«
Expand/Collapse
94 items tagged "security authors"
Related tags:
slides [+],
paper [+],
asia [+],
keynote [+],
tobias matt fiddler [+],
petkov [+],
marc weber tobias [+],
marc weber [+],
joe grand [+],
client side [+],
security [+],
windows [+],
computer [+],
application [+],
vista [+],
security network [+],
rod beckstrom [+],
jennifer granick [+],
bruce schneier [+],
access [+],
web application security [+],
web [+],
wade polk [+],
vpls [+],
understanding [+],
tobias bluzmanis [+],
things that go bump in the night [+],
tags [+],
paul malkewicz [+],
network [+],
mpls [+],
legal [+],
kiosk [+],
jaroslav novak [+],
introduction [+],
industrial [+],
hardware hacking [+],
fischbach [+],
electronic access control [+],
de haas [+],
cyber security [+],
computer security [+],
bump [+],
Hardware [+],
zusman [+],
zach lanier [+],
x event [+],
wireless radio [+],
voip [+],
vipin kumar [+],
tracy ann kosa [+],
software radio [+],
security vulnerability [+],
rich internet [+],
ria world [+],
radio [+],
privacy event [+],
privacy [+],
physical security [+],
osx [+],
old [+],
nitin kumar vipin kumar tags [+],
nicolas fischbach [+],
new [+],
mobile application [+],
mike zusman [+],
mike rothman [+],
michael weiss [+],
michael ossmann [+],
mac os x [+],
mac os [+],
line [+],
law [+],
kosa [+],
justine osborne tags [+],
iphone [+],
hat europe [+],
fundamentals [+],
europe [+],
enno rey tags [+],
desktop security [+],
dan kaminsky [+],
charles edge [+],
chaos communication camp [+],
blurring [+],
bill pennington [+],
alex stamos [+],
Software [+],
black hat [+],
usa [+],
wireless lan security [+],
winny [+],
wilco [+],
warszawa [+],
video windows [+],
video kiosk [+],
video client [+],
vboot [+],
van ginkel [+],
truths [+],
toolkits [+],
three truths [+],
takayuki sugiura [+],
symbian [+],
survey result [+],
survey [+],
stephen dugan [+],
sql [+],
sms security [+],
smartphones [+],
smart card security [+],
smart [+],
server [+],
seris [+],
security 2002 [+],
security 2001 [+],
sap [+],
sandro [+],
rich smith [+],
rich [+],
rfid [+],
rey tags [+],
relationship [+],
psychology [+],
programming mistake [+],
power [+],
poor [+],
pocket [+],
physical [+],
phone security [+],
phone [+],
paul sebastian ziegler [+],
paul sebastian [+],
p security [+],
overview [+],
osi [+],
oracle database server [+],
oracle [+],
night [+],
network security [+],
network flows [+],
mulitlevel [+],
ms sql server [+],
mobile [+],
mind control devices [+],
michael d. glasser [+],
marcus sachs [+],
marc witteman [+],
mandy andress [+],
malaysia [+],
mac osx [+],
layer [+],
lan security [+],
krakow [+],
kevin spett [+],
kevin cardwell [+],
kernel mode [+],
k security [+],
jon oberheide [+],
jesper johansson [+],
jeremiah grossman [+],
java event [+],
java decompilation [+],
java [+],
jacob appelbaum [+],
involuntary [+],
invisible [+],
internet [+],
hack in the box [+],
government systems [+],
government [+],
global [+],
glasser [+],
gauci [+],
flows [+],
fail [+],
edward farrell tags [+],
edward farrell [+],
dugan [+],
discovering [+],
development [+],
decompilation [+],
death [+],
david litchfield [+],
database security [+],
database [+],
damian finol [+],
cyber [+],
culture [+],
computing security [+],
computing [+],
cisco security [+],
cisco event [+],
chris nickerson [+],
chinese security [+],
challenge [+],
cesar cerrudo [+],
carrier [+],
cardwell [+],
card [+],
botnet [+],
black [+],
billy hoffman [+],
bill pennington jeremiah grossman [+],
bill pennington dennis groves [+],
backbone [+],
approach [+],
anthony lai [+],
all in [+],
ajax [+],
advanced [+],
abap [+],
Wireless [+],
Programming [+],
video [+],
authors [+],
security event [+],
audio [+]
-
-
21:34
»
SecDocs
Authors:
Ilja van Sprundel Tags:
secure development iPhone Event:
Chaos Communication Camp 2011 Abstract: Over the last few years there has been a signifant amount of iPhone and iPad application development going on. Although based on Mac OSX, its development APIs are new and very specific to the iPhone and iPad. In this presentation, Ilja van Sprundel, Principal Security Consultant at IOActive, will discuss lessons learned from auditing iPhone and iPad applications over the last year. It will cover the use of specific APIs, why some of them aren't granular enough, and why they might expose way too much attack surface. The talk will cover ssl, xml, url handling, UIWebViews and more. Furthermore, it will also cover what apps are allowed to do when inside their sandbox once an application has been hacked.
-
21:34
»
SecDocs
Authors:
Ilja van Sprundel Tags:
secure development iPhone Event:
Chaos Communication Camp 2011 Abstract: Over the last few years there has been a signifant amount of iPhone and iPad application development going on. Although based on Mac OSX, its development APIs are new and very specific to the iPhone and iPad. In this presentation, Ilja van Sprundel, Principal Security Consultant at IOActive, will discuss lessons learned from auditing iPhone and iPad applications over the last year. It will cover the use of specific APIs, why some of them aren't granular enough, and why they might expose way too much attack surface. The talk will cover ssl, xml, url handling, UIWebViews and more. Furthermore, it will also cover what apps are allowed to do when inside their sandbox once an application has been hacked.
-
-
21:40
»
SecDocs
-
21:40
»
SecDocs
-
21:40
»
SecDocs
-
-
21:51
»
SecDocs
-
21:51
»
SecDocs
-
21:51
»
SecDocs
-
6:41
»
SecDocs
-
-
21:31
»
SecDocs
-
-
21:49
»
SecDocs
-
4:11
»
SecDocs
-
-
21:46
»
SecDocs
-
-
10:02
»
SecDocs
-
-
21:34
»
SecDocs
-
-
21:28
»
SecDocs
-
21:28
»
SecDocs
-
-
21:53
»
SecDocs
-
-
21:42
»
SecDocs
-
-
6:46
»
SecDocs
-
-
21:25
»
SecDocs
-
21:25
»
SecDocs
-
-
2:28
»
SecDocs
-
2:27
»
SecDocs
-
2:26
»
SecDocs
-
-
21:48
»
SecDocs
-
-
21:30
»
SecDocs
-
-
21:44
»
SecDocs
-
-
21:47
»
SecDocs
-
-
21:25
»
SecDocs
-
-
21:25
»
SecDocs
-
-
21:29
»
SecDocs
-
-
22:44
»
SecDocs
-
-
22:46
»
SecDocs
-
-
22:48
»
SecDocs
-
-
22:54
»
SecDocs
-
10:53
»
SecDocs
-
-
3:30
»
SecDocs
-
-
0:46
»
SecDocs
-
-
0:58
»
SecDocs
-
-
1:01
»
SecDocs
-
-
2:15
»
SecDocs
-
-
2:15
»
SecDocs
-
-
1:48
»
SecDocs
-
-
5:14
»
SecDocs
-
-
10:02
»
SecDocs
Authors:
Ertunga Arsal Tags:
SAP ABAP Event:
Hashdays 2010 Abstract: ABAP is the programming language used for developing ERP applications on SAP® systems. The ABAP stack runs similar to “kernel mode” and it has access to most critical components. Any programming mistake can have disastrous effects. Whether for adding another “root” (SAP_ALL) user to the system or for stealing password hashes, it on the shopping list of most SAP hackers. Our talk focuses on insecure ABAP code, how to exploit it and how to prevent future mistakes.
-
-
3:35
»
SecDocs
-
-
13:36
»
SecDocs
-
13:08
»
SecDocs
-
-
11:01
»
SecDocs
-
-
22:25
»
SecDocs
-
22:25
»
SecDocs
-
22:25
»
SecDocs
-
-
21:25
»
SecDocs
-
-
21:25
»
SecDocs
Authors:
Edward Farrell Tags:
RFID Event:
Ruxcon 2010 Abstract: RFID technology is the new cool. It’s the access pass around our neck, the overpriced contactless train ticket that goes “ping” and the payment card that doesn’t bother with two factor authentication. Even with issues with the underlying architecture, the majority of implementations out there haven’t quite thought things through (like getting rid of manufacturers keys and locking down the read/write access). We’re going to melt back the noooiiiice looking plastic on RFIDs and see what’s inside before the government starts using them as mind control devices.
-
-
11:11
»
SecDocs
-
10:46
»
SecDocs
-
-
15:22
»
SecDocs
-
14:50
»
SecDocs
-
-
12:35
»
SecDocs
-
11:40
»
SecDocs
-
-
7:45
»
SecDocs
-
7:44
»
SecDocs
-
4:10
»
SecDocs
-
4:05
»
SecDocs
-
-
6:36
»
SecDocs
-
6:35
»
SecDocs
-
-
1:45
»
SecDocs
-
-
21:10
»
SecDocs
-
21:10
»
SecDocs
-
21:10
»
SecDocs
-
-
21:09
»
SecDocs
-
21:09
»
SecDocs
-
-
21:11
»
SecDocs
-
13:49
»
SecDocs
-
13:49
»
SecDocs
-
-
21:03
»
SecDocs
-
21:03
»
SecDocs
-
-
0:58
»
SecDocs
-
0:58
»
SecDocs
-
0:58
»
SecDocs
-
-
21:02
»
SecDocs
-
-
21:00
»
SecDocs
-
-
21:01
»
SecDocs
-
-
21:16
»
SecDocs
-
-
21:16
»
SecDocs
-
-
21:15
»
SecDocs
-
-
21:15
»
SecDocs
-
-
21:09
»
SecDocs
-
21:09
»
SecDocs
-
21:09
»
SecDocs
-
10:45
»
SecDocs
-
10:45
»
SecDocs
-
10:45
»
SecDocs