Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Vulnerabilities / Threats

7/7/2008
09:20 AM
Connect Directly
Google+
Twitter
RSS
E-Mail
50%
50%

Hackers to Face Off in Black Hat 'Iron Chef' Contest

Black hat stars don chefs' hats in hacking challenge

Two 'Iron Hackers' will have one hour to find as many vulnerabilities in a piece of mystery code as possible at Black Hat USA next month.

For the second year in a row, Fortify Software is hosting its own version of the wildly popular Food Network show “Iron Chef,” pitting fuzzing techniques against static-code analysis in the Iron Chef-style hacking contest. (See Hacking, Iron Chef Style.)

The two hackers who will face off in Vulnerability Stadium on Aug. 6 are Charlie Miller, principal analyst at Independent Security Evaluators, who will use fuzzing techniques to find vulnerabilities in the code; and Sean Fay, lead engineer for source code analysis at Fortify, who will show his stuff with static-code analysis techniques.

Miller was recruited for the hacking battle after nearly stealing the show last year. “Last year, this epic battle taking place wasn’t the battle we thought it was going to be -- it ended up being a battle between Iron Chef [session] and the session next door, with the iPhone vulnerability [found by] Charlie Miller. So we had to get some resolution this year,” quips Brian Chess, chief scientist at Fortify Software. “This year, Charlie Miller is taking up the cause of fuzzing."

Chess is keeping details about the open source code -- the “secret ingredient” -- close to the vest, but he did say it would be something that Miller would be comfortable with. “But we won’t be handing out iPhones,” Chess says.

One thing Fortify learned from last year’s competition was that actual exploits are more palatable to the security-celebrity judges and audience than theoretical vulnerability finds. “Showing something exploitable goes a long way to impressing people. They had their theoretical results, but what ended up carrying it were the exploits of some simpler stuff,” Chess says of last year’s contest. “Even if it’s not as wild as the theoretical stuff,” the judges were hungry for actionable exploits, he says.

The contestants bring their own machines and tools for the contest, and they don’t see the code until the contest begins. The audience is also able to compete simultaneously, and Chess and Jacob West, who heads up Fortify’s Security Research Group, will serve as emcees and provide live commentary and presentations on the techniques the Iron Hackers are deploying.

“It isn’t just one presentation… there are three or four going on,” Chess says.

“It’s controlled chaos,” West says.

And Iron Chef audience members who get the most vulnerabilities get a free dinner at one of Vegas’s hot new restaurants. Just don’t tell Miller or Fay: “Nothing but glory for the guys up on stage,” Chess says.

Fortify is also sponsoring another hacking competition during the week that could win you an iPhone. “We’re going to put up a Web app that will be vulnerable in a couple of ways we know about, and probably a couple we don’t know about,” Chess says. “The iPhone goes to whoever finds the most vulns in the application.”

Have a comment on this story? Please click "Discuss" below. If you'd like to contact Dark Reading's editors directly, send us a message.

  • Fortify Software Inc. Kelly Jackson Higgins is the Executive Editor of Dark Reading. She is an award-winning veteran technology and business journalist with more than two decades of experience in reporting and editing for various publications, including Network Computing, Secure Enterprise ... View Full Bio

    Comment  | 
    Print  | 
    More Insights
  • Comments
    Newest First  |  Oldest First  |  Threaded View
    Register for Dark Reading Newsletters
    White Papers
    Video
    Cartoon Contest
    Write a Caption, Win a Starbucks Card! Click Here
    Latest Comment: Our Endpoint Protection system is a little outdated... 
    Current Issue
    The Year in Security: 2019
    This Tech Digest provides a wrap up and overview of the year's top cybersecurity news stories. It was a year of new twists on old threats, with fears of another WannaCry-type worm and of a possible botnet army of Wi-Fi routers. But 2019 also underscored the risk of firmware and trusted security tools harboring dangerous holes that cybercriminals and nation-state hackers could readily abuse. Read more.
    Flash Poll
    Rethinking Enterprise Data Defense
    Rethinking Enterprise Data Defense
    Frustrated with recurring intrusions and breaches, cybersecurity professionals are questioning some of the industrys conventional wisdom. Heres a look at what theyre thinking about.
    Twitter Feed
    Dark Reading - Bug Report
    Bug Report
    Enterprise Vulnerabilities
    From DHS/US-CERT's National Vulnerability Database
    CVE-2019-16246
    PUBLISHED: 2019-12-12
    Intesync Solismed 3.3sp1 allows Local File Inclusion (LFI), a different vulnerability than CVE-2019-15931. This leads to unauthenticated code execution.
    CVE-2019-17358
    PUBLISHED: 2019-12-12
    Cacti through 1.2.7 is affected by multiple instances of lib/functions.php unsafe deserialization of user-controlled data to populate arrays. An authenticated attacker could use this to influence object data values and control actions taken by Cacti or potentially cause memory corruption in the PHP ...
    CVE-2019-17428
    PUBLISHED: 2019-12-12
    An issue was discovered in Intesync Solismed 3.3sp1. An flaw in the encryption implementation exists, allowing for all encrypted data stored within the database to be decrypted.
    CVE-2019-18345
    PUBLISHED: 2019-12-12
    A reflected XSS issue was discovered in DAViCal through 1.1.8. It echoes the action parameter without encoding. If a user visits an attacker-supplied link, the attacker can view all data the attacked user can view, as well as perform all actions in the name of the user. If the user is an administrat...
    CVE-2019-19198
    PUBLISHED: 2019-12-12
    The Scoutnet Kalender plugin 1.1.0 for WordPress allows XSS.