Event Archives

HITBSecConf2011 – Amsterdam

Amsterdam, 17-20 May 2011

Attacking 3G and 4G Telecommunication Networks

Speaker: Enno Rey & Daniel Mende

In 2010 a number of practical high-profile attacks against GSM has been discussed and demonstrated. Still it should be noted that those only work against GSM (“2G”) which has been standardized in the early 90s. It was followed by the “3G” family of standards in 2000 which in turn are currently superseded (better: complemented) by yet another generation (“4G”). LTE (4G) which is expected to be “the next big thing in mobile telco business” has an all-IP network architecture that is much flatter than the earlier architectures’ ones.

In the so-called backhaul and core parts of 3G and 4G networks mainly one IP based protocol can be found, that is GTP [GPRS Tunneling Protocol]. Given that 3GPP standards mandate that GTP is either only used within one security domain (operator) or in case of roaming users should be secured by IPsec one should never be able to reach GTP speaking components from the Internet. Well, yes, one should not, but we show that reality is so often a bit different.

We will outline 3G and 4G architectures and associated attack paths, enriched by “anecdotes from the field” and – potentially more interesting results from some 3G/4G security testing “performed in the wild”. An attack classification based on the protocols involved and the attack originating networks (user equipment, other operators, Internet etc.) will be given. Lastly, we will discuss (and, of course, release) a GTP scanning tool that allows to identify entry points into mobile telecommunication networks. A number of demos will add some spice.

More information here: conference.hitb.org

Please find the slides below:


ERNW_HITB_AMS_Mende_Rey_Attacking_mobile_telecommunication_networks.pdf (1MB)

it security 2011

Munich, 16-18 May 2011

Workshop - IPv6-Sicherheit in LANs
Trainer: Christopher Werny

Integration des neues Personalausweises in Enterprise-Umgebungen: Chancen, Aufwände, Gefahren

Speaker: Friedwart Kuhn

Sicherheit von Multifunktionsgeräten (Drucker, Scanner, Kopierer, Fax) in Unternehmen

Speaker: Matthias Luft & Michael Schaefer

Please find the complete agenda here: www.it-security-2011.de

Special: There's an exclusive deal for ERNW's customers in place. Please contact us for further details.

TROOPERS11

Heidelberg, 28 March - 1 April 2011

Visit www.troopers.de or follow us on Twitter to keep up-to-date on TROOPERS - the premium IT-Security conference series.

Find the full agenda here: www.troopers.de/agenda/
Read everything about this year's speakers: www.troopers.de/speakers/
Download slides: Please head over to www.troopers.de/downloads/

BASTA! 2011

Darmstadt, 21-25 February 2011

Web Security - Hacking Night School

Speaker: Matthias Luft

Die traditionelle Hacking Night School präsentiert aktuelle
Angriffstechniken gegen Webapplikationen. Die Demonstration umfasst
mehrere Beispiele, wie moderne Serversysteme, also Microsoft Windows
Server 2008 und SQL Server 2008, kompromittiert werden können. Dabei
werden verschiedene Angriffsvektoren, wie zum Beispiel SQL und XML
Injection, in Kombination mit Schwächen in vermeintlich bewährten
Standards, wie zum Beispiel SSL/TLS, verwendet, um Systeme komplett zu
übernehmen. In einem letzten Schritt wird die Fallstudie einer komplexen
Sicherheitslücke in ASP.NET besprochen. Anhand der Konzeption und der
möglichen Gegenmaßnahmen wird ein allgemeines Sicherheitsmodell
erläutert, das auch bisher unbekannte Sicherheitslücken adressiert.

Find the slides below:

Tech Forum „Verkabelung/Netzwerk- und RZ-Infrastruktur”

Munich, 8-9 February 2011

Risiken bei der Integration mobiler Endgeräte

Speaker: Rene Graf

ShmooCon 2011

Washington DC, 28-30 January 2011

Attacking 3G and 4G mobile telecommunications networks

Speakers: Enno Rey & Daniel Mende

In 2010 a number of practical high-profile attacks against GSM has been discussed and demonstrated. Still it should be noted that GSM ("2G") has been standardized in the early 90s, followed by the "3G" family of standards in 2000 which in turn is currently superseded (better: complemented) by yet another generation ("4G"). What about their security aspects? In this talk we'll outline 3G and 4G architectures and associated attack paths, enriched by "anecdotes from the field" and - potentially more interesting ;-) - results from some 3G/4G security testing "performed in the wild".


Shmoocon_ERNW_Attacking_mobile_telecommunication_networks.pdf (3MB)

Tech Forum „Security in der Cloud/Virtualisierung”

Munich, 15 November 2010

Keynote: The seven sisters wearing the emperor‘s new clothes

Speaker: Enno Rey

On the changing role of fundamental network security principles in the age of virtualization and cloud computing.


ERNW_LANline_VirtCloudSec_Keynote.pdf (1MB)

Day-Con IV

Dayton, 22-23 October 2010

Supply Chain (In-) Security

Speakers: Enno Rey & Graeme Neilson

Find the slides below:


Daycon2010_Aura_ERNW_Supply_Chain_Insecurity.pdf (3MB)

Tech Forum „Industrial Ethernet”

Stuttgart, 6 October 2010

Industrial Firewalls

Speaker: Rene Graf


ERNW_LanLine_Industrial_Firewalls.pdf (1MB)

ISSE 2010

Berlin, 5-7 October 2010

A small leak will sink a great ship: An Empirical Study of DLP solutions

Speakers: Matthias Luft, Thorsten Holz

Matthias Luft and Thorsten Holz submitted an Whitepaper (Link coming soon) about the evaluation of Data Leakage Prevention Solutions to the EEMA conference ISSE. The Whitepaper presents a methodology to evaluate DLP solutions and exemplifies the method by testing two DLP implementations in detail. This essential step in every product lifecycle revealed several flaws that were reported to the vendors.

Download slides here:


ISSE_An_Empirical_Study_of_DLP_Solutions.pdf (1MB)

Security in virtualized environments

27 September 2010

Security in virtualized environments

Speaker: Enno Rey


ERNW_Virtualisierungssicherheit.pdf (1MB)

BASTA! 2010

Mainz, 20-24. September

Compliance in the Cloud

Speaker: Enno Rey

Get the slides here:


ERNW_BASTA2010_Compliance_in_the_Cloud.pdf (1MB)

Black Hat USA 2010

Las Vegas, 24-29 July 2010

Burning Asgard - What happens when Loki breaks free

Speakers: Daniel Mende, Rene Graf

I personally remember the release of Yersinia at Black Hat Europe 2005. It was a ground breaking experience: a number of Layer 2 attacks regarded purely theoretical until then, was suddenly available in a mostly automated way. And those guys even showed some forays completely unbeknownst to me at the time. We plan to do the same in Vegas, with a new tool called Loki (after the giant from Norse mythology associated with cunning, trickery and evil). It's a Python based framework implementing many packet generation and attack modules for Layer 3 protocols, including BGP, LDP, OSPF, VRRP and quite a few others.

After outlining Loki's inner architecture we'll give insight into several modules and discuss some particularly interesting attacks in the routing protocol space (e.g. cracking OSPF MD5 keys, injection of routes into OSPF and EIGRP environments etc.). Furthermore we'll describe vulnerabilities in lesser known protocols like VRRP. Every attack we mention will be shown in a practical demo and - of course - Loki will be released right after our talk.

Download here:

Presentation & Others:
Presentation
Demo Videos

Code/Builds:
Source

Please visit our tool section for gentoo and ubuntu builds.

PlumberCon

Vienna, 9-11 July 2010

PlumberCon is proudly supported by ERNW. We provide the conference's network.

Crash Course in Penetration Testing

Speaker: Oliver Roeschke

This course will cover some of the newer aspects of penetration testing such as open source intelligence gathering with Maltego and other open source tools. Advanced scanning, enumeration, exploitation (remote and client-side), and post-exploitation relying heavily on the features included in the Metasploit Framework will also be covered.
Emphasis throughout the entire workshop will be placed on being as stealthy as possible, and dealing with popular defensive technologies.


Attacking Cisco Enterprise WLAN

Speaker: Oliver Roeschke

Enterprise WLAN solutions depict complex setups that should support security and managability by combining several technologies and protocols. This complexity needs distinguished design patterns to ensure all security goals. Usage of insecure mechanisms can result in total breakdown regarding security. One prominent example is Cisco's Structured Wireless-Aware Network (SWAN) architecture, composed of autonomous access points combined with some components for centralized management. This architecture is still deployed in a number of early corporate wireless networks. The proprietary 'Wireless LAN Context Control Protocol' (WLCCP) plays a major role in here.

Unfortunately, the protocol design is debatable in several aspects, leading to practical attacks that impose high risk to wireless networks. A second example is Cisco's current solution, called 'Unified Wireless Networks'. It consists of several entities with interesting communication patterns. Additionally it is built on a broken trust model.

In this talk we will describe the inner workings of these pieces, dissect the vulnerable parts and have some discussion on good or bad protocol design. As usual, some demos will demonstrate the issues.


PacketWars™

Hosted by: Daniel Mende

PacketWars™ is a sport like nothing you have ever experienced! Games known as Battles pit individual players each other in a race against time to achieve predefined objectives, win prizes and attain FAME. Operating in the shadows of the Internet beyond the rule of TCP/IP and devoid of compassion, a secret war rages. Sometimes spilling over into the “real” world, digital battles are waged to advance the will of the combatants. The combatants are as varied as their skills and motivation. Every engagement is unique. It is our duty to chronicle these events. Join us as we open a portal to extreme hacking. Do you have what it takes to survive?

Read also our blog post on the conference: www.insinuator.net

HITBSecConf2010 – Amsterdam

Amsterdam, 29 June - 2 July 2010

How to rate the security in closed source software

Speaker: Michael Thumann

Security evaluation of software is getting more and more common in large enterprises to ensure that they can trust the software and secure the processed data. But beneath the common source code reviews, pentests and fuzzing tests, it's still hard to rate the security of closed source software without reverse engineering it. This talk will introduce some ideas how to rate this software in an almost automated way using the right tools and based on some quality metrics and other facts of the binary. It will give some advises how to implement the concept in the enterprise.

More information here: conference.hitb.org


ERNW_HITB2010_How_to_rate_the_security_of_closed_source_software_Michael_Thumann.pdf (1MB)
TTICheck.zip (37KB)

Just4Meeting

Lisbon, 25-27 June 2010

Lecture - All Your Packets Are Belong to Us – Attacking Backbone Technologies

Speaker: Daniel Mende

Daniel Mende is a German security researcher specialized on network protocols and technologies. He’s well known for his Layer2 extensions of the SPIKE and Sulley fuzzing frameworks, he has discussed new ways in building botnets and presented on protocol security at many occasions including Troopers08, ShmooCon and Blackhat. Usually he releases a new tool when giving a talk.


Workshop - Can Data Leakage Prevention Prevent Data Leakage?

Speaker: Matthias Luft

Matthias is a seasoned pentester with vast experience in corporate environments. Over the years he focused on evaluating and reviewing all kinds of applications. So he’s one of the first researches who revealed major design flaws and vulnerabilities in the approach of Data Leakage Prevention . He is a regular speaker at international security
conferences and will happily share his knowledge with the audience.

Visit www.just4meeting.com for more information.

Bechtle Security Day [non-public]

Würzburg, 23 June 2010

Roger Klose and Matthias Luft present at Bechtle Security Day in Würzburg. This is an exclusive event for customers and partners of Bechtle AG.

Get in contact: www.bechtle.com

Download the slides here:


BechtleSecDay2010_ERNW_AttackingWeb20.pdf (1MB)
BechtleSecDay2010_ERNW_SinnUnsinnWAFs.pdf (1MB)

it security 2010

Munich, 26-28 April 2010

This is an event in Germany - talks on this event are normally held in German language.

Einführung in die „Rapid Risk Assessment"-Methodik

Speaker: Enno Rey

Effiziente Risiko-Analyse ist eines der wichtigsten Werkzeuge moderner Sicherheitsarbeit. Nicht umsonst fordert ISO 27001 ein funktionales Risk Assessment & Management Framework in Organisationen und die ISO 27000 Familie hält mit ISO 27005 ja auch einen eigenen Standard zum Thema bereit. Leider scheitert Risiko-Analyse als Prozess in vielen Umgebungen an überzogenen Erwartungen, schlechter organisatorischer Einbindung oder zu hoher Komplexität. Der Vortrag stellt ein für einen der weltgrößten Outsourcer entwickeltes Modell („Rapid Risk Assessment") vor. Dessen Ziel ist es, effiziente Risk Assessments in kurzer Zeit (etwa einem 1-2 Stunden Conference Call) durchzuführen, um Sicherheitsentscheidungen vorzubereiten. Wir diskutieren praktische Erfahrungen mit dem Ansatz und unserer Learning Curve, und stellen wichtige Bestandteile exemplarisch bereit.


Attacking Web Applications 2.0 (oder „Moderne Angriffe gegen Web-Applikationen")

Speaker: Michael Thumann

Der Vortrag beschäftigt sich mit aktuellen Angriffstechniken gegen Webanwendungen. Im Zeitalter des „Webifyings" von Unternehmensapplikationen sind Web-Applikationen schon länger im Fokus der Hacker und neue Technologien wie Web 2.0 einerseits wie auch intensive Researcharbeit der Angreifer andererseits führen zu einer Vielzahl von neuen Angriffsmöglichkeiten. Die behandelten Angriffe umfassen Web Filter Bypassing, Session Hijacking, Advanced SQL Injection gegen moderne Datenbank Server und SSL Renegotiation Attacks. Live-Demonstrationen zeigen, wie aktuelle Angriffstechniken praktisch funktionieren. Eine ausführliche Diskussion effizienter und angemessener Schutzmaßnahmen rundet die Präsentation ab.


Security Assessment von Cisco Enterprise WLAN-Technologien

Speaker: Oliver Roeschke

Die Welt der „Enterprise WLAN-Lösungen" ist voller obskurer und nicht-standardisierter Technologien, die zu Sicherheitsproblemen führen können. Cisco bildet hier keine Ausnahme. Insbesondere die „Structured Wireless-Aware Network" (SWAN)-Architektur (die auf dem proprietären WLCCP-Protokoll basiert), aber auch moderne Wireless LAN Controller (WLC) basierte Umgebungen weisen in verschiedenen Szenarien Schwachstellen auf. In diesem Vortrag werden theoretische und praktische (!) Angriffsmöglichkeiten in solchen Netzen behandelt und demonstriert sowie die entstehenden Risiken bewertet. Ziel ist, sowohl die Investition wie auch die transportierten Daten abzusichern.


Weitere Informationen finden Sie unter www.it-security-2010.de

HITBSecConf2010 – Dubai

Dubai, 19-22 April 2010

Attacking CISCO WLAN Solutions

Speaker: Oliver Roeschke, Daniel Mende

The world of “Enterprise WLAN solutions” is full of obscure and “non-standard” elements and technologies. Cisco’s solutions are no exception here.

In this talk we will describe potential and practical attacks against components, network traffic and/or cryptographic material in different generations of their “Enterprise WLAN offerings”. This includes pretty standard attacks against management interfaces as well as some not-so-common insight how one of their proprietary protocols works (or fails, security-wise). As usual, a number of demos will add spice and some code will be released.

For more information regarding the conference please visit: conference.hackinthebox.org

Black Hat Europe 2010

Barcelona, 12-15 April 2010

Hacking Cisco Enterprise WLANs

Speakers: Enno Rey, Daniel Mende

The world of "Enterprise WLAN solutions" is full of obscure and "non-standard" elements and technologies. Cisco's solutions, from the early Structured Wireless-Aware Network (SWAN) to the current Cisco Wireless Unified Networking (CUWN) architectures, only partly differ here. In this talk we describe the inner workings of these solutions, dissect the vulnerable parts and discuss theoretical and practical attacks, with some nice demos.

A new tool automating a number of attacks (incl. taking over the WDS master role, extracting WPA pairwise master keys from intra-AP communication etc) will be released at Black Hat Europe.

For more information regarding the conference please visit: www.blackhat.com

TROOPERS10

Heidelberg, 8-12 March 2010

TROOPERS10 - This time it's a home match.

This year we're bringing back the action right to the place where everything started: Heidelberg, Germany.

In 2007 the idea of a security conference without the usual product presentations, marketing blabla, and bull*ht-bingo was born – just pure practical IT security. After an enthusiastic response from our audiences in Munich we decided to evolve the concept into a full-blown conference combined with a series of workshops and round tables.

We're inviting (C)ISOs, IT auditors, sysadmins, security consultants and everyone who is involved with IT security to come to Heidelberg and get in touch with leading experts from all over the world. A number of workshops on monday and tuesday covers highly relevant topics in detail, on wednesday and thursday you'll learn about the latest developments, threats and achievements from world class security evangelists, experts and hackers. And on friday we seat you on round tables right next to the speakers and fellow experts. You'll be able to discuss your own strategies and concerns with them face-to-face. You will be listened to, because in the end of the day we're all the same: TROOPERS in the infosec world.

TROOPERS10 is hosted by ERNW GmbH, an independent information security consultancy and assessment company from Heidelberg, Germany. In the past years, speakers from ERNW were invited all around the world to present their latest ITsec research results and to share their knowledge within the global hacking and infosec community. With this global experience in mind, in 2008 ERNW decided to launch an international conference in Germany. Reconfirmed by the success of the year 2009 edition we decided to step up and take this thing to the next level. Once more it's going to be an event unlike most other "security conferences": No pointless marketing talks, just high-end workshops with hands-on experiences and most important: You'll get real answers and practical benefits to meet today´s and tomorrow's threats.

You're a TROOPER and your next boot camp is scheduled for 8 - 12th of March 2010, Heidelberg, Germany.


Please visit www.troopers.de for more information and sign-up.

BASTA! Spring 2010

Darmstadt, 22-26 February 2010

This is an event in Germany - talks on this event are normally held in German language.

Freeware-Security-Tools für .NET-Entwickler

Sprecher: Michael Thumann

In dieser Session werden frei erhältliche Security-Tools für .NET-Entwickler vorgestellt. Vom Sourcecode Analyzer über sinnvolle Bibliotheken wie AntiXSS und ESAPI bis hin zu Threat-Modeling-Tools werden die Entwickler in die Werkzeuge eingeführt und ihr Nutzen am Beispiel des Microsoft Security Development Lifecycles demonstriert. Mithilfe dieser Werkzeuge kann auch ohne die Einführung aufwendiger Unternehmensprozesse die Qualität in der Softwareentwicklung massiv gesteigert werden.


Advanced Hacking

Workshopleiter: Michael Thumann

Die traditionelle Hacking Night School präsentiert aktuelle Angriffstechniken gegen Web Application, beispielsweise SQL Injection, und zeigt, wie diese in Kombination mit anderen Angriffen (z. B. gegen das Windows-Signed-Driver-Modell) ausgenutzt werden, um Systeme komplett zu kompromittieren. Das Angriffsziel sind dabei die aktuellen Serverversionen von Microsoft, also Windows Server 2008 und SQL Server 2008.


Security & Compliance beim Outsourcing

Sprecher: Enno Rey

Der Vortrag behandelt rechtliche Aspekte und gängige Sicherheitsmaßnahmen bei der Verlagerung von Daten oder Services auf Dienstanbieter. Dabei kann es sich um Webhosting von Anwendungen oder um die komplette Verlagerung "in die Cloud" handeln. Es werden die wichtigsten Rahmenbedingungen technischer und vertraglicher Art diskutiert und typische Szenarien vorgestellt.


Weitere Informationen finden Sie unter: www.basta.net

Hier finden Sie die Folien:


ERNW_BASTAS_Spring2010_Security_und_Compliance_beim_Outsourcing.pdf (1MB)

ShmooCon 2010

Washington DC, 5-7 February 2010

WLCCP - Analysis of a Potentially Flawed Protocol

Speakers: Enno Rey, Oliver Roeschke

The world of "Enterprise WLAN solutions" is full of obscure and "non-standard" elements and technologies. One prominent example is Cisco's Structured Wireless-Aware Network (SWAN) architecture, composed of autonomous access points combined with some components for centralized management, and still deployed in a number of corporate networks. The proprietary "Wireless LAN Context Control Protocol" (WLCCP) plays a major role here. Unfortunately it seems the design of the protocol might be debatable in several aspects, leading to some theoretical and, well, practical vulnerabilities. In this talk we will describe the inner workings of this piece, dissect the vulnerable parts and have some discussion on good or bad protocol design. As usual, some demos will add spice and some code will be released.

Find more information and a video of the talk at www.shmoocon.org.

Download the slides here:


ERNW_ShmooCon2010_Cisco_Enterprise_Wlan_Sec.pdf (2MB)

IT Underground

Warsaw, 16-18 November 2009

IT Underground 2009 is held in Warsaw. Several ERNW experts are on-site, amongst others you'll meet: Roger Klose, Oliver Röschke and Matthias Luft. More to be announced soon.

For more information regarding the conference please visit: www.itunderground.org

Science Days 2009

Leipzig, 16-17 November 2009

All Your Packets are belong to us - Attacking Backbone Technologies

Speakers: Enno Rey, Daniel Mende

The year 2008 has seen some severe attacks on infrastructure protocols (SNMP, DNS, BGP). We will continue down that road and discuss potential and real vulnerabilities in backbone technologies used in today's carrier space (e.g. MPLS, Carrier Ethernet, QinQ and the like). The talk includes a number of demos (like cracking BGP MD5 keys, redirecting MPLS traffic on a site level and some Carrier Ethernet stuff) all of which will be performed with a new tool kit made available in our "Download" section. It's about making the theoretical practical, once more!

More information: www.hft-leipzig.de
Download the tools: Download section

Download the slides here:


ERNW_Science_Days_09_All_your_packets.pdf (1MB)

Paranoia 2009

Oslo, 29 October 2009

All your packets are belong to us - Attacking backbone technologies

Speaker: Daniel Mende, Roger Klose

The year 2008 has seen some severe attacks on infrastructure protocols (SNMP, DNS, BGP). We will continue down that road and discuss potential and real vulnerabilities in backbone technologies used in today's carrier space (e.g. MPLS, Carrier Ethernet, QinQ and the like). The talk includes a number of demos (like cracking BGP MD5 keys, redirecting MPLS traffic on a site level and some Carrier Ethernet stuff) all of which will be performed with a new tool kit made available in our "Download" section. It's about making the theoretical practical, once more!

More information: paranoia.watchcom.no
Download the tools: Download section

RSA Conference Europe 2009

London, 20-22 October 2009

Reversing Malware for Business Purposes

Speaker: Michael Thumann

This session will examine different ways to analyse malware for business purposes and discusses advantages and disadvantages of the approaches. It will introduce the most common online sandboxes and compare them to sandbox systems built individually. It will also cover the reverse engineering approach and give some conclusions which approach is useful in a business context.

Visit www.rsaconference.com for more information.

Day-Con III featuring PacketWars™

Dayton, 14-15 October 2009

The Day-Con III Keynote is delivered by Enno Rey.

More information: www.day-con.org

IIR "IT-Virtualisierung-Forum 2009"

Frankfurt, 7-8 October 2009

IIR IT-Virtualisierung-Forum 2009

Enno Rey gives a lecture on Risk Analysis concerning virtualized environments. Look here for a detailed agenda of the 2-day forum.

More information: www.iir.de

BruCON

Brussels, 18-19 September 2009

All your packets are belong to us - Attacking backbone technologies

Speakers: Daniel Mende, Roger Klose

The year 2008 has seen some severe attacks on infrastructure protocols (SNMP, DNS, BGP). We will continue down that road and discuss potential and real vulnerabilities in backbone technologies used in today's carrier space (e.g. MPLS, Carrier Ethernet, QinQ and the like). The talk includes a number of demos (like cracking BGP MD5 keys, redirecting MPLS traffic on a site level and some Carrier Ethernet stuff) all of which will be performed with a new tool kit made available in our "Download" section. It's about making the theoretical practical, once more!

More information: www.brucon.org
Download the tools: Download section

Download the slides here:


ERNW_BruCon_All_your_packets.pdf (1MB)

BASTA! 2009

Mainz, 21-25 September 2009

Secure the weakest Link - An holistic view on End-User Security

Speaker: Michael Thumann

This talk is held in German language. Summary:

Die Absicherung moderner (Web-)Anwendungen erfordert ein tiefgreifendes Verständnis des Zusammenwirkens von Applikation, (Betriebs-)System, Netzwerkprotokollen und Datenbanken. In dieser Session wird gezeigt, mit welchen Methoden und Tools moderne Angreifer gegen Anwendungen bzw. die von Ihnen verarbeiteten Daten vorgehen. Anhand praktischer Demos (die die Teilnehmer teilweise selbst in der Session nachstellen können; eigener Laptop erforderlich) zeigt der Referent, wo typischerweise Schwachstellen zu finden sind, die "außerhalb des Scopes" des Entwicklers liegen. Diskutiert wird auch, wo etwa Infrastrukturangriffe gegen DNS oder Internet-Routing (BGP) Auswirkungen auf die Sicherheit von Anwendungen haben können und warum daher eine ganzheitliche Sicht auf Application Security notwendig ist. Weiterhin werden die verschiedenen Angriffe gegen SSL präsentiert und welche Gegenmaßnahmen hier aus Entwicklerperspektive sinnvoll sind. Last but not least wird die sicherheitskritische Rolle der oft erforderlichen Datenbankanbindung diskutiert.

More information: here.

Download the slides here:


ERNW_Basta09_Secure_the_weakest_link.pdf (1021KB)

Hacking at Random 2009

Vierhouten, 13-16 August 2009

All your packets are belong to us - Attacking backbone technologies

Speakers: Daniel Mende, Simon Rich, Michael Schaefer

The year 2008 has seen some severe attacks on infrastructure protocols (SNMP, DNS, BGP). We will continue down that road and discuss potential and real vulnerabilities in backbone technologies used in today's carrier space (e.g. MPLS, Carrier Ethernet, QinQ and the like). The talk includes a number of demos (like cracking BGP MD5 keys, redirecting MPLS traffic on a site level and some Carrier Ethernet stuff) all of which will be performed with a new tool kit made available in our "Download" section.

Daniel Mende and his crew offer a workshop on MPLS Security at a conference for the first time. The workshop is free and will include heaps of hands-on learning. It's about making the theoretical practical, once more!

More information: www.har2009.org
Download the tools: Download section

Black Hat USA 2009

Las Vegas, 25-30 July 2009

Cloudifornication: Indiscriminate Information Intercourse Involving Internet Infrastructure

Speakers: Enno Rey, Chris Hoff

[19. July 2009] Update: Unfortunately Chris and Enno had to cancel the talk due to an executive scheduling issue on Chris' side. We hope to give it soon at another occasion.

What was in is now out. This metaphor holds true not only as an accurate analysis of adoption trends of disruptive technology and innovation in the enterprise, but also parallels the amazing velocity of how our datacenters are being re-perimiterized and quite literally turned inside out thanks to Cloud computing and virtualization. One of the really scary things happening with the massive convergence of virtualization and cloud computing is its effect on security models and the information they are designed to protect.

Where and how our data is created, processed, accessed, stored, backed up and destroyed in what is sure to become massively overlaid cloud-based services (and by whom and using whose infrastructure) yields significant concerns related to security, privacy, compliance and survivability. Further, the "stacked turtle" problem becomes incredibly scary as the notion of nested clouds becomes reality: cloud SaaS providers depending on Cloud IaaS providers which rely on Cloud network providers. It's a house of, well, turtles.

This "infrastructure intercourse" where your resources and data can be located anywhere makes it very interesting to try and secure your assets when you don't own the infrastructure and in most cases can't control the level of security. We will show multiple cascading levels of failure associated with relying on cloud on cloud infrastructure and services including exposing flawed assumptions and untested theories as it relates to security, privacy and confidentiality in the Cloud with some unique attack vectors.

More information: www.blackhat.com

IIR IT-Security Update

Frankfurt, 1 July 2009

IIR IT-Security Update with Enno Rey, Vojislav Kosanovic and Thomas Kopp

This event covers a broad spectrum of current IT-Security topics. Look here for a detailed agenda.

More information: www.iir.de

Bechtle Security Day [non-public]

Würzburg, 18 June 2009

Roger Klose and Matthias Luft presented at Bechtle Security Day in Würzburg. Their talks included a broad spectrum of current topics like "Targeted Attacks" and "Virtual Security". Please note that there's an other event of this series taking place in Frankfurt.

Download the slides here:


ERNW_BechtleSecDay_Virtualisierungssicherheit.pdf (7MB)
ERNW_BechtleSecDay_Targeted_Attacks.pdf (3MB)
ERNW_BechtleSecDay_Sicherheit_in_Produktionsnetzen.pdf (3MB)

F-Secure Customer Event [non-public]

Munich, 18 Mai 2009

Matthias Luft and Daniel Mende gave a lecture on "Hacking Mobile Devices" at an event of F-Secure on 18th May. It featured a series of practical demos. We would be pleased to present the demos to your organization or be supportive with securing your mobile platforms.

Download the slides here:


ERNW_FSecure_Hacking_Mobile_Devices.pdf (3MB)

itsecurity & Troopers09

Munich, 22-23 April 2009

Reversing Malware for business purposes

Speaker: Michael Thumann

This talks covers different ways to analyze malware for business purposes and discusses advantages and disadvantages of the approaches. The most common online sandboxes are introduced and compared to sandbox systems that are built indiviudally. Also the basic requirements and the mandatory tool set are defined for building your own sandbox system. The tool set consists of analyzers, unpackers, debuggers and disassemblers and the talk will also mention the steps that are needed for proper analysis of the malware. Finally the countermeasures of the attackers to defeat the analysis process are presented and also some ways to mitigate them.


All your packets are belong to us - Attacking backbone technologies

Speaker: Daniel Mende, Simon Rich

The year 2008 has seen some severe attacks on infrastructure protocols (SNMP, DNS, BGP). We will continue down that road and discuss potential and real vulnerabilities in backbone technologies used in today's carrier space (e.g. MPLS, Carrier Ethernet, QinQ and the like). The talk includes a number of demos (like cracking BGP MD5 keys, redirecting MPLS traffic on a site level and some Carrier Ethernet stuff) all of which will be performed with a new tool kit made available at the con. It's about making the theoretical practical, once more!

Visit www.troopers09.org for more information, slides & videos.

Black Hat Europe

Amsterdam, 14-17 April 2009

All your packets are belong to us - Attacking backbone technologies

Speakers: Daniel Mende, Enno Rey

The year 2008 has seen some severe attacks on infrastructure protocols (SNMP, DNS, BGP). We will continue down that road and discuss potential and real vulnerabilities in backbone technologies used in today's carrier space (e.g. MPLS, Carrier Ethernet, QinQ and the like). The talk includes a number of demos (like cracking BGP MD5 keys, redirecting MPLS traffic on a site level and some Carrier Ethernet stuff) all of which will be performed with a new tool kit made available at the con. It's about making the theoretical practical, once more!

Additional material:

Check out darkreading.com for an interview with Enno Rey.
Download the tools released with this talk.


ERNW_BlackHatEurope09_all_your_packets.pdf (1MB)
ERNW_White_paper_All_your_packets.pdf (978KB)

IT UNDERGROUND

Prague, 23-25 March 2009

First Day Workshop
Attacking Endpoints

Speakers: Roger Klose, Matthias Luft

This workshop is focused on techniques how endpoints (workstations or laptops) can be owned remotely or when physical access is available. In times of workstations with their CD/DVD drives removed and USB blocked even the latter might not always be an easy task. In the past we performed quite a number of assessments where we had to get the control over some endpoint and we have compiled/developed our own toolset for this purpose. The audience will get a CD with this stuff and will have the opportunity to practice most attacks in the classroom. After a detailed discussion of attacks we will also cover ways how to protect computers against these attacks and various mitigating controls.


Second Day Talk
Reversing Malware

Speakers: Michael Thumann, Michael Schaefer


Third Day Talk
All your packets are belong to us - Attacking backbone technologies

Speakers: Daniel Mende, Simon Rich

The year 2008 has seen some severe attacks on infrastructure protocols (SNMP, DNS, BGP). We will continue down that road and discuss potential and real vulnerabilities in backbone technologies used in today's carrier space (e.g. MPLS, Carrier Ethernet, QinQ and the like). The talk includes a number of demos (like cracking BGP MD5 keys, redirecting MPLS traffic on a site level and some Carrier Ethernet stuff) all of which will be performed with a new tool kit made available at the con. It's about making the theoretical practical, once more!

BASTA! 2008

Mainz, 22-26 September 2008

What a developer can do (wrong) – An architect‘s view

Speaker: Enno Rey


ERNW_BASTA09_what_a_developer.pdf (4MB)

ShmooCon 2009

Washington DC, 6-8 February 2009

All your packets are belong to us - Attacking backbone technologies

Speakers: Daniel Mende, Enno Rey

The year 2008 has seen some severe attacks on infrastructure protocols (SNMP, DNS, BGP). We will continue down that road and discuss potential and real vulnerabilities in backbone technologies used in today's carrier space (e.g. MPLS, Carrier Ethernet, QinQ and the like). The talk includes a number of demos (like cracking BGP MD5 keys, redirecting MPLS traffic on a site level and some Carrier Ethernet stuff) all of which will be performed with a new tool kit made available at the con. It's about making the theoretical practical, once more!


Exploring Novel Ways in Building Botnets

Speakers: Daniel Mende, Enno Rey

Botnets are widely regarded as the most imminent threat to the internet's infrastructure security. While a bot's lifecycle has mostly stayed the same (initial infection, C+C contact, download of payloads/instructions, performance of malicious actions) for some time now, the communication structures are currently undergoing a shift in direction of P2P methods. In this talk we will cover some novel ways in mobilizing well-known and not-so-well-known protocols within botnets. Amongst others we will show how to perform quite efficient DoS attacks without prior OS exploitation and how to abuse some servers run by Microsoft itself for downright untraceable C2 communication and payload distribution.


ERNW_shmocon09_all_your_packets.pdf (1MB)

Ethernet Services Product Evolution

Brussels, 2-4 Febuary 2009

Guaranteeing data and network security in Ethernet networks for business customers

Speaker: Enno Rey


ERNW_ESPE09_security_ethernet_networks.pdf (3MB)

Deepsec 2008

November 11–14, The Imperial Riding School Vienna, Austria

Exploring Novelty Ways in Building Botnets

Speaker: Simon Rich & Daniel Mende

Botnets are widely regarded as the most imminent threat to the internet's infrastructure security. While a bot's lifecycle has mostly stayed the same (initial infection, C+C contact, download of payloads/instructions, performance of malicious actions) for some time now, the communication structures are currently undergoing a shift in direction of P2P methods. In this talk we will cover some novelty ways in mobilizing well-known and not-so-well-known protocols within botnets. Amongst others we will show how to perform quite efficient DoS attacks without prior OS exploitation and how to abuse some servers run by Microsoft itself for downright untraceable C2 communication and payload distribution. Additionally some code for an intelligent agent's "phone home" without direct IP based communication channel will be discussed and released.


ERNW_Novel_ways_to_build_botnets.pdf (4MB)

IT UNDERGROUND

Warsaw, 27-29 October 2008

First Day Workshop
Modern offensive techniques

Speakers: Daniel Mende, Michael Schaefer

Second Day Talk
A first inspection of Microsoft's Hyper-V security

Speakers: Enno Rey & Roger Klose

It is expected that Microsoft's Hyper-V will rapidly gain ground in the ever emerging virtualization market. Still, the crucial question remains: how trustworthy is this piece as for isolation of guests and protection of the hypervisor itself and management interfaces. This talk tries to give a first answer. I will present the design and architectural components of Hyper-V, explain configuration tweaks and pitfalls and discuss hardening steps & tools. Furthermore the results of in-deep security testing of Hyper-V will be published. Some fuzzing demo against various pieces of Hyper-V is included and I will provide a detailed comparison of the security features and potential weaknesses of Hyper-V and VMware ESX.

Third Day Talk
Exploring Novel Ways in Building Botnets

Speakers: Daniel Mende & Simon Rich

Botnets are widely regarded as the most imminent threat to the internet's infrastructure security. While a bot's lifecycle has mostly stayed the same (initial infection, C+C contact, download of payloads/instructions, performance of malicious actions) for some time now, the communication structures are currently undergoing a shift in direction of P2P methods. In this talk we will cover some novelty ways in mobilizing well-known and not-so-well-known protocols within botnets. Amongst others we will show how to perform quite efficient DoS attacks without prior OS exploitation and how to abuse some servers run by Microsoft itself for downright untraceable C2 communication and payload distribution. Additionally some code for an intelligent agent's "phone home" without direct IP based communication channel will be discussed and released.

Meet us at the Systems

21.-24.10.2008 in Munich


ernw_-_datensicherheit_opensource_mschaefer_de.pdf (760KB)

Day-Con II 2008

October 10-12, 2008 / Crowne Plaza Dayton, Ohio

Microsoft's Hyper-V Security

Speaker: Enno Rey

It is expected that Microsoft's Hyper-V will rapidly gain ground in the ever emerging virtualization market. Still, the crucial question remains: how trustworthy is this piece as for isolation of guests and protection of the hypervisor itself and management interfaces. This talk tries to give a first answer. I will present the design and architectural components of Hyper-V, explain configuration tweaks and pitfalls and discuss hardening steps & tools. Furthermore the results of in-deep security testing of Hyper-V will be published. Some fuzzing demo against various pieces of Hyper-V is included and I will provide a detailed comparison of the security features and potential weaknesses of Hyper-V and VMware ESX.

Application Trustworthiness

Speaker: Michael Thumann

This talk covers the different test methodologies to decide if an application can be used securely in a business environment. From blackbox testing, fuzzing, source code review to reverse engineering all the different approaches are explained, that are used by ERNW do conduct these kind of tests in real life. Finally the metric used in the assessments will be presented to give an idea how the results and findings can be used to answer the Question "can we trust this application?" in a comprehensible way.

Exploring Novelty Ways in Building Botnets

Speakers: Daniel Mende & Simon Rich

Botnets are widely regarded as the most imminent threat to the internet's infrastructure security. While a bot's lifecycle has mostly stayed the same (initial infection, C+C contact, download of payloads/instructions, performance of malicious actions) for some time now, the communication structures are currently undergoing a shift in direction of P2P methods. In this talk we will cover some novelty ways in mobilizing well-known and not-so-well-known protocols within botnets. Amongst others we will show how to perform quite efficient DoS attacks without prior OS exploitation and how to abuse some servers run by Microsoft itself for downright untraceable C2 communication and payload distribution. Additionally some code for an intelligent agent's "phone home" without direct IP based communication channel will be discussed and released.

More information


ERNW_DayConII_microsoft_hyperV_security.pdf (904KB)
ERNW_DayConII_application_trustworthiness.pdf (5MB)

ekoparty Security Conference - 4th edition

Buenos Aires, 2-3 October 2008

Exploring Novelty Ways in Building Botnets

Speakers: Simon Rich & Daniel Mende

Botnets are widely regarded as the most imminent threat to the internet's infrastructure security. While a bot's lifecycle has mostly stayed the same (initial infection, C+C contact, download of payloads/instructions, performance of malicious actions) for some time now, the communication structures are currently undergoing a shift in direction of P2P methods. In this talk we will cover some novelty ways in mobilizing well-known and not-so-well-known protocols within botnets. Amongst others we will show how to perform quite efficient DoS attacks without prior OS exploitation and how to abuse some servers run by Microsoft itself for downright untraceable C2 communication and payload distribution. Additionally some code for an intelligent agent's "phone home" without direct IP based communication channel will be discussed and released.

 

Basta! 08

22 - 26 september 2008, Rheingoldhalle Mayence

From Ariane 5 To Sasser – Code security in complex environments

Speaker: Enno Rey

This talk deals with the meaning of software security for complex environments and discusses about the ways of avoiding typical risks at the architecture level. Various methods will be presented which are preventing the execution of untrustwothy or incorrect codes in shared environments. Furthermore showcases will be discussed: how to limit the codes' destructive capicity. The part of priviligies, compartments and capabilites and thier impact on the whole security of the ecosystem is often underrated and disregarded in the development process.

Sofware security testing

Speaker: Michael Thumann

This talk deals with the various software security testing methods. Following topics among others will be raised: Blackbox testing and fuzzing, source code analysis, source code recovery by means of reverse engineering and de-compilation, runtime analysis and manual testing of applications. Furthermore some helpful and necessary tools wil be introduced, which are used during ERNW audits. Finally a few security metrics facillating the results analysis will be discussed.


Michael_Thumann-SecurityTesting.pdf (3MB)

Mobile & Wireless Security Forum 2008

16 – 17 September 2008, Dorint Hotel, Cologne

Forum's chairman: Enno Rey

iPhone - Funky Gadget, Hacker Device or just a Security Risk?
Speaker: Michael Thumann

Apple has launched with its iPhone a multifunctional portable device. The using concept is revolutionary and seduces most of the people. Its Mac OS X based user interface provides the user with nearly inexhaustible enlargement possibilities. Its new software allows the use in big companies and is also a perfect tool for top management. This talk deals with the possibilities and the security risks of the iPhone and describes its use as a business device and as an hacking tool. You will find out if your company is "iPhone ready".


iphone-ernw.pdf (4MB)

IT-Symposium 2008

4 - 5 June 2008 - Sheraton Congress Hotel, Francfort

Speakers:

Enno Rey:
Voice-over-IP, Attacks and Countermeasures

Roger Klose:
Security aspects of virtualization with a focus on VMware ESX
Fuzzing of infrastructure protocols - Methodology, Tools & Results

 

1B05_erey_ss7_security.pdf (1MB)
1B05_erey_voip_risk_analysis.pdf (468KB)
1B05_ernw_voipsec.pdf (3MB)
DECUS_Infrastructure_Fuzzing.pdf (2MB)
DECUS_VirtSec_und_ESX.pdf (3MB)

IIR Windows Forum

03-04 June 2008, Radisson SAS Schwarzer Bock, Wiesbaden

Windows Server 2008 and virtualization in practice

Speaker: Friedwart Kuhn

PKI rollout in a national organisation
• Tasks of the PKI in the organisation
• CA Hierarchy of the organisation
• The rollout
• Technical components
• Organisational components
• Interim result

More information

ComConsult IT-Security-Forum 2008

26.05. - 29.05.08, Francfort

Security aspects of the virtualized environment
Speaker: Roger Klose

• Threats & Vulnerabilities in virtualized environments
• Definition of criteria for a "safe virtualization"
• Virtual appliances & virtual Shields - Concepts & Products
• Overview of measures
27.05.2008, 15:15 Uhr – 16:00 Uhr

Workshop: VMware - Attacks and security measures with attacks live demos
Speaker: Roger Klose

• Attacks overview in VMware environments (specially VMware ESX)
• Discussion about attacks with the participants
• Demo "VM Backdoor“ attacks against management interfaces
• Demo attacks on the nework level
• Classification of mitigating controls (network, storage, management)
• Risk assessment & measures evaluation
28.05.2008, 9:00 - 12:30 Uhr


VirtSec_Training_and_Workshop_v.0.9.2_Vortrag.pdf (3MB)

Metaverse 08

27.05 - 28.05.2008 Karlsruhe / Convention Center

"Hacking Second Life"
Speaker: Michael Thumann
Examining the virtual world of Second Life from an hacker point of view and seeing the risks.
The talks „Hacking Second Life“ is made up of following points:
- Short introduction: Why are attacks against online games and metaverses so interesting for hackers?
- SL Architeckture: how is made the SL architecture?
- Based on Microsoft STRIDE some interesting attacks will be identified
- Analysis of the SL Viewer. Is the idendity of the SL user protected enough; is it possible to cheat?
- Short overview of the architecture's security level of Linden Labs
- Attacks from the virtual world agianst real systems iwith demo
- Are those attacks practicable?
- A short outlook in the future

Troopers08 Hacking Conference

23. & 24. April 2008 / Kempinski Airport Hotel, Munich, Germany

Troopers08 is a Hacking Conference. Its goal is to share in-depth knowledge about the aspects of attacking and defending information technology infrastructure and applications. The featured presentations and demonstrations represent the latest discoveries and developments of the global hacker scene and will provide the audience with valuable practical know-how.
More information.

Hack In The Box Security Conference

14th - 17th April 2008 United Arab Emirates

The main aim of the HITBSecConf conference series is to enable the dissemination, discussion and sharing of deep knowledge network security information. Featuring presentations by respected members of both the mainstream network security arena as well as the underground or black hat community, HITBSecConf2008 - Dubai will see over 20 of the world’s leading network security specialists talk about their latest tools and research.

Speaker: Michael Thumann
Beyond being an online game SecondLife is a growing marketplace for big companies where lot of money is made. And living and acting in a virtual world gives the people the opportunity to do things they would never do in real life. Therefore, it is not surprising that SecondLife has increasingly attracted real world hackers.

The talk will cover the basic architecture of SecondLife and point out the possible attack vectors against SecondLife itself, but will also demonstrate hacks from the inside of SecondLife against real-life systems in the internet. So watch out what virtualization can do for the “Bad Guys”.

IT Security 2008

15 -16.April 2008, Munich

IT Security is nowadays a very important topic. The threats are various and omnipresent.
It is therefore fundamental to be prepared.

Speakers: Roger Klose
Cisco Advanced Hacking

Roger Klose & Gunther Niehues:
Vulnerabilities of virtualization softwares: Hacking VMWare ESX


ERNW_ESX-(In)Security.pdf (5MB)
ERNW_Cisco_Hacking.pdf (3MB)

RSA Conference 2008

April 7-11, San Fransisco

Speaker: Michael Thumann

Reversing - A Structured Approach
For many people Reverse Engineering sounds like magic, but it's yet another methodology to understand what soft- and hardware is doing. This session will cover the methodology and tools that are used in our company to answer very specific customer questions relating to software. Examples will be provided during this session to demonstrate the efficiency of this structured approach.
More information

Notacon 5

4 - 6 April, Cleveland / Ohio

Speakers: Enno Rey & Bryan Fite

Topic: Data Loss Protection - Hope or Hype?

To lose control over one's own data is one of the primal fears of the digital age. More than ever this applies in particular to the world of corporations and organizations with all their trade secrets and peachy marketing plans to be protected from leaking outside. To prevent such leakage is the promise of salvation of a new set of security tools called "Data Loss Protection" or "Extrusion Prevention" solutions. All relevant vendors are already offering such pieces (mostly by acquisition of smaller companies specialized in the field).
This talk will discuss why the approach these solutions take will fail in most environments and which pre-requisites must be fulfilled before even thinking about such a piece. We will further discuss on a structural level how individuals and organizations can use the existing tool set of the infosec space to protect their sensitive data.
More information

Black Hat Europe 2008 Briefings & Training

March 25-28, Moevenpick City Centre / Amsterdam, Netherlands

The Black Hat Briefings are a series of highly technical information security conferences that bring together thought leaders from all facets of the infosec world – from the corporate and government sectors to academic and even underground researchers. The environment is strictly vendor-neutral and focused on the sharing of practical insights and timely, actionable knowledge.

Speaker: Michael Thumann
Hacking Second Life
Beyond being an online game SecondLife is a growing marketplace for big companies where lot of money is made. And living and acting in a virtual world gives the people the opportunity to do things they would never do in real life. Therefor it is not surprising that SecondLife has increasingly attracted real world hackers. The talk will cover the basic architecture of SecondLife and point out the possible attack vectors against SecondLife itself, but will also demonstrate hacks from the inside of SecondLife against real-life systems in the internet. So watch out what virtualization can do for the "Bad Guys".

Telecoms Fraud & Network Security

Mon 10 Mar 2008 - Thu 13 Mar 2008 / Hilton Amsterdam, Amsterdam, Netherlands

This intensive conference will provide a senior level and exclusive knowledge sharing forum for fixed and mobile network operators from across the globe, providing you with critical business information to radically reduce fraud and network security threats. IIR’s annual event has long been considered the leading telecoms fraud conference and year on year attracts a formidable number of network operators enabling attendees to network and build excellent contacts with senior telecoms fraud and security professionals.

Speaker: Enno Rey
Topic: Developing Strategies To Protect SS7 From Manipulation And Abuse


erey_ss7_security_v07.pdf (1MB)

IT Underground 2008

27.02 - 29.02 Hotel STEP, Prague, Czech Republic

Speakers:
Daniel Mende and Oliver Roeschke
Advanced Network Security

Enno Rey
Data Loss Protection - Hope or Hype?

Daniel Mende and Simon Rich
The Art of Protocol Fuzzing


erey_dlp_hype_hope_v091.pdf (975KB)

ShmooCon Hacker Convention

February 15-17, 2008 / Wardman Park Marriott Hotel, Washington DC

ShmooCon is an annual East coast hacker convention hell-bent on offering three days of an interesting atmosphere for demonstrating technology exploitation, inventive software & hardware solutions, and open discussions of critical infosec issues.

Speakers: Enno Rey and Daniel Mende
Advanced Protocol Fuzzing - What We Learned when Bringing Layer2 Logic to "SPIKE Land"
The talk is based on a research project whose goal was to evaluate the security of network devices used in carrier space. After some (very short) introduction into the main concepts of fuzzing (in particular of network protocols) we will explain which options of existing fuzzers and frameworks we found and why we finally chose SPIKE. Given SPIKE has no Layer2 functionality by default we were forced to write some additional modules like a (libnet-based) generic Layer 2 packet generator and lots of SPK-scripts for different protocols. We will describe this development process, the pitfalls and lessons learned. Furthermore we will release all the code and discuss the results of performing extensive fuzz-testing of network devices and some common operating systems.

Tech Forum: "Desktop Virtualization and Thin Client Computing"

22.01.2008, Munich, Holiday Inn Munich-City Centre

High Security Duo SBC and Thin Clients

Speaker: Roger Klose

Security and compliance aspects on server and client side. Higher security and easier compliance to legal regulation with SBC and TCs; data management entirely based on server vs. local storage, VPNs, Identity-Management with Tokens/Smartcards, PKI, use of ADS, USB port safety, Spyware prevention.

 
Talk of Roger Klose
SBC_und_ThinClients_V15_RK.pdf (1MB)

Konradin Congress: "Technical Information for the health care"

05.12.2007, Düsseldorf, Radisson SAS Scandinavia Hotel Düsseldorf

Speaker: Enno Rey
Topic: Secure WLAN meeting the requirements of the data protection

The PDAs and notebooks of the doctors and of the hospital staff facilitate and improve the patient care and make sure that the medical staff always get important information. The WLAN technique has to be extremely reliable in order to fulffill the high requests of the medical institutions. In this conference you will learn in what way the technical level conforms to these requirements.

 

Laboratoy-IT Forum, 04-05. December 2007

Holiday Inn Heidelberg

Future Trends of laboratory IT

Wireless Local Area Network (WLAN) - The Wireless Networked Laboratory
- WLAN - Mobility support in the laboratory
- Is WLAN a better solution than a complex and expensive cable-bound net?
- Security aspect - Is WLAN more vulnerable than the cable-bound net?

Solution congress "IT-security for people"

04.12.2007, Düsseldorf, Radisson SAS Scandinavia Hotel Düsseldorf

Topics:

- People and IT-security
- Awareness campaigns
- Indentity management
- Network Access Control
- Industrie espionage

Security Education Conference Toronto (SecTor)

Nov 20 / 21, 2007

Speaker: Dror-John Röcher & Michael Thumann
Topic: Attacking Cisco Network Admission Control

Solution congress: "virtualization"

12.11.2007, Munich, Hotel Hilton City München

Speaker: Enno Rey
Virtualization security

According to recent surveys, half the IT managers project to virtualize wide parts of their computer centers within the next 12 months. Meanwhile 43 % of them worry about the security. In this conference, you will learn what securiy risks may result from the virtualization. Vulnerabilities and contermeasures will be discussed with the example of important commercial solutions and concrete attack settings will be demonstrated.

 

IT Underground 2007

7.11 - 9.11. Warsaw

Advanced Network Security
Speakers: Enno Rey, Daniel Mende

This conference focuses on the realisation of IT Security in the level of network-infrastructure. Usually Security is implemented at single points of a network (eg. at firewalls or on important servers). The perspective from an network-infrastructure often is uncared-for. The growing complexity of network-structures brings along many risks for secure traffic and high availability. You will learn what kind of dangers there are on a network level and how efficient security-measures can be implemented.

Securing Linux and FreeBSD webservers with kernel based security mechanisms
Spekers: Enno Rey, René Graf

What History can Tell us - An Introduction to Multi Level Security
Speaker: Enno Rey


erey_mls_v09.pdf (2MB)

Meet us at the Systems

23.10. - 26.10.2007 in Munich

Michael Thumann "Second Life Hacking" at the Systems.
Hacking2ndLife-en_ger.pdf (805KB)

NextGen CyberCrime

22.-25. Oktober 2007, Singapore


erey_carriers_cybercrime.pdf (755KB)
erey_network_security.pdf (845KB)

Day-Con 2007

12.-14. Oktober 2007, Dayton USA

Speaker: Enno Rey
Topic: Advanced Protocol Fuzzing - What We Learned when Bringing Layer2 Logic to
"SPIKE Land"

The talk is based on a research project whose goal was to evaluate the
security of network devices used in carrier space.
After some (short) introduction into the main concepts of fuzzing (in
particular of network protocols) we will explain which options of existing
fuzzers and frameworks we found and why we finally chose SPIKE. Given SPIKE
has no Layer2 functionality by default we were forced to write some
additional modules like a (libnet-based) generic Layer 2 packet generator
and lots of SPK-scripts for different protocols. We will describe this
development process, the pitfalls and lessons learned. Furthermore we will
release all the code and discuss the results of performing extensive
fuzz-testing of network devices and some common operating systems.


erey_virtualization_v099r.pdf (879KB)
l2_fuzzing_v099r.pdf (522KB)
Hacking2ndLife-en.pdf (805KB)

Carrier Ethernet World Congress

24.-28. September 2007, Geneva

Speaker: Enno Rey
28. September
Topic: Understanding and mitigating the security issues for Ethernet-based networks and services

Conference Enno Rey
erey_security_ethernet_services.pdf (724KB)

Conference: Security Eye 2007

18. September 2007, Francfort

Topic: Vulnerability Scoring with CVSS 2.0

Speaker: Dror-John Röcher

Der transparenten und nachvollziehbaren Bewertung von Schwachstellen kommt
nicht nur durch Compliance-Anforderungen eine ständig wachsende Bedeutung
zu. Auch für effizientes Patchmanagement ist die korrekte Bewertung von
Schwachstellen ausschlaggebend. Zum einen hat CVSS mit der kuerzlich
erschienen Version 2.0 qualitativ einen grossen Schritt in die richtige
Richtung getan, zum Anderen kristallisiert sich CVSS als kommender,
herstellerunabhaengiger Standard zur Bewertung von Schwachstellen heraus.
Ziel des Vortrags ist neben der Vorstellung und Diskussion von CVSS 2.0 eine
Erörterung in welchen Szenarien und unter welchen Randbedingungen der
Einsatz von CVSS sinnvoll möglich ist.


cvss-patch02x.pdf (2MB)

Wireless & Mobile Security 2007

17.-19. September 2007, Cologne

Topics:
- Bluetooth Hacking
- Spying and sabotage by radio network
- Blackberry-Security
- Encryption and communication security
- Security aspects from mobile operating systems

You can meet there our specialists Enno Rey, Michael Thumann and Dror-John Röcher, you can find more information here.


sdn2007-04x.pdf (3MB)

ISACA - Network Security Conference

10.-12.09.2007, Las Vegas

Topic: Network Security on Layer 2 and 3 (12.09.2007, 11:00-12:30 Uhr)
Speaker: Enno Rey

HITBSecConf2007

03.-06.09.2007, Malaysia

Topics: Attacking Cisco Network Admission Control – NAC@ACK
Speakers: Michael Thumann & Dror-John Röcher

The last two years have seen a big new marketing-buzz named “Admission Control” or “Endpoint Compliance Enforcement” and most major network and security players have developed a product-suite to secure their share of the cake. While the market is still evolving one framework has been getting a lot of market-attentiont: “Cisco Network Admission Control”. NAC is a pivotal part of Cisco’s “Self Defending Network” strategy and supported on the complete range of Cisco network- and security-products. From a security point of view “NAC” is a very interesting emerging technology which deservers some scrutiny. The Cisco NAC solution contains two major design-flaws which enable us to hack (at least) two of the three different variants using some kind of “posture spoofing attack”. We will demonstate code & tool for posture spoofing in Cisco NAC secured networks.


D1T1-MichaelThumannandDror-JohnRoecher-HackingCiscoNAC.pdf (4MB)

BlackHat USA, 2007

01.-02. August 2007, Las Vegas

Topic: NACATTACK
Speakers: Dror-John Röcher & Michael Thumann

Part I: Introduction—Marketing Buzz:
The last two years have seen a big new marketing-buzz named "Admission Control" or "Endpoint Compliance Enforcement" and most major network and security players have developed a product-suite to secure their share of the cake. As the market is still evolving and one framework has been quite successful on the market: "Cisco Network Admission Control". NAC is a pivotal part of Cisco’s "Self Defending Network" strategy and supported on the complete range of Cisco network- and security-products. From a security point of view “NAC” is a very interesting emerging technology which deservers some scrutiny. We are able to hack the Cisco NAC-solution by exploiting a fundamental design flaw.

Part II: NAC Technology—How it works:
The basic idea behind Cisco NAC is quite simple: Before allowing a client admittance to the network the client is tested against a predefined set of “policies”. These tests are performed by a backend system (a Cisco ACS) which processes .credentials supplied by the client against one or more administrator-defined policies. Based on the result of these tests a client is categorized and a well-defined access-level to the network is granted. While the client is connected to the network it is repeatedly rechecked and the state of the client is reassessed. On a somewhat more technical layer the communication takes place using EAP over UDP with undisclosed Cisco-proprietary EAP messages and the UDP connection itself is secured using SSL. The connection-point to the network (e.g. the switch, wireless AP, Firewall, Router, etc.) acts sort of as a "translating proxy" between the client talking EAPoU and the Cisco Secure ACS server talking RADIUS [Client <-EAPoU-> Switch <-RADIUS-> ACS). Besides this "proxy"-functionality the connection-point also acts as an enforcing element of the security policy. Three somewhat different deployment flavours of Cisco NAC exist but the underlying concept “admittance-level based on the result of a test” is always the same.

For every .NAC-enabled application on the client a client-side agent provides so called “credentials” to the ACS server where they are compared against the defined tests to derive a “posture token” per application. From all application posture tokens an overall “system posture token” is inferred which determines the access-level granted to the client. The client-side agent of the framework responsible for the communication is the “Cisco Trust Agent” (CTA) which also includes the capability to report a few basic credentials (e.g. OS Version, Hostname, etc) without an additional NAC-enabled application. The CTA contains an API enabling third-party vendors to hook their applications into the NAC framework. Anti-Virus Vendors have been among the first to join the NAC-Alliance formed by Cisco.

Part III: The Problem—NAC is not “secure by design”:
The Cisco NAC solution contains at least one major design-flaw which enables us to hack (at least) two of the three different variants: The server authenticates itself to the client using a server-certificate and client and server establish a secure tunnel (something like “SSL over UDP”), but the client does not authenticate itself to the server, so we have a situation in which a component (the client) is authorized without prior authentication. After realizing this fundamental design-error, the idea of a “posture spoofing attack” was born and research started with evaluating different attack-vectors for their feasibility. In the end we decided to analyse the protocols used within the framework and code our own “NAC-client” which provides the ACS with attacker-supplied-credentials in order to get illegitimate access to NAC-secured networks.

Part IV: The Hack—how we did it
NAC is a complex system involving different protocols which are used in an odd combination. Especially the usage of SSL over UDP/EAP-FAST over UDP made the usage of SSL-Proxies for man-in-the-middle attacks or clear-text-traffic-analysis with standard methods impossible. So instead of focusing on the network-traffic (which was our first approach—“stare at the packets until you understand them”), we decided to focus on the client first. Analysing the CTA client in different versions and on different operating systems revealed some of the inner workings of the protocols. Besides “Client analysis” we built a NAC test-lab and developed a “NAC-test-suite” to implement different “admission-scenarios”. While running theses tests we hooked into the interesting functions of the client in order to understand the functions used and their (inter)dependencies. As a next step we started coding our own NAC client to get a better insight into the communication process. The first goal was to get a clear text dump of the communication by establishing the secure tunnel. The next goal was to provide our own credentials to the ACS in order to get access to the NAC protected network. We will release our "NAC-Credential-Spoofing"-tool at the conference alongside with our insight into the operating of NAC.

Part V: Our proposed talk
We do not wish to simply release a tool; we want the audience to understand how Cisco NAC works, why it is not as secure as Cisco wants us to believe and which mitigations exist, if NAC is implemented (there actually exist mitigations and secure setup-approaches). We will present our approach, disclose technical details yet unpublished and release our tool. As an “add-on”-benefit we will explain how to tackle a complex system like NAC when doing security research.

Dror-John Roecher has enjoyed working with Cisco stuff for more than eight years and is usually busy assessing the security of enterprise networks and data-centers. He works as a senior security consultant for germany-based ERNW GmbH all over Europe and has published multiple whitepapers on security-related topics. He is a seasoned speaker and enjoys sharing his experience with his audience.

The last two years have seen him develop additional points of interests, as e.g. “Mobile Security” [he simply loves to play around with all the newest funky gadgets] and “Endpoint Security”—but at the heart he still is a networker.

Michael Thumann is Chief Security Officer and head of the ERNW "Research" and "Pen-Test" teams. He has published security advisories regarding topics like 'Cracking IKE Prshared Keys' and Buffer Overflows in Web Servers/VPN Software/VoIP Software. Michael enjoys sharing his self-written security tools (e.g. 'tomas—a Cisco Password Cracker', 'ikeprobe—IKE PSK Vulnerability Scanner' or 'dnsdigger—a dns information gathering tool') and his experience with the community. Besides numerous articles and papers he wrote the first (and only) german Pen-Test Book that has become a recommended reading at german universities. In addition to his daily pentesting tasks he is a regular conference-speaker and has also contributed exploit code to the Metasploit Framework. With more than 10 years of experience in computer security Michaels' main interest is to uncover vulnerabilities and security design flaws from the network to the application level.

Tech Forum: "IT-Services und -Strategie/ IT Service Management"

28. Juni 2007, München

Topic: "Captain, Eisberg voraus" - Was wir von der Titanic über Incident Response Prozesse lernen können.
Speaker: Friedwart Kuhn

 

IIR Forum "IT-Sicherheit in der Produktion"

27.-28.06.2007, Stuttgart

Vortragsthema: Wireless LAN in der Produktion (27.06.2007 14:15-15:00 Uhr)
Firewalls in der Industrie- und Produktionsumgebung (27.06.2007 16:15-17:00 Uhr)
Referent: Dror-John Röcher

- Segmemtierung von Produktionsnetzen
- Aktueller Stand WLAN-Security - Angriffsmethoden & Sicherheits- Technologien, Protokolle
- Managed vs. unmanaged Access Points, Produkte und Sicherheits-Diskussion
- WLAN-Design und -Segmentierung* Managed vs. unmanaged Access Points, Produkte und Sicherheits-Diskussion
- WLAN-Design und -Segmentierung
- Access Point Security - Hardening und sicherer Betrieb
- Wichtige Prozesse (Rollout, Management, Intrusion Detection)
- Neue Ansätze, Protokolle, Probleme
- Einsatz von Firewalls


Vortragsthema: Firewalls in Industrie- und Produktionsumgebung
Referent: Dror-John Röcher

* Sicherheit in den Produktionsnetzen
* Unterscheiden sich Produktionsnetzwerke stark von Büro-Netzwerken?
* Anforderungen an die Komponenten
* Praxisbeispiel: Einführung von Firewalls in einer großen, dezentralen Produktionsumgebung


Workshop: Risiko-Analyse als Werkzeug zur effizienten Steuerung von IT-Sicherheit (29.06.2007 9:00-17:00 Uhr)
Referent: Enno Rey

- Methoden und Tools
- Anwendungsszenarien und Beispiele aus der Praxis
- Notwendige Tabellen und Checklisten

 
Download des Vortrags "Firewalls für die Produktion - ein Erfahrungsbericht"
industrial-firewall-0.4dr.pdf (5MB) Download des Vortrags "Wireless LANs in der Produktion"
industrial-wlan_01dr.pdf (5MB)

Tech Forum

20.-21. Juni 2007, Düsseldorf

Topic: Firewalls in Industrie- und Produktionsumgebung
Speaker: Dror-John Röcher

 

IIR Windows Forum

18.-21. Juni 2007, Köln

Speaker: Friedwart Kuhn
Windows Vista Security
UAC and Mandatory Integrity Control (MIC)
BitLocker
Services Hardening
Code-Integrity
Internet Explorer
Auditing

 

Solution Kongress "VoIP"

14. Juni 2007, München

Topic: VoIP Security
Speaker: Roger Klose

Hier der Vortrag von Herrn Klose zum Download.
ernw_voip_assessment_rk.pdf (3MB)

Tech-Forum Industrial Ethernet/Security

12.-13. Juni 2007, Stuttgart

Topic: Industrial Firewalls
Speaker: Dror-John Röcher

(in German)
ERNW_Industrial-Firewall-03dr.pdf (4MB)

Solution Kongress "Security"

23.-24. Mai 2007, München

Vortragsthema: tba
Referent: tba

 

TRISC

15.-17. Mai 2007, Austin

Topic: SNMP, Routing Security (16 May 2007)
Speaker: Enno Rey

 

ComConsult ITSF 2007

07.-10. Mai 2007, Königswinter

07 May 2007: "Sicheres Netzwerk-Management", Speaker: Enno Rey
08 May 2007 "MPLS-Sicherheit", Speaker: Enno Rey

 

FutureNet

April 30 - May 3, New York

MPLS Security Methodology
Speaker: Enno Rey

Are They Secure? How to Assess MPLS Providers From a Customer Perspective?

One of our clients, a multi billion revenue corporation with HQ in New York is currently in the course of a world wide network migration to MPLS based structures. Given the absolute priority of information security at our client and against the background that MPLS-VPNs are not regarded as a "trustworthy technology" in itself an internal evaluation methodology was developed to rate the eligible carriers as for their security/trustworthiness. This methodology consists of detailed questionnaires delivered to the carriers, extensive lab testing together with carrier personnel and on-site reviews. During the talk the methodology and some of the results will be presented and discussed. We will share our experiences and learning curve with the audience. Service providers will learn what security-sensitive customers will expect from them and enterprise people will get an idea how to conduct such an assessment.

 

ernw_are_they_secure.pdf (547KB)

NOTACON

27.-29. April 2007, Cleveland, OH, USA

Topic: "Kid Tracking" (28.04.2007, 11:00 Uhr)
Speaker: Enno Rey
Abstract:
"RFID technology has many (ab-) uses. Amongst them are so called localization services that permit to inventory cattle or to detect lost kids in theme parks. The same approach can also be found in GPS-based tracking services used to follow movements of delinquents on probation. On the other side these techniques seem pretty appealing for parents desiring to track their children to prohibit kidnapping or to locate them after accidents. Several questions quickly arise though: when should such a .track your kid. thing be applied, when . if ever . removed? Do we really want to put our children in the panopticon Michel Foucault describes in .Discipline and Punish.? In which way must we re-think our own responsibilities? The talk will give an overview of the tools involved and their current state-of-implementation. Using some risk analysis method I will then illustrate potential problems (security-/privacy-wise) and discuss the social implications of this technology."

 

IT-Security 2007

18.-19. April 2007, München

Speaker: Roger Klose
Workshop-Topic: Sicheres Netzwerk-Management (18.04.2007)


Speaker: Dror-John Röcher
Topic: "Segen oder Fluch? - Cisco Network Admission Control" (18.04.2007)

 
Presentation Routing-Security, Dror-John Röcher
itsecurity07_routing_sec_dr_02.pdf (538KB) Presentation MPLS-Security, Roger Klose (in German)
itsecurity07_mpls_sec_rklose.pdf (859KB) Presentation NAC - Segen oder Fluch, Dror-John Röcher (in German)
itsecurity07_NAC-Segen_oder_Fluch_01_dr.pdf (1MB)

DECUS Symposium 2007

16.-20. April 2007, Nürnberg

Topic: Sicheres Netzwerk-Management (16.04.2007, 9:00-17:00 Uhr)

Speaker: Enno Rey

 

Hack in the Box Security Conference 2007

02.-05.April 2007, Dubai

Topic: "Digging into SNMP 2007 - An Exercise on Breaking Networks" by Enno Rey


ERNW_026_SNMP_HitB_Dubai_2007.pdf (383KB)

BlackHat Europe 2007

29.+30. März 2007,Amsterdam

Topic: "NAC@ACK" (30.03.2007)
Speaker: Michael Thumann + Dror-John Röcher

Abstract:
The last two years have seen a big new marketing-buzz named "Admission Control" or "Endpoint Compliance Enforcement" and most major network and security players have developed a product-suite to secure their share of the cake. While the market is still evolving one framework has been getting a lot of market-attentiont: "Cisco Network Admission Control". NAC is a pivotal part of Cisco?s "Self Defending Network" strategy and supported on the complete range of Cisco network- and security-products. From a security point of view ?NAC? is a very interesting emerging technology which deservers some scrutiny. The Cisco NAC solution contains two major design-flaws which enable us to hack (at least) two of the three different variants using some kind of ?posture spoofing attack?. We will release updated code & tool for posture spoofing in Cisco NAC ?secured? networks.

 
NAC@ACK Paper zur BlackHat Amsterdam 2007
ERNW_nacattack_10_dr_20070307.pdf (1MB) NAC@ACK Präsentation BlackHat Amsterdam 2007
bh07-europe_nacattack_03.pdf (2MB)

Reaction: here´s the reply from Cisco

IT-Underground 2007

07.-09. März, Prag

Enno Rey: "Digging into SNMP in 2007 - an exercise on Breaking Networks"

Dror Roecher: "Routing Protocol Security - Still a problem?"

PANEL DISCUSSION: "Why bother with security?"

leader : Enno Rey

co-leaders: Fyodor Yarochkin, Michael Kemp, Renaud Bidou, Shawn Merdinger, Raoul Chiesa, Alexander Kornbrust, Dror Roecher, Angelo Rosiello
ospf-sec_02_dr.pdf (732KB)
ospf-ash.zip (4KB)

IT-Underground 2006, Warsaw

26-27 September 2006

Enno Rey: "MPLS-Security
ITU2006_mpls2.pdf (1MB)

Lanline & Computer Zeitung Solution Kongress

11. Juli 2006, München

Topic: Hacking VoIP or fun and profit Speaker: Enno Rey & Michael Thumann
ERNW_Hacking_VoIP_Security_2006.pdf (618KB)

Lanline und Computer Zeitung Solution Kongress Security "Sichere IT im Spannungsfeld von Cyberkriminellen und gesetzlichen Anforderungen"

18. Juli 2006, München

Topic: WLan Security Speaker: Enno Rey
ERNW_019_WLAN_Security_2006.pdf (796KB)

Lanline und Computer Zeitung Tech-Forum "E-Mail, Messaging und Collaboration"

23. Juni 2006, München

"Die Blackberry Security Diskussion – Aufarbeitung und Bewertung" von Dror-John Röcher
ERNW_003_BlackberrySecurity_dr_05_2006.pdf (1MB)

Black Hat Europe 2006

02.-03. März 2006

Die Black Hat Europe 2006 fand in Amsterdam statt. In diesem Rahmen hat Enno Rey den Vortrag MPLS and VPLS Security gehalten.
ERNW_mpls_vpls_sec.pdf (1MB)

Techforum "COMPLIANCE - Rechtskonformer und datenschutzgerechter IT-Betrieb"

06.-07. Februar 2006, München

Unser Mitarbeiter Dror-John Röcher hat dort den Vortrag "Werkzeuge zur technischen Umsetzung von Security Compliance" gehalten.
ERNW_Compliance.pdf (1MB)

IIR Security Forum 2005

"Self-Defending Networks" von Dror-John Röcher
ERNW_Self-Defending-Networks.pdf (1MB)

AWI Events VoIP Kongress

November 2005, Düsseldorf

Sicherheitsaspekte der IP-Telefonie, Hacking VoIP
ERNW_VoIP_Sec_AWI_11_2005.pdf (875KB)

Konradin Events Tech-Forum "Netzwerkmanagement"

Oktober 2005, Neuss

"Netzwerk-Segmentierung und -Sicherheit" von Enno Rey
ERNW_Netzwerksicherheit_und_vlans.pdf (1MB)

AWI Events Roadshow IT-Lösungen Mittelstand & VoIP Kongress

September & November 2005

Erfahrungsbericht & Implementierung einer OpenSourceVoIP-Lösung mit Asterisk von Frank Dölitzscher.
ERNW_VoIP.pdf (855KB)

AWI Events Solution Kongress Security

18.-19. April 2005, Neuss

Ein Vortrag über mögliche Bedrohungen in TS/Citrix-Umgebungen, typische Schwachstellen, Angriffe gegen Microsoft Terminal Services, Angriffe gegen Citrix Metaframe/PS, Gegenmassnahme von Enno Rey
ERNW_CitrixSecurity.pdf (375KB)

AWI Events Solution Kongress Security

November 2004, München

Sicherheit per Quarantäne - Moderne Ansätze beim Design sicherer Netze von Enno Rey.
ERNW_Quarantaene.pdf (268KB)

Dominick Baier

Applikationssicherheit

Ein Vortrag, der Ihnen die aktuellen Sicherheitsproblematiken (u.a. Cross-Site Scripting, SQL-Injection, Parameter Tampering, Permission Management, Buffer Overflows) bei Webapplikationen vor Augen führt (in englischer Sprache)
ERNW_ApplicationSecurity.pdf (233KB)

Dominick Baier

Hackproofing IIS6

Dieser Vortrag von Dominick Baier befasst sich mit dem Härten von IIS6 Webservern durch zielgerichtetes Hacking (Pentesting)
ERNW_Hackproofing_IIS6.pdf (84KB)

IIR-Security

Herbst 2004

Ein Vortrag von Enno Rey über RFID Security.
ERNW_RfidSecurity.pdf (267KB)

Michael Thumann & Enno Rey

PSK Cracking using IKE Aggressive Mode

Dieses Papier entstand als Proof of Concept, um zu demonstrieren, daß schwach gesicherte VPNs vergleichsweise einfach anzugreifen sind. Download links zu den Hinweisen der Herstellern: http://www.checkpoint.com/ http://www.cisco.com/
pskattack.pdf (166KB)

Lanline Tech Forum

14.-15. November 2004, Neuss

In diesem Rahmen hielt Enno Rey den Vortrag "Sicherheitsprobleme IPsec-basierter VPNs und die technische Realisierung von SSL-basierten VPNs" Hier skizzierte er typische Sicherheitsprobleme IPsec-basierter VPNs und führte anschließend in die zugrunde liegenden Techniken SSL-basierter VPNs ein, um diese im Vergleich zu bewerten.
ERNW_IPSec.pdf (365KB)

Dominick Baier

Rollen-basierte Sicherheit mit Microsoft Authorization Manager

Dieser Vortrag entstand im Rahmen des IIR Windows Forums 2004. Der Microsoft Authorization Manager ist eine neue Betriebssystem-Komponente von Windows 2003. Er enthält eine Programmierschnittstelle für Anwendungen um leichter Autorisierungs-Entscheidungen treffen zu können. Das Archiv enthält die Folien im PDF Format sowie einem Beispiel XML Authorization Store.
Rollen-basierteAnwendungs-SicherheitmitMicrosoftAuthorizationManager.pdf (520KB)

Dominick Baier

Terminal Services über OpenSSh PDF

Dieses Papier beschreibt das Konzept und die Implementierung zum Tunnelung von Microsoft Terminal Services über OpenSSH.
sshts.pdf (959KB)

Enno Rey & Michael Thumann

Penetrationstests - Herausforderung Sicherheit

Auf einem Sicherheitsforum gehalten, zeigt dieser Vortrag die Vorgehensweise bei einem Penetrationstest. Als Beispiel wird der komplette Hack eines Microsoft IIS4 Webservers schrittweise erklärt
pen-test.pdf (2MB)

Enno Rey & Martin Freiss (atsec)

Firewall-1 mit SecuRemote u. OpenSSL als CA

Dieses Papier wurde im November 2001 im Zuge eines Projektes von Martin Freiss und Enno Rey gemeinsam erstellt und beschäftigt sich mit der Authentifizierung von SecuRemote Clients mit Hilfe von OpenSSL Zertifikaten
fw1-openssl.howto.pdf (19KB)

Enno Rey

VPN zwischen Cisco Routern und W2K Clients

Dieses Papier entstand als Ergebnis einer großen IPSec Studie mit dem Ziel VPNs ohne den Einsatz zusätzlicher Produkte zu implementieren. Software Voraussetzungen sind lediglich Cisco IOS mit IPSec und Windows 2000
ipsec1.pdf (677KB)

Michael Thumann

GRE Tunnel über IPSec mit Cisco Routern

Dieses Paper ist das Ergebnis einer Kundenanforderung, Implementierung des Protokolles IPX in ein IPSec basierendes VPN über das Internet. Auch andere Protokolle können über GRE transportiert werden, so daß IPX hier lediglich als Beispiel zu verstehen ist.
gre-ipsec.pdf (175KB)

Enno Rey & Michael Thumann

Mobile Security

Dieser Auf einem Sicherheitsforum gehaltene Vortrag beschäftigt sich mit der Sicherheit Mobiler Endgeräte bzgl. VPNs (Virtual private Networks) .und Wireless LANs.
mobilesecurity.pdf (392KB)

TROOPERS12 takes place in March, 29th - 23rd, 2012 in Heidelberg. Mark your calendars now and sign up for the official TROOPERS newsletter to stay up-to-date. [More]
Testing IT security is one of the core competences of ERNW. Many of our customers get their IT infrastructure and (Web) applications checked on a regular basis. This may either be done on a very technical level in terms of penetration testing or in a more formal way in terms of general security audits, during which we verify the IT Security Compliance of your company compared to best practices according to ISO17799/ISO27001 ... [More]
Research is the foundation of our Know-How leadership. The objections of this work is to unveil security flaws and vulnerabilities in protocols, technologies and products. Some findings derive from design-flaws, some from poor implementation on a technical level.... [More]