Elie Bursztein

Elie Bursztein

Recherche offensive en sécurité des réseaux et du web

franceview my personal page in english

Embedded Management Interfaces: Emerging Massive Insecurity

BlackHat USA 2009 (BlackHat USA 09)
Las Vegas, USA
Over the last few years, the number of devices that embed user-friendly management interfaces accessible from the network has drastically increased. These interfaces can be found on almost every kind of device, from lights-out management systems for PCs, to small SOHO NAS appliances, to photo frames. In this talk, we will cover the attack surface of embedded management interfaces and pinpoint which parts of them are the most likely to be vulnerable, based on our evaluation of more than a dozen device models from different categories. In particular, we will review known yet underestimated implementation shortcuts that lead to vulnerabilities. To illustrate each shortcut, we will describe real-world vulnerabilities that we have found and exploited in devices from Intel, Linksys, Lacie, Samsung, and Dell among others.
Tags: Embedded devices, web, offensive technologie
Files:
view it link it
paper http://ly.tl/t3a  
slides http://ly.tl/t3s  
Emploi :
Scientifique
Lab :
Stanford Security Lab
Université :
Stanford University, USA
Email :
Mobile :
Social profiles :
Elie's Facebook page Elie's Twitter Elie's Linkedin profile Elie's on asmallworld
social icon
News des réseaux sociaux
rss feed
Blog
chargement, veuillez patienter
map
Dernière visite
 Usenix Securiy 2010 (Other - Entertainment)
""