Site uses cookies to provide basic functionality.
Javascript rendering is set to off by default when visiting the site via .onion and .i2p domains. It can be enabled back again in user's settings section. Javascript rendering set to off means, that you can disable javascript in your browser now and the site will remain functional.
There is also IRC server now available via native IRC clients or non javascript web based one.
Fonts can be adjusted in user's settings section as well.
Check FAQ for more.

OK

I will show people how to secure different Windows servers using common sense and a variety of different tools. The fundamentals can be applied to any Windows server whether it is NT 4 / 2000 / .NET as well as IIS or Exchange. I will also walk people thru many good security tools that are a must have for any Windows server. I will actually secure a server at the talk that will later be placed on the CTF network. I will anounce a FTP locatio..

I will show people how to secure different Windows servers using common sense and a variety of different tools. The fundamentals can be applied to any Windows server whether it is NT 4 / 2000 / .NET as well as IIS or Exchange. I will also walk people thru many good security tools that are a must have for any Windows server. I will actually secure a server at the talk that will later be placed on the CTF network. I will anounce a FTP locatio..

Ken will talk about different types/implementations of community wireless networks. He will also discuss why companies in the industry like, dislike and do know what to make of the community wireless movement. Most importantly he will tell you why this movement is important and what role it has promoting privacy, community owned infrastructure, and peer to peer communications Ken Caruso is a co-founder of the Seattlewireless.net projec..

Ken will talk about different types/implementations of community wireless networks. He will also discuss why companies in the industry like, dislike and do know what to make of the community wireless movement. Most importantly he will tell you why this movement is important and what role it has promoting privacy, community owned infrastructure, and peer to peer communications Ken Caruso is a co-founder of the Seattlewireless.net projec..

SQL injection is a technique for exploiting web applications that use client-supplied data in SQL queries without stripping potentially harmful characters first. Despite being remarkably simple to protect against, there is an astonishing number of production systems connected to the Internet that are vulnerable to this type of attack. The objective of this talk is to educate the professional security community on the techniques that can be ....

SQL injection is a technique for exploiting web applications that use client-supplied data in SQL queries without stripping potentially harmful characters first. Despite being remarkably simple to protect against, there is an astonishing number of production systems connected to the Internet that are vulnerable to this type of attack. The objective of this talk is to educate the professional security community on the techniques that can be ....

The Trusted Computing Platform Alliance, which includes Intel, AMD, HP, Microsoft, and 180 additional PC platform product vendors, has been working in secrecy for 3 years to develop a chip which will begin shipping mounted on new PC motherboards starting early next year. This tamper-resistant Trusted Platform Module (TPM) will enable operating system and application vendors to ensure that the owner of the motherboard will never again b....

The Trusted Computing Platform Alliance, which includes Intel, AMD, HP, Microsoft, and 180 additional PC platform product vendors, has been working in secrecy for 3 years to develop a chip which will begin shipping mounted on new PC motherboards starting early next year. This tamper-resistant Trusted Platform Module (TPM) will enable operating system and application vendors to ensure that the owner of the motherboard will never again b....

The topic of the talk will be covering both high security locks, and access control products. The locks covered will be including, Medeco, Mul-T-Lock, Assa, Fichet, Concept, Miwa and others. The access control technology will cover, Proximity cards, Mag stripe cards, Biometrics, keypad technology, and others. Questions will be answered on other topics, such as safes, standard locks, lock picking, CCTV, computer security, and other secu..

The topic of the talk will be covering both high security locks, and access control products. The locks covered will be including, Medeco, Mul-T-Lock, Assa, Fichet, Concept, Miwa and others. The access control technology will cover, Proximity cards, Mag stripe cards, Biometrics, keypad technology, and others. Questions will be answered on other topics, such as safes, standard locks, lock picking, CCTV, computer security, and other secu..

Steganographic Trojans As anti-virus manufacturers develop more efficient techniques for stopping an infection, potential attackers must become more cunning and resourceful in their deployment methodologies; they must create "invisible" code...but how? What are the possibilities of developing an invisible virus or Trojan? The purpose of this talk is to explain the research we have collected, and to identify potential distribution ..

You can have a lot of fun with the Internet by ditching your browser in favor of writing special purpose programs that look for -- or do -- very specific things on the Internet. This session will equip you with techniques to extract and interact with data from web sites without a browser, parse and filter data, follow links, deal with encryption and passwords, and manage terabytes of information. You'll also learn why writing these programs..

Steganographic Trojans As anti-virus manufacturers develop more efficient techniques for stopping an infection, potential attackers must become more cunning and resourceful in their deployment methodologies; they must create "invisible" code...but how? What are the possibilities of developing an invisible virus or Trojan? The purpose of this talk is to explain the research we have collected, and to identify potential distribution ..

You can have a lot of fun with the Internet by ditching your browser in favor of writing special purpose programs that look for -- or do -- very specific things on the Internet. This session will equip you with techniques to extract and interact with data from web sites without a browser, parse and filter data, follow links, deal with encryption and passwords, and manage terabytes of information. You'll also learn why writing these programs..

Centralized event-logging and automated intrusion detection are required tools for good network security. But what can you do to prevent your loggers and IDS probes from falling victim to the same attacks they're supposed to warn you about? As it happens, one cool thing you can do is run such systems without IP addresses. In my presentation I'll describe the benefits and drawbacks of this technique, and demonstrate how it can be used in con..

Centralized event-logging and automated intrusion detection are required tools for good network security. But what can you do to prevent your loggers and IDS probes from falling victim to the same attacks they're supposed to warn you about? As it happens, one cool thing you can do is run such systems without IP addresses. In my presentation I'll describe the benefits and drawbacks of this technique, and demonstrate how it can be used in con..

N Stage Biometric Authentication The topic will be about using biometric authentication as part of a multiple stage authentication mechanism. This discussion will explore various applications and flaws with the technology along with some of my ongoing research into a replay attack on the devices by capturing what "goes down the wire". I am a sophomore at the University of Nebraska at Omaha working towards a degreee in computer sci..

N Stage Biometric Authentication The topic will be about using biometric authentication as part of a multiple stage authentication mechanism. This discussion will explore various applications and flaws with the technology along with some of my ongoing research into a replay attack on the devices by capturing what "goes down the wire". I am a sophomore at the University of Nebraska at Omaha working towards a degreee in computer sci..

Our talk will cover the (in)security of layer 2 protocols (CDP, xTP, HSRP, VRRP, VLANs, etc) and its consequences. We will also discuss routing protocols attacks and how to (try to) protect your infrastructure. The architecture, security, secure management and forensics of routers and switches will also be covered. This last part of the talk will be complementary to the presentation from FX of Phenoelit. Nicolas Fischbach is managing t....

Our talk will cover the (in)security of layer 2 protocols (CDP, xTP, HSRP, VRRP, VLANs, etc) and its consequences. We will also discuss routing protocols attacks and how to (try to) protect your infrastructure. The architecture, security, secure management and forensics of routers and switches will also be covered. This last part of the talk will be complementary to the presentation from FX of Phenoelit. Nicolas Fischbach is managing t....

Xprobe, written and maintained by Fyodor Yarochkin & Ofir Arkin, is an active operating system fingerprinting tool based on Ofir Arkin's "ICMP Usage in Scanning" research project (http://www.sys-security.com). Last year at the Blackhat briefings, July 2001, the first generation of Xprobe was released. The tool's first generation (Xprobe v0.0.1) relies on a hard coded static-based logic tree. Although it has a lot of advantages (1-4 pac....

Michael Morgenstern will be leading a panel comprised of several individuals from the 'other side' of Information Security. Panel highlights will include: # An overview on vulnerability disclosure in the past # Potential impacts of irresponsible disclosure # New threats (Does cyber terrorism exist?) # The vulnerability disclosure "food chain" # The issues involved in the handling of a new vulnerability, from the perspective of a c..

Xprobe, written and maintained by Fyodor Yarochkin & Ofir Arkin, is an active operating system fingerprinting tool based on Ofir Arkin's "ICMP Usage in Scanning" research project (http://www.sys-security.com). Last year at the Blackhat briefings, July 2001, the first generation of Xprobe was released. The tool's first generation (Xprobe v0.0.1) relies on a hard coded static-based logic tree. Although it has a lot of advantages (1-4 pac....

Michael Morgenstern will be leading a panel comprised of several individuals from the 'other side' of Information Security. Panel highlights will include: # An overview on vulnerability disclosure in the past # Potential impacts of irresponsible disclosure # New threats (Does cyber terrorism exist?) # The vulnerability disclosure "food chain" # The issues involved in the handling of a new vulnerability, from the perspective of a c..

Security is a problem of trust. Having a system that offers services to Internet and that can be trusted is very hard to achieve. Classical security models focus on the physical limit of the machine. We will see that it can be interesting to move the trust limit between user space and kernel space and that it is still possible to enforce a security policy from this trusted place. We will also see some practical aspects with a review of some..

DEF CON 10 was held August 2nd to the 4th at the Alexis Park Hotel and Resort in Las Vegas, Nevada, USA. . Past speeches and talks from DEF CON hacking conferences in an iTunes friendly m4v format. The DEFCON series of hacking conferences were started in 1993 to focus on both the technical and social trends in hacking, and has grown to be world known event. If you did not make it, or missed the speaker you wanted to see here is you ch..

DEF CON 10 was held August 2nd to the 4th at the Alexis Park Hotel and Resort in Las Vegas, Nevada, USA. . Past speeches and talks from DEF CON hacking conferences in an iTunes friendly m4b format. The DEFCON series of hacking conferences were started in 1993 to focus on both the technical and social trends in hacking, and has grown to be world known event. If you did not make it, or missed the speaker you wanted to see here is you ch..

The telephony industry was late to adopt open-source software and commodity protocols. The open-source development community is rapidly correcting that problem. Everyone from enthusiasts to Fortune 500 companies are now deploying open-source telephony software, from PBX's to voice messaging systems to VoIP gateways. This lecture will focus on the practical. We'll provide demos of the major open-source telephony systems, a brief tutorial on ....

The telephony industry was late to adopt open-source software and commodity protocols. The open-source development community is rapidly correcting that problem. Everyone from enthusiasts to Fortune 500 companies are now deploying open-source telephony software, from PBX's to voice messaging systems to VoIP gateways. This lecture will focus on the practical. We'll provide demos of the major open-source telephony systems, a brief tutorial on ....

Ten years ago hacking was a frontier; ten years from now, hacking will be embedded in everything we do, defined by the context in which it emerges. Real hackers will be pushing the frontiers of information networks, perception management, the wetware/dryware interface, and the exploration of our galactic neighborhood. Mastery means not only having the tools in your hands but knowing that you have them ... and using them to build the Big Pic..

Ten years ago hacking was a frontier; ten years from now, hacking will be embedded in everything we do, defined by the context in which it emerges. Real hackers will be pushing the frontiers of information networks, perception management, the wetware/dryware interface, and the exploration of our galactic neighborhood. Mastery means not only having the tools in your hands but knowing that you have them ... and using them to build the Big Pic..

This talk will cover: # How different computer viruses work "boot sector, file infector, multi-parti, VBS, Java, the different OS viruses, etc..." # How to remove different computer viruses with and without anti-virus software. # How to defend against computer viruses and hostile code. # Computer viruses and different operating systems. # The future of computer viruses and hostile code. Robert Lupo "V1RU5" currently works for..

This talk will cover: # How different computer viruses work "boot sector, file infector, multi-parti, VBS, Java, the different OS viruses, etc..." # How to remove different computer viruses with and without anti-virus software. # How to defend against computer viruses and hostile code. # Computer viruses and different operating systems. # The future of computer viruses and hostile code. Robert Lupo "V1RU5" currently works for..

The presentation will describe the inner workings of the Trojan "Setiri". Setiri leads a new wave of Trojan Horse technology that defeats most conventional security devices including personal firewalls, NAT, statefull inspection firewalls, IDS, proxy type firewalls and content level checking. The presentation will focus on the setting up of a bi-directional communication stream in non-conducive environments, rather than describing the featu....

The presentation will describe the inner workings of the Trojan "Setiri". Setiri leads a new wave of Trojan Horse technology that defeats most conventional security devices including personal firewalls, NAT, statefull inspection firewalls, IDS, proxy type firewalls and content level checking. The presentation will focus on the setting up of a bi-directional communication stream in non-conducive environments, rather than describing the featu....

This research is targeted at demonstrating that small amounts of data can be dispersed over IP based networks, utilizing the data payloads of existing protocols. Such data is expected to be kept alive on the ether until one chooses to retrieve it. The crux of the scheme is the fact that this type of data dispersal is expected to be extremely difficult to detect. Such a scheme also raises some very interesting aspects regarding using Interne....

This research is targeted at demonstrating that small amounts of data can be dispersed over IP based networks, utilizing the data payloads of existing protocols. Such data is expected to be kept alive on the ether until one chooses to retrieve it. The crux of the scheme is the fact that this type of data dispersal is expected to be extremely difficult to detect. Such a scheme also raises some very interesting aspects regarding using Interne....

The vulnerability reporting process is rife with competing interests. Research is conducted by software vendors themselves, paid consultants, government agencies, professional and academic researchers, as well as people who make their living in other ways. Each of these groups have particular interests in the process. The vendor of the targeted software has their concerns. The public at large has an interest in the process (and its results)....

The vulnerability reporting process is rife with competing interests. Research is conducted by software vendors themselves, paid consultants, government agencies, professional and academic researchers, as well as people who make their living in other ways. Each of these groups have particular interests in the process. The vendor of the targeted software has their concerns. The public at large has an interest in the process (and its results)....

FreeBSD security fundamentals will cover some security basics as well as advanced topics on FreeBSD host and network security. Emphasis will be on hardening a FreeBSD machine from the inside-out, locking down ports, services, filesystems, network activity, etc. Some of the material presented in this talk will be BSD-agnostic, and some will apply to a UNIX environment in general. Review of several recent UNIX security vulnerabilities and val....

FreeBSD security fundamentals will cover some security basics as well as advanced topics on FreeBSD host and network security. Emphasis will be on hardening a FreeBSD machine from the inside-out, locking down ports, services, filesystems, network activity, etc. Some of the material presented in this talk will be BSD-agnostic, and some will apply to a UNIX environment in general. Review of several recent UNIX security vulnerabilities and val....

Post 9-11 knee-jerk legislation such as the U.S. Patriot Act. Calls for new legislation requiring ISPs to retain 90 days worth of email. The European Union collecting Internet communications. The continued fall of the nation state, and continued rise of the transnationals. Echelon. Carnivore. Last year's Widdershins talk outlined a need for hackers to band together, put aside petty differences, and start thinking about what we can do a....

Post 9-11 knee-jerk legislation such as the U.S. Patriot Act. Calls for new legislation requiring ISPs to retain 90 days worth of email. The European Union collecting Internet communications. The continued fall of the nation state, and continued rise of the transnationals. Echelon. Carnivore. Last year's Widdershins talk outlined a need for hackers to band together, put aside petty differences, and start thinking about what we can do a....

Many people are interested in bringing their local underground community closer together by organising meetings for those in the area. While this is certainly a good idea, doing it successfully is not as simple as it sounds. Grifter (Salt Lake City 2600) and skroo (Los Angeles 2600) intend to cover the more relevant points of starting local meetings. Topics discussed will include identifying if your area needs a meeting, setting things..

93 visitors online