Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Vulnerabilities / Threats

7/7/2008
09:20 AM
Connect Directly
Google+
Twitter
RSS
E-Mail
50%
50%

Hackers to Face Off in Black Hat 'Iron Chef' Contest

Black hat stars don chefs' hats in hacking challenge

Two 'Iron Hackers' will have one hour to find as many vulnerabilities in a piece of mystery code as possible at Black Hat USA next month.

For the second year in a row, Fortify Software is hosting its own version of the wildly popular Food Network show “Iron Chef,” pitting fuzzing techniques against static-code analysis in the Iron Chef-style hacking contest. (See Hacking, Iron Chef Style.)

The two hackers who will face off in Vulnerability Stadium on Aug. 6 are Charlie Miller, principal analyst at Independent Security Evaluators, who will use fuzzing techniques to find vulnerabilities in the code; and Sean Fay, lead engineer for source code analysis at Fortify, who will show his stuff with static-code analysis techniques.

Miller was recruited for the hacking battle after nearly stealing the show last year. “Last year, this epic battle taking place wasn’t the battle we thought it was going to be -- it ended up being a battle between Iron Chef [session] and the session next door, with the iPhone vulnerability [found by] Charlie Miller. So we had to get some resolution this year,” quips Brian Chess, chief scientist at Fortify Software. “This year, Charlie Miller is taking up the cause of fuzzing."

Chess is keeping details about the open source code -- the “secret ingredient” -- close to the vest, but he did say it would be something that Miller would be comfortable with. “But we won’t be handing out iPhones,” Chess says.

One thing Fortify learned from last year’s competition was that actual exploits are more palatable to the security-celebrity judges and audience than theoretical vulnerability finds. “Showing something exploitable goes a long way to impressing people. They had their theoretical results, but what ended up carrying it were the exploits of some simpler stuff,” Chess says of last year’s contest. “Even if it’s not as wild as the theoretical stuff,” the judges were hungry for actionable exploits, he says.

The contestants bring their own machines and tools for the contest, and they don’t see the code until the contest begins. The audience is also able to compete simultaneously, and Chess and Jacob West, who heads up Fortify’s Security Research Group, will serve as emcees and provide live commentary and presentations on the techniques the Iron Hackers are deploying.

“It isn’t just one presentation… there are three or four going on,” Chess says.

“It’s controlled chaos,” West says.

And Iron Chef audience members who get the most vulnerabilities get a free dinner at one of Vegas’s hot new restaurants. Just don’t tell Miller or Fay: “Nothing but glory for the guys up on stage,” Chess says.

Fortify is also sponsoring another hacking competition during the week that could win you an iPhone. “We’re going to put up a Web app that will be vulnerable in a couple of ways we know about, and probably a couple we don’t know about,” Chess says. “The iPhone goes to whoever finds the most vulns in the application.”

Have a comment on this story? Please click "Discuss" below. If you'd like to contact Dark Reading's editors directly, send us a message.

  • Fortify Software Inc. Kelly Jackson Higgins is the Executive Editor of Dark Reading. She is an award-winning veteran technology and business journalist with more than two decades of experience in reporting and editing for various publications, including Network Computing, Secure Enterprise ... View Full Bio
     

    Recommended Reading:

    Comment  | 
    Print  | 
    More Insights
  • Comments
    Threaded  |  Newest First  |  Oldest First
    COVID-19: Latest Security News & Commentary
    Dark Reading Staff 7/2/2020
    Ripple20 Threatens Increasingly Connected Medical Devices
    Kelly Sheridan, Staff Editor, Dark Reading,  6/30/2020
    DDoS Attacks Jump 542% from Q4 2019 to Q1 2020
    Dark Reading Staff 6/30/2020
    Register for Dark Reading Newsletters
    White Papers
    Video
    Cartoon
    Current Issue
    How Cybersecurity Incident Response Programs Work (and Why Some Don't)
    This Tech Digest takes a look at the vital role cybersecurity incident response (IR) plays in managing cyber-risk within organizations. Download the Tech Digest today to find out how well-planned IR programs can detect intrusions, contain breaches, and help an organization restore normal operations.
    Flash Poll
    The Threat from the Internetand What Your Organization Can Do About It
    The Threat from the Internetand What Your Organization Can Do About It
    This report describes some of the latest attacks and threats emanating from the Internet, as well as advice and tips on how your organization can mitigate those threats before they affect your business. Download it today!
    Twitter Feed
    Dark Reading - Bug Report
    Bug Report
    Enterprise Vulnerabilities
    From DHS/US-CERT's National Vulnerability Database
    CVE-2020-9498
    PUBLISHED: 2020-07-02
    Apache Guacamole 1.1.0 and older may mishandle pointers involved inprocessing data received via RDP static virtual channels. If a userconnects to a malicious or compromised RDP server, a series ofspecially-crafted PDUs could result in memory corruption, possiblyallowing arbitrary code to be executed...
    CVE-2020-3282
    PUBLISHED: 2020-07-02
    A vulnerability in the web-based management interface of Cisco Unified Communications Manager, Cisco Unified Communications Manager Session Management Edition, Cisco Unified Communications Manager IM & Presence Service, and Cisco Unity Connection could allow an unauthenticated, remote attack...
    CVE-2020-5909
    PUBLISHED: 2020-07-02
    In versions 3.0.0-3.5.0, 2.0.0-2.9.0, and 1.0.1, when users run the command displayed in NGINX Controller user interface (UI) to fetch the agent installer, the server TLS certificate is not verified.
    CVE-2020-5910
    PUBLISHED: 2020-07-02
    In versions 3.0.0-3.5.0, 2.0.0-2.9.0, and 1.0.1, the Neural Autonomic Transport System (NATS) messaging services in use by the NGINX Controller do not require any form of authentication, so any successful connection would be authorized.
    CVE-2020-5911
    PUBLISHED: 2020-07-02
    In versions 3.0.0-3.5.0, 2.0.0-2.9.0, and 1.0.1, the NGINX Controller installer starts the download of Kubernetes packages from an HTTP URL On Debian/Ubuntu system.