Hacking Articles Tips Tricks Videos Tutorials
470 subscribers
66K photos
15 videos
157 files
132K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
Media is too big
VIEW IN TELEGRAM
Black Hat (Youtube)
Multiple Bugs in Multi-Party Computation: Breaking Cryptocurrency's Strongest Wallets

Cryptocurrency wallets in exchange platforms or banks require strong security because they protect vast amounts of money. Some solutions rely on advanced cryptographic methods that distribute trust across multiple parties, in the spirit of Shamir's secret-sharing. These include multi-party computation (MPC) and threshold signature schemes (TSS), which are a special case of MPC to sign data in a distributed, yet trustless manner. TSS has notably been tested and deployed in major organizations where secret key generation and digital signing are needed. But these techniques, although powerful and "magic" on paper, can prove fragile in practice, as this talk will show.

By Omer Shlomovits and Jean-Philippe Aumasson
Full Abstract & Presentation Materials: https://www.blackhat.com/us-20/briefings/schedule/#multiple-bugs-in-multi-party-computation-breaking-cryptocurrencys-strongest-wallets-19763
Hacking Articles Tips Tricks Videos Tutorials
Photo
Black Hat (Youtube)
You have No Idea Who Sent that Email: 18 Attacks on Email Sender Authentication


Our study demonstrates an unfortunate fact that even a conscientious security professional using a state-of-the-art email provider service like Gmail cannot with confidence readily determine, when receiving an email, whether it is forged.

We identified 18 types of attacks to bypass email sender authentication (including SPF, DKIM, and DMARC). Leveraging those techniques, an attacker can impersonate arbitrary senders without breaking authentication and even forge DKIM-signed emails with a legitimate site's signature. We evaluated our attacks against 10 popular email providers (e.g., Gmail.com, iCloud.com) and 19 email clients (e.g., Outlook, Thunderbird), and found all of them proved vulnerable to various attacks. We reported our findings to the affected vendors, who rewarded our report and are actively addressing them.

By Jianjun Chen, Vern Paxson, and Jian Jiang

Full Abstract & Presentation Materials: https://www.blackhat.com/us-20/briefings/schedule/#you-have-no-idea-who-sent-that-email--attacks-on-email-sender-authentication-19902
Media is too big
VIEW IN TELEGRAM
Black Hat (Youtube)
How I Created My Clone Using AI - Next-Gen Social Engineering

This talk is inspired by an episode of Black Mirror. I will be demonstrating a live demo creating a bot who talks like me and can be used to impersonate me online and do social engineering. I will be showing a live demo of how to a create such bots over text, voice or video and walk through various techniques which the attendees can use to create such smart social engineering attacks.

By Tamaghna Basu

Full Abstract & Presentation Materials: https://www.blackhat.com/us-20/briefings/schedule/#how-i-created-my-clone-using-ai---next-gen-social-engineering-19802
Media is too big
VIEW IN TELEGRAM
Black Hat (Youtube)
Discovering Hidden Properties to Attack the Node.js Ecosystem

We present a novel attack method against the Node.js platform, called hidden property abusing (HPA). The new attack leverages the widely used data exchanging feature of JavaScript to tamper critical program states of Node.js programs, like server-side applications.

By Feng Xiao, Jianwei Huang, Yichang Xiong, Guangliang Yang, Hong Hu, Guofei Gu, Wenke Lee

Full Abstract & Presentation Materials: https://www.blackhat.com/us-20/briefings/schedule/#discovering-hidden-properties-to-attack-the-nodejs-ecosystem-19594
Hacking Articles Tips Tricks Videos Tutorials
Photo
Black Hat (Youtube)
Repurposing Neural Networks to Generate Synthetic Media for Information Operations


Using open source pre-trained natural language processing, computer vision, and speech recognition neural networks, we demonstrate the relative ease with which fine tuning in the text, image, and audio domains can be adopted for generative impersonation. We quantify the effort involved in generating credible synthetic media, along with the challenges that time- and resource-limited investigators face in detecting generations produced by fine-tuned models. We wargame out these capabilities in the context of social media-driven information operations, and assess the challenges underlying detection, attribution, and response in scenarios where actors can anonymously generate and distribute credible fake content. Our resulting analysis suggests meaningful paths forward for a future where synthetically generated media increasingly looks, speaks, and writes like us.

By Philip Tully

Full Abstract & Presentation Materials: https://www.blackhat.com/us-20/briefings/schedule/#repurposing-neural-networks-to-generate-synthetic-media-for-information-operations-19529
Hacking Articles Tips Tricks Videos Tutorials
Photo
Black Hat (Youtube)
Spectra: Breaking Separation Between Wireless Chips


Nowadays wireless technologies are increasingly sharing spectrum. This is the case for Wi-Fi and Bluetooth, but also some LTE bands and harmonics. Operating on the same frequency means that these different technologies need to coordinate wireless spectrum access to avoid collisions. Especially for nearby sources, as it is the case for multiple chips within one smartphone, so-called coexistence is the key to high-performance spectrum sharing.

By Jiska Classen and Francesco Gringoli

Full Abstract & Presentation Materials: https://www.blackhat.com/us-20/briefings/schedule/#spectra-breaking-separation-between-wireless-chips-20005
Hacking Articles Tips Tricks Videos Tutorials
Photo
Black Hat (Youtube)
iOS Kernel PAC, One Year Later


In February 2019, I reported to Apple five ways to bypass kernel Pointer Authentication on the iPhone XS . My impression was that the design, while a dramatic improvement on the ARMv8.3 standard, had some fundamental issues when defending kernel control flow against attackers with kernel memory access. This talk will look at how PAC has (and hasn't) improved in the subsequent year, once again concluding with five new ways to bypass kernel PAC to obtain arbitrary kernel code execution on iOS 13.3.

By Brandon Azad
Full Abstract & Presentation Materials: https://www.blackhat.com/us-20/briefings/schedule/#ios-kernel-pac-one-year-later-19726
Media is too big
VIEW IN TELEGRAM
Black Hat (Youtube)
A Decade After Stuxnet's Printer Vulnerability: Printing is Still the Stairway to Heaven

In 2010, Stuxnet, the most powerful malware in the world revealed itself, causing physical damage to Iranian nuclear enrichment centrifuges. In order to reach Iran's centrifuges, it exploited a vulnerability in the Windows Print Spooler service to gain code execution as NT AUTHORITY\SYSTEM. Due to the hype around this critical vulnerability, we (and probably everyone else) were pretty sure that this attack surface would no longer exist a decade later. We were wrong…

By Peleg Hadar and Tomer Bar

Full Abstract & Presentation Materials: https://www.blackhat.com/us-20/briefings/schedule/#a-decade-after-stuxnets-printer-vulnerability-printing-is-still-the-stairway-to-heaven-19685