Skip to content

Details

Hey all!

We'll be having Mario Heiderich (@0x6d6172696f) in town all the way from Germany to drop some knowledge on one of the most basic components of a desktop operating system: the clipboard. No joke.

Dr. Mario is a true web wizard. From my perspective, Mario's Twitter account might as well be a bot spitting out random text since I can't make sense of his l33tness. He's on an entirely different plane of existence when it comes to web security. It's like rsnake's old XSS cheatsheet on LSD. To him, same-origin policy is just a friendly suggestion from the browser. Websites will frequently return 404s and hide instead of processing Mario's HTTP requests.

So, you should probably come out and see his talk! Can't wait to see him apply his skillz to something as fun(damental)w as copy and paste. Hope to see you there!

Title:

Copy and Pest: A case-study on the clipboard, blind trust and invisible cross-application XSS

Abstract:

The clipboard is one of the most commonly used tools across operating systems, window managers and devices. Pressing Ctrl-C and Ctrl-V has become so fundamentally important to productivity and usability that we cannot get rid of it anymore. We happily and often thoughtlessly copy things from one source and paste them into another. URLs into address-bars, lengthy commands into console windows, text segments into web editors and mail interfaces. And we never worry about security when doing so. Because what could possibly go wrong, right?

But have we ever asked ourselves what the clipboard content actually consists of? Do we really know what it contains? And are we aware of the consequences a thoughtless copy&paste interaction can have? Who else can control the contents of the clipboard? Is it really just us doing Ctrl-C or is there other forces in the realm who are able to infect what we believe to be clean, who can desecrate what we trust so blindly that we never question or observe it? This talk is about the clipboard and the technical details behind it. How it works, what it really contains – and who can influence its complex range of contents.

We will learn about a new breed of targeted attacks, including cross-application XSS from PDF, ODT, DOC and XPS that allow to steal website accounts faster than you can click, turn your excel sheet into a monster and learn about ways to smuggle creepy payload that is hidden from sight until it executes. Oh, and we’ll also see what can be done about that and what defensive measures we achieved to create so far.

Bio:

Mario Heiderich works as a researcher for the Ruhr-University in Bochum, Germany, focuses on HTML5, SVG security and believes XSS can be eradicated by using JavaScript. Maybe. Some day. Mario invoked the HTML5 security cheat-sheet and maintains the PHPIDS filter rules. In his spare time he delivers trainings and security consultancy for larger German and international companies for sweet sweet money and the simple minded fun in breaking things. Mario has spoken on a large variety of international conferences, co-authored two books, several academic papers and doesn’t see a problem in his some weeks old son having a netbook already. There you have it.

http://photos3.meetupstatic.com/photos/event/2/2/2/b/600_435308747.jpeg

Streaming live on Youtube for those who can't make it.

http://duo.sc/techtalk-april2015

Related topics

You may also like