Once moreShmooCon is the place to be for some days in late
January. Great con, great people and five ERNW guys amongst them 😉
We regard Shmoo(Con) as one of the most important community events at all and it
allows us to meet fellow researchers from the US who we can’t easily sit down
with to chat very often.
And some lucky guys from ERNW will even continue the trip to head to San Diego
(!) for NANOG and
NDSS. Not to
mention they stay in some fancy beach resort ;-), while I myself fly back today.
(Getting older I don’t enjoy staying away from home for a week anymore and I
have been missing my kids since some days…)
It’s done. The exciting (and demanding) process of selecting talks for Troopers
is complete (for the record: second round of talk selection was
here,
the first
here).
We’re quite happy and looking forward to the event 😉
==================
Rodrigo Branco: Into the Darkness – Dissecting Targeted Attacks
The current threat landscape around cyber attacks is complex and hard to
understand even for IT pros. The media coverage on recent events increases the
challenge by putting fundamentally different attacks into the same category,
often labeled as advanced persistent threats (APTs). The resulting mix of
attacks includes everything from broadly used, exploit-kit driven campaigns
driven by cyber criminals, to targeted attacks that use 0-day vulnerabilities
and are hard to fend off – blurring the threat landscape, causing confusion
where clarity is most needed.
after having announced the first round of Troopers
speakers
here,
we’re happy to publish the second round today 😉
Here we go:
==================
Dmitry Sklyarov – “Secure Password Managers” and “Military-Grade Encryption” on
Smartphones: Oh Really?
Abstract: The task of providing privacy and data confidentiality with mobile
applications becomes more and more important as the adoption of smartphones and
tablets grows. As a result, there are a number of vendors and applications
providing solutions to address those needs, such as password managers and file
encryption utilities for mobile devices.
“This document was produced jointly with the OWASP mobile security project. It
is also published as an ENISA deliverable in accordance with our work
program 2011. It is written for developers of smartphone apps as a guide to
developing secure apps. It may however also be of interest to project managers
of smartphone development projects.
We’re delighted to provide the first announcement of talks of next year’s
Troopers edition. Looks like it’s going to be a great
event again 😉
Here we go:
==================
Andreas Wiegenstein: Real SAP Backdoors
Abstract: In the past year the number of lecture sessions with traumatizing
headlines about hacking SAP systems has dramatically risen. Their content,
however, is usually the same. Insecure implementations of algorithms, side
effects in commands, flawed business logic and designs that brilliantly miss the
point of security. In essence, security defects built into the SAP framework by
mistake.
Currently there’s
quite some discussion
ongoing why it took Apple so long to fix a
severe vulnerability in the update process
of iTunes. A severe vulnerability which could easily be exploited by means of an
automated tool called
evilgrade which can
be downloaded here (Hi
Francisco!). Just one small note here: did you know that evilgrade was first
shown and released at the 2008 edition of
Troopers? We had a number of initial releases of tools
in the last years (like
wafw00f at the
2009 edition and
VASTO at the
2010 edition) and we will
continue this fine tradition in 2012. I can already promise that some nice code
is going to be released for the first time at Troopers12…
The above is the exact title of a
Gartner research note
published some days ago. Its main thesis is that an increased convergence of
carriers’ MPLS and Internet infrastructures onto shared IP infrastructures
requires that enterprises re-evaluate their security and performance risks.
While I do not agree with the overall line of reasoning in the paper, it still
highlights a number of interesting points when it comes to MPLS security. Which
in turn reminds me of quite some stuff we’ve done in the past, mainly our Black
Hat Europe 2009
talk “All your packets are belong to us – Attacking backbone technologies”.
Today we’ll release an updated version of the accompanying whitepaper as a
kind-of technical report. Its title is “Practical Attacks against MPLS or
Carrier Ethernet Networks” and it can be found
here.
Once again there’s a
reference to
some action movie here, as some of you may have immediately spotted ;-).
For the record: this one is from “Snake Plissken”, the main protagonist in John
Carpenter’s “Escape from New York”. There’s another well-known quote of the same
character in the kind-of sequel “Escape from L.A.” which goes like: “The more
things change, the more they stay the same”. I’m aware that this is not the
initial source (but French novelist Jean-Baptiste Alphonse Karr presumably is,
at the time in French ;-)); still this gives a nice transition to today’s
topic.
This week I stayed some days in Zurich, to give a workshop and to meet both
clients and fellow researchers (kudos again to C. for the awesome office tour
@Google). In the course of one of those dinners somehow Troopers was mentioned
and a guy asked: “I’ve heard of the conference. What’s so special about it?”
Funnily enough I didn’t even have to respond myself as a
2011 attendee
coincidentally present at the table jumped in and started praising the event
(“best con ever. great spirit, great talks”). Obviously this gave me a big grin…
but it reminded as well me that some of you might ask themselves the very same
question.
As a follow-up to
this post somebody
pointed us to
this interesting article
on S/MIME support and associated certificate mgmt in iOS 5. Nice read which some
of you may find worthwhile.
On a related note: if anyone is aware of an easy way/good (3rd party) solution
for pushing certs to iOS devices (besides SCEP) we would be very interested in
that one. In that case pls leave a comment or shoot us an email.