Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Vulnerabilities / Threats

7/7/2008
09:20 AM
Connect Directly
Google+
Twitter
RSS
E-Mail
50%
50%

Hackers to Face Off in Black Hat 'Iron Chef' Contest

Black hat stars don chefs' hats in hacking challenge

Two 'Iron Hackers' will have one hour to find as many vulnerabilities in a piece of mystery code as possible at Black Hat USA next month.

For the second year in a row, Fortify Software is hosting its own version of the wildly popular Food Network show “Iron Chef,” pitting fuzzing techniques against static-code analysis in the Iron Chef-style hacking contest. (See Hacking, Iron Chef Style.)

The two hackers who will face off in Vulnerability Stadium on Aug. 6 are Charlie Miller, principal analyst at Independent Security Evaluators, who will use fuzzing techniques to find vulnerabilities in the code; and Sean Fay, lead engineer for source code analysis at Fortify, who will show his stuff with static-code analysis techniques.

Miller was recruited for the hacking battle after nearly stealing the show last year. “Last year, this epic battle taking place wasn’t the battle we thought it was going to be -- it ended up being a battle between Iron Chef [session] and the session next door, with the iPhone vulnerability [found by] Charlie Miller. So we had to get some resolution this year,” quips Brian Chess, chief scientist at Fortify Software. “This year, Charlie Miller is taking up the cause of fuzzing."

Chess is keeping details about the open source code -- the “secret ingredient” -- close to the vest, but he did say it would be something that Miller would be comfortable with. “But we won’t be handing out iPhones,” Chess says.

One thing Fortify learned from last year’s competition was that actual exploits are more palatable to the security-celebrity judges and audience than theoretical vulnerability finds. “Showing something exploitable goes a long way to impressing people. They had their theoretical results, but what ended up carrying it were the exploits of some simpler stuff,” Chess says of last year’s contest. “Even if it’s not as wild as the theoretical stuff,” the judges were hungry for actionable exploits, he says.

The contestants bring their own machines and tools for the contest, and they don’t see the code until the contest begins. The audience is also able to compete simultaneously, and Chess and Jacob West, who heads up Fortify’s Security Research Group, will serve as emcees and provide live commentary and presentations on the techniques the Iron Hackers are deploying.

“It isn’t just one presentation… there are three or four going on,” Chess says.

“It’s controlled chaos,” West says.

And Iron Chef audience members who get the most vulnerabilities get a free dinner at one of Vegas’s hot new restaurants. Just don’t tell Miller or Fay: “Nothing but glory for the guys up on stage,” Chess says.

Fortify is also sponsoring another hacking competition during the week that could win you an iPhone. “We’re going to put up a Web app that will be vulnerable in a couple of ways we know about, and probably a couple we don’t know about,” Chess says. “The iPhone goes to whoever finds the most vulns in the application.”

Have a comment on this story? Please click "Discuss" below. If you'd like to contact Dark Reading's editors directly, send us a message.

  • Fortify Software Inc. Kelly Jackson Higgins is the Executive Editor of Dark Reading. She is an award-winning veteran technology and business journalist with more than two decades of experience in reporting and editing for various publications, including Network Computing, Secure Enterprise ... View Full Bio

    Comment  | 
    Print  | 
    More Insights
  • Comments
    Threaded  |  Newest First  |  Oldest First
    Data Leak Week: Billions of Sensitive Files Exposed Online
    Kelly Jackson Higgins, Executive Editor at Dark Reading,  12/10/2019
    Lessons from the NSA: Know Your Assets
    Robert Lemos, Contributing Writer,  12/12/2019
    4 Tips to Run Fast in the Face of Digital Transformation
    Shane Buckley, President & Chief Operating Officer, Gigamon,  12/9/2019
    Register for Dark Reading Newsletters
    White Papers
    Video
    Cartoon
    Current Issue
    The Year in Security: 2019
    This Tech Digest provides a wrap up and overview of the year's top cybersecurity news stories. It was a year of new twists on old threats, with fears of another WannaCry-type worm and of a possible botnet army of Wi-Fi routers. But 2019 also underscored the risk of firmware and trusted security tools harboring dangerous holes that cybercriminals and nation-state hackers could readily abuse. Read more.
    Flash Poll
    Rethinking Enterprise Data Defense
    Rethinking Enterprise Data Defense
    Frustrated with recurring intrusions and breaches, cybersecurity professionals are questioning some of the industrys conventional wisdom. Heres a look at what theyre thinking about.
    Twitter Feed
    Dark Reading - Bug Report
    Bug Report
    Enterprise Vulnerabilities
    From DHS/US-CERT's National Vulnerability Database
    CVE-2019-19807
    PUBLISHED: 2019-12-15
    In the Linux kernel before 5.3.11, sound/core/timer.c has a use-after-free caused by erroneous code refactoring, aka CID-e7af6307a8a5. This is related to snd_timer_open and snd_timer_close_locked. The timeri variable was originally intended to be for a newly created timer instance, but was used for ...
    CVE-2014-8650
    PUBLISHED: 2019-12-15
    python-requests-Kerberos through 0.5 does not handle mutual authentication
    CVE-2014-3536
    PUBLISHED: 2019-12-15
    CFME (CloudForms Management Engine) 5: RHN account information is logged to top_output.log during registration
    CVE-2014-3643
    PUBLISHED: 2019-12-15
    jersey: XXE via parameter entities not disabled by the jersey SAX parser
    CVE-2014-3652
    PUBLISHED: 2019-12-15
    JBoss KeyCloak: Open redirect vulnerability via failure to validate the redirect URL.