Wednesday, July 28, 2010

Blackhat 2010 - Day One

It's summer in Vegas! That means two things, 100+ degree heat (but it's a dry heat, yeah right) and the Blackhat security conference. My how Blackhat has grown! This year there are no fewer than eleven tracks - yes, you read that right, eleven tracks. Far too many IMO as it's now impossible to attend all of the talks that you want as several are sure to overlap. Hopefully in future years they'll scale back the number of tracks or consider extending the conference over additional days.

While I wasn't able to attend everything that I would have liked to, I did take in several great talks and here's an overview of the hilights.

Dan Hubbard, Websense
Real-Time Search Poisoning

Dan has been spending time researching ways to abuse realtime search of social networking content, most notably Twitter. His goal - figure out how to ensure that your desired content shows up in the most popular results for a given topic. Think Blackhat SEO with a social angle. Dan illustrated a variety of approaches that focused on the following techniques:
  • Time and trend hacks - continual or well timed postings
  • Social graph hacking - linking to or taking control of existing account
  • Geo hacks - spoof your location to target people in a certain geography (i.e. Nearby Tweets)
Looks like the Blackhat SEO crew has a whole new playground.

Wolfgang Kandek, Qualys
Jeremiah Grossman, Whitehat Security
CSA Application Security Findings

I wasn't able to stay for the full talk but Jeremiah made some insightful comments.
  • Web application security is a scale problem. 200M websites built before we knew that they needed to be secured and 200M more built by people that don't have security knowledge.
  • Web application developers have a lack of motivation when it comes to security - developers get paid to ship product, not secure product.
So true Jeremiah.

Charlie Miller
Noah Johnson
Crash Analysis Using BitBlaze
I'm always up for a good Charlie Miller talk. He's sure to drop an 0day (Adobe was the target this time) and speak his mind. He's also a great guy, after all, he provided critical feedback on the Fuzzing book that we released in 2007. Charlie spoke about BitBlaze, a binary analyzer out of UC Berkeley that he's been using to streamline vulnerability discovery. It fuzes static and dynamic analysis, allows for taint analysis and delivers taint slicing - an approach which allows the researcher to more easily follow the path of user supplied input throughout the code execution process. Charlie's ultimate assessment - the trace data provided by BitBlaze is very valuable. Although the tool can be a bit slow, the overall approach will likely save you time in the end as you'll be able to better focus on crashes likely to be exploitable.

Michael Sutton, Zscaler
Dan Hubbard, Websense
Steven Adair, ShadowServer
Steve Riley, Amazon
Michael Panico, Microsoft
Chris St. Myers, Rackspace
Alex Rice, Facebook
Unpanel Royale
Dan and I had the good fortune to assemble an all-star cast to debate security in the cloud and how the cloud is being abused by attackers. I was especially pleased at how honest the vendors were willing to be, providing insight into the challenges that they face. More than once they hilighted the fact that they are restricted in what they can do from a security perspective due to business requirements to maintain customer privacy. Yes, they could identify malicious content if they scanned all uploaded content but that would not be well received by customers who expect that their data will not be inspected - a business/security battle that will need to be resolved. Monitoring is therefore largely restricted to the network level. To date, far too much security from cloud vendors has been the man behind the curtain, with too little shared publicly. It was great to hear directly from the vendors that they recognize the security challenges and are working to resolve them. My favorite quote came from Steve Riley who insisted that Amazon is committed to providing customers with options and not locking them into the AWS platform. He stated that "[Amazon] wants to build a service that is as easy for you to enter as it is to exit". Good for you Steve - we're going to hold you to that.

I unfortunately wasn't able to attend what was ultimately the talk of the day as it conflicted with our panel. After lunch, Barnaby Jack delivered a talk that was pulled last year on how to hack ATM machines. Barnaby actually purchased his own ATMs for the research and was able to root the machines. Here's a video of his live demo - getting a machine to spit out dollar bills using his program called (what else) Jackpot...and he did it all to music.
Day one done.
- michael

No comments: