• Link to X
  • Link to Xing
  • Link to LinkedIn
  • English English English en
  • Deutsch Deutsch German de
SevenShift
  • Services
  • Training
    • IoT Security Bootcamp
    • ASSESSING and EXPLOITING CONTROL SYSTEMS & IIoT
    • IoT Security Strategy Training
  • Blog
  • About Us
    • Contact
    • Partners
    • Career
  • Projects
    • Bunkai
    • CRACoWi
  • Click to open the search input field Click to open the search input field Search
  • Menu Menu

BSides Munich 2019 Recap

Between the 24th and 25th of March I participated in the BSides Conference and Workshops, this piece presents a short recapitulation of what I saw, learned and liked about the event.

My journey started in the middle of January when I filled out the call for papers and workshops. The goal present a one day workshop to give back to the security community and test some new hands-on exercises and slides on wireless hacking. About one month later I received a friendly acceptance email.

Day one: workshop

As always, some things kept me working until well into the night a couple of days before the event. But finally, left for the workshop on the Sunday at 3:30 am. I got to the venue on time, even though I had planned a buffer just in case.

Everything was very well organized. I picked up my credentials and made my way to the classroom. The location, was the brand new office of the TÜV SÜD in Munich. The meeting rooms even had the protective plastics on.

I was lucky to have the biggest group, 16 participants with different backgrounds and experience levels. From experienced pentesters and security experts in other domains to college students. Did I mention that the event, including my workshop was sold out in less than two hours!

We pretty much went through the material as planned, covering an introduction to SDR and radio waves. We covered some tools like gnuradio and RTL-SDR and then dove into working with universal radio hacker (urh). I did manage to get some Yardstick Ones delivered on time for the event, so we practiced capturing and sending information with them. We closed, by reverse engineering the signals from a couple temperature sensors working in the ISM bands.

The direct feedback was great. All participants said that it was worth investing the day indoors, even though there was gorgeous weather outside. I’m happy that the new content, especially the hands-on exercises, were as educational as I expected.

Day two: conference

  • Wireless hacking workshop

  • The slide deck

  • Wireless hacking with Yardstick One

  • The conference break room

  • Resources, slide of "From crying out cloud"

  • Automotive complexity

  • Automotive security process

    Looks a lot like a SDLC

  • Automotive security tools

    Reminds me a lot of an IoT Security toolbox

  • The BSides Munich 2019 Team

Previous Previous Previous Next Next Next
123456789

The conference was as well organized as the workshops. The team got everyone checked in pretty quickly, paths were pretty clear on where to go for the talks and they even did a simultaneous broadcast from the main auditorium into the smaller Moonshot Track room.

As all conferences it is very hard to pick which talks to attend, you never know all the variables: Is the speaker good? Can he deliver his message? Will it be edutaining or will I be bored to death? Will I actually learn something about the topic? In which talk will I gain the knowledge nuget I came for?

The best talks I saw on site were the following:

  • For Crying out Cloud by Stu Hirst & Tash Norris – [recording]

Stu and Tash delivered a really cool talk. They shared the little secrets that have allowed
them to build and motivate an external team to support their efforts. Since they are the only dedicated FTE’s working on security they depend a lot on management, IT and developers to help them get anything done.

  • Quick and Easy Forensic Timelines via Sysmon, WEF, and ELK by Aaron Jewitt – [recording] – [slides]

Aaron presented a really good talk: to the point and filled with actionable information on how to build a system that allows you to create forensic timelines and detect security issues.

  • My lessons learned in automotive Security by Sebastian Haase – [recording]

Sebastian talked about his experience doing offensive security for an automotive OEM (car manufacturer in automove lingo). He presented the challenges of the industry, timelines and how it has evolved in the last couple of years. The high level overview of the testing methodology, tools and required knowledge, were really good.
For me it was very interesting to see how testing a car is not very different than the work I do in IoT.

In parallel to the conference, there was a Capture the Flag (CtF) event. I always find it pretty hard to do a conference and the CtF at the same time. So I normally try to do the conference and pick my brain with the challenges when I get bored. One of the highlights, were the IoT challenges. These went from a voice powered interface to UART hacking of microcontrollers.

Summary

To sum up the event in a couple of sentences. It was very good in content and organization. The team was very friendly and did a great job to make it a smooth experience. I will come back next year. Look for the slides and recording to all the talks on the BSidesMuc Website.

Next Trainings & Events

  • No events
  • Latests news

    • Training strategy 20232023-02-23 - 19:37
    • IoT Security Bootcamp live at BruCON 0x0E (Spring and Conference)2022-03-04 - 09:52
    • 2020_in_review
      Looking back at the year 20202021-01-31 - 16:54

    Where to find us

    SevenShift GmbH
    Im Mediapark 5
    50670 Cologne
    Germany

    How to contact us

    Email: info@sevenshift.de
    Phone: +49 221 952 609 12
    Fax: +49 221 952 609 11

    • Services
    • Training
      • IoT Security Bootcamp
      • ASSESSING and EXPLOITING CONTROL SYSTEMS & IIoT
      • IoT Security Strategy Training
    • Blog
    • About Us
      • Contact
      • Partners
      • Career
    • Projects
      • Bunkai
      • CRACoWi
    @Copyright - SevenShift GmbH 2018
    • Link to X
    • Link to Xing
    • Link to LinkedIn
    • Contact
    • Career
    • Legal Notice | Privacy Policy
    • Terms & Cond.
    Link to: IoT Security Bootcamp 2019-05: Last call for Early Bird Tickets Link to: IoT Security Bootcamp 2019-05: Last call for Early Bird Tickets IoT Security Bootcamp 2019-05: Last call for Early Bird TicketsPhoto by Braden Collum on Unsplash Link to: Presenting our new partner: ISH – Information Security Hub Link to: Presenting our new partner: ISH – Information Security Hub Airplane waiting to be loaded. ISH and Sevenshift logosFoto credit: ken-yam-1152004-unsplashPresenting our new partner: ISH – Information Security Hub
    Scroll to top Scroll to top Scroll to top

    This site uses cookies. By continuing to browse the site, you are agreeing to our use of cookies. For details see our Legal Notice | Privacy Policy.

    OK

    Cookie and Privacy Settings



    How we use cookies

    We may request cookies to be set on your device. We use cookies to let us know when you visit our websites, how you interact with us, to enrich your user experience, and to customize your relationship with our website.

    Click on the different category headings to find out more. You can also change some of your preferences. Note that blocking some types of cookies may impact your experience on our websites and the services we are able to offer.

    Essential Website Cookies

    These cookies are strictly necessary to provide you with services available through our website and to use some of its features.

    Because these cookies are strictly necessary to deliver the website, you cannot refuse them without impacting how our site functions. You can block or delete them by changing your browser settings and force blocking all cookies on this website.

    Google Analytics Cookies

    These cookies collect information that is used either in aggregate form to help us understand how our website is being used or how effective our marketing campaigns are, or to help us customize our website and application for you in order to enhance your experience.

    If you do not want that we track your visist to our site you can disable tracking in your browser here:

    Other external services

    We also use different external services like Google Webfonts, Google Maps and external Video providers. Since these providers may collect personal data like your IP address we allow you to block them here. Please be aware that this might heavily reduce the functionality and appearance of our site. Changes will take effect once you reload the page.

    Google Webfont Settings:

    Google Map Settings:

    Vimeo and Youtube video embeds:

    Privacy Policy

    You can read about our cookies and privacy settings in detail on our Privacy Policy Page.

    Legal Notice | Privacy Policy
    Accept settingsHide notification only