Security B-Sides SF 2013: The Pineapple Express: Live mobile application hacking demo…

pineapple express

All aboard the Pineapple Express, its a speeding bullet to the mobile backend! I’m looking forward to speaking at the upcoming B-Sides San Francisco. Most of the mobile security research has been focused on the apps on devices, but I have been more interested in the services and back-ends that power mobile apps.

B-sides san francisco logo

I’m excited about the new wifi Pineapple software that I have discovered while doing my research on mobile application security and I’m leveraging it to create a wifi hotspot during my talk.

In this talk, we’ll go beyond the typical discussion points on mobile security to delve into the vulnerable back-ends mobile applications. I will demonstrate how easy it is to find vulnerabilities and attack the service calls in social media, banking and payment applications.

These applications leverage new formats like JSON, AJAX and REST to deliver a rich user experience, but unfortunately they are too often exposing the same familiar vulnerabilities like SQL and Command injection. During this talk, I will demonstrate just how vulnerable these back-ends can be and how easy it is to watch the traffic and attack these interfaces.

The first step in learning to attack these mobile applications is understanding the formats used. Participants learn how to break-down these new formats, where to attack them and which tools and techniques make it easy to attack these back-end interfaces.

The audience will have the opportunity to connect to my Wifi Pineapple and use their real apps, which I will snoop and demonstrate how to hack the backends. While they won’t actually hack applications, the group will watch the live traffic and the discuss techniques that can be used to hack those applications.

Last updated by at .

About Dan Kuykendall

Dan Kuykendall is the CTO and Co-CEO at NT OBJECTives. Dan is a founder of NT OBJECTives and has been with the company for more than 10 years. He is responsible for the strategic direction and development of products and services and works closely with technology partners to make sure integrations are both deep and valuable. As a result of Dan’s dedication to security, technology innovation and software development, NTO application security scanning software is often recognized as the most accurate because of its sophisticated automation techniques. Dan joined NT OBJECTives from Foundstone, where he was responsible for the portal interface to the company’s flagship product, FoundScan. Prior to Foundstone, Dan was the founder of the Information Security team in the United States branches of Fortis. Dan is a regular blogger on web application security issues on ManVsWebApp.com and co-hosts An Information Security Place Podcast. His has presented on the topics of mobile and application security at many of the top security industry conferences such as ISSA (2011), B-Sides (2012-2013), OWASP AppSecUSA (2012), HouSecCon (2010-2012), ToorCon (2013) and THOTCON (2013). Dan has been involved with Web Application Security Consortium and is a regular contributor to many open source development projects including founding the RPM Builder, phpGroupWare and podPress projects. Connect with Dan on Google+

Leave a Reply

Your email address will not be published. Required fields are marked *