<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Events on Insinuator.net - Bold Statements</title>
    <link>https://insinuator.net/categories/events/</link>
    <description>Recent content in Events on Insinuator.net - Bold Statements</description>
    <generator>Hugo</generator>
    <language>en-us</language>
    <lastBuildDate>Tue, 11 Aug 2026 00:00:00 +0000</lastBuildDate>
    <atom:link href="https://insinuator.net/categories/events/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>#TROOPERS26 AD &amp; Entra ID Security Track</title>
      <link>https://insinuator.net/2026/08/troopers26-ad-entra-id-security-track/</link>
      <pubDate>Tue, 11 Aug 2026 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2026/08/troopers26-ad-entra-id-security-track/</guid>
      <description>&lt;p&gt;The #TROOPERS26 ‘AD &amp;amp; Entra ID Security’ track delivered an incredible experience – much like the entire conference! We were thrilled to host some of the brightest minds in identity research alongside a highly engaged audience who brought valuable insights to the roundtable discussions. While the presentation slides have already been published on the TROOPERS website, several speakers have shared complementary tools, in-depth blog posts, and active social media threads. To make things easy, we’ve compiled a comprehensive list of all these fantastic resources from the track below.&lt;/p&gt;</description>
    </item>
    <item>
      <title>TROOPERS26: Integrating Incident Analysis and Digital Forensics Tooling for Automated Compromise Detection</title>
      <link>https://insinuator.net/2026/06/troopers26-integrating-incident-analysis-and-digital-forensics-tooling-for-automated-compromise-detection/</link>
      <pubDate>Mon, 29 Jun 2026 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2026/06/troopers26-integrating-incident-analysis-and-digital-forensics-tooling-for-automated-compromise-detection/</guid>
      <description>&lt;p&gt;Last week I gave a talk at #TROOPERS26: &lt;a href=&#34;https://troopers.de/troopers26/talks/m7qtn7/&#34;&gt;Integrating Incident Analysis and Digital Forensics Tooling for Automated Compromise Detection&lt;/a&gt;. I discussed the challenges of incident analysis, such as increasing storage capacities and the lack of integration between tools. I presented a modular framework that integrates established forensic and analysis tools using a decision-tree-based control mechanism. A workflow was designed to control the execution of 14 integrated analysis tools in order to reproduce the manual analysis process usually performed by analysts. Moreover, the framework is capable of identifying whether a system has been compromised and compiles a analyst-oriented report. Together with the audience we took a look at the report in a live demonstration. The evaluation results of the framework were promising as it was able to identify all compromised systems. However, a significant number of false positive classifications were also observed. To improve the framework possible future extensions include functionality such as recovering already deleted files to detect missed Indicators of Compromise. Additionally, our team want to integrate artificial intelligence in the workflow to help in data processing and make more decisions automatically. The slides will be published next week on the conference website. I will add the link in this blog post when they become available. A more detailed description of the content of the talk can be found in the following sections. Looking forward to #TROOPERS27!&lt;/p&gt;</description>
    </item>
    <item>
      <title>Heads-up: TROOPERS Roundtable – Supply Chain Security</title>
      <link>https://insinuator.net/2026/06/heads-up-troopers-roundtable-supply-chain-security/</link>
      <pubDate>Mon, 22 Jun 2026 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2026/06/heads-up-troopers-roundtable-supply-chain-security/</guid>
      <description>&lt;h2 id=&#34;how-to-strengthen-supply-chain-security-practical-exchange-and-roadmap&#34;&gt;How to strengthen Supply Chain Security: Practical Exchange and Roadmap&lt;/h2&gt;&#xA;&lt;p&gt;Join an open, practitioner-focused roundtable for direct exchange on supply chain security. This session offers a concise overview of core concepts, e.g. SBOM, CSAF, and VEX and digs into the processes behind them: how to obtain, process and apply information to improve security across the supply chain.&lt;/p&gt;&#xA;&lt;p&gt;We will examine:&lt;/p&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;How SBOM, CSAF and VEX relate and why version-level detail matters.&lt;/li&gt;&#xA;&lt;li&gt;The practical value of an SBOM and why it’s increasingly required by law and IT procurement.&lt;/li&gt;&#xA;&lt;li&gt;How to create and consume SBOMs?&lt;/li&gt;&#xA;&lt;li&gt;Methods to identify dependencies in the context of vulnerabilities.&lt;/li&gt;&#xA;&lt;li&gt;Approaches to triage: not all vulnerabilities affect every stakeholder equally.&lt;/li&gt;&#xA;&lt;li&gt;Techniques to analyze vulnerabilities and identify affected products and product families.&lt;/li&gt;&#xA;&lt;li&gt;Sources of vulnerability information and how to map data unambiguously to products and specific software versions.&lt;/li&gt;&#xA;&lt;li&gt;Reporting obligations: where and how to disclose vulnerabilities.&lt;/li&gt;&#xA;&lt;li&gt;Tools and automation that help manage information volume and complexity.&lt;/li&gt;&#xA;&lt;li&gt;Technical, organizational and personnel challenges to achieving end-to-end supply chain security.&lt;/li&gt;&#xA;&lt;li&gt;The role of AI in supply chain security.&lt;/li&gt;&#xA;&lt;li&gt;How do we protect ourselves from malicious actors / infected dependencies?&lt;/li&gt;&#xA;&lt;li&gt;The Cyber Resilience Act (CRA): implications for companies, products and consumers, the CRA roadmap, and concrete deadlines and actions.&lt;/li&gt;&#xA;&lt;li&gt;We will show a live demonstration of the whole process, e.g. covering the consumption of SBOMs, vulnerability identification and assessment, creation of VEX documents.&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;p&gt;This roundtable is designed for security practitioners, product owners, compliance officers and decision-makers who want actionable guidance and peer discussion. Expect candid conversation, real-world examples and next steps you can take to strengthen resilience across your supply chains.&lt;/p&gt;</description>
    </item>
    <item>
      <title>MCTTP 2025 / Keynote</title>
      <link>https://insinuator.net/2025/10/mcttp-2025-/-keynote/</link>
      <pubDate>Mon, 20 Oct 2025 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2025/10/mcttp-2025-/-keynote/</guid>
      <description>&lt;p&gt;Three weeks ago, I attended &lt;a href=&#34;https://www.mcttp.de&#34;&gt;MCTTP 2025&lt;/a&gt; in Munich,&#xA;organized by Vogel IT and curated by the fine folks Florian Hansemann, Dr. Marc&#xA;Maisch, and Florian Oelmaier. Awesome event with some very cool talks, and great&#xA;conversations over dinner and most notably at the Oktoberfest on Saturday&#xA;(thanks again for that special trip, Flo!). I had the pleasure and honor to give&#xA;the keynote on the 2nd day. The goal was to make it a bit entertaining and&#xA;enlightening for the international audience, so I covered some German&#xA;literature, too ;-). The slides can be found&#xA;&lt;a href=&#34;https://ernw.de/download/Enno_ERNW_MCTTP_keynote.pdf&#34;&gt;here&lt;/a&gt;, and the transcript&#xA;&lt;a href=&#34;https://ernw.de/download/ERNW_Enno_MCTTP_2025_Faust.pdf&#34;&gt;here&lt;/a&gt;. Looking forward&#xA;to meeting some folks again next year, maybe even at&#xA;&lt;a href=&#34;https://troopers.de&#34;&gt;TROOPERS26&lt;/a&gt; 😉&lt;/p&gt;</description>
    </item>
    <item>
      <title>#TROOPERS25 AD &amp; Entra ID Security Track</title>
      <link>https://insinuator.net/2025/08/troopers25-ad-entra-id-security-track/</link>
      <pubDate>Thu, 14 Aug 2025 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2025/08/troopers25-ad-entra-id-security-track/</guid>
      <description>&lt;p&gt;The #TROOPERS25 ‘AD &amp;amp; Entra ID Security’ track was a blast – as was the whole&#xA;conference 😉 –  bringing together some of the smartest researchers in the field&#xA;and a great audience of practitioners willing to share their experiences during&#xA;the &lt;a href=&#34;https://troopers.de/roundtables/&#34;&gt;roundtable&lt;/a&gt;. The slides of the talks have&#xA;been released in the interim on the &lt;a href=&#34;https://troopers.de&#34;&gt;TROOPERS website&lt;/a&gt;, but&#xA;since many speakers published additional blogposts or released tools, we provide&#xA;a compilation of resources from the track in the following.&lt;/p&gt;</description>
    </item>
    <item>
      <title>TROOPERS24 Agenda Preview: Active Directory &amp; Entra ID Security Track</title>
      <link>https://insinuator.net/2024/06/troopers24-agenda-preview-active-directory-entra-id-security-track/</link>
      <pubDate>Fri, 14 Jun 2024 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2024/06/troopers24-agenda-preview-active-directory-entra-id-security-track/</guid>
      <description>&lt;p&gt;Hi,&lt;/p&gt;&#xA;&lt;p&gt;are you curious about the agenda of the Active Directory- &amp;amp; Entra ID security track at TROOPERS24? Here’s a sneak peak of the already published tracks:&lt;/p&gt;&#xA;&lt;h3 id=&#34;wednesday-2024-06-26&#34;&gt;Wednesday, 2024-06-26:&lt;/h3&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://troopers.de/troopers24/talks/vxs8wy&#34;&gt;A Decade of Active Directory Attacks: What We’ve Learned &amp;amp; What’s Next&lt;/a&gt; – Sean Metcalf&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://troopers.de/troopers24/talks/uepkle&#34;&gt;ADillesHeel: Making the Impossible Possible in AD Attack Path Analysis&lt;/a&gt; – SHANG-DE JIANG&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://troopers.de/troopers24/talks/jt97ha&#34;&gt;So You Performed A Forest Recovery. How Do You Reconnect Your AD Again With Azure AD?&lt;/a&gt; – Jorge de Almeida Pinto&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://troopers.de/troopers24/talks/8ekvxr&#34;&gt;Decrypting the Directory: A Journey into a static analysis of the Active Directory NTDS to identify misconfigurations and vulnerabilities&lt;/a&gt; – Bastien Cacace (XMCO company)&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://troopers.de/troopers24/talks/a8zf7h&#34;&gt;Say Hello to your new cache flow!&lt;/a&gt; – Geoffrey Bertoli, Rémi Jullian&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://troopers.de/troopers24/talks/kzymd8&#34;&gt;Analyzing and Executing ADCS Attack Paths with BloodHound&lt;/a&gt; – by Andy Robbins, Jonas Bülow Knudsen&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;h3 id=&#34;thursday-2024-06-27&#34;&gt;Thursday, 2024-06-27:&lt;/h3&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://troopers.de/troopers24/talks/kynuwx&#34;&gt;The (almost) complete LDAP guide&lt;/a&gt; – Sapir Federovsky&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://troopers.de/troopers24/talks/z3dexp&#34;&gt;Exploiting Token-Based Authentication: Attacking and Defending Identities in the 2020s&lt;/a&gt; – Dr Nestori Syynimaa&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://troopers.de/troopers24/talks/3vlccy&#34;&gt;Attacking Primary Refresh Tokens using their MacOS implementation&lt;/a&gt; – Olaf Hartong, Dirk-jan Mollema&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://troopers.de/troopers24/talks/nvp3zs&#34;&gt;Misconfiguration Manager: Overlooked and Overprivileged&lt;/a&gt; – Duane Michael, Chris Thompson&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://troopers.de/troopers24/talks/jlaupj&#34;&gt;The Registry Rundown&lt;/a&gt; – Cedric Van Bockhaven, Max Grim&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;p&gt;The full conference agenda including timeslots will be published soon at &lt;a href=&#34;https://troopers.de/troopers24/conference/&#34;&gt;TROOPERS24&lt;/a&gt;. The trainings are already sold out, but &lt;a href=&#34;https://troopers.de/tickets/&#34;&gt;a handful of tickets is currently left&lt;/a&gt;.  Stay tuned &amp;amp; make the world a safer place!&lt;/p&gt;</description>
    </item>
    <item>
      <title>Summary of &#39;Software-Defined Radio applied to security assessments&#39; at Troopers21</title>
      <link>https://insinuator.net/2021/04/summary-of-software-defined-radio-applied-to-security-assessments-at-troopers21/</link>
      <pubDate>Tue, 20 Apr 2021 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2021/04/summary-of-software-defined-radio-applied-to-security-assessments-at-troopers21/</guid>
      <description>&lt;p&gt;The training&#xA;&lt;a href=&#34;https://troopers.de/troopers21/trainings/cmxfqk/&#34;&gt;Software-Defined Radio applied to security assessments&lt;/a&gt;&#xA;was held by Sébastien Dudek at Troopers21 and was remotely organized – like most&#xA;other events – due to Covid-19. Once we were all caffeinated, we had an exciting&#xA;journey through basically all things radio.&lt;/p&gt;&#xA;&lt;p&gt;We started with the technical and physical basics in radio technology, such as&#xA;various sorts of antennas, analog to digital coding (and backward), encoding&#xA;schemes, and general risks and possible vulnerabilities of using radio devices.&#xA;Commonly found vulnerabilities include the following:&lt;/p&gt;</description>
    </item>
    <item>
      <title>ACM WiSec 2020</title>
      <link>https://insinuator.net/2020/07/acm-wisec-2020/</link>
      <pubDate>Sun, 26 Jul 2020 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2020/07/acm-wisec-2020/</guid>
      <description>&lt;p&gt;Last week I attended &lt;a href=&#34;https://wisec2020.ins.jku.at/&#34;&gt;ACM WiSec&lt;/a&gt;. Of course, only virtually. The first virtual conference I attended. Coincidentally, it was also the first conference I presented at. While the experience was quite different from a “real” conference, the organizers did a great job to make the experience as good as possible with, for example, a mattermost instance to interact with other conference participants.&lt;/p&gt;&#xA;&lt;p&gt;In the following, I will list a few talks and papers that I either found very interesting or that generally stood out to me:&lt;/p&gt;</description>
    </item>
    <item>
      <title>TROOPERS20 Training Teaser: Attack And Defence In AWS: Chaining Vulnerabilities To Go Beyond The OWASP Top 10</title>
      <link>https://insinuator.net/2020/02/troopers20-training-teaser-attack-and-defence-in-aws-chaining-vulnerabilities-to-go-beyond-the-owasp-top-10/</link>
      <pubDate>Thu, 27 Feb 2020 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2020/02/troopers20-training-teaser-attack-and-defence-in-aws-chaining-vulnerabilities-to-go-beyond-the-owasp-top-10/</guid>
      <description>&lt;p&gt;Attackers are everywhere. They are now on the cloud too! Attacking the most popular cloud provider – AWS, requires the knowledge of how different services are setup, what defences do we need to bypass, what service attributes can be abused, where can information be leaked, how do I escalate privileges, what about monitoring solutions that may be present in the environment and so on! We try to answer these questions in our intense, hands-on scenario driven training on attacking and subsequently defending against the attacks on AWS.&lt;/p&gt;</description>
    </item>
    <item>
      <title>TROOPERS20 Training Teaser: Hacking Node.js &amp; Electron apps, shells, injections and fun!</title>
      <link>https://insinuator.net/2020/02/troopers20-training-teaser-hacking-node.js-electron-apps-shells-injections-and-fun/</link>
      <pubDate>Thu, 06 Feb 2020 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2020/02/troopers20-training-teaser-hacking-node.js-electron-apps-shells-injections-and-fun/</guid>
      <description>&lt;p&gt;Did you know that in the ever evolving field of Web and Desktop apps, it turns out these can all now be powered with JavaScript? You read that right: JavaScript is now used to power both web apps (Node.js) as well as Desktop apps (Electron). What could possibly go wrong?&lt;/p&gt;&#xA;&lt;p&gt;So, the burning question is: how does this affect Web and Desktop app security? If you want to find out, come to our training and you will experience this in a 100% hands-on fashion! 🙂&lt;/p&gt;</description>
    </item>
    <item>
      <title>Blackhoodie@Troopers 2020</title>
      <link>https://insinuator.net/2020/01/blackhoodie@troopers-2020/</link>
      <pubDate>Mon, 27 Jan 2020 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2020/01/blackhoodie@troopers-2020/</guid>
      <description>&lt;p&gt;Once again, we are super excited to announce that Blackhoodie is happening at Troopers 2020. This is the 3rd time that Blackhoodie is joining with Troopers. As always, one of the main motivation for Blackhoodie is bringing more women into reversing and other core security topics. So we would like to see more women apply to the training slots. However, if you are not a woman and still feel really excited about Blackhoodie, you are welcome to apply. The registration is open now.  Please hurry up and make your registration now. We will close the registration once the seats are filled up with enough quality submissions. We do have a very limited number of seats at this training site. So we apologize in advance if we can’t accommodate everyone, even though we wish we could!&lt;/p&gt;</description>
    </item>
    <item>
      <title>TROOPERS20 Training Teaser: TLS in the Enterprise – Post Quantum Security</title>
      <link>https://insinuator.net/2019/12/troopers20-training-teaser-tls-in-the-enterprise-post-quantum-security/</link>
      <pubDate>Mon, 09 Dec 2019 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2019/12/troopers20-training-teaser-tls-in-the-enterprise-post-quantum-security/</guid>
      <description>&lt;p&gt;Our workshop “TLS in the enterprise” was held for the first time at Troopers 2018 and was our special contribution to the IT Security world to increase the usage of TLS and point out the pitfalls, when switching to TLS.&lt;/p&gt;&#xA;&lt;p&gt;But time is changing and TLS is a kind of standard nowadays, at least when looking at HTTPS, but there are still a lot of things to do regarding other protocols like&lt;/p&gt;</description>
    </item>
    <item>
      <title>TROOPERS20 Training Teaser: Swim with the whales – Docker, DevOps &amp;amp; Security in Enterprise Environments</title>
      <link>https://insinuator.net/2019/12/troopers20-training-teaser-swim-with-the-whales-docker-devops-amp-security-in-enterprise-environments/</link>
      <pubDate>Mon, 02 Dec 2019 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2019/12/troopers20-training-teaser-swim-with-the-whales-docker-devops-amp-security-in-enterprise-environments/</guid>
      <description>&lt;p&gt;Containerization dominates the market nowadays. Fancy buzzwords like continuous integration/deployment/delivery, microservices, containers, DevOps are floating around, but what do they mean? What benefits do they offer compared to the old dogmas? You’re gonna find out in our training!&lt;/p&gt;&#xA;&lt;p&gt;We are going to start with the basics of Docker, Containers and DevOps, but soon you’ll end up with your own applications running inside containers with the images residing in your own registry. Of course, following the microservices approach, and the second day hasn’t even started.After the fundamental topics of containerization are understood, you’re going to create and operate your own Kubernetes cluster. A lot of fun and challenging exercises lie ahead, to give you hands-on experience with all the technologies.&lt;/p&gt;</description>
    </item>
    <item>
      <title>BASTA! Autumn 2019 – Security in DevOps</title>
      <link>https://insinuator.net/2019/11/basta-autumn-2019-security-in-devops/</link>
      <pubDate>Thu, 28 Nov 2019 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2019/11/basta-autumn-2019-security-in-devops/</guid>
      <description>&lt;p&gt;Some time ago I had the pleasure to speak at the &lt;a href=&#34;https://basta.net/&#34;&gt;BASTA!&lt;/a&gt; Autumn 2019 conference. There, I promised to publish my &lt;a href=&#34;https://insinuator.net/wp-content/uploads/2019/11/201909_BASTA_DevOps-Sc_v1.0.pdf&#34;&gt;slides&lt;/a&gt; such that they can be used as a reference for developers and security guys like me. And with this blog post I would like to hold up to my promise.&lt;/p&gt;&#xA;&lt;p&gt;Overall, the talk was about the challenges of “How to bring security into modern DevOps processes”. Hence, I demonstrated how security can be integrated more or less seamlessly into the modern agile software development workflow. I proposed some risk-depended recommendations about which measurements should be established, for example, within the CI pipeline.&lt;/p&gt;</description>
    </item>
    <item>
      <title>TROOPERS20 teaser: Hacking mobile apps</title>
      <link>https://insinuator.net/2019/11/troopers20-teaser-hacking-mobile-apps/</link>
      <pubDate>Thu, 28 Nov 2019 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2019/11/troopers20-teaser-hacking-mobile-apps/</guid>
      <description>&lt;p&gt;“If it’s a thing, then there’s an app for it!”…We trust mobile apps to process our bank transactions, handle our private data and set us up on romantic dates. However, few of us care to wonder,”How (in)secure can these apps be?” Well… at Troopers 20, you can learn how to answer this question yourself!&lt;/p&gt;&#xA;&lt;p&gt;In our 2 day long “Hacking mobile apps” workshop, we teach how to find security vulnerabilities in mobile apps, exploit them and defend against them. We start from scratch, therefore no prior experience in hacking or developing mobile apps is required. Whether you want to learn how to pentest mobile apps, you are an app developer that fancies to secure his/her apps, or just curios, our workshop is a jumpstart to your goal.&lt;/p&gt;</description>
    </item>
    <item>
      <title>TROOPERS20 Training Teaser: Insight Into Windows Internals</title>
      <link>https://insinuator.net/2019/11/troopers20-training-teaser-insight-into-windows-internals/</link>
      <pubDate>Mon, 25 Nov 2019 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2019/11/troopers20-training-teaser-insight-into-windows-internals/</guid>
      <description>&lt;p&gt;Windows 10 is one of the most commonly deployed operating systems at this time. Knowledge about its components and internal working principles is highly beneficial. Among other things, such a knowledge enables:&lt;/p&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;in-depth studies of undocumented, or poorly documented, system functionalities;&lt;/li&gt;&#xA;&lt;li&gt;development of performant and compatible software to monitor or extend the activities of the operating system itself; and&lt;/li&gt;&#xA;&lt;li&gt;analysis of security-related issues, such as persistent malware.&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;p&gt;The “Insight into Windows Internals” training offered at TROOPERS20 delivers knowledge on the core components and inner working principles of Windows 10. For example, the training provides knowledge on how Windows 10 uses virtualization to isolate security-critical functionalities from attackers that have managed to compromise the system. The training includes a variety of practical exercises allowing attendees to observe first-hand the operation of Windows 10.&lt;/p&gt;</description>
    </item>
    <item>
      <title>DevSecCon19 London – How to Secure OpenShift Environments and What Happens If You Don´t</title>
      <link>https://insinuator.net/2019/11/devseccon19-london-how-to-secure-openshift-environments-and-what-happens-if-you-dont/</link>
      <pubDate>Tue, 19 Nov 2019 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2019/11/devseccon19-london-how-to-secure-openshift-environments-and-what-happens-if-you-dont/</guid>
      <description>&lt;p&gt;This week I was at &lt;a href=&#34;https://www.devseccon.com/london-2019/&#34;&gt;DevSecCon in London&lt;/a&gt; to present my current research on Red Hat OpenShift. In this talk, I gave a brief introduction to OpenShift, demonstrated some threats that exist for such environments, and dived into different configuration issues that may affect the security of OpenShift environments. The implications of misconfigurations of such an environment have been shown in live demos.&lt;/p&gt;&#xA;&lt;p&gt;You can find the slides for my talk here.&lt;/p&gt;</description>
    </item>
    <item>
      <title>TROOPERS20 Training Teaser: Hacking 101</title>
      <link>https://insinuator.net/2019/11/troopers20-training-teaser-hacking-101/</link>
      <pubDate>Thu, 07 Nov 2019 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2019/11/troopers20-training-teaser-hacking-101/</guid>
      <description>&lt;p&gt;Hi there,&lt;br&gt;&#xA;like in recent years the popular &lt;a href=&#34;https://www.troopers.de/troopers20/trainings/3crqx8/&#34;&gt;Hacking 101 workshop&lt;/a&gt; will take place on TROOPERS20, too! The workshop will give you an insight into the &lt;strong&gt;hacking techniques&lt;/strong&gt; required for &lt;strong&gt;penetration testing&lt;/strong&gt;. These techniques will cover various topics:&lt;/p&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;Information gathering&lt;/li&gt;&#xA;&lt;li&gt;Network scanning&lt;/li&gt;&#xA;&lt;li&gt;Web application hacking&lt;/li&gt;&#xA;&lt;li&gt;Low-level exploitation&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;p&gt;…and more!&lt;/p&gt;&#xA;&lt;p&gt;During this workshop &lt;strong&gt;you will learn&lt;/strong&gt;, step by step, a &lt;strong&gt;testing methodology&lt;/strong&gt; that applies to the majority of scenarios. So imagine you have to &lt;strong&gt;assess&lt;/strong&gt; the &lt;strong&gt;security of a system&lt;/strong&gt; running on the Internet. How would you start? First, you need a good understanding of the target, including running services or related systems. Just &lt;strong&gt;scanning&lt;/strong&gt; the target’s IP address will most likely not reveal all relevant information you can get. In the information gathering step, you will learn where you could find more relevant information than just a list of open ports. A brief understanding of the target and it’s related systems/services/applications will make scanning and &lt;strong&gt;identifying vulnerabilities&lt;/strong&gt; a lot easier and more effective. Then, the last step will be the &lt;strong&gt;exploitation&lt;/strong&gt; of the identified vulnerabilities, with the ultimate aim to &lt;strong&gt;get access to the target system&lt;/strong&gt; and pivot to other, probably internal, systems and resources.&lt;/p&gt;</description>
    </item>
    <item>
      <title>TROOPERS20 Training Teaser: Windows &amp; Linux Binary Exploitation</title>
      <link>https://insinuator.net/2019/11/troopers20-training-teaser-windows-linux-binary-exploitation/</link>
      <pubDate>Mon, 04 Nov 2019 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2019/11/troopers20-training-teaser-windows-linux-binary-exploitation/</guid>
      <description>&lt;p&gt;We are happy to announce that TROOPERS20 will feature the 5th anniversary of the popular Windows &amp;amp; Linux Binary Exploitation workshop!&lt;/p&gt;&#xA;&lt;p&gt;In this workshop, attendees will learn how to exploit those nasty stack-based buffer overflow vulnerabilities by applying the theoretical methods taught in this course to hands-on exercises. Exercises will be performed for real world (32-bit) software such as the Foxit Reader Plugin for Firefox, Wireshark, and nginx.&lt;/p&gt;&#xA;&lt;p&gt;Each exercise will start with an initially uncontrolled overwrite of the instruction pointer register by a stack-based buffer overflow vulnerability. From there on, we will work our way through many obstacles to finally gain remote code execution. Obstacles that will be encountered during the exercises include modern stack-based buffer overflow defense mechanisms such as stack cookies, data execution prevention (DEP), and address space layout randomization (ASLR). For all of these defense mechanisms, attendees will learn and apply certain methods to bypass the protection.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Medical Device Security Summit 2019, 19th of November of 2019</title>
      <link>https://insinuator.net/2019/10/medical-device-security-summit-2019-19th-of-november-of-2019/</link>
      <pubDate>Wed, 09 Oct 2019 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2019/10/medical-device-security-summit-2019-19th-of-november-of-2019/</guid>
      <description>&lt;p&gt;*This event will be held in German*&lt;/p&gt;&#xA;&lt;p&gt;Inspiriert durch die erfolgreichen Round-Table-Diskussionen der TROOPERS-Konferenz freuen wir uns, Ihnen heute mit dem Medical Device Security Summit 2019, eine weitere Veranstaltung in einer Reihe zu Trend-Themen im Bereich der IT-Sicherheit vorzustellen.&lt;/p&gt;&#xA;&lt;p&gt;Die Veranstaltung beginnt am Morgen mit einem Eröffnungsvortrag von Peter Hecko (Leiter der IT-Sicherheit bei HELIOS IT Service GmbH, Podcaster und jahrelanges Mitglied im CCC), gefolgt von Fallstudien und Vorträgen von ERNW Experten und weiteren Referenten aus der Lehre, Industrie und klinischer Praxis.&lt;/p&gt;</description>
    </item>
    <item>
      <title>TelcoSecDay 2020 CFP is open</title>
      <link>https://insinuator.net/2019/09/telcosecday-2020-cfp-is-open/</link>
      <pubDate>Mon, 23 Sep 2019 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2019/09/telcosecday-2020-cfp-is-open/</guid>
      <description>&lt;p&gt;We are back again with another &lt;a href=&#34;https://troopers.de/troopers20/telco-sec-day/&#34;&gt;TelcoSecDay 2020&lt;/a&gt; (TSD20) which is going to happen on March 16th, 2020 as an additional event to &lt;a href=&#34;https://troopers.de/&#34;&gt;TROOPERS&lt;/a&gt;. This year, it is going to be on &lt;strong&gt;Monday&lt;/strong&gt; of the TROOPERS week. We are delighted to inform that the event is happening for the 9th year in a row. The &lt;a href=&#34;https://cfp.ernw-insight.de/tsd20/cfp&#34;&gt;CFP&lt;/a&gt; is open now. If you have an interesting topic related to the field of Telco Security, please make a submission. The deadline is &lt;strong&gt;November 17, 2019.&lt;/strong&gt; The final notification for TSD submission is December 20, 2019.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Black Hat US 2019 / Some Talks</title>
      <link>https://insinuator.net/2019/08/black-hat-us-2019-/-some-talks/</link>
      <pubDate>Tue, 13 Aug 2019 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2019/08/black-hat-us-2019-/-some-talks/</guid>
      <description>&lt;p&gt;I’ve been at Black Hat Vegas last week and in the following I’ll shortly discuss some talks I’ve attended and which I found interesting.&lt;/p&gt;&#xA;&lt;p&gt;&lt;strong&gt;&lt;a href=&#34;https://twitter.com/gabbifish&#34;&gt;Gabriele Fisher&lt;/a&gt; &amp;amp; &lt;a href=&#34;https://twitter.com/lukevalenta&#34;&gt;Luke Valenta&lt;/a&gt;: Monsters in the Middleboxes. Building Tools for Detecting HTTPS Interception&lt;/strong&gt;&lt;/p&gt;&#xA;&lt;p&gt;This talk was about identifying if inbound HTTPS traffic reaching a server had been intercepted by a &lt;a href=&#34;https://tools.ietf.org/rfc/rfc3234.txt&#34;&gt;middlebox&lt;/a&gt; (or its software equivalent which is usually called “middleware”, a prominent example being the Lenovo Superfish piece a few years ago) on its path.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Back from PowerShell Conference Europe…</title>
      <link>https://insinuator.net/2019/06/back-from-powershell-conference-europe/</link>
      <pubDate>Wed, 12 Jun 2019 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2019/06/back-from-powershell-conference-europe/</guid>
      <description>&lt;p&gt;The &lt;a href=&#34;http://www.psconf.eu/&#34;&gt;PowerShell Conference Europe 2019&lt;/a&gt; took place last week in Hannover, and I had the pleasure to attend and speak for the second year in a row. I want to thank &lt;a href=&#34;https://twitter.com/TobiasPSP&#34;&gt;@TobiasPSP&lt;/a&gt; &lt;a href=&#34;https://twitter.com/alexandair&#34;&gt;@Alexandair&lt;/a&gt; &lt;a href=&#34;https://twitter.com/sqldbawithbeard&#34;&gt;@sqldbawithbeard&lt;/a&gt; and the &lt;a href=&#34;https://twitter.com/psconfeu&#34;&gt;@PSConfEU&lt;/a&gt; crew for putting up this &lt;a href=&#34;https://twitter.com/hashtag/PowerShell&#34;&gt;#PowerShell&lt;/a&gt; feast. From a RaspberryPi to the Clouds, from PowerShell internals to a dancing Lego robot, if you have anything to do with windows, PowerShell, or a computer, there was some content made for you…[I will update this post with links as soon as the videos are published. Make sure to check it out.]&lt;/p&gt;</description>
    </item>
    <item>
      <title>#TR19 Next Generation Internet (NGI) Summaries</title>
      <link>https://insinuator.net/2019/05/%23tr19-next-generation-internet-ngi-summaries/</link>
      <pubDate>Thu, 02 May 2019 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2019/05/%23tr19-next-generation-internet-ngi-summaries/</guid>
      <description>&lt;p&gt;This blogpost contains summaries of talks from this year’s &lt;a href=&#34;https://troopers.de/troopers19/&#34;&gt;TROOPERS19&lt;/a&gt; Active Directory Security Track.&lt;/p&gt;&#xA;&lt;h1 id=&#34;microsoft-it-secure-journey-to-ipv6-only&#34;&gt;Microsoft IT (Secure) Journey to IPv6-Only&lt;/h1&gt;&#xA;&lt;p&gt;Veronika McKillop, Network Architect, Cloud and Connectivity Engineering (CCE)&lt;/p&gt;&#xA;&lt;p&gt;The speaker, Veronika McKillop, working at Microsofts network infrastructure services, has given a talk about the process of switching a company network from IPv4 to IPv6-only.&lt;/p&gt;&#xA;&lt;p&gt;Within the talk the following topics were introduced: Dual Stack, Drivers for IPv6, Status of IPv6 in Networks and Security in IPv6 Networks. The talk covers the reasons why a company would like to switch from IPv4 to IPv6. Technics like NAT64 and DNS64 are introduced. The requirements to software and especially drivers to work in IPv6 environments are described. Also the problems to switch from IPv4 to IPv6-only in heterogeneous networks are addressed.&lt;/p&gt;</description>
    </item>
    <item>
      <title>#TR19 Active Directory Security Summaries</title>
      <link>https://insinuator.net/2019/04/%23tr19-active-directory-security-summaries/</link>
      <pubDate>Tue, 30 Apr 2019 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2019/04/%23tr19-active-directory-security-summaries/</guid>
      <description>&lt;p&gt;This blogpost contains summaries of talks from this year’s &lt;a href=&#34;https://troopers.de/troopers19/&#34;&gt;TROOPERS19&lt;/a&gt; Active Directory Security Track.&lt;/p&gt;&#xA;&lt;h1 id=&#34;from-workstation-to-domain-admin-why-secure-administration-isnt-secure-and-how-to-fix-it-by-sean-metcalf&#34;&gt;From Workstation to Domain Admin: Why Secure Administration Isn’t Secure and How to Fix It by Sean Metcalf&lt;/h1&gt;&#xA;&lt;p&gt;Active Directory is probably used in almost every corporation today to administer all kinds of Authorization, Authentication and Privileges. This means they are valuable targets for attackers, because once compromised they could do whatever they want. This would be the worst case scenario, right? Therefore securing AD is important and this year TROOPERS19 featured a whole track solely for AD Security.&lt;/p&gt;</description>
    </item>
    <item>
      <title>#TR19 Attack &amp; Research Summaries</title>
      <link>https://insinuator.net/2019/04/%23tr19-attack-research-summaries/</link>
      <pubDate>Mon, 29 Apr 2019 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2019/04/%23tr19-attack-research-summaries/</guid>
      <description>&lt;p&gt;This blogpost contains summaries of talks from this year’s &lt;a href=&#34;https://www.troopers.de/troopers19/&#34;&gt;TROOPERS19&lt;/a&gt; Attack &amp;amp; Research Track.&lt;/p&gt;&#xA;&lt;h1 id=&#34;vxlan-security-or-injection-and-protection&#34;&gt;VXLAN Security or Injection, and protection&lt;/h1&gt;&#xA;&lt;p&gt;The talk “VXLAN Security or Injection, and protection” was held by Henrik Lund Kramshøj, who is the owner of Zencurity ApS, a small security company located in Denmark.&lt;/p&gt;&#xA;&lt;p&gt;Henrik gives an overview about lesser known VXLAN insecurities, mostly packet spoofing.&lt;/p&gt;&#xA;&lt;p&gt;In the end he gives advice how to protect against this attacks.&lt;/p&gt;</description>
    </item>
    <item>
      <title>DMEA 2019: A reunion with the Medical Informatics Community</title>
      <link>https://insinuator.net/2019/04/dmea-2019-a-reunion-with-the-medical-informatics-community/</link>
      <pubDate>Mon, 29 Apr 2019 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2019/04/dmea-2019-a-reunion-with-the-medical-informatics-community/</guid>
      <description>&lt;p&gt;Earlier this month I attended the Digital Medical Expertise &amp;amp; Applications (DMEA) 2019. The DMEA fair in Berlin (formerly conhIT) is the central platform for digital health care as it brings together companies of health IT, academic institutions, politics and healthcare delivery organizations in several format such as innovation hubs and talks during congress sessions as a part of the industry fair. I participated in a congress session about IT security in healthcare with a talk about medical device security and common security flaws in medical devices. Some of the aspects have also been covered in my talk at #TR19 [1].&lt;/p&gt;</description>
    </item>
    <item>
      <title>Troopers &amp;amp; Chill…</title>
      <link>https://insinuator.net/2019/04/troopers-amp-chill/</link>
      <pubDate>Fri, 26 Apr 2019 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2019/04/troopers-amp-chill/</guid>
      <description>&lt;p&gt;As promised in my &lt;a href=&#34;https://insinuator.net/2019/03/the-mmm-in-community/&#34;&gt;previous post&lt;/a&gt;, I am back for an overview of the &lt;strong&gt;Troopers19 – Active Directory&lt;/strong&gt; related talks… Videos have been published and it’s popcorn time… So if you are into stories about Kingdoms and Crown Jewels, grab your loved one [or a drink…] and turn the lights down low, ’cause tonight it’s “Troopers &amp;amp; Chill…”&lt;/p&gt;&#xA;&lt;p&gt;Warning: Don’t watch it all in one go… or you will start to feel some anxiety and pain…&lt;br&gt;&#xA;and then the Flying Dutchman will move to the cloud… And at that point we are not insured anymore.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Upcoming ISH Conference</title>
      <link>https://insinuator.net/2019/04/upcoming-ish-conference/</link>
      <pubDate>Wed, 03 Apr 2019 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2019/04/upcoming-ish-conference/</guid>
      <description>&lt;p&gt;We’re happy to announce that some fine folks of ERNW will be present at the upcoming &lt;a href=&#34;https://www.ish-muc.com/conference&#34;&gt;ISH Conference&lt;/a&gt;.&lt;/p&gt;&#xA;&lt;p&gt;The next generation IT security training facility for all industries and any institution that manages complex infrastructure invites you to join the first ISH Conference about threats, prevention and response in Information Security on May 6th– 9th, 2019.&lt;br&gt;&#xA;The event consists of two days of conference and two days of training with insights and shared knowledge by world leading experts at the Information Security Hub (ISH) Munich Airport.&lt;br&gt;&#xA;Learn and discuss the newest threats and solutions with world-renowned experts like Eugene Kaspersky, Adam Meyer, Adrian Nish and others.&lt;/p&gt;</description>
    </item>
    <item>
      <title>The “mmm…” in Community</title>
      <link>https://insinuator.net/2019/03/the-mmm-in-community/</link>
      <pubDate>Thu, 28 Mar 2019 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2019/03/the-mmm-in-community/</guid>
      <description>&lt;p&gt;When I got home last weekend after an awesome week at &lt;a href=&#34;https://twitter.com/WEareTROOPERS&#34;&gt;WEareTROOPERS&lt;/a&gt;, my 5yr old asked me what actually happened in Heidelberg…&lt;br&gt;&#xA;I told him we were meeting with some people from all over the world to talk about computer security, and he asked me if it was “to stop the bad guys, like super-heroes?”. So I told him “yes, kind of…”, and he decided he would take his new Troopers T-Shirt to school on Monday to show his classmates. Kids are truly amazing… [&amp;lt;3 &amp;lt;3 &amp;lt;3]&lt;/p&gt;</description>
    </item>
    <item>
      <title>Binaries, shellcoding, bug hunting, ROP gadgets and more at Blackhoodie@TR19</title>
      <link>https://insinuator.net/2019/03/binaries-shellcoding-bug-hunting-rop-gadgets-and-more-at-blackhoodie@tr19/</link>
      <pubDate>Fri, 01 Mar 2019 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2019/03/binaries-shellcoding-bug-hunting-rop-gadgets-and-more-at-blackhoodie@tr19/</guid>
      <description>&lt;p&gt;We have the most amazing trainers this year lined up for Blackhoodie at Troopers 2019. We have &lt;a href=&#34;https://twitter.com/barbieauglend&#34;&gt;Thais&lt;/a&gt;, &lt;a href=&#34;https://twitter.com/SilviaValiSV&#34;&gt;Silvia&lt;/a&gt;, &lt;a href=&#34;https://twitter.com/chiliz16&#34;&gt;Lisa&lt;/a&gt; and &lt;a href=&#34;https://twitter.com/__noutoff__&#34;&gt;Ninon&lt;/a&gt; going to give workshops on various interesting topics! Below are some of the workshop contents:&lt;/p&gt;&#xA;&lt;h3 id=&#34;64-bit-shellcoding-and-introduction-to-buffer-overflow-exploitation-on-linux-by-silvia-väli&#34;&gt;64-bit shellcoding and introduction to buffer overflow exploitation on Linux by &lt;a href=&#34;https://twitter.com/SilviaValiSV&#34;&gt;Silvia Väli&lt;/a&gt;&lt;/h3&gt;&#xA;&lt;p&gt;64-bit shellcoding and introduction to buffer overflow exploitation on Linux is a 3 hour workshop which is essentially divided into 3 parts:&lt;/p&gt;&#xA;&lt;ol&gt;&#xA;&lt;li&gt;Introduction to 64-bit architecture in order to get familiar with registers, stack, calling conventions described in the Intel 64 (x86-64) architecture manual and the most common assembly instructions and syscalls which we will later use to write our shellcodes.&lt;/li&gt;&#xA;&lt;li&gt;Shellcoding where we try different techniques to write the shellcode and of course you gonna get to greet the shellcoding world with your own Hello World shellcode in addition to reverse shell which we will use later on in part 3&lt;/li&gt;&#xA;&lt;li&gt;Introduction to buffer overflows, so you can put your newly received know-how about stack into practise right away. Shellcode without being used is a wasted shellcode! Part 3 ends with a buffer overflow challenge where your goal is to use your reverse shellcode to get a connection back to your machine.&lt;/li&gt;&#xA;&lt;/ol&gt;&#xA;&lt;p&gt;&lt;strong&gt;Objectives:&lt;/strong&gt;&lt;/p&gt;</description>
    </item>
    <item>
      <title>Offensivecon 2019</title>
      <link>https://insinuator.net/2019/02/offensivecon-2019/</link>
      <pubDate>Wed, 20 Feb 2019 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2019/02/offensivecon-2019/</guid>
      <description>&lt;p&gt;Hi,&lt;/p&gt;&#xA;&lt;p&gt;Last week I had the pleasure to attend &lt;a href=&#34;https://www.offensivecon.org/&#34;&gt;Offensivecon&lt;/a&gt; 2019 in Berlin. The conference was organized very well, and I liked the familial atmosphere which allowed to meet lots of different people. Thanks to the organizers, speakers and everyone else involved for this conference! Andreas posted a &lt;a href=&#34;https://twitter.com/andreasdotorg/status/1096464330915225600&#34;&gt;one tweet tldr&lt;/a&gt; of the first day; fuzzing is still the way to go to find bugs, and mitigations make exploitation harder. Here are some short summaries of the talks I enjoyed.&lt;/p&gt;</description>
    </item>
    <item>
      <title>TelcoSecDay 2019 – First talks preview</title>
      <link>https://insinuator.net/2019/01/telcosecday-2019-first-talks-preview/</link>
      <pubDate>Tue, 29 Jan 2019 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2019/01/telcosecday-2019-first-talks-preview/</guid>
      <description>&lt;p&gt;This year we had some excellent submissions for TelcoSecDay.  Here are the first four confirmed speakers who are going to talk about the below mentioned topics:&lt;/p&gt;&#xA;&lt;h4 id=&#34;1-telecom-protocols-revisited--not-just-a-signalling-problem--by-fredrik-söderlund&#34;&gt;&lt;strong&gt;1. Telecom protocols revisited – Not just a signalling problem – by Fredrik Söderlund&lt;/strong&gt;&lt;/h4&gt;&#xA;&lt;p&gt;A look at the design of the currently deployed signalling protocols for core networks, both SS7 and Diameter (legacy and LTE). Peculiar quirks and how the design has lead to the industry sometimes failing to adhere to its own standards.&lt;/p&gt;</description>
    </item>
    <item>
      <title>#TR19 Active Directory Security Track</title>
      <link>https://insinuator.net/2019/01/%23tr19-active-directory-security-track/</link>
      <pubDate>Wed, 23 Jan 2019 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2019/01/%23tr19-active-directory-security-track/</guid>
      <description>&lt;p&gt;As some of you might recall we’ve introduced a dedicated “Active Directory Security Track” at last year’s &lt;a href=&#34;https://www.troopers.de/&#34;&gt;Troopers&lt;/a&gt;. For Troopers19 we’ve expanded it to two days (as the SAP Security Track was discontinued), and in the following I’ll provide a list of talks in the track.&lt;/p&gt;&#xA;&lt;p&gt;&lt;strong&gt;Vincent Le Toux: You “try” to detect mimikatz&lt;/strong&gt;&lt;/p&gt;&#xA;&lt;p&gt;Abstract: This is 2019 and you still “try” to detect mimikatz. “Try”, because after many years, this post exploitation tool continues to be successful.&lt;br&gt;&#xA;As a contributor to mimikatz and also a blue team guy, I’m asking myself why antivirus vendors are unable to catch it after many years.&lt;br&gt;&#xA;How can a tool be blocked if nobody does not know what this tool is doing? Because surprisingly, it is known only for credential collection but mimikatz is a lot more.&lt;br&gt;&#xA;To mitigate the lack of antivirus vendor, should we buy new fancy EDR tool or try a technical approach? Apply a Framework? Rely on Compliance? Use a SIEM to collect logs and apply correlation? In sumarry, can we detect mimikatz?&lt;br&gt;&#xA;In this presentation we will try to understand why mimikatz has such power and especially some weakness related to credential gathering and active directory will be exposed.&lt;/p&gt;</description>
    </item>
    <item>
      <title>TROOPERS19 Training Teaser: Hacking mobile applications</title>
      <link>https://insinuator.net/2019/01/troopers19-training-teaser-hacking-mobile-applications/</link>
      <pubDate>Wed, 16 Jan 2019 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2019/01/troopers19-training-teaser-hacking-mobile-applications/</guid>
      <description>&lt;p&gt;“If it’s a thing, then there’s an app for it!”…We trust mobile apps to process our bank transactions, handle our private data and set us up on romantic dates. However, few of us care to wonder,”How (in)secure can these apps be?” Well… at Troopers 19, you can learn how to answer this question yourself!&lt;/p&gt;&#xA;&lt;p&gt;In our 2 day long “Hacking mobile applications” workshop, we teach how to find security vulnerabilities in mobile apps, exploit them and defend against them. We start from scratch, therefore no prior experience in hacking or developing mobile apps is required. Whether you want to learn how to pentest mobile apps, you are an app developer that fancies to secure his/her apps, or just curios, our workshop is a jumpstart to your goal.&lt;/p&gt;</description>
    </item>
    <item>
      <title>TROOPERS19 Training Teaser: Insight Into Windows Internals</title>
      <link>https://insinuator.net/2019/01/troopers19-training-teaser-insight-into-windows-internals/</link>
      <pubDate>Tue, 15 Jan 2019 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2019/01/troopers19-training-teaser-insight-into-windows-internals/</guid>
      <description>&lt;p&gt;Windows 10 is one of the most commonly deployed operating systems at this time. Knowledge about its components and internal working principles is highly beneficial. Among other things, such a knowledge enables:&lt;/p&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;in-depth studies of undocumented, or poorly documented, system functionalities;&lt;/li&gt;&#xA;&lt;li&gt;development of performant and compatible software to monitor or extend the activities of the operating system itself; and&lt;/li&gt;&#xA;&lt;li&gt;analysis of security-related issues, such as persistent malware.&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;p&gt;The “Insight into Windows Internals” training offered at TROOPERS’19 delivers knowledge on the core components and inner working principles of Windows 10. For example, the training provides knowledge on how Windows 10 uses virtualization to isolate security-critical functionalities from attackers that have managed to compromise the system. The training includes a variety of practical exercises allowing attendees to observe first-hand the operation of Windows 10.&lt;/p&gt;</description>
    </item>
    <item>
      <title>TROOPERS19 Training Teaser: Hacking 101</title>
      <link>https://insinuator.net/2019/01/troopers19-training-teaser-hacking-101/</link>
      <pubDate>Mon, 14 Jan 2019 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2019/01/troopers19-training-teaser-hacking-101/</guid>
      <description>&lt;p&gt;Hi there,&lt;br&gt;&#xA;like in recent years the popular &lt;a href=&#34;https://www.troopers.de/troopers19/trainings/beheul/&#34;&gt;Hacking 101 workshop&lt;/a&gt; will take place on TROOPERS19, too! The workshop will give you an insight into the &lt;strong&gt;hacking techniques&lt;/strong&gt; required for &lt;strong&gt;penetration testing&lt;/strong&gt;. These techniques will cover various topics:&lt;/p&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;Information gathering&lt;/li&gt;&#xA;&lt;li&gt;Network scanning&lt;/li&gt;&#xA;&lt;li&gt;Web application hacking&lt;/li&gt;&#xA;&lt;li&gt;Low-level exploitation&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;p&gt;…and more!&lt;/p&gt;&#xA;&lt;p&gt;During this workshop &lt;strong&gt;you will learn&lt;/strong&gt;, step by step, a &lt;strong&gt;testing methodology&lt;/strong&gt; that applies to the majority of scenarios. So imagine you have to &lt;strong&gt;assess&lt;/strong&gt; the &lt;strong&gt;security of a system&lt;/strong&gt; running on the Internet. How would you start? First, you need a good understanding of the target, including running services or related systems. Just &lt;strong&gt;scanning&lt;/strong&gt; the target’s IP address will most likely not reveal all relevant information you can get. In the information gathering step, you will learn where you could find more relevant information than just a list of open ports. A brief understanding of the target and it’s related systems/services/applications will make scanning and &lt;strong&gt;identifying vulnerabilities&lt;/strong&gt; a lot easier and more effective. Then, the last step will be the &lt;strong&gt;exploitation&lt;/strong&gt; of the identified vulnerabilities, with the ultimate aim to &lt;strong&gt;get access to the target system&lt;/strong&gt; and pivot to other, probably internal, systems and resources.&lt;/p&gt;</description>
    </item>
    <item>
      <title>TROOPERS19 Training Teaser: Windows &amp;amp; Linux Binary Exploitation</title>
      <link>https://insinuator.net/2019/01/troopers19-training-teaser-windows-amp-linux-binary-exploitation/</link>
      <pubDate>Mon, 14 Jan 2019 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2019/01/troopers19-training-teaser-windows-amp-linux-binary-exploitation/</guid>
      <description>&lt;p&gt;Once again Troopers will have its Windows &amp;amp; Linux Binary Exploitation workshop. Its main focus are the ever-present stack-based buffer overflows still found in software today (e.g. CVE-2018-5002, CVE-2018-1459, and CVE-2018-12897) and their differences with regard to exploitation on Windows and Linux systems. If you ever wanted to know the details of the exploit development process for these systems then this workshop is for you.&lt;/p&gt;&#xA;&lt;p&gt;After initial exercises involving the exploitation of classic stack-based buffer overflows, modern defense mechanism such as Stack Cookies, DEP, and ASLR are presented and analyzed for weaknesses. The participants will learn how these defense mechanisms can be bypassed and will develop exploits targeting real world applications such as the Foxit Reader Plugin for Firefox, Wireshark, and nginx.&lt;/p&gt;</description>
    </item>
    <item>
      <title>TROOPERS19 Training Teaser: Hardening Microsoft Environments</title>
      <link>https://insinuator.net/2019/01/troopers19-training-teaser-hardening-microsoft-environments/</link>
      <pubDate>Fri, 11 Jan 2019 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2019/01/troopers19-training-teaser-hardening-microsoft-environments/</guid>
      <description>&lt;p&gt;“Credential Theft” or “Credential Reuse” attack techniques are the biggest known threats to Active Directory environments. This can be attributed to significant advances in and broad distribution of attack and reconnaissance tools such as mimikatz or Bloodhound. This means that after the first system in an environment is compromised it often takes less than 48 hours for a complete compromise of an Active Directory but unfortunately typically 8 to 9 months until the attack is discovered.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Secure CI/CD Pipelines @Troopers ’19</title>
      <link>https://insinuator.net/2019/01/secure-ci/cd-pipelines-@troopers-19/</link>
      <pubDate>Thu, 10 Jan 2019 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2019/01/secure-ci/cd-pipelines-@troopers-19/</guid>
      <description>&lt;p&gt;In the last couple of months we participated in an increasing count of customer projects following current trends of agile software development approaches and corresponding toolstacks. Especially the terms &lt;em&gt;Continuous Integration&lt;/em&gt; and &lt;em&gt;Continuous Delivery&lt;/em&gt; kept (and still keep) popping up on every corner. The frameworks and processes behind those two hypes aid developing software at higher quality in shorter release cycles. This is especially relevant since end consumers nowadays expect fast releases including the newest features. If companies neglect this demand, competitors might take advantage of their better time-to-market which might result in increased market share and -dominance. A lot of changes are happening in the space of CI/CD. Existing tools become more mature, gaining increased attention, and new ones are appearing every month including better ways of integrating them into existing or new processes. Companies benefit from more choices, increased flexibility, and faster integration into existing company policies.&lt;/p&gt;</description>
    </item>
    <item>
      <title>35C3: Refreshing Memories</title>
      <link>https://insinuator.net/2019/01/35c3-refreshing-memories/</link>
      <pubDate>Mon, 07 Jan 2019 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2019/01/35c3-refreshing-memories/</guid>
      <description>&lt;p&gt;Hello fellow Troopers and Happy new Year!&lt;/p&gt;&#xA;&lt;p&gt;35C3 is over, and the recordings are available so in case you did not have the chance or the time to watch the live streams during the holidays or overwhelmed with the number of talks, see in the following a list of recommended talks to fill your evenings or weekends. Apart from the broad coverage of topics in different areas (Ethics, Society &amp;amp; Politics, Hardware &amp;amp; Making, Resilience, Art and Culture, Security, Science, Resilience), foundation talks were aiming for the very basics following this year’s motto “Refreshing Memories.”&lt;/p&gt;</description>
    </item>
    <item>
      <title>Blackhoodie at TROOPERS19</title>
      <link>https://insinuator.net/2019/01/blackhoodie-at-troopers19/</link>
      <pubDate>Fri, 04 Jan 2019 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2019/01/blackhoodie-at-troopers19/</guid>
      <description>&lt;p&gt;We are going to have a &lt;a href=&#34;https://insinuator.net/tag/blackhoodie/&#34;&gt;Blackhoodie event&lt;/a&gt; at &lt;a href=&#34;https://www.troopers.de/&#34;&gt;Troopers 2019&lt;/a&gt; on March 18th and 19th in Heidelberg. With a very exciting event last year, we have decided to roll it once again during Troopers.&lt;/p&gt;&#xA;&lt;p&gt;As always, one of the main motivation for &lt;a href=&#34;https://www.blackhoodie.re/about/&#34;&gt;Blackhoodie&lt;/a&gt; is bringing more women into reversing and other core security topics. So we would like to see more women apply to the training slots. However, if you are not a women and still feel really excited about Blackhoodie, you are welcome to apply. We do have a very limited number of seats at this training site. So we apologize in advance if we can’t accommodate everyone, even though we wish we could! Please apply before &lt;strong&gt;“February 10th”&lt;/strong&gt; and we will contact you regarding next steps.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Catching fire with Docker, DevOps &amp;amp; Security in Enterprise Environments</title>
      <link>https://insinuator.net/2019/01/catching-fire-with-docker-devops-amp-security-in-enterprise-environments/</link>
      <pubDate>Fri, 04 Jan 2019 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2019/01/catching-fire-with-docker-devops-amp-security-in-enterprise-environments/</guid>
      <description>&lt;p&gt;Docker has become the go-to technology in enterprise- and DevOps contexts. Yet, before mastering a skill, there is the thumb rule: one must learn the basics to have solid fundament before building a house on top.&lt;/p&gt;&#xA;&lt;p&gt;Simon and I start from the very beginning. We introduce you to the fundamental concepts of containers starting at process isolation and extending our tour to the whole ecosystem of Docker and further associated technologies. We will cover Docker, microservices, containers, DevOps, continuous integration/deployment/delivery – all those fancy buzzwords that can be read in the context of modern software development methodologies.&lt;/p&gt;</description>
    </item>
    <item>
      <title>And Five Talks More Were Accepted at TROOPERS19!</title>
      <link>https://insinuator.net/2018/12/and-five-talks-more-were-accepted-at-troopers19/</link>
      <pubDate>Mon, 10 Dec 2018 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2018/12/and-five-talks-more-were-accepted-at-troopers19/</guid>
      <description>&lt;p&gt;And five talks more were chosen for TROOPERS19! It sounds like it is going to be the best year ever again…&lt;/p&gt;&#xA;&lt;p&gt;Follow us on Twitter (&lt;a href=&#34;https://twitter.com/WEareTROOPERS&#34;&gt;@WEareTROOPERS&lt;/a&gt;) for more information and do not hesitate to use our hashtag #TR19 when you have questions or remarks about TROOPERS19!&lt;/p&gt;&#xA;&lt;p&gt;Your TROOPERS Team&lt;/p&gt;&#xA;&lt;p&gt;——————————–&lt;/p&gt;&#xA;&lt;h1 id=&#34;not-a-security-boundary-breaking-forest-trusts-by-will-schroeder-lee-christensen&#34;&gt;Not A Security Boundary: Breaking Forest Trusts by Will Schroeder, Lee Christensen&lt;/h1&gt;&#xA;&lt;p&gt;Presenting at the Active Directory Security Track&lt;/p&gt;&#xA;&lt;p&gt;&lt;strong&gt;Abstract:&lt;/strong&gt;&lt;/p&gt;</description>
    </item>
    <item>
      <title>First Talks of TROOPERS19 Accepted!</title>
      <link>https://insinuator.net/2018/11/first-talks-of-troopers19-accepted/</link>
      <pubDate>Thu, 29 Nov 2018 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2018/11/first-talks-of-troopers19-accepted/</guid>
      <description>&lt;p&gt;TROOPERS18 was the best year ever (did you check our &lt;a href=&#34;https://troopers.de/archives/&#34;&gt;archives&lt;/a&gt;?) and it will be challenging to do better… However, we accept the challenge!&lt;/p&gt;&#xA;&lt;p&gt;The trainings and talks were from high quality and choices were difficult to make… We hope you will enjoy reading these little teasers!&lt;/p&gt;&#xA;&lt;p&gt;Follow us on Twitter (&lt;a href=&#34;https://twitter.com/WEareTROOPERS&#34;&gt;@WEareTROOPERS&lt;/a&gt;) for more information and do not hesitate to use our hashtag #TR19 when you have questions or remarks about TROOPERS19!&lt;/p&gt;</description>
    </item>
    <item>
      <title>The Dog Whisperer’s Handbook</title>
      <link>https://insinuator.net/2018/11/the-dog-whisperers-handbook/</link>
      <pubDate>Mon, 19 Nov 2018 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2018/11/the-dog-whisperers-handbook/</guid>
      <description>&lt;p&gt;Generally speaking, I’m more of a Cat type of guy, but I have to say I really love BloodHound. And if you do too, you are in for a treat…&lt;br&gt;&#xA;Last week, the &lt;a href=&#34;https://twitter.com/ERNW_Insight&#34;&gt;ERNW Insight&lt;/a&gt; &lt;strong&gt;Active Directory Security Summit&lt;/strong&gt; took place in Heidelberg. (&lt;a href=&#34;https://insinuator.net/2018/11/active-directory-security-summit-2018-slides-online/&#34;&gt;More Info&lt;/a&gt;)&lt;br&gt;&#xA;For this occasion, &lt;a href=&#34;https://twitter.com/Enno_Insinuator&#34;&gt;@Enno_Insinuator&lt;/a&gt; asked me if I would like to deliver a &lt;strong&gt;BloodHound Workshop&lt;/strong&gt;, and of course I accepted the challenge…&lt;/p&gt;&#xA;&lt;p&gt;We had a full class, I had a blast training it, and I hope the trainees enjoyed it as much as I did.&lt;br&gt;&#xA;But that’s not all…&lt;br&gt;&#xA;Another part of the deal was that I had to write a &lt;strong&gt;Training Guide&lt;/strong&gt; that we would then &lt;strong&gt;share with the Community&lt;/strong&gt; (aka you).&lt;br&gt;&#xA;So here it is, fresh from the Heidelberg press and available for download:&lt;/p&gt;</description>
    </item>
    <item>
      <title>Active Directory Security Summit 2018 – Slides Online</title>
      <link>https://insinuator.net/2018/11/active-directory-security-summit-2018-slides-online/</link>
      <pubDate>Fri, 16 Nov 2018 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2018/11/active-directory-security-summit-2018-slides-online/</guid>
      <description>&lt;p&gt;on Tuesday, 13.th of November we realized our second AD security summit with the title: “&lt;a href=&#34;https://ernw-insight.de/de/events/2018-11-13-summit18-ad/&#34;&gt;Active Directory Security: On-Prem-Security, Secure Extension into the Cloud &amp;amp; Secure Operations&lt;/a&gt;” in Heidelberg. First, we had three talks: the first one about “&lt;a href=&#34;https://ernw.de/download/AD_Summit_2018/01_AD_Summit_CoreSecPrinciples_fk_hw_v.1.2_signed.pdf&#34;&gt;Active Directory Core Security Principles &amp;amp; Best Practices&lt;/a&gt;” covering hybrid AD and AD Trusts as well (by Friedwart Kuhn &amp;amp; Heinrich Wiederkehr from ERNW), the second one a case study about the &lt;a href=&#34;https://ernw.de/download/AD_Summit_2018/SecureAD_realWorldScenario_final.pdf&#34;&gt;implementation of an ESAE Forest in a big insurance company&lt;/a&gt; (by Fabian Böhm from &lt;a href=&#34;https://www.teal-consulting.de/&#34;&gt;Teal Technology Consulting&lt;/a&gt;) and the third one about a case study with respect to the (security) challenges of a hybrid AD (by Raphael Rojas from &lt;a href=&#34;https://www.stihl.de/&#34;&gt;STIHL&lt;/a&gt;). The afternoon passed quickly with a very fruitful and vivid discussion about implementing and operating securely ESAE environments and hybrid ADs and how to deal with the high number of AD Trusts many organisations suffer from. Today we published the slides. Enjoy and stay tuned!&lt;/p&gt;</description>
    </item>
    <item>
      <title>Hack.lu 2018: Back and forth with the ERNW Crew</title>
      <link>https://insinuator.net/2018/11/hack.lu-2018-back-and-forth-with-the-ernw-crew/</link>
      <pubDate>Tue, 13 Nov 2018 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2018/11/hack.lu-2018-back-and-forth-with-the-ernw-crew/</guid>
      <description>&lt;p&gt;If a conference feels like a great vacation, then the organizers are doing it absolutely right! &lt;a href=&#34;https://hack.lu/&#34;&gt;Hack.lu&lt;/a&gt; took place for the 14th time in Luxembourg. From the 16th – 18th October, the Alvisse Parc Hotel hosted the Hack.lu conference. Those three days were full of talks, workshops and “discussions about computer security, privacy, information technology and its cultural/technical implication on society“. Some members of the ERNW crew had the chance to attend Hack.lu this year and we all enjoyed it a lot!&lt;/p&gt;</description>
    </item>
    <item>
      <title>Hack.lu 2018: Fuzzing Workshop by René Freingruber</title>
      <link>https://insinuator.net/2018/11/hack.lu-2018-fuzzing-workshop-by-ren%C3%A9-freingruber/</link>
      <pubDate>Tue, 06 Nov 2018 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2018/11/hack.lu-2018-fuzzing-workshop-by-ren%C3%A9-freingruber/</guid>
      <description>&lt;p&gt;I was at the hack.lu conference in Luxembourg this year and attended the fuzzing workshop, held by &lt;a href=&#34;https://twitter.com/renefreingruber&#34;&gt;René Freingruber&lt;/a&gt; from &lt;a href=&#34;https://sec-consult.com/en/&#34;&gt;SEC Consult&lt;/a&gt;. I have been curious about this topic for some years now, but besides doing some manual fuzzing and web-fuzzing, I never looked into the whole topic that much.&lt;/p&gt;&#xA;&lt;p&gt;The workshop lasted for around four hours. Before the workshop started each student got two VMs (Linux/Windows) where everything necessary was already set up. The VMs included 23 exercises, with step-by-step explanations, source code and exploits. René started out with an introduction to fuzzing, listing popular fuzzers and showing an example on how to fuzz with &lt;a href=&#34;http://lcamtuf.coredump.cx/afl/&#34;&gt;afl&lt;/a&gt;.&lt;/p&gt;</description>
    </item>
    <item>
      <title>H2HC2018 – Attacking VMware NSX</title>
      <link>https://insinuator.net/2018/11/h2hc2018-attacking-vmware-nsx/</link>
      <pubDate>Fri, 02 Nov 2018 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2018/11/h2hc2018-attacking-vmware-nsx/</guid>
      <description>&lt;p&gt;&lt;a href=&#34;https://twitter.com/uchi_mata&#34;&gt;Matthias&lt;/a&gt; and &lt;a href=&#34;https://twitter.com/NodyTweet&#34;&gt;I&lt;/a&gt; had the pleasure to give a talk at the &lt;a href=&#34;https://www.h2hc.com.br/&#34;&gt;H2HC2018&lt;/a&gt; in São Paulo, Brazil about attacking VMware NSX. The talk is an introduction to VMware NSX for security researchers, and it discusses possible attack vectors including the management, controlling, and data exchange planes. We demonstrated how to prepare a fuzzing and debugging setup for the ESXi kernel and the kernel modules. It should be noted that &lt;a href=&#34;https://twitter.com/Syyyrius&#34;&gt;Olli&lt;/a&gt; was also supporting the research.&lt;br&gt;&#xA;The slides can be found &lt;a href=&#34;https://insinuator.net/wp-content/uploads/2018/11/H2HC_HarrieLuft_AttackingVMwareNSX-1.pdf&#34;&gt;here&lt;/a&gt;.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Hack.lu 2018: ARM IoT Firmware Emulation Workshop by Saumil Udayan Shah</title>
      <link>https://insinuator.net/2018/10/hack.lu-2018-arm-iot-firmware-emulation-workshop-by-saumil-udayan-shah/</link>
      <pubDate>Wed, 24 Oct 2018 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2018/10/hack.lu-2018-arm-iot-firmware-emulation-workshop-by-saumil-udayan-shah/</guid>
      <description>&lt;p&gt;First day at &lt;a href=&#34;https://2018.hack.lu/&#34;&gt;hack.lu&lt;/a&gt;. Three of us kicked the conference off with the ARM IoT Firmware Emulation workshop by &lt;a href=&#34;https://twitter.com/therealsaumil&#34;&gt;Saumil&lt;/a&gt;. The goal of this workshop was not so much to write exploits or to pwn boxes but to learn how to build a beneficial research environment by emulating the hardware of a Linux based IoT device to run its firmware in order to run analysis and tests.&lt;/p&gt;&#xA;&lt;p&gt;First step is to obtain the firmware. This could be done by dumping it directly from the device or by downloading firmware images from the vendor. In order to dump the firmware from the device one has to obtain access to the underlying system which is usually done by finding the serial console on the hardware since this one often exposes an unauthenticated root shell. I think there is enough documentation online on how to identify and connect to a serial console so I won’t cover the details here. It’s also covered in Saumil’s &lt;a href=&#34;https://www.slideshare.net/saumilshah/hacklu-2018-make-arm-shellcode-great-again&#34;&gt;slides&lt;/a&gt; in detail. Having the bootup logs from this console will be helpful later though. While talking about baud rates for the serial console Saumil made a great pun I don’t want to withhold: “Most common is baud rate 115200. If you find a console with baud rate 9600 you are in fact talking to an acoustic coupler. That’s not an IoT device, it rather belongs to a museum.”&lt;/p&gt;</description>
    </item>
    <item>
      <title>Incident Analysis and Digital Forensics Summit 2018, 14th of November of 2018</title>
      <link>https://insinuator.net/2018/10/incident-analysis-and-digital-forensics-summit-2018-14th-of-november-of-2018/</link>
      <pubDate>Mon, 08 Oct 2018 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2018/10/incident-analysis-and-digital-forensics-summit-2018-14th-of-november-of-2018/</guid>
      <description>&lt;p&gt;*This event will be held in German*&lt;/p&gt;&#xA;&lt;p&gt;Inspiriert durch die erfolgreichen Round-Table-Diskussionen der Troopers-Konferenz freuen wir uns, Ihnen heute mit dem Incident Analysis and Digital Forensics Summit 2018, eine weitere Veranstaltung in einer Reihe zu Trend-Themen im Bereich der IT-Sicherheit vorzustellen.&lt;/p&gt;&#xA;&lt;p&gt;Die Veranstaltung beginnt am Morgen mit einem Eröffnungsvortrag von Thomas Schreck (Chairman of the Board des internationalen CERT Verbunds FIRST), gefolgt von Fallstudien und Vorträgen durch weitere Referenten aus der Industrie und Strafverfolgung.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Active Directory Security Summit 2018, 13th. of November of 2018</title>
      <link>https://insinuator.net/2018/09/active-directory-security-summit-2018-13th.-of-november-of-2018/</link>
      <pubDate>Mon, 03 Sep 2018 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2018/09/active-directory-security-summit-2018-13th.-of-november-of-2018/</guid>
      <description>&lt;p&gt;I have the pleasure to announce the Active Directory Security Summit 2018 at 13^(th). of November of 2018. The summit covers current Active Directory security related topics such as challenging tasks of hybrid Active Directory operations as well as new security best practices and some ‘evergreens’ – Admin Tiering implementations (what about Exchange and DNS…??), ESAE operations etc. 😉&lt;/p&gt;&#xA;&lt;p&gt;The primary objective of the Active Directory Security Summit is to bring experts together:&lt;/p&gt;</description>
    </item>
    <item>
      <title>Diversity, Community, Blackhoodie</title>
      <link>https://insinuator.net/2018/07/diversity-community-blackhoodie/</link>
      <pubDate>Thu, 26 Jul 2018 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2018/07/diversity-community-blackhoodie/</guid>
      <description>&lt;p&gt;Gender equality in the Infosec world as a topic of discussion comes with a lot of heated arguments and differences in opinion.&lt;br&gt;&#xA;So let me start with some disclaimers on the target audience for this post. If you are in the category who believes everything about gender is perfect in the infosec world, this post is not for you. If you are in the category who believes gender and bringing diversity is not your area of interest, then this post is not for you either. There are so many interesting problems that the world offers you. Climate change, poverty, diseases, unemployment, addiction, science problems and what not. Everybody has the freedom to choose their area of interest and contribute towards it. If you are in the category who thinks gender equality in infosec needs some attention and would like to explore more on the topic without prejudices, then this post may  be interesting to you.&lt;/p&gt;</description>
    </item>
    <item>
      <title>The building IoT 2018 in Cologne</title>
      <link>https://insinuator.net/2018/06/the-building-iot-2018-in-cologne/</link>
      <pubDate>Mon, 18 Jun 2018 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2018/06/the-building-iot-2018-in-cologne/</guid>
      <description>&lt;p&gt;In Mai 2018, Tobias and me were in Cologne at the Building IoT conference. The topics of the talks covered a broad spectrum of the Internet of Things field. There were three tracks covering different topics ranging from the jungle of IoT protocols, secure Linux hypervisors specially developed for IoT modules to machine learning and blockchain.&lt;/p&gt;&#xA;&lt;p&gt;In “How to secure over the air updates” the speaker showed how to securely deploy updates over the standard communication channel to the target device. Many consumer IoT devices have a short support for updates if they get any updates at all. This leads and in the future will lead to bad news like botnets, bricked devices and exploited IP cameras streaming publicly. Therefore, a patch and vulnerability management is required – especially in industrial Internet of Things devices. Some updates have to be performed over the air due to the physical inaccessibility of some IoT devices in production environments. There are two possibilities to update such systems: First, a rescue OS (Operating System) boots and overwrites the existing production OS. The second option is a redundant OS, which copies the updates to the inactive OS and reboots to that.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Modern Application Stacks &amp; Security</title>
      <link>https://insinuator.net/2018/06/modern-application-stacks-security/</link>
      <pubDate>Fri, 15 Jun 2018 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2018/06/modern-application-stacks-security/</guid>
      <description>&lt;p&gt;I had the pleasure to give a presentation at the &lt;a href=&#34;https://www.sig-switzerland.ch/conference/sigs-technology-conference/&#34;&gt;Security Interest Group Switzerland Technology Conference&lt;/a&gt; about modern application stacks and how they can be used to improve infrastructure and application security posture – the slides can be found &lt;a href=&#34;https://ernw.de/download/ERNW_SIG_Cloud_ModernAppStackSecurity_mluft.pdf&#34;&gt;here&lt;/a&gt;. Besides seeing a lot of &lt;a href=&#34;https://twitter.com/ioshints&#34;&gt;old friends&lt;/a&gt;, I particularly enjoyed a round table discussion on security integration into CI/CD pipelines. There was a relevant exchange on approaches that actually work and were tested in environments beyond just recommending some container scanner (product). One participant had an interesting case study on how they enabled developers to maintain WAF policies in configuration files in their code repository including automated deployment to the WAF. He also emphasized that the environments with actual security benefits resulted from a close cooperation between development and security team (were domain knowledge was combined 😉 ).&lt;/p&gt;</description>
    </item>
    <item>
      <title>GI Sicherheit 2018 Conference</title>
      <link>https://insinuator.net/2018/05/gi-sicherheit-2018-conference/</link>
      <pubDate>Thu, 03 May 2018 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2018/05/gi-sicherheit-2018-conference/</guid>
      <description>&lt;p&gt;Last week (25^(th) – 27^(th) April), I attended the “Sicherheit 2018” in Konstanz which is the annual meeting of the security community of the Gesellschaft für Informatik e.V. (GI) in Germany. The conference is in equal proportions attended by researchers and people of the industry working in security-related disciplines which lead to lively and pleasant discussions conversations.&lt;/p&gt;&#xA;&lt;p&gt;The topics discussed were contentual wide-reaching, so there were very technical talks like Sebastian Banescu who was the winner and one of two candidates nominated for the best PhD thesis award presenting about “Characterizing the Strength of Software Obfuscation Against Automated Attacks”, as well as conceptual presentations such as Sabrina Krausz elucidated her bachelor thesis about an integrated procedure model for planning and implementing an ISMS on the example of the pharmaceutical production.&lt;/p&gt;</description>
    </item>
    <item>
      <title>TROOPERS18 Photos online!</title>
      <link>https://insinuator.net/2018/05/troopers18-photos-online/</link>
      <pubDate>Thu, 03 May 2018 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2018/05/troopers18-photos-online/</guid>
      <description>&lt;p&gt;We are very excited to publish some (more to come!) of our photos from &lt;a href=&#34;https://www.troopers.de/troopers18/&#34;&gt;TROOPERS18&lt;/a&gt;! Based on feedback from #TR18 we would also like to take a moment for our official TROOPERS photographer to introduce himself and tell you a little about what inspires him.&lt;/p&gt;&#xA;&lt;p&gt;Peter Walter is a 37 year old photographer based in Germany near Stuttgart. For many years now he is the official TROOPERS photographer and very proud to be part of the Troopers family.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Industrial IoT Overview &amp; Case Studies</title>
      <link>https://insinuator.net/2018/04/industrial-iot-overview-case-studies/</link>
      <pubDate>Wed, 25 Apr 2018 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2018/04/industrial-iot-overview-case-studies/</guid>
      <description>&lt;p&gt;Stefan and I had the pleasure of joining a one-day closed workshop on Industrial IoT Security. As always, we ended up with plenty of new research ideas and great contacts. We hope of course to post on follow-up research, but in this short post we quickly want to publish our slides which contain our input for the workshop. We mainly presented on IT security challenges for modern IIoT environments and presented some case studies for successful hardening/protection of IIoT environments as well as security in IIoT product development.&lt;/p&gt;</description>
    </item>
    <item>
      <title>#TR18 Attack &amp; Research Summaries</title>
      <link>https://insinuator.net/2018/03/%23tr18-attack-research-summaries/</link>
      <pubDate>Fri, 23 Mar 2018 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2018/03/%23tr18-attack-research-summaries/</guid>
      <description>&lt;p&gt;This blogpost contains summaries of talks from this year’s &lt;a href=&#34;https://www.troopers.de/troopers18/&#34;&gt;TROOPERS18&lt;/a&gt; Attack &amp;amp; Research Track.&lt;/p&gt;&#xA;&lt;h1 id=&#34;reverse-engineering-blackbox-systems-with-greatfet--facedancer-by-kate-temkin-and-dominic-spill&#34;&gt;Reverse Engineering Blackbox Systems with GreatFET &amp;amp; Facedancer by Kate Temkin and Dominic Spill&lt;/h1&gt;&#xA;&lt;p&gt;USB is everywhere, your phone, gaming consoles, IoT waffle irons, you name it. Due to its’ widespread use in everyday life it is typically trusted by the user. And even if one wanted to find out what’s happening behind the scenes, surely digging into USB communication is too much of a chore to be worth the hassle, right? This talk by Kate Temkin and Dominic Spill are about to prove that very wrong with an impressive display of their tools &lt;a href=&#34;https://greatscottgadgets.com/greatfet/&#34;&gt;GreatFET&lt;/a&gt; and &lt;a href=&#34;https://github.com/ktemkin/Facedancer&#34;&gt;Facedancer&lt;/a&gt;.&lt;/p&gt;</description>
    </item>
    <item>
      <title>#TR18 Defense &amp; Management Summaries</title>
      <link>https://insinuator.net/2018/03/%23tr18-defense-management-summaries/</link>
      <pubDate>Fri, 23 Mar 2018 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2018/03/%23tr18-defense-management-summaries/</guid>
      <description>&lt;p&gt;This blogpost contains summaries of talks from this year’s &lt;a href=&#34;https://www.troopers.de/troopers18/&#34;&gt;TROOPERS18&lt;/a&gt; Defense &amp;amp; Management Track.&lt;/p&gt;&#xA;&lt;h1 id=&#34;all-your-cloud-are-belong-to-us&#34;&gt;All Your Cloud Are Belong to Us&lt;/h1&gt;&#xA;&lt;p&gt;The talk “All Your Cloud Belong Are Belong to Us” was held by &lt;a href=&#34;https://twitter.com/dk_effect&#34;&gt;Nate Warfield&lt;/a&gt;, who is a Senior Security Program Manager for the Microsoft Security Response Center (MSRC).&lt;br&gt;&#xA;Before Microsoft he worked as a network engineer about 18 years and 10 of this for a large amount of cell phone companies.&lt;br&gt;&#xA;Nate gives an overview about the state of the cloud solution provided by Microsoft, Azure, and how he hunts vulnerabilities in this environment.&lt;br&gt;&#xA;Finally he concludes that the giving up your infrastructure to the cloud doesn’t mean that you give up your responsibility.&lt;/p&gt;</description>
    </item>
    <item>
      <title>#TR18 Next Generation Internet (NGI) Summaries</title>
      <link>https://insinuator.net/2018/03/%23tr18-next-generation-internet-ngi-summaries/</link>
      <pubDate>Fri, 23 Mar 2018 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2018/03/%23tr18-next-generation-internet-ngi-summaries/</guid>
      <description>&lt;p&gt;This blogpost contains summaries of talks from this year’s &lt;a href=&#34;https://www.troopers.de/troopers18/&#34;&gt;TROOPERS18&lt;/a&gt; Next Generation Internet Event.&lt;/p&gt;&#xA;&lt;p&gt; &lt;/p&gt;&#xA;&lt;h1 id=&#34;ngi-keynote-by-graeme-neilson&#34;&gt;NGI Keynote by &lt;a href=&#34;https://www.troopers.de/events/speaker/7_graeme_neilson/&#34;&gt;Graeme Neilson&lt;/a&gt;&lt;/h1&gt;&#xA;&lt;p&gt;Before his infosec career Graeme was a street performer, then security researcher, now he calls himself a defender. The talk was built around the following sentence: “The infosec industry and community have completely failed to create meaningful change in the behavior of people”.&lt;/p&gt;&#xA;&lt;p&gt;The following example is a resume of how hacking worked from 1988 to 2017:&lt;/p&gt;</description>
    </item>
    <item>
      <title>#TR18 SAP Security Summaries</title>
      <link>https://insinuator.net/2018/03/%23tr18-sap-security-summaries/</link>
      <pubDate>Fri, 23 Mar 2018 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2018/03/%23tr18-sap-security-summaries/</guid>
      <description>&lt;p&gt;This blogpost contains summaries of talks from this year’s &lt;a href=&#34;https://www.troopers.de/troopers18/&#34;&gt;TROOPERS18&lt;/a&gt; SAP Security Track.&lt;/p&gt;&#xA;&lt;h1 id=&#34;sap-igs--the-vulnerable-forgotten-component-by-yvan-genuer&#34;&gt;SAP IGS : The ‘vulnerable’ forgotten component by Yvan Genuer&lt;/h1&gt;&#xA;&lt;p&gt;The Internet Graphics Server (IGS) is used to generate Web Based graphics from the SAP Web AS. Yvan Genuer looked at the security of an ancient component with very few public vulnerabilities available so far. In his talk he gave us insights on the structure of the IGS, its services, and problems he had when looking for documentation of the IGS and its components.&lt;/p&gt;</description>
    </item>
    <item>
      <title>#TR18 Active Directory Security Track, Part 1</title>
      <link>https://insinuator.net/2018/03/%23tr18-active-directory-security-track-part-1/</link>
      <pubDate>Thu, 22 Mar 2018 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2018/03/%23tr18-active-directory-security-track-part-1/</guid>
      <description>&lt;p&gt;This is the first post discussing talks of the &lt;em&gt;Active Directory Security Track&lt;/em&gt; of &lt;a href=&#34;https://www.troopers.de/troopers18/&#34;&gt;this year’s Troopers&lt;/a&gt; which took place last week in Heidelberg (like in the last nine years ;-). It featured, amongst others, a new track focused on Microsoft AD and its security properties &amp;amp; implications. &lt;a href=&#34;https://www.troopers.de/troopers18/agenda/#agenda-day--2018-03-15&#34;&gt;This&lt;/a&gt; was the agenda.&lt;/p&gt;&#xA;&lt;p&gt;The idea for this special track was born out of two considerations:&lt;/p&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;we had noted there’s a lot of stuff going on in the space, both on the offense and on the defense side. And in pretty much every incident analysis &amp;amp; response project we were brought in recently Active Directory played a huge role…&lt;/li&gt;&#xA;&lt;li&gt;already in the early phase of the CfP several interesting submissions came in (maybe due to the fact that some big guns of the field had voiced &lt;a href=&#34;https://twitter.com/mattifestation/status/906180147203645440&#34;&gt;very&lt;/a&gt; &lt;a href=&#34;https://twitter.com/christruncer/status/845321214788849666&#34;&gt;kind&lt;/a&gt; &lt;a href=&#34;https://twitter.com/harmj0y/status/710229755795144704&#34;&gt;words&lt;/a&gt; &lt;a href=&#34;https://twitter.com/subTee/status/972191912277901312&#34;&gt;in&lt;/a&gt; &lt;a href=&#34;https://twitter.com/Cneelis/status/845321978089295872&#34;&gt;the&lt;/a&gt; &lt;a href=&#34;https://twitter.com/PyroTek3/status/918214609273868288&#34;&gt;past&lt;/a&gt;)… and creating an extra track simply relieved us from the burden to make a tough choice between those.&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;p&gt;As this was the first Troopers since its creation where I didn’t have any official roles and out of personal interest (in a very distant past I happened to be the co-author of the first German book on &lt;a href=&#34;https://www.amazon.de/Security-unter-Windows-NT-4/dp/3778526707/&#34;&gt;Windows NT4 Security&lt;/a&gt;)  I decided to spend the majority of conference day 2 in the AD track. In hindsight I’m tempted to say that the track was a huge success: brilliant talks, pretty much always a packed room, and quite good discussions after the talks. (yes, of course I’m biased, what makes you think that?).&lt;/p&gt;</description>
    </item>
    <item>
      <title>The Hackers‘ Sanctuary City</title>
      <link>https://insinuator.net/2018/03/the-hackers-sanctuary-city/</link>
      <pubDate>Wed, 14 Mar 2018 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2018/03/the-hackers-sanctuary-city/</guid>
      <description>&lt;p&gt;&lt;a href=&#34;https://youtu.be/wCMwTUS3k4c&#34;&gt;https://youtu.be/wCMwTUS3k4c&lt;/a&gt;&lt;/p&gt;&#xA;&lt;p&gt;&lt;a href=&#34;http://troopers.de&#34;&gt;&lt;strong&gt;TROOPERS&lt;/strong&gt;&lt;/a&gt; has a long history of theming the conference every year. Usually we pick a surreal topic, a fun story which we think is worth to pick up on. Some of it starts as a crazy thought, others have been the result of long discussions. Most of them are online, only our master piece from 2016 is securely stored in the company’s vaults.&lt;/p&gt;&#xA;&lt;p&gt;&lt;img src=&#34;fake_news.png&#34; alt=&#34;&#34;&gt;&lt;/p&gt;&#xA;&lt;p&gt;However, this year was different. Traveling across the globe, speaking at and attending other conferences, connecting with our peers and the community, we felt that 2017 was a particularly tough year for many of us, both professionally and personally. There was this doom and gloom baseline to it.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Auditing AWS Environments</title>
      <link>https://insinuator.net/2018/03/auditing-aws-environments/</link>
      <pubDate>Wed, 07 Mar 2018 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2018/03/auditing-aws-environments/</guid>
      <description>&lt;h2 id=&#34;introduction&#34;&gt;Introduction&lt;/h2&gt;&#xA;&lt;p&gt;Related to our new TROOPERS workshop &lt;a href=&#34;https://troopers.de/troopers18/trainings/jfc3gg/&#34;&gt;“Jump-Starting Public Cloud Security”&lt;/a&gt;, this post is going to describe some relevant components which need to be taken care of when constructing and auditing an Amazon Web Services (AWS) cloud environment. Those include amongst others the general AWS account structure, Identity and Access Management (IAM), Auditing and Logging (CloudTrail and CloudWatch), Virtual Private Cloud (VPC) networks, as well as S3 buckets.&lt;/p&gt;&#xA;&lt;p&gt;The AWS IAM service is responsible for identity and access management (surprise!). This includes managing user accounts, defining password policies, and – most importantly – creating, defining, and assigning groups and roles.&lt;/p&gt;</description>
    </item>
    <item>
      <title>TelcoSecDay 2018 – Talks Part2</title>
      <link>https://insinuator.net/2018/02/telcosecday-2018-talks-part2/</link>
      <pubDate>Mon, 26 Feb 2018 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2018/02/telcosecday-2018-talks-part2/</guid>
      <description>&lt;p&gt;We have the next set of selected talks being announced here. I am super excited about the variety of applications we had this year. Here are some of the talks we will have.&lt;/p&gt;&#xA;&lt;p&gt;&lt;strong&gt;Title: From LoRa technology to deployment within Orange affiliates&lt;/strong&gt;&lt;/p&gt;&#xA;&lt;p&gt;&lt;em&gt;Speakers: Franck L’Hereec and  Albert Nguyen&lt;/em&gt;&lt;/p&gt;&#xA;&lt;p&gt;Just deployed, the LoRa technology has already passed into the hands of hackers who have analyzed the LoRaWAN protocol as well as the objects and gateways that implement it. At Orange, Orange Labs’ security experts have therefore looked into those issues, first to understand it better, and also ensure the network’s deployment in optimal security conditions. Demonstration via the example of the treatment of the security of an innovation project by Orange. During the presentation we will present :&lt;/p&gt;</description>
    </item>
    <item>
      <title>TLS in the Enterprise: Is Heartbleed still a Problem?</title>
      <link>https://insinuator.net/2018/02/tls-in-the-enterprise-is-heartbleed-still-a-problem/</link>
      <pubDate>Fri, 16 Feb 2018 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2018/02/tls-in-the-enterprise-is-heartbleed-still-a-problem/</guid>
      <description>&lt;p&gt;Our new workshop about &lt;a href=&#34;https://troopers.de/troopers18/trainings/9afapk/&#34;&gt;TLS/SSL in the enterprise&lt;/a&gt; will be held for the 1st time at Troopers 2018. So I would like to take the opportunity and post a short teaser about stuff we will cover in this workshop.&lt;/p&gt;&#xA;&lt;p&gt;TLS/SSL is a complicated topic especially in enterprise environments due to the fact, that&lt;/p&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;encrypted traffic should be inspected e.g. for malware&lt;/li&gt;&#xA;&lt;li&gt;customers/users must be able to use important applications&lt;/li&gt;&#xA;&lt;li&gt;crypto attacks are complex and sometimes considered to be only a problem in theory&lt;/li&gt;&#xA;&lt;li&gt;the internal CERT wants to have every issue fixed, if feasible or not 😉&lt;/li&gt;&#xA;&lt;li&gt;impact of configuration changes can not be foreseen&lt;/li&gt;&#xA;&lt;li&gt;Software inventory is incomplete (do you want to make a bet that Heartbleed is fixed completely in your environment ;-)? )&lt;/li&gt;&#xA;&lt;li&gt;… and so forth&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;p&gt;In the workshop we will cover all these points, discuss them and share our experience regarding feasibility and useful mitigating controls. We will explain the most common SSL vulnerabilities/attacks, demonstrate tools to test (and sometimes to exploit) them, point out pitfalls and recommend what to do. Let us have a look at one example, Heartbleed:&lt;/p&gt;</description>
    </item>
    <item>
      <title>Get your hands dirty playing with RFID/NFC</title>
      <link>https://insinuator.net/2018/02/get-your-hands-dirty-playing-with-rfid/nfc/</link>
      <pubDate>Wed, 14 Feb 2018 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2018/02/get-your-hands-dirty-playing-with-rfid/nfc/</guid>
      <description>&lt;p&gt;&lt;em&gt;This is a guest blog post by Nahuel Grisolia.&lt;/em&gt;&lt;/p&gt;&#xA;&lt;p&gt;The first time I’ve heard about RFID was at high school, back in 2002, when I was studying Electronics. Back in that time, this technology was like some sort of black magic to me. A few years later in 2011, our government in Argentina decided to implement a “new technology” called NFC, designed as the new and only way of payment for the use of public transport. So, I decided to understand it better, play with it, and try some hacks I heard from the cool people of the CCC.&lt;/p&gt;</description>
    </item>
    <item>
      <title>TelcoSecDay 2018 – CFP and First talks</title>
      <link>https://insinuator.net/2018/02/telcosecday-2018-cfp-and-first-talks/</link>
      <pubDate>Thu, 08 Feb 2018 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2018/02/telcosecday-2018-cfp-and-first-talks/</guid>
      <description>&lt;p&gt;We have a short update from the TelcoSecDay 2018 Agenda. But before that, a short reminder. The CFP for TelcoSecDay 2018 is still open. If you are into telco research, and if you have something interesting to talk, please make a submission &lt;a href=&#34;https://cfp.ernw-insight.de/tsd18/&#34;&gt;here&lt;/a&gt;. The deadline is &lt;strong&gt;17th February 2018.&lt;/strong&gt;&lt;/p&gt;&#xA;&lt;p&gt;Here are the first two confirmed speakers who are going to talk about the below mentioned topics:&lt;/p&gt;&#xA;&lt;p&gt;&lt;strong&gt;Title: Data Security for 4G Interconnection and 5G Interconnection Risk Areas&lt;/strong&gt;&lt;/p&gt;</description>
    </item>
    <item>
      <title>Blackhoodie at TROOPERS18</title>
      <link>https://insinuator.net/2018/02/blackhoodie-at-troopers18/</link>
      <pubDate>Fri, 02 Feb 2018 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2018/02/blackhoodie-at-troopers18/</guid>
      <description>&lt;p&gt;We are thrilled to announce the &lt;a href=&#34;https://insinuator.net/tag/blackhoodie/&#34;&gt;Blackhoodie event&lt;/a&gt; at &lt;a href=&#34;https://www.troopers.de/&#34;&gt;Troopers 2018&lt;/a&gt; on March 12th and 13th in Heidelberg. This time it is going to be a 2 day workshop with various interesting topics related to reverse engineering. We will make sure that you get some hands on experience with reversing and more.&lt;/p&gt;&#xA;&lt;p&gt;As always, one of the main motivation for &lt;a href=&#34;https://www.blackhoodie.re/about/&#34;&gt;Blackhoodie&lt;/a&gt; is bringing more women into reversing.&lt;br&gt;&#xA;So we would like to see more women apply to the training slots. However, we are open to everyone who would like to apply. We do have a very limited number of seats at this training site. So we apologize in advance if we can’t accommodate everyone, even though we wish we could! Please apply before &lt;strong&gt;“February 20th”&lt;/strong&gt; and we will contact you regarding next steps.&lt;/p&gt;</description>
    </item>
    <item>
      <title>#TR18 Active Directory Security Track</title>
      <link>https://insinuator.net/2018/01/%23tr18-active-directory-security-track/</link>
      <pubDate>Fri, 05 Jan 2018 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2018/01/%23tr18-active-directory-security-track/</guid>
      <description>&lt;p&gt;A happy new year to everybody!&lt;/p&gt;&#xA;&lt;p&gt;At &lt;a href=&#34;https://www.troopers.de/&#34;&gt;Troopers18&lt;/a&gt; there will be a new special track on Microsoft Active Directory and its security aspects, similar to the SAP security track which we established some years ago. The AD security track will feature, amongst others, the following talks.&lt;/p&gt;&#xA;&lt;p&gt;&lt;strong&gt;Sean Metcalf: Active Directory Security. The Journey&lt;/strong&gt;&lt;/p&gt;&#xA;&lt;p&gt;&lt;strong&gt;Abstract&lt;/strong&gt;: This talk is a journey into the challenges most organizations encounter while trying to secure their ‘castle’. The attacker has to be right only once, right? Not exactly. We will walk through effective security strategies that will stymie and frustrate attackers and better protect the Active Directory environment.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Yet another edition of BlackHoodie – #BlackHoodie17</title>
      <link>https://insinuator.net/2017/12/yet-another-edition-of-blackhoodie-%23blackhoodie17/</link>
      <pubDate>Mon, 11 Dec 2017 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2017/12/yet-another-edition-of-blackhoodie-%23blackhoodie17/</guid>
      <description>&lt;p&gt;I am amazed by how this years &lt;a href=&#34;https://www.blackhoodie.re/&#34;&gt;BlackHoodie&lt;/a&gt; unraveled. Three days that included a pre-conference of lightening talks and two parallel tracks with a total of 64 enthusiastic members. The very spirit of &lt;a href=&#34;https://www.blackhoodie.re/&#34;&gt;BlackHoodie&lt;/a&gt; is nothing other than the quest to gain deep knowledge. Reverse engineering is one of the hardest fields in security. It touches on all fields of computing, starting from assembly, programming, file formats, operating systems, networks and what not. This makes it hard but an extremely fulfilling experience to spend time learning it. For me, the very idea of staring at a binary till you understand what it does is a magical feeling.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Let’s talk about RFC 6980</title>
      <link>https://insinuator.net/2017/12/lets-talk-about-rfc-6980/</link>
      <pubDate>Fri, 01 Dec 2017 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2017/12/lets-talk-about-rfc-6980/</guid>
      <description>&lt;p&gt;Following my work with the &lt;a href=&#34;https://insinuator.net/2017/06/testing-rfc-6980-implementations-of-freebsd/&#34;&gt;FreeBSD implementation of RFC 6980&lt;/a&gt; I was happy to present my work at last week’s DENOG 9 meeting.&lt;br&gt;&#xA;To make it available to anyone who did not meet me there and go into some more detail that would have exceeded the boundaries of the talk, I will cover the topic here.&lt;/p&gt;&#xA;&lt;p&gt;After the preceding work on &lt;a href=&#34;https://insinuator.net/2017/03/testing-rfc-6980-implementations-with-chiron/&#34;&gt;Windows Server 2016&lt;/a&gt; and the FreeBSD testing, as a Linux user, lover and administrator, I of course wanted to take a look at how different Linux systems complied with the RFC 6980 standard.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Announcing the first 5 talks of TROOPERS18!!!!</title>
      <link>https://insinuator.net/2017/11/announcing-the-first-5-talks-of-troopers18/</link>
      <pubDate>Wed, 29 Nov 2017 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2017/11/announcing-the-first-5-talks-of-troopers18/</guid>
      <description>&lt;p&gt;&lt;a href=&#34;https://www.troopers.de/troopers17/&#34;&gt;TROOPERS17&lt;/a&gt; was unlike any TROOPERS we had known before. Everything just seemed bolder, better, and beyond our expectations. From surprise speakers like &lt;a href=&#34;https://twitter.com/thegrugq&#34;&gt;the grugq&lt;/a&gt; (do you have a follow-up talk for #TR18 by the way?) to new speakers who are now TROOPERS family, TROOPERS17 is one for the history books!&lt;/p&gt;&#xA;&lt;p&gt;If you were there you might be wondering to yourself, how could they possibly top it (and if you were not there check out this &lt;a href=&#34;https://www.youtube.com/watch?v=pfA63LGkf0w&#34;&gt;video from TR17&lt;/a&gt;)? Well, I am not going to lie, it will be a challenge. However, the high quality of talk and training submissions for this year have us feeling pretty positive about making #TR18 the “best year ever”!&lt;/p&gt;</description>
    </item>
    <item>
      <title>My Journey to DockerCon Europe 2017</title>
      <link>https://insinuator.net/2017/11/my-journey-to-dockercon-europe-2017/</link>
      <pubDate>Thu, 09 Nov 2017 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2017/11/my-journey-to-dockercon-europe-2017/</guid>
      <description>&lt;p&gt;From October 17th – 19th I had the chance to attend my first &lt;a href=&#34;https://europe-2017.dockercon.com/&#34;&gt;DockerCon Europe 2017&lt;/a&gt;.&lt;/p&gt;&#xA;&lt;p&gt;The conference was very well organized and attendee focused, which could be seen by the many little details found on the conference. For example you never ran out of coffee or beverages, there was a new Hallway Track where you could meet people from all disciplines, discuss about your favorite topics and there was always a place to sit and take a break between all those interesting presentations. I had the chance to speak to very nice people from different industries, most importantly in my case on the topic security. It was nice to see how the Docker community is growing and the adoption rate is increasing, especially in companies. The main focus of the conference (especially seen in talks held by people from Docker Inc.) was the Docker Enterprise Edition.&lt;/p&gt;</description>
    </item>
    <item>
      <title>TROOPERS for Students!</title>
      <link>https://insinuator.net/2017/10/troopers-for-students/</link>
      <pubDate>Thu, 12 Oct 2017 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2017/10/troopers-for-students/</guid>
      <description>&lt;p&gt;We are super excited for &lt;a href=&#34;https://www.troopers.de/&#34;&gt;TROOPERS18&lt;/a&gt; (March 12-16th, 2018) as are many of you! We even have this great saying that “&lt;em&gt;after&lt;/em&gt; TROOPERS is &lt;em&gt;before&lt;/em&gt; TROOPERS”, which means we spend a lot of time looking through feedback from attendees, speakers/trainers, and our own Crew for ways to not only top what we’ve done in the years before, but also how to simply make it &lt;strong&gt;better&lt;/strong&gt; for everyone involved.  Looking around at our Crew we realized how many have either attended TROOPERS or other conferences as students. We heard from them, as well as other students, how life changing it was to be able, as a student, to attend an IT-Security conference. How they got to meet a speaker whose work they’d read about in class. How people felt even more a part of the community they were studying hard to belong to. &lt;/p&gt;</description>
    </item>
    <item>
      <title>Daycon X1</title>
      <link>https://insinuator.net/2017/10/daycon-x1/</link>
      <pubDate>Wed, 04 Oct 2017 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2017/10/daycon-x1/</guid>
      <description>&lt;p&gt;This is my short write up on &lt;a href=&#34;http://day-con.org/styled/&#34;&gt;Daycon X1&lt;/a&gt;, 2017.  The summit was held at Dayton, the land where &lt;a href=&#34;https://en.wikipedia.org/wiki/Wright_brothers&#34;&gt;Wright brothers&lt;/a&gt; were born. Apart from being my first US trip, I also gave my first training on Hacking 101 also called the Bootcamp.&lt;/p&gt;&#xA;&lt;p&gt;The Daycon X1  bootcamp started on 18th September. Ahmad, my colleague focused on web security, network scanning and metasploit exercises. I mainly handled classes on reversing and binary exploitation along with some pcap anaylsis and network attacks. It was highly fulfilling  experience to give a workshop. Teaching is definitely the best way to learn any topic by digging deep into it.The simpler you can explain, the more clarity you have on the topic. But I must say that it was indeed exhausting by the end of three days.&lt;/p&gt;</description>
    </item>
    <item>
      <title>RIPE IoT Roundtable Meeting / Balanced Security for IPv6 CPE Revisited</title>
      <link>https://insinuator.net/2017/09/ripe-iot-roundtable-meeting-/-balanced-security-for-ipv6-cpe-revisited/</link>
      <pubDate>Fri, 29 Sep 2017 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2017/09/ripe-iot-roundtable-meeting-/-balanced-security-for-ipv6-cpe-revisited/</guid>
      <description>&lt;p&gt;Last week I had the pleasure to participate at the first &lt;a href=&#34;https://www.ripe.net/participate/meetings/roundtable/september-2017/ripe-iot-roundtable-meeting-21-september-2017&#34;&gt;&lt;em&gt;RIPE IoT Roundtable Meeting&lt;/em&gt;&lt;/a&gt; in Leeds (thanks! to &lt;a href=&#34;https://www.ripe.net/about-us/press-centre/publications/speakers/marco-hogewoning&#34;&gt;Marco Hogewoning&lt;/a&gt; for organising it). It was a day with many fruitful discussions. I particularly enjoyed &lt;a href=&#34;https://twitter.com/kistel&#34;&gt;Robert Kisteleki&lt;/a&gt;‘s talk on RIPE NCC’s own design &amp;amp; (security) process considerations in the context of &lt;a href=&#34;https://atlas.ripe.net/&#34;&gt;RIPE Atlas&lt;/a&gt; (at TR17 NGI there was an &lt;a href=&#34;https://www.troopers.de/downloads/troopers17/TR17_RIPEatlas.pdf&#34;&gt;intro to Atlas&lt;/a&gt;, too).&lt;br&gt;&#xA;In this post I’d like to quickly lay out the main points of my own contribution on “Balanced Security for IPv6 CPE Revisited” (the slides can be found &lt;a href=&#34;https://www.ernw.de/download/RIPE_IoT_Roundtable_Sep2017_EnnoRey_BalancedIPv6Sec.pdf&#34;&gt;here&lt;/a&gt;).&lt;/p&gt;</description>
    </item>
    <item>
      <title>HITCON CMT 2017</title>
      <link>https://insinuator.net/2017/09/hitcon-cmt-2017/</link>
      <pubDate>Thu, 28 Sep 2017 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2017/09/hitcon-cmt-2017/</guid>
      <description>&lt;p&gt;Some of our Troopers had the chance to visit HITCON conference in Taiwan this year. There are two main events: HITCON Pacific, which is aimed more at corporate attendees and HITCON CMT, the community edition, which aims at students and the general Infosec community. HITCON is the biggest security conference in Taiwan.&lt;/p&gt;&#xA;&lt;p&gt;The venue for the event is the Academia Sinica, one of the most important academic institution in the Republic of China and was founded in 1928 to promote and undertake scholarly research in sciences and humanities. The conference had three usual tracks and one special track that was free to use for the public for demos, presentations and discussions.&lt;/p&gt;</description>
    </item>
    <item>
      <title>DFRWS USA 2017</title>
      <link>https://insinuator.net/2017/09/dfrws-usa-2017/</link>
      <pubDate>Wed, 06 Sep 2017 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2017/09/dfrws-usa-2017/</guid>
      <description>&lt;p&gt;As mentioned in my last &lt;a href=&#34;https://insinuator.net/2017/07/release-of-glibc-heap-analysis-plugins-for-rekall/&#34;&gt;blogpost&lt;/a&gt;, I had the pleasure to participate in this years DFRWS USA and present our paper. The paper and presentation can be freely viewed and downloaded &lt;a href=&#34;https://www.dfrws.org/conferences/dfrws-usa-2017/sessions/linux-memory-forensics-dissecting-user-space-process-heap&#34;&gt;here&lt;/a&gt; or &lt;a href=&#34;https://authors.elsevier.com/sd/article/S1742287617301895&#34;&gt;here&lt;/a&gt;. Note that there is also an extended version of the paper, which can be downloaded &lt;a href=&#34;https://opus4.kobv.de/opus4-fau/frontdoor/index/index/docId/8340&#34;&gt;here&lt;/a&gt;.&lt;/p&gt;&#xA;&lt;p&gt;The keepassx, zsh and heap analysis plugins are now also part of the &lt;a href=&#34;https://github.com/google/rekall/releases/tag/v1.7.0rc1&#34;&gt;Rekall release candidate 1.7.0RC1&lt;/a&gt;, so it’s easier to get started.&lt;/p&gt;&#xA;&lt;p&gt;The conference had some great talks and workshops, which I’m going to briefly sum up.&lt;/p&gt;</description>
    </item>
    <item>
      <title>11th USENIX Workshop on Offensive Technologies (WOOT17)</title>
      <link>https://insinuator.net/2017/08/11th-usenix-workshop-on-offensive-technologies-woot17/</link>
      <pubDate>Wed, 16 Aug 2017 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2017/08/11th-usenix-workshop-on-offensive-technologies-woot17/</guid>
      <description>&lt;p&gt;The 11th USENIX Workshop on Offensive Technologies (WOOT17) took place the last two days in Vancouver. Some colleagues and I had the chance to attend and enjoy the presentations of all accepted papers of this rather small, single-track co-located USENIX event. Unfortunately, the talks have not been recorded. However, all the papers should be available on the &lt;a href=&#34;https://www.usenix.org/conference/woot17/workshop-program&#34;&gt;website&lt;/a&gt;. It’s worth taking a look at all of the papers, but these are some presentations that we’ve enjoyed:&lt;/p&gt;</description>
    </item>
    <item>
      <title>Black Hat 20 &amp; DEFCON 25</title>
      <link>https://insinuator.net/2017/08/black-hat-20-defcon-25/</link>
      <pubDate>Wed, 09 Aug 2017 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2017/08/black-hat-20-defcon-25/</guid>
      <description>&lt;p&gt;Some of the ERNW Crew hit up Black Hat USA and DEFCON. Our own Omar Eissa even gave his first BH and DEFCON talks! See which talk we liked and what inspiration we took home.&lt;/p&gt;&#xA;&lt;p&gt;BlackHat US 20:&lt;/p&gt;&#xA;&lt;p&gt;ERNW´s Omar Eissa presented on Cisco Autonomic networks showing how&lt;br&gt;&#xA;slides: &lt;a href=&#34;https://www.blackhat.com/docs/us-17/wednesday/us-17-Eissa-Network-Automation-Isn&#39;t-Your-Safe-Haven-Protocol-Analysis-And-Vulnerabilities-Of-Autonomic-Network.pdf&#34;&gt;https://www.blackhat.com/docs/us-17/wednesday/us-17-Eissa-Network-Automation-Isn’t-Your-Safe-Haven-Protocol-Analysis-And-Vulnerabilities-Of-Autonomic-Network.pdf&lt;/a&gt;&lt;br&gt;&#xA;insinuator blogposts:&lt;br&gt;&#xA;&lt;a href=&#34;https://insinuator.net/2017/03/autonomic-network-overview/&#34;&gt;https://insinuator.net/2017/03/autonomic-network-overview/&lt;/a&gt;&lt;br&gt;&#xA;&lt;a href=&#34;https://insinuator.net/2017/03/autonomic-network-analysis/&#34;&gt;https://insinuator.net/2017/03/autonomic-network-analysis/&lt;/a&gt;&lt;br&gt;&#xA;&lt;a href=&#34;https://insinuator.net/2017/04/autonomic-network-vulnerabilities/&#34;&gt;https://insinuator.net/2017/04/autonomic-network-vulnerabilities/&lt;/a&gt;&lt;/p&gt;&#xA;&lt;p&gt; &lt;/p&gt;&#xA;&lt;p&gt;BoradPWN&lt;br&gt;&#xA;– Speaker: Nitay Artenstein&lt;br&gt;&#xA;– Slides: &lt;a href=&#34;https://www.blackhat.com/docs/us-17/thursday/us-17-Artenstein-Broadpwn-Remotely-Compromising-Android-And-iOS-Via-A-Bug-In-Broadcoms-Wifi-Chipsets.pdf&#34;&gt;https://www.blackhat.com/docs/us-17/thursday/us-17-Artenstein-Broadpwn-Remotely-Compromising-Android-And-iOS-Via-A-Bug-In-Broadcoms-Wifi-Chipsets.pdf&lt;/a&gt;&lt;br&gt;&#xA;– Paper: &lt;a href=&#34;https://www.blackhat.com/docs/us-17/thursday/us-17-Artenstein-Broadpwn-Remotely-Compromising-Android-And-iOS-Via-A-Bug-In-Broadcoms-Wifi-Chipsets-wp.pdf&#34;&gt;https://www.blackhat.com/docs/us-17/thursday/us-17-Artenstein-Broadpwn-Remotely-Compromising-Android-And-iOS-Via-A-Bug-In-Broadcoms-Wifi-Chipsets-wp.pdf&lt;/a&gt;&lt;br&gt;&#xA;– Broadly covered in main stream Media –&amp;gt; Wired article, tons of write-ups…link: &lt;a href=&#34;https://www.wired.com/story/broadpwn-wi-fi-vulnerability-ios-android/&#34;&gt;https://www.wired.com/story/broadpwn-wi-fi-vulnerability-ios-android/&lt;/a&gt;&lt;br&gt;&#xA;– Initial Blog Post: &lt;a href=&#34;https://blog.exodusintel.com/2017/07/26/broadpwn/&#34;&gt;https://blog.exodusintel.com/2017/07/26/broadpwn/&lt;/a&gt;&lt;br&gt;&#xA;– He took a deep dive into the internals of the BCM4354, 4358 and 4359 Wi-Fi chipsets and found an issue that he exploited to an extent where he created the world´s first wifi worm.&lt;br&gt;&#xA;– This hits most of the mobiles users pretty hard. Affected devices are for example: Samsung Galaxy from S3 through S8, inclusive All Samsung Notes3. Nexus 5, 6, 6X and 6P, All iPhones after iPhone 5&lt;br&gt;&#xA;– An infected device can be used to infect other mobile devices.&lt;br&gt;&#xA;– Luckily currently there is no malware that is actively exploiting this issue.&lt;/p&gt;</description>
    </item>
    <item>
      <title>17. Gulaschprogrammiernacht</title>
      <link>https://insinuator.net/2017/06/17.-gulaschprogrammiernacht/</link>
      <pubDate>Wed, 21 Jun 2017 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2017/06/17.-gulaschprogrammiernacht/</guid>
      <description>&lt;p&gt;Over one of the recent long weekends I attended the 17th “Gulaschprogrammiernacht”, or “GPN17” for short, in Karlsruhe, the largest CCC Event after the Chaos Communication Congress with roughly a thousand attendees. The name literally translates to “goulash programming night”, which makes about as much sense as the German version. Despite the name it lasted from Thursday to Sunday, had a much wider scope than just coding and offered various other (incl. vegan) dishes besides goulash. As an active member of the CCC community I planned on attending it anyway, but submitted my talk about Automated Binary Analysis in case there was interest. I didn’t anticipate that much interest given that it was a fairly theoretical IT-Security topic at an event that was not focused on IT-Security, but nonetheless the hall was filled with people from various backgrounds like math, formal verification and software optimization. The talk was an improved version of the one I gave at &lt;a href=&#34;https://insinuator.net/2017/03/csa-summit-cee-and-bsides-ljubljana-2017/&#34;&gt;Bsides Ljubljana&lt;/a&gt;, incorporating feedback I received and new things I had learned since then. The English slides are available &lt;a href=&#34;https://entropia.de/images/b/bb/Binary-analysis-v2.2.pdf&#34;&gt;here&lt;/a&gt;, the recording of the talk in German can be found &lt;a href=&#34;https://media.ccc.de/v/gpn17-8585-introduction_to_automated_binary_analysis&#34;&gt;here&lt;/a&gt;.&lt;/p&gt;</description>
    </item>
    <item>
      <title>DevOps, Continuous Deployment &amp; Agile Security September 7, 2017</title>
      <link>https://insinuator.net/2017/06/devops-continuous-deployment-agile-security-september-7-2017/</link>
      <pubDate>Thu, 08 Jun 2017 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2017/06/devops-continuous-deployment-agile-security-september-7-2017/</guid>
      <description>&lt;p&gt;&lt;em&gt;The following post is in German as it is covering an Event with German as the main language.&lt;/em&gt;&lt;/p&gt;&#xA;&lt;hr&gt;&#xA;&lt;p&gt;&lt;strong&gt;INSIGHT SUMMIT 2017 präsentiert DevOps, Continuous Deployment &amp;amp; Agile Security&lt;/strong&gt;&lt;/p&gt;&#xA;&lt;p&gt;Inspiriert durch die erfolgreichen Round Table Session der TROOPERS freuen wir uns Ihnen heute mit dem AgileSecurity Insight Summit 2017 eine weitere Veranstaltung in einer Reihe zu Trend-Themen im Bereich der IT-Sicherheit vorzustellen.&lt;/p&gt;&#xA;&lt;p&gt;Die Veranstaltung beginnt am Morgen mit einer Keynote, gefolgt von Fallstudien und Vorträgen durch interne und externe Referenten aus der Industrie. Im Anschluss werden alle Teilnehmer in zwei Gruppen aufgeteilt, die nacheinander an beiden Round-Table Sessions teilnehmen. In den Round-Table Sessions werden unter Expertenmoderation typische Problemstellungen und Lösungsansätze diskutiert.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Docker Security &amp; (Sec) DevOps Training July 19-20th</title>
      <link>https://insinuator.net/2017/06/docker-security-sec-devops-training-july-19-20th/</link>
      <pubDate>Mon, 05 Jun 2017 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2017/06/docker-security-sec-devops-training-july-19-20th/</guid>
      <description>&lt;p&gt;&lt;em&gt;The following post is in German as it is covering a Training with German as the main language.&lt;/em&gt;&lt;/p&gt;&#xA;&lt;hr&gt;&#xA;&lt;p&gt;&lt;strong&gt;Professionelles Training im Workshop Character:&lt;/strong&gt;&lt;br&gt;&#xA;Docker, Microservices, Kubernetes, DevOps, Continuous&lt;br&gt;&#xA;Integration/Deployment/Delivery (CI/CD), Container – moderne&lt;br&gt;&#xA;Entwicklungsprozesse kommen nicht mehr ohne diese Begriffe aus. In diesem Kurs&lt;br&gt;&#xA;lernen Sie die Security Grundlagen um diese Dinge zu beherschen.&lt;/p&gt;&#xA;&lt;p&gt;&lt;strong&gt;Docker Security &amp;amp; (Sec) DevOps Training:&lt;/strong&gt;&lt;br&gt;&#xA;Im Training werden unter Anderem die folgenden Fragestellungen behandelt:&lt;/p&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;Wie stark/zuverlässig sind die Isolationsmechanismen hinter Docker/Linux/Betriebssystem-Containern?&lt;/li&gt;&#xA;&lt;li&gt;Wie beeinflussen Container typische Applikations- und Netzwerk-Landschaften?&lt;/li&gt;&#xA;&lt;li&gt;Wie beeinflussen die CI/CD/Microservice Paradigmen traditionelle Entwicklungsprozesse?&lt;/li&gt;&#xA;&lt;li&gt;Wie sieht eine typische CI/CD Pipeline aus?&lt;/li&gt;&#xA;&lt;li&gt;Was sind potentielle Schnittstellen zwischen „Security“ und diesen Paradigmen?&lt;/li&gt;&#xA;&lt;li&gt;Welche zusätzlichen Security-Herausforderungen ergeben sich aus der veränderten Entwicklungslandschaft und neuen Tool-Chains?&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;p&gt;&lt;strong&gt;Voraussetzungen:&lt;/strong&gt;&lt;br&gt;&#xA;Die Teilnehmer sollten grundlegende Kenntnisse der Linux Kommandozeile besitzen&lt;br&gt;&#xA;sowie ein System mit einem SSH Client. Teilnehmer die die Demo-VM gerne selbst&lt;br&gt;&#xA;betreiben möchten erhalten diese auf einem USB-Stick, müssen sich aber selbst um&lt;br&gt;&#xA;Import und Start kümmern.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Active Directory Security &amp; Secure Operations July 18, 2017</title>
      <link>https://insinuator.net/2017/06/active-directory-security-secure-operations-july-18-2017/</link>
      <pubDate>Thu, 01 Jun 2017 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2017/06/active-directory-security-secure-operations-july-18-2017/</guid>
      <description>&lt;p&gt;&lt;em&gt;The following post is in German as it is covering an Event with German as the main language.&lt;/em&gt;&lt;/p&gt;&#xA;&lt;hr&gt;&#xA;&lt;p&gt;&lt;strong&gt;INSIGHT SUMMIT 2017 präsentiert Active Directory Security &amp;amp; Secure Operations&lt;/strong&gt;&lt;/p&gt;&#xA;&lt;p&gt;Inspiriert durch die erfolgreichen Round Table Sessions der TROOPERS freuen wir uns Ihnen heute mit dem Active Directory Insight Summit 2017 eine weitere Veranstaltung in einer Reihe zu Trend-Themen im Bereich der IT-Sicherheit vorzustellen.&lt;br&gt;&#xA;Die Veranstaltung beginnt am Morgen mit einer Hinführung zum Thema Active Directory Sicherheit gefolgt von Fallstudien und Vorträgen durch interne und externe Referenten aus Wirtschaft und Industrie. Im Anschluss werden alle Teilnehmer in zwei Gruppen aufgeteilt, die nacheinander an beiden Round Table Sessions teilnehmen (jeder Teilnehmer kann an beiden Sessions teilnehmen). In den Round Table Sessions werden unter Expertenmoderation typische Problemstellungen und Lösungsansätze diskutiert.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Looking back on RIPE 74</title>
      <link>https://insinuator.net/2017/05/looking-back-on-ripe-74/</link>
      <pubDate>Fri, 19 May 2017 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2017/05/looking-back-on-ripe-74/</guid>
      <description>&lt;p&gt;From May 8th to 12th I was able to attend the 74th RIPE meeting in Budapest, Hungary. Being rather new to the networking community, I enjoyed learning a lot of different things, not only from the various interesting talks but also from inspiring conversations with a variety of people from all areas during the beautiful social events.&lt;/p&gt;&#xA;&lt;p&gt;As it was the first RIPE meeting for me, I was very thankful for the “Newcomer’s Introduction” on Monday morning, containing a RIPE and RIPE NCC 101. It was quite helpful to get into the mindset and understand the structure of the meeting, like the division into different working groups based on the participants’ interests. After familiarizing myself with the concept, I chose to attend several sessions on Address Policy, IPv6, Routing, Open Source, and DNS working groups besides the general plenary sessions. I’ll be reviewing those sessions here.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Some Quick Tips for Submitting a Talk to Black Hat or TROOPERS</title>
      <link>https://insinuator.net/2017/04/some-quick-tips-for-submitting-a-talk-to-black-hat-or-troopers/</link>
      <pubDate>Sat, 01 Apr 2017 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2017/04/some-quick-tips-for-submitting-a-talk-to-black-hat-or-troopers/</guid>
      <description>&lt;p&gt;Given the &lt;a href=&#34;https://www.blackhat.com/us-17/call-for-papers.html&#34;&gt;CfP for Black Hat US&lt;/a&gt; in Vegas ends in a few days – and as apparently &lt;a href=&#34;https://twitter.com/HashtagCyber/status/846093463120678913&#34;&gt;some&lt;/a&gt; &lt;a href=&#34;https://twitter.com/christruncer/status/845213468269662209&#34;&gt;people&lt;/a&gt; have already started to think about their TR18 submissions – I’ll quickly provide some loose recommendations on how to write a submission here. There’s quite some reasonable advice out there already (the BH CfP site lists &lt;a href=&#34;https://www.helpnetsecurity.com/2016/03/30/how-to-get-your-talk-accepted-at-black-hat/&#34;&gt;this&lt;/a&gt; and &lt;a href=&#34;http://hexsec.blogspot.de/2012/12/create-good-security-cfp-responses.html&#34;&gt;this&lt;/a&gt; which you should both read as well) but some of you might find it useful to get (yet) another perspective.&lt;/p&gt;</description>
    </item>
    <item>
      <title>CSA Summit CEE and BSides Ljubljana 2017</title>
      <link>https://insinuator.net/2017/03/csa-summit-cee-and-bsides-ljubljana-2017/</link>
      <pubDate>Fri, 17 Mar 2017 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2017/03/csa-summit-cee-and-bsides-ljubljana-2017/</guid>
      <description>&lt;p&gt;At the end of last week I had the pleasure to visit the &lt;a href=&#34;https://csa-cee-summit.eu/&#34;&gt;CSA Summit CEE&lt;/a&gt; and the &lt;a href=&#34;https://bsidesljubljana.si/&#34;&gt;Bsides Event in Ljubljana&lt;/a&gt;.&lt;/p&gt;&#xA;&lt;p&gt;At CSA, I was talking about hypervisors, breakouts and an overview of security measures to protect the host. (&lt;a href=&#34;https://csa-cee-summit.eu/florian-magin/&#34;&gt;Slides&lt;/a&gt;)&lt;br&gt;&#xA;This ranged from the basic features some hypervisors provide out of the box to advanced features like SELinux, device domain models and XSM-FLASK.&lt;/p&gt;&#xA;&lt;p&gt;Most of the other talks were more targeted towards management level employees, but even as a fairly technical person I found Mike Bursell’s &lt;a href=&#34;https://csa-cee-summit.eu/mike-bursell/&#34;&gt;talk&lt;/a&gt;  highly interesting. After my talk about securing the host system from a malicious guest, he dealt with the inverse: Technologies to protect a guest from a malicious or compromised host.&lt;/p&gt;</description>
    </item>
    <item>
      <title>31c0n 2017 in Auckland, New Zealand</title>
      <link>https://insinuator.net/2017/03/31c0n-2017-in-auckland-new-zealand/</link>
      <pubDate>Fri, 03 Mar 2017 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2017/03/31c0n-2017-in-auckland-new-zealand/</guid>
      <description>&lt;p&gt;Last week we gave a talk at the very first &lt;a href=&#34;https://www.31c0n.co.nz/&#34;&gt;31c0n&lt;/a&gt; in Auckland, New Zealand. The talk focused mainly on the methodology that we use to assess security products.&lt;/p&gt;&#xA;&lt;p&gt;More specifically, this methodology consists of 7 steps&lt;/p&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;Literature Research&lt;/li&gt;&#xA;&lt;li&gt;Jailbreak the Target&lt;/li&gt;&#xA;&lt;li&gt;Identify Components&lt;/li&gt;&#xA;&lt;li&gt;Understand the Architecture&lt;/li&gt;&#xA;&lt;li&gt;Map the Attack Surface&lt;/li&gt;&#xA;&lt;li&gt;Prioritize&lt;/li&gt;&#xA;&lt;li&gt;Analyze.&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;p&gt;Details on these steps as well as general suggestions to viable alternatives for security products can be found &lt;a href=&#34;https://www.ernw.de/download/31c0n_2017_sec_appliances.pdf&#34;&gt;here&lt;/a&gt; in the slides.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Troopers17 GSM Network – How about your own SMPP Service?</title>
      <link>https://insinuator.net/2017/03/troopers17-gsm-network-how-about-your-own-smpp-service/</link>
      <pubDate>Wed, 01 Mar 2017 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2017/03/troopers17-gsm-network-how-about-your-own-smpp-service/</guid>
      <description>&lt;p&gt;The event of the events is getting closer and again, we are very optimistic to have a lot of awesome &lt;a href=&#34;https://www.troopers.de/&#34;&gt;trainings, talks, evening events&lt;/a&gt;, and discussions. But we again will also have some “features” and gimmicks for those of you who would like to play with new, old, or just interesting technologies. As you might remember, since some years one of these features is and again will be our own GSM Network. As we are improving &lt;a href=&#34;https://insinuator.net/2016/03/troopers16-gsm-network-2/&#34;&gt;our setup&lt;/a&gt; from year to year, this time we’d like to give you the chance to actively participate with ideas and your own services.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Summary of “Lockpicking in the IoT” at 33C3</title>
      <link>https://insinuator.net/2017/02/summary-of-lockpicking-in-the-iot-at-33c3/</link>
      <pubDate>Tue, 14 Feb 2017 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2017/02/summary-of-lockpicking-in-the-iot-at-33c3/</guid>
      <description>&lt;p&gt;“Lockpicking in the IoT, …or why adding BTLE to a device sometimes isn’t smart at all” by Ray was one of my favourite talks, as it beautifully showed many different attack vectors as well as giving a nice guide for getting started in this area.&lt;/p&gt;&#xA;&lt;p&gt;It impressed me how carefree vendors and startups handled hardware and software security in “smart” devices as it seems that their devices were more or less easy to own. In his talk Ray pointed out physical AND implementational weaknesses that remained even after he reported them to the vendors.&lt;br&gt;&#xA;The most prominent sample he gave was when he opened a “Masterlock” by spinning a magnet on the lock itself to open it.&lt;/p&gt;</description>
    </item>
    <item>
      <title>33c3 Talks – What could possibly go wrong with “insert x86 instruction here” ?</title>
      <link>https://insinuator.net/2017/02/33c3-talks-what-could-possibly-go-wrong-with-insert-x86-instruction-here/</link>
      <pubDate>Wed, 01 Feb 2017 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2017/02/33c3-talks-what-could-possibly-go-wrong-with-insert-x86-instruction-here/</guid>
      <description>&lt;p&gt;&lt;a href=&#34;https://media.ccc.de/v/33c3-8044-what_could_possibly_go_wrong_with_insert_x86_instruction_here&#34;&gt;This&lt;/a&gt; was one of the few technical talks at 33c3 I managed to see, by that I mean live-stream during an access control shift, by Clémentine Maurice and Moritz Lipp.&lt;/p&gt;&#xA;&lt;p&gt;The talk gave an overview of some already known possible information leaks by abusing certain x86 instructions(the same concept applies to ARM too though) and demonstrating the various ways an attacker could use them. They started off by quickly explaining how the caches on modern CPUs are set up and how they work and how you can exploit the timing differences in memory accesses to leak data without actually knowing the content of the cache. This data leak can then be used to establish a covert channel.&lt;/p&gt;</description>
    </item>
    <item>
      <title>ERNW at 33C3 – Part 1</title>
      <link>https://insinuator.net/2017/01/ernw-at-33c3-part-1/</link>
      <pubDate>Thu, 26 Jan 2017 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2017/01/ernw-at-33c3-part-1/</guid>
      <description>&lt;p&gt;This is &lt;strong&gt;part 1&lt;/strong&gt; of our report series on &lt;strong&gt;interesting talks of the 33rd Congress&lt;/strong&gt; of the Chaos Computer Club. Every year the congress attracts hundreds (up to twelve thousand this year) of technical interested people with the opportunity to socialize and exchange knowledge with each other. The congress is organized by the European largest hacker association and speakers give talks about technical and societal issues like surveillance, privacy, freedom of information, data security and various more.&lt;/p&gt;</description>
    </item>
    <item>
      <title>TR17 Training: Hacking 101</title>
      <link>https://insinuator.net/2017/01/tr17-training-hacking-101/</link>
      <pubDate>Thu, 26 Jan 2017 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2017/01/tr17-training-hacking-101/</guid>
      <description>&lt;p&gt;Hi there,&lt;br&gt;&#xA;Like in recent years the popular &lt;a href=&#34;https://www.troopers.de/events/troopers17/735_hacking_101/&#34;&gt;Hacking 101 workshop&lt;/a&gt; will take place on TROOPERS17, too! The workshop will give attendees an insight into the &lt;strong&gt;hacking techniques&lt;/strong&gt; required for &lt;strong&gt;penetration testing&lt;/strong&gt;. These techniques will cover various topics:&lt;/p&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;information gathering&lt;/li&gt;&#xA;&lt;li&gt;network scanning&lt;/li&gt;&#xA;&lt;li&gt;web application hacking&lt;/li&gt;&#xA;&lt;li&gt;low-level exploitation&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;p&gt;…and more!&lt;/p&gt;&#xA;&lt;p&gt;During this workshop &lt;strong&gt;you will learn&lt;/strong&gt;, step by step, a &lt;strong&gt;testing methodology&lt;/strong&gt; that is applicable to the majority of scenarios. So imagine you have to &lt;strong&gt;assess&lt;/strong&gt; the &lt;strong&gt;security of a system&lt;/strong&gt; running on the Internet. How would you start? First, you need a good understanding about the target, including running services or related systems. Just &lt;strong&gt;scanning&lt;/strong&gt; an IP will most likely not reveal a lot of information about the system. The gathered information may help you to identify communication relations of services that could include vulnerabilities. A brief understanding of the target and it’s related systems/services/applications will make scanning and &lt;strong&gt;identifying vulnerabilities&lt;/strong&gt; a lot easier and more effective. Then, the last step will be the &lt;strong&gt;exploitation&lt;/strong&gt; of the identified vulnerabilities, with the ultimate aim to &lt;strong&gt;get access to the target system&lt;/strong&gt; and pivot to other, probably internal, systems and resources.&lt;/p&gt;</description>
    </item>
    <item>
      <title>First dedicated Forensic Computing Training at TR17</title>
      <link>https://insinuator.net/2017/01/first-dedicated-forensic-computing-training-at-tr17/</link>
      <pubDate>Wed, 11 Jan 2017 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2017/01/first-dedicated-forensic-computing-training-at-tr17/</guid>
      <description>&lt;p&gt;I am looking forward to our newly introduced dedicated Forensic Computing Training at TR17!&lt;br&gt;&#xA;We will start the first day with a detailed background briefing about Forensic Computing as a Forensic Science, Digital Evidence, and the Chain of Custody. The rest of the workshop we will follow the Order of Volatility starting with the analysis of persistent storage using file system internals and carving, as well as RAID reassembly with lots of hands-on case studies using open source tools. As a next step, we will smell the smoking gun in live forensics exercises. Depending on your preferences we will then dig a bit into memory forensics and network forensics.&lt;/p&gt;</description>
    </item>
    <item>
      <title>TelcoSecDay 2017 – 2nd Round of Talks</title>
      <link>https://insinuator.net/2017/01/telcosecday-2017-2nd-round-of-talks/</link>
      <pubDate>Tue, 03 Jan 2017 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2017/01/telcosecday-2017-2nd-round-of-talks/</guid>
      <description>&lt;p&gt;Hello and a Happy new Year!&lt;/p&gt;&#xA;&lt;p&gt;There are only two and a half months left, so I’d like to publish the next two talks for &lt;a href=&#34;https://www.troopers.de/troopers17/telcosec-day/&#34;&gt;TelcoSecDay 2017&lt;/a&gt;, taking place at 21st of March in Heidelberg. Both talks are about the security of an upcoming technology which importance will raise in near future: 5G Networks.&lt;/p&gt;&#xA;&lt;p&gt;One of the talks will be from an attacker’s point of view, highlighting weaknesses of 2G/3G/4G networks and what we have to fix in 5G, and the other one will give us insights into current developments of the 3GPP standardization group.&lt;/p&gt;</description>
    </item>
    <item>
      <title>TR17 Training: Crypto attacks and defenses</title>
      <link>https://insinuator.net/2017/01/tr17-training-crypto-attacks-and-defenses/</link>
      <pubDate>Tue, 03 Jan 2017 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2017/01/tr17-training-crypto-attacks-and-defenses/</guid>
      <description>&lt;p&gt;This is a guest blog written by &lt;a href=&#34;https://www.troopers.de/events/speaker/557_jean-philippe_aumasson/&#34;&gt;Jean-Philippe Aumasson&lt;/a&gt; &amp;amp; &lt;a href=&#34;https://www.troopers.de/events/speaker/978_philipp__jovanovic/&#34;&gt;Philipp Jovanovic&lt;/a&gt; about their upcoming TROOPERS17 training: &lt;a href=&#34;https://www.troopers.de/events/troopers17/725_crypto_attacks_and_defenses/&#34;&gt;Crypto attacks and defenses. &lt;/a&gt;&lt;/p&gt;&#xA;&lt;p&gt;The &lt;a href=&#34;https://www.troopers.de/events/troopers16/578_crypto_for_developers/&#34;&gt;1-day training from last TROOPERS&lt;/a&gt; has become a 2-day training, featuring even more real-world attacks and defenses as well as new hands-on sessions! We’ll teach you, step by step, how to spot and exploit crypto vulnerabilities, how to use the strongest forms of state-of-the-art cryptography to secure modern systems (like IoT or mobile applications), and bring you up to speed on the latest and greatest developments in the world of cryptography, such as TLS 1.3, blockchains, and post-quantum crypto.&lt;/p&gt;</description>
    </item>
    <item>
      <title>3rd Round of TROOPERS17 Talks</title>
      <link>https://insinuator.net/2016/12/3rd-round-of-troopers17-talks/</link>
      <pubDate>Tue, 20 Dec 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/12/3rd-round-of-troopers17-talks/</guid>
      <description>&lt;p&gt;We had to make some tough choices regarding our &lt;a href=&#34;http://troopers.de&#34;&gt;TROOPERS17&lt;/a&gt; Main Conference Agenda. Thank you again to everyone for submitting! The full agenda will be published later this week, but for now here are the next round of talks!&lt;/p&gt;&#xA;&lt;p&gt;Ivan Pepelnjak: &lt;em&gt;Securing Network Automation&lt;/em&gt;&lt;br&gt;&#xA;If you have operational experience in running large networks then you’re probably yearning to replace the traditional way of managing individual network devices via SSH with something better and more reliable. Software Defined Networking (SDN) was touted as the all-encompassing solution, but what we got instead is a heap of academic ideas, several platforms that require as much investment as an SAP deployment, and a bunch of proprietary products focused more on increasing lock-in and vendor revenue than solving operational problems.&lt;/p&gt;</description>
    </item>
    <item>
      <title>PoC Con Seoul 2016</title>
      <link>https://insinuator.net/2016/12/poc-con-seoul-2016/</link>
      <pubDate>Thu, 15 Dec 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/12/poc-con-seoul-2016/</guid>
      <description>&lt;p&gt;Recently I had the pleasure to join the &lt;a href=&#34;http://www.powerofcommunity.net/&#34;&gt;PowerOfCommunity&lt;/a&gt; conference in Seoul. Florian and Felix attended the conference in the past and enjoyed it a lot, so I took the opportunity to join this year. From what I had heard the conference is highly technical, offensive security and community focused (surprise 😉 ). Boy did they deliver!&lt;br&gt;&#xA;Located in a hotel next to a nice park and close to the famous Gangnam district in Seoul we came together to feel the power of community. The conference was planned for two days and offered two tracks per day. Several key talks were presented for everyone.&lt;br&gt;&#xA;I really liked the topics a lot. Some contributions I found particularly interesting were:&lt;br&gt;&#xA;Petr Švenda with “The Million-Key Question – How RSA Public Key Leaks Its Origin”, where he presented his research of fingerprinting RSA public keys. By analyzing the RSA keys from smartcards and software sources he was able to find similarities between them, which allowed fingerprinting the generating source for some cases. With this information it could be possible gather some potentially important details from simple keys. He is currently expanding his work, please send him an E-Mail if you have RSA keys from an exotic resource. 😉&lt;/p&gt;</description>
    </item>
    <item>
      <title>TR17 Training: Fuzzing with American Fuzzy Lop, Address Sanitizer and LibFuzzer</title>
      <link>https://insinuator.net/2016/12/tr17-training-fuzzing-with-american-fuzzy-lop-address-sanitizer-and-libfuzzer/</link>
      <pubDate>Thu, 15 Dec 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/12/tr17-training-fuzzing-with-american-fuzzy-lop-address-sanitizer-and-libfuzzer/</guid>
      <description>&lt;p&gt;This is a guest blog written by &lt;a href=&#34;https://hboeck.de/&#34;&gt;Hanno Böck&lt;/a&gt; who will be running the &lt;a href=&#34;https://www.troopers.de/events/troopers17/737_fuzzing_with_american_fuzzy_lop_address_sanitizer_and_libfuzzer/&#34;&gt;Fuzzing with American Fuzzy Lop, Address Sanitizer and LibFuzzer&lt;/a&gt; at TROOPERS17.&lt;/p&gt;&#xA;&lt;p&gt;Fuzzing is a very old technique to find bugs and vulnerabilities in software. However it has seen a new push in recent years due to vastly improved tools. The compilers gcc and clang have received Sanitizer tools that allow finding a lot of bugs like use after free errors and out of bounds reads that are otherwise very hard to find.&lt;/p&gt;</description>
    </item>
    <item>
      <title>2nd Rounds of TROOPERS17 Talks!</title>
      <link>https://insinuator.net/2016/12/2nd-rounds-of-troopers17-talks/</link>
      <pubDate>Wed, 14 Dec 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/12/2nd-rounds-of-troopers17-talks/</guid>
      <description>&lt;p&gt;It is the end of the year and we are hoping it is not too hectic of a time for you all! But if it is, hopefully the announcement of our next round of &lt;a href=&#34;http://troopers.de&#34;&gt;TROOPERS17&lt;/a&gt; talks is enough to get you in the TROOPERS (if not the holiday) spirit 🙂&lt;/p&gt;&#xA;&lt;hr&gt;&#xA;&lt;p&gt;Francis Alexander &amp;amp; Bharadwaj Machiraju: &lt;em&gt;How we hacked Distributed Configuration Management Systems&lt;/em&gt;&lt;/p&gt;&#xA;&lt;p&gt;With increase in necessity of distributed applications, coordination and configuration management tools for these classes of applications have popped up. These systems might pop-up occasionally during penetration tests. The major focus of this research was to find ways to abuse these systems as well as use them for getting deeper access to other systems.&lt;/p&gt;</description>
    </item>
    <item>
      <title>TelcoSecDay 2017 – First Talks Published</title>
      <link>https://insinuator.net/2016/12/telcosecday-2017-first-talks-published/</link>
      <pubDate>Thu, 08 Dec 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/12/telcosecday-2017-first-talks-published/</guid>
      <description>&lt;p&gt;Even if the CFP for TelcoSecDay 2017 is officially closed, I am still getting mails in. First of all: thank you for all your great feedback! As the TelcoSecDay is a complimentary and non-public event with highly specialized topics, it only works by sharing knowledge with each other. But please keep in mind that the speaker-slots are limited and I have to make a decision at some point of time.&lt;br&gt;&#xA;Anyhow, I am looking forward for a great event and I am proud to publish the first accepted talks:&lt;/p&gt;</description>
    </item>
    <item>
      <title>Defending Democracy</title>
      <link>https://insinuator.net/2016/11/defending-democracy/</link>
      <pubDate>Thu, 24 Nov 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/11/defending-democracy/</guid>
      <description>&lt;p&gt;I recently had the pleasure to attend two events organized by the &lt;a href=&#34;https://www.esmt.org/faculty-research/centers-chairs-and-institutes/digital-society-institute-dsi&#34;&gt;Digital Society Institute&lt;/a&gt;, one was a &lt;a href=&#34;https://www.esmt.org/node/26449&#34;&gt;workshop on software vulnerabilities&lt;/a&gt; and one was their annual &lt;a href=&#34;https://www.esmt.org/faculty-research/events/conferences-and-workshops/digital-society-conference-2016-defending&#34;&gt;conference&lt;/a&gt;. For both events I delivered input on the security of security products and their evaluation (slides can be found &lt;a href=&#34;https://www.ernw.de/download/ERNWResearch_CritivalViewOnSecProducts_mluft.pdf&#34;&gt;here&lt;/a&gt;). The DSI did a great job of assembling people from various areas (e.g. industry, academia, politics, and research) so there was a lot of input which is not covered by conferences I usually attend. The workshop I attended also resulted in a short policy recommendation when it comes to the security of security products which can be found &lt;a href=&#34;https://www.esmt.org/sites/default/files/2016_dsi_ipr_vulnerabilities-in-it-security-products.pdf&#34;&gt;here&lt;/a&gt;.&lt;/p&gt;</description>
    </item>
    <item>
      <title>CCS’16 – Day 2 – 25th October 2016</title>
      <link>https://insinuator.net/2016/11/ccs16-day-2-25th-october-2016/</link>
      <pubDate>Wed, 23 Nov 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/11/ccs16-day-2-25th-october-2016/</guid>
      <description>&lt;p&gt;Hello again.&lt;/p&gt;&#xA;&lt;p&gt;Andrei Costin (at &lt;a href=&#34;http://firmware.re/&#34;&gt;http://firmware.re&lt;/a&gt; project) is here, and this is the second post from a series of guest postings courtesy of ERNW (thanks Niki and Enno!).&lt;/p&gt;&#xA;&lt;p&gt;Few days ago, the first CCS’16 summarization post went online: &lt;a href=&#34;https://insinuator.net/2016/11/introduction-ccs16-day-1-24th-october-2016/&#34;&gt;https://insinuator.net/2016/11/introduction-ccs16-day-1-24th-october-2016/&lt;/a&gt;&lt;/p&gt;&#xA;&lt;p&gt;It summarized five presentations of the 6th Annual Workshop on Security and Privacy in Smartphones (SPSM’16). In short, it contained presentations on: over-the-top and phone number abuse, smartphone fingerprinting, apps privacy increase and protection/security, and apps privacy ranking.&lt;/p&gt;</description>
    </item>
    <item>
      <title>BlackHoodie 2016</title>
      <link>https://insinuator.net/2016/11/blackhoodie-2016/</link>
      <pubDate>Mon, 21 Nov 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/11/blackhoodie-2016/</guid>
      <description>&lt;p&gt;This year’s &lt;a href=&#34;http://0x1338.blogspot.de/2016/06/that-thing-with-rocking-harder-and.html&#34;&gt;BlackHoodie&lt;/a&gt; workshop rolled out with 28 amazing women from all parts of the world. It was a very vibrant group with students, professionals, engineers, researchers, physicists and what not. This is the second year that &lt;a href=&#34;https://twitter.com/pinkflawd&#34;&gt;Marion Marschalek&lt;/a&gt; is running this reverse engineering workshop exclusively for women. There were a variety of topics that were covered. This includes anti emulation tricks, anti debuggers, packers, obfuscation, encryption/decryption functions, and a lot of fun with IDA.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Introduction &amp; CCS’16 – Day 1 – 24th October 2016</title>
      <link>https://insinuator.net/2016/11/introduction-ccs16-day-1-24th-october-2016/</link>
      <pubDate>Mon, 21 Nov 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/11/introduction-ccs16-day-1-24th-october-2016/</guid>
      <description>&lt;p&gt; I am Andrei Costin (at &lt;a href=&#34;http://firmware.re/&#34;&gt;http://firmware.re&lt;/a&gt; project), and this is the first post from a series of guest postings courtesy of ERNW.&lt;/p&gt;&#xA;&lt;p&gt;Between 24th and 28th October, I had the pleasure and the great opportunity to attend ACM CCS 2016 in Vienna, Austria, where I also presented at the TrustED’16 workshop my paper titled “&lt;a href=&#34;http://dl.acm.org/citation.cfm?id=2995290&#34;&gt;Security of CCTV and Video Surveillance Systems: Threats, Vulnerabilities, Attacks, and Mitigations&lt;/a&gt;”.&lt;/p&gt;&#xA;&lt;p&gt;My attendance throughout the entire ACM CCS 2016 week and my presentation at TrustED was possible thanks to generous support from Enno Rey and ERNW, and I thank them again for this opportunity!&lt;/p&gt;</description>
    </item>
    <item>
      <title>15. Cyber-Sicherheits-Tag</title>
      <link>https://insinuator.net/2016/11/15.-cyber-sicherheits-tag/</link>
      <pubDate>Tue, 08 Nov 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/11/15.-cyber-sicherheits-tag/</guid>
      <description>&lt;p&gt;Today Kevin and I had the pleasure to to present at the German &lt;a href=&#34;https://www.allianz-fuer-cybersicherheit.de/ACS/DE/Erfahrungsaustausch/CST/cur/cst.html&#34;&gt;15. Cyber-Sicherheits-Tag&lt;/a&gt; in &lt;a href=&#34;https://en.wikipedia.org/wiki/Project_Blinkenlights&#34;&gt;Berlin&lt;/a&gt; which is organized by the &lt;a href=&#34;https://www.allianz-fuer-cybersicherheit.de/ACS/DE/Home/startseite.html&#34;&gt;Alliance for Cyber Security&lt;/a&gt;. This iteration covered security aspects of the Internet of Things and we enjoyed some great conversations. The presentations were limited to ten slides and can be found here:&lt;/p&gt;&#xA;&lt;p&gt;&lt;a href=&#34;https://www.ernw.de/download/ERNW_Defense_in_Depth_IoT_kschaller.pdf&#34;&gt;Kevin Schaller – Defense in Depth in IoT&lt;/a&gt;&lt;/p&gt;&#xA;&lt;p&gt;&lt;a href=&#34;https://www.ernw.de/download/ERNWResearch_UpdateManagementAndIoT_mluft.pdf&#34;&gt;Matthias Luft – Update Management in IoT&lt;/a&gt;&lt;/p&gt;&#xA;&lt;p&gt;Since the slides were supposed to be short and only support the presentation, you still have the chance to get the full content (and even challenge it or ask to dive deeper during the break-out discussions) next week at &lt;a href=&#34;https://www.troopers.de/iot-insight-summit-2016/iot-insight-summit-2016-overview/&#34;&gt;our own IoT event&lt;/a&gt; 😉&lt;/p&gt;</description>
    </item>
    <item>
      <title>ITSeCX 2016: Pulling an all-nighter in Austria</title>
      <link>https://insinuator.net/2016/11/itsecx-2016-pulling-an-all-nighter-in-austria/</link>
      <pubDate>Tue, 08 Nov 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/11/itsecx-2016-pulling-an-all-nighter-in-austria/</guid>
      <description>&lt;p&gt;Last Friday I gave a talk at the &lt;a href=&#34;https://itsecx.fhstp.ac.at/&#34;&gt;ITSeCX&lt;/a&gt; in St. Pölten, Austria. The conference, hosted by the local University of Applied Sciences, has already taken place ten times. I don’t know how many people attended this time, 2014 there were about 600; &lt;a href=&#34;http://www.computerwelt.at/news/technologie-strategie/security/detail/artikel/113099-it-secx-2015-eine-nacht-im-zeichen-der-it-security/&#34;&gt;I read somewhere on the net&lt;/a&gt;. There were four tracks and some workshops from 4pm to the conference’s end at midnight. I enjoyed the community-feeling there very much, even though I arrived late. The only talks I saw, were Adrian Dabrowski speaking about the DARPA Cyber Grand Challenge, the finals took part in Las Vegas this August, and the very entertaining end-of-year review from two UAS guys.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Announcing the first 5 talks of TROOPERS17!!!!</title>
      <link>https://insinuator.net/2016/11/announcing-the-first-5-talks-of-troopers17/</link>
      <pubDate>Fri, 04 Nov 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/11/announcing-the-first-5-talks-of-troopers17/</guid>
      <description>&lt;h2&gt;&lt;/h2&gt;&#xA;&lt;p&gt;&lt;a href=&#34;https://www.troopers.de/troopers16/&#34;&gt;TROOPERS16&lt;/a&gt; was packed with epic talks from around the world, an unknown evil twin brother appearing, hands-on trainings, and a legendary year for our TROOPERS Charity efforts! If you were there you might be wondering to yourself how could they possibly top it? Well, I am going to let you in on a little secret: Next year is the 10th edition of &lt;a href=&#34;https://www.troopers.de/troopers17/&#34;&gt;TROOPERS&lt;/a&gt;. One DECADE of TROOPERS, and we are pulling out all the stops! Starting with the announcement of the first 5 talks!&lt;/p&gt;</description>
    </item>
    <item>
      <title>TelcoSecDay 2017 – CFP Opens</title>
      <link>https://insinuator.net/2016/10/telcosecday-2017-cfp-opens/</link>
      <pubDate>Sat, 29 Oct 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/10/telcosecday-2017-cfp-opens/</guid>
      <description>&lt;p&gt;For the 6th year in a row, the next TelcoSecDay will take place in 2017 on March 21th. Again, it will be held one day before &lt;a href=&#34;http://www.troopers.de&#34;&gt;Troopers IT-Security Conference&lt;/a&gt; as an invitation-only event. For those of you who don’t know the TSD, it is organized by ERNW and is aimed at bringing researchers and people from the telecommunication industry together to discuss about current security weaknesses, challenges and strategies. To do so, various topics will be presented during the talks and there will surely be enough time to follow-up in extensive discussions.&lt;br&gt;&#xA;To give you an idea, here’s the &lt;a href=&#34;https://insinuator.net/2016/03/telcosecday-2016-final-agenda-and-more/&#34;&gt;TSD 2016 agenda&lt;/a&gt;, and here’s &lt;a href=&#34;https://insinuator.net/2015/03/final-agenda-of-troopers15-telcosecday/&#34;&gt;the one of 2015&lt;/a&gt;.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Day-Con X Recap</title>
      <link>https://insinuator.net/2016/10/day-con-x-recap/</link>
      <pubDate>Thu, 27 Oct 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/10/day-con-x-recap/</guid>
      <description>&lt;p&gt;Just a few days ago I had the pleasure of visiting &lt;a href=&#34;http://day-con.org/&#34;&gt;Day-Con X&lt;/a&gt;. I listened to some great talks in the closed and public sessions. Since the first day was the security summit (closed session) I will just name a few titles with some brief words.&lt;/p&gt;&#xA;&lt;p&gt;Captivating Security – Safety versus Passion (Josh More):&lt;br&gt;&#xA;Was quite interesting to compare the IT-World with zoos.&lt;/p&gt;&#xA;&lt;p&gt;Beyond Embedded (Brittany Postnikoff):&lt;br&gt;&#xA;Robots are fun soon :).&lt;/p&gt;</description>
    </item>
    <item>
      <title>IoT Insight Summit November 15, 2016</title>
      <link>https://insinuator.net/2016/10/iot-insight-summit-november-15-2016/</link>
      <pubDate>Wed, 26 Oct 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/10/iot-insight-summit-november-15-2016/</guid>
      <description>&lt;p&gt;The newest addition to ERNW, ERNW Insight which now hosts &lt;a href=&#34;https://www.troopers.de/troopers17/&#34;&gt;TROOPERS&lt;/a&gt;, is launching a new concept this year. Based on the successful TROOPERS Roundtable sessions, ERNW Insight will host a series events every year covering current and relevant topics in the field of IT Security. While the style of the events may vary the in-depth knowledge sharing that you have come to know from TROOPERS will not!&lt;/p&gt;&#xA;&lt;p&gt;The inaugural event will be our&lt;a href=&#34;https://www.troopers.de/iot-insight-summit-2016/iot-insight-summit-2016-overview/&#34;&gt; IoT Insight Summit&lt;/a&gt;, taking place on November 15, 2016 at the &lt;a href=&#34;https://www.ihg.com/crowneplaza/hotels/us/en/heidelberg/hdbge/hoteldetail&#34;&gt;Crowne Plaza Heidelberg&lt;/a&gt;.  This 1-day event will begin with a keynote and case study from industry experts.  Afterwards, all participants will be divided into five groups of 10 persons each to participate in our “Break Out Sessions”. Every participant  will get the opportunity to attend all 5 Break Out Sessions, where our IT Security moderators will lead discussions on typical problems and solutions in IoT.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Black Hat 2016 Summary Part 2.1</title>
      <link>https://insinuator.net/2016/10/black-hat-2016-summary-part-2.1/</link>
      <pubDate>Thu, 06 Oct 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/10/black-hat-2016-summary-part-2.1/</guid>
      <description>&lt;p&gt;A few months ago I had the opportunity to visit this year’s Black Hat in Las Vegas. Due to a few weeks of vacation following the conference here are my delayed 2 cents (part 1)&lt;/p&gt;&#xA;&lt;p&gt;&lt;a href=&#34;//www.blackhat.com/us-16/briefings.html#abusing-bleeding-edge-web-standards-for-appsec-glory&#34;&gt;&lt;/a&gt;&amp;mdash;bryant-zadegan-&amp;amp;-ryan-lester)&lt;a href=&#34;https://www.blackhat.com/us-16/briefings.html#abusing-bleeding-edge-web-standards-for-appsec-glory&#34;&gt;Abusing Bleeding Edge Web Standards For AppSec Glory&lt;/a&gt; – Bryant Zadegan &amp;amp; Ryan Lester (&lt;a href=&#34;https://www.blackhat.com/docs/us-16/materials/us-16-Zadegan-Abusing-Bleeding-Edge-Web-Standards-For-AppSec-Glory.pdf&#34;&gt;Slides&lt;/a&gt;)&lt;/p&gt;&#xA;&lt;p&gt;Bryant and Ryan talked about new web standards which are already implemented in parts of the current browser jungle. Namely these standard were:&lt;/p&gt;</description>
    </item>
    <item>
      <title>Attacking BaseStations @Defcon24</title>
      <link>https://insinuator.net/2016/09/attacking-basestations-@defcon24/</link>
      <pubDate>Tue, 20 Sep 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/09/attacking-basestations-@defcon24/</guid>
      <description>&lt;p&gt;Hello Guys,&lt;br&gt;&#xA;back from my vacation I’d like to give you some impressions about Defcon 24 and our talk “Attacking BaseStations”. Defcon itself had a couple of great talks but was a very crowded location. Anyhow, we had a couple of great discussions with the people before and after our talk.&lt;/p&gt;&#xA;&lt;p&gt;The talk “Attacking BaseStations” focussed on attack vectors we simulated in &lt;a href=&#34;https://www.insinuator.net/2015/05/how-to-get-as-basestation/&#34;&gt;our lab&lt;/a&gt;. Besides attacking a BaseStation via Radio interface, in this talk we focussed on local and remote interfaces as introduced in &lt;a href=&#34;https://www.insinuator.net/2014/10/lte-vs-darwin-hackers-to-hackers-conference-11/&#34;&gt;“LTE vs. Darwin”&lt;/a&gt;. As target of evaluation one of our eNodeB’s came into play, which we purchased on the Internet. Anyhow, the talk covered the following attack scenarios:&lt;/p&gt;</description>
    </item>
    <item>
      <title>BSides LV 2016: Recap</title>
      <link>https://insinuator.net/2016/09/bsides-lv-2016-recap/</link>
      <pubDate>Mon, 19 Sep 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/09/bsides-lv-2016-recap/</guid>
      <description>&lt;p&gt;Hey everyone,&lt;/p&gt;&#xA;&lt;p&gt;Just a short recap from my side regarding this year’s BSide in Las Vegas, NV. It was my first time there and I pretty much enjoyed it. After entering the venue on the first con day (Tuesday) I was a little bit shocked, as the staff sent me to the “end of the line just around the corner” – the end being many corners and many floors away 😉 Speaking to some guys while standing in line, time quickly passed by and before finally hitting the registration desk, there were already some people from the staff giving away the conference badges to the waiting folks. The waiting time was no comparison to last year’s DEF CON, where I (and obviously all the other “humans”, how attendees at DEF CON are called) had to wait nearly _four_ hours to get a badge to enter the con. DEF CON staff already calls this the annual “Line Con”. Enough bashing, back to topic 😉&lt;/p&gt;</description>
    </item>
    <item>
      <title>SIGS DC Day</title>
      <link>https://insinuator.net/2016/09/sigs-dc-day/</link>
      <pubDate>Fri, 16 Sep 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/09/sigs-dc-day/</guid>
      <description>&lt;p&gt;Today I had to give the pleasure to give a keynote at the &lt;a href=&#34;http://digs.ch/dc-day/&#34;&gt;SIGS DC Day&lt;/a&gt; on the need to evaluate Cloud Service Providers in a way that looks behind (or at least tries to) security whitepapers and certification reports. The slides can be found &lt;a href=&#34;https://www.ernw.de/download/ERNWResearch_TrustEvaluationCloudProvider_mluft.pdf&#34;&gt;here&lt;/a&gt;.&lt;/p&gt;&#xA;&lt;p&gt;I also particularly enjoyed the following two talks:&lt;/p&gt;&#xA;&lt;p&gt;Sean O’Tool from Swisscom AG covered challenges of an infrastructure to cloud migration. Even though he only briefly touched the topic, I enjoyed his description of their firewalling model: Seeing that centralized firewall operation (or more precisely, rule design and approval) is limited/challenged by the understanding of the application, they transferred control over firewall rule sets (beyond a basic set of infrastructure/ground rules) to the application teams (using of features like OpenStack’s security groups, where he also talked about limitations of those). They compensated the loss of “centralized enforcement by a security group” with rule reviews — an approach that will become way more relevant (and necessary) in the future.&lt;/p&gt;</description>
    </item>
    <item>
      <title>25th USENIX Security Symposium &amp;amp; WOOT Workshop</title>
      <link>https://insinuator.net/2016/09/25th-usenix-security-symposium-amp-woot-workshop/</link>
      <pubDate>Mon, 12 Sep 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/09/25th-usenix-security-symposium-amp-woot-workshop/</guid>
      <description>&lt;p&gt;Last month the annual USENIX Security Symposium with its co-located workshops (WOOT, CSET, FOCI, ASE, and HotSec) was held in Austin, Texas. The program of the conference together with the published papers can be found &lt;a href=&#34;https://www.usenix.org/conference/usenixsecurity16/technical-sessions&#34;&gt;here&lt;/a&gt; and information on the workshops can be found &lt;a href=&#34;https://www.usenix.org/conference/usenixsecurity16/workshops&#34;&gt;here&lt;/a&gt;.&lt;/p&gt;&#xA;&lt;p&gt;The research topics were quite diverse and included subjects such as low-level attacks, cryptographic attacks, and vehicle attacks. To give you an impression on the research that has been presented at the conference, let us discuss some of the talks in the following:&lt;/p&gt;</description>
    </item>
    <item>
      <title>MRMCD16 – diagnosis:critical</title>
      <link>https://insinuator.net/2016/09/mrmcd16-diagnosiscritical/</link>
      <pubDate>Sat, 03 Sep 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/09/mrmcd16-diagnosiscritical/</guid>
      <description>&lt;p&gt;This year’s &lt;a href=&#34;https://2016.mrmcd.net/en/&#34;&gt;MRMCD16&lt;/a&gt; had a topic that immediately let me submit a talk about medical device security: “diagnosis:critical”. Or to quote the official website:&lt;/p&gt;&#xA;&lt;p&gt;Security issues in soft- and hardware have a low chance of healing, especially in medical IT.&lt;/p&gt;&#xA;&lt;p&gt;Despite years of therapy using code reviews and programming guidelines, we still face huge amounts of vulnerable software that probably is in need of palliative treatment.&lt;/p&gt;&#xA;&lt;p&gt;Security vulnerabilities caused by the invasion of IT in the medical sector are becoming real threats. From insulin pumps over analgesic pumps through to pace makers, more and more medical devices have been hacked already. This year&amp;rsquo;s motto &amp;ldquo;mrmcd2016 - diagnosis:critical&amp;rdquo; stands summarizing for the current state of the whole IT sector.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Black Hat 2016 Summary</title>
      <link>https://insinuator.net/2016/08/black-hat-2016-summary/</link>
      <pubDate>Tue, 09 Aug 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/08/black-hat-2016-summary/</guid>
      <description>&lt;p&gt;Just a few days ago I had a blast again at this year’s Black Hat. Some of the talks were really worth listening to, so I wanted to point them out and give a short summary.&lt;/p&gt;&#xA;&lt;p&gt; &lt;/p&gt;&#xA;&lt;p&gt;&lt;a href=&#34;https://www.blackhat.com/us-16/briefings.html#using-undocumented-cpu-behavior-to-see-into-kernel-mode-and-break-kaslr-in-the-process&#34;&gt;USING UNDOCUMENTED CPU BEHAVIOR TO SEE INTO KERNEL MODE AND BREAK KASLR IN THE PROCESS&lt;/a&gt; – Anders Fogh &amp;amp; Daniel Gruss&lt;/p&gt;&#xA;&lt;p&gt;They had the last slot at the last day of Black Hat which resulted in a kind of empty room, but in my opinion it was an awesome talk and I even had the pleasure to meet these two guys at our ERNW dinner.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Not Sure Which Talks to Attend at BHUSA?</title>
      <link>https://insinuator.net/2016/07/not-sure-which-talks-to-attend-at-bhusa/</link>
      <pubDate>Fri, 29 Jul 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/07/not-sure-which-talks-to-attend-at-bhusa/</guid>
      <description>&lt;p&gt;Hi,&lt;/p&gt;&#xA;&lt;p&gt;I won’t be in Vegas for Black Hat this year as there’s a direct conflict with one of my kids’ birthdays, but I thought one or another reader might find it helpful to get some inspiration as for selecting the talks to catch (not least as there’s so many interesting ones). I hence decided to quickly write this post.&lt;/p&gt;&#xA;&lt;p&gt;Here’s my would-be schedule for the first day (second day to follow, maybe, in another post), under the assumption to attend exactly one talk per slot. I could give a longer rationale per talk than the one below, based on several (mostly technical) factors, but this is just about providing suggestions in a brief form.&lt;br&gt;&#xA;Disclaimer: I was on the &lt;a href=&#34;https://www.blackhat.com/review-board.html&#34;&gt;BH guest review board&lt;/a&gt; this year so I might be biased in some cases.&lt;/p&gt;</description>
    </item>
    <item>
      <title>REcon 2016 – A Quick Recap</title>
      <link>https://insinuator.net/2016/07/recon-2016-a-quick-recap/</link>
      <pubDate>Mon, 25 Jul 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/07/recon-2016-a-quick-recap/</guid>
      <description>&lt;p&gt;Some of us had the pleasure to visit this year’s &lt;a href=&#34;https://recon.cx/&#34;&gt;REcon&lt;/a&gt; in Montreal, Canada. Unfortunately, work caught us just when we arrived back in Germany, so I haven’t had time to sit down and write down a few words so far. However, we think that what we’ve experienced at REcon is worth writing about.&lt;/p&gt;&#xA;&lt;p&gt;The overall quality of the speakers and talks were very nice. What really amazed me was the art work of REcon:&lt;/p&gt;</description>
    </item>
    <item>
      <title>SnoopCon Guest Day</title>
      <link>https://insinuator.net/2016/07/snoopcon-guest-day/</link>
      <pubDate>Fri, 01 Jul 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/07/snoopcon-guest-day/</guid>
      <description>&lt;p&gt;This year I had the pleasure to join the guest day of BT’s SnoopCon. There were quite a number of interesting talks throughout the day such as&lt;/p&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://twitter.com/therealsaumil&#34;&gt;Saumil Shah&lt;/a&gt;‘s presentation on Stegosploit (as well as his rant about the state of information security)&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://twitter.com/drgfragkos&#34;&gt;Dr. Grigorios Fragkos&lt;/a&gt;‘ talk on airplane security (where he presented some maybe not-so-pleasant but also some good-to-hear facts on the security posture of airplanes)&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://twitter.com/dominicgs&#34;&gt;Dominic Spill&lt;/a&gt;‘s demonstration of tools and methods used to reverse engineer RF protocols&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://twitter.com/hackerfantastic&#34;&gt;Hacker Fantastic&lt;/a&gt;‘s talk on how to use the AX.25 protocol to bounce radio signals off the ISS to communicate with systems around the world&lt;/li&gt;&#xA;&lt;li&gt;Kostas Litovois’ and Vincent Yiu’s presentation on #WePWNise, a tool that can be used to efficiently create malicious VBA macros (by taking EMET configuration details into account)&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://twitter.com/bryanfite&#34;&gt;Bryan Fite&lt;/a&gt;‘s talk on how we have to think about Safety, Security, and Privacy in the IoT age.&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;p&gt;I really enjoyed the talks and had a great time! Thanks to all the organizers and speakers!&lt;/p&gt;</description>
    </item>
    <item>
      <title>Area41 Conference 2016</title>
      <link>https://insinuator.net/2016/06/area41-conference-2016/</link>
      <pubDate>Sat, 18 Jun 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/06/area41-conference-2016/</guid>
      <description>&lt;p&gt;Last Friday, Brian and I were at the  Area41 Security Conference. The conference is a branch of Defcon conference and is more or less a small conference of the Swiss hacker community. Being in a “rock music club”, the speakers presented on a stage where usually the rock stars are performing – which gives the conference a very special flair and an interesting atmosphere. We’ve been at the &lt;a href=&#34;http://area41.io/speakers/#hendrikschmidt&#34;&gt;conference&lt;/a&gt; to present our research about VoLTE technology including some attack scenarios we’ve evaluated in the &lt;a href=&#34;https://www.insinuator.net/2016/01/security-analysis-of-volte-part-1/&#34;&gt;past&lt;/a&gt;. More on this later, let’s first talk about the conference itself.&lt;/p&gt;</description>
    </item>
    <item>
      <title>IPv6 &amp; Threat Intelligence</title>
      <link>https://insinuator.net/2016/06/ipv6-threat-intelligence/</link>
      <pubDate>Fri, 03 Jun 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/06/ipv6-threat-intelligence/</guid>
      <description>&lt;p&gt;Tomorrow, I will join a meeting where I’m expected to contribute, amongst others, to a discussion on the impact of IPv6 on threat intelligence. To prepare for that I started putting together some thoughts &amp;amp; ideas on the topic, and I even thought I might share this in a post (the one you read right now ;-), not least to, maybe, stimulate a discussion.&lt;/p&gt;&#xA;&lt;p&gt;I don’t know much about threat intelligence so it might happen that, at times, I use some misguided terms or I expose a (too) naïve understanding of some concepts. Happy to be corrected in one way or another.&lt;/p&gt;</description>
    </item>
    <item>
      <title>New Methods for Exploiting ORM Injections in Java Applications (HITB16)</title>
      <link>https://insinuator.net/2016/06/new-methods-for-exploiting-orm-injections-in-java-applications-hitb16/</link>
      <pubDate>Thu, 02 Jun 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/06/new-methods-for-exploiting-orm-injections-in-java-applications-hitb16/</guid>
      <description>&lt;p&gt;The HITBSecConf or “Hack In The Box” in Amsterdam is a well known security conference in Europe. We also attended this year too, and there were quite some interesting talks at the HITBSecConf16 conference. One of the talks was about “New Methods for Exploiting ORM Injections in Java Applications” by the security researchers Mikhail Egorov and Sergey Soldatov.&lt;/p&gt;&#xA;&lt;p&gt;&lt;strong&gt;I. What is Object-Relational Mapping (ORM)?&lt;/strong&gt;&lt;/p&gt;&#xA;&lt;p&gt;ORM stands for Object-Relational Mapping, which is a technique that automatically converts data from a relational database management system (RDBMS) into objects. This is often used in business applications of today.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Telescope – Peering Into the Depths of TLS Traffc in Real-Time (HITB16)</title>
      <link>https://insinuator.net/2016/05/telescope-peering-into-the-depths-of-tls-traffc-in-real-time-hitb16/</link>
      <pubDate>Mon, 30 May 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/05/telescope-peering-into-the-depths-of-tls-traffc-in-real-time-hitb16/</guid>
      <description>&lt;p&gt;Last week we have visited the HITBSecConf16 – conference in Amsterdam.&lt;br&gt;&#xA;There were many interesting talks, and in this post I am going to tell you about a talk held by Radu Caragea – “Telescope: Peering Into the Depths of TLS Traffic in Real-Time”.&lt;/p&gt;&#xA;&lt;p&gt;While performing a dynamic malware analysis one often needs to analyze network traffic in order to determine malware communication with C&amp;amp;C servers, to observe the malware delivery from sites, or to investigate honeypot traffic under TLS.&lt;br&gt;&#xA;There are already existing solutions to help with this task. However in the given talk considering virtual environments the speaker presented a novel technique that works for virtualized machines with a minimal overhead, and is actually OS-agnostic and crypto-library-agnostic.&lt;/p&gt;</description>
    </item>
    <item>
      <title>The Beauty of IPv6 Link-Local Addressing. Not</title>
      <link>https://insinuator.net/2016/05/the-beauty-of-ipv6-link-local-addressing.-not/</link>
      <pubDate>Sat, 28 May 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/05/the-beauty-of-ipv6-link-local-addressing.-not/</guid>
      <description>&lt;p&gt;In November 2014, after quite some controversy in the IETF OPSEC working group (for those interested look at the &lt;a href=&#34;http://www.ietf.org/mail-archive/web/opsec/current/maillist.html&#34;&gt;archives&lt;/a&gt;), the &lt;em&gt;Informational&lt;/em&gt; &lt;a href=&#34;https://tools.ietf.org/rfc/rfc7404.txt&#34;&gt;RFC 7404&lt;/a&gt; “Using Only Link-Local Addressing inside an IPv6 Network” was published. It is authored by &lt;a href=&#34;http://blogs.cisco.com/author/michaelbehringer&#34;&gt;Michael Behringer&lt;/a&gt; and &lt;a href=&#34;https://twitter.com/evyncke&#34;&gt;Eric Vyncke&lt;/a&gt; and discusses the advantages &amp;amp; disadvantages of an approach using “only link-local addresses on infrastructure links between routers”.&lt;/p&gt;&#xA;&lt;p&gt;So it’s (merely) about “infrastructure links” which some people call “transit networks” or “point to point” (ptp) links. I’m aware that there might be subtle differences between all these, depending on your specific use of the terms. Still I assume that most readers will have an understanding of what types of links are in focus of the RFC, and subsequently of this post.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Because of Cyber – A Recap</title>
      <link>https://insinuator.net/2016/05/because-of-cyber-a-recap/</link>
      <pubDate>Wed, 11 May 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/05/because-of-cyber-a-recap/</guid>
      <description>&lt;p&gt;Troopers16 has been over for quite a while now, but because sharing is caring, we would like to give you some more insight and share some gems that happened over the 2 days of us running a small/medium sized enterprise in mid-west Russia as part of the well received FishBowl side story.&lt;/p&gt;&#xA;&lt;p&gt;Technology wise the whole infrastructure of FishBowl, as well as the Cyber Emergency Response Team, was hosted on one FreeBSD machine with exception of the challenge scoreboard which was on site only, hence conference network only.&lt;br&gt;&#xA;The C.E.R.T. web site was static web site using the &lt;a href=&#34;jekyllrb.com&#34;&gt;jekyll&lt;/a&gt; engine. FishBowl on the other hand required some dynamic web magic which is why we choose to use the &lt;a href=&#34;http://flask.pocoo.org/&#34;&gt;flask framework&lt;/a&gt;. For the FishBowl web design we simply helped ourselves with the styles of the &lt;a href=&#34;https://www.troopers.de&#34;&gt;Troopers web site&lt;/a&gt;, who of you noticed? 😉&lt;br&gt;&#xA;All web related stuff was reverse proxied by an &lt;a href=&#34;http://nginx.org/&#34;&gt;nginx&lt;/a&gt; to provide a common layer of technology even though every venture was segregated into its own FreeBSD jail environment.&lt;br&gt;&#xA;For mail a simple postfix setup was set up. Having a proper mail server for such »shenanigans« turned out to be very enjoyable, but more on that later.&lt;/p&gt;</description>
    </item>
    <item>
      <title>A Trip to Hannover Messe</title>
      <link>https://insinuator.net/2016/04/a-trip-to-hannover-messe/</link>
      <pubDate>Wed, 27 Apr 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/04/a-trip-to-hannover-messe/</guid>
      <description>&lt;p&gt;Once every few years I decide to head to Hannover and attend &lt;a href=&#34;http://www.hannovermesse.de/&#34;&gt;Hannover Messe&lt;/a&gt;, probably the largest industrial trade fair in Germany and apparently on of the most important in the world. As this year’s main topic was “Industrie 4.0” I simply could not resist to go out on a hunt for new and interesting (secure) smart connected magic! And trust me, I was not disappointed – here’s a few of my impressions.&lt;/p&gt;</description>
    </item>
    <item>
      <title>SAP Security @ Troopers16</title>
      <link>https://insinuator.net/2016/04/sap-security-@-troopers16/</link>
      <pubDate>Mon, 25 Apr 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/04/sap-security-@-troopers16/</guid>
      <description>&lt;p&gt;When it comes to SAP, Troopers has two events that are about Security in SAP Systems in particular. On the first day of the Troopers16 Trainings the BIZEC workshop takes place. The second event is a dedicated SAP track during the conference. Apart from these events there were of course a lot of nice folks to talk to (about SAP) 🙂 This post is a short overview about SAP security &lt;a href=&#34;https://www.troopers.de/troopers16/&#34;&gt;@ TROOPERS16.&lt;/a&gt;&lt;/p&gt;</description>
    </item>
    <item>
      <title>Defense &amp; Management Day 2</title>
      <link>https://insinuator.net/2016/04/defense-management-day-2/</link>
      <pubDate>Fri, 15 Apr 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/04/defense-management-day-2/</guid>
      <description>&lt;p&gt;&lt;a href=&#34;https://www.troopers.de/troopers16/&#34;&gt;TROOPERS16&lt;/a&gt; offered many different speakers from around the globe. Below are three different talks from the afternoon of Day 2’s Defense and Management Track. &lt;/p&gt;&#xA;&lt;p&gt;===&lt;/p&gt;&#xA;&lt;p&gt;The TROOPERS16 talk “&lt;a href=&#34;https://www.troopers.de/events/troopers16/629_attacking__protecting_big_data_environments/&#34;&gt;Attacking &amp;amp; Protecting Big Data Environments&lt;/a&gt;” presented the research of Birk Kauer and Matthias Luft, (&lt;a href=&#34;http://ernw.de&#34;&gt;ERNW&lt;/a&gt;) in which they showed how enterprise-grade “big data” environments, based on e.g. HortonWorks or Cloudera, comprising of components such as HDFS, Yarn, Hue, Flume, Hive, Spark, Sentry/Ranger could be attacked. These environments typically process huge amounts of data. The data is either stored in a cluster file system or streamed into clusters. The processing of these datasets are done by jobs, and these jobs can be arbitrary code execution.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Infiltrate and Syscan 360</title>
      <link>https://insinuator.net/2016/04/infiltrate-and-syscan-360/</link>
      <pubDate>Fri, 15 Apr 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/04/infiltrate-and-syscan-360/</guid>
      <description>&lt;p&gt;Hi everyone,&lt;/p&gt;&#xA;&lt;p&gt;I spent the last weeks traveling to Singapore and Miami to present my &lt;em&gt;Xenpwn&lt;/em&gt; research about double fetch vulnerabilities in paravirtualized devices at Infiltrate and Syscan360. You can find my slides &lt;a href=&#34;https://www.ernw.de/download/xenpwn.pdf&#34;&gt;here&lt;/a&gt;. Both conferences had great organization, very technical talks and a cool audience. In the following I want to give a short recap of some of the talks I liked the most:&lt;/p&gt;&#xA;&lt;h2 id=&#34;sean-heelan-automatic-root-cause-identification-for-crashing-executions-infiltrate&#34;&gt;Sean Heelan – Automatic Root-Cause Identification for Crashing Executions (Infiltrate)&lt;/h2&gt;&#xA;&lt;p&gt;Sean Heelan talked about his work on automated root cause analysis. The goal of this research is to give a human researcher a detailed analysis of the potential root causes (in the form of violated predicates) that triggered a crash during a fuzzing run. Sean summarizes the core idea of his research much better than I would be able to in his &lt;a href=&#34;https://sean.heelan.ie/2016/04/13/some-early-stage-work-on-statistical-crash-triage/&#34;&gt;blog post&lt;/a&gt;, which also contains a link to his slides. I’m always a big fan of his talks because he is one of the few peoples working in the intersection between the academic program verification community and the IT security industry.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Summary GI Sicherheit</title>
      <link>https://insinuator.net/2016/04/summary-gi-sicherheit/</link>
      <pubDate>Fri, 08 Apr 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/04/summary-gi-sicherheit/</guid>
      <description>&lt;p&gt;This is a short summary of selected talks (i.e. those that I found the most interesting of those I was able to personally attend) of the &lt;em&gt;&lt;a href=&#34;https://sicherheit2016.de/&#34;&gt;GI Sicherheit 2016&lt;/a&gt;&lt;/em&gt;.&lt;/p&gt;&#xA;&lt;p&gt;First of all, congratulations to Dr. Fabian Yamaguchi, who received an award (the &lt;em&gt;GI Promotionspreis&lt;/em&gt;) for his PhD thesis “&lt;a href=&#34;https://ediss.uni-goettingen.de/bitstream/handle/11858/00-1735-0000-0023-9682-0/mainFastWeb.pdf&#34;&gt;Pattern-Based Vulnerability Discovery&lt;/a&gt;“!&lt;br&gt;&#xA;His work presents an “approach for identifying vulnerabilities which combines techniques from static analysis, machine learning, and graph mining to augment the analyst’s abilities rather than trying to replace her” by identifying and highlighting patterns of potential vulnerabilities in source code.&lt;/p&gt;</description>
    </item>
    <item>
      <title>TSD 2016 – Follow Up</title>
      <link>https://insinuator.net/2016/04/tsd-2016-follow-up/</link>
      <pubDate>Thu, 07 Apr 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/04/tsd-2016-follow-up/</guid>
      <description>&lt;p&gt;Thanks again for all the great talks and fruitful discussions &lt;a href=&#34;https://www.troopers.de/events/troopers16/580_telcosecday_2016_invitation_only/&#34;&gt;@TSD 2016&lt;/a&gt;! I hope everybody had a safe trip home and enjoyed Troopers as we did. In the meantime I contacted all speakers to talk about publication of their slidesets. Some of them agreed (or already published them on their own) so I’d like to share these with you:&lt;/p&gt;&#xA;&lt;p&gt;&lt;a href=&#34;https://www.ernw.de/download/TSD2016_Assaulting_diameter_IPX_network.pdf&#34;&gt;&lt;strong&gt;Alexandre De Oliveira&lt;/strong&gt; – &lt;em&gt;Assaulting IPX Diameter roaming network&lt;/em&gt;&lt;/a&gt;&lt;a href=&#34;https://www.ernw.de/download/TSD2016_Known_Unknowns_of_SS7.pdf&#34;&gt;&lt;br&gt;&#xA;&lt;strong&gt;Siddharth Rao&lt;/strong&gt; – &lt;em&gt;The known unknowns of SS7 and beyond.&lt;/em&gt;&lt;/a&gt;&lt;br&gt;&#xA;&lt;a href=&#34;https://www.ernw.de/download/TSD2016_rucki_zucki.pdf&#34;&gt;&lt;strong&gt;Joao Collier de Mendonca&lt;/strong&gt; – &lt;em&gt;“rucki zucki” scanning tool&lt;/em&gt;&lt;/a&gt;&lt;br&gt;&#xA;&lt;a href=&#34;http://git.gnumonks.org/index.html/laforge-slides/plain/2016/telcosecday/foss-gsm.html&#34;&gt;&lt;strong&gt;Harald Welte&lt;/strong&gt; – &lt;em&gt;Open Source Network Elements for Security Analysis of Mobile Networks&lt;/em&gt;&lt;/a&gt;&lt;br&gt;&#xA;&lt;a href=&#34;https://www.ernw.de/download/TSD2016_Ravi-Altaf.pdf&#34;&gt;&lt;strong&gt;Ravi &amp;amp; Altaf Shaik&lt;/strong&gt; – &lt;em&gt;Don’t connect to my 4G base station: investigating info leaks in 4G basebands&lt;/em&gt;&lt;/a&gt;&lt;/p&gt;</description>
    </item>
    <item>
      <title>Unpatchable – Living with a vulnerable implanted device</title>
      <link>https://insinuator.net/2016/04/unpatchable-living-with-a-vulnerable-implanted-device/</link>
      <pubDate>Thu, 07 Apr 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/04/unpatchable-living-with-a-vulnerable-implanted-device/</guid>
      <description>&lt;p&gt;TL;DR: Marie Moe talked about security issues of medical devices, especially implantable devices like pacemakers, but not in overwhelming technological depth. She wanted to point out the necessity of intensified security research in the field of medical devices as vendors and medical personnel seem to be lacking necessary awareness of security of devices, interfaces, services, and even data privacy.”Get involved, &lt;a href=&#34;https://www.iamthecavalry.org/&#34;&gt;join the cavalry&lt;/a&gt;” was her core message.&lt;/p&gt;&#xA;&lt;p&gt;&lt;strong&gt;Lub-Dub-Lub-Dub-Lub-Dub&lt;/strong&gt;&lt;br&gt;&#xA;Marie started her talk with the sound of a repeating heartbeat. First she introduced how she came up with the topic of her talk: Marie relies on a pacemaker herself andsince she got it implanted she was curious how secure this little device might be. A minimum education of the auditorium followed including an explanation how a human heart works and what a pacemaker does.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Security Assessment of Microsoft DirectAccess</title>
      <link>https://insinuator.net/2016/04/security-assessment-of-microsoft-directaccess/</link>
      <pubDate>Wed, 06 Apr 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/04/security-assessment-of-microsoft-directaccess/</guid>
      <description>&lt;p&gt;A &lt;a href=&#34;https://www.troopers.de/events/ipv6-security-summit-2016/698_security_assessment_of_microsoft_directaccess/&#34;&gt;talk&lt;/a&gt; about DirectAccess (an IPv6-only VPN solution) was given by our colleague Ali Hardudi during IPv6 summit. Ali has recently finished his master thesis on this topic.&lt;/p&gt;&#xA;&lt;p&gt;The DirectAccess VPN technology was introduced by Microsoft starting from Windows server 2008. It allows users remotely, seamlessly and securely connect to their internal network resources without a need to provide user credentials, which is done using different technologies such as Windows domain group policies.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Anonymization IPv6 in PCAPs – Challenges and Wins</title>
      <link>https://insinuator.net/2016/04/anonymization-ipv6-in-pcaps-challenges-and-wins/</link>
      <pubDate>Tue, 05 Apr 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/04/anonymization-ipv6-in-pcaps-challenges-and-wins/</guid>
      <description>&lt;p&gt;Jasper Bongertz is a Senior Technical Consultant at Airbus Defence and Space CyberSecurity. He is focusing on IT security, Incident Response and Network Forensics.&lt;br&gt;&#xA;During the IPv6 summit on Troopers16 he had given a &lt;a href=&#34;https://www.troopers.de/events/ipv6-security-summit-2016/693_anonymization_ipv6_in_pcaps_-_challenges_and_wins/&#34;&gt;talk&lt;/a&gt; on anonymization IPv6 in PCAPs and presented his new tool.&lt;/p&gt;&#xA;&lt;p&gt;Sometimes you need to share your packet capture files (PCAPs), but distributing them involves a risk of exposing the confidential information. To avoid this, you must sanitize your PCAPs. The goal of sanitization is to remove the critical details but keep enough information for the PCAP to still be useful. The original-to-sanitized ratio is based on your goals.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Passive Intelligence Gathering and Analytics – It’s all Just Metadata!</title>
      <link>https://insinuator.net/2016/04/passive-intelligence-gathering-and-analytics-its-all-just-metadata/</link>
      <pubDate>Tue, 05 Apr 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/04/passive-intelligence-gathering-and-analytics-its-all-just-metadata/</guid>
      <description>&lt;p&gt;The first talk after the keynote on day 2 of TROOPERS was from Christopher Truncer about passive intelligence gathering and the analytics of that. Christopher Truncer (@ChrisTruncer) is a red teamer with Mandiant. He is a co-founder and current developer of the Veil-Framework, a project aimed to bridge the gap between advanced red team and penetration testing toolsets.&lt;/p&gt;&#xA;&lt;p&gt;His talk is mainly about defending a network from different threats by collecting and analyzing metadata from different sources.&lt;/p&gt;</description>
    </item>
    <item>
      <title>The Kings in your Castle</title>
      <link>https://insinuator.net/2016/04/the-kings-in-your-castle/</link>
      <pubDate>Tue, 05 Apr 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/04/the-kings-in-your-castle/</guid>
      <description>&lt;p&gt;At the second day of the TROOPERS16 conference an interesting talk about Advanced Persistent Threats took place from Marion Marschalek and Raphaël Vinot. Marion Marschalek is a Security Researcher, focusing on the analysis of emerging threats and exploring novel methods of threat detection. Marion started her career within the anti-virus industry and also worked on advanced threat protection systems where she built a thorough understanding of how threats and protection systems work and how both occasionally fail.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Advanced IPv6 Network Reconnaissance</title>
      <link>https://insinuator.net/2016/04/advanced-ipv6-network-reconnaissance/</link>
      <pubDate>Sun, 03 Apr 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/04/advanced-ipv6-network-reconnaissance/</guid>
      <description>&lt;p&gt;Fernando Gont, who is specializing in the field of communications protocols security, gave a &lt;a href=&#34;https://www.troopers.de/events/ipv6-security-summit-2016/594_advanced_ipv6_network_reconnaissance/&#34;&gt;talk&lt;/a&gt; during this year’s Troopers IPv6 summit. He spoke about network reconnaissance techniques in IPv6 area and presented a brand new set of tools for this purpose.&lt;/p&gt;&#xA;&lt;p&gt;Comparing with methods for IPv4, reconnaissance techniques for IPv6 should be different. It offers much larger address space, so such attacks as brute force address scanning are not feasible anymore, because it would take too much time to send one packet to each and every possible address. Fernando has also noted that in general network reconnaissance support in security tools has traditionally been poor. Together these facts prompt that it’s time for something new, and recently a new &lt;a href=&#34;https://tools.ietf.org/html/rfc7707&#34;&gt;IETF RFC 7707&lt;/a&gt; was published.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Patch Me If You Can</title>
      <link>https://insinuator.net/2016/04/patch-me-if-you-can/</link>
      <pubDate>Sat, 02 Apr 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/04/patch-me-if-you-can/</guid>
      <description>&lt;p&gt;Right after the Opening Keynote of TROOPERS16, an informative and interesting talk took place at the SAP Security track. This talk was given by three speakers; Damian Poddebniak who is currently a master student at the University of Applied Sciences of Münster, Sebastian Schinzel who works as an IT security Professor at the University of Applied Sciences of Münster and he is also the founder of CycleSEC GmbH and finally the sixth-time speaker at Troopers “Andreas Wiegenstein” who is the CTO of Virtual Forge GmbH and a professional SAP security consultant since 2003.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Tools for Troubleshooting and Monitoring IPv6 Networks</title>
      <link>https://insinuator.net/2016/04/tools-for-troubleshooting-and-monitoring-ipv6-networks/</link>
      <pubDate>Sat, 02 Apr 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/04/tools-for-troubleshooting-and-monitoring-ipv6-networks/</guid>
      <description>&lt;p&gt;Yet another interesting 180-minute workshop in IPv6 Security Summit of TROOPERS16, which aimed to introduce the IPv6 troubleshooting and monitoring tools, which are essentially needed by users in order to know how to deal with IPv6 in any IPv6-enabled network.&lt;/p&gt;&#xA;&lt;p&gt;Before we dive into this post, let me introduce you in few words “Gabriel Müller” the speaker and the instructor of this workshop. Gabriel works as a senior consultant at AWK Group by mainly assisting clients in the public and private sectors as a project manager and an expert in the network area.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Caring for file formats</title>
      <link>https://insinuator.net/2016/04/caring-for-file-formats/</link>
      <pubDate>Fri, 01 Apr 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/04/caring-for-file-formats/</guid>
      <description>&lt;p&gt;Ange Albertini is a reverse engineer and author of Corkami.&lt;/p&gt;&#xA;&lt;p&gt;First and foremost he explained what a polyglot file is. A polyglot is a special file that has more than one type in the same file. For example, Ange Albertini demonstrated a polyglot which is a pdf, a pdf reader, a java executable and an html file inside of one file. The second polyglot he demonstrated was a file which had the characteristics that when you encrypted it with AES you get a PNG image and if it´s encrypted with another key you will get a flash video and when you encrypted it with DES you get a PDF document. He pointed out that a file format is not just a sequence of byte it´s rather a computer dialect to communicate between communities. He also highlighted that people don’t really care about what is behind the file format they only what to use it and communicate with other people.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Imma Chargin Mah Lazer-How to protect against (D)DoS attacks</title>
      <link>https://insinuator.net/2016/04/imma-chargin-mah-lazer-how-to-protect-against-ddos-attacks/</link>
      <pubDate>Fri, 01 Apr 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/04/imma-chargin-mah-lazer-how-to-protect-against-ddos-attacks/</guid>
      <description>&lt;p&gt;Denial of Service (DoS) attacks aim to make services and systems unavailable to legitimate users . If these attacks are performed by multiple sources at the same time and for the same target, they are called Distributed Denial of Service (DDoS) attacks. This talk “Imma Chargin Mah Lazer” describes different types of (D)DoS attacks that are out in the wild and are seen on a daily basis by different corporations. Furthermore,  a multi-layered strategy to mitigate such kinds of attacks has been presented within the talk. The speaker is Dr. Oliver Matula, an IT security researcher at ERNW who holds a PHD degree in physics. He presented the topic in a simple way which eases the delivery of information to audience of different technical levels and backgrounds.&lt;/p&gt;</description>
    </item>
    <item>
      <title>QNX: 99 Problems but a Microkernel ain’t one!</title>
      <link>https://insinuator.net/2016/04/qnx-99-problems-but-a-microkernel-aint-one/</link>
      <pubDate>Fri, 01 Apr 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/04/qnx-99-problems-but-a-microkernel-aint-one/</guid>
      <description>&lt;p&gt;The talk “QNX: 99 Problems but a Microkernel ain’t one!” was part of the Troopers conference in Heidelberg, 16 March 2016. The talk was done by the researchers Alex Plaskett and Georgi Geshev from the MWR Labs. The MWR Labs is the research department of the cyber security consultancy MWR InfoSecurity located in the UK.&lt;br&gt;&#xA; &lt;br&gt;&#xA;The talk provided an overview of the research on the architecture and security systems of the QNX kernel with focus on the Blackberry 10 operating system. The talk was divided into two parts. First Alex Plaskett gave an introduction regarding the general structure of the QNX operation system and introduced the main subsystems. Second Georgi Geshev presented tools and approaches to abuse vulnerabilities in the QNX system.&lt;/p&gt;</description>
    </item>
    <item>
      <title>The road to secure Smart Cars: ENISA approach</title>
      <link>https://insinuator.net/2016/04/the-road-to-secure-smart-cars-enisa-approach/</link>
      <pubDate>Fri, 01 Apr 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/04/the-road-to-secure-smart-cars-enisa-approach/</guid>
      <description>&lt;p&gt;At TROOPERS16, Dr. Cédric LÉVY-BENCHETON an expert in cyber security at ENISA, the European Union Agency for Network and Information Security. Dr. Cédric LÉVY-BENCHETON  holds a presentation about cyber security of IoT (Internet of Things) and smart cars he presents the current threats in IoT and Smart cars. ENISA is an agency of the European Union. ENISA assists the Commission, the Member States and, the business community in meeting the requirements of network and information security.&lt;/p&gt;</description>
    </item>
    <item>
      <title>unrubby: reversing without reversing</title>
      <link>https://insinuator.net/2016/04/unrubby-reversing-without-reversing/</link>
      <pubDate>Fri, 01 Apr 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/04/unrubby-reversing-without-reversing/</guid>
      <description>&lt;p&gt;The talk “unrubby: reversing without reversing” was part of the Troopers conference in Heidelberg, 16 March 2016. The talk was done by Richo Healey, who is currently working on the security engineering team at the Irish payment company Stripe. Richo Healey is an experienced conference speaker. Amongst other he has spoken at Kiwicon, DEF CON and 44con.&lt;br&gt;&#xA; &lt;br&gt;&#xA;In his talk Richo Healey spoke about reverse engineering of Ruby software. First he talked about existing tools and techniques to regenerate source code from Ruby bytecode. Then he presented a new concept, which is implemented in his tool “unrubby”.&lt;/p&gt;</description>
    </item>
    <item>
      <title>BMC BladeLogic: CVE-2016-1542 and CVE-2016-1543</title>
      <link>https://insinuator.net/2016/03/bmc-bladelogic-cve-2016-1542-and-cve-2016-1543/</link>
      <pubDate>Thu, 31 Mar 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/03/bmc-bladelogic-cve-2016-1542-and-cve-2016-1543/</guid>
      <description>&lt;p&gt;Hi everyone,&lt;/p&gt;&#xA;&lt;p&gt;Hope those of you who attended Troopers16 enjoyed it as much as we did! In this post I want to summarize my &lt;a href=&#34;https://www.troopers.de/events/troopers16/648_one_tool_to_rule_them_all_-_and_what_can_it_lead_to/&#34;&gt;Troopers16 talk&lt;/a&gt; and provide you with some details about freshly assigned CVE-2016-1542 and CVE-2016-1543 related to BMC BladeLogic software.&lt;/p&gt;&#xA;&lt;p&gt;To start with, BMC Software Inc. is an American company specializing in business service management software; they develop software used for multiple functions, including IT service management, data center automation, performance management, virtualization lifecycle management and cloud computing management. Among other products they have developed a BladeLogic suite that includes Database Automation, Middleware Automation, Server Automation, and Network Automation tools. The one under our focus was BladeLogic Server Automation (BSA).&lt;/p&gt;</description>
    </item>
    <item>
      <title>DFRWS EU 2016 Summary</title>
      <link>https://insinuator.net/2016/03/dfrws-eu-2016-summary/</link>
      <pubDate>Thu, 31 Mar 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/03/dfrws-eu-2016-summary/</guid>
      <description>&lt;p&gt;In this article, I want to provide a concise sum-up of the (to me) most interesting talks of this year’s DFRWS EU (&lt;a href=&#34;http://www.dfrws.org/2016eu/&#34;&gt;http://www.dfrws.org/2016eu/&lt;/a&gt;).&lt;/p&gt;&#xA;&lt;p&gt;Eoghan Casey, one of most famous pioneers in digital forensics, and David-Olivier Jaquet-Chiffelle, professor in police science at University of Lausanne, gave a keynote that emphasized the need for theoretical fundamental basis research in the field of digital forensics, which I fully agreed on, as this was exactly what I addressed in some of my former research.&lt;/p&gt;</description>
    </item>
    <item>
      <title>How easy to grow robust botnet with low hanging fruits (IoT) – for free</title>
      <link>https://insinuator.net/2016/03/how-easy-to-grow-robust-botnet-with-low-hanging-fruits-iot-for-free/</link>
      <pubDate>Thu, 31 Mar 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/03/how-easy-to-grow-robust-botnet-with-low-hanging-fruits-iot-for-free/</guid>
      <description>&lt;p&gt;Attila Marosi works as a Senior Threat Research at Sophos Labs in Hungary. His talk focused on vulnerable IoT devices that are exposed to the internet. His approach was to look for vulnerable devices with low cost tools and publicly available data.&lt;/p&gt;&#xA;&lt;p&gt;He started his talk with the spoiler that he is not going to reveal any new attacks nor new techniques. But newer data are more adequate and we can see the current state of vulnerable devices connected to the internet. This means his approach was to test the state of IoT devices like Routers, NAS and so on with publicly available data.&lt;/p&gt;</description>
    </item>
    <item>
      <title>I Have the Power(View): Offensive Active Directory with PowerShell</title>
      <link>https://insinuator.net/2016/03/i-have-the-powerview-offensive-active-directory-with-powershell/</link>
      <pubDate>Thu, 31 Mar 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/03/i-have-the-powerview-offensive-active-directory-with-powershell/</guid>
      <description>&lt;p&gt;In his talk &lt;a href=&#34;https://www.troopers.de/events/troopers16/604_i_have_the_powerview_offensive_active_directory_with_powershell/&#34;&gt;I have the Power(View): Offensive Active Directory with PowerShell&lt;/a&gt; Will Schroeder, a researcher and Red teamer in Veris Group´s Adaptive Thread Division, presented offensive Active Directory information gathering technics using his Tool PowerView.&lt;/p&gt;&#xA;&lt;p&gt;PowerView does not use the built in AD cmdlets to be independent from the Remote Server Administration Tools (RSAT)-AD PowerShell Module which is only compatible with PowerShell 3.0+ and by default only installed on servers that have Active Directory services roles. PowerView, however, is compatible with PowerShell 2.0 and has no outer dependencies. Furthermore, it does not require any installation process.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Keynote #1 Troopers 2016</title>
      <link>https://insinuator.net/2016/03/keynote-%231-troopers-2016/</link>
      <pubDate>Thu, 31 Mar 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/03/keynote-%231-troopers-2016/</guid>
      <description>&lt;p&gt;The first Keynote directly after the Opening by Enno Rey was held by Ben Zevenbergen. At the beginning he pointed out that he is not a very technical guy rather he specialized in Information Law and a policy advisor to the European Parliament. Before he started to dive into his Keynote he talked about some rant story’s which happened to him while trying to make his point clear on previous conferences and that he came in peace to Troopers ;).&lt;/p&gt;</description>
    </item>
    <item>
      <title>Mind The Gap – Exploit Free Whitelisting Evasion Tactics</title>
      <link>https://insinuator.net/2016/03/mind-the-gap-exploit-free-whitelisting-evasion-tactics/</link>
      <pubDate>Thu, 31 Mar 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/03/mind-the-gap-exploit-free-whitelisting-evasion-tactics/</guid>
      <description>&lt;p&gt;At the Troopers 16 Casey Smith has given a talk about the gap in Application Whitelisting.&lt;/p&gt;&#xA;&lt;p&gt;Application Whitelisting is a technique that should prevent malware and unauthorized applications from running. Broadly speaking this is implemented by deciding if an application is trusted or not before executing it. Casey’s talk gave an understanding where this whitelisiting fails down.&lt;/p&gt;&#xA;&lt;p&gt;In his introduction about the architecture he reminded us: There is no perfect defense. It is important to understand how the defenses work and where they fail. In the difference to exploits, which can be patched, there is no possibility to patch architecture flaws.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Reverse Engineering a Digital Two-Way Radio</title>
      <link>https://insinuator.net/2016/03/reverse-engineering-a-digital-two-way-radio/</link>
      <pubDate>Thu, 31 Mar 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/03/reverse-engineering-a-digital-two-way-radio/</guid>
      <description>&lt;p&gt;In their talk “&lt;a href=&#34;https://www.troopers.de/events/troopers16/620_reverse_engineering_a_digital_two-way_radio/&#34;&gt;Reverse Engineering a Digital Two Way Radio&lt;/a&gt;” Travis Goodspeed and Christiane Ruetten presented the challenges they faced and overcame while reverse engineering “Tytera MD380”, a handheld transceiver for the Digital Mobile Radio (DMR) protocol.&lt;/p&gt;&#xA;&lt;p&gt;“Tytera MD380” is based around two chips: STM32F405 CPU with an ARM Cortex M4F core and Readout Device Protection and a HRC5000 baseband processor which implements the actual digital radio. While STM32F405 is fully documented, there is no documentation for HRC5000 publicly available but with the help of the Chinese community they were able to obtain the Chinese documentation.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Towards a LangSec-aware SDLC</title>
      <link>https://insinuator.net/2016/03/towards-a-langsec-aware-sdlc/</link>
      <pubDate>Thu, 31 Mar 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/03/towards-a-langsec-aware-sdlc/</guid>
      <description>&lt;p&gt;At the TROOPERS’15 Jacob l. Torrey held a track about LangSec-Aware Software Development Lifecycle. He talked about programming conventions and what tools can be used for enforcing the compliance. There is a lack of metrics to understand what make software more secure or less secure. His main goals was to show that LangSec has far-reaching impacts into software security and to give the audience a framework to transform the theory into practice. A SLDC should help to find bugs sooner in the development process and reduce defect rate in production thereby. A lower defect rate in production does not only improve security it also reduces costs.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Troopers Netmon</title>
      <link>https://insinuator.net/2016/03/troopers-netmon/</link>
      <pubDate>Thu, 31 Mar 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/03/troopers-netmon/</guid>
      <description>&lt;p&gt;Hi everybody,&lt;/p&gt;&#xA;&lt;p&gt;Christopher talked already about our WiFi Network during the &lt;a href=&#34;https://www.troopers.de/events/ipv6-security-summit-2016/672_building_a_reliable_and_secure_ipv6_wifi_network/&#34;&gt;IPv6 Security Summit&lt;/a&gt; and mentioned our monitoring system (we like to call “netmon”). As there were quite some people interested in the detailed setup and configuration, we would like to share the details with you. This year we used a widely known frontend called Grafana and as backend components InfluxDB and collectd. During Troopers the monitoring system was public reachable over IPv6 and provided statistics about Uplink Bandwidth, IP Protocol Distribution, Clients and Wireless Bands.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Generic RAID Reassembly using Block-Level Entropy</title>
      <link>https://insinuator.net/2016/03/generic-raid-reassembly-using-block-level-entropy/</link>
      <pubDate>Wed, 30 Mar 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/03/generic-raid-reassembly-using-block-level-entropy/</guid>
      <description>&lt;p&gt;&lt;img src=&#34;https://www.insinuator.net/wp-content/uploads/2016/03/FullSizeRender-209x300.jpg&#34; alt=&#34;DFRWS EU 2016 Talk Forensic Raid Recovery&#34;&gt;&lt;/p&gt;&#xA;&lt;p&gt;DFRWS EU 2016 Talk Forensic Raid Recovery&lt;/p&gt;&#xA;&lt;p&gt;We just presented our Paper “&lt;em&gt;Generic RAID Reassembly using Block-Level Entropy&lt;/em&gt;” at the &lt;em&gt;DFRWS EU 2016&lt;/em&gt; digital forensics conference (&lt;a href=&#34;http://www.dfrws.org/&#34;&gt;http://www.dfrws.org/&lt;/a&gt;). The article is about a new approach that we developed for forensic RAID recovery. Our technique calculates block-wise entropy all over the disks and uses generic heuristics on those to detect all the relevant RAID parameters such as stripe size, stripe map, disk order, and RAID type, that are needed to reassemble the RAID and make the data accessible again for forensic investigations (or just for data recovery).&lt;/p&gt;</description>
    </item>
    <item>
      <title>Medical Device Security: Hack or Hype</title>
      <link>https://insinuator.net/2016/03/medical-device-security-hack-or-hype/</link>
      <pubDate>Wed, 30 Mar 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/03/medical-device-security-hack-or-hype/</guid>
      <description>&lt;p&gt;Kevin Fu is an Associate Professor at the University of Michigan where he directs the Archimedes Center for Medical Device Security and cofounded Virta Labs. At Troopers 16 he held a talk in the field of his research: &lt;a href=&#34;https://www.troopers.de/events/troopers16/697_medical_device_security_hack_or_hype/&#34;&gt;medical device security&lt;/a&gt;.&lt;/p&gt;&#xA;&lt;p&gt;He started his talk with a brief introduction how he got started with medical device security and how it has changed since he started. Round about ten years ago he started dumpster diving for medical devices to investigate how they are protected and maintained. In 2006 he held his first talk about medical device security at the FDA. In 2008 he presented a wireless replay attack against a pacemaker. In 2013 concerns about medical device security became more and more mainstream when the television series homeland featured an episode where the pacemaker of the American vice president was attacked resulting in his death. Now, instead of dumpster diving for medical devices, he works together with clinicians and has a lab for testing devices. The communication with clinicians is very important for his work, so he visits hospitals with his student so that they can learn how the process works on the inside.&lt;/p&gt;</description>
    </item>
    <item>
      <title>IPv6 Security Summit – Track 2</title>
      <link>https://insinuator.net/2016/03/ipv6-security-summit-track-2/</link>
      <pubDate>Tue, 29 Mar 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/03/ipv6-security-summit-track-2/</guid>
      <description>&lt;p&gt;The Troopers experience will never be the same without the “&lt;a href=&#34;https://www.troopers.de/ipv6-security-summit/&#34;&gt;IPv6 summit&lt;/a&gt;”. It is one of kind of two-day special event where different security experts gather to discuss IPv6 current challenges. It addresses different topics ranging from a broad introduction of the IPv6 to how secure the protocol  is and what  the latest standards are.&lt;/p&gt;&#xA;&lt;p&gt;The summit is divided into 2 different tracks that run simultaneously. For the first day on the second track, &lt;em&gt;Christopher Werny&lt;/em&gt; and &lt;em&gt;Rafael Schaefer&lt;/em&gt; have carried out the first three sessions.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Troopers 16: Wireshark in IP version 6</title>
      <link>https://insinuator.net/2016/03/troopers-16-wireshark-in-ip-version-6/</link>
      <pubDate>Tue, 29 Mar 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/03/troopers-16-wireshark-in-ip-version-6/</guid>
      <description>&lt;p&gt;Wireshark in IP version 6 workshop was a part of IPv6 summit sessions of Troopers 16. It was held by Jeffery Carrell on the second day of IPv6 summit on Tuesday, the 15th of March.  The workshop was generally divided into two sections: a short introduction to IPv6 and analyzing some IPv6 packets on Wireshark.&lt;/p&gt;&#xA;&lt;p&gt;&lt;strong&gt;Introduction to IPv6&lt;/strong&gt;&lt;/p&gt;&#xA;&lt;p&gt;IPv6 protocol was defined at the end of 1990’s, mainly to provide a huge address pool after realizing that the world would run out of IPv4 addresses quickly. The work on IPv6 started before the introduction of NAT and Private addressing to IPv4, which are considered temporary solutions of IPv4 address shortage problem. IPv6 address consists of 128 bits, divided into 8 groups called &lt;em&gt;nibbles&lt;/em&gt;, &lt;em&gt;quibbles&lt;/em&gt; or &lt;em&gt;hextets&lt;/em&gt; separated by colons. Each nibble consists of four hexadecimal digits. The 128 bits address length provides 340 trillion trillion trillion addresses. An IPv6 address is divided into two parts: the left part is the network identifier while the right one is the host identifier. The default prefix is /64 which divided the IP address into two halves. An IPv6 address looks as follows: 2001:0db8:1010:61ab:f005:ba11:00da:11a5/64&lt;/p&gt;</description>
    </item>
    <item>
      <title>Attacking Next-Generation Firewalls</title>
      <link>https://insinuator.net/2016/03/attacking-next-generation-firewalls/</link>
      <pubDate>Mon, 28 Mar 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/03/attacking-next-generation-firewalls/</guid>
      <description>&lt;p&gt;Felix Wilhelm presented in his talk various ways to attack his new target – The PA-500 which is produced by Palo Alto Networks.&lt;/p&gt;&#xA;&lt;p&gt;He discovered vulnerabilities in 3 different exposed aspects of the device. The first vulnerability occurred inside of an unauthenticated API from the Management-Website which could only be accessed within the Admin Network. This vulnerability was a typical off-by-one Command Injection, which could be abused by reaching out to the API with a special client=wget Request.&lt;/p&gt;</description>
    </item>
    <item>
      <title>SDR and non-SDR tools for reverse engineering wireless systems</title>
      <link>https://insinuator.net/2016/03/sdr-and-non-sdr-tools-for-reverse-engineering-wireless-systems/</link>
      <pubDate>Mon, 28 Mar 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/03/sdr-and-non-sdr-tools-for-reverse-engineering-wireless-systems/</guid>
      <description>&lt;p&gt;Hey there!&lt;br&gt;&#xA;The God of frequencies Michael Ossmann visited us again this year at the &lt;a href=&#34;https://www.troopers.de/troopers16/&#34;&gt;TROOPERS16&lt;/a&gt; and showed us how to break another device using a specific setup.&lt;/p&gt;&#xA;&lt;p&gt;Last time he introduced the HackRF One to us (Read here:&lt;a href=&#34;https://www.insinuator.net/2014/08/hackrf-one-the-story-continues/&#34;&gt;https://www.insinuator.net/2014/08/hackrf-one-the-story-continues/&lt;/a&gt;), but this post is a short summary of his talk about “Rapid Radio Reversing”, he is a wireless security researcher, who makes hardware for hackers. Best known for the HackRF, Ubertooth, and Daisho projects, he founded Great Scott Gadgets in an effort to put exciting, new tools into the hands of innovative people.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Security Evaluation of Dual-Stack Systems [Troopers 2016 recap] (Part 1)</title>
      <link>https://insinuator.net/2016/03/security-evaluation-of-dual-stack-systems-troopers-2016-recap-part-1/</link>
      <pubDate>Mon, 28 Mar 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/03/security-evaluation-of-dual-stack-systems-troopers-2016-recap-part-1/</guid>
      <description>&lt;p&gt;Dear Readers of Insinuator,&lt;/p&gt;&#xA;&lt;p&gt;**tldr;**This blogpost presents a measurement study of a current security state regarding to open ports on a direct comparison of IPv4 and IPv6. The study analyses almost 58,000 dual-stacked domains in order to find discrepancies in applied security policies. We further discuss the potential reasons and, more importantly, the implications of the identified differences. &lt;strong&gt;\tldr;&lt;/strong&gt;&lt;/p&gt;&#xA;&lt;p&gt;For those of you who couldn’t participate at Troopers Conference 2016 in Heidelberg or watch my talk at the IPv6 Security Summit, I want to recap some of the most important parts of my research in this blogpost.&lt;/p&gt;</description>
    </item>
    <item>
      <title>The Joy of Sandbox Mitigations</title>
      <link>https://insinuator.net/2016/03/the-joy-of-sandbox-mitigations/</link>
      <pubDate>Mon, 28 Mar 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/03/the-joy-of-sandbox-mitigations/</guid>
      <description>&lt;p&gt;This year at TROOPERS16 in Heidelberg we welcomed James Forshaw for his talk about “&lt;a href=&#34;https://www.troopers.de/events/troopers16/644_the_joy_of_sandbox_mitigations/&#34;&gt;The Joy of Sandbox Mitigations&lt;/a&gt;“.&lt;/p&gt;&#xA;&lt;p&gt;He is a security researcher in Google’s Project Zero. He has been involved with computer hardware and software security for over 10 years looking at a range of different platforms and applications. With a great interest in logical vulnerabilities he has numerous disclosures in a wide range of products from web browsers to virtual machine breakouts as well as being a Pwn2Own and Microsoft Mitigation Bypass bounty winner. He has spoken at a number of security conferences including Black Hat USA, CanSecWest, Bluehat, HITB, and Infiltrate.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Reflections on the IPv6-only WiFi Experience during Troopers</title>
      <link>https://insinuator.net/2016/03/reflections-on-the-ipv6-only-wifi-experience-during-troopers/</link>
      <pubDate>Fri, 25 Mar 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/03/reflections-on-the-ipv6-only-wifi-experience-during-troopers/</guid>
      <description>&lt;p&gt;Hello,&lt;/p&gt;&#xA;&lt;p&gt;Troopers is (unfortunately) over. It was a blast (but I may be biased ;-))! After things have settled, I want to take the opportunity to reflect my thoughts and impressions on the IPv6-only WiFi we had deployed during the conference. To make sure that everybody is on the same page let’s start at the beginning.&lt;/p&gt;&#xA;&lt;p&gt;In the last couple of years we had provided Dual-Stack connectivity on the main “Troopers” SSID but also had an additional IPv6-only SSID. This year we decided to spice things up and made the “Troopers“ SSID IPv6-only (with NAT64) while providing Dual-Stack connectivity on the “Legacy“ SSID. We wanted to get a feeling how many clients and applications can work properly in an IPv6-only environment. We intentionally didn’t announce it vastly beforehand, hoping that attendees would just connect to the main SSID without noticing anything. We were aware that some applications might expose issues but, as I said , we wanted to get a feeling to which degree problems actually occured.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Troopers 16 – Taking the Badge to yet Another Level!</title>
      <link>https://insinuator.net/2016/03/troopers-16-taking-the-badge-to-yet-another-level/</link>
      <pubDate>Sun, 20 Mar 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/03/troopers-16-taking-the-badge-to-yet-another-level/</guid>
      <description>&lt;p&gt;Real men used to wear pink pagers, but that’s the past and recently it was time for Troopers 16. Meaning: Real Troopers wear awesome Badges! And, from the feedback we got, they did!&lt;br&gt;&#xA;Troopers might be over, but the era of the TR16 Badge is seemingly just beginning. As such, here’s a quick insight into the badge!&lt;/p&gt;&#xA;&lt;p&gt;To start, this is the first of (at least) three blogposts covering the badge. As we’re currently in the middle of stripping and cleaning our source code repository, this post now will not cover the firmware. The stripping is not about hiding something, but as we used an Open Source &lt;a href=&#34;https://en.wikipedia.org/wiki/Real-time_operating_system&#34;&gt;RTOS&lt;/a&gt; our repo currently contains modules, which are for completely other architectures.&lt;br&gt;&#xA;In addition we needed a few workarounds while getting the badge up and running for the conference, following our own hacking sessions, there will be a dedicated post concerned with hardware modifications and hacks which can be performed.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Troopers16 – GSM Network</title>
      <link>https://insinuator.net/2016/03/troopers16-gsm-network/</link>
      <pubDate>Wed, 16 Mar 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/03/troopers16-gsm-network/</guid>
      <description>&lt;p&gt;Hello Troopers!&lt;/p&gt;&#xA;&lt;p&gt;only a few seconds left! As a short reminder, there is a GSM network running on Troopers 2016. It should be available in the whole building. To attend the network you need to&lt;/p&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;Get a SIM Card @Troopers_Desk&lt;/li&gt;&#xA;&lt;li&gt;Put it in your phone&lt;/li&gt;&#xA;&lt;li&gt;Start the phone&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;p&gt;That’s it!&lt;/p&gt;&#xA;&lt;p&gt;You can always dial &lt;strong&gt;*#100#&lt;/strong&gt; to get your phone number. All further information (and a phonebook) you’ll find on gsm.troopers.de, but here again a brief summary:&lt;/p&gt;</description>
    </item>
    <item>
      <title>TelcoSecDay 2016 – Final Agenda and more</title>
      <link>https://insinuator.net/2016/03/telcosecday-2016-final-agenda-and-more/</link>
      <pubDate>Thu, 10 Mar 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/03/telcosecday-2016-final-agenda-and-more/</guid>
      <description>&lt;p&gt;Only a few days left until Troopers! I’d like to use this chance to publish the final agenda of &lt;a href=&#34;https://www.troopers.de/events/troopers16/580_telcosecday_2016_invitation_only/&#34;&gt;TelcoSecDay 2016&lt;/a&gt;. We will start around 8:30am and will finish at about 6:15pm. After this, we will have a shared dinner in the historic center of Heidelberg. The exact location will be announced during the TSD.&lt;/p&gt;&#xA;&lt;p&gt;8:30: Opening Remarks&lt;br&gt;&#xA;9:00: &lt;a href=&#34;https://www.troopers.de/events/troopers16/606_telcosecday_new_age_phreacking_magic_tricks_for_wholesale_fraud/&#34;&gt;David Batanero – New Age Phreaking: Magic tricks for wholesale fraud&lt;/a&gt;&lt;br&gt;&#xA;9:45: &lt;a href=&#34;https://www.troopers.de/events/troopers16/657_towards_carrier_based_imsi_catcher_detection/&#34;&gt;Adrian Dabrowski – Towards Carrier Based IMSI Catcher Detection&lt;/a&gt;&lt;br&gt;&#xA;10:30: Break&lt;br&gt;&#xA;11:00: &lt;a href=&#34;https://www.troopers.de/events/troopers16/653_assaulting_ipx_diameter_roaming_network/&#34;&gt;Alexandre De Oliveira – Assaulting IPX Diameter roaming networks&lt;/a&gt;&lt;br&gt;&#xA;11:45: &lt;a href=&#34;https://www.troopers.de/events/troopers16/654_the_known_unknowns_of_ss7_and_beyond/&#34;&gt;Rao Siddharth – The known and unknowns of SS7 and beyond&lt;/a&gt;&lt;br&gt;&#xA;12:30: &lt;a href=&#34;https://www.troopers.de/events/troopers16/652_rucki_zucki_scanning_tool/&#34;&gt;Joao Collier de Mendonca – “rucki zucki” scanning tool&lt;/a&gt;&lt;br&gt;&#xA;13:00: Lunch&lt;br&gt;&#xA;14:00: &lt;a href=&#34;https://www.troopers.de/events/troopers16/658_open_source_network_elements_for_security_analysis_of_mobile_networks/&#34;&gt;Harald Welte – Open Source Network Elements for Security Analysis of Mobile Networks&lt;/a&gt;&lt;br&gt;&#xA;14:45: &lt;a href=&#34;https://www.troopers.de/events/troopers16/659_advance_apt_attribution_for_researchers/&#34;&gt;Rahul Sasi – Advance APT Attribution for researchers&lt;/a&gt;&lt;br&gt;&#xA;15:30: Break&lt;br&gt;&#xA;16:00: &lt;a href=&#34;https://www.troopers.de/events/troopers16/660_dont_connect_to_my_4g_base_station_investigating_info_leaks_in_4g_basebands/&#34;&gt;Ravi and Altaf Shaik – Don’t connect to my 4G base station: investigating info leaks in 4G basebands&lt;/a&gt;&lt;br&gt;&#xA;16:45: Talk from some guy with interest in telco sec&lt;br&gt;&#xA;17:15: Break&lt;br&gt;&#xA;17:30: &lt;a href=&#34;https://www.troopers.de/events/troopers16/662_observations_on_mobile_communication_platforms/&#34;&gt;Dieter Spaar – Observations on mobile communication platforms&lt;/a&gt;&lt;/p&gt;</description>
    </item>
    <item>
      <title>Troopers16 – GSM Network</title>
      <link>https://insinuator.net/2016/03/troopers16-gsm-network/</link>
      <pubDate>Thu, 03 Mar 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/03/troopers16-gsm-network/</guid>
      <description>&lt;p&gt;Same as &lt;a href=&#34;https://www.insinuator.net/2015/03/gsmtroopers/&#34;&gt;last year&lt;/a&gt;, we will have a GSM based telephony network running at Troopers 2016. The network will be a closed network, which means it only can be used with Troopers SIM cards and between Troopers attendees only. You can use the network for&lt;/p&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;doing Voice Calls&lt;/li&gt;&#xA;&lt;li&gt;send Short Messages (SMS)&lt;/li&gt;&#xA;&lt;li&gt;have Internet Access&lt;/li&gt;&#xA;&lt;li&gt;submit Challenge Tokens (see below)&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;p&gt;In contrast to last year, you will need a Troopers SIM card to attend the network with your cellphone. The SIM cards will be handed out at the registration desk; if you have questions you always can contact me or Kevin Redon (thanks again for assisting us).&lt;/p&gt;</description>
    </item>
    <item>
      <title>Multicast Based IPv6 Neighbor Spoofing / Response Behavior on Cisco Devices</title>
      <link>https://insinuator.net/2016/03/multicast-based-ipv6-neighbor-spoofing-/-response-behavior-on-cisco-devices/</link>
      <pubDate>Tue, 01 Mar 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/03/multicast-based-ipv6-neighbor-spoofing-/-response-behavior-on-cisco-devices/</guid>
      <description>&lt;p&gt;Dear readers,&lt;/p&gt;&#xA;&lt;p&gt;today we want to examine the behavior of Cisco devices when they receive spoofed IPv6 Neighbor Advertisement packets from an untrusted system pretending to be the default router for the local segment. We start with a quick refresher how Cisco devices behave in the legacy (IPv4) world when they receive a spoofed broadcast ARP packet containing the IP address of the device but with a different MAC address, followed by a discussion of the corresponding behavior in the IPv6 world.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Observations from the Cisco Live Europe 2016 Wifi Infrastructure</title>
      <link>https://insinuator.net/2016/02/observations-from-the-cisco-live-europe-2016-wifi-infrastructure/</link>
      <pubDate>Tue, 16 Feb 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/02/observations-from-the-cisco-live-europe-2016-wifi-infrastructure/</guid>
      <description>&lt;p&gt;Good Evening,&lt;/p&gt;&#xA;&lt;p&gt;Enno and I spent the first day on Cisco Live Europe in Berlin today attending the “Advanced Practical Knowledge for Enterprise Deploying IPv6” technical breakout held by &lt;a href=&#34;https://twitter.com/bckcntryskr&#34;&gt;Tim Martin&lt;/a&gt; and &lt;a href=&#34;https://www.ciscolive.com/online/connect/speakerDetail.ww?PERSON_ID=B87EDE562B1002BDCC3504AD38E52492&#34;&gt;Jim Bailey&lt;/a&gt;. It was a good breakout session, and thanks again Tim for the honorable mention of our work in your slides! We really appreciate it. Like &lt;a href=&#34;https://www.insinuator.net/2015/01/observations-from-the-cisco-live-europe-wifi-infrastructure/&#34;&gt;last year&lt;/a&gt;, we were curious how the Wifi network was setup this year as I face a corresponding task for &lt;a href=&#34;https://www.troopers.de/troopers16/&#34;&gt;Troopers&lt;/a&gt; in March, with some &lt;a href=&#34;https://www.insinuator.net/2016/02/tr16-ipv6-security-summit-teaser-building-a-reliable-and-secure-ipv6-wifi-network/&#34;&gt;major changes&lt;/a&gt; in comparison to the last years. The Wifi infastructure in Berlin looked very similar to the one from last year in Milan, we had the “standard” Cisco Live SSID as well as an IPv6-only (with NAT64 as translation mechanism) SSID. The standard SSID looked identical to last year with the exception that now the &lt;a href=&#34;http://www.cisco.com/c/en/us/td/docs/wireless/controller/technotes/8-0/IPV6_DG.html#pgfId-76925&#34;&gt;RA Throttling&lt;/a&gt; feature on the WLC was active from the beginning! Neither the M nor the O flag are set which means that my client has to use the legacy protocol to resolve AAAA records. As I am running Windows, it does not support &lt;a href=&#34;https://tools.ietf.org/html/rfc6106&#34;&gt;RA option 25 &lt;/a&gt; but the option wasn’t included in the RAs anyway. The preference was configured to the default “medium”. One thing I noticed, but haven’t had a chance to ask &lt;a href=&#34;https://twitter.com/ayourtch&#34;&gt;Andrew Yourtchenko&lt;/a&gt;, was that for the legacy (IPv4) connection they use HSRPv2 as an FHRP protocol (indicated by the MAC address &lt;a href=&#34;http://www.cisco.com/c/en/us/td/docs/ios-xml/ios/ipapp_fhrp/configuration/xe-3s/fhp-xe-3s-book/fhp-hsrp-v2.html&#34;&gt;00:00:0c:9f:f0:01&lt;/a&gt; I received from the gateway) but for IPv6 I received Router Advertisements from two different MAC addresses (which both belong to Cisco, so I don’t think anyone sent spoofed RAs).  I am curious about the reasoning for this approach 🙂&lt;br&gt;&#xA;What i also encountered was that the Peer-to-Peer Blocking feature was apparently not enabled on the SSID as I was able to enumerate approx. 1600 active clients at the time. No worries, I haven’t done anything else, just was curious whether the feature was activated or not…&lt;/p&gt;</description>
    </item>
    <item>
      <title>#TR16 IPv6 Security Summit Teaser: Basic IPv6 Attacks &amp; Defenses Workshop</title>
      <link>https://insinuator.net/2016/02/%23tr16-ipv6-security-summit-teaser-basic-ipv6-attacks-defenses-workshop/</link>
      <pubDate>Sat, 13 Feb 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/02/%23tr16-ipv6-security-summit-teaser-basic-ipv6-attacks-defenses-workshop/</guid>
      <description>&lt;p&gt;Dear Readers,&lt;/p&gt;&#xA;&lt;p&gt;It’s me again with another teaser for an upcoming workshop at the &lt;a href=&#34;https://www.troopers.de/ipv6-security-summit/&#34;&gt;IPv6 Security Summit&lt;/a&gt;. This one is a classic! If you happen to deploy IPv6 in your environment in the near future, but didn’t had the time to think about the security implications, this &lt;a href=&#34;https://www.troopers.de/events/ipv6-security-summit-2016/614_basic_ipv6_attacks__defenses_hands-on_workshop/&#34;&gt;workshop&lt;/a&gt; is the right place to start.&lt;/p&gt;&#xA;&lt;p&gt;We will start the workshop with a quick refresher of the core behavior of IPv6 to make sure that every attendee is on the same page. Before we start discussing and demonstrating various IPv6 attacks, we dive into (a little more abstract) topic of why IPv6 security actually isn’t that easy to implement. We will continue with IPv6 attacks targeted at the local link. Rafael and I will introduce commonly used IPv6 attack tools as well as performing various attacks in a dedicated lab environment. Every attendee is encouraged to participate in these exercises.  We will provide you with the necessary tools; you just have to bring a laptop with (ideally) Linux installed. We will prepare some virtual machines including VMware Player in case your corporate laptop runs Windows.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Multiple Address Family OSPFv3</title>
      <link>https://insinuator.net/2016/02/multiple-address-family-ospfv3/</link>
      <pubDate>Wed, 10 Feb 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/02/multiple-address-family-ospfv3/</guid>
      <description>&lt;p&gt;Dear Readers,&lt;/p&gt;&#xA;&lt;p&gt;today I want to talk about OSPFv3. I won’t cover the glory details of &lt;a href=&#34;http://tools.ietf.org/html/rfc5340&#34;&gt;OSPFv3&lt;/a&gt;, there are smarter guys than me out there who did that &lt;a href=&#34;http://packetlife.net/blog/2010/mar/2/ospfv2-versus-ospfv3/&#34;&gt;already&lt;/a&gt; 😉 and there are great resources to familiarize yourself with the protocol. However, it should be noted that OSPFv3 is not only OSPF for IPv6, OSPFv3 brought some major enhancements compared to OSPFv2. Wouldn’t it be cool to benefit from the enhancements in the IPv4 world as well?&lt;/p&gt;</description>
    </item>
    <item>
      <title>#TR16 IPv6 Security Summit Teaser: First-Hop-Security on HP Network Devices</title>
      <link>https://insinuator.net/2016/02/%23tr16-ipv6-security-summit-teaser-first-hop-security-on-hp-network-devices/</link>
      <pubDate>Tue, 09 Feb 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/02/%23tr16-ipv6-security-summit-teaser-first-hop-security-on-hp-network-devices/</guid>
      <description>&lt;p&gt;Hello Everybody,&lt;/p&gt;&#xA;&lt;p&gt;Today I want to give you a little teaser about my upcoming talk at the &lt;a href=&#34;https://www.troopers.de/ipv6-security-summit/&#34;&gt;IPv6 Security Summit&lt;/a&gt; about &lt;em&gt;First-Hop-Security&lt;/em&gt; on HP devices. In the past I presented on about First-Hop-Security in the &lt;a href=&#34;https://www.troopers.de/events/troopers13/363_securing_ipv6_in_the_cisco_space/&#34;&gt;Cisco&lt;/a&gt; realm and in &lt;a href=&#34;https://www.troopers.de/events/troopers15/482_ipv6_first_hop_security_in_virtualized_environments/&#34;&gt;virtualized e&lt;/a&gt;nvironments. Until recently, Cisco was mostly the only vendor who had a sufficient implementation of various IPv6 security features on their access-layer switches, but HP closed the gap considerably and it’s time to have an in-depth look at their implementation of those features.&lt;/p&gt;</description>
    </item>
    <item>
      <title>#TR16 IPv6 Security Summit Teaser: Building a Reliable and Secure IPv6 WiFi Network</title>
      <link>https://insinuator.net/2016/02/%23tr16-ipv6-security-summit-teaser-building-a-reliable-and-secure-ipv6-wifi-network/</link>
      <pubDate>Mon, 08 Feb 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/02/%23tr16-ipv6-security-summit-teaser-building-a-reliable-and-secure-ipv6-wifi-network/</guid>
      <description>&lt;p&gt;Hi everyone,&lt;/p&gt;&#xA;&lt;p&gt;some of you may have seen my last &lt;a href=&#34;https://www.insinuator.net/2016/02/dhcpv6-option-52-on-cisco-dhcpv6-server/&#34;&gt;blog post&lt;/a&gt; about the preparation of the Troopers network. Today I want to give you a little teaser on what to expect for the &lt;a href=&#34;https://www.troopers.de/events/ipv6-security-summit-2016/672_case_study_building_a_secure_ipv6_guest_wifi_network/&#34;&gt;talk&lt;/a&gt; I will present during the IPv6 Security Summit. As the title implies, it’s not only about building a secure IPv6 WiFi, but also a reliable one. One might think that there aren’t many differences in comparison to IPv4, but the heavy reliance on multicast of IPv6 does have implications for Wi-Fi networks in general.&lt;/p&gt;</description>
    </item>
    <item>
      <title>DHCPv6 Option 52 on Cisco DHCPv6 Server</title>
      <link>https://insinuator.net/2016/02/dhcpv6-option-52-on-cisco-dhcpv6-server/</link>
      <pubDate>Sat, 06 Feb 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/02/dhcpv6-option-52-on-cisco-dhcpv6-server/</guid>
      <description>&lt;p&gt;Hi,&lt;/p&gt;&#xA;&lt;p&gt;I am currently preparing the &lt;a href=&#34;https://www.troopers.de&#34;&gt;Troopers&lt;/a&gt; network in a lab environment to ensure that we all will have a smooth Wi-Fi experience during Troopers. I wanted to spice things up a little bit for the Wi-Fi deployment (more on that in a following blogpost) and get rid of IPv4 wherever possible. Our Wi-Fi infrastructure consists of typical Cisco Access Points (1602) and a 2504 Wireless LAN Controller. Beginning with WLC image 8.0 it is finally supported to establish the CAPWAP tunnel between the AP and the WLC over IPv6, which is awesome and I wanted to implement it right away.&lt;/p&gt;</description>
    </item>
    <item>
      <title>TelcoSecDay 2016 – Second Round of Talks</title>
      <link>https://insinuator.net/2016/02/telcosecday-2016-second-round-of-talks/</link>
      <pubDate>Wed, 03 Feb 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/02/telcosecday-2016-second-round-of-talks/</guid>
      <description>&lt;p&gt;I am very happy to announce the second round of talks for the &lt;a href=&#34;https://www.troopers.de/events/troopers16/580_telcosecday_2016_invitation_only/&#34;&gt;TelcoSecDay 2016&lt;/a&gt;. As mentioned in my &lt;a href=&#34;https://www.insinuator.net/2016/01/telcosecday-first-round-of-talks/&#34;&gt;previous post&lt;/a&gt; it will take place on March 15th. All invitations should be out by now; if you think you can contribute to the group and you are willing to join us – please let me know (&lt;a href=&#34;mailto:hschmidt@ernw.de&#34;&gt;hschmidt@ernw.de&lt;/a&gt;).&lt;/p&gt;&#xA;&lt;p&gt;Still, not all talks are confirmed but the newly published talks will provide an idea about TSD 2016 and its discussions.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Pentesting with Metasploit #TR16 Training</title>
      <link>https://insinuator.net/2016/02/pentesting-with-metasploit-%23tr16-training/</link>
      <pubDate>Tue, 02 Feb 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/02/pentesting-with-metasploit-%23tr16-training/</guid>
      <description>&lt;p&gt;In this year’s MSF training we will guide you through the typical steps of the pentest cycle: information gathering, attacking and looting your targets. For each step, demos and exercises will help you deepen and test your newly acquired knowledge. In addition to the typical penetration-test scenarios you will also learn several advanced aspects of the framework such as: how writing your own metasploit modules works, how to export payloads and make them undetected. With a final exercise each day you can finally challenge yourself and apply what you have learned!&lt;/p&gt;</description>
    </item>
    <item>
      <title>Web Hacking Special Ops Workshop @ TR16</title>
      <link>https://insinuator.net/2016/01/web-hacking-special-ops-workshop-@-tr16/</link>
      <pubDate>Tue, 26 Jan 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/01/web-hacking-special-ops-workshop-@-tr16/</guid>
      <description>&lt;p&gt;&lt;strong&gt;Trooper!&lt;/strong&gt;&lt;/p&gt;&#xA;&lt;p&gt;You passed Hacking 1on1 with flying colors?&lt;/p&gt;&#xA;&lt;p&gt;You evade web application firewalls as they would be opened doors?&lt;/p&gt;&#xA;&lt;p&gt;You have successfully exploitated CVE-2015-8769?&lt;/p&gt;&#xA;&lt;p&gt;Then it’s time for the next challenge! Follow us down the rabbit hole to the not so well known attacks against modern web applications.&lt;/p&gt;&#xA;&lt;p&gt;At Troopers16 we will be presenting the second iteration of our WebHackingSpecialOps workshop in which more advanced techniques to break current web application technologies will be explained. On the first day there will be an introduction that gives a quick overview on the well-known attacks like SQLi, XSS and XSRF. Then attacks will be shown that build upon these “old” vectors including blind/clientside SQLi, NoSQLi and some specialties on NodeJS, the javascript based server-side runtime. Next to these technical topics several formal subjects like 3rd library handling and a guideline on how to deploy TLS in a secure way will be given. Especially the 3rd party library chapter since they have become more and more relevant, as in the near past several major vulnerabilities in such libraries were found which gave attackers the chance to break web applications that were based on these. This shows that even though developers do a great job and developer companies get familiar with secure development lifecycles, there are still problems depending on the used technologies that cannot be addressed easily. One example of such a vulnerability is the object deserialization flaw in the Apache Commons Collections library, which was discovered at the beginning of 2015 and got attention in November, when two researchers presented their &lt;a href=&#34;http://frohoff.github.io/appseccali-marshalling-pickles/&#34;&gt;talk on AppSecCali2015&lt;/a&gt; and showed how easy remote code execution can be done through this kind of flaw. The details of all kind of object deserialization (as almost all current scripting/high level programming languages support this feature) will be part of our course. Next to these topics a deep-dive into current crypto algorithms, their usecases concerning webapplications and their flaws will be given. Within every part of this course several demos and hands-on exercises will be done, so every attendee will be able to apply new knowledge directly. Don’t miss this chance to improve, Trooper!&lt;/p&gt;</description>
    </item>
    <item>
      <title>Hacking 101 Training at TROOPERS16</title>
      <link>https://insinuator.net/2016/01/hacking-101-training-at-troopers16/</link>
      <pubDate>Mon, 25 Jan 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/01/hacking-101-training-at-troopers16/</guid>
      <description>&lt;p&gt;This year’s &lt;a href=&#34;https://www.troopers.de/events/troopers16/572_hacking_101/&#34;&gt;Hacking 101&lt;/a&gt; workshop at TROOPERS16 will give attendees an insight into the hacking techniques required for penetration testing. These techniques will cover various topics like information gathering, network mapping, vulnerability scanning, web application hacking, low-level exploitation and more.&lt;/p&gt;&#xA;&lt;p&gt;During this workshop you will learn, step by step, a testing methodology that is applicable to the majority of scenarios. So imagine you have to assess the security of a system running on the Internet. How would you start? First, you need a good understanding about the target, including running services or related systems. Just scanning an IP will most likely not reveal a lot of information about the system. The gathered information may help you to identify communication relations of services that could include vulnerabilities. A brief understanding of the target and it’s related systems/services/applications will make scanning and identifying vulnerabilities a lot easier and more effective. Then, the last step will be the exploitation of the identified vulnerabilities, with the ultimate aim to get access to the target system and pivot to other, probably internal, systems and resources.&lt;/p&gt;</description>
    </item>
    <item>
      <title>32C3 Recap – Part 2</title>
      <link>https://insinuator.net/2016/01/32c3-recap-part-2/</link>
      <pubDate>Sat, 16 Jan 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/01/32c3-recap-part-2/</guid>
      <description>&lt;p&gt;Hello everybody and welcome to the second part of our 32C3 recap!&lt;/p&gt;&#xA;&lt;p&gt;In case you didn’t see &lt;a href=&#34;http://www.insinuator.net/2016/01/32c3-recap-part1/&#34;&gt;the first part&lt;/a&gt;, make sure to check it out 😉&lt;/p&gt;&#xA;&lt;h2 id=&#34;logjam&#34;&gt;Logjam&lt;/h2&gt;&#xA;&lt;p&gt;by **Nadia Heninger &amp;amp; Alex Halderman&lt;br&gt;&#xA;**&lt;a href=&#34;https://media.ccc.de/v/32c3-7288-logjam_diffie-hellman_discrete_logs_the_nsa_and_you&#34;&gt;Video&lt;/a&gt; | &lt;a href=&#34;https://lab.dsst.io/32c3-slides/slides/7288.pdf&#34;&gt;Slides&lt;/a&gt;&lt;/p&gt;&#xA;&lt;p&gt;This talk was held by Nadia Heninger and Alex Halderman on the second day of the congress. Both work in academic and the field of cryptology. They talked about the “Logjam”-Attack they and several colleagues discovered and published in may of 2014. They started their talk by explaining how they uncovered the vulnerability which was quite interesting since Logjam was no breaking news anymore. And well it was inspired by the congress of the year before, 31C3. The research was conducted because they got curious how the NSA might be able to decrypt VPN traffic as stated by Jacob Applebaum and Laura Poitras in their “reconstructing narratives” talk.&lt;/p&gt;</description>
    </item>
    <item>
      <title>TelcoSecDay – First Round of Talks</title>
      <link>https://insinuator.net/2016/01/telcosecday-first-round-of-talks/</link>
      <pubDate>Sat, 16 Jan 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/01/telcosecday-first-round-of-talks/</guid>
      <description>&lt;p&gt;Dear all,&lt;br&gt;&#xA;This year the &lt;a href=&#34;https://www.troopers.de/events/troopers16/580_telcosecday_2016_invitation_only/&#34;&gt;TelcoSecDay&lt;/a&gt; will take place on March 15th. For those of you who does not know about: the TelcoSecDay it is a sub-event of &lt;a href=&#34;http://www.troopers.de&#34;&gt;Troopers&lt;/a&gt; bringing together researchers, vendors and practitioners from the telecommunication / mobile security field.&lt;/p&gt;&#xA;&lt;p&gt;The event is celebrating its 5th anniversary now, that’s why I’d like to say “thank you” to everybody taking part at this very great discussion round in the last few years. We always had a lot of very good feedback and interesting discussions and the increasing participation list of operators from year to year says (almost) everything!&lt;/p&gt;</description>
    </item>
    <item>
      <title>5th Round of TROOPERS16 Talks Accepted</title>
      <link>https://insinuator.net/2016/01/5th-round-of-troopers16-talks-accepted/</link>
      <pubDate>Thu, 14 Jan 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/01/5th-round-of-troopers16-talks-accepted/</guid>
      <description>&lt;p&gt;Happy 2016 everyone! We are &lt;strong&gt;exactly&lt;/strong&gt; 2 months away from the start of TROOPERS16!! Speakers and Trainers across the globe are polishing (or in some cases creating) their PowerPoints to use while delivering their highly technical and entertaining talks. While we here at TR HQ are busy tweaking orders, creating challenges to boggle the mind and test your skills, and of course working on some top secret fun. 😉&lt;/p&gt;&#xA;&lt;p&gt;#BestWeekEver&lt;/p&gt;&#xA;&lt;p&gt;Your TROOPERS Team&lt;/p&gt;</description>
    </item>
    <item>
      <title>32C3 Recap – Part1</title>
      <link>https://insinuator.net/2016/01/32c3-recap-part1/</link>
      <pubDate>Fri, 08 Jan 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/01/32c3-recap-part1/</guid>
      <description>&lt;p&gt;Every year a group of us are happy to use the holidays to travel to Hamburg to meet other people and learn something new at the 32C3.&lt;/p&gt;&#xA;&lt;p&gt;In this small series we’ll present you recaps of some talks we found most interesting, but you also should make sure to watch the recording of them. 😉&lt;/p&gt;&#xA;&lt;h2 id=&#34;beyond-your-cable-modem--how-to-not-do-docsis-networks&#34;&gt;Beyond your cable modem – How to not do DOCSIS networks&lt;/h2&gt;&#xA;&lt;p&gt;by **Alexander Graf&lt;br&gt;&#xA;**&lt;a href=&#34;https://media.ccc.de/v/32c3-7133-beyond_your_cable_modem&#34;&gt;Video&lt;/a&gt;&lt;/p&gt;&#xA;&lt;p&gt;Alexander Graf presents (insecurity) insights on how cable modems work and connect to the ISP.&lt;/p&gt;</description>
    </item>
    <item>
      <title>DPRK’s RedStar OS on 32c3</title>
      <link>https://insinuator.net/2015/12/dprks-redstar-os-on-32c3/</link>
      <pubDate>Wed, 30 Dec 2015 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2015/12/dprks-redstar-os-on-32c3/</guid>
      <description>&lt;p&gt;Niklaus and me had the chance to talk about our research on RedStar OS on the 32nd Chaos Communication Congress in Hamburg this year. You can see the talk online at &lt;a href=&#34;https://media.ccc.de/v/32c3-7174-lifting_the_fog_on_red_star_os#video&#34;&gt;media.ccc.de&lt;/a&gt; or on &lt;a href=&#34;https://www.youtube.com/watch?v=KTBemKiSgWI&#34;&gt;Youtube&lt;/a&gt;.&lt;/p&gt;&#xA;&lt;p&gt;We talked about the details of the watermarking mechanism that &lt;a href=&#34;https://www.insinuator.net/2015/07/redstar-os-watermarking/&#34;&gt;we found in July&lt;/a&gt; and additional features of RedStar OS like it’s “Virus Scanner” and the system architecture. During the days after our talk we were able to find watermarks applied by RedStar OS in the wild on some sites on the Internet. We can confirm at least 7 different instances of RedStar OS that have applied watermarks to JPGs. Cleaning up the data is work in progress and we will get back to you with the results! Niklaus has put our presentation and additional resources in the &lt;a href=&#34;https://github.com/takeshixx/redstar-tools&#34;&gt;git&lt;/a&gt;. Feel free to join us in our research and make the world a safer place!&lt;/p&gt;</description>
    </item>
    <item>
      <title>#TR16 IPv6 Security Summit – New Talks Added</title>
      <link>https://insinuator.net/2015/12/%23tr16-ipv6-security-summit-new-talks-added/</link>
      <pubDate>Wed, 23 Dec 2015 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2015/12/%23tr16-ipv6-security-summit-new-talks-added/</guid>
      <description>&lt;p&gt;In the interim we’ve worked on the agenda of next year’s &lt;em&gt;&lt;a href=&#34;https://www.troopers.de/ipv6-security-summit/&#34;&gt;IPv6 Security Summit&lt;/a&gt;&lt;/em&gt; (for those not familiar with the event, &lt;a href=&#34;https://www.troopers.de/events/troopers15/322_ipv6_security_summit/&#34;&gt;here’s the 2015 edition&lt;/a&gt; and &lt;a href=&#34;https://www.troopers.de/events/troopers14/372_ipv6_security_summit/&#34;&gt;here the one of 2014&lt;/a&gt;), and some new talks have been added.&lt;/p&gt;&#xA;&lt;p&gt;&lt;strong&gt;Rafael Schaefer: Advanced IPv6 Attacks Using Chiron. Hands-On Workshop&lt;/strong&gt;&lt;/p&gt;&#xA;&lt;p&gt;Outline: During the IPv6 Security Summit at Troopers 14, &lt;a href=&#34;http://www.secfu.net/tools-scripts/&#34;&gt;Chiron&lt;/a&gt;, an all-in-one IPv6 penetration testing framework was released publicly for first time. Since then, the advanced features of Chiron were used to discover some 0-day evasion techniques against high-end commercial and open-source Intrusion Detection / Prevention Systems. Moreover, for Troopers 15 it was enhanced with new features, like advanced MLD support and a fake DHCPv6 server, which can be combined with its other features, like the use of arbitrary Extension Headers and fragmentation to leverage really advanced attacks.&lt;br&gt;&#xA;In this workshop, after a quick refreshing to the basic capabilities of Chiron, we will focus on the advanced IPv6 functionalities that the framework offers. We will not only show how to reproduce the latest published IPv6 attacks, but moreover, how you can create your own arbitrary IPv6 attacking scenarios for your own security assessments or penetration testing purposes. A lab will be set up in order not only to reproduce the presented techniques, but to also try your skills and – why not – to discover your own 0-day techniques :).&lt;/p&gt;</description>
    </item>
    <item>
      <title>4th Round of TROOPERS16 Talks Accepted</title>
      <link>https://insinuator.net/2015/12/4th-round-of-troopers16-talks-accepted/</link>
      <pubDate>Tue, 22 Dec 2015 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2015/12/4th-round-of-troopers16-talks-accepted/</guid>
      <description>&lt;p&gt;As we come to the end of the year we can’t help but take a moment to thank all of your who made TROOPERS15 special! It just makes us all the more pumped to kick it up a notch for TROOPERS16!! #BestWeekEver&lt;/p&gt;&#xA;&lt;p&gt;Happy Holiday and much Joy to you in the New Year!&lt;/p&gt;&#xA;&lt;p&gt;Your TROOPERS Team&lt;/p&gt;&#xA;&lt;p&gt;===&lt;/p&gt;&#xA;&lt;p&gt;Aaron Zauner: &lt;a href=&#34;https://www.troopers.de/events/troopers16/609_bettercrypto_three_years_in/&#34;&gt;BetterCrypto: three years in&lt;/a&gt;&lt;br&gt;&#xA;&lt;strong&gt;FIRST TIME TROOPERS SPEAKER&lt;/strong&gt;&lt;/p&gt;&#xA;&lt;p&gt;The BetterCrypto Project started out in the fall of 2013 as a collaborative community effort by systems engineers, security engineers, developers and cryptographers to build up a sound set of recommendations for strong cryptography and privacy enhancing technologies catered towards the operations community in the face of overarching wiretapping and data-mining by nation-state actors. The project has since evolved with a lot of positive feedback from the open source and operations community in general with input from various browser vendors, linux distribution security teams and researchers.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Teaser on the TROOPERS16 Incident Analysis Workshop: Analyzing the current Spam Flood</title>
      <link>https://insinuator.net/2015/12/teaser-on-the-troopers16-incident-analysis-workshop-analyzing-the-current-spam-flood/</link>
      <pubDate>Fri, 18 Dec 2015 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2015/12/teaser-on-the-troopers16-incident-analysis-workshop-analyzing-the-current-spam-flood/</guid>
      <description>&lt;p&gt;As we are giving another round of our Incident &lt;a href=&#34;https://www.troopers.de/events/troopers16/566_incident_analysis/&#34;&gt;Analysis workshop&lt;/a&gt; at &lt;a href=&#34;https://www.troopers.de/troopers16/&#34;&gt;Troopers16&lt;/a&gt;, we wanted to give a little sample taste what you can expect.&lt;/p&gt;&#xA;&lt;p&gt;&lt;strong&gt;Table of Contents&lt;/strong&gt;&lt;br&gt;&#xA;&lt;a href=&#34;#extraction&#34;&gt;&lt;strong&gt;Extracting Mail Attachments&lt;/strong&gt;&lt;/a&gt;&lt;br&gt;&#xA;&lt;a href=&#34;#word&#34;&gt;&lt;strong&gt;Word Document Analysis&lt;/strong&gt;&lt;/a&gt;&lt;br&gt;&#xA;&lt;a href=&#34;#static&#34;&gt;&lt;strong&gt;Static JavaScript Analysis&lt;/strong&gt;&lt;/a&gt;&lt;br&gt;&#xA;&lt;a href=&#34;#dynamic&#34;&gt;&lt;strong&gt;Dynamic JavaScript Analysis&lt;/strong&gt;&lt;/a&gt;&lt;/p&gt;&#xA;&lt;p&gt;Before we dive into the analysis, I wanted to mention that if you are going to analyze anything unknown/potentially malicious, do it in a safe environment (VM with no internet connection, in the best case on a separate physical analysis device, or at least strip all unnecessary functionality from that VM (CVE-2015-3456 is an example to answer the “why”)). Even things like looking at content with a text editor or extracting zip files should be done in the safe environment, as those tools could contain vulnerabilities.&lt;/p&gt;</description>
    </item>
    <item>
      <title>3rd Round of TROOPERS16 Talks Accepted</title>
      <link>https://insinuator.net/2015/12/3rd-round-of-troopers16-talks-accepted/</link>
      <pubDate>Thu, 17 Dec 2015 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2015/12/3rd-round-of-troopers16-talks-accepted/</guid>
      <description>&lt;p&gt;Here at TROOPERS HQ we are well into the Holiday (read TROOPERS) Spirit so we thought we would publish another round of talks! The current agenda can be found &lt;a href=&#34;https://www.troopers.de/troopers16/agenda/&#34;&gt;here&lt;/a&gt;.&lt;/p&gt;&#xA;&lt;p&gt;Happy Holidays!&lt;/p&gt;&#xA;&lt;p&gt;Your TROOPERS Team&lt;/p&gt;&#xA;&lt;p&gt;===&lt;/p&gt;&#xA;&lt;p&gt;2nd Day Keynote&lt;br&gt;&#xA;&lt;strong&gt;FIRST TIME TROOPERS SPEAKER&lt;/strong&gt;&lt;/p&gt;&#xA;&lt;p&gt;&lt;strong&gt;Bio:&lt;/strong&gt; Ben Zevenbergen joined the Oxford Internet Institute to pursue a DPhil on the intersection of privacy law, technology, social science, and the Internet. He runs a side project that aims to establish ethics guidelines for Internet research, as well as working in multidisciplinary teams such as the EU funded Network of Excellence in Internet Science. He has worked on legal, political and policy aspects of the information society for several years. Most recently he was a policy advisor to an MEP in the European Parliament, working on Europe’s Digital Agenda. Previously Ben worked as an ICT/IP lawyer and policy consultant in the Netherlands. Bendert holds a degree in law, specialising in Information Law.&lt;/p&gt;</description>
    </item>
    <item>
      <title>2nd Rounds of TROOPERS16 Talks</title>
      <link>https://insinuator.net/2015/12/2nd-rounds-of-troopers16-talks/</link>
      <pubDate>Fri, 11 Dec 2015 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2015/12/2nd-rounds-of-troopers16-talks/</guid>
      <description>&lt;p&gt;Here’s the second round of TROOPERS16 talks. For more information  check out our website: &lt;a href=&#34;https://www.troopers.de/&#34;&gt;TROOPERS&lt;/a&gt;&lt;/p&gt;&#xA;&lt;p&gt;Happy Holidays and all the best for 2016 to everybody!&lt;/p&gt;&#xA;&lt;p&gt;Your TROOPERS Team&lt;/p&gt;&#xA;&lt;p&gt;===&lt;/p&gt;&#xA;&lt;p&gt;Ivan Pepelnjak: Real-life Software-Defined Security&lt;/p&gt;&#xA;&lt;p&gt;Vendors, pundits, and industry media love to talk about Software-Defined Everything, but nothing ever changes in the enterprise world, right? Wrong. Some engineers are already solving security problems with a software-defined approach to networking and security, be it microsegmentation in NSX or OpenStack environment, building scale-out IDS clusters, or respond to DoS or intrusion events in real-time… and we’ll cover all these ideas in this fast-paced presentation&lt;/p&gt;</description>
    </item>
    <item>
      <title>First Talks of TROOPERS 2016 Accepted!</title>
      <link>https://insinuator.net/2015/12/first-talks-of-troopers-2016-accepted/</link>
      <pubDate>Wed, 09 Dec 2015 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2015/12/first-talks-of-troopers-2016-accepted/</guid>
      <description>&lt;p&gt;Here’s the first round of TROOPERS16 talks. For more information  check out our website: &lt;a href=&#34;https://www.troopers.de&#34;&gt;TROOPERS&lt;/a&gt;&lt;/p&gt;&#xA;&lt;p&gt;Happy Holidays and all the best for 2016 to everybody!&lt;/p&gt;&#xA;&lt;p&gt;Your TROOPERS Team&lt;/p&gt;&#xA;&lt;p&gt;===&lt;br&gt;&#xA;Mike Ossmann: Rapid Radio Reversing&lt;/p&gt;&#xA;&lt;p&gt;Wireless security researchers have an unprecedented array of tools at their disposal today. Although Software Defined Radio (SDR) is the single most valuable tool for reverse engineering wireless signals, it is sometimes faster and easier to use other tools for portions of the reverse engineering process. I’ll discuss how beneficial a hybrid SDR/non-SDR approach has been to security researchers, and I’ll walk through an example of the process.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Welcome to Brazil!</title>
      <link>https://insinuator.net/2015/12/welcome-to-brazil/</link>
      <pubDate>Tue, 01 Dec 2015 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2015/12/welcome-to-brazil/</guid>
      <description>&lt;p&gt;Welcome to Brazil!&lt;/p&gt;&#xA;&lt;p&gt;“Welcome to Brazil”, I think, turned to being the most used statement during the past Hackers to Hackers Conference in Sao Paulo. It was used as the main reaction to every speech taking moment, and there were a lot of those! To honor the moments and give you a quick insight into was what going on in Sao Paulo, here is a quick summary of the overall event and our own contribution.&lt;/p&gt;</description>
    </item>
    <item>
      <title>DENOG7</title>
      <link>https://insinuator.net/2015/11/denog7/</link>
      <pubDate>Thu, 19 Nov 2015 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2015/11/denog7/</guid>
      <description>&lt;p&gt;Hi everyone,&lt;/p&gt;&#xA;&lt;p&gt;we (Christopher, Jan-Pascal and me) had the pleasure to join the 7th &lt;a href=&#34;http://www.denog.de/meetings/denog7/?lang=de&#34;&gt;DENOG&lt;/a&gt; (German Network Operators Group) &lt;a href=&#34;http://www.denog.de/meetings/denog7/?lang=de&#34;&gt;meeting&lt;/a&gt; in Darmstadt which takes place yearly in autumn. For the first time the meeting was scheduled for two days which offered more time for talks and discussions than the previous meetings. The concept of DENOG is to meet, talk, discuss and share experience with the network operator community in Germany. &lt;/p&gt;&#xA;&lt;p&gt;The meeting started withe a talk from Peter Sievers from Juniper about Network Automation and Programmability. He presented why automation and programmability is getting more and more important even for network operators. It will help to automate the build process, the configuration and should ideally help you operating and troubleshooting your envirnoment. The focus of the talk was on the platforms which are already available and ready to use to automate day to day activities.&lt;/p&gt;</description>
    </item>
    <item>
      <title>13th escar Europe conference | Embedded Security in Cars</title>
      <link>https://insinuator.net/2015/11/13th-escar-europe-conference-embedded-security-in-cars/</link>
      <pubDate>Tue, 17 Nov 2015 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2015/11/13th-escar-europe-conference-embedded-security-in-cars/</guid>
      <description>&lt;p&gt;Last week I had the pleasure to attend the “&lt;strong&gt;escar&lt;/strong&gt;” (&lt;em&gt;Embedded Security in Cars&lt;/em&gt;) &lt;strong&gt;conference&lt;/strong&gt; in &lt;em&gt;Cologne, Germany&lt;/em&gt;.&lt;br&gt;&#xA;Arriving late Tuesday, I had the chance to get a rich breakfast before joining the con in the hotel Dorint at Cologne’s famous place the Heumarkt. Unfortunately I had to deal with two stumbling blocks on my way to the Dobrint: The magnetic sensor of my mobile which went crazy (no compass) and – the date. 11th of November in Cologne means just one thing – &lt;em&gt;&lt;strong&gt;carneval&lt;/strong&gt;&lt;/em&gt;! The whole city was just in a state of exception. Everybody on my way to the venue seemed to be drinking or beeing already drunk – at 9am! 😉&lt;br&gt;&#xA;Being a little late, I went straight to the room after registration. As there was only one track to follow you could not miss any talk – nice thing!&lt;br&gt;&#xA;After we were welcomed by the hosts, and the first talk started.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Wireless LAN Pros Conference</title>
      <link>https://insinuator.net/2015/11/wireless-lan-pros-conference/</link>
      <pubDate>Wed, 11 Nov 2015 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2015/11/wireless-lan-pros-conference/</guid>
      <description>&lt;p&gt;Last week, on the 27th-28th I attended a nice wireless conference in berlin, the WLPC (Wireless LAN Pros Conference). You can visit their website at &lt;a href=&#34;http://berlin2015.wlanprosconference.com/http:/berlin2015.wlanprosconference.com/&#34;&gt;http://berlin2015.wlanprosconference.com.&lt;/a&gt;&lt;/p&gt;&#xA;&lt;p&gt;This conference is a community-driven conference from wireless professionals with focus on typical topics that come up when you are planning or running large wireless networks. This is a mainly Twitter based community, you can see some Tweets with hashtags #WLPC for example. There were also some interesting talks about future networks, for example Marko Tisler gave a talk about wireless LAN and SDN and what we can expect and what SDN will not solve for wireless networks.&lt;/p&gt;</description>
    </item>
    <item>
      <title>A Visual Guide to Day-Con 9</title>
      <link>https://insinuator.net/2015/11/a-visual-guide-to-day-con-9/</link>
      <pubDate>Mon, 09 Nov 2015 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2015/11/a-visual-guide-to-day-con-9/</guid>
      <description>&lt;h2 id=&#34;welcome-to-dayton&#34;&gt;Welcome to Dayton&lt;/h2&gt;&#xA;&lt;p&gt;In mid-October our friend Bryan Fite aka Angus Blitter invited the community for the ninth edition of &lt;a href=&#34;http://day-con.org/&#34;&gt;Day-Con&lt;/a&gt;. Bryan’s annual security summit, which we regard as the sister event of TROOPERS, is a pretty good reason to visit lovely Dayton, Ohio.&lt;/p&gt;&#xA;&lt;p&gt;&lt;a href=&#34;http://www.insinuator.net/wp-content/uploads/2015/11/IMG_2144.jpg&#34;&gt;&lt;img src=&#34;http://www.insinuator.net/wp-content/uploads/2015/11/IMG_2144.jpg&#34; alt=&#34;Day-Con Summit&#34;&gt;&lt;/a&gt;&lt;/p&gt;&#xA;&lt;p&gt;And so we did… ERNW sent in five delegates. Delegates is &lt;em&gt;Day-Con-speak&lt;/em&gt; for all attendees and speakers and such a subtle choice of wording sets the tone for the whole event. People seemed to be really focused and the roundtable-like setting during the talks (see above) provided a cozy atmosphere for in-depth expert chatting.&lt;/p&gt;</description>
    </item>
    <item>
      <title>“We have a Code Blue right here!”</title>
      <link>https://insinuator.net/2015/11/we-have-a-code-blue-right-here/</link>
      <pubDate>Wed, 04 Nov 2015 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2015/11/we-have-a-code-blue-right-here/</guid>
      <description>&lt;p&gt;That was the opener for my presentation on the Security in Medical Devices at &lt;a href=&#34;http://codeblue.jp/2015/en/&#34;&gt;CodeBlue 2015&lt;/a&gt; last week in Tokyo, Japan. A &lt;a href=&#34;https://en.wikipedia.org/wiki/Hospital_emergency_codes#Code_Blue&#34;&gt;Code Blue&lt;/a&gt; often describes a patient in a critical condition, mostly needing resuscitation. That just seemed to be a perfect match, also in the sense that the condition of some medical devices out there are still pretty critical concerning security. If you follow our current research on this you know what I am talking about. I hope that we are not talking about this topic anymore three years from now. That would mean that we have made the world a safer place, although it took some time … 😉&lt;/p&gt;</description>
    </item>
    <item>
      <title>hardwear.io: Applied Physical Attacks on x86 Systems</title>
      <link>https://insinuator.net/2015/10/hardwear.io-applied-physical-attacks-on-x86-systems/</link>
      <pubDate>Sat, 10 Oct 2015 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2015/10/hardwear.io-applied-physical-attacks-on-x86-systems/</guid>
      <description>&lt;p&gt;&lt;a href=&#34;http://www.insinuator.net/wp-content/uploads/2015/10/casey_davis_superbloodmoon.jpg&#34;&gt;&lt;img src=&#34;http://www.insinuator.net/wp-content/uploads/2015/10/casey_davis_superbloodmoon-280x300.jpg&#34; alt=&#34;stolen off the internet&#34;&gt;&lt;/a&gt;&lt;/p&gt;&#xA;&lt;p&gt;On Monday the 28th of September 2015 a rather rare event occurred. At around 4 a.m. the moon changed its colour into a dim of red, luckily the sky was clear enough to see something.&lt;/p&gt;&#xA;&lt;p&gt;[ picture stolen from &lt;a href=&#34;http://www.nasa.gov/image-feature/super-blood-moon-photo-contest-winner&#34;&gt;NASA&lt;/a&gt; ]&lt;/p&gt;&#xA;&lt;p&gt;If you missed that event your next chance will be in about 15 years or so.&lt;/p&gt;&#xA;&lt;p&gt;The reason for being awake this early wasn’t the moon in the first place but what followed afterwards – my trip to the &lt;a href=&#34;http://hardwear.io/&#34;&gt;hardwear.io Security Conference&lt;/a&gt; in The Hague.&lt;/p&gt;</description>
    </item>
    <item>
      <title>hardwear.io: Conference Day 1</title>
      <link>https://insinuator.net/2015/10/hardwear.io-conference-day-1/</link>
      <pubDate>Sat, 10 Oct 2015 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2015/10/hardwear.io-conference-day-1/</guid>
      <description>&lt;p&gt;During my stay in The Hague I needed to print something, so I asked for a Copy shop and this is where they sent me:&lt;/p&gt;&#xA;&lt;p&gt;&lt;a href=&#34;http://www.insinuator.net/wp-content/uploads/2015/10/coffeeshop.jpg&#34;&gt;&lt;img src=&#34;http://www.insinuator.net/wp-content/uploads/2015/10/coffeeshop-300x225.jpg&#34; alt=&#34;coffeeshop&#34;&gt;&lt;/a&gt;&lt;/p&gt;&#xA;&lt;p&gt;Against the common rule to just talk about the personal favorites, I will cover all talks in one, two or more sentences (arbitrarily decided while writing). This also gives you a broader picture of the conference.&lt;/p&gt;&#xA;&lt;p&gt;Jumping right in with the keynote of Day 1 by Jon Callas and my favorite quote “Make your devices fixable”. Enough said.&lt;/p&gt;</description>
    </item>
    <item>
      <title>hardwear.io: Conference Day 2</title>
      <link>https://insinuator.net/2015/10/hardwear.io-conference-day-2/</link>
      <pubDate>Sat, 10 Oct 2015 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2015/10/hardwear.io-conference-day-2/</guid>
      <description>&lt;p&gt;&lt;a href=&#34;http://www.insinuator.net/wp-content/uploads/2015/10/politie_logo.jpg&#34;&gt;&lt;img src=&#34;http://www.insinuator.net/wp-content/uploads/2015/10/politie_logo.jpg&#34; alt=&#34;stolen off the internet&#34;&gt;&lt;/a&gt;Netherlands Police is called Politie because they’re so polite. (works only if you suffer from dyslexia)&lt;/p&gt;&#xA;&lt;p&gt;[ picture stolen from the &lt;a href=&#34;https://www.politie.nl/&#34;&gt;polite politie&lt;/a&gt; ]&lt;/p&gt;&#xA;&lt;p&gt;Unlike the German Oktoberfest in Munich which already started in September, the Oktoberfest in The Hague started on 2nd October.&lt;/p&gt;&#xA;&lt;p&gt;&lt;a href=&#34;http://www.insinuator.net/wp-content/uploads/2015/10/oktoberfest.jpg&#34;&gt;&lt;img src=&#34;http://www.insinuator.net/wp-content/uploads/2015/10/oktoberfest-300x225.jpg&#34; alt=&#34;oktoberfest&#34;&gt;&lt;/a&gt;&lt;/p&gt;&#xA;&lt;p&gt;In spite of this competing event the decision going to the last day of the hardwear.io Conference definitely paid off.&lt;/p&gt;&#xA;&lt;p&gt;Day 2 started with the Keynote from Harald Welte (the father of Osmocom) and his view about Telecom Security for the last few years. His observation is that nothing has changed so far – we still suffer from a lack of tools and monoculture throughout the industry.&lt;/p&gt;</description>
    </item>
    <item>
      <title>ERNW speaking @ hardwear.io</title>
      <link>https://insinuator.net/2015/10/ernw-speaking-@-hardwear.io/</link>
      <pubDate>Mon, 05 Oct 2015 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2015/10/ernw-speaking-@-hardwear.io/</guid>
      <description>&lt;p&gt;&lt;img src=&#34;http://www.insinuator.net/wp-content/uploads/2015/10/hardwarebug-266x300.png&#34; alt=&#34;Hardwarebug&#34;&gt;&lt;/p&gt;&#xA;&lt;p&gt;On October 1st and 2nd Flo and I were presenting at&lt;br&gt;&#xA;hardwear.io in The Hague, NL. My topic was “&lt;a href=&#34;https://www.ernw.de/download/ERNW_hardwear.io_2015_living_in_a_fools_wireless-secured_paradise_skiese.pdf&#34;&gt;Living in a fool’s&lt;/a&gt;&lt;br&gt;&#xA;&lt;a href=&#34;https://www.ernw.de/download/ERNW_hardwear.io_2015_living_in_a_fools_wireless-secured_paradise_skiese.pdf&#34;&gt;wireless-secured paradise&lt;/a&gt;” and Flo was presenting his current research&lt;br&gt;&#xA;on medical device security. It was the first talk at an international&lt;br&gt;&#xA;security conference for me and I am still quite excited!&lt;/p&gt;&#xA;&lt;p&gt;I was speaking about the (in)security of wireless consumer alarm&lt;br&gt;&#xA;systems, which you can buy just in every consumer electronics store&lt;br&gt;&#xA;around the corner for about $10 – $250. I analyzed the systems on&lt;br&gt;&#xA;different levels, e.g. looking at UART and JTAG and the wireless domain&lt;br&gt;&#xA;with Software Defined Radio (SDR). I gave an overview of my current&lt;br&gt;&#xA;research and the tools I usually use for hardware hacking, especially my&lt;br&gt;&#xA;favorite thing to play with: SDR.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Being at VB2015…</title>
      <link>https://insinuator.net/2015/10/being-at-vb2015/</link>
      <pubDate>Fri, 02 Oct 2015 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2015/10/being-at-vb2015/</guid>
      <description>&lt;p&gt;I am currently at the 25th &lt;a href=&#34;https://www.virusbtn.com/index&#34;&gt;Virus Bulletin International Conference&lt;/a&gt; in Prague. The VB2015 is hosted by the Virus Bulletin portal and provides three full days of learning opportunities and networking.&lt;/p&gt;&#xA;&lt;p&gt;VB2015 focuses on the key themes:&lt;/p&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;&#xA;&lt;p&gt;Malware &amp;amp; botnets&lt;/p&gt;&#xA;&lt;/li&gt;&#xA;&lt;li&gt;&#xA;&lt;p&gt;Anti-malware tools &amp;amp; techniques&lt;/p&gt;&#xA;&lt;/li&gt;&#xA;&lt;li&gt;&#xA;&lt;p&gt;Mobile devices&lt;/p&gt;&#xA;&lt;/li&gt;&#xA;&lt;li&gt;&#xA;&lt;p&gt;Hacking &amp;amp; vulnerabilities&lt;/p&gt;&#xA;&lt;/li&gt;&#xA;&lt;li&gt;&#xA;&lt;p&gt;Spam &amp;amp; social networks&lt;/p&gt;&#xA;&lt;/li&gt;&#xA;&lt;li&gt;&#xA;&lt;p&gt;Network security&lt;/p&gt;&#xA;&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;p&gt;&lt;strong&gt;General Observations:&lt;/strong&gt;&lt;/p&gt;&#xA;&lt;p&gt;What I liked about VB2015 was the very friendly and always helpful staff. The good conference location, it never felt overcrowded or to empty and the very good catering during the conference.&lt;/p&gt;</description>
    </item>
    <item>
      <title>BlackHoodie: Reversing Workshop for Women</title>
      <link>https://insinuator.net/2015/09/blackhoodie-reversing-workshop-for-women/</link>
      <pubDate>Tue, 29 Sep 2015 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2015/09/blackhoodie-reversing-workshop-for-women/</guid>
      <description>&lt;p&gt;In the beginning of September, I had an opportunity to take part in BlackHoodie – a reversing workshop for women organized by Marion Marschalek, senior malware researcher at Cyphort, Inc. It took place on 5th and 6th of September at University of Applied Sciences St. Pölten, Austria.&lt;/p&gt;&#xA;&lt;p&gt;Besides me, 14 more young women from different countries came to attend the workshop; the overall atmosphere was very friendly and productive. Before the actual event all participants were getting preparatory assignments and recommendations (not to spend our two days on learning the very basics), and during the workshop itself we got our hands on analyzing and reversing some actual malware samples. I personally found it very interesting how one can detect and overcome several layers of anti-analysis protection. I left the workshop excited and packed with some new knowledge as a basis for further skills development – it’s just the beginning! 😉&lt;/p&gt;</description>
    </item>
    <item>
      <title>Reminiscing About Black Hat USA 2015</title>
      <link>https://insinuator.net/2015/09/reminiscing-about-black-hat-usa-2015/</link>
      <pubDate>Mon, 21 Sep 2015 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2015/09/reminiscing-about-black-hat-usa-2015/</guid>
      <description>&lt;p&gt;&lt;a href=&#34;http://www.insinuator.net/wp-content/uploads/2015/09/IMG_0245.jpg&#34;&gt;&lt;img src=&#34;http://www.insinuator.net/wp-content/uploads/2015/09/IMG_0245.jpg&#34; alt=&#34;The Strip&#34;&gt;&lt;/a&gt;&lt;/p&gt;&#xA;&lt;p&gt;While searching for some photos for my last &lt;a href=&#34;https://www.insinuator.net/2015/09/miners-canary-revival-in-it-security/&#34;&gt;blog post on Thinkst Canary&lt;/a&gt; I found a couple more from our recent trip to &lt;a href=&#34;https://www.blackhat.com/us-15/&#34;&gt;Black Hat USA&lt;/a&gt; and &lt;a href=&#34;https://defcon.org/html/links/dc-archives/dc-23-archive.html&#34;&gt;DEF CON&lt;/a&gt;, which I consider worth sharing. Nothing too technical, just some visual impressions and comments from my side. Let’s get it on!&lt;/p&gt;&#xA;&lt;p&gt;&lt;a href=&#34;http://www.insinuator.net/wp-content/uploads/2015/09/signup.jpg&#34;&gt;&lt;img src=&#34;http://www.insinuator.net/wp-content/uploads/2015/09/signup.jpg&#34; alt=&#34;Sign Up&#34;&gt;&lt;/a&gt;&lt;/p&gt;&#xA;&lt;p&gt;My colleague Patrik and myself arrived one day early before the briefings and headed right to Mandalay Bay to check out the Black Hat venue and get a feel for the city. The sheer size of just everything is mind-blowing.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Miner’s Canary Revival in IT Security</title>
      <link>https://insinuator.net/2015/09/miners-canary-revival-in-it-security/</link>
      <pubDate>Sat, 19 Sep 2015 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2015/09/miners-canary-revival-in-it-security/</guid>
      <description>&lt;p&gt;&lt;img src=&#34;http://www.insinuator.net/wp-content/uploads/2015/09/canary_credit_to_javier_bano-300x201.jpg&#34; alt=&#34;canary_credit_to_javier_bano&#34;&gt;&lt;/p&gt;&#xA;&lt;h3 id=&#34;what-is-a-miners-canary&#34;&gt;What is a Miner’s Canary?&lt;/h3&gt;&#xA;&lt;p&gt;Well, it’s a canary (these cute yellow songbirds some people have as a pet), and its main feature is that &lt;em&gt;it dies before you will&lt;/em&gt;.&lt;/p&gt;&#xA;&lt;p&gt;What the hack [pun intended]? And by the way… what has this to do with IT Security? Well… let me first quote Wikipedia on the birds:&lt;/p&gt;&#xA;&lt;blockquote&gt;&#xA;&lt;p&gt;“Canaries were once regularly used in coal mining as an early warning system. Toxic gases such as carbon monoxide, methane or carbon dioxide in the mine would kill the bird before affecting the miners. Signs of distress from the bird indicated to the miners that conditions were unsafe.” Source: &lt;a href=&#34;https://en.wikipedia.org/wiki/Domestic_canary#Miner.27s_canary&#34;&gt;https://en.wikipedia.org/wiki/Domestic_canary#Miner.27s_canary&lt;/a&gt;&lt;/p&gt;</description>
    </item>
    <item>
      <title>IPv6@MRMCD2015</title>
      <link>https://insinuator.net/2015/09/ipv6@mrmcd2015/</link>
      <pubDate>Mon, 14 Sep 2015 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2015/09/ipv6@mrmcd2015/</guid>
      <description>&lt;p&gt;Greetings everyone,&lt;/p&gt;&#xA;&lt;p&gt;On Saturday last week I had the pleasure of delivering a &lt;a href=&#34;https://mrmcd.net/2015/fahrplan/events/7045.html&#34;&gt;workshop on IPv6 networking&lt;/a&gt; at the &lt;a href=&#34;https://mrmcd.net/&#34;&gt;MRMCD2015&lt;/a&gt; conference in Darmstadt, Germany. It goes without saying that the atmosphere was quite amicable; as usual at CCC-related events. What definitely impressed me the most was the diversity of the audience. There were around thirty attendees representing several age groups and all with seemingly differing backgrounds.&lt;/p&gt;&#xA;&lt;p&gt;The engagement of everyone was stunning. I questioned the most engaged attendees relentlessly and they fired back. I was being constantly bombarded with questions from enthusiastic geeks and they got, hopefully, what they deserved. This provided for a great learning environment, a friendly atmosphere and in my humble opinion really constructive dialogues. Well, one has to be interested and enthusiastic in order to spend three hours on a rainy Saturday evening discussing IPv6.&lt;/p&gt;</description>
    </item>
    <item>
      <title>24th USENIX Security Symposium &amp;amp; WOOT Workshop</title>
      <link>https://insinuator.net/2015/08/24th-usenix-security-symposium-amp-woot-workshop/</link>
      <pubDate>Fri, 28 Aug 2015 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2015/08/24th-usenix-security-symposium-amp-woot-workshop/</guid>
      <description>&lt;p&gt;Recently I had the pleasure to attend the 24th USENIX Security Symposium and its co-located Workshop on Offensive Technologies (WOOT) in Washington, D.C. The workshop has received quite some attention this year, 57 submissions of which 19 have been accepted, so that the organizers decided to double its length from one to two days.&lt;/p&gt;&#xA;&lt;p&gt;The first day of the workshop began with an excellent keynote by Adam Langley, in which he reflected on the current state of SSL/TLS and its vulnerabilities. As a side remark he mentioned that to tackle the everlasting problem of such vulnerabilities to occur, research should be performed with a much higher level of abstraction rather than focusing on the exact details of a “certain hash function of some specific CBC cipher”.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Black Hat Talks &amp; Papers related to Windows/Active Directory Security</title>
      <link>https://insinuator.net/2015/08/black-hat-talks-papers-related-to-windows/active-directory-security/</link>
      <pubDate>Fri, 07 Aug 2015 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2015/08/black-hat-talks-papers-related-to-windows/active-directory-security/</guid>
      <description>&lt;p&gt;This year’s Black Hat US saw a number of quite interesting talks in the context of Windows or Active Directory Security. For those of you too lazy to search for themselves 😉 and for our own Windows/AD Sec team (who couldn’t send anyone to Vegas due to heavy project load) I’ve compiled a little list of those.&lt;/p&gt;&#xA;&lt;p&gt;&lt;a href=&#34;https://twitter.com/pdjstone&#34;&gt;Paul Stone&lt;/a&gt; &amp;amp; &lt;a href=&#34;https://twitter.com/NoxrNet&#34;&gt;Alex Chapman&lt;/a&gt;: WSUSPect – Compromising the Windows Enterprise via Windows Update&lt;br&gt;&#xA;Slides &lt;a href=&#34;https://www.blackhat.com/docs/us-15/materials/us-15-Stone-WSUSpect-Compromising-Windows-Enterprise-Via-Windows-Update.pdf&#34;&gt;here&lt;/a&gt;.&lt;br&gt;&#xA;Whitepaper &lt;a href=&#34;http://www.contextis.com/media/documents/CTX_WSUSpect_White_Paper.pdf&#34;&gt;here&lt;/a&gt;. (Attention: on the BH website there’s an older this. the above link leads to the latest one).&lt;/p&gt;</description>
    </item>
    <item>
      <title>IPv6 Hackers Meeting @ IETF 93 in Prague</title>
      <link>https://insinuator.net/2015/07/ipv6-hackers-meeting-@-ietf-93-in-prague/</link>
      <pubDate>Wed, 29 Jul 2015 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2015/07/ipv6-hackers-meeting-@-ietf-93-in-prague/</guid>
      <description>&lt;p&gt;After the &lt;a href=&#34;http://www.insinuator.net/2013/08/ipv6-hackers-meeting-ietf-87-in-berlin-slides/&#34;&gt;first “IPv6 Hackers Meeting”&lt;/a&gt; held two years ago in Berlin, &lt;a href=&#34;https://twitter.com/FernandoGont&#34;&gt;Fernando Gont&lt;/a&gt; kindly organized a &lt;a href=&#34;http://www.ipv6hackers.org/home&#34;&gt;similar event in Prague&lt;/a&gt; last week.&lt;/p&gt;&#xA;&lt;p&gt;Although a bit on short notice it was a good meeting with interesting discussions. I contributed with shortened versions of two talks we had delivered in the past:&lt;/p&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;the “&lt;a href=&#34;https://www.ernw.de/download/Atlasis_Rey_Schaefer_IETF93_IPv6Hackers_Evasion_of_HighEnd_IPS_Devices.pdf&#34;&gt;Evasion of High-End IDPS Devices at the IPv6 Era&lt;/a&gt;” talk which &lt;a href=&#34;https://twitter.com/AntoniosAtlasis&#34;&gt;Antonios&lt;/a&gt;, Rafael and I had given at Black Hat US &amp;amp; Europe 2014. The accompanying white paper with the exact details &lt;a href=&#34;https://www.ernw.de/download/eu-14-Atlasis-Rey-Schaefer-briefings-Evasion-of-HighEnd-IPS-Devices-wp.pdf&#34;&gt;can be found here&lt;/a&gt;; the tool Chiron &lt;a href=&#34;http://www.secfu.net/tools-scripts/&#34;&gt;here&lt;/a&gt; (and a tutorial &lt;a href=&#34;https://www.ernw.de/download/Chiron_Tutorial.pdf&#34;&gt;here&lt;/a&gt;).&lt;/li&gt;&#xA;&lt;li&gt;the “MLD Considered Harmful” talk that Antonios, &lt;a href=&#34;https://twitter.com/anantary&#34;&gt;Jayson&lt;/a&gt; and I had presented at the &lt;a href=&#34;https://www.troopers.de/events/troopers15/322_ipv6_security_summit/&#34;&gt;Troopers IPv6 Security Summit 2015&lt;/a&gt;. The mentioned Internet-Draft on MLD security which &lt;a href=&#34;https://www.vyncke.org/ipv6status/&#34;&gt;Eric Vyncke&lt;/a&gt;, Antonios and myself are working on can be &lt;a href=&#34;https://tools.ietf.org/html/draft-vyncke-pim-mld-security-00&#34;&gt;found here&lt;/a&gt;. We’re happy to receive any feedback on that one.&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;p&gt;Special thanks go to &lt;a href=&#34;http://www.internetsociety.org/who-we-are/staff/mr-jan-%C5%BEor%C5%BE&#34;&gt;Jan Zorz&lt;/a&gt; and to &lt;a href=&#34;http://www.nic.cz/&#34;&gt;CZ.NIC&lt;/a&gt; for hosting us and providing refreshments. Much appreciated, guys!&lt;/p&gt;</description>
    </item>
    <item>
      <title>BT SnoopCon</title>
      <link>https://insinuator.net/2015/06/bt-snoopcon/</link>
      <pubDate>Mon, 29 Jun 2015 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2015/06/bt-snoopcon/</guid>
      <description>&lt;p&gt;I had the honour to be invited to &lt;a href=&#34;http://www.bt.com&#34;&gt;BT&lt;/a&gt;‘s SnoopCon, which is their annual internal conference for people involved with security at BT. There were several external and internal speakers and I was stunned by the quality of the talks and the collaborative atmosphere. Since this event is somewhat internal (even though I’m obviously allowed to talk about it), I won’t go into details, however there were two particularly great talks about military war games (which I personally enjoyed very much given my history in CTF contests) and PoS security.&lt;/p&gt;</description>
    </item>
    <item>
      <title>CSA.no Nordic Summit</title>
      <link>https://insinuator.net/2015/06/csa.no-nordic-summit/</link>
      <pubDate>Sun, 28 Jun 2015 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2015/06/csa.no-nordic-summit/</guid>
      <description>&lt;p&gt;Flo and I had the pleasure to present at the &lt;a href=&#34;https://csanorway.no/&#34;&gt;CSA&lt;/a&gt; &lt;a href=&#34;https://csanordicsummitandsummercon2015.sched.org/&#34;&gt;Nordic Summit&lt;/a&gt; in Norway. Being in Oslo for the first time, we enjoyed the conference (small, familiar atmosphere) very much and want to thank Lars and Kai for putting together such a good event &amp;amp; having us there!&lt;/p&gt;&#xA;&lt;p&gt;Our slides can be found here:&lt;/p&gt;&#xA;&lt;p&gt;&lt;a href=&#34;https://www.ernw.de/download/ERNW_CSA-No-Summit_Hacking_Medical_Devices_fgrunow.pdf&#34;&gt;Hacking Medical Devices&lt;/a&gt;&lt;/p&gt;&#xA;&lt;p&gt;&lt;a href=&#34;https://www.ernw.de/download/ERNW_CSA-No-Summit_ToolsOfTheTrade_mluft.pdf&#34;&gt;Tools of the Trade: Lessons Learned from the (C)ISO’s Desk&lt;/a&gt;&lt;/p&gt;&#xA;&lt;p&gt; &lt;/p&gt;&#xA;&lt;p&gt;best,&lt;/p&gt;&#xA;&lt;p&gt;Matthias&lt;/p&gt;</description>
    </item>
    <item>
      <title>NANOG64</title>
      <link>https://insinuator.net/2015/06/nanog64/</link>
      <pubDate>Fri, 26 Jun 2015 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2015/06/nanog64/</guid>
      <description>&lt;p&gt;I recently had the pleasure to join the &lt;a href=&#34;https://www.nanog.org/meetings/nanog64&#34;&gt;64th NANOG&lt;/a&gt; (North American Network Operators’ Group) meeting in San Francisco, which can be understood as one of the largest Internet engineering conferences at all. It takes place three times a year at different locations in North America.&lt;/p&gt;&#xA;&lt;p&gt;What I personally like about NANOG is its strong collaborative and cooperative character. It is not about single persons and also not too much about spectacular projects but more about discussing technologies, ideas, challenges and numbers. Every talk has a comparatively large time slot reserved for discussion, which is often more than fully used. Discussion is typically actively focused and is more time-consuming (and even more relevant) than the talk itself. Which often is intended by the community. The climate of discussion is almost always impressively polite and constructive, even for controversially discussed topics.&lt;/p&gt;</description>
    </item>
    <item>
      <title>ERNW @PHDays V in Moscow</title>
      <link>https://insinuator.net/2015/06/ernw-@phdays-v-in-moscow/</link>
      <pubDate>Tue, 09 Jun 2015 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2015/06/ernw-@phdays-v-in-moscow/</guid>
      <description>&lt;p&gt;Здравствуйте Insinuator Followers,&lt;/p&gt;&#xA;&lt;p&gt;End of May eight ERNW members were travelling to Moscow (Russia) to visit the &lt;a href=&#34;http://www.phdays.com/&#34;&gt;PHDays V&lt;/a&gt; conference. It was a very nice trip because we met a lot of gentle people, ate some great food and had quite some fun in this exciting and history-charged metropole, and we were able to get around using hands and feet (and Google translate ;-)).&lt;/p&gt;&#xA;&lt;p&gt;The remainder of this post contains summaries of some of the most interesting talks at PHD V:&lt;/p&gt;</description>
    </item>
    <item>
      <title>Advanced Security Evaluation of Network Protocols</title>
      <link>https://insinuator.net/2015/06/advanced-security-evaluation-of-network-protocols/</link>
      <pubDate>Mon, 08 Jun 2015 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2015/06/advanced-security-evaluation-of-network-protocols/</guid>
      <description>&lt;p&gt;Hi,&lt;/p&gt;&#xA;&lt;p&gt;I’m back from London where I gave a talk about security evaluation of proprietary network protocols. I had a great time at &lt;a href=&#34;http://www.infosecurityeurope.com/en/education/education-programme/Session-Search-Pages/intelligence-defence/&#34;&gt;InfoSecurity Intelligent Defence&lt;/a&gt; and &lt;a href=&#34;https://www.securitybsides.org.uk/&#34;&gt;BSides London&lt;/a&gt;, many thanks for inviting me and giving me the opportunity to speak to so much nice people.&lt;/p&gt;&#xA;&lt;p&gt;Find the abstract and the download link to the slides after the break.&lt;/p&gt;&#xA;&lt;blockquote&gt;&#xA;&lt;p&gt;Even in the time of Cloud-based security tools, behavior- and machine learning-based APT detection and colorful security appliances, a lot of vulnerabilities are still buried deep within the protocol layers. For security researchers it is quite a challenge to find those in well documented protocols (take SSL for an example), and when it comes to proprietary protocols, the bar is raised even (significantly) higher. This keynote will show that there is still an urgent need for security evaluation on (undocumented) network protocols, discuss war stories on protocol fails, and also give an introduction into the methodology of protocol reversing and how those protocol fails could have been avoided.&lt;/p&gt;</description>
    </item>
    <item>
      <title>ERNW @Mudiator</title>
      <link>https://insinuator.net/2015/06/ernw-@mudiator/</link>
      <pubDate>Sun, 07 Jun 2015 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2015/06/ernw-@mudiator/</guid>
      <description>&lt;p&gt;Today the ERNW Team participated in the &lt;a href=&#34;http://mudiator.com/&#34;&gt;Mudiator&lt;/a&gt; mud race in &lt;a href=&#34;https://www.google.de/maps/place/49%C2%B028&#39;11.7%22N+8%C2%B031&#39;34.6%22E/@49.469926,8.526285,17z&#34;&gt;Mannheim&lt;/a&gt;. This mud run features 25 obstacles over 8 km, you can do either one or two rounds. Participating for the first time, the ERNW team went for one round (the &lt;em&gt;Legionnaire&lt;/em&gt; distance as opposed to the two round &lt;em&gt;Hercules&lt;/em&gt; distance):&lt;/p&gt;&#xA;&lt;p&gt; &lt;/p&gt;&#xA;&lt;p&gt;&lt;a href=&#34;http://www.insinuator.net/wp-content/uploads/2015/06/20150607_105045_small.jpg&#34;&gt;&lt;img src=&#34;http://www.insinuator.net/wp-content/uploads/2015/06/20150607_105045_small.jpg&#34; alt=&#34;20150607_105045_small&#34;&gt;&lt;/a&gt;&lt;/p&gt;&#xA;&lt;p&gt;Following our idea of open access to knowledge (both about vulnerabilities and sports 😉 ), here are some hints/lessons learned:&lt;/p&gt;</description>
    </item>
    <item>
      <title>Blog 5: Beyond the Thunderdome: &lt;BR /&gt; A Review of TROOPERS15</title>
      <link>https://insinuator.net/2015/06/blog-5-beyond-the-thunderdome-br-/-a-review-of-troopers15/</link>
      <pubDate>Wed, 03 Jun 2015 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2015/06/blog-5-beyond-the-thunderdome-br-/-a-review-of-troopers15/</guid>
      <description>&lt;p&gt;&lt;a href=&#34;http://www.insinuator.net/wp-content/uploads/2015/06/Troopers13_101.jpg&#34;&gt;&lt;img src=&#34;http://www.insinuator.net/wp-content/uploads/2015/06/Troopers13_101-200x300.jpg&#34; alt=&#34;Troopers13_101&#34;&gt;&lt;/a&gt;     The final blog in our series “Beyond the Thunderdome: A Review of TROOPERS15” focuses Exploitation &amp;amp; Attacking. With the last of this series we hope we you are already fired up and inspired for what lays a head during our upcoming &lt;strong&gt;&lt;a href=&#34;http://www.troopers.de&#34;&gt;TROOPERS16&lt;/a&gt;&lt;/strong&gt; (March 14-18, 2016)! Can’t wait to see you there!&lt;/p&gt;&#xA;&lt;hr&gt;&#xA;&lt;p&gt; &lt;/p&gt;&#xA;&lt;p&gt;“The old is new, again. CVE20112461 is back” talk created and given by Luca Carettoni and Mauro Gentile&lt;/p&gt;</description>
    </item>
    <item>
      <title>ERNW@HAXPO/HITB 2015</title>
      <link>https://insinuator.net/2015/06/ernw@haxpo/hitb-2015/</link>
      <pubDate>Wed, 03 Jun 2015 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2015/06/ernw@haxpo/hitb-2015/</guid>
      <description>&lt;p&gt;Last week we enjoyed quite a wonderful HAXPO exhibition and HITB conference in Amsterdam. A number of great talks could be heard at the main HITB conference such as “&lt;em&gt;Bootkit via SMS: 4G Access Level Security Assessment&lt;/em&gt;” or “&lt;em&gt;Stegosploit: Hacking with Pictures&lt;/em&gt;“. And not only that: there were also several engaging hands-on workshops.&lt;/p&gt;&#xA;&lt;p&gt;Apart from the main conference, there was the HAXPO – a hacker exhibition. At this exhibition you could connect with people from different companies, get a lot of merchandise, and also listen to several briefings on security and its philosophy. Fortunately, we had the pleasure to present two of these briefings and maybe you tested your web application skills at the ERNW booth.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Blog 4: Beyond the Thunderdome: &lt;BR/&gt;A Review of TROOPERS15</title>
      <link>https://insinuator.net/2015/06/blog-4-beyond-the-thunderdome-br/a-review-of-troopers15/</link>
      <pubDate>Mon, 01 Jun 2015 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2015/06/blog-4-beyond-the-thunderdome-br/a-review-of-troopers15/</guid>
      <description>&lt;p&gt;&lt;a href=&#34;http://www.insinuator.net/wp-content/uploads/2015/06/Blog4.jpg&#34;&gt;&lt;img src=&#34;http://www.insinuator.net/wp-content/uploads/2015/06/Blog4-300x134.jpg&#34; alt=&#34;Blog4&#34;&gt;&lt;/a&gt;&lt;/p&gt;&#xA;&lt;p&gt;We hope you are enjoying the ride as we continue our journey through IPv6. Below we have a great mix of talks, slides, and videos in this area posted below. We look forward to hosting more IPv6 (March 14^(th) &amp;amp; 15^(th)) talks next year at &lt;a href=&#34;http://www.troopers.de&#34;&gt;TROOPERS16&lt;/a&gt;!&lt;/p&gt;&#xA;&lt;hr&gt;&#xA;&lt;p&gt; &lt;/p&gt;&#xA;&lt;p&gt;“New Features of the SI6 Networks’IPv6 Toolkit” talk created and given by Fernando Gont&lt;/p&gt;&#xA;&lt;p&gt;The IPV6 Toolkit was originally developed for UK CPNI in an effort to enhance and be able to test the current state of IPv6 security. The toolkit itself was mainly developed for security analysis and trouble shooting of IPv6 networks and implementations. It is running on a wide range of *nix based systems (this probably is considered painful to support given that low level implementation of network functions) and release under the GPL. You can directly check it out here: &lt;a href=&#34;https://github.com/fgont/ipv6toolkit.&#34;&gt;https://github.com/fgont/ipv6toolkit.&lt;/a&gt;&lt;/p&gt;</description>
    </item>
    <item>
      <title>Blog 3: Beyond the Thunderdome: A Review of TROOPERS15</title>
      <link>https://insinuator.net/2015/05/blog-3-beyond-the-thunderdome-a-review-of-troopers15/</link>
      <pubDate>Fri, 29 May 2015 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2015/05/blog-3-beyond-the-thunderdome-a-review-of-troopers15/</guid>
      <description>&lt;p&gt;&lt;a href=&#34;http://www.insinuator.net/wp-content/uploads/2015/05/Blog3.jpg&#34;&gt;&lt;img src=&#34;http://www.insinuator.net/wp-content/uploads/2015/05/Blog3-300x163.jpg&#34; alt=&#34;Blog3&#34;&gt;&lt;/a&gt;&lt;/p&gt;&#xA;&lt;p&gt;Welcome to the third edition of “Beyond the Thunderdome: A Review of&#xA;TROOPERS15”. The focus today is on IPv6 and Data Center Networks, so kick back&#xA;and enjoy the following talks and videos. And as always, check out our website&#xA;&lt;strong&gt;&lt;a href=&#34;http://www.troopers.de&#34;&gt;www.troopers.de&lt;/a&gt;&lt;/strong&gt; for details on TROOPERS16 March&#xA;14-18, 2016.&lt;/p&gt;&#xA;&lt;hr&gt;&#xA;&lt;p&gt; &lt;/p&gt;&#xA;&lt;p&gt;“Enabling and Securing IPv6 in Service Provider Networks” talk created and given by Tarko Titan&lt;/p&gt;&#xA;&lt;p&gt;Telekom.ee had no IPv6, 8 moths ago. They deployed IPv6 in about 4 weeks and by now about 6% of all transported traffic is IPv6 traffic. Actually the 4 weeks timeframe is a bit too optimistic but more on that later. Tarko first explains the biggest problems in the network migration, which were the access network and the Customer -Provider Edge (CPE). Also Telekom Estonia doesn’t want to make a tradeoff at security in the IPv6 deployment.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Blog 2: Beyond the Thunderdome:&lt;BR /&gt;A Review of TROOPERS15</title>
      <link>https://insinuator.net/2015/05/blog-2-beyond-the-thunderdomebr-/a-review-of-troopers15/</link>
      <pubDate>Wed, 27 May 2015 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2015/05/blog-2-beyond-the-thunderdomebr-/a-review-of-troopers15/</guid>
      <description>&lt;p&gt;&lt;a href=&#34;http://www.insinuator.net/wp-content/uploads/2015/05/Blog2.cropped.jpg&#34;&gt;&lt;img src=&#34;http://www.insinuator.net/wp-content/uploads/2015/05/Blog2.cropped-300x137.jpg&#34; alt=&#34;Blog2.cropped&#34;&gt;&lt;/a&gt;&lt;/p&gt;&#xA;&lt;p&gt;Today’s focus in our blog series will cover large-scale environments: Cryptography in Cloud environments and Network Automation. Since these topics will only become more important over time stay tuned for our &lt;a href=&#34;http://www.troopers.de&#34;&gt;TROOPERS16’s&lt;/a&gt; developing agenda to see what new talks will be available (or submit your own talk during our Call for Papers starting in August via our new CFP Submission tool!)&lt;/p&gt;&#xA;&lt;hr&gt;&#xA;&lt;p&gt; &lt;/p&gt;&#xA;&lt;p&gt;“Crypto in the Cloud” talk created and given by Frederik Armknecht&lt;/p&gt;</description>
    </item>
    <item>
      <title>Beyond the Thunderdome:&lt;BR /&gt;A Review of TROOPERS15</title>
      <link>https://insinuator.net/2015/05/beyond-the-thunderdomebr-/a-review-of-troopers15/</link>
      <pubDate>Mon, 25 May 2015 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2015/05/beyond-the-thunderdomebr-/a-review-of-troopers15/</guid>
      <description>&lt;p&gt;&lt;a href=&#34;http://www.insinuator.net/wp-content/uploads/2015/05/beyondthunderdome.jpg&#34;&gt;&lt;img src=&#34;http://www.insinuator.net/wp-content/uploads/2015/05/beyondthunderdome.jpg&#34; alt=&#34;beyondthunderdome&#34;&gt;&lt;/a&gt;&lt;/p&gt;&#xA;&lt;p&gt;Here in Heidelberg we are already gearing up for TROOPERS16 (&lt;strong&gt;taking place from 14th to 18th March 2016&lt;/strong&gt;!). While you are preparing for our Call for Papers or waiting eagerly to sign up for your spot in one of our legendary trainings take a look at our newest blog series “Beyond the Thunderdome: A Review of TROOPERS15”. It may offer some inspiration, help you kill time while waiting for next year’s TROOPERS,  or for those that are new to our conference,  give you a taste for what TROOPERS is all about. See you soon at &lt;a href=&#34;http://www.troopers.de&#34;&gt;TROOPERS16&lt;/a&gt;!&lt;/p&gt;</description>
    </item>
    <item>
      <title>RIPE70 in Amsterdam</title>
      <link>https://insinuator.net/2015/05/ripe70-in-amsterdam/</link>
      <pubDate>Sun, 24 May 2015 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2015/05/ripe70-in-amsterdam/</guid>
      <description>&lt;p&gt;Two weeks ago Christopher and I joined the RIPE70 meeting in Amsterdam. Being part of the group was fun as always and we had quite some interesting conversations with peers from the IPv6 community.&lt;/p&gt;&#xA;&lt;p&gt;We could even contribute a bit to some discussions, with two talks. I gave one titled “Will It Be Routed? – On IPv6 Address Space Allocation &amp;amp; Assignment Approaches in Very Large Organizations” in the Address Policy Working Group session on Wednesday. This is the abstract:&lt;/p&gt;</description>
    </item>
    <item>
      <title>ERNW @ HAXPO 2015</title>
      <link>https://insinuator.net/2015/05/ernw-@-haxpo-2015/</link>
      <pubDate>Wed, 20 May 2015 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2015/05/ernw-@-haxpo-2015/</guid>
      <description>&lt;p&gt;There are lots of interesting places to visit in Amsterdam, but if you are there between the 26th and the 29th of May, then our booth at HAXPO exhibition should be your main destination.&lt;/p&gt;&#xA;&lt;p&gt;&lt;a href=&#34;http://haxpo.nl/haxpo2015ams/&#34;&gt;HAXPO&lt;/a&gt; is a great exhibition, where you can become up-to-date with the latest security technologies, attend various workshops and get in touch with more than 35 IT and information security companies. It will take place in the beautiful historical building “Beurs van Berlage” in the center of Amsterdam. As usual, ERNW will take part in HAXPO. We will be waiting for you in the Community Village section (booth NL-018). Come visit and get to know more about us. You are invited to take our hacking challenges, where the levels of complexity vary from beginners to advanced. Furthermore, we will bring our KNX hacking suitcase!&lt;/p&gt;</description>
    </item>
    <item>
      <title>Hek.si 2015</title>
      <link>https://insinuator.net/2015/05/hek.si-2015/</link>
      <pubDate>Tue, 05 May 2015 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2015/05/hek.si-2015/</guid>
      <description>&lt;p&gt;Hey!&lt;/p&gt;&#xA;&lt;p&gt;I attended this &lt;a href=&#34;http://hek.si/&#34;&gt;really nice conference in Slovenia&lt;/a&gt; on April 16th. It was a smaller conference, but very memorable for the people (students, IT sec professionals and managers alike) who attended.&lt;br&gt;&#xA;I also had the pleasure to present on &lt;a href=&#34;https://www.ernw.de/download/ERNW_heksi_how_secure_am_i_with_emet_v1.0.pdf&#34;&gt;How secure am I with EMET?&lt;/a&gt; and &lt;a href=&#34;https://www.ernw.de/download/ERNW_heksi_apt_armor_eval_v1.0.pdf&#34;&gt;Evaluating the APT armor&lt;/a&gt; and wanted to share the slides with you — feel free to approach me for any kind of feedback or discussion.&lt;/p&gt;&#xA;&lt;p&gt;I’m looking forward to go to Ljubljana again! 😉&lt;/p&gt;</description>
    </item>
    <item>
      <title>SSL Tidbits at the BASTA.NET</title>
      <link>https://insinuator.net/2015/04/ssl-tidbits-at-the-basta.net/</link>
      <pubDate>Wed, 29 Apr 2015 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2015/04/ssl-tidbits-at-the-basta.net/</guid>
      <description>&lt;p&gt;A while a go Dominik and I gave an introductory presentation about SSL at the BASTA.NET conference, a developer-oriented event held in Darmstadt twice a year. At that time there were quite some enthusiastic participants but recently we’ve also gotten some inquiries asking for the relevant materials. Although there’s no recording of the session, we’ve decided to put the slides here for those interested who didn’t make it to the talk.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Troopers PacketWars 2015 – Write Up</title>
      <link>https://insinuator.net/2015/04/troopers-packetwars-2015-write-up/</link>
      <pubDate>Tue, 21 Apr 2015 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2015/04/troopers-packetwars-2015-write-up/</guid>
      <description>&lt;h1 id=&#34;hello-hackers&#34;&gt;Hello Hackers!&lt;/h1&gt;&#xA;&lt;p&gt; &lt;/p&gt;&#xA;&lt;p&gt; &lt;/p&gt;&#xA;&lt;p&gt;This year’s &lt;a href=&#34;http://www.packetwars.com&#34;&gt;PacketWars&lt;/a&gt; contest at Troopers was a blast! Under the topic of “Connected Car” the teams faced several different challenges, which we will describe (as a debriefing) here.&lt;/p&gt;&#xA;&lt;h1 id=&#34;story&#34;&gt;Story&lt;/h1&gt;&#xA;&lt;p&gt; &lt;/p&gt;&#xA;&lt;p&gt; &lt;/p&gt;&#xA;&lt;p&gt;From the &lt;a href=&#34;https://twitter.com/bryanfite&#34;&gt;Packetmaster’s&lt;/a&gt; Battle Briefing:&lt;/p&gt;&#xA;&lt;p&gt;You and your krew are “freelancers” hired to identify and neutralize an unknown threat agent who has created weaponized software and delivered it to civilian Connected Cars via compromised EV (Electrical Vehicle) charing stations. To make matters worse there are indications that new strains of the malware are appearing as the “worm” spreads from car to car. The mobile mesh network created by the Connect Car is highly resilient, allowing the malware to spread exponentially. Time is of the essence.&lt;br&gt;&#xA;Malware analysis suggests that besides a botnet module, there is an active CANBus injection capability. There appears to be other modules but they haven’t been properly reversed and analyzed yet.&lt;/p&gt;</description>
    </item>
    <item>
      <title>SI6 Networks’ IPv6 Toolkit v2.0 (Guille) released at the Troopers IPv6 Security Summit</title>
      <link>https://insinuator.net/2015/04/si6-networks-ipv6-toolkit-v2.0-guille-released-at-the-troopers-ipv6-security-summit/</link>
      <pubDate>Sun, 05 Apr 2015 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2015/04/si6-networks-ipv6-toolkit-v2.0-guille-released-at-the-troopers-ipv6-security-summit/</guid>
      <description>&lt;p&gt;This is a guest post from &lt;a href=&#34;https://twitter.com/FernandoGont&#34;&gt;Fernando Gont&lt;/a&gt;.&lt;/p&gt;&#xA;&lt;p&gt;On March 16^(th), 2015, at the Troopers &lt;a href=&#34;https://www.troopers.de/events/troopers15/322_ipv6_security_summit/&#34;&gt;IPv6 Security Summit&lt;/a&gt;, we finally released the SI6 Networks’ IPv6 Toolkit v2.0 (Guille). The aforementioned release is now available at the &lt;a href=&#34;http://www.si6networks.com/tools/ipv6toolkit&#34;&gt;SI6 IPv6 Toolkit homepage&lt;/a&gt;. It is the result of over a year of work, and includes improvements in the following areas:&lt;/p&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;Increased portability&lt;/li&gt;&#xA;&lt;li&gt;Bug fixes&lt;/li&gt;&#xA;&lt;li&gt;Additional features in existing tools&lt;/li&gt;&#xA;&lt;li&gt;Brand-new tools&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;p&gt;Increased Portability&lt;/p&gt;&#xA;&lt;p&gt;One of the goals that the SI6 Toolkit had since its inception is that of portability. The SI6 Toolkit has supported all major BSD-derived OSes, Linux, and Mac OS for a number of years now. And this new release supports yet another new platform: OpenSolaris. We believe that besides supporting a greater user base, increased portability ultimately results in improved code quality.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Syscan 2015</title>
      <link>https://insinuator.net/2015/03/syscan-2015/</link>
      <pubDate>Tue, 31 Mar 2015 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2015/03/syscan-2015/</guid>
      <description>&lt;p&gt;Last week Matthias and I went to Singapore to teach our workshop on &lt;a href=&#34;https://www.troopers.de/events/troopers15/293_exploiting_hypervisors/&#34;&gt;Hypervisor Exploitation&lt;/a&gt; at &lt;a href=&#34;https://syscan.org/&#34;&gt;SyScan&lt;/a&gt;. After a very unpleasant Lufthansa strike (which made us arrive late in Singapore) and two intense workshop days, we were free to attend the “last” SyScan. There are few IT security conferences that have such a great reputation in the community and so we had high expectations, which were definitely not disappointed. This year had a lot of really interesting talks so I will just summarize some of the ones I liked the most.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Troopers 15 Badge</title>
      <link>https://insinuator.net/2015/03/troopers-15-badge/</link>
      <pubDate>Tue, 31 Mar 2015 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2015/03/troopers-15-badge/</guid>
      <description>&lt;p&gt;As TROOPERS15 has come to an end, I’ve finally got the time and energy to give you a deeper insight into the TR15 badge. As most of you have probably heard during the conference, this year’s badge was based on the &lt;a href=&#34;http://www.openpcd.org/OpenPCD_2_RFID_Reader_for_13.56MHz&#34;&gt;OpenPCD2&lt;/a&gt;. The OpenPCD 2 is a 13.56MHz NFC Reader, Writer and Emulator under the GNU GPL v2. As NFC is, yet again, on an uprise, a badge with NFC simply gives you the chance to fiddle around and hack stacks of stuff in the real world. Adding some TROOPERS spirit and a few little secrets we hope we’ve designed a pretty nice badge!&lt;/p&gt;</description>
    </item>
    <item>
      <title>Troopers15 Videos Online</title>
      <link>https://insinuator.net/2015/03/troopers15-videos-online/</link>
      <pubDate>Sat, 28 Mar 2015 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2015/03/troopers15-videos-online/</guid>
      <description>&lt;p&gt;We’ve just published the videos from TROOPERS15. The playlist can be found &lt;a href=&#34;https://www.youtube.com/playlist?list=PL1eoQr97VfJkfckz9nZFR7tZoBkjij23f&#34;&gt;here&lt;/a&gt;.&lt;br&gt;&#xA;Thanks! again to everybody for joining us in Heidelberg. We had a great time with you 😉&lt;/p&gt;&#xA;&lt;p&gt;Have a good weekend,&lt;/p&gt;&#xA;&lt;p&gt;Enno&lt;/p&gt;&#xA;&lt;p&gt; &lt;/p&gt;</description>
    </item>
    <item>
      <title>GSM@Troopers</title>
      <link>https://insinuator.net/2015/03/gsm@troopers/</link>
      <pubDate>Wed, 18 Mar 2015 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2015/03/gsm@troopers/</guid>
      <description>&lt;p&gt;Additionally to Wifi, Troopers is also offering a GSM network.&lt;br&gt;&#xA;If you want to use it, simply ask your phone to scan for available mobile networks. There you should see the usual T-Mobile D, Vodafone.de, E-Plus, O2-de operators, but also the unusual D 23 or 262 23. Just select this one, and your are done. You also can use the Troopers SIMs which you get on the welcome desk on the ground floor.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Final Agenda of Troopers15 TelcoSecDay</title>
      <link>https://insinuator.net/2015/03/final-agenda-of-troopers15-telcosecday/</link>
      <pubDate>Tue, 10 Mar 2015 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2015/03/final-agenda-of-troopers15-telcosecday/</guid>
      <description>&lt;p&gt;Admitted, we’re a bit late this time, but here we go with the agenda of this year’s TelcoSecDay.&lt;/p&gt;&#xA;&lt;p&gt;Given the high number of quality contributions overall there’s more talks than in the previous years and we’ll hence start more early (and finish later 🙂 ), so please plan accordingly.&lt;br&gt;&#xA;This is the agenda, details for the invididual talks can be found in the respective links:&lt;/p&gt;&#xA;&lt;p&gt;8:30-9:00 Opening &amp;amp; Intro&lt;br&gt;&#xA;9:00-9:45 &lt;a href=&#34;http://www.insinuator.net/2015/02/troopers-15-telcosecday-first-talks/&#34;&gt;Luca Bruno: Through the Looking-Glass, and What Eve Found There&lt;/a&gt;&lt;br&gt;&#xA;9:45-10:30 &lt;a href=&#34;http://www.insinuator.net/2015/02/troopers-telcosecday-next-talks/&#34;&gt;Dieter Spaar: How to Assess M2M Communication from an Attacker’s Perspective&lt;/a&gt;&lt;br&gt;&#xA;Break&lt;br&gt;&#xA;11:00-11:45 &lt;a href=&#34;http://www.insinuator.net/2015/02/troopers-15-telcosecday-first-talks/&#34;&gt;Tobias Engel: Securing the SS7 Interconnect&lt;/a&gt;&lt;br&gt;&#xA;11:45-12:30 &lt;a href=&#34;http://www.insinuator.net/2015/02/troopers-telcosecday-next-talks/&#34;&gt;Ravishankar Borgaonkar: TelcoSecurity Mirage: 1G to 5G&lt;/a&gt;&lt;br&gt;&#xA;12:30-13:00 &lt;a href=&#34;http://www.insinuator.net/2015/02/troopers-telcosecday-next-talks-ii/&#34;&gt;Hendrik Schmidt: Security Aspects of VoLTE&lt;/a&gt;&lt;br&gt;&#xA;Lunch&lt;br&gt;&#xA;14:00-14:45 &lt;a href=&#34;http://www.insinuator.net/2015/02/another-talk-added-to-troopers15-telcosecday/&#34;&gt;Rob Kuiters: On her majesty’s secret service – GRX and a Spy Agency&lt;/a&gt;&lt;br&gt;&#xA;14:45-15:30 &lt;a href=&#34;http://www.insinuator.net/2015/02/troopers-telcosecday-next-talks-ii/&#34;&gt;“Watching the Watchers”&lt;/a&gt;&lt;br&gt;&#xA;Break&lt;br&gt;&#xA;16:00-16:45 &lt;a href=&#34;http://www.insinuator.net/2015/02/troopers-15-telcosecday-first-talks/&#34;&gt;Markus Vervier: Borrowing Mobile Network Identities – Just Because We Can&lt;/a&gt;&lt;br&gt;&#xA;16:45-17:15 &lt;a href=&#34;http://www.insinuator.net/2015/02/troopers-telcosecday-next-talks-ii/&#34;&gt;Shahar Tal: I hunt TR-069 admins – CWMP Insecurity&lt;/a&gt;&lt;br&gt;&#xA;Refreshment&lt;br&gt;&#xA;17:30-18:00 Sébastien Roche (Orange): tba&lt;/p&gt;</description>
    </item>
    <item>
      <title>A Chiron Workshop at the IPv6 Security Summit of Troopers 15</title>
      <link>https://insinuator.net/2015/03/a-chiron-workshop-at-the-ipv6-security-summit-of-troopers-15/</link>
      <pubDate>Wed, 04 Mar 2015 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2015/03/a-chiron-workshop-at-the-ipv6-security-summit-of-troopers-15/</guid>
      <description>&lt;p&gt;This is a guest post from &lt;a href=&#34;https://twitter.com/AntoniosAtlasis&#34;&gt;Antonios Atlasis&lt;/a&gt;.&lt;/p&gt;&#xA;&lt;p&gt;&lt;a href=&#34;http://www.insinuator.net/2014/02/a-short-teaser-on-my-new-ipv6-testing-framework/&#34;&gt;Last year&lt;/a&gt;, during the &lt;a href=&#34;https://www.troopers.de/events/troopers14/372_ipv6_security_summit/&#34;&gt;IPv6 Security Summit&lt;/a&gt; of &lt;a href=&#34;https://www.troopers.de/archives/troopers14/&#34;&gt;Troopers 14&lt;/a&gt; I had the pleasure to present publicly, for first time, my IPv6 Penetration Testing / Security Assessment framework called &lt;a href=&#34;http://www.secfu.net/tools-scripts/&#34;&gt;&lt;em&gt;Chiron&lt;/em&gt;&lt;/a&gt;&lt;em&gt;,&lt;/em&gt; while later, it was also presented at &lt;a href=&#34;http://2014.brucon.org/index.php/&#34;&gt;Brucon 14&lt;/a&gt; as part of the 5×5 project. This year, I am returning back to the place where it all started, to the beautiful city of Heidelberg to give another workshop about &lt;em&gt;Chiron&lt;/em&gt; at the &lt;a href=&#34;https://www.troopers.de/events/troopers15/322_ipv6_security_summit/&#34;&gt;IPv6 Security Summit&lt;/a&gt; of &lt;a href=&#34;https://www.troopers.de/troopers/&#34;&gt;Troopers 15&lt;/a&gt;. But, is it just another workshop with the known Chiron features or has something changed?&lt;br&gt;&#xA;I would say a lot :). The most significant enhancements are described below.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Another Talk Added to Troopers15 TelcoSecDay</title>
      <link>https://insinuator.net/2015/02/another-talk-added-to-troopers15-telcosecday/</link>
      <pubDate>Sat, 14 Feb 2015 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2015/02/another-talk-added-to-troopers15-telcosecday/</guid>
      <description>&lt;p&gt;We have pretty much finalized the agenda for the &lt;a href=&#34;https://www.troopers.de/troopers/&#34;&gt;Troopers&lt;/a&gt; TelcoSecDay and here’s another cool talk (the others can be found &lt;a href=&#34;http://www.insinuator.net/2015/02/troopers-15-telcosecday-first-talks/&#34;&gt;here&lt;/a&gt;, &lt;a href=&#34;http://www.insinuator.net/2015/02/troopers-telcosecday-next-talks/&#34;&gt;here&lt;/a&gt; and &lt;a href=&#34;http://www.insinuator.net/2015/02/troopers-telcosecday-next-talks-ii/&#34;&gt;here&lt;/a&gt;):&lt;/p&gt;&#xA;&lt;p&gt;&lt;strong&gt;Rob Kuiters: On her majesty’s secret service – GRX and a Spy Agency&lt;/strong&gt;&lt;/p&gt;&#xA;&lt;p&gt;Synopsis: In 2013 the GPRS Roaming eXchange (GRX) was in mainstream media as part of the high profile Edward Snowden revelations. The leaked documents indicated that the UK government’s intelligence organisation, Government Communications Headquarters’ (GCHQ) hacked the Belgian GRX provider, Belgacom International Carrier Services (BICS). They did this by targeting the GRX provider’s employees with the ultimate aim of gaining access to Belgacom’s Core GRX routers. Allegedly, GCHQ hacked the GRX routers in order to carry out man-in-the middle “traffic sniffing” attacks against mobile users who are roaming with smartphones or other devices capable of handling data.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Troopers TelcoSecDay – Next Talks (II)</title>
      <link>https://insinuator.net/2015/02/troopers-telcosecday-next-talks-ii/</link>
      <pubDate>Thu, 12 Feb 2015 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2015/02/troopers-telcosecday-next-talks-ii/</guid>
      <description>&lt;p&gt;Hi,&lt;/p&gt;&#xA;&lt;p&gt;in addition to those &lt;a href=&#34;http://www.insinuator.net/2015/02/troopers-15-telcosecday-first-talks/&#34;&gt;recently announced&lt;/a&gt; and &lt;a href=&#34;http://www.insinuator.net/2015/02/troopers-telcosecday-next-talks/&#34;&gt;these&lt;/a&gt;, we’ve identified three more suitable talks for the TelcoSecDay &lt;img src=&#34;http://www.insinuator.net/wp-includes/images/smilies/icon_wink.gif&#34; alt=&#34;;-)&#34;&gt;.&lt;/p&gt;&#xA;&lt;p&gt;These are:&lt;/p&gt;&#xA;&lt;p&gt;&lt;strong&gt;Hendrik Schmidt: Security Aspects of VoLTE&lt;/strong&gt;&lt;/p&gt;&#xA;&lt;p&gt;Synopsis: VoLTE is on its rise in mobile telecommunications. The service is provided by the IP Multimedia Subsystem (IMS) which consists of a couple of components. All those components offer new and, from an attacker’s perspective, interesting interfaces. This talk evaluates the most interesting interfaces and demonstrates attack vectors an attacker could abuse. This covers attacks from customer access, Internet VoIP services and roaming exchange.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Troopers TelcoSecDay – Next Talks</title>
      <link>https://insinuator.net/2015/02/troopers-telcosecday-next-talks/</link>
      <pubDate>Tue, 10 Feb 2015 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2015/02/troopers-telcosecday-next-talks/</guid>
      <description>&lt;p&gt;Hi,&lt;/p&gt;&#xA;&lt;p&gt;in addition to those &lt;a href=&#34;http://www.insinuator.net/2015/02/troopers-15-telcosecday-first-talks/&#34;&gt;recently announced&lt;/a&gt; we’ve identified two more suitable talks for the TelcoSecDay 😉&lt;br&gt;&#xA;These are&lt;/p&gt;&#xA;&lt;p&gt;&lt;strong&gt;Ravishankar Borgaonkar – TelcoSecurity Mirage: 1G to 5G&lt;/strong&gt;&lt;/p&gt;&#xA;&lt;p&gt;Synopsis: The evolution of the mobile networking technology from 1G to 5G is driving the needs of our modern Digital Society. In this talk, we visit the security pillars of these technologies and discuss if 5G can strengthen them or not from an end-users perspective. In particular, we try to fill up security requirements for 5G networks based on the ongoing design direction.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Troopers 15 TelcoSecDay – First Talks</title>
      <link>https://insinuator.net/2015/02/troopers-15-telcosecday-first-talks/</link>
      <pubDate>Sat, 07 Feb 2015 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2015/02/troopers-15-telcosecday-first-talks/</guid>
      <description>&lt;p&gt;At &lt;a href=&#34;https://www.troopers.de/troopers/&#34;&gt;Troopers15&lt;/a&gt; there will be another TelcoSecDay, like in the years before (&lt;a href=&#34;https://www.troopers.de/events/troopers14/395_telcosec_day_2014_invitation_only/&#34;&gt;2014&lt;/a&gt;, &lt;a href=&#34;https://www.troopers.de/events/troopers13/406_telcosec_day_2013_invitation_only/&#34;&gt;2013&lt;/a&gt;, &lt;a href=&#34;https://www.troopers.de/events/troopers12/427_telcosec_day/&#34;&gt;2012&lt;/a&gt;). Here’s the first three talks (of overall 5-6):&lt;/p&gt;&#xA;&lt;p&gt;&lt;strong&gt;Luca Bruno: Through the Looking-Glass, and What Eve Found There&lt;/strong&gt;&lt;/p&gt;&#xA;&lt;p&gt;Synopsis: Traditionally, network operators have provided some kind of public read-only access to their current view of the BGP routing table, by the means of a “looking glass”.&lt;br&gt;&#xA;In this talk we inspect looking glass instances from a security point of view, showing many shortcomings and flaws which could let a malicious entity take control of critical devices connected to them. In particular, we will highlight how easy it is for a low-skilled attacker to gain access to core routers within multiple ISP infrastructures.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Observations from the Cisco Live Europe Wifi Infrastructure</title>
      <link>https://insinuator.net/2015/01/observations-from-the-cisco-live-europe-wifi-infrastructure/</link>
      <pubDate>Tue, 27 Jan 2015 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2015/01/observations-from-the-cisco-live-europe-wifi-infrastructure/</guid>
      <description>&lt;p&gt;Given that Enno and I are network geeks, and that I am responsible for setting up the &lt;a href=&#34;https://www.troopers.de/&#34;&gt;Troopers&lt;/a&gt; Wifi network I was curious which components might be used at Cisco Live and which IPv6 related configuration was done for the Wifi network to ensure a reliable network and reduce the chatty nature of IPv6. Andrew Yourtchenko (&lt;a href=&#34;https://twitter.com/ayourtch&#34;&gt;@ayourtch&lt;/a&gt;) already did an amazing job last year at Cisco Live Europe explaining in detail (at the time session &lt;a href=&#34;http://d2zmdbbm9feqrf.cloudfront.net/2014/eur/pdf/BRKEWN-2666.pdf&#34;&gt;BRKEWN-2666&lt;/a&gt;) the intricacies of IPv6 in Wifi networks, and how to optimize IPv6 for these networks. He was also a great inspiration for me when setting up the &lt;a href=&#34;https://www.troopers.de/media/filer_public/22/9d/229d97ec-f2de-4dac-a533-6651a493f231/troopers14-case_study-building_a_secure_ipv6_guest_wifi_network-christopher_werny.pdf&#34;&gt;Troopers Wifi network&lt;/a&gt; a couple of weeks later. Thank You!&lt;/p&gt;</description>
    </item>
    <item>
      <title>Troopers15 IPv6 Security Summit</title>
      <link>https://insinuator.net/2015/01/troopers15-ipv6-security-summit/</link>
      <pubDate>Tue, 20 Jan 2015 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2015/01/troopers15-ipv6-security-summit/</guid>
      <description>&lt;p&gt;We’ve finalized the agenda for this year’s IPv6 Security Summit. Here’s an overview of the event:&lt;/p&gt;&#xA;&lt;p&gt;The “IPv6 Security Summit” is a special two-day convention in the context of the &lt;a href=&#34;https://www.troopers.de/troopers/&#34;&gt;Troopers security conference&lt;/a&gt;. It will be run in two tracks of both half-day workshops and 90 minute presentations on specific topics. The goal is to foster the discussion of IPv6 security aspects &amp;amp; issues and to provide practical advice for security officers, network planners and practitioners in the IPv6 security field.&lt;/p&gt;</description>
    </item>
    <item>
      <title>31C3 Recap</title>
      <link>https://insinuator.net/2015/01/31c3-recap/</link>
      <pubDate>Sat, 10 Jan 2015 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2015/01/31c3-recap/</guid>
      <description>&lt;p&gt;As every year some of us used the holidays to visit the Chaos Communication Congress to socialize with like-minded people and to hear interesting talks.&lt;br&gt;&#xA;I mean what other reasons than learning about security might exist to leave behind all your lovely in-laws you’ve been sharing some relative’s house with the days before … 😉&lt;br&gt;&#xA;Here is a short recap of some of the talks we found most interesting:&lt;/p&gt;&#xA;&lt;p&gt;&lt;strong&gt;Mining for Bugs with Graph Database Queries&lt;/strong&gt; by &lt;strong&gt;Fabian Yamaguchi&lt;/strong&gt;&lt;br&gt;&#xA;&lt;a href=&#34;http://media.ccc.de/browse/congress/2014/31c3_-_6534_-_en_-_saal_g_-_201412282030_-_mining_for_bugs_with_graph_database_queries_-_fabs.html#video&#34;&gt;Video&lt;/a&gt;&lt;br&gt;&#xA;One of my favorite talks at this years congress was about the open source tool &lt;a href=&#34;http://mlsec.org/joern/&#34;&gt;joern&lt;/a&gt;, a code analysis platform for C/C++ applications. Fabian, the main author of joern, presented his work on vulnerability discovery in large code bases. One of the key points of his work is robustness, meaning that the resulting tools should produce meaningful results in large and noisy real world projects even if this results in a loss of accuracy. The second important point is that tools should assist human auditors, not replace them, which seems to be one of the more interesting current research directions (see also &lt;a href=&#34;https://static.squarespace.com/static/507c09ede4b0954f51d59c75/t/528965cbe4b037c7a156b3f1/1384736203503/think_cyborg_not_robot.pdf&#34;&gt;this paper&lt;/a&gt;). At its core joern combines standard compiler technology with modern graph databases to offer auditors a powerful way to search for certain code constructs. To do this joern parses source code into an AST (Abstract Syntax Tree) and creates the corresponding CFG (Control Flow Graph), as well as a Data Dependency Graph (PDG) for all functions. This creates the Code Property Graph which combines all three representation forms into a single unified layer.&lt;br&gt;&#xA;The Code Property Graph is stored inside a graph database (joern uses &lt;a href=&#34;http://neo4j.com/&#34;&gt;neo4j&lt;/a&gt;), which can be queried using a powerful graph traversal language named &lt;a href=&#34;https://github.com/tinkerpop/gremlin/wiki&#34;&gt;gremlin&lt;/a&gt; (&lt;a href=&#34;https://github.com/tinkerpop/gremlin/wiki)&#34;&gt;https://github.com/tinkerpop/gremlin/wiki)&lt;/a&gt;. The combination of gremlin with some wrapper tools included in joern gives an auditor the possibility to construct powerful search queries against the code base. Fabian presented different queries he used to search for vulnerabilities in the VLC video player, as well as the Linux kernel that resulted in really impressive results (and a high number of discovered vulnerabilities). Joern is definitely a tool you should check out and I’m looking forward to more impressive research by its author.&lt;br&gt;&#xA;– Felix&lt;/p&gt;</description>
    </item>
    <item>
      <title>Troopers15 – 5th Round of Talks Selected</title>
      <link>https://insinuator.net/2015/01/troopers15-5th-round-of-talks-selected/</link>
      <pubDate>Sat, 03 Jan 2015 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2015/01/troopers15-5th-round-of-talks-selected/</guid>
      <description>&lt;p&gt;Happy new year and all the best for 2015 to everybody!&lt;br&gt;&#xA;Here’s the next round of Troopers15 talks (all the others can be found &lt;a href=&#34;http://www.insinuator.net/tag/TR15/&#34;&gt;here&lt;/a&gt;):&lt;/p&gt;&#xA;&lt;p&gt;===&lt;/p&gt;&#xA;&lt;p&gt;Marion Marschalek &amp;amp; Moti Joseph: The Wallstreet of Windows Binaries        &lt;strong&gt;FIRST TIME MATERIAL&lt;/strong&gt;&lt;/p&gt;&#xA;&lt;p&gt;&lt;strong&gt;Synopsis&lt;/strong&gt;: Nowadays common ways to find exploitable vulnerabilities include but are not limited to fuzzing, static and dynamic analysis and patch reversing. All common approaches have advantages and limits. Fuzzers tend to only find a limited number of bugs, depending on the sophistication of the fuzzer which is indirectly dependent on the development time invested. Reverse engineering a binary for finding bugs, regardless whether statically or with a debugger, is tedious and requires a lot of time and expertise.&lt;br&gt;&#xA;As we are lazy bastards, we refuse to do all the work by hand and brain. And, as we are greedy bastards, we want a maximum scope of vulnerabilities we can cover and not be limited to what we see from a fuzzers perspective.&lt;br&gt;&#xA;So as you know – in general the lazy greedy bastards have the better ideas. We present you with our idea, which is built after the model of the Wallstreet. We built a tool which weighs the value of a function in a Windows binary as the Wallstreet values a stock; the value telling us the likability of a function to be exploitable.&lt;br&gt;&#xA;The Wallstreet technique works with two different evaluation methods, for once the likability that a function is vulnerable and also the likability that it is exploitable.&lt;br&gt;&#xA;We collect indicators, which help us evaluate that a specific function is potentially vulnerable. Such could be a present memory allocation or conversion function, a lacking sanitization check or a suspicious pattern in the functionname such as ‘create’, ‘convert’ or ‘set’. A combination of these and a handful more indicators lets us calculate what we call the speculation value.&lt;br&gt;&#xA;For the validation of the exploitability we traverse the call tree of a suspicious candidate, to verify its accessibility in an automated way. Only functions which we can influence as an attacker are interesting for us; thus we rate these accessible functions with a price-to-earnings value. Finally putting speculation value and price-to-earnings value in context, we evaluate a function with either ‘buy’ if we believe it comes with an exploitable vulnerability, or with ‘sell’ when we are certain it is not interesting to us. No worries, the presentation will not contain advanced mathematical equations.&lt;br&gt;&#xA;Our tool parses binaries and persists all the gathered information to a database, from where we can retrieve highly suspicious functions in an automated way. Without getting our hands dirty, that is. And because we are lazy bastards who like colors, a lot, we use visuals to make evaluation even easier. The tool is dubbed Wallstreet, free after the most famous stock market on the planet. It is based on Python, C and SQLite and will be released under the WTFPL license (&lt;a href=&#34;http://www.wtfpl.net/)&#34;&gt;http://www.wtfpl.net/)&lt;/a&gt;. Also, there will be demos 😀&lt;br&gt;&#xA;Wrapping it up, this presentation shows an easy to use approach which makes the complicated topic of binary exploitation more accessible. Wallstreet of Windows Binaries provides beginners with better understanding of the challenges and practitioners with a hands-on tool.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Troopers15 – Fourth Round of Talks Selected</title>
      <link>https://insinuator.net/2014/12/troopers15-fourth-round-of-talks-selected/</link>
      <pubDate>Mon, 29 Dec 2014 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2014/12/troopers15-fourth-round-of-talks-selected/</guid>
      <description>&lt;p&gt;As we promised some days ago here’s the fourth round of Troopers15 talks (the first three can be found &lt;a href=&#34;http://www.insinuator.net/tag/tr15/&#34;&gt;here&lt;/a&gt;). We really can’t wait for the con ourselves 😉 !&lt;/p&gt;&#xA;&lt;p&gt;Arrigo Triulzi: Pneumonia, Shardan, Antibiotics and Nasty MOV: a Dead Hand’s Tale&lt;br&gt;&#xA;&lt;strong&gt;FIRST TIME MATERIAL&lt;/strong&gt;&lt;/p&gt;&#xA;&lt;p&gt;Synopsis: Starting in the 80’s we will discuss the influence of nuclear weapons on the design of an ITsec “Dead Hand” system for a security practitioner, how it merged with research into firmware backdoors and microcode modification and finally triggered when instead of enjoying Summer pneumonia struck unannounced, or rather, announced by the Dead Hand via Twitter.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Troopers15 – Third Round of Talks Selected</title>
      <link>https://insinuator.net/2014/12/troopers15-third-round-of-talks-selected/</link>
      <pubDate>Sat, 20 Dec 2014 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2014/12/troopers15-third-round-of-talks-selected/</guid>
      <description>&lt;p&gt;As we promised some days ago here’s the third round of Troopers15 speakers (first one &lt;a href=&#34;http://www.insinuator.net/2014/11/troopers15-first-round-of-talks-selected/&#34;&gt;here&lt;/a&gt;, second &lt;a href=&#34;http://www.insinuator.net/2014/12/troopers15-second-round-of-talks-selected/&#34;&gt;here&lt;/a&gt;). It’s going to be awesome!&lt;/p&gt;&#xA;&lt;p&gt;&lt;a href=&#34;http://3vildata.tumblr.com/&#34;&gt;Andreas Lindh&lt;/a&gt;: Defender Economics         &lt;strong&gt;FIRST TIME MATERIAL&lt;/strong&gt;&lt;/p&gt;&#xA;&lt;p&gt;Synopsis: There are a lot of preconceptions about defense, the most prevalent one probably the “defenders dilemma” in which it is stated that an attacker only needs to find one weakness to compromise a network while a defender needs to defend all of them. While this may be true in a technical sense, things become a lot more complicated once you apply real world considerations. Preconceptions like this are often the foundation on which risk management and ultimately defense strategies are based, something that has led to a number of false but generally accepted assumptions about attackers and their capabilities, and how to defend against them.&lt;br&gt;&#xA;This talk will discuss the capabilities, and more importantly the limitations, of different types of attackers. Using the ancient wisdom of the Teenage Mutant Ninja Turtles, the speaker will explain how knowledge of an attacker’s limitations can be leveraged to raise the cost of attack, something that will tip the scale in the defenders favor. The speaker will also explain how different defensive measures will affect different types of attackers, how they are likely to react to them, and in the end how to get them to hopefully move on to another target.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Troopers15 – Second Round of Talks Selected</title>
      <link>https://insinuator.net/2014/12/troopers15-second-round-of-talks-selected/</link>
      <pubDate>Fri, 05 Dec 2014 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2014/12/troopers15-second-round-of-talks-selected/</guid>
      <description>&lt;p&gt;As we promised some days ago when we &lt;a href=&#34;http://www.insinuator.net/2014/11/troopers15-first-round-of-talks-selected/&#34;&gt;published the first round&lt;/a&gt;, here we go with the second:&lt;/p&gt;&#xA;&lt;p&gt;&lt;a href=&#34;https://twitter.com/michaelossmann&#34;&gt;Mike Ossmann&lt;/a&gt;: RF Retroreflectors, Emission Security and SDR&lt;/p&gt;&#xA;&lt;p&gt;Synopsis: The leaked pages from the NSA ANT catalog provided a glimpse into the modern world of emission security. Extending beyond passive monitoring of unintentional emissions, today’s spooks employ active attacks with tools such as RF retroreflectors. I’ll report on my experiments to reproduce such techniques with open source hardware and software, primarily using SDR.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Troopers15 – First Round of Talks Selected</title>
      <link>https://insinuator.net/2014/11/troopers15-first-round-of-talks-selected/</link>
      <pubDate>Sat, 22 Nov 2014 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2014/11/troopers15-first-round-of-talks-selected/</guid>
      <description>&lt;p&gt;We’re delighted to provide the first announcement of talks of next year’s &lt;a href=&#34;https://www.troopers.de/&#34;&gt;Troopers&lt;/a&gt; edition. Looks like it’s going to be a great event again &lt;img src=&#34;http://www.insinuator.net/wp-includes/images/smilies/icon_wink.gif&#34; alt=&#34;;-)&#34;&gt;.&lt;br&gt;&#xA;Here we go:&lt;/p&gt;&#xA;&lt;p&gt;Jacob Torrey – The foundation is rotting and the basement is flooding: A deeper look at the implicit trust relationships in your organization        &lt;strong&gt;FIRST TIME MATERIAL&lt;/strong&gt;&lt;/p&gt;&#xA;&lt;p&gt;Synopsis: In this session, a new hardware-level attack on PCIe is presented as an example for the implicit trust your organization places in 3rd parties. These implicit trust relationships that are typically overlooked will be closely examined under the lens of “InfoSec debt” and providing guidance to InfoSec decision makers on the ROI or risks of adding additional IT services/appliances to an organization’s network.&lt;br&gt;&#xA;The “InfoSec debt” metric can then be tracked over time and provides an intuitive way to explain the cost/benefits of IT security to other organizational stakeholders.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Power of Community 2014</title>
      <link>https://insinuator.net/2014/11/power-of-community-2014/</link>
      <pubDate>Thu, 13 Nov 2014 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2014/11/power-of-community-2014/</guid>
      <description>&lt;p&gt;I had the pleasure to participate in this year’s &lt;a href=&#34;http://www.powerofcommunity.net/index.html&#34; title=&#34;Power of Community 2014&#34;&gt;Power of Community&lt;/a&gt; and was invited to talk about the insecurity of medical devices. The conference is based in Seoul, Korea and started in 2006. It has a strong technical focus and it is a community driven event. For me it was great to participate as mostly hackers from Asia were there and I got the chance to talk to a lot of nice folks that I wouldn’t be able to meet otherwise. This is especially true for the host, vangelis.&lt;/p&gt;</description>
    </item>
    <item>
      <title>LTE vs. Darwin @ Hackers to Hackers Conference 11</title>
      <link>https://insinuator.net/2014/10/lte-vs.-darwin-@-hackers-to-hackers-conference-11/</link>
      <pubDate>Sun, 19 Oct 2014 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2014/10/lte-vs.-darwin-@-hackers-to-hackers-conference-11/</guid>
      <description>&lt;p&gt;Hello Everybody and greetings from Sao Paulo,&lt;/p&gt;&#xA;&lt;p&gt; &lt;br&gt;&#xA;We’re currently enjoying the Brazilian sunshine, waiting for H2H2 11’s closing remarks and decided to give you a few details on the past three days. The conference was opened by a short welcome by our fellow Trooper Rodrigo Rubira Branco and stuffed with loads of great talks. This year’s keynotes came from Daniel J. Bernstein and Halvar Flake and gave yet another insight into the ever changing world of InfoSec. The international lineup also included Travis Goodspeed, Sergej Bratus and Fernando Gont. H2HC was a great chance for us to talk to various Hackers from around the world and share our opinions and knowledge.We can only warmly recommend a visit to next year’s H2HC in Sao Paulo.&lt;br&gt;&#xA;Many many thanks to Rodrigo, Laila and the rest of the team for an awesome weekend. And a quick hello to all new followers on Insinuator.net, we’re looking forward to meeting you all again, soon.&lt;/p&gt;</description>
    </item>
    <item>
      <title>North American IPv6 Summit 2014</title>
      <link>https://insinuator.net/2014/10/north-american-ipv6-summit-2014/</link>
      <pubDate>Tue, 14 Oct 2014 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2014/10/north-american-ipv6-summit-2014/</guid>
      <description>&lt;p&gt;Hello everyone,&lt;/p&gt;&#xA;&lt;p&gt;I know I am a bit late with this post, but I was speaking on the &lt;a href=&#34;http://www.rmv6tf.org/na-ipv6-summit/2014-na-ipv6-summit&#34;&gt;North American IPv6 Summit&lt;/a&gt; in Denver three weeks ago. The focus of my talk was on &lt;em&gt;&lt;a href=&#34;https://www.ernw.de/download/TROOPERS_IPv6SecSummit_ERNW_IPv6_Structural_Deficits.pdf&#34;&gt;Why IPv6 Security is hard – Structural Deficits of IPv6 &amp;amp; Their Implications&lt;/a&gt;&lt;/em&gt; (slightly modified/updated from the &lt;a href=&#34;https://www.troopers.de/troopers14/troopers14-ipv6-security-summit-2014/index.html&#34;&gt;Troopers IPv6 Security Summit&lt;/a&gt;).  We consider the NA IPv6 Summit as one of the most important IPv6 events at all and we were happy to contribute to the overall success. The conference was organized for the 7^(th) time by the &lt;a href=&#34;http://www.rmv6tf.org/&#34;&gt;Rocky Mountain IPv6 Task Force&lt;/a&gt; and took place in the Grand Hyatt Denver (37th floor ;-)). Luckily the weather was perfect, and the view of the landscape from the conference rooms was just amazing. I really enjoyed the time in Denver, as the organizer sdid all they could to treat the speaker well J. The talks were of mix of regular research or case-study type talks and some sponsored talks ranging from deployment experience, security and statistics to SDN (Yes, I said it ;)) and the Internet of Things (I said it again ;)). The line-up was nicely put together.&lt;/p&gt;</description>
    </item>
    <item>
      <title>“Hacking for a B33r” at Ghent</title>
      <link>https://insinuator.net/2014/09/hacking-for-a-b33r-at-ghent/</link>
      <pubDate>Sat, 27 Sep 2014 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2014/09/hacking-for-a-b33r-at-ghent/</guid>
      <description>&lt;p&gt;This is a guest post by &lt;a href=&#34;http://www.secfu.net/about-me/&#34;&gt;Antonios Atlasis&lt;/a&gt;.&lt;/p&gt;&#xA;&lt;p&gt;This week I had the pleasure to attend &lt;a href=&#34;http://2014.brucon.org/&#34;&gt;BruCON 2014&lt;/a&gt;. While participating at the &lt;em&gt;Brucon 5×5&lt;/em&gt; program, I had also the chance to attend this well-known European Con which is held in the beautiful city of Ghent.&lt;/p&gt;&#xA;&lt;p&gt;The main event took place two days (on 25th and 26th of September), while some very interesting trainings were given in the previous days. There was mainly one track, plus some workshops that you could also attend, if you wished. You could book your seat at one of the workshops using an &lt;a href=&#34;http://sched.brucon.org/&#34;&gt;on-line scheduling system&lt;/a&gt;.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Wrap-Up: A Memorable Week at Black Hat and DEFCON in Las Vegas</title>
      <link>https://insinuator.net/2014/08/wrap-up-a-memorable-week-at-black-hat-and-defcon-in-las-vegas/</link>
      <pubDate>Fri, 15 Aug 2014 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2014/08/wrap-up-a-memorable-week-at-black-hat-and-defcon-in-las-vegas/</guid>
      <description>&lt;p&gt;Information security conferences are known to be attended because of several reasons. For some it’s the technical content, for others the networking potential and for some others simply meeting old friends. Pinpointing our motives is clearly a challenging task, but the following wrap-up ought to share our personal highlights of the week we spent visiting Black Hat USA 2014 and DEFCON 22 in Las Vegas.&lt;/p&gt;&#xA;&lt;p&gt;After somewhat 18 hours of flight, some sleep and with the beautiful scenery of perpetual clear skies above Las Vegas we began what was to be an incredible week.&lt;/p&gt;</description>
    </item>
    <item>
      <title>ERNW @BlackHat US 2014</title>
      <link>https://insinuator.net/2014/08/ernw-@blackhat-us-2014/</link>
      <pubDate>Tue, 12 Aug 2014 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2014/08/ernw-@blackhat-us-2014/</guid>
      <description>&lt;p&gt;Last week we had the opportunity and pleasure to present some of our research results at BlackHat US 2014 (besides of meeting a lot of old friends and having a great researchers’ dinner).&lt;/p&gt;&#xA;&lt;p&gt;Enno and Antonios gave their presentation on IDPS evasion by IPv6 Extension Headers, described &lt;a href=&#34;http://www.insinuator.net/2014/08/evading-idps-by-combining-ipv6-extension-headers-and-fragmentation-features-the-story-of-my-life/&#34;&gt;here&lt;/a&gt;.&lt;/p&gt;&#xA;&lt;p&gt;The material can be found here: &lt;a href=&#34;https://www.ernw.de/download/Atlasis_Rey_BHUSA_2014_IPv6_Evasion_of_HighEnd_IPS_Devices_web.pdf&#34;&gt;Slides&lt;/a&gt;, &lt;a href=&#34;http://www.secfu.net/tools-scripts/&#34;&gt;tools&lt;/a&gt; (the main tool used was Chiron, authored by Antonios) &amp;amp; &lt;a href=&#34;https://www.ernw.de/download/us-14-Atlasis-Evasion-Of-HighEnd-IPS-Devices-In-The-Age-Of-IPv6-WP.pdf&#34;&gt;whitepaper&lt;/a&gt;.&lt;/p&gt;&#xA;&lt;p&gt;Ayhan and me presented our results of the security analysis of Cisco’s EnergyWise protocol. The protocol enables network-wide power monitoring and control (ie turning servers off or on, putting phones to standby — basically controlling the power state of all EnergyWise-enabled or PoE devices). The main problem (besides a DoS vulnerability we found in IOS, see &lt;a href=&#34;http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20140806-energywise&#34;&gt;official Cisco advisory&lt;/a&gt;) is its PSK-based authentication model, which enables an attacker to cause large-scale blackouts in data centers if the deployment is lacking certain controls (for example our good old favorite, segmentation…). There will be a longer blogpost/newsletter on this topic soon.&lt;br&gt;&#xA;The material can be found here: &lt;a href=&#34;https://www.ernw.de/download/ERNW_BHUS14_WhenTheLightsGoOut_akoca-mluft.pdf&#34;&gt;Slides&lt;/a&gt; &amp;amp; &lt;a href=&#34;https://www.ernw.de/download/tools/energywise_attack_suite_BH_US14.zip&#34;&gt;tools&lt;/a&gt;&lt;/p&gt;</description>
    </item>
    <item>
      <title>HackInTheBox and Haxpo – 2014</title>
      <link>https://insinuator.net/2014/07/hackinthebox-and-haxpo-2014/</link>
      <pubDate>Mon, 07 Jul 2014 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2014/07/hackinthebox-and-haxpo-2014/</guid>
      <description>&lt;p&gt;&lt;img src=&#34;http://www.insinuator.net/wp-content/uploads/2014/06/haxpoHITB_overview_small.jpg&#34; alt=&#34;Haxpo Overview 2014&#34;&gt;&lt;/p&gt;&#xA;&lt;p&gt;Haxpo Overview 2014&lt;/p&gt;&#xA;&lt;p&gt;Past month we (which is me and a group of other ERNW students, supported by some of the “old” guys — I hope my team lead won’t yell at me for this 😉 ) attended the Haxpo and Hack in the Box in Amsterdam. Starting from 28. May, we had three days at this great conference (&lt;a href=&#34;http://www.hitb.org/&#34;&gt;HITB&lt;/a&gt;) and exposition (&lt;a href=&#34;http://haxpo.nl/&#34;&gt;Haxpo&lt;/a&gt;). The two events took place in the former building of the stock exchange in Amsterdam, called: “&lt;a href=&#34;http://www.beursvanberlage.nl/&#34;&gt;Beurs van Berlage&lt;/a&gt;”. Upon entering the building for the first time we were given details on where our booth was and where the talks would take place — setting up our booth and planning the shifts was just another thing to do before exploring the Haxpo area:&lt;/p&gt;</description>
    </item>
    <item>
      <title>Hackito Ergo Sum 2014</title>
      <link>https://insinuator.net/2014/05/hackito-ergo-sum-2014/</link>
      <pubDate>Fri, 02 May 2014 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2014/05/hackito-ergo-sum-2014/</guid>
      <description>&lt;p&gt;Greetings from Heidelberg to Paris,&lt;/p&gt;&#xA;&lt;p&gt;and thanks for a great time at &lt;a href=&#34;http://2014.hackitoergosum.org/&#34;&gt;HES14&lt;/a&gt;! A nice venue (&lt;a href=&#34;http://www.cite-sciences.fr/fr/accueil/&#34;&gt;a museum&lt;/a&gt;), sweet talks and stacks of spirit carried us through the three day con. It all set off with a keynote byTROOPERs veteran Edmond ‘bigezy’ Rogers, who stuck to a quite simple principle: “People do stupid things” and I guess every single one of you has quite a few examples for that on offer. Next to every speaker referenced that statement at some point during her/his talk. Furthermore we presented an updated version of our talk &lt;a href=&#34;http://2014.hackitoergosum.org/slides/day1_ERNW_LTEvsDarwin_HES.pdf&#34;&gt;LTE vs. Darwin&lt;/a&gt;, covering our research of security in LTE networks and potential upcoming problems.&lt;/p&gt;</description>
    </item>
    <item>
      <title>The Three Billion Dollar App – Some Notes on My Upcoming Troopers Talk</title>
      <link>https://insinuator.net/2014/02/the-three-billion-dollar-app-some-notes-on-my-upcoming-troopers-talk/</link>
      <pubDate>Tue, 25 Feb 2014 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2014/02/the-three-billion-dollar-app-some-notes-on-my-upcoming-troopers-talk/</guid>
      <description>&lt;p&gt;This is a guest post from Vladimir Wolstencroft from our friends of &lt;a href=&#34;http://www.aurainfosec.com/&#34;&gt;aura information security&lt;br&gt;&#xA;=&lt;/a&gt;=================================================================&lt;/p&gt;&#xA;&lt;p&gt;Mobile messaging applications have been occupying people’s attention and it seems to be all the latest news. Perhaps I should have called my presentation the 19 Billion dollar app but at the time of writing and research I thought the proposed 3 Billion dollar amount for SnapChat was a little ludicrous, who could have known that would have been just a drop in the ocean.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Preliminary Agenda for Troopers 2014 Telco Sec Day</title>
      <link>https://insinuator.net/2014/02/preliminary-agenda-for-troopers-2014-telco-sec-day/</link>
      <pubDate>Tue, 04 Feb 2014 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2014/02/preliminary-agenda-for-troopers-2014-telco-sec-day/</guid>
      <description>&lt;p&gt;Given we’ve received a number of inquiries as for the agenda of this year’s TelcoSecDay here’s a first preliminary agenda. To get an idea of the event’s character you might have a look at the agenda of the &lt;a href=&#34;https://www.troopers.de/archives/troopers12/agenda12/troopers12-telcosec-day/index.html&#34;&gt;2012 edition&lt;/a&gt; or the &lt;a href=&#34;https://www.troopers.de/archives/troopers13/agenda13/troopers13-telcosec-day-2013/index.html&#34;&gt;2013 edition&lt;/a&gt;. Pls note that there might be changes/additions to the following outline as we’re currently discussing potential contributions with two European operators. Here we go, for today:&lt;/p&gt;&#xA;&lt;p&gt;9:00: Opening Remarks &amp;amp; Introduction&lt;br&gt;&#xA;9:15: Ravi Borgaonkor – Evolution of SIM Card Security&lt;br&gt;&#xA;10:15: Break&lt;br&gt;&#xA;10:45: Adrian Dabrowski&lt;br&gt;&#xA;11:45: Collin Mulliner – PatchDroid – Third Party Security Patches for Android&lt;br&gt;&#xA;12:30: Lunch&lt;br&gt;&#xA;13:45: Philippe Langlois&lt;br&gt;&#xA;14:45: Break&lt;br&gt;&#xA;15:15: Haya Shulman – The Illusion of Challenge-Response Authentication&lt;br&gt;&#xA;16:00: Christian Sielaff &amp;amp; Daniel Hauenstein – Breaking Network Monitoring Tools Used in Telco Space&lt;br&gt;&#xA;16:30: Closing Remarks&lt;br&gt;&#xA;19:00: Joint dinner (hosted by ERNW) in Heidelberg Altstadt for those interested and/or staying for the main conference&lt;/p&gt;</description>
    </item>
    <item>
      <title>LTE@ShmooCon, a Summary</title>
      <link>https://insinuator.net/2014/01/lte@shmoocon-a-summary/</link>
      <pubDate>Tue, 28 Jan 2014 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2014/01/lte@shmoocon-a-summary/</guid>
      <description>&lt;p&gt;Hey guys,&lt;br&gt;&#xA;as some of you may have noticed, just recently at ShmooCon we gave our talk “LTE vs. Darwin” (Slides &lt;a href=&#34;http://www.insinuator.net/wp-content/uploads/2014/01/ERNW_LTEvsDarwin.pdf&#34;&gt;here&lt;/a&gt;). There we presented some results of our research in 4G telco network security. Some of those originate from our research contribution to &lt;a href=&#34;www.asmonia.de&#34;&gt;ASMONIA&lt;/a&gt;, but we expanded the scope and also took a look at the air interface. Both the air interface and the backend links &amp;amp; protocols must be secured appropriately; otherwise communication may be eavesdropped or sensitive information may be compromised. In the following we want to provide an overview of LTE main components and potential attack vectors.&lt;/p&gt;</description>
    </item>
    <item>
      <title>ShmooCon 2014</title>
      <link>https://insinuator.net/2014/01/shmoocon-2014/</link>
      <pubDate>Sun, 26 Jan 2014 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2014/01/shmoocon-2014/</guid>
      <description>&lt;p&gt;Last weekend, from 17 to 19 January, &lt;a href=&#34;http://www.shmoocon.org/&#34;&gt;ShmooCon&lt;/a&gt; was held in Washington, DC. A number of different topics was covered in great talks and we want to give you a short overview of the conference. In the following our favorite talks are briefly summarized.&lt;/p&gt;&#xA;&lt;p&gt;&lt;strong&gt;Privacy Online: What Now?&lt;/strong&gt;&lt;br&gt;&#xA;Ian Goldberg, one of the designers of the &lt;a href=&#34;http://en.wikipedia.org/wiki/Off-the-Record_Messaging&#34;&gt;OTR Protocol&lt;/a&gt;, gave the keynote on the first day. His talk was quite interesting and he presented some really nice approaches, one of those being an attack against PGP. He described the attack as follows: an attacker could copy a key server by downloading all the stored keys. If this is done it is possible to create new key pairs with exactly the same settings as the keys downloaded. The third step is to create all the signing links between the keys as they exist on the real key server. Finally, the attacker uploads these new keys including the signing links to the original key server.&lt;br&gt;&#xA;Now, in case Alice wants to retrieve the public key of Bob, Alice would find two keys with seemingly identical properties. If choosing the wrong key for encryption the message will be decipherable by the attacker and in case of MitM situation be accessed. Furthermore, if Alice then signs the “mirror key”, the cloned keys and the original would merge, resulting in further problems.&lt;br&gt;&#xA;This was just one consideration discussed in Goldberg’s talk. For the full content, watch the recording, available soon on ShmooCon page.&lt;/p&gt;</description>
    </item>
    <item>
      <title>More Troopers Talks Selected</title>
      <link>https://insinuator.net/2014/01/more-troopers-talks-selected/</link>
      <pubDate>Sat, 18 Jan 2014 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2014/01/more-troopers-talks-selected/</guid>
      <description>&lt;p&gt;Today we have to pleasure to announce another round of &lt;a href=&#34;https://www.troopers.de/&#34;&gt;Troopers&lt;/a&gt; talks.&lt;br&gt;&#xA;Here we go:&lt;/p&gt;&#xA;&lt;p&gt; &lt;br&gt;&#xA;Noam Liram: Vulnerability Classification in the SaaS Era      &lt;strong&gt;FIRST TIME MATERIAL&lt;/strong&gt;&lt;/p&gt;&#xA;&lt;p&gt;Abstract: In this talk we will thoroughly analyze two major SaaS vulnerabilities that were found by Adallom (one of which is still in responsible disclosure stages at the time of writing). By demonstrating this new class of exploits which we have nick-named “Ice Dagger” attacks, we aim to change the current industry-wide criteria for vulnerability classifications, which were developed in the Desktop/Server world, are inadequate when classifying SaaS vulnerabilities. We will specifically discuss the details of MS13-104.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Some notes on 30C3</title>
      <link>https://insinuator.net/2014/01/some-notes-on-30c3/</link>
      <pubDate>Wed, 08 Jan 2014 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2014/01/some-notes-on-30c3/</guid>
      <description>&lt;p&gt;We wish you a happy new year and a good start to 2014. A new year has begun and, just before that, 30C3 took place. I think almost all of you have heard about the congress and its topics. In particukar there was Glenn Greenwald’s &lt;a href=&#34;https://events.ccc.de/congress/2013/Fahrplan/events/5622.html&#34;&gt;keynote&lt;/a&gt; or there were new &lt;a href=&#34;https://events.ccc.de/congress/2013/Fahrplan/events/5713.html&#34;&gt;publications/revelations&lt;/a&gt; by Jacob Appelbaum, which you will probably have heard about from main media.&lt;br&gt;&#xA;But besides of all that, there were really a lot of other interesting talks we want to give you a short introduction to. Overall it was a really good conference this year and a lot of awesome talks. But, like always, it is not possible to see all of them, so here is a short summary of some of our favorites:&lt;/p&gt;</description>
    </item>
    <item>
      <title>Troopers 2014 – Third Round of Talks Selected</title>
      <link>https://insinuator.net/2014/01/troopers-2014-third-round-of-talks-selected/</link>
      <pubDate>Fri, 03 Jan 2014 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2014/01/troopers-2014-third-round-of-talks-selected/</guid>
      <description>&lt;p&gt;At first a very happy new year to all our readers!&lt;/p&gt;&#xA;&lt;p&gt;Today we announce the third round of Troopers 2014 talks (first round &lt;a href=&#34;http://www.insinuator.net/2013/11/troopers-2014-first-round-of-talks-selected/&#34;&gt;here&lt;/a&gt;, second &lt;a href=&#34;http://www.insinuator.net/2013/12/troopers-2014-second-round-of-talks-selected/&#34;&gt;here&lt;/a&gt;).&lt;/p&gt;&#xA;&lt;p&gt;Here we go:&lt;/p&gt;&#xA;&lt;p&gt;===&lt;/p&gt;&#xA;&lt;p&gt;Daniel Mende: Implementing an USB Host Driver Fuzzer         &lt;strong&gt;FIRST TIME MATERIAL&lt;/strong&gt;&lt;/p&gt;&#xA;&lt;p&gt;Abstract: The Universal Serial Bus (USB) can be found everywhere these days, may it be to connect a mouse or keyboard to the computer, transfer data on a flash drive connected via USB or to attach some additional hardware like a Digital Video Broadcast receiver. Some of these devices use a standardized device class which are served by an operating system default driver while other, special purpose devices, do not fit into any of those classes, so vendors ship their own drivers. As every vendor specific USB driver installed on a system adds additional attack surface, there needs to be some method to evaluate the stability and the security of those vendor proprietary drivers. The simplest way to perform a stability analysis of closed source products is the fuzzing approach. As there have been no publicly available tools for performing USB host driver fuzzing, I decided to develop one ;-), building on Sergey’s and Travis’ legendary &lt;a href=&#34;https://www.troopers.de/wp-content/uploads/2012/12/TROOPERS13-You_wouldnt_share_a_syringe_Would_you_share_a_USB_port-Sergey_Bratus+Travis_Goodspeed.pdf&#34;&gt;Troopers13 talk&lt;/a&gt;. Be prepared to learn a lot about USB specifics, and to see quite a number of blue screens and stack traces on major server operating systems…&lt;/p&gt;</description>
    </item>
    <item>
      <title>Troopers 2014 – Second Round of Talks Selected</title>
      <link>https://insinuator.net/2013/12/troopers-2014-second-round-of-talks-selected/</link>
      <pubDate>Wed, 18 Dec 2013 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2013/12/troopers-2014-second-round-of-talks-selected/</guid>
      <description>&lt;p&gt;We’re very happy to announce the second round of Troopers 2014 talks today (first round &lt;a href=&#34;http://www.insinuator.net/2013/11/troopers-2014-first-round-of-talks-selected/&#34;&gt;here&lt;/a&gt;).&lt;br&gt;&#xA;Some (well, actually most 😉 ) of these talks haven’t been presented before, at any other occasion, so this is exciting fresh material which was/is prepared especially for &lt;a href=&#34;https://www.troopers.de&#34;&gt;Troopers&lt;/a&gt;.&lt;/p&gt;&#xA;&lt;p&gt; &lt;/p&gt;&#xA;&lt;p&gt;&lt;strong&gt;Andreas Wiegenstein &amp;amp; Xu Jia: Risks in Hosted SAP Environments.&lt;/strong&gt; &lt;strong&gt;FIRST TIME MATERIAL&lt;/strong&gt;&lt;/p&gt;&#xA;&lt;p&gt;**Synopsis: **Many SAP customers have outsourced the operation of their SAP systems in order to save cost. In doing so, they entrust their most critical data to a hosting provider, potentially sharing the same SAP server with a number of companies and organizations unknown to them. These companies and organizations virtually sit in the same boat, without knowing each other and without trusting each other. They all trust in the ability of their hosting provider to run their operating environment in a secure way, though.&lt;/p&gt;</description>
    </item>
    <item>
      <title>ACSAC 2013</title>
      <link>https://insinuator.net/2013/12/acsac-2013/</link>
      <pubDate>Thu, 12 Dec 2013 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2013/12/acsac-2013/</guid>
      <description>&lt;p&gt;Matthias and I currently have to pleasure to be at &lt;a href=&#34;http://www.acsac.org/&#34;&gt;ACSAC&lt;/a&gt;, in New Orleans.&lt;br&gt;&#xA;From my perspective, at ACSAC the usual conference visit side-effect of personal interaction with peers plays an even larger role than at many other events. In fact we met a number of people we hadn’t seen for quite some time and I could even clear a long unresolved debt (Hi Pastor! and thanks for those &lt;a href=&#34;https://archive.org/details/International_Journal_of_PoC_2013_08_05&#34;&gt;International Journal of PoC&lt;/a&gt; issues).&lt;/p&gt;</description>
    </item>
    <item>
      <title>DeepSec 2013</title>
      <link>https://insinuator.net/2013/12/deepsec-2013/</link>
      <pubDate>Mon, 09 Dec 2013 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2013/12/deepsec-2013/</guid>
      <description>&lt;p&gt;Last week Florian and I participated at this year’s DeepSec in Vienna. We had a really good time, thanks again to the DeepSec staff for a nice conference. Although it might be a bit late, I want to share some impressions about various talks I enjoyed.&lt;/p&gt;&#xA;&lt;p&gt;## spin: Static Instrumentation For Binary Reverse-Engineering&lt;/p&gt;&#xA;&lt;p&gt;This talk primarily covered a technique called &lt;em&gt;binary instrumentation&lt;/em&gt;, which is used e.g. for performance evaluation, CPU emulation, tracing and profiling but also for malware- and threat-analysis. David Guillen Fandos proposed the application of this technique in the field of reverse engineering. Binary instrumentation is a technique which allows to modify and rewrite binaries during their execution by injecting instructions into the original code (pretty much like virtual machines do too). Therefore one could easily wrap instructions with logging/tracing functions, to observe the execution status before and after easy instruction step (and/or dump the output into a file). For the purpose of reversing, one could also create complex conditional breakpoints (retaining status across executions), which makes it possible to characterize functions.&lt;/p&gt;</description>
    </item>
    <item>
      <title>t2’13 Infosec Conference</title>
      <link>https://insinuator.net/2013/11/t213-infosec-conference/</link>
      <pubDate>Sun, 17 Nov 2013 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2013/11/t213-infosec-conference/</guid>
      <description>&lt;p&gt;Hey everybody,&lt;/p&gt;&#xA;&lt;p&gt;I am little bit late to the party, but I had the pleasure to present a talk about VoIP based toll fraud incidents (more on this in a following blogpost, for the moment my slides can be found &lt;a href=&#34;https://www.ernw.de/download/T2_VoIP_TollFraud_cwerny_v1.0.pdf&#34;&gt;here&lt;/a&gt;) at the annual &lt;a href=&#34;http://t2.fi/&#34;&gt;t2 security conference&lt;/a&gt; in Helsinki. The conference took place from 24th to 25th October in the Radisson Blu Royal hotel. I must say that it was a blast. Tomi (the host) took really good care of all speakers, and I really liked the spirit of the conference, very similar to &lt;a href=&#34;https://www.troopers.de&#34;&gt;Troopers&lt;/a&gt;. It is not an commercial event, seats are limited to 100 and it is all about delivering a &lt;a href=&#34;http://t2.fi/schedule/2013/&#34;&gt;great set of talks&lt;/a&gt; to the audience and having a good time during and after the conference. Sure the conference has some sponsors and tickets are sold, but Tomi doesn’t do it to earn money. His only intention is to cover the cost for setting up this great event.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Troopers 2014 – First Round of Talks Selected</title>
      <link>https://insinuator.net/2013/11/troopers-2014-first-round-of-talks-selected/</link>
      <pubDate>Sat, 16 Nov 2013 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2013/11/troopers-2014-first-round-of-talks-selected/</guid>
      <description>&lt;p&gt;We’re delighted to provide the first announcement of talks of next year’s &lt;a href=&#34;http://www.troopers.de&#34;&gt;Troopers&lt;/a&gt; edition. Looks like it’s going to be a great event again 😉&lt;br&gt;&#xA;Here we go:&lt;/p&gt;&#xA;&lt;p&gt;==================&lt;/p&gt;&#xA;&lt;p&gt;Toby Kohlenberg: Granular Trust – Making it Work&lt;/p&gt;&#xA;&lt;p&gt;Over the last 5 years the concept of using dynamic or granular trust models to control access to systems, networks and applications has become well known and is now seeing partial adoption in many places. The challenge is how granular and dynamic can you get and the question is whether it is worth it. As the architect of Intel’s trust model Toby can speak to the entire journey from initial idea through current implementation and the likely road ahead. This talk will include the good, bad and ugly parts of designing a trust model and then implementing it in a Fortune 50 company’s production environment. You will learn from his mistakes so you can make different ones.&lt;/p&gt;</description>
    </item>
    <item>
      <title>ISSE 2013 – ERNW Rapid Rating System</title>
      <link>https://insinuator.net/2013/10/isse-2013-ernw-rapid-rating-system/</link>
      <pubDate>Mon, 28 Oct 2013 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2013/10/isse-2013-ernw-rapid-rating-system/</guid>
      <description>&lt;p&gt;Michael Thumann and me had the chance to give a talk at this year’s &lt;a href=&#34;http://www.isse.eu.com/&#34; title=&#34;ISSE&#34;&gt;ISSE&lt;/a&gt; conference in Brussels, Belgium. ISSE was founded in 1999 as an initiative of the European Commission Directorate General Information Society. The con had a focus on eGovernment, electronic business processes and the corresponding security issues.&lt;/p&gt;&#xA;&lt;p&gt;We talked about the ERRS, the &lt;a href=&#34;https://www.troopers.de/archives/troopers13/agenda13/troopers13-presentations/&#34; title=&#34;here&#34;&gt;ERNW Rapid Rating System&lt;/a&gt;, that can be used to perform a vulnerability rating for findings that result from different kinds of sources. Audits and Pentests will find a vast amount of vulnerabilities in the infrastructure. To deal with these vulnerabilities, you have to use some kind of prioritization in order to use resources effectively. We tried to adopt the strengths from metrics like CVSS and developed our own set of parameters to calculate the metric, focussing on the relevant customer questions concerning vulnerabilities from all kinds of sources.&lt;/p&gt;</description>
    </item>
    <item>
      <title>DayCon VII</title>
      <link>https://insinuator.net/2013/09/daycon-vii/</link>
      <pubDate>Thu, 26 Sep 2013 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2013/09/daycon-vii/</guid>
      <description>&lt;p&gt;Some of us had the pleasure to participate in this year’s &lt;a href=&#34;http://www.day-con.org&#34;&gt;Daycon VII&lt;/a&gt;, three days of Real Hacking and Relevant Content, in Dayton, OH. The event began on September 16th with the Packetwars bootcamp. We had the chance to teach some really promising young students and to prepare them for the Packetwars battle that was scheduled four days later. The students had to go through topics like Windows security, network security and web application security both practical and in theory.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Security Team 2.0</title>
      <link>https://insinuator.net/2013/08/security-team-2.0/</link>
      <pubDate>Sat, 24 Aug 2013 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2013/08/security-team-2.0/</guid>
      <description>&lt;p&gt;I’m currently catching up on a lot of papers and presentation from the &lt;a href=&#34;https://www.usenix.org/conference/usenixsecurity13&#34;&gt;Usenix Security Symposium&lt;/a&gt; in order to finish the blog post series I started last week (summarizing &lt;a href=&#34;http://www.insinuator.net/2013/08/woot13/&#34;&gt;WOOT&lt;/a&gt; and &lt;a href=&#34;http://www.insinuator.net/2013/08/leet13/&#34;&gt;LEET&lt;/a&gt;). One presentation, which unfortunately is  not available online [edit: see also update, &lt;a href=&#34;https://www.usenix.org/conference/usenixsecurity13/security-team-20&#34;&gt;videos&lt;/a&gt; are available now], included several particularly relevant messages that I want to share in this dedicated post. Chris Evans, the head of the Google Chrome security team (herein short: GCST), described some new approaches they employed for their security team operations, some lessons learned, and how others can benefit from it as well (actually the potential of these messages to make the world a safer place was my motivation to write this post, even though I got teased for supposedly being a Google fanboy 😉 ):&lt;/p&gt;</description>
    </item>
    <item>
      <title>WOOT’13</title>
      <link>https://insinuator.net/2013/08/woot13/</link>
      <pubDate>Wed, 14 Aug 2013 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2013/08/woot13/</guid>
      <description>&lt;p&gt;Continuing &lt;a href=&#34;http://www.insinuator.net/2013/08/leet13/&#34;&gt;yesterday’s post&lt;/a&gt;, I compiled a short summary of relevant &lt;a href=&#34;https://www.usenix.org/conference/woot13/tech-schedule/workshop-program&#34;&gt;WOOT’13&lt;/a&gt; presentations.&lt;/p&gt;&#xA;&lt;hr&gt;&#xA;&lt;p&gt;&lt;em&gt;Truncating TLS Connections to Violate Beliefs in Web Applications&lt;/em&gt;&lt;br&gt;&#xA;&lt;em&gt;Ben Smyth and Alfredo Pironti, INRIA Paris-Rocquencourt&lt;/em&gt;&lt;/p&gt;&#xA;&lt;p&gt;This presentation was also given at &lt;a href=&#34;https://media.blackhat.com/us-13/US-13-Smyth-Truncating-TLS-Connections-to-Violate-Beliefs-in-Web-Applications-Slides.pdf&#34;&gt;BlackHat&lt;/a&gt; some weeks ago. It outlines a very interesting class of attacks against web applications abusing the TLS specification which states that “failure to properly close a connection no longer requires that a session not be resumed […] to conform with widespread implementation practice”. This characteristic enables new attack vectors on shared systems where certain outgoing (TLS encrypted) packets can be dropped in order to prevent applications from e.g. correctly finishing transaction (such as log out procedures) or even modifying the request bodies by dropping the last parts.&lt;/p&gt;</description>
    </item>
    <item>
      <title>LEET’13</title>
      <link>https://insinuator.net/2013/08/leet13/</link>
      <pubDate>Tue, 13 Aug 2013 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2013/08/leet13/</guid>
      <description>&lt;p&gt;I have the pleasure to visit this year’s &lt;a href=&#34;https://www.usenix.org/conference/usenixsecurity13&#34;&gt;USENIX Security Symposium&lt;/a&gt; in Washington, DC. Besides the nice venue close to the &lt;a href=&#34;http://en.wikipedia.org/wiki/National_mall&#34;&gt;national mall&lt;/a&gt;, there are also several co-located workshops. Every night I will try and provide a summary of those presentations I regard as most interesting. However, I hope to manage to keep up with it as there are a lot of interesting events, people to meet, and still some projects to keep up with. The short summaries below are from the &lt;em&gt;6th USENIX Workshop on Large-Scale Exploits and Emergent Threats&lt;/em&gt;.&lt;/p&gt;</description>
    </item>
    <item>
      <title>IPv6 Hackers Meeting @ IETF 87 in Berlin / Slides</title>
      <link>https://insinuator.net/2013/08/ipv6-hackers-meeting-@-ietf-87-in-berlin-/-slides/</link>
      <pubDate>Thu, 01 Aug 2013 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2013/08/ipv6-hackers-meeting-@-ietf-87-in-berlin-/-slides/</guid>
      <description>&lt;p&gt;&lt;a href=&#34;http://www.ipv6hackers.org/meetings/berlin-2013&#34;&gt;That meeting&lt;/a&gt; was actually a great event. Once more, big thanks! to Fernando for organizing it and to &lt;a href=&#34;http://www.eantc.com/&#34;&gt;EANTC&lt;/a&gt; for providing the logistics.&lt;br&gt;&#xA;A couple of unordered notes to follow:&lt;/p&gt;&#xA;&lt;p&gt;a) The slides of our contribution can be found &lt;a href=&#34;http://www.ernw.de/download/ERNW_IETF87_IPv6Hackers_Capabilities_v0_9.pdf&#34;&gt;here&lt;/a&gt;. Again, pls note that this is work in progress and we’re happy to receive any kind of feedback.&lt;br&gt;&#xA;[given Fernando explicitly mentioned Troopers, we’ve allowed ourselves to put some reference to it into this version of the slide deck…]&lt;/p&gt;</description>
    </item>
    <item>
      <title>IPv6 Hackers Meeting @ IETF 87, Berlin</title>
      <link>https://insinuator.net/2013/07/ipv6-hackers-meeting-@-ietf-87-berlin/</link>
      <pubDate>Fri, 26 Jul 2013 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2013/07/ipv6-hackers-meeting-@-ietf-87-berlin/</guid>
      <description>&lt;p&gt;Next to &lt;a href=&#34;https://www.ietf.org/meeting/87/index.html&#34;&gt;IETF 87&lt;/a&gt; going on in Berlin in a few days there will be an &lt;a href=&#34;http://www.ipv6hackers.org/meetings/berlin-2013&#34;&gt;informal meeting of the “IPv6 Hackers”&lt;/a&gt; on Tuesday. We really look forward to personally meet a number of people who we (so far) only know from the associated &lt;a href=&#34;http://www.si6networks.com/community/mailing-lists.html&#34;&gt;mailing list&lt;/a&gt; or similar machine-enhanced exchange. We hope to contribute as well. Based on the stuff of &lt;a href=&#34;https://www.troopers.de/archives/troopers13/agenda13/troopers13-ipv6-security-summit-2013/troopers13-ipv6-security-summit-2013-workshop-overview-of-the-real-world-capabilities-of-major-commercial-security-products/index.html&#34;&gt;this workshop&lt;/a&gt; from the &lt;a href=&#34;https://www.troopers.de/archives/troopers13/agenda13/troopers13-ipv6-security-summit-2013/index.html&#34;&gt;IPv6 Security Summit&lt;/a&gt; at &lt;a href=&#34;http://www.troopers.de&#34;&gt;Troopers13&lt;/a&gt; we might give a short project presentation along the lines of “Some Notes on Testing the Real-World IPv6 Capabilities of Commercial Security Products”, providing an overview of some testing done on commercial gear, together with a discussion of testing approaches, tools and key aspects.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Pre-Weekend Goody: TROOPERS13 Video</title>
      <link>https://insinuator.net/2013/07/pre-weekend-goody-troopers13-video/</link>
      <pubDate>Thu, 11 Jul 2013 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2013/07/pre-weekend-goody-troopers13-video/</guid>
      <description>&lt;p&gt;Enjoy! After seeing this I personally feel like signing up for the &lt;a href=&#34;https://www.troopers.de/index.html&#34;&gt;TROOPERS14 Enthusiast Package&lt;/a&gt; 😉&lt;/p&gt;&#xA;&lt;p&gt;Carry on&lt;br&gt;&#xA;Florian &amp;amp; Team&lt;/p&gt;</description>
    </item>
    <item>
      <title>TROOPERS14 Registration Open &#43; TROOPERS13 Photos Online</title>
      <link>https://insinuator.net/2013/06/troopers14-registration-open--troopers13-photos-online/</link>
      <pubDate>Sun, 30 Jun 2013 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2013/06/troopers14-registration-open--troopers13-photos-online/</guid>
      <description>&lt;p&gt;**Dear blog followers, TROOPERS speakers &amp;amp; attendees,&lt;br&gt;&#xA;**we hope you’re doing fine! Today we have a couple of great things to share with you:&lt;/p&gt;&#xA;&lt;p&gt;&lt;strong&gt;TROOPERS14&lt;/strong&gt;&lt;br&gt;&#xA;Let’s start with a date. Get your calendar and mark &lt;strong&gt;March 17th – 21st 2014&lt;/strong&gt;. It’s your TROOPERS14 holidays. One week full of high-end education, workshops, talks, reconnecting with friends, action, delicious food and one or the other party. You know the drill – more details further down.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Impressions from the Google I/O Con</title>
      <link>https://insinuator.net/2013/06/impressions-from-the-google-i/o-con/</link>
      <pubDate>Tue, 04 Jun 2013 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2013/06/impressions-from-the-google-i/o-con/</guid>
      <description>&lt;p&gt;&lt;a href=&#34;http://www.insinuator.net/wp-content/uploads/2013/05/moscone.jpg&#34;&gt;&lt;img src=&#34;http://www.insinuator.net/wp-content/uploads/2013/05/moscone.jpg&#34; alt=&#34;moscone&#34;&gt;&lt;/a&gt;&lt;br&gt;&#xA;From 15th – 17th of May, the sixth Google I/O conference took place in San Francisco, California and I was one of the lucky guys attending. More then 5500 people, primarily web, mobile, and enterprise developers, attended this annual event. A lot of presentations included announcements of new and exciting technologies, APIs as well as of two new devices.&lt;/p&gt;&#xA;&lt;p&gt;During the first minutes of the &lt;a href=&#34;https://developers.google.com/events/io/&#34; title=&#34;Google I/O 2013 Keynote&#34;&gt;keynote&lt;/a&gt; some of Google’s managers announced that by now over 900 million Android devices are activated and that 48 billion apps are installed, which demonstrates that this market is still heavily growing. As the major part of the audience were (app-) developers, these numbers were received quite greatfully and euphoric.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Troopers13 Videos Online</title>
      <link>https://insinuator.net/2013/06/troopers13-videos-online/</link>
      <pubDate>Sat, 01 Jun 2013 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2013/06/troopers13-videos-online/</guid>
      <description>&lt;p&gt;Hi,&lt;/p&gt;&#xA;&lt;p&gt;as we’ve received quite some requests re: the videos from &lt;a href=&#34;http://www.troopers.de&#34;&gt;Troopers&lt;/a&gt; 2013: the YouTube playlist can be found &lt;a href=&#34;https://www.youtube.com/playlist?list=PL1eoQr97VfJl1LdMzyQPz71uR6bwiUGog&#34;&gt;here&lt;/a&gt;.&lt;/p&gt;&#xA;&lt;p&gt;Have fun (and learn something ;-)) watching, cu next year&lt;/p&gt;&#xA;&lt;p&gt;Enno&lt;/p&gt;</description>
    </item>
    <item>
      <title>Presentations from TR13 TelcoSecDay Online</title>
      <link>https://insinuator.net/2013/04/presentations-from-tr13-telcosecday-online/</link>
      <pubDate>Sun, 28 Apr 2013 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2013/04/presentations-from-tr13-telcosecday-online/</guid>
      <description>&lt;p&gt;Hi,&lt;/p&gt;&#xA;&lt;p&gt;just to let you know that all presentations from this year’s &lt;a href=&#34;https://www.troopers.de/archives/troopers13/agenda13/troopers13-telcosec-day-2013/index.html&#34;&gt;TelcoSecDay&lt;/a&gt; are published in the interim. (Harald [Welte] couldn’t participate as in the morning of that day FRA airport was closed on short notice).&lt;/p&gt;&#xA;&lt;p&gt;Next year’s TSD will happen on 03/18/2014.&lt;/p&gt;&#xA;&lt;p&gt;Take care,&lt;/p&gt;&#xA;&lt;p&gt;Enno&lt;/p&gt;&#xA;&lt;p&gt; &lt;/p&gt;</description>
    </item>
    <item>
      <title>Summary of Talks Held at HITB 2013 – Day 1</title>
      <link>https://insinuator.net/2013/04/summary-of-talks-held-at-hitb-2013-day-1/</link>
      <pubDate>Wed, 17 Apr 2013 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2013/04/summary-of-talks-held-at-hitb-2013-day-1/</guid>
      <description>&lt;p&gt;This is a short summary of some selected talks from the first day of this year’s &lt;a href=&#34;http://conference.hackinthebox.org/hitbsecconf2013ams/&#34; title=&#34;Hack In The Box&#34;&gt;Hack in the Box&lt;/a&gt; conference in Amsterdam.&lt;/p&gt;&#xA;&lt;p&gt; &lt;br&gt;&#xA;&lt;strong&gt;Abusing Twitter’s API and OAuth Implementation by Nicolas Seriot&lt;/strong&gt;&lt;/p&gt;&#xA;&lt;p&gt;Nicolas Seriot (&lt;a href=&#34;https://twitter.com/nst021&#34;&gt;https://twitter.com/nst021&lt;/a&gt;) is an iOS Cocoa developer with an interest in privacy and security. He is currently a mobile applications developer and project manager in Switzerland. Nicolas focused his talk on the extraction of consumer tokens that are needed for OAuth to authenticate a consumer to a service provider. These tokens can then be used by rogue applications to gain access to a victims twitter account.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Summary of Talks Held at HITB 2013 – Day 2</title>
      <link>https://insinuator.net/2013/04/summary-of-talks-held-at-hitb-2013-day-2/</link>
      <pubDate>Wed, 17 Apr 2013 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2013/04/summary-of-talks-held-at-hitb-2013-day-2/</guid>
      <description>&lt;p&gt;This is a short summary of some selected talks from the second day of this year’s Hack in the Box conference in Amsterdam.&lt;/p&gt;&#xA;&lt;p&gt; &lt;br&gt;&#xA;&lt;strong&gt;Rethinking the Front Lines by Bob Lord&lt;/strong&gt;&lt;/p&gt;&#xA;&lt;p&gt;Bob Lord is currently the Director of Information Security at Twitter. He has worked at numerous companies in the area of security and software engineering.&lt;/p&gt;&#xA;&lt;p&gt;In his keynote for the second day of HITB13AMS he tackled a topic that has raised a lot of discussions in the past months. His talk was a summary of what twitter does internally to ensure the security of the company and a plea to implement so called security awareness trainings for employees in a sustainable way.&lt;/p&gt;</description>
    </item>
    <item>
      <title>TROOPERS13 – The Badge Code</title>
      <link>https://insinuator.net/2013/03/troopers13-the-badge-code/</link>
      <pubDate>Fri, 15 Mar 2013 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2013/03/troopers13-the-badge-code/</guid>
      <description>&lt;p&gt;As a lot of people were asking for, here comes the code of your badge. All You need to customize your badge, is a micro controller programmer, like the &lt;a href=&#34;http://www.microchip.com/pickit3&#34;&gt;Pickit&lt;/a&gt; (its around 30 to 40 euros) and the build environment, &lt;a href=&#34;http://www.microchip.com/mplabx/&#34;&gt;MPLAB&lt;/a&gt; which you can get for free. Then just &lt;a href=&#34;https://www.ernw.de/download/tr13_badge.tar.bz2&#34;&gt;download the code&lt;/a&gt; and implement your own super cool features. Let us know what you did, the best hacks will get into the TROOPERS hall of fame (-;&lt;/p&gt;</description>
    </item>
    <item>
      <title>Troopers13 IPv6 Security Summit – First Presentations Available</title>
      <link>https://insinuator.net/2013/03/troopers13-ipv6-security-summit-first-presentations-available/</link>
      <pubDate>Mon, 11 Mar 2013 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2013/03/troopers13-ipv6-security-summit-first-presentations-available/</guid>
      <description>&lt;p&gt;We had a great day today at the &lt;a href=&#34;https://www.troopers.de/agenda13/troopers13-ipv6-security-summit-2013/index.html&#34;&gt;Troopers IPv6 Security Summit&lt;/a&gt;. Good conversations, quite some technical discussion and a prevailing overall will to improve actual IPv6 network security.&lt;/p&gt;&#xA;&lt;p&gt;&lt;a href=&#34;https://www.ernw.de/download/IPv6%20Extension%20Headers%20-%20New%20Features,%20and%20New%20Attack%20Vectors.pdf&#34;&gt;Here&lt;/a&gt; are the slides of Antonios Atlasis’ great talk on extension headers and &lt;a href=&#34;https://www.ernw.de/download/IPv6%20Extension%20Headers%20-%20New%20Features,%20and%20New%20Attack%20Vectors.py&#34;&gt;these&lt;/a&gt; are some of his accompanying Python/Scapy scripts. My own presentation on high secure IPv6 networks can be found &lt;a href=&#34;https://www.ernw.de/download/ERNW_TR13_High_Secure_Networks_v1_0web.pdf&#34;&gt;here&lt;/a&gt;. The slides of the &lt;a href=&#34;https://www.troopers.de/agenda13/troopers13-ipv6-security-summit-2013/troopers13-ipv6-security-summit-2013-workshop-overview-of-the-real-world-capabilities-of-major-commercial-security-products/index.html&#34;&gt;real-world capabilities workshop&lt;/a&gt; will not be published yet as we first have to discuss some stuff with a vendor.&lt;/p&gt;</description>
    </item>
    <item>
      <title>IPv6 Neighbor Cache Exhaustion Attacks – Risk Assessment &amp; Mitigation Strategies, Part 1</title>
      <link>https://insinuator.net/2013/03/ipv6-neighbor-cache-exhaustion-attacks-risk-assessment-mitigation-strategies-part-1/</link>
      <pubDate>Tue, 05 Mar 2013 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2013/03/ipv6-neighbor-cache-exhaustion-attacks-risk-assessment-mitigation-strategies-part-1/</guid>
      <description>&lt;p&gt;Recently there has been quite some discussion about so-called neighbor cache exhaustion (“NCE”) attacks in the IPv6 world. &lt;a href=&#34;http://inconcepts.biz/~jsw/IPv6_NDP_Exhaustion.pdf&#34;&gt;This&lt;/a&gt; is Jeff Wheeler’s “classic paper” on the subject, my kind-of personal networking guru &lt;a href=&#34;https://www.troopers.de/agenda13/troopers13-presentations/index.html#virtual_firewalls&#34;&gt;Ivan Pepelnjak&lt;/a&gt; &lt;a href=&#34;http://blog.ioshints.info/2011/05/ipv6-neighbor-discovery-exhaustion.html&#34;&gt;blogged&lt;/a&gt; about it back some time, &lt;a href=&#34;https://groups.google.com/forum/?fromgroups=#!topic/ipv6hackers/cFCcsjnhImw&#34;&gt;here&lt;/a&gt;‘s a related discussion on the IPv6 hackers mailing list and in March 2012 (only three months after the respective IETF draft’s version 0 was released) the &lt;a href=&#34;%20https://tools.ietf.org/html/rfc6583&#34;&gt;RFC 6583&lt;/a&gt; was published, covering various protection strategies.&lt;/p&gt;</description>
    </item>
    <item>
      <title>IPv6 Security Problems Related to Extension Headers &amp; Fragmentation</title>
      <link>https://insinuator.net/2013/03/ipv6-security-problems-related-to-extension-headers-fragmentation/</link>
      <pubDate>Mon, 04 Mar 2013 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2013/03/ipv6-security-problems-related-to-extension-headers-fragmentation/</guid>
      <description>&lt;p&gt;&lt;a href=&#34;http://www.mh-sec.de/&#34;&gt;Marc Heuse&lt;/a&gt; – who happens to give &lt;a href=&#34;https://www.troopers.de/agenda13/troopers13-ipv6-security-summit-2013/troopers13-ipv6-security-summit-2013-workshop-penetration-testing-in-ipv6-networks/index.html&#34;&gt;this workshop&lt;/a&gt; at the &lt;a href=&#34;https://www.troopers.de/agenda13/troopers13-ipv6-security-summit-2013/index.html&#34;&gt;Troopers IPv6 Security Summit&lt;/a&gt; next week – just sent &lt;a href=&#34;http://lists.si6networks.com/pipermail/ipv6hackers/2013-March/000972.html&#34;&gt;this email&lt;/a&gt; (subject: “Remote system freeze thanks to Kaspersky Internet Security 2013”) to the &lt;a href=&#34;http://lists.si6networks.com/listinfo/ipv6hackers/&#34;&gt;IPv6 hackers mailing list&lt;/a&gt;, describing how a system running a certain flavor of Kaspersky security products can be remotely frozen when receiving IPv6 packets with a specific combination of extension headers and fragmentation (which in turn can be easily generated by his &lt;a href=&#34;www.thc.org/thc-ipv6&#34;&gt;IPv6 protocol attack suite&lt;/a&gt;).&lt;/p&gt;</description>
    </item>
    <item>
      <title>BASTA! Spring 2013</title>
      <link>https://insinuator.net/2013/02/basta-spring-2013/</link>
      <pubDate>Thu, 28 Feb 2013 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2013/02/basta-spring-2013/</guid>
      <description>&lt;p&gt;Yesterday I was giving two presentations about Cloud security at the &lt;a href=&#34;http://basta.net/&#34;&gt;BASTA!&lt;/a&gt; Spring 2013 Security Day. While my presentations covered Microsoft Azure security considerations (which also included a part of the Cloud security approach covered in our &lt;a href=&#34;https://www.troopers.de/agenda13/troopers13-1-day-workshop-auditing-the-cloud/index.html&#34;&gt;workshops&lt;/a&gt;; slides available &lt;a href=&#34;https://www.ernw.de/download/ERNW_BastaSpring13_AzureSec.pdf&#34;&gt;here&lt;/a&gt;) and some major Cloud incidents (suitable to transport different messages about Cloud security in general ;); slides available &lt;a href=&#34;https://www.ernw.de/download/ERNW_BastaSpring13_CloudFails.pdf&#34;&gt;here&lt;/a&gt;), I also saw &lt;a href=&#34;http://leastprivilege.com/&#34;&gt;Dominick’s&lt;/a&gt; very interesting &lt;a href=&#34;https://speakerdeck.com/leastprivilege/windows-8-security-for-developers&#34;&gt;presentation&lt;/a&gt; about security aspects and changes in Windows 8. Inspired by that, we hope to be able to publish another blogpost on those aspects with regard to enterprise environments soon — most likely we won’t find any time for it before &lt;a href=&#34;http://www.troopers.de&#34;&gt;TROOPERS&lt;/a&gt; 😉&lt;/p&gt;</description>
    </item>
    <item>
      <title>Latest SAP threats, SAP Forensics &amp;amp; BIZEC @Troopers!</title>
      <link>https://insinuator.net/2013/02/latest-sap-threats-sap-forensics-amp-bizec-@troopers/</link>
      <pubDate>Wed, 27 Feb 2013 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2013/02/latest-sap-threats-sap-forensics-amp-bizec-@troopers/</guid>
      <description>&lt;h3 id=&#34;this-is-a-guest-post-from-mariano-nunez-and-juan-perez-etchegoyen&#34;&gt;This is a guest post from &lt;a href=&#34;https://www.troopers.de/agenda13/troopers13-1-day-workshop-sap-security-protecting-your-sap-systems-against-hackers-and-industrial-espionage/index.html&#34;&gt;Mariano Nunez and Juan Perez-Etchegoyen&lt;/a&gt;&lt;/h3&gt;&#xA;&lt;p&gt;Juan Perez-Etchegoyen (&lt;a href=&#34;https://twitter.com/intent/user?screen_name=jp_pereze&#34;&gt;@jp_pereze&lt;/a&gt;) and Mariano Nunez (&lt;a href=&#34;https://twitter.com/intent/user?screen_name=marianonunezdc&#34;&gt;@marianonunezdc&lt;/a&gt;) from &lt;a href=&#34;http://www.onapsis.com/&#34;&gt;Onapsis&lt;/a&gt; here, thrilled to be &lt;a href=&#34;https://www.troopers.de&#34;&gt;troopers&lt;/a&gt; for the third time! In this post we want to share with you a glimpse of what you will see regarding SAP security at this amazing conference.&lt;/p&gt;&#xA;&lt;p&gt;Last week we released advisories regarding several vulnerabilities affecting SAP platforms. Some of these vulnerabilities are in fact very critical, and their exploitation could lead to a &lt;strong&gt;full-compromise&lt;/strong&gt; of the entire SAP implementation – even &lt;strong&gt;by completely anonymous attackers&lt;/strong&gt;. Following our responsible disclosure policy, SAP released the relevant SAP Security Notes (patches) for all these vulnerabilities a long time ago, so if you are an SAP customer make sure you have properly implemented them!&lt;/p&gt;</description>
    </item>
    <item>
      <title>APT</title>
      <link>https://insinuator.net/2013/02/apt/</link>
      <pubDate>Thu, 21 Feb 2013 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2013/02/apt/</guid>
      <description>&lt;p&gt;Many of you have probably seen the public media coverage (e.g. [&lt;a href=&#34;http://www.nytimes.com/2013/02/19/technology/chinas-army-is-seen-as-tied-to-hacking-against-us.html?hp&amp;amp;_r=0&#34;&gt;1&lt;/a&gt;], [&lt;a href=&#34;http://www.spiegel.de/politik/ausland/chinas-armee-soll-beruechtigte-hacker-truppe-betreiben-a-884164.html&#34;&gt;2&lt;/a&gt;]) of  Mandiant’s &lt;a href=&#34;http://intelreport.mandiant.com/Mandiant_APT1_Report.pdf&#34;&gt;latest report&lt;/a&gt; on APT.&lt;/p&gt;&#xA;&lt;p&gt;Just to let you know: &lt;a href=&#34;https://www.troopers.de/agenda13/index.html&#34;&gt;Trooper&lt;/a&gt;‘s traditional panel discussion on the first day will be on APT this year. So if you want to discuss the topic with other practitioners from the field, join us there.&lt;/p&gt;&#xA;&lt;p&gt;have a great day&lt;/p&gt;&#xA;&lt;p&gt;Enno&lt;/p&gt;</description>
    </item>
    <item>
      <title>Bluevoxing</title>
      <link>https://insinuator.net/2013/02/bluevoxing/</link>
      <pubDate>Thu, 21 Feb 2013 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2013/02/bluevoxing/</guid>
      <description>&lt;h3 id=&#34;this-is-a-guest-post-from-graeme-neilson&#34;&gt;This is a guest post from &lt;a href=&#34;https://www.troopers.de/agenda13/troopers13-2-day-workshop-reverse-engineering/index.html&#34;&gt;Graeme Neilson&lt;/a&gt;&lt;/h3&gt;&#xA;&lt;p&gt;Reverse engineering is generally thought of as using debuggers, disassemblers and hex editors. Much as I love hex editors, IDA and staring at opcodes for the last few years I have been focused on applying my reverse engineering methodology to larger, composed systems. At &lt;a href=&#34;https://www.troopers.de/agenda13/troopers13-telcosec-day-2013/index.html&#34;&gt;Troopers TelcoSec day&lt;/a&gt; this year I will be presenting &lt;a href=&#34;https://www.troopers.de/agenda13/troopers13-telcosec-day-2013/index.html#BlueVoxing&#34;&gt;Bluevoxing&lt;/a&gt; which demonstrates how this approach works. &lt;a href=&#34;https://www.troopers.de/agenda13/troopers13-telcosec-day-2013/index.html#BlueVoxing&#34;&gt;Bluevoxing&lt;/a&gt; is about reverse engineering how web based “audio one time password” systems work. Simply put audio one time password systems use a short audio file as an authentication token. When I discovered these systems I was intrigued as reversing them would involve a range of techniques and tools from web testing, audio tools, signal analysis, phreaking and cryptanalysis. The disassembler would be of no use instead I would have to employ audio tools such as audacity and ruby-processing.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Paparazzi over IP – Slides</title>
      <link>https://insinuator.net/2013/02/paparazzi-over-ip-slides/</link>
      <pubDate>Mon, 18 Feb 2013 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2013/02/paparazzi-over-ip-slides/</guid>
      <description>&lt;p&gt;We are back from ShmooCon had a great time and it was a lot of fun talking to all of you guys. Here are the &lt;a href=&#34;https://www.ernw.de/download/publikationen/PaparazzioverIP_shmoo2013.pdf&#34;&gt;slides&lt;/a&gt; of our talk. Thanks to all who made this possible, we really enjoyed being part of this years Shmoo.&lt;/p&gt;&#xA;&lt;p&gt;cheers&lt;/p&gt;&#xA;&lt;p&gt;/daniel and pascal&lt;/p&gt;</description>
    </item>
    <item>
      <title>Paparazzi over IP</title>
      <link>https://insinuator.net/2013/02/paparazzi-over-ip/</link>
      <pubDate>Fri, 15 Feb 2013 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2013/02/paparazzi-over-ip/</guid>
      <description>&lt;p&gt;Almost every higher class DSLR on the market today features multiple and complex access technologies. To name a few, canons new flagship features IP connectivity wired via 802.3 as well as wireless via 802.11. All the big vendors are pushing these features to the market and advertise them with real time image transfer to the cloud. We have taken a look at the layer 2 and 3 implementations in the CamOS and the services running upon those, so here is what we found while examine the EOS 1D X:&lt;/p&gt;</description>
    </item>
    <item>
      <title>TROOPERS13: TelcoSecDay, IPv6 Security Summit and some more Updates</title>
      <link>https://insinuator.net/2013/02/troopers13-telcosecday-ipv6-security-summit-and-some-more-updates/</link>
      <pubDate>Sat, 02 Feb 2013 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2013/02/troopers13-telcosecday-ipv6-security-summit-and-some-more-updates/</guid>
      <description>&lt;p&gt;Here’s a number of updates as for upcoming &lt;a href=&#34;https://www.troopers.de/&#34;&gt;TROOPERS13&lt;/a&gt;.&lt;/p&gt;&#xA;&lt;p&gt;The preliminary agenda for this year’s TelcoSecDay can be found &lt;a href=&#34;https://www.troopers.de/agenda13/troopers13-telcosec-day-2013/index.html&#34;&gt;here&lt;/a&gt;.&lt;/p&gt;&#xA;&lt;p&gt;&lt;a href=&#34;https://www.troopers.de/agenda13/troopers13-ipv6-security-summit-2013/index.html&#34;&gt;Here&lt;/a&gt;‘s the (again: preliminary) agenda of the IPv6 Security Summit.&lt;/p&gt;&#xA;&lt;p&gt;Last, but not least we’ve included another four talks in the main conference:&lt;/p&gt;&#xA;&lt;p&gt;======&lt;/p&gt;&#xA;&lt;p&gt;Sergey Bratus &amp;amp; Travis Goodspeed: You wouldn’t share a syringe. Would you share a USB port?&lt;/p&gt;&#xA;&lt;p&gt;Synopsis: Previous work has shown that a USB port left unattended may be subject to pwnage via insertion of a device that types into your command shell (e.g. &lt;a href=&#34;http://www.social-engineer.org/framework/Computer_Based_Social_Engineering_Tools:_Social_Engineer_Toolkit_(SET)#Teensy_USB_HID_Attack_Vector&#34;&gt;here&lt;/a&gt;). Impressive attack payloads have been delivered over USB to &lt;a href=&#34;http://arstechnica.com/gaming/2010/08/the-ps3-jailbroken-usb-hack-allows-homebrew-copied-games/&#34;&gt;jailbreak PS3&lt;/a&gt; and a “&lt;a href=&#34;https://www.usenix.org/sites/default/files/conference/protected-files/michele_woot12_slides.pdf&#34;&gt;smart TV&lt;/a&gt;“. Not surprisingly, USB stacks started incorporating defenses such as device registration, USB firewalls, and other protective kits. But do these protective measures go far enough to let you safely plug in a strange thumb drive into your laptop’s USB port?&lt;/p&gt;</description>
    </item>
    <item>
      <title>Troopers 2013 – Third Round of Talks Selected</title>
      <link>https://insinuator.net/2013/01/troopers-2013-third-round-of-talks-selected/</link>
      <pubDate>Thu, 17 Jan 2013 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2013/01/troopers-2013-third-round-of-talks-selected/</guid>
      <description>&lt;p&gt;We’re very happy to announce the third round of Troopers 2013 talks today (first round &lt;a href=&#34;http://www.insinuator.net/2012/12/troopers-2013-first-round-of-talks-selected/&#34;&gt;here&lt;/a&gt;, second &lt;a href=&#34;http://www.insinuator.net/2013/01/troopers-2013-second-round-of-talks-selected/&#34;&gt;here&lt;/a&gt;).&lt;/p&gt;&#xA;&lt;p&gt;So much quality stuff… it seems to get (ever) better every year ;-).&lt;/p&gt;&#xA;&lt;p&gt;Here we go:&lt;/p&gt;&#xA;&lt;p&gt;==================&lt;/p&gt;&#xA;&lt;p&gt;&lt;strong&gt;Michael Ossmann &amp;amp; Dominic Spill: Introducing Daisho – monitoring multiple communication technologies at the physical layer.&lt;/strong&gt;&lt;/p&gt;&#xA;&lt;p&gt;&lt;strong&gt;Synopsis:&lt;/strong&gt; Most communications media can be monitored and debugged at various levels of the stack, but we believe that it is most important to examine them at the physical layer. From there, the security of every level can be investigated and tested. The task of monitoring physical layer communications has become increasingly difficult as we try to squeeze more and more bandwidth out of our links. A passive tapping circuit can be used to monitor a 100BASE-TX connections, but no such circuit exists for 1000BASE-T networks.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Troopers 2013 – Second Round of Talks Selected</title>
      <link>https://insinuator.net/2013/01/troopers-2013-second-round-of-talks-selected/</link>
      <pubDate>Thu, 10 Jan 2013 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2013/01/troopers-2013-second-round-of-talks-selected/</guid>
      <description>&lt;p&gt;We’re very happy to announce the second round of Troopers 2013 talks today (first round &lt;a href=&#34;http://www.insinuator.net/2012/12/troopers-2013-first-round-of-talks-selected/&#34;&gt;here&lt;/a&gt;).&lt;br&gt;&#xA;Some (well, actually most ;-)) of these talks haven’t been presented before, at any other occasion, so this is exciting fresh material which was/is prepared especially for &lt;a href=&#34;https://www.troopers.de/agenda13/index.html&#34;&gt;Troopers&lt;/a&gt;.&lt;/p&gt;&#xA;&lt;p&gt;Here we go:&lt;/p&gt;&#xA;&lt;p&gt;==================&lt;/p&gt;&#xA;&lt;p&gt;&lt;strong&gt;Andreas Wiegenstein &amp;amp; Xu Jia: Ghost in the Shell.&lt;/strong&gt; &lt;strong&gt;FIRST TIME MATERIAL&lt;/strong&gt;&lt;/p&gt;&#xA;&lt;p&gt;&lt;strong&gt;Synopsis:&lt;/strong&gt; Security conferences in the past years have made it clear, that common security vulnerabilities such as SQL Injection, XSS, CSRF, HTTP verb tampering and many others also exist in SAP software. This talk covers several vulnerabilities that are unique to SAP systems and shows how these can be used in order to bypass crucial security mechanisms and at the same time operate completely below the (forensic) Radar. We uncovered undocumented mechanisms in the SAP kernel, that allow launching attacks that cannot be traced back to the attacker by forensic means. These mechanisms allow to *actively* inject commands at any time into the running backend-session of an arbitrary logged on user, chosen by the attacker. We named this attack mechanism “Ghost in the Shell”. We will also demo how to use this attack vector to distribute malware to the attacked user’s client machine despite mechanisms in the SAP standard that are designed to prevent this.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Troopers 2013 – First Round of Talks Selected</title>
      <link>https://insinuator.net/2012/12/troopers-2013-first-round-of-talks-selected/</link>
      <pubDate>Sun, 23 Dec 2012 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2012/12/troopers-2013-first-round-of-talks-selected/</guid>
      <description>&lt;p&gt;We’re delighted to provide the first announcement of talks of next year’s Troopers edition. Looks like it’s going to be a great event again 😉&lt;br&gt;&#xA;Here we go:&lt;/p&gt;&#xA;&lt;p&gt;==================&lt;/p&gt;&#xA;&lt;p&gt;&lt;strong&gt;Peter Kieseberg: Malicious pixels – QR-codes as attack vectors.&lt;/strong&gt;&lt;/p&gt;&#xA;&lt;p&gt;**Synopsis: **QR-Codes, a version of two-dimensional barcodes that are able to store quite large amounts of information, started gaining huge popularity throughout the last few years, including all sorts of new applications for them. Originating from the area of logistics, they found their ways into marketing and since the rise of modern smartphones with their ability to scan them in the street; they can be found virtually everywhere, often linking to sites on the internet. Currently even standards for paying using QR-codes were proposed and standardized. In this talk we will highlight possible attack vectors arising from the use of QR-Codes. Furthermore we will outline an algorithm for calculating near-collisions in order to launch phishing attacks and we will demonstrate the practical utilization of this technique.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Back from DayCon VI</title>
      <link>https://insinuator.net/2012/11/back-from-daycon-vi/</link>
      <pubDate>Thu, 01 Nov 2012 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2012/11/back-from-daycon-vi/</guid>
      <description>&lt;p&gt;Two weeks ago we had a great time at &lt;a href=&#34;http://www.day-con.org&#34; title=&#34;DayCon&#34;&gt;Day-Con VI&lt;/a&gt;. Enno, Matthias, Rene, Frank and me traveled to Dayton, OH to give workshops and presentations. We started a tough week full of  &lt;a href=&#34;http://day-con.org/POOH.html&#34;&gt;workshops&lt;/a&gt; on Tuesday where Rene gave a deep inside look into the world of security on current mobile platforms. Matthias discussed security problems and possible design patterns of cloud environments in his Cloud &amp;amp; Virtualization Security Workshop before he gave a first insight into the world of reverse engineering on Wednesday. Frank and me taught the basics of hacking and pentesting in the &lt;a href=&#34;http://www.packetwars.com&#34;&gt;PacketWars&lt;/a&gt; bootcamp (comparable to the one at &lt;a href=&#34;https://www.troopers.de/troopers12/agenda/hacking-101-workshop/index.html&#34;&gt;TROOPERS&lt;/a&gt;), preparing the participants for the &lt;a href=&#34;http://packetwars.com/&#34; title=&#34;packetwars&#34;&gt;PacketWars&lt;/a&gt; on Saturday. Obviously we were not the only ones having a &lt;a href=&#34;http://msdaisysramblings.blogspot.de/2012/10/packetwars-and-daycon-exploding-my.html&#34;&gt;great time&lt;/a&gt; 😉&lt;/p&gt;</description>
    </item>
    <item>
      <title>DAY-CON VI</title>
      <link>https://insinuator.net/2012/07/day-con-vi/</link>
      <pubDate>Sat, 21 Jul 2012 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2012/07/day-con-vi/</guid>
      <description>&lt;p&gt;As &lt;a href=&#34;http://www.insinuator.net/2011/10/packetwars-sun-skills/&#34;&gt;every year&lt;/a&gt;, we will be attending &lt;a href=&#34;http://day-con.org&#34;&gt;Day-Con&lt;/a&gt;, a one-day security summit in Dayton, OH — this year for its VIth edition. Even though the actual conference comprises “only” one day full with talks and discussions (please find the agenda &lt;a href=&#34;http://day-con.org/SCHEDULE_%26_SPEAKERS.html&#34;&gt;here&lt;/a&gt;), the overall event consists of &lt;a href=&#34;http://day-con.org/pooh2012.pdf&#34;&gt;trainings&lt;/a&gt; before the conference and &lt;a href=&#34;http://packetwars.com/&#34;&gt;PacketWars&lt;/a&gt; battles (including an infamous party) afterwards. Since we will be leading and attending some of the training sessions, those might be of particular interest for people who missed our &lt;a href=&#34;http://www.troopers.de/archives/troopers12/agenda/&#34;&gt;Troopers workshops&lt;/a&gt; — so you don’t have to wait a whole year but get another chance in October 😉&lt;/p&gt;</description>
    </item>
    <item>
      <title>VMDK Has Left the Building – Slides available</title>
      <link>https://insinuator.net/2012/05/vmdk-has-left-the-building-slides-available/</link>
      <pubDate>Fri, 25 May 2012 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2012/05/vmdk-has-left-the-building-slides-available/</guid>
      <description>&lt;p&gt;&lt;img src=&#34;http://www.insinuator.net/wp-content/uploads/2012/05/HITB_talk.jpg&#34; alt=&#34;&#34; title=&#34;HITB_talk&#34;&gt;A quick update on the workshop we’ve just finished at &lt;a href=&#34;http://conference.hitb.org/hitbsecconf2012ams/&#34;&gt;Hack in the Box 2012 Amsterdam&lt;/a&gt;:&lt;br&gt;&#xA;Due to popular demand we decided to bring the slides online without wasting any more time. The official website of the conference is currently experiencing some problems due to high interest in all the stuff what was released in the last two days. Great conference!&lt;/p&gt;&#xA;&lt;p&gt;Here you go: &lt;a href=&#34;http://www.insinuator.net/wp-content/uploads/2012/11/HITB_AMS_2012_ERNW_VMDK_v1.0_release.pdf&#34;&gt;HITB2012AMS ERNW VMDK Has Left the Building&lt;/a&gt; [PDF, 6MB, link fixed]&lt;/p&gt;</description>
    </item>
    <item>
      <title>Slides from Troopers Telco Sec Day Online</title>
      <link>https://insinuator.net/2012/05/slides-from-troopers-telco-sec-day-online/</link>
      <pubDate>Mon, 14 May 2012 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2012/05/slides-from-troopers-telco-sec-day-online/</guid>
      <description>&lt;p&gt;As I mentioned the Telco Sec Day in the last post… for those who missed Flo’s announcement: in the interim all slides of the Telco Sec Day are available online &lt;a href=&#34;http://www.troopers.de/archives/troopers12/downloads/&#34;&gt;here&lt;/a&gt;.&lt;/p&gt;&#xA;&lt;p&gt;Obviously, given I initiated the event, I’m biased 😉 but to me it provided great insight from both the talks and the networking with other guys from the telco security field, and it did actually what it was meant for: fostering the exchange between different players in that space, for the sake of sustainably improving its’ overall security posture.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Troopers TelcoSecDay</title>
      <link>https://insinuator.net/2012/03/troopers-telcosecday/</link>
      <pubDate>Sat, 17 Mar 2012 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2012/03/troopers-telcosecday/</guid>
      <description>&lt;p&gt;As there has been some public demand for that, here we go with the final agenda for the Troopers “&lt;a href=&#34;http://www.troopers.de/troopers12/agenda/telcosec-day/&#34;&gt;TelcoSecDay&lt;/a&gt;“. The workshop is meant to provide a platform for research exchange between operators, vendors and researchers. The slides of the talks will potentially be made available as well.&lt;/p&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;8:30: Opening Remarks &amp;amp; Introduction&lt;/li&gt;&#xA;&lt;li&gt;9:00: Sebastian Schrittwieser (SBA Research): Guess Who’s Texting You? Evaluating the Security of Smartphone Messaging Applications.&lt;/li&gt;&#xA;&lt;li&gt;10:00: Peter Schneider (NSN): How to secure an LTE-Network: Just applying the 3GPP security standards and that’s it?&lt;/li&gt;&#xA;&lt;li&gt;10:45: Break&lt;/li&gt;&#xA;&lt;li&gt;11:00: Kevin Redon (T-Labs): Weaponizing Femtocells – The Effect of Rogue Devices on Mobile Telecommunications&lt;/li&gt;&#xA;&lt;li&gt;11:45: Christian Kagerhuber (Group IT Security, Deutsche Telekom AG): Security Compliance Audit Automation (SCA, TeleManagementForum TMF528)&lt;/li&gt;&#xA;&lt;li&gt;12:30: Lunch&lt;/li&gt;&#xA;&lt;li&gt;13:45: Philipp Langlois (P1 Security): Assault on the GRX (GPRS Roaming eXchange) from the Telecom Core Network perspective, from 2.5G to LTE Advanced.&lt;/li&gt;&#xA;&lt;li&gt;15:00: Break&lt;/li&gt;&#xA;&lt;li&gt;15:15: Harald Welte (sysmocom): Structural deficits in telecom security&lt;/li&gt;&#xA;&lt;li&gt;16:30: Closing Remarks&lt;/li&gt;&#xA;&lt;li&gt;17:00: End of workshop&lt;/li&gt;&#xA;&lt;li&gt;19:00: Joint dinner (hosted by ERNW) in Heidelberg Altstadt for those interested and/or staying for the main conference&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;p&gt;====&lt;/p&gt;</description>
    </item>
    <item>
      <title>Diving Into Real-World Security Threats to SAP Systems</title>
      <link>https://insinuator.net/2012/02/diving-into-real-world-security-threats-to-sap-systems/</link>
      <pubDate>Wed, 01 Feb 2012 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2012/02/diving-into-real-world-security-threats-to-sap-systems/</guid>
      <description>&lt;p&gt;&lt;em&gt;&lt;strong&gt;This is a guest post by the SAP security experts of BIZEC. Enjoy reading:&lt;/strong&gt;&lt;/em&gt;&lt;/p&gt;&#xA;&lt;p&gt;On March 20^(th), the first &lt;a href=&#34;http://www.bizec.org/&#34;&gt;BIZEC&lt;/a&gt; workshop will be held at the amazing Troopers conference in Heidelberg, Germany. For those still unfamiliar with BIZEC: the &lt;em&gt;business application security initiative&lt;/em&gt; is a non-profit organization focused on security threats affecting ERP systems and business-critical infrastructures.&lt;/p&gt;&#xA;&lt;p&gt;The main goals of BIZEC are:&lt;/p&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;Raise awareness, demonstrating that ERP security must be analyzed holistically.&lt;/li&gt;&#xA;&lt;li&gt;Analyze current and future threats affecting these systems.&lt;/li&gt;&#xA;&lt;li&gt;Serve as a unique central point of knowledge and reference in this subject.&lt;/li&gt;&#xA;&lt;li&gt;Provide experienced feedback to global organizations, helping them to increase the security of their business-critical information.&lt;/li&gt;&#xA;&lt;li&gt;Organize events with the community to share and exchange information.&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;p&gt;The “&lt;a href=&#34;http://http://www.troopers.de/troopers12/agenda/bizec-workshop-sap-security-vulnerabilities-exploits-remediation/&#34;&gt;BIZEC workshop at Troopers 2012&lt;/a&gt;” will dive into the security of SAP platforms. Still to this day, a big part of the Auditing and Information Security industries believe that Segregation of Duties (SoD) controls are enough to protect these business-critical systems.&lt;br&gt;&#xA;By attending this session, InfoSec professionals and SAP security managers will be able to stop “flying blind” with regards to the security of their SAP systems. They will learn why SoD controls are not enough, which current threats exist that could be exploited by evil hackers, and how to protect their business-critical information from cyber-attacks.&lt;/p&gt;</description>
    </item>
    <item>
      <title>ShmooCon, Again</title>
      <link>https://insinuator.net/2012/01/shmoocon-again/</link>
      <pubDate>Sun, 29 Jan 2012 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2012/01/shmoocon-again/</guid>
      <description>&lt;p&gt;&lt;a href=&#34;http://www.insinuator.net/2011/01/washington-dc-for-shmoocon/%20&#34;&gt;Once more&lt;/a&gt; &lt;a href=&#34;http://www.shmoocon.org&#34;&gt;ShmooCon&lt;/a&gt; is the place to be for some days in late January. Great con, great people and five ERNW guys amongst them 😉&lt;/p&gt;&#xA;&lt;p&gt;We regard Shmoo(Con) as one of the most important community events at all and it allows us to meet fellow researchers from the US who we can’t easily sit down with to chat very often.&lt;/p&gt;&#xA;&lt;p&gt;And some lucky guys from ERNW will even continue the trip to head to San Diego (!) for &lt;a href=&#34;http://www.nanog.org/meetings/nanog54/index.php&#34;&gt;NANOG&lt;/a&gt; and &lt;a href=&#34;http://www.internetsociety.org/events/ndss-symposium-2012&#34;&gt;NDSS&lt;/a&gt;. Not to mention they stay in some fancy beach resort ;-), while I myself fly back today. (Getting older I don’t enjoy staying away from home for a week anymore and I have been missing my kids since some days…)&lt;/p&gt;</description>
    </item>
    <item>
      <title>Troopers 2012 – Final round of talks selected</title>
      <link>https://insinuator.net/2012/01/troopers-2012-final-round-of-talks-selected/</link>
      <pubDate>Wed, 25 Jan 2012 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2012/01/troopers-2012-final-round-of-talks-selected/</guid>
      <description>&lt;p&gt;It’s done. The exciting (and demanding) process of selecting talks for Troopers is complete (for the record: second round of talk selection was &lt;a href=&#34;http://www.insinuator.net/2012/01/troopers-2012-%E2%80%93-second-round-of-talks-selected/&#34;&gt;here&lt;/a&gt;, the first &lt;a href=&#34;http://www.insinuator.net/2011/12/troopers-2012-%E2%80%93-first-round-of-talks-selected/&#34;&gt;here&lt;/a&gt;).&lt;/p&gt;&#xA;&lt;p&gt;We’re quite happy and looking forward to the event 😉&lt;/p&gt;&#xA;&lt;p&gt; &lt;/p&gt;&#xA;&lt;p&gt;==================&lt;/p&gt;&#xA;&lt;p&gt;Rodrigo Branco: Into the Darkness – Dissecting Targeted Attacks&lt;/p&gt;&#xA;&lt;p&gt;The current threat landscape around cyber attacks is complex and hard to understand even for IT pros. The media coverage on recent events increases the challenge by putting fundamentally different attacks into the same category, often labeled as advanced persistent threats (APTs). The resulting mix of attacks includes everything from broadly used, exploit-kit driven campaigns driven by cyber criminals, to targeted attacks that use 0-day vulnerabilities and are hard to fend off – blurring the threat landscape, causing confusion where clarity is most needed.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Troopers 2012 – Second Round of Talks Selected</title>
      <link>https://insinuator.net/2012/01/troopers-2012-second-round-of-talks-selected/</link>
      <pubDate>Thu, 12 Jan 2012 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2012/01/troopers-2012-second-round-of-talks-selected/</guid>
      <description>&lt;p&gt;Hi everybody,&lt;/p&gt;&#xA;&lt;p&gt;after having announced the first round of &lt;a href=&#34;http://www.troopers.de&#34;&gt;Troopers&lt;/a&gt; speakers &lt;a href=&#34;http://www.insinuator.net/2011/12/troopers-2012-%E2%80%93-first-round-of-talks-selected/&#34;&gt;here&lt;/a&gt;, we’re happy to publish the second round today 😉&lt;/p&gt;&#xA;&lt;p&gt;Here we go:&lt;/p&gt;&#xA;&lt;p&gt; &lt;/p&gt;&#xA;&lt;p&gt;==================&lt;/p&gt;&#xA;&lt;p&gt;Dmitry Sklyarov – “Secure Password Managers” and “Military-Grade Encryption” on Smartphones: Oh Really?&lt;/p&gt;&#xA;&lt;p&gt;Abstract:  The task of providing privacy and data confidentiality with mobile applications becomes more and more important as the adoption of smartphones and tablets grows. As a result, there are a number of vendors and applications providing solutions to address those needs, such as password managers and file encryption utilities for mobile devices.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Troopers 2012 – First round of talks selected</title>
      <link>https://insinuator.net/2011/12/troopers-2012-first-round-of-talks-selected/</link>
      <pubDate>Sun, 18 Dec 2011 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2011/12/troopers-2012-first-round-of-talks-selected/</guid>
      <description>&lt;p&gt;We’re delighted to provide the first announcement of talks of next year’s &lt;a href=&#34;http://www.troopers.de&#34;&gt;Troopers&lt;/a&gt; edition. Looks like it’s going to be a great event again  😉&lt;/p&gt;&#xA;&lt;p&gt;Here we go:&lt;/p&gt;&#xA;&lt;p&gt;==================&lt;/p&gt;&#xA;&lt;p&gt;Andreas Wiegenstein: Real SAP Backdoors&lt;/p&gt;&#xA;&lt;p&gt;Abstract: In the past year the number of lecture sessions with traumatizing headlines about hacking SAP systems has dramatically risen. Their content, however, is usually the same. Insecure implementations of algorithms, side effects in commands, flawed business logic and designs that brilliantly miss the point of security. In essence, security defects built into the SAP framework by mistake.&lt;/p&gt;</description>
    </item>
    <item>
      <title>“What’s so special about Troopers?”</title>
      <link>https://insinuator.net/2011/11/whats-so-special-about-troopers/</link>
      <pubDate>Fri, 11 Nov 2011 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2011/11/whats-so-special-about-troopers/</guid>
      <description>&lt;p&gt;This week I stayed some days in Zurich, to give a workshop and to meet both clients and fellow researchers (kudos again to C. for the awesome office tour @Google). In the course of one of those dinners somehow Troopers was mentioned and a guy asked: “I’ve heard of the conference. What’s so special about it?”&lt;/p&gt;&#xA;&lt;p&gt;Funnily enough I didn’t even have to respond myself as a &lt;a href=&#34;http://www.troopers.de/archives/troopers11/agenda/&#34;&gt;2011&lt;/a&gt; attendee coincidentally present at the table jumped in and started praising the event (“best con ever. great spirit, great talks”). Obviously this gave me a big grin… but it reminded as well me that some of you might ask themselves the very same question.&lt;/p&gt;</description>
    </item>
    <item>
      <title>A Sneak Peek into TROOPERS12</title>
      <link>https://insinuator.net/2011/11/a-sneak-peek-into-troopers12/</link>
      <pubDate>Thu, 10 Nov 2011 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2011/11/a-sneak-peek-into-troopers12/</guid>
      <description>&lt;h2 id=&#34;troopers11-speaker-badgeshere-we-go-again-troopers12-is-scheduled-for-march-19th--23rd-2012-in-heidelberg-germany&#34;&gt;&lt;img src=&#34;http://www.insinuator.net/wp-content/uploads/2011/11/speaker_badges.jpg&#34; alt=&#34;TROOPERS11 Speaker badges&#34; title=&#34;TROOPERS11 Speaker badges&#34;&gt;Here we go again: &lt;strong&gt;TROOPERS12&lt;/strong&gt; is scheduled for March 19^(th) – 23^(rd) 2012 in Heidelberg, Germany.&lt;/h2&gt;&#xA;&lt;p&gt;Those who attended &lt;strong&gt;TROOPERS&lt;/strong&gt; before know for what we are up to. For all newcomers I’ll quickly outline what’s going to happen:&lt;/p&gt;&#xA;&lt;p&gt;&lt;strong&gt;TROOPERS&lt;/strong&gt; is your premium IT security event in Europe. Think of your usual IT educational event without annoying sales pitching and outdated topics. Now add a superb conference location, an elite line-up of international researchers and practitioners as well as an &lt;a href=&#34;http://www.ernw.de&#34; title=&#34;ERNW GmbH&#34;&gt;organizing team&lt;/a&gt; not dedicated to make a living doing this, but to celebrate our craftsmanship together with like-minded people.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Packetwars, Sun &amp; Skills</title>
      <link>https://insinuator.net/2011/10/packetwars-sun-skills/</link>
      <pubDate>Sun, 16 Oct 2011 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2011/10/packetwars-sun-skills/</guid>
      <description>&lt;p&gt;During the last days, some of our guys (including me) had some great days in Dayton. Rene, Christopher, Hendrik, Sergej, and me flew in to give workshops and presentations at &lt;a href=&#34;http://day-con.org/&#34; title=&#34;daycon&#34;&gt;Day-Con&lt;/a&gt; as well as to compete in the infamous &lt;a href=&#34;http://www.packetwars.com&#34;&gt;PacketWars&lt;/a&gt; game. While Day-Con is a one day event, the two days before the conference comprised workshops on &lt;a href=&#34;http://www.hmtrainingsolutions.com/en/home/85-ios-security-sichere-integration-von-iphone-a-ipad.html&#34;&gt;secure iOS integration&lt;/a&gt; (given by Rene) and &lt;a href=&#34;http://www.hmtrainingsolutions.com/en/home/91-ipv6technologie-und-integration.html&#34;&gt;IPv6 security&lt;/a&gt; (given by Christopher). Since the overall topic of the conference was trust, Rene gave a &lt;a href=&#34;http://www.ernw.de/publikationen/DayConV_ERNW_Broken_Trust_v025.pdf%20&#34;&gt;keynote&lt;/a&gt; on broken trust which was based exemplary trust analysis, development of a trust metric, and different trust factors. Those trust factors were also used in my talk about evaluation methodologies for &lt;a href=&#34;http://www.ernw.de/publikationen/do_they_deliver.pdf%20&#34;&gt;cloud service providers&lt;/a&gt; (regular followers will recognize some of the content of both talks from &lt;a href=&#34;http://www.insinuator.net/2011/10/broken-trust-part-2-applying-the-approach-to-dropbox/&#34;&gt;different&lt;/a&gt; &lt;a href=&#34;http://www.insinuator.net/2011/07/the-key-to-your-datacenter/&#34;&gt;posts&lt;/a&gt; 😉 ). There were also talks from Sergey Bratus, Graeme Neilson and Angus Blitter. While Sergey proposed a sound (not to say academic 😉 ) definition on the classification of vulnerabilities and their connection to &lt;a href=&#34;http://www.wolframalpha.com/input/?i=turing+completeness&#34;&gt;turing complete input languages&lt;/a&gt;, Angus gave an introduction to &lt;a href=&#34;http://grouper.ieee.org/groups/1901/&#34;&gt;PowerLine technologies&lt;/a&gt; and laid out, that these technologies still suffer from naive assumptions about trusted networks (he also refered to &lt;a href=&#34;http://www.blackhat.com/presentations/bh-europe-09/Rey_Mende/BlackHat-Europe-2009-Mende-Rey-All-Your-Packets-slides.pdf&#34;&gt;this&lt;/a&gt;). The day after the conference, the ERNW Allstars had to defend their championship title in PacketWars. Since the first battle was scheduled for 10AM, we had quite some time to tan in the sunny 30°C weather, recover from the conference and prepare the expected victory celebration (some of you might remember some “Champagne tradition” from &lt;a href=&#34;http://www.troopers.de&#34;&gt;Troopers&lt;/a&gt;). In face of this motivation, we rushed through the 3 battles and were able to score first place second year in a row. At this point, kudos to the two other participating teams who gave us a tough battle, especially during the reversing challenges.&lt;/p&gt;</description>
    </item>
    <item>
      <title>HITB Aftermath</title>
      <link>https://insinuator.net/2011/05/hitb-aftermath/</link>
      <pubDate>Sat, 28 May 2011 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2011/05/hitb-aftermath/</guid>
      <description>&lt;p&gt;Hi,&lt;br&gt;&#xA;didn’t find the time so far to post a short blog about &lt;a href=&#34;http://conference.hackinthebox.org/hitbsecconf2011ams/&#34;&gt;HITB Amsterdam&lt;/a&gt; so far… but here we go.&lt;/p&gt;&#xA;&lt;p&gt;Unfortunately I couldn’t arrive in AMS earlier than Thursday evening so I missed the first day (and – from what I heard – some great talks). However we went out for dinner that night with the likes of Andreas (Wiegenstein), Jim (Geovedi), Raoul (Chiesa), Travis (Goodspeed), Claudio (Criscione) and some more guys and I had some quite good conversations, both on technical matters and on Intra-European cultural differences ;-). Btw: thanks again to Martijn for taking care of the restaurant.&lt;/p&gt;</description>
    </item>
    <item>
      <title>TROOPERS11 – Slides available</title>
      <link>https://insinuator.net/2011/04/troopers11-slides-available/</link>
      <pubDate>Tue, 05 Apr 2011 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2011/04/troopers11-slides-available/</guid>
      <description>&lt;p&gt;&lt;strong&gt;TROOPERS11&lt;/strong&gt; slides are available now! Please find them here: &lt;a href=&#34;http://www.troopers.de/troopers11/downloads/&#34;&gt;http://www.troopers.de/troopers11/downloads/&lt;/a&gt;&lt;/p&gt;&#xA;&lt;p&gt;&lt;strong&gt;TROOPERS11&lt;/strong&gt; was a blast! We received great feedback from all attendees and speakers. This really pushes ourselves towards the next goals and an even better security conference in 2012.&lt;/p&gt;&#xA;&lt;p&gt;We’re happy that everybody got home safely with new ideas and inspirations in mind. On a side note: The awesome &lt;strong&gt;TROOPERS&lt;/strong&gt; badge caused trouble for some of you with the airport security 😉 I really hope everybody could find a way to take it back home. It will hopefully find its way to an adequate place right next to your old memorabilia (cup of the first won soccer match, your college degree or photos from your first ballet show). Regard it as the proof of your latest achievement and tell everybody proud and loud: &lt;strong&gt;WE ARE TROOPERS.&lt;/strong&gt;&lt;/p&gt;</description>
    </item>
    <item>
      <title>Troopers 2011 – First round of speakers selected</title>
      <link>https://insinuator.net/2010/12/troopers-2011-first-round-of-speakers-selected/</link>
      <pubDate>Tue, 07 Dec 2010 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2010/12/troopers-2011-first-round-of-speakers-selected/</guid>
      <description>&lt;p&gt;We’re delighted to announce the first speakers of next year’s &lt;a href=&#34;http://www.troopers.de&#34;&gt;Troopers&lt;/a&gt; edition. Looks like it’s going to be a great event again ;-).&lt;br&gt;&#xA;Here we go:&lt;/p&gt;&#xA;&lt;p&gt;==================&lt;/p&gt;&#xA;&lt;p&gt;Ravishankar Borgaonkar &amp;amp; Kevin Redon: Femtocell: Femtostep to the Holy Grail  (Attacks &amp;amp; Research Track)&lt;/p&gt;&#xA;&lt;p&gt;Abstract: Femtocells are now being rolled out across the world to enhance third generation (3G) coverage and to provide assurance of always best connectivity in the 3G telecommunication networks. It acts as an access point that securely connect standard mobile handset to the mobile network operator’s core network using an existing wired broadband connection.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Back from Day-Con</title>
      <link>https://insinuator.net/2010/10/back-from-day-con/</link>
      <pubDate>Sat, 30 Oct 2010 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2010/10/back-from-day-con/</guid>
      <description>&lt;p&gt;… which was, as in the years before, an awesome &lt;a href=&#34;http://www.day-con.org&#34;&gt;event&lt;/a&gt;. Great talks, great people, great fun.&lt;br&gt;&#xA;Bruce Potter gave a &lt;a href=&#34;http://www.ernw.de/download/DayCon-10-Keynote.pdf&#34;&gt;keynote&lt;/a&gt; which did exactly what a good keynote should do: make the audience think and entertain it at the same time.&lt;br&gt;&#xA;[Those readers familiar with ERNW’s security model will certainly notice that we do not necessarily agree with everything he said. We still think that – in particular in times where infosec resources are scarce anyway – putting your bets on prevention provides a better cost/[security] benefit ratio than going for extensive detection capabilities.&lt;br&gt;&#xA;Fix the doors first, then think about installing a CCTV.&lt;br&gt;&#xA;Still, human nature tends to exchange “good security with low visibility” for “poor security with potentially good visibility” quite easily… as can be noted every day in many environments.]&lt;/p&gt;</description>
    </item>
    <item>
      <title>Some recent presentations</title>
      <link>https://insinuator.net/2010/10/some-recent-presentations/</link>
      <pubDate>Mon, 11 Oct 2010 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2010/10/some-recent-presentations/</guid>
      <description>&lt;p&gt;Just a short notice today on some recent presentations from our team. As some of you might know we regularly give talks at conferences. This not only encompasses highly sophisticated security events like Black Hat or &lt;a href=&#34;http://www.troopers.de&#34;&gt;Troopers&lt;/a&gt;. Additionally – on our mission for a safer world – we try to spread the (security) word at various industry events that are usually focused on some aspect of the large and ramified IT world, not necessarily equipped with a strong focus on information security.&lt;br&gt;&#xA;A number of such events took place in the last few weeks and here’s some links on presentations given there. While not being as technically deep as the average Black Hat or Troopers &lt;a href=&#34;http://www.troopers.de&#34;&gt;&lt;/a&gt; attendee might expect, we still hope that one or another valued reader finds them useful (pls note that some parts are in German).&lt;/p&gt;</description>
    </item>
    <item>
      <title>ERNW at NinjaCon (fka PlumberCon)</title>
      <link>https://insinuator.net/2010/07/ernw-at-ninjacon-fka-plumbercon/</link>
      <pubDate>Sat, 10 Jul 2010 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2010/07/ernw-at-ninjacon-fka-plumbercon/</guid>
      <description>&lt;p&gt;&lt;a href=&#34;http://www.insinuator.net/wp-content/uploads/2010/07/ninja_con.jpg&#34;&gt;&lt;img src=&#34;http://www.insinuator.net/wp-content/uploads/2010/07/ninja_con.jpg&#34; alt=&#34;&#34; title=&#34;ninja_con&#34;&gt;&lt;/a&gt;&lt;/p&gt;&#xA;&lt;p&gt;Yesterday we made our way to Vienna to participate and contribute to NinjaCon (formerly known as PlumberCon, before Nintendo Inc. claimed their rights ;)).&lt;/p&gt;&#xA;&lt;p&gt;After our arrival Oliver held a five hour workshop on &lt;a href=&#34;http://plumbercon.org/schedule/68&#34;&gt;Penetration Testing&lt;/a&gt; and did the finishing touches on his slides about ‘&lt;a href=&#34;http://plumbercon.org/schedule/49&#34;&gt;Attacking Cisco Enterprise WLANs&lt;/a&gt;‘, which he will deliver later today together with Daniel. And last but not least Daniel will be the Packet Master of PacketWars™ Vienna taking place in the evening.&lt;/p&gt;</description>
    </item>
    <item>
      <title>TROOPERS10 presentation materials finally online</title>
      <link>https://insinuator.net/2010/06/troopers10-presentation-materials-finally-online/</link>
      <pubDate>Mon, 21 Jun 2010 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2010/06/troopers10-presentation-materials-finally-online/</guid>
      <description>&lt;p&gt;I’m happy to announce that the presentations and a majority of the videos from TROOPERS10 are finally available to you.&lt;/p&gt;&#xA;&lt;p&gt;You’ll find the slides at the conference’s website &lt;a href=&#34;http://www.troopers.de&#34;&gt;troopers.de&lt;/a&gt;, more precisely &lt;a href=&#34;http://troopers.de/content/e728/e897/index_eng.html&#34;&gt;here&lt;/a&gt;. Plenty of videos were uploaded and are now ready for streaming at &lt;a href=&#34;http://www.viddler.com/TROOPERS/&#34;&gt;viddler.com/TROOPERS&lt;/a&gt;. Enjoy!&lt;/p&gt;&#xA;&lt;p&gt;Please excuse the long waiting time – this is a big point on our ‘improvements for upcoming events’ list. Talking about improvements: If you have any suggestions, criticism or even praise for past or upcoming events – let us know in the comment section.&lt;/p&gt;</description>
    </item>
  </channel>
</rss>
