Clicky

Pages

Sunday, September 26, 2010

Crimepack 3.1.3 Exploit kit info


Download Crimepack 3.1.3 Deny IP list CrimepackDenyiplist.txt

Download deny ip list as is, without whois info



Please note that I am not the owner of the exploit pack and will not post any files for the download. Thank you ~ Mila
Update 2 Sept 29
The cryptor.php, which is the pdf builder, indeed contains enough code to build malicious pdf for the last Adobe zero day CVE-2010-2883. However, it appears to be work in progress and not a fully implemented feature. Will post more information as it becomes available.

Update 1 sept 27 Percy Sabourin @Garlandors pointed out that one piece of code was taken from the Metasploit exploit for the "Cooltype" Adobe 0 day CVE-2010-2883, which became public on Sept. 9, 2010. See the last screenshot and below this paragraph. The code indeed looks the same, we first thought it was only for the content part of the pdf but at this time it is not clear whether the pdf generator would actually generate a working pdf exploit using this vulnerability CVE-2010-2883. There are no corresponding ini or php files in the pack too. Also, nearly all php files in the pack are encrypted with ionCube encoder.

Also, it means the pack or at least crypter.php was produced during the period Sept 9-21, 2010

        $PDFFile .= self::rndSeparators("<>",0);
        $PDFFile .= self::rndSeparators("endobj",0);
        $PDFFile .= self::rndSeparators("8 0 obj ",0);
        $PDFFile .= self::rndSeparators("<>",0);
        $PDFFile .= self::rndSeparators("stream",0);
        $PDFFile .= self::rndSeparators("0 g BT /F7 32 Tf 32 Tc 1 0 0 1 32 773.872 Tm (Hello World!) Tj   ET",0);
        $PDFFile .= self::rndSeparators("endstream",0);
        $PDFFile .= self::rndSeparators("endobj",0);
        $PDFFile .= self::rndSeparators("9 0 obj ",0);
        $PDFFile .= self::rndSeparators("<>",0);
        $PDFFile .= self::rndSeparators("endobj",0);

Crimepack 3.1.3 Java exploit analysis is available at InReverse.net by Donato 'ratsoul' Ferrante
Crimepack 3.1.3 – checking vital signs

 Crimpack 3.1.3 Deny IP list
(to prevent analysis and detection by security companies and ISP providers) 




Crimepack 3.1.3 includes 15 exploits listed below. 

001
name="mdac"
desc="IE6 COM CreateObject Code Execution"
CVE-2006-0003 -MS06-014 for lE6/Microsoft Data Access Components (MDAC) Remote Code Execution

002
name="msiemc"
desc="IE7 Uninitialized Memory Corruption"
CVE-2009-0075/0076 - MS09-002 - lE7 Memory Corruption

003
name="javagetval"
desc="Java getValue Remote Code Execution"
CVE-2010-0840 Java Trusted Method Chaining

004
name="javanew"
desc="JRE 'WebStart' RCE"
CVE-2010-1423 - Java Deployment Toolkit Remote Argument Injection Vulnerability

005
name="javaold"
desc="Java Deserialize"
CVE-2008-5353 - Javad0—JRECalendar  Java Deserialize

006
name="hcp"
desc="Microsoft Help & Support Centre"
CVE-2010-1885 - Help Center URL Validation Vulnerability

007
name="iepeers"
desc="IEPeers Remote Code Execution"
CVE-2010-0806 - IEPeers Remote Code Execution

008
name="pdfexpl"
desc="PDF Exploits (collectEmailInfo, getIcon, util.printf)"
CVE-2008-2992 - PDF Exploit• util.printf     
CVE-2009-0927 - PDF Exploit- collab.getlcon      
CVE-2007-5659/2008-0655 - PDF Exploit -collab, collectEmaillnfo

009
name="opera"
desc="Opera TN3270"
CVE-2009-3269 - Telnet for Opera Th3270 

010
name="aol"
desc="AOL Radio AmpX Buffer Overflow"
CVE-2007-5755 - AOL Radio AmpX Buffer Overflow 

011
name="iexml"
desc="Internet Explorer 7 XML Exploit"
CVE-2008-4844 - Internet Explorer 7 XML Exploit 

012
name="firefoxdiffer"
desc="Firefox 3.5/1.4/1.5 exploits"
CVE-2009-0355 - Firefox - Components/sessionstore/src/nsSessionStore.js 

013
name="spreadsheet"
desc="OWC Spreadsheet Memory Corruption"
CVE-2009-1136 - MSO9-043 - lE OWC Spreadsheet ActiveX control Memory Corruption
 

The following exploits that were present in the previous versions were removed:
CVE-2008-2463 - M508-041 - MS Access Snapshot Viewer
CVE-2009-3867 - Java Runtime Env. getSoundBank Stack BOF  
CVE-2010-0188    PDF Exploit - LibTiff Integer Overflow  

PDF Generator
This version of exploit pack does not include many pdf exploits - only three older ones using the following vulnerabilities. 
CVE-2008-2992 - PDF Exploit• util.printf     
CVE-2009-0927 - PDF Exploit- collab.getlcon      
CVE-2007-5659/2008-0655 - PDF Exploit -collab, collectEmaillnfo


However, it includes a pdf exploit builder - generator cryptor.php, which will generate malicious pdfs on the fly with various MD5 hash values for each victim.
Please read a bit more at InReverse.net

Friday, September 24, 2010

hello world

The week has been busy and no new updates were done. I am planning to post some this weekend - mostly CVE-2010-2883 and older (i.e. no new cve at the moment). Have a great weekend.


Tuesday, September 21, 2010

Sep 21 CVE-2010-2883 PDF Agenda of the United Nations Criminal Justice Events in October 2010

CVE-2010-2883 Stack-based buffer overflow in CoolType.dll in Adobe Reader and Acrobat 9.3.4 and earlier allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a PDF document with a long field in a Smart INdependent Glyphlets (SING) table in a TTF font, as exploited in the wild in September 2010. NOTE: some of these details are obtained from third party information. 


Download  ac4a484bb27e08433f822d4120291be4 UNICRI-Agenda-2010.pdf as a password protected archive (contact me if you need the password)


From: Cook Henry [mailto:henry.b.cook@gmail.com]
Sent: Tuesday, September 21, 2010 2:46 PM
To: XXXXXXXXXX
Subject: Agenda of the United Nations Criminal Justice Events in October 2010

 sir,
   In case this is useful for you.


File name:
UNICRI-Agenda-2010.pdf
http://www.virustotal.com/file-scan/report.html?id=b058fcc16446464c0aa94edabbc98cfd87d5d2ac2f9e3009b11a3aff96ed53b7-1286451255
13/ 43 (30.2%)
AntiVir    7.10.12.146    2010.10.07    HTML/Malicious.PDF.Gen
Avast    4.8.1351.0    2010.10.07    PDF:CVE-2010-2883
Avast5    5.0.594.0    2010.10.07    PDF:CVE-2010-2883
AVG    9.0.0.851    2010.10.07    Exploit_c.KLX
BitDefender    7.2    2010.10.07    Exploit.PDF-TTF.Gen
Emsisoft    5.0.0.50    2010.10.07    Exploit.Win32.CVE-2010-2883.a!A2
F-Secure    9.0.15370.0    2010.10.07    Exploit.PDF-TTF.Gen
Fortinet    4.2.249.0    2010.10.07    PDF/CoolType!exploit.CVE20102883
GData    21    2010.10.07    Exploit.PDF-TTF.Gen
Kaspersky    7.0.0.125    2010.10.07    Exploit.Win32.CVE-2010-2883.a
Microsoft    1.6201    2010.10.07    Exploit:Win32/CVE-2010-2883.A
PCTools    7.0.3.5    2010.10.07    HeurEngine.MaliciousExploit
Symantec    20101.2.0.161    2010.10.07    Bloodhound.Exploit.357
Additional information
MD5   : ac4a484bb27e08433f822d4120291be4

Friday, September 17, 2010

CVE-2010-2883 Adobe 0-Day David Leadbetter's One Point Lesson from 193.106.85.61 thomasbennett34@yahoo.com


Technical Analysis and Research links (just a few, in no particular order, send more if you want me to add)
Download  687b8d2112f25e330820143ede7fedce Golf Clinic.pdf as a password protected archive (contact me if you need the password)


Download files





  • golf clinic.pdf - (\Application Data) - 6AF93ED231AEA3B00769FC8283943E75
  • iso88591 - (same location as the original) F7A341ACBB05F6A597EC33ACCB7AD04E
  • wincrng.exe + winhelp32.exe (downloaded from academyhouse.us)  687B8D2112F25E330820143EDE7FEDCE
  • igfxver.exe (%tmp%)   E8CE9CB98C71405F0FB3888235302568 - dropped by the original

Download hlp.cpl signed with the stolen Verisign certificate issued to secure2.ccuu.com


Update 10
Lead Adobe 0-day CVE-2010-2883 Made in Korea  - by villy


Update9

[Unofficial] 0-Day Acrobat SING Table Vulnerability Patch (sent by INT3 CC, thank you)

https://www.rafzar.com/node/22

I did not test but heard it works well. Try it, test it

Update 8
 DEP Bypass in Golf Clinic PDF by Cédric Gilbert, SkyRecon Systems
Cédric Gilbert, from  SkyRecon Systems sent a short and later (per my request, because I wanted to understand it ) , a more detailed explanation for the DEP bypass  - in clear terms, for people who don't already know everything :)
Please comment and correct, if you find mistakes, we will add the corrections. Many thanks!
---------------------------------------------

There are 4 settings for DEP :
-          AlwaysOff
-          Opt-in
-          Opt-out
-          Always On


‘Opt-in’ is the one used by default on every Desktop Edition of Windows, while ‘opt-out’ is the default for Server Editions.
‘Opt-in’ only protects software that is fully compatible with DEP (those software programs are marked at compilation with the flag ‘/NXCOMPAT’).
‘Opt-out’ protects every software program (even the ones without /NXCOMPAT) except the ones explicitly added by the administrator to a white list.

“AcroRd32.exe” is not /NXCOMPAT, thus if an execution occurs in a page in memory marked as ‘not executable’ (the heap for instance), DEP in ‘opt-in’ mode will ignore the fault and silently change the rights of the page to ‘EXECUTE’. On the other hand, if DEP is set to ‘opt-out’, it will immediately kill the faulting process. This is why most exploits using heap spraying actually do work. Because even though execution occurs on the heap (NO EXEC) when the execution flow is redirected into the ‘nop’ slide, DEP in opt-in mode will not block the attack.

Now the writers of the exploit used in this case obviously wanted to go a step further by bypassing DEP even in its ‘opt-out’ or ‘always-on’ mode.

Which means that they had to find a way to execute their payload without triggering any ‘page fault’ in NO EXECUTE memory.

The best way to do so is to use some kind of ‘ret into libc’ technique (in this case a ROP technique). Instead of redirecting the execution flow into the heap, they redirect it to a CODE section in a DLL (which got EXECUTE rights) by overwriting saved eip on the stack. Of course no DLL exactly have the code that the attacker would like to execute, so the idea is to chain calls into this DLL on small code portions using return addresses smartly placed on the stack before the vulnerability is triggered. The problem with this technique is that it requires the attacker to use ‘hardcoded’ addresses pointing at each code portion that he wishes to execute. 

Starting with Windows Vista, Microsoft introduced a new protection called ‘ASLR’ for Address Space Layout Randomization. This protection, among other things, randomize the base address of each DLL when they get loaded into a process address space (the random base address changes at each boot). This protection was meant to defeat attacks, which used hardcoded addresses, since a randomized DLL place in memory is changing at each boot.

So to defeat both DEP and ASLR, the attacker got AcroRd32.exe to load a DLL not compatible with ASLR into its address space (I do not know how they managed to do so at the moment).
The DLL used is “icucnv34.dll”, the fact that it is not compatible with ASLR means that it will always get loaded at the same address in memory, thus allowing the attacker to use ‘hardcoded’ addresses pointing to this DLL.

The thing is, it’s very complicated to build a whole shellcode using this kind chained call into a DLL. So the attacker used it only to get a place in memory allocated with exec rights, copy his shellcode on it and, eventually, jump on it and do whatever he wants without caring about DEP anymore.

In this exploit, the attacker manages to do so by chaining 4 API call in “icucnv34.dll”.

1)      CreateFileA:
IN      LPCTSTR lpFileName                       = 4a8254e0                 = « iso88591 »
IN      DWORD dwDesiredAccess              = 0x 10000000           = GENERIC_ALL
IN      DWORD dwShareMode                   = 0                               = not shared
IN      lpSecurityAttributes (OPTIONAL)   = 0
IN      DWORD dwCreationDisposition      = 2                              = CREATE_ALWAYS
IN      DWORD dwFlagsAndAttributes      = 0x102                      = FILE_ATTRIBUTE_TEMPORARY | FILE_ATTRIBUTE_HIDDEN
Here the attacker creates an empty file called “iso88591” at the location where the pdf was opened.

2)      CreateFileMappingA
IN           HANDLE               hFile                                       = 0x1c4                = handle on « iso88591 » 
IN OPT  lpAttributes                                                            = NULL
IN           DWORD               flProtect                                  = 0x40                  = PAGE_EXECUTE_READWRITE
IN           DWORD               dwMaximumSizeHigh            = 0
IN           DWORD               dwMaximumSizeLow            = 0x10000
IN OPT  LPCTSTR              lpName                                    = NULL
Since the file is empty, the attacker has to specify an arbitrary size for the file mapping.
At this point the attacker is ready to map the file into memory.

3)      MapViewOfFile
IN           HANDLE               hFileMappingObject              = 0x2dc          = Handle from CreateFileMappingA
IN           DWORD                dwDesiredAccess                  = 0x22            = FILE_MAP_EXECUTE | FILE_MAP_WRITE
IN           DWORD               dwFileOffsetHigh                  = 0
IN           DWORD               dwFileOffsetLow                   = 0
IN           SIZE_T                  dwNumberOfBytesToMap    = 0x10000
Now the attacker’s got a 0x10000 bytes space with EXECUTE rights allocated into memory. All that he has to do to complete his ‘DEP-evading-technique’ is to copy the shellcode that he wishes to execute in this newly allocated exec space and jump on it.
Which he does by calling :
4)       MSVCR80!memcpy
Dst = 0x05bc0000     // Base Address returned from the MapViewOfFile above
Src = 0885f118          // Not sure whether it is an address from the mapping of the pdf itself or something that he sprayed on the heap before
Len = 0x1000

And here we are, after this call the real payload (at 0x0885f118) is mapped into an ‘EXEC’ memory space (at 0x05bc0000). The jump to the the payload is actually made by the memcpy call itself since the return address set on the stack by the attacker for this call is the destination of the copy (0x05bc0000) ! BAM! Both ASLR and DEP are defeated!

Now one may ask : ”Ok nice, icucnv34.dll is not ASLR-compatible, but kernel32.dll is, so how did the attacker get the required API addresses?”. Well, it is pretty simple actually, he just had to use API imported by icucnv34.dll ! When this DLL got loaded, its import table got fixed by the loader with the addresses of all API required by the DLL.
Since the base address of icucnv34.dll is known by the attacker, he just had to retrieve the needed addresses from icucnv34.dll import table :)
  Cédric Gilbert, SkyRecon Systems

 
Update7    - Aurora?
Here here an interesting observation by Itzhak Avraham (Zuk) @ihackbanme about the fact that this pdf is using a technique similar to one found in Aurora.


DMS.bat mentioned in Update 6, has been observed during analysis of ad_1_.jpg file, which was one of the files recovered during the Aurora investigation (see Aurora US-CERT advisory here)

ad_1_.jpg unpacking/analysis - Aurora by Itzhak Avraham (Zuk)

DFS.bat from ad_1_.jpg (Aurora)



The DMS.bat from CVE-2010-2883 Adobe 0-Day
:Repeat
DEL "C:\DOCUME~1\USER\LOCALS~1\Temp\hlp.cpl"
if exist "C:\DOCUME~1\USER\LOCALS~1\Temp\hlp.cpl" goto Repeat
DEL "C:\DOCUME~1\USER\LOCALS~1\Temp\DMS.bat" 



Update6
Exploit in action:(see a video demo in the end of this post)
According to Sophos researchers (many thanks to Chester Wisniewski) -
  • the shellcode drops hlp.cpl  DLL to  user %tmp% folder and then manually parses to its StartUp export and runs from there. 
  • wincrng .exe gets downloaded using the DLLs's "DownloadFile" export from hxxp://academyhouse .us/from/wincrng exe to user Application Data folder, renames it to winhelp32.exe and runs it. The domain is currently under the control of Shadow Server (http:/internal/tools/whois/?domain=academyhouse.us)
  • The DLL then calls its "MakeAndShowEgg" export, which reads a filename from the original PDF ("Golf Clinic.pdf") and then drops a clean PDF file (golf clinic.pdf 6AF93ED231AEA3B00769FC8283943E75) and launches it in Acrobat Reader so as not to arouse suspicion.  The text of the PDF, however, still arouses a lot of suspicion - see below :)
  • Finally the DLL calls the imaginatively-titled "DeleteMyself" export to drop the file DMS.bat which deletes the DLL and then itself.
  The DMS.bat contents are
:Repeat
DEL "C:\DOCUME~1\USER\LOCALS~1\Temp\hlp.cpl"
if exist "C:\DOCUME~1\USER\LOCALS~1\Temp\hlp.cpl" goto Repeat
DEL "C:\DOCUME~1\USER\LOCALS~1\Temp\DMS.bat"  
 

Update5
 
A few more variants of this message

Variant 2
from 119.247.163.249 MD5 2802c47b48cced7f1f027f3b278d6bb3
From: Thomas Bennett [mailto:Thomas.Bennett@gmx.com]
Sent: Tuesday, September 07, 2010 5:41 AM
To: xxx
Subject: Golf Clinic, David Leadbetter's One Point Lesson
Importance: High

Hi
Want to improve your score?
In these golf tips David Leadbetter shows you some important principles Cause & Effect, which have been helpful to thousands of amateur golfers around world.

Whatever your handicap, Whatever your age or ability, the tips will improve your game!

bye

Thursday, September 16, 2010

Publication (Symantec Security Response): The Rise of PDF Malware by Karthik Selvaraj and Nino Fred Gutierrez

This is a good overview of the current PDF malware (up to September 2010)
Download paper

This appendix has a very nice chart of what is what when it comes to PDF these days (Click to enlarge)

Sep 15 CVE-2010-2883 Adobe 0-Day PDF US Government Programs to Pay Medical Expenses from rodney.cadataa@gmail.com



Download  Beneficial medical programs.pdf and dropped files  as a password protected archive (contact me if you need the password)



From: CENTERS FOR MEDICARE & MEDICAID SERVICES [mailto:rodney.cadataa@gmail.com]
Sent: Wednesday, September 15, 2010 10:22 AM
To: XXXXXXXXXXXXXXXXXX
Subject: US Government Programs to Pay Medical Expenses

There are Federal and state programs available for people with Medicare who have limited income and resources. These programs may help you save on your health care and prescription drug costs.

For More Information
Call or visit your State Medical Assistance (Medicaid) office, and ask for information on Medicaid and Medicare Savings Programs. The names of these programs and how they work may vary by state. Call if you think you qualify for any of these programs, even if you aren't sure.
Call 1-800-MEDICARE (1-800-633-4227), and say "medicaid" to get the telephone number for your state. TTY users should call 1-877-486-2048.



Sep14 CVE-2010-2883 Adobe 0-Day Fwd: China-U.S. Trade Issues from sara.ml.davis@gmail.com



Download  RL33536.pdf and dropped files  as a password protected archive (contact me if you need the password)



1. Adobe PSIRT team confirmed that the attached exploit pdf is indeed for CVE-2010-2883 vulnerability and that their next update on October 4 will protect from a pdf like this one.

2. The message is from a gmail account but it is crafted to appear like a forwarded message by a CRS researcher. The real report with the researcher's name is published online and this is where they probably got the information.
(thanks to @xanda for sending the link to the report)

3. The pdf appears to be generated with Metasploit. (thanks to villy for the clue)

From: Davis L.M. [mailto:sara.ml.davis@gmail.com]
Sent: Tuesday, September 14, 2010 10:11 AM
To: XXXXXXXXXXXXXXXXXXXXXXXXXXXXXX
Subject: Fwd: China-U.S. Trade Issues

---------- Forwarded message ----------
From: Wayne M. Morrison
Date: 2010/9/14
Subject: China-U.S. Trade Issues
To: sara.ml.davis@gmail.com


FYI.

Wayne M. Morrison
Congressional Research Service
Specialist in Asian Trade and Finance


Sep 16 CVE-2010-2883 PDF INTEREST & FOREIGN EXCHANGE RATES



Download  INTEREST_&_FOREIGN_EXCHANGE_RATES.pdf and dropped files  as a password protected archive (contact me if you need the password)

-----Original Message-----
From: XXXXXXXXXXXXXXXXXXXXXXXXXXXX
Sent: Thursday, September 16, 2010 11:32 AM
To: XXXXXXXXXXXXXX
Subject: INTEREST & FOREIGN EXCHANGE RATES


Dear XXXXXXXXXXXXXXXXXXX,

Hope this email finds you well.

Maby you are intersted of this article.

Apologies for this sudden request, but we would greatly appreciate your advice.

Best Regards,

----------------------------------------------------------------
This message was sent using IMP, the Internet Messaging Program.

Thursday, September 9, 2010

Sep 09 CVE-2009-4324 + CVE-2010-1297 + CVE-2009-0927 PDF U.S. economy slips from spoofed henryAron@brookings.org 210.64.253.96



CVE-2009-0927 Stack-based buffer overflow in Adobe Reader and Adobe Acrobat 9 before 9.1, 8 before 8.1.3 , and 7 before 7.1.1 allows remote attackers to execute arbitrary code via a crafted argument to the getIcon method of a Collab object, a different vulnerability than CVE-2009-0658.


Download  as a password protected archive with the original PDf and analysis files/dropped binaries (contact me if you need the password)


-----Original Message-----
From: Henry J. Aaron [mailto:henryAron@brookings.org]
Sent: Thursday, September 09, 2010 9:38 AM
To: XXXXXXXXX
Subject: FW: U.S. economy slips to 4th in WEF's competitiveness rankings

To whom it may concern.

Henry J. Aaron

Senior Fellow, Economic Studies

The Brookings Institution
Headers
Received: (qmail 12137 invoked from network); 9 Sep 2010 13:43:33 -0000
Received: from h96-210-64-253.seed.net.tw (HELO brookings.org) (210.64.253.96)
  by XXXXXXXXXXXX with SMTP; 9 Sep 2010 13:43:33 -0000
From: "Henry J. Aaron"
Subject: FW: U.S. economy slips to 4th in WEF's competitiveness rankings
To: XXXXXXX
Content-Type: multipart/mixed;
    boundary="=_NextPart_2rfkindysadvnqw3nerasdf"; charset="US-ASCII"
MIME-Version: 1.0
Reply-To: h.swain65@yahoo.com
Date: Thu, 9 Sep 2010 21:37:54 +0800
X-Priority: 3
X-Mailer: Microsoft Outlook Express 5.00.2615.200

210.64.253.96

Hostname:    h96-210-64-253.seed.net.tw
ISP:    Digital United Inc.
Organization:    Seednet-TaipeiDP-S
State/Region:    T'ai-pei
City:    Taipei

CVE-2009-4324
CVE-2010-1297
CVE-2009-0927
http://wepawet.cs.ucsb.edu/view.php?hash=47a46ba2220cf6368eb0d42d8a6d40e3&type=js


Saturday, September 4, 2010

Defcon 18 Audio in MP3 files

 Defcon 18 MP3 files


TRACK 1
  1. Track-1_Perspectives_in_Cybersecurity_and_Cyberwarfare_Max_Kelly
  2. Track 1 Meet the Feds - CSITCPIP Panel
  3. Track 1 DNS Systemic Vulnerabilities and Risk Management A Discussion Panel
  4. Track 1 Meet the Feds - Policy, Privacy, Deterrence and Cyber War Panel 
  5. Track 1 Enough Cyber Talk Already! Help Get this Collaboration Engine Running Riley Repko 
  6. Track 1 Open Letter - Call to Action Panel
  7. Track 1 Of Bytes and Bullets Panel 
  8. Track 1 Exploiting WebSphere Application Server’s JSP Engine Ed Schaller
  9. Track 1 Mastering the Nmap Scripting Engine Fyodor David Fifield
  10. Track 1 Meet the EFF Kevin Bankston- Eva Galperin- Jennifer Granick- Marcia Hofmann- Kurt Opsahl
  11. Track 1 Black Ops Of Fundamental Defense Web Edition Dan Kaminsky
  12. Track 1 Legal Developments in Hardware Hacking Jennifer Granick Matt Zimmerman
  13. Track 1 App Attack Surviving the Mobile Application Explosion Kevin Mahaffey John Hering
  14. Track 1 This is Not the Droid You’re Looking For Nicholas J. Percoco- Christian Papathanasiou
  15. Track 1 Practical Cellphone Spying Chris Paget
  16. Track 1 HD Voice - The Overdue Revolution Doug Mohney
  17. Track 1 These Aren’t the Permissions You’re Looking For  Anthony Lineberry- David Luke Richardson- Tim Wyatt
  18. Track 1 Mobile Privacy Tor on the iPhone and Other Unusual Devices Marco Bonetti
  19. Track 1 Resilient Botnet Command and Control with Tor
  20. Track 1 Ripping Media Off Of the Wire HONEY
  21. Track 1 The Search for Perfect Handcuffs... and the Perfect Handcuff Key Deviant Ollam- Dave- Dr. Tran- Ray
  22. Track 1 Attack the Key, Own the Lock Schuyler Towne- datagram
  23. Track 1 PCI Compromising Controls and Compromising Security Jack Daniel Panel
  24. Track 1 How I Met Your Girlfriend Samy Kamkar
  25. Track 1 Decoding reCAPTCHA Chad Houck- Jason Lee
  26. Track 1 So Many Ways to Slap A Yo-Ho Xploiting Yoville and Facebook for Tom Stracener Strace- Sean Barnum- Chris Peterson
  27. Track 1 Social Networking Special Ops Extending Data Visualization Tools The Suggmeister
  28. Track 1 Getting Social with the Smart Grid Justin Morehouse Tony Flick
TRACK 2

  1. Track 2 An Examination of the Adequacy of the Laws Related to Cyber Warfare Dondi West
  2. Track 2 Balancing the Pwn Trade Deficit Val Smith- Colin Ames- Anthony Lai
  3. Track 2 Build Your Own Security Operations Center for Little or No Money
  4. Track 2 Cloud Computing, a Weapon of Mass Destruction David VideoMan- M. N.Bryan- Michael Anderson
  5. Track 2 Cyber CrimeWarCharting Dangerous Waters Iftach Ian Amit
  6. Track 2 Cyberterrorism and the Security of the National Drinking Water Infrastructure John McNabb
  7. Track 2 Drivesploit Circumventing Both Automated AND Manual Wayne Huang
  8. Track 2 Exploiting SCADA Systems Jeremy Brown
  9. Track 2 Hacking and Protecting Oracle Database Vault Esteban Martínez Fayó
  10. Track 2 Hacking Oracle From Web Apps
  11. Track 2 How Unique Is Your Browser Peter Eckersley
  12. Track 2 Industrial Cyber Security Wade Polk- Paul Malkewicz- J. Novak
  13. Track 2 Kim Jong-il and Me How to Build a Cyber Army to Defeat the U.S. Charlie Miller
  14. Track 2 Lord of the Bing Taking Back Search Engine Hacking Rob Ragan- Francis Brown
  15. Track 2 Multiplayer Metasploit Tag-Team Penetration and Information Gathering Ryan Linn
  16. Track 2 NoSQL, No Injection Wayne Huang, Kuon Ding
  17. Track 2 Passive DNS Hardening Robert Edmonds- Paul Vixie
  18. Track 2 Powershell...omfg David Kennedy ReL1K-, Josh Kelley
  19. Track 2 SCADA and ICS for Security Experts How to Avoid Cyberdouchery James Arlen
  20. Track 2 Seccubus - Analyzing Vulnerability Assessment Data the Easy Way Frank Breedijk
  21. Track 2 SHODAN for Penetration Testers Michael Schearer
  22. Track 2 Tales from the Crypto G. Mark Hardy
  23. Track 2 The Night The Lights Went Out In Vegas Demystifying The Night The Lights Went Out In Vegas Demystifying  Barrett Weisshaar, Garret Picchioni
  24. Track 2 The Power of Chinese Security Anthony Lai-Jake Appelbaum- Jon Oberheide.
  25. Track 2 Token Kidnapping's Revenge Cesar Cerrudo
  26. Track 2 Toolsmithing an IDA Bridge, Case Study for Building a RE tool Adam Pridgen, Matt Wollenweber
  27. Track 2 Wardriving the Smart Grid Practical Approaches to Attacking Utilit Shawn Moyer- Nathan Keltner
  28. Track 2 You Spent All That Money and You Still Got Owned Joseph McCray
TRACK 3
  1.     Track 3 0box Analyzer AfterDark Runtime Forensics for Automated Malware Analysis and Clustering Wayne Huang, Jeremy Chiu, Benson Wu
  2.     Track 3 A New Approach to Forensic Methodology - !!BUSTED!! Case Studies David C. Smith, Samuel Petreski
  3.     Track 3 Advanced Format String Attacks Paul Haas
  4.     Track 3 An Observatory for the SSLiverse Peter Eckersley, Jesse Burns
  5.     Track 3 Bad Memories Elie Bursztein, Baptiste Gourdin, Gustav Rydstedt, Dan Boneh
  6.     Track 3 Big Brother on the Big Screen FactFiction Nicole Ozer, Kevin Bankston
  7.     Track 3 Browser Based Defenses James Shewmaker
  8.     Track 3 Changing Threats To Privacy From TIA to Google Moxie Marlinspike
  9.     Track 3 Connection String Parameter Attacks Chema Alonso, José Palazón "Palako"
  10.     Track 3 Constricting the Web Offensive Python for Web Hackers Nathan Hamiel, Marcin Wielgoszewski
  11.     Track 3 Exploiting Internet Surveillance Systems Decius
  12.     Track 3 FOCA2 The FOCA Strikes Back Chema Alonso, José Palazón "Palako"
  13.     Track 3 Hacking DOCSIS For Fun and Profit Blake Self, bitemytaco
  14.     Track 3 Hacking Facebook Privacy Chris Conley
  15.     Track 3 How To Get Your FBI File (and Other Information You Want from the Federal Government) Marcia Hofmann
  16.     Track 3 How to Hack Millions of Routers Craig Heffner
  17.     Track 3 masSEXploitation Michael Brooks "The Rook"
  18.     Track 3 Open Source Framework for Advanced Intrusion Detection Solutions Patrick Mullen, Ryan Pentney
  19.     Track 3 Our Instrumented Lives Sensors, Sensors, Everywhere...Greg Conti
  20.     Track 3 pyREtic - In-memory Reverse Engineering for Obfuscated Python Bytecode Rich Smith
  21.     Track 3 Repelling the Wily Insider Matias Madou, Jacob West
  22.     Track 3 Search & Seizure & Golfballs Jim Rennie, Eric Rachner
  23.     Track 3 The Anatomy of Drug Testing Jimi Fiekert
  24.     Track 3 The Law of Laptop Search and Seizure Jennifer Granick, Kevin Bankston, Marcia Hofmann, Kurt Opsahl
  25.     Track 3 This Needs to be Fixed, and Other Jokes in Commit Statements Bruce Potter, Logan Lodge
  26.     Track 3 WPA Too Md Sohail Ahmad
  27.     Track 3 Your ISP and the Government Best Friends Forever Christopher Soghoian
TRACK 4
  1. track 4    Breaking Bluetooth by Being Bored JP Dunning
  2. track 4    Build a Lie Detector/Beat a Lie Detector Rain- urbanmonkey
  3. track 4    Build your own UAV 2.0 - Wireless Mayhem from the Heavens Michael Weigand- Renderman- Mike Kershaw
  4. track 4    Bypassing Smart-Card Authentication and Blocking Debiting Vulnerabilities in Atmel Cryptomemory-Based Stored-Value Systems Jonathan Lee- Neil Pahl
  5. track 4    DCFluX in: Moon-Bouncer Matt Krick
  6. track 4    Deceiving the Heavens to Cross the Sea Using the 36 Stratagems for Social Engineering Jayson E. Street
  7. track 4    Exploitation on ARM - Technique and Bypassing Defense Mechanisms Itzhak “zuk”” Avraham
  8. track 4    Exploiting Digital Cameras Oren Isacson- Alfredo Ortega
  9. track 4    ExploitSpotting: Locating Vulnerabilities Out of Vendor Patches Automatically Jeongwook Oh
  10. track 4    Extreme-Range RFID Tracking Chris Paget
  11. track 4    Function Hooking for Mac OSX and Linux Joe Damato
  12. track 4    Getting Root: Remote Viewing- Non-Local Consciousness Richard Thieme
  13. track 4    Hacking with Hardware: Introducing the Universal RF Usb Keboard Emulation Device - URFUKED Monta Elkins
  14. track 4    How Hackers Won the Zombie Apocalypse Dennis Brown
  15. track 4    Implementing IPv6 at ARIN Matt Ryanczak
  16. track 4    Insecurity Engineering of Physical Security Systems: Locks- Lies- and Videotape Marc Weber Tobias- Tobias Bluzmanis- Matt Fiddler
  17. track 4    IPv6: No Longer Optional John Curran
  18. track 4    Jackpotting Automated Teller Machines Redux Barnaby Jack
  19. track 4    Live Fire Exercise: Baltic Cyber Shield 2010 Kenneth Geers
  20. track 4    Physical Computing- Virtual Security: Adding the Arduino Microcontroller Leigh Honeywell- follower
  21. track 4    Physical Security Youre Doing It Wrong A.P. Delchi
  22. track 4    Programmable HID USB Keystroke Dongle Using the Teensy as a Pen Testing Device Adrian Crenshaw
  23. track 4    SMART Project: Applying Reliability Metrics to Security Vulnerabilities Blake Self- Wayne Zage- Dolores Zage
  24. track 4    VirGraff101: An Introduction to Virtual Graffiti Tottenkoph
  25. track 4    We Don’t Need No Stinkin Badges: Hacking Electronic Door Access Controllers Shawn Merdinger
  26. track 4    Weaponizing Lady GaGa- Psychosonic Attacks Brad Smith
  27. track 4    Web Services We Just Don’t Need Mike “mckt” Bailey
  28. track 4    Welcome and Making the DEF CON 18 Badge Dark Tangent- Joe Grand
TRACK 5
  1. Track 5 Air Traffic Control Insecurity 2.0 Righter Kunkel
  2. Track 5 Antique Exploitation aka Terminator 3.1.1 for Workgroups Jon Oberheide
  3. Track 5 Be a Mentor Marisa Fagan
  4. Track 5 Blitzableiter - the Release Felix FX Lindner
  5. Track 5 ChaosVPN for Playing CTFs mc.fly, ryd, vyrus, no_maam
  6. Track 5 Crawling BitTorrent DHTs for Fun Scott Wolchok
  7. Track 5 Defcon Security Jam III: Now in 3-D Panel
  8. Track 5 Electronic Weaponry or How to Rule the World While Shopping at Radio Shack Mage2
  9. Track 5 Evilgrade, You Still Have Pending Upgrades Francisco Amato- Federico Kirschbaum
  10. Track 5 Facial Recognition: Facts, Fiction; and Fcsk-Ups Joshua Marpet
  11. Track 5 FOE‚ The Release of Feed Over Email Sho Ho
  12. Track 5 From No Way to 0-day Weaponizing the Unweaponizable Joshua Wise
  13. Track 5 Gaming in the Glass Safe - Games DRM and Privacy Ferdinand Schober
  14. Track 5 Google Toolbar The NARC Within Jeff Bryner
  15. Track 5 Hacking .Net Applications A Dynamic Attack Jon McCoy
  16. Track 5 Hardware Hacking for Software Guys Dave King
  17. Track 5 Kartograph Finding a Needle in a Haystack or How to Apply Reverse Engineering Techniques to Cheat at Video Games Elie Bursztein Jocelyn Lagarenne
  18. Track 5 Katana Portable Multi-Boot Security Suite JP Dunning
  19. Track 5 Letting the Air Out of Tire Pressure Monitoring Systems Mike Metzger
  20. Track 5 Like a Boss: Attacking JBoss Tyler Krpata
  21. Track 5 Malware Freak Show 2 The Client-Side Boogaloo Nicholas J. Percoco, Jibran Ilyas
  22. Track 5 Malware Migrating to Gaming Consoles Embedded Devices an Antivirus-Free Safe Hideout For Malware Ahn Ki-Chan Ha Dong-Joo
  23. Track 5 My Life as a Spyware Developer Garry Pejski
  24. Track 5 oCTF: 5 years in 50 minutes Panel
  25. Track 5 Open Public Sensors and Trend Monitoring Daniel Burroughs
  26. Track 5 Operating System Fingerprinting for Virtual Machines Nguyen Anh Quynh
  27. Track 5 Pwned By The Owner What Happens When You Steal a Hacker’s Computer Zoz
  28. Track 5 Searching for Malware A Review of Attackers’ Use of Search Engines to Lure Victims David Maynor, Paul Judge, PhD
  29. Track 5 Securing MMOs A Security Professional’s View from the Inside metr0
  30. Track 5 The Games We Play Brandon Nesbit
  31. Track 5 Training the Next Generation of Hardware Hackers Andrew Kongs- Dr. Gerald Kane
  32. Track 5 Web Application Fingerprinting with Static Files Patrick Thomas
  33. Track 5 Who Cares About IPv6 Sam Bowne
  34. Track 5 WiMAX Hacking 2010 Pierce, Goldy, aSmig, sanitybit
  35. Track 5 Your Boss is a Douchebag... How About You Luiz effffn Eduardo
Early video from Defcon.org
  1. DEFCON 18 Hacking Conference Presentation By Joe Grand and Dark Tangent - Welcome And Behind The Scenes Of The DEFCON Badge - Slides.m4v
  2. DEFCON 18 Hacking Conference Presentation By Barnaby Jack - Jackpotting Automated Teller Machines Redux - Slides.m4v
  3. DEFCON 18 Hacking Conference Presentation By David Maynor and Paul Judge - Searching For Malware - Slides.m4v
  4. DEFCON 18 Hacking Conference Presentation By Chris Paget - Practical Cellphone Spying - Slides.m4v 
  5. DEFCON 18 Hacking Conference Presentation By Md Sohail Ahmad - WPA Too! - Slides.m4v

Many thanks to MG
to be continued....