December meeting recap

Ngharo got this started with going around the room and asking everyone what they have been hacking and what they plan on hacking on next, then talking about some improvements to the dc414 server, such as how it is now fully IPv6 friendly and some improvements to the VPN. Then I gave a demo of how BeEF when used with Metasploit can pwn browsers from the inside out. dw5304 stepped in and showed us how to use the windows 7 UI on windows 8 with out having to worry about updates messing things up. Then Noize stepped up and gave us all a great introduction to Subterfuge, a MITM framework that utilizes arp attacks. Then I attempted to give another demo but failed, more on that later 😉 We spent the rest of the night drinking, eating cupcakes “thanx darkwinds wife” and loling at horror pics of server rooms and wiring closets. Congrats to Castor, Tony, and Peppergomez for winning the dc414 free junk giveaway!! Enjoy your junk guys 😛

We got $42 in donations which paid for the pizza and some of the beer with nothing left over for the server :/ which cost about $71 a month. Remember your donations are what keeps dc414 running smoothly for YOU!!!!

November 2012 Meeting Recap

We had a great turnout this meeting.  At least 4 new people showed up!

The night started out with introductions and updates on any member projects going on.  It was interesting to hear the new people give a quick overview of what they’re interested in.  We hope to see them again next month.

We started the fun with Anarchy giving a remote demo of BeEF and Metasploit.  It was very interesting and raised many questions (which is always a good thing).  He demonstrated how to take over a browser session using a BeEF JavaScript inclusion in IE.  BeEF relied on XHR requests to a HTTP server it had launched to execute code on the client’s browser session.

Darkwind gave another demo of FLEX pager decoding using his modified scanner radio which piped audio into his laptop that had software running to decode the FLEX protocol.  Always interesting to see potentially private information flying around over old school pagers.  Still very popular in the medical and alerting agencies.  There was a lot of interesting discussions happening and projects to look at while the projector showed incoming pages.  T3 had his oscilloscope and was looking at ethernet signals, which is very neat if you haven’t seen it.  One can identify physical problems in cable just by looking at the patterns.

F4R4D4Y donated items (covert lock-picking set and roll of solder) for the free junk giveaway which went to Castor and CoderDX.  Thanks for everyone pitching in a few bucks to keep the server up and beer flowing!

Til next time…

September meeting recap

Last meeting was awesome as always, we had some good demos and new faces which is always great. Ngharo started it off going around the room and asking ppl what they hacked last month and what they plan to hack next.

I gave my fakeAP demo to get credit card numbers or sniff traffic. The CC part failed :/ but the sniff part worked like a charm!! Then dw5304 gave a demo titled “Cable hacking for fun” and talked about how to get online anonymously with cable modems, getting almost unlimited bandwidth, modem cloning and lots more. Faraday came packing with some lithium ion batteries and big ass LEDs he gave out “to make flash lights out of” and stuff for making your capacitors which is always fun.

Then I spent the rest of the night drinking beer and yelling in to a ham radio, so I didn’t take any pictures. Congrats to uberushaximus for winning the dc414 free junk giveaway!

Here is a link to the github fakeAP pwnage project, it only works with Backtrack 5 and could use some improvement.
https://github.com/dc414/fakeAP_pwnage

Here is the slides to dw5304’s Cable hacking for fun:
https://skydrive.live.com/redir?resid=463779BB134E309F!375&authkey=!AF56QcP0xP4Ofco

dc414 @ barcampmke7

Last years barcampmke was awesome, everyone had lots of fun and met some great people. Some of you might remember we had a little stand last year and ran the good old wall of sheep, well we liked it so much that this year we decided to become an official sponsor of barcampmke and expand our operations. This year we will not only be doing the the wall of sheep, but we will also be running a lockpick and tamper evident village, cat5 cable making couples contest, plus giving away free beer!! To get a free beer you have to either pick a lock from the village in under 2 minutes or reveal the secret message contained in a package secured with tamper evident lables, tape, lock seals, and tug tights, or beat your competitor to making a working cat5 cable! So sharpen up on your skills and win some free beer! See you at barcamp.

Lets hack schools

School is about to start back up for the year which gives us a great opportunity to give. So at the next meeting “9.7.12” if you bring in school/art supplies to donate in addition to the normal $5 dc414 donation you will get a “I HACK SCHOOLS” pin and the satisfaction of helping tomorrows generation to learn. So lets hack schools together!

Some ideas of stuff to give:
No.2 pencils
ballpoint pens “red and black”
Spiral-bound or composition notebooks
colored pencils
colored clay
non colored clay “grey”
backpacks
index cards
construction paper
glue
three ring binders
erasers
Pencil sharpener (hand-held with a top to collect shavings)
folders

dc414 donations bucket 2.0

A while back we started using a bucket to collect cash donations at meetings and for a while I have been wanting to trick it out. So I was keeping an eye out for things to add other then blinking lights, then cmoney came home with a powerball advertisement thing from her gas station that has a electric pendulum thing. I wish I had a picture of it but I didn’t have the for site to take one before I took it apart.

So anyway I got right to work on making the bucket pimp. First I made a little board

with a 555 timer blinking light circuit on it.

put some lights on it and wired the pendulum thing to it.

And hot glued it all to the lid of the bucket.

Here is what it looks like all together.

Ok thats it, I hope you think its cool. If you don’t, go fuck your mom.

August meeting awesomeness

Klaiviel started us off by giving us a nice show of binary key card hotel locks popular over seas, showed us a 3d printed key for one of his locks, explained pick proof locks from the 40s that are no longer used but highly effective and how to make them today using regular locks. Then he showed us why he is the second best key impressionist in the world, and made a working key for a lock right in front of us and giving us step by step instructions on how to do it our selves.

I stepped in and gave a quick demo of how I made our new and improved donations bucket which I will be making a blog post on later. Darkwind came packing with a alfa wifi antenna hooked up to a satellite dish! This made a killer directional wifi antenna, we took it up to the roof of bucketworks and got signals from all over including the moon 😛 Ngharo hooked it up to his lappy and cracked a few networks 🙂

After the roof party was over and we got back down stairs Castor gave a DEFCON20 badge hacking demo and showed us how to turn our badges into any other badge type we wanted, then showed us how to make the LEDs on the badge flash out words and stuffs. Then we all just started bull shitting and talking about up coming projects.

Cmoney couldnt make it out so I took a few picture that you can view here. Congrats to darkwind and faraday for winning the dc414 free junk giveaway!!

dc414 @ DEFCON20

Most of the crew will be in Vegas for DEFCON20 this year!!! Lets all get drunk and party! I will also be getting married while there to the super awesome cmoney!! For our brothers not going, we will be doing our best to drink your share of booze 🙂 I get the opportunity to speak on the DCG panel again this year so if you are at DC20 come check it out, me and other POCs will be laying down some knowledge for y’all. Also find me or other dc414 members so we can all party 😀 I will be taking lots of pictures and posting them on Twitter, Facebook, and G+ so be sure to check that shit out as well. See ya there.