Newsletter Archive

Newsletter 31 / June 2010

Secure Configuration of Microsoft Internet Explorer, Version 8

This newsletter evaluates configuration options, reflecting security and possible usability impact, incorporating typical large scale enterprise usage of browser based content. The evaluation was done for a globally operating enterprise.


ERNW_Newsletter_31_Secure_IE8_Configuration_en.pdf (925KB)
ERNW_Newsletter_31_Secure_IE8_Configuration_signed_en.pdf (902KB)

Newsletter 30 / February 2010

Some Security Notes on Cisco Enterprise WLAN Solutions

This newsletter displays results of on-going research regarding Cisco Enterprise Wireless LAN solutions.


ERNW_Newsletter_30a_3IT-Security_Bits_de.pdf (65KB)
ERNW_Newsletter_30a_3IT-Security_Bits_signed_de.pdf (181KB)
ERNW_Newsletter_30b_Cisco_WLAN_Sec_en.pdf (2MB)
ERNW_Newsletter_30b_Cisco_WLAN_Sec_signed_en.pdf (2MB)

Newsletter 29 / November 2009

Data Leakage Prevention – A Practical Evaluation

This newsletter illustrates the new technology Data Leakage Prevention (DLP). After some basic definitions and theoretical explanations, the evaluation of two exemplary DLP suites is described in detail. This examination is based on several requirements and derived test cases, which cover most aspects of DLP and can also serve as a framework for further examinations.


ERNW_Newsletter_29_Data_Leakage_Prevention_en.pdf (253KB)
ERNW_Newsletter_29_Data_Leakage_Prevention_signed_en.pdf (266KB)

Newsletter 28 / August 2009

Active Directory: Security Analysis of the Privilege "Trusted for delegation"

This document analyzes security-relevant implications of using the privilege "Trusted for delegation" in Active Directory. This newsletter will also give you recommendations towards a safe implementation of this privilege.


ERNW_Newsletter_28_Trusted_for_Delegation_de.pdf (105KB)
ERNW_Newsletter_28_Trusted_for_Delegation_signed_de.pdf (226KB)

Newsletter 27 / June 2009

Security Analysis of Over-the-Air Generation of Master Encryption Keys between BlackBerry Devices and the BlackBerry Enterprise Server

This newsletter analyzes and evaluates the safe generation of master encryption keys for the initial setup of BlackBerry devices and the automatic update of these keys between BlackBerry devices and the BlackBerry Enterprise Server. The technical analysis comes along with recommendations of measures towards a safe operation.


ERNW_Newsletter_27_BB_Security_de.pdf (297KB)
Digitally signed version:

ERNW_Newsletter_27_BB_Security_signed_de.pdf (419KB)

Newsletter 26 / April 2009

VoIP / H.323 Security: Don’t Pay Money for Someone Else’s Calls - A Story from the Field

This newsletter tells the story of a company that built a VoIP trunk to a remote site over the internet and doing so, it opened a security hole. The vulnerability was presumably exploited, which led to the loss of money for the victim. It is a true story, but it will be presented in a generic way, mainly giving a technical description of the incident and pointing out what could have been done to avoid it.


ERNW_Newsletter_26_VoIP_Sec.pdf (2MB)

Newsletter 25 / March 2009

Malware Analysis for Business Purposes

This newsletter will introduce different approaches how malware can be analyzed and discuss their respective pros and cons. It will cover online sandboxes, individually built sandbox systems with a dedicated tool set and also a reverse engineering approach. Obfuscation techniques that are used by attackers to prevent malware analysis are discussed and possible solutions to defeat them are presented. Finally we will give some recommendations which approach works best in different corporations from our point of view.


ERNW_Newsletter_25_Malware_en.pdf (3MB)

Newsletter 24 / October 2008

An introduction to TrueCrypt

TrueCrypt is a free software application used for transparent real-time encryption and decryption. Its Version 6.0a has just been launched and offers many features and a wide range of functionalities.
This newsletter will give you an overlook and introduce you to user-friendly data encryption.


ERNW_Newsletter_24_TrueCrypt_de.pdf (255KB)

Newsletter 23 / April 2008

News from the underground - Report about Blackhat Europe 2008

On the 27th of March the last results of the hacker scene were presented during two days at the Blackhat Europe in Amsterdam. ERNW was also there with the „Hacking SecondLife“ talk. It was also a good opportunity to get newest information from another experts and to discuss about the actual trends in the scene. In this newsletter we circulate the information and therefore summed up for you the most important and interesting talks.


ERNW_Newsletter_23_Blackhat_de.pdf (75KB)

Newsletter 22 / March 2008

Security analysis of removable media, in particular of USB flash drives under Windows

This Newsletter describes the questions the IT security management should ask when using USB devices. Technical and organisational measures for solutions under Windows Vista as well as risk assessment will be discussed.


ERNW_Newsletter_22_v1.0.pdf (2MB)

Newsletter 21 / February 2008

Introduction into the risk assessment and examples

This newsletter deals with the risk assessment, one of the most important subprocesses. After a short introduction, a customer project is presented as an example.


ERNW_Newsletter_21_Risikoanalyse_de.pdf (117KB)
voip_risk_analysis_ger.pdf (468KB)

Newsletter 20 / October 2007

SNMP Version 3 in practise

The "Simple Network Management Protocol" version 3 is neglected by the network administrators despite its conveniences over its predecessors. This newsletter tries to explain the advantages and the reasons of this negligence and shows by means of a pratical example that SNMPv3 may be interesting for the enterprise.


ERNW_Newsletter_20_CW_und_SNMPv3_de.pdf (465KB)

Newsletter 19 / September 2007

Metrics based patch with CVSS 2.0 - concept with methodology

by Dror-John Röcher

Introduction:
This newsletter describes a methodology for analysing vulnerabilities, which are based on the metrics of the Common Vulnerability Scoring Systems (CVSS) and demonstrates how the analysis can be integrated in the patch management process.
This document is available in German.


ERNW_Newsletter_19_CVSS_de.pdf (637KB)

You can get here the ERNW CVSS calculator which is referenced in the newsletter.
ernw-cvsscalc.zip (198KB)

Newsletter 18 / August 2007

Compliance mit Sophos NAC 3.0 aus Sicht des CISO - Ein dutzend Fragen und Antworten

"Compliance with Sophos NAC 3.0 from CISOs point of view - Questions and answers

by Friedwart Kuhn, Dror-John Röcher and Michael Thumann

Introduction :
This newsletter deals with the compliance from CISOs point of view (Chief Information Security Officers) and analyses the way Sophos NAC 3.0 may be a useful tool.


ERNW_Newsletter_18_Compliance_mit_Sophos-NAC_de.pdf (1MB)

Newsletter 17 / Juli 2007

"Mandatory Integrity Control" unter Windows Vista von Friedwart Kuhn

This Document is available in German.

Newsletter 16 / April 2007

"Logging und Logauswertung im Windows-Umfeld als Stütze der IT-Sicherheitsarchitektur"

This Document is available in German.


ERNW_Newsletter_16_WinLog_de.pdf (722KB)

ERNW IT-Security Newsletter Nr. 15

Security Analysis des Cisco NAC Framework

Abstract:
The last two years have seen a big new marketing-buzz named "Admission Control" or "Endpoint Compliance Enforcement" and most major network and security players have developed a product-suite to secure their share of the cake. As the market is still evolving and one framework has been quite successful on the market: "Cisco Network Admission Control". NAC is a pivotal part of Cisco’s "Self Defending Network" strategy and supported on the complete range of Cisco network- and security-products. From a security point of view “NAC” is a very interesting emerging technology which deservers some scrutiny. We are able to hack the Cisco NAC-solution by exploiting a fundamental design flaw.
This Document ist available in German language.


ERNW_Newsletter_15_NAC@ACK_de.pdf (1MB)

Newsletter 14 / Februar 2007

PCI-Compliance

"PCI-Compliance" by Enno Rey (erey@ernw.de)

The Payment Card Industry Data Security Standard (PCI DSS), originally iniiated by Mastercard and Visa, describes measures and tools to ensure safe handling and proccessing of credit card data.
Online Merchants (and softewaredevelopers in this field) are - depending on the amount of transactions p.a. - obliged to prove their "compliance" to PCI DSS and will be fined in case they fail to do so.
This document is available in German.

Dieser Newsletter stellt den Standard und die Prüf-Methodik vor.
ERNW_Newsletter_14_PCI-Compliance_de.pdf (155KB)

Newsletter 13 / February 2007

WLAN Security

This paper shows tries to give you a brief snapshot of the current standards in WLAN-Security.
This document is available in German.

Dazu werden aktuelle Angriffsmethoden, zugehörige Gegenmassnahmen und Entwicklungen beleuchtet.
ERNW_Newsletter_13_WLAN-Sec_de(3).pdf (311KB)

Newsletter 12 / Oktober 2006

Vista Security

With Windows Vista Microsoft introduces a complete new security architecture. Central components are here the technologies "user Access Control" (UAC) and "Mandatory Integrity Control" (MIC). Protecting UAC meanwhile is well documented, is MIC up to a Blog of the Microsoft employee Steve Riley [1) widely undocumented.

Our employee Enno Rey has closed some tests which carried out some surprised results and post his result as a comment in Steve Rileys Blog.

Here because of the obviously big interest in Vista and his security model the text is published again.

This document is available in german language.
ERNW_Newsletter_12_de.pdf (149KB)

Newsletter 11 / September 2006

BlackBerry Security & Mobile Security

The Newsletter contain a summary of the aktual Security Diskussion around BlackBerry devices and RIM-Email-Push-Services. Beside the technical aspects organizational aspects and the user are also taken into consideration

This document is available in german language.
ERNW_Newsletter_11_de.pdf (839KB)

Newsletter 10 / June 2006

Buffer Overflow in PrivateWire

The described bug
"Buffer Overflow in Algorithmic Researchs PrivateWire Online Registration Facility"
was uncovered by the IT-Security Research-Team under direction of Michael Thumann. The assignment of the ERNW IT-Security Research-Team is to sign up unknown security problems. That can be on conceptual as well as at technical level (e.g. bug search in Software). When a bug found we communicate with the maufacturer and usually we debug in cooperation. As soon as possible we puplish a fix (e.g a Patch) in form of a White-Paper or a ERNW Security-Advisory.

The Research-Team operate with different techniques (e.g. reverse engineering, code audits, protokoll network communication, fault-injection) to search for bugs.

The work of the ERNW IT-Security Research-Team serves the internal continuing education as well as our customer, because they can make the IT safer.

This document is available in german language.
ERNW_Newsletter_10_de.pdf (161KB)

Newsletter 9 / May 2006

"Smartcard-basiertes SSO mit STARCOS/AET Safesign in Active Directory-Umgebungen mit Citrix und Zertifikaten einer 3.-Party CA"

"Smartcard-based SSO using STARCOS/AET Safesign in Active Directory-Umgebungen with Citrix and 3rd-Party Certificates" (by Enno Rey and Friedwart Kuhn).

Newsletter 8 / November 2005

"Gründung der ERNW.PT"

The foundation of ERNW.PT and our cooperation with the Portugese Chamber of Commerce and Industry.

This document is available in german language.
ERNW_Newsletter_8_de.pdf (217KB)

Newsletter 7 / July 2005

"Neue Angriffe auf Layer 2 in Cisco-Netzen"

"New Attacks on Layer 2 in Cisco Networks / Neue Angriffe auf Layer 2 in Cisco Netzen" by Enno Rey.

This document is available in german language.
ERNW_Newsletter_7_de.pdf (274KB)

Newsletter 6 / February 2005

"Active Directory und Domänencontroller Disaster Protection und –Recovery"

"Active Directory und Domänencontroller Disaster Protection und -Recovery" by Friedwart Kuhn.

This document is available in german language.
newsletter6_de.pdf (142KB)

Newsletter 5 / September 2004

"Neue Möglichkeiten Sicherheit durch Server 2003-basierte Gesamtstrukturen zu implementieren."

This paper describes new security features by which the access between Server 2003-based forests can be made more secure and can be controlled with more granularity (even through firewall borders).
newsletter5_de.pdf (117KB)

Newsletter 4 / May 2004

"Arbeiten als Non-Admin unter Windows"

"Working with Windows as a Non-Admin" by Enno Rey.

This document is available in german language.
newsletter4.pdf (256KB)

Newsletter 3 / September 2003

"Methoden der Spam-Bekämpfung"

"Methods of fighting Spam" by Enno Rey.

This document is available in german language.
newsletter3.pdf (60KB)

Newsletter 2 / July 2003

"Vertrauen ist gut, korrekte Konfiguration ist besser!"

"Trust is good, correct configurated systems are better" by Enno Rey.

This document is available in german language.
newsletter2.pdf (62KB)

Newsletter 1 / May 2003

"Host-Security am Beispiel sendmail"

Host-Security using sendmail by Enno Rey.

This document is available in german language.
newsletter1.pdf (53KB)

TROOPERS11 takes place from 14-18. March 2011 at Heidelberg. Mark your calendars now and sign up for the official TROOPERS newsletter to stay up-to-date. [More]
Testing IT security is one of the core competences of ERNW. Many of our customers get their IT infrastructure and (Web) applications checked on a regular basis. This may either be done on a very technical level in terms of penetration testing or in a more formal way in terms of general security audits, during which we verify the IT Security Compliance of your company compared to best practices according to ISO17799/ISO27001 ... [More]
Research is the foundation of our Know-How leadership. The objections of this work is to unveil security flaws and vulnerabilities in protocols, technologies and products. Some findings derive from design-flaws, some from poor implementation on a technical level.... [More]