From WAN to NAS: A Pwn2Own Journey Through the SOHO Attack Surface - Daan Keuper - NDC Security 2026

Security
youtube
From WAN to NAS: A Pwn2Own Journey Through the SOHO Attack Surface - Daan Keuper - NDC Security 2026 This talk was recorded at NDC Security in Oslo, Norway. #ndcsecurity #ndcconferences #security #developer #softwaredeveloper Attend the next NDC conference near you: Subscribe to our YouTube channel and learn every day: @NDC Follow our Social Media! #hacker #iot The SOHO Smashup is a famous category in the IoT focused edition of Pwn2Own. Contestants are challenged to exploit a router from the WAN side and then use that device to exploit a second device on the internal LAN. Last year, we took them up on this challenge and successfully demonstrated a 0day exploit chain against a QNAP router and pivoting to a TrueNAS system. In this presentation, we'll describe how we performed our research and the vulnerabilities we found. The Dutch NCSC issued a warning last year that they see an increase of threat actors that shift their attention from endpoints to edge devices, including routers. This demonstrates the relevance of the SOHO Smashup category in Pwn2Own. Vulnerabilities in routers that could be exploited from the WAN side pose a real security risk for companies; as these devices are often badly monitored and not kept up to date. Threat actors who are able to compromise a router are in a key position to further advance into the internal network of a company. In this talk we'll describe the vulnerabilities and exploits. Specifically, we'll describe our research method on the QNAP router. We tried to increase our attack surface step by step, until we fo
  2026/03/27      youtube

関連するプログラミング動画 [security]

Our Tag

最近投稿されたプログラミング学習動画

Python Match Statement: Features You Didn't Know

python

Download your free Python Cheat Sheet he...

  2026/04/09

Using Loguru to Simplify Python Logging: Setting Up & Understanding Lo

python

Download your free Python Cheat Sheet he...

  2026/04/09

MCP Apps: AI With Visual UI, Not Just Text

python

Download your free Python Cheat Sheet he...

  2026/04/08

What is your ANSWER?👇

Want to make real money with coding? I s...

  2026/04/08

Astro Crash Course #8 - Content Collections (with JSON)

In this Astro tutorial series, you'll le...

  2026/04/08

他のAIが記憶した脳をそのまま移行できる?!今からClaudeを活用していきたい人はこの方法がおすすめです

本日はChatGPTからClaudeへ乗り換えたい人が知っておくべき知識について...

  2026/04/08

Which ONE do you use?

Want to make real money with coding? I s...

  2026/04/07

Role-based Access Control and Sharing lists | Code, Commit, Deploy, Re

Welcome back to Code, Commit, Deploy, Re...

  2026/04/07

Bad UX Is Driving Users Away From Apple

python
Apple

Download your free Python Cheat Sheet he...

  2026/04/07

50x Cheaper Than Claude - But Can It Actually Code?

MiniMax Token Plan 12% OFF: MiniMax 2....

  2026/04/07

PyCon JP TV #63: PythonAsia 2026報告会

python
Google

PyCon JP Associationが主催するYouTubeライブです。実験...

  2026/04/07

Astro Crash Course #7 - Reusable Components

In this Astro tutorial series, you'll le...

  2026/04/07

Build A Smart Chat Bot Using Python & Machine Learning Audio Improved

python
study

Build A Smart Chat Bot Using Python & Ma...

  2026/04/07