34C3 - Are all BSDs created equally?

  Рет қаралды 8,637

media.ccc.de

media.ccc.de

Күн бұрын

media.ccc.de/v...
A survey of BSD kernel vulnerabilities.
In this presentation I start off asking the question „How come there are only a handful of BSD security kernel bugs advisories released every year?“ and then proceed to try and look at some data from several sources.
It should come as no surprise that those sources are fairly limited and somewhat outdated.
The presentation then moves on to try and collect some data ourselves. This is done by actively investigating and auditing. Code review, fuzzing, runtime testing on all 3 major BSD distributions [NetBSD/OpenBSD/FreeBSD]. This is done by first investigating what would be good places where the bugs might be. Once determined, a detailed review is performed of these places. Samples and demos will be shown.
I end the presentation with some results and conclusions. I will list what the outcome was in terms of bugs found, and who - based on the data I now have - among the three main BSD distributions can be seen as the clear winner and loser. I will go into detail about the code quality observed and give some pointers on how to improve some code. Lastly I will try and answer the question I set out to answer („How come there are only a handful of BSD security kernel bugs advisories released every year?“).
Ilja van Sprundel
fahrplan.event...

Пікірлер
34C3 -  Decoding Contactless (Card) Payments
58:19
media.ccc.de
Рет қаралды 10 М.
36C3 -  A systematic evaluation of OpenBSD's mitigations
53:02
media.ccc.de
Рет қаралды 15 М.
Кто круче, как думаешь?
00:44
МЯТНАЯ ФАНТА
Рет қаралды 4,9 МЛН
ТЫ В ДЕТСТВЕ КОГДА ВЫПАЛ ЗУБ😂#shorts
00:59
BATEK_OFFICIAL
Рет қаралды 4 МЛН
Can You Find Hulk's True Love? Real vs Fake Girlfriend Challenge | Roblox 3D
00:24
34C3 -  Deep Learning Blindspots
53:48
media.ccc.de
Рет қаралды 8 М.
34C3 -  Microarchitectural Attacks on Trusted Execution Environments
55:02
34C3 -  BBSs and early Internet access in the 1990ies
1:01:42
media.ccc.de
Рет қаралды 10 М.
34C3 -  LatticeHacks
1:05:56
media.ccc.de
Рет қаралды 6 М.
FreeBSD Kernel Internals, Dr. Marshall Kirk McKusick
59:57
bsdconferences
Рет қаралды 90 М.
🚀  TDD, Where Did It All Go Wrong (Ian Cooper)
1:03:55
DevTernity Conference
Рет қаралды 567 М.
Langner's Stuxnet Deep Dive
1:03:38
S4 Events
Рет қаралды 83 М.
Creator of git, Linus Torvalds Presents the Fundamentals of git
1:10:15
Developers Alliance
Рет қаралды 144 М.
Кто круче, как думаешь?
00:44
МЯТНАЯ ФАНТА
Рет қаралды 4,9 МЛН