35C3 - In Soviet Russia Smart Card Hacks You

Title:
35C3 - In Soviet Russia Smart Card Hacks You
Description:

https://media.ccc.de/v/35c3-9346-in_soviet_russia_smart_card_hacks_you

The classic spy movie hacking sequence: The spy inserts a magic smart card provided by the agency technicians into the enemy's computer, … the screen unlocks … What we all laughed about is possible!

Smartcards are secure and trustworthy. This is the idea smart card driver developers have in mind when developing drivers and smart card software. The work presented in this talk not only challenges, but crushes this assumption by attacking drivers using malicious smart cards.

We will present a fuzzing framework for *nix and Windows along with some interesting bugs found by auditing and fuzzing smart card drivers and middleware. Among them classic stack and heap buffer overflows, double frees, but also a replay attack against smart card authentication.

Since smart cards are used in the authentication process, a lot of vulnerabilities can be triggered by an unauthenticated user, in code running with high privileges. During the author's research, bugs were discovered in OpenSC (EPass, PIV, OpenPGP, CAC, Cryptoflex …), YubiKey drivers, pam_p11, pam_pkc11, Apple's smartcard-services and others.

Eric Sesterhenn

https://fahrplan.events.ccc.de/congress/2018/Fahrplan/events/9346.html

more » « less
Video Language:
English
Duration:
38:16
http://www.youtube.com/watch?v=8j7NqeHYxoQ
Format: Youtube
Primary
Original
Added   by C3Subtitles
Format: Youtube
Primary
Original
http://www.youtube.com/watch?v=cl9ElZta0ZE
Format: Youtube
Added   by C3Subtitles
Format: Youtube
http://www.youtube.com/watch?v=c_86Oy1NysI
Format: Youtube
Added   by C3Subtitles
Format: Youtube
This video is part of Amara Public.

Subtitles download

Incomplete subtitles (1)