Site uses cookies to provide basic functionality.
Javascript rendering is set to off by default when visiting the site via .onion and .i2p domains. It can be enabled back again in user's settings section. Javascript rendering set to off means, that you can disable javascript in your browser now and the site will remain functional.
There is also IRC server now available via native IRC clients or non javascript web based one.
Fonts can be adjusted in user's settings section as well.
Check FAQ for more.

OK

In this talk, I'll use my knowledge of working in a Security Operations Center to provide you with a framework to guide you in building your own SOC or network monitoring system capable of monitoring small to medium sized networks. The goal of this kind of monitoring is to watch for things such as break-in attempts on your network, malware downloads and malware beaconing out after installation and to be a central location for IT security th....

Facial Recognition sucks. But it's getting better. Big brother is watching, and he is interested in what you do, where you go, and who you talk to. Whether it's Deep Packet Inspection, or Facial Recognition, the idea of personalization as applied to privacy invasion is a fascinating and cogent issue. Governments are using it to locate fugitives with fake id's in the DMV database. DHS-like agencies, the world over, are starting to use i....

Many system administrators take a patch for a denial of service attack to be optional. What's the worst that could happen? Oh no -- a local user could crash the system. We'll just reboot it; MyPhpGresQL.py on Rails is totally transactional, right? Commit messages fixing these sorts of crashes are often characteristically underreported, too: "allows attackers to cause an application crash". In some cases, the descriptions are correct; t....

Many system administrators take a patch for a denial of service attack to be optional. What's the worst that could happen? Oh no -- a local user could crash the system. We'll just reboot it; MyPhpGresQL.py on Rails is totally transactional, right? Commit messages fixing these sorts of crashes are often characteristically underreported, too: "allows attackers to cause an application crash". In some cases, the descriptions are correct; t....

Many system administrators take a patch for a denial of service attack to be optional. What's the worst that could happen? Oh no -- a local user could crash the system. We'll just reboot it; MyPhpGresQL.py on Rails is totally transactional, right? Commit messages fixing these sorts of crashes are often characteristically underreported, too: "allows attackers to cause an application crash". In some cases, the descriptions are correct; t....

Bluetooth has come leaps and bounds in its past decade of use. Finding its way into billions of devices world wide. This talk introduces several new Bluetooth attack tools and projects focusing on automated pen-testing, obfuscation, Bluetooth profile cloning, war-nibbling, Denial of Service, and mapping Bluetooth device information. We will be discussing what information your Bluetooth devices gives out about you and what you can do about i..

Tired of keeping up with dozens of CDs and flash drives loaded with various Live operating systems and applications? I will be introducing the Katana: Portable Multi-Boot Security Suite; which brings many of the best live operating systems and portable applications together onto a single flash drive. Katana includes live distros like Backtrack, the Ultimate Boot CD, UBCD4Win, Ophcrack, and Trinity Rescue Kit as well as hundreds of portable ..

Bluetooth has come leaps and bounds in its past decade of use. Finding its way into billions of devices world wide. This talk introduces several new Bluetooth attack tools and projects focusing on automated pen-testing, obfuscation, Bluetooth profile cloning, war-nibbling, Denial of Service, and mapping Bluetooth device information. We will be discussing what information your Bluetooth devices gives out about you and what you can do about i..

Tired of keeping up with dozens of CDs and flash drives loaded with various Live operating systems and applications? I will be introducing the Katana: Portable Multi-Boot Security Suite; which brings many of the best live operating systems and portable applications together onto a single flash drive. Katana includes live distros like Backtrack, the Ultimate Boot CD, UBCD4Win, Ophcrack, and Trinity Rescue Kit as well as hundreds of portable ..

Bluetooth has come leaps and bounds in its past decade of use. Finding its way into billions of devices world wide. This talk introduces several new Bluetooth attack tools and projects focusing on automated pen-testing, obfuscation, Bluetooth profile cloning, war-nibbling, Denial of Service, and mapping Bluetooth device information. We will be discussing what information your Bluetooth devices gives out about you and what you can do about i..

Tired of keeping up with dozens of CDs and flash drives loaded with various Live operating systems and applications? I will be introducing the Katana: Portable Multi-Boot Security Suite; which brings many of the best live operating systems and portable applications together onto a single flash drive. Katana includes live distros like Backtrack, the Ultimate Boot CD, UBCD4Win, Ophcrack, and Trinity Rescue Kit as well as hundreds of portable ..

Littered with endless threats and vulnerabilities surrounding both social networking and the Smart Grid, the marriage of these two technologies is official, despite protests by the security community. Consumers love it because they can brag to their friends about how green they are. Businesses love it more because it provides fresh material for their marketing departments. Hackers love it the most because it opens up attack vectors, both ne....

Littered with endless threats and vulnerabilities surrounding both social networking and the Smart Grid, the marriage of these two technologies is official, despite protests by the security community. Consumers love it because they can brag to their friends about how green they are. Businesses love it more because it provides fresh material for their marketing departments. Hackers love it the most because it opens up attack vectors, both ne....

Littered with endless threats and vulnerabilities surrounding both social networking and the Smart Grid, the marriage of these two technologies is official, despite protests by the security community. Consumers love it because they can brag to their friends about how green they are. Businesses love it more because it provides fresh material for their marketing departments. Hackers love it the most because it opens up attack vectors, both ne....

In May, 2010, the Cooperative Cyber Defence Centre of Excellence in Estonia and the Swedish National Defence College hosted the Baltic Cyber Shield (BCS) international cyber defense exercise (CDX). For two days, six Blue Teams from northern European government, military and academic institutions defended simulated power generation companies against a Red Team of twenty hostile computer hackers. The scenario described a volatile geopolitical....

Get the latest information about how the law is racing to catch up with technological change from staffers at the Electronic Frontier Foundation, the nation’s premiere digital civil liberties group fighting for freedom and privacy in the computer age. This session will include updates on current EFF issues such as Digital Millennium Copyright Act (DMCA) use and misuse (and--maybe--the much delayed exemptions), whether breaking Captchas brea....

In May, 2010, the Cooperative Cyber Defence Centre of Excellence in Estonia and the Swedish National Defence College hosted the Baltic Cyber Shield (BCS) international cyber defense exercise (CDX). For two days, six Blue Teams from northern European government, military and academic institutions defended simulated power generation companies against a Red Team of twenty hostile computer hackers. The scenario described a volatile geopolitical....

Get the latest information about how the law is racing to catch up with technological change from staffers at the Electronic Frontier Foundation, the nation’s premiere digital civil liberties group fighting for freedom and privacy in the computer age. This session will include updates on current EFF issues such as Digital Millennium Copyright Act (DMCA) use and misuse (and--maybe--the much delayed exemptions), whether breaking Captchas brea....

In May, 2010, the Cooperative Cyber Defence Centre of Excellence in Estonia and the Swedish National Defence College hosted the Baltic Cyber Shield (BCS) international cyber defense exercise (CDX). For two days, six Blue Teams from northern European government, military and academic institutions defended simulated power generation companies against a Red Team of twenty hostile computer hackers. The scenario described a volatile geopolitical....

Get the latest information about how the law is racing to catch up with technological change from staffers at the Electronic Frontier Foundation, the nation’s premiere digital civil liberties group fighting for freedom and privacy in the computer age. This session will include updates on current EFF issues such as Digital Millennium Copyright Act (DMCA) use and misuse (and--maybe--the much delayed exemptions), whether breaking Captchas brea....

The mobile app revolution is upon us. Applications on your smartphone know more about you than anyone or anything else in the world. Apps know where you are, who you talk to, and what you're doing on the web; they have access to your financial accounts, can trigger charges to your phone bill, and much more. Have you ever wondered what smartphone apps are actually doing under the hood? We built the largest-ever mobile application security da....

The mobile app revolution is upon us. Applications on your smartphone know more about you than anyone or anything else in the world. Apps know where you are, who you talk to, and what you're doing on the web; they have access to your financial accounts, can trigger charges to your phone bill, and much more. Have you ever wondered what smartphone apps are actually doing under the hood? We built the largest-ever mobile application security da....

The mobile app revolution is upon us. Applications on your smartphone know more about you than anyone or anything else in the world. Apps know where you are, who you talk to, and what you're doing on the web; they have access to your financial accounts, can trigger charges to your phone bill, and much more. Have you ever wondered what smartphone apps are actually doing under the hood? We built the largest-ever mobile application security da....

The Arduino microcontroller platform entered the world under the guise of "physical computing" aimed at designers and artists but just like you can use a paint brush to jimmy open a door, you can use the Arduino in your security toolkit too. Attend this talk to learn how the Arduino makes microcontrollers and embedded hardware accessible to hax0rs too. After a quick tour through the Arduino ecosystem we'll move on to offensive uses. You'll ....

The Arduino microcontroller platform entered the world under the guise of "physical computing" aimed at designers and artists but just like you can use a paint brush to jimmy open a door, you can use the Arduino in your security toolkit too. Attend this talk to learn how the Arduino makes microcontrollers and embedded hardware accessible to hax0rs too. After a quick tour through the Arduino ecosystem we'll move on to offensive uses. You'll ....

The Arduino microcontroller platform entered the world under the guise of "physical computing" aimed at designers and artists but just like you can use a paint brush to jimmy open a door, you can use the Arduino in your security toolkit too. Attend this talk to learn how the Arduino makes microcontrollers and embedded hardware accessible to hax0rs too. After a quick tour through the Arduino ecosystem we'll move on to offensive uses. You'll ....

These days, all hackers have jobs and make some type of money. No matter if you are an independent researcher/ consultant/ 1337 hacker/ or entrepreneur, sometimes you have to deal with the corporate crap, one way or another. Now, how about those who really have to deal with it on a daily-basis in the corporate world? Well, this is an updated version of my DEF CON15 talk, shorter in time, yet, heavier on rants. Years go by, and most companie....

These days, all hackers have jobs and make some type of money. No matter if you are an independent researcher/ consultant/ 1337 hacker/ or entrepreneur, sometimes you have to deal with the corporate crap, one way or another. Now, how about those who really have to deal with it on a daily-basis in the corporate world? Well, this is an updated version of my DEF CON15 talk, shorter in time, yet, heavier on rants. Years go by, and most companie....

These days, all hackers have jobs and make some type of money. No matter if you are an independent researcher/ consultant/ 1337 hacker/ or entrepreneur, sometimes you have to deal with the corporate crap, one way or another. Now, how about those who really have to deal with it on a daily-basis in the corporate world? Well, this is an updated version of my DEF CON15 talk, shorter in time, yet, heavier on rants. Years go by, and most companie....

These days, all hackers have jobs and make some type of money. No matter if you are an independent researcher/ consultant/ 1337 hacker/ or entrepreneur, sometimes you have to deal with the corporate crap, one way or another. Now, how about those who really have to deal with it on a daily-basis in the corporate world? Well, this is an updated version of my DEF CON15 talk, shorter in time, yet, heavier on rants. Years go by, and most companie....

These days, all hackers have jobs and make some type of money. No matter if you are an independent researcher/ consultant/ 1337 hacker/ or entrepreneur, sometimes you have to deal with the corporate crap, one way or another. Now, how about those who really have to deal with it on a daily-basis in the corporate world? Well, this is an updated version of my DEF CON15 talk, shorter in time, yet, heavier on rants. Years go by, and most companie....

These days, all hackers have jobs and make some type of money. No matter if you are an independent researcher/ consultant/ 1337 hacker/ or entrepreneur, sometimes you have to deal with the corporate crap, one way or another. Now, how about those who really have to deal with it on a daily-basis in the corporate world? Well, this is an updated version of my DEF CON15 talk, shorter in time, yet, heavier on rants. Years go by, and most companie....

Many lock manufacturers do not understand the relationship and intersection between "mechanical engineering" and "security engineering" in their products. Typically, design engineers are fairly adept at making things work properly, but often fail to contemplate, conceive of, or identify potential or actual "real world" vulnerabilities in the locks and related hardware that they manufacture. This failure can lead to serious breaches in secur....

Many lock manufacturers do not understand the relationship and intersection between "mechanical engineering" and "security engineering" in their products. Typically, design engineers are fairly adept at making things work properly, but often fail to contemplate, conceive of, or identify potential or actual "real world" vulnerabilities in the locks and related hardware that they manufacture. This failure can lead to serious breaches in secur....

Many lock manufacturers do not understand the relationship and intersection between "mechanical engineering" and "security engineering" in their products. Typically, design engineers are fairly adept at making things work properly, but often fail to contemplate, conceive of, or identify potential or actual "real world" vulnerabilities in the locks and related hardware that they manufacture. This failure can lead to serious breaches in secur....

Want to know the story behind the latest government scandal, or see what a three-letter agency knows about you? In this workshop, the Electronic Frontier Foundation will show you how to use two open government laws, the Freedom of Information Act and the Privacy Act, to ask for records from the federal government. We'll discuss what you can (and can't) get under these laws, how to write an effective open government request, how to appeal an....

Mobile phones are still a proving ground for keeping the users' privacy safe. This presentation will describe the problems which are arising around the use of these technologies and how they can affect mobile users. It will propose Tor as a possible solution for some of these problems, describing its own strengths and weaknesses and the efforts developers put to implement a working port of the program on different devices, from the Chumby O....

Want to know the story behind the latest government scandal, or see what a three-letter agency knows about you? In this workshop, the Electronic Frontier Foundation will show you how to use two open government laws, the Freedom of Information Act and the Privacy Act, to ask for records from the federal government. We'll discuss what you can (and can't) get under these laws, how to write an effective open government request, how to appeal an....

Mobile phones are still a proving ground for keeping the users' privacy safe. This presentation will describe the problems which are arising around the use of these technologies and how they can affect mobile users. It will propose Tor as a possible solution for some of these problems, describing its own strengths and weaknesses and the efforts developers put to implement a working port of the program on different devices, from the Chumby O....

Want to know the story behind the latest government scandal, or see what a three-letter agency knows about you? In this workshop, the Electronic Frontier Foundation will show you how to use two open government laws, the Freedom of Information Act and the Privacy Act, to ask for records from the federal government. We'll discuss what you can (and can't) get under these laws, how to write an effective open government request, how to appeal an....

Mobile phones are still a proving ground for keeping the users' privacy safe. This presentation will describe the problems which are arising around the use of these technologies and how they can affect mobile users. It will propose Tor as a possible solution for some of these problems, describing its own strengths and weaknesses and the efforts developers put to implement a working port of the program on different devices, from the Chumby O....

Breaking in to the Information Security field isn't easy. The web of certifications, skills, and credibility is hard to climb through without the help of someone who's been there. Many of us would not be here today without the guidance of a mentor. The Information Security Mentor Match-up program is here at DEF CON to help those people new to the field meet with seasoned pros who know the value of mentoring. Whether you're a researcher, pen....

Breaking in to the Information Security field isn't easy. The web of certifications, skills, and credibility is hard to climb through without the help of someone who's been there. Many of us would not be here today without the guidance of a mentor. The Information Security Mentor Match-up program is here at DEF CON to help those people new to the field meet with seasoned pros who know the value of mentoring. Whether you're a researcher, pen....

Breaking in to the Information Security field isn't easy. The web of certifications, skills, and credibility is hard to climb through without the help of someone who's been there. Many of us would not be here today without the guidance of a mentor. The Information Security Mentor Match-up program is here at DEF CON to help those people new to the field meet with seasoned pros who know the value of mentoring. Whether you're a researcher, pen....

34 visitors online