Sponsored White Papers, Webcasts, and Downloads
ZDNet Resources
- Black Hat recap podcast: SSL, SMS, BIOS rootkits
- Black Hat recap podcast: SSL, SMS, BIOS rootkitsVirushttp://www.youtube.com/watch?v=O6_4hBhJGoAVeriSign Responds to Black HatTim Callan, vice president of product marketing at VeriSign, responds to these Black Hat presentations in his new SSL blogpost:https://blogs.verisign.com/ssl-blog/2009/07/busy_day_at_black_hat.phpHe fills some of the holes that these researchers dug.Also, VeriSign issued a press pelease confirming that all SSL and...
- Tags: SSL/TLS, Authentication/Encryption, Rootkits, Podcasts, Network security, Text messaging/SMS/MMS, SECURITY, Black Hat, SSL, VeriSign Inc., rootkit, SMS, BIOS, podcast
- Discussion threads 2009-08-03
- Black Hat recap podcast: SSL, SMS, BIOS rootkits
- In this podcast, I chat with Threatpost.com co-editor Dennis Fisher about the big news coming out of the Black Hat security conference. We discuss the attacks using SMS and MMS, rootkits in keyboards and BIOSes, vulnerabilities in SSL and the response from vendors to these problems. Listen here [mp3]. by...
- Tags: Black Hat, SSL, SMS, Rootkits, BIOS, Text Messaging/SMS/MMS, Podcasts, Ssl/Tls, Authentication/Encryption, Telephony, Cellular Phones, Network Security, Security, Spyware, Adware & Malware, Hardware, Components, Consumer Electronics, Personal Technology, Online Communications, Internet, Networking, Ryan Naraine
- Blog posts 2009-08-03
- Researchers exploit SSL and domain flaws
- Researchers exploit SSL and domain flawsI read in an article earlier that read Dan Kaminsky's website hacked.It was an interesting read earlier this morning, 5 A.M. July 29, 2009 3:13 PM PDTSecurity experts' sites hacked on eve of Black Hat conferenceby Elinor Millshttp://news.cnet.com/8301-27080_3-10299126-245.htmlVeriSign Responds to Black HatTim Callan, vice president...
- Tags: SSL/TLS, Authentication/Encryption, Network security, SECURITY, domain flaw, SSL, Black Hat
- Discussion threads 2009-07-30
- SecurityBSides 'unconference' takes on Las Vegas during Black Hat, Defcon
- SecurityBSides is a free, two-day event made up of 65 attendees, 15 presenters, and six organizers. by Jennifer Leggio
- Tags: Black Hat, SecurityBSides, Jennifer Leggio
- Blog posts 2009-07-22
- Sub-Prime PKI: Attacking Extended Validation SSL
- One of the attributes that the paper discusses is the type of SSL certificate presented by a web server when negotiating a secure connection. Modern web browsers support both Domain Validated DV and Extended Validation EV SSL certificates. EV SSL certificates were created to combat phishing and other web based...
- Tags: Black Hat, Web, SSL, Ssl/Tls, Authentication/Encryption, PKI, Web Site Development, Network Security, Channel Management, Phishing, Security, Internet, Networking, Marketing, Spam And Phishing
- White papers 2009-07-01
- Rob Carter at the Movenpick (Black Hat Europe 2008)
- Rob Carter at the Movenpick (Black Hat Europe 2008)I would love to go to one!!This is one of the most exclusive events in IT. Hackers - black hat, white hat and red hats everywhere? Has anyone here been to one?RE: Rob Carter at the Movenpick (Black Hat Europe 2008)Of course...
- Tags: Movenpick, Black Hat Europe 2008, Rob Carter, Black Hat
- Discussion threads 2008-12-04
- Intel ships BIOS fix for Rutkowska's Black Hat flaw
- Intel ships BIOS fix for Rutkowska's Black Hat flawDoes it affect Windows98?Does this affect Windows98? I'm running a 3.1 MySQL server in my DMZ on Windows98 and I hope it won't be affected by this. My Gram-mummy uses an SSH tunnel through the TOR Onion router network to get to...
- Tags: OPEN SOURCE, Databases, Intel Corp., MySQL, Gram-mummy, Windows98, Black Hat, BIOS
- Discussion threads 2008-08-27
- Intel ships BIOS fix for Rutkowska's Black Hat flaw
- Intel has shipped a BIOS update with a fix for a privilege escalation vulnerability that was used by rootkit researcher Joanna Rutkowska to bluepill the Xen hypervisor. The vulnerability was discussed by Rutkowska at the Black Hat briefings earlier this month but details on the exploit were...
- Tags: Black Hat, Hypervisor, Motherboard, BIOS Update, Intel Corp., Flaw, System Management Mode, Level Privilege, BIOS, Virtualization, Hardware, Components, Ryan Naraine
- Blog posts 2008-08-27
- The ugly truth: Satan, social networks and security
- Here's the simplest way to get arbitrary code execution in the browsers of millions of users -- ask for permission. by Jennifer Leggio
- Tags: Social Networking, Black Hat, Network, App, MySpace, SocNets, SocNet, Security, Jennifer Leggio
- Blog posts 2008-08-25
- Alarmed about Vista security? Black Hat researcher Alexander Sotirov speaks out
- Alarmed about Vista security? Black Hat researcher Alexander Sotirov speaks outNicely doneI appreciate that you took the time to speak with the researcher who actually discovered the flaws.There are a couple of bloggers on ZDNET who always seem slant their "blogs" with grandiose claims against one platform or technology.I think...
- Tags: Microsoft Windows Vista (Longhorn), Blogging, Black Hat, Microsoft Windows Vista, Alexander Sotirov, Microsoft Corp., security
- Discussion threads 2008-08-11
- Alarmed about Vista security? Black Hat researcher Alexander Sotirov speaks out
- Earlier today I published a lengthy blog post questioning some of the sensationalist conclusions raised in press coverage of a paper presented by Alexander Sotirov and Mark Dowd at last week’s Black Hat Conference in Las Vegas. This afternoon, I received an e-mail from Sotirov, who says he was "horrified...
- Tags: Technique, Black Hat, Microsoft Windows XP, Vulnerability, Microsoft Windows Vista, Microsoft Corp., Web Browser, Exploitation, Microsoft Windows Vista (Longhorn), Web Browsers, Security, Operating Systems, Microsoft Windows, Software, Internet, Ed Bott
- Blog posts 2008-08-11
- Windows security rendered useless? Uh, not exactly
- Oh dear. The Chicken Little contingent is out in full force. Break out your Kevlar helmets, everyone, because the sky is falling on Windows! At last week’s Black Hat conference in Las Vegas, researchers Alexander Sotirov and Mark Dowd presented a paper that outlined some new attack vectors they had...
- Tags: Black Hat, Attacker, Windows Security, Vulnerability, Microsoft Windows Vista, Defense, Memory Protection, Vulnerability Disclosure, Microsoft Windows, Microsoft Windows Vista (Longhorn), Security, Operating Systems, Software, Ed Bott
- Blog posts 2008-08-11
- Black Hat Las Vegas Day 2
- Black Hat Las Vegas Day 2Dowd and SotirovYou mention Dowd and Sotirov's talk in passing. I'm intensely curious to read your take on their presentation when you get an opportunity to review their stuff. Is it on your blogging agenda?GreatSounds like lots of fun. Nice update. Don't know how you...
- Tags: Blogging, Sotirov, Dowd, Black Hat
- Discussion threads 2008-08-09
- Black Hat Las Vegas Day 2
- Again, sorry for the late updates. Vegas is the kind of place that demands a lot of a person. Too many parties make it difficult to find time to blog on the conference. Pictures of the even are a bit sparse, due to consistently forgetting to bring my camera, but...
- Tags: black hat, microsoft corp., applet, image, vegas, nathan mcfeters
- Blog posts 2008-08-09
- Black Hat Las Vegas Day 1
- Black Hat Las Vegas Day 1Way to go Nate, Billy, and Rob.Congrats on the Pwnie, I read about it at Dark reading, but haven't actually read your current blog yet.That bit with Kaminsky was...odd. Booing? Really?edit: Now that I've read your blog, I've got to say that I really like...
- Tags: Blogging, Black Hat
- Discussion threads 2008-08-08
- Black Hat Las Vegas Day 1
- Well, this is well late, but here's my recap of Black Hat Day 1. Sorry for the delay, but I've been terribly busy finishing up preparations for my Day 2 talk. The first talk I went to see, "Pointers and Handles, A Story of Unchecked Assumptions...
- Tags: Billy Rios, Black Hat, Cyberthreats, Nathan McFeters, Phishing, Security, Spam, Spam And Phishing, Viruses And Worms
- Blog posts 2008-08-08
- On GIFARs
- Ever since Rob McMillan of IDG published a story giving a preview of our coming Black Hat talk, specifically a preview of the portion of our talk related to GIFARs, media coverage of the research has swirled a bit out of control and there's been some misconceptions. My co-presenter John...
- Tags: Black Hat, Vector, Applet, Image, Attack, Heasman, Nathan McFeters
- Blog posts 2008-08-02
- Black Hat Sneak Preview
- Rob McMillan from IDG interviewed John Heasman and I today about the presentation we will be delivering with Rob Carter at Black Hat Vegas next week. The article has a good teaser about one of the more interesting of the many attacks we will cover, namely what we've coined...
- Tags: Black Hat, Java Applet, Web Application, Web Browser, Applet, Attack, GIFAR, Java, Programming Languages, Security, Software Development, Software/Web Development, Nathan McFeters
- Blog posts 2008-08-01
- Black Hat talk on Apple encryption flaw pulled
- Black Hat talk on Apple encryption flaw pulledCan something be common and interesting too?[i]I find it interesting that Apple is more than happy to let its own employee, Alex Ionescu, discuss flaws in the Microsoft Windows Kernel, but not willing to allow another researcher to talk about Apple.[/i]Apple double standards...
- Tags: Apple Inc., encryption flaw, Black Hat
- Discussion threads 2008-07-31
- Black Hat talk on Apple encryption flaw pulled
- Brian Krebs from the Washington Post "Security Fix" Blog reported that one of the talks slated for next week's Black Hat convention on a previously undiscovered flaw in Apple's FileVault encryption system has been canceled, the researcher citing confidentiality agreements as the reason he will not be speaking. ...
- Tags: Black Hat, Researcher, Apple Inc., Flaw, Security, Nathan McFeters
- Blog posts 2008-07-31
White Papers and Webcasts