1:45PM
to 3:00PM

Hristo Bojinov, Elie Bursztein & Dan Boneh: Embedded Management Interfaces

event::type Random
: Augustus Ballroom 5-6
About: Over the last few years, the number of devices that embed user-friendly management interfaces accessible from the network has drastically increased. These interfaces can be found on almost every kind of device, from lights-out management systems for PCs, to small SOHO NAS appliances, to photo frames.
In this talk, we will cover the attack surface of embedded management interfaces and pinpoint which parts of them are the most likely to be vulnerable, based on our evaluation of more than a dozen device models from different categories. In particular, we will review known yet underestimated implementation shortcuts that lead to vulnerabilities. To illustrate each shortcut, we will describe real-world vulnerabilities that we have found and exploited in devices from Intel, Linksys, Lacie, Samsung, and Dell among others.

: Hristo Bojinov, Dan Boneh, Elie Bursztein
event::url http://www.blackhat.com/html/bh-usa-09/bh-usa-09-speakers.html#Bojinov

 


 

event::comment

 



footer::loading