On March 16^(th), 2015, at the Troopers
IPv6 Security Summit,
we finally released the SI6 Networks’ IPv6 Toolkit v2.0 (Guille). The
aforementioned release is now available at the
SI6 IPv6 Toolkit homepage. It is
the result of over a year of work, and includes improvements in the following
areas:
Increased portability
Bug fixes
Additional features in existing tools
Brand-new tools
Increased Portability
One of the goals that the SI6 Toolkit had since its inception is that of
portability. The SI6 Toolkit has supported all major BSD-derived OSes, Linux,
and Mac OS for a number of years now. And this new release supports yet another
new platform: OpenSolaris. We believe that besides supporting a greater user
base, increased portability ultimately results in improved code quality.
We’ve just published the videos from TROOPERS15. The playlist can be found
here.
Thanks!
again to everybody for joining us in Heidelberg. We had a great time with you 😉
Admitted, we’re a bit late this time, but here we go with the agenda of this
year’s TelcoSecDay.
Given the high number of quality contributions overall there’s more talks than
in the previous years and we’ll hence start more early (and finish later 🙂 ),
so please plan accordingly.
This is the agenda, details for the invididual talks can be found in the
respective links:
We’ve just released a whitepaper discussing the behavior of different operating
systems once they receive IPv6 configuration parameters from different sources.
For that purpose a number of lab tests were conducted.
In short, it’s a mess.
Again, RFC ambiguity and/or
(perceived) vendor implementation freedom suck big time. For us practitioners
out (t)here this means (once more) we need extensive test labs and good
troubleshooting guides for large scale IPv6 deployments.
Based on recent research in the ERNW IPv6 lab and with
our MLD talk looming
we’ve put together a (as we think) comprehensive document discussing how to
thoroughly test MLD implementations in various components (network devices or
servers/clients). We hope it can contribute to a better understanding of the
protocol and that it can serve as either a checklist for your own environment or
as a source of inspiration for researchers looking at MLD themselves.
Last year,
during the
IPv6 Security Summit
of Troopers 14 I had the
pleasure to present publicly, for first time, my IPv6 Penetration Testing /
Security Assessment framework called
Chiron, while later, it was also
presented at Brucon 14 as part of the 5×5
project. This year, I am returning back to the place where it all started,
to the beautiful city of Heidelberg to give another workshop about Chiron at
the
IPv6 Security Summit
of Troopers 15. But, is it just another
workshop with the known Chiron features or has something changed?
I would say a lot :). The most significant enhancements are described below.
This is a guest post from Vladimir Wolstencroft, to provide some details of his
upcoming
#TR15 talk.
What do you get when you combine a security appliance vendor, a bug bounty
program, readily available virtualised machines, a lack of understanding of best
security practices and broken crypto?
Ownage, a good story and maybe even that bounty…
Focusing on Barracuda’s numerous security appliances, this talk will detail bug
hunting methods and the principles used to examine these machines:
Starting with a black box test and the challenges that this approach poses, to
decrypting the firmware, getting system root, bricking the box, fighting the
(de)activation methods, getting system root again, DOS’ing the VM host and
finally using Barracuda’s own source code to find those vulnerabilities that
otherwise would be invisible or impossible to find! There were also some
unexpected outcomes that followed…
We have pretty much finalized the agenda for the
Troopers TelcoSecDay and here’s another
cool talk (the others can be found
here,
here and
here):
Rob Kuiters: On her majesty’s secret service – GRX and a Spy Agency
Synopsis: In 2013 the GPRS Roaming eXchange (GRX) was in mainstream media as
part of the high profile Edward Snowden revelations. The leaked documents
indicated that the UK government’s intelligence organisation, Government
Communications Headquarters’ (GCHQ) hacked the Belgian GRX provider, Belgacom
International Carrier Services (BICS). They did this by targeting the GRX
provider’s employees with the ultimate aim of gaining access to Belgacom’s Core
GRX routers. Allegedly, GCHQ hacked the GRX routers in order to carry out
man-in-the middle “traffic sniffing” attacks against mobile users who are
roaming with smartphones or other devices capable of handling data.
in addition to those
recently announced and
these,
we’ve identified three more suitable talks for the TelcoSecDay
.
These are:
Hendrik Schmidt: Security Aspects of VoLTE
Synopsis: VoLTE is on its rise in mobile telecommunications. The service is
provided by the IP Multimedia Subsystem (IMS) which consists of a couple of
components. All those components offer new and, from an attacker’s perspective,
interesting interfaces. This talk evaluates the most interesting interfaces and
demonstrates attack vectors an attacker could abuse. This covers attacks from
customer access, Internet VoIP services and roaming exchange.