Hacking Medical Devices and Healthcare Infrastructure
Hack In The Box Security Conference via YouTube
Overview
Syllabus
SPEAKER BIO
#whoami
Agenda
Securing hospitals
Understanding medical devices
HL7 - Health Level 7
In a nutshell
HL 72.x crash course
ADT - Admit Discharge and Transfer
ADT - Potential Entry Points
ORM - Order message
ORM - Potential Entry points
ORU - Observation Result
RDE - Pharmacy order message
MDM - Medical Document Management
DFT - Detail Financial Transaction
Recon
Message source not validated
Unvalidated size
Bad server attacks
Denial of service
Abusing file upload / download functionality
Taught by
Hack In The Box Security Conference