misasia logo
Global experts’ debate to include BlackBerry spying and ATM hacking By AvantiKumar
05 Oct 2009

KUALA LUMPUR, 5 OCTOBER 2009 – Cloud clobbering, ATM hacking and BlackBerry spying are some of the themes at the 7th Hack in The Box Security Conference ((HITBSecConf) in Malaysia.

Conference organisers said some of the most exciting mainstream and underground ICT security experts are in Kuala Lumpur, October 7-8, to discuss a range of relevant hardware and software security topics.

Sensepost technical director Haroon Meer said that his talk—Clobbering the Cloud—is an examination of the new technologies in, as well as the various risks and vulnerabilities of the new systems behind Cloud Computing,

ZenConsultant head of research and development, Sheran Gunasekera, said that while the BlackBerry has always enjoyed a reputation for being a secure platform without a single vulnerability reported on it for the past two years, he will show how the handhelds can be compromised to sniff user’s email (and optionally instant messages, web browsing traffic, and SMS messages).

Hack In The Box (HITB) is the owner and organiser of HITBSecConf, the largest network security conference in Asia and the Middle East. HITBSecConf has been held in Malaysia since 2003 and is endorsed by the Malaysian Communications and Multimedia Commission (MCMC), the Malaysian International Chamber of Commerce and industry (MICCI), the Malaysian National Computer Confederation (MNCC) and the Malaysian Multimedia Development Corporation (MDeC).

ATM vulnerabilities

Other speakers include ENCODE Middle East managing director, Dimitrios Petropoulos, who said: “The cornerstone of every bank’s ATM network is a number of HSMs [Hardware Security Modules], which securely create, store, verify, translate and ultimately destroy the verification PINs [Personal Identification Numbers] associated with each debit/credit card.”

“However, the protocols used and the APIs [Application Programming Interface] exposed by the HSMs are known to suffer from a number of inherent vulnerabilities that open the system to a wide range of attacks, from the trivial to highly complex, all of which lead to the same result—the unauthorised disclosure of large numbers of client PINs,” said Petropoulos, adding that he would give examples of some successful recent attacks perpetrated using the described vulnerabilities.

Comments

Be the first to comment.


Post your comment

  • Please use English to post and reply to comments
  • Please do not use offensive language in the form of racial or ethnic slurs, abuse or personal insults
  • We welcome opinion and debate geared towards finding solutions
  • Please keep comments relevant to the topic
  • All comments are moderated
** Mandatory Field

Name
    **

Email
    **

Country


Comments
Maximum characters allowed: 2000
Disclaimer: All the content posted in this category comes independently from readers of Fairfax Business Media (FBM) Asia publications, unless specified otherwise. Fairfax Business Media (FBM) is not responsible for the opinions of its readers and the content posted by them does not represent the views and opinions of FBM.

Also of Interest

Beach Reading

IT Management

CIOs reveal their picks for beach reads

By Mary K. Pratt
Panasonic 3D

Digital Cameras

Panasonic debuts first consumer 3D camcorders

By Martyn Williams
Julian Assange

Security

Wikileaks releases 92,000 hidden Afghan war docs

By The Sydney Morning Herald

Feature

Zafar Anjum

Techlightenment

Cinema and Technology: Inception

As I exited the multiplex, I was wondering if we and our physical world, the universe, are really parts of a maya jaal, the Hindu concept of a web of illusion, a mere dream inside the head of God.
By Zafar Anjum | 27 Jul 2010

RSS Feeds

Add this section to your favourite feed reader.