Class Central is learner-supported. When you buy through links on our site, we may earn an affiliate commission.

YouTube

IPC - The Broken Dream of Inherent Security

Cooper via YouTube

Overview

This course aims to teach learners about the vulnerabilities in Inter-process communication (IPC) and how they can be exploited by attackers. By the end of the course, students will be able to identify and understand the security risks associated with IPC, such as client and server impersonation, man-in-the-middle attacks, and unauthorized access to devices like USB HID and FIDO U2F keys. The course covers various IPC methods, including network sockets, Windows named pipes, and standalone password managers, and provides mitigation strategies to enhance security. The teaching method involves a detailed exploration of IPC vulnerabilities through real-world examples and demonstrations. This course is intended for cybersecurity professionals, network administrators, and anyone interested in understanding and securing IPC mechanisms.

Syllabus

Intro
Traditional network threat model
Our focus: Inter-process communication (IPC)
Man-in-the-Machine (Mit Ma)
What makes IPC vulnerable
Network socket on localhost
Network socket: Client impersonation
Network socket: Server impersonation
Network socket Man-in-the-middle
Windows named pipe: Access control
Windows named pipe: Client impersonation
Windows named pipe: Server impersonation
Windows named pipe: Man-in-the-Middle
USB HID devices
Standalone password managers
Client impersonation on RoboForm
1Password - Key derivation protocol
Server impersonation on 1Password
Password managers with Native messaging
Man-in-the-Middle on Password Boss (2)
FIDO U2F security key
Unauthorized access of FIDO U2F key
Mitigation
Conclusion

Taught by

Cooper

Reviews

Start your review of IPC - The Broken Dream of Inherent Security

Never Stop Learning.

Get personalized course recommendations, track subjects and courses with reminders, and more.

Someone learning on their laptop while sitting on the floor.