Address
304 North Cardinal St.
Dorchester Center, MA 02124
Work Hours
Monday to Friday: 7AM - 7PM
Weekend: 10AM - 5PM
Address
304 North Cardinal St.
Dorchester Center, MA 02124
Work Hours
Monday to Friday: 7AM - 7PM
Weekend: 10AM - 5PM
I got the chance to attend ShmooCon 2017, and it was definitely enjoyable for my first Shmoo.
This is actually where I got even luckier than I realized. I had a co-worker buy two tickets on the first release after asking if I wanted to go with him. He was able to get them, and then everyone I spoke to told me that it might be the last time I get tickets unless I work for a sponsor. That said, if he could do it, so can you!
While I’ve been to D.C. before, going for an actual conference was a nice change.
Driving is never the best, but I caught a ride with a coworker and only had to perform navigational duties.
As far as the neighborhood the hotel was in, it was nice enough, but I could have used a few more shops/restaurants within walking distance. That said, I had forgotten how expensive D.C. was. While I was only there for a few days, every time I had to spend $8 on a beer or $14 on a burger I wasn’t that excited.
All in all, it’s a nice place to have a con, and it was good to spend some more time in that area of D.C. again.
Unfortunately, there wasn’t a lot in the way of CTFs there. That said, the Wireless CTF seemed pretty popular, but my lack of skills and recviking‘s lack of gear meant we couldn’t do much.
I did grab a few flags in G2’s Switches Get Stiches (their spelling, not mine) CTF for a free shirt/shot glass, but that was about it.
While there wasn’t a CTF to my liking, it also meant that I got to go to more talks!
You can find the videos for these, and the rest of the talks, on archive.org.
Here are a few of the talks that I really liked, or plan on looking into more.
I’d be lying if I didn’t say I probably spent most of my time playing against SmashBot. As a former (current?) Melee player AND a pentester, this felt like the perfect intersection of my two hobbies. Initially, I tried to play it as if it was a regular Melee opponent, which obviously didn’t work. After a few tries, I realized that it was just a black box penetration test, and started my fuzzing. I was able to take quite a number of notes against it, and ended up finding quite a few vulnerabilities. In the end, I was able to beat it twice and get up to 158% damage.
I may try to post a bit more about this in a separate post, so that’s all about it for now. That said, if you have some controllers, I recommend installing Dolphin and giving it a try.
I think this was the con that I left with the most free stuff as well. Nothing too exciting, but a bunch of nice shirts, some shot glasses, and a few more bottle openers.
ShmooCon was definitely fun, and in the realm of DerbyCon as far as size and atmosphere. I’d like to go back, but with the cost of DC and the difficulty to get tickets, it won’t be the highest on my priority list. I do recommend it though, but you might have to pickups tickets from work/Twitter.
Ray Doyle is an avid pentester/security enthusiast/beer connoisseur who has worked in IT for almost 16 years now. From building machines and the software on them, to breaking into them and tearing it all down; he’s done it all. To show for it, he has obtained an OSCE, OSCP, eCPPT, GXPN, eWPT, eWPTX, SLAE, eMAPT, Security+, ICAgile CP, ITIL v3 Foundation, and even a sabermetrics certification!
He currently serves as a Senior Staff Adversarial Engineer for Avalara, and his previous position was a Principal Penetration Testing Consultant for Secureworks.
This page contains links to products that I may receive compensation from at no additional cost to you. View my Affiliate Disclosure page here. As an Amazon Associate, I earn from qualifying purchases.
Hi
This is Charles here – We have a mega resource of events that take place around the world for those interested in Cybersecurity Conferences.
I was wondering whether you might include our Cybersecurity Conference Directory in your blog posts?
Our directory resource is here (which lists over 500+ events!!). – https://infosec-conferences.com/
Let me know if you’d like us to post a link or article to one of your websites – we’d be happy to reciprocate the link!
Thanks!
Kind regards
Charles
Hi Charles,
Awesome, and I’ve included it!
Feel free to link to any, though especially my tool releases.
Thanks,
Ray
[…] ShmooCon 2017 – More Talks, More Moose, More Fun! […]