Site uses cookies to provide basic functionality.
Javascript rendering is set to off by default when visiting the site via .onion and .i2p domains. It can be enabled back again in user's settings section. Javascript rendering set to off means, that you can disable javascript in your browser now and the site will remain functional.
There is also IRC server now available via native IRC clients or non javascript web based one.
Fonts can be adjusted in user's settings section as well.
Check FAQ for more.

OK

There Isn't an App For That” - Windows Apps I haven't been able to replace in Mac OS X For a very long time I was a Windows guy, I was once a DOS guy. I switched nearly exclusively to Mac for my home use about 4 years ago. I’ve been very happy with it. Its stable, well engineered, and - my favorite part of all - consistent. Yet, in this time there remain a few applications I cannot seem to replace. Nusphere PhpED I am a PHP Develope....

There Isn't an App For That” - Windows Apps I haven't been able to replace in Mac OS X For a very long time I was a Windows guy, I was once a DOS guy. I switched nearly exclusively to Mac for my home use about 4 years ago. I’ve been very happy with it. Its stable, well engineered, and - my favorite part of all - consistent. Yet, in this time there remain a few applications I cannot seem to replace. Nusphere PhpED I am a PHP Develope....

This talk demonstrates how to use SNMPv3 software (specifically illustrated using Net-SNMP) both with minor custom configurations and also with specialized MIBs and Agents to provide file data and file hashes on demand over secure channels. I also discuss the use of the TCP Inform Trap as a syslog style message transfer mechanism. I spend the majority of the time showing how the authentication and privacy features of SNMPv3 provide robust b....

This talk demonstrates how to use SNMPv3 software (specifically illustrated using Net-SNMP) both with minor custom configurations and also with specialized MIBs and Agents to provide file data and file hashes on demand over secure channels. I also discuss the use of the TCP Inform Trap as a syslog style message transfer mechanism. I spend the majority of the time showing how the authentication and privacy features of SNMPv3 provide robust b....

DC Phone Home (DreamCast Phone Home, a pun on the well-known film ET: The Extraterrestrial) is a project that challenges conventional enterprise security models by showing the ease by which an attack to an organization's network resources and infrastructure can be performed from an internal perspective. Simply put, once the DreamCast is deployed, it 'phones home' joining an organization's internal network with a remote network. We show that....

Did you buy The Fast and the Furious Soundtrack only to find out you couldn' t archive the songs to MP3s on your PC? Companies including Vivendi Universal, AOL Time Warner and Sony employ different protection methods on DVDs, video games and CDs. Many consumers argue that these protections abrogate their legal rights. I'll be presenting a broad overview of these Consumer Media Protections (CMPs) and will conduct demonstrations of how to ide..

Did you buy The Fast and the Furious Soundtrack only to find out you couldn' t archive the songs to MP3s on your PC? Companies including Vivendi Universal, AOL Time Warner and Sony employ different protection methods on DVDs, video games and CDs. Many consumers argue that these protections abrogate their legal rights. I'll be presenting a broad overview of these Consumer Media Protections (CMPs) and will conduct demonstrations of how to ide..

AgentOJ, a Macintosh programmer for Team2600, will be speaking on Applescript in the OS X environment, covering both attack and defense tools using Applescript. Topics covered will include: Applescript as an information gathering tool (system info, list of users, open services, etc). Applescript as an attack tool (applescript trojans, destructive scripts, exploiting scriptable applications, and a proof of concept applescript trojan). Apples..

AgentOJ, a Macintosh programmer for Team2600, will be speaking on Applescript in the OS X environment, covering both attack and defense tools using Applescript. Topics covered will include: Applescript as an information gathering tool (system info, list of users, open services, etc). Applescript as an attack tool (applescript trojans, destructive scripts, exploiting scriptable applications, and a proof of concept applescript trojan). Apples..

Wireless networks have seen explosive growth in the last year. Wardriving a city last July resulted in only a handful of access points. Now there are hundreds if not thousands of access points in every city in the nation. And during the same time holes have been shot in all major wireless security protocols. People deploying wireless technologies are either unaware of the risk involved or have decided the productivity gain out weighs the ri....

Wireless networks have seen explosive growth in the last year. Wardriving a city last July resulted in only a handful of access points. Now there are hundreds if not thousands of access points in every city in the nation. And during the same time holes have been shot in all major wireless security protocols. People deploying wireless technologies are either unaware of the risk involved or have decided the productivity gain out weighs the ri....

A step by step guide to hardening a Solaris installation. Focusing primarily on Solaris 8 but with concepts that apply to all Solaris/Unix installs, attendees will learn the steps that need to be taken to lock down a Solaris installation. While recognizing the best practice of pre-deployment hardening, the concepts presented also apply to already live Solaris installations. Rather than focusing on known attacks and reacting to them, this pr....

A step by step guide to hardening a Solaris installation. Focusing primarily on Solaris 8 but with concepts that apply to all Solaris/Unix installs, attendees will learn the steps that need to be taken to lock down a Solaris installation. While recognizing the best practice of pre-deployment hardening, the concepts presented also apply to already live Solaris installations. Rather than focusing on known attacks and reacting to them, this pr....

Communication under TCP/IP networks has become extraordinarily popular; still, there remains significant problems that as of yet have remained unsolved within its layered rules. So, lets break the rules, elegance (and possibly security) be damned. Signficant new techniques and code will be unveiled to answer the following questions: A) Instant Portscan # Is it possible to discover instantaneously what network services have been made ava....

Communication under TCP/IP networks has become extraordinarily popular; still, there remains significant problems that as of yet have remained unsolved within its layered rules. So, lets break the rules, elegance (and possibly security) be damned. Signficant new techniques and code will be unveiled to answer the following questions: A) Instant Portscan # Is it possible to discover instantaneously what network services have been made ava....

Standard approaches to intrusion detection and response attempt to detect and prevent individual attacks. However, it is not the attack but rather the attacker against which our networks must be defended To do this, the information that is being provided by intrusion detect systems (IDS) must be gathered and then divided into its component parts such that the activity of individual attackers is made clear. By applying techniques from radar ....

Standard approaches to intrusion detection and response attempt to detect and prevent individual attacks. However, it is not the attack but rather the attacker against which our networks must be defended To do this, the information that is being provided by intrusion detect systems (IDS) must be gathered and then divided into its component parts such that the activity of individual attackers is made clear. By applying techniques from radar ....

DEF CON 10 was held August 2nd to the 4th at the Alexis Park Hotel and Resort in Las Vegas, Nevada, USA. . Past speeches and talks from DEF CON hacking conferences in an iTunes friendly m4v format. The DEFCON series of hacking conferences were started in 1993 to focus on both the technical and social trends in hacking, and has grown to be world known event. If you did not make it, or missed the speaker you wanted to see here is you ch..

DEF CON 10 was held August 2nd to the 4th at the Alexis Park Hotel and Resort in Las Vegas, Nevada, USA. . Past speeches and talks from DEF CON hacking conferences in an iTunes friendly m4b format. The DEFCON series of hacking conferences were started in 1993 to focus on both the technical and social trends in hacking, and has grown to be world known event. If you did not make it, or missed the speaker you wanted to see here is you ch..

This presentation focuses on the ease with which many web application Session IDs can be brute-forced, allowing an attacker to hijack a legitimate web user's online session (e.g. Slashdot, Apache, Register.com, PHPNuke, etc.). While a somewhat narrow area of web application security, the simplicity of the attacks and the prevalence of these vulnerabilities on the Internet make this an important topic. Malicious users can easily try (usually....

This presentation focuses on the ease with which many web application Session IDs can be brute-forced, allowing an attacker to hijack a legitimate web user's online session (e.g. Slashdot, Apache, Register.com, PHPNuke, etc.). While a somewhat narrow area of web application security, the simplicity of the attacks and the prevalence of these vulnerabilities on the Internet make this an important topic. Malicious users can easily try (usually....

Like computers on large heterogeneous environments, networked printers and other peripherals have vulnerabilities that can lead to exposure of data, denial of service, and as a gateway for attacks on other systems. Yet, while many organizations seek to protect their computers, they ignore printers and other peripherals. We will discuss general attacks against printers and other peripherals, with specifics on known (and some newly discovered....

Like computers on large heterogeneous environments, networked printers and other peripherals have vulnerabilities that can lead to exposure of data, denial of service, and as a gateway for attacks on other systems. Yet, while many organizations seek to protect their computers, they ignore printers and other peripherals. We will discuss general attacks against printers and other peripherals, with specifics on known (and some newly discovered....

DEF CON 10 was held August 2nd to the 4th at the Alexis Park Hotel and Resort in Las Vegas, Nevada, USA. . Past speeches and talks from DEF CON hacking conferences in an iTunes friendly m4v format. The DEFCON series of hacking conferences were started in 1993 to focus on both the technical and social trends in hacking, and has grown to be world known event. If you did not make it, or missed the speaker you wanted to see here is you ch..

DEF CON 10 was held August 2nd to the 4th at the Alexis Park Hotel and Resort in Las Vegas, Nevada, USA. . Past speeches and talks from DEF CON hacking conferences in an iTunes friendly m4b format. The DEFCON series of hacking conferences were started in 1993 to focus on both the technical and social trends in hacking, and has grown to be world known event. If you did not make it, or missed the speaker you wanted to see here is you ch..

Windows .NET Server is Microsoft's new contender against Linux in the server market. Scheduled for release in 2003, .NET Server (which was originally released for beta testing under the codename "Whistler") is re-engineered from the Windows 2000 Server codebase. .NET Server's survival will probably depend on how users perceive its security. Bill Gates himself realized this when he released his "Trustworthy Computing" memo in Jan. 2002. His ....

Windows .NET Server is Microsoft's new contender against Linux in the server market. Scheduled for release in 2003, .NET Server (which was originally released for beta testing under the codename "Whistler") is re-engineered from the Windows 2000 Server codebase. .NET Server's survival will probably depend on how users perceive its security. Bill Gates himself realized this when he released his "Trustworthy Computing" memo in Jan. 2002. His ....

The brand-new technology of quantum computers offers the prospect of exponential speedup, making heretofore infeasible problems like cracking RSA conceiveable. The fundamentals of quantum computing are presented, and how a quantum computer could be used to crack RSA is described. Dr. Walter C. Daugherity is a Senior Lecturer in Computer Science and Electrical Engineering at Texas A&M University. He received a bachelor's degree from Okl..

Covert Channels in TCP and IP Headers How would you communicate securely in a country where encryption is outlawed or where key escrow is mandatory? How can you prevent the Feds from forcing you to turn over your encryption keys? Simple. Don't let your adversaries know that you're transmitting encrypted information. Using covert channels you can completely hide the fact that you're transmitting encrypted information. During this presen..

Covert Channels in TCP and IP Headers How would you communicate securely in a country where encryption is outlawed or where key escrow is mandatory? How can you prevent the Feds from forcing you to turn over your encryption keys? Simple. Don't let your adversaries know that you're transmitting encrypted information. Using covert channels you can completely hide the fact that you're transmitting encrypted information. During this presen..

DEF CON 10 was held August 2nd to the 4th at the Alexis Park Hotel and Resort in Las Vegas, Nevada, USA. . Past speeches and talks from DEF CON hacking conferences in an iTunes friendly m4v format. The DEFCON series of hacking conferences were started in 1993 to focus on both the technical and social trends in hacking, and has grown to be world known event. If you did not make it, or missed the speaker you wanted to see here is you ch..

DEF CON 10 was held August 2nd to the 4th at the Alexis Park Hotel and Resort in Las Vegas, Nevada, USA. . Past speeches and talks from DEF CON hacking conferences in an iTunes friendly m4b format. The DEFCON series of hacking conferences were started in 1993 to focus on both the technical and social trends in hacking, and has grown to be world known event. If you did not make it, or missed the speaker you wanted to see here is you ch..

This talk is primarily about psychology and relates to typical programming in no way. Neuro-Linguistic Programming is best described as new age pseudo science by some and the future of psychology to others. Through this talk on NLP you will learn about the ability to control and otherwise manipulate as well as teaching via "knowledge encoded linguistic algorithms." You should also gain the ability to do a "cold read." You will also lea..

This talk is primarily about psychology and relates to typical programming in no way. Neuro-Linguistic Programming is best described as new age pseudo science by some and the future of psychology to others. Through this talk on NLP you will learn about the ability to control and otherwise manipulate as well as teaching via "knowledge encoded linguistic algorithms." You should also gain the ability to do a "cold read." You will also lea..

This is a fingerprinting library designed to bring together the fingerprinting capabilities of NMAP, QueSO and X (at least version 1). Using this library you should be able to add operating system sensitive code to your favorite Perl, Java, C or C++ code. At the most basic level the goal of this library is to provide a mechanism so that you can add code to your programs that reads if(OS.Family == Windows Family) { 'do something'} ....

This is a fingerprinting library designed to bring together the fingerprinting capabilities of NMAP, QueSO and X (at least version 1). Using this library you should be able to add operating system sensitive code to your favorite Perl, Java, C or C++ code. At the most basic level the goal of this library is to provide a mechanism so that you can add code to your programs that reads if(OS.Family == Windows Family) { 'do something'} ....

Servers, workstations and PCs are the common targets of an average attacker, but there is much more to find in todays networks. Every device that has a processor, some memory and a network interface can become a target. Using printers and other common devices as examples, we will show how to exploit design failures and vulnerabilities and use the target as an attack platform. We will also release some tools, methods and sample code to enter..

Servers, workstations and PCs are the common targets of an average attacker, but there is much more to find in todays networks. Every device that has a processor, some memory and a network interface can become a target. Using printers and other common devices as examples, we will show how to exploit design failures and vulnerabilities and use the target as an attack platform. We will also release some tools, methods and sample code to enter..

The talk will cover current techniques used for picking locks such as mushroom pin tumblers, medeco, abloy, and tubular locks. The talk will also cover how to formulate attacks on new locks. I am a self taught hobbyist. I have five years experience in amateur locksmithing. I am currently attending a Canadian University as a Computer Science major.

The talk will cover current techniques used for picking locks such as mushroom pin tumblers, medeco, abloy, and tubular locks. The talk will also cover how to formulate attacks on new locks. I am a self taught hobbyist. I have five years experience in amateur locksmithing. I am currently attending a Canadian University as a Computer Science major.

Wolves Among Us GOBBLES Security members will be giving a presentation called "Wolves Among Us", which will discuss the evil motivations of certain members and organizations of the security industry, the big companies that are underqualified for security and yet reap such incredible revenue for their services, the way the media is uninformed and further intentionally writes incorrect information concerning hackers, and more. Concrete e..

Wolves Among Us GOBBLES Security members will be giving a presentation called "Wolves Among Us", which will discuss the evil motivations of certain members and organizations of the security industry, the big companies that are underqualified for security and yet reap such incredible revenue for their services, the way the media is uninformed and further intentionally writes incorrect information concerning hackers, and more. Concrete e..

DOC has had the privilege of working on a project that was focused on looking at new product technologies relating to DOS and DDOS mitigation. Several commercial companies were formed who's entire focus was to find solutions to DOS and DDOS issues. Different types of detection were used in each product from pure rate analysis to statistical analysis and anomaly detection. This talk will focus on the testing methodology, testing results, les....

DOC has had the privilege of working on a project that was focused on looking at new product technologies relating to DOS and DDOS mitigation. Several commercial companies were formed who's entire focus was to find solutions to DOS and DDOS issues. Different types of detection were used in each product from pure rate analysis to statistical analysis and anomaly detection. This talk will focus on the testing methodology, testing results, les....

35 visitors online