Softpedia
 

NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
Home > News > Security

July 29th, 2010, 16:48 GMT · By

Bugs Allowed Access to Black Hat Streams for Free

SHARE:

Adjust text size:


Flaws allow bypassing Black Hat Uplink restrictions
Enlarge picture
A Web application security researcher has uncovered several security issues in the Black Hat Uplink portal. The bugs allowed users to view the real-time video streams from the security conference without paying the access fee.

Black Hat is a technical security conference, which brings together thousands of industry researchers, professionals and journalists every year in Las Vegas. Black Hat and its sister conference DEF CON, are widely viewed as the top security events and hacker gatherings in the world.

At this Black Hat USA edition, the organizers are providing a portal, where non-participants can view the presentations and keynotes in real time over the Internet. Dubbed the Black Hat Uplink, the system gives paying users access to two separate video streams, as well as post-conference material.

"With Black Hat Uplink, you can experience essential content that shapes the security industry for the coming year - for only $395," the organizers claim. However, as Michael Coates, a Mozilla Web security expert discovered, that wasn't necessarily true.

While in the process of signing up to watch the event, the researcher encountered some strange quirks in the system, which drove him to investigate further. After poking around for a while he managed to register a username without having to provide any credit card information. He then uncovered a special page that allowed him to log in successfully and watch the streams without paying.

"Clearly my non-standard path through the registration app had identified a few key security flaws in their design," Coates writes on his blog. "Now, to be fair, Black Hat didn't operate this video service themselves. They used a third party for the video application. But its still a bit ironic that the largest hacking conference in the world [has] this security hole in their video streaming service," he adds.

The researcher managed to get in contact with the company in charge of maintaining the service and the issues which he describes as “a combination of logic flaws and misconfigured systems” were addressed in a matter of hours.

You can follow the editor on Twitter @lconstantin

TELL US WHAT YOU THINK:

1,412 hits · Link to this article · Print article · Send to friend · Subscribe to news

MUST-READ RELATED ARTICLES:


Researcher Forces Cash Out of Automated Teller Machines

2010 Pwnie Award Winners Announced at Black Hat

Security Researcher Pressured into Canceling Talk on Chinese Cyber Army

DNS Rebinding Attack Can Be Used to Hack Home Routers

The Pirate Bay Hacked

READER COMMENTS:



No user comments yet.
Be the first to express your opinion!
Copyright © 2001-2012 Softpedia. Contact/Tip us at

WindowsGamesDriversMacLinuxScriptsMobileHandheldNews

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   UPDATE YOUR SOFTWARE   |   ROMANIAN FORUM