Events

31c0n 2017 in Auckland, New Zealand

Last week we gave a talk at the very first 31c0n in Auckland, New Zealand. The talk focused mainly on the methodology that we use to assess security products.

More specifically, this methodology consists of 7 steps

  • Literature Research
  • Jailbreak the Target
  • Identify Components
  • Understand the Architecture
  • Map the Attack Surface
  • Prioritize
  • Analyze.

Details on these steps as well as general suggestions to viable alternatives for security products can be found here in the slides.

Continue reading
Breaking

Setting up a Research Environment for IP Cameras

Embedded devices often serve as an entry point for an attack on a private or corporate network. The infamous attack on HackingTeam, for example, followed exactly this path as was revealed here. Although the attack may have been for the greater good (refer also to this great keynote), such incidents demonstrate that it is important to properly secure your embedded devices. In a recent blog post, Niklaus presented how he analyzed the security posture of a MAX! Cube LAN Gateway. Moreover, Brian reported a few weeks ago on the security posture of IoT devices (and in particular on one of his cameras). With this post I would like to share my experiences with analyzing another embedded device: the IC-3116W IP camera by Edimax. 

Continue reading
Events

25th USENIX Security Symposium & WOOT Workshop

Last month the annual USENIX Security Symposium with its co-located workshops (WOOT, CSET, FOCI, ASE, and HotSec) was held in Austin, Texas. The program of the conference together with the published papers can be found here and information on the workshops can be found here.

The research topics were quite diverse and included subjects such as low-level attacks, cryptographic attacks, and vehicle attacks. To give you an impression on the research that has been presented at the conference, let us discuss some of the talks in the following:

Continue reading
Events

SnoopCon Guest Day

This year I had the pleasure to join the guest day of BT’s SnoopCon. There were quite a number of interesting talks throughout the day such as

  • Saumil Shah‘s presentation on Stegosploit (as well as his rant about the state of information security)
  • Dr. Grigorios Fragkos‘ talk on airplane security (where he presented some maybe not-so-pleasant but also some good-to-hear facts on the security posture of airplanes)
  • Dominic Spill‘s demonstration of tools and methods used to reverse engineer RF protocols
  • Hacker Fantastic‘s talk on how to use the AX.25 protocol to bounce radio signals off the ISS to communicate with systems around the world
  • Kostas Litovois’ and Vincent Yiu’s presentation on #WePWNise, a tool that can be used to efficiently create malicious VBA macros (by taking EMET configuration details into account)
  • Bryan Fite‘s talk on how we have to think about Safety, Security, and Privacy in the IoT age.

I really enjoyed the talks and had a great time! Thanks to all the organizers and speakers!

Continue reading
Events

24th USENIX Security Symposium & WOOT Workshop

Recently I had the pleasure to attend the 24th USENIX Security Symposium and its co-located Workshop on Offensive Technologies (WOOT) in Washington, D.C. The workshop has received quite some attention this year, 57 submissions of which 19 have been accepted, so that the organizers decided to double its length from one to two days.

The first day of the workshop began with an excellent keynote by Adam Langley, in which he reflected on the current state of SSL/TLS and its vulnerabilities. As a side remark he mentioned that to tackle the everlasting problem of such vulnerabilities to occur, research should be performed with a much higher level of abstraction rather than focusing on the exact details of a “certain hash function of some specific CBC cipher”.

Continue reading