The Dutch
Security Cluster
 
 
The Dutch
Security Cluster

null Meetup: "Flying Drones, NSA Hacking and Backdooring Bootloaders"

01
Nov
Date:
01 November 2017
Time:
18:30 - 21:30 hrs
Location:
Teleportboulevard 121, Amsterdam Sloterdijk
Organised by:
KPN

Agenda:

1. "Drones Don't Fly When the Sky is Grey" with Javi Moreno
2. "I Boot when U-Boot" by Bernardo Maia Rodrigues - Vincent Ruijter

------------------

Abstract of first talk: A short film by Bea Cabrera. Project presentation, film screening and Q&A.
Storyline: After discovering the tracks of what looks like an illegal hacking attempt upon his company’s network, Mike Donahue will pursue the trespassers’ digital trail while staying one step ahead of the NSA. A fictional story about government surveillance loosely, but factually, based on recent real events.

------------------

Abstract of second talk: Personal computer systems are now considerably more secure than embedded devices. Trusted Platform Module (TPM) and secure boot are readily available and even default in a lot of new desktop computers and laptops. Numerous small office and consumer devices, including routers and smart televisions, however, are lacking even the most basic security features. In this talk we will demonstrate and describe the inner-workings of a custom developed (Fully Weaponised IoT Cyber™) bootkit, which gains persistence on U-Boot based embedded devices, at a lower level than even the firmware. Firmware updates and factory resets usually do not interfere with the bootloader, as a small problem could render the device unusable for an end-user: the bootkit will therefore remain present. By including a properly functioning killswitch and a multi-boot like technique, it is possible to switch between a regular and a backdoored image to thwart detection. Enterprises and ISPs must take this additional attack surface into account, and put effort into detecting and responding to this threat. Well-known security researchers have long advocated for easier ways to verify and demonstrate the integrity of hardware, but this comes at a price that vendors are not willing to pay for security. Recently however, regulatory bodies have started to enforce vendors to lock-down their wireless devices, in order to prevent them from operating outside of their certified frequencies. But these 'vendor lock-downs' are not sufficient to increase the device security, as we will demonstrate, it's just a minor inconvenience.

------------------

Speakers:

Javi Moreno works as a security consultant, specialised in cryptography and embedded security. Used to play CTFs often, now he prefers to sleep. He participated in Drones Don't Fly When the Sky is Grey as producer, advisor and coffee provider. You can follow him at @vierito5

Bernardo Maia Rodrigues (Brazil) Bernardo works as an Ethical Hacker for KPNs (Royal Duth Telecom) REDteam. He enjoys hacking (and bricking) embedded devices including routers, modems and TVs. He presented on security topics at the NullByte Conference, the null Amsterdam chapter and local venues. He frequently participates in CTFs with TheGoonies and is famous for not using buzzwords like IoT, APT and Cyber in his bio.

Vincent Ruijter (Netherlands) Pacifistic Internetveapon @ KPNs (Royal Dutch Telco) REDteam, who thinks he knows Linux. Moderator @ null Amsterdam chapter, with an endless curiosity for all things binary. Knows how to quit Vi ^[ESC!wqwq:wq!

More events

31
Mar

Cybersecurity en partnerships: "vloek en zegen" - (Webinar)

location:
InnStyle, Maarsen
organised by:
Cybersprint
HSD event
01
Apr

Digital Experience Belgium - Postponed due to Corona

location:
Van der Valk Brussel Airport
organised by:
DataExpert BV
HSD event
01-03
Apr

ASIS Europe 2020 - From Risk to Resilience - Postponed due to Corona

location:
Prague, Czech Republic
organised by:
ASIS International
HSD event
07
Apr

HSD Café: OT Security - Uitgesteld ivm Corona

location:
HSD Campus, 7th floor
organised by:
HSD Office
HSD event
17
Apr

Finals Blue Tulip Awards 2020

location:
Taets Art and Event Park, Zaandam
organised by:
Accenture
HSD event
17
Apr

ICP Captains' Conference 2020 - Postponed due to Corona

location:
WTC The Hague
organised by:
ICP (International Community Platform)
HSD event
20-23
Apr

EC-Council MasterClass Certified Ethical Hacker Program

location:
Amsterdam, Netherlands
organised by:
EC-Council
HSD event
23
Apr

Dag van de Fraude Onderzoeker

location:
Fokker Terminal Den Haag
organised by:
IFFC
HSD event
27-01
Apr-May

Hardwear.io Security Training - Cancelled due to Corona

location:
Biltmore Hotel and Suits, Santa Clara, CA, USA
organised by:
Hardwear.io
HSD event
29-30
Apr

Mobile 360 - Security for 5G - Cancelled due to Corona

location:
The Hague Conference Centre, New Babylon
organised by:
GSMA
HSD event
27-01
Apr-May

Hardwear.io Security Training - Cancelled due to Corona

location:
Biltmore Hotel and Suits, Santa Clara, CA, USA
organised by:
Hardwear.io
HSD event
13-14
May

ESCO Cyber Investor Days

location:
Brussels, Belgium
organised by:
ECSO and Digital Accelerator
HSD event
13
May

Matchmaking event: DRONE-DAYS 2.0

location:
Hôtel de la Poste, Tour & Taxis Avenue du Port 86c 1000, Brussels
organised by:
Hub.Brussels, Enterprise Europe Network
HSD event
19
May

Resilience and Adaptivity in Professional Education to Prepare for a Changing Security Environment - Cancelled due to Corona

location:
Brasserskade, The Hague
organised by:
Instituut Defensie Leergangen (Netherlands Defence College)
HSD event
19-21
May

Industry 4.0 Forum at #DES2020

location:
Madrid
organised by:
Digital Enterprise
HSD event
27
May

Jaarcongres 2020: Maak Haaglanden de innovatiefste regio

location:
World Horti Center Naaldwijk
organised by:
Innovatief Haaglanden
HSD event
02-04
Jun

Info Security Europe

location:
Olympia London
organised by:
Info Security Europe
HSD event
11
Jun

ASIS Security Management Congres 2020

location:
The Hague Marriott Hotel Johan de Wittlaan 30 2517 JR Den Haag
organised by:
Security Management, ASIS international
HSD event
13-17
Jun

Hannover Messe 2020 | Holland High Tech House

location:
Hannover, Duitsland
organised by:
FME
HSD event
25
Jun

HSD Café: MKB Special - Boost Your Partnership

location:
HSD Campus, 7th floor
organised by:
HSD Office
HSD event
27
Jun

Challenge the Cyber 2020

location:
Dutch Innovation Factory: Bleiswijkseweg 37 2712 PB Zoetermeer
organised by:
National Cyber Security Centre, Ministery of Justice and Security, Dcypher
HSD event
23-28
Aug

International Cyber Security Summer School 2020

location:
organised by:
NATO C&I Agency, Europol,EY, Leiden University and HSD
HSD event
23-24
Sep

CyberTech Europe, Rome

location:
organised by:
CyberTech
HSD event
28
Sep

Hack The Hague 2020: Save the Date

location:
City Hall, Spui 70, 2511 BT The Hague
organised by:
City of The Hague and Cybersprint
HSD event
29-30
Sep

One Conference 2020: Save the Date

location:
World Forum, The Hague
organised by:
Ministry of Economic Affairs and Climate Policy, Ministry of Justice and Security, National Cyber Security Centre
HSD event
06-08
Oct

IT-SA 2020

location:
Exhibition Centre Nuremberg
organised by:
HSD event
06-08
Oct

Safety & Security Asia (SSA) 2020

location:
Singapore
organised by:
CEMS - Conference & Exhibition Management Services Ptr Ltd
HSD event
07-08
Oct

Digital Experience 2020 (NL)

location:
Van der Valk Hotel Utrecht
organised by:
DataExpert
HSD event
20-22
Oct

WorldPensionSummit 2020

location:
Louwman Museum, The Hague
organised by:
Pensions & Investments
HSD event
27
Oct

Impactfest 2020

location:
Fokker Terminal Den Haag
organised by:
HSD event
22-24
Nov

CyberTech Africa

location:
organised by:
CyberTech
HSD event
24-26
Mar

Call for proposal: EIT Digital 2021 Brokerage Events

location:
Brussels
organised by:
EIT Digitial
HSD event
27
Mar

Operatie Volt

location:
DeFabrique Westkanaaldijk 7 3542 DA Utrecht
organised by:
Politie en het Ministery van Defentie
HSD event