Site uses cookies to provide basic functionality.
Javascript rendering is set to off by default when visiting the site via .onion and .i2p domains. It can be enabled back again in user's settings section. Javascript rendering set to off means, that you can disable javascript in your browser now and the site will remain functional.
There is also IRC server now available via native IRC clients or non javascript web based one.
Fonts can be adjusted in user's settings section as well.
Check FAQ for more.

OK

Any attacker can scam one or two users into revealing themselves, but do you know how to talk an entire community of smart hackers into weakening its anonymity? In spite of progress in traffic analysis, social engineering attacks remain the most effective way to break users' anonymity and one of the best force multipliers for traditional traffic analysis attacks. Why bother doing traffic analysis when you can trick users into isolating....

There hasn't been a talk from the developers of Tor (the popular anonymity network) at Defcon since 2004. Since then, we've revised the protocols, added piles of new features to the software, tightened security, integrated more helper tools, made hard strategic decisions, and suffered growing pains. There have been new attacks, new defenses, new research, and new ideas. In this talk, I'll present the most important technical changes an....

What's in a name? How do you know you should "trust" the content you are receiving? In today's World Wide Web, we place a lot of "trust" into domain names. For many, domain names help determine the whether a particular link or file should be trusted, or eyed with suspicion. Domain name trust has even made its way into security systems, considering many of the protections built into our browsers are based strictly on domain names! In th....

Timing attacks have been exploited in the wild for ages. In recent times timing attacks have largely been relegated to use only by cryptographers and cryptanalysts. In this presentation SensePost analysts will show that timing attacks are still very much alive and kicking on the Internet and fairly prevalent in web applications (if only we were looking for them). The talk will cover SensePost-aTime (our new SQL Injection tool that operates ....

Dynamic analysis, or fuzzing, is a popular method of finding security vulnerabilities in software. Fuzzing may be used by a developer to find potential problems as part of the quality-assurance process or may be used to find potential exploits in an existing software application. Fuzzing has grown in popularity because it is much easier (and often more effective) to generate and run arbitrary inputs than it is to perform a manual code audit....

More unlicensed bandwidth from TV!?! A long-term push to free up more wireless spectrum is expected to come to fruition this year as the FCC will open up unused TV channels ? dubbed ?white spaces? ? for unlicensed broadband use this fall, with full-blown availability in 2008 once the DTV transition takes place. Dell, Google, HP, Intel, Microsoft and Philips have joined together in the ?White Spaces Coalition? to lobby for a spec....

Penetration testing often focuses on individual vulnerabilities and services. This talk introduces a tactical approach that does not rely on exploiting known vulnerabilities. Using combination of new tools and obscure techniques, I will walk through the process of compromising an organization without the use of normal exploit code. Many of the tools will be made available as new modules for the Metasploit Framework. HD Moore is the di....

Dark Tangent never speaks at DEF CON because he thinks it is cheating.. but not for the 15th anniversary! Come listen to a behind the scenes account of what really happened during the "Cisco/ISS Gate" fiasco from 2005. Throughout the talk the audience will be asked what they would have done at key points and then learn what I chose to do. A cautionary and comical tale of what happens when communication breaks down. The Dark Tangent st..

NEW!! Advanced Data Recovery Material. Even people who think they know everything about a hard drive will be surprised at what they will learn in this presentation. Everyone will learn something new about hard drives and how to perform data recovery. We will lay it on the line and tell all! We will display All NEW Material and Animations on the inner workings of a hard drive. We will discuss rebuilding a hard drive and will teach you what ..

As of today, Vista, XP, 2K03, OS X, every major Linux distro, and each of the BSD's either contain some facet of (stack|buffer|heap) protection, or have one available that's relatively trivial to implement/enable. So, this should mean the end of memory corruption-based attacks as we know it, right? Sorry, thanks for playing. The fact remains that many (though not all) implementations are incomplete at best, and at worst are simply bull....

You think your systems and data are safe from any attack. You fear no script kiddie. You get a +5 against social engineering. Yet a single subpoena can crack your junk open wide. A search warrant might leave you with an empty server room. The law might be the biggest threat to your users, systems and you. Learn how to plan for and react to search warrants, subpoenas and wiretaps. I?m going to speak about the law in an IT context, make i..

Event logging in Windows Vista is quite different in terms of the way events are stored on disk and the way they are used by applications. Vista uses a new encoding of event records that lends itself to much broader flexibility for searching events. This encoding has a direct impact on forensic examination of event logs, which will be discussed in this presentation. The impact of the new application programming interface (API) is no less im....

Video games are the most effective and accessible tool for hacking your physical and mental state, yet the potential impact of these technologies has yet to be exploited. In this presentation we will take you on a journey through video games -past, present and future-, dispelling the myths and emphasizing the realities, both positive and dark. We will also explain how different input devices can be used to improve the brai....

Hackers and tech users in the United States have long benefited from some long-lived institutions that have worked to helped defend and publicise their rights, including but not limited to EFF and DefCon itself. But the legal and political fights over DRM and copyright, privacy invasions, cybercrime round-ups and security scaremongering, are now increasingly international battles. How can hackers across the world build their own institution....

With Phishing, Fraud, and Identity Theft at peak levels, banks, credit unions, credit card companies, and other financial institutions are enhancing the security of their website authentication. This talk will cover the new methods of authentication, such as mutual authentication, device fingerprinting, out of band authentication, one time passwords, and knowledge base archives. We will analyze how these controls are intended to function, w....

Organizations that are implementing XML based systems, Web Services, Web 2.0 applications are discovering that there are security challenges unique to them that can surface throughout the various phases of lifecycle. Traditional network and application protection and infrastructure systems lack the functionality, performance, and operational efficiencies needed to provide a secure, cost effective solution. Web Services, SaaS and SOA provide....

OpenBSD is regarded as a very secure Operating System. This article details one of the few remote exploit against this system. A kernel shellcode is described, that disables the protections of the OS and installs a user-mode process. Several other possible techniques of exploitation are described. Several other ipv6-related vulnerabilities are described and disclosed. Alfredo Ortega: Born at Esquel, Chubut, Argentina on 1978. Worked on..

Across the world law enforcement, enterprises and national security apparatus utilize a small but important set of software tools to perform data recovery and investigations. These tools are expected to perform a large range of dangerous functions, such as parsing dozens of different file systems, email databases and dense binary file formats. Although the software we tested is considered a critical part of the investigatory cycle in the ....

Gadi Evron Moderator Andrew Fried IRS Thomas Grasso FBI Dan Hubbard Websense Dan Kaminsky IOActive Randy Vaughn Baylor Paul Vixie ISC Continuing our new tradition from last year, leading experts from different industries, academia and law enforcement will go on stage and participate in this panel, discussing the current threats on and to the Internet, from regular cyber-crime all the way to the mafia, and even some informat....

The Church of WiFi (reformed) returns to Las Vegas bigger and better than ever. Last year we brought you the first pre-computed rainbow tables for faster WPA cracking. This year, we've gone overboard and expanded the tables to places and sizes not dared before. Can you say: our own live distro? And that's not all: we're prostelytizing our wireless foo this year by hosting the Wireless Village, a place for tutorials, mini-presentat....

Have you ever considered publishing your own book? Your own DVD? Self-publishing has been a part of the computer underground since its inception, from the Neon Knights to the Syndicate of London's recent book _End of Dayz_. This panel will discuss types of self-publishing (both on- and off-line) and their relevance to the computer underground. They will also discuss their personal experiences in self-publishing. Ample time for qu....

It seems that at every con nowadays there is at least one talk dedicated to physical security. Our servers and data can be encrypted and passworded with the latest algorithms, but that doesn't do the trick if someone marches them out the door when we're not looking. In the past, many physical security talks have focused on passive defense: locks that resist picking, safes which resist cracking, etc. However, sometimes....

The web browser is ever increasing in its importance to many organizations. Far from its origin as an application for fetching and rendering HTML, today's web browser offers an expansive attack surface to exploit. All the major browsers now include full-featured runtime engines for a variety of interpreted scripting languages, including the popular JavaScript. The web experience now depends more than ever on the ability of the browser to dy....

Imagine your only connection to the Internet was through a potentially hostile environment such as the Defcon wireless network. Worse, imagine all someone had to do to own you was to inject some html that runs a plugin or some clever javascript to bypass your proxy settings. Unfortunately, this is the risk faced by many users of the Tor anonymity network who use the default configurations of many popular browsers and other network software.....

As wi-fi becomes increasingly popular and as more layers of access control are added, the fact that a wireless access point exists becomes less interesting to us. The problem is that manually going through a long list of access points checking for interesting information is tedious at best. Wicrawl is a tool that will allow you to "crawl" through discovered access points with a series of plugins that implement common tools (nmap, aircr....

Novell's Identity Manager and related components are become fairly common in large networks. Identity management systems in general bring a number of security implications that are often not well understood. Even when best practices are followed, the system often has vulnerabilities that can be exploited. Since there seems to be little research into hacking identity management systems, the goal of this talk is to bring some recognition to ....

The fox is guarding the hen house, and both the fox and the hens are making a lot of money in the process. Such is the state of the security industry in 2007. For the last 15 years, we have been building security into our networks and applications using concepts like "defense in depth" and "layered security." It turns out, that the attackers are now leveraging our security systems against us. Worse, we have made the security industry ....

Software armoring techniques have increasingly created problems for reverse engineers and software analysts. As protections such as packers, run-time obfuscators, virtual machine and debugger detectors become common newer methods must be developed to cope with them. In this talk we will present our covert debugging platform named Saffron. Saffron is based upon dynamic instrumentation techniques as well as a newly developed page fault assist....

Widgets (or Gadgets) are small applications, which usually provide some kind of visual information or access to a frequently used function. Because widgets are in fact applications, they too can include malicious code. Furthermore, due to the simplicity of legitimate widgets, such as calculators and clocks, they are developed without security in mind. In this presentation, we will explain the three different types of widgets in detail....

WEP Cloaking is a recently proposed anti-WEP-cracking technique that is claiming to be the savior of legacy WLAN devices still replying on WEP encryption. The WEP Cloaking mechanism is meant to be used in Wireless Intrusion Prevention Systems (WIPS) to protect WEP encrypted networks. The WEP Cloaking technique sends spoofed WEP encrypted packets a.k.a. ?chaff? into the air. These packets are specially crafted to try and confuse WEP crack....

With this presentation we will demonstrate a new tool called eescan that automates extrusion and exploitability scanning using a client/server approach. Eescan will be released under the GPL and utilizes python to create an extensible framework for testing extrusion and exploit defenses. All network security systems have gaps. Layered security tries to cover the gaps with overlapping protections like firewalls, intrusion prevention, pr....

Whats in a name? How do you know you should "trust" the content you are receiving? In today's World Wide Web, we place a lot of "trust" into domain names. For many, domain names help determine the whether a particular link or file should be trusted, or eyed with suspicion. Domain name trust has even made its way into security systems, considering many of the protections built into our browsers are based strictly on domain names! In thi....

Every day billions of dollars pass through middleware, the unglamorous component of most enterprise applications. Middleware may be unglamorous, but even if billions of dollars doesn't interest you, it's bound to attract someone's interest sooner or later. Often security is addressed in the front-end web server and back-end database but the other components are often ignored. The reason for this can be a lack of understanding of the risks o....

Networks are central do almost everything that hackers do. Be they computer networks, peer-to-peer networks, information networks, or social networks, they are all around us and understanding them is the key to understanding both the strengths and vulnerabilities of our world. The speaker, a mathematician working in the field of complex networks, will introduce the modern mathematics of networks, and how it can be applied to real-world situ....

What in the world is a U.S. Navy officer (a Naval Flight Officer, no less) doing in the middle of Iraq? Electronic warfare, of course! The Church of WiFi presents an unclassified presentation of theprez98's experiences during his 9-month tour in Iraq. Embedded with Army units on the ground, theprez98 brought his expertise in electronic warfare to bear against the biggest threat to coalition forces - the improvised explosive device (IED). H....

Security is both a feeling and a reality. You can feel secure without actually being secure, and you can be secure even though you don't feel secure. In the industry, we tend to discount the feeling in favor of the reality, but the difference between the two is important. It explains why we have so much security theater that doesn't work, and why so many smart security solutions go unimplemented. Two different fields?behavioral economics an....

domain images; like MySpace or eBay. By uploading the following line of HTML to a community website,[img src="http://www.mydomain.com/executable.jpg?] you can launch a dynamic program that masquerades as a static image and capable of reading and writing cookies, analyzing referrer (and other browser) variables and access databases. It is even possible to create an image the causes a browser to execute JavaScript. A previous DEFCON Spe..

Too often, "Computer History" gets shoved into a forgotten bin of irrelevancy, devoid of use for lessons and understanding. Even more often, people often fail to realize they're making history themselves. Jason Scott will walk though the basics of computer history, what to save, how to ensure things last for future generations, or perhaps how to ensure it's never found again. Jason Scott is a hard-core computer historian now celeb..

A Crazy Toaster: Can Home Devices turn against us?" Home networking devices, wireless equivalents, hardware and technology raise new privacy and trust issues. Can Home Devices turn against us and spy on our home Network? Do we care if our Toaster sees us Naked? This talk will cover a scenario of "Crazy Toaster". Trojan device under Vista and XP environment, or software with TCP/IP capabilities like Routers, Media Players....

Utu is the Maori word for a system of revenge used by Maori society to provide social controls and retribution. Utu is also a protocol that uses cryptographic models of social interaction to allow peers to vote on their dislike of other peer's behavior. The goal of Utu is to experiment with the effects of bringing identity, reputation, and retribution to human communications on the Internet. A secondary goal is wiping ....

As one of the founders of WarDrivingWorld.com, where over the past few years we have sold thousands of WiFi devices and antennas for Pen testing and extended range WiFi, I will be presenting simple, but very effective techniques for extending the range of WiFi beyond the standard 15-30 meter range to 3-5 km, or more using home brew components. Pilgrim is an ancient hacker who came from the tombs of Egypt. In those days punch cards ruled the..

We hear it in the news all too frequently, "26 IRS tapes containing taxpayer information potentially contain taxpayers' names, SSNs, bank account numbers, or employer information", "tapes containing customer information were stolen from a lock box... 196,000 names, SSN, etc", "disappearance of 9 tapes containing payroll information on 52,000 employees, including SSNs and in some cases bank account numbers. The 9th tape contained "less sensi....

The process of obfuscating intermediate platform independent code, such as Java bytecode or Common Intermediate Language (CIL) code aims to make the source code generated by reverse engineering much less useful to an attacker or competitor. This talk focuses on the examination of fingerprinting particular obfuscators and provides a tool capable of cracking key obfuscation processes performed. As more programming languages use intermediate p....

You're over the line," an intelligence professional told Richard Thieme recently. "You know enough to know what's not true but you can't know enough to know what is. You're well into the wilderness of mirrors." Hacking one complex system is always in some ways like hacking another. You must see nested levels of the context that others assume and which is therefore invisible, you must see through the story that the system tells about i....

3 visitors online