Site uses cookies to provide basic functionality.
Javascript rendering is set to off by default when visiting the site via .onion and .i2p domains. It can be enabled back again in user's settings section. Javascript rendering set to off means, that you can disable javascript in your browser now and the site will remain functional.
There is also IRC server now available via native IRC clients or non javascript web based one.
Fonts can be adjusted in user's settings section as well.
Check FAQ for more.

OK

Estonia is one of the most advanced countries in the world, and just now survived what has been referred to as "the first 'real' cyber conflict". What really happened there, and what does it mean to us? Gadi Evron works for the McLean, VA based vulnerability assessment solution vendor Beyond Security as Security Evangelist and is the chief editor of the security portal SecuriTeam. He is a known leader in the world of Internet security..

The thousands of servers in collation centers and hosting farms are irresistible targets for bot-herders in the market for an ideal attack platform. Learn how ISPs are . with varying success . detecting and responding to bot-herders. frequent attempts to take control. Gadi Evron works for the McLean, VA based vulnerability assessment solution vendor Beyond Security as Security Evangelist and is the chief editor of the security portal ..

Matt Fiddler leads a Threat Management Team for a Fortune 100 Organization. Mr. Fiddler's research into lock bypass techniques have resulted in many public and private disclosures of critical lock design flaws. Mr. Fiddler began his career as an Intelligence Analyst with the United States Marine Corps. Since joining the commercial sector in 1992, he has spent the last 15 years enhancing his extensive expertise in the area of Unix and Networ....

An overview and demonstration of common access control and biometric systems. This will include the key elements of their implementation and includes in-depth technical analysis of their common weakness. I will then demonstrate bespoke hardware developed to perform an attack that renders most access control systems useless. Zac Franken has been running operations for Defcon for nearly 14 years. Generally preferring to stay behind th..

Come and spend 50 minutes with the King, not Elvis, but King Tuna. He is going to give you a peak into EvDo and some of the goodies it has to offer. After a very brief overview of what EvDo is he is going to go into detail about the different hardware options you have, and most importantly, how EvDo cards can be hacked and the advantages of delving into the insides of the card. Can ESN's be moved? Can EvDo be used in monitor mode? Brin..

Imagine you are king for a day. Enemies are all around you, and they seem to be using the Internet to plot against you. Using real-world cyber war stories from the most tightly controlled nations on Earth, Greetz from Room 101 puts you in the shoes of a king who must defend the royal palace against cyber-equipped revolutionaries. Can a monarch buy cyber security? Are his trusty henchmen smart enough to learn network protocol analysis? Could....

Damian Gomez is a Security Researcher at Immunity, which he joined in February 2006, after five years as the Chief Security Officer at Informar Argentina S.A., where his responsibilities included internal security auditing, network design, and intellectual property management with watermarking technologies. Prior to Informar, Damian worked on secure networking infrastructure at the Comision Nacional de Comunicaciones. In addition to consult..

This presentation pertains to a discovery of a more potent variant of Evil Twin. We call it Multipot. Multipot consists of multiple APs which are configured with the same SSID and lure WiFi clients into connecting to them. The term Multipot is derived from multiple and honeypot. Multipot can occur naturally in the form of multiple Municipal APs or Metro APs around the victim client, all of which are naturally configured for the same SSID (e....

Joe Grand is an electrical engineer, prominent speaker, and prolific inventor with multiple pending patents and over a dozen commercially available products. He is the President of Grand Idea Studio, a San Francisco-based product research, development, and licensing firm, where he specializes in the design of consumer electronics and video game accessories. Involved in computers and electronics since the age of 7, Joe has had the fortu....

The simple decision by a researcher to tell what he or she has discovered about a software product or website can be very complicated both legally and ethically. The applicable legal rules are complicated, there isn't necessarily any precedent, and what rules there are may be in flux. In this presentation, I will use Cisco and ISS's lawsuit against Michael Lynn (from Black Hat 2005) and HID's cease and desist letter to IOActive (from ....

This presentation is an introduction to hardware design and reverse engineering, with an eye towards developing an individual laboratory for future exploration. We start by covering the basic tools and setting up a laboratory. In this section, we cover the basic tools, such as soldering tools, oscilloscopes, and logic analyzers. The focus is on getting the tools for low or no cost. From there, we cover the forward engineering process, inclu....

Malware has come a long way since it consisted mostly of small-scale (if prolific) nuisances perpetrated by script kiddies. Today, it's increasingly being created by professional programmers and managed by international criminal organisations. This talk will look at the methods and technology employed by the professional malware idustry, which is turning out "product" that matches (and in some cases even exceeds) the sophistication of st....

Sysmin The Hacker Pimps Marklar The Hacker Pimps This presentation focuses on analysis and strategies in dealing with systems that gather information, more specifically, personal information. This talk suggests that we need to start looking at the technology of the future through different a different set of eyes, the ones of a researcher. A new classification method is introduced for the classification of attacks on information gath....

We present the INTERSTATE fuzzer to detect security vulnerabilities in VOIP phones which implement Session Initiation Protocol (SIP). INTERSTATE generates an input sequence for a SIP phone which is constructed to reveal common security vulnerabilities. SIP is a stateful protocol so a state machine description of the SIP protocol is used by INTERSTATE to ensure that the entire state space is explored. The input sequence consists of SIP reque....

Macs use an ultra-modern industry standard technology called EFI to handle booting. Sadly, Windows XP, and even Vista, are stuck in the 1980s with old-fashioned BIOS. But with Boot Camp, the Mac can operate smoothly in both centuries." - Quote taken from http://www.apple.com/macosx/bootcamp/ The Extensible Firmware Interface (EFI) has long been touted as the replacement for the traditional BIOS and was chosen by Apple as the pre-bo....

What happens when you combine a natural hacker, a computer controlled car, and security consultant's discretionary income spent on a pile of parts? A four cylinder, 2.5 liter, 500hp monster daily driver that runs on pump gas. (Pump gas plus computer controlled methanol injection for that extra umph.) If you love the smell of gasoline and want to learn about performance tuning and ECU hacking, then this presentation is for you. If you h....

GeoLocation of 802.11b Access Points is not a trivial task. As wardrivers who?ve stumbled various networks with a GPS unit will attest, "Netstumbler doesn't provide the real location of access points". Instead, it provides an estimate of where the software thinks they are. Why should this be so? In a comparative sport made popular by the proliferation of portable GPS units, GeoCachers routinely find their "caches" or treasures with amazi....

Greg Hoglund has been a pioneer in the area of software security for ten years. He created and documented the first Windows NT-based rootkit, founding www.rootkit.com in the process.

As the world comes to rely on computers and rapidly changing technologies, the threat posed by computer attackers has become increasingly significant. Computer attackers exploit vulnerabilities in systems and circumvent antivirus software to obtain all manner of personal and financial information. However, individuals no longer need to rely on their abilities, as malware and automated tools quickly and efficiently perform attacks for them. ....

Broward Horne is a software consultant with a diverse IT background, doing contract work for Unigard, Nike, JP Morgan, Verizon, Transcore and the US Department of Transportation, a former employee of several large corporations (Hewlett Packard, Avnet, Teradyne, Litton) and two startup companies. His projects include network construction and administration, prototype wireless LANs, prototype pen-top software, CRM software, e-commerce, insu....

We have all heard of Honeypots and more recently HoneyClients. Now we are introducing the concept of HoneyJax. Once again functionality has beaten our security, and Web 2.0 is in full force. User-created content, radical trust, and social networks have lead to several malicious code attacks and spammers have learned that the web a great compliment to sell there trade. This session will show provide examples and insights into the prob....

I've been giving talks on how FPGAs are cool for the past couple of years at Defcon, so what's different this year? Well, I'll be releasing a couple of new tools. BTCrack is a Bluetooth PIN cracker that will allow you to crack 8-digit Bluetooth PINs on an FPGA or 5-digit PINs on your computer in real-time (Longer PINs require a little more time) using a capture of the pairing process. The other tool, WinZipCrack will let you cra....

BGP Prefix hijacks take the IP addresses of others and make them your own. This talk provides a chilling account of the current use of prefix hijacks by spammers in a successful effort to defeat RBL's. Placed within the context of the history of the spamwar, this talk makes clear the grim future we face if we continue to escalate the spam war into the network layer; namely a future where every spammer on earth can arbitrarily choose and ....

Design bugs are really difficult to fix -- nobody ever takes a dependency on a buffer overflow, after all. Few things have had their design stretched as far as the web; as such, I've been starting to take a look at some interesting aspects of the "Web 2.0" craze. Here's a few things I've been looking at: Slirpie: VPN'ing into Protected Networks With Nothing But A Lured Web Browser. Part of the design of the web is that browsers are ab....

There is always a possibility to get infected by some malware, i.e. by surfing the web and catching the malware that uses some new exploit in your browser. What should you do then? Do you know what is available on Windows system to fight malware? The problem of fighting malware on Windows is the limitation of basically available tools. I am going to show you some tricks that will let you do some complicated actions using ONLY components of ....

Patrik Karlsson is the founder of the security related website cqure.net, where he publishes some of his security related work. He is also a partner at Inspect it, a Swedish based information security consultancy. His work has been mentioned in a number of articles and books and used for education and security testing. For the last couple of years he has specialized in web application security, databases and his family.

This talk will introduce a simple and incredibly powerful framework for the scripted generation of network traffic: Funk, a new tool for fuzzing arbitrary network protocols written using the Chicken Scheme-to-C compiler. Source code will be provided and explained, so you can start using this framework today for all your network traffic generation needs! Some familiarity with functional languages like Lisp or Scheme will be helpful, but no....

Last fall, the Department of Defense Cyber Crime Center (DC3) hosted a digital forensics challenge that included interesting puzzles such as physical media reconstruction, data carving, password cracking, and booting forensic images with virtual machines. My team from Georgetown University competed with a shoestring budget against a 140 teams and came in 4th place overall. The presentation will cover the individual challenges, our solu..

If you're going to buy an application security tool, which one will it be? Every vendor likes to talk about how their tools are the best. "We are the market leader!" they all say. But not everyone can lead all the time. I will show how I took half a dozen "leading" application security tools (both static and dynamic) and compared them head-to-head against the same open source application. All of the tools found something, but no two tools f....

If you're going to buy an application security tool, which one will it be? Every vendor likes to talk about how their tools are the best. "We are the market leader!" they all say. But not everyone can lead all the time. I will show how I took half a dozen "leading" application security tools (both static and dynamic) and compared them head-to-head against the same open source application. All of the tools found something, but no two tools f....

Johnny Long was a relative forensics newbie who was faced with the challenge of hunting down the amazingly agile and paranoid "Knuth" from the best-selling Syngress 'stealing the Network? book series. In the story, Knuth melted down his hard drive platters and USB sticks before leaving the country, leaving any investigator next to no digital evidence. Fortunately for the good guys, Knuth left behind some oft-neglected hardware that left ..

Each year thousands of work hours are lost by security practitioners as time is spent sorting through web application security reports and separating out erroneous vulnerability data. Individuals must currently work through this process in a vacuum, as there is no publicly available information that is helpful. Restrictive EULAs (End User License Agreements) prohibit examining a signature code-base for common errors or signature flaws. Due ....

Any attacker can scam one or two users into revealing themselves, but do you know how to talk an entire community of smart hackers into weakening its anonymity? In spite of progress in traffic analysis, social engineering attacks remain the most effective way to break users' anonymity and one of the best force multipliers for traditional traffic analysis attacks. Why bother doing traffic analysis when you can trick users into isolating....

There hasn't been a talk from the developers of Tor (the popular anonymity network) at Defcon since 2004. Since then, we've revised the protocols, added piles of new features to the software, tightened security, integrated more helper tools, made hard strategic decisions, and suffered growing pains. There have been new attacks, new defenses, new research, and new ideas. In this talk, I'll present the most important technical changes an....

What's in a name? How do you know you should "trust" the content you are receiving? In today's World Wide Web, we place a lot of "trust" into domain names. For many, domain names help determine the whether a particular link or file should be trusted, or eyed with suspicion. Domain name trust has even made its way into security systems, considering many of the protections built into our browsers are based strictly on domain names! In th....

Timing attacks have been exploited in the wild for ages. In recent times timing attacks have largely been relegated to use only by cryptographers and cryptanalysts. In this presentation SensePost analysts will show that timing attacks are still very much alive and kicking on the Internet and fairly prevalent in web applications (if only we were looking for them). The talk will cover SensePost-aTime (our new SQL Injection tool that operates ....

Dynamic analysis, or fuzzing, is a popular method of finding security vulnerabilities in software. Fuzzing may be used by a developer to find potential problems as part of the quality-assurance process or may be used to find potential exploits in an existing software application. Fuzzing has grown in popularity because it is much easier (and often more effective) to generate and run arbitrary inputs than it is to perform a manual code audit....

More unlicensed bandwidth from TV!?! A long-term push to free up more wireless spectrum is expected to come to fruition this year as the FCC will open up unused TV channels ? dubbed ?white spaces? ? for unlicensed broadband use this fall, with full-blown availability in 2008 once the DTV transition takes place. Dell, Google, HP, Intel, Microsoft and Philips have joined together in the ?White Spaces Coalition? to lobby for a spec....

Penetration testing often focuses on individual vulnerabilities and services. This talk introduces a tactical approach that does not rely on exploiting known vulnerabilities. Using combination of new tools and obscure techniques, I will walk through the process of compromising an organization without the use of normal exploit code. Many of the tools will be made available as new modules for the Metasploit Framework. HD Moore is the di....

Dark Tangent never speaks at DEF CON because he thinks it is cheating.. but not for the 15th anniversary! Come listen to a behind the scenes account of what really happened during the "Cisco/ISS Gate" fiasco from 2005. Throughout the talk the audience will be asked what they would have done at key points and then learn what I chose to do. A cautionary and comical tale of what happens when communication breaks down. The Dark Tangent st..

NEW!! Advanced Data Recovery Material. Even people who think they know everything about a hard drive will be surprised at what they will learn in this presentation. Everyone will learn something new about hard drives and how to perform data recovery. We will lay it on the line and tell all! We will display All NEW Material and Animations on the inner workings of a hard drive. We will discuss rebuilding a hard drive and will teach you what ..

As of today, Vista, XP, 2K03, OS X, every major Linux distro, and each of the BSD's either contain some facet of (stack|buffer|heap) protection, or have one available that's relatively trivial to implement/enable. So, this should mean the end of memory corruption-based attacks as we know it, right? Sorry, thanks for playing. The fact remains that many (though not all) implementations are incomplete at best, and at worst are simply bull....

You think your systems and data are safe from any attack. You fear no script kiddie. You get a +5 against social engineering. Yet a single subpoena can crack your junk open wide. A search warrant might leave you with an empty server room. The law might be the biggest threat to your users, systems and you. Learn how to plan for and react to search warrants, subpoenas and wiretaps. I?m going to speak about the law in an IT context, make i..

Event logging in Windows Vista is quite different in terms of the way events are stored on disk and the way they are used by applications. Vista uses a new encoding of event records that lends itself to much broader flexibility for searching events. This encoding has a direct impact on forensic examination of event logs, which will be discussed in this presentation. The impact of the new application programming interface (API) is no less im....

4 visitors online