We have the next set of selected talks being announced here. I am super excited
about the variety of applications we had this year. Here are some of the talks
we will have.
Title: From LoRa technology to deployment within Orange affiliates
Speakers: Franck L’Hereec and Albert Nguyen
Just deployed, the LoRa technology has already passed into the hands of hackers
who have analyzed the LoRaWAN protocol as well as the objects and gateways that
implement it. At Orange, Orange Labs’ security experts have therefore looked
into those issues, first to understand it better, and also ensure the network’s
deployment in optimal security conditions. Demonstration via the example of the
treatment of the security of an innovation project by Orange. During the
presentation we will present :
Our new workshop about
TLS/SSL in the enterprise
will be held for the 1st time at Troopers 2018. So I would like to take the
opportunity and post a short teaser about stuff we will cover in this workshop.
TLS/SSL is a complicated topic especially in enterprise environments due to the
fact, that
encrypted traffic should be inspected e.g. for malware
customers/users must be able to use important applications
crypto attacks are complex and sometimes considered to be only a problem in
theory
the internal CERT wants to have every issue fixed, if feasible or not 😉
impact of configuration changes can not be foreseen
Software inventory is incomplete (do you want to make a bet that Heartbleed is
fixed completely in your environment ;-)? )
… and so forth
In the workshop we will cover all these points, discuss them and share our
experience regarding feasibility and useful mitigating controls. We will explain
the most common SSL vulnerabilities/attacks, demonstrate tools to test (and
sometimes to exploit) them, point out pitfalls and recommend what to do. Let us
have a look at one example, Heartbleed:
During years, many different researches and attacks against digital and physical
payment methods have been discussed. New security techniques and methodologies
such as tokenization process attempts to reduce or prevent fraudulent
transactions.
Extracting or capturing data from a transaction have been studied in different
ways, and some of the most common techniques are skimming, wireless skimming,
relay attacks,
traffic sniffing or
modifying a PoS(Point of Sale)
system. In our talk,
“NFC Payments: The Art of Relay & Replay Attacks”
at TROOPERS18, we will discuss a new technique and
methodology that malicious individuals could implement to extract data.
The first time I’ve heard about RFID was at high school, back in 2002, when I
was studying Electronics. Back in that time, this technology was like some sort
of black magic to me. A few years later in 2011, our government in Argentina
decided to implement a “new technology” called NFC, designed as the new and only
way of payment for the use of public transport. So, I decided to understand it
better, play with it, and try some hacks I heard from the cool people of the
CCC.
We are thrilled to announce the
Blackhoodie event at
Troopers 2018 on March 12th and 13th in Heidelberg.
This time it is going to be a 2 day workshop with various interesting topics
related to reverse engineering. We will make sure that you get some hands on
experience with reversing and more.
As always, one of the main motivation for
Blackhoodie is bringing more women into
reversing.
So we would like to see more women apply to the training slots. However, we are
open to everyone who would like to apply. We do have a very limited number of
seats at this training site. So we apologize in advance if we can’t accommodate
everyone, even though we wish we could! Please apply before “February 20th”
and we will contact you regarding next steps.
As Kai and I will be holding a
TROOPERS workshop on automation with ansible,
we needed a setup for the attendees to use ansible
against virtual machines we set up with the necessary environment. The idea was,
that every attendee has their own VMs to run ansible against, ideally including
one to run ansible from, as we want to avoid setup or version incompatibilities
if they set up their own ansible environment on their laptop. Also they should
only be able to talk to their own machines, thus avoiding conflicts because of
accidental usage of wrong IPs or host names but also simplify the setup for the
users.
At Troopers18 there will be a new special track on
Microsoft Active Directory and its security aspects, similar to the SAP security
track which we established some years ago. The AD security track will feature,
amongst others, the following talks.
Sean Metcalf: Active Directory Security. The Journey
Abstract: This talk is a journey into the challenges most organizations
encounter while trying to secure their ‘castle’. The attacker has to be right
only once, right? Not exactly. We will walk through effective security
strategies that will stymie and frustrate attackers and better protect the
Active Directory environment.
TROOPERS17 was unlike any TROOPERS we had
known before. Everything just seemed bolder, better, and beyond our
expectations. From surprise speakers like
the grugq (do you have a follow-up talk for
#TR18 by the way?) to new speakers who are now TROOPERS family, TROOPERS17 is
one for the history books!
If you were there you might be wondering to yourself, how could they possibly
top it (and if you were not there check out this
video from TR17)? Well, I am not
going to lie, it will be a challenge. However, the high quality of talk and
training submissions for this year have us feeling pretty positive about making
#TR18 the “best year ever”!
We are super excited for TROOPERS18 (March
12-16th, 2018) as are many of you! We even have this great saying that “after
TROOPERS is before TROOPERS”, which means we spend a lot of time looking
through feedback from attendees, speakers/trainers, and our own Crew for ways to
not only top what we’ve done in the years before, but also how to simply make it
better for everyone involved. Looking around at our Crew we realized how
many have either attended TROOPERS or other conferences as students. We heard
from them, as well as other students, how life changing it was to be able, as a
student, to attend an IT-Security conference. How they got to meet a speaker
whose work they’d read about in class. How people felt even more a part of the
community they were studying hard to belong to.
Given the
CfP for Black Hat US in
Vegas ends in a few days – and as
apparently somepeople have
already started to think about their TR18 submissions – I’ll quickly provide
some loose recommendations on how to write a submission here. There’s quite some
reasonable advice out there already (the BH CfP site lists
this
and
this which
you should both read as well) but some of you might find it useful to get (yet)
another perspective.