This blog post is the continuation of our parcel research. We already reported
about how we broke parcel tracking at
DHL
and the disclosure process of the identified problems. As DHL is not the only
parcel service in Germany, we also investigated the other available parcel
services. In this blog post, we want to talk about DPD, also called Geopost,
which belongs to the French Post Office.
Efficient Guessing of Tracking Numbers
DPD uses the recipient’s ZIP code to unlock detailed shipment information and
additional options. After trying some ZIP codes manually, we received CAPTCHA
prompts in the web interface (more on this later).
At Troopers 2023, we gave a talk on how to attack DHL parcel tracking
information based on OSINT. Since we previously had an exemplary disclosure
process about this attack with DHL, Mr. Kiehne (from DHL) joined us to provide
interesting background information and insights on how they addressed our
findings.
We want to thank DHL and especially Mr. Kiehne for sharing those insights with
us at Troopers 2023. It is the ideal case, but still not common that
organizations talk openly about their actions and views on a disclosure process.
Today I had to give the pleasure to give a keynote at the
SIGS DC Day on the need to evaluate Cloud Service
Providers in a way that looks behind (or at least tries to) security whitepapers
and certification reports. The slides can be found
here.
I also particularly enjoyed the following two talks:
Sean O’Tool from Swisscom AG covered challenges of an infrastructure to cloud
migration. Even though he only briefly touched the topic, I enjoyed his
description of their firewalling model: Seeing that centralized firewall
operation (or more precisely, rule design and approval) is limited/challenged by
the understanding of the application, they transferred control over firewall
rule sets (beyond a basic set of infrastructure/ground rules) to the application
teams (using of features like OpenStack’s security groups, where he also talked
about limitations of those). They compensated the loss of “centralized
enforcement by a security group” with rule reviews — an approach that will
become way more relevant (and necessary) in the future.
I’m back from London where I gave a talk about security evaluation of
proprietary network protocols. I had a great time at
InfoSecurity Intelligent Defence
and BSides London, many thanks for
inviting me and giving me the opportunity to speak to so much nice people.
Find the abstract and the download link to the slides after the break.
Even in the time of Cloud-based security tools, behavior- and machine
learning-based APT detection and colorful security appliances, a lot of
vulnerabilities are still buried deep within the protocol layers. For security
researchers it is quite a challenge to find those in well documented protocols
(take SSL for an example), and when it comes to proprietary protocols, the bar
is raised even (significantly) higher. This keynote will show that there is
still an urgent need for security evaluation on (undocumented) network
protocols, discuss war stories on protocol fails, and also give an
introduction into the methodology of protocol reversing and how those protocol
fails could have been avoided.