Last friday Florian and me attended the
6th No-Spy Conference in Stuttgart, Germany. We
gave a talk about surveillance and censorship on modern devices in North Korea
and discussed various aspects with the attendees. The atmosphere was very
welcoming and we had some nice discussions about various topics which allowed us
to better clarify some things. The slides are available
here.
I’m on my way back from the
RIPE74 meeting in Budapest. It was a great event:
quite a few nice technical talks in the plenary, productive working group
meetings and some really good hallway discussions.
Big thanks to the RIPE NCC team for the smooth organization and for taking care
of us!
Here’s some stuff I found particularly interesting:
Andrew Alston’s take on “Anti-Shutdown
Policies” (slides
and video incl. extensive mic
discussion)
It is a pleasant surprise for many (us included) that Microsoft implemented
support for the RDNSS (RFC 8106) option
in Router Advertisements beginning with the
Windows 10 Creators Update.
Interestingly, I wasn’t able to find any official documents from Microsoft
stating this. As we are involved in a lot of IPv6 related projects for our
customers, the lack of RDNSS support for Windows and DHCPv6 for Android is a
major pain point when implementing IPv6 in mixed client segments, as you need to
implement both mechanisms to ensure that all clients do get the relevant network
parameters. I won’t beat on the dead horse, but Microsoft’s decision is a huge
step in the right direction and one can hope that one day Google finds a
“compelling use case” to implement at least stateless DHCPv6 for Android.
Troopers ’17 – the 10th edition – madness is over and
hopefully all of you are well rested and recovered after this special week. Of
course the rest of the world did not stand still and thus Google lifted the
curtains on a new public portal collecting and promoting the Open Source
Software projects developed by employees of Google:
opensource.google.com. There are a lot of
interesting projects that might incubate new interesting developments. And even
security oriented tools and projects (51 at the time of writing to be precise)
are publically available [1].
In
the recent post
on the IPv6 properties of the latest MS Windows versions I announced another one
providing details on the RFC 6980
related testing I had performed. So here we go.
When doing IPv6 security testing there’s mainly four toolkits which can be used:
Scapy (whose IPv6 capabilities are,
afaik, mainly maintained by Guillaume Valadon.
some tutorial on IPv6 packet crafting with scapy can
be found here).
Each of them has specific strenghts & limits, which will not be discussed here.
For the testing I performed I chose Chiron as it has the most powerful options
when it comes to IPv6 extension headers and fragmentation.
Exactly one week ago I noticed an “urgent” tweet from Tavis Ormandy to get in
contact with the Cloudflare team.
Normally when a tweet like this appears from Tavis, something is horribly
broken. Well, today we know the background of this tweet as the
bug tracker
issue went public and it exposed quite a bug from Cloudflare.
While there is some background story how Tavis found the bug, because he wasn´t
actively looking into the Cloudflare infrastructure and it was rather discovered
by accident when odd data appeared in his fuzzing corpus. When he looked closely
he found data that was not in any mean related to the expected data from various
websites.
IP Multimedia Subsystem (IMS) offers many multimedia services to any IP-based
access network, such as LTE or DSL. In addition to VoLTE, IMS adds service
provider flexibility, better QoS and charging control to the 4th generation of
mobile networks. IMS exchanges SIP messages with its users or other IMS and
usually these communications are secured by TLS or IPSec. But if an attacker
manages to break the confidentiality and the integrity with IMS, he would find
it vulnerable to several attacks.
Have you for example thought about classes of incidents that are most likely to
affect you and formulated Incident Handling Preparation Plans for those
incidents?
Niklaus, Manuel and me had a great time speaking about one of the latest Tablet
PCs from DPRK at
33C3 this year.
Our work on
RedStar OS from last year
revealed a nasty watermarking mechanism that can be used to track the origin and
distribution path of media files in North Korea. We have seen some interesting
dead code in some of RedStar’s binaries that indicated a more sophisticated
mechanism to control the distribution of media files. We got hands on a Tablet
PC called “Ul-lim” that implemented this advanced control mechanism.
Recently we posted
first part of our
Bluetooth research diary. Today, we want to continue on that topic and tell you
about Bluetooth proxying and packet replay with a new tool.
This time we had a new gadget to play with: our colleague Florian Grunow shared
with us a curious IoT device – Bluetooth socks… real socks that you control with
an app to heat your feet. The future is here… 😉