Uploaded by ChRiStIaAn008 on Jan 29, 2011
Speaker: Martyn Ruks Senior Security Consultant MWR InfoSecurity
Every day billions of dollars pass through middleware, the unglamorous component of most enterprise applications. Middleware may be unglamorous, but even if billions of dollars doesn't interest you, it's bound to attract someone's interest sooner or later. Often security is addressed in the front-end web server and back-end database but the other components are often ignored. The reason for this can be a lack of understanding of the risks or lack of knowledge of the middleware products and how they can be attacked. One important property of a multi-tier environment is the ability to reliably pass data between authorised system components and therefore messaging software is often required. A popular and widely deployed example of such a component is IBM's Websphere MQ (formally MQ Series).
This software can be run across a number of platforms including Microsoft Windows, commercial and Open Source UNIX platforms and IBM \u2019s z/OS and i5 Operating Systems. Companies use the technology to pass messages between application components and it is widely deployed across a wide range of industry sectors including Finance, Retail, Healthcare and many others. During penetration tests conducted by MWR InfoSecurity against its clients it has been discovered that the security features provided by the product are either not utilised correctly or are not suitable for their intended use.
This presentation will uncover the truth behind Websphere MQ security as it is deployed in the real world and will look at how the software can be abused by an attacker resulting in remote code execution. The talk will focus on methods for analysing the security controls that can be used to protect an installation of MQ and the limitations of each of them. Following on from this section of the talk a number of methods will be presented for compromising both the message data and the Operating System through the MQ service. This will culminate in a demonstration of some of the attacks presented in the talk, followed by a discussion about the methods that exist for protecting an installation and ensuring that security breaches do not occur.
For more information visit: http://bit.ly/defcon15_information
To download the video visit: http://bit.ly/defcon15_videos
Category:
Tags:
License:
Standard YouTube License
-
1 likes, 0 dislikes
52:53
DEFCON 15: VIRTUAL WORLD, REAL HACKINGby ChRiStIaAn008368 views
6:48
WAS7 Part 4 - Configuring Service Integration Bus, JMS Queue and Topicby kanoncloud1,505 views
38:38
DEFCON 15: Panel 1: Meet the Fedby ChRiStIaAn008324 views
14:47
WebSphere MQ Webinar Online workshop 1/4by RoyalCyberSolutions1,271 views
11:32
WAS7 Part 5 - Installing WebSphere MQ and Configuring MQ in WASby kanoncloud1,897 views
10:45
IBM WebSphere Message Queue (MQ)- RoyalCyber-webinar-Part 3 of 4by RoyalCyberSolutions1,514 views
48:50
DEFCON 15: Hacking the EULA: Reverse Benchmarking Web Application Security Scannersby ChRiStIaAn008219 views
6:18
What is Enterprise Messaging?by jazonsamillano11,754 views
46:49
DEFCON 15: Tactical Exploitationby ChRiStIaAn008258 views
44:20
DEFCON 17: Advanced SQL Injectionby ChRiStIaAn00812,501 views
2:12
Track 02 - Nailin´ The Kelvinby skatr1503205 views
45:15
DefCon 15 How to be a WiFi Ninjaby basic2049,276 views
1:32
IBM Linux Commercial: The Kidby NOSMax33,405 views
47:10
DEFCON 15: Dirty Secrets of the Security Industryby ChRiStIaAn008850 views
55:22
DEFCON 15: Black Ops 2007: Design Reviewing The Webby ChRiStIaAn008197 views
10:00
OpenSplice DDS Explained - Part 1/2by OpenSpliceTube5,904 views
53:24
DEFCON 15: Computer and Internet Security Law - A Year in Review 2006 - 2007by ChRiStIaAn008128 views
4:32
DEFCON 18: Industrial Cyber Security 4/4by ChRiStIaAn008148 views
29:49
DEFCON 15: Fingerprinting and Cracking Java Obfuscated Codeby ChRiStIaAn008503 views
2:09
IBM WebSphere Application Server Installationby ankilbpatel23,987 views
- Loading more suggestions...
Link to this comment:
All Comments (0)