We had a great day today at the
Troopers IPv6 Security Summit.
Good conversations, quite some technical discussion and a prevailing overall
will to improve actual IPv6 network security.
Here
are the slides of Antonios Atlasis’ great talk on extension headers and
these
are some of his accompanying Python/Scapy scripts. My own presentation on high
secure IPv6 networks can be found
here.
The slides of the
real-world capabilities workshop
will not be published yet as we first have to discuss some stuff with a vendor.
Recently there has been quite some discussion about so-called neighbor cache
exhaustion (“NCE”) attacks in the IPv6 world.
This is Jeff Wheeler’s
“classic paper” on the subject, my kind-of personal networking guru
Ivan Pepelnjakblogged
about it back some time,
here‘s
a related discussion on the IPv6 hackers mailing list and in March 2012 (only
three months after the respective IETF draft’s version 0 was released) the
RFC 6583 was published, covering
various protection strategies.
Marc Heuse – who happens to give
this workshop
at the
Troopers IPv6 Security Summit next
week – just sent
this email (subject:
“Remote system freeze thanks to Kaspersky Internet Security 2013”) to the
IPv6 hackers mailing list,
describing how a system running a certain flavor of Kaspersky security products
can be remotely frozen when receiving IPv6 packets with a specific combination
of extension headers and fragmentation (which in turn can be easily generated by
his IPv6 protocol attack suite).
Yesterday I was giving two presentations about Cloud security at
the BASTA! Spring 2013 Security Day. While my presentations
covered Microsoft Azure security considerations (which also included a part of
the Cloud security approach covered in our
workshops;
slides available
here) and some
major Cloud incidents (suitable to transport different messages about Cloud
security in general ;); slides available
here), I also
saw Dominick’s very interesting
presentation
about security aspects and changes in Windows 8. Inspired by that, we hope to be
able to publish another blogpost on those aspects with regard to enterprise
environments soon — most likely we won’t find any time for it before
TROOPERS 😉
Juan Perez-Etchegoyen
(@jp_pereze) and
Mariano Nunez
(@marianonunezdc)
from Onapsis here, thrilled to be
troopers for the third time! In this post we want to
share with you a glimpse of what you will see regarding SAP security at this
amazing conference.
Last week we released advisories regarding several vulnerabilities affecting SAP
platforms. Some of these vulnerabilities are in fact very critical, and their
exploitation could lead to a full-compromise of the entire SAP
implementation – even by completely anonymous attackers. Following our
responsible disclosure policy, SAP released the relevant SAP Security Notes
(patches) for all these vulnerabilities a long time ago, so if you are an SAP
customer make sure you have properly implemented them!
Many of you have probably seen the public media coverage (e.g.
[1],
[2])
of Mandiant’s
latest report on
APT.
Just to let you know: Trooper‘s
traditional panel discussion on the first day will be on APT this year. So if
you want to discuss the topic with other practitioners from the field, join us
there.
Reverse engineering is generally thought of as using debuggers, disassemblers
and hex editors. Much as I love hex editors, IDA and staring at opcodes for the
last few years I have been focused on applying my reverse engineering
methodology to larger, composed systems. At
Troopers TelcoSec day
this year I will be presenting
Bluevoxing
which demonstrates how this approach works.
Bluevoxing
is about reverse engineering how web based “audio one time password” systems
work. Simply put audio one time password systems use a short audio file as an
authentication token. When I discovered these systems I was intrigued as
reversing them would involve a range of techniques and tools from web testing,
audio tools, signal analysis, phreaking and cryptanalysis. The disassembler
would be of no use instead I would have to employ audio tools such as audacity
and ruby-processing.
Mobile devices play an important role in the business world. Yet with increased
emphasis on the Bring Your Own Device (BYOD) model, defenses are not where they
need to be to slow the loss of valuable intellectual property.
Corporate defenses have traditionally focused on the network, the endpoints, and
not necessarily on the ecosystem of how these devices interact outside of
network sockets. Smartphones bring unique network connectivity, an array of
sensors, and can be overlooked by resources invested on IDS/IPS not being
effectively leveraged.
We are back from ShmooCon had a great time and it was a lot of fun talking to
all of you guys. Here are the
slides
of our talk. Thanks to all who made this possible, we really enjoyed being part
of this years Shmoo.