Only a few days left until Troopers! I’d like to use this chance to publish the final agenda of TelcoSecDay 2016. We will start around 8:30am and will finish at about 6:15pm. After this, we will have a shared dinner in the historic center of Heidelberg. The exact location will be announced during the TSD.
Continue reading “TelcoSecDay 2016 – Final Agenda and more”
Check your SAP landscape for default Solution Manager users
This is a guest post from Joris van de Vis @jvis, on his upcoming Troopers talk. Additional credits go to: Robin Vleeschhouwer, and Fred van de Langenberg.
As presented at Troopers this year, ERP-SEC research has uncovered a set of potential default accounts related to the use of SAP Solution Manager. These default accounts might pose a big risk to your SAP supported business as some of them have wide authorisations. It is therefore important to check if they exist in your landscape and change the default passwords.
Continue reading “Check your SAP landscape for default Solution Manager users”
Continue readingDocker, DevOps & Security
Hi,
this week I gave a presentation together with Florian Barth from Stocard on Docker, DevOps/Microservices, and Security — a topic and collaboration that I will definitely cover in even more detail in the future!
Continue reading “Docker, DevOps & Security”
Continue readingCloud Security & Trust
Hi,
I gave a presentation on Cloud Security, Compliance & Trust the other day. The basic message was to look beyond the Cloud buzzword and see the actual technologies which are used, understand which security principles still apply and which need to be re-thought, giving a rough direction about regulatory compliance in Cloud environments (which of course is non-binding, as I’m not a lawyer), and the importance of trust evaluations (especially) when it comes to Cloud services.
Continue reading “Cloud Security & Trust”
Continue readingTroopers16 – GSM Network
Same as last year, we will have a GSM based telephony network running at Troopers 2016. The network will be a closed network, which means it only can be used with Troopers SIM cards and between Troopers attendees only. You can use the network for
- doing Voice Calls
- send Short Messages (SMS)
- have Internet Access
- submit Challenge Tokens (see below)
Continue reading “Troopers16 – GSM Network”
Continue readingHow to crack a white-box without much effort
By: Philippe Teuwen (@doegox)
White-box cryptography is a relatively new field that aims at enabling safely cryptographic operations in hostile situations.
A typical example is its use in digital-right management (DRM) schemes, but nowadays you also find white-box implementations in mobile applications such as Host Card Emulation (HCE) and the protection of credentials to the cloud.
In all these use-cases the software implementation uses the secret key of a third-party which should remain secret from the owner of the device which is running this executable.
Continue reading “How to crack a white-box without much effort”
Continue readingMulticast Based IPv6 Neighbor Spoofing / Response Behavior on Cisco Devices
Dear readers,
today we want to examine the behavior of Cisco devices when they receive spoofed IPv6 Neighbor Advertisement packets from an untrusted system pretending to be the default router for the local segment. We start with a quick refresher how Cisco devices behave in the legacy (IPv4) world when they receive a spoofed broadcast ARP packet containing the IP address of the device but with a different MAC address, followed by a discussion of the corresponding behavior in the IPv6 world. Continue reading “Multicast Based IPv6 Neighbor Spoofing / Response Behavior on Cisco Devices”
Continue readingHow to test Kerberos authenticated web applications?
First of all: This is not an in-depth Kerberos how-to, nor is this tutorial about the different aspects of web application testing. This tutorial is just to give support in testing Kerberos authenticated web applications. The goal is to hand over the right tools and steps to be able to perform the configuration and be able to test the application.
Continue reading “How to test Kerberos authenticated web applications?”
Continue readingDual Stack vs. IPv6-only in Enterprise Networks
I had the pleasure to sit in Mark Townsley “Addressing Networking Challenges With Latest Innovations in IPv6” session at Cisco Live yesterday and – somewhat inevitably – there was a mention of Facebook having implemented an IPv6-only approach in their data centers (here’s a talk from Paul Saab/FB laying out details). So, with the “IPv6 Panel” looming, I started reflecting on “Why don’t we see this in our customer space?”. This post quickly summarizes some observations and thoughts.
Continue reading “Dual Stack vs. IPv6-only in Enterprise Networks”
Continue readingss7MAPer – A SS7 pen testing toolkit
While running some SS7 pentests last year, I developed a small tool automating some of the well-known SS7 attack cases. Today I’m releasing the first version of ss7MAPer, a SS7 MAP (pen-)testing toolkit.
Continue reading “ss7MAPer – A SS7 pen testing toolkit”