<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Benedikt Troester on Insinuator.net - Bold Statements</title>
    <link>https://insinuator.net/authors/benedikt-troester/</link>
    <description>Recent content in Benedikt Troester on Insinuator.net - Bold Statements</description>
    <generator>Hugo</generator>
    <language>en-us</language>
    <lastBuildDate>Thu, 15 Dec 2016 00:00:00 +0000</lastBuildDate>
    <atom:link href="https://insinuator.net/authors/benedikt-troester/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>PoC Con Seoul 2016</title>
      <link>https://insinuator.net/2016/12/poc-con-seoul-2016/</link>
      <pubDate>Thu, 15 Dec 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/12/poc-con-seoul-2016/</guid>
      <description>&lt;p&gt;Recently I had the pleasure to join the &lt;a href=&#34;http://www.powerofcommunity.net/&#34;&gt;PowerOfCommunity&lt;/a&gt; conference in Seoul. Florian and Felix attended the conference in the past and enjoyed it a lot, so I took the opportunity to join this year. From what I had heard the conference is highly technical, offensive security and community focused (surprise 😉 ). Boy did they deliver!&lt;br&gt;&#xA;Located in a hotel next to a nice park and close to the famous Gangnam district in Seoul we came together to feel the power of community. The conference was planned for two days and offered two tracks per day. Several key talks were presented for everyone.&lt;br&gt;&#xA;I really liked the topics a lot. Some contributions I found particularly interesting were:&lt;br&gt;&#xA;Petr Švenda with “The Million-Key Question – How RSA Public Key Leaks Its Origin”, where he presented his research of fingerprinting RSA public keys. By analyzing the RSA keys from smartcards and software sources he was able to find similarities between them, which allowed fingerprinting the generating source for some cases. With this information it could be possible gather some potentially important details from simple keys. He is currently expanding his work, please send him an E-Mail if you have RSA keys from an exotic resource. 😉&lt;/p&gt;</description>
    </item>
    <item>
      <title>Hek.si 2015</title>
      <link>https://insinuator.net/2015/05/hek.si-2015/</link>
      <pubDate>Tue, 05 May 2015 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2015/05/hek.si-2015/</guid>
      <description>&lt;p&gt;Hey!&lt;/p&gt;&#xA;&lt;p&gt;I attended this &lt;a href=&#34;http://hek.si/&#34;&gt;really nice conference in Slovenia&lt;/a&gt; on April 16th. It was a smaller conference, but very memorable for the people (students, IT sec professionals and managers alike) who attended.&lt;br&gt;&#xA;I also had the pleasure to present on &lt;a href=&#34;https://www.ernw.de/download/ERNW_heksi_how_secure_am_i_with_emet_v1.0.pdf&#34;&gt;How secure am I with EMET?&lt;/a&gt; and &lt;a href=&#34;https://www.ernw.de/download/ERNW_heksi_apt_armor_eval_v1.0.pdf&#34;&gt;Evaluating the APT armor&lt;/a&gt; and wanted to share the slides with you — feel free to approach me for any kind of feedback or discussion.&lt;/p&gt;&#xA;&lt;p&gt;I’m looking forward to go to Ljubljana again! 😉&lt;/p&gt;</description>
    </item>
    <item>
      <title>Troopers PacketWars 2015 – Write Up</title>
      <link>https://insinuator.net/2015/04/troopers-packetwars-2015-write-up/</link>
      <pubDate>Tue, 21 Apr 2015 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2015/04/troopers-packetwars-2015-write-up/</guid>
      <description>&lt;h1 id=&#34;hello-hackers&#34;&gt;Hello Hackers!&lt;/h1&gt;&#xA;&lt;p&gt; &lt;/p&gt;&#xA;&lt;p&gt; &lt;/p&gt;&#xA;&lt;p&gt;This year’s &lt;a href=&#34;http://www.packetwars.com&#34;&gt;PacketWars&lt;/a&gt; contest at Troopers was a blast! Under the topic of “Connected Car” the teams faced several different challenges, which we will describe (as a debriefing) here.&lt;/p&gt;&#xA;&lt;h1 id=&#34;story&#34;&gt;Story&lt;/h1&gt;&#xA;&lt;p&gt; &lt;/p&gt;&#xA;&lt;p&gt; &lt;/p&gt;&#xA;&lt;p&gt;From the &lt;a href=&#34;https://twitter.com/bryanfite&#34;&gt;Packetmaster’s&lt;/a&gt; Battle Briefing:&lt;/p&gt;&#xA;&lt;p&gt;You and your krew are “freelancers” hired to identify and neutralize an unknown threat agent who has created weaponized software and delivered it to civilian Connected Cars via compromised EV (Electrical Vehicle) charing stations. To make matters worse there are indications that new strains of the malware are appearing as the “worm” spreads from car to car. The mobile mesh network created by the Connect Car is highly resilient, allowing the malware to spread exponentially. Time is of the essence.&lt;br&gt;&#xA;Malware analysis suggests that besides a botnet module, there is an active CANBus injection capability. There appears to be other modules but they haven’t been properly reversed and analyzed yet.&lt;/p&gt;</description>
    </item>
    <item>
      <title>HackInTheBox and Haxpo – 2014</title>
      <link>https://insinuator.net/2014/07/hackinthebox-and-haxpo-2014/</link>
      <pubDate>Mon, 07 Jul 2014 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2014/07/hackinthebox-and-haxpo-2014/</guid>
      <description>&lt;p&gt;&lt;img src=&#34;http://www.insinuator.net/wp-content/uploads/2014/06/haxpoHITB_overview_small.jpg&#34; alt=&#34;Haxpo Overview 2014&#34;&gt;&lt;/p&gt;&#xA;&lt;p&gt;Haxpo Overview 2014&lt;/p&gt;&#xA;&lt;p&gt;Past month we (which is me and a group of other ERNW students, supported by some of the “old” guys — I hope my team lead won’t yell at me for this 😉 ) attended the Haxpo and Hack in the Box in Amsterdam. Starting from 28. May, we had three days at this great conference (&lt;a href=&#34;http://www.hitb.org/&#34;&gt;HITB&lt;/a&gt;) and exposition (&lt;a href=&#34;http://haxpo.nl/&#34;&gt;Haxpo&lt;/a&gt;). The two events took place in the former building of the stock exchange in Amsterdam, called: “&lt;a href=&#34;http://www.beursvanberlage.nl/&#34;&gt;Beurs van Berlage&lt;/a&gt;”. Upon entering the building for the first time we were given details on where our booth was and where the talks would take place — setting up our booth and planning the shifts was just another thing to do before exploring the Haxpo area:&lt;/p&gt;</description>
    </item>
    <item>
      <title>Django Image Validation Vulnerability</title>
      <link>https://insinuator.net/2014/05/django-image-validation-vulnerability/</link>
      <pubDate>Fri, 16 May 2014 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2014/05/django-image-validation-vulnerability/</guid>
      <description>&lt;p&gt;Hi!&lt;/p&gt;&#xA;&lt;p&gt;In the course of a recent penetration test, we came across an Image validation vulnerability in Django when using the &lt;a href=&#34;http://www.pythonware.com/products/pil/&#34;&gt;Python-Imaging-Library (PIL)&lt;/a&gt; which we want to explain in this post.&lt;/p&gt;&#xA;&lt;p&gt;Everybody who doesn’t know what &lt;a href=&#34;https://www.djangoproject.com/&#34;&gt;Django&lt;/a&gt; and/or the PIL is:&lt;br&gt;&#xA;Django is a framework to create web applications with Python (comparable to Rails or Zend). The PIL is a powerful standard python library which provides a toolset to modify, display and verify images of many different formats.&lt;/p&gt;</description>
    </item>
    <item>
      <title>ASCII Protocol Scheme Generator</title>
      <link>https://insinuator.net/2014/05/ascii-protocol-scheme-generator/</link>
      <pubDate>Thu, 08 May 2014 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2014/05/ascii-protocol-scheme-generator/</guid>
      <description>&lt;p&gt;As we historically have a strong connection to network technologies (not surprising, given the “NW” in “ERNW” stands for “Networks”), I developed a small script to create RFC-style ASCII representations of protocol schemes. The following listing shows an example created for a fictitious protocol:&lt;/p&gt;&#xA;&lt;pre&gt;&lt;code&gt; 0                   1                   2                   3  &#xA; 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1&#xA;+---------------------------------------------------------------+&#xA;|             type              |              id               |&#xA;+---------------------------------------------------------------+&#xA;|     flags     |                   reserved                    |&#xA;+---------------------------------------------------------------+&#xA;|                            payload                            |&#xA;+---------------------------------------------------------------+&#xA;&lt;/code&gt;&lt;/pre&gt;&#xA;&lt;p&gt; &lt;/p&gt;</description>
    </item>
  </channel>
</rss>
