Uploaded by ChRiStIaAn008 on Sep 24, 2010
Speakers: Meredith L. Patterson, Len Sassaman
One of the most difficult aspects of securing a protocol implementation is simply bounding the scope of the attack surface: how do you tell where attacks are likely to crop up? Historically, variations between implementations have led to some of the most successful attack techniques -- from simple TCP "Christmas tree" packets to last year's multiple break of the X.509 certificate authority system (by these speakers). But without access to all the relevant source code, how can developers identify potential sources of exploitable variations in behavior? In this presentation, we go beyond the accumulated wisdom of "best practices" and demonstrate a quantitative technique for minimizing inconsistent behavior between implementations. We will also show how this technique can be used from an attacker's perspective. Last year we showed you how to break X.509; this year, we will show you how we found those vulnerabilities and how the same techniques can be used to discover multiple novel 0-days in any vulnerable protocol implementation.
For more information click here (http://bit.ly/dwlBpJ)
-
2 likes, 0 dislikes
14:58
Black Hat USA 2010: Exploiting the Forest with Trees 4/5by ChRiStIaAn008163 views
14:58
Black Hat USA 2010: JavaSnoop: How to Hack Anything Written in Java 1/4by ChRiStIaAn0082,210 views
14:01
Black Hat USA 2010: Constricting the Web: Offensive Python for Web Hackers 1/4by ChRiStIaAn008794 views
4:29
Black Hat USA 2010: JavaSnoop: How to Hack Anything Written in Java 4/4by ChRiStIaAn008344 views
1:31
Black Hat USA 2010: Becoming the Six Million Dollar Man 6/6by ChRiStIaAn008181 views
9:59
Black Hat DC 2010: Internet Explorer turns your personal computer into a public file server 1/7by ChRiStIaAn0082,361 views
14:58
Black Hat USA 2010: JavaSnoop: How to Hack Anything Written in Java 2/4by ChRiStIaAn008710 views
4:09
Len Sassaman & Meredith Patterson are CodeCon Valentinesby geekentertainmenttv1,504 views
14:58
Black Hat USA 2010: App Attack: Surviving the Mobile Application Explosion 1/5by ChRiStIaAn008342 views
3:50
Altering Source Codeby TheHex3d4,871 views
14:57
Black Hat USA 2010: App Attack: Surviving the Mobile Application Explosion 3/5by ChRiStIaAn008178 views
14:57
Black Hat USA 2010: JavaSnoop: How to Hack Anything Written in Java 3/4by ChRiStIaAn008602 views
2:42
Black Hat USA 2010: Hacking Browser's DOM: Exploiting Ajax and RIA 6/6by ChRiStIaAn008176 views
14:01
Blackhat 2010 - You will be billed 90000 for this call - Mikko Hypponen-00.aviby killab666611,489 views
1:28
DEFCON 18 registration line at Black Hat USAby kingpinempire3,487 views
14:58
Black Hat USA 2010: Hacking Browser's DOM: Exploiting Ajax and RIA 1/6by ChRiStIaAn0081,570 views
2:30
CERTIFICATE AUTHORITY HACKING BY ANTO Y.aviby 2040anto28 views
14:58
Black Hat USA 2010: How to Hack Millions of Routers 2/4by ChRiStIaAn0081,915 views
3:06
Black Hat USA 2010: App Attack: Surviving the Mobile Application Explosion 5/5by ChRiStIaAn00892 views
10:00
Black Hat USA 2010: Jackpotting Automated Teller Machines Redux 1/5by ChRiStIaAn0084,532 views
- Loading more suggestions...
Link to this comment:
All Comments (0)