DEF CON 30 - Sam Quinn, Steve Povolny - Perimeter Breached Hacking an Access Control System

  Рет қаралды 31,937

DEFCONConference

DEFCONConference

Күн бұрын

The first critical component to any attack is an entry point. As we lock down firewalls and routers, it can be easy to overlook the network-connected physical access control systems. A study done by IBM in 2021 showed that the average cost of a physical security compromise is $3.54 million and takes an average of 223 days to identify a breach.
HID Mercury is a global distributor of access control systems with more than 20 OEM partners, deployed across multiple industries and certified for use in federal and state government facilities.
Trellix's Advanced Threat Research team uncovered 4 unique 0-day vulnerabilities and 4 additional undisclosed vulnerabilities leading to remote, unauthenticated code execution on multiple HID Mercury access control panels. These findings lead to full system control including the ability for an attacker to remotely manipulate door locks. During this presentation, we will briefly cover the hardware debugging process, leading to a root shell on the target. We will explore in greater depth the vulnerability discovery techniques, including emulation, fuzzing, static and dynamic reverse engineering, and a detailed walkthrough of several of the most critical vulnerabilities. We’ll address our approach to exploitation using simplistic malware we designed to control system functionality and culminate the talk with a live demo featuring full system control, unlocking doors remotely without triggering any software notification

Пікірлер: 30
@boira817
@boira817 Жыл бұрын
When will all defcon 30 videos be uploaded? Wanted to attend this year to defcon but I couldn't go😢
@ocsanik502
@ocsanik502 Жыл бұрын
^^^^
@DJNuckChorris
@DJNuckChorris Жыл бұрын
Where are the slides?
@katiehesse6578
@katiehesse6578 Жыл бұрын
In the video? they show up later in the vid, as a file? on the defcon ftp server
@DJNuckChorris
@DJNuckChorris Жыл бұрын
@@katiehesse6578 I’m dumb. Thank you lol
@silverhawkroman
@silverhawkroman Жыл бұрын
More importantly, where's Ye?
@cedricvillani8502
@cedricvillani8502 Жыл бұрын
Once inside said installation, guess what? The electronics are not even wired the same. And I mean down to the electron flow(a broad use of the term, but for this crowd it’s perfect) anyway a card reader? Really, AiOT? Ya ok, don’t mix up government with Corp gov. Lol oh the slides they used to post on there website.
@fvdstone
@fvdstone Жыл бұрын
First few minutes... Like every conference video... Where are the slides?
@laalbujhakkar
@laalbujhakkar Жыл бұрын
we all know Sam did all the work.
@poetac15
@poetac15 Жыл бұрын
Thx for posting
@Gameboygenius
@Gameboygenius Жыл бұрын
So buggy you might mistake it for a CTF. 😅
@MorningStarChrist
@MorningStarChrist Жыл бұрын
bravo
@ianirungu2129
@ianirungu2129 Жыл бұрын
where are the slides
@willyv374
@willyv374 Жыл бұрын
Noice
@p0ln
@p0ln Жыл бұрын
Did someone say 'Death Con 3'0
@yepyep7101
@yepyep7101 Жыл бұрын
Oy vey
@doublepositivezero8329
@doublepositivezero8329 Жыл бұрын
The fact that that implies direct service line and uses lube and 5th element
@doublepositivezero8329
@doublepositivezero8329 Жыл бұрын
He's welcome to take his compromised state elsewhere
@doublepositivezero8329
@doublepositivezero8329 Жыл бұрын
📃🗣️" "
@user-gm4og2cu1r
@user-gm4og2cu1r Жыл бұрын
What?
@user-cv9nh8ru2q
@user-cv9nh8ru2q Жыл бұрын
🥰🥰😍Tob 33100
@alanhoff89
@alanhoff89 Жыл бұрын
Dude wearing a mask, lol
@jeffreyhall9703
@jeffreyhall9703 Жыл бұрын
I liked him too haha. I'm guessing it was a podium hijacking attack? Or was that an actual presentation that was wrapping up?
@GabrielM01
@GabrielM01 Жыл бұрын
he scared of getting a small flu
@humbllbug
@humbllbug Жыл бұрын
Yahshua - you know Him as Jesus - was born to a virgin, turned water to wine, taught, healed the sick, raised the dead, casted out demons, walked on water, calmed the storm, and fed a crowd of thousands with a few fish and a few loaves of bread, among many other things. He was killed on the cross as payment for the sins of all mankind, three days later He rose from the dead. Forty days later He ascended into heaven where He sits at the right hand of the Father. He is returning very soon, but before He does, Satan, the devil, is coming to pretend to be Jesus/God (2 Thessalonians 2:1-4). Satan is an angel, and he will have certain supernatural powers with which to try to fool everyone. He will, for example, be able to make fire come down from heaven in the sight of men. He will only be on earth a short time before the real King of Kings, Jesus Christ, God in the flesh, returns. When the real Jesus comes we will all be transformed into our spiritual bodies at the same moment. Jesus came in the flesh to offer forgiveness of sins and eternal life to anyone who believes and calls on His precious name! if thou shalt confess with thy mouth the Lord Jesus, and shalt believe in thine heart that God hath raised him from the dead, thou shalt be saved. - Romans 10:9 Now when Jesus was in Bethany, in the house of Simon the leper, There came unto him a woman having an alabaster box of very precious ointment, and poured it on his head, as he sat at meat. But when his disciples saw it, they had indignation, saying, To what purpose is this waste? For this ointment might have been sold for much, and given to the poor. When Jesus understood it, he said unto them, Why trouble ye the woman? for she hath wrought a good work upon me. For ye have the poor always with you; but me ye have not always. For in that she hath poured this ointment on my body, she did it for my burial. Verily I say unto you, Wheresoever this gospel shall be preached in the whole world, there shall also this, that this woman hath done, be told for a memorial of her. - Matthew 26:6-13 Seek ye the LORD while he may be found, call ye upon him while he is near: Let the wicked forsake his way, and the unrighteous man his thoughts: and let him return unto the LORD, and he will have mercy upon him; and to our God, for he will abundantly pardon. . ... To anoint your self, the sick, or a building for spiritual protection: Get a small bottle of olive oil and pour off a small amount into a smaller vessel like a vial or baby food jar. Use the rest of the bottle for cooking. Ask the Lord to bless your vial of oil in Jesus name. Anoint yourself with the oil by placing a dab of oil on tip of finger and touch it to your forehead, and ask the Lord to bless you/heal you. Place a dab of oil on your finger and anoint the door posts and order all negativity and evil out of the house, and order that nothing negative or evil can enter into your home including piggybacking on a person entering, order it to be so in the name of Jesus. Anoint all potential entrances to your home. To anoint the sick, place oil on tip of finger and touch it to the head of the sick and say a prayer of healing over them in Jesus name. See James Chapter 5:14-15...........
@GusMichaelisnotreal
@GusMichaelisnotreal Жыл бұрын
TL:DR and no one cares. Pick a better work of fiction to quote next time that book sucks and is badly translated.
@LakeVermilionDreams
@LakeVermilionDreams Жыл бұрын
Cool story, bro
Perimeter Breached! Hacking an Access Control System
34:45
Black Hat
Рет қаралды 1,3 М.
Cute Barbie Gadget 🥰 #gadgets
01:00
FLIP FLOP Hacks
Рет қаралды 33 МЛН
Would you like a delicious big mooncake? #shorts#Mooncake #China #Chinesefood
00:30
ПАРАЗИТОВ МНОГО, НО ОН ОДИН!❤❤❤
01:00
Chapitosiki
Рет қаралды 2,5 МЛН
Reducing Risk From Chrome Zero-Day Vulnerabilities
2:21
Aiden Technologies, Inc.
Рет қаралды 3
How a DNS Server (Domain Name System) works.
6:05
PowerCert Animated Videos
Рет қаралды 4,8 МЛН
DEF CON 31 War Stories - Living Next Door to Russia - Mikko Hypponen
47:46
DEF CON 31 - Terminally Owned - 60 Years of Escaping - David Leadbeater
47:34
How to bypass many Mifare classic based door access systems
9:55
Quentyn Taylor
Рет қаралды 53 М.
cool watercooled mobile phone radiator #tech #cooler #ytfeed
0:14
Stark Edition
Рет қаралды 7 МЛН
Apple watch hidden camera
0:34
_vector_
Рет қаралды 53 МЛН
ПК с Авито за 3000р
0:58
ЖЕЛЕЗНЫЙ КОРОЛЬ
Рет қаралды 1,7 МЛН
Очень странные дела PS 4 Pro
1:00
ТЕХНОБЛОГ ГУБАРЕВ СЕРГЕЙ
Рет қаралды 275 М.
С Какой Высоты Разобьётся NOKIA3310 ?!😳
0:43
POCO F6 PRO - ЛУЧШИЙ POCO НА ДАННЫЙ МОМЕНТ!
18:51