We're sorry but this page doesn't work properly without JavaScript enabled. Please enable it to continue.
Feedback

AppSec Village - A Heaven for Hackers: Breaking a Web Security Virtual Appliances

Formal Metadata

Title
AppSec Village - A Heaven for Hackers: Breaking a Web Security Virtual Appliances
Title of Series
Number of Parts
374
Author
License
CC Attribution 3.0 Unported:
You are free to use, adapt and copy, distribute and transmit the work or content in adapted or unchanged form for any legal purpose as long as the work is attributed to the author in the manner specified by the author or licensor.
Identifiers
Publisher
Release Date
Language

Content Metadata

Subject Area
Genre
Abstract
Most security products require to be placed in the heart of the organization's IT configuration. Even though we are highly paranoid and security aware about every single third party tool that we include in our IT structure; we lose these concerns when it comes to security products. We forget to see that even though these are security products in their nature; they are not necessarily secure in terms of their operation; despite the fact that they require much more permission than any other software. In this talk, I will take you through the steps of vulnerability research, which attack vectors were more promising than the others, which critical vulnerabilities were easier to find, how was the exploiting phase and much more. To do that, I will be using one of my 0day remote code execution exploit that targets Trend Micro Web Security product, which uses a combination of 3 different vulnerabilities to gain RCE as a case-study.