Site uses cookies to provide basic functionality.
Javascript rendering is set to off by default when visiting the site via .onion and .i2p domains. It can be enabled back again in user's settings section. Javascript rendering set to off means, that you can disable javascript in your browser now and the site will remain functional.
There is also IRC server now available via native IRC clients or non javascript web based one.
Fonts can be adjusted in user's settings section as well.
Check FAQ for more.

OK

On even a moderately sized network, activity can easily reach the order of millions, perhaps billions, of packets. Hidden in this sea of data is malicious activity. Current network analysis and monitoring tools primarily use text and simple charting to present information. These methods, while effective in some circumstances, can overwhelm the analyst with too much, or the wrong type of, information. This situation is worsened by today's al....

Phreaking in the age of Voice Over IP? What the hell is Voice Over IP? If you're asking this question and you'reinterested in phones and thought phreaking was dead back in the early "80s when blueboxing died, or 2002 when ATandT killed redboxing on long distance calls then this is the speech for you. Or if you know what VoIP is but want to know how the hell it has any impact on phreaking you should also attend. This talk intends to ed....

Despite decades of evolution, Internet file transfer is still plagued with problems to which formalized solutions are either inadequate or nonexistent. Lack of server-side bandwidth often renders high demand content inaccessible (which we affectionately refer to as the Slashdot effect). When the ability of a single server to provide content is exceeded, manual mirror selection is often utilized, providing an unnecessary and often problemati....

The FCC, at Hollywood's request, has mandated a broadcast flag for high-definition digital television (HDTV). By July 2005, it will be unlawful to sell devices that don"t respond to a "do not copy" flag or that provide unencumbered high-definition digital outputs. The flag's "robustness" requirement will make it impossible to build an open-source HDTV version of the TiVo. This talk will demonstrate how these rules thwart user innovation, sh....

Continuing the research done in previous years on advanced protocol manipulation and the high speed evaluation of large network characteristics, this year's Black Ops of TCP/IP goes into new territory with a deep analysis of the Domain Name System. A core element of the TCP/IP application suite, it is everywhere and there is unexpected power contained within. * Interesting Facets of the Global DNS Architecture: A high speed scanner for....

Down with the RIAA is a look at the current state of the music business and where it is headed. The presentation uses statistics and facts to map out where the industry currently is and details the problems with the current model. After the problems with the current model are shown then the groundwork for the future of the music business is laid out showing how the recording industry is no longer needed. Included in the presentation is info....

The goal of Prometheus is to create an Open Source project that takes into account the inherent flaws in the Microsoft implementation of Alternate Data Streams (ADS) and uses those attributes to create a tool for increased security. The concept is similar to making lemonade from lemons. We"re taking an insecure component of the NTFS file system and creating a tool that will provide increased security. Russ and Grifter will be explaining and....

It seems that the major target of most online bugs is actually quite the same. Over and over again the uninspired, pop the box, seems to be what most writers are after. In this talk I will explore a bit of virus history in relation to goals, starting with older viral intentions, moving to what appears to be the intentions today and what possibly could be the intentions tomorrow. This talk will be fairly abstract and I will setup t....

The boundaries between network access control devices and network monitoring devices are steadily becomming blured. Network intrusion detection systems are moving into the realm of not only monitoring network traffic, but also modifying it either through dynamic reconfiguration of firewall rulesets, spoofed session-busting traffic, or outright alteration of application layer data (ala Snort_inline). Firewalls themselves are also getting sma....

The Electronic Frontier Foundation (EFF) is one of the premiere digital liberties organizations in the world. We fight for freedom of expression on the Internet, the right for researchers and consumers to reverse-engineer their devices, expansion of the public domain, and electronic privacy and anonymity. On this panel, three representatives of EFF will discuss the latest developments in digital liberties, including free speech on the Inter....

Electronic Civil Disobedience and the Republican National Convention An introduction to the theory of hacktivism and the usage of hacking skills as a means of fighting for social justice by pressuring corporations and government to adopt progressive changes. Explores the history of electronic civil disobedience, tips on how to wage your own ECD campaigns, and how to participate in the upcoming actions to coincide with the protests agai....

The IPv6 Primer will encompass the basics of IPv6, including some of its roots, the transitioning mechanisms available, and some security concerns early adopters should be aware of in several different environments. This presentation is meant for anyone who has heard about IPv6, but would like to know the basics of the protocol and its implementation. Gene Cronk, CISSP, NSA-IAM, resides in Jacksonville, FL and is currently providing sy....

In a courtyard at CIA Headquarters stands an encrypted sculpture called Kryptos. Its thousands of characters contain encoded messages, three of which have been solved. The fourth part, 97 or 98 characters at the very bottom, have withstood cryptanalysis for over a decade. The artist who created Kryptos, James Sanborn, has also created other encrypted sculptures such as the decade-old Cyrillic Projector, which was cracked last September by a....

The search for a unified theory of everything in contemporary physics stems in part from the fundamental inability to reconcile quantum physics and relativity theory. This has pushed research toward complex mathematical models such as string theory in an effort to model a single way of looking at everything. The same can be said of the distribution of power in networks and hierarchies. The individual person looks like one kind of thing....

Do you think using Internet Telephony is more secure than a regular phone? Think again! Internet Telephony is becoming more common and those that think it is safer from wiretaps than regular phone communications are wrong. This presentation will demonstrate how to decrypt Net2Phone's dialed phone numbers, and playback fully reconstructed audio conversations from network packet captures. Included will be a demonstration of NetWitness 5.0's V....

Privacy doesnt mean the same thing to everyone... Since you"re interacting in a global space, you need to understand what people outside your immediate frame of reference are thinking when they talk about privacy because what they think will influence ttheir expectations and their actions. This talk will give you the opportunity to examine some other views of privacy, explore your own thinking, and compare it with others both from the globa..

Sun Tzu once stated, "Know your enemy and know yourself, and in a hundred battles you will never be defeated." By denying outsiders information about our systems and software, we make it more difficult to mount successful attacks. There are a wealth of options for OS-fingerprinting today, evolving from basic TCP-flag mangling tools such as Queso, through the ICMP quirk-detection of the original Xprobe, and the packet timing analysis of....

Recently, surveillance has become somewhat of a pop-culture fascination. From the Reality TV shows permeating every network's line up to the webcam phenomenon of the late 1990s, surveillance has become more a source of entertainment than ever before. Benjamin Franklin's quote, Those who would give up essential Liberty, to purchase a little temporary Safety, deserve neither Liberty nor Safety, has long served to exemplify the American, Big B....

The Hacker Foundation (THF) is a non-profit organization dedicated to establishing and maintaining a research and service organization to promote and explore the creative use of technological resources. Simply put, we want to help people do useful things with technology. This announcement is a formal launch of the foundation. There will be a brief statement about the foundation's goals, operations and how the foundation can work for you. ..

The windows GDI interface uses messages to pass input and events to windows. As there is currently no way of determining who the sender of the message is, it is possible for a low privileged application to send messages to and interact with a process of higher privilege. This presentation will cover in details some of the flaws exposed through these messages, and demonstrate how they can be exploited to conduct privilege escalation and..

Jason Scott of TEXTFILES.COM, a site dedicated to the history of Dial-Up Bulletin Board Systems, embarked on a quest to film an all-inclusive BBS documentary in 2001. What started out as a one-year project grew to three, and what started as a two-hour film will be a six-hour series. Thousands of miles of travel and 200 interviews later, the production is now nearing the end of editing and the release date. Jason tells you what he learned, w....

Since the introduction of metamorphic stealth in the computer virus world, it has been suggested that the method can also be used to protect any, even legitimate, code. The only downfall of this technique is that how the engine manipulates the code remains constant. This allows the original code to be obtained by using an optimizer. The next step for this stealth method is to create an engine that will change how the code in manipulated. Th..

When the Tables Turn Until now network security defences have largely been about building walls and fences around the network. This talk revolves around spiking those walls and electrifying those fences! During this talk we will highlight techniques (and tools) that can be used to turn the tables on prospective attackers with passive-Strike-Back. We will explore the possibilities across the assesment spectrum responding to the standard....

Hearken back to the days of yesterday, circa 1993, when men were men, the Internet "backbone" was T3 and run by ANS, and a few brave start-up companies around Washington D.C. were fighting the phone company and each other to build the "commercial" Internet. One of them, DIGEX, literally started out in the founder's basement in "92 and rapidly grew to be a major force in what ultimately became known as web hosting. DIGEX "invented" web hosti....

Automotive Networks This presentation provides an introduction to the electronic networks present on late model automobiles. These networks will be described loosely following the OSI model of networking. Common uses of these networks will be presented, and the privacy implications of some uses will be questioned. The presentation will conclude with an introduction to OpenOtto, a free software and hardware project implementing the netw..

NoSEBrEaK Defeating Honeynets Honeynets are one of the more recent toys in the white-hat arsenal. They are usually assumed to be hard to detect and attempts to detect or disable them can be unconditionally monitored. Sometimes it is even suggested that deploying honenets is a way to incerase security. We scrutinize this assumption and demonstrate a method how a host in a honeynet can be completely controlled by an attacker without any ....

Smart Cards are used all over the place in every day life. The unfortunate (or fortunate) side of Smart Cards is that most widely deployed systems don"t use any real security and rely mostly on obscurity. This presentation will discuss the different types of Smart Cards, exactly how to reverse engineer the protocols they use, and how to exploit their security weaknesses. For demonstration, we will look at GSM SIM Cards and San Diego Parking....

The Metasploit Framework has progressed from a simple network game to a powerful tool for administrators and security analysts alike. Over the past several months, the Framework has been enhanced with improved exploit techniques and a truly advanced suite of payloads. This presentation provides a background on what exploit frameworks are, what they can provide you, and why you should be using one. A live demonstration will highlight many of....

Everyday you"re right to privacy is being compromised! From security cameras, to illegal searches, to unauthorized monitoring you are being watched. You must protect yourself...and your rights. Using Identification Evasion, you can immediately strengthen your protections. I"ll discuss knowledge and countermeasures in the Computer and Real Worlds while presenting many great methods to turn the tables on surveillance. In addition to other in-....

VICE - Catch the Hookers! Rootkits are the backbone of software penetrations. They provide stealth and consistent access to a computer system. Rootkits employ technology for covert ex-filtration of data, IDS evasion, and anti-forensics. Rootkit technology is now incorporated into the most deadly of threats, network worms. Serious security professionals must understand rootkit technology in detail. Commercial anti-virus technology is wo....

Much software that promises "anonymity" fails to deliver, as witnessed by a succession of compromised file-trading networks, back-doored communications systems, overhyped vapornets, and insecure "improvements" on existing remailer networks. I"ll discuss a bunch of allegedly anonymous systems, and explain how a clever attacker can defeat each of them. Audience members will learn to recognize the warning signs of broken anonymity in anonymous..

This talk provides an overview of the RF-ID Smart-Labes, small labels on products with an embedded microchip and an antenna. Smart-Labes store product and serial-number, expiration date etc. and can be read from a distance. The Industry is planning to put these labels with an international product code on every product within the next decade, effectively replacing the old bar-code system. Some stores already use Smart-Labes, for exampl....

One of the most dangerous cybersecurity threats is ``control hijacking"" attacks, which hijack the control of a victim application, and execute arbitrary system calls assuming the identity of the victim program's effective user. These types of attacks are viperous because they do not require any special set-up and because production-mode programs with such vulnerabilities appear to be wide spread. System call monitoring has been toute....

The "Type II" remailer network has been operating since 1995, providing strong anonymity email services to the public. We recently performed an analysis of the anonymity provided by the two independent implementations of the Type II protocol. This is joint work with Claudia Diaz and Evelyne Dewitte, to be presented at the ESORICS conference in September. This talk will discuss the methods used to evaluate the anonymity provided by Mixm....

From the same crazy folks who brought you Airsnort, Airsnarf, Bluesniff, Fine Tooth Comb, HotspotDK, and yes, the HackerBot, comes the annual deluge of wireless wackiness. The Shmoo Group takes a break from beer, Root-Fu, and their constant media-whore campaign to just give Shmoo shtuff away, and it's all wireless-related for you RF rogues. Updated hardware. Updated software. Blah, blah, same old boring sh WAIT! What's this?! NEW hardware? ....

CryptoMail Encrypted E-Mail for All (Including Grandma) Four years ago, CryptoMail introduced the first secure open source web based email solution. System administrators and hostile parties no longer had the ability to read a users email. With functionality similar to Hushmail, the world was introduced to an open source solution that they themselves could host. At Defcon 12, CryptoMail.org will be releasing to the public a major ....

In the rush to solve problems that emerged from Florida's Presidential election dispute in 2000, computerized voting systems have been deployed in unprecedented numbers. Estimates indicate that 30% of the USA will be voting on fully electronic equipment offering no capability for independent recounts, and another 50% of the country will be casting ballots tabulated by computer-based scanners. Vendors and promoters of these systems hav....

In November 2003, Adam discovered serious flaws in the authentication and data transfer mechanisms on some bluetooth enabled devices, and, in particular, mobile phones including commonly used Nokia, Sony Ericsson and Motorola models. Shortly thereafter, Martin Herfurt of Salzburg Research Forschungsgesellschaft mbH expanded on these problems, and teamed up with Adam to investigate further. This talk will cover the issues arising out of....

Since March 2000 the Freenet project has been the very embodiment of the "release early, release often" mantra, gaining invaluable experience of the unpredictable challenges encountered when deploying a P2P architecture on a large scale. This talk will discuss recent developments in the project including our "next generation" routing algorithm, and a sophisticated but elegant new load balancing mechanism called "adaptive rate limiting". ....

This briefing addresses the world's first global Internet war: the cyber skirmishes associated with the Palestinian intifadah. What started out as a localized conflict spread to battles around the globe as forces sympathetic to either the Israelis or the Palestinians joined the fray. With the Middle East cyber war as a backdrop, this presentation will cover the ways in which people can try to affect the course of world history through coord....

The time has come for people to start using email encryption extensively. There is enough threat from attackers as well as ignorant judges that email is not safe. SSL isn"t good enough. But how? How do we get people to do this? How do you get people whose VCRs blink 12:00 to use encryption? How do you get people to remember to encrypt? This talk discusses both specific answers as well as open architectures to nudge people down the..

Like leaving breadcrumbs in the forest, individuals leave a data trail throughout their day. This talk will look at practical ways to leave a smaller data wake. Privacy isn"t dead. Time, money and effort are needed to maintain and live outside the data collection mechanisms that are now part of society. Level of privacy achieved How easy it is to lose one's privacy... This is not a talk to look at the ways in which your dat....

Interested in hardware hacking but were not sure where to start? This presentation is for you. I will show you how to get started with modifying equipment for fun and useful purposes. I will show you the best ways for opening the enclosures for electronic equipment without destroying it, how to identify electronic components, how to solder together circuits, where to get parts, and will do a walk through of several hacks i have completed. t....

Hackers have been demonized and romantisized in the media. Some hackers interactions with the media have caused their eventual incarseration, while others seem to pimp the media to promote their careers. Dead Addict will provide a framework for manipulating the media and avoid being the victim of the media. While this talk will be relavent to hackers, it is applicable to all that consume or are consumed by media. Dead Addict wil..

3 visitors online