Mark Curphey (Director, Microsoft Corp)
Cesar Cerrudo (Founder / CEO ArgenISS)
Saumil Shah (Founder CEO Net-Square)
Shreeraj Shah (Founder, BlueInfy)
Fredric Raynal (Sogeti/Cap Gemini)
Robert Hansen (rsnake) (SecTheory)
Alexander Kornburst (Red Database)
Emmanuel Gadaix (Founder, TSTF)
Andrea Barisani (Inverse Path)
Ed Skoudis (InGuardians)
Haroon Meer (Sensepost)
Mark Curphey (Director, Microsoft Corp)
Cesar Cerrudo (Founder / CEO ArgenISS)
Saumil Shah (Founder CEO Net-Square)
Shreeraj Shah (Founder, BlueInfy)
Fredric Raynal (Sogeti/Cap Gemini)
Robert Hansen (rsnake) (SecTheory)
Alexander Kornburst (Red Database)
Emmanuel Gadaix (Founder, TSTF)
Andrea Barisani (Inverse Path)
Ed Skoudis (InGuardians)
Haroon Meer (Sensepost)
Mark Curphey (Director, Microsoft Corp)
Cesar Cerrudo (Founder / CEO ArgenISS)
Saumil Shah (Founder CEO Net-Square)
Shreeraj Shah (Founder, BlueInfy)
Fredric Raynal (Sogeti/Cap Gemini)
Robert Hansen (rsnake) (SecTheory)
Alexander Kornburst (Red Database)
Emmanuel Gadaix (Founder, TSTF)
Andrea Barisani (Inverse Path)
Ed Skoudis (InGuardians)
Haroon Meer (Thinkst)
FileReference.download() allows ActionScript programs to execute the
methods without user interaction (CVE-2008-4401).
* The Settings Manager controls can be disguised as normal graphical
elements. This so-called "clickjacking" vulnerability was disclosed
by Robert Hansen of SecTheory, Jeremiah Grossman of WhiteHat
Security, Eduardo Vela, Matthew Mastracci of DotSpots, and Liu Die Yu
of TopsecTianRongXin (CVE-2008-4503).
* Matthew Dempsky reported a null-pointer dereference flaw when
loading two SWF files compiled with different Flash versions from the
Mark Curphey (Director, Microsoft Corp)
Cesar Cerrudo (Founder / CEO ArgenISS)
Saumil Shah (Founder CEO Net-Square)
Shreeraj Shah (Founder, BlueInfy)
Fredric Raynal (Sogeti/Cap Gemini)
Robert Hansen (rsnake) (SecTheory)
Alexander Kornburst (Red Database)
Emmanuel Gadaix (Founder, TSTF)
Andrea Barisani (Inverse Path)
Ed Skoudis (InGuardians)
Haroon Meer (Sensepost)
Black Hat Webcast #5 is scheduled for Thursday, November 20 at 1pm PST.
The topic this time is Clickjacking, and our featured guest is Jeremiah
Grossman, the co-discoverer of the widely publicized vulnerability. For the
uninitiated, it's a set of techniques discovered by Jeremiah Grossman and
Robert Hansen that allows an attacker to transparently capture a user's
clicks, forcing the user to do all manner of unpleasant things ranging from
adjusting security settings to unwittingly visiting websites with malicious
code.
The vectors for this attack include all the major browsers and Flash. In