34C3 - Are all BSDs created equally?

  Рет қаралды 8,595

media.ccc.de

media.ccc.de

6 жыл бұрын

media.ccc.de/v...
A survey of BSD kernel vulnerabilities.
In this presentation I start off asking the question „How come there are only a handful of BSD security kernel bugs advisories released every year?“ and then proceed to try and look at some data from several sources.
It should come as no surprise that those sources are fairly limited and somewhat outdated.
The presentation then moves on to try and collect some data ourselves. This is done by actively investigating and auditing. Code review, fuzzing, runtime testing on all 3 major BSD distributions [NetBSD/OpenBSD/FreeBSD]. This is done by first investigating what would be good places where the bugs might be. Once determined, a detailed review is performed of these places. Samples and demos will be shown.
I end the presentation with some results and conclusions. I will list what the outcome was in terms of bugs found, and who - based on the data I now have - among the three main BSD distributions can be seen as the clear winner and loser. I will go into detail about the code quality observed and give some pointers on how to improve some code. Lastly I will try and answer the question I set out to answer („How come there are only a handful of BSD security kernel bugs advisories released every year?“).
Ilja van Sprundel
fahrplan.event...

Пікірлер
36C3 -  A systematic evaluation of OpenBSD's mitigations
53:02
media.ccc.de
Рет қаралды 15 М.
34C3 -  Public FPGA based DMA Attacking
31:27
media.ccc.de
Рет қаралды 10 М.
Крутой фокус + секрет! #shorts
00:10
Роман Magic
Рет қаралды 22 МЛН
ОТОМСТИЛ МАМЕ ЗА ЧИПСЫ🤯#shorts
00:44
INNA SERG
Рет қаралды 4,7 МЛН
when you have plan B 😂
00:11
Andrey Grechka
Рет қаралды 67 МЛН
34C3 -  BBSs and early Internet access in the 1990ies
1:01:42
media.ccc.de
Рет қаралды 10 М.
34C3 -  Reverse engineering FPGAs
42:09
media.ccc.de
Рет қаралды 11 М.
34C3 -  Microarchitectural Attacks on Trusted Execution Environments
55:02
The Tragedy of systemd
47:18
linux.conf.au
Рет қаралды 1,1 МЛН
34C3 -  Decoding Contactless (Card) Payments
58:19
media.ccc.de
Рет қаралды 10 М.
OpenBSD Attack Mitigations - Alexander Bluhm - EuroBSDcon 2023
51:54
34C3 -  Type confusion: discovery, abuse, and protection
56:39
media.ccc.de
Рет қаралды 4,8 М.
34C3 -  LatticeHacks
1:05:56
media.ccc.de
Рет қаралды 6 М.
34C3 -  MQA - A clever stealth DRM-Trojan
1:00:32
media.ccc.de
Рет қаралды 17 М.
How the Best Hackers Learn Their Craft
42:46
RSA Conference
Рет қаралды 2,6 МЛН