Site uses cookies to provide basic functionality.
Javascript rendering is set to off by default when visiting the site via .onion and .i2p domains. It can be enabled back again in user's settings section. Javascript rendering set to off means, that you can disable javascript in your browser now and the site will remain functional.
There is also IRC server now available via native IRC clients or non javascript web based one.
Fonts can be adjusted in user's settings section as well.
Check FAQ for more.

OK

For many years people have been debating whether or not surveillance capabilities should be built into the Internet. Cypherpunks see a future of perfect end to end encryption while telecom companies are hard at work building surveillance interfaces into their networks. Do these lawful intercept interfaces create unnecessary security risks? This talk will review published architectures for lawful intercept and explain how a number of di....

In April, 2010, a zombie outbreak occurred in Providence, Rhode Island. These were not traditional zombies however; They were controlled by an electronic device that allowed for wireless attacks against the living around them. Fortunately, the living had their own devices, and were able to fight off the zombies... but more threatening enemies entered the fray. This is the story about the QuahogCon 2010 badge and the embedded Zombie I....

For many years people have been debating whether or not surveillance capabilities should be built into the Internet. Cypherpunks see a future of perfect end to end encryption while telecom companies are hard at work building surveillance interfaces into their networks. Do these lawful intercept interfaces create unnecessary security risks? This talk will review published architectures for lawful intercept and explain how a number of di....

In April, 2010, a zombie outbreak occurred in Providence, Rhode Island. These were not traditional zombies however; They were controlled by an electronic device that allowed for wireless attacks against the living around them. Fortunately, the living had their own devices, and were able to fight off the zombies... but more threatening enemies entered the fray. This is the story about the QuahogCon 2010 badge and the embedded Zombie I....

There's nothing worse than toiling away at building a large, powerful botnet after months of effort, only to see it get taken down due to being taken down by an ISP, hosting provider or due to law enforcement intervention. Fortunately, a tool exists that will help us hide the command and control channels of botnets to allow us control our botnets anonymously. This tool is Tor. This presentation discusses several ways to operate a botne..

There's nothing worse than toiling away at building a large, powerful botnet after months of effort, only to see it get taken down due to being taken down by an ISP, hosting provider or due to law enforcement intervention. Fortunately, a tool exists that will help us hide the command and control channels of botnets to allow us control our botnets anonymously. This tool is Tor. This presentation discusses several ways to operate a botne..

There's nothing worse than toiling away at building a large, powerful botnet after months of effort, only to see it get taken down due to being taken down by an ISP, hosting provider or due to law enforcement intervention. Fortunately, a tool exists that will help us hide the command and control channels of botnets to allow us control our botnets anonymously. This tool is Tor. This presentation discusses several ways to operate a botne..

Toool, Deviant Ollam, Dave, Dr. Tran & Ray - The Search for Perfect Handcuffs... and the Perfect Handcuff Key The few handcuff talks which have appeared at conferences in the past have focused mostly on how these restraints function and how to open them without a key. While this talk is no exception (going into great detail about the specialized anti-pick protections used by many brands) we will also reveal the product of ongoing, prec....

This paper argues that the current rules of war are adequate for addressing the unique issues that are encountered as a result of conducting and defending against cyber warfare. The author begins by giving a survey of the laws that have the biggest impact on cyber warfare. Next, the author describes several paradigms that have come about as a result of cyber warfare, followed by a direct rebuttal. The author then asserts five reasons for wh....

Toool, Deviant Ollam, Dave, Dr. Tran & Ray - The Search for Perfect Handcuffs... and the Perfect Handcuff Key The few handcuff talks which have appeared at conferences in the past have focused mostly on how these restraints function and how to open them without a key. While this talk is no exception (going into great detail about the specialized anti-pick protections used by many brands) we will also reveal the product of ongoing, prec....

This paper argues that the current rules of war are adequate for addressing the unique issues that are encountered as a result of conducting and defending against cyber warfare. The author begins by giving a survey of the laws that have the biggest impact on cyber warfare. Next, the author describes several paradigms that have come about as a result of cyber warfare, followed by a direct rebuttal. The author then asserts five reasons for wh....

Toool, Deviant Ollam, Dave, Dr. Tran & Ray - The Search for Perfect Handcuffs... and the Perfect Handcuff Key The few handcuff talks which have appeared at conferences in the past have focused mostly on how these restraints function and how to open them without a key. While this talk is no exception (going into great detail about the specialized anti-pick protections used by many brands) we will also reveal the product of ongoing, prec....

This paper argues that the current rules of war are adequate for addressing the unique issues that are encountered as a result of conducting and defending against cyber warfare. The author begins by giving a survey of the laws that have the biggest impact on cyber warfare. Next, the author describes several paradigms that have come about as a result of cyber warfare, followed by a direct rebuttal. The author then asserts five reasons for wh....

After kicking around on the back shelf for years, HD voice is finally gaining traction both in the broadband world and the cellular. And the French are leading the way! The audio standards for a POTS (Plain Old Telephone System) call have been frozen since about 1937. Since then, modern society has had FM radio, Dolby Sound, TV, HDTV, cell phones, satellite broadcast, the Internet, fiber optics, but no improvement to a stock voice phon....

After kicking around on the back shelf for years, HD voice is finally gaining traction both in the broadband world and the cellular. And the French are leading the way! The audio standards for a POTS (Plain Old Telephone System) call have been frozen since about 1937. Since then, modern society has had FM radio, Dolby Sound, TV, HDTV, cell phones, satellite broadcast, the Internet, fiber optics, but no improvement to a stock voice phon....

After kicking around on the back shelf for years, HD voice is finally gaining traction both in the broadband world and the cellular. And the French are leading the way! The audio standards for a POTS (Plain Old Telephone System) call have been frozen since about 1937. Since then, modern society has had FM radio, Dolby Sound, TV, HDTV, cell phones, satellite broadcast, the Internet, fiber optics, but no improvement to a stock voice phon....

WebSphere Application Server (WAS), IBM's Java Enterprise Edition (JEE) application server, is one of the leading application servers and is the predominate application server in the financial and insurance sectors. It is also embedded in several of IBM's other products including WebSphere Portal, WebSphere Process Server and WebSphere Message Broker. In March 2009, IBM released PK81387 which patches a "Possible application source file....

No matter which kind of cryptography you are using to defend your network, , sooner or later to make it work you will have to store somewhere a password, a key or a certificate. If the attacker is able to tampers with its storage mechanism then even the strongest encryption mechanism became irrelevant. In this talk we will present Tapjacking attacks which abuse smartphone features to create more efficient clickjacking attacks. We also ....

WebSphere Application Server (WAS), IBM's Java Enterprise Edition (JEE) application server, is one of the leading application servers and is the predominate application server in the financial and insurance sectors. It is also embedded in several of IBM's other products including WebSphere Portal, WebSphere Process Server and WebSphere Message Broker. In March 2009, IBM released PK81387 which patches a "Possible application source file....

No matter which kind of cryptography you are using to defend your network, , sooner or later to make it work you will have to store somewhere a password, a key or a certificate. If the attacker is able to tampers with its storage mechanism then even the strongest encryption mechanism became irrelevant. In this talk we will present Tapjacking attacks which abuse smartphone features to create more efficient clickjacking attacks. We also ....

WebSphere Application Server (WAS), IBM's Java Enterprise Edition (JEE) application server, is one of the leading application servers and is the predominate application server in the financial and insurance sectors. It is also embedded in several of IBM's other products including WebSphere Portal, WebSphere Process Server and WebSphere Message Broker. In March 2009, IBM released PK81387 which patches a "Possible application source file....

No matter which kind of cryptography you are using to defend your network, , sooner or later to make it work you will have to store somewhere a password, a key or a certificate. If the attacker is able to tampers with its storage mechanism then even the strongest encryption mechanism became irrelevant. In this talk we will present Tapjacking attacks which abuse smartphone features to create more efficient clickjacking attacks. We also ....

While we were slaving away hacking an awesome memory analysis tool, Kartograph, our lazy graduate student friends next door were busy honing their skills in CIV 4, Age of Empire III, Anno, C&C, and WarCraft III. They did not anticipate that we could use Kartograph to own them in these games. This talk shows how we turned the tables on them by using Kartograph to build 0-day cheats. Kartograph is a tool designed to reverse-engineer the memor....

While we were slaving away hacking an awesome memory analysis tool, Kartograph, our lazy graduate student friends next door were busy honing their skills in CIV 4, Age of Empire III, Anno, C&C, and WarCraft III. They did not anticipate that we could use Kartograph to own them in these games. This talk shows how we turned the tables on them by using Kartograph to build 0-day cheats. Kartograph is a tool designed to reverse-engineer the memor....

While we were slaving away hacking an awesome memory analysis tool, Kartograph, our lazy graduate student friends next door were busy honing their skills in CIV 4, Age of Empire III, Anno, C&C, and WarCraft III. They did not anticipate that we could use Kartograph to own them in these games. This talk shows how we turned the tables on them by using Kartograph to build 0-day cheats. Kartograph is a tool designed to reverse-engineer the memor....

Oracle Database Vault was launched a few years ago to put a limit on DBAs unlimited power especially over highly confidential data where it is required by regulations. This presentation will show how this add-on product for Oracle Database performs on this difficult task, first giving an introduction to DB Vault and what protections does it brings, then showing with many examples how it is possible to bypass the protections provided. The at....

The talk presents a simple but effective approach for securing Rich Internet Application (RIA) content before using it. Focusing on Adobe Flash content, the security threats presented by Flash movies are discussed, as well as their inner workings that allow such attacks to happen. Some of those details will make you laugh, some will make you wince. Based on the properties discussed, the idea behind the defense approach will be presented, as....

Oracle Database Vault was launched a few years ago to put a limit on DBAs unlimited power especially over highly confidential data where it is required by regulations. This presentation will show how this add-on product for Oracle Database performs on this difficult task, first giving an introduction to DB Vault and what protections does it brings, then showing with many examples how it is possible to bypass the protections provided. The at....

The talk presents a simple but effective approach for securing Rich Internet Application (RIA) content before using it. Focusing on Adobe Flash content, the security threats presented by Flash movies are discussed, as well as their inner workings that allow such attacks to happen. Some of those details will make you laugh, some will make you wince. Based on the properties discussed, the idea behind the defense approach will be presented, as....

Oracle Database Vault was launched a few years ago to put a limit on DBAs unlimited power especially over highly confidential data where it is required by regulations. This presentation will show how this add-on product for Oracle Database performs on this difficult task, first giving an introduction to DB Vault and what protections does it brings, then showing with many examples how it is possible to bypass the protections provided. The at....

The talk presents a simple but effective approach for securing Rich Internet Application (RIA) content before using it. Focusing on Adobe Flash content, the security threats presented by Flash movies are discussed, as well as their inner workings that allow such attacks to happen. Some of those details will make you laugh, some will make you wince. Based on the properties discussed, the idea behind the defense approach will be presented, as....

DRM is the new form of slavery - but it also spies on you." - conversation with a gamer After years of perceived-rampant piracy on the PC, game publishers are beginning to shackle gamers with increasingly intrusive DRM systems. However, recent game news headlines are brimming with failures of these measures. Cracks either get released weeks prior to street dates, or systems fail and prohibit legitimate buyers from running their games. ....

DRM is the new form of slavery - but it also spies on you." - conversation with a gamer After years of perceived-rampant piracy on the PC, game publishers are beginning to shackle gamers with increasingly intrusive DRM systems. However, recent game news headlines are brimming with failures of these measures. Cracks either get released weeks prior to street dates, or systems fail and prohibit legitimate buyers from running their games. ....

DRM is the new form of slavery - but it also spies on you." - conversation with a gamer After years of perceived-rampant piracy on the PC, game publishers are beginning to shackle gamers with increasingly intrusive DRM systems. However, recent game news headlines are brimming with failures of these measures. Cracks either get released weeks prior to street dates, or systems fail and prohibit legitimate buyers from running their games. ....

Vulnerabilities are disclosed daily and in the best case new patches are released. Is no new that many application's update process have security weaknesses allowing fake updates injection. The new version of the framework will show how many updates system are still vulnerable to this trivial attack. Francisco Amato is a researcher and computer security consultant who works in the area of vulnerability Development, blackbox testing, re....

Vulnerabilities are disclosed daily and in the best case new patches are released. Is no new that many application's update process have security weaknesses allowing fake updates injection. The new version of the framework will show how many updates system are still vulnerable to this trivial attack. Francisco Amato is a researcher and computer security consultant who works in the area of vulnerability Development, blackbox testing, re....

Vulnerabilities are disclosed daily and in the best case new patches are released. Is no new that many application's update process have security weaknesses allowing fake updates injection. The new version of the framework will show how many updates system are still vulnerable to this trivial attack. Francisco Amato is a researcher and computer security consultant who works in the area of vulnerability Development, blackbox testing, re....

As part of his job as Security Engineer at Schuberg Philis, Frank Breedijk performs regular security scans. The repetitive nature of scanning the same customer infrastructure over and over again made him decide to look for a more automated approach. After building his first scanning scheduler he realized that it actually does not make sense to look at all findings every time they are reported. It would be much better to only investigate the....

y = mx+b? f(x) = sin(x/freq)*amp?! SIN X = (A+BX+CX^2)/(P+QX+RX^2)?! None of these formulas as they stand alone really mean much of anything-- except maybe a headache for some. Isolating the variables, however, will eventually open the door for us to manipulate our code in creative and exciting ways. This isn't necessarily a ground-breaking technique in obfuscation, but who cares if it's fun? Given an arbitrary formula, we can place our cod....

As part of his job as Security Engineer at Schuberg Philis, Frank Breedijk performs regular security scans. The repetitive nature of scanning the same customer infrastructure over and over again made him decide to look for a more automated approach. After building his first scanning scheduler he realized that it actually does not make sense to look at all findings every time they are reported. It would be much better to only investigate the....

y = mx+b? f(x) = sin(x/freq)*amp?! SIN X = (A+BX+CX^2)/(P+QX+RX^2)?! None of these formulas as they stand alone really mean much of anything-- except maybe a headache for some. Isolating the variables, however, will eventually open the door for us to manipulate our code in creative and exciting ways. This isn't necessarily a ground-breaking technique in obfuscation, but who cares if it's fun? Given an arbitrary formula, we can place our cod....

As part of his job as Security Engineer at Schuberg Philis, Frank Breedijk performs regular security scans. The repetitive nature of scanning the same customer infrastructure over and over again made him decide to look for a more automated approach. After building his first scanning scheduler he realized that it actually does not make sense to look at all findings every time they are reported. It would be much better to only investigate the....

y = mx+b? f(x) = sin(x/freq)*amp?! SIN X = (A+BX+CX^2)/(P+QX+RX^2)?! None of these formulas as they stand alone really mean much of anything-- except maybe a headache for some. Isolating the variables, however, will eventually open the door for us to manipulate our code in creative and exciting ways. This isn't necessarily a ground-breaking technique in obfuscation, but who cares if it's fun? Given an arbitrary formula, we can place our cod....

Most hackers can use Nmap for simple port scanning and OS detection, but the Nmap Scripting Engine (NSE) takes scanning to a whole new level. Nmap's high-speed networking engine can now spider web sites for SQL injection vulnerabilities, brute-force crack and query MSRPC services, find open proxies, and more. Nmap includes more than 125 NSE scripts for network discovery, vulnerability detection, exploitation, and authentication cracking. ....

6 visitors online