<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Breaking on Insinuator.net - Bold Statements</title>
    <link>https://insinuator.net/categories/breaking/</link>
    <description>Recent content in Breaking on Insinuator.net - Bold Statements</description>
    <generator>Hugo</generator>
    <language>en-us</language>
    <lastBuildDate>Tue, 16 Jun 2026 00:00:00 +0000</lastBuildDate>
    <atom:link href="https://insinuator.net/categories/breaking/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>Vulnerability Disclosure: Stealing Emails via Firefox’s AI Features</title>
      <link>https://insinuator.net/2026/06/vulnerability-disclosure-stealing-emails-via-firefoxs-ai-features/</link>
      <pubDate>Tue, 16 Jun 2026 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2026/06/vulnerability-disclosure-stealing-emails-via-firefoxs-ai-features/</guid>
      <description>&lt;p&gt;Imagine the following: You visit a webpage with a lot of text you don’t want to read and ask your AI assistant for a summary. A few moments later, the AI assistant has extracted one of your emails and sent it to an attacker without you ever knowing.&lt;/p&gt;&#xA;&lt;p&gt;In October 2025, we found exactly this vulnerability in Firefox’s AI chatbot integration&lt;sup id=&#34;fnref:1&#34;&gt;&lt;a href=&#34;#fn:1&#34; class=&#34;footnote-ref&#34; role=&#34;doc-noteref&#34;&gt;1&lt;/a&gt;&lt;/sup&gt;.&lt;/p&gt;&#xA;&lt;p&gt;Firefox offers a summarization, explaination and proofread AI feature. When a user makes use of one of these features, Firefox pastes a prompt into the sidebar AI chat including the page title, the selected text (or, if the whole page is summarized, a selection is being made by Firefox) and an instruction on how to process the provided text. The sidebar AI chat is essentially an IFrame of a third-party chatbot (Claude, Copilot, …).&lt;/p&gt;</description>
    </item>
    <item>
      <title>CVE-2026-47237 – Overly Permissive Istio Permissions Allow Kubeflow Authorization Token Stealing</title>
      <link>https://insinuator.net/2026/05/cve-2026-47237-overly-permissive-istio-permissions-allow-kubeflow-authorization-token-stealing/</link>
      <pubDate>Wed, 20 May 2026 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2026/05/cve-2026-47237-overly-permissive-istio-permissions-allow-kubeflow-authorization-token-stealing/</guid>
      <description>&lt;p&gt;Kubeflow is vulnerable to the theft of authorization tokens by any user of the&#xA;Kubeflow UI or APIs, such as the Dashboard, Pipelines API, or Notebooks. With&#xA;this token, the attacker can take over the user&amp;rsquo;s account and the data that is&#xA;processed by that user. The attacker needs a valid user with the &lt;code&gt;kubeflow-edit&lt;/code&gt;&#xA;or Contributor role in a random Kubeflow namespace to perform this attack. This&#xA;is given if &lt;em&gt;Automatic Profile Creation&lt;/em&gt; is enabled. A setup based on the&#xA;official manifests prior to version 1.10, and on most other packaged Kubeflow&#xA;distributions, is vulnerable.&lt;/p&gt;&#xA;&lt;p&gt;The Istio edit permissions were removed by Kubeflow in a timely manner. Affected&#xA;users should update to the latest version to mitigate this issue.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Disclosure: Command Injection in Geutebrück Cameras</title>
      <link>https://insinuator.net/2026/04/disclosure-command-injection-in-geutebr%C3%BCck-cameras/</link>
      <pubDate>Thu, 16 Apr 2026 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2026/04/disclosure-command-injection-in-geutebr%C3%BCck-cameras/</guid>
      <description>&lt;p&gt;During a penetration test for a customer, we identified a command injection&#xA;vulnerability in Geutebrück security cameras that allows authenticated attackers&#xA;to execute arbitrary commands as root through the web interface. The root cause&#xA;is unsanitized user input being passed into a &lt;code&gt;sed&lt;/code&gt; script (and at least 12&#xA;other CGI endpoints). In addition to the injection, we identified an XSS&#xA;vulnerability, an exposed system menu leaking configuration and log data, and an&#xA;insecure GET-parameter-to-environment-variable mapping that enables abuse of&#xA;variables like &lt;code&gt;LD_PRELOAD&lt;/code&gt; and &lt;code&gt;LD_DEBUG&lt;/code&gt;. We reported the findings to&#xA;Geutebrück and a patched firmware was provided. This post walks through how we&#xA;got from a  &lt;code&gt;sed&lt;/code&gt; error message to a root shell.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Vulnerabilities in Broadcom VMware Aria Operations: Privilege Escalation (CVE-2025-41245 / CVE-2026-22721)</title>
      <link>https://insinuator.net/2026/03/vulnerabilities-in-broadcom-vmware-aria-operations-privilege-escalation-cve-2025-41245-/-cve-2026-22721/</link>
      <pubDate>Wed, 18 Mar 2026 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2026/03/vulnerabilities-in-broadcom-vmware-aria-operations-privilege-escalation-cve-2025-41245-/-cve-2026-22721/</guid>
      <description>&lt;p&gt;During a customer project, we identified privilege escalation vulnerabilities in&#xA;Broadcom VMware Aria Operations. It is possible to escalate the privileges of an&#xA;administrative vCenter user to an Aria administrator and take over systems&#xA;integrated in Aria. Meaning, the vCenter user can gain privileged access to&#xA;systems they have no access to. While both users might sound similarly&#xA;privileged, this is not true in most environments – especially not in complex&#xA;corporate environments: An insignificant vCenter user in a development&#xA;environment can take over all other vCenters in a complex corporate environment.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Hacking a Bluetooth Printer Server: GATT to UART Adapter?</title>
      <link>https://insinuator.net/2026/03/hacking-a-bluetooth-printer-server-gatt-to-uart-adapter/</link>
      <pubDate>Thu, 12 Mar 2026 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2026/03/hacking-a-bluetooth-printer-server-gatt-to-uart-adapter/</guid>
      <description>&lt;p&gt;This blog post describes the journey of how we discovered an interesting&#xA;Bluetooth SoC within the Datong NP330, a&#xA;&lt;a href=&#34;https://www.dtprinter.cn/upload/doc/NP330_NP332UserManual_en.pdf&#34;&gt;Printer Server IoT device&lt;/a&gt;.&#xA;Our initial goal was to reverse-engineer and analyze the Bluetooth controller&#xA;that is included in the device. So we wanted to be able to dump the firmware or,&#xA;if possible, get shell access on the printer server. During that journey we&#xA;found a few vulnerabilities that ultimately let an attacker fully compromise the&#xA;device. This is possible over Bluetooth or network via unauthenticated remote&#xA;code execution with root privileges.&lt;/p&gt;</description>
    </item>
    <item>
      <title>BlackBoxAI: AI Agent can get your computer fully compromised</title>
      <link>https://insinuator.net/2026/03/blackboxai-ai-agent-can-get-your-computer-fully-compromised/</link>
      <pubDate>Tue, 03 Mar 2026 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2026/03/blackboxai-ai-agent-can-get-your-computer-fully-compromised/</guid>
      <description>&lt;p&gt;AI agents are here, there, and everywhere. Smarter, faster, and more skilled,&#xA;they gain greater autonomy and trust. We trust their capabilities to do many&#xA;tasks much faster and sometimes better than we can. We trust them as they&#xA;usually demonstrate their eagerness to please us and fulfill our commands. Isn’t&#xA;that too good to be true, and we might be dealing with a double-edged sword&#xA;here? Can attackers use the same capabilities of the AI agents to attack their&#xA;own users? Can they exploit their eagerness to please their users to fulfill the&#xA;attackers’ intentions? And most importantly: what’s the worst that could happen&#xA;if you fully trust some random AI Agent?&lt;/p&gt;</description>
    </item>
    <item>
      <title>Vulnerability Disclosure: JWT Authentication Bypass in OpenID Connect Authenticator for Tomcat</title>
      <link>https://insinuator.net/2026/02/vulnerability-disclosure-jwt-authentication-bypass-in-openid-connect-authenticator-for-tomcat/</link>
      <pubDate>Tue, 17 Feb 2026 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2026/02/vulnerability-disclosure-jwt-authentication-bypass-in-openid-connect-authenticator-for-tomcat/</guid>
      <description>&lt;p&gt;During a customer project we identified an issue with the validation of JWT&#xA;tokens that allowed us to bypass the authentication by using unsigned tokens&#xA;with arbitrary payloads. During analysis we found out that this is caused by a&#xA;vulnerability within the library&#xA;&lt;a href=&#34;https://github.com/boylesoftware/tomcat-oidcauth&#34;&gt;OpenID Connect Authenticator for Tomcat&lt;/a&gt;.&lt;/p&gt;&#xA;&lt;p&gt;&lt;a href=&#34;https://github.com/boylesoftware/tomcat-oidcauth&#34;&gt;OpenID Connect Authenticator for Tomcat&lt;/a&gt;&#xA;between versions 2.0.0 and 2.5.0, as well as the current state on branch&#xA;&lt;code&gt;master&lt;/code&gt; contain a security flaw (introduced with commit &lt;code&gt;64e9a99&lt;/code&gt;) that allows&#xA;attackers to bypass JWT signature validation easily.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Release of ERNW White Paper 73: Analyzing WinpMem Driver Vulnerabilities</title>
      <link>https://insinuator.net/2025/10/release-of-ernw-white-paper-73-analyzing-winpmem-driver-vulnerabilities/</link>
      <pubDate>Thu, 02 Oct 2025 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2025/10/release-of-ernw-white-paper-73-analyzing-winpmem-driver-vulnerabilities/</guid>
      <description>&lt;p&gt;Today we are releasing a new white paper that delivers a technical analysis of&#xA;security weaknesses discovered in WinpMem, an open-source Windows memory&#xA;acquisition driver widely used in digital forensics.&lt;/p&gt;&#xA;&lt;p&gt;After a concise primer on relevant Windows internals (virtual vs. physical&#xA;memory, page tables and PTEs, CR3 context switching, and kernel and user memory&#xA;separation), the report examines how both the fundamental design of WinpMem and&#xA;specific implementation choices create severe risk.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Disclosure: Authentication Bypass in VERTIV Avocent AutoView (Version 2.10.0.0.4736)</title>
      <link>https://insinuator.net/2025/09/disclosure-authentication-bypass-in-vertiv-avocent-autoview-version-2.10.0.0.4736/</link>
      <pubDate>Mon, 08 Sep 2025 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2025/09/disclosure-authentication-bypass-in-vertiv-avocent-autoview-version-2.10.0.0.4736/</guid>
      <description>&lt;p&gt;The VERTIV Avocent AutoView switches are analog keyboard, video, and mouse (KVM)&#xA;switches used in data center servers. They also expose a web server in the&#xA;network, which allows for some configuration.&lt;/p&gt;&#xA;&lt;p&gt;During a penetration test for a customer, a device of this type was identified&#xA;in the infrastructure and analyzed, revealing an authentication bypass in the&#xA;web application.&lt;/p&gt;&#xA;&lt;p&gt;The application is written in PHP. To gain access to the PHP scripts, the&#xA;firmware update was downloaded from the vendor’s download page. From the update,&#xA;the PHP files can easily be extracted and analyzed.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Vulnerability Disclosure: Stealing Emails via Prompt Injections</title>
      <link>https://insinuator.net/2025/09/vulnerability-disclosure-stealing-emails-via-prompt-injections/</link>
      <pubDate>Tue, 02 Sep 2025 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2025/09/vulnerability-disclosure-stealing-emails-via-prompt-injections/</guid>
      <description>&lt;p&gt;With the rise of AI assistance features in an increasing number of products, we&#xA;have begun to focus some of our research efforts on refining our internal&#xA;detection and testing guidelines for LLMs by taking a brief look at the new AI&#xA;integrations we discover.&lt;/p&gt;&#xA;&lt;p&gt;Alongside the rise of applications with LLM integrations, an increasing number&#xA;of customers come to ERNW to specifically assess AI applications. Our colleagues&#xA;&lt;a href=&#34;https://www.linkedin.com/in/fgrunow&#34;&gt;Florian Grunow&lt;/a&gt; and&#xA;&lt;a href=&#34;https://www.linkedin.com/in/hannesmohr/&#34;&gt;Hannes Mohr&lt;/a&gt; analyzed the novel attack&#xA;vectors that emerged and presented the results at&#xA;&lt;a href=&#34;https://troopers.de/troopers24/talks/vnwhm8/&#34;&gt;TROOPERS24&lt;/a&gt; already.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Windows Hello for Business - Faceplant: Planting Biometric Templates</title>
      <link>https://insinuator.net/2025/08/windows-hello-for-business-faceplant-planting-biometric-templates/</link>
      <pubDate>Fri, 29 Aug 2025 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2025/08/windows-hello-for-business-faceplant-planting-biometric-templates/</guid>
      <description>&lt;p&gt;We are back from Black Hat USA, where we presented our research on&#xA;&lt;a href=&#34;https://www.blackhat.com/us-25/briefings/schedule/index.html#windows-hell-no-for-business-45865&#34;&gt;Windows Hello for Business&lt;/a&gt;&#xA;(&lt;a href=&#34;http://i.blackhat.com/BH-USA-25/Presentations/US-25-David-Windows-Hello-No-for-Business-Wendsday.pdf&#34;&gt;Slides&lt;/a&gt;)&#xA;once more. In the last two blog posts, we have discussed the&#xA;&lt;a href=&#34;https://insinuator.net/2025/06/windows-hello-for-business-past-and-present-attacks/&#34;&gt;architecture of WHfB and past attacks&lt;/a&gt;,&#xA;as well as how the&#xA;&lt;a href=&#34;https://insinuator.net/2025/07/windows-hello-for-business-the-face-swap/&#34;&gt;database works and how to swap identities&lt;/a&gt; in&#xA;the database.&lt;/p&gt;&#xA;&lt;p&gt;First, a few words regarding my experience at Black Hat: for me, it was the&#xA;first time attending the conference and then directly as a speaker. I thoroughly&#xA;enjoyed Black Hat. It took a while to get used to the size of the conference and&#xA;the vibe of Las Vegas. What was especially interesting for me was connecting&#xA;with other researchers. One thing that stood out was meeting with the team from&#xA;MSRC and putting faces to the team itself. It feels way more personal to know&#xA;who you’re talking to when you know the people handling your cases. During&#xA;TROOPERS I typically have the chance to connect with many researchers, mainly&#xA;from Europe. At Black Hat US, on the other hand, it is possible to connect more&#xA;with the US scene and meet people you haven’t seen in a long time! Seeing&#xA;familiar faces again is always nice, as opposed to putting them into your&#xA;biometric template database. One nice detail was that some international&#xA;researchers are aware of the research BSI (German: “Bundesamt für Sicherheit in&#xA;der Informationstechnik” – “German federal office for IT security”) is&#xA;facilitating. The results of our presentation stem from the “Windows Dissected”&#xA;project we are performing on behalf of the BSI.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Windows Hello for Business - The Face Swap</title>
      <link>https://insinuator.net/2025/07/windows-hello-for-business-the-face-swap/</link>
      <pubDate>Tue, 15 Jul 2025 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2025/07/windows-hello-for-business-the-face-swap/</guid>
      <description>&lt;p&gt;In the&#xA;&lt;a href=&#34;https://insinuator.net/2025/06/windows-hello-for-business-past-and-present-attacks/&#34;&gt;last blog post&lt;/a&gt;,&#xA;we discussed the full authentication flow using Windows Hello for Business&#xA;(WHfB) with face recognition to authenticate against an Active Directory with&#xA;Kerberos and showcased existing and new vulnerabilities. In this blog post, we&#xA;dive into the architectural challenges WHfB faces and explore how we can exploit&#xA;them.&lt;/p&gt;&#xA;&lt;p&gt;The majority of the work was conducted in the context of the “Windows Dissected”&#xA;project. This project, funded by the BSI (German: “Bundesamt für Sicherheit in&#xA;der Informationstechnik” – the German Federal Office for Information Security),&#xA;has the goal to perform ” various in-depth security analyses of&#xA;security-critical components and functions in Windows.” Over the next years we&#xA;will discuss these results here once they are published.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Security Advisory: Airoha-based Bluetooth Headphones and Earbuds</title>
      <link>https://insinuator.net/2025/06/security-advisory-airoha-based-bluetooth-headphones-and-earbuds/</link>
      <pubDate>Thu, 26 Jun 2025 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2025/06/security-advisory-airoha-based-bluetooth-headphones-and-earbuds/</guid>
      <description>&lt;p&gt;&lt;strong&gt;Important note:&lt;/strong&gt; Some media coverage on this topic falsely or inaccurately&#xA;depicts the attack conditions. To be clear: Any vulnerable device can be&#xA;compromised if the attacker is in Bluetooth range. That is the only&#xA;precondition.&lt;/p&gt;&#xA;&lt;hr&gt;&#xA;&lt;p&gt;During our research on Bluetooth headphones and earbuds, we identified several&#xA;vulnerabilities in devices that incorporate Airoha Systems on a Chip (SoCs). In&#xA;this blog post, we briefly want to describe the vulnerabilities, point out their&#xA;impact and provide some context to currently running patch delivery processes as&#xA;described at this year’s&#xA;&lt;a href=&#34;https://troopers.de/troopers25/talks/fbnb8y/&#34;&gt;TROOPERS Conference&lt;/a&gt;.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Disclosure: Multiple Vulnerabilities in X.Org X server prior to 21.1.17 and Xwayland prior to 24.1.7</title>
      <link>https://insinuator.net/2025/06/disclosure-multiple-vulnerabilities-in-x.org-x-server-prior-to-21.1.17-and-xwayland-prior-to-24.1.7/</link>
      <pubDate>Tue, 17 Jun 2025 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2025/06/disclosure-multiple-vulnerabilities-in-x.org-x-server-prior-to-21.1.17-and-xwayland-prior-to-24.1.7/</guid>
      <description>&lt;p&gt;The X11 Window System has been used since September 1987 for Unix desktop&#xA;systems, allowing applications to display their windows. Today, one of the&#xA;server implementations of the protocol is the X.Org X server and XWayland, which&#xA;both use the same codebase. While reviewing the X server, several legacy&#xA;security issues were identified. These appear to originate from earlier design&#xA;stages when security considerations were less prominent. Despite the project’s&#xA;maturity and widespread use, some of these issues have persisted.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Disclosure: Input Validation Vulnerabilities in Microsoft Bookings</title>
      <link>https://insinuator.net/2025/05/disclosure-input-validation-vulnerabilities-in-microsoft-bookings/</link>
      <pubDate>Thu, 08 May 2025 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2025/05/disclosure-input-validation-vulnerabilities-in-microsoft-bookings/</guid>
      <description>&lt;p&gt;In a recent customer project, we discovered vulnerabilities in Microsoft&#xA;Bookings, an online appointment scheduling tool integrated into Microsoft 365,&#xA;allowing companies to have customers book meetings in available times&#xA;themselves. The findings originate from insufficient input validation on the&#xA;public meeting scheduling endpoint. Although Microsoft has largely mitigated&#xA;this vulnerability, our analysis provides important insights into potential&#xA;risks and areas for improvement.&lt;/p&gt;&#xA;&lt;h2 id=&#34;introduction--context&#34;&gt;Introduction &amp;amp; Context&lt;/h2&gt;&#xA;&lt;p&gt;Microsoft Bookings is a service that allows organizations to manage appointments&#xA;and meetings via a web interface. With integration to services such as Microsoft&#xA;Teams, the security of the booking process is critical. This blog post outlines&#xA;our technical analysis of the vulnerability, including proof-of-concept details&#xA;and an overview of the vendor response.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Full Disclosure: Multiple Rundeck Job Command Injections</title>
      <link>https://insinuator.net/2025/05/full-disclosure-multiple-rundeck-job-command-injections/</link>
      <pubDate>Mon, 05 May 2025 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2025/05/full-disclosure-multiple-rundeck-job-command-injections/</guid>
      <description>&lt;p&gt;During a red-teaming-style customer project, we managed to get access to an&#xA;&lt;a href=&#34;https://www.rundeck.com/&#34;&gt;Rundeck&lt;/a&gt; API token. Rundeck is a job scheduler and&#xA;runbook automation platform designed to automate routine IT tasks across&#xA;multiple systems. At first, we were excited about this API token because if we&#xA;could create new Rundeck jobs, we could execute arbitrary code on the Rundeck&#xA;nodes and move laterally from there. However, it turned out that with this token&#xA;we only had permissions to run existing jobs.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Vulnerability Disclosure: Restricted Shell Breakout (CVE-2025-1950) and Privilege Escalation (CVE-2025-1951) in IBM Power Hardware Management Console (HMC)</title>
      <link>https://insinuator.net/2025/04/vulnerability-disclosure-restricted-shell-breakout-cve-2025-1950-and-privilege-escalation-cve-2025-1951-in-ibm-power-hardware-management-console-hmc/</link>
      <pubDate>Fri, 25 Apr 2025 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2025/04/vulnerability-disclosure-restricted-shell-breakout-cve-2025-1950-and-privilege-escalation-cve-2025-1951-in-ibm-power-hardware-management-console-hmc/</guid>
      <description>&lt;p&gt;We discovered a private key for accessing an IBM Hardware Management Console&#xA;(HMC) during a recent red team engagement. The IBM Hardware Management Console&#xA;(HMC) is a dedicated management system used to control and manage IBM servers,&#xA;especially those running on Power Systems (like IBM Power9/Power10) and&#xA;mainframes (z Systems). After brief research, we identified two security&#xA;vulnerabilities that can be leveraged to gain root access to the HMC.&lt;/p&gt;&#xA;&lt;p&gt;Access for most users via SSH is limited through the &lt;code&gt;hmcbash&lt;/code&gt;, a restricted&#xA;shell environment. Using &lt;code&gt;LD_PRELOAD&lt;/code&gt;, attackers can break out of the restricted&#xA;bash and gain access to additional binaries installed on the system. With the&#xA;restrictions lifted, attackers can use a &lt;code&gt;setuid&lt;/code&gt; binary, &lt;code&gt;copysshkey&lt;/code&gt;, to&#xA;elevate privileges to &lt;code&gt;root&lt;/code&gt;.&lt;/p&gt;</description>
    </item>
    <item>
      <title>CVE-2024-11035: Minor Security Issues in VMware Carbon Black Cloud</title>
      <link>https://insinuator.net/2025/03/cve-2024-11035-minor-security-issues-in-vmware-carbon-black-cloud/</link>
      <pubDate>Mon, 31 Mar 2025 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2025/03/cve-2024-11035-minor-security-issues-in-vmware-carbon-black-cloud/</guid>
      <description>&lt;p&gt;We recently conducted a security assessment of VMware Carbon Black Cloud, a&#xA;unified SaaS solution that integrates endpoint detection and response (EDR),&#xA;anti-virus, and vulnerability management capabilities. As part of our&#xA;evaluation, we tested the solution’s ability to detect and prevent malicious&#xA;activity on Windows and Linux systems. Our analysis focused on the Carbon Black&#xA;agents for these platforms, and although we did not identify any critical&#xA;vulnerabilities, we want to share some of the findings in this blog post.&lt;/p&gt;</description>
    </item>
    <item>
      <title>CVE-2025-20908: Use of insufficiently random values in Samsung&#39;s Auracast implementation</title>
      <link>https://insinuator.net/2025/03/cve-2025-20908-use-of-insufficiently-random-values-in-samsungs-auracast-implementation/</link>
      <pubDate>Thu, 13 Mar 2025 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2025/03/cve-2025-20908-use-of-insufficiently-random-values-in-samsungs-auracast-implementation/</guid>
      <description>&lt;p&gt;As part of our &lt;a href=&#34;https://insinuator.net/2025/01/auracast-part1/&#34;&gt;research&lt;/a&gt; into&#xA;the Auracast feature set in Bluetooth, we also started looking into vendor&#xA;implementations. At the time we started with our research, there weren’t a lot&#xA;of products on the market yet. But new products are coming out pretty frequently&#xA;now.&lt;/p&gt;&#xA;&lt;p&gt;One of the vendors that had Auracast implemented pretty early was Samsung. At&#xA;the time the Samsung Galaxy S23 and S24 phones were able to broadcast Audio,&#xA;while the Galaxy Buds were able to join these broadcasts.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Part I: Bluetooth Auracast from a Security Researcher’s Perspective</title>
      <link>https://insinuator.net/2025/01/part-i-bluetooth-auracast-from-a-security-researchers-perspective/</link>
      <pubDate>Mon, 27 Jan 2025 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2025/01/part-i-bluetooth-auracast-from-a-security-researchers-perspective/</guid>
      <description>&lt;p&gt;Auracast, the new Bluetooth LE Broadcast Audio feature has gained some publicity&#xA;in the past months. The Bluetooth SIG has introduced the LE Audio feature-set to&#xA;the Bluetooth 5.2 Specification in 2019 and vendors are only now starting to&#xA;implement it. Auracast facilitates broadcasting audio over Bluetooth LE to a&#xA;potentially unlimited number of devices. It does not require pairing or&#xA;interaction between the sender and the receivers.&lt;/p&gt;&#xA;&lt;p&gt;We also presented this topic&#xA;&lt;a href=&#34;https://media.ccc.de/v/38c3-auracast-breaking-broadcast-le-audio-before-it-hits-the-shelves&#34;&gt;at 38c3&lt;/a&gt;.&#xA;This blog post will contain similar contents albeit with some more details.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Vulnerability Disclosure: Command Injection in Kemp LoadMaster Load Balancer (CVE-2024-7591)</title>
      <link>https://insinuator.net/2024/11/vulnerability-disclosure-command-injection-in-kemp-loadmaster-load-balancer-cve-2024-7591/</link>
      <pubDate>Wed, 27 Nov 2024 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2024/11/vulnerability-disclosure-command-injection-in-kemp-loadmaster-load-balancer-cve-2024-7591/</guid>
      <description>&lt;p&gt;While conducting security research, I identified a critical vulnerability in Kemp’s LoadMaster Load Balancer. This vulnerability is a &lt;a href=&#34;https://owasp.org/www-community/attacks/Command_Injection&#34;&gt;Command Injection&lt;/a&gt; and allows full system compromise. It requires no authentication and can be exploited remotely by having access to the Web User Interface (WUI). Kemp found that all LoadMaster versions up to and including version 7.2.60.0 and also the multi-tenant hypervisors up to and including version 7.1.35.11 are affected.&lt;/p&gt;&#xA;&lt;p&gt;Kemp LoadMaster is a widely used Load Balancing Application that can commonly be seen in customer engagements. Therefore, we decided to take a closer look as part of our regular research projects.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Vulnerability Disclosure: Authentication Bypass in Vaultwarden versions &lt; 1.32.5 - CVE-2024-55225</title>
      <link>https://insinuator.net/2024/11/vulnerability-disclosure-authentication-bypass-in-vaultwarden-versions-1.32.5-cve-2024-55225/</link>
      <pubDate>Fri, 22 Nov 2024 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2024/11/vulnerability-disclosure-authentication-bypass-in-vaultwarden-versions-1.32.5-cve-2024-55225/</guid>
      <description>&lt;p&gt;During a penetration test for a customer, we briefly assessed &lt;a href=&#34;https://github.com/dani-garcia/vaultwarden&#34;&gt;Vaultwarden&lt;/a&gt;, an open-source online password safe. In June 2024, the German Federal Office for Information Security (BSI) published results&lt;sup id=&#34;fnref:1&#34;&gt;&lt;a href=&#34;#fn:1&#34; class=&#34;footnote-ref&#34; role=&#34;doc-noteref&#34;&gt;1&lt;/a&gt;&lt;/sup&gt; of a static and dynamic test of the Vaultwarden server component. Therefore, only a partial source code audit was performed during our assessment. However, a quick look was needed to find some glaring issues with the authentication.&lt;/p&gt;&#xA;&lt;h2 id=&#34;vaultwarden&#34;&gt;Vaultwarden&lt;/h2&gt;&#xA;&lt;p&gt;&lt;a href=&#34;https://github.com/dani-garcia/vaultwarden&#34;&gt;Vaultwarden&lt;/a&gt; is an alternative online password safe server to Bitwarden and exposes the same API so that Bitwarden clients can connect to the Vaultwarden server. Since Bitwarden has a Browser client and Mobile clients, they can all connect to Vaultwarden, too.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Disclosure: Potential Limitations of Apple ADE in Corporate Usage Scenarios</title>
      <link>https://insinuator.net/2024/09/disclosure-potential-limitations-of-apple-ade-in-corporate-usage-scenarios/</link>
      <pubDate>Tue, 03 Sep 2024 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2024/09/disclosure-potential-limitations-of-apple-ade-in-corporate-usage-scenarios/</guid>
      <description>&lt;p&gt;Apple Automated Device Enrollment (ADE) is presented as a way to automate and simplify the enrollment process of Apple devices within Mobile Device Management (MDE) solutions. This blog post is aimed at organizations currently planning or even already using this feature and making you, the reader, aware of potential limitations of this process that might otherwise not be clearly addressed in your companies’ device management process.&lt;/p&gt;&#xA;&lt;h2 id=&#34;how-apple-ade-is-presented&#34;&gt;How Apple ADE Is Presented&lt;/h2&gt;&#xA;&lt;p&gt;Looking at the Apple Support pages today, Automated Device Enrollment is described as a process that&lt;/p&gt;</description>
    </item>
    <item>
      <title>Disclosure: Apple ADE – Network Based Provisioning Bypass</title>
      <link>https://insinuator.net/2024/08/disclosure-apple-ade-network-based-provisioning-bypass/</link>
      <pubDate>Fri, 09 Aug 2024 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2024/08/disclosure-apple-ade-network-based-provisioning-bypass/</guid>
      <description>&lt;p&gt;Mobile Device Management (MDM) solutions are used to centrally manage mobile devices in corporate environments. This includes the monitoring of the device, automatic installation/removal of apps or certificates and restrict the functionality. Even though MDM solutions exist for multiple vendors, we will look specifically on Apple devices enrolled via Intune. When an Apple device is registered for Automated Device Enrollment (ADE), it will automatically download and apply these policies during the initial setup and prior to the first boot.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Security Advisory: Achieving PHP Code Execution in ILIAS eLearning LMS before v7.30/v8.11/v9.1</title>
      <link>https://insinuator.net/2024/05/security-advisory-achieving-php-code-execution-in-ilias-elearning-lms-before-v7.30/v8.11/v9.1/</link>
      <pubDate>Wed, 22 May 2024 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2024/05/security-advisory-achieving-php-code-execution-in-ilias-elearning-lms-before-v7.30/v8.11/v9.1/</guid>
      <description>&lt;p&gt;During my Bachelor’s thesis, I identified several XSS vulnerabilities and a PHP Code Execution vulnerability via an insecure file upload in the learning management system (LMS) ILIAS. The XSS vulnerability can be chained with the code execution vulnerability so that attackers with tutor privileges in at least one course can perform this exploit chain.&lt;/p&gt;&#xA;&lt;p&gt;The Bachelor’s thesis was motivated by the ever-increasing number of compromised universities in Germany&lt;sup id=&#34;fnref:1&#34;&gt;&lt;a href=&#34;#fn:1&#34; class=&#34;footnote-ref&#34; role=&#34;doc-noteref&#34;&gt;1&lt;/a&gt;&lt;/sup&gt;^(,)&lt;sup id=&#34;fnref:2&#34;&gt;&lt;a href=&#34;#fn:2&#34; class=&#34;footnote-ref&#34; role=&#34;doc-noteref&#34;&gt;2&lt;/a&gt;&lt;/sup&gt;^(,)&lt;sup id=&#34;fnref:3&#34;&gt;&lt;a href=&#34;#fn:3&#34; class=&#34;footnote-ref&#34; role=&#34;doc-noteref&#34;&gt;3&lt;/a&gt;&lt;/sup&gt;^(,)&lt;sup id=&#34;fnref:4&#34;&gt;&lt;a href=&#34;#fn:4&#34; class=&#34;footnote-ref&#34; role=&#34;doc-noteref&#34;&gt;4&lt;/a&gt;&lt;/sup&gt;^(,)&lt;sup id=&#34;fnref:5&#34;&gt;&lt;a href=&#34;#fn:5&#34; class=&#34;footnote-ref&#34; role=&#34;doc-noteref&#34;&gt;5&lt;/a&gt;&lt;/sup&gt;. The thesis analyzed the importance of LMS systems in that context, as those services are often exposed to the internet.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Vulnerability in Jitsi Meet: Meeting Password Disclosure affecting Meetings with Lobbies</title>
      <link>https://insinuator.net/2024/05/vulnerability-in-jitsi-meet-meeting-password-disclosure-affecting-meetings-with-lobbies/</link>
      <pubDate>Thu, 02 May 2024 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2024/05/vulnerability-in-jitsi-meet-meeting-password-disclosure-affecting-meetings-with-lobbies/</guid>
      <description>&lt;p&gt;During a customer project, we identified a logic flaw in &lt;a href=&#34;https://jitsi.org/&#34;&gt;Jitsi Meet&lt;/a&gt;, an open-source video conferencing and messaging platform for secure video conferencing, voice calls, and messaging. The vulnerability affects password protected Jitsi meetings that make use of a lobby. This logic flaw leads to the disclosure of the meeting password when a user is invited to the call after waiting in the lobby.&lt;/p&gt;&#xA;&lt;p&gt;Jitsi offers two security options to meeting moderators. Firstly, the meeting can be assigned a password that must be entered when joining. Secondly, a lobby mode can be activated, which first adds joining users to a lobby, from where they can then be added to the meeting by a user with moderation permissions.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Breaking GLS Parcel Tracking</title>
      <link>https://insinuator.net/2024/04/breaking-gls-parcel-tracking/</link>
      <pubDate>Thu, 25 Apr 2024 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2024/04/breaking-gls-parcel-tracking/</guid>
      <description>&lt;p&gt;Recently, we held a talk at the Winterkongress&lt;sup id=&#34;fnref:1&#34;&gt;&lt;a href=&#34;#fn:1&#34; class=&#34;footnote-ref&#34; role=&#34;doc-noteref&#34;&gt;1&lt;/a&gt;&lt;/sup&gt; of the &lt;em&gt;Digitale Gesellschaft Schweiz&lt;/em&gt; in Winterthur, Switzerland, about our research project on breaking German parcel tracking sites. We could not name all the parcel services for which we identified vulnerabilities respecting disclosure timelines. Today, we describe our findings at GLS, another player in the German parcel market, and the disclosure process of corresponding vulnerabilities.&lt;/p&gt;&#xA;&lt;h1 id=&#34;findings&#34;&gt;Findings&lt;/h1&gt;&#xA;&lt;p&gt;Similar to the vulnerabilities previously disclosed for DHL&lt;sup id=&#34;fnref:2&#34;&gt;&lt;a href=&#34;#fn:2&#34; class=&#34;footnote-ref&#34; role=&#34;doc-noteref&#34;&gt;2&lt;/a&gt;&lt;/sup&gt; and DPD&lt;sup id=&#34;fnref:3&#34;&gt;&lt;a href=&#34;#fn:3&#34; class=&#34;footnote-ref&#34; role=&#34;doc-noteref&#34;&gt;3&lt;/a&gt;&lt;/sup&gt;, and UPS&lt;sup id=&#34;fnref:4&#34;&gt;&lt;a href=&#34;#fn:4&#34; class=&#34;footnote-ref&#34; role=&#34;doc-noteref&#34;&gt;4&lt;/a&gt;&lt;/sup&gt;, we identified that the GLS parcel tracking website discloses the recipient’s geographic area by showing the name of the destination parcel center. Furthermore, the recipient’s ZIP code was used to unlock personal information (including the exact coordinates of the address) and features that influence the parcel delivery process. The website did not implement rate-limiting or other techniques to prevent brute-forcing ZIP codes using the API.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Breaking UPS Parcel Tracking</title>
      <link>https://insinuator.net/2024/04/breaking-ups-parcel-tracking/</link>
      <pubDate>Wed, 10 Apr 2024 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2024/04/breaking-ups-parcel-tracking/</guid>
      <description>&lt;p&gt;Today, we describe our findings at United Parcel Service of America, Inc. (UPS), another German parcel market player, and the corresponding vulnerabilities’ disclosure process.&lt;/p&gt;&#xA;&lt;h1 id=&#34;findings&#34;&gt;Findings&lt;/h1&gt;&#xA;&lt;p&gt;Only a valid tracking number is needed to get the personal information of a parcel’s receiver, including the sender’s location, the recipient’s name, and the recipient’s location (city and country). It was possible to enumerate numerous tracking numbers during testing by iterating from known ones. Since the last digit of a tracking number is a checksum, it can be calculated. Also, certain businesses have a predefined prefix in their tracking numbers. This schema allows the enumeration of every parcel sent from a particular business.&lt;/p&gt;</description>
    </item>
    <item>
      <title>I know what you ordered last summer @ Winterkongress 2024</title>
      <link>https://insinuator.net/2024/04/i-know-what-you-ordered-last-summer-@-winterkongress-2024/</link>
      <pubDate>Wed, 03 Apr 2024 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2024/04/i-know-what-you-ordered-last-summer-@-winterkongress-2024/</guid>
      <description>&lt;p&gt;Dennis and I already published blog posts about our research project dealing with vulnerabilities in parcel tracking implementations at &lt;a href=&#34;https://insinuator.net/2023/07/all-your-parcel-are-belong-to-us-talk-at-troopers-2023/&#34;&gt;DHL&lt;/a&gt; and &lt;a href=&#34;https://insinuator.net/2023/09/breaking-dpd-parcel-tracking/&#34;&gt;DPD&lt;/a&gt;. At the &lt;a href=&#34;https://cfp.winterkongress.ch/wk24/schedule/&#34;&gt;&lt;em&gt;Winterkongress&lt;/em&gt;&lt;/a&gt; (winter congress) in Winterthur, Switzerland, we had the great opportunity to give a talk about the matter. The talk was recorded and can be watched &lt;a href=&#34;https://media.ccc.de/v/dgwk2024-56194-ich-wei-was-du-letzten-so&#34;&gt;here&lt;/a&gt;.&lt;/p&gt;&#xA;&lt;p&gt;&lt;a href=&#34;https://digitale-gesellschaft.ch&#34;&gt;&lt;em&gt;DigiGes&lt;/em&gt;&lt;/a&gt; held the Winterkongress, which took place in Winterthur on 01.03. till 02.03.2024. The main topics are ethics, threats, and opportunities of IT. This year, many talks looked at AI in some way.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Lua-Resty-JWT Authentication Bypass</title>
      <link>https://insinuator.net/2023/10/lua-resty-jwt-authentication-bypass/</link>
      <pubDate>Tue, 10 Oct 2023 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2023/10/lua-resty-jwt-authentication-bypass/</guid>
      <description>&lt;p&gt;I was writing some challenges for PacketWars at&#xA;&lt;a href=&#34;https://troopers.de/&#34;&gt;TROOPERS22&lt;/a&gt;. One was intended to be a JWT key confusion&#xA;challenge where the public key from an RSA JWT should be recovered and used to&#xA;sign a symmetric JWT. For that, I was searching for a library vulnerable to JWT&#xA;key confusion by default and found &lt;em&gt;lua-resty-jwt&lt;/em&gt;. The original repository by&#xA;&lt;em&gt;SkyLothar&lt;/em&gt; is not maintained and different from the library that is installed&#xA;with the LuaRocks package manager. The investigated library is a&#xA;&lt;a href=&#34;https://github.com/cdbattags/lua-resty-jwt&#34;&gt;fork&lt;/a&gt; of the original repository,&#xA;maintained by &lt;em&gt;cdbattags&lt;/em&gt; in version 0.2.3 and was downloaded more than&#xA;&lt;a href=&#34;https://luarocks.org/modules/cdbattags/lua-resty-jwt&#34;&gt;4.8 million times&lt;/a&gt;&#xA;according to LuaRocks.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Breaking DPD Parcel Tracking</title>
      <link>https://insinuator.net/2023/09/breaking-dpd-parcel-tracking/</link>
      <pubDate>Tue, 12 Sep 2023 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2023/09/breaking-dpd-parcel-tracking/</guid>
      <description>&lt;p&gt;This blog post is the continuation of our parcel research. We already reported&#xA;about how we broke parcel tracking at&#xA;&lt;a href=&#34;https://insinuator.net/2023/07/all-your-parcel-are-belong-to-us-talk-at-troopers-2023/&#34;&gt;DHL&lt;/a&gt;&#xA;and the disclosure process of the identified problems. As DHL is not the only&#xA;parcel service in Germany, we also investigated the other available parcel&#xA;services. In this blog post, we want to talk about DPD, also called Geopost,&#xA;which belongs to the French Post Office.&lt;/p&gt;&#xA;&lt;h2 id=&#34;efficient-guessing-of-tracking-numbers&#34;&gt;Efficient Guessing of Tracking Numbers&lt;/h2&gt;&#xA;&lt;p&gt;DPD uses the recipient’s ZIP code to unlock detailed shipment information and&#xA;additional options. After trying some ZIP codes manually, we received CAPTCHA&#xA;prompts in the web interface (more on this later).&lt;/p&gt;</description>
    </item>
    <item>
      <title>All your parcel are belong to us – Talk at Troopers 2023</title>
      <link>https://insinuator.net/2023/07/all-your-parcel-are-belong-to-us-talk-at-troopers-2023/</link>
      <pubDate>Tue, 11 Jul 2023 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2023/07/all-your-parcel-are-belong-to-us-talk-at-troopers-2023/</guid>
      <description>&lt;p&gt;At Troopers 2023, we gave a talk on how to attack DHL parcel tracking&#xA;information based on OSINT. Since we previously had an exemplary disclosure&#xA;process about this attack with DHL, Mr. Kiehne (from DHL) joined us to provide&#xA;interesting background information and insights on how they addressed our&#xA;findings.&lt;/p&gt;&#xA;&lt;p&gt;We want to thank DHL and especially Mr. Kiehne for sharing those insights with&#xA;us at Troopers 2023. It is the ideal case, but still not common that&#xA;organizations talk openly about their actions and views on a disclosure process.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Jasper Reports Library Code Injection</title>
      <link>https://insinuator.net/2023/06/jasper-reports-library-code-injection/</link>
      <pubDate>Tue, 13 Jun 2023 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2023/06/jasper-reports-library-code-injection/</guid>
      <description>&lt;p&gt;During the past year we had several projects where our target application used&#xA;&lt;a href=&#34;https://community.jaspersoft.com/&#34;&gt;Jasper Reports&lt;/a&gt; in some way. In a few of the&#xA;cases we found an API that offered to render a template along with some&#xA;arguments into a PDF file. This was done with the help of the Jasper Reports&#xA;Java library. Due to the way the library and the expression mechanism works,&#xA;this endpoint gave us the possibility to inject Java code and gain remote code&#xA;execution on the target systems.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Some experiments with Process Hollowing</title>
      <link>https://insinuator.net/2022/09/some-experiments-with-process-hollowing/</link>
      <pubDate>Thu, 29 Sep 2022 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2022/09/some-experiments-with-process-hollowing/</guid>
      <description>&lt;p&gt;Process Hollowing is a technique used by various malware families (such as&#xA;FormBook, TrickBot and Agent Tesla) to hide their malicious code within a benign&#xA;appearing process. The typical workflow for setting up such a&#xA;&lt;a href=&#34;https://attack.mitre.org/techniques/T1055/012/&#34;&gt;hollowed process&lt;/a&gt; is as&#xA;follows:&lt;/p&gt;&#xA;&lt;ol&gt;&#xA;&lt;li&gt;Create a new process (victim) using a benign executable, in suspended state.&lt;/li&gt;&#xA;&lt;li&gt;Unmap the executable from that process.&lt;/li&gt;&#xA;&lt;li&gt;Allocate memory for the malicious executable at the address of the&#xA;previously mapped victim executable.&lt;/li&gt;&#xA;&lt;li&gt;Write the malicious executable to the new memory area and potentially apply&#xA;relocations.&lt;/li&gt;&#xA;&lt;li&gt;Adjust the entry point.&lt;/li&gt;&#xA;&lt;li&gt;Resume process.&lt;/li&gt;&#xA;&lt;/ol&gt;&#xA;&lt;p&gt;We will refer to this as the “normal” Process Hollowing workflow. There are also&#xA;variants of this technique, one being to not unmap the original executable and&#xA;to allocate the new memory somewhere else. We will call this one no-unmap. But&#xA;wait, why does malware not simply overwrite the existing executable but creates&#xA;a new memory area which stands out due to its characteristics? In this blog post&#xA;we will have a closer look at this overwrite approach but also on the no-unmap&#xA;method, their effects on analysis/detection tools and on some tricks to make the&#xA;detection harder. We are also releasing Proof of Concept implementations of all&#xA;mentioned tools/plugins (the links are at the end of this post).&lt;/p&gt;</description>
    </item>
    <item>
      <title>Security Advisories for Broadcom Automic Automation (UC4)</title>
      <link>https://insinuator.net/2022/06/security-advisories-for-broadcom-automic-automation-uc4/</link>
      <pubDate>Thu, 09 Jun 2022 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2022/06/security-advisories-for-broadcom-automic-automation-uc4/</guid>
      <description>&lt;h2 id=&#34;updated-on-200622-with-cves-and-link-to-broadcom-security-notice&#34;&gt;Updated on 20.06.22 with CVEs and link to Broadcom Security Notice.&lt;/h2&gt;&#xA;&lt;p&gt;In April 2021 we reported seven vulnerabilities in Broadcom Automic Automation&#xA;(UC4) 12.3.5+hf.3. CVE IDs were assigned on 16.06.22, the corresponding Broadcom&#xA;Security Notice can be found&#xA;&lt;a href=&#34;https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/20629&#34;&gt;here&lt;/a&gt;.&lt;/p&gt;&#xA;&lt;p&gt;The vulnerabilities have been found in the course of a research project, in&#xA;which we analyzed the security of multiple Endpoint Management solutions.&#xA;Similar vulnerabilities have been found in other solutions as we pointed out in&#xA;previous posts about the&#xA;&lt;a href=&#34;https://insinuator.net/2020/06/security-advisories-for-ivanti-dsm-suite/&#34;&gt;Ivanti DSM Suite&lt;/a&gt;,&#xA;&lt;a href=&#34;https://insinuator.net/2020/07/security-advisories-for-nagios-xi/&#34;&gt;Nagios XI&lt;/a&gt;,&#xA;and&#xA;&lt;a href=&#34;https://insinuator.net/2020/12/security-advisories-for-solarwinds-n-central/&#34;&gt;Solarwinds N-Central&lt;/a&gt;. &#xA;The outcome of the research project will be published as a whitepaper and a&#xA;conference talk at&#xA;&lt;a href=&#34;https://troopers.de/troopers22/talks/brzgam/&#34;&gt;Troopers 2022&lt;/a&gt;.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Change Your BLE Passkey Like You Change Your Underwear</title>
      <link>https://insinuator.net/2021/10/change-your-ble-passkey-like-you-change-your-underwear/</link>
      <pubDate>Thu, 21 Oct 2021 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2021/10/change-your-ble-passkey-like-you-change-your-underwear/</guid>
      <description>&lt;p&gt;Using a static passkey for Bluetooth Low Energy pairing is insecure. Recent&#xA;versions of the Bluetooth specification contain an explicit warning about this.&#xA;However, in practice, we often see static passkeys being used. Moreover, there&#xA;are no public implementations of proofs-of-concept that can practically show why&#xA;using a static passkey is an issue. This is why we implemented one.&lt;/p&gt;&#xA;&lt;p&gt;In a recent assessment, we were testing a device that offered a Bluetooth&#xA;interface for data export and configuration. This device uses Bluetooth Low&#xA;Energy (BLE), and a static passkey (or PIN) is required to pair with it. This&#xA;passkey is displayed for a few seconds when the device is booted and stays the&#xA;same on each reboot. In fact, it is derived from static, device-specific data.&lt;/p&gt;</description>
    </item>
    <item>
      <title>ManiMed: Ypsomed AG – mylife YpsoPump System Vulnerabilities</title>
      <link>https://insinuator.net/2021/07/manimed-ypsomed-ag-mylife-ypsopump-system-vulnerabilities/</link>
      <pubDate>Thu, 29 Jul 2021 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2021/07/manimed-ypsomed-ag-mylife-ypsopump-system-vulnerabilities/</guid>
      <description>&lt;p&gt;The Federal Office for Information Security (BSI) aims to sensitize&#xA;manufacturers and the public regarding security risks of networked medical&#xA;devices in Germany. In response to the often fatal security reports and press&#xA;releases of networked medical devices, the BSI initiated the project&#xA;Manipulation of Medical Devices (ManiMed) in 2019. In this project, a security&#xA;analysis of selected products is carried out through security assessments&#xA;followed by Coordinated Vulnerability Diclosure (CVD) processes. The project&#xA;report was published on December 31, 2020, and can be accessed on the BSI&#xA;website&#xA;[&lt;a href=&#34;https://www.bsi.bund.de/SharedDocs/Downloads/DE/BSI/DigitaleGesellschaft/ManiMed_Abschlussbericht_EN.html&#34;&gt;1&lt;/a&gt;].&lt;/p&gt;</description>
    </item>
    <item>
      <title>Attack llvmpipe Graphics Driver from Chromium</title>
      <link>https://insinuator.net/2021/05/attack-llvmpipe-graphics-driver-from-chromium/</link>
      <pubDate>Tue, 04 May 2021 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2021/05/attack-llvmpipe-graphics-driver-from-chromium/</guid>
      <description>&lt;p&gt;In this post, we are discussing a bug we came across in Mesas llvmpipe Gallium3D&#xA;graphics driver. This bug was accessible through Chromium’s WebGL implementation&#xA;and can provide control of the program counter (pc) within Chromium’s GPU&#xA;process if llvmpipe is used. Llvmpipe is a software rasterizer that is used on&#xA;Linux if no hardware acceleration (graphics card) is available. This is a pretty&#xA;rare edge case as llvmpipe has no widespread use. An estimate by Google is that&#xA;approx 0.06% of the Chromium users are affected by this. However, as this is a&#xA;simple but valid Chromium bug, we want to give you a quick walkthrough. The&#xA;issue is tracked as&#xA;&lt;a href=&#34;https://bugs.chromium.org/p/chromium/issues/detail?id=1155974&#34;&gt;CVE-2021-21153&lt;/a&gt;&#xA;and was fixed in February 2020.&lt;/p&gt;</description>
    </item>
    <item>
      <title>fpicker: Fuzzing with Frida</title>
      <link>https://insinuator.net/2021/03/fpicker-fuzzing-with-frida/</link>
      <pubDate>Mon, 15 Mar 2021 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2021/03/fpicker-fuzzing-with-frida/</guid>
      <description>&lt;h2 id=&#34;introduction&#34;&gt;Introduction&lt;/h2&gt;&#xA;&lt;p&gt;In this post, I will introduce fpicker. Fpicker is a Frida-based&#xA;coverage-guided, mostly in-process, blackbox fuzzing suite. Its most significant&#xA;feature is the AFL++ proxy mode which enables blackbox in-process fuzzing with&#xA;AFL++ on platforms supported by Frida. In practice, this means that fpicker&#xA;enables fuzzing binary-only targets with AFL++ on potentially any system that is&#xA;supported by Frida. For example, it allows fuzzing a user-space application on&#xA;the iOS operating system, such as the Bluetooth daemon bluetoothd – which was&#xA;part of the original motivation to implement fpicker.&lt;/p&gt;</description>
    </item>
    <item>
      <title>ManiMed: Hamilton Medical AG – HAMILTON-T1 Ventilator Vulnerabilities</title>
      <link>https://insinuator.net/2021/02/manimed-hamilton-medical-ag-hamilton-t1-ventilator-vulnerabilities/</link>
      <pubDate>Mon, 22 Feb 2021 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2021/02/manimed-hamilton-medical-ag-hamilton-t1-ventilator-vulnerabilities/</guid>
      <description>&lt;p&gt;The Federal Office for Information Security (BSI) aims to sensitize&#xA;manufacturers and the public regarding security risks of networked medical&#xA;devices in Germany. In response to the often fatal security reports and press&#xA;releases of networked medical devices, the BSI initiated the project&#xA;Manipulation of Medical Devices (ManiMed) in 2019. In this project, a security&#xA;analysis of selected products is carried out through security assessments&#xA;followed by Coordinated Vulnerability Diclosure (CVD) processes. The project&#xA;report was published on December 31, 2020, and can be accessed on the BSI&#xA;website &lt;sup id=&#34;fnref:1&#34;&gt;&lt;a href=&#34;#fn:1&#34; class=&#34;footnote-ref&#34; role=&#34;doc-noteref&#34;&gt;1&lt;/a&gt;&lt;/sup&gt;.&lt;/p&gt;</description>
    </item>
    <item>
      <title>ManiMed: B. Braun Melsungen AG – Space System Vulnerabilities</title>
      <link>https://insinuator.net/2021/02/manimed-b.-braun-melsungen-ag-space-system-vulnerabilities/</link>
      <pubDate>Mon, 15 Feb 2021 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2021/02/manimed-b.-braun-melsungen-ag-space-system-vulnerabilities/</guid>
      <description>&lt;p&gt;The Federal Office for Information Security (BSI) aims to sensitize&#xA;manufacturers and the public regarding security risks of networked medical&#xA;devices in Germany. In response to the often fatal security reports and press&#xA;releases of networked medical devices, the BSI initiated the project&#xA;Manipulation of Medical Devices (ManiMed) in 2019. In this project, a security&#xA;analysis of selected products is carried out through security assessments&#xA;followed by Coordinated Vulnerability Diclosure (CVD) processes. The project&#xA;report was published on December 31, 2020, and can be accessed on the BSI&#xA;website&lt;sup id=&#34;fnref:1&#34;&gt;&lt;a href=&#34;#fn:1&#34; class=&#34;footnote-ref&#34; role=&#34;doc-noteref&#34;&gt;1&lt;/a&gt;&lt;/sup&gt;.&lt;/p&gt;</description>
    </item>
    <item>
      <title>ManiMed: Innokas Yhtymä Oy - VC150 Patient Monitor Vulnerabilities</title>
      <link>https://insinuator.net/2021/02/manimed-innokas-yhtym%C3%A4-oy-vc150-patient-monitor-vulnerabilities/</link>
      <pubDate>Mon, 01 Feb 2021 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2021/02/manimed-innokas-yhtym%C3%A4-oy-vc150-patient-monitor-vulnerabilities/</guid>
      <description>&lt;p&gt;The Federal Office for Information Security (BSI) aims to sensitize&#xA;manufacturers and the public regarding security risks of networked medical&#xA;devices in Germany. In response to the often fatal security reports and press&#xA;releases of networked medical devices, the BSI initiated the project&#xA;Manipulation of Medical Devices (ManiMed) in 2019. In this project, a security&#xA;analysis of selected products is carried out through security assessments&#xA;followed by Coordinated Vulnerability Diclosure (CVD) processes. The project&#xA;report was published on December 31, 2020, and can be accessed on the BSI&#xA;website&lt;sup id=&#34;fnref:1&#34;&gt;&lt;a href=&#34;#fn:1&#34; class=&#34;footnote-ref&#34; role=&#34;doc-noteref&#34;&gt;1&lt;/a&gt;&lt;/sup&gt;.&lt;/p&gt;</description>
    </item>
    <item>
      <title>ManiMed: Philips Medizin Systeme Böblingen GmbH – IntelliVue System Vulnerabilities</title>
      <link>https://insinuator.net/2021/01/manimed-philips-medizin-systeme-b%C3%B6blingen-gmbh-intellivue-system-vulnerabilities/</link>
      <pubDate>Mon, 25 Jan 2021 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2021/01/manimed-philips-medizin-systeme-b%C3%B6blingen-gmbh-intellivue-system-vulnerabilities/</guid>
      <description>&lt;p&gt;The Federal Office for Information Security (BSI) aims to sensitize&#xA;manufacturers and the public regarding security risks of networked medical&#xA;devices in Germany. In response to the often fatal security reports and press&#xA;releases of networked medical devices, the BSI initiated the project&#xA;Manipulation of Medical Devices (ManiMed) in 2019. In this project, a security&#xA;analysis of selected products is carried out through security assessments&#xA;followed by Coordinated Vulnerability Diclosure (CVD) processes. The project&#xA;report was published on December 31, 2020, and can be accessed on the BSI&#xA;website&lt;sup id=&#34;fnref:1&#34;&gt;&lt;a href=&#34;#fn:1&#34; class=&#34;footnote-ref&#34; role=&#34;doc-noteref&#34;&gt;1&lt;/a&gt;&lt;/sup&gt;/&lt;/p&gt;</description>
    </item>
    <item>
      <title>ManiMed: Market Analysis</title>
      <link>https://insinuator.net/2021/01/manimed-market-analysis/</link>
      <pubDate>Mon, 18 Jan 2021 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2021/01/manimed-market-analysis/</guid>
      <description>&lt;p&gt;The Federal Office for Information Security (BSI) aims to sensitize&#xA;manufacturers and the public regarding security risks of networked medical&#xA;devices in Germany. In response to the often fatal security reports and press&#xA;releases of networked medical devices, the BSI initiated the project&#xA;Manipulation of Medical Devices (ManiMed) in 2019. In this project, a security&#xA;analysis of selected products is carried out through security assessments&#xA;followed by Coordinated Vulnerability Diclosure (CVD) processes. The project&#xA;report was published on December 31, 2020, and can be accessed on the BSI&#xA;website&lt;sup id=&#34;fnref:1&#34;&gt;&lt;a href=&#34;#fn:1&#34; class=&#34;footnote-ref&#34; role=&#34;doc-noteref&#34;&gt;1&lt;/a&gt;&lt;/sup&gt;.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Root Cause Analysis of a Heap-Based Buffer Overflow in GNU Readline</title>
      <link>https://insinuator.net/2020/12/root-cause-analysis-of-a-heap-based-buffer-overflow-in-gnu-readline/</link>
      <pubDate>Thu, 17 Dec 2020 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2020/12/root-cause-analysis-of-a-heap-based-buffer-overflow-in-gnu-readline/</guid>
      <description>&lt;p&gt;In the &lt;a href=&#34;https://insinuator.net/2020/12/how-fuzzers-decide-if-a-crash-is-unique/&#34;&gt;last blog post&lt;/a&gt;, we discussed how fuzzers determine the uniqueness of a crash. In this blog post, we discuss how we can manually triage a crash and determine the root cause. As an example, we use a heap-based buffer overflow I found in GNU readline 8.1 rc2, which has been fixed in the newest release. We use GDB and rr for time-travel debugging to determine the root cause of the bug.&lt;/p&gt;</description>
    </item>
    <item>
      <title>VMware NSX-T MITM Vulnerability (CVE-2020-3993)</title>
      <link>https://insinuator.net/2020/11/vmware-nsx-t-mitm-vulnerability-cve-2020-3993/</link>
      <pubDate>Thu, 26 Nov 2020 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2020/11/vmware-nsx-t-mitm-vulnerability-cve-2020-3993/</guid>
      <description>&lt;p&gt;NSX-T is a Software-Defined-Networking (SDN) solution of VMware which, as its basic functionality, supports spanning logical networks across VMs on distributed ESXi and KVM hypervisors. The central controller of the SDN is the NSX-T Manager Cluster which is responsible for deploying the network configurations to the hypervisor hosts.&lt;/p&gt;&#xA;&lt;p&gt;This summer, I looked into the mechanism which is used to add new KVM hypervisor nodes to the SDN via the NSX-T Manager. By tracing what happens on the KVM host, I discovered that the KVM hypervisor got instructed to download the NSX-T software packages from the NSX-T Manager via unencrypted HTTP and install them without any verification. This enables a Man-in-the-Middle (MITM) attacker on the network path to replace the downloaded packages with malicious ones and compromise the KVM hosts.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Vulnerabilities in GNU Readline Fixed</title>
      <link>https://insinuator.net/2020/10/vulnerabilities-in-gnu-readline-fixed/</link>
      <pubDate>Wed, 07 Oct 2020 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2020/10/vulnerabilities-in-gnu-readline-fixed/</guid>
      <description>&lt;p&gt;Recently I discovered some vulnerabilities in &lt;a href=&#34;https://tiswww.case.edu/php/chet/readline/rltop.html&#34;&gt;GNU Readline&lt;/a&gt;. These bugs have been &lt;a href=&#34;https://lists.gnu.org/archive/html/bug-readline/2020-10/msg00002.html&#34;&gt;fixed&lt;/a&gt; in GNU Readline version 8.1.&lt;/p&gt;&#xA;&lt;p&gt;The case of identifying the vulnerabilities was rather interesting. I wanted to fuzz another program and wrote a quick harness to test if my setup works. This test harness used GNU Readline to read input from stdin and passed the data along to the function under test. I left the fuzzer running while I started to improve the harness (which would also mean getting rid of GNU Readline as it is relatively slow for the use-case at hand). However, AFL showed the first crashes and upon inspection, the vulnerabilities where not in the code I actually wanted to fuzz but in my systems GNU Readline.&lt;/p&gt;</description>
    </item>
    <item>
      <title>ERNW White Paper 69 – Safety Impact of Vulnerabilities in Insulin Pumps</title>
      <link>https://insinuator.net/2020/09/ernw-white-paper-69-safety-impact-of-vulnerabilities-in-insulin-pumps/</link>
      <pubDate>Fri, 11 Sep 2020 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2020/09/ernw-white-paper-69-safety-impact-of-vulnerabilities-in-insulin-pumps/</guid>
      <description>&lt;p&gt;With this blog post I am pleased to announce the publication of a new ERNW White Paper &lt;a href=&#34;https://ernw-research.de/en/whitepapers/issue-69.html&#34;&gt;[1]&lt;/a&gt;. The paper is about severe vulnerabilities in an insulin pump we assessed during project ManiMed and we are proud to publish this subset of the results today.&lt;/p&gt;&#xA;&lt;h2 id=&#34;manipulating-medical-devices&#34;&gt;Manipulating Medical Devices&lt;/h2&gt;&#xA;&lt;p&gt;The German Federal Office for Information Security (BSI), in its role as the Federal Cyber Security Authority in Germany, aims to sensitize manufacturers and the public regarding security risks of networked medical devices. In response to the often fatal security reports and press releases of networked medical devices, the BSI initiated the project Manipulation of Medical Devices (ManiMed) in 2019. In this project, a security analysis of selected products is carried out through security assessments. In the context of this project, severe vulnerabilities were identified during the assessment of the DANA Diabecare RS system.&lt;/p&gt;</description>
    </item>
    <item>
      <title>ACM WiSec 2020</title>
      <link>https://insinuator.net/2020/07/acm-wisec-2020/</link>
      <pubDate>Sun, 26 Jul 2020 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2020/07/acm-wisec-2020/</guid>
      <description>&lt;p&gt;Last week I attended &lt;a href=&#34;https://wisec2020.ins.jku.at/&#34;&gt;ACM WiSec&lt;/a&gt;. Of course, only virtually. The first virtual conference I attended. Coincidentally, it was also the first conference I presented at. While the experience was quite different from a “real” conference, the organizers did a great job to make the experience as good as possible with, for example, a mattermost instance to interact with other conference participants.&lt;/p&gt;&#xA;&lt;p&gt;In the following, I will list a few talks and papers that I either found very interesting or that generally stood out to me:&lt;/p&gt;</description>
    </item>
    <item>
      <title>Medical Device Security: HL7v2 Injections in Patient Monitors</title>
      <link>https://insinuator.net/2020/04/medical-device-security-hl7v2-injections-in-patient-monitors/</link>
      <pubDate>Thu, 23 Apr 2020 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2020/04/medical-device-security-hl7v2-injections-in-patient-monitors/</guid>
      <description>&lt;p&gt;Digital networking is already widespread in many areas of life. In the healthcare industry, a clear trend towards networked devices is noticeable, so that the number of high-tech medical devices in hospitals is steadily increasing.&lt;/p&gt;&#xA;&lt;p&gt;In this blog post, we want to elucidate a vulnerability we identified during the security assessment of a patient monitor. The device sends HL7 v2.x messages, such as observation results to HL7 v2.x capable electronic medical record (EMR) systems. A user with malicious intent can tamper these messages. As HL7 v2.x is a common medical communication standard, we also want to present how this kind of vulnerability may be mitigated. The assessment was part of the BSI project ManiMed, which we would like to present in the following section.&lt;/p&gt;</description>
    </item>
    <item>
      <title>CVE-2020-0022 an Android 8.0-9.0 Bluetooth Zero-Click RCE – BlueFrag</title>
      <link>https://insinuator.net/2020/04/cve-2020-0022-an-android-8.0-9.0-bluetooth-zero-click-rce-bluefrag/</link>
      <pubDate>Wed, 22 Apr 2020 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2020/04/cve-2020-0022-an-android-8.0-9.0-bluetooth-zero-click-rce-bluefrag/</guid>
      <description>&lt;p&gt;Nowadays, Bluetooth is an integral part of mobile devices. Smartphones interconnect with smartwatches and wireless headphones. By default, most devices are configured to accept Bluetooth connections from any&lt;br&gt;&#xA;nearby unauthenticated device. Bluetooth packets are processed by the Bluetooth chip (also called a controller), and then passed to the host (Android, Linux, etc.). Both, the firmware on the chip and the host Bluetooth subsystem, are a target for Remote Code Execution (RCE) attacks.&lt;/p&gt;</description>
    </item>
    <item>
      <title>DNS exfiltration case study</title>
      <link>https://insinuator.net/2020/03/dns-exfiltration-case-study/</link>
      <pubDate>Wed, 04 Mar 2020 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2020/03/dns-exfiltration-case-study/</guid>
      <description>&lt;p&gt;Lately, we came across a remote code execution in a Tomcat web service by utilizing &lt;a href=&#34;https://docs.oracle.com/javaee/6/tutorial/doc/gjddd.html&#34;&gt;Expression Language&lt;/a&gt;. The vulnerable POST body field expected a number. When sending &lt;code&gt;${1+2}&lt;/code&gt; instead, the web site included a Java error message about a failed conversion to &lt;code&gt;java.lang.Long&lt;/code&gt; from &lt;code&gt;java.lang.String&lt;/code&gt; with value &lt;code&gt;&amp;quot;3&amp;quot;&lt;/code&gt;.&lt;/p&gt;&#xA;&lt;p&gt;From that error message we learned a couple of things:&lt;/p&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;The application uses Java&lt;/li&gt;&#xA;&lt;li&gt;We are able to execute EL expressions&lt;/li&gt;&#xA;&lt;li&gt;Output from the EL engine is always returned as &lt;code&gt;String&lt;/code&gt;&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;p&gt;Whenever you are able to execute code within a Java Context, the most interesting part is to check whether we can get a &lt;code&gt;Runtime&lt;/code&gt; object and execute arbitrary OS commands.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Critical Bluetooth Vulnerability in Android (CVE-2020-0022) – BlueFrag</title>
      <link>https://insinuator.net/2020/02/critical-bluetooth-vulnerability-in-android-cve-2020-0022-bluefrag/</link>
      <pubDate>Thu, 06 Feb 2020 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2020/02/critical-bluetooth-vulnerability-in-android-cve-2020-0022-bluefrag/</guid>
      <description>&lt;p&gt;On November 3rd, 2019, we have reported a critical vulnerability affecting the Android Bluetooth subsystem. This vulnerability has been assigned &lt;a href=&#34;https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-0022&#34;&gt;CVE-2020-0022&lt;/a&gt; and was now patched in the &lt;a href=&#34;https://source.android.com/security/bulletin/2020-02-01.html&#34;&gt;latest security patch&lt;/a&gt; from February 2020. The security impact is as follows:&lt;/p&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;On Android 8.0 to 9.0, a remote attacker within proximity can silently execute arbitrary code with the privileges of the Bluetooth daemon as long as Bluetooth is enabled. No user interaction is required and only the Bluetooth MAC address of the target devices has to be known. For some devices, the Bluetooth MAC address can be deduced from the WiFi MAC address. This vulnerability can lead to theft of personal data and could potentially be used to spread malware (Short-Distance Worm).&lt;/li&gt;&#xA;&lt;li&gt;On Android 10, this vulnerability is not exploitable for technical reasons and only results in a crash of the Bluetooth daemon.&lt;/li&gt;&#xA;&lt;li&gt;Android versions even older than 8.0 might also be affected but we have not evaluated the impact.&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;p&gt;Users are strongly advised to install the latest available security patch from February 2020. If you have no patch available yet or your device is not supported anymore, you can try to mitigate the impact by some generic behavior rules:&lt;/p&gt;</description>
    </item>
    <item>
      <title>Jenkins – Groovy Sandbox breakout (SECURITY-1538 / CVE-2019-10393, CVE-2019-10394, CVE-2019-10399, CVE-2019-10400)</title>
      <link>https://insinuator.net/2019/09/jenkins-groovy-sandbox-breakout-security-1538-/-cve-2019-10393-cve-2019-10394-cve-2019-10399-cve-2019-10400/</link>
      <pubDate>Fri, 20 Sep 2019 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2019/09/jenkins-groovy-sandbox-breakout-security-1538-/-cve-2019-10393-cve-2019-10394-cve-2019-10399-cve-2019-10400/</guid>
      <description>&lt;p&gt;Recently, I discovered a sandbox breakout in the Groovy Sandbox used by the Jenkins script-security Plugin in their Pipeline Plugin for build scripts. We responsibly disclosed this vulnerability and in the current version of Jenkins it has been fixed and the according &lt;a href=&#34;https://jenkins.io/security/advisory/2019-09-12/&#34;&gt;Jenkins Security Advisory 2019-09-12&lt;/a&gt; has been published. In this blogpost I want to report a bit on the technical details of the vulnerability.&lt;/p&gt;&#xA;&lt;h1 id=&#34;description&#34;&gt;Description&lt;/h1&gt;&#xA;&lt;p&gt;The groovy sandbox transforms some AST nodes of the script to add security checks. For example&lt;/p&gt;</description>
    </item>
    <item>
      <title>How to break out of restricted shells with tcpdump</title>
      <link>https://insinuator.net/2019/07/how-to-break-out-of-restricted-shells-with-tcpdump/</link>
      <pubDate>Mon, 29 Jul 2019 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2019/07/how-to-break-out-of-restricted-shells-with-tcpdump/</guid>
      <description>&lt;p&gt;During security assessments we sometimes obtain access to a restricted shell on a target system. To advance further and gain complete control of the system, the next step is usually to break out of this shell. If the restricted shell provides access to certain system binaries, these binaries can often be exploited to perform such a break out. Here we would like to show an interesting example of such a break out by using the tcpdump binary.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Multiple Vulnerabilities in innovaphone VoIP Products Fixed</title>
      <link>https://insinuator.net/2019/07/multiple-vulnerabilities-in-innovaphone-voip-products-fixed/</link>
      <pubDate>Mon, 08 Jul 2019 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2019/07/multiple-vulnerabilities-in-innovaphone-voip-products-fixed/</guid>
      <description>&lt;p&gt;Dear all,&lt;/p&gt;&#xA;&lt;p&gt;&lt;a href=&#34;https://www.innovaphone.com/&#34;&gt;innovaphone&lt;/a&gt; fixed several vulnerabilities in two VoIP products that we disclosed a while ago. The affected products are the &lt;a href=&#34;https://wiki.innovaphone.com/index.php?title=Reference10:Concept_Linux_Application_Platform&#34;&gt;Linux Application Platform&lt;/a&gt; and the &lt;a href=&#34;https://www.innovaphone.com/de/ip-telefonie/innovaphone-pbx.html&#34;&gt;IPVA&lt;/a&gt;. Unfortunately, the release notes are not public (yet?) and the vendor does not include information about the vulnerabilities for the Linux Application Platform. Therefore, we decided to publish some more technical details for the issues.&lt;/p&gt;&#xA;&lt;h2 id=&#34;multiple-vulnerabilities-in-linux-application-platform&#34;&gt;Multiple Vulnerabilities in Linux Application Platform&lt;/h2&gt;&#xA;&lt;p&gt;The Linux Application Platform was affected by three vulnerabilities that could be chained to get full root access to a target system. However, the initial access vector is only exploitable by authenticated users. The vulnerabilities have been identified on the Linux Application Platform V10 SR41. According to the vendor they have been fixed in &lt;a href=&#34;http://wiki.innovaphone.com/index.php?title=Support:Linux_Application_Platform_100264_%28sr57%29_available&#34;&gt;V10 SR57&lt;/a&gt;.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Security Advisories for Cisco ACI</title>
      <link>https://insinuator.net/2019/07/security-advisories-for-cisco-aci/</link>
      <pubDate>Thu, 04 Jul 2019 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2019/07/security-advisories-for-cisco-aci/</guid>
      <description>&lt;p&gt;Again, Cisco released security advisories for their software-defined networking (SDN) solution called Application Centric Infrastructure (ACI). As before (see blog post &lt;a href=&#34;https://insinuator.net/2019/05/security-advisory-for-cisco-nexus-9000-series-fabric-switches-in-aci-mode/&#34;&gt;here&lt;/a&gt;), the published advisories originated from research performed in our ACI lab.&lt;/p&gt;&#xA;&lt;p&gt;The following advisories have been published:&lt;/p&gt;&#xA;&lt;p&gt;Cisco Nexus 9000 Series Fabric Switches ACI Mode Fabric Infrastructure VLAN Unauthorized Access Vulnerability&lt;br&gt;&#xA;&lt;a href=&#34;https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190703-n9kaci-bypass&#34;&gt;https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190703-n9kaci-bypass&lt;/a&gt;&lt;br&gt;&#xA;CVSS Base Score: 7.4&lt;/p&gt;&#xA;&lt;p&gt;Cisco Application Policy Infrastructure Controller REST API Privilege Escalation Vulnerability&lt;br&gt;&#xA;&lt;a href=&#34;https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190703-ccapic-restapi&#34;&gt;https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190703-ccapic-restapi&lt;/a&gt;&lt;br&gt;&#xA;CVSS Base Score: 7.2&lt;/p&gt;</description>
    </item>
    <item>
      <title>On the insecurity of math.random and it’s siblings</title>
      <link>https://insinuator.net/2018/11/on-the-insecurity-of-math.random-and-its-siblings/</link>
      <pubDate>Thu, 29 Nov 2018 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2018/11/on-the-insecurity-of-math.random-and-its-siblings/</guid>
      <description>&lt;p&gt;During code reviews we often see developers using weak RNGs like &lt;em&gt;math.random()&lt;/em&gt; to generate cryptographic secrets. We think it is commonly known that weak random number generators (RNG) must not be used for any kind of secret and recommend using secure alternatives. I explicitly did not state a specific language yet, because basically every language offers both weak and strong RNGs.&lt;/p&gt;&#xA;&lt;p&gt;So I asked myself: What if I use a weak RNG to generate a secret? Is it possible to recover the secret from some derived value, like a hash?&lt;/p&gt;</description>
    </item>
    <item>
      <title>Plume Twitter Client URL Spoofing</title>
      <link>https://insinuator.net/2018/11/plume-twitter-client-url-spoofing/</link>
      <pubDate>Fri, 23 Nov 2018 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2018/11/plume-twitter-client-url-spoofing/</guid>
      <description>&lt;p&gt;It is possible to spoof the URLs that Plume will open to arbitrary locations because of how Plume parses URLs. The preview of an URL in a tweet will show the complete (at least the host name and the first few chars of the URL) but shortened URL. However, if the URL contains a semicolon (;) the URL that will be opened is the part after the semicolon.&lt;/p&gt;&#xA;&lt;p&gt;An attacker can make use of this behavior by specifying a URL like the following in a Tweet or direct message:&lt;/p&gt;</description>
    </item>
    <item>
      <title>Pidgin, Word Documents, my Clipboard and I</title>
      <link>https://insinuator.net/2018/11/pidgin-word-documents-my-clipboard-and-i/</link>
      <pubDate>Mon, 19 Nov 2018 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2018/11/pidgin-word-documents-my-clipboard-and-i/</guid>
      <description>&lt;p&gt;Lately, I’ve experienced some weird &lt;a href=&#34;https://pidgin.im/&#34;&gt;Pidgin&lt;/a&gt; crashes when I was copy&amp;amp;pasting into chat windows. The strange part was: I didn’t even know what triggered the crash because I actually didn’t know what was in my clipboard at this exact point. This is a quick write-up of how I investigated the issue and some interesting properties I found out about clipboards.&lt;/p&gt;&#xA;&lt;p&gt;Everything started with a document that I was editing in a Windows VM in Microsoft Word. At some point, I wanted to copy some lines of the document and paste it into a Pidgin chat window on my Linux host system. As I did this, I noticed that when I pasted the data into the chat window it included a lot of white spaces. I thought something went wrong and just tried to delete it by pressing CTRL+A (to mark everything) and press BACKSPACE. But this caused Pidgin (2.13.0-5 on Arch Linux) to close with a segfault and created a core dump.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Dumping Decrypted Documents from a North Korean PDF Reader</title>
      <link>https://insinuator.net/2018/11/dumping-decrypted-documents-from-a-north-korean-pdf-reader/</link>
      <pubDate>Fri, 16 Nov 2018 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2018/11/dumping-decrypted-documents-from-a-north-korean-pdf-reader/</guid>
      <description>&lt;p&gt;This is a write-up about how to use &lt;a href=&#34;https://www.frida.re/&#34;&gt;Frida&lt;/a&gt; to dump documents from a process after they have been loaded and decrypted. It’s a generic and very effective approach demonstrated on a piece of software from North Korea.&lt;/p&gt;&#xA;&lt;p&gt;Some time ago we received an ISO file which was a dump of a CD-ROM from North Korea. The only information we got was that it included a document viewer and various PDF documents. I started to dump the content of the ISO in order to analyze what the reader was actually doing by mounting it:&lt;/p&gt;</description>
    </item>
    <item>
      <title>Multiple Vulnerabilities in Nexus Repository Manager</title>
      <link>https://insinuator.net/2018/11/multiple-vulnerabilities-in-nexus-repository-manager/</link>
      <pubDate>Wed, 14 Nov 2018 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2018/11/multiple-vulnerabilities-in-nexus-repository-manager/</guid>
      <description>&lt;p&gt;Recently, we identified security issues in the Nexus Repository Manager software developed by Sonatype. The tested versions were OSS 3.12.1-01 and OSS 3.13.1-01.&lt;/p&gt;&#xA;&lt;p&gt;The following issues could be identified:&lt;/p&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;Multiple Cross-Site Scripting (&lt;a href=&#34;https://support.sonatype.com/hc/en-us/articles/360010789893-CVE-2018-16619-Nexus-Repository-Manager-XSS-October-17-2018&#34;&gt;CVE-2018-16619&lt;/a&gt;)&lt;/li&gt;&#xA;&lt;li&gt;Missing Access Controls (&lt;a href=&#34;https://support.sonatype.com/hc/en-us/articles/360010789453-CVE-2018-16620-Nexus-Repository-Manager-Missing-Access-Controls-October-17-2018?_ga=2.232570207.1112299337.1542137786-592006867.1539786845&#34;&gt;CVE-2018-16620&lt;/a&gt;)&lt;/li&gt;&#xA;&lt;li&gt;Java Expression Language Injection (&lt;a href=&#34;https://support.sonatype.com/hc/en-us/articles/360010789153-CVE-2018-16621-Nexus-Repository-Manager-Java-Injection-October-17-2018?_ga=2.232570207.1112299337.1542137786-592006867.1539786845&#34;&gt;CVE-2018-16621&lt;/a&gt;)&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;p&gt; &lt;/p&gt;&#xA;&lt;p&gt;The vulnerabilities are fixed in version 3.14.0. See the &lt;a href=&#34;https://help.sonatype.com/repomanager3/release-notes/2018-release-notes#id-2018ReleaseNotes-RepositoryManager3.14.0&#34;&gt;release notes&lt;/a&gt; and &lt;a href=&#34;https://support.sonatype.com/hc/en-us/sections/203012668-Security-Advisories&#34;&gt;security advisories&lt;/a&gt;  for further information.&lt;/p&gt;&#xA;&lt;p&gt; &lt;/p&gt;&#xA;&lt;p&gt;We identified a Java Expression Language Injection in the role and user creation function. In order to exploit this issue, the attacker needs to be authenticated with high privileges, the standard anonymous user is not sufficient.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Multiple Vulnerabilities in UNIFY OpenScape Desk Phone CP600</title>
      <link>https://insinuator.net/2018/10/multiple-vulnerabilities-in-unify-openscape-desk-phone-cp600/</link>
      <pubDate>Fri, 12 Oct 2018 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2018/10/multiple-vulnerabilities-in-unify-openscape-desk-phone-cp600/</guid>
      <description>&lt;p&gt;We recently identified security issues in the UNIFY OpenScape Desk Phone CP600 HFA software. We disclosed the vulnerabilities to Unify, as a fix is now provided we want to give a brief overview of the vulnerability affecting the web interface.&lt;/p&gt;&#xA;&lt;p&gt; &lt;/p&gt;&#xA;&lt;p&gt;We were able to identify the following vulnerabilities in the Web interface of the telephone:&lt;/p&gt;&#xA;&lt;p&gt; &lt;/p&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;Command Injection in Picture Delete function of OpenScape Desk Phone Webportal&lt;/li&gt;&#xA;&lt;li&gt;Unauthenticated Arbitrary File Access in the OpenScape Desk Phone Webportal&lt;/li&gt;&#xA;&lt;li&gt;Memory Corruption in the OpenScape Desk Phone Webservice&lt;/li&gt;&#xA;&lt;li&gt;Missing Hardening of the OpenScape Desk Phone Webservice Binary&lt;/li&gt;&#xA;&lt;li&gt;Cross Site Request Forgery Missing in the OpenScape Desk Phone Webservice&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;p&gt; &lt;/p&gt;</description>
    </item>
    <item>
      <title>Vulnerabilities in Sitefinity WCMS – A Success Story of a Responsible Disclosure Process</title>
      <link>https://insinuator.net/2018/10/vulnerabilities-in-sitefinity-wcms-a-success-story-of-a-responsible-disclosure-process/</link>
      <pubDate>Mon, 08 Oct 2018 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2018/10/vulnerabilities-in-sitefinity-wcms-a-success-story-of-a-responsible-disclosure-process/</guid>
      <description>&lt;h1 id=&#34;preface&#34;&gt;Preface&lt;/h1&gt;&#xA;&lt;p&gt;For those who never heard of &lt;em&gt;Sitefinity&lt;/em&gt; before, it is an &lt;em&gt;ASP.NET&lt;/em&gt;-based Web Content Management System (&lt;em&gt;WCMS&lt;/em&gt;), which is used to deploy and manage applications as other &lt;em&gt;CMS&lt;/em&gt;‘s do. A bitter quick glance at &lt;em&gt;Sitefinity&lt;/em&gt; and its advantages can be found in this &lt;a href=&#34;https://www.progress.com/documentation/sitefinity-cms/sitefinity-overview&#34;&gt;overview.&lt;/a&gt;&lt;/p&gt;&#xA;&lt;p&gt;Delving into the core of this blog post, recently I had the opportunity to look at &lt;em&gt;Sitefinity WCMS&lt;/em&gt; in which I found two &lt;em&gt;reflected&lt;/em&gt; &lt;em&gt;Cross Site Scripting&lt;/em&gt; (&lt;em&gt;XSS&lt;/em&gt;) (&lt;em&gt;&lt;a href=&#34;https://www.cvedetails.com/cve/CVE-2018-17053/&#34; title=&#34;CVE-2018-17053 security vulnerability details&#34;&gt;CVE-2018-17053&lt;/a&gt; and &lt;a href=&#34;https://www.cvedetails.com/cve/CVE-2018-17056/&#34; title=&#34;CVE-2018-17056 security vulnerability details&#34;&gt;CVE-2018-17056&lt;/a&gt;&lt;/em&gt;), a* stored XSS* (&lt;em&gt;&lt;a href=&#34;https://www.cvedetails.com/cve/CVE-2018-17054/&#34; title=&#34;CVE-2018-17054 security vulnerability details&#34;&gt;CVE-2018-17054&lt;/a&gt;&lt;/em&gt;) and an arbitrary file upload (&lt;a href=&#34;https://www.cvedetails.com/cve/CVE-2018-17055/&#34; title=&#34;CVE-2018-17055 security vulnerability details&#34;&gt;&lt;em&gt;CVE-2018-17055&lt;/em&gt;&lt;/a&gt;) vulnerabilities.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Spraying arbitrary objects into the non-paged pool</title>
      <link>https://insinuator.net/2018/10/spraying-arbitrary-objects-into-the-non-paged-pool/</link>
      <pubDate>Wed, 03 Oct 2018 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2018/10/spraying-arbitrary-objects-into-the-non-paged-pool/</guid>
      <description>&lt;p&gt;Recently, I had some time to play around with HEVD [&lt;a href=&#34;https://github.com/hacksysteam/HackSysExtremeVulnerableDriver&#34;&gt;1&lt;/a&gt;], an extremly vulnerable Windows driver available for 32-bit and 64-bit systems.&lt;/p&gt;&#xA;&lt;p&gt;Since exploits for all vulnerabilities of the 32-bit variant are publically available, I was wondering why this is not the case for the 64-bit version, especially for the pool corruption and UAF vulnerabilities.&lt;/p&gt;&#xA;&lt;p&gt;After digging around a bit, it turned out that the reason is the following. HEVD uses a “special” sized object which is improperly handled such that a Use-After-Free vulnerability arises.&lt;/p&gt;</description>
    </item>
    <item>
      <title>A few notes on WordPress Security</title>
      <link>https://insinuator.net/2018/08/a-few-notes-on-wordpress-security/</link>
      <pubDate>Wed, 22 Aug 2018 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2018/08/a-few-notes-on-wordpress-security/</guid>
      <description>&lt;p&gt;Taking a look at the &lt;a href=&#34;https://cve.mitre.org/cgi-bin/cvekey.cgi?keyword=wordpress&#34;&gt;CVE List for WordPress&lt;/a&gt;, most vulnerabilities aren’t found within the WordPress core but inside of third-party plugins and themes.&lt;/p&gt;&#xA;&lt;p&gt;Today, let’s talk about WordPress.&lt;/p&gt;&#xA;&lt;p&gt;Performing a WordPress assessment might seem boring at first as core functionality [tested] and configuration does not allow for extensive security misconfigurations. Luckily, most instances use plugins and themes to add features not offered by the WordPress core.&lt;/p&gt;&#xA;&lt;p&gt;In this blog post I would like to discuss the findings and how I discovered them. Also, I will describe different vendor responsiveness reaching from not responding at all, to not understanding the issue to fast and professional responses kindly asking for a review of the updated code ready for deployment.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Security of Busch-Jaeger IP Gateway</title>
      <link>https://insinuator.net/2018/05/security-of-busch-jaeger-ip-gateway/</link>
      <pubDate>Wed, 16 May 2018 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2018/05/security-of-busch-jaeger-ip-gateway/</guid>
      <description>&lt;p&gt;IoT is everywhere right now and there are a lot of products out there. I have been looking at an IP Gateway lately and found some serious issues. The &lt;a href=&#34;https://www.busch-jaeger.de/en/products/systems/door-communication/abb-welcome-ip-gateway-app-and-myabb-livingspace/&#34;&gt;Busch-Welcome IP-Gateway from Busch-Jaeger&lt;/a&gt; is one of the devices that bridges the gap between sensors and actors in your smart home and the network/Internet. It enables the communication to a door control system that implements various smart home functions. The device itself is offering an HTTP service to configure it, which is protected by a username and password. Some folks even actually expose the device and its login to the Internet. I tried to configure one of these lately and stumbled upon some security issues that I would like to discuss in this blog post.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Reversing and Patching .NET Binaries with Embedded References</title>
      <link>https://insinuator.net/2018/04/reversing-and-patching-.net-binaries-with-embedded-references/</link>
      <pubDate>Mon, 30 Apr 2018 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2018/04/reversing-and-patching-.net-binaries-with-embedded-references/</guid>
      <description>&lt;p&gt;Lately I’ve been analyzing a .NET binary that was quite interesting. It was a portable binary that shipped without any third-party dependencies. I started looking at the .NET assembly with ILSpy and noticed that there was not that much code that ILSpy found and there were a lot of references to classes/methods that were neither in the classes identified by ILSpy nor were they part of the .NET framework.&lt;/p&gt;&#xA;&lt;p&gt;At some point I was going through everything that ILSpy displayed about the binary, including the resources which were looking very interesting:&lt;/p&gt;</description>
    </item>
    <item>
      <title>Yet Another Information Disclosure?</title>
      <link>https://insinuator.net/2018/04/yet-another-information-disclosure/</link>
      <pubDate>Tue, 24 Apr 2018 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2018/04/yet-another-information-disclosure/</guid>
      <description>&lt;p&gt;Hey there, for those of you that roll your eyes when writing the nth Information Disclosure Finding in a report, here is a short story of how such information helped compromising a system.&lt;/p&gt;&#xA;&lt;p&gt;In a recent penetration we found a hidden debug page which disclosed information about internal parameters. Along with database connection strings and key material there was a username and a user home parameter disclosed on said debug page.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Squirrelmail Full Disclosure – TROOPERS18</title>
      <link>https://insinuator.net/2018/03/squirrelmail-full-disclosure-troopers18/</link>
      <pubDate>Thu, 15 Mar 2018 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2018/03/squirrelmail-full-disclosure-troopers18/</guid>
      <description>&lt;p&gt;Birk an me basically fully disclosed a 0day in &lt;a href=&#34;http://squirrelmail.org/&#34;&gt;Squirrelmail&lt;/a&gt; yesterday. This is a short Q&amp;amp;A to answer the most common questions about the issue to calm you all down a little bit. 😉&lt;/p&gt;&#xA;&lt;p&gt;&lt;strong&gt;What is the punchline, what do I need to know?&lt;/strong&gt;&lt;/p&gt;&#xA;&lt;p&gt;An attacker able to exploit this vulnerability can extract files of the server the application is running on. This may include configuration files, log files and additionally all files that are readable for all users on the system. This issue is post-authentication. That means an attacker would need valid credentials for the application to log in or needs to exploit an additional vulnerability of which we are not aware of at this point of time.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Extracting data from an EMV (Chip-And-Pin) Card with NFC technology</title>
      <link>https://insinuator.net/2018/02/extracting-data-from-an-emv-chip-and-pin-card-with-nfc-technology/</link>
      <pubDate>Thu, 15 Feb 2018 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2018/02/extracting-data-from-an-emv-chip-and-pin-card-with-nfc-technology/</guid>
      <description>&lt;p&gt;&lt;em&gt;This is a guest blog post by Salvador Mendoza.&lt;/em&gt;&lt;/p&gt;&#xA;&lt;p&gt;During years, many different researches and attacks against digital and physical payment methods have been discussed. New security techniques and methodologies such as tokenization process attempts to reduce or prevent fraudulent transactions.&lt;/p&gt;&#xA;&lt;p&gt;Extracting or capturing data from a transaction have been studied in different ways, and some of the most common techniques are skimming, wireless skimming, &lt;a href=&#34;https://media.defcon.org/DEF%20CON%2025/DEF%20CON%2025%20presentations/DEFCON-25-Haoqi-Shan-and-Jian-Yuan-Man-in-the-NFC.pdf&#34;&gt;relay attacks&lt;/a&gt;, traffic sniffing or &lt;a href=&#34;https://www.cl.cam.ac.uk/research/security/banking/relay/&#34;&gt;modifying a PoS(Point of Sale)&lt;/a&gt; system. In our talk, “&lt;a href=&#34;https://www.troopers.de/troopers18/agenda/tr18-nfc-payments/&#34;&gt;NFC Payments: The Art of Relay &amp;amp; Replay Attacks&lt;/a&gt;” at &lt;a href=&#34;https://www.troopers.de/&#34;&gt;TROOPERS18&lt;/a&gt;, we will discuss a new technique and methodology that malicious individuals could implement to extract data.&lt;/p&gt;</description>
    </item>
    <item>
      <title>AndroTickler: Tickling Vulnerabilities out of Android Apps</title>
      <link>https://insinuator.net/2018/02/androtickler-tickling-vulnerabilities-out-of-android-apps/</link>
      <pubDate>Sat, 10 Feb 2018 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2018/02/androtickler-tickling-vulnerabilities-out-of-android-apps/</guid>
      <description>&lt;p&gt;If you attack someone, they will defend themselves, but if you tickle them, they will eventually crack open. This surprisingly applies to Android apps as well! Therefore, I created AndroTickler, not to test apps against certain attacks or examine them for specific vulnerabilities, which developers would learn to avoid. However, it helps pentesters to analyze and test apps in their own style, but in a faster, easier and more flexible way. AndroTickler is a Swiss-Army-Knife pentesting tool for Android apps. It provides information gathering, static and dynamic analysis features, and also automates actions that pentesters frequently do and highly need during their pentests. In addition, it makes use of the powerful Frida to hook to the app and manipulate it in real-time.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Hacking 101 to mobile data</title>
      <link>https://insinuator.net/2018/02/hacking-101-to-mobile-data/</link>
      <pubDate>Tue, 06 Feb 2018 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2018/02/hacking-101-to-mobile-data/</guid>
      <description>&lt;p&gt;Here is a short blog post that explains how you can make your own Man-in-the-Middle (MitM) setup for sniffing the traffic between a SIM card and the backend server. This is** NOT a new research** but I hope this will help anyone who doesn’t have a telco background to get started to play with mobile data sniffing and fake base stations. This is applicable to many scenarios today as we have so many IoT devices with SIM cards in it that connects to the backend.&lt;br&gt;&#xA;In this particular case, I am explaining the simplest scenario where the SIM card is working with 2G and GPRS. You can probably expect me with more articles with 3G, 4G MitM in future. But lets stick to 2G and GPRS for now.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Extract Non-Exportable Certificates and Evade Anti-Virus with Mimikatz and Powersploit</title>
      <link>https://insinuator.net/2017/10/extract-non-exportable-certificates-and-evade-anti-virus-with-mimikatz-and-powersploit/</link>
      <pubDate>Fri, 20 Oct 2017 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2017/10/extract-non-exportable-certificates-and-evade-anti-virus-with-mimikatz-and-powersploit/</guid>
      <description>&lt;p&gt;Some time ago, one of our customers contacted us with a special request. For some legitimate reason, they needed to centrally collect certain certificates including their private keys which were distributed across many client systems running Windows and stored in the corresponding user stores. Unfortunately (only in this case, but actually good from a security perspective), the particular private keys were marked non-exportable making a native export in the context of the user impossible. As if this wasn’t enough, the extraction was supposed to be executed in the context of the current user (i.e. without administrative privileges) while not triggering the existing Anti Virus solution at all. Also, the certificates needed to be transferred to some trusted system where they could not be accessed in an unauthorized way. So let’s have a look how we tackled these problems:&lt;/p&gt;</description>
    </item>
    <item>
      <title>Erlang distribution RCE and a cookie bruteforcer</title>
      <link>https://insinuator.net/2017/10/erlang-distribution-rce-and-a-cookie-bruteforcer/</link>
      <pubDate>Thu, 05 Oct 2017 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2017/10/erlang-distribution-rce-and-a-cookie-bruteforcer/</guid>
      <description>&lt;p&gt;In one of the last pentests we’ve found an &lt;em&gt;epmd&lt;/em&gt; (Erlang port mapper daemon) listening on a target system (tcp/4369). It is used to coordinate distributed erlang instances, but also can lead to a RCE, given one knows the so called “authentication cookie”. Usually, this cookie is located in ~/.erlang.cookie and is generated by erlang at the first start. If not modified or set manually it is a random string [A:Z] with a length of 20 characters. If an attacker gains this cookie, a RCE is quite easy – as I like to describe below.&lt;/p&gt;</description>
    </item>
    <item>
      <title>FireEye Security Bug: Connection to physical host and adjacent network possible during analysis in Live-Mode</title>
      <link>https://insinuator.net/2017/09/fireeye-security-bug-connection-to-physical-host-and-adjacent-network-possible-during-analysis-in-live-mode/</link>
      <pubDate>Wed, 13 Sep 2017 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2017/09/fireeye-security-bug-connection-to-physical-host-and-adjacent-network-possible-during-analysis-in-live-mode/</guid>
      <description>&lt;p&gt;We recently identified a security issue in FireEye AX 5400, that also affected other products. We responsibly disclosed the bug to FireEye and a fix that addresses the issue has been released with version 7.7.7. The fix was also merged into the common core and is available as 8.0.1 for other products (i.e. FireEye EX).&lt;/p&gt;&#xA;&lt;p&gt;The related release notes can be found here:&lt;/p&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://docs.fireeye.com/docs/docs_en/AX/sw/7.7.7/RN/AX_RN_7.7.7_en.pdf&#34;&gt;https://docs.fireeye.com/docs/docs_en/AX/sw/7.7.7/RN/AX_RN_7.7.7_en.pdf&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://docs.fireeye.com/docs/docs_en/EX/sw/8.0.1/RN/EX_RN_8.0.1_en.pdf&#34;&gt;https://docs.fireeye.com/docs/docs_en/EX/sw/8.0.1/RN/EX_RN_8.0.1_en.pdf&lt;/a&gt;&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;p&gt;FireEye announced to post a 2017 Q3 notice with credit to us, too.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Git Shell Bypass By Abusing Less (CVE-2017-8386)</title>
      <link>https://insinuator.net/2017/05/git-shell-bypass-by-abusing-less-cve-2017-8386/</link>
      <pubDate>Wed, 10 May 2017 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2017/05/git-shell-bypass-by-abusing-less-cve-2017-8386/</guid>
      <description>&lt;p&gt;The &lt;em&gt;git-shell&lt;/em&gt; is a restricted shell maintained by the git developers and is meant to be used as the upstream peer in a git remote session over a ssh tunnel. The basic idea behind this shell is to restrict the allowed commands in a ssh session to the ones required by git which are as follows:&lt;/p&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;&lt;em&gt;git-receive-pack&lt;/em&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;Receives repository updates from the client.&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;/li&gt;&#xA;&lt;li&gt;&lt;em&gt;git-upload-pack&lt;/em&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;Pushes repository updates to the client.&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;/li&gt;&#xA;&lt;li&gt;&lt;em&gt;git-upload-archive&lt;/em&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;Pushes a repository archive to the client.&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;p&gt;Besides those built-in commands, an administrator can also provide it’s own commands via shell scripts or other executable files. As those are typically completely custom, this post will concentrate on the built-in ones.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Autonomic Network Part 3: Vulnerabilities</title>
      <link>https://insinuator.net/2017/04/autonomic-network-part-3-vulnerabilities/</link>
      <pubDate>Thu, 13 Apr 2017 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2017/04/autonomic-network-part-3-vulnerabilities/</guid>
      <description>&lt;p&gt;This is the 3rd post in the series of Autonomic Network (AN), it will dedicated for discussing the vulnerabilities. I recommend reading the first 2 parts (&lt;a href=&#34;https://insinuator.net/2017/03/autonomic-network-overview/&#34;&gt;part one&lt;/a&gt;, &lt;a href=&#34;https://insinuator.net/2017/03/autonomic-network-analysis/&#34;&gt;part two&lt;/a&gt;) to be familiar with the technology and how the proprietary protocol is constructed.&lt;/p&gt;&#xA;&lt;p&gt;Initially we will discuss 2 of the reported CVEs, but later there is more CVEs to come 😉&lt;/p&gt;&#xA;&lt;p&gt;Here is a quick overview on how our network looks like for 2 CVEs&lt;/p&gt;</description>
    </item>
    <item>
      <title>Autonomic Networking – Part 2: Analysis</title>
      <link>https://insinuator.net/2017/03/autonomic-networking-part-2-analysis/</link>
      <pubDate>Mon, 20 Mar 2017 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2017/03/autonomic-networking-part-2-analysis/</guid>
      <description>&lt;p&gt;This is the second part in the Autonomic Network series. We have introduced previously in our &lt;a href=&#34;https://insinuator.net/2017/03/autonomic-network-overview/&#34;&gt;first part&lt;/a&gt; the Autonomic Network (AN), took a look about the needed configuration to run it on Cisco gear and what is the expected communication flow. In this post, we will dive deeper to have a closer look on the packets and how they are composed. Cisco’s AN protocol is a proprietary one and as far as I know, the analysis provided here for the protocol is the first of its kind.&lt;/p&gt;</description>
    </item>
    <item>
      <title>This is Why Your Wireless Mouse Should Have a Tail and Your Presenter is a Fail</title>
      <link>https://insinuator.net/2017/03/this-is-why-your-wireless-mouse-should-have-a-tail-and-your-presenter-is-a-fail/</link>
      <pubDate>Mon, 20 Mar 2017 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2017/03/this-is-why-your-wireless-mouse-should-have-a-tail-and-your-presenter-is-a-fail/</guid>
      <description>&lt;p&gt;Puh…it’s been a long time since my &lt;a href=&#34;https://insinuator.net/2016/11/itsecx-2016-pulling-an-all-nighter-in-austria/&#34;&gt;last post&lt;/a&gt;, huh?&lt;br&gt;&#xA;However, let’s get straight back to topic. Today, I want to issue a warning, especially in face of upcoming &lt;a href=&#34;https://www.troopers.de/troopers17/&#34;&gt;Troopers 2017&lt;/a&gt; (less than two days to go, wooo! 10th anniversary!): be careful when using wireless equipment (presenters, mouses, keyboards,…), especially during Troopers, but also in daily use.&lt;/p&gt;&#xA;&lt;p&gt;TL;DR Please take into account that you put your laptop at risk of being hacked by using wireless equipment during &lt;a href=&#34;https://www.troopers.de/&#34;&gt;Troopers&lt;/a&gt;. This could lead to a full system compromise. Wirelessly. Attacks like keystroke injection or sniffing of latter and mouse movements are possible. This, e.g. applies to speakers, using wireless presenters (like Logitech R400/R800, old and new models), as also to any attendee or crew member who might use wireless mouses or keyboards. Be aware of this!&lt;/p&gt;</description>
    </item>
    <item>
      <title>Autonomic Networking – Part 1: Overview</title>
      <link>https://insinuator.net/2017/03/autonomic-networking-part-1-overview/</link>
      <pubDate>Sun, 19 Mar 2017 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2017/03/autonomic-networking-part-1-overview/</guid>
      <description>&lt;p&gt;This is a 3-part series which introduces and analyzes Cisco’s implementation for Autonomic Network. In the 1st part, the technology is introduced and we have an overview about communication flow. In the &lt;a href=&#34;https://insinuator.net/2017/03/autonomic-network-analysis/&#34;&gt;2nd part&lt;/a&gt;, Cisco’s proprietary protocol is reverse engineered ? then finally in the &lt;a href=&#34;https://insinuator.net/2017/04/autonomic-network-vulnerabilities/&#34;&gt;3rd part&lt;/a&gt;, multiple vulnerabilities will be disclosed for the first time. If you’re aware of the technology, you can skip directly to part 2 where the action begins! &lt;/p&gt;</description>
    </item>
    <item>
      <title>Information About SAP Security Note 2336795</title>
      <link>https://insinuator.net/2017/03/information-about-sap-security-note-2336795/</link>
      <pubDate>Tue, 14 Mar 2017 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2017/03/information-about-sap-security-note-2336795/</guid>
      <description>&lt;p&gt;Last year I encountered a slight variation of an internal port scan vulnerability for the CrystalReports component of SAP Business Objects. The original vulnerability was presented and disclosed by rapid7 in the talk “Hacking SAP Business Objects”. The corresponding slides can be found &lt;a href=&#34;http://spl0it.org/files/talks/source_barcelona10/Hacking%20SAP%20BusinessObjects.pdf&#34;&gt;here&lt;/a&gt;.&lt;/p&gt;&#xA;&lt;p&gt;Basically, the original vulnerability allowed port scanning of (internal) systems via the URL http://hostname/CrystalReports/viewrpt.cwr?id=$ID&amp;amp;wid=$WID&amp;amp;apstoken=ip:port@$TOKEN. By accessing this URL, different responses were received depending on if the port (parameter port in the URL) of the system (parameter ip in the URL) was in the state “open” or “closed”. The original vulnerability has been fixed a long time ago (SAP security note 1432881), but the fix did allow for a slight variation to make the attack work again.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Cisco: Magic WebEx URL Allows Arbitrary Remote Command Execution – Project Zero</title>
      <link>https://insinuator.net/2017/01/cisco-magic-webex-url-allows-arbitrary-remote-command-execution-project-zero/</link>
      <pubDate>Tue, 24 Jan 2017 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2017/01/cisco-magic-webex-url-allows-arbitrary-remote-command-execution-project-zero/</guid>
      <description>&lt;p&gt;Tavis did it again[1]. As stated in the title it is possible to remotely execute commands via the Chrome extension for the popular meeting software Cisco WebEx. This post summarizes the most relevant information for you.&lt;/p&gt;&#xA;&lt;p&gt;A test page with working &lt;a href=&#34;https://bugs.chromium.org/p/project-zero/issues/attachmentText?aid=267784&#34;&gt;demo code&lt;/a&gt; is available to check for the issue on Windows systems [2]. From our point of view the Chrome extension is affected by this issue as well as the Firefox extension as both extension APIs are quite similar. However, Mozilla blocked the FireFox plugin to protect users from the risk of being exploited through the plugin[3][4]. IE seems to be fine thanks to Cisco’s decision to invoke the WebEx Meeting Center via e.g. ActiveX.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Insomni’hack pwn50 write-up</title>
      <link>https://insinuator.net/2017/01/insomnihack-pwn50-write-up/</link>
      <pubDate>Tue, 24 Jan 2017 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2017/01/insomnihack-pwn50-write-up/</guid>
      <description>&lt;p&gt;Hi all,&lt;/p&gt;&#xA;&lt;p&gt;i´ve looked a bit at the &lt;a href=&#34;https://insomnihack.ch/?page_id=16&#34;&gt;Insomni’hack CTF&lt;/a&gt; which took place on the 21st January and lasted for 36 hours.&lt;br&gt;&#xA;For the sake of warming up a bit for our Troopers workshop &lt;a href=&#34;https://www.troopers.de/events/troopers17/728_windows_and_linux_exploitation/&#34;&gt;Windows and Linux Exploitation&lt;/a&gt;,&lt;br&gt;&#xA;I decided to create a write-up of the first pwn50 challenge.&lt;/p&gt;&#xA;&lt;p&gt;To grab your own copy of the presented files you can also find it in our &lt;a href=&#34;https://github.com/ernw/insinuator-snippets/tree/master/Insomnihack&#34;&gt;Github&lt;/a&gt; repository:&lt;/p&gt;&#xA;&lt;p&gt;When downloading the first binary, we are presented with 2 files:&lt;/p&gt;</description>
    </item>
    <item>
      <title>A short Addendum on the Mirai Botnet Blog Post</title>
      <link>https://insinuator.net/2016/12/a-short-addendum-on-the-mirai-botnet-blog-post/</link>
      <pubDate>Thu, 08 Dec 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/12/a-short-addendum-on-the-mirai-botnet-blog-post/</guid>
      <description>&lt;p&gt;While doing heap research on Linux processes (results are going to be published soon), I came across the bot from the Mirai Botnet. As already mentioned in the blog post by &lt;a href=&#34;https://insinuator.net/2016/10/a-quick-insight-into-the-mirai-botnet/&#34;&gt;Brian&lt;/a&gt;, the Mirai bot uses obfuscated configuration data which contains e.g. the CnC server. When now confronted only with a bot (e.g. in the context of a running task or the ELF binary), but without the according source code, the decryption of this configuration data for e.g. incident analysis purposes might not be easily possible (with the python script from the blog post), if the key has been changed.&lt;br&gt;&#xA;But in this case that is not a problem at all, because&lt;/p&gt;</description>
    </item>
    <item>
      <title>Analyzing yet another Smart Home device</title>
      <link>https://insinuator.net/2016/12/analyzing-yet-another-smart-home-device/</link>
      <pubDate>Mon, 05 Dec 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/12/analyzing-yet-another-smart-home-device/</guid>
      <description>&lt;p&gt;As you have probably already recognized, some of us here at ERNW are doing research in the area of smart home technologies e.g. KNX. Recently, we took a deeper look into a device which is used to control a smart home system produced by the vendor BAB TECHNOLOGIE GmbH called “eibPort”. This device can be used to control smart home systems based on different technologies e.g. EnoCean or KNX depending on the version of the device. The eibPort comes with a visualization running on a webserver to control the whole system e.g. open or close windows, changing the temperature in different rooms or turning the alarm system on or off by simply clicking on symbols. The following screenshots illustrate an example of such a visualization:&lt;/p&gt;</description>
    </item>
    <item>
      <title>Research Diary: Blue Coat</title>
      <link>https://insinuator.net/2016/12/research-diary-blue-coat/</link>
      <pubDate>Mon, 05 Dec 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/12/research-diary-blue-coat/</guid>
      <description>&lt;p&gt;As a part of our research time here at ERNW, last week we had an interesting time looking at one of the widespread and commonly adopted proxy appliance by many organizations Blue Coat Secure Gateway.&lt;/p&gt;&#xA;&lt;h1 id=&#34;introduction&#34;&gt;Introduction&lt;/h1&gt;&#xA;&lt;p&gt;The Blue Coat proxy Secure Gateway (SG) has been already in the market since 2001 [1]. The main aim of introducing the appliance was to achieve the following goals [2]:&lt;br&gt;&#xA;• High performance optimization.&lt;br&gt;&#xA;• Increasing the security measurements, by introducing malware/spyware protections, web based filtering, virus scanning and more.&lt;br&gt;&#xA;• Flexible Access Control capabilities.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Some Notes from the Lab – BlackNurse in the IPv6 Era</title>
      <link>https://insinuator.net/2016/12/some-notes-from-the-lab-blacknurse-in-the-ipv6-era/</link>
      <pubDate>Mon, 05 Dec 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/12/some-notes-from-the-lab-blacknurse-in-the-ipv6-era/</guid>
      <description>&lt;p&gt;Since BlackNurse was released on 10th of November, we asked ourselves whether this problem does also apply to ICMPv6 traffic. To answer this question, Christian Tanck (one of our students) build a lab with several firewall appliances. Kudos to him for testing and the following blog post.&lt;/p&gt;&#xA;&lt;h3 id=&#34;intro&#34;&gt;Intro&lt;/h3&gt;&#xA;&lt;p&gt;&lt;img src=&#34;bl1.png&#34; alt=&#34;bl1&#34;&gt;&lt;/p&gt;&#xA;&lt;p&gt; &lt;/p&gt;&#xA;&lt;p&gt;On 10^(th) of November, 2016 the &lt;a href=&#34;https://www.trusted-introducer.org/directory/teams/tdc-soc.html&#34;&gt;TDC Security Operations Center in Denmark&lt;/a&gt; published the BlackNurse Denial of Service Attack Report as an &lt;a href=&#34;http://soc.tdc.dk/blacknurse/blacknurse.pdf&#34;&gt;PDF download&lt;/a&gt; on their website and a &lt;a href=&#34;http://www.netresec.com/?page=Blog&amp;amp;month=2016-11&amp;amp;post=BlackNurse-Denial-of-Service-Attack&#34;&gt;blog post&lt;/a&gt; written by Erik Hjelmvik from NETRESEC. He was involved in the project by helping with the analysis of packet dumps, testing different systems, with ideas for test scenarios and at least inspired me with his blog post on how to build a test lab described later in this post. The attack on its own was discovered by the TDC analysts Kenneth B. Jørgensen and Lenny Hansson.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Research Diary: IP-Cameras Part 2</title>
      <link>https://insinuator.net/2016/11/research-diary-ip-cameras-part-2/</link>
      <pubDate>Wed, 30 Nov 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/11/research-diary-ip-cameras-part-2/</guid>
      <description>&lt;p&gt;Hi everybody,&lt;br&gt;&#xA;This is the second entry in our research diary on IP cameras. If you haven’t done so yet, you should read the first entry in advance. This time we focused more on analysis and exploitation.&lt;/p&gt;&#xA;&lt;h2 id=&#34;another-entry-vector&#34;&gt;&lt;a href=&#34;#another-entry-vector&#34;&gt;&lt;/a&gt;Another entry vector&lt;/h2&gt;&#xA;&lt;p&gt;After running a vulnerability scan on both devices, it was revealed that the M1033 has multiple buffer overflow vulnerabilities (CVE-2012-5958 to CVE-2012-5965), which are readily exploitable via Metasploit. This gave us another shell (in addition to the root shell mentioned in the last post), though this time it was not a root shell. By using the &lt;em&gt;find&lt;/em&gt; command, we searched for executables having the &lt;em&gt;setuid&lt;/em&gt; or &lt;em&gt;setgid&lt;/em&gt; bit set. We hoped to use one of those to escalate privileges. To do so yourself add the parameter &lt;em&gt;-perm -4000&lt;/em&gt; to &lt;em&gt;find&lt;/em&gt; and it will search for files having the setuid bit set. If you try that on your own unix-like device, for example it should yield &lt;em&gt;/bin/passwd&lt;/em&gt; which is perfectly reasonable as you’re able to change your password without being root.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Research Diary: IP-Cameras</title>
      <link>https://insinuator.net/2016/11/research-diary-ip-cameras/</link>
      <pubDate>Tue, 22 Nov 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/11/research-diary-ip-cameras/</guid>
      <description>&lt;p&gt;As you probably know we perform research on a regular basis at ERNW. This post is the first entry on our – Benjamin’s and Pascal’s – research diary. You might already have seen &lt;a href=&#34;https://insinuator.net/2016/10/setting-up-a-research-environment-for-ip-cameras/&#34;&gt;Oliver’s post on setting up an research environment&lt;/a&gt; or Brian’s posts on IoT botnets (&lt;a href=&#34;https://insinuator.net/2016/10/how-to-become-part-of-an-iot-botnet/&#34;&gt;here&lt;/a&gt; and &lt;a href=&#34;https://insinuator.net/2016/10/a-quick-insight-into-the-mirai-botnet/&#34;&gt;here&lt;/a&gt;). With that in mind we want to take a look at one of the market leaders for network camera equipment: AXIS.&lt;/p&gt;&#xA;&lt;p&gt;At first we’d like to give a quick overview of our research objects. We bought two cameras, an AXIS M1033-W and an AXIS M3005-V. The M1033’s description states that it is for “small business, hotels, residences and more”. The M3005 has a typical dome design and was actually seen in some customer environments during projects this year.&lt;/p&gt;</description>
    </item>
    <item>
      <title>IoT the S is for Secure – Unknown Administration Interface in Wireless Plug</title>
      <link>https://insinuator.net/2016/11/iot-the-s-is-for-secure-unknown-administration-interface-in-wireless-plug/</link>
      <pubDate>Mon, 21 Nov 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/11/iot-the-s-is-for-secure-unknown-administration-interface-in-wireless-plug/</guid>
      <description>&lt;p&gt;Dear Readers,&lt;/p&gt;&#xA;&lt;p&gt;just recently i bought a wireless plug on &lt;a href=&#34;https://www.amazon.de/gp/product/B01LXASIZG/ref=oh_aui_detailpage_o01_s00?ie=UTF8&amp;amp;psc=1&#34;&gt;Amazon&lt;/a&gt; with the main use of controlling my coffee machine with an app. The installation of the wireless plug was quite easy and only requires me to set my Wifi SSID and my passphrase – that’s it. But what happened behind the scenes? I visited the control interface of my router and saw that along with the other devices there was a new one with the network name HF-LPB100 and a local IP address in my case 192.168.0.235. First of all i wondered about the name itself, but ignored that and kept on looking for open ports.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Reverse Engineering With Radare2 – Part 3</title>
      <link>https://insinuator.net/2016/10/reverse-engineering-with-radare2-part-3/</link>
      <pubDate>Mon, 24 Oct 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/10/reverse-engineering-with-radare2-part-3/</guid>
      <description>&lt;p&gt;Sorry about the larger delay between the previous post and this one, but I was very busy the last weeks.&lt;br&gt;&#xA;(And the technology I wanted to show wasn’t completely implemented in radare2, which means that I had to implement it on my own 😉 ). In case you’re new to this series, you’ll find the previous posts &lt;a href=&#34;https://insinuator.net/tag/radare2/&#34;&gt;here&lt;/a&gt;.&lt;/p&gt;&#xA;&lt;p&gt;As you may already know, we’ll deal with the third challenge today. The purpose for this one is to introduce&lt;br&gt;&#xA;some constructs which are often used in real programs.&lt;/p&gt;</description>
    </item>
    <item>
      <title>A Quick Insight Into the Mirai Botnet</title>
      <link>https://insinuator.net/2016/10/a-quick-insight-into-the-mirai-botnet/</link>
      <pubDate>Thu, 20 Oct 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/10/a-quick-insight-into-the-mirai-botnet/</guid>
      <description>&lt;p&gt;As you might have read, &lt;a href=&#34;https://insinuator.net/2016/10/how-to-become-part-of-an-iot-botnet/&#34;&gt;I recently had a closer look at how easy it actually is to become part of an IoT Botnet&lt;/a&gt;. To start a further discussion and share some of my findings I gave a quick overview at the recent &lt;a href=&#34;http://day-con.org/&#34;&gt;Dayton Security Summit&lt;/a&gt;. The Mirai Botnet was supposed to be one of the case studies here. But the way things go if one starts diving into code…I eventually gave an overview of how the Mirai Bot actually works and what it does. As such: Here a quick summary of the Mirai Botnet bot.&lt;br&gt;&#xA;As described in my previous post, &lt;a href=&#34;https://krebsonsecurity.com/2016/09/krebsonsecurity-hit-with-record-ddos/&#34;&gt;KrebsonSecurity.com was attacked by a major DDoS attack&lt;/a&gt;. Reaching between 620Gbps and 660Gbps it was the largest documented DDoS attack so far. The attack seemingly resulted from a Botnet called Mirai. Shortly after the attack, a &lt;a href=&#34;https://krebsonsecurity.com/2016/10/source-code-for-iot-botnet-mirai-released/&#34;&gt;post on hackforums&lt;/a&gt; claimed to contain the actual source code of just this botnet.&lt;br&gt;&#xA;The &lt;a href=&#34;https://github.com/jgamblin/Mirai-Source-Code&#34;&gt;source code&lt;/a&gt; consists of three projects: The bot itself with its CnC server and a loader component.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Linq Injection – From Attacking Filters to Code Execution</title>
      <link>https://insinuator.net/2016/10/linq-injection-from-attacking-filters-to-code-execution/</link>
      <pubDate>Mon, 17 Oct 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/10/linq-injection-from-attacking-filters-to-code-execution/</guid>
      <description>&lt;p&gt;Some of you (especially the .Net guys) might have heard of the query language Linq (&lt;em&gt;Language Integrated Query&lt;/em&gt;) used by Microsoft .Net applications and web sites. It’s used to access data from various sources like databases, files and internal lists. It can internally transform the accessed data in application objects and provides filter mechanisms similar to SQL. As it is used directly inside the application source code, it will be processed at compile time and not interpreted at runtime. While this provides a great type safety and almost no attack surface for injection attacks (except from possible handling problems in the different backends), it is extremely difficult to implement a dynamic filter system (e.g. for datatables which should allow users to select the column to filter on). That’s probably the reason why Scott Guthrie (Executive Vice President of the Cloud and Enterprise group in Microsoft, also one of the founders of the .Net project) &lt;a href=&#34;https://weblogs.asp.net/scottgu/dynamic-linq-part-1-using-the-linq-dynamic-query-library&#34;&gt;presented&lt;/a&gt; the System.Linq.Dynamic package as part of the VS-2008 samples in 2008. This library allows to build Linq queries at runtime and therefore simplify dynamic filters. But as you may know, dynamic interpretation of languages based on user input is most of the time not the best option….&lt;/p&gt;</description>
    </item>
    <item>
      <title>Setting up a Research Environment for IP Cameras</title>
      <link>https://insinuator.net/2016/10/setting-up-a-research-environment-for-ip-cameras/</link>
      <pubDate>Mon, 17 Oct 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/10/setting-up-a-research-environment-for-ip-cameras/</guid>
      <description>&lt;p&gt;Embedded devices often serve as an entry point for an attack on a private or corporate network. The infamous attack on HackingTeam, for example, followed exactly this path as was revealed &lt;a href=&#34;http://pastebin.com/raw/0SNSvyjJ&#34;&gt;here&lt;/a&gt;. Although the attack may have been for the greater good (refer also to this great &lt;a href=&#34;https://www.troopers.de/events/troopers16/635_opening_keynote/&#34;&gt;keynote&lt;/a&gt;), such incidents demonstrate that it is important to properly secure your embedded devices. In a recent &lt;a href=&#34;https://www.insinuator.net/2016/04/discover-the-unknown-analyzing-an-iot-device/&#34;&gt;blog post&lt;/a&gt;, Niklaus presented how he analyzed the security posture of a MAX! Cube LAN Gateway. Moreover, Brian reported a few weeks ago on the &lt;a href=&#34;https://insinuator.net/2016/10/how-to-become-part-of-an-iot-botnet/&#34;&gt;security posture of IoT devices&lt;/a&gt; (and in particular on one of his cameras). With this post I would like to share my experiences with analyzing another embedded device: the &lt;a href=&#34;http://www.edimax.com/edimax/merchandise/merchandise_detail/data/edimax/au/home_network_cameras_indoor_fixed/ic-3116w/&#34;&gt;IC-3116W&lt;/a&gt; IP camera by Edimax. &lt;/p&gt;</description>
    </item>
    <item>
      <title>DameWare Vulnerability</title>
      <link>https://insinuator.net/2016/10/dameware-vulnerability/</link>
      <pubDate>Wed, 05 Oct 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/10/dameware-vulnerability/</guid>
      <description>&lt;p&gt;In course of a recent research project, I had a look at SolarWinds DameWare, which is a commercial Remote Access Software product running on Windows Server. I identified a remote file download vulnerability in the download function for the client software that can be exploited remotely and unauthenticated and that allows to download arbitrary files from the server that is running the software.&lt;/p&gt;&#xA;&lt;p&gt;A very simple proof of concept HTTP request to download the C:\Windows\win.ini file of the target machine is the following:&lt;/p&gt;</description>
    </item>
    <item>
      <title>How to Become Part of an IoT Botnet</title>
      <link>https://insinuator.net/2016/10/how-to-become-part-of-an-iot-botnet/</link>
      <pubDate>Sat, 01 Oct 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/10/how-to-become-part-of-an-iot-botnet/</guid>
      <description>&lt;p&gt;I suppose there are many people out there who want to achieve a greater good, fight evil corp and “show those guys”. So why not set a statement and become part of a botnet? #Irony!!! Of course I suppose (hope) that none of you actually want to be part of something like an IoT botnet, but joining could in theory be dead easy. So quite a while back I bought a dead cheap WiFi camera for use at home. It was kind of just as insecure as I had expected, so it got it’s own VLAN and stuff and here is why….&lt;/p&gt;</description>
    </item>
    <item>
      <title>Attacking BaseStations @Defcon24</title>
      <link>https://insinuator.net/2016/09/attacking-basestations-@defcon24/</link>
      <pubDate>Tue, 20 Sep 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/09/attacking-basestations-@defcon24/</guid>
      <description>&lt;p&gt;Hello Guys,&lt;br&gt;&#xA;back from my vacation I’d like to give you some impressions about Defcon 24 and our talk “Attacking BaseStations”. Defcon itself had a couple of great talks but was a very crowded location. Anyhow, we had a couple of great discussions with the people before and after our talk.&lt;/p&gt;&#xA;&lt;p&gt;The talk “Attacking BaseStations” focussed on attack vectors we simulated in &lt;a href=&#34;https://www.insinuator.net/2015/05/how-to-get-as-basestation/&#34;&gt;our lab&lt;/a&gt;. Besides attacking a BaseStation via Radio interface, in this talk we focussed on local and remote interfaces as introduced in &lt;a href=&#34;https://www.insinuator.net/2014/10/lte-vs-darwin-hackers-to-hackers-conference-11/&#34;&gt;“LTE vs. Darwin”&lt;/a&gt;. As target of evaluation one of our eNodeB’s came into play, which we purchased on the Internet. Anyhow, the talk covered the following attack scenarios:&lt;/p&gt;</description>
    </item>
    <item>
      <title>Hardware Hacking Week @ ERNW</title>
      <link>https://insinuator.net/2016/09/hardware-hacking-week-@-ernw/</link>
      <pubDate>Fri, 09 Sep 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/09/hardware-hacking-week-@-ernw/</guid>
      <description>&lt;p&gt;Internal workshops are one of the reoccurring events at ERNW, that help us to gain knowledge in areas outside our usual expertise. One of the recent workshops which happened during the week from August 22nd-25th was Hardware Hacking. Held by Brian Butterly (&lt;a href=&#34;https://twitter.com/BadgeWizard&#34;&gt;@BadgeWizard&lt;/a&gt;) and Dominic Spill &lt;a href=&#34;http://@dominicgs&#34;&gt;(@dominicgs),&lt;/a&gt; this workshop took place in two parts. Brian kickstarted the introductory session by guiding us through the fundamental steps of Hardware Hacking. Brian did an excellent job of making things simpler by giving a detailed explanation on the basic concepts. For a beginner in hardware hacking, the topic could be rather intimidating if not handled properly.&lt;/p&gt;</description>
    </item>
    <item>
      <title>KNXmap: A KNXnet/IP Scanning and Auditing Tool</title>
      <link>https://insinuator.net/2016/09/knxmap-a-knxnet/ip-scanning-and-auditing-tool/</link>
      <pubDate>Mon, 05 Sep 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/09/knxmap-a-knxnet/ip-scanning-and-auditing-tool/</guid>
      <description>&lt;p&gt;Users of the &lt;a href=&#34;https://en.wikipedia.org/wiki/KNX_(standard)&#34;&gt;KNX&lt;/a&gt;, a standard for home automation bus systems, may already have come across KNXnet/IP (also known as EIBnet/IP): It is an extension for KNX that defines Ethernet as a communication medium for KNX which allows communication with KNX buses over IP driven networks. Additionally, it enables one to couple multiple bus installations over IP gateways, or so called KNXnet/IP gateways.&lt;/p&gt;&#xA;&lt;p&gt;In the course of some KNX related research we’ve had access to various KNXnet/IP gateways from different vendors, most of them coupled in a lab setup for testing purposes. The typical tools used for such tasks are &lt;a href=&#34;https://knx.org/knx-de/software/ets/herunterladen/index.php&#34;&gt;ETS&lt;/a&gt;, the professional software developed by the creators of KNX (proprietary, test licenses available) and &lt;a href=&#34;https://www.auto.tuwien.ac.at/~mkoegler/index.php/eibd&#34;&gt;eibd&lt;/a&gt;, an open source implementation of the KNX standard developed by the TU Vienna.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Reverse Engineering With Radare2 – Part 2</title>
      <link>https://insinuator.net/2016/08/reverse-engineering-with-radare2-part-2/</link>
      <pubDate>Mon, 29 Aug 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/08/reverse-engineering-with-radare2-part-2/</guid>
      <description>&lt;p&gt;Welcome back to the radare2 reversing tutorials. If you’ve missed the previous parts, you can find them &lt;a href=&#34;https://www.insinuator.net/?p=6233&#34;&gt;here&lt;/a&gt; and &lt;a href=&#34;https://www.insinuator.net/2016/08/reverse-engineering-with-radare2-part-1/&#34;&gt;here&lt;/a&gt;.&lt;/p&gt;&#xA;&lt;p&gt;Last time we’ve used the rabin2 application to view the  strings found inside the challenge01 binary to find password candidates. Based on the results we looked into the assembly to find the correct password. In this post, we’ll go through the next challenge and try out some of the features provided by radare2.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Follow-Up on CVE-2016-1409 – IPv6 NDP DoS Vulnerability</title>
      <link>https://insinuator.net/2016/08/follow-up-on-cve-2016-1409-ipv6-ndp-dos-vulnerability/</link>
      <pubDate>Sun, 21 Aug 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/08/follow-up-on-cve-2016-1409-ipv6-ndp-dos-vulnerability/</guid>
      <description>&lt;p&gt;This is a guest post from &lt;a href=&#34;https://twitter.com/kafetzj&#34;&gt;Jed Kafetz&lt;/a&gt;.&lt;/p&gt;&#xA;&lt;p&gt;After seeing &lt;a href=&#34;https://www.insinuator.net/2016/05/cve-2016-1409-ipv6-ndp-dos-vulnerability-in-cisco-software/&#34;&gt;Christopher’s post&lt;/a&gt; I decided to create a proof using GNS3 and Virtualbox.&lt;br&gt;&#xA;The aim is to perform the exact attacking using Antonios Atlasis’ &lt;a href=&#34;http://www.secfu.net/tools-scripts/&#34;&gt;Chiron tools&lt;/a&gt; and run a Wireshark packet capture to prove the hop limit drops below 255.&lt;/p&gt;&#xA;&lt;p&gt;The following topology is used in GNS3:&lt;/p&gt;&#xA;&lt;p&gt;&lt;img src=&#34;https://www.insinuator.net/wp-content/uploads/2016/08/nw_diagram.png&#34; alt=&#34;nw_diagram&#34;&gt;The routers used are Cisco C372 and the machine labled Ubuntu is running 14.04 LTS Ubuntu Desktop, default installation. F0/0 is on the right and F0/1 is on the left.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Reverse Engineering With Radare2 – Part 1</title>
      <link>https://insinuator.net/2016/08/reverse-engineering-with-radare2-part-1/</link>
      <pubDate>Fri, 19 Aug 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/08/reverse-engineering-with-radare2-part-1/</guid>
      <description>&lt;p&gt;Welcome back to the radare2 reversing tutorials. If you’ve missed the intro, you can find it &lt;a href=&#34;https://www.insinuator.net/?p=6233&#34;&gt;here&lt;/a&gt;.&lt;/p&gt;&#xA;&lt;p&gt;The last time you got the challenge01 binary and your goal was to find the password for the login. Let’s see how the application looks like:&lt;/p&gt;&#xA;&lt;pre tabindex=&#34;0&#34;&gt;&lt;code&gt;$ ./challenge01&#xA;##################################&#xA;#          Challenge 1           #&#xA;#                                #&#xA;#      (c) 2016 Timo Schmid      #&#xA;##################################&#xA;Enter Password: test&#xA;Wrong!&lt;/code&gt;&lt;/pre&gt;&#xA;&lt;p&gt;The first and simplest step would be to look for strings inside the binary. We could do this either by using the unix utility &lt;em&gt;strings&lt;/em&gt; or the binary analyzing binary from radare &lt;em&gt;rabin2:&lt;/em&gt;&lt;/p&gt;</description>
    </item>
    <item>
      <title>PFX Profiles in Microsoft’s System Management Server</title>
      <link>https://insinuator.net/2016/08/pfx-profiles-in-microsofts-system-management-server/</link>
      <pubDate>Fri, 05 Aug 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/08/pfx-profiles-in-microsofts-system-management-server/</guid>
      <description>&lt;p&gt;In a recent assessment, we had to evaluate how Microsoft’s System Management Server (SMS) certificate management solution (CMS) stores and handles certificates. This question came up because sensitive, encrypted user certificates were to be stored in the SMS CMS. Due to the sensitivity of the handled certificates, we assessed the protection capabilities of the certificate management solution against extraction attempts from a local attacker with administrative privileges.&lt;/p&gt;&#xA;&lt;h2 id=&#34;how-did-we-do-it&#34;&gt;How did we do it?&lt;/h2&gt;&#xA;&lt;p&gt;We determined a five steps approach to gain access to the certificates and be able to decrypt the accessed certificate material:&lt;/p&gt;</description>
    </item>
    <item>
      <title>Reverse Engineering With Radare2 – Intro</title>
      <link>https://insinuator.net/2016/08/reverse-engineering-with-radare2-intro/</link>
      <pubDate>Wed, 03 Aug 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/08/reverse-engineering-with-radare2-intro/</guid>
      <description>&lt;p&gt;As some of you may know, there is a “new” reverse engineering toolkit out there which tries to compete with IDA Pro in terms of reverse engineering. I’m talking about &lt;a href=&#34;http://radare.org/r/index.html&#34;&gt;radare2&lt;/a&gt;, a framework for reversing, patching, debugging and exploiting.&lt;/p&gt;&#xA;&lt;p&gt;It has large scripting capabilities, runs on all major plattforms (Android, GNU/Linux, [Net|Free|Open]BSD, iOS, OSX, QNX, w32, w64, Solaris, Haiku, FirefoxOS and even on your pebble smartwatch 😉 ) and is free.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Pentesting Webservices with Net.TCP Binding</title>
      <link>https://insinuator.net/2016/08/pentesting-webservices-with-net.tcp-binding/</link>
      <pubDate>Mon, 01 Aug 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/08/pentesting-webservices-with-net.tcp-binding/</guid>
      <description>&lt;p&gt;Hi all,&lt;/p&gt;&#xA;&lt;p&gt;Most of you that are  pentesters  may have already tested plenty of webservices using SOAP (&lt;em&gt;Simple Object Access Protocol&lt;/em&gt;)* *for communication. Typically, such SOAP messages are transferred over HTTP (&lt;em&gt;Hypertext Transfer Protocol&lt;/em&gt;) and are encapsulated in XML (&lt;em&gt;Extensible Markup Language&lt;/em&gt;). Microsoft has developed different representations of this protocols to reduce the network load. As these representations/protocols aren’t really covered by typical tools out there, this post will show you some of them, and a proxy which can be used to simplify the testing.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Remote Code Execution via Server Side Template Injection at OFBiz 13.07.03 (CVE-2016-4462)</title>
      <link>https://insinuator.net/2016/07/remote-code-execution-via-server-side-template-injection-at-ofbiz-13.07.03-cve-2016-4462/</link>
      <pubDate>Fri, 29 Jul 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/07/remote-code-execution-via-server-side-template-injection-at-ofbiz-13.07.03-cve-2016-4462/</guid>
      <description>&lt;p&gt;Dear Reader,&lt;/p&gt;&#xA;&lt;p&gt;this blog post is about Server Side Template Injections for the Apache Freemarker Template Engine, how to detect them, how to craft an exploit and what countermeasures can be implemented. Server Side Template Injections are critical because they often allow even Remote Code Execution, like the exploit of Apache OFBiz 13.07.03 that triggered this post in the first place. It is fair to note, that the exploit of Apache OFBiz requires a valid session with the server, but often this is just an inconvenience for an attacker.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Your Mouse Got Sick and You Don’t Know it. aka “Reverse Shell via Mouse”</title>
      <link>https://insinuator.net/2016/07/your-mouse-got-sick-and-you-dont-know-it.-aka-reverse-shell-via-mouse/</link>
      <pubDate>Fri, 29 Jul 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/07/your-mouse-got-sick-and-you-dont-know-it.-aka-reverse-shell-via-mouse/</guid>
      <description>&lt;p&gt;Ever got a backdoor installed on your computer by your beloved mouse? Here’s the story of a poor mouse that got really, really sick.&lt;/p&gt;&#xA;&lt;p&gt;&lt;img src=&#34;https://www.insinuator.net/wp-content/uploads/2016/07/mouse-300x169.jpg&#34; alt=&#34;Agent &amp;ldquo;Danger Mouse&amp;rdquo;&#34;&gt;&lt;/p&gt;&#xA;&lt;p&gt;Agent “Danger Mouse”&lt;/p&gt;&#xA;&lt;p&gt;Do you remember the times where people put Teensy-boards and USB hubs in their mouses? [Chris? ;)] Their aim was to attach an additional &lt;a href=&#34;https://en.wikipedia.org/wiki/Human_interface_device&#34;&gt;Human Interface Device&lt;/a&gt; (HID, like keyboards or mouses) with some payload in kind of e.g. keystrokes or mouse movements. Also, there are devices available like the USB Rubber Ducky in the housing of a USB thumb drive.&lt;br&gt;&#xA;The principle is easy: The tools are using a programmable microcontroller with the capability to emulate USB HID. That’s it. Just program your board of choice with the payload fitting your needs and plug it in at the target computer. The latter will recognize it as a keyboard/mouse and the payload-keystrokes will be entered.&lt;br&gt;&#xA;But why should external hardware be used? Many modern gaming peripherals provide functions to store macros on them, including enough onboard memory for little payloads.&lt;/p&gt;</description>
    </item>
    <item>
      <title>New Ransomware-Wave Analysis</title>
      <link>https://insinuator.net/2016/07/new-ransomware-wave-analysis/</link>
      <pubDate>Thu, 28 Jul 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/07/new-ransomware-wave-analysis/</guid>
      <description>&lt;p&gt;In the context of a customer project, we examined a new variant of the Locky ransomware. As in the meantime stated by a law enforcement agency, this has been part of a large wave of attacks hitting various enterprises in the night from Tuesday (2016-07-26) to Wednesday.&lt;/p&gt;&#xA;&lt;p&gt;As an initial attack vector, the attackers use emails with an attachment that probably even uses a 0day exploit, that enables the payload to be executed already when displayed in the MS Outlook preview.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Notes on Hijacking GSM/GPRS Connections</title>
      <link>https://insinuator.net/2016/07/notes-on-hijacking-gsm/gprs-connections/</link>
      <pubDate>Sun, 17 Jul 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/07/notes-on-hijacking-gsm/gprs-connections/</guid>
      <description>&lt;p&gt;As shown in previous blogposts we regularly work with GSM/GPRS basestations for &lt;a href=&#34;https://www.insinuator.net/2016/05/some-notes-on-utilizing-telco-networks-for-penetration-tests/&#34;&gt;testing devices with cellular uplinks&lt;/a&gt; or to simply run a &lt;a href=&#34;https://www.insinuator.net/2016/03/troopers16-gsm-network/&#34;&gt;private network during TROOPERS&lt;/a&gt;. Here the core difference between a random TROOPERS attendee and a device we want to hack is the will to join our network, or not! While at the conference we hand out own SIM cards which accept the TROOERPS GSM network as their “home network” some device need to be pushed a little bit.&lt;br&gt;&#xA;Every SIM card has it’s own home network, which is encoded in the fist five (European standard) or six (North American standard) digits of its IMSI – International Subscriber Number. The first three digits are the MCC, the Mobile Country Code, the next two/three the MNC, Mobile Network Code. International network overview are publicly available and for example &lt;a href=&#34;https://www.itu.int/dms_pub/itu-t/opb/sp/T-SP-E.212B-2014-PDF-E.pdf&#34;&gt;can be found &amp;gt;here&amp;lt;&lt;/a&gt;. For instance, Germany has the MCC 262 and Vodafone Germany uses MNC 02. So a SIM card with an IMSI starting with 26202 belongs to them.&lt;br&gt;&#xA;Sticking to the settings in its own SIM card a device will always prefer to connect to it’s own home network above all others. If the home network is not available it will usually go for the strongest signal. To protect users from unnecessary costs, an operator will usually add certain rules to prevent the device from connecting to other networks in the same country. So if you’re an O2 customer in Germany, visit a shopping center and only have reception for a T-Mobile cell, your phone will not directly jump into this network, even though it’s the strongest signal source.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Gotta Catch ‘Em All! – WORLDWIDE! (or how to spoof GPS to cheat at Pokémon GO)</title>
      <link>https://insinuator.net/2016/07/gotta-catch-em-all-worldwide-or-how-to-spoof-gps-to-cheat-at-pok%C3%A9mon-go/</link>
      <pubDate>Fri, 15 Jul 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/07/gotta-catch-em-all-worldwide-or-how-to-spoof-gps-to-cheat-at-pok%C3%A9mon-go/</guid>
      <description>&lt;p&gt;The moment, when your team leader asks you to cheat at Pokémon GO…everyone knows it, right? No? Well, I do 😉&lt;/p&gt;&#xA;&lt;p&gt;&lt;img src=&#34;https://www.insinuator.net/wp-content/uploads/2016/07/setup_edit-300x169.jpg&#34; alt=&#34;GPS Spoofing Setup&#34;&gt;&lt;/p&gt;&#xA;&lt;p&gt;GPS Spoofing Setup&lt;/p&gt;&#xA;&lt;p&gt;As I’m not a gamer, the technical part was of much more interest – that’s the real gaming for me.&lt;br&gt;&#xA;So, challenge accepted!&lt;/p&gt;&#xA;&lt;p&gt;In the past I was often fiddling around with SDR (Software Defined Radio), started with DVB-T sticks some years ago. When I came to ERNW in 2014 I got in touch with &lt;a href=&#34;http://greatscottgadgets.com/hackrf/&#34;&gt;Michael Ossman’s great HackRF One&lt;/a&gt; for the first time, and subsequently my thesis was based on SDR.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Jenkins Remoting RCE II – The return of the ysoserial</title>
      <link>https://insinuator.net/2016/07/jenkins-remoting-rce-ii-the-return-of-the-ysoserial/</link>
      <pubDate>Fri, 01 Jul 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/07/jenkins-remoting-rce-ii-the-return-of-the-ysoserial/</guid>
      <description>&lt;p&gt;&lt;img src=&#34;https://www.insinuator.net/wp-content/uploads/2016/06/headshot.png&#34; alt=&#34;Jenkins Logo&#34;&gt;&lt;/p&gt;&#xA;&lt;p&gt;&lt;a href=&#34;http://jenkins-ci.org/&#34;&gt;Jenkins&lt;/a&gt; is a continuous integration server, widely used in Java environments for building automation and deployment. The project recently disclosed an unauthenticated remote code execution vulnerability discovered by Moritz Bechler. Depending on the development environment, a Jenkins server can be a critical part of the infrastructure: It often creates the application packages that later will be deployed on production application servers. If an attacker can execute arbitrary code, s/he can easily manipulate those packages and inject additional code. Another scenario would be that the attacker stealing credentials, like passwords, private keys that are used for authentication in the deployment process or similar.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Some infos about SAP Security Note 2258786</title>
      <link>https://insinuator.net/2016/06/some-infos-about-sap-security-note-2258786/</link>
      <pubDate>Thu, 30 Jun 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/06/some-infos-about-sap-security-note-2258786/</guid>
      <description>&lt;p&gt;On the 8th of March SAP released the security note for a vulnerability we reported during an assessment of a SAP landscape. The issue affects the SAP NetWeaver Web Administration Interface.  By knowing a special URL a malicious user can acquire version information about the services enabled in the SAP system as well as the operating system used.  We wanted to share some details on the issue.&lt;/p&gt;&#xA;&lt;p&gt;The vulnerability is a bypass of the HTTP Basic Authorization for the &lt;a href=&#34;https://help.sap.com/saphelp_nw73/helpdata/en/4b/c1cd5cfb0050e9e10000000a15822b/content.htm?frameset=/en/48/3e191a252f72d0e10000000a42189c/frameset.htm&amp;amp;current_toc=/en/62/d678c5330a4992bc6fe927e6137c9d/plain.htm&amp;amp;node_id=155&amp;amp;show_children=false&#34;&gt;SAP Web Administration Interface&lt;/a&gt;. It discloses version information about the system respectively operating system, a brief SAP patch level overview and running services including their corresponding ports.&lt;/p&gt;</description>
    </item>
    <item>
      <title>VoLTE Security Analysis, part 2</title>
      <link>https://insinuator.net/2016/06/volte-security-analysis-part-2/</link>
      <pubDate>Fri, 24 Jun 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/06/volte-security-analysis-part-2/</guid>
      <description>&lt;p&gt;In our talk &lt;em&gt;&lt;a href=&#34;https://www.ernw.de/download/telco/ERNW_Area41_IMSecure.pdf&#34;&gt;IMSEcure – Attacking VoLTE&lt;/a&gt;&lt;/em&gt; Brian and me presented some theoretical and practical attacks against IP Multimedia Subsystems (IMS). Some of the attacks already have been introduced in a former &lt;a href=&#34;https://www.insinuator.net/2016/01/security-analysis-of-volte-part-1/&#34;&gt;blogpost&lt;/a&gt; and Ahmad &lt;a href=&#34;https://www.insinuator.net/2016/02/denial-of-service-attacks-on-volte/&#34;&gt;continued&lt;/a&gt; with a deeper analysis of the Flooding and targeted DoS scenario. But still, there are some open topics I’d like to continue with now. The methods I am demonstrating here also help to get a better understanding of VoLTE/IMS and how it is implemented on modern smartphones.&lt;/p&gt;</description>
    </item>
    <item>
      <title>SAMLReQuest Burpsuite Extention</title>
      <link>https://insinuator.net/2016/06/samlrequest-burpsuite-extention/</link>
      <pubDate>Mon, 06 Jun 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/06/samlrequest-burpsuite-extention/</guid>
      <description>&lt;p&gt;Security Assertion Markup Language (SAML) is an XML standard for exchanging authentication and authorization data between a Service Provider (SP) and an  Identification Provider (IdP). SAML is used in many Single Sign-On (SSO) implementations, when a user is authenticated once by IdP to access multiple related SPs. When a user requests to access a SP, it creates a SAML Authentication Request and redirects the user to IdP to be authenticated according to this authentication request. If the user is successfully authenticated, IdP creates a SAML authentication response and sends it back to SP through the user’s browser.&lt;/p&gt;</description>
    </item>
    <item>
      <title>The ULIN Story</title>
      <link>https://insinuator.net/2016/06/the-ulin-story/</link>
      <pubDate>Fri, 03 Jun 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/06/the-ulin-story/</guid>
      <description>&lt;p&gt;Some of you might have noticed the &lt;a href=&#34;http://www.forbes.com/sites/thomasbrewster/2016/05/31/ability-unlimited-spy-system-ulin-ss7/&#34;&gt;articles&lt;/a&gt;, or the leaked &lt;a href=&#34;https://www.documentcloud.org/documents/2843200-ULIN-Manual.html&#34;&gt;manual&lt;/a&gt; itself, about a tool called ULIN. ULIN is a “bleeding-edge spy tool” for mobile communication networks. According to the manual, it is aimed to be a surveillance software for agencies (or others with enough money) for tracking and intercepting the Voice Calls and SMS of arbitrary phones. They call this “remote recording and geolocation of mobile handsets using 2G/3G/4G networks”.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Implementing an Obsolete VPN Protocol on Top of HTTP: Because Why Not?</title>
      <link>https://insinuator.net/2016/05/implementing-an-obsolete-vpn-protocol-on-top-of-http-because-why-not/</link>
      <pubDate>Tue, 31 May 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/05/implementing-an-obsolete-vpn-protocol-on-top-of-http-because-why-not/</guid>
      <description>&lt;p&gt;Recently I’ve started some research on MikroTik’s RouterOS, the operating system that ships with RouterBOARD devices. As I’m running such a device myself, one day I got curious about security vulnerabilities that have been reported on the operating system and the running services as it comes with tons of &lt;a href=&#34;http://wiki.mikrotik.com/wiki/Manual:RouterOS_features&#34;&gt;features&lt;/a&gt;. Searching for known vulnerabilities in RouterOS on Google doesn’t really yield a lot of recent security related stuff. So I thought, there is either a lack of (public) research or maybe it is super secure… 🙂&lt;/p&gt;</description>
    </item>
    <item>
      <title>CVE-2016-1409 – IPv6 NDP DoS Vulnerability in Cisco Software</title>
      <link>https://insinuator.net/2016/05/cve-2016-1409-ipv6-ndp-dos-vulnerability-in-cisco-software/</link>
      <pubDate>Mon, 30 May 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/05/cve-2016-1409-ipv6-ndp-dos-vulnerability-in-cisco-software/</guid>
      <description>&lt;p&gt;Dear readers,&lt;/p&gt;&#xA;&lt;p&gt;As you may have already noticed, Cisco released an urgent &lt;a href=&#34;https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20160525-ipv6&#34;&gt;security advisory&lt;/a&gt; describing an IPv6 Neighbor Discovery DoS Vulnerability in several flavors of Cisco’s operating systems. Currently IOS-XR, XE and NX-OS are affected while ASA and “classic” IOS are under investigation. At first glance, it might look like yet another IPv6 DoS vulnerability. Looking closer, Cisco is mentioning an unauthenticated, remote attacker due to insufficient processing logic for crafted IPv6 NDP packets that are sent to an affected device. Following the public discussion about the vulnerability, it seems that these packets will reach the, probably low rate-limited, &lt;a href=&#34;https://supportforums.cisco.com/document/93456/asr9000xr-local-packet-transport-services-lpts-copp&#34;&gt;LPTS&lt;/a&gt; filter/queue on IOS XR devices “crowding” out legitimate NDP packets resulting in a DoS for IPv6 traffic, or in general a high CPU load as these packets will be processed by the CPU. More details are currently not available, but this might indicate the affected systems aren’t doing proper message validation checks on NDP packets (in addition to the LPTS filter/queue problem).&lt;/p&gt;</description>
    </item>
    <item>
      <title>WPAD Name Collision Vulnerability (TA16-144A)</title>
      <link>https://insinuator.net/2016/05/wpad-name-collision-vulnerability-ta16-144a/</link>
      <pubDate>Tue, 24 May 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/05/wpad-name-collision-vulnerability-ta16-144a/</guid>
      <description>&lt;p&gt;Yesterday the US-CERT released a &lt;a href=&#34;https://www.us-cert.gov/ncas/alerts/TA16-144A&#34;&gt;Technical Alert&lt;/a&gt; (TA16-144A) about the recently found WPAD Name Collision Vulnerability. We will give you a summary about the vulnerability as well as the basic mechanisms here.&lt;/p&gt;&#xA;&lt;h2 id=&#34;wpad&#34;&gt;WPAD&lt;/h2&gt;&#xA;&lt;p&gt;The Web Proxy Auto-Discovery Protocol is used to auto-configure the proxy for web browsers. So when joining the according network the browser can use DHCP and DNS methods to find a specific configuration file (typically named wpad.dat), which is loaded and applied to the browser’s settings. Therefore, there is no need to configure each browser in your environment individually/manually.&lt;/p&gt;</description>
    </item>
    <item>
      <title>BMC BladeLogic Vulnerabilities PoCs</title>
      <link>https://insinuator.net/2016/05/bmc-bladelogic-vulnerabilities-pocs/</link>
      <pubDate>Mon, 23 May 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/05/bmc-bladelogic-vulnerabilities-pocs/</guid>
      <description>&lt;p&gt;Hi everyone!&lt;/p&gt;&#xA;&lt;p&gt;A quick update: earlier in our blog we released &lt;a href=&#34;https://www.insinuator.net/2016/03/bmc-bladelogic-cve-2016-1542-and-cve-2016-1543/&#34;&gt;BMC BladeLogic: CVE-2016-1542 and CVE-2016-1543&lt;/a&gt; vulnerabilities. Now the exploits are also available in our &lt;a href=&#34;https://github.com/ernw/insinuator-snippets/tree/master/bmc_bladelogic&#34;&gt;github&lt;/a&gt; if you want to check your systems 😉&lt;/p&gt;&#xA;&lt;p&gt;Have a nice week,&lt;br&gt;&#xA;Olga&lt;/p&gt;</description>
    </item>
    <item>
      <title>How ‘security’ black boxes might corrupt your investment</title>
      <link>https://insinuator.net/2016/04/how-security-black-boxes-might-corrupt-your-investment/</link>
      <pubDate>Fri, 29 Apr 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/04/how-security-black-boxes-might-corrupt-your-investment/</guid>
      <description>&lt;p&gt;Usually I’m not the kind of guy who talks about such economic topics. Because I’m an engineer / security researcher who is exclusively concerned with understanding technical problems and if possible, solving them accordingly. My whole education is based on this and contains predominantly technical aspects of information security. This sometimes makes it difficult to understand what the market cares about (and why some products are being developed / exist on the market 😉 ). Nevertheless, a current engagement for one of our customers made me stumble upon such a product.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Discover the Unknown: Analyzing an IoT Device</title>
      <link>https://insinuator.net/2016/04/discover-the-unknown-analyzing-an-iot-device/</link>
      <pubDate>Mon, 11 Apr 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/04/discover-the-unknown-analyzing-an-iot-device/</guid>
      <description>&lt;p&gt;This blog post will give a brief overview about how a simple IoT device can be assessed. It will show a basic methodology, what tools can be used for different tasks and how to solve problems that may arise during analyses. It is aimed at readers that are interested in how such a device can be assessed, those with general interest in reverse engineering or the ones who just want to see how to technically approach an unknown device.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Classic Web Vulns Found in Google Search Appliance 7.4</title>
      <link>https://insinuator.net/2016/03/classic-web-vulns-found-in-google-search-appliance-7.4/</link>
      <pubDate>Wed, 23 Mar 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/03/classic-web-vulns-found-in-google-search-appliance-7.4/</guid>
      <description>&lt;p&gt;&lt;a href=&#34;https://www.google.com/intx/en/work/search/products/gsa.html&#34;&gt;&lt;img src=&#34;https://www.insinuator.net/wp-content/uploads/2016/03/servers-300x156.png&#34; alt=&#34;Google Search Appliances&#34;&gt;&lt;/a&gt;Hi all,&lt;/p&gt;&#xA;&lt;p&gt;I’ve recently found some sort of classic web vulnerabilities in the Google Search Appliance (GSA) and as they are now fixed [0][1][2], I’d like to share them with you.&lt;/p&gt;&#xA;&lt;p&gt;First of all, some infrastructure details about the GSA itself. The GSA is used by companies to apply the Google search algorithms to their internal documents without publishing them to cloud providers. To accomplish this task, the GSA provides multiple interfaces including a search interface, an administrative interface and multiple interfaces to index the organization’s data.&lt;/p&gt;</description>
    </item>
    <item>
      <title>How to crack a white-box without much effort</title>
      <link>https://insinuator.net/2016/03/how-to-crack-a-white-box-without-much-effort/</link>
      <pubDate>Wed, 02 Mar 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/03/how-to-crack-a-white-box-without-much-effort/</guid>
      <description>&lt;p&gt;&lt;strong&gt;By: Philippe Teuwen (&lt;a href=&#34;http://twitter.com/doegox&#34;&gt;@doegox&lt;/a&gt;)&lt;/strong&gt;&lt;/p&gt;&#xA;&lt;p&gt;White-box cryptography is a relatively new field that aims at enabling safely cryptographic operations in hostile situations.&lt;br&gt;&#xA;A typical example is its use in digital-right management (DRM) schemes, but nowadays you also find white-box implementations in mobile applications such as Host Card Emulation (HCE) and the protection of credentials to the cloud.&lt;br&gt;&#xA;In all these use-cases the software implementation uses the secret key of a third-party which should remain secret from the owner of the device which is running this executable.&lt;/p&gt;</description>
    </item>
    <item>
      <title>How to test Kerberos authenticated web applications?</title>
      <link>https://insinuator.net/2016/02/how-to-test-kerberos-authenticated-web-applications/</link>
      <pubDate>Thu, 18 Feb 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/02/how-to-test-kerberos-authenticated-web-applications/</guid>
      <description>&lt;p&gt;First of all: This is not an in-depth Kerberos how-to, nor is this tutorial about the different aspects of web application testing. This tutorial is just to give support in testing Kerberos authenticated web applications. The goal is to hand over the right tools and steps to be able to perform the configuration and be able to test the application.&lt;/p&gt;&#xA;&lt;p&gt;&lt;strong&gt;When to use it?&lt;/strong&gt;&lt;br&gt;&#xA;When there is a 401 server response with the header “WWW-Authenticate: Negotiate”. This can either mean Kerberos or NTLM authentication is needed. It is possible to distinguish them by looking at valid authenticated client traffic. As a simple reminder: The NTLM Authorization header will always start with the value “TlRM…”, the Kerberos Authorization header will always start with “YII…”. For further information this &lt;a href=&#34;http://blogs.technet.com/b/tristank/archive/2006/08/02/negotiate-this.aspx&#34;&gt;link&lt;/a&gt; is recommend.&lt;br&gt;&#xA;In this tutorial the term “Kerberos authentication” will be used. There are other terms sometimes used like SPNEGO, SSO or integrated authentication.&lt;/p&gt;</description>
    </item>
    <item>
      <title>ss7MAPer – A SS7 pen testing toolkit</title>
      <link>https://insinuator.net/2016/02/ss7maper-a-ss7-pen-testing-toolkit/</link>
      <pubDate>Tue, 16 Feb 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/02/ss7maper-a-ss7-pen-testing-toolkit/</guid>
      <description>&lt;p&gt;While running some SS7 pentests last year, I developed a small tool automating some of the well-known SS7 attack cases. Today I’m releasing the first version of ss7MAPer, a &lt;a href=&#34;https://en.wikipedia.org/wiki/Signalling_System_No._7&#34;&gt;SS7&lt;/a&gt; &lt;a href=&#34;https://en.wikipedia.org/wiki/Mobile_Application_Part%20&#34;&gt;MAP&lt;/a&gt; (pen-)testing toolkit.&lt;/p&gt;&#xA;&lt;p&gt;The toolkit is build upon the &lt;a href=&#34;http://cgit.osmocom.org/erlang/osmo_ss7/&#34;&gt;Osmocom SS7 stack&lt;/a&gt; and implements some basic MAP messages. At its current state tests against the &lt;a href=&#34;https://en.wikipedia.org/wiki/Home_Location_Register&#34;&gt;HLR&lt;/a&gt; are ready for use, in future versions tests against &lt;a href=&#34;https://en.wikipedia.org/wiki/Visitor_Location_Register&#34;&gt;VLR&lt;/a&gt;, &lt;a href=&#34;https://en.wikipedia.org/wiki/Network_switching_subsystem&#34;&gt;MSC&lt;/a&gt; and &lt;a href=&#34;https://en.wikipedia.org/wiki/Short_message_service_center&#34;&gt;SMSC&lt;/a&gt; will follow.&lt;/p&gt;&#xA;&lt;p&gt;The source code of the tool is published on &lt;a href=&#34;https://github.com/ernw/ss7MAPer&#34;&gt;github&lt;/a&gt;, feel free to use and extend.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Denial of Service attacks on VoLTE</title>
      <link>https://insinuator.net/2016/02/denial-of-service-attacks-on-volte/</link>
      <pubDate>Wed, 03 Feb 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/02/denial-of-service-attacks-on-volte/</guid>
      <description>&lt;p&gt;Some weeks ago Hendrik explained in his blogpost &lt;a href=&#34;https://www.insinuator.net/2016/01/security-analysis-of-volte-part-1/&#34;&gt;Security Analysis of VoLTE, Part 1&lt;/a&gt; some attack vectors for Voice over LTE (VoLTE). One attack vector introduced was Denial of Service (DoS), which I also discussed in my Masterthesis “Evaluation of IMS security and Developing penetration tests of IMS”.&lt;/p&gt;&#xA;&lt;p&gt;In general, DoS attacks aim to prevent a system or a network from efficiently providing its service to legitimate users . The impact of such attacks can vary from a big degradation of quality to total blockage. DoS can occur on users level, where a user or a group of users cannot use the service. But the common conception of DoS is on the service level, where the whole service is broken, unstable or totally down. This blog post is about targeting DoS of the whole VoLTE service by attacking IMS.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Damn Vulnerable Safe</title>
      <link>https://insinuator.net/2016/01/damn-vulnerable-safe/</link>
      <pubDate>Sat, 30 Jan 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/01/damn-vulnerable-safe/</guid>
      <description>&lt;p&gt;A while back Stefan and I held a little crash course/orientation run on hardware hacking at a German Fachhochschule. Planning to use something “real” we went for a simple electronic safe with a bunch of different vulnerabilities. I guess most security guys who spend a fair amount of time in hotels will understand this choice. As we needed something we could rely on would break, we stripped the device and swapped the original electronics for our own. The result was the “Damn Vulnerable Safe”.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Dynamic IDA Enrichment (aka. DIE)</title>
      <link>https://insinuator.net/2016/01/dynamic-ida-enrichment-aka.-die/</link>
      <pubDate>Thu, 28 Jan 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/01/dynamic-ida-enrichment-aka.-die/</guid>
      <description>&lt;p&gt;Last year on the &lt;a href=&#34;https://hex-rays.com/contests/2015/index.shtml&#34;&gt;Hex-rays plugin Contest&lt;/a&gt; the Dynamic IDA Enrichment (DIE) plugin won first place, so we decided to have a look and play around with it.&lt;/p&gt;&#xA;&lt;p&gt;DIE extends IDA to add Dynamic Data to the static analysis. So after the installation, we are able to perform the static analysis using a lot of supporting information from the actual execution of the binary under assessment.&lt;/p&gt;&#xA;&lt;p&gt;Since DIE is purely written in Python you will need at least Python 2.7 and IDA Versions prior to 6.8 won´t work. In the current version DIE will only work on Windows which will hopefully soon be available cross-platform.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Security Analysis of VoLTE, Part 1</title>
      <link>https://insinuator.net/2016/01/security-analysis-of-volte-part-1/</link>
      <pubDate>Wed, 06 Jan 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/01/security-analysis-of-volte-part-1/</guid>
      <description>&lt;p&gt;Hello everybody,&lt;br&gt;&#xA;this time I’d like to share some thoughts and results about our telco research last year. We gathered a lot of information out of some projects we’d like to share and discuss with you. The following sections also provide an idea of the upcoming Telecommunication Security Workshop I will give with Kevin Redon at Troopers (&lt;a href=&#34;https://www.troopers.de/events/troopers16/573_telco_network_security/&#34;&gt;click&lt;/a&gt;). The workshop will be about Radio Network Security (covered by Kevin) and security aspects of the Core Network (covered by myself), mainly focusing on Voice over LTE (VoLTE). That’s also the topic of today’s post.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Xen XSA 155: Double fetches in paravirtualized devices</title>
      <link>https://insinuator.net/2015/12/xen-xsa-155-double-fetches-in-paravirtualized-devices/</link>
      <pubDate>Thu, 17 Dec 2015 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2015/12/xen-xsa-155-double-fetches-in-paravirtualized-devices/</guid>
      <description>&lt;p&gt;As part of my research on the security of paravirtualized devices, I reported a number of vulnerabilities to the Xen security team, which were patched &lt;a href=&#34;http://xenbits.xen.org/xsa/advisory-155.html&#34;&gt;today&lt;/a&gt;. All of them are double fetch vulnerabilities affecting the different backend components used for paravirtualized devices. While the severity and impact of these bugs varies heavily and is dependent on a lot of external factors, I would recommend patching them as soon as possible. In the rest of this blog post I’ll give a short teaser about my research with full details coming out in the first quarter of 2016 .&lt;/p&gt;</description>
    </item>
    <item>
      <title>Investigating Memory Analysis Tools – SSDT Hooking via Pointer Replacement</title>
      <link>https://insinuator.net/2015/12/investigating-memory-analysis-tools-ssdt-hooking-via-pointer-replacement/</link>
      <pubDate>Sun, 13 Dec 2015 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2015/12/investigating-memory-analysis-tools-ssdt-hooking-via-pointer-replacement/</guid>
      <description>&lt;p&gt;In this blogpost we will briefly explain a well known Syscall hooking technique (a more detailed explanation can be gathered from e.g.  http://resources.infosecinstitute.com/hooking-system-service-dispatch-table-ssdt/) used by multiple malware samples (like the laqma trojan) and right after discuss how some memory analysis tools have trouble in the analysis and/or reporting of these.&lt;/p&gt;&#xA;&lt;p&gt;Before we go further, I just shortly wanted to say, that this post is not intended to be a bashing of any tool. We have the greatest respect for all the effort and work which has been and most probably will be done in the future.&lt;/p&gt;</description>
    </item>
    <item>
      <title>VMware did it again: vCenter Remote Code Execution</title>
      <link>https://insinuator.net/2015/10/vmware-did-it-again-vcenter-remote-code-execution/</link>
      <pubDate>Fri, 02 Oct 2015 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2015/10/vmware-did-it-again-vcenter-remote-code-execution/</guid>
      <description>&lt;p&gt;Yesterday 7Elements released &lt;a href=&#34;https://www.7elements.co.uk/resources/blog/cve-2015-2342-remote-code-execution-within-vmware-vcenter/&#34;&gt;the description&lt;/a&gt; of a Remote Code Execution vulnerability in VMware vCenter. The information came in at a good point as I’m at the moment drafting a follow-up blogpost for &lt;a href=&#34;https://www.insinuator.net/2014/01/state-of-virtualization-security-14/&#34;&gt;this one&lt;/a&gt; which will summarize some of our approaches to virtualization security. The vCenter vulnerability is both quite critical and particularly interesting in several ways:&lt;/p&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;Once there is proper network isolation &amp;amp; restriction, the vulnerability should not be exploitable from the overall corporate network (or maybe even the Internet — a quick inaccurate shodan search for “vcenter” returned about 1800 results and at random checks actually revealed vCenter systems). It should also not be exploitable from ESXi hosts managed through the vCenter: ESXi hosts need to be able to connect to the vCenter for heartbeat messages, however “only” on ports 443 and 902 — the vulnerability exploits a service running on TCP ports &lt;a href=&#34;http://kb.vmware.com/selfservice/microsites/search.do?language=en_US&amp;amp;cmd=displayKC&amp;amp;externalId=2051575&#34;&gt;9875 – 9877&lt;/a&gt;.&lt;/li&gt;&#xA;&lt;li&gt;It is questionable whether the exploited Java RMI functionality is really required for the operation of VMware infrastructures. This &lt;a href=&#34;http://www.accuvant.com/blog/exploiting-jmx-rmi&#34;&gt;blogpost&lt;/a&gt; provides further detail on the known type of vulnerability in Java applications. VMware had a similar issue back in 2010, where &lt;a href=&#34;http://kb.vmware.com/selfservice/microsites/search.do?language=en_US&amp;amp;cmd=displayKC&amp;amp;externalId=1034175&#34;&gt;their workaround&lt;/a&gt; to fix a vulnerability was to just disable the affected component, resulting in the impression that it wasn’t even required in the first place. Let’s see whether the future will bring up more vulnerabilities which could have been prevented by implementing more thorough hardening of all components (e.g. following the &lt;em&gt;minimal machine&lt;/em&gt; principle). Furthermore in 2011 there was a similar 3^(rd) party component vulnerability in vCenter which we covered &lt;a href=&#34;https://www.insinuator.net/2011/03/vmsa-2011-0005-vmware-vcenter-orchestrator-remote-code-execution-vulnerability/&#34;&gt;in this blogpost&lt;/a&gt;. The totality of our posts on VMware security can be found &lt;a href=&#34;https://www.insinuator.net/tag/vmware/&#34;&gt;here&lt;/a&gt;.&lt;/li&gt;&#xA;&lt;li&gt;For high-security environments we have been recommending for some time to use a dedicated vCenter per hypervisor cluster (i.e. if you have two hypervisor clusters, one for internal and one for DMZ systems, you should use two separate vCenter systems). Vulnerabilities like these illustrate the need for that, given that the ESXi hosts need to be able to access the vCenter on the network level.&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;p&gt;Happy patching &amp;amp; stay tuned,&lt;/p&gt;</description>
    </item>
    <item>
      <title>New iOS Version – New Lockscreen Bypass</title>
      <link>https://insinuator.net/2015/09/new-ios-version-new-lockscreen-bypass/</link>
      <pubDate>Sun, 27 Sep 2015 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2015/09/new-ios-version-new-lockscreen-bypass/</guid>
      <description>&lt;p&gt;At the 16th of September Apple released its new version of the mobile operating system iOS 9. As several versions before, this new iteration suffers from a weakness that makes it possible to bypass the lockscreen without entering the respective PIN code. Exploiting this flaw requires Siri to be enabled and phyiscal access to the phone. A successful exploitation results in a major loss of confidentiality as all photos and contacts in the phonebook can be accessed by the attacker. The following steps lead to the lockscreen bypass:&lt;/p&gt;</description>
    </item>
    <item>
      <title>Cisco and the Maintenance Operation Protocol (MOP)</title>
      <link>https://insinuator.net/2015/08/cisco-and-the-maintenance-operation-protocol-mop/</link>
      <pubDate>Tue, 25 Aug 2015 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2015/08/cisco-and-the-maintenance-operation-protocol-mop/</guid>
      <description>&lt;p&gt;Howdy,&lt;/p&gt;&#xA;&lt;p&gt;this is a short write up about the Maintenance Operation Protocol (MOP), an ancient remote management protocol from the &lt;a href=&#34;https://de.wikipedia.org/wiki/DECnet&#34;&gt;DECnet&lt;/a&gt; protocol suite. It’s old, rarely used and in most cases not needed at all. But as we stumbled across this protocol in some network assessments, it seems like a lot of network admins and other users don’t know about it. Even various hardening guides we’ve seen don’t mention MOP at all.&lt;/p&gt;</description>
    </item>
    <item>
      <title>KNX Support for Nmap</title>
      <link>https://insinuator.net/2015/08/knx-support-for-nmap/</link>
      <pubDate>Sun, 09 Aug 2015 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2015/08/knx-support-for-nmap/</guid>
      <description>&lt;p&gt;Hi folks,&lt;/p&gt;&#xA;&lt;p&gt;our home automation research, especially with KNX, is still in progress. As part of this research we’ve implemented various tools to easy the process of identifying and enumerating KNX devices, in both IP driven networks and on the bus.&lt;/p&gt;&#xA;&lt;p&gt;Lately we’ve written two Nmap NSE scripts to discover KNXnet/IP gateways. These allow everyone to discover such gateways in local and remote networks and print some useful information about them. One of them follows the specification to discover gateways by sending multicast packets, where all devices on the network must respond to. Due to the specification of KNXnet/IP this process is rather non-invasive because only a single UDP packet is needed to discover multiple gateways. The other script allows to identify gateways via unicast connections by a slightly different message type, which allows discovery over e.g. the Internet.&lt;/p&gt;</description>
    </item>
    <item>
      <title>HackRF meets PortaPack H1</title>
      <link>https://insinuator.net/2015/08/hackrf-meets-portapack-h1/</link>
      <pubDate>Sat, 08 Aug 2015 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2015/08/hackrf-meets-portapack-h1/</guid>
      <description>&lt;p&gt;Today we received a few &lt;a href=&#34;http://www.sharebrained.com/2014/05/28/portapack-h1-imminent/&#34;&gt;ShareBrained Technology – PortaPack H1&lt;/a&gt; to use with our HackRFs. Having done a first few minutes of scanning, I just wanted to give you a quick overview of its features and potential…&lt;/p&gt;&#xA;&lt;p&gt;After having had &lt;a href=&#34;https://www.troopers.de/events/speaker/31_michael_ossmann/&#34;&gt;Michael Ossmann&lt;/a&gt; in for a few workshops with his &lt;a href=&#34;https://www.insinuator.net/2013/08/hack-rf/&#34;&gt;Jawbreaker&lt;/a&gt; and &lt;a href=&#34;https://www.insinuator.net/2014/08/hackrf-one-the-story-continues/&#34;&gt;HackRF One&lt;/a&gt; we have used the HackRF on multiple occasions. No matter if &lt;a href=&#34;https://www.insinuator.net/2015/04/analysis-of-an-alarm-system/&#34;&gt;research projects&lt;/a&gt; or actual customer projects, the HackRF has always been of great help. As we mainly use it on laptops, we’ve got certain constraints concerning its portability when wanting to do some quick mobile scanning. Although there are a few solutions for tablets and smartphones, they haven’t been quite able to convince all of us. So a while back we decided to keep an eye on the &lt;a href=&#34;http://www.sharebrained.com/2014/05/28/portapack-h1-imminent/&#34;&gt;PortaPack&lt;/a&gt; and have been since been waiting for its release.&lt;/p&gt;</description>
    </item>
    <item>
      <title>RedStar OS Watermarking</title>
      <link>https://insinuator.net/2015/07/redstar-os-watermarking/</link>
      <pubDate>Thu, 16 Jul 2015 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2015/07/redstar-os-watermarking/</guid>
      <description>&lt;p&gt;During the last few months information about one of North Koreas operating systems was leaked. It is a Linux based OS that tries to simulate the look and feel of a Mac. Some of it’s features have already been discussed on &lt;a href=&#34;https://www.northkoreatech.org/2014/12/30/red-star-3-0-desktop-finally-becomes-public/&#34; title=&#34;rs desktop&#34;&gt;various&lt;/a&gt; &lt;a href=&#34;https://www.northkoreatech.org/2014/01/31/north-koreas-red-star-os-goes-mac/&#34; title=&#34;rs mac&#34;&gt;blog&lt;/a&gt; &lt;a href=&#34;http://www.openingupnorthkorea.com/downloads-2&#34; title=&#34;rs download&#34;&gt;posts&lt;/a&gt; and news &lt;a href=&#34;http://www.golem.de/news/red-star-ausprobiert-das-linux-aus-nordkorea-1501-111443-3.html&#34; title=&#34;golem rs&#34;&gt;articles&lt;/a&gt;. We thought we would take a short look at the OS. This blog post contains some of the results.&lt;/p&gt;&#xA;&lt;p&gt;As you can imagine, most interesting for us was to investigate features that impact the privacy of the users. There are some &lt;a href=&#34;http://www.openwall.com/lists/oss-security/2015/01/09/1&#34; title=&#34;sec vuln rs&#34;&gt;publications concerning the security&lt;/a&gt; of the OS, this is an aspect that we will not cover in this post. We will stick to a privacy issue that we identified in this post. As ERNW has a long history of “Making the World a Safer Place”, we consider this topic an important one. The privacy of potential users (especially from North Korea) may be impacted and therefore we think that the results must be made available for the public. So, here we go …&lt;/p&gt;</description>
    </item>
    <item>
      <title>Evasion of Cisco ACLs by (Ab)Using IPv6 – Part 2</title>
      <link>https://insinuator.net/2015/07/evasion-of-cisco-acls-by-abusing-ipv6-part-2/</link>
      <pubDate>Wed, 08 Jul 2015 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2015/07/evasion-of-cisco-acls-by-abusing-ipv6-part-2/</guid>
      <description>&lt;p&gt;When we wrote our initial blogpost regarding the &lt;a href=&#34;http://www.insinuator.net/2015/01/evasion-of-cisco-acls-by-abusing-ipv6-discussion-of-mitigation-techniques/&#34;&gt;evasion of Cisco ACLs by (Ab)Using IPv6&lt;/a&gt;, where we described (&lt;a href=&#34;http://www.insinuator.net/2015/01/the-persistent-problem-of-state-in-ipv6-security/&#34;&gt;known to Cisco&lt;/a&gt;) cases of Access Control Lists (ACL) circumvention, we also suggested some mitigation techniques including the blocking of some (if not all) IPv6 Extension Headers.&lt;br&gt;&#xA;Almost a month later, we got &lt;a href=&#34;http://www.insinuator.net/2015/01/evasion-of-cisco-acls-by-abusing-ipv6-discussion-of-mitigation-techniques/#respond&#34;&gt;a comment&lt;/a&gt; from &lt;em&gt;Matej Gregr&lt;/em&gt; that, even if the ACLs of certain Cisco Switches are configured to block IPv6 Extension headers like Hop-by-Hop or Destination Options headers, this does not actually happen/work as expected. Of course this made us re-visit the lab in the interim ;-).&lt;/p&gt;</description>
    </item>
    <item>
      <title>The patient’s last words: I am not a target!</title>
      <link>https://insinuator.net/2015/07/the-patients-last-words-i-am-not-a-target/</link>
      <pubDate>Wed, 01 Jul 2015 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2015/07/the-patients-last-words-i-am-not-a-target/</guid>
      <description>&lt;p&gt;Last week I gave a short interview for Süddeutsche Zeitung on the security of medical devices. You can find it &lt;a href=&#34;http://www.sueddeutsche.de/wirtschaft/medizintechnik-naechtliches-desaster-1.2534424&#34;&gt;here&lt;/a&gt;. Unfortunately it is in German so I decided to sum up some of my key points that made it into the article and some that didn’t in this blog post.&lt;/p&gt;&#xA;&lt;p&gt;The medical devices that we have been looking into include patient monitors, syringe pumps, EEGs, home monitoring devices and an MRI. All of these devices had major flaws that look like they came straight out of the 90s. Sometimes, we were able to crash the machines by simply doing a port scan, sometimes we could get around access controls protecting PIN codes of devices, and in most cases we were able to render the machine unusable. All these attacks were performed over the network and no physical access to the device was needed.&lt;/p&gt;</description>
    </item>
    <item>
      <title>TACACS&#43; module for loki</title>
      <link>https://insinuator.net/2015/06/tacacs-module-for-loki/</link>
      <pubDate>Wed, 10 Jun 2015 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2015/06/tacacs-module-for-loki/</guid>
      <description>&lt;p&gt;There has been, again, some development within the loki domain. Today I’m going to write about the latest module added to the suite, a module for decoding and cracking Cisco’s TACACS+.&lt;/p&gt;&#xA;&lt;p&gt;TACACS is the Terminal Access Controller Access-Control System, a protocol for handling remote user authentication and central access control. It originated in 1984 and was used in the old Unix world. TACACS+ is a related protocol developed by Cisco Systems and is widely used for AAA (Authentication, Authorization, Accounting) on IOS based devices. It was released as an &lt;a href=&#34;http://tools.ietf.org/html/draft-grant-tacacs-02&#34;&gt;open standard&lt;/a&gt; in 1993 (and expired in 1998 by the way ;-)).&lt;/p&gt;</description>
    </item>
    <item>
      <title>Analysis of an Alarm System – Part 2/3</title>
      <link>https://insinuator.net/2015/05/analysis-of-an-alarm-system-part-2/3/</link>
      <pubDate>Tue, 12 May 2015 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2015/05/analysis-of-an-alarm-system-part-2/3/</guid>
      <description>&lt;p&gt;A few days later than planned (sorry about that), but here we go with part 2 (&lt;a href=&#34;http://www.insinuator.net/2015/04/analysis-of-an-alarm-system/&#34;&gt;Part1&lt;/a&gt;) and the demodulation/analysis part.&lt;/p&gt;&#xA;&lt;p&gt;&lt;strong&gt;Initial Analysis&lt;/strong&gt;&lt;br&gt;&#xA;To analyse a captured signal, the tool baudline seems to be the best way at the moment. So we open it with the following options and have a closer look (ContextMenu-&amp;gt;Input-&amp;gt;Open file):&lt;/p&gt;&#xA;&lt;p&gt;&lt;img src=&#34;https://www.ernw.de/download/alarm_system/step3_baudlineOpenOptions.png&#34; alt=&#34;&#34;&gt;&lt;/p&gt;&#xA;&lt;p&gt;After using the open button, you should be able to see something similar to this:&lt;/p&gt;</description>
    </item>
    <item>
      <title>Car Hacking Lab – Work in Progress</title>
      <link>https://insinuator.net/2015/04/car-hacking-lab-work-in-progress/</link>
      <pubDate>Tue, 28 Apr 2015 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2015/04/car-hacking-lab-work-in-progress/</guid>
      <description>&lt;p&gt;We just wanted to share some impressions from our car hacking lab:&lt;/p&gt;&#xA;&lt;p&gt;&lt;a href=&#34;https://www.insinuator.net/wp-content/uploads/2015/04/car_lab2.mp4&#34;&gt;https://www.insinuator.net/wp-content/uploads/2015/04/car_lab2.mp4&lt;/a&gt;&lt;/p&gt;&#xA;&lt;p&gt; &lt;/p&gt;&#xA;&lt;p&gt;stay tuned,&lt;/p&gt;&#xA;&lt;p&gt;The ERNW Car Hacking Team&lt;/p&gt;&#xA;&lt;p&gt; &lt;/p&gt;</description>
    </item>
    <item>
      <title>Analysis of an Alarm System – Part 1/3</title>
      <link>https://insinuator.net/2015/04/analysis-of-an-alarm-system-part-1/3/</link>
      <pubDate>Mon, 20 Apr 2015 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2015/04/analysis-of-an-alarm-system-part-1/3/</guid>
      <description>&lt;p&gt;&lt;strong&gt;Introduction&lt;/strong&gt;&lt;br&gt;&#xA;This and the following two posts should serve as a step-by-step guide through the whole process of analyzing a radio frequency black box, demodulate and understand the data transfered and finally modulate our own data in order to e.g. perform a brute force attacks.&lt;/p&gt;&#xA;&lt;p&gt;The information provided and the results are immensely inspired by Michael Ossmann and the workshops he has given at our location. Visit him and his great tool HackRF at &lt;a href=&#34;https://greatscottgadgets.com/hackrf/&#34;&gt;https://greatscottgadgets.com/hackrf/&lt;/a&gt; !&lt;/p&gt;</description>
    </item>
    <item>
      <title>General Pr0ken Filesystem – Hacking IBM’s GPFS</title>
      <link>https://insinuator.net/2015/04/general-pr0ken-filesystem-hacking-ibms-gpfs/</link>
      <pubDate>Sun, 12 Apr 2015 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2015/04/general-pr0ken-filesystem-hacking-ibms-gpfs/</guid>
      <description>&lt;p&gt;&lt;em&gt;This post is a short wrap-up of our Troopers talk about the research we did on IBM’s General Parallel File System. If you are interested in all the technical details take a look at our &lt;a href=&#34;https://www.troopers.de/media/filer_public/69/81/69812750-49b0-4631-a3e6-fb402c88adf3/fwfggpfs_troopers15.pdf&#34; title=&#34;slides&#34;&gt;slides&lt;/a&gt; or the &lt;a href=&#34;https://www.youtube.com/watch?v=rmWMEdA-3Qs&#34;&gt;video recording&lt;/a&gt;. We will also give an updated version of this talk at the &lt;a href=&#34;http://www.phdays.com/&#34;&gt;PHDays&lt;/a&gt; conference in Moscow next month.&lt;/em&gt;&lt;/p&gt;&#xA;&lt;p&gt;The IBM General Parallel File System is a distributed file system used in large scale enterprise environments, high performance clusters as well as some of the worlds largest super computers. It is considered by many in the industry to be the most feature rich and production hardened distributed file system currently available. GPFS has a long and really interesting history, going back to the Tiger Shark file system created by IBM 1993.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Apple iOS PIN Bruteforce</title>
      <link>https://insinuator.net/2015/04/apple-ios-pin-bruteforce/</link>
      <pubDate>Tue, 07 Apr 2015 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2015/04/apple-ios-pin-bruteforce/</guid>
      <description>&lt;p&gt;Over the past few weeks, multiple news sites have covered some mystical approach to bruteforce PINs on Apple iOS devices. All articles cover a black box called IP Box, the fact that PINs can be broken and that sometimes the automatic wipe after 10 failed tries can be circumvented. Sadly, as often, the what is described but not the how……&lt;/p&gt;&#xA;&lt;h2&gt;&lt;/h2&gt;&#xA;&lt;p&gt;This blog post will give you a simple overview of both the practical attacks and the vulnerabilities behind them. Although the Headings don’t quite give away the content, the post starts with a simple PIN bruteforce against iOS 7.x and then goes over to a more advanced attack on iOS 8.x and a few technical details on the “black box”.&lt;/p&gt;</description>
    </item>
    <item>
      <title>XML External Entity (XXE) Injection in Apache Batik Library [CVE-2015-0250]</title>
      <link>https://insinuator.net/2015/03/xml-external-entity-xxe-injection-in-apache-batik-library-cve-2015-0250/</link>
      <pubDate>Sat, 21 Mar 2015 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2015/03/xml-external-entity-xxe-injection-in-apache-batik-library-cve-2015-0250/</guid>
      <description>&lt;p&gt;During one of our latest web application code review projects I came across a vulnerability for which I think it is worth to speak about. It is an injection based attack against XML parsers which uses a rarely required feature called external entity expansion. The XML specification allows XML documents to define entities which reference resources external to the document and parsers typically support this feature by default. If an application parses XML input from untrusted sources and the parsing routine is not properly configured this can be exploited by an attacker with a so called XML external entity (XXE) injection. A successful XXE injection attack could allow an attacker to access the file system, cause a DoS attack or inject script code (e.g. Javascript to perform an XSS attack).&lt;/p&gt;</description>
    </item>
    <item>
      <title>Revisiting Xen’s x86 Emulation: Xen XSA 123</title>
      <link>https://insinuator.net/2015/03/revisiting-xens-x86-emulation-xen-xsa-123/</link>
      <pubDate>Tue, 10 Mar 2015 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2015/03/revisiting-xens-x86-emulation-xen-xsa-123/</guid>
      <description>&lt;p&gt;In my &lt;a href=&#34;http://www.insinuator.net/2015/02/the-dangers-of-x86-emulation-xen-xsa-110-and-105/&#34; title=&#34;The Dangers of x86 Emulation: Xen XSA 110 and 105&#34;&gt;last blog post&lt;/a&gt;, I gave an overview about recent vulnerabilities discovered in the x86 emulation layer of Xen. While both of the discussed vulnerabilities only allow for guest privilege escalation, the complexity of the involved code seemed to indicate that even more interesting bugs could be discovered. So I spent some time searching for memory corruption issues and discovered a very interesting bug that resulted in &lt;a href=&#34;http://xenbits.xen.org/xsa/advisory-123.html&#34;&gt;XSA 123&lt;/a&gt; . This post gives an overview about the root cause of the bug and a short description of exploitation challenges. A follow-up post will describe possible exploitation strategies in more detail.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Bug Hunting for the Man on the Street</title>
      <link>https://insinuator.net/2015/03/bug-hunting-for-the-man-on-the-street/</link>
      <pubDate>Tue, 03 Mar 2015 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2015/03/bug-hunting-for-the-man-on-the-street/</guid>
      <description>&lt;p&gt;This is a guest post from Vladimir Wolstencroft, to provide some details of his upcoming &lt;a href=&#34;https://www.troopers.de/events/troopers15/499_bug_hunting_for_the_man_on_the_street/&#34;&gt;#TR15 talk&lt;/a&gt;.&lt;/p&gt;&#xA;&lt;p&gt;What do you get when you combine a security appliance vendor, a bug bounty program, readily available virtualised machines, a lack of understanding of best security practices and broken crypto?&lt;br&gt;&#xA;Ownage, a good story and maybe even that bounty…&lt;/p&gt;&#xA;&lt;p&gt;Focusing on Barracuda’s numerous security appliances, this talk will detail bug hunting methods and the principles used to examine these machines:&lt;br&gt;&#xA;Starting with a black box test and the challenges that this approach poses, to decrypting the firmware, getting system root, bricking the box, fighting the (de)activation methods, getting system root again, DOS’ing the VM host and finally using Barracuda’s own source code to find those vulnerabilities that otherwise would be invisible or impossible to find! There were also some unexpected outcomes that followed…&lt;/p&gt;</description>
    </item>
    <item>
      <title>The Dangers of x86 Emulation: Xen XSA 110 and 105</title>
      <link>https://insinuator.net/2015/02/the-dangers-of-x86-emulation-xen-xsa-110-and-105/</link>
      <pubDate>Mon, 23 Feb 2015 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2015/02/the-dangers-of-x86-emulation-xen-xsa-110-and-105/</guid>
      <description>&lt;p&gt;&lt;img src=&#34;http://www.insinuator.net/wp-content/uploads/2015/02/xen-300x81.png&#34; alt=&#34;Xen Logo&#34;&gt;&lt;/p&gt;&#xA;&lt;p&gt;Developing a secure and feature rich hypervisor is no easy task. Recently, the open source Xen hypervisor was affected by two interesting vulnerabilities involving its x86 emulation code: &lt;a href=&#34;http://xenbits.xen.org/xsa/advisory-110.html&#34;&gt;XSA 110&lt;/a&gt; and &lt;a href=&#34;http://xenbits.xen.org/xsa/advisory-105.html&#34;&gt;XSA 105&lt;/a&gt;. Both bugs show that the attack surface of hypervisors is often larger than expected. XSA 105 was &lt;a href=&#34;//labs.bitdefender.com/wp-content/uploads/downloads/2014/10/Gaining-kernel-privileges-using-the-Xen-emulator.pdf&#34;&gt;originally reported&lt;/a&gt;) by Andrei Lutas from BitDefender. The patch adds missing privilege checks to the emulation routines of several critical system instructions including LGDT and LIDT. The vulnerable code can be reached from unprivileged user code running inside hardware virtual machine (HVM) guests and can be used to escalate guest privileges. XSA 110 was reported by Jan Beulich from SUSE and concerns insufficient checks when emulating long jumps, calls or returns.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Evasion of Cisco ACLs by (Ab)Using IPv6 &amp; Discussion of Mitigation Techniques</title>
      <link>https://insinuator.net/2015/01/evasion-of-cisco-acls-by-abusing-ipv6-discussion-of-mitigation-techniques/</link>
      <pubDate>Wed, 28 Jan 2015 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2015/01/evasion-of-cisco-acls-by-abusing-ipv6-discussion-of-mitigation-techniques/</guid>
      <description>&lt;p&gt;This is a guest post of &lt;a href=&#34;https://twitter.com/antoniosatlasis&#34;&gt;Antonios Atlasis&lt;/a&gt;.&lt;/p&gt;&#xA;&lt;p&gt;During our blogpost regarding &lt;a href=&#34;http://www.insinuator.net/2015/01/dhcpv6-guard-do-it-like-ra-guard-evasion/&#34;&gt;&lt;em&gt;DHCPv6 Guard evasion&lt;/em&gt;&lt;/a&gt;, one of the side-effects was that Access Control Lists (ACLs) configured to block access to UDP ports 546 can be evaded by abusing (again) IPv6 Extension headers. Having that in mind, we decided to check the effectiveness of Cisco IPv6 ACLs under various scenarios. Our goal was to examine whether the IPv6 ACLs of Cisco routers can be evaded, as well as under which conditions this can take place. To this end, several representative scenarios from enterprise environments or other potential ones are examined.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Riding the Z-Wave, Part 1</title>
      <link>https://insinuator.net/2015/01/riding-the-z-wave-part-1/</link>
      <pubDate>Tue, 20 Jan 2015 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2015/01/riding-the-z-wave-part-1/</guid>
      <description>&lt;p&gt;Simple everyday work dialog:&lt;br&gt;&#xA;“The heater in the basement is still missing a proper thermostat, the ‘binary solution’ isn’t that effective”&lt;br&gt;&#xA;–  “Buy one…”&lt;br&gt;&#xA;–  “Ok”&lt;br&gt;&#xA;–  “Get one you can break…”&lt;br&gt;&#xA;– “Ok, but then I’d like a few tools, too”&lt;br&gt;&#xA;– “Go for it.”&lt;br&gt;&#xA;(That’s the way work should be!)&lt;br&gt;&#xA;Result of the dialog: a &lt;a href=&#34;http://radiatorthermostats.danfoss.com/products/living-by-Danfoss/living-connect/%20&#34;&gt;Danfoss Living Connect Z ( 014G0013 )&lt;/a&gt; and a &lt;a href=&#34;http://www.ti.com/tool/cc1110dk-mini-868&#34;&gt;TI CC1100 Wireless Mini Dev Kit&lt;/a&gt; plus a copy of &lt;a href=&#34;https://code.google.com/p/z-force/&#34;&gt;Z-Force&lt;/a&gt; to start with.&lt;br&gt;&#xA;&lt;em&gt;Goal: Talk to the thermostat!&lt;/em&gt;&lt;/p&gt;</description>
    </item>
    <item>
      <title>(In-)secure SD cards on WP8.1</title>
      <link>https://insinuator.net/2015/01/in-secure-sd-cards-on-wp8.1/</link>
      <pubDate>Thu, 15 Jan 2015 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2015/01/in-secure-sd-cards-on-wp8.1/</guid>
      <description>&lt;p&gt;During our first year of testing Windows Phone 8 applications we had yet another, let’s say: “surprising” finding. It all started with the first approaches on pentesting mobile applications on that  new and rather closed platform. Lacking jailbreak, root, and similar approaches we had a closer look at alternate approaches to have a look at an apps interior. We quickly hooked onto using modified firmwares (with deeper system access) and found a perfect solution in a little flaw concerning the handling of SD cards in WP8.1. A flaw that was, sadly for us, fixed silently….&lt;/p&gt;</description>
    </item>
    <item>
      <title>Telco Research 2015</title>
      <link>https://insinuator.net/2015/01/telco-research-2015/</link>
      <pubDate>Fri, 02 Jan 2015 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2015/01/telco-research-2015/</guid>
      <description>&lt;p&gt;Hello and a happy new year 2015 to everybody!&lt;/p&gt;&#xA;&lt;p&gt;As follow up of our 2014 talk &lt;a href=&#34;http://www.insinuator.net/2014/10/lte-vs-darwin-hackers-to-hackers-conference-11/&#34;&gt;“LTE vs. Darwin&lt;/a&gt;” I want to inform you about our telco research in 2015. We are currently dealing with the so called IP Multimedia Subsystem (IMS), which handles the call and media logic of 4G telecommunication networks. This network part provides functions like VoIP (or VoLTE) and takes care of the interconnection to other call or media related networks.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Revisiting an Old Friend: Shell Globbing</title>
      <link>https://insinuator.net/2014/12/revisiting-an-old-friend-shell-globbing/</link>
      <pubDate>Tue, 23 Dec 2014 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2014/12/revisiting-an-old-friend-shell-globbing/</guid>
      <description>&lt;p&gt;One interesting observation we make when testing complex environments is that at the bottom of huge technology stacks, there is usually a handful of shell scripts doing interesting stuff. More often than not these helper scripts are started as part of cron jobs running as root and perform basic administrative tasks like compressing and copying log files or deleting leftover files in temporary directories. Of course, these high privileges make them an interesting target for privilege escalation attacks and one class of vulnerability we reliably encounter in shell scripts is unsafe handling of globbing or filename expansions.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Getting 20k Inline-QR-Codes out of Burp</title>
      <link>https://insinuator.net/2014/12/getting-20k-inline-qr-codes-out-of-burp/</link>
      <pubDate>Fri, 19 Dec 2014 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2014/12/getting-20k-inline-qr-codes-out-of-burp/</guid>
      <description>&lt;p&gt;Lately we had to analyze QR-Codes in a pentest. Those held some random data which was used as a token for login and we wanted to know if that data was really random.&lt;/p&gt;&#xA;&lt;p&gt;If you ever worked with the Burp Suite you may know the Burp Sequencer, which offers some statistical analysis regarding the randomness of tokens which appear in requests (you just have to tell Burp what or where the token is). In our case the QR-Code was delivered as an inline-image in HTML to the browser, like this:&lt;/p&gt;</description>
    </item>
    <item>
      <title>Penetration Testing Tools that (do not) Support IPv6</title>
      <link>https://insinuator.net/2014/12/penetration-testing-tools-that-do-not-support-ipv6/</link>
      <pubDate>Thu, 11 Dec 2014 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2014/12/penetration-testing-tools-that-do-not-support-ipv6/</guid>
      <description>&lt;p&gt;We just released a white paper authored by &lt;a href=&#34;https://twitter.com/AntoniosAtlasis&#34;&gt;Antonios Atlasis&lt;/a&gt; that provides an overview which pentesting tools currently support IPv6 and how to (still) use them if that’s not the case. It can be found &lt;a href=&#34;https://www.ernw.de/category/newsletter/index.html&#34;&gt;in our newsletter section&lt;/a&gt;.&lt;/p&gt;&#xA;&lt;p&gt;Best&lt;/p&gt;&#xA;&lt;p&gt;Enno&lt;/p&gt;</description>
    </item>
    <item>
      <title>Scal(e)ing down Privacy</title>
      <link>https://insinuator.net/2014/11/scaleing-down-privacy/</link>
      <pubDate>Sat, 22 Nov 2014 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2014/11/scaleing-down-privacy/</guid>
      <description>&lt;p&gt;As you might know we are continuously doing &lt;a href=&#34;http://www.insinuator.net/2013/11/medical-device-security/&#34; title=&#34;Medical Devices&#34;&gt;research on medical devices&lt;/a&gt;. I presented some of the new results at &lt;a href=&#34;http://www.powerofcommunity.net/index.html&#34; title=&#34;Power of Community 2014&#34;&gt;Power of Community 2014&lt;/a&gt; last week and we thought we would share some of the details with you here. The focus of the previous work was testing medical devices that are used in hospitals like patient monitors, syringe pumps or even MRIs. This time we looked at a device that every user can use at home and which is available to anyone on the market: A smart scale.&lt;/p&gt;</description>
    </item>
    <item>
      <title>GitHub Enterprise 2.0.0 Fixes Multiple Vulnerabilities</title>
      <link>https://insinuator.net/2014/11/github-enterprise-2.0.0-fixes-multiple-vulnerabilities/</link>
      <pubDate>Mon, 17 Nov 2014 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2014/11/github-enterprise-2.0.0-fixes-multiple-vulnerabilities/</guid>
      <description>&lt;p&gt;Recently we had the pleasure to take a look at GitHub’s Enterprise appliance. The appliance allows one to deploy the excellent GitHub web interface locally to host code on-site. Besides the well known interface, which is similar to the one hosted at &lt;a href=&#34;https://github.com/&#34;&gt;github.com&lt;/a&gt;, the appliance ships with a separate interface called the management console, which is used for administrative tasks like the configuration of the appliance itself. This management interface is completely decoupled from the user interface.&lt;/p&gt;</description>
    </item>
    <item>
      <title>A “Please, Don’t Waste my Time” Approach and the Sourcefire/Snort Evasion</title>
      <link>https://insinuator.net/2014/10/a-please-dont-waste-my-time-approach-and-the-sourcefire/snort-evasion/</link>
      <pubDate>Sat, 18 Oct 2014 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2014/10/a-please-dont-waste-my-time-approach-and-the-sourcefire/snort-evasion/</guid>
      <description>&lt;p&gt;This is a guest post from &lt;a href=&#34;http://www.secfu.net/about-me/&#34;&gt;Antonios Atlasis&lt;/a&gt;.&lt;/p&gt;&#xA;&lt;p&gt;Yesterday we (Rafael Schaefer, Enno and me) had the pleasure to deliver together our talk at BlackHat Europe 2014 named &lt;a href=&#34;https://www.blackhat.com/eu-14/briefings.html#evasion-of-high-end-idps-devices-at-the-ipv6-era&#34;&gt;Evasion of High-End IDPS Devices at the IPv6 Era&lt;/a&gt; (by the way, latest slides can be found &lt;a href=&#34;https://www.ernw.de/download/Atlasis_Rey_Schaefer_BHEU_2014_Evasion_of_HighEnd_IPS_Devices.pdf&#34;&gt;here&lt;/a&gt; and the white paper &lt;a href=&#34;https://www.ernw.de/download/eu-14-Atlasis-Rey-Schaefer-briefings-Evasion-of-HighEnd-IPS-Devices-wp.pdf&#34;&gt;here&lt;/a&gt;). In this talk we summarised all the IDPS evasion techniques that we have found so far. At previous blogposts I had the chance to describe how to evade &lt;a href=&#34;http://www.insinuator.net/2014/08/evading-idps-by-combining-ipv6-extension-headers-and-fragmentation-features-the-story-of-my-life/&#34;&gt;Suricata&lt;/a&gt; and &lt;a href=&#34;http://www.insinuator.net/2014/05/a-novel-way-of-abusing-ipv6-extension-headers-to-evade-ipv6-security-devices/&#34;&gt;TippingPoint&lt;/a&gt;. In this post I am going to describe some other techniques that can be used to evade &lt;a href=&#34;https://www.snort.org/&#34;&gt;Snort&lt;/a&gt;, and its companion commercial version, &lt;a href=&#34;http://www.sourcefire.com/&#34;&gt;Sourcefire&lt;/a&gt;. The tool used to evade these IDPS is –  what else – &lt;a href=&#34;http://www.insinuator.net/2014/10/chiron-an-all-in-one-ipv6-penetration-testing-framework/&#34;&gt;Chiron&lt;/a&gt;.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Chiron – An All-In-One IPv6 Penetration Testing Framework</title>
      <link>https://insinuator.net/2014/10/chiron-an-all-in-one-ipv6-penetration-testing-framework/</link>
      <pubDate>Sat, 04 Oct 2014 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2014/10/chiron-an-all-in-one-ipv6-penetration-testing-framework/</guid>
      <description>&lt;p&gt;This is a guest post from &lt;a href=&#34;http://www.secfu.net/about-me/&#34;&gt;Antonios Atlasis&lt;/a&gt;.&lt;/p&gt;&#xA;&lt;p&gt;Last week I had the pleasure to give you my impressions regarding my experience about &lt;a href=&#34;http://www.insinuator.net/2014/09/hacking-for-a-b33r-at-ghent/&#34;&gt;&lt;em&gt;hacking for b33r at Ghent&lt;/em&gt;&lt;/a&gt;, that is, my participation at &lt;a href=&#34;http://2014.brucon.org/&#34;&gt;&lt;em&gt;BruCON 2014&lt;/em&gt;&lt;/a&gt; hacking conference. As I said among else, the reason that I was there was to present &lt;a href=&#34;http://www.secfu.net/tools-scripts/&#34;&gt;&lt;em&gt;Chiron&lt;/em&gt;&lt;/a&gt;, my IPv6 penetration testing/security assessment framework, which was supported by the &lt;a href=&#34;http://blog.brucon.org/2013/12/2014-5by5-announcement.html&#34;&gt;&lt;em&gt;Brucon 5×5&lt;/em&gt;&lt;/a&gt; program. The first version of &lt;em&gt;Chiron&lt;/em&gt; had been presented at &lt;a href=&#34;https://www.troopers.de/troopers14/troopers14-ipv6-security-summit-2014/troopers14-ipv6-security-summit-2014-workshop-an-all-in-one-advanced-ipv6-testing-framework/index.html&#34;&gt;Troopers 14&lt;/a&gt;, during the &lt;a href=&#34;https://www.troopers.de/troopers14/troopers14-ipv6-security-summit-2014/index.html&#34;&gt;&lt;em&gt;IPv6 Security Summit&lt;/em&gt;&lt;/a&gt;.&lt;/p&gt;</description>
    </item>
    <item>
      <title>ERNW’s Top 9 Burp Plugins</title>
      <link>https://insinuator.net/2014/08/ernws-top-9-burp-plugins/</link>
      <pubDate>Mon, 25 Aug 2014 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2014/08/ernws-top-9-burp-plugins/</guid>
      <description>&lt;p&gt;In the context of an internal evaluation, we recently had a look at most of the burp plugins available from the BApp store. The following overview represents our personal top 9 plugins, categorized in “Scanner Extensions”, “Manual Testing” and “Misc” in alphabetic order:&lt;/p&gt;&#xA;&lt;p&gt;&lt;strong&gt;Scanner Extensions&lt;/strong&gt;&lt;/p&gt;&#xA;&lt;p&gt;ActiveScan++&lt;/p&gt;&#xA;&lt;p&gt;This plugin adds some tests for Dynamic code injection, &lt;a href=&#34;http://carlos.bueno.org/2008/06/host-header-injection.html&#34; title=&#34;Host header attacks&#34;&gt;Host header attacks&lt;/a&gt; (&lt;a href=&#34;http://www.skeletonscribe.net/2013/05/practical-http-host-header-attacks.html&#34; title=&#34;Password reset poisoning&#34;&gt;password reset poisoning&lt;/a&gt;, &lt;a href=&#34;https://www.owasp.org/index.php/Cache_Poisoning&#34; title=&#34;cache poisoning&#34;&gt;cache poisoning&lt;/a&gt;, DNS rebinding), OS command injection and &lt;a href=&#34;http://www.thespanner.co.uk/2014/03/21/rpo/&#34; title=&#34;Relative path overwrite&#34;&gt;Relative path overwrite&lt;/a&gt;. In some internal tests, it seemed to deliver what it promises.&lt;/p&gt;</description>
    </item>
    <item>
      <title>HackRF One the story continues…</title>
      <link>https://insinuator.net/2014/08/hackrf-one-the-story-continues/</link>
      <pubDate>Wed, 20 Aug 2014 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2014/08/hackrf-one-the-story-continues/</guid>
      <description>&lt;p&gt;Hello fellow frequency hoppers,&lt;/p&gt;&#xA;&lt;p&gt;once again, we welcomed Michael Ossmann at the ERNW headquarters for fun with SDR. This time with Mike´s advanced SDR workshop. And to be up front about it…it was plain awesome. For everybody who is not familiar with Software Defined Radio (SDR): Let’s regard it as the ultimate tool when working with radio signals. Take a look a &lt;a href=&#34;http://www.insinuator.net/2013/08/hack-rf/#more-2539&#34; title=&#34;HackRF&#34;&gt;this&lt;/a&gt; to learn more.&lt;/p&gt;&#xA;&lt;p&gt;Mike showed us the new revision of his HackRF One and explained us some more advanced techniques when it comes to Radio Frequnecies hacking. Compared to last time, the workshop focused on reversing signals and how to synthesize them. So this time we were crafting RF packets ourselves instead of just replaying a capture. This introduces different attack types which can be carried out over the air for  example bruteforcing or fuzzing of radio devices.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Some notes on VMware vCenter Operations Manager</title>
      <link>https://insinuator.net/2014/08/some-notes-on-vmware-vcenter-operations-manager/</link>
      <pubDate>Tue, 12 Aug 2014 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2014/08/some-notes-on-vmware-vcenter-operations-manager/</guid>
      <description>&lt;p&gt;While fairytales often start with “Once upon a time…”, our blogposts often start with “During a recent security assessment…” — and so does this one. This time we were able to spend some time on VMware’s &lt;a href=&#34;http://www.vmware.com/products/vcenter-operations-manager&#34;&gt;vCenter Operations Manager&lt;/a&gt; (herein short: VCOPS). VCOPS is a monitoring solution for load and health of your vSphere environment. In order to provide this service, two virtual machines (analytics engine and Web-based UI) must be deployed (as a so-called vApp) that are configured on startup by various scripts (mainly /usr/lib/vmware-vcops/user/conf/install/firstbootcommon.sh) to match the actual environment and communicate via an OpenVPN tunnel that is established directly between the two machines. To gather the monitoring data, read-only access to the vCenter is required.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Evading IDPS by Combining IPv6 Extension Headers and Fragmentation “Features” – The Story of My Life…</title>
      <link>https://insinuator.net/2014/08/evading-idps-by-combining-ipv6-extension-headers-and-fragmentation-features-the-story-of-my-life/</link>
      <pubDate>Sat, 09 Aug 2014 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2014/08/evading-idps-by-combining-ipv6-extension-headers-and-fragmentation-features-the-story-of-my-life/</guid>
      <description>&lt;p&gt;This is a guest post from &lt;a href=&#34;http://www.secfu.net/about-me/&#34;&gt;Antonios Atlasis&lt;/a&gt;.&lt;/p&gt;&#xA;&lt;p&gt;In the “&lt;a href=&#34;http://www.insinuator.net/2014/05/a-novel-way-of-abusing-ipv6-extension-headers-to-evade-ipv6-security-devices/&#34;&gt;A Novel Way of Abusing IPv6 Extension Headers to Evade IPv6 Security Devices&lt;/a&gt;” blogpost I described a way to evade a high-end commercial IDPS device, the Tipping Point IDPS (TOS Tipping Point, Package 3.6.1.4036 and vaccine 3.2.0.8530 digital), by abusing a minor detail at the IPv6 specification. As I promised at the end of that blogpost, this is not the end. In this blogpost I am going to describe several new and different ways of evading another popular IDPS, an open-source one this time, &lt;a href=&#34;http://suricata-ids.org/&#34;&gt;Suricata&lt;/a&gt;.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Cisco Cloud Services Router 1000V and the Virtual Matryoshka</title>
      <link>https://insinuator.net/2014/07/cisco-cloud-services-router-1000v-and-the-virtual-matryoshka/</link>
      <pubDate>Mon, 28 Jul 2014 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2014/07/cisco-cloud-services-router-1000v-and-the-virtual-matryoshka/</guid>
      <description>&lt;p&gt;Recently we started playing around with Cisco’s virtual router, the CSR 1000V, while doing some protocol analysis. We found Cisco offering an BIN file for download (alternatively there is an ISO file which contains a GRUB boot loader and the BIN file, or an OVA file which contains a virtual machine description and the ISO file) and file(1) identifies it as DOS executable:&lt;/p&gt;&#xA;&lt;pre tabindex=&#34;0&#34;&gt;&lt;code&gt;$ file csr1000v-universalk9.03.12.00.S.154-2.S-std.SPA.bin &#xA;    csr1000v-universalk9.03.12.00.S.154-2.S-std.SPA.bin: DOS executable (COM)&lt;/code&gt;&lt;/pre&gt;&#xA;&lt;p&gt;We didn’t manage to get the file running, neither in a (Free-)DOS environment, nor in a wine virtual DOS environment, except using the boot loader from the ISO file. So we became curious as for the structure and ingredients of the file.&lt;/p&gt;</description>
    </item>
    <item>
      <title>New Tool: s1ap_enum</title>
      <link>https://insinuator.net/2014/06/new-tool-s1ap_enum/</link>
      <pubDate>Wed, 25 Jun 2014 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2014/06/new-tool-s1ap_enum/</guid>
      <description>&lt;p&gt;As we continue our research in the 3GPP protocol world, there is a new tool for you to play with. It is called &lt;strong&gt;s1ap_enum&lt;/strong&gt; and thats also what it does  😉&lt;/p&gt;&#xA;&lt;p&gt;The tool itself is written in erlang, as i found no other free ASN.1 parser that is able to parse those fancy 3GPP protocol specs. It connects to an MME on sctp/36412 and tries to initiate a S1AP session by sending an S1SetupRequest PDU. To establish a S1AP session with an MME the right MCC and MNC are needed in the PLMNIdentity. The tool tries to guess the right MCC/MNC combinations. It comes with a preset of known MCC/MNC pairs from &lt;a href=&#34;http://www.mcc-mnc.com/&#34;&gt;mcc-mnc.com&lt;/a&gt;, but can try all other combinations as well.&lt;/p&gt;</description>
    </item>
    <item>
      <title>A Novel Way of Abusing IPv6 Extension Headers to Evade IPv6 Security Devices</title>
      <link>https://insinuator.net/2014/05/a-novel-way-of-abusing-ipv6-extension-headers-to-evade-ipv6-security-devices/</link>
      <pubDate>Mon, 26 May 2014 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2014/05/a-novel-way-of-abusing-ipv6-extension-headers-to-evade-ipv6-security-devices/</guid>
      <description>&lt;p&gt;(Or How the Smallest Detail Can Make a Difference)&lt;/p&gt;&#xA;&lt;p&gt;This is a guest post from &lt;a href=&#34;http://www.secfu.net/&#34;&gt;Antonios Atlasis&lt;/a&gt;.&lt;/p&gt;&#xA;&lt;p&gt; &lt;/p&gt;&#xA;&lt;p&gt;As it is well known to the IPv6 enthusiasts, one of the most significant changes that IPv6 brings with it, apart from supporting a really huge address space, is the improved support for Extensions and Options, which is achieved by the usage of IPv6 Extension headers. According to &lt;a href=&#34;http://www.rfc-editor.org/rfc/rfc2460.txt&#34;&gt;RFC 2460&lt;/a&gt;, “&lt;em&gt;changes in the way IP header options are encoded allows for more efficient forwarding, less stringent limits on the length of options, and greater flexibility for introducing new options in the future&lt;/em&gt;.” So, by adding IPv6 Extension headers, according to the designers of the protocol, flexibility and efficiency in the IP layer is improved.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Django Image Validation Vulnerability</title>
      <link>https://insinuator.net/2014/05/django-image-validation-vulnerability/</link>
      <pubDate>Fri, 16 May 2014 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2014/05/django-image-validation-vulnerability/</guid>
      <description>&lt;p&gt;Hi!&lt;/p&gt;&#xA;&lt;p&gt;In the course of a recent penetration test, we came across an Image validation vulnerability in Django when using the &lt;a href=&#34;http://www.pythonware.com/products/pil/&#34;&gt;Python-Imaging-Library (PIL)&lt;/a&gt; which we want to explain in this post.&lt;/p&gt;&#xA;&lt;p&gt;Everybody who doesn’t know what &lt;a href=&#34;https://www.djangoproject.com/&#34;&gt;Django&lt;/a&gt; and/or the PIL is:&lt;br&gt;&#xA;Django is a framework to create web applications with Python (comparable to Rails or Zend). The PIL is a powerful standard python library which provides a toolset to modify, display and verify images of many different formats.&lt;/p&gt;</description>
    </item>
    <item>
      <title>The Role of VGX.DLL in the Context of the Latest IE 0-Day</title>
      <link>https://insinuator.net/2014/05/the-role-of-vgx.dll-in-the-context-of-the-latest-ie-0-day/</link>
      <pubDate>Tue, 13 May 2014 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2014/05/the-role-of-vgx.dll-in-the-context-of-the-latest-ie-0-day/</guid>
      <description>&lt;p&gt;On Saturday, April 26 Microsoft announced that Internet Explorer version 6 until version 11 is under potential risk against drive-by attacks from malicious websites, regardless of the underlying Microsoft operating system and the associated memory protection features integrated with the operating system. Microsoft has assigned CVE-2014-1776 to this unknown use-after-free vulnerability, which in the worst case could allow remote code execution if a user views a specially crafted website. If an attacker successfully exploits this vulnerability, s/he will gain the same rights and privileges as the current user (once again, activated User Account Control [UAC] helps keeping privileges of the user low).&lt;/p&gt;</description>
    </item>
    <item>
      <title>Bruting Android Pins</title>
      <link>https://insinuator.net/2014/05/bruting-android-pins/</link>
      <pubDate>Fri, 02 May 2014 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2014/05/bruting-android-pins/</guid>
      <description>&lt;p&gt;Hi there,&lt;/p&gt;&#xA;&lt;p&gt;a few weeks ago I held a talk at &lt;a href=&#34;http://unfuck.eu/2014/&#34; title=&#34;UnFUCK&#34;&gt;UnFUC&lt;/a&gt;K, a small University con from students for students. I had decided to give a short talk on “Owning Stuff via USB” aka how to use our TR14 &lt;a href=&#34;http://www.insinuator.net/2014/03/a-troopers-keyboard/&#34; title=&#34;Badge&#34;&gt;Badge&lt;/a&gt;! During the preparations and while building my demos, I tested my new &lt;a href=&#34;http://hakshop.myshopify.com/collections/usb-rubber-ducky&#34; title=&#34;USB RubberDucky&#34;&gt;USB RubberDucky&lt;/a&gt;. One rather “trivial” demo was actually to use it as a keyboard on an Android phone.&lt;/p&gt;&#xA;&lt;p&gt;Android has been able to use the &lt;a href=&#34;http://en.wikipedia.org/wiki/USB_On-The-Go&#34; title=&#34;USB OTG&#34;&gt;USB OTG&lt;/a&gt; features for quite a while now, where most people enjoy being able to connect a USB stick to a phone, some others might have already used a keyboard on a tablet. OTG enables a USB device to play master and hence connect two USB devices to each other. For this the fifth PIN on a micro USB cable is used (it’s simply pulled down to ground). To be able to use USB OTG you both need a special cable (micro USB to female USB A) and a master device with all the necessary drivers. Depending on the Android device and the client (USB stick/HDD, keyboard) you want to connect you might need a rooted phone.When trying the RubberDucky on Android for the first time, I had a S3, a Nexus 4, a Nexus 5 and an SE Xperia Z1. All of these devices detected the Ducky as a keyboard and I was able to write stuff on the phone. But I hadn’t aimed at “just typing text”, I wanted to type numbers or rather PINs –&amp;gt; One can use the external keyboard while unlocking the device. The Ducky’s user guide contains an example script for bruteforcing PINs on Android. But how?&lt;br&gt;&#xA;Just type!&lt;/p&gt;</description>
    </item>
    <item>
      <title>How to Own a Router – Fritz!Box AVM Vulnerability Analysis</title>
      <link>https://insinuator.net/2014/03/how-to-own-a-router-fritzbox-avm-vulnerability-analysis/</link>
      <pubDate>Tue, 11 Mar 2014 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2014/03/how-to-own-a-router-fritzbox-avm-vulnerability-analysis/</guid>
      <description>&lt;p&gt;&lt;em&gt;The below post was originally written on February 9th as a little educational exercise &amp;amp; follow-up to my &lt;a href=&#34;http://www.insinuator.net/2013/07/reverse-engineering-tools/&#34;&gt;BinDiff&lt;/a&gt; post. (This research was actually triggered by a relative asking about that strange Fritz!Box vulnerability he heard about on the radio). Once we realized the full potential of the bug we decided against publishing the post and contacted several parties instead. Amongst others this contributed to the German BSI &lt;a href=&#34;https://www.bsi.bund.de/DE/Presse/Pressemitteilungen/Presse2014/Fritz-Box-Update_11022014.html&#34;&gt;press release&lt;/a&gt;. Given the &lt;a href=&#34;http://www.heise.de/security/meldung/Hack-gegen-AVM-Router-Fritzbox-Luecke-offengelegt-Millionen-Router-in-Gefahr-2136784.html&#34;&gt;cat is out of the bag&lt;/a&gt; now anyway, we see no reason to hold it back. We will further take this as an opportunity to lay out our basic vulnerability disclosure principles in a future post. This topic will also be discussed in the panel “Ethics of Security Work &amp;amp; Research” at &lt;a href=&#34;http://www.troopers.de&#34;&gt;Troopers&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;</description>
    </item>
    <item>
      <title>How to use Intel AMT and have some fun with Mainboards</title>
      <link>https://insinuator.net/2014/03/how-to-use-intel-amt-and-have-some-fun-with-mainboards/</link>
      <pubDate>Sat, 08 Mar 2014 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2014/03/how-to-use-intel-amt-and-have-some-fun-with-mainboards/</guid>
      <description>&lt;p&gt;I recently got in contact with &lt;a href=&#34;http://www.intel.com/content/www/us/en/architecture-and-technology/intel-active-management-technology.html&#34; title=&#34;Intel AMT&#34;&gt;Intel AMT&lt;/a&gt; for the first time. Surely I had heard about it, knew it was “dangerous”, it was kind of exploitable and had to be deactivated. But I hadn’t actually seen it myself. Well, now I have, and I simply love it and you will probably, too (and don’t forget: love and hate are very very close to each other 😉 )&lt;br&gt;&#xA;The following blogpost will be a set of features and instructions on how to own a device with an unconfigured copy of Intel AMT without using any complicated hacks or the famous magic!&lt;/p&gt;</description>
    </item>
    <item>
      <title>A Short Teaser on My New IPv6 Testing Framework</title>
      <link>https://insinuator.net/2014/02/a-short-teaser-on-my-new-ipv6-testing-framework/</link>
      <pubDate>Fri, 21 Feb 2014 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2014/02/a-short-teaser-on-my-new-ipv6-testing-framework/</guid>
      <description>&lt;h1 id=&#34;this-is-a-guest-post-from-antonios-atlasis&#34;&gt;This is a guest post from Antonios Atlasis&lt;/h1&gt;&#xA;&lt;p&gt; &lt;/p&gt;&#xA;&lt;p&gt;Hi,&lt;/p&gt;&#xA;&lt;p&gt;my name is Antonios and I am an independent IT Security Researcher from Greece. One of my latest “hobbies” is IPv6 and its potential insecurities so, please let me talk to you about my latest experience on this.&lt;/p&gt;&#xA;&lt;p&gt;This week, I had the opportunity to work together with the ERNW guys at their premises. They had built an IPv6 lab that included several commercial IPv6 security devices (firewalls, IDS/IPS and some high-end switches) and they kindly offered their lab to me to play with (thank you guys 🙂 – I always liked …expensive toys). The goal of this co-operation was two-fold: First, to test my new (not yet released) IPv6 pen-testing tool and secondly, to try to find out any IPv6-related security or operational issues on these devices (after all, they all claim that they are “IPv6-Ready”, right?).&lt;/p&gt;</description>
    </item>
    <item>
      <title>Fresh Meat From the Coding Front</title>
      <link>https://insinuator.net/2014/02/fresh-meat-from-the-coding-front/</link>
      <pubDate>Thu, 20 Feb 2014 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2014/02/fresh-meat-from-the-coding-front/</guid>
      <description>&lt;p&gt;Within the last months I had some time to work on my code and today I’m releasing some of that: a new version of dizzy as well as two new loki modules.&lt;/p&gt;&#xA;&lt;h2 id=&#34;new-version-of-dizzy&#34;&gt;New version of dizzy:&lt;/h2&gt;&#xA;&lt;p&gt;Download version 0.8.2 &lt;a href=&#34;http://c0decafe.de/tools/dizzy-0.8.2.tar.bz2&#34;&gt;here&lt;/a&gt;.&lt;/p&gt;&#xA;&lt;h3 id=&#34;usb-target-support&#34;&gt;USB target support&lt;/h3&gt;&#xA;&lt;p&gt;Dizzy is able to use neighbor travis’ &lt;a href=&#34;http://goodfet.sourceforge.net/hardware/facedancer21/&#34; title=&#34;facedancer&#34;&gt;facedancer&lt;/a&gt; to emulate a client device. Two fuzzing modes are available for USB descriptor fuzzing and USB endpoint fuzzing.&lt;/p&gt;&#xA;&lt;p&gt;Here is an example cmd to start usb configuration descriptor fuzzing:&lt;/p&gt;</description>
    </item>
    <item>
      <title>Analyzing a CVE-2013-3346/CVE-2013-5065 Exploit with peepdf</title>
      <link>https://insinuator.net/2014/02/analyzing-a-cve-2013-3346/cve-2013-5065-exploit-with-peepdf/</link>
      <pubDate>Mon, 10 Feb 2014 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2014/02/analyzing-a-cve-2013-3346/cve-2013-5065-exploit-with-peepdf/</guid>
      <description>&lt;p&gt;This is a guest post from Jose Miguel Esparza (&lt;a href=&#34;https://twitter.com/EternalTodo&#34;&gt;@EternalTodo&lt;/a&gt;)&lt;/p&gt;&#xA;&lt;p&gt; &lt;/p&gt;&#xA;&lt;p&gt;There are already some good blog posts talking about this exploit, but I think this is a really good example to show how &lt;a href=&#34;http://peepdf.eternal-todo.com/&#34;&gt;&lt;em&gt;peepdf&lt;/em&gt;&lt;/a&gt; works and what you can learn if you attend the workshop &lt;a href=&#34;https://www.troopers.de/troopers14/troopers14-1-day-workshop-squeezing-exploit-kits-and-pdf-exploits/index.html&#34;&gt;&lt;em&gt;“Squeezing Exploit Kits and PDF Exploits”&lt;/em&gt;&lt;/a&gt; at &lt;a href=&#34;https://www.troopers.de/troopers14/index.html&#34;&gt;Troopers14&lt;/a&gt;.  The mentioned exploit was using the &lt;a href=&#34;http://www.zerodayinitiative.com/advisories/ZDI-13-212/&#34;&gt;Adobe Reader ToolButton Use-After-Free&lt;/a&gt; vulnerability to execute code in the victim’s machine and then the &lt;a href=&#34;http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-5065&#34;&gt;Windows privilege escalation 0day&lt;/a&gt; to bypass the &lt;a href=&#34;http://cansecwest.com/slides/2013/Adobe%20Sandbox.pdf&#34;&gt;Adobe sandbox&lt;/a&gt; and execute a new payload without restrictions.&lt;/p&gt;</description>
    </item>
    <item>
      <title>XSS in SAP Netweaver</title>
      <link>https://insinuator.net/2014/01/xss-in-sap-netweaver/</link>
      <pubDate>Fri, 24 Jan 2014 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2014/01/xss-in-sap-netweaver/</guid>
      <description>&lt;p&gt;We just got &lt;a href=&#34;http://scn.sap.com/docs/DOC-8218&#34; title=&#34;Acknowledgments to Security Researchers&#34;&gt;credits&lt;/a&gt; for a flaw we found in SAP Netweaver. The issue is a reflected &lt;a href=&#34;https://www.owasp.org/index.php/Top_10_2013-A3-Cross-Site_Scripting_%28XSS%29&#34; title=&#34;OWASP Top 10 - XSS&#34;&gt;Cross-Site Scripting&lt;/a&gt; (XSS). It can be triggered in the administrative interface for the Internet Communication Manager (ICM) and Web Dispatcher. This means that the targets for this XSS will definitely be users with administrative privileges. This makes it especially juicy for an attacker.&lt;/p&gt;&#xA;&lt;p&gt;SAP rated the vulnerability with CVSS and a Base Score of 4.3 having a Base Vector of &lt;code&gt;AV:N/AC:M/AU:N/C:N/I:P/A:N&lt;/code&gt;. Which again opens the discussion on how to rate the impact of XSS by using CVSS. CVSS &lt;a href=&#34;http://www.first.org/cvss/cvss-guide#i3.1.1&#34; title=&#34;CVSS rating XSS&#34;&gt;states&lt;/a&gt; that XSS “&lt;em&gt;should be scored with no impact to confidentiality or availability, and partial impact to integrity&lt;/em&gt;“, which is clearly arguable. Especially when thinking of the impact on confidentiality. As you might know by now, we tried to tackle the problem of rating vulnerabilities ourselves with the &lt;a href=&#34;http://www.insinuator.net/2013/10/isse-2013-ernw-rapid-rating-system/&#34; title=&#34;ERRS&#34;&gt;ERNW Rapid Rating System&lt;/a&gt; (ERRS) and it was not an easy task. 😉 However, SAP states that this is a correction with high priority, so you should apply the patches as soon as possible.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Serial Port Debugging Between two Virtual Machines in VMware Fusion</title>
      <link>https://insinuator.net/2014/01/serial-port-debugging-between-two-virtual-machines-in-vmware-fusion/</link>
      <pubDate>Thu, 16 Jan 2014 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2014/01/serial-port-debugging-between-two-virtual-machines-in-vmware-fusion/</guid>
      <description>&lt;p&gt;In the course of our virtualization research, we came across a certain technical issue we couldn’t find an easy solution on knowledge bases and the like. However, as we found the question several times on the web, the following post gives just a short hint on a technical detail.&lt;/p&gt;&#xA;&lt;p&gt;If you want to connect two virtual machines in VMware Fusion using a serial port (e.g. for debugging purposes), Fusion doesn’t provide you an GUI option to configure that. However, if you just add the following config to the debugger system’s VMX file:&lt;/p&gt;</description>
    </item>
    <item>
      <title>Exploiting Hyper-V: How We Discovered MS13-092</title>
      <link>https://insinuator.net/2014/01/exploiting-hyper-v-how-we-discovered-ms13-092/</link>
      <pubDate>Tue, 14 Jan 2014 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2014/01/exploiting-hyper-v-how-we-discovered-ms13-092/</guid>
      <description>&lt;p&gt;During a recent research project we performed an in-depth security assessment of Microsoft’s virtualization technologies, including Hyper-V and Azure. While we already had experience in discovering security vulnerabilities in other virtual environments (e.g. &lt;a href=&#34;http://www.insinuator.net/2012/05/vmdk-has-left-the-building/&#34;&gt;here&lt;/a&gt; and &lt;a href=&#34;http://www.insinuator.net/2011/07/the-key-to-your-datacenter/&#34;&gt;here&lt;/a&gt;), this was our first research project on the Microsoft virtualization stack and we took care to use a &lt;a href=&#34;http://www.insinuator.net/2013/05/analysis-of-hypervisor-breakouts/&#34;&gt;structured evaluation strategy&lt;/a&gt; to cover all potential attack vectors.&lt;br&gt;&#xA;Part of our research concentrated on the Hyper-V hypervisor itself and we discovered a critical vulnerability which can be exploited by an unprivileged virtual machine to crash the hypervisor and potentially compromise other virtual machines on the same physical host. This bug was recently patched, see &lt;a href=&#34;https://technet.microsoft.com/en-us/security/bulletin/ms13-092&#34;&gt;MS13-092&lt;/a&gt; and our &lt;a href=&#34;http://www.insinuator.net/2014/01/state-of-virtualization-security-14/&#34;&gt;corresponding post&lt;/a&gt;.&lt;/p&gt;</description>
    </item>
    <item>
      <title>State of Virtualization Security ‘14</title>
      <link>https://insinuator.net/2014/01/state-of-virtualization-security-14/</link>
      <pubDate>Sun, 05 Jan 2014 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2014/01/state-of-virtualization-security-14/</guid>
      <description>&lt;p&gt;First of all, I hope you all had a good start to 2014. Having some time off “between the years” (which is a German saying for the time between Christmas and NYE), I caught up on several virtualization security topics.&lt;/p&gt;&#xA;&lt;p&gt;While virtualization is widely accepted as a sufficiently secure technology in many areas of IT operations (also for sensitive applications or exposed systems, like &lt;a href=&#34;http://www.insinuator.net/2009/12/some-reflections-on-virtualization-security-part-1/&#34;&gt;DMZs&lt;/a&gt;) by 2014, there are several recent vulnerabilities and incidents that are worth mentioning.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Medical Device Security</title>
      <link>https://insinuator.net/2013/11/medical-device-security/</link>
      <pubDate>Thu, 21 Nov 2013 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2013/11/medical-device-security/</guid>
      <description>&lt;p&gt;One of our guiding principles at ERNW is “Make the World a Safer Place”. There could not be a topic that matches this principle more than the security or insecurity of medical devices. This is why we started a research project that is looking at how vulnerable those devices are that might be deployed in hospitals around the world. Recently the U.S. Food and Drug Administration (FDA) has put out a &lt;a href=&#34;http://www.fda.gov/medicaldevices/safety/alertsandnotices/ucm356423.htm&#34; title=&#34;FDA recommendation&#34;&gt;recommendation&lt;/a&gt; concerning the security of medical devices. It recommends that “manufacturers and health care facilities take steps to assure that appropriate safeguards are in place to reduce the risk of failure due to cyberattack, which could be initiated by the introduction of malware into the medical equipment or unauthorized access to configuration settings in medical devices and hospital networks”. We thought that we should take a look at how manufacturers deal with security for these devices.&lt;/p&gt;</description>
    </item>
    <item>
      <title>pytacle – alpha2</title>
      <link>https://insinuator.net/2013/10/pytacle-alpha2/</link>
      <pubDate>Wed, 30 Oct 2013 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2013/10/pytacle-alpha2/</guid>
      <description>&lt;p&gt;Its been a long time, since i released the last version of pytacle, but now the time has come. Here is alpha2 with some new features:&lt;/p&gt;&#xA;&lt;p&gt;– Support of RTLSDR sticks&lt;br&gt;&#xA;– Possibility to scan for cells around you&lt;br&gt;&#xA;– Changed the code to generate real KCs (but as nobody noticed the wrong KCs i guess you were good with the others 😉&lt;/p&gt;&#xA;&lt;p&gt;Im also planning to address hopping channels in the future, but ive not made it far enough in my DSP lecture, yet 😉&lt;/p&gt;</description>
    </item>
    <item>
      <title>Some Security Impacts of HTML5 CORS or How to use a Browser as a Proxy</title>
      <link>https://insinuator.net/2013/08/some-security-impacts-of-html5-cors-or-how-to-use-a-browser-as-a-proxy/</link>
      <pubDate>Mon, 26 Aug 2013 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2013/08/some-security-impacts-of-html5-cors-or-how-to-use-a-browser-as-a-proxy/</guid>
      <description>&lt;p&gt;With HTML 5 the current web development moves from server side generated content and layout to client side generated. Most of the so called &lt;em&gt;HTML5 powered&lt;/em&gt; websites use JavaScript and CSS for generating beautiful looking and responsive user experiences. This ultimately leads to the point were developers want to include or request third-party resources. &lt;em&gt;Un&lt;/em&gt;fortunately all current browsers prevent scripts to request external resources through a security feature called the &lt;em&gt;Same-Origin-Policy&lt;/em&gt;. This policy specifies that client side code could only request resources from the domain being executed from. This means that a script from example.com can not load a resource from google.com via AJAX(XHR/XmlHttpRequest).&lt;/p&gt;</description>
    </item>
    <item>
      <title>Vulnerabilities &amp;amp; attack vectors of VPNs (Pt 1)</title>
      <link>https://insinuator.net/2013/08/vulnerabilities-amp-attack-vectors-of-vpns-pt-1/</link>
      <pubDate>Thu, 15 Aug 2013 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2013/08/vulnerabilities-amp-attack-vectors-of-vpns-pt-1/</guid>
      <description>&lt;p&gt;This is the first part of an article that will give an overview of known vulnerabilities and potential attack vectors against commonly used Virtual Private Network (VPN) protocols and technologies. This post will cover vulnerabilities and mitigation controls of the Point-to-Point Tunneling Protocol (PPTP) and IPsec. The second post will cover SSL-based VPNs like OpenVPN and the Secure Socket Tunneling Protocol (SSTP). As surveillance of Internet communications has become an important issue, besides the traditional goals of information security, typically referred as  confidentiality, integrity and authenticity, another security goal has become explicitly desirable: Perfect Forward Secrecy (PFS). PFS may be achieved if the initial session-key agreement generates unique keys for each session. This ensures that even if the private key would be compromised, older sessions (that one may have captured) can’t be decrypted. The concept of PFS will be covered in the second post.&lt;/p&gt;</description>
    </item>
    <item>
      <title>MFD Vulnerabilities</title>
      <link>https://insinuator.net/2013/08/mfd-vulnerabilities/</link>
      <pubDate>Wed, 07 Aug 2013 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2013/08/mfd-vulnerabilities/</guid>
      <description>&lt;p&gt;A recent &lt;a href=&#34;http://seclists.org/bugtraq/2013/Aug/28&#34;&gt;post&lt;/a&gt; describing some nasty vulnerabilities in HP &lt;a href=&#34;http://www.google.de/search?hl=en&amp;amp;site=imghp&amp;amp;tbm=isch&amp;amp;source=hp&amp;amp;biw=1276&amp;amp;bih=663&amp;amp;q=multifunction+device&amp;amp;oq=multifunction+device&amp;amp;gs_l=img.3..0j0i5j0i24l7.2450.5517.0.5606.20.15.0.4.4.0.99.959.15.15.0....0...1ac.1.24.img..1.19.973.43a2mDdYMDE&#34;&gt;multifunction devices&lt;/a&gt; (MFDs) brings back memories of a &lt;a href=&#34;https://www.troopers.de/wp-content/uploads/2011/04/TR11_Schaefer_Luft_Multifunction_devices.pdf&#34;&gt;presentation&lt;/a&gt; Micele and I gave at &lt;a href=&#34;https://www.troopers.de/archives/troopers11&#34;&gt;Troopers11&lt;/a&gt; on MFD security. The published vulnerabilities are highly relevant  (such as unauthenticated retrieval of administrative credentials) and reminded me of some of the basic recommendations we gave. MFD vulnerabilities are regularly discovered, and it is often basic stuff such as hardcoded $SECRET_INFORMATION (don’t get me wrong here, I fully appreciate the quality of the published research, but it is just surprising — let’s go with this attribute 😉 — that those types of vulnerabilities still occur that often). Yet many environments &lt;em&gt;do not&lt;/em&gt; patch their MFDs or implement other controls. As it is not an option to not use MFDs (they are already present in pretty much every environment, and the vast majority of vendors periodically suffer from vulnerabilities), let’s recall some of our recommendations as those would have mitigated the risk resulting from the published vulnerability:&lt;/p&gt;</description>
    </item>
    <item>
      <title>Cross-Site Request Forgery with Cross-Origin Resource Sharing</title>
      <link>https://insinuator.net/2013/08/cross-site-request-forgery-with-cross-origin-resource-sharing/</link>
      <pubDate>Fri, 02 Aug 2013 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2013/08/cross-site-request-forgery-with-cross-origin-resource-sharing/</guid>
      <description>&lt;p&gt;During one of our last projects in a large environment we encountered an interesting flaw. Although it was not possible to exploit it in this particular context, it’s worth to be mentioned here. The finding was about &lt;a href=&#34;https://www.owasp.org/index.php/CSRF&#34; title=&#34;OWASP CSRF&#34;&gt;Cross-Site Request Forgery&lt;/a&gt;, a quite well-known attack that forces a user to execute unintended actions within the authenticated context of a web application. With a little help of social engineering (like sending a link via email, chat, embedded code in documents, etc…) an attacker may force the user to execute actions of the attacker’s choice.&lt;/p&gt;</description>
    </item>
    <item>
      <title>SNMP Reflected Amplification DDoS Attacks</title>
      <link>https://insinuator.net/2013/07/snmp-reflected-amplification-ddos-attacks/</link>
      <pubDate>Wed, 31 Jul 2013 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2013/07/snmp-reflected-amplification-ddos-attacks/</guid>
      <description>&lt;p&gt;Just recently on the NANOG mailing list a discussion popped up titled “&lt;a href=&#34;http://mailman.nanog.org/pipermail/nanog/2013-July/060094.html&#34;&gt;SNMP DDoS: the vulnerability you might not know you have&lt;/a&gt;“.&lt;br&gt;&#xA;There’s a couple of points here:&lt;/p&gt;&#xA;&lt;p&gt;a) if you’re interested in the technical details of these attacks (and mitigation advice), pls see &lt;a href=&#34;http://www.bitag.org/documents/SNMP-Reflected-Amplification-DDoS-Attack-Mitigation.pdf&#34;&gt;this excellent technical&lt;/a&gt; report the Broadband Internet Technical Advisory Group published last year (apparently Comcast &lt;a href=&#34;ttp://corporate.comcast.com/comcast-voices/taking-steps-to-prevent-unintentional-network-abuse&#34;&gt;had observed&lt;/a&gt; such attacks before).&lt;/p&gt;&#xA;&lt;p&gt;b) Daniel and I gave a &lt;a href=&#34;https://www.ernw.de/download/ERNW_HITB_Dubai_2007_Attacking_SNMP.pdf&#34;&gt;talk on attacking SNMP&lt;/a&gt; at HITB Dubai 2007 (&lt;a href=&#34;http://conference.hitb.org/&#34;&gt;Hi Amy &amp;amp; Dhillon! 😉&lt;/a&gt;) laying out the basic idea for that type of attack and we later described it in a bit more detail at &lt;a href=&#34;http://www.shmoocon.org/shmoocon_2009&#34;&gt;ShmooCon 2009&lt;/a&gt; where we even demoed it publicly (camera recording stopped at that point, for obvious reasons). We used (a slightly modified version of) &lt;a href=&#34;https://www.ernw.de/download/snmpattack.pl&#34;&gt;this tool&lt;/a&gt;.&lt;br&gt;&#xA;From the research we did at the time we can confirm this was/presumably still is a huge problem, at least for European carriers’ broadband segments (acting as amplifiers).&lt;/p&gt;</description>
    </item>
    <item>
      <title>BlackBerry 10 USB Modes</title>
      <link>https://insinuator.net/2013/07/blackberry-10-usb-modes/</link>
      <pubDate>Tue, 23 Jul 2013 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2013/07/blackberry-10-usb-modes/</guid>
      <description>&lt;p&gt;So we got these shiny new BlackBerry Q10 and Z10 device laying on the desk one morning. It’s my first BlackBerry, I have to admit, but never the less, the hole wushy GUI and touchy glass stuff wasn’t my main concern, instead i &lt;a href=&#34;https://www.troopers.de/archives/troopers13/agenda13/troopers13-presentations/index.html#you_wouldnt_share&#34;&gt;took a look at the stuff&lt;/a&gt; going on while you connect the phone (do i have to call it blackberry? its a phone, isn’t it?) to your computer.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Reverse Engineering Tools Part 1: BinDiff</title>
      <link>https://insinuator.net/2013/07/reverse-engineering-tools-part-1-bindiff/</link>
      <pubDate>Mon, 08 Jul 2013 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2013/07/reverse-engineering-tools-part-1-bindiff/</guid>
      <description>&lt;p&gt;&lt;em&gt;When teaching courses on topics like Reverse Engineering or Malware Analysis we always emphasize the need to minimize unneeded work. Because reversing an unknown binary is a time consuming and complex process, tools that simplify the RE process are invaluable when working under time pressure. In this blogpost series I will present multiple tools and techniques that can help to reverse an unknown binary. Please note that these articles do not contain cutting edge research but rather target at newcomers. However, I hope to also provide some useful and interesting information for moreexperienced practitioners.&lt;/em&gt;&lt;/p&gt;</description>
    </item>
    <item>
      <title>Slides &amp; Scripts from Antonios Atlasis’ “Advanced Attack Techniques against IPv6 Networks” Workshop</title>
      <link>https://insinuator.net/2013/06/slides-scripts-from-antonios-atlasis-advanced-attack-techniques-against-ipv6-networks-workshop/</link>
      <pubDate>Tue, 25 Jun 2013 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2013/06/slides-scripts-from-antonios-atlasis-advanced-attack-techniques-against-ipv6-networks-workshop/</guid>
      <description>&lt;p&gt;After his great presentations on &lt;a href=&#34;https://www.troopers.de/archives/troopers13/agenda13/troopers13-ipv6-security-summit-2013/troopers13-ipv6-security-summit-2013-presentations/index.html#extension_headers&#34;&gt;IPv6 Extensions Headers&lt;/a&gt; and &lt;a href=&#34;https://www.troopers.de/archives/troopers13/agenda13/troopers13-ipv6-security-summit-2013/troopers13-ipv6-security-summit-2013-presentations/index.html#fragmentation_overlapping&#34;&gt;security problems related to fragmentation&lt;/a&gt; we had invited Antonios Atlasis to Heidelberg to give  &lt;a href=&#34;https://www.ernw.de/wp-content/uploads/M44b-Advanced_Attack_Techniques_24-06-2013_Heidelberg.pdf&#34;&gt;this workshop&lt;/a&gt; at ERNW. It was a great experience with many fruitful discussions between the participants (mostly security practitioners from very large organizations planning to have their Internet edge IPv6 enabled within the next 6-12 months) and him/us. Antonios thankfully decided to make his &lt;a href=&#34;https://www.ernw.de/download/Advanced%20Attack%20Techniques%20against%20IPv6%20Networks-final.pdf&#34;&gt;slides&lt;/a&gt; and &lt;a href=&#34;https://www.ernw.de/download/Advanced_Attack_Techniques_Scripts.zip&#34;&gt;scripts&lt;/a&gt; available for those interested in further research on the topics (it should be noted that the scripts have not been tested thoroughly and he’s happy to receive feedback of any kind at antoniosDOTatlasisDOTgmailDOTcom). Today Marc (Heuse) gives &lt;a href=&#34;https://www.ernw.de/wp-content/uploads/M44a-PentestWorkshop_25-06-2013_Heidelberg.pdf&#34;&gt;his workshop&lt;/a&gt; on pentesting in the IPv6 age. Hopefully such events help to move things into the right direction in the IPv6 security space…&lt;/p&gt;</description>
    </item>
    <item>
      <title>Analysis of Hypervisor Breakouts</title>
      <link>https://insinuator.net/2013/05/analysis-of-hypervisor-breakouts/</link>
      <pubDate>Mon, 20 May 2013 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2013/05/analysis-of-hypervisor-breakouts/</guid>
      <description>&lt;p&gt;In the course of a current virtualization research project, I was reviewing a lot of documentation on hypervisor security. While “hypervisor security” is a very wide field, hypervisor breakouts are usually one of the most (intensely) discussed topics. I don’t want to go down the road of rating the risk of hypervisor breakouts and giving appropriate recommendations (even though we do this on a regular base which, surprisingly often, leads to almost religious debates. I know I say this way too often:I’ll cover this topic in a future post ;)), but share a few observations of analyzing well-known examples of vulnerabilities that led to guest-to-host-escape scenarios. The following table provides an overview of the vulnerabilities in question:&lt;/p&gt;</description>
    </item>
    <item>
      <title>Microsoft Surface RT, a quick insight</title>
      <link>https://insinuator.net/2013/04/microsoft-surface-rt-a-quick-insight/</link>
      <pubDate>Wed, 24 Apr 2013 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2013/04/microsoft-surface-rt-a-quick-insight/</guid>
      <description>&lt;p&gt;After being on the market for a few months now, Microsoft started quite a large advertising campaign in Germany for its new &lt;em&gt;Surface RT&lt;/em&gt; . We had a comprehensive look at the new tablet PC and here are a few thoughts and impressions:&lt;/p&gt;&#xA;&lt;p&gt;Running a slightly reduced ARM version of Windows 8, I heard somebody calling it “Windows 8 Home”, which in comparison to older versions hits the spot, Microsoft offers an easily usable interface. Software is reduced to market apps (the minimal run level on a plain Windows is 0, any, and 8, Microsoft, on Windows RT), so you can’t just install your favourite app, or can you?&lt;/p&gt;</description>
    </item>
    <item>
      <title>BPDU Guard in Virtualized Environments (2)</title>
      <link>https://insinuator.net/2013/04/bpdu-guard-in-virtualized-environments-2/</link>
      <pubDate>Wed, 17 Apr 2013 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2013/04/bpdu-guard-in-virtualized-environments-2/</guid>
      <description>&lt;p&gt;Just a quick update here: Ivan (who gave the magnificent &lt;a href=&#34;https://www.troopers.de/archives/troopers13/agenda13/troopers13-presentations/index.html#virtual_firewalls&#34;&gt;Virtual Firewalls&lt;/a&gt; talk at &lt;a href=&#34;http://www.troopers.de&#34;&gt;Troopers&lt;/a&gt; recently) blogged about this and some guy added some feedback from an environment with Cisco FEX and “one of the server guys start[ing] a Citrix Netscaler” ;-). See the second comment to his &lt;a href=&#34;http://blog.ioshints.info/2013/04/vm-bpdu-spoofing-attack-works-quite.html&#34;&gt;post&lt;/a&gt;.&lt;/p&gt;&#xA;&lt;p&gt;This shows, once more, that the dependencies of various technologies (and what they are used for) must be well understood in cloud/virtualized environments. Complexity … but who do we tell. Y’ all know that, right?&lt;/p&gt;</description>
    </item>
    <item>
      <title>3 Ways for 3-Letter-Agencies to get your Government Proof, Indecipherable Cloud Text Messages</title>
      <link>https://insinuator.net/2013/04/3-ways-for-3-letter-agencies-to-get-your-government-proof-indecipherable-cloud-text-messages/</link>
      <pubDate>Wed, 10 Apr 2013 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2013/04/3-ways-for-3-letter-agencies-to-get-your-government-proof-indecipherable-cloud-text-messages/</guid>
      <description>&lt;p&gt;The &lt;a href=&#34;http://gritsforbreakfast.blogspot.de/2013/04/encryption-for-cloud-communications-may.html&#34;&gt;gritsforbreakfast blog post&lt;/a&gt; making the rounds on the &lt;a href=&#34;https://mailman.stanford.edu/pipermail/liberationtech/2013-April/008100.html&#34;&gt;Liberation Tech mailing list&lt;/a&gt; about security of Apple’s iMessaging service is gaining quite some attention. The post refers to a &lt;a href=&#34;http://news.cnet.com/8301-13578_3-57577887-38/apples-imessage-encryption-trips-up-feds-surveillance/&#34;&gt;CNET article&lt;/a&gt; on how the iMessage service “stymied attempts by federal drug enforcement agents to eavesdrop” conversations due its end-to-end encryption and commends Apple for protecting the user’s privacy while pointing out that Gmail and Facebook Messaging don’t. However, I disagree on some points of the blog post and therefore want to discuss them here.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Thoughts on Cloud Governance, Part 1</title>
      <link>https://insinuator.net/2013/04/thoughts-on-cloud-governance-part-1/</link>
      <pubDate>Fri, 05 Apr 2013 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2013/04/thoughts-on-cloud-governance-part-1/</guid>
      <description>&lt;p&gt;Last week Rapid7 &lt;a href=&#34;https://community.rapid7.com/community/infosec/blog/2013/03/27/1951-open-s3-buckets&#34;&gt;posted&lt;/a&gt; an interesting analysis of the Amazon S3 storage system: Apparently roughly one out of six S3 buckets (a bucket is, simply said, a kind of folder) is accessible without any authentication mechanism. Accessing those files, the &lt;a href=&#34;http://www.rapid7.com/&#34;&gt;Rapid7&lt;/a&gt; guys were able to download a &lt;a href=&#34;http://www.google.com/search?q=site%3As3.amazonaws.com+filetype%3Axls+password&amp;amp;btnG=Search&amp;amp;client=opera&amp;amp;oe=utf-8&amp;amp;channel=suggest&amp;amp;gbv=1&#34;&gt;wide range of data&lt;/a&gt;, also comprising confidential information such as source code or employee information, comparable to past research for &lt;a href=&#34;http://blog.rootshell.be/2012/05/19/what-are-you-sharing-with-dropbox/&#34;&gt;other platforms&lt;/a&gt; (see also this presentation I gave on some of the &lt;a href=&#34;https://www.ernw.de/download/ERNW_BastaSpring13_CloudFails.pdf&#34;&gt;biggest Cloud #Fails&lt;/a&gt;)&lt;/p&gt;</description>
    </item>
    <item>
      <title>BPDU Guard: Bringing Down Infrastructures</title>
      <link>https://insinuator.net/2013/04/bpdu-guard-bringing-down-infrastructures/</link>
      <pubDate>Thu, 04 Apr 2013 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2013/04/bpdu-guard-bringing-down-infrastructures/</guid>
      <description>&lt;p&gt;As you may already be familiar with some of our &lt;a href=&#34;http://www.insinuator.net/2012/05/vmdk-has-left-the-building/&#34;&gt;previous&lt;/a&gt; &lt;a href=&#34;https://www.ernw.de/download/ERNW_Newsletter_41_ExploitingVirtualFileFormats_signed.pdf&#34;&gt;work&lt;/a&gt; which was mainly focused on isolation issues of hypervisors, we also want to present you an issue concerning availability in Cloud environments. This issue was already covered in some of our &lt;a href=&#34;https://www.ernw.de/download/ERNW_DCVI-HypervisorsToClouds.pdf&#34;&gt;presentations&lt;/a&gt;, but will be explained in greater detail in this blog post.&lt;/p&gt;&#xA;&lt;p&gt;In the course of one of our security assessments of a public IaaS Cloud environment, we experienced the following network setting:&lt;/p&gt;</description>
    </item>
    <item>
      <title>A Word on Cisco Jabber</title>
      <link>https://insinuator.net/2013/04/a-word-on-cisco-jabber/</link>
      <pubDate>Wed, 03 Apr 2013 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2013/04/a-word-on-cisco-jabber/</guid>
      <description>&lt;p&gt;Recently we took a look on Ciscos XMPP client, called Cisco Jabber. The Client is used in combination with Ciscos Unified Communication Server (CUCM) and Ciscos Unified Presence Server (CUPS). Only the latter one is used for XMPP communication.&lt;/p&gt;&#xA;&lt;p&gt;We built a small lab setup with this components (CUCM, CUPS and the Win7 Client) and watched the client working.&lt;/p&gt;&#xA;&lt;p&gt;First the client connects to a web service at https://CUPS:8443/EPASSoap/service/v80. We intercepted this connection with the Burp Proxy and had no problems getting into the SSL. Inside we found a SOAP request containing the users authentication credentials and a SOAP response with a onetime password, which is used for authentication in the XMPP stream later on. Phew, the users credentials _and_ unlimited onetime passwords _that_ easy? Thanks Cisco!&lt;/p&gt;</description>
    </item>
    <item>
      <title>VMDK Has Left the Building — Newsletter</title>
      <link>https://insinuator.net/2013/02/vmdk-has-left-the-building-newsletter/</link>
      <pubDate>Sat, 23 Feb 2013 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2013/02/vmdk-has-left-the-building-newsletter/</guid>
      <description>&lt;p&gt;We are pleased to announce that we summarized the results from our &lt;a href=&#34;http://www.insinuator.net/2012/05/vmdk-has-left-the-building/&#34;&gt;VMDK research&lt;/a&gt; in our latest newsletter.&lt;/p&gt;&#xA;&lt;p&gt;We hope you enjoy the reading and will get some “food for thought”!&lt;/p&gt;&#xA;&lt;p&gt;The newsletter can be found at:&lt;br&gt;&#xA;&lt;a href=&#34;https://www.ernw.de/download/ERNW_Newsletter_41_ExploitingVirtualFileFormats.pdf&#34;&gt;ERNW_Newsletter_41_ExploitingVirtualFileFormats.pd&lt;/a&gt;&lt;/p&gt;&#xA;&lt;p&gt;A digitally signed version can be found at:&lt;br&gt;&#xA;&lt;a href=&#34;https://www.ernw.de/download/ERNW_Newsletter_41_ExploitingVirtualFileFormats_signed.pdf&#34;&gt;ERNW_Newsletter_41_ExploitingVirtualFileFormats_signed.pdf&lt;/a&gt;&lt;/p&gt;&#xA;&lt;p&gt;Enjoy your weekend,&lt;br&gt;&#xA;Matthias&lt;/p&gt;</description>
    </item>
    <item>
      <title>Corporate Espionage via Mobile Compromise: A technical deep dive</title>
      <link>https://insinuator.net/2013/02/corporate-espionage-via-mobile-compromise-a-technical-deep-dive/</link>
      <pubDate>Tue, 19 Feb 2013 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2013/02/corporate-espionage-via-mobile-compromise-a-technical-deep-dive/</guid>
      <description>&lt;h3 id=&#34;this-is-a-guest-post-from-david-weinstein&#34;&gt;This is a guest post from &lt;a href=&#34;https://www.troopers.de/agenda13/troopers13-presentations/index.html#corporate_espionage_via_mobile_compromise&#34;&gt;David Weinstein&lt;/a&gt;&lt;/h3&gt;&#xA;&lt;p&gt;Mobile devices play an important role in the business world. Yet with increased emphasis on the Bring Your Own Device (BYOD) model, defenses are not where they need to be to slow the loss of valuable intellectual property.&lt;/p&gt;&#xA;&lt;p&gt;Corporate defenses have traditionally focused on the network, the endpoints, and not necessarily on the ecosystem of how these devices interact outside of network sockets. Smartphones bring unique network connectivity, an array of sensors, and can be overlooked by resources invested on IDS/IPS not being effectively leveraged.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Apple iOS and the history of a workin’ lockscreen… NOT</title>
      <link>https://insinuator.net/2013/02/apple-ios-and-the-history-of-a-workin-lockscreen-not/</link>
      <pubDate>Sun, 17 Feb 2013 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2013/02/apple-ios-and-the-history-of-a-workin-lockscreen-not/</guid>
      <description>&lt;p&gt;Once again a vulnerability in Apples mobile operating system iOS was found by some guys of the Jailbreak Nation. The newest version of this operating system suffers from a weakness that makes it possible to unlock the lockscreen of all iPhones that use iOS version 6.1. In this case it does not matter whether a PIN or a password is used to unlock the phone. After successful exploitation an attacker is able to see and edit contact-information, to add new contacts to the phonebook, to view all pictures, to call the inbox or any of the contacts and to see and delete the list of recent calls or parts of it.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Paparazzi over IP</title>
      <link>https://insinuator.net/2013/02/paparazzi-over-ip/</link>
      <pubDate>Fri, 15 Feb 2013 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2013/02/paparazzi-over-ip/</guid>
      <description>&lt;p&gt;Almost every higher class DSLR on the market today features multiple and complex access technologies. To name a few, canons new flagship features IP connectivity wired via 802.3 as well as wireless via 802.11. All the big vendors are pushing these features to the market and advertise them with real time image transfer to the cloud. We have taken a look at the layer 2 and 3 implementations in the CamOS and the services running upon those, so here is what we found while examine the EOS 1D X:&lt;/p&gt;</description>
    </item>
    <item>
      <title>Mobile Application Testing</title>
      <link>https://insinuator.net/2013/02/mobile-application-testing/</link>
      <pubDate>Thu, 14 Feb 2013 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2013/02/mobile-application-testing/</guid>
      <description>&lt;p&gt;Our new &lt;a href=&#34;https://www.troopers.de/agenda13/troopers13-2-day-workshop-mobile-application-testing/index.html&#34;&gt;workshop about mobile application testing&lt;/a&gt;, held for the 1st time at the Troopers conference 2013, is coming closer. So I would like to take the opportunity and post an appetizer for those who are still undetermined if they should attend the workshop ;-).&lt;/p&gt;&#xA;&lt;p&gt;While the topic of mobile application testing is a wide field that may contain reverse engineering, secure storage analysis, vulnerability research, network traffic analysis and so forth, in the end of the day you have to answer one question: Can I trust this application and run it on my enterprise devices? So first you have to define some criteria, which kind of behavior and characteristics of an application you regard as trustworthy (or not). Let us peek at malware … besides harming your devices and data, malware is typically:&lt;/p&gt;</description>
    </item>
    <item>
      <title>Analysis of Rails XML Parameter Parsing Vulnerability</title>
      <link>https://insinuator.net/2013/01/analysis-of-rails-xml-parameter-parsing-vulnerability/</link>
      <pubDate>Tue, 08 Jan 2013 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2013/01/analysis-of-rails-xml-parameter-parsing-vulnerability/</guid>
      <description>&lt;p&gt;This post tries to give an overview about the background and impact of the &lt;a href=&#34;https://groups.google.com/forum/#!topic/rubyonrails-security/61bkgvnSGTQ/discussion&#34;&gt;new Rails XML parameter parsing vulnerability patched today&lt;/a&gt;.&lt;/p&gt;&#xA;&lt;h2 id=&#34;the-bug&#34;&gt;The bug&lt;/h2&gt;&#xA;&lt;p&gt;The root cause of the vulnerability is Rails handling of formatted parameters. In addition to standard GET and POST parameter formats, Rails can handle multiple different data encodings inside the body of POST requests. By default JSON and XML are supported. While support for JSON is widely used in production, the XML functionality does not seem to be known by many Rails developers.&lt;/p&gt;</description>
    </item>
    <item>
      <title>All Your Calls Are Still Belong to Us – continued</title>
      <link>https://insinuator.net/2013/01/all-your-calls-are-still-belong-to-us-continued/</link>
      <pubDate>Thu, 03 Jan 2013 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2013/01/all-your-calls-are-still-belong-to-us-continued/</guid>
      <description>&lt;p&gt;Hi again and a happy new year 2013!&lt;/p&gt;&#xA;&lt;p&gt;Lets continue were I left you the last time.&lt;/p&gt;&#xA;&lt;h2 id=&#34;the-ctl&#34;&gt;The CTL&lt;/h2&gt;&#xA;&lt;p&gt;The CTL is basically a binary TLV file with 1 byte type, followed by 2 bytes length and finally the data. But as this is far to easy, some special fields omit the length field and just place the data after the type (I guess those are fields with a fixed length). Here is an example CTL file:&lt;/p&gt;</description>
    </item>
    <item>
      <title>All Your Calls Are Still Belong to Us – aka. Hacking Cisco high secure Enterprise VoIP Solution</title>
      <link>https://insinuator.net/2012/12/all-your-calls-are-still-belong-to-us-aka.-hacking-cisco-high-secure-enterprise-voip-solution/</link>
      <pubDate>Thu, 27 Dec 2012 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2012/12/all-your-calls-are-still-belong-to-us-aka.-hacking-cisco-high-secure-enterprise-voip-solution/</guid>
      <description>&lt;p&gt;Some of you may have heard the topic before, as we have spoken about on this years &lt;a href=&#34;http://www.youtube.com/watch?v=hWe5zGfsN0g&#34;&gt;BlackHat Europe&lt;/a&gt;, &lt;a href=&#34;https://www.troopers.de/archives/troopers12/agenda12/troopers12-protecting-voice-over-ip-in-2012/index.html&#34;&gt;TROOPERS12&lt;/a&gt;  and &lt;a href=&#34;http://www.ustream.tv/recorded/21808461&#34;&gt;HES12&lt;/a&gt;, so this is nothing completely new, but as we’re done with responsible disclosure (finally (-; )  and all the stuff should be fixed, we’re going to publish the code that brought us there. I will split the topic into two blog posts, this one will wrap up the setup, used components and protocols, the next one [tbd. till EOY, hopefully] will get into detail on the tools and techniques we used to break the enterprise grade security.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Loki for Windows released</title>
      <link>https://insinuator.net/2012/11/loki-for-windows-released/</link>
      <pubDate>Thu, 08 Nov 2012 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2012/11/loki-for-windows-released/</guid>
      <description>&lt;p&gt;Today is a great day, its the day, Loki finally runs on all big operating systems. Im proud to announce the first Loki release for Windows!&lt;/p&gt;&#xA;&lt;p&gt;There are a few things not working (yet / at all) under Windows. Those are:&lt;/p&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;The WLCCP Module – ive not yet managed to build and link against asleap on windows [but time may help (-; ]&lt;/li&gt;&#xA;&lt;li&gt;TCP-MD5 Auth for BGP – This will never work, as Windows has no TCP-MD5 impl. in the kernel&lt;/li&gt;&#xA;&lt;li&gt;The MPLS Module – Had some hassle here with WinPcap, may be working in the future&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;p&gt;The most testing so far was done on Windows 7 were all the other functions work as they do on Linux and Mac.&lt;/p&gt;</description>
    </item>
    <item>
      <title>SQL Injection in Cisco MeetingPlace</title>
      <link>https://insinuator.net/2012/11/sql-injection-in-cisco-meetingplace/</link>
      <pubDate>Thu, 08 Nov 2012 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2012/11/sql-injection-in-cisco-meetingplace/</guid>
      <description>&lt;p&gt;Cisco has released a &lt;a href=&#34;http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20121031-mp&#34;&gt;security advisory&lt;/a&gt; for a vulnerability we discovered last year.&lt;br&gt;&#xA;For comparison here is our original advisory to cisco:&lt;/p&gt;&#xA;&lt;h5 id=&#34;security-advisory-for-cisco-unified-communications-solution&#34;&gt;Security Advisory for Cisco Unified Communications Solution&lt;/h5&gt;&#xA;&lt;h5 id=&#34;release-date-1182012-author-daniel-mende&#34;&gt;Release Date: 11/8/2012 Author: Daniel Mende&lt;/h5&gt;&#xA;&lt;h5 id=&#34;1-summary-multiple-critical-sql-injections-exist-in-cisco-unified-meeting-place&#34;&gt;1 SUMMARY Multiple critical SQL injections exist in Cisco unified meeting place.&lt;/h5&gt;&#xA;&lt;h5 id=&#34;2-affected-products-the-following-products-have-been-tested-as-vulnerable-so-far-cisco-unified-meetingplace-with-the-following-modules--meetingplace-agent-7119--meetingplace-audio-service-7118--meetingplace-gateway-sim-7112--meetingplace-replication-service-7119--meetingplace-master-service-7118--meetingplace-extension-7118--meetingplace-authentication-filter-7118&#34;&gt;2 AFFECTED PRODUCTS The following Products have been tested as vulnerable so far: Cisco Unified Meetingplace with the following modules: • MeetingPlace Agent 7.1.1.9 • MeetingPlace Audio Service 7.1.1.8 • MeetingPlace Gateway SIM 7.1.1.2 • MeetingPlace Replication Service 7.1.1.9 • MeetingPlace Master Service 7.1.1.8 • MeetingPlace Extension 7.1.1.8 • MeetingPlace Authentication Filter 7.1.1.8&lt;/h5&gt;&#xA;&lt;h5 id=&#34;3-details-the-following-parameters-are-affected-httpipmpwebscriptsmpxdll-post-parameter-wcrecurmtgid&#34;&gt;3 DETAILS The following parameters are affected: http://$IP/mpweb/scripts/mpx.dll [POST Parameter wcRecurMtgID]&lt;/h5&gt;&#xA;&lt;h5 id=&#34;4-vulnerability-scoring-the-severity-rating-based-on-cvss-version-2-base-vector-avn--acl--aus--cp--ip--ap-cvss-version-2-score-65-severity-low&#34;&gt;4 VULNERABILITY SCORING The severity rating based on CVSS Version 2: Base Vector: (AV:N / AC:L / Au:S / C:P / I:P / A:P) CVSS Version 2 Score: 6.5 Severity: Low&lt;/h5&gt;&#xA;&lt;h5 id=&#34;5-proof-of-concept-post-mpwebscriptsmpxdll-http11-host-10xxx-user-agent-mozilla50-accept-texthtmlapplicationxhtmlxmlapplicationxmlq09q08-accept-language-en-usenq05-accept-encoding-gzip-deflate-accept-charset-iso-8859-1utf-8q07q07-proxy-connection-keep-alive-referer-http10xxxmpwebscriptsmpxdll-cookie-cookiestrue-content-type-applicationx-www-form-urlencoded-content-length-571&#34;&gt;5 PROOF OF CONCEPT POST /mpweb/scripts/mpx.dll HTTP/1.1 Host: 10.X.X.X User-Agent: Mozilla/5.0 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8 Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip, deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7 Proxy-Connection: keep-alive Referer: http://10.X.X.X/mpweb/scripts/mpx.dll Cookie: cookies=true Content-Type: application/x-www-form-urlencoded Content-Length: 571&lt;/h5&gt;&#xA;&lt;h5 id=&#34;sessionida40490a1-ab17-4c1e-ba4a-e3c5c90f62ca1ed59e5c-a774-4546-8683--aeb15d6fbd0d55931857-6296-48ec-9434-3231c683c47dadadfjadlkenmfhmplaihgkddg-wcmeetingidwcrecurmtgid-or-11-url0wcbasetpltxt0startseiteurl1-txt1url2txt2url3txt3url4txt4url5txt5mtgcattosearch-28all2bcategories29ml_publicpostedyesmtgidtosearch0000007schedulerid-wcrequestwchashformtypelistmeetingswcstate3stplwcfindmtgtplftpl-wcfindmtgtplml_listmt_todayml_endtime_monthml_endtime_dayml_end-time_yearml_showcontmtgsyessp_vlanguagelang999i00&#34;&gt;SessionID=A40490A1-AB17-4C1E-BA4A-E3C5C90F62CA.1ED59E5C-A774-4546-8683- AEB15D6FBD0D.55931857-6296-48ec-9434-3231c683c47d.ADadfjadlkeNmFhmplaihgkdDg &amp;amp;wcMeetingID=&amp;amp;wcRecurMtgID=‘ or 1=1 —&amp;amp;URL0=wcBase.tpl&amp;amp;TXT0=Startseite&amp;amp;URL1=&amp;amp; TXT1=&amp;amp;URL2=&amp;amp;TXT2=&amp;amp;URL3=&amp;amp;TXT3=&amp;amp;URL4=&amp;amp;TXT4=&amp;amp;URL5=&amp;amp;TXT5=&amp;amp;MtgCatToSearch= %28all%2Bcategories%29&amp;amp;ML_PublicPosted=Yes&amp;amp;MtgIDToSearch=0000007&amp;amp;SchedulerID= &amp;amp;wcRequest=&amp;amp;wcHash=&amp;amp;FormType=listmeetings&amp;amp;wcState=3&amp;amp;STPL=wcFindMtg.tpl&amp;amp;FTPL= wcFindMtg.tpl&amp;amp;ML_List=MT_Today&amp;amp;ML_EndTime_Month=&amp;amp;ML_EndTime_Day=&amp;amp;ML_End Time_Year=&amp;amp;ML_ShowContMtgs=Yes&amp;amp;SP_VLanguage=lang999i00&lt;/h5&gt;&#xA;&lt;p&gt; &lt;/p&gt;</description>
    </item>
    <item>
      <title>VMDK Has Left the Building — Denial of Service</title>
      <link>https://insinuator.net/2012/11/vmdk-has-left-the-building-denial-of-service/</link>
      <pubDate>Sat, 03 Nov 2012 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2012/11/vmdk-has-left-the-building-denial-of-service/</guid>
      <description>&lt;p&gt;Almost all of our presentations and write-ups on the VMDK File Inclusion Vulnerability contained a slide stating something like&lt;/p&gt;&#xA;&lt;p&gt;&lt;em&gt;“we’re rather sure that DoS is possible as well ;-)”&lt;/em&gt;&lt;/p&gt;&#xA;&lt;p&gt;including the following screenshot of the ESX purple screen of death:&lt;/p&gt;&#xA;&lt;p&gt;&lt;a href=&#34;http://www.insinuator.net/wp-content/uploads/2012/11/DOS_PoC_CoreDump.jpeg&#34;&gt;&lt;img src=&#34;http://www.insinuator.net/wp-content/uploads/2012/11/DOS_PoC_CoreDump.jpeg&#34; alt=&#34;&#34; title=&#34;DOS_PoC_CoreDump&#34;&gt;&lt;/a&gt;&lt;/p&gt;&#xA;&lt;p&gt;So it seems like we still owe you that one — sorry for the delay! However the actual attack to trigger this purple screen was rather simple: Just include &lt;em&gt;multiple&lt;/em&gt; VMDK raw files that cannot be aligned with 512 Byte blocks — e.g. several files of 512 * X + [0 &amp;lt; Y &amp;lt; 512] Bytes. Writing to a virtual hard drive composed of such single files for a short amount of time (typically one to three minutes, this is what we observed in our lab) triggered the purple screen on both ESXi4 and ESXi5 — at least for a patch level earlier than Releasebuild-515841/March 2012: it seems like this vulnerability was patched in Patch &lt;a href=&#34;http://kb.vmware.com/selfservice/microsites/search.do?language=en_US&amp;amp;cmd=displayKC&amp;amp;externalId=2010814&#34;&gt;ESXi500-201203201-UG&lt;/a&gt;.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Pytacle alpha1 released!</title>
      <link>https://insinuator.net/2012/10/pytacle-alpha1-released/</link>
      <pubDate>Wed, 31 Oct 2012 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2012/10/pytacle-alpha1-released/</guid>
      <description>&lt;p&gt;Finally it’s here!&lt;/p&gt;&#xA;&lt;p&gt;&lt;a href=&#34;http://www.ernw.de/download/pytacle-alpha1.tar.gz&#34;&gt;pytacle&lt;/a&gt; is a tool inspired by &lt;a href=&#34;http://www.data.ks.uni-freiburg.de/download/masterarbeit/SS11/09-betz-gsm/&#34;&gt;tentacle&lt;/a&gt;. It automates the task of sniffing GSM frames of the air, extracting the key exchange, feeding &lt;a href=&#34;https://srlabs.de/decrypting_gsm/&#34;&gt;kraken&lt;/a&gt; with the key material and finally decode/decrypt the voice data. All You need is a &lt;a href=&#34;http://www.ettus.com/&#34;&gt;USRP&lt;/a&gt; (or similar) to capture the GSM band and a &lt;a href=&#34;git://git.srlabs.de/kraken.git&#34;&gt;kraken&lt;/a&gt; instance with the &lt;a href=&#34;http://opensource.srlabs.de/projects/a51-decrypt/files&#34;&gt;berlin tables&lt;/a&gt; (only about 2TB 😉 )&lt;/p&gt;&#xA;&lt;p&gt;I’ve posted a &lt;a href=&#34;http://www.insinuator.net/2011/12/pytacle-preview/&#34;&gt;preview&lt;/a&gt; before, take a look at the video to see the tool in action.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Update: Microsoft Advisory 2757760 Windows Internet Explorer Vulnerability</title>
      <link>https://insinuator.net/2012/09/update-microsoft-advisory-2757760-windows-internet-explorer-vulnerability/</link>
      <pubDate>Thu, 20 Sep 2012 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2012/09/update-microsoft-advisory-2757760-windows-internet-explorer-vulnerability/</guid>
      <description>&lt;p&gt;Microsoft takes this vulnerability quite serious and was acting fast. The Microsoft Security Response Center announced the availability of a fix last night in the &lt;a href=&#34;http://blogs.technet.com/b/msrc/archive/2012/09/19/internet-explorer-fix-it-available-now-security-update-scheduled-for-friday.aspx&#34;&gt;MSRC Blog&lt;/a&gt;.&lt;/p&gt;&#xA;&lt;p&gt;The fix will be available via Windows Update on friday, the 21st of september. So it’s time to get ready for this update ;-).&lt;/p&gt;&#xA;&lt;p&gt;Have a nice day&lt;br&gt;&#xA;Michael&lt;/p&gt;</description>
    </item>
    <item>
      <title>Microsoft Advisory 2757760: Windows Internet Explorer Zero-Day Vulnerability</title>
      <link>https://insinuator.net/2012/09/microsoft-advisory-2757760-windows-internet-explorer-zero-day-vulnerability/</link>
      <pubDate>Wed, 19 Sep 2012 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2012/09/microsoft-advisory-2757760-windows-internet-explorer-zero-day-vulnerability/</guid>
      <description>&lt;p&gt;Actually a Windows Vulnerability (&lt;a href=&#34;http://technet.microsoft.com/en-us/security/advisory/2757760&#34;&gt;Microsoft Advisory 2757760&lt;/a&gt;) related to the Internet Explorer Version 7, 8 and 9 is in the news. Microsoft is aware of the problem, but there’s no patch available yet. We call this a 0-Day :-). Making the problem even worse, on monday reliable &lt;a href=&#34;https://community.rapid7.com/community/metasploit/blog/2012/09/17/lets-start-the-week-with-a-new-internet-explorer-0-day-in-metasploit&#34;&gt;exploit code&lt;/a&gt; was released within the Metasploit project, so exploit code is already in the wild.&lt;/p&gt;&#xA;&lt;p&gt;Basically Microsoft suggests two workarounds:&lt;/p&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;Usage of EMET &lt;a href=&#34;http://support.microsoft.com/kb/2458544&#34;&gt;(Enhanced Mitigation Experience Toolkit&lt;/a&gt;)&lt;/li&gt;&#xA;&lt;li&gt;Disabling Active X and Active Scripting in the Internet Settings&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;p&gt;But both of them have some impact: EMET must be deployed before any usage (btw. EMET can be configured via Group Policies) and disabling Active X and Active Scripting might break some business relevant web sites (that can be added to the “Trusted Sites” Zone, but might produce major operational effort).&lt;/p&gt;</description>
    </item>
    <item>
      <title>VMDK Has Left the Building – Write Access</title>
      <link>https://insinuator.net/2012/09/vmdk-has-left-the-building-write-access/</link>
      <pubDate>Wed, 05 Sep 2012 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2012/09/vmdk-has-left-the-building-write-access/</guid>
      <description>&lt;p&gt;In our last series of posts regarding the VMDK file inclusion attack, we focused on &lt;a href=&#34;http://www.insinuator.net/2012/05/vmdk-has-left-the-building/&#34;&gt;read access&lt;/a&gt; and &lt;a href=&#34;http://www.insinuator.net/2012/05/vmdk-has-left-the-building-follow-up/&#34;&gt;prerequisites&lt;/a&gt; for the attack, but avoided stating too much about potential write access. But as we promised to cover write access in the course of our future research, the following post will describe our latest research results.&lt;/p&gt;&#xA;&lt;p&gt;First of all, the same &lt;a href=&#34;http://www.insinuator.net/2012/05/vmdk-has-left-the-building-follow-up/&#34;&gt;prerequisites&lt;/a&gt; (which will be refined a little bit more later on) as for read access must be fulfilled and the same &lt;a href=&#34;http://www.insinuator.net/2012/05/vmdk-has-left-the-building/&#34;&gt;steps&lt;/a&gt; have to be performed in order to carry out the attack successfully. If that is the case, there are several POIs (Partitions Of Interest) on a ESXi hypervisor that are interesting to include:&lt;/p&gt;</description>
    </item>
    <item>
      <title>A First Glance – RA Guard Support in Hyper-V 3.0</title>
      <link>https://insinuator.net/2012/07/a-first-glance-ra-guard-support-in-hyper-v-3.0/</link>
      <pubDate>Tue, 24 Jul 2012 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2012/07/a-first-glance-ra-guard-support-in-hyper-v-3.0/</guid>
      <description>&lt;p&gt;Last week I read about the new networking features of the integrated vSwitch of Hyper-V 3.0. I was quite surprised that RA Guard will be natively supported and was curious about implementation and functionality. If you don’t know how RA Guard  works, I recommend reading our previous blog posts &lt;a href=&#34;http://www.insinuator.net/2011/01/ipv6-security-part-1-ra-guard-the-theory-3/&#34;&gt;here&lt;/a&gt;, &lt;a href=&#34;http://www.insinuator.net/2011/03/ipv6-security-part-2-ra-guard-%E2%80%93-lets-get-practical/&#34;&gt;here&lt;/a&gt;, &lt;a href=&#34;http://www.insinuator.net/2011/03/ipv6-security-%E2%80%92-the-story-continues/&#34;&gt;here&lt;/a&gt;, &lt;a href=&#34;http://www.insinuator.net/2011/05/yet-another-update-on-ipv6-security-some-notes-from-the-ipv6-kongress-in-frankfurt/&#34;&gt;here&lt;/a&gt; and &lt;a href=&#34;http://www.insinuator.net/2012/03/the-story-continues-another-ipv6-update/&#34;&gt;here&lt;/a&gt;, or have a look at our workshop at &lt;a href=&#34;http://www.troopers.de/archives/troopers12/agenda/advanced-ipv6-security-workshop/&#34;&gt;Troopers12&lt;/a&gt;.&lt;/p&gt;&#xA;&lt;p&gt;I downloaded Windows Server 2012 RC to do some practical testing. Since my girlfriend was working the whole weekend, I had plenty of time to play around with all that stuff without risking trouble 😉&lt;/p&gt;</description>
    </item>
    <item>
      <title>The Web Application Firewall Story continues</title>
      <link>https://insinuator.net/2012/06/the-web-application-firewall-story-continues/</link>
      <pubDate>Fri, 22 Jun 2012 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2012/06/the-web-application-firewall-story-continues/</guid>
      <description>&lt;p&gt;Some days ago another &lt;a href=&#34;https://www.sec-consult.com/files/20120618-1_Airlock_WAF_overlong_UTF8_bypass.txt&#34;&gt;advisory&lt;/a&gt; related to a web application firewall (WAF) product was published. This time the product Airlock by &lt;a href=&#34;http://www.ergon.ch/&#34;&gt;Ergon&lt;/a&gt; was affected by a vulnerability that combines Encoding and NULL Byte attacks to circumvent the pattern based detection engine. We have described these attacks in detail in our newsletter “&lt;a href=&#34;http://www.ernw.de/content/e15/e28/e1659/download1661/ERNW_Newsletter_35_WAF_en_ger.pdf&#34;&gt;Web Application Firewall Security and The Swiss Army Knife for Web Application Firewalls&lt;/a&gt;” because they belong to a well known category of attacks against WAFs.&lt;/p&gt;</description>
    </item>
    <item>
      <title>VMDK Has Left the Building — FAQ</title>
      <link>https://insinuator.net/2012/06/vmdk-has-left-the-building-faq/</link>
      <pubDate>Sun, 17 Jun 2012 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2012/06/vmdk-has-left-the-building-faq/</guid>
      <description>&lt;p&gt;As we are receiving a lot of questions about our &lt;a href=&#34;http://www.insinuator.net/2012/05/vmdk-has-left-the-building/&#34;&gt;VMDK has left the building post&lt;/a&gt;, we’re compiling this FAQ post — which will be updated as our research goes on.&lt;/p&gt;&#xA;&lt;p&gt;** **&lt;/p&gt;&#xA;&lt;p&gt;&lt;strong&gt;How does the attack essentially work?&lt;/strong&gt;&lt;/p&gt;&#xA;&lt;p&gt;&lt;em&gt;By bringing a specially crafted VMDK file into a VMware ESXi based virtualization environment. The specific attack path is described &lt;a href=&#34;http://www.insinuator.net/2012/05/vmdk-has-left-the-building-follow-up/&#34;&gt;here&lt;/a&gt;.&lt;/em&gt;&lt;/p&gt;&#xA;&lt;p&gt;* *&lt;/p&gt;&#xA;&lt;p&gt;&lt;strong&gt;What is a VMDK file?&lt;/strong&gt;&lt;/p&gt;&#xA;&lt;p&gt;&lt;em&gt;A combination of two different types of VMDK files, the plain-text descriptor file containing meta data and the actual binary disk file, describes a VMware virtual hard disk. A detailed description can be found &lt;a href=&#34;http://www.insinuator.net/2012/05/vmdk-has-left-the-building/&#34;&gt;here&lt;/a&gt;.&lt;/em&gt;&lt;/p&gt;</description>
    </item>
    <item>
      <title>SQL Injection Testing for Business Purposes Part 3</title>
      <link>https://insinuator.net/2012/06/sql-injection-testing-for-business-purposes-part-3/</link>
      <pubDate>Wed, 13 Jun 2012 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2012/06/sql-injection-testing-for-business-purposes-part-3/</guid>
      <description>&lt;h2 id=&#34;extract-the-data&#34;&gt;Extract the data&lt;/h2&gt;&#xA;&lt;p&gt;If you want to extract some data from a database you first need to gather knowledge about the internal structure of the database.&lt;/p&gt;&#xA;&lt;p&gt;One of the first steps (after determining the database type) is enumerating the available tables and the corresponding columns. Most database systems have a meta database called information_schema. By querying this database it is possible to get information about the internal structure of the installed databases. For example you could get the tables and their corresponding columns in MS SQL and MySQL by injecting “&lt;code&gt;SELECT table_name, column_name FROM information_schema.columns&lt;/code&gt;“. Oracle databases have their own meta tables, so you have to handle them differently. For getting the same output in Oracle, you have to query the all_tab_columns table (or user_tab_columns if you only want to search in the currently selected database). If the found vulnerability only allows to receive a single column (or if it is too complicated to identify two columns in the server response) you could concatenate the columns to one single string, e.g. in Oracle: “&lt;code&gt;SELECT table_name||&#39;:&#39;||column_name FROM all_tab_columns&lt;/code&gt;“.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Fuzzing VMDK files</title>
      <link>https://insinuator.net/2012/05/fuzzing-vmdk-files/</link>
      <pubDate>Wed, 30 May 2012 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2012/05/fuzzing-vmdk-files/</guid>
      <description>&lt;p&gt;As announced at last week’s &lt;a href=&#34;http://conference.hitb.org/hitbsecconf2012ams/&#34;&gt;#HITB2012AMS&lt;/a&gt;, I’ll describe the fuzzing steps which were performed during our initial research. The very first step was the definition of the interfaces we wanted to test. We decided to go with the plain text VMDK file, as this is the main virtual disk description file and in most deployment scenarios user controlled, and the data part of a special kind of VMDK files, the &lt;em&gt;Host Sparse Extends&lt;/em&gt;.&lt;/p&gt;</description>
    </item>
    <item>
      <title>SQL Injection Testing for Business Purposes Part 2</title>
      <link>https://insinuator.net/2012/05/sql-injection-testing-for-business-purposes-part-2/</link>
      <pubDate>Mon, 28 May 2012 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2012/05/sql-injection-testing-for-business-purposes-part-2/</guid>
      <description>&lt;h2 id=&#34;take-care-of-the-database&#34;&gt;Take Care of the Database&lt;/h2&gt;&#xA;&lt;p&gt;There are some database specifics, every pentester should be aware of, when testing for and exploiting SQLi vulnerabilities. Besides the different string concatenation variants already covered above, there are some other specifics that have to be considered and might turn out useful in some circumstances. For example with Oracle Databases, every SELECT statement needs a following FROM statement even if the desired data is not stored within a database. So when trying to extract e.g. the DB username using a UNION SELECT statement, the DUAL table may be utilized, which should always be available. Another point, if dealing with MySQL, is the possibility to simplify the classic payload&lt;/p&gt;</description>
    </item>
    <item>
      <title>VMDK Has Left the Building – Slides available</title>
      <link>https://insinuator.net/2012/05/vmdk-has-left-the-building-slides-available/</link>
      <pubDate>Fri, 25 May 2012 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2012/05/vmdk-has-left-the-building-slides-available/</guid>
      <description>&lt;p&gt;&lt;img src=&#34;http://www.insinuator.net/wp-content/uploads/2012/05/HITB_talk.jpg&#34; alt=&#34;&#34; title=&#34;HITB_talk&#34;&gt;A quick update on the workshop we’ve just finished at &lt;a href=&#34;http://conference.hitb.org/hitbsecconf2012ams/&#34;&gt;Hack in the Box 2012 Amsterdam&lt;/a&gt;:&lt;br&gt;&#xA;Due to popular demand we decided to bring the slides online without wasting any more time. The official website of the conference is currently experiencing some problems due to high interest in all the stuff what was released in the last two days. Great conference!&lt;/p&gt;&#xA;&lt;p&gt;Here you go: &lt;a href=&#34;http://www.insinuator.net/wp-content/uploads/2012/11/HITB_AMS_2012_ERNW_VMDK_v1.0_release.pdf&#34;&gt;HITB2012AMS ERNW VMDK Has Left the Building&lt;/a&gt; [PDF, 6MB, link fixed]&lt;/p&gt;</description>
    </item>
    <item>
      <title>VMDK Has Left the Building — Some Nasty Attacks Against VMware vSphere 5 Based Cloud Infrastructures</title>
      <link>https://insinuator.net/2012/05/vmdk-has-left-the-building-some-nasty-attacks-against-vmware-vsphere-5-based-cloud-infrastructures/</link>
      <pubDate>Thu, 24 May 2012 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2012/05/vmdk-has-left-the-building-some-nasty-attacks-against-vmware-vsphere-5-based-cloud-infrastructures/</guid>
      <description>&lt;p&gt;&lt;strong&gt;Update #1:&lt;/strong&gt; Slides are available for download &lt;a href=&#34;http://www.insinuator.net/2012/05/vmdk-has-left-the-building-slides-available/&#34;&gt;here&lt;/a&gt;.&lt;/p&gt;&#xA;&lt;p&gt;In the course of our ongoing &lt;a href=&#34;http://www.troopers.de/archives/troopers12/agenda/auditing-the-cloud-workshop/&#34;&gt;cloud security research&lt;/a&gt;, we’re continuously thinking about potential attack vectors against public cloud infrastructures. Approaching this enumeration from an external customer’s (speak: attacker’s 😉 ) perspective, there are the following possibilities to communicate with and thus send malicious input to typical cloud infrastructures:&lt;/p&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;Management interfaces&lt;/li&gt;&#xA;&lt;li&gt;Guest/hypervisor interaction&lt;/li&gt;&#xA;&lt;li&gt;Network communication&lt;/li&gt;&#xA;&lt;li&gt;File uploads&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;p&gt;As there are already several successful exploits against management interfaces (e.g. &lt;a href=&#34;http://www.nds.rub.de/media/nds/veroeffentlichungen/2011/10/22/AmazonSignatureWrapping.pdf&#34;&gt;here&lt;/a&gt; and &lt;a href=&#34;http://www.insinuator.net/2011/07/the-key-to-your-datacenter/&#34;&gt;here&lt;/a&gt;) and guest/hypervisor interaction (see for example &lt;a href=&#34;http://www.vmware.com/security/advisories/VMSA-2012-0009.html&#34;&gt;this one&lt;/a&gt;; yes, this is the funny one with that ridiculous recommendation “Do not allow untrusted users access to your virtual machines.” ;-)), we’re focusing on the upload of files to cloud infrastructures in this post. According to our experience with major &lt;em&gt;Infrastructure-as-a-Service&lt;/em&gt; (IaaS) cloud providers, the most relevant file upload possibility is the deployment of already existing virtual machines to the provided cloud infrastructure. However, since a quick additional research shows that most of those allow the upload of VMware-based virtual machines and, to the best of our knowledge, the VMware virtualization file format was not analyzed as for potential vulnerabilities yet, we want to provide an analysis of the relevant file types and present resulting attack vectors.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Releasing dizzy version 0.6</title>
      <link>https://insinuator.net/2012/05/releasing-dizzy-version-0.6/</link>
      <pubDate>Wed, 23 May 2012 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2012/05/releasing-dizzy-version-0.6/</guid>
      <description>&lt;p&gt;Hi @all,&lt;br&gt;&#xA;today im releasing a new version of our famous fuzzing framework, dizzy. The version counts 0.6 by now and youll get some brand new features!&lt;/p&gt;&#xA;&lt;p&gt;see the CHANGELOG:&lt;br&gt;&#xA;v0.6:&lt;br&gt;&#xA;– ssl support&lt;br&gt;&#xA;– server side fuzzing mode&lt;br&gt;&#xA;– command output&lt;br&gt;&#xA;– new dizz funktions: lambda_length, csum, lambda_csum, lambda2_csum&lt;br&gt;&#xA;– recursive mutation mode&lt;br&gt;&#xA;– new dizz objects: fill&lt;br&gt;&#xA;– new interaction objects: null_dizz&lt;br&gt;&#xA;– reconnect option&lt;br&gt;&#xA;– additional fuzzing values&lt;/p&gt;</description>
    </item>
    <item>
      <title>SQL Injection Testing for Business Purposes Part 1</title>
      <link>https://insinuator.net/2012/05/sql-injection-testing-for-business-purposes-part-1/</link>
      <pubDate>Mon, 14 May 2012 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2012/05/sql-injection-testing-for-business-purposes-part-1/</guid>
      <description>&lt;h2 id=&#34;introduction&#34;&gt;Introduction&lt;/h2&gt;&#xA;&lt;p&gt;SQL injection attacks have been well known for a long time and many people think that developers should have fixed these issues years ago, but doing web application pentests almost all the time, we have a slightly different view. Many SQL injection problems  potentially remain undetecteddue to a lack of proper test methodology, so we would like to share our approach and experience and help others in identifying these issues.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Untrusted code or why exploit code should only be executed by professionals</title>
      <link>https://insinuator.net/2012/04/untrusted-code-or-why-exploit-code-should-only-be-executed-by-professionals/</link>
      <pubDate>Sun, 22 Apr 2012 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2012/04/untrusted-code-or-why-exploit-code-should-only-be-executed-by-professionals/</guid>
      <description>&lt;p&gt;In march 2012 Microsoft announced a critical vulnerability (&lt;a href=&#34;http://technet.microsoft.com/en-us/security/bulletin/ms12-020&#34;&gt;Microsoft Security Bulletin MS12-020&lt;/a&gt;) related to RDP that affects all windows operating systems and allows remote code execution. A lot of security professionals are expecting almost the same impact as with MS08-067 (the conficker vulnerability) and that it will be only a matter of time, until we will spot reliable exploits in the wild. Only a few days later an exploit, working for all unpatched windows versions was released, so it seems that they were right ;-), but of course no one will run an exploit without investigating the code. So lets have a look into the exploit Code.&lt;/p&gt;</description>
    </item>
    <item>
      <title>A Comment on Android PIN bypass</title>
      <link>https://insinuator.net/2012/03/a-comment-on-android-pin-bypass/</link>
      <pubDate>Thu, 22 Mar 2012 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2012/03/a-comment-on-android-pin-bypass/</guid>
      <description>&lt;p&gt;Lately there have been some rumors on the full-disclosure mailing list referring to a blogpost of  Hatforce about a new method to bypass the PIN/password lock on Android Gingerbread phones.&lt;br&gt;&#xA;The approach was to boot into the Recovery Mode and execute a reset to factory state. The ideal result should be a reliable wipe of the /data partition. However, the author managed to recover data after the wiping process. This has been stated as a method on extracting sensitive date without knowing the actual pin or passcode.&lt;/p&gt;</description>
    </item>
    <item>
      <title>ERP Platforms Are Vulnerable</title>
      <link>https://insinuator.net/2012/03/erp-platforms-are-vulnerable/</link>
      <pubDate>Thu, 08 Mar 2012 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2012/03/erp-platforms-are-vulnerable/</guid>
      <description>&lt;p&gt;&lt;em&gt;&lt;strong&gt;This is a guest post by the SAP security expert Juan Pablo Perez-Etchegoyen, CTO of  Onapsis. Enjoy reading:&lt;/strong&gt;&lt;/em&gt;&lt;/p&gt;&#xA;&lt;p&gt;At &lt;a href=&#34;http://www.onapsis.com/&#34;&gt;Onapsis&lt;/a&gt; we are continuously researching in the ERP security field to identify the risks that ERP systems and business-critical applications are exposed to. This way we help customers and vendors to increase their security posture and mitigate threats that may be affecting their most important platform: the one that stores and manages their business’ crown jewels.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Groundhog Day: Don’t Pay Money for Some Else’s Calls, Still</title>
      <link>https://insinuator.net/2012/02/groundhog-day-dont-pay-money-for-some-elses-calls-still/</link>
      <pubDate>Fri, 24 Feb 2012 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2012/02/groundhog-day-dont-pay-money-for-some-elses-calls-still/</guid>
      <description>&lt;p&gt;Hi everyone,&lt;br&gt;&#xA;it’s me again with another story of a toll fraud incident at one of our customers (not the same as &lt;a href=&#34;http://www.insinuator.net/2012/02/dont-pay-money-for-someone-elses-calls-again/&#34; title=&#34;Don’t Pay Money for Someone Else’s Calls, Again&#34;&gt;the last time&lt;/a&gt; of course ;-)).&lt;br&gt;&#xA;The story began basically like the last one: We received a call with an urgent request to help investigating a toll fraud issue. Like the last time I visited the site in order to get an idea on what was going on exactly. The customer has a VoIP deployment consisting of the whole UC Suite Cisco offers: Call Manager, Unity Connection for the voice mailboxes, Cisco based Voice-Gateways and of course, IP phones.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Assesment of Visual Voicemail on iPhones</title>
      <link>https://insinuator.net/2012/02/assesment-of-visual-voicemail-on-iphones/</link>
      <pubDate>Wed, 22 Feb 2012 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2012/02/assesment-of-visual-voicemail-on-iphones/</guid>
      <description>&lt;p&gt;&lt;a href=&#34;http://www.insinuator.net/wp-content/uploads/2012/02/vmm.png&#34;&gt;&lt;img src=&#34;http://www.insinuator.net/wp-content/uploads/2012/02/vmm.png&#34; alt=&#34;&#34;&gt;&lt;/a&gt;&lt;/p&gt;&#xA;&lt;p&gt;VVM on iOS 5.0.1&lt;/p&gt;&#xA;&lt;p&gt;Visual Voicemail (VVM) is a common feature of phone providers which allows accessing the good old voice-mailbox through the phone’s visual interface. In contrast to the classical voicemail approach, VVM allows intuitive navigation through voice-messages without dealing with an automated voice which tells you about message count and possible options. However, this implies the need of actually loading the messages of missed calls on the phone. The VVM-app displays missed calls and downloads corresponding messages which have been left by the initial caller. The software comes with your iPhone and is not intended for uninstallation. However, providers have to support it and will have to activate it for supporting clients. This feature is available on iPhones since August 2009 and became available on BlackBerrys and few Nokia phones later. Android doesn’t implement VVM in general. However some telecommunication providers offer their own apps to add this feature. Since version 4.0, Android offers an official Voicemail Provider API enabling better integration for the mobile OS.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Don’t Pay Money for Someone Else’s Calls, Again</title>
      <link>https://insinuator.net/2012/02/dont-pay-money-for-someone-elses-calls-again/</link>
      <pubDate>Thu, 02 Feb 2012 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2012/02/dont-pay-money-for-someone-elses-calls-again/</guid>
      <description>&lt;p&gt;One of our customers called us recently and asked for some support in investigating a toll fraud issue they encountered in one of their sites. Their telecommunications provider had contacted them informing them that they had accumulated a bill of 30.000€ over the last ten days.&lt;/p&gt;&#xA;&lt;p&gt;Without knowing anything more specific, I drove to the affected site to get the whole picture.&lt;/p&gt;&#xA;&lt;p&gt;They have a VoIP deployment based on Cisco Unified Communications Manager (CUCM, aka Call Manager) as Call Agent. The CUCM is connected via a H.323 trunk to a Cisco 2911 ISR G2 which is acting as a voice gateway. The ISR has a primary rate ISDN (PRI) Interface which is connected to the PBX of the telco. Furthermore they use a feature called Direct-inward Dial (DID) or Direct Dial-in (DDI) which is offered by Telco’s to enable calling parties to dial directly to an extension on a PBX or voice gateway.&lt;/p&gt;</description>
    </item>
    <item>
      <title>No Connectivity — No Malware Protection</title>
      <link>https://insinuator.net/2012/01/no-connectivity-no-malware-protection/</link>
      <pubDate>Fri, 06 Jan 2012 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2012/01/no-connectivity-no-malware-protection/</guid>
      <description>&lt;p&gt;During a recent penetration test, we evaluated the security of a typical corporate employee notebook. It was to be assessed whether employees with a default corporate user account would be able to gain administrative access and subsequently abuse the system for attacks against a certain high value database system. When evaluating this problem set, the first step is to find ways to bring tools and exploit code on the system. Usually this task requires the bypassing of the malware protection agent of the system. At some point, we thought we figured a way to &lt;a href=&#34;http://carnal0wnage.attackresearch.com/2010/03/msfencode-msfpayload-into-existing.html&#34;&gt;encode&lt;/a&gt; exploits and payloads in a way that would not be detected by the malware protection solution.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Python Library for De- and Encoding of WCF-Binary streams</title>
      <link>https://insinuator.net/2011/12/python-library-for-de-and-encoding-of-wcf-binary-streams/</link>
      <pubDate>Fri, 23 Dec 2011 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2011/12/python-library-for-de-and-encoding-of-wcf-binary-streams/</guid>
      <description>&lt;p&gt;In a .NET environment WCF services can use the proprietary WCF binary XML protocol described &lt;a href=&#34;https://blogs.msdn.com/b/drnick/archive/2009/09/11/binary-encoding-part-4.aspx&#34;&gt;here&lt;/a&gt;. Microsoft uses this protocol to save some time parsing the transmitted XML data. If you have to (pen-) test such services, it would be nice to read (and modify) the communication between (for example) clients and servers. One possibility is &lt;a href=&#34;http://www.fiddler2.com&#34;&gt;Fiddler&lt;/a&gt;.&lt;/p&gt;&#xA;&lt;p&gt;Fiddler’s strengths include its extensibility and its WCF binary plugins. Sadly, these plugins can only decode and display the binary content as XML text.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Use Python for Burp plugins with pyBurp</title>
      <link>https://insinuator.net/2011/12/use-python-for-burp-plugins-with-pyburp/</link>
      <pubDate>Fri, 23 Dec 2011 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2011/12/use-python-for-burp-plugins-with-pyburp/</guid>
      <description>&lt;p&gt;One of our favorite tools for conducting penetration tests (especially, but not only, web application tests) is Portswiggers’s &lt;a href=&#34;http://portswigger.net/burp/&#34; title=&#34;Burp Suite&#34;&gt;Burp Suite.&lt;/a&gt; Burp allows to extend its features by writing own plugins. But because Burp is written in Java, it only supports Java classes as plugins. Additionally, Burp only allows to use one plugin at the same time which has to be loaded on start-up.&lt;/p&gt;&#xA;&lt;p&gt;Now we have written a Burp-Python proxy (called &lt;strong&gt;pyBurp&lt;/strong&gt;) which adds some features to the plugin system:&lt;/p&gt;</description>
    </item>
    <item>
      <title>How Safe is Smart?</title>
      <link>https://insinuator.net/2011/12/how-safe-is-smart/</link>
      <pubDate>Thu, 22 Dec 2011 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2011/12/how-safe-is-smart/</guid>
      <description>&lt;p&gt;&lt;img src=&#34;http://www.insinuator.net/wp-content/uploads/2011/12/bt_smart_ready.jpg&#34; alt=&#34;Bluetooth Smart Ready Logo&#34; title=&#34;Bluetooth Smart Ready&#34;&gt;About two months ago the Bluetooth SIG &lt;a href=&#34;http://www.bluetooth.com/Pages/Press-Releases-Detail.aspx?ItemID=138%20&#34;&gt;renamed their latest standard&lt;/a&gt;, which was previously known as “Bluetooth v4.0”. When version numbers get higher and higher marketing likes to interfere and try something new. In this case: Bluetooth Smart.&lt;/p&gt;&#xA;&lt;h2 id=&#34;sounds-smart-but-is-it&#34;&gt;Sounds smart, but is it?&lt;/h2&gt;&#xA;&lt;p&gt;Without getting into too much detail, let me quickly quote Wikipedia to get started:&lt;/p&gt;&#xA;&lt;blockquote&gt;&#xA;&lt;p&gt; &lt;em&gt;“Cost-reduced single-mode chips, which enable &lt;strong&gt;highly integrated&lt;/strong&gt; and &lt;strong&gt;compact&lt;/strong&gt; devices, feature a &lt;strong&gt;lightweight&lt;/strong&gt; Link Layer providing &lt;strong&gt;ultra-low power&lt;/strong&gt; idle mode operation, &lt;strong&gt;simple&lt;/strong&gt; device discovery, and &lt;strong&gt;reliable&lt;/strong&gt; point-to-multipoint data transfer with &lt;strong&gt;advanced power-save&lt;/strong&gt; and &lt;strong&gt;secure encrypted&lt;/strong&gt; connections at the &lt;strong&gt;lowest possible cost&lt;/strong&gt;.”&lt;/em&gt;&lt;/p&gt;</description>
    </item>
    <item>
      <title>Liferay Portlet Shell</title>
      <link>https://insinuator.net/2011/12/liferay-portlet-shell/</link>
      <pubDate>Wed, 21 Dec 2011 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2011/12/liferay-portlet-shell/</guid>
      <description>&lt;p&gt;During one of our pentests in some corporate environment we were to analyze an application-server called &lt;a href=&#34;http://www.liferay.com&#34; title=&#34;Download Liferay Portlet Shell&#34;&gt;Liferay&lt;/a&gt;. Liferay comes with a lot of functionalities, runs on top of Apache Tomcat and includes a nice API that makes it very easy to add components or further functionality that are not part of the core. These (potentially selfmade) “addons” are called “portlets” and they can be inserted in any place in the frontend.&lt;/p&gt;</description>
    </item>
    <item>
      <title>pytacle preview</title>
      <link>https://insinuator.net/2011/12/pytacle-preview/</link>
      <pubDate>Sun, 18 Dec 2011 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2011/12/pytacle-preview/</guid>
      <description>&lt;p&gt;Hi,&lt;/p&gt;&#xA;&lt;p&gt;today I’ll give a short preview of my newest tool, pytacle. It is simply a little helper program to control gnuradio/airprobe/kraken/some_other_tools, convert their input/output and to find a use able clear/cipher text combination to break A5/1. In the end it should record, crack and decode/play a gsm phone call with ~5 mouse clicks.&lt;/p&gt;&#xA;&lt;p&gt;Take a look at this video:&lt;/p&gt;&#xA;&lt;p&gt;The code is not available yet, as its not finished 😉 the recording and cracking part are working, but the decoding doesn’t. I need to put some more time into the code, but there isn’t much spare in that time of the year 😀&lt;/p&gt;</description>
    </item>
    <item>
      <title>A Wrap-up on MFD Security</title>
      <link>https://insinuator.net/2011/11/a-wrap-up-on-mfd-security/</link>
      <pubDate>Wed, 16 Nov 2011 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2011/11/a-wrap-up-on-mfd-security/</guid>
      <description>&lt;p&gt;On last year’s &lt;a href=&#34;http://www.troopers.de/archives/troopers11/&#34;&gt;TROOPERS11&lt;/a&gt;, Matthias (mluft) and I gave a &lt;a href=&#34;http://www.troopers.de/wp-content/uploads/2011/04/TR11_Schaefer_Luft_Multifunction_devices.pdf&#34;&gt;talk&lt;/a&gt; on Multifunction Devices. Hardly surprising: It was related to the state of &lt;em&gt;secure&lt;/em&gt; operation of MFDs. It was heavily motivated by experiences we collected out in the wild. We faced a frightening low level of awareness concerning the role of MFDs for the overall security picture – in particular regarding the processing of sensitive data…&lt;/p&gt;&#xA;&lt;p&gt;However, instead of only showing and proving well-known weaknesses and vulnerabilities, we decided to adapt ERNW’s *&lt;a href=&#34;http://www.ernw.de/content/e7/e181/e1612/download1614/ERNW_LANline_VirtCloudSec_Keynote_ger.pdf&#34;&gt;Seven Sisters&lt;/a&gt; *model in order to match the needs of secure MFD operation and to develop some kind of guideline. As Matthias already lost some &lt;a href=&#34;http://www.insinuator.net/2011/04/sisters-act-of-mfd-security/&#34;&gt;words&lt;/a&gt; on this, I’m not gonna waste your valuable time by repeating, what has already been said. However I described our approach and our thoughts on that topic in a recently published &lt;a href=&#34;http://ernw.de/content/e15/e28/index_ger.html&#34;&gt;ERNW Newsletter&lt;/a&gt;. If for what ever reason you didn’t see our talk or even didn’t attend &lt;a href=&#34;http://www.troopers.de/archives/troopers11/&#34;&gt;TROOPERS11&lt;/a&gt; at all, have a look on Newsletter 37 and give us feedback on what you think about the whole topic…&lt;/p&gt;</description>
    </item>
    <item>
      <title>All Your Clouds are Belong to us</title>
      <link>https://insinuator.net/2011/10/all-your-clouds-are-belong-to-us/</link>
      <pubDate>Mon, 24 Oct 2011 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2011/10/all-your-clouds-are-belong-to-us/</guid>
      <description>&lt;p&gt;&lt;a href=&#34;http://www.nds.rub.de/media/nds/veroeffentlichungen/2011/10/22/AmazonSignatureWrapping.pdf&#34;&gt;This&lt;/a&gt; is a _very_ interesting paper just published by some researchers (mainly) from RUB (Ruhr-University Bochum). Here’s the abstract:&lt;/p&gt;&#xA;&lt;p&gt;“Cloud Computing resources are handled through control interfaces. It is through these interfaces that the new machine images can be added, existing ones can be modied, and instances can be started or ceased. Effectively, a successful attack on a Cloud control interface grants the attacker a complete power over the victim’s account, with all the stored data included.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Broken Trust, Part 2: Applying the Approach to… Dropbox</title>
      <link>https://insinuator.net/2011/10/broken-trust-part-2-applying-the-approach-to-dropbox/</link>
      <pubDate>Mon, 03 Oct 2011 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2011/10/broken-trust-part-2-applying-the-approach-to-dropbox/</guid>
      <description>&lt;p&gt;After having introduced the basic elements of our concept of trust, control and confidence in &lt;a href=&#34;http://www.insinuator.net/2011/06/broken-trust-part-1-definitions-fundamentals-some-more-reflections-on-rsa/&#34;&gt;this&lt;/a&gt; post, today I’ll try to strengthen your (and maybe even my own as well ;-)) understanding of these ideas by applying them to another candidate, that is Dropbox. Hence this post is mainly about performing a certain analysis method to some object; conclusions as for the question if Dropbox is suited to be used in enterprise environments processing sensitive data are out of scope and are left entirely to you, the valued reader.&lt;/p&gt;</description>
    </item>
    <item>
      <title>tsakwaf 0.9.1 released</title>
      <link>https://insinuator.net/2011/09/tsakwaf-0.9.1-released/</link>
      <pubDate>Sun, 11 Sep 2011 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2011/09/tsakwaf-0.9.1-released/</guid>
      <description>&lt;p&gt;A few weeks ago, I released version 0.9 of a web application testing tool called tsakwaf (The Swiss Army Knife for Web Application Firewalls) together with an ERNW &lt;a href=&#34;http://www.ernw.de/content/e15/e28/index_ger.html&#34; title=&#34;Newsletter&#34;&gt;Newsletter&lt;/a&gt; about &lt;a href=&#34;http://www.insinuator.net/2011/06/the-5-myths-of-web-application-firewalls/&#34; title=&#34;web application firewalls&#34;&gt;web application firewalls&lt;/a&gt;. tsakwaf is based on perl and supports fingerprinting of some supported WAFs and code generation methods to circumvent filter rules. Today, version 0.9.1 will be released, which adds SSL support for the WAF fingerprinting function (Big thanks to Simon Rich!) and a bug fix regarding the detection of WAF reactions which may lead to false positives. Additionally, I’m happy to announce that at least one talk at next year’s &lt;a href=&#34;http://www.troopers.de&#34; title=&#34;Troopers&#34;&gt;Troopers&lt;/a&gt; will cover attacks against WAFs (like this one from the 2009 &lt;a href=&#34;http://troopers09.org/content/e644/e649/TROOPERS09_gauci_henrique_web_application_firewalls.pdf&#34; title=&#34;edition&#34;&gt;edition&lt;/a&gt;) . So mark your calendar – Troopers12 will happen on 21^(st) and 22^(nd) March 2012, with the usual workshops before the conference and the round table sessions the day after – and enjoy playing with tsakwaf!&lt;/p&gt;</description>
    </item>
    <item>
      <title>The Key to your Datacenter</title>
      <link>https://insinuator.net/2011/07/the-key-to-your-datacenter/</link>
      <pubDate>Tue, 19 Jul 2011 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2011/07/the-key-to-your-datacenter/</guid>
      <description>&lt;p&gt; &lt;/p&gt;&#xA;&lt;p&gt;During our ongoing research on the security of cloud service providers and cloud based applications, we performed a regular audit of our &lt;a href=&#34;http://aws.amazon.com&#34; title=&#34;AWS&#34;&gt;AWS&lt;/a&gt; account password. Thinking of &lt;a href=&#34;http://www.wired.com/threatlevel/2009/07/kaminsky-hacked/&#34;&gt;popular incidents&lt;/a&gt; and evergreens in &lt;a href=&#34;%20http://88.84.128.30/~isnochys/wordpress/wp-content/bruteforce.jpg&#34;&gt;attack vectors&lt;/a&gt;, we were wondering which consequences an online bruteforce attack on our AWS password would have. So we decided to perform a bruteforce attack against our own account. Analyzing the login process of AWS, the following requirements for the bruteforce tool to be used could be derived:&lt;/p&gt;</description>
    </item>
    <item>
      <title>Week of releases – apnbf</title>
      <link>https://insinuator.net/2011/07/week-of-releases-apnbf/</link>
      <pubDate>Thu, 14 Jul 2011 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2011/07/week-of-releases-apnbf/</guid>
      <description>&lt;p&gt;Another day, another tool 😉&lt;/p&gt;&#xA;&lt;p&gt;Today I’m proudly releasing the first version of apnbf, a small python script designed for enumerating valid APNs (Access Point Name) on a GTP-C speaking device. It tries to establish a new PDP session with the endpoint via sending a createPDPContextRequest. This request needs to include a valid APN, so one can easily distinguish from a valid APN (which will be answered with a createPDPContextResponse) and an invalid APN (which will be answered with an error indication message). In addition the tool also parses the error indication and displays the reason (which should be “Missing or unknown APN” in case of an invalid APN).&lt;/p&gt;</description>
    </item>
    <item>
      <title>Week of releases – gtp_scan-0.7</title>
      <link>https://insinuator.net/2011/07/week-of-releases-gtp_scan-0.7/</link>
      <pubDate>Wed, 13 Jul 2011 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2011/07/week-of-releases-gtp_scan-0.7/</guid>
      <description>&lt;p&gt;So, after having a completely new release yesterday, we will stay with already known but updated software today. You might have heard of gtp_scan before, which is a small python script for scanning mainly 3G and 4G devices and detecting GTP (GPRS Tunneling Protocol) enabled ports. As GTP is transported via UDP and we all know, UDP scanning is a pain, the tool uses the GTP build-in echo mechanism to detect GTP speaking ports. Since the last version I’ve implemented some new features:&lt;/p&gt;</description>
    </item>
    <item>
      <title>Week of releases – dizzy</title>
      <link>https://insinuator.net/2011/07/week-of-releases-dizzy/</link>
      <pubDate>Tue, 12 Jul 2011 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2011/07/week-of-releases-dizzy/</guid>
      <description>&lt;p&gt;I’m proud to announce, today a new fuzzing framework will see the light of day. It’s called &lt;em&gt;dizzy&lt;/em&gt; and was written because the tools we used for fuzzing in past didn’t match our requirements. Some (unique) features are:&lt;/p&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;Python based&lt;/li&gt;&#xA;&lt;li&gt;Fast!&lt;/li&gt;&#xA;&lt;li&gt;Can send to L2 as well as to upper layers (TCP/UDP/SCTP)&lt;/li&gt;&#xA;&lt;li&gt;Ability to work with odd length packet fields (no need to match byte borders, so even single flags or 7bit long fields can be represented and fuzzed)&lt;/li&gt;&#xA;&lt;li&gt;Very easy protocol definition syntax&lt;/li&gt;&#xA;&lt;li&gt;Ability to do multi packet state-full fuzzing with the ability to use received target data in response.&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;p&gt;We already had a lot of success using it, now you will be able to know the true promises.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Week of releases – loki-0.2.7</title>
      <link>https://insinuator.net/2011/07/week-of-releases-loki-0.2.7/</link>
      <pubDate>Mon, 11 Jul 2011 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2011/07/week-of-releases-loki-0.2.7/</guid>
      <description>&lt;p&gt;Today I’m going to open up the ‘Week of releases’, which means there will be some new software in the next days.&lt;/p&gt;&#xA;&lt;p&gt;Lets start with a new version of &lt;em&gt;loki&lt;/em&gt;. The version goes up to 0.2.7 and there are a lot of new features:&lt;/p&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;SCTP support in the base.&lt;/li&gt;&#xA;&lt;li&gt;Invalid option and invalid header scan in the ICMP6 module.&lt;/li&gt;&#xA;&lt;li&gt;On-line msg updates for neighbor messages in the RIP module.&lt;/li&gt;&#xA;&lt;li&gt;New module for rewriting 802.1Q labels&lt;/li&gt;&#xA;&lt;li&gt;Lots of small improvements and bug-fixes&lt;/li&gt;&#xA;&lt;li&gt;Some new features I won’t tell right now, get the source and find them yourself 😉&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;p&gt;Also there are new packages for gentoo, ubuntu-11.04 and fedora-15, also its the first time, packages for amd64 systems are available.&lt;/p&gt;</description>
    </item>
    <item>
      <title>The 5 Myths of Web Application Firewalls</title>
      <link>https://insinuator.net/2011/06/the-5-myths-of-web-application-firewalls/</link>
      <pubDate>Mon, 27 Jun 2011 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2011/06/the-5-myths-of-web-application-firewalls/</guid>
      <description>&lt;p&gt;Some days ago a security advisory related to web application firewalls (WAFs) was published on Full Disclosure. Wendel Guglielmetti Henrique found another bug in the IBM Web Application Firewall which can be used to circumvent the WAF and execute typical web application attacks like SQL injection (click here for details). Wendel talked already (look &lt;a href=&#34;http://troopers09.org/content/e644/e649/TROOPERS09_gauci_henrique_web_application_firewalls.pdf%20&#34;&gt;here&lt;/a&gt;) at the &lt;a href=&#34;http://www.troopers.de&#34;&gt;Troopers&lt;/a&gt; Conference in 2009 about the different techniques to identify and bypass WAFs, so this kind of bypass methods are not quite new.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Broken Trust, Part 1: Definitions &amp; Fundamentals &#43; Some More Reflections on RSA</title>
      <link>https://insinuator.net/2011/06/broken-trust-part-1-definitions-fundamentals--some-more-reflections-on-rsa/</link>
      <pubDate>Sun, 19 Jun 2011 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2011/06/broken-trust-part-1-definitions-fundamentals--some-more-reflections-on-rsa/</guid>
      <description>&lt;p&gt;This again is going to be a little series of posts. Their main topic – next to the usual deviations &amp;amp; ranting I tend to include in blogposts 😉 – is some discussion of “trust” and putting this discussion into the context of recent events and future developments in the infosec space. The title originates from a conversation between Angus Blitter and me in a nice Thai restaurant in Zurich where we figured the consequences of the &lt;a href=&#34;http://arstechnica.com/security/news/2011/06/rsa-finally-comes-clean-securid-is-compromised.ars%20&#34;&gt;latest RSA revelations&lt;/a&gt;. While we both expect that – unfortunately – not much is really going to happen (surprisingly many people, including some CSOs we know, are still trying to somehow downplay this or sweep it under the carpet, shying away from the – obvious – consequences it might have to accept that for a number of environments RSA SecurID is potentially reduced to single factor auth nowadays…), the long term impact on our understanding of 3rd party (e.g. vendor) trust might be more interesting. Furthermore “Broken Trust” seems a promising title for a talk at upcoming &lt;a href=&#34;http://www.day-con.org&#34;&gt;Day-Con V&lt;/a&gt;… 😉&lt;/p&gt;</description>
    </item>
    <item>
      <title>Extracting Data from Very Large Pcap Files – Part 3: Pcap Filtering in the Cloud</title>
      <link>https://insinuator.net/2011/06/extracting-data-from-very-large-pcap-files-part-3-pcap-filtering-in-the-cloud/</link>
      <pubDate>Mon, 13 Jun 2011 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2011/06/extracting-data-from-very-large-pcap-files-part-3-pcap-filtering-in-the-cloud/</guid>
      <description>&lt;p&gt;This is the third (and last) part of the series (parts &lt;a href=&#34;http://www.insinuator.net/2011/04/extracting-data-from-very-large-pcap-files-part-1-tools-and-hardware/%20&#34;&gt;1&lt;/a&gt; &amp;amp; &lt;a href=&#34;http://www.insinuator.net/2011/06/extracting-data-from-very-large-pcap-files-%E2%80%93-part-2-results-from-the-local-lab/%20&#34;&gt;2&lt;/a&gt; here). We’ll provide the results from some additional tests supported by public cloud services, namely AWS (Amazon Web Services).&lt;/p&gt;&#xA;&lt;p&gt; &lt;br&gt;&#xA;&lt;strong&gt;Lab Setup&lt;/strong&gt;&lt;/p&gt;&#xA;&lt;p&gt;The Amazon Elastic Compute Cloud (short: EC2) provides a flexible environment for the on demand provisioning of virtual machines of different performance levels. For our lab setup, a so-called extra large instance was used. According to Amazon, the technical specs are the following:&lt;/p&gt;</description>
    </item>
    <item>
      <title>Extracting Data from Very Large Pcap Files – Part 2: Results from the Local Lab</title>
      <link>https://insinuator.net/2011/06/extracting-data-from-very-large-pcap-files-part-2-results-from-the-local-lab/</link>
      <pubDate>Thu, 02 Jun 2011 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2011/06/extracting-data-from-very-large-pcap-files-part-2-results-from-the-local-lab/</guid>
      <description>&lt;p&gt;In the &lt;a href=&#34;http://www.insinuator.net/2011/04/extracting-data-from-very-large-pcap-files-part-1-tools-and-hardware/&#34;&gt;first post&lt;/a&gt; I’ve laid out the tools and lab setup, so in this one I’m going to discuss some results.&lt;/p&gt;&#xA;&lt;p&gt;&lt;strong&gt;Description of overall test methodology&lt;/strong&gt;&lt;/p&gt;&#xA;&lt;p&gt;To evaluate the performance of the different setups used to analyze capture data, both tcpdump and pcap_extractor (see last post) were used. For the tests, five capture files were created using mergecap. Various sample traffic dumps were merged to five large files with different file sizes. All these files consisted of several capture files containing a variety of protocols (including iSCSI and FCoE packets). Capture files of ∼40, ∼80, ∼200, ∼500, and ∼800 GB size were created and were analyzed with both tools. For all tests the filtering expressions for tcpdump and pcap_extractor were configured to search for a specific source IP and a specific destination IP matching to iSCSI packets contained in the capture file. Additionally pcap_extractor was “instructed” to look for some search string (formatted like a credit card number).To address the performance bottleneck (again, see last post), that is the I/O throughput, two different setups of the testing environment (see above) were implemented, the first one going with a raid0 approach using four SSD hard drives, the second one with four individual SSD hard drives, each of them processing only a fourth of the analyzed capture file. Standard UNIX time command was invoked to measure the time of execution. Additionally the tools analyzing the data were started with the highest possible scheduling priority to ensure execution with the maximum of available resources. This is a sample command line invoking the test:&lt;/p&gt;</description>
    </item>
    <item>
      <title>update for your fuzzing toolkit</title>
      <link>https://insinuator.net/2011/05/update-for-your-fuzzing-toolkit/</link>
      <pubDate>Mon, 02 May 2011 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2011/05/update-for-your-fuzzing-toolkit/</guid>
      <description>&lt;p&gt;As I’m currently developing the ‘next gen’ state-full fuzzing framework @ERNW [called dizzy, to be released soon 😉 ], I will give you an updated set of fuzzing scripts from the ‘old world’.&lt;/p&gt;&#xA;&lt;p&gt;Some of you will remember the 2008 release of sulley_l2, which was a modified version of the sulley fuzzing framework, enhanced with Layer 2 sending capabilities and a hole bunch of (L2) fuzzing scripts. All the blinking, rebooting, mem-corrupting ciscos gave us some attention. Back from then, we continued to write and use the fuzzing scripts, so the hole collection grew.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Extracting Data from Very Large Pcap Files – Part 1: Tools and Hardware</title>
      <link>https://insinuator.net/2011/04/extracting-data-from-very-large-pcap-files-part-1-tools-and-hardware/</link>
      <pubDate>Thu, 28 Apr 2011 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2011/04/extracting-data-from-very-large-pcap-files-part-1-tools-and-hardware/</guid>
      <description>&lt;p&gt;There is a common misconception that the sheer amount of data coupled with multiplexed channels (e.g. WDM technology) make successful eavesdropping attacks on high speed Ethernet links – like those connecting data centers – highly unlikely. This is mainly based on the assumption that the amount of resources (e.g. RAM, [sufficiently fast] storage or CPU power) needed to process large files of captured data is a limiting factor. However, to the best of our knowledge, no practical evaluation of these assumptions has so far been performed.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Sisters’ Act of MFD Security</title>
      <link>https://insinuator.net/2011/04/sisters-act-of-mfd-security/</link>
      <pubDate>Thu, 07 Apr 2011 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2011/04/sisters-act-of-mfd-security/</guid>
      <description>&lt;p&gt;Recently Micele and I were researching for our talk about the current state of security of Multifunction Devices (MFDs). Since we’re both seasoned pentesters who are quite familar with MFDs, we were really surprised that very little new research is going on on the topic of MFD security. While diving deeper into the topic, we found a very simple explanation for this: As in 2002, it is still possible to download print or scan jobs using &lt;a href=&#34;http://h20000.www2.hp.com/bc/docs/support/SupportManual/bpl13208/bpl13208.pdf&#34;&gt;PJL&lt;/a&gt;, many devices still offer default FTP or Telnet access, and, of course, stored files can be recovered from MFD hard drives — on an enterprise wide scale. To even strengthen our impression of the current state of MFD security, most devices crashed or did go wild while performing some scans — and we do not talk about fuzzing here.&lt;/p&gt;</description>
    </item>
    <item>
      <title>RSA: Anatomy of an Attack</title>
      <link>https://insinuator.net/2011/04/rsa-anatomy-of-an-attack/</link>
      <pubDate>Wed, 06 Apr 2011 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2011/04/rsa-anatomy-of-an-attack/</guid>
      <description>&lt;p&gt;Lots of stuff has been written about &lt;a href=&#34;http://blogs.rsa.com/rivner/anatomy-of-an-attack/&#34;&gt;this blog post&lt;/a&gt; from RSA describing the (potential) details of the attack, so I will refrain from detailed comments on this piece that Marsh Ray nicely called “some of the most egregious hyperbole I’ve read in infosec”.&lt;/p&gt;&#xA;&lt;p&gt;Just one short note. Presumably the attack, in an early stage, used a “spreadsheet [that] contained a zero-day exploit that installs a backdoor through an Adobe Flash vulnerability (CVE-2011-0609)”.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Reflections on the RSA Break-in</title>
      <link>https://insinuator.net/2011/03/reflections-on-the-rsa-break-in/</link>
      <pubDate>Sun, 20 Mar 2011 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2011/03/reflections-on-the-rsa-break-in/</guid>
      <description>&lt;p&gt;Some of you may have heard of the &lt;a href=&#34;http://www.rsa.com/node.aspx?id=3872&#34;&gt;break-in at RSA&lt;/a&gt; and may now be wondering “what does this mean to us?” and “what can be done?”. Not being an expert on RSA SecurID at all – I’ve been involved in some projects, however not on the technical implementation side but on the architecture or overall [risk] management side – I’ll still try to contribute to the debate 😉&lt;/p&gt;&#xA;&lt;p&gt;Feel free to correct me either by comment or by personal email in case the following contains factual errors.&lt;/p&gt;</description>
    </item>
    <item>
      <title>VMSA-2011-0005: VMware vCenter Orchestrator remote code execution vulnerability</title>
      <link>https://insinuator.net/2011/03/vmsa-2011-0005-vmware-vcenter-orchestrator-remote-code-execution-vulnerability/</link>
      <pubDate>Mon, 14 Mar 2011 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2011/03/vmsa-2011-0005-vmware-vcenter-orchestrator-remote-code-execution-vulnerability/</guid>
      <description>&lt;p&gt;Reading &lt;a href=&#34;http://www.vmware.com/security/advisories/VMSA-2011-0005.html&#34;&gt;this advisory&lt;/a&gt; I’m quite tempted to emit another rant on the relationship of heavy use of 3rd party components, lack of (security) quality assurance and services running at times where they’re not needed (see second workaround &lt;a href=&#34;http://kb.vmware.com/selfservice/microsites/search.do?language=en_US&amp;amp;cmd=displayKC&amp;amp;externalId=1034175&#34;&gt;here&lt;/a&gt;). I’ll refrain  from that for today. Just wanted to let you know that the &lt;a href=&#34;http://blog.o0o.nu/2010/07/cve-2010-1870-struts2xwork-remote.html&#34;&gt;underlying vulnerability&lt;/a&gt; in Struts2 was initially discovered by Meder Kydyraliev who gives &lt;a href=&#34;http://www.troopers.de/troopers11/agenda/milking-a-horse-or-executing-remote-code-in-modern-java-web-frameworks/&#34;&gt;this talk&lt;/a&gt; at &lt;a href=&#34;http://www.troopers.de&#34;&gt;Troopers&lt;/a&gt; in two weeks. He’ll certainly describe the inner workings of this one, and others… 😉&lt;/p&gt;</description>
    </item>
    <item>
      <title>GTP_SCAN released</title>
      <link>https://insinuator.net/2011/03/gtp_scan-released/</link>
      <pubDate>Tue, 01 Mar 2011 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2011/03/gtp_scan-released/</guid>
      <description>&lt;p&gt;gtp_scan is a small python script that scans for GTP (GPRS tunneling protocol) speaking hosts. To discover those hosts it uses the GTP build in PING mechanism, it sends a GTP packet of the type ECHO_REQUEST and listens for an incoming GTP ECHO_REPLY. Its capable of generating ECHO_REQUESTS for GTP version 1 and GTP version 2. Also the script can scan for both, GTP-C and GTP-U (the control channel and the user data channel), only the port differs here.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Some More Security Research on The nPA AusweisApp</title>
      <link>https://insinuator.net/2010/11/some-more-security-research-on-the-npa-ausweisapp/</link>
      <pubDate>Mon, 22 Nov 2010 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2010/11/some-more-security-research-on-the-npa-ausweisapp/</guid>
      <description>&lt;p&gt;After the initial quick shot (see this &lt;a href=&#34;http://www.insinuator.net/2010/11/our-contribution-to-the-public-discussion-about-the-german-new-id-card-npa/&#34;&gt;post&lt;/a&gt;) we decided to have a closer look. And some more stuff turned up.&lt;/p&gt;&#xA;&lt;p&gt;After decompiling the integrated java stuff we stumbled about hard coded server credentials:&lt;/p&gt;&#xA;&lt;p&gt;&lt;code&gt;package Idonttell;&lt;/code&gt;&lt;/p&gt;&#xA;&lt;p&gt;&lt;code&gt; &lt;/code&gt;&lt;/p&gt;&#xA;&lt;p&gt;&lt;code&gt; public abstract interface Idonttell&lt;/code&gt;&lt;br&gt;&#xA;&lt;code&gt;{&lt;/code&gt;&lt;br&gt;&#xA;&lt;code&gt;public static final boolean debug = false;&lt;/code&gt;&lt;br&gt;&#xA;&lt;code&gt;public static final boolean auth = true;&lt;/code&gt;&lt;br&gt;&#xA;&lt;code&gt;public static final String SMTP_SERVER = &amp;quot;Idonttell.openlimit.com&amp;quot;;&lt;/code&gt;&lt;br&gt;&#xA;&lt;code&gt;public static final String SMTP_USER = &amp;quot;Idonttell@Idonttell.openlimit.com&amp;quot;;&lt;/code&gt;&lt;br&gt;&#xA;&lt;code&gt;public static final String SMTP_PASSWORD = &amp;quot;Idonttell&amp;quot;;&lt;/code&gt;&lt;br&gt;&#xA;&lt;code&gt;public static final String SEND_FROM = &amp;quot;Idonttell@Idonttell.openlimit.com&amp;quot;;&lt;/code&gt;&lt;br&gt;&#xA;&lt;code&gt;public static final String[] SEND_TO = { &amp;quot;buergerclient.it-solutions@Idonttell.com&amp;quot; };&lt;/code&gt;&lt;br&gt;&#xA;&lt;code&gt;public static final String MAIL_HEADER_FIELD = &amp;quot;OpenLimitErrorMessage&amp;quot;;&lt;/code&gt;&lt;br&gt;&#xA;&lt;code&gt;public static final String MAIL_HEADER_FIELD_PROP = &amp;quot;yes&amp;quot;;&lt;/code&gt;&lt;br&gt;&#xA;&lt;code&gt;}&lt;/code&gt;&lt;/p&gt;</description>
    </item>
    <item>
      <title>Our contribution to the public discussion about the German new ID card (nPA)</title>
      <link>https://insinuator.net/2010/11/our-contribution-to-the-public-discussion-about-the-german-new-id-card-npa/</link>
      <pubDate>Thu, 11 Nov 2010 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2010/11/our-contribution-to-the-public-discussion-about-the-german-new-id-card-npa/</guid>
      <description>&lt;p&gt;Currently there’s quite some discussion about the security properties and posture of the German new ID card (“Neuer Personalausweis”, “nPA”, some technically reasonable security discussion can here be found e.g. &lt;a href=&#34;http://blog.cj2s.de/categories/5-German-ID-Cad-nPA&#34;&gt;here&lt;/a&gt;.&lt;/p&gt;&#xA;&lt;p&gt;While – as of our current knowledge – we do not expect major security flaws on the architecture level, the problems discussed so far (like &lt;a href=&#34;http://www.troopers08.org/content/e6/e461/AMATOFrancisco-evilgrade-ENG-Troopers-fk.pdf&#34;&gt;Evilgrade&lt;/a&gt; style attacks against one of the main applications or keylogging the PIN in scenarios with &lt;a href=&#34;http://www.ccc.de/de/updates/2010/sicherheitsprobleme-bei-suisseid-und-epa&#34;&gt;pinpad-less readers&lt;/a&gt; ) certainly show that security best practices must be followed by all parties involved in the development, deployment and use of the nPA and it’s associated applications. From our perspective this may be expected from the applications’ developers as well.&lt;br&gt;&#xA;Looking at this:&lt;/p&gt;</description>
    </item>
    <item>
      <title>Back to the roots</title>
      <link>https://insinuator.net/2010/09/back-to-the-roots/</link>
      <pubDate>Fri, 24 Sep 2010 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2010/09/back-to-the-roots/</guid>
      <description>&lt;p&gt;Finding exploitable vulnerabilities is getting harder. This statement of Dennis Fisher published on &lt;a href=&#34;http://threatpost.com/en_us/blogs/easily-exploitable-bugs-becoming-precious-commodity-090110&#34;&gt;Kaspersky’s Threatpost blog&lt;/a&gt; summarizes a trend in the development lifecycle of software . The last published vulnerabilities that were gaining some attention in the public had all one thing in common, they were quite hard to exploit. The so called jailbreakme vulnerability was based on several different vulnerabilities that had to be chained together to break out of the iPhone sandbox, escalate its privileges and run arbitrary code. Modern software and especially modern operating systems are more secure, they contain less software flaws and more protection features that make reliable exploitation a big problem that can only be solved by very skilled hackers. Decades ago it was just like this, but intelligent tools and sharing of the needed knowledge enabled even low skilled people to develop working exploits and attack vulnerable systems. Nowadays we are going back to the roots where only a few very knowledgeable people are able to circumvent modern security controls, but that doesn’t mean that all problems are gone. Attackers are moving to design flaws like the DLL highjacking problem, so only the class of attacks is changing from the old school memory corruption vulnerabilities to logical flaws that still can be exploited easily. But the number of exploitable vulnerabilities is decreasing, so this might be a sign that we are on the right way to develop reliable and secure systems and that developing companies are adopting Microsofts Secure Development Lifecycle (SDL) to produce more secure software. As stated in my previous &lt;a href=&#34;http://www.insinuator.net/2010/07/software-developers-dont-use-available-security-features/&#34;&gt;blogpost&lt;/a&gt; the protection features are available, but not used very often. But if they are used and if the developers are strictly following the recommendations of the SDL, this trend of “harder to exploit vulnerabilities” proves that it can be a success story to do so.&lt;/p&gt;</description>
    </item>
    <item>
      <title>MS10-063, Prevention</title>
      <link>https://insinuator.net/2010/09/ms10-063-prevention/</link>
      <pubDate>Wed, 15 Sep 2010 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2010/09/ms10-063-prevention/</guid>
      <description>&lt;p&gt;One of the four vulnerabilities rated “critical” from yesterday’s MS patchday, that is &lt;a href=&#34;http://www.microsoft.com/technet/security/bulletin/MS10-063.mspx&#34;&gt;MS10-063&lt;/a&gt;, has an interesting “Workarounds” section as for MS Internet Explorer. There it’s stated:&lt;/p&gt;&#xA;&lt;p&gt;“Disabling the support for the parsing of embedded fonts in Internet Explorer prevents this application from being used as an attack vector.”&lt;/p&gt;&#xA;&lt;p&gt;which, according to the advisory, should/can be done by setting the “Font Downloading” parameter to “Disable”.&lt;/p&gt;&#xA;&lt;p&gt;Which is exactly what &lt;a href=&#34;http://www.ernw.de/content/e15/e28/e1497/download1499/ERNW_Newsletter_31_Secure_IE8_Configuration_en_ger.pdf&#34;&gt;this document&lt;/a&gt; suggests. So taking a preventive approach, once more, might have saved some concerns (“Will we be targeted by this one”) and patch/testing time…&lt;/p&gt;</description>
    </item>
    <item>
      <title>“blackberry api to record phone calls”</title>
      <link>https://insinuator.net/2010/08/blackberry-api-to-record-phone-calls/</link>
      <pubDate>Wed, 25 Aug 2010 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2010/08/blackberry-api-to-record-phone-calls/</guid>
      <description>&lt;p&gt;This is currently the most frequent search term leading Internet users to the Troopers website.&lt;br&gt;&#xA;Probably &lt;a href=&#34;http://www.troopers.de/content/e728/e897/e900/TROOPERS10_Bugs_and_Kisses_Sheran_Gunasekera.pdf&#34;&gt;Sheran Gunasekera’s great presentation “Bugs &amp;amp; Kisses – Spying on BlackBerry users for fun”&lt;/a&gt; is the piece they are after. Whatever they look for, this search term may help to shed light to an aspect that seems a bit overlooked in the ongoing debate about governments (U.A.E., Saudi Arabia, India) trying to get their hands on communication acts performed with BlackBerries in their countries.&lt;br&gt;&#xA;[For those interested in that discussion &lt;a href=&#34;http://www.schneier.com/blog/archives/2010/08/uae_to_ban_blac.html&#34;&gt;this blog entry of Bruce Schneier&lt;/a&gt; may serve as a starting point.]&lt;/p&gt;</description>
    </item>
    <item>
      <title>Just a Quick Note on the Library Loading / Binary Planting Stuff</title>
      <link>https://insinuator.net/2010/08/just-a-quick-note-on-the-library-loading-/-binary-planting-stuff/</link>
      <pubDate>Tue, 24 Aug 2010 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2010/08/just-a-quick-note-on-the-library-loading-/-binary-planting-stuff/</guid>
      <description>&lt;p&gt;For those of you who missed it: Microsoft released the &lt;a href=&#34;http://www.microsoft.com/technet/security/advisory/2269637.mspx&#34;&gt;associated advisory&lt;/a&gt; yesterday, together with a &lt;a href=&#34;http://support.microsoft.com/?kbid=2264107&#34;&gt;hotfix&lt;/a&gt; introducing a new registry key that allows users to control the DLL search path algorithm. For a detailed explanation of the problem we refer to &lt;a href=&#34;http://arstechnica.com/microsoft/news/2010/08/new-windows-dll-security-flaw-everything-old-is-new-again.ars&#34;&gt;the excellent article on Ars Technica&lt;/a&gt;.&lt;/p&gt;&#xA;&lt;p&gt;For the record: no, AV (anti-virus software) will – in most cases – not protect you from security problems related to this one. And, no, there is no easy patch for this one either.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Research on “Application Virtualization” – Results online now</title>
      <link>https://insinuator.net/2010/08/research-on-application-virtualization-results-online-now/</link>
      <pubDate>Mon, 16 Aug 2010 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2010/08/research-on-application-virtualization-results-online-now/</guid>
      <description>&lt;p&gt;Just wanted to let you know that we sent out &lt;a href=&#34;http://ernw.de/content/e15/e28/e1575/download1577/ERNW_Newsletter_32_ThinApp_signed_en_ger.pdf&#34;&gt;ERNW Newsletter 32&lt;/a&gt; end of last week. As we &lt;a href=&#34;http://www.insinuator.net/2010/08/application-virtualization-as-browser-security-control/&#34;&gt;promised&lt;/a&gt; it includes the results of  research regarding the question “Is browser virtualization a valid security control in order to mitigate browser based security risks?”.&lt;/p&gt;&#xA;&lt;p&gt;Simon did a great job with writing the latest newsletter. It’s a 30-page document which should help you to have a basis for well-informed decisions when it comes to the deployment of an application virtualization technology.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Try Loki!</title>
      <link>https://insinuator.net/2010/08/try-loki/</link>
      <pubDate>Wed, 11 Aug 2010 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2010/08/try-loki/</guid>
      <description>&lt;p&gt;&lt;a href=&#34;http://www.insinuator.net/wp-content/uploads/2010/08/ERNW_loki_tool.jpg&#34;&gt;&lt;img src=&#34;http://www.insinuator.net/wp-content/uploads/2010/08/ERNW_loki_tool.jpg&#34; alt=&#34;Loki is set free!&#34; title=&#34;ERNW_loki_tool&#34;&gt;&lt;/a&gt;&lt;/p&gt;&#xA;&lt;p&gt;Everybody who is interested in our newest tool ‘Loki’ is welcomed to head over to &lt;a href=&#34;http://ernw.de/content/e6/e180/index_eng.html&#34;&gt;ERNW’s tool section&lt;/a&gt; and download it. Take this monster for a spin and let us know in the comments how you like it. Loki’s coding father Daniel is more than happy to answer your questions and criticism.&lt;/p&gt;&#xA;&lt;p&gt;You don’t even know what Loki is?&lt;/p&gt;&#xA;&lt;p&gt;In short: An advanced security testing tool for layer 3 protocols.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Application Virtualization as Browser Security Control?</title>
      <link>https://insinuator.net/2010/08/application-virtualization-as-browser-security-control/</link>
      <pubDate>Mon, 09 Aug 2010 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2010/08/application-virtualization-as-browser-security-control/</guid>
      <description>&lt;p&gt;One of the biggest pains in the ass of most ISOs – and subsequently subject of fierce debates between business and infosec – is the topic of “Browser Security”, i.e. essentially the question “How to protect the organization from malicious code  brought into the environment by users surfing the Internet?”.&lt;/p&gt;&#xA;&lt;p&gt;Commonly the chain of events (of a typical malware infection act) can be broken down to the following steps:&lt;/p&gt;&#xA;&lt;p&gt;1.) Some code – no matter if binary or script code – gets transferred (mostly: downloaded) to some system “from the Internet”, that means “over the network”.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Spooky Story about Break-In in Military Contractor Facility</title>
      <link>https://insinuator.net/2010/07/spooky-story-about-break-in-in-military-contractor-facility/</link>
      <pubDate>Sun, 25 Jul 2010 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2010/07/spooky-story-about-break-in-in-military-contractor-facility/</guid>
      <description>&lt;p&gt;… recently published &lt;a href=&#34;http://www.tampabay.com/news/publicsafety/crime/thieves-swipe-thousands-of-laptops-from-special-ops-contractor-in/1108521&#34;&gt;here&lt;/a&gt;.&lt;br&gt;&#xA;While I certainly agree with those comments stating that there’s a fishy element in the – conspiracy theory nurturing – story itself, this reminds me that Graeme Neilson (who gave the “&lt;a href=&#34;http://www.troopers.de/content/e728/e897/e938/TROOPERS10_Netscreen_of_the_Dead_Graeme_Neilson.pdf&#34;&gt;Netscreen of the Dead&lt;/a&gt;” talk at &lt;a href=&#34;http://www.troopers.de&#34;&gt;Troopers&lt;/a&gt;, discussing modified firmware on Juniper and Fortinet devices) and I plan to give a talk on “Supply Chain (In-)Security” at this year’s &lt;a href=&#34;http://www.day-con.org&#34;&gt;Day-Con&lt;/a&gt; event. We still have to figure out with Angus if it fits into the agenda (and if we have enough material for an interesting 45 min storyline ;-)) though. Stay tuned for news on this here.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Some reflections on virtualization security, part 1</title>
      <link>https://insinuator.net/2009/12/some-reflections-on-virtualization-security-part-1/</link>
      <pubDate>Mon, 07 Dec 2009 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2009/12/some-reflections-on-virtualization-security-part-1/</guid>
      <description>&lt;p&gt;Today was an interesting day, for a number of reasons. Amongst those it stuck out that we were approached by two very large environments (both &amp;gt; 50K employees) to provide security review/advise, as they want to “virtualize their DMZs, by means of VMware ESX”.&lt;br&gt;&#xA;[yes, more correctly I could/should have written: “virtualize some of their DMZ segments”. but this essentially means: “mostly all of their DMZs” in 6-12 months. and “their DMZ backend systems together with some internal servers” in 12-24 months. and “all of this” in 24-36 months. so it’s the same discussion anyway, just on a shifted timescale ;-)]&lt;/p&gt;</description>
    </item>
    <item>
      <title>New SSL/TLS MiTM Attacks</title>
      <link>https://insinuator.net/2009/11/new-ssl/tls-mitm-attacks/</link>
      <pubDate>Mon, 09 Nov 2009 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2009/11/new-ssl/tls-mitm-attacks/</guid>
      <description>&lt;p&gt;A number of customers has approached us with questions like “Those new MiTM attacks against SSL/TLS, what’s their impact as for the security of our SSL VPNs with client certificates”?&lt;br&gt;&#xA;In the following we give our estimation, based on the information publicly available as of today.&lt;/p&gt;&#xA;&lt;p&gt;On 11/04/09 two security researchers (Marsh Ray and Steve Dispensa) published a &lt;a href=&#34;http://extendedsubset.com/Renegotiating_TLS.pdf&#34;&gt;paper&lt;/a&gt; describing some previously (presumably/hopefully) unknown MiTM attacks against SSL/TLS. CVE-2009-3555 was assigned to the underlying vulnerabilities within SSL/TLS.&lt;br&gt;&#xA;The attacks described might potentially allow an attacker to hijack an authenticated user’s (SSL/TLS) session. In an &lt;a href=&#34;https://svn.resiprocate.org/rep/ietf-drafts/ekr/draft-rescorla-tls-renegotiate.txt&#34;&gt;IETF draft&lt;/a&gt; published 11/09/09 and describing a potential protocol extension intended to mitigate the attacks the following is stated:&lt;br&gt;&#xA;“SSL and TLS renegotiation are vulnerable to an attack in which the attacker forms a TLS connection with the target server, injects content of his choice, and then splices in a new TLS connection from a client.  The server treats the client’s initial TLS handshake as a renegotiation and thus believes that the initial data transmitted by the attacker is from the same entity as the subsequent client data.”&lt;/p&gt;</description>
    </item>
    <item>
      <title>If they had used DLP…</title>
      <link>https://insinuator.net/2009/10/if-they-had-used-dlp/</link>
      <pubDate>Sat, 31 Oct 2009 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2009/10/if-they-had-used-dlp/</guid>
      <description>&lt;p&gt;… &lt;a href=&#34;http://www.securityfocus.com/brief/1030&#34; title=&#34;Security Focus on Peer to Peer Data Loss&#34;&gt;this&lt;/a&gt; would not have happened. At least this is what $SOME_DLP_VENDOR might tell you.&lt;br&gt;&#xA;Maybe, maybe not. It wouldn’t have happened if they’d followed “common security best practices” either. Like “not to process sensitive data on (presumably) private laptops” or “not to run file sharing apps on organizational ones” or “not to connect to organizational VPNs and home networks simultanously”. yadda yadda yadda.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Series on “Outdated Threat Models” – Part 1</title>
      <link>https://insinuator.net/2009/10/series-on-outdated-threat-models-part-1/</link>
      <pubDate>Sun, 25 Oct 2009 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2009/10/series-on-outdated-threat-models-part-1/</guid>
      <description>&lt;p&gt;Yesterday I took a long run (actually I did the full distance &lt;a href=&#34;http://www.albmarathon.de&#34;&gt;here&lt;/a&gt;) and usually such exercises are good opportunities to “reflect on the world in general and the infosec dimension of it in particular”… at least as long as your blood sugar is still on a level to support somewhat reasonable brain activity 😉&lt;/p&gt;&#xA;&lt;p&gt;Anyhow, one of the outcomes of the number of strange mental stages I went through was the idea of a series of blogposts on architectural or technological approaches that are widely regarded as “good security practice” but may – when looked at with a bit more of scrutiny – turn out to be based on what I’d call “outdated threat models”.&lt;/p&gt;</description>
    </item>
  </channel>
</rss>
