Site uses cookies to provide basic functionality.
Javascript rendering is set to off by default when visiting the site via .onion and .i2p domains. It can be enabled back again in user's settings section. Javascript rendering set to off means, that you can disable javascript in your browser now and the site will remain functional.
There is also IRC server now available via native IRC clients or non javascript web based one.
Fonts can be adjusted in user's settings section as well.
Check FAQ for more.

OK

https://www.defcon.org/defcon-19/dc-19-presentations/Baldwin/DEFCON-19-Baldwin-DVCS.pdf White Paper Here: https://www.defcon.org/defcon-19/dc-19-presentations/Baldwin/DEFCON-19-Baldwin-DVCS-WP.pdf Distributed Version Control Systems, like git are becoming an increasingly popular way to deploy web applications and web related resources. Our research shows these repositories commonly contain information very useful to an attacker. T....

https://www.defcon.org/images/defcon-19/dc-19-presentations/Baldwin/DEFCON-19-Baldwin-DVCS.pdf White Paper Here: https://www.defcon.org/images/defcon-19/dc-19-presentations/Baldwin/DEFCON-19-Baldwin-DVCS-WP.pdf Distributed Version Control Systems, like git are becoming an increasingly popular way to deploy web applications and web related resources. Our research shows these repositories commonly contain information very useful to ....

https://www.defcon.org/images/defcon-19/dc-19-presentations/Barisani-Bianco-Laurie-Franken/DEFCON-19-Barisani-Bianco-Laurie-Franken.pdf The EMV global standard for electronic payments is widely used for inter-operation between chip equipped credit/debit cards, Point of Sales devices and ATMs. Following the trail of the serious vulnerabilities published by Murdoch and Drimer's team at Cambridge University regarding the usage of sto....

https://www.defcon.org/images/defcon-19/dc-19-presentations/Barisani-Bianco-Laurie-Franken/DEFCON-19-Barisani-Bianco-Laurie-Franken.pdf The EMV global standard for electronic payments is widely used for inter-operation between chip equipped credit/debit cards, Point of Sales devices and ATMs. Following the trail of the serious vulnerabilities published by Murdoch and Drimer's team at Cambridge University regarding the usage of sto....

https://www.defcon.org/defcon-19/dc-19-presentations/Barisani-Bianco-Laurie-Franken/DEFCON-19-Barisani-Bianco-Laurie-Franken.pdf The EMV global standard for electronic payments is widely used for inter-operation between chip equipped credit/debit cards, Point of Sales devices and ATMs. Following the trail of the serious vulnerabilities published by Murdoch and Drimer's team at Cambridge University regarding the usage of stolen car....

https://www.defcon.org/images/defcon-19/dc-19-presentations/Barisani-Bianco-Laurie-Franken/DEFCON-19-Barisani-Bianco-Laurie-Franken.pdf The EMV global standard for electronic payments is widely used for inter-operation between chip equipped credit/debit cards, Point of Sales devices and ATMs. Following the trail of the serious vulnerabilities published by Murdoch and Drimer's team at Cambridge University regarding the usage of sto....

https://www.defcon.org/images/defcon-19/dc-19-presentations/Barnett/DEFCON-19-Barnett-Deceptive-Hacking.pdf White Paper Here: https://www.defcon.org/images/defcon-19/dc-19-presentations/Barnett/DEFCON-19-Barnett-Deceptive-Hacking-WP.pdf There are many similarities between professional hackers and professional magicians. Magicians are experts in creating deception, and these skills can be applied when penetrating a network. The a....

https://www.defcon.org/images/defcon-19/dc-19-presentations/Barnett/DEFCON-19-Barnett-Deceptive-Hacking.pdf White Paper Here: https://www.defcon.org/images/defcon-19/dc-19-presentations/Barnett/DEFCON-19-Barnett-Deceptive-Hacking-WP.pdf There are many similarities between professional hackers and professional magicians. Magicians are experts in creating deception, and these skills can be applied when penetrating a network. The a....

https://www.defcon.org/defcon-19/dc-19-presentations/Barnett/DEFCON-19-Barnett-Deceptive-Hacking.pdf White Paper Here: https://www.defcon.org/defcon-19/dc-19-presentations/Barnett/DEFCON-19-Barnett-Deceptive-Hacking-WP.pdf There are many similarities between professional hackers and professional magicians. Magicians are experts in creating deception, and these skills can be applied when penetrating a network. The author, with 30....

https://www.defcon.org/images/defcon-19/dc-19-presentations/Barnett/DEFCON-19-Barnett-Deceptive-Hacking.pdf White Paper Here: https://www.defcon.org/images/defcon-19/dc-19-presentations/Barnett/DEFCON-19-Barnett-Deceptive-Hacking-WP.pdf There are many similarities between professional hackers and professional magicians. Magicians are experts in creating deception, and these skills can be applied when penetrating a network. The a....

https://www.defcon.org/defcon-19/dc-19-presentations/Bilodeau/DEFCON-19-Bilodeau-FingerBank.pdf The presentation will first take a step back and offer a basic reminder of what passive fingerprinting is and, more precisely, DHCP fingerprinting. Then we will offer defensive and offensive use cases for DHCP fingerprinting. Next, we will cover the goals and resources offered by the new project and some future plans. As part of the announcem....

https://www.defcon.org/defcon-19/dc-19-presentations/Bilodeau/DEFCON-19-Bilodeau-PacketFence.pdf Ever heard of PacketFence? It's a free and open source Network Access Control (NAC) software that's been out there since 2005. In the last two years we had several major releases with important new features that makes it an even more compelling solution. Trying to appeal to both attackers and defenders, this presentation will cover all ....

https://www.defcon.org/images/defcon-19/dc-19-presentations/Bouillon/DEFCON-19-Bouillon-Federation-and-Empire.pdf Federated Identity is getting prevalent in corporate environments. True, solving cross domain access control to Web applications or services is a nagging issue. Today, unsatisfying traditional approaches based on duplicated user accounts or dangerous trust domain relationships are being replaced by neater solutions. One of ....

https://www.defcon.org/images/defcon-19/dc-19-presentations/Bouillon/DEFCON-19-Bouillon-Federation-and-Empire.pdf Federated Identity is getting prevalent in corporate environments. True, solving cross domain access control to Web applications or services is a nagging issue. Today, unsatisfying traditional approaches based on duplicated user accounts or dangerous trust domain relationships are being replaced by neater solutions. One of ....

https://www.defcon.org/defcon-19/dc-19-presentations/Bouillon/DEFCON-19-Bouillon-Federation-and-Empire.pdf Federated Identity is getting prevalent in corporate environments. True, solving cross domain access control to Web applications or services is a nagging issue. Today, unsatisfying traditional approaches based on duplicated user accounts or dangerous trust domain relationships are being replaced by neater solutions. One of them is....

https://www.defcon.org/images/defcon-19/dc-19-presentations/Bouillon/DEFCON-19-Bouillon-Federation-and-Empire.pdf Federated Identity is getting prevalent in corporate environments. True, solving cross domain access control to Web applications or services is a nagging issue. Today, unsatisfying traditional approaches based on duplicated user accounts or dangerous trust domain relationships are being replaced by neater solutions. One of ....

https://www.defcon.org/images/defcon-19/dc-19-presentations/Bowne/DEFCON-19-Bowne-Three-Generations-of-DoS-Attacks.pdf Denial-of-service (DoS) attacks are very common. They are used for extortion, political protest, revenge, or just LULz. Most of them use old, inefficient methods like UDP Floods, which require thousands of attackers to bring down a Web server. The newer Layer 7 attacks like Slowloris and Rudy are more powerful, and can ....

https://www.defcon.org/images/defcon-19/dc-19-presentations/Bowne/DEFCON-19-Bowne-Three-Generations-of-DoS-Attacks.pdf Denial-of-service (DoS) attacks are very common. They are used for extortion, political protest, revenge, or just LULz. Most of them use old, inefficient methods like UDP Floods, which require thousands of attackers to bring down a Web server. The newer Layer 7 attacks like Slowloris and Rudy are more powerful, and can ....

https://www.defcon.org/defcon-19/dc-19-presentations/Bowne/DEFCON-19-Bowne-Three-Generations-of-DoS-Attacks.pdf Denial-of-service (DoS) attacks are very common. They are used for extortion, political protest, revenge, or just LULz. Most of them use old, inefficient methods like UDP Floods, which require thousands of attackers to bring down a Web server. The newer Layer 7 attacks like Slowloris and Rudy are more powerful, and can stop a ....

https://www.defcon.org/images/defcon-19/dc-19-presentations/Bowne/DEFCON-19-Bowne-Three-Generations-of-DoS-Attacks.pdf Denial-of-service (DoS) attacks are very common. They are used for extortion, political protest, revenge, or just LULz. Most of them use old, inefficient methods like UDP Floods, which require thousands of attackers to bring down a Web server. The newer Layer 7 attacks like Slowloris and Rudy are more powerful, and can ....

We will cover on how the DEF CON network team builds a network from scratch, in three days with very little budget. How this network evolved, what worked for us, and what didn't work over the last ten years. This network started as an idea, and after acquiring some kick butt hardware, has allowed us to support several thousand users concurrently. In addition I will cover the new WPA2 enterprise deployment, what worked, and what didn't, and ....

https://www.defcon.org/defcon-19/dc-19-presentations/Bryner/DEFCON-19-Bryner-Kinectasploit.pdf We've all seen hackers in movies flying through 3D worlds as they hack the gibson. How about trying it for real? Now that we've got the kinect, lets hook it up to some hacking tools and see what it looks like to hack via kinect! Jeff Bryner has 20 years of experience integrating systems, fixing security issues, performing incident respon..

Physical memory forensics has gained a lot of traction over the past five or six years. While it will never eliminate the need for disk forensics, memory analysis has proven its efficacy during incident response and more traditional forensic investigations. Previously, memory forensics, although useful, focused on a process' address space in the form of Virtual Address Descriptors (VADs) but ignored other rich sources of information. In the....

https://www.defcon.org/defcon-19/dc-19-presentations/Carey/DEFCON-19-Carey-Metasploit-vSploit-Modules.pdf This talk is for security practitioners who are responsible for and need to test enterprise network security solutions. Marcus Carey, David Rude, and Will Vandevanter discuss how to use the Metasploit Framework beyond penetration testing to validate whether security solutions are working as expected. Marcus initiated the creation v....

https://www.defcon.org/images/defcon-19/dc-19-presentations/Chamales/DEFCON-19-Chamales-Securing-Crisis-Maps.pdf Crisis maps collect and present open source intelligence (Twitter, Facebook, YouTube, news reports) and direct messages (SMS, email) during disasters such as the Haiti earthquake and civil unrest in Africa. The deployment of crisis mapping technology is on its way to becoming a standard tool to collect and track ground truth....

https://www.defcon.org/images/defcon-19/dc-19-presentations/Chamales/DEFCON-19-Chamales-Securing-Crisis-Maps.pdf Crisis maps collect and present open source intelligence (Twitter, Facebook, YouTube, news reports) and direct messages (SMS, email) during disasters such as the Haiti earthquake and civil unrest in Africa. The deployment of crisis mapping technology is on its way to becoming a standard tool to collect and track ground truth....

https://www.defcon.org/defcon-19/dc-19-presentations/Chamales/DEFCON-19-Chamales-Securing-Crisis-Maps.pdf Crisis maps collect and present open source intelligence (Twitter, Facebook, YouTube, news reports) and direct messages (SMS, email) during disasters such as the Haiti earthquake and civil unrest in Africa. The deployment of crisis mapping technology is on its way to becoming a standard tool to collect and track ground truth from c....

https://www.defcon.org/images/defcon-19/dc-19-presentations/Chamales/DEFCON-19-Chamales-Securing-Crisis-Maps.pdf Crisis maps collect and present open source intelligence (Twitter, Facebook, YouTube, news reports) and direct messages (SMS, email) during disasters such as the Haiti earthquake and civil unrest in Africa. The deployment of crisis mapping technology is on its way to becoming a standard tool to collect and track ground truth....

https://www.defcon.org/images/defcon-19/dc-19-presentations/Chow/DEFCON-19-Chow-Abusing-HTML5.pdf Extra Material Here: https://www.defcon.org/images/defcon-19/dc-19-presentations/Chow/Extras.zip The spike of i{Phone, Pod Touch, Pad}, Android, and other mobile devices that do not support Flash has spurred the growth and interest in HTML5, even though the standard is still evolving. The power of HTML5 allows developers to create alm....

https://www.defcon.org/images/defcon-19/dc-19-presentations/Chow/DEFCON-19-Chow-Abusing-HTML5.pdf Extra Material Here: https://www.defcon.org/images/defcon-19/dc-19-presentations/Chow/Extras.zip The spike of i{Phone, Pod Touch, Pad}, Android, and other mobile devices that do not support Flash has spurred the growth and interest in HTML5, even though the standard is still evolving. The power of HTML5 allows developers to create alm....

https://www.defcon.org/defcon-19/dc-19-presentations/Chow/DEFCON-19-Chow-Abusing-HTML5.pdf Extra Material Here: https://www.defcon.org/defcon-19/dc-19-presentations/Chow/DEFCON-19-Chow-Abusing-HTML5-Extras.zip The spike of i{Phone, Pod Touch, Pad}, Android, and other mobile devices that do not support Flash has spurred the growth and interest in HTML5, even though the standard is still evolving. The power of HTML5 allows developer....

https://www.defcon.org/images/defcon-19/dc-19-presentations/Chow/DEFCON-19-Chow-Abusing-HTML5.pdf Extra Material Here: https://www.defcon.org/images/defcon-19/dc-19-presentations/Chow/Extras.zip The spike of i{Phone, Pod Touch, Pad}, Android, and other mobile devices that do not support Flash has spurred the growth and interest in HTML5, even though the standard is still evolving. The power of HTML5 allows developers to create alm....

Good programmers write code, great programmers reuse" is one of the most well known truisms of software development. But what does that mean for security? For over 30 years software engineering has focused on writing the perfect code and reusing it as often as they can, believing if they can just get the bugs out, the system will be secure. In our talk we will demonstrate how the most prominent doctrine of programming is deadly for security....

https://www.defcon.org/images/defcon-19/dc-19-presentations/Cleary/DEFCON-19-Cleary-Art-of-the-Possible.pdf This session will discuss the "Art of the Possible" when it comes to "Offensive Cyber Operations" and why it is so important for both military and non-military cyber professionals to understand each others perspectives on "Offensive Cyber Operations". Discussion will focus on the military's planning process and how the potential ....

https://www.defcon.org/images/defcon-19/dc-19-presentations/Cleary/DEFCON-19-Cleary-Art-of-the-Possible.pdf This session will discuss the "Art of the Possible" when it comes to "Offensive Cyber Operations" and why it is so important for both military and non-military cyber professionals to understand each others perspectives on "Offensive Cyber Operations". Discussion will focus on the military's planning process and how the potential ....

https://www.defcon.org/defcon-19/dc-19-presentations/Cleary/DEFCON-19-Cleary-Art-of-the-Possible.pdf This session will discuss the "Art of the Possible" when it comes to "Offensive Cyber Operations" and why it is so important for both military and non-military cyber professionals to understand each others perspectives on "Offensive Cyber Operations". Discussion will focus on the military's planning process and how the potential introdu....

https://www.defcon.org/images/defcon-19/dc-19-presentations/Cleary/DEFCON-19-Cleary-Art-of-the-Possible.pdf This session will discuss the "Art of the Possible" when it comes to "Offensive Cyber Operations" and why it is so important for both military and non-military cyber professionals to understand each others perspectives on "Offensive Cyber Operations". Discussion will focus on the military's planning process and how the potential ....

This presentation is an introduction to the new world of automobile communication, data and entertainment systems, highlighting the Ford Sync System. The Ford Sync System is a remarkable technological advance that has changed the automobile industry. While hard drives have been used in automobile entertainment applications for some time now, the Ford Sync System is different. It allows the user to interact with the car's communication ....

This presentation is an introduction to the new world of automobile communication, data and entertainment systems, highlighting the Ford Sync System. The Ford Sync System is a remarkable technological advance that has changed the automobile industry. While hard drives have been used in automobile entertainment applications for some time now, the Ford Sync System is different. It allows the user to interact with the car's communication ....

This presentation is an introduction to the new world of automobile communication, data and entertainment systems, highlighting the Ford Sync System. The Ford Sync System is a remarkable technological advance that has changed the automobile industry. While hard drives have been used in automobile entertainment applications for some time now, the Ford Sync System is different. It allows the user to interact with the car's communication ....

This presentation is an introduction to the new world of automobile communication, data and entertainment systems, highlighting the Ford Sync System. The Ford Sync System is a remarkable technological advance that has changed the automobile industry. While hard drives have been used in automobile entertainment applications for some time now, the Ford Sync System is different. It allows the user to interact with the car's communication ....

https://www.defcon.org/images/defcon-19/dc-19-presentations/Cook/DEFCON-19-Cook-Kernel-Exploitation.pdf Extra material here: https://www.defcon.org/images/defcon-19/dc-19-presentations/Cook/Extras.zip Leveraging uninitialized stack memory into a full-blown root escalation is easier than it sounds. See how to find these vulnerabilities, avoid the pitfalls of priming the stack, and turn your "memory corruption" into full root privil..

https://www.defcon.org/images/defcon-19/dc-19-presentations/Cook/DEFCON-19-Cook-Kernel-Exploitation.pdf Extra material here: https://www.defcon.org/images/defcon-19/dc-19-presentations/Cook/Extras.zip Leveraging uninitialized stack memory into a full-blown root escalation is easier than it sounds. See how to find these vulnerabilities, avoid the pitfalls of priming the stack, and turn your "memory corruption" into full root privil..

https://www.defcon.org/defcon-19/dc-19-presentations/Cook/DEFCON-19-Cook-Kernel-Exploitation.pdf Extra material here: https://www.defcon.org/defcon-19/dc-19-presentations/Cook/DEFCON-19-Cook-Kernel-Exploitation-Extras.zip Leveraging uninitialized stack memory into a full-blown root escalation is easier than it sounds. See how to find these vulnerabilities, avoid the pitfalls of priming the stack, and turn your "memory corruption" ..

115 visitors online