Site uses cookies to provide basic functionality.
Javascript rendering is set to off by default when visiting the site via .onion and .i2p domains. It can be enabled back again in user's settings section. Javascript rendering set to off means, that you can disable javascript in your browser now and the site will remain functional.
There is also IRC server now available via native IRC clients or non javascript web based one.
Fonts can be adjusted in user's settings section as well.
Check FAQ for more.

OK

They say third time is the charm. Some of the biggest mouths in Information Security are back again and once again, we will show you all new of security FAIL. Our panelists will demonstrate innovative hacking techniques in naked routing, web application (in)security, and wireless goats. After taking a sabatical year, we are also proud to announce that Chris "Squirrel" Hoff will be keeping the rest of us honest with his real-time snarkage. S....

The average criminal case today has over a terabyte worth of data to analyze. The cyber forensics field is just beginning to mature. Join federal agents to discuss the forensics field now and in the future. Jim Christy DC3 Mike Convertino AF Jerry Dixon Ex-DHS John Garris NASA Barry Grundy Treasury Bob Hopper NW3C Ken Privette USPS IG Tom Talleur Ex-NASA Trent Teyema FBI

This panel of federal agents will discuss cyber policy. How do we conduct robust continuous monitoring across a large multi-organizational enterprise yet stay within the constitutional requirements for privacy, civil rights and civil liberties? What changes are needed in the criminal justice system to increase the deterrence of committing cyber-crime? Once a cyber-crime has occurred - and through investigative efforts is determined to be a ..

This panel of federal agents will discuss cyber policy. How do we conduct robust continuous monitoring across a large multi-organizational enterprise yet stay within the constitutional requirements for privacy, civil rights and civil liberties? What changes are needed in the criminal justice system to increase the deterrence of committing cyber-crime? Once a cyber-crime has occurred - and through investigative efforts is determined to be a ..

This panel of federal agents will discuss cyber policy. How do we conduct robust continuous monitoring across a large multi-organizational enterprise yet stay within the constitutional requirements for privacy, civil rights and civil liberties? What changes are needed in the criminal justice system to increase the deterrence of committing cyber-crime? Once a cyber-crime has occurred - and through investigative efforts is determined to be a ..

Over the past 5 years oCTF has grown and evolved. Running the contest has been a lot of work, a lot of fun, and educational for both the contestants as well as for us. This panel talk will go over everything from the inspirations which started it back at the Alexis Park, right through to this year when we passed the torch to The Tube Warriors. DC-949 was founded at some point in 2004, and has slowly amassed members of like minded and p..

This authors' panel has all the makings of a page-turning bestseller: crime lords, heroes, spies, global cartels, corporate scandals, hi-tech gizmos, betrayal, revolution, political intrigue, and midnight assassination attempts. As with all good books, it's the characters – the researchers, the criminals, and the victims – and their unique stories that will keep you riveted to your seat. Jeffrey Carr, (Principal, GreyLogic) is a cyber ....

Over the past 5 years oCTF has grown and evolved. Running the contest has been a lot of work, a lot of fun, and educational for both the contestants as well as for us. This panel talk will go over everything from the inspirations which started it back at the Alexis Park, right through to this year when we passed the torch to The Tube Warriors. DC-949 was founded at some point in 2004, and has slowly amassed members of like minded and p..

This authors' panel has all the makings of a page-turning bestseller: crime lords, heroes, spies, global cartels, corporate scandals, hi-tech gizmos, betrayal, revolution, political intrigue, and midnight assassination attempts. As with all good books, it's the characters – the researchers, the criminals, and the victims – and their unique stories that will keep you riveted to your seat. Jeffrey Carr, (Principal, GreyLogic) is a cyber ....

Over the past 5 years oCTF has grown and evolved. Running the contest has been a lot of work, a lot of fun, and educational for both the contestants as well as for us. This panel talk will go over everything from the inspirations which started it back at the Alexis Park, right through to this year when we passed the torch to The Tube Warriors. DC-949 was founded at some point in 2004, and has slowly amassed members of like minded and p..

This authors' panel has all the makings of a page-turning bestseller: crime lords, heroes, spies, global cartels, corporate scandals, hi-tech gizmos, betrayal, revolution, political intrigue, and midnight assassination attempts. As with all good books, it's the characters – the researchers, the criminals, and the victims – and their unique stories that will keep you riveted to your seat. Jeffrey Carr, (Principal, GreyLogic) is a cyber ....

Past speeches and talks from DEF CON hacking conferences in an iTunes friendly M4b format. The DEF CON series of hacking conferences were started in 1993 to focus on both the technical and social trends in hacking, and has grown to be world known event. Video, audio and supporting materials from past conferences will be posted here, starting with the newest and working our way back to the oldest with new content added as available!


Past speeches and talks from DEF CON hacking conferences in an iTunes friendly M4b format. The DEF CON series of hacking conferences were started in 1993 to focus on both the technical and social trends in hacking, and has grown to be world known event. Video, audio and supporting materials from past conferences will be posted here, starting with the newest and working our way back to the oldest with new content added as available!

The experts on this panel will provide their views on systemic risks facing the DNS and provide thoughts on measures that should be undertaken to remediate the risks. The panelists will discuss both the challenges and the security benefits that will arise from the implementation of DNSSec. Rod Beckstrom is a highly successful entrepreneur, founder and CEO of a publicly-traded company, a best-selling author, avowed environmentalist, pub....

Razorback is the result of extensive research by members of the Sourcefire Vulnerability Research Team into developing a platform to address advanced detection problems. The level of sophistication currently demonstrated both by actors described as the 'Advanced Persistent Threat' (APT) and publicly available exploit frameworks such as Metasploit, CANVAS and Core Impact leave increasingly fewer options to provide robust detection. This proj....

The experts on this panel will provide their views on systemic risks facing the DNS and provide thoughts on measures that should be undertaken to remediate the risks. The panelists will discuss both the challenges and the security benefits that will arise from the implementation of DNSSec. Rod Beckstrom is a highly successful entrepreneur, founder and CEO of a publicly-traded company, a best-selling author, avowed environmentalist, pub....

Razorback is the result of extensive research by members of the Sourcefire Vulnerability Research Team into developing a platform to address advanced detection problems. The level of sophistication currently demonstrated both by actors described as the 'Advanced Persistent Threat' (APT) and publicly available exploit frameworks such as Metasploit, CANVAS and Core Impact leave increasingly fewer options to provide robust detection. This proj....

The experts on this panel will provide their views on systemic risks facing the DNS and provide thoughts on measures that should be undertaken to remediate the risks. The panelists will discuss both the challenges and the security benefits that will arise from the implementation of DNSSec. Rod Beckstrom is a highly successful entrepreneur, founder and CEO of a publicly-traded company, a best-selling author, avowed environmentalist, pub....

Razorback is the result of extensive research by members of the Sourcefire Vulnerability Research Team into developing a platform to address advanced detection problems. The level of sophistication currently demonstrated both by actors described as the 'Advanced Persistent Threat' (APT) and publicly available exploit frameworks such as Metasploit, CANVAS and Core Impact leave increasingly fewer options to provide robust detection. This proj....

Web Application fingerprinting before 2010 has been a hodge-podge of different techniques, usually relying on meta tags or other clues helpfully added by well meaning (but security challenged) developers. Current hardening approaches hamper standard web application fingerprinting, but new static file techniques provide extremely high accuracy and require new hardening approaches. We will discuss implementation details of static file fingerp..

Web Application fingerprinting before 2010 has been a hodge-podge of different techniques, usually relying on meta tags or other clues helpfully added by well meaning (but security challenged) developers. Current hardening approaches hamper standard web application fingerprinting, but new static file techniques provide extremely high accuracy and require new hardening approaches. We will discuss implementation details of static file fingerp..

Web Application fingerprinting before 2010 has been a hodge-podge of different techniques, usually relying on meta tags or other clues helpfully added by well meaning (but security challenged) developers. Current hardening approaches hamper standard web application fingerprinting, but new static file techniques provide extremely high accuracy and require new hardening approaches. We will discuss implementation details of static file fingerp..

Format string attacks remain difficult in both software and hackademic exercises as the techniques have not improved since their discovery. This session demonstrates advanced format string attack techniques designed to automate the process from creation to compromise as well as incorporate those techniques into the Metasploit framework. The audience is encouraged to bring a basic understanding of format string attacks in order to leave the ....

This talk reports the results of the panopticlick browser fingerprinting experiment. We show how inoccent-looking version and configuration information can be used to uniquely identify almost all desktop browsers, without use of cookies or IP addresses. We discuss how this comes about, how serious a problem it is, and just how hard it will be to fix... Peter Eckersley is a Senior Staff Technologist at the Electronic Frontier Foundation..

Format string attacks remain difficult in both software and hackademic exercises as the techniques have not improved since their discovery. This session demonstrates advanced format string attack techniques designed to automate the process from creation to compromise as well as incorporate those techniques into the Metasploit framework. The audience is encouraged to bring a basic understanding of format string attacks in order to leave the ....

This talk reports the results of the panopticlick browser fingerprinting experiment. We show how inoccent-looking version and configuration information can be used to uniquely identify almost all desktop browsers, without use of cookies or IP addresses. We discuss how this comes about, how serious a problem it is, and just how hard it will be to fix... Peter Eckersley is a Senior Staff Technologist at the Electronic Frontier Foundation..

Format string attacks remain difficult in both software and hackademic exercises as the techniques have not improved since their discovery. This session demonstrates advanced format string attack techniques designed to automate the process from creation to compromise as well as incorporate those techniques into the Metasploit framework. The audience is encouraged to bring a basic understanding of format string attacks in order to leave the ....

This talk reports the results of the panopticlick browser fingerprinting experiment. We show how inoccent-looking version and configuration information can be used to uniquely identify almost all desktop browsers, without use of cookies or IP addresses. We discuss how this comes about, how serious a problem it is, and just how hard it will be to fix... Peter Eckersley is a Senior Staff Technologist at the Electronic Frontier Foundation..

This talk reports a comprehensive study of the set of certificates currently in use on public HTTPS servers. We investigate who signed the certs, what properties they have, and whether there is any evidence of malicious certificates signed, directly or indirectly, by trusted CAs. Peter Eckersley is a Senior Staff Technologist at the Electronic Frontier Foundation. His research interests include digital copyright and alternatives to dig....

It's 2010. WiMAX networks have now been deployed in most major US and European cities. Laptops are being sold with WiMAX built in, and mobile phones are now hitting the market. This talk covers some of the latest findings, public and private, from the wimax-hacking google group. Come see what's been done, what's possible, and what we are working on. Pierce, Goldy and aSmig are security researchers from Portland Oregon, and active contr..

This talk reports a comprehensive study of the set of certificates currently in use on public HTTPS servers. We investigate who signed the certs, what properties they have, and whether there is any evidence of malicious certificates signed, directly or indirectly, by trusted CAs. Peter Eckersley is a Senior Staff Technologist at the Electronic Frontier Foundation. His research interests include digital copyright and alternatives to dig....

It's 2010. WiMAX networks have now been deployed in most major US and European cities. Laptops are being sold with WiMAX built in, and mobile phones are now hitting the market. This talk covers some of the latest findings, public and private, from the wimax-hacking google group. Come see what's been done, what's possible, and what we are working on. Pierce, Goldy and aSmig are security researchers from Portland Oregon, and active contr..

This talk reports a comprehensive study of the set of certificates currently in use on public HTTPS servers. We investigate who signed the certs, what properties they have, and whether there is any evidence of malicious certificates signed, directly or indirectly, by trusted CAs. Peter Eckersley is a Senior Staff Technologist at the Electronic Frontier Foundation. His research interests include digital copyright and alternatives to dig....

It's 2010. WiMAX networks have now been deployed in most major US and European cities. Laptops are being sold with WiMAX built in, and mobile phones are now hitting the market. This talk covers some of the latest findings, public and private, from the wimax-hacking google group. Come see what's been done, what's possible, and what we are working on. Pierce, Goldy and aSmig are security researchers from Portland Oregon, and active contr..

Everyone seems to be acquainted with the idea that the polygraph is fallible and that there a million tricks that can supposedly be used to beat it, but how can you really know for sure? One way would be if you pieced together your own polygraph for the singular reason of trying to beat it and we have done just that. We will take a look at the history of deception detection from the birth of Jesus through the Age of Reason to try and get a ....

Everyone seems to be acquainted with the idea that the polygraph is fallible and that there a million tricks that can supposedly be used to beat it, but how can you really know for sure? One way would be if you pieced together your own polygraph for the singular reason of trying to beat it and we have done just that. We will take a look at the history of deception detection from the birth of Jesus through the Age of Reason to try and get a ....

Everyone seems to be acquainted with the idea that the polygraph is fallible and that there a million tricks that can supposedly be used to beat it, but how can you really know for sure? One way would be if you pieced together your own polygraph for the singular reason of trying to beat it and we have done just that. We will take a look at the history of deception detection from the birth of Jesus through the Age of Reason to try and get a ....

Increasing numbers of commercial and closed source applications are being developed in Python. Developers of such applications are investing more & more to stop people being able to see their source code through a variety of code obfuscation techniques. At the same time Python is an increasingly present component of 'Cloud' technologies where traditional bytecode decompilation techniques fall down through lack of access to files on disk. ....

Richard Thieme celebrates speaking for Def Con for fifteen years by discussing the deepest truths he knows and relating them to Big Picture hacking. Thieme references the most fervent explorations of his life, from immersion in the works of the Society for Psychical Research while living in England as a young man to conversations with remote viewers in the governmentís Stargate program to thirty years of research in UFO reports (in par....

Increasing numbers of commercial and closed source applications are being developed in Python. Developers of such applications are investing more & more to stop people being able to see their source code through a variety of code obfuscation techniques. At the same time Python is an increasingly present component of 'Cloud' technologies where traditional bytecode decompilation techniques fall down through lack of access to files on disk. ....

Richard Thieme celebrates speaking for Def Con for fifteen years by discussing the deepest truths he knows and relating them to Big Picture hacking. Thieme references the most fervent explorations of his life, from immersion in the works of the Society for Psychical Research while living in England as a young man to conversations with remote viewers in the governmentís Stargate program to thirty years of research in UFO reports (in par....

Increasing numbers of commercial and closed source applications are being developed in Python. Developers of such applications are investing more & more to stop people being able to see their source code through a variety of code obfuscation techniques. At the same time Python is an increasingly present component of 'Cloud' technologies where traditional bytecode decompilation techniques fall down through lack of access to files on disk. ....

Richard Thieme celebrates speaking for Def Con for fifteen years by discussing the deepest truths he knows and relating them to Big Picture hacking. Thieme references the most fervent explorations of his life, from immersion in the works of the Society for Psychical Research while living in England as a young man to conversations with remote viewers in the governmentís Stargate program to thirty years of research in UFO reports (in par....

4 visitors online