Sept 2016 – Bad, Bad USB

Screen_Shot_2014-08-01_at_4.55.11_PM_1024x1024

We are in for a treat in September! Jeremy Dorrough is going to do an updated version of the presentation he did at DEF CON last year.

woo hoo

USB Attack to Decrypt Wi-Fi Communications

Jeremy Dorrough Senior Network Security Architect / Genworth Financial

The term “Bad USB” has gotten some much needed press in last few months. There have been talks that have identified the risks that are caused by the inherent trust between the OS and any device attached by USB. I found in my research that most of the available payloads for the USB rubber ducky would be stopped by common enterprise security solutions. I then set out to create a new exploit that would force the victim to trust my Man-In-The-Middle access point. After my payload is deployed, all Wi-Fi communications will be readable, including usernames, passwords and authentication cookies. The attack will work without the need of elevating privileges, which makes it ideal for corporate environments.

usb-flash-drive-skull-ring-2-Check Flash

Bio: Jeremy has built his career around protecting assets in the most critical IT sectors. He started his career working in a Network Operations Security Center for the US Army. He then went on to work as a Network Security Engineer defending Dominion’s North Anna Nuclear Power Station. He is currently a Senior Network Security Engineer/Architect at Genworth Financial. He is a MBA, CISSP, CEH, GIAC GPPA, CSA CCSK, ABCDEFG… Blah Blah Blah.

Jeremy has spent over 10 years researching and implementing new ways to defend against the latest attacks. He enjoys creating new exploits and feels it makes him a more well-rounded defensive Security Engineer. He is happily married and a father to two soon to be hackers. When he’s not staring at a command prompt, he is busy building and driving demolition derby cars.

Twitter: @jdorrough1

ECPI was kind enough to host this month, the meeting will be on Sept. 8th @ 5:30pm.

We got the money

 

make it rain

We had  another good meeting in August, Rob showed us all how to make it rain. We had some fantastic security discussions on various current topics afterwards as well.

Here are Rob’s slides,  Risk Assessment,  Technical Review and a few photos:

August 2016 – Show Me The Money!

Our own Rob Garbee (Bio below) will be presenting Thursday,  August 11th, at R&K Solutions (Google Maps). Rob will be talking about 5 steps to getting the funding you need for IT Security. As we all know getting the funding for personnel or security tools can often be difficult. If you haven’t had a breach everyone often assumes everything is fine. Why do we need all this security stuff? Rob will cover some strategies to win the battle with management to justify the security funding you need.

The_Art_of_War_Running_Press

Bio: Robert Garbee works as a Technical Security Analyst with a mid-tier medical service provider in Roanoke, VA.  In this role, Robert is responsible for managing risk and compliance aspects for both HIPAA related activities and overarching business concerns.   Robert has more than 20 years of experience in information technology and during that time has held IT positions in the banking industry, DOD contracting, and most recently HIPAA security and compliance.  Robert is a graduate of Liberty University with a BMIS degree and holds an ISC2 CISSP certification.  Prior to starting his information technology career Robert served seven years as a crew chief on C-5 Galaxies in the United States Air Force.

June 2016 – Security Architecture: Then and Now

then-and-now

We are ready and set for our next meeting on June 9th.  This meeting will be hosted by our friends at SyCom Technologies:

SyCom Technologies
2800 Electric Rd #103c
Roanoke, VA 24018

Google maps

We will start at our usual time of 5:30pm.  Our speaker this month is Allen Surface and his subject will be Security Architecture: Then and Now.  Allen will walk us through how Security Architectures have changed over the years, where they are headed and how we need to plan for these changes.  Allen is a founding member of RISE and has worked for the past eight years as a solutions architect with SyCom Technologies.  He is currently focused on designing network and security solutions for various customers in both medium and large scale networks.  Prior to moving into his Security Architect role Allen was responsible for implementing hardware solutions such as Intrusion Prevention Systems, Firewalls, and DMVPNs.   What this says is that Allen is one of us!  He is a down in the trenches kind of guy that is willing to share his experiences with us.  Come on out and support one of own and hear his take on where we are all headed as IT Security Professionals.

Taming the Shark

105687

Another great meeting with a lot new faces and a lot of familiar ones. Big “Thanks!” to David Raymond (@dnomyard) for presenting and ECPI for hosting. David was kind enough to provide us a copy of the slides, you can grab them here:

fun_w_wireshark

If you want some more practice with pcaps and malware definitely check out: http://www.malware-traffic-analysis.net/  Just be careful if you export HTTP Objectshazmat out of those as they do contain actual malware. Don’t infect yourself! 🙂

Brad (@malware_traffic), who runs that site, does an outstanding job posting tutorials as well as breakdowns of current samples and traffic patterns. He joined Unit 42, Palo Alto’s Threat Research group,which does some excellent in depth write-ups on malware. This write-up on Locky ransomware and Nuclear EK is a good example: http://researchcenter.paloaltonetworks.com/2016/03/locky-ransomware-installed-through-nuclear-ek/

IMG_4053David Raymond presenting

IMG_4057David,  Michael and Rob

IMG_4056Just talkin’ shop

Also, don’t forget the RBTC Vulnerability Management forum is coming up as well as RVASec. If you know of other “local” security events please email roanokeinfosec@gmail.com and we will get them posted to the site.

Last but not least, if there is a topic that you would like to request for a presentation please let us know. We will do our best to line up a speaker. Or if you can speak on a topic please let us know and we’ll get you in the line up!

May 2016 – Deep Dive with Wireshark

sharks-1

Meeting info: May 12th, @6pm, at ECPI (directions below).

This meeting is a can’t miss opportunity for a hands on deep dive with Wireshark. David Raymond  (@dnomyard, bio below) who has previously spoken at Black Hat USA, RSA and Scmoocon will be presenting.

wireshark2

Wireshark is a great tool for quick-and-dirty network traffic analysis and it is widely used for network troubleshooting and incident response. In this hands-on discussion, we will review the basics of Wireshark and discuss capture filters, display filters, and basic protocol analysis. We’ll then go beyond the basics to talk about more advanced features of Wireshark and touch on some of the command-line utilities that come with it, such as tshark, editcap, mergecap, and randcap.

To get the most from the discussion, attendees should bring a laptop with the latest version of Wireshark installed.

ECPI  (5234 Airport Rd NW #200, Roanoke, VA 24012 or Google Maps) will be hosting the meeting and there will be some lab machines available for use by those without a laptop available.

David Raymond currently serves as Deputy Director in the Virginia Tech IT Security Office and Lab. In this position he helps oversee the security of the VT network, advises graduate students and undergrads doing cybersecurity research, and teaches courses in computer networking and security in the Department of Electrical and Computer Engineering. David holds a Ph.D. in Computer Engineering from Virginia Tech, a Masters in Computer Science from Duke University, and a Bachelors in CS from West Point. He has published over 25 journal and conference publications on a variety of topics and has spoken at numerous industry and academic conferences to include Black Hat USA, RSA, Shmoocon, and the NATO Conference on Cyber Conflict.

RBTC Cyber Security Forum: Vulnerability Management – May 24th

cyber-security-forum_post-image_may16-d

Don’t miss another great local opportunity to network with area security professionals. The RBTC Cyber Security Form next month is all about vulnerability management. Prior RBTC events have been excellent, and the hors d’oeuvres are not to be missed! Details on the event can be found on the RBTC website: https://rbtc.tech/2016/04/cyber-security-forum-vulnerability-management-may/

 

We’re Growing

growing2

It was awesome to see so many new faces and so many familiar ones at last Thursday’s meeting, thanks again to ECPI for hosting. We ended up running out of chairs!

April meeting1

April meeting2

I hope to see everyone again next month, where we will dive back down in to the weeds and take an in-depth look at Wireshark.

wireshark

Get on the mailing list or check the site for more details once we get them finalized.