Media Summary: Many automotive dealers in the USA utilize centralized platforms for everything from sales to service to marketing. FIDO2 is the de-facto standard for passwordless and 2FA authentication. FIDO2 relies on the Client-to-Authenticator Protocol ... Dealers are a vital part of the automotive industry – intentionally separate entities from the manufacturers, but highly ...

Def Con 33 How Api - Detailed Analysis & Overview

Many automotive dealers in the USA utilize centralized platforms for everything from sales to service to marketing. FIDO2 is the de-facto standard for passwordless and 2FA authentication. FIDO2 relies on the Client-to-Authenticator Protocol ... Dealers are a vital part of the automotive industry – intentionally separate entities from the manufacturers, but highly ... It was the summer of 2016, and like everyone else, I was out playing Pokémon Go. Except my rural location barely spawned ... For more than five years, firewall vendors have been under persistent, cyclical struggle against a well-resourced and relentless ... When Liberty Safe was found to have provided safe unlock codes to authorities, it made us wonder; how was it even possible for ...

Have you ever wondered how the On-Board Units (OBUs) in smart buses communicate and authenticate with Advanced Public ... This talk explores the hidden risks in apps leveraging modern AI systems—especially those using large language models (LLMs) ... The accelerating evolution of technology, specifically AI, has created a "meta-system" so complex and intertwined with all domains ... Some people think the days of critical HTTP request smuggling attacks on hardened targets have passed. Unfortunately, this is an ... Gaining initial access to an intranet is one of the most challenging parts of red teaming. If an attack chain is intercepted by an ... Imagine your home modem as a loaded gun aimed at global security. Our research exposes critical vulnerabilities in ISP-supplied ...

Microsoft Entra ID – one of the most used identity providers in the enterprise market. Or from our perspective: the most targeted ...

Photo Gallery

DEF CON 33 - How API flaws led to admin access to 1k+ USA dealers & control of yr car - Eaton Zveare
DEF CON 33 - CTRAPS-CTAP Impersonation, API Confusion Attacks on FIDO2 - M Casagrande, D Antonioli
DEF CON 33 - How a vuln in dealer software could've unlocked your car  - E Zveare, R Piyush
DEF CON 33 - Breakin 'Em All – Overcoming Pokemon Go's Anti Cheat Mechanism - Tal Skverer
DEF CON 33 - China's 5+ year campaign to penetrate perimeter network defenses - Andrew  Brandt
DEF CON 33 - Cash, Drugs, and Guns - Why Your Safes Aren't Safe - Mark Omo, James Rowley
DEF CON 33 - Smart Bus Smart Hacking:  Free WiFi to Total Control  - Kai Ching Wang, Chiao-Lin Yu
DEF CON 33 - Exploiting Shadow Data from AI Models and Embeddings - Patrick Walsh
DEF CON 33 - Thinking Like a Hacker in the Age of AI - Richard 'neuralcowboy' Thieme
DEF CON 33 - HTTP 1 1 Must Die! The Desync Endgame  - James 'albinowax' Kettle
DEF CON 33 - New Red Team Networking Techniques for Initial Access and Evasion -Shu-Hao, Tung 123ojp
DEF CON 33 - Gateways to Chaos - How We Proved Modems Are a Ticking Time Bomb - Chiao-Lin  Yu
View Detailed Profile
DEF CON 33 - How API flaws led to admin access to 1k+ USA dealers & control of yr car - Eaton Zveare

DEF CON 33 - How API flaws led to admin access to 1k+ USA dealers & control of yr car - Eaton Zveare

Many automotive dealers in the USA utilize centralized platforms for everything from sales to service to marketing.

DEF CON 33 - CTRAPS-CTAP Impersonation, API Confusion Attacks on FIDO2 - M Casagrande, D Antonioli

DEF CON 33 - CTRAPS-CTAP Impersonation, API Confusion Attacks on FIDO2 - M Casagrande, D Antonioli

FIDO2 is the de-facto standard for passwordless and 2FA authentication. FIDO2 relies on the Client-to-Authenticator Protocol ...

DEF CON 33 - How a vuln in dealer software could've unlocked your car  - E Zveare, R Piyush

DEF CON 33 - How a vuln in dealer software could've unlocked your car - E Zveare, R Piyush

Dealers are a vital part of the automotive industry – intentionally separate entities from the manufacturers, but highly ...

DEF CON 33 - Breakin 'Em All – Overcoming Pokemon Go's Anti Cheat Mechanism - Tal Skverer

DEF CON 33 - Breakin 'Em All – Overcoming Pokemon Go's Anti Cheat Mechanism - Tal Skverer

It was the summer of 2016, and like everyone else, I was out playing Pokémon Go. Except my rural location barely spawned ...

DEF CON 33 - China's 5+ year campaign to penetrate perimeter network defenses - Andrew  Brandt

DEF CON 33 - China's 5+ year campaign to penetrate perimeter network defenses - Andrew Brandt

For more than five years, firewall vendors have been under persistent, cyclical struggle against a well-resourced and relentless ...

DEF CON 33 - Cash, Drugs, and Guns - Why Your Safes Aren't Safe - Mark Omo, James Rowley

DEF CON 33 - Cash, Drugs, and Guns - Why Your Safes Aren't Safe - Mark Omo, James Rowley

When Liberty Safe was found to have provided safe unlock codes to authorities, it made us wonder; how was it even possible for ...

DEF CON 33 - Smart Bus Smart Hacking:  Free WiFi to Total Control  - Kai Ching Wang, Chiao-Lin Yu

DEF CON 33 - Smart Bus Smart Hacking: Free WiFi to Total Control - Kai Ching Wang, Chiao-Lin Yu

Have you ever wondered how the On-Board Units (OBUs) in smart buses communicate and authenticate with Advanced Public ...

DEF CON 33 - Exploiting Shadow Data from AI Models and Embeddings - Patrick Walsh

DEF CON 33 - Exploiting Shadow Data from AI Models and Embeddings - Patrick Walsh

This talk explores the hidden risks in apps leveraging modern AI systems—especially those using large language models (LLMs) ...

DEF CON 33 - Thinking Like a Hacker in the Age of AI - Richard 'neuralcowboy' Thieme

DEF CON 33 - Thinking Like a Hacker in the Age of AI - Richard 'neuralcowboy' Thieme

The accelerating evolution of technology, specifically AI, has created a "meta-system" so complex and intertwined with all domains ...

DEF CON 33 - HTTP 1 1 Must Die! The Desync Endgame  - James 'albinowax' Kettle

DEF CON 33 - HTTP 1 1 Must Die! The Desync Endgame - James 'albinowax' Kettle

Some people think the days of critical HTTP request smuggling attacks on hardened targets have passed. Unfortunately, this is an ...

DEF CON 33 - New Red Team Networking Techniques for Initial Access and Evasion -Shu-Hao, Tung 123ojp

DEF CON 33 - New Red Team Networking Techniques for Initial Access and Evasion -Shu-Hao, Tung 123ojp

Gaining initial access to an intranet is one of the most challenging parts of red teaming. If an attack chain is intercepted by an ...

DEF CON 33 - Gateways to Chaos - How We Proved Modems Are a Ticking Time Bomb - Chiao-Lin  Yu

DEF CON 33 - Gateways to Chaos - How We Proved Modems Are a Ticking Time Bomb - Chiao-Lin Yu

Imagine your home modem as a loaded gun aimed at global security. Our research exposes critical vulnerabilities in ISP-supplied ...

DEF CON 33 - Turning Microsoft's Login Page into our Phishing Infrastructure - Keanu 'RedByte' Nys

DEF CON 33 - Turning Microsoft's Login Page into our Phishing Infrastructure - Keanu 'RedByte' Nys

Microsoft Entra ID – one of the most used identity providers in the enterprise market. Or from our perspective: the most targeted ...