Site uses cookies to provide basic functionality.
Javascript rendering is set to off by default when visiting the site via .onion and .i2p domains. It can be enabled back again in user's settings section. Javascript rendering set to off means, that you can disable javascript in your browser now and the site will remain functional.
There is also IRC server now available via native IRC clients or non javascript web based one.
Fonts can be adjusted in user's settings section as well.
Check FAQ for more.

OK

Abstract: This paper outlines a Distributed Denial of Service (DDoS) attack which abuses open recursive Domain Name System (DNS) name servers using spoofed UDP packets. Our study is based on packet captures and logs from attacks reported to have a volume of 2.8Gbps. We study this data in order to further understand the basics of the reported recursive name server amplification attacks which are also known as DNS amplification or DNS reflec....

Abstract: When trying to analyze a complex system for its security properties, very little information is available in the beginning. If the complex system in question contains parts that the analyst cannot see or touch, proprietary hardware and software as well as large scale server software, the task doesn't get any easier. The talk will tell the story about how Phenoelit went about looking at RIM's BlackBerry messaging solution while fo....

Abstract: Despite many appearances in film and television, fairly little is widely known about how safes can be opened without the proper combination or key. This talk will attempt to address some of the questions commonly asked about the craft, such as -- is it really possible to have a safe open in a minute or two using just a stethoscope and some clever finger-work? (Yes, but it will take a bit more time than a few minutes.) Are the gadg....

Abstract: DNS operations today are no longer just a secure configuration and bandwidth, but rather a whole world of online abuse and criminal activities. In this presentation we will discuss how DNS has become this infrastructure for online crime and abuse. Spam, DDoS attacks, botnets and extremely reliable phishing servers all owe their existence to DNS games Further, we will discuss how DNS helps discover and combat malicious activities..

Abstract: The wrtp54g/rtp300 is a linksys VOIP Proxy router with one primary distinguishing characteristic that separates it from all other VOIP Routers on the market today: It's based on linux. This fact alone makes this router the key to learning the inner workings of VOIP and opens up a world of possibilities when it comes to its de-obfuscation. After all, 3rd party firmware on its parent router, of which it is a descendant of the wrt5....

Abstract: Hacking stuff is for the birds. I'm taking a new path in life. I've decided to become a technical consultant for Hollywood. (No, not really, but work with me here). In my new role, I've decided it's time to take up the torch for all my fellow consultants who have been abused by you people through the years. We're all just sick and tired of your snide little comments about hackers in the movies. So go ahead. Make fun of Hollywood.....

Abstract: Research in Motion's Blackberry technology has quickly become the defacto standard for executives and technical personnel alike to maintain unteathered remote access to critical data. Often regarded as inherently secure, most administrators deploy this solution without a full understanding of the technology or risks involved. This presentation will demonstrate how an attacker could utilize many typical corporate blackberry deploy....

Abstract: Binary disassembling and manual analysis to find exploitable vulnerabilities is a cool topic. What's cooler? Saving yourself hours of time and brain rot by letting a program do the hard parts for you! In this talk, we will dissect a well-known exploitable vulnerability as well as an open source tool for automatically detecting that vulnerability. By the end of the talk, you will understand the basics of static code analysis, expl....

Abstract: In 2006 the Help America Vote Act (HAVA) rid the country of lever voting machines and punchcard ballots, and gave the states enormous budgets for buying electronic voting machines. What's still unresolved is how these electronic voting machines are going to be audited. Trying to keep track of many different vendors, each of which has many different machines, is like getting lost in a funhouse hall of mirrors. Yet, there is good n....

Abstract: Detecting global abuse patterns with realtime black lists, spamtraps and honey pots. Understanding what your network is doing to the rest of the community is difficult, we discuss how to use our tools to understand how your network is abusing other networks and show graphs and stats of trends globably and within the us. Bio: Rick Wesson has worked in the IETF and ICANN on DNS, whois, and Registry and Registrar protocols; Served..

Abstract: Learn to Spy on Corporate Network Traffic. After attending this talk, you will learn how to perform targeted packet sniffing to capture web, e-mail, chat conversations, VoIP, and file transfer traffic. Many tools are covered, including Effetech, MSN Protocol Analyzer, Ethereal filters, URLSnarf, FileSnarf, ACE, Cain and Abel, and others. Bio: Andrew Whitaker is the Director of Enterprise Security for InfoSec Academy, a global ....

Abstract: We all want to be awesome hackers, but let's face it: inventing the sploitz can be hard work. What if there were a way to make interesting security discoveries using relatively simple tools, recycled concepts from research in other fields, and readily available data? For better or worse, this is the kind of question that we at foofus.net ask ourselves on a regular basis. And it's in that spirit that we present this fine talk. We....

Abstract: If you want to know how the National Security Agency and telecommunications companies are conspiring to invade your privacy, this is the panel for you. The Electronic Frontier Foundation (EFF) is currently suing AT&T for collaborating with the NSA in its massive and illegal program to wiretap and data-mine Americans' phone and internet communications. Come learn about the legal and technical issues surrounding the NSA surveillance....

Abstract: " During this presentation SensePost will discuss and demonstrate two pieces of new technology?the Suru WebProxy and the SP_LR Generic network proxy. The Suru web proxy is an inline web proxy (the likes of Paros, @stake webproxy and Webscarab) and offers the analyst unparalleled functionality. Are the days of the web proxy counted? Is there really room for another web proxy? Come to their presentation and see what happened when t....

Abstract: This talk looks at the technical and psychological backgrounds behind why phishing works, and how this can be exploited to make phishing attacks more effective. To date, apart from the occasional use of psychology grads by 419 scammers, no-one has really looked at the wetware mechanisms that make phishing successful. Security technology doesn't help here, with poorly-designed user interfaces playing right into the phishers hands.....

Abstract: An Anonymous identity is difficult but not impossible to obtain. With help of international laws and loopholes a new identity can be created. This talk will demonstrate how this can be done with never before published methods. There are many reasons why a person might choose to obscure their identity and become anonymous. Several of these reasons are legal and legitimate - someone, for example, who feels threatened by someone e....

Abstract: This presentation will focus on disabling many of the windows based network security solutions that are most widely used. New payloads will be presented that demonstrate how host based firewalls at this time are not adequate defense to safeguard one's network resources. The speech is highly technical and requires knowledge of reverse engineering and process injection. Bio: Lin0xx has been a code and security enthusiast for a nu..

Abstract: Reverse engineers often like to argue that a prime motivator for their activities is the desire to discover and patch vulnerabilities in closed-source binary software. Given the veritable plethora.. nay, Katrina-like flood of vulnerabilities being discovered on a near daily basis, one has to wonder where all these binary patches are hiding. Clearly this argument is a sham to make reverse engineers feel better about their DMCA vio....

Abstract: The Census Bureau is the Only Federal Agency that is acquiring detailed personal data on Every person in the United States. While the Census provides valuable information that is vital to our form of government, major privacy concerns exists. The potential for abuse of the data has historical roots, the most notorious being the rounding up and relocation of Japanese-Americans during World War II. Learn how the Social, Economic, ....

Abstract: The web of trust, as used in PGP, is a well-known system for establishing trust between people, even if the people have not previously met. Why does it work so well in crypto? The answer is simple: it's the same system that we all use on a daily basis when dealing with friends, family, relationships, andjust about everyone else we have to interact with. On the crypto side, however, there are a number of restrictions that limit the....

We describe requirements for a malware collection repository. The repository serves as a clearing house for malware samples, as well as analysis provided by members of the clearing house. We discuss how malware authors are aware of, and actively exploit inherent inefficiencies in the current generation of competitive, closed malware collections. We demonstrate how, by illuminating AV sensors, and by using frequent updates, malware authors ....

Abstract: This session will reveal to you how the FBI uses Neuro-Linguistic Programming (NLP) during interview and interrogation sessions. Gaining cooperation with special speech and word changes, Clues to help determine whether clients are lying or remembering and the traditional "Cop Stop technique" will all be revealed and practiced by attendees. Seldom taught outside the law or medical community, you'll be instructed in and actual prac....

Mosquito is a secure remote execution framework available via LGPL that combines high-grade cryptography and a small efficient virtual machine on both ends to ensure that intellectual property is protected. It also presents a dynamic environment on a target host that can be reprogrammed on the fly over a secure communications channel to fit the current situation.'-" The virtual machine was written from scratch for this purpose, with a buil....

Snort has become a standard component of many IT security environments. Snort is mature and widely deployed, and is no longer viewed as new or exciting by the industry. However, with such widespread deployment, enhancing Snort's capabilities offers the potential for a large and immediate impact. Instead of chasing the industry's new-hotness of the day, it frequently makes more sense to add new capabilities to an existing security control. ....

A major drawback with the use of most reverse engineering tools is that they were not designed with collaboration in mind. Numerous kludgy solutions exist from asynchronous use of the same data files to working on multiple copies of data files which quickly diverge leaving the differences to somehow be reconciled. Pedram Amini's Ida Sync provided a first step towards automated collaboration among Ida users however Ida Sync suffers from seve....

OpenVMS is considered a highly secure and reliable operating system relied upon by large enterprises around the globe such as Stock Exchanges, Governments and Infrastructure for critical operations. Our talk will focus on subverting the security of the OpenVMS operating system in a number of new and creative ways. There will be an initial brief introduction to the OS basics, security model and its core features. We will also talk about thin....

This presentation is intended for individuals with an understanding of the Intel 8051 and Motorola 6805 processor families from an Assembly language perspective. This will be an interactive presentation with the audience. Log files will be examined that have been taken from the targets (smartcards) at every clock cycle of the CPU during its runtime. We will discuss our possibilities and determine points in time (clock cycle periods)....

This talk discusses privacy issues concerning Adobe Flash Local Shared Objects. Adobe LSOs are similar to HTTP cookies, but not as easily controlled or configured using a standard web browser. Potential problems with Flash LSOs will be presented, as well as suggestions for increasing privacy while using Adobe LSOs. Clinton Wong published HTTP Pocket Reference and Web Client Programming with Perl. He works in Silicon Valley.

It's past time for a session layer. It's time to replace port knocking with a real authentication framework. It's time to do what DNS did with IP addresses to port numbers. It's time to run services over NATs, eliminate the need for vhosts in your webserver and provide optional transparent encryption for any client who wants it. In this talk, we'll do that and a couple other tricks... within the framework of a little-known RFC that was writ....

DNS is at the heart of every network -- when a web site is browsed to, it says where the site is, and when an email is sent, DNS says where to. The answer is usually correct -- but not always. Six months ago, it became clear that there was an ancient design flaw, present in the original 1983 specification for DNS, that would allow any attacker to insert their own addresses for DNS names. An industry wide bug hunt commenced, culminating in a..

While commercial web application scanners have been available for quite a while, the selection of open source tools has been limited. Grendel-Scan is a new tool that aims to provide in-depth application assessment. Written entirely in Java and featuring an easy to use GUI, the tool is intended to be useful to a wide variety of technical backgrounds: from IT security managers, to experienced penetration testers. Grendel-Scan can test fo....

Security is getting better; there is no doubt about that. High value targets are increasing their security while buying into the buzzword hype with phrases like "defense in depth". Firewalls, IPS, AV, NAC, and a host of other technologies have done a lot to give the pointy hair bosses of the world the ability to sleep easy...or has it. While those PHB sleep easy in their bed the ability to compromise a site at will continues to grow. R....


This presentation will detail the newest developments in RE:Trace, a reverse engineering framework based on Ruby and DTrace. We will discuss implementations for walking and searching the heap on OS X, tracing for kernel and driver vulnerabilities, pinpointing format string bugs and leveraging custom application probes, such as those built into browser and database software. David Weston is security researcher and penetration tester at ....

Stories about the loss of sensitive data are becoming more common, and an untold number of others probably are not known because they were not covered by law or did not get the attention of regulators. A loss may happen when data is stolen or simply lost, or when a system is breached. Existing federal and state laws cover specific industries and prescribe particular responses, but pending legislative proposals threaten to expand coverage si....

Security-related laws and regulations, with parallel privacy measures, are assuming an ever-expanding role in American society. As a result, the likelihood that an organization will receive a call, visit, subpoena, or letter from a law enforcement agency is constantly increasing. This program will address issues related to addressing these contacts. It will explore relevant legal questions but also the real world processes and consideration....

Come learn how identification cards have taken over our lives, how they can be manufactured at home, and how you can start a legal ID making business. Come learn all the tips and tricks about amateur id manufacturing and pickup the first ever Complete Amateur ID Making Guide. Also, come test your ability to spot a fake, vs. a real, and check out the newest in ID technology. Polycarbonate laminates, biometrics, Teslin, and RFID. Lastly, see ..

Your stack is smash-proof. Your dumpster is fully alarmed. And your firewall is so secure that it has former Soviet officials green with envy. So why are the developers finding their undocumented features in competitors' products, or company executives on a constant hunt for leaks and traitors? There's a whole lot more to doing an end-run around network security than calling up and pretending to be the help desk or hoping someone chucks a s..

In less than an hour, during a scheduled pentest, our team was able to retrieve 3.2 million patient insurance records from a HIPAA-compliant medical facility. Using these records, we could have generated counterfeit insurance and prescription cards which would pass muster at any doctor's office or pharmacy counter. If you are one of the 47 million Americans with no health insurance or happen to have a medical condition you wished to hide fr....

How fast a port-scan can be is largely dependent on the performance of the network in question. Nonetheless, it is clear that choosing the most efficient scanning-speed is only possible based on sufficient information on the network's performance. We have thus designed and implemented a port-scanning method which provokes extra network-activity to increase the amount of information at our disposal in an attempt to gain speed on the long run....

Thanks to Web 2.0 and other over hyped BS, development has been moving farther and farther away from bare metal. Assuming you trust your libraries, this could even be called a good thing. If you're high." PC gaming, despite Microsoft's best efforts, is not dead. Yet. The modding community is alive and active, and even those same over hyped web technologies are starting to encroach in to shaders, and other things they shouldn't touch....

Recent developments such as the FBI operation "Cisco Raider" that resulted in the discovery of 3,500 counterfeit Cisco network components show the growing concern of U.S. government about an electronic hardware equivalent of a "Trojan horse". In an electronic Trojan attack, extra circuitry is illicitly added to hardware during its manufacture. When triggered, the hardware Trojan performs an illicit action such as leaking secret information,....

The talk focuses on 1D and 2D barcode applications with interference possibilities for the ordinary citizen. Ever wondered what is in these blocks of squares on postal packages, letters and tickets? Playing with them might have interesting effects, reaching from good old fun to theft and severe impact. Barcodes have been around for ages, but most of the time were used as simple tags with a number. The rise of 2D barcodes started to put....

Attacks on network infrastructure are not a new field. However, the increasing default protections in common operating systems, platforms and development environments increase interest in the less protected infrastructure sector. Today, performing in-depth crash analysis or digital forensics is almost impossible on the most widely used routing platform. This talk will show new developments in this sector and how a slightly adjusted net....

4 visitors online