<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>PacketWars on Insinuator.net - Bold Statements</title>
    <link>https://insinuator.net/tags/packetwars/</link>
    <description>Recent content in PacketWars on Insinuator.net - Bold Statements</description>
    <generator>Hugo</generator>
    <language>en-us</language>
    <lastBuildDate>Wed, 04 Oct 2017 00:00:00 +0000</lastBuildDate>
    <atom:link href="https://insinuator.net/tags/packetwars/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>Daycon X1</title>
      <link>https://insinuator.net/2017/10/daycon-x1/</link>
      <pubDate>Wed, 04 Oct 2017 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2017/10/daycon-x1/</guid>
      <description>&lt;p&gt;This is my short write up on &lt;a href=&#34;http://day-con.org/styled/&#34;&gt;Daycon X1&lt;/a&gt;, 2017.  The summit was held at Dayton, the land where &lt;a href=&#34;https://en.wikipedia.org/wiki/Wright_brothers&#34;&gt;Wright brothers&lt;/a&gt; were born. Apart from being my first US trip, I also gave my first training on Hacking 101 also called the Bootcamp.&lt;/p&gt;&#xA;&lt;p&gt;The Daycon X1  bootcamp started on 18th September. Ahmad, my colleague focused on web security, network scanning and metasploit exercises. I mainly handled classes on reversing and binary exploitation along with some pcap anaylsis and network attacks. It was highly fulfilling  experience to give a workshop. Teaching is definitely the best way to learn any topic by digging deep into it.The simpler you can explain, the more clarity you have on the topic. But I must say that it was indeed exhausting by the end of three days.&lt;/p&gt;</description>
    </item>
    <item>
      <title>A Visual Guide to Day-Con 9</title>
      <link>https://insinuator.net/2015/11/a-visual-guide-to-day-con-9/</link>
      <pubDate>Mon, 09 Nov 2015 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2015/11/a-visual-guide-to-day-con-9/</guid>
      <description>&lt;h2 id=&#34;welcome-to-dayton&#34;&gt;Welcome to Dayton&lt;/h2&gt;&#xA;&lt;p&gt;In mid-October our friend Bryan Fite aka Angus Blitter invited the community for the ninth edition of &lt;a href=&#34;http://day-con.org/&#34;&gt;Day-Con&lt;/a&gt;. Bryan’s annual security summit, which we regard as the sister event of TROOPERS, is a pretty good reason to visit lovely Dayton, Ohio.&lt;/p&gt;&#xA;&lt;p&gt;&lt;a href=&#34;http://www.insinuator.net/wp-content/uploads/2015/11/IMG_2144.jpg&#34;&gt;&lt;img src=&#34;http://www.insinuator.net/wp-content/uploads/2015/11/IMG_2144.jpg&#34; alt=&#34;Day-Con Summit&#34;&gt;&lt;/a&gt;&lt;/p&gt;&#xA;&lt;p&gt;And so we did… ERNW sent in five delegates. Delegates is &lt;em&gt;Day-Con-speak&lt;/em&gt; for all attendees and speakers and such a subtle choice of wording sets the tone for the whole event. People seemed to be really focused and the roundtable-like setting during the talks (see above) provided a cozy atmosphere for in-depth expert chatting.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Troopers PacketWars 2015 – Write Up</title>
      <link>https://insinuator.net/2015/04/troopers-packetwars-2015-write-up/</link>
      <pubDate>Tue, 21 Apr 2015 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2015/04/troopers-packetwars-2015-write-up/</guid>
      <description>&lt;h1 id=&#34;hello-hackers&#34;&gt;Hello Hackers!&lt;/h1&gt;&#xA;&lt;p&gt; &lt;/p&gt;&#xA;&lt;p&gt; &lt;/p&gt;&#xA;&lt;p&gt;This year’s &lt;a href=&#34;http://www.packetwars.com&#34;&gt;PacketWars&lt;/a&gt; contest at Troopers was a blast! Under the topic of “Connected Car” the teams faced several different challenges, which we will describe (as a debriefing) here.&lt;/p&gt;&#xA;&lt;h1 id=&#34;story&#34;&gt;Story&lt;/h1&gt;&#xA;&lt;p&gt; &lt;/p&gt;&#xA;&lt;p&gt; &lt;/p&gt;&#xA;&lt;p&gt;From the &lt;a href=&#34;https://twitter.com/bryanfite&#34;&gt;Packetmaster’s&lt;/a&gt; Battle Briefing:&lt;/p&gt;&#xA;&lt;p&gt;You and your krew are “freelancers” hired to identify and neutralize an unknown threat agent who has created weaponized software and delivered it to civilian Connected Cars via compromised EV (Electrical Vehicle) charing stations. To make matters worse there are indications that new strains of the malware are appearing as the “worm” spreads from car to car. The mobile mesh network created by the Connect Car is highly resilient, allowing the malware to spread exponentially. Time is of the essence.&lt;br&gt;&#xA;Malware analysis suggests that besides a botnet module, there is an active CANBus injection capability. There appears to be other modules but they haven’t been properly reversed and analyzed yet.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Some Design Aspects of Hacking Challenges</title>
      <link>https://insinuator.net/2015/01/some-design-aspects-of-hacking-challenges/</link>
      <pubDate>Sun, 04 Jan 2015 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2015/01/some-design-aspects-of-hacking-challenges/</guid>
      <description>&lt;p&gt;We’re currently starting the preparation for the &lt;a href=&#34;https://www.troopers.de&#34;&gt;Troopers15&lt;/a&gt; &lt;a href=&#34;http://packetwars.com/&#34;&gt;PacketWars Challenge&lt;/a&gt;, and since I’ve participated in quite some CTF games and have been involved in the preparation of a number of PacketWars Battles, I thought I’d write down some thoughts on the design of hacking challenges.&lt;/p&gt;&#xA;&lt;p&gt;First of all, my experience is limited almost exclusively to attack-defend-CTFs or interactive war games (such as &lt;a href=&#34;http://packetwars.com/&#34;&gt;PacketWars&lt;/a&gt; or &lt;a href=&#34;http://en.wikipedia.org/wiki/National_Collegiate_Cyber_Defense_Competition&#34;&gt;CCDC&lt;/a&gt;). While thinking about this blogpost, I also came across several terms which are used, so I decided to give a short summary:&lt;/p&gt;</description>
    </item>
    <item>
      <title>Packetwars, Sun &amp; Skills</title>
      <link>https://insinuator.net/2011/10/packetwars-sun-skills/</link>
      <pubDate>Sun, 16 Oct 2011 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2011/10/packetwars-sun-skills/</guid>
      <description>&lt;p&gt;During the last days, some of our guys (including me) had some great days in Dayton. Rene, Christopher, Hendrik, Sergej, and me flew in to give workshops and presentations at &lt;a href=&#34;http://day-con.org/&#34; title=&#34;daycon&#34;&gt;Day-Con&lt;/a&gt; as well as to compete in the infamous &lt;a href=&#34;http://www.packetwars.com&#34;&gt;PacketWars&lt;/a&gt; game. While Day-Con is a one day event, the two days before the conference comprised workshops on &lt;a href=&#34;http://www.hmtrainingsolutions.com/en/home/85-ios-security-sichere-integration-von-iphone-a-ipad.html&#34;&gt;secure iOS integration&lt;/a&gt; (given by Rene) and &lt;a href=&#34;http://www.hmtrainingsolutions.com/en/home/91-ipv6technologie-und-integration.html&#34;&gt;IPv6 security&lt;/a&gt; (given by Christopher). Since the overall topic of the conference was trust, Rene gave a &lt;a href=&#34;http://www.ernw.de/publikationen/DayConV_ERNW_Broken_Trust_v025.pdf%20&#34;&gt;keynote&lt;/a&gt; on broken trust which was based exemplary trust analysis, development of a trust metric, and different trust factors. Those trust factors were also used in my talk about evaluation methodologies for &lt;a href=&#34;http://www.ernw.de/publikationen/do_they_deliver.pdf%20&#34;&gt;cloud service providers&lt;/a&gt; (regular followers will recognize some of the content of both talks from &lt;a href=&#34;http://www.insinuator.net/2011/10/broken-trust-part-2-applying-the-approach-to-dropbox/&#34;&gt;different&lt;/a&gt; &lt;a href=&#34;http://www.insinuator.net/2011/07/the-key-to-your-datacenter/&#34;&gt;posts&lt;/a&gt; 😉 ). There were also talks from Sergey Bratus, Graeme Neilson and Angus Blitter. While Sergey proposed a sound (not to say academic 😉 ) definition on the classification of vulnerabilities and their connection to &lt;a href=&#34;http://www.wolframalpha.com/input/?i=turing+completeness&#34;&gt;turing complete input languages&lt;/a&gt;, Angus gave an introduction to &lt;a href=&#34;http://grouper.ieee.org/groups/1901/&#34;&gt;PowerLine technologies&lt;/a&gt; and laid out, that these technologies still suffer from naive assumptions about trusted networks (he also refered to &lt;a href=&#34;http://www.blackhat.com/presentations/bh-europe-09/Rey_Mende/BlackHat-Europe-2009-Mende-Rey-All-Your-Packets-slides.pdf&#34;&gt;this&lt;/a&gt;). The day after the conference, the ERNW Allstars had to defend their championship title in PacketWars. Since the first battle was scheduled for 10AM, we had quite some time to tan in the sunny 30°C weather, recover from the conference and prepare the expected victory celebration (some of you might remember some “Champagne tradition” from &lt;a href=&#34;http://www.troopers.de&#34;&gt;Troopers&lt;/a&gt;). In face of this motivation, we rushed through the 3 battles and were able to score first place second year in a row. At this point, kudos to the two other participating teams who gave us a tough battle, especially during the reversing challenges.&lt;/p&gt;</description>
    </item>
  </channel>
</rss>
