DEF CON 30 - Sam Quinn, Steve Povolny - Perimeter Breached Hacking an Access Control System
The first critical component to any attack is an entry point. As we lock down firewalls and routers, it can be easy to overlook the network-connected physical access control systems. A study done by IBM in 2021 showed that the average cost of a physical security compromise is $ million and takes an average of 223 days to identify a breach.
HID Mercury is a global distributor of access control systems with more than 20 OEM partners, deployed across multiple industries and certified for use in federal and state government facilities.
Trellix’s Advanced Threat Research team uncovered 4 unique 0-day vulnerabilities and 4 additional undisclosed vulnerabilities leading to remote, unauthenticated code execution on multiple HID Mercury access control panels. These findings lead to full system control including the ability for an attacker to remotely manipulate door locks. During this presentation, we will briefly cover the hardware debugging process, leading to a root shell on the target. We will explore in greater depth the vulnerability discovery techniques, including emulation, fuzzing, static and dynamic reverse engineering, and a detailed walkthrough of several of the most critical vulnerabilities. We’ll address our approach to exploitation using simplistic malware we designed to control system functionality and culminate the talk with a live demo featuring full system control, unlocking doors remotely without triggering any software notification
1 view
0
0
2 months ago 00:00:00 1
Resonancerz - Let The Galaxy Burn
2 months ago 00:03:09 1
Jay Z - 99 Problems OFFICIAL VIDEO
2 months ago 00:00:00 1
Classic Rock Songs 70s 80s 90s Full Album - Queen, Eagles, Pink Floyd, Def Leppard, Bon Jovi
2 months ago 00:00:00 1
Top 100 Classic Rock Songs Of All Time - ACDC, Pink Floyd, Eagles, Queen, Def Leppard, Bon Jovi
2 months ago 00:01:29 1
Peaceful 31
3 months ago 00:04:54 1
Los Borbones son unos Ladrones VIDEOCLIP + LETRA
3 months ago 01:14:27 1
[Angels Of Love] Dave Morales ’’Revoluciòn’’ live @ Disco Metropolis 31-08-2002
3 months ago 00:03:19 8
NOELIA RODILES & FERNANDO ARIAS en FILARMÓNICA DE ZARAGOZA. Letanía D 343 de
3 months ago 00:46:42 1
ЛУЧШИЕ ИГРЫ про ХОЛОДНУЮ ВОЙНУ
3 months ago 00:35:15 1
The Absolute Craziest Mind Blowing Knives / Stuff at a Knife Show
3 months ago 01:04:33 2
Danny Eaton Guestmix
3 months ago 00:22:46 1
PREPARE YOUR FAMILY FOR A FULL SCALE EVACUATION OF THE URBAN AREAS BEFORE SHTF!
3 months ago 00:42:23 1
⚡ALERT: WW3 GROUND WAR BEGINS! US SENDS TROOPS! KREMLIN/ IRAN EMERGENCY! PUTIN GOES DEFCON 2!
3 months ago 00:02:22 1
Les manifestations après le décès de Philippine
3 months ago 00:44:06 1
DEF CON 25 - Chris Sumner - Rage Against the Weaponized AI Propaganda Machine
3 months ago 00:04:38 1
VIEUX CON !
3 months ago 00:00:00 1
Mamy Samb et Ngoné à Bougane “nagn ko barricadé nakh mou bagna guénati def conférence presse“
3 months ago 00:04:02 1
Resonancerz - Power Of Harmony
3 months ago 00:15:23 1
Russian short film – “Defcon“ (2009)
3 months ago 00:08:22 1
“Rusia entraría en DEFCON4 si Zelensky usa los misiles de largo alcance de EEUU”. Villaroya
4 months ago 01:33:23 1
Cyber Risk Thursday: Internet of Bodies
4 months ago 02:03:39 1
Ori Uplift - Uplifting Only 422 (March 11, 2021) [All Instrumental]
4 months ago 00:04:25 1
Resonancerz - Sigmar Lied
4 months ago 00:00:00 1
ACDC, Pink Floyd, Eagles, Queen, Def Leppard, Bon Jovi, U2 Power Ballads | Classic Rock Songs