BlackHat Mobile Security Summit - London 2015
In June 2015 I attended the Blackhat Mobile Security Summit in London, a 2 days event filled with talks from various researchers and security professionals, there was a 3rd day in the form of a workshop for anyone attending the Interop London hosting event.
Blackhat is historically a USA based event with its main conference taking place in Las Vegas every year, lately they started to host similar (but smaller) conferences around the world such as in Singapore and Amsterdam (which I blogged about last year here).
This London edition was definitely on the "smaller" side and this actually had a few advantages:
- You could attend all the sessions as none were run in parallel
- It was easier to mingle among fellow participants and speakers
- There was less "walking"! :)
The quality of the talks were high, as you would expect from the "Blackhat" brand, with only a couple having a speaker struggling to deliver their presentation in English. You can download most presentations and relevant white papers from the Blackhat summit page.
Below are the key take aways from this summit sessions:
Key Takeaways
The machines that betrayed their masters
- Mobile Data leakage
Android Security State of the Union
- Google speaking about their security controls
Abusing android apps and gaining remote code execution
- A new type of mobile attack vector
SAP Mobile: Attack and Defense
- Common issues with SAP mobile dev
Blackbox iOS app testing with idb
- iOS hacking technics
Security analysis of android factory resets
- Problems with secure delete on Android
Witchcraft for windows phone breakers
- Windows hacking technics
-
- SCADA systems at remote risk because of mobile
-
- Cell network malware monitoring
Detailed Talks
1. The machines that betrayed their masters (click for BH description)
Presenter: Glen Wilkinson
Contact: @Glennzw
Glen put an interesting twist to a common security topic: how much data your personal/portable devices leak about you.
He discussed the tool he created, Snoopy, which shows how many people had attended his previous talks and where they lived.
An interesting point made was about the identifiers beyond the "MAC address". He mentioned apps network signatures, email access patterns, and browser signatures as sources of leaked information.
Glen indicated that Snoopy-ng allows tracking in a central database and works efficiently on low performance Linux machines like Raspberry Pi.
Additionally, he shared that iPhones become silent about saved WIFI networks unless a hidden SSID is created which makes them noisy again!
2. Android Security State of the Union
Presenter: Adrian Ludwig
Adrian discussed Android security at Google, articulating how Google is taking its ecosystem's cyber security seriously. He explained the numerous security measures being implemented to improve Android security.
Key points included that Google believes their ultimate aim is not zero malware but to maintain a small and manageable number of vulnerabilities. He also mentioned the Android Security Reward program which pays for vulnerability disclosures.
3. Abusing android apps and gaining remote code execution (click for BH description)
Presenter: Ryan Welton Contact: @fuzion24
Ryan introduced a new attack technique utilizing zip directory traversal, where crafted zip files can be unzipped outside of their respective app directories due to a flaw in the Android Zip library's handling of paths.
He illustrated this with two examples: one involving a vulnerability in a popular video app framework called Vungle and another in Samsung's default keyboard installation method.
4. SAP Mobile: Attack and Defense (click for BH description)
Presenters: Julian Rapisardi and Fernando Russ
The focus was on SAP FIORI, a mobile development framework used by many companies, highlighting vulnerabilities that could arise as SAP goes mobile.
Their main demonstration illustrated vulnerabilities in a mock app they designed while following standard practices for SAP mobile app development.
5. Blackbox iOS app testing with idb (click for BH description)
Presenter: Daniel Mayer
Daniel highlighted security controls in iOS and outlined security risks such as unencrypted sensitive information in the cache.
6. Security analysis of android factory resets (click for BH description)
Presenter: Laurent Simon Contact and papers: Laurent's Page
Laurent presented flaws in data deletion methods in Android phones and how they allow recovery of sensitive data even after factory resets.
7. Witchcraft for windows phone breakers (click for BH description)
Presenter: Luca de fulgentis
Luca discussed different types of attacks on Windows Phones (Logical, Physical, Network) and strategies for mitigation.
8. SCADA and Mobile (click for BH description)
Presenters: Alexander Bolshev and Ivan Iushkevich
This talk scrutinized the vulnerabilities present in mobile apps controlling Industrial Control Systems, emphasizing the risks associated with compromised communication and app security.
9. Malware network view (click for BH description)
Presenter: Kevin McNamee
Kevin shared insights on how phone companies monitor mobile networks for malware, presenting statistics on infection rates and the growing concern of mobile devices in network safety.