WHY2025

STÖK

Hacker | Creative | Security Researcher | Public Speaker

STÖK is passionate about learning new things and sharing his curiosity with the world. Over the past three decades, he has professionally hacked everything from computers, web technology, marketing strategies to consultancy, content creation, digital advertising, sustainable fashion, communication, and even the human mind.

His unique ability to ask the right questions and break down technically complex subjects in an entertaining way, combined with his passion for novel security research, attention to detail, curiosity, design and “Good Vibes Only” mentality, has inspired millions of people around the world.

His fast-paced creative presentation style and innovative security research have placed him on the main stages of multiple international security conferences, including Blackhat USA, DEF CON, Securityfest, Ekoparty, Disobey, SEC-T, and many more.


Session

08-08
19:00
50min
Flipping Bits: Your Credentials Are Certainly Mine
STÖK, joohoi

Did you know that if you change a single bit from 1 to 0 (or vice versa) in the first 'g' of the domain name google.com (which is 01100111 in binary) you will end up with variety of valid "bitflip" domains like coogle.com, oogle.com, & woogle.com

So what happens if you generate and register a bunch of cheap bitfliped versions of popular cloud / Saas provider domains, point them to your VPS, log all incoming requests & then forget about the whole thing for two years?

Hacking
Andromeda