Site uses cookies to provide basic functionality.
Javascript rendering is set to off by default when visiting the site via .onion and .i2p domains. It can be enabled back again in user's settings section. Javascript rendering set to off means, that you can disable javascript in your browser now and the site will remain functional.
There is also IRC server now available via native IRC clients or non javascript web based one.
Fonts can be adjusted in user's settings section as well.
Check FAQ for more.

OK

Copy of the slides for this talk are here:http://m6rqq6kocsyugo2laitup5nn32bwm3lh677chuodjfmggczoafzwfcad.onion/dc-20/presentations/Holeman/DEFCON-20-Holeman-Scapy.pdf Extras: http://m6rqq6kocsyugo2laitup5nn32bwm3lh677chuodjfmggczoafzwfcad.onion/dc-20/presentations/Holeman/Extras.zip Passive Bluetooth Monitoring in Scapy Ryan Holeman Recognizing a need to support passive bluetooth monitoring in Scapy, Python's interactive mo....

Copy of the slides for this talk are here: http://m6rqq6kocsyugo2laitup5nn32bwm3lh677chuodjfmggczoafzwfcad.onion/dc-20/presentations/King/DEFCON-20-King-Reflective-Injection-Detection.pdf Detecting Reflective Injection Andrew King Contract Researcher, GrayHat Research, LLC This talk will focus on detecting reflective injection with some mildly humorous notes and bypassing said protections until vendors start actually working on th....

Copy of the slides for this talk are here:http://m6rqq6kocsyugo2laitup5nn32bwm3lh677chuodjfmggczoafzwfcad.onion/dc-20/presentations/Kirk/DEFCON-20-Kirk-An-Inside-Look-Into-Defense-Industrial-Base.pdf Extras:http://m6rqq6kocsyugo2laitup5nn32bwm3lh677chuodjfmggczoafzwfcad.onion/dc-20/presentations/Kirk/Extras.zip An Inside Look Into Defense Industrial Base (DIB) Technical Security Controls: How Private Industry Protects Our Country's Secr....

Copy of the slides for this talk are here:http://m6rqq6kocsyugo2laitup5nn32bwm3lh677chuodjfmggczoafzwfcad.onion/dc-20/presentations/Kovah-Kallenberg/DEFCON-20-Kovah-Kallenberg-Checkmate-RC3.pdf No More Hooks: Detection of Code Integrity Attacks Xeno Kovah The MITRE Corporation Corey Kallenberg The MITRE Corporation Hooking is the act of redirecting program control flow somewhere other than it would go by default. For insta....

Copy of the slides for this talk are here:http://m6rqq6kocsyugo2laitup5nn32bwm3lh677chuodjfmggczoafzwfcad.onion/dc-20/presentations/Lai-Miu-Wong-Chung/DEFCON-20-Lai-Miu-Wong-Chung-DDoS-Kungfu.pdf DDoS Black and White "Kungfu" Revealed Anthony "Darkfloyd" Lai Security Researcher, Valkyrie-X Security Research Group (VXRL) Tony "MT" Miu Researcher, VXRL Kelvin "Captain" Wong Researcher, VXRL Alan "Avenir" Chung Researcher, VX....

Copy of the slides for this talk are here:http://m6rqq6kocsyugo2laitup5nn32bwm3lh677chuodjfmggczoafzwfcad.onion/dc-20/presentations/Holeman/DEFCON-20-Holeman-Scapy.pdf Extras: http://m6rqq6kocsyugo2laitup5nn32bwm3lh677chuodjfmggczoafzwfcad.onion/dc-20/presentations/Holeman/Extras.zip Passive Bluetooth Monitoring in Scapy Ryan Holeman Recognizing a need to support passive bluetooth monitoring in Scapy, Python's interactive mo....

Copy of the slides for this talk are here: http://m6rqq6kocsyugo2laitup5nn32bwm3lh677chuodjfmggczoafzwfcad.onion/dc-20/presentations/King/DEFCON-20-King-Reflective-Injection-Detection.pdf Detecting Reflective Injection Andrew King Contract Researcher, GrayHat Research, LLC This talk will focus on detecting reflective injection with some mildly humorous notes and bypassing said protections until vendors start actually working on th....

Copy of the slides for this talk are here:http://m6rqq6kocsyugo2laitup5nn32bwm3lh677chuodjfmggczoafzwfcad.onion/dc-20/presentations/Kirk/DEFCON-20-Kirk-An-Inside-Look-Into-Defense-Industrial-Base.pdf Extras:http://m6rqq6kocsyugo2laitup5nn32bwm3lh677chuodjfmggczoafzwfcad.onion/dc-20/presentations/Kirk/Extras.zip An Inside Look Into Defense Industrial Base (DIB) Technical Security Controls: How Private Industry Protects Our Country's Secr....

Copy of the slides for this talk are here:http://m6rqq6kocsyugo2laitup5nn32bwm3lh677chuodjfmggczoafzwfcad.onion/dc-20/presentations/Kovah-Kallenberg/DEFCON-20-Kovah-Kallenberg-Checkmate-RC3.pdf No More Hooks: Detection of Code Integrity Attacks Xeno Kovah The MITRE Corporation Corey Kallenberg The MITRE Corporation Hooking is the act of redirecting program control flow somewhere other than it would go by default. For insta....

Copy of the slides for this talk are here:http://m6rqq6kocsyugo2laitup5nn32bwm3lh677chuodjfmggczoafzwfcad.onion/dc-20/presentations/Lai-Miu-Wong-Chung/DEFCON-20-Lai-Miu-Wong-Chung-DDoS-Kungfu.pdf DDoS Black and White "Kungfu" Revealed Anthony "Darkfloyd" Lai Security Researcher, Valkyrie-X Security Research Group (VXRL) Tony "MT" Miu Researcher, VXRL Kelvin "Captain" Wong Researcher, VXRL Alan "Avenir" Chung Researcher, VX....

Copy of the slides for this talk are here:http://m6rqq6kocsyugo2laitup5nn32bwm3lh677chuodjfmggczoafzwfcad.onion/dc-20/presentations/Holeman/DEFCON-20-Holeman-Scapy.pdf Extras: http://m6rqq6kocsyugo2laitup5nn32bwm3lh677chuodjfmggczoafzwfcad.onion/dc-20/presentations/Holeman/Extras.zip Passive Bluetooth Monitoring in Scapy Ryan Holeman Recognizing a need to support passive bluetooth monitoring in Scapy, Python's interactive mo....

Copy of the slides for this talk are here: http://m6rqq6kocsyugo2laitup5nn32bwm3lh677chuodjfmggczoafzwfcad.onion/dc-20/presentations/King/DEFCON-20-King-Reflective-Injection-Detection.pdf Detecting Reflective Injection Andrew King Contract Researcher, GrayHat Research, LLC This talk will focus on detecting reflective injection with some mildly humorous notes and bypassing said protections until vendors start actually working on th....

Copy of the slides for this talk are here:http://m6rqq6kocsyugo2laitup5nn32bwm3lh677chuodjfmggczoafzwfcad.onion/dc-20/presentations/Kirk/DEFCON-20-Kirk-An-Inside-Look-Into-Defense-Industrial-Base.pdf Extras:http://m6rqq6kocsyugo2laitup5nn32bwm3lh677chuodjfmggczoafzwfcad.onion/dc-20/presentations/Kirk/Extras.zip An Inside Look Into Defense Industrial Base (DIB) Technical Security Controls: How Private Industry Protects Our Country's Secr....

Copy of the slides for this talk are here:http://m6rqq6kocsyugo2laitup5nn32bwm3lh677chuodjfmggczoafzwfcad.onion/dc-20/presentations/Kovah-Kallenberg/DEFCON-20-Kovah-Kallenberg-Checkmate-RC3.pdf No More Hooks: Detection of Code Integrity Attacks Xeno Kovah The MITRE Corporation Corey Kallenberg The MITRE Corporation Hooking is the act of redirecting program control flow somewhere other than it would go by default. For insta....

Copy of the slides for this talk are here:http://m6rqq6kocsyugo2laitup5nn32bwm3lh677chuodjfmggczoafzwfcad.onion/dc-20/presentations/Lai-Miu-Wong-Chung/DEFCON-20-Lai-Miu-Wong-Chung-DDoS-Kungfu.pdf DDoS Black and White "Kungfu" Revealed Anthony "Darkfloyd" Lai Security Researcher, Valkyrie-X Security Research Group (VXRL) Tony "MT" Miu Researcher, VXRL Kelvin "Captain" Wong Researcher, VXRL Alan "Avenir" Chung Researcher, VX....

NFC Hacking: The Easy Way Eddie Lee Senior Security Researcher, Blackwing Intelligence Until now, getting into NFC/RFID hacking required enthusiasts to buy special hardware and learn about the underlying transfer protocols. No longer! NFCProxy is a new tool (being released at DEF CON 20) that allows you to proxy RFID transactions using Android phones. NFCProxy can record and replay RFID transactions from the perspective of the tag or....

Copy of the slides for this talk are here: NFC Hacking: The Easy Way Eddie Lee Senior Security Researcher, Blackwing Intelligence Until now, getting into NFC/RFID hacking required enthusiasts to buy special hardware and learn about the underlying transfer protocols. No longer! NFCProxy is a new tool (being released at DEF CON 20) that allows you to proxy RFID transactions using Android phones. NFCProxy can record and replay RFID ....

Copy of the slides for this talk are here: NFC Hacking: The Easy Way Eddie Lee Senior Security Researcher, Blackwing Intelligence Until now, getting into NFC/RFID hacking required enthusiasts to buy special hardware and learn about the underlying transfer protocols. No longer! NFCProxy is a new tool (being released at DEF CON 20) that allows you to proxy RFID transactions using Android phones. NFCProxy can record and replay RFID ....

Copy of the slides for this talk are here: NFC Hacking: The Easy Way Eddie Lee Senior Security Researcher, Blackwing Intelligence Until now, getting into NFC/RFID hacking required enthusiasts to buy special hardware and learn about the underlying transfer protocols. No longer! NFCProxy is a new tool (being released at DEF CON 20) that allows you to proxy RFID transactions using Android phones. NFCProxy can record and replay RFID ....

Anonymous and the Online Fight for Justice Amber Lyon Independent Investigative Journalist Gabriella Coleman Chair in Scientific and Technological Literacy, McGill University, Department of Art History & Communication Studies Marcia Hoffman Senior Staff Attorney, Electronic Frontier Foundation Mercedes Haefer Student, UNLV Jay Leiderman Attorney, Leiderman Devine LLP Gráinne O’Neill Coordinator Anonlg Project, National Lawyers G....

OPFOR 4Ever Tim Maletic Senior Security Consultant,Trustwave SpiderLabs Christopher Pogue Managing Consultant, Trustwave SpiderLabs Training utilizing Opposing Forces, or OPFOR, is an exercise focused on improving detection and response through the principle of "train as you fight." We will demonstrate how we have applied OPFOR to build a continuous feedback loop between penetration testing and incident response. In OPFOR 4Ever, th....

Weaponizing the Windows API with Metasploit’s Railgun David "thelightcosine" Maloney Software Engineer, Metasploit Rapid7 No part of the Metasploit Framework has been shrouded in more mystery and confusion than the Railgun extension. Railgun is one of the most powerful tools in the Metasploit arsenal when it comes to Post Exploitation. In this talk we will examine what Railgun is, and how we can use it to turn Windows completely aga....

Don't Stand So Close To Me: An Analysis of the NFC Attack Surface Charlie Miller Principal Research Consultant, Accuvant Labs Near Field Communication (NFC) has been used in mobile devices in some countries for a while and is now emerging on devices in use in the United States. This technology allows NFC enabled devices to communicate with each other within close range, typically a few centimeters. It is being rolled out as a way to ....

Copy of the slides for this talk are here:http://m6rqq6kocsyugo2laitup5nn32bwm3lh677chuodjfmggczoafzwfcad.onion/dc-20/presentations/Panel-Anonymous-and-the-Online-Fight-for-Justice/DEFCON-20-Criminal-Codes.pdf Anonymous and the Online Fight for Justice Amber Lyon Independent Investigative Journalist Gabriella Coleman Chair in Scientific and Technological Literacy, McGill University, Department of Art History & Communication Stud....

Copy of the slides for this talk are here:http://m6rqq6kocsyugo2laitup5nn32bwm3lh677chuodjfmggczoafzwfcad.onion/dc-20/presentations/Maletic-Pogue/DEFCON-20-Maletic-Pogue-OPFOR4Ever.pdf OPFOR 4Ever Tim Maletic Senior Security Consultant,Trustwave SpiderLabs Christopher Pogue Managing Consultant, Trustwave SpiderLabs Training utilizing Opposing Forces, or OPFOR, is an exercise focused on improving detection and response thro....

Copy of the slides for this talk are here:http://m6rqq6kocsyugo2laitup5nn32bwm3lh677chuodjfmggczoafzwfcad.onion/dc-20/presentations/Maloney/DEFCON-20-Maloney-Railgun.pdf Weaponizing the Windows API with Metasploit’s Railgun David "thelightcosine" Maloney Software Engineer, Metasploit Rapid7 No part of the Metasploit Framework has been shrouded in more mystery and confusion than the Railgun extension. Railgun is one of the mo....

Copy of the slides for this talk are here:http://m6rqq6kocsyugo2laitup5nn32bwm3lh677chuodjfmggczoafzwfcad.onion/dc-20/presentations/Miller/DEFCON-20-Miller-NFC-Attack-Surface.pdf Don't Stand So Close To Me: An Analysis of the NFC Attack Surface Charlie Miller Principal Research Consultant, Accuvant Labs Near Field Communication (NFC) has been used in mobile devices in some countries for a while and is now emerging on devices ....

Copy of the slides for this talk are here:http://m6rqq6kocsyugo2laitup5nn32bwm3lh677chuodjfmggczoafzwfcad.onion/dc-20/presentations/Panel-Anonymous-and-the-Online-Fight-for-Justice/DEFCON-20-Criminal-Codes.pdf Anonymous and the Online Fight for Justice Amber Lyon Independent Investigative Journalist Gabriella Coleman Chair in Scientific and Technological Literacy, McGill University, Department of Art History & Communication Stud....

Copy of the slides for this talk are here:http://m6rqq6kocsyugo2laitup5nn32bwm3lh677chuodjfmggczoafzwfcad.onion/dc-20/presentations/Maletic-Pogue/DEFCON-20-Maletic-Pogue-OPFOR4Ever.pdf OPFOR 4Ever Tim Maletic Senior Security Consultant,Trustwave SpiderLabs Christopher Pogue Managing Consultant, Trustwave SpiderLabs Training utilizing Opposing Forces, or OPFOR, is an exercise focused on improving detection and response thro....

Copy of the slides for this talk are here:http://m6rqq6kocsyugo2laitup5nn32bwm3lh677chuodjfmggczoafzwfcad.onion/dc-20/presentations/Maloney/DEFCON-20-Maloney-Railgun.pdf Weaponizing the Windows API with Metasploit’s Railgun David "thelightcosine" Maloney Software Engineer, Metasploit Rapid7 No part of the Metasploit Framework has been shrouded in more mystery and confusion than the Railgun extension. Railgun is one of the mo....

Copy of the slides for this talk are here:http://m6rqq6kocsyugo2laitup5nn32bwm3lh677chuodjfmggczoafzwfcad.onion/dc-20/presentations/Miller/DEFCON-20-Miller-NFC-Attack-Surface.pdf Don't Stand So Close To Me: An Analysis of the NFC Attack Surface Charlie Miller Principal Research Consultant, Accuvant Labs Near Field Communication (NFC) has been used in mobile devices in some countries for a while and is now emerging on devices ....

Copy of the slides for this talk are here:http://m6rqq6kocsyugo2laitup5nn32bwm3lh677chuodjfmggczoafzwfcad.onion/dc-20/presentations/Panel-Anonymous-and-the-Online-Fight-for-Justice/DEFCON-20-Criminal-Codes.pdf Anonymous and the Online Fight for Justice Amber Lyon Independent Investigative Journalist Gabriella Coleman Chair in Scientific and Technological Literacy, McGill University, Department of Art History & Communication Stud....

Copy of the slides for this talk are here:http://m6rqq6kocsyugo2laitup5nn32bwm3lh677chuodjfmggczoafzwfcad.onion/dc-20/presentations/Maletic-Pogue/DEFCON-20-Maletic-Pogue-OPFOR4Ever.pdf OPFOR 4Ever Tim Maletic Senior Security Consultant,Trustwave SpiderLabs Christopher Pogue Managing Consultant, Trustwave SpiderLabs Training utilizing Opposing Forces, or OPFOR, is an exercise focused on improving detection and response thro....

Copy of the slides for this talk are here:http://m6rqq6kocsyugo2laitup5nn32bwm3lh677chuodjfmggczoafzwfcad.onion/dc-20/presentations/Maloney/DEFCON-20-Maloney-Railgun.pdf Weaponizing the Windows API with Metasploit’s Railgun David "thelightcosine" Maloney Software Engineer, Metasploit Rapid7 No part of the Metasploit Framework has been shrouded in more mystery and confusion than the Railgun extension. Railgun is one of the mo....

Copy of the slides for this talk are here:http://m6rqq6kocsyugo2laitup5nn32bwm3lh677chuodjfmggczoafzwfcad.onion/dc-20/presentations/Miller/DEFCON-20-Miller-NFC-Attack-Surface.pdf Don't Stand So Close To Me: An Analysis of the NFC Attack Surface Charlie Miller Principal Research Consultant, Accuvant Labs Near Field Communication (NFC) has been used in mobile devices in some countries for a while and is now emerging on devices ....

How to Hack VMware vCenter Server in 60 Seconds Alexander Minozhenko Senior Penetration Tester, ERPScan This talk will discuss some ways to gain control over the virtual infrastructure through vCenter's services. I will describe a few non-dangerous bugs (they were 0-days when we found them), but if we can use all of them together, we will get administrative access to vCenter which means to the whole virtual network. Alexander Mi..

DEF CON Comedy Jam V, V for Vendetta David Mortman Chief Security Architect, enStratus Rich Mogull Securosis, @rmogull Chris Hoff Rational Security, @beaker Dave Maynor Errata, @donicer Larry Pesce pauldotcom.com, @haxorthematrix James Arlen Liquid Matrix, @myrcurial Robert David Graham Errata Security, @ErrataRob You know you can't stay away! The most talked about panel at DEF CON! Nearly two hours of non-stop FAIL. Come....

Cortana: Rise of the Automated Red Team Raphael Mudge Principal, Strategic Cyber LLC Do you ever wish that you could clone yourself during a penetration test? Meet Cortana, a new scripting language to automate Metasploit and extend Armitage. Cortana is a penetration tester's scripting language inspired by scriptable IRC clients and bots. Its purpose is two-fold. You may create long running bots that simulate virtual red team mem....

SQL ReInjector - Automated Exfiltrated Data Identification Jason A. Novak Assistant Director, Digital Forensics; Stroz Friedberg, LLC Andrea (Drea) London Digital Forensic Examiner; Stroz Friedberg, LLC In 2011, SQL injections became front page news as ever more high profile companies were victims of automated SQL injection attacks. Responders spent countless hours looking at values in log files like "0x31303235343830303536" trying....

Copy of the slides for this talk are here: http://m6rqq6kocsyugo2laitup5nn32bwm3lh677chuodjfmggczoafzwfcad.onion/dc-20/presentations/Minozhenko/DEFCON-20-Minozhenko-Hack-VMware-60-Seconds.pdf How to Hack VMware vCenter Server in 60 Seconds Alexander Minozhenko Senior Penetration Tester, ERPScan This talk will discuss some ways to gain control over the virtual infrastructure through vCenter's services. I will describe a few non-dan..

Copy of the slides for this talk are here:http://m6rqq6kocsyugo2laitup5nn32bwm3lh677chuodjfmggczoafzwfcad.onion/dc-20/presentations/Mudge/DEFCON-20-Mudge-Cortana.pdf Cortana: Rise of the Automated Red Team Raphael Mudge Principal, Strategic Cyber LLC Do you ever wish that you could clone yourself during a penetration test? Meet Cortana, a new scripting language to automate Metasploit and extend Armitage. Cortana is a pe....

Copy of the slides for this talk are here:http://m6rqq6kocsyugo2laitup5nn32bwm3lh677chuodjfmggczoafzwfcad.onion/dc-20/presentations/Novak-London/DEFCON-20-Novak-London-SQLReInjector.pdf Extras:http://m6rqq6kocsyugo2laitup5nn32bwm3lh677chuodjfmggczoafzwfcad.onion/dc-20/presentations/Novak-London/Extras.zip SQL ReInjector - Automated Exfiltrated Data Identification Jason A. Novak Assistant Director, Digital Forensics; Stroz Friedberg, LLC....

Copy of the slides for this talk are here:http://m6rqq6kocsyugo2laitup5nn32bwm3lh677chuodjfmggczoafzwfcad.onion/dc-20/presentations/Panel-Comedy-Jam-V/DEFCON-20-Mortman-Panel-Comedy-Jam-V-V-For-Vendetta.pdf DEF CON Comedy Jam V, V for Vendetta David Mortman Chief Security Architect, enStratus Rich Mogull Securosis, @rmogull Chris Hoff Rational Security, @beaker Dave Maynor Errata, @donicer Larry Pesce pauldotcom.com, @h....

Copy of the slides for this talk are here: http://m6rqq6kocsyugo2laitup5nn32bwm3lh677chuodjfmggczoafzwfcad.onion/dc-20/presentations/Minozhenko/DEFCON-20-Minozhenko-Hack-VMware-60-Seconds.pdf How to Hack VMware vCenter Server in 60 Seconds Alexander Minozhenko Senior Penetration Tester, ERPScan This talk will discuss some ways to gain control over the virtual infrastructure through vCenter's services. I will describe a few non-dan..

117 visitors online