35C3 - In Soviet Russia Smart Card Hacks You

  Рет қаралды 8,914

media.ccc.de

media.ccc.de

Күн бұрын

media.ccc.de/v...
The classic spy movie hacking sequence: The spy inserts a magic smart card provided by the agency technicians into the enemy's computer, … the screen unlocks … What we all laughed about is possible!
Smartcards are secure and trustworthy. This is the idea smart card driver developers have in mind when developing drivers and smart card software. The work presented in this talk not only challenges, but crushes this assumption by attacking drivers using malicious smart cards.
We will present a fuzzing framework for *nix and Windows along with some interesting bugs found by auditing and fuzzing smart card drivers and middleware. Among them classic stack and heap buffer overflows, double frees, but also a replay attack against smart card authentication.
Since smart cards are used in the authentication process, a lot of vulnerabilities can be triggered by an unauthenticated user, in code running with high privileges. During the author's research, bugs were discovered in OpenSC (EPass, PIV, OpenPGP, CAC, Cryptoflex …), YubiKey drivers, pam_p11, pam_pkc11, Apple's smartcard-services and others.
Eric Sesterhenn
fahrplan.event...

Пікірлер
35C3 -  Viva la Vita Vida
56:37
media.ccc.de
Рет қаралды 17 М.
35C3 -  Smart Home - Smart Hack
51:22
media.ccc.de
Рет қаралды 197 М.
Cheerleader Transformation That Left Everyone Speechless! #shorts
00:27
Fabiosa Best Lifehacks
Рет қаралды 14 МЛН
If people acted like cats 🙀😹 LeoNata family #shorts
00:22
LeoNata Family
Рет қаралды 43 МЛН
35C3 -  Safe and Secure Drivers in High-Level Languages
1:01:57
media.ccc.de
Рет қаралды 7 М.
35C3 -  Die verborgene Seite des Mobilfunks
1:00:45
media.ccc.de
Рет қаралды 396 М.
35C3 -  Attacking Chrome IPC
54:13
media.ccc.de
Рет қаралды 17 М.
35C3 -  Dissecting Broadcom Bluetooth
43:03
media.ccc.de
Рет қаралды 6 М.
35C3 -  Archäologische Studien im Datenmüll
41:32
media.ccc.de
Рет қаралды 133 М.
Karl-Heinz Niemann | PROFINET Security - aktueller Stand und nächste Schritte
31:56
35C3 -  Sneaking In Network Security
1:00:53
media.ccc.de
Рет қаралды 11 М.
aoc 2024 04 elisp solution reconstruction
41:25
Kalman Reti
Рет қаралды 43
35C3 -  Repair-Cafés
43:04
media.ccc.de
Рет қаралды 10 М.