Black Hat Europe
October 14-17, 2014
Amsterdam Rai, The Netherlands
4/15/2014
01:00 PM
Black Hat Staff
Black Hat Staff
Event Updates
50%
50%

Black Hat USA 2014: Pentesting? Thought You'd Never Ask

If Black Hat USA 2014 isn't quite around the corner, it's definitely on the horizon, and the team is hard at work putting together this year's programming.

The call for papers just closed on April 4, and both the show itself and its many Training sessions are open for signups. We're still in the early-bird period, so confirm your plans now to save a bundle. To kick off the hype, here are three Training highlights from the ever-popular pentesting arena.

Theory has its place, but when it comes to learning penetration testing, practice and real-world applications are indispensable. That's the thinking behind Veris Group's Adaptive Penetration Testing, in which you'll spend most of your time immersed in solving real-world pentesting problems in a fully operational lab environment that includes the powerful Cobalt Strike testing suite. If you want to hit the ground running, this might be the Training to beat.

Pentesting isn't getting any easier; new security technologies, hardening techniques, and detection routines demand ever more advanced tricks to circumvent. Join David "ReL1K" Kennedy, the author of the Social-Engineer Toolkit, for Bypassing Security Defenses - Secret Penetration Testing Techniques, which will teach you the advanced techniques needed to keep up in the arms race. A focus on attack avenues, tricks of the trade, and open-source tools will give you a strong foundation. By the end of the Training, you'll be writing your own tools and exploits in Python.

Two words to describe Penetration Testing with Kali Linux? Practical and intensive. Offensive Security, the creator of Kali Linux, not only wants to walk you through the basics and more hard-core security scenarios. It wants to instill the lateral thinking needed to solve real-world pentesting problems. You'll not only use the tools, but you'll also understand the mechanisms and technologies that allow them to work. Specific topics include bash scripting, fuzzing, reverse tunneling and infiltration, and much, much more. (We're already sweating.)

[UPDATE: Penetration Testing with Kali Linux is now sold out. If you are interested in any of the Black Hat Trainings, we recommend you reserve your spot soon.]

Ready to register? That's great, because you'll lock in those sweet, sweet early-bird rates. Please visit Black Hat USA 2014's registration page to get started.

Comment  | 
Print  | 
More Insights
Register for Dark Reading Newsletters
White Papers
Cartoon
Current Issue
Dark Reading December Tech Digest
Experts weigh in on the pros and cons of end-user security training.
Flash Poll
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2014-3407
Published: 2014-11-27
The SSL VPN implementation in Cisco Adaptive Security Appliance (ASA) Software 9.3(.2) and earlier does not properly allocate memory blocks during HTTP packet handling, which allows remote attackers to cause a denial of service (memory consumption) via crafted packets, aka Bug ID CSCuq68888.

CVE-2014-4829
Published: 2014-11-27
Cross-site request forgery (CSRF) vulnerability in IBM Security QRadar SIEM and QRadar Risk Manager 7.1 before MR2 Patch 9 and 7.2 before 7.2.4 Patch 1, and QRadar Vulnerability Manager 7.2 before 7.2.4 Patch 1, allows remote attackers to hijack the authentication of arbitrary users for requests tha...

CVE-2014-4831
Published: 2014-11-27
IBM Security QRadar SIEM and QRadar Risk Manager 7.1 before MR2 Patch 9 and 7.2 before 7.2.4 Patch 1, and QRadar Vulnerability Manager 7.2 before 7.2.4 Patch 1, allow remote attackers to hijack sessions via unspecified vectors.

CVE-2014-4832
Published: 2014-11-27
IBM Security QRadar SIEM and QRadar Risk Manager 7.1 before MR2 Patch 9 and 7.2 before 7.2.4 Patch 1, and QRadar Vulnerability Manager 7.2 before 7.2.4 Patch 1, allow remote attackers to obtain sensitive cookie information by sniffing the network during an HTTP session.

CVE-2014-4883
Published: 2014-11-27
resolv.c in the DNS resolver in uIP, and dns.c in the DNS resolver in lwIP 1.4.1 and earlier, does not use random values for ID fields and source ports of DNS query packets, which makes it easier for man-in-the-middle attackers to conduct cache-poisoning attacks via spoofed reply packets.

Best of the Web
Dark Reading Radio
Archived Dark Reading Radio
Now that the holiday season is about to begin both online and in stores, will this be yet another season of nonstop gifting to cybercriminals?