Defcon – Hacker Disneyland and Ai

by admin

Saturday, August 1st, 2026 at 10:27 pm

For the last 10 years, I’ve said the same thing: I’m not going back to DEFCON. Every year I told myself the only way I’d return was if work paid for it. And honestly, this might be the last time. Unless I land somewhere new next year that gives me a reason to go, I think I’m finally done. I’ve been going to DEFCON for 15 years. I’ve watched it grow, change, and slowly drift away from what made it special in the first place even before I spent a few million in Bitcoin to fund the first trip (yea im still kicking myself in the ass for selling 75, but not as bad as the 20k bitcoin pizza or the countless others who lost a shitload)

Back in the day, DEFCON was about hackers being hackers. It was about curiosity, breaking things apart to understand how they worked, building weird projects, sharing knowledge, and finding the handful of people in the room who were just as obsessed with technology as you were. It wasn’t about branding. It wasn’t about influencers. It wasn’t about career fairs, corporate booths, or people trying to sell you the latest “cybersecurity roadmap” package. Now? It feels like a different animal.

The price tells part of the story. When I started going, a ticket was around $100. Fifteen years later, it’s pushing $600. That’s a massive jump for an event that feels like it has become increasingly watered down. A lot of the original hacker culture has been replaced by people who discovered hacking through Hollywood, Mr. Robot, and movies that turned hackers into some kind of edgy superhero archetype. The problem isn’t that new people show up everyone was new once. The problem is that too many people show up looking for the shortcut instead of wanting to learn.

The hacker mindset was never about getting a badge, a six-week online certification, or memorizing enough buzzwords to get past a recruiter. It was about spending nights tearing apart hardware, reading obscure documentation, experimenting, failing, and learning because you were genuinely curious. Now everyone wants the title without the work.

Cybersecurity has become full of people chasing the money instead of the craft. Every year there are more boot camps, more “guaranteed career” programs, and more people selling the dream that you can become an expert overnight. And, as always, there are plenty of wolves waiting to separate fools from their money.

Then came AI. AI has changed everything. It has made some things easier, but it has also flooded the space with people who think pressing a button makes them a hacker.

Working with AI can feel a lot like Charlie Babbitt (Tom Cruise) in Rain Man. At first, you think you’re the one driving. You ask a question, expecting a straight answer, and instead you’re sitting in the passenger seat while your brilliant, eccentric companion fixates on something completely different. You say, “Help me write a business proposal.”

The AI replies with a lecture on the history of proposals, three philosophical caveats, and an unsolicited deep dive into Kmart underwear because, somewhere in the statistical machinery, it decided that was relevant. It isn’t stupid. In fact, it’s often frighteningly brilliant. That’s what makes the experience so strange. One moment it’s compressing a thousand pages into five paragraphs. The next it’s obsessing over a detail that has nothing to do with your actual goal.

You learn that using AI isn’t about asking questions. It’s about steering. You become less of a user and more of a handler, constantly nudging an incredibly intelligent partner back toward the objective whenever it decides the scenic route is more interesting than the destination. In that sense, AI doesn’t replace expertise. It demands a different kind of expertise. The people who get the most out of it aren’t the ones who blindly accept every answer. They’re the ones who know enough to recognize when it’s drifting, hallucinating, or confidently solving the wrong problem.

AI needs a sidekick. Not because it isn’t powerful, but because it has no judgment. It can generate possibilities all day long, but it can’t reliably distinguish between the clever answer and the useful one without someone capable of making that call. The danger is that AI creates the illusion that borrowed intelligence is the same thing as earned intelligence. When everyone has access to the same model, it’s easy to mistake fluent output for deep understanding. People start believing they’re experts because they can produce expert-looking work. They mistake acceleration for mastery. The machine did the heavy lifting, and they confuse operating the machine with possessing the knowledge behind it. That’s not an argument against AI. It’s an argument against intellectual complacency. A calculator didn’t teach anyone mathematics. GPS didn’t teach anyone geography. AI won’t teach anyone how to think simply because they can prompt it well. In fact, if you’re not careful, it can become a substitute for thinking instead of an aid to thinking.

The people who become dramatically more capable with AI are usually the ones who were already curious. They interrogate its answers. They test assumptions. They recognize mistakes because they’ve spent years building intuition the hard way. Everyone else risks becoming faster without becoming better.

The signal-to-noise ratio is worse than ever. Everyone has a tool, everyone has an opinion, and everyone wants to call themselves a security professional. But tools don’t create hackers. Curiosity does. Obsession does. The willingness to chase a question long after everyone else has accepted the first answer. The hacker scene wasn’t built by people looking for shortcuts. It was built by people who couldn’t leave well enough alone ,people who wanted to know why something worked, not just that it worked.

The scene isn’t dead because new people arrived.

It’s changing because the culture that produced great researchers is slowly being replaced by a culture that rewards appearances over understanding. It’s easier than ever to look knowledgeable. Harder than ever to know who has actually done the work.DEFCON will always have its history. There are still extraordinary researchers there. There are still people quietly pushing the boundaries of what’s possible.

But the feeling is different.The underground became mainstream, and the mainstream brought metrics, branding, audiences, algorithms, and monetization. The hacker scene used to reward exploration for its own sake. Now it often rewards visibility.

The irony is that the greatest technology for amplifying human intelligence arrived at exactly the moment when fewer people seem interested in developing their own. AI can make great thinkers astonishingly productive. But it can also make shallow thinking sound sophisticated. The difference isn’t the tool. It’s whether the person behind the keyboard is still asking questions after the AI has already given them an answer.

Maybe that’s just what happens when something grows too big. The outsiders arrive, the corporations follow, the money shows up, and eventually the thing that made it special gets harder to find. For those of us who were around before the hype, before the certifications, before everyone wanted to be a “cybersecurity professional,” it’s hard not to miss what it used to be.

The old scene isn’t coming back. And maybe that’s the part that’s hardest to accept.

Get off my lawn.

…As one final effort to keep an old tradition alive, I’m bringing some of the stickers and random stuff I’ve been making in Photoshop over the years. The goal has always been the same: make something that either makes people laugh, makes people uncomfortable, or gets someone to stop and say, “What the hell am I looking at?”

Over the years, that has included things like 3D-printed novelty items featuring hacker-themed designs, questionable jokes, and other weird creations that probably shouldn’t exist, but somehow do.

This year, I’m making a batch of 3D-printed Nintendo cartridge keychains with fake game titles and stupid ideas that seemed funny at the time. The plan is to print around 60 of them and hand them out to friends.

I’m not making these to sell, start a brand, or turn them into some kind of side hustle. They’re just little pieces of the old-school DEFCON spirit: make something weird, share it with people, and hopefully get a few laughs. I’ll post pictures of them here once they’re done.

Iran so far away

by admin

Monday, April 27th, 2026 at 7:28 pm

yearly check in , still not ww3 yet though. bbl.

Heyo

by admin

Sunday, March 23rd, 2025 at 11:48 pm

OK after serious neglect for a while now i finally got around to updating some shit on the site. Still lazy and using WordPress so come hack it if you can. Discord server is still around so ping me if you want access.

sup

by admin

Saturday, April 20th, 2024 at 10:21 pm

now that covid is over and ww3 about to start figured id stop by and say hi.

Moving to gitlab

by admin

Tuesday, February 9th, 2021 at 5:18 pm

Starting to push all code to gitlab, all the code on github will be left there but the account will be abandoned.

Swag

by admin

Tuesday, May 5th, 2020 at 2:07 am

Swag reminder https://teespring.com/stores/illmob-swag-shop

Link Dump 12/9/19

by admin

Monday, December 9th, 2019 at 1:52 am

Tools:
Simple tool to create HTA with Evading AV
CORS Misconfiguration Scanner.
Metasploit Shellcode Grows Up: Encrypted and Authenticated C Shells
harismuneer/Ultimate-Facebook-Scraper
Invoke-Procdump.ps1
SkelSec/pypykatz 0.3.0 released
rogerorr/DllSurrogate-dll to call x32com from x64 binaries
phackt/stager.dll- metasploit shellcode detection evasion
ANDRAX v4 DragonFly – Penetration Testing on Android
request smuggler
facebookincubator/WEASEL- DNS covert channel implant
Cobalt Strike 4.0 Released
macOS Red Team: Calling Apple APIs Without Building Binaries
antonioCoco/RogueWinRM – Windows Local Privilege Esc
xFreed0m/Disruption – Terraform script to deploy AD-based environment on Azure
b4rtik/ATPMiniDump – Evading WinDefender ATP credential-theft
sachinkamath/ntlmrecon – fast NTLM reconnaissance
Pwnagotchi 1.4.0 Released
FSecureLABS/awspx– Graph tool for access and resource relationships in AWS
https://hat.sh/
leo-lb/wpbrute-rs – WordPress login bruteforcer
CVE-2019-2890 – PoC
harleo/asnipASN – IP range attack surface mapping
Mimikatz 2.2.0 20191125 – released
hackerschoice/thc-tesla-powerwall2-hack
sailay1996/UAC_Bypass_In_The_WildWindows 10 UAC bypass for all executable files which are autoelevate true
0vercl0k/CVE-2019-11708 – Full exploit chain (CVE-2019-11708 & CVE-2019-9810) against Firefox on Windows 64-bit.

Reading:
AMSI as a Service — Automating AV Evasion
Bad Binder: Android In-The-Wild Exploit
Getting Malicious Office Documents to Fire with Protected View
Weak encryption cipher and hardcoded cryptographic keys in Fortinet products
Reflected XSS in graph.facebook.com leads to account takeover
Cracking Mifare Classic cards with Proxmark3 RDV4
Red Team Diary, Entry #3: Custom Malware Development
Evading WinDefender ATP credential-theft
Dumping LSASS without Mimikatz with MiniDumpWriteDump
[CVE-2019-14899] Inferring and hijacking VPN-tunneled TCP connections.
HackerOne breach lets outside hacker read customers’ private bug reports
your_xkcd_passwords_are_pwned
CVE-2019-12750: Symantec Endpoint Protection Local Privilege Escalation
BMW Infiltrated by Hackers Hunting for Automotive Trade Secrets
We thought they were potatoes but they were beans (from Service Accounts
Spilling Local Files via XXE When HTTP OOB Fails

casibom

Link Dump 11/21/19

by admin

Thursday, November 21st, 2019 at 1:43 pm

Tools:
https://github.com/byt3bl33d3r/WitnessMe
https://github.com/NotSoSecure/cloud-service-enum
https://github.com/theMiddleBlue/CVE-2019-11043
https://github.com/cobbr/Covenant
https://github.com/n1xbyte/donutCS
https://sqlectron.github.io/
https://github.com/sansatart/scrapts/blob/master/shodan-favicon-hashes.csv
https://gitlab.com/initstring/evil-ssdp
https://github.com/nyxgeek/ntlmscan
https://twitter.com/cry__pto/status/1190045825914802176
https://github.com/3gstudent/Homework-of-C-Language/blob/master/Install_.Net_Framework_from_the_command_line.cpp
https://github.com/initstring/uptux
https://github.com/b4rtik/RedPeanut
https://github.com/rvazarkar/SharpHound3
https://github.com/Binject/go-donut
https://github.com/infosecn1nja/MaliciousMacroMSBuild
https://gist.github.com/TarlogicSecurity/2f221924fef8c14a1d8e29f3cb5c5c4a
https://shenaniganslabs.io/2019/11/12/Ghost-Potato.html
https://github.com/0x09AL/RdpThief
https://github.com/Mr-Un1k0d3r/SCShell
https://labs.nettitude.com/blog/introducing-sharpsocks-v2-0/
https://github.com/FuzzySecurity/Sharp-Suite#remoteviewing
https://github.com/liamg/pax
https://github.com/skelsec/jackdaw

Reading:
https://twitter.com/Alra3ees/status/1192246345341513729
https://www.mdsec.co.uk/2019/11/rdpthief-extracting-clear-text-credentials-from-remote-desktop-clients/
C2 Comparisons
https://twitter.com/OSINTtechniques/status/1197102283869376513
http://powerofcommunity.net/poc2019/Qian.pdf
https://www.nccgroup.trust/uk/about-us/newsroom-and-events/blogs/2019/november/cve-2019-1405-and-cve-2019-1322-elevation-to-system-via-the-upnp-device-host-service-and-the-update-orchestrator-service/
https://medium.com/@c2defense/man-in-the-network-network-devices-are-endpoints-too-d5bd4a279e37
https://leucosite.com/Edge-Local-File-Disclosure-and-EoP/
https://posts.specterops.io/cve-2019-12757-local-privilege-escalation-in-symantec-endpoint-protection-1f7fd5c859c6
https://www.embercybersecurity.com/blog/cve-2019-1378-exploiting-an-access-control-privilege-escalation-vulnerability-in-windows-10-update-assistant-wua
http://tpm.fail/
https://limitedresults.com/2019/11/pwn-the-esp32-forever-flash-encryption-and-sec-boot-keys-extraction/
https://www.bleepingcomputer.com/news/security/magento-urges-users-to-apply-security-update-for-rce-bug/
https://medium.com/@d.bougioukas/red-team-diary-entry-2-stealthily-backdooring-cms-through-redis-memory-space-5813c62f8add
https://medium.com/@two06/amsi-as-a-service-automating-av-evasion-2e2f54397ff9
https://googleprojectzero.blogspot.com/2019/11/bad-binder-android-in-wild-exploit.html

Breaches:
https://threatpost.com/hackers-dump-2-2m-gaming-cryptocurrency-passwords-online/150451/
https://headleaks.com/2019/11/21/millions-of-sites-using-jetpack-wordpress-plugin-exposed-by-a-security-vulnerability-Q1VaTHc4VUhUazZGeWcyWDgxL2dYQT09
https://www.helpnetsecurity.com/2019/11/20/confidential-medical-images/
https://gizmodo.com/7-5-million-adobe-accounts-exposed-by-security-blunder-1839364598
https://www.bleepingcomputer.com/news/security/macys-customer-payment-info-stolen-in-magecart-data-breach/
https://pastebin.com/8rXhtqgr

+20 new dumps added to our database

Link Dump 10/12/19

by admin

Saturday, October 12th, 2019 at 1:01 pm

https://github.com/h43z/dns-rebinding-tool/
http://intx0x80.blogspot.com/2019/10/JWT.html
https://twitter.com/kaluche_/status/1181834267204210688
https://github.com/Hackplayers/Salsa-tools
https://github.com/AlmondOffSec/PoCs/tree/master/Windows_wermgr_eop
https://github.com/HunnicCyber/SharpSniper
https://github.com/3gstudent/GadgetToJScript
https://github.com/ZeroPointSecurity/GoldenTicket
https://github.com/coolboy4me/cve-2019-0708_bluekeep_rce
https://github.com/bugbounty-site/exploits/tree/master/CVE-2019-14994

Reading
https://xz.aliyun.com/t/6498
https://thewover.github.io/Bear-Claw/
https://blog.hunniccyber.com/phishing-with-netlify/
https://www.preempt.com/blog/drop-the-mic-2-active-directory-open-to-more-ntlm-attacks/
https://silentbreaksecurity.com/cve-2019-10617/
https://www.nextron-systems.com/2019/10/04/antivirus-event-analysis-cheat-sheet-v1-7-2/
https://jailbreak.fce365.info/Thread-It-s-possible-once-again-to-bypass-iCloud-by-using-a-CFW-with-the-CheckM8-Exploit?pid=1151#pid1151
https://offsec.almond.consulting/windows-error-reporting-arbitrary-file-move-eop.html
https://ssd-disclosure.com/archives/4033/ssd-advisory-openssh-pre-auth-xmss-integer-overflow
https://safebreach.com/Post/HP-Touchpoint-Analytics-DLL-Search-Order-Hijacking-Potential-Abuses-CVE-2019-6333

Link Dump 10/2

by admin

Wednesday, October 2nd, 2019 at 7:03 pm

Tools:
HRShell –  Flask HTTP/HTTPS Reverse Shell/C2
Evil WinRM + Donut-Loader
USB Armory MKII
PyPyKatz-WASM – Parse lsass dumps in the cloud
https://shell.now.sh/
SMB2 snapshots with Impacket SMBClient
Python API wrapper for spyse.com tools
SharpDoor – termsrv.dll multiRDP patcher

Reading:
https://thehackernews.com/2019/09/windows-fileless-malware-attack.html
https://posts.specterops.io/understanding-and-defending-against-access-token-theft-finding-alternatives-to-winlogon-exe-80696c8a73b
https://www.praetorian.com/blog/running-a-net-assembly-in-memory-with-meterpreter

IP: Loading... - Host: Loading...
IP Geolocation: unknown.

We love our country, but fear our government.