DEF CON 33 - Game Hacking 101  - Julian 'Julez' Dunning

DEF CON 33 - Game Hacking 101 - Julian 'Julez' Dunning

Source: YouTube · DEFCONConference · published Oct 10, 2025 · 39:56

Cybersecurity
No ratings yet Log in to rate
Transcript Available
Description

This talk explores game hacking as a way to learn security concepts 1:47, with Julian from offensive security sharing insights on game vulnerabilities 0:00.

Key Takeaways:
• Game logic exploits like "shadow boxing" in Baldur's Gate demonstrate how newer games aren't necessarily more secure 4:25
• Super Mario 64's backward speed exploit shows how missing negative value caps create security vulnerabilities 7:20
• Modding drives gaming innovation, with major titles like Counter-Strike and Dota originating as mods 12:40
• Memory hacking allows players to find and modify game values like health and position 16:01
• Anti-cheat systems create a kernel-level permissions battle between developers and hackers 22:24

The Game Hacking Village offers practical challenges to learn these security concepts through gaming 27:01.

Sources:

  • 0:00 Introduction of Julian and his background
  • 1:47 Purpose: game hacking for learning, not cheating
  • 4:25 Baldur's Gate "shadow boxing" exploit example
  • 7:20 Super Mario 64 backward speed exploit
  • 12:40 Modding examples driving gaming innovation
  • 16:01 Memory hacking concepts and tools
  • 22:24 Anti-cheat systems and kernel level permissions
  • [27

Generate CPE Credits

Generate a professional CPE document from this video's transcript.

Estimated credit: 0.5 CPE hours

Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.

Topic: Cybersecurity. Commonly maps to: Security and Risk Management, Security Operations. Exact CISSP domains are assigned during generation.

CISSP Domain Mapping
Learning Objectives
Self-Assessment Questions
PDF Export Ready

Free account. One generation at a time, with a daily limit.

CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.

Watch on YouTube

Transcript Preview

First 800 characters of the transcript

All right. So, uh, going forward, uh, who am I? I'm Julian. Uh, I do a lot within the offensive security space. Uh, a lot of storied history doing that within consulting and everything. That's most of what my background has been. As part of that uh, I founded co-founded a open security uh, project and then turned company called Truffle Hog uh, or Truffle Security uh, as the company where we found a lot of open source secrets. So that's kind of like the the base of where I'm coming from. I also have done a lot of password cracking research. So just random things that I've been interested in from an offensive security space has kind of been like my go-to. Um I was I had the honor of being on the Forbes 30 under 30 back in, you know, the day I'm now officially a has been. So um and then I als…