Black Hat USA 2018 - Pestilential Protocol How Unsecure HL7 Messages Threaten Patient Lives @HackersOnBoard
Black Hat USA 2018 - Pestilential Protocol How Unsecure HL7 Messages Threaten Patient Lives  @HackersOnBoard
Uploaded October 2019 | Updated September 2026, 3 days ago
Healthcare infosec is in critical condition- too few bodies, underfunded to a fault, and limping along on legacy systems stuffed with vulnerabilities. From exploited insulin/medication pumps to broken pacemakers, no implantable or medical device is safe. But there’s an even bigger risk on the horizon.

WannaCry was a wake-up- when you knock out systems that enable a hospital to care for patients, you start knocking out patients. Hospitals are no longer secure by virtue of being obscure- connected infrastructure means vulnerable infrastructure.

The HL7 standards comprises the backbone of clinical data transfer used in every hospital around the globe. Frequently implemented as plain text messages sent across flat networks with no authentication or verification, HL7 is both critically ubiquitous and massively unsecured- and thus every lab sample, every medical image, every doctor’s order becomes a potential time bomb.

Join Quaddi and r3plicant, hackers who moonlight as physicians, and Maxwell Bland as they explore the myriad of ways in which HL7 attacks can be used to subvert the implicit trust doctors place in this infrastructure- and just how catastrophic that broken trust can be. Come for the sobering premise, stay for the live HL7 attack demo- but be warned: there will be blood.
Black Hat USA 2018 - Pestilential Protocol How Unsecure HL7 Messages Threaten Patient LivesEdge Side Include Injection Abusing Caching Servers into SSRF and Transparent Session HijackingEfail Breaking S MIME and OpenPGP Email Encryption using Exfiltration ChannelsBlack Hat USA 2018 - Exploitation of a Modern Smartphone BasebandBlack Hat USA 2018 - A Deep Dive into macOS MDM and How it can be CompromisedDEF CON 27 - Douglas McKee - HVACking Understand the Delta Between Security and RealityDEF CON 27 - Kyle Gwinnup - Next Generation Process Emulation with BineeBlockchain Autopsies - Analyzing Ethereum Smart Contract DeathsMiasm Reverse Engineering FrameworkFollow the White Rabbit Simplifying Fuzz Testing Using FuzzExMachinaDEF CON 27 - More Keys Than A Piano: Finding Secrets In Publicly Exposed Ebs VolumesBeating the Blockchain by Mapping Out Decentralized Namecoin and Emercoin Infrastructure
HackersOnBoard |

Black Hat USA 2018 - Pestilential Protocol How Unsecure HL7 Messages Threaten Patient Lives

SHARE TO X SHARE TO REDDIT SHARE TO FACEBOOK WALLPAPER