Site uses cookies to provide basic functionality.
Javascript rendering is set to off by default when visiting the site via .onion and .i2p domains. It can be enabled back again in user's settings section. Javascript rendering set to off means, that you can disable javascript in your browser now and the site will remain functional.
There is also IRC server now available via native IRC clients or non javascript web based one.
Fonts can be adjusted in user's settings section as well.
Check FAQ for more.

OK

Working with more than 50 malicious backdoors written over the last 10 years we show how insiders who write code, whether they are developers working for an enterprise or contributors to an open source project, have an almost unlimited number of ways to put chinks in the armor of their software. These holes are often put in place for seemingly good reasons to facilitate easy debugging, make working from home easier, or as a failsafe in case....

This presentation will look at ways you can get critical data across the country during a wired infrastructure break down, Including taking over satellites, low altitude wifi via weather balloons, and bouncing signals off the moon. We will also take a look at some other stuff you can blame us for as time permits. Matt "DCFluX" Krick is Chief Engineer of New West Broadcasting Systems, Inc., Operators of broadcast stations KGMN-FM, KZKE-..

Working with more than 50 malicious backdoors written over the last 10 years we show how insiders who write code, whether they are developers working for an enterprise or contributors to an open source project, have an almost unlimited number of ways to put chinks in the armor of their software. These holes are often put in place for seemingly good reasons to facilitate easy debugging, make working from home easier, or as a failsafe in case....

This presentation will look at ways you can get critical data across the country during a wired infrastructure break down, Including taking over satellites, low altitude wifi via weather balloons, and bouncing signals off the moon. We will also take a look at some other stuff you can blame us for as time permits. Matt "DCFluX" Krick is Chief Engineer of New West Broadcasting Systems, Inc., Operators of broadcast stations KGMN-FM, KZKE-..

Working with more than 50 malicious backdoors written over the last 10 years we show how insiders who write code, whether they are developers working for an enterprise or contributors to an open source project, have an almost unlimited number of ways to put chinks in the armor of their software. These holes are often put in place for seemingly good reasons to facilitate easy debugging, make working from home easier, or as a failsafe in case....

This presentation will look at ways you can get critical data across the country during a wired infrastructure break down, Including taking over satellites, low altitude wifi via weather balloons, and bouncing signals off the moon. We will also take a look at some other stuff you can blame us for as time permits. Matt "DCFluX" Krick is Chief Engineer of New West Broadcasting Systems, Inc., Operators of broadcast stations KGMN-FM, KZKE-..

Matt Ryanczak, Network Operations Manager at the American Registry for Internet Numbers (ARIN), began deploying IPv6 in production in 2003. Matt has encountered and overcome the common challenges many of you will encounter working with IPv6. ARIN would like to share its IPv6 deployment experiences with you and relay our knowledge of other production IPv6 deployments to help you get a jump start on your own efforts. Matt will talk in de..

Matt Ryanczak, Network Operations Manager at the American Registry for Internet Numbers (ARIN), began deploying IPv6 in production in 2003. Matt has encountered and overcome the common challenges many of you will encounter working with IPv6. ARIN would like to share its IPv6 deployment experiences with you and relay our knowledge of other production IPv6 deployments to help you get a jump start on your own efforts. Matt will talk in de..

Matt Ryanczak, Network Operations Manager at the American Registry for Internet Numbers (ARIN), began deploying IPv6 in production in 2003. Matt has encountered and overcome the common challenges many of you will encounter working with IPv6. ARIN would like to share its IPv6 deployment experiences with you and relay our knowledge of other production IPv6 deployments to help you get a jump start on your own efforts. Matt will talk in de..

With the current media hype about cyber threats and cyber warfare, Max Kelly - former CSO of Facebook - offers his perspective on the effects of internet militarization and it's relationship to traditional security operations. Max Kelly is a recognized thought leader in the security space. As CSO of Facebook, he founded, built, and managed the Facebook Security Team from 2005-1010. He was responsible for all aspects of Facebook Securit..

ChaosVPN - the American name is AgoraLink - is a tinc based, fully meshed VPN to connect hackerspaces and other hacker related networks for fun, sharing, learning and competition with each other. Its purpose is to provide a trusted, private and secure network with high bandwidth, low latency, without single points of failure. The first intended usage of the network was VoIP, but it has become used for lots of different purposes - whate....

With the current media hype about cyber threats and cyber warfare, Max Kelly - former CSO of Facebook - offers his perspective on the effects of internet militarization and it's relationship to traditional security operations. Max Kelly is a recognized thought leader in the security space. As CSO of Facebook, he founded, built, and managed the Facebook Security Team from 2005-1010. He was responsible for all aspects of Facebook Securit..

ChaosVPN - the American name is AgoraLink - is a tinc based, fully meshed VPN to connect hackerspaces and other hacker related networks for fun, sharing, learning and competition with each other. Its purpose is to provide a trusted, private and secure network with high bandwidth, low latency, without single points of failure. The first intended usage of the network was VoIP, but it has become used for lots of different purposes - whate....

With the current media hype about cyber threats and cyber warfare, Max Kelly - former CSO of Facebook - offers his perspective on the effects of internet militarization and it's relationship to traditional security operations. Max Kelly is a recognized thought leader in the security space. As CSO of Facebook, he founded, built, and managed the Facebook Security Team from 2005-1010. He was responsible for all aspects of Facebook Securit..

ChaosVPN - the American name is AgoraLink - is a tinc based, fully meshed VPN to connect hackerspaces and other hacker related networks for fun, sharing, learning and competition with each other. Its purpose is to provide a trusted, private and secure network with high bandwidth, low latency, without single points of failure. The first intended usage of the network was VoIP, but it has become used for lots of different purposes - whate....

WPA2 is the most robust security configuration available today for WiFi networks. It is widely used to secure enterprise WLANs. Interestingly, it is also being used to secure guest, municipal and public WiFi networks. In this paper, we present a new vulnerability found in WPA2 protocol which can be exploited by a malicious user to attack and compromise legitimate users. We also present a few attack mitigation techniques which can be used to....

WPA2 is the most robust security configuration available today for WiFi networks. It is widely used to secure enterprise WLANs. Interestingly, it is also being used to secure guest, municipal and public WiFi networks. In this paper, we present a new vulnerability found in WPA2 protocol which can be exploited by a malicious user to attack and compromise legitimate users. We also present a few attack mitigation techniques which can be used to....

WPA2 is the most robust security configuration available today for WiFi networks. It is widely used to secure enterprise WLANs. Interestingly, it is also being used to secure guest, municipal and public WiFi networks. In this paper, we present a new vulnerability found in WPA2 protocol which can be exploited by a malicious user to attack and compromise legitimate users. We also present a few attack mitigation techniques which can be used to....

Gold farmers. Cheaters. Beleaguered programmers. All ingredients in a recipe for an unstable, fun-sapping game. Closely following the model of "Brief Title: Long, Boring Description," Securing MMOs: A Security Professional's View From the Inside will give attendees a look at the security problems plaguing the MMO industry and how modern engineers are taking the fight to cheaters and hackers in MMOs. metr0 is currently a Senior Sof..

This talk covers the use of chaining vulnerabilities in order to bypass layered security systems. This talk will also cover ways of obtaining wormable remote code execution on a modern LAMP platform. These attacks where developed by me, and they are very new. These attacks are as real as it gets, and the results are making the headlines. "Apocalyptic infection" -- The Register Michael Brooks: This will be my 3rd year in a row that ..

Gold farmers. Cheaters. Beleaguered programmers. All ingredients in a recipe for an unstable, fun-sapping game. Closely following the model of "Brief Title: Long, Boring Description," Securing MMOs: A Security Professional's View From the Inside will give attendees a look at the security problems plaguing the MMO industry and how modern engineers are taking the fight to cheaters and hackers in MMOs. metr0 is currently a Senior Sof..

This talk covers the use of chaining vulnerabilities in order to bypass layered security systems. This talk will also cover ways of obtaining wormable remote code execution on a modern LAMP platform. These attacks where developed by me, and they are very new. These attacks are as real as it gets, and the results are making the headlines. "Apocalyptic infection" -- The Register Michael Brooks: This will be my 3rd year in a row that ..

Gold farmers. Cheaters. Beleaguered programmers. All ingredients in a recipe for an unstable, fun-sapping game. Closely following the model of "Brief Title: Long, Boring Description," Securing MMOs: A Security Professional's View From the Inside will give attendees a look at the security problems plaguing the MMO industry and how modern engineers are taking the fight to cheaters and hackers in MMOs. metr0 is currently a Senior Sof..

This talk covers the use of chaining vulnerabilities in order to bypass layered security systems. This talk will also cover ways of obtaining wormable remote code execution on a modern LAMP platform. These attacks where developed by me, and they are very new. These attacks are as real as it gets, and the results are making the headlines. "Apocalyptic infection" -- The Register Michael Brooks: This will be my 3rd year in a row that ..

SHODAN is a computer search engine. But it is unlike any other search engine. While other search engines scour the web for content, SHODAN scans for information about the sites themselves. The result is a search engine that aggregates banners from well-known services. This presentation will focus on the applications of SHODAN to penetration testers, and in particular will detail a number of case studies demonstrating passive vulnerability a....

SHODAN is a computer search engine. But it is unlike any other search engine. While other search engines scour the web for content, SHODAN scans for information about the sites themselves. The result is a search engine that aggregates banners from well-known services. This presentation will focus on the applications of SHODAN to penetration testers, and in particular will detail a number of case studies demonstrating passive vulnerability a....

SHODAN is a computer search engine. But it is unlike any other search engine. While other search engines scour the web for content, SHODAN scans for information about the sites themselves. The result is a search engine that aggregates banners from well-known services. This presentation will focus on the applications of SHODAN to penetration testers, and in particular will detail a number of case studies demonstrating passive vulnerability a....

Earlier this year the community was shown how to successfully Build your own Predator UAV @ 99.95% Discount - and a recon mission over DC! But now new payloads take the fun/danger to a new level! Come find out how you can not only easily warfly and conduct aerial reconnaissance for your next 'mission' but also use your UAV as a roving angel of wireless death, as always from the confines of your couch.. Or Vegas hotel room. The presente....

A barbecue with a built in webserver. Remote command execution via Twitter. Great geek projects, but do we really need them? On the serious side of things, do we really need web-based management interfaces on firewalls, printers, and phone systems? Maybe it's time to take a look at the sometimes-humorous, often-dangerous downsides. mckt (pronounced "mckt") is a three time consecutive winner of the Bill Bilano 'Heeey Dude!' award, and a..

Earlier this year the community was shown how to successfully Build your own Predator UAV @ 99.95% Discount - and a recon mission over DC! But now new payloads take the fun/danger to a new level! Come find out how you can not only easily warfly and conduct aerial reconnaissance for your next 'mission' but also use your UAV as a roving angel of wireless death, as always from the confines of your couch.. Or Vegas hotel room. The presente....

A barbecue with a built in webserver. Remote command execution via Twitter. Great geek projects, but do we really need them? On the serious side of things, do we really need web-based management interfaces on firewalls, printers, and phone systems? Maybe it's time to take a look at the sometimes-humorous, often-dangerous downsides. mckt (pronounced "mckt") is a three time consecutive winner of the Bill Bilano 'Heeey Dude!' award, and a..

Earlier this year the community was shown how to successfully Build your own Predator UAV @ 99.95% Discount - and a recon mission over DC! But now new payloads take the fun/danger to a new level! Come find out how you can not only easily warfly and conduct aerial reconnaissance for your next 'mission' but also use your UAV as a roving angel of wireless death, as always from the confines of your couch.. Or Vegas hotel room. The presente....

A barbecue with a built in webserver. Remote command execution via Twitter. Great geek projects, but do we really need them? On the serious side of things, do we really need web-based management interfaces on firewalls, printers, and phone systems? Maybe it's time to take a look at the sometimes-humorous, often-dangerous downsides. mckt (pronounced "mckt") is a three time consecutive winner of the Bill Bilano 'Heeey Dude!' award, and a..

Since 2008 every new car sold in the US requires some type of Tire Pressure Monitoring System be installed. The most popular uses simple unencrypted RF communications to relay the tire pressure information back to the car ECU. This talk goes over the basic history, implementation, and most importantly the unforeseen issues with privacy and subversion of TPM systems Mike Metzger is a technology consultant offering network, security, vir..

If do right, no can defence" -Miyagi Do you check every USB plug on your computer before you log-in? Didn't think so... URFUKED is used to take over the user's keyboard input and quickly execute preprogrammed attacks with the user's privileges. Plug in the USB receiver into the victim's computer. Then attack immediately or if necessary wait for the user to login- then trigger the attack remotely with an RF transmitter. Walk b..

Since 2008 every new car sold in the US requires some type of Tire Pressure Monitoring System be installed. The most popular uses simple unencrypted RF communications to relay the tire pressure information back to the car ECU. This talk goes over the basic history, implementation, and most importantly the unforeseen issues with privacy and subversion of TPM systems Mike Metzger is a technology consultant offering network, security, vir..

If do right, no can defence" -Miyagi Do you check every USB plug on your computer before you log-in? Didn't think so... URFUKED is used to take over the user's keyboard input and quickly execute preprogrammed attacks with the user's privileges. Plug in the USB receiver into the victim's computer. Then attack immediately or if necessary wait for the user to login- then trigger the attack remotely with an RF transmitter. Walk b..

Since 2008 every new car sold in the US requires some type of Tire Pressure Monitoring System be installed. The most popular uses simple unencrypted RF communications to relay the tire pressure information back to the car ECU. This talk goes over the basic history, implementation, and most importantly the unforeseen issues with privacy and subversion of TPM systems Mike Metzger is a technology consultant offering network, security, vir..

If do right, no can defence" -Miyagi Do you check every USB plug on your computer before you log-in? Didn't think so... URFUKED is used to take over the user's keyboard input and quickly execute preprogrammed attacks with the user's privileges. Plug in the USB receiver into the victim's computer. Then attack immediately or if necessary wait for the user to login- then trigger the attack remotely with an RF transmitter. Walk b..

A lot has changed since discussions around digital privacy began. The security community won the war for strong cryptography, anonymous darknets have been successfully deployed, and much of the communications infrastructure has been decentralized. These strategies were carefully conceived while planning for the most dystopian visions of the future imaginable, and yet somehow they've fallen short of delivering us from the most pernicious pri....

A lot has changed since discussions around digital privacy began. The security community won the war for strong cryptography, anonymous darknets have been successfully deployed, and much of the communications infrastructure has been decentralized. These strategies were carefully conceived while planning for the most dystopian visions of the future imaginable, and yet somehow they've fallen short of delivering us from the most pernicious pri....

A lot has changed since discussions around digital privacy began. The security community won the war for strong cryptography, anonymous darknets have been successfully deployed, and much of the communications infrastructure has been decentralized. These strategies were carefully conceived while planning for the most dystopian visions of the future imaginable, and yet somehow they've fallen short of delivering us from the most pernicious pri....

It seems that everything is a web application nowadays. Whether the application is cloud-based, mobile, or even fat client they all seem to be using web protocols to communicate. Adding to the traditional landscape there is rise in the use of application programming interfaces, integration hooks, and next generation web technologies. What this means for someone testing web applications is that flexibility is the key to success. The Python p....

Operating System fingerprinting (OSF) is important to help on deciding security policy enforced on protected Virtual Machine (VM). Unfortunately, current OSF techniques suffer many problems, such as: they fail badly against modern Operating Systems (OS), they are slow, and only support limited OS-es and hypervisors. This paper analyzes the drawbacks of current OSF approaches against VM in the cloud, then introduces a novel method, name....

130 visitors online