Site uses cookies to provide basic functionality.
Javascript rendering is set to off by default when visiting the site via .onion and .i2p domains. It can be enabled back again in user's settings section. Javascript rendering set to off means, that you can disable javascript in your browser now and the site will remain functional.
There is also IRC server now available via native IRC clients or non javascript web based one.
Fonts can be adjusted in user's settings section as well.
Check FAQ for more.

OK

Weaponizing the Windows API with Metasploit’s Railgun David "thelightcosine" Maloney Software Engineer, Metasploit Rapid7 No part of the Metasploit Framework has been shrouded in more mystery and confusion than the Railgun extension. Railgun is one of the most powerful tools in the Metasploit arsenal when it comes to Post Exploitation. In this talk we will examine what Railgun is, and how we can use it to turn Windows completely aga....

Don't Stand So Close To Me: An Analysis of the NFC Attack Surface Charlie Miller Principal Research Consultant, Accuvant Labs Near Field Communication (NFC) has been used in mobile devices in some countries for a while and is now emerging on devices in use in the United States. This technology allows NFC enabled devices to communicate with each other within close range, typically a few centimeters. It is being rolled out as a way to ....

Copy of the slides for this talk are here:http://m6rqq6kocsyugo2laitup5nn32bwm3lh677chuodjfmggczoafzwfcad.onion/dc-20/presentations/Panel-Anonymous-and-the-Online-Fight-for-Justice/DEFCON-20-Criminal-Codes.pdf Anonymous and the Online Fight for Justice Amber Lyon Independent Investigative Journalist Gabriella Coleman Chair in Scientific and Technological Literacy, McGill University, Department of Art History & Communication Stud....

Copy of the slides for this talk are here:http://m6rqq6kocsyugo2laitup5nn32bwm3lh677chuodjfmggczoafzwfcad.onion/dc-20/presentations/Maletic-Pogue/DEFCON-20-Maletic-Pogue-OPFOR4Ever.pdf OPFOR 4Ever Tim Maletic Senior Security Consultant,Trustwave SpiderLabs Christopher Pogue Managing Consultant, Trustwave SpiderLabs Training utilizing Opposing Forces, or OPFOR, is an exercise focused on improving detection and response thro....

Copy of the slides for this talk are here:http://m6rqq6kocsyugo2laitup5nn32bwm3lh677chuodjfmggczoafzwfcad.onion/dc-20/presentations/Maloney/DEFCON-20-Maloney-Railgun.pdf Weaponizing the Windows API with Metasploit’s Railgun David "thelightcosine" Maloney Software Engineer, Metasploit Rapid7 No part of the Metasploit Framework has been shrouded in more mystery and confusion than the Railgun extension. Railgun is one of the mo....

Copy of the slides for this talk are here:http://m6rqq6kocsyugo2laitup5nn32bwm3lh677chuodjfmggczoafzwfcad.onion/dc-20/presentations/Miller/DEFCON-20-Miller-NFC-Attack-Surface.pdf Don't Stand So Close To Me: An Analysis of the NFC Attack Surface Charlie Miller Principal Research Consultant, Accuvant Labs Near Field Communication (NFC) has been used in mobile devices in some countries for a while and is now emerging on devices ....

Copy of the slides for this talk are here:http://m6rqq6kocsyugo2laitup5nn32bwm3lh677chuodjfmggczoafzwfcad.onion/dc-20/presentations/Panel-Anonymous-and-the-Online-Fight-for-Justice/DEFCON-20-Criminal-Codes.pdf Anonymous and the Online Fight for Justice Amber Lyon Independent Investigative Journalist Gabriella Coleman Chair in Scientific and Technological Literacy, McGill University, Department of Art History & Communication Stud....

Copy of the slides for this talk are here:http://m6rqq6kocsyugo2laitup5nn32bwm3lh677chuodjfmggczoafzwfcad.onion/dc-20/presentations/Maletic-Pogue/DEFCON-20-Maletic-Pogue-OPFOR4Ever.pdf OPFOR 4Ever Tim Maletic Senior Security Consultant,Trustwave SpiderLabs Christopher Pogue Managing Consultant, Trustwave SpiderLabs Training utilizing Opposing Forces, or OPFOR, is an exercise focused on improving detection and response thro....

Copy of the slides for this talk are here:http://m6rqq6kocsyugo2laitup5nn32bwm3lh677chuodjfmggczoafzwfcad.onion/dc-20/presentations/Maloney/DEFCON-20-Maloney-Railgun.pdf Weaponizing the Windows API with Metasploit’s Railgun David "thelightcosine" Maloney Software Engineer, Metasploit Rapid7 No part of the Metasploit Framework has been shrouded in more mystery and confusion than the Railgun extension. Railgun is one of the mo....

Copy of the slides for this talk are here:http://m6rqq6kocsyugo2laitup5nn32bwm3lh677chuodjfmggczoafzwfcad.onion/dc-20/presentations/Miller/DEFCON-20-Miller-NFC-Attack-Surface.pdf Don't Stand So Close To Me: An Analysis of the NFC Attack Surface Charlie Miller Principal Research Consultant, Accuvant Labs Near Field Communication (NFC) has been used in mobile devices in some countries for a while and is now emerging on devices ....

Copy of the slides for this talk are here:http://m6rqq6kocsyugo2laitup5nn32bwm3lh677chuodjfmggczoafzwfcad.onion/dc-20/presentations/Panel-Anonymous-and-the-Online-Fight-for-Justice/DEFCON-20-Criminal-Codes.pdf Anonymous and the Online Fight for Justice Amber Lyon Independent Investigative Journalist Gabriella Coleman Chair in Scientific and Technological Literacy, McGill University, Department of Art History & Communication Stud....

Copy of the slides for this talk are here:http://m6rqq6kocsyugo2laitup5nn32bwm3lh677chuodjfmggczoafzwfcad.onion/dc-20/presentations/Maletic-Pogue/DEFCON-20-Maletic-Pogue-OPFOR4Ever.pdf OPFOR 4Ever Tim Maletic Senior Security Consultant,Trustwave SpiderLabs Christopher Pogue Managing Consultant, Trustwave SpiderLabs Training utilizing Opposing Forces, or OPFOR, is an exercise focused on improving detection and response thro....

Copy of the slides for this talk are here:http://m6rqq6kocsyugo2laitup5nn32bwm3lh677chuodjfmggczoafzwfcad.onion/dc-20/presentations/Maloney/DEFCON-20-Maloney-Railgun.pdf Weaponizing the Windows API with Metasploit’s Railgun David "thelightcosine" Maloney Software Engineer, Metasploit Rapid7 No part of the Metasploit Framework has been shrouded in more mystery and confusion than the Railgun extension. Railgun is one of the mo....

Copy of the slides for this talk are here:http://m6rqq6kocsyugo2laitup5nn32bwm3lh677chuodjfmggczoafzwfcad.onion/dc-20/presentations/Miller/DEFCON-20-Miller-NFC-Attack-Surface.pdf Don't Stand So Close To Me: An Analysis of the NFC Attack Surface Charlie Miller Principal Research Consultant, Accuvant Labs Near Field Communication (NFC) has been used in mobile devices in some countries for a while and is now emerging on devices ....

How to Hack VMware vCenter Server in 60 Seconds Alexander Minozhenko Senior Penetration Tester, ERPScan This talk will discuss some ways to gain control over the virtual infrastructure through vCenter's services. I will describe a few non-dangerous bugs (they were 0-days when we found them), but if we can use all of them together, we will get administrative access to vCenter which means to the whole virtual network. Alexander Mi..

DEF CON Comedy Jam V, V for Vendetta David Mortman Chief Security Architect, enStratus Rich Mogull Securosis, @rmogull Chris Hoff Rational Security, @beaker Dave Maynor Errata, @donicer Larry Pesce pauldotcom.com, @haxorthematrix James Arlen Liquid Matrix, @myrcurial Robert David Graham Errata Security, @ErrataRob You know you can't stay away! The most talked about panel at DEF CON! Nearly two hours of non-stop FAIL. Come....

Cortana: Rise of the Automated Red Team Raphael Mudge Principal, Strategic Cyber LLC Do you ever wish that you could clone yourself during a penetration test? Meet Cortana, a new scripting language to automate Metasploit and extend Armitage. Cortana is a penetration tester's scripting language inspired by scriptable IRC clients and bots. Its purpose is two-fold. You may create long running bots that simulate virtual red team mem....

SQL ReInjector - Automated Exfiltrated Data Identification Jason A. Novak Assistant Director, Digital Forensics; Stroz Friedberg, LLC Andrea (Drea) London Digital Forensic Examiner; Stroz Friedberg, LLC In 2011, SQL injections became front page news as ever more high profile companies were victims of automated SQL injection attacks. Responders spent countless hours looking at values in log files like "0x31303235343830303536" trying....

Copy of the slides for this talk are here: http://m6rqq6kocsyugo2laitup5nn32bwm3lh677chuodjfmggczoafzwfcad.onion/dc-20/presentations/Minozhenko/DEFCON-20-Minozhenko-Hack-VMware-60-Seconds.pdf How to Hack VMware vCenter Server in 60 Seconds Alexander Minozhenko Senior Penetration Tester, ERPScan This talk will discuss some ways to gain control over the virtual infrastructure through vCenter's services. I will describe a few non-dan..

Copy of the slides for this talk are here:http://m6rqq6kocsyugo2laitup5nn32bwm3lh677chuodjfmggczoafzwfcad.onion/dc-20/presentations/Mudge/DEFCON-20-Mudge-Cortana.pdf Cortana: Rise of the Automated Red Team Raphael Mudge Principal, Strategic Cyber LLC Do you ever wish that you could clone yourself during a penetration test? Meet Cortana, a new scripting language to automate Metasploit and extend Armitage. Cortana is a pe....

Copy of the slides for this talk are here:http://m6rqq6kocsyugo2laitup5nn32bwm3lh677chuodjfmggczoafzwfcad.onion/dc-20/presentations/Novak-London/DEFCON-20-Novak-London-SQLReInjector.pdf Extras:http://m6rqq6kocsyugo2laitup5nn32bwm3lh677chuodjfmggczoafzwfcad.onion/dc-20/presentations/Novak-London/Extras.zip SQL ReInjector - Automated Exfiltrated Data Identification Jason A. Novak Assistant Director, Digital Forensics; Stroz Friedberg, LLC....

Copy of the slides for this talk are here:http://m6rqq6kocsyugo2laitup5nn32bwm3lh677chuodjfmggczoafzwfcad.onion/dc-20/presentations/Panel-Comedy-Jam-V/DEFCON-20-Mortman-Panel-Comedy-Jam-V-V-For-Vendetta.pdf DEF CON Comedy Jam V, V for Vendetta David Mortman Chief Security Architect, enStratus Rich Mogull Securosis, @rmogull Chris Hoff Rational Security, @beaker Dave Maynor Errata, @donicer Larry Pesce pauldotcom.com, @h....

Copy of the slides for this talk are here: http://m6rqq6kocsyugo2laitup5nn32bwm3lh677chuodjfmggczoafzwfcad.onion/dc-20/presentations/Minozhenko/DEFCON-20-Minozhenko-Hack-VMware-60-Seconds.pdf How to Hack VMware vCenter Server in 60 Seconds Alexander Minozhenko Senior Penetration Tester, ERPScan This talk will discuss some ways to gain control over the virtual infrastructure through vCenter's services. I will describe a few non-dan..

Copy of the slides for this talk are here:http://m6rqq6kocsyugo2laitup5nn32bwm3lh677chuodjfmggczoafzwfcad.onion/dc-20/presentations/Mudge/DEFCON-20-Mudge-Cortana.pdf Cortana: Rise of the Automated Red Team Raphael Mudge Principal, Strategic Cyber LLC Do you ever wish that you could clone yourself during a penetration test? Meet Cortana, a new scripting language to automate Metasploit and extend Armitage. Cortana is a pe....

Copy of the slides for this talk are here:http://m6rqq6kocsyugo2laitup5nn32bwm3lh677chuodjfmggczoafzwfcad.onion/dc-20/presentations/Novak-London/DEFCON-20-Novak-London-SQLReInjector.pdf Extras:http://m6rqq6kocsyugo2laitup5nn32bwm3lh677chuodjfmggczoafzwfcad.onion/dc-20/presentations/Novak-London/Extras.zip SQL ReInjector - Automated Exfiltrated Data Identification Jason A. Novak Assistant Director, Digital Forensics; Stroz Friedberg, LLC....

Copy of the slides for this talk are here:http://m6rqq6kocsyugo2laitup5nn32bwm3lh677chuodjfmggczoafzwfcad.onion/dc-20/presentations/Panel-Comedy-Jam-V/DEFCON-20-Mortman-Panel-Comedy-Jam-V-V-For-Vendetta.pdf DEF CON Comedy Jam V, V for Vendetta David Mortman Chief Security Architect, enStratus Rich Mogull Securosis, @rmogull Chris Hoff Rational Security, @beaker Dave Maynor Errata, @donicer Larry Pesce pauldotcom.com, @h....

Copy of the slides for this talk are here: http://m6rqq6kocsyugo2laitup5nn32bwm3lh677chuodjfmggczoafzwfcad.onion/dc-20/presentations/Minozhenko/DEFCON-20-Minozhenko-Hack-VMware-60-Seconds.pdf How to Hack VMware vCenter Server in 60 Seconds Alexander Minozhenko Senior Penetration Tester, ERPScan This talk will discuss some ways to gain control over the virtual infrastructure through vCenter's services. I will describe a few non-dan..

Copy of the slides for this talk are here:http://m6rqq6kocsyugo2laitup5nn32bwm3lh677chuodjfmggczoafzwfcad.onion/dc-20/presentations/Mudge/DEFCON-20-Mudge-Cortana.pdf Cortana: Rise of the Automated Red Team Raphael Mudge Principal, Strategic Cyber LLC Do you ever wish that you could clone yourself during a penetration test? Meet Cortana, a new scripting language to automate Metasploit and extend Armitage. Cortana is a pe....

Copy of the slides for this talk are here:http://m6rqq6kocsyugo2laitup5nn32bwm3lh677chuodjfmggczoafzwfcad.onion/dc-20/presentations/Novak-London/DEFCON-20-Novak-London-SQLReInjector.pdf Extras:http://m6rqq6kocsyugo2laitup5nn32bwm3lh677chuodjfmggczoafzwfcad.onion/dc-20/presentations/Novak-London/Extras.zip SQL ReInjector - Automated Exfiltrated Data Identification Jason A. Novak Assistant Director, Digital Forensics; Stroz Friedberg, LLC....

Copy of the slides for this talk are here:http://m6rqq6kocsyugo2laitup5nn32bwm3lh677chuodjfmggczoafzwfcad.onion/dc-20/presentations/Panel-Comedy-Jam-V/DEFCON-20-Mortman-Panel-Comedy-Jam-V-V-For-Vendetta.pdf DEF CON Comedy Jam V, V for Vendetta David Mortman Chief Security Architect, enStratus Rich Mogull Securosis, @rmogull Chris Hoff Rational Security, @beaker Dave Maynor Errata, @donicer Larry Pesce pauldotcom.com, @h....

The End of the PSTN As You Know It Jason Ostrom Security Researcher, VIPER Lab (Voice over IP Exploit Research), Avaya, Inc. Karl Feinauer Vulnerability Research Software Engineer, VIPER Lab William Borskey Senior Security Consultant, VIPER Lab The PSTN as you know it is changing. In March of 2012, the NSA announced "Project Fishbowl", a reference architecture for secure mobility VoIP usage on smartphones using WiFi or 3GPP netwo....

APK File Infection on an Android System Bob Pan Mobile Security Research Engineer, TrendMicro Inc. This concept of APK file infection on Android is similar to the concept of PE file infection on Windows systems. As the performance of Android device has increased, it's become possible to implement such a concept in Android systems. We will demonstrate how to implement this concept. In addition, we will also give a demo to show that ..

Anti-Forensics and Anti-Anti-Forensics: Attacks and Mitigating Techniques for Digital-Forensic Investigations Michael Perklin Digital investigations may be conducted differently by various labs (law enforcement agencies, private firms, enterprise corporations) but each lab performs similar steps when acquiring, processing, analyzing, or reporting on data. This talk will discuss techniques that criminals can use to throw wrenches into....

Network Anti-Reconnaissance: Messing with Nmap Through Smoke and Mirrors Dan "AltF4" Petro Security Researcher, DataSoft Corp Reconnaissance on a network has been an attacker's game for far too long, where's the defense? Nmap routinely evades firewalls, traverses NATs, bypasses signature based NIDS, and gathers up the details of your highly vulnerable box serving Top Secret documents. Why make it so easy? In this talk, we will e....

Bypassing Endpoint Security for $20 or Less Phil Polstra Computer Security Professor, University of Dubuque In this talk cheap easily constructed devices which can be used to bypass endpoint security software by making any USB mass storage (flash or hard) drive appear as authorized devices will be presented. The design and implementation will be discussed in detail. Devices can be constructed for approximately $18 and $30 for a ....

Copy of the slides for this talk are here:http://m6rqq6kocsyugo2laitup5nn32bwm3lh677chuodjfmggczoafzwfcad.onion/dc-20/presentations/Ostrom-Feinauer-Borskey/DEFCON-20-Ostrom-Feinauer-Borskey-The-End-of-the-PTSN.pdf The End of the PSTN As You Know It Jason Ostrom Security Researcher, VIPER Lab (Voice over IP Exploit Research), Avaya, Inc. Karl Feinauer Vulnerability Research Software Engineer, VIPER Lab William Borskey Senior Se....

Copy of the slides for this talk are here:http://m6rqq6kocsyugo2laitup5nn32bwm3lh677chuodjfmggczoafzwfcad.onion/dc-20/presentations/Pan/DEFCON-20-Pan-APK-File-Infection-on-Android-System.pdf APK File Infection on an Android System Bob Pan Mobile Security Research Engineer, TrendMicro Inc. This concept of APK file infection on Android is similar to the concept of PE file infection on Windows systems. As the performance of A....

Copy of the slides for this talk are here:http://m6rqq6kocsyugo2laitup5nn32bwm3lh677chuodjfmggczoafzwfcad.onion/dc-20/presentations/Perklin/DEFCON-20-Perklin-AntiForensics.pdf Anti-Forensics and Anti-Anti-Forensics: Attacks and Mitigating Techniques for Digital-Forensic Investigations Michael Perklin Digital investigations may be conducted differently by various labs (law enforcement agencies, private firms, enterprise corpor....

Copy of the slides for this talk are here:http://m6rqq6kocsyugo2laitup5nn32bwm3lh677chuodjfmggczoafzwfcad.onion/dc-20/presentations/Petro/DEFCON-20-Petro-Messing-with-Nmap.pdf Network Anti-Reconnaissance: Messing with Nmap Through Smoke and Mirrors Dan "AltF4" Petro Security Researcher, DataSoft Corp Reconnaissance on a network has been an attacker's game for far too long, where's the defense? Nmap routinely evades firewalls,....

Copy of the slides for this talk are here: http://m6rqq6kocsyugo2laitup5nn32bwm3lh677chuodjfmggczoafzwfcad.onion/dc-20/presentations/Polstra/DEFCON-20-Polstra-Bypassing-Endpoint-Security.pdf Exrtas:http://m6rqq6kocsyugo2laitup5nn32bwm3lh677chuodjfmggczoafzwfcad.onion/dc-20/presentations/Polstra/Philip Polstra.txt Bypassing Endpoint Security for $20 or Less Phil Polstra Computer Security Professor, University of Dubuque In ....

Copy of the slides for this talk are here:http://m6rqq6kocsyugo2laitup5nn32bwm3lh677chuodjfmggczoafzwfcad.onion/dc-20/presentations/Ostrom-Feinauer-Borskey/DEFCON-20-Ostrom-Feinauer-Borskey-The-End-of-the-PTSN.pdf The End of the PSTN As You Know It Jason Ostrom Security Researcher, VIPER Lab (Voice over IP Exploit Research), Avaya, Inc. Karl Feinauer Vulnerability Research Software Engineer, VIPER Lab William Borskey Senior Se....

Copy of the slides for this talk are here:http://m6rqq6kocsyugo2laitup5nn32bwm3lh677chuodjfmggczoafzwfcad.onion/dc-20/presentations/Pan/DEFCON-20-Pan-APK-File-Infection-on-Android-System.pdf APK File Infection on an Android System Bob Pan Mobile Security Research Engineer, TrendMicro Inc. This concept of APK file infection on Android is similar to the concept of PE file infection on Windows systems. As the performance of A....

Copy of the slides for this talk are here:http://m6rqq6kocsyugo2laitup5nn32bwm3lh677chuodjfmggczoafzwfcad.onion/dc-20/presentations/Perklin/DEFCON-20-Perklin-AntiForensics.pdf Anti-Forensics and Anti-Anti-Forensics: Attacks and Mitigating Techniques for Digital-Forensic Investigations Michael Perklin Digital investigations may be conducted differently by various labs (law enforcement agencies, private firms, enterprise corpor....

Copy of the slides for this talk are here:http://m6rqq6kocsyugo2laitup5nn32bwm3lh677chuodjfmggczoafzwfcad.onion/dc-20/presentations/Petro/DEFCON-20-Petro-Messing-with-Nmap.pdf Network Anti-Reconnaissance: Messing with Nmap Through Smoke and Mirrors Dan "AltF4" Petro Security Researcher, DataSoft Corp Reconnaissance on a network has been an attacker's game for far too long, where's the defense? Nmap routinely evades firewalls,....

70 visitors online