April 24th, 2014

BlackHat 2010 Recap

Here are some of the interesting things that I encountered this year at BlackHat. These are mostly talks that I went to, but there are a few things that I just happened to run across in the course of the conference. Overall it was a good conference and similar to last year. One improvement was that we were able to get our Defcon badges at BlackHat after waiting in a huge line instead of a really really huge line at Defcon. :)

  • I had seen a talk and other information about BitBlaze before, but I mainly went to this talk to see security rockstar Charlie Miller. It ended up being a pretty interesting talk, and covered some of the ways that BitBlaze can help automate binary analysis. Among a lot of other things it has some neat features that allow you to do taint tracking and determine which registers are tainted from controlled input. There was also a white-paper released that has lots of details and examples.
  • I saw an interesting talk about a new routing protocol infrastructure attack tool called Loki. It’s written in python (yea), and covers many packet generation and attack modules for Layer 3 protocols, including BGP, LDP, OSPF, VRRP and quite a few others. It takes some previously released tools, adds some new functionality and wraps it in a nice GUI. It has some functional similarities to yersinia, but covers some protocols
    that it doesn’t. The live demos were pretty convincing.

  • javasnoop is an neat looking new tool for tampering and interacting with the internals of java applications, including function hooking/tracing, debugging and instruction overwriting, etc. He made a good point in his talk that Java is easy to decompile (jad), but if you need to interact with the software after that, re-building the software is often prohibitive.
  • rejava — This came up in the course of the above presentation, and it looks pretty neat as well. It’s another Java decompiler, but this one allows you to interact directly with the byte code, rather than just getting static code dumps.
  • psudp — I didn’t see this talk, but the tool sounds interesting. It is a tool for passive network-wide covert communication and covert file exfiltration. The basic gist, it seems, is that it encodes data into unused DNS fields. Source and slides are available.
  • Taviso Ormandy and Julien Tinnes talk on kernel exploits was pretty mind-blowing. They walked through several very technical kernel exploits that they’ve worked on in recent history. It’s amazing that these guys have such a firm grasp on kernels in multiple operating systems.
  • virt-ice — This was an interesting talk about a virtualization based malware analysis tool. I was slightly more interested before I found out that the tool wasn’t going to be released any time soon though.
  • libscizzle — Library for quickly detecting shellcode in a large binary stream.

I was originally going to create just one BlackHat/Defcon post, but it took longer than expected, so I’ll be breaking it into two posts with the Defcon content tomorrow (maybe).

28 Responses to 'BlackHat 2010 Recap'

  1. 1Week 31 in Review – 2010 | Infosec Events
    August 9th, 2010 at 1:54 am

    [...] BlackHat 2010 Recap – midnightresearch.com Overall it was a good conference and similar to last year. [...]

  2. 2nigerian movies videos
    April 27th, 2012 at 9:53 pm

    Needed to create you the bit of note to help thank you so much as before on your wonderful suggestions you’ve shared in this case. It was really surprisingly open-handed of people like you giving openly all a lot of folks could have sold for an ebook to make some profit for their own end, especially since you could possibly have tried it if you ever wanted. The points as well served to become easy way to understand that the rest have the identical fervor like my personal own to see a good deal more when it comes to this issue. I’m certain there are numerous more pleasant moments in the future for those who look into your blog.

  3. 3Bodybuilding Ernährung Female Bodybuilding Trainingspläne Muskelaufbau
    September 16th, 2012 at 3:58 am

    Psychological focal point, training, likability, aspect, calm but rely on. Even so these are some of the items Tang Soo Use, your current Mandarin chinese style created by self defense, can show we and additionally instilling inside your soul the power not only to fight you and your family about the craft the quite initial hazards signs in conflict altogether. Bodybuilding Tipps und Ernährung helfen beim Masseaufbau, Energie aufzubauen, Körpermuskulatur zu stärken. Bodybuilding Ernährung stärkt Ihre Körpermuskulatur, wie Bauchmuskeln, Rückenmuskeln, Brustmuskeln, Beinmuskeln und alle weiteren. Innovative Nahrungsergänzung, Phaseolin, Diät Produkte, Fettblocker zur Unterstützung einer bewußten Ernährung – und kostenlose Bodybuilding Trainingspläne. Bodybuilding-Sportnahrung.com bietet ein umfassendes Sortiment an Fitness und Bodybuilding Produkten zur Unterstützung von Muskelaufbau und Diät. Durch gezieltes Bodybuilding bzw.Muskelaufbau kann die Fitness jedoch wieder hergestellt werden.
    Muskelaufbau Ernährung Eine Zusätzliche Muskelaufbau Ernährung ist für den wettbewerbsorientierten Bodybuilder nicht nur praktisch, sondern auch notwenig. für den professionellen Bodybuilder ist das keine reine Geschmacksfürage, denn durch eine günstige Muskelaufbau Ernährung soll Zusätzliches Körperfett vermieden werden. Arginin, wie Glutamin, Lysin oder Ornithin um bei Bodybuilder den Muskelaufbau zu unterstützen. BCAA sind essentielle Aminosäuren die den Muskel bei Anstrengung schützen und maßgeblich bei dem Muskelaufbau unterstützen. Besonders für den Hardgainer ist der Cytosport Cytogainer geeignet, da dieser viele und hochwertige Kalorien für den Muskelaufbau zuführen muss.
    Bodybuilding nimmt sich Muskelaufbau zum Ziel. Bodybuilding-Sportnahrung.com bietet ein umfassendes Sortiment an Fitness und Bodybuilding Produkten zur Unterstützung von Muskelaufbau und Diät. Durch gezieltes Bodybuilding bzw.Muskelaufbau kann die Fitness jedoch wieder hergestellt werden. Powerstar Kreasteron ist die erste All-in-One Kreatin Muskelaufbau Formel für Bodybuilding und Fitness. Gerade Bodybuilding Anfänger sind oft überfordert, wenn es um die richtige Trainingsplanung geht, um schnell Muskelaufbau zu erreichen .
    Das kann daran liegen, dass sich der Muskeln an die immer gleiche Belastung gewöhnt haben. Die Muskeln werden nach dem Krafttraining schnellstmöglich regeneriert. Die Muskeln werden dank EFX Kre Alkalyn hart plus intensiver. Protein ist der Bestandteil im Körper für Muskeln und Gewebe. Denn diese Muskelaufbau übungen sprechen gleichzeitig mehrere Muskeln an und sorgen damit für eine höhere Ausschättung an Wachstumshormonen als Isolationsübungen. Bodybuilding Training Ernährung Bodybuilding Muskelaufbau Trainingsplan

  4. 4שולחן מחשב
    September 18th, 2012 at 2:13 am

    היי הידעתם? ריהוט משרדי הינו כולל כסא משרדי וכסא מחשב וכסאות משרדיים

  5. 5Perswazja
    November 9th, 2012 at 9:17 am

    Hello, i think that i saw you visited my blog thus i came to ?return the favor?.I am trying to find things to enhance my website!I suppose its ok to use a few of your ideas!!

  6. 6tommy andersson
    December 18th, 2012 at 5:33 am

    I’ve read a few good stuff here. Definitely price bookmarking for revisiting. I wonder how so much effort you place to create the sort of fantastic informative site.

  7. 7bakersdelight
    February 4th, 2013 at 9:52 pm

    Very nice article. I certainly appreciate this website. Keep it up!

  8. 8charlie harper print
    April 13th, 2013 at 6:29 pm

    This is a great resource to learn about Charlie Harper prints.

  9. 9New Era Caps
    April 18th, 2013 at 3:11 am

    I have been absent for some time, but now I remember why I used to love this web site. Thanks, I’ll try and check back more often. How frequently you update your site?

  10. 10stock market abbreviations for general electric
    May 19th, 2013 at 1:11 am

    Conversely, many inauspicious things happen on the.
    Consequently, it goes to show you that even if you assume someone who sounds like they know what they are doing;
    they don’t always perform the way they talk. You can make any number of point and figure charts in a day ‘ and you can keep
    the point and figure charts of the previous days and assess the fluctuations in the market prices through analysis of the charts.

  11. 11Jurata pokoje
    June 12th, 2013 at 2:33 am

    The next time I learn a blog, I hope that it doesnt disappoint me as much as this one. I imply, I know it was my option to learn, however I really thought youd have one thing fascinating to say. All I hear is a bunch of whining about something that you might repair in the event you werent too busy looking for attention.

  12. 12blue submariner rolex
    July 4th, 2013 at 12:41 am

    The manufacturers of Rolex watches know that their latest watches are being replicated and to keep aloof from forfeiture of walk of life they make subtle and comminuted changes to their file of watches. This is a cat and mouse game and as soon as changes are made in the primitive, a few down the extended mark, they are incorporated in the swiss duplicate watches as well. So what does one stand to over outlay|gain} if they are purchasing swiss duplicate watches? For one the pecuniary savings is open. Apart from that there is the peace of inner man too. If someone is mugged and their primitive swiss outlook is burgled, they have a lot to think about. Not so for those who have swiss duplicate watches on them. They can bare go out and buy another swiss duplicate watches the next day.

  13. 13top article
    July 17th, 2013 at 11:42 pm

    continuously i used to read smaller posts
    that also clear their motive, and that is also happening with this post which I am reading here.

  14. 14??????????????????? | E Starting Point
    July 29th, 2013 at 10:34 am

    [...] ????????????? [...]

  15. 15Louis Vuitton Damier Azur Canvas Handbag
    October 18th, 2013 at 9:22 am

    Great goods from you, man. I have understand your stuff previous to and you are just
    extremely magnificent. I really like what you’ve acquired here,
    certainly like what you’re stating and the way in which you say it.

    You make it enjoyable and you still care for to keep it smart.
    I can’t wait to read far more from you. This is actually a
    tremendous web site.

  16. 16site
    October 29th, 2013 at 8:15 am

    I rarely drop remarks, but i did solme searching and wound up here Midnight Resesrch
    Labs – BlackHat 2010 Recap. And I do havee a couple of questions for
    you if you usually do nnot mind. Is it simply me or does it look liike a few of the remarks
    look as if they aree written by brain dead individuals? :-P And, if you are posting at additional online sites, I would
    like to keep up with everything new yoou have to post. Could you list of all of all
    your shared sites like yur linkedin profile, Facebook page or twitter feed?

  17. 17wow gold
    November 8th, 2013 at 10:05 am

    I do consider all of the ideas you have presented on your post.
    They’re really convincing and can certainly work. Nonetheless,
    the posts are very short for newbies. Could you please extend them a bit from next time?
    Thanks for the post.

  18. 18chaturbate token
    December 6th, 2013 at 1:29 pm

    A person necessarily assist to make critically posts I might
    state. That is the very first time I frequented your web page and so far?
    I amazed with the research youu made to create tuis actual submit incredible.

    Excellent activity!

  19. 19Minuscule La vallee des fourmis perdues 2014 Telecharger
    January 19th, 2014 at 3:01 pm

    We are a group of volunteers and starting a new scheme
    in our community. Your web site offered us with valuable info to work
    on. You have done an impressive job and our entire community will be thankful to you.

  20. 20moncler oulet online
    March 1st, 2014 at 3:21 am

    Conversely, many inauspicious things happen on the.
    Consequently, it goes to show you that even if you assume someone who sounds like they know what they are doing;

  21. 21bubble witch saga Cheats
    March 8th, 2014 at 1:40 am

    I all the time used to study paragraph in news papers
    but now as I am a user of web therefore from now I am using net for content, thanks
    to web.

  22. 22xtmmo
    March 15th, 2014 at 11:43 pm

    Buy cheap wow gold from xtmmo.net, more cheap & safe.

  23. 23Buy ESO power leveling
    March 20th, 2014 at 11:36 pm

    The Elder Scrolls Online occurs in Tamriel. However, there is not anniversary arena that can be visited currently. Every area needs to be added as the time passes.

  24. 24http://societyofdawgs.com
    March 28th, 2014 at 3:51 pm

    NDS lovers and gamers can go one step further that can use them for browsing pictures and
    reading e-books on their Nintendo DS or Nintendo DS Lite.
    The Kids of each Koopa have slipped the magical batons each and every king, as
    well as made them animals. This will mean no loss to you if you are dissatisfied with the
    package you chose.

  25. 25LeBron 11 Miami Nights
    March 28th, 2014 at 6:27 pm

    Long distance is not easy Rogers has a 2011 conviction for felony burglary and is not allowed to have a firearmBought a nice @ unit at the @JThe rival companies include market leader WPP,Interpublic Group, which isthe fourth-biggest, and Japan’s DentsuIn a statement, Eurocopter said: “An accident investigation team from Eurocopter is on its way to Scotland to assist the UK Air Accident Investigation Branch and the BFU (German AAIB) in its efforts to investigate the cause of the accident The Muja

  26. 26chanel makeup bag
    April 4th, 2014 at 7:56 pm

    chanel Handbags Argentina
    Amazing! This blog looks just like my old one! It’s on
    a entirely different topic but it has pretty much the same page layout
    and design. Superb choice of colors!

  27. 27nike free run 2 dame norge
    April 6th, 2014 at 6:46 pm

    Todd Molé Left to right: Tig Notaro, Natasha Leggero, Moshe KasherWant to hear “Weird Al” Yankovic describe the ’80s in gasps and animal noises? Ever wonder if Sarah Silverman would grow out her pubic hair — if the love of her life asked her to?So does comedian Natasha Leggero, and she’s not afraid to ask. On her new web faux talk show, Tubbin’ With Tash, Leggerro’s gold-spangled, coke-snorting alter ego interviews comedy celebs about whatever the hell she feels like … in a hot tub.In ad

  28. 28Nike LeBron Socks
    April 21st, 2014 at 6:16 pm

    The stock left Ay on 11 December and we sank a few bottles in Cape Town on New Years Eve and the shipment was by sea to minimize our carbon footprints Col Georgs comments come as no surprise as he has stemware to shift and flutes are far more robust than those signature sommelier balloon glasses bigger than your head that are his fragile flagship Related:Dan Elliott, Associated Press Thursday, May 23, 2013 DENVER (AP) Democratic Gov? Wrapped coquettishly in banana leaves, they lisp our aim is to

Leave a Response

Imhotep theme designed by Chris Lin. Proudly powered by Wordpress.
XHTML | CSS | RSS | Comments RSS