Looking Back On SOHOpelessly Broken at DEF CON 25

DEF CON 22 was my third DEF CON and the first time ever for the IoT Village and related “SOHOpelessly Broken” contests. That year, I easily won both tracks of the competition with only a handful of hours spent analyzing and hacking routers. As anyone who’s ever attended DEF CON can tell you, there are […]… Read More

The post Looking Back On SOHOpelessly Broken at DEF CON 25 appeared first on The State of Security.

Continue reading Looking Back On SOHOpelessly Broken at DEF CON 25

Brainwashing Embedded Systems IoT Hack Lab Update

I’ve been studying the security designs of various embedded devices for the past couple of years. This research has led me to uncover dozens of critical flaws in internet-connected devices ranging from enterprise NAS devices and access points to countless consumer products like wireless routers, home automation controllers, security cameras and more. I even had the […]… Read More

The post Brainwashing Embedded Systems IoT Hack Lab Update appeared first on The State of Security.

Continue reading Brainwashing Embedded Systems IoT Hack Lab Update

VERT Research: A Security Review of Freelance Web Development

Back in June, Robert Hansen posted an interesting write-up[1] on his Smartphone Exec blog about outsourced web development that was returned with multiple embedded PHP backdoors. While this betrayal of trust by a freelance web developer shouldn’t have been surprising, it was, and it prompted Tripwire’s Vulnerability and Exposure Research Team (VERT) to ask: How […]… Read More

The post VERT Research: A Security Review of Freelance Web Development appeared first on The State of Security.

Continue reading VERT Research: A Security Review of Freelance Web Development

Shining Light on The Shadow Brokers

The summer of 2016 was a tumultuous ride for those of us in the security community.  Less than a year ago, nobody had ever heard of The Shadow Brokers or Anna-Senpai but the same month (August 2016), these two as yet unidentified persons or groups made it clear that we are in the midst of […]… Read More

The post Shining Light on The Shadow Brokers appeared first on The State of Security.

Continue reading Shining Light on The Shadow Brokers

The Internet’s Freshest Wounds: My Thoughts On Ticketbleed, Cloudbleed and HTTPS

In April 2014, the security community was shocked with the revelation that a poorly implemented TLS extension in OpenSSL could allow attackers to easily disclose private memory contents from an astonishing number of HTTPS sites. This bug, of course, is CVE-2014-0160 but it is better known by its brand name “Heartbleed.” This bug was cleverly […]… Read More

The post The Internet’s Freshest Wounds: My Thoughts On Ticketbleed, Cloudbleed and HTTPS appeared first on The State of Security.

Continue reading The Internet’s Freshest Wounds: My Thoughts On Ticketbleed, Cloudbleed and HTTPS

No, CVE Details Did Not Just Prove Android Security Stinks!

It’s January again, and as usual, various media outlets are busy reporting on vulnerability statistics from the previous year. As usual, the CVE Details folks have worked up a lot of hype based on CVE counts, and once again, the media has taken the bait with sensational headlines about Google’s Android being the most vulnerable […]… Read More

The post No, CVE Details Did Not Just Prove Android Security Stinks! appeared first on The State of Security.

Continue reading No, CVE Details Did Not Just Prove Android Security Stinks!

Ruckus Raucous: Finding Security Flaws in Enterprise-Class Hardware

Wireless routers designed for consumers often do not employ proper security practices. This topic was extensively covered in VERT’s 2014 report, “SOHO Wireless Router (In)security.” Our research revealed that 74% of the 50 top-selling consumer routers on Amazon shipped with security vulnerabilities, including 20 different models where the latest firmware from the vendor was exploitable. […]… Read More

The post Ruckus Raucous: Finding Security Flaws in Enterprise-Class Hardware appeared first on The State of Security.

Continue reading Ruckus Raucous: Finding Security Flaws in Enterprise-Class Hardware

Five Security Tips to Protect Embedded Devices

Embedded devices on enterprise networks make attractive targets for hackers because they provide potential footholds. These systems perform a variety of functions, often involving sensitive data or control of critical systems. Network gear, printers, storage appliances and other equipment generally do not have end-point protection installed, making them an ideal spot for an attacker to […]… Read More

The post Five Security Tips to Protect Embedded Devices appeared first on The State of Security.

Continue reading Five Security Tips to Protect Embedded Devices

DEF CON 24: Brainwashing Embedded Systems

Come get your hands dirty with embedded device hacks during my DEF CON 24 workshop. Brainwashing Embedded Systems will be held in Las Vegas Ballroom 3 on Saturday, August 10, from 10AM – 2PM. This workshop is a condensed version of the full-day training offered at the 2016 AusCERT and SecTor conferences. During the workshop, […]… Read More

The post DEF CON 24: Brainwashing Embedded Systems appeared first on The State of Security.

Continue reading DEF CON 24: Brainwashing Embedded Systems

My TLS Rant

The Internet as we know it is only possible thanks to cryptography and specifically TLS (formerly known as SSL). Without this crucial technology providing a means for private online communications, e-commerce would quite simply not be a thing, and the Internet would likely be little more than a world-wide party line for sharing bad jokes. […]… Read More

The post My TLS Rant appeared first on The State of Security.

Continue reading My TLS Rant