April 30, 2008 11:24 AM PDT

Microsoft's Blue Hat talks start Thursday

On Thursday and Friday, Microsoft will once again gather select security researchers in Redmond, Wash., for its seventh annual Blue Hat talks.

The conference, by invitation only, has gained a reputation for providing Microsoft engineers with a first-hand opportunity to hear from and question leading security researchers. There will be an executive event on Thursday, with general sessions on Friday. Microsoft has more on the Blue Hat schedule here, and a blog here.

Among those invited to present is Cesar Cerrudo, of Argeniss, who will update his Hack the Box talk on Token Kidnapping. Cerrudo defines an access token as "an object that describes the security context of a process of thread," which includes the identity and privileges of the user account. He will show, according to Microsoft, "how it's possible in Windows XP and Windows Server 2003 to elevate privileges to Local System from any process that has impersonation rights."

What's interesting is that Microsoft issued a pre-patch advisory shortly after Cerrudo's April 17 Hack the Box talk. CVE-2008-1436 states that "Microsoft Windows XP Professional SP2, Vista, and Server 2003 and 2008 does not properly assign activities to the NetworkService and LocalService accounts, which might allow context-dependent attackers to gain privileges...related to improper management of the SeImpersonatePrivilege user right, as originally reported for Internet Information Services. " Look for a Microsoft patch announcement regarding this in May.

Other presentations at Blue Hat worth noting are Alex "Kuza55" K. of Sift on "Web Browsers and Other Mistakes"; Manuel Caballero and Fukami on "A Resident in My Domain, plus, Unweaving Silverlight from Flash"; SoWhat of Nevis Labs on "Attacking Antivirus"; and Billy Rios and Nitesh Dhanjani will reprise their Black Hat D.C. talk, "Bad Sushi: Beating Phishers at Their Own Game."

Recent posts from Defense in Depth
ZoneAlarm virtualizes the desktop Internet browser
Yahoo e-mail accounts compromised for spammers' use
Skeleton key unlocks Microsoft SQL servers in latest Web attack
Web browsers and other mistakes
Goodbye Storm, Hello Srizbi
Add a Comment (Log in or register) 2 comments (Page 1 of 1)
Executive Event?
by Vegaman_Dan April 30, 2008 5:33 PM PDT
I certainly hope this was a mistake in the article. An executive event where the execs of companies get together is typically more of a junket / vacation than a productive workshop. I'd much rather see researchers and developers get together and hash out some ideas than a Q&A session with execs who really don't know much about the nuts and bolts issues. Unfortunately, developers and such don't get invited to such things and kept in the prison cells hammering out code with little air or light (but free soda).
Reply to this comment View reply
Powered by Jive Software
advertisement
Click Here
  • About Defense in Depth

  • With over eight years at CNET covering computer viruses and computer crime, Robert Vamosi goes beyond the hype to provide you with expert interviews with the top security researchers making the news as well as offering the hands-on, non-technical advice you'll need to stay safe online.

Add this feed to your online news reader
Google
Yahoo
MSN

Latest blog posts from News.com

Featured blogs

Beyond Binary by Ina Fried A look at how technology is changing our lives and at the people behind all that life-changing stuff.

Coop's Corner by Charles Cooper Charles Cooper weighs in on Silicon Valley hijinks, and he doesn't suffer fools gladly.

Geek Gestalt by Daniel Terdiman At the tech culture nexus of video games, fire art, and virtual worlds.

Green Tech Fresh green tech news and commentary.

One More Thing by Tom Krazit Tom Krazit takes on the tech phenomenon that is Apple, and keeps a close watch on the chip industry.

Outside the Lines by Dan Farber When business and technology meet, that's when things get interesting.

The Iconoclast by Declan McCullagh Exploring the intersection of politics and technology.

The Social by Caroline McCarthy Exploring all facets of social media and tech culture.

Underexposed by Stephen Shankland Coverage of digital photography, science, and open-source software.

Resource center from News.com sponsors

advertisement
On TechRepublic: Top 5 operating systems you never used
Advanced
search
Advanced
search
Visit other CNET Networks sites: