Oh my God, we’re back again! Another year, another DEFCON. And a Backstreet Boys reunion. This year we sent 12 people, gave 1 workshop, gave 1 talk, and participated in 2 panels. This post is gonna be bringing the flavor, showcasing the teams personal highlights from our DEFCON34 experience.

SRA @ DEFCON

  • Clone to Pwn: Remote Badge Cloning with the Flipper Zero
    • Langston Clement - Physical Security Village (Talk)
  • Purple Teaming? Simulating the Adversary in the World of AI Systems
    • Evan Perotti - Adversary Village (Panel)
  • Detection Coverage Is a Hypothesis: Testing it Through Adversarial Execution Variance
    • Connor Jackson, Nahid Sarker, Raphael Soto, Russell Harvey - Adversary Village (Workshop)
  • From Threat-Intel to Tested Defense, the Adversary Simulation Playbook
    • Sarah Hume - Adversary Village (Panel)

Highlights

Across the 12 of us that went, here are our personal picks for content that stood out:

Title Author Description Link
Transformers: Dark Side of the Type - Weaponizing the Conversion Layer Oleksandr Mirosh A new class of attacks that works similarly to insecure deserialization, but targets the type transformation layer rather than a deserializer. link
Can AI do novel security research? Meet the HTTP Terminator James Kettle A deep dive into using AI for developing novel attack classes link
CRLF-Powered Desync Attacks: Beheading HTTP Streams Tom Stacey & Tobia Righi Using HTTP Header Injection to enable novel desync attacks link
Identity Crisis: Novel Vulnerabilities Leading to Kerberos Downgrade, DoS, and Full Domain Takeover Shai Laron Using unfilterable/invisible Unicode characters to bypass Kerberos uniquiness constraints for SPNs & UPNs link
Certified Re-Pwned: escalating all the way up Daniel Monzon & Eric Labrador Five new ADCS exploits
Breaking BIOS in ATMs Arnold Jared Morales Yepez Using DMA attacks for ATM jackpotting link
LaunchBreak: RCE Through Custom URIs Gavin Zhong, Zhengyu Liu, & Jinajia Yu RCE in Electron apps via custom URI schemas link
Lights Out – Out Of Band Management Exploitation HD Moore Introduced several new BMC attack techniques link
Click Me: Turning URI Links into Bug Bounty RCEs Tobias Diehl Abusing Windows protocol handlers for RCE
What Scammers Know That Social Engineers Don’t Megan Squire Improve social engineering interactions by learning from techniques used by scammers
Anyone Can Hack IoT - Even Easier Now Andrew Bellini Using AI to perform IoT hacking tasks link
Bring Your own EDR Shahak Morag Abusing SentinelOne’s privileged COM interfaces to attack other EDR processes link
Bypassing the Human EDR Daniel Isler Identify existing phishing/scam training to create pretexts that your target won’t flag as suspicious
Lyra Rafael Felix A cross-platform, LLVM-based obfuscator for Rust link
SilentChrome Gordon Long Using chrome extension hollowing to overwrite legitimate plugins with malicious content link
pathfinding.cloud DataDog AWS privilege escalation methods link
EvilFont Drew G Hiding invisible machine-readable text in fonts to enable social engineering and prompt injection link