We are glad to announce the
Windows Insight repository. The
content of this repository aims to assist efforts on analysing inner working
principles, functionalities, and properties of the Microsoft Windows operating
system. This repository stores relevant documentation as well as executable
files needed for conducting analysis studies.
Some of the content of this repository has been created in the course of a
project named ‘Studie zu Systemaufbau, Protokollierung, Härtung und
Sicherheitsfunktionen in Windows 10 (SiSyPHuS Win10)’ (ger.) – ‘Study of system
design, logging, hardening, and security functions in Windows 10’ (eng.). This
project has been contracted by the
German Federal Office for Information Security
(ger., Bundesamt für Sicherheit in der Informationstechnik – BSI). The work
planned as part of the project is conducted by ERNW GmbH, starting in May 2017.
Chris and I will give a tutorial on the above
topic at next week’s RIPE Meeting in Reykjavík. In
this post (actually this will probably become a small series of posts) I’ll try
to summarize some thoughts on IPv6 security in enterprise environments in 2019.
We’re going to cover three main areas:
Why IPv6 Is Different, Security-wise
Traffic Filtering in IPv6 Networks
IPv6 Security in L2 Networks / First Hop Security et al.
Let’s start with the first item. In real-life scenarios the security of “a
protocol” – IPv6 can rather be considered a “protocol family” which includes
helper protocols like ICMPv6 and MLD (which in turn is implemented by means of
ICMPv6 messages) and potentially others like DHCPv6 – might depend on a number
of factors:
Dominik Phillips and I are taking part in a tour organized by
Heise Security – the
Heise Security Tour. We
give a talk titled “PowerShell: Attack under the radar”. In this talk, we
provide an overview of the architecture of PowerShell and show how attackers may
use PowerShell for malicious purposes. We demonstrate PowerShell
post-exploitation activities implemented as part of publicly available
frameworks, such as Empire. We also discuss
a security concept for defending against such activities.
This blogpost contains summaries of talks from this year’s
TROOPERS19 Active Directory Security Track.
Microsoft IT (Secure) Journey to IPv6-Only
Veronika McKillop, Network Architect, Cloud and Connectivity Engineering (CCE)
The speaker, Veronika McKillop, working at Microsofts network infrastructure
services, has given a talk about the process of switching a company network from
IPv4 to IPv6-only.
Within the talk the following topics were introduced: Dual Stack, Drivers for
IPv6, Status of IPv6 in Networks and Security in IPv6 Networks. The talk covers
the reasons why a company would like to switch from IPv4 to IPv6. Technics like
NAT64 and DNS64 are introduced. The requirements to software and especially
drivers to work in IPv6 environments are described. Also the problems to switch
from IPv4 to IPv6-only in heterogeneous networks are addressed.
Yesterday, Cisco released a number of security advisories. Three of the
advisories originated from research performed by us for the Cisco Nexus 9000
Series Fabric Switches / Cisco Application Centric Infrastructure (ACI).
More specifically, these advisories are the following:
This blogpost contains summaries of talks from this year’s
TROOPERS19 Active Directory Security Track.
From Workstation to Domain Admin: Why Secure Administration Isn’t Secure and How to Fix It by Sean Metcalf
Active Directory is probably used in almost every corporation today to
administer all kinds of Authorization, Authentication and Privileges. This means
they are valuable targets for attackers, because once compromised they could do
whatever they want. This would be the worst case scenario, right? Therefore
securing AD is important and this year TROOPERS19 featured a whole track solely
for AD Security.
This blogpost contains summaries of talks from this year’s
TROOPERS19 Attack & Research Track.
VXLAN Security or Injection, and protection
The talk “VXLAN Security or Injection, and protection” was held by Henrik Lund
Kramshøj, who is the owner of Zencurity ApS, a small security company located in
Denmark.
Henrik gives an overview about lesser known VXLAN insecurities, mostly packet
spoofing.
In the end he gives advice how to protect against this attacks.
Earlier this month I attended the Digital Medical Expertise & Applications
(DMEA) 2019. The DMEA fair in Berlin (formerly conhIT) is the central platform
for digital health care as it brings together companies of health IT, academic
institutions, politics and healthcare delivery organizations in several format
such as innovation hubs and talks during congress sessions as a part of the
industry fair. I participated in a congress session about IT security in
healthcare with a talk about medical device security and common security flaws
in medical devices. Some of the aspects have also been covered in my talk at
#TR19 [1].
As promised in my
previous post, I am back
for an overview of the Troopers19 – Active Directory related talks… Videos
have been published and it’s popcorn time… So if you are into stories about
Kingdoms and Crown Jewels, grab your loved one [or a drink…] and turn the
lights down low, ’cause tonight it’s “Troopers & Chill…”
Warning: Don’t watch it all in one go… or you will start to feel some anxiety
and pain…
and then the Flying Dutchman will move to the cloud… And at that point we are
not insured anymore.
When you are working in the area of mobile security, you sooner or later receive
requests from clients asking you to test specific ‘Mobile Device Management’
(MDM) solutions which they (plan to) use, the corresponding mobile apps, as well
as different environment setups and device policy sets.
The expectations are often high, not only for the MDM solutions ability to
massively reduce the administrative workload of keeping track, updating and
managing the often hundreds or thousands of devices within a company but also
regarding the improvements towards the level of security that an MDM solution is
regularly advertised to provide.