<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Black Hat on Insinuator.net - Bold Statements</title>
    <link>https://insinuator.net/tags/black-hat/</link>
    <description>Recent content in Black Hat on Insinuator.net - Bold Statements</description>
    <generator>Hugo</generator>
    <language>en-us</language>
    <lastBuildDate>Fri, 29 Aug 2025 00:00:00 +0000</lastBuildDate>
    <atom:link href="https://insinuator.net/tags/black-hat/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>Windows Hello for Business - Faceplant: Planting Biometric Templates</title>
      <link>https://insinuator.net/2025/08/windows-hello-for-business-faceplant-planting-biometric-templates/</link>
      <pubDate>Fri, 29 Aug 2025 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2025/08/windows-hello-for-business-faceplant-planting-biometric-templates/</guid>
      <description>&lt;p&gt;We are back from Black Hat USA, where we presented our research on&#xA;&lt;a href=&#34;https://www.blackhat.com/us-25/briefings/schedule/index.html#windows-hell-no-for-business-45865&#34;&gt;Windows Hello for Business&lt;/a&gt;&#xA;(&lt;a href=&#34;http://i.blackhat.com/BH-USA-25/Presentations/US-25-David-Windows-Hello-No-for-Business-Wendsday.pdf&#34;&gt;Slides&lt;/a&gt;)&#xA;once more. In the last two blog posts, we have discussed the&#xA;&lt;a href=&#34;https://insinuator.net/2025/06/windows-hello-for-business-past-and-present-attacks/&#34;&gt;architecture of WHfB and past attacks&lt;/a&gt;,&#xA;as well as how the&#xA;&lt;a href=&#34;https://insinuator.net/2025/07/windows-hello-for-business-the-face-swap/&#34;&gt;database works and how to swap identities&lt;/a&gt; in&#xA;the database.&lt;/p&gt;&#xA;&lt;p&gt;First, a few words regarding my experience at Black Hat: for me, it was the&#xA;first time attending the conference and then directly as a speaker. I thoroughly&#xA;enjoyed Black Hat. It took a while to get used to the size of the conference and&#xA;the vibe of Las Vegas. What was especially interesting for me was connecting&#xA;with other researchers. One thing that stood out was meeting with the team from&#xA;MSRC and putting faces to the team itself. It feels way more personal to know&#xA;who you’re talking to when you know the people handling your cases. During&#xA;TROOPERS I typically have the chance to connect with many researchers, mainly&#xA;from Europe. At Black Hat US, on the other hand, it is possible to connect more&#xA;with the US scene and meet people you haven’t seen in a long time! Seeing&#xA;familiar faces again is always nice, as opposed to putting them into your&#xA;biometric template database. One nice detail was that some international&#xA;researchers are aware of the research BSI (German: “Bundesamt für Sicherheit in&#xA;der Informationstechnik” – “German federal office for IT security”) is&#xA;facilitating. The results of our presentation stem from the “Windows Dissected”&#xA;project we are performing on behalf of the BSI.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Black Hat US 2019 / Some Talks</title>
      <link>https://insinuator.net/2019/08/black-hat-us-2019-/-some-talks/</link>
      <pubDate>Tue, 13 Aug 2019 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2019/08/black-hat-us-2019-/-some-talks/</guid>
      <description>&lt;p&gt;I’ve been at Black Hat Vegas last week and in the following I’ll shortly discuss some talks I’ve attended and which I found interesting.&lt;/p&gt;&#xA;&lt;p&gt;&lt;strong&gt;&lt;a href=&#34;https://twitter.com/gabbifish&#34;&gt;Gabriele Fisher&lt;/a&gt; &amp;amp; &lt;a href=&#34;https://twitter.com/lukevalenta&#34;&gt;Luke Valenta&lt;/a&gt;: Monsters in the Middleboxes. Building Tools for Detecting HTTPS Interception&lt;/strong&gt;&lt;/p&gt;&#xA;&lt;p&gt;This talk was about identifying if inbound HTTPS traffic reaching a server had been intercepted by a &lt;a href=&#34;https://tools.ietf.org/rfc/rfc3234.txt&#34;&gt;middlebox&lt;/a&gt; (or its software equivalent which is usually called “middleware”, a prominent example being the Lenovo Superfish piece a few years ago) on its path.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Some Quick Tips for Submitting a Talk to Black Hat or TROOPERS</title>
      <link>https://insinuator.net/2017/04/some-quick-tips-for-submitting-a-talk-to-black-hat-or-troopers/</link>
      <pubDate>Sat, 01 Apr 2017 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2017/04/some-quick-tips-for-submitting-a-talk-to-black-hat-or-troopers/</guid>
      <description>&lt;p&gt;Given the &lt;a href=&#34;https://www.blackhat.com/us-17/call-for-papers.html&#34;&gt;CfP for Black Hat US&lt;/a&gt; in Vegas ends in a few days – and as apparently &lt;a href=&#34;https://twitter.com/HashtagCyber/status/846093463120678913&#34;&gt;some&lt;/a&gt; &lt;a href=&#34;https://twitter.com/christruncer/status/845213468269662209&#34;&gt;people&lt;/a&gt; have already started to think about their TR18 submissions – I’ll quickly provide some loose recommendations on how to write a submission here. There’s quite some reasonable advice out there already (the BH CfP site lists &lt;a href=&#34;https://www.helpnetsecurity.com/2016/03/30/how-to-get-your-talk-accepted-at-black-hat/&#34;&gt;this&lt;/a&gt; and &lt;a href=&#34;http://hexsec.blogspot.de/2012/12/create-good-security-cfp-responses.html&#34;&gt;this&lt;/a&gt; which you should both read as well) but some of you might find it useful to get (yet) another perspective.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Black Hat 2016 Summary Part 2.1</title>
      <link>https://insinuator.net/2016/10/black-hat-2016-summary-part-2.1/</link>
      <pubDate>Thu, 06 Oct 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/10/black-hat-2016-summary-part-2.1/</guid>
      <description>&lt;p&gt;A few months ago I had the opportunity to visit this year’s Black Hat in Las Vegas. Due to a few weeks of vacation following the conference here are my delayed 2 cents (part 1)&lt;/p&gt;&#xA;&lt;p&gt;&lt;a href=&#34;//www.blackhat.com/us-16/briefings.html#abusing-bleeding-edge-web-standards-for-appsec-glory&#34;&gt;&lt;/a&gt;&amp;mdash;bryant-zadegan-&amp;amp;-ryan-lester)&lt;a href=&#34;https://www.blackhat.com/us-16/briefings.html#abusing-bleeding-edge-web-standards-for-appsec-glory&#34;&gt;Abusing Bleeding Edge Web Standards For AppSec Glory&lt;/a&gt; – Bryant Zadegan &amp;amp; Ryan Lester (&lt;a href=&#34;https://www.blackhat.com/docs/us-16/materials/us-16-Zadegan-Abusing-Bleeding-Edge-Web-Standards-For-AppSec-Glory.pdf&#34;&gt;Slides&lt;/a&gt;)&lt;/p&gt;&#xA;&lt;p&gt;Bryant and Ryan talked about new web standards which are already implemented in parts of the current browser jungle. Namely these standard were:&lt;/p&gt;</description>
    </item>
    <item>
      <title>Black Hat 2016 Summary</title>
      <link>https://insinuator.net/2016/08/black-hat-2016-summary/</link>
      <pubDate>Tue, 09 Aug 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/08/black-hat-2016-summary/</guid>
      <description>&lt;p&gt;Just a few days ago I had a blast again at this year’s Black Hat. Some of the talks were really worth listening to, so I wanted to point them out and give a short summary.&lt;/p&gt;&#xA;&lt;p&gt; &lt;/p&gt;&#xA;&lt;p&gt;&lt;a href=&#34;https://www.blackhat.com/us-16/briefings.html#using-undocumented-cpu-behavior-to-see-into-kernel-mode-and-break-kaslr-in-the-process&#34;&gt;USING UNDOCUMENTED CPU BEHAVIOR TO SEE INTO KERNEL MODE AND BREAK KASLR IN THE PROCESS&lt;/a&gt; – Anders Fogh &amp;amp; Daniel Gruss&lt;/p&gt;&#xA;&lt;p&gt;They had the last slot at the last day of Black Hat which resulted in a kind of empty room, but in my opinion it was an awesome talk and I even had the pleasure to meet these two guys at our ERNW dinner.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Not Sure Which Talks to Attend at BHUSA?</title>
      <link>https://insinuator.net/2016/07/not-sure-which-talks-to-attend-at-bhusa/</link>
      <pubDate>Fri, 29 Jul 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/07/not-sure-which-talks-to-attend-at-bhusa/</guid>
      <description>&lt;p&gt;Hi,&lt;/p&gt;&#xA;&lt;p&gt;I won’t be in Vegas for Black Hat this year as there’s a direct conflict with one of my kids’ birthdays, but I thought one or another reader might find it helpful to get some inspiration as for selecting the talks to catch (not least as there’s so many interesting ones). I hence decided to quickly write this post.&lt;/p&gt;&#xA;&lt;p&gt;Here’s my would-be schedule for the first day (second day to follow, maybe, in another post), under the assumption to attend exactly one talk per slot. I could give a longer rationale per talk than the one below, based on several (mostly technical) factors, but this is just about providing suggestions in a brief form.&lt;br&gt;&#xA;Disclaimer: I was on the &lt;a href=&#34;https://www.blackhat.com/review-board.html&#34;&gt;BH guest review board&lt;/a&gt; this year so I might be biased in some cases.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Reminiscing About Black Hat USA 2015</title>
      <link>https://insinuator.net/2015/09/reminiscing-about-black-hat-usa-2015/</link>
      <pubDate>Mon, 21 Sep 2015 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2015/09/reminiscing-about-black-hat-usa-2015/</guid>
      <description>&lt;p&gt;&lt;a href=&#34;http://www.insinuator.net/wp-content/uploads/2015/09/IMG_0245.jpg&#34;&gt;&lt;img src=&#34;http://www.insinuator.net/wp-content/uploads/2015/09/IMG_0245.jpg&#34; alt=&#34;The Strip&#34;&gt;&lt;/a&gt;&lt;/p&gt;&#xA;&lt;p&gt;While searching for some photos for my last &lt;a href=&#34;https://www.insinuator.net/2015/09/miners-canary-revival-in-it-security/&#34;&gt;blog post on Thinkst Canary&lt;/a&gt; I found a couple more from our recent trip to &lt;a href=&#34;https://www.blackhat.com/us-15/&#34;&gt;Black Hat USA&lt;/a&gt; and &lt;a href=&#34;https://defcon.org/html/links/dc-archives/dc-23-archive.html&#34;&gt;DEF CON&lt;/a&gt;, which I consider worth sharing. Nothing too technical, just some visual impressions and comments from my side. Let’s get it on!&lt;/p&gt;&#xA;&lt;p&gt;&lt;a href=&#34;http://www.insinuator.net/wp-content/uploads/2015/09/signup.jpg&#34;&gt;&lt;img src=&#34;http://www.insinuator.net/wp-content/uploads/2015/09/signup.jpg&#34; alt=&#34;Sign Up&#34;&gt;&lt;/a&gt;&lt;/p&gt;&#xA;&lt;p&gt;My colleague Patrik and myself arrived one day early before the briefings and headed right to Mandalay Bay to check out the Black Hat venue and get a feel for the city. The sheer size of just everything is mind-blowing.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Miner’s Canary Revival in IT Security</title>
      <link>https://insinuator.net/2015/09/miners-canary-revival-in-it-security/</link>
      <pubDate>Sat, 19 Sep 2015 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2015/09/miners-canary-revival-in-it-security/</guid>
      <description>&lt;p&gt;&lt;img src=&#34;http://www.insinuator.net/wp-content/uploads/2015/09/canary_credit_to_javier_bano-300x201.jpg&#34; alt=&#34;canary_credit_to_javier_bano&#34;&gt;&lt;/p&gt;&#xA;&lt;h3 id=&#34;what-is-a-miners-canary&#34;&gt;What is a Miner’s Canary?&lt;/h3&gt;&#xA;&lt;p&gt;Well, it’s a canary (these cute yellow songbirds some people have as a pet), and its main feature is that &lt;em&gt;it dies before you will&lt;/em&gt;.&lt;/p&gt;&#xA;&lt;p&gt;What the hack [pun intended]? And by the way… what has this to do with IT Security? Well… let me first quote Wikipedia on the birds:&lt;/p&gt;&#xA;&lt;blockquote&gt;&#xA;&lt;p&gt;“Canaries were once regularly used in coal mining as an early warning system. Toxic gases such as carbon monoxide, methane or carbon dioxide in the mine would kill the bird before affecting the miners. Signs of distress from the bird indicated to the miners that conditions were unsafe.” Source: &lt;a href=&#34;https://en.wikipedia.org/wiki/Domestic_canary#Miner.27s_canary&#34;&gt;https://en.wikipedia.org/wiki/Domestic_canary#Miner.27s_canary&lt;/a&gt;&lt;/p&gt;</description>
    </item>
    <item>
      <title>Black Hat Talks &amp; Papers related to Windows/Active Directory Security</title>
      <link>https://insinuator.net/2015/08/black-hat-talks-papers-related-to-windows/active-directory-security/</link>
      <pubDate>Fri, 07 Aug 2015 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2015/08/black-hat-talks-papers-related-to-windows/active-directory-security/</guid>
      <description>&lt;p&gt;This year’s Black Hat US saw a number of quite interesting talks in the context of Windows or Active Directory Security. For those of you too lazy to search for themselves 😉 and for our own Windows/AD Sec team (who couldn’t send anyone to Vegas due to heavy project load) I’ve compiled a little list of those.&lt;/p&gt;&#xA;&lt;p&gt;&lt;a href=&#34;https://twitter.com/pdjstone&#34;&gt;Paul Stone&lt;/a&gt; &amp;amp; &lt;a href=&#34;https://twitter.com/NoxrNet&#34;&gt;Alex Chapman&lt;/a&gt;: WSUSPect – Compromising the Windows Enterprise via Windows Update&lt;br&gt;&#xA;Slides &lt;a href=&#34;https://www.blackhat.com/docs/us-15/materials/us-15-Stone-WSUSpect-Compromising-Windows-Enterprise-Via-Windows-Update.pdf&#34;&gt;here&lt;/a&gt;.&lt;br&gt;&#xA;Whitepaper &lt;a href=&#34;http://www.contextis.com/media/documents/CTX_WSUSpect_White_Paper.pdf&#34;&gt;here&lt;/a&gt;. (Attention: on the BH website there’s an older this. the above link leads to the latest one).&lt;/p&gt;</description>
    </item>
    <item>
      <title>Wrap-Up: A Memorable Week at Black Hat and DEFCON in Las Vegas</title>
      <link>https://insinuator.net/2014/08/wrap-up-a-memorable-week-at-black-hat-and-defcon-in-las-vegas/</link>
      <pubDate>Fri, 15 Aug 2014 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2014/08/wrap-up-a-memorable-week-at-black-hat-and-defcon-in-las-vegas/</guid>
      <description>&lt;p&gt;Information security conferences are known to be attended because of several reasons. For some it’s the technical content, for others the networking potential and for some others simply meeting old friends. Pinpointing our motives is clearly a challenging task, but the following wrap-up ought to share our personal highlights of the week we spent visiting Black Hat USA 2014 and DEFCON 22 in Las Vegas.&lt;/p&gt;&#xA;&lt;p&gt;After somewhat 18 hours of flight, some sleep and with the beautiful scenery of perpetual clear skies above Las Vegas we began what was to be an incredible week.&lt;/p&gt;</description>
    </item>
    <item>
      <title>ERNW @BlackHat US 2014</title>
      <link>https://insinuator.net/2014/08/ernw-@blackhat-us-2014/</link>
      <pubDate>Tue, 12 Aug 2014 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2014/08/ernw-@blackhat-us-2014/</guid>
      <description>&lt;p&gt;Last week we had the opportunity and pleasure to present some of our research results at BlackHat US 2014 (besides of meeting a lot of old friends and having a great researchers’ dinner).&lt;/p&gt;&#xA;&lt;p&gt;Enno and Antonios gave their presentation on IDPS evasion by IPv6 Extension Headers, described &lt;a href=&#34;http://www.insinuator.net/2014/08/evading-idps-by-combining-ipv6-extension-headers-and-fragmentation-features-the-story-of-my-life/&#34;&gt;here&lt;/a&gt;.&lt;/p&gt;&#xA;&lt;p&gt;The material can be found here: &lt;a href=&#34;https://www.ernw.de/download/Atlasis_Rey_BHUSA_2014_IPv6_Evasion_of_HighEnd_IPS_Devices_web.pdf&#34;&gt;Slides&lt;/a&gt;, &lt;a href=&#34;http://www.secfu.net/tools-scripts/&#34;&gt;tools&lt;/a&gt; (the main tool used was Chiron, authored by Antonios) &amp;amp; &lt;a href=&#34;https://www.ernw.de/download/us-14-Atlasis-Evasion-Of-HighEnd-IPS-Devices-In-The-Age-Of-IPv6-WP.pdf&#34;&gt;whitepaper&lt;/a&gt;.&lt;/p&gt;&#xA;&lt;p&gt;Ayhan and me presented our results of the security analysis of Cisco’s EnergyWise protocol. The protocol enables network-wide power monitoring and control (ie turning servers off or on, putting phones to standby — basically controlling the power state of all EnergyWise-enabled or PoE devices). The main problem (besides a DoS vulnerability we found in IOS, see &lt;a href=&#34;http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20140806-energywise&#34;&gt;official Cisco advisory&lt;/a&gt;) is its PSK-based authentication model, which enables an attacker to cause large-scale blackouts in data centers if the deployment is lacking certain controls (for example our good old favorite, segmentation…). There will be a longer blogpost/newsletter on this topic soon.&lt;br&gt;&#xA;The material can be found here: &lt;a href=&#34;https://www.ernw.de/download/ERNW_BHUS14_WhenTheLightsGoOut_akoca-mluft.pdf&#34;&gt;Slides&lt;/a&gt; &amp;amp; &lt;a href=&#34;https://www.ernw.de/download/tools/energywise_attack_suite_BH_US14.zip&#34;&gt;tools&lt;/a&gt;&lt;/p&gt;</description>
    </item>
    <item>
      <title>Applying the ERNW Seven Sisters Approach to VoIP Networks</title>
      <link>https://insinuator.net/2012/03/applying-the-ernw-seven-sisters-approach-to-voip-networks/</link>
      <pubDate>Sat, 03 Mar 2012 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2012/03/applying-the-ernw-seven-sisters-approach-to-voip-networks/</guid>
      <description>&lt;p&gt;Hi,&lt;/p&gt;&#xA;&lt;p&gt;if you’re following this blog regularly or if you’ve ever attended an &lt;a href=&#34;http://www.hmtrainingsolutions.com/&#34;&gt;ERNW-led workshop&lt;/a&gt; which included an “architecture section” you will certainly remember the “Seven Sisters of Infrastructure Security” stuff (used for example in &lt;a href=&#34;http://www.insinuator.net/2011/01/ipv6-security-part-1-ra-guard-the-theory-3/&#34;&gt;this post&lt;/a&gt;). These are a number of (well, more precisely, it’s seven ;-)) fundamental security principles which can be applied to any complex infrastructure, be that a network, a building, an airport or the like.&lt;/p&gt;&#xA;&lt;p&gt;As part of our upcoming &lt;a href=&#34;https://www.blackhat.com/html/bh-eu-12/bh-eu-12-briefings.html#rey&#34;&gt;Black Hat&lt;/a&gt; and &lt;a href=&#34;http://www.troopers.de/troopers12/agenda/protecting-voice-over-ip-in-2012/&#34;&gt;Troopers&lt;/a&gt; talks we will apply those principles to some VoIP networks we (security-) assessed and, given we won’t cover them in detail there, it might be helpful to perform a quick refresher of them, together with an initial application to VoIP deployments. Here we go; these are the “Seven Sisters of Infrastructure Security”:&lt;/p&gt;</description>
    </item>
  </channel>
</rss>
