The Exploit

Just For Fun

What We Brought Home from DEF CON 34

What We Brought Home from DEF CON 34

Members of the Raxis pentest team joined me last week at the Las Vegas Convention Center for DEF CON 34. As always, we came home with more homework than souvenirs. 

This year’s theme was “Agency,” a call to take back control of the technology that increasingly makes decisions for us. The idea showed up everywhere, right down to the badge itself, an open and fully inspectable device from Bunnie Huang that doubles as a hardware security token you can actually audit.

A few sessions landed especially close to the work we do every day.

Identity Is Still the Shortest Path In

One session walked through escalating from a low-privilege foothold to full domain compromise by way of Active Directory Certificate Services. Another detailed novel vulnerabilities that force a Kerberos downgrade. Neither is exotic. Both describe the kind of misconfiguration our team finds routinely on internal engagements, and both are worth checking in your environment.

Trust Is Weaponized

A researcher demonstrated turning legitimate Microsoft applications into a phishing platform, which means the sender your users have been trained to trust becomes the delivery mechanism. Another showed a persistent browser-in-the-middle technique that survives the controls most organizations assume will stop credential theft.

The Devices Around Us Aren’t Secure

A dealer-installed anti-theft system exposed more than a million vehicles over Bluetooth. A single wildcard certificate exposed 1.1 million cameras sitting behind an IoT cloud. These are not research curiosities. They are the same class of vendor shortcut we find on client networks.

AI Moved from Novelty to Infrastructure

Last year the AI conversation was mostly about what these tools might eventually do. This year it was about breaking the runtimes and agent sandboxes that organizations have already deployed. If your company adopted an AI platform in the past twelve months, it is now part of your attack surface whether or not anyone has tested it.

Our Takeaways

Before attending DEF CON this year, our team worked the Raxis booth at Black Hat, and this ties directly to what we saw there. There are several pentest companies that want organizations to trust their security to automated processes and AI without humans taking part in the process. While that saves money on testing, it misses the key attacks that are the biggest threats.

What I keep coming back to is DEF CON’s theme. Agency means knowing what your systems are actually doing instead of trusting that someone else (or some system) has handled it. That is the entire premise of a good human-led penetration test, and it is why we make the trip every August.

Keep Reading

Request a quote

Tell Us What You Need Tested

We usually respond in one business day.

Please let us know what's on your mind. Include any details about your target environment, timeline, or compliance drivers.