It has been a year since fragmentation attacks in IPv6 were last examined
publicly (in
Black Hat Europe 2012).
Issues well known from the IPv4 era appeared again in IPv6. Surprisingly enough,
some of the most popular Operating Systems (OS), included ones considered
“secure”, were proven to be vulnerable to such attacks, although fragmentation
overlapping is strictly forbidden in IPv6 since 2009 (RFC5722). Some other OS,
although in a better shape, still appeared to have some issues in specific
cases.
at first a happy new year to all our readers!
And, of course, to everybody else, too ;-). May 2013 bring good things for you
all, in particular (but not only) in the infosec space.
At the recent ATSAC 2012 conference a guy from the CERT
Insider Threat Center gave a talk on the exact topic. Given that the
ENISA Cloud Computing Risk Assessment lists
“Cloud Provider Malicious Insider” as one of the top eight risks (out of overall
35 risks evaluated) and we just had some discussion about this in a customer
environment, this might be of interest for some readers.
Recommendations by the
German Federal Office for Information Security
(BSI – Bundesamt für Sicherheit in der Informationstechnik) are obligatory for
German government agencies, civil services and authorities (like recommendations
of the NIST are relevant to American government agencies and authorities). They
are often used as references and security best practices in other countries as
well. Hence it is hard to understand why the recommendations on how to harden
Windows Server 2008 based systems were published only some weeks ago and
only on a preliminary draft basis (which is, obviously, better than nothing
;-)).
As
in 2011
we really liked the conference; there was a number of interesting talks and we
met quite some fellows from the IPv6 security space. Btw: we plan to organize a
dedicated IPv6 security summit in late 2012 (probably on 6th and 7th of
November) in Heidelberg, similar to the
Telco Sec Day
at Troopers. We’ll annouce details as for this one in some weeks.
TROOPERS12 came to an end last week on Friday; needless to say it was an
awesome event. 😉
The first two days offered workshops on various topics. On Monday Enno,
Marc “Van Hauser” Heuse and I gave a one day workshop on
“Advanced IPv6 Security”. I think attendees as well as trainers had a real good
time during and after the workshop fiddling around with IPv6. Especially Marc
had quite some fun as he discovered that we provided “global” IPv6 Connectivity
for the conference network, and according to one of his tweets, TROOPERS12 was
the first security conference he visited, offering this kind of connectivity.
if you’re following this blog regularly or if you’ve ever attended an
ERNW-led workshop which included an
“architecture section” you will certainly remember the “Seven Sisters of
Infrastructure Security” stuff (used for example in
this post).
These are a number of (well, more precisely, it’s seven ;-)) fundamental
security principles which can be applied to any complex infrastructure, be that
a network, a building, an airport or the like.
As part of our upcoming
Black Hat
and
Troopers
talks we will apply those principles to some VoIP networks we (security-)
assessed and, given we won’t cover them in detail there, it might be helpful to
perform a quick refresher of them, together with an initial application to VoIP
deployments. Here we go; these are the “Seven Sisters of Infrastructure
Security”:
I’m currently involved in creating an up to date approach to handling external
connections (read: temporary/permanent connections with external parties like
business partners) of a very large enterprise. Currently they have sth along the
lines of: “there’s two types of external connections, trusted and untrusted. the
untrusted ones have to be connected by means of a double staged firewall”.
Which – of course – doesn’t work at all in a
VUCA
world, for a number of reasons (the demarcation between trusted and untrusted is
quite unclear – just think of mergers & acquisitions –; “business doesn’t like
implementing 2-staged firewalls in some part of the world where they just signed
the memorandum for a joint venture to build windmills in the desert”; firewalls
might not be the appropriate control for quite some threats anyway – see for
example slide 46 of
this presentation– and
so on). Not to mention that I personally think that the “double staged firewall”
thing is based on an outdated threat model, in particular when implemented with
two different vendors (for the simple reason that the added operational effort
usually is not worth the added security benefit. see
this post for
some discussion of the concept of “operational feasibility”…).
“This document was produced jointly with the OWASP mobile security project. It
is also published as an ENISA deliverable in accordance with our work
program 2011. It is written for developers of smartphone apps as a guide to
developing secure apps. It may however also be of interest to project managers
of smartphone development projects.
Currently there’s
quite some discussion
ongoing why it took Apple so long to fix a
severe vulnerability in the update process
of iTunes. A severe vulnerability which could easily be exploited by means of an
automated tool called
evilgrade which can
be downloaded here (Hi
Francisco!). Just one small note here: did you know that evilgrade was first
shown and released at the 2008 edition of
Troopers? We had a number of initial releases of tools
in the last years (like
wafw00f at the
2009 edition and
VASTO at the
2010 edition) and we will
continue this fine tradition in 2012. I can already promise that some nice code
is going to be released for the first time at Troopers12…
The above is the exact title of a
Gartner research note
published some days ago. Its main thesis is that an increased convergence of
carriers’ MPLS and Internet infrastructures onto shared IP infrastructures
requires that enterprises re-evaluate their security and performance risks.
While I do not agree with the overall line of reasoning in the paper, it still
highlights a number of interesting points when it comes to MPLS security. Which
in turn reminds me of quite some stuff we’ve done in the past, mainly our Black
Hat Europe 2009
talk “All your packets are belong to us – Attacking backbone technologies”.
Today we’ll release an updated version of the accompanying whitepaper as a
kind-of technical report. Its title is “Practical Attacks against MPLS or
Carrier Ethernet Networks” and it can be found
here.