Advertisement

Bertin Bervis - Mixing industrial protocols with web application security - DEF CON 27 IoT Village

Bertin Bervis - Mixing industrial protocols with web application security - DEF CON 27 IoT Village In this talk i'm going to explain in detail a new technique to achieve javascript code persistence in web applications from devices using the Bacnet protocol (building automation) in the underlying device protocol/web app arquitecture.
A remote attacker is able to inject javascript code in the Bacnet device abusing the read/write properties from the Bacnet protocol itself, the code is going to be stored in the Bacnet database helping the attacker to achieve persistence in the victim browser, we are talking about devices that operates in building enviroments or industrial facilities , the posibility to jump from that point to another point in the industrial network using this particular vector is really high.

Bio:
Bertin is a Security Researcher

DEF,CON,DEFCON,DEF CON,hacker conference,security conference,information security conference,information security,conference speakers,hackers,hacking,hacking videos,security research,Internet of things,

Post a Comment

0 Comments