This blogpost contains summaries of talks from this year’s
TROOPERS19 Active Directory Security Track.
From Workstation to Domain Admin: Why Secure Administration Isn’t Secure and How to Fix It by Sean Metcalf
Active Directory is probably used in almost every corporation today to
administer all kinds of Authorization, Authentication and Privileges. This means
they are valuable targets for attackers, because once compromised they could do
whatever they want. This would be the worst case scenario, right? Therefore
securing AD is important and this year TROOPERS19 featured a whole track solely
for AD Security.
This blogpost contains summaries of talks from this year’s
TROOPERS19 Attack & Research Track.
VXLAN Security or Injection, and protection
The talk “VXLAN Security or Injection, and protection” was held by Henrik Lund
Kramshøj, who is the owner of Zencurity ApS, a small security company located in
Denmark.
Henrik gives an overview about lesser known VXLAN insecurities, mostly packet
spoofing.
In the end he gives advice how to protect against this attacks.
Earlier this month I attended the Digital Medical Expertise & Applications
(DMEA) 2019. The DMEA fair in Berlin (formerly conhIT) is the central platform
for digital health care as it brings together companies of health IT, academic
institutions, politics and healthcare delivery organizations in several format
such as innovation hubs and talks during congress sessions as a part of the
industry fair. I participated in a congress session about IT security in
healthcare with a talk about medical device security and common security flaws
in medical devices. Some of the aspects have also been covered in my talk at
#TR19 [1].
As promised in my
previous post, I am back
for an overview of the Troopers19 – Active Directory related talks… Videos
have been published and it’s popcorn time… So if you are into stories about
Kingdoms and Crown Jewels, grab your loved one [or a drink…] and turn the
lights down low, ’cause tonight it’s “Troopers & Chill…”
Warning: Don’t watch it all in one go… or you will start to feel some anxiety
and pain…
and then the Flying Dutchman will move to the cloud… And at that point we are
not insured anymore.
When you are working in the area of mobile security, you sooner or later receive
requests from clients asking you to test specific ‘Mobile Device Management’
(MDM) solutions which they (plan to) use, the corresponding mobile apps, as well
as different environment setups and device policy sets.
The expectations are often high, not only for the MDM solutions ability to
massively reduce the administrative workload of keeping track, updating and
managing the often hundreds or thousands of devices within a company but also
regarding the improvements towards the level of security that an MDM solution is
regularly advertised to provide.
Sadly, TROOPERS 19 is already over. I had great fun meeting all of you, helping
you with your badge problems and seeing others hacking on their badges for
example to get custom images on there.
With this year’s badge we wanted to give you something you can reuse after the
conference, learn new things new build something on your own.
As promised in our talk Jeff and
I would like to give you a short introduction into the badge internals. Along
with this post we will release the source code for the badge firmware, the
provisioning server and the schematics for the PCB.
We’re happy to announce that some fine folks of ERNW will be present at the
upcoming ISH Conference.
The next generation IT security training facility for all industries and any
institution that manages complex infrastructure invites you to join the first
ISH Conference about threats, prevention and response in Information Security on
May 6th– 9th, 2019.
The event consists of two days of conference and two days of training with
insights and shared knowledge by world leading experts at the Information
Security Hub (ISH) Munich Airport.
Learn and discuss the newest threats and solutions with world-renowned experts
like Eugene Kaspersky, Adam Meyer, Adrian Nish and others.
When I got home last weekend after an awesome week at
WEareTROOPERS, my 5yr old asked me what
actually happened in Heidelberg…
I told him we were meeting with some people from all over the world to talk
about computer security, and he asked me if it was “to stop the bad guys, like
super-heroes?”. So I told him “yes, kind of…”, and he decided he would take his
new Troopers T-Shirt to school on Monday to show his classmates. Kids are truly
amazing… [<3 <3 <3]
We have the most amazing trainers this year lined up for Blackhoodie at
Troopers 2019. We have Thais,
Silvia, Lisa
and Ninon going to give workshops on various
interesting topics! Below are some of the workshop contents:
64-bit shellcoding and introduction to buffer overflow exploitation on Linux by Silvia Väli
64-bit shellcoding and introduction to buffer overflow exploitation on Linux is
a 3 hour workshop which is essentially divided into 3 parts:
Introduction to 64-bit architecture in order to get familiar with registers,
stack, calling conventions described in the Intel 64 (x86-64) architecture
manual and the most common assembly instructions and syscalls which we will
later use to write our shellcodes.
Shellcoding where we try different techniques to write the shellcode and of
course you gonna get to greet the shellcoding world with your own Hello
World shellcode in addition to reverse shell which we will use later on in
part 3
Introduction to buffer overflows, so you can put your newly received
know-how about stack into practise right away. Shellcode without being used
is a wasted shellcode! Part 3 ends with a buffer overflow challenge where
your goal is to use your reverse shellcode to get a connection back to your
machine.
We’re regularly asked to review IPv6 address plans from different organizations
and I’d like to share some reflections from such a process currently happening.
I’ve discussed a few aspects of IPv6 address planning before; those readers
interested please see
this post which
contains some references.
The organization in question is headquartered in Germany, has ~60K employees and
a number of subsidiaries in European countries. They belong to a “traditional
industry sector” (so they’re not an “Internet company”, even though they – as
the majority of large organizations right now – strive to be one in a few years
;-).