Kos SecurityA blog about security.

Hacking Google Chrome OS

Presented at BlackHat USA 2011, BSidesLV 2011, and Defcon 19 (2011). WhitePaper:



Presentation Slides:



Video after the break.
(more…)

The Hidden XSS Attacking the Desktop & Mobile Platforms – Slides & Video

A few weeks ago (October 2th) I was in Louisville, Kentucky, giving a talk at Derbycon. I also gave the same talk in San Diego (October 9th) at Toorcon 13. It’s a much expanded version of a talk I did back in June at Toorcon Seattle, “XSS Without the Browser”.

Slides are below, and video is after the break. The slides are a bit different than the video. I modified, reordered, and added a few slides, and also included a new Google application vulnerability.



(more…)

Toorcon Seattle 2011, “XSS Without the Browser”

Toorcon Seattle 2011, “XSS Without the Browser” (PDF). Presentation I gave about embedded HTML/Javascript engines, and potential security risks with whe not implemented securely. An old Skype bug is used as an example.