Events

Black Hat 20 & DEFCON 25

Some of the ERNW Crew hit up Black Hat USA and DEFCON. Our own Omar Eissa even gave his first BH and DEFCON talks! See which talk we liked and what inspiration we took home.

BlackHat US 20:

ERNW´s Omar Eissa presented on Cisco Autonomic networks showing how
slides: https://www.blackhat.com/docs/us-17/wednesday/us-17-Eissa-Network-Automation-Isn’t-Your-Safe-Haven-Protocol-Analysis-And-Vulnerabilities-Of-Autonomic-Network.pdf
insinuator blogposts:
https://insinuator.net/2017/03/autonomic-network-overview/
https://insinuator.net/2017/03/autonomic-network-analysis/
https://insinuator.net/2017/04/autonomic-network-vulnerabilities/

 

BoradPWN
– Speaker: Nitay Artenstein
– Slides: https://www.blackhat.com/docs/us-17/thursday/us-17-Artenstein-Broadpwn-Remotely-Compromising-Android-And-iOS-Via-A-Bug-In-Broadcoms-Wifi-Chipsets.pdf
– Paper: https://www.blackhat.com/docs/us-17/thursday/us-17-Artenstein-Broadpwn-Remotely-Compromising-Android-And-iOS-Via-A-Bug-In-Broadcoms-Wifi-Chipsets-wp.pdf
– Broadly covered in main stream Media –> Wired article, tons of write-ups…link: https://www.wired.com/story/broadpwn-wi-fi-vulnerability-ios-android/
– Initial Blog Post: https://blog.exodusintel.com/2017/07/26/broadpwn/
– He took a deep dive into the internals of the BCM4354, 4358 and 4359 Wi-Fi chipsets and found an issue that he exploited to an extent where he created the world´s first wifi worm.
– This hits most of the mobiles users pretty hard. Affected devices are for example: Samsung Galaxy from S3 through S8, inclusive All Samsung Notes3. Nexus 5, 6, 6X and 6P, All iPhones after iPhone 5
– An infected device can be used to infect other mobile devices.
– Luckily currently there is no malware that is actively exploiting this issue.

Continue reading
Breaking, Events

Attacking BaseStations @Defcon24

Hello Guys,
back from my vacation I’d like to give you some impressions about Defcon 24 and our talk “Attacking BaseStations”. Defcon itself had a couple of great talks but was a very crowded location. Anyhow, we had a couple of great discussions with the people before and after our talk.

The talk “Attacking BaseStations” focussed on attack vectors we simulated in our lab. Besides attacking a BaseStation via Radio interface, in this talk we focussed on local and remote interfaces as introduced in “LTE vs. Darwin”. As target of evaluation one of our eNodeB’s came into play, which we purchased on the Internet. Anyhow, the talk covered the following attack scenarios:

Continue reading
Events

Reminiscing About Black Hat USA 2015

The Strip

While searching for some photos for my last blog post on Thinkst Canary I found a couple more from our recent trip to Black Hat USA and DEF CON, which I consider worth sharing. Nothing too technical, just some visual impressions and comments from my side. Let’s get it on!

Sign Up

My colleague Patrik and myself arrived one day early before the briefings and headed right to Mandalay Bay to check out the Black Hat venue and get a feel for the city. The sheer size of just everything is mind-blowing.

Continue reading
Events

Wrap-Up: A Memorable Week at Black Hat and DEFCON in Las Vegas

Information security conferences are known to be attended because of several reasons. For some it’s the technical content, for others the networking potential and for some others simply meeting old friends. Pinpointing our motives is clearly a challenging task, but the following wrap-up ought to share our personal highlights of the week we spent visiting Black Hat USA 2014 and DEFCON 22 in Las Vegas.

After somewhat 18 hours of flight, some sleep and with the beautiful scenery of perpetual clear skies above Las Vegas we began what was to be an incredible week.

Continue reading