Announcement

Collapse
No announcement yet.

"Power Corrupts; Corrupt It Back! Hacking Power Management in Data Centers" Sam Quinn , Jesse Chick

Collapse
X
 
  • Filter
  • Time
  • Show
Clear All
new posts

  • "Power Corrupts; Corrupt It Back! Hacking Power Management in Data Centers" Sam Quinn , Jesse Chick


    Power Corrupts; Corrupt It Back! Hacking Power Management in Data Centers ,

    Sam Quinn, Sr. Security Researcher. Trellix Advanced Research Center, He/Him

    Jesse Chick, Security Researcher. Trellix Advanced Research Center, He/Him

    | Demo, Exploit | 45



    Our current administration lists "Defend Critical Infrastructure" as the #1 item in the 2023 National Cybersecurity Strategy. At the intersection of governmental and corporate concerns is data center security, a trend that is bound to continue as more and more operations move to the cloud. This talk details our findings in the domain of power management, the first category in a broader effort to investigate the security of critical data center components. We will reveal nine vulnerabilities in two integral data center appliances: a Power Distribution Unit (PDU) and a Data Center Infrastructure Management (DCIM) system. Continuing, we will delve into the technical details of the most impactful vulnerabilities and highlight the potential impact on their respective operations. The talk will challenge the misconception that data centers are inherently more secure than on-prem by exposing how attackers could leverage these vulnerabilities. This presentation will be valuable to data center professionals, security researchers, and anyone interested in understanding the characteristic vulnerabilities associated with modern data centers.



    Sam Quinn is a Senior Security Researcher on the Advanced Research Center Vulnerability team, focused on finding new vulnerabilities in both software and hardware. Sam has a focus on embedded devices with knowledge in the fields of reverse engineering and exploitation. He has had numerous vulnerability findings, published CVEs in IOT and enterprise software, and has spoken at multiple industry conferences such as Def Con, BlackHat, North Sec, and Hardwear.io.

    @eAyeP




    Jesse Chick is a Security Researcher with the Advanced Research Center's vulnerability team. Jesse focusses on vulnerability discovery and exploit development for all things connected to the internet and is credited with numerous CVEs affecting popular embedded devices. He is passionate about reverse engineering, full system emulation, and educating others in offensive security techniques.

    @ravenousbytes


    REFERENCES:

    Contributing Researcher - Philippe Laulheret
    Claroty Research - https://claroty.com/team82/research/...ectric-devices
    National Cybersecurity Strategy - https://www.whitehouse.gov/briefing-...rity-strategy/ ,
    Last edited by number6; July 31, 2023, 13:36.
Working...
X