DeepSec supports Security B-Sides London 2013

René Pfeiffer/ December 11, 2012/ Conference

We are happy to announce that we will support the Security B-Sides London 2013! Specifically we support the BSides London “Rookie Track”, and we offer a ticket for DeepSec 2013 including two nights at the conference hotel in Vienna. There’s also a special arrangement covering a flight to Vienna and back. We believe in new ideas and new perspectives. That’s why we offer special slots at our conference for young security researchers (the U21 category marked in our CfP form). We will be present during the “Rookie Track” talks during BSides London. DeepSec wishes to encourage any kind of security research by supporting curious and talented researchers. Never having presented results in public should be no reason not to share them with all of us. We believe that the idea of having mentors and

Read More

DeepSec 2012 Talk: When I Grow up I want to be a Cyberterrorist

René Pfeiffer/ November 25, 2012/ Conference

We have asked Mike Kemp to give an overview of what to expect from his talk When I Grow up I want to be a Cyberterrorist: Terrorism is not big. It is not clever. It is definitely not funny (unless it involves pies in the face). It can however (like so much in life), be utterly absurd. To clarify, the reactions to it can be. The UK is the most surveiled place on earth (outside of Disneyland). The United Kingdom has lots of cameras, lots of privately collected and held data, lots of asinine legislation, and lots of panic. The media and political classes have conspired to protect the once freedom loving residents of the UK against themselves (and we are not alone in living the Panopticon dream). Frankly, it’s pissing me off. In

Read More

Using untrusted Network Environments

René Pfeiffer/ November 15, 2012/ Administrivia, Conference, Security

We mentioned on Twitter that DeepSec 2012 will again feature an open wireless network. This means that there will be no barriers when connecting to the Internet – no passwords, no login, no authentication and no encryption. Some of us are used to operate in untrusted environments, most others aren’t. So the tricky part is giving proper advice for all those who are not familiar with protecting their computing devices and network connections. We don’t know what your skills are, but we try to give some (hopefully) sensible hints. If you are well-versed with IT security and its tools, then you probably already know what you are doing. Nevertheless it’s a good habit to double-check. We caught one of our own sessions chairs with his crypto pants down and found a password – just

Read More

DeepSec 2012 Talk: A Non-Attribution-Dilemma and its Impact on legal Regulation of Cyberwar

René Pfeiffer/ November 14, 2012/ Conference, Discussion

We asked Michael Niekamp and Florian Grunert to give an outlook on their presentation titled A Non-Attribution-Dilemma and its Impact on Legal Regulation of Cyberwar: A general challenge of cyberwar lies in the field of legal regulation under conditions of non-attribution. The optimistic view emphasizes that our international law and its underlying standards are sufficient (in principle and de facto) to solve all emerging problems. A more sceptical view postulates “the impossibility of global regulation”. Although we lean towards the sceptical view, we’ll provide a different and new line of reasoning for the impossibility of a rational legal regulation by formulating a non-attribution-dilemma. In contrast to some prominent arguments, we do not overestimate the suggestive power of the non-attribution-problem concerning the question of rational “deterrence through a threat of retaliation” (DTR for short), but

Read More

DeepSec 2012 Showcase: Cuteforce Analyzer

René Pfeiffer/ November 13, 2012/ Discussion, Security

The University of Applied Sciences Upper Austria will be showing the Cuteforce Analyzer at DeepSec 2012. This beast is a massively parallel computing cluster for cryptographic applications. The goals of this project was to develop a cluster framework and to evaluate suitable hardware. The cluster itself utilises two different types of co-processors, namely the well-known graphics processing units (GPUs) also used in super-computing, and field-programmable gate arrays (FPGAs). Both types of processors have their strength and weaknesses, both depending on the algorithm being executed on the hardware. The cluster framework connects both hardware platforms, and assigns computing tasks according to the advantages of the co-processor. Thus you get to use all the advantages; in addition the framework software makes sure that you can use the different hardware processors as a whole. The research team

Read More

Conference seats are running low…

Mika/ November 8, 2012/ Conference

Honestly: We have such a big interest this year, which is beyond any expectations that we might need to close our ticket sales one or two weeks before the conference. If the trend continues like past years we will exceed the capacity for the conference rooms and the restaurant.We are negotiating with the hotel and do our best to accommodate everyone who wants to attend. Booking is still open at: https://deepsec.net/register.html We have already exceeded the room contingency at our hotel, The Imperial Riding School (Renaissance Vienna Hotel), which grants an attractive room rate, incl breakfast etc… The rate is EUR115,- per night (single person) inc. all fees and taxes, inc. American breakfast and a cancellation possible until 6 PM on the arrival date. Cheaper offers on travel-booking sites typically don’t include breakfast or

Read More

DeepSec 2012 Talk: Pentesting iOS Apps – Runtime Analysis and Manipulation

René Pfeiffer/ November 8, 2012/ Conference, Security

Since one of the focus topics of DeepSec 2012 deals with mobile computing and devices, we asked Andreas Kurtz to elaborate on his presentation about pentesting iOS apps: „Apple’s iPhone and iPad are quite trendy consumer devices, and have become increasingly popular even in enterprises nowadays. Apps, downloaded from the AppStore or developed in-house, are supposed to completely change and optimize the way of work. Suddenly, managers have access to business intelligence information, data warehouses and financial charts on their mobile devices: Apps are used as front ends to executive information systems and, thus, are carrying around loads of sensitive data. At a first glance it seems, that there’s nothing new on it. Indeed, it is quite common to remotely access critical business data. However, the popularity of mobile devices, combined with the sensitive

Read More

Alien Technology in our Datacenters

Mika/ November 5, 2012/ High Entropy, Security, Stories

Sometimes when I watch administrators at work, especially when I start to ask questions, I get an uneasy feeling: “this is not right”. As it turns out many of the people who maintain, manage and configure IT or communication equipment don’t understand the technology they are using. At least not in depth. Mostly they have a rough idea what it’s all about but cannot explain in detail how it works and cannot predict what will happen if a few changes are made to the setup. Although I couldn’t put my finger on it I had a familiar feeling, something like a déjà-vu. Just recently when I browsed through my bookshelves it suddenly became clear: I reached for a science fiction classic, “Gateway” by Frederic Pohl which describes an alien race, the “Heechee”, which have

Read More

Talk about Data Loss Prevention

René Pfeiffer/ November 5, 2012/ Security

We will be presenting a talk about data loss prevention (DLP) on 9 November 2012 at the IT-Security Community Xchange 2012 (IT-SecX 2012) in St. Pölten, Lower Austria. DLP is a good example for measuring the security of your IT infrastructure. Keeping data in is as important as keeping attackers out these days. The tricky part is to know what data you have and where it lives. We will discuss how to approach DLP in terms of preparation, planning and implementation. In case you are in Austria you can meet us at the IT-SecX 2012. The event is organised by the University of Applied Sciences St. Pölten.

DeepSec 2012 Training: SAP Security In-Depth

René Pfeiffer/ November 2, 2012/ Security, Training

Your SAP installation is probably the most critical system in your company’s infrastructure. At the same time the informations accessed and processed by SAP systems origin from many sources. Securing infrastructure with this complexity is not an easy task, and testing your security measures requires a great deal of knowledge and training. In addition your will probably run web services talking to your SAP system – which is quite handy for attackers. In case you are short on knowledge about your own SAP deployment, there’s help. There will be an SAP security workshop at DeepSec 2012! The SAP Security In-Depth training will show you how to find out if your SAP infrastructure is secured. Knowing about segregation of duties and securing roles and profiles is fine in theory, but you have to make sure

Read More

DeepSec 2012 Talk: Wargames in the Fifth Domain

René Pfeiffer/ November 2, 2012/ Conference

We asked Karin Kosina to illustrate her talk Wargames in the Fifth Domain: “This is a pre-9/11 moment. The attackers are plotting.” These are the words of U.S. Secretary of Defense Leon Panetta addressing business executives on the dangers of cyberwar two weeks ago in New York. And just in case this did not leave the audience scared enough, Panetta also warned about the possibility of an upcoming “cyber-Pearl Harbor”. A massively destructive cyberwar, it seems, is imminent. Or is it? Is the world really on the brink of cyberwar? Time to panic and hide in our cyber shelters? – Well, I think things are slightly more complicated than that. Before you dismiss me as a peace-loving hippie who views the world through rose-tinted glasses: There is no doubt that our emerging information society

Read More

Zombies at the Hospital

René Pfeiffer/ October 31, 2012/ High Entropy, Security

It’s 31 October, so we have to talk about these zombies. You know them from the horror films. Dead, evil, and always hungry for brains (the latter also being true for any self-respecting HR department). Security researchers know a different kind of zombie. A zombie computer is a machine or device infected by a computer virus. It is considered compromised and contains additional features such as information retrieval, remote access or anything else you can put into code. Usually this is undesirable and fought with anti-virus software or (even better) strict security procedures. Now let’s combine the two types of zombies and add a spiffy virus outbreak into the mix. To go even further cinematic we use a hospital as the stage. Too unrealistic? On the contrary, hospitals do have a virus and zombie

Read More

DeepSec 2012 Talk: The „WOW Effect“

René Pfeiffer/ October 24, 2012/ Conference

If you have ever been in the position of analysing the remains of a compromised system, then you will probably know that a lot of forensic methods rely on data stored in file systems. Of course, you can always look at individual blocks, too, however sooner or later you will need the logical structure of the data. The question is: Do you rely on the file system to be honest with you? What happens if the file system (with a little help from the OS around it) tricks you into believing false information? The answer is easy. Your investigation will fail. Christian Wojner from CERT.at has a presentation for you which describes the stunning „WOW Effect“ stemming from Microsoft’s WoW64 technology. WoW64 is the abbreviation for Windows 32-bit on Windows 64-bit. It allows 64-bit

Read More

Groundhog Day (Not a Film Review)

Mika/ October 20, 2012/ High Entropy, Security

Recently there was a re-run of the movie “Groundhog Day” on German TV and after a while I felt a familiar feeling: Our security efforts are a lot like the story. The protagonist is caught in something like a time-loop until he gets everything right. A previously cynical, disrespecting, arrogant and selfish news reporter wakes up every morning to the same scene: The alarm clock switches to 6:00 in the morning, the radio plays “I got you babe” and the same day repeats over and over again. During the first iterations he doesn’t change his behavior, being quite a discomforting guy until he realizes that slight changes can make a big difference. He is only relieved from this situation after he gets everything right: Being nice to his former school schoolmate, changing the tires

Read More

DeepSec 2012 Keynote: We Came In Peace – They Don’t: Hackers vs. CyberWar

René Pfeiffer/ October 19, 2012/ Conference

„Cyberwar“ is all the fashion these days. Everyone knows about it, everyone has capabilities, everyone has a military doctrine to deal with it. Sceptics make fun of it, politicians use it for election campaigns, security researchers wonder what’s new about it, „experts“ use it to beef up their CV, cybercrime yawns, journalists invent new words, most others are confused or don’t care (probably both). This is why DeepSec 2012 features four talks about this topic, including the keynote by Felix ‘FX’ Lindner. FX explains what you can expect from his presentation: “The issues we are facing concerning the militarization and beginning arms race in the so-called “cyber domain” are not what you might think they are. I would like to highlight two aspects of how we, the civilian hackers, in my opinion handle things

Read More