In this post, I will introduce fpicker. Fpicker is a Frida-based
coverage-guided, mostly in-process, blackbox fuzzing suite. Its most significant
feature is the AFL++ proxy mode which enables blackbox in-process fuzzing with
AFL++ on platforms supported by Frida. In practice, this means that fpicker
enables fuzzing binary-only targets with AFL++ on potentially any system that is
supported by Frida. For example, it allows fuzzing a user-space application on
the iOS operating system, such as the Bluetooth daemon bluetoothd – which was
part of the original motivation to implement fpicker.
The Federal Office for Information Security (BSI) aims to sensitize
manufacturers and the public regarding security risks of networked medical
devices in Germany. In response to the often fatal security reports and press
releases of networked medical devices, the BSI initiated the project
Manipulation of Medical Devices (ManiMed) in 2019. In this project, a security
analysis of selected products is carried out through security assessments
followed by Coordinated Vulnerability Diclosure (CVD) processes. The project
report was published on December 31, 2020, and can be accessed on the BSI
website 1.
The Federal Office for Information Security (BSI) aims to sensitize
manufacturers and the public regarding security risks of networked medical
devices in Germany. In response to the often fatal security reports and press
releases of networked medical devices, the BSI initiated the project
Manipulation of Medical Devices (ManiMed) in 2019. In this project, a security
analysis of selected products is carried out through security assessments
followed by Coordinated Vulnerability Diclosure (CVD) processes. The project
report was published on December 31, 2020, and can be accessed on the BSI
website1.
The Federal Office for Information Security (BSI) aims to sensitize
manufacturers and the public regarding security risks of networked medical
devices in Germany. In response to the often fatal security reports and press
releases of networked medical devices, the BSI initiated the project
Manipulation of Medical Devices (ManiMed) in 2019. In this project, a security
analysis of selected products is carried out through security assessments
followed by Coordinated Vulnerability Diclosure (CVD) processes. The project
report was published on December 31, 2020, and can be accessed on the BSI
website1.
I am glad to announce the release of the ERNW whitepaper 71 containing
information about quarantine file formats of different AV software vendors. It
is available
here.
Anti-Virus Software
I took quarantine files from real-life incidents and created some in a lab
environment. Afterwards I tried to identify metadata, like timestamps, path
names, malware names, and the actual malicious file in the quarantine files. One
goal was to use this information to support our incident analyses: Using the
results, we can now easily create timelines showing information about
quarantined files, extract the detected malware, and sometimes even find
information about processes that created the malicious files.
The Federal Office for Information Security (BSI) aims to sensitize
manufacturers and the public regarding security risks of networked medical
devices in Germany. In response to the often fatal security reports and press
releases of networked medical devices, the BSI initiated the project
Manipulation of Medical Devices (ManiMed) in 2019. In this project, a security
analysis of selected products is carried out through security assessments
followed by Coordinated Vulnerability Diclosure (CVD) processes. The project
report was published on December 31, 2020, and can be accessed on the BSI
website1/
It’s Friday, you managed to escape for a couple of hours from a busy working day
to see a doctor. Now you have to wait in a boring waiting room at the clinic
until it’s your turn to see her majesty. What would you like to do in this time?
Answer pending business emails, get lost in social media, or choose a new theme
to make your iPhone look awesome? What about: all of the above? It’s nice to
have everything on your iPhone: MDM enrollment to access business data, in
addition to jailbreak for device freedom. However, MDM solutions ban jailbroken
devices, because they are not secure enough to handle sensitive business data.
And so, cat and mouse games of jailbreak detection/bypass between MDM solutions
and some users develop.
The Federal Office for Information Security (BSI) aims to sensitize
manufacturers and the public regarding security risks of networked medical
devices in Germany. In response to the often fatal security reports and press
releases of networked medical devices, the BSI initiated the project
Manipulation of Medical Devices (ManiMed) in 2019. In this project, a security
analysis of selected products is carried out through security assessments
followed by Coordinated Vulnerability Diclosure (CVD) processes. The project
report was published on December 31, 2020, and can be accessed on the BSI
website1.
With this blog post, I will provide information on how to proceed when testing
ELK Stack landscapes. Information regarding the exploitation of the ELK Stack is
very rare on the internet. Therefore, following article aims to provide you with
some approaches that can be useful during a penetration test.
Disclaimer:
All information below were collected during a research project and there is no
claim for completeness. The guide focuses on ELK Stack deployments for Linux
machines. Further, this article does not include information for identifying
misconfigurations in a white-box configuration audit.
With this blog post I am pleased to announce the publication of a new ERNW White
Paper about the HL7 FHIR communication standard.
Introduction
Digital networking is already widespread in many areas of life. More and more
medical devices are also being networked in the healthcare industry. This growth
makes the development and use of new medical communication standards necessary
since existing solutions can only meet the changing requirements with great
effort. The HL7 FHIR standard is an example of such a medical communication
standard. FHIR is said to have increased the interoperability between different
medical contexts,e.g., administration, billing, and clinical care, to enable
data exchange of various systems. The FHIR standard addresses the security risks
associated with strongly networked communication from a large number of systems
across the trust and organizational boundaries only indirectly because FHIR does
not define mandatory security controls or requirements.