Events

Announcing the first 5 talks of TROOPERS17!!!!

TROOPERS16 was packed with epic talks from around the world, an unknown evil twin brother appearing, hands-on trainings, and a legendary year for our TROOPERS Charity efforts! If you were there you might be wondering to yourself how could they possibly top it? Well, I am going to let you in on a little secret: Next year is the 10th edition of TROOPERS. One DECADE of TROOPERS, and we are pulling out all the stops! Starting with the announcement of the first 5 talks!

Continue reading
Events

TelcoSecDay 2017 – CFP Opens

For the 6th year in a row, the next TelcoSecDay will take place in 2017 on March 21th. Again, it will be held one day before Troopers IT-Security Conference as an invitation-only event. For those of you who don’t know the TSD, it is organized by ERNW and is aimed at bringing researchers and people from the telecommunication industry together to discuss about current security weaknesses, challenges and strategies. To do so, various topics will be presented during the talks and there will surely be enough time to follow-up in extensive discussions.
To give you an idea, here’s the TSD 2016 agenda, and here’s the one of 2015.

Continue reading
Events

Because of Cyber – A Recap

Troopers16 has been over for quite a while now, but because sharing is caring, we would like to give you some more insight and share some gems that happened over the 2 days of us running a small/medium sized enterprise in mid-west Russia as part of the well received FishBowl side story.

Technology wise the whole infrastructure of FishBowl, as well as the Cyber Emergency Response Team, was hosted on one FreeBSD machine with exception of the challenge scoreboard which was on site only, hence conference network only.
The C.E.R.T. web site was static web site using the jekyll engine. FishBowl on the other hand required some dynamic web magic which is why we choose to use the flask framework. For the FishBowl web design we simply helped ourselves with the styles of the Troopers web site, who of you noticed? 😉
All web related stuff was reverse proxied by an nginx to provide a common layer of technology even though every venture was segregated into its own FreeBSD jail environment.
For mail a simple postfix setup was set up. Having a proper mail server for such »shenanigans« turned out to be very enjoyable, but more on that later.

Continue reading
Events

Defense & Management Day 2

TROOPERS16 offered many different speakers from around the globe. Below are three different talks from the afternoon of Day 2’s Defense and Management Track. 

===

The TROOPERS16 talk “Attacking & Protecting Big Data Environments” presented the research of Birk Kauer and Matthias Luft, (ERNW) in which they showed how enterprise-grade “big data” environments, based on e.g. HortonWorks or Cloudera, comprising of components such as HDFS, Yarn, Hue, Flume, Hive, Spark, Sentry/Ranger could be attacked. These environments typically process huge amounts of data. The data is either stored in a cluster file system or streamed into clusters. The processing of these datasets are done by jobs, and these jobs can be arbitrary code execution.

Continue reading
Events

TSD 2016 – Follow Up

Thanks again for all the great talks and fruitful discussions @TSD 2016! I hope everybody had a safe trip home and enjoyed Troopers as we did. In the meantime I contacted all speakers to talk about publication of their slidesets. Some of them agreed (or already published them on their own) so I’d like to share these with you:

Alexandre De OliveiraAssaulting IPX Diameter roaming network
Siddharth RaoThe known unknowns of SS7 and beyond.

Joao Collier de Mendonca“rucki zucki” scanning tool
Harald WelteOpen Source Network Elements for Security Analysis of Mobile Networks
Ravi & Altaf ShaikDon’t connect to my 4G base station: investigating info leaks in 4G basebands

Continue reading
Events

Unpatchable – Living with a vulnerable implanted device

TL;DR: Marie Moe talked about security issues of medical devices, especially implantable devices like pacemakers, but not in overwhelming technological depth. She wanted to point out the necessity of intensified security research in the field of medical devices as vendors and medical personnel seem to be lacking necessary awareness of security of devices, interfaces, services, and even data privacy.”Get involved, join the cavalry” was her core message.

Lub-Dub-Lub-Dub-Lub-Dub
Marie started her talk with the sound of a repeating heartbeat. First she introduced how she came up with the topic of her talk: Marie relies on a pacemaker herself andsince she got it implanted she was curious how secure this little device might be. A minimum education of the auditorium followed including an explanation how a human heart works and what a pacemaker does.

Continue reading
Events

Security Assessment of Microsoft DirectAccess

A talk about DirectAccess (an IPv6-only VPN solution) was given by our colleague Ali Hardudi during IPv6 summit. Ali has recently finished his master thesis on this topic.

The DirectAccess VPN technology was introduced by Microsoft starting from Windows server 2008. It allows users remotely, seamlessly and securely connect to their internal network resources without a need to provide user credentials, which is done using different technologies such as Windows domain group policies.

Continue reading
Events

Anonymization IPv6 in PCAPs – Challenges and Wins

Jasper Bongertz is a Senior Technical Consultant at Airbus Defence and Space CyberSecurity. He is focusing on IT security, Incident Response and Network Forensics.
During the IPv6 summit on Troopers16 he had given a talk on anonymization IPv6 in PCAPs and presented his new tool.

Sometimes you need to share your packet capture files (PCAPs), but distributing them involves a risk of exposing the confidential information. To avoid this, you must sanitize your PCAPs. The goal of sanitization is to remove the critical details but keep enough information for the PCAP to still be useful. The original-to-sanitized ratio is based on your goals.

Continue reading
Events

Passive Intelligence Gathering and Analytics – It’s all Just Metadata!

The first talk after the keynote on day 2 of TROOPERS was from Christopher Truncer about passive intelligence gathering and the analytics of that. Christopher Truncer (@ChrisTruncer) is a red teamer with Mandiant. He is a co-founder and current developer of the Veil-Framework, a project aimed to bridge the gap between advanced red team and penetration testing toolsets.

His talk is mainly about defending a network from different threats by collecting and analyzing metadata from different sources.

Continue reading