Site uses cookies to provide basic functionality.
Javascript rendering is set to off by default when visiting the site via .onion and .i2p domains. It can be enabled back again in user's settings section. Javascript rendering set to off means, that you can disable javascript in your browser now and the site will remain functional.
There is also IRC server now available via native IRC clients or non javascript web based one.
Fonts can be adjusted in user's settings section as well.
Check FAQ for more.

OK

https://www.defcon.org/defcon-19/dc-19-presentations/Foofus/DEFCON-19-Foofus-Forceful-Browsing-WP.pdf Using only script-kiddie skills, it may be possible to handicap the outcome of decisions of national importance. This talk presents a walk-though of a project to make more accurate predictions of US Supreme Court case outcomes. That could be a useful thing, if you had something at stake. Conventional techniques for predicting outcom....

https://www.defcon.org/defcon-19/dc-19-presentations/Fritschie-Witmer/DEFCON-19-Fritschie-Witmer-F-On-the-River.pdf Online poker is a multi-million dollar industry that is rapidly growing, but is not highly regulated. There have been "hacks" recently (i.e. weak SSL implementation, superuser account) that have drawn more attention to security in the poker industry, especially as it moves to full regulation in the United States. This tal....

People inherently trust their phones, but should they? "Cellular Privacy: A Forensic Analysis of Android Network Traffic" is a presentation of results from forensically analyzing the network traffic of an Android phone. The results paint an interesting picture. Is Google more trustworthy than the application developers? Are legitimate market apps more trustworthy than their rooted counterparts? Perhaps most importantly, should you trust you..

https://www.defcon.org/defcon-19/dc-19-presentations/Garcia/DEFCON-19-Garcia-UPnP-Mapping.pdf Universal Plug and Play(UPnP) is a technology developed by Microsoft in 1999, as a solution for NAT traversal(among other things). This talk explores the exploiting of port mapping services in UPnP/IGD devices from the WAN. It also talks about a tool called Umap to help process the UPnP requests. Attacking UPnP allows attackers to use devices ....

https://www.defcon.org/defcon-19/dc-19-presentations/Gavin/DEFCON-19-Gavin-OpenDLP.pdf Got domain admin to a couple of thousand Windows systems? Got an hour to spare? Steal sensitive data from all of these systems simultaneously in under an hour with OpenDLP. OpenDLP is an open source, agent-based, massively distributable, centrally managed data discovery program that runs as a service on Windows systems and is controlled from a centra....

https://www.defcon.org/defcon-19/dc-19-presentations/Geers/DEFCON-19-Geers-Strategic-Cyber-Security.pdf White Paper Here: https://www.defcon.org/defcon-19/dc-19-presentations/Geers/DEFCON-19-Geers-Strategic-Cyber-Security-WP.pdf This presentation argues that computer security has evolved from a technical discipline to a strategic concept. The world's growing dependence on a powerful but vulnerable Internet - combined with the disr....

https://www.defcon.org/defcon-19/dc-19-presentations/Gomez/DEFCON-19-Gomez-Bulletproofing-The-Cloud.pdf Cloud security has come into focus in the last few years; while many ways to break the cloud have been proposed, few solutions have been put forward. This talk is primarily a conceptual discussion on how cloud providers can and should be (but probably are not) protecting both their own and their clients' assets in their cloud impleme....

Cameras are hugely important to urban and suburban battlefields. Reconnaissance is a must-have for commanders, and a force multiplier for actual combat units. A combat-deployable camera system is being developed or used by nearly every military-industrial manufacturer and government agency, ranging from Throwable Camera Balls to Grenade-style launched cameras. But they're expensive and inaccessible to civilians. Would it be possible to buil....

https://www.defcon.org/defcon-19/dc-19-presentations/DC-Groups-Panel/DEFCON-19-DC-Groups-Panel.pdf Fabricating, circumventing, forging, partying, milling, crafting, building breaking - Defcon Groups have risen, fallen, and endured the last 8 years as decentralized and smoldering embers of the local hacker think-tank. This year Defcon sets out to stoke that fire and unite our groups, at and outside of the conference. The talk will co....

https://www.defcon.org/defcon-19/dc-19-presentations/Hamiel/DEFCON-19-Hamiel-Smartfuzzing_the_Web_DC.pdf Extra Material: https://www.defcon.org/defcon-19/dc-19-presentations/Hamiel/DEFCON-19-Hamiel-Smartfuzzing_the_Web_DC-Extras.zip It can be scary to think about how little of the modern attack surface many tools cover. There is no one best tool for the job and on top of that some tools don't do a great job at anything. Often in t....

https://www.defcon.org/defcon-19/dc-19-presentations/Havelt-Henrique/DEFCON-19-Havelt-Henrique.pdf Earth vs. The Giant Spider: Amazingly True Stories of Real Penetration Tests brings the DEF CON 19 audience the most massive collection of weird, downright bizarre, freaky, and altogether unlikely hacks ever seen in the wild. This talk will focus on those complex hacks found in real environments - some in very high end and important syste....

https://www.defcon.org/defcon-19/dc-19-presentations/Heiland/DEFCON-19-Heiland-Printer-To-Pwnd.pdf https://www.defcon.org/defcon-19/dc-19-presentations/Heiland/DEFCON-19-Heiland-Printer-To-Pwnd-Extras.zip In this presentation we go beyond the common printer issues and focus on harvesting data from multifunction printer (MFP) that can be leveraged to gain access to other core network systems. By taking advantage of poor printer sec....

https://www.defcon.org/defcon-19/dc-19-presentations/Holt-Kilger/DEFCON-19-Holt-Kilger-Assessing-Civilian-Willingness.pdf Changes in the social dynamics and motivations of the hacking community are a potential catalyst that when combined with the expanding reliance of critical infrastructure components upon networked control systems may provide the genesis for the emergence of what is being called the civilian cyberwarrior The emerg....

https://www.defcon.org/defcon-19/dc-19-presentations/Howard/DEFCON-19-Howard-Cyber-Security-Trends.pdf White Paper Here: https://www.defcon.org/defcon-19/dc-19-presentations/Howard/DEFCON-19-Howard-Cyber-Security-Trends-WP.pdf Verisign iDefense General Manager, Rick Howard, will provide an inside look into current cyber security trends with regard to Cyber War, Cyber Hacktivism, and Cyber Espionage. In this presentation Rick will ....

This talk will educate listeners on best practices for safety and privacy on the Internet.It aims to demonstrate the improbability of staying anonymous while engaging in group or social activities on the internet, and especially while engaging in criminal activities as a group. This talk will reveal how Hubris, A5h3r4h, and Backtrace security staged a cyber war against anonymous, using Anonymous' own methods, and how key operatives in ....

https://www.defcon.org/defcon-19/dc-19-presentations/Imhoff/DEFCON-19-Imhoff-Password-Cracking.pdf As this shift to "General Computing" and working in the cloud has accelerated in the last 4 years, so has the ability to take advantage of these technologies from an Information Security vantage point. This could not be more apparent than with the sudden uptick in GPU based password cracking technologies. In this presentation we will expl....

https://www.defcon.org/defcon-19/dc-19-presentations/Jakhar/DEFCON-19-Jakhar-Jugaad-Linux-Thread-Injection.pdf Windows malware conveniently use the CreateRemoteThread() api to delegate critical tasks inside of other processes. However till now there is no API on Linux to perform such operation. This paper talks about my work on creating an API similar to createRemoteThread() on *nix OSes. The kit currently works on Linux, allocates spa....

https://www.defcon.org/defcon-19/dc-19-presentations/Joyce/DEFCON-19-Joyce-trollspotting.png Trolling is something that today has a very negative connotation on the Internet and in the common usage of the word outside of it. However, for better or worse trolling has long enjoyed a close relationship with hacking be it in the area of information security, or simply in technology development. I intend to delve into the definition of a tr....

Remember when networks represented interesting targets, when TCP/IP was itself a vector for messiness, when packet crafting was a required skill? In this thoroughly retro talk, we're going to play with systems the old fashioned way, cobbling together various interesting behaviors with the last few shreds of what low level networking has to offer. Here's a few things to expect: * IPv4 and IPv6 Fragmentation Attacks, Eight Years In The M..

https://www.defcon.org/defcon-19/dc-19-presentations/Kennedy/DEFCON-19-Kennedy-Pentesting-Over-Powerlines-2.pdf When performing penetration tests on the internal network in conjunction with physical pentests your always concerned about being located. Let's remove that barrier and perform your penitents over power lines and never be detected. In this presentation we'll cover how you can perform full penetration tests over the power line....

https://www.defcon.org/defcon-19/dc-19-presentations/Kennish/DEFCON-19-Kennish-Tracking-the-Trackers.pdf What companies and organizations are collecting our web-browsing activity? How complete is their data? Do they have personally-identifiable information? What do they do with the data? The speaker, an ex-Google and DoubleClick engineer, will answer these questions by detailing the research he did for The Wall Street Journal (htt....

https://www.defcon.org/defcon-19/dc-19-presentations/Kornbrust/DEFCON-19-Kornbrust-Hacking-and-Securing-DB2.pdf DB2 for Linux, Unix and Windows is one of the databases where only little bit information about security problems is available. Nevertheless DB2 LUW is installed in many corporate networks and if not hardened properly could be an easy target for attackers. In many aspects DB2 is different from other databases, starting at the....

https://www.defcon.org/defcon-19/dc-19-presentations/Kotler-Amit/DEFCON-19-Kotler-Amit-Sounds-Like-Botnet.pdf VoIP is one of the most widely-used technologies among businesses and, increasingly, in households. It represents a combination of Internet technology and phone technology that enhances and expands the possibilities of both. One of these possibilities involves using it for botnet command and control infrastructure and a data ex....

https://www.defcon.org/defcon-19/dc-19-presentations/Krick/DEFCON-19-Krick-License-to-Transmit.pdf https://www.defcon.org/defcon-19/dc-19-presentations/Krick/DEFCON-19-Krick-License-to-Transmit-Extras.zip When cell phones, land lines and the internet break down in a disaster, Amateur radio is there. Considered to be one of the earliest forms of Hacking, this talk will take a look at some of the things that can be done if you are a..

https://www.defcon.org/defcon-19/dc-19-presentations/Lai-Wu-Chiu-PK/DEFCON-19-Lai-Wu-Chiu-PK-APT-Secrets-2.pdf In last year, we have given a talk over China-made malware in both Blackhat and DEFCON, which is appreciated by various parties and we would like to continue this effort and discuss over APT attacks in Asia this year. However, case studies are not just our main dish this time, we will carry out technical analysis over the samp....

Are you concerned that you have become a subject of unwarranted scrutiny? Convinced that the black helicopters are incoming and ruthless feds are determined in to steal your plans of world domination? This talk explores several potential designs for quick and ruthless destruction of data as a last resort, break glass in case of emergency type of situation. Projectiles and chemical warfare will be involved along with other methods. Each meth....

https://www.defcon.org/defcon-19/dc-19-presentations/Lenik/DEFCON-19-Lenik-MAC(b)Daddy.pdf The field of Computer Forensics moves more and more in the direction of rapid response and live system analysis every day. As breaches and attacks become more and more sophisticated the responders need to continually re-examine their arsenal for new tactics and faster ways to process large amounts of data. Timelines and super-timelines have been ....

At Defcon 17 when a speaker didn't show a bottle of vodka was offered to whoever gave an impromptu talk. Somebody went up and talked about his robot project. He mentioned that it didn't normally drive straight, and talked about all the software solutions he had tried to fix this. I was reasonably intoxicated and wound up shouting at him over the crowd that it did not drive straight because of his drive base design, and not his software. Thi....

https://www.defcon.org/defcon-19/dc-19-presentations/Linn/DEFCON-19-Linn-PIG-Finding-Truffles.pdf When we connect to a network we leak information. Whether obtaining an IP address, finding our default gateway, or using Dropbox there are packets that can be used to help identify more about our machine and network. This talk and series of demonstrations will help you learn to passively profile a network through a new Metasploit module by....

David Litchfield is recognized as one of the world's leading authorities on database security. He is the author of Oracle Forensics, the Oracle Hacker's Handbook, the Database Hacker's Handbook and SQL Server Security and is the co-author of the Shellcoder's Handbook. He is a regular speaker at a number of computer security conferences and has delivered lectures to the National Security Agency, the UK's Security Service, GCHQ and the Bundes..

Picking on charities is just plain rude. Thankfully, that's not what we're about. We're about proving that hackers have amazing skills that can transform charitable organizations. We're about stepping into the gap to feed and educate the world's most vulnerable citizens. We are virtual, geographically diverse and different. We've fed thousands of families through our "food for work" program We build computer labs to help students ..

What Cloak? Recent policy proposals from the US Executive seem to call for government support for strong encryption use by individuals and vendors in the name of protecting privacy and anonymity. Yet strong encryption is still considered a controlled resource, requiring explicit permission to import or export from the US. This is also true for other countries. This talk will try to couch these proposals in light of past crypto rules, illumi..

https://www.defcon.org/defcon-19/dc-19-presentations/Maresca/DEFCON-19-Maresca-FIPS-140.pdf Many standards, especially those provided by the government, are often viewed as more trouble the actual help. The goal of this talk is to shed a new light onto onesuch standard (FIPS 140) and show what it is inteded for and how is can sometimes help ensure good design practices for security products. But everything is not roses and there are ce....

In the early 90's, at the dawn of the World Wide Web, some engineers at Netscape developed a protocol for making secure HTTP requests, and what they came up with was called SSL. Given the relatively scarce body of knowledge concerning secure protocols at the time, as well the intense pressure that everyone at Netscape was working under, their efforts can only be seen as incredibly heroic. But while it's amazing that SSL has endured for as l..

This presentation will cover the Black Arts of making Cracks, KeyGens, Malware, and more. The information in this presentation will allow a .NET programmer to do unspeakable things .NET applications. I will cover the life cycle of developing such attacks and over coming common countermeasures to stop such attacks. New tools to assist in the attacks will be supplied. This presentation will focus on C# but applies to any application based on ..

https://www.defcon.org/defcon-19/dc-19-presentations/McGrew/DEFCON-19-McGrew-Covert.pdf https://www.defcon.org/defcon-19/dc-19-presentations/McGrew/DEFCON-19-McGrew-Covert-WP.pdf https://www.defcon.org/defcon-19/dc-19-presentations/McGrew/DEFCON-19-McGrew-Covert-Extras.zip In digital forensics, most examinations take place after the hardware has been physically seized (in most law enforcement scenarios) or a preinstalled agen....

https://www.defcon.org/defcon-19/dc-19-presentations/McNabb/DEFCON-19-McNabb-Vulns-Wireless-Water-Meter-Networks.pdf Why research wireless water meters? Because they are a potential security hole in a critical infrastructure, which can lead to a potential leakage of private information, and create the potential to steal water by lowering water bills? It's a technology that's all around us but seems to too mundane to think about. Becaus....

https://www.defcon.org/defcon-19/dc-19-presentations/Miller/DEFCON-19-Miller-Battery-Firmware-Hacking.pdf Ever wonder how your laptop battery knows when to stop charging when it is plugged into the wall, but the computer is powered off? Modern computers are no longer just composed of a single processor. Computers possess many other embedded microprocessors. Researchers are only recently considering the security implications of multiple....

We're baaaaaack! The most talked about panel at DEF CON! Nearly two hours of non-stop FAIL. Come hear some of the loudest mouths in the industry talk about the epic security failures of the last year. We'll be covering mobile phones, cloud, money laundering and food cooked on stage to name just a few topics. Nothing is sacred not even each other. Come for the FAIL stay for the crepes! David Mortman runs Operations and Security for C3, ....

https://www.defcon.org/defcon-19/dc-19-presentations/Ocepek/DEFCON-19-Ocepek-Blinkie-Lights-Arduino.pdf https://www.defcon.org/defcon-19/dc-19-presentations/Ocepek/DEFCON-19-Ocepek-Blinkie-Lights-Arduino-Extras.zip Remember the good old days, when you'd stare at Rx and Tx on your shiny new Supra 1200bps modem, and actually know what the heck was going on? Systems tend to talk a lot more nowadays, and somewhere along the line I com....

Get the latest information about how the law is racing to catch up with technological change from staffers at the Electronic Frontier Foundation, the nation's premiere digital civil liberties group fighting for freedom and privacy in the computer age. This session will include updates on current EFF issues such as surveillance online and fighting efforts to use intellectual property claims to shut down free speech and halt innovation, discu....

https://www.defcon.org/defcon-19/dc-19-presentations/Osborn-Johansen/DEFCON-19-Osborn-Johansen-Hacking-Google-Chrome-OS.pdf Google recently announced Chrome OS powered computers, called Chromebooks, at Google I/O and the company is getting ready to market them to businesses as well as consumers. What's different about Chrome OS and Chromebooks, other than the entire user-experience taking place exclusively in a Web browser (Google Chro....

This presentation is about the security of VoIP deployed in hotel guest rooms. What it is, why it benefits administrators and users, and how easily it can be broken. The hospitality industry is widely deploying VoIP. Since 2008, we've seen an increase of these rollouts along with Admin awareness of applying the required security controls in order to mitigate this potential backdoor into a company's mission critical data and systems - their ....

Can the NSA really do that? Um, yes. Join me at the movies to take a close look at how current technology has caught up with the spy gadgets dreamed up for Hollywood flicks- from old favorites like Brazil to newer additions like Bourne and Dark Knight. Jaunty tin foil hats and movie snacks will be provided! Nicole Ozer directs the Technology and Civil Liberties Program at the ACLU of Northern California and spearheads the organization'....

117 visitors online