Kiosk Hacking: Windows XP Exploits & iKAT Tools from Defcon 16

By | August 6, 2026

Last Updated on August 6, 2026 by Craig Allen Keefner

Quick Answer

The Defcon 16 Kiosk Hacking demonstration, led by Paul Craig, showcased methods to exploit Windows XP and Windows 7 kiosks by leveraging remote input vectors and bypassing application sandboxes. A key tool highlighted was iKAT, an online resource at ikat.h.cked.net, designed to help penetration testers escape application jails on kiosk terminals. While the demonstration specifically targeted older Windows versions, the underlying principles of these exploits remain relevant for informing current security strategies across various kiosk operating systems and lockdown software. The full methodology is detailed in the 'defcon-16-craig' PDF presentation.

What was covered in the Kiosk Hacking Demo at Defcon 16?

Lots of tools out there. This one sorts of puts the wrap on Windows XP (and 7 to extent).Complete how-to from Defcon 16 and Paul Craig (who has since moved onto ATMs).

The Kiosk Hacking Demo at Defcon 16 covered a complete how-to for exploiting Windows XP and 7 kiosks, detailing tools like iKAT (ikat.h.cked.net) and various remote input vectors. The full methodology is available in the 'defcon-16-craig' PDF presentation, which outlines methods to escape application jails and leverage vulnerabilities through JavaScript, Java Applets, ActiveX, ClickOnce applications, Internet Zone protocol handlers, file type handlers, and browser plug-ins like Flash and QuickTime.

Industry Group Kiosks Digital Signage

The web address for iKat is ikat period h period cked period net

  • An online tool you visit from any Kiosk terminal.
  • Provides content to help an escape from any application jail.
  • “Sure would help me during penetration tests”

 

Available Remote Input Vectors:
 Remotely hosted content, viewed by a Kiosk.
 JavaScript.
 Java Applets.
 ActiveX.
 ClickOnce applications (.NET Online Application Deployment).
 Internet Zone protocol handlers.
 File type handlers.
 Flash, Director, Windows Media Player, Real, QuickTime, Acrobat, other browser plug-ins.

More Security Kiosk news

    Frequently Asked Questions

    1 Are the Windows XP exploits discussed in the Defcon 16 demonstration still relevant for modern kiosk security?

    While the Defcon 16 demonstration specifically targeted Windows XP, the underlying principles of exploiting remote input vectors and application sandbox bypasses remain relevant. Understanding these historical methods helps inform current security strategies for various kiosk operating systems and lockdown software.

    2 What kind of protection lockdown software is mentioned to prevent kiosk hacking?

    The article mentions protection lockdown software like Sitekiosk and KioWare as examples used to secure kiosks. The demonstration focused on ways to exploit systems even when protected by such solutions, highlighting the need for robust and continuously updated security measures.

    3 What is the iKAT tool mentioned in the Defcon 16 kiosk hacking demonstration?

    The iKAT tool, accessible via ikat.h.cked.net, is described as an online resource designed to help escape from application jails on kiosk terminals. It provides content to facilitate bypassing security measures during penetration tests.

    4 Does the article provide resources for understanding kiosk penetration testing methodologies?

    Yes, the article references a complete how-to PDF presentation from Defcon 16 by Paul Craig, titled "defcon-16-craig". This resource details the methods and tools used in the kiosk hacking demonstration, including the iKAT online tool.

    Author: Craig Allen Keefner

    Craig Allen Keefner is an industry analyst, content strategist, and longtime authority on self-service kiosks, digital signage, unattended payment systems, and interactive technology. He manages content and industry strategy for Kiosk Industry and The Industry Group, with a focus on kiosk software, hardware-software integration, accessibility, payment compliance, healthcare kiosks, restaurant self-service, and emerging AI automation. Craig has covered the self-service and kiosk industry since the 1990s, tracking how public-facing terminals move from concept to field deployment. His work combines industry research, vendor analysis, operator conversations, standards tracking, trade show coverage, and practical experience with the real-world constraints of kiosk deployments. https://www.linkedin.com/in/kiosk