Two 'Iron Hackers' will have one hour to find as many vulnerabilities in a piece of mystery code as possible at Black Hat USA next month.
For the second year in a row, Fortify Software is hosting its own version of the wildly popular Food Network show Iron Chef, pitting fuzzing techniques against static-code analysis in the Iron Chef-style hacking contest. (See Hacking, Iron Chef Style.)
The two hackers who will face off in Vulnerability Stadium on Aug. 6 are Charlie Miller, principal analyst at Independent Security Evaluators, who will use fuzzing techniques to find vulnerabilities in the code; and Sean Fay, lead engineer for source code analysis at Fortify, who will show his stuff with static-code analysis techniques.
Miller was recruited for the hacking battle after nearly stealing the show last year. Last year, this epic battle taking place wasnt the battle we thought it was going to be -- it ended up being a battle between Iron Chef [session] and the session next door, with the iPhone vulnerability [found by] Charlie Miller. So we had to get some resolution this year, quips Brian Chess, chief scientist at Fortify Software. This year, Charlie Miller is taking up the cause of fuzzing."
Chess is keeping details about the open source code -- the secret ingredient -- close to the vest, but he did say it would be something that Miller would be comfortable with. But we wont be handing out iPhones, Chess says.
One thing Fortify learned from last years competition was that actual exploits are more palatable to the security-celebrity judges and audience than theoretical vulnerability finds. Showing something exploitable goes a long way to impressing people. They had their theoretical results, but what ended up carrying it were the exploits of some simpler stuff, Chess says of last years contest. Even if its not as wild as the theoretical stuff, the judges were hungry for actionable exploits, he says.
The contestants bring their own machines and tools for the contest, and they dont see the code until the contest begins. The audience is also able to compete simultaneously, and Chess and Jacob West, who heads up Fortifys Security Research Group, will serve as emcees and provide live commentary and presentations on the techniques the Iron Hackers are deploying.
It isnt just one presentation there are three or four going on, Chess says.
Its controlled chaos, West says.
And Iron Chef audience members who get the most vulnerabilities get a free dinner at one of Vegass hot new restaurants. Just dont tell Miller or Fay: Nothing but glory for the guys up on stage, Chess says.
Fortify is also sponsoring another hacking competition during the week that could win you an iPhone. Were going to put up a Web app that will be vulnerable in a couple of ways we know about, and probably a couple we dont know about, Chess says. The iPhone goes to whoever finds the most vulns in the application.
Have a comment on this story? Please click "Discuss" below. If you'd like to contact Dark Reading's editors directly, send us a message.