Site uses cookies to provide basic functionality.
Javascript rendering is set to off by default when visiting the site via .onion and .i2p domains. It can be enabled back again in user's settings section. Javascript rendering set to off means, that you can disable javascript in your browser now and the site will remain functional.
There is also IRC server now available via native IRC clients or non javascript web based one.
Fonts can be adjusted in user's settings section as well.
Check FAQ for more.

OK

It seems that everything is a web application nowadays. Whether the application is cloud-based, mobile, or even fat client they all seem to be using web protocols to communicate. Adding to the traditional landscape there is rise in the use of application programming interfaces, integration hooks, and next generation web technologies. What this means for someone testing web applications is that flexibility is the key to success. The Python p....

Operating System fingerprinting (OSF) is important to help on deciding security policy enforced on protected Virtual Machine (VM). Unfortunately, current OSF techniques suffer many problems, such as: they fail badly against modern Operating Systems (OS), they are slow, and only support limited OS-es and hypervisors. This paper analyzes the drawbacks of current OSF approaches against VM in the cloud, then introduces a novel method, name....

It seems that everything is a web application nowadays. Whether the application is cloud-based, mobile, or even fat client they all seem to be using web protocols to communicate. Adding to the traditional landscape there is rise in the use of application programming interfaces, integration hooks, and next generation web technologies. What this means for someone testing web applications is that flexibility is the key to success. The Python p....

Operating System fingerprinting (OSF) is important to help on deciding security policy enforced on protected Virtual Machine (VM). Unfortunately, current OSF techniques suffer many problems, such as: they fail badly against modern Operating Systems (OS), they are slow, and only support limited OS-es and hypervisors. This paper analyzes the drawbacks of current OSF approaches against VM in the cloud, then introduces a novel method, name....

Android is a software stack for mobile devices that includes an operating system, middleware and key applications and uses a modified version of the Linux kernel. 60,000 cell phones with Android are shipping every day. Android platform ranks as the fourth most popular smartphone device-platform in the United States as of February 2010. To date, very little has been discussed regarding rootkits on mobile devices. Android forms a perfect....

Android is a software stack for mobile devices that includes an operating system, middleware and key applications and uses a modified version of the Linux kernel. 60,000 cell phones with Android are shipping every day. Android platform ranks as the fourth most popular smartphone device-platform in the United States as of February 2010. To date, very little has been discussed regarding rootkits on mobile devices. Android forms a perfect....

Android is a software stack for mobile devices that includes an operating system, middleware and key applications and uses a modified version of the Linux kernel. 60,000 cell phones with Android are shipping every day. Android platform ranks as the fourth most popular smartphone device-platform in the United States as of February 2010. To date, very little has been discussed regarding rootkits on mobile devices. Android forms a perfect....

We had a busy year. We investigated over 200 incidents in 24 different countries. We ended up collecting enough malware freaks [samples] to fill up Kunstkammer a few times over. Building upon last year's talk, we want to dive deeper and bring you the most interesting samples from around the world - including one that made international headlines and the rest we're positive no one's ever seen before (outside of us and the kids who wrote them....

Can the NSA really do that? Um, yes. Join us at the movies to take a close look at how government surveillance has caught up with the fables dreamed up for Hollywood flicks- from old favorites like Brazil to newer additions like Bourne and Dark Knight. Jaunty tin foil hats and popcorn will be provided! Nicole Ozer directs the Technology and Civil Liberties Program at the ACLU of Northern California and spearheads the organization's new....

We had a busy year. We investigated over 200 incidents in 24 different countries. We ended up collecting enough malware freaks [samples] to fill up Kunstkammer a few times over. Building upon last year's talk, we want to dive deeper and bring you the most interesting samples from around the world - including one that made international headlines and the rest we're positive no one's ever seen before (outside of us and the kids who wrote them....

Can the NSA really do that? Um, yes. Join us at the movies to take a close look at how government surveillance has caught up with the fables dreamed up for Hollywood flicks- from old favorites like Brazil to newer additions like Bourne and Dark Knight. Jaunty tin foil hats and popcorn will be provided! Nicole Ozer directs the Technology and Civil Liberties Program at the ACLU of Northern California and spearheads the organization's new....

We had a busy year. We investigated over 200 incidents in 24 different countries. We ended up collecting enough malware freaks [samples] to fill up Kunstkammer a few times over. Building upon last year's talk, we want to dive deeper and bring you the most interesting samples from around the world - including one that made international headlines and the rest we're positive no one's ever seen before (outside of us and the kids who wrote them....

Can the NSA really do that? Um, yes. Join us at the movies to take a close look at how government surveillance has caught up with the fables dreamed up for Hollywood flicks- from old favorites like Brazil to newer additions like Bourne and Dark Knight. Jaunty tin foil hats and popcorn will be provided! Nicole Ozer directs the Technology and Civil Liberties Program at the ACLU of Northern California and spearheads the organization's new....

In this talk we present how to reverse-engineering Canon Powershot digital cameras and take control of most of them to exploit interesting security threats. We present a novel attack method that allows taking control of a digital camera through a compromised memory card. This is a realistic attack scenario, as using the card in unsecured PCs is a common practice among many users. This attack vector leaves users of digital cameras vulnerable....

In this talk we present how to reverse-engineering Canon Powershot digital cameras and take control of most of them to exploit interesting security threats. We present a novel attack method that allows taking control of a digital camera through a compromised memory card. This is a realistic attack scenario, as using the card in unsecured PCs is a common practice among many users. This attack vector leaves users of digital cameras vulnerable....

In this talk we present how to reverse-engineering Canon Powershot digital cameras and take control of most of them to exploit interesting security threats. We present a novel attack method that allows taking control of a digital camera through a compromised memory card. This is a realistic attack scenario, as using the card in unsecured PCs is a common practice among many users. This attack vector leaves users of digital cameras vulnerable....

They say third time is the charm. Some of the biggest mouths in Information Security are back again and once again, we will show you all new of security FAIL. Our panelists will demonstrate innovative hacking techniques in naked routing, web application (in)security, and wireless goats. After taking a sabatical year, we are also proud to announce that Chris "Squirrel" Hoff will be keeping the rest of us honest with his real-time snarkage. S....

The average criminal case today has over a terabyte worth of data to analyze. The cyber forensics field is just beginning to mature. Join federal agents to discuss the forensics field now and in the future. Jim Christy DC3 Mike Convertino AF Jerry Dixon Ex-DHS John Garris NASA Barry Grundy Treasury Bob Hopper NW3C Ken Privette USPS IG Tom Talleur Ex-NASA Trent Teyema FBI

They say third time is the charm. Some of the biggest mouths in Information Security are back again and once again, we will show you all new of security FAIL. Our panelists will demonstrate innovative hacking techniques in naked routing, web application (in)security, and wireless goats. After taking a sabatical year, we are also proud to announce that Chris "Squirrel" Hoff will be keeping the rest of us honest with his real-time snarkage. S....

The average criminal case today has over a terabyte worth of data to analyze. The cyber forensics field is just beginning to mature. Join federal agents to discuss the forensics field now and in the future. Jim Christy DC3 Mike Convertino AF Jerry Dixon Ex-DHS John Garris NASA Barry Grundy Treasury Bob Hopper NW3C Ken Privette USPS IG Tom Talleur Ex-NASA Trent Teyema FBI

They say third time is the charm. Some of the biggest mouths in Information Security are back again and once again, we will show you all new of security FAIL. Our panelists will demonstrate innovative hacking techniques in naked routing, web application (in)security, and wireless goats. After taking a sabatical year, we are also proud to announce that Chris "Squirrel" Hoff will be keeping the rest of us honest with his real-time snarkage. S....

The average criminal case today has over a terabyte worth of data to analyze. The cyber forensics field is just beginning to mature. Join federal agents to discuss the forensics field now and in the future. Jim Christy DC3 Mike Convertino AF Jerry Dixon Ex-DHS John Garris NASA Barry Grundy Treasury Bob Hopper NW3C Ken Privette USPS IG Tom Talleur Ex-NASA Trent Teyema FBI

This panel of federal agents will discuss cyber policy. How do we conduct robust continuous monitoring across a large multi-organizational enterprise yet stay within the constitutional requirements for privacy, civil rights and civil liberties? What changes are needed in the criminal justice system to increase the deterrence of committing cyber-crime? Once a cyber-crime has occurred - and through investigative efforts is determined to be a ..

This panel of federal agents will discuss cyber policy. How do we conduct robust continuous monitoring across a large multi-organizational enterprise yet stay within the constitutional requirements for privacy, civil rights and civil liberties? What changes are needed in the criminal justice system to increase the deterrence of committing cyber-crime? Once a cyber-crime has occurred - and through investigative efforts is determined to be a ..

This panel of federal agents will discuss cyber policy. How do we conduct robust continuous monitoring across a large multi-organizational enterprise yet stay within the constitutional requirements for privacy, civil rights and civil liberties? What changes are needed in the criminal justice system to increase the deterrence of committing cyber-crime? Once a cyber-crime has occurred - and through investigative efforts is determined to be a ..

Over the past 5 years oCTF has grown and evolved. Running the contest has been a lot of work, a lot of fun, and educational for both the contestants as well as for us. This panel talk will go over everything from the inspirations which started it back at the Alexis Park, right through to this year when we passed the torch to The Tube Warriors. DC-949 was founded at some point in 2004, and has slowly amassed members of like minded and p..

This authors' panel has all the makings of a page-turning bestseller: crime lords, heroes, spies, global cartels, corporate scandals, hi-tech gizmos, betrayal, revolution, political intrigue, and midnight assassination attempts. As with all good books, it's the characters – the researchers, the criminals, and the victims – and their unique stories that will keep you riveted to your seat. Jeffrey Carr, (Principal, GreyLogic) is a cyber ....

Over the past 5 years oCTF has grown and evolved. Running the contest has been a lot of work, a lot of fun, and educational for both the contestants as well as for us. This panel talk will go over everything from the inspirations which started it back at the Alexis Park, right through to this year when we passed the torch to The Tube Warriors. DC-949 was founded at some point in 2004, and has slowly amassed members of like minded and p..

This authors' panel has all the makings of a page-turning bestseller: crime lords, heroes, spies, global cartels, corporate scandals, hi-tech gizmos, betrayal, revolution, political intrigue, and midnight assassination attempts. As with all good books, it's the characters – the researchers, the criminals, and the victims – and their unique stories that will keep you riveted to your seat. Jeffrey Carr, (Principal, GreyLogic) is a cyber ....

Over the past 5 years oCTF has grown and evolved. Running the contest has been a lot of work, a lot of fun, and educational for both the contestants as well as for us. This panel talk will go over everything from the inspirations which started it back at the Alexis Park, right through to this year when we passed the torch to The Tube Warriors. DC-949 was founded at some point in 2004, and has slowly amassed members of like minded and p..

This authors' panel has all the makings of a page-turning bestseller: crime lords, heroes, spies, global cartels, corporate scandals, hi-tech gizmos, betrayal, revolution, political intrigue, and midnight assassination attempts. As with all good books, it's the characters – the researchers, the criminals, and the victims – and their unique stories that will keep you riveted to your seat. Jeffrey Carr, (Principal, GreyLogic) is a cyber ....

Past speeches and talks from DEF CON hacking conferences in an iTunes friendly M4b format. The DEF CON series of hacking conferences were started in 1993 to focus on both the technical and social trends in hacking, and has grown to be world known event. Video, audio and supporting materials from past conferences will be posted here, starting with the newest and working our way back to the oldest with new content added as available!


Past speeches and talks from DEF CON hacking conferences in an iTunes friendly M4b format. The DEF CON series of hacking conferences were started in 1993 to focus on both the technical and social trends in hacking, and has grown to be world known event. Video, audio and supporting materials from past conferences will be posted here, starting with the newest and working our way back to the oldest with new content added as available!

The experts on this panel will provide their views on systemic risks facing the DNS and provide thoughts on measures that should be undertaken to remediate the risks. The panelists will discuss both the challenges and the security benefits that will arise from the implementation of DNSSec. Rod Beckstrom is a highly successful entrepreneur, founder and CEO of a publicly-traded company, a best-selling author, avowed environmentalist, pub....

Razorback is the result of extensive research by members of the Sourcefire Vulnerability Research Team into developing a platform to address advanced detection problems. The level of sophistication currently demonstrated both by actors described as the 'Advanced Persistent Threat' (APT) and publicly available exploit frameworks such as Metasploit, CANVAS and Core Impact leave increasingly fewer options to provide robust detection. This proj....

The experts on this panel will provide their views on systemic risks facing the DNS and provide thoughts on measures that should be undertaken to remediate the risks. The panelists will discuss both the challenges and the security benefits that will arise from the implementation of DNSSec. Rod Beckstrom is a highly successful entrepreneur, founder and CEO of a publicly-traded company, a best-selling author, avowed environmentalist, pub....

Razorback is the result of extensive research by members of the Sourcefire Vulnerability Research Team into developing a platform to address advanced detection problems. The level of sophistication currently demonstrated both by actors described as the 'Advanced Persistent Threat' (APT) and publicly available exploit frameworks such as Metasploit, CANVAS and Core Impact leave increasingly fewer options to provide robust detection. This proj....

The experts on this panel will provide their views on systemic risks facing the DNS and provide thoughts on measures that should be undertaken to remediate the risks. The panelists will discuss both the challenges and the security benefits that will arise from the implementation of DNSSec. Rod Beckstrom is a highly successful entrepreneur, founder and CEO of a publicly-traded company, a best-selling author, avowed environmentalist, pub....

Razorback is the result of extensive research by members of the Sourcefire Vulnerability Research Team into developing a platform to address advanced detection problems. The level of sophistication currently demonstrated both by actors described as the 'Advanced Persistent Threat' (APT) and publicly available exploit frameworks such as Metasploit, CANVAS and Core Impact leave increasingly fewer options to provide robust detection. This proj....

Web Application fingerprinting before 2010 has been a hodge-podge of different techniques, usually relying on meta tags or other clues helpfully added by well meaning (but security challenged) developers. Current hardening approaches hamper standard web application fingerprinting, but new static file techniques provide extremely high accuracy and require new hardening approaches. We will discuss implementation details of static file fingerp..

Web Application fingerprinting before 2010 has been a hodge-podge of different techniques, usually relying on meta tags or other clues helpfully added by well meaning (but security challenged) developers. Current hardening approaches hamper standard web application fingerprinting, but new static file techniques provide extremely high accuracy and require new hardening approaches. We will discuss implementation details of static file fingerp..

Web Application fingerprinting before 2010 has been a hodge-podge of different techniques, usually relying on meta tags or other clues helpfully added by well meaning (but security challenged) developers. Current hardening approaches hamper standard web application fingerprinting, but new static file techniques provide extremely high accuracy and require new hardening approaches. We will discuss implementation details of static file fingerp..

Format string attacks remain difficult in both software and hackademic exercises as the techniques have not improved since their discovery. This session demonstrates advanced format string attack techniques designed to automate the process from creation to compromise as well as incorporate those techniques into the Metasploit framework. The audience is encouraged to bring a basic understanding of format string attacks in order to leave the ....

11 visitors online