<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Michael Thumann on Insinuator.net - Bold Statements</title>
    <link>https://insinuator.net/authors/michael-thumann/</link>
    <description>Recent content in Michael Thumann on Insinuator.net - Bold Statements</description>
    <generator>Hugo</generator>
    <language>en-us</language>
    <lastBuildDate>Mon, 09 Dec 2019 00:00:00 +0000</lastBuildDate>
    <atom:link href="https://insinuator.net/authors/michael-thumann/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>TROOPERS20 Training Teaser: TLS in the Enterprise – Post Quantum Security</title>
      <link>https://insinuator.net/2019/12/troopers20-training-teaser-tls-in-the-enterprise-post-quantum-security/</link>
      <pubDate>Mon, 09 Dec 2019 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2019/12/troopers20-training-teaser-tls-in-the-enterprise-post-quantum-security/</guid>
      <description>&lt;p&gt;Our workshop “TLS in the enterprise” was held for the first time at Troopers 2018 and was our special contribution to the IT Security world to increase the usage of TLS and point out the pitfalls, when switching to TLS.&lt;/p&gt;&#xA;&lt;p&gt;But time is changing and TLS is a kind of standard nowadays, at least when looking at HTTPS, but there are still a lot of things to do regarding other protocols like&lt;/p&gt;</description>
    </item>
    <item>
      <title>DirectoryRanger 1.5.0 Is Available</title>
      <link>https://insinuator.net/2019/06/directoryranger-1.5.0-is-available/</link>
      <pubDate>Thu, 13 Jun 2019 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2019/06/directoryranger-1.5.0-is-available/</guid>
      <description>&lt;p&gt;The next major release of DirectoryRanger is now available for customers, and for everyone who would like to try it ;-). Current attacks show that quite often the topic of Active Directory Security is not on the security agenda, but it should be, and this was the reason for us to build the tool and, of course, to maintain and improve it. So what are the major new features released with DirectoryRanger 1.5.0? Here we go:&lt;/p&gt;</description>
    </item>
    <item>
      <title>DirectoryRanger 1.1.0 Introduces Informational Audit Checks</title>
      <link>https://insinuator.net/2018/12/directoryranger-1.1.0-introduces-informational-audit-checks/</link>
      <pubDate>Mon, 03 Dec 2018 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2018/12/directoryranger-1.1.0-introduces-informational-audit-checks/</guid>
      <description>&lt;p&gt;With version 1.1.0 our tool DirectoryRanger introduces a new feature: informational audit checks. These checks do not have a severity rating because they are just “for your information” and the included information might or might not contain security issues, depending on other facts. But these checks can help to reduce your Active Directory attack surface by pointing you to some aspects which need your attention and at least require to be discussed and documented (and they might also imply governance measures like a risk acceptance).&lt;/p&gt;</description>
    </item>
    <item>
      <title>printf(“Hello World!”) Part 2</title>
      <link>https://insinuator.net/2018/04/printfhello-world-part-2/</link>
      <pubDate>Mon, 30 Apr 2018 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2018/04/printfhello-world-part-2/</guid>
      <description>&lt;p&gt;As our journey to the new product continues we are facing the typical challenges of phase 2 in the software development life cycle, the design phase (see &lt;a href=&#34;https://insinuator.net/2018/02/printfhello-world/&#34;&gt;part 1&lt;/a&gt; for the overview of the phases):&lt;/p&gt;&#xA;&lt;p&gt;&lt;img src=&#34;2.png&#34; alt=&#34;&#34;&gt;&lt;/p&gt;&#xA;&lt;p&gt; &lt;/p&gt;&#xA;&lt;h3 id=&#34;design-and-components&#34;&gt;Design and Components&lt;/h3&gt;&#xA;&lt;p&gt;The new tool will deal with Active Directory security so it has to integrate into large scale Windows based customer environments, which in turn makes the decision about the components quite easy ;-). We have chosen .NET as our primary development platform including key components from Microsoft to run our application, these components include the IIS and Microsoft SQL Express/Server and of course one Windows Server.&lt;/p&gt;</description>
    </item>
    <item>
      <title>printf(“Hello World!”)</title>
      <link>https://insinuator.net/2018/02/printfhello-world/</link>
      <pubDate>Fri, 23 Feb 2018 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2018/02/printfhello-world/</guid>
      <description>&lt;p&gt;ERNW has a new baby, so please say “hello” to the new ERNW SecTools GmbH ;-).&lt;br&gt;&#xA;But why another ERNW company? Short answer: Because we want to contribute to changing the way how software is built today: insecure, focused on profit and sometimes made by people who ignore lessons from history. So how can we contribute in this space? Start changing it ;-).&lt;/p&gt;&#xA;&lt;p&gt;Confucius said: “The man who moves a mountain begins by carrying away small stones” and that’s our way to go. It is not about building error free or unbreakable software, it is about changing the way how software is built today, about improving security and about raising the bar.&lt;/p&gt;</description>
    </item>
    <item>
      <title>TLS in the Enterprise: Is Heartbleed still a Problem?</title>
      <link>https://insinuator.net/2018/02/tls-in-the-enterprise-is-heartbleed-still-a-problem/</link>
      <pubDate>Fri, 16 Feb 2018 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2018/02/tls-in-the-enterprise-is-heartbleed-still-a-problem/</guid>
      <description>&lt;p&gt;Our new workshop about &lt;a href=&#34;https://troopers.de/troopers18/trainings/9afapk/&#34;&gt;TLS/SSL in the enterprise&lt;/a&gt; will be held for the 1st time at Troopers 2018. So I would like to take the opportunity and post a short teaser about stuff we will cover in this workshop.&lt;/p&gt;&#xA;&lt;p&gt;TLS/SSL is a complicated topic especially in enterprise environments due to the fact, that&lt;/p&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;encrypted traffic should be inspected e.g. for malware&lt;/li&gt;&#xA;&lt;li&gt;customers/users must be able to use important applications&lt;/li&gt;&#xA;&lt;li&gt;crypto attacks are complex and sometimes considered to be only a problem in theory&lt;/li&gt;&#xA;&lt;li&gt;the internal CERT wants to have every issue fixed, if feasible or not 😉&lt;/li&gt;&#xA;&lt;li&gt;impact of configuration changes can not be foreseen&lt;/li&gt;&#xA;&lt;li&gt;Software inventory is incomplete (do you want to make a bet that Heartbleed is fixed completely in your environment ;-)? )&lt;/li&gt;&#xA;&lt;li&gt;… and so forth&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;p&gt;In the workshop we will cover all these points, discuss them and share our experience regarding feasibility and useful mitigating controls. We will explain the most common SSL vulnerabilities/attacks, demonstrate tools to test (and sometimes to exploit) them, point out pitfalls and recommend what to do. Let us have a look at one example, Heartbleed:&lt;/p&gt;</description>
    </item>
    <item>
      <title>Mobile Application Testing</title>
      <link>https://insinuator.net/2013/02/mobile-application-testing/</link>
      <pubDate>Thu, 14 Feb 2013 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2013/02/mobile-application-testing/</guid>
      <description>&lt;p&gt;Our new &lt;a href=&#34;https://www.troopers.de/agenda13/troopers13-2-day-workshop-mobile-application-testing/index.html&#34;&gt;workshop about mobile application testing&lt;/a&gt;, held for the 1st time at the Troopers conference 2013, is coming closer. So I would like to take the opportunity and post an appetizer for those who are still undetermined if they should attend the workshop ;-).&lt;/p&gt;&#xA;&lt;p&gt;While the topic of mobile application testing is a wide field that may contain reverse engineering, secure storage analysis, vulnerability research, network traffic analysis and so forth, in the end of the day you have to answer one question: Can I trust this application and run it on my enterprise devices? So first you have to define some criteria, which kind of behavior and characteristics of an application you regard as trustworthy (or not). Let us peek at malware … besides harming your devices and data, malware is typically:&lt;/p&gt;</description>
    </item>
    <item>
      <title>Update: Microsoft Advisory 2757760 Windows Internet Explorer Vulnerability</title>
      <link>https://insinuator.net/2012/09/update-microsoft-advisory-2757760-windows-internet-explorer-vulnerability/</link>
      <pubDate>Thu, 20 Sep 2012 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2012/09/update-microsoft-advisory-2757760-windows-internet-explorer-vulnerability/</guid>
      <description>&lt;p&gt;Microsoft takes this vulnerability quite serious and was acting fast. The Microsoft Security Response Center announced the availability of a fix last night in the &lt;a href=&#34;http://blogs.technet.com/b/msrc/archive/2012/09/19/internet-explorer-fix-it-available-now-security-update-scheduled-for-friday.aspx&#34;&gt;MSRC Blog&lt;/a&gt;.&lt;/p&gt;&#xA;&lt;p&gt;The fix will be available via Windows Update on friday, the 21st of september. So it’s time to get ready for this update ;-).&lt;/p&gt;&#xA;&lt;p&gt;Have a nice day&lt;br&gt;&#xA;Michael&lt;/p&gt;</description>
    </item>
    <item>
      <title>Microsoft Advisory 2757760: Windows Internet Explorer Zero-Day Vulnerability</title>
      <link>https://insinuator.net/2012/09/microsoft-advisory-2757760-windows-internet-explorer-zero-day-vulnerability/</link>
      <pubDate>Wed, 19 Sep 2012 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2012/09/microsoft-advisory-2757760-windows-internet-explorer-zero-day-vulnerability/</guid>
      <description>&lt;p&gt;Actually a Windows Vulnerability (&lt;a href=&#34;http://technet.microsoft.com/en-us/security/advisory/2757760&#34;&gt;Microsoft Advisory 2757760&lt;/a&gt;) related to the Internet Explorer Version 7, 8 and 9 is in the news. Microsoft is aware of the problem, but there’s no patch available yet. We call this a 0-Day :-). Making the problem even worse, on monday reliable &lt;a href=&#34;https://community.rapid7.com/community/metasploit/blog/2012/09/17/lets-start-the-week-with-a-new-internet-explorer-0-day-in-metasploit&#34;&gt;exploit code&lt;/a&gt; was released within the Metasploit project, so exploit code is already in the wild.&lt;/p&gt;&#xA;&lt;p&gt;Basically Microsoft suggests two workarounds:&lt;/p&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;Usage of EMET &lt;a href=&#34;http://support.microsoft.com/kb/2458544&#34;&gt;(Enhanced Mitigation Experience Toolkit&lt;/a&gt;)&lt;/li&gt;&#xA;&lt;li&gt;Disabling Active X and Active Scripting in the Internet Settings&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;p&gt;But both of them have some impact: EMET must be deployed before any usage (btw. EMET can be configured via Group Policies) and disabling Active X and Active Scripting might break some business relevant web sites (that can be added to the “Trusted Sites” Zone, but might produce major operational effort).&lt;/p&gt;</description>
    </item>
    <item>
      <title>The Web Application Firewall Story continues</title>
      <link>https://insinuator.net/2012/06/the-web-application-firewall-story-continues/</link>
      <pubDate>Fri, 22 Jun 2012 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2012/06/the-web-application-firewall-story-continues/</guid>
      <description>&lt;p&gt;Some days ago another &lt;a href=&#34;https://www.sec-consult.com/files/20120618-1_Airlock_WAF_overlong_UTF8_bypass.txt&#34;&gt;advisory&lt;/a&gt; related to a web application firewall (WAF) product was published. This time the product Airlock by &lt;a href=&#34;http://www.ergon.ch/&#34;&gt;Ergon&lt;/a&gt; was affected by a vulnerability that combines Encoding and NULL Byte attacks to circumvent the pattern based detection engine. We have described these attacks in detail in our newsletter “&lt;a href=&#34;http://www.ernw.de/content/e15/e28/e1659/download1661/ERNW_Newsletter_35_WAF_en_ger.pdf&#34;&gt;Web Application Firewall Security and The Swiss Army Knife for Web Application Firewalls&lt;/a&gt;” because they belong to a well known category of attacks against WAFs.&lt;/p&gt;</description>
    </item>
    <item>
      <title>SQL Injection Testing for Business Purposes Part 3</title>
      <link>https://insinuator.net/2012/06/sql-injection-testing-for-business-purposes-part-3/</link>
      <pubDate>Wed, 13 Jun 2012 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2012/06/sql-injection-testing-for-business-purposes-part-3/</guid>
      <description>&lt;h2 id=&#34;extract-the-data&#34;&gt;Extract the data&lt;/h2&gt;&#xA;&lt;p&gt;If you want to extract some data from a database you first need to gather knowledge about the internal structure of the database.&lt;/p&gt;&#xA;&lt;p&gt;One of the first steps (after determining the database type) is enumerating the available tables and the corresponding columns. Most database systems have a meta database called information_schema. By querying this database it is possible to get information about the internal structure of the installed databases. For example you could get the tables and their corresponding columns in MS SQL and MySQL by injecting “&lt;code&gt;SELECT table_name, column_name FROM information_schema.columns&lt;/code&gt;“. Oracle databases have their own meta tables, so you have to handle them differently. For getting the same output in Oracle, you have to query the all_tab_columns table (or user_tab_columns if you only want to search in the currently selected database). If the found vulnerability only allows to receive a single column (or if it is too complicated to identify two columns in the server response) you could concatenate the columns to one single string, e.g. in Oracle: “&lt;code&gt;SELECT table_name||&#39;:&#39;||column_name FROM all_tab_columns&lt;/code&gt;“.&lt;/p&gt;</description>
    </item>
    <item>
      <title>SQL Injection Testing for Business Purposes Part 2</title>
      <link>https://insinuator.net/2012/05/sql-injection-testing-for-business-purposes-part-2/</link>
      <pubDate>Mon, 28 May 2012 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2012/05/sql-injection-testing-for-business-purposes-part-2/</guid>
      <description>&lt;h2 id=&#34;take-care-of-the-database&#34;&gt;Take Care of the Database&lt;/h2&gt;&#xA;&lt;p&gt;There are some database specifics, every pentester should be aware of, when testing for and exploiting SQLi vulnerabilities. Besides the different string concatenation variants already covered above, there are some other specifics that have to be considered and might turn out useful in some circumstances. For example with Oracle Databases, every SELECT statement needs a following FROM statement even if the desired data is not stored within a database. So when trying to extract e.g. the DB username using a UNION SELECT statement, the DUAL table may be utilized, which should always be available. Another point, if dealing with MySQL, is the possibility to simplify the classic payload&lt;/p&gt;</description>
    </item>
    <item>
      <title>SQL Injection Testing for Business Purposes Part 1</title>
      <link>https://insinuator.net/2012/05/sql-injection-testing-for-business-purposes-part-1/</link>
      <pubDate>Mon, 14 May 2012 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2012/05/sql-injection-testing-for-business-purposes-part-1/</guid>
      <description>&lt;h2 id=&#34;introduction&#34;&gt;Introduction&lt;/h2&gt;&#xA;&lt;p&gt;SQL injection attacks have been well known for a long time and many people think that developers should have fixed these issues years ago, but doing web application pentests almost all the time, we have a slightly different view. Many SQL injection problems  potentially remain undetecteddue to a lack of proper test methodology, so we would like to share our approach and experience and help others in identifying these issues.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Untrusted code or why exploit code should only be executed by professionals</title>
      <link>https://insinuator.net/2012/04/untrusted-code-or-why-exploit-code-should-only-be-executed-by-professionals/</link>
      <pubDate>Sun, 22 Apr 2012 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2012/04/untrusted-code-or-why-exploit-code-should-only-be-executed-by-professionals/</guid>
      <description>&lt;p&gt;In march 2012 Microsoft announced a critical vulnerability (&lt;a href=&#34;http://technet.microsoft.com/en-us/security/bulletin/ms12-020&#34;&gt;Microsoft Security Bulletin MS12-020&lt;/a&gt;) related to RDP that affects all windows operating systems and allows remote code execution. A lot of security professionals are expecting almost the same impact as with MS08-067 (the conficker vulnerability) and that it will be only a matter of time, until we will spot reliable exploits in the wild. Only a few days later an exploit, working for all unpatched windows versions was released, so it seems that they were right ;-), but of course no one will run an exploit without investigating the code. So lets have a look into the exploit Code.&lt;/p&gt;</description>
    </item>
    <item>
      <title>The 5 Myths of Web Application Firewalls</title>
      <link>https://insinuator.net/2012/04/the-5-myths-of-web-application-firewalls/</link>
      <pubDate>Mon, 16 Apr 2012 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2012/04/the-5-myths-of-web-application-firewalls/</guid>
      <description>&lt;p&gt;Some days ago a security advisory related to web application firewalls (WAFs) was published on Full Disclosure. Wendel Guglielmetti Henrique found another bug in the IBM Web Application Firewall which can be used to circumvent the WAF and execute typical web application attacks like SQL injection (click &lt;a href=&#34;http://lists.grok.org.uk/pipermail/full-disclosure/2011-June/081605.html&#34;&gt;here&lt;/a&gt; for details). Wendel talked already (look &lt;a href=&#34;http://troopers09.org/content/e644/e649/TROOPERS09_gauci_henrique_web_application_firewalls.pdf%20&#34;&gt;here&lt;/a&gt;) at the &lt;a href=&#34;http://www.troopers.de&#34;&gt;Troopers&lt;/a&gt; Conference in 2009 about the different techniques to identify and bypass WAFs, so this kind of bypass methods are not quite new.&lt;/p&gt;</description>
    </item>
    <item>
      <title>The 5 Myths of Web Application Firewalls</title>
      <link>https://insinuator.net/2011/06/the-5-myths-of-web-application-firewalls/</link>
      <pubDate>Mon, 27 Jun 2011 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2011/06/the-5-myths-of-web-application-firewalls/</guid>
      <description>&lt;p&gt;Some days ago a security advisory related to web application firewalls (WAFs) was published on Full Disclosure. Wendel Guglielmetti Henrique found another bug in the IBM Web Application Firewall which can be used to circumvent the WAF and execute typical web application attacks like SQL injection (click here for details). Wendel talked already (look &lt;a href=&#34;http://troopers09.org/content/e644/e649/TROOPERS09_gauci_henrique_web_application_firewalls.pdf%20&#34;&gt;here&lt;/a&gt;) at the &lt;a href=&#34;http://www.troopers.de&#34;&gt;Troopers&lt;/a&gt; Conference in 2009 about the different techniques to identify and bypass WAFs, so this kind of bypass methods are not quite new.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Some More Security Research on The nPA AusweisApp</title>
      <link>https://insinuator.net/2010/11/some-more-security-research-on-the-npa-ausweisapp/</link>
      <pubDate>Mon, 22 Nov 2010 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2010/11/some-more-security-research-on-the-npa-ausweisapp/</guid>
      <description>&lt;p&gt;After the initial quick shot (see this &lt;a href=&#34;http://www.insinuator.net/2010/11/our-contribution-to-the-public-discussion-about-the-german-new-id-card-npa/&#34;&gt;post&lt;/a&gt;) we decided to have a closer look. And some more stuff turned up.&lt;/p&gt;&#xA;&lt;p&gt;After decompiling the integrated java stuff we stumbled about hard coded server credentials:&lt;/p&gt;&#xA;&lt;p&gt;&lt;code&gt;package Idonttell;&lt;/code&gt;&lt;/p&gt;&#xA;&lt;p&gt;&lt;code&gt; &lt;/code&gt;&lt;/p&gt;&#xA;&lt;p&gt;&lt;code&gt; public abstract interface Idonttell&lt;/code&gt;&lt;br&gt;&#xA;&lt;code&gt;{&lt;/code&gt;&lt;br&gt;&#xA;&lt;code&gt;public static final boolean debug = false;&lt;/code&gt;&lt;br&gt;&#xA;&lt;code&gt;public static final boolean auth = true;&lt;/code&gt;&lt;br&gt;&#xA;&lt;code&gt;public static final String SMTP_SERVER = &amp;quot;Idonttell.openlimit.com&amp;quot;;&lt;/code&gt;&lt;br&gt;&#xA;&lt;code&gt;public static final String SMTP_USER = &amp;quot;Idonttell@Idonttell.openlimit.com&amp;quot;;&lt;/code&gt;&lt;br&gt;&#xA;&lt;code&gt;public static final String SMTP_PASSWORD = &amp;quot;Idonttell&amp;quot;;&lt;/code&gt;&lt;br&gt;&#xA;&lt;code&gt;public static final String SEND_FROM = &amp;quot;Idonttell@Idonttell.openlimit.com&amp;quot;;&lt;/code&gt;&lt;br&gt;&#xA;&lt;code&gt;public static final String[] SEND_TO = { &amp;quot;buergerclient.it-solutions@Idonttell.com&amp;quot; };&lt;/code&gt;&lt;br&gt;&#xA;&lt;code&gt;public static final String MAIL_HEADER_FIELD = &amp;quot;OpenLimitErrorMessage&amp;quot;;&lt;/code&gt;&lt;br&gt;&#xA;&lt;code&gt;public static final String MAIL_HEADER_FIELD_PROP = &amp;quot;yes&amp;quot;;&lt;/code&gt;&lt;br&gt;&#xA;&lt;code&gt;}&lt;/code&gt;&lt;/p&gt;</description>
    </item>
    <item>
      <title>Our contribution to the public discussion about the German new ID card (nPA)</title>
      <link>https://insinuator.net/2010/11/our-contribution-to-the-public-discussion-about-the-german-new-id-card-npa/</link>
      <pubDate>Thu, 11 Nov 2010 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2010/11/our-contribution-to-the-public-discussion-about-the-german-new-id-card-npa/</guid>
      <description>&lt;p&gt;Currently there’s quite some discussion about the security properties and posture of the German new ID card (“Neuer Personalausweis”, “nPA”, some technically reasonable security discussion can here be found e.g. &lt;a href=&#34;http://blog.cj2s.de/categories/5-German-ID-Cad-nPA&#34;&gt;here&lt;/a&gt;.&lt;/p&gt;&#xA;&lt;p&gt;While – as of our current knowledge – we do not expect major security flaws on the architecture level, the problems discussed so far (like &lt;a href=&#34;http://www.troopers08.org/content/e6/e461/AMATOFrancisco-evilgrade-ENG-Troopers-fk.pdf&#34;&gt;Evilgrade&lt;/a&gt; style attacks against one of the main applications or keylogging the PIN in scenarios with &lt;a href=&#34;http://www.ccc.de/de/updates/2010/sicherheitsprobleme-bei-suisseid-und-epa&#34;&gt;pinpad-less readers&lt;/a&gt; ) certainly show that security best practices must be followed by all parties involved in the development, deployment and use of the nPA and it’s associated applications. From our perspective this may be expected from the applications’ developers as well.&lt;br&gt;&#xA;Looking at this:&lt;/p&gt;</description>
    </item>
    <item>
      <title>Back to the roots</title>
      <link>https://insinuator.net/2010/09/back-to-the-roots/</link>
      <pubDate>Fri, 24 Sep 2010 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2010/09/back-to-the-roots/</guid>
      <description>&lt;p&gt;Finding exploitable vulnerabilities is getting harder. This statement of Dennis Fisher published on &lt;a href=&#34;http://threatpost.com/en_us/blogs/easily-exploitable-bugs-becoming-precious-commodity-090110&#34;&gt;Kaspersky’s Threatpost blog&lt;/a&gt; summarizes a trend in the development lifecycle of software . The last published vulnerabilities that were gaining some attention in the public had all one thing in common, they were quite hard to exploit. The so called jailbreakme vulnerability was based on several different vulnerabilities that had to be chained together to break out of the iPhone sandbox, escalate its privileges and run arbitrary code. Modern software and especially modern operating systems are more secure, they contain less software flaws and more protection features that make reliable exploitation a big problem that can only be solved by very skilled hackers. Decades ago it was just like this, but intelligent tools and sharing of the needed knowledge enabled even low skilled people to develop working exploits and attack vulnerable systems. Nowadays we are going back to the roots where only a few very knowledgeable people are able to circumvent modern security controls, but that doesn’t mean that all problems are gone. Attackers are moving to design flaws like the DLL highjacking problem, so only the class of attacks is changing from the old school memory corruption vulnerabilities to logical flaws that still can be exploited easily. But the number of exploitable vulnerabilities is decreasing, so this might be a sign that we are on the right way to develop reliable and secure systems and that developing companies are adopting Microsofts Secure Development Lifecycle (SDL) to produce more secure software. As stated in my previous &lt;a href=&#34;http://www.insinuator.net/2010/07/software-developers-dont-use-available-security-features/&#34;&gt;blogpost&lt;/a&gt; the protection features are available, but not used very often. But if they are used and if the developers are strictly following the recommendations of the SDL, this trend of “harder to exploit vulnerabilities” proves that it can be a success story to do so.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Software Developers Don’t Use Available Security Features</title>
      <link>https://insinuator.net/2010/07/software-developers-dont-use-available-security-features/</link>
      <pubDate>Wed, 21 Jul 2010 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2010/07/software-developers-dont-use-available-security-features/</guid>
      <description>&lt;p&gt;According to &lt;a href=&#34;http://www.sans.org/newsletters/newsbites/newsbites.php&#34;&gt;SANS NewsBites Vol. XII, Issue 53&lt;/a&gt; recently published there’s a lack of 3rd party developer support for some security features Microsoft introduced already years ago. We at ERNW have made similar observations when performing security assessments of COTS [commercial off-the-shelf] software. We therefore created a methodology, a &lt;a href=&#34;http://www.ernw.de/content/e7/e181/e1501/download1541/TTICheck_ger.zip&#34;&gt;proof of concept tool&lt;/a&gt; and a metric to test and to rate closed source software, where (amongst other approaches) these security features are checked and their (non-) presence contributes to an overall evaluation as for the trustworthiness of the applications in question. The concept “How to rate the security in closed source software” was presented to the public at &lt;a href=&#34;http://www.troopers.de&#34;&gt;Troopers10&lt;/a&gt; and at &lt;a href=&#34;https://conference.hackinthebox.org&#34;&gt;Hack in the Box 2010&lt;/a&gt; in Amsterdam. The slides can be found &lt;a href=&#34;http://www.ernw.de/content/e7/e181/e1501/download1542/ERNW_HITB2010_How_to_rate_the_security_of_closed_source_software_Michael_Thumann_ger.pdf&#34;&gt;here&lt;/a&gt;.&lt;/p&gt;</description>
    </item>
  </channel>
</rss>
