Site uses cookies to provide basic functionality.
Javascript rendering is set to off by default when visiting the site via .onion and .i2p domains. It can be enabled back again in user's settings section. Javascript rendering set to off means, that you can disable javascript in your browser now and the site will remain functional.
There is also IRC server now available via native IRC clients or non javascript web based one.
Fonts can be adjusted in user's settings section as well.
Check FAQ for more.

OK

Copy of the slides for this talk are here: http://m6rqq6kocsyugo2laitup5nn32bwm3lh677chuodjfmggczoafzwfcad.onion/dc-20/presentations/Xenofex/DEFCON-20-Xenofex-Panel-Hacking-the-GoogleTV.pdf Hacking the Google TV Amir "Zenofex" Etemadieh CJ Heres Dan Rosenberg Tom "tdweng" Dwenger The GoogleTV platform is designed to bring an integrated web experience, utilizing the Chrome web browser and Android applications, to your tele....

Copy of the slides for this talk are here: http://m6rqq6kocsyugo2laitup5nn32bwm3lh677chuodjfmggczoafzwfcad.onion/dc-20/presentations/Fasel/DEFCON-20-Fasel-Owned-in-60-Seconds.pdf Owned in 60 Seconds: From Network Guest to Windows Domain Admin Zack Fasel Their systems were fully patched, their security team watching, and the amateur pentesters just delivered their "compliant" report. They thought their Windows domain was secure. Th....

Copy of the slides for this talk are here: http://m6rqq6kocsyugo2laitup5nn32bwm3lh677chuodjfmggczoafzwfcad.onion/dc-20/presentations/Floren/DEFCON-20-Floren-Hellaphone.pdf Hellaphone: Replacing the Java in Android John Floren Senior Member of Technical Staff, Sandia National Labs Android is the only widespread open-source phone environment available today, but actually hacking on it can be an exercise in frustration, with ove....

Hacking [Redacted] Routers FX Leader, Phenoelit Group, Recurity Labs Greg Recurity Labs [Redacted] routers are no longer devices only seen in [Redacted]. Entire countries run their Internet infrastructure exclusively on these products and established tier 1 ISPs make increasing use of them. However, very little is known of [Redacted]'s Software Platform and its security. This presentation will introduce the architecture, special pr....

Demorpheus: Getting Rid Of Polymorphic Shellcodes In Your Network Svetlana Gaivoronski PhD Student, Moscow State University Dennis Gamayunov Senior Researcher, Moscow State University One of the most effective techniques used in CTF is the usage of various exploits, written with the help of well-known tools or even manually during the game. Experience in CTF participation shows that the mechanism for detecting such exploits is able....

New Techniques in SQLi Obfuscation: SQL never before used in SQLi Nick Galbreath SQLi remains a popular sport in the security arms-race. However, after analysis of hundreds of thousands of real world SQLi attacks, output from SQLi scanners, published reports, analysis of WAF source code, and database vendor documentation, both SQLi attackers and defenders have missed a few opportunities. This talk will iterate through the dark corner....

Uncovering SAP Vulnerabilities: Reversing and Breaking the Diag Protocol Martin Gallo Security Consultant, Core Security Nowadays, SAP Netweaver has become the most extensive platform for building enterprise applications and run critical business processes. In recent years it has become a hot topic in information security. However, while fixes and countermeasures are released monthly by SAP at an incredible rate, the available securi....

Post-Exploitation Nirvana: Launching OpenDLP Agents over Meterpreter Sessions Andrew Gavin Security Consultant, Verizon Business Michael Baucom Vice President of R&D, N2 Net Security Inc. Charles Smith Software Developer, N2 Net Security Inc. OpenDLP is a free and open source agent-based data discovery tool that works against Microsoft Windows systems using appropriate authentication credentials. However, one drawback to OpenDLP ....

Hacking [Redacted] Routers FX Leader, Phenoelit Group, Recurity Labs Greg Recurity Labs [Redacted] routers are no longer devices only seen in [Redacted]. Entire countries run their Internet infrastructure exclusively on these products and established tier 1 ISPs make increasing use of them. However, very little is known of [Redacted]'s Software Platform and its security. This presentation will introduce the architecture, special....

Copy of the slides for this talk are here: http://m6rqq6kocsyugo2laitup5nn32bwm3lh677chuodjfmggczoafzwfcad.onion/dc-20/presentations/Svetlana-Gaivoronski/DEFCON-20-Svetlana-Gaivoronski-Demorpheus.pdf Demorpheus: Getting Rid Of Polymorphic Shellcodes In Your Network Svetlana Gaivoronski PhD Student, Moscow State University Dennis Gamayunov Senior Researcher, Moscow State University One of the most effective techniques used in CT....

Copy of the slides for this talk are here:http://m6rqq6kocsyugo2laitup5nn32bwm3lh677chuodjfmggczoafzwfcad.onion/dc-20/presentations/Galbreath/DEFCON-20-Galbreath-SQLi-Obfuscation.pdf New Techniques in SQLi Obfuscation: SQL never before used in SQLi Nick Galbreath SQLi remains a popular sport in the security arms-race. However, after analysis of hundreds of thousands of real world SQLi attacks, output from SQLi scanners, publi....

Copy of the slides for this talk are here: http://m6rqq6kocsyugo2laitup5nn32bwm3lh677chuodjfmggczoafzwfcad.onion/dc-20/presentations/Gallo/DEFCON-20-Gallo-Uncovering-SAP-Vulnerabilities.pdf Uncovering SAP Vulnerabilities: Reversing and Breaking the Diag Protocol Martin Gallo Security Consultant, Core Security Nowadays, SAP Netweaver has become the most extensive platform for building enterprise applications and run critical b....

Copy of the slides for this talk are here:http://m6rqq6kocsyugo2laitup5nn32bwm3lh677chuodjfmggczoafzwfcad.onion/dc-20/presentations/Gavin-Baucom-Smith/DEFCON-20-Gavin-Baucom-Smith-OpenDLP.pdf Post-Exploitation Nirvana: Launching OpenDLP Agents over Meterpreter Sessions R&D Andrew Gavin Security Consultant, Verizon Business Michael Baucom Vice President of R&D, N2 Net Security Inc. Charles Smith Software Developer, N2 Net Secur....

Hacking [Redacted] Routers FX Leader, Phenoelit Group, Recurity Labs Greg Recurity Labs [Redacted] routers are no longer devices only seen in [Redacted]. Entire countries run their Internet infrastructure exclusively on these products and established tier 1 ISPs make increasing use of them. However, very little is known of [Redacted]'s Software Platform and its security. This presentation will introduce the architecture, special....

Copy of the slides for this talk are here: http://m6rqq6kocsyugo2laitup5nn32bwm3lh677chuodjfmggczoafzwfcad.onion/dc-20/presentations/Svetlana-Gaivoronski/DEFCON-20-Svetlana-Gaivoronski-Demorpheus.pdf Demorpheus: Getting Rid Of Polymorphic Shellcodes In Your Network Svetlana Gaivoronski PhD Student, Moscow State University Dennis Gamayunov Senior Researcher, Moscow State University One of the most effective techniques used in CT....

Copy of the slides for this talk are here:http://m6rqq6kocsyugo2laitup5nn32bwm3lh677chuodjfmggczoafzwfcad.onion/dc-20/presentations/Galbreath/DEFCON-20-Galbreath-SQLi-Obfuscation.pdf New Techniques in SQLi Obfuscation: SQL never before used in SQLi Nick Galbreath SQLi remains a popular sport in the security arms-race. However, after analysis of hundreds of thousands of real world SQLi attacks, output from SQLi scanners, publi....

Copy of the slides for this talk are here: http://m6rqq6kocsyugo2laitup5nn32bwm3lh677chuodjfmggczoafzwfcad.onion/dc-20/presentations/Gallo/DEFCON-20-Gallo-Uncovering-SAP-Vulnerabilities.pdf Uncovering SAP Vulnerabilities: Reversing and Breaking the Diag Protocol Martin Gallo Security Consultant, Core Security Nowadays, SAP Netweaver has become the most extensive platform for building enterprise applications and run critical b....

Copy of the slides for this talk are here:http://m6rqq6kocsyugo2laitup5nn32bwm3lh677chuodjfmggczoafzwfcad.onion/dc-20/presentations/Gavin-Baucom-Smith/DEFCON-20-Gavin-Baucom-Smith-OpenDLP.pdf Post-Exploitation Nirvana: Launching OpenDLP Agents over Meterpreter Sessions R&D Andrew Gavin Security Consultant, Verizon Business Michael Baucom Vice President of R&D, N2 Net Security Inc. Charles Smith Software Developer, N2 Net Secur....

Hacking [Redacted] Routers FX Leader, Phenoelit Group, Recurity Labs Greg Recurity Labs [Redacted] routers are no longer devices only seen in [Redacted]. Entire countries run their Internet infrastructure exclusively on these products and established tier 1 ISPs make increasing use of them. However, very little is known of [Redacted]'s Software Platform and its security. This presentation will introduce the architecture, special....

Copy of the slides for this talk are here: http://m6rqq6kocsyugo2laitup5nn32bwm3lh677chuodjfmggczoafzwfcad.onion/dc-20/presentations/Svetlana-Gaivoronski/DEFCON-20-Svetlana-Gaivoronski-Demorpheus.pdf Demorpheus: Getting Rid Of Polymorphic Shellcodes In Your Network Svetlana Gaivoronski PhD Student, Moscow State University Dennis Gamayunov Senior Researcher, Moscow State University One of the most effective techniques used in CT....

Copy of the slides for this talk are here:http://m6rqq6kocsyugo2laitup5nn32bwm3lh677chuodjfmggczoafzwfcad.onion/dc-20/presentations/Galbreath/DEFCON-20-Galbreath-SQLi-Obfuscation.pdf New Techniques in SQLi Obfuscation: SQL never before used in SQLi Nick Galbreath SQLi remains a popular sport in the security arms-race. However, after analysis of hundreds of thousands of real world SQLi attacks, output from SQLi scanners, publi....

Copy of the slides for this talk are here: http://m6rqq6kocsyugo2laitup5nn32bwm3lh677chuodjfmggczoafzwfcad.onion/dc-20/presentations/Gallo/DEFCON-20-Gallo-Uncovering-SAP-Vulnerabilities.pdf Uncovering SAP Vulnerabilities: Reversing and Breaking the Diag Protocol Martin Gallo Security Consultant, Core Security Nowadays, SAP Netweaver has become the most extensive platform for building enterprise applications and run critical b....

Copy of the slides for this talk are here:http://m6rqq6kocsyugo2laitup5nn32bwm3lh677chuodjfmggczoafzwfcad.onion/dc-20/presentations/Gavin-Baucom-Smith/DEFCON-20-Gavin-Baucom-Smith-OpenDLP.pdf Post-Exploitation Nirvana: Launching OpenDLP Agents over Meterpreter Sessions R&D Andrew Gavin Security Consultant, Verizon Business Michael Baucom Vice President of R&D, N2 Net Security Inc. Charles Smith Software Developer, N2 Net Secur....

The Art of Cyberwar Kenneth Geers NCIS Cyber Subject Matter Expert The establishment of US Cyber Command in 2010 confirmed that cyberspace is a new domain of warfare. Computers are now both a weapon and a target. Future wars may even be fought over the ownership of IT infrastructure. Therefore, national security thinkers must find a way to incorporate cyber attack and defense into military doctrine as soon as possible. The world’s mo....

More Projects of Prototype This! Joe Grand Electrical Engineer, Grand Idea Studio Zoz Robotics Engineer For 18 months, Joe Grand and Zoz Brooks were co-hosts of Discovery Channel's Prototype This, an engineering entertainment program that followed the real-life design process of a unique prototype every episode. At DEF CON 17, Joe and Zoz talked about the show and a few of their favorite builds. The dynamic nerd duo returns to....

Hacking Measured Boot and UEFI Dan Griffin President, JW Secure, Inc. There's been a lot buzz about UEFI Secure Booting, and the ability of hardware and software manufacturers to lock out third-party loaders (and rootkits). Even the NSA has been advocating the adoption of measured boot and hardware-based integrity checks. But what does this trend mean to the open source and hacker communities? In this talk I'll demonstrate measured b....

Exchanging Demands Peter Hannay Security Researcher, PhD Student Smart phones and other portable devices are increasingly used with Microsoft Exchange to allow people to check their corporate emails or sync their calendars remotely. Exchange has an interesting relationship with its mobile clients. It demands a certain level of control over the devices, enforcing policy such as password complexity, screen timeouts, remote lock out and....

Copy of the slides for this talk are here:http://m6rqq6kocsyugo2laitup5nn32bwm3lh677chuodjfmggczoafzwfcad.onion/dc-20/presentations/Geers/DEFCON-20-Kenneth-Geers-Sun-Tzu-and-Cyber-War.pdf Extra Materials here:http://m6rqq6kocsyugo2laitup5nn32bwm3lh677chuodjfmggczoafzwfcad.onion/dc-20/presentations/Geers/DEFCON-20-Kenneth-Geers-Strategic-Cyber-Security.pdf The Art of Cyberwar Kenneth Geers NCIS Cyber Subject Matter Expert The ....

Copy of the slides for this talk are here:http://m6rqq6kocsyugo2laitup5nn32bwm3lh677chuodjfmggczoafzwfcad.onion/dc-20/presentations/Grand-Zoz/DEFCON-20-Grand-Zoz-Projects-of-Prototype-This.pdf More Projects of Prototype This! Joe Grand Electrical Engineer, Grand Idea Studio Zoz Robotics Engineer For 18 months, Joe Grand and Zoz Brooks were co-hosts of Discovery Channel's Prototype This, an engineering entertainment program....

Copy of the slides for this talk are here:http://m6rqq6kocsyugo2laitup5nn32bwm3lh677chuodjfmggczoafzwfcad.onion/dc-20/presentations/Griffin/DEFCON-20-Griffin-Hacking-Measured-Boot-and-UEFI.pdf Hacking Measured Boot and UEFI Dan Griffin President, JW Secure, Inc. There's been a lot buzz about UEFI Secure Booting, and the ability of hardware and software manufacturers to lock out third-party loaders (and rootkits). Even the NSA....

Copy of the slides for this talk are here:http://m6rqq6kocsyugo2laitup5nn32bwm3lh677chuodjfmggczoafzwfcad.onion/dc-20/presentations/Hannay/DEFCON-20-Hannay-Exchanging-Demands.pdf Extras:http://m6rqq6kocsyugo2laitup5nn32bwm3lh677chuodjfmggczoafzwfcad.onion/dc-20/presentations/Hannay/Extras.zip Exchanging Demands Peter Hannay Security Researcher, PhD Student Smart phones and other portable devices are increasingly used with Mi....

Copy of the slides for this talk are here:http://m6rqq6kocsyugo2laitup5nn32bwm3lh677chuodjfmggczoafzwfcad.onion/dc-20/presentations/Geers/DEFCON-20-Kenneth-Geers-Sun-Tzu-and-Cyber-War.pdf Extra Materials here:http://m6rqq6kocsyugo2laitup5nn32bwm3lh677chuodjfmggczoafzwfcad.onion/dc-20/presentations/Geers/DEFCON-20-Kenneth-Geers-Strategic-Cyber-Security.pdf The Art of Cyberwar Kenneth Geers NCIS Cyber Subject Matter Expert The ....

Copy of the slides for this talk are here:http://m6rqq6kocsyugo2laitup5nn32bwm3lh677chuodjfmggczoafzwfcad.onion/dc-20/presentations/Grand-Zoz/DEFCON-20-Grand-Zoz-Projects-of-Prototype-This.pdf More Projects of Prototype This! Joe Grand Electrical Engineer, Grand Idea Studio Zoz Robotics Engineer For 18 months, Joe Grand and Zoz Brooks were co-hosts of Discovery Channel's Prototype This, an engineering entertainment program....

Copy of the slides for this talk are here:http://m6rqq6kocsyugo2laitup5nn32bwm3lh677chuodjfmggczoafzwfcad.onion/dc-20/presentations/Griffin/DEFCON-20-Griffin-Hacking-Measured-Boot-and-UEFI.pdf Hacking Measured Boot and UEFI Dan Griffin President, JW Secure, Inc. There's been a lot buzz about UEFI Secure Booting, and the ability of hardware and software manufacturers to lock out third-party loaders (and rootkits). Even the NSA....

Copy of the slides for this talk are here:http://m6rqq6kocsyugo2laitup5nn32bwm3lh677chuodjfmggczoafzwfcad.onion/dc-20/presentations/Hannay/DEFCON-20-Hannay-Exchanging-Demands.pdf Extras:http://m6rqq6kocsyugo2laitup5nn32bwm3lh677chuodjfmggczoafzwfcad.onion/dc-20/presentations/Hannay/Extras.zip Exchanging Demands Peter Hannay Security Researcher, PhD Student Smart phones and other portable devices are increasingly used with Mi....

Copy of the slides for this talk are here:http://m6rqq6kocsyugo2laitup5nn32bwm3lh677chuodjfmggczoafzwfcad.onion/dc-20/presentations/Geers/DEFCON-20-Kenneth-Geers-Sun-Tzu-and-Cyber-War.pdf Extra Materials here:http://m6rqq6kocsyugo2laitup5nn32bwm3lh677chuodjfmggczoafzwfcad.onion/dc-20/presentations/Geers/DEFCON-20-Kenneth-Geers-Strategic-Cyber-Security.pdf The Art of Cyberwar Kenneth Geers NCIS Cyber Subject Matter Expert The ....

Copy of the slides for this talk are here:http://m6rqq6kocsyugo2laitup5nn32bwm3lh677chuodjfmggczoafzwfcad.onion/dc-20/presentations/Grand-Zoz/DEFCON-20-Grand-Zoz-Projects-of-Prototype-This.pdf More Projects of Prototype This! Joe Grand Electrical Engineer, Grand Idea Studio Zoz Robotics Engineer For 18 months, Joe Grand and Zoz Brooks were co-hosts of Discovery Channel's Prototype This, an engineering entertainment program....

Copy of the slides for this talk are here:http://m6rqq6kocsyugo2laitup5nn32bwm3lh677chuodjfmggczoafzwfcad.onion/dc-20/presentations/Griffin/DEFCON-20-Griffin-Hacking-Measured-Boot-and-UEFI.pdf Hacking Measured Boot and UEFI Dan Griffin President, JW Secure, Inc. There's been a lot buzz about UEFI Secure Booting, and the ability of hardware and software manufacturers to lock out third-party loaders (and rootkits). Even the NSA....

Copy of the slides for this talk are here:http://m6rqq6kocsyugo2laitup5nn32bwm3lh677chuodjfmggczoafzwfcad.onion/dc-20/presentations/Hannay/DEFCON-20-Hannay-Exchanging-Demands.pdf Extras:http://m6rqq6kocsyugo2laitup5nn32bwm3lh677chuodjfmggczoafzwfcad.onion/dc-20/presentations/Hannay/Extras.zip Exchanging Demands Peter Hannay Security Researcher, PhD Student Smart phones and other portable devices are increasingly used with Mi....

Passive Bluetooth Monitoring in Scapy Ryan Holeman Recognizing a need to support passive bluetooth monitoring in Scapy, Python's interactive monitoring framework, a project was launched to produce this functionality. Through this functionality, a new means for interactively observing bluetooth was created along with Python APIs to assist in the development of bluetooth auditing, pentesting and exploitation tools. The project sup....

Detecting Reflective Injection Andrew King Contract Researcher, GrayHat Research, LLC This talk will focus on detecting reflective injection with some mildly humorous notes and bypassing said protections until vendors start actually working on this problem. It seems amazing that reflective injection still works. Why is that? Because programmers are lazy. They don't want to write new engines, they want to write definitions for an engi....

An Inside Look Into Defense Industrial Base (DIB) Technical Security Controls: How Private Industry Protects Our Country's Secrets James Kirk Senior Security Consultant / Rapid7, Inc. With an ever changing threat of nation states targeting the United States and its infrastructure and insiders stealing information for public release, we must continuously evaluate the procedural and technical controls we place on our national assets. T....

No More Hooks: Detection of Code Integrity Attacks Xeno Kovah The MITRE Corporation Corey Kallenberg The MITRE Corporation Hooking is the act of redirecting program control flow somewhere other than it would go by default. For instance code can be "inlined hooked" by rewriting instructions to unconditionally transfer to other code. Or code can be hooked by manipulating control flow data like function pointers (IAT, IDT, SSDT, retur....

DDoS Black and White "Kungfu" Revealed Anthony "Darkfloyd" Lai Security Researcher, Valkyrie-X Security Research Group (VXRL) Tony "MT" Miu Researcher, VXRL Kelvin "Captain" Wong Researcher, VXRL Alan "Avenir" Chung Researcher, VXRL Enterprises currently dump millions of bucks to defense against DDoS, some trading firms here are paying for fear to the DDoS attack from China about 5K to 100K USD per day and InfoSec teams believe....

117 visitors online