Starting a post, in 2019, with a mention of sth being “IPv4-only” somewhat hurts
;-), but here we go. Recently Manel Rodero
from Barcelona asked me the
following question on
Twitter:
In this post I’ll try to discuss some inherent aspects of that question and ofc
I’ll try to provide a response to it, too ;-).
Let’s first think about the main IPv6-related risks (= threats put into a
context of relevance) in an “environment [that] is only IPv4”. While some of
you might scratch your heads “what IPv6 threats could there be in an IPv4
setting?” I’m tempted to scratch my head: “what could be the reasons to run an
university network without IPv6 these days, or to use BIND?” (which I have a
strong opinion on, see here or
here). But I
disgress. More seriously the main reason for the question can be broken down to:
Last week I had the pleasure to attend
Offensivecon 2019 in Berlin. The conference was
organized very well, and I liked the familial atmosphere which allowed to meet
lots of different people. Thanks to the organizers, speakers and everyone else
involved for this conference! Andreas posted a
one tweet tldr of
the first day; fuzzing is still the way to go to find bugs, and mitigations make
exploitation harder. Here are some short summaries of the talks I enjoyed.
Some years ago Christopher wrote two posts
(2016,
2015)
about the IPv6-related characteristics of the WiFi network at Cisco Live
Europe. To somewhat continue this tradition and for mere technical interest I
had a look at some properties of this year’s setting.
There were two SSIDs of interest: a dual-stacked one (“CiscoLive2019”) and one
with v6-only plus NAT64 (“CL-NAT64”). For some background on the underlying
infrastructure components you might look at this
thread
by Nicolas Darchis from the NOC or
at this tweet
from Dominik Pickhardt. Some stats on
IPv6 usage at CLEUR can be
found here.
This year we had some excellent submissions for TelcoSecDay. Here are the first
four confirmed speakers who are going to talk about the below mentioned topics:
1. Telecom protocols revisited – Not just a signalling problem – by Fredrik Söderlund
A look at the design of the currently deployed signalling protocols for core
networks, both SS7 and Diameter (legacy and LTE). Peculiar quirks and how the
design has lead to the industry sometimes failing to adhere to its own
standards.
Back from Holidays, you started the year well motivated to make the world a
safer place.
However, sitting at your desk today you realize nothing really changed since
last year, and you are surfing the web, feeling a bit blue, trying to avoid that
pile of emails waiting for you and wondering how you could gain some
visibility on your domain in order to better defend it.
No worries, emails can wait a bit longer. All you need is some fresh air and
something cool to keep your defensive mind motivated for the year, and I might
have just what you need; so put on your shoes and let me take you on a 15 minute
Cypher walk with a cool blue dog…
As some of you might recall we’ve introduced a dedicated “Active Directory
Security Track” at last year’s Troopers. For
Troopers19 we’ve expanded it to two days (as the SAP Security Track was
discontinued), and in the following I’ll provide a list of talks in the track.
Vincent Le Toux: You “try” to detect mimikatz
Abstract: This is 2019 and you still “try” to detect mimikatz. “Try”, because
after many years, this post exploitation tool continues to be successful.
As a contributor to mimikatz and also a blue team guy, I’m asking myself why
antivirus vendors are unable to catch it after many years.
How can a tool be blocked if nobody does not know what this tool is doing?
Because surprisingly, it is known only for credential collection but mimikatz is
a lot more.
To mitigate the lack of antivirus vendor, should we buy new fancy EDR tool or
try a technical approach? Apply a Framework? Rely on Compliance? Use a SIEM to
collect logs and apply correlation? In sumarry, can we detect mimikatz?
In this presentation we will try to understand why mimikatz has such power and
especially some weakness related to credential gathering and active directory
will be exposed.
“If it’s a thing, then there’s an app for it!”…We trust mobile apps to process
our bank transactions, handle our private data and set us up on romantic dates.
However, few of us care to wonder,”How (in)secure can these apps be?” Well… at
Troopers 19, you can learn how to answer this question yourself!
In our 2 day long “Hacking mobile applications” workshop, we teach how to find
security vulnerabilities in mobile apps, exploit them and defend against them.
We start from scratch, therefore no prior experience in hacking or developing
mobile apps is required. Whether you want to learn how to pentest mobile apps,
you are an app developer that fancies to secure his/her apps, or just curios,
our workshop is a jumpstart to your goal.
Windows 10 is one of the most commonly deployed operating systems at this time.
Knowledge about its components and internal working principles is highly
beneficial. Among other things, such a knowledge enables:
in-depth studies of undocumented, or poorly documented, system
functionalities;
development of performant and compatible software to monitor or extend the
activities of the operating system itself; and
analysis of security-related issues, such as persistent malware.
The “Insight into Windows Internals” training offered at TROOPERS’19 delivers
knowledge on the core components and inner working principles of Windows 10. For
example, the training provides knowledge on how Windows 10 uses virtualization
to isolate security-critical functionalities from attackers that have managed to
compromise the system. The training includes a variety of practical exercises
allowing attendees to observe first-hand the operation of Windows 10.
Hi there,
like in recent years the popular
Hacking 101 workshop
will take place on TROOPERS19, too! The workshop will give you an insight into
the hacking techniques required for penetration testing. These
techniques will cover various topics:
Information gathering
Network scanning
Web application hacking
Low-level exploitation
…and more!
During this workshop you will learn, step by step, a testing methodology
that applies to the majority of scenarios. So imagine you have to assess the
security of a system running on the Internet. How would you start? First,
you need a good understanding of the target, including running services or
related systems. Just scanning the target’s IP address will most likely not
reveal all relevant information you can get. In the information gathering step,
you will learn where you could find more relevant information than just a list
of open ports. A brief understanding of the target and it’s related
systems/services/applications will make scanning and identifying
vulnerabilities a lot easier and more effective. Then, the last step will be
the exploitation of the identified vulnerabilities, with the ultimate aim to
get access to the target system and pivot to other, probably internal,
systems and resources.
Once again Troopers will have its Windows & Linux Binary Exploitation workshop.
Its main focus are the ever-present stack-based buffer overflows still found in
software today (e.g. CVE-2018-5002, CVE-2018-1459, and CVE-2018-12897) and their
differences with regard to exploitation on Windows and Linux systems. If you
ever wanted to know the details of the exploit development process for these
systems then this workshop is for you.
After initial exercises involving the exploitation of classic stack-based buffer
overflows, modern defense mechanism such as Stack Cookies, DEP, and ASLR are
presented and analyzed for weaknesses. The participants will learn how these
defense mechanisms can be bypassed and will develop exploits targeting real
world applications such as the Foxit Reader Plugin for Firefox, Wireshark, and
nginx.