Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Black Hat USA
July 31 - August 5, 2021
Las Vegas, NV, USA
SecTor
November 4 - October 30, 2021
Toronto, ON, Canada
Black Hat Europe
November 8-11, 2021
Virtual Event
5/17/2016
01:00 PM
Black Hat Staff
Black Hat Staff
Event Updates
50%
50%

Black Hat USA 2016: Mobile Hacking

Over 1.4 billion people across the world are using Android devices, according to Google. Unlike Apple's iOS, Android is not tied to a specific manufacturer, allowing it to account for 81.6% of the smartphone operating system market (Statistica). However, since Android dominates the smartphone market, it presents an ideal opportunity for hackers to tap into a large base of user information. It's essential for Android users, as well as iOS users, to learn how to protect themselves.

Mobile Hacking

Can You Trust Me Now? An Exploration Into the Mobile Threat Landscape gives an overview of the entire mobile ecosystem. Learn everything from the hardware components to the operating systems of myriad mobile devices. This Briefing reveals the vulnerabilities that mobile devices encounter today and the threats that are projected to arise in the future. Mobile trusted computing has limitations, which can leave your device exposed to any experienced hacker who breaks through the trust. If your device is compromised, it can often be difficult to detect. This talk will present real-world tactics to enhance your security to keep your information protected.

Adaptive Kernel Live Patching: An Open Collaborative Effort To Ameliorate Android N-Day Root Exploits reveals that Android’s biggest threat to users is its kernel vulnerability. It is common for underground businesses to use kernel vulnerabilities in their malware and APTs. It’s extremely difficult to patch vulnerable devices at scale, due to a large number of vendors not providing up-to-date kernel source code for all of their devices. This talk presents the adaptive Android live patching framework, which offers access to live patching for kernels and multiple advantages for developers.

In addition to the mobile threats directed at Android users, the Pangu 9 Internals Briefing exposes some of the security threats iOS users can encounter. Pangu 9 is considered the first unbound jailbreak tool that offered hackers access to the iOS 9. Fortunately, iOS 9.2 fixed the dangerous bug but there were no specific details disclosed on how the security problem was resolved. This talk offers an inside look at the logical error in the system that created the original vulnerability and an additional new vulnerability in the backup-restore process.

If you want to test Android and iOS platforms yourself, the Mobile Application Bootcamp - Journeyman Level Training teaches attendees the techniques hackers use to attack mobile devices overall. Learning how mobile hacking is accomplished will provide greater insight into the methods you can use to protect your own information. Attendees will learn how to conduct penetration testing through a series of lectures, labs, demonstrations, and group exercises. If you’re interested in security testing specifically designed for Android devices, the Android Application Hacking - Pentesting and Reversing Mobile Apps Training offers in-depth techniques on how to perform static analytics, traffic manipulation, debugging, and more!

Black Hat USA 2016 Trainings run July 30 - August 2, with both 2-day and 4-day classes available. Then the Briefings will be presented August 3 and 4. Comprehensive event information can be found at blackhat.com/us-16/.

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
Edge-DRsplash-10-edge-articles
I Smell a RAT! New Cybersecurity Threats for the Crypto Industry
David Trepp, Partner, IT Assurance with accounting and advisory firm BPM LLP,  7/9/2021
News
Attacks on Kaseya Servers Led to Ransomware in Less Than 2 Hours
Robert Lemos, Contributing Writer,  7/7/2021
Commentary
It's in the Game (but It Shouldn't Be)
Tal Memran, Cybersecurity Expert, CYE,  7/9/2021
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
How Enterprises Are Assessing Cybersecurity Risk in Today's Environment
The adoption of cloud services spurred by the COVID-19 pandemic has resulted in pressure on cyber-risk professionals to focus on vulnerabilities and new exposures that stem from pandemic-driven changes. Many cybersecurity pros expect fundamental, long-term changes to their organization's computing and data security due to the shift to more remote work and accelerated cloud adoption. Download this report from Dark Reading to learn more about their challenges and concerns.
Flash Poll
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2021-24976
PUBLISHED: 2022-01-24
The Smart SEO Tool WordPress plugin before 3.0.6 does not sanitise and escape the search parameter before outputting it back in an attribute when the TDK optimisation setting is enabled, leading to a Reflected Cross-Site Scripting
CVE-2021-24985
PUBLISHED: 2022-01-24
The Easy Forms for Mailchimp WordPress plugin before 6.8.6 does not sanitise and escape the field_name and field_type parameters before outputting them back in attributes, leading to Reflected Cross-Site Scripting issues
CVE-2021-24989
PUBLISHED: 2022-01-24
The Accept Donations with PayPal WordPress plugin before 1.3.4 does not have CSRF check in place and does not ensure that the post to be deleted belongs to the plugin, allowing attackers to make a logged in admin delete arbitrary posts from the blog
CVE-2021-25008
PUBLISHED: 2022-01-24
The Code Snippets WordPress plugin before 2.14.3 does not escape the snippets-safe-mode parameter before outputting it back in attributes, leading to a Reflected Cross-Site Scripting issue
CVE-2021-25013
PUBLISHED: 2022-01-24
The Qubely WordPress plugin before 1.7.8 does not have authorisation and CSRF check on the qubely_delete_saved_block AJAX action, and does not ensure that the block to be deleted belong to the plugin, as a result, any authenticated users, such as subscriber can delete arbitrary posts