Although a bit on short notice it was a good meeting with interesting
discussions. I contributed with shortened versions of two talks we had delivered
in the past:
the “MLD Considered Harmful” talk that Antonios,
Jayson and I had presented at the
Troopers IPv6 Security Summit 2015.
The mentioned Internet-Draft on MLD security which
Eric Vyncke, Antonios and myself are
working on can be
found here.
We’re happy to receive any feedback on that one.
Special thanks go to
Jan Zorz
and to CZ.NIC for hosting us and providing refreshments.
Much appreciated, guys!
I had the honour to be invited to BT‘s SnoopCon, which is
their annual internal conference for people involved with security at BT. There
were several external and internal speakers and I was stunned by the quality of
the talks and the collaborative atmosphere. Since this event is somewhat
internal (even though I’m obviously allowed to talk about it), I won’t go into
details, however there were two particularly great talks about military war
games (which I personally enjoyed very much given my history in CTF contests)
and PoS security.
Flo and I had the pleasure to present at the CSANordic Summit in Norway.
Being in Oslo for the first time, we enjoyed the conference (small, familiar
atmosphere) very much and want to thank Lars and Kai for putting together such a
good event & having us there!
I recently had the pleasure to join the
64th NANOG (North American Network
Operators’ Group) meeting in San Francisco, which can be understood as one of
the largest Internet engineering conferences at all. It takes place three times
a year at different locations in North America.
What I personally like about NANOG is its strong collaborative and cooperative
character. It is not about single persons and also not too much about
spectacular projects but more about discussing technologies, ideas, challenges
and numbers. Every talk has a comparatively large time slot reserved for
discussion, which is often more than fully used. Discussion is typically
actively focused and is more time-consuming (and even more relevant) than the
talk itself. Which often is intended by the community. The climate of discussion
is almost always impressively polite and constructive, even for controversially
discussed topics.
End of May eight ERNW members were travelling to Moscow (Russia) to visit the
PHDays V conference. It was a very nice trip
because we met a lot of gentle people, ate some great food and had quite
some fun in this exciting and history-charged metropole, and we were able to get
around using hands and feet (and Google translate ;-)).
The remainder of this post contains summaries of some of the most interesting
talks at PHD V:
I’m back from London where I gave a talk about security evaluation of
proprietary network protocols. I had a great time at
InfoSecurity Intelligent Defence
and BSides London, many thanks for
inviting me and giving me the opportunity to speak to so much nice people.
Find the abstract and the download link to the slides after the break.
Even in the time of Cloud-based security tools, behavior- and machine
learning-based APT detection and colorful security appliances, a lot of
vulnerabilities are still buried deep within the protocol layers. For security
researchers it is quite a challenge to find those in well documented protocols
(take SSL for an example), and when it comes to proprietary protocols, the bar
is raised even (significantly) higher. This keynote will show that there is
still an urgent need for security evaluation on (undocumented) network
protocols, discuss war stories on protocol fails, and also give an
introduction into the methodology of protocol reversing and how those protocol
fails could have been avoided.
Today the ERNW Team participated in the Mudiator mud
race in
Mannheim.
This mud run features 25 obstacles over 8 km, you can do either one or two
rounds. Participating for the first time, the ERNW team went for one round (the
Legionnaire distance as opposed to the two round Hercules distance):
Following our idea of open access to knowledge (both about vulnerabilities and
sports 😉 ), here are some hints/lessons learned:
The final blog in our series “Beyond the Thunderdome: A Review of TROOPERS15”
focuses Exploitation & Attacking. With the last of this series we hope we you
are already fired up and inspired for what lays a head during our upcoming
TROOPERS16 (March 14-18, 2016)! Can’t wait to see
you there!
“The old is new, again. CVE20112461 is back” talk created and given by Luca
Carettoni and Mauro Gentile
Last week we enjoyed quite a wonderful HAXPO exhibition and HITB conference in
Amsterdam. A number of great talks could be heard at the main HITB conference
such as “Bootkit via SMS: 4G Access Level Security Assessment” or
“Stegosploit: Hacking with Pictures“. And not only that: there were also
several engaging hands-on workshops.
Apart from the main conference, there was the HAXPO – a hacker exhibition. At
this exhibition you could connect with people from different companies, get a
lot of merchandise, and also listen to several briefings on security and its
philosophy. Fortunately, we had the pleasure to present two of these briefings
and maybe you tested your web application skills at the ERNW booth.
We hope you are enjoying the ride as we continue our journey through IPv6. Below
we have a great mix of talks, slides, and videos in this area posted below. We
look forward to hosting more IPv6 (March 14^(th) & 15^(th)) talks next year at
TROOPERS16!
“New Features of the SI6 Networks’IPv6 Toolkit” talk created and given by
Fernando Gont
The IPV6 Toolkit was originally developed for UK CPNI in an effort to enhance
and be able to test the current state of IPv6 security. The toolkit itself was
mainly developed for security analysis and trouble shooting of IPv6 networks and
implementations. It is running on a wide range of *nix based systems (this
probably is considered painful to support given that low level implementation of
network functions) and release under the GPL. You can directly check it out
here: https://github.com/fgont/ipv6toolkit.