In our presentation, we explored the security challenges of namespace-based multi-tenancy in Kubernetes. We demonstrated real-world attacks against Kubeflow, Istio, and Traefik that can break the intended isolation between namespaces and workloads. One of the highlights was demonstrating a privilege-escalation attack we discovered that allowed us to gain cluster-admin privileges.
First, a few words regarding my experience at Black Hat: for me, it was the
first time attending the conference and then directly as a speaker. I thoroughly
enjoyed Black Hat. It took a while to get used to the size of the conference and
the vibe of Las Vegas. What was especially interesting for me was connecting
with other researchers. One thing that stood out was meeting with the team from
MSRC and putting faces to the team itself. It feels way more personal to know
who you’re talking to when you know the people handling your cases. During
TROOPERS I typically have the chance to connect with many researchers, mainly
from Europe. At Black Hat US, on the other hand, it is possible to connect more
with the US scene and meet people you haven’t seen in a long time! Seeing
familiar faces again is always nice, as opposed to putting them into your
biometric template database. One nice detail was that some international
researchers are aware of the research BSI (German: “Bundesamt für Sicherheit in
der Informationstechnik” – “German federal office for IT security”) is
facilitating. The results of our presentation stem from the “Windows Dissected”
project we are performing on behalf of the BSI.
I’ve been at Black Hat Vegas last week and in the following I’ll shortly discuss
some talks I’ve attended and which I found interesting.
Gabriele Fisher &
Luke Valenta: Monsters in the Middleboxes.
Building Tools for Detecting HTTPS Interception
This talk was about identifying if inbound HTTPS traffic reaching a server had
been intercepted by a middlebox (or
its software equivalent which is usually called “middleware”, a prominent
example being the Lenovo Superfish piece a few years ago) on its path.
Given the
CfP for Black Hat US in
Vegas ends in a few days – and as
apparently somepeople have
already started to think about their TR18 submissions – I’ll quickly provide
some loose recommendations on how to write a submission here. There’s quite some
reasonable advice out there already (the BH CfP site lists
this
and
this which
you should both read as well) but some of you might find it useful to get (yet)
another perspective.
A few months ago I had the opportunity to visit this year’s Black Hat in Las
Vegas. Due to a few weeks of vacation following the conference here are my
delayed 2 cents (part 1)
Just a few days ago I had a blast again at this year’s Black Hat. Some of the
talks were really worth listening to, so I wanted to point them out and give a
short summary.
They had the last slot at the last day of Black Hat which resulted in a kind of
empty room, but in my opinion it was an awesome talk and I even had the pleasure
to meet these two guys at our ERNW dinner.
I won’t be in Vegas for Black Hat this year as there’s a direct conflict with
one of my kids’ birthdays, but I thought one or another reader might find it
helpful to get some inspiration as for selecting the talks to catch (not least
as there’s so many interesting ones). I hence decided to quickly write this
post.
Here’s my would-be schedule for the first day (second day to follow, maybe, in
another post), under the assumption to attend exactly one talk per slot. I could
give a longer rationale per talk than the one below, based on several (mostly
technical) factors, but this is just about providing suggestions in a brief
form.
Disclaimer: I was on the
BH guest review board this year so
I might be biased in some cases.
While searching for some photos for my
last blog post on Thinkst Canary
I found a couple more from our recent trip to
Black Hat USA and
DEF CON, which I
consider worth sharing. Nothing too technical, just some visual impressions and
comments from my side. Let’s get it on!
My colleague Patrik and myself arrived one day early before the briefings and
headed right to Mandalay Bay to check out the Black Hat venue and get a feel for
the city. The sheer size of just everything is mind-blowing.
Well, it’s a canary (these cute yellow songbirds some people have as a pet), and
its main feature is that it dies before you will.
What the hack [pun intended]? And by the way… what has this to do with IT
Security? Well… let me first quote Wikipedia on the birds:
“Canaries were once regularly used in coal mining as an early warning system.
Toxic gases such as carbon monoxide, methane or carbon dioxide in the mine
would kill the bird before affecting the miners. Signs of distress from the
bird indicated to the miners that conditions were unsafe.”
Source: https://en.wikipedia.org/wiki/Domestic_canary#Miner.27s_canary
This year’s Black Hat US saw a number of quite interesting talks in the context
of Windows or Active Directory Security. For those of you too lazy to search for
themselves 😉 and for our own Windows/AD Sec team (who couldn’t send anyone to
Vegas due to heavy project load) I’ve compiled a little list of those.
Paul Stone &
Alex Chapman: WSUSPect – Compromising the Windows
Enterprise via Windows Update
Slides here.
Whitepaper
here.
(Attention: on the BH website there’s an older this. the above link leads to the
latest one).