35C3 is over, and the recordings are available so in case you did not have the
chance or the time to watch the live streams during the holidays or overwhelmed
with the number of talks, see in the following a list of recommended talks to
fill your evenings or weekends. Apart from the broad coverage of topics in
different areas (Ethics, Society & Politics, Hardware & Making, Resilience, Art
and Culture, Security, Science, Resilience), foundation talks were aiming for
the very basics following this year’s motto “Refreshing Memories.”
Tavis did it again[1]. As stated in the title it is possible to remotely
execute commands via the Chrome extension for the popular meeting software Cisco
WebEx. This post summarizes the most relevant information for you.
A test page with working
demo code
is available to check for the issue on Windows systems [2]. From our point of
view the Chrome extension is affected by this issue as well as the Firefox
extension as both extension APIs are quite similar. However, Mozilla blocked the
FireFox plugin to protect users from the risk of being exploited through the
plugin[3][4]. IE seems to be fine thanks to Cisco’s decision to invoke the
WebEx Meeting Center via e.g. ActiveX.
On the 8th of March SAP released the security note for a vulnerability we
reported during an assessment of a SAP landscape. The issue affects the SAP
NetWeaver Web Administration Interface. By knowing a special URL a malicious
user can acquire version information about the services enabled in the SAP
system as well as the operating system used. We wanted to share some details on
the issue.
The vulnerability is a bypass of the HTTP Basic Authorization for the
SAP Web Administration Interface.
It discloses version information about the system respectively operating system,
a brief SAP patch level overview and running services including their
corresponding ports.
When it comes to SAP, Troopers has two events that are about Security in SAP
Systems in particular. On the first day of the Troopers16 Trainings the BIZEC
workshop takes place. The second event is a dedicated SAP track during the
conference. Apart from these events there were of course a lot of nice folks to
talk to (about SAP) 🙂 This post is a short overview about SAP security
@ TROOPERS16.
Last week we enjoyed quite a wonderful HAXPO exhibition and HITB conference in
Amsterdam. A number of great talks could be heard at the main HITB conference
such as “Bootkit via SMS: 4G Access Level Security Assessment” or
“Stegosploit: Hacking with Pictures“. And not only that: there were also
several engaging hands-on workshops.
Apart from the main conference, there was the HAXPO – a hacker exhibition. At
this exhibition you could connect with people from different companies, get a
lot of merchandise, and also listen to several briefings on security and its
philosophy. Fortunately, we had the pleasure to present two of these briefings
and maybe you tested your web application skills at the ERNW booth.
once again, we welcomed Michael Ossmann at the ERNW headquarters for fun with
SDR. This time with Mike´s advanced SDR workshop. And to be up front about it…it
was plain awesome. For everybody who is not familiar with Software Defined Radio
(SDR): Let’s regard it as the ultimate tool when working with radio signals.
Take a look a
this to learn
more.
Mike showed us the new revision of his HackRF One and explained us some more
advanced techniques when it comes to Radio Frequnecies hacking. Compared to last
time, the workshop focused on reversing signals and how to synthesize them. So
this time we were crafting RF packets ourselves instead of just replaying a
capture. This introduces different attack types which can be carried out over
the air for example bruteforcing or fuzzing of radio devices.