DEF CON 20 - Peter Hannay - Exchanging Demands
287 views · Published 30 October 2013 · 43:15 · Indexed 29 September 2026
Channel: DEFCONConference · 2013 · Science & Technology
Copy of the slides for this talk are here:https://media.defcon.org/dc-20/presentations/Hannay/DEFCON-20-Hannay-Exchanging-Demands.pdf Extras:https://media.defcon.org/dc-20/presentations/Hannay/Extras.zip Exchanging Demands Peter Hannay Security Researcher, PhD Student Smart phones and other portable devices are increasingly used with Microsoft Exchange to allow people to check their corporate emails or sync their calendars remotely. Exchange has an interesting relationship with its mobile clients. It demands a certain level of control over the devices, enforcing policy such as password complexity, screen timeouts, remote lock out and remote wipe functionality. This behavior is usually accepted by the user via a prompt when they first connect to Exchange. However, the protocol for updating these policies provides very little in the way of security and is quickly accepted by the device, often with no user interaction required. In this talk we will focus on the remote wipe functionality and how a potential attacker could abuse this functionality to remotely wipe devices that are connected to Exchange. By impersonating an Exchange server and sending appropriate policy updates through a simple script we are able to erase all data on devices remotely without any need for authentication. The presentation will explain how this can be accomplished and show proof of concept code for Android & iOS devices. Peter Hannay is a PhD student, researcher and lecturer based at Edith Cowan University in Perth Western Australia. His PhD research is focused on the acquisition and analysis of data from small and embedded devices. In addition to this he is involved in smart grid & network security research and other projects under the banner of the SECAU research organisation. Peter is an accomplished academic, with more than 20 publications in peer reviewed conferences and journals, in addition he is a regular speaker at the Ruxcon and Kiwicon hacker conferences taking place in Australia and New Zealand respectively. Twitter:@kronicd http://openduck.com
More from this channel
-
7:53
DEF CON 20 Documentary Bonus Clips - CDC muxed
-
47:43
DEF CON 20 - Raphael Mudge - Cortana: Rise of the Automated Red Team
-
25:01
DEF CON 20 - Ryan Holeman - Passive Bluetooth Monitoring in Scapy
-
48:14
DEF CON 20 - Xeno Kovah and Corey Kallenberg - No More Hooks
-
51:04
DEF CON 20 - Panel - The Making of DEF CON 20
-
50:01
DEF CON 20 - Josh "m0nk" Thomas and Jeff "stoker" Robble - Off-Grid Communications with Android
-
48:06
DEF CON 20 - Mark Weatherford - The Christopher Columbus Rule and DHS
-
50:01
DEF CON 20 - Jason Ostrom, Karl Feinauer, William Borskey - The End of the PSTN As You Know It