Главная
Study mode:
on
1
Intro
2
Disclaimer
3
3 to DARPA
4
The Problem: Smartphones in the Workplace
5
Threats against smartphones: Apps
6
Threats against smartphones: software bugs
7
Threats against smartphones: social engineering • Users can be tricked into opening malicious links
8
Threats against smartphones: jailbreaking
9
The Question
10
What's out there now? Pentesting from Smartphones: zAnti
11
Structure of the framework
12
Framework console
13
Framework GUI
14
Framework Smartphone App
15
What you can test for
16
Remote Vulnerability Example
17
Client Side Vulnerability Example Smartphone browsers, etc. are subject to vulnerabilities
18
Social Engineering Vulnerability Example SMS is the new email for spam/phishing attacks
19
Local Vulnerability Example
20
Post exploitation
21
Mitigating Strategies
22
Future of the Project
Description:
Explore the world of smartphone security in this 56-minute conference talk from BruCON Security Conference. Delve into the Smartphone Penetration Testing Framework, a DARPA Cyber Fast Track project, designed to assess the security of mobile devices in corporate environments. Learn about unique attack vectors specific to smartphones and how this open-source toolkit addresses various aspects of security assessment. Discover the framework's capabilities in information gathering, exploitation, social engineering, and post-exploitation through both traditional IP networks and mobile modems. Gain insights into using the framework via command line console, graphical user interface, and smartphone app. Witness demonstrations of the framework assessing multiple smartphone platforms and understand its potential for security teams and penetration testers. Explore threats such as malicious apps, software bugs, social engineering, and jailbreaking. Examine remote, client-side, social engineering, and local vulnerability examples, as well as post-exploitation techniques and mitigating strategies. Get a glimpse into the future of this project and its implications for smartphone security in the workplace. Read more

Introducing the Smartphone Penetration Testing Framework

BruCON Security Conference
Add to list