Many Websites mix secure and insecure content on the same page, like Facebook. This makes it possible to steal all the data entered on such a page easily, using Moxie Marlinspike's new SSLstrip tool.

SlowLoris is a new denial of service attack developed by RSnake.

Both exploits are explained and demonstrated.

Slides, handouts, and detailed instructions for these attacks are available at:

samsclass.info/defcon.html

Loading more stuff…

Hmm…it looks like things are taking a while to load. Try again?

Loading videos…