Some time ago I had the pleasure to speak at the BASTA!
Autumn 2019 conference. There, I promised to publish my
slides
such that they can be used as a reference for developers and security guys like
me. And with this blog post I would like to hold up to my promise.
Overall, the talk was about the challenges of “How to bring security into modern
DevOps processes”. Hence, I demonstrated how security can be integrated more or
less seamlessly into the modern agile software development workflow. I proposed
some risk-depended recommendations about which measurements should be
established, for example, within the CI pipeline.
“If it’s a thing, then there’s an app for it!”…We trust mobile apps to process
our bank transactions, handle our private data and set us up on romantic dates.
However, few of us care to wonder,”How (in)secure can these apps be?” Well… at
Troopers 20, you can learn how to answer this question yourself!
In our 2 day long “Hacking mobile apps” workshop, we teach how to find security
vulnerabilities in mobile apps, exploit them and defend against them. We start
from scratch, therefore no prior experience in hacking or developing mobile apps
is required. Whether you want to learn how to pentest mobile apps, you are an
app developer that fancies to secure his/her apps, or just curios, our workshop
is a jumpstart to your goal.
Windows 10 is one of the most commonly deployed operating systems at this time.
Knowledge about its components and internal working principles is highly
beneficial. Among other things, such a knowledge enables:
in-depth studies of undocumented, or poorly documented, system
functionalities;
development of performant and compatible software to monitor or extend the
activities of the operating system itself; and
analysis of security-related issues, such as persistent malware.
The “Insight into Windows Internals” training offered at TROOPERS20 delivers
knowledge on the core components and inner working principles of Windows 10. For
example, the training provides knowledge on how Windows 10 uses virtualization
to isolate security-critical functionalities from attackers that have managed to
compromise the system. The training includes a variety of practical exercises
allowing attendees to observe first-hand the operation of Windows 10.
This week I was at DevSecCon in London
to present my current research on Red Hat OpenShift. In this talk, I gave a
brief introduction to OpenShift, demonstrated some threats that exist for such
environments, and dived into different configuration issues that may affect the
security of OpenShift environments. The implications of misconfigurations of
such an environment have been shown in live demos.
Hi there,
like in recent years the popular
Hacking 101 workshop
will take place on TROOPERS20, too! The workshop will give you an insight into
the hacking techniques required for penetration testing. These
techniques will cover various topics:
Information gathering
Network scanning
Web application hacking
Low-level exploitation
…and more!
During this workshop you will learn, step by step, a testing methodology
that applies to the majority of scenarios. So imagine you have to assess the
security of a system running on the Internet. How would you start? First,
you need a good understanding of the target, including running services or
related systems. Just scanning the target’s IP address will most likely not
reveal all relevant information you can get. In the information gathering step,
you will learn where you could find more relevant information than just a list
of open ports. A brief understanding of the target and it’s related
systems/services/applications will make scanning and identifying
vulnerabilities a lot easier and more effective. Then, the last step will be
the exploitation of the identified vulnerabilities, with the ultimate aim to
get access to the target system and pivot to other, probably internal,
systems and resources.
We are happy to announce that TROOPERS20 will feature the 5th anniversary of the
popular Windows & Linux Binary Exploitation workshop!
In this workshop, attendees will learn how to exploit those nasty stack-based
buffer overflow vulnerabilities by applying the theoretical methods taught in
this course to hands-on exercises. Exercises will be performed for real world
(32-bit) software such as the Foxit Reader Plugin for Firefox, Wireshark, and
nginx.
Each exercise will start with an initially uncontrolled overwrite of the
instruction pointer register by a stack-based buffer overflow vulnerability.
From there on, we will work our way through many obstacles to finally gain
remote code execution. Obstacles that will be encountered during the exercises
include modern stack-based buffer overflow defense mechanisms such as stack
cookies, data execution prevention (DEP), and address space layout randomization
(ASLR). For all of these defense mechanisms, attendees will learn and apply
certain methods to bypass the protection.
After our
last blogpost
regarding Emotet and several other Emotet and Ransomware samples that we
encountered, we recently stumbled across a variant belonging to the Gozi,
ISFB, Dreambot respectively Ursnif family. In this blogpost, we want to
share our insights from the analysis of this malware, whose malware family is
mainly known for being a banking trojan that typically tries to infect browser
sessions and sniff/redirect data. In particular, we are going to provide details
about the first stage Word Document, the embedded JavaScript/XSL document, an
in-depth runtime analysis of the downloaded executable, and some details
regarding detection.
The Windows Insight repository now
hosts three articles on Windows code integrity and WDAC (Windows Defender
Application Control):
Device Guard Image Integrity: Architecture Overview (Aleksandar
Milenkoski, Dominik Phillips): In this work, we present the high-level
architecture of the code integrity mechanism implemented as part of
Windows 10.
Windows Defender Application Control: Initialization (Dominik Phillips,
Aleksandar Milenkoski): This work describes the process for initializing
WDAC performed by the Windows loader and the kernel when Windows 10 is booted.
Windows Defender Application Control: Image verification (Aleksandar
Milenkoski): This work discusses the workflow of WDAC for verifying images.
SadProcessor here, happy to be back on the Insinuator to share with you some of
my latest BloodHound adventures and experiments…
TL;DR Well too bad for you…
Before diving into a bit of code and some BloodHound data manipulation,
I would like to thank the BruCon Crew for having me over last week for
BruCON0x0B.
I had the pleasure of delivering a 4h BloodHound & Cypher workshop in the
lovely city of Gent [in a fantastic training room], and I am pleased with the
interaction & feedback I had with the attendees.
I was also very happy to see almost as many Blues as Reds in the room [as well
as regular security folks!!], all together having a play with BloodHound &
Cypher.
Inspiriert durch die erfolgreichen Round-Table-Diskussionen der
TROOPERS-Konferenz freuen wir uns, Ihnen heute mit dem Medical Device Security
Summit 2019, eine weitere Veranstaltung in einer Reihe zu Trend-Themen im
Bereich der IT-Sicherheit vorzustellen.
Die Veranstaltung beginnt am Morgen mit einem Eröffnungsvortrag von Peter Hecko
(Leiter der IT-Sicherheit bei HELIOS IT Service GmbH, Podcaster und jahrelanges
Mitglied im CCC), gefolgt von Fallstudien und Vorträgen von ERNW Experten und
weiteren Referenten aus der Lehre, Industrie und klinischer Praxis.