Site uses cookies to provide basic functionality.
Javascript rendering is set to off by default when visiting the site via .onion and .i2p domains. It can be enabled back again in user's settings section. Javascript rendering set to off means, that you can disable javascript in your browser now and the site will remain functional.
There is also IRC server now available via native IRC clients or non javascript web based one.
Fonts can be adjusted in user's settings section as well.
Check FAQ for more.

OK

Selling Out For Fun and Profit Recent events in the security industry have caused multiple groups to cry foul and claim that many so called hackers have sold out. A war of words has errupted between those crying foul and those who have apparently sold out. Most recently, Gweeds presented a talk at H2K2 that touched on many nerves when he pointed fingers at specific people in the security industry. While the talk given by Gweeds wa....

Selling Out For Fun and Profit Recent events in the security industry have caused multiple groups to cry foul and claim that many so called hackers have sold out. A war of words has errupted between those crying foul and those who have apparently sold out. Most recently, Gweeds presented a talk at H2K2 that touched on many nerves when he pointed fingers at specific people in the security industry. While the talk given by Gweeds wa....

The talk will discuss the backgroup, current architecture and use the LIDS. And also will talk about what kind of attacks LIDS can detect and prevent and finally will get into details how to build a secure linux system with LIDS. Huagang Xie, the author of the open source (GPL) LIDS project, is a kernel hacker and linux enthusiast. Gradudated from Tsinghua University and Insititue of Computing Techology of Chinese Academy of Sciences,h..

The talk will discuss the backgroup, current architecture and use the LIDS. And also will talk about what kind of attacks LIDS can detect and prevent and finally will get into details how to build a secure linux system with LIDS. Huagang Xie, the author of the open source (GPL) LIDS project, is a kernel hacker and linux enthusiast. Gradudated from Tsinghua University and Insititue of Computing Techology of Chinese Academy of Sciences,h..

IDSs have traditionally been seen as purely information resources, requiring human intervention in order to act on alerts. Recently, support for modifying firewall rules and killing active connections have begun to appear in IDSs, but these suffer from shortcomings. A desire has been recently expressed by many people for an active, 'Gateway' IDS (GIDS), allowing filtering and routing of traffic to be performed by a gateway computer using bo..

IDSs have traditionally been seen as purely information resources, requiring human intervention in order to act on alerts. Recently, support for modifying firewall rules and killing active connections have begun to appear in IDSs, but these suffer from shortcomings. A desire has been recently expressed by many people for an active, 'Gateway' IDS (GIDS), allowing filtering and routing of traffic to be performed by a gateway computer using bo..

Citrix and Terminal Services are becoming very popular. Ian Vitek will speak about: # Scanning and finding Terminal Services and Published Applications. This will include statistics of open and vulnerable servers. # Connection to Published Applications. This can be harder than you think. Most of the servers have Published Applications. You can’t just see them. # Breaking out from the given environment and elevation of rights. # Demo..

Citrix and Terminal Services are becoming very popular. Ian Vitek will speak about: # Scanning and finding Terminal Services and Published Applications. This will include statistics of open and vulnerable servers. # Connection to Published Applications. This can be harder than you think. Most of the servers have Published Applications. You can’t just see them. # Breaking out from the given environment and elevation of rights. # Demo..

A prudent System Administrator will review system logs. While performing this log analysis, administrators may detect nefarious activity of various types (port probes, exploit attempts, DOS/DDOS). Of course, what you receive in the system logs doesn't contain the offender's name and telephone number. Rather, most Firewalls and Intrusion Detection Systems will log an IP address, or at best, a reverse DNS lookup of the IP address. This presen....

A prudent System Administrator will review system logs. While performing this log analysis, administrators may detect nefarious activity of various types (port probes, exploit attempts, DOS/DDOS). Of course, what you receive in the system logs doesn't contain the offender's name and telephone number. Rather, most Firewalls and Intrusion Detection Systems will log an IP address, or at best, a reverse DNS lookup of the IP address. This presen....

The Unix FTP servers have been called 'the IIS of the Unix world' for their frequent and potent vulnerabilities. Each has provided remote exploits, usually at the root privilege level, on a consistent and frequent basis. WU-FTPd is the most popular Unix FTP server by far, shipping by default on most Linux distributions, and even on Solaris, and being installed most commonly on the rest of the Unix platforms. This talk will demonstrate worki....

The Unix FTP servers have been called 'the IIS of the Unix world' for their frequent and potent vulnerabilities. Each has provided remote exploits, usually at the root privilege level, on a consistent and frequent basis. WU-FTPd is the most popular Unix FTP server by far, shipping by default on most Linux distributions, and even on Solaris, and being installed most commonly on the rest of the Unix platforms. This talk will demonstrate worki....

Bastille Linux is a security tightening program that has proven capable of thwarting or containing many of the vulnerabilities discovered in operating systems. Originally written for Red Hat Linux, Bastille has now been ported to six operating systems, including HP-UX. This talk will talk about what Bastille does, what we've done to it in the last year, and what we're working on next. Most importantly, it will teach you something about hard....

Bastille Linux is a security tightening program that has proven capable of thwarting or containing many of the vulnerabilities discovered in operating systems. Originally written for Red Hat Linux, Bastille has now been ported to six operating systems, including HP-UX. This talk will talk about what Bastille does, what we've done to it in the last year, and what we're working on next. Most importantly, it will teach you something about hard....

This DefCon10 presentation, while drawing from the study, will discuss the implications of employing hackers in the work place. The book Hacking of America (Greenwood, 2002) reports on the Laurentian University study of the hacker community and in particular the conference participants of DefCon8 and H2K. The study data was collected though a 20 page self-report questionnaire completed by hackers at these conferences. It was also supplement....

This DefCon10 presentation, while drawing from the study, will discuss the implications of employing hackers in the work place. The book Hacking of America (Greenwood, 2002) reports on the Laurentian University study of the hacker community and in particular the conference participants of DefCon8 and H2K. The study data was collected though a 20 page self-report questionnaire completed by hackers at these conferences. It was also supplement....

I will show people how to secure different Windows servers using common sense and a variety of different tools. The fundamentals can be applied to any Windows server whether it is NT 4 / 2000 / .NET as well as IIS or Exchange. I will also walk people thru many good security tools that are a must have for any Windows server. I will actually secure a server at the talk that will later be placed on the CTF network. I will anounce a FTP locatio..

I will show people how to secure different Windows servers using common sense and a variety of different tools. The fundamentals can be applied to any Windows server whether it is NT 4 / 2000 / .NET as well as IIS or Exchange. I will also walk people thru many good security tools that are a must have for any Windows server. I will actually secure a server at the talk that will later be placed on the CTF network. I will anounce a FTP locatio..

Ken will talk about different types/implementations of community wireless networks. He will also discuss why companies in the industry like, dislike and do know what to make of the community wireless movement. Most importantly he will tell you why this movement is important and what role it has promoting privacy, community owned infrastructure, and peer to peer communications Ken Caruso is a co-founder of the Seattlewireless.net projec..

Ken will talk about different types/implementations of community wireless networks. He will also discuss why companies in the industry like, dislike and do know what to make of the community wireless movement. Most importantly he will tell you why this movement is important and what role it has promoting privacy, community owned infrastructure, and peer to peer communications Ken Caruso is a co-founder of the Seattlewireless.net projec..

SQL injection is a technique for exploiting web applications that use client-supplied data in SQL queries without stripping potentially harmful characters first. Despite being remarkably simple to protect against, there is an astonishing number of production systems connected to the Internet that are vulnerable to this type of attack. The objective of this talk is to educate the professional security community on the techniques that can be ....

SQL injection is a technique for exploiting web applications that use client-supplied data in SQL queries without stripping potentially harmful characters first. Despite being remarkably simple to protect against, there is an astonishing number of production systems connected to the Internet that are vulnerable to this type of attack. The objective of this talk is to educate the professional security community on the techniques that can be ....

The Trusted Computing Platform Alliance, which includes Intel, AMD, HP, Microsoft, and 180 additional PC platform product vendors, has been working in secrecy for 3 years to develop a chip which will begin shipping mounted on new PC motherboards starting early next year. This tamper-resistant Trusted Platform Module (TPM) will enable operating system and application vendors to ensure that the owner of the motherboard will never again b....

The Trusted Computing Platform Alliance, which includes Intel, AMD, HP, Microsoft, and 180 additional PC platform product vendors, has been working in secrecy for 3 years to develop a chip which will begin shipping mounted on new PC motherboards starting early next year. This tamper-resistant Trusted Platform Module (TPM) will enable operating system and application vendors to ensure that the owner of the motherboard will never again b....

The topic of the talk will be covering both high security locks, and access control products. The locks covered will be including, Medeco, Mul-T-Lock, Assa, Fichet, Concept, Miwa and others. The access control technology will cover, Proximity cards, Mag stripe cards, Biometrics, keypad technology, and others. Questions will be answered on other topics, such as safes, standard locks, lock picking, CCTV, computer security, and other secu..

The topic of the talk will be covering both high security locks, and access control products. The locks covered will be including, Medeco, Mul-T-Lock, Assa, Fichet, Concept, Miwa and others. The access control technology will cover, Proximity cards, Mag stripe cards, Biometrics, keypad technology, and others. Questions will be answered on other topics, such as safes, standard locks, lock picking, CCTV, computer security, and other secu..

Steganographic Trojans As anti-virus manufacturers develop more efficient techniques for stopping an infection, potential attackers must become more cunning and resourceful in their deployment methodologies; they must create "invisible" code...but how? What are the possibilities of developing an invisible virus or Trojan? The purpose of this talk is to explain the research we have collected, and to identify potential distribution ..

You can have a lot of fun with the Internet by ditching your browser in favor of writing special purpose programs that look for -- or do -- very specific things on the Internet. This session will equip you with techniques to extract and interact with data from web sites without a browser, parse and filter data, follow links, deal with encryption and passwords, and manage terabytes of information. You'll also learn why writing these programs..

Steganographic Trojans As anti-virus manufacturers develop more efficient techniques for stopping an infection, potential attackers must become more cunning and resourceful in their deployment methodologies; they must create "invisible" code...but how? What are the possibilities of developing an invisible virus or Trojan? The purpose of this talk is to explain the research we have collected, and to identify potential distribution ..

You can have a lot of fun with the Internet by ditching your browser in favor of writing special purpose programs that look for -- or do -- very specific things on the Internet. This session will equip you with techniques to extract and interact with data from web sites without a browser, parse and filter data, follow links, deal with encryption and passwords, and manage terabytes of information. You'll also learn why writing these programs..

Centralized event-logging and automated intrusion detection are required tools for good network security. But what can you do to prevent your loggers and IDS probes from falling victim to the same attacks they're supposed to warn you about? As it happens, one cool thing you can do is run such systems without IP addresses. In my presentation I'll describe the benefits and drawbacks of this technique, and demonstrate how it can be used in con..

Centralized event-logging and automated intrusion detection are required tools for good network security. But what can you do to prevent your loggers and IDS probes from falling victim to the same attacks they're supposed to warn you about? As it happens, one cool thing you can do is run such systems without IP addresses. In my presentation I'll describe the benefits and drawbacks of this technique, and demonstrate how it can be used in con..

N Stage Biometric Authentication The topic will be about using biometric authentication as part of a multiple stage authentication mechanism. This discussion will explore various applications and flaws with the technology along with some of my ongoing research into a replay attack on the devices by capturing what "goes down the wire". I am a sophomore at the University of Nebraska at Omaha working towards a degreee in computer sci..

N Stage Biometric Authentication The topic will be about using biometric authentication as part of a multiple stage authentication mechanism. This discussion will explore various applications and flaws with the technology along with some of my ongoing research into a replay attack on the devices by capturing what "goes down the wire". I am a sophomore at the University of Nebraska at Omaha working towards a degreee in computer sci..

Our talk will cover the (in)security of layer 2 protocols (CDP, xTP, HSRP, VRRP, VLANs, etc) and its consequences. We will also discuss routing protocols attacks and how to (try to) protect your infrastructure. The architecture, security, secure management and forensics of routers and switches will also be covered. This last part of the talk will be complementary to the presentation from FX of Phenoelit. Nicolas Fischbach is managing t....

Our talk will cover the (in)security of layer 2 protocols (CDP, xTP, HSRP, VRRP, VLANs, etc) and its consequences. We will also discuss routing protocols attacks and how to (try to) protect your infrastructure. The architecture, security, secure management and forensics of routers and switches will also be covered. This last part of the talk will be complementary to the presentation from FX of Phenoelit. Nicolas Fischbach is managing t....

Xprobe, written and maintained by Fyodor Yarochkin & Ofir Arkin, is an active operating system fingerprinting tool based on Ofir Arkin's "ICMP Usage in Scanning" research project (http://www.sys-security.com). Last year at the Blackhat briefings, July 2001, the first generation of Xprobe was released. The tool's first generation (Xprobe v0.0.1) relies on a hard coded static-based logic tree. Although it has a lot of advantages (1-4 pac....

Michael Morgenstern will be leading a panel comprised of several individuals from the 'other side' of Information Security. Panel highlights will include: # An overview on vulnerability disclosure in the past # Potential impacts of irresponsible disclosure # New threats (Does cyber terrorism exist?) # The vulnerability disclosure "food chain" # The issues involved in the handling of a new vulnerability, from the perspective of a c..

Xprobe, written and maintained by Fyodor Yarochkin & Ofir Arkin, is an active operating system fingerprinting tool based on Ofir Arkin's "ICMP Usage in Scanning" research project (http://www.sys-security.com). Last year at the Blackhat briefings, July 2001, the first generation of Xprobe was released. The tool's first generation (Xprobe v0.0.1) relies on a hard coded static-based logic tree. Although it has a lot of advantages (1-4 pac....

Michael Morgenstern will be leading a panel comprised of several individuals from the 'other side' of Information Security. Panel highlights will include: # An overview on vulnerability disclosure in the past # Potential impacts of irresponsible disclosure # New threats (Does cyber terrorism exist?) # The vulnerability disclosure "food chain" # The issues involved in the handling of a new vulnerability, from the perspective of a c..

Security is a problem of trust. Having a system that offers services to Internet and that can be trusted is very hard to achieve. Classical security models focus on the physical limit of the machine. We will see that it can be interesting to move the trust limit between user space and kernel space and that it is still possible to enforce a security policy from this trusted place. We will also see some practical aspects with a review of some..

DEF CON 10 was held August 2nd to the 4th at the Alexis Park Hotel and Resort in Las Vegas, Nevada, USA. . Past speeches and talks from DEF CON hacking conferences in an iTunes friendly m4v format. The DEFCON series of hacking conferences were started in 1993 to focus on both the technical and social trends in hacking, and has grown to be world known event. If you did not make it, or missed the speaker you wanted to see here is you ch..

DEF CON 10 was held August 2nd to the 4th at the Alexis Park Hotel and Resort in Las Vegas, Nevada, USA. . Past speeches and talks from DEF CON hacking conferences in an iTunes friendly m4b format. The DEFCON series of hacking conferences were started in 1993 to focus on both the technical and social trends in hacking, and has grown to be world known event. If you did not make it, or missed the speaker you wanted to see here is you ch..

The telephony industry was late to adopt open-source software and commodity protocols. The open-source development community is rapidly correcting that problem. Everyone from enthusiasts to Fortune 500 companies are now deploying open-source telephony software, from PBX's to voice messaging systems to VoIP gateways. This lecture will focus on the practical. We'll provide demos of the major open-source telephony systems, a brief tutorial on ....

93 visitors online