Black Hat USA
August 2-7, 2014
Mandalay Bay, Las Vegas, NV
Black Hat Europe
October 14-17, 2014
Amsterdam Rai, The Netherlands
6/3/2014
02:00 PM
Black Hat Staff
Black Hat Staff
Event Updates
Connect Directly
RSS
E-Mail
50%
50%

Black Hat USA 2014: AppSec Grab Bag

If Black Hat had a middle name -- it doesn't, for the record -- it could well be Application Security. Which is actually two names, so maybe we'd have to hyphenate it. You can see it gets complicated. Today's five Black Hat Briefing highlights cover a potpourri of application security topics, ranging from vulnerabilities in webapps and the cloud to weaknesses in shared libraries.

Cross-Site Scripting (XSS) remain one of the most severe security vulnerabilities of the web. Browser vendors' client-side XSS filters help. Unfortunately, they are far from perfect. Call To Arms: A Tale of the Weaknesses of Current Client-Side XSS Filtering examines the particulars of Google Chrome's XSS Auditor, in which the presenters have discovered 17 separate flaws that enable them to bypass its filtering. They'll debut tools to automate these attacks, and they'll wrap with a wider look at XSS vulnerabilities in the Alexa Top 10,000, along with a look at future XSS protection prospects.

When it comes to online social network (OSN) authorization, it's generally believed that correct use of OAuth 2.0 (by provider and app developer) is secure enough. But that's not so. How to Leak a 100-Million-Node Social Graph in Just One Week? A Reflection on Oauth and API Design in Online Social Networks will demonstrate a massive user data leak achieved through subtle feats of application impersonation and $150 of Amazon Web Service. You'll see that industrial practitioners have some work cut out for them when designing the next generation of sign-on protocols.

Speaking of abusing cloud services, what happens when criminals start using friendly cloud services for malicious activities? CloudBots: Harvesting Crypto Coins Like a Botnet Farmer will explore just how easy it is to generate massive amounts of unique emails, use them to get free trial accounts, deploy code, and distribute commands (C2), creating a semi-legal botnet that evades malware protections and web filters. The presenters will share their botnet-related pentest and security research tools, and they will reveal how they found out that they weren't the only ones doing this.

A common side-channel vulnerability in many web applications comes in timing side-channels, which allows an attacker to extract information based on different response times. Alas, the severity of these vulnerabilities is woefully misunderstood. Time Trial: Racing Towards Practical Timing Attacks will debut a tool for detecting these vulnerabilities and show just how common they can be. This should be of interest to a spectrum of Black Hat attendees, including pentesters and defensive specialists.

The last item -- and the one with the single most impressive word in its title -- is Epidemiology of Software Vulnerabilities: A Study of Attack Surface Spread, which will blow a whistle on security flaws in third-party software libraries (middleware) of the sort widely adopted by developers. Third-party libraries can spread a single vulnerability across multiple products, exposing enterprises and requiring repeated patches. How big of an issue is this, and which shared libraries are the worst offenders? Come find out.

Please visit Black Hat USA 2014's registration page to register.

Comment  | 
Print  | 
More Insights
Register for Dark Reading Newsletters
White Papers
Flash Poll
Current Issue
Cartoon
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2014-4725
Published: 2014-07-27
The MailPoet Newsletters (wysija-newsletters) plugin before 2.6.7 for WordPress allows remote attackers to bypass authentication and execute arbitrary PHP code by uploading a crafted theme using wp-admin/admin-post.php and accessing the theme in wp-content/uploads/wysija/themes/mailp/.

CVE-2014-4726
Published: 2014-07-27
Unspecified vulnerability in the MailPoet Newsletters (wysija-newsletters) plugin before 2.6.8 for WordPress has unspecified impact and attack vectors.

CVE-2014-2363
Published: 2014-07-26
Morpho Itemiser 3 8.17 has hardcoded administrative credentials, which makes it easier for remote attackers to obtain access via a login request.

CVE-2014-2625
Published: 2014-07-26
Directory traversal vulnerability in the storedNtxFile function in HP Network Virtualization 8.6 (aka Shunra Network Virtualization) allows remote attackers to read arbitrary files via crafted input, aka ZDI-CAN-2023.

CVE-2014-2626
Published: 2014-07-26
Directory traversal vulnerability in the toServerObject function in HP Network Virtualization 8.6 (aka Shunra Network Virtualization) allows remote attackers to create files, and consequently execute arbitrary code, via crafted input, aka ZDI-CAN-2024.

Best of the Web
Dark Reading Radio
Archived Dark Reading Radio
Sara Peters hosts a conversation on Botnets and those who fight them.