Third Time’s a Charm: Solution to Exploitation is not Encryption

No ratings

Presented at BSidesToronto 2018 by

In late 2016, the ZDI had received multiple reports of command injection vulnerabilities residing in Hewlett Packard Enterprise Intelligent Management Center. As of now, HPE has attempted to patch these issues twice. After each patch release, researchers promptly bypass the ineffective patch and exploited the same underlying issues. This talk delves into the root cause of the vulnerabilities and patch diff-ing. Our technical analysis and patch analysis lets you to walk in the shoes of a bug hunter.