Hey there!
The God of frequencies Michael Ossmann visited us again this year at the
TROOPERS16 and showed us how to break
another device using a specific setup.
Last time he introduced the HackRF One to us (Read
here:https://www.insinuator.net/2014/08/hackrf-one-the-story-continues/), but
this post is a short summary of his talk about “Rapid Radio Reversing”, he is a
wireless security researcher, who makes hardware for hackers. Best known for the
HackRF, Ubertooth, and Daisho projects, he founded Great Scott Gadgets in an
effort to put exciting, new tools into the hands of innovative people.
He is a security researcher in Google’s Project Zero. He has been involved with
computer hardware and software security for over 10 years looking at a range of
different platforms and applications. With a great interest in logical
vulnerabilities he has numerous disclosures in a wide range of products from web
browsers to virtual machine breakouts as well as being a Pwn2Own and Microsoft
Mitigation Bypass bounty winner. He has spoken at a number of security
conferences including Black Hat USA, CanSecWest, Bluehat, HITB, and Infiltrate.
White-box cryptography is a relatively new field that aims at enabling safely
cryptographic operations in hostile situations.
A typical example is its use in digital-right management (DRM) schemes, but
nowadays you also find white-box implementations in mobile applications such as
Host Card Emulation (HCE) and the protection of credentials to the cloud.
In all these use-cases the software implementation uses the secret key of a
third-party which should remain secret from the owner of the device which is
running this executable.
In this year’s MSF training we will guide you through the typical steps of the
pentest cycle: information gathering, attacking and looting your targets. For
each step, demos and exercises will help you deepen and test your newly acquired
knowledge. In addition to the typical penetration-test scenarios you will also
learn several advanced aspects of the framework such as: how writing your own
metasploit modules works, how to export payloads and make them undetected. With
a final exercise each day you can finally challenge yourself and apply what you
have learned!
In the last few years, attack techniques which fall in the categories of
“Credential Theft” or “Credential Reuse” have grown into one of the biggest
threats to Microsoft Windows environments. Microsoft has stated more than one
time, that nearly almost all of their customers that run Active Directory have
experienced “Pass-the-Hash” (PtH) attacks recently.[1] Once an
attacker gains an initial foothold on a single system in the environment it
takes often less than 48 hours until the entire Active Directory infrastructure
is compromised. To defend against this kind of attacks, a well-planned approach
is required as part of a comprehensive security architecture and operations
program. As breach has to be assumed[2], this includes a
preventative mitigating control strategy, where technical and organizational
controls are implemented, as well as preparations against insider attacks. This
is mainly achieved by partitioning the credential flow in order to firstly limit
their exposure and secondly limit their usefulness if an attacker was able to
get them. Although we spoke last year at Troopers 15 about “How to Efficiently
Protect Active Directory from Credential Theft & Large Scale
Compromise”[3], we would like to summarize exemplary later in this
post Active Directory pentest findings that we classified in four categories in
order to better understand what goes typically wrong and thus has to be
addressed. For a better understanding of the overall security goals, we
classified the findings as to belonging as a security best practice violation of
the following categories:
Happy 2016 everyone! We are exactly 2 months away from the start of
TROOPERS16!! Speakers and Trainers across the globe are polishing (or in some
cases creating) their PowerPoints to use while delivering their highly technical
and entertaining talks. While we here at TR HQ are busy tweaking orders,
creating challenges to boggle the mind and test your skills, and of course
working on some top secret fun. 😉
In this post I want to add (yet) another perspective, motivated by a disclosure
procedure which just happened recently.
todb’s article,
R7-2015-23: Comcast XFINITY Home Security System Insecure Fail Open
is a well planned public forum vulnerability disclosure. The article itself is
very well done: It gives credit to the researcher who discovered the
vulnerability and it shows a vulnerability disclosure timeline where Rapid7
reached out to Comcast (the vendor). They even go a step further and publish the
link showing the process for discovered vulnerabilities in a Rapid7 product as
well as how Rapid7 handles disclosing those vulnerabilities they find in
external products. For their internal disclosure process, they make sure to
release a patch before “publicly announcing the vulnerability in the release
notes of the update”(rapid7 disclosure).
As we come to the end of the year we can’t help but take a moment to thank all
of your who made TROOPERS15 special! It just makes us all the more pumped to
kick it up a notch for TROOPERS16!! #BestWeekEver
Happy Holiday and much Joy to you in the New Year!
The BetterCrypto Project started out in the fall of 2013 as a collaborative
community effort by systems engineers, security engineers, developers and
cryptographers to build up a sound set of recommendations for strong
cryptography and privacy enhancing technologies catered towards the operations
community in the face of overarching wiretapping and data-mining by nation-state
actors. The project has since evolved with a lot of positive feedback from the
open source and operations community in general with input from various browser
vendors, linux distribution security teams and researchers.
Here at TROOPERS HQ we are well into the Holiday (read TROOPERS) Spirit so we
thought we would publish another round of talks! The current agenda can be
found here.
Happy Holidays!
Your TROOPERS Team
===
2nd Day Keynote FIRST TIME TROOPERS SPEAKER
Bio: Ben Zevenbergen joined the Oxford Internet Institute to pursue a DPhil
on the intersection of privacy law, technology, social science, and the
Internet. He runs a side project that aims to establish ethics guidelines for
Internet research, as well as working in multidisciplinary teams such as the EU
funded Network of Excellence in Internet Science. He has worked on legal,
political and policy aspects of the information society for several years. Most
recently he was a policy advisor to an MEP in the European Parliament, working
on Europe’s Digital Agenda. Previously Ben worked as an ICT/IP lawyer and policy
consultant in the Netherlands. Bendert holds a degree in law, specialising in
Information Law.
Here’s the second round of TROOPERS16 talks. For more information check out our
website: TROOPERS
Happy Holidays and all the best for 2016 to everybody!
Your TROOPERS Team
===
Ivan Pepelnjak: Real-life Software-Defined Security
Vendors, pundits, and industry media love to talk about Software-Defined
Everything, but nothing ever changes in the enterprise world, right? Wrong. Some
engineers are already solving security problems with a software-defined approach
to networking and security, be it microsegmentation in NSX or OpenStack
environment, building scale-out IDS clusters, or respond to DoS or intrusion
events in real-time… and we’ll cover all these ideas in this fast-paced
presentation