We had a pretty good line up this time. Steven gave us a preview of his submission to Schmoocon. Dave pointed out some command injection using various stock Perl modules in Linux. vesh gave a talk on the mystery of the urlmon call “FileBearsMarkOfTheWeb” and the safety of using the WinHTTP and Wininet libraries in your RAT. Cruxpot showed off his version of the DEFCON portal tool from this years’ con.