Site uses cookies to provide basic functionality.
Javascript rendering is set to off by default when visiting the site via .onion and .i2p domains. It can be enabled back again in user's settings section. Javascript rendering set to off means, that you can disable javascript in your browser now and the site will remain functional.
There is also IRC server now available via native IRC clients or non javascript web based one.
Fonts can be adjusted in user's settings section as well.
Check FAQ for more.

OK

I currently run my own computer consulting firm and I think that I can help others. I don't specialize in security, but obviously, there are similar tasks that need to be done. I would cover things like: - Incorporation - Taxes - Marketing - Keeping the client happy - Billing and getting paid To find out more about me, I invite you visit my web site at http://www.beridney.com There, you will find out about the books I have written an..

The unchecked proliferation of global information networks has left society vulnerable to a digital Armageddon. Computer viruses can counter this vulnerability by stabilizing and strengthening information systems. Using analogies from medicine, this paper demonstrates the pressing need for well-designed computer viruses. This paper also proposes the design, implementation, and distribution of an open-source, international, attenuated comp..

The unchecked proliferation of global information networks has left society vulnerable to a digital Armageddon. Computer viruses can counter this vulnerability by stabilizing and strengthening information systems. Using analogies from medicine, this paper demonstrates the pressing need for well-designed computer viruses. This paper also proposes the design, implementation, and distribution of an open-source, international, attenuated comp..

As the Internet grows in popularity around the world, we are beginning to see clashes between individuals and governments from different cultural backgrounds. Corporations, organizations, and legislatures are using local laws in order to enforce their wishes on others worldwide. Much work has been put into producing privacy-enhancing technologies that protect clients of online interactive Internet services. In this talk, we present ....

As the Internet grows in popularity around the world, we are beginning to see clashes between individuals and governments from different cultural backgrounds. Corporations, organizations, and legislatures are using local laws in order to enforce their wishes on others worldwide. Much work has been put into producing privacy-enhancing technologies that protect clients of online interactive Internet services. In this talk, we present ....

Distributed Intrusion Detection System Evasion Distributed Intrusion Detection System (DIDSE) A fast connection is the new era, but your IDS system can handle it?, your Operating System can handle it?. Can you handle it?. A DDoS is not the worse thing that an attacker can do in a distributed way. A evasion attack can take place while your IDS is just dropping packets, while it is just there checking an innumerable amount of u....

Distributed Intrusion Detection System Evasion Distributed Intrusion Detection System (DIDSE) A fast connection is the new era, but your IDS system can handle it?, your Operating System can handle it?. Can you handle it?. A DDoS is not the worse thing that an attacker can do in a distributed way. A evasion attack can take place while your IDS is just dropping packets, while it is just there checking an innumerable amount of u....

Macintosh Security has gone unnoticed by the public for many years, only recently it has become a topic due to the release of Apple's Mac OS X. With BSD functionality there is a whole new realm of security issues to be discussed. This years discussion will include the following, if there are other topics you would like discussed please email rnicholas@usa.net with the topics. # Secure Installation of Mac OS X # Configuring the firewa..

Macintosh Security has gone unnoticed by the public for many years, only recently it has become a topic due to the release of Apple's Mac OS X. With BSD functionality there is a whole new realm of security issues to be discussed. This years discussion will include the following, if there are other topics you would like discussed please email rnicholas@usa.net with the topics. # Secure Installation of Mac OS X # Configuring the firewa..

The protection of networked computers depends on the security and integrity of the underlying communication layers. In the last years, many people invested time to research bugs and exploits on the application level and less interest was on the network layers. We are going into the realms of protocols of ISO OSI layer 2 and 3. The audience will get a quick refresher on what Layer 2 and 3 are about and which general attack approaches e....

The protection of networked computers depends on the security and integrity of the underlying communication layers. In the last years, many people invested time to research bugs and exploits on the application level and less interest was on the network layers. We are going into the realms of protocols of ISO OSI layer 2 and 3. The audience will get a quick refresher on what Layer 2 and 3 are about and which general attack approaches e....

Two parties, both operating in hostile network territory, need to communicate covertly via an internetwork. They need to do so in a manner such that a well-resourced attacker cannot gain knowledge of the content of their transactions, nor even gain evidence beyond plausible deniability that discrete communication is taking place. The assumptions made are extreme; it is understood that lives may be at stake. Is the creation of such a ....

Two parties, both operating in hostile network territory, need to communicate covertly via an internetwork. They need to do so in a manner such that a well-resourced attacker cannot gain knowledge of the content of their transactions, nor even gain evidence beyond plausible deniability that discrete communication is taking place. The assumptions made are extreme; it is understood that lives may be at stake. Is the creation of such a ....

This talk will demonstrate each of the major (widely available) exploits against Red Hat 6.x, before and after hardening the system with Bastille Linux. The idea is to show, very concretely, how Bastille Linux was effective at stopping/containing attacks, before the exploit was ever written. This is not simply a "product demo" for an Open Source tool, though! We'll describe exactly what hardening steps are taken to combat each attack and ..

This talk will demonstrate each of the major (widely available) exploits against Red Hat 6.x, before and after hardening the system with Bastille Linux. The idea is to show, very concretely, how Bastille Linux was effective at stopping/containing attacks, before the exploit was ever written. This is not simply a "product demo" for an Open Source tool, though! We'll describe exactly what hardening steps are taken to combat each attack and ..

DEF CON 9 was held July 13th - 15th, 2001, in Las Vegas, Nevada USA. Past speeches and talks from DEF CON hacking conferences in an iTunes friendly m4v format. The DEFCON series of hacking conferences were started in 1993 to focus on both the technical and social trends in hacking, and has grown to be world known event. If you did not make it, or missed the speaker you wanted to see here is you chance to download and watch the present..

DEF CON 9 was held July 13th - 15th, 2001, in Las Vegas, Nevada USA. Past speeches and talks from DEF CON hacking conferences in an iTunes friendly m4b format. The DEFCON series of hacking conferences were started in 1993 to focus on both the technical and social trends in hacking, and has grown to be world known event. If you did not make it, or missed the speaker you wanted to see here is you chance to download and watch the present..

This years panel will build on last years format: A brief introduction and statement from each of the panel memebers, and then right into Audience Questions and Answers. Jim Christy will be moderating. So far the Panel includes: # OSD - Paul Smulian (Information Assurance) # GAO - Keith Rhodes (Chief Tech Officer) # Arizona State Representative Wes Marsh # NSA - Ray Semko, Interagency OPSEC Support Staff

This years panel will build on last years format: A brief introduction and statement from each of the panel memebers, and then right into Audience Questions and Answers. Jim Christy will be moderating. So far the Panel includes: # OSD - Paul Smulian (Information Assurance) # GAO - Keith Rhodes (Chief Tech Officer) # Arizona State Representative Wes Marsh # NSA - Ray Semko, Interagency OPSEC Support Staff

Polymorphism has been around for years in the form of virus attacks. There is a wealth of information pertaining to this. This presentation will concern itself with the implementation of an API designed to place some black-box code (probably shellcode) within an encoded structure and deliver it against a number of Architectures (SPARC,HP,IA32,more soon). This code has been tested thoroughly against a number of popular NIDS Sensors (..

Polymorphism has been around for years in the form of virus attacks. There is a wealth of information pertaining to this. This presentation will concern itself with the implementation of an API designed to place some black-box code (probably shellcode) within an encoded structure and deliver it against a number of Architectures (SPARC,HP,IA32,more soon). This code has been tested thoroughly against a number of popular NIDS Sensors (..

Windows 2000 provides a lot of new security features that were previously not available in earlier versions. The NT line, however, has never been considered very secure right out of the box. We'll be talking about how to use NTFS permissions, Default Security templates, Custom Security templates, and Group Policy to lock down a Win2k box. We'll look at what level of security is applied by default on a Win2k box, how to analyze these sett....

Windows 2000 provides a lot of new security features that were previously not available in earlier versions. The NT line, however, has never been considered very secure right out of the box. We'll be talking about how to use NTFS permissions, Default Security templates, Custom Security templates, and Group Policy to lock down a Win2k box. We'll look at what level of security is applied by default on a Win2k box, how to analyze these sett....

DEF CON 9 was held July 13th - 15th, 2001, in Las Vegas, Nevada USA. Past speeches and talks from DEF CON hacking conferences in an iTunes friendly m4v format. The DEFCON series of hacking conferences were started in 1993 to focus on both the technical and social trends in hacking, and has grown to be world known event. If you did not make it, or missed the speaker you wanted to see here is you chance to download and watch the present..

DEF CON 9 was held July 13th - 15th, 2001, in Las Vegas, Nevada USA. Past speeches and talks from DEF CON hacking conferences in an iTunes friendly m4b format. The DEFCON series of hacking conferences were started in 1993 to focus on both the technical and social trends in hacking, and has grown to be world known event. If you did not make it, or missed the speaker you wanted to see here is you chance to download and watch the present..

The goal of FreeCertis to provide free or low-cost certificate authority services to individuals and organizations with limited budgets, as well as raise awareness of the services that CA's actually provide. Many users of the Internet today are unaware of what role a CA plays in the process of secure website viewing. In my presentation, I intend to give a brief explanation of how SSL works and what it is that a CA does. I will explain ....

The goal of FreeCertis to provide free or low-cost certificate authority services to individuals and organizations with limited budgets, as well as raise awareness of the services that CA's actually provide. Many users of the Internet today are unaware of what role a CA plays in the process of secure website viewing. In my presentation, I intend to give a brief explanation of how SSL works and what it is that a CA does. I will explain ....

The different technologies today for providing IP-access over the air to handheld devices all pose some interesting questions about traditional securitywork. How to firewall? What is the physical differences of being on the "inside" versus the "outside" of the firewall? How to implement prudent securitymeasures if there is no security on the physical layer? Today, we can conclude that most base-stations used for Radio LAN:s, regardless of t....

The different technologies today for providing IP-access over the air to handheld devices all pose some interesting questions about traditional securitywork. How to firewall? What is the physical differences of being on the "inside" versus the "outside" of the firewall? How to implement prudent securitymeasures if there is no security on the physical layer? Today, we can conclude that most base-stations used for Radio LAN:s, regardless of t....

The study of Artificial Intelligence bring many treasures to the development of both offensive and defensive network tools. Code can be designed to make "intelligent" decisions based on a presented data sample. When rules are explicitly laid out by RFC to indicate proper connection handling, these rules can be mapped and recalled. This would allow for an automated handling of network traffic with decision making enforced on next-packet in....

The study of Artificial Intelligence bring many treasures to the development of both offensive and defensive network tools. Code can be designed to make "intelligent" decisions based on a presented data sample. When rules are explicitly laid out by RFC to indicate proper connection handling, these rules can be mapped and recalled. This would allow for an automated handling of network traffic with decision making enforced on next-packet in....

It is now an accepted fact that computer hackers, crackers, hacktivists, virus writers, and other politically-aware individuals in the computer underground are 'taking matters into their own hands.' Whether through website defacementsor full-scale denial-of-service attacks, non-governmental, non-aligned individuals and groups are conducting what the military refers to as 'information operations' of increasing sophistication. What is c....

It is now an accepted fact that computer hackers, crackers, hacktivists, virus writers, and other politically-aware individuals in the computer underground are 'taking matters into their own hands.' Whether through website defacementsor full-scale denial-of-service attacks, non-governmental, non-aligned individuals and groups are conducting what the military refers to as 'information operations' of increasing sophistication. What is c....

The old addage holds there is an inverse relationship between usability and security. The more user-friendly the system, the less secure it is. However, recent user heuristics research may lend insight into how to design more usable, more secure operating system interfaces--independent of the underlying OS architecture, AND the gullibility of the user. By highlighting the graphical and subtexual cues recently highlighted in popular OS....

The old addage holds there is an inverse relationship between usability and security. The more user-friendly the system, the less secure it is. However, recent user heuristics research may lend insight into how to design more usable, more secure operating system interfaces--independent of the underlying OS architecture, AND the gullibility of the user. By highlighting the graphical and subtexual cues recently highlighted in popular OS....

During my research with the “ICMP Usage In Scanning” project, I have discovered some new active and passive operating system fingerprinting methods using the ICMP protocol. Methods that are simple, and efficient. The active operating system fingerprinting methods were not correlated into a certain logic. A logic that would allow us to have the ability to use any available method in order to, wisely, actively fingerprint an operating s....

During my research with the "ICMP Usage In Scanning" project, I have discovered some new active and passive operating system fingerprinting methods using the ICMP protocol. Methods that are simple, and efficient. The active operating system fingerprinting methods were not correlated into a certain logic. A logic that would allow us to have the ability to use any available method in order to, wisely, actively fingerprint an operating s....

This is the release of KIS. KIS is a self contained binary that when executed on a system installs itself so that it will be loaded on reboot and loads a kernel module. This LKM hides itself, all of its subprocesses or desired processes, all of their files, directories, and network connections automatically. The presentation will consist of demonstrating how to setup and use KIS as well as explain some of the basic design concepts. O..

This is the release of KIS. KIS is a self contained binary that when executed on a system installs itself so that it will be loaded on reboot and loads a kernel module. This LKM hides itself, all of its subprocesses or desired processes, all of their files, directories, and network connections automatically. The presentation will consist of demonstrating how to setup and use KIS as well as explain some of the basic design concepts. O..

Mr. Shipley will discuss his latest research concerning open WLANs in the corporate and home environment. Early results will be presented along with maps illustrating the current threats showing that the current security models in 802.11 networking have set the state of network security back a decade. Mr. Shipley is one of the few individuals who is well known and highly respected in the professional world as well as the underground /....

Mr. Shipley will discuss his latest research concerning open WLANs in the corporate and home environment. Early results will be presented along with maps illustrating the current threats showing that the current security models in 802.11 networking have set the state of network security back a decade. Mr. Shipley is one of the few individuals who is well known and highly respected in the professional world as well as the underground /....

Microcontrollers" are microprocessors with additional peripherals, I/O controls, and memory all built into one chip. Last year, Phil introduced the wonderful world of 8-bit micro controllers and showed how to set up your own project development lab. This year he looks at more fun, cute, and devious electronic devices you can build, this time focusing on micro controllers with only 8 pins. What can you do with 2K of code spaces and only a ....

Microcontrollers" are microprocessors with additional peripherals, I/O controls, and memory all built into one chip. Last year, Phil introduced the wonderful world of 8-bit micro controllers and showed how to set up your own project development lab. This year he looks at more fun, cute, and devious electronic devices you can build, this time focusing on micro controllers with only 8 pins. What can you do with 2K of code spaces and only a ....

Denial of Service attacks are well known in the security field, but in recent years distributed Denial of Service attacks have become more of a worry and a priority to ISPs. Recognizing when a DDoS attack is crossing your network is important, and being able to shut it down at your network's edge is even more so. But due to the increasing ease of spoofing the source IPs of a DDoS attack, correctly finding where the traffic is entering you....

104 visitors online