Sadly, BlackHat 2012 US and DefCon20 refused this short/fast/lightning talk.
Here are the slides for “Harvesting and Collecting Voice Conference Bridges, Passwords, Pins, Access, Codes”.
Here is the CFP submission:
Code:
---------------------------------- | |
Detailed Outline | |
---------------------------------- | |
| |
In this talk, I will try to present: | |
- what are voice bridges (though, I bet everyone used voice conferencing at least once in their lifetime) | |
- various pieces and techniques of the voice bridges harvesting and processing puzzle | |
- what are the possible tools and how to make use of various tools at hand | |
- various ideas on how to (partially) automate all of this for a fast, semi-automated and distributed intelligence gathering | |
| |
I will try to summarize with a few hints which can perhaps make life more secure | |
| |
---------------------------------- | |
Abstract | |
---------------------------------- | |
| |
Voice conferencing is a core platform making enterprises more efficient and driving them forward. | |
Voice conferencing is usually outsource to 3rd party providers and can be implemented/managed in-house. | |
| |
No matter how it's being implemented, the security of the data exchanged over the conference lines represents a concern for the enterprises. This is why security PINs are being used. | |
| |
However, the importance of these security details (like conference ID and conference PIN) is not very well understood and this is one can find these kind of details floating around - on the web, in details of shared/open calendars of Exchange/AD, etc. |
Enjoy!
Securely yours,
Andrei
Xerox started to roll out fixes for some of my security advisories (ACSA).
So, here we go:
XRX12-003 v1.1
Jumping ahead, Secunia confirmed that from their point of view the “HP JetDirect Download Manager” is not backdoored/infected. Nevertheless, I’m posting the details for the interested ones.
My suspicions lied within this functionality:
Code:
"Model found in backdoor file!" | |
"FirmwareFileManager::ReadFirmwareBackDoorFile" | |
"FirmwareFileManager::ReadBackDoorfile" |
Download slides:
Have open my New Year with myself closing Google Hall of Fame October-December 2011 (I guess it was the last entry of 2011, since I submitted during last days of December)
More details about why I ended up there will follow, hopefully at one of the next conference talks.
Stay tuned. Stay secure.
:: Next Page >>
A deep dive into brain's curiosities
| Next >
| Sun | Mon | Tue | Wed | Thu | Fri | Sat |
|---|---|---|---|---|---|---|
| << < | > >> | |||||
| 1 | 2 | 3 | 4 | |||
| 5 | 6 | 7 | 8 | 9 | 10 | 11 |
| 12 | 13 | 14 | 15 | 16 | 17 | 18 |
| 19 | 20 | 21 | 22 | 23 | 24 | 25 |
| 26 | 27 | 28 | 29 | 30 | 31 | |