Black Hat Asia
March 24-27, 2015
Marina Bay Sands, Singapore
7/22/2014
01:00 PM
Black Hat Staff
Black Hat Staff
Event Updates
50%
50%

Black Hat USA 2014: Danger! High Bandwidth

Now that the world is basically one giant network, it's kind of mind-blowing to look back at computers from the days before they were so intimately intertwined. But the ubiquity of networking is also our Achilles' heel, which today's trio of Black Hat Briefings amply illustrate with their focus on Internet-based attacks.

Consumer premises equipment (CPE) like routers is nearly ubiquitous these days, but abuse of such devices is inordinately problematic, given the owner's subsequent difficulty in interfacing with the device to fix it, as well as the long-rotted, vulnerable code that exists in almost all such equipment. The result is an Internet-scale problem, almost like a public health crisis. Abuse of CPE Devices and Recommended Fixes will attempt to quantify the risk at work here -- think of all those midscale DSL connections just waiting to be harnessed for a DDoS -- and offer some recommendations on quelling this epidemic before it strikes.

RIPE NCC allocated its last IPv4 address space quite some time ago, so IPv6 is here, whether you decide to acknowledge it or not. Perhaps your ears will perk up when you come to Evasion of High-End IPS Devices in the Age of IPv6, in which Antonios Atlasis and Enno Rey will debut three novel techniques that allow attackers to exploit IPv6 and blind high-end commercial security devices. With these tricks, bad guys can launch any kind of attack, but the presenters will suggest potential mitigating measures, both short-term and long.

MultiPath TCP (MPTCP) is an extension to TCP that enables sessions to use multiple network endpoints and multiple network paths at the same time, and to change addresses in the middle of a connection. Though MPTCP works transparently over most network infrastructure, very few security and network management tools can correctly interpret MPTCP streams. Network security is changed: How do you secure traffic when you can't see it all and when the endpoint addresses change in the middle of a connection? Come to Multipath TCP: Breaking Today's Networks with Tomorrow's Protocols for a primer on MPTCP's assumption breaking, as well as tools and strategies for mitigating the risks of MPTCP-capable devices.

Regular registration ends July 26, which is really soon. Please visit Black Hat USA 2014's registration page to get started.

Comment  | 
Print  | 
More Insights
Register for Dark Reading Newsletters
White Papers
Cartoon
Current Issue
Dark Reading Tech Digest, Dec. 19, 2014
Software-defined networking can be a net plus for security. The key: Work with the network team to implement gradually, test as you go, and take the opportunity to overhaul your security strategy.
Flash Poll
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2014-4632
Published: 2015-01-31
VMware vSphere Data Protection (VDP) 5.1, 5.5 before 5.5.9, and 5.8 before 5.8.1 does not properly verify X.509 certificates from vCenter Server SSL servers, which allows man-in-the-middle attackers to spoof servers, and bypass intended backup and restore access restrictions, via a crafted certifica...

CVE-2014-7287
Published: 2015-01-31
The key-management component in Symantec PGP Universal Server and Encryption Management Server before 3.3.2 MP7 allows remote attackers to trigger unintended content in outbound e-mail messages via a crafted key UID value in an inbound e-mail message, as demonstrated by the outbound Subject header.

CVE-2014-7288
Published: 2015-01-31
Symantec PGP Universal Server and Encryption Management Server before 3.3.2 MP7 allow remote authenticated administrators to execute arbitrary shell commands via a crafted command line in a database-backup restore action.

CVE-2014-8266
Published: 2015-01-31
Multiple cross-site scripting (XSS) vulnerabilities in the note-creation page in QPR Portal 2014.1.1 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) title or (2) body field.

CVE-2014-8267
Published: 2015-01-31
Cross-site scripting (XSS) vulnerability in QPR Portal 2014.1.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the RID parameter.

Best of the Web
Dark Reading Radio
Archived Dark Reading Radio
If you’re a security professional, you’ve probably been asked many questions about the December attack on Sony. On Jan. 21 at 1pm eastern, you can join a special, one-hour Dark Reading Radio discussion devoted to the Sony hack and the issues that may arise from it.