Black Hat USA
August 1-6, 2015
Mandalay Bay | Las Vegas, NV
Black Hat Europe
November 10-13, 2015
Amsterdam RAI | The Netherlands
BH Executive Summit
December 10-8, 2015
Omni Montelucia | Scottsdale, AZ
4/15/2014
01:00 PM
Black Hat Staff
Black Hat Staff
Event Updates
50%
50%

Black Hat USA 2014: Pentesting? Thought You'd Never Ask

If Black Hat USA 2014 isn't quite around the corner, it's definitely on the horizon, and the team is hard at work putting together this year's programming.

The call for papers just closed on April 4, and both the show itself and its many Training sessions are open for signups. We're still in the early-bird period, so confirm your plans now to save a bundle. To kick off the hype, here are three Training highlights from the ever-popular pentesting arena.

Theory has its place, but when it comes to learning penetration testing, practice and real-world applications are indispensable. That's the thinking behind Veris Group's Adaptive Penetration Testing, in which you'll spend most of your time immersed in solving real-world pentesting problems in a fully operational lab environment that includes the powerful Cobalt Strike testing suite. If you want to hit the ground running, this might be the Training to beat.

Pentesting isn't getting any easier; new security technologies, hardening techniques, and detection routines demand ever more advanced tricks to circumvent. Join David "ReL1K" Kennedy, the author of the Social-Engineer Toolkit, for Bypassing Security Defenses - Secret Penetration Testing Techniques, which will teach you the advanced techniques needed to keep up in the arms race. A focus on attack avenues, tricks of the trade, and open-source tools will give you a strong foundation. By the end of the Training, you'll be writing your own tools and exploits in Python.

Two words to describe Penetration Testing with Kali Linux? Practical and intensive. Offensive Security, the creator of Kali Linux, not only wants to walk you through the basics and more hard-core security scenarios. It wants to instill the lateral thinking needed to solve real-world pentesting problems. You'll not only use the tools, but you'll also understand the mechanisms and technologies that allow them to work. Specific topics include bash scripting, fuzzing, reverse tunneling and infiltration, and much, much more. (We're already sweating.)

[UPDATE: Penetration Testing with Kali Linux is now sold out. If you are interested in any of the Black Hat Trainings, we recommend you reserve your spot soon.]

Ready to register? That's great, because you'll lock in those sweet, sweet early-bird rates. Please visit Black Hat USA 2014's registration page to get started.

Comment  | 
Print  | 
More Insights
Register for Dark Reading Newsletters
White Papers
Cartoon
Current Issue
Flash Poll
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2015-5084
Published: 2015-08-02
The Siemens SIMATIC WinCC Sm@rtClient and Sm@rtClient Lite applications before 01.00.01.00 for Android do not properly store passwords, which allows physically approximate attackers to obtain sensitive information via unspecified vectors.

CVE-2015-5352
Published: 2015-08-02
The x11_open_helper function in channels.c in ssh in OpenSSH before 6.9, when ForwardX11Trusted mode is not used, lacks a check of the refusal deadline for X connections, which makes it easier for remote attackers to bypass intended access restrictions via a connection outside of the permitted time ...

CVE-2015-5537
Published: 2015-08-02
The SSL layer of the HTTPS service in Siemens RuggedCom ROS before 4.2.0 and ROX II does not properly implement CBC padding, which makes it easier for man-in-the-middle attackers to obtain cleartext data via a padding-oracle attack, a different vulnerability than CVE-2014-3566.

CVE-2015-5600
Published: 2015-08-02
The kbdint_next_device function in auth2-chall.c in sshd in OpenSSH through 6.9 does not properly restrict the processing of keyboard-interactive devices within a single connection, which makes it easier for remote attackers to conduct brute-force attacks or cause a denial of service (CPU consumptio...

CVE-2015-1009
Published: 2015-07-31
Schneider Electric InduSoft Web Studio before 7.1.3.5 Patch 5 and Wonderware InTouch Machine Edition through 7.1 SP3 Patch 4 use cleartext for project-window password storage, which allows local users to obtain sensitive information by reading a file.

Dark Reading Radio
Archived Dark Reading Radio
What’s the future of the venerable firewall? We’ve invited two security industry leaders to make their case: Join us and bring your questions and opinions!