Site uses cookies to provide basic functionality.
Javascript rendering is set to off by default when visiting the site via .onion and .i2p domains. It can be enabled back again in user's settings section. Javascript rendering set to off means, that you can disable javascript in your browser now and the site will remain functional.
There is also IRC server now available via native IRC clients or non javascript web based one.
Fonts can be adjusted in user's settings section as well.
Check FAQ for more.

OK

GeoLocation of 802.11b Access Points is not a trivial task. As wardrivers who?ve stumbled various networks with a GPS unit will attest, "Netstumbler doesn't provide the real location of access points". Instead, it provides an estimate of where the software thinks they are. Why should this be so? In a comparative sport made popular by the proliferation of portable GPS units, GeoCachers routinely find their "caches" or treasures with amazi....

Greg Hoglund has been a pioneer in the area of software security for ten years. He created and documented the first Windows NT-based rootkit, founding www.rootkit.com in the process.

As the world comes to rely on computers and rapidly changing technologies, the threat posed by computer attackers has become increasingly significant. Computer attackers exploit vulnerabilities in systems and circumvent antivirus software to obtain all manner of personal and financial information. However, individuals no longer need to rely on their abilities, as malware and automated tools quickly and efficiently perform attacks for them. ....

Broward Horne is a software consultant with a diverse IT background, doing contract work for Unigard, Nike, JP Morgan, Verizon, Transcore and the US Department of Transportation, a former employee of several large corporations (Hewlett Packard, Avnet, Teradyne, Litton) and two startup companies. His projects include network construction and administration, prototype wireless LANs, prototype pen-top software, CRM software, e-commerce, insu....

We have all heard of Honeypots and more recently HoneyClients. Now we are introducing the concept of HoneyJax. Once again functionality has beaten our security, and Web 2.0 is in full force. User-created content, radical trust, and social networks have lead to several malicious code attacks and spammers have learned that the web a great compliment to sell there trade. This session will show provide examples and insights into the prob....

I've been giving talks on how FPGAs are cool for the past couple of years at Defcon, so what's different this year? Well, I'll be releasing a couple of new tools. BTCrack is a Bluetooth PIN cracker that will allow you to crack 8-digit Bluetooth PINs on an FPGA or 5-digit PINs on your computer in real-time (Longer PINs require a little more time) using a capture of the pairing process. The other tool, WinZipCrack will let you cra....

BGP Prefix hijacks take the IP addresses of others and make them your own. This talk provides a chilling account of the current use of prefix hijacks by spammers in a successful effort to defeat RBL's. Placed within the context of the history of the spamwar, this talk makes clear the grim future we face if we continue to escalate the spam war into the network layer; namely a future where every spammer on earth can arbitrarily choose and ....

Design bugs are really difficult to fix -- nobody ever takes a dependency on a buffer overflow, after all. Few things have had their design stretched as far as the web; as such, I've been starting to take a look at some interesting aspects of the "Web 2.0" craze. Here's a few things I've been looking at: Slirpie: VPN'ing into Protected Networks With Nothing But A Lured Web Browser. Part of the design of the web is that browsers are ab....

There is always a possibility to get infected by some malware, i.e. by surfing the web and catching the malware that uses some new exploit in your browser. What should you do then? Do you know what is available on Windows system to fight malware? The problem of fighting malware on Windows is the limitation of basically available tools. I am going to show you some tricks that will let you do some complicated actions using ONLY components of ....

Patrik Karlsson is the founder of the security related website cqure.net, where he publishes some of his security related work. He is also a partner at Inspect it, a Swedish based information security consultancy. His work has been mentioned in a number of articles and books and used for education and security testing. For the last couple of years he has specialized in web application security, databases and his family.

This talk will introduce a simple and incredibly powerful framework for the scripted generation of network traffic: Funk, a new tool for fuzzing arbitrary network protocols written using the Chicken Scheme-to-C compiler. Source code will be provided and explained, so you can start using this framework today for all your network traffic generation needs! Some familiarity with functional languages like Lisp or Scheme will be helpful, but no....

Last fall, the Department of Defense Cyber Crime Center (DC3) hosted a digital forensics challenge that included interesting puzzles such as physical media reconstruction, data carving, password cracking, and booting forensic images with virtual machines. My team from Georgetown University competed with a shoestring budget against a 140 teams and came in 4th place overall. The presentation will cover the individual challenges, our solu..

If you're going to buy an application security tool, which one will it be? Every vendor likes to talk about how their tools are the best. "We are the market leader!" they all say. But not everyone can lead all the time. I will show how I took half a dozen "leading" application security tools (both static and dynamic) and compared them head-to-head against the same open source application. All of the tools found something, but no two tools f....

If you're going to buy an application security tool, which one will it be? Every vendor likes to talk about how their tools are the best. "We are the market leader!" they all say. But not everyone can lead all the time. I will show how I took half a dozen "leading" application security tools (both static and dynamic) and compared them head-to-head against the same open source application. All of the tools found something, but no two tools f....

Johnny Long was a relative forensics newbie who was faced with the challenge of hunting down the amazingly agile and paranoid "Knuth" from the best-selling Syngress 'stealing the Network? book series. In the story, Knuth melted down his hard drive platters and USB sticks before leaving the country, leaving any investigator next to no digital evidence. Fortunately for the good guys, Knuth left behind some oft-neglected hardware that left ..

Each year thousands of work hours are lost by security practitioners as time is spent sorting through web application security reports and separating out erroneous vulnerability data. Individuals must currently work through this process in a vacuum, as there is no publicly available information that is helpful. Restrictive EULAs (End User License Agreements) prohibit examining a signature code-base for common errors or signature flaws. Due ....

Any attacker can scam one or two users into revealing themselves, but do you know how to talk an entire community of smart hackers into weakening its anonymity? In spite of progress in traffic analysis, social engineering attacks remain the most effective way to break users' anonymity and one of the best force multipliers for traditional traffic analysis attacks. Why bother doing traffic analysis when you can trick users into isolating....

There hasn't been a talk from the developers of Tor (the popular anonymity network) at Defcon since 2004. Since then, we've revised the protocols, added piles of new features to the software, tightened security, integrated more helper tools, made hard strategic decisions, and suffered growing pains. There have been new attacks, new defenses, new research, and new ideas. In this talk, I'll present the most important technical changes an....

What's in a name? How do you know you should "trust" the content you are receiving? In today's World Wide Web, we place a lot of "trust" into domain names. For many, domain names help determine the whether a particular link or file should be trusted, or eyed with suspicion. Domain name trust has even made its way into security systems, considering many of the protections built into our browsers are based strictly on domain names! In th....

Timing attacks have been exploited in the wild for ages. In recent times timing attacks have largely been relegated to use only by cryptographers and cryptanalysts. In this presentation SensePost analysts will show that timing attacks are still very much alive and kicking on the Internet and fairly prevalent in web applications (if only we were looking for them). The talk will cover SensePost-aTime (our new SQL Injection tool that operates ....

Dynamic analysis, or fuzzing, is a popular method of finding security vulnerabilities in software. Fuzzing may be used by a developer to find potential problems as part of the quality-assurance process or may be used to find potential exploits in an existing software application. Fuzzing has grown in popularity because it is much easier (and often more effective) to generate and run arbitrary inputs than it is to perform a manual code audit....

More unlicensed bandwidth from TV!?! A long-term push to free up more wireless spectrum is expected to come to fruition this year as the FCC will open up unused TV channels ? dubbed ?white spaces? ? for unlicensed broadband use this fall, with full-blown availability in 2008 once the DTV transition takes place. Dell, Google, HP, Intel, Microsoft and Philips have joined together in the ?White Spaces Coalition? to lobby for a spec....

Penetration testing often focuses on individual vulnerabilities and services. This talk introduces a tactical approach that does not rely on exploiting known vulnerabilities. Using combination of new tools and obscure techniques, I will walk through the process of compromising an organization without the use of normal exploit code. Many of the tools will be made available as new modules for the Metasploit Framework. HD Moore is the di....

Dark Tangent never speaks at DEF CON because he thinks it is cheating.. but not for the 15th anniversary! Come listen to a behind the scenes account of what really happened during the "Cisco/ISS Gate" fiasco from 2005. Throughout the talk the audience will be asked what they would have done at key points and then learn what I chose to do. A cautionary and comical tale of what happens when communication breaks down. The Dark Tangent st..

NEW!! Advanced Data Recovery Material. Even people who think they know everything about a hard drive will be surprised at what they will learn in this presentation. Everyone will learn something new about hard drives and how to perform data recovery. We will lay it on the line and tell all! We will display All NEW Material and Animations on the inner workings of a hard drive. We will discuss rebuilding a hard drive and will teach you what ..

As of today, Vista, XP, 2K03, OS X, every major Linux distro, and each of the BSD's either contain some facet of (stack|buffer|heap) protection, or have one available that's relatively trivial to implement/enable. So, this should mean the end of memory corruption-based attacks as we know it, right? Sorry, thanks for playing. The fact remains that many (though not all) implementations are incomplete at best, and at worst are simply bull....

You think your systems and data are safe from any attack. You fear no script kiddie. You get a +5 against social engineering. Yet a single subpoena can crack your junk open wide. A search warrant might leave you with an empty server room. The law might be the biggest threat to your users, systems and you. Learn how to plan for and react to search warrants, subpoenas and wiretaps. I?m going to speak about the law in an IT context, make i..

Event logging in Windows Vista is quite different in terms of the way events are stored on disk and the way they are used by applications. Vista uses a new encoding of event records that lends itself to much broader flexibility for searching events. This encoding has a direct impact on forensic examination of event logs, which will be discussed in this presentation. The impact of the new application programming interface (API) is no less im....

Video games are the most effective and accessible tool for hacking your physical and mental state, yet the potential impact of these technologies has yet to be exploited. In this presentation we will take you on a journey through video games -past, present and future-, dispelling the myths and emphasizing the realities, both positive and dark. We will also explain how different input devices can be used to improve the brai....

Hackers and tech users in the United States have long benefited from some long-lived institutions that have worked to helped defend and publicise their rights, including but not limited to EFF and DefCon itself. But the legal and political fights over DRM and copyright, privacy invasions, cybercrime round-ups and security scaremongering, are now increasingly international battles. How can hackers across the world build their own institution....

With Phishing, Fraud, and Identity Theft at peak levels, banks, credit unions, credit card companies, and other financial institutions are enhancing the security of their website authentication. This talk will cover the new methods of authentication, such as mutual authentication, device fingerprinting, out of band authentication, one time passwords, and knowledge base archives. We will analyze how these controls are intended to function, w....

Organizations that are implementing XML based systems, Web Services, Web 2.0 applications are discovering that there are security challenges unique to them that can surface throughout the various phases of lifecycle. Traditional network and application protection and infrastructure systems lack the functionality, performance, and operational efficiencies needed to provide a secure, cost effective solution. Web Services, SaaS and SOA provide....

OpenBSD is regarded as a very secure Operating System. This article details one of the few remote exploit against this system. A kernel shellcode is described, that disables the protections of the OS and installs a user-mode process. Several other possible techniques of exploitation are described. Several other ipv6-related vulnerabilities are described and disclosed. Alfredo Ortega: Born at Esquel, Chubut, Argentina on 1978. Worked on..

Across the world law enforcement, enterprises and national security apparatus utilize a small but important set of software tools to perform data recovery and investigations. These tools are expected to perform a large range of dangerous functions, such as parsing dozens of different file systems, email databases and dense binary file formats. Although the software we tested is considered a critical part of the investigatory cycle in the ....

Gadi Evron Moderator Andrew Fried IRS Thomas Grasso FBI Dan Hubbard Websense Dan Kaminsky IOActive Randy Vaughn Baylor Paul Vixie ISC Continuing our new tradition from last year, leading experts from different industries, academia and law enforcement will go on stage and participate in this panel, discussing the current threats on and to the Internet, from regular cyber-crime all the way to the mafia, and even some informat....

The Church of WiFi (reformed) returns to Las Vegas bigger and better than ever. Last year we brought you the first pre-computed rainbow tables for faster WPA cracking. This year, we've gone overboard and expanded the tables to places and sizes not dared before. Can you say: our own live distro? And that's not all: we're prostelytizing our wireless foo this year by hosting the Wireless Village, a place for tutorials, mini-presentat....

Have you ever considered publishing your own book? Your own DVD? Self-publishing has been a part of the computer underground since its inception, from the Neon Knights to the Syndicate of London's recent book _End of Dayz_. This panel will discuss types of self-publishing (both on- and off-line) and their relevance to the computer underground. They will also discuss their personal experiences in self-publishing. Ample time for qu....

It seems that at every con nowadays there is at least one talk dedicated to physical security. Our servers and data can be encrypted and passworded with the latest algorithms, but that doesn't do the trick if someone marches them out the door when we're not looking. In the past, many physical security talks have focused on passive defense: locks that resist picking, safes which resist cracking, etc. However, sometimes....

The web browser is ever increasing in its importance to many organizations. Far from its origin as an application for fetching and rendering HTML, today's web browser offers an expansive attack surface to exploit. All the major browsers now include full-featured runtime engines for a variety of interpreted scripting languages, including the popular JavaScript. The web experience now depends more than ever on the ability of the browser to dy....

Imagine your only connection to the Internet was through a potentially hostile environment such as the Defcon wireless network. Worse, imagine all someone had to do to own you was to inject some html that runs a plugin or some clever javascript to bypass your proxy settings. Unfortunately, this is the risk faced by many users of the Tor anonymity network who use the default configurations of many popular browsers and other network software.....

As wi-fi becomes increasingly popular and as more layers of access control are added, the fact that a wireless access point exists becomes less interesting to us. The problem is that manually going through a long list of access points checking for interesting information is tedious at best. Wicrawl is a tool that will allow you to "crawl" through discovered access points with a series of plugins that implement common tools (nmap, aircr....

Novell's Identity Manager and related components are become fairly common in large networks. Identity management systems in general bring a number of security implications that are often not well understood. Even when best practices are followed, the system often has vulnerabilities that can be exploited. Since there seems to be little research into hacking identity management systems, the goal of this talk is to bring some recognition to ....

The fox is guarding the hen house, and both the fox and the hens are making a lot of money in the process. Such is the state of the security industry in 2007. For the last 15 years, we have been building security into our networks and applications using concepts like "defense in depth" and "layered security." It turns out, that the attackers are now leveraging our security systems against us. Worse, we have made the security industry ....

Software armoring techniques have increasingly created problems for reverse engineers and software analysts. As protections such as packers, run-time obfuscators, virtual machine and debugger detectors become common newer methods must be developed to cope with them. In this talk we will present our covert debugging platform named Saffron. Saffron is based upon dynamic instrumentation techniques as well as a newly developed page fault assist....

3 visitors online