As probably so many of you, I’m currently in various discussions on the dawn of vulnerabilities discovered by AI. While the topic isn’t new, the dimensions very well might. Here a few thoughts.
AI is moving forward quickly, making life easier for the one and harder for the others. “Vibe Coding” was established in 2025 as one of the terms in this context, thus lets take the “Vibe” term a little bit further.
A while back I registered privlab.xyz for of my projects. A side job of this project is publicly sharing privlab.xyz to everybody learning and playing with IT, by having a public private DNS setup Here are the details on what it does.
The Cyber Resilience Act contains various chapters referring to products and when they were placed on the market. Here is a short insight into a tiny little pitfall that makes a big difference: The definition of “product”.
Working in Security, one of my core tasks is defending threats and attack vectors. Next to everybody tries to do downplay Security risks as improbable or irrelevant or simply wrong. Having a real world threat on the other side of the table should help, or at least I thought so…
IDs no matter if government or company issued, for fun or a club, have both crucial but also symbolic roles. Allowing access in many different ways, having an ID can be vital for both work and leisure. But how to get one if you shouldn’t have one? Well, have one printed for you!
Currently needing some deeper insights into LLMs, what they do and especially how they do it, I decided to write down a few lines, which I hope might be helpful. The post is mainly focused on, well, the dry basics and what implications these have or could have. In addition, it contains a short legal perspective, with the question: What is an AI System!?
Just having lost about a week debugging a potentially major issue, I’ve decided to share a few insights, to potentially save others the time I, we, just wasted: FortiVPN Auth with SSO shows a strange email address and redirects to login.live.com.
One of the most fun things of doing OT Security is being able to share strange things, just like todays Atlas Copco IPM IAM Process Control. What sounds fancy, well, lets just have a look.
Currently giving Binarly a spin, I got to run analysis on a bunch of firmware, I’ve been wanting to have a look at for a long time, with one special trait, it’s automated. Upload, wait a few minutes and then dive into the results. I started comparing the amounts of vulns, the criticality, rated a few devices myself and then got stuck on the question, what significance my comparisons have. Well,…
(Sorry, all German!)Ich habe im Laufe meiner Zeit, im Freundeskreis und anderswo, Aussagen wie “mach das doch nicht selbst, du bist doch viel zu teuer dafür” gehört. Meist fiel diese Aussage mit Bezug auf Gartenarbeit oder Reparaturen am Haus. Während ich nun, bereits seit längerem, größere Arbeiten am Haus kalkuliere und dabei einige Leistungen in Eigenarbeit machen möchte kriselt es etwas bei…
Sometimes, one wants to see whats going on on an embedded device, or maybe, what might have been going on in the past. For reliability and stability reasons, this is often not possibe as the UI provided by a device is there to protect the user from themselves. Yes, they might know what their doing, but it will break during the next update! In return, the limitations resulting from a specific UI,…
So I recently had to read through a few ten-thousand lines of Fortigate configs. Fun - No! But necessary. To make things a little easier and not having to do it all twice I wrote a small python script, creating a summary of the config. While not replacing a full manual assessment, it does make life easier!
So, somehow, I feel like often causing irritation by turning around, looking for an Ikea Samla Box, of which I now have just under 200, and quickly do a PoC, prove a point or find a reference. While others are often irritated that I have everything here, I’m irritated that they don’t. Here a few thoughts…
A few years back, mainly out of frustration, I developed something that started as a poor man’s asset management system for a company’s perimeter, which turned into a poor man’s perimeter Security tool. Right now, I’m doing the same again, so I guess it’s time to do a short write up.
After a long while, I’ve finally managed to write a few lines on my telescope. In addition it’s the last chance to motivate you to see the rings of saturn from your own garden.
I’m often told my home network is typical me and far to complex. For me it’s just as complex as necessary, as I honestly don’t have very much time to invest. Here a few notes on how I got here and why
The German elektronische PatientenAkte or electronic patient file is a central approach, storing notes from all doctors on all generally insured patients in a central, more or less, secure place. Sadly it’s just having a rough start with risk analysis excluding nation state attackers and various proven attack vectors. I did a small writeup for friends and familiy which I didn’t want to…
As already mentioned on various channels, I brought a fun little card printer with me to this year’s H2HC in Sao Paulo. Here a little bit of information on getting something printed!
Back in 2019 I gave a presentation at hardwear.io titled “Day One with a TTIG-868” . My talk was aimed at two aspects: An insight into device, I was curious as I had seen multiple commercial LoRaWAN gateways before and sharing the concept of single day security tests. Right now, I’m back at the point to want to stress the method as a potential quality assurance approach.
Most things that can easily kill you and others, require certification to ensure that applicable measures to reduce risks have been applied and that they’re functional. While all this is pretty trivial in the analog world, open a door -> release a switch -> open switch triggers a relay -> machine stops, the digital world is a little more complex. Especially when a program running on an operating…
A while back I started looking for a solution with which I could prove to be able to work safely from home while breaking devices. Sadly, I wasn’t able to find anything small and cheap enough to actually fit my desk. The best options I found where actual workbenches and tables in various sizes. Thus I decided to design my own Electronics Working Environment.
Back when COVID had started and the first vaccinations had been applied, there was the fun challenge of proving one’s vaccination status. It ended up working based on a digital signature provided as QR Code on a piece of paper. Needing it every day, paper didn’t quite have the necessary durability, the digital versions only helped people with smart phones, so I created a plastic card alternative.
Possibly highly intuitive to others, but a real b**** when not being fit. Here an insight into how to configure a Site to Site VPN with OpenVPN and two OPNsense routers and multiple subnets on both sides.
In Germany petrol stations have to regularly share the price of their products with a government agency. In addition public APIs were created, which give close to realtime access to the prices. Here a little example on how to fetch and use the data.
A while back Germany decided it would be a good idea to regulate the IT infrastructure in doctor’s practices. While obviously a smart move, it resulted in strange interpretations and even stranger architectures being implemented. This post shows the actual setup. But, er ist auf deutsch (it’s in German).
type: ‘post’ title: ‘USB Malware’ date: ‘2024-06-22 01:00:01 +0000’ tags: [] author: ‘brian’ A short while ago I needed some real life malware samples to do a PoC related to the infection mass storage devices like memory cards and USB drives. Sadly, while there was a lot of information on the malware, and a few available samples, I wasn’t able…
I recently received a nanoBTS 165G, which strangely enough made a rattling sound. While it’s a bad sign, as there might be a chance to short out and break the BTS, it’s a super easy fix. Here the insights!
One of my big Todo List projects is temperature monitoring for the house. Being a big fan of wired approaches, many available solutions don’t match my requirements or are far to expensive. Luckily Olimex published the perfect plattform a while back. I finally managed to get one. Here are some insights.
A lot of time is invested into defining and describing OT Security or Operational Technology Security, especially in contrast to IT Security. It’s very often hard to draw a proper line between both and complicated to keep it strict. Here is a little insight into why the line helps, where it makes things worse and a few recommendations on dealing with the resulting challenges.
A while back Germany decided it would be a good idea to regulate the IT infrastructure in doctor’s practices. While obviously a smart move, it resulted in strange interpretations and even stranger architectures being implemented. This post shows a secure reference architecture with explanations. But, er ist auf deutsch (it’s in German).
Yet another PoC from my to do list: Which data passes through the SIM card on a data modem? The specific question was, whether the APN credentials where passed to the SIM and could be intercepted with a SIMTrace. This post gives a quick overview on how to use a SIMTrace2 to create a PCAP trace.
After a long time discussing the concept of USB sticks with internal AV engines, I’ve decided to create a quick and dirty PoC. Thus, this post shows how to utilize a USB Armory MK II and ClamAV as a self-scanning USB stick. The Summary: It failed successfully!
type: ‘post’ title: ‘Why and how Flipper Zero, not What’ date: ‘2023-12-13 10:00:01 +0000’ tags: [] author: ‘brian’ I always enjoy talking to people with various practical experience in the Security field and how questions and discussions slightly shift. I.e. questions during the recent H2HC shifted from “What does the Flipper do?” over…
I recently got to make a new, fun badge for H2HC , which turned out to be a custom GameBoy game. This post gives a quick and easy insight into the how! If you just want to play, go here .
Sorry, only in German this time. Der verzweifelte Versuch Leuten zu erklären wieso “Wir kaufen da eine Security Schulung und dann ist fertig” eigentlich nicht so wirklich der Fall ist. Zusätzlich der Unterschied zwischen “Wir machen da mal eine Schulung” und “danach ist die Person Experte”.
Working with risks is a task various departments and roles have to perform throughout a large company or cooperations. Every single one of these as a different, valid, and important perspective on the same thing and thus has different requirements and wishes. This can easily result in overly complex situations and a lot of conflicts. Here a little insight into potential issues and risks when…
CyberChef is a quick and easy tool for playing with encodings, data and information. Using it regularly in presentations, trainings and examples I was recently asked for a super quick “HowTo”, so here it is.
I recently ran a hardware based CTF at H2HC in Brazil. As the CTF was to run for two days, it was setup in two phases, where each of them had tasks that could be solved independently and others that need hints from other challenges. Sadly, the challenges were seemingly far to hard for most of the attendees and the winning team only managed to extract 5 flags. Here is the complete writeup and guide…
Running some Ubiquiti UniFi equipment, I’ve also got a USW-Flex-Mini 5 port switch in my setup. Turns out it’s easy to mess up one’s config for them, when taking shortcuts. Here a little insight into the issue, supported features and the solution for the Flex Mini.
I recently wanted to understand why a product, which was certified following multiple different standards was so easy to pwn. Thus, I got to read a few standards..yay… Here a few random thoughts.
Needing a victim for an OT related talk, I decided to hit eBay and quickly found a cheap offer for a few Hirschmann industrial router/firewall/VPN node “EAGLE One” . For about 25Euro each, they were perfectly in budget and although it was the old and seemingly EOL version, I ordered two and had a look.
Since our first Packetwars at H2HC in 2015, it has somehow become a fun tradition. Although not having been involved in 2018, I was back this year and brought a few fun but seemingly too uggly challenges. Here is a short write up on the concepts, ideas and challenges.
A few months ago a friend asked me whether I’d be prepared to assist the Hacker Jeopardy staff to create a fun little prize for the 25th jubilee edition. After talking cool ideas, steampunk, nixie tubes and badges, we changed over to a small diorama of the HJ stage. All in all it resulted in the production of a limited edition of 15 Nixie tube clocks.
It seems that Hackers have a significant interest in Adrenaline and Epi-Pens: How they work, what they look like and how to use them. So, due to “having access”, I decided to write a short post with a “demo”. Obviously, above being interesting, it’s good to know how to use them.
I’m just on my way home from visiting Blue Frost Security ’s second edition of OffensiveCon . So, obviously, I need to start with a big thanks to Miguel, Lukas and all of the staff for a great conference! Now, sitting on the train with a few symptoms sleep deprivation, I thought I’d drop a few lines a small event I “ran” on the side: Lobby Con!
type: ‘post’ title: ‘#UnlockedLaptop’ date: ‘2019-02-05 00:00:01 +0000’ tags: [] author: ‘brian’ Still traveling quite a bit, I’m always fascinated to see people in various places “just quickly getting up” and leaving their laptop unlocked. Although they usually only leave their device unattended for a few minutes, well, all of us…