Last Friday I gave a talk at the ITSeCX in St. Pölten, Austria. The conference, hosted by the local University of Applied Sciences, has already taken place ten times. I don’t know how many people attended this time, 2014 there were about 600; I read somewhere on the net. There were four tracks and some workshops from 4pm to the conference’s end at midnight. I enjoyed the community-feeling there very much, even though I arrived late. The only talks I saw, were Adrian Dabrowski speaking about the DARPA Cyber Grand Challenge, the finals took part in Las Vegas this August, and the very entertaining end-of-year review from two UAS guys.
Continue reading Continue readingAnnouncing the first 5 talks of TROOPERS17!!!!
TROOPERS16 was packed with epic talks from around the world, an unknown evil twin brother appearing, hands-on trainings, and a legendary year for our TROOPERS Charity efforts! If you were there you might be wondering to yourself how could they possibly top it? Well, I am going to let you in on a little secret: Next year is the 10th edition of TROOPERS. One DECADE of TROOPERS, and we are pulling out all the stops! Starting with the announcement of the first 5 talks!
Continue reading Continue readingIPv6 Source Address Selection
As we all know an IPv6 enabled host can have multiple addresses. In order to select a source address for a to-be established outbound connection, operating systems implement a source address selection mechanism that evaluates multiple source address candidates and selects the (potentially) best candidate. Criteria for this selection are defined in RFC6724 (which obsoletes RFC 3484).
To find out if there are differences as for the way various OSs implement this mechanism we performed a little study whose results can be found in this whitepaper. Those differences might be particularly relevant for data center environments or enterprise networks with a variety of heterogeneous client operating systems. If interested in IPv6 in enterprise networks this training that I’ll give in some weeks might be worth attending for some of you, too.
Continue reading Continue readingTelcoSecDay 2017 – CFP Opens
For the 6th year in a row, the next TelcoSecDay will take place in 2017 on March
21th. Again, it will be held one day before
Troopers IT-Security Conference as an invitation-only
event. For those of you who don’t know the TSD, it is organized by ERNW and is
aimed at bringing researchers and people from the telecommunication industry
together to discuss about current security weaknesses, challenges and
strategies. To do so, various topics will be presented during the talks and
there will surely be enough time to follow-up in extensive discussions.
To give you an idea, here’s the
TSD 2016 agenda,
and here’s
the one of 2015.
Day-Con X Recap
Just a few days ago I had the pleasure of visiting Day-Con X. I listened to some great talks in the closed and public sessions. Since the first day was the security summit (closed session) I will just name a few titles with some brief words.
Captivating Security – Safety versus Passion (Josh More):
Was quite interesting to compare the IT-World with zoos.
Beyond Embedded (Brittany Postnikoff):
Robots are fun soon :).
IoT Insight Summit November 15, 2016
The newest addition to ERNW, ERNW Insight which now hosts TROOPERS, is launching a new concept this year. Based on the successful TROOPERS Roundtable sessions, ERNW Insight will host a series events every year covering current and relevant topics in the field of IT Security. While the style of the events may vary the in-depth knowledge sharing that you have come to know from TROOPERS will not!
The inaugural event will be our IoT Insight Summit, taking place on November 15, 2016 at the Crowne Plaza Heidelberg. This 1-day event will begin with a keynote and case study from industry experts. Afterwards, all participants will be divided into five groups of 10 persons each to participate in our “Break Out Sessions”. Every participant will get the opportunity to attend all 5 Break Out Sessions, where our IT Security moderators will lead discussions on typical problems and solutions in IoT.
Continue reading Continue readingReverse Engineering With Radare2 – Part 3
Sorry about the larger delay between the previous post and this one, but I was
very busy the last weeks.
(And the technology I wanted to show wasn’t completely implemented in radare2,
which means that I had to implement it on my own 😉 ). In case you’re new to
this series, you’ll find the previous posts
here.
As you may already know, we’ll deal with the third challenge today. The purpose
for this one is to introduce
some constructs which are often used in real programs.
A Journey Into the Depths of VoWiFi Security
T-mobile pioneered with the native seamless support for WiFi calling technology embedded within the smartphones. This integrated WiFi calling feature is adopted by most major providers as well as many smartphones today. T-mobile introduced VoWiFi in Germany in May 2016. You can make voice calls that allows to switch between LTE and WiFi networks seamlessly. This post is going to be about security analysis of Voice over WiFi (VoWiFi), another name for WiFi calling, from the user end. Before we get started, let me warn you in advance. If you are not familiar with telecommunication network protocols, then you might get lost in the heavy usage of acronyms and abbreviations. I am sorry about that. But trust me, after a while, you get used to it 🙂 .
Continue reading Continue readingA Quick Insight Into the Mirai Botnet
As you might have read,
I recently had a closer look at how easy it actually is to become part of an IoT Botnet.
To start a further discussion and share some of my findings I gave a quick
overview at the recent Dayton Security Summit. The Mirai
Botnet was supposed to be one of the case studies here. But the way things go if
one starts diving into code…I eventually gave an overview of how the Mirai Bot
actually works and what it does. As such: Here a quick summary of the Mirai
Botnet bot.
As described in my previous post,
KrebsonSecurity.com was attacked by a major DDoS attack.
Reaching between 620Gbps and 660Gbps it was the largest documented DDoS attack
so far. The attack seemingly resulted from a Botnet called Mirai. Shortly after
the attack, a
post on hackforums
claimed to contain the actual source code of just this botnet.
The source code consists of
three projects: The bot itself with its CnC server and a loader component.
Linq Injection – From Attacking Filters to Code Execution
Some of you (especially the .Net guys) might have heard of the query language Linq (Language Integrated Query) used by Microsoft .Net applications and web sites. It’s used to access data from various sources like databases, files and internal lists. It can internally transform the accessed data in application objects and provides filter mechanisms similar to SQL. As it is used directly inside the application source code, it will be processed at compile time and not interpreted at runtime. While this provides a great type safety and almost no attack surface for injection attacks (except from possible handling problems in the different backends), it is extremely difficult to implement a dynamic filter system (e.g. for datatables which should allow users to select the column to filter on). That’s probably the reason why Scott Guthrie (Executive Vice President of the Cloud and Enterprise group in Microsoft, also one of the founders of the .Net project) presented the System.Linq.Dynamic package as part of the VS-2008 samples in 2008. This library allows to build Linq queries at runtime and therefore simplify dynamic filters. But as you may know, dynamic interpretation of languages based on user input is most of the time not the best option….
Continue reading Continue reading