Shmoocon Labs – Looking Back

So now that I’ve settled back into my life after the whirlwind that was getting married and 3 weeks later being at Shmoo, I wanted to reflect on my experience this year, as well as look back a bit at what has come before. Labs ( and shmoo ) has been a part of my life for 7 years now, and 6 of them teaching. It’s always fun, always a learning experience, and always something I really look forward to.

What is Labs?

Labs is an environment where we build all the infrastructure for Shmoocon in 24 hours. It’s designed to be a teaching environment at several levels: team-leads teach a specific area, attendees build that area, and everyone must work together ( most times with someone they don’t know ) to bring things together. While it can be a stressful environment, we also have a really good time finding solutions to problems. Getting to work with your peers is one of the best parts of Labs.

History

So I started with labs waayyy back in 2006 as a participant. I had come to the Shmoocon before, having found it on a short list of east-coast security cons. I had tried several others locally including SANS and ShadowCon at Quantico, but this was the first ‘hacker’ con I went to. What fun. I had never been in a place where people throw balls at speakers for spouting merde, let alone building 2 cycle shmooball shooting devices ( And starting them up in the conference ball room! ). At the end of that ‘con I asked if I could help out. Heidi recommended that I check out labs, so I put in my paper and was accepted.

We had a ball. We had to build the network from the ground up, literally because we had blank machines. We downloaded the ISOs (cd’s back then ;-) and constructed the machines. I was on the ‘infrastructure’ team.. and we got things running pretty quickly. We even hung a hotel sheet on the wall using gaff-tape and put up a display of our system logs and such. Way fun. The team I worked with was a spread of beginners to senior SA’s, but all had the willingness to learn new stuff and try new things. We had pizza and coffee to keep us going and our network didn’t get hacked, didn’t go down. I walked away with a personal commitment to continue to participate, and perhaps get more involved.

The next year, I offered to ‘teach’ Infrastructure, and was accepted. We got labs going and everything went really well ( Tho I think that’s the year we attempted #openbsd and it exploded in our face). The next day as we were last minute tweaking, I found out I was promoted to shmoocon staff when I was unexpectedly invited to the pre-con staff meeting. What a great feeling! It was really neat to have my hard work recognized and become part of such a neat family. It cemented my commitment to working with the ‘con.

So thru the next several years, I continued to teach Infrastructure. I also started thinking of other things i could do for the ‘con. At the ’0wn the con’ one year, I mentioned how silly it was to have paper reviews when we’re a bunch of computer geeks, and was promptly told “well then fix it!”, and so I created our reviews site. I have also taught a self defense course for geeks ( in CoungNhu karate), and this year I gave my paper ‘TTL of a Penetration‘ which was well accepted.

2012

This year, Labs went even better than expected. It was a bit different in that Brett Thorson staged a bunch of ‘vm’s for us, and we had most all of the configs from last year, so we were able to start from about a 70% complete state. Also my team was made up of senior admins, so we could explore some areas we’d never done before. So we added:

  • A certificate authority
  • A puppet-based VM deployment tool
  • central auth using LDAP
  • central syslogging and nagios ( we didn’t have a monitoring team this year )
  • Trac based Wiki and Ticketing system

And everything mostly went really well. Even with all the pre-event planning on the mailing lists ( a record number of emails this year! ) we still dynamically have to alter plans and come up with solutions. We had a few hiccups .. but that’s normal and part of the plan actually. As we’re a group of people with the same objective, and usually diverse training and capability, someone always brings something new the rest of us can learn from. Our team did an outstanding job this year, and I owe them a debt of gratitude.

We’ve already started planning new concepts and ideas for next year, and as labs seems to grow and improve with every iteration, I expect we’ll actually implement some of them. There seems to be a recurring theme for next year in that we start looking at ‘defense’ as strongly as ‘offense’. Hackers tend to like to find ways to break into things, and admins like for that NOT to happen, so I am hoping to build a new idea into shmoocon that incorporates both ideas. Labs is kinda the epitome of ‘defense’ given our attendee group ;-) and so that crew could be a group to move that idea forward. Time will tell.

If you’re reading this and considering labs, you’ll love it. As a newbie, you’ll get to work with senior people who can teach you both theory and application in building a high-risk network. As a senior person, you’ll get to work with your peers, and play in a really cool environment. You can learn everything from IPv6 to making Cat-5 cables, creating a secure firewall to displaying data in really cool ways. It remains one of the high-points of my year, and something I will always look forward to. I encourage you, if you win that golden ticket, apply for labs and come join us! I promise you won’t be disappointed.

Posted in shmoocon | 1 Comment

ShmooCon Talk Slides and Vid are up

Just found they posted everything on shmoocon site:

If you have comments about these .. please leave em below.

I am constantly refining this presentation and would love to give it again, if you have interest, let me know!

Posted in IT Security, shmoocon | 2 Comments

In Boston

Got some quick work supporting Dept of Transportation on a cutover. Got to hang with my bud Desmo .. had a nice evening. It’s cold up here. They’re expecting snow .. and the accents ( tho I am sure I sound like a pickemuptruck redneck to them ) .. geez. Tho .. I’ve been careful NOT to mention the word ‘Giants’ *snicker* whilst I am here.

Anyway .. back home tonight… yay!

Posted in IT Security, Work | Leave a comment

ShmooCon 2012 Talk

I had a great time talking at Shmoocon this year! Thanks to all the people who sent in feedback!  I take such very seriously and have already worked to tweak this presentation with those comments in mind. I am putting the Shmoo2012 version of my talk up so people can find it if they’re interested.  With out further adieu:

 http://sandsite.org/~branson/TTL-Penetration-Shmoo.pdf

If yer interested in me giving this talk for a group,  I love to do such things, let me know.

UPDATE: My talk was also mentioned in the Washington Post.  My .15 seconds of fame are up!

Posted in IT Security, shmoocon | Tagged | Leave a comment

SOPA Roundup

Lots of things going on in prep for the blackout:

– List of sites goin black: here

– Another .. more full list: http://sopastrike.com/

– GREAT song:

Lots of wordpress plugins ..

seems like this thing is gonna happen. Good to see peeps getting involved!

Posted in Uncategorized | Leave a comment

SOPA Dead .. PIPA next

So reading all over that SOPA is Dead(tm) .. however .. it’s not really dead till withdrawn. So I have concerns that it’s a red herring.  Especially since we’ve seen congress backdoor legislation ( NDAA anyone ) when they couldn’t do it publicly. I am still going thru with the blackout as I believe that awareness needs to be raised.  Hopefully people will see and react.

I did see an interview/debate on UP between Reddits Alexis and the VP and Gen Counsel of NBC.  It wasn’t bad… I feel like Alexis got caught on the whole idea of ‘finding a legit way to access content’ .. but the VP was a total ass: interrupting the interview several times and spouting talking points instead of answering questions and debating on the substance of the issue.  You can see it here .

Posted in Politics | Leave a comment

Wedding Pictures

We’ve had lots of requests for pictures from the wedding. Vikki has been working diligently to make em look pretty.. so with out further ado …

Branson and Vikki wedding

We were married on Jan 1 2012

[img src=http://sandsite.org/wp-content/flagallery/WEDDING PIC/Wedding-john card/thumbs/thumbs_DSC_0007cr.jpg]Wedding Cake
[img src=http://sandsite.org/wp-content/flagallery/WEDDING PIC/Wedding-john card/thumbs/thumbs_DSC_0009cr.jpg]Candles
[img src=http://sandsite.org/wp-content/flagallery/WEDDING PIC/Wedding-john card/thumbs/thumbs_DSC_0011cr.jpg]Fire place we were married in front of
[img src=http://sandsite.org/wp-content/flagallery/WEDDING PIC/Wedding-john card/thumbs/thumbs_DSC_0014cr.jpg]The Dad's and Sebastian
[img src=http://sandsite.org/wp-content/flagallery/WEDDING PIC/Wedding-john card/thumbs/thumbs_DSC_0015cr.jpg]Dad's Sebastian and TJ
[img src=http://sandsite.org/wp-content/flagallery/WEDDING PIC/Wedding-john card/thumbs/thumbs_DSC_0016cr.jpg]Crystal, Branson, Devyn and Jordan
[img src=http://sandsite.org/wp-content/flagallery/WEDDING PIC/Wedding-john card/thumbs/thumbs_DSC_0022cr.jpg]Sheryl and Vikki coming in
[img src=http://sandsite.org/wp-content/flagallery/WEDDING PIC/Wedding-john card/thumbs/thumbs_DSC_0024.jpg]Vikki and her Dad Terry
[img src=http://sandsite.org/wp-content/flagallery/WEDDING PIC/Wedding-john card/thumbs/thumbs_DSC_0026cr.jpg]Vikki and her Dad
[img src=http://sandsite.org/wp-content/flagallery/WEDDING PIC/Wedding-john card/thumbs/thumbs_DSC_0039.jpg]Vikki and Branson saying 'I Do'
[img src=http://sandsite.org/wp-content/flagallery/WEDDING PIC/Wedding-john card/thumbs/thumbs_DSC_0048cr.jpg]Vikki and Branson lighting the candle for life.
[img src=http://sandsite.org/wp-content/flagallery/WEDDING PIC/Wedding-john card/thumbs/thumbs_DSC_0058cr.jpg]The happy couple
[img src=http://sandsite.org/wp-content/flagallery/WEDDING PIC/Wedding-john card/thumbs/thumbs_DSC_0059cr.jpg]YAY! We did it!
[img src=http://sandsite.org/wp-content/flagallery/WEDDING PIC/Wedding-john card/thumbs/thumbs_DSC_0060cr.jpg]Claudia, Sebastian, Jordan and Devyn
[img src=http://sandsite.org/wp-content/flagallery/WEDDING PIC/Wedding-john card/thumbs/thumbs_DSC_0062cr.jpg]The wedding Party
Devyn, TJ, Sebastian, Claudia, Branson, Jordan, Vikki and Sheryl
[img src=http://sandsite.org/wp-content/flagallery/WEDDING PIC/Wedding-john card/thumbs/thumbs_DSC_0065cr.jpg]VIkki and Branson with Lana and Don
[img src=http://sandsite.org/wp-content/flagallery/WEDDING PIC/Wedding-john card/thumbs/thumbs_DSC_0068cr.jpg]Branson and Vikki with all the Parents
[img src=http://sandsite.org/wp-content/flagallery/WEDDING PIC/Wedding-john card/thumbs/thumbs_DSC_0070cr.jpg]Branson and Vikki with Terry and Linda
[img src=http://sandsite.org/wp-content/flagallery/WEDDING PIC/Wedding-john card/thumbs/thumbs_DSC_0072cr.jpg]Branson and Vikki with Terry and Linda
[img src=http://sandsite.org/wp-content/flagallery/WEDDING PIC/Wedding-john card/thumbs/thumbs_DSC_0074cr.jpg]The Happy Couple
[img src=http://sandsite.org/wp-content/flagallery/WEDDING PIC/Wedding-john card/thumbs/thumbs_DSC_0084cr.jpg]Another of the happy couple
[img src=http://sandsite.org/wp-content/flagallery/WEDDING PIC/Wedding-john card/thumbs/thumbs_DSC_0085cr.jpg]Beautiful Bride in front of the snow
[img src=http://sandsite.org/wp-content/flagallery/WEDDING PIC/Wedding-john card/thumbs/thumbs_DSC_0092cr.jpg]Soo Pretty Bride
[img src=http://sandsite.org/wp-content/flagallery/WEDDING PIC/Wedding-john card/thumbs/thumbs_DSC_0094cr.jpg]Mom and Son
[img src=http://sandsite.org/wp-content/flagallery/WEDDING PIC/Wedding-john card/thumbs/thumbs_DSC_0096cr.jpg]Tj giving a kiss
[img src=http://sandsite.org/wp-content/flagallery/WEDDING PIC/Wedding-john card/thumbs/thumbs_DSC_0097cr.jpg]B, V and TJ
[img src=http://sandsite.org/wp-content/flagallery/WEDDING PIC/Wedding-john card/thumbs/thumbs_DSC_0100cr.jpg]Branson, Vik and Sheryl
[img src=http://sandsite.org/wp-content/flagallery/WEDDING PIC/Wedding-john card/thumbs/thumbs_DSC_0101cr.jpg]Sebastian, Branson, Vikki and Claudia
[img src=http://sandsite.org/wp-content/flagallery/WEDDING PIC/Wedding-john card/thumbs/thumbs_DSC_0103.jpg]Vikki and her nephew and neice
[img src=http://sandsite.org/wp-content/flagallery/WEDDING PIC/Wedding-john card/thumbs/thumbs_DSC_0105cr.jpg]Sebastian and Claudia
[img src=http://sandsite.org/wp-content/flagallery/WEDDING PIC/Wedding-john card/thumbs/thumbs_DSC_0106cr.jpg]Sebastian and Claudia
[img src=http://sandsite.org/wp-content/flagallery/WEDDING PIC/Wedding-john card/thumbs/thumbs_DSC_0107crr.jpg]Sebastian Smiling!!!
Posted in Personal, Uncategorized | Tagged | Leave a comment

Got Married

Had a fantastic wedding against a glass pane full of snow. Had lots of good family and a great time. I’ll post pics as soon as we get them up. Thanks to the 28 peeps that ustreamed the event and watched us get married. Now just to get home .. snowing it’s butt off.

Posted in Uncategorized | Leave a comment

Getting Married

I wanted to invite everyone to join Vikki and I virtually! for our wedding. We’re getting married Jan 1, 2012 in Traverse City, Michigan; at the Park Place Hotel at Noon EST. Our venue is small, but in the tradition of being a geek, I will be recording the event and streaming it live so we can fit everyone that wants to celebrate with us.

So ..after doing some testing .. we’ll be using ustream to accomplish this virtual wedding. Please goto:

http://www.ustream.tv/channel/matheson-wedding

And you should find us. Can’t wait to see you here!

 

Posted in Personal | Tagged | 2 Comments

ShmooCon Paper Accepted

Woot! .. I just got mail from the ShmooCon selection committee, my paper TTL of a Penetration was accepted for a speaking slot at shmoo this year.  I’ll be a busy little camper as we approach the ‘con .. but should be LOTS of fun. Can’t wait!

Posted in IT Security, shmoocon | Leave a comment