At the Troopers 16 Casey Smith has given a talk about the gap in Application
Whitelisting.
Application Whitelisting is a technique that should prevent malware and
unauthorized applications from running. Broadly speaking this is implemented by
deciding if an application is trusted or not before executing it. Casey’s talk
gave an understanding where this whitelisiting fails down.
In his introduction about the architecture he reminded us: There is no perfect
defense. It is important to understand how the defenses work and where they
fail. In the difference to exploits, which can be patched, there is no
possibility to patch architecture flaws.
In their talk
“Reverse Engineering a Digital Two Way Radio”
Travis Goodspeed and Christiane Ruetten presented the challenges they faced and
overcame while reverse engineering “Tytera MD380”, a handheld transceiver for
the Digital Mobile Radio (DMR) protocol.
“Tytera MD380” is based around two chips: STM32F405 CPU with an ARM Cortex M4F
core and Readout Device Protection and a HRC5000 baseband processor which
implements the actual digital radio. While STM32F405 is fully documented, there
is no documentation for HRC5000 publicly available but with the help of the
Chinese community they were able to obtain the Chinese documentation.
At the TROOPERS’15 Jacob l. Torrey held a track about LangSec-Aware Software
Development Lifecycle. He talked about programming conventions and what tools
can be used for enforcing the compliance. There is a lack of metrics to
understand what make software more secure or less secure. His main goals was to
show that LangSec has far-reaching impacts into software security and to give
the audience a framework to transform the theory into practice. A SLDC should
help to find bugs sooner in the development process and reduce defect rate in
production thereby. A lower defect rate in production does not only improve
security it also reduces costs.
Christopher talked already about our WiFi Network during the
IPv6 Security Summit
and mentioned our monitoring system (we like to call “netmon”). As there were
quite some people interested in the detailed setup and configuration, we would
like to share the details with you. This year we used a widely known frontend
called Grafana and as backend components InfluxDB and collectd. During Troopers
the monitoring system was public reachable over IPv6 and provided statistics
about Uplink Bandwidth, IP Protocol Distribution, Clients and Wireless Bands.
We just presented our Paper “Generic RAID Reassembly using Block-Level
Entropy” at the DFRWS EU 2016 digital forensics conference
(http://www.dfrws.org/). The article is about a new
approach that we developed for forensic RAID recovery. Our technique calculates
block-wise entropy all over the disks and uses generic heuristics on those to
detect all the relevant RAID parameters such as stripe size, stripe map, disk
order, and RAID type, that are needed to reassemble the RAID and make the data
accessible again for forensic investigations (or just for data recovery).
Kevin Fu is an Associate Professor at the University of Michigan where he
directs the Archimedes Center for Medical Device Security and cofounded Virta
Labs. At Troopers 16 he held a talk in the field of his research:
medical device security.
He started his talk with a brief introduction how he got started with medical
device security and how it has changed since he started. Round about ten years
ago he started dumpster diving for medical devices to investigate how they are
protected and maintained. In 2006 he held his first talk about medical device
security at the FDA. In 2008 he presented a wireless replay attack against a
pacemaker. In 2013 concerns about medical device security became more and more
mainstream when the television series homeland featured an episode where the
pacemaker of the American vice president was attacked resulting in his death.
Now, instead of dumpster diving for medical devices, he works together with
clinicians and has a lab for testing devices. The communication with clinicians
is very important for his work, so he visits hospitals with his student so that
they can learn how the process works on the inside.
The Troopers experience will never be the same without the
“IPv6 summit”. It is one of
kind of two-day special event where different security experts gather to discuss
IPv6 current challenges. It addresses different topics ranging from a broad
introduction of the IPv6 to how secure the protocol is and what the latest
standards are.
The summit is divided into 2 different tracks that run simultaneously. For the
first day on the second track, Christopher Werny and Rafael Schaefer have
carried out the first three sessions.
At times with many many digitally transmittable diseases, protection might be
more important than ever. When connecting your smartphone to a rogue charger, or
a foreign smartphone to your own laptop, you never now what will happen. You
never know what data crosses the lines. But there is help: A USB condom!
As the
Troopers 16 Badge
was a neat integrated device, we had the challenge to identify something to be
soldered for our attendees. The past has shown, that soldering rocks and all of
our attendees, all of you, really enjoy it! After some looking around and
roaming the Internet, we decided to go for a simple device, which would protect
you and your devices in a hostile world. A slim PCB, which will protect your
phone when having to connect it to some unknown charger or for situations when
“a mate” just wants to connect his/her phone to your laptop for “charging
purposes”.
Wireshark in IP version 6 workshop was a part of IPv6 summit sessions of
Troopers 16. It was held by Jeffery Carrell on the second day of IPv6 summit on
Tuesday, the 15th of March. The workshop was generally divided into two
sections: a short introduction to IPv6 and analyzing some IPv6 packets on
Wireshark.
Introduction to IPv6
IPv6 protocol was defined at the end of 1990’s, mainly to provide a huge address
pool after realizing that the world would run out of IPv4 addresses quickly. The
work on IPv6 started before the introduction of NAT and Private addressing to
IPv4, which are considered temporary solutions of IPv4 address shortage problem.
IPv6 address consists of 128 bits, divided into 8 groups called nibbles,
quibbles or hextets separated by colons. Each nibble consists of four
hexadecimal digits. The 128 bits address length provides 340 trillion trillion
trillion addresses. An IPv6 address is divided into two parts: the left part is
the network identifier while the right one is the host identifier. The default
prefix is /64 which divided the IP address into two halves. An IPv6 address
looks as follows: 2001:0db8:1010:61ab:f005:ba11:00da:11a5/64
Felix Wilhelm presented in his talk various ways to attack his new target – The
PA-500 which is produced by Palo Alto Networks.
He discovered vulnerabilities in 3 different exposed aspects of the device. The
first vulnerability occurred inside of an unauthenticated API from the
Management-Website which could only be accessed within the Admin Network. This
vulnerability was a typical off-by-one Command Injection, which could be abused
by reaching out to the API with a special client=wget Request.