Dennis and I already published blog posts about our research project dealing
with vulnerabilities in parcel tracking implementations at
DHL
and DPD. At the
Winterkongress (winter
congress) in Winterthur, Switzerland, we had the great opportunity to give a
talk about the matter. The talk was recorded and can be watched
here.
DigiGes held the Winterkongress, which
took place in Winterthur on 01.03. till 02.03.2024. The main topics are ethics,
threats, and opportunities of IT. This year, many talks looked at AI in some
way.
This is the first blog post in a series about issues we think are currently
relevant in the field of AI-Security. The intention is not to get full coverage
of the topic, but to point out things that seem practical and relevant. We will
base some of our statements on lab setups and real-life examples. The technology
that we will focus on is chat bots based on generative AI, mainly OpenAI’s
ChatGPT. Right now, this specific application of AI in the wild seems to be the
best way to demonstrate issues and pitfalls when it comes to IT security.
In 2021, ERNW collaborated with
Hochschule Mannheim for their CEP (Cyber Security
Entwicklungsprojekt) to build an auditing framework for testing operating system
configurations against security procedures. This project is part of the
education program of the university to give the students the chance to utilize
the knowledge gained throughout the first semesters in a real world project.
ERNW posed as the fictitious customer, providing a requirements document and
regular meetings with all project groups for feedback. We planned to process and
adapt the results for an open source auditing framework. Unfortunately, we were
not able to finish this project yet, but we think the students should get some
attention for their work independent from our side. So here is a short summary
of what the students created and the corresponding repositories.
Two weeks ago, I was at the c0c0n conference in
Cochin (India). This conference is quite special for at least two
considerations. At first, this is – to the best of my knowledge – one of the few
conferences which officially brings together hackers, industrials, politics, and
security forces. This is not always obvious for all these different persons to
talk together, may be due to a lack of mutual understanding ?. But for a couple
of days, all of them meet, talk, exchange, and they share mutual needs and
appropriate solutions. And this may explain the second consideration, why c0c0n
is one of the oldest cyber security conferences in India (more than 15 years).
And yes, this is the conference where police forces directly pick you up from
the gates of your plane at airport, sitting you at the back of a police car to
drive you to your hotel with emergency lights ?
I was writing some challenges for PacketWars at
TROOPERS22. One was intended to be a JWT key confusion
challenge where the public key from an RSA JWT should be recovered and used to
sign a symmetric JWT. For that, I was searching for a library vulnerable to JWT
key confusion by default and found lua-resty-jwt. The original repository by
SkyLothar is not maintained and different from the library that is installed
with the LuaRocks package manager. The investigated library is a
fork of the original repository,
maintained by cdbattags in version 0.2.3 and was downloaded more than
4.8 million times
according to LuaRocks.
This blog post is the continuation of our parcel research. We already reported
about how we broke parcel tracking at
DHL
and the disclosure process of the identified problems. As DHL is not the only
parcel service in Germany, we also investigated the other available parcel
services. In this blog post, we want to talk about DPD, also called Geopost,
which belongs to the French Post Office.
Efficient Guessing of Tracking Numbers
DPD uses the recipient’s ZIP code to unlock detailed shipment information and
additional options. After trying some ZIP codes manually, we received CAPTCHA
prompts in the web interface (more on this later).
I’m happy to announce the publication of the paper
Windows memory forensics: Identification of (malicious) modifications in memory-mapped image files
at this years DFRWS USA, and the release of the corresponding
volatility plugin.
With this research came also an update to the Ptenum family (affecting
especially the ptemalfind plugin), which makes the plugins reliable in
identifying modified pages despite memory combining, so make sure to grab the
newest version from the Github repository.
Although, more and more companies start to move their IT-Infrastructure from
on-premise to public cloud solutions like Amazon Web Services (AWS) and
Microsoft Azure, public cloud providers are not an option for every
organization. This is where private cloud platforms come into play as they give
organizations direct control over their information, can be more energy
efficient than other on-premise hosting solutions, and offer companies the
possibility to manage their data centers efficiently.
OpenStack is a widely deployed, open-source
private cloud platform many companies and universities use.
At Troopers 2023, we gave a talk on how to attack DHL parcel tracking
information based on OSINT. Since we previously had an exemplary disclosure
process about this attack with DHL, Mr. Kiehne (from DHL) joined us to provide
interesting background information and insights on how they addressed our
findings.
We want to thank DHL and especially Mr. Kiehne for sharing those insights with
us at Troopers 2023. It is the ideal case, but still not common that
organizations talk openly about their actions and views on a disclosure process.
In symmetric-key cryptography, we typically distinguish two types of encryption
schemes: block ciphers and stream ciphers. Block ciphers divide a plaintext into
blocks of a fixed size (e.g., 64 or 128 bits) and encrypt one such block of data
as a whole. Stream ciphers, on the other hand, consider the plaintext as a
continuous stream of data. The stream cipher maintains an internal state and in
each step it outputs one bit or several bits and updates its internal state. The
output bit stream is then combined with the plaintext, usually using the XOR
operation. One advantage of stream ciphers is that their resource requirements
are lower than those of block ciphers in many application scenarios. This makes
them particularly useful in lightweight cryptography targeting resource
constrained devices such as low-cost RFID tags.