BEGIN:VCALENDAR
VERSION:2.0
PRODID:Data::ICal 0.24
BEGIN:VEVENT
DESCRIPTION:   'Title: Looking and Peering: Attacking from beyond BGP Adjac
 ency\n   Tags: DEF CON Official Talk | Demo 💻 | Exploit 🪲\n   When: 
 Saturday\, Aug 8\, 14:30 - 15:30 PDT\n   Where: LVCCW Level 1 Hall 3 904 (
 Main Track 4) and DCTV-4 - [1]Map\n\n   Description:\n\n   The internet is
  fragile. A single misconfiguration in BGP can cause\n   worldwide outages
 . There have been various efforts to harden BGP\, like\n   BGPsec\, RPKI\,
  and MANRS\, but those mostly address route validation.\n   The session-le
 vel boundary that everything else rests on is adjacency\n   trust. If your
  router only connects to trusted peers\, the router\n   should be safe. Th
 at assumption shaped a lot of the security design\n   around BGP: peer whi
 telisting\, MD5 / TCP-AO authentication\, GTSM (RFC\n   5082) using TTL to
  enforce that a peer is one hop away.\n\n   In this talk\, we look beyond 
 that boundary. Building on Route to Bugs\n   (dos Santos & Guiot\, DC31) a
 nd From Spoofing to Tunneling (123ojp\,\n   DC33)\, we demonstrate three v
 ectors that undermine the assumption. We\n   hijack a trusted peer through
  pre-auth command injection in BGP\n   monitoring tools. We abuse tunnel i
 njection to establish adjacency\n   from off-path\, and chain into a heap 
 UAF for unauthenticated RCE. We\n   turn implementation disagreement betwe
 en FRR\, BIRD\, and other daemons\n   into a weapon: we craft UPDATEs that
  one router type happily re-emits\n   while causing denial of service in a
  different implementation.\n\n   BGP: - Route to Bugs:\n   https://i.black
 hat.com/BH-US-23/Presentations/US-23-dosSantos-Route-to-Bugs-Analyzing-the
 -Security-of-BGP.pdf\n\n   Tunnel injection: - From spoofing to tunneling:
 \n   https://i.blackhat.com/BH-USA-25/Presentations/USA-25-Tung-From-Spoof
 ing-To-Tunneling-New.pdf?_ga=2.41373794.1394109082.1756795982-2018511848.1
 751622634\n   - Free VPNs everywhere — tunnel injection:\n   https://blo
 g.chummydns.com/blogs/tunnel-injection-english/ - Hunted by\n   legacy: di
 scovering and exploiting vulnerable tunneling hosts:\n   https://www.useni
 x.org/system/files/usenixsecurity25-beitis.pdf\n\n   Looking glasses: - Th
 rough the looking-glass and what eve found there:\n   https://www.usenix.o
 rg/system/files/conference/woot14/woot14-bruno.pdf\n   - Looking glass res
 earch WOOT2014 / DEFCON 22:\n   https://blog.talosintelligence.com/looking
 -glasses-with-bacon/\n\n   SpeakerBio:  Bo-Shiun "bronson113" Yen\, Calif.
 io\n\n   Bronson Yen (@bronson113) is a security researcher working at [2]
 Calif.io.\n   He has experience in researching networking equipment and ha
 rdware\n   attacks\, with a focus on binary exploitation and cryptography.
  He\n   previously presented at HITCON for his work in router exploitation
 .\n\n   '\n\n   1. #LVCCW_Level1_Hall3\n   2. http://calif.io/\n\n\n
DTEND:20260808T223000Z
DTSTART:20260808T213000Z
LOCATION:DEF CON Talks - LVCCW Level 1 Hall 3 904 (Main Track 4) and DCTV-4
SUMMARY:Looking and Peering: Attacking from beyond BGP Adjacency
END:VEVENT
END:VCALENDAR
