ie8 fix
madison

Zero Day

Ryan Naraine, Emil Protalinski and Dancho Danchev

Black Hat: 10 can't-miss hacks and presentations

By | August 1, 2011, 9:00am PDT

Summary: The 2011 Black Hat security conference is promising a smorgasbord of (in)security fun. From vulnerabilities in PLCs (programmable logic controllers) to the security design of Apple’s iOS and potential hacker attacks on medical implant devices, the range of presentations this year could be the best ever.

LAS VEGAS — The 2011 Black Hat security conference is promising a smorgasbord of (in)security fun. From vulnerabilities in PLCs (programmable logic controllers) to the security design of Apple’s iOS and potential hacker attacks on medical implant devices, the range of presentations this year could be the best ever.

Here’s my list of this year’s can’t-miss presentations:

1. Exploiting Siemens Simatic S7 PLCs

Dillon Beresford (right), a security researcher at NSS Labs, has already courted controversy with this topic.  The talk was originally scheduled for the TakeDownCon security conference in May but was withdrawn after some bigwigs (including the Department of Homeland Security) got nervous about the pre-patch disclosure ramifications.

At Black Hat, Beresford is promising to cover newly discovered Siemens Simatic S7-1200 PLC vulnerabilities and to demonstrate how an attacker could impersonate the Siemens Step 7 PLC communication protocol using some PROFINET-FU over ISO-TSAP and take control.

Beresford is a brand-name security researcher in the SCADA world.  Earlier this year, he developed an exploit for one of the most popular high performance production SCADA/HMI software applications in China which is widely used in power, water conservancy, coal mine, environmental protection, defense and aerospace.

Because security holes in Siemens’ PLCs played a key role in the success of the mysterious Stuxnet worm, Beresfords’s Black Hat disclosures is sure to raise eyebrows.

2. Hacking Google Chrome OS

Google + the cloud + web applications is a recipe for a fun security cocktail.

In the last few months, two members of the WhiteHat Security’s Threat Research Center — Matt Johansen and Kyle Osborn — hacked away at Google’s Cr-48 prototype laptops and discovered a slew of serious and fundamental security design flaws.

Now, they are sharing their findings with the Black Hat audience, promising to discuss security holes that could expose users to the following types of attacks:follow Ryan Naraine on twitter

  • Exposing of all user email, contacts, and saved documents.
  • Conduct high speed scans their intranet work and revealing active host IP addresses.
  • Spoofing messaging in their Google Voice account.
  • Taking over their Google account by stealing session cookies, and in some case do the same on other visited domains.

Johansen and Osborn said Google was informed of the findings and has already fixed some vulnerabilities they plan to discuss many of the underlying Google Chrome OS weaknesses that remain — including for evil extensions to be easily made available in the WebStore, the ability for payloads to go viral, and javascript malware survive reboot.

3. Apple iOS Security Evaluation: Vulnerability Analysis and Data Encryption

When Dino Dai Zovi speaks about Apple and security, you stop and listen.

Best known for his successful hijack of a MacBook at the CanSecWest hacker conference, Dai Zovi has now turned his attention to Apple’s iOS, the smartphone platform that powers iPhones and iPads.

Dai Zovi performed a detailed audit of the security mechanisms and features of iOS 4 and will share his findings on things like Trusted Boot, Mandatory Code Signing, Code Signing Enforcement, Sandboxing, Device Encryption, Data Protection, and (as of iOS 4.3) Address Space Layout Randomization.

The security assessment focused on the concerns of an enterprise considering a deployment of iOS-based devices or allowing employees to store sensitive business data on their personal devices so we can expect to hear about the real-world implications of using iPhones and iPads in the enterprise.

Dai Zovi is promising to document the risks of a lost device or a remote iOS compromise through a malicious web page or e-mail and, based on the strengths and weaknesses identified, make concrete recommendations on what compensating measures an organization can and should take when deploying iOS-based devices for business use.

4. Exploiting the iOS Kernel

Stefan Esser is best known for his epic work around PHP security but if you’ve been following his Twitter stream lately, you’d notice the German researcher has taken a liking to Apple’s iOS platform.

In this Black Hat session, Esser is promising a deep-dive discussion of kernel level exploitation of iPhones. It will include details on previously disclosed kernel vulnerabilities,  the exploitation of uninitialized kernel variables, kernel stack buffer overflows, out of bound writes and kernel heap buffer overflows.

Esser also plans to look closely at the kernel patches applied by iPhone jailbreaks to provide an understanding of how certain security features are deactivated.  He also plans to release a tool that allows the selectively de-activation some of certain kernel patches for more realistic exploit tests.

* Image via Sebastian Bergmann (Flickr CC 2.0)

5. Hacking Androids for Profit

The growing popularity of smart phones has generated a predictable surge in security research around mobile platforms and this year’s Black Hat agenda contains quite a few good presentations.

This talk, by Riley Hassell and Shane Macaulay, puts Android under the microscope with a promise to reveal new threats to Android Apps and discuss known and unknown weaknesses in the Android OS and Android Market.

The researchers will discuss the inner working of Android apps and the risks any user faces when installing and using apps from the marketplace.

Next — SSL and authenticity, water meter vulnerabilities, hacking medical devices…

Ryan Naraine is a journalist and social media enthusiast specializing in Internet and computer security issues.

Disclosure

Ryan Naraine

The most important disclosure is of my employment with Kaspersky Lab as a member of the global research and analysis team. Kaspersky Lab is a global company specializing in anti-malware and secure content management technologies. I do not own stocks or other investments in any technology company.

Biography

Ryan Naraine

Ryan Naraine is a journalist and social media enthusiast specializing in Internet and computer security issues. He is currently security evangelist at Kaspersky Lab, an anti-malware company with operations around the globe. He is taking a leadership role in developing the company's online community initiative around secure content management technologies.

Prior to joining Kaspersky Lab, Ryan was Editor-at-Large/Security at eWEEK, leading the magazine's and Web site's coverage of Internet and computer security issues and managing the popular SecurityWatch blog, covering the daily threats, vulnerabilities and IT security technologies. He also covered IT security, hacker attacks and secure content management topics for Jupiter Media's internetnetnews.com.

Ryan can be reached at naraine SHIFT 2 gmail.com. For daily updates on Ryan's activities, follow him on Twitter.

14
Comments

Join the conversation!

Just In

RE: Black Hat: 10 can't-miss hacks and presentations
sazkove 26th Sep
Android and Chrome OS can't enter the enterprise market if they are unibet so insecure. CIO's should understand Linux, Windows and MacOSX have decades in security research and are now safe to install in large enterprises. The problem with Google is they lost 10 years since 2000 and only cared about the web search market, and now they want to enter the OS market, but I think they are too ambitious and won't be able to have success in the enterprise market until they proove their software is secure. It is amazing to learn what things potentially can be hacked. But I think we should not loose focus on those items that we actually use and maintain ourself and where we sazkove kancelarecould be confronted with the consequences of a hack.
@kd5auq
very good one.
Will these videos be streamed anywhere?
Don't worry!!!!!!!!!!!!
EVERYTHING is computerized and NOTHING can go wrongggghhhhhh, wrongeeeecccchchh, wronggggggiiijjj.
Remember to LIE on all filled out forms.
@trm1945
Don't lie, just use Ryan's data wink

Hope they stream this shocked
It is amazing to learn what things potentially can be hacked. But I think we should not loose focus on those items that we actually use and maintain ourself and where we could be confronted with the consequences of a hack.

http://www.blackhat.com/html/bh-us-11/bh-us-11-schedule.html
0 Votes
+ -
The Nerd Lounge
NerdLounger 2nd Aug
The Nerd Lounge wants you! Come check us out and join in on the discussions! The Nerd Lounge is home to nerds like you and me.

www.thenerdlounge.com
0 Votes
+ -
Android and Chrome OS can't enter the enterprise market if they are so insecure. CIO's should understand Linux, Windows and MacOSX have decades in security research and are now safe to install in large enterprises. The problem with Google is they lost 10 years since 2000 and only cared about the web search market, and now they want to enter the OS market, but I think they are too ambitious and won't be able to have success in the enterprise market until they proove their software is secure.
@Gabriel Hernandez
Funny, I always thought that ChromeOS and Android (and OSX in a round abbout kind of way) were Linu based.....

The techniques and methods for securing operating systems are well known. The reason security holes still exist / reoccur is pretty much
* accidental errors in design / coding, which are either ignored or not picked up in testing, and
* deliberate errors in design, usually in favour of 'ease of use'
Mainly because products are rattling straight forward, locomotion, to see our own elements connected with coach factory outlet ???? you can actually just make an effort to accomplish without this.The reputation of the coach outlet with the good old bag, was actually the original inspiration came from a softball glove, Cheap replica Coach ******** features soft. coach factory outlet online ???? is actually a stylish Coach online store to sell high quality and discount Coach ********, Coach bags, Coach wallets etc. If you love Coach, you will like to get the best price on it. coach factory outlet store ???? comes from the prestigious American which has constantly introduced its classic series of works by their innovation. For your consideration is the Cheap coach purses ???? which is made in USA . It is crafted in traditional monogram canvas and has natural cowhide leather.Though ******** are basically an accessory item of girls, there are many modern ******** and wallets for males too as it has become the ultimate fashion accessory at coach factory outlet ????. coach outlet online ???? is the eldest, voice of reason, and authority of the Left 4 Dead 2 team, playing a similar role to Bill in Left 4 Dead. coach outlet ???? can provide the coach exactly the same is expected in a retail store. It can help you find bags of various colors, shapes and designs, which prove once again that the coach is actually a selection for the housekeeper. Are you still worrying about where to buy yourself a Coach? Then coach bags ???? Online offering top-quality goods and first-class service can be your way-out.He went rapidly up the stairs, walked into his unlocked coach ******** ???? room and at once fastened the latch. It's for you to obey, trembling creation, and not to have desires, for that's not for you!Almost everyone has identified effectively about this, below, among the best to make sure you will get much more information about coach outlet ????.I received the Coach purse I ordered at the coach outlet store ???? yesterday.I like its fashionable style as well as fine workmanship very much. coach outlet ???? has become a popular shopping experience for consumers around the world, and a desirable distribution channel for manufacturer's and retailers.There certainly are a amount of methods to acquire affordable coach products at coach factory outlet ????,it could possibly the most effective options.the most vital cause may be the reality that you simply can purchase genuine coach products at there.Coach ******** from the coach factory outlet online ???? are popular now because of the colorful fabric. It is fashionable and beautiful. You can see the opening of the bag like wave, which is its special design.Coach bags of coach factory store online ???? successfully conbine modernity and classicality and are quite suitable for fashionable young girls and ladies. coach outlet ???? can provide the coach exactly the same is expected in a retail store. It can help you find bags of various colors, shapes and designs, which prove once again that the coach is actually a selection for the housekeeper.If you want to have the latest Coach arrivals, coach factory outlet online ???? may be a good choice. It provides its members with actually beneficial?prices?and high quality services. coach factory outlet ???? can design new and original products that are also functional. The stylish appearance of products, sophisticated workmanship, superior quality and highly competitive prices have won the customer's trust and love from consumers at home and abroad. So you can rest assured that purchase. coach factory store online ???? is sensible for female for you personally to elect to possess the bigger purses and ******** compared to scaled-down types. The most incredible knack about the coach bag of coach outlet online ???? is that it would excellently please your minds beyond your mind's eye. For example, if you want to become the Angelina Julie, you will immediately need to wear the coach handbag around your shoulder.In terms of the quality and superior design that make more and more customers are satisfied to coach factory outlet online ????.Welcome!Coach is a leading American designer and maker of luxury lifestyle ******** and accessories.There is no doubt that here coach factory outlet ???? is the exact place you should visit. coach outlet ???? has a zippered closure and buckles for extra security. Shiny brass hardware, rounded leather handle, and an interior pocket. It also includes a limited edition Hawaii luggage tag and lock. No one can deny the shopping at the coach factory outlet ???? is satisfactory. For the low prices and good quality.Bright colors, exquisite workmanship, durable material and up-to-date style all lead to the great fame of the goods in coach outlet ????. coach factory outlet online ???? is one of the most popular and successful leather brands in the U.S. market.Coach stands for the most-admired innovative style and conventions in American fashion. coach factory ???? is the premier source to review all new Coach and other stylish brands of ********, Purses, and accessories to capture fabulous styles at even more fabulous prices. If you want to have the latest Coach arrivals, coach factory outlet online ???? may be a good choice. It provides its members with actually beneficial?prices?and high quality services.With the safe door to door shipping, the coach outlet ???? will send the products to your hands, which are of top quality and at competitive factory prices.That experts claim coach factory outlet ???? shopping is in the changes they are available in, which can make it well suited for benefit from to be a'luggage'bag.Highest classic, modern design and best quality are the goals of coach factory store ????.It's distinctly that these Coach Crossbody with distinct design and style.
LV ******** adopt special patterns in the appearance. The modelling of each type of ******** have their own unique flavor. To get one LV handbag, louis vuitton online ???? is a nice option.As we show below, louis vuitton outlet ???? have a number of Louis Vuitton Earrings, louis vuitton replica ********, in different styles for your selection.If you feel more and more online shopping department store thinned Market,then do a local version of their own. When the gradual opening of louis vuitton outlet online ????. Public will be increasingly in popularity.They also have put their louis vuitton sale ???? to make it more convenient and economical for their customers to buy their goods. Have you ever dreamed of being as charming as Madonna? Have you ever thought of becoming an envy of all your friends? If so, come to louis vuitton outlet ????.The louis vuitton outlet online ???? is so colorful.Its products, both for the female and the male, touch upon all walks of life.Have you ever dreamed of being as charming as Madonna? Have you ever thought of becoming an envy of all your friends? If so, come to louis vuitton outlet ????. The ******** at the louis vuitton online ???? come in refreshing Monogram Multicolore canvas. They Features the LV signature in 33 different colours for a bright yet sophisticated look.If you feel more and more online shopping department store thinned Market,then do a local version of their own. When the gradual opening of louis vuitton outlet online ????. Public will be increasingly in popularity.In the web times, even if you are a noble person on louis vuitton outlet ????, or to real action to prove himself, has been integrated into a new era.If in a foreign country to join the twitter, it is best to join army of micro-Bo; Successfully buying products from the louis vuitton sale ???? online now, people can even have ******** as gifts. Time is limited. Just seize the chance. louis vuitton outlet ???? leads you to bags collection of wide, such as LV bags and LV handbag etc. They are main name in luxury and style. It is excellent quality, fine Italian technology and extraordinary beauty.When you hold a Louis Vuitton ********, you can see and feel the quality. If it were for the fact that fashions change so often, louis vuitton outlet sale ???? will be your good choice for a lifetime.People need a complete range of bags from the louis vuitton sale ???? to suit different occasions, formal or casual. Of course, we need at least one patent leather bag in decent color for formal occasion to match our profession. If you want to catch up to the latest vogue, having louis vuitton bags outlet ???? of the latest styles can absolutely satisfy you. louis vuitton bags ???? using the most exclusive materials and state-of-the-art workmanship. The skilled artistry that goes into creating each product guarantees impeccable quality.As we show below, louis vuitton outlet ???? have a number of Louis Vuitton Earrings, louis vuitton replica ********, in different styles for your selection. louis vuitton outlet online ???? will not solely store and build pertaining to your entire necessities,and makes it possible for you to create a typical appearance.Lots of women like these bags.
m2 pvp serverlar tan??t??m?? pvp serverler mt2 private servers metin2 pvp serverler metin2 games metin2 pvp serverlar
mt2 pvp servers pvp metin2 online games mt2 pvp m2 games servers metin2
private servers mt2 private server m2 private online game metin 2
g??zel s??zler roms guzel sozler
face 100 ifadeleri yemek tarifleri yemek tarifleri face guncel news face t He Facebook land facebook
games hiller metin2 hile games dowland metin2 indir

chat
mynet
sex
sex hikayeleri
The problem with Google is they lost 10 years since 2000 and only cared about the web search market, and now they want to enter the OS market, but I think they are too ambitious stavkyand won't be able to have success in the enterprise market until they proove their software is secure.
Android and Chrome OS can't enter the enterprise market if they are unibet so insecure. CIO's should understand Linux, Windows and MacOSX have decades in security research and are now safe to install in large enterprises. The problem with Google is they lost 10 years since 2000 and only cared about the web search market, and now they want to enter the OS market, but I think they are too ambitious and won't be able to have success in the enterprise market until they proove their software is secure. It is amazing to learn what things potentially can be hacked. But I think we should not loose focus on those items that we actually use and maintain ourself and where we sazkove kancelarecould be confronted with the consequences of a hack.

Join the conversation!

Formatting +
BB Codes - Note: HTML is not supported in forums
  • [b] Bold [/b]
  • [i] Italic [/i]
  • [u] Underline [/u]
  • [s] Strikethrough [/s]
  • [q] "Quote" [/q]
  • [ol][*] 1. Ordered List [/ol]
  • [ul][*] · Unordered List [/ul]
  • [pre] Preformat [/pre]
  • [quote] "Blockquote" [/quote]
ie8 fix
Click Here
ie8 fix

The best of ZDNet, delivered

ZDNet Newsletters

Get the best of ZDNet delivered straight to your inbox

Facebook Activity

White Papers, Webcasts, & Resources
ie8 fix
ie8 fix