Ange Albertini is a reverse engineer and author of Corkami.
First and foremost he explained what a polyglot file is. A polyglot is a special
file that has more than one type in the same file. For example, Ange Albertini
demonstrated a polyglot which is a pdf, a pdf reader, a java executable and an
html file inside of one file. The second polyglot he demonstrated was a file
which had the characteristics that when you encrypted it with AES you get a PNG
image and if it´s encrypted with another key you will get a flash video and when
you encrypted it with DES you get a PDF document. He pointed out that a file
format is not just a sequence of byte it´s rather a computer dialect to
communicate between communities. He also highlighted that people don’t really
care about what is behind the file format they only what to use it and
communicate with other people.
Denial of Service (DoS) attacks aim to make services and systems unavailable to
legitimate users . If these attacks are performed by multiple sources at the
same time and for the same target, they are called Distributed Denial of Service
(DDoS) attacks. This talk “Imma Chargin Mah Lazer” describes different types of
(D)DoS attacks that are out in the wild and are seen on a daily basis by
different corporations. Furthermore, a multi-layered strategy to mitigate such
kinds of attacks has been presented within the talk. The speaker is Dr. Oliver
Matula, an IT security researcher at ERNW who holds a PHD degree in physics. He
presented the topic in a simple way which eases the delivery of information to
audience of different technical levels and backgrounds.
The talk “QNX: 99 Problems but a Microkernel ain’t one!” was part of the
Troopers conference in Heidelberg, 16 March 2016. The talk was done by the
researchers Alex Plaskett and Georgi Geshev from the MWR Labs. The MWR Labs is
the research department of the cyber security consultancy MWR InfoSecurity
located in the UK.
The talk provided an overview of the research on the architecture and security
systems of the QNX kernel with focus on the Blackberry 10 operating system. The
talk was divided into two parts. First Alex Plaskett gave an introduction
regarding the general structure of the QNX operation system and introduced the
main subsystems. Second Georgi Geshev presented tools and approaches to abuse
vulnerabilities in the QNX system.
At TROOPERS16, Dr. Cédric LÉVY-BENCHETON an expert in cyber security at ENISA,
the European Union Agency for Network and Information Security. Dr. Cédric
LÉVY-BENCHETON holds a presentation about cyber security of IoT (Internet of
Things) and smart cars he presents the current threats in IoT and Smart cars.
ENISA is an agency of the European Union. ENISA assists the Commission, the
Member States and, the business community in meeting the requirements of network
and information security.
The talk “unrubby: reversing without reversing” was part of the Troopers
conference in Heidelberg, 16 March 2016. The talk was done by Richo Healey, who
is currently working on the security engineering team at the Irish payment
company Stripe. Richo Healey is an experienced conference speaker. Amongst other
he has spoken at Kiwicon, DEF CON and 44con.
In his talk Richo Healey spoke about reverse engineering of Ruby software. First
he talked about existing tools and techniques to regenerate source code from
Ruby bytecode. Then he presented a new concept, which is implemented in his tool
“unrubby”.
Hope those of you who attended Troopers16 enjoyed it as much as we did! In this
post I want to summarize my
Troopers16 talk
and provide you with some details about freshly assigned CVE-2016-1542 and
CVE-2016-1543 related to BMC BladeLogic software.
To start with, BMC Software Inc. is an American company specializing in business
service management software; they develop software used for multiple functions,
including IT service management, data center automation, performance management,
virtualization lifecycle management and cloud computing management. Among other
products they have developed a BladeLogic suite that includes Database
Automation, Middleware Automation, Server Automation, and Network Automation
tools. The one under our focus was BladeLogic Server Automation (BSA).
In this article, I want to provide a concise sum-up of the (to me) most
interesting talks of this year’s DFRWS EU
(http://www.dfrws.org/2016eu/).
Eoghan Casey, one of most famous pioneers in digital forensics, and
David-Olivier Jaquet-Chiffelle, professor in police science at University of
Lausanne, gave a keynote that emphasized the need for theoretical fundamental
basis research in the field of digital forensics, which I fully agreed on, as
this was exactly what I addressed in some of my former research.
Attila Marosi works as a Senior Threat Research at Sophos Labs in Hungary. His
talk focused on vulnerable IoT devices that are exposed to the internet. His
approach was to look for vulnerable devices with low cost tools and publicly
available data.
He started his talk with the spoiler that he is not going to reveal any new
attacks nor new techniques. But newer data are more adequate and we can see the
current state of vulnerable devices connected to the internet. This means his
approach was to test the state of IoT devices like Routers, NAS and so on with
publicly available data.
PowerView does not use the built in AD cmdlets to be independent from the Remote
Server Administration Tools (RSAT)-AD PowerShell Module which is only compatible
with PowerShell 3.0+ and by default only installed on servers that have Active
Directory services roles. PowerView, however, is compatible with PowerShell 2.0
and has no outer dependencies. Furthermore, it does not require any installation
process.
The first Keynote directly after the Opening by Enno Rey was held by Ben
Zevenbergen. At the beginning he pointed out that he is not a very technical guy
rather he specialized in Information Law and a policy advisor to the European
Parliament. Before he started to dive into his Keynote he talked about some rant
story’s which happened to him while trying to make his point clear on previous
conferences and that he came in peace to Troopers ;).