Vulnerabilities / Threats
2/6/2014
03:58 PM
Connect Directly
RSS
E-Mail
50%
50%
Repost This

Black Hat Asia 2014: The Internet Of Things

Here are three Briefings from Black Hat Asia 2014 that focus on hacking Net-enabled hardware

With Gartner forecasting 26 billion devices connected to the Internet by 2020, the so-called Internet of Things will play an ever-larger role in our everyday interactions. But where there are computers there are attack opportunities and security vulns. Here are three Briefings from Black Hat Asia 2014 that focus on hacking net-enabled hardware:

It used to be that most folks would only worry about computers being hacked. But as more consumer products increasingly incorporate networking features, that concern should extend to door locks, thermostats, baby monitors... you name it. In Abusing the Internet of Things: Blackouts, Freakouts, and Stakeouts, Nitesh Dhanjani will delve into (and demonstrate) critical vulnerabilities in home automation products. From spying through a baby monitor to remotely causing a blackout in your home or office building, this talk breaks open an array of high impact attack vectors. What are the security requirements of a next-generation device infrastructure?

In recent times the term, "Trojan horse," has primarily described disguised malware, but in Building Trojan Hardware at Home, JP Dunning will bring the concept back to the physical arena. Almost any computer peripheral can be turned into an attack platform and surprisingly you don't even need advanced hardware expertise to make it happen. Dunning will showcase his own hardware attack platform dubbed, 'The Glitch,' designed to embed into existing hardware, while also covering the threats of modified firmware as a staging point inside corporate networks.

How much do you trust you phone? (If you're coming to Black Hat, we can take a guess.) The average person is unaware of just how much uniquely identifying information leaks from a smartphone, much less how it can be harnessed for attacks. The Machines That Betrayed Their Masterswill walk you through how Glenn Wilkinson built a resilient, modular, reliable, distributed tracking framework, Snoopy, which has not only expanded into vectors beyond Wi-Fi, but is now airborne via a quadcopter.

Looking to register? Please visit Black Hat Asia 2014's registration page to get started.

Comment  | 
Print  | 
More Insights
Register for Dark Reading Newsletters
White Papers
Cartoon
Latest Comment: LOL.
Current Issue
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2013-6213
Published: 2014-04-19
Unspecified vulnerability in Virtual User Generator in HP LoadRunner before 11.52 Patch 1 allows remote attackers to execute arbitrary code via unknown vectors, aka ZDI-CAN-1833.

CVE-2013-6214
Published: 2014-04-19
Unspecified vulnerability in the Integration Service in HP Universal Configuration Management Database 9.05, 10.01, and 10.10 allows remote authenticated users to obtain sensitive information via unknown vectors, aka ZDI-CAN-2042.

CVE-2012-0871
Published: 2014-04-18
The session_link_x11_socket function in login/logind-session.c in systemd-logind in systemd, possibly 37 and earlier, allows local users to create or overwrite arbitrary files via a symlink attack on the X11 user directory in /run/user/.

CVE-2012-6646
Published: 2014-04-18
F-Secure Anti-Virus, Safe Anywhere, and PSB Workstation Security before 11500 for Mac OS X allows local users to disable the Mac OS X firewall via unspecified vectors.

CVE-2013-4279
Published: 2014-04-18
imapsync 1.564 and earlier performs a release check by default, which sends sensitive information (imapsync, operating system, and Perl version) to the developer's site.

Best of the Web