35C3 is over, and the recordings are available so in case you did not have the
chance or the time to watch the live streams during the holidays or overwhelmed
with the number of talks, see in the following a list of recommended talks to
fill your evenings or weekends. Apart from the broad coverage of topics in
different areas (Ethics, Society & Politics, Hardware & Making, Resilience, Art
and Culture, Security, Science, Resilience), foundation talks were aiming for
the very basics following this year’s motto “Refreshing Memories.”
We are going to have a
Blackhoodie event at
Troopers 2019 on March 18th and 19th in Heidelberg.
With a very exciting event last year, we have decided to roll it once again
during Troopers.
As always, one of the main motivation for
Blackhoodie is bringing more women into
reversing and other core security topics. So we would like to see more women
apply to the training slots. However, if you are not a women and still feel
really excited about Blackhoodie, you are welcome to apply. We do have a very
limited number of seats at this training site. So we apologize in advance if we
can’t accommodate everyone, even though we wish we could! Please apply before
“February 10th” and we will contact you regarding next steps.
Docker has become the go-to technology in enterprise- and DevOps contexts. Yet,
before mastering a skill, there is the thumb rule: one must learn the basics to
have solid fundament before building a house on top.
Simon and I start from the very beginning. We introduce you to the fundamental
concepts of containers starting at process isolation and extending our tour to
the whole ecosystem of Docker and further associated technologies. We will cover
Docker, microservices, containers, DevOps, continuous
integration/deployment/delivery – all those fancy buzzwords that can be read in
the context of modern software development methodologies.
And five talks more were chosen for TROOPERS19! It sounds like it is going to be
the best year ever again…
Follow us on Twitter (@WEareTROOPERS) for
more information and do not hesitate to use our hashtag #TR19 when you have
questions or remarks about TROOPERS19!
Your TROOPERS Team
——————————–
Not A Security Boundary: Breaking Forest Trusts by Will Schroeder, Lee Christensen
TROOPERS18 was the best year ever (did you check our
archives?) and it will be challenging to do
better… However, we accept the challenge!
The trainings and talks were from high quality and choices were difficult to
make… We hope you will enjoy reading these little teasers!
Follow us on Twitter (@WEareTROOPERS) for
more information and do not hesitate to use our hashtag #TR19 when you have
questions or remarks about TROOPERS19!
Generally speaking, I’m more of a Cat type of guy, but I have to say I really
love BloodHound. And if you do too, you are in for a treat…
Last week, the ERNW InsightActive
Directory Security Summit took place in Heidelberg.
(More Info)
For
this occasion, @Enno_Insinuator asked me
if I would like to deliver a BloodHound Workshop, and of course I accepted
the challenge…
We had a full class, I had a blast training it, and I hope the trainees enjoyed
it as much as I did.
But that’s not all…
Another part of the deal was that I had to write a Training Guide that we
would then share with the Community (aka you).
So here it is, fresh from the Heidelberg press and available for download:
If a conference feels like a great vacation, then the organizers are doing it
absolutely right! Hack.lu took place for the 14th time in
Luxembourg. From the 16th – 18th October, the Alvisse Parc Hotel hosted the
Hack.lu conference. Those three days were full of talks, workshops and
“discussions about computer security, privacy, information technology and its
cultural/technical implication on society“. Some members of the ERNW crew had
the chance to attend Hack.lu this year and we all enjoyed it a lot!
I was at the hack.lu conference in Luxembourg this year and attended the fuzzing
workshop, held by René Freingruber from
SEC Consult. I have been curious about this topic
for some years now, but besides doing some manual fuzzing and web-fuzzing, I
never looked into the whole topic that much.
The workshop lasted for around four hours. Before the workshop started each
student got two VMs (Linux/Windows) where everything necessary was already set
up. The VMs included 23 exercises, with step-by-step explanations, source code
and exploits. René started out with an introduction to fuzzing, listing popular
fuzzers and showing an example on how to fuzz with
afl.
Matthias and I
had the pleasure to give a talk at the H2HC2018 in
São Paulo, Brazil about attacking VMware NSX. The talk is an introduction to
VMware NSX for security researchers, and it discusses possible attack vectors
including the management, controlling, and data exchange planes. We demonstrated
how to prepare a fuzzing and debugging setup for the ESXi kernel and the kernel
modules. It should be noted that Olli was also
supporting the research.
The slides can be found
here.