Explore the dark side of log manipulation in this 41-minute Black Hat conference talk. Delve into the world of ANSI escape sequences and their potential for injecting, vandalizing, and weaponizing logfiles in modern applications. Revisit old terminal injection research and log tampering techniques from the 80s and 90s, and discover how they can be combined with new features to create chaos in today's cloud CLIs, mobile devices, and DevOps terminal emulators. Learn about the vital role of logs in maintaining application reliability, performance, and security, and understand how they can be exploited to compromise an application's security. Gain insights from speaker STOK on this forensic nightmare and its implications for developers and security teams.
Overview
Syllabus
Weaponizing Plain Text: ANSI Escape Sequences as a Forensic Nightmare
Taught by
Black Hat