The event of the events is getting closer and again, we are very optimistic to have a lot of awesome trainings, talks, evening events, and discussions. But we again will also have some “features” and gimmicks for those of you who would like to play with new, old, or just interesting technologies. As you might remember, since some years one of these features is and again will be our own GSM Network. As we are improving our setup from year to year, this time we’d like to give you the chance to actively participate with ideas and your own services.
Continue reading Continue readingTROOPERS
TR17 Training: Hacking 101
Hi there,
Like in recent years the popular
Hacking 101 workshop
will take place on TROOPERS17, too! The workshop will give attendees an insight
into the hacking techniques required for penetration testing. These
techniques will cover various topics:
- information gathering
- network scanning
- web application hacking
- low-level exploitation
…and more!
During this workshop you will learn, step by step, a testing methodology that is applicable to the majority of scenarios. So imagine you have to assess the security of a system running on the Internet. How would you start? First, you need a good understanding about the target, including running services or related systems. Just scanning an IP will most likely not reveal a lot of information about the system. The gathered information may help you to identify communication relations of services that could include vulnerabilities. A brief understanding of the target and it’s related systems/services/applications will make scanning and identifying vulnerabilities a lot easier and more effective. Then, the last step will be the exploitation of the identified vulnerabilities, with the ultimate aim to get access to the target system and pivot to other, probably internal, systems and resources.
Continue reading Continue readingFirst dedicated Forensic Computing Training at TR17
I am looking forward to our newly introduced dedicated Forensic Computing
Training at TR17!
We will start the first day with a detailed background briefing about Forensic
Computing as a Forensic Science, Digital Evidence, and the Chain of Custody. The
rest of the workshop we will follow the Order of Volatility starting with the
analysis of persistent storage using file system internals and carving, as well
as RAID reassembly with lots of hands-on case studies using open source tools.
As a next step, we will smell the smoking gun in live forensics exercises.
Depending on your preferences we will then dig a bit into memory forensics and
network forensics.
TelcoSecDay 2017 – 2nd Round of Talks
Hello and a Happy new Year!
There are only two and a half months left, so I’d like to publish the next two talks for TelcoSecDay 2017, taking place at 21st of March in Heidelberg. Both talks are about the security of an upcoming technology which importance will raise in near future: 5G Networks.
One of the talks will be from an attacker’s point of view, highlighting weaknesses of 2G/3G/4G networks and what we have to fix in 5G, and the other one will give us insights into current developments of the 3GPP standardization group.
Continue reading Continue readingTR17 Training: Crypto attacks and defenses
This is a guest blog written by Jean-Philippe Aumasson & Philipp Jovanovic about their upcoming TROOPERS17 training: Crypto attacks and defenses.
The 1-day training from last TROOPERS has become a 2-day training, featuring even more real-world attacks and defenses as well as new hands-on sessions! We’ll teach you, step by step, how to spot and exploit crypto vulnerabilities, how to use the strongest forms of state-of-the-art cryptography to secure modern systems (like IoT or mobile applications), and bring you up to speed on the latest and greatest developments in the world of cryptography, such as TLS 1.3, blockchains, and post-quantum crypto.
Continue reading Continue reading3rd Round of TROOPERS17 Talks
We had to make some tough choices regarding our TROOPERS17 Main Conference Agenda. Thank you again to everyone for submitting! The full agenda will be published later this week, but for now here are the next round of talks!
Ivan Pepelnjak: Securing Network Automation
If you have operational experience in running large networks then you’re
probably yearning to replace the traditional way of managing individual network
devices via SSH with something better and more reliable. Software Defined
Networking (SDN) was touted as the all-encompassing solution, but what we got
instead is a heap of academic ideas, several platforms that require as much
investment as an SAP deployment, and a bunch of proprietary products focused
more on increasing lock-in and vendor revenue than solving operational problems.
PoC Con Seoul 2016
Recently I had the pleasure to join the
PowerOfCommunity conference in Seoul.
Florian and Felix attended the conference in the past and enjoyed it a lot, so I
took the opportunity to join this year. From what I had heard the conference is
highly technical, offensive security and community focused (surprise 😉 ). Boy
did they deliver!
Located in a hotel next to a nice park and close to the famous Gangnam district
in Seoul we came together to feel the power of community. The conference was
planned for two days and offered two tracks per day. Several key talks were
presented for everyone.
I really liked the topics a lot. Some contributions I found particularly
interesting were:
Petr Švenda with “The Million-Key Question – How RSA Public Key Leaks Its
Origin”, where he presented his research of fingerprinting RSA public keys. By
analyzing the RSA keys from smartcards and software sources he was able to find
similarities between them, which allowed fingerprinting the generating source
for some cases. With this information it could be possible gather some
potentially important details from simple keys. He is currently expanding his
work, please send him an E-Mail if you have RSA keys from an exotic resource. 😉
TR17 Training: Fuzzing with American Fuzzy Lop, Address Sanitizer and LibFuzzer
This is a guest blog written by Hanno Böck who will be running the Fuzzing with American Fuzzy Lop, Address Sanitizer and LibFuzzer at TROOPERS17.
Fuzzing is a very old technique to find bugs and vulnerabilities in software. However it has seen a new push in recent years due to vastly improved tools. The compilers gcc and clang have received Sanitizer tools that allow finding a lot of bugs like use after free errors and out of bounds reads that are otherwise very hard to find.
Continue reading Continue reading2nd Rounds of TROOPERS17 Talks!
It is the end of the year and we are hoping it is not too hectic of a time for you all! But if it is, hopefully the announcement of our next round of TROOPERS17 talks is enough to get you in the TROOPERS (if not the holiday) spirit 🙂
Francis Alexander & Bharadwaj Machiraju: How we hacked Distributed Configuration Management Systems
With increase in necessity of distributed applications, coordination and configuration management tools for these classes of applications have popped up. These systems might pop-up occasionally during penetration tests. The major focus of this research was to find ways to abuse these systems as well as use them for getting deeper access to other systems.
Continue reading Continue readingTelcoSecDay 2017 – First Talks Published
Even if the CFP for TelcoSecDay 2017 is officially closed, I am still getting
mails in. First of all: thank you for all your great feedback! As the
TelcoSecDay is a complimentary and non-public event with highly specialized
topics, it only works by sharing knowledge with each other. But please keep in
mind that the speaker-slots are limited and I have to make a decision at some
point of time.
Anyhow, I am looking forward for a great event and I am proud to publish the
first accepted talks: