Posts

First Security Conference, First Defcon, Defcon 34

Remembering my first security security conference

Tags: security-conference , conference , defcon

On This Page

This post is coming very late. It should’ve been here about two months ago. There are a few reasons. The main ones being :

  • I was worried about writing posts because even though I dont want AI companies using my posts without my consent in their dataset, I cannot ensure this, and I cannot for some reason trust them to use not just mine, but anyone’s work without consent.
  • I was so deep in the work immediately after coming from DEFCON, I barely used to leave my room for days.

What about now? What changed? Well, first of all I realized that I’m restraining myself for something that I like doing sometimes. I like writing about things I’m learning or have learned and I should not confine myself in fear of training an agent about how to generate the next token. Second, this two months after defcon, I’ve spent my time heavily on using agents and writing custom harnesses. I wasnt well introduced with anything about how LLMs and agents work and suddenly I just realized I can have some fun writing a harness and watch the agent being in the loop, doing part of my repetitive work for me. As a result, I do want the agents to improve in their writing and in their thought process, just not without proper crediting the original source of information.

Next, I realized closing myself in a room and working day and night, losing sleep over getting results so I can talk to my professor is not really a good idea. It took two months and a whole lot of stress and peak mental exhaustion, to the point that I was seriously considering myself on the edge of depression. This can be a completely different topic for discussion, which I think will automatically appear in my upcoming posts. I have learned a lot of interesting stuff in this span of two months and I’m excited to write about all of it ASAP.

Info

Also… if you’re a PhD student, or someone who has access to a mentor, and are confused about when to talk to your advisor/mentor? Talk to them about what you’ve been working on. Maybe bi-weekly or monthly, or whatever timing works for you two. Up until now I was confused on when to go for a meeting with my advisor. It’s not always possible to some results in a time you think you’ll have it by. If you work on that, you’ll start stressing yourself out just before your own self-set deadline. The best way to work this out is to make your report as what you did in that time span rather than some advancement in your progress.

Posts will come about the agents and harness writing part, this post is a short note on my very first DEFCON experience.

Very First Security Conference!

I haven’t attended any security conference up until now. Strange. I’ve been in and out of security field for quite some time again and again, but every time I got a chance to visit a security conference in India something came up with higher priority and I had to skip the conference.

I was lucky enough to get a chance to visit DEFCON as my very first security conference. I was given an opportunity to work with Defcon Academy. It’s hosted by pwn.college where students and professors from ASU create courses and hacking modules to teach other students hacking.

defcon.pwn.college

At first I was going for the DEFCON CTF, because I play the quals with Shellphish. Even though I wasnt able to solve a single challenge, because either someone else or some AI agent will solve the challenge, and even though I didnt want to use AI agents for solving CTF challenges, everybody was using it and I didn’t wanna put my team back so I used it as well, so reluctantly started using it. Everyone else, especially the really good players in our team were quite excited in using the agents for solving challenges. That may be because they just have that energy all the time, with or without agent.

team shellphish

… btw, some challenges can just be so dumb and lame and you just wanna quit playing the whole CTF.

Going with Defcon Academy allowed me to explore the conference a bit rather than just spending time playing the CTF. I was prepared to spend part of time time at the conference and part of my time playing the CTF and there are mixed opinions in my head about this decision. We had a stall setup at DEFCON for Defcon Academy and we were teaching people basic skills requried for hacking. We even provided laptops for people who didn’t bring one and people were loving pwn.college

The Setup & Selling The Setup

The basic setup was that some of us would stand at the front of the stall and tell people about pwn.college when they approached the stall. We set baits by putting out amazing stickers at the front table and very basic strategy was that when they approached the stall for stickers we would ask them about their interest in hacking and we tell them about pwn.college.

The first day was mostly empty (at least in my shift). The second day, Yan came and he just had this energy that started pulling people in and I was amazed by witnessing it right in front of me. We just had to change our strategy slightly to achieve this in the first day itself. [Yan][yanncomm.net]’s strategy was to ask people whether they wanted to “start hacking right now?”, as compared to our strategy of just telling people about what pwn.college works. I also started doing the same thing that he did and we just started filling up the spaces quite fast.

A simple trick! Rather than telling people about the product, you give them a trial of the product.

There was this time when people were standing and listening to the ongoing talks (by other PhD students) just because the seats were all filled and I really didn’t expect this by the numbers we got on the first day. I mean, pwn.college has been giving away free, high quality, hacking education for all this time and obviously when people just heard about all these things, they probably thought there’s a hidden cost other than their time!

Met Amazing People

On the second day I was working my shift and it was about to end when I saw Laurie Wired. I couldn’t hold in my excitement because I already had watched some of her videos and I found the whole Lain’s theme really impressive, plus, she creates high quality content in the cybersecurity space. In excitement I forgot to ask for a picture together and I was hoping to meet her again just because I thought I should capture this memory that I meant Laurie in my first security conference ever!

The very last day, I had time on my hands because for some reason, not many people were coming. I later came to know the reason. On the last day of DEFCON, many stalls are already packed and moved out, and people are just there completing their villages that they started working on in earlier days, or just wandering around having fun. I was free this day because my tentative shift was the second one, but we just didn’t knew that there’s no second shift because DEFCON closes at around 2 PM (IIRC). So, I was just wandering around, hoping to meet some other amazing people and have a nice chat with them if possible.

Wandering around, I came across a LiveOverflow sticker in the HexTree’s fault injection village. I hoped to find Fabian himself and to my surpise he was just nearby his stall, giving an interview. I just wanted to talk to him! Because I’ve watched many of his videos and I even once tried to create his style of videos, but gave up after realising I dont like video editing that much. It takes too much time to render the results on the potato laptop I had that time. It does not feed my dopamine hits at as high rate as writing blogs or just working something on my own. So, I waited for his interview to compelete and then I got a chance to talk to him! I asked him about his views on AI in CTFs and what he thinks about using AI for regular work in cybersecurity. We have same thoughts on AI in CTF, but he gave some other ideas as well that I kept myself blocked from thinking.

This time, I didn’t faulter to ask for a selfie together unlike last time with Laurie

Conclusion

All in all, this was quite fun experience. I got to visit Las Vegas. My sleep schedule was really messed up because I even tried to play CTF after my first day with DEFCON academy in hopes of getting a solve this time, but that completely ruined by sleep cycle for the rest of the stay. So the rest of the days I just focused on DEFCON academy and slept.

Past the Conclusion, The Future, The Past

Soon after coming from DEFCON, I realized I have a Mac Mini lying around with me. I bought it back in 2025 to consult a company, and write them software for Linux, Mac and Windows. Linux and Windows were doable, but Mac? I couldn’t even install it inside an emulator! Anyways, now I dont work with them, and I’m doing my PhD now.

What do I do with this machine? I don’t want to sell it, but it has 24G shared VRAM, and at that moment it struck me! I can run local inference on it! Unaware of what inference even means back then, I started looking into it. I thought that if I can write an agent that can do tasks for me like read my server logs for me, or do web searches, read my mail, etc… that would be really amazing! I started exploring the usage, and ended up up realizing I can do bug hunting with the local inference (oblivious of the fact that I only have 24G VRAM, out of which not all was usable!).

I still ended up learning lots of amazing stuff that I just wanna write about. This information might already be out there, but these are the things that I learned by experiment first approach. When I wanted to improve something, I would get some inspiration from blogs written by other people.

I was especially inspired by this post (System Over Model: Zero-Day Discovery at the Jagged Frontier) by AISLE where the Stanlisav states that models in bug hunting are a jagged frontier, meaning some big model have chances of doing worse than small models in some cases, and model performance does not only depend on the model itself.

There’s also this post (System Over Model, Tested: Reproducing Mythos’s FreeBSD Find on Local Open-Weight Models) by clearbluejar where they verify ASILE’s claim about using a small local model to reproduce the find of the 17 year old bug that was making waves in the cybersecurity space. It was a good find, but these two blog posts split that find into two parts : The actual bug found, and the marketing push behind it. This essentially opened a new dimension of questioning agentic bug hunting to me.