BEGIN:VCALENDAR
VERSION:2.0
PRODID:Data::ICal 0.24
BEGIN:VEVENT
DESCRIPTION:   'Title: What To Expect When You’re Exploiting: Attacking a
 nd\n   Discovering Zero-Days in Baby Monitors and Wi-Fi Cameras\n   When: 
 Saturday\, Aug 10\, 11:15 - 11:59 PDT\n   Where: LVCC West/Floor 1/Hall 2/
 Creator Stage 1 - [1]Map\n\n   Description:\n\n   Home surveillance techno
 logy is a modern convenience that has been\n   made accessible to the mass
 es through the rise of IoT devices\, namely\n   cloud-connected Wi-Fi came
 ras. From parents monitoring their infants\n   to homeowners watching thei
 r entryways\, these cameras provide users\n   with access to instant\, hig
 h definition video from the convenience of\n   a mobile phone\, tablet\, o
 r PC. However\, the affordability of these\n   devices and relative ease o
 f cloud access generally correlates to\n   flawed security\, putting users
  at risk. We set out to explore the\n   attack surface of various Wi-Fi ca
 mera models to gain a deeper\n   understanding of how these devices are be
 ing exploited. In the end\, we\n   devised methods to gain local root acce
 ss\, uncovered user privacy\n   issues\, discovered a zero-day vulnerabili
 ty within a prominent IoT\n   device management platform that allows attac
 kers to gain remote\n   control of millions of cameras worldwide and acces
 s sensitive user\n   data\, and revealed how these devices may be vulnerab
 le to remote code\n   execution attacks through completely unauthenticated
  means thanks to\n   an inherently flawed implementation of their underlyi
 ng peer to peer\n   networking protocol. Along with demonstrating our expl
 oits against\n   live cameras\, we will highlight the methods used to obta
 in our most\n   significant findings and provide guidance on remediating t
 he issues we\n   encountered so these devices can be used safely in your h
 ousehold. We\n   will also invite audience members to probe and attack a c
 amera during\n   our talk and earn a prize in the process!\n\n   Speakers:
 Eric Forte\,Mark Mager\n\n   SpeakerBio:  Eric Forte\, Security Research E
 ngineer at Elastic\n\n   Eric Forte is a Security Research Engineer at Ela
 stic with a\n   background in embedded systems and streaming data analysis
 . He has\n   worked in technical leadership roles in engineering Low Size 
 Weight\n   and Power (SWaP) capabilities and network security solutions. A
 s part\n   of this work\, he managed an IoT research and reverse engineeri
 ng lab\n   to help in the development of these different capabilities for 
 various\n   organizations across the United States.\n\n   SpeakerBio:  Mar
 k Mager\, Lead\, Endpoint Protections Team at Elastic\n\n   Mark Mager lea
 ds the Endpoint Protections Team at Elastic. He has\n   served in prominen
 t technical leadership roles in the research and\n   development of advanc
 ed computer network operations tools and has\n   provided malware analysis
  and reverse engineering subject matter\n   expertise to government and co
 mmercial clients in the Washington\, D.C.\n   metropolitan area.\n\n   '\n
 \n   1. #LVCCW_Level1_Hall2\n\n\n
DTEND:20240810T185900Z
DTSTART:20240810T181500Z
LOCATION:IOTV - LVCC West/Floor 1/Hall 2/Creator Stage 1
SUMMARY:What To Expect When You’re Exploiting: Attacking and Discovering 
 Zero-Days in Baby Monitors and Wi-Fi Cameras
END:VEVENT
END:VCALENDAR
