40 Years of Phrack: Hacking, Zines & Digital Dissent

richinseattle, Netspooky, Chompie

DEF CON 33 · Day 3 · Main Stage

Overview

Phrack is the longest-running hacker technical publication in existence. Born in 1985 on a BBS in an era before the World Wide Web, it has survived Secret Service raids, legal battles, the commerciali

Slides

Visual summary for 40 Years of Phrack: Hacking, Zines & Digital Dissent by richinseattle, Netspooky, Chompie
Visual summary for 40 Years of Phrack: Hacking, Zines & Digital Dissent by richinseattle, Netspooky, Chompie

Key moments

  1. 0:48 Phrack history: from 1985 origins through 40 years of underground hacking culture
  2. 2:24 This was the era of early network intrusion research.
  3. 5:00 x86 and SPARC exploitation — broadening from a single architecture to...
  4. 8:00 Phrack is expanding its physical and geographic reach.
  5. 11:00 Heap Exploitation Papers: Extended analysis of modern allocator techniques,...
  6. 14:00 Physical DEF CON issue: 10,000 copies of Phrack 72 distributed at the conference
  7. 17:24 The vulnerability lifecycle starts in underground research.

40 Years of Phrack: Hacking, Zines & Digital Dissent

Speakers: richinseattle, Netspooky, Chompie

Conference: DEF CON 33 (Las Vegas, August 10, 2025)

YouTube: https://www.youtube.com/watch?v=TW-D1I27E08

Slides: https://media.defcon.org/DEF%20CON%2033/DEF%20CON%2033%20presentations/richinseattle%20Netspooky%20Chompie%20-%2040%20Years%20of%20Phrack%20Hacking%20Zines%20%26%20Digital%20Dissent.pdf

Overview

Phrack is the longest-running hacker technical publication in existence. Born in 1985 on a BBS in an era before the World Wide Web, it has survived Secret Service raids, legal battles, the commercialization of security research, the rise and fall of multiple hacker generations, and years of extended dormancy — always to re-emerge as the place where the most technically ambitious offensive security research finds its home.

At DEF CON 33, the current Phrack editorial team — richinseattle, Netspooky, and Chompie — delivered a 40th anniversary retrospective and celebration, including the announcement and distribution of Phrack 72, the first issue produced under the new staff and the landmark 40th anniversary edition. The talk is simultaneously a technical history of offensive security research, a cultural history of the hacker underground, and a statement of intent about where Phrack is heading.

For practitioners in offensive security research, exploitation development, and the broader security community, Phrack is not mere nostalgia. It is the publication where "Smashing the Stack for Fun and Profit" appeared, where the first heap exploitation techniques were documented, where SMM bootkits were introduced to the world, and where techniques that later became industry-standard offense originated as underground research. Understanding Phrack's history is, in a meaningful sense, understanding the history of modern exploitation.

Background

1985–1991: Phone Phreaking and the BBS Era

Phrack was founded in 1985 by Taran King on the Metalhot BBS. In this pre-internet era, BBSes were the infrastructure of the hacker underground: direct-dial connections, pirated software, and the exchange of zero-day techniques. Phrack's early content reflected the era's preoccupations — phone phreaking, obtaining free phone calls, and the culture of digital exploration that would later be codified in texts like the Hacker Manifesto.

The defining event of this era was the 1991 publication of the E911 paper — a detailed technical document about the 911 emergency calling system. The Secret Service determined that this crossed a line. They raided the operators; Bruce Sterling documented the aftermath in The Hacker Crackdown. The Electronic Frontier Foundation was created in direct response to provide legal defense. Ultimately the charges were dropped, but the incident defined the tension between technical publication and legal jeopardy that would shadow Phrack for years.

1992–1996: X.25, Mobile Networks, and Legion of Doom

After the raid, Chris Goggins (Taran King's successor) and Eric Bloodaxe of the Legion of Doom took over. The content shifted from phone phreaking to X.25 (the leased-line corporate proto-internet), early mobile networks like AMPS (the analog cellular system Kevin Mitnick exploited with an OKI 900 handset while being pursued by the FBI), and emerging network exploitation techniques. This was the era of early network intrusion research.

1996 brought another transition: Route took over editorial control. Two significant events define this period in exploitation history: the release of nmap (the network scanner that became foundational to modern security assessment) and, most significantly, the publication of "Smashing the Stack for Fun and Profit" by Aleph One (Elias Levy). This paper, appearing in Phrack 49, introduced the concept of stack-based buffer overflow exploitation to a broad audience and launched the memory corruption exploitation era that still defines much of offensive security practice today.

2001–2005: The Memory Corruption Expansion

Phrack entered an anonymous editorial phase from 2001 to 2005. The content expanded from stack overflows to:

  • Return-to-libc / ROP chains — bypassing non-executable stack protections
  • Format string exploitation — abusing %n format specifiers for arbitrary writes
  • glibc hardening techniques — documenting and analyzing emerging compiler protections
  • "Living off the land" — using legitimate system tools and libraries to avoid forensic detection (a concept Phrack documented before it became a mainstream red team methodology)
  • First heap exploitation papers — extending memory corruption techniques to heap allocators

This era also produced the first three physical printed copies of Phrack: at the Dutch hacker camp Hac.What (2001), at Ruxcon, and at What the Hack. The print editions were a deliberate act of historical documentation, connecting underground digital publishing to a physical artifact tradition.

2005 Onward: Depth, Breadth, and Dormancy

Transitions to Mayhem, Thiago, and Strauss took Phrack into increasingly technical territory:

  • x86 and SPARC exploitation — broadening from a single architecture to multi-platform techniques
  • SMM bootkits — Rodrigo Branco's publication of the first SMM (System Management Mode) bootkit techniques represented a significant escalation: SMM runs at a privilege level below the hypervisor, making SMM-resident malware essentially invisible to all OS-level defenses
  • Heap allocator deep dives — extended papers on glibc, jemalloc, and Windows heap implementation internals
  • Kernel infection and kprobes — techniques for persistent Linux kernel compromise
  • ELF infection — file-format level persistence in Linux executables
  • OSX exploitation after the Intel switch — Apple's transition to x86 opened new attack surfaces immediately documented in Phrack

Extended dormancy periods between issues became characteristic of the later years. The publication's output slowed, but each issue remained technically dense.

Key Findings

This talk is not a vulnerability disclosure but a historiographical and cultural document. Its key "findings" are a curated account of what Phrack actually contributed to the field:

1. Phrack preceded and shaped exploitation practice. Techniques documented in Phrack — format string exploitation, return-to-libc, heap exploitation, living off the land — later became foundational concepts in offensive security certification programs, red team playbooks, and CVE exploitation. The publication created the shared technical vocabulary that practitioners use today.

2. The current team represents genuine editorial continuity. The transition from the previous Phrack staff to the current team (richinseattle, Netspooky, Chompie, and collaborators) occurred through a deliberate selection process. Previous staff noticed the current team's work on Tempout, an ELF virus zine, and identified it as operating in the same spirit as Phrack. The handoff was brokered through Grock (a prior Phrack staff member) via Discord. Netspooky described it as the equivalent of a small DJ stream being invited to run an entire legendary club.

3. Phrack 72 is substantive. Sixteen mainline papers and eight inline noise pieces, produced with a global contributor base spanning generations of hackers. The issue includes: papers on CPU backdoors and microcode; North Korean hacker box shell credential files; old-school throwback techniques alongside cutting-edge exploitation research; ELF infection techniques; kernel injection; and a sophisticated binary exploitation CTF.

4. Phrack is expanding its physical and geographic reach. 15,000 physical copies across four different conference-specific covers (DEF CON, Dutch hacker camp Y, HOPE New York, and a print order edition), plus distribution at HitCon (Taiwan) and Dragon Jarcon (Medellín, Colombia). The physical print run is the largest in Phrack's history.

Technical Deep Dive

Phrack 72: Issue Content

Phrack 72 — the 40th anniversary edition — was produced for release at DEF CON 33 and simultaneously at the Dutch hacker camp Y (held the same week). Notable technical content includes:

CPU Backdoors and Microcode: Exploration of hardware-level backdoors through microcode manipulation — an area of research sitting at the intersection of hardware security, firmware analysis, and supply chain risk. Microcode updates modify processor instruction behavior at the silicon level; understanding how they can be weaponized represents a frontier of offensive research.

North Korean Hacker Infrastructure: A paper examining a North Korean hacker toolbox including a shell environment with password files — a rare primary-source look at DPRK threat actor operational infrastructure obtained through technical means.

SMM and Firmware: Continuing the tradition established by Rodrigo's earlier SMM bootkit work, Phrack 72 includes papers extending techniques in the firmware exploitation domain — at privilege levels below the hypervisor and inaccessible to OS-layer defenses.

ELF Infection and Kernel Injection: Linux-focused persistence techniques, continuing Phrack's long tradition of documenting low-level Unix exploitation. Dev CM kernel injection by SD and DEVIC explores advanced kernel-level implantation.

Heap Exploitation Papers: Extended analysis of modern allocator techniques, applicable to contemporary CTF and real-world vulnerability exploitation.

Pi3's Stack Cookie Bypass: A paper documenting byte-by-byte overflow chain techniques for bypassing stack canaries remotely — a refinement of a technique Pi3 (Adam) had explored in Phrack 67.

CTS (Phrack 71 author): Another returning contributor, extending prior published work.

Phrack 72 CTF

Chompie designed the Phrack 72 CTF as a centerpiece of the anniversary release. Key design elements:

  • Requires physical copies: The CTF cannot be solved without both the DEF CON Phrack 72 copy and the Y copy. QR codes in each copy combine to provide the challenge URL, enforcing physical participation across two continents as a prerequisite.
  • Two binary exploitation challenges: One Linux, one Windows — both based on realistic vulnerability research and exploit development, not contrived CTF puzzles.
  • Collaboration-first design: The requirement for two different physical copies from two different conferences was intentional — the CTF rewards community collaboration across geographic boundaries.
  • Prizes: An exclusive Phrack coin (designed by ACMA) plus a 0-day public drop from Phrack 72, with the winning writeup featured on the Phrack website.
  • Status at talk time: The Linux challenge had been solved; the Windows challenge remained open.

The Physical Print Initiative

The 15,000-copy print run represents a deliberate choice to establish Phrack as a physical artifact, not merely a digital archive. The new team learned magazine layout software to produce print-quality output. Four different covers were commissioned for different release contexts:

| Edition | Designer | Notable Feature |

|---|---|---|

| DEF CON | MAR | 10,000 copies; CTF QR code |

| Y (Dutch hacker camp) | Not specified | CTF QR code (required with DEF CON copy) |

| HOPE (NYC) | Digitalis & Portal | Exclusive cover; released following week |

| Online print order | Netspooky | Available for purchase |

Additional conference copies at HitCon (Taiwan) and Dragon Jarcon (Medellín, Colombia) represent Phrack's explicit push toward global distribution — the first Latin American distribution in the publication's history.

Demo / PoC

The "demo" in this talk is the distribution of Phrack 72 itself — physical copies available at DEF CON, CTF challenges active, and the full 40th anniversary issue in the hands of attendees. Specific deliverables:

  • Phrack 72 physical copies — 10,000 at DEF CON, with remaining distribution at Y, HOPE, HitCon, Dragon Jarcon
  • Phrack 72 CTF — live during DEF CON and continuing online
  • Phrack coins — commemorative coins for contributors, staff, and CTF winners
  • Phrack website (pending CTF solve) for future releases and writeups

The publication accepts submissions on a rolling basis. The team described their editorial philosophy: deep technical content, global contributor base, accessible to experienced practitioners but unwilling to compromise on depth.

Defensive Implications

A talk about Phrack is fundamentally about offensive research, but defenders benefit from understanding what Phrack documents:

The vulnerability lifecycle starts in underground research. Techniques published in Phrack — from Smashing the Stack to heap exploitation to SMM bootkits — typically precede their appearance in mass exploitation by years. Reading Phrack gives defenders a forward-looking view of where the offensive community is investing research effort.

SMM and firmware persistence is a real threat. Phrack has been documenting firmware-level attack techniques for over a decade. Defenses at the OS layer are categorically insufficient against SMM-resident implants. Hardware security modules, Secure Boot chain of trust validation, and firmware integrity monitoring are required.

"Living off the land" has hacker roots. The phrase and concept originated in underground research and Phrack documentation before becoming a standard red team term. Understanding the research basis helps defenders recognize the genuine scope of the technique beyond its current buzzword status.

Heap exploitation is ongoing and maturing. Modern allocators (glibc 2.3x, Windows segment heap, jemalloc) have protections, but Phrack contributors continue to identify novel exploitation paths. Defenders should treat memory-safe languages and compiler mitigations (ASAN, heap integrity checks) as meaningful but not absolute defenses.

Underground publishing creates attribution challenges. Phrack's pseudonymous tradition means that significant offensive capability development occurs in a context deliberately divorced from individual identity and corporate attribution. This complicates threat intelligence that relies on identity-linked actor tracking.

Key Takeaways

  • Phrack 72, released at DEF CON 33 as the 40th anniversary edition, is the first issue under the current editorial team and represents a genuine continuation of Phrack's technical depth with expanded global reach.
  • The 40-year history of Phrack maps directly onto the history of exploitation technique development: from phone phreaking through stack overflows, heap exploitation, SMM bootkits, and beyond — Phrack published many of these techniques first.
  • The new team (richinseattle, Netspooky, Chompie, and expanded staff) received the publication directly from previous editors who identified their work on the Tempout ELF virus zine as spiritually aligned with Phrack's mission.
  • Phrack 72's 15,000-copy physical print run, four-cover release across multiple continents, and collaborative CTF represent a significant operational expansion beyond anything previous editors attempted.
  • The publication continues to accept submissions on a rolling basis and represents a meaningful venue for deep offensive security research that commercial publication channels are poorly suited to carry.

About the Speakers

richinseattle is a former DEF CON and Black Hat speaker and trainer with a long career in offensive security. He brings institutional memory of the broader hacker conference community and serves as a public face for the new Phrack editorial team. He describes himself as "the old guy on stage" among the current Phrack staff.

Netspooky describes themselves as an "online menace" and is a core member of the new Phrack editorial team. Active in the ELF virus and low-level binary research communities, Netspooky's work on the Tempout zine — an ELF virus publication — was what first brought the current team to the attention of previous Phrack staff. They designed the online print order cover for Phrack 72 and manages much of the publication's community presence.

Chompie is a professional poster, exploit writer, and reverse engineer on the Phrack team. She designed the Phrack 72 CTF, including both binary exploitation challenges (Linux and Windows), with a deliberate emphasis on realistic vulnerability research and collaborative participation requiring physical copies from multiple conferences. She is representative of the current Phrack team's commitment to CTF and community engagement as a vector for surfacing new talent and maintaining hacker culture.

All three speakers are part of a broader editorial staff including additional contributors, editors, and an arts team responsible for the publication's expanded print production capabilities.

Reviews

Dr. Zero (Offensive Security Researcher) — STRONG ACCEPT

The current Phrack editorial team — richinseattle, Netspooky, and Chompie — deliver a 40th anniversary retrospective of Phrack, documenting the publication's history from 1985 BBS-era phone phreaking through 'Smashing the Stack,' heap exploitation, SMM bootkits, and to the present day. The talk also announces and distributes Phrack 72, the first issue under the new editorial team, with 15,000 physical copies across four conference-specific covers, a cross-continental binary exploitation CTF, and sixteen mainline technical papers.

Heather Calloway (CISO) — SOLID

The current Phrack editorial team delivers a 40th anniversary retrospective coinciding with the release of Phrack 72 — the first issue under new stewardship, with 16 technical papers, a cross-continental CTF, and 15,000 physical copies. The talk maps Phrack's history against the development of offensive security technique. For practitioners who care about where the field came from and what Phrack 72 contains, this is worth the time.

→ Top-rated talks at DEF CON 33

All talks from DEF CON 33