Black Hat Asia
March 26-29, 2019
Singapore
Black Hat USA
August 3-8, 2019
Las Vegas, NV, USA
Black Hat Europe
December 3-6, 2019
London UK
4/15/2014
01:00 PM
Black Hat Staff
Black Hat Staff
Event Updates
50%
50%

Black Hat USA 2014: Pentesting? Thought You'd Never Ask

If Black Hat USA 2014 isn't quite around the corner, it's definitely on the horizon, and the team is hard at work putting together this year's programming.

The call for papers just closed on April 4, and both the show itself and its many Training sessions are open for signups. We're still in the early-bird period, so confirm your plans now to save a bundle. To kick off the hype, here are three Training highlights from the ever-popular pentesting arena.

Theory has its place, but when it comes to learning penetration testing, practice and real-world applications are indispensable. That's the thinking behind Veris Group's Adaptive Penetration Testing, in which you'll spend most of your time immersed in solving real-world pentesting problems in a fully operational lab environment that includes the powerful Cobalt Strike testing suite. If you want to hit the ground running, this might be the Training to beat.

Pentesting isn't getting any easier; new security technologies, hardening techniques, and detection routines demand ever more advanced tricks to circumvent. Join David "ReL1K" Kennedy, the author of the Social-Engineer Toolkit, for Bypassing Security Defenses - Secret Penetration Testing Techniques, which will teach you the advanced techniques needed to keep up in the arms race. A focus on attack avenues, tricks of the trade, and open-source tools will give you a strong foundation. By the end of the Training, you'll be writing your own tools and exploits in Python.

Two words to describe Penetration Testing with Kali Linux? Practical and intensive. Offensive Security, the creator of Kali Linux, not only wants to walk you through the basics and more hard-core security scenarios. It wants to instill the lateral thinking needed to solve real-world pentesting problems. You'll not only use the tools, but you'll also understand the mechanisms and technologies that allow them to work. Specific topics include bash scripting, fuzzing, reverse tunneling and infiltration, and much, much more. (We're already sweating.)

[UPDATE: Penetration Testing with Kali Linux is now sold out. If you are interested in any of the Black Hat Trainings, we recommend you reserve your spot soon.]

Ready to register? That's great, because you'll lock in those sweet, sweet early-bird rates. Please visit Black Hat USA 2014's registration page to get started.

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
Russia Hacked Clinton's Computers Five Hours After Trump's Call
Robert Lemos, Technology Journalist/Data Researcher,  4/19/2019
Tips for the Aftermath of a Cyberattack
Kelly Sheridan, Staff Editor, Dark Reading,  4/17/2019
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
5 Emerging Cyber Threats to Watch for in 2019
Online attackers are constantly developing new, innovative ways to break into the enterprise. This Dark Reading Tech Digest gives an in-depth look at five emerging attack trends and exploits your security team should look out for, along with helpful recommendations on how you can prevent your organization from falling victim.
Flash Poll
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2019-11350
PUBLISHED: 2019-04-19
CloudBees Jenkins Operations Center 2.150.2.3, when an expired trial license exists, allows Cleartext Password Storage and Retrieval via the proxy configuration page.
CVE-2019-11351
PUBLISHED: 2019-04-19
TeamSpeak 3 Client before 3.2.5 allows remote code execution in the Qt framework.
CVE-2019-2039
PUBLISHED: 2019-04-19
In rw_i93_sm_detect_ndef of rw_i93.cc, there is a possible out-of-bound read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android. Versions: Android-7.0 Android-7.1...
CVE-2019-2040
PUBLISHED: 2019-04-19
In rw_i93_process_ext_sys_info of rw_i93.cc, there is a possible out-of-bound read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android. Versions: Android-9. Androi...
CVE-2019-2041
PUBLISHED: 2019-04-19
In the configuration of NFC modules on certain devices, there is a possible failure to distinguish individual devices due to an insecure default value. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation. Produc...