ERNW News

Newsletter 37 / November 2011

Security Reflections on Multifunction Devices

This Newsletter is a follow-up on the talk ERNW's experts Michael Schaefer and Matthias Luft gave on this year's TROOPERS11 conference in Heidelberg. They focused on developing a guideline for secure operation and reducing risk of Multifunction Devices (MFD) in a corporate environment. This newsletter describes how Michael and Matthias approached the topic of MFD security, which results they ended up with and what they recommend in order to increase the security level of MFDs within a corporate environment.


ERNW_Newsletter_37_Security_Reflections_on_MFDs_en.pdf (491KB)
ERNW_Newsletter_37_Security_Reflections_on_MFDs_en_signed.pdf (562KB)

Newsletter 36 / October 2011

Certificate Based Device Authentication with iOS Devices

Mobile device like iPhones and iPads are used more and more often in corporate environments. Companies not supporting such devices find their users unhappy and doing all kinds of silly stuff like forwarding confidential data to free email accounts to be able to access them on their private iOS devices. The pressure on the IT departments to support these devices in an official way grows from day to day.
To integrate those devices into the corporate environment a lot of use cases require access to internal resources. Those devices basically have two ways to connect to a corporate network: WLAN and VPN connections. WLAN is a wireless technology and a VPN typically can be accessed over the InternetInternetInternet – also a very insecure network.
In order to protect the internal corporate network, strong authentication mechanisms are required. Thus all devices must support these authentication methods.
Using cryptographic authentication methods, such as client certificates, can fulfill the need for a strong authentication mechanism.
This newsletter shows how certificates can be used for device authentication on iOS devices.


ERNW_Newsletter_36_Cert_for_iOS_en.pdf (851KB)
ERNW_Newsletter_36_Cert_for_iOS_en_signed.pdf (908KB)

Newsletter 35 / July 2011

Web Application Firewall Security and The Swiss Army Knife for Web Application Firewalls

This newsletter gives a short introduction to Web Application Firewalls and explains ways and methods to fingerprint and bypass WAFs. In addition, a new tool called tsakwaf will be released and covered in this newsletter which main purpose is to help testing the detection capabilities of a WAF.


ERNW_Newsletter_35_WAF_en.pdf (603KB)

Newsletter 33 / September 2010

Using the iPad in Corporate Environments

This newsletter gives an overview of the relevant threats the iPad introduces into the corporate IT environment. It includes a risk assessment based on ERNW’s Rapid Risk Assessment approach and makes recommendations for secure operation of Apple’s recent gimmick. Also there are some security relevant improvements described, that are introduced in iOS 4 for iPad (should be during the last quarter of 2010)

Because iPad and iPhone use the same operating system family, most of the things shown here apply to both of them.


ERNW_Newsletter_33_iPad_de.pdf (500KB)
ERNW_Newsletter_33_iPad_signed_de.pdf (587KB)
ERNW_Newsletter_33_iPad_en.pdf (477KB)
ERNW_Newsletter_33_iPad_signed_en.pdf (563KB)

Newsletter 32 / August 2010

Application Virtualization as a Browser Security Control?

To contribute to the discussion whether application virtualization can help to mitigate browser based security risks we’ve performed some tests with an application virtualization solution (VMware ThinApp). The goal of the tests was to determine whether exploits can be stopped from causing harm if they happened within a virtualized deployment, which modes of deployment to use, which additional tweaks to apply etc.
This newsletter describes the test cases and results and might thereby help to have a basis for well-informed decisions when it comes to the deployment of an application virtualization technology.

Download Newsletter 32 here, browse the archive or sign-up for further ERNW newsletters.

 

Download Loki

Layer 3 Security Testing Tool

Head over to our tools section to download presentation, tools and other stuff regarding our latest Blackhat USA talk.

Please visit NetworkWorld.com to read an article about the tool.

ERNW @ Black Hat USA

Releasing 'Loki'

Five years after the release of 'Yersinia' at Black Hat Europe 2005 ERNW is taking the same approach to a different network layer.

We're calling it 'Loki' after the god from Norse mythology. It will feature a Python based framework implementing many packet generation and attack modules for Layer 3 protocols, including BGP, LDP, OSPF, VRRP and quite a few others. This tool will see the light of the day at Black Hat USA 2010.

You'll find the tool here after the presentation on 28th of July 2010. More information here.

TROOPERS10

Presentatios & Videos available

Please visit www.troopers.de to browse all the presentation slides from TROOPERS10 IT-Security Conference. Additionally you find some videos of the talks at www.viddler.com/TROOPERS ready to stream.

Newsletter 31 / June 2010

Secure Configuration of Microsoft Internet Explorer, Version 8

This newsletter evaluates configuration options, reflecting security and possible usability impact, incorporating typical large scale enterprise usage of browser based content. The evaluation was done for a globally operating enterprise.


ERNW_Newsletter_31_Secure_IE8_Configuration_en.pdf (925KB)
ERNW_Newsletter_31_Secure_IE8_Configuration_signed_en.pdf (902KB)

ERNW @ Black Hat Europe

12-15 April 2010, Barcelona / Background Report at DarkReading.com

For the 5th year in a row ERNW is presenting at Black Hat Conference to make their latest research available to a broad audience. This year Enno Rey and Daniel Mende address several vulnerabilities in Cisco Enterprise WLAN solutions.

You'll find more information on the talk at www.blackhat.com, and there's a background report at www.DarkReading.com.

Newsletter 30 / February 2010

Some Security Notes on Cisco Enterprise WLAN Solutions

This newsletter displays results of on-going research regarding Cisco Enterprise Wireless LAN solutions.


ERNW_Newsletter_30b_Cisco_WLAN_Sec_en.pdf (2MB)
ERNW_Newsletter_30b_Cisco_WLAN_Sec_signed_en.pdf (2MB)

Newsletter 29 / November 2009

Data Leakage Prevention – A Practical Evaluation

This newsletter illustrates the new technology Data Leakage Prevention (DLP). After some basic definitions and theoretical explanations, the evaluation of two exemplary DLP suites is described in detail. This examination is based on several requirements and derived test cases, which cover most aspects of DLP and can also serve as a framework for further examinations.


ERNW_Newsletter_29_Data_Leakage_Prevention_en.pdf (253KB)
ERNW_Newsletter_29_Data_Leakage_Prevention_signed_en.pdf (266KB)

Newsletter 28 / August 2009

Active Directory: Security Analysis of the Privilege "Trusted for delegation"

Friedwart Kuhn analyzes security-relevant implications of using the privilege "Trusted for delegation" in Active Directory. This newsletter will also give you recommendations towards a safe implementation of this privilege.


ERNW_Newsletter_28_Trusted_for_Delegation_de.pdf (105KB)
ERNW_Newsletter_28_Trusted_for_Delegation_signed_de.pdf (226KB)

New Workshop Dates

& new slides in our event archives

Our excellent coaches provide for an educational and practically oriented experience. With ERNW there's no compromise between profound theoretical knowledge and applicable practical knowhow. Visit our "Workshop Section" to get an overview over all topics and upcoming dates.

Head over to our event archives for new slides on "Virtual Security" and "Targeted Attacks" [in German language].

Newsletter 27 / June 2009

Security Analysis of Over-the-Air Generation of Master Encryption Keys between BlackBerry Devices and the BlackBerry Enterprise Server

Friedwart Kuhn analyzes and evaluates the safe generation of master encryption keys for the initial setup of BlackBerry devices and the automatic update of these keys between BlackBerry devices and the BlackBerry Enterprise Server. The technical analysis comes along with recommendations of measures towards a safe operation.


ERNW_Newsletter_27_BB_Security_de.pdf (297KB)
Digitally signed version:

ERNW_Newsletter_27_BB_Security_signed_de.pdf (419KB)

"Hacking Mobile Devices" Talk

& upcoming events

Matthias Luft and Daniel Mende gave a lecture on "Hacking Mobile Devices" at an event of F-Secure on 18th May. It featured a series of practical demos. Download the presentation's slides here - we would be pleased to present the demos to your organization or be supportive with securing your mobile platforms.

We've updated the "upcoming events" section. Have a look where the ERNW guys are transferring their deep knowledge to international audience. Amongst others Enno Rey is contributing to Blackhat USA 2009 together with Chris Hoff - get more information about their talk "Cloudifornication" here.

ERNW Security Advisory 01-2009 released

XSS in Blackberries Mobile Data Service Connection Service

Following ERNW's Responsible Disclosure policy, Michael Thumann reported a XSS vulnerability affecting Blackberry Enterprise Server.

ERNW Security Advisory 01-2009 is now online. See also: www.blackberry.com

Black Hat Europe: ERNW talk & tools online

Grab a copy today!

Amsterdam - 16.04.2009 Today Enno Rey and Daniel Mende presented their talk " All your packets are belong to us – Attacking backbone technologies " to the Black Hat audience. Have a look at their presentation slides or even better: Download their tools and use them in your own test environment to fully understand the feasibility of their findings. More information can be found in the white paper that accompanies the Black Hat talk.

If you want to have a chat with our speakers and you're interested in seeing this talk live don't hesitate and use your opportunity @Troopers09 [more].

Update: Due to some requests we'd like to point your attention to Enno's talk "Are They Secure? How to Assess MPLS Providers From a Customer Perspective" given at FutureNet 2007 in New York. It discusses a customer project where we were involved in rating the trustworthiness of world wide MPLS providers.

 

ERNW @ Black Hat Europe

A Fine Tradition continues - 16/17 April 2009, Amsterdam

For the fourth year in a row, ERNW is sending speakers to Black Hat Europe Briefings – thus continuing a fine tradition which demonstrates our unwavering dedication to research in our field. Exploring trends and digging deep into widely adopted technologies has been part of our DNA since the beginning.

This year, Enno Rey and Daniel Mende will present their latest achievements in the area of backbone security, including a tool release. Proofing the feasibility of turning a theoretical vulnerability into a practical exploit recently raised world-wide media interest.

Check out darkreading.com for an interview with Enno Rey.
For more information on Black Hat Europe 2009 Briefings visit blackhat.com

Newsletter 26 / April 2009

VoIP / H.323 Security: Don’t Pay Money for Someone Else’s Calls - A Story from the Field

This newsletter tells the story of a company that built a VoIP trunk to a remote site over the internet and doing so, it opened a security hole. The vulnerability was presumably exploited, which led to the loss of money for the victim. It is a true story, but it will be presented in a generic way, mainly giving a technical description of the incident and pointing out what could have been done to avoid it.


ERNW_Newsletter_26_VoIP_Sec.pdf (2MB)

Troopers09 - We'll do it again!

itsecurity & Troopers09, MUNICH 22 - 23 April 2009: Get your ticket now!

In 2008 ERNW pioneered the introduction of a cutting-edge Security Conference in Germany - without the usual marketing happenings and product presentations - just pure practical information security. This year we're doing it again! We teamed up with the itsecurity09 conference to deliver you an even more complete update on current and future security topics.

Join us on 22 - 23 April 2009 in Munich, Germany. Get updated on the latest research projects of leading information security researchers and specialists from all over the world. Expect some hands-on experience and don't forget to bring your own laptop to join the legendary PacketWars™.

For a complete agenda and more details visit www.troopers09.org

Publications & Talks section updated

ERNW's presence at the latest security conferences

Visit our Publications & Talks section to get an overview on past conferences and upcoming events. Among other things, you'll find new slides of our talks from ShmooCon09 and BASTA! 2008.

There's also a new subsection for talks addressed to an Academic Audience.

Workshop: Voice-over-IP Security

Audience: Information Security Officers, Internal Audit, Network or Security Consultants

The continuing merger of data and voice networks brings new security challenges. This 2-day course provides detailled knowledge about securing complex Voice-over-IP implementations. We will cover typical threats and vulnerabilities in VoIP networks and provide a risk-based approach in securing them.

Lots of real world examples and some hands-on experience might help to get a better understanding of the interactions, potential threats and mitigating controls to come across in VoIP networks.

Available dates:
April 7-8, 2009
May 18-19, 2009
June 23-24, 2009

For more information please head over to our 'Knowhow-Transfer' section.

ERNW wins Packet Wars Hacking competition in the USA

The ERNW hacker team Roger Klose, Daniel Mende, Simon Rich and Grandmaster Michael Thumann, could stand up their many talented North American Ninja Hackers at the PacketWars, during the Day-Con. Congratulation!

Newsletter 25 / March 2009

Malware Analysis for Business Purposes

This newsletter will introduce different approaches how malware can be analyzed and discuss their respective pros and cons. It will cover online sandboxes, individually built sandbox systems with a dedicated tool set and also a reverse engineering approach. Obfuscation techniques that are used by attackers to prevent malware analysis are discussed and possible solutions to defeat them are presented. Finally we will give some recommendations which approach works best in different corporations from our point of view.


ERNW_Newsletter_25_Malware_en.pdf (3MB)

Newsletter 24 / October 2008

An introduction to TrueCrypt

TrueCrypt is a free software application used for transparent real-time encryption and decryption. Its Version 6.0a has just been launched and offers many features and a wide range of functionalities.
This newsletter will give you an overlook and introduce you to user-friendly data encryption.


ERNW_Newsletter_24_TrueCrypt_de.pdf (255KB)

Security Testing

Testing & Auditing

Testing IT Security is one of the core competences of ERNW. Many of our customers get their IT infrastructure and (Web-) applications checked on a regular basis. This may either be done on a very technical level in terms of penetration testing or in a more formal way in terms of general security audits, during which we verify the IT Security Compliance of your company compared to best practices according to ISO17799/ISO27001 and/or your enterprise security policies. As a result of our reports you will be able to realistically assess the risks related to the detected security flaws and vulnerabilities. (more)

Research

Research & Technologie-Evaluation Research is the foundation of our knowledge leadership. The intent of this work is to unveil security flaws and vulnerabilities in protocols, technologies and products. Some findings derive from design-flaws, some from poor implementation on a technical level. In these cases we communicate the vulnerabilities to our clients and/or the manufacturer and assist in the development of a solution of the problem (e.g. patches) and as soon as a patch is available we publish advisories (ERNW Newsletter). (more)

Services

VoIP-Vulnerability Test

New in our Pen-Testing Portfolio: VoIP-Vulnerability check of the participating protocols, gateways, devices and softphones that may lead to:

  • Sniffing
  • Denial-of-Service
  • Redirecting phone calls
  • Hacking of hard- and softphones
  • Spoofing
  • SPIT (VoIP-Spam)

more Pen-Test modules


TROOPERS12 takes place in March, 29th - 23rd, 2012 in Heidelberg. Mark your calendars now and sign up for the official TROOPERS newsletter to stay up-to-date. [More]
Testing IT security is one of the core competences of ERNW. Many of our customers get their IT infrastructure and (Web) applications checked on a regular basis. This may either be done on a very technical level in terms of penetration testing or in a more formal way in terms of general security audits, during which we verify the IT Security Compliance of your company compared to best practices according to ISO17799/ISO27001 ... [More]
Research is the foundation of our Know-How leadership. The objections of this work is to unveil security flaws and vulnerabilities in protocols, technologies and products. Some findings derive from design-flaws, some from poor implementation on a technical level.... [More]