Events

#TR18 Defense & Management Summaries

This blogpost contains summaries of talks from this year’s TROOPERS18 Defense & Management Track.

All Your Cloud Are Belong to Us

The talk “All Your Cloud Belong Are Belong to Us” was held by Nate Warfield, who is a Senior Security Program Manager for the Microsoft Security Response Center (MSRC).
Before Microsoft he worked as a network engineer about 18 years and 10 of this for a large amount of cell phone companies.
Nate gives an overview about the state of the cloud solution provided by Microsoft, Azure, and how he hunts vulnerabilities in this environment.
Finally he concludes that the giving up your infrastructure to the cloud doesn’t mean that you give up your responsibility.

Continue reading
Events

#TR18 Next Generation Internet (NGI) Summaries

This blogpost contains summaries of talks from this year’s TROOPERS18 Next Generation Internet Event.

 

NGI Keynote by Graeme Neilson

Before his infosec career Graeme was a street performer, then security researcher, now he calls himself a defender. The talk was built around the following sentence: “The infosec industry and community have completely failed to create meaningful change in the behavior of people”.

The following example is a resume of how hacking worked from 1988 to 2017:

Continue reading
Events

#TR18 SAP Security Summaries

This blogpost contains summaries of talks from this year’s TROOPERS18 SAP Security Track.

SAP IGS : The ‘vulnerable’ forgotten component by Yvan Genuer

The Internet Graphics Server (IGS) is used to generate Web Based graphics from the SAP Web AS. Yvan Genuer looked at the security of an ancient component with very few public vulnerabilities available so far. In his talk he gave us insights on the structure of the IGS, its services, and problems he had when looking for documentation of the IGS and its components.

Continue reading
Events

#TR18 Active Directory Security Track, Part 1

This is the first post discussing talks of the Active Directory Security Track of this year’s Troopers which took place last week in Heidelberg (like in the last nine years ;-). It featured, amongst others, a new track focused on Microsoft AD and its security properties & implications. This was the agenda.

The idea for this special track was born out of two considerations:

  • we had noted there’s a lot of stuff going on in the space, both on the offense and on the defense side. And in pretty much every incident analysis & response project we were brought in recently Active Directory played a huge role…
  • already in the early phase of the CfP several interesting submissions came in (maybe due to the fact that some big guns of the field had voiced very kind words in the past)… and creating an extra track simply relieved us from the burden to make a tough choice between those.

As this was the first Troopers since its creation where I didn’t have any official roles and out of personal interest (in a very distant past I happened to be the co-author of the first German book on Windows NT4 Security)  I decided to spend the majority of conference day 2 in the AD track. In hindsight I’m tempted to say that the track was a huge success: brilliant talks, pretty much always a packed room, and quite good discussions after the talks. (yes, of course I’m biased, what makes you think that?).

Continue reading
Events

The Hackers‘ Sanctuary City

https://youtu.be/wCMwTUS3k4c

TROOPERS has a long history of theming the conference every year. Usually we pick a surreal topic, a fun story which we think is worth to pick up on. Some of it starts as a crazy thought, others have been the result of long discussions. Most of them are online, only our master piece from 2016 is securely stored in the company’s vaults.

However, this year was different. Traveling across the globe, speaking at and attending other conferences, connecting with our peers and the community, we felt that 2017 was a particularly tough year for many of us, both professionally and personally. There was this doom and gloom baseline to it.

Continue reading
Events

Auditing AWS Environments

Introduction

Related to our new TROOPERS workshop “Jump-Starting Public Cloud Security”, this post is going to describe some relevant components which need to be taken care of when constructing and auditing an Amazon Web Services (AWS) cloud environment. Those include amongst others the general AWS account structure, Identity and Access Management (IAM), Auditing and Logging (CloudTrail and CloudWatch), Virtual Private Cloud (VPC) networks, as well as S3 buckets.

The AWS IAM service is responsible for identity and access management (surprise!). This includes managing user accounts, defining password policies, and – most importantly – creating, defining, and assigning groups and roles.

Continue reading
Events

TelcoSecDay 2018 – Talks Part2

We have the next set of selected talks being announced here. I am super excited about the variety of applications we had this year. Here are some of the talks we will have.

Title: From LoRa technology to deployment within Orange affiliates

Speakers: Franck L’Hereec and  Albert Nguyen

Just deployed, the LoRa technology has already passed into the hands of hackers who have analyzed the LoRaWAN protocol as well as the objects and gateways that implement it. At Orange, Orange Labs’ security experts have therefore looked into those issues, first to understand it better, and also ensure the network’s deployment in optimal security conditions. Demonstration via the example of the treatment of the security of an innovation project by Orange. During the presentation we will present :

Continue reading
Events

TLS in the Enterprise: Is Heartbleed still a Problem?

Our new workshop about TLS/SSL in the enterprise will be held for the 1st time at Troopers 2018. So I would like to take the opportunity and post a short teaser about stuff we will cover in this workshop.

TLS/SSL is a complicated topic especially in enterprise environments due to the fact, that

  • encrypted traffic should be inspected e.g. for malware
  • customers/users must be able to use important applications
  • crypto attacks are complex and sometimes considered to be only a problem in theory
  • the internal CERT wants to have every issue fixed, if feasible or not 😉
  • impact of configuration changes can not be foreseen
  • Software inventory is incomplete (do you want to make a bet that Heartbleed is fixed completely in your environment ;-)? )
  • … and so forth

In the workshop we will cover all these points, discuss them and share our experience regarding feasibility and useful mitigating controls. We will explain the most common SSL vulnerabilities/attacks, demonstrate tools to test (and sometimes to exploit) them, point out pitfalls and recommend what to do. Let us have a look at one example, Heartbleed:

Continue reading
Events

Get your hands dirty playing with RFID/NFC

This is a guest blog post by Nahuel Grisolia.

The first time I’ve heard about RFID was at high school, back in 2002, when I was studying Electronics. Back in that time, this technology was like some sort of black magic to me. A few years later in 2011, our government in Argentina decided to implement a “new technology” called NFC, designed as the new and only way of payment for the use of public transport. So, I decided to understand it better, play with it, and try some hacks I heard from the cool people of the CCC.

Continue reading
Events

TelcoSecDay 2018 – CFP and First talks

We have a short update from the TelcoSecDay 2018 Agenda. But before that, a short reminder. The CFP for TelcoSecDay 2018 is still open. If you are into telco research, and if you have something interesting to talk, please make a submission here. The deadline is 17th February 2018.

Here are the first two confirmed speakers who are going to talk about the below mentioned topics:

Title: Data Security for 4G Interconnection and 5G Interconnection Risk Areas

Continue reading