Information security conferences are known to be attended because of several
reasons. For some it’s the technical content, for others the networking
potential and for some others simply meeting old friends. Pinpointing our
motives is clearly a challenging task, but the following wrap-up ought to share
our personal highlights of the week we spent visiting Black Hat USA 2014 and
DEFCON 22 in Las Vegas.
After somewhat 18 hours of flight, some sleep and with the beautiful scenery of
perpetual clear skies above Las Vegas we began what was to be an incredible
week.
Last week we had the opportunity and pleasure to present some of our research
results at BlackHat US 2014 (besides of meeting a lot of old friends and having
a great researchers’ dinner).
Enno and Antonios gave their presentation on IDPS evasion by IPv6 Extension
Headers, described
here.
The material can be found
here: Slides,
tools (the main tool used was Chiron,
authored by Antonios) &
whitepaper.
Ayhan and me presented our results of the security analysis of Cisco’s
EnergyWise protocol. The protocol enables network-wide power monitoring and
control (ie turning servers off or on, putting phones to standby — basically
controlling the power state of all EnergyWise-enabled or PoE devices). The main
problem (besides a DoS vulnerability we found in IOS, see
official Cisco advisory)
is its PSK-based authentication model, which enables an attacker to cause
large-scale blackouts in data centers if the deployment is lacking certain
controls (for example our good old favorite, segmentation…). There will be a
longer blogpost/newsletter on this topic soon.
The material can be found
here: Slides &
tools
if you’re following this blog regularly or if you’ve ever attended an
ERNW-led workshop which included an
“architecture section” you will certainly remember the “Seven Sisters of
Infrastructure Security” stuff (used for example in
this post).
These are a number of (well, more precisely, it’s seven ;-)) fundamental
security principles which can be applied to any complex infrastructure, be that
a network, a building, an airport or the like.
As part of our upcoming
Black Hat
and
Troopers
talks we will apply those principles to some VoIP networks we (security-)
assessed and, given we won’t cover them in detail there, it might be helpful to
perform a quick refresher of them, together with an initial application to VoIP
deployments. Here we go; these are the “Seven Sisters of Infrastructure
Security”: