFP deadline, Aug 10.

2007-07-31 Thread Dragos Ruiu
Some folks have been trying to convince us to extend deadlines, so being the sticklers we are, we said: no way... But they convinced us. So to be fair - this is a heads up for others who didn't have time to submit. :-) We'll try to turn around the selection reviews ASAP, before the end of August

PacSec 2007 Call For Papers (Nov. 29/30, deadline July 27)

2007-07-03 Thread Dragos Ruiu
PacSec CALL FOR PAPERS World Security Pros To Converge on Japan TOKYO, Japan -- To address the increasing importance of information security in Japan, the best known figures in the international security industry will get together with leading Japanese researchers to share best

EUSecWest 2007 Papers

2007-01-18 Thread Dragos Ruiu
Hi, For those who asked, we are still processing the submissions for CanSecWest and the call closed, please stand by. The paper selections are back from the reviewers for EUSecWest, in London on March 1-2. In absolutely random order: Threats against and protection of Microsoft's internal

CanSecWest 2007 (April 18-20) Call For Papers (Deadline Jan 7th)

2006-12-13 Thread Dragos Ruiu
CanSecWest 2007 CALL FOR PAPERS VANCOUVER, Canada -- The eighth annual CanSecWest applied technical security conference - where the eminent figures in the international security industry will get together share best practices and technology - will be held in downtown Vancouver at the the

EUSecWest/London CFP extended to Nov. 7

2006-11-02 Thread Dragos Ruiu
Hi folks, some brief news: Some people have asked for late submissions to the EUSecWest paper selections. In the interest of fairness, we are extending the deadline for all until next Tuesday (November 7), at which time the submissions will be reviewed. Details of submissions can be found on the

PacSec 2006 announcement, EUSecWest 2007 Call For Papers (Mar 1-2, deadline Oct 20th)

2006-10-03 Thread Dragos Ruiu
The PacSec 2006 paper selections have been announced: Smashing Heap by Free Simulation - Sandip Chaudhari Methods of increasing source code security automatically - Ben Chelf, Coverity IPTV: Triple Play Triple Threats - YM Chen, McAfee Windows Vista Security Model - Matt Conover,

PacSec 2006 CALL FOR PAPERS (Deadline Aug. 4; Event Nov. 27-30)

2006-07-17 Thread Dragos Ruiu
url: http://pacsec.jp PacSec 2006 CALL FOR PAPERS World Security Pros To Converge on Japan TOKYO, Japan -- To address the increasing importance of information security in Japan, the best known figures in the international security industry will get together with leading Japanese

CanSecWest/core06 Vancouver April 3-7

2006-03-07 Thread Dragos Ruiu
The call for papers is now closed and the proposals have been reviewed for the CanSecWest/core06 Applied Technical Security Conference held on April 5-7 2006 at the Mariott Renaissance Harbourside in Vancouver, B.C. Canada. The selected submissions are : An hour of Rap and Comedy about SAP -

EUSecWest papers and CanSecWest CFP

2006-01-12 Thread Dragos Ruiu
url: http://eusecwest.com url: http://cansecwest.com (CanSecWest Call For Papers attached below) EUSecWest/core06 Conference --- Announcing the final selection of papers for the EUSecWest conference in London, U.K. on Feb. 20/21 at the Victoria Park Plaza Hotel. The

EUSecWest/London Call for Papers and PacSec/Tokyo announcements

2005-10-31 Thread Dragos Ruiu
url: http://eusecwest.com url: http://pacsec.jp (PacSec/Tokyo Announcement below...) EUSecWest/core06 CALL FOR PAPERS London Security Summit February 20/21 2006 LONDON, United Kingdom -- Applied technical security will be the focus of a new annual conference

PacSec05

2005-09-26 Thread Dragos Ruiu
English url: http://pacsec.jp/index.html?LANG=ENGLISH Japanese url: http://pacsec.jp/index.html?LANG=JAPANESE Myamoto Musashi famous swordsman and author of Go Rin No Sho (the Book of Five Rings) wrote Study the Way of all professions. In the way of computer networks, one must understand attacks