This blogpost contains summaries of talks from this year’s
TROOPERS18 SAP Security Track.
SAP IGS : The ‘vulnerable’ forgotten component by Yvan Genuer
The Internet Graphics Server (IGS) is used to generate Web Based graphics from
the SAP Web AS. Yvan Genuer looked at the security of an ancient component with
very few public vulnerabilities available so far. In his talk he gave us
insights on the structure of the IGS, its services, and problems he had when
looking for documentation of the IGS and its components.
This is the first post discussing talks of the Active Directory Security Track
of this year’s Troopers which took place
last week in Heidelberg (like in the last nine years ;-). It featured, amongst
others, a new track focused on Microsoft AD and its security properties &
implications.
This was
the agenda.
The idea for this special track was born out of two considerations:
we had noted there’s a lot of stuff going on in the space, both on the offense
and on the defense side. And in pretty much every incident analysis & response
project we were brought in recently Active Directory played a huge role…
already in the early phase of the CfP several interesting submissions came in
(maybe due to the fact that some big guns of the field had voiced
verykindwordsinthepast)… and creating
an extra track simply relieved us from the burden to make a tough choice
between those.
As this was the first Troopers since its creation where I didn’t have any
official roles and out of personal interest (in a very distant past I happened
to be the co-author of the first German book on
Windows NT4 Security)
I decided to spend the majority of conference day 2 in the AD track. In
hindsight I’m tempted to say that the track was a huge success: brilliant talks,
pretty much always a packed room, and quite good discussions after the talks.
(yes, of course I’m biased, what makes you think that?).
Birk an me basically fully disclosed a 0day in
Squirrelmail yesterday. This is a short Q&A to
answer the most common questions about the issue to calm you all down a little
bit. 😉
What is the punchline, what do I need to know?
An attacker able to exploit this vulnerability can extract files of the server
the application is running on. This may include configuration files, log files
and additionally all files that are readable for all users on the system. This
issue is post-authentication. That means an attacker would need valid
credentials for the application to log in or needs to exploit an additional
vulnerability of which we are not aware of at this point of time.
TROOPERS has a long history of theming the conference
every year. Usually we pick a surreal topic, a fun story which we think is worth
to pick up on. Some of it starts as a crazy thought, others have been the result
of long discussions. Most of them are online, only our master piece from 2016 is
securely stored in the company’s vaults.
However, this year was different. Traveling across the globe, speaking at and
attending other conferences, connecting with our peers and the community, we
felt that 2017 was a particularly tough year for many of us, both professionally
and personally. There was this doom and gloom baseline to it.
Related to our new TROOPERS workshop
“Jump-Starting Public Cloud Security”,
this post is going to describe some relevant components which need to be taken
care of when constructing and auditing an Amazon Web Services (AWS) cloud
environment. Those include amongst others the general AWS account structure,
Identity and Access Management (IAM), Auditing and Logging (CloudTrail and
CloudWatch), Virtual Private Cloud (VPC) networks, as well as S3 buckets.
The AWS IAM service is responsible for identity and access management
(surprise!). This includes managing user accounts, defining password policies,
and – most importantly – creating, defining, and assigning groups and roles.
We have the next set of selected talks being announced here. I am super excited
about the variety of applications we had this year. Here are some of the talks
we will have.
Title: From LoRa technology to deployment within Orange affiliates
Speakers: Franck L’Hereec and Albert Nguyen
Just deployed, the LoRa technology has already passed into the hands of hackers
who have analyzed the LoRaWAN protocol as well as the objects and gateways that
implement it. At Orange, Orange Labs’ security experts have therefore looked
into those issues, first to understand it better, and also ensure the network’s
deployment in optimal security conditions. Demonstration via the example of the
treatment of the security of an innovation project by Orange. During the
presentation we will present :
In various scenarios it might be helpful or even required to have a statically
compiled version of Nmap available. This applies to e.g. scenarios where only
limited user privileges are available and installing anything to the system
might not be desirable.
For such cases I’ve started to create recipes to build such binaries. Similar
projects are already available on GitHub, but there are several reasons why I
chose to create my own tools:
ERNW has a new baby, so please say “hello” to the new ERNW SecTools GmbH ;-).
But why another ERNW company? Short answer: Because we want to contribute to
changing the way how software is built today: insecure, focused on profit and
sometimes made by people who ignore lessons from history. So how can we
contribute in this space? Start changing it ;-).
Confucius said: “The man who moves a mountain begins by carrying away small
stones” and that’s our way to go. It is not about building error free or
unbreakable software, it is about changing the way how software is built today,
about improving security and about raising the bar.
Our new workshop about
TLS/SSL in the enterprise
will be held for the 1st time at Troopers 2018. So I would like to take the
opportunity and post a short teaser about stuff we will cover in this workshop.
TLS/SSL is a complicated topic especially in enterprise environments due to the
fact, that
encrypted traffic should be inspected e.g. for malware
customers/users must be able to use important applications
crypto attacks are complex and sometimes considered to be only a problem in
theory
the internal CERT wants to have every issue fixed, if feasible or not 😉
impact of configuration changes can not be foreseen
Software inventory is incomplete (do you want to make a bet that Heartbleed is
fixed completely in your environment ;-)? )
… and so forth
In the workshop we will cover all these points, discuss them and share our
experience regarding feasibility and useful mitigating controls. We will explain
the most common SSL vulnerabilities/attacks, demonstrate tools to test (and
sometimes to exploit) them, point out pitfalls and recommend what to do. Let us
have a look at one example, Heartbleed:
During years, many different researches and attacks against digital and physical
payment methods have been discussed. New security techniques and methodologies
such as tokenization process attempts to reduce or prevent fraudulent
transactions.
Extracting or capturing data from a transaction have been studied in different
ways, and some of the most common techniques are skimming, wireless skimming,
relay attacks,
traffic sniffing or
modifying a PoS(Point of Sale)
system. In our talk,
“NFC Payments: The Art of Relay & Replay Attacks”
at TROOPERS18, we will discuss a new technique and
methodology that malicious individuals could implement to extract data.