We are thrilled to announce the
Blackhoodie event at
Troopers 2018 on March 12th and 13th in Heidelberg.
This time it is going to be a 2 day workshop with various interesting topics
related to reverse engineering. We will make sure that you get some hands on
experience with reversing and more.
As always, one of the main motivation for
Blackhoodie is bringing more women into
reversing.
So we would like to see more women apply to the training slots. However, we are
open to everyone who would like to apply. We do have a very limited number of
seats at this training site. So we apologize in advance if we can’t accommodate
everyone, even though we wish we could! Please apply before “February 20th”
and we will contact you regarding next steps.
At Troopers18 there will be a new special track on
Microsoft Active Directory and its security aspects, similar to the SAP security
track which we established some years ago. The AD security track will feature,
amongst others, the following talks.
Sean Metcalf: Active Directory Security. The Journey
Abstract: This talk is a journey into the challenges most organizations
encounter while trying to secure their ‘castle’. The attacker has to be right
only once, right? Not exactly. We will walk through effective security
strategies that will stymie and frustrate attackers and better protect the
Active Directory environment.
I am amazed by how this years BlackHoodie
unraveled. Three days that included a pre-conference of lightening talks and two
parallel tracks with a total of 64 enthusiastic members. The very spirit of
BlackHoodie is nothing other than the quest to
gain deep knowledge. Reverse engineering is one of the hardest fields in
security. It touches on all fields of computing, starting from assembly,
programming, file formats, operating systems, networks and what not. This makes
it hard but an extremely fulfilling experience to spend time learning it. For
me, the very idea of staring at a binary till you understand what it does is a
magical feeling.
Following my work with the
FreeBSD implementation of RFC 6980
I was happy to present my work at last week’s DENOG 9 meeting.
To make it available to anyone who did not meet me there and go into some more
detail that would have exceeded the boundaries of the talk, I will cover the
topic here.
After the preceding work on
Windows Server 2016
and the FreeBSD testing, as a Linux user, lover and administrator, I of course
wanted to take a look at how different Linux systems complied with the RFC 6980
standard.
TROOPERS17 was unlike any TROOPERS we had
known before. Everything just seemed bolder, better, and beyond our
expectations. From surprise speakers like
the grugq (do you have a follow-up talk for
#TR18 by the way?) to new speakers who are now TROOPERS family, TROOPERS17 is
one for the history books!
If you were there you might be wondering to yourself, how could they possibly
top it (and if you were not there check out this
video from TR17)? Well, I am not
going to lie, it will be a challenge. However, the high quality of talk and
training submissions for this year have us feeling pretty positive about making
#TR18 the “best year ever”!
The conference was very well organized and attendee focused, which could be seen
by the many little details found on the conference. For example you never ran
out of coffee or beverages, there was a new Hallway Track where you could meet
people from all disciplines, discuss about your favorite topics and there was
always a place to sit and take a break between all those interesting
presentations. I had the chance to speak to very nice people from different
industries, most importantly in my case on the topic security. It was nice to
see how the Docker community is growing and the adoption rate is increasing,
especially in companies. The main focus of the conference (especially seen in
talks held by people from Docker Inc.) was the Docker Enterprise Edition.
We are super excited for TROOPERS18 (March
12-16th, 2018) as are many of you! We even have this great saying that “after
TROOPERS is before TROOPERS”, which means we spend a lot of time looking
through feedback from attendees, speakers/trainers, and our own Crew for ways to
not only top what we’ve done in the years before, but also how to simply make it
better for everyone involved. Looking around at our Crew we realized how
many have either attended TROOPERS or other conferences as students. We heard
from them, as well as other students, how life changing it was to be able, as a
student, to attend an IT-Security conference. How they got to meet a speaker
whose work they’d read about in class. How people felt even more a part of the
community they were studying hard to belong to.
This is my short write up on Daycon X1, 2017. The
summit was held at Dayton, the land where
Wright brothers were born.
Apart from being my first US trip, I also gave my first training on Hacking 101
also called the Bootcamp.
The Daycon X1 bootcamp started on 18th September. Ahmad, my colleague focused
on web security, network scanning and metasploit exercises. I mainly handled
classes on reversing and binary exploitation along with some pcap anaylsis and
network attacks. It was highly fulfilling experience to give a workshop.
Teaching is definitely the best way to learn any topic by digging deep into
it.The simpler you can explain, the more clarity you have on the topic. But I
must say that it was indeed exhausting by the end of three days.
Last week I had the pleasure to participate at the
first RIPE IoT Roundtable Meeting
in Leeds (thanks! to
Marco Hogewoning
for organising it). It was a day with many fruitful discussions. I particularly
enjoyed Robert Kisteleki‘s talk on RIPE NCC’s own
design & (security) process considerations in the context of
RIPE Atlas (at TR17 NGI there was an
intro to Atlas,
too).
In this post I’d like to quickly lay out the main points of my own contribution
on “Balanced Security for IPv6 CPE Revisited” (the slides can be found
here).
Some of our Troopers had the chance to visit HITCON conference in Taiwan this
year. There are two main events: HITCON Pacific, which is aimed more at
corporate attendees and HITCON CMT, the community edition, which aims at
students and the general Infosec community. HITCON is the biggest security
conference in Taiwan.
The venue for the event is the Academia Sinica, one of the most important
academic institution in the Republic of China and was founded in 1928 to promote
and undertake scholarly research in sciences and humanities. The conference had
three usual tracks and one special track that was free to use for the public for
demos, presentations and discussions.