YoVDO

A Practical Attack Against VDI Solutions

Offered By: Black Hat via YouTube

Tags

Black Hat Courses Cybersecurity Courses Malware Courses Data Exfiltration Courses Virtual Desktop Infrastructure Courses

Course Description

Overview

Explore a Black Hat conference talk that exposes vulnerabilities in Virtual Desktop Infrastructure (VDI) solutions. Delve into a practical attack demonstration where researchers Daniel Brodie and Michael Shaulov reveal how malicious apps can exploit screen scraping techniques to compromise data security in VDI platforms. Learn about the architecture of VDI systems, their perceived security benefits, and how attackers can circumvent both client-side and server-side malware detection measures. Gain insights into mobile remote access trojans, government-grade malware, and surveillance tools used in these attacks. Witness a proof-of-concept demonstration and understand the implications for BYOD security strategies. Examine key findings, architectural vulnerabilities, and potential threats across Android and iOS devices.

Syllabus

Introduction
About MDM
Agenda
Disclaimer
Recap
Enablement
Device Loss DLP
VDI Marketing
VDI Architecture
Niche Players
Threats
Mobile Remote Access Trojan
HighLevel Example
Government Grade Malware
Surveillance Tools
Hacking Team
Research
MSpy
How Much
The Architecture
Key Findings
The Report
The Real Threat
Android
MacKinnon
Screen Recording
Communication
iOS Configuration Profiles
Demo
Summary


Taught by

Black Hat

Related Courses

Computer Security
Stanford University via Coursera
Cryptography II
Stanford University via Coursera
Malicious Software and its Underground Economy: Two Sides to Every Story
University of London International Programmes via Coursera
Building an Information Risk Management Toolkit
University of Washington via Coursera
Introduction to Cybersecurity
National Cybersecurity Institute at Excelsior College via Canvas Network