Site uses cookies to provide basic functionality.
Javascript rendering is set to off by default when visiting the site via .onion and .i2p domains. It can be enabled back again in user's settings section. Javascript rendering set to off means, that you can disable javascript in your browser now and the site will remain functional.
There is also IRC server now available via native IRC clients or non javascript web based one.
Fonts can be adjusted in user's settings section as well.
Check FAQ for more.

OK

0-day, gh0stnet and the inside story of the Adobe JBIG2 vulnerability Matt Richard Malicious Code Researcher, Raytheon Steven Adair Researcher, Shadowserver This talk is the story of 0-day PDF attacks, the now famous gh0stnet ring and the disclosure debacle of the Adobe JBIG2 vulnerability in January and February 2009. This is the story of international cyber-espionage using 0-days and the fierce debate over how to defend networks ....

Cracking 400,000 Passwords, or How to Explain to Your Roommate why the Power Bill is a Little High… Matt Weir PhD Student, Florida State University Professor Sudhir Aggarwal Florida State University Remember when phpbb.com was hacked in January and over 300,000 usernames and passwords were disclosed? Don't worry though, the hacker only tried to crack a third of them, (dealing with big password lists is a pain), and of those he/she ....

Cracking 400,000 Passwords, or How to Explain to Your Roommate why the Power Bill is a Little High… Matt Weir PhD Student, Florida State University Professor Sudhir Aggarwal Florida State University Remember when phpbb.com was hacked in January and over 300,000 usernames and passwords were disclosed? Don't worry though, the hacker only tried to crack a third of them, (dealing with big password lists is a pain), and of those he/she ....

Cracking 400,000 Passwords, or How to Explain to Your Roommate why the Power Bill is a Little High… Matt Weir PhD Student, Florida State University Professor Sudhir Aggarwal Florida State University Remember when phpbb.com was hacked in January and over 300,000 usernames and passwords were disclosed? Don't worry though, the hacker only tried to crack a third of them, (dealing with big password lists is a pain), and of those he/she ....

Wi-Fish Finder: Who Will Bite the Bait MD Sohail Ahmad Senior Wireless Security Researcher, AirTight Networks Prabhash Dhyani Wireless Security Researcher Threat of Evil Twin and Honeypots lurking at office parking lots and public hotspots are well known yet awareness level among WiFi users about exposure to such threats remains quite low. Security conscious WiFi users and IT administrators too don't have any simple tools to assess....

Wi-Fish Finder: Who Will Bite the Bait MD Sohail Ahmad Senior Wireless Security Researcher, AirTight Networks Prabhash Dhyani Wireless Security Researcher Threat of Evil Twin and Honeypots lurking at office parking lots and public hotspots are well known yet awareness level among WiFi users about exposure to such threats remains quite low. Security conscious WiFi users and IT administrators too don't have any simple tools to assess....

Wi-Fish Finder: Who Will Bite the Bait MD Sohail Ahmad Senior Wireless Security Researcher, AirTight Networks Prabhash Dhyani Wireless Security Researcher Threat of Evil Twin and Honeypots lurking at office parking lots and public hotspots are well known yet awareness level among WiFi users about exposure to such threats remains quite low. Security conscious WiFi users and IT administrators too don't have any simple tools to assess....

BitTorrent Hacks Michael Brooks David Aslanian This is the journey of two pirates hacking BitTorrent. This talk will cover ways of abusing the BitTorrent protocol, finding vulnerabilities in BitTorrent clients and exploiting them. We will also cover counter measures to these attacks. Michael Brooks is a hacker, Michael finds new vulnerabilities and writes exploit code: http://milw0rm.com/author/677 Michael hacks for the c....

BitTorrent Hacks Michael Brooks David Aslanian This is the journey of two pirates hacking BitTorrent. This talk will cover ways of abusing the BitTorrent protocol, finding vulnerabilities in BitTorrent clients and exploiting them. We will also cover counter measures to these attacks. Michael Brooks is a hacker, Michael finds new vulnerabilities and writes exploit code: http://milw0rm.com/author/677 Michael hacks for the c....

BitTorrent Hacks Michael Brooks David Aslanian This is the journey of two pirates hacking BitTorrent. This talk will cover ways of abusing the BitTorrent protocol, finding vulnerabilities in BitTorrent clients and exploiting them. We will also cover counter measures to these attacks. Michael Brooks is a hacker, Michael finds new vulnerabilities and writes exploit code: http://milw0rm.com/author/677 Michael hacks for the c....

Who Invented the Proximity Card? Michael L. Davis Who invented the first Proximity Card System? And what security company dismissed it as a mere magician's trick? And what does this have to do with goldfish? Stop by and take a trip down memory lane as we explore the history of a prolific inventor who was one of the founding fathers of the physical security industry. (Hint: This person was a musician with perfect pitch whose first pat....

Who Invented the Proximity Card? Michael L. Davis Who invented the first Proximity Card System? And what security company dismissed it as a mere magician's trick? And what does this have to do with goldfish? Stop by and take a trip down memory lane as we explore the history of a prolific inventor who was one of the founding fathers of the physical security industry. (Hint: This person was a musician with perfect pitch whose first pat....

Who Invented the Proximity Card? Michael L. Davis Who invented the first Proximity Card System? And what security company dismissed it as a mere magician's trick? And what does this have to do with goldfish? Stop by and take a trip down memory lane as we explore the history of a prolific inventor who was one of the founding fathers of the physical security industry. (Hint: This person was a musician with perfect pitch whose first pat....

Making Fun of Your Malware Michael Ligh Malicious Code Analyst, iDefense Matthew Richard Malicious Code Operations Lead, Raytheon Corporation Would you laugh if you saw a bank robber accidentally put his mask on backwards and fall into a man hole during the getaway, because he couldn't tell where he was going? Criminals do ridiculous things so often, its impossible to capture them all on video. Rest assured, when the criminals are ....

Making Fun of Your Malware Michael Ligh Malicious Code Analyst, iDefense Matthew Richard Malicious Code Operations Lead, Raytheon Corporation Would you laugh if you saw a bank robber accidentally put his mask on backwards and fall into a man hole during the getaway, because he couldn't tell where he was going? Criminals do ridiculous things so often, its impossible to capture them all on video. Rest assured, when the criminals are ....

Making Fun of Your Malware Michael Ligh Malicious Code Analyst, iDefense Matthew Richard Malicious Code Operations Lead, Raytheon Corporation Would you laugh if you saw a bank robber accidentally put his mask on backwards and fall into a man hole during the getaway, because he couldn't tell where he was going? Criminals do ridiculous things so often, its impossible to capture them all on video. Rest assured, when the criminals are ....

Screen Scraper Tricks: Extracting Data from Difficult Websites Michael Schrenk Screen scrapers and data mining bots often encounter problems when extracting data from modern websites. Obstacles like AJAX discourage many bot writers from completing screen scraping projects. The good news is that you can overcome most challenges if you learn a few tricks. This session describes the (sometimes mind numbing) roadblocks that can come....

Screen Scraper Tricks: Extracting Data from Difficult Websites Michael Schrenk Screen scrapers and data mining bots often encounter problems when extracting data from modern websites. Obstacles like AJAX discourage many bot writers from completing screen scraping projects. The good news is that you can overcome most challenges if you learn a few tricks. This session describes the (sometimes mind numbing) roadblocks that can come....

Screen Scraper Tricks: Extracting Data from Difficult Websites Michael Schrenk Screen scrapers and data mining bots often encounter problems when extracting data from modern websites. Obstacles like AJAX discourage many bot writers from completing screen scraping projects. The good news is that you can overcome most challenges if you learn a few tricks. This session describes the (sometimes mind numbing) roadblocks that can come....

CSRF: Yeah, It Still Works Mike "mckt" Bailey ASS Russ McRee ASS Bad News: CSRF is nasty, it's everywhere, and you can't stop it on the client side. Good News: It can do neat things. CSRF is likely amongst the lamest security bugs available, as far as "cool" bugs go. In essence, the attack forces another user's browser to do something on your behalf. If that user is an authenticated user or an administrator on a....

CSRF: Yeah, It Still Works Mike "mckt" Bailey ASS Russ McRee ASS Bad News: CSRF is nasty, it's everywhere, and you can't stop it on the client side. Good News: It can do neat things. CSRF is likely amongst the lamest security bugs available, as far as "cool" bugs go. In essence, the attack forces another user's browser to do something on your behalf. If that user is an authenticated user or an administrator on a....

CSRF: Yeah, It Still Works Mike "mckt" Bailey ASS Russ McRee ASS Bad News: CSRF is nasty, it's everywhere, and you can't stop it on the client side. Good News: It can do neat things. CSRF is likely amongst the lamest security bugs available, as far as "cool" bugs go. In essence, the attack forces another user's browser to do something on your behalf. If that user is an authenticated user or an administrator on a....

Criminal Charges are not pursued: Hacking PKI Mike Zusman Intrepidus Group From the night of Friday to Saturday at the 20 of December a new subscriber named Mike Zusman registered at the CA site. Subsequently he succeeded in overcoming the domain validation interface by validating for domains not under his control." - Critical Event Report The last year has been a rough one for SSL PKI. Fraudulently provisioned certificates, MD5....

Criminal Charges are not pursued: Hacking PKI Mike Zusman Intrepidus Group From the night of Friday to Saturday at the 20 of December a new subscriber named Mike Zusman registered at the CA site. Subsequently he succeeded in overcoming the domain validation interface by validating for domains not under his control." - Critical Event Report The last year has been a rough one for SSL PKI. Fraudulently provisioned certificates, MD5....

Criminal Charges are not pursued: Hacking PKI Mike Zusman Intrepidus Group From the night of Friday to Saturday at the 20 of December a new subscriber named Mike Zusman registered at the CA site. Subsequently he succeeded in overcoming the domain validation interface by validating for domains not under his control." - Critical Event Report The last year has been a rough one for SSL PKI. Fraudulently provisioned certificates, MD5....

More Tricks For Defeating SSL Moxie Marlinspike This talk aims to pick up where SSL stripping left off. While sslstrip ultimately remains quite deadly in practice, this talk will demonstrate some new tricks for defeating SSL/TLS in places where sslstrip does not reach. Cautious users, for example, have been advised to explicitly visit https URLs or to use bookmarks in order to protect themselves from sslstrip, while other SSL/TLS bas..

More Tricks For Defeating SSL Moxie Marlinspike This talk aims to pick up where SSL stripping left off. While sslstrip ultimately remains quite deadly in practice, this talk will demonstrate some new tricks for defeating SSL/TLS in places where sslstrip does not reach. Cautious users, for example, have been advised to explicitly visit https URLs or to use bookmarks in order to protect themselves from sslstrip, while other SSL/TLS bas..

More Tricks For Defeating SSL Moxie Marlinspike This talk aims to pick up where SSL stripping left off. While sslstrip ultimately remains quite deadly in practice, this talk will demonstrate some new tricks for defeating SSL/TLS in places where sslstrip does not reach. Cautious users, for example, have been advised to explicitly visit https URLs or to use bookmarks in order to protect themselves from sslstrip, while other SSL/TLS bas..

Advanced MySQL Exploitation Muhaimin Dzulfakar Security Consultant, security-assessment.com This talk focuses on how MySQL SQL injection vulnerabilities can be used to gain remote code execution on the LAMP and WAMP environments. Attackers performing SQL injection on a MySQL platform must deal with several limitations and constraints. For example, the lack of multiple statements in one query makes MySQL an unpopular platform for remo....

Advanced MySQL Exploitation Muhaimin Dzulfakar Security Consultant, security-assessment.com This talk focuses on how MySQL SQL injection vulnerabilities can be used to gain remote code execution on the LAMP and WAMP environments. Attackers performing SQL injection on a MySQL platform must deal with several limitations and constraints. For example, the lack of multiple statements in one query makes MySQL an unpopular platform for remo....

Advanced MySQL Exploitation Muhaimin Dzulfakar Security Consultant, security-assessment.com This talk focuses on how MySQL SQL injection vulnerabilities can be used to gain remote code execution on the LAMP and WAMP environments. Attackers performing SQL injection on a MySQL platform must deal with several limitations and constraints. For example, the lack of multiple statements in one query makes MySQL an unpopular platform for remo....

Hacking Sleep: How to Build Your Very Own Sleep Lab Ne0nRa1n Researcher Keith Biddulph Researcher What is sleep? What happens when we don't get enough of it? Can it be hacked? Now that electronics are cheaper and more portable than ever before, a new generation of hackers have found themselves with the ability to build their own machines to measure and analyze the human body in ways only available to universities and hospitals in t....

Hacking Sleep: How to Build Your Very Own Sleep Lab Ne0nRa1n Researcher Keith Biddulph Researcher What is sleep? What happens when we don't get enough of it? Can it be hacked? Now that electronics are cheaper and more portable than ever before, a new generation of hackers have found themselves with the ability to build their own machines to measure and analyze the human body in ways only available to universities and hospitals in t....

Hacking Sleep: How to Build Your Very Own Sleep Lab Ne0nRa1n Researcher Keith Biddulph Researcher What is sleep? What happens when we don't get enough of it? Can it be hacked? Now that electronics are cheaper and more portable than ever before, a new generation of hackers have found themselves with the ability to build their own machines to measure and analyze the human body in ways only available to universities and hospitals in t....

Malware Freak Show Nicholas J. Percoco Vice President of SpiderLabs, Trustwave Jibran Ilyas Senior Forensic Investigator, SpiderLabs, Trustwave We see a lot of compromised environments every year. In 2008 alone, we performed full forensic investigations on over 150 different environments ranging from financial institutions, hotels, restaurants and even some casinos not too far from DEFCON. This presentation will show the inner work....

Malware Freak Show Nicholas J. Percoco Vice President of SpiderLabs, Trustwave Jibran Ilyas Senior Forensic Investigator, SpiderLabs, Trustwave We see a lot of compromised environments every year. In 2008 alone, we performed full forensic investigations on over 150 different environments ranging from financial institutions, hotels, restaurants and even some casinos not too far from DEFCON. This presentation will show the inner work....

Win at Reversing: Tracing and Sandboxing through Inline Hooking Nick Harbour Principal Consultant, Mandiant This presentation will discuss a new free tool for Reverse Engineering called API Thief, the "I Win" button for malware analysis. The unique way the tool operates will be explored as well as how it is able to provide better quality data than other tracing tools currently available. Advanced usage of the tool for malware analysi....

Win at Reversing: Tracing and Sandboxing through Inline Hooking Nick Harbour Principal Consultant, Mandiant This presentation will discuss a new free tool for Reverse Engineering called API Thief, the "I Win" button for malware analysis. The unique way the tool operates will be explored as well as how it is able to provide better quality data than other tracing tools currently available. Advanced usage of the tool for malware analysi....

Win at Reversing: Tracing and Sandboxing through Inline Hooking Nick Harbour Principal Consultant, Mandiant This presentation will discuss a new free tool for Reverse Engineering called API Thief, the "I Win" button for malware analysis. The unique way the tool operates will be explored as well as how it is able to provide better quality data than other tracing tools currently available. Advanced usage of the tool for malware analysi....

DEFCON 101 HighWiz, The Dark Tangent, Russr, DJ Jackalope, Deviant Ollam, Thorn, ThePrez98, LosT, Noid, Siviak What is DefCon 101? With the ever expanding landscape of DefCon: the amount of Games and Contests, the Parties, the Villages, the vast array of Art and Music... All that is going on and to do can be quite daunting to New People beginning their first DefConian adventure. There are even many long time DefCon attendees who....

DEFCON 101 HighWiz, The Dark Tangent, Russr, DJ Jackalope, Deviant Ollam, Thorn, ThePrez98, LosT, Noid, Siviak What is DefCon 101? With the ever expanding landscape of DefCon: the amount of Games and Contests, the Parties, the Villages, the vast array of Art and Music... All that is going on and to do can be quite daunting to New People beginning their first DefConian adventure. There are even many long time DefCon attendees who....

DEFCON 101 HighWiz, The Dark Tangent, Russr, DJ Jackalope, Deviant Ollam, Thorn, ThePrez98, LosT, Noid, Siviak What is DefCon 101? With the ever expanding landscape of DefCon: the amount of Games and Contests, the Parties, the Villages, the vast array of Art and Music... All that is going on and to do can be quite daunting to New People beginning their first DefConian adventure. There are even many long time DefCon attendees who....

Hardware Black Magic - Building devices with FPGAs Dr. Fouad Kiamilev Professor, Electrical and Computer Engineering Department, University of Delaware Rodney McGee Researcher, Electrical and Computer Engineering Department, University of Delaware Last year at the HHV we rolled into town full of goodies in our bags. To excite people about hardware we demoed and gave away some FPGA boards to those in attendance. We realized quickly ....

Hardware Black Magic - Building devices with FPGAs Dr. Fouad Kiamilev Professor, Electrical and Computer Engineering Department, University of Delaware Rodney McGee Researcher, Electrical and Computer Engineering Department, University of Delaware Last year at the HHV we rolled into town full of goodies in our bags. To excite people about hardware we demoed and gave away some FPGA boards to those in attendance. We realized quickly ....

83 visitors online