Assessing and Exploiting BigNum Vulnerabilities

Assessing and Exploiting BigNum Vulnerabilities

Black Hat via YouTube Direct link

The patch

10 of 18

10 of 18

The patch

Class Central Classrooms beta

YouTube videos curated by Class Central.

Classroom Contents

Assessing and Exploiting BigNum Vulnerabilities

Automatically move to the next video in the Classroom when playback concludes

  1. 1 Intro
  2. 2 Outline
  3. 3 Motivation: break crypto, maybe?
  4. 4 Introduction to BigNum Arithmetic
  5. 5 Widely used implementations
  6. 6 Anatomy of CVE-2014-3570
  7. 7 OpenSSL's impact assessment (1/2)
  8. 8 Counterargument
  9. 9 GMP 5 mult bugs
  10. 10 The patch
  11. 11 Bug pattern: carry mispropagation
  12. 12 libgcrypt 1.6.0
  13. 13 Symbolic Execution Challenges
  14. 14 Galois' SAW
  15. 15 Alternative property-based bug hunting
  16. 16 Fuzzing
  17. 17 Conclusions
  18. 18 Bibliography

Never Stop Learning.

Get personalized course recommendations, track subjects and courses with reminders, and more.

Someone learning on their laptop while sitting on the floor.