after having announced the first round of Troopers
speakers
here,
we’re happy to publish the second round today 😉
Here we go:
==================
Dmitry Sklyarov – “Secure Password Managers” and “Military-Grade Encryption” on
Smartphones: Oh Really?
Abstract: The task of providing privacy and data confidentiality with mobile
applications becomes more and more important as the adoption of smartphones and
tablets grows. As a result, there are a number of vendors and applications
providing solutions to address those needs, such as password managers and file
encryption utilities for mobile devices.
During a recent penetration test, we evaluated the security of a typical
corporate employee notebook. It was to be assessed whether employees with a
default corporate user account would be able to gain administrative access and
subsequently abuse the system for attacks against a certain high value database
system. When evaluating this problem set, the first step is to find ways to
bring tools and exploit code on the system. Usually this task requires the
bypassing of the malware protection agent of the system. At some point, we
thought we figured a way to
encode
exploits and payloads in a way that would not be detected by the malware
protection solution.
In a .NET environment WCF services can use the proprietary WCF binary XML
protocol described
here.
Microsoft uses this protocol to save some time parsing the transmitted XML data.
If you have to (pen-) test such services, it would be nice to read (and modify)
the communication between (for example) clients and servers. One possibility is
Fiddler.
Fiddler’s strengths include its extensibility and its WCF binary plugins. Sadly,
these plugins can only decode and display the binary content as XML text.
One of our favorite tools for conducting penetration tests (especially, but not
only, web application tests) is
Portswiggers’s Burp Suite. Burp
allows to extend its features by writing own plugins. But because Burp is
written in Java, it only supports Java classes as plugins. Additionally, Burp
only allows to use one plugin at the same time which has to be loaded on
start-up.
Now we have written a Burp-Python proxy (called pyBurp) which adds some
features to the plugin system:
About
two months ago the Bluetooth SIG
renamed their latest standard,
which was previously known as “Bluetooth v4.0”. When version numbers get higher
and higher marketing likes to interfere and try something new. In this case:
Bluetooth Smart.
Sounds smart, but is it?
Without getting into too much detail, let me quickly quote Wikipedia to get
started:
“Cost-reduced single-mode chips, which enable highly integrated and
compact devices, feature a lightweight Link Layer providing
ultra-low power idle mode operation, simple device discovery, and
reliable point-to-multipoint data transfer with advanced power-save
and secure encrypted connections at the lowest possible cost.”
During one of our pentests in some corporate environment we were to analyze an
application-server called
Liferay. Liferay
comes with a lot of functionalities, runs on top of Apache Tomcat and includes a
nice API that makes it very easy to add components or further functionality that
are not part of the core. These (potentially selfmade) “addons” are called
“portlets” and they can be inserted in any place in the frontend.
“This document was produced jointly with the OWASP mobile security project. It
is also published as an ENISA deliverable in accordance with our work
program 2011. It is written for developers of smartphone apps as a guide to
developing secure apps. It may however also be of interest to project managers
of smartphone development projects.
today I’ll give a short preview of my newest tool, pytacle. It is simply a
little helper program to control gnuradio/airprobe/kraken/some_other_tools,
convert their input/output and to find a use able clear/cipher text combination
to break A5/1. In the end it should record, crack and decode/play a gsm phone
call with ~5 mouse clicks.
Take a look at this video:
The code is not available yet, as its not finished 😉 the recording and cracking
part are working, but the decoding doesn’t. I need to put some more time into
the code, but there isn’t much spare in that time of the year 😀
We’re delighted to provide the first announcement of talks of next year’s
Troopers edition. Looks like it’s going to be a great
event again 😉
Here we go:
==================
Andreas Wiegenstein: Real SAP Backdoors
Abstract: In the past year the number of lecture sessions with traumatizing
headlines about hacking SAP systems has dramatically risen. Their content,
however, is usually the same. Insecure implementations of algorithms, side
effects in commands, flawed business logic and designs that brilliantly miss the
point of security. In essence, security defects built into the SAP framework by
mistake.
Currently there’s
quite some discussion
ongoing why it took Apple so long to fix a
severe vulnerability in the update process
of iTunes. A severe vulnerability which could easily be exploited by means of an
automated tool called
evilgrade which can
be downloaded here (Hi
Francisco!). Just one small note here: did you know that evilgrade was first
shown and released at the 2008 edition of
Troopers? We had a number of initial releases of tools
in the last years (like
wafw00f at the
2009 edition and
VASTO at the
2010 edition) and we will
continue this fine tradition in 2012. I can already promise that some nice code
is going to be released for the first time at Troopers12…