Тёмный

35C3 - In Soviet Russia Smart Card Hacks You 

media.ccc.de
Подписаться 211 тыс.
Просмотров 9 тыс.
50% 1

media.ccc.de/v...
The classic spy movie hacking sequence: The spy inserts a magic smart card provided by the agency technicians into the enemy's computer, … the screen unlocks … What we all laughed about is possible!
Smartcards are secure and trustworthy. This is the idea smart card driver developers have in mind when developing drivers and smart card software. The work presented in this talk not only challenges, but crushes this assumption by attacking drivers using malicious smart cards.
We will present a fuzzing framework for *nix and Windows along with some interesting bugs found by auditing and fuzzing smart card drivers and middleware. Among them classic stack and heap buffer overflows, double frees, but also a replay attack against smart card authentication.
Since smart cards are used in the authentication process, a lot of vulnerabilities can be triggered by an unauthenticated user, in code running with high privileges. During the author's research, bugs were discovered in OpenSC (EPass, PIV, OpenPGP, CAC, Cryptoflex …), YubiKey drivers, pam_p11, pam_pkc11, Apple's smartcard-services and others.
Eric Sesterhenn
fahrplan.event...

Опубликовано:

 

22 окт 2024

Поделиться:

Ссылка:

Скачать:

Готовим ссылку...

Добавить в:

Мой плейлист
Посмотреть позже
Комментарии    
Далее
35C3 -  Viva la Vita Vida
56:37
Просмотров 17 тыс.
Living off Microsoft Copilot
42:06
Просмотров 23 тыс.
Ребенок по калькуляции 😂
00:32
Просмотров 148 тыс.
35C3 -  Open Source Orgelbau
49:37
Просмотров 8 тыс.
Windows Servers Can Expose PowerShell on the Web
18:12
35C3 -  Attacking Chrome IPC
54:13
Просмотров 16 тыс.
35C3 -  Verhalten bei Hausdurchsuchungen
1:01:48
Просмотров 314 тыс.
The Only Unbreakable Law
53:25
Просмотров 333 тыс.
35C3 -  Dissecting Broadcom Bluetooth
43:03
Просмотров 6 тыс.
35C3 -  Repair-Cafés
43:04
Просмотров 10 тыс.
How the Best Hackers Learn Their Craft
42:46
Просмотров 2,6 млн
35C3 -  Safe and Secure Drivers in High-Level Languages
1:01:57