Black hat and defcon 2014

25
Black hat / Defcon 2014

description

Presenting BlackHat USA 2014 and Dercon 22

Transcript of Black hat and defcon 2014

Page 1: Black hat and defcon 2014

Black hat / Defcon 2014

Page 2: Black hat and defcon 2014

What is (a) Blackhat?• A conference for security professionals• 4 days of training, 2 days of briefings• 9,000 security executives, hackers, academics, and spies attended Black Hat this year• A "black hat" hacker is a hacker who "violates computer security for little reason beyond maliciousness or

for personal gain“• Ticket price range from $1795 - $2595 just for the briefings

Page 3: Black hat and defcon 2014

Venue – Mandalay Bay

Nothing says Vegas like a hotel wedding chapel

• First year that BH enters Mandalay• 3,309 hotel rooms and a casino of

12,500 m2

• Convention center is 93,000 m2 (!)

Page 4: Black hat and defcon 2014

What is Defcon ?• By hackers, for hackers• Nearly 16,000 attendees, up from last year’s 12,000.• Tickets cost $220 at the door – cash only (I wonder why)

Page 5: Black hat and defcon 2014

Venue – Rio

• 2,522 hotel rooms and a casino of 11,000 m2

• Convention center only 15,000 m2

• Long lines...

Page 6: Black hat and defcon 2014

Focus on hacks, whatever it might be• Badge hacking• SDR hacking• Hardware• Software• Locks• People…• Hack all the things!

Page 7: Black hat and defcon 2014

People who think that they’re hackers

Page 8: Black hat and defcon 2014

Wall of sheep• Dedicated to security research and

the advancement of security awareness through, in many cases, unconventional methods.

”Free charge?! Awesome!”

Page 9: Black hat and defcon 2014

Skytalks

• A con within a con (conception?)• Classic, old-school Defcon: no cameras, no recording.

No pre-con content takedowns. No sobriety. No bullshit.• Solely funded by donations• “Special” talks• A brief history of teledildonics. Yeah, apparently that’s a thing.• Breaking MIFARE ULTRALIGHT.. or how to get free rides and more

Page 10: Black hat and defcon 2014

Summary

Page 11: Black hat and defcon 2014
Page 12: Black hat and defcon 2014

A Survey of Remote Automotive Attack Surfaces • Hacking cars remotely

Source: autoguide.com

Page 13: Black hat and defcon 2014

BadUSB

Page 14: Black hat and defcon 2014

Extreme Privilege Escalation on Windows 8/UEFI Systems• Hacking Windows through the bios

https://www.blackhat.com/docs/us-14/materials/us-14-Kallenberg-Extreme-Privilege-Escalation-On-Windows8-UEFI-Systems-WP.pdf

Page 15: Black hat and defcon 2014
Page 16: Black hat and defcon 2014

Interesting sessionsCyber defend yourself – Don’t screw up!

Page 17: Black hat and defcon 2014

Interesting sessions• Hacking RFID – or how to ride for free on public transportation

Source: SL

Page 18: Black hat and defcon 2014

Interesting sessions• Internet of things

Source: Morgan Stanley

Page 19: Black hat and defcon 2014

Interesting sessions• Post Exploitation – Veil Pillage

Page 20: Black hat and defcon 2014

Interesting sessions• What the Watchers see – or not…

Page 21: Black hat and defcon 2014

Interesting sessions• Veaponize your pets

Source: Funnypostcard.coml

Page 22: Black hat and defcon 2014

Interesting sessions cont.• Exploiting Thunderbolt

Source: Intel

Page 23: Black hat and defcon 2014

Everybody loves to hack credit cards!

Page 24: Black hat and defcon 2014

Credit card hacks present or presented at Defcon

• Jackpotting ATMs• Mag stripe skimming (duh…)• Relay attack • False terminals (capture PIN)• No PIN attack (MiTM attack)

• More www.lightbluetouchpaper.org• And http://www.cl.cam.ac.uk/~rja14/banksec.html

Page 25: Black hat and defcon 2014

Interesting sessions• And of course…. Lots on NSA playset

Source: Der Spiegel