DEF CON 27 - Breaking The Back End It Is Not Always A Bug Sometimes It Is Just Bad Design @HackersOnBoard
DEF CON 27 - Breaking The Back End It Is Not Always A Bug Sometimes It Is Just Bad Design  @HackersOnBoard
Uploaded December 2019 | Updated September 2026, 5 days ago
Reverse engineering is critical to exploitation. However, going through the process of reverse engineering can often lead to a great deal more than just uncovering a bug. So much so that you might find what you need for exploitation even if you don't find a bug.

That's right. If you go through object data, object representation, object states, and state changes enough you can find out quite a lot. Yes. Poor application logic is a bitch. Just ask any application penetration tester. This time it is not the magstripe. It's appsec and you will get to see how application attacks can be used against a hardware platform.

In this talk, I will go through the journey that I took in reverse engineering the public transportation system of an east asian mega-city, the questions that I asked as I wondered "How does this work?", the experiments that I ran to answers those questions, what I learned that lead me to an exploit capable of generating millions of dollars in fake tickets for that very same system, and how other designers can avoid the same fate. Not without risk, this research was done under a junta so I will also be telling you how I kept myself out of jail while doing it. Please join me. You won't want to miss it.

Talk by Gregory Pickett
DEF CON 27 - Breaking The Back End It Is Not Always A Bug Sometimes It Is Just Bad DesignDEF CON 27 - 100 Seconds of Solitude Defeating Cisco Trust Anchor With FPGA Bitstream ShenanigansDEF CON 27 - Panel - DEF CON to help hackers anonymously submit bugs to the government discussDEF CON 27 - Alvaro Munoz - SSO Wars The Token MenaceBlack Hat USA 2018 - Fire & Ice Making and Breaking macOS FirewallsDEF CON 27 - smea - Adventures In Smart Buttplug Penetration testingDEF CON 27 - Unpacking Pkgs A Look Inside Macos Installer Packages And Common Security FlawsBlack Hat USA 2018 - Dissecting Non Malicious Artifacts One IP at a TimeDEF CON 27 - Brent Stone - Reverse Engineering 17 plus Cars in Less Than 10 MinutesDEF CON 27 - Bruce Schneier - Information Security in the Public InterestDEF CON 27 - Brad Dixon - Cheating in eSports How to Cheat at Virtual Cycling Using USB HacksBlack Hat USA 2018 - Hardening Hyper V through Offensive Security Research
HackersOnBoard |

DEF CON 27 - Breaking The Back End It Is Not Always A Bug Sometimes It Is Just Bad Design

SHARE TO X SHARE TO REDDIT SHARE TO FACEBOOK WALLPAPER