The Adventures of AV and the Leaky Sandbox
2,321 views · Published 30 May 2018 · 51:37 · Indexed 23 September 2026
Channel: Black Hat · 2018 · Travel & Events
In this presentation, we describe and demonstrate a novel technique for exfiltrating data from highly secure enterprises whose endpoints have no direct Internet connection, or whose endpoints' connection to the Internet is restricted to hosts used by their legitimately installed software. Assuming the endpoint has a cloud-enhanced antivirus product installed, we show that if the anti-virus product employs an Internet-connected sandbox in its cloud, it in fact facilitates such exfiltration. By Itzik Kotler & Amit Klein Full Abstract & Presentation Materials: https://www.blackhat.com/us-17/briefings.html#the-adventures-of-av-and-the-leaky-sandbox
More from this channel
-
1:00:09
Black Hat USA 2000 - Advanced Windows NT/2K Security (II)
-
56:16
Black Hat USA 2000 - Defending Windows 2000 on the Internet
-
1:25:09
Black Hat USA 2002 - Professional Source Code Auditing
-
1:01:46
Black Hat EU 2003 - Briefing
-
1:30:54
Black Hat Windows 2004 - Data Hiding On A Live (NTFS) System
-
1:14:00
Black Hat EU 2001 - Protecting your IP Network Infrastructure
-
1:15:10
Black Hat Windows 2002 - The Devil Inside: Planning Security in Active Directory Design
-
1:33:04
Black Hat Windows 2004 - Hardening Windows Servers