Josh Yavor

Josh Yavor

Ann Arbor, Michigan, United States
3K followers 500+ connections

Experience

  • Credible Security

    Ann Arbor, Michigan, United States

  • -

    Allendale, Michigan, United States

  • -

  • -

  • -

    Ann Arbor, Michigan, United States

  • -

    Ann Arbor, MI

  • -

    Ann Arbor, MI

  • -

    San Francisco Bay Area

  • -

    San Francisco Bay Area

  • -

    San Francisco Bay Area

  • -

    Greater Kalamazoo Area

  • -

    Kalamazoo, Michigan, United States

Education

Projects

  • Ruxcon 2013 - The BYOD PEAP Show: Mobile Devices Bare Auth

    An updated version of my talk at DEF CON 21.

    Slide Deck:
    https://docs.google.com/file/d/0B9vdTPvjDMKxWDhrX3EySzZYM2c/edit?usp=sharing&pli=1

    Abstract/Bio:
    http://ruxcon.org.au/speakers/#Josh Yavor

    See project
  • DEF CON 21 - The BYOD PEAP Show: Mobile Devices Bare Auth

    **Slides**
    https://www.defcon.org/images/defcon-21/dc-21-presentations/Yavor/DEFCON-21-Yavor-The-BYOD-PEAP-Show-Updated.pdf

    **Abstract**
    The onslaught of Bring Your Own Device(s) in recent years places a new focus on the security of wireless networks. In "The BYOD PEAP Show", Josh Yavor explores fundamental flaws in one of the most common and widely supported 802.1x authentication protocols used by countless corporate WPA2-Enterprise networks today. A series of events in the recent…

    **Slides**
    https://www.defcon.org/images/defcon-21/dc-21-presentations/Yavor/DEFCON-21-Yavor-The-BYOD-PEAP-Show-Updated.pdf

    **Abstract**
    The onslaught of Bring Your Own Device(s) in recent years places a new focus on the security of wireless networks. In "The BYOD PEAP Show", Josh Yavor explores fundamental flaws in one of the most common and widely supported 802.1x authentication protocols used by countless corporate WPA2-Enterprise networks today. A series of events in the recent past created a situation in which PEAP can no longer be used safely. In this talk, we will re-trace this path and investigate how the combination of BYOD, new technology and new tools led to this situation. A live demonstration with audience participation will punctuate the danger of supporting PEAP. Attendees will leave with an understanding of the underlying flaws, methods of exploitation, a set of tools and most importantly, how to secure WPA2-Enterprise networks that currently support PEAP. A new tool, peapshow, will be released after DEF CON and will make testing and exploitation of this issue truly trivial.

    Besides, this is DEF CON. Someone has to mess with the WiFi.

    See project
  • R00tz Asylum (DEF CON Kids) 2013 - Watching the TV Watchers

    **Media Coverage**
    http://www.npr.org/blogs/alltechconsidered/2013/08/13/211669208/hacking-real-things-becomes-childs-play-at-this-camp
    http://www.cbsnews.com/8301-205_162-57596857/can-your-smart-tv-watch-you

    **Abstract**
    There is nothing wrong with your television set. Do not attempt to adjust the picture. We are controlling the transmission.

    "Smart" TVs are becoming more and more common. Samsung and other vendors such as Sony and LG have sold more than a hundred million…

    **Media Coverage**
    http://www.npr.org/blogs/alltechconsidered/2013/08/13/211669208/hacking-real-things-becomes-childs-play-at-this-camp
    http://www.cbsnews.com/8301-205_162-57596857/can-your-smart-tv-watch-you

    **Abstract**
    There is nothing wrong with your television set. Do not attempt to adjust the picture. We are controlling the transmission.

    "Smart" TVs are becoming more and more common. Samsung and other vendors such as Sony and LG have sold more than a hundred million Smart TVs in the last few years. During this talk, Aaron Grattafiori and Josh Yavor will discuss the Samsung SmartTV design, attack surfaces and overall insecurity of the platform. A short discussion of the current application stack, TV operating system and other details will be provided to help set the stage for details of signi?cant ?aws found within the Samsung SmartTV application architecture, APIs and current applications.

    A number of vulnerabilities will be explored and demonstrated which allow malicious developers or remotely hijacked applications (such as the web browser or social media applications) to take complete control of the TV, steal accounts stored within it and install a userland rootkit. Exploitation of these vulnerabilities also provides the ability for an attacker to use the front-facing video camera or built-in microphone for spying and surveillance as well as facilitate access to local network for continued exploitation. This talk will also discuss methods to bypass what (meager) security protections exist and put forth several worst case scenarios (TV worm anyone?).

    Concluding this talk, Aaron and Josh will discuss what has been Fixed by Samsung and discuss what overall weaknesses should be avoided by future "Smart" platforms. Video demos of exploits and userland rootkits will be provided.

    Other creators
    See project
  • Black Hat USA 2013 - The Outer Limits: Hacking the Samsung Smart TV

    **Media Coverage**
    http://money.cnn.com/2013/08/01/technology/security/tv-hack/index.html
    http://www.cbsnews.com/8301-205_162-57596857/can-your-smart-tv-watch-you/
    http://mashable.com/2013/08/02/samsung-smart-tv-hack/
    http://www.cbsnews.com/8301-205_162-57596263/5-scariest-cybersecurity-threats-at-black-hat-defcon/
    http://www.cnn.com/2013/08/05/tech/mobile/five-hacks

    **Abstract**
    There is nothing wrong with your television set. Do not attempt to adjust the picture. We…

    **Media Coverage**
    http://money.cnn.com/2013/08/01/technology/security/tv-hack/index.html
    http://www.cbsnews.com/8301-205_162-57596857/can-your-smart-tv-watch-you/
    http://mashable.com/2013/08/02/samsung-smart-tv-hack/
    http://www.cbsnews.com/8301-205_162-57596263/5-scariest-cybersecurity-threats-at-black-hat-defcon/
    http://www.cnn.com/2013/08/05/tech/mobile/five-hacks

    **Abstract**
    There is nothing wrong with your television set. Do not attempt to adjust the picture. We are controlling the transmission.

    "Smart" TVs are becoming more and more common. Samsung and other vendors such as Sony and LG have sold more than a hundred million Smart TVs in the last few years. During this talk, Aaron Grattafiori and Josh Yavor will discuss the Samsung SmartTV design, attack surfaces and overall insecurity of the platform. A short discussion of the current application stack, TV operating system and other details will be provided to help set the stage for details of significant flaws found within the Samsung SmartTV application architecture, APIs and current applications.

    A number of vulnerabilities will be explored and demonstrated which allow malicious developers or remotely hijacked applications (such as the web browser or social media applications) to take complete control of the TV, steal accounts stored within it and install a userland rootkit. Exploitation of these vulnerabilities also provides the ability for an attacker to use the front-facing video camera or built-in microphone for spying and surveillance as well as facilitate access to local network for continued exploitation. This talk will also discuss methods to bypass what (meager) security protections exist and put forth several worst case scenarios (TV worm anyone?).

    Concluding this talk, Aaron and Josh will discuss what has been fixed by Samsung and discuss what overall weaknesses should be avoided by future "Smart" platforms. Video demos of exploits and userland rootkits will be provided.

    Other creators
    See project

View Josh’s full profile

  • See who you know in common
  • Get introduced
  • Contact Josh directly
Join to view full profile

Other similar profiles

Explore top content on LinkedIn

Find curated posts and insights for relevant topics all in one place.

View top content