DEF CON 15 - Meer and Slaviero - Its All About the Timing
279 views · Published 4 February 2014 · 49:29 · Indexed 25 September 2026
Channel: DEFCONConference · 2014 · Science & Technology
Haroon Meer & Marco Slaviero: It's All About the Timing Timing attacks have been exploited in the wild for ages. In recent times timing attacks have largely been relegated to use only by cryptographers and cryptanalysts. In this presentation SensePost analysts will show that timing attacks are still very much alive and kicking on the Internet and fairly prevalent in web applications (if only we were looking for them). The talk will cover SensePost-aTime (our new SQL Injection tool that operates purely on timing differences to extract data from injectable sites behind draconian firewall rulesets), our new generic (timing aware) web brute-forcer and lots of new twists on old favorites. We will discuss the implications of timing on current JavaScript malware discussing XSRT (Cross Site Request Timing)(because we can never have too many acronyms!) and will demonstrate how reasonably effective this is against the "Same Origin Policy". If you are doing testing today, and are not thinking a lot about timing, chances are you are missing attack vectors right beneath your stop-watch! Haroon Meer is the Technical Director of SensePost. He joined SensePost in 2001 and has not slept since his early childhood. He has co-authored several technical books on Information Security and has spoken and trained at conferences around the world. He has played in most aspects of IT Security from development to deployment and currently gets his kicks from reverse engineering, application assessments and similar forms of pain. Marco Slaviero is a senior security analyst, avid reader and recovering student. He is currently a PHd candidate and a valuable member of SensePosts Security Assessment team. He doesn't smoke and is rumored to harbor personal animosity towards figs.
More from this channel
-
7:53
DEF CON 20 Documentary Bonus Clips - CDC muxed
-
47:43
DEF CON 20 - Raphael Mudge - Cortana: Rise of the Automated Red Team
-
43:15
DEF CON 20 - Peter Hannay - Exchanging Demands
-
49:37
DEF CON 20 - Richard Thieme - Twenty Years Back Twenty Years Ahead
-
25:01
DEF CON 20 - Ryan Holeman - Passive Bluetooth Monitoring in Scapy
-
48:14
DEF CON 20 - Xeno Kovah and Corey Kallenberg - No More Hooks
-
43:51
DEF CON 20 - Wesley McGrew - SCADA HMI and Microsoft Bob
-
51:04
DEF CON 20 - Panel - The Making of DEF CON 20