Site uses cookies to provide basic functionality.
Javascript rendering is set to off by default when visiting the site via .onion and .i2p domains. It can be enabled back again in user's settings section. Javascript rendering set to off means, that you can disable javascript in your browser now and the site will remain functional.
There is also IRC server now available via native IRC clients or non javascript web based one.
Fonts can be adjusted in user's settings section as well.
Check FAQ for more.

OK

https://www.defcon.org/defcon-19/dc-19-presentations/Percoco-Spiderlabs/DEFCON-19-Percoco-Spiderlabs-SSLizzard.pdf Extra Materials Here: https://www.defcon.org/defcon-19/dc-19-presentations/Percoco-Spiderlabs/Extras/SSLizzard.zip The world has seen a seismic shift from browser-based web applications to GUI-rich semi-thick client applications running on handheld mobile devices. In the browser world, the industry had placed a great ....

https://www.defcon.org/defcon-19/dc-19-presentations/Percoco-Spiderlabs/DEFCON-19-Percoco-Spiderlabs-Malware-Freakshow-3.pdf Well There's malware on the interwebs. They're pwning all your systems, snatching your data up. So hide your cards, hide your docs, and hide your phone, 'cause they're pwning er'body out there! This may be the 3rd and final installment of the Malware Freak Show series, so we're pulling out all the stops. This yea....

https://www.defcon.org/defcon-19/dc-19-presentations/Percoco-Spiderlabs/DEFCON-19-Percoco-Spiderlabs-Droid.pdf Extra Materials Here: https://www.defcon.org/defcon-19/dc-19-presentations/Percoco-Spiderlabs/Extras/DEFCON-19-Percoco-Droid-BanthaPudu-1.0.apk Last year, we presented a talk on the implication of malware and rootkits on mobile devices. We focused on the kernel layer of the Android OS stack. With the proliferation of Apps....

https://www.defcon.org/defcon-19/dc-19-presentations/Phillips/DEFCON-19-Phillips-Hacking-MMORPGs.pdf Extra Materials Here: https://www.defcon.org/defcon-19/dc-19-presentations/Phillips/DEFCON-19-Phillips-Hacking-MMORPGs-Extras.zip Online games, such as MMORPG's, are the most complex multi-user applications ever created. The security problems that plague these games are universal to all distributed software systems. Online virtual ....

https://www.defcon.org/defcon-19/dc-19-presentations/Pickett/DEFCON-19-Pickett-Port-Scanning-Without-Packets.pdf https://www.defcon.org/defcon-19/dc-19-presentations/Pickett/DEFCON-19-Pickett-Resources.pdf With auto-configuration protocols now being added to operating systems and implemented by default in your network devices, hosts are now actively advertising their available attack surfaces to anyone listening on the network. ....

Authentication is an integral part of our modern, digital lifestyle. It is a universal means of access to our work, to our finances, and to our friends and recreation. Of all the types of authentication available, passwords are still the most common form of authentication in use. Indeed, passwords in one form or another have been utilized since the dawn of computing. This, as this presentation will demonstrate, is not necessarily a good thi....

Being a most prevalent document exchange format on the Internet, Portable Document Format (PDF) is in danger of becoming the main target for client-side attack. With estimation of more than 1.5 million line of code and loaded with huge functionalities, this powerful document format is suffered with several high impact vulnerabilities, allowing attackers to exploit and use it as malware spreading vector. Until now, there are thousands o....

https://www.defcon.org/defcon-19/dc-19-presentations/Rezchikov-Wang-Engelman/DEFCON-19-Rezchikov-Wang-Engelman-Airport-Security-WP.pdf Eight years after 9/11 TSA finally decided to fix their security system. But what has really changed? Homeland Security's science division has been busy lately, and is currently polishing up a project called FAST - Future Attribute Screening Technology. FAST, part of project MALINTENT, is a project of t....

Whoever fights monsters should see to it that in the process he does not become a monster." - Friedrich Nietzsche. Aaron Barr returns for the first time in what's sure to be a gritty and frank (and heated) panel. How can we conduct ourselves without losing ourselves? How far is too far - or not far enough? IT security has finally gotten the attention of the mainstream media, Pentagon generals and public policy authors in the Beltway, a....

https://www.defcon.org/defcon-19/dc-19-presentations/Robinson/DEFCON-19-Robinson-Time.pdf Computer forensic examiners rely heavily on timestamps during investigations. Timeline analysis is a critical technique in determining what happened and when. In 2005, timestomp.exe was released and this gave non-observant investigators a run for their money. Unfortunately, there are some gaps in what timestomp.exe will do. Observant investigators....

Originally considered to be the stuff of myth, remote kernel exploits allow attackers to bypass all operating system protection mechanisms and gain instant root access to remote systems. While reviewing prior work in remote kernel exploitation, this talk will go over some of the challenges and limitations associated with developing remote kernel exploits. We will discuss in detail the development of an exploit for a remotely triggerabl....

Radar is used extensively by the military, police, weather, air travel, and maritime industries - why not you? Come learn how to build a radar imaging system on the cheap! This talk will explain the basics of how radar works as well as how to measure range and velocity of your chosen targets. You will learn how to use synthetic aperture techniques to generate a two- or even three-dimensional image. The hardware and software design will be t....

Over the last five years, network neutrality has moved from an abstract buzzword to FCC-enacted policy. Supporters and detractors both contend that their opponents position means "the end of the Internet as we know it!" This panel discussion will present a reasoned discussion of the issue from multiple viewpoints. Among the issues to answer: What is network neutrality and can we even agree on a definition? Does the FCC have the authority to..

https://www.defcon.org/defcon-19/dc-19-presentations/Schearer/DEFCON-19-Schearer-WTF-Privacy.pdf There is no explicit right to privacy in the Constitution, but some aspects of privacy are protected by the First, Third, Fourth and Fifth Amendments. This presentation will discuss the historical development of the right to privacy, and in particular, the development of the Fourth Amendment; and then compares this historical development to....

For the last few years, historian and archivist Jason Scott has been involved with a loose, rogue band of data preservation activists called The Archive Team. As major sites with brand recognition and the work of millions announce short-notice shutdowns of their entire services, including Geocities, Friendster, and Yahoo Video, Archive Team arrives on the scene to duplicate as much as they possibly can for history before all the data is wip....

The Smart Grid brings greater benefits for utilities and customer alike, however these benefits come at a cost from a security perspective. Unlike the over-hyped messages we usually hear from the media, the sky is NOT falling. However, just like any other technology, the systems and devices that make up the Smart Grid will have weaknesses and vulnerabilities. It is important for us to understand these vulnerabilities, how they can be attack....

https://www.defcon.org/defcon-19/dc-19-presentations/Shah/DEFCON-19-Shah-Mobile-Moolah.pdf Smartphones are a hot new market for software developers. Millions of potential customers, and a large percentage willing to part with a small sum of money for your latest creation. Even a moderately successful app can help fill your pockets. It's hard to ignore for legitimate developers. It's even harder to ignore for criminals. Things have....

When a CISO pays good money for a thorough pentesting, she wants results. Not necessarily the ones that the pentester had in mind, either. Whether the time allotted is too short, the pentester has to achieve multiple objectives, or they disagree on the severity of the findings, both the CISO and the pentester have to agree on both sides of the engagement. We discuss numerous aspects of voluntary pwnage: the differences between a security as..

https://www.defcon.org/defcon-19/dc-19-presentations/Skunkworks/DEFCON-19-Skunkworks-Bitcoin.pdf In the post 9/11 era when it's nearly impossible to buy a pack of gum without alerting the big three credit bureaus, you may think that anonymity is long gone from the economy. That's where bitcoin comes in. Bitcoin is a decentralized peer-to-peer currency based solely on computing power. It is (mostly) untraceable and highly anonymous, not..

Halloween makers or how haunters void warranties, social engineer and find the joy of creativity. A short path down to what a community of makers that mod hardware, special effect and mood you in order to scare the shit out of you just one night a year. These people comprise electrical engineers to housewives and personally I've learned to solder better, faster because of it. Reeves Smith has been working with hardware for security's s..

https://www.defcon.org/defcon-19/dc-19-presentations/Street/DEFCON-19-Street-Steal-Everything.pdf This is not a presentation where I talk about how I would get in or the things I might be able to do. This is a talk where I am already in and I show you pictures from actual engagements that I have been on. They say one picture is worth a thousand words I show you how one picture cost a company a million dollars and maybe even a few lives....

https://www.defcon.org/defcon-19/dc-19-presentations/Sumner-Byers-Alien/DEFCON-19-Sumner-Byers-Alien-Weaponizing-Cyberpsychology.pdf Almost everything we do in life leaves a personality footprint and what we do on social networking sites like Facebook is no exception. During this talk we will examine: * What it is possible to determine about someone's personality from their facebook activity * What to look for when you are try....

The presentation will take a deep dive into two newly released Owasp tools; the Owasp Hatkit Proxy and the Owasp Hatkit Datafiddler. The name Hatkit is an acronym (of sorts) for Http Analysis Toolkit and are tools mainly for people who analyse (hack!) web applications. The tools make extensive use of MongoDB, in particular the advanced querying facilities in available in this database. Prior knowledge of Javascript and Python is an advantag....

https://www.defcon.org/defcon-19/dc-19-presentations/Tassey-Perkins/DEFCON-19-Tassey-Perkins-Wireless-Aerial-Surveillance-Platform.pdf Tired of theory? This session has everything you want, big yellow aircraft flown by computers, pounds of highly volatile chemicals, CUDA, 50 Amp electrical circuits and the ability to attack networks, systems and cell phones interactively from a remote location anywhere in the world. We will demonstrate....

https://www.defcon.org/defcon-19/dc-19-presentations/Thieme/DEFCON-19-Thieme-Staring-into-the-Abyss-WP.pdf Nothing is harder to see than things we believe so deeply we don't even see them. This is certainly true in the "security space," in which our narratives are self-referential, bounded by mutual self-interest, and characterized by a heavy dose of group-think. That narrative serves as insulation to filter out the most critical truth....

Lock manufacturers continue to produce insecure designs in both mechanical and electro-mechanical locks. While these devices are designed to provide secure access control to commercial and government facilities, in fact many do not. Recent disclosures with regard to extremely popular push-button locks have led to an expanded investigation into their technology and security by our research team. As a consequence, it appears that mechanical l....

Ever leave the house without your picks only to find yourself in a situation where you desperately need them? Well, never fear! I'm going to explain how to open everything from cars, to briefcases to safes with objects as common as popsicle sticks and unconventional as palm sanders. Every attack will be fully explained so you understand the underlying mechanisms and how we are taking advantage of mechanical tolerances and design flaws to ow....

https://www.defcon.org/defcon-19/dc-19-presentations/Trimble/DEFCON-19-Trimble-Cybertravel.ppt.pdf This presentation discusses the current legal status of evasion of geolocation and the potential liability of the user-evader or provider of an evasion tool. The presentation also projects how the law might develop to treat acts of evasion and what challenges the technical community might face in this area. The legal community has sh....

https://www.defcon.org/defcon-19/dc-19-presentations/Webb/DEFCON-19-Webb-Runtime-Process-Insemination.pdf Injecting arbitrary code during runtime in linux is a painful process. This presentation discusses current techniques and reveals a new technique not used in other projects. The proposed technique allows for anonymous injection of shared objects, the ability to pwn a process without leaving any physical evidence behind. Libhijack, ..

https://www.defcon.org/defcon-19/dc-19-presentations/Weeks/DEFCON-19-Weeks-Network-Nightmare.pdf The best techniques for exploitation, maintaining access, and owning in general move down the stack, using low-level code to bypass security controls. Take the preboot execution environment and get bios-level access to the hardware from across the network, outside any control of the on-disk operating system. In this presentation I will deta....

https://www.defcon.org/defcon-19/dc-19-presentations/O%27Neil-Chin/DEFCON-19-O%27Neil-Chin-Google-Android.pdf According to Google, Android was designed to give mobile developers "an excellent software platform for everyday users" on which to build rich applications for the growing mobile device market. The power and flexibility of the Android platform are undeniable, but where does it leave developers when it comes to security? In this....

https://www.defcon.org/defcon-19/dc-19-presentations/Weyers/DEFCON-19-Weyers-Key-Impressioning.pdf We've all seen lockpicking explained on several security venues. You might even have tried it yourself. But what if you need to open a lock a number of times? Wouldn't it be great to have an opening technique that would supply you with a working key in the process? A method to do this has existed for quite some time, but until recently it....

https://www.defcon.org/defcon-19/dc-19-presentations/Wilhelm/DEFCON-19-Wilhelm-Staying-Connected%20.pdf During the recent revolutions in Africa and the Middle East, governments have shut down both Internet and Phone services in an attempt to quell communication among demonstrators. In addition, during natural disasters, people have been left without a means of finding out the latest news regarding emergency services. We will discuss me....

https://www.defcon.org/html/links/dc-archives/dc-19-archive.html The only thing worse than no security is a false sense of security. And though we know, "you can't win by defense alone", our modern approaches tend to act as though offense and defense are two entirely separate things. Treating security as an issue of quality has gotten us far, however, nearly everyday, some of the largest companies are still being compromised. It's beco....

At Defcon 17 when a speaker didn't show a bottle of vodka was offered to whoever gave an impromptu talk. Somebody went up and talked about his robot project. He mentioned that it didn't normally drive straight, and talked about all the software solutions he had tried to fix this. I was reasonably intoxicated and wound up shouting at him over the crowd that it did not drive straight because of his drive base design, and not his software. Thi....

There is a long tradition of researchers presenting at security conferences on topics that are embarrassing to a large company or government agency: ATM hacking, router vulnerabilities, Massachusetts toll road RFIDs, etc. Many of these brave researchers risk lawsuits or career ruin to reveal the truth. THIS is the first talk that puts the presenters' very lives in peril. Much has been made of the so-called "IPv4 address exhaustion" problem,....

https://www.defcon.org/images/defcon-19/dc-19-presentations/Cryer/DEFCON-19-Cryer-Taking-Your-Ball-and-Going-Home.pdf When for-profit companies offer a free app, there is always going to be strings attached. As we have increasingly seen, these strings are often tied to your privacy to enable said third party company to monetize you in some way, but in worse cases your security can be compromised leaving you open to identity theft at be....

https://www.defcon.org/images/defcon-19/dc-19-presentations/PCI-PANEL/DEFCON-19-JackDaniel-PCI-2-PANEL.pdf Building on last year's panel discussion of PCI and its impact on the world of infosec, we are back for more- including "actionable" information. Having framed the debates in the initial panel, this year we will focus on what works, what doesn't, and what we can do about it. Compliance issues in general, and PCI-DSS in partic....

Former keynotes keep coming back to DEFCON. Join The Dark Tangent, Rod Beckstrom, Jerry Dixon, Tony Sager, and Linton Wells to discuss the future of cyber security. Rod Beckstrom is a highly successful entrepreneur, founder and CEO of a publicly-traded company, a best-selling author, avowed environmentalist, public diplomacy leader and, most recently, the head of a top-level federal government agency entrusted with protecting the natio....

Tamper evident technologies are quickly becoming an interesting topic for hackers around the world. DEF CON 18 (2010) held the first ever "Tamper Evident" contest, where contestants were given a box sealed with a variety of tamper evident devices, many of which purport to be "tamper proof." All of these devices were defeated, even by those with little experience and a limited toolkit. Like the computer world, many of these devices are overm....

https://www.defcon.org/images/defcon-19/dc-19-presentations/Devarajan-LeBert/DEFCON-19-Devarajan-LeBert-VDLDS.pptx.pdf Anytime you want to bypass the system, you tend to have a telephone conversation instead of leaving a paper trail. Data Leakage Prevention (DLP) is on top of the list for most organizations, be it financial or medical industry. In order to overcome this issue we need to devise a new system that can monitor phone conver....

https://www.defcon.org/images/defcon-19/dc-19-presentations/Ollam/DEFCON-19-Ollam-Gun-Safes.pdf Hackers like guns. Hackers like locks. Hackers like to tinker with guns and locks. And, most of the time, hackers protect their guns with high-quality locks. However, while it's one thing to own a nice gun safe protected by a high security dial, that sort of solution tends to be best for the firearms that one doesn't have in daily use. Many ....

Come watch Whitfield Diffie and Moxie Marlinspike talk about certificate authorities, DNSSEC, SSL, dane, trust agility and whatever else they want to. Moderated by the Dark Tangent and with Q&A from the audience.

https://www.defcon.org/images/defcon-19/dc-19-presentations/Dinaburg/DEFCON-19-Dinaburg-Bit-Squatting.pdf We are generally accustomed to assuming that computer hardware will work as described, barring deliberate sabotage. This assumption is mistaken. Poor manufacturing, errant radiation, and heat can cause malfunction. Commonly, such malfunction DRAM chips manifest as flipped bits. Security researchers have known about the danger of su....

119 visitors online