Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Vulnerabilities / Threats

5/27/2013
08:31 PM
50%
50%

Black Hat Reveals BlueTooth, SSL Exploit Talks For July Show

Each presentation will dip into clever exploits and workarounds for major protocols

[NOTE: Black Hat and Dark Reading are both part of UBM Tech. As the key July 27th-August 1st information security event in Las Vegas approaches, we'll be sharing information about the show directly from its creators here on Dark Reading.]

With just a handful of days left to Black Hat USA 2013's Friday early registration deadline, organizers have revealed a number of notable new talks -- just one of multiple updates debuting this week, since a large amount of high-profile Briefings content is being revealed.

Click here for more of Dark Reading's Black Hat articles.

This comes just after the announcement of the show's second keynote, in the form of Brian Muirhead, Chief Engineer, NASA's Jet Propulsion Laboratory, and former manager of the Mars Pathfinder Mission, who will be giving an inspirational talk based on his amazing accomplishment with Pathfinder, "Take Risk, Don't Fail."

This time, we're focusing on three talks presented for the first time at Black Hat USA 2013, each of which dips into clever exploits and workarounds for major protocols -- from BlueTooth 4.0 through SSL to TLS sessions. Here's some more details on each of them:

-- In "Bluetooth Smart: The Good, The Bad, The Ugly, and The Fix!," iSec Partners' Mike Ryan presents a painstakingly researched talk on the widely used protocol. This talk not only shows the weaknesses (both bad and ugly, as noted!) of BlueTooth 4.0, it shows the tools to hack it and even how to prevent being sniffed yourself. And even better, in a growing trend at Black Hat, more and more researchers are including guidance on how to fix the discovered issue. So if you'd like to see a live demonstration of sniffing and recovering encryption keys using open-source tools Ryan and partners developed, alongside a clever fix to render the protocol secure against passive eavesdroppers, this'll be the lecture for you.

-- Next, we're focusing on "SSL, gone in 30 seconds – A BREACH beyond CRIME," presented by Angelo Prado and Neal Harris. This talk is particularly important because HTTPS gives consumers the feeling of safety. Security professionals look to SSL to provide a notion of identity (you know who you are talking to) and confidentiality (the stream of data is just for you and the server!). This talk shows how to reliably retrieve encrypted messages like session IDs, OAuth tokens, email addresses, and more via an exploit. The presenters then explain how you can protect against this type of attack, and will even release a tool, BREACH, at the end of the session to help the community test and mitigate.

-- Finally, "Truncating TLS sessions to violate beliefs" from Ben Smyth showcases attacks against a basic Internet communication security layer to do a number of eye-opening things. As Smyth explains, his research has "identified Web applications that fail to maintain order between TLS sessions ... thereby causing a desynchronization between the expected state of the user and server." As a result, Smyth shows how he can exploit the Helios electronic voting system to cast votes on behalf of honest voters, take full control of Microsoft Live accounts, and gain temporary access to Google accounts -- all substantive and notable exploits which will give major lessons to Web security development professionals.

More information about Black Hat USA 2013, which has a rapidly growing set of Briefings talks, as well as a comprehensive set of two- and four-day trainings, is available now -- early, reduced-rated registration is open until May 31st.

Comment  | 
Print  | 
More Insights
Comments
Oldest First  |  Newest First  |  Threaded View
7 Tips for Infosec Pros Considering A Lateral Career Move
Kelly Sheridan, Staff Editor, Dark Reading,  1/21/2020
For Mismanaged SOCs, The Price Is Not Right
Kelly Sheridan, Staff Editor, Dark Reading,  1/22/2020
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Write a Caption, Win a Starbucks Card! Click Here
Latest Comment:   It's a PEN test of our cloud security.
Current Issue
IT 2020: A Look Ahead
Are you ready for the critical changes that will occur in 2020? We've compiled editor insights from the best of our network (Dark Reading, Data Center Knowledge, InformationWeek, ITPro Today and Network Computing) to deliver to you a look at the trends, technologies, and threats that are emerging in the coming year. Download it today!
Flash Poll
How Enterprises are Attacking the Cybersecurity Problem
How Enterprises are Attacking the Cybersecurity Problem
Organizations have invested in a sweeping array of security technologies to address challenges associated with the growing number of cybersecurity attacks. However, the complexity involved in managing these technologies is emerging as a major problem. Read this report to find out what your peers biggest security challenges are and the technologies they are using to address them.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2020-5226
PUBLISHED: 2020-01-24
Cross-site scripting in SimpleSAMLphp before version 1.18.4. The www/erroreport.php script allows error reports to be submitted and sent to the system administrator. Starting with SimpleSAMLphp 1.18.0, a new SimpleSAML\Utils\EMail class was introduced to handle sending emails, implemented as a wrapp...
CVE-2019-1517
PUBLISHED: 2020-01-24
** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2019. Notes: none.
CVE-2019-1518
PUBLISHED: 2020-01-24
** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2019. Notes: none.
CVE-2019-1519
PUBLISHED: 2020-01-24
** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2019. Notes: none.
CVE-2019-1520
PUBLISHED: 2020-01-24
** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2019. Notes: none.