You need to be logged in to mark episodes as watched. Log in or sign up.
Season 2
2x1
A Kinesthetic Approach To Learning Encryption with Antoinette Stevens
Episode overview
Kinesthetic style, or tactile learning, means that some learn best by physically doing to fully learn and memorize a topic. Capture the flag competitions can be a way to understand
.. show full overview
Kinesthetic style, or tactile learning, means that some learn best by physically doing to fully learn and memorize a topic. Capture the flag competitions can be a way to understand security concepts with reading, understanding, applying and watching it in action. Creating a full multi-sensory learning experience to retain those concepts in memory for later.
2x2
More Than Tor: Shining a Light on Different Corners of the Dark Web with Benjamin Brown
Episode overview
When the terms Darknet or Dark Web are invoked, it is almost always in reference to the Tor network, but what about the other extant Darknet frameworks? In this talk Benjamin will expand
.. show full overview
When the terms Darknet or Dark Web are invoked, it is almost always in reference to the Tor network, but what about the other extant Darknet frameworks? In this talk Benjamin will expand the field of view to include frameworks such as Freenet, I2P, and OpenBazaar. He'll take a quick look at the origins and technical underpinnings of these Darknets as well as their actors and offerings.
2x3
The Magic of Forensic Artifacts Hiding in Plain Sight with Cindy Murphy
Episode overview
Digital forensics expert Cindy Murphy, M.Sc. will use this session to unpack the myths of digital forensics she uncovered since her career pivot from law enforcement to private digital
.. show full overview
Digital forensics expert Cindy Murphy, M.Sc. will use this session to unpack the myths of digital forensics she uncovered since her career pivot from law enforcement to private digital forensics work. She will discuss how to navigate common myths and most importantly, how to keep moving forward in an ever-changing industry.
In this very informative panel, Joe Cicero examines phishing bait for enterprise protection. Subjects covered are: the red flag concept, identifying phishing email basics, examining
.. show full overview
In this very informative panel, Joe Cicero examines phishing bait for enterprise protection. Subjects covered are: the red flag concept, identifying phishing email basics, examining headers, examining attachments and links. Additional topics covered are: the differences between a legit email, spam, marketing and phishing.
Brad talk's about phone phreaking back in the late 1980's, until the mid 1990's. He will cover what phreaking was, why it worked, and why it was done. Devices used, the theory behind
.. show full overview
Brad talk's about phone phreaking back in the late 1980's, until the mid 1990's. He will cover what phreaking was, why it worked, and why it was done. Devices used, the theory behind them, and some entertaining stories about those devices are covered. He will cover the slew of 'secret' numbers that existed in the phone system and discuss the decline in phreaking with the newer versions of ESS.
The shift to the cloud is making it more difficult for security teams to control what happens in their organizations and secure systems. The solution is more security tools, more
.. show full overview
The shift to the cloud is making it more difficult for security teams to control what happens in their organizations and secure systems. The solution is more security tools, more security people, and ever-inventive ways to reign in your environment. We'll talk about how engineering automation to create a culture of empowerment, self-reliance and trust can result in better security outcomes.
Bug Bounties and Vulnerability Disclosure Program (VDP) are one of the fastest growing, most popular ways for companies to engage with the security research community and uncover unknown
.. show full overview
Bug Bounties and Vulnerability Disclosure Program (VDP) are one of the fastest growing, most popular ways for companies to engage with the security research community and uncover unknown security vulnerabilities. This talk will explore how the law interacts with bug bounties, VDP, anti-hacking laws, bounty legalese myths, and contract standardization efforts widely adopted across the industry.
This talk will cover the basics of using the user-api to automate functions in Hashtopolis. Connecting to an HTP instance, creating hashlists, creating attacks, recovering plaintext, user creation and more will be covered.
This talk will cover the basics of using the user-api to automate functions in Hashtopolis. Connecting to an HTP instance, creating hashlists, creating attacks, recovering plaintext, user creation and more will be covered.
Amazing new A.I. based services from Amazon, Google, and Microsoft let organizations rely on automated technology to crawl through their cloud-based data to identify sensitive info,
.. show full overview
Amazing new A.I. based services from Amazon, Google, and Microsoft let organizations rely on automated technology to crawl through their cloud-based data to identify sensitive info, security weaknesses, and hacking attempts. In this talk, Ed will analyze security implications, ethical, business, and privacy issues they raise as cloud-based A.I. intertwines itself in our lives deeper every day.
There are 2 camps of attackers: low skilled opportunists (script kiddies) and APT - Advanced Persistent Threats (funded organized crime, nation states). In between lurks a skilled
.. show full overview
There are 2 camps of attackers: low skilled opportunists (script kiddies) and APT - Advanced Persistent Threats (funded organized crime, nation states). In between lurks a skilled persistent threat, capable of doing even more damage. These adversaries require human responders to identify, track, & oppose. Understand the constraints of the persistent threat, and you can learn to counter them.
Wireless pentesting typically requires physical proximity to a target which requires time, limited resources, and constant traveling. Eric & Matt have pioneered an inexpensive device to
.. show full overview
Wireless pentesting typically requires physical proximity to a target which requires time, limited resources, and constant traveling. Eric & Matt have pioneered an inexpensive device to covertly perform wireless pentests anywhere on earth. In this talk, they'll discuss why they built it, how it works, and why they think it will revolutionize wireless pentesting.
2x12
Building a Cohesive Undergraduate Security Club with Ian Klatzco
Episode overview
The university security club had its ups and downs between boring meetings and inaccessibility to newcomers. It improved with a tighter meeting format, approachable 24-7 internal CTF,
.. show full overview
The university security club had its ups and downs between boring meetings and inaccessibility to newcomers. It improved with a tighter meeting format, approachable 24-7 internal CTF, and internal documentation. There was better attendance, more people staying after meetings, and freshmen successfully completing projects with upperclassman mentorship. Interested? Learn more by watching this video.
2x13
Encryption, Silver Bullets & Holy Water with J. Wolfgang Goerlich
Episode overview
Werewolves attack, we have silver bullets. Vampires attack, we have holy water. Criminal hackers attack, we have encryption. The villains come and the heroes fight back. But too often,
.. show full overview
Werewolves attack, we have silver bullets. Vampires attack, we have holy water. Criminal hackers attack, we have encryption. The villains come and the heroes fight back. But too often, encryption is like water without the holy or bullets without the silver. The configuration is wrong or the code is incomplete. This talk will cover how and where to architect for encryption to get real protection.
2x14
Always Look a Gift (Trojan) Horse In the Mouth with James Arndt
Episode overview
In this talk, learn various tools and techniques that can be used to thoroughly analyze a malicious email attachment and everything that comes after it. In order to get as many stones as
.. show full overview
In this talk, learn various tools and techniques that can be used to thoroughly analyze a malicious email attachment and everything that comes after it. In order to get as many stones as possible, we will want to leave no stone unturned. This information can then be used to look for indicators of compromise throughout your environment.
2x15
Unhinging Security On the Buffalo Terastation NAS with Ian Sindermann
Episode overview
It only takes a small oversight to cause a vulnerability, even when it comes to severe vulnerabilities. The Buffalo TeraStation NAS demonstrates this idea beautifully in that it has a
.. show full overview
It only takes a small oversight to cause a vulnerability, even when it comes to severe vulnerabilities. The Buffalo TeraStation NAS demonstrates this idea beautifully in that it has a variety of features that do just a tad more than they should. Ian will provide an overview of the thought processes, mindset, and skills used to turn happy little oversights into happy little shells.
2x16
Decrypting the Mess that is Communication Security Negotiation with Jim Nitterauer
Episode overview
This talk will provide a an overview of the major SSL/TLS versions along with their major vulnerabilities. Jim will discuss how he was able to use some F5 iRule magic on his load
.. show full overview
This talk will provide a an overview of the major SSL/TLS versions along with their major vulnerabilities. Jim will discuss how he was able to use some F5 iRule magic on his load balancers combined with Graylog to track and block undesirable client and server connections to his proxy end points. This strategy can easily be adapted to any protocol scenario that uses TLS connection negotiation.
2x17
What are We Thinking Here? Rethinking Security with Jeff Man
Episode overview
There's too much focus on vulnerabilities and not enough attention on other elements that derive the standard risk equation. Meltdown/Spectre introduced a perfect storm scenario where
.. show full overview
There's too much focus on vulnerabilities and not enough attention on other elements that derive the standard risk equation. Meltdown/Spectre introduced a perfect storm scenario where the vulnerability wasn't easy to fix and the solution broke things. But, there's still persistent vulnerability. What else should we focus on in terms of security if/when the vulnerabilities still remain?
This presentation will be a mini-tutorial on how the various forms of "bot detection" out there work, and how to modify/spoof the necessary client environments to bypass nearly all of
.. show full overview
This presentation will be a mini-tutorial on how the various forms of "bot detection" out there work, and how to modify/spoof the necessary client environments to bypass nearly all of them using anything from Python Requests to Selenium, Puppet and beyond.
2x19
What the World Needs Now is Ham, Sweet Ham with Jonathan Tomek
Episode overview
Let's increase your appetite for becoming a HAM. Whether you have an SDR laying around or hand-held you have had since the last hackercon, you should get to know how to use it. For those
.. show full overview
Let's increase your appetite for becoming a HAM. Whether you have an SDR laying around or hand-held you have had since the last hackercon, you should get to know how to use it. For those HAMs out there, this should still get you excited to try something new. Since it wouldn't be Cyphercon without the "cypher", there will be some fun things here to spir the curiosity in your old hackerself.
There are few topics that capture headlines like Bitcoin. Bitcoin's blockchain is like art; sometimes you have to see it with your own eyes. How does Bitcoin work? What secrets does
.. show full overview
There are few topics that capture headlines like Bitcoin. Bitcoin's blockchain is like art; sometimes you have to see it with your own eyes. How does Bitcoin work? What secrets does blockchain hold for us to find? Everything we look at is open data and all the tools we use are open source. You can continue the investigation on your own using what you learn here as your inspiration and guide.
What happens with disk, flash, and floppy drives when you drop them off at thrift stores or e-recycling centers? How do you properly dispose of those devices safely and securely? We look
.. show full overview
What happens with disk, flash, and floppy drives when you drop them off at thrift stores or e-recycling centers? How do you properly dispose of those devices safely and securely? We look into thrift shopping, in particular, buying your data back from those who agreed to destroy it. You signed an agreement stating your disks be wiped and data destroyed, that couldn't be further from the truth.
2x22
Capture the Fail - Avoiding Pitfalls when running your C.T.F. with Kris & Chris Silvers
Episode overview
Kris and Chris Silvers, creators of the OSINT C.T.F., share some lessons they've learned on their journey. They've run into some interesting problems. Like their scoring engine's
.. show full overview
Kris and Chris Silvers, creators of the OSINT C.T.F., share some lessons they've learned on their journey. They've run into some interesting problems. Like their scoring engine's exploitable vulnerabilities to targets changing their attack surface mid-competition and met them all head-on. Laugh along and learn something as they walk through their toughest challenges and how they handled them.
2x23
Anatomy of a Hot Wallet: Bitcoin at Scale with Matthew Werner
Episode overview
Coinbase has become one of the leading cryptocurrency exchanges in the world. This talk describes how the systems operate, challenges we've faced, and how we've overcome these
.. show full overview
Coinbase has become one of the leading cryptocurrency exchanges in the world. This talk describes how the systems operate, challenges we've faced, and how we've overcome these constraints to provide our customers with a world-class cryptocurrency product. The talk will include topics such as fee estimation, coin selection, change splitting, UTXO consolidation, and child pays for parent.
On June 29, 2018, Toys "R" Us shut its doors to the public after filing Chapter 11 bankruptcy. The months leading up to that day consisted of liquidating its assets, including computer
.. show full overview
On June 29, 2018, Toys "R" Us shut its doors to the public after filing Chapter 11 bankruptcy. The months leading up to that day consisted of liquidating its assets, including computer hardware. While everything should have been sanitized before being sold, it wasn't. We'll review my forensics investigation: what I was able to recover, how I did it, and the importance of sanitizing devices.
2x25
What Happens when a Genome Database is Breached with Michelle Meas
Episode overview
DNA sequencing has become a lot cheaper since its invention, even becoming a consumer good. However, the companies that perform this sequencing are unregulated, and what they do with the
.. show full overview
DNA sequencing has become a lot cheaper since its invention, even becoming a consumer good. However, the companies that perform this sequencing are unregulated, and what they do with the data is hardly transparent. We will begin with an overview of gene sequencing technology, discuss the data collected by companies and discuss how this data could be weaponized by bad actors after a data breach.
Someone in the 1860's one day decided 'Imma order this houseplant from Asia on the Internet and plant it in my garden!' They clicked that Buy Now button and six months later the package
.. show full overview
Someone in the 1860's one day decided 'Imma order this houseplant from Asia on the Internet and plant it in my garden!' They clicked that Buy Now button and six months later the package arrived. Because we all know the Internet was still working on their package drone prototypes back then. Anyway now that little plant grows in all your backyards.
Sometimes, owning an embedded device takes multiple different vulnerabilities, creativity, and a little finesse. In this live demo, we show how we were able to chain multiple
.. show full overview
Sometimes, owning an embedded device takes multiple different vulnerabilities, creativity, and a little finesse. In this live demo, we show how we were able to chain multiple vulnerabilities in the Lenovo ix4-300d network attached storage device into a remote exploit that can be executed with little user interaction.
This presentation introduces Micro-Segmentation and includes industry adoption statistics, strategies, and implementation examples. Covered, is why we need segmentation, what the
.. show full overview
This presentation introduces Micro-Segmentation and includes industry adoption statistics, strategies, and implementation examples. Covered, is why we need segmentation, what the benefits are, how it evolved, and what it enables before explaining a flaw of Micro- Segmentation and how it is addressed using the recently defined term Nano-Segmentation.
2x29
A look at Historic Cons & their Transition to a Digital World with Stephanie Carruthers
Episode overview
What does a pig in a poke, pigeon drops, and salting have in common? They are just a few of old school confidence tricks (cons) used from the late middle ages to more recently which
.. show full overview
What does a pig in a poke, pigeon drops, and salting have in common? They are just a few of old school confidence tricks (cons) used from the late middle ages to more recently which swindled marks out of money. In this presentation Stephanie will cover how some famous historic cons were used in their day, and how they are now being transitioned into today's digital world.
In this talk, Vi Grey will demonstrate how it is possible to innovate under the limitations the NES restricts us with to create new ways a person can interact with a game. You will see
.. show full overview
In this talk, Vi Grey will demonstrate how it is possible to innovate under the limitations the NES restricts us with to create new ways a person can interact with a game. You will see NES games that are also fully functioning web pages and ZIP files, console memory dumps that can be opened as JPEG images, game cartridges that secretly contain other entire NES games, and much more.
2x31
The X-15 Rocket Plane, Flying the First Wings into Space with Michelle Evans
Episode overview
With the Soviet Union's launch of the first Sputnik satellite in 1957, the Cold War soared to new heights as Americans feared losing the race into space. This presentation tells the
.. show full overview
With the Soviet Union's launch of the first Sputnik satellite in 1957, the Cold War soared to new heights as Americans feared losing the race into space. This presentation tells the little-known story of the hypersonic X-15 which opened the way into human controlled spaceflight. Also discussed are the 12 men who guided it into space, and all the people who kept it flying for nearly a decade.
If there are missing episodes or banners (and they exist on TheTVDB) you can request an automatic full show update:
Request show update
Update requested