If you’re the type that likes to dig deeper into tech, into the depths of the operating system and compiled code, then the August RISE meeting was for you. Shane Kennedy presented part 1 of a multi-part series on software exploit development that laid foundational concepts of software exploits such as buffer overflows.
KringleCon (by SANS #HolidayHack)
December is over four months away, but the SANS #HolidayHack team is hard at work preparing for this year’s event. They’ve opened registration for KringleCon, a free virtual conference in conjunction with this year’s event. Be sure to check it out!
August 2018 – Software Exploitation (Part 1)

Ready to learn about ‘buffer overflows’ and methods of exploiting binary software packages? Our next meeting will kick off a short series in the world of software exploitation and the tools and techniques used for analysis and execution. Continue reading
Meeting Notes – July Cook-out and ISE
Special thanks to our hosts for the July RISE meeting – ABS Technology – who provided the venue, great food, and presentation. Attendees enjoyed their fill of hot dogs and hamburgers and were then treated to an excellent technical presentation by Lee Berdick.

Rob photo-bombs the grill
July 2018 — ISE ISE Baby
RISE is excited to announce our July meeting – a cook-out hosted by ABS Technology! We are asking for RSVPs for this event so please read below if you plan to attend.
Our next meeting on Thursday, July 12, will be held at ABS Technology’s office in downtown Roanoke. Join us at 5:30pm for some great food in the view of Roanoke’s Downtown Historic District. Don’t worry about that summer heat as there will be plenty of ISE…Cisco Identity Services Engine. Speaker Lee Berdick will introduce ISE and discuss how it provides secure network access to users and devices.
Date: Thursday, July 12, 5:30pm
Address: ABS Technology, 109 Norfolk Ave, 2nd Floor, Roanoke, VA
RSVP REQUESTED! Please respond to roanokeinfosec@gmail.com if you will be there so we may estimate attendance. Free parking information will be provided to those who RSVP in advance. We don’t normally ask for this and appreciate your understanding so we can help our hosts plan for this special event.
Topic: Cisco ISE
Cisco ISE allows you to provide highly secure network access to users and devices. It helps you gain visibility into what is happening in your network, such as who is connected, which applications are installed and running, and much more. It also shares vital contextual data, such as user and device identities, threats, and vulnerabilities with integrated solutions from Cisco technology partners, so you can identify, contain, and remediate threats faster.
Speaker Bio: Lee Berdick
Lee joined ABS Technology in 2017 as a Senior Solutions Consultant. He graduated from Florida State University with a degree in Information Studies and a Graduate Certificate in Library Information Science.
Lee has been passionate about the IT field since he was 17 years old. It has been a central focus and interest in his life that led him to his career path. He holds several certifications including Certified Cisco Network Associate, Certified Cisco Design Associate, ITILv3, Palo Alto Networks Accredited Configuration Engineer, Splunk – SE I.
Outside of IT, Lee produces and DJ’s electronic dance music and has an extensive vinyl record collection with over 3,500 pieces.

(source: dilbert.com)
June 2018 — Harden Your Defenses

Mark your calendars to join us on Thursday, June 14th, at R&K Solutions for the next RISE meeting! This month Nate Sykes and James Gray will tag-team to present tools for risk management, compliance, and hardening your Windows-based servers. Learn about resources freely available on-line from the Defense Information Systems Agency such as Security Technical Implementation Guides, checklists, and scripts to ease implementation of secure configurations.
Address: R&K Solutions, 2797 Frontage Rd NW, Roanoke, VA 24017

Topic: Harden Your Defenses – Host-based Security in your Risk Management
Summary:
In the next RISE meeting we’ll be discussing one of the layers of Defense in Depth. Specifically, host-based security and how to implement Operating System hardening for Windows systems. We’ll be covering What, How, and Why. DoD Security Technical Implementation Guides (STIGs) will be used to create a secure baseline that you can deploy over and over to improve host-based security in your network. We’ll also be discussing how this maps to risk management and compliance framework controls, and how that can bring value to your organization.
Speaker Bios:
Nate Sykes
Nate Sykes is the IT Director at R&K Solutions and one of the founding members of RISE. Nate has worked in all areas of system and network administration. He has been involved in different aspects of security for the last 6 years, mostly involving prevention and detection. He holds GSEC, GMON and Security+ certifications.
James Gray
James Gray is a security professional working in operations and risk management. Some projects involve continuous monitoring, cloud security, and enterprise compliance. His professional history includes software quality assurance (QA/testing) management, training media development, counseling, education, driving buses, and bagging groceries. When he isn’t managing risk, James can be found enjoying the outdoors, gaming, and thinking about things.
Meeting notes – ‘Attacking the Gatekeeper’
This week RISE welcomed Harrison Neal (PatchAdvisor) via video conference to talk about two vulnerabilities he discovered in the RSA authentication agent for IIS. Thanks to R&K Solutions for hosting the event!

Harrison’s was a tale of accidental findings, curiosity, and persistence. Some odd language he found while working on an unrelated task provided a tantalizing thread to pull. Over the next few months, he spent his spare time fuzzing, analyzing encryption schemes, and reading up on named pipes to convert that accidental finding into two CVEs: CVE-2018-1232 and CVE-2018-1234.
The brief exemplified many qualities of successful vulnerability analysis. A curious eye caught an oddly-worded statement. Data gathering ensued using a methodical approach and a common tool set to look for known vulnerabilities, patterns, or unusual signatures as starting points for research. Researching vendor documentation to understand the systems and look for additional attack vectors. Perhaps most importantly – persistence in spending many hours of personal time in trial-and-error working towards a solution. Even if his work hadn’t resulted in two findings, Harrison likely picked up additional knowledge and techniques in the journey for future application.

RISE thanks Harrison for sharing his story with our members. Do you have an idea for an upcoming meeting? Share your stories or expertise! Reach out to us at roanokeinfosec@gmail.com.
May 2018 – Attacking the Gatekeeper

(source: xkcd.com; Don’t forget Mother’s Day!)
It’s scheduled! Mark your calendars to join us on May 10th at R&K Solutions for more experts sharing their trade craft. Harrison Neal, Security Engineer with PatchAdvisor, joins us to present a couple of (now patched) vulnerabilities he reported in the RSA authentication agent for IIS. If you’re interested in vulnerability research and details you’ll want to be at this meeting. Come for the tech, stay for the networking and refreshments!
Date and Location:
May 10th, 2018 @ 5:30 PM
R&K Solutions
2797 Frontage Rd NW
Roanoke, VA 24017
Google Maps Link
Topic: Attacking the gatekeeper: RSA’s Authentication Agent for IIS
Summary: This presentation will discuss two vulnerabilities recently discovered and patched in RSA’s software to enable two-factor authentication in IIS-hosted web applications. These vulnerabilities could enable an unprivileged domain user to impersonate other users, or crash IIS. While the vulnerabilities are fairly straightforward, there are some peculiarities that will be explored, such as exploiting one vulnerability through a named pipe rather than typical IP sockets. The presentation will also review known available mitigations for administrators.
Speaker Bio: Harrison Neal alternates between pentesting and security research roles, primarily around the DC metro area. His free time is typically spent metaphorically poking bears, enjoying the company of cats, playing Pokemon Go, or getting locked in Shenandoah National Park after hours.
April Intro to KALI Meeting Notes
Thanks to Nate Sykes and R&K Solutions for hosting our April ‘Intro to KALI’ meeting! Rob Garbee reviewed some of the popular tools included in the KALI Linux distribution. Rob’s presentation can be downloaded using the link below.
We’re lining up events for the coming months. If you have a topic or idea of interest to the group, please drop us a line at roanokeinfosec@gmail.com.
April 2018 – Intro to KALI
FINALLY!
It’s really gonna happen this time. Seriously, I mean it.

After multiple attempts to get this one in we’re really gonna do it this time.
Our next meeting will be on April 12th at R&K Solutions in Roanoke, VA. at 5:30pm. Our subject will be an Intro to KALI Linux. If you don’t know what KALI Linux is or if you do but want to know a little more have we got a meeting for you! This operating system is the defacto standard for Pen Testing. We will be going through some of the more popular tools such as Metasploit, SPARTA, NMAP and OpenVAS as well as Offensive Security cert paths.
Please come out and join us.
Address: R&K Solutions, 2797 Frontage Rd NW, Roanoke, VA 24017
More info about KALI below:
Kali Linux is a Debian-based Linux distribution aimed at advanced Penetration Testing and Security Auditing. Kali contains several hundred tools which are geared towards various information security tasks, such as Penetration Testing, Security research, Computer Forensics and Reverse Engineering. Kali Linux is developed, funded and maintained by Offensive Security, a leading information security training company.