Black Hat Europe
October 14-17, 2014
Amsterdam Rai, The Netherlands
6/3/2014
02:00 PM
Black Hat Staff
Black Hat Staff
Event Updates
50%
50%

Black Hat USA 2014: AppSec Grab Bag

If Black Hat had a middle name -- it doesn't, for the record -- it could well be Application Security. Which is actually two names, so maybe we'd have to hyphenate it. You can see it gets complicated. Today's five Black Hat Briefing highlights cover a potpourri of application security topics, ranging from vulnerabilities in webapps and the cloud to weaknesses in shared libraries.

Cross-Site Scripting (XSS) remain one of the most severe security vulnerabilities of the web. Browser vendors' client-side XSS filters help. Unfortunately, they are far from perfect. Call To Arms: A Tale of the Weaknesses of Current Client-Side XSS Filtering examines the particulars of Google Chrome's XSS Auditor, in which the presenters have discovered 17 separate flaws that enable them to bypass its filtering. They'll debut tools to automate these attacks, and they'll wrap with a wider look at XSS vulnerabilities in the Alexa Top 10,000, along with a look at future XSS protection prospects.

When it comes to online social network (OSN) authorization, it's generally believed that correct use of OAuth 2.0 (by provider and app developer) is secure enough. But that's not so. How to Leak a 100-Million-Node Social Graph in Just One Week? A Reflection on Oauth and API Design in Online Social Networks will demonstrate a massive user data leak achieved through subtle feats of application impersonation and $150 of Amazon Web Service. You'll see that industrial practitioners have some work cut out for them when designing the next generation of sign-on protocols.

Speaking of abusing cloud services, what happens when criminals start using friendly cloud services for malicious activities? CloudBots: Harvesting Crypto Coins Like a Botnet Farmer will explore just how easy it is to generate massive amounts of unique emails, use them to get free trial accounts, deploy code, and distribute commands (C2), creating a semi-legal botnet that evades malware protections and web filters. The presenters will share their botnet-related pentest and security research tools, and they will reveal how they found out that they weren't the only ones doing this.

A common side-channel vulnerability in many web applications comes in timing side-channels, which allows an attacker to extract information based on different response times. Alas, the severity of these vulnerabilities is woefully misunderstood. Time Trial: Racing Towards Practical Timing Attacks will debut a tool for detecting these vulnerabilities and show just how common they can be. This should be of interest to a spectrum of Black Hat attendees, including pentesters and defensive specialists.

The last item -- and the one with the single most impressive word in its title -- is Epidemiology of Software Vulnerabilities: A Study of Attack Surface Spread, which will blow a whistle on security flaws in third-party software libraries (middleware) of the sort widely adopted by developers. Third-party libraries can spread a single vulnerability across multiple products, exposing enterprises and requiring repeated patches. How big of an issue is this, and which shared libraries are the worst offenders? Come find out.

Please visit Black Hat USA 2014's registration page to register.

Comment  | 
Print  | 
More Insights
Register for Dark Reading Newsletters
White Papers
Cartoon
Current Issue
Dark Reading December Tech Digest
Experts weigh in on the pros and cons of end-user security training.
Flash Poll
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2010-5312
Published: 2014-11-24
Cross-site scripting (XSS) vulnerability in jquery.ui.dialog.js in the Dialog widget in jQuery UI before 1.10.0 allows remote attackers to inject arbitrary web script or HTML via the title option.

CVE-2012-6662
Published: 2014-11-24
Cross-site scripting (XSS) vulnerability in the default content option in jquery.ui.tooltip.js in the Tooltip widget in jQuery UI before 1.10.0 allows remote attackers to inject arbitrary web script or HTML via the title attribute, which is not properly handled in the autocomplete combo box demo.

CVE-2014-1424
Published: 2014-11-24
apparmor_parser in the apparmor package before 2.8.95~2430-0ubuntu5.1 in Ubuntu 14.04 allows attackers to bypass AppArmor policies via unspecified vectors, related to a "miscompilation flaw."

CVE-2014-7817
Published: 2014-11-24
The wordexp function in GNU C Library (aka glibc) 2.21 does not enforce the WRDE_NOCMD flag, which allows context-dependent attackers to execute arbitrary commands, as demonstrated by input containing "$((`...`))".

CVE-2014-7821
Published: 2014-11-24
OpenStack Neutron before 2014.1.4 and 2014.2.x before 2014.2.1 allows remote authenticated users to cause a denial of service (crash) via a crafted dns_nameservers value in the DNS configuration.

Best of the Web
Dark Reading Radio
Archived Dark Reading Radio
Now that the holiday season is about to begin both online and in stores, will this be yet another season of nonstop gifting to cybercriminals?