Uploaded by ChRiStIaAn008 on Sep 20, 2010
Speakers: Meredith L. Patterson, Len Sassaman
One of the most difficult aspects of securing a protocol implementation is simply bounding the scope of the attack surface: how do you tell where attacks are likely to crop up? Historically, variations between implementations have led to some of the most successful attack techniques -- from simple TCP "Christmas tree" packets to last year's multiple break of the X.509 certificate authority system (by these speakers). But without access to all the relevant source code, how can developers identify potential sources of exploitable variations in behavior? In this presentation, we go beyond the accumulated wisdom of "best practices" and demonstrate a quantitative technique for minimizing inconsistent behavior between implementations. We will also show how this technique can be used from an attacker's perspective. Last year we showed you how to break X.509; this year, we will show you how we found those vulnerabilities and how the same techniques can be used to discover multiple novel 0-days in any vulnerable protocol implementation.
For more information click here (http://bit.ly/dwlBpJ)
-
5 likes, 0 dislikes
14:58
Black Hat USA 2010: Exploiting the Forest with Trees 2/5by ChRiStIaAn008681 views
14:58
Black Hat USA 2010: Exploiting the Forest with Trees 4/5by ChRiStIaAn008163 views
14:57
Black Hat USA 2010: Exploiting the Forest with Trees 3/5by ChRiStIaAn008269 views
14:58
Black Hat USA 2010: Network Stream Debugging with Mallory 2/5by ChRiStIaAn008971 views
13:39
Black Hat USA 2010: Exploiting the Forest with Trees 5/5by ChRiStIaAn008165 views
14:58
Black Hat USA 2010: State of SSL on the Internet: 2010 Survey Results and Conclusions 1/4by ChRiStIaAn008549 views
4:09
Len Sassaman & Meredith Patterson are CodeCon Valentinesby geekentertainmenttv1,504 views
14:58
Black Hat USA 2010: The Emperor Has No Clothes: Insecurities in Security Infrastructure 1/4by ChRiStIaAn008570 views
14:58
Black Hat USA 2010: Bad Memories 1/4by ChRiStIaAn008449 views
0:30
Black Hat USA 2010: Network Stream Debugging with Mallory 5/5by ChRiStIaAn008305 views
14:58
Black Hat USA 2010: Attacking Phone Privacy 1/5by ChRiStIaAn008693 views
14:58
Black Hat USA 2010: Understanding Fragmentation Heap: From Allocation to Exploitation 1/4by ChRiStIaAn008687 views
14:58
Black Hat USA 2010: GWT Security: Don't Get Distracted By Bright Shiny Objects 1/4by ChRiStIaAn008684 views
14:58
Black Hat USA 2010: Everybody Be Cool This is a Roppery 1/5by ChRiStIaAn008281 views
14:57
Black Hat USA 2010: The Emperor Has No Clothes: Insecurities in Security Infrastructure 3/4by ChRiStIaAn008227 views
14:58
Black Hat USA 2010: JavaSnoop: How to Hack Anything Written in Java 1/4by ChRiStIaAn0082,210 views
2:19
I bought a rainforest - International trailerby WGfilm3,849 views
14:58
Black Hat USA 2010: Malware Attribution: Tracking Cyber Spies and Digital Criminals 1/5by ChRiStIaAn0081,024 views
14:57
Black Hat USA 2010: Mastering the Nmap Scripting Engine 1/5by ChRiStIaAn0083,075 views
10:00
Black Hat USA 2010: Jackpotting Automated Teller Machines Redux 1/5by ChRiStIaAn0084,532 views
- Loading more suggestions...
Link to this comment:
All Comments (0)