We're sorry but this page doesn't work properly without JavaScript enabled. Please enable it to continue.
Feedback

IoT Village - "Mixing industrial protocols with web applications flaws in order to exploit devices in the internet"

00:00

Formal Metadata

Title
IoT Village - "Mixing industrial protocols with web applications flaws in order to exploit devices in the internet"
Alternative Title
Mixing industrial protocols with web application security
Title of Series
Number of Parts
335
Author
License
CC Attribution 3.0 Unported:
You are free to use, adapt and copy, distribute and transmit the work or content in adapted or unchanged form for any legal purpose as long as the work is attributed to the author in the manner specified by the author or licensor.
Identifiers
Publisher
Release Date
Language

Content Metadata

Subject Area
Genre
Abstract
In this talk i'm going to explain in detail a new technique to achieve javascript code persistence in web applications from devices using the Bacnet protocol (building automation) in the underlying device protocol/web app arquitecture. A remote attacker is able to inject javascript code in the Bacnet device abusing the read/write properties from the Bacnet protocol itself, the code is going to be stored in the Bacnet database helping the attacker to achieve persistence in the victim browser, we are talking about devices that operates in building enviroments or industrial facilities , the posibility to jump from that point to another point in the industrial network using this particular vector is really high.
Communications protocolIndependence (probability theory)Information securityCommunications protocolWeb applicationOrder (biology)Mixed realityInternetworkingComputer animationMeeting/Interview
Communications protocolInformation securityComputer networkConnected spaceInternetworkingTheoryExploit (computer security)Vector spaceFundamental theorem of algebraSoftware testingLatent heatServer (computing)Service (economics)InjektivitätBroadcasting (networking)Web browserCodeScripting languageUDP <Protokoll>Revision controlPerspective (visual)Presentation of a groupVertex (graph theory)Integrated development environmentSoftwareFirewall (computing)Search engine (computing)Remote procedure callVector spaceInformation securityExploit (computer security)Web applicationMultiplication signSoftwareNetwork topologyCodeCommunications protocolFundamental theorem of algebraNeuroinformatikResultantInjektivitätService (economics)InternetworkingVirtual machineImplementationOrder (biology)Web browserScripting languageTrailAuthenticationLatent heatTheoryRouter (computing)Port scannerWeb 2.0Ocean currentData conversionServer (computing)Integrated development environmentSoftware testingCase moddingFirewall (computing)WeightTouch typingProcess (computing)DigitizingPresentation of a groupDecimalLink (knot theory)Information technology consultingConfiguration spaceReading (process)Set (mathematics)Game controllerBitComputer animation
Programmable read-only memoryOSI modelInternetworkingOpen setUDP <Protokoll>Complex (psychology)Mechanism designInformation securityCyclic redundancy checkData integrityData structureFunction (mathematics)Link (knot theory)Virtual realityControl flowData typeExecution unitComputer networkCommunications protocolRevision controlEmailRepresentation (politics)BuildingPrice indexAnwendungsschichtParameter (computer programming)Computer wormWikiWritingAxiom of choiceObject (grammar)Uniqueness quantificationCategory of beingString (computer science)Data modelWorld Wide Web ConsortiumEmailoutputCASE <Informatik>Special unitary groupClient (computing)Web applicationGame controllerInternetworkingResolvent formalismWordLatent heatFormal languageLengthCategory of beingRevision controlIdentifiabilityBitLink (knot theory)Configuration spaceObject (grammar)Information securityCartesian coordinate systemWeightString (computer science)Data structureCommunications protocolAxiom of choiceMathematicsProfil (magazine)INTEGRALSoftwareTelecommunicationOrder (biology)NumberSharewareInformationFirewall (computing)Execution unitUniform resource locatorType theoryRight anglePairwise comparisonService (economics)Combinational logicFunctional (mathematics)Mechanism designFunction (mathematics)Query languageHash functionDependent and independent variablesWikiRepresentation (politics)Graph coloringEndliche ModelltheoriePoint (geometry)HexagonReading (process)ResultantUnicastingverfahrenVirtualizationMilitary baseLocal ringWeb 2.0Network socketComplex (psychology)IntegerComputer animation
SharewareScripting languageFunctional (mathematics)SoftwareOrder (biology)WordObject (grammar)Revision controlComputer animation
DataflowTelecommunicationIdentifiabilityInternetworkingInformationObject (grammar)Computer animation
Uniform resource locatorObject (grammar)SoftwareCartesian coordinate systemRevision controlDescriptive statisticsInformationIdentifiabilityEndliche ModelltheorieResultantCommunications protocolProcess (computing)Scripting languageTelecommunicationFunction (mathematics)Web applicationFigurate numberComputer animation
Scripting languageHeegaard splittingCodeConnected spaceRight angleDependent and independent variablesNetwork socketOrder (biology)Single-precision floating-point formatPlanningCommunications protocolComputer animation
Dependent and independent variablesTelecommunicationLatent heatMathematical analysisData structureTheoryString (computer science)CodeWeb browserDependent and independent variablesPoint (geometry)Object (grammar)IdentifiabilityNumberOrder (biology)TelecommunicationComputer animation
Data structureTheoryCodeString (computer science)Web browserObject (grammar)Category of beingCommunications protocolWeb applicationData structureUniform resource locatorPhysical systemJava appletCodeCommunications protocolInternetworkingCategory of beingObject (grammar)Multiplication signCartesian coordinate systemTheoryOrder (biology)IdentifiabilityString (computer science)Computer animation
Workstation <Musikinstrument>outputInternetworkingSource codePasswordReal numberCartesian coordinate systemMereologyOpen sourceComputer animation
NumberPetri netPredicate (grammar)Source codeWeb pageLine (geometry)Uniform resource locatorSharewareOrder (biology)Client (computing)Computer animation
Module (mathematics)TelecommunicationSource codeMusical ensembleUniform resource locatorCommunications protocolInjektivitätWeb applicationWordInformation securityVector spaceOrder (biology)CodeComputer animation
Module (mathematics)SharewareCodeExploit (computer security)Web browserComputer wormScripting languageData structureString (computer science)Open sourceCommunications protocolPasswordCartesian coordinate systemControl flowExploit (computer security)String (computer science)Multiplication signWeightGoodness of fitCodeCross-site scriptingWeb applicationCommunications protocolSingle-precision floating-point formatTheoryData structureComputer wormSource codeUniform resource locatorScripting languageResultantWritingOpen setOpen sourceFront and back endsSharewareComputer animation
SharewareModule (mathematics)VideoconferencingSharewareUniform resource locatorComputer animation
CodeSource codeUniform resource locatorComputer wormInformationMathematicsDescriptive statisticsComputer animation
SoftwareEmailComputer wormCartesian coordinate systemHexagonExploit (computer security)Web applicationComputer animation
Spectrum (functional analysis)Computer wormDataflowWeb 2.0CodeScripting languageComputer animation
Module (mathematics)SharewareLeakServer (computing)Web applicationCodeCartesian coordinate systemMultiplication signLeakServer (computing)Computer animation
Server (computing)LeakOpcodeCommunications protocolComputer wormNumberElectric currentConvex hullNumberVulnerability (computing)Profil (magazine)Web applicationCommunications protocolRoutingLeakLatent heatoutputServer (computing)Web 2.0Cartesian coordinate systemTrailObject (grammar)Ocean currentDescriptive statisticsInjektivitätConfiguration spaceOperator (mathematics)Musical ensembleTouch typingMoving averageComputer wormFlow separationLengthMereologyEmailComputer animation
Router (computing)TrailGateway (telecommunications)Vulnerability (computing)Annihilator (ring theory)System callRouter (computing)Computer animation
Film editingComputer configurationWeightInternetworkingCodeReverse engineeringCartesian coordinate systemSystem administratorComputer animation
System administratorComputer configurationGastropod shellCuboidFilm editingWeightComputer animation
Figurate numberComputer wormScripting languageFilm editingWeightGastropod shellComputer animation
InternetworkingPasswordComputer-assisted translationMultiplication signComputer animation
Convex hullRouter (computing)TrailAnalytic continuationTwitterComputer animation
Transcript: English(auto-generated)