<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Matthias Luft on Insinuator.net - Bold Statements</title>
    <link>https://insinuator.net/authors/matthias-luft/</link>
    <description>Recent content in Matthias Luft on Insinuator.net - Bold Statements</description>
    <generator>Hugo</generator>
    <language>en-us</language>
    <lastBuildDate>Fri, 15 Jun 2018 00:00:00 +0000</lastBuildDate>
    <atom:link href="https://insinuator.net/authors/matthias-luft/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>Modern Application Stacks &amp; Security</title>
      <link>https://insinuator.net/2018/06/modern-application-stacks-security/</link>
      <pubDate>Fri, 15 Jun 2018 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2018/06/modern-application-stacks-security/</guid>
      <description>&lt;p&gt;I had the pleasure to give a presentation at the &lt;a href=&#34;https://www.sig-switzerland.ch/conference/sigs-technology-conference/&#34;&gt;Security Interest Group Switzerland Technology Conference&lt;/a&gt; about modern application stacks and how they can be used to improve infrastructure and application security posture – the slides can be found &lt;a href=&#34;https://ernw.de/download/ERNW_SIG_Cloud_ModernAppStackSecurity_mluft.pdf&#34;&gt;here&lt;/a&gt;. Besides seeing a lot of &lt;a href=&#34;https://twitter.com/ioshints&#34;&gt;old friends&lt;/a&gt;, I particularly enjoyed a round table discussion on security integration into CI/CD pipelines. There was a relevant exchange on approaches that actually work and were tested in environments beyond just recommending some container scanner (product). One participant had an interesting case study on how they enabled developers to maintain WAF policies in configuration files in their code repository including automated deployment to the WAF. He also emphasized that the environments with actual security benefits resulted from a close cooperation between development and security team (were domain knowledge was combined 😉 ).&lt;/p&gt;</description>
    </item>
    <item>
      <title>Industrial IoT Overview &amp; Case Studies</title>
      <link>https://insinuator.net/2018/04/industrial-iot-overview-case-studies/</link>
      <pubDate>Wed, 25 Apr 2018 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2018/04/industrial-iot-overview-case-studies/</guid>
      <description>&lt;p&gt;Stefan and I had the pleasure of joining a one-day closed workshop on Industrial IoT Security. As always, we ended up with plenty of new research ideas and great contacts. We hope of course to post on follow-up research, but in this short post we quickly want to publish our slides which contain our input for the workshop. We mainly presented on IT security challenges for modern IIoT environments and presented some case studies for successful hardening/protection of IIoT environments as well as security in IIoT product development.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Agile Development &amp; Security</title>
      <link>https://insinuator.net/2017/02/agile-development-security/</link>
      <pubDate>Sun, 26 Feb 2017 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2017/02/agile-development-security/</guid>
      <description>&lt;p&gt;I’m a big fan of Chris Gates’ publications on &lt;a href=&#34;https://www.slideshare.net/chrisgates/devoops-redux-ken-johnson-chris-gates-appsec-usa-2016&#34;&gt;DevOops&lt;/a&gt; and &lt;a href=&#34;http://www.carnal0wnage.com/papers/LARES-From-Low-To-Pwned.pdf&#34;&gt;From Low to Pwned&lt;/a&gt;. The content reflects a lot of issues that we also experience in many assessments in general and assessments &lt;a href=&#34;https://wycd.net/posts/2017-02-21-ibm-whole-cluster-privilege-escalation-disclosure.html&#34;&gt;in agile environments in particular&lt;/a&gt;. In addition, we were supporting several projects recently that were organized in an agile way. In this post, I want to summarize some thoughts on how security work can/should be integrated into agile projects. The post was also a result from the preparation of our upcoming Troopers workshop on &lt;a href=&#34;https://www.troopers.de/events/troopers17/730_docker_security__secdevops/&#34;&gt;Docker Security &amp;amp; Devops&lt;/a&gt;, which of course also covers organizational aspects, but not to the degree this post describes them.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Defending Democracy</title>
      <link>https://insinuator.net/2016/11/defending-democracy/</link>
      <pubDate>Thu, 24 Nov 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/11/defending-democracy/</guid>
      <description>&lt;p&gt;I recently had the pleasure to attend two events organized by the &lt;a href=&#34;https://www.esmt.org/faculty-research/centers-chairs-and-institutes/digital-society-institute-dsi&#34;&gt;Digital Society Institute&lt;/a&gt;, one was a &lt;a href=&#34;https://www.esmt.org/node/26449&#34;&gt;workshop on software vulnerabilities&lt;/a&gt; and one was their annual &lt;a href=&#34;https://www.esmt.org/faculty-research/events/conferences-and-workshops/digital-society-conference-2016-defending&#34;&gt;conference&lt;/a&gt;. For both events I delivered input on the security of security products and their evaluation (slides can be found &lt;a href=&#34;https://www.ernw.de/download/ERNWResearch_CritivalViewOnSecProducts_mluft.pdf&#34;&gt;here&lt;/a&gt;). The DSI did a great job of assembling people from various areas (e.g. industry, academia, politics, and research) so there was a lot of input which is not covered by conferences I usually attend. The workshop I attended also resulted in a short policy recommendation when it comes to the security of security products which can be found &lt;a href=&#34;https://www.esmt.org/sites/default/files/2016_dsi_ipr_vulnerabilities-in-it-security-products.pdf&#34;&gt;here&lt;/a&gt;.&lt;/p&gt;</description>
    </item>
    <item>
      <title>15. Cyber-Sicherheits-Tag</title>
      <link>https://insinuator.net/2016/11/15.-cyber-sicherheits-tag/</link>
      <pubDate>Tue, 08 Nov 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/11/15.-cyber-sicherheits-tag/</guid>
      <description>&lt;p&gt;Today Kevin and I had the pleasure to to present at the German &lt;a href=&#34;https://www.allianz-fuer-cybersicherheit.de/ACS/DE/Erfahrungsaustausch/CST/cur/cst.html&#34;&gt;15. Cyber-Sicherheits-Tag&lt;/a&gt; in &lt;a href=&#34;https://en.wikipedia.org/wiki/Project_Blinkenlights&#34;&gt;Berlin&lt;/a&gt; which is organized by the &lt;a href=&#34;https://www.allianz-fuer-cybersicherheit.de/ACS/DE/Home/startseite.html&#34;&gt;Alliance for Cyber Security&lt;/a&gt;. This iteration covered security aspects of the Internet of Things and we enjoyed some great conversations. The presentations were limited to ten slides and can be found here:&lt;/p&gt;&#xA;&lt;p&gt;&lt;a href=&#34;https://www.ernw.de/download/ERNW_Defense_in_Depth_IoT_kschaller.pdf&#34;&gt;Kevin Schaller – Defense in Depth in IoT&lt;/a&gt;&lt;/p&gt;&#xA;&lt;p&gt;&lt;a href=&#34;https://www.ernw.de/download/ERNWResearch_UpdateManagementAndIoT_mluft.pdf&#34;&gt;Matthias Luft – Update Management in IoT&lt;/a&gt;&lt;/p&gt;&#xA;&lt;p&gt;Since the slides were supposed to be short and only support the presentation, you still have the chance to get the full content (and even challenge it or ask to dive deeper during the break-out discussions) next week at &lt;a href=&#34;https://www.troopers.de/iot-insight-summit-2016/iot-insight-summit-2016-overview/&#34;&gt;our own IoT event&lt;/a&gt; 😉&lt;/p&gt;</description>
    </item>
    <item>
      <title>Introducing the Kernel Space Invaders</title>
      <link>https://insinuator.net/2016/09/introducing-the-kernel-space-invaders/</link>
      <pubDate>Tue, 20 Sep 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/09/introducing-the-kernel-space-invaders/</guid>
      <description>&lt;p&gt;Today it is my pleasure to shortly introduce ERNW’s Capture the Flag team, the Kernel Space Invaders. As a long-time CTF enthusiast, I’m really amazed how many of us make the time to tackle IT security challenges also on the weekends or evenings. Even if we cannot participate in all CTFs out there (which would be challenging anyways given the &lt;a href=&#34;https://ctftime.org/&#34;&gt;large number of CTF events&lt;/a&gt; happening nowadays), we started to compile a &lt;a href=&#34;https://github.com/ernw/ctf-writeups/&#34;&gt;repository&lt;/a&gt; of some of our write-ups — I hope some of you will enjoy!&lt;/p&gt;</description>
    </item>
    <item>
      <title>Files Your Webserver Shouldn’t Deliver</title>
      <link>https://insinuator.net/2016/09/files-your-webserver-shouldnt-deliver/</link>
      <pubDate>Sun, 18 Sep 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/09/files-your-webserver-shouldnt-deliver/</guid>
      <description>&lt;p&gt;During penetration tests, we often find interesting files on web servers. Almost as often, those files enable us to carry out further attacks with much higher impact. Inspired by Chris Gate’s great series &lt;a href=&#34;http://carnal0wnage.attackresearch.com/2012/05/from-low-to-pwned-4-browsable.html&#34;&gt;From Low to Pwned&lt;/a&gt;, we decided to share the following small piece.&lt;/p&gt;&#xA;&lt;p&gt;The web server under test did not deliver directory listings. However, the directory contained a &lt;a href=&#34;https://en.wikipedia.org/wiki/.DS_Store&#34;&gt;.DS_Store&lt;/a&gt; file (one of macOS’ many — lets say special — traits). While .DS_Store files store various information, a simple cat shows one relevant characteristic:&lt;/p&gt;</description>
    </item>
    <item>
      <title>SIGS DC Day</title>
      <link>https://insinuator.net/2016/09/sigs-dc-day/</link>
      <pubDate>Fri, 16 Sep 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/09/sigs-dc-day/</guid>
      <description>&lt;p&gt;Today I had to give the pleasure to give a keynote at the &lt;a href=&#34;http://digs.ch/dc-day/&#34;&gt;SIGS DC Day&lt;/a&gt; on the need to evaluate Cloud Service Providers in a way that looks behind (or at least tries to) security whitepapers and certification reports. The slides can be found &lt;a href=&#34;https://www.ernw.de/download/ERNWResearch_TrustEvaluationCloudProvider_mluft.pdf&#34;&gt;here&lt;/a&gt;.&lt;/p&gt;&#xA;&lt;p&gt;I also particularly enjoyed the following two talks:&lt;/p&gt;&#xA;&lt;p&gt;Sean O’Tool from Swisscom AG covered challenges of an infrastructure to cloud migration. Even though he only briefly touched the topic, I enjoyed his description of their firewalling model: Seeing that centralized firewall operation (or more precisely, rule design and approval) is limited/challenged by the understanding of the application, they transferred control over firewall rule sets (beyond a basic set of infrastructure/ground rules) to the application teams (using of features like OpenStack’s security groups, where he also talked about limitations of those). They compensated the loss of “centralized enforcement by a security group” with rule reviews — an approach that will become way more relevant (and necessary) in the future.&lt;/p&gt;</description>
    </item>
    <item>
      <title>ERNW Hardening Repository</title>
      <link>https://insinuator.net/2016/08/ernw-hardening-repository/</link>
      <pubDate>Sun, 21 Aug 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/08/ernw-hardening-repository/</guid>
      <description>&lt;p&gt;Today we started publishing several of our hardening documents to a &lt;a href=&#34;https://github.com/ernw/hardening&#34;&gt;dedicated GitHub repository&lt;/a&gt; — and we’re quite excited about it! It took a while to develop a suitable markdown template to support all the requirements you have when you write a hardening guide, but we’re online now!&lt;/p&gt;&#xA;&lt;p&gt;At the moment, only a few hardening guides are online, but that should continuously increase in the future.&lt;/p&gt;&#xA;&lt;p&gt;&lt;a href=&#34;https://github.com/ernw/hardening&#34;&gt;Click here for the GitHub ERNW Hardening Repository!&lt;/a&gt;&lt;/p&gt;</description>
    </item>
    <item>
      <title>Check your SAP landscape for default Solution Manager users</title>
      <link>https://insinuator.net/2016/03/check-your-sap-landscape-for-default-solution-manager-users/</link>
      <pubDate>Thu, 10 Mar 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/03/check-your-sap-landscape-for-default-solution-manager-users/</guid>
      <description>&lt;p&gt;This is a guest post from Joris van de Vis &lt;a href=&#34;https://twitter.com/jvis&#34;&gt;@jvis&lt;/a&gt;,  on his upcoming Troopers &lt;a href=&#34;https://www.troopers.de/events/troopers16/603_an_easy_way_into_your_multi-million_dollar_sap_systems_an_unknown_default_sap_account/&#34;&gt;talk&lt;/a&gt;. Additional credits go to: Robin Vleeschhouwer, and Fred van de Langenberg.&lt;/p&gt;&#xA;&lt;hr&gt;&#xA;&lt;p&gt; &lt;/p&gt;&#xA;&lt;p&gt;&lt;img src=&#34;https://www.insinuator.net/wp-content/uploads/2016/03/Picture1.png&#34; alt=&#34;Picture1&#34;&gt;&lt;/p&gt;&#xA;&lt;p&gt;As &lt;a href=&#34;https://www.troopers.de/events/troopers16/603_an_easy_way_into_your_multi-million_dollar_sap_systems_an_unknown_default_sap_account/&#34;&gt;presented at Troopers&lt;/a&gt; this year, ERP-SEC research has uncovered a set of potential default accounts related to the use of SAP Solution Manager. These default accounts might pose a big risk to your SAP supported business as some of them have wide authorisations. It is therefore important to check if they exist in your landscape and change the default passwords.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Cloud Security &amp; Trust</title>
      <link>https://insinuator.net/2016/03/cloud-security-trust/</link>
      <pubDate>Thu, 10 Mar 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/03/cloud-security-trust/</guid>
      <description>&lt;p&gt;Hi,&lt;/p&gt;&#xA;&lt;p&gt;I gave a presentation on Cloud Security, Compliance &amp;amp; Trust the other day. The basic message was to look beyond the Cloud buzzword and see the actual technologies which are used, understand which security principles still apply and which need to be re-thought, giving a rough direction about regulatory compliance in Cloud environments (which of course is non-binding, as I’m not a lawyer), and the importance of trust evaluations (especially) when it comes to Cloud services.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Docker, DevOps &amp; Security</title>
      <link>https://insinuator.net/2016/03/docker-devops-security/</link>
      <pubDate>Thu, 10 Mar 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/03/docker-devops-security/</guid>
      <description>&lt;p&gt;Hi,&lt;/p&gt;&#xA;&lt;p&gt;this week I gave a presentation together with &lt;a href=&#34;https://twitter.com/der_Cthulhu&#34;&gt;Florian Barth&lt;/a&gt; from &lt;a href=&#34;http://stocardapp.com/&#34;&gt;Stocard&lt;/a&gt; on Docker, DevOps/Microservices, and Security — a topic and collaboration that I will definitely cover in even more detail in the future!&lt;/p&gt;&#xA;&lt;p&gt;The slides can be found &lt;a href=&#34;https://www.ernw.de/download/ERNW_Stocard_Docker-Devops-Security_fbarth-mluft.pdf&#34;&gt;here&lt;/a&gt;.&lt;/p&gt;&#xA;&lt;p&gt;so long,&lt;/p&gt;&#xA;&lt;p&gt;Matthias&lt;/p&gt;</description>
    </item>
    <item>
      <title>VMware did it again: vCenter Remote Code Execution</title>
      <link>https://insinuator.net/2015/10/vmware-did-it-again-vcenter-remote-code-execution/</link>
      <pubDate>Fri, 02 Oct 2015 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2015/10/vmware-did-it-again-vcenter-remote-code-execution/</guid>
      <description>&lt;p&gt;Yesterday 7Elements released &lt;a href=&#34;https://www.7elements.co.uk/resources/blog/cve-2015-2342-remote-code-execution-within-vmware-vcenter/&#34;&gt;the description&lt;/a&gt; of a Remote Code Execution vulnerability in VMware vCenter. The information came in at a good point as I’m at the moment drafting a follow-up blogpost for &lt;a href=&#34;https://www.insinuator.net/2014/01/state-of-virtualization-security-14/&#34;&gt;this one&lt;/a&gt; which will summarize some of our approaches to virtualization security. The vCenter vulnerability is both quite critical and particularly interesting in several ways:&lt;/p&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;Once there is proper network isolation &amp;amp; restriction, the vulnerability should not be exploitable from the overall corporate network (or maybe even the Internet — a quick inaccurate shodan search for “vcenter” returned about 1800 results and at random checks actually revealed vCenter systems). It should also not be exploitable from ESXi hosts managed through the vCenter: ESXi hosts need to be able to connect to the vCenter for heartbeat messages, however “only” on ports 443 and 902 — the vulnerability exploits a service running on TCP ports &lt;a href=&#34;http://kb.vmware.com/selfservice/microsites/search.do?language=en_US&amp;amp;cmd=displayKC&amp;amp;externalId=2051575&#34;&gt;9875 – 9877&lt;/a&gt;.&lt;/li&gt;&#xA;&lt;li&gt;It is questionable whether the exploited Java RMI functionality is really required for the operation of VMware infrastructures. This &lt;a href=&#34;http://www.accuvant.com/blog/exploiting-jmx-rmi&#34;&gt;blogpost&lt;/a&gt; provides further detail on the known type of vulnerability in Java applications. VMware had a similar issue back in 2010, where &lt;a href=&#34;http://kb.vmware.com/selfservice/microsites/search.do?language=en_US&amp;amp;cmd=displayKC&amp;amp;externalId=1034175&#34;&gt;their workaround&lt;/a&gt; to fix a vulnerability was to just disable the affected component, resulting in the impression that it wasn’t even required in the first place. Let’s see whether the future will bring up more vulnerabilities which could have been prevented by implementing more thorough hardening of all components (e.g. following the &lt;em&gt;minimal machine&lt;/em&gt; principle). Furthermore in 2011 there was a similar 3^(rd) party component vulnerability in vCenter which we covered &lt;a href=&#34;https://www.insinuator.net/2011/03/vmsa-2011-0005-vmware-vcenter-orchestrator-remote-code-execution-vulnerability/&#34;&gt;in this blogpost&lt;/a&gt;. The totality of our posts on VMware security can be found &lt;a href=&#34;https://www.insinuator.net/tag/vmware/&#34;&gt;here&lt;/a&gt;.&lt;/li&gt;&#xA;&lt;li&gt;For high-security environments we have been recommending for some time to use a dedicated vCenter per hypervisor cluster (i.e. if you have two hypervisor clusters, one for internal and one for DMZ systems, you should use two separate vCenter systems). Vulnerabilities like these illustrate the need for that, given that the ESXi hosts need to be able to access the vCenter on the network level.&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;p&gt;Happy patching &amp;amp; stay tuned,&lt;/p&gt;</description>
    </item>
    <item>
      <title>BT SnoopCon</title>
      <link>https://insinuator.net/2015/06/bt-snoopcon/</link>
      <pubDate>Mon, 29 Jun 2015 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2015/06/bt-snoopcon/</guid>
      <description>&lt;p&gt;I had the honour to be invited to &lt;a href=&#34;http://www.bt.com&#34;&gt;BT&lt;/a&gt;‘s SnoopCon, which is their annual internal conference for people involved with security at BT. There were several external and internal speakers and I was stunned by the quality of the talks and the collaborative atmosphere. Since this event is somewhat internal (even though I’m obviously allowed to talk about it), I won’t go into details, however there were two particularly great talks about military war games (which I personally enjoyed very much given my history in CTF contests) and PoS security.&lt;/p&gt;</description>
    </item>
    <item>
      <title>CSA.no Nordic Summit</title>
      <link>https://insinuator.net/2015/06/csa.no-nordic-summit/</link>
      <pubDate>Sun, 28 Jun 2015 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2015/06/csa.no-nordic-summit/</guid>
      <description>&lt;p&gt;Flo and I had the pleasure to present at the &lt;a href=&#34;https://csanorway.no/&#34;&gt;CSA&lt;/a&gt; &lt;a href=&#34;https://csanordicsummitandsummercon2015.sched.org/&#34;&gt;Nordic Summit&lt;/a&gt; in Norway. Being in Oslo for the first time, we enjoyed the conference (small, familiar atmosphere) very much and want to thank Lars and Kai for putting together such a good event &amp;amp; having us there!&lt;/p&gt;&#xA;&lt;p&gt;Our slides can be found here:&lt;/p&gt;&#xA;&lt;p&gt;&lt;a href=&#34;https://www.ernw.de/download/ERNW_CSA-No-Summit_Hacking_Medical_Devices_fgrunow.pdf&#34;&gt;Hacking Medical Devices&lt;/a&gt;&lt;/p&gt;&#xA;&lt;p&gt;&lt;a href=&#34;https://www.ernw.de/download/ERNW_CSA-No-Summit_ToolsOfTheTrade_mluft.pdf&#34;&gt;Tools of the Trade: Lessons Learned from the (C)ISO’s Desk&lt;/a&gt;&lt;/p&gt;&#xA;&lt;p&gt; &lt;/p&gt;&#xA;&lt;p&gt;best,&lt;/p&gt;&#xA;&lt;p&gt;Matthias&lt;/p&gt;</description>
    </item>
    <item>
      <title>ERNW @Mudiator</title>
      <link>https://insinuator.net/2015/06/ernw-@mudiator/</link>
      <pubDate>Sun, 07 Jun 2015 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2015/06/ernw-@mudiator/</guid>
      <description>&lt;p&gt;Today the ERNW Team participated in the &lt;a href=&#34;http://mudiator.com/&#34;&gt;Mudiator&lt;/a&gt; mud race in &lt;a href=&#34;https://www.google.de/maps/place/49%C2%B028&#39;11.7%22N+8%C2%B031&#39;34.6%22E/@49.469926,8.526285,17z&#34;&gt;Mannheim&lt;/a&gt;. This mud run features 25 obstacles over 8 km, you can do either one or two rounds. Participating for the first time, the ERNW team went for one round (the &lt;em&gt;Legionnaire&lt;/em&gt; distance as opposed to the two round &lt;em&gt;Hercules&lt;/em&gt; distance):&lt;/p&gt;&#xA;&lt;p&gt; &lt;/p&gt;&#xA;&lt;p&gt;&lt;a href=&#34;http://www.insinuator.net/wp-content/uploads/2015/06/20150607_105045_small.jpg&#34;&gt;&lt;img src=&#34;http://www.insinuator.net/wp-content/uploads/2015/06/20150607_105045_small.jpg&#34; alt=&#34;20150607_105045_small&#34;&gt;&lt;/a&gt;&lt;/p&gt;&#xA;&lt;p&gt;Following our idea of open access to knowledge (both about vulnerabilities and sports 😉 ), here are some hints/lessons learned:&lt;/p&gt;</description>
    </item>
    <item>
      <title>Evaluating Behavior-based Malware Detection</title>
      <link>https://insinuator.net/2015/01/evaluating-behavior-based-malware-detection/</link>
      <pubDate>Fri, 23 Jan 2015 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2015/01/evaluating-behavior-based-malware-detection/</guid>
      <description>&lt;p&gt;Quite some organizations complemented their traditional AV solutions with a technology that can best be described as behavior-based malware detection. While we all know we are talking about products like Fireeye Email/Network Security, zScaler Web Security/APT Protection, or Cisco WSA, there are a lot of terms around to describe this type of products (such as next generation malware analysis/detection, Secure Web Gateways, or behavior-based malware detection). Those offerings typically promise the detection of malware by analyzing the behavior of ‘samples’ (which are files captured in transit of different types, such as executables or PDF documents). However, beyond the taxonomy challenges, both assessment and consulting work gets us frequently in contact with those solutions. While the main task during assessments is to bypass those solutions, the main question in the consulting context typically is “to what degree are the solutions suited to protect from common targeted attacks in the enterprise context”. Luckily, the experience from assessment work allows us to tackle this question in a structured way (which is our approach for consulting anyways: Benefit from our assessment experiences in order to provide reasonable consulting advice…).&lt;/p&gt;</description>
    </item>
    <item>
      <title>Some Design Aspects of Hacking Challenges</title>
      <link>https://insinuator.net/2015/01/some-design-aspects-of-hacking-challenges/</link>
      <pubDate>Sun, 04 Jan 2015 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2015/01/some-design-aspects-of-hacking-challenges/</guid>
      <description>&lt;p&gt;We’re currently starting the preparation for the &lt;a href=&#34;https://www.troopers.de&#34;&gt;Troopers15&lt;/a&gt; &lt;a href=&#34;http://packetwars.com/&#34;&gt;PacketWars Challenge&lt;/a&gt;, and since I’ve participated in quite some CTF games and have been involved in the preparation of a number of PacketWars Battles, I thought I’d write down some thoughts on the design of hacking challenges.&lt;/p&gt;&#xA;&lt;p&gt;First of all, my experience is limited almost exclusively to attack-defend-CTFs or interactive war games (such as &lt;a href=&#34;http://packetwars.com/&#34;&gt;PacketWars&lt;/a&gt; or &lt;a href=&#34;http://en.wikipedia.org/wiki/National_Collegiate_Cyber_Defense_Competition&#34;&gt;CCDC&lt;/a&gt;). While thinking about this blogpost, I also came across several terms which are used, so I decided to give a short summary:&lt;/p&gt;</description>
    </item>
    <item>
      <title>Hardening Against Local PrivEsc: Protecting Your Links</title>
      <link>https://insinuator.net/2014/12/hardening-against-local-privesc-protecting-your-links/</link>
      <pubDate>Tue, 30 Dec 2014 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2014/12/hardening-against-local-privesc-protecting-your-links/</guid>
      <description>&lt;p&gt;Following up on &lt;a href=&#34;https://www.insinuator.net/2014/12/revisiting-an-old-friend-shell-globbing/&#34;&gt;this post&lt;/a&gt;, we want to provide some details on &lt;a href=&#34;http://www.openwall.com/lists/kernel-hardening/2012/01/07/1&#34;&gt;two rather new&lt;/a&gt; (well, compared to its lifespan) Linux kernel parameters — and emphasize the need to enable those:&lt;/p&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;fs.protected_hardlinks&lt;/li&gt;&#xA;&lt;li&gt;fs.protected_symlinks&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;p&gt;For BSD, similar parameters for hardlinks exist: security.bsd.hardlink_check_uid/security.bsd.hardlink_check_gid.&lt;/p&gt;&#xA;&lt;p&gt;Those parameters control whether users are allowed to create links pointing to files which are not owned by them. If &lt;em&gt;fs.protected_hardlinks/symlinks&lt;/em&gt; is set to &lt;em&gt;1&lt;/em&gt;, users can only create links to files which they own. Attackers have used this possibility for a long time, and here are some sample attack scenarios:&lt;/p&gt;</description>
    </item>
    <item>
      <title>ERNW @BlackHat US 2014</title>
      <link>https://insinuator.net/2014/08/ernw-@blackhat-us-2014/</link>
      <pubDate>Tue, 12 Aug 2014 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2014/08/ernw-@blackhat-us-2014/</guid>
      <description>&lt;p&gt;Last week we had the opportunity and pleasure to present some of our research results at BlackHat US 2014 (besides of meeting a lot of old friends and having a great researchers’ dinner).&lt;/p&gt;&#xA;&lt;p&gt;Enno and Antonios gave their presentation on IDPS evasion by IPv6 Extension Headers, described &lt;a href=&#34;http://www.insinuator.net/2014/08/evading-idps-by-combining-ipv6-extension-headers-and-fragmentation-features-the-story-of-my-life/&#34;&gt;here&lt;/a&gt;.&lt;/p&gt;&#xA;&lt;p&gt;The material can be found here: &lt;a href=&#34;https://www.ernw.de/download/Atlasis_Rey_BHUSA_2014_IPv6_Evasion_of_HighEnd_IPS_Devices_web.pdf&#34;&gt;Slides&lt;/a&gt;, &lt;a href=&#34;http://www.secfu.net/tools-scripts/&#34;&gt;tools&lt;/a&gt; (the main tool used was Chiron, authored by Antonios) &amp;amp; &lt;a href=&#34;https://www.ernw.de/download/us-14-Atlasis-Evasion-Of-HighEnd-IPS-Devices-In-The-Age-Of-IPv6-WP.pdf&#34;&gt;whitepaper&lt;/a&gt;.&lt;/p&gt;&#xA;&lt;p&gt;Ayhan and me presented our results of the security analysis of Cisco’s EnergyWise protocol. The protocol enables network-wide power monitoring and control (ie turning servers off or on, putting phones to standby — basically controlling the power state of all EnergyWise-enabled or PoE devices). The main problem (besides a DoS vulnerability we found in IOS, see &lt;a href=&#34;http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20140806-energywise&#34;&gt;official Cisco advisory&lt;/a&gt;) is its PSK-based authentication model, which enables an attacker to cause large-scale blackouts in data centers if the deployment is lacking certain controls (for example our good old favorite, segmentation…). There will be a longer blogpost/newsletter on this topic soon.&lt;br&gt;&#xA;The material can be found here: &lt;a href=&#34;https://www.ernw.de/download/ERNW_BHUS14_WhenTheLightsGoOut_akoca-mluft.pdf&#34;&gt;Slides&lt;/a&gt; &amp;amp; &lt;a href=&#34;https://www.ernw.de/download/tools/energywise_attack_suite_BH_US14.zip&#34;&gt;tools&lt;/a&gt;&lt;/p&gt;</description>
    </item>
    <item>
      <title>Some notes on VMware vCenter Operations Manager</title>
      <link>https://insinuator.net/2014/08/some-notes-on-vmware-vcenter-operations-manager/</link>
      <pubDate>Tue, 12 Aug 2014 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2014/08/some-notes-on-vmware-vcenter-operations-manager/</guid>
      <description>&lt;p&gt;While fairytales often start with “Once upon a time…”, our blogposts often start with “During a recent security assessment…” — and so does this one. This time we were able to spend some time on VMware’s &lt;a href=&#34;http://www.vmware.com/products/vcenter-operations-manager&#34;&gt;vCenter Operations Manager&lt;/a&gt; (herein short: VCOPS). VCOPS is a monitoring solution for load and health of your vSphere environment. In order to provide this service, two virtual machines (analytics engine and Web-based UI) must be deployed (as a so-called vApp) that are configured on startup by various scripts (mainly /usr/lib/vmware-vcops/user/conf/install/firstbootcommon.sh) to match the actual environment and communicate via an OpenVPN tunnel that is established directly between the two machines. To gather the monitoring data, read-only access to the vCenter is required.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Serial Port Debugging Between two Virtual Machines in VMware Fusion</title>
      <link>https://insinuator.net/2014/01/serial-port-debugging-between-two-virtual-machines-in-vmware-fusion/</link>
      <pubDate>Thu, 16 Jan 2014 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2014/01/serial-port-debugging-between-two-virtual-machines-in-vmware-fusion/</guid>
      <description>&lt;p&gt;In the course of our virtualization research, we came across a certain technical issue we couldn’t find an easy solution on knowledge bases and the like. However, as we found the question several times on the web, the following post gives just a short hint on a technical detail.&lt;/p&gt;&#xA;&lt;p&gt;If you want to connect two virtual machines in VMware Fusion using a serial port (e.g. for debugging purposes), Fusion doesn’t provide you an GUI option to configure that. However, if you just add the following config to the debugger system’s VMX file:&lt;/p&gt;</description>
    </item>
    <item>
      <title>Exploiting Hyper-V: How We Discovered MS13-092</title>
      <link>https://insinuator.net/2014/01/exploiting-hyper-v-how-we-discovered-ms13-092/</link>
      <pubDate>Tue, 14 Jan 2014 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2014/01/exploiting-hyper-v-how-we-discovered-ms13-092/</guid>
      <description>&lt;p&gt;During a recent research project we performed an in-depth security assessment of Microsoft’s virtualization technologies, including Hyper-V and Azure. While we already had experience in discovering security vulnerabilities in other virtual environments (e.g. &lt;a href=&#34;http://www.insinuator.net/2012/05/vmdk-has-left-the-building/&#34;&gt;here&lt;/a&gt; and &lt;a href=&#34;http://www.insinuator.net/2011/07/the-key-to-your-datacenter/&#34;&gt;here&lt;/a&gt;), this was our first research project on the Microsoft virtualization stack and we took care to use a &lt;a href=&#34;http://www.insinuator.net/2013/05/analysis-of-hypervisor-breakouts/&#34;&gt;structured evaluation strategy&lt;/a&gt; to cover all potential attack vectors.&lt;br&gt;&#xA;Part of our research concentrated on the Hyper-V hypervisor itself and we discovered a critical vulnerability which can be exploited by an unprivileged virtual machine to crash the hypervisor and potentially compromise other virtual machines on the same physical host. This bug was recently patched, see &lt;a href=&#34;https://technet.microsoft.com/en-us/security/bulletin/ms13-092&#34;&gt;MS13-092&lt;/a&gt; and our &lt;a href=&#34;http://www.insinuator.net/2014/01/state-of-virtualization-security-14/&#34;&gt;corresponding post&lt;/a&gt;.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Tomcat 7 Hardening Guide</title>
      <link>https://insinuator.net/2014/01/tomcat-7-hardening-guide/</link>
      <pubDate>Sat, 11 Jan 2014 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2014/01/tomcat-7-hardening-guide/</guid>
      <description>&lt;p&gt;Hi,&lt;/p&gt;&#xA;&lt;p&gt;continuing our tradition from last year (see &lt;a href=&#34;http://www.insinuator.net/2013/08/sles-11-hardening-guide/&#34;&gt;here&lt;/a&gt; and &lt;a href=&#34;http://www.insinuator.net/2013/07/basic-os-x-hardening-dma/&#34;&gt;here&lt;/a&gt;), we summarized more of our hardening recommendations for you. This guide is covering Tomcat 7 and is supposed to provide a solid base of hardening measures. It includes configuration examples and all necessary commands for each control, specifically for the most recent branch of Tomcat as there were some significant changes. Download: &lt;a href=&#34;https://www.ernw.de/download/hardening/ERNW_Checklist_Tomcat7_Hardening.pdf&#34;&gt;ERNW_Checklist_Tomcat7_Hardening.pdf&lt;/a&gt;&lt;/p&gt;&#xA;&lt;p&gt;Have a good one,&lt;/p&gt;&#xA;&lt;p&gt;Matthias&lt;/p&gt;</description>
    </item>
    <item>
      <title>State of Virtualization Security ‘14</title>
      <link>https://insinuator.net/2014/01/state-of-virtualization-security-14/</link>
      <pubDate>Sun, 05 Jan 2014 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2014/01/state-of-virtualization-security-14/</guid>
      <description>&lt;p&gt;First of all, I hope you all had a good start to 2014. Having some time off “between the years” (which is a German saying for the time between Christmas and NYE), I caught up on several virtualization security topics.&lt;/p&gt;&#xA;&lt;p&gt;While virtualization is widely accepted as a sufficiently secure technology in many areas of IT operations (also for sensitive applications or exposed systems, like &lt;a href=&#34;http://www.insinuator.net/2009/12/some-reflections-on-virtualization-security-part-1/&#34;&gt;DMZs&lt;/a&gt;) by 2014, there are several recent vulnerabilities and incidents that are worth mentioning.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Security Team 2.0</title>
      <link>https://insinuator.net/2013/08/security-team-2.0/</link>
      <pubDate>Sat, 24 Aug 2013 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2013/08/security-team-2.0/</guid>
      <description>&lt;p&gt;I’m currently catching up on a lot of papers and presentation from the &lt;a href=&#34;https://www.usenix.org/conference/usenixsecurity13&#34;&gt;Usenix Security Symposium&lt;/a&gt; in order to finish the blog post series I started last week (summarizing &lt;a href=&#34;http://www.insinuator.net/2013/08/woot13/&#34;&gt;WOOT&lt;/a&gt; and &lt;a href=&#34;http://www.insinuator.net/2013/08/leet13/&#34;&gt;LEET&lt;/a&gt;). One presentation, which unfortunately is  not available online [edit: see also update, &lt;a href=&#34;https://www.usenix.org/conference/usenixsecurity13/security-team-20&#34;&gt;videos&lt;/a&gt; are available now], included several particularly relevant messages that I want to share in this dedicated post. Chris Evans, the head of the Google Chrome security team (herein short: GCST), described some new approaches they employed for their security team operations, some lessons learned, and how others can benefit from it as well (actually the potential of these messages to make the world a safer place was my motivation to write this post, even though I got teased for supposedly being a Google fanboy 😉 ):&lt;/p&gt;</description>
    </item>
    <item>
      <title>WOOT’13</title>
      <link>https://insinuator.net/2013/08/woot13/</link>
      <pubDate>Wed, 14 Aug 2013 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2013/08/woot13/</guid>
      <description>&lt;p&gt;Continuing &lt;a href=&#34;http://www.insinuator.net/2013/08/leet13/&#34;&gt;yesterday’s post&lt;/a&gt;, I compiled a short summary of relevant &lt;a href=&#34;https://www.usenix.org/conference/woot13/tech-schedule/workshop-program&#34;&gt;WOOT’13&lt;/a&gt; presentations.&lt;/p&gt;&#xA;&lt;hr&gt;&#xA;&lt;p&gt;&lt;em&gt;Truncating TLS Connections to Violate Beliefs in Web Applications&lt;/em&gt;&lt;br&gt;&#xA;&lt;em&gt;Ben Smyth and Alfredo Pironti, INRIA Paris-Rocquencourt&lt;/em&gt;&lt;/p&gt;&#xA;&lt;p&gt;This presentation was also given at &lt;a href=&#34;https://media.blackhat.com/us-13/US-13-Smyth-Truncating-TLS-Connections-to-Violate-Beliefs-in-Web-Applications-Slides.pdf&#34;&gt;BlackHat&lt;/a&gt; some weeks ago. It outlines a very interesting class of attacks against web applications abusing the TLS specification which states that “failure to properly close a connection no longer requires that a session not be resumed […] to conform with widespread implementation practice”. This characteristic enables new attack vectors on shared systems where certain outgoing (TLS encrypted) packets can be dropped in order to prevent applications from e.g. correctly finishing transaction (such as log out procedures) or even modifying the request bodies by dropping the last parts.&lt;/p&gt;</description>
    </item>
    <item>
      <title>LEET’13</title>
      <link>https://insinuator.net/2013/08/leet13/</link>
      <pubDate>Tue, 13 Aug 2013 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2013/08/leet13/</guid>
      <description>&lt;p&gt;I have the pleasure to visit this year’s &lt;a href=&#34;https://www.usenix.org/conference/usenixsecurity13&#34;&gt;USENIX Security Symposium&lt;/a&gt; in Washington, DC. Besides the nice venue close to the &lt;a href=&#34;http://en.wikipedia.org/wiki/National_mall&#34;&gt;national mall&lt;/a&gt;, there are also several co-located workshops. Every night I will try and provide a summary of those presentations I regard as most interesting. However, I hope to manage to keep up with it as there are a lot of interesting events, people to meet, and still some projects to keep up with. The short summaries below are from the &lt;em&gt;6th USENIX Workshop on Large-Scale Exploits and Emergent Threats&lt;/em&gt;.&lt;/p&gt;</description>
    </item>
    <item>
      <title>MFD Vulnerabilities</title>
      <link>https://insinuator.net/2013/08/mfd-vulnerabilities/</link>
      <pubDate>Wed, 07 Aug 2013 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2013/08/mfd-vulnerabilities/</guid>
      <description>&lt;p&gt;A recent &lt;a href=&#34;http://seclists.org/bugtraq/2013/Aug/28&#34;&gt;post&lt;/a&gt; describing some nasty vulnerabilities in HP &lt;a href=&#34;http://www.google.de/search?hl=en&amp;amp;site=imghp&amp;amp;tbm=isch&amp;amp;source=hp&amp;amp;biw=1276&amp;amp;bih=663&amp;amp;q=multifunction+device&amp;amp;oq=multifunction+device&amp;amp;gs_l=img.3..0j0i5j0i24l7.2450.5517.0.5606.20.15.0.4.4.0.99.959.15.15.0....0...1ac.1.24.img..1.19.973.43a2mDdYMDE&#34;&gt;multifunction devices&lt;/a&gt; (MFDs) brings back memories of a &lt;a href=&#34;https://www.troopers.de/wp-content/uploads/2011/04/TR11_Schaefer_Luft_Multifunction_devices.pdf&#34;&gt;presentation&lt;/a&gt; Micele and I gave at &lt;a href=&#34;https://www.troopers.de/archives/troopers11&#34;&gt;Troopers11&lt;/a&gt; on MFD security. The published vulnerabilities are highly relevant  (such as unauthenticated retrieval of administrative credentials) and reminded me of some of the basic recommendations we gave. MFD vulnerabilities are regularly discovered, and it is often basic stuff such as hardcoded $SECRET_INFORMATION (don’t get me wrong here, I fully appreciate the quality of the published research, but it is just surprising — let’s go with this attribute 😉 — that those types of vulnerabilities still occur that often). Yet many environments &lt;em&gt;do not&lt;/em&gt; patch their MFDs or implement other controls. As it is not an option to not use MFDs (they are already present in pretty much every environment, and the vast majority of vendors periodically suffer from vulnerabilities), let’s recall some of our recommendations as those would have mitigated the risk resulting from the published vulnerability:&lt;/p&gt;</description>
    </item>
    <item>
      <title>Basic OS X Hardening &amp; DMA</title>
      <link>https://insinuator.net/2013/07/basic-os-x-hardening-dma/</link>
      <pubDate>Wed, 31 Jul 2013 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2013/07/basic-os-x-hardening-dma/</guid>
      <description>&lt;p&gt;In the course of a recent endpoint assessment, we also had a OS X 10.8 client system as a target. While we still rely on the Firewire “capability” of unlocking systems on a regular base (using &lt;a href=&#34;http://www.breaknenter.org/projects/inception/&#34;&gt;this great tool&lt;/a&gt;), we noticed that Apple released a &lt;a href=&#34;http://support.apple.com/kb/HT5002&#34;&gt;patch&lt;/a&gt; to disable Firewire DMA access whenever the system is in a &lt;em&gt;locked&lt;/em&gt; state (e.g. with an active screensaver or no user logged in). As we test the Firewire DMA access vulnerability quite often (at least we thought so 😉 ) to prepare for demonstrations in the board room or client assessments, we were quite surprised that we must have actually missed that nice update. In order to verify the effectiveness of the patch, we ran our typical test bed and can quite happily confirm that the update successfully mitigates Firewire DMA access in locked system states.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Analysis of Hypervisor Breakouts</title>
      <link>https://insinuator.net/2013/05/analysis-of-hypervisor-breakouts/</link>
      <pubDate>Mon, 20 May 2013 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2013/05/analysis-of-hypervisor-breakouts/</guid>
      <description>&lt;p&gt;In the course of a current virtualization research project, I was reviewing a lot of documentation on hypervisor security. While “hypervisor security” is a very wide field, hypervisor breakouts are usually one of the most (intensely) discussed topics. I don’t want to go down the road of rating the risk of hypervisor breakouts and giving appropriate recommendations (even though we do this on a regular base which, surprisingly often, leads to almost religious debates. I know I say this way too often:I’ll cover this topic in a future post ;)), but share a few observations of analyzing well-known examples of vulnerabilities that led to guest-to-host-escape scenarios. The following table provides an overview of the vulnerabilities in question:&lt;/p&gt;</description>
    </item>
    <item>
      <title>Thoughts on Cloud Governance, Part 1</title>
      <link>https://insinuator.net/2013/04/thoughts-on-cloud-governance-part-1/</link>
      <pubDate>Fri, 05 Apr 2013 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2013/04/thoughts-on-cloud-governance-part-1/</guid>
      <description>&lt;p&gt;Last week Rapid7 &lt;a href=&#34;https://community.rapid7.com/community/infosec/blog/2013/03/27/1951-open-s3-buckets&#34;&gt;posted&lt;/a&gt; an interesting analysis of the Amazon S3 storage system: Apparently roughly one out of six S3 buckets (a bucket is, simply said, a kind of folder) is accessible without any authentication mechanism. Accessing those files, the &lt;a href=&#34;http://www.rapid7.com/&#34;&gt;Rapid7&lt;/a&gt; guys were able to download a &lt;a href=&#34;http://www.google.com/search?q=site%3As3.amazonaws.com+filetype%3Axls+password&amp;amp;btnG=Search&amp;amp;client=opera&amp;amp;oe=utf-8&amp;amp;channel=suggest&amp;amp;gbv=1&#34;&gt;wide range of data&lt;/a&gt;, also comprising confidential information such as source code or employee information, comparable to past research for &lt;a href=&#34;http://blog.rootshell.be/2012/05/19/what-are-you-sharing-with-dropbox/&#34;&gt;other platforms&lt;/a&gt; (see also this presentation I gave on some of the &lt;a href=&#34;https://www.ernw.de/download/ERNW_BastaSpring13_CloudFails.pdf&#34;&gt;biggest Cloud #Fails&lt;/a&gt;)&lt;/p&gt;</description>
    </item>
    <item>
      <title>BPDU Guard: Bringing Down Infrastructures</title>
      <link>https://insinuator.net/2013/04/bpdu-guard-bringing-down-infrastructures/</link>
      <pubDate>Thu, 04 Apr 2013 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2013/04/bpdu-guard-bringing-down-infrastructures/</guid>
      <description>&lt;p&gt;As you may already be familiar with some of our &lt;a href=&#34;http://www.insinuator.net/2012/05/vmdk-has-left-the-building/&#34;&gt;previous&lt;/a&gt; &lt;a href=&#34;https://www.ernw.de/download/ERNW_Newsletter_41_ExploitingVirtualFileFormats_signed.pdf&#34;&gt;work&lt;/a&gt; which was mainly focused on isolation issues of hypervisors, we also want to present you an issue concerning availability in Cloud environments. This issue was already covered in some of our &lt;a href=&#34;https://www.ernw.de/download/ERNW_DCVI-HypervisorsToClouds.pdf&#34;&gt;presentations&lt;/a&gt;, but will be explained in greater detail in this blog post.&lt;/p&gt;&#xA;&lt;p&gt;In the course of one of our security assessments of a public IaaS Cloud environment, we experienced the following network setting:&lt;/p&gt;</description>
    </item>
    <item>
      <title>BASTA! Spring 2013</title>
      <link>https://insinuator.net/2013/02/basta-spring-2013/</link>
      <pubDate>Thu, 28 Feb 2013 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2013/02/basta-spring-2013/</guid>
      <description>&lt;p&gt;Yesterday I was giving two presentations about Cloud security at the &lt;a href=&#34;http://basta.net/&#34;&gt;BASTA!&lt;/a&gt; Spring 2013 Security Day. While my presentations covered Microsoft Azure security considerations (which also included a part of the Cloud security approach covered in our &lt;a href=&#34;https://www.troopers.de/agenda13/troopers13-1-day-workshop-auditing-the-cloud/index.html&#34;&gt;workshops&lt;/a&gt;; slides available &lt;a href=&#34;https://www.ernw.de/download/ERNW_BastaSpring13_AzureSec.pdf&#34;&gt;here&lt;/a&gt;) and some major Cloud incidents (suitable to transport different messages about Cloud security in general ;); slides available &lt;a href=&#34;https://www.ernw.de/download/ERNW_BastaSpring13_CloudFails.pdf&#34;&gt;here&lt;/a&gt;), I also saw &lt;a href=&#34;http://leastprivilege.com/&#34;&gt;Dominick’s&lt;/a&gt; very interesting &lt;a href=&#34;https://speakerdeck.com/leastprivilege/windows-8-security-for-developers&#34;&gt;presentation&lt;/a&gt; about security aspects and changes in Windows 8. Inspired by that, we hope to be able to publish another blogpost on those aspects with regard to enterprise environments soon — most likely we won’t find any time for it before &lt;a href=&#34;http://www.troopers.de&#34;&gt;TROOPERS&lt;/a&gt; 😉&lt;/p&gt;</description>
    </item>
    <item>
      <title>VMDK Has Left the Building — Newsletter</title>
      <link>https://insinuator.net/2013/02/vmdk-has-left-the-building-newsletter/</link>
      <pubDate>Sat, 23 Feb 2013 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2013/02/vmdk-has-left-the-building-newsletter/</guid>
      <description>&lt;p&gt;We are pleased to announce that we summarized the results from our &lt;a href=&#34;http://www.insinuator.net/2012/05/vmdk-has-left-the-building/&#34;&gt;VMDK research&lt;/a&gt; in our latest newsletter.&lt;/p&gt;&#xA;&lt;p&gt;We hope you enjoy the reading and will get some “food for thought”!&lt;/p&gt;&#xA;&lt;p&gt;The newsletter can be found at:&lt;br&gt;&#xA;&lt;a href=&#34;https://www.ernw.de/download/ERNW_Newsletter_41_ExploitingVirtualFileFormats.pdf&#34;&gt;ERNW_Newsletter_41_ExploitingVirtualFileFormats.pd&lt;/a&gt;&lt;/p&gt;&#xA;&lt;p&gt;A digitally signed version can be found at:&lt;br&gt;&#xA;&lt;a href=&#34;https://www.ernw.de/download/ERNW_Newsletter_41_ExploitingVirtualFileFormats_signed.pdf&#34;&gt;ERNW_Newsletter_41_ExploitingVirtualFileFormats_signed.pdf&lt;/a&gt;&lt;/p&gt;&#xA;&lt;p&gt;Enjoy your weekend,&lt;br&gt;&#xA;Matthias&lt;/p&gt;</description>
    </item>
    <item>
      <title>VMDK Has Left the Building — Denial of Service</title>
      <link>https://insinuator.net/2012/11/vmdk-has-left-the-building-denial-of-service/</link>
      <pubDate>Sat, 03 Nov 2012 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2012/11/vmdk-has-left-the-building-denial-of-service/</guid>
      <description>&lt;p&gt;Almost all of our presentations and write-ups on the VMDK File Inclusion Vulnerability contained a slide stating something like&lt;/p&gt;&#xA;&lt;p&gt;&lt;em&gt;“we’re rather sure that DoS is possible as well ;-)”&lt;/em&gt;&lt;/p&gt;&#xA;&lt;p&gt;including the following screenshot of the ESX purple screen of death:&lt;/p&gt;&#xA;&lt;p&gt;&lt;a href=&#34;http://www.insinuator.net/wp-content/uploads/2012/11/DOS_PoC_CoreDump.jpeg&#34;&gt;&lt;img src=&#34;http://www.insinuator.net/wp-content/uploads/2012/11/DOS_PoC_CoreDump.jpeg&#34; alt=&#34;&#34; title=&#34;DOS_PoC_CoreDump&#34;&gt;&lt;/a&gt;&lt;/p&gt;&#xA;&lt;p&gt;So it seems like we still owe you that one — sorry for the delay! However the actual attack to trigger this purple screen was rather simple: Just include &lt;em&gt;multiple&lt;/em&gt; VMDK raw files that cannot be aligned with 512 Byte blocks — e.g. several files of 512 * X + [0 &amp;lt; Y &amp;lt; 512] Bytes. Writing to a virtual hard drive composed of such single files for a short amount of time (typically one to three minutes, this is what we observed in our lab) triggered the purple screen on both ESXi4 and ESXi5 — at least for a patch level earlier than Releasebuild-515841/March 2012: it seems like this vulnerability was patched in Patch &lt;a href=&#34;http://kb.vmware.com/selfservice/microsites/search.do?language=en_US&amp;amp;cmd=displayKC&amp;amp;externalId=2010814&#34;&gt;ESXi500-201203201-UG&lt;/a&gt;.&lt;/p&gt;</description>
    </item>
    <item>
      <title>DAY-CON VI</title>
      <link>https://insinuator.net/2012/07/day-con-vi/</link>
      <pubDate>Sat, 21 Jul 2012 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2012/07/day-con-vi/</guid>
      <description>&lt;p&gt;As &lt;a href=&#34;http://www.insinuator.net/2011/10/packetwars-sun-skills/&#34;&gt;every year&lt;/a&gt;, we will be attending &lt;a href=&#34;http://day-con.org&#34;&gt;Day-Con&lt;/a&gt;, a one-day security summit in Dayton, OH — this year for its VIth edition. Even though the actual conference comprises “only” one day full with talks and discussions (please find the agenda &lt;a href=&#34;http://day-con.org/SCHEDULE_%26_SPEAKERS.html&#34;&gt;here&lt;/a&gt;), the overall event consists of &lt;a href=&#34;http://day-con.org/pooh2012.pdf&#34;&gt;trainings&lt;/a&gt; before the conference and &lt;a href=&#34;http://packetwars.com/&#34;&gt;PacketWars&lt;/a&gt; battles (including an infamous party) afterwards. Since we will be leading and attending some of the training sessions, those might be of particular interest for people who missed our &lt;a href=&#34;http://www.troopers.de/archives/troopers12/agenda/&#34;&gt;Troopers workshops&lt;/a&gt; — so you don’t have to wait a whole year but get another chance in October 😉&lt;/p&gt;</description>
    </item>
    <item>
      <title>VMDK Has Left the Building — FAQ</title>
      <link>https://insinuator.net/2012/06/vmdk-has-left-the-building-faq/</link>
      <pubDate>Sun, 17 Jun 2012 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2012/06/vmdk-has-left-the-building-faq/</guid>
      <description>&lt;p&gt;As we are receiving a lot of questions about our &lt;a href=&#34;http://www.insinuator.net/2012/05/vmdk-has-left-the-building/&#34;&gt;VMDK has left the building post&lt;/a&gt;, we’re compiling this FAQ post — which will be updated as our research goes on.&lt;/p&gt;&#xA;&lt;p&gt;** **&lt;/p&gt;&#xA;&lt;p&gt;&lt;strong&gt;How does the attack essentially work?&lt;/strong&gt;&lt;/p&gt;&#xA;&lt;p&gt;&lt;em&gt;By bringing a specially crafted VMDK file into a VMware ESXi based virtualization environment. The specific attack path is described &lt;a href=&#34;http://www.insinuator.net/2012/05/vmdk-has-left-the-building-follow-up/&#34;&gt;here&lt;/a&gt;.&lt;/em&gt;&lt;/p&gt;&#xA;&lt;p&gt;* *&lt;/p&gt;&#xA;&lt;p&gt;&lt;strong&gt;What is a VMDK file?&lt;/strong&gt;&lt;/p&gt;&#xA;&lt;p&gt;&lt;em&gt;A combination of two different types of VMDK files, the plain-text descriptor file containing meta data and the actual binary disk file, describes a VMware virtual hard disk. A detailed description can be found &lt;a href=&#34;http://www.insinuator.net/2012/05/vmdk-has-left-the-building/&#34;&gt;here&lt;/a&gt;.&lt;/em&gt;&lt;/p&gt;</description>
    </item>
    <item>
      <title>VMDK Has Left the Building — Some Nasty Attacks Against VMware vSphere 5 Based Cloud Infrastructures</title>
      <link>https://insinuator.net/2012/05/vmdk-has-left-the-building-some-nasty-attacks-against-vmware-vsphere-5-based-cloud-infrastructures/</link>
      <pubDate>Thu, 24 May 2012 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2012/05/vmdk-has-left-the-building-some-nasty-attacks-against-vmware-vsphere-5-based-cloud-infrastructures/</guid>
      <description>&lt;p&gt;&lt;strong&gt;Update #1:&lt;/strong&gt; Slides are available for download &lt;a href=&#34;http://www.insinuator.net/2012/05/vmdk-has-left-the-building-slides-available/&#34;&gt;here&lt;/a&gt;.&lt;/p&gt;&#xA;&lt;p&gt;In the course of our ongoing &lt;a href=&#34;http://www.troopers.de/archives/troopers12/agenda/auditing-the-cloud-workshop/&#34;&gt;cloud security research&lt;/a&gt;, we’re continuously thinking about potential attack vectors against public cloud infrastructures. Approaching this enumeration from an external customer’s (speak: attacker’s 😉 ) perspective, there are the following possibilities to communicate with and thus send malicious input to typical cloud infrastructures:&lt;/p&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;Management interfaces&lt;/li&gt;&#xA;&lt;li&gt;Guest/hypervisor interaction&lt;/li&gt;&#xA;&lt;li&gt;Network communication&lt;/li&gt;&#xA;&lt;li&gt;File uploads&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;p&gt;As there are already several successful exploits against management interfaces (e.g. &lt;a href=&#34;http://www.nds.rub.de/media/nds/veroeffentlichungen/2011/10/22/AmazonSignatureWrapping.pdf&#34;&gt;here&lt;/a&gt; and &lt;a href=&#34;http://www.insinuator.net/2011/07/the-key-to-your-datacenter/&#34;&gt;here&lt;/a&gt;) and guest/hypervisor interaction (see for example &lt;a href=&#34;http://www.vmware.com/security/advisories/VMSA-2012-0009.html&#34;&gt;this one&lt;/a&gt;; yes, this is the funny one with that ridiculous recommendation “Do not allow untrusted users access to your virtual machines.” ;-)), we’re focusing on the upload of files to cloud infrastructures in this post. According to our experience with major &lt;em&gt;Infrastructure-as-a-Service&lt;/em&gt; (IaaS) cloud providers, the most relevant file upload possibility is the deployment of already existing virtual machines to the provided cloud infrastructure. However, since a quick additional research shows that most of those allow the upload of VMware-based virtual machines and, to the best of our knowledge, the VMware virtualization file format was not analyzed as for potential vulnerabilities yet, we want to provide an analysis of the relevant file types and present resulting attack vectors.&lt;/p&gt;</description>
    </item>
    <item>
      <title>No Connectivity — No Malware Protection</title>
      <link>https://insinuator.net/2012/01/no-connectivity-no-malware-protection/</link>
      <pubDate>Fri, 06 Jan 2012 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2012/01/no-connectivity-no-malware-protection/</guid>
      <description>&lt;p&gt;During a recent penetration test, we evaluated the security of a typical corporate employee notebook. It was to be assessed whether employees with a default corporate user account would be able to gain administrative access and subsequently abuse the system for attacks against a certain high value database system. When evaluating this problem set, the first step is to find ways to bring tools and exploit code on the system. Usually this task requires the bypassing of the malware protection agent of the system. At some point, we thought we figured a way to &lt;a href=&#34;http://carnal0wnage.attackresearch.com/2010/03/msfencode-msfpayload-into-existing.html&#34;&gt;encode&lt;/a&gt; exploits and payloads in a way that would not be detected by the malware protection solution.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Short iCloud Follow-Up</title>
      <link>https://insinuator.net/2011/10/short-icloud-follow-up/</link>
      <pubDate>Mon, 31 Oct 2011 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2011/10/short-icloud-follow-up/</guid>
      <description>&lt;p&gt;After the basic iCloud discussion in &lt;a href=&#34;http://www.insinuator.net/2011/10/itrust-or-not/&#34;&gt;this&lt;/a&gt; post, I would like to add some more technical information. The following items are just a loose compilation of facts about the mentioned controls which allow the restriction of iCloud usage. The basic iCloud usage, consisting of backup, document sync, and photo stream, can be deactivated using the most recent version of the &lt;a href=&#34;http://support.apple.com/kb/dl851&#34;&gt;iPhone Configuration Utility&lt;/a&gt;:&lt;/p&gt;&#xA;&lt;p&gt;&lt;a href=&#34;http://www.insinuator.net/wp-content/uploads/2011/10/icloud_config_icloud.png&#34;&gt;&lt;img src=&#34;http://www.insinuator.net/wp-content/uploads/2011/10/icloud_config_icloud.png&#34; alt=&#34;&#34; title=&#34;icloud_config_icloud&#34;&gt;&lt;/a&gt;&lt;/p&gt;&#xA;&lt;p&gt;Since there are no default settings for these values, it is necessary to include the disabled entries in existing configuration profiles.&lt;/p&gt;</description>
    </item>
    <item>
      <title>iTrust. Or not?</title>
      <link>https://insinuator.net/2011/10/itrust.-or-not/</link>
      <pubDate>Sun, 23 Oct 2011 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2011/10/itrust.-or-not/</guid>
      <description>&lt;p&gt;A few days ago (on 10/12/2011) Apple launched its new cloud offering which is called — who would have guessed 😉 — iCloud. Since we’re performing quite some research in the area of cloud security, we had a first look at the basic functionality and concepts of the iCloud. Its main features include the possibility to store full backups of Apple devices (at least, an iPhone, iPad or iPod touch running iOS 5 or a Mac running OS X Lion 10.7.2 is required), photos, music, or documents online. The data to be stored online is initially pushed to the cloud storage and then synchronized to any device which is using the same iCloud account. From this moment on, all changes on the cloudified data is immediately synchronized to the iCloud and then pushed to all participating devices. At this point, most infosec people might start to be worried a little bit: The common cloud concept of centralized data storage on premise of a third party does not cope well with the usual control focused approach of most technical infosec guys. The resulting concerns can be attributed to several main cloud computing related risks (which are proposed by &lt;a href=&#34;http://www.enisa.europa.eu/&#34;&gt;ENISA&lt;/a&gt; and actually very valuable &lt;a href=&#34;http://www.enisa.europa.eu/act/rm/files/deliverables/cloud-computing-risk-assessment/at_download/fullReport&#34;&gt;work&lt;/a&gt;:&lt;/p&gt;</description>
    </item>
    <item>
      <title>Packetwars, Sun &amp; Skills</title>
      <link>https://insinuator.net/2011/10/packetwars-sun-skills/</link>
      <pubDate>Sun, 16 Oct 2011 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2011/10/packetwars-sun-skills/</guid>
      <description>&lt;p&gt;During the last days, some of our guys (including me) had some great days in Dayton. Rene, Christopher, Hendrik, Sergej, and me flew in to give workshops and presentations at &lt;a href=&#34;http://day-con.org/&#34; title=&#34;daycon&#34;&gt;Day-Con&lt;/a&gt; as well as to compete in the infamous &lt;a href=&#34;http://www.packetwars.com&#34;&gt;PacketWars&lt;/a&gt; game. While Day-Con is a one day event, the two days before the conference comprised workshops on &lt;a href=&#34;http://www.hmtrainingsolutions.com/en/home/85-ios-security-sichere-integration-von-iphone-a-ipad.html&#34;&gt;secure iOS integration&lt;/a&gt; (given by Rene) and &lt;a href=&#34;http://www.hmtrainingsolutions.com/en/home/91-ipv6technologie-und-integration.html&#34;&gt;IPv6 security&lt;/a&gt; (given by Christopher). Since the overall topic of the conference was trust, Rene gave a &lt;a href=&#34;http://www.ernw.de/publikationen/DayConV_ERNW_Broken_Trust_v025.pdf%20&#34;&gt;keynote&lt;/a&gt; on broken trust which was based exemplary trust analysis, development of a trust metric, and different trust factors. Those trust factors were also used in my talk about evaluation methodologies for &lt;a href=&#34;http://www.ernw.de/publikationen/do_they_deliver.pdf%20&#34;&gt;cloud service providers&lt;/a&gt; (regular followers will recognize some of the content of both talks from &lt;a href=&#34;http://www.insinuator.net/2011/10/broken-trust-part-2-applying-the-approach-to-dropbox/&#34;&gt;different&lt;/a&gt; &lt;a href=&#34;http://www.insinuator.net/2011/07/the-key-to-your-datacenter/&#34;&gt;posts&lt;/a&gt; 😉 ). There were also talks from Sergey Bratus, Graeme Neilson and Angus Blitter. While Sergey proposed a sound (not to say academic 😉 ) definition on the classification of vulnerabilities and their connection to &lt;a href=&#34;http://www.wolframalpha.com/input/?i=turing+completeness&#34;&gt;turing complete input languages&lt;/a&gt;, Angus gave an introduction to &lt;a href=&#34;http://grouper.ieee.org/groups/1901/&#34;&gt;PowerLine technologies&lt;/a&gt; and laid out, that these technologies still suffer from naive assumptions about trusted networks (he also refered to &lt;a href=&#34;http://www.blackhat.com/presentations/bh-europe-09/Rey_Mende/BlackHat-Europe-2009-Mende-Rey-All-Your-Packets-slides.pdf&#34;&gt;this&lt;/a&gt;). The day after the conference, the ERNW Allstars had to defend their championship title in PacketWars. Since the first battle was scheduled for 10AM, we had quite some time to tan in the sunny 30°C weather, recover from the conference and prepare the expected victory celebration (some of you might remember some “Champagne tradition” from &lt;a href=&#34;http://www.troopers.de&#34;&gt;Troopers&lt;/a&gt;). In face of this motivation, we rushed through the 3 battles and were able to score first place second year in a row. At this point, kudos to the two other participating teams who gave us a tough battle, especially during the reversing challenges.&lt;/p&gt;</description>
    </item>
    <item>
      <title>The Key to your Datacenter</title>
      <link>https://insinuator.net/2011/07/the-key-to-your-datacenter/</link>
      <pubDate>Tue, 19 Jul 2011 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2011/07/the-key-to-your-datacenter/</guid>
      <description>&lt;p&gt; &lt;/p&gt;&#xA;&lt;p&gt;During our ongoing research on the security of cloud service providers and cloud based applications, we performed a regular audit of our &lt;a href=&#34;http://aws.amazon.com&#34; title=&#34;AWS&#34;&gt;AWS&lt;/a&gt; account password. Thinking of &lt;a href=&#34;http://www.wired.com/threatlevel/2009/07/kaminsky-hacked/&#34;&gt;popular incidents&lt;/a&gt; and evergreens in &lt;a href=&#34;%20http://88.84.128.30/~isnochys/wordpress/wp-content/bruteforce.jpg&#34;&gt;attack vectors&lt;/a&gt;, we were wondering which consequences an online bruteforce attack on our AWS password would have. So we decided to perform a bruteforce attack against our own account. Analyzing the login process of AWS, the following requirements for the bruteforce tool to be used could be derived:&lt;/p&gt;</description>
    </item>
    <item>
      <title>Sisters’ Act of MFD Security</title>
      <link>https://insinuator.net/2011/04/sisters-act-of-mfd-security/</link>
      <pubDate>Thu, 07 Apr 2011 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2011/04/sisters-act-of-mfd-security/</guid>
      <description>&lt;p&gt;Recently Micele and I were researching for our talk about the current state of security of Multifunction Devices (MFDs). Since we’re both seasoned pentesters who are quite familar with MFDs, we were really surprised that very little new research is going on on the topic of MFD security. While diving deeper into the topic, we found a very simple explanation for this: As in 2002, it is still possible to download print or scan jobs using &lt;a href=&#34;http://h20000.www2.hp.com/bc/docs/support/SupportManual/bpl13208/bpl13208.pdf&#34;&gt;PJL&lt;/a&gt;, many devices still offer default FTP or Telnet access, and, of course, stored files can be recovered from MFD hard drives — on an enterprise wide scale. To even strengthen our impression of the current state of MFD security, most devices crashed or did go wild while performing some scans — and we do not talk about fuzzing here.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Intel’s &lt;i&gt;Known Good&lt;/i&gt; Approach — Chances for a Paradigm Shift?</title>
      <link>https://insinuator.net/2010/09/intels-iknown-good/i-approach-chances-for-a-paradigm-shift/</link>
      <pubDate>Sat, 18 Sep 2010 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2010/09/intels-iknown-good/i-approach-chances-for-a-paradigm-shift/</guid>
      <description>&lt;p&gt;During the keynote of the &lt;a href=&#34;http://download.intel.com/newsroom/kits/idf/2010_fall/pdfs/Day1_IDF_Keynote_Transcript_Otellini.pdf&#34;&gt;Intel Developer Forum&lt;/a&gt;, Intel’s CEO Paul Otellini explained their motivation for the acquisition of McAfee. Basically, Intel wants to provide a possibility to shift computer security from &lt;em&gt;a known bad model to something that is a known good model&lt;/em&gt;.&lt;/p&gt;&#xA;&lt;p&gt;Coming back to some of our &lt;a href=&#34;http://www.insinuator.net/2010/08/just-a-quick-note-on-the-library-loading-binary-planting-stuff/&#34;&gt;recent&lt;/a&gt; &lt;a href=&#34;http://www.insinuator.net/2010/09/that-new-worm/&#34;&gt;blog posts&lt;/a&gt;, we think that a reliable and working approach to implement application whitelisting would increase security in corporate environments — especially when thinking of the latest vulnerabilities with exploit code in the wild that could not be catched up by any AV solution. As covered by &lt;a href=&#34;http://feeds.arstechnica.com/~r/arstechnica/everything/~3/ZyQ42S4_7PU/intels-walled-garden-plan-to-put-av-vendors-out-of-business.ars&#34;&gt;this article&lt;/a&gt;, the possibility that such an approach succeeds depends heavily on the critical mass that would use it. The widespread &lt;a href=&#34;http://www.intel.com/Assets/PDF/manual/253666.pdf&#34;&gt;x86 architecture&lt;/a&gt; therefore is the perfect plattform for accomplishing a widely used known good model. Presuming the possibility for flexibel and secure operation, Intel’s efforts could be the chance to shift the paradigm of corporate security from a reactive to a preventive model.&lt;/p&gt;</description>
    </item>
  </channel>
</rss>
