Today we have to pleasure to announce another round of
Troopers talks.
Here we go:
Noam Liram: Vulnerability Classification in the SaaS Era FIRST TIME
MATERIAL
Abstract: In this talk we will thoroughly analyze two major SaaS vulnerabilities
that were found by Adallom (one of which is still in responsible disclosure
stages at the time of writing). By demonstrating this new class of exploits
which we have nick-named “Ice Dagger” attacks, we aim to change the current
industry-wide criteria for vulnerability classifications, which were developed
in the Desktop/Server world, are inadequate when classifying SaaS
vulnerabilities. We will specifically discuss the details of MS13-104.
In an upcoming series of blog posts I will discuss some principles &
considerations on developing an IPv6 address plan. In (hopefully) rather quick
succession there will be three posts:
the first on some general rules as for IPv6 address planning which we regard
instrumental in the process.
the second covering the “PI space from a single RIR or PI space from each
(relevant, as for $ORG) RIR?” debate.
the third on actual approaches to structuring/grouping each region’s /32 (or
/36) into subdivisions like sites, VRFs, facilities, use types, buildings,
whatever. I understand that this part is probably the one quite some readers
are most interested in; still for a reasonable line of thought the others have
to be covered in advance.
As you might have already spotted from the prefix lengths mentioned above, the
presumed setting (read: the main audience) of this piece is a sufficiently large
enterprise organization with sites/subsidiaries/plants all over the globe,
potentially mainly in the EMEA, APAC and Americas regions. So if you’re [with]
a service provider organization, a university or small[er] organization, some
of the recommendations I lay out might not apply to you. This focus (or
restriction thereof) is for the simple reason of ignorance. Given I haven’t been
involved in many address planning efforts in such organizations I don’t feel
qualified to advance opinions on their settings.
At first a very happy new year to all our readers!
Today we announce the third round of Troopers 2014 talks (first round
here,
second
here).
Here we go:
===
Daniel Mende: Implementing an USB Host Driver Fuzzer FIRST TIME
MATERIAL
Abstract: The Universal Serial Bus (USB) can be found everywhere these days, may
it be to connect a mouse or keyboard to the computer, transfer data on a flash
drive connected via USB or to attach some additional hardware like a Digital
Video Broadcast receiver. Some of these devices use a standardized device class
which are served by an operating system default driver while other, special
purpose devices, do not fit into any of those classes, so vendors ship their own
drivers. As every vendor specific USB driver installed on a system adds
additional attack surface, there needs to be some method to evaluate the
stability and the security of those vendor proprietary drivers. The simplest way
to perform a stability analysis of closed source products is the fuzzing
approach. As there have been no publicly available tools for performing USB host
driver fuzzing, I decided to develop one ;-), building on Sergey’s and Travis’
legendary
Troopers13 talk.
Be prepared to learn a lot about USB specifics, and to see quite a number of
blue screens and stack traces on major server operating systems…
We’re very happy to announce the second round of Troopers 2014 talks today
(first round
here).
Some
(well, actually most 😉 ) of these talks haven’t been presented before, at any
other occasion, so this is exciting fresh material which was/is prepared
especially for Troopers.
Andreas Wiegenstein & Xu Jia: Risks in Hosted SAP Environments.FIRST TIME
MATERIAL
**Synopsis: **Many SAP customers have outsourced the operation of their SAP
systems in order to save cost. In doing so, they entrust their most critical
data to a hosting provider, potentially sharing the same SAP server with a
number of companies and organizations unknown to them. These companies and
organizations virtually sit in the same boat, without knowing each other and
without trusting each other. They all trust in the ability of their hosting
provider to run their operating environment in a secure way, though.
It’s been a long time… we just published an
ERNW Newsletter. Here’s
the abstract:
In order to protect sensitive data on corporate laptops, most companies are
using full disk encryption solutions. While native encryption products like
Microsoft Bitlocker, Apple FileVault and open source solutions like TrueCrypt
were already heavily scrutinized by security researchers, many popular
commercial third party products are to some point still black boxes.
In this paper, we discuss Check Point Full Disk Encryption (FDE) with active
“Windows Integrated Logon”. Checkpoint FDE is a software package that is part of
Check Point Endpoint Security and offers full disk encryption on Microsoft
Windows and Mac OS X systems. The “Windows Integrated Logon” feature reduces
total cost of ownership by disabling pre-boot authentication. Check Point
themselves warn about security risk associated with using this feature.
Such was the title of a talk I gave yesterday at
ACSAC 29. It was an updated and shortened version of a
similar talk I had given at the Troopers IPv6
Security Summit (btw:
this
is the preliminary agenda of the 2014 event).
Matthias and I currently have to pleasure to be at
ACSAC, in New Orleans.
From my perspective, at ACSAC the usual conference visit side-effect of personal
interaction with peers plays an even larger role than at many other events. In
fact we met a number of people we hadn’t seen for quite some time and I could
even clear a long unresolved debt (Hi Pastor! and thanks for those
International Journal of PoC
issues).
We’re delighted to provide the first announcement of talks of next year’s
Troopers edition. Looks like it’s going to be a great
event again 😉
Here we go:
==================
Toby Kohlenberg: Granular Trust – Making it Work
Over the last 5 years the concept of using dynamic or granular trust models to
control access to systems, networks and applications has become well known and
is now seeing partial adoption in many places. The challenge is how granular and
dynamic can you get and the question is whether it is worth it. As the architect
of Intel’s trust model Toby can speak to the entire journey from initial idea
through current implementation and the likely road ahead. This talk will include
the good, bad and ugly parts of designing a trust model and then implementing it
in a Fortune 50 company’s production environment. You will learn from his
mistakes so you can make different ones.
Having just finished the second
“Advanced Attack Techniques against IPv6 Networks” workshop (some
of the course material can be found
here),
organised and hosted by ERNW and their partner
HM Training Solutions, I would like to
take this opportunity to release publicly one of my scripting tools, an IPv6
scanner. This tool is based on Scapy (so you have to install Scapy and its
prerequisites before using it). It should not be considered as a replacement or
a competitor of nmap against IPv6 or of the scanners incorporated into the great
IPv6 toolkits already released by Marc Heuse
and Fernando Gont,
but, instead, as a tool released mainly for educational purposes. Specifically,
this scanner, apart from supporting some of the most well known port scanning
techniques, from ping scanning to SYN, RESET, ACK, XMAS, etc., etc., TCP or UDP
scanning, it also combines, by using the suitable switches, some IDS/IPS evasion
techniques. As I have found out up to now, at least two of them, if used
“properly”, can be effective against a very popular IDS/IPS software used by
many “Fortune 100” companies out there. This means that you can launch actually
any type of the supported network-scanning techniques while flying under the
radar of this specific IDS software (and perhaps some other too, who knows…).
But first of all, as always please check the corresponding README file.
I recently had a discussion with some practitioners about requirements to IP
Address Management (IPAM) solutions which are specific for IPv6 networks. We
came up with the following:
Mandatory: Track all dynamic IPv6 assignments (SLAAC + PrivExtensions, DHCP
etc.), by polling neighbor caches from network devices. Support SNMPv3 for this
task.
Optional (read: nice-to-have): support other methods than SNMP to gather this
info (e.g. SSH-ing into devices and execution of appropriate “show” commands).