YoVDO

Digging Deep Into the Flash Sandboxes

Offered By: Black Hat via YouTube

Tags

Black Hat Courses Software Security Courses Vulnerability Analysis Courses

Course Description

Overview

Explore the intricate world of Flash sandboxing technology in this Black Hat USA 2012 conference talk. Delve into the internals of three sandbox implementations for Adobe's Flash Player: Protected Mode Flash for Chrome, Protected Mode Flash for Firefox, and Pepper Flash. Gain insights into the high-level architecture of each sandbox implementation, understanding the roles of different processes and their interconnections. Examine the internal sandbox mechanisms, including restrictions, IPC protocols, and services exposed by higher-privileged processes. Analyze the security aspects, current limitations, and weaknesses of each implementation, and discover potential avenues for sandbox bypasses or escapes. Compare and contrast the various differences between these implementations throughout the presentation. Witness demonstrations of Flash sandbox escape vulnerabilities uncovered during the research process.

Syllabus

Introduction
Overview
Targets
Sandbox Architecture
Sandbox Mechanism
Sandbox Restrictions
Interprocess Communication
Services Exposed
Policy Engine
Sandbox Limitations
Sandbox Escapes
Demo


Taught by

Black Hat

Related Courses

Attack on Titan M, Reloaded - Vulnerability Research on a Modern Security Chip
Black Hat via YouTube
Attacks From a New Front Door in 4G & 5G Mobile Networks
Black Hat via YouTube
AAD Joined Machines - The New Lateral Movement
Black Hat via YouTube
Better Privacy Through Offense - How to Build a Privacy Red Team
Black Hat via YouTube
Whip the Whisperer - Simulating Side Channel Leakage
Black Hat via YouTube