Site uses cookies to provide basic functionality.
Javascript rendering is set to off by default when visiting the site via .onion and .i2p domains. It can be enabled back again in user's settings section. Javascript rendering set to off means, that you can disable javascript in your browser now and the site will remain functional.
There is also IRC server now available via native IRC clients or non javascript web based one.
Fonts can be adjusted in user's settings section as well.
Check FAQ for more.

OK

EMET 4.0 PKI Mitigation NEIL SIKKA SOFTWARE SECURITY ENGINEER, MICROSOFT Microsoft EMET is a free Mitigation tool. In addition to its memory corruption exploit mitigations, a newly introduced feature is the PKI mitigation. This mitigation implements x509 certificate pinning to prevent usage of forged certificates in HTTPS sessions in the web browser. This talk is technical as it demos EMET in action and explains how the PKI mitigation w....

EMET 4.0 PKI Mitigation NEIL SIKKA SOFTWARE SECURITY ENGINEER, MICROSOFT Microsoft EMET is a free Mitigation tool. In addition to its memory corruption exploit mitigations, a newly introduced feature is the PKI mitigation. This mitigation implements x509 certificate pinning to prevent usage of forged certificates in HTTPS sessions in the web browser. This talk is technical as it demos EMET in action and explains how the PKI mitigation w....

A Password is Not Enough: Why disk encryption is broken and how we might fix it DANIEL SELIFONOV Since the publication of the cold boot attack on software disk encryption 5 years ago, there has been little progress on developing countermeasures and implementing defenses in the disk encryption technologies already in wide use. Furthermore, many users of full disk encryption have physical security habits that fall outside the security mo....

A Password is Not Enough: Why disk encryption is broken and how we might fix it DANIEL SELIFONOV Since the publication of the cold boot attack on software disk encryption 5 years ago, there has been little progress on developing countermeasures and implementing defenses in the disk encryption technologies already in wide use. Furthermore, many users of full disk encryption have physical security habits that fall outside the security mo....

All Your RFz Are Belong to Me - Hacking the Wireless World with Software Defined Radio BALINT SEEBER SPENCH.NET Ever wondered what traffic is flowing through the many satellites in orbit above you? Have you wanted to intercept RADAR signals from air traffic control and visualise your local airspace in real-time on a 3D map? While youíre at it, check how many faults have been reported by the next plane youíll be travelling on (e.g. do th....

All Your RFz Are Belong to Me - Hacking the Wireless World with Software Defined Radio BALINT SEEBER SPENCH.NET Ever wondered what traffic is flowing through the many satellites in orbit above you? Have you wanted to intercept RADAR signals from air traffic control and visualise your local airspace in real-time on a 3D map? While youíre at it, check how many faults have been reported by the next plane youíll be travelling on (e.g. do th....

Making Of The DEF CON Documentary JASON SCOTT DIRECTOR, DEF CON: THE DOCUMENTARY RACHEL LOVINGER PRODUCER, DEF CON: THE DOCUMENTARY Early in 2012, to commemorate the 20th year of the conference, Jason Scott was asked if he would be interested in filming a documentary about DEF CON, whose policies and attendees have traditionally rejected media scrutiny and access. He was interested. Working with his producer, Rachel Lovinger, and a cr....

Making Of The DEF CON Documentary JASON SCOTT DIRECTOR, DEF CON: THE DOCUMENTARY RACHEL LOVINGER PRODUCER, DEF CON: THE DOCUMENTARY Early in 2012, to commemorate the 20th year of the conference, Jason Scott was asked if he would be interested in filming a documentary about DEF CON, whose policies and attendees have traditionally rejected media scrutiny and access. He was interested. Working with his producer, Rachel Lovinger, and a cr....

Examining the Bitsquatting Attack Surface JAESON SCHULTZ THREAT RESEARCH ENGINEER, CISCO SYSTEMS Bit errors in computer memory, when they occur in a stored domain name, can cause Internet traffic to be directed to the wrong Internet location potentially compromising security. When a domain name one bit different from a target domain is registered, this is called "bitsquatting". This presentation builds on previous work in this area pres....

Examining the Bitsquatting Attack Surface JAESON SCHULTZ THREAT RESEARCH ENGINEER, CISCO SYSTEMS Bit errors in computer memory, when they occur in a stored domain name, can cause Internet traffic to be directed to the wrong Internet location potentially compromising security. When a domain name one bit different from a target domain is registered, this is called "bitsquatting". This presentation builds on previous work in this area pres....

How my Botnet Purchased Millions of Dollars in Cars and Defeated the Russian Hackers MICHAEL SCHRENK This is the true story of a botnet that created a competitive advantage for a car dealership. This dealership found a website that offered returned lease vehicles—great cars for their inventory—but bad web design and heavy competition from other automotive dealerships made the website useless. In response, a botnet was developed to make ....

How my Botnet Purchased Millions of Dollars in Cars and Defeated the Russian Hackers MICHAEL SCHRENK This is the true story of a botnet that created a competitive advantage for a car dealership. This dealership found a website that offered returned lease vehicles—great cars for their inventory—but bad web design and heavy competition from other automotive dealerships made the website useless. In response, a botnet was developed to make ....

Safety of the Tor network: a look at network diversity, relay operators, and malicious relays RUNA A. SANDVIK DEVELOPER, THE TOR PROJECT Rumor has it that the Tor network is a CIA honeypot, that all relays are malicious, and that only bad people use Tor to do bad things online. How much of this is true? How much can we say about the safety of the network? The safety of the Tor network has been a much discussed topic ever since the oni....

Safety of the Tor network: a look at network diversity, relay operators, and malicious relays RUNA A. SANDVIK DEVELOPER, THE TOR PROJECT Rumor has it that the Tor network is a CIA honeypot, that all relays are malicious, and that only bad people use Tor to do bad things online. How much of this is true? How much can we say about the safety of the network? The safety of the Tor network has been a much discussed topic ever since the oni....

Building an Android IDS on Network Level JAIME SANCHEZ A3SEC Being popular is not always a good thing and hereís why. As mobile devices grow in popularity, so do the incentives for attackers. Mobile malware and threats are clearly on the rise, as attackers experiment with new business models by targeting mobile phones. Nowadays, several behavior-based malware analysis and detection techniques for mobile threats have been proposed for mo....

Building an Android IDS on Network Level JAIME SANCHEZ A3SEC Being popular is not always a good thing and hereís why. As mobile devices grow in popularity, so do the incentives for attackers. Mobile malware and threats are clearly on the rise, as attackers experiment with new business models by targeting mobile phones. Nowadays, several behavior-based malware analysis and detection techniques for mobile threats have been proposed for mo....

The dawn of Web 3.0: website mapping and vulnerability scanning in 3D, just like you saw in the movies TEAL ROGERS TRINARY SOFTWARE, OWNER ALEJANDRO CACERES OWNER, HYPERION GRAY, LLC Remember that scene in Hackers where Jonny Lee Miller and Angelina Jolie get a bunch of hackers to attack Fisher Steven's network through vulnerabilities that they find while flying (literally) through Fisher's network? Even though it had no basis in real....

Forensic Fails - Shift + Delete won't help you here ERIC ROBI FORENSIC EXAMINER, ELLUMA DISCOVERY MICHAEL PERKLIN CYBER INVESTIGATOR Forensic fails illustrates the rather comedic attempts at "anti-forensics" by inept computer users trying to hide their tracks. We will recount real-life stories about folks whose level of hacker-mojo might aspire to 1337 status but fall a little short. This talk covers why and how these fails happened a....

Forensic Fails - Shift + Delete won't help you here ERIC ROBI FORENSIC EXAMINER, ELLUMA DISCOVERY MICHAEL PERKLIN CYBER INVESTIGATOR Forensic fails illustrates the rather comedic attempts at "anti-forensics" by inept computer users trying to hide their tracks. We will recount real-life stories about folks whose level of hacker-mojo might aspire to 1337 status but fall a little short. This talk covers why and how these fails happened a....

Defense by numbers: Making problems for script kiddies and scanner monkeys CHRIS JOHN RILEY On the surface most common browsers look the same, function the same, and deliver web content to the user in a relatively uniformed fashion. Under the shiny surface however, the way specific user agents handle traffic varies in a number of interesting and unique ways. This variation allows for defenders to play games with attackers and scripted ....

Defense by numbers: Making problems for script kiddies and scanner monkeys CHRIS JOHN RILEY On the surface most common browsers look the same, function the same, and deliver web content to the user in a relatively uniformed fashion. Under the shiny surface however, the way specific user agents handle traffic varies in a number of interesting and unique ways. This variation allows for defenders to play games with attackers and scripted ....

Hacker Law School JIM RENNIE ATTORNEY MARCIA HOFMANN ATTORNEY In the past year, several high-profile prosecutions of hackers have underscored the need for legal education in our community. This workshop will provide you with the fundamentals of Intellectual Property, Crimimal Law, and Criminal Procedure that you need to protect yourself. Learn where the grey areas of law are that increase your risk. This session will also enable you t....

We are Legion: Pentesting with an Army of Low-power Low-cost Devices DR. PHILIP POLSTRA HACKER IN RESIDENCE, UNIVERSITY OF DUBUQUE This talk will show attendees how they can do penetration testing with a network of small, battery-powered, penetration testing systems. The small devices discussed will be running a version of The Deck, a full-featured penetration testing and forensics Linux distro. The Deck runs on the BeagleBoard and Beag....

We are Legion: Pentesting with an Army of Low-power Low-cost Devices DR. PHILIP POLSTRA HACKER IN RESIDENCE, UNIVERSITY OF DUBUQUE This talk will show attendees how they can do penetration testing with a network of small, battery-powered, penetration testing systems. The small devices discussed will be running a version of The Deck, a full-featured penetration testing and forensics Linux distro. The Deck runs on the BeagleBoard and Beag....

Let's screw with nmap GREGORY PICKETT PENETRATION TESTER, HELLFIRE SECURITY Differences in packet headers allow tools like nmap to fingerprint operating systems. My new approach to packet normalization removes these header differences. Starting TTL, TCP Options used, and TCP Option order, after normalization, are the same from one packet to the next no matter which operating system sends it. If we normalized the packets transiting our n....

Let's screw with nmap GREGORY PICKETT PENETRATION TESTER, HELLFIRE SECURITY Differences in packet headers allow tools like nmap to fingerprint operating systems. My new approach to packet normalization removes these header differences. Starting TTL, TCP Options used, and TCP Option order, after normalization, are the same from one packet to the next no matter which operating system sends it. If we normalized the packets transiting our n....

Defending Networks with Incomplete Information: A Machine Learning Approach ALEXANDRE PINTO SECURITY RESEARCHER Let's face it: we may win some battles, but we are losing the war pretty badly. Regardless of the advances in malware and targeted attacks detection technologies, our top security practitioners can only do so much in a 24 hour day. Even less, if you let them eat and sleep. On the other hand, there is a severe shortage of capab....

Defending Networks with Incomplete Information: A Machine Learning Approach ALEXANDRE PINTO SECURITY RESEARCHER Let's face it: we may win some battles, but we are losing the war pretty badly. Regardless of the advances in malware and targeted attacks detection technologies, our top security practitioners can only do so much in a 24 hour day. Even less, if you let them eat and sleep. On the other hand, there is a severe shortage of capab....

Theron Conrey writes about using: BitTorrent Sync as Geo-Replication for Storage We got a chance to talk about this idea at Linuxcon. I'm not entirely convinced there aren't some problem edge cases with this solution, but I think it will be hard to tell as long as the BitTorrent sync library is proprietary. I did come up with a special case of Theron's idea that I believe could work well. The special case uses the optimization that t..

Theron Conrey writes about using: BitTorrent Sync as Geo-Replication for Storage We got a chance to talk about this idea at Linuxcon. I'm not entirely convinced there aren't some problem edge cases with this solution, but I think it will be hard to tell as long as the BitTorrent sync library is proprietary. I did come up with a special case of Theron's idea that I believe could work well. The special case uses the optimization that t..

Slices are used everywhere in my code. If I am working with data from MongoDB, it is stored in a slice. If I need to keep track of a collection of problems after running an operation, it is stored in a slice. If you don’t understand how slices work yet or have been avoiding them like I did when I started, read these two posts to learn more. https://www.ardanlabs.com/blog/2013/08/understanding-slices-in-go-programming.html https..




Hi All, I wrote this a while back for myself and finally got around to polishing it enough to release into the store. It’s a really basic app which will connect to your flurry account and show you new users and number of sessions while your out and about! http://www.windowsphone.com/en-gb/store/app/flurrystats/94d9ad3c-61d2-4ce6-8a61-60b4b8b1fe87

An Ant Hill is a masterpiece of nature. Hidden from the human eye it grows intricate, complex and deep. It’s a beautiful structure crafted by one of the most humble creatures. But in the world of Colosseum’s and Eiffel’s tower it is generally overlooked. How do we define creativity in such a context? Is creativity … Continue reading Creativity: Taj Mahals and Ant-Hills

I’m here in New Orleans hacking up a storm and getting to meet fellow gluster users IRL. John Mark Walker started off with a great “State of the GlusterFS union” style talk. Today Louis (semiosis) gave a great talk about running glusterfs on amazon. It was highly pragmatic and he explained how he chose the number of bricks per host. The talk will be posted online shortly. Marco Ceppi from Canonical gave a talk about juju and glust....

I’m here in New Orleans hacking up a storm and getting to meet fellow gluster users IRL. John Mark Walker started off with a great “State of the GlusterFS union” style talk. Today Louis (semiosis) gave a great talk about running glusterfs on amazon. It was highly pragmatic and he explained how he chose the number of bricks per host. The talk will be posted online shortly. Marco Ceppi from Canonical gave a talk about juju and glust....

Doing Bad Things to 'Good' Security Appliances PHORKUS (MARK CAREY) CHIEF SCIENTIST, PEAK SECURITY EVILROB (ROB BATHURST) THAT GUY The problem with security appliances is verifying that they are as good as the marketing has lead you to believe. You need to spend lots of money to buy a unit, or figure out how to obtain it another way; we chose eBay. We now have a hardened, encrypted, AES 256 tape storage unit and a mission, break it ev....

Doing Bad Things to 'Good' Security Appliances PHORKUS (MARK CAREY) CHIEF SCIENTIST, PEAK SECURITY EVILROB (ROB BATHURST) THAT GUY The problem with security appliances is verifying that they are as good as the marketing has lead you to believe. You need to spend lots of money to buy a unit, or figure out how to obtain it another way; we chose eBay. We now have a hardened, encrypted, AES 256 tape storage unit and a mission, break it ev....

ACL Steganography - Permissions to Hide Your Porn MICHAEL PERKLIN SECURITY RESEARCHER Everyone's heard the claim: Security through obscurity is no security at all. Challenging this claim is the entire field of steganography itself - the art of hiding things in plain sight. Most people know you can hide a text file inside a photograph, or embed a photograph inside an MP3. But how does this work under the hood? What's new in the stego fie....

ACL Steganography - Permissions to Hide Your Porn MICHAEL PERKLIN SECURITY RESEARCHER Everyone's heard the claim: Security through obscurity is no security at all. Challenging this claim is the entire field of steganography itself - the art of hiding things in plain sight. Most people know you can hide a text file inside a photograph, or embed a photograph inside an MP3. But how does this work under the hood? What's new in the stego fie....

Exploiting Music Streaming with JavaScript FRANZ PAYER PROGRAMMER, TACTICAL NETWORK SOLUTIONS As the music industry transitioned from physical to digital distribution, they have forgotten the one thing they hold most dear to them: Their DRM. Many browser-based music streaming services use no DRM to secure their music. By doing this, they leave their library of high quality songs free for the picking. This presentation details the use....

Exploiting Music Streaming with JavaScript FRANZ PAYER PROGRAMMER, TACTICAL NETWORK SOLUTIONS As the music industry transitioned from physical to digital distribution, they have forgotten the one thing they hold most dear to them: Their DRM. Many browser-based music streaming services use no DRM to secure their music. By doing this, they leave their library of high quality songs free for the picking. This presentation details the use....

4 visitors online