Last week we gave a talk at the very first 31c0n in
Auckland, New Zealand. The talk focused mainly on the methodology that we use to
assess security products.
More specifically, this methodology consists of 7 steps
Literature Research
Jailbreak the Target
Identify Components
Understand the Architecture
Map the Attack Surface
Prioritize
Analyze.
Details on these steps as well as general suggestions to viable alternatives for
security products can be found
here in the
slides.
Embedded devices often serve as an entry point for an attack on a private or
corporate network. The infamous attack on HackingTeam, for example, followed
exactly this path as was revealed here.
Although the attack may have been for the greater good (refer also to this great
keynote), such
incidents demonstrate that it is important to properly secure your embedded
devices. In a recent
blog post,
Niklaus presented how he analyzed the security posture of a MAX! Cube LAN
Gateway. Moreover, Brian reported a few weeks ago on the
security posture of IoT devices
(and in particular on one of his cameras). With this post I would like to share
my experiences with analyzing another embedded device: the
IC-3116W
IP camera by Edimax.
Last month the annual USENIX Security Symposium with its co-located workshops
(WOOT, CSET, FOCI, ASE, and HotSec) was held in Austin, Texas. The program of
the conference together with the published papers can be found
here
and information on the workshops can be found
here.
The research topics were quite diverse and included subjects such as low-level
attacks, cryptographic attacks, and vehicle attacks. To give you an impression
on the research that has been presented at the conference, let us discuss some
of the talks in the following:
This year I had the pleasure to join the guest day of BT’s SnoopCon. There were
quite a number of interesting talks throughout the day such as
Saumil Shah‘s presentation on Stegosploit
(as well as his rant about the state of information security)
Dr. Grigorios Fragkos‘ talk on airplane
security (where he presented some maybe not-so-pleasant but also some
good-to-hear facts on the security posture of airplanes)
Dominic Spill‘s demonstration of tools and
methods used to reverse engineer RF protocols
Hacker Fantastic‘s talk on how to use
the AX.25 protocol to bounce radio signals off the ISS to communicate with
systems around the world
Kostas Litovois’ and Vincent Yiu’s presentation on #WePWNise, a tool that can
be used to efficiently create malicious VBA macros (by taking EMET
configuration details into account)
Bryan Fite‘s talk on how we have to think
about Safety, Security, and Privacy in the IoT age.
I really enjoyed the talks and had a great time! Thanks to all the organizers
and speakers!
Recently I had the pleasure to attend the 24th USENIX Security Symposium and its
co-located Workshop on Offensive Technologies (WOOT) in Washington, D.C. The
workshop has received quite some attention this year, 57 submissions of which 19
have been accepted, so that the organizers decided to double its length from one
to two days.
The first day of the workshop began with an excellent keynote by Adam Langley,
in which he reflected on the current state of SSL/TLS and its vulnerabilities.
As a side remark he mentioned that to tackle the everlasting problem of such
vulnerabilities to occur, research should be performed with a much higher level
of abstraction rather than focusing on the exact details of a “certain hash
function of some specific CBC cipher”.