<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Matthieu Suiche&#039;s blog &#187; Presentations</title>
	<atom:link href="http://www.msuiche.net/category/presentations/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.msuiche.net</link>
	<description>Happiness only real when shared.</description>
	<lastBuildDate>Sat, 24 Apr 2010 09:10:12 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.8.3</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Challenge of Windows physical memory acquisition and exploitation</title>
		<link>http://www.msuiche.net/2009/06/12/challenge-of-windows-physical-memory-acquisition-and-exploitation/</link>
		<comments>http://www.msuiche.net/2009/06/12/challenge-of-windows-physical-memory-acquisition-and-exploitation/#comments</comments>
		<pubDate>Fri, 12 Jun 2009 05:11:18 +0000</pubDate>
		<dc:creator>Matthieu Suiche</dc:creator>
				<category><![CDATA[Presentations]]></category>
		<category><![CDATA[Windows]]></category>

		<guid isPermaLink="false">http://www.msuiche.net/?p=239</guid>
		<description><![CDATA[(Honolulu, HW) &#8211; Here is a quick post to provide ressources presented this afternoon at Shakacon 2009.
This talks aims at showing to win32dd users (forensics engineers, investigators, incident response engineers, ..) why physical memory analysis is important, and mainly covers how to rethink memory acquisition and exploitation in a more efficient way.
Slides are available here. [...]]]></description>
			<content:encoded><![CDATA[<p><em>(Honolulu, HW)</em> &#8211; Here is a quick post to provide ressources presented this afternoon at <a href="http://shakacon.org/">Shakacon 2009</a>.<br />
This talks aims at showing to win32dd users (forensics engineers, investigators, incident response engineers, ..) why physical memory analysis is important, and mainly covers how to rethink memory acquisition and exploitation in a more efficient way.</p>
<p>Slides are available <a href="http://msuiche.net/con/shakacon2009/NFI-Shakacon-win32dd0.3.pdf">here</a>. Not rocket science but very interesting to see how efficient results can be obtained if we put different exciting and performant technologies together.</p>
<p>PowerShell script used to retrieve erased EPROCESS entries from PspCidTable is available <a href="http://msuiche.net/con/shakacon2009/PspCidTable_PowerShell_Script.zip">here</a>.</p>
<p><center><a href="http://www.msuiche.net/con/shakacon2009/hidden.png"><img src="http://www.msuiche.net/con/shakacon2009/hidden.png" alt="hidden process" height="70%" width="70%" /></a><br />
<strong>Figure 1 &#8211; Screenshot of the powershell script in action</strong><br />
<em>Magic command (.\FUto.ps1 | Out-GridView)</em></center></p>
<p>And here is <a href="http://www.msuiche.net/countcount/click.php?id=8">win32dd v1.2.1.20090608</a> &#8211; If you want more information about the update go <a href="http://www.msuiche.net/2009/06/08/update-win32dd-12220090608-fixes-improvements/">here</a>.</p>
<p>PS. Do not copy win32dd in the System32 directory and run it as Administrator. I think I&#8217;ll write a HOWTO document soon.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.msuiche.net/2009/06/12/challenge-of-windows-physical-memory-acquisition-and-exploitation/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Samba eXPerience conference &#8211; Germany</title>
		<link>http://www.msuiche.net/2008/04/20/samba-experience-conference-germany/</link>
		<comments>http://www.msuiche.net/2008/04/20/samba-experience-conference-germany/#comments</comments>
		<pubDate>Sun, 20 Apr 2008 18:21:41 +0000</pubDate>
		<dc:creator>Matthieu Suiche</dc:creator>
				<category><![CDATA[Presentations]]></category>
		<category><![CDATA[Interoperability]]></category>

		<guid isPermaLink="false">http://www.msuiche.net/?p=43</guid>
		<description><![CDATA[





Day 1 :: Workshop
8.00 PM (yeah it&#8217;s late)
I had almost 7 hours of time travel in Train from Paris to Goettigen. It was really exhausting but it was a good opportunity to talk with pretty girls visiting Europa :)
This year, SambaXP conference hold in Freizeit Hotel (Free time in English) in Goettingen (Germany)  from [...]]]></description>
			<content:encoded><![CDATA[<div>
<div>
<p>
<img src='http://www.sambaxp.org/fileadmin/sambaxp05/bilder/sambaXP_logo.gif' alt='SambaXP'  style="float:right; margin-left 1em;" />
</p>
</div>
<li><strong>Day 1 :: Workshop</strong></li>
<p><em>8.00 PM (yeah it&#8217;s late)</em><br />
I had almost 7 hours of time travel in Train from Paris to Goettigen. It was really exhausting but it was a good opportunity to talk with pretty girls visiting Europa :)</p>
<p>This year, <a href="http://www.sambaxp.org">SambaXP</a> conference hold in Freizeit Hotel (<em>Free time in English</em>) in Goettingen (Germany)  from 14th to 18th April.<br />
During the dinner, I met <a href="http://www.samba.org">Samba Team</a>, <a href="http://openchange.org">OpenChange Team</a> and sponsors people.</p>
<li><strong>Day 2 :: Workshop</strong></li>
<p>I had a really interesting discussion with the folks of Samba about <a href="http://samba.org/samba/PFIF/PFIF_history.html">Protocol</a> <a href="http://samba.org/samba/PFIF/PFIF_agreement.pdf">Freedom</a> <a href="http://samba.org/samba/PFIF/PFIF_agreement.html">Information</a> <a href="http://samba.org/samba/PFIF/">Foundation</a> (<a href="http://www.protocolfreedom.org/">PFIF</a>).</p>
<p>My main question was : What&#8217;s the difference between semi-private documentation provided by PFIF since December 2007 and public documentation provided by MSDN since March?<br />
Technically, the content is the same. But if you look the law part PFIF grants extra patents protections.<br />
For instance, if someone uses PFIF docs then Microsoft has a limited number of patents they can assert against the developer but if he uses MSDN docs then he doesn&#8217;t have patent protection.</p>
<p>I strongly recommend you to read links I posted above. That&#8217;s really an impressive work they did since <a href="http://us1.samba.org/samba/docs/10years.html">1992</a>.</p>
<li><strong>Day 3 :: Tutorials</strong></li>
<p><em>Weather in Germany is cold! I even wonder if it&#8217;s colder than North France one.</em></p>
<p>During the dinner, I had the occasion to meet <a href="http://port25.technet.com/archive/2006/03/18/Port-25-Contributors.aspx"><strong>Tom Hanrahan</strong></a> from <a href="http://port25.technet.com/">Port 25</a> (MSFT) who works as Director of Linux Interoperability. </p>
<p>I&#8217;d like to share an interesting reference from <a href="http://shearer.org"><strong>Dan</strong></a> to a speech of <strong><a href="http://en.wikipedia.org/wiki/Eben_Moglen">Eben</a> <a href="http://emoglen.law.columbia.edu/">Moglen</a> </strong>about <u><em>&#8220;The Global Software Industry in Transformation: After GPLv3&#8243;</em></u>. (<a href="http://www.archive.org/details/EbenMoglenLectureEdinburghJune2007">Audio</a>, <a href="http://jeremiad.org/moglentext.shtml">Txt</a>).</p>
<li><strong>Day 4 :: Conference</strong></li>
<p><strong><a href="http://www.samba.org/~tridge/">Andrew</a> <a href="http://en.wikipedia.org/wiki/Andrew_Tridgell">Tridgell</a></strong> (Samba Team), <u><i>Samba and the PFIF</i></u> renamed <u><i>Samba and Microsoft</i></u> to focus on new relationship between Samba and Microsoft engineers.</p>
<p><strong>Andrew </strong>gave a quick review of the relationship with Microsoft timeline from early 90&#8217;s to now including the antitrust action in Europe during (99 &#8211; 07),  WSPP/PFIF agreement (late 2007) to actual open cooperation publicly release of documentation MSDN (MSFT interoperability initiative).</p>
<p>PFIF (Protocol Freedom information foundation) has been introduced. For people who never heard about PFIF, it&#8217;s a legal entity that allows free software projects to take advantage of the WSPP protocol program. It makes protocol documentation available under a NDA but compatible with GPL. With an additional guarantees provided for at least 5 years of updates and corrections. Andrew also talked about the <a href="http://www.msuiche.net/2008/04/06/few-words-about-microsoft-interoperability-initiative/">recent errors discovered</a> in the documentation and the fact that Microsoft is now close to developers to fix it. </p>
<p>As you probably know, WSPP and MCPP documents are now public under a liberal license. It means Samba can now build an open community for  cooperation on protocol knowledge. All previous secret on WSPP/PFIF is finished because the documentation is now available to everyone. PFIF also provides some additional guarantees on documentation updates and corrections.</p>
<p>As <strong>Andrew</strong> said, it means a good technical cooperation because lawyers are now sidelined and engineers have taken over. He also mentioned there is now a public forum for protocol discussion where PFIF members and MS Engineers can talk.</p>
<p>Tridge also highlighted two notable events for 2008: </p>
<ul>Samba&#8217;ll be participing file system plugfest at Microsoft in June.</ul>
<ul>Microsoft will actively participate in the CIFS plugfest in August.</ul>
<p><strong>Julien Kerihuel</strong> (<a href="http://www.openchange.org">OpenChange</a>): <u><i>When OpenChange assimilates the Borg</i></u><br />
OpenChange is 5 years old project build over Samba 4 infrastructure, two members of Openchange belong to Samba Team. <strong>Julien </strong>mostly talks about the libmapi client implementation  This library provides an interface for NSPI &#038; EMSMDB protocol. </p>
<p><em>*Party!*</em></p>
<li><strong>Day 5 :: Conference</strong></li>
<p>This day is composed of three simultaneous room for three simultaneous talks.</p>
<p>There is a presentation I really appreciated, entitled <i><u>Samba Encryption</u></i> by <strong>Jeremy Allison</strong> (Google &#038; Samba Team). The talk was about SMB protocol internal and some programming stuff.  </p>
</div>
]]></content:encoded>
			<wfw:commentRss>http://www.msuiche.net/2008/04/20/samba-experience-conference-germany/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Enter Sandman &#8211; Japan Pacsec 2007</title>
		<link>http://www.msuiche.net/2007/12/06/enter-sandman-japan-pacsec-2007/</link>
		<comments>http://www.msuiche.net/2007/12/06/enter-sandman-japan-pacsec-2007/#comments</comments>
		<pubDate>Thu, 06 Dec 2007 17:46:36 +0000</pubDate>
		<dc:creator>Matthieu Suiche</dc:creator>
				<category><![CDATA[Presentations]]></category>
		<category><![CDATA[Windows]]></category>

		<guid isPermaLink="false">http://www.msuiche.net/2007/12/06/enter-sandman-japan-pacsec-2007/</guid>
		<description><![CDATA[For people who wasn&#8217;t (or was :)) at PacSec the last week. Slides of Sandman lecture can be found in Japanese[PPT] or in English (updated  &#8211; last version) [PDF]. 
[JP] http://www.msuiche.net/pres/psj07ruffsuiche-jp.pdf
[EN] http://www.msuiche.net/pres/PacSec07-slides-0.4.pdf
An overview of hibernation file format is explained and the forensics library we called Sandman is introduced.
Sandman status is reachable here :
http://sandman.msuiche.net/
]]></description>
			<content:encoded><![CDATA[<p>For people who wasn&#8217;t (or was :)) at PacSec the last week. Slides of Sandman lecture can be found in <a href="http://www.msuiche.net/pres/psj07ruffsuiche-jp.pdf">Japanese</a>[PPT] or in <a href="http://www.msuiche.net/pres/PacSec07-slides-0.4.pdf">English</a> (updated  &#8211; last version) [PDF]. </p>
<p>[JP] <a href="http://www.msuiche.net/pres/psj07ruffsuiche-jp.pdf">http://www.msuiche.net/pres/psj07ruffsuiche-jp.pdf</a><br />
[EN] <a href="http://www.msuiche.net/pres/PacSec07-slides-0.4.pdf">http://www.msuiche.net/pres/PacSec07-slides-0.4.pdf</a></p>
<p>An overview of hibernation file format is explained and the forensics library we called Sandman is introduced.</p>
<p>Sandman status is reachable here :<br />
<a href="http://sandman.msuiche.net/">http://sandman.msuiche.net/</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.msuiche.net/2007/12/06/enter-sandman-japan-pacsec-2007/feed/</wfw:commentRss>
		<slash:comments>4</slash:comments>
		</item>
		<item>
		<title>Enter sandman&#8230; :)</title>
		<link>http://www.msuiche.net/2007/10/22/enter-sandman/</link>
		<comments>http://www.msuiche.net/2007/10/22/enter-sandman/#comments</comments>
		<pubDate>Mon, 22 Oct 2007 19:08:04 +0000</pubDate>
		<dc:creator>Matthieu Suiche</dc:creator>
				<category><![CDATA[Presentations]]></category>
		<category><![CDATA[Reverse Engineering]]></category>
		<category><![CDATA[Windows]]></category>

		<guid isPermaLink="false">http://www.msuiche.net/2007/10/22/enter-sandman/</guid>
		<description><![CDATA[Everyone knows that Dumbledore is homosexual but there is a most important thing you have to know!
The PacSec Agenda had been released! http://www.securityfocus.com/archive/1/482602/30/0/threaded
Speaker list: 
http://www.pacsec.jp/speakers.html
Talk selections for PacSec 2007 - November 29 and 30 - Aoyama Diamond Hall
-------
- Programmed I/O accesses: a threat to virtual machine monitors? -
 Loic Duflot,
- Developing Fuzzers with Peach -
Michael [...]]]></description>
			<content:encoded><![CDATA[<p>Everyone knows that <a href="http://theknightshift.blogspot.com/2007/10/jk-rowling-says-albus-dumbledore-is.html">Dumbledore is homosexual</a> but there is a most important thing you have to know!</p>
<p>The PacSec Agenda had been released! <a href="http://www.securityfocus.com/archive/1/482602/30/0/threaded">http://www.securityfocus.com/archive/1/482602/30/0/threaded</a><br />
Speaker list: <a href="http://www.pacsec.jp/speakers.html"><br />
http://www.pacsec.jp/speakers.html</a></p>
<p><code>Talk selections for <a href="http://www.pacsec.jp">PacSec</a> 2007 - November 29 and 30 - Aoyama Diamond Hall</p>
<p>-------<br />
- Programmed I/O accesses: a threat to virtual machine monitors? -<br />
<i> Loic Duflot,</i></p>
<p>- Developing Fuzzers with Peach -<br />
<i>Michael Eddington, Leviathan Security</i></p>
<p>- Cyber Attacks Against Japan -<br />
<i> Hiroshi Kawaguchi, LAC</i></p>
<p>- Windows Localization: Owning Asian Windows Versions -<br />
<i> Kostya Kortchinsky, Immunity</i></p>
<p>- TOMOYO Linux -<br />
<i>Toshiharu Harada, NTT Data </i></p>
<p>- IPV6 Demystified -<br />
<i>Jun-ichiro itojun Hagino , IPv6Samurais</i></p>
<p>- Automated JavaScript Deobfuscation -<br />
<i>Alex Rice, Websense Security Labs</i></p>
<p><strong>- Enter Sandman (why you should never go to sleep) -<br />
<i> Nicolas Ruff &#038; Matthieu Suiche, EADS</i></strong></p>
<p>- Agent-oriented SQL Abuse -<br />
<i> Fernando Russ &#038; Diego Tiscornia, Core</i></p>
<p>- Bad Ideas: Using a JVM/CLR for Intellectual Property Protection<br />
<i> Marc Schoenefeld, University of Bamberg</i></p>
<p>- Heap exploits are dead. Heap exploits remain dead. And we have killed them.<br />
<i>Nicolas Waisman, Immunity</i></p>
<p>- Deploying and operating a Global Distributed Honeynet<br />
<i>David Watson, Honeynet Project</i></p>
<p>- Office 0days and the people who love them<br />
<i>TBA, Microsoft</i><br />
.<br />
(I would also like to thank Colin Delaney and Stephen Ridley as standby<br />
presenters)</p>
<p>------</code></p>
<p>The topic is talking about forensic/hiberation under Windows. More information will be available in November&#8230;</p>
]]></content:encoded>
			<wfw:commentRss>http://www.msuiche.net/2007/10/22/enter-sandman/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Translation of my &#8220;Patchguard alternative theory&#8221; presentation!</title>
		<link>http://www.msuiche.net/2006/12/24/translation-of-my-patchguard-alternative-theory-presentation/</link>
		<comments>http://www.msuiche.net/2006/12/24/translation-of-my-patchguard-alternative-theory-presentation/#comments</comments>
		<pubDate>Sun, 24 Dec 2006 19:01:57 +0000</pubDate>
		<dc:creator>Matthieu Suiche</dc:creator>
				<category><![CDATA[Presentations]]></category>
		<category><![CDATA[Reverse Engineering]]></category>
		<category><![CDATA[Windows]]></category>

		<guid isPermaLink="false">http://www.msuiche.net/?p=12</guid>
		<description><![CDATA[I did a translation into English of my previous presentation which explain how to realize a protector for IDT, SSDT, and syscall address on Windows 32 and 64bits.
The translation can be found at the following link : Windows Vista Kernel Security &#8211; [EN].ppt
I&#8217;m writting an article about it which will be released very soon.
Happy merry [...]]]></description>
			<content:encoded><![CDATA[<p>I did a translation into English of my previous presentation which explain how to realize a protector for IDT, SSDT, and syscall address on Windows 32 and 64bits.</p>
<p>The translation can be found at the following link : <a href="http://www.msuiche.net/pres/Windows Vista Kernel Security - [EN].ppt">Windows Vista Kernel Security &#8211; [EN].ppt</a></p>
<p>I&#8217;m writting an article about it which will be released very soon.</p>
<p>Happy merry xmas !</p>
]]></content:encoded>
			<wfw:commentRss>http://www.msuiche.net/2006/12/24/translation-of-my-patchguard-alternative-theory-presentation/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>OSSIR &#8211; Windows Vista Kernel Security</title>
		<link>http://www.msuiche.net/2006/12/11/ossir-windows-vista-kernel-security/</link>
		<comments>http://www.msuiche.net/2006/12/11/ossir-windows-vista-kernel-security/#comments</comments>
		<pubDate>Mon, 11 Dec 2006 20:22:02 +0000</pubDate>
		<dc:creator>Matthieu Suiche</dc:creator>
				<category><![CDATA[Presentations]]></category>
		<category><![CDATA[Reverse Engineering]]></category>
		<category><![CDATA[Windows]]></category>

		<guid isPermaLink="false">http://www.msuiche.net/?p=10</guid>
		<description><![CDATA[Hi there,
Today I did a presentation at the French Engineer School named Ecole Normal Supérieur. French Slides can be found at the following link OSSIR &#8211; Windows Vista Kernel Security.
In this presentation I&#8217;m showing an alternative theory to Patchguard on Windows Vista 32/64bits. 
An article will be soon available.
]]></description>
			<content:encoded><![CDATA[<p>Hi there,</p>
<p>Today I did a presentation at the French Engineer School named Ecole Normal Supérieur. French Slides can be found at the following link <a href="http://www.msuiche.net/pres/OSSIR - Windows Vista Kernel Security - v1.1.ppt">OSSIR &#8211; Windows Vista Kernel Security</a>.</p>
<p>In this presentation I&#8217;m showing an alternative theory to Patchguard on Windows Vista 32/64bits. </p>
<p>An article will be soon available.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.msuiche.net/2006/12/11/ossir-windows-vista-kernel-security/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
