Building

Review about the System and Security Info iOS App from SektionEins GmbH

Dear readers of Insinuator,

Today I want to give a little review about the latest app released by SektionEins called “System and Security Info” due to its recent media appearance. So first of all the app can be obtained via the Apple App store for 0,99€ at the time this article was written. This article will try to answer two basic questions: for whom (or “which groups of people”) is this app helpful, and which security features does this app actually has. The design of the app is straight forward and pretty minimalistic with a clean and modern design. The first page of the Application called “Overview” provides nothing more than the current CPU usage of the device, with detailed subdivision in User, Idle, Total and Load. The next section provides an overview about the used RAM divided into Wire, Active RAM usage, Inactive RAM usage, “other”, free and the total amount of the device’s ram. The next option shows the used and unused part of the devices available storage, with “used”, “free” and total amount of space. While these features can be handled with several other (free and open source) applications I won’t write a comment wether it  these components make sense.

Continue reading Continue reading
Events

Because of Cyber – A Recap

Troopers16 has been over for quite a while now, but because sharing is caring, we would like to give you some more insight and share some gems that happened over the 2 days of us running a small/medium sized enterprise in mid-west Russia as part of the well received FishBowl side story.

Technology wise the whole infrastructure of FishBowl, as well as the Cyber Emergency Response Team, was hosted on one FreeBSD machine with exception of the challenge scoreboard which was on site only, hence conference network only.
The C.E.R.T. web site was static web site using the jekyll engine. FishBowl on the other hand required some dynamic web magic which is why we choose to use the flask framework. For the FishBowl web design we simply helped ourselves with the styles of the Troopers web site, who of you noticed? 😉
All web related stuff was reverse proxied by an nginx to provide a common layer of technology even though every venture was segregated into its own FreeBSD jail environment.
For mail a simple postfix setup was set up. Having a proper mail server for such »shenanigans« turned out to be very enjoyable, but more on that later.

Continue reading Continue reading
Breaking

How ‘security’ black boxes might corrupt your investment

Usually I’m not the kind of guy who talks about such economic topics. Because I’m an engineer / security researcher who is exclusively concerned with understanding technical problems and if possible, solving them accordingly. My whole education is based on this and contains predominantly technical aspects of information security. This sometimes makes it difficult to understand what the market cares about (and why some products are being developed / exist on the market 😉 ). Nevertheless, a current engagement for one of our customers made me stumble upon such a product.

Continue reading Continue reading
Events

A Trip to Hannover Messe

Once every few years I decide to head to Hannover and attend Hannover Messe, probably the largest industrial trade fair in Germany and apparently on of the most important in the world. As this year’s main topic was “Industrie 4.0” I simply could not resist to go out on a hunt for new and interesting (secure) smart connected magic! And trust me, I was not disappointed – here’s a few of my impressions.

Continue reading Continue reading
Events

SAP Security @ Troopers16

When it comes to SAP, Troopers has two events that are about Security in SAP Systems in particular. On the first day of the Troopers16 Trainings the BIZEC workshop takes place. The second event is a dedicated SAP track during the conference. Apart from these events there were of course a lot of nice folks to talk to (about SAP) 🙂 This post is a short overview about SAP security @ TROOPERS16.

Continue reading Continue reading
Events

Defense & Management Day 2

TROOPERS16 offered many different speakers from around the globe. Below are three different talks from the afternoon of Day 2’s Defense and Management Track. 

===

The TROOPERS16 talk “Attacking & Protecting Big Data Environments” presented the research of Birk Kauer and Matthias Luft, (ERNW) in which they showed how enterprise-grade “big data” environments, based on e.g. HortonWorks or Cloudera, comprising of components such as HDFS, Yarn, Hue, Flume, Hive, Spark, Sentry/Ranger could be attacked. These environments typically process huge amounts of data. The data is either stored in a cluster file system or streamed into clusters. The processing of these datasets are done by jobs, and these jobs can be arbitrary code execution.

Continue reading Continue reading
Events

Infiltrate and Syscan 360

Hi everyone,

I spent the last weeks traveling to Singapore and Miami to present my Xenpwn research about double fetch vulnerabilities in paravirtualized devices at Infiltrate and Syscan360. You can find my slides here. Both conferences had great organization, very technical talks and a cool audience. In the following I want to give a short recap of some of the talks I liked the most:

Sean Heelan – Automatic Root-Cause Identification for Crashing Executions (Infiltrate)

Sean Heelan talked about his work on automated root cause analysis. The goal of this research is to give a human researcher a detailed analysis of the potential root causes (in the form of violated predicates) that triggered a crash during a fuzzing run. Sean summarizes the core idea of his research much better than I would be able to in his blog post, which also contains a link to his slides. I’m always a big fan of his talks because he is one of the few peoples working in the intersection between the academic program verification community and the IT security industry.

Continue reading Continue reading
Breaking

Discover the Unknown: Analyzing an IoT Device

This blog post will give a brief overview about how a simple IoT device can be assessed. It will show a basic methodology, what tools can be used for different tasks and how to solve problems that may arise during analyses. It is aimed at readers that are interested in how such a device can be assessed, those with general interest in reverse engineering or the ones who just want to see how to technically approach an unknown device.

Continue reading Continue reading
Events

Summary GI Sicherheit

This is a short summary of selected talks (i.e. those that I found the most interesting of those I was able to personally attend) of the GI Sicherheit 2016.

First of all, congratulations to Dr. Fabian Yamaguchi, who received an award (the GI Promotionspreis) for his PhD thesis “Pattern-Based Vulnerability Discovery“!
His work presents an “approach for identifying vulnerabilities which combines techniques from static analysis, machine learning, and graph mining to augment the analyst’s abilities rather than trying to replace her” by identifying and highlighting patterns of potential vulnerabilities in source code.

Continue reading Continue reading
Events

TSD 2016 – Follow Up

Thanks again for all the great talks and fruitful discussions @TSD 2016! I hope everybody had a safe trip home and enjoyed Troopers as we did. In the meantime I contacted all speakers to talk about publication of their slidesets. Some of them agreed (or already published them on their own) so I’d like to share these with you:

Alexandre De Oliveira – Assaulting IPX Diameter roaming network
Siddharth Rao – The known unknowns of SS7 and beyond.

Joao Collier de Mendonca – “rucki zucki” scanning tool
Harald Welte – Open Source Network Elements for Security Analysis of Mobile Networks
Ravi & Altaf Shaik – Don’t connect to my 4G base station: investigating info leaks in 4G basebands

Continue reading Continue reading