Introducción a BIOS y SMM
OpenSecurityTraining ha liberado/actualizado el material de otra de sus magníficas clases. En este caso una clase de nivel avanzada llamada: Introduction to BIOS and SMM (System Management Mode).
La clase se recomienda que se tome en 2 ó 3 días. Los objetivos de la misma son:
- Entender diferencias y similitudes entre UEFI y una BIOS regular.
- Entender el entorno de arranque de BIOS/UEFI y cómo interactúan con la arquitectura del sistema.
- Cómo configurar BIOS/UEFI para maximizar la seguridad, y cómo los atacantes han saltado dichos mecanismos.
- Cómo SMM es inicializado y debe ser protegido.
- Cómo SMM puede ser usado para añadir nuevas capas de seguridad.
- Cómo el chip de la BIOS debería protegerse apropiadamente y qué tipo de ataques se podrían llevar a cabo si éste no es protegido.
- Aprender cómo hacer ingeniería inversa a módulos UEFI.
- Aprender cómo investigar por tu cuenta en este campo.
Alternativas a LastPass. Gestores de contraseñas
LastPass es una aplicación que nos ayuda a gestionar nuestros passwords. Es bastante conocido y con buenas críticas, pero hace poco se anunció la adquisición de estos por parte de LogMeIn. Dicha adquisición no parece haber sido bien recibida por muchos, y justo después del anuncio, un competidor directo, Dashlane, reportó un incremento en el número de registros. En las redes sociales tampoco fue muy acogida dicha adquisición, incluso conocidos en el mundo de la seguridad como Troy Hunt, publicó una entrada sobre cómo migrar de LastPass a 1Password.
Introducción a la programación ensamblador para Amiga
Amiga, un viejo conocido de Cyberhades y amado incondicionalmente por el que escribe, fue un ordenador revolucionario a mediados/finales de los 80s, principalmente por el potencial gráfico y el sistema operativo AmigaOS.
Desde Reaktor nos traen una entrada muy didáctica sobre como programar en ensamblador para dicho sistema.
La entrada comienza con la preparación del sistema, en el que usa el emulador FS-UAE (por lo que no necesitas tener un Amiga físicamente), la ROM Kickstart 1.3 y Vasm como ensamblador. A partir de ahí nos muestran unos trucos para la depuración del código, explicación de ciertas parte del código que usa como ejemplo.
Material de LinuxCon Europe 2015
Ya podemos descargarnos las diapositivas (PDFs) de las presentaciones de la LinuxCon Europe 2015 celebrada a principios de este mes de octubre.
- IoTivity Core Framework: Features & Opportunities
- IoT Meets Security
- Creating IoT Demos with IoTivity
- Container mechanics in rkt and Linux
- TC: Traffic Control
- Measuring and reducing crosstalk between virtual machines
- Introduction to GPUs and the Free Software Graphics Stack
- At-Scale Datacenters and the Demand for New Storage Architectures
- Reducing Latency for Linux Transport
- Maximum Performance: How to get it and how to avoid pitfalls
- Linux Performance Profiling and Monitoring
- Introducing the Industrial IIO subsystem - the home of sensor drivers
- Deadline scheduler in the audio domain
- Secure server
- Network Analysis: People and Open Source Communities
- Challenges in Distributed SDN
- Portable Linux Lab - a novel approach to teaching programming in schools
- BitRot detection in GlusterFS
- How to Thoroughly Insult and Offend People in Your Open Source Communities, or “Your #$%@ $%@&ing Sucks and I $%@&ing Hate It"
- OpenSMTPD: we deliver !!
- Use "strace" to understand your shell (BASH)
- gnuplot - A picture says a thousand numbers
- The Devil Wears RPM: Continuous Security Integration
- Introduction to Advanced Bash Usage
- Data Plane Isolation via the Jailhouse Hypervisor
- Enhancements to FreeIPA replication topology management
- Towards Application Driven Storage: Controlling Data Placement and Garbage Collection using RocksDB with LightNVM.
- Developers Care About the License: Using SPDX to Describe License Information
- Outreachy kernel internship report
- Enhance OpenSSH for fun and security
- Balancing Power and Performance in the Linux kernel
- HOW TO DO AFFORDABLE SUPERCOMPUTING AT HOME?
- Suspend/Resume at the Speed of Light
- Setting up an IPv6 Lan with Linux
- eBPF on the mainframe - Packet filtering and more
- Reflections on data plane performance, iptables and ipsets
- How To Make a Positive Impact In Open Source Without Doing Any Coding
- Statistical Performance Analysis with Performance Co-Pilot and R
- Advancements in Automatic File Replication in Gluster
- dbusoorexx - Bringing the Power of D-Bus to Your Fingertips
- Catch Up on the Raspberry Pi
- container management apis: an overview
- NFS-Ganesha and Clustered NAS on Distributed Storage Systems
- Static Analysis of your OSS Project with Coverity
- Tracing virtual machines from the host with trace-cmd virt-server
- ACPI on ARM64: challenges ahead
- IoTivity, the Open Interconnect Consortium and the IoT Challenge
- System recovery with BTRFS and snapshots/rollback
- Boosting Developer Productivity with Clang
thefuck, una aplicación que corrige tu último comando de consola
¿Cuántas veces has intentado instalar una aplicación en tu sistema Linux y has olvidado el comando sudo? ¿O cuántas veces has escrito de forma equivocada un comando o un argumento del mismo?
thefuck es una aplicación que es capaz de corregir tu último comando. Se basa en una serie predefinida de errores, pero además te permite añadir tus propias reglas, en caso que quieras añadir algunas nuevas o modificar las ya existentes.
Vídeos de GrrCON 2015
Una vez más desde la web de IronGeek podemos ver los vídeos que se han publicado de la edición de este año de GrrCON, conferencia anual sobre seguridad celebrada en Michigan los pasados 9 y 10 de octubre.
- Subject matter to be determined by the number of federal agents present in the audience Chris Roberts
- Breaking in Bad (I,m The One Who Doesn,t Knock) Jayson Street
- Process The Salvation of Incident Response - Charles Herring
- But Can They Hack?: Examining Technological Proficiency in the US Far Right Tom Holt
- The wrong side of history - everything that is old is new again Arron Finnon
- Poking The Bear Mike Kemp
- The Hitch Hikers Guide to Information Security Kellman Meghu
- Backdooring Git John Menerick
- Spanking the Monkey (or how pentesters can do it better!) Justin Whithead, Chester Bishop
- Adding +10 Security to Your Scrum Agile Environment tehEx0dus
- How I Got Network Creds Without Even Asking: A Social Engineering Case Study Jen Fox
- Shooting Phish in a Barrel and Other Terrible Fish Related Puns infosystir
- This Is All Your Fault Duncan Manuts
- The Safety You Think You Have is Only a Masquerade Nathan Dragun
- Security Incident Response Derek Milroy
- Hacking the Next Generation HealWHans
- Findings Needles in a Needlestack: Enterprise Mass Triage Keven Murphy
- Punch and Counter-punch Part Deux: Web Applications J Wolfgang Goerlich, NerdyBeardo
- Application Recon - The Lost Art Tony Miller
- The Hand That Rocks the Cradle: Hacking Baby Monitors Mark Stanislav
- Software Security IWR Thomas "G13" Richards
- Cyber 101 - Upstaring your career in a leading industry Johnny Deutsch
- Understanding and Improving the Military Cyber Culture Dariusz Mikulski
- Harness the Force for Better Penetration Testing Patrick Fussell
- Targeted Attacks and the Privileged Pivot Mark Nafe
- Shell scripting live Linux Forensics Dr. Phil Polstra
- Can you patch a cloud? Scott Thomas
- Is it EVIL? Chaoticflaws
- Ticking me off: From Threat Intel to Reversing Juan Cortes
- Securing Todays Enterprise WAN Andy Mansfield
- Footprints of This Year's Top Attack Vectors Kerstyn Clover
- Phones and Privacy for Consumers Matt Hoy (mattrix) and David Khudaverdyan (deltaflyer)
- Path Well-Traveled: Common Mistakes with SIEM Nick Jacob
- How compliance doesn't have to suck….at least totally Robert Carson & Bradley Stine
- What is a cloud access broker and do I need one? Tom Doane
- Security Frameworks: What was once old is new again Brian Wrozek
- Attacks Against Critical Infrastructures Weakest Links Jonathan Curtis
- Wireless Intrusion Detection Systems with the Raspberry Pi Chris J
- No One Cares About Your Data Breach Except You ... And Why Should They? Joel Cardella
Currículo Open Source Society University
En Cyberhades creemos firmemente en la educación continúa, sobre todo en el campo en el que nos movemos: la tecnología.
Si sigues el blog, sabrás que nos gustan publicar vídeos, material y clases que se ofrecen de forma gratuita, ya hemos hablado de Coursera, Udacity, MIT (OpenCourseWare), etc, verdaderas joyas para el autodidacta.
En sitios web como Coursera o Udacity, pusieron de moda la idea de Specializations o Nanodegrees respectivamente. Estos no son más que un currículo que agrupa una serie de clases ofrecidas por los mismos, con enfoque a un tema en particular.
Fotos de la Maker Faire 2015
Este año hemos tenido también la suerte de asistir a la fantástica Maker Faire de Queens en Nueva York. Aquí podéis ver una selección de productos y stands que más nos han llamado la atención. Aún seguimos analizando toda la información que hemos sacado de nuestra visita e intentaremos publicarla también poco a poco en el blog.
De Nuevo hay que destacar la gran afluencia de público, sobre todo familias, donde se compartían diferentes actividades creativas como aprender a soldar, programar ladrillos de LEGO, coser o incluso a montar pinballs de cartón.
Vídeos de Black Hat USA 2015
Y después del material, ya podemos acceder también a los vídeos de las presentaciones de Black Hat USA 2015:
- ZigBee Exploited The Good, The Bad, And The Ugly
- WSUSpect Compromising The Windows Enterprise Via Windows Update
- Writing Bad @$$ Malware For OS X
- Winning The Online Banking War
- Why Security Data Science Matters & How It's Different Pitfalls And Promises Of
- Why Security Data Science Matters & How It's Different Pitfalls And Promises Of
- When IoT Attacks Hacking A Linux Powered Rifle
- Web Timing Attacks Made Practical
- Using Static Binary Analysis To Find Vulnerabilities And Backdoors In Firmware
- Unicorn Next Generation CPU Emulator Framework
- Understanding The Attack Surface & Attack Resilience Of Project Spartan's New E
- Understanding And Managing Entropy Usage
- TrustKit Code Injection On IOS 8 For The Greater Good
- ThunderStrike 2 Sith Strike
- THIS IS DeepERENT Tracking App Behaviors With Nothing Changed Phone
- These're Not Your Grand Daddy's CPU Performance Counters CPU Hardware Performa
- The Tactical Application Security Program Getting Stuff Done
- The NSA Playset A Year Of Toys And Tools
- The Node js Highway Attacks Are At Full Throttle
- The Memory Sinkhole Unleashing An X86 Design Flaw Allowing Universal Privilege
- The Little Pump Gauge That Could Attacks Against Gas Pump Monitoring Systems
- The Lifecycle Of A Revolution
- The Kali Linux Dojo Workshop #2 Kali USB Setups With Persistent Stores & LUKS N
- The Kali Linux Dojo Workshop #1 Rolling Your Own Generating Custom Kali Linux 2
- The Battle For Free Speech On The Internet
- The Applications Of Deep Learning On Traffic Identification
- Taxonomic Modeling Of Security Threats In Software Defined Networking
- Targeted Takedowns Minimizing Collateral Damage Using Passive DNS
- Taking Event Correlation With You
- Take A Hacker To Work Day How Federal Prosecutors Use The CFAA
- Switches Get Stitches
- Subverting Satellite Receivers For Botnet And Profit
- Stranger Danger! What Is The Risk From 3rd Party Libraries
- Staying Persistent In Software Defined Networks
- Stagefright Scary Code In The Heart Of Android
- Spread Spectrum Satcom Hacking Attacking The Globalstar Simplex Data Service
- Social Engineering The Windows Kernel Finding & Exploiting Token Handling Vulne
- SMBv2 Sharing More Than Just Your Files
- Server Side Template Injection RCE For The Modern Web App
- Securing Your Big Data Environment
- ROPInjector Using Return Oriented Programming For Polymorphism & Antivirus Evas
- Rocking The Pocket Book Hacking Chemical Plant For Competition And Extortion
- Review And Exploit Neglected Attack Surfaces In IOS 8
- Return To Where You Can't Exploit What You Can't Find
- Repurposing OnionDuke A Single Case Study Around Reusing Nation State Malware
- Remote Physical Damage 101 Bread And Butter Attacks
- Remote Exploitation Of An Unaltered Passenger Vehicle
- Red Vs Blue Modern Active Directory Attacks, Detection, And Protection
- PWNIE AWARDS
- Pen Testing A City
- Panel How The Wassenaar Arrangement's Export Control Of Intrusion Soft Affect
- Optimized Fuzzing IOKit In IOS
- My Bro The ELK Obtaining Context From Security Events
- Most Ransomware Isn't As Complex As You Might Think
- Mobile Point Of Scam Attacking The Square Reader
- Is The NSA Still Listening To Your Calls A Surveillance Debate Congressiona
- Internet Scale File Analysis
- Internet Facing PLCs A New Back Orifice
- Internet Plumbing Gor Security Professionals The State Of BGP Security
- Information Access And Information Sharing Where We Are And Where We Are Going
- How Vulnerable Are We To Scams
- How To Implement IT Security After A Cyber Meltdown
- How To Hack Government Technologists As Policy Makers
- Hidden Risks Of Biometric Identifiers And How To Avoid Them
- HI THIS IS URGENT PLZ FIX ASAP Critical Vulnerabilities And Bug Bounty Programs
- Harnessing Intelligence From Malware Repositories
- Graphic Content Ahead Towards Auto Scalable Analysis Of Graphical Images Emb
- GameOver Zeus Badguys And Backends
- From False Positives To Actionable Analysis Behavioral Intrusion Detection
- Forging The USB Armory, An Open Source Secure Flash Drive Sized Computer
- Fingerprints On Mobile Devices Abusing And Leaking
- FileCry The New Age Of XXE
- Faux Disk Encryption Realities Of Secure Storage On Mobile Devices
- Exploiting XXE Vulnerabilities In File Parsing Functionality
- Exploiting The DRAM Rowhammer Bug To Gain Kernel Privileges
- Exploiting Out of Order Execution For Covert Cross VM Communication
- Emanate Like A Boss Generalized Covert Data Exfiltration With Funtenna
- Dom Flow Untangling The DOM For More Easy Juicy Bugs
- Distributing The Reconstruction Of High Level Intermediate Representation
- Defeating Pass the Hash Separation Of Powers
- Defeating Machine Learning What Your Security Vendor Is Not Telling You
- Deep Learning On Disassembly
- Data Driven Threat Intelligence Metrics On Indicator Dissemination And Sharing
- Dance Like Nobodys Watching Encrypt Like Everyone Is A Peek Inside The BlackHat
- Crash & Pay How To Own And Clone Contactless Payment Devices
- CrackLord Maximizing Password Cracking Boxes
- Commercial Mobile Spyware Detecting The Undetectable
- Cloning 3G4G SIM Cards With A PC And An Oscilloscope Lessons Learned
- Certifi gate Front Door Access To Pwning Millions Of Androids
- Bypass Surgery Abusing Content Delivery Networks With Ser-Side Request Forgery
- Bypass Control Flow Guard Comprehensively
- Broadcasting Your Attack Security Testing DAB Radio In Cars
- Bringing A Cannon To A Knife Fight
- Bring Back The Honeypots
- Breaking Payloads With Runtime Code Stripping And Image Freezing
- Breaking HTTPS With BGP Hijacking
- Breaking Honeypots For Fun And Profit
- Breaking Access Controls With BLEKey
- Big Game Hunting The Peculiarities Of Nation State Malware Research
- BGP Stream
- Behind The Mask The Agenda, Tricks, & Tactics Of The Federal Trade Commission A
- Battle Of The SKM And IUM How Windows 10 Rewrites OS Architecture
- Back Doors And Front Doors Breaking The Unbreakable System
- Automated Human Vulnerability Scanning With AVA
- Attacking Interoperability An OLE Edition
- Attacking Hypervisors Using Firmware And Hardware
- Attacking ECMAScript Engines With Redefinition
- Assessing And Exploiting BigNum Vulnerabilities
- API Deobfuscator Resolving Obfuscated API Functions In Modern Packers
- Android Security State Of The Union
- Ah! Universal Android Rooting Is Back
- Adventures In Femtoland 350 Yuan For Invaluable Fun
- Advanced IC Reverse Engineering Tech In Depth Analysis Of A Modern Smart Ca
- Abusing XSLT For Practical Attacks
- Abusing Windows Management Instrumentation WMI To Build A Persistent, Asyn
- Abusing Silent Mitigations Understanding Weaknesses Within Internet Explorer's

