Events

5th Round of TROOPERS16 Talks Accepted

Happy 2016 everyone! We are exactly 2 months away from the start of TROOPERS16!! Speakers and Trainers across the globe are polishing (or in some cases creating) their PowerPoints to use while delivering their highly technical and entertaining talks. While we here at TR HQ are busy tweaking orders, creating challenges to boggle the mind and test your skills, and of course working on some top secret fun. 😉

#BestWeekEver

Your TROOPERS Team

Continue reading
Events

#TR16 IPv6 Security Summit – New Talks Added

In the interim we’ve worked on the agenda of next year’s IPv6 Security Summit (for those not familiar with the event, here’s the 2015 edition and here the one of 2014), and some new talks have been added.

Rafael Schaefer: Advanced IPv6 Attacks Using Chiron. Hands-On Workshop

Outline: During the IPv6 Security Summit at Troopers 14, Chiron, an all-in-one IPv6 penetration testing framework was released publicly for first time. Since then, the advanced features of Chiron were used to discover some 0-day evasion techniques against high-end commercial and open-source Intrusion Detection / Prevention Systems. Moreover, for Troopers 15 it was enhanced with new features, like advanced MLD support and a fake DHCPv6 server, which can be combined with its other features, like the use of arbitrary Extension Headers and fragmentation to leverage really advanced attacks.
In this workshop, after a quick refreshing to the basic capabilities of Chiron, we will focus on the advanced IPv6 functionalities that the framework offers. We will not only show how to reproduce the latest published IPv6 attacks, but moreover, how you can create your own arbitrary IPv6 attacking scenarios for your own security assessments or penetration testing purposes. A lab will be set up in order not only to reproduce the presented techniques, but to also try your skills and – why not – to discover your own 0-day techniques :).

Continue reading
Events

4th Round of TROOPERS16 Talks Accepted

As we come to the end of the year we can’t help but take a moment to thank all of your who made TROOPERS15 special! It just makes us all the more pumped to kick it up a notch for TROOPERS16!! #BestWeekEver

Happy Holiday and much Joy to you in the New Year!

Your TROOPERS Team

===

Aaron Zauner: BetterCrypto: three years in
FIRST TIME TROOPERS SPEAKER

The BetterCrypto Project started out in the fall of 2013 as a collaborative community effort by systems engineers, security engineers, developers and cryptographers to build up a sound set of recommendations for strong cryptography and privacy enhancing technologies catered towards the operations community in the face of overarching wiretapping and data-mining by nation-state actors. The project has since evolved with a lot of positive feedback from the open source and operations community in general with input from various browser vendors, linux distribution security teams and researchers.

Continue reading
Events

Teaser on the TROOPERS16 Incident Analysis Workshop: Analyzing the current Spam Flood

As we are giving another round of our Incident Analysis workshop at Troopers16, we wanted to give a little sample taste what you can expect.

Table of Contents
Extracting Mail Attachments
Word Document Analysis
Static JavaScript Analysis
Dynamic JavaScript Analysis

Before we dive into the analysis, I wanted to mention that if you are going to analyze anything unknown/potentially malicious, do it in a safe environment (VM with no internet connection, in the best case on a separate physical analysis device, or at least strip all unnecessary functionality from that VM (CVE-2015-3456 is an example to answer the “why”)). Even things like looking at content with a text editor or extracting zip files should be done in the safe environment, as those tools could contain vulnerabilities.

Continue reading
Events

3rd Round of TROOPERS16 Talks Accepted

Here at TROOPERS HQ we are well into the Holiday (read TROOPERS) Spirit so we thought we would publish another round of talks! The current agenda can be found here.

Happy Holidays!

Your TROOPERS Team

===

2nd Day Keynote
FIRST TIME TROOPERS SPEAKER

Bio: Ben Zevenbergen joined the Oxford Internet Institute to pursue a DPhil on the intersection of privacy law, technology, social science, and the Internet. He runs a side project that aims to establish ethics guidelines for Internet research, as well as working in multidisciplinary teams such as the EU funded Network of Excellence in Internet Science. He has worked on legal, political and policy aspects of the information society for several years. Most recently he was a policy advisor to an MEP in the European Parliament, working on Europe’s Digital Agenda. Previously Ben worked as an ICT/IP lawyer and policy consultant in the Netherlands. Bendert holds a degree in law, specialising in Information Law.

Continue reading
Events

2nd Rounds of TROOPERS16 Talks

Here’s the second round of TROOPERS16 talks. For more information  check out our website: TROOPERS

Happy Holidays and all the best for 2016 to everybody!

Your TROOPERS Team

===

Ivan Pepelnjak: Real-life Software-Defined Security

Vendors, pundits, and industry media love to talk about Software-Defined Everything, but nothing ever changes in the enterprise world, right? Wrong. Some engineers are already solving security problems with a software-defined approach to networking and security, be it microsegmentation in NSX or OpenStack environment, building scale-out IDS clusters, or respond to DoS or intrusion events in real-time… and we’ll cover all these ideas in this fast-paced presentation

Continue reading
Events

First Talks of TROOPERS 2016 Accepted!

Here’s the first round of TROOPERS16 talks. For more information  check out our website: TROOPERS

Happy Holidays and all the best for 2016 to everybody!

Your TROOPERS Team

===
Mike Ossmann: Rapid Radio Reversing

Wireless security researchers have an unprecedented array of tools at their disposal today. Although Software Defined Radio (SDR) is the single most valuable tool for reverse engineering wireless signals, it is sometimes faster and easier to use other tools for portions of the reverse engineering process. I’ll discuss how beneficial a hybrid SDR/non-SDR approach has been to security researchers, and I’ll walk through an example of the process.

Continue reading
Events

Blog 5: Beyond the Thunderdome: <BR /> A Review of TROOPERS15

Troopers13_101     The final blog in our series “Beyond the Thunderdome: A Review of TROOPERS15” focuses Exploitation & Attacking. With the last of this series we hope we you are already fired up and inspired for what lays a head during our upcoming TROOPERS16 (March 14-18, 2016)! Can’t wait to see you there!


 

“The old is new, again. CVE20112461 is back” talk created and given by Luca Carettoni and Mauro Gentile

Continue reading
Events

Blog 4: Beyond the Thunderdome: <BR/>A Review of TROOPERS15

Blog4

We hope you are enjoying the ride as we continue our journey through IPv6. Below we have a great mix of talks, slides, and videos in this area posted below. We look forward to hosting more IPv6 (March 14^(th) & 15^(th)) talks next year at TROOPERS16!


 

“New Features of the SI6 Networks’IPv6 Toolkit” talk created and given by Fernando Gont

The IPV6 Toolkit was originally developed for UK CPNI in an effort to enhance and be able to test the current state of IPv6 security. The toolkit itself was mainly developed for security analysis and trouble shooting of IPv6 networks and implementations. It is running on a wide range of *nix based systems (this probably is considered painful to support given that low level implementation of network functions) and release under the GPL. You can directly check it out here: https://github.com/fgont/ipv6toolkit.

Continue reading
Events

Blog 3: Beyond the Thunderdome: A Review of TROOPERS15

Blog3

Welcome to the third edition of “Beyond the Thunderdome: A Review of TROOPERS15”. The focus today is on IPv6 and Data Center Networks, so kick back and enjoy the following talks and videos. And as always, check out our website www.troopers.de for details on TROOPERS16 March 14-18, 2016.


 

“Enabling and Securing IPv6 in Service Provider Networks” talk created and given by Tarko Titan

Telekom.ee had no IPv6, 8 moths ago. They deployed IPv6 in about 4 weeks and by now about 6% of all transported traffic is IPv6 traffic. Actually the 4 weeks timeframe is a bit too optimistic but more on that later. Tarko first explains the biggest problems in the network migration, which were the access network and the Customer -Provider Edge (CPE). Also Telekom Estonia doesn’t want to make a tradeoff at security in the IPv6 deployment.

Continue reading