Black Hat Asia
March 24-27, 2015
Marina Bay Sands, Singapore
5/20/2014
01:00 PM
Black Hat Staff
Black Hat Staff
Event Updates
50%
50%

Black Hat USA 2014: Something in the Air

Today's quartet of Black Hat 2014 Training highlights delve into the wide world of wireless hacking.

We start off from a defensive posture with Foundstone's Ultimate Hacking: Wireless. Sure, your org's got an authorized wireless infrastructure, but what about the wireless networks that aren't supposed to be there? The "temporary" access point that's still there months later? That AP brought in by a passing contractor? All are possible attack points. This Training aims to help you see WiFi networks like hackers do, which will give you the knowledge you need to defend against WiFi hackers' increasingly sophisticated tools, techniques, and methods. 

A case in point might be someone with the knowledge offered in our next highlighted Training, Hacking by Numbers Reloaded: Wireless Bootcamp. Starting from the basics, you'll learn the standard techniques Sensepost's analysts use in their wireless engagements, eventually working your way up to bleeding-edge research. Expect theory, practical exercises, and a lot of hands-on WiFi hacking. WPA won't know what hit it. 

Looking beyond WiFi, software-defined radio is an idea whose time has finally come. The aptly named Training Software Defined Radio will bring you up to speed on this brave new world of freeform radio with the help of a shiny new HackRF One SDR radio transceiver, yours to keep. Or for another approach to the topic check out Radio Exploitation, which will show you how to intercept, demodulate, decode, and reverse engineer RF signals, as well as exploit vulnerabilities in RF systems. WiFi too passé? Check out these waveforms! 

Ready to register? Early-bird rates are available until June 2. Please visit Black Hat USA 2014's registration page to get started. 

Comment  | 
Print  | 
More Insights
Register for Dark Reading Newsletters
White Papers
Cartoon
Current Issue
Dark Reading Tech Digest, Dec. 19, 2014
Software-defined networking can be a net plus for security. The key: Work with the network team to implement gradually, test as you go, and take the opportunity to overhaul your security strategy.
Flash Poll
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2014-8802
Published: 2015-01-23
The Pie Register plugin before 2.0.14 for WordPress does not properly restrict access to certain functions in pie-register.php, which allows remote attackers to (1) add a user by uploading a crafted CSV file or (2) activate a user account via a verifyit action.

CVE-2014-9623
Published: 2015-01-23
OpenStack Glance 2014.2.x through 2014.2.1, 2014.1.3, and earlier allows remote authenticated users to bypass the storage quote and cause a denial of service (disk consumption) by deleting an image in the saving state.

CVE-2014-9638
Published: 2015-01-23
oggenc in vorbis-tools 1.4.0 allows remote attackers to cause a denial of service (divide-by-zero error and crash) via a WAV file with the number of channels set to zero.

CVE-2014-9639
Published: 2015-01-23
Integer overflow in oggenc in vorbis-tools 1.4.0 allows remote attackers to cause a denial of service (crash) via a crafted number of channels in a WAV file, which triggers an out-of-bounds memory access.

CVE-2014-9640
Published: 2015-01-23
oggenc/oggenc.c in vorbis-tools 1.4.0 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted raw file.

Best of the Web
Dark Reading Radio
Archived Dark Reading Radio
If you’re a security professional, you’ve probably been asked many questions about the December attack on Sony. On Jan. 21 at 1pm eastern, you can join a special, one-hour Dark Reading Radio discussion devoted to the Sony hack and the issues that may arise from it.