**Dear blog followers, TROOPERS speakers & attendees,
**we hope you’re doing fine! Today we have a couple of great things to share
with you:
TROOPERS14
Let’s start with a date. Get your calendar and mark March 17th – 21st 2014.
It’s your TROOPERS14 holidays. One week full of high-end education, workshops,
talks, reconnecting with friends, action, delicious food and one or the other
party. You know the drill – more details further down.
Due to “popular demand” and given Marc couldn’t join us
at the
IPv6 Security Summit (as
flights into FRA were canceled that day due to snow) we decided to invite him
and
Antonios Atlasis
another time, to present their knowledge, skills & voodoo in two workshops held
in Heidelberg, in late June. More details can be found
here.
See you all potentially at the Heise IPv6 Kongress, take care
just to let you know that all presentations from this year’s
TelcoSecDay
are published in the interim. (Harald [Welte] couldn’t participate as in the
morning of that day FRA airport was closed on short notice).
As a lot of people were asking for, here comes the code of your badge. All You
need to customize your badge, is a micro controller programmer, like the
Pickit (its around 30 to 40 euros) and the
build environment, MPLAB which you can get
for free. Then just
download the code and
implement your own super cool features. Let us know what you did, the best hacks
will get into the TROOPERS hall of fame (-;
We had a great day today at the
Troopers IPv6 Security Summit.
Good conversations, quite some technical discussion and a prevailing overall
will to improve actual IPv6 network security.
Here
are the slides of Antonios Atlasis’ great talk on extension headers and
these
are some of his accompanying Python/Scapy scripts. My own presentation on high
secure IPv6 networks can be found
here.
The slides of the
real-world capabilities workshop
will not be published yet as we first have to discuss some stuff with a vendor.
Juan Perez-Etchegoyen
(@jp_pereze) and
Mariano Nunez
(@marianonunezdc)
from Onapsis here, thrilled to be
troopers for the third time! In this post we want to
share with you a glimpse of what you will see regarding SAP security at this
amazing conference.
Last week we released advisories regarding several vulnerabilities affecting SAP
platforms. Some of these vulnerabilities are in fact very critical, and their
exploitation could lead to a full-compromise of the entire SAP
implementation – even by completely anonymous attackers. Following our
responsible disclosure policy, SAP released the relevant SAP Security Notes
(patches) for all these vulnerabilities a long time ago, so if you are an SAP
customer make sure you have properly implemented them!
Reverse engineering is generally thought of as using debuggers, disassemblers
and hex editors. Much as I love hex editors, IDA and staring at opcodes for the
last few years I have been focused on applying my reverse engineering
methodology to larger, composed systems. At
Troopers TelcoSec day
this year I will be presenting
Bluevoxing
which demonstrates how this approach works.
Bluevoxing
is about reverse engineering how web based “audio one time password” systems
work. Simply put audio one time password systems use a short audio file as an
authentication token. When I discovered these systems I was intrigued as
reversing them would involve a range of techniques and tools from web testing,
audio tools, signal analysis, phreaking and cryptanalysis. The disassembler
would be of no use instead I would have to employ audio tools such as audacity
and ruby-processing.
Here’s a number of updates as for upcoming
TROOPERS13.
The preliminary agenda for this year’s TelcoSecDay can be found
here.
Here‘s
the (again: preliminary) agenda of the IPv6 Security Summit.
Last, but not least we’ve included another four talks in the main conference:
======
Sergey Bratus & Travis Goodspeed: You wouldn’t share a syringe. Would you share
a USB port?
Synopsis: Previous work has shown that a USB port left unattended may be subject
to pwnage via insertion of a device that types into your command shell (e.g.
here).
Impressive attack payloads have been delivered over USB to
jailbreak PS3
and a
“smart TV“.
Not surprisingly, USB stacks started incorporating defenses such as device
registration, USB firewalls, and other protective kits. But do these protective
measures go far enough to let you safely plug in a strange thumb drive into your
laptop’s USB port?
We’re very happy to announce the third round of Troopers 2013 talks today (first
round
here,
second
here).
So much quality stuff… it seems to get (ever) better every year ;-).
Here we go:
==================
Michael Ossmann & Dominic Spill: Introducing Daisho – monitoring multiple
communication technologies at the physical layer.
Synopsis: Most communications media can be monitored and debugged at various
levels of the stack, but we believe that it is most important to examine them at
the physical layer. From there, the security of every level can be investigated
and tested. The task of monitoring physical layer communications has become
increasingly difficult as we try to squeeze more and more bandwidth out of our
links. A passive tapping circuit can be used to monitor a 100BASE-TX
connections, but no such circuit exists for 1000BASE-T networks.