As mentioned in my last
blogpost,
I had the pleasure to participate in this years DFRWS USA and present our paper.
The paper and presentation can be freely viewed and downloaded
here
or here. Note that
there is also an extended version of the paper, which can be downloaded
here.
The keepassx, zsh and heap analysis plugins are now also part of the
Rekall release candidate 1.7.0RC1,
so it’s easier to get started.
The conference had some great talks and workshops, which I’m going to briefly
sum up.
The 11th USENIX Workshop on Offensive Technologies (WOOT17) took place the last
two days in Vancouver. Some colleagues and I had the chance to attend and enjoy
the presentations of all accepted papers of this rather small, single-track
co-located USENIX event. Unfortunately, the talks have not been recorded.
However, all the papers should be available on the
website. It’s worth
taking a look at all of the papers, but these are some presentations that we’ve
enjoyed:
Some of the ERNW Crew hit up Black Hat USA and DEFCON. Our own Omar Eissa even
gave his first BH and DEFCON talks! See which talk we liked and what inspiration
we took home.
Over one of the recent long weekends I attended the 17th
“Gulaschprogrammiernacht”, or “GPN17” for short, in Karlsruhe, the largest CCC
Event after the Chaos Communication Congress with roughly a thousand attendees.
The name literally translates to “goulash programming night”, which makes about
as much sense as the German version. Despite the name it lasted from Thursday to
Sunday, had a much wider scope than just coding and offered various other (incl.
vegan) dishes besides goulash. As an active member of the CCC community I
planned on attending it anyway, but submitted my talk about Automated Binary
Analysis in case there was interest. I didn’t anticipate that much interest
given that it was a fairly theoretical IT-Security topic at an event that was
not focused on IT-Security, but nonetheless the hall was filled with people from
various backgrounds like math, formal verification and software optimization.
The talk was an improved version of the one I gave at
Bsides Ljubljana,
incorporating feedback I received and new things I had learned since then. The
English slides are available
here, the recording
of the talk in German can be found
here.
Inspiriert durch die erfolgreichen Round Table Session der TROOPERS freuen wir
uns Ihnen heute mit dem AgileSecurity Insight Summit 2017 eine weitere
Veranstaltung in einer Reihe zu Trend-Themen im Bereich der IT-Sicherheit
vorzustellen.
Die Veranstaltung beginnt am Morgen mit einer Keynote, gefolgt von Fallstudien
und Vorträgen durch interne und externe Referenten aus der Industrie. Im
Anschluss werden alle Teilnehmer in zwei Gruppen aufgeteilt, die nacheinander an
beiden Round-Table Sessions teilnehmen. In den Round-Table Sessions werden unter
Expertenmoderation typische Problemstellungen und Lösungsansätze diskutiert.
The following post is in German as it is covering a Training with German as the
main language.
Professionelles Training im Workshop Character:
Docker, Microservices, Kubernetes, DevOps, Continuous
Integration/Deployment/Delivery (CI/CD), Container – moderne
Entwicklungsprozesse kommen nicht mehr ohne diese Begriffe aus. In diesem Kurs
lernen Sie die Security Grundlagen um diese Dinge zu beherschen.
Docker Security & (Sec) DevOps Training:
Im Training werden unter Anderem die folgenden Fragestellungen behandelt:
Wie stark/zuverlässig sind die Isolationsmechanismen hinter
Docker/Linux/Betriebssystem-Containern?
Wie beeinflussen Container typische Applikations- und Netzwerk-Landschaften?
Wie beeinflussen die CI/CD/Microservice Paradigmen traditionelle
Entwicklungsprozesse?
Wie sieht eine typische CI/CD Pipeline aus?
Was sind potentielle Schnittstellen zwischen „Security“ und diesen Paradigmen?
Welche zusätzlichen Security-Herausforderungen ergeben sich aus der
veränderten Entwicklungslandschaft und neuen Tool-Chains?
Voraussetzungen:
Die Teilnehmer sollten grundlegende Kenntnisse der Linux Kommandozeile
besitzen
sowie ein System mit einem SSH Client. Teilnehmer die die Demo-VM gerne selbst
betreiben möchten erhalten diese auf einem USB-Stick, müssen sich aber selbst
um
Import und Start kümmern.
The following post is in German as it is covering an Event with German as the
main language.
INSIGHT SUMMIT 2017 präsentiert Active Directory Security & Secure
Operations
Inspiriert durch die erfolgreichen Round Table Sessions der TROOPERS freuen wir
uns Ihnen heute mit dem Active Directory Insight Summit 2017 eine weitere
Veranstaltung in einer Reihe zu Trend-Themen im Bereich der IT-Sicherheit
vorzustellen.
Die Veranstaltung beginnt am Morgen mit einer Hinführung zum Thema Active
Directory Sicherheit gefolgt von Fallstudien und Vorträgen durch interne und
externe Referenten aus Wirtschaft und Industrie. Im Anschluss werden alle
Teilnehmer in zwei Gruppen aufgeteilt, die nacheinander an beiden Round Table
Sessions teilnehmen (jeder Teilnehmer kann an beiden Sessions teilnehmen). In
den Round Table Sessions werden unter Expertenmoderation typische
Problemstellungen und Lösungsansätze diskutiert.
From May 8th to 12th I was able to attend the 74th RIPE meeting in Budapest,
Hungary. Being rather new to the networking community, I enjoyed learning a lot
of different things, not only from the various interesting talks but also from
inspiring conversations with a variety of people from all areas during the
beautiful social events.
As it was the first RIPE meeting for me, I was very thankful for the “Newcomer’s
Introduction” on Monday morning, containing a RIPE and RIPE NCC 101. It was
quite helpful to get into the mindset and understand the structure of the
meeting, like the division into different working groups based on the
participants’ interests. After familiarizing myself with the concept, I chose to
attend several sessions on Address Policy, IPv6, Routing, Open Source, and DNS
working groups besides the general plenary sessions. I’ll be reviewing those
sessions here.
Given the
CfP for Black Hat US in
Vegas ends in a few days – and as
apparently somepeople have
already started to think about their TR18 submissions – I’ll quickly provide
some loose recommendations on how to write a submission here. There’s quite some
reasonable advice out there already (the BH CfP site lists
this
and
this which
you should both read as well) but some of you might find it useful to get (yet)
another perspective.
At CSA, I was talking about hypervisors, breakouts and an overview of security
measures to protect the host.
(Slides)
This ranged from the basic features some hypervisors provide out of the box to
advanced features like SELinux, device domain models and XSM-FLASK.
Most of the other talks were more targeted towards management level employees,
but even as a fairly technical person I found Mike Bursell’s
talk highly interesting. After my
talk about securing the host system from a malicious guest, he dealt with the
inverse: Technologies to protect a guest from a malicious or compromised host.