Vulnerabilities / Threats
3/7/2014
02:22 PM
Connect Directly
RSS
E-Mail
50%
50%

Black Hat Asia 2014: The Weaponized Web

These Black Hat Briefings explore ways the Web can be weaponized -- and how to defend against them

The World Wide Web has grown exponentially since its birth 21 years ago, and it now serves as the interface for many of the apps we use every day. It's hard to imagine a more enticing target for hacks and exploits. Today's trio of Black Hat Briefings explore ways the Web can be weaponized ... and how to defend against it.

Even as HTML 5 proliferates as an enabler of rich interactive Web applications, cross-site scripting (XSS) remains one of the top three Web application vulnerabilities. DOM-based XSS is growing in popularity, but its client-side nature makes it difficult to monitor for malicious payloads. Ultimate Dom Based XSS Detection Scanner on Clouddelves into this thorny issue. Nera W. C. Liu and Albert Yu will show how they managed to introduce and propagate tainted attributes to a DOM input interface, and then devised a system to detect such breaches by harnessing the power of PhantomJS, a headless browser for automation.

JavaScript's ubiquity makes it the subject of aggressive security-community research, boosting its effective security level every day. Sounds good, but in JS Suicide: Using JavaScript Security Features to Kill JS Security, AhamedNafeez will demonstrate that these security features can be a double-edged sword, sometimes allowing an attacker to disable certain other JS protection mechanisms. In particular, the sandboxing features of ECMAScript 5 can break security in many JS applications. Real-world examples of other JS security lapses are also on the agenda.

Ready-made exploit kits make it easier than ever for malicious parties to victimize unwary Internet users. Jose Miguel Esparza will take us down that rabbit hole in PDF Attack: A Journey From the Exploit Kit to the Shellcode, in which he'll teach how to manually extract obfuscated URLs and binaries from these weaponized pages. You'll also learn how to do modify a malicious PDF payload yourself to bypass AV software, a useful trick for pentesting.

Looking to register? Please visit Black Hat Asia 2014's registration page to get started.

Comment  | 
Print  | 
More Insights
Register for Dark Reading Newsletters
White Papers
Flash Poll
Current Issue
Cartoon
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2013-6306
Published: 2014-08-22
Unspecified vulnerability on IBM Power 7 Systems 740 before 740.70 01Ax740_121, 760 before 760.40 Ax760_078, and 770 before 770.30 01Ax770_062 allows local users to gain Service Processor privileges via unknown vectors.

CVE-2014-0232
Published: 2014-08-22
Multiple cross-site scripting (XSS) vulnerabilities in framework/common/webcommon/includes/messages.ftl in Apache OFBiz 11.04.01 before 11.04.05 and 12.04.01 before 12.04.04 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors, which are not properly handled in a (1)...

CVE-2014-3525
Published: 2014-08-22
Unspecified vulnerability in Apache Traffic Server 4.2.1.1 and 5.x before 5.0.1 has unknown impact and attack vectors, possibly related to health checks.

CVE-2014-3563
Published: 2014-08-22
Multiple unspecified vulnerabilities in Salt (aka SaltStack) before 2014.1.10 allow local users to have an unspecified impact via vectors related to temporary file creation in (1) seed.py, (2) salt-ssh, or (3) salt-cloud.

CVE-2014-3587
Published: 2014-08-22
Integer overflow in the cdf_read_property_info function in cdf.c in file through 5.19, as used in the Fileinfo component in PHP before 5.4.32 and 5.5.x before 5.5.16, allows remote attackers to cause a denial of service (application crash) via a crafted CDF file. NOTE: this vulnerability exists bec...

Best of the Web
Dark Reading Radio
Archived Dark Reading Radio
Three interviews on critical embedded systems and security, recorded at Black Hat 2014 in Las Vegas.