<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Swengel on Insinuator.net - Bold Statements</title>
    <link>https://insinuator.net/authors/swengel/</link>
    <description>Recent content in Swengel on Insinuator.net - Bold Statements</description>
    <generator>Hugo</generator>
    <language>en-us</language>
    <lastBuildDate>Wed, 27 Feb 2013 00:00:00 +0000</lastBuildDate>
    <atom:link href="https://insinuator.net/authors/swengel/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>Latest SAP threats, SAP Forensics &amp;amp; BIZEC @Troopers!</title>
      <link>https://insinuator.net/2013/02/latest-sap-threats-sap-forensics-amp-bizec-@troopers/</link>
      <pubDate>Wed, 27 Feb 2013 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2013/02/latest-sap-threats-sap-forensics-amp-bizec-@troopers/</guid>
      <description>&lt;h3 id=&#34;this-is-a-guest-post-from-mariano-nunez-and-juan-perez-etchegoyen&#34;&gt;This is a guest post from &lt;a href=&#34;https://www.troopers.de/agenda13/troopers13-1-day-workshop-sap-security-protecting-your-sap-systems-against-hackers-and-industrial-espionage/index.html&#34;&gt;Mariano Nunez and Juan Perez-Etchegoyen&lt;/a&gt;&lt;/h3&gt;&#xA;&lt;p&gt;Juan Perez-Etchegoyen (&lt;a href=&#34;https://twitter.com/intent/user?screen_name=jp_pereze&#34;&gt;@jp_pereze&lt;/a&gt;) and Mariano Nunez (&lt;a href=&#34;https://twitter.com/intent/user?screen_name=marianonunezdc&#34;&gt;@marianonunezdc&lt;/a&gt;) from &lt;a href=&#34;http://www.onapsis.com/&#34;&gt;Onapsis&lt;/a&gt; here, thrilled to be &lt;a href=&#34;https://www.troopers.de&#34;&gt;troopers&lt;/a&gt; for the third time! In this post we want to share with you a glimpse of what you will see regarding SAP security at this amazing conference.&lt;/p&gt;&#xA;&lt;p&gt;Last week we released advisories regarding several vulnerabilities affecting SAP platforms. Some of these vulnerabilities are in fact very critical, and their exploitation could lead to a &lt;strong&gt;full-compromise&lt;/strong&gt; of the entire SAP implementation – even &lt;strong&gt;by completely anonymous attackers&lt;/strong&gt;. Following our responsible disclosure policy, SAP released the relevant SAP Security Notes (patches) for all these vulnerabilities a long time ago, so if you are an SAP customer make sure you have properly implemented them!&lt;/p&gt;</description>
    </item>
    <item>
      <title>Bluevoxing</title>
      <link>https://insinuator.net/2013/02/bluevoxing/</link>
      <pubDate>Thu, 21 Feb 2013 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2013/02/bluevoxing/</guid>
      <description>&lt;h3 id=&#34;this-is-a-guest-post-from-graeme-neilson&#34;&gt;This is a guest post from &lt;a href=&#34;https://www.troopers.de/agenda13/troopers13-2-day-workshop-reverse-engineering/index.html&#34;&gt;Graeme Neilson&lt;/a&gt;&lt;/h3&gt;&#xA;&lt;p&gt;Reverse engineering is generally thought of as using debuggers, disassemblers and hex editors. Much as I love hex editors, IDA and staring at opcodes for the last few years I have been focused on applying my reverse engineering methodology to larger, composed systems. At &lt;a href=&#34;https://www.troopers.de/agenda13/troopers13-telcosec-day-2013/index.html&#34;&gt;Troopers TelcoSec day&lt;/a&gt; this year I will be presenting &lt;a href=&#34;https://www.troopers.de/agenda13/troopers13-telcosec-day-2013/index.html#BlueVoxing&#34;&gt;Bluevoxing&lt;/a&gt; which demonstrates how this approach works. &lt;a href=&#34;https://www.troopers.de/agenda13/troopers13-telcosec-day-2013/index.html#BlueVoxing&#34;&gt;Bluevoxing&lt;/a&gt; is about reverse engineering how web based “audio one time password” systems work. Simply put audio one time password systems use a short audio file as an authentication token. When I discovered these systems I was intrigued as reversing them would involve a range of techniques and tools from web testing, audio tools, signal analysis, phreaking and cryptanalysis. The disassembler would be of no use instead I would have to employ audio tools such as audacity and ruby-processing.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Corporate Espionage via Mobile Compromise: A technical deep dive</title>
      <link>https://insinuator.net/2013/02/corporate-espionage-via-mobile-compromise-a-technical-deep-dive/</link>
      <pubDate>Tue, 19 Feb 2013 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2013/02/corporate-espionage-via-mobile-compromise-a-technical-deep-dive/</guid>
      <description>&lt;h3 id=&#34;this-is-a-guest-post-from-david-weinstein&#34;&gt;This is a guest post from &lt;a href=&#34;https://www.troopers.de/agenda13/troopers13-presentations/index.html#corporate_espionage_via_mobile_compromise&#34;&gt;David Weinstein&lt;/a&gt;&lt;/h3&gt;&#xA;&lt;p&gt;Mobile devices play an important role in the business world. Yet with increased emphasis on the Bring Your Own Device (BYOD) model, defenses are not where they need to be to slow the loss of valuable intellectual property.&lt;/p&gt;&#xA;&lt;p&gt;Corporate defenses have traditionally focused on the network, the endpoints, and not necessarily on the ecosystem of how these devices interact outside of network sockets. Smartphones bring unique network connectivity, an array of sensors, and can be overlooked by resources invested on IDS/IPS not being effectively leveraged.&lt;/p&gt;</description>
    </item>
    <item>
      <title>IPv6 Extension Headers: New Features, and New Attack Vectors</title>
      <link>https://insinuator.net/2013/02/ipv6-extension-headers-new-features-and-new-attack-vectors/</link>
      <pubDate>Sun, 17 Feb 2013 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2013/02/ipv6-extension-headers-new-features-and-new-attack-vectors/</guid>
      <description>&lt;h3 id=&#34;this-is-a-guest-post-from-antonios-atlasis&#34;&gt;This is a guest post from &lt;a href=&#34;https://www.troopers.de/agenda13/troopers13-ipv6-security-summit-2013/troopers13-ipv6-security-summit-2013-presentations/index.html#extension_headers&#34;&gt;Antonios Atlasis&lt;/a&gt;&lt;/h3&gt;&#xA;&lt;p&gt;IPv6 introduces a lot of new features and consequently, a lot of new capabilities. Obviously, the most significant of them is the huge address space that it offers. However, this is not the only one. IPv6 also introduces the use of the IPv6 Extension Headers. The IPv6 header has been considerably simplified in comparison with IPv4 one. On the other hand, the IPv6 Extension Headers, not only do the “job” of most of the fields which were removed from the main header, but, additionally, they add many more. However, any new “technology” creates new attack opportunities and a “new” protocol, such as IPv6 could not be an exception, especially since its design and implementation is more complicated than it’s predecessor.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Fragmentation (overlapping) attacks in IPv6. Have we learned our lesson, yet?</title>
      <link>https://insinuator.net/2013/01/fragmentation-overlapping-attacks-in-ipv6.-have-we-learned-our-lesson-yet/</link>
      <pubDate>Tue, 29 Jan 2013 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2013/01/fragmentation-overlapping-attacks-in-ipv6.-have-we-learned-our-lesson-yet/</guid>
      <description>&lt;h3 id=&#34;this-is-a-guest-post-from-antonios-atlasis&#34;&gt;This is a guest post from &lt;a href=&#34;https://www.troopers.de/agenda13/troopers13-ipv6-security-summit-2013/troopers13-ipv6-security-summit-2013-presentations/index.html#extension_headers&#34;&gt;Antonios Atlasis&lt;/a&gt;&lt;/h3&gt;&#xA;&lt;p&gt;It has been a year since fragmentation attacks in IPv6 were last examined publicly (in &lt;a href=&#34;https://media.blackhat.com/bh-eu-12/Atlasis/bh-eu-12-Atlasis-Attacking_IPv6-Slides.pdf&#34;&gt;Black Hat Europe 2012&lt;/a&gt;). Issues well known from the IPv4 era appeared again in IPv6. Surprisingly enough, some of the most popular Operating Systems (OS), included ones considered “secure”, were proven to be vulnerable to such attacks, although fragmentation overlapping is strictly forbidden in IPv6 since 2009 (RFC5722). Some other OS, although in a better shape, still appeared to have some issues in specific cases.&lt;/p&gt;</description>
    </item>
  </channel>
</rss>
