| By Business Wire | Article Rating: |
|
| February 4, 2010 12:35 PM EST | Reads: |
238 |
Core Security Technologies, provider of CORE IMPACT Pro, the most comprehensive product for proactive enterprise security testing, today announced that one of its researchers will serve as a featured presenter at the ShmooCon 2010 ethical hacking convention being held at the Wardman Park Marriott Feb. 5 – 7.
At the conference, Core Security Technical Support Engineer Dan Crowley will offer his latest presentation “Windows File Pseudonyms: Strange filenames” during which he will demonstrate how features not widely known in Windows path and filename normalization routines cause unexpected behavior and allow for potential attacks.
Crowley will specifically highlight how an attacker may be able use the technique to bypass filters, access control lists, intrusion detection systems and other defensive mechanisms, as well as alter the way that files are handled and processed, and make brute force attacks to enumerate files far more easily.
The expert, whose responsibilities include working with Core Security Customers to ensure that they get the most out of their IMPACT Pro deployments, will also disclose and demonstrate real vulnerabilities and techniques for their exploitation developed for the scenarios being proposed.
“The devil really is in the details here,” said Crowley. “And with incomplete and sometimes vague documentation and the lack of source code available for an operating system that has been built and changed over the course of close to two decades now, there are lots and lots of details, most of which need to be understood before appropriate security mechanisms can be designed.”
What: “Windows
File Pseudonyms: Strange filenames and haiku”
When: Friday,
Feb. 5, 2010; 5:30-6p.m. ET
Where: ShmooCon 2010, Wardman Park
Marriott
Who: Dan Crowley, Core Security Technical Support Engineer
Crowley will also defend his title in the “Gringo Warrior” lock bypass competition.
Core Security continues to feed the intelligence garnered via the work of its SCS consultants and CoreLabs research experts directly into its CORE IMPACT family of automated penetration testing solutions to ensure that organizations can proactively determine their exposure to such widely available vulnerabilities.
For more information about the presentation or to schedule meetings with Core Security’s experts at ShmooCon 2010, please contact Tim Whitman or Lauren O’Leary at 781-684-0770 or via email at: coresecurity@schwartz-pr.com.
About Core Security Technologies
Core Security Technologies is the leader in comprehensive penetration testing software solutions that IT executives rely on to expose vulnerabilities, measure operational risk and assure security effectiveness. The company’s CORE IMPACT product family offers a comprehensive approach to assessing the security of network systems, endpoint systems, email users and web applications against complex threats. All CORE IMPACT security testing solutions are backed by trusted vulnerability research and leading-edge threat expertise from the company’s Security Consulting Services, CoreLabs and Engineering groups. Based in Boston, MA and Buenos Aires, Argentina, Core Security Technologies can be reached at 617-399-6980 or on the Web at http://www.coresecurity.com.
Published February 4, 2010 Reads 238
Copyright © 2010 SYS-CON Media, Inc. — All Rights Reserved.
Syndicated stories and blog feeds, all rights reserved by the author.
More Stories By Business Wire
Copyright © 2009 Business Wire. All rights reserved. Republication or redistribution of Business Wire content is expressly prohibited without the prior written consent of Business Wire. Business Wire shall not be liable for any errors or delays in the content, or for any actions taken in reliance thereon.
- Big Data in Telecom: The Need for Analytics
- Patterns for Building High Performance Applications
- What Motivates Open Standards in the Cloud?
- What to Expect in 2012: Cloud Computing and Open Source Software
- Will PaaS Finally Bring Open Source Love to the Enterprise?
- Ten Hot Trends in Cloud Data for 2012
- Cross-Platform Mobile Website Development – a Tool Comparison
- Oracle Disaster Recovery Site Hosted by Amazon Cloud
- Three Buzzwords That Every CIO Hears but One They Should Listen To
- Write Once Run Anywhere or Cross Platform Mobile Development Tools
- Big Data Highlights from McKinsey: Part 2 - Production, Supply, and Logistics
- Microsoft’s New Cloudware Could Cast a Shadow over VMware
- The Future of Cloud Computing: Industry Predictions for 2012
- Gartner Hype Cycle for Emerging Technologies 2011
- Book Excerpt: Introducing HTML5
- Adobe Sends Flex to the Apache Foundation
- Big Data in Telecom: The Need for Analytics
- Book Excerpt: Java Application Profiling Tips and Tricks
- i-Technology in 2012: Five Industry Predictions
- Patterns for Building High Performance Applications
- Microsoft Tries Hadoop on Azure
- The Next Web Architecture
- Cloud Computing: A Comparison of Computing Models
- Amazon to Fix Some Kindle Fire Problems
- The i-Technology Right Stuff
- The Top 150 Players in Cloud Computing
- Who Are The All-Time Heroes of i-Technology?
- Where Are RIA Technologies Headed in 2008?
- Get the Message
- ESB Myth Busters: 10 Enterprise Service Bus Myths Debunked
- i-Technology Viewpoint: Is Web 2.0 the Global SOA?
- i-Technology Viewpoint: Thinking Outside the VC Box
- i-Technology Viewpoint: When to Leave Your First IT Job
- SOA Web Services Edge Conference Coverage on SYS-CON.TV
- SYS-CON.TV's "SOA Web Services" and "Enterprise Open Source" Programs To Air in December
- Five Reasons Why Web 2.0 Matters




















