Threat Level: green Handler on Duty: Johannes Ullrich

SANS ISC: SANS Daily Network Security Podcast (Stormcast) for Monday, June 12th 2017 - SANS Internet Storm Center SANS Daily Network Security Podcast (Stormcast) for Monday, June 12th 2017


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

SAMBA Vuln. Exploited;

SANS Daily Network Security Podcast (Stormcast) for Monday, June 12th 2017
00:00

My Next Class

Intrusion Detection In-DepthSan AntonioMay 28th - Jun 2nd 2019
Defending Web Applications Security EssentialsMunichJul 1st - Jul 6th 2019

… more classes

Spotify spotify logo

Discussion

For an interesting overview of the unique attack surface presented by Wifi SOCs in general / Broadcom chips in particular as well as a detailed walk through of an interesting vulnerability and how it was used to get code execution on the application processor, check out some recent work by Google Project Zero:

Part 1
https://googleprojectzero.blogspot.com/2017/04/over-air-exploiting-broadcoms-wi-fi_4.html

Part 2
https://googleprojectzero.blogspot.com/2017/04/over-air-exploiting-broadcoms-wi-fi_11.html

As smart phone operating systems present more and more difficult targets to attackers, expect attackers to start looking into other system components as a way in: Cellular baseband, Wifi, bluetooth, NFC, etc. These things are made by third parties and often there is very little known about them, so you can guess that security is not going to be as good. They are ripe grounds for new vulnerabilities and they will only become more attractive to attackers.
Posted by Anonymous on Mon Jun 12 2017, 16:50

New Discussions closed for all Podcasts older than two(2) weeks
Please send your comments to our Contact Form

Intrusion Detection In-DepthSan AntonioMay 28th - Jun 2nd 2019
Defending Web Applications Security EssentialsMunichJul 1st - Jul 6th 2019
Intrusion Detection In-DepthLondonJul 8th - Jul 13th 2019
Intrusion Detection In-DepthBostonJul 29th - Aug 3rd 2019
Defending Web Applications Security EssentialsSan JoseAug 12th - Aug 17th 2019
Defending Web Applications Security EssentialsArlingtonAug 14th - Aug 19th 2019
Defending Web Applications Security EssentialsBrusselsSep 2nd - Sep 7th 2019
Intrusion Detection In-DepthLondonSep 23rd - Sep 28th 2019
Intrusion Detection In-DepthChicagoOct 9th - Oct 14th 2019
Defending Web Applications Security EssentialsSan FranciscoDec 2nd - Dec 7th 2019