AI-Powered Application Penetration Testing—Scale Security Without Compromise Learn More

Customer Stories

Iotium: Securing an Industrial IoT Platform

Iotium: Securing an Industrial IoT Platform

IoTium, a solution designed for the Industrial Internet of Things (IIoT), enlisted Bishop Fox to verify the security of their product offering.

Read Story
Workshops & Training

Drone Hacking: Wireless Mouse Flyby Hijack with DangerDrone

Drone Hacking: Wireless Mouse Flyby Hijack with DangerDrone

Some quick live footage of flying the Danger Drone, a free penetration testing platform from Bishop Fox.

Watch Workshop
Customer Stories

Zephyr Health: Building a Healthy Security Program

Zephyr Health: Building a Healthy Security Program

Designed a security program that meets the highest privacy standards to protect sensitive patient health data.

Read Story
Workshops & Training

Weaponizing Machine Learning

Weaponizing Machine Learning

At risk of appearing like mad scientists, reveling in our latest unholy creation, we proudly introduce you to DeepHack: the open-source hacking AI. This bot learns how to break into web applications using a neural network, trial-and-error, and a frightening disregard for humankind.

Watch Workshop
Workshops & Training

DEF CON 25 (2017) - Game of Drones

DEF CON 25 (2017) - Game of Drones

We’ve taken a MythBusters-style approach to testing the effectiveness of a variety of drone defense solutions, pitting them against our DangerDrone. Videos demonstrating the results should be almost as fun for you to watch as they were for us to produce. Expect to witness epic aerial battles against an assortment of drone defense types.

Watch Workshop
Workshops & Training

Drone Hacking: Defeating Net Defense Products with a Protective Chicken Wire Cage

Drone Hacking: Defeating Net Defense Products with a Protective Chicken Wire Cage

Defeating net-based drone defense products by using a protective chicken wire bubble would defeat the majority of net drone defensive products which rely on the net getting caught in the propellers to take down the drone.

Watch Workshop
Workshops & Training

Drone Hacking: SKYNET Shotgun Shells - Drone Net Shell Testing

Drone Hacking: SKYNET Shotgun Shells - Drone Net Shell Testing

Defeating net-based drone defense products by using a protective chicken wire bubble: The SKYNET 12 gauge shotgun shells blew a hole right through our chicken wire protective cage.

Watch Workshop
Virtual Sessions

Weaponizing Machine Learning: Humanity Was Overrated Anyway

Weaponizing Machine Learning: Humanity Was Overrated Anyway

A video teaser to Bishop Fox's "DeepHack" program, presented at DEF CON 25 on July 29th.

Watch Session
Workshops & Training

DeepHack Demo - Exploiting SQLi by Using an Open-source Hacking AI Tool

DeepHack Demo - Exploiting SQLi by Using an Open-source Hacking AI Tool

At risk of appearing like mad scientists, reveling in our latest unholy creation, we proudly introduce you to DeepHack: the open-source hacking AI. This bot learns how to break into web applications using a neural network, trial-and-error, and a frightening disregard for humankind.

Watch Workshop
Workshops & Training

Lord of the Bing - Search Engine Hacking

Lord of the Bing - Search Engine Hacking

This presentation picks up the subtle art of search engine hacking at the current state and discusses why these techniques fail. We will then reveal several new search engine hacking techniques that have resulted in remarkable breakthroughs against both Google and Bing.

Watch Workshop
Workshops & Training

How We Can Stop Email Spoofing

How We Can Stop Email Spoofing

According to our research, 98 percent of the internet is not protected against email spoofing, which is a relatively easy problem to solve. If you’re concerned that your domain may be vulnerable to spoofing, check out SpoofCheck, our tool that diagnoses web and email domains.

Watch Workshop
Workshops & Training

Danger Drone - Arsenal DEMO

Danger Drone - Arsenal DEMO

Some quick live footage of flying the Danger Drone, a free penetration testing platform from Bishop Fox. She handles great!

Watch Workshop
Workshops & Training

Drone Hacking: Live Footage of Danger Drone

Drone Hacking: Live Footage of Danger Drone

Some quick live footage of flying the Danger Drone, a free penetration testing platform from Bishop Fox. She handles great!

Watch Workshop
Workshops & Training

Game Over, Man! – Reversing Video Games to Create an Unbeatable AI Player

Game Over, Man! – Reversing Video Games to Create an Unbeatable AI Player

“Super Smash Bros: Melee.” – Furrowed brows, pain in your thumbs, trash talk your Mom would blush to hear. What started as a fun coding project in response to a simple dare grew into an obsession that encompassed the wombo-combo of hacking disciplines including binary reverse engineering, AI research, and programming.

Watch Workshop
Workshops & Training

If You Can't Break Crypto, Break the Client

If You Can't Break Crypto, Break the Client

CVE-2016-1764, fixed by Apple in March of 2016, is an application-layer bug that leads to the remote disclosure of all message content and attachments in plaintext by exploiting the OS X Messages client.

Watch Workshop
Workshops & Training

Bypass Surgery - Abusing CDNs with SSRF Flash and DNS

Bypass Surgery - Abusing CDNs with SSRF Flash and DNS

It is unlikely when a bug affects almost every CDN and it becomes vulnerable, but when this happens the possibilities are endless and potentially disastrous. This is a story of exploit development with fascinating consequences.

Watch Workshop
Workshops & Training

RFIDiggity - Pentester Guide to Hacking HF/NFC and UHF RFID

RFIDiggity - Pentester Guide to Hacking HF/NFC and UHF RFID

Have you ever attended an RFID hacking presentation and walked away with more questions than answers? This talk will finally provide practical guidance for penetration testers on hacking High Frequency (HF - 13.56 MHz) and Ultra-High Frequency (UHF – 840-960 MHz).

Watch Workshop
Workshops & Training

Brink's Smart Safe Hacking

Brink's Smart Safe Hacking

It’s possible for a thief to plug a USB drive into Brink’s CompuSafe Galileo, automate hacking the safe, and steal the cash inside. Our video explains this exploit in under 60 seconds.

Watch Workshop
Technical Briefings

AirDroid Exploit Demo

AirDroid Exploit Demo

A vulnerability in the AirDroid application’s web interface made it possible for an attacker to essentially hijack a user’s phone. This video highlights the vulnerability’s implications and how an app’s permissions can become too pervasive.

Read Briefing
Resource

Black Hat USA 2014 - CloudBots - Harvesting Crypto Coins like a Botnet Farmer

Black Hat USA 2014 - CloudBots - Harvesting Crypto Coins like a Botnet Farmer

In this presentation, we explore how to (ab)use free trials to get access to vast amounts of computing power, storage, and pre-made hacking environments.

Learn More
Resource

HOPE X (2014) - Rickrolling your neighbors with Google Chromecast

HOPE X (2014) - Rickrolling your neighbors with Google Chromecast

Take control over your neighbors’ TVs like in the movies! This talk will demonstrate how to hijack any Google Chromecast – even if it’s behind a secure Wi-Fi network – to do your bidding.

Learn More
Resource

Bsides LV 2014 - Untwisting The Mersenne Twister: How I killed the PRNG

Bsides LV 2014 - Untwisting The Mersenne Twister: How I killed the PRNG

Untwister is a tool designed to help pentesters predict random number sequences when an application generates them using an insecure algorithm. This presentation focuses on weaponizing what used to be theoretical into our tool: untwister.

Learn More
Resource

RickMote Controller - Hijacking TVs via Google Chromecast

RickMote Controller - Hijacking TVs via Google Chromecast

Video Demo - using Bishop Fox's "RickMote Controller" to wirelessly hijack someones nearby TV by taking over their Google Chromecast.

Learn More
Customer Stories

August: Built-in Security in IoT Devices

August: Built-in Security in IoT Devices

Secured a new voice-enabled speaker at launch by integrating security testing into every stage of development.

Read Story

This site uses cookies to provide you with a great user experience. By continuing to use our website, you consent to the use of cookies. To find out more about the cookies we use, please see our Privacy Policy.