Site uses cookies to provide basic functionality.
Javascript rendering is set to off by default when visiting the site via .onion and .i2p domains. It can be enabled back again in user's settings section. Javascript rendering set to off means, that you can disable javascript in your browser now and the site will remain functional.
There is also IRC server now available via native IRC clients or non javascript web based one.
Fonts can be adjusted in user's settings section as well.
Check FAQ for more.

OK

Do you ever find your self wondering if good social engineers and highly influential people are just born that way? Well, you might be surprised to find out that any human skill can be duplicated including being a master at influence. This is what forms the basis for a field of study known as NLP or Neuro-Linguistic-Programming. In this talk I will give an introduction to what NLP is and how it is used and will also provide you with some to..

Do you ever find your self wondering if good social engineers and highly influential people are just born that way? Well, you might be surprised to find out that any human skill can be duplicated including being a master at influence. This is what forms the basis for a field of study known as NLP or Neuro-Linguistic-Programming. In this talk I will give an introduction to what NLP is and how it is used and will also provide you with some to..

As the demand for mobile internet access increases, more and more public wireless access points are becoming available for general usage. Unfortunately, as awareness of these access points increases, some companies have been capitalizing on the idea, charging monthly and hourly rates. This talk discusses methods of silently bypassing current implementations of authenticated wireless networks. An automated proof of concept tool is rele....

As the demand for mobile internet access increases, more and more public wireless access points are becoming available for general usage. Unfortunately, as awareness of these access points increases, some companies have been capitalizing on the idea, charging monthly and hourly rates. This talk discusses methods of silently bypassing current implementations of authenticated wireless networks. An automated proof of concept tool is rele....

Roberto Preatoni (aka Sys64738), Fabio Ghioni The speech will be intended to let the attendees understand where and how the digital conflicts are conducted today but we will dig deeply into the future. We will take as example the US Army program F.C.S. (Future Combat System) as the perfect example on how a developed superpower might carry on a super-advanced war program, all based on combat computer systems and networks that control un....

Roberto Preatoni (aka Sys64738), Fabio Ghioni The speech will be intended to let the attendees understand where and how the digital conflicts are conducted today but we will dig deeply into the future. We will take as example the US Army program F.C.S. (Future Combat System) as the perfect example on how a developed superpower might carry on a super-advanced war program, all based on combat computer systems and networks that control un....

Despite its crucial importance, the network backbone is often ignored or exempted from security testing. This talk will cover how to sanely and effectively perform a pen-test against routers, switches, and similar network infrastructure equipment. Avenues of attack will range from the physical to the routing protocol-based, from the local to the remote, and suggested mitigation measures will also be discussed. Raven splits her time bet..

Despite its crucial importance, the network backbone is often ignored or exempted from security testing. This talk will cover how to sanely and effectively perform a pen-test against routers, switches, and similar network infrastructure equipment. Avenues of attack will range from the physical to the routing protocol-based, from the local to the remote, and suggested mitigation measures will also be discussed. Raven splits her time bet..

Security threats to PDAs and mobiles become more and more serious. This presentation will show a buffer overflow exploitation example in Windows CE. It will cover some knowledge about ARM architecture and memory management, the features of processes and threads of Windows CE. It alse show how to write a shellcode in Windows CE (including some knowledge about decoding shellcode of Windows CE with ARM processor), and a live attack demonstrati..

Security threats to PDAs and mobiles become more and more serious. This presentation will show a buffer overflow exploitation example in Windows CE. It will cover some knowledge about ARM architecture and memory management, the features of processes and threads of Windows CE. It alse show how to write a shellcode in Windows CE (including some knowledge about decoding shellcode of Windows CE with ARM processor), and a live attack demonstrati..

Bruce Potter, Beetle, CowboyM, Dan Moniz, Rodney Thayer, 3ricj, Pablos all speaking on behalf of the Shmoo Group Last Summer, they dared to make a Wi-Fi sniper rifle that fried their eyeballs and scared the crap out of UPS. They built a robot that owned your Mom's access point and showed you the password to her underwear drawer, too. Last Winter, they ran up a $3000 bar tab at a nightclub in D.C. with several hundred ShmooCon attendees....

Bruce Potter, Beetle, CowboyM, Dan Moniz, Rodney Thayer, 3ricj, Pablos all speaking on behalf of the Shmoo Group Last Summer, they dared to make a Wi-Fi sniper rifle that fried their eyeballs and scared the crap out of UPS. They built a robot that owned your Mom's access point and showed you the password to her underwear drawer, too. Last Winter, they ran up a $3000 bar tab at a nightclub in D.C. with several hundred ShmooCon attendees....

Documentaries have a place in telling the history and story of many different cultures and events, but documentaries about technical subjects tend to run into common problems: too light, too wrong, too hated. Is the patient terminal? Can you create a film that is both informative and of interest to a general audience? Having spent 4 years creating a tech documentary of his own on the era of the Dial-up Bulletin Board system, Jason Scot....

Documentaries have a place in telling the history and story of many different cultures and events, but documentaries about technical subjects tend to run into common problems: too light, too wrong, too hated. Is the patient terminal? Can you create a film that is both informative and of interest to a general audience? Having spent 4 years creating a tech documentary of his own on the era of the Dial-up Bulletin Board system, Jason Scot....

How far can automation be taken? How much intelligence can be embodied in code? How generic can automated IT security assessment tools really be? This presentation will attempt to show which areas of attacks lend themselves to automation and which aspects should best be left for manual human inspection and analyses. SensePost will provide the audience a glimpse of BiDiBLAH - an attempt to automate a focussed yet comprehensive assessmen....

How far can automation be taken? How much intelligence can be embodied in code? How generic can automated IT security assessment tools really be? This presentation will attempt to show which areas of attacks lend themselves to automation and which aspects should best be left for manual human inspection and analyses. SensePost will provide the audience a glimpse of BiDiBLAH - an attempt to automate a focussed yet comprehensive assessmen....

Proper recovery of evidence can be critical to a successful investigation or prosecution. This talk focuses on the different tools and techniques that are used by US Law Enforcement to get an uncontaminated copy of digital evidence from a suspect machine. The goal of this presentation is to teach not only how to copy all the data from a suspect machine, but also to instruct on how to make sure that any evidence collected can be used in cour..

Proper recovery of evidence can be critical to a successful investigation or prosecution. This talk focuses on the different tools and techniques that are used by US Law Enforcement to get an uncontaminated copy of digital evidence from a suspect machine. The goal of this presentation is to teach not only how to copy all the data from a suspect machine, but also to instruct on how to make sure that any evidence collected can be used in cour..

WarDriving is becoming a popular sport among hackers and DEF CON attendees, and WiFi site surveying has become an important tool for the IT security professional. This workshop will describe the basic equipment required for WarDriving and WiFi site surveying. There will be a brief presentation on the benefits and features of different types of WiFi hardware, adapter cards, chipsets, cables, pigtails, and antennas. The session will include a....

WarDriving is becoming a popular sport among hackers and DEF CON attendees, and WiFi site surveying has become an important tool for the IT security professional. This workshop will describe the basic equipment required for WarDriving and WiFi site surveying. There will be a brief presentation on the benefits and features of different types of WiFi hardware, adapter cards, chipsets, cables, pigtails, and antennas. The session will include a....

Matthew L. Shuchman ("Pilgrim"), Frank Thornton, Blackthorn Systems ("Thorn"), Robert V. Hale II, Lawyer This is a proposal for a panel discussion on the legality of accessing WiFi signals without the permission of the owner and will include a review of the legal and ethical issues presented by freely available WiFi both to the owner of the AP and to the users. Included in the panel will be a presentation of recent cases involving....

Matthew L. Shuchman ("Pilgrim"), Frank Thornton, Blackthorn Systems ("Thorn"), Robert V. Hale II, Lawyer This is a proposal for a panel discussion on the legality of accessing WiFi signals without the permission of the owner and will include a review of the legal and ethical issues presented by freely available WiFi both to the owner of the AP and to the users. Included in the panel will be a presentation of recent cases involving....

Simple Nomad, NMRC NMRC Collective: HellNBak, Disturbing; ertia,  Weasel,  jrandom, MadHat, Lock up your children and mid-sized barnyard animals, NMRC is coming to DEF CON13. From their underground bunker located somewhere in North America, NMRC will emerge with your basic shitload of handy tools and toys, geared for helping the humble hacker in everyday chores. Look for crypto, utilities, and other hackerish tools to bring your hac....

Simple Nomad, NMRC NMRC Collective: HellNBak, Disturbing; ertia,  Weasel,  jrandom, MadHat, Lock up your children and mid-sized barnyard animals, NMRC is coming to DEF CON13. From their underground bunker located somewhere in North America, NMRC will emerge with your basic shitload of handy tools and toys, geared for helping the humble hacker in everyday chores. Look for crypto, utilities, and other hackerish tools to bring your hac....

Increasingly, users are adding licensing agreements to all of their online content. One of the most popular licensing agreements for non-coders is the Creative Commons license. Its integration into several popular web products and ease of use have quickly made it the standard license for bloggers. While the Creative Commons provides a "human readable" version of the license, that version doesn't tell the whole story. There are several right....

Buffer overflow attacks are known to be the most common type of attacks that allow attackers to hijack a remote system by sending a specially crafted packet to a vulnerable network application running on it. A comprehensive defense strategy against such attacks should include (1) an attack detection component that determines the fact that a program is compromised and prevents the attack from further propagation, (2) an attack identification....

Increasingly, users are adding licensing agreements to all of their online content. One of the most popular licensing agreements for non-coders is the Creative Commons license. Its integration into several popular web products and ease of use have quickly made it the standard license for bloggers. While the Creative Commons provides a "human readable" version of the license, that version doesn't tell the whole story. There are several right....

Buffer overflow attacks are known to be the most common type of attacks that allow attackers to hijack a remote system by sending a specially crafted packet to a vulnerable network application running on it. A comprehensive defense strategy against such attacks should include (1) an attack detection component that determines the fact that a program is compromised and prevents the attack from further propagation, (2) an attack identification....

The AdWords program is an advertising system used by Google. It is a pay-per-click system like may others but Google doesn't give it the attention to design that it deserves. Not only does Google take some liberties with the Terms of Service and what they allow and don't allow in the program, but also have several flaws in the logical design of the system. There are several loopholes in this system and they will be explained and demonstrate..

The AdWords program is an advertising system used by Google. It is a pay-per-click system like may others but Google doesn't give it the attention to design that it deserves. Not only does Google take some liberties with the Terms of Service and what they allow and don't allow in the program, but also have several flaws in the logical design of the system. There are several loopholes in this system and they will be explained and demonstrate..

Last year at Black Hat, we introduced the rootkit FU. FU took an unprecented approach to hiding not previously seen before in a Windows rootkit. Rather than patching code or modifying function pointers in well known operating system structures like the system call table, FU demonstrated that is was possible to control the execution path indirectly by modifying private kernel objects in memory. This technique was coined DKOM, or Direct Kerne....

Last year at Black Hat, we introduced the rootkit FU. FU took an unprecented approach to hiding not previously seen before in a Windows rootkit. Rather than patching code or modifying function pointers in well known operating system structures like the system call table, FU demonstrated that is was possible to control the execution path indirectly by modifying private kernel objects in memory. This technique was coined DKOM, or Direct Kerne....

The purpose of this paper is to explain and introduce the free culture movement and organization to the hacker community. We make the case that hackers should not only care about the ideas of free culture in the literal sense in that we seek to protect technological and digital rights, but also in a broader cultural sense. The idea of using and reusing bits of culture(the goal in a free culture) parallels the central tenets of the hacker et....

The purpose of this paper is to explain and introduce the free culture movement and organization to the hacker community. We make the case that hackers should not only care about the ideas of free culture in the literal sense in that we seek to protect technological and digital rights, but also in a broader cultural sense. The idea of using and reusing bits of culture(the goal in a free culture) parallels the central tenets of the hacker et....

Alex Stamos, Founding Partner, Information Security Partners Scott Stender, Founding Partner, iSEC Partners, LLC Web Services represent a new and unexplored set of security-sensitive technologies that have been widely deployed by large companies, governments, financial institutions, and in consumer applications. Unfortunately, the attributes that make web services attractive, such as their ease of use, platform independence, use o....

Alex Stamos, Founding Partner, Information Security Partners Scott Stender, Founding Partner, iSEC Partners, LLC Web Services represent a new and unexplored set of security-sensitive technologies that have been widely deployed by large companies, governments, financial institutions, and in consumer applications. Unfortunately, the attributes that make web services attractive, such as their ease of use, platform independence, use o....

In this lecture we will begin with a brief introduction on a couple of the common or not so common threats that exist to the Internet and Internet infrastructure today, provide with some statistics and discuss the harm rather than potential risks. We will then proceed to discuss problems we face dealing with these threats, and what actually gets done to combat them, globally - and by who. We will also try and determine "where do w....

In this lecture we will begin with a brief introduction on a couple of the common or not so common threats that exist to the Internet and Internet infrastructure today, provide with some statistics and discuss the harm rather than potential risks. We will then proceed to discuss problems we face dealing with these threats, and what actually gets done to combat them, globally - and by who. We will also try and determine "where do w....

Recent public disclosures detailing physical lock and safe bypass techniques have raised consumer awareness detailing the efficacy of the hardware that protects some of our most important assets. This talk will address the ethics of full-disclosure, the liability for failure to disclose, and the impact of public dissemination. Demonstrations and new discoveries of lock bypass techniques will be reviewed. Marc Weber Tobias is an Investi....

Recent public disclosures detailing physical lock and safe bypass techniques have raised consumer awareness detailing the efficacy of the hardware that protects some of our most important assets. This talk will address the ethics of full-disclosure, the liability for failure to disclose, and the impact of public dissemination. Demonstrations and new discoveries of lock bypass techniques will be reviewed. Marc Weber Tobias is an Investi....

Ever wonder what to do with the media when it seemingly (and definitely) reports inaccuracies with regard to hackers and hacking in general Fed up with the constant misconceptions you feel the media has of hackers? What is to be done? This forum shall act as an interactive discussion on the misconceptions between hackers and the media, what to do in order to protect yourself, ho to handle the media and your (as well as the media s) constitu....

Ever wonder what to do with the media when it seemingly (and definitely) reports inaccuracies with regard to hackers and hacking in general Fed up with the constant misconceptions you feel the media has of hackers? What is to be done? This forum shall act as an interactive discussion on the misconceptions between hackers and the media, what to do in order to protect yourself, ho to handle the media and your (as well as the media s) constitu....

Do you think that all those tools you download for security testing are free? Well, they may be free of cost for some uses, but the licenses of many tools commonly used by the security community are getting more restrictive and complicated. This interactive discussion will look at the current state of security tool licensing and also look at where this field may be headed. Specific examples of license restrictions in many commonly used tool....

Do you think that all those tools you download for security testing are free? Well, they may be free of cost for some uses, but the licenses of many tools commonly used by the security community are getting more restrictive and complicated. This interactive discussion will look at the current state of security tool licensing and also look at where this field may be headed. Specific examples of license restrictions in many commonly used tool....

149 visitors online