Unlock Your Brain, Harden Your System! #UYBHYS2021 https://unlockyourbrain.bzh/2021 Workshops + Conférences + CTF Fri, 05 Nov 2021 16:10:34 +0000 en-US hourly 1 https://wordpress.org/?v=6.8 https://unlockyourbrain.bzh/2021/wp-content/uploads/2020/02/cropped-UYBHYSFormecercleCouleurs-32x32.png Unlock Your Brain, Harden Your System! #UYBHYS2021 https://unlockyourbrain.bzh/2021 32 32 MISP – Threat Intelligence Sharing Platform https://unlockyourbrain.bzh/2021/2021/10/29/misp-threat-intelligence-sharing-platform/ Fri, 29 Oct 2021 12:03:28 +0000 https://www.unlockyourbrain.bzh/?p=6499

Contenu à venir

Alexandre Dulaunoy

Chercheur en sécurité à CIRCL.LU

]]>
Mobile Reverse Engineering with R2Frida https://unlockyourbrain.bzh/2021/2021/10/29/mobile-reverse-engineering-with-r2frida/ Fri, 29 Oct 2021 11:57:31 +0000 https://www.unlockyourbrain.bzh/?p=6494

Combining dynamic with static analysis is the key to quickly solving many challenges when performing binary analysis. Have you ever thought about combining Radare2 with Frida? This combination has given birth to “r2frida”, an IO plugin that allows you to put the power of Frida into r2land.

During this workshop, we will walk you through how to use r2frida, primarily on mobile apps. Attendees will learn about offensive mobile security, e.g how to unpack malware, bypass jailbreak protections, SSL pinning, anti-debugging or even Frida detections using Frida itself.

The workshop is suitable for pentesters, reversers, malware analysts and mobile developers who want to learn more about mobile security

Eduardo Novella Lorente

Mobile security research engineer at Nowsecure

Alejandro Soler Alvarez

Security engineer

]]>
Software Defined Radio pour débutant https://unlockyourbrain.bzh/2021/2021/10/29/software-defined-radio-pour-debutant/ Fri, 29 Oct 2021 11:43:00 +0000 https://www.unlockyourbrain.bzh/?p=6492

Découvrez le monde des transmissions radios et familiarisez-vous avec les logiciels GQRX, inspectrum et GNURadio !

Apprenez à identifier, manipuler et décoder des signaux radio de la FM, des TPMS de voiture ou encore du GSM au travers d’exercices pratiques réels.

Ce workshop permettra aux participants d’acquérir les bases et de démystifier le Software Defined Radio.

Cyril Delétré
IT and Network Security Expert
]]>
Élévation de privilèges sur Android https://unlockyourbrain.bzh/2021/2021/10/29/elevation-de-privileges-sur-android/ Fri, 29 Oct 2021 11:39:17 +0000 https://www.unlockyourbrain.bzh/?p=6490

Android est le système d’exploitation mobile le plus utilisé au monde. Il met en œuvre la plupart des protections modernes, côté noyau, visant à assurer le cloisonnement entre applications et l’intégrité du noyau.

Dans cet atelier, nous présenterons ces protections et étudierons leur implémentation. Le fil rouge de l’atelier sera l’exploitation d’une vulnérabilité sur un émulateur Android.

Nous clôturerons l’atelier par la mise en perspective des mesures de sécurité supplémentaires que l’on rencontre sur les périphériques du commerce.

Guillaume Teissier

Analyste et rétroconception chez Thales

]]>
Bitlocker and Trusted Platform Module https://unlockyourbrain.bzh/2021/2021/10/28/bitlocker-and-trusted-platform-module/ Thu, 28 Oct 2021 09:42:34 +0000 https://www.unlockyourbrain.bzh/?p=6423

Hardware security is going more and more deeper. Hardware as root of trust is the heart of every secure operation. There are several devices and integrated components, made for security reasons, and among these we find the Trusted Platform Module.

Unfortunately, using secure hardware by itself is not enough. The manufacturers must use these components appropriately by designing security measurements into each step of the firmware execution.

In this presentation we would like to highlight the security weaknesses of the Bitlocker and Trusted Platform Module, focusing on how they can be exploited to gain access to personal data and the operating system. These weaknesses could on the one hand lead a malicious user to access sensitive information and on other could help the Red Teaming assessment or Digital Forensics analysis.
Finally will be present a tool made by our team to exploit these security flaws.

The purpose of this presentation is to describe the Trusted Platform Module and its use in the Bitlocker software architecture, highlighting the main security weaknesses.

The TPM is an integrated component present in most of our personal computers and not only that. It provides a series of security features to ensure, for example, the storage of cryptographic keys and the execution of sensitive routines in Trusted Execution Environment. Furthermore, we will also describe tools like Bitlocker, which use the TPM to increase security and guarantee user privacy.We will then go on to analyze in detail the tool and its basic functionality and the various ways it can be used, before moving on to security implications, vulnerability and weakness software features, that allow a malicious user to access sensitive data and the operating system.

Finally, we will show a tool created by our team which decodes part of the communication between BIOS and TPM in order to obtain the cryptographic key used by the software to encrypt the disk.

Luigi Fragale

Luigi Fragale est pentester chez Communication Valley Reply.

]]>
Tool Demo : ReNgine [EN] https://unlockyourbrain.bzh/2021/2021/10/28/tool-demo-rengine-en/ Thu, 28 Oct 2021 09:41:53 +0000 https://www.unlockyourbrain.bzh/?p=6445

reNgine is an automated reconnaissance framework for web applications with a focus on highly configurable streamlined recon process via Engines, recon data correlation, and organization, continuous monitoring, backed by a database, and a simple yet intuitive User Interface.

reNgine makes it easy for penetration testers to gather reconnaissance and gather vulnerabilities with minimal configuration and with the help of reNgine’s correlation, it just makes recon effortless.

reNgine has some of the most advanced features on any recon tools like data correlation and organization, the custom query “like” language for recon data filtering, screenshot gallery with filtering options, powerful and highly configurable scan engines, customizable notifications to discord, slack or telegram, automatic vulnerability reporting to Hackerone, support for GF pattern matching, OSINT, Recon Data Visualization, Support for Recon Notes and Todos, Perform Advanced Query lookup using natural language alike and, or, not operations, and proxy support.

reNgine also introduces the ability to automatically find interesting subdomains, tagging targets, and find recon data changes, like how many subdomains are newly discovered or no longer exist and also reNgine supports Clocked Scans (Run reconnaissance exactly at X Hours and Y minutes) and Periodic Scans (Runs reconnaissance every X minutes/hours/days/week)

reNgine aims to address the shortcomings of traditional recon workflow using these features.

This tool demo/talk will be a walkthrough on reNgine, on how organizations or individuals could make the best out of reNgine for continuous monitoring and reconnaissance.

Yogesh Ojha

Research Engineer TRG.

Creator of reNgine, an open-source automated reconnaissance framework. reNgine is an automated reconnaissance framework for web applications with focus on highly configurable streamlined recon process via Engines, recon data correlation and organization, continuous monitoring, backed by database and simple yet intuitive User Interface.

]]>
Opsec tips for OSINT investigators https://unlockyourbrain.bzh/2021/2021/10/28/opsec-tips-for-osint-investigators/ Thu, 28 Oct 2021 09:39:25 +0000 https://www.unlockyourbrain.bzh/?p=6479

One can think that the priority of an osint investigation is to obtain results on the target. Nevertheless, it is essential to implement all the operational security measures (opsec) so that the target is not aware of the investigations in progress on it. In this lecture we will see an introduction of the do’s and don’t that can guarantee or compromise your investigations.

Palenath Megadose

OSINT, HUMINT, SE, SOCMINT, Maltego, Infosec and Open Source lover

]]>
Le numérique est politique https://unlockyourbrain.bzh/2021/2021/10/28/le-numerique-est-politique/ Thu, 28 Oct 2021 09:37:46 +0000 https://www.unlockyourbrain.bzh/?p=6457

Le modèle économique prédateur des Big Tech, théorisé sous l’angle du “capitalisme de surveillance”, est-il devenu une source de tensions géopolitiques en raison du RGPD, des afficionados de Mastodon ou de Cambridge Analytica ? La protection des infrastructures critiques contre la cybercriminalité opportuniste relève-t-elle uniquement des équipes cybersécurité ou devrait-elle être prise au sérieux pour le politique et le législateur ?

En réalité, quel que soit l’exemple qu’on prend, l’intimité entre le personnel, le sociétal et le numérique est actée. Que ça nous plaise ou pas, on est tous l’utilisateur final de quelqu’un. Mais le fossé entre l’impact que cette situation a sur nous et la maîtrise qu’on peut avoir de cette situation ne cesse de s’élargir. Si l’on sort du personnel (moi face à mon écran) pour embrasser une vision sociétale, ces défis sont multipliés d’autant. Et continue à se poser la même question : à partir de quel moment, un sujet technique devient-il un sujet de gouvernance et de politique ?

Brève conférence pour tenter une sensibilisation des visiteurs et participants très technophiles aux sujets de fabrique de la loi, où je tenterai de leur expliquer comment hacker son élu-e à travers quelques exemples concrets.

Rayna Stomboliyska

Experte en gestion des risques et des crises, Rayna Stamboliyska est consultante en gouvernance de sécurité et conformité auprès d’entreprises et d’organisations internationales. Elle est également l’auteure de « La face cachée d’Internet » (éd. Larousse), primé par le Prix du livre Cyber “Grand Public” au Forum International de Cybersécurité (FIC) 2018. Elle a aussi étudié l’impact des données et technologies de l’information dans de nombreux pays en situation de conflit et post-conflit, notamment en Europe de l’Est et au Moyen Orient. Rayna enseigne à l’IAE de Poitiers et tient la chronique « 50 nuances d’Internet » sur ZDNet.fr.

]]>
Persistent Like A Bear https://unlockyourbrain.bzh/2021/2021/10/28/persistent-like-a-bear/ Thu, 28 Oct 2021 09:35:59 +0000 https://www.unlockyourbrain.bzh/?p=6471

Les mécanismes de persistance désignent les techniques utilisées par les cyber malfaisants pour conserver leurs accès aux systèmes compromis.

L’objectif, pour ces acteurs malveillants, est de pouvoir maintenir leur emprise sur ces systèmes compromis et cela malgré les redémarrages complets, les changements de sessions ou autres interruptions qui pourraient leur faire perdre leurs accès initiaux.

Le sujet de cette intervention est de présenter quelques-unes des techniques utilisées par les attaquants de tout poil et de faire un focus plus spécifique sur les techniques employées par les “ours”, acteurs malveillants présumés proches des services d’état de la fédération de Russie.

A l’issue de cette présentation, nous réaliserons une démonstration « live » de mise en œuvre d’un des mécanismes de persistance avancé basé sur les modes opératoires de l’Advanced Persistent Threat “Turla” dans le cadre de leur campagne de compromission de serveur de courrier « Microsoft Exchange » dite « LightNeuron ».

Igor & Boris
]]>
HashLookup API https://unlockyourbrain.bzh/2021/2021/10/28/hashlookup-api/ Thu, 28 Oct 2021 09:34:38 +0000 https://www.unlockyourbrain.bzh/?p=6487

Contenu à venir

Alexandre Dulaunoy

Chercheur en sécurité à CIRCL.LU

]]>