Today I want to give a little review about the latest app released by
SektionEins called “System and Security Info” due to its recent media
appearance. So first of all the app can be obtained via the Apple App store for
0,99€ at the time this article was written. This article will try to answer two
basic questions: for whom (or “which groups of people”) is this app helpful, and
which security features does this app actually has. The design of the app is
straight forward and pretty minimalistic with a clean and modern design. The
first page of the Application called “Overview” provides nothing more than the
current CPU usage of the device, with detailed subdivision in User, Idle, Total
and Load. The next section provides an overview about the used RAM divided into
Wire, Active RAM usage, Inactive RAM usage, “other”, free and the total amount
of the device’s ram. The next option shows the used and unused part of the
devices available storage, with “used”, “free” and total amount of space. While
these features can be handled with several other (free and open source)
applications I won’t write a comment wether it these components make sense.
Troopers16 has been over for quite a while now, but because sharing is caring,
we would like to give you some more insight and share some gems that happened
over the 2 days of us running a small/medium sized enterprise in mid-west Russia
as part of the well received FishBowl side story.
Technology wise the whole infrastructure of FishBowl, as well as the Cyber
Emergency Response Team, was hosted on one FreeBSD machine with exception of the
challenge scoreboard which was on site only, hence conference network only.
The C.E.R.T. web site was static web site using the jekyll
engine. FishBowl on the other hand required some dynamic web magic which is why
we choose to use the flask framework. For the
FishBowl web design we simply helped ourselves with the styles of the
Troopers web site, who of you noticed? 😉
All web related stuff was reverse proxied by an nginx to
provide a common layer of technology even though every venture was segregated
into its own FreeBSD jail environment.
For mail a simple postfix setup was set up. Having a proper mail server for such
»shenanigans« turned out to be very enjoyable, but more on that later.
Usually I’m not the kind of guy who talks about such economic topics. Because
I’m an engineer / security researcher who is exclusively concerned with
understanding technical problems and if possible, solving them accordingly. My
whole education is based on this and contains predominantly technical aspects of
information security. This sometimes makes it difficult to understand what the
market cares about (and why some products are being developed / exist on the
market 😉 ). Nevertheless, a current engagement for one of our customers made me
stumble upon such a product.
Once every few years I decide to head to Hannover and attend
Hannover Messe, probably the largest industrial
trade fair in Germany and apparently on of the most important in the world. As
this year’s main topic was “Industrie 4.0” I simply could not resist to go out
on a hunt for new and interesting (secure) smart connected magic! And trust me,
I was not disappointed – here’s a few of my impressions.
When it comes to SAP, Troopers has two events that are about Security in SAP
Systems in particular. On the first day of the Troopers16 Trainings the BIZEC
workshop takes place. The second event is a dedicated SAP track during the
conference. Apart from these events there were of course a lot of nice folks to
talk to (about SAP) 🙂 This post is a short overview about SAP security
@ TROOPERS16.
TROOPERS16 offered many different
speakers from around the globe. Below are three different talks from the
afternoon of Day 2’s Defense and Management Track.
===
The TROOPERS16 talk
“Attacking & Protecting Big Data Environments”
presented the research of Birk Kauer and Matthias Luft, (ERNW)
in which they showed how enterprise-grade “big data” environments, based on e.g.
HortonWorks or Cloudera, comprising of components such as HDFS, Yarn, Hue,
Flume, Hive, Spark, Sentry/Ranger could be attacked. These environments
typically process huge amounts of data. The data is either stored in a cluster
file system or streamed into clusters. The processing of these datasets are done
by jobs, and these jobs can be arbitrary code execution.
I spent the last weeks traveling to Singapore and Miami to present my Xenpwn
research about double fetch vulnerabilities in paravirtualized devices at
Infiltrate and Syscan360. You can find my slides
here. Both conferences had great
organization, very technical talks and a cool audience. In the following I want
to give a short recap of some of the talks I liked the most:
Sean Heelan – Automatic Root-Cause Identification for Crashing Executions (Infiltrate)
Sean Heelan talked about his work on automated root cause analysis. The goal of
this research is to give a human researcher a detailed analysis of the potential
root causes (in the form of violated predicates) that triggered a crash during a
fuzzing run. Sean summarizes the core idea of his research much better than I
would be able to in his
blog post,
which also contains a link to his slides. I’m always a big fan of his talks
because he is one of the few peoples working in the intersection between the
academic program verification community and the IT security industry.
This blog post will give a brief overview about how a simple IoT device can be
assessed. It will show a basic methodology, what tools can be used for different
tasks and how to solve problems that may arise during analyses. It is aimed at
readers that are interested in how such a device can be assessed, those with
general interest in reverse engineering or the ones who just want to see how to
technically approach an unknown device.
This is a short summary of selected talks (i.e. those that I found the most
interesting of those I was able to personally attend) of the
GI Sicherheit 2016.
First of all, congratulations to Dr. Fabian Yamaguchi, who received an award
(the GI Promotionspreis) for his PhD thesis
“Pattern-Based Vulnerability Discovery“!
His
work presents an “approach for identifying vulnerabilities which combines
techniques from static analysis, machine learning, and graph mining to augment
the analyst’s abilities rather than trying to replace her” by identifying and
highlighting patterns of potential vulnerabilities in source code.
Thanks again for all the great talks and fruitful discussions
@TSD 2016!
I hope everybody had a safe trip home and enjoyed Troopers as we did. In the
meantime I contacted all speakers to talk about publication of their slidesets.
Some of them agreed (or already published them on their own) so I’d like to
share these with you: