Class Central is learner-supported. When you buy through links on our site, we may earn an affiliate commission.

YouTube

Hacking Medical Devices and Healthcare Infrastructure

Hack In The Box Security Conference via YouTube

Overview

This course aims to educate participants on hacking medical devices and healthcare infrastructure, focusing on the HL7 2.x messaging standard. The learning outcomes include understanding HL7 2.x messages, their significance, and the potential impact of gaining unauthorized access to patient information and medical systems. Participants will learn to pentest medical systems with HL7 interfaces, identify common flaws and attack surfaces, and develop security testing methodologies for hospital infrastructure. The course covers topics such as ADT, ORM, ORU, RDE, MDM, DFT messages, as well as security vulnerabilities like message source validation, server attacks, denial of service, and exploiting file functionalities. The intended audience for this course includes security professionals seeking to enhance their understanding of healthcare standards and infrastructure security.

Syllabus

SPEAKER BIO
#whoami
Agenda
Securing hospitals
Understanding medical devices
HL7 - Health Level 7
In a nutshell
HL 72.x crash course
ADT - Admit Discharge and Transfer
ADT - Potential Entry Points
ORM - Order message
ORM - Potential Entry points
ORU - Observation Result
RDE - Pharmacy order message
MDM - Medical Document Management
DFT - Detail Financial Transaction
Recon
Message source not validated
Unvalidated size
Bad server attacks
Denial of service
Abusing file upload / download functionality

Taught by

Hack In The Box Security Conference

Reviews

Start your review of Hacking Medical Devices and Healthcare Infrastructure

Never Stop Learning.

Get personalized course recommendations, track subjects and courses with reminders, and more.

Someone learning on their laptop while sitting on the floor.