Uploaded by mediarchives on May 30, 2009
Recorded at www.ToorCon.org Oct 20, 2007. Content posted by www.MediaArchives.com BLACK OPS 2007 DESIGN REVIEWING THE WEB, with Dan Kaminsky. Design bugs are really difficult to fix - nobody ever takes a dependency on a buffer overflow, after all. Few things have had their design stretched as far as the web; as such, I've been starting to take a look at some interesting aspects of the "Web 2.0" craze. Here's a few things I've been looking at: Slirpie: VPN'ing into Protected Networks With Nothing But A Lured Web Browser. Part of the design of the web is that browsers are able to collect and render resources across security boundaries. This has a number of issues, but they've historically been mitigated with what's known as the Same Origin Policy, which attempts to restrict scripting and other forms of enhanced access to sites with the same name. But scripts are not acquired from names; they come from addresses. As RSnake of ha.ckers.org and Dan Boneh of Stanford University have pointed out, so-called "DNS Rebinding" attacks can break the link between the names that are trusted, and the addresses that are connected to, allowing an attacker to proxy connectivity from a client. I will demonstrate an extension of RSnake and Boneh's work, that grants full IP connectivity, by design, to any attacker who can lure a web browser to render his page. I will also discuss how the existence of attacks such as Slirpie creates special requirements for anyone intending to design or deploy Web Single Sign On technologies. Slirpie falls to some of them, but slices through the rest handily. p0wf: Passing Fingerprinting of Web Content Frameworks. Traditional OS fingerprinting has looked to identify the OS Kernel that one is communicating with, based on the idea that if one can identify the kernel, one can target daemons that tend to be associated with it. But the web has become almost an entirely separate OS layer of its own, and especially with AJAX and Web 2.0, new forms of RPC and marshalling are showing up faster than anyone can identify. p0wf intends to analyze these streams and determine just which frameworks are being exposed on what sites. LudiVu: A number of web sites have resorted to mechanisms known as CAPTCHAs, which are intended to separate humans from automated submission scripts. For accessibility reasons, these CAPTCHAs need to be both visual and auditory. They are usually combined with a significant amount of noise, so as to make OCR and speech recognition impossible. I was in the process of porting last year's dotplot similarity analysis code to audio streams for non-security related purposes, when Zane Lackey of iSec Partners proposed using this to analyze CAPTCHAs. It turns out that, indeed, Audio CAPTCHAs exhibit significant self-similarity that visualizes well in dotplot form. This will probably be the first Toorcon talk to use WinAMP as an attack tool.
-
3 likes, 1 dislikes
9:01
Pt2of7 BLACK OPS 2007 DESIGN REVIEWING THE WEB, with Dan Kaminsky.by mediarchives519 views
9:01
Pt3of7 BLACK OPS 2007 DESIGN REVIEWING THE WEB, with Dan Kaminsky.by mediarchives412 views
9:01
Pt5of7 BLACK OPS 2007 DESIGN REVIEWING THE WEB, with Dan Kaminsky.by mediarchives253 views
9:01
Pt5of7 BLACK OPS 2007 DESIGN REVIEWING THE WEB, with Dan Kaminsky.by mediarchives321 views
10:01
Pt7of7 BLACK OPS 2007 DESIGN REVIEWING THE WEB, with Dan Kaminsky.by mediarchives283 views
9:01
Pt6of7 BLACK OPS 2007 DESIGN REVIEWING THE WEB, with Dan Kaminsky.by mediarchives238 views
5:47
Demonstration of the Kaminsky bugby internetfoundation206 views
5:01
Hope2601 Pt 10, Adam Savage and "The RFID Censorship Question" www.HOPE.netby mediarchives572,920 views
7:42
Dan Kaminsky - IOActive - Part Oneby ITvoices481 views
0:38
audio captchaby hellonearthisman1,633 views
1:16:49
Blackhat 2010 Black Ops of fundamental defense Dan Kaminsky Partby killab66661383 views
8:16
Researchers explain serious MMS spoofing flaw at Black Hatby SearchSecurity14,995 views
2:09
Call of Duty 7: Black Ops Trailer Quick Analysisby UltraSquirrel7,586 views
8:26
Black Hat DC 2009 - Interview with Dan Kaminsky part 1/2by BlackHatBriefings2,307 views
1:23
How to make your internet 50x faster on a macby djedjeserb33,369 views
0:31
shmoocon 2007, Dan Kaminskyby risquette2,506 views
1:46
Sarah on DNSby effugas61,786 views
1:14
Defcon 16 - Dan Kaminsky Post Hacker jeopardy night 1.by meesensei717 views
12:31
Geek Alert: Dan Kaminsky on the DNS Bug of 2008by OreillyMedia12,661 views
9:00
Owasp5004 Part3 - GET RICH OR DIE TRYING: BLACK HAT WAY w Ford, Brennan, Grossmanby mediarchives137 views
- Loading more suggestions...
i love your uploads dude!
Antipolicestate 2 years ago