Site uses cookies to provide basic functionality.
Javascript rendering is set to off by default when visiting the site via .onion and .i2p domains. It can be enabled back again in user's settings section. Javascript rendering set to off means, that you can disable javascript in your browser now and the site will remain functional.
There is also IRC server now available via native IRC clients or non javascript web based one.
Fonts can be adjusted in user's settings section as well.
Check FAQ for more.

OK

Copy of the slides for this talk are here: http://m6rqq6kocsyugo2laitup5nn32bwm3lh677chuodjfmggczoafzwfcad.onion/dc-20/presentations/Alonso-Sur/DEFCON-20-Alonso-Sur-Owning-Bad-Guys-Using-JavaScript-Botnets.pdf Whitepaper: http://m6rqq6kocsyugo2laitup5nn32bwm3lh677chuodjfmggczoafzwfcad.onion/dc-20/presentations/Alonso-Sur/DEFCON-20-Alonso-Sur-Owning-Bad-Guys-Using-JavaScript-Botnets-WP.pdf Owning Bad Guys {And Mafia} With Jav....

Copy of the slides for this talk are here: http://m6rqq6kocsyugo2laitup5nn32bwm3lh677chuodjfmggczoafzwfcad.onion/dc-20/presentations/Anch-Omega/DEFCON-20-Anch-Omega-The-Darknet-of-Things.pdf The Darknet of Things, Building Sensor Networks That Do Your Bidding Anch Omega The Internet of Things... It is coming, wearing hardware that communicates across the Internet is starting to become a reality, chips are getting small....

Copy of the slides for this talk are here: http://m6rqq6kocsyugo2laitup5nn32bwm3lh677chuodjfmggczoafzwfcad.onion/dc-20/presentations/Atlas/DEFCON-20-Atlas-Sub-Ghz-or-Bust.pdf Extra Materials: http://m6rqq6kocsyugo2laitup5nn32bwm3lh677chuodjfmggczoafzwfcad.onion/dc-20/presentations/Atlas/Extras.zip atlas 0f d00m c0rp0ration Wifi is cool and so is cellular, but the real fun stuff happens below the GHz line. Medical systems, m....

Blind XSS Adam "EvilPacket" Baldwin Chief Security Officer, &yet This talk will announce the release and demonstrate the xss.io toolkit. xss.io is a platform to help ease cross-site scripting (xss) exploitation and specifically for this talk identification of blind xss vectors. Think drag and drop exploits post xss vuln identification. For blind xss, xss.io is a callback and hook manager for intel collected by executed and non-execut....

Overwriting the Exception Handling Cache PointerDwarf Oriented Programming Rodrigo Rubira Branco Vulnerability & Malware Research Labs, Qualys James Oakley Programmer Sergey Bratus Research Ass't Professor, Comp. Science, Dartmouth College This presentation describes a new technique for abusing the DWARF exception handling architecture used by the GCC tool chain. This technique can be used to exploit vulnerabilities in programs c....

Exploit Archaeology: Raiders of the Lost Payphones Josh Brashars Penetration Tester, Member DC 949 Payphones. Remember those? They used to be a cornerstone of modern civilation, available at every street corner, gas station, or any general place of commerce. For decades, hackers and phone phreaks crowded around them as an altar to high technology and a means to "reach out and touch someone". Fast forward to today, most people ha....

Hardware Backdooring is Practical Jonathan Brossard Toucan System Whitepaper Available here: https://www.defcon.org/images/defcon-20/dc-20-presentations/Brossard/DEFCON-20-Brossard-Hardware-Backdooring-is-Practical-WP.pdf This presentation will demonstrate that permanent backdooring of hardware is practical. We have built a generic proof of concept malware for the intel architecture, Rakshasa, capable of infecting more than a....

DIY Electric Car Dave Brown Electric Vehicles are an exciting area of developing technology entering the mainstream market. Every major manufacturer is working on new hybrid and electric vehicles but prices will be high and options few for years to come. As with many industries, a DIY approach can yield similar results for much less cost, while creating something truly unique. This talk will explore the possibilities and pr..

Copy of the slides for this talk are here: http://m6rqq6kocsyugo2laitup5nn32bwm3lh677chuodjfmggczoafzwfcad.onion/dc-20/presentations/Baldwin/DEFCON-20-Adam-Baldwin-Blind-XSS.pdf Blind XSS Adam "EvilPacket" Baldwin Chief Security Officer, & yet. This talk will announce the release and demonstrate the xss.io toolkit. xss.io is a platform to help ease cross-site scripting (xss) exploitation and specifically for this talk identifi....

Copy of the slides for this talk are here: http://m6rqq6kocsyugo2laitup5nn32bwm3lh677chuodjfmggczoafzwfcad.onion/dc-20/presentations/Branco-Oakley-Bratus/DEFCON-20-Branco-Oakley-Bratus-Dwarf-Oriented-Programming.pdf Extra Paper: http://m6rqq6kocsyugo2laitup5nn32bwm3lh677chuodjfmggczoafzwfcad.onion/dc-20/presentations/Branco-Oakley-Bratus/RodrigoBranco.txt Overwriting the Exception Handling Cache PointerDwarf Oriented Programming ....

Copy of the slides for this talk are here: http://m6rqq6kocsyugo2laitup5nn32bwm3lh677chuodjfmggczoafzwfcad.onion/dc-20/presentations/Brashars/DEFCON-20-Brashars-Exploit-Archaeology.pdf Exploit Archaeology: Raiders of the Lost Payphones Josh Brashars Penetration Tester, Member DC 949 Payphones. Remember those? They used to be a cornerstone of modern civilation, available at every street corner, gas station, or any general place ....

Copy of the slides for this talk are here: http://m6rqq6kocsyugo2laitup5nn32bwm3lh677chuodjfmggczoafzwfcad.onion/dc-20/presentations/Brossard/DEFCON-20-Brossard-Hardware-Backdooring-is-Practical.pdf Whitepaper Available here: http://m6rqq6kocsyugo2laitup5nn32bwm3lh677chuodjfmggczoafzwfcad.onion/dc-20/presentations/Brossard/DEFCON-20-Brossard-Hardware-Backdooring-is-Practical-WP.pdf Hardware Backdooring is Practical Jonathan Brossa....

Copy of the slides for this talk are here: http://m6rqq6kocsyugo2laitup5nn32bwm3lh677chuodjfmggczoafzwfcad.onion/dc-20/presentations/Brown/DEFCON-20-Dave-Brown-DIY-Electric-Car.pdf DIY Electric Car Dave Brown Electric Vehicles are an exciting area of developing technology entering the mainstream market. Every major manufacturer is working on new hybrid and electric vehicles but prices will be high and options few for years to c....

Copy of the slides for this talk are here: http://m6rqq6kocsyugo2laitup5nn32bwm3lh677chuodjfmggczoafzwfcad.onion/dc-20/presentations/Baldwin/DEFCON-20-Adam-Baldwin-Blind-XSS.pdf Blind XSS Adam "EvilPacket" Baldwin Chief Security Officer, & yet. This talk will announce the release and demonstrate the xss.io toolkit. xss.io is a platform to help ease cross-site scripting (xss) exploitation and specifically for this talk identifi....

Copy of the slides for this talk are here: http://m6rqq6kocsyugo2laitup5nn32bwm3lh677chuodjfmggczoafzwfcad.onion/dc-20/presentations/Branco-Oakley-Bratus/DEFCON-20-Branco-Oakley-Bratus-Dwarf-Oriented-Programming.pdf Extra Paper: http://m6rqq6kocsyugo2laitup5nn32bwm3lh677chuodjfmggczoafzwfcad.onion/dc-20/presentations/Branco-Oakley-Bratus/RodrigoBranco.txt Overwriting the Exception Handling Cache PointerDwarf Oriented Programming ....

Copy of the slides for this talk are here: http://m6rqq6kocsyugo2laitup5nn32bwm3lh677chuodjfmggczoafzwfcad.onion/dc-20/presentations/Brashars/DEFCON-20-Brashars-Exploit-Archaeology.pdf Exploit Archaeology: Raiders of the Lost Payphones Josh Brashars Penetration Tester, Member DC 949 Payphones. Remember those? They used to be a cornerstone of modern civilation, available at every street corner, gas station, or any general place ....

Copy of the slides for this talk are here: http://m6rqq6kocsyugo2laitup5nn32bwm3lh677chuodjfmggczoafzwfcad.onion/dc-20/presentations/Brossard/DEFCON-20-Brossard-Hardware-Backdooring-is-Practical.pdf Whitepaper Available here: http://m6rqq6kocsyugo2laitup5nn32bwm3lh677chuodjfmggczoafzwfcad.onion/dc-20/presentations/Brossard/DEFCON-20-Brossard-Hardware-Backdooring-is-Practical-WP.pdf Hardware Backdooring is Practical Jonathan Brossa....

Copy of the slides for this talk are here: http://m6rqq6kocsyugo2laitup5nn32bwm3lh677chuodjfmggczoafzwfcad.onion/dc-20/presentations/Brown/DEFCON-20-Dave-Brown-DIY-Electric-Car.pdf DIY Electric Car Dave Brown Electric Vehicles are an exciting area of developing technology entering the mainstream market. Every major manufacturer is working on new hybrid and electric vehicles but prices will be high and options few for years to c....

Copy of the slides for this talk are here: http://m6rqq6kocsyugo2laitup5nn32bwm3lh677chuodjfmggczoafzwfcad.onion/dc-20/presentations/Baldwin/DEFCON-20-Adam-Baldwin-Blind-XSS.pdf Blind XSS Adam "EvilPacket" Baldwin Chief Security Officer, & yet. This talk will announce the release and demonstrate the xss.io toolkit. xss.io is a platform to help ease cross-site scripting (xss) exploitation and specifically for this talk identifi....

Copy of the slides for this talk are here: http://m6rqq6kocsyugo2laitup5nn32bwm3lh677chuodjfmggczoafzwfcad.onion/dc-20/presentations/Branco-Oakley-Bratus/DEFCON-20-Branco-Oakley-Bratus-Dwarf-Oriented-Programming.pdf Extra Paper: http://m6rqq6kocsyugo2laitup5nn32bwm3lh677chuodjfmggczoafzwfcad.onion/dc-20/presentations/Branco-Oakley-Bratus/RodrigoBranco.txt Overwriting the Exception Handling Cache PointerDwarf Oriented Programming ....

Copy of the slides for this talk are here: http://m6rqq6kocsyugo2laitup5nn32bwm3lh677chuodjfmggczoafzwfcad.onion/dc-20/presentations/Brashars/DEFCON-20-Brashars-Exploit-Archaeology.pdf Exploit Archaeology: Raiders of the Lost Payphones Josh Brashars Penetration Tester, Member DC 949 Payphones. Remember those? They used to be a cornerstone of modern civilation, available at every street corner, gas station, or any general place ....

Copy of the slides for this talk are here: http://m6rqq6kocsyugo2laitup5nn32bwm3lh677chuodjfmggczoafzwfcad.onion/dc-20/presentations/Brossard/DEFCON-20-Brossard-Hardware-Backdooring-is-Practical.pdf Whitepaper Available here: http://m6rqq6kocsyugo2laitup5nn32bwm3lh677chuodjfmggczoafzwfcad.onion/dc-20/presentations/Brossard/DEFCON-20-Brossard-Hardware-Backdooring-is-Practical-WP.pdf Hardware Backdooring is Practical Jonathan Brossa....

Copy of the slides for this talk are here: http://m6rqq6kocsyugo2laitup5nn32bwm3lh677chuodjfmggczoafzwfcad.onion/dc-20/presentations/Brown/DEFCON-20-Dave-Brown-DIY-Electric-Car.pdf DIY Electric Car Dave Brown Electric Vehicles are an exciting area of developing technology entering the mainstream market. Every major manufacturer is working on new hybrid and electric vehicles but prices will be high and options few for years to c....

KinectasploitV2: Kinect Meets 20 Security Tools Jeff Bryner p0wnlabs/0wner Last year saw the release of Kinectasploit v1 linking the Kinect with Metasploit in a 3D, first person shooter environment. What if we expanded Kinectasploit to use 20 security tools in honor of DEF CON's 20th anniversary?! Jeff Bryner Jeff has toiled for over 20 years integrating systems, performing incident response and forensics and ultimately fixing s..

Into the Droid: Gaining Access to Android User Data Thomas Cannon Director of Research and Development, viaForensics This talk details a selection of techniques for getting the data out of an Android device in order to perform forensic analysis. It covers cracking lockscreen passwords, creating custom forensic ramdisks, bypassing bootloader protections and stealth real-time data acquisition. We’ll even cover some crazy techniques - t....

Bad (and Sometimes Good) Tech Policy: It's Not Just a DC Thing Chris Conley Technology & Civil Liberties Policy Attorney, ACLU of Northern California Efforts at the federal level to pass laws like SOPA and CISPA and require that tech companies build backdoors into their services for law enforcement use have attacted widespread attention and criticism, and rightly so. But DC is far from the only place that officials are making decisio....

Life Inside a Skinner Box: Confronting our Future of Automated Law Enforcement Greg Conti Director, Cyber Research Center, West Point Lisa Shay Ass't Professor, Electrical Engineering & Computer Science, West Point Woody Hartzog Ass't Professor, Cumberland School of Law, Samford University From smart pajamas that monitor our sleep patterns to mandatory black boxes in cars to smart trash carts that divulge recycling violations in ....

Copy of the slides for this talk are here: http://m6rqq6kocsyugo2laitup5nn32bwm3lh677chuodjfmggczoafzwfcad.onion/dc-20/presentations/Bryner/DEFCON-20-Bryner-KinectASploitv2.pdf KinectasploitV2: Kinect Meets 20 Security Tools Jeff Bryner p0wnlabs/0wner Last year saw the release of Kinectasploit v1 linking the Kinect with Metasploit in a 3D, first person shooter environment. What if we expanded Kinectasploit to use 20 security to..

Copy of the slides for this talk are here: http://m6rqq6kocsyugo2laitup5nn32bwm3lh677chuodjfmggczoafzwfcad.onion/dc-20/presentations/Cannon/DEFCON-20-Cannon-Into-The-Droid.pdf Into the Droid: Gaining Access to Android User Data Thomas Cannon Director of Research and Development, viaForensics This talk details a selection of techniques for getting the data out of an Android device in order to perform forensic analysis. It covers....

Copy of the slides for this talk are here: http://m6rqq6kocsyugo2laitup5nn32bwm3lh677chuodjfmggczoafzwfcad.onion/dc-20/presentations/Conley/DEFCON-20-DEF-CON-Conley-Bad-Tech-Policy.pdf Bad (and Sometimes Good) Tech Policy: It's Not Just a DC Thing Chris Conley Technology & Civil Liberties Policy Attorney, ACLU of Northern California Efforts at the federal level to pass laws like SOPA and CISPA and require that tech companies buil....

Copy of the slides for this talk are here: http://m6rqq6kocsyugo2laitup5nn32bwm3lh677chuodjfmggczoafzwfcad.onion/dc-20/presentations/Conti-Shay-Hartzog/DEFCON-20-Conti-Shay-Hartzog-SkinnerBox.pdf Life Inside a Skinner Box: Confronting our Future of Automated Law Enforcement Greg Conti Director, Cyber Research Center, West Point Lisa Shay Ass't Professor, Electrical Engineering & Computer Science, West Point Woody Hartzog Ass'....

Copy of the slides for this talk are here: http://m6rqq6kocsyugo2laitup5nn32bwm3lh677chuodjfmggczoafzwfcad.onion/dc-20/presentations/Bryner/DEFCON-20-Bryner-KinectASploitv2.pdf KinectasploitV2: Kinect Meets 20 Security Tools Jeff Bryner p0wnlabs/0wner Last year saw the release of Kinectasploit v1 linking the Kinect with Metasploit in a 3D, first person shooter environment. What if we expanded Kinectasploit to use 20 security to..

Copy of the slides for this talk are here: http://m6rqq6kocsyugo2laitup5nn32bwm3lh677chuodjfmggczoafzwfcad.onion/dc-20/presentations/Cannon/DEFCON-20-Cannon-Into-The-Droid.pdf Into the Droid: Gaining Access to Android User Data Thomas Cannon Director of Research and Development, viaForensics This talk details a selection of techniques for getting the data out of an Android device in order to perform forensic analysis. It covers....

Copy of the slides for this talk are here: http://m6rqq6kocsyugo2laitup5nn32bwm3lh677chuodjfmggczoafzwfcad.onion/dc-20/presentations/Conley/DEFCON-20-DEF-CON-Conley-Bad-Tech-Policy.pdf Bad (and Sometimes Good) Tech Policy: It's Not Just a DC Thing Chris Conley Technology & Civil Liberties Policy Attorney, ACLU of Northern California Efforts at the federal level to pass laws like SOPA and CISPA and require that tech companies buil....

Copy of the slides for this talk are here: http://m6rqq6kocsyugo2laitup5nn32bwm3lh677chuodjfmggczoafzwfcad.onion/dc-20/presentations/Conti-Shay-Hartzog/DEFCON-20-Conti-Shay-Hartzog-SkinnerBox.pdf Life Inside a Skinner Box: Confronting our Future of Automated Law Enforcement Greg Conti Director, Cyber Research Center, West Point Lisa Shay Ass't Professor, Electrical Engineering & Computer Science, West Point Woody Hartzog Ass'....

Copy of the slides for this talk are here: http://m6rqq6kocsyugo2laitup5nn32bwm3lh677chuodjfmggczoafzwfcad.onion/dc-20/presentations/Bryner/DEFCON-20-Bryner-KinectASploitv2.pdf KinectasploitV2: Kinect Meets 20 Security Tools Jeff Bryner p0wnlabs/0wner Last year saw the release of Kinectasploit v1 linking the Kinect with Metasploit in a 3D, first person shooter environment. What if we expanded Kinectasploit to use 20 security to..

Copy of the slides for this talk are here: http://m6rqq6kocsyugo2laitup5nn32bwm3lh677chuodjfmggczoafzwfcad.onion/dc-20/presentations/Cannon/DEFCON-20-Cannon-Into-The-Droid.pdf Into the Droid: Gaining Access to Android User Data Thomas Cannon Director of Research and Development, viaForensics This talk details a selection of techniques for getting the data out of an Android device in order to perform forensic analysis. It covers....

Copy of the slides for this talk are here: http://m6rqq6kocsyugo2laitup5nn32bwm3lh677chuodjfmggczoafzwfcad.onion/dc-20/presentations/Conley/DEFCON-20-DEF-CON-Conley-Bad-Tech-Policy.pdf Bad (and Sometimes Good) Tech Policy: It's Not Just a DC Thing Chris Conley Technology & Civil Liberties Policy Attorney, ACLU of Northern California Efforts at the federal level to pass laws like SOPA and CISPA and require that tech companies buil....

Copy of the slides for this talk are here: http://m6rqq6kocsyugo2laitup5nn32bwm3lh677chuodjfmggczoafzwfcad.onion/dc-20/presentations/Conti-Shay-Hartzog/DEFCON-20-Conti-Shay-Hartzog-SkinnerBox.pdf Life Inside a Skinner Box: Confronting our Future of Automated Law Enforcement Greg Conti Director, Cyber Research Center, West Point Lisa Shay Ass't Professor, Electrical Engineering & Computer Science, West Point Woody Hartzog Ass'....

Owning the Network: Adventures in Router Rootkits Michael Coppola Security Consultant at Virtual Security Research Routers are the blippy switchy boxes that make up the infrastructure of networks themselves, yet few administrators actually care to change the default login on these devices. Interestingly, nearly all consumer (SOHO) routers allow a user to reflash the device by uploading a (presumably vendor-provided) firmware image. B....

World War 3.0: Chaos, Control & the Battle for the Net Joshua Corman Director of Security Intelligence, Akamai Technologies Dan Kaminsky Jeff Moss Founder, DEF CON and Black Hat Rod Beckstrom Michael Joseph Gross Author of the Vanity Fair article 'A Declaration of Cyber-War', Moderator There is a battle under way for control of the Internet. Some see it as a fight between forces of Order (who want to superimpose existing, pre....

Embedded Device Firmware Vulnerability Hunting Using FRAK, the Firmware Reverse Analysis Konsole Ang Cui Red Balloon Security We present FRAK, the firmware reverse analysis konsole. FRAK is a framework for unpacking, analyzing, modifying and repacking the firmware images of proprietary embedded devices. The FRAK framework provides a programmatic environment for the analysis of arbitrary embedded device firmware as well as an interact....

Looking Into The Eye Of The Meter Cutaway InGuardians, Inc. When you look at a Smart Meter, it practically winks at you. Their Optical Port calls to you. It calls to criminals as well. But how do criminals interact with it? We will show you how they look into the eye of the meter. More specifically, this presentation will show how criminals gather information from meters to do their dirty work. From quick memory acquisition technique....

SQL Injection to MIPS Overflows: Rooting SOHO Routers Zachary Cutlip Security Researcher, Tactical Network Solutions Three easy steps to world domination: Pwn a bunch of SOHO routers. ??? Profit I can help you with Step 1. In this talk, I'll describe several 0-day vulnerabilities in Netgear wireless routers. I'll show you how to exploit an unexposed buffer overflow using nothing but a SQL injection and your bare h....

91 visitors online