Elie Bursztein

Elie Bursztein

Recherche offensive en sécurité des réseaux et du web

franceview my personal page in english

Bad Memories

BlackHat USA 2010/ Defcon 18 (BlackHat USA / Defcon)
Las Vegas, USA
No matter which kind of cryptography you are using to defend your network, , sooner or later to make it work you will have to store somewhere a password, a key or a certificate. If the attacker is able to tampers with its storage mechanism then even the strongest encryption mechanism became irrelevant. In this talk we will present Tapjacking attacks which abuse smartphone features to create more efficient clickjacking attacks. We also show how to attack storage mechanisms to tampers with SSL session and break into Wifi network that use WPA encryption. For SSL we will show how to exploit warning inconsistency and caching mechanisms to trick the user into accepting a bad cert and gets his credential stolen. For Wifi network we will demonstrate how to use clickjacking, CSRF, and XSS to steal from routers the two pieces of information that an attacker needs to geo-localize and break into it, namely the WPA key and the mac address. Finally we will discuss how to discuss what frame busting defense are used by the Alexa top 100 website and how we were able to break them using standard and not so standard tricks. We also demonstrate how to use Paul Stone scrolling attack in novel ways. This is joint work with Dan Boneh and Collin Jackson
Tags: web, offensive technologies
Files:
view it link it
slides http://ly.tl/t9s  
WPA attack http://ly.tl/bh1  
HTTPS cache injection attack http://ly.tl/bh2  
TapJacking http://ly.tl/bh3  
Emploi :
Scientifique
Lab :
Stanford Security Lab
Université :
Stanford University, USA
Email :
Mobile :
Social profiles :
Elie's Facebook page Elie's Twitter Elie's Linkedin profile Elie's on asmallworld
social icon
News des réseaux sociaux
rss feed
Blog
chargement, veuillez patienter
map
Dernière visite
 Usenix Securiy 2010 (Other - Entertainment)
""