<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>SecDocs Feed for author Daniel Mende</title>
    <link>http://secdocs.lonerunners.net</link>
    <atom:link type="application/rss+xml" href="http://secdocs.lonerunners.net/rss/author/546-daniel-mende" rel="self"/>
    <description>Latest security documents RSS feed for author Daniel Mende</description>
    <language>en-us</language>
    <item>
      <title>[Paper] Burning Asgard - What happens when Loki breaks free</title>
      <description>&lt;b&gt;Authors&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/authors/details/546-daniel-mende"&gt;Daniel Mende&lt;/a&gt; &lt;a href="http://secdocs.lonerunners.net/authors/details/867-enno-rey"&gt;Enno Rey&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Tags&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/tags/details/24-network"&gt;network&lt;/a&gt; &lt;a href="http://secdocs.lonerunners.net/tags/details/25-routing"&gt;routing&lt;/a&gt; &lt;a href="http://secdocs.lonerunners.net/tags/details/83-exploiting"&gt;exploiting&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Event&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/events/details/71-black-hat-usa-2010"&gt;Black Hat USA 2010&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Abstract&lt;/b&gt;: I personally remember the release of Yersinia at Black Hat Europe 2005. It was a ground breaking experience: a number of Layer 2 attacks regarded purely theoretical until then, was suddenly available in a mostly automated way. And those guys even showed some forays completely unbeknownst to me at the time. We plan to do the same in Vegas, with a new tool called Loki (after the giant from Norse mythology associated with cunning, trickery and evil). It's a Python based framework implementing many packet generation and attack modules for Layer 3 protocols, including BGP, LDP, OSPF, VRRP and quite a few others.  After outlining Loki's inner architecture we'll give insight into several modules and discuss some particularly interesting attacks in the routing protocol space (e.g. cracking OSPF MD5 keys, injection of routes into OSPF and EIGRP environments etc.). Furthermore we'll describe vulnerabilities in lesser known protocols like VRRP. Every attack we mention will be shown in a practical demo and - of course - Loki will be released right after our talk.</description>
      <pubDate>Wed, 21 Sep 2011 20:39:50 +0200</pubDate>
      <link>http://secdocs.lonerunners.net/documents/details/4039-burning-asgard---what-happens-when-loki-breaks-free</link>
      <guid>http://secdocs.lonerunners.net/documents/details/4039-burning-asgard---what-happens-when-loki-breaks-free</guid>
    </item>
    <item>
      <title>[Slides] Burning Asgard - What happens when Loki breaks free</title>
      <description>&lt;b&gt;Authors&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/authors/details/546-daniel-mende"&gt;Daniel Mende&lt;/a&gt; &lt;a href="http://secdocs.lonerunners.net/authors/details/867-enno-rey"&gt;Enno Rey&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Tags&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/tags/details/24-network"&gt;network&lt;/a&gt; &lt;a href="http://secdocs.lonerunners.net/tags/details/25-routing"&gt;routing&lt;/a&gt; &lt;a href="http://secdocs.lonerunners.net/tags/details/83-exploiting"&gt;exploiting&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Event&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/events/details/71-black-hat-usa-2010"&gt;Black Hat USA 2010&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Abstract&lt;/b&gt;: I personally remember the release of Yersinia at Black Hat Europe 2005. It was a ground breaking experience: a number of Layer 2 attacks regarded purely theoretical until then, was suddenly available in a mostly automated way. And those guys even showed some forays completely unbeknownst to me at the time. We plan to do the same in Vegas, with a new tool called Loki (after the giant from Norse mythology associated with cunning, trickery and evil). It's a Python based framework implementing many packet generation and attack modules for Layer 3 protocols, including BGP, LDP, OSPF, VRRP and quite a few others.  After outlining Loki's inner architecture we'll give insight into several modules and discuss some particularly interesting attacks in the routing protocol space (e.g. cracking OSPF MD5 keys, injection of routes into OSPF and EIGRP environments etc.). Furthermore we'll describe vulnerabilities in lesser known protocols like VRRP. Every attack we mention will be shown in a practical demo and - of course - Loki will be released right after our talk.</description>
      <pubDate>Wed, 21 Sep 2011 20:39:34 +0200</pubDate>
      <link>http://secdocs.lonerunners.net/documents/details/4038-burning-asgard---what-happens-when-loki-breaks-free</link>
      <guid>http://secdocs.lonerunners.net/documents/details/4038-burning-asgard---what-happens-when-loki-breaks-free</guid>
    </item>
    <item>
      <title>[Slides] Attacking Cisco Enterprise WLANs</title>
      <description>&lt;b&gt;Authors&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/authors/details/546-daniel-mende"&gt;Daniel Mende&lt;/a&gt; &lt;a href="http://secdocs.lonerunners.net/authors/details/950-oliver-roeschke"&gt;Oliver Roeschke&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Tags&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/tags/details/24-network"&gt;network&lt;/a&gt; &lt;a href="http://secdocs.lonerunners.net/tags/details/107-cisco"&gt;Cisco&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Event&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/events/details/46-hack-in-the-box-2010-dubai"&gt;Hack In The Box 2010 Dubai&lt;/a&gt; &lt;br/&gt;</description>
      <pubDate>Fri, 01 Oct 2010 10:25:00 +0200</pubDate>
      <link>http://secdocs.lonerunners.net/documents/details/2911-attacking-cisco-enterprise-wlans</link>
      <guid>http://secdocs.lonerunners.net/documents/details/2911-attacking-cisco-enterprise-wlans</guid>
    </item>
    <item>
      <title>[Paper] Hacking Cisco Enterprise WLANs</title>
      <description>&lt;b&gt;Authors&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/authors/details/546-daniel-mende"&gt;Daniel Mende&lt;/a&gt; &lt;a href="http://secdocs.lonerunners.net/authors/details/867-enno-rey"&gt;Enno Rey&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Tags&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/tags/details/24-network"&gt;network&lt;/a&gt; &lt;a href="http://secdocs.lonerunners.net/tags/details/107-cisco"&gt;Cisco&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Event&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/events/details/41-black-hat-eu-2010"&gt;Black Hat EU 2010&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Abstract&lt;/b&gt;: The world of "Enterprise WLAN solutions" is full of obscure and "non-standard" elements and technologies. Cisco's solutions, from the early Structured Wireless-Aware Network (SWAN) to the current Cisco Wireless Unified Networking (CUWN) architectures, only partly differ here. In this talk we describe the inner workings of these solutions, dissect the vulnerable parts and discuss theoretical and practical attacks, with some nice demos.  A new tool automating a number of attacks (incl. taking over the WDS master role, extracting WPA pairwise master keys from intra-AP communication etc) will be released at Black Hat Europe.</description>
      <pubDate>Mon, 21 Jun 2010 02:12:19 +0200</pubDate>
      <link>http://secdocs.lonerunners.net/documents/details/2565-hacking-cisco-enterprise-wlans</link>
      <guid>http://secdocs.lonerunners.net/documents/details/2565-hacking-cisco-enterprise-wlans</guid>
    </item>
    <item>
      <title>[Slides] Hacking Cisco Enterprise WLANs</title>
      <description>&lt;b&gt;Authors&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/authors/details/546-daniel-mende"&gt;Daniel Mende&lt;/a&gt; &lt;a href="http://secdocs.lonerunners.net/authors/details/867-enno-rey"&gt;Enno Rey&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Tags&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/tags/details/24-network"&gt;network&lt;/a&gt; &lt;a href="http://secdocs.lonerunners.net/tags/details/107-cisco"&gt;Cisco&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Event&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/events/details/41-black-hat-eu-2010"&gt;Black Hat EU 2010&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Abstract&lt;/b&gt;: The world of "Enterprise WLAN solutions" is full of obscure and "non-standard" elements and technologies. Cisco's solutions, from the early Structured Wireless-Aware Network (SWAN) to the current Cisco Wireless Unified Networking (CUWN) architectures, only partly differ here. In this talk we describe the inner workings of these solutions, dissect the vulnerable parts and discuss theoretical and practical attacks, with some nice demos.  A new tool automating a number of attacks (incl. taking over the WDS master role, extracting WPA pairwise master keys from intra-AP communication etc) will be released at Black Hat Europe.</description>
      <pubDate>Mon, 21 Jun 2010 02:12:18 +0200</pubDate>
      <link>http://secdocs.lonerunners.net/documents/details/2564-hacking-cisco-enterprise-wlans</link>
      <guid>http://secdocs.lonerunners.net/documents/details/2564-hacking-cisco-enterprise-wlans</guid>
    </item>
    <item>
      <title>[Video] All Your Packets Are Belong to Us</title>
      <description>&lt;b&gt;Authors&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/authors/details/546-daniel-mende"&gt;Daniel Mende&lt;/a&gt; &lt;a href="http://secdocs.lonerunners.net/authors/details/547-simon-rich"&gt;Simon Rich&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Tags&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/tags/details/24-network"&gt;network&lt;/a&gt; &lt;a href="http://secdocs.lonerunners.net/tags/details/64-mpls"&gt;MPLS&lt;/a&gt; &lt;a href="http://secdocs.lonerunners.net/tags/details/250-bgp"&gt;BGP&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Event&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/events/details/31-har-2009"&gt;HAR 2009&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Abstract&lt;/b&gt;: The year 2008 has seen some severe attacks on infrastructure protocols (SNMP, DNS, BGP). We will continue down that road and discuss potential and real vulnerabilities in backbone technologies used in today's carrier space (e.g. MPLS, Carrier Ethernet, QinQ and the like). The talk includes a number of demos (like cracking BGP MD5 keys, redirecting MPLS traffic on a site level and some Carrier Ethernet stuff) all of which will be performed with a new tool kit made available at the con. It's about making the theoretical practical, once more!</description>
      <pubDate>Sat, 17 Oct 2009 12:18:00 +0200</pubDate>
      <link>http://secdocs.lonerunners.net/documents/details/1375-all-your-packets-are-belong-to-us</link>
      <guid>http://secdocs.lonerunners.net/documents/details/1375-all-your-packets-are-belong-to-us</guid>
    </item>
    <item>
      <title>[Slides] All Your Packets Are Belong to Us</title>
      <description>&lt;b&gt;Authors&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/authors/details/546-daniel-mende"&gt;Daniel Mende&lt;/a&gt; &lt;a href="http://secdocs.lonerunners.net/authors/details/547-simon-rich"&gt;Simon Rich&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Tags&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/tags/details/24-network"&gt;network&lt;/a&gt; &lt;a href="http://secdocs.lonerunners.net/tags/details/64-mpls"&gt;MPLS&lt;/a&gt; &lt;a href="http://secdocs.lonerunners.net/tags/details/250-bgp"&gt;BGP&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Event&lt;/b&gt;: &lt;a href="http://secdocs.lonerunners.net/events/details/31-har-2009"&gt;HAR 2009&lt;/a&gt; &lt;br/&gt;&lt;b&gt;Abstract&lt;/b&gt;: The year 2008 has seen some severe attacks on infrastructure protocols (SNMP, DNS, BGP). We will continue down that road and discuss potential and real vulnerabilities in backbone technologies used in today's carrier space (e.g. MPLS, Carrier Ethernet, QinQ and the like). The talk includes a number of demos (like cracking BGP MD5 keys, redirecting MPLS traffic on a site level and some Carrier Ethernet stuff) all of which will be performed with a new tool kit made available at the con. It's about making the theoretical practical, once more!</description>
      <pubDate>Sat, 17 Oct 2009 12:07:00 +0200</pubDate>
      <link>http://secdocs.lonerunners.net/documents/details/1374-all-your-packets-are-belong-to-us</link>
      <guid>http://secdocs.lonerunners.net/documents/details/1374-all-your-packets-are-belong-to-us</guid>
    </item>
  </channel>
</rss>

