Zardus's Avatar

Zardus

@zardus.bsky.social

Retired DEFCON CTF org. Shellphish Captain Emeritus. ASU Prof. angr hacker. pwn.college sensei. Looking for students/interns! https://yancomm.net https://github.com/zardus https://defcon.social/@Zardus

239 Followers  |  1 Following  |  123 Posts  |  Joined: 22.08.2023  |  2.2192

Latest posts by zardus.bsky.social on Bluesky

Post image

The room is FULL for @the_robwaz’s talk about Speculative Execution and micro architectural vulnerabilities at @DEFCON Academy (but I only photographed the man himself)!

10.08.2025 20:02 β€” πŸ‘ 2    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

Spread the word! @DEFCON’s brand new @DEFCONAcademy is giving out shirts, coins, and stickers! And also KNOWLEDGE! So tell your friends (including you, @DEFCON account!) and come by room 235 today to LEARN TO HACK and GET SOME SWAG!

10.08.2025 16:52 β€” πŸ‘ 1    πŸ” 1    πŸ’¬ 0    πŸ“Œ 0
Post image

The @the_robwaz is setting up for his @DEFCONAcademy talk on Race Conditions at 1pm in room 235! At @DEFCON? Come learn about concurrency errors in software!

09.08.2025 19:54 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

Hello Hackers! Earned a @pwncollege belt? Other amazing achievements? Hanging out @DEFCON? Come by @DEFCONAcademy and get belted at 5pm!

09.08.2025 19:05 β€” πŸ‘ 4    πŸ” 1    πŸ’¬ 0    πŸ“Œ 0

Hello Hackers! Come to @DEFCON Academy (room 235) for a live episode of our pwn.talk starting NOW!

09.08.2025 19:00 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Post image

Standing room only at @x3ero0’s @DEFCON Academy talk about Getting into CTF!

08.08.2025 23:59 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Post image

Come to @DEFCON Academy to see @TheWyrmSuperior talk about buffer overflows, starting in two minutes!

08.08.2025 21:58 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

We are going full speed in @DEFCON's @DEFCONAcademy! Two talks down (Intro to Linux and Intro to Assembly), with the next talk (Intro to Buffer Overflows) at 3pm. Meanwhile, learners are learning through hands-on challenges between the talks. Come by and LEARN TO HACK in W235!

08.08.2025 21:09 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Post image

Me waiting for the @DARPA AI Cyber Challenge result announcement after having interviewed all the teams:

08.08.2025 17:59 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

@DEFCONAcademy is a big effort, brought to you by dozens of people. I'll call them out on this thread throughout the weekend, but why wait? Come meet them in person and pick up some skills!

08.08.2025 01:33 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

Best of all? You might get to meet @the_robwaz, to whose effort we owe this year's @DEFCONAcademy. Robert has spent months working tirelessly to make sure everything goes smoothly, and will be standing by to oversee and guide. Don't miss this opportunity to learn from the best!

08.08.2025 01:33 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 1    πŸ“Œ 0
Post image

Need more motivation? We have swag and awards! Come early, and we'll have stickers. Solve enough challenges, and we'll give you a limited-edition challenge coin, a pwn shirt, or, for the true high achievers, a belt to induct you into the martial art of hacking. All at Room 235!

08.08.2025 01:32 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 1    πŸ“Œ 0

@DEFCONAcademy is approachable to all, regardless of skill level or equipment. We have laptops for you to use, our material ranges from "how to Linux" to "how to exploit microarchitectural vulnerabilities in CPUs" to much in between, all, again, with mentor support! COME LEARN!

08.08.2025 01:32 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 1    πŸ“Œ 0
Post image

We've spent the intervening year preparing a whole weekend of talks, demos, fascinating material, and dozens of mentors standing by to help you learn through hundreds of hands-on challenges. Check out the schedule (defcon.pwn.college/) and come to Room 235 to learn!

08.08.2025 01:32 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 1    πŸ“Œ 0
Zardus: "Hello hackers! In case you missed it at @defcon: …" - DEF CON Social Hello hackers! In case you missed it at @defcon: @perribus, @adamdoupe, @the_robwaz, @TheConnorNelson, @thedarktangent and I announced @DEFCONAcademy! I kept meaning to spread the word, and now that there's hype (https://news.asu.edu/20241031-science-and-technology-def-con-academy-looks-serve-build-community), it's time for the thread! Read on! 🧡

Learning impediments abound, from a lack of resources to a lack of mentorship. Last year, @thedarktangent, @perribus, @adamdoupe, @the_robwaz, @theconnornelson, and I announced @DEFCONAcademy, an effort to bridge these impediments for the community (defcon.social/deck/@...).

08.08.2025 01:32 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 1    πŸ“Œ 0

This is my 25th year attending @DEFCON, in roles ranging from wandering the halls as a newbie to competing in village competitions to competing in and then running the DEF CON CTF itself. I've watched many people become a bit less noob alongside me, and... it's not easy!

08.08.2025 01:32 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 1    πŸ“Œ 0

Hello hackers! Excited for @DEFCON tomorrow? Make sure to stop by @DEFCONAcademy, a brand new community effort to provide a path for everyone to LEARN TO HACK. Read on for the details! 🧡

08.08.2025 01:32 β€” πŸ‘ 2    πŸ” 0    πŸ’¬ 1    πŸ“Œ 0

That was a longer thread than expected, but we're super excited about these next steps in CTF Academy! Stay tuned for more exciting stuff in the future and, if you want a non-microblogging place to stay up to date, keep an eye on ctf.asu.edu/educatio...

13.05.2025 23:38 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

Want to see your education platform feeding into CTFs as well? If you run an educational platform that you think is a great bridge to CTF Academy, let us know!

13.05.2025 23:38 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 1    πŸ“Œ 0

An amazing cryptography education resource is cryptohack.org. These hackers, too, would be amazing to help ramp into CTF and the real world. Now, once you reach Level 15 there, you're welcome to join us at CTF Academy by filling out this form! docs.google.com/form...

13.05.2025 23:38 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 1    πŸ“Œ 0
Preview
pwn.college Learn to Hack!

On to the Platforms! pwn.college has good (and growing!) content in various security concepts, but shines most in binary exploitation. Other sites (I maintain a list at https://wargame.nexus) have other specialties, so including their top hackers would be great!

13.05.2025 23:37 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 1    πŸ“Œ 0
Preview
pwn.college Learn to Hack!

pwn.college Green Belts learn ROP, Heap, kernel security, and even microarch concepts, so we're inviting Green (and, pending capacity, earlier) Belts to CTF Academy! We expect this will help Green Belts solidify their skills without adding too much CTF mentor load.

13.05.2025 23:37 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 1    πŸ“Œ 0

This has worked quite well! Rather than explaining Heap Exploitation, the mentors could focus on, e.g., tricky heap massaging in complex applications, or just how to approach a complex challenge in general. In fact, it's worked well enough that we're relaxing the requirements!

13.05.2025 23:37 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 1    πŸ“Œ 0
Preview
pwn.college Learn to Hack!

Next, we're scaling hacker skill levels! So far, we limited CTF Academy to hackers who completed the Blue Belt (Advanced Exploitation) material on pwn.college, so that mentors would not be overloaded with introductory technical mentoring, saving mentoring capacity.

13.05.2025 23:37 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 1    πŸ“Œ 0
Preview
CTF Academy - Call for Mentors CTF Academy is an initiative to help pwn.college students transition from self-paced training to real-world CTF competitions. We invite experienced CTF teams to mentor students during live CTFs. Mentors guide students through challenges, answer technical questions, and help them experience the thrill of competing on the leaderboard. By joining CTF Academy as a mentor, you get to shape the next generation of CTF players and potentially discover future teammates. For more information visit CTF Academy

On the mentor side, we're scaling this out to more teams! If you're an established CTF team that is interested in taking a turn in the mentor rotation, we'd love to have you on board! Check out more info and a sign up form here: docs.google.com/form...

13.05.2025 23:37 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 1    πŸ“Œ 0

Today, we're growing the CTF Academy in three ways: more mentors, more skill levels, and more platforms! Read on for the full scoop, or stay up to date on the new CTF Academy website: ctf.asu.edu/educatio...

13.05.2025 23:37 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 1    πŸ“Œ 0

@Shellphish and @l3akctf have taken turns mentoring our team of budding hackers through CTFs, leading to flags, skills, confidence development, and some great results! Last week, the CTF Academy team placed 21st in @DamCTF; a few weeks ago, 27th in boilers! Now it's time to grow.

13.05.2025 23:37 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 1    πŸ“Œ 0

Over the intervening months, this idea has solidified into a pilot project! This has largely been thanks to the awesome work of @X3eRo0, the Sensei of CTF Academy, and our mentor teams @Shellphish and @l3akctf. The CTF Academy has been busy...

13.05.2025 23:37 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 1    πŸ“Œ 0
Zardus: "Output Gap: pwn.college should prepare students t…" - DEF CON Social Output Gap: pwn.college should prepare students to step directly into technical cybersecurity roles, but in practice, there's a gap between students honing skills on carefully-crafted educational challenges versus applying this knowledge in more chaotic environments.

Back in July, ASU's ACE Institute launched the CTF Academy with the goal of bridging this gap through mentorship of top pwncollege learners by established CTF teams and players through CTF competitions (en route to the real world)! That July announcement: defcon.social/@Zardu...

13.05.2025 23:37 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 1    πŸ“Œ 0
Post image

Capture the Flag contests aren't specifically meant to educate: challenges can involve learning, perfecting, or expanding skills, but may or may not help the hacker with that process. This approachability gap between pwncollege and CTF/real security is something we often observe.

13.05.2025 23:37 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 1    πŸ“Œ 0

@zardus is following 1 prominent accounts