This is a guest post from Vladimir Wolstencroft, to provide some details of his
upcoming
#TR15 talk.
What do you get when you combine a security appliance vendor, a bug bounty
program, readily available virtualised machines, a lack of understanding of best
security practices and broken crypto?
Ownage, a good story and maybe even that bounty…
Focusing on Barracuda’s numerous security appliances, this talk will detail bug
hunting methods and the principles used to examine these machines:
Starting with a black box test and the challenges that this approach poses, to
decrypting the firmware, getting system root, bricking the box, fighting the
(de)activation methods, getting system root again, DOS’ing the VM host and
finally using Barracuda’s own source code to find those vulnerabilities that
otherwise would be invisible or impossible to find! There were also some
unexpected outcomes that followed…
Developing a secure and feature rich hypervisor is no easy task. Recently, the
open source Xen hypervisor was affected by two interesting vulnerabilities
involving its x86 emulation code:
XSA 110 and
XSA 105. Both bugs show that the
attack surface of hypervisors is often larger than expected. XSA 105 was
originally reported)
by Andrei Lutas from BitDefender. The patch adds missing privilege checks to the
emulation routines of several critical system instructions including LGDT and
LIDT. The vulnerable code can be reached from unprivileged user code running
inside hardware virtual machine (HVM) guests and can be used to escalate guest
privileges. XSA 110 was reported by Jan Beulich from SUSE and concerns
insufficient checks when emulating long jumps, calls or returns.
We have pretty much finalized the agenda for the
Troopers TelcoSecDay and here’s another
cool talk (the others can be found
here,
here and
here):
Rob Kuiters: On her majesty’s secret service – GRX and a Spy Agency
Synopsis: In 2013 the GPRS Roaming eXchange (GRX) was in mainstream media as
part of the high profile Edward Snowden revelations. The leaked documents
indicated that the UK government’s intelligence organisation, Government
Communications Headquarters’ (GCHQ) hacked the Belgian GRX provider, Belgacom
International Carrier Services (BICS). They did this by targeting the GRX
provider’s employees with the ultimate aim of gaining access to Belgacom’s Core
GRX routers. Allegedly, GCHQ hacked the GRX routers in order to carry out
man-in-the middle “traffic sniffing” attacks against mobile users who are
roaming with smartphones or other devices capable of handling data.
Server operating systems with an OS, for which vendor support has ended, come
with many risks that have to be considered and addressed. The primary goal
should be always to decommission or migrate the majority of end-of-life (EoL)
servers to OS versions, supported by the vendor. Here it should be noted that a
migration to an up-to-date OS should be preferably done before your organization
enters the end of life of that software 😉
in addition to those
recently announced and
these,
we’ve identified three more suitable talks for the TelcoSecDay
.
These are:
Hendrik Schmidt: Security Aspects of VoLTE
Synopsis: VoLTE is on its rise in mobile telecommunications. The service is
provided by the IP Multimedia Subsystem (IMS) which consists of a couple of
components. All those components offer new and, from an attacker’s perspective,
interesting interfaces. This talk evaluates the most interesting interfaces and
demonstrates attack vectors an attacker could abuse. This covers attacks from
customer access, Internet VoIP services and roaming exchange.
in addition to those
recently announced
we’ve identified two more suitable talks for the TelcoSecDay 😉
These are
Ravishankar Borgaonkar – TelcoSecurity Mirage: 1G to 5G
Synopsis: The evolution of the mobile networking technology from 1G to 5G is
driving the needs of our modern Digital Society. In this talk, we visit the
security pillars of these technologies and discuss if 5G can strengthen them or
not from an end-users perspective. In particular, we try to fill up security
requirements for 5G networks based on the ongoing design direction.
This is the sequel to the similar post on
“IPv6-related Requirements for the Internet Uplink or MPLS Networks“.
As mentioned there these requirements were created in the course of an RfP for
network security services. The goal of this document was to provide a check list
of IPv6-related requirements that security devices being part of the individual
providers’ offerings have to fulfill in order to fully support the future IPv6
network.
At Troopers15 there will be another
TelcoSecDay, like in the years before
(2014,
2013,
2012). Here’s the
first three talks (of overall 5-6):
Luca Bruno: Through the Looking-Glass, and What Eve Found There
Synopsis: Traditionally, network operators have provided some kind of public
read-only access to their current view of the BGP routing table, by the means of
a “looking glass”.
In this talk we inspect looking glass instances from a security point of view,
showing many shortcomings and flaws which could let a malicious entity take
control of critical devices connected to them. In particular, we will highlight
how easy it is for a low-skilled attacker to gain access to core routers within
multiple ISP infrastructures.
Similar to the documents we
released for Linux
and
Windows (and
actually inspired by a comment to the post on the Linux
guide) Antonios wrote another guide, this
time for Mac OS X.
It can
be found here.
We hope some of you might find it helpful.
Have a great day