Nsauditor Network Security Auditor - Advanced All-In-One Network Tools Suite!
  Recommended Product
Network Security Audit Software
Network Security Audit Software and Computer Security Tools
  Learn More
 
 
  Network Security Software
Network Bandwidth Monitor Network Bandwidth Monitor
NBMonitor tracks Internet bandwidth usage (upload and downloads) and shows process names initiated network connections...
Network Hardware Inventory Software Network Hardware Inventory Software
Nsasoft Hardware Software Inventory is a powerful network inventory software for home, office and enterprise networks...
BlueAuditor Monitors Mobile Devices in Wireless Network BlueAuditor Monitors Mobile Devices in Wireless Network
BlueAuditor is a wireless personal area network auditor and easy-to-use program for detecting and monitoring mobile devices in a wireless network...
Network Access Monitoring Network Access Monitoring
ShareAlarmPro allows easily perform network shares and folder monitoring, block unwanted users attempting to access secured shares...
Network Shares Monitoring Network Share Watcher
Monitors network folders permissions and identify shares which are violating company data access policy...
NetworkSleuth Network File Search Utili NetworkSleuth Network File Search Utiliy
NetworkSleuth is a network file searching utility, that allows you to quickly locate files across a network....
Product Key Finder Product Key Finder
Product Key Explorer enables you to quickly recover over 3000 popular software product keys from network computers...
Backup Key Recovery Crashed Drive Keys Recovery Backup Key Recovery Crashed Drive Keys Recovery
Backup Key Recovery retrieves product keys for Windows, MS Office, SQL Server, Adobe products and more than 2500 popular software products...
 
 

Network Security News

Black Hat roundup: Let the electric-shock craziness begin

July 31 2011

Ready to power on next week, the annual Black Hat Conference in Las Vegas promises to be the high-voltage event it has been in the past where security experts tear apart any naïve hope that there's really anything secure at all that was ever made by the high-tech industry.

Black Hat 2011 will showcase more than 50 presentations by security researchers in which the most intense will detail vulnerabilities in everything from USB devices, to printers and scanners, to iPhones to Android devices, to hacking Chrome OS and notebooks, to industrial SCADA systems.

PREVIEW: Exploit demo at Black Hat could 'make your water undrinkable'

Details on some of this are already spilling out, such as in the case of Charlie Miller, who in a Fortune article said he has found a way to hack the chips that control the batteries in Apple's MacBook, MacBook Pro and MacBook Air, letting him ruin them or install persistent malware.

There could be a few horror-inducing sessions, too, such as the presentation from iSec Partners researchers Don Bailey and Matthew Solnik, who will provide a few tips on "war texting" to find cars -- yes, automobiles -- and exploit mobile-networking vulnerabilities in them in order to unlock someone else's car and turn the engine on via a laptop.

And if you're interested in printers, there's a session on how embedded Web servers in printers and scanners can be easily found on the Internet and documents they recently processed gathered up without even breaking into them. That one is being done by Zscaler Labs researcher Michael Sutton.

Here are a few picks from the Black Hat schedule that promise some electrifying chills and thrills (unless the presenters chicken out, as has happened before, because they're afraid that some vendor might sue them). Also, the excitement can also be a little muted once the researcher tells you that of course he already told the vendor about the problem and it's been fixed. Nonetheless, here are some promising acts from the surreal circus that is Black Hat:

- "Exploiting the iOS Kernel," by Stefan Esser, who promises to "introduce the audience to kernel-level exploitation of iPhones."

- "Hacking Androids for Profit," by Riley Hassell and Shane Macaulay, who swear they will "reveal new threats to Android apps, and discuss known and unknown weaknesses in the Android OS and Android market."

- "Apple iOS Security Evaluation: Vulnerability Analysis and Data Encryption," by Dino Dai Zovi, will focus on what the enterprise should be concerned about in "several key security mechanisms" in terms of their strengths and weaknesses.

- "Hacking Google Chrome OS," by Matt Johansen and Kyle Osborn, who say they have "discovered a slew of serious and fundamental security design flaws that with no more than a single mouse-click may victimize users by exposing all user email, contacts, and saved documents," plus much more, including "taking over their Google account by stealing session cookies" and other ways.

- "Chip & PIN is definitely broken," by foursome Adam Laurie, Zac Franken, Andrea Barisani and Daniele Bianco, with their take on "credit-card skimming and PIN harvesting in an EMV world," which will bite down on chip-based payment cards.

- "Exploiting Siemens Simatic S7 PLCs" will feature Dillon Beresford, an independent researcher who also works at NSS Labs, telling us what's wrong with industrial SCADA systems.

- "Owning the Routing Table," by Gabi Nakibly, intends to "present newfound vulnerabilities in the OSPF protocol" which enable an attacker to "own a router's routing table without having to own the router itself."

- "Sophail: A Critical Analysis of Sophos Antivirus," by Tavis Ormandy, gets a little personal in ripping into the Sophos Antivirus product for a "thorough examination of Sophos Antivirus" in order to do an analysis of the vendor's technical claims, as well as "exploring the rich attack surface exposed, and demonstrating weaknesses and vulnerabilities."

- "Exploiting USB Devices with Arduino," by Greg Ose, will talk about exploiting components of the Arduino hardware architecture.

- "A Crushing Blow at the Heart of SAP J2EE Engine," by Alexander Polyakov, will detail an attack on vulnerabilities -- and offer a free tool to try scanning against the attack.

- "Hacking and Forensicating an Oracle Database Server" will feature David Litchfield, an experienced database security researcher who in the past has found critical security weaknesses in Oracle products and who should be taken very seriously.

Some additional highlights: Although it may only have historic value to most of us, security researcher Chris Paget intends to talk about "Microsoft Vista: NDA-less The Good, The Bad and The Ugly," in which he will reveal "previously secret information about the security process that Vista went through." He says he will talk about Vista because the non-disclosure agreement he signed five years ago to get access to the source code and design specifications related to Windows Vista expires right before the Black Hat Conference starts.

That should make it feel like old home week when Kate Moussouris, head of Microsoft's Security Community Outreach and Strategy Team, does her talk, "From Redmond with Love!"

She's supposed to tell the Black Hat attendees -- who have sometimes shown almost excessive love for finding holes in Microsoft Windows products --about how "in 2008, people thought we'd lost our minds when we announced three strategic programs: sharing vulnerability information in our products before there was an update, finding vulnerabilities in third-party products and predicting which vulnerabilities would get reliably exploited in a short timeframe."

After all these years, Microsoft is still wild and wacky, she assures us, saying, "Well, it's 2011 and we haven't stopped coming up with crazy ideas." What gonzo stuff is Microsoft sending her out to tell us about at Black Hat? Stay tuned.

Sours From

View more news

 
  Most Popular Articles
 
 
  Popular Searches
network security magazine network security auditor network security news network security software corporate network security network security systems home network security product key finder password recovery software Network Bandwidth Monitor Network Access Monitoring data access policy monitoring remote shutdown Network File Search key recovery Network Monitoring Computer Security Ethical Hacking Network Security Network Inventory Software Information Security
 
 
  Partner Sites
Network Security Auditor
Nsauditor is a complete networking utilities package that includes more than 45 network tools and utilities for network auditing, scanning,network connections monitoring and more. For more information, please visit:
www.nsauditor.com


Password Recovery Software
SpotAuditor is All-in-one password recovery program that offers administrators and users a comprehensive solution for recovering passwords and other critical business information saved in users' computers. For more information, please visit:
www.password-recovery-software.com

Product Key Explorer
Product Key Explorer quickly recovers and displays product key, including Windows 7 keys, Windows Vista key, Windows XP product key, Microsoft Office 7 product key, MS office 2010 key, Adobe Photoshop, Adobe CS5, CS4, CS3, SQL Server, Electronic Arts games and more than 3000 popular software products:
www.product-key-explorer.com/