Security/BlackHat 2012
Black Hat & DEFCON 2012
This is to track organization and attendees for Black Hat and DEFCON 2012 security conferences this coming Summer. Black Hat is at Caesars Palace and DEFCON is at the Rio.
Dates
Black Hat is from July 21 through 26, 2012. DEFCON 20 is from July 26 through 29.
Sessions to be covered
Interesting-sounding Blackhat and DEFCON sessions
- Exploiting the jemalloc Memory Allocator: Owning Firefox's Heap
- Hacking with WebSockets
- Google Native Client - Analysis Of A Secure Browser Plugin Sandbox
- HTML5 Top 10 Threats – Stealth Attacks and Silent Exploits
From dveditz's mail to security-group:
At the top of my list is the one with Owning Firefox in the title. Is there anyone working on jemalloc we could send? The speakers will be releasing debugging utilities at the talk.
Attacks (ab)using recent web features. Need to be considered especially in the context of apps and our web services and what mitigations should be built into Gecko
- "Hacking with WebSockets"
- "HTML5 Top 10 Threats – Stealth Attacks and Silent Exploits"
- "Blended Threats and JavaScript: A Plan for Permanent Network Compromise"
For Gaia/WebAPI folks some attacks on Chrome extensions that may have relevance to types of attacks we face on apps.
For the B2G folks there are a couple that might help us with our phone designs. If nothing else they may inform our testing.
- "Advanced ARM exploitation"
- "Scaling Up Baseband Attacks: More (Unexpected) Attack Surface"
- "Don't Stand So Close To Me: An Analysis of the NFC Attack Surface"
Defeating ASLR through info leaks, and how to cause them.
- "The Info Leak Era on Software Exploitation" (an example of one he wrote up on Flash is http://seclists.org/bugtraq/2012/Apr/63 )
A comparison of three different Flash sandboxes, Chrome, IE, and Firefox
New defensive features of Win8 we should consider using. Some may be compiler/linker features that will help on other versions of windows, too.
For the privacy geeks -- decloaking "private browsing" among other ways to track people.
A wildcard... Math.random() isn't crytographically secure, could we be vulnerable to anything like these PHP issues? If you go bring your open mind and wear your brainstorming hat.
dinners/meetups
Tuesday Night Dinner Sign Up
8:30 PM ??
- Joe Stevensen
- Eric Parker
- Guillaume Destuynder
- Gary Kwong
- Adam Muntner
- Ben Kero
- Brian Hourigan
Wed Night Dinner Sign Up
8:30 PM ??
- Joe Stevensen
- Michael Herny :tinfoil
- Gary Kwong
- Ben Kero
- Brian Hourigan
Thurs Night Dinner Sign Up
8:30 PM ??
- Joe Stevensen
- Gary Kwong
- Ben Kero
- Brian Hourigan
Friday Night Dinner Sign Up
8:30 PM ??
- Joe Stevensen
- Gary Kwong
- Ben Kero
- Brian Hourigan
Sat Night Dinner Sign Up
8:30 PM ??
- Joe Stevensen
- Gary Kwong
- Ben Kero
- Brian Hourigan
Attendees
Enter your name below if you plan on attending one or both conferences.
Name | Black Hat? | DEFCON? | Arrival Date | Departure Date |
---|---|---|---|---|
Al Billings | Yes | Yes | ? | ? |
Raymond Forbes | Yes | Yes | 2012-07-24 | 2012-07-30 |
Joe Stevensen | Yes | Yes | 2012-07-24 | 2012-07-29 |
Gary Kwong | Yes | Yes | 2012-07-24 | 2012-07-29 |
Guillaume Destuynder | Yes | Yes | 2012-07-24 | 2012-07-29 |
Jorge Villalobos | Yes | Yes | 2012-07-24 | 2012-07-29 |
Adam Muntner | Yes | Yes | 2012-07-24 | 2012-07-29 |
Michael Henry :tinfoil | No | Yes | 2012-07-24 | 2012-07-30 |
Jesse Ruderman | Yes | Yes | ? | ? |
Anthony Hughes | Yes | Yes | 2012-07-24 | 2012-07-30 |
John Morrison :jrgm | Yes | No | 2012-07-24 | ? |
Kevin Brosnan :kbrosnan | Yes | Yes | 2012-07-24 | 2012-07-29 |
Ben Kero :bkero | Yes | Yes | 2012-07-24 | 2012-07-29 |
Brian Hourigan :digi | Yes | Yes | 2012-07-24 | 2012-07-29 |
Conference registration numbers for attendees
hotel reservation confirmations
Flight planning
Name | Outbound Flight | Return Flight | Notes |
---|---|---|---|
Joe Stevensen | VX906 Arrives 7/24 14:55 | VX905 Departs 7/29 11:00 | |
Guillaume Destuynder | VX906 Arrives 7/24 14:55 | VX905 Departs 7/29 11:00 | |
Kevin Brosnan | VX906 Arrives 7/24 14:55 | VX901 Departs 7/29 09:20 | |
Al Billings | VX260 Arrives 7/24 13:35 | VX915 Departs 7/29 17:30 | |
Jorge Villalobos | UA1608 Arrives 7/24 22:01 | UA1254 Departs 07/29 01:16 | |
Ben Kero | AS620 Arrives 7/24 20:06 | AS621 Departs 7/29 20:50 | |