**Dear blog followers, TROOPERS speakers & attendees,
**we hope you’re doing fine! Today we have a couple of great things to share
with you:
TROOPERS14
Let’s start with a date. Get your calendar and mark March 17th – 21st 2014.
It’s your TROOPERS14 holidays. One week full of high-end education, workshops,
talks, reconnecting with friends, action, delicious food and one or the other
party. You know the drill – more details further down.
After his great presentations on
IPv6 Extensions Headers
and
security problems related to fragmentation
we had invited Antonios Atlasis to Heidelberg to give
this workshop
at ERNW. It was a great experience with many fruitful discussions between the
participants (mostly security practitioners from very large organizations
planning to have their Internet edge IPv6 enabled within the next 6-12 months)
and him/us. Antonios thankfully decided to make his
slides
and
scripts
available for those interested in further research on the topics (it should be
noted that the scripts have not been tested thoroughly and he’s happy to receive
feedback of any kind at antoniosDOTatlasisDOTgmailDOTcom). Today Marc (Heuse)
gives
his workshop
on pentesting in the IPv6 age. Hopefully such events help to move things into
the right direction in the IPv6 security space…
From
15th – 17th of May, the sixth Google I/O conference took place in San Francisco,
California and I was one of the lucky guys attending. More then 5500 people,
primarily web, mobile, and enterprise developers, attended this annual event. A
lot of presentations included announcements of new and exciting technologies,
APIs as well as of two new devices.
During the first minutes of the
keynote
some of Google’s managers announced that by now over 900 million Android devices
are activated and that 48 billion apps are installed, which demonstrates that
this market is still heavily growing. As the major part of the audience were
(app-) developers, these numbers were received quite greatfully and euphoric.
In the course of a current virtualization research project, I was reviewing a
lot of documentation on hypervisor security. While “hypervisor security” is a
very wide field, hypervisor breakouts are usually one of the most (intensely)
discussed topics. I don’t want to go down the road of rating the risk of
hypervisor breakouts and giving appropriate recommendations (even though we do
this on a regular base which, surprisingly often, leads to almost religious
debates. I know I say this way too often:I’ll cover this topic in a future post
;)), but share a few observations of analyzing well-known examples of
vulnerabilities that led to guest-to-host-escape scenarios. The following table
provides an overview of the vulnerabilities in question:
Recently Jozef Pivarník and Matěj Grégr published
an
excellent write-up
on RA Guard & evasion techniques. Amongst others they tested the
“undetermined-transport” ACL we described
here
and
here.
As it turns out the “workaround” for implementing undetermined-transport on
platforms seemingly not supporting it, causes some bad collateral damage: the
respective port does not forward any IPv6 packets any more (this was brought
to my attention by Roberto Taccon). We had done some tests after applying it (by
means of the “workaround”) but we had just looked at fragmented RA packets
(which did not get through => test succeeded). So, frankly: the
undetermined-transport trick does not make sense at all on the “unsupported
platforms”…
Due to “popular demand” and given Marc couldn’t join us
at the
IPv6 Security Summit (as
flights into FRA were canceled that day due to snow) we decided to invite him
and
Antonios Atlasis
another time, to present their knowledge, skills & voodoo in two workshops held
in Heidelberg, in late June. More details can be found
here.
See you all potentially at the Heise IPv6 Kongress, take care
on the [ipv6-ops] mailing
list currently there’s some discussion about RA guard support on switches from
different vendors.
Stefan, one of our students (btw: working on a topic similar to this
session),
quickly put together a preliminary list, based on publicly available information
(read: the WWW ;-)). Some of you may find this useful; it can be found
here. Furthermore
on the list
this link
was mentioned which seems to provide some info as well (albeit potentially not
very up-to-date).
just to let you know that all presentations from this year’s
TelcoSecDay
are published in the interim. (Harald [Welte] couldn’t participate as in the
morning of that day FRA airport was closed on short notice).