Overview
Syllabus
Intro
Alice and Bob at the Black Hat Clinic
What is Clinical Productivity Software?
Decrypting Client Side Data
Clinical Productivity System Findings
What is a Drug Dispensary?
Authenticated Users and Configuration Files
SQL Account Decryption
UA* Account Decryption
Drug Cabinet System Findings
Clinical Imaging System
IDA Review Process
Patching the Binary
Administrator Tool Patched
Imaging System Findings
Downtime Device Security
Crack the Hash
Cracking Downtime Device Hashes
Generic User Space
Privileged Escalation
Downtime Device Key Extract
Downtime Device Findings
Findings Summary
Red Flag Indicators
What are we doing at Penn Med?
Where to from here?
Taught by
Black Hat