Site uses cookies to provide basic functionality.
Javascript rendering is set to off by default when visiting the site via .onion and .i2p domains. It can be enabled back again in user's settings section. Javascript rendering set to off means, that you can disable javascript in your browser now and the site will remain functional.
There is also IRC server now available via native IRC clients or non javascript web based one.
Fonts can be adjusted in user's settings section as well.
Check FAQ for more.

OK

Technology trends are treacherous. Should you learn java or visual basic? Pay for Windows or download Linux? Will that investment in Bluetooth pay off? Or will you get suckered by a faddish book written by a fading technology guru? You can't know the future (yet), but you can make educated guesses and tilt the odds in your favor. Meme Miner is a simple program for trend tracking. Its power lies in the business and social bandwidth conc....

Technology trends are treacherous. Should you learn java or visual basic? Pay for Windows or download Linux? Will that investment in Bluetooth pay off? Or will you get suckered by a faddish book written by a fading technology guru? You can't know the future (yet), but you can make educated guesses and tilt the odds in your favor. Meme Miner is a simple program for trend tracking. Its power lies in the business and social bandwidth conc....

Computer use in elementary schools is problematic. Seldom are computers well integrated into the general curriculum. Often, they are used merely as instructional surrogates to "drill" skills. Particularly disturbing is the lack of exploration of the computer itself, and the culture of technology. Programming can teach vital problem solving skills, project management, respect for others work, and the value of collaboration. So why not cultiv....

Computer use in elementary schools is problematic. Seldom are computers well integrated into the general curriculum. Often, they are used merely as instructional surrogates to "drill" skills. Particularly disturbing is the lack of exploration of the computer itself, and the culture of technology. Programming can teach vital problem solving skills, project management, respect for others work, and the value of collaboration. So why not cultiv....

Trust Transience: Post Intrusion SSH Hijacking explores the issues of transient trust relationships between hosts, and how to exploit them. Applying technique from anti-forensics, linux VXers, and some good-ole-fashioned blackhat creativity, a concrete example is presented in the form of a post-intrusion transparent SSH connection hijacker. The presentation covers the theory, a real world demonstration, the implementation of the SSH Hijacke....

A unique opportunity to surrender and confess all of your crimes to law enforcement agents from multiple federal and possibly international agencies. The "Meet the Fed" Panel is again chaired by Special Agent Jim Christy, Director of the Department of Defense Cyber Crime Institute. Jim will have on his panel representatives from: * Department of Defense Cyber Crime Center (DoD) * The Internal Revenue Service (IRS - always a favorite)..

Trust Transience: Post Intrusion SSH Hijacking explores the issues of transient trust relationships between hosts, and how to exploit them. Applying technique from anti-forensics, linux VXers, and some good-ole-fashioned blackhat creativity, a concrete example is presented in the form of a post-intrusion transparent SSH connection hijacker. The presentation covers the theory, a real world demonstration, the implementation of the SSH Hijacke....

A unique opportunity to surrender and confess all of your crimes to law enforcement agents from multiple federal and possibly international agencies. The "Meet the Fed" Panel is again chaired by Special Agent Jim Christy, Director of the Department of Defense Cyber Crime Institute. Jim will have on his panel representatives from: * Department of Defense Cyber Crime Center (DoD) * The Internal Revenue Service (IRS - always a favorite)..

Do you ever find your self wondering if good social engineers and highly influential people are just born that way? Well, you might be surprised to find out that any human skill can be duplicated including being a master at influence. This is what forms the basis for a field of study known as NLP or Neuro-Linguistic-Programming. In this talk I will give an introduction to what NLP is and how it is used and will also provide you with some to..

Do you ever find your self wondering if good social engineers and highly influential people are just born that way? Well, you might be surprised to find out that any human skill can be duplicated including being a master at influence. This is what forms the basis for a field of study known as NLP or Neuro-Linguistic-Programming. In this talk I will give an introduction to what NLP is and how it is used and will also provide you with some to..

As the demand for mobile internet access increases, more and more public wireless access points are becoming available for general usage. Unfortunately, as awareness of these access points increases, some companies have been capitalizing on the idea, charging monthly and hourly rates. This talk discusses methods of silently bypassing current implementations of authenticated wireless networks. An automated proof of concept tool is rele....

As the demand for mobile internet access increases, more and more public wireless access points are becoming available for general usage. Unfortunately, as awareness of these access points increases, some companies have been capitalizing on the idea, charging monthly and hourly rates. This talk discusses methods of silently bypassing current implementations of authenticated wireless networks. An automated proof of concept tool is rele....

Roberto Preatoni (aka Sys64738), Fabio Ghioni The speech will be intended to let the attendees understand where and how the digital conflicts are conducted today but we will dig deeply into the future. We will take as example the US Army program F.C.S. (Future Combat System) as the perfect example on how a developed superpower might carry on a super-advanced war program, all based on combat computer systems and networks that control un....

Roberto Preatoni (aka Sys64738), Fabio Ghioni The speech will be intended to let the attendees understand where and how the digital conflicts are conducted today but we will dig deeply into the future. We will take as example the US Army program F.C.S. (Future Combat System) as the perfect example on how a developed superpower might carry on a super-advanced war program, all based on combat computer systems and networks that control un....

Despite its crucial importance, the network backbone is often ignored or exempted from security testing. This talk will cover how to sanely and effectively perform a pen-test against routers, switches, and similar network infrastructure equipment. Avenues of attack will range from the physical to the routing protocol-based, from the local to the remote, and suggested mitigation measures will also be discussed. Raven splits her time bet..

Despite its crucial importance, the network backbone is often ignored or exempted from security testing. This talk will cover how to sanely and effectively perform a pen-test against routers, switches, and similar network infrastructure equipment. Avenues of attack will range from the physical to the routing protocol-based, from the local to the remote, and suggested mitigation measures will also be discussed. Raven splits her time bet..

Security threats to PDAs and mobiles become more and more serious. This presentation will show a buffer overflow exploitation example in Windows CE. It will cover some knowledge about ARM architecture and memory management, the features of processes and threads of Windows CE. It alse show how to write a shellcode in Windows CE (including some knowledge about decoding shellcode of Windows CE with ARM processor), and a live attack demonstrati..

Security threats to PDAs and mobiles become more and more serious. This presentation will show a buffer overflow exploitation example in Windows CE. It will cover some knowledge about ARM architecture and memory management, the features of processes and threads of Windows CE. It alse show how to write a shellcode in Windows CE (including some knowledge about decoding shellcode of Windows CE with ARM processor), and a live attack demonstrati..

Bruce Potter, Beetle, CowboyM, Dan Moniz, Rodney Thayer, 3ricj, Pablos all speaking on behalf of the Shmoo Group Last Summer, they dared to make a Wi-Fi sniper rifle that fried their eyeballs and scared the crap out of UPS. They built a robot that owned your Mom's access point and showed you the password to her underwear drawer, too. Last Winter, they ran up a $3000 bar tab at a nightclub in D.C. with several hundred ShmooCon attendees....

Bruce Potter, Beetle, CowboyM, Dan Moniz, Rodney Thayer, 3ricj, Pablos all speaking on behalf of the Shmoo Group Last Summer, they dared to make a Wi-Fi sniper rifle that fried their eyeballs and scared the crap out of UPS. They built a robot that owned your Mom's access point and showed you the password to her underwear drawer, too. Last Winter, they ran up a $3000 bar tab at a nightclub in D.C. with several hundred ShmooCon attendees....

Documentaries have a place in telling the history and story of many different cultures and events, but documentaries about technical subjects tend to run into common problems: too light, too wrong, too hated. Is the patient terminal? Can you create a film that is both informative and of interest to a general audience? Having spent 4 years creating a tech documentary of his own on the era of the Dial-up Bulletin Board system, Jason Scot....

Documentaries have a place in telling the history and story of many different cultures and events, but documentaries about technical subjects tend to run into common problems: too light, too wrong, too hated. Is the patient terminal? Can you create a film that is both informative and of interest to a general audience? Having spent 4 years creating a tech documentary of his own on the era of the Dial-up Bulletin Board system, Jason Scot....

How far can automation be taken? How much intelligence can be embodied in code? How generic can automated IT security assessment tools really be? This presentation will attempt to show which areas of attacks lend themselves to automation and which aspects should best be left for manual human inspection and analyses. SensePost will provide the audience a glimpse of BiDiBLAH - an attempt to automate a focussed yet comprehensive assessmen....

How far can automation be taken? How much intelligence can be embodied in code? How generic can automated IT security assessment tools really be? This presentation will attempt to show which areas of attacks lend themselves to automation and which aspects should best be left for manual human inspection and analyses. SensePost will provide the audience a glimpse of BiDiBLAH - an attempt to automate a focussed yet comprehensive assessmen....

Proper recovery of evidence can be critical to a successful investigation or prosecution. This talk focuses on the different tools and techniques that are used by US Law Enforcement to get an uncontaminated copy of digital evidence from a suspect machine. The goal of this presentation is to teach not only how to copy all the data from a suspect machine, but also to instruct on how to make sure that any evidence collected can be used in cour..

Proper recovery of evidence can be critical to a successful investigation or prosecution. This talk focuses on the different tools and techniques that are used by US Law Enforcement to get an uncontaminated copy of digital evidence from a suspect machine. The goal of this presentation is to teach not only how to copy all the data from a suspect machine, but also to instruct on how to make sure that any evidence collected can be used in cour..

WarDriving is becoming a popular sport among hackers and DEF CON attendees, and WiFi site surveying has become an important tool for the IT security professional. This workshop will describe the basic equipment required for WarDriving and WiFi site surveying. There will be a brief presentation on the benefits and features of different types of WiFi hardware, adapter cards, chipsets, cables, pigtails, and antennas. The session will include a....

WarDriving is becoming a popular sport among hackers and DEF CON attendees, and WiFi site surveying has become an important tool for the IT security professional. This workshop will describe the basic equipment required for WarDriving and WiFi site surveying. There will be a brief presentation on the benefits and features of different types of WiFi hardware, adapter cards, chipsets, cables, pigtails, and antennas. The session will include a....

Matthew L. Shuchman ("Pilgrim"), Frank Thornton, Blackthorn Systems ("Thorn"), Robert V. Hale II, Lawyer This is a proposal for a panel discussion on the legality of accessing WiFi signals without the permission of the owner and will include a review of the legal and ethical issues presented by freely available WiFi both to the owner of the AP and to the users. Included in the panel will be a presentation of recent cases involving....

Matthew L. Shuchman ("Pilgrim"), Frank Thornton, Blackthorn Systems ("Thorn"), Robert V. Hale II, Lawyer This is a proposal for a panel discussion on the legality of accessing WiFi signals without the permission of the owner and will include a review of the legal and ethical issues presented by freely available WiFi both to the owner of the AP and to the users. Included in the panel will be a presentation of recent cases involving....

Simple Nomad, NMRC NMRC Collective: HellNBak, Disturbing; ertia,  Weasel,  jrandom, MadHat, Lock up your children and mid-sized barnyard animals, NMRC is coming to DEF CON13. From their underground bunker located somewhere in North America, NMRC will emerge with your basic shitload of handy tools and toys, geared for helping the humble hacker in everyday chores. Look for crypto, utilities, and other hackerish tools to bring your hac....

Simple Nomad, NMRC NMRC Collective: HellNBak, Disturbing; ertia,  Weasel,  jrandom, MadHat, Lock up your children and mid-sized barnyard animals, NMRC is coming to DEF CON13. From their underground bunker located somewhere in North America, NMRC will emerge with your basic shitload of handy tools and toys, geared for helping the humble hacker in everyday chores. Look for crypto, utilities, and other hackerish tools to bring your hac....

Increasingly, users are adding licensing agreements to all of their online content. One of the most popular licensing agreements for non-coders is the Creative Commons license. Its integration into several popular web products and ease of use have quickly made it the standard license for bloggers. While the Creative Commons provides a "human readable" version of the license, that version doesn't tell the whole story. There are several right....

Buffer overflow attacks are known to be the most common type of attacks that allow attackers to hijack a remote system by sending a specially crafted packet to a vulnerable network application running on it. A comprehensive defense strategy against such attacks should include (1) an attack detection component that determines the fact that a program is compromised and prevents the attack from further propagation, (2) an attack identification....

Increasingly, users are adding licensing agreements to all of their online content. One of the most popular licensing agreements for non-coders is the Creative Commons license. Its integration into several popular web products and ease of use have quickly made it the standard license for bloggers. While the Creative Commons provides a "human readable" version of the license, that version doesn't tell the whole story. There are several right....

Buffer overflow attacks are known to be the most common type of attacks that allow attackers to hijack a remote system by sending a specially crafted packet to a vulnerable network application running on it. A comprehensive defense strategy against such attacks should include (1) an attack detection component that determines the fact that a program is compromised and prevents the attack from further propagation, (2) an attack identification....

The AdWords program is an advertising system used by Google. It is a pay-per-click system like may others but Google doesn't give it the attention to design that it deserves. Not only does Google take some liberties with the Terms of Service and what they allow and don't allow in the program, but also have several flaws in the logical design of the system. There are several loopholes in this system and they will be explained and demonstrate..

The AdWords program is an advertising system used by Google. It is a pay-per-click system like may others but Google doesn't give it the attention to design that it deserves. Not only does Google take some liberties with the Terms of Service and what they allow and don't allow in the program, but also have several flaws in the logical design of the system. There are several loopholes in this system and they will be explained and demonstrate..

Last year at Black Hat, we introduced the rootkit FU. FU took an unprecented approach to hiding not previously seen before in a Windows rootkit. Rather than patching code or modifying function pointers in well known operating system structures like the system call table, FU demonstrated that is was possible to control the execution path indirectly by modifying private kernel objects in memory. This technique was coined DKOM, or Direct Kerne....

Last year at Black Hat, we introduced the rootkit FU. FU took an unprecented approach to hiding not previously seen before in a Windows rootkit. Rather than patching code or modifying function pointers in well known operating system structures like the system call table, FU demonstrated that is was possible to control the execution path indirectly by modifying private kernel objects in memory. This technique was coined DKOM, or Direct Kerne....

The purpose of this paper is to explain and introduce the free culture movement and organization to the hacker community. We make the case that hackers should not only care about the ideas of free culture in the literal sense in that we seek to protect technological and digital rights, but also in a broader cultural sense. The idea of using and reusing bits of culture(the goal in a free culture) parallels the central tenets of the hacker et....

The purpose of this paper is to explain and introduce the free culture movement and organization to the hacker community. We make the case that hackers should not only care about the ideas of free culture in the literal sense in that we seek to protect technological and digital rights, but also in a broader cultural sense. The idea of using and reusing bits of culture(the goal in a free culture) parallels the central tenets of the hacker et....

Alex Stamos, Founding Partner, Information Security Partners Scott Stender, Founding Partner, iSEC Partners, LLC Web Services represent a new and unexplored set of security-sensitive technologies that have been widely deployed by large companies, governments, financial institutions, and in consumer applications. Unfortunately, the attributes that make web services attractive, such as their ease of use, platform independence, use o....

Alex Stamos, Founding Partner, Information Security Partners Scott Stender, Founding Partner, iSEC Partners, LLC Web Services represent a new and unexplored set of security-sensitive technologies that have been widely deployed by large companies, governments, financial institutions, and in consumer applications. Unfortunately, the attributes that make web services attractive, such as their ease of use, platform independence, use o....

114 visitors online