In the last few years, attack techniques which fall in the categories of “Credential Theft” or “Credential Reuse” have grown into one of the biggest threats to Microsoft Windows environments. Microsoft has stated more than one time, that nearly almost all of their customers that run Active Directory have experienced “Pass-the-Hash” (PtH) attacks recently.[1] Once an attacker gains an initial foothold on a single system in the environment it takes often less than 48 hours until the entire Active Directory infrastructure is compromised. To defend against this kind of attacks, a well-planned approach is required as part of a comprehensive security architecture and operations program. As breach has to be assumed[2], this includes a preventative mitigating control strategy, where technical and organizational controls are implemented, as well as preparations against insider attacks. This is mainly achieved by partitioning the credential flow in order to firstly limit their exposure and secondly limit their usefulness if an attacker was able to get them. Although we spoke last year at Troopers 15 about “How to Efficiently Protect Active Directory from Credential Theft & Large Scale Compromise”[3], we would like to summarize exemplary later in this post Active Directory pentest findings that we classified in four categories in order to better understand what goes typically wrong and thus has to be addressed. For a better understanding of the overall security goals, we classified the findings as to belonging as a security best practice violation of the following categories:
Continue reading Continue readingWeb Hacking Special Ops Workshop @ TR16
Trooper!
You passed Hacking 1on1 with flying colors?
You evade web application firewalls as they would be opened doors?
You have successfully exploitated CVE-2015-8769?
Then it’s time for the next challenge! Follow us down the rabbit hole to the not so well known attacks against modern web applications.
At Troopers16 we will be presenting the second iteration of our WebHackingSpecialOps workshop in which more advanced techniques to break current web application technologies will be explained. On the first day there will be an introduction that gives a quick overview on the well-known attacks like SQLi, XSS and XSRF. Then attacks will be shown that build upon these “old” vectors including blind/clientside SQLi, NoSQLi and some specialties on NodeJS, the javascript based server-side runtime. Next to these technical topics several formal subjects like 3rd library handling and a guideline on how to deploy TLS in a secure way will be given. Especially the 3rd party library chapter since they have become more and more relevant, as in the near past several major vulnerabilities in such libraries were found which gave attackers the chance to break web applications that were based on these. This shows that even though developers do a great job and developer companies get familiar with secure development lifecycles, there are still problems depending on the used technologies that cannot be addressed easily. One example of such a vulnerability is the object deserialization flaw in the Apache Commons Collections library, which was discovered at the beginning of 2015 and got attention in November, when two researchers presented their talk on AppSecCali2015 and showed how easy remote code execution can be done through this kind of flaw. The details of all kind of object deserialization (as almost all current scripting/high level programming languages support this feature) will be part of our course. Next to these topics a deep-dive into current crypto algorithms, their usecases concerning webapplications and their flaws will be given. Within every part of this course several demos and hands-on exercises will be done, so every attendee will be able to apply new knowledge directly. Don’t miss this chance to improve, Trooper!
Continue reading Continue readingHacking 101 Training at TROOPERS16
This year’s Hacking 101 workshop at TROOPERS16 will give attendees an insight into the hacking techniques required for penetration testing. These techniques will cover various topics like information gathering, network mapping, vulnerability scanning, web application hacking, low-level exploitation and more.
During this workshop you will learn, step by step, a testing methodology that is applicable to the majority of scenarios. So imagine you have to assess the security of a system running on the Internet. How would you start? First, you need a good understanding about the target, including running services or related systems. Just scanning an IP will most likely not reveal a lot of information about the system. The gathered information may help you to identify communication relations of services that could include vulnerabilities. A brief understanding of the target and it’s related systems/services/applications will make scanning and identifying vulnerabilities a lot easier and more effective. Then, the last step will be the exploitation of the identified vulnerabilities, with the ultimate aim to get access to the target system and pivot to other, probably internal, systems and resources.
Continue reading Continue reading32C3 Recap – Part 2
Hello everybody and welcome to the second part of our 32C3 recap!
In case you didn’t see the first part, make sure to check it out 😉
Logjam
by **Nadia Heninger & Alex Halderman
**Video |
Slides
This talk was held by Nadia Heninger and Alex Halderman on the second day of the congress. Both work in academic and the field of cryptology. They talked about the “Logjam”-Attack they and several colleagues discovered and published in may of 2014. They started their talk by explaining how they uncovered the vulnerability which was quite interesting since Logjam was no breaking news anymore. And well it was inspired by the congress of the year before, 31C3. The research was conducted because they got curious how the NSA might be able to decrypt VPN traffic as stated by Jacob Applebaum and Laura Poitras in their “reconstructing narratives” talk.
Continue reading Continue readingTelcoSecDay – First Round of Talks
Dear all,
This year the
TelcoSecDay
will take place on March 15th. For those of you who does not know about: the
TelcoSecDay it is a sub-event of Troopers bringing
together researchers, vendors and practitioners from the telecommunication /
mobile security field.
The event is celebrating its 5th anniversary now, that’s why I’d like to say “thank you” to everybody taking part at this very great discussion round in the last few years. We always had a lot of very good feedback and interesting discussions and the increasing participation list of operators from year to year says (almost) everything!
Continue reading Continue reading5th Round of TROOPERS16 Talks Accepted
Happy 2016 everyone! We are exactly 2 months away from the start of TROOPERS16!! Speakers and Trainers across the globe are polishing (or in some cases creating) their PowerPoints to use while delivering their highly technical and entertaining talks. While we here at TR HQ are busy tweaking orders, creating challenges to boggle the mind and test your skills, and of course working on some top secret fun. 😉
#BestWeekEver
Your TROOPERS Team
Continue reading Continue readingThings to Consider When Starting Your IPv6 Deployment
Hi,
today I’m going to suspend the
“Developing an Enterprise IPv6 Security Strategy”
series for a moment and discuss some other aspects of IPv6 deployment.
We’ve been involved in a number of IPv6 projects in large organizations in the
past few years and in many of those there was a
planning phase in which several documents were created
(often these include a road map, an address concept/plan and a security
concept).
Point is: at some point it’s getting real ;-), read: IPv6 is actually enabled on
some systems. Pretty much all enterprise customers we know start(ed) their IPv6
deployment “at the perimeter”, enabling IPv6 (usually in dual-stack mode) on
some systems/services facing the Internet and/or external parties.
Unfortunately there’s a number of (seemingly small) things that can go wrong in
this phase and “little errors” made today are probably meant to stay for a long
time (in German we have the nice phrase “Nichts ist so dauerhaft wie ein
Provisorium”, and I’m sure people with an IT operations background will
understand this even without a translator…).
In this post I will hence lay out some things to consider when you enable IPv6
on perimeter elements for the first time.
32C3 Recap – Part1
Every year a group of us are happy to use the holidays to travel to Hamburg to meet other people and learn something new at the 32C3.
In this small series we’ll present you recaps of some talks we found most interesting, but you also should make sure to watch the recording of them. 😉
Beyond your cable modem – How to not do DOCSIS networks
by **Alexander Graf
**Video
Alexander Graf presents (insecurity) insights on how cable modems work and connect to the ISP.
Continue reading Continue readingAnother Perspective in Vulnerability Disclosure
As you know we (as in ERNW) are quite involved when it comes to vulnerability disclosure and we’ve tried to contribute to a discussion at several occasions, such as Reflections on Vulnerability Disclosure and ERNW Newsletter 50 Vulnerability Disclosure Reflections Case Study.
In this post I want to add (yet) another perspective, motivated by a disclosure procedure which just happened recently.
todb’s article, R7-2015-23: Comcast XFINITY Home Security System Insecure Fail Open is a well planned public forum vulnerability disclosure. The article itself is very well done: It gives credit to the researcher who discovered the vulnerability and it shows a vulnerability disclosure timeline where Rapid7 reached out to Comcast (the vendor). They even go a step further and publish the link showing the process for discovered vulnerabilities in a Rapid7 product as well as how Rapid7 handles disclosing those vulnerabilities they find in external products. For their internal disclosure process, they make sure to release a patch before “publicly announcing the vulnerability in the release notes of the update”(rapid7 disclosure).
Continue reading Continue readingSecurity Analysis of VoLTE, Part 1
Hello everybody,
this time I’d like to share some thoughts and results about our telco research
last year. We gathered a lot of information out of some projects we’d like to
share and discuss with you. The following sections also provide an idea of the
upcoming Telecommunication Security Workshop I will give with Kevin Redon at
Troopers
(click).
The workshop will be about Radio Network Security (covered by Kevin) and
security aspects of the Core Network (covered by myself), mainly focusing on
Voice over LTE (VoLTE). That’s also the topic of today’s post.