Black Hat Europe
November 10-13, 2015
Amsterdam RAI | The Netherlands
BH Executive Summit
December 8-10, 2015
Omni Montelucia | Scottsdale, AZ
Black Hat Asia
March 29 - April 1, 2016
Marina Bay Sands | Singapore
01:00 PM
Black Hat Staff
Black Hat Staff
Event Updates

Black Hat USA 2014: Something in the Air

Today's quartet of Black Hat 2014 Training highlights delve into the wide world of wireless hacking.

We start off from a defensive posture with Foundstone's Ultimate Hacking: Wireless. Sure, your org's got an authorized wireless infrastructure, but what about the wireless networks that aren't supposed to be there? The "temporary" access point that's still there months later? That AP brought in by a passing contractor? All are possible attack points. This Training aims to help you see WiFi networks like hackers do, which will give you the knowledge you need to defend against WiFi hackers' increasingly sophisticated tools, techniques, and methods. 

A case in point might be someone with the knowledge offered in our next highlighted Training, Hacking by Numbers Reloaded: Wireless Bootcamp. Starting from the basics, you'll learn the standard techniques Sensepost's analysts use in their wireless engagements, eventually working your way up to bleeding-edge research. Expect theory, practical exercises, and a lot of hands-on WiFi hacking. WPA won't know what hit it. 

Looking beyond WiFi, software-defined radio is an idea whose time has finally come. The aptly named Training Software Defined Radio will bring you up to speed on this brave new world of freeform radio with the help of a shiny new HackRF One SDR radio transceiver, yours to keep. Or for another approach to the topic check out Radio Exploitation, which will show you how to intercept, demodulate, decode, and reverse engineer RF signals, as well as exploit vulnerabilities in RF systems. WiFi too passé? Check out these waveforms! 

Ready to register? Early-bird rates are available until June 2. Please visit Black Hat USA 2014's registration page to get started. 

Comment  | 
Print  | 
More Insights
Register for Dark Reading Newsletters
White Papers
Current Issue
Dark Reading Tech Digest September 7, 2015
Some security flaws go beyond simple app vulnerabilities. Have you checked for these?
Flash Poll
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
Published: 2015-10-05
system/session/drivers/cookie.php in Anchor CMS 0.9.x allows remote attackers to conduct PHP object injection attacks and execute arbitrary PHP code via a crafted serialized object in a cookie.

Published: 2015-10-05
The Secure Meeting (Pulse Collaboration) in Pulse Connect Secure (formerly Juniper Junos Pulse) before 7.1R22.1, 7.4, 8.0 before 8.0R11, and 8.1 before 8.1R3 provides different messages for attempts to join a meeting depending on the status of the meeting, which allows remote attackers to enumerate ...

Published: 2015-10-05
The Secure Meeting (Pulse Collaboration) in Pulse Connect Secure (formerly Juniper Junos Pulse) before 7.1R22.1, 7.4, 8.0 before 8.0R11, and 8.1 before 8.1R3 allows remote authenticated users to bypass intended access restrictions and log into arbitrary meetings by leveraging a meeting id and meetin...

Published: 2015-10-05
Heap-based buffer overflow in the parse_string function in libs/esl/src/esl_json.c in FreeSWITCH before 1.4.23 and 1.6.x before 1.6.2 allows remote attackers to execute arbitrary code via a trailing \u in a json string to cJSON_Parse.

Published: 2015-10-05
Unrestricted file upload in GLPI before 0.85.3 allows remote authenticated users to execute arbitrary code by adding a file with an executable extension as an attachment to a new ticket, then accessing it via a direct request to the file in files/_tmp/.

Dark Reading Radio
Archived Dark Reading Radio
What can the information security industry do to solve the IoT security problem? Learn more and join the conversation on the next episode of Dark Reading Radio.