Black Hat Europe 2010 Media

Published: April 24th, 2010 | Category: Security Conferences, Security Workshops | (1) Comment

The Black Hat Europe 2010 wrapped up recently and the initial batch of media from the event have been uploaded. Some of the more interesting sessions are listed below, though please note that some do not have media files uploaded yet. We will update you once they come online.

  • Universal XSS via IE8s XSS FiltersDavid Lindsay & Eduardo Vela Nava
    Even with Internet Explorer 8’s XSS security features, there are still ways to break through and even abuse it. The presenters even showed how an exploit could potentially endanger almost all major websites with this security hole. PPT
  • SAP Backdoors: A ghost at the heart of your businessMariano Nuñez Di Croce
    Most high-profile companies use SAP as their software of choice for Enterprise Resource Planning. With operations spanning several countries for most of these firms, the temptation for a cyber criminal to enter this type of system is very high indeed. This talk concentrates on how this type of financial fraud is performed and some steps to detect, prevent and secure against it. A free tool for such a task is also introduced by the speaker. PPT
  • Practical Crypto Attacks Against Web ApplicationsThai Duong & Juliano Rizzo
    A strong crypto-based attack is distilled to a usable form as presented by these speakers. It allows hackers to access encrypted data from a few major online services and web development frameworks. They further revealed that there are more of these vulnerabilities that will come out as they continue their research. PDF | PPT
  • Oracle, Interrupted: Stealing Sessions and CredentialsSteve Ocepek & Wendel G. Henrique
    One of the most popular database systems in the world is also one of the most often the subject of hack attacks – Oracle. With a combination of take-over exploits and downgrade attacks, the pair introduces a novel approach to account hijacking in Oracle with the help of a new tool called thicknet. PDF | PPT
  • Abusing JBossChristian Papathanasiou
    JBoss, a J2EE server architecture used for custom middleware, is the target of this session’s exploits. A Metasploit framework is executed that can possibly become a persistent backdoor that can be used to connect directly and control the target machine or machines. PPT
  • Hacking Cisco Enterprise WLANsEnno Rey & Daniel Mende
    WLAN solutions for enterprise customers are a rather new technology. The presenters dive into the vulnerabilities of these wireless networks and introduce a tool that can exploit the system to take over the WDS master role, extract WPA pairwise master keys, among others. PDF | PPT
  • Attacking JAVA Serialized CommunicationManish Saindane
    A plug-in for Burp is used as a PoC for handling JAVA Object Serialization data streams to give pentesters the same control and power a developer has. PDF | PPT | CODE
  • Next Generation ClickjackingPaul Stone
    Misdirection in the Internet has been around ever since it began. As software became more sophisticated, so did the software used to waylay Web surfers. The presentation includes basic clickjacking information, a demo of several cross-browser attacks and a new tool that while easy to use is a great case on why clickjacking attacks need to be urgently addressed. PPT
  • Virtual ForensicsChristiaan Beek
    A talk on the issues when using virtual environments and system forensics – the challenges faced and tools that can be used. PPT
  • Fireshark – A tool to Link the Malicious WebStephan Chenette
    A new tool that can crawl a throng of websites at a time to execute, store and analyze their content. With this, researchers can more easily see the “state of the Web” in terms of what malicious content is out there and also to reconstruct deobfuscated code. PPT
  • Defending the PoorFX
    The speaker discusses a “simple but effective approach” to help secure Adobe Flash content and Flash movies.
  • 0-knowledge fuzzingVincenzo Iozzo
    A primer on how to fuzz effectively with no information on the user input or the code using techniques such as code coverage, data tainting and in-memory fuzzing.

Stay tuned for more presentations and media from this conference.

Black Hat Europe Around The Web

Published: April 20th, 2010 | Category: Security Conferences | (1) Comment

Another great security event has come and gone. Here are a few posts related to the recent Black Hat Europe conference held in Barcelona last April 12 – 15.
Summary posts of the conference activities:

BlackHat Briefings Day #1
BlackHat Briefings Day #2
BlackHat Europe 2010 Conference
Attending Security Conferences from a Social Point of View

Posts about individual talks during [...]

Week 15 in Review – 2010

Published: April 19th, 2010 | Category: Hacking Contests, Security Conferences, Security Tools, Security Training, Security Vulnerabilities, Security Workshops, Vendor News | (1) Comment

Events Related:

Announcing 1st Workshop: Malicious PDF Analysis – brucon.org
Didier Stevens talks about PDFiD and pdf-parser at Brucon this year.
MSU Red Team – Fun, Success – mcgrewsecurity.com
This CCDC was a “practice” run for two Alaskan teams and two Hawaiian teams.

Resources:

Cell Phone Security – cellphones.org
With the increased capabilities and conveniences of today’s cell phones comes the increased [...]

Week 14 in Review – 2010

Published: April 12th, 2010 | Category: Security Conferences, Security Tools, Security Training, Security Vulnerabilities, Vendor News | (0) Comments

Events Related:

CERIAS Symposium Posts

Opening Keynote: Mike McConnell (Symposium Summary) – cerias.purdue.edu
Morning Keynote Address: DHS Undersecretary Rand Beers (Symposium Summary) – cerias.purdue.edu
CERIAS Seminar Presentation: David Bell (Symposium Summary) – cerias.purdue.edu
Panel #1: Visualization of Security (Symposium Summary) – cerias.purdue.edu
Panel #2: Infosec Ethics (Symposium Summary) – cerias.purdue.edu
Panel #3: The Evolution of Research Funding and Projects (Symposium Summary) – [...]

Week 13 in Review – 2010

Published: April 5th, 2010 | Category: Hacking Contests, Security Conferences, Security Vulnerabilities, Vendor News | (1) Comment

Events Related:

CanSecWest posts
A round-up of the events in the recent Canadian conference

CanSecWest 2010 Day 1 – sophos.com
CanSecWest 2010 day 2 summary – sophos.com
CanSecWest 2010 day 3 summary – sophos.com
Hacker Olympics: a shout-out from Vancouver, BC! – technet.com

Videos in Hack in the Box – hitb.org
Videos of the keynotes of HITB Malaysia 2009

Resources:

Passware Kit Forensic Decrypts [...]

Information Security Events in April

Published: March 31st, 2010 | Category: Hacking Contests, Security Conferences, Security Training, Security Workshops | (1) Comment

Here are the information security events in North America this month:

Notacon 7 – April 15 – 18 in Cleveland

InfoSec World 2010 – April 17 – 23 in Orlando

Source Boston 2010 – April 21 -23 in Boston

THOTCON 0×1 – April 23 in Chicago

QuahogCon – April 23 -25 in Providence

SecurityBSides Boston – April 24 – 25 in [...]

CanSecWest 2010 in Pictures

Published: March 29th, 2010 | Category: Hacking Contests, Security Conferences, Security Tools, Security Vulnerabilities | (2) Comments

CanSecWest 2010 banners

Tom Gallagher and David Conger from Microsoft talk about distributed file fuzzing and the Microsoft Office 2010 security model.

  
Some other notes from their talk:

Office supports 300 file formats. each can have different sub formats .wpd extension has 3 different parsers. fuzzing surface=huge
Microsoft built their own distributed fuzzer system [...]

Week 12 in Review – 2010

Published: March 29th, 2010 | Category: Hacking Contests, Security Tools, Vendor News | (1) Comment

Events Related:

Security BSides San Francisco and Austin – uncommonsensesecurity.com
Reminiscing about past BSides.
Pwn2Own 2010 Day 1 Overview – liquidmatrix.org
A look back into the events of the first day of Pwn2Own.
Outerz0ne 2010 Videos – archive.org
Talks from their latest event.

Resources:

VERIS Incident Classification Mindmap – verizonbusiness.com
VERIS employs the A4 Threat Model developed by Verizon’s Risk Intelligence team.
Security Book Review: [...]

CanSecWest 2010 Agenda

Published: March 23rd, 2010 | Category: Parties, Security Conferences | (1) Comment

Canada’s premier conference is starting tomorrow, March 24! CanSecWest is the most comprehensive and advanced applied digital security event in North America. With cutting-edge speakers delving into a host of highly-informative and highly-technical sessions, this is one security conference you would not want to miss.
Unlike most events, CanSecWest features a single track of presentations, distilling [...]

Week 11 in Review – 2010

Published: March 22nd, 2010 | Category: Hacking Contests, Security Conferences, Security Tools, Security Vulnerabilities, Security Workshops, Vendor News | (2) Comments

Events Related:

Belated RSA postings
Some last-minute RSA catchups

RSA 2010 – Day 1 Metricon – chuvakin.blogspot.com
RSA 2010 – Day 2-3 – chuvakin.blogspot.com
RSA 2010 – Day 4-5 – chuvakin.blogspot.com

Ninja Networks Twitter – twitter.com
Follow ninjanetworks @ twitter leading up to and during DEFCON for Ninja badge and event information.
Hackers In Japan – hackerspaces.org
The primary idea is to do a [...]

Infosec Events. Copyright 2010. All Rights Reserved.
Home - Calendar - Communities - Training - Archives - Contact