• Link zu X
  • Link zu Xing
  • Link zu LinkedIn
  • English English Englisch en
  • Deutsch Deutsch Deutsch de
SevenShift
  • Services
  • Training
    • IoT Security Bootcamp
    • ASSESSING und EXPLOITING CONTROL SYSTEMS & IIoT
    • IoT Security Strategy Training
  • Blog DE
  • Über uns
    • Kontakt
    • Partners
    • Karriere
  • Click to open the search input field Click to open the search input field Suche
  • Menü Menü

BSides München 2019 Fazit

Between the 24th and 25th of March I participated in the BSides Conference and Workshops, this piece presents a short recapitulation of what I saw, learned and liked about the event.

My journey started in the middle of January when I filled out the call for papers and workshops. The goal present a one day workshop to give back to the security community and test some new hands-on exercises and slides on wireless hacking. About one month later I received a friendly acceptance email.

Tag eins: Workshop

As always, some things kept me working until well into the night a couple of days before the event. But finally, left for the workshop on the Sunday at 3:30 am. I got to the venue on time, even though I had planned a buffer just in case.

Everything was very well organized. I picked up my credentials and made my way to the classroom. The location, was the brand new office of the TÜV SÜD in Munich. The meeting rooms even had the protective plastics on.

I was lucky to have the biggest group, 16 participants with different backgrounds and experience levels. From experienced pentesters and security experts in other domains to college students. Did I mention that the event, including my workshop was sold out in less than two hours!

We pretty much went through the material as planned, covering an introduction to SDR and radio waves. We covered some tools like gnuradio and RTL-SDR and then dove into working with universal radio hacker (urh). I did manage to get some Yardstick Ones delivered on time for the event, so we practiced capturing and sending information with them. We closed, by reverse engineering the signals from a couple temperature sensors working in the ISM bands.

The direct feedback was great. All participants said that it was worth investing the day indoors, even though there was gorgeous weather outside. I’m happy that the new content, especially the hands-on exercises, were as educational as I expected.

Tag zwei: Konferenz

  • Wireless Hacking Workshop

  • Die Folien

  • Wireless Hacking mit Yardstick One

  • Break room

  • Resources, Folie aus "From crying out cloud"

  • Automotive complexity

  • Automotive security process

    Looks a lot like a SDLC

  • Automotive security tools

    Reminds me a lot of an IoT Security toolbox

  • The BSides Munich 2019 Team

Zurück Zurück Zurück Weiter Weiter Weiter
123456789

The conference was as well organized as the workshops. The team got everyone checked in pretty quickly, paths were pretty clear on where to go for the talks and they even did a simultaneous broadcast from the main auditorium into the smaller Moonshot Track room.

As all conferences it is very hard to pick which talks to attend, you never know all the variables: Is the speaker good? Can he deliver his message? Will it be edutaining or will I be bored to death? Will I actually learn something about the topic? In which talk will I gain the knowledge nuget I came for?

The best talks I saw on site were the following:

  • For Crying out Cloud by Stu Hirst & Tash Norris – [recording]

Stu and Tash delivered a really cool talk. They shared the little secrets that have allowed
them to build and motivate an external team to support their efforts. Since they are the only dedicated FTE’s working on security they depend a lot on management, IT and developers to help them get anything done.

  • Quick and Easy Forensic Timelines via Sysmon, WEF, and ELK by Aaron Jewitt – [recording] – [slides]

Aaron presented a really good talk: to the point and filled with actionable information on how to build a system that allows you to create forensic timelines and detect security issues.

  • My lessons learned in automotive Security by Sebastian Haase – [recording]

Sebastian talked about his experience doing offensive security for an automotive OEM (car manufacturer in automove lingo). He presented the challenges of the industry, timelines and how it has evolved in the last couple of years. The high level overview of the testing methodology, tools and required knowledge, were really good.
For me it was very interesting to see how testing a car is not very different than the work I do in IoT.

In parallel to the conference, there was a Capture the Flag (CtF) event. I always find it pretty hard to do a conference and the CtF at the same time. So I normally try to do the conference and pick my brain with the challenges when I get bored. One of the highlights, were the IoT challenges. These went from a voice powered interface to UART hacking of microcontrollers.

Fazit

To sum up the event in a couple of sentences. It was very good in content and organization. The team was very friendly and did a great job to make it a smooth experience. I will come back next year. Look for the slides and recording to all the talks on the BSidesMuc Website.

Next Trainings & Events

  • No events
  • Latests news

    • Training strategy 202323. Februar 2023 - 19:37
    • IoT Security Bootcamp live at BruCON 0x0E (Spring and Conference)4. März 2022 - 9:52
    • Rückblick auf das Jahr 2020
      Rückblick auf das Jahr 202031. Januar 2021 - 16:54

    Where to find us

    SevenShift GmbH
    Im Mediapark 5
    50670 Cologne
    Germany

    How to contact us

    Email: info@sevenshift.de
    Phone: +49 221 952 609 12
    Fax: +49 221 952 609 11

    • Services
    • Training
      • IoT Security Bootcamp
      • ASSESSING und EXPLOITING CONTROL SYSTEMS & IIoT
      • IoT Security Strategy Training
    • Blog DE
    • Über uns
      • Kontakt
      • Partners
      • Karriere
    @Copyright - SevenShift GmbH 2018
    • Link zu X
    • Link zu Xing
    • Link zu LinkedIn
    • Kontakt
    • Karriere
    • Impressum | Datenschutz
    • AGBs
    Link to: IoT Security Bootcamp 2019-05: Last call für Frühbuchertickets (Early Bird) Link to: IoT Security Bootcamp 2019-05: Last call für Frühbuchertickets (Early Bird) IoT Security Bootcamp 2019-05: Last call für Frühbuchertickets (Early Bir... Link to: Präsentation unseres neuen Partners: ISH – Information Security Hub Link to: Präsentation unseres neuen Partners: ISH – Information Security Hub Flugzeug wartet darauf, geladen zu werden. Logos von ISH und SevenshiftPräsentation unseres neuen Partners: ISH – Information Security Hub
    Nach oben scrollen Nach oben scrollen Nach oben scrollen

    Diese Website verwendet Cookies. Durch das weitere Durchsuchen der Website erklären Sie sich mit der Verwendung von Cookies einverstanden. Für Details siehe unsere Impressum | Datenschutz.

    OK

    Cookie- und Datenschutzeinstellungen



    Wie wir Cookies verwenden

    Wir können Cookies anfordern, die auf Ihrem Gerät eingestellt werden. Wir verwenden Cookies, um uns mitzuteilen, wenn Sie unsere Websites besuchen, wie Sie mit uns interagieren, Ihre Nutzererfahrung verbessern und Ihre Beziehung zu unserer Website anpassen.

    Klicken Sie auf die verschiedenen Kategorienüberschriften, um mehr zu erfahren. Sie können auch einige Ihrer Einstellungen ändern. Beachten Sie, dass das Blockieren einiger Arten von Cookies Auswirkungen auf Ihre Erfahrung auf unseren Websites und auf die Dienste haben kann, die wir anbieten können.

    Notwendige Website Cookies

    Diese Cookies sind unbedingt erforderlich, um Ihnen die auf unserer Webseite verfügbaren Dienste und Funktionen zur Verfügung zu stellen.

    Da diese Cookies für die auf unserer Webseite verfügbaren Dienste und Funktionen unbedingt erforderlich sind, hat die Ablehnung Auswirkungen auf die Funktionsweise unserer Webseite. Sie können Cookies jederzeit blockieren oder löschen, indem Sie Ihre Browsereinstellungen ändern und das Blockieren aller Cookies auf dieser Webseite erzwingen. Sie werden jedoch immer aufgefordert, Cookies zu akzeptieren / abzulehnen, wenn Sie unsere Website erneut besuchen.

    Wir respektieren es voll und ganz, wenn Sie Cookies ablehnen möchten. Um zu vermeiden, dass Sie immer wieder nach Cookies gefragt werden, erlauben Sie uns bitte, einen Cookie für Ihre Einstellungen zu speichern. Sie können sich jederzeit abmelden oder andere Cookies zulassen, um unsere Dienste vollumfänglich nutzen zu können. Wenn Sie Cookies ablehnen, werden alle gesetzten Cookies auf unserer Domain entfernt.

    Wir stellen Ihnen eine Liste der von Ihrem Computer auf unserer Domain gespeicherten Cookies zur Verfügung. Aus Sicherheitsgründen können wie Ihnen keine Cookies anzeigen, die von anderen Domains gespeichert werden. Diese können Sie in den Sicherheitseinstellungen Ihres Browsers einsehen.

    Google Analytics Cookies

    Diese Cookies sammeln Informationen, die uns - teilweise zusammengefasst - dabei helfen zu verstehen, wie unsere Webseite genutzt wird und wie effektiv unsere Marketing-Maßnahmen sind. Auch können wir mit den Erkenntnissen aus diesen Cookies unsere Anwendungen anpassen, um Ihre Nutzererfahrung auf unserer Webseite zu verbessern.

    Wenn Sie nicht wollen, dass wir Ihren Besuch auf unserer Seite verfolgen können Sie dies hier in Ihrem Browser blockieren:

    Andere externe Dienste

    Wir nutzen auch verschiedene externe Dienste wie Google Webfonts, Google Maps und externe Videoanbieter. Da diese Anbieter möglicherweise personenbezogene Daten von Ihnen speichern, können Sie diese hier deaktivieren. Bitte beachten Sie, dass eine Deaktivierung dieser Cookies die Funktionalität und das Aussehen unserer Webseite erheblich beeinträchtigen kann. Die Änderungen werden nach einem Neuladen der Seite wirksam.

    Google Webfont Einstellungen:

    Google Maps Einstellungen:

    Google reCaptcha Einstellungen:

    Vimeo und YouTube Einstellungen:

    Andere Cookies

    Die folgenden Cookies werden ebenfalls gebraucht - Sie können auswählen, ob Sie diesen zustimmen möchten:

    Datenschutzrichtlinie

    Sie können unsere Cookies und Datenschutzeinstellungen im Detail in unseren Datenschutzrichtlinie nachlesen.

    Impressum | Datenschutz
    Accept settingsHide notification only