We are happy to announce that TROOPERS20 will feature the 5th anniversary of the
popular Windows & Linux Binary Exploitation workshop!
In this workshop, attendees will learn how to exploit those nasty stack-based
buffer overflow vulnerabilities by applying the theoretical methods taught in
this course to hands-on exercises. Exercises will be performed for real world
(32-bit) software such as the Foxit Reader Plugin for Firefox, Wireshark, and
nginx.
Each exercise will start with an initially uncontrolled overwrite of the
instruction pointer register by a stack-based buffer overflow vulnerability.
From there on, we will work our way through many obstacles to finally gain
remote code execution. Obstacles that will be encountered during the exercises
include modern stack-based buffer overflow defense mechanisms such as stack
cookies, data execution prevention (DEP), and address space layout randomization
(ASLR). For all of these defense mechanisms, attendees will learn and apply
certain methods to bypass the protection.
After our
last blogpost
regarding Emotet and several other Emotet and Ransomware samples that we
encountered, we recently stumbled across a variant belonging to the Gozi,
ISFB, Dreambot respectively Ursnif family. In this blogpost, we want to
share our insights from the analysis of this malware, whose malware family is
mainly known for being a banking trojan that typically tries to infect browser
sessions and sniff/redirect data. In particular, we are going to provide details
about the first stage Word Document, the embedded JavaScript/XSL document, an
in-depth runtime analysis of the downloaded executable, and some details
regarding detection.
The Windows Insight repository now
hosts three articles on Windows code integrity and WDAC (Windows Defender
Application Control):
Device Guard Image Integrity: Architecture Overview (Aleksandar
Milenkoski, Dominik Phillips): In this work, we present the high-level
architecture of the code integrity mechanism implemented as part of
Windows 10.
Windows Defender Application Control: Initialization (Dominik Phillips,
Aleksandar Milenkoski): This work describes the process for initializing
WDAC performed by the Windows loader and the kernel when Windows 10 is booted.
Windows Defender Application Control: Image verification (Aleksandar
Milenkoski): This work discusses the workflow of WDAC for verifying images.
SadProcessor here, happy to be back on the Insinuator to share with you some of
my latest BloodHound adventures and experiments…
TL;DR Well too bad for you…
Before diving into a bit of code and some BloodHound data manipulation,
I would like to thank the BruCon Crew for having me over last week for
BruCON0x0B.
I had the pleasure of delivering a 4h BloodHound & Cypher workshop in the
lovely city of Gent [in a fantastic training room], and I am pleased with the
interaction & feedback I had with the attendees.
I was also very happy to see almost as many Blues as Reds in the room [as well
as regular security folks!!], all together having a play with BloodHound &
Cypher.
Inspiriert durch die erfolgreichen Round-Table-Diskussionen der
TROOPERS-Konferenz freuen wir uns, Ihnen heute mit dem Medical Device Security
Summit 2019, eine weitere Veranstaltung in einer Reihe zu Trend-Themen im
Bereich der IT-Sicherheit vorzustellen.
Die Veranstaltung beginnt am Morgen mit einem Eröffnungsvortrag von Peter Hecko
(Leiter der IT-Sicherheit bei HELIOS IT Service GmbH, Podcaster und jahrelanges
Mitglied im CCC), gefolgt von Fallstudien und Vorträgen von ERNW Experten und
weiteren Referenten aus der Lehre, Industrie und klinischer Praxis.
We are back again with another
TelcoSecDay 2020 (TSD20) which
is going to happen on March 16th, 2020 as an additional event to
TROOPERS. This year, it is going to be on Monday of
the TROOPERS week. We are delighted to inform that the event is happening for
the 9th year in a row. The CFP is open
now. If you have an interesting topic related to the field of Telco Security,
please make a submission. The deadline is November 17, 2019. The final
notification for TSD submission is December 20, 2019.
Recently, I discovered a sandbox breakout in the Groovy Sandbox used by the
Jenkins script-security Plugin in their Pipeline Plugin for build scripts. We
responsibly disclosed this vulnerability and in the current version of Jenkins
it has been fixed and the according
Jenkins Security Advisory 2019-09-12
has been published. In this blogpost I want to report a bit on the technical
details of the vulnerability.
Description
The groovy sandbox transforms some AST nodes of the script to add security
checks. For example
On September 14th the final deadline of complying with the new Payment Service
Directive PSD2 will be reached. Among other things, this directive will bring
quite a few technical challenges for credit institutions. These include new
requirements on two-factor authentication and API access for third parties. In
this blog post we will give a short overview of what this means for banks from a
security perspective and outline a few of the security-related issues based on
what we have been observing during recent assessments of such APIs.
This is meant to be the first part of a 3-part series discussing the space &
types of IP addresses, with a particular focus on what has changed between IPv4
and IPv6. In this first post I’ll take the audience through a historical tour of
some developments within the IPv4 address space.
In a second part I’ll discuss the properties of different types of addresses
from a routing and from a security perspective, both in the IPv4 and in the IPv6
space. In the third part we’ll look at the implications of deploying IPv6 in
certain networks based on those differences, e.g. “how to handle ACLs and IP
address based log analysis approaches in a dual-stack network where systems have
one RFC 1918 IPv4 address and multiple IPv6 GUAs?” (for specific reasons the
latter two parts might be published on another medium though). In any case let’s
start with a brief history of IPv4. The goal here is to understand how we got to
the state that we have today.
I’ve been at Black Hat Vegas last week and in the following I’ll shortly discuss
some talks I’ve attended and which I found interesting.
Gabriele Fisher &
Luke Valenta: Monsters in the Middleboxes.
Building Tools for Detecting HTTPS Interception
This talk was about identifying if inbound HTTPS traffic reaching a server had
been intercepted by a middlebox (or
its software equivalent which is usually called “middleware”, a prominent
example being the Lenovo Superfish piece a few years ago) on its path.