Welcome to the third edition of “Beyond the Thunderdome: A Review of
TROOPERS15”. The focus today is on IPv6 and Data Center Networks, so kick back
and enjoy the following talks and videos. And as always, check out our website
www.troopers.de for details on TROOPERS16 March
14-18, 2016.
“Enabling and Securing IPv6 in Service Provider Networks” talk created and given
by Tarko Titan
Telekom.ee had no IPv6, 8 moths ago. They deployed IPv6 in about 4 weeks and by
now about 6% of all transported traffic is IPv6 traffic. Actually the 4 weeks
timeframe is a bit too optimistic but more on that later. Tarko first explains
the biggest problems in the network migration, which were the access network and
the Customer -Provider Edge (CPE). Also Telekom Estonia doesn’t want to make a
tradeoff at security in the IPv6 deployment.
Today’s focus in our blog series will cover large-scale environments:
Cryptography in Cloud environments and Network Automation. Since these topics
will only become more important over time stay tuned for our
TROOPERS16’s developing agenda to see what new talks
will be available (or submit your own talk during our Call for Papers starting
in August via our new CFP Submission tool!)
“Crypto in the Cloud” talk created and given by Frederik Armknecht
Here in Heidelberg we are already gearing up for TROOPERS16 (taking place from
14th to 18th March 2016!). While you are preparing for our Call for Papers or
waiting eagerly to sign up for your spot in one of our legendary trainings take
a look at our newest blog series “Beyond the Thunderdome: A Review of
TROOPERS15”. It may offer some inspiration, help you kill time while waiting for
next year’s TROOPERS, or for those that are new to our conference, give you a
taste for what TROOPERS is all about. See you soon
at TROOPERS16!
Two weeks ago Christopher and I joined the RIPE70 meeting in Amsterdam. Being
part of the group was fun as always and we had quite some interesting
conversations with peers from the IPv6 community.
We could even contribute a bit to some discussions, with two talks. I gave one
titled “Will It Be Routed? – On IPv6 Address Space Allocation & Assignment
Approaches in Very Large Organizations” in the Address Policy Working Group
session on Wednesday. This is the abstract:
There are lots of interesting places to visit in Amsterdam, but if you are there
between the 26th and the 29th of May, then our booth at HAXPO exhibition should
be your main destination.
HAXPO is a great exhibition, where you can
become up-to-date with the latest security technologies, attend various
workshops and get in touch with more than 35 IT and information security
companies. It will take place in the beautiful historical building “Beurs van
Berlage” in the center of Amsterdam. As usual, ERNW will take part in HAXPO. We
will be waiting for you in the Community Village section (booth NL-018). Come
visit and get to know more about us. You are invited to take our hacking
challenges, where the levels of complexity vary from beginners to advanced.
Furthermore, we will bring our KNX hacking suitcase!
I attended this really nice conference in Slovenia on April
16th. It was a smaller conference, but very memorable for the people (students,
IT sec professionals and managers alike) who attended.
I also had the pleasure to present
on How secure am I with EMET?
and
Evaluating the APT armor and
wanted to share the slides with you — feel free to approach me for any kind of
feedback or discussion.
A while a go Dominik and I gave an introductory presentation about SSL at the
BASTA.NET conference, a developer-oriented event held in Darmstadt twice a year.
At that time there were quite some enthusiastic participants but recently we’ve
also gotten some inquiries asking for the relevant materials. Although there’s
no recording of the session, we’ve decided to put the slides here for those
interested who didn’t make it to the talk.
This year’s PacketWars contest at Troopers was a
blast! Under the topic of “Connected Car” the teams faced several different
challenges, which we will describe (as a debriefing) here.
You and your krew are “freelancers” hired to identify and neutralize an unknown
threat agent who has created weaponized software and delivered it to civilian
Connected Cars via compromised EV (Electrical Vehicle) charing stations. To make
matters worse there are indications that new strains of the malware are
appearing as the “worm” spreads from car to car. The mobile mesh network created
by the Connect Car is highly resilient, allowing the malware to spread
exponentially. Time is of the essence.
Malware analysis suggests that besides a botnet module, there is an active
CANBus injection capability. There appears to be other modules but they haven’t
been properly reversed and analyzed yet.
On March 16^(th), 2015, at the Troopers
IPv6 Security Summit,
we finally released the SI6 Networks’ IPv6 Toolkit v2.0 (Guille). The
aforementioned release is now available at the
SI6 IPv6 Toolkit homepage. It is
the result of over a year of work, and includes improvements in the following
areas:
Increased portability
Bug fixes
Additional features in existing tools
Brand-new tools
Increased Portability
One of the goals that the SI6 Toolkit had since its inception is that of
portability. The SI6 Toolkit has supported all major BSD-derived OSes, Linux,
and Mac OS for a number of years now. And this new release supports yet another
new platform: OpenSolaris. We believe that besides supporting a greater user
base, increased portability ultimately results in improved code quality.
Last week Matthias and I went to Singapore to teach our workshop on
Hypervisor Exploitation at
SyScan. After a very unpleasant Lufthansa strike (which
made us arrive late in Singapore) and two intense workshop days, we were free to
attend the “last” SyScan. There are few IT security conferences that have such a
great reputation in the community and so we had high expectations, which were
definitely not disappointed. This year had a lot of really interesting talks so
I will just summarize some of the ones I liked the most.