Site uses cookies to provide basic functionality.
Javascript rendering is set to off by default when visiting the site via .onion and .i2p domains. It can be enabled back again in user's settings section. Javascript rendering set to off means, that you can disable javascript in your browser now and the site will remain functional.
There is also IRC server now available via native IRC clients or non javascript web based one.
Fonts can be adjusted in user's settings section as well.
Check FAQ for more.

OK

Making Fun of Your Malware Michael Ligh Malicious Code Analyst, iDefense Matthew Richard Malicious Code Operations Lead, Raytheon Corporation Would you laugh if you saw a bank robber accidentally put his mask on backwards and fall into a man hole during the getaway, because he couldn't tell where he was going? Criminals do ridiculous things so often, its impossible to capture them all on video. Rest assured, when the criminals are ....

Screen Scraper Tricks: Extracting Data from Difficult Websites Michael Schrenk Screen scrapers and data mining bots often encounter problems when extracting data from modern websites. Obstacles like AJAX discourage many bot writers from completing screen scraping projects. The good news is that you can overcome most challenges if you learn a few tricks. This session describes the (sometimes mind numbing) roadblocks that can come....

Screen Scraper Tricks: Extracting Data from Difficult Websites Michael Schrenk Screen scrapers and data mining bots often encounter problems when extracting data from modern websites. Obstacles like AJAX discourage many bot writers from completing screen scraping projects. The good news is that you can overcome most challenges if you learn a few tricks. This session describes the (sometimes mind numbing) roadblocks that can come....

Screen Scraper Tricks: Extracting Data from Difficult Websites Michael Schrenk Screen scrapers and data mining bots often encounter problems when extracting data from modern websites. Obstacles like AJAX discourage many bot writers from completing screen scraping projects. The good news is that you can overcome most challenges if you learn a few tricks. This session describes the (sometimes mind numbing) roadblocks that can come....

CSRF: Yeah, It Still Works Mike "mckt" Bailey ASS Russ McRee ASS Bad News: CSRF is nasty, it's everywhere, and you can't stop it on the client side. Good News: It can do neat things. CSRF is likely amongst the lamest security bugs available, as far as "cool" bugs go. In essence, the attack forces another user's browser to do something on your behalf. If that user is an authenticated user or an administrator on a....

CSRF: Yeah, It Still Works Mike "mckt" Bailey ASS Russ McRee ASS Bad News: CSRF is nasty, it's everywhere, and you can't stop it on the client side. Good News: It can do neat things. CSRF is likely amongst the lamest security bugs available, as far as "cool" bugs go. In essence, the attack forces another user's browser to do something on your behalf. If that user is an authenticated user or an administrator on a....

CSRF: Yeah, It Still Works Mike "mckt" Bailey ASS Russ McRee ASS Bad News: CSRF is nasty, it's everywhere, and you can't stop it on the client side. Good News: It can do neat things. CSRF is likely amongst the lamest security bugs available, as far as "cool" bugs go. In essence, the attack forces another user's browser to do something on your behalf. If that user is an authenticated user or an administrator on a....

Criminal Charges are not pursued: Hacking PKI Mike Zusman Intrepidus Group From the night of Friday to Saturday at the 20 of December a new subscriber named Mike Zusman registered at the CA site. Subsequently he succeeded in overcoming the domain validation interface by validating for domains not under his control." - Critical Event Report The last year has been a rough one for SSL PKI. Fraudulently provisioned certificates, MD5....

Criminal Charges are not pursued: Hacking PKI Mike Zusman Intrepidus Group From the night of Friday to Saturday at the 20 of December a new subscriber named Mike Zusman registered at the CA site. Subsequently he succeeded in overcoming the domain validation interface by validating for domains not under his control." - Critical Event Report The last year has been a rough one for SSL PKI. Fraudulently provisioned certificates, MD5....

Criminal Charges are not pursued: Hacking PKI Mike Zusman Intrepidus Group From the night of Friday to Saturday at the 20 of December a new subscriber named Mike Zusman registered at the CA site. Subsequently he succeeded in overcoming the domain validation interface by validating for domains not under his control." - Critical Event Report The last year has been a rough one for SSL PKI. Fraudulently provisioned certificates, MD5....

More Tricks For Defeating SSL Moxie Marlinspike This talk aims to pick up where SSL stripping left off. While sslstrip ultimately remains quite deadly in practice, this talk will demonstrate some new tricks for defeating SSL/TLS in places where sslstrip does not reach. Cautious users, for example, have been advised to explicitly visit https URLs or to use bookmarks in order to protect themselves from sslstrip, while other SSL/TLS bas..

More Tricks For Defeating SSL Moxie Marlinspike This talk aims to pick up where SSL stripping left off. While sslstrip ultimately remains quite deadly in practice, this talk will demonstrate some new tricks for defeating SSL/TLS in places where sslstrip does not reach. Cautious users, for example, have been advised to explicitly visit https URLs or to use bookmarks in order to protect themselves from sslstrip, while other SSL/TLS bas..

More Tricks For Defeating SSL Moxie Marlinspike This talk aims to pick up where SSL stripping left off. While sslstrip ultimately remains quite deadly in practice, this talk will demonstrate some new tricks for defeating SSL/TLS in places where sslstrip does not reach. Cautious users, for example, have been advised to explicitly visit https URLs or to use bookmarks in order to protect themselves from sslstrip, while other SSL/TLS bas..

Advanced MySQL Exploitation Muhaimin Dzulfakar Security Consultant, security-assessment.com This talk focuses on how MySQL SQL injection vulnerabilities can be used to gain remote code execution on the LAMP and WAMP environments. Attackers performing SQL injection on a MySQL platform must deal with several limitations and constraints. For example, the lack of multiple statements in one query makes MySQL an unpopular platform for remo....

Advanced MySQL Exploitation Muhaimin Dzulfakar Security Consultant, security-assessment.com This talk focuses on how MySQL SQL injection vulnerabilities can be used to gain remote code execution on the LAMP and WAMP environments. Attackers performing SQL injection on a MySQL platform must deal with several limitations and constraints. For example, the lack of multiple statements in one query makes MySQL an unpopular platform for remo....

Advanced MySQL Exploitation Muhaimin Dzulfakar Security Consultant, security-assessment.com This talk focuses on how MySQL SQL injection vulnerabilities can be used to gain remote code execution on the LAMP and WAMP environments. Attackers performing SQL injection on a MySQL platform must deal with several limitations and constraints. For example, the lack of multiple statements in one query makes MySQL an unpopular platform for remo....

Hacking Sleep: How to Build Your Very Own Sleep Lab Ne0nRa1n Researcher Keith Biddulph Researcher What is sleep? What happens when we don't get enough of it? Can it be hacked? Now that electronics are cheaper and more portable than ever before, a new generation of hackers have found themselves with the ability to build their own machines to measure and analyze the human body in ways only available to universities and hospitals in t....

Hacking Sleep: How to Build Your Very Own Sleep Lab Ne0nRa1n Researcher Keith Biddulph Researcher What is sleep? What happens when we don't get enough of it? Can it be hacked? Now that electronics are cheaper and more portable than ever before, a new generation of hackers have found themselves with the ability to build their own machines to measure and analyze the human body in ways only available to universities and hospitals in t....

Hacking Sleep: How to Build Your Very Own Sleep Lab Ne0nRa1n Researcher Keith Biddulph Researcher What is sleep? What happens when we don't get enough of it? Can it be hacked? Now that electronics are cheaper and more portable than ever before, a new generation of hackers have found themselves with the ability to build their own machines to measure and analyze the human body in ways only available to universities and hospitals in t....

Malware Freak Show Nicholas J. Percoco Vice President of SpiderLabs, Trustwave Jibran Ilyas Senior Forensic Investigator, SpiderLabs, Trustwave We see a lot of compromised environments every year. In 2008 alone, we performed full forensic investigations on over 150 different environments ranging from financial institutions, hotels, restaurants and even some casinos not too far from DEFCON. This presentation will show the inner work....

Malware Freak Show Nicholas J. Percoco Vice President of SpiderLabs, Trustwave Jibran Ilyas Senior Forensic Investigator, SpiderLabs, Trustwave We see a lot of compromised environments every year. In 2008 alone, we performed full forensic investigations on over 150 different environments ranging from financial institutions, hotels, restaurants and even some casinos not too far from DEFCON. This presentation will show the inner work....

Win at Reversing: Tracing and Sandboxing through Inline Hooking Nick Harbour Principal Consultant, Mandiant This presentation will discuss a new free tool for Reverse Engineering called API Thief, the "I Win" button for malware analysis. The unique way the tool operates will be explored as well as how it is able to provide better quality data than other tracing tools currently available. Advanced usage of the tool for malware analysi....

Win at Reversing: Tracing and Sandboxing through Inline Hooking Nick Harbour Principal Consultant, Mandiant This presentation will discuss a new free tool for Reverse Engineering called API Thief, the "I Win" button for malware analysis. The unique way the tool operates will be explored as well as how it is able to provide better quality data than other tracing tools currently available. Advanced usage of the tool for malware analysi....

Win at Reversing: Tracing and Sandboxing through Inline Hooking Nick Harbour Principal Consultant, Mandiant This presentation will discuss a new free tool for Reverse Engineering called API Thief, the "I Win" button for malware analysis. The unique way the tool operates will be explored as well as how it is able to provide better quality data than other tracing tools currently available. Advanced usage of the tool for malware analysi....

DEFCON 101 HighWiz, The Dark Tangent, Russr, DJ Jackalope, Deviant Ollam, Thorn, ThePrez98, LosT, Noid, Siviak What is DefCon 101? With the ever expanding landscape of DefCon: the amount of Games and Contests, the Parties, the Villages, the vast array of Art and Music... All that is going on and to do can be quite daunting to New People beginning their first DefConian adventure. There are even many long time DefCon attendees who....

DEFCON 101 HighWiz, The Dark Tangent, Russr, DJ Jackalope, Deviant Ollam, Thorn, ThePrez98, LosT, Noid, Siviak What is DefCon 101? With the ever expanding landscape of DefCon: the amount of Games and Contests, the Parties, the Villages, the vast array of Art and Music... All that is going on and to do can be quite daunting to New People beginning their first DefConian adventure. There are even many long time DefCon attendees who....

DEFCON 101 HighWiz, The Dark Tangent, Russr, DJ Jackalope, Deviant Ollam, Thorn, ThePrez98, LosT, Noid, Siviak What is DefCon 101? With the ever expanding landscape of DefCon: the amount of Games and Contests, the Parties, the Villages, the vast array of Art and Music... All that is going on and to do can be quite daunting to New People beginning their first DefConian adventure. There are even many long time DefCon attendees who....

Hardware Black Magic - Building devices with FPGAs Dr. Fouad Kiamilev Professor, Electrical and Computer Engineering Department, University of Delaware Rodney McGee Researcher, Electrical and Computer Engineering Department, University of Delaware Last year at the HHV we rolled into town full of goodies in our bags. To excite people about hardware we demoed and gave away some FPGA boards to those in attendance. We realized quickly ....

Hardware Black Magic - Building devices with FPGAs Dr. Fouad Kiamilev Professor, Electrical and Computer Engineering Department, University of Delaware Rodney McGee Researcher, Electrical and Computer Engineering Department, University of Delaware Last year at the HHV we rolled into town full of goodies in our bags. To excite people about hardware we demoed and gave away some FPGA boards to those in attendance. We realized quickly ....

Hardware Black Magic - Building devices with FPGAs Dr. Fouad Kiamilev Professor, Electrical and Computer Engineering Department, University of Delaware Rodney McGee Researcher, Electrical and Computer Engineering Department, University of Delaware Last year at the HHV we rolled into town full of goodies in our bags. To excite people about hardware we demoed and gave away some FPGA boards to those in attendance. We realized quickly ....

Metasploit Evolved H.D. Moore Metasploit has continuously evolved since its inception in 2003, switching focuses, development teams, licenses, and languages as the demands of the security community changed. This talk focuses on the organizational and development changes that have taken place over the last year and where things are headed in the future. This briefly touches on the dozens of new features and technologies that have been....

Metasploit Evolved H.D. Moore Metasploit has continuously evolved since its inception in 2003, switching focuses, development teams, licenses, and languages as the demands of the security community changed. This talk focuses on the organizational and development changes that have taken place over the last year and where things are headed in the future. This briefly touches on the dozens of new features and technologies that have been....

Metasploit Evolved H.D. Moore Metasploit has continuously evolved since its inception in 2003, switching focuses, development teams, licenses, and languages as the demands of the security community changed. This talk focuses on the organizational and development changes that have taken place over the last year and where things are headed in the future. This briefly touches on the dozens of new features and technologies that have been....

Injecting Electromagnetic Pulses into Digital Devices Paul F. Renda Data Security Analyst, Futurist This talk is not about someone on the ground firing a ray gun at a jet and bringing it down, this talk is about someone on the jet injecting EMP in the wiring system of the jet and causing great problems with the aviation systems and the black box. I will define smart and dumb digital devices based to how they respond to injected pulse....

Injecting Electromagnetic Pulses into Digital Devices Paul F. Renda Data Security Analyst, Futurist This talk is not about someone on the ground firing a ray gun at a jet and bringing it down, this talk is about someone on the jet injecting EMP in the wiring system of the jet and causing great problems with the aviation systems and the black box. I will define smart and dumb digital devices based to how they respond to injected pulse....

Injecting Electromagnetic Pulses into Digital Devices Paul F. Renda Data Security Analyst, Futurist This talk is not about someone on the ground firing a ray gun at a jet and bringing it down, this talk is about someone on the jet injecting EMP in the wiring system of the jet and causing great problems with the aviation systems and the black box. I will define smart and dumb digital devices based to how they respond to injected pulse....

Attacks Against 2wire Residential Gateways Pedro "hkm" Joaquin Some time ago there was a vulnerability in 2wire residential routers that allowed DNS Poisoning via Cross Site Request Forgery, this was widely exploited in Mexico where this router is most commonly used. The patch actually contained an Authentication Bypass vulnerability that made things worse, and now, after the patch got patched, there are still many public unpatc....

Smashing the Stack with Hydra: The Many Heads of Advanced Polymorphic Shellcode Pratap Prabhu Research Assistant, Columbia University Yingbo Song Research Assistant, Columbia University Salvatore. J. Stolfo Professor of Computer Science, Columbia University Recent work on the analysis of polymorphic shellcode engines suggests that modern obfuscation methods would soon eliminate the usefulness of signature-based network intrusion ....

Smashing the Stack with Hydra: The Many Heads of Advanced Polymorphic Shellcode Pratap Prabhu Research Assistant, Columbia University Yingbo Song Research Assistant, Columbia University Salvatore. J. Stolfo Professor of Computer Science, Columbia University Recent work on the analysis of polymorphic shellcode engines suggests that modern obfuscation methods would soon eliminate the usefulness of signature-based network intrusion ....

Smashing the Stack with Hydra: The Many Heads of Advanced Polymorphic Shellcode Pratap Prabhu Research Assistant, Columbia University Yingbo Song Research Assistant, Columbia University Salvatore. J. Stolfo Professor of Computer Science, Columbia University Recent work on the analysis of polymorphic shellcode engines suggests that modern obfuscation methods would soon eliminate the usefulness of signature-based network intrusion ....

Maximum CTF: Getting the Most Out of Capture the Flag Psifertex Among all the amazing Defcon competitions, the Capture the Flag contest reigns supreme. Psifertex will examine some of the history of CTF, focusing on the reign of terror pwnage that was the Kenshoto CTF from 2005-2008. The talk will both be technical (including rapid-fire discussions of technical challenges and solutions), and entertaining (expect guest appearances from....

Maximum CTF: Getting the Most Out of Capture the Flag Psifertex Among all the amazing Defcon competitions, the Capture the Flag contest reigns supreme. Psifertex will examine some of the history of CTF, focusing on the reign of terror pwnage that was the Kenshoto CTF from 2005-2008. The talk will both be technical (including rapid-fire discussions of technical challenges and solutions), and entertaining (expect guest appearances from....

Maximum CTF: Getting the Most Out of Capture the Flag Psifertex Among all the amazing Defcon competitions, the Capture the Flag contest reigns supreme. Psifertex will examine some of the history of CTF, focusing on the reign of terror pwnage that was the Kenshoto CTF from 2005-2008. The talk will both be technical (including rapid-fire discussions of technical challenges and solutions), and entertaining (expect guest appearances from....

USB Attacks: Fun with Plug&0wn Rafael Dominguez Vega Security Researcher How many times have you been handed a USB device and asked to copy a presentation or spreadsheet onto it? Often our biggest concern is around whether the device will be lost along with our company projections or takeover proposals. However, should we be more concerned about whether the device itself can be used to attack us and gain access to our system. In....

4 visitors online