DEF CON 30 - Orange Tsai - Let's Dance in the Cache - Destabilizing Hash Table on Microsoft IIS
Hash Table, as the most fundamental Data Structure in Computer Science, is extensively applied in Software Architecture to store data in an associative manner. However, its architecture makes it prone to Collision Attacks. To deal with this problem, 25 years ago, Microsoft designed its own Dynamic Hashing algorithm and applied it everywhere in IIS, the Web Server from Microsoft, to serve various data from HTTP Stack. As Hash Table is everywhere, isn't the design from Microsoft worth scrutinizing? We dive into IIS internals through months of Reverse-Engineering efforts to examine both the Hash Table implementation and the use of Hash Table algorithms. Several types of attacks are proposed and uncovered in our research, including (1) A specially designed Zero-Hash Flooding Attack against Microsoft's self-implemented algorithm. (2) A Cache Poisoning Attack based on the inconsistency between Hash-Keys. (3) An unusual Authentication Bypass based on a hash collision. By understanding this talk, the audience won't be surprised why we can destabilize the Hash Table easily. The audience will also learn how we explore the IIS internals and will be surprised by our results. These results could not only make a default installed IIS Server hang with 100% CPU but also modify arbitrary HTTP responses through crafted HTTP request. Moreover, we'll demonstrate how we bypass the authentication requirement with a single, crafted password by colliding the identity cache!

Attacking AI - Jason Haddix - NDC Security 2026

DEF CON 33 - Kill List: Hacking an Assassination Site on the Dark Web - Carl Miller, Chris Monteiro

Palo Alto PSE Strata System Engineer Professional Exam Prep: Full Course
![Nicholas Carlini - Black-hat LLMs | [un]prompted 2026](https://i.ytimg.com/vi/1sd26pWhfmg/hqdefault.jpg?sqp=-oaymwE9CNACELwBSFryq4qpAy8IARUAAAAAGAElAADIQj0AgKJDeAHwAQH4Af4JgALQBYoCDAgAEAEYciBmKDYwDw==&rs=AOn4CLBn1sRfbeYcMnkqD2mtRZhq1TO6JQ)
Nicholas Carlini - Black-hat LLMs | [un]prompted 2026

Zig 2026: No-AI Policy, $670K Foundation, Left GitHub & Why Zig Isn’t 1.0 - Andrew Kelley Explains

Hacking the Hackers: The Art of Compromising C2 Servers with Vangelis Stykas

AI agent buys itself a robot and car, does exactly what experts warned

He Once Worked at Subway. At 58, He Solved An "Impossible" Problem

DEF CON 33 - Cash, Drugs, and Guns - Why Your Safes Aren't Safe - Mark Omo, James Rowley

Orange Tsai - Infiltrating Corporate Intranet Like NSA Preauth RCE - DEF CON 27 Conference

Trump Faces GOP Fury Over Iran Deal; Fox News Blames JD Vance; Iran Gets $300 Billion: A Closer Look

Web Scraping Using Python For Beginners and File Handling in Python | Python Web Scraping

DEF CON 32 - Gotta Cache ‘em all bending the rules of web cache exploitation - Martin Doyhenard

DEF CON 30 - Daniel Jensen - Hunting Bugs in the Tropics

I Built Retracting Casters that are Actually GOOD

SEC-T 0x10: Orange Tsai - Confusion Attacks: Exploiting Hidden Semantic Ambiguity in Apache

Output Caching in ASP.NET Core 7 | OD114

China’s Secret | The Most Unbelievable Megaprojects in China | 4K Travel Documentary

$1200 Gaming Motherboard Destroyed By Junior Tech | Don't Do This!

