Zoz - Pwned By The Owner: What Happens When You Steal A Hacker's Computer
Having your place broken into and your computer stolen can be a nightmare. Getting revenge on the fucker who has your machine can be a dream come true. I had the opportunity to experience both of these...
View ArticleFyodor & David Fifield - Mastering the Nmap Scripting Engine
Most hackers can use Nmap for simple port scanning and OS detection, but the Nmap Scripting Engine (NSE) takes scanning to a whole new level. Nmap's high-speed networking engine can now spider web...
View Articlefrank^2 - Trolling Reverse-Engineers with Math: Ness... It hurts...
y = mx+b? f(x) = sin(x/freq)*amp?! SIN X = (A+BX+CX^2)/(P+QX+RX^2)?! None of these formulas as they stand alone really mean much of anything-- except maybe a headache for some. Isolating the variables,...
View ArticleFrank Breedijk - Seccubus - Analyzing Vulnerability Assessment Data the Easy Way
As part of his job as Security Engineer at Schuberg Philis, Frank Breedijk performs regular security scans. The repetitive nature of scanning the same customer infrastructure over and over again made...
View ArticleFrancisco Amato & Federico Kirschbaum - Evilgrade, You Still Have Pending...
Vulnerabilities are disclosed daily and in the best case new patches are released. Is no new that many application's update process have security weaknesses allowing fake updates injection. The new...
View ArticleFerdinand Schober - Gaming in the Glass Safe - Games DRM & Privacy
"DRM is the new form of slavery - but it also spies on you." - conversation with a gamer After years of perceived-rampant piracy on the PC, game publishers are beginning to shackle gamers with...
View ArticleFelix "FX" Lindner - Blitzableiter - the Release
The talk presents a simple but effective approach for securing Rich Internet Application (RIA) content before using it. Focusing on Adobe Flash content, the security threats presented by Flash movies...
View ArticleEsteban Martínez Fayó - Hacking and Protecting Oracle Database Vault
Oracle Database Vault was launched a few years ago to put a limit on DBAs unlimited power especially over highly confidential data where it is required by regulations. This presentation will show how...
View ArticleElie Bursztein & Jocelyn Lagarenne - Kartograph : Finding a Needle in a...
While we were slaving away hacking an awesome memory analysis tool, Kartograph, our lazy graduate student friends next door were busy honing their skills in CIV 4, Age of Empire III, Anno, C&C, and...
View ArticleElie Bursztein & Panel - Bad Memories
No matter which kind of cryptography you are using to defend your network, , sooner or later to make it work you will have to store somewhere a password, a key or a certificate. If the attacker is...
View ArticleEd Schaller - Exploiting WebSphere Application Server's JSP Engine
WebSphere Application Server (WAS), IBM's Java Enterprise Edition (JEE) application server, is one of the leading application servers and is the predominate application server in the financial and...
View ArticleDoug Mohney - HD Voice - The Overdue Revolution
After kicking around on the back shelf for years, HD voice is finally gaining traction both in the broadband world and the cellular. And the French are leading the way! The audio standards for a POTS...
View ArticleDondi West - An Examination of the Adequacy of the Laws Related to Cyber Warfare
This paper argues that the current rules of war are adequate for addressing the unique issues that are encountered as a result of conducting and defending against cyber warfare. The author begins by...
View ArticleToool - The Search for Perfect Handcuffs... and the Perfect Handcuff Key
Toool, Deviant Ollam, Dave, Dr. Tran & Ray - The Search for Perfect Handcuffs... and the Perfect Handcuff Key The few handcuff talks which have appeared at conferences in the past have focused...
View ArticleDennis Brown - Resilient Botnet Command and Control with Tor
There's nothing worse than toiling away at building a large, powerful botnet after months of effort, only to see it get taken down due to being taken down by an ISP, hosting provider or due to law...
View ArticleDennis Brown - How Hackers Won the Zombie Apocalypse
In April, 2010, a zombie outbreak occurred in Providence, Rhode Island. These were not traditional zombies however; They were controlled by an electronic device that allowed for wireless attacks...
View ArticleDecius - Exploiting Internet Surveillance Systems
For many years people have been debating whether or not surveillance capabilities should be built into the Internet. Cypherpunks see a future of perfect end to end encryption while telecom companies...
View ArticleDavid Maynor & Paul Judge, PhD - Searching for Malware: A Review of...
For many people, the first page they visit online is a search engine; in fact, in the US alone more than 14 billion searches per month happen on Google, Yahoo! and Bing. These searches are then...
View ArticleDavid Kennedy "ReL1K" & Josh Kelley - Powershell...omfg
Powershell is as close to a programming language we are going to get through a command line interface on Windows. The ability to perform almost any task we want through Windows is a huge benefit for...
View ArticleDavid C. Smith & Samuel Petreski - A New Approach to Forensic Methodology -...
Imagine the following experiment, a unique case is given to three digital forensic analysts and each is given the opportunity to engage the requester in order to develop the information needed to...
View ArticleDavid "VideoMan" M. N. Bryan & Michael Anderson - Cloud Computing, a Weapon...
Using cloud computing to attack systems allows for the testing of a company's incident response and recovery program. We have been using the cloud computing environment to test real world scenarios for...
View ArticleDave King - Hardware Hacking for Software Guys
Hardware hacking is cool, but it can be daunting to software guys. Microcontrollers mix hardware and software basically allowing software guys to do hardware in software. Lately several products have...
View ArticleThe Dark Tangent & Joe Grand - Welcome and Making the DEF CON 18 Badge
For the fifth year in a row, the DEFCON Badge makes its appearance as a full-fledged, active electronic system. Pushing fabrication techniques to the limit and using some components that are so new...
View ArticleDaniel Burroughs - Open Public Sensors and Trend
Our world is instrumented with countless sensors. While many of these are outside of our control (at least without significant effort...) there is an incredible amount of publicly available information...
View ArticleDan Kaminsky - Black Ops Of Fundamental Defense: Web Edition
Lets be honest: Year in, year out, we keep finding the same bugs in the same places, and wondering: Why don't they learn? Why don't developers use these beautiful tools we provide them -- parameterized...
View ArticleCraig Heffner - How to Hack Millions of Routers
This talk will demonstrate how many consumer routers can be exploited via DNS rebinding to gain interactive access to the router's internal-facing administrative interface. Unlike other DNS rebinding...
View ArticleChristopher Soghoian - Your ISP and the Government: Best Friends Forever
Your Internet, phone and web application providers are all, for the most part, in bed with the government. They all routinely disclose their customers' communications and other private data to law...
View ArticleChris Paget - Practical Cellphone Spying
It's widely accepted that the cryptoscheme in GSM can be broken, but did you know that if you're within radio range of your target you can intercept all of their cellphone calls by bypassing the...
View ArticleChris Paget - Extreme-Range RFID Tracking
If you think that RFID tags can only be read a few inches away from a reader you haven't met EPC Gen2, the tag that can be found in Enhanced Drivers Licenses - this 900MHz tag is readable from 30 feet...
View ArticleChris Conley - Hacking Facebook Privacy
Facebook's privacy issues are numerous and well-documented, from software "glitches" to decisions that take control away from users. Despite that, it is a still-growing force in the modern Internet and...
View ArticleChema Alonso & José Palazón "Palako" - FOCA2: The FOCA Strikes Back
FOCA is a tool to extract information in footprinting and fingerprinting phases during a penetration test. It helps auditors to extract and analyze information from metadata, hidden info and lost data...
View ArticleChema Alonso & José Palazón "Palako" - Connection String Parameter Attacks
This session is about Parameter Pollution in Connection Strings Attack. Today, a lot of tools and web applications allow users to configure dynamically a connection against a Database server. This...
View ArticleCharlie Miller - Kim Jong-il and Me: How to Build a Cyber Army to Defeat the...
Think you might ever be "asked" by a dictator of an Axis of Evil country to take down the USA in a cyberwar? Ever wonder how someone who finds vulnerabilities and breaks into computers for a living...
View ArticleChad Houck & Jason Lee - Decoding reCAPTCHA
Due to the prevalence of spammers on the internet CAPTCHAs have become a necessary security measure. Without a CAPTCHA in place a system is incapable of knowing whether a human or an automated computer...
View ArticleCesar Cerrudo - Token Kidnapping's Revenge
On April 14, 2009 Microsoft released a patch (http://www.microsoft.com/technet/security/bulletin/MS09-012.mspx) to fix the issues detailed in my previous Token Kidnapping presentation...
View ArticleBruce Potter & Logan Lodge - This Needs to be Fixed, and Other Jokes in...
Open source. These two words mean lots of things to lots of people. Some say, because it's open source it's more secure because you have complete transparency. Some say, because it's open source it's...
View ArticleBrandon Nesbit - The Games We Play
An in depth forensic analysis of video games and the systems they're played on. The goal of which is to identify the types of information useful to a forensics investigation and any other bits of...
View ArticleBrad Smith - Weaponizing Lady GaGa, Psychosonic Attacks
This session introduces and demonstrates the emerging attack vector of psychosonics. Attend and you'll understand how to turn ANY MP3 into a weapon, a study aid, a hidden calming session or helping you...
View ArticleBlake Self, Wayne Zage & Dolores Zage - SMART Project: Applying Reliability...
Battlefield operations depend heavily on network-centric computing systems. Such complex and widely dispersed operations expose network-based systems to unprecedented levels of reliability and security...
View ArticleBlake Self & bitemytaco - Hacking DOCSIS For Fun and Profit
At Defcon 16 we showed various modifications and techniques to gain free and anonymous cable modem internet access. During our last talk, the DOCSIS hacking scene was behind the cable companies. Thanks...
View ArticleBarnaby Jack - Jackpotting Automated Teller Machines Redux
The presentation "Jackpotting Automated Teller Machines" was originally on the schedule at Black Hat USA 2009. Due to circumstances beyond my control, the talk was pulled at the last minute. The...
View ArticleBONUS- BLACK HAT- Barnaby Jack - Jackpotting Automated Teller Machines Redux...
BONUS- BLACK HAT Presentation. The presentation "Jackpotting Automated Teller Machines" was originally on the schedule at Black Hat USA 2009. Due to circumstances beyond my control, the talk was...
View ArticleBarrett Weisshaar & Garret Picchioni - The Night The Lights Went Out In...
Smart meter technology is moving from news PR item to reality in many major utility markets, bringing with it the promise of fewer site visits and lower rates. With these devices, your local utility...
View ArticleAnthony Lineberry, David Luke Richardson & Tim Wyatt - These Aren't the...
The rise of the robot revolution is among us. In the past year Android has stepped up to become a leader in the world of mobile platforms. As of early may the platform has surpassed the iPhone in...
View ArticleAnthony Lai, Jake Appelbaum & Jon Oberheide - The Power of Chinese Security
If you visit China, I am sure you would like the Great Wall, however, if you surf the Internet in China, I am sure you hate the Great FireWall (GFW). How a firewall could "serve" over 3.8 billion...
View ArticleAndrew Kongs & Dr. Gerald Kane - Training the Next Generation of Hardware...
Hardware hacking can be lots of fun but can be very intimidating getting started. Andrew Kongs and Dr. Gerald Kane wanted to spread the hardware hacking culture to others and saw incoming college...
View ArticleKi-Chan Ahn & Dong-Joo Ha - Malware Migrating to Gaming Consoles: Embedded...
A large portion of people who possess a Gaming Console or a Smartphone are downloading paid software illegally from the web or p2p. Most of those people do not even give a second thought before...
View ArticleAdrian Crenshaw - Programmable HID USB Keystroke Dongle: Using the Teensy as...
The Programmable HID USB Keystroke Dongle (PHUKD) is a small device based around the Teensy microcontroller development board. It allows users to program in keystrokes and mouse macros that can execute...
View ArticleAdam Pridgen & Matt Wollenweber - Toolsmithing an IDA Bridge, Case Study for...
The presentation is a case study about an approach to building reverse engineering tools, but in this case, a network bridge between IDA Pro and Debuggers. The presentation will cover the development...
View ArticleA.P. Delchi - Physical Security : You're Doing It Wrong!
Follow in the footsteps of a seasoned geek as he recalls his adventures in the design, buildout, and operation of a physical security system. Learn how to plan ahead for the issues that will fall on...
View Article