Vulnerabilities / Threats
7/22/2014
08:20 PM
Connect Directly
Twitter
Twitter
RSS
E-Mail

7 Black Hat Sessions Sure To Cause A Stir

At Black Hat, researchers will point out the weaknesses in everything from the satellites in outer space to the thermostat in your home.
2 of 7

Mission mPOSsible
(Source: Square)

The Speakers: Nils and Jon Butler, security researchers for MWR Labs

The Research: For this talk, Nils and Butler took a close look at the weaknesses of mobile point-of-sale (mPOS) systems that have been all the rage in the SMB community over the last several years. They'll detail a number of vulnerabilities that gave them code execution of the devices, and they will demo a number of attack methods, including a malicious credit card that leaves a remote root on the mPOS device.

(Source: Square)

The Speakers: Nils and Jon Butler, security researchers for MWR Labs

The Research: For this talk, Nils and Butler took a close look at the weaknesses of mobile point-of-sale (mPOS) systems that have been all the rage in the SMB community over the last several years. They'll detail a number of vulnerabilities that gave them code execution of the devices, and they will demo a number of attack methods, including a malicious credit card that leaves a remote root on the mPOS device.

2 of 7
Comment  | 
Print  | 
Comments
Newest First  |  Oldest First  |  Threaded View
Page 1 / 2   >   >>
Marilyn Cohodas
50%
50%
Marilyn Cohodas,
User Rank: Strategist
7/31/2014 | 8:18:02 AM
Re: Dates and Times
This will be my first Black Hat & I'm psyched! Any session recommendations from seasoned show veterans or security pros who would like to attend but can't?  Complete BH briefing list is here
DarkReadingTim
50%
50%
DarkReadingTim,
User Rank: Strategist
7/31/2014 | 1:09:50 AM
Re: Dates and Times
It never ceases to amaze me what these speakers can hack. I have seen them make money come out of ATMs, stop a pacemaker, and blow up a computer over a remote connection. It looks like they will have another batch of surprises for us this year!
RyanSepe
0%
100%
RyanSepe,
User Rank: Ninja
7/28/2014 | 12:24:12 PM
Re: Dates and Times
Thanks for this! For me, I am interested to hear about the shortcomings of TLS and 48 secrets of cryptographers.

Should be interesting!
Marilyn Cohodas
50%
50%
Marilyn Cohodas,
User Rank: Strategist
7/25/2014 | 10:09:53 AM
Re: Dates and Times
Here is the schedule for Black Hat and also a list of speakers. The Dark Reading editorial team is also planning a series of radio shows based on a few of the more popular Black Hat sessions. So stay tuned. We'll keep you posted on the what, when and where. There will also be a lot of live coverage from the show. So keep Dark Reading open in your browser Aug. 2-7.
Robert McDougal
50%
50%
Robert McDougal,
User Rank: Ninja
7/24/2014 | 11:15:36 AM
Re: Tip of the iceberg
Agreed, this is only the material that people are willing to share.  Imagine what people are not willing to share...
Robert McDougal
50%
50%
Robert McDougal,
User Rank: Ninja
7/24/2014 | 11:13:58 AM
Re: Dates and Times
Not sure when the material will be released but when it is you can find it here:

https://www.blackhat.com/html/archives.html
Whoopty
50%
50%
Whoopty,
User Rank: Moderator
7/23/2014 | 11:56:51 AM
Tip of the iceberg
As impressive as all of this is, it has to be just the tip of the iceberg compared to what some truly nefarious black hats out there can do. 
CraigB159
50%
50%
CraigB159,
User Rank: Apprentice
7/23/2014 | 9:51:05 AM
Re: Dates and Times
Hi Ryan - you can find more information on Ruben's SATCOM presentation here: http://blog.ioactive.com/2014/04/a-wake-up-call-for-satcom-security.html It includes a link to his white paper on the topic.
GonzSTL
50%
50%
GonzSTL,
User Rank: Ninja
7/23/2014 | 9:32:27 AM
Re: Dates and Times
I have one of those :)
Marilyn Cohodas
50%
50%
Marilyn Cohodas,
User Rank: Strategist
7/23/2014 | 9:04:35 AM
Re: Dates and Times
The google glass demo will surely be an eye-opener. :-)
Page 1 / 2   >   >>
Register for Dark Reading Newsletters
White Papers
Cartoon
Current Issue
Dark Reading Tech Digest, Dec. 19, 2014
Software-defined networking can be a net plus for security. The key: Work with the network team to implement gradually, test as you go, and take the opportunity to overhaul your security strategy.
Flash Poll
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2015-1414
Published: 2015-02-27
Integer overflow in FreeBSD before 8.4 p24, 9.x before 9.3 p10. 10.0 before p18, and 10.1 before p6 allows remote attackers to cause a denial of service (crash) via a crafted IGMP packet, which triggers an incorrect size calculation and allocation of insufficient memory.

CVE-2015-2072
Published: 2015-02-27
Multiple cross-site scripting (XSS) vulnerabilities in SAP HANA 73 (1.00.73.00.389160) and HANA Developer Edition 80 (1.00.80.00.391861) allow remote attackers to inject arbitrary web script or HTML via unspecified vectors to (1) ide/core/plugins/editor/templates/trace/hanaTraceDetailService.xsjs or...

CVE-2015-2075
Published: 2015-02-27
SAP BussinessObjects Edge 4.0 allows remote attackers to delete audit events from the auditee queue via a clearData CORBA operation, aka SAP Note 2011396.

CVE-2015-2076
Published: 2015-02-27
The Auditing service in SAP BussinessObjects Edge 4.0 allows remote attackers to obtains sensitive information by reading an audit event, aka SAP Note 2011395.

CVE-2015-2101
Published: 2015-02-27
Cross-site scripting (XSS) vulnerability in the Navigate bar in the Navigate module before 6.x-1.1 and 7.x-1.x before 7.x-1.1 for Drupal allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

Dark Reading Radio
Archived Dark Reading Radio
How can security professionals better engage with their peers, both in person and online? In this Dark Reading Radio show, we will talk to leaders at some of the security industry’s professional organizations about how security pros can get more involved – with their colleagues in the same industry, with their peers in other industries, and with the IT security community as a whole.