Some of us had the pleasure to visit this year’s REcon in
Montreal, Canada. Unfortunately, work caught us just when we arrived back in
Germany, so I haven’t had time to sit down and write down a few words so far.
However, we think that what we’ve experienced at REcon is worth writing about.
The overall quality of the speakers and talks were very nice. What really amazed
me was the art work of REcon:
As shown in previous blogposts we regularly work with GSM/GPRS basestations for
testing devices with cellular uplinks
or to simply run a
private network during TROOPERS.
Here the core difference between a random TROOPERS attendee and a device we want
to hack is the will to join our network, or not! While at the conference we hand
out own SIM cards which accept the TROOERPS GSM network as their “home network”
some device need to be pushed a little bit.
Every SIM card has it’s own home network, which is encoded in the fist five
(European standard) or six (North American standard) digits of its IMSI –
International Subscriber Number. The first three digits are the MCC, the Mobile
Country Code, the next two/three the MNC, Mobile Network Code. International
network overview are publicly available and for example
can be found >here<.
For instance, Germany has the MCC 262 and Vodafone Germany uses MNC 02. So a SIM
card with an IMSI starting with 26202 belongs to them.
Sticking to the settings in its own SIM card a device will always prefer to
connect to it’s own home network above all others. If the home network is not
available it will usually go for the strongest signal. To protect users from
unnecessary costs, an operator will usually add certain rules to prevent the
device from connecting to other networks in the same country. So if you’re an O2
customer in Germany, visit a shopping center and only have reception for a
T-Mobile cell, your phone will not directly jump into this network, even though
it’s the strongest signal source.
The moment, when your team leader asks you to cheat at Pokémon GO…everyone knows
it, right? No? Well, I do 😉
GPS Spoofing Setup
As I’m not a gamer, the technical part was of much more interest – that’s the
real gaming for me.
So, challenge accepted!
In the past I was often fiddling around with SDR (Software Defined Radio),
started with DVB-T sticks some years ago. When I came to ERNW in 2014 I got in
touch with
Michael Ossman’s great HackRF One for
the first time, and subsequently my thesis was based on SDR.
Jenkins is a continuous integration server, widely
used in Java environments for building automation and deployment. The project
recently disclosed an unauthenticated remote code execution vulnerability
discovered by Moritz Bechler. Depending on the development environment, a
Jenkins server can be a critical part of the infrastructure: It often creates
the application packages that later will be deployed on production application
servers. If an attacker can execute arbitrary code, s/he can easily manipulate
those packages and inject additional code. Another scenario would be that the
attacker stealing credentials, like passwords, private keys that are used for
authentication in the deployment process or similar.
This year I had the pleasure to join the guest day of BT’s SnoopCon. There were
quite a number of interesting talks throughout the day such as
Saumil Shah‘s presentation on Stegosploit
(as well as his rant about the state of information security)
Dr. Grigorios Fragkos‘ talk on airplane
security (where he presented some maybe not-so-pleasant but also some
good-to-hear facts on the security posture of airplanes)
Dominic Spill‘s demonstration of tools and
methods used to reverse engineer RF protocols
Hacker Fantastic‘s talk on how to use
the AX.25 protocol to bounce radio signals off the ISS to communicate with
systems around the world
Kostas Litovois’ and Vincent Yiu’s presentation on #WePWNise, a tool that can
be used to efficiently create malicious VBA macros (by taking EMET
configuration details into account)
Bryan Fite‘s talk on how we have to think
about Safety, Security, and Privacy in the IoT age.
I really enjoyed the talks and had a great time! Thanks to all the organizers
and speakers!
On the 8th of March SAP released the security note for a vulnerability we
reported during an assessment of a SAP landscape. The issue affects the SAP
NetWeaver Web Administration Interface. By knowing a special URL a malicious
user can acquire version information about the services enabled in the SAP
system as well as the operating system used. We wanted to share some details on
the issue.
The vulnerability is a bypass of the HTTP Basic Authorization for the
SAP Web Administration Interface.
It discloses version information about the system respectively operating system,
a brief SAP patch level overview and running services including their
corresponding ports.
In our talk
IMSEcure – Attacking VoLTE
Brian and me presented some theoretical and practical attacks against IP
Multimedia Subsystems (IMS). Some of the attacks already have been introduced in
a former
blogpost
and Ahmad
continued
with a deeper analysis of the Flooding and targeted DoS scenario. But still,
there are some open topics I’d like to continue with now. The methods I am
demonstrating here also help to get a better understanding of VoLTE/IMS and how
it is implemented on modern smartphones.
Last Friday, Brian and I were at the Area41 Security Conference. The conference
is a branch of Defcon conference and is more or less a small conference of the
Swiss hacker community. Being in a “rock music club”, the speakers presented on
a stage where usually the rock stars are performing – which gives the conference
a very special flair and an interesting atmosphere. We’ve been at the
conference to present our research
about VoLTE technology including some attack scenarios we’ve evaluated in the
past.
More on this later, let’s first talk about the conference itself.
Security Assertion Markup Language (SAML) is an XML standard for exchanging
authentication and authorization data between a Service Provider (SP) and an
Identification Provider (IdP). SAML is used in many Single Sign-On (SSO)
implementations, when a user is authenticated once by IdP to access multiple
related SPs. When a user requests to access a SP, it creates a SAML
Authentication Request and redirects the user to IdP to be authenticated
according to this authentication request. If the user is successfully
authenticated, IdP creates a SAML authentication response and sends it back to
SP through the user’s browser.
Tomorrow, I will join a meeting where I’m expected to contribute, amongst
others, to a discussion on the impact of IPv6 on threat intelligence. To prepare
for that I started putting together some thoughts & ideas on the topic, and I
even thought I might share this in a post (the one you read right now ;-), not
least to, maybe, stimulate a discussion.
I don’t know much about threat intelligence so it might happen that, at times, I
use some misguided terms or I expose a (too) naïve understanding of some
concepts. Happy to be corrected in one way or another.