DiscoverDEF CON 23 [Audio] Speeches from the Hacker ConventionLuke Young - Investigating the Practicality and Cost of Abusing Memory Errors with DNS
Luke Young - Investigating the Practicality and Cost of Abusing Memory Errors with DNS

Luke Young - Investigating the Practicality and Cost of Abusing Memory Errors with DNS

Update: 2015-10-30
Share

Description

Investigating the Practicality and Cost of Abusing Memory Errors with DNS

Luke Young Information Security Engineer, Hydrant Labs LLC



In a world full of targeted attacks and complex exploits this talk explores an attack that can simplified so even the most non-technical person can understand, yet the potential impact is massive:



Ever wonder what would happen if one of the millions of bits in memory flipped value from a 0 to a 1 or vice versa? This talk will explore abusing that specific memory error, called a bit flip, via DNS.



The talk will cover the various hurdles involved in exploiting these errors, as well as the costs of such exploitation. It will take you through my path to 1.3 million mis-directed queries a day, purchasing hundreds of domain names, wildcard SSL certificates, getting banned from payment processors, getting banned from the entire Comcast network and much more.



Luke Young (@innoying) - is a freshman undergraduate student pursuing a career in information security. As an independent researcher, he has investigated a variety of well-known products and network protocols for design and implementation flaws. His research at various companies has resulted in numerous CVE assignments and recognition in various security Hall of Fames. He currently works as an Information Security Intern at LinkedIn.



Twitter: @innoying

LinkedIn: www.linkedin.com/in/innoying

Comments 
In Channel
loading
00:00
00:00
x

0.5x

0.8x

1.0x

1.25x

1.5x

2.0x

3.0x

Sleep Timer

Off

End of Episode

5 Minutes

10 Minutes

15 Minutes

30 Minutes

45 Minutes

60 Minutes

120 Minutes

Luke Young - Investigating the Practicality and Cost of Abusing Memory Errors with DNS

Luke Young - Investigating the Practicality and Cost of Abusing Memory Errors with DNS

DEF CON Announcements