First day at hack.lu. Three of us kicked the conference
off with the ARM IoT Firmware Emulation workshop by
Saumil. The goal of this workshop was not
so much to write exploits or to pwn boxes but to learn how to build a beneficial
research environment by emulating the hardware of a Linux based IoT device to
run its firmware in order to run analysis and tests.
First step is to obtain the firmware. This could be done by dumping it directly
from the device or by downloading firmware images from the vendor. In order to
dump the firmware from the device one has to obtain access to the underlying
system which is usually done by finding the serial console on the hardware since
this one often exposes an unauthenticated root shell. I think there is enough
documentation online on how to identify and connect to a serial console so I
won’t cover the details here. It’s also covered in Saumil’s
slides
in detail. Having the bootup logs from this console will be helpful later
though. While talking about baud rates for the serial console Saumil made a
great pun I don’t want to withhold: “Most common is baud rate 115200. If you
find a console with baud rate 9600 you are in fact talking to an acoustic
coupler. That’s not an IoT device, it rather belongs to a museum.”
Inspiriert durch die erfolgreichen Round-Table-Diskussionen der
Troopers-Konferenz freuen wir uns, Ihnen heute mit dem Incident Analysis and
Digital Forensics Summit 2018, eine weitere Veranstaltung in einer Reihe zu
Trend-Themen im Bereich der IT-Sicherheit vorzustellen.
Die Veranstaltung beginnt am Morgen mit einem Eröffnungsvortrag von Thomas
Schreck (Chairman of the Board des internationalen CERT Verbunds FIRST), gefolgt
von Fallstudien und Vorträgen durch weitere Referenten aus der Industrie und
Strafverfolgung.
I have the pleasure to announce the Active Directory Security Summit 2018 at
13^(th). of November of 2018. The summit covers current Active Directory
security related topics such as challenging tasks of hybrid Active Directory
operations as well as new security best practices and some ‘evergreens’ – Admin
Tiering implementations (what about Exchange and DNS…??), ESAE operations etc.
😉
The primary objective of the Active Directory Security Summit is to bring
experts together:
Gender equality in the Infosec world as a topic of discussion comes with a lot
of heated arguments and differences in opinion.
So let me start with some disclaimers on the target audience for this post. If
you are in the category who believes everything about gender is perfect in the
infosec world, this post is not for you. If you are in the category who believes
gender and bringing diversity is not your area of interest, then this post is
not for you either. There are so many interesting problems that the world offers
you. Climate change, poverty, diseases, unemployment, addiction, science
problems and what not. Everybody has the freedom to choose their area of
interest and contribute towards it. If you are in the category who thinks gender
equality in infosec needs some attention and would like to explore more on the
topic without prejudices, then this post may be interesting to you.
In Mai 2018, Tobias and me were in Cologne at the Building IoT conference. The
topics of the talks covered a broad spectrum of the Internet of Things field.
There were three tracks covering different topics ranging from the jungle of IoT
protocols, secure Linux hypervisors specially developed for IoT modules to
machine learning and blockchain.
In “How to secure over the air updates” the speaker showed how to securely
deploy updates over the standard communication channel to the target device.
Many consumer IoT devices have a short support for updates if they get any
updates at all. This leads and in the future will lead to bad news like botnets,
bricked devices and exploited IP cameras streaming publicly. Therefore, a patch
and vulnerability management is required – especially in industrial Internet of
Things devices. Some updates have to be performed over the air due to the
physical inaccessibility of some IoT devices in production environments. There
are two possibilities to update such systems: First, a rescue OS (Operating
System) boots and overwrites the existing production OS. The second option is a
redundant OS, which copies the updates to the inactive OS and reboots to that.
I had the pleasure to give a presentation at the
Security Interest Group Switzerland Technology Conference
about modern application stacks and how they can be used to improve
infrastructure and application security posture – the slides can be found
here.
Besides seeing a lot of old friends, I
particularly enjoyed a round table discussion on security integration into CI/CD
pipelines. There was a relevant exchange on approaches that actually work and
were tested in environments beyond just recommending some container scanner
(product). One participant had an interesting case study on how they enabled
developers to maintain WAF policies in configuration files in their code
repository including automated deployment to the WAF. He also emphasized that
the environments with actual security benefits resulted from a close cooperation
between development and security team (were domain knowledge was combined 😉 ).
Last week (25^(th) – 27^(th) April), I attended the “Sicherheit 2018” in
Konstanz which is the annual meeting of the security community of the
Gesellschaft für Informatik e.V. (GI) in Germany. The conference is in equal
proportions attended by researchers and people of the industry working in
security-related disciplines which lead to lively and pleasant discussions
conversations.
The topics discussed were contentual wide-reaching, so there were very technical
talks like Sebastian Banescu who was the winner and one of two candidates
nominated for the best PhD thesis award presenting about “Characterizing the
Strength of Software Obfuscation Against Automated Attacks”, as well as
conceptual presentations such as Sabrina Krausz elucidated her bachelor thesis
about an integrated procedure model for planning and implementing an ISMS on the
example of the pharmaceutical production.
We are very excited to publish some (more to come!) of our photos from
TROOPERS18! Based on feedback from #TR18
we would also like to take a moment for our official TROOPERS photographer to
introduce himself and tell you a little about what inspires him.
Peter Walter is a 37 year old photographer based in Germany near Stuttgart. For
many years now he is the official TROOPERS photographer and very proud to be
part of the Troopers family.
Stefan and I had the pleasure of joining a one-day closed workshop on Industrial
IoT Security. As always, we ended up with plenty of new research ideas and great
contacts. We hope of course to post on follow-up research, but in this short
post we quickly want to publish our slides which contain our input for the
workshop. We mainly presented on IT security challenges for modern IIoT
environments and presented some case studies for successful hardening/protection
of IIoT environments as well as security in IIoT product development.
This blogpost contains summaries of talks from this year’s
TROOPERS18 Attack & Research Track.
Reverse Engineering Blackbox Systems with GreatFET & Facedancer by Kate Temkin and Dominic Spill
USB is everywhere, your phone, gaming consoles, IoT waffle irons, you name it.
Due to its’ widespread use in everyday life it is typically trusted by the user.
And even if one wanted to find out what’s happening behind the scenes, surely
digging into USB communication is too much of a chore to be worth the hassle,
right? This talk by Kate Temkin and Dominic Spill are about to prove that very
wrong with an impressive display of their tools
GreatFET and
Facedancer.