Overview
Syllabus
Intro
Today's topic: bug bounties
Introducing Adobe Flash
Embedding Flash code
Flash security sandboxes
Local by definition - Flash
Escaping the local sandbox (2/2)
Exfiltrating files out of sandbox
SMB authentication
SMB Relay attack (2008)
NTLMv2 hashes
Attack variant: SMBTrap
CVE-2016-4271: discussion (1/2)
The (revised) remote sandbox
SMB attacks, revisited (1/2)
Testing for susceptibility: basic idea
Testing for susceptibility: first try
Side track: cross-domain policy file
Testing for susceptibility: second try
CVE-2017-3085: discussion (1/3)
CVE-2017-3085: discussion (3/3)
Concluding remarks
Want to break stuff?
Taught by
Cooper