Experience
Education
Projects
-
Ruxcon 2013 - The BYOD PEAP Show: Mobile Devices Bare Auth
See projectAn updated version of my talk at DEF CON 21.
Slide Deck:
https://docs.google.com/file/d/0B9vdTPvjDMKxWDhrX3EySzZYM2c/edit?usp=sharing&pli=1
Abstract/Bio:
http://ruxcon.org.au/speakers/#Josh Yavor -
DEF CON 21 - The BYOD PEAP Show: Mobile Devices Bare Auth
See project**Slides**
https://www.defcon.org/images/defcon-21/dc-21-presentations/Yavor/DEFCON-21-Yavor-The-BYOD-PEAP-Show-Updated.pdf
**Abstract**
The onslaught of Bring Your Own Device(s) in recent years places a new focus on the security of wireless networks. In "The BYOD PEAP Show", Josh Yavor explores fundamental flaws in one of the most common and widely supported 802.1x authentication protocols used by countless corporate WPA2-Enterprise networks today. A series of events in the recent…**Slides**
https://www.defcon.org/images/defcon-21/dc-21-presentations/Yavor/DEFCON-21-Yavor-The-BYOD-PEAP-Show-Updated.pdf
**Abstract**
The onslaught of Bring Your Own Device(s) in recent years places a new focus on the security of wireless networks. In "The BYOD PEAP Show", Josh Yavor explores fundamental flaws in one of the most common and widely supported 802.1x authentication protocols used by countless corporate WPA2-Enterprise networks today. A series of events in the recent past created a situation in which PEAP can no longer be used safely. In this talk, we will re-trace this path and investigate how the combination of BYOD, new technology and new tools led to this situation. A live demonstration with audience participation will punctuate the danger of supporting PEAP. Attendees will leave with an understanding of the underlying flaws, methods of exploitation, a set of tools and most importantly, how to secure WPA2-Enterprise networks that currently support PEAP. A new tool, peapshow, will be released after DEF CON and will make testing and exploitation of this issue truly trivial.
Besides, this is DEF CON. Someone has to mess with the WiFi. -
R00tz Asylum (DEF CON Kids) 2013 - Watching the TV Watchers
**Media Coverage**
http://www.npr.org/blogs/alltechconsidered/2013/08/13/211669208/hacking-real-things-becomes-childs-play-at-this-camp
http://www.cbsnews.com/8301-205_162-57596857/can-your-smart-tv-watch-you
**Abstract**
There is nothing wrong with your television set. Do not attempt to adjust the picture. We are controlling the transmission.
"Smart" TVs are becoming more and more common. Samsung and other vendors such as Sony and LG have sold more than a hundred million…**Media Coverage**
http://www.npr.org/blogs/alltechconsidered/2013/08/13/211669208/hacking-real-things-becomes-childs-play-at-this-camp
http://www.cbsnews.com/8301-205_162-57596857/can-your-smart-tv-watch-you
**Abstract**
There is nothing wrong with your television set. Do not attempt to adjust the picture. We are controlling the transmission.
"Smart" TVs are becoming more and more common. Samsung and other vendors such as Sony and LG have sold more than a hundred million Smart TVs in the last few years. During this talk, Aaron Grattafiori and Josh Yavor will discuss the Samsung SmartTV design, attack surfaces and overall insecurity of the platform. A short discussion of the current application stack, TV operating system and other details will be provided to help set the stage for details of signi?cant ?aws found within the Samsung SmartTV application architecture, APIs and current applications.
A number of vulnerabilities will be explored and demonstrated which allow malicious developers or remotely hijacked applications (such as the web browser or social media applications) to take complete control of the TV, steal accounts stored within it and install a userland rootkit. Exploitation of these vulnerabilities also provides the ability for an attacker to use the front-facing video camera or built-in microphone for spying and surveillance as well as facilitate access to local network for continued exploitation. This talk will also discuss methods to bypass what (meager) security protections exist and put forth several worst case scenarios (TV worm anyone?).
Concluding this talk, Aaron and Josh will discuss what has been Fixed by Samsung and discuss what overall weaknesses should be avoided by future "Smart" platforms. Video demos of exploits and userland rootkits will be provided.Other creatorsSee project -
Black Hat USA 2013 - The Outer Limits: Hacking the Samsung Smart TV
**Media Coverage**
http://money.cnn.com/2013/08/01/technology/security/tv-hack/index.html
http://www.cbsnews.com/8301-205_162-57596857/can-your-smart-tv-watch-you/
http://mashable.com/2013/08/02/samsung-smart-tv-hack/
http://www.cbsnews.com/8301-205_162-57596263/5-scariest-cybersecurity-threats-at-black-hat-defcon/
http://www.cnn.com/2013/08/05/tech/mobile/five-hacks
**Abstract**
There is nothing wrong with your television set. Do not attempt to adjust the picture. We…**Media Coverage**
http://money.cnn.com/2013/08/01/technology/security/tv-hack/index.html
http://www.cbsnews.com/8301-205_162-57596857/can-your-smart-tv-watch-you/
http://mashable.com/2013/08/02/samsung-smart-tv-hack/
http://www.cbsnews.com/8301-205_162-57596263/5-scariest-cybersecurity-threats-at-black-hat-defcon/
http://www.cnn.com/2013/08/05/tech/mobile/five-hacks
**Abstract**
There is nothing wrong with your television set. Do not attempt to adjust the picture. We are controlling the transmission.
"Smart" TVs are becoming more and more common. Samsung and other vendors such as Sony and LG have sold more than a hundred million Smart TVs in the last few years. During this talk, Aaron Grattafiori and Josh Yavor will discuss the Samsung SmartTV design, attack surfaces and overall insecurity of the platform. A short discussion of the current application stack, TV operating system and other details will be provided to help set the stage for details of significant flaws found within the Samsung SmartTV application architecture, APIs and current applications.
A number of vulnerabilities will be explored and demonstrated which allow malicious developers or remotely hijacked applications (such as the web browser or social media applications) to take complete control of the TV, steal accounts stored within it and install a userland rootkit. Exploitation of these vulnerabilities also provides the ability for an attacker to use the front-facing video camera or built-in microphone for spying and surveillance as well as facilitate access to local network for continued exploitation. This talk will also discuss methods to bypass what (meager) security protections exist and put forth several worst case scenarios (TV worm anyone?).
Concluding this talk, Aaron and Josh will discuss what has been fixed by Samsung and discuss what overall weaknesses should be avoided by future "Smart" platforms. Video demos of exploits and userland rootkits will be provided.Other creatorsSee project
Other similar profiles
Explore top content on LinkedIn
Find curated posts and insights for relevant topics all in one place.
View top content