BEGIN:VCALENDAR
VERSION:2.0
PRODID:Data::ICal 0.24
BEGIN:VEVENT
DESCRIPTION:   'Title: Exploiting Bluetooth - from your car to the bank acc
 ount$$\n   When: Saturday\, Aug 10\, 16:00 - 16:30 PDT\n   Where: LVCC Wes
 t/Floor 1/Hall 4/Creator Stage 3 - [1]Map\n\n   Description:\n\n   Over th
 e past decade\, infotainment systems experienced a growth in\n   functiona
 lity\, broader adoption and central incorporation into the\n   vehicle arc
 hitecture. Due to the ever-growing role of wireless\n   protocols such as 
 Bluetooth and a known lack of patches alongside the\n   difficulty of patc
 h installation\, this poses a new attack surface and\n   a genuine threat 
 to the users. At the same time\, the tools and\n   methodologies required 
 for testing are scattered across the Internet\,\n   absent and need a rigo
 rous setup.\n\n   In this talk\, we share a comprehensive framework BlueTo
 olkit to test\n   and replay Bluetooth Classic vulnerabilities. We provide
  practical\n   information and tips. Additionally\, we release new exploit
 s and a\n   privilege escalation attack vector.\n\n   We show how we used 
 the toolkit to find 64 new vulnerabilities in 22\n   modern cars and the G
 armin Flight Stream flight management system used\n   in several aircraft 
 types.\n\n   Our work equips Bluetooth hackers with necessary information 
 on novel\n   implementation-specific vulnerabilities that could be used to
  steal\n   information from target cars\, establish MitM position or escal
 ate\n   privileges to hijack victims’ accounts stealthily.\n\n   We beli
 eve our research will be beneficial in finding new\n   vulnerabilities and
  making Bluetooth research more accessible and\n   reproducible.\n\n   Spe
 akers:Vladyslav Zubkov\,Martin Strohmeier\n\n   SpeakerBio:  Vladyslav Zub
 kov\, Bug Bounty Hunter\n\n   Vladyslav Zubkov (aka yso and schwytz) is a 
 bug bounty hunter. He is\n   consistently among the top hackers at live ha
 cking events organized by\n   Meta\, Intel\, Louis Vuitton\, Intigriti and
  YesWeHack. His interests\n   include vulnerability research\, application
  security\, red teaming\, bug\n   bounty hunting\, developing tools and pr
 oactively securing systems.\n\n   SpeakerBio:  Martin Strohmeier\, Senior 
 Scientist at Cyber Defence\n   Campus\n\n   Martin Strohmeier is a Senior 
 Scientist at the Swiss Cyber Defence\n   Campus\, where he is responsible 
 for vulnerability research programmes\n   into aircraft\, satellites and c
 ars. His work was published in all\n   major systems security conferences\
 , totalling more than 100\n   publications to date. He has also spoken pre
 viously at the DEFCON\n   Aerospace Village and co-organized CTFs there.\n
 \n   '\n\n   1. #LVCCW_Level1_Hall4\n\n\n
DTEND:20240810T233000Z
DTSTART:20240810T230000Z
LOCATION:CHV - LVCC West/Floor 1/Hall 4/Creator Stage 3
SUMMARY:Exploiting Bluetooth - from your car to the bank account$$
END:VEVENT
END:VCALENDAR
