News: 1628481731

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Black Hat security conference returns to Las Vegas – complete with hacks to quiet the hotel guest from hell

(2021/08/09)


In Brief After a year off due to a certain virus, the Black Hat and DEF CON security conferences returned to Las Vegas last week, just in time for the US government's attempts to foster more collaboration across the infosec industry.

The [1]newly appointed Security Director of the Cybersecurity and Infrastructure Agency Jen Easterly took to the virtual Black Hat stage last week (although there was a limited and well-spaced physical conference this year) and [2]announced the Joint Cyber Defense Collaborative (JCDC), which she claimed would be a true public/private partnership to try to lock down security incidents by sharing data and skills.

Microsoft, AWS, Google and several US telcos have signed up, but Easterly's keynote was particularly aimed at bringing in independent talent. Among the suggestions were increasing public sector salaries and taking a more flexible approach to hiring.

[3]

DHS Secretary Alejandro Mayorkas also gave a keynote speech along the same lines, saying his agency stood ready to do its bit.

[4]

[5]

"We're really hard at work and we have no illusions about the road ahead," [6]he said . "There is nothing simple about the cybersecurity challenges we face, and we need your help to get this right. We need your expertise to inform our policies and the future of our critical mission."

Hotel neighbor from hell

We've all had the hotel trip where someone's being too noisy. When a fellow traveler in a capsule hotel got on his nerves, a security consultant for Lexfo named Kyasupā decided to hit back.

The hotel allowed guests to control aspects of their room using an iPod Touch with Bluetooth and Wi-Fi. Kyasupā [7]found [PDF] that the iPod connected to a Nasnos CS8700 router. By chaining together six vulnerabilities and forcing a reboot of the iPod touch, Kyasupā found he could control any capsule in the hotel.

Kyasupā had asked one guest, called Bob for anonymity, if he could be quieter at night, since the person was prone to loud 2AM phone calls. After repeated unsuccessful attempts to sort this out, Kyasupā simply programmed the man's bed to convert into a couch and back again and flashed the room lights every two hours.

[8]

He then went to the hotel's management team, who were surprisingly nice about it, and fixed the issue. The moral of the story? Politeness is important.

Punkspider is back, inventors claim it's cool this time

Web app scanner Punkspider has been controversial since [9]its release in 2013, with critics saying it can too easily be abused.

The project went dark in 2015, but now it's back, say its creators, and it's nothing for folks to worry about. A presentation at DEF CON saw Alejandro Caceres, director of computer network exploitation at QOMPLX, and self-described hacker Jason Hopper, explaining.

"We got banned more than a 15-year-old with a fake ID trying to get into a bar. It became a pain and hardly sustainable without a lot of investment in time and money. Each time we got banned it meant thousands of dollars and countless hours moving sh** around," [10]they said .

"Now we've solved our problems and completely re-engineered and expanded the system."

[11]

The proof of that pudding will be in the eating, however, and the team may find itself shut down again. Many fear that the tool will be abused again – not just to expose vulnerabilities, but to exploit some as well. You can see the full talk [12]here .

Inside the Middle East security machine

One [13]disturbing talk [PDF] at Black Hat this year was from former NSA instruction specialist David Evenden, now running security shop StandardUser.

Evenden recounted how he and others were wooed by intelligence agencies around the world to work with a group called CyberPoint in the United Arab Emirates on a scheme named [14]Project Raven . The work was supposed to be intelligence gathering and defensive security work, but Evenden said he was increasingly being asked to pull in more harmful data.

Evenden and others were being asked to spy on journalists, members of the local royal families, and he even found some of Michelle Obama's emails. Despite the generous tax-free salary he, and some others, decided to get out of the country while they still could.

Evenden warned that you should never lodge your passport with an employer and always have enough cash and a plan to get out if something looks too good to be true – and to check a potential employer's history carefully.

The other virus

Jeff Moss, AKA Dark Tangent and the man who founded the conferences, offered a sobering warning at the start of the show. He said the industry has lost good people this year and COVID-19 will be around for a while, it seems.

Reports on the ground suggest the conferences have been very sparsely attended – certainly nothing like the mad crush of tens of thousands of visitors that's normal for the show. Most attendees wore masks, but more than a few maskless wandered about.

Las Vegas already has a big COVID problem, and events like this can act as superspreader events, as this hack found out to his cost at the RSA Conference last year. Let's be careful out there, folks. ®

Get our [15]Tech Resources



[1] https://www.theregister.com/2021/07/19/in_brief_security/

[2] https://www.theregister.com/2021/08/06/cisa_convenes_joint_cyber_defense_collaborative/

[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YRD84p-g3mp08uefu7D8@wAAAJQ&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YRD84p-g3mp08uefu7D8@wAAAJQ&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YRD84p-g3mp08uefu7D8@wAAAJQ&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[6] https://www.dhs.gov/news/2021/08/05/secretary-mayorkas-delivers-keynote-address-black-hat-usa

[7] https://i.blackhat.com/USA21/Wednesday-Handouts/us-21-Hacking-A-Capsule-Hotel-Ghost-In-The-Bedrooms.pdf

[8] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YRD84p-g3mp08uefu7D8@wAAAJQ&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[9] https://www.theregister.com/2013/02/21/punkspider/

[10] https://defcon.org/html/defcon-29/dc-29-speakers.html#caceres

[11] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YRD84p-g3mp08uefu7D8@wAAAJQ&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[12] https://www.youtube.com/watch?v=DlS_sl4hTWg

[13] https://i.blackhat.com/USA21/Wednesday-Handouts/us-21-Whoops-I-Accidentally-Helped-Start-The-Offensive-Intel-Branch-Of-A-Foreign-Intel-Service.pdf

[14] https://www.theregister.com/2019/07/10/mozilla_darkmatter_ban/

[15] https://whitepapers.theregister.com/



lglethal

"He then went to the hotel's management team, who were surprisingly nice about it, and fixed the issue."

Which issue? "Bob" the noisy neighbour? Or just the Router?

Worth a watch

steviebuk

Always worth a watch. The best one was the talk the guy did about his kit being stolen from his flat. Then he went on to trace who'd now had it as he had dyndns setup and they never wiped it. Really good talk that one.

Will they be on YouTube? Technically you're no longer allowed to put hacking videos on YouTube (a shit rule) my RDS session hijack example is still up. More reason to move to lbry I think.

Re: Worth a watch

lglethal

Having not heard of Lbry before your comment, I've had a quick look and it seems... interesting.

I would be very intersted to hear what you think of it. Is it any good?

The whole monetisation thing seems like trying to create money from air (so par for the course for digital currencies), and the lack of central controls seems like it would quickly become inundated with conspiracy theories and other bollocks pretty quickly once it gets popular, but for now it seems it could be good.

What are your experiences?

Re: lbry

Pascal Monett

The website says it's a " Blockchain-based file-sharing and payment network ".

Thanks but no thanks. I have no intention of dedicating gigabytes of my disk space to hold the entire content database of a website.

I'll stick with Youtube until a better alternative is given.

Conscience is what hurts when everything else feels so good.