black hat 2014 - wait! wait! don't pwn me!

79
Wait, wait! Don’t pwn me! August 2014 Security News Headlines Q&A game

Upload: seniorstoryteller

Post on 29-Nov-2014

158 views

Category:

Software


1 download

DESCRIPTION

At the Black Hat 2014 Conference in Las Vegas, OWASP presented the third installment of their popular game show, Wait, Wait! Don't Pwn Me. Play along and see how many news stories you can identify for the month of July 2014.

TRANSCRIPT

Page 1: Black Hat 2014 - Wait! Wait! Don't Pwn Me!

Wait, wait! Don’t pwn me!

August 2014 Security News Headlines Q&A game

Page 2: Black Hat 2014 - Wait! Wait! Don't Pwn Me!

INTRODUCTIONS: THE PANEL

Page 3: Black Hat 2014 - Wait! Wait! Don't Pwn Me!

ONLINE NEWS RESOURCES

Hacker NewsCSOCNNars technicaThe VergeThreat PostNetworkWorldSANS

Brian KrebsPandodailyForbesTeslaFBI.govStar TribuneErrata Security

Page 4: Black Hat 2014 - Wait! Wait! Don't Pwn Me!

Twitter: #BlackHat #WaitWait

Page 5: Black Hat 2014 - Wait! Wait! Don't Pwn Me!

THE RULESEach correct answer to the initial question is worth 3 pointsA wrong answer subtracts 2 pointsA pass on the question loses 1 pointIf a question is answered incorrectly, the second response is worth 1 pointA correct answer from an audience member gets allocated 2 points to panelist of choice

The moderator may arbitrarily give or take away points at any time

Page 6: Black Hat 2014 - Wait! Wait! Don't Pwn Me!

SCORE KEEPER: WE NEED A VOLUNTEER!

Page 7: Black Hat 2014 - Wait! Wait! Don't Pwn Me!

AUDIENCE PARTICIPATION:

WARM UP

Page 8: Black Hat 2014 - Wait! Wait! Don't Pwn Me!

Who is retiring as Executive Director of OWASP?

Page 9: Black Hat 2014 - Wait! Wait! Don't Pwn Me!
Page 10: Black Hat 2014 - Wait! Wait! Don't Pwn Me!

According to the project evaluation committee findings, what is the most active project in OWASP?

Page 11: Black Hat 2014 - Wait! Wait! Don't Pwn Me!
Page 12: Black Hat 2014 - Wait! Wait! Don't Pwn Me!

FOR THE PANEL:

HACKS IN THE NEWS

Page 13: Black Hat 2014 - Wait! Wait! Don't Pwn Me!

In Sydney Australia, hackers turned an ATM into one, gigantic game player. What game to they did they put on the machine?

Page 14: Black Hat 2014 - Wait! Wait! Don't Pwn Me!
Page 15: Black Hat 2014 - Wait! Wait! Don't Pwn Me!

According to Karsten Nohl, what common portable device can be used in a new type of attack?

Page 16: Black Hat 2014 - Wait! Wait! Don't Pwn Me!
Page 17: Black Hat 2014 - Wait! Wait! Don't Pwn Me!

Microsoft was recently ordered by the United States government to turn over email that resided in what country’s servers?

Page 18: Black Hat 2014 - Wait! Wait! Don't Pwn Me!
Page 19: Black Hat 2014 - Wait! Wait! Don't Pwn Me!

Aircraft satellite communication systems can be hacked via what, according to Ruben Santamarta?

Page 20: Black Hat 2014 - Wait! Wait! Don't Pwn Me!
Page 21: Black Hat 2014 - Wait! Wait! Don't Pwn Me!

Feds’ Silk Road investigation broke “what”, defendant tells court?

Page 22: Black Hat 2014 - Wait! Wait! Don't Pwn Me!
Page 23: Black Hat 2014 - Wait! Wait! Don't Pwn Me!

Name one of two major applications that use a vulnerable version of Apache Cordova.

Page 24: Black Hat 2014 - Wait! Wait! Don't Pwn Me!
Page 25: Black Hat 2014 - Wait! Wait! Don't Pwn Me!

Visit the wrong website, and what government agency could end up in your computer?

Page 26: Black Hat 2014 - Wait! Wait! Don't Pwn Me!
Page 27: Black Hat 2014 - Wait! Wait! Don't Pwn Me!

Godzilla Hacker took down 43 major website of what government?

Page 28: Black Hat 2014 - Wait! Wait! Don't Pwn Me!
Page 29: Black Hat 2014 - Wait! Wait! Don't Pwn Me!

Anonymous Group took down whose website over the Gaza conflict?

Page 30: Black Hat 2014 - Wait! Wait! Don't Pwn Me!
Page 31: Black Hat 2014 - Wait! Wait! Don't Pwn Me!

The Russian government asked Apple to hand over what?

Page 32: Black Hat 2014 - Wait! Wait! Don't Pwn Me!
Page 33: Black Hat 2014 - Wait! Wait! Don't Pwn Me!

Attackers breached Tor’s system to reveal what?

Page 34: Black Hat 2014 - Wait! Wait! Don't Pwn Me!
Page 35: Black Hat 2014 - Wait! Wait! Don't Pwn Me!

What scam did a 24 year old many use to steal $309,768 from Apple?

Page 36: Black Hat 2014 - Wait! Wait! Don't Pwn Me!
Page 37: Black Hat 2014 - Wait! Wait! Don't Pwn Me!
Page 38: Black Hat 2014 - Wait! Wait! Don't Pwn Me!

BY THE NUMBERS

Page 39: Black Hat 2014 - Wait! Wait! Don't Pwn Me!

Within 100,000, how many passwords did a Russian criminal group lift from 420,000 websites?

Page 40: Black Hat 2014 - Wait! Wait! Don't Pwn Me!
Page 41: Black Hat 2014 - Wait! Wait! Don't Pwn Me!

Credit Card Breach Confirmed At 33 restaurant locations. Which restaurant chain was it?

Page 42: Black Hat 2014 - Wait! Wait! Don't Pwn Me!
Page 43: Black Hat 2014 - Wait! Wait! Don't Pwn Me!

What popular developer network accidently exposed thousands of developers emails and password?

Page 44: Black Hat 2014 - Wait! Wait! Don't Pwn Me!
Page 45: Black Hat 2014 - Wait! Wait! Don't Pwn Me!

On average, how many vulnerabilities did researchers find per Internet of Things device?

Page 46: Black Hat 2014 - Wait! Wait! Don't Pwn Me!
Page 47: Black Hat 2014 - Wait! Wait! Don't Pwn Me!

Within 5%, what percent of employees xpose critical corporate data by mistake?

Page 48: Black Hat 2014 - Wait! Wait! Don't Pwn Me!
Page 49: Black Hat 2014 - Wait! Wait! Don't Pwn Me!

Within 5%, how many Critical Infrastructure Providers were breached last year?

Page 50: Black Hat 2014 - Wait! Wait! Don't Pwn Me!
Page 51: Black Hat 2014 - Wait! Wait! Don't Pwn Me!

REALLY? THAT’S UNBELIEVABLE!

Page 52: Black Hat 2014 - Wait! Wait! Don't Pwn Me!

EZ-Pass was hit with what kind of scheme to defraud users?

Page 53: Black Hat 2014 - Wait! Wait! Don't Pwn Me!
Page 54: Black Hat 2014 - Wait! Wait! Don't Pwn Me!

A warrant authorized the FBI to Track and do what to people’s computers?

Page 55: Black Hat 2014 - Wait! Wait! Don't Pwn Me!
Page 56: Black Hat 2014 - Wait! Wait! Don't Pwn Me!

Android malware SandroRAT disguises itself as what?

Page 57: Black Hat 2014 - Wait! Wait! Don't Pwn Me!
Page 58: Black Hat 2014 - Wait! Wait! Don't Pwn Me!

Scientists reconstruct “what” by watching a bag of potato chips?

Page 59: Black Hat 2014 - Wait! Wait! Don't Pwn Me!
Page 60: Black Hat 2014 - Wait! Wait! Don't Pwn Me!

THE BUSINESS SIDE

Page 61: Black Hat 2014 - Wait! Wait! Don't Pwn Me!

Google fixed what security hole in Android?

Page 62: Black Hat 2014 - Wait! Wait! Don't Pwn Me!
Page 63: Black Hat 2014 - Wait! Wait! Don't Pwn Me!

What should be of high concern for travelers using business centers at the hotel?

Page 64: Black Hat 2014 - Wait! Wait! Don't Pwn Me!
Page 65: Black Hat 2014 - Wait! Wait! Don't Pwn Me!

LIGHTNING ROUND

NOTHING BUT OWASP

Page 66: Black Hat 2014 - Wait! Wait! Don't Pwn Me!

Within 5000, how many listens has the OWASP 24/7 Podcast had within the past 9 months?

Page 67: Black Hat 2014 - Wait! Wait! Don't Pwn Me!
Page 68: Black Hat 2014 - Wait! Wait! Don't Pwn Me!

Within 10, how many projects are currently under evaluation by the Johanna and the evaluation committee?

Page 69: Black Hat 2014 - Wait! Wait! Don't Pwn Me!

141 Projects

Page 70: Black Hat 2014 - Wait! Wait! Don't Pwn Me!

In the OWASP Top 10, what does section A9 cover?

Page 71: Black Hat 2014 - Wait! Wait! Don't Pwn Me!
Page 72: Black Hat 2014 - Wait! Wait! Don't Pwn Me!

What very popular project does Colin Watson run?

Page 73: Black Hat 2014 - Wait! Wait! Don't Pwn Me!
Page 74: Black Hat 2014 - Wait! Wait! Don't Pwn Me!

How many days until AppSec USA 2014?

Page 75: Black Hat 2014 - Wait! Wait! Don't Pwn Me!
Page 76: Black Hat 2014 - Wait! Wait! Don't Pwn Me!

TALLY THE SCORE: WHO WON?

Page 77: Black Hat 2014 - Wait! Wait! Don't Pwn Me!

THANK YOU TO THE PANEL

Page 78: Black Hat 2014 - Wait! Wait! Don't Pwn Me!

A NEW OWASP PROJECT: THE WAIT WAIT GAME

[email protected]

Page 79: Black Hat 2014 - Wait! Wait! Don't Pwn Me!

Wait, wait! Don’t pwn me!

August 2014 Security News Headlines Q&A game