2012-07-31

DEFCON 20: Network Forensics Puzzle Contest

Decryption keys and answers for the DEFCON 20 Network Forensics Puzzle Contest are listed below.  The website indicated that they will provide a full write up of the solution.

If you're wondering where the questions are, they were on CDs handed out during the con when you registered to play.  You just have to go to the DC Contest Area and look for their desk.  The moderators will give you a piece of paper where you have to write your team name and a phone number where they can text you the decryption keys.  They will also provide you a cell number where you can text your answers.  For every correct answer you text them, they will text you back the decryption key for the next round and so on....etc. 

I guess if you can read packets, write code, analyze and listen to talks at the same time during the con, then you have a good chance of having a productive Defcon weekend. 



Decryption Keys
Contest Container: W3lc0m3toNFPC2012@defcon
Round2: Aw3s0m3s4uc3@
Round3: DFC=w00t!
Round4: 4r3g3ttingh4rd
Round5: tHiswi11b3fun#
Round6: Th3R4c3is0n$

Answers to DEFCON 2012 Contest Questions
Round 1 Answer: 99901
Round 2 Answer: Golden Alley
Round 3 Answer: ICdarkwater
Round 4 Answer: 15684-b5.12
Round 5 Answer: 2300
Round 6 Answer: Dogfort

2012-07-30

DEFCON 20: Swag and Con Stash

I was able to acquire items I planned to get this year.  The only item I missed out was the RFID reader because the vendor ran out.  I got 2 badges and all 3 lanyards.  You'll need all 3 lanyards (green, red, yellow) to solve the puzzles.  I also got the Defcon backpack and pocket books.  I was also able to get my copy of Metasploit signed by Dave.  Other acquisitions worth mentioning, Reaver Pro and the Wifi Pineapple Elite.  My badge was able to pair with a number of other badges, minus the Artist and the Uber.  I remember pairing with an Artist on Saturday night, but obviously it did not dock properly.  As far as the Uber was concerned, I did try to find any of the contest winners Sunday afternoon after the Closing Ceremonies but it seemed like everyone of them was rushing to the airport or to the next party in Rio.  Either way, my badge still reported my rank as "Hustler"


DEFCON 20: Badges

Here are the Defcon 20 badges (pics borrowed from the Parallax website).  Parallax had the awesome job of making them this year, and they did an amazing job.  You read all about it on their website



Each of the badges are issued to the type of attendee you are.  I personally think that other than the Uber (black) the Goons (red) and the Press (blue/yellow) had the best badges.  They have an infra red sensor that can dock with other badges.  According to l057, by completing on docking all the badge types, it'll reveal an easter egg.  To check what you have to far, you'll have to plug  your badge to the Parallax Serial Terminal at 57,600 BPS to see who you have encountered.  You can see my badge results below.  I thought I was able to pair with an artist but it obviously did not dock.  The Uber (contest winners) holders were pretty hard to locate since they do not give those out until the end of the con.  Most of them just rush to the airport...



The Human badges also come in multiple variations. I'm not sure how many there were.  According to DT, they made 16,500 badges this year.  The rough estimate for attendees was about 15,000.  So they had extra Human badges after the con.  He has announced that they will be selling the badges for $40 each.  

The Defcon 20 badge and Always Panti liners..

I was searching the hotel room for some kind of material that can at least protect the DEFCON 20 badges and survive the trip home in my backpack without breaking in half. I came across the perfect size in length and protection.... my lovely wife's Always Panti liner box...
The fit is perfect and offers complete protection!

2012-07-28

Defcon 20th Anniversary Hacker Jeopardy Challenge Coin

Defcon 20 Hacker Jeopardy Challenge Coin Limited Edition #21
This coin was not available at the swag booth.  It can be acquired only at the Hacker Jeopardy contest during the Friday night elimination and the Saturday night finals.  Winn was giving it away to individuals from the audience for answering hard Hacker Jeopardy questions.  Other than that, the only other way to get it was to donate to the EFF.  I do not know exactly how many was made or given away.  But is would have been awesome if I got #20 for Defcon's 20th Anniversary.  BTW, it doubles as a bottle opener.






Hak5 Challenge Coin
 I also got the Hak5 challenge coin courtesy of Snubs.  It has little stamps of pineapples (wifi pineapple) on it.  I thought it was a pretty cool coin also, but I don't think I can win any free drinks with it.   But it's still pretty cool.

Defcon 20 gear.

I did not finish prepping my gear this year. Plus, the hotel we are staying in does not have free wifi. Thank God for high gain wifi antennas, now leeching wifi from the hotel next door.
So here's the gear for this year:
MacBook Pro: Lion plus Virtual Box running a variety of Linux, Backtrack and yes, ehem Windows 8 preview.
Gateway NetBook: aka my Defcon laptop - triple booting Ubuntu, Backtrack 5 and Windows 7.
1 iPhone
1 Android
I also brought my wifi Pineapple for fun...
Variety of cables and power cords
No I didn't bring a soldering iron this year. Being unprepared this year... I think I'd might have to rebuild the netbook after the Con.

Defcon 20: Hackers and Feds.

It was unimaginable a few years ago to ever think we would actually align with the Feds. Gen. Alexander on stage in DEFCON 20! Commander of the US Cyber Command and Director of the National Security Agency.... boom! major street cred!

Update: The General's talk was voted worst talk during the Defcon Recognition Awards.  DT has to inform him that he won the worst talk award.

2012-07-27

The Defcon 20 Rotunda Clues









For the 2nd year at Defcon, clues were left on the rotunda floors by 1o57.  I didn't spend anytime on figuring them out this year due to a number of reasons, basically technical reasons.  I was not able to connect to the Defcon Secure Wifi so my resources were an issue. In any case, I hope the pictures help for your personal entertainment and learning.  There were more clues tweeted by 1o57 from his twitter account, so the bread crumbs are all over the place.  You just have to put it all together.