Site uses cookies to provide basic functionality.
Javascript rendering is set to off by default when visiting the site via .onion and .i2p domains. It can be enabled back again in user's settings section. Javascript rendering set to off means, that you can disable javascript in your browser now and the site will remain functional.
There is also IRC server now available via native IRC clients or non javascript web based one.
Fonts can be adjusted in user's settings section as well.
Check FAQ for more.

OK

https://www.defcon.org/images/defcon-19/dc-19-presentations/Kennish/DEFCON-19-Kennish-Tracking-the-Trackers.pdf What companies and organizations are collecting our web-browsing activity? How complete is their data? Do they have personally-identifiable information? What do they do with the data? The speaker, an ex-Google and DoubleClick engineer, will answer these questions by detailing the research he did for The Wall Street Journ....

https://www.defcon.org/images/defcon-19/dc-19-presentations/Kornbrust/DEFCON-19-Kornbrust-Hacking-and-Securing-DB2.pdf DB2 for Linux, Unix and Windows is one of the databases where only little bit information about security problems is available. Nevertheless DB2 LUW is installed in many corporate networks and if not hardened properly could be an easy target for attackers. In many aspects DB2 is different from other databases, starting....

https://www.defcon.org/images/defcon-19/dc-19-presentations/Kotler-Amit/DEFCON-19-Kotler-Amit-Sounds-Like-Botnet.pdf VoIP is one of the most widely-used technologies among businesses and, increasingly, in households. It represents a combination of Internet technology and phone technology that enhances and expands the possibilities of both. One of these possibilities involves using it for botnet command and control infrastructure and a ....

https://www.defcon.org/images/defcon-19/dc-19-presentations/Krick/DEFCON-19-Krick-License-to-Transmit.pdf https://www.defcon.org/images/defcon-19/dc-19-presentations/Krick/Extras.zip When cell phones, land lines and the internet break down in a disaster, Amateur radio is there. Considered to be one of the earliest forms of Hacking, this talk will take a look at some of the things that can be done if you are a licensed amateur radi..

https://www.defcon.org/images/defcon-19/dc-19-presentations/Lai-Wu-Chiu-PK/DEFCON-19-Lai-Wu-Chiu-PK-APT-Secrets-2.pdf In last year, we have given a talk over China-made malware in both Blackhat and DEFCON, which is appreciated by various parties and we would like to continue this effort and discuss over APT attacks in Asia this year. However, case studies are not just our main dish this time, we will carry out technical analysis over t....

Are you concerned that you have become a subject of unwarranted scrutiny? Convinced that the black helicopters are incoming and ruthless feds are determined in to steal your plans of world domination? This talk explores several potential designs for quick and ruthless destruction of data as a last resort, break glass in case of emergency type of situation. Projectiles and chemical warfare will be involved along with other methods. Each meth....

https://www.defcon.org/images/defcon-19/dc-19-presentations/Lenik/DEFCON-19-Lenik-MAC(b)Daddy.pdf The field of Computer Forensics moves more and more in the direction of rapid response and live system analysis every day. As breaches and attacks become more and more sophisticated the responders need to continually re-examine their arsenal for new tactics and faster ways to process large amounts of data. Timelines and super-timelines hav....

https://www.defcon.org/images/defcon-19/dc-19-presentations/Linn/DEFCON-19-Linn-PIG-Finding-Truffles.pdf When we connect to a network we leak information. Whether obtaining an IP address, finding our default gateway, or using Dropbox there are packets that can be used to help identify more about our machine and network. This talk and series of demonstrations will help you learn to passively profile a network through a new Metasploit mo....

David Litchfield is recognized as one of the world's leading authorities on database security. He is the author of Oracle Forensics, the Oracle Hacker's Handbook, the Database Hacker's Handbook and SQL Server Security and is the co-author of the Shellcoder's Handbook. He is a regular speaker at a number of computer security conferences and has delivered lectures to the National Security Agency, the UK's Security Service, GCHQ and the Bundes..

What Cloak? Recent policy proposals from the US Executive seem to call for government support for strong encryption use by individuals and vendors in the name of protecting privacy and anonymity. Yet strong encryption is still considered a controlled resource, requiring explicit permission to import or export from the US. This is also true for other countries. This talk will try to couch these proposals in light of past crypto rules, illumi..

https://www.defcon.org/images/defcon-19/dc-19-presentations/Maresca/DEFCON-19-Maresca-FIPS-140.pdf Many standards, especially those provided by the government, are often viewed as more trouble the actual help. The goal of this talk is to shed a new light onto onesuch standard (FIPS 140) and show what it is inteded for and how is can sometimes help ensure good design practices for security products. But everything is not roses and there....

In the early 90's, at the dawn of the World Wide Web, some engineers at Netscape developed a protocol for making secure HTTP requests, and what they came up with was called SSL. Given the relatively scarce body of knowledge concerning secure protocols at the time, as well the intense pressure that everyone at Netscape was working under, their efforts can only be seen as incredibly heroic. But while it's amazing that SSL has endured for as l..

This presentation will cover the Black Arts of making Cracks, KeyGens, Malware, and more. The information in this presentation will allow a .NET programmer to do unspeakable things .NET applications. I will cover the life cycle of developing such attacks and over coming common countermeasures to stop such attacks. New tools to assist in the attacks will be supplied. This presentation will focus on C# but applies to any application based on ..

https://www.defcon.org/images/defcon-19/dc-19-presentations/McGrew/DEFCON-19-McGrew-Covert.pdf https://www.defcon.org/images/defcon-19/dc-19-presentations/McGrew/DEFCON-19-McGrew-Covert-WP.pdf https://www.defcon.org/images/defcon-19/dc-19-presentations/McGrew/Extras.zip In digital forensics, most examinations take place after the hardware has been physically seized (in most law enforcement scenarios) or a preinstalled agent a....

https://www.defcon.org/images/defcon-19/dc-19-presentations/McNabb/DEFCON-19-McNabb-Vulns-Wireless-Water-Meter-Networks.pdf Why research wireless water meters? Because they are a potential security hole in a critical infrastructure, which can lead to a potential leakage of private information, and create the potential to steal water by lowering water bills? It's a technology that's all around us but seems to too mundane to think about.....

https://www.defcon.org/images/defcon-19/dc-19-presentations/Miller/DEFCON-19-Miller-Battery-Firmware-Hacking.pdf Ever wonder how your laptop battery knows when to stop charging when it is plugged into the wall, but the computer is powered off? Modern computers are no longer just composed of a single processor. Computers possess many other embedded microprocessors. Researchers are only recently considering the security implications of m....

We're baaaaaack! The most talked about panel at DEF CON! Nearly two hours of non-stop FAIL. Come hear some of the loudest mouths in the industry talk about the epic security failures of the last year. We'll be covering mobile phones, cloud, money laundering and food cooked on stage to name just a few topics. Nothing is sacred not even each other. Come for the FAIL stay for the crepes! David Mortman runs Operations and Security for C3, ....

https://www.defcon.org/images/defcon-19/dc-19-presentations/Ocepek/DEFCON-19-Ocepek-Blinkie-Lights-Arduino.pdf https://www.defcon.org/images/defcon-19/dc-19-presentations/Ocepek/Extras.zip Remember the good old days, when you'd stare at Rx and Tx on your shiny new Supra 1200bps modem, and actually know what the heck was going on? Systems tend to talk a lot more nowadays, and somewhere along the line I completely lost track of who ....

Get the latest information about how the law is racing to catch up with technological change from staffers at the Electronic Frontier Foundation, the nation's premiere digital civil liberties group fighting for freedom and privacy in the computer age. This session will include updates on current EFF issues such as surveillance online and fighting efforts to use intellectual property claims to shut down free speech and halt innovation, discu....

https://www.defcon.org/images/defcon-19/dc-19-presentations/Osborn-Johansen/DEFCON-19-Osborn-Johansen-Hacking-Google-Chrome-OS.pdf Google recently announced Chrome OS powered computers, called Chromebooks, at Google I/O and the company is getting ready to market them to businesses as well as consumers. What's different about Chrome OS and Chromebooks, other than the entire user-experience taking place exclusively in a Web browser (Goog....

This presentation is about the security of VoIP deployed in hotel guest rooms. What it is, why it benefits administrators and users, and how easily it can be broken. The hospitality industry is widely deploying VoIP. Since 2008, we've seen an increase of these rollouts along with Admin awareness of applying the required security controls in order to mitigate this potential backdoor into a company's mission critical data and systems - their ....

Can the NSA really do that? Um, yes. Join me at the movies to take a close look at how current technology has caught up with the spy gadgets dreamed up for Hollywood flicks- from old favorites like Brazil to newer additions like Bourne and Dark Knight. Jaunty tin foil hats and movie snacks will be provided! Nicole Ozer directs the Technology and Civil Liberties Program at the ACLU of Northern California and spearheads the organization'....

https://www.defcon.org/images/defcon-19/dc-19-presentations/Percoco-Spiderlabs/DEFCON-19-Percoco-Spiderlabs-SSLizzard.pdf Extra Materials Here: https://www.defcon.org/images/defcon-19/dc-19-presentations/Percoco-Spiderlabs/Extras/SSLizzard.zip The world has seen a seismic shift from browser-based web applications to GUI-rich semi-thick client applications running on handheld mobile devices. In the browser world, the industry had p....

https://www.defcon.org/images/defcon-19/dc-19-presentations/Percoco-Spiderlabs/DEFCON-19-Percoco-Spiderlabs-Malware-Freakshow-3.pdf Well There's malware on the interwebs. They're pwning all your systems, snatching your data up. So hide your cards, hide your docs, and hide your phone, 'cause they're pwning er'body out there! This may be the 3rd and final installment of the Malware Freak Show series, so we're pulling out all the stops. T....

https://www.defcon.org/images/defcon-19/dc-19-presentations/Percoco-Spiderlabs/DEFCON-19-Percoco-Spiderlabs-Droid.pdf Extra Materials Here: https://www.defcon.org/images/defcon-19/dc-19-presentations/Percoco-Spiderlabs/Extras/DEFCON-19-Percoco-Droid-BanthaPudu-1.0.apk Last year, we presented a talk on the implication of malware and rootkits on mobile devices. We focused on the kernel layer of the Android OS stack. With the prolife....

https://www.defcon.org/images/defcon-19/dc-19-presentations/Phillips/DEFCON-19-Phillips-Hacking-MMORPGs.pdf Extra Materials Here: https://www.defcon.org/images/defcon-19/dc-19-presentations/Phillips/Extras.zip Online games, such as MMORPG's, are the most complex multi-user applications ever created. The security problems that plague these games are universal to all distributed software systems. Online virtual worlds are eventually....

https://www.defcon.org/images/defcon-19/dc-19-presentations/Pickett/DEFCON-19-Pickett-Port-Scanning-Without-Packets.pdf https://www.defcon.org/images/defcon-19/dc-19-presentations/Pickett/DEFCON-19-Pickett-Resources.pdf With auto-configuration protocols now being added to operating systems and implemented by default in your network devices, hosts are now actively advertising their available attack surfaces to anyone listening on t....

Being a most prevalent document exchange format on the Internet, Portable Document Format (PDF) is in danger of becoming the main target for client-side attack. With estimation of more than 1.5 million line of code and loaded with huge functionalities, this powerful document format is suffered with several high impact vulnerabilities, allowing attackers to exploit and use it as malware spreading vector. Until now, there are thousands o....

https://www.defcon.org/images/defcon-19/dc-19-presentations/Rezchikov-Wang-Engelman/DEFCON-19-Rezchikov-Wang-Engelman-Airport-Security-WP.pdf Eight years after 9/11 TSA finally decided to fix their security system. But what has really changed? Homeland Security's science division has been busy lately, and is currently polishing up a project called FAST - Future Attribute Screening Technology. FAST, part of project MALINTENT, is a proje....

Whoever fights monsters should see to it that in the process he does not become a monster." - Friedrich Nietzsche. Aaron Barr returns for the first time in what's sure to be a gritty and frank (and heated) panel. How can we conduct ourselves without losing ourselves? How far is too far - or not far enough? IT security has finally gotten the attention of the mainstream media, Pentagon generals and public policy authors in the Beltway, a....

https://www.defcon.org/images/defcon-19/dc-19-presentations/Robinson/DEFCON-19-Robinson-Time.pdf Computer forensic examiners rely heavily on timestamps during investigations. Timeline analysis is a critical technique in determining what happened and when. In 2005, timestomp.exe was released and this gave non-observant investigators a run for their money. Unfortunately, there are some gaps in what timestomp.exe will do. Observant invest....

Originally considered to be the stuff of myth, remote kernel exploits allow attackers to bypass all operating system protection mechanisms and gain instant root access to remote systems. While reviewing prior work in remote kernel exploitation, this talk will go over some of the challenges and limitations associated with developing remote kernel exploits. We will discuss in detail the development of an exploit for a remotely triggerabl....

Radar is used extensively by the military, police, weather, air travel, and maritime industries - why not you? Come learn how to build a radar imaging system on the cheap! This talk will explain the basics of how radar works as well as how to measure range and velocity of your chosen targets. You will learn how to use synthetic aperture techniques to generate a two- or even three-dimensional image. The hardware and software design will be t....

Over the last five years, network neutrality has moved from an abstract buzzword to FCC-enacted policy. Supporters and detractors both contend that their opponents position means "the end of the Internet as we know it!" This panel discussion will present a reasoned discussion of the issue from multiple viewpoints. Among the issues to answer: What is network neutrality and can we even agree on a definition? Does the FCC have the authority to..

https://www.defcon.org/images/defcon-19/dc-19-presentations/Schearer/DEFCON-19-Schearer-WTF-Privacy.pdf There is no explicit right to privacy in the Constitution, but some aspects of privacy are protected by the First, Third, Fourth and Fifth Amendments. This presentation will discuss the historical development of the right to privacy, and in particular, the development of the Fourth Amendment; and then compares this historical develop....

For the last few years, historian and archivist Jason Scott has been involved with a loose, rogue band of data preservation activists called The Archive Team. As major sites with brand recognition and the work of millions announce short-notice shutdowns of their entire services, including Geocities, Friendster, and Yahoo Video, Archive Team arrives on the scene to duplicate as much as they possibly can for history before all the data is wip....

The Smart Grid brings greater benefits for utilities and customer alike, however these benefits come at a cost from a security perspective. Unlike the over-hyped messages we usually hear from the media, the sky is NOT falling. However, just like any other technology, the systems and devices that make up the Smart Grid will have weaknesses and vulnerabilities. It is important for us to understand these vulnerabilities, how they can be attack....

https://www.defcon.org/images/defcon-19/dc-19-presentations/Shah/DEFCON-19-Shah-Mobile-Moolah.pdf Smartphones are a hot new market for software developers. Millions of potential customers, and a large percentage willing to part with a small sum of money for your latest creation. Even a moderately successful app can help fill your pockets. It's hard to ignore for legitimate developers. It's even harder to ignore for criminals. Thin....

When a CISO pays good money for a thorough pentesting, she wants results. Not necessarily the ones that the pentester had in mind, either. Whether the time allotted is too short, the pentester has to achieve multiple objectives, or they disagree on the severity of the findings, both the CISO and the pentester have to agree on both sides of the engagement. We discuss numerous aspects of voluntary pwnage: the differences between a security as..

https://www.defcon.org/images/defcon-19/dc-19-presentations/Skunkworks/DEFCON-19-Skunkworks-Bitcoin.pdf In the post 9/11 era when it's nearly impossible to buy a pack of gum without alerting the big three credit bureaus, you may think that anonymity is long gone from the economy. That's where bitcoin comes in. Bitcoin is a decentralized peer-to-peer currency based solely on computing power. It is (mostly) untraceable and highly anonymo..

Halloween makers or how haunters void warranties, social engineer and find the joy of creativity. A short path down to what a community of makers that mod hardware, special effect and mood you in order to scare the shit out of you just one night a year. These people comprise electrical engineers to housewives and personally I've learned to solder better, faster because of it. Reeves Smith has been working with hardware for security's s..

https://www.defcon.org/images/defcon-19/dc-19-presentations/Street/DEFCON-19-Street-Steal-Everything.pdf This is not a presentation where I talk about how I would get in or the things I might be able to do. This is a talk where I am already in and I show you pictures from actual engagements that I have been on. They say one picture is worth a thousand words I show you how one picture cost a company a million dollars and maybe even a fe....

https://www.defcon.org/images/defcon-19/dc-19-presentations/Sumner-Byers-Alien/DEFCON-19-Sumner-Byers-Alien-Weaponizing-Cyberpsychology.pdf Almost everything we do in life leaves a personality footprint and what we do on social networking sites like Facebook is no exception. During this talk we will examine: * What it is possible to determine about someone's personality from their facebook activity * What to look for when you ....

https://www.defcon.org/images/defcon-19/dc-19-presentations/Swende-Karlsson/DEFCON-19-Swende-Karlsson-Owasp-Hatkit.pdf The presentation will take a deep dive into two newly released Owasp tools; the Owasp Hatkit Proxy and the Owasp Hatkit Datafiddler. The name Hatkit is an acronym (of sorts) for Http Analysis Toolkit and are tools mainly for people who analyse (hack!) web applications. The tools make extensive use of MongoDB, in particul....

17 visitors online