BEGIN:VCALENDAR
VERSION:2.0
PRODID:Data::ICal 0.24
BEGIN:VEVENT
DESCRIPTION:   'Title: Zero-Day Provisioning: Chaining TP-Link ZTP Vulnerab
 ilities\n   for Infiltrating Networks\n   Tags: DEF CON Official Talk | De
 mo 💻 | Exploit 🪲\n   When: Saturday\, Aug 8\, 15:30 - 16:30 PDT\n   
 Where: LVCCW Level 1 Hall 3 1007 (Main Track 2) and DCTV-2 - [1]Map\n\n   
 Description:\n\n   Today network equipment vendors offer Zero-Touch Provis
 ioning (ZTP)\n   for configuring devices with little-to-no manual interven
 tion.\n   However\, it is often taken for granted that that the networking
 \n   protocols used in ZTP are secure.\n\n   Most vulnerability and threat
  intelligence reports on network\n   equipment focus on individual “devi
 ce takeover” vulnerabilities\n   allowing for direct Remote Code Executi
 on. Yet\, there is little recent\n   research examining the security of ZT
 P designs and implementations\,\n   where the exploitation impact may be o
 n a much larger scale.\n\n   In this talk\, we will present 17 vulnerabili
 ties affecting TP-Link\n   Omada – a device ecosystem designed with ZTP 
 in mind. We will\n   present the Omada protocols ZTP and discuss key vulne
 rabilities in\n   them\, including a chain of trust compromise due to the 
 use of\n   hard-coded cryptographic keys\, sensitive information disclosur
 e\, and\n   remote code execution against some devices.\n\n   We will pres
 ent attacks against controllers and client devices that\n   allow attacker
 s to infiltrate networks by taking over Omada equipment.\n   We will also 
 show that some of the issues go way beyond one device\n   family and affec
 t other network equipment\, security cameras\, smart\n   home devices\, an
 d mobile apps with millions of downloads.\n\n   Speakers:Francesco La Spin
 a\,Stanislav Dashevskyi\n\n   SpeakerBio:  Francesco La Spina\, Forescout 
 Technologies\n\n   Francesco La Spina holds an MSc in Computer Science fro
 m the\n   University of Trento\, Italy. He began his career as a software\
 n   engineer with a focus on IT/IoT security gateway development\, honing\
 n   his expertise in crafting robust security solutions for digital\n   in
 frastructures. Having served as a security engineer for an ISP and\n   fin
 ancial institutions\, he also gained invaluable experience in\n   fortifyi
 ng networks against potential threats. Currently\, Francesco is\n   engage
 d in cutting-edge security research and threat analysis within\n   the rea
 lms of IT and IoT at Forescout Technologies - Vedere Labs.\n\n   SpeakerBi
 o:  Stanislav Dashevskyi\, Forescout Technologies\n\n   Stanislav Dashevsk
 yi is a Security Researcher at Forescout. He\n   received his PhD from the
  International Doctorate School in\n   Information and Communication Techn
 ologies (ICT) at the University of\n   Trento (Italy) in 2017. His main re
 search interests are open source\n   software\, software security\, and vu
 lnerability analysis.\n\n   '\n\n   1. #LVCCW_Level1_Hall3\n\n\n
DTEND:20260808T233000Z
DTSTART:20260808T223000Z
LOCATION:DEF CON Talks - LVCCW Level 1 Hall 3 1007 (Main Track 2) and DCTV-
 2
SUMMARY:Zero-Day Provisioning: Chaining TP-Link ZTP Vulnerabilities for Inf
 iltrating Networks
END:VEVENT
END:VCALENDAR
