Site uses cookies to provide basic functionality.
Javascript rendering is set to off by default when visiting the site via .onion and .i2p domains. It can be enabled back again in user's settings section. Javascript rendering set to off means, that you can disable javascript in your browser now and the site will remain functional.
There is also IRC server now available via native IRC clients or non javascript web based one.
Fonts can be adjusted in user's settings section as well.
Check FAQ for more.

OK

Defcon Security Jam 2: The Fails Keep on Coming David Mortman CSO in Residence, Echelon One Rich Mogull Securosis Dave Maynor Founder&CTO Errata Security Larry Pesce Paul.com Robert "RSnake" Hansen ha.ckers.org We're baaaack. Yup that's right, some of the biggest mouths in Information Security and once again, we will show you all new of security FAIL. Our panelists will demonstrate innovative hacking techniques in naked wirel....

The security risks of Web 2.0 David Rook Web 2.0 technologies are changing the landscape of the Internet by delivering significant increases in the functionality of websites and providing a more interactive experience to the user. This rapid proliferation of new technologies is also accompanied by new attack vectors that hackers are eager to exploit. I will detail the security risks introduced by web 2.0 and how you can prevent them.....

DEFCON 1 - A Personal Account Dead Addict As time slips away, so do the memories of cons past. In this talk I'm going to talk about DC1, its planning, execution, components, and challenges. I'll give snippets of seemingly practical advise; don't design T-shirts with lots of dense text on the back, no matter how clever. I'll discuss of obvious misjudgments; don't invite both the prosecutor and the subject of an active prosec....

Unfair Use - Speculations on the Future of Piracy Dead Addict Piracy has always been a sophisticated, if not chaotically organized effort - from acquisition, packaging, distribution, risk analysis and managing criminal volunteers. Piracy has moved from software, to all mediums - books, comic books, knitting patterns, video medium of all kinds. Despite distinctions in types of piracy, there are evolutionary measures that need to ....

Welcome to Defcon 17 with Dark Tangent and the Making of & Hacking the DC17 Badge Joe Grand (Kingpin) & The Dark Tangent For the fourth year in a row, the DEFCON Badge makes its appearance as a full-fledged, active electronic system. Pushing fabrication techniques to the limit and using some components that are so new they barely exist, the design of this year's badge took some serious risks. Did they pay off? You be the judge! Every....

Welcome to Defcon 17 with Dark Tangent and the Making of & Hacking the DC17 Badge Joe Grand (Kingpin) & The Dark Tangent For the fourth year in a row, the DEFCON Badge makes its appearance as a full-fledged, active electronic system. Pushing fabrication techniques to the limit and using some components that are so new they barely exist, the design of this year's badge took some serious risks. Did they pay off? You be the judge! Every....

Welcome to Defcon 17 with Dark Tangent and the Making of & Hacking the DC17 Badge Joe Grand (Kingpin) & The Dark Tangent For the fourth year in a row, the DEFCON Badge makes its appearance as a full-fledged, active electronic system. Pushing fabrication techniques to the limit and using some components that are so new they barely exist, the design of this year's badge took some serious risks. Did they pay off? You be the judge! Every....

Dark Tangent and Defcon Staff Closing Ceremonies The Conference is wrapped up, Closing speech by The Dark Tangent, Thank you speeches are given and Contest results are announced.

Dark Tangent and Defcon Staff Closing Ceremonies The Conference is wrapped up, Closing speech by The Dark Tangent, Thank you speeches are given and Contest results are announced.

Dark Tangent and Defcon Staff Closing Ceremonies The Conference is wrapped up, Closing speech by The Dark Tangent, Thank you speeches are given and Contest results are announced.

Something about Network Security Dan Kaminsky IOActive Dan Kaminsky is the Director of Penetration Testing for Seattle-based IOActive, where he is greatly enjoying having minions. Formerly of Cisco and Avaya, Dan was most recently one of the "Blue Hat Hackers" tasked with auditing Microsoft's Vista client and Windows Server 2008 operating systems. He specializes in absurdly large scale network sweeps, strange packet tricks, and de..

Automated Malware Similarity Analysis Daniel Raygoza DC3 / General Dynamics While it is fairly straightforward for a malware analyst to compare two pieces of malware for code reuse, it is not a simple task to scale to thousands of pieces of code. Many existing automated approaches focus on runtime analysis and critical trait extraction through signatures, but they don't focus on code reuse. Automated code reuse detection can help mal....

Reverse Engineering By Crayon: Game Changing Hypervisor Based Malware Analysis and Visualization Danny Quist CEO, Offensive Computing Lorie M. Liebrock New Mexico Tech Computer Science Department Recent advances in hypervisor based application profilers have changed the game of reverse engineering. These powerful tools have made it orders of magnitude easier to reverse engineer and enabled the next generation of analysis techniques....

Something about Network Security Dan Kaminsky IOActive Dan Kaminsky is the Director of Penetration Testing for Seattle-based IOActive, where he is greatly enjoying having minions. Formerly of Cisco and Avaya, Dan was most recently one of the "Blue Hat Hackers" tasked with auditing Microsoft's Vista client and Windows Server 2008 operating systems. He specializes in absurdly large scale network sweeps, strange packet tricks, and de..

Automated Malware Similarity Analysis Daniel Raygoza DC3 / General Dynamics While it is fairly straightforward for a malware analyst to compare two pieces of malware for code reuse, it is not a simple task to scale to thousands of pieces of code. Many existing automated approaches focus on runtime analysis and critical trait extraction through signatures, but they don't focus on code reuse. Automated code reuse detection can help mal....

Reverse Engineering By Crayon: Game Changing Hypervisor Based Malware Analysis and Visualization Danny Quist CEO, Offensive Computing Lorie M. Liebrock New Mexico Tech Computer Science Department Recent advances in hypervisor based application profilers have changed the game of reverse engineering. These powerful tools have made it orders of magnitude easier to reverse engineer and enabled the next generation of analysis techniques....

Automated Malware Similarity Analysis Daniel Raygoza DC3 / General Dynamics While it is fairly straightforward for a malware analyst to compare two pieces of malware for code reuse, it is not a simple task to scale to thousands of pieces of code. Many existing automated approaches focus on runtime analysis and critical trait extraction through signatures, but they don't focus on code reuse. Automated code reuse detection can help mal....

Confidence Game Theater Cough Security Researcher This presentation will include a brief discussion of the history, nature, and basic principles behind Confidence Games. For the bulk of the presentation we will be acting out some Confidence Games in skit form. Cough is an amateur historian with a strong interest in crimes of deception.

AAPL- Automated Analog Telephone Logging Da Beave Security Researcher JFalcon Security Researcher Since 1983 when Hollywood introduced "Wardialing" to the public, there has been little change in the methods involved. While some pieces of hardware attempted to take it beyond what was essentially a telephonic "ping" scan, the methods and technology didn't maintain that momentum. However, thanks to modern computing and open source sof....

Confidence Game Theater Cough Security Researcher This presentation will include a brief discussion of the history, nature, and basic principles behind Confidence Games. For the bulk of the presentation we will be acting out some Confidence Games in skit form. Cough is an amateur historian with a strong interest in crimes of deception.

AAPL- Automated Analog Telephone Logging Da Beave Security Researcher JFalcon Security Researcher Since 1983 when Hollywood introduced "Wardialing" to the public, there has been little change in the methods involved. While some pieces of hardware attempted to take it beyond what was essentially a telephonic "ping" scan, the methods and technology didn't maintain that momentum. However, thanks to modern computing and open source sof....

Confidence Game Theater Cough Security Researcher This presentation will include a brief discussion of the history, nature, and basic principles behind Confidence Games. For the bulk of the presentation we will be acting out some Confidence Games in skit form. Cough is an amateur historian with a strong interest in crimes of deception.

AAPL- Automated Analog Telephone Logging Da Beave Security Researcher JFalcon Security Researcher Since 1983 when Hollywood introduced "Wardialing" to the public, there has been little change in the methods involved. While some pieces of hardware attempted to take it beyond what was essentially a telephonic "ping" scan, the methods and technology didn't maintain that momentum. However, thanks to modern computing and open source sof....

RFID MythBusting Chris Paget Founder, H4RDW4RE LLC This presentation is about challenging many of the popular preconceptions about RFID technology. "Short-range" will be shot down first (I'm aiming to set a half-mile world record in the Nevada desert just before Defcon), "secure" will be busted second (don't bring _any_ RFID tags unless you want them cloned), "immune to electromagnetic pulse weaponry" will fall last (and hopefully mo..

Subverting the World Of Warcraft API Christopher Mooney Software Engineer, Project DoD Inc. James Luedke Software Engineer, Project DoD Inc. The authors will demonstrate how to work within the World of Warcraft API framework to re-enable the features of protected and disabled functions. They will explain their library and how to use it to get around the restrictions on programmatically casting spells, targeting, moving, and perform....

Manipulation and Abuse of the Consumer Credit Reporting Agencies Christopher Soghoian This talk will present a number of loopholes and exploits against the system of consumer credit in the United States that can enable a careful attacker to hugely leverage her (or someone else's) credit report for hundreds of thousands of dollars. While the techniques outlined in this talk have been used for the personal (and legal) profit by a small....

Hack like the Movie Stars: A Big-Screen Multi-Touch Network Monitor George Louthan Research Assistant, University of Tulsa Cody Pollet Research Assistant, University of Tulsa You know all those movies where exaggerated nerd-types accomplish impossible hacking feats using a ridiculous, big-screen friendly, animated graphical interface where they appear to fly through the network, performing complicated tasks with the flick of their ....

RFID MythBusting Chris Paget Founder, H4RDW4RE LLC This presentation is about challenging many of the popular preconceptions about RFID technology. "Short-range" will be shot down first (I'm aiming to set a half-mile world record in the Nevada desert just before Defcon), "secure" will be busted second (don't bring _any_ RFID tags unless you want them cloned), "immune to electromagnetic pulse weaponry" will fall last (and hopefully mo..

Subverting the World Of Warcraft API Christopher Mooney Software Engineer, Project DoD Inc. James Luedke Software Engineer, Project DoD Inc. The authors will demonstrate how to work within the World of Warcraft API framework to re-enable the features of protected and disabled functions. They will explain their library and how to use it to get around the restrictions on programmatically casting spells, targeting, moving, and perform....

Manipulation and Abuse of the Consumer Credit Reporting Agencies Christopher Soghoian This talk will present a number of loopholes and exploits against the system of consumer credit in the United States that can enable a careful attacker to hugely leverage her (or someone else's) credit report for hundreds of thousands of dollars. While the techniques outlined in this talk have been used for the personal (and legal) profit by a small....

Hack like the Movie Stars: A Big-Screen Multi-Touch Network Monitor George Louthan Research Assistant, University of Tulsa Cody Pollet Research Assistant, University of Tulsa You know all those movies where exaggerated nerd-types accomplish impossible hacking feats using a ridiculous, big-screen friendly, animated graphical interface where they appear to fly through the network, performing complicated tasks with the flick of their ....

RFID MythBusting Chris Paget Founder, H4RDW4RE LLC This presentation is about challenging many of the popular preconceptions about RFID technology. "Short-range" will be shot down first (I'm aiming to set a half-mile world record in the Nevada desert just before Defcon), "secure" will be busted second (don't bring _any_ RFID tags unless you want them cloned), "immune to electromagnetic pulse weaponry" will fall last (and hopefully mo..

Subverting the World Of Warcraft API Christopher Mooney Software Engineer, Project DoD Inc. James Luedke Software Engineer, Project DoD Inc. The authors will demonstrate how to work within the World of Warcraft API framework to re-enable the features of protected and disabled functions. They will explain their library and how to use it to get around the restrictions on programmatically casting spells, targeting, moving, and perform....

Manipulation and Abuse of the Consumer Credit Reporting Agencies Christopher Soghoian This talk will present a number of loopholes and exploits against the system of consumer credit in the United States that can enable a careful attacker to hugely leverage her (or someone else's) credit report for hundreds of thousands of dollars. While the techniques outlined in this talk have been used for the personal (and legal) profit by a small....

Hack like the Movie Stars: A Big-Screen Multi-Touch Network Monitor George Louthan Research Assistant, University of Tulsa Cody Pollet Research Assistant, University of Tulsa You know all those movies where exaggerated nerd-types accomplish impossible hacking feats using a ridiculous, big-screen friendly, animated graphical interface where they appear to fly through the network, performing complicated tasks with the flick of their ....

Q & A with Bruce Schneier Bruce Schneier is an internationally renowned security technologist and CTO of BT Counterpane, referred to by The Economist as a "security guru." He is the author of eight books -- including the best sellers "Beyond Fear: Thinking Sensibly about Security in an Uncertain World," "Secrets and Lies," and "Applied Cryptography" -- and hundreds of articles and academic papers. His influential newsletter, Crypto-Gra..

Proxy Prank-o-Matic Charlie Vedaa Founder @ PacketProtector.org "Anonymous secondary speaker" The Upside-Down-Ternet was just the beginning. What else can you do with a proxy server and a mischievous mind? We'll show you how to send your victims back in time (fun with archive.org), to the all-porn Internet (is there any other kind?), or to the Tourette-net (Cartman runs the Internets)! Via browser settings or port forwarding, using..

Tactical Fingerprinting Using Metadata, Hidden Info and Lost Data Chema Alonso MVP Enterprise Security, CTO Inform·tica64 Jose Palazon "Palako" Yahoo! In 2003 Tony Blair was "bytten" by a word document which its metadata demonstrated had been edited. Since that days a lot of advisories warning about to keep free of undesired data all published document shown up around the whole Internet... but times went by and people don't worry s....

Breaking the "Unbreakable" Oracle with Metasploit Chris Gates Member of the Metasploit Project Mario Ceballos Developer for the Metasploit Project Over the years there have been tons of Oracle exploits, SQL Injection vulnerabilities, and post exploitation tricks and tools that had no order, methodology, or standardization, mainly just random .sql files. Additionally, none of the publicly available Pentest Frameworks have the abilit....

Q & A with Bruce Schneier Bruce Schneier is an internationally renowned security technologist and CTO of BT Counterpane, referred to by The Economist as a "security guru." He is the author of eight books -- including the best sellers "Beyond Fear: Thinking Sensibly about Security in an Uncertain World," "Secrets and Lies," and "Applied Cryptography" -- and hundreds of articles and academic papers. His influential newsletter, Crypto-Gra..

Proxy Prank-o-Matic Charlie Vedaa Founder @ PacketProtector.org "Anonymous secondary speaker" The Upside-Down-Ternet was just the beginning. What else can you do with a proxy server and a mischievous mind? We'll show you how to send your victims back in time (fun with archive.org), to the all-porn Internet (is there any other kind?), or to the Tourette-net (Cartman runs the Internets)! Via browser settings or port forwarding, using..

Tactical Fingerprinting Using Metadata, Hidden Info and Lost Data Chema Alonso MVP Enterprise Security, CTO Inform·tica64 Jose Palazon "Palako" Yahoo! In 2003 Tony Blair was "bytten" by a word document which its metadata demonstrated had been edited. Since that days a lot of advisories warning about to keep free of undesired data all published document shown up around the whole Internet... but times went by and people don't worry s....

Breaking the "Unbreakable" Oracle with Metasploit Chris Gates Member of the Metasploit Project Mario Ceballos Developer for the Metasploit Project Over the years there have been tons of Oracle exploits, SQL Injection vulnerabilities, and post exploitation tricks and tools that had no order, methodology, or standardization, mainly just random .sql files. Additionally, none of the publicly available Pentest Frameworks have the abilit....

Q & A with Bruce Schneier Bruce Schneier is an internationally renowned security technologist and CTO of BT Counterpane, referred to by The Economist as a "security guru." He is the author of eight books -- including the best sellers "Beyond Fear: Thinking Sensibly about Security in an Uncertain World," "Secrets and Lies," and "Applied Cryptography" -- and hundreds of articles and academic papers. His influential newsletter, Crypto-Gra..

4 visitors online