Artwork

内容由Bruce Bracken提供。所有播客内容(包括剧集、图形和播客描述)均由 Bruce Bracken 或其播客平台合作伙伴直接上传和提供。如果您认为有人在未经您许可的情况下使用您的受版权保护的作品,您可以按照此处概述的流程进行操作https://zh.player.fm/legal
Player FM -播客应用
使用Player FM应用程序离线!

From Specs to Security

33:40
 
分享
 

Manage episode 418345829 series 3486243
内容由Bruce Bracken提供。所有播客内容(包括剧集、图形和播客描述)均由 Bruce Bracken 或其播客平台合作伙伴直接上传和提供。如果您认为有人在未经您许可的情况下使用您的受版权保护的作品,您可以按照此处概述的流程进行操作https://zh.player.fm/legal

Dor Dali, Head of Security Research at Cyolo, joins Nic Fillingham on this week's episode of The BlueHat Podcast. They delve into Dor's journey into cybersecurity, from pranking friends as a teenager to his professional roles, including his involvement in the Blue Hat conference through GE, where he helped create the Capture The Flag (CTF) challenge. Dor details the vulnerabilities in the RDP protocol by closely following the protocol specifications and identifying discrepancies that led to security flaws. They detail a vulnerability related to RDP Gateway's UDP cookie authentication process, the implications of Dor's research for other security researchers and hackers and the importance of leveraging available resources, such as protocol specifications and open-source implementations, to understand closed-source systems better and potentially uncover vulnerabilities.

In This Episode You Will Learn:

  • The unique perspective Dor has with RDP security research
  • How to approach security research when following the protocol specifications
  • The importance of clear documentation in preventing security vulnerabilities

Some Questions We Ask:

  • How did you design and build the Capture the Flag event?
  • Did you face any unexpected hurdles while researching the RDP protocol's security?
  • Have you found other security vulnerabilities by closely adhering to protocol specifications?

Resources:

View Dor Dali on LinkedIn

View Wendy Zenone on LinkedIn

View Nic Fillingham on LinkedIn

Related Microsoft Podcasts:

Discover and follow other Microsoft podcasts at microsoft.com/podcasts


Hosted on Acast. See acast.com/privacy for more information.

  continue reading

41集单集

Artwork
icon分享
 
Manage episode 418345829 series 3486243
内容由Bruce Bracken提供。所有播客内容(包括剧集、图形和播客描述)均由 Bruce Bracken 或其播客平台合作伙伴直接上传和提供。如果您认为有人在未经您许可的情况下使用您的受版权保护的作品,您可以按照此处概述的流程进行操作https://zh.player.fm/legal

Dor Dali, Head of Security Research at Cyolo, joins Nic Fillingham on this week's episode of The BlueHat Podcast. They delve into Dor's journey into cybersecurity, from pranking friends as a teenager to his professional roles, including his involvement in the Blue Hat conference through GE, where he helped create the Capture The Flag (CTF) challenge. Dor details the vulnerabilities in the RDP protocol by closely following the protocol specifications and identifying discrepancies that led to security flaws. They detail a vulnerability related to RDP Gateway's UDP cookie authentication process, the implications of Dor's research for other security researchers and hackers and the importance of leveraging available resources, such as protocol specifications and open-source implementations, to understand closed-source systems better and potentially uncover vulnerabilities.

In This Episode You Will Learn:

  • The unique perspective Dor has with RDP security research
  • How to approach security research when following the protocol specifications
  • The importance of clear documentation in preventing security vulnerabilities

Some Questions We Ask:

  • How did you design and build the Capture the Flag event?
  • Did you face any unexpected hurdles while researching the RDP protocol's security?
  • Have you found other security vulnerabilities by closely adhering to protocol specifications?

Resources:

View Dor Dali on LinkedIn

View Wendy Zenone on LinkedIn

View Nic Fillingham on LinkedIn

Related Microsoft Podcasts:

Discover and follow other Microsoft podcasts at microsoft.com/podcasts


Hosted on Acast. See acast.com/privacy for more information.

  continue reading

41集单集

Minden epizód

×
 
Loading …

欢迎使用Player FM

Player FM正在网上搜索高质量的播客,以便您现在享受。它是最好的播客应用程序,适用于安卓、iPhone和网络。注册以跨设备同步订阅。

 

快速参考指南