40 Years Of Phrack: Hacking, Zines & Digital Dissent -richinseattle, Netspooky, Chompie
Rich in Seattle, Net Spooky, Chompy (professional poster)
DEF CON 33 · Day 1 · Main Stage
Overview
The DEF CON talk "40 Years Of Phrack: Hacking, Zines & Digital Dissent" offered a comprehensive journey through the history, evolution, and enduring cultural significance of Phrack, arguably the most iconic and longest-running hacker zine. Presented by Rich in Seattle, Net Spooky, and Chompy, with contributions from past authors and staff, the session celebrated Phrack's four-decade legacy as a crucible for groundbreaking technical research, a platform for digital dissent, and a vital community builder. The speakers not only meticulously chronicled Phrack's pivotal role in shaping the hacker ethos from the BBS era to the modern internet but also unveiled the ambitious revitalization efforts by its new editorial staff.

Key moments
- 0:00 Introduction and Phrack's origins on BBS in 1985
- 2:00 E911 paper, Secret Service raid, and EFF's creation
- 2:50 Nmap, 'Smashing the Stack' and memory corruption era
- 3:40 Heap exploitation, SMM hacking, and first physical Phrack copies
- 6:00 How the Tempout team became the new Phrack staff
- 7:10 New staff's first print issue and conference distribution
40 Years Of Phrack: Hacking, Zines & Digital Dissent
Speakers: Rich in Seattle, Former Devcon/Black Hat Speaker/Trainer; Net Spooky, Online Menace; Chompy, Professional Poster
Conference: DEF CON
YouTube: https://www.youtube.com/watch?v=TW-D1I27E08
Overview
The DEF CON talk "40 Years Of Phrack: Hacking, Zines & Digital Dissent" offered a comprehensive journey through the history, evolution, and enduring cultural significance of Phrack, arguably the most iconic and longest-running hacker zine. Presented by Rich in Seattle, Net Spooky, and Chompy, with contributions from past authors and staff, the session celebrated Phrack's four-decade legacy as a crucible for groundbreaking technical research, a platform for digital dissent, and a vital community builder. The speakers not only meticulously chronicled Phrack's pivotal role in shaping the hacker ethos from the BBS era to the modern internet but also unveiled the ambitious revitalization efforts by its new editorial staff.
This talk served as both a historical retrospective and a forward-looking vision, emphasizing Phrack's continuous adaptation to new technological landscapes while staying true to its core spirit of open knowledge sharing and community empowerment. It highlighted how Phrack has consistently pushed the boundaries of security research, from early phone phreaking and memory corruption exploits to advanced kernel and hardware attacks. More than just a technical archive, the discussion underscored Phrack's unique position as a cultural touchstone that has inspired generations of hackers, fostered collaboration, and challenged the commercialization of exploit knowledge.
The session culminated in the announcement of Phrack 72, a record-breaking release that embodies the zine's renewed energy and global reach. By addressing prevalent issues like imposter syndrome among potential contributors and navigating the complexities of commercial interests in the cybersecurity industry, the speakers articulated a clear vision for Phrack's future: to remain a beacon for technical excellence, digital dissent, and community-driven knowledge exchange, encouraging a new generation to contribute and uphold the hacker spirit.
Background
▶ Watch: Introduction and Phrack's origins on BBS in 1985 (0:00)
Phrack Magazine emerged in 1985, predating the widespread adoption of the World Wide Web and standard internet usage. Born on a BBS (Bulletin Board System), it served as a direct-dial platform for message boards, files, and text documents, becoming a nexus for early hacker culture. The initial era, spanning the 1980s until 1991, was heavily influenced by phone phreaking, where individuals explored telecommunication systems to make free calls and connect to other BBSs, sharing pirated software and nascent zero-day techniques. This period solidified the foundational ethos of digital dissent and exploration, famously encapsulated in The Hacker Manifesto, a seminal document first published in Phrack.
A significant turning point occurred in 1991 when the Secret Service raided several hackers associated with Phrack after the publication of the E911 paper, which detailed vulnerabilities in the emergency services system. This event, chronicled in Bruce Sterling's book The Hacker Crackdown, led to the formation of the Electronic Frontier Foundation (EFF), which successfully defended the accused, ultimately leading to dropped charges. This incident cemented Phrack's role as a platform for challenging authority and advocating for digital rights.
The zine continued its evolution through distinct eras, each marked by shifts in technology and exploitation techniques. The Legion of Doom took the helm in 1992, transitioning research from pure phone phreaking to X.25 leased-line corporate internet and early mobile networks like AMPS. This era saw papers detailing techniques used by figures such as Kevin Mitnick, who famously leveraged an OK900 phone. By 1996, under the leadership of route, Phrack released Nmap, the now-ubiquitous network scanner, and published the highly influential "Smashing The Stack For Fun And Profit," a paper that effectively launched the modern memory corruption exploitation era.
From 2001 to 2005, an anonymous group of contributors expanded on these techniques, introducing concepts like Return-to-libc (ret2libc), format string exploitation, and the first papers on heap exploitation. This period also saw the development of living off the land techniques to evade forensics and Grugq's work on binary hardening. Phrack began publishing physical copies during this time, notably at Dutch hacker camps and Ruxcon. Subsequent leadership transitions, including Mayhem, Thiago, and Strauss, pushed the boundaries further, delving into SMM (System Management Mode) hacking—with Rodrigo contributing early bootkit papers—and exploring advanced rootkits like those detailed in Malak Malificarium and Devme rootkits. The publication of Radare and early OSX attacks (following Apple's switch to x86) further broadened its scope. The pre-current staff era continued deep dives into heap allocators, hardened FTP servers, taint analysis, and kernel infection techniques using K probes, with contributions from BS Damon and Elfmaster.
The current staff's involvement began with Net Spooky and Chompy, who previously collaborated with Rich in Seattle on Tempout, an ELF virus zine. Their work caught the attention of the previous Phrack staff, with Atesache acting as a liaison. This transition, described as akin to a small Twitch DJ being asked to run a major techno club, was driven by a shared spirit of grassroots hacking and community. The new team quickly embarked on creating a new issue, learning magazine layouts, and expanding distribution, leading to the highly anticipated Phrack 72.
Key Findings
▶ Watch: Nmap, 'Smashing the Stack' and memory corruption era (2:50)
The talk highlighted several key findings and contributions, primarily centered on the revitalization and enduring relevance of Phrack in the contemporary hacker landscape.
Firstly, the successful transition and reinvigoration of Phrack by a new generation of staff, including Net Spooky, Chompy, and Rich in Seattle, stands as a significant achievement. This new team, hailing from the Tempout zine, was tasked with maintaining Phrack's legacy while adapting it for modern audiences, a challenge they met by expanding the editorial team, arts team, and logistics support globally. Their efforts culminated in Phrack 72, which represents the largest release in the zine's history, featuring 16 mainline papers and 8 "line noise" contributions, with a staggering 15,000 copies printed for distribution across various international conferences.
Secondly, the talk identified and directly addressed imposter syndrome as a pervasive barrier preventing talented individuals from contributing to Phrack. The speakers recounted common reactions from potential authors: "Me, write for Phrack? I'm not good enough." This finding underscored a crucial cultural challenge within the hacker community—many highly skilled individuals underestimate their own capabilities or perceive Phrack as an exclusive domain. The message from the new staff was clear: "We are all Phrack," emphasizing that the zine is a community project driven by the collective knowledge and spirit of hackers, regardless of their perceived status. This call to action, encapsulated by the quote "If not you, who? If not now, when?", aims to encourage a broader, more diverse range of contributors.
Thirdly, the talk presented an innovative approach to community engagement through the Phrack 72 CTF (Capture The Flag). Designed by Net Spooky, this unique binary exploitation challenge requires physical collaboration, as players must combine QR codes from two different print copies of Phrack 72 (one from DEF CON, one from a Dutch hacker camp) to access the challenge link. This mechanism not only fosters inter-conference interaction but also serves as a practical, hands-on demonstration of the technical skills Phrack promotes. The CTF features two challenges—one targeting Linux and another targeting Windows—described as "realistic vulnerability research exploit development tasks" based on real-life bugs, offering a Frack coin prize and early public access to Phrack 72 for the winners.
Finally, the discussion provided critical insights into the complex relationship between the traditional hacker ethos and the commercialization of exploits. Speakers acknowledged that while commercialization is an "unstoppable force" driven by individual motivations and the growth of the security industry, it often comes at the expense of community building. They highlighted a shift from sharing knowledge for collective growth to publishing for personal brand or financial gain. Phrack's continued existence, supported by industry luminaries and community contributions, stands as a testament to the enduring value of open, non-commercial knowledge sharing and the importance of maintaining the "Phrack spirit" of giving back.
Technical Deep Dive
▶ Watch: Heap exploitation, SMM hacking, and first physical Phrack copies (3:40)
Phrack's four-decade history is a veritable catalog of cutting-edge technical research, charting the evolution of hacking from its nascent stages to highly sophisticated modern attacks. The talk underscored many of these pivotal technical contributions.
The zine's genesis was deeply rooted in phone phreaking, where early hackers explored the intricacies of the telephone network to achieve feats like free long-distance calls. While the specific methods weren't detailed in the talk, this era laid the groundwork for understanding complex systems and finding unintended uses. As technology advanced, Phrack transitioned to documenting early network exploitation. The Legion of Doom era saw exploration of X.25 corporate networks and AMPS mobile networks, prefiguring modern wireless security research. A landmark contribution was the release of Nmap in 1996, which revolutionized network reconnaissance and port scanning, becoming an indispensable tool for both attackers and defenders.
The late 1990s and early 2000s were dominated by memory corruption vulnerabilities, largely popularized by Phrack. The seminal "Smashing The Stack For Fun And Profit" detailed buffer overflows, demonstrating how to overwrite return addresses on the stack to achieve arbitrary code execution. This foundational paper directly led to the development of sophisticated techniques like Return-to-libc (ret2libc), which allowed attackers to bypass non-executable stack protections by chaining calls to existing library functions. Further innovations included format string exploitation, where vulnerabilities in printf-like functions could be abused to read or write arbitrary memory locations, and early papers on heap exploitation, detailing methods to manipulate memory allocators for control.
Phrack also extensively covered rootkits and stealth techniques. The influential Malak Malificarium series explored complex kernel-level rootkits, including the Devme rootkits paper by SD and DEVIC, which delved into kernel injection. SMM (System Management Mode) hacking emerged as a particularly advanced area, with Rodrigo (a current Phrack staff member and panelist) contributing some of the first papers on SMM bootkits, demonstrating how to implant persistent malicious code at a very low level of the system architecture. The concept of living off the land was also introduced, emphasizing the use of pre-installed system tools and features to avoid leaving forensic traces.
As systems grew more complex, Phrack continued to push the envelope. Later issues delved into intricate details of different heap allocators, exploring their internal mechanisms to find new exploitation primitives. Taint analysis became a focus for identifying how untrusted input could flow through a system to vulnerable sinks. Kernel infection techniques evolved, with contributions like Elfmaster's work on Linux kernel infection and the use of K probes for dynamic kernel instrumentation and subversion. The zine also adapted to new platforms, detailing attacks on OSX after its transition to x86 architecture. More recently, Phrack has touched upon esoteric hardware topics such as CPU backdoors and microcode manipulation, demonstrating the zine's continuous pursuit of the deepest technical vulnerabilities.
The Phrack 72 CTF, designed by Net Spooky, serves as a modern embodiment of Phrack's technical spirit. It features two binary exploitation challenges—one tailored for Linux and another for Windows. These are not "puzzly CTF" challenges but rather "realistic vulnerability research exploit development tasks," drawing from real-life bugs discovered by the designer. This hands-on approach directly applies the principles of memory corruption, system interaction, and exploit development that Phrack has chronicled for decades, challenging participants to leverage deep technical understanding to solve complex, practical security problems.
Demo / Proof of Concept
▶ Watch: How the Tempout team became the new Phrack staff (6:00)
While the talk itself did not feature a live, traditional software demonstration or exploit execution, it effectively presented an innovative and interactive "demo" in the form of the Phrack 72 CTF (Capture The Flag). This CTF serves as a powerful proof of concept for Phrack's commitment to community engagement, technical education, and fostering collaborative hacking.
The Phrack 72 CTF is meticulously designed to inspire collaboration and active participation. To even begin the challenge, participants must acquire two physical copies of Phrack 72: one distributed at DEF CON and another from the Y (Dutch hacker camp) conference. Inside each issue, a unique QR code is printed. The "puzzle" aspect of the CTF requires combining these two QR codes to unlock the link to the challenge platform. This ingenious mechanism encourages inter-conference networking and reinforces the value of the physical zine as a tangible artifact of hacker culture.
Once accessed, the CTF presents two distinct binary exploitation challenges: one targeting a Linux environment and the other a Windows environment. Net Spooky, the designer, emphasized that these are not abstract, "puzzly" CTFs but rather "realistic vulnerability research exploit development tasks." These challenges are based on actual bugs and exploitation scenarios encountered in real-life vulnerability research, providing participants with a practical experience in identifying and exploiting vulnerabilities. The design encourages cross-platform collaboration, with a call to "Linux friends, find your Windows friends, Windows friends, find your Linux friends" to work together on solving both challenges.
The incentives for solving the CTF are significant. Winners receive an exclusive Frack coin, a custom-designed token of appreciation by ACMA, a Phrack staff member. More importantly, successfully solving the CTF makes Phrack 72 publicly available online, offering an "0-day drop" of the zine to the broader community. This strategy creates a direct link between community participation and the open dissemination of cutting-edge research, embodying Phrack's core principle of knowledge sharing. Additionally, winners gain "hacker cred," with their write-ups potentially being featured on the official Phrack website, further encouraging detailed technical documentation and peer recognition. As of the talk, only the Linux challenge had been solved, leaving the Windows challenge open for discovery, highlighting its complexity and the ongoing opportunity for engagement.
This CTF, therefore, acts as a dynamic, community-driven proof of concept that Phrack is not merely a historical archive but a living, evolving platform actively engaging the next generation of hackers through challenging, real-world technical problems. It demonstrates a creative approach to distributing knowledge and fostering the collaborative spirit that has defined Phrack for 40 years.
Defensive Implications
▶ Watch: New staff's first print issue and conference distribution (7:10)
Phrack's relentless pursuit and documentation of vulnerabilities have historically served as a critical, albeit adversarial, driver for defensive security advancements. The talk, by recounting Phrack's history, inherently highlighted the constant cat-and-mouse game between attackers and defenders, and offered insights into current and future defensive strategies.
From the early days of Smashing the Stack, Phrack's publications directly led to the development of fundamental memory safety mitigations. The widespread exploitation of buffer overflows spurred the implementation of non-executable stacks (NX/XD bit), stack cookies (CANARYs), and eventually Address Space Layout Randomization (ASLR), designed to make reliable exploitation significantly harder. The detailed papers on Return-to-libc (ret2libc) and format string exploitation forced operating system developers and compilers to harden their codebases and runtime environments. Rodrigo, a panelist, aptly summarized this continuous learning by noting that his current work in fuzzing is essentially "rootkitting a process" to modify data in transit for bug discovery, a technique directly stemming from his early exposure to elf and kernel infection papers in Phrack. Understanding these historical attack vectors remains crucial for modern defenders to build robust systems and identify recurring vulnerability patterns.
Looking ahead, the discussion touched upon the future of mitigations, predicting the widespread adoption of Control Flow Integrity (CFI) within the next decade. CFI aims to ensure that program execution follows a legitimate path, preventing attackers from hijacking control flow. Furthermore, the speakers anticipated the integration of advanced hardware-level protections such as pointer authentication and various forms of memory tagging. Technologies like CHERI and ARM MTE (Memory Tagging Extension), which enforce memory safety at the hardware level by tagging memory regions and pointers, are expected to significantly raise the bar for heap exploitation and other memory corruption attacks by enforcing life cycle enforcement for heap objects. These advancements are envisioned to span the entire software stack, from application and allocator levels down to the runtime and hardware.
However, the talk also underscored emerging attack surfaces and challenges for defenders. The increasing complexity of modern systems, including virtualized kernels and intricate hypervisors, creates new layers for potential vulnerabilities. The rise of AI-generated code presents a significant concern; a recent report indicated that approximately 40% of AI-generated code contains vulnerabilities. While this percentage mirrors human-written code's vulnerability rate (as observed by Google's OSS-fuzz), the sheer volume and speed of AI code generation could introduce a massive wave of insecure software. Beyond traditional software, the speakers highlighted the immaturity and insecurity of nascent technologies like blockchains and the difficulty in securing AI/Large Language Models (LLMs) against prompt injection attacks, as exemplified by a DEF CON CTF challenge that bypassed "unhackable" LLM defenses. The imminent arrival of AI robots in homes and the broader cyber-physical world transition represent a new frontier where digital vulnerabilities could have direct, tangible impacts on the physical environment, demanding a holistic and proactive defensive posture.
Ultimately, Phrack's continued existence and revitalization serve as a defensive implication in itself. By fostering a community where cutting-edge research is openly shared, it empowers a new generation of security professionals to understand, analyze, and ultimately defend against the most sophisticated threats. The emphasis on ethical hacking, community knowledge sharing, and challenging the commercialization of exploits reinforces the idea that collective intelligence and transparency are powerful tools in the ongoing fight to secure the digital world.
Key Takeaways
- Phrack's Enduring Legacy: For 40 years, Phrack has been a foundational pillar of hacker culture, evolving from BBS-era phone phreaking to modern hardware and kernel exploitation, consistently documenting groundbreaking technical research and fostering digital dissent.
- A New Era of Revitalization: Under new leadership, Phrack has successfully launched Phrack 72, its largest release ever with 15,000 copies distributed globally, demonstrating a renewed commitment to its original spirit and community.
- Empowering New Voices: The Phrack team actively combats imposter syndrome within the hacker community, encouraging talented individuals, regardless of experience, to contribute their knowledge and uphold the zine's "we are all Phrack" ethos.
- Innovation in Engagement: The Phrack 72 CTF exemplifies a creative approach to community involvement, combining physical distribution with collaborative binary exploitation challenges based on real-world vulnerabilities, offering exclusive prizes and early access to the zine.
- Navigating Commercialization: The talk provided a nuanced perspective on the "unstoppable force" of exploit commercialization, advocating for individuals to maintain moral integrity and the community spirit of knowledge sharing, despite the industry's shift towards personal gain.
- The Future of Hacking and Defense: Hacking continues to expand into hybrid attacks across software and hardware layers. Upcoming mitigations like CFI, pointer authentication, and memory tagging will strengthen defenses, but new frontiers like AI-generated code, insecure emerging technologies (blockchains, LLMs), and the cyber-physical world present novel challenges for both attackers and defenders.
About the Speaker(s)
Rich in Seattle is introduced as a former DEF CON speaker, Black Hat speaker, and trainer, and is affectionately referred to as the "old guy on stage," signifying his deep roots and extensive experience in the cybersecurity community. He played a key role in setting the historical context for Phrack, drawing from his long-standing involvement in the hacker scene.
Net Spooky is described as an "online menace" and was instrumental in the transition of Phrack to its new staff. Previously working on the Tempout zine with Rich in Seattle and Chompy, Net Spooky was approached by the former Phrack staff, specifically Grock, to take over the zine. Net Spooky is also the designer of the innovative Phrack 72 CTF, which incorporates realistic binary exploitation challenges based on their own bug discoveries.
Chompy is introduced as a "professional poster" and is part of the new Phrack staff, having collaborated with Rich in Seattle and Net Spooky on the Tempout zine. Chompy contributes to the collective effort of revitalizing Phrack and expanding its reach and influence within the global hacker community.
Reviews
Dr. Zero (Offensive Security Researcher) — SOLID
A loving retrospective on Phrack's 40-year run that earns its place on a DEF CON stage by virtue of subject matter alone — this is cultural history that matters. But the talk is fundamentally a celebration and a recruitment pitch, not a technical research session, and it should be graded accordingly: it does its job competently without doing anything that will stick in memory beyond the nostalgia hit.
Heather Calloway (CISO) — WEAK
A heartfelt cultural retrospective on Phrack's 40-year history that delivers real value to the underground technical community but offers almost nothing to security leaders, defenders, or institutions. The governance and operational layers are entirely absent — this is a celebration, not a briefing.