meetings
where & when
- where
- denhac, 700 Kalamath Street, Denver, CO 80204
- when
- typically 4th fridays (alternative dates can be arranged for speakers), 7-9 pm
- discord
- join the community on discord — decode:
ZGlzY28gcmQge2RvdH0gZ2d7c2xhc2h9Q2FKV2pVZ3FFVg== - topics
- we encourage members to be active and contribute to the group. if you have a meeting topic or idea, propose it in the discord channel or contact us directly.
past meetings
Discussion: Best of Blackhat/Defcon
a better zip bomb
presentation on a new type of highly compressed zip bomb, and a technical description of how it works. source code, sample zip bombs, and a writeup are here. if you wish, bring zip-capable software to test.
Kevin farrow => eaphammer => stealing radius credentials from wpa2-enterprise networks using eaphammer
TeeOne => Hacking WiFi with the Pineapple Tetra
Hands on with Ghidra
If you can, pre-install the tool using the instructions here.
Mock CCDC Red Team Engagement
presenter: xync
This meeting will be a hands-on red team of a Windows domain environment, post exploitation tools, and pivoting. Prereq: setup an AWS account (free tier is fine) and download/install this: Terraform
Hands on with the radare2 tool... A (free) swiss army knife of reverse engineering utilities.
Main page
Feature comparison
Book
Xync => Automated pentest lab deployment
A new tool/technique: SILENTTRINITY
A new tool/technique called SILENTTRINITY was released at Derbycon earlier this month. The tagline is “A post-exploitation agent powered by Python, IronPython, C#/.NET.” This looks like something fun to experiment with. Bring a Windows target VM and something to run the C2 server that can do Python 3.7. You will probably also need a development environment setup (see following links). Github repo. Dev enviornment setup. The Derbycon presentation (53 minutes).