Site uses cookies to provide basic functionality.
Javascript rendering is set to off by default when visiting the site via .onion and .i2p domains. It can be enabled back again in user's settings section. Javascript rendering set to off means, that you can disable javascript in your browser now and the site will remain functional.
There is also IRC server now available via native IRC clients or non javascript web based one.
Fonts can be adjusted in user's settings section as well.
Check FAQ for more.

OK

Get the latest information about how the law is racing to catch up with technological change from staffers at the Electronic Frontier Foundation, the nation's premiere digital civil liberties group fighting for freedom and privacy in the computer age. This session will include updates on current EFF issues such as NSA wiretapping and fighting efforts to use intellectual property claims to shut down free speech and halt innovation, highlight....

An autoimmune disorder is a condition that occurs when the immune system mistakenly attacks and destroys healthy body tissue. This presentation is about discovery of autoimmunity disorder in select open source and commercial 802.11 AP implementations. By sending specially crafted packets, it is possible to trigger autoimmunity disorder and cause AP to turn hostile against its own clients. Eight examples of autoimmune disorder will be demons....

Black vs. White: The complete life cycle of a real world breach combines a unique idea and a real-world case study from a client of ours that details the start of a hack to the identification, forensics, and reversing. We will be discussing some advanced penetration techniques and reversing topics. Starting off, we will be performing a full system compromise from the internet (complete with live demos), installing some undetectable viruses,....

If you were to "hack the planet" how many hosts do you think you could compromise through a single vulnerable application technology? A million? A hundred-million? A billion? What kind of application is so ubiquitous that it would enable someone to launch a planet-wide attack? - why, the Web browser of course! We've all seen and studied one side of the problem - the mass- defacements and iframe injections. But how many vulnerable Web browse....

Our talk will start with some of our latest and greatest hacks. In 2003 we were the first to analyze the security of Diebold's AccuVote-TS voting machine software. We'll discuss the inside scoop on how we got the code, broke it, and then went public. In 2008 we also published the first attacks against a real, common wireless implantable medical device - an implantable defibrillator and pacemaker - and we did so using off-the-shelf software ....

Some of the panel members in previous years: Andrew Fried IRS Thomas Grasso FBI Dan Hubbard Websense Dan Kaminsky IOActive Randy Vaughn Baylor Paul Vixie ISC This year's panel members will be announced closer to the conference date. Continuing our new tradition from the past two years, leading experts from different industries, academia and law enforcement will go on stage and participate in this panel, discussing t....

Rich Internet Applications (RIA) represent the next generation of the Web. Designed to run without constant Internet connectivity, they provide a graphical experience equivalent to thick desktop applications with the easy install experience of thin Web apps. They intentionally blur the line between websites and traditional desktop applications and greatly complicate the jobs of web developers, corporate security teams, and external security....

Jim Christy DC3 Mike Convertino AFCC Cynthia Cuddihy RCMP James Finch FBI Barry Grundy NASA David Helfen NCIS Bob Hopper NW3C Ray Kessenich DCITA Tim Kosiba NSA Mischel Kwon USCERT Rich Marshall NSA Marc Moreau RCMP Tom Pownall RCMP Ken Privette USPS IG Lin Wells NDU Ever had to sweat through an interrogation or watch some poor sap suffer a similar fate? Have you ever wanted to ....

Internet Kiosks have become common place in today's Internet centric society. Public Internet Kiosks can be found everywhere, from Airports, Train stations, Libraries and Hotels to corporate lobbies and street corners. Kiosks are used by thousands of users daily from all different walks of life, creed, and social status. Internet kiosk terminals often implement custom browser software which rely on proprietary security mechanisms and a....

David Hahn was working on his atomic energy Eagle Scout badge when he had the idea why not build a reactor. However, not just any reactor, he would build a breeder reactor. This type of reactor produces more fuel and power as long as it is working. David used social engineering, unlimited drive and resourcefulness to produce his reactor type device. He succeeded further that any expert in the nuclear world would have dreamed. Ultimatel....

The presentation will deal briefly (20 minutes) with the concepts surrounding Open Source Warfare (OSW) and broader adoption for use not only within the context of war fighting, but also its uses within the political arena in order to influence opinion. The presentation will only deal with publicly available data, couple with real world deployment examples. It WILL NOT contain any type of classified data or anything that can be constru....


Urban Exploration is the practice of discovering and exploring (and often photographing) the more "off-beat" areas of human civilization. Popular targets of Urban Exploration include abandoned hospitals or institutions, empty factories, and other disused structures, but it can also include "active" sites such as service corridors, utility levels, rooftops, storm drains, steam tunnels, you name it. For years, the Urban Exploration commu....

The wonders of technology have given rise to a new breed of workforce, the mobile workforce. Able to leap large oceans in a single cattle class bound, they are the newest agent of business and the newest pain in your butt. The average business traveler carries with him a multitude of ways to get pwn'd while away from the office and away from your watchful BOFH eye. Come count the ways we can pwn that beleaguered business traveler without ev....

Using a Balloon as an aerial network surveillance platform, a.k.a. "WarBallooning" is an idea that evolved as a natural progression out of my Rocket-based experiment @ Defcon 14 entitled, "WarRocketing - Network Stumbling 50 sq. miles in <60 seconds." Interestingly, after my presentation in 2006, many in the wireless community discussed Balloon-based network discovery, notably CoWF & Slashdot. But, alas, like many great concepts in the....

For years people have been warned that blind SQL injection is a problem, yet there are a multitude of vulnerable websites out there to this day. Perhaps people don't realize that these vulnerabilities are very real. The current state of the art tools are Absinthe and SQL Brute for exploiting blind SQL injection. DNS exfiltration has been proposed as a method of reaching previously unassailable blind SQL injection access points. We have crea....

There have been a number of exciting bugs and design flaws in Tor over the years, with effects ranging from complete anonymity compromise to remote code execution. Some of them are our fault, and some are the fault of components (libraries, browsers, operating systems) that we trusted. Further, the academic research community has been coming up with increasingly esoteric --- and increasingly effective! --- attacks against all anonymity desi....

IDS/IPS systems are becoming more and more advanced and geocoding is adding another layer of intelligence to try and defend against a company's vulnerabilities. Learn how to evade complex geospatial threat detection countermeasures. Most crackers use zombie machines to launch professional attacks...but zombies even leave geographic fingerprints that are easily picked up by pattern recognition algorithms. Learn how to take professional attac....

Hanging Chads, Hopping votes, Flipped votes, Tripled votes, Missing memory cards, Machine malfunctions, Software glitches, Undervotes, Overvotes. Reports of voting machine failures flooded the news after the last elections and left most voters wondering "Does my vote really count?" "Can these electronic voting machines be trusted?" "How secure are my state's voting systems?" In December 2007, we published an in depth, source code and h....

Locksport is growing up in America. In this talk we will explore four case studies demonstrating how the community has leveraged itself to bring about significant advances in the lock industry. We will demonstrate exploits discovered in both Medeco and ABUS high security locks and discuss how Kwikset's Smartkey system responded to the spread of information about bumping and how they plan to work with the community in the future. We will inv....

If the only requirement for you to become a Computer Forensic person is to be a Private Investigator, why would you ever take a certification again? You would never need to be a CCE (computer certified examiner), nor any other certification of any kind. You would be one of the only people in your area that could legally do the job and why spend a single dime you don't have to? These new laws will destroy certifications and qualifications as....

This speech is all ANIMATION in 3D! Data on a Solid State Device is virtualized and the Physical Sector that you are asking for is not actually the sector it was 5 minutes ago. The data moves around using wear leveling schemes controlled by the drive using propriety methods. When you ask for Sector 125, its physical address block is converted to an LBA block and every 5 write cycles the data is moved to a new and empty previously erased blo....

In 2007 SensePost demonstrated the how DNS and Timing attacks could be used for a variety of attacks. This year we take those attacks further and show how small footholds in a target network can be converted into portals we can (and do) drive trucks through! With some updated SensePost tools, and some brand new ones, we will demonstrate how to convert your simple SQL Injection attacks (against well hardened environments) into point and clic....

Signaure-based Antivirus is dead, we want to show you just how dead it is. This presentation will detail our findings from running the Race-2-Zero contest during DC16. The contest involves teams or individuals being given a sample set of malicious programs to modify and upload through the contest portal. The portal passes the modified samples through a number of antivirus engines and determines if the sample is a known threat. The first to ....

This talk explores the death and subsequent re-birth of the penetration test. Comprised of conclusions drawn from the collective experiences of two seasoned pen-testers, our talk is filled with facts, fun and rhetoric. We will describe the landscape, the problems, and offer real solutions. In our talk, we will explore the problems with modern-day pen-tests and pen-testers, and ways to stand out amongst the frauds selling their lacklust....

In this talk we will discuss the paradigm shift of WiFi attacks away from the Access Points and focusing toward the clients. We will cover in depth how simple tricks such as HoneyPot Access Points or even hotspotter simply are not enough anymore and more flexible and powerful methods are being developed and used. The older, dated technologies built into Access Points for ensuring network security have failed the test of time paving way for ....

There has been a recent global push for the creation of Hacker Spaces. Unfortunately, these ventures are risky and can be quite costly. In an effort to provide an alternative, or at least an intermediary step, this talk will discuss a different type of Hacker Space, one that is on wheels. During the course of this speech, we will discuss the advantages and disadvantages of building a mobile hacker space, and present a real-world example, wh....

Google Gadgets are symptomatic of the Way 2.0 Way of things: from lame gadgets that rotate through pictures of puppies to calendars, and inline email on your iGoogle homepage. This talk will analyze the security history of Google Gadgets and demonstrate ways to exploit Gadgets for nefarious purposes. We will also show ways to create Gadgets that allow you to port scan internal systems and do various JavaScript hacks via malicious (or useful....

In this talk, we will discuss the pros and cons (mostly cons) of the cash less society and how it might endanger your privacy and civil liberties. This movement towards the elimination of cash has been picking up speed and mostly accepted by the populace as a huge convenience. We examine some reasons why this isn't such a good thing. We also look at legislation and laws in this area that give banks and the government unprecedented ability t....

Outdoor digital billboards are becoming the new way to advertise multiple products/services/etc with a single board as compared to having a street littered with dozens of these eyesores. Therefore, they're more fun to take apart and play with. While driving one day, I noticed a 404 error on one of these billboards and after discussing it with my fellow speakers, hatched a plan to hack into their network and advertise our own ideas/ "product....

In 1990, a wire-bound book was published in Paris by the title of "Voyage au centre de la HP28 c/s". It presents a very thorough account of the inner workings of the Hewlett Packard 28 series of graphing calculators. Designed before the days of prepackaged microprocessors, the series uses the Saturn architecture, which HP designed in-house. This architecture is very different from today's homogeneous RISC chips, with registers of 1, 4, 12, ....

When penetration testing large environments, testers require the ability to maintain persistent access to systems they have exploited, leverage trusts to access other systems, and increase their foothold into the target. Post exploitation activities are some of the most labor intensive aspects of pen testing. These include password management, persistent host access, privileged escalation, trust relationships, acquiring GUI access, etc. Pen....

Have you ever wanted to: * Transmit secret codes and messages * Protect Nuclear launch codes * Dabble in Intellectual Property protection * Warez/file-sharing with legal liability protection * Develop and share terrorist plots * Smuggle illegal substances * Hide digital pr0n from others * Exchange classified information securely * Exchange diskette with "Leonardo da Vinci" virus, culled from the hacked "garbage....

Compliance is no longer new. Compliance has been accepted by the corporate-state. Compliance is common-place. Compliance is the intruders' new friend. Decision makers thinks Compliance == Security. While many compliance standards have resulted in the implementation of some very important controls, they have also left a roadmap for intruders, ill doers and the sort to hone their attack. This presentation will go over such weaknesses and show..

WAF (Web Application Firewalls) are often called 'Deep Packet Inspection Firewalls' because they look at every request and response within the HTTP/HTTPS/SOAP/XML-RPC/Web Service layers. Some WAFs look for certain 'attack signatures' to try to identify a specific attack that an intruder may be sending, while others look for abnormal behavior that doesn't fit the websites normal traffic patterns. Web Application Firewalls can be either softw....

Need help understanding your gigabytes of application logs or network captures? Your OS performance metrics do not make sense? Then DAVIX, the live CD for visualizing IT data, is your answer! To simplify the analysis of vast amounts of security data, visualization is slowly penetrating the security community. There are many free tools available for analysis and visualization of data. To simplify the use of these tools, the open source ....

This year new shiny toys are abound, as I'll tell you about the credentials in your wallet, and even in you. How secure (or not) they are and a few ways to duplicate / replicate /emulate them. Last year at Defcon 15 I had a bit of a chat with you guys and gave you an overview of access control systems, told you of their common flaw, and showed you some cool toys that exploit it. This year, from the humble magnetic stripe card to the mo....

The Dark Tangent welcomes the Defcon 16 attendees at the start of the conference. For the third year in a row, Kingpin has had the honor of designing the DEFCON Badge. No longer just a boring piece of passive material, the badge is now a full-featured, active electronic product. If you're up early enough and interested in details of the entire development process of the badge, from initial concept drawings to prototype electronics to c....

This presentation will cover a variety of topics of interest to anyone on a cellphone network in the US. I'm going to cover how to use your own backends for MMS and WAP access, unlock Bluetooth tethering, and circumvent some of the more obnoxious carrier restrictions. Of course, the best part is baking your own firmware and running your own code. I'll provide an overview of the processes necessary to do so, a quick rundown of what you can....

In this presentation we're going to show Defcon how broken the Internet is, how helpless its users are without provider intervention, and how much apathy there is towards routing security. With the method described in this talk, an attacker is able to gain full control and visibility of all IP packets heading towards an arbitrary destination prefix on the Internet. From the perspective of the victims network, every inbound packet they....

NetBSD is a portable operating system for just about every architecture available. There is a notable lack of tools available for the penetration tester. In this talk we will present Toasterkit, a generic NetBSD rootkit. It has been tested on i386, Mac PPC, and VAX systems. Anthony Martinez is a system administrator for the New Mexico Tech Computer Center, and an undergraduate Computer Science student at the university. Thomas B..

Countless hours are spent researching vulnerabilities in proprietary and open source software for each bug found. Many indicators of potential vulnerabilities are visible both in the disassembly and debugging, if you know what to look for. How much can be automated? VulnCatcher illustrates the power of programmatic debugging using the VTRACE libraries for cross-platform debugging. atlas a disciple of the illustrious Skodo, has a histor..

Snort has become a standard component of many IT security environments. Snort is mature and widely deployed, and is no longer viewed as new or exciting by the industry. However, with such widespread deployment, enhancing Snort's capabilities offers the potential for a large and immediate impact. Instead of chasing the industry's new-hotness of the day, it frequently makes more sense to add new capabilities to an existing security control. ....

Using various modifications and techniques - it is possible to gain free and anonymous cable modem internet access. This talk will analyze and discuss the tools, techniques, and technology behind both hacking cable modems and attempting to catch the users who are hacking cable modems. Previously confidential information gained from a senior network technician at Time Warner will be disclosed in this speech. We will also talk about how these....

3 visitors online