Vulnerabilities / Threats
3/7/2014
02:22 PM
Connect Directly
RSS
E-Mail
50%
50%

Black Hat Asia 2014: The Weaponized Web

These Black Hat Briefings explore ways the Web can be weaponized -- and how to defend against them

The World Wide Web has grown exponentially since its birth 21 years ago, and it now serves as the interface for many of the apps we use every day. It's hard to imagine a more enticing target for hacks and exploits. Today's trio of Black Hat Briefings explore ways the Web can be weaponized ... and how to defend against it.

Even as HTML 5 proliferates as an enabler of rich interactive Web applications, cross-site scripting (XSS) remains one of the top three Web application vulnerabilities. DOM-based XSS is growing in popularity, but its client-side nature makes it difficult to monitor for malicious payloads. Ultimate Dom Based XSS Detection Scanner on Clouddelves into this thorny issue. Nera W. C. Liu and Albert Yu will show how they managed to introduce and propagate tainted attributes to a DOM input interface, and then devised a system to detect such breaches by harnessing the power of PhantomJS, a headless browser for automation.

JavaScript's ubiquity makes it the subject of aggressive security-community research, boosting its effective security level every day. Sounds good, but in JS Suicide: Using JavaScript Security Features to Kill JS Security, AhamedNafeez will demonstrate that these security features can be a double-edged sword, sometimes allowing an attacker to disable certain other JS protection mechanisms. In particular, the sandboxing features of ECMAScript 5 can break security in many JS applications. Real-world examples of other JS security lapses are also on the agenda.

Ready-made exploit kits make it easier than ever for malicious parties to victimize unwary Internet users. Jose Miguel Esparza will take us down that rabbit hole in PDF Attack: A Journey From the Exploit Kit to the Shellcode, in which he'll teach how to manually extract obfuscated URLs and binaries from these weaponized pages. You'll also learn how to do modify a malicious PDF payload yourself to bypass AV software, a useful trick for pentesting.

Looking to register? Please visit Black Hat Asia 2014's registration page to get started.

Comment  | 
Print  | 
More Insights
Register for Dark Reading Newsletters
White Papers
Cartoon
Current Issue
Flash Poll
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2014-0485
Published: 2014-09-02
S3QL 1.18.1 and earlier uses the pickle Python module unsafely, which allows remote attackers to execute arbitrary code via a crafted serialized object in (1) common.py or (2) local.py in backends/.

CVE-2014-3861
Published: 2014-09-02
Cross-site scripting (XSS) vulnerability in CDA.xsl in HL7 C-CDA 1.1 and earlier allows remote attackers to inject arbitrary web script or HTML via a crafted reference element within a nonXMLBody element.

CVE-2014-3862
Published: 2014-09-02
CDA.xsl in HL7 C-CDA 1.1 and earlier allows remote attackers to discover potentially sensitive URLs via a crafted reference element that triggers creation of an IMG element with an arbitrary URL in its SRC attribute, leading to information disclosure in a Referer log.

CVE-2014-5076
Published: 2014-09-02
The La Banque Postale application before 3.2.6 for Android does not prevent the launching of an activity by a component of another application, which allows attackers to obtain sensitive cached banking information via crafted intents, as demonstrated by the drozer framework.

CVE-2014-5136
Published: 2014-09-02
Cross-site scripting (XSS) vulnerability in Innovative Interfaces Sierra Library Services Platform 1.2_3 allows remote attackers to inject arbitrary web script or HTML via unspecified parameters.

Best of the Web
Dark Reading Radio
Archived Dark Reading Radio
This episode of Dark Reading Radio looks at infosec security from the big enterprise POV with interviews featuring Ron Plesco, Cyber Investigations, Intelligence & Analytics at KPMG; and Chris Inglis & Chris Bell of Securonix.