<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Stefan Kiese on Insinuator.net - Bold Statements</title>
    <link>https://insinuator.net/authors/stefan-kiese/</link>
    <description>Recent content in Stefan Kiese on Insinuator.net - Bold Statements</description>
    <generator>Hugo</generator>
    <language>en-us</language>
    <lastBuildDate>Mon, 20 Mar 2017 00:00:00 +0000</lastBuildDate>
    <atom:link href="https://insinuator.net/authors/stefan-kiese/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>This is Why Your Wireless Mouse Should Have a Tail and Your Presenter is a Fail</title>
      <link>https://insinuator.net/2017/03/this-is-why-your-wireless-mouse-should-have-a-tail-and-your-presenter-is-a-fail/</link>
      <pubDate>Mon, 20 Mar 2017 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2017/03/this-is-why-your-wireless-mouse-should-have-a-tail-and-your-presenter-is-a-fail/</guid>
      <description>&lt;p&gt;Puh…it’s been a long time since my &lt;a href=&#34;https://insinuator.net/2016/11/itsecx-2016-pulling-an-all-nighter-in-austria/&#34;&gt;last post&lt;/a&gt;, huh?&lt;br&gt;&#xA;However, let’s get straight back to topic. Today, I want to issue a warning, especially in face of upcoming &lt;a href=&#34;https://www.troopers.de/troopers17/&#34;&gt;Troopers 2017&lt;/a&gt; (less than two days to go, wooo! 10th anniversary!): be careful when using wireless equipment (presenters, mouses, keyboards,…), especially during Troopers, but also in daily use.&lt;/p&gt;&#xA;&lt;p&gt;TL;DR Please take into account that you put your laptop at risk of being hacked by using wireless equipment during &lt;a href=&#34;https://www.troopers.de/&#34;&gt;Troopers&lt;/a&gt;. This could lead to a full system compromise. Wirelessly. Attacks like keystroke injection or sniffing of latter and mouse movements are possible. This, e.g. applies to speakers, using wireless presenters (like Logitech R400/R800, old and new models), as also to any attendee or crew member who might use wireless mouses or keyboards. Be aware of this!&lt;/p&gt;</description>
    </item>
    <item>
      <title>ITSeCX 2016: Pulling an all-nighter in Austria</title>
      <link>https://insinuator.net/2016/11/itsecx-2016-pulling-an-all-nighter-in-austria/</link>
      <pubDate>Tue, 08 Nov 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/11/itsecx-2016-pulling-an-all-nighter-in-austria/</guid>
      <description>&lt;p&gt;Last Friday I gave a talk at the &lt;a href=&#34;https://itsecx.fhstp.ac.at/&#34;&gt;ITSeCX&lt;/a&gt; in St. Pölten, Austria. The conference, hosted by the local University of Applied Sciences, has already taken place ten times. I don’t know how many people attended this time, 2014 there were about 600; &lt;a href=&#34;http://www.computerwelt.at/news/technologie-strategie/security/detail/artikel/113099-it-secx-2015-eine-nacht-im-zeichen-der-it-security/&#34;&gt;I read somewhere on the net&lt;/a&gt;. There were four tracks and some workshops from 4pm to the conference’s end at midnight. I enjoyed the community-feeling there very much, even though I arrived late. The only talks I saw, were Adrian Dabrowski speaking about the DARPA Cyber Grand Challenge, the finals took part in Las Vegas this August, and the very entertaining end-of-year review from two UAS guys.&lt;/p&gt;</description>
    </item>
    <item>
      <title>BSides LV 2016: Recap</title>
      <link>https://insinuator.net/2016/09/bsides-lv-2016-recap/</link>
      <pubDate>Mon, 19 Sep 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/09/bsides-lv-2016-recap/</guid>
      <description>&lt;p&gt;Hey everyone,&lt;/p&gt;&#xA;&lt;p&gt;Just a short recap from my side regarding this year’s BSide in Las Vegas, NV. It was my first time there and I pretty much enjoyed it. After entering the venue on the first con day (Tuesday) I was a little bit shocked, as the staff sent me to the “end of the line just around the corner” – the end being many corners and many floors away 😉 Speaking to some guys while standing in line, time quickly passed by and before finally hitting the registration desk, there were already some people from the staff giving away the conference badges to the waiting folks. The waiting time was no comparison to last year’s DEF CON, where I (and obviously all the other “humans”, how attendees at DEF CON are called) had to wait nearly _four_ hours to get a badge to enter the con. DEF CON staff already calls this the annual “Line Con”. Enough bashing, back to topic 😉&lt;/p&gt;</description>
    </item>
    <item>
      <title>Your Mouse Got Sick and You Don’t Know it. aka “Reverse Shell via Mouse”</title>
      <link>https://insinuator.net/2016/07/your-mouse-got-sick-and-you-dont-know-it.-aka-reverse-shell-via-mouse/</link>
      <pubDate>Fri, 29 Jul 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/07/your-mouse-got-sick-and-you-dont-know-it.-aka-reverse-shell-via-mouse/</guid>
      <description>&lt;p&gt;Ever got a backdoor installed on your computer by your beloved mouse? Here’s the story of a poor mouse that got really, really sick.&lt;/p&gt;&#xA;&lt;p&gt;&lt;img src=&#34;https://www.insinuator.net/wp-content/uploads/2016/07/mouse-300x169.jpg&#34; alt=&#34;Agent &amp;ldquo;Danger Mouse&amp;rdquo;&#34;&gt;&lt;/p&gt;&#xA;&lt;p&gt;Agent “Danger Mouse”&lt;/p&gt;&#xA;&lt;p&gt;Do you remember the times where people put Teensy-boards and USB hubs in their mouses? [Chris? ;)] Their aim was to attach an additional &lt;a href=&#34;https://en.wikipedia.org/wiki/Human_interface_device&#34;&gt;Human Interface Device&lt;/a&gt; (HID, like keyboards or mouses) with some payload in kind of e.g. keystrokes or mouse movements. Also, there are devices available like the USB Rubber Ducky in the housing of a USB thumb drive.&lt;br&gt;&#xA;The principle is easy: The tools are using a programmable microcontroller with the capability to emulate USB HID. That’s it. Just program your board of choice with the payload fitting your needs and plug it in at the target computer. The latter will recognize it as a keyboard/mouse and the payload-keystrokes will be entered.&lt;br&gt;&#xA;But why should external hardware be used? Many modern gaming peripherals provide functions to store macros on them, including enough onboard memory for little payloads.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Gotta Catch ‘Em All! – WORLDWIDE! (or how to spoof GPS to cheat at Pokémon GO)</title>
      <link>https://insinuator.net/2016/07/gotta-catch-em-all-worldwide-or-how-to-spoof-gps-to-cheat-at-pok%C3%A9mon-go/</link>
      <pubDate>Fri, 15 Jul 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/07/gotta-catch-em-all-worldwide-or-how-to-spoof-gps-to-cheat-at-pok%C3%A9mon-go/</guid>
      <description>&lt;p&gt;The moment, when your team leader asks you to cheat at Pokémon GO…everyone knows it, right? No? Well, I do 😉&lt;/p&gt;&#xA;&lt;p&gt;&lt;img src=&#34;https://www.insinuator.net/wp-content/uploads/2016/07/setup_edit-300x169.jpg&#34; alt=&#34;GPS Spoofing Setup&#34;&gt;&lt;/p&gt;&#xA;&lt;p&gt;GPS Spoofing Setup&lt;/p&gt;&#xA;&lt;p&gt;As I’m not a gamer, the technical part was of much more interest – that’s the real gaming for me.&lt;br&gt;&#xA;So, challenge accepted!&lt;/p&gt;&#xA;&lt;p&gt;In the past I was often fiddling around with SDR (Software Defined Radio), started with DVB-T sticks some years ago. When I came to ERNW in 2014 I got in touch with &lt;a href=&#34;http://greatscottgadgets.com/hackrf/&#34;&gt;Michael Ossman’s great HackRF One&lt;/a&gt; for the first time, and subsequently my thesis was based on SDR.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Introduction of a new hardware guy</title>
      <link>https://insinuator.net/2016/05/introduction-of-a-new-hardware-guy/</link>
      <pubDate>Wed, 18 May 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/05/introduction-of-a-new-hardware-guy/</guid>
      <description>&lt;p&gt;Hi folks!&lt;/p&gt;&#xA;&lt;p&gt;We couldn’t be more proud to welcome such a predestined #1 hardware hacking victim, than &lt;strong&gt;VICTor&lt;/strong&gt; is!&lt;br&gt;&#xA;Before Brian and I gave a lecture on hardware hacking last week at &lt;a href=&#34;https://www.mosbach.dhbw.de&#34;&gt;DHBW Mosbach&lt;/a&gt;, we felt, that we needed a custom victim which is fully documented and provides a good “hackability” to the students.&lt;br&gt;&#xA;Surely we could also have used some cheap $wifi_ap, but here’s the thing: Would you really want to use a device which you don’t really know? Mostly, there’s a massive lack of documentation regarding the SoCs used…not to mention the unavailability of schematics and layouts.&lt;br&gt;&#xA;As we wanted to teach students the basics of hardware hacking effectively, we decided to create something by ourselves.&lt;/p&gt;</description>
    </item>
    <item>
      <title>13th escar Europe conference | Embedded Security in Cars</title>
      <link>https://insinuator.net/2015/11/13th-escar-europe-conference-embedded-security-in-cars/</link>
      <pubDate>Tue, 17 Nov 2015 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2015/11/13th-escar-europe-conference-embedded-security-in-cars/</guid>
      <description>&lt;p&gt;Last week I had the pleasure to attend the “&lt;strong&gt;escar&lt;/strong&gt;” (&lt;em&gt;Embedded Security in Cars&lt;/em&gt;) &lt;strong&gt;conference&lt;/strong&gt; in &lt;em&gt;Cologne, Germany&lt;/em&gt;.&lt;br&gt;&#xA;Arriving late Tuesday, I had the chance to get a rich breakfast before joining the con in the hotel Dorint at Cologne’s famous place the Heumarkt. Unfortunately I had to deal with two stumbling blocks on my way to the Dobrint: The magnetic sensor of my mobile which went crazy (no compass) and – the date. 11th of November in Cologne means just one thing – &lt;em&gt;&lt;strong&gt;carneval&lt;/strong&gt;&lt;/em&gt;! The whole city was just in a state of exception. Everybody on my way to the venue seemed to be drinking or beeing already drunk – at 9am! 😉&lt;br&gt;&#xA;Being a little late, I went straight to the room after registration. As there was only one track to follow you could not miss any talk – nice thing!&lt;br&gt;&#xA;After we were welcomed by the hosts, and the first talk started.&lt;/p&gt;</description>
    </item>
    <item>
      <title>ERNW speaking @ hardwear.io</title>
      <link>https://insinuator.net/2015/10/ernw-speaking-@-hardwear.io/</link>
      <pubDate>Mon, 05 Oct 2015 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2015/10/ernw-speaking-@-hardwear.io/</guid>
      <description>&lt;p&gt;&lt;img src=&#34;http://www.insinuator.net/wp-content/uploads/2015/10/hardwarebug-266x300.png&#34; alt=&#34;Hardwarebug&#34;&gt;&lt;/p&gt;&#xA;&lt;p&gt;On October 1st and 2nd Flo and I were presenting at&lt;br&gt;&#xA;hardwear.io in The Hague, NL. My topic was “&lt;a href=&#34;https://www.ernw.de/download/ERNW_hardwear.io_2015_living_in_a_fools_wireless-secured_paradise_skiese.pdf&#34;&gt;Living in a fool’s&lt;/a&gt;&lt;br&gt;&#xA;&lt;a href=&#34;https://www.ernw.de/download/ERNW_hardwear.io_2015_living_in_a_fools_wireless-secured_paradise_skiese.pdf&#34;&gt;wireless-secured paradise&lt;/a&gt;” and Flo was presenting his current research&lt;br&gt;&#xA;on medical device security. It was the first talk at an international&lt;br&gt;&#xA;security conference for me and I am still quite excited!&lt;/p&gt;&#xA;&lt;p&gt;I was speaking about the (in)security of wireless consumer alarm&lt;br&gt;&#xA;systems, which you can buy just in every consumer electronics store&lt;br&gt;&#xA;around the corner for about $10 – $250. I analyzed the systems on&lt;br&gt;&#xA;different levels, e.g. looking at UART and JTAG and the wireless domain&lt;br&gt;&#xA;with Software Defined Radio (SDR). I gave an overview of my current&lt;br&gt;&#xA;research and the tools I usually use for hardware hacking, especially my&lt;br&gt;&#xA;favorite thing to play with: SDR.&lt;/p&gt;</description>
    </item>
  </channel>
</rss>
