nCircle.com >> 360 Security

« cansecwest/core06 "Metaexploitation" | Main | SCADAGard SIG To Be Established »

cansecwest/core06: last two things from day one

The day ended with a tool that is effective in evaluating the Host IPS (HIPS) to the point where it can be evaded. Julien Tinnes - France Telecom R&D and the tool is called Slipfest (HIPS evaluation toolkit). It was his first presentation ever but the tool itself was strong enough to stand on its own.

A quick demo showed how the tool helped defeat the protection offered by Cisco CSA. His research shows that all other HIPS are victim to this toolkit. Nice job.
Check it out for yourself:
slipfest.cr0.org

Lastly, a panel was formed to speak about the commercialization of vulnerability research. I’m not going to say much about this other than it was poorly moderated. From the start, the argument for the debate was not clearly stated and at any one point in time, it was hard to tell if the object was the knowledge of a vulnerability or if it was a working exploit. These were not stupid people on the panel, it was just poorly moderated and I found it frustrating. Why? Because it is a complicated multi-dimensional problem and in order to move forward, a more structured debate is needed. Maybe next year.

Comments (1)

you can download the HIPS evaluation suite and toolkit from http://slipfest.cr0.org/

Post a comment

(If you haven't left a comment here before, you may need to be approved by the site owner before your comment will appear. Until then, it won't appear on the entry. Thanks for waiting.)

About

This page contains a single entry from the blog posted on April 6, 2006 12:40 AM.

The previous post in this blog was cansecwest/core06 "Metaexploitation".

The next post in this blog is SCADAGard SIG To Be Established.

Many more can be found on the main index page or by looking through the archives.