Site uses cookies to provide basic functionality.
Javascript rendering is set to off by default when visiting the site via .onion and .i2p domains. It can be enabled back again in user's settings section. Javascript rendering set to off means, that you can disable javascript in your browser now and the site will remain functional.
There is also IRC server now available via native IRC clients or non javascript web based one.
Fonts can be adjusted in user's settings section as well.
Check FAQ for more.

OK

Abstract: Security competitions have been of interest to many individuals for a number of years. The popularity of the annual DEFCON competition demonstrates the level of interest in these events. This talk will discuss the creation of the National Collegiate Cyber Defense Competition which was held in April 2006. A brief history covering the development of this competition will be covered as well as a discussion of the event itself. The r....

Abstract: Every hard drive will die a quick and sudden death sooner rather than later. What happens after that death can be very important to your data and become the deciding factor in its survival. We will display the inner workings of a hard drive in a beautiful animation and discuss the successes and failures in rebuilding a hard drive. We will teach you what to look for and how to accomplish this task on your own. We will delve into t....

Abstract: It's been a year since Major Mal gave his talk on hotel IR systems, and things haven't got any better...In fact, they've got worse. No, wait a minute...that's not right...They've *stayed* worse!! Having plumbed the depths of the IR in his room, and finding himself with little else to do, Major turned his attention to another piece of technology easily to hand: his magstripe room key...Now these have been around since Mary checked....

Abstract: DEFCON began in 1993 as an "orgy of information exchange, viewpoints, speeches, education, enlightenment...and most of all sheer, unchecked PARTYING."(DEFCON 1 Announcement, 1993). Fourteen years later, the convention is one of the most established hacker conventions, and is defined as "the largest underground hacking convention in the world."However, significant social and technological changes have occurred during this period. ....

Abstract: In this day and age, forensics evidence lurks everywhere. The task presented to modern forensics investigators is a daunting one. During this talk, you'll slip into the shoes of an uber-agent hot on the trail of the illustrious Knuth from the Stealing the Network series. Haven't read the latest installation? You should. How would YOU catch a guy that MELTED his hard drive platters and sanded down all his CDs? Where's the evidence....

ExpressPay is a stored-value cash card system which utilizes the Infineon SLE4442 chip; it was developed by enTrac Technologies of Toronto, Ontario, and its largest application is as the pre-paid cash card system in use at FedEx Kinko's. Analysis of a few dozen cards reveals that the data stored on the card is unencrypted and poorly protected against fraud, and a simple attack can be used to obtain the security code necessary to alter the d..

Abstract: This presentation looks at computer network defense and the legal cases of the last year that affect internet and computer security. This presentation clearly and simply explains (in non-legal terms) the legal foundations available to users and service providers to defend their networks. Quickly tracing the legal origins from early property common-law doctrine into today?s statutes and then moving into recent court cases and ba....

Abstract: Jack Grove tries to stop his racing heart as he slips into a dark dingy alley. His paranoia is getting the best of him as he looks behind him. No one is following him, but he senses they are coming. He is afraid. The hack hadn't gone down as planned. Damn it, he was supposed to have taken everything into account, he got sloppy. He knew his only saving grace was no one would be able to recover his laptop. Not after what he did to i....

Abstract: Get the latest information about how the law is racing to catch up with technological change from staffers at the Electronic Frontier Foundation, the nation?s premiere digital civil liberties group fighting for freedom and privacy in the computer age. This session will include updates on current EFF issues such as NSA wiretapping, cellphone tracking by the government, bloggers? rights and online journalism, the Sony rootkit scanda....

Abstract: In 2004, the Department of Homeland Security began the deployment of US-VISIT?a system for tracking visitors to the United States. Since that time, the capabilities of US-VISIT have increased dramatically; US-VISIT now incorporates a number of controversial technologies which violate the privacy, anonymity, and overall security of visitors to the USA in significant ways. In this talk, the technology and capabilities of US-VISIT ....

Abstract: Security analysis is severely complicated by the size and abundance of executable code. Existing concepts and code can be combined, obfuscated, packed, and hidden toward the ends of evading detection and frustrating analysis. Is that patch fixing the problem it claims to fix? Have you seen that malicious code before? Have you seen these particular motifs/style before? All very interesting questions, some of which can be addresse....

Phishing, it starts with 'Ph' for a reason. Some best practices to detect and prevent for some new point of attack methods. When banks and other financial institutions tell their customers to only give personal information (e.g.: Credit Card, Social Security Number, ETC) via the telephone, because of online attacks from phishers, that's when phishers get creative and go back to what the root of phishing has been and blend it with some new ..

Abstract: In 2002 the President issued an Executive Order authorizing the National Security Agency (NSA) to wiretap phone and email communications involving United States persons within the U.S., without obtaining a warrant or court order pursuant to the Foreign Intelligence Surveillance Act of 1978 (FISA), which prohibits such unauthorized electronic surveillance. Investigate the technology timeline regarding this Contentious activity. Th....

Abstract: It's hard to prosecute someone if you can't prove what they did. In this session, we will quickly cover 10 easy ways to cover your tracks using Mac OS X. The features of Mac OS X at the GUI level were in a lot of ways designed to cater to the paranoid (eg. Steve Jobs). Underneath the hood, using some easily scriptable techniques you can cover your tracks in such a way that will make it easy to hide what you?ve done as well as your....

Abstract: Radio Frequency Identification (RFID) tags are remotely-powered data carriers that augment physical objects with wireless computing abilities. This allows us to create smart homes and offices, optimize our supply chains, and keep a watchful eye on our pets, livestock, and kids. But unfortunately, RFID security and privacy issues have been addressed as an afterthought; it is regretfully easy to interfere with RFID systems, as many....

Abstract: The OODA Loop theory was conceived by Col John Boyd, AF fighter pilot. He believed that a pilot in a lethal engagement that could Observe, Orient, Decide, and Act (OODA) before his adversary had a better chance to survive. He considered air combat an art rather than a science. John Boyd proved air combat could be codified; for every maneuver there is a series of counter maneuvers and there is a counter to every counter. Today, suc....

Abstract: The Mac OS X operating system is beautiful, but it?s not as secure as you think. It?s mostly Unix under that shiny GUI and while we?ve come to expect a very locked down system from recent Unix/Linux releases, that expectation isn?t entirely realistic when it comes to OS X. For instance, the firewall GUI tool makes it seem like you can create a default-deny firewall that only lets packets from established sessions in. The firewall ....

Abstract: This talk provides an overview of new RFID Technologie used for Dual-Interfaces Cards (Credit cards, Ticketing and Passports), and RFID Tags with encryption and security features. Problems and attacks to these security features are discussed and attacks to these features are presented. After dealing with the tags an overview to the rest of a RFID-implementation, middelware and backend database and the results of special attacks ..

Abstract: The ability to both conceal and detect hidden data on the hard drive of a compromised computer represents an important arms-race between hackers and forensic analysts. While rootkits and other kernel manipulation tools make hiding on live systems fairly easy, the trick of hiding data from forensic tools and offline drive analysis is much more difficult. In this presentation, we will review traditional data hiding techniques, exam....

Abstract: Apple claims not to care about the enterprise market, but there is no doubt that Apple networks are growing. The number of Apple systems in enterprise networks are growing as well. For security purposes it is becoming more and more important to manage these systems in the same way that we manage Windows clients. In this session we will cover the tools that Apple and some 3rd party organizations have been quietly building for use....

Abstract: In the age of NSA phone taps, mandatory data retention, CALEA, the PATRIOT Act, and national firewalls, establishing a truly covert communications channel without leaving a trail is becoming almost impossible. Even when strong encryption is used to protect the message, Government agencies now have the ability to use pattern analysis to pinpoint almost all participants in the conversation. Without tremendous diligence, truly anony....

Abstract: Event and Log Analysis is becoming one of the main tools for security analysts to investigate and comprehend the state of their networks, hosts, and applications. Recent developments, such as regulatory compliance requirements and an increased focus on insider threat has increased the demand for analytical tools to help in the process. Event correlation is one of the tools that helps addressing the challenges. However, the vast a....

Abstract: Governments around the world are investing serious time, effort, and money into the next gen Internet, based on IP version 6. With important mandatory and remarkably close deadlines looming for v6 deployment, much yet remains to be understood about its security and socio-economic implications as well as our readiness to fully embrace it. While Europe and Asia have been trailblazing IPv6 industry for years now, the U.S. Government....

Abstract: tommEE pickles (http://tommEE.net) presents an explanation of 802.1x networking. Exploring what 802.1x is and why we would use it. He explains how 802.1x might be used in a corporate environment, wireless or wired. Giving an explanation on how you can start 802.1x network and get your users on it. Hardware and Software resources will be discussed and recommendations for free ways of accomplishing it will be presented. He will tal..

Abstract: In 2006 thousands of people will create applications based on the free Oracle 10g Express Edition. Even if this version of Oracle (based on Oracle 10g Rel. 2) is the most secure database from Oracle out of the box so far, there is still room for improvements. This presentation shows different possibilities to attack Oracle 10g Express Edition (and Oracle 10g Rel. 1 and Rel. 2). With Oracle 10g Oracle introduced some new securit....

This topic will present a new web-app/DB pen-test tool. This tool supports both proxy (passive) mode as well as direct URL targeting. It is a mixed Web App SQL Injection systematic pen-test and WebApp/Database scanner/auditing-style tool and supports most popular databases used by web applications such as Oracle, SQL Server, Access and DB2. It has many unique features from web app backend Database automatic detection to the ability to brows....

Abstract: Zulu is a light weight 802.11 wireless frame generation tool to enable fast and easy debugging and probing of 802.11 networks. It has an intuitive command line interface and operates with the unmodified madwifi-ng and partially with prism based Linux network drivers. Individual fields in frames can be set or unset, generating frames that possibly violate the IEEE 802.11 protocol. It can generate all control, data, and management ....

Abstract: The known topics for this year include: 1. The Worldwide SSL Analysis?There's a major flaw in the way many, many SSL devices operate. I'll discuss how widespread this flaw is, as well as announce results from this worldwide SSL scan. 2. Syntax Highlighting...on Hexdumps. Reverse Engineering efforts often require looking at hex dumps?without much context for whats being looked at. I will discuss a "bridge" position between AI an..

Abstract: The Evolving Art of Fuzzing will be a technical talk detailing the current state of fuzzing and describing cutting edge techniques. Fuzzer types, metrics, and future research will be presented. Also, three of ASI's private fuzzer tools will be discussed. They will be released on the DEFCON CD. Bio: Jared DeMott Jared DeMott is a vulnerability researcher for Applied Security, Inc. (ASI). Jared earned a masters degree from Johns ..

Abstract: From the 1337 hax0rs that brought you Anonym.OS, kaos.theory/security.research presents SAMAEL (Secure, Anonymous, Megalomaniacal, Autonomous, Encrypting Linux), the natural evolution of our secure, automagicically anonymizing operating system, Anonym.OS into a kick-ass anonymizing server! When kaos.theory released the Anonym.OS at ShmooCon in January of this year, we received many requests for features we had already planned to....

Today, as more punch gets packed into 1u than ever, server resources can be further consolidated and abstracted to securely separate complex and sophisticated services in the same hardware server, by running secure virtual UNIX machines. Who wants jails? System Administrators who need to securely separate small yet important services. Software Developers who always need more dev machines to hack amok. Root-Kit Testing and Debugging. Ed....

Abstract: Reverse engineering continues to evolve, or rather REvolve. The reverse engineering toolset primarily consists of disconnected disassemblers and debuggers. Without symbol information or data acquired from disassembly, the use of a debugger can be blind and tedious. Reverse engineering has fueled the need to enable these tools to work together. When disassemblers and debuggers are used in conjunction, the resulting union is great....

Abstract: Why would you want to attack IBM Networking? Isn?t it old, unused and unimportant in today?s modern business environments? The answer is why not attack it, after all it is still deployed in lots of high value environments. IBM Networking usually means Mainframes and therefore the potential to get to some cool financial or intelligence data. But what was that I heard you say? You can only route IP across the Internet! Maybe so, b....

Single Packet Authentication is becoming an increasingly important method for protecting arbitrary network services through the use of a kernel level filtering mechanism such as Netfilter in the Linux kernel. By sending SPA packets over the Tor network, SPA packets can be endowed with an additional layer of privacy and anonymity. It becomes cryptographically difficult to deduce the communication of the SPA packet from any particular source ....

Abstract: Metamorphism has been touted as a way to generate undetectable viruses and worms, and it has also been suggested as a potential security-enhancing technique. Today metamorphic virus construction kits are readily available on the Internet. A visit to the VX Heavens reveals more than 150 generators and engines to choose from in the category of "Worm/Virus Creation Tools". The purpose of a metamorphic generator is to create multiple....

Abstract: Mobile Ad-Hoc Networking (MANET) technology promises disaster-tolerant, interoperable, secure communications that work the way we users do. Features like automatic peer discovery and stable multi-transport TCP connections are so attractive that some may wonder if it isn't all too good to be true. After a brief but clear introduction to the more-or-less subtle differences between wireless routing technologies, we will delve direct....

The 802.11 link-layer wireless protocol is widely known for its design flaws. Unauthenticated management packets, a ridiculous attempt at providing link layer confidentiality and authentication (WEP), and general vendor stupidity have all contributed to 802.11 being the most sensationalized protocol ever mentioned in the media. All of the above topics have been beaten to death. Instead this talk explores new advances not in design problems....

Abstract: Reverse Engineering has come a long way?what used to be practiced behind closed doors is now a mainstream occupation practiced throughout the security industry. Compilers and languages are changing, and the reverse engineer has to adapt: Nowadays, understanding C and the target platform assembly language is not sufficient any more. Too many reverse engineers shy away from analyzing C++ code and run into trouble dealing with heavil....

Abstract: The Plausible Deniability Toolkit is a collection of processes and tools designed to protect its users from invasions of privacy and infringement of civil rights by oppresive organizations and governments. The foundation for this toolkit is the result of anti-forensics gap analysis and the need for fabrication of evidence. Certainly most of these techniques have been in use by child pornography rings and various governmental TLA'....

Abstract: Experience from domestic and foreign humanitarian assistance and disaster relief (HADR) operations shows that shared situational awareness and the information systems that support it are the critical enablers of all other functions in such situations. They are not merely technical adjuncts to the delivery of food, water and shelter. Federal Agencies can respond better to disasters (both domestic and international) by sharing uncl....

Abstract: The amount of new malware being developed has increased at a staggering rate over the last couple of years. At the same time, executable packing technology has grown to provide malware authors with a myriad of choices in how they pack their malware to evade detection and analysis. This presents a growing problem to analysts who lack the time to learn how each packer works and can be unpacked, but still need to be able to quickly ....

Abstract: Kiosks are being deployed in an increasing number of locations including supermarkets, banks and airports. Providing public computer access from machines connected to your internal network is one of the most challenging IT problems. Traditionally, an anonymous user with local access to a machine that can talk to the Internet and the internal network is an administrator?s nightmare. Therefore the techniques to secure these machines....

Abstract: Government organizations are required by the Office of Management and Budget to migrate their networks over to IPv6 by 2008. There is a belief that this opens inherit risk to the organization due to undiscovered flaws and security holes that may be opened up. One such breach is the use of covert channels to push data in or out of a network in the guise of standard traffic. Covert channels are not new, and have been exploited i....

Abstract: Although there has been a significant amount of attention paid to the topic of late, there are complexities that must be understood to accurately gauge the impact of "Bumping Locks" on physical security. This talk will explore the vulnerabilities and exposures of virtually all pin-tumbler locks, highlighting the legal issues surrounding the possession and use of bump-keys and bumping implements. Case examples and demonstrations de....

133 visitors online