Showing posts with label Microsoftt Blue Hat. Show all posts
Showing posts with label Microsoftt Blue Hat. Show all posts

Finding the name behind the GMail address

Ah, this is a fun little trick. I’m not sure if it represents a vulnerability, but certainly I expect Google will try to get rid of this feature. The SecuriTeam blog has reported that it is possible to expose the full name of the user who registered a GMail account. This is, of course, contingent on the fact that the person who registered the GMail account didn’t use a fake first and last name, but still, an interesting trick.

The reason this vulnerability exists is due to the strong tie-ins between GMail and all of Google’s other services, such as Google Calendar, Blogger, and Google Code AND the strong desire for Google Apps to be able to share data with people. This isn’t the first time, the second time, or the last time the strong tie-ins have produced interesting results, see my post on Billy Rios’s Google Code exploit, Billy’s taking ownership (pwnership) of content attacks against Google Spreadsheets, Billy and I stealing documents from Google Docs, and see my talk at Black Hat for more.

The steps to accomplish this are as follows:

  1. Sign up for Google Calendar
  2. Go to the ’share this calendar’ tab
  3. Enter the email address in the ‘person’ box
  4. Click ‘add person’ and ’save’
  5. When you return to this screen you will see the first and last name along with the gmail address
Read the rest of this entry

[Source: zdnet]

Hackers in Seattle for Microsoft’s Blue Hat, ToorCon

White hat hackers have descended on Seattle for two semi-private security conferences where new attack and exploitation techniques are being discussed.

The first is the Spring 2007 edition of Microsoft's Blue Hat Security Briefings where researchers are invited to Redmond "to share knowledge and to educate and help protect customers against common threats."David Maynor

This is the fifth series of Blue Hat briefings and, as usual, Microsoft is hush-hush about the list of attendees and presenters.  IDG's Robert McMillan was able to find out the names of a few hackers on the speaker list — Robert Hansen (RSnake), David Maynor, John Hering and Rob Thomas — but details are very scarce.

A source tells me Maynor (pictured) and Robert Graham, co-founders at Errata Security, are talking about how to evade security tools and Hansen is giving a presentation on Web application security.

Hardware hacker Bonnie Huang is also giving a talk at Blue Hat. 

Immediately after Blue Hat, the hackers will move to a more informal setting for ToorCon Seattle (Beta), an invite-only get-together of around 100 security professionals.

ToorCon Seattle (Beta) runs from May 11-13 and features a single track of 20 minute talks and 5 minute lightning talks. 

The ToorCon Seattle schedule looks very intriguing. A sample:

  • Sourcefire's Lurene 'Pusscat' Grenier  - Automating exploitation.
  • Dan Griffin -  Hacking Windows Vista Security
  • Microsoft's Adam Shostack — Security breaches are good for you (See this .pdf file for slides on this talk, which was given at SchmooCon earlier this year)
  • RSnake - Master Recon-Tool (Mr. T)
  • IOActive's  Dan Kaminsky - Further Adventures In Visual Data Exploration

[UPDATE: May 10,2007 @ 1:20 PM] Microsoft has just posted the session descriptions and speaker bios for Blue Hat v5.  Andrew Cushman explains on the MSRC blog that the content centers around Microsoft's newest products like XBos, Mobile, Security Products and Web Apps.  Sarah Blankinship has more on the official Blue Hat blog.

[Source :Zdnet]