Site uses cookies to provide basic functionality.
Javascript rendering is set to off by default when visiting the site via .onion and .i2p domains. It can be enabled back again in user's settings section. Javascript rendering set to off means, that you can disable javascript in your browser now and the site will remain functional.
There is also IRC server now available via native IRC clients or non javascript web based one.
Fonts can be adjusted in user's settings section as well.
Check FAQ for more.

OK


Presentation and demonstration of attack attempts against common security software. Highlighting use of common hacking tools to attack Boot Protection, File Encryption, and other misplaced ideas. Seeking out the weakest section of security architecture and attacking based upon it Demonstrations including: # sector editors # Windows based password attack programs (password grenadiers) # Windows window password broadcasting ....

DEF CON 9 was held July 13th - 15th, 2001, in Las Vegas, Nevada USA. Past speeches and talks from DEF CON hacking conferences in an iTunes friendly m4v format. The DEFCON series of hacking conferences were started in 1993 to focus on both the technical and social trends in hacking, and has grown to be world known event. If you did not make it, or missed the speaker you wanted to see here is you chance to download and watch the present..

DEF CON 9 was held July 13th - 15th, 2001, in Las Vegas, Nevada USA. Past speeches and talks from DEF CON hacking conferences in an iTunes friendly m4b format. The DEFCON series of hacking conferences were started in 1993 to focus on both the technical and social trends in hacking, and has grown to be world known event. If you did not make it, or missed the speaker you wanted to see here is you chance to download and watch the present..

CyberEthical Game - defcon.org - 16 years ago - eng
DEF CON 9 was held July 13th - 15th, 2001, in Las Vegas, Nevada USA. Past speeches and talks from DEF CON hacking conferences in an iTunes friendly m4v format. The DEFCON series of hacking conferences were started in 1993 to focus on both the technical and social trends in hacking, and has grown to be world known event. If you did not make it, or missed the speaker you wanted to see here is you chance to download and watch the present..

CyberEthical Game - defcon.org - 16 years ago - eng
DEF CON 9 was held July 13th - 15th, 2001, in Las Vegas, Nevada USA. Past speeches and talks from DEF CON hacking conferences in an iTunes friendly m4b format. The DEFCON series of hacking conferences were started in 1993 to focus on both the technical and social trends in hacking, and has grown to be world known event. If you did not make it, or missed the speaker you wanted to see here is you chance to download and watch the present..

DEF CON 9 was held July 13th - 15th, 2001, in Las Vegas, Nevada USA. Past speeches and talks from DEF CON hacking conferences in an iTunes friendly m4v format. The DEFCON series of hacking conferences were started in 1993 to focus on both the technical and social trends in hacking, and has grown to be world known event. If you did not make it, or missed the speaker you wanted to see here is you chance to download and watch the present..

Gateway Cryptography: Hacking Impossible Tunnels Through Improbable Networks with OpenSSH and the GNU Privacy Guard 1) Theory of Gateway Cryptography 2) Methods of securely connecting mutually firewalled hosts 3) Turning any SSHD into a VPN termination point (without using PPP over SSH) 4) Dynamically Rekeyed OpenPGP 5) PPTP over SSH 6) Securely SUing to root 7) Robustifying live-configuration of OpenSSH 8) SFTP Compatib..

Gateway Cryptography: Hacking Impossible Tunnels Through Improbable Networks with OpenSSH and the GNU Privacy Guard 1) Theory of Gateway Cryptography 2) Methods of securely connecting mutually firewalled hosts 3) Turning any SSHD into a VPN termination point (without using PPP over SSH) 4) Dynamically Rekeyed OpenPGP 5) PPTP over SSH 6) Securely SUing to root 7) Robustifying live-configuration of OpenSSH 8) SFTP Compatib..

The two greatest weaknesses of Intrusion Detection Systems (IDS) are the ease of which they may be evaded and their tendency to generate vast amounts of false alarms. Sophisticated attackers are able to easily avoid detection, maintaining a low profile by spreading out the attack both in time and (network) space. Meanwhile alerts are generated by normal user activity. IDS have not yet reached a level where they can reliably detect and as....

A presentation of the DMCA, a discussion of the terms and meanings with specific reference to the technical aspect of the Act, a case law study of specific cases around the country (not many as the law is very new and untested), and the repercussions of specific "hacking" acts that may result in a violation of the Act.

The two greatest weaknesses of Intrusion Detection Systems (IDS) are the ease of which they may be evaded and their tendency to generate vast amounts of false alarms. Sophisticated attackers are able to easily avoid detection, maintaining a low profile by spreading out the attack both in time and (network) space. Meanwhile alerts are generated by normal user activity. IDS have not yet reached a level where they can reliably detect and as....

A presentation of the DMCA, a discussion of the terms and meanings with specific reference to the technical aspect of the Act, a case law study of specific cases around the country (not many as the law is very new and untested), and the repercussions of specific "hacking" acts that may result in a violation of the Act.

The Defendant" put up a website critical of his ex-employer, and within a week found himself in the center of a $120,000 lawsuit, facing some of the most powerful lawyers and largest firms in the country. With a week to fight the restraining order put against him, he had to learn everything he needed to know about legal procedures, presenting a defense, and speaking to the press. Through this, he kept the website up, answered many questions..

The Defendant" put up a website critical of his ex-employer, and within a week found himself in the center of a $120,000 lawsuit, facing some of the most powerful lawyers and largest firms in the country. With a week to fight the restraining order put against him, he had to learn everything he needed to know about legal procedures, presenting a defense, and speaking to the press. Through this, he kept the website up, answered many questions..

I currently run my own computer consulting firm and I think that I can help others. I don't specialize in security, but obviously, there are similar tasks that need to be done. I would cover things like: - Incorporation - Taxes - Marketing - Keeping the client happy - Billing and getting paid To find out more about me, I invite you visit my web site at http://www.beridney.com There, you will find out about the books I have written an..

I currently run my own computer consulting firm and I think that I can help others. I don't specialize in security, but obviously, there are similar tasks that need to be done. I would cover things like: - Incorporation - Taxes - Marketing - Keeping the client happy - Billing and getting paid To find out more about me, I invite you visit my web site at http://www.beridney.com There, you will find out about the books I have written an..

The unchecked proliferation of global information networks has left society vulnerable to a digital Armageddon. Computer viruses can counter this vulnerability by stabilizing and strengthening information systems. Using analogies from medicine, this paper demonstrates the pressing need for well-designed computer viruses. This paper also proposes the design, implementation, and distribution of an open-source, international, attenuated comp..

The unchecked proliferation of global information networks has left society vulnerable to a digital Armageddon. Computer viruses can counter this vulnerability by stabilizing and strengthening information systems. Using analogies from medicine, this paper demonstrates the pressing need for well-designed computer viruses. This paper also proposes the design, implementation, and distribution of an open-source, international, attenuated comp..

As the Internet grows in popularity around the world, we are beginning to see clashes between individuals and governments from different cultural backgrounds. Corporations, organizations, and legislatures are using local laws in order to enforce their wishes on others worldwide. Much work has been put into producing privacy-enhancing technologies that protect clients of online interactive Internet services. In this talk, we present ....

As the Internet grows in popularity around the world, we are beginning to see clashes between individuals and governments from different cultural backgrounds. Corporations, organizations, and legislatures are using local laws in order to enforce their wishes on others worldwide. Much work has been put into producing privacy-enhancing technologies that protect clients of online interactive Internet services. In this talk, we present ....

Distributed Intrusion Detection System Evasion Distributed Intrusion Detection System (DIDSE) A fast connection is the new era, but your IDS system can handle it?, your Operating System can handle it?. Can you handle it?. A DDoS is not the worse thing that an attacker can do in a distributed way. A evasion attack can take place while your IDS is just dropping packets, while it is just there checking an innumerable amount of u....

Distributed Intrusion Detection System Evasion Distributed Intrusion Detection System (DIDSE) A fast connection is the new era, but your IDS system can handle it?, your Operating System can handle it?. Can you handle it?. A DDoS is not the worse thing that an attacker can do in a distributed way. A evasion attack can take place while your IDS is just dropping packets, while it is just there checking an innumerable amount of u....

Macintosh Security has gone unnoticed by the public for many years, only recently it has become a topic due to the release of Apple's Mac OS X. With BSD functionality there is a whole new realm of security issues to be discussed. This years discussion will include the following, if there are other topics you would like discussed please email rnicholas@usa.net with the topics. # Secure Installation of Mac OS X # Configuring the firewa..

Macintosh Security has gone unnoticed by the public for many years, only recently it has become a topic due to the release of Apple's Mac OS X. With BSD functionality there is a whole new realm of security issues to be discussed. This years discussion will include the following, if there are other topics you would like discussed please email rnicholas@usa.net with the topics. # Secure Installation of Mac OS X # Configuring the firewa..

The protection of networked computers depends on the security and integrity of the underlying communication layers. In the last years, many people invested time to research bugs and exploits on the application level and less interest was on the network layers. We are going into the realms of protocols of ISO OSI layer 2 and 3. The audience will get a quick refresher on what Layer 2 and 3 are about and which general attack approaches e....

The protection of networked computers depends on the security and integrity of the underlying communication layers. In the last years, many people invested time to research bugs and exploits on the application level and less interest was on the network layers. We are going into the realms of protocols of ISO OSI layer 2 and 3. The audience will get a quick refresher on what Layer 2 and 3 are about and which general attack approaches e....

Two parties, both operating in hostile network territory, need to communicate covertly via an internetwork. They need to do so in a manner such that a well-resourced attacker cannot gain knowledge of the content of their transactions, nor even gain evidence beyond plausible deniability that discrete communication is taking place. The assumptions made are extreme; it is understood that lives may be at stake. Is the creation of such a ....

Two parties, both operating in hostile network territory, need to communicate covertly via an internetwork. They need to do so in a manner such that a well-resourced attacker cannot gain knowledge of the content of their transactions, nor even gain evidence beyond plausible deniability that discrete communication is taking place. The assumptions made are extreme; it is understood that lives may be at stake. Is the creation of such a ....

This talk will demonstrate each of the major (widely available) exploits against Red Hat 6.x, before and after hardening the system with Bastille Linux. The idea is to show, very concretely, how Bastille Linux was effective at stopping/containing attacks, before the exploit was ever written. This is not simply a "product demo" for an Open Source tool, though! We'll describe exactly what hardening steps are taken to combat each attack and ..

This talk will demonstrate each of the major (widely available) exploits against Red Hat 6.x, before and after hardening the system with Bastille Linux. The idea is to show, very concretely, how Bastille Linux was effective at stopping/containing attacks, before the exploit was ever written. This is not simply a "product demo" for an Open Source tool, though! We'll describe exactly what hardening steps are taken to combat each attack and ..

DEF CON 9 was held July 13th - 15th, 2001, in Las Vegas, Nevada USA. Past speeches and talks from DEF CON hacking conferences in an iTunes friendly m4v format. The DEFCON series of hacking conferences were started in 1993 to focus on both the technical and social trends in hacking, and has grown to be world known event. If you did not make it, or missed the speaker you wanted to see here is you chance to download and watch the present..

DEF CON 9 was held July 13th - 15th, 2001, in Las Vegas, Nevada USA. Past speeches and talks from DEF CON hacking conferences in an iTunes friendly m4b format. The DEFCON series of hacking conferences were started in 1993 to focus on both the technical and social trends in hacking, and has grown to be world known event. If you did not make it, or missed the speaker you wanted to see here is you chance to download and watch the present..

This years panel will build on last years format: A brief introduction and statement from each of the panel memebers, and then right into Audience Questions and Answers. Jim Christy will be moderating. So far the Panel includes: # OSD - Paul Smulian (Information Assurance) # GAO - Keith Rhodes (Chief Tech Officer) # Arizona State Representative Wes Marsh # NSA - Ray Semko, Interagency OPSEC Support Staff

This years panel will build on last years format: A brief introduction and statement from each of the panel memebers, and then right into Audience Questions and Answers. Jim Christy will be moderating. So far the Panel includes: # OSD - Paul Smulian (Information Assurance) # GAO - Keith Rhodes (Chief Tech Officer) # Arizona State Representative Wes Marsh # NSA - Ray Semko, Interagency OPSEC Support Staff

Polymorphism has been around for years in the form of virus attacks. There is a wealth of information pertaining to this. This presentation will concern itself with the implementation of an API designed to place some black-box code (probably shellcode) within an encoded structure and deliver it against a number of Architectures (SPARC,HP,IA32,more soon). This code has been tested thoroughly against a number of popular NIDS Sensors (..

Polymorphism has been around for years in the form of virus attacks. There is a wealth of information pertaining to this. This presentation will concern itself with the implementation of an API designed to place some black-box code (probably shellcode) within an encoded structure and deliver it against a number of Architectures (SPARC,HP,IA32,more soon). This code has been tested thoroughly against a number of popular NIDS Sensors (..

Windows 2000 provides a lot of new security features that were previously not available in earlier versions. The NT line, however, has never been considered very secure right out of the box. We'll be talking about how to use NTFS permissions, Default Security templates, Custom Security templates, and Group Policy to lock down a Win2k box. We'll look at what level of security is applied by default on a Win2k box, how to analyze these sett....

Windows 2000 provides a lot of new security features that were previously not available in earlier versions. The NT line, however, has never been considered very secure right out of the box. We'll be talking about how to use NTFS permissions, Default Security templates, Custom Security templates, and Group Policy to lock down a Win2k box. We'll look at what level of security is applied by default on a Win2k box, how to analyze these sett....

DEF CON 9 was held July 13th - 15th, 2001, in Las Vegas, Nevada USA. Past speeches and talks from DEF CON hacking conferences in an iTunes friendly m4v format. The DEFCON series of hacking conferences were started in 1993 to focus on both the technical and social trends in hacking, and has grown to be world known event. If you did not make it, or missed the speaker you wanted to see here is you chance to download and watch the present..

DEF CON 9 was held July 13th - 15th, 2001, in Las Vegas, Nevada USA. Past speeches and talks from DEF CON hacking conferences in an iTunes friendly m4b format. The DEFCON series of hacking conferences were started in 1993 to focus on both the technical and social trends in hacking, and has grown to be world known event. If you did not make it, or missed the speaker you wanted to see here is you chance to download and watch the present..

The goal of FreeCertis to provide free or low-cost certificate authority services to individuals and organizations with limited budgets, as well as raise awareness of the services that CA's actually provide. Many users of the Internet today are unaware of what role a CA plays in the process of secure website viewing. In my presentation, I intend to give a brief explanation of how SSL works and what it is that a CA does. I will explain ....

The goal of FreeCertis to provide free or low-cost certificate authority services to individuals and organizations with limited budgets, as well as raise awareness of the services that CA's actually provide. Many users of the Internet today are unaware of what role a CA plays in the process of secure website viewing. In my presentation, I intend to give a brief explanation of how SSL works and what it is that a CA does. I will explain ....

The different technologies today for providing IP-access over the air to handheld devices all pose some interesting questions about traditional securitywork. How to firewall? What is the physical differences of being on the "inside" versus the "outside" of the firewall? How to implement prudent securitymeasures if there is no security on the physical layer? Today, we can conclude that most base-stations used for Radio LAN:s, regardless of t....

3 visitors online