You evade web application firewalls as they would be opened doors?
You have successfully exploitated CVE-2015-8769?
Then it’s time for the next challenge! Follow us down the rabbit hole to the not
so well known attacks against modern web applications.
At Troopers16 we will be presenting the second iteration of our
WebHackingSpecialOps workshop in which more advanced techniques to break current
web application technologies will be explained. On the first day there will be
an introduction that gives a quick overview on the well-known attacks like SQLi,
XSS and XSRF. Then attacks will be shown that build upon these “old” vectors
including blind/clientside SQLi, NoSQLi and some specialties on NodeJS, the
javascript based server-side runtime. Next to these technical topics several
formal subjects like 3rd library handling and a guideline on how to deploy TLS
in a secure way will be given. Especially the 3rd party library chapter since
they have become more and more relevant, as in the near past several major
vulnerabilities in such libraries were found which gave attackers the chance to
break web applications that were based on these. This shows that even though
developers do a great job and developer companies get familiar with secure
development lifecycles, there are still problems depending on the used
technologies that cannot be addressed easily. One example of such a
vulnerability is the object deserialization flaw in the Apache Commons
Collections library, which was discovered at the beginning of 2015 and got
attention in November, when two researchers presented their
talk on AppSecCali2015
and showed how easy remote code execution can be done through this kind of flaw.
The details of all kind of object deserialization (as almost all current
scripting/high level programming languages support this feature) will be part of
our course. Next to these topics a deep-dive into current crypto algorithms,
their usecases concerning webapplications and their flaws will be given. Within
every part of this course several demos and hands-on exercises will be done, so
every attendee will be able to apply new knowledge directly. Don’t miss this
chance to improve, Trooper!
This year’s
Hacking 101
workshop at TROOPERS16 will give attendees an insight into the hacking
techniques required for penetration testing. These techniques will cover various
topics like information gathering, network mapping, vulnerability scanning, web
application hacking, low-level exploitation and more.
During this workshop you will learn, step by step, a testing methodology that is
applicable to the majority of scenarios. So imagine you have to assess the
security of a system running on the Internet. How would you start? First, you
need a good understanding about the target, including running services or
related systems. Just scanning an IP will most likely not reveal a lot of
information about the system. The gathered information may help you to identify
communication relations of services that could include vulnerabilities. A brief
understanding of the target and it’s related systems/services/applications will
make scanning and identifying vulnerabilities a lot easier and more
effective. Then, the last step will be the exploitation of the identified
vulnerabilities, with the ultimate aim to get access to the target system and
pivot to other, probably internal, systems and resources.
Hello everybody and welcome to the second part of our 32C3 recap!
In case you didn’t see
the first part, make sure
to check it out 😉
Logjam
by **Nadia Heninger & Alex Halderman
**Video |
Slides
This talk was held by Nadia Heninger and Alex Halderman on the second day of the
congress. Both work in academic and the field of cryptology. They talked about
the “Logjam”-Attack they and several colleagues discovered and published in may
of 2014. They started their talk by explaining how they uncovered the
vulnerability which was quite interesting since Logjam was no breaking news
anymore. And well it was inspired by the congress of the year before, 31C3. The
research was conducted because they got curious how the NSA might be able to
decrypt VPN traffic as stated by Jacob Applebaum and Laura Poitras in their
“reconstructing narratives” talk.
Dear all,
This year the
TelcoSecDay
will take place on March 15th. For those of you who does not know about: the
TelcoSecDay it is a sub-event of Troopers bringing
together researchers, vendors and practitioners from the telecommunication /
mobile security field.
The event is celebrating its 5th anniversary now, that’s why I’d like to say
“thank you” to everybody taking part at this very great discussion round in the
last few years. We always had a lot of very good feedback and interesting
discussions and the increasing participation list of operators from year to year
says (almost) everything!
Happy 2016 everyone! We are exactly 2 months away from the start of
TROOPERS16!! Speakers and Trainers across the globe are polishing (or in some
cases creating) their PowerPoints to use while delivering their highly technical
and entertaining talks. While we here at TR HQ are busy tweaking orders,
creating challenges to boggle the mind and test your skills, and of course
working on some top secret fun. 😉
Niklaus and me had the chance to talk about our research on RedStar OS on the
32nd Chaos Communication Congress in Hamburg this year. You can see the talk
online at
media.ccc.de
or on Youtube.
We talked about the details of the watermarking mechanism that
we found in July
and additional features of RedStar OS like it’s “Virus Scanner” and the system
architecture. During the days after our talk we were able to find watermarks
applied by RedStar OS in the wild on some sites on the Internet. We can confirm
at least 7 different instances of RedStar OS that have applied watermarks to
JPGs. Cleaning up the data is work in progress and we will get back to you with
the results! Niklaus has put our presentation and additional resources in the
git. Feel free to join us in our
research and make the world a safer place!
Rafael Schaefer: Advanced IPv6 Attacks Using Chiron. Hands-On Workshop
Outline: During the IPv6 Security Summit at Troopers 14,
Chiron, an all-in-one IPv6 penetration
testing framework was released publicly for first time. Since then, the advanced
features of Chiron were used to discover some 0-day evasion techniques against
high-end commercial and open-source Intrusion Detection / Prevention Systems.
Moreover, for Troopers 15 it was enhanced with new features, like advanced MLD
support and a fake DHCPv6 server, which can be combined with its other features,
like the use of arbitrary Extension Headers and fragmentation to leverage really
advanced attacks.
In this workshop, after a quick refreshing to the basic capabilities of Chiron,
we will focus on the advanced IPv6 functionalities that the framework offers. We
will not only show how to reproduce the latest published IPv6 attacks, but
moreover, how you can create your own arbitrary IPv6 attacking scenarios for
your own security assessments or penetration testing purposes. A lab will be set
up in order not only to reproduce the presented techniques, but to also try your
skills and – why not – to discover your own 0-day techniques :).
As we come to the end of the year we can’t help but take a moment to thank all
of your who made TROOPERS15 special! It just makes us all the more pumped to
kick it up a notch for TROOPERS16!! #BestWeekEver
Happy Holiday and much Joy to you in the New Year!
The BetterCrypto Project started out in the fall of 2013 as a collaborative
community effort by systems engineers, security engineers, developers and
cryptographers to build up a sound set of recommendations for strong
cryptography and privacy enhancing technologies catered towards the operations
community in the face of overarching wiretapping and data-mining by nation-state
actors. The project has since evolved with a lot of positive feedback from the
open source and operations community in general with input from various browser
vendors, linux distribution security teams and researchers.
Before we dive into the analysis, I wanted to mention that if you are going to
analyze anything unknown/potentially malicious, do it in a safe environment (VM
with no internet connection, in the best case on a separate physical analysis
device, or at least strip all unnecessary functionality from that VM
(CVE-2015-3456 is an example to answer the “why”)). Even things like looking at
content with a text editor or extracting zip files should be done in the safe
environment, as those tools could contain vulnerabilities.