Last Updated on August 6, 2026 by Craig Allen Keefner
The Defcon 16 Kiosk Hacking demonstration, led by Paul Craig, showcased methods to exploit Windows XP and Windows 7 kiosks by leveraging remote input vectors and bypassing application sandboxes. A key tool highlighted was iKAT, an online resource at ikat.h.cked.net, designed to help penetration testers escape application jails on kiosk terminals. While the demonstration specifically targeted older Windows versions, the underlying principles of these exploits remain relevant for informing current security strategies across various kiosk operating systems and lockdown software. The full methodology is detailed in the 'defcon-16-craig' PDF presentation.
What was covered in the Kiosk Hacking Demo at Defcon 16?
Lots of tools out there. This one sorts of puts the wrap on Windows XP (and 7 to extent).Complete how-to from Defcon 16 and Paul Craig (who has since moved onto ATMs).
The Kiosk Hacking Demo at Defcon 16 covered a complete how-to for exploiting Windows XP and 7 kiosks, detailing tools like iKAT (ikat.h.cked.net) and various remote input vectors. The full methodology is available in the 'defcon-16-craig' PDF presentation, which outlines methods to escape application jails and leverage vulnerabilities through JavaScript, Java Applets, ActiveX, ClickOnce applications, Internet Zone protocol handlers, file type handlers, and browser plug-ins like Flash and QuickTime.
The web address for iKat is ikat period h period cked period net
- An online tool you visit from any Kiosk terminal.
- Provides content to help an escape from any application jail.
- “Sure would help me during penetration tests”
Available Remote Input Vectors:
Remotely hosted content, viewed by a Kiosk.
JavaScript.
Java Applets.
ActiveX.
ClickOnce applications (.NET Online Application Deployment).
Internet Zone protocol handlers.
File type handlers.
Flash, Director, Windows Media Player, Real, QuickTime, Acrobat, other browser plug-ins.
More Security Kiosk news