Главная
Study mode:
on
1
Intro
2
Agenda
3
Background
4
Revenue Market Share
5
Polycom HDX Systems
6
Attack Surface
7
Firmware Analysis
8
PUP File Structure
9
PUP Header
10
Header HMAC
11
Public Key DSA Signature
12
HDX Boot Modes
13
Enabling Development Mode
14
Polycom Command Shell
15
Device Rooting - Method #2
16
Problems with previous Methods
17
Device Rooting - Method #3
18
System Architecture
19
Filesystem
20
Configuration Files
21
Main Processes
22
AppMain Java Process
23
Polycom AVC
24
Remote Debugging
25
Watchdog Daemon
26
Ready for Bug Hunting...
27
H.323 Protocol
28
H.323 Signaling Protocols
29
Call Initiation
30
Call Detail Records
31
Vulnerabilities
32
SQL Injection Exploit Challenges
33
Vulnerability #2
34
Exploiting the Format String Bug
35
Post Exploitation
36
Polycom XCOM IPC
37
Polycom Disclosure Process
Description:
Explore the world of hacking video conferencing systems in this Black Hat EU 2013 conference talk. Delve into a comprehensive case study on Polycom HDX devices, uncovering vulnerabilities in high-end videoconferencing systems commonly deployed in critical corporate locations. Learn how to analyze software update file formats, gain system-level access to closed devices, and set up a vulnerability development environment. Witness a demonstration of remotely compromising Polycom HDX devices over the network by exploiting vulnerabilities in the H.323 stack. Discover post-exploitation techniques, including methods to control attached peripherals like video cameras and microphones, potentially leading to the creation of a surveillance rootkit. Gain insights into the device architecture, filesystem, configuration files, and main processes of these systems. Explore the intricacies of the H.323 protocol, call initiation, and call detail records. Understand the challenges of SQL injection exploits and format string bugs. Finally, learn about the Polycom disclosure process and the implications of these security findings for the videoconferencing industry. Read more

Hacking Video Conferencing Systems

Black Hat
Add to list
0:00 / 0:00