Today’s focus in our blog series will cover large-scale environments:
Cryptography in Cloud environments and Network Automation. Since these topics
will only become more important over time stay tuned for our
TROOPERS16’s developing agenda to see what new talks
will be available (or submit your own talk during our Call for Papers starting
in August via our new CFP Submission tool!)
“Crypto in the Cloud” talk created and given by Frederik Armknecht
Here in Heidelberg we are already gearing up for TROOPERS16 (taking place from
14th to 18th March 2016!). While you are preparing for our Call for Papers or
waiting eagerly to sign up for your spot in one of our legendary trainings take
a look at our newest blog series “Beyond the Thunderdome: A Review of
TROOPERS15”. It may offer some inspiration, help you kill time while waiting for
next year’s TROOPERS, or for those that are new to our conference, give you a
taste for what TROOPERS is all about. See you soon
at TROOPERS16!
This year’s PacketWars contest at Troopers was a
blast! Under the topic of “Connected Car” the teams faced several different
challenges, which we will describe (as a debriefing) here.
You and your krew are “freelancers” hired to identify and neutralize an unknown
threat agent who has created weaponized software and delivered it to civilian
Connected Cars via compromised EV (Electrical Vehicle) charing stations. To make
matters worse there are indications that new strains of the malware are
appearing as the “worm” spreads from car to car. The mobile mesh network created
by the Connect Car is highly resilient, allowing the malware to spread
exponentially. Time is of the essence.
Malware analysis suggests that besides a botnet module, there is an active
CANBus injection capability. There appears to be other modules but they haven’t
been properly reversed and analyzed yet.
On March 16^(th), 2015, at the Troopers
IPv6 Security Summit,
we finally released the SI6 Networks’ IPv6 Toolkit v2.0 (Guille). The
aforementioned release is now available at the
SI6 IPv6 Toolkit homepage. It is
the result of over a year of work, and includes improvements in the following
areas:
Increased portability
Bug fixes
Additional features in existing tools
Brand-new tools
Increased Portability
One of the goals that the SI6 Toolkit had since its inception is that of
portability. The SI6 Toolkit has supported all major BSD-derived OSes, Linux,
and Mac OS for a number of years now. And this new release supports yet another
new platform: OpenSolaris. We believe that besides supporting a greater user
base, increased portability ultimately results in improved code quality.
As TROOPERS15 has come to an end, I’ve finally got the time and energy to give
you a deeper insight into the TR15 badge. As most of you have probably heard
during the conference, this year’s badge was based on the
OpenPCD2. The
OpenPCD 2 is a 13.56MHz NFC Reader, Writer and Emulator under the GNU GPL v2. As
NFC is, yet again, on an uprise, a badge with NFC simply gives you the chance to
fiddle around and hack stacks of stuff in the real world. Adding some TROOPERS
spirit and a few little secrets we hope we’ve designed a pretty nice badge!
We’ve just published the videos from TROOPERS15. The playlist can be found
here.
Thanks!
again to everybody for joining us in Heidelberg. We had a great time with you 😉
Additionally to Wifi, Troopers is also offering a GSM network.
If you want to use it, simply ask your phone to scan for available mobile
networks. There you should see the usual T-Mobile D, Vodafone.de, E-Plus, O2-de
operators, but also the unusual D 23 or 262 23. Just select this one, and your
are done. You also can use the Troopers SIMs which you get on the welcome desk
on the ground floor.
Admitted, we’re a bit late this time, but here we go with the agenda of this
year’s TelcoSecDay.
Given the high number of quality contributions overall there’s more talks than
in the previous years and we’ll hence start more early (and finish later 🙂 ),
so please plan accordingly.
This is the agenda, details for the invididual talks can be found in the
respective links:
Troopers is right around the corner and as
I am responsible for the whole conference network I wanted to make sure that
everything is working as expected. I went to the venue on Friday because of two
things I wanted/needed to setup. Compared to last year’s setup we had a couple
of changes in regards to the provider connection (resulting in some changes for
our network setup). First, we now have a rather big pipe for the uplink and more
importantly (well that depends on the point of view ;)) there is a native IPv6
connection. Before that I had to tunnel all IPv6 traffic from the venue to one
of our gateways and to forward it out (as native IPv6) from there. As this step
isn’t necessary anymore, and the staff on the venue isn’t that experienced with
IPv6, I had in mind to setup and verify that IPv6 is working as desired. The
router used over there is a
Mikrotek Routerboard. As I haven’t
worked with these devices before, I was curious whether everything works as it
should ;).
Last year,
during the
IPv6 Security Summit
of Troopers 14 I had the
pleasure to present publicly, for first time, my IPv6 Penetration Testing /
Security Assessment framework called
Chiron, while later, it was also
presented at Brucon 14 as part of the 5×5
project. This year, I am returning back to the place where it all started,
to the beautiful city of Heidelberg to give another workshop about Chiron at
the
IPv6 Security Summit
of Troopers 15. But, is it just another
workshop with the known Chiron features or has something changed?
I would say a lot :). The most significant enhancements are described below.