Listen "On The BlackPage: Timing"
Episode Synopsis
.See the link below for more details, descriptions and commentary.
On The BlackPage: Timing by Dominique Brezinski
It is that time again: Black Hat in the hot LV summer. It always comes sooner than I expect. We have been working like mad to get the schedule together, which is basically done. One of the underlying themes this year is timing. I don't pick these things; it is really a reflection of the direction of research in our community. Another theme is nuance.
Timing attacks are not new. They have been part of the cryptanalyst's side-channel tool set for some time. In the last few years something caused researchers to start applying it beyond cryptographic operations. Maybe it was Boneh's remote timing attack against OpenSSL in 2003. I don't know. Whatever the reason, a number of researchers have started delivering results using timing as an attack vector. My prediction is that we are going to see a lot of things fall over based on timing attacks.
The research community's understanding of program control flow and its data dependencies is ever increasing. We are at a point where any user-supplied data in the address space should be suspect, because researchers are finding very subtle ways to direct program flow to user-supplied data. In many cases the vulnerabilities are based on unforeseen synchronicity and what were once minor programming mistakes.
A few of the presentations in the Zero Day Attack track highlight the themes of timing and nuance: "Understanding the Heap by Breaking It" by Justin Ferguson, "Timing Attacks for Recovering Private Entries From Database Engines" by Ariel Waissbein and Damian Saura and "Dangling Pointer" by Jonathan Afek. Also, Haroon Meer and Marco Slaviero will be presenting the aptly named "It's All About The Timing." I am excited to see what these guys pull out of the hat.
Link: https://blackhat.com/html/bh-blackpage/bh-blackpage-06132007.html
More episodes of the podcast Black Hat Announcements
Black Hat USA 2010 Training: Assaulting IPS
09/03/2010
Free Black Hat March Webcast - Pen Testing the Web with Firefox by Michael Schearer ("theprez98")
04/03/2010
Black Hat USA 2010 Registration Now Open!
03/03/2010
Feb 18 Webcast
11/02/2010
Black Hat DC Keynote
21/01/2010
ZARZA We are Zarza, the prestigious firm behind major projects in information technology.