SOHO Hacking at Pwn2Own
Offered By: Hack In The Box Security Conference via YouTube
Course Description
Overview
Explore the security challenges of home office networks and enterprise perimeter shifts in this conference talk from Hack In The Box Security Conference. Dive into the methodologies used by NCC Exploit Development Group (EDG) to rapidly identify vulnerabilities in consumer routers and small business devices during Pwn2Own 2022 Toronto. Learn about the differences between LAN and WAN attack surfaces, custom tooling for vulnerability analysis, and the process of creating multiple exploit chains. Discover specific vulnerabilities found in Netgear, TP-Link, and Synology devices, and understand the unique challenges posed by the Pwn2Own competition. Examine the development of multi-stage exploit chains used to compromise routers via WAN and pivot to LAN devices. Gain insights into the security shortcomings of consumer devices and their implications for end users and enterprises. Witness demonstrations of vulnerabilities and understand how threat actors could exploit these attacks for lateral movement and persistence in networks.
Syllabus
#HITB2023AMS D1T1 - SOHO Hacking At Pwn2Own - Alex Plaskett & McCaulay Hudson
Taught by
Hack In The Box Security Conference
Related Courses
Computer SecurityStanford University via Coursera Cryptography II
Stanford University via Coursera Malicious Software and its Underground Economy: Two Sides to Every Story
University of London International Programmes via Coursera Building an Information Risk Management Toolkit
University of Washington via Coursera Introduction to Cybersecurity
National Cybersecurity Institute at Excelsior College via Canvas Network