Join Us At Hacker Summer Camp

Mind the Gap: Bridges, Backplanes, and BloodHound

Breaking Ground, Tue, August 4 @ 2pm PDT (Florentine A)
lanyard-rope
lanyard-clip

Presented by:

HD Moore

Founder and CEO

Segmentation is the last line of defense for unsecurable systems, but it's the toughest control to enforce at scale. Savvy attackers skip the firewall and slip through the accidental bridges, out-of-band channels, and protocol gateways that nobody scoped: from a technician's laptop, to a dusty old printer, to a thermostat that exposes hundreds of building controls from a single overlooked service. This talk covers the most dangerous failures and how to analyze them at scale using open-source tools.

We'll start with three common entry points and how to find them: 

  • Bridges: multi-interface hosts and network devices doing things they shouldn't.
  • Out-of-band channels: baseboard management controllers, KVM-over-IP systems, and serial port servers used for remote console access.
  • Backplanes and buses: the OT and building-automation protocols that expose sensitive equipment to hostile networks. 

With the raw data in hand, we'll cover the identity-correlation tricks that catch the same physical host sitting on two networks at once, then feed the result into BloodHound Open Graph and produce the real network map; not the one IT handed you.


More great things from HD

Podcasts
The shadow era AI, exploits, and cybersecurity's 90s comeback
HD Moore explains how AI is turning hacking back to the 90s, generating permanent exploit skeleton keys and breaking traditional defense.
Talks
Identifying exposures at scale with BloodHound OpenGraph
Traditional exposure management misses hidden attack paths. Learn how BloodHound and Cypher queries can uncover vulnerabilities beyond individual...
Podcasts
Know Your Adversary with HD Moore
runZero CEO HD Moore breaks down the myth of air-gapped networks, the impact of AI on security, and why asset connectivity is everything.
Webcasts
Defending in the shadow era: when the CVE feed goes dark
HD Moore walks through the three eras of vulnerability management: the predictable cycles era, the triage ara of AI-scale discovery, and now the...

More Summer Camp Talks!

Wed, August 5 @ 12:00pm - 12:45pm (Florentine F)
I am CVE, AMA!

Tod Beardsley returns to BSides Las Vegas to lead a spirited discussion on the past, present, and future of the CVE Program. Joining him is an expert panel featuring program sponsors Katie Trimble-Noble and Lindsey Cerkovnik, vulnerability managers Lisa Olson (MSRC) and Madison Ficorilli (GitHub Advisory DB), and data scientist Jerry Gamblin (RogoLabs).

This year, the mic belongs to you. Bring your burning questions as the panel tackles the CVE program's role in the global cybersecurity ecosystem, how it handles the onslaught of AI-discovered and AI-created vulnerabilities, and its impact from initial research to downstream applications.

Learn More
Wed, August 5 @ 3:35pm - 4:15pm (Oceanside A, Level 2)
Lights Out: BMC's are Still Broken and Now We Have the Receipts

HD Moore uncovers the critical, overlooked threats hiding in your server's BMCs. Drawing from a massive scan of over 140,000 devices, HD reveals that three out of four internet-facing IPMI hosts still leak passwords and system data.

Learn how attackers are using these always-on, highly trusted devices to deploy persistent firmware implants that survive OS reinstalls, and gain access to OOBscan, a brand-new open-source IPMI auditing tool released exclusively during this session.

Learn More
Sat, August 8 @ 2pm - 3pm (LVCC - L1 - Exhibit Hall West 3 - 1006, Main Track 1)
Lights Out: Out-of-Band, Out of Mind, Out of Control
In this talk, runZero's HD Moore exposes severe flaws in BMC's, demonstrating how his team extracted password hashes from 75% of 140,000 scanned targets without credentials and bypassed "random" password laws.

HD reveals how attackers can completely neutralize network segmentation by using the internal PCIe bus to pivot from a compromised host into the management VLAN, ultimately hijacking the entire fleet.

The session concludes with a live demonstration of this devastating attack chain using their new open-source tool, OOBscan.
Learn More

Book some 1:1 time

Meet with us during Summer Camp