<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>SecDocs Feed for author Don Bailey</title>
    <link>http://secdocs.lonerunners.net</link>
    <atom:link type="application/rss+xml" href="http://secdocs.lonerunners.net/rss/author/839-don-bailey" rel="self"/>
    <description>Latest security documents RSS feed for author Don Bailey</description>
    <language>en-us</language>
    <item>
      <title>[Paper] Carmen Sandiego is On the Run!</title>
      <description>&lt;b&gt;Authors&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/authors/details/839-don-bailey"&gt;Don Bailey&lt;/a&gt; &lt;a href="http://secdocs.lonerunners.net/authors/details/730-nick-depetrillo"&gt;Nick DePetrillo&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Tags&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/tags/details/101-intelligence"&gt;intelligence&lt;/a&gt; &lt;a href="http://secdocs.lonerunners.net/tags/details/108-gsm"&gt;GSM&lt;/a&gt; &lt;a href="http://secdocs.lonerunners.net/tags/details/233-phone"&gt;phone&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Event&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/events/details/71-black-hat-usa-2010"&gt;Black Hat USA 2010&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Abstract&lt;/b&gt;: The global telephone network is often an opaque and muddy environment where many false assumptions of privacy are made by its users. Providers do their best to compartmentalize as much privacy-centric data as possible. However, information must be shared for the sake of network interoperability. The speakers will discuss gaps in privacy protection and how they can be leveraged to expose who you are, your location, and the privacy of those in contact with you.  Demonstrations will reveal how location data can be augmented and used in several fashions. First, the speakers will show how information can be leveraged to develop fairly accurate physical boundaries of a particular mobile switching center and how this information changes over time. Second, the speakers will overlay cellular tower data to depict coverage in a particular mobile switching center. Next, the speakers will demonstrate how to visualize an individual traveling across adjacent mobile switching centers and the cell towers they are likely to associate with. Finally, the speakers will demonstrate how known location values for many subscribers can reveal location information for handsets where location information can't be obtained directly.  Lastly, the speakers will elaborate on mitigation strategies for these attacks at the subscriber level and potential mitigation strategies for the provider level.</description>
      <pubDate>Tue, 06 Sep 2011 08:36:21 +0200</pubDate>
      <link>http://secdocs.lonerunners.net/documents/details/3963-carmen-sandiego-is-on-the-run</link>
      <guid>http://secdocs.lonerunners.net/documents/details/3963-carmen-sandiego-is-on-the-run</guid>
    </item>
    <item>
      <title>[Slides] Micro Control Attacking uC Applications</title>
      <description>&lt;b&gt;Authors&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/authors/details/839-don-bailey"&gt;Don Bailey&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Tags&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/tags/details/98-hardware-hacking"&gt;hardware hacking&lt;/a&gt; &lt;a href="http://secdocs.lonerunners.net/tags/details/192-microcontroller"&gt;microcontroller&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Event&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/events/details/48-hack-in-the-box-2010-malaysia"&gt;Hack In The Box 2010 Malaysia&lt;/a&gt; &lt;br/&gt;</description>
      <pubDate>Sat, 16 Oct 2010 18:41:00 +0200</pubDate>
      <link>http://secdocs.lonerunners.net/documents/details/2964-micro-control-attacking-uc-applications</link>
      <guid>http://secdocs.lonerunners.net/documents/details/2964-micro-control-attacking-uc-applications</guid>
    </item>
    <item>
      <title>[Video] Winning the Race to Bare Metal &#8211; UEFI Hypervisors</title>
      <description>&lt;b&gt;Authors&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/authors/details/380-martin-mocko"&gt;Martin Mocko&lt;/a&gt; &lt;a href="http://secdocs.lonerunners.net/authors/details/839-don-bailey"&gt;Don Bailey&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Tags&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/tags/details/1-virtualization"&gt;virtualization&lt;/a&gt; &lt;a href="http://secdocs.lonerunners.net/tags/details/115-hypervisor"&gt;hypervisor&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Event&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/events/details/42-black-hat-usa-2008"&gt;Black Hat USA 2008&lt;/a&gt; &lt;br/&gt;</description>
      <pubDate>Wed, 23 Jun 2010 06:03:29 +0200</pubDate>
      <link>http://secdocs.lonerunners.net/documents/details/2584-winning-the-race-to-bare-metal-%E2%80%93-uefi-hypervisors</link>
      <guid>http://secdocs.lonerunners.net/documents/details/2584-winning-the-race-to-bare-metal-%E2%80%93-uefi-hypervisors</guid>
    </item>
    <item>
      <title>[Audio] Winning the Race to Bare Metal &#8211; UEFI Hypervisors</title>
      <description>&lt;b&gt;Authors&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/authors/details/380-martin-mocko"&gt;Martin Mocko&lt;/a&gt; &lt;a href="http://secdocs.lonerunners.net/authors/details/839-don-bailey"&gt;Don Bailey&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Tags&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/tags/details/1-virtualization"&gt;virtualization&lt;/a&gt; &lt;a href="http://secdocs.lonerunners.net/tags/details/115-hypervisor"&gt;hypervisor&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Event&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/events/details/42-black-hat-usa-2008"&gt;Black Hat USA 2008&lt;/a&gt; &lt;br/&gt;</description>
      <pubDate>Wed, 23 Jun 2010 06:03:28 +0200</pubDate>
      <link>http://secdocs.lonerunners.net/documents/details/2583-winning-the-race-to-bare-metal-%E2%80%93-uefi-hypervisors</link>
      <guid>http://secdocs.lonerunners.net/documents/details/2583-winning-the-race-to-bare-metal-%E2%80%93-uefi-hypervisors</guid>
    </item>
    <item>
      <title>[Slides] Winning the Race to Bare Metal &#8211; UEFI Hypervisors</title>
      <description>&lt;b&gt;Authors&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/authors/details/380-martin-mocko"&gt;Martin Mocko&lt;/a&gt; &lt;a href="http://secdocs.lonerunners.net/authors/details/839-don-bailey"&gt;Don Bailey&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Tags&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/tags/details/1-virtualization"&gt;virtualization&lt;/a&gt; &lt;a href="http://secdocs.lonerunners.net/tags/details/115-hypervisor"&gt;hypervisor&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Event&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/events/details/42-black-hat-usa-2008"&gt;Black Hat USA 2008&lt;/a&gt; &lt;br/&gt;</description>
      <pubDate>Wed, 23 Jun 2010 06:03:26 +0200</pubDate>
      <link>http://secdocs.lonerunners.net/documents/details/2582-winning-the-race-to-bare-metal-%E2%80%93-uefi-hypervisors</link>
      <guid>http://secdocs.lonerunners.net/documents/details/2582-winning-the-race-to-bare-metal-%E2%80%93-uefi-hypervisors</guid>
    </item>
    <item>
      <title>[Paper] Winning the Race to Bare Metal &#8211; UEFI Hypervisors</title>
      <description>&lt;b&gt;Authors&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/authors/details/380-martin-mocko"&gt;Martin Mocko&lt;/a&gt; &lt;a href="http://secdocs.lonerunners.net/authors/details/839-don-bailey"&gt;Don Bailey&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Tags&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/tags/details/1-virtualization"&gt;virtualization&lt;/a&gt; &lt;a href="http://secdocs.lonerunners.net/tags/details/115-hypervisor"&gt;hypervisor&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Event&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/events/details/42-black-hat-usa-2008"&gt;Black Hat USA 2008&lt;/a&gt; &lt;br/&gt;</description>
      <pubDate>Tue, 22 Jun 2010 14:09:47 +0200</pubDate>
      <link>http://secdocs.lonerunners.net/documents/details/2581-winning-the-race-to-bare-metal-%E2%80%93-uefi-hypervisors</link>
      <guid>http://secdocs.lonerunners.net/documents/details/2581-winning-the-race-to-bare-metal-%E2%80%93-uefi-hypervisors</guid>
    </item>
    <item>
      <title>[Slides] We Found Carmen San Diego</title>
      <description>&lt;b&gt;Authors&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/authors/details/730-nick-depetrillo"&gt;Nick DePetrillo&lt;/a&gt; &lt;a href="http://secdocs.lonerunners.net/authors/details/839-don-bailey"&gt;Don Bailey&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Tags&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/tags/details/108-gsm"&gt;GSM&lt;/a&gt; &lt;a href="http://secdocs.lonerunners.net/tags/details/233-phone"&gt;phone&lt;/a&gt; &lt;a href="http://secdocs.lonerunners.net/tags/details/234-locating"&gt;locating&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Event&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/events/details/40-source-conference-boston-2010"&gt;Source Conference Boston 2010&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Abstract&lt;/b&gt;: Using new resources in concert with new and old telephony tricks, the speakers have been able to successfully track users of GSM mobile phones without direct access to SS7. Though, initially, the granularity of the location information was not fine enough, the speakers have been able to develop effective techniques to supplement the location data. Augmenting this attack is the ability to learn a target user's mobile phone number without the user's knowledge, enhancing the passive nature of the attack. The speakers will elaborate on new real world attack vectors that make these threats both credible and practical. GSM location data in the US is private. However, unscrupulous providers have exposed this data to an international audience, allowing anyone access to this information for a price. The researchers will elaborate on the technical details of how and why the above attacks work, what solutions are possible, and how users can protect themselves.</description>
      <pubDate>Wed, 26 May 2010 12:45:00 +0200</pubDate>
      <link>http://secdocs.lonerunners.net/documents/details/2513-we-found-carmen-san-diego</link>
      <guid>http://secdocs.lonerunners.net/documents/details/2513-we-found-carmen-san-diego</guid>
    </item>
  </channel>
</rss>

