Site uses cookies to provide basic functionality.
Javascript rendering is set to off by default when visiting the site via .onion and .i2p domains. It can be enabled back again in user's settings section. Javascript rendering set to off means, that you can disable javascript in your browser now and the site will remain functional.
There is also IRC server now available via native IRC clients or non javascript web based one.
Fonts can be adjusted in user's settings section as well.
Check FAQ for more.

OK

Copy of the slides for this talk are here:http://m6rqq6kocsyugo2laitup5nn32bwm3lh677chuodjfmggczoafzwfcad.onion/dc-20/presentations/Mudge/DEFCON-20-Mudge-Cortana.pdf Cortana: Rise of the Automated Red Team Raphael Mudge Principal, Strategic Cyber LLC Do you ever wish that you could clone yourself during a penetration test? Meet Cortana, a new scripting language to automate Metasploit and extend Armitage. Cortana is a pe....

Copy of the slides for this talk are here:http://m6rqq6kocsyugo2laitup5nn32bwm3lh677chuodjfmggczoafzwfcad.onion/dc-20/presentations/Novak-London/DEFCON-20-Novak-London-SQLReInjector.pdf Extras:http://m6rqq6kocsyugo2laitup5nn32bwm3lh677chuodjfmggczoafzwfcad.onion/dc-20/presentations/Novak-London/Extras.zip SQL ReInjector - Automated Exfiltrated Data Identification Jason A. Novak Assistant Director, Digital Forensics; Stroz Friedberg, LLC....

Copy of the slides for this talk are here:http://m6rqq6kocsyugo2laitup5nn32bwm3lh677chuodjfmggczoafzwfcad.onion/dc-20/presentations/Panel-Comedy-Jam-V/DEFCON-20-Mortman-Panel-Comedy-Jam-V-V-For-Vendetta.pdf DEF CON Comedy Jam V, V for Vendetta David Mortman Chief Security Architect, enStratus Rich Mogull Securosis, @rmogull Chris Hoff Rational Security, @beaker Dave Maynor Errata, @donicer Larry Pesce pauldotcom.com, @h....

Copy of the slides for this talk are here: http://m6rqq6kocsyugo2laitup5nn32bwm3lh677chuodjfmggczoafzwfcad.onion/dc-20/presentations/Minozhenko/DEFCON-20-Minozhenko-Hack-VMware-60-Seconds.pdf How to Hack VMware vCenter Server in 60 Seconds Alexander Minozhenko Senior Penetration Tester, ERPScan This talk will discuss some ways to gain control over the virtual infrastructure through vCenter's services. I will describe a few non-dan..

Copy of the slides for this talk are here:http://m6rqq6kocsyugo2laitup5nn32bwm3lh677chuodjfmggczoafzwfcad.onion/dc-20/presentations/Mudge/DEFCON-20-Mudge-Cortana.pdf Cortana: Rise of the Automated Red Team Raphael Mudge Principal, Strategic Cyber LLC Do you ever wish that you could clone yourself during a penetration test? Meet Cortana, a new scripting language to automate Metasploit and extend Armitage. Cortana is a pe....

Copy of the slides for this talk are here:http://m6rqq6kocsyugo2laitup5nn32bwm3lh677chuodjfmggczoafzwfcad.onion/dc-20/presentations/Novak-London/DEFCON-20-Novak-London-SQLReInjector.pdf Extras:http://m6rqq6kocsyugo2laitup5nn32bwm3lh677chuodjfmggczoafzwfcad.onion/dc-20/presentations/Novak-London/Extras.zip SQL ReInjector - Automated Exfiltrated Data Identification Jason A. Novak Assistant Director, Digital Forensics; Stroz Friedberg, LLC....

Copy of the slides for this talk are here:http://m6rqq6kocsyugo2laitup5nn32bwm3lh677chuodjfmggczoafzwfcad.onion/dc-20/presentations/Panel-Comedy-Jam-V/DEFCON-20-Mortman-Panel-Comedy-Jam-V-V-For-Vendetta.pdf DEF CON Comedy Jam V, V for Vendetta David Mortman Chief Security Architect, enStratus Rich Mogull Securosis, @rmogull Chris Hoff Rational Security, @beaker Dave Maynor Errata, @donicer Larry Pesce pauldotcom.com, @h....

The End of the PSTN As You Know It Jason Ostrom Security Researcher, VIPER Lab (Voice over IP Exploit Research), Avaya, Inc. Karl Feinauer Vulnerability Research Software Engineer, VIPER Lab William Borskey Senior Security Consultant, VIPER Lab The PSTN as you know it is changing. In March of 2012, the NSA announced "Project Fishbowl", a reference architecture for secure mobility VoIP usage on smartphones using WiFi or 3GPP netwo....

APK File Infection on an Android System Bob Pan Mobile Security Research Engineer, TrendMicro Inc. This concept of APK file infection on Android is similar to the concept of PE file infection on Windows systems. As the performance of Android device has increased, it's become possible to implement such a concept in Android systems. We will demonstrate how to implement this concept. In addition, we will also give a demo to show that ..

Anti-Forensics and Anti-Anti-Forensics: Attacks and Mitigating Techniques for Digital-Forensic Investigations Michael Perklin Digital investigations may be conducted differently by various labs (law enforcement agencies, private firms, enterprise corporations) but each lab performs similar steps when acquiring, processing, analyzing, or reporting on data. This talk will discuss techniques that criminals can use to throw wrenches into....

Network Anti-Reconnaissance: Messing with Nmap Through Smoke and Mirrors Dan "AltF4" Petro Security Researcher, DataSoft Corp Reconnaissance on a network has been an attacker's game for far too long, where's the defense? Nmap routinely evades firewalls, traverses NATs, bypasses signature based NIDS, and gathers up the details of your highly vulnerable box serving Top Secret documents. Why make it so easy? In this talk, we will e....

Bypassing Endpoint Security for $20 or Less Phil Polstra Computer Security Professor, University of Dubuque In this talk cheap easily constructed devices which can be used to bypass endpoint security software by making any USB mass storage (flash or hard) drive appear as authorized devices will be presented. The design and implementation will be discussed in detail. Devices can be constructed for approximately $18 and $30 for a ....

Copy of the slides for this talk are here:http://m6rqq6kocsyugo2laitup5nn32bwm3lh677chuodjfmggczoafzwfcad.onion/dc-20/presentations/Ostrom-Feinauer-Borskey/DEFCON-20-Ostrom-Feinauer-Borskey-The-End-of-the-PTSN.pdf The End of the PSTN As You Know It Jason Ostrom Security Researcher, VIPER Lab (Voice over IP Exploit Research), Avaya, Inc. Karl Feinauer Vulnerability Research Software Engineer, VIPER Lab William Borskey Senior Se....

Copy of the slides for this talk are here:http://m6rqq6kocsyugo2laitup5nn32bwm3lh677chuodjfmggczoafzwfcad.onion/dc-20/presentations/Pan/DEFCON-20-Pan-APK-File-Infection-on-Android-System.pdf APK File Infection on an Android System Bob Pan Mobile Security Research Engineer, TrendMicro Inc. This concept of APK file infection on Android is similar to the concept of PE file infection on Windows systems. As the performance of A....

Copy of the slides for this talk are here:http://m6rqq6kocsyugo2laitup5nn32bwm3lh677chuodjfmggczoafzwfcad.onion/dc-20/presentations/Perklin/DEFCON-20-Perklin-AntiForensics.pdf Anti-Forensics and Anti-Anti-Forensics: Attacks and Mitigating Techniques for Digital-Forensic Investigations Michael Perklin Digital investigations may be conducted differently by various labs (law enforcement agencies, private firms, enterprise corpor....

Copy of the slides for this talk are here:http://m6rqq6kocsyugo2laitup5nn32bwm3lh677chuodjfmggczoafzwfcad.onion/dc-20/presentations/Petro/DEFCON-20-Petro-Messing-with-Nmap.pdf Network Anti-Reconnaissance: Messing with Nmap Through Smoke and Mirrors Dan "AltF4" Petro Security Researcher, DataSoft Corp Reconnaissance on a network has been an attacker's game for far too long, where's the defense? Nmap routinely evades firewalls,....

Copy of the slides for this talk are here: http://m6rqq6kocsyugo2laitup5nn32bwm3lh677chuodjfmggczoafzwfcad.onion/dc-20/presentations/Polstra/DEFCON-20-Polstra-Bypassing-Endpoint-Security.pdf Exrtas:http://m6rqq6kocsyugo2laitup5nn32bwm3lh677chuodjfmggczoafzwfcad.onion/dc-20/presentations/Polstra/Philip Polstra.txt Bypassing Endpoint Security for $20 or Less Phil Polstra Computer Security Professor, University of Dubuque In ....

Copy of the slides for this talk are here:http://m6rqq6kocsyugo2laitup5nn32bwm3lh677chuodjfmggczoafzwfcad.onion/dc-20/presentations/Ostrom-Feinauer-Borskey/DEFCON-20-Ostrom-Feinauer-Borskey-The-End-of-the-PTSN.pdf The End of the PSTN As You Know It Jason Ostrom Security Researcher, VIPER Lab (Voice over IP Exploit Research), Avaya, Inc. Karl Feinauer Vulnerability Research Software Engineer, VIPER Lab William Borskey Senior Se....

Copy of the slides for this talk are here:http://m6rqq6kocsyugo2laitup5nn32bwm3lh677chuodjfmggczoafzwfcad.onion/dc-20/presentations/Pan/DEFCON-20-Pan-APK-File-Infection-on-Android-System.pdf APK File Infection on an Android System Bob Pan Mobile Security Research Engineer, TrendMicro Inc. This concept of APK file infection on Android is similar to the concept of PE file infection on Windows systems. As the performance of A....

Copy of the slides for this talk are here:http://m6rqq6kocsyugo2laitup5nn32bwm3lh677chuodjfmggczoafzwfcad.onion/dc-20/presentations/Perklin/DEFCON-20-Perklin-AntiForensics.pdf Anti-Forensics and Anti-Anti-Forensics: Attacks and Mitigating Techniques for Digital-Forensic Investigations Michael Perklin Digital investigations may be conducted differently by various labs (law enforcement agencies, private firms, enterprise corpor....

Copy of the slides for this talk are here:http://m6rqq6kocsyugo2laitup5nn32bwm3lh677chuodjfmggczoafzwfcad.onion/dc-20/presentations/Petro/DEFCON-20-Petro-Messing-with-Nmap.pdf Network Anti-Reconnaissance: Messing with Nmap Through Smoke and Mirrors Dan "AltF4" Petro Security Researcher, DataSoft Corp Reconnaissance on a network has been an attacker's game for far too long, where's the defense? Nmap routinely evades firewalls,....

Copy of the slides for this talk are here: http://m6rqq6kocsyugo2laitup5nn32bwm3lh677chuodjfmggczoafzwfcad.onion/dc-20/presentations/Polstra/DEFCON-20-Polstra-Bypassing-Endpoint-Security.pdf Exrtas:http://m6rqq6kocsyugo2laitup5nn32bwm3lh677chuodjfmggczoafzwfcad.onion/dc-20/presentations/Polstra/Philip Polstra.txt Bypassing Endpoint Security for $20 or Less Phil Polstra Computer Security Professor, University of Dubuque In ....

Copy of the slides for this talk are here:http://m6rqq6kocsyugo2laitup5nn32bwm3lh677chuodjfmggczoafzwfcad.onion/dc-20/presentations/Ostrom-Feinauer-Borskey/DEFCON-20-Ostrom-Feinauer-Borskey-The-End-of-the-PTSN.pdf The End of the PSTN As You Know It Jason Ostrom Security Researcher, VIPER Lab (Voice over IP Exploit Research), Avaya, Inc. Karl Feinauer Vulnerability Research Software Engineer, VIPER Lab William Borskey Senior Se....

Copy of the slides for this talk are here:http://m6rqq6kocsyugo2laitup5nn32bwm3lh677chuodjfmggczoafzwfcad.onion/dc-20/presentations/Pan/DEFCON-20-Pan-APK-File-Infection-on-Android-System.pdf APK File Infection on an Android System Bob Pan Mobile Security Research Engineer, TrendMicro Inc. This concept of APK file infection on Android is similar to the concept of PE file infection on Windows systems. As the performance of A....

Copy of the slides for this talk are here:http://m6rqq6kocsyugo2laitup5nn32bwm3lh677chuodjfmggczoafzwfcad.onion/dc-20/presentations/Perklin/DEFCON-20-Perklin-AntiForensics.pdf Anti-Forensics and Anti-Anti-Forensics: Attacks and Mitigating Techniques for Digital-Forensic Investigations Michael Perklin Digital investigations may be conducted differently by various labs (law enforcement agencies, private firms, enterprise corpor....

Copy of the slides for this talk are here:http://m6rqq6kocsyugo2laitup5nn32bwm3lh677chuodjfmggczoafzwfcad.onion/dc-20/presentations/Petro/DEFCON-20-Petro-Messing-with-Nmap.pdf Network Anti-Reconnaissance: Messing with Nmap Through Smoke and Mirrors Dan "AltF4" Petro Security Researcher, DataSoft Corp Reconnaissance on a network has been an attacker's game for far too long, where's the defense? Nmap routinely evades firewalls,....

Copy of the slides for this talk are here: http://m6rqq6kocsyugo2laitup5nn32bwm3lh677chuodjfmggczoafzwfcad.onion/dc-20/presentations/Polstra/DEFCON-20-Polstra-Bypassing-Endpoint-Security.pdf Exrtas:http://m6rqq6kocsyugo2laitup5nn32bwm3lh677chuodjfmggczoafzwfcad.onion/dc-20/presentations/Polstra/Philip Polstra.txt Bypassing Endpoint Security for $20 or Less Phil Polstra Computer Security Professor, University of Dubuque In ....

Hacker + Airplanes = No Good Can Come Of This RenderMan Chief Researcher What happens when a hacker gets bored and starts looking at an aircraft tracking systems? This talk will look at ADS-B (Automatic Dependent Surveillance-Broadcast), a common technology installed or being installed on a vast majority of commercial airliners that involves an unencrypted and unauthenticated radio broadcast. This technology has some interesting feat....

MegaUpload: Guilty or Not Guilty? Jim Rennie Attorney Jennifer Granick Attorney On January 19, 2012, Kim DotCom was arrested in a dramatic raid after being indicted on federal criminal charges that he knew that his website, MegaUpload, was a haven of piracy and counterfeiting. In the days that followed, the media commented on the presumed guilt of MegaUpload. In this debate, Jim argues that the law and evidence clearly point to Meg....

Stamp Out Hash Corruption! Crack All The Things! Ryan Reynolds Manager, Security and Privacy at Crowe Horwath LLP Jonathan Claudius Security Researcher, Spiderlabs Research, Trustwave The precursor to cracking any password is getting the right hash. In this talk we are going to cover how we discovered that Cain and Able, Creddump, Metasploit and other hash extraction tools regularly yield corrupt hashes that cannot be cracked. We w....

Copy of the slides for this talk are here: http://m6rqq6kocsyugo2laitup5nn32bwm3lh677chuodjfmggczoafzwfcad.onion/dc-20/presentations/Renderman/DEFCON-20-RenderMan-Hackers-plus-Airplanes.pdf Hacker + Airplanes = No Good Can Come Of This RenderMan Chief Researcher What happens when a hacker gets bored and starts looking at an aircraft tracking systems? This talk will look at ADS-B (Automatic Dependent Surveillance-Broadcast), a comm....

Copy of the slides for this talk are here:http://m6rqq6kocsyugo2laitup5nn32bwm3lh677chuodjfmggczoafzwfcad.onion/dc-20/presentations/Rennie-Grannick/DEFCON-20-Rennie-Grannick-Megaupload-Indictment.pdf MegaUpload: Guilty or Not Guilty? Jim Rennie Attorney Jennifer Granick Attorney On January 19, 2012, Kim DotCom was arrested in a dramatic raid after being indicted on federal criminal charges that he knew that his website, Meg....

Copy of the slides for this talk are here:http://m6rqq6kocsyugo2laitup5nn32bwm3lh677chuodjfmggczoafzwfcad.onion/dc-20/presentations/Reynolds/DEFCON-20-Reynolds-Stamp-Out-Hash-Extraction.pdf Whitepaper: http://m6rqq6kocsyugo2laitup5nn32bwm3lh677chuodjfmggczoafzwfcad.onion/dc-20/presentations/Reynolds/DEFCON-20-Reynolds-Stamp-Out-Hash-Extraction-WP.pdf Extras:http://m6rqq6kocsyugo2laitup5nn32bwm3lh677chuodjfmggczoafzwfcad.onion/dc-20/pr....

Copy of the slides for this talk are here: http://m6rqq6kocsyugo2laitup5nn32bwm3lh677chuodjfmggczoafzwfcad.onion/dc-20/presentations/Renderman/DEFCON-20-RenderMan-Hackers-plus-Airplanes.pdf Hacker + Airplanes = No Good Can Come Of This RenderMan Chief Researcher What happens when a hacker gets bored and starts looking at an aircraft tracking systems? This talk will look at ADS-B (Automatic Dependent Surveillance-Broadcast), a comm....

Copy of the slides for this talk are here:http://m6rqq6kocsyugo2laitup5nn32bwm3lh677chuodjfmggczoafzwfcad.onion/dc-20/presentations/Rennie-Grannick/DEFCON-20-Rennie-Grannick-Megaupload-Indictment.pdf MegaUpload: Guilty or Not Guilty? Jim Rennie Attorney Jennifer Granick Attorney On January 19, 2012, Kim DotCom was arrested in a dramatic raid after being indicted on federal criminal charges that he knew that his website, Meg....

Copy of the slides for this talk are here:http://m6rqq6kocsyugo2laitup5nn32bwm3lh677chuodjfmggczoafzwfcad.onion/dc-20/presentations/Reynolds/DEFCON-20-Reynolds-Stamp-Out-Hash-Extraction.pdf Whitepaper: http://m6rqq6kocsyugo2laitup5nn32bwm3lh677chuodjfmggczoafzwfcad.onion/dc-20/presentations/Reynolds/DEFCON-20-Reynolds-Stamp-Out-Hash-Extraction-WP.pdf Extras:http://m6rqq6kocsyugo2laitup5nn32bwm3lh677chuodjfmggczoafzwfcad.onion/dc-20/pr....

Copy of the slides for this talk are here: http://m6rqq6kocsyugo2laitup5nn32bwm3lh677chuodjfmggczoafzwfcad.onion/dc-20/presentations/Renderman/DEFCON-20-RenderMan-Hackers-plus-Airplanes.pdf Hacker + Airplanes = No Good Can Come Of This RenderMan Chief Researcher What happens when a hacker gets bored and starts looking at an aircraft tracking systems? This talk will look at ADS-B (Automatic Dependent Surveillance-Broadcast), a comm....

Copy of the slides for this talk are here:http://m6rqq6kocsyugo2laitup5nn32bwm3lh677chuodjfmggczoafzwfcad.onion/dc-20/presentations/Rennie-Grannick/DEFCON-20-Rennie-Grannick-Megaupload-Indictment.pdf MegaUpload: Guilty or Not Guilty? Jim Rennie Attorney Jennifer Granick Attorney On January 19, 2012, Kim DotCom was arrested in a dramatic raid after being indicted on federal criminal charges that he knew that his website, Meg....

Copy of the slides for this talk are here:http://m6rqq6kocsyugo2laitup5nn32bwm3lh677chuodjfmggczoafzwfcad.onion/dc-20/presentations/Reynolds/DEFCON-20-Reynolds-Stamp-Out-Hash-Extraction.pdf Whitepaper: http://m6rqq6kocsyugo2laitup5nn32bwm3lh677chuodjfmggczoafzwfcad.onion/dc-20/presentations/Reynolds/DEFCON-20-Reynolds-Stamp-Out-Hash-Extraction-WP.pdf Extras:http://m6rqq6kocsyugo2laitup5nn32bwm3lh677chuodjfmggczoafzwfcad.onion/dc-20/pr....






28 visitors online