<?xml version="1.0" encoding="utf-8"?>
<rss version="0.92">
<channel>
<title>SecuObs.com</title>
<link>http://www.secuobs.com</link>
<description>Observatoire de la securite Internet</description>
<language>fr</language>
<webMaster>webmaster@secuobs.com</webMaster>
 <item><title>7829  SCTP-PF  A Quick Failover Algorithm for the Stream Control Transmission Protocol</title><description>2016-04-20 03:54:49 - New RFCs :  53KB  DOI </description><link>http://www.secuobs.com/revue/news/604176.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/604176.shtml</guid></item>
<item><title>7787  Distributed Node Consensus Protocol</title><description>2016-04-19 03:26:25 - New RFCs :  94KB  DOI </description><link>http://www.secuobs.com/revue/news/604063.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/604063.shtml</guid></item>
<item><title>7788  Home Networking Control Protocol</title><description>2016-04-19 03:26:25 - New RFCs :  92KB  DOI </description><link>http://www.secuobs.com/revue/news/604062.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/604062.shtml</guid></item>
<item><title>Snort Lab  Custom SCADA Protocol IDS Signatures</title><description>2016-04-14 15:39:04 - Security Bloggers Network : In this lab, you are going to learn how to create custom Snort signatures for the Modbus TCP protocol First, let s take some time to examine the Modbus TCP Target system Start the Modbus TCP Go on to the site to read the full article </description><link>http://www.secuobs.com/revue/news/603775.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/603775.shtml</guid></item>
<item><title>Shmoocon 2016 - LTE Security Protocol Exploits</title><description>2016-04-13 11:43:06 - SecurityTube.Net : The Long Term Evolution  LTE  is the newest standard being deployed globally for mobile communications Despite the well understood security flaws of legacy 2G networks, which lack of mutual authentication and implement an outdated encryption algorithm, LTE is generally considered secure given its mutual authentication and strong encryption scheme To the day, the main cellular vulnerabilities being exploited in most IMSI catchers and stingrays are based on 2G base stations Nevertheless, rogue base stations and protocol exploits are also possible in LTE Before the authentication and encryption steps of a connection are executed, a mobile device engages in a substantial exchange of messages with  any  LTE base station  real or rogue  that advertises itself with the right broadcast information And this broadcast information is sent in the clear and can be easily sniffed This talk overviews my work on LTE protocol exploits ranging from full-LTE IMSI catchers, blocking of the SIM or the device until device reboot, severe battery drain, location leaks and low-power jamming Some of these exploits have been previously released in some form and some others have not, such as a new way to track devices as they hand over from tower to tower Roger Piqueras Jover is a Wireless Security Research Scientist at the Security Architecture team of Bloomberg LP Previous to that, he spent 5 years as Principal Member of Technical Staff at the AT T Security Research Center His work focuses on LTE mobile network security, protocol exploits and exploring the security of anything that communicates wirelessly For More Information Please Visit - http shmooconorg </description><link>http://www.secuobs.com/revue/news/603601.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/603601.shtml</guid></item>
<item><title>PJON, Fancy One Wire Arduino Communications Protocol For Home Automation</title><description>2016-03-31 22:08:21 - Hackaday :    PJON, pronounced like the iridescent sky rats found in every city, is a cool one wire protocol designed by  gioblu   gioblu  wasn t impressed with the complications of I2C He thought one-wire was too proprietary, too complicated, and its Arduino implementations did not impress What he really wanted was a protocol that could deal with a ton of noise and a weak signal in his home automation project with the smallest amount of wiring possible That s where is his,  Padded Jittering Operative Network,  comes in It can support up to 255 Arduinos on one bus and its error handling is apparently  read more </description><link>http://www.secuobs.com/revue/news/602586.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/602586.shtml</guid></item>
<item><title>7820  UDP Checksum Complement in the One-Way Active Measurement Protocol  OWAMP  and Two-Way Active Measurement Protocol  TWAMP </title><description>2016-03-31 03:43:56 - New RFCs :  30KB  DOI </description><link>http://www.secuobs.com/revue/news/602493.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/602493.shtml</guid></item>
<item><title>7821  UDP Checksum Complement in the Network Time Protocol  NTP </title><description>2016-03-31 03:43:56 - New RFCs :  25KB  DOI </description><link>http://www.secuobs.com/revue/news/602492.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/602492.shtml</guid></item>
<item><title>7822  Network Time Protocol Version 4  NTPv4  Extension Fields</title><description>2016-03-31 03:43:56 - New RFCs :  15KB  DOI </description><link>http://www.secuobs.com/revue/news/602491.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/602491.shtml</guid></item>
<item><title>7817  Updated Transport Layer Security  TLS  Server Identity Check Procedure for Email-Related Protocols</title><description>2016-03-25 00:34:52 - New RFCs :  29KB  DOI </description><link>http://www.secuobs.com/revue/news/602018.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/602018.shtml</guid></item>
<item><title>Google, Microsoft, Yahoo Join Forces To Create New Encrypted Email Protocol</title><description>2016-03-21 19:36:23 - Slashdot  Your Rights Online : An anonymous reader writes  A group of independent security researchers and major Silicon Valley tech giants have submitted a proposal for a new email protocol called SMTP STS  Strict Transport Security  In theory, this new extension looks like the HSTS  HTTP Strict Transport Security  extension to HTTPS Much like HSTS, SMTP STS brings message confidentiality and server authenticity to the process of starting an encrypted email communications channel The new protocol also works with HTTPS to avoid SSL TLS downgrades and MitM attacks The biggest names on the contributors list include Microsoft, Google, Yahoo, LinkedIn, and Comcast Last year, Oracle also submitted a similar proposal called DEEP  Deployable Enhanced Email Privacy   IMAGE   IMAGE  Share on Google  Read more of this story at Slashdot </description><link>http://www.secuobs.com/revue/news/601648.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/601648.shtml</guid></item>
<item><title>7774  Multicast Protocol for Low-Power and Lossy Networks  MPL  Parameter Configuration Option for DHCPv6</title><description>2016-03-17 00:52:11 - New RFCs :  21KB  DOI </description><link>http://www.secuobs.com/revue/news/601254.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/601254.shtml</guid></item>
<item><title>7761  Protocol Independent Multicast - Sparse Mode  PIM-SM  Protocol Specification  Revised </title><description>2016-03-12 02:40:09 - New RFCs :  288KB  DOI </description><link>http://www.secuobs.com/revue/news/600877.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/600877.shtml</guid></item>
<item><title>7791  Cloning the IKE Security Association in the Internet Key Exchange Protocol Version 2  IKEv2 </title><description>2016-03-03 22:01:57 - New RFCs :  32KB  DOI </description><link>http://www.secuobs.com/revue/news/600097.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/600097.shtml</guid></item>
<item><title>7731  Multicast Protocol for Low-Power and Lossy Networks  MPL </title><description>2016-02-19 01:06:46 - New RFCs :  62KB  DOI </description><link>http://www.secuobs.com/revue/news/598732.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/598732.shtml</guid></item>
<item><title>7732  Forwarder Policy for Multicast with Admin-Local Scope in the Multicast Protocol for Low-Power and Lossy Networks  MPL </title><description>2016-02-19 01:06:46 - New RFCs :  34KB  DOI </description><link>http://www.secuobs.com/revue/news/598731.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/598731.shtml</guid></item>
<item><title>7733  Applicability Statement  The Use of the Routing Protocol for Low-Power and Lossy Networks  RPL  Protocol Suite in Home Automation and Building Control</title><description>2016-02-19 01:06:46 - New RFCs :  83KB  DOI </description><link>http://www.secuobs.com/revue/news/598730.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/598730.shtml</guid></item>
<item><title>BSides Huntsville - History of WRT and Wireless Mesh protocols</title><description>2016-02-18 08:06:34 - SecurityTube.Net : This talk will go over the history of WRT firmware and the vast amount of projects created from the open source contributors For More Information Please Visit - https wwwbsideshuntsvilleorg  http wwwirongeekcom iphp page videos bsideshuntsville2016 mainlist </description><link>http://www.secuobs.com/revue/news/598615.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/598615.shtml</guid></item>
<item><title>7765  TCP and Stream Control Transmission Protocol  SCTP  RTO Restart</title><description>2016-02-11 21:20:34 - New RFCs :  35KB  DOI </description><link>http://www.secuobs.com/revue/news/598078.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/598078.shtml</guid></item>
<item><title>7767  Application-Initiated Check-Pointing via the Port Control Protocol  PCP </title><description>2016-02-09 07:09:58 - New RFCs :  24KB  DOI </description><link>http://www.secuobs.com/revue/news/597698.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/597698.shtml</guid></item>
<item><title>NorthSec 2015 - Trevor Perrin - TextSecure Protocol  Present and Future</title><description>2016-02-05 13:22:24 - SecurityTube.Net : This talk will cover the TextSecure protocol for end-to-end encrypted messaging We ll discuss how it handles cryptographic challenges like forward secrecy, multi-party and multi-device cases, authentication, and others We ll also discuss what the future might hold, including emerging use cases and approaches to authentication, federation, and metadata hiding For More Information Please Visit - https wwwnsecio  </description><link>http://www.secuobs.com/revue/news/597469.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/597469.shtml</guid></item>
<item><title>7753  Port Control Protocol  PCP  Extension for Port-Set Allocation</title><description>2016-02-05 01:54:38 - New RFCs :  34KB  DOI </description><link>http://www.secuobs.com/revue/news/597430.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/597430.shtml</guid></item>
<item><title>7750  Differentiated Service Code Point and Explicit Congestion Notification Monitoring in the Two-Way Active Measurement Protocol  TWAMP </title><description>2016-02-03 03:53:06 - New RFCs :  24KB  DOI </description><link>http://www.secuobs.com/revue/news/597191.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/597191.shtml</guid></item>
<item><title> Your board and cyber risk  Reimagining security protocols from the top down</title><description>2016-02-02 10:17:11 - Help Net Security : As scrutiny of well-known financial services firms  security practices continues to make news, the SEC has chosen to turn its attention to risks facing a certain subset of the industry   registered br </description><link>http://www.secuobs.com/revue/news/597117.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/597117.shtml</guid></item>
<item><title>Radio Hacking  Reverse Engineering Protocols Part II - Hak5 1914</title><description>2016-01-29 04:06:40 - Hak5 :  Today on Hak5, Mike Ossmann joins us in studio to talk reverse engineering protocols for radio hacking Shop  http wwwhakshopcom Suppor </description><link>http://www.secuobs.com/revue/news/596815.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/596815.shtml</guid></item>
<item><title>UK Government Promoting Backdoor-Enabled Voice Encryption Protocol</title><description>2016-01-23 13:42:14 - Security Bloggers Network :    The UK government is pushing something called the MIKEY-SAKKE protocol to secure voice Basically, it's an identity-based system that necessarily requires a trusted key-distribution center So key escrow is inherently built in, and there's no perfect forward secrecy The only reasonable explanation for designing a protocol with these properties is third-party eavesdropping Steven Murdoch has explained the details The upshot  The design of MIKEY-SAKKE is motivated by the desire to allow undetectable and unauditable mass surveillance, which may be a requirement in exceptional scenarios such as within government departments processing classified information However, in the vast majority of cases the properties that MIKEY-SAKKE offers are actively harmful for security It creates a vulnerable single point of failure, which would require huge effort, skill and cost to secure requiring resource beyond the capability of most companies Better options for voice encryption exist today, though they are not perfect either In particular, more work is needed on providing scalable and usable protection against man-in-the-middle attacks, and protection of metadata for contact discovery and calls More broadly, designers of protocols and systems need to appreciate the ethical consequences of their actions in terms of the political and power structures which naturally follow from their use MIKEY-SAKKE is the latest example to raise questions over the policy of many governments, including the UK, to put intelligence agencies in charge of protecting companies and individuals from spying, given the conflict of interest it creates And GCHQ previously rejected a more secure standard, MIKEY-IBAKE, because it didn't allow undetectable spying Both the NSA and GCHQ repeatedly choose surveillance over security We need to reject that decision </description><link>http://www.secuobs.com/revue/news/596317.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/596317.shtml</guid></item>
<item><title>7727  Spanning Tree Protocol  STP  Application of the Inter-Chassis Communication Protocol  ICCP </title><description>2016-01-23 02:48:07 - New RFCs :  47KB  DOI </description><link>http://www.secuobs.com/revue/news/596300.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/596300.shtml</guid></item>
<item><title>7723  Port Control Protocol  PCP  Anycast Addresses</title><description>2016-01-23 02:48:07 - New RFCs :  20KB  DOI </description><link>http://www.secuobs.com/revue/news/596299.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/596299.shtml</guid></item>
<item><title>Shmoocon 2016  Z-Wave Protocol Hacked with SDR</title><description>2016-01-16 16:13:19 - Hackaday :    The first talk at 2016 Shmoocon was a great one Joseph Hall and Ben Ramsey presented their work hacking Z-Wave The Z-Wave network that has been gaining a huge market share in both consumer and industrial connected devices EZ-Wave uses commodity Software Defined Radio to exploit Z-Wave networks This is not limited to sniffing, but also used for control with the potential for mayhem Z-Wave is a proprietary wireless protocol which operates in the 900 Mhz spectrum This spectrum is great for penetrating walls and floors which is part of the reason Z-Wave has been seeing a lot of success  read more </description><link>http://www.secuobs.com/revue/news/595766.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/595766.shtml</guid></item>
<item><title> SLOTH attacks weaken secure protocols because they still use MD5 and SHA-1</title><description>2016-01-08 17:33:31 - Help Net Security : Researchers Karthikeyan Bhargavan and Gaetan Leurent from INRIA, the French national research institute for computer science, have discovered a new class of transcript collision attacks that can </description><link>http://www.secuobs.com/revue/news/595202.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/595202.shtml</guid></item>
<item><title>How samba was written French cafe protocol reversing</title><description>2016-01-03 01:19:06 - Reverse Engineering : submitted by sam_bwut  link   comment  </description><link>http://www.secuobs.com/revue/news/594684.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/594684.shtml</guid></item>
<item><title>European Payment Card Protocols Wide Open To Fraud</title><description>2015-12-29 18:18:52 - Slashdot  Your Rights Online : Trailrunner7 writes  Researchers have discovered serious security vulnerabilities in a pair of protocols used by software in some point-of-sale terminals, bugs that could lead to easy theft of money from customers or retailers The vulnerabilities lie in two separate protocols that are used in PoS systems, mainly in Germany, but also in some other European countries Karsten Nohl, a prominent security researcher, and two colleagues, discovered that ZVT, an older protocol, contains a weakness that enables an attacker to read data from credit and debit cards under some circumstances In order to exploit the vulnerability, an attacker would need to have a man-in-the-middle position on the target network, which isn't usually a terribly high barrier for experienced attackers  IMAGE   IMAGE  Share on Google  Read more of this story at Slashdot </description><link>http://www.secuobs.com/revue/news/594424.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/594424.shtml</guid></item>
<item><title>7722  Multi-Topology Extension for the Optimized Link State Routing Protocol Version 2  OLSRv2 </title><description>2015-12-29 07:38:11 - New RFCs :  51KB  DOI </description><link>http://www.secuobs.com/revue/news/594352.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/594352.shtml</guid></item>
<item><title>Common payment processing protocols found to be full of flaws</title><description>2015-12-29 01:03:01 - Risk Assessment   Ars Technica : Stealing PINs and pillaging bank accounts are both trivial </description><link>http://www.secuobs.com/revue/news/594338.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/594338.shtml</guid></item>
<item><title>7717  IKEv2-Derived Shared Secret Key for the One-Way Active Measurement Protocol  OWAMP  and Two-Way Active Measurement Protocol  TWAMP </title><description>2015-12-19 01:07:09 - New RFCs :  34KB  DOI </description><link>http://www.secuobs.com/revue/news/593692.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/593692.shtml</guid></item>
<item><title>7718  Registries for the One-Way Active Measurement Protocol  OWAMP </title><description>2015-12-19 01:07:09 - New RFCs :  14KB  DOI </description><link>http://www.secuobs.com/revue/news/593691.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/593691.shtml</guid></item>
<item><title>7701  Multi-party Chat Using the Message Session Relay Protocol  MSRP </title><description>2015-12-15 06:48:56 - New RFCs :  97KB  DOI </description><link>http://www.secuobs.com/revue/news/593147.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/593147.shtml</guid></item>
<item><title>7702  Interworking between the Session Initiation Protocol  SIP  and the Extensible Messaging and Presence Protocol  XMPP  Groupchat</title><description>2015-12-15 06:48:56 - New RFCs :  84KB  DOI </description><link>http://www.secuobs.com/revue/news/593146.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/593146.shtml</guid></item>
<item><title>7720  DNS Root Name Service Protocol and Deployment Requirements</title><description>2015-12-10 01:32:29 - New RFCs :  10KB  DOI </description><link>http://www.secuobs.com/revue/news/592683.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/592683.shtml</guid></item>
<item><title>Tutorial  How to reverse unknown protocols using Netzob</title><description>2015-12-09 18:12:03 - Reverse Engineering : submitted by chubbymaggie  link   comment  </description><link>http://www.secuobs.com/revue/news/592634.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/592634.shtml</guid></item>
<item><title>Radio Hacking  Reverse Engineering Protocols Part 1 - Hak5 1913 </title><description>2015-12-09 04:37:43 - Hak5 :  Today on Hak5, Mike Ossmann joins us in studio to talk reverse engineering protocols for radio hacking </description><link>http://www.secuobs.com/revue/news/592560.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/592560.shtml</guid></item>
<item><title>Hong Kong government praised for world-leading data protection protocols despite weaknesses exposed by hacking of VTech</title><description>2015-12-08 15:27:14 - Office of Inadequate Security : Jack Liu reports  As Hong Kong reels from last month s hacking of children s toy maker VTech, global telecoms experts say </description><link>http://www.secuobs.com/revue/news/592463.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/592463.shtml</guid></item>
<item><title>7714  AES-GCM Authenticated Encryption in the Secure Real-time Transport Protocol  SRTP </title><description>2015-12-08 02:24:32 - New RFCs :  93KB  DOI </description><link>http://www.secuobs.com/revue/news/592370.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/592370.shtml</guid></item>
<item><title> Week in review  Information the FBI can collect with NSLs revealed, VPN protocol flaw gives away users true IP address</title><description>2015-12-07 08:05:36 - Help Net Security : Here's an overview of some of last week's most interesting news and articles  Human element of security to the fore at IRISSCON 2015 Training people to take more precautions with their organisat </description><link>http://www.secuobs.com/revue/news/592258.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/592258.shtml</guid></item>
<item><title> VPN protocol flaw allows attackers to discover users true IP address</title><description>2015-11-30 14:53:52 - Help Net Security : The team running the Perfect Privacy VPN service has discovered a serious vulnerability that affects all VPN providers that offer port forwarding, and which can be exploited to reveal the real IP addr </description><link>http://www.secuobs.com/revue/news/591547.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/591547.shtml</guid></item>
<item><title> Network protocol analyzer Wireshark 20 released</title><description>2015-11-24 09:12:52 - Help Net Security : Wireshark, the most popular network protocol analyzer, has reached version 20 It features a completely new user interface which should provide a smoother, faster user experience Here's an in-dep </description><link>http://www.secuobs.com/revue/news/591005.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/591005.shtml</guid></item>
<item><title>7712  Domain Name Associations  DNA  in the Extensible Messaging and Presence Protocol  XMPP </title><description>2015-11-20 01:46:09 - New RFCs :  49KB  DOI </description><link>http://www.secuobs.com/revue/news/590652.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/590652.shtml</guid></item>
<item><title>7656  A Taxonomy of Semantics and Mechanisms for Real-Time Transport Protocol  RTP  Sources</title><description>2015-11-19 02:49:09 - New RFCs :  99KB  DOI </description><link>http://www.secuobs.com/revue/news/590514.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/590514.shtml</guid></item>
<item><title>Vigilance - Cisco IOS XE   déni de service via Cisco Discovery Protocol, analysé le 17 09 2015</title><description>2015-11-17 11:23:35 - Vigilance   vulnérabilités publiques : Un attaquant peut envoyer un paquet Cisco Discovery Protocol malveillant vers Cisco IOS XE, afin de mener un déni de service </description><link>http://www.secuobs.com/revue/news/590270.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/590270.shtml</guid></item>
<item><title>Tricking an Ancient Protocol To Play Tunes</title><description>2015-11-06 13:17:06 - Hackaday :    A lot of technological milestones were reached in 2007 The first iPhone, for example, was released that January, and New Horizons passed Jupiter later on that year But even with all of these amazing achievements, Volvo still wasn t putting auxiliary inputs on the stereo systems in their cars They did have antiquated ports in their head units though, and  Kalle  went about engineering this connector to accommodate an auxiliary input The connector in question is an 8-pin DIN in the back, which in the days of yore  almost eight years ago  would have been used for a CD changer Since  read more </description><link>http://www.secuobs.com/revue/news/589277.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/589277.shtml</guid></item>
<item><title>7694  Hypertext Transfer Protocol  HTTP  Client-Initiated Content-Encoding</title><description>2015-11-04 05:44:49 - New RFCs :  13KB  DOI </description><link>http://www.secuobs.com/revue/news/588991.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/588991.shtml</guid></item>
<item><title>Weaknesses in the PLAID Protocol</title><description>2015-10-30 14:35:46 - Security Bloggers Network : In 2009, the Australian government released the Protocol for Lightweight Authentication of Identity  PLAID  protocol It was recently analyzed  original paper is from 2014, but was just updated , and it's a security disaster Matt Green wrote a good bl </description><link>http://www.secuobs.com/revue/news/588534.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/588534.shtml</guid></item>
<item><title>Network Time Protocol flaws defy HTTPS, cause network chaos</title><description>2015-10-22 14:45:12 - Security Bloggers Network : Serious flaws have been discovered in NTP which can be exploited to cause wholesale destruction on a network -- because of a clock </description><link>http://www.secuobs.com/revue/news/587631.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/587631.shtml</guid></item>
<item><title>New attacks on Network Time Protocol can defeat HTTPS and create chaos</title><description>2015-10-22 00:40:12 - Ars Technica   Risk Assessment : Exploits can be used to snoop on encrypted traffic and cause debilitating outages </description><link>http://www.secuobs.com/revue/news/587565.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/587565.shtml</guid></item>
<item><title>Cisco Identifies Multiple Vulnerabilities in Network Time Protocol daemon  ntpd </title><description>2015-10-21 22:11:35 - Security Bloggers Network : Cisco is committed to improving the overall security of the products and services our customers rely on As part of this commitment, Cisco assesses the security of software components used in our products Open source software plays a key role in many Cisco products and as a result, ensuring the security of open source software components is vital, especially in the wake of major vulnerabilities such as Heartbleed and Shellshock In April 2014, the Linux Foundation spearheaded the creation of the Core Infrastructure Initiative in response to the disclosure of Heartbleed with the goal of securing open source projects that are widely used on the internet As a member of the Linux Foundation Core Infrastructure Initiative  CII  Steering Group, Cisco is contributing to the CII effort by evaluating the Network Time Protocol daemon  ntpd  for security defects ntpd is a widely deployed software package used to synchronize time between hosts ntpd ships with a wide variety of network and embedded devices as well as desktop and server operating systems, including Mac OS X, major Linux distributions, and BSDs Today, in coordination with the NTP Project, Cisco is releasing 8 advisories for vulnerabilities that have been identified by the Talos Group and the Advanced Security Initiatives Group  ASIG  within Cisco These vulnerabilities have been reported to the NTP Project in accordance with Cisco vulnerability reporting and disclosure guidelines The following serves as a summary for all the advisories being released For the full advisories, readers should visit the Vulnerability Reports page on the Talos website Advisory Summaries ------------------ The advisories that are being released today are broken down by vulnerability type Error Handling Logic Error An error handling logic error exists within ntpd that manifests due to improper error condition handling associated with certain crypto-NAK packets An unauthenticated, off-path attacker can force ntpd processes on targeted servers to peer with time sources of the attacker's choosing by transmitting symmetric active crypto-NAK packets to ntpd This attack bypasses the authentication typically required to establish a peer association and allows an attacker to make arbitrary changes to system time Matthew Van Gundy of Cisco ASIG is credited with discovering this vulnerability   CVE-2015-7871 - NAK to the Future  NTP crypto-NAK Symmetric Association Authentication Bypass Vulnerability Memory Corruption Multiple memory corruption vulnerabilities exist within ntpd that can manifest themselves due to improper handling of objects in memory An adversary who exploits these vulnerabilities could modify memory via a buffer overflow or use-after-free condition Aleksandar Nikolic and Yves Younan of Cisco Talos are credited with the discovery of these vulnerabilities   CVE-2015-7849 - Network Time Protocol Trusted Keys Memory Corruption Vulnerability   CVE-2015-7852 - Network Time Protocol ntpq atoascii Memory Corruption Vulnerability   CVE-2015-7853 - Network Time Protocol Reference Clock Memory Corruption Vulnerability   CVE-2015-7854 - Network Time Protocol Password Length Memory Corruption Vulnerability Denial of Service Multiple denial of service vulnerabilities exist within ntpd that manifest themselves due to ntpd failing to properly validate input received via private mode packets or a remote configuration file An adversary who crafts a specially formatted packet and transmits it to an ntpd server, or who crafts a specially formatted configuration file and transmits it to the ntpd server could cause the server daemon to crash or enter an infinite loop Aleksandar Nikolic and Yves Younan of Cisco Talos are credited with the discovery of these vulnerabilities   CVE-2015-7848 - Network Time Protocol Multiple Integer Overflow Read Access Violations   CVE-2015-7850 - Network Time Protocol Remote Configuration Denial of Service Vulnerability Directory Traversal   File Overwrite A file path traversal vulnerability exists within ntpd that manifests when saving a config file on VMS operating systems, potentially resulting in files being overwritten An adversary would need to provide a malicious path in the configuration file to exploit this vulnerability Yves Younan of Cisco Talos is credited with the discovery of this vulnerability   CVE-2015-7851 - Network Time Protocol saveconfig Directory Traversal Vulnerability Known Vulnerable Versions   ntp 425p186 though ntp 428p3   ntp-dev4370 Cisco remains committed to improving the overall security of the products and services our customers rely on by assessing the security of all software components that are used in our products Through the research efforts by Talos and ASIG to identify vulnerabilities in ntpd, Cisco is able to assist the CII in improving the overall security of open source software components the overall community relies on In response to these vulnerability disclosures, Cisco is taking the following actions to help address our customer's concerns Cisco PSIRT has posted a Security Advisory enumerating which Cisco products are affected by these ntpd vulnerabilities You can find the Cisco Security Advisory here  http toolsciscocom security center publicationListingx In addition, Talos has released rules that detect attempts to exploit these vulnerabilities to protect our customers Please note that additional rules may be released at a future date and current rules are subject to change pending additional vulnerability information For the most current rule information, please refer to your Defense Center, FireSIGHT Management Center or Snortorg Snort Rules  35831, 36250-36253, 36536 For additional information and vulnerability reports visit  http talosintelcom vulnerability-reports IMAGE   IMAGE   IMAGE  </description><link>http://www.secuobs.com/revue/news/587554.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/587554.shtml</guid></item>
<item><title>7630  HMAC-SHA-2 Authentication Protocols in the User-based Security Model  USM  for SNMPv3</title><description>2015-10-15 02:54:56 - New RFCs :  29KB  DOI </description><link>http://www.secuobs.com/revue/news/586808.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/586808.shtml</guid></item>
<item><title>7671  The DNS-Based Authentication of Named Entities  DANE  Protocol  Updates and Operational Guidance</title><description>2015-10-15 02:54:56 - New RFCs :  79KB  DOI </description><link>http://www.secuobs.com/revue/news/586805.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/586805.shtml</guid></item>
<item><title>7641  Observing Resources in the Constrained Application Protocol  CoAP </title><description>2015-10-01 02:43:31 - New RFCs :  64KB  DOI </description><link>http://www.secuobs.com/revue/news/585278.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/585278.shtml</guid></item>
<item><title>7652  Port Control Protocol  PCP  Authentication Mechanism</title><description>2015-10-01 02:43:31 - New RFCs :  76KB  DOI </description><link>http://www.secuobs.com/revue/news/585277.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/585277.shtml</guid></item>
<item><title>7648  Port Control Protocol  PCP  Proxy Function</title><description>2015-09-30 23:49:53 - New RFCs :  31KB  DOI </description><link>http://www.secuobs.com/revue/news/585266.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/585266.shtml</guid></item>
<item><title>7604  Comparison of Different NAT Traversal Techniques for Media Controlled by the Real-Time Streaming Protocol  RTSP </title><description>2015-09-26 02:36:47 - New RFCs :  108KB  DOI </description><link>http://www.secuobs.com/revue/news/584759.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/584759.shtml</guid></item>
<item><title>7644  System for Cross-domain Identity Management  Protocol</title><description>2015-09-26 02:36:47 - New RFCs :  166KB  DOI </description><link>http://www.secuobs.com/revue/news/584756.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/584756.shtml</guid></item>
<item><title>7645  The Keying and Authentication for Routing Protocol  KARP  IS-IS Security Analysis</title><description>2015-09-26 00:53:14 - New RFCs :  28KB  DOI </description><link>http://www.secuobs.com/revue/news/584750.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/584750.shtml</guid></item>
<item><title>7650  A Constrained Application Protocol  CoAP  Usage for REsource LOcation And Discovery  RELOAD </title><description>2015-09-24 00:41:08 - New RFCs :  37KB  DOI </description><link>http://www.secuobs.com/revue/news/584481.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/584481.shtml</guid></item>
<item><title>MI5 s website uses obsolete encryption protocol   and they re fine with that</title><description>2015-09-18 18:46:03 - Security Bloggers Network : Is British intelligence service MI5 following best security practice on its website  Or have they just scraped a C grade  </description><link>http://www.secuobs.com/revue/news/583984.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/583984.shtml</guid></item>
<item><title>7651  3GPP IP Multimedia Subsystems  IMS  Option for the Internet Key Exchange Protocol Version 2  IKEv2 </title><description>2015-09-16 23:39:38 - New RFCs :  18KB  DOI </description><link>http://www.secuobs.com/revue/news/583762.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/583762.shtml</guid></item>
<item><title>7622  Extensible Messaging and Presence Protocol  XMPP  Address Format</title><description>2015-09-08 21:53:38 - New RFCs :  59KB  DOI </description><link>http://www.secuobs.com/revue/news/582747.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/582747.shtml</guid></item>
<item><title>7619  The NULL Authentication Method in the Internet Key Exchange Protocol Version 2  IKEv2 </title><description>2015-08-27 06:48:35 - New RFCs :  24KB  DOI </description><link>http://www.secuobs.com/revue/news/581536.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/581536.shtml</guid></item>
<item><title>7634  ChaCha20, Poly1305, and Their Use in the Internet Key Exchange Protocol  IKE  and IPsec</title><description>2015-08-21 02:29:11 - New RFCs :  27KB  DOI </description><link>http://www.secuobs.com/revue/news/580898.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/580898.shtml</guid></item>
<item><title>7609  IBM's Shared Memory Communications over RDMA  SMC-R  Protocol</title><description>2015-08-15 03:36:42 - New RFCs :  319KB  DOI </description><link>http://www.secuobs.com/revue/news/580263.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/580263.shtml</guid></item>
<item><title>Le gestionnaire de console avancé Lantronix SLC  8000 met en œuvre des protocoles de sécurité conformes à la norme FIPS 140-2</title><description>2015-08-12 10:02:45 - Global Security Mag Online : Lantronix, Inc, entreprise spécialisée dans les réseaux, proposant des solutions IoT et M2M intelligentes, a annoncé une nouvelle version logicielle 7200 pour son gestionnaire de console avancé SLC  8000, qui est conforme à la norme fédérale américaine de traitement des informations  FIPS  140-2 FIPS 140-2 est une norme de sécurité pour les systèmes informatiques, obligatoire pour les applications de l'armée et du secteur public américaines et canadiennes, qui utilisent une sécurité cryptographique    - Produits </description><link>http://www.secuobs.com/revue/news/579942.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/579942.shtml</guid></item>
<item><title>7544  Mapping and Interworking of Diversion Information between Diversion and History-Info Header Fields in the Session Initiation Protocol  SIP </title><description>2015-08-07 20:36:36 - New RFCs :  67KB  </description><link>http://www.secuobs.com/revue/news/579607.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/579607.shtml</guid></item>
<item><title>Bsides London 2015 - Jakub Kaluzny - Proprietary network protocols - risky business on the wire</title><description>2015-07-21 06:24:40 - SecurityTube.Net : When speed and latency counts, there is no place for standard HTTP SSL stack and a wise head comes up with a proprietary network protocol How to deal with embedded software or thick clients using protocols with no documentation at all  Binary TCP connections, unlike anything, impossible to be adapted by a well-known local proxy Without disassembling the protocol, pentesting the server backend is very limited However, when you dive inside this traffic and reverse-engineer the communication inside, you are there Welcome to the world full of own cryptography, revertible hash algorithms and no access control at all We would like to present our approach and a short guideline how to reverse engineer proprietary protocols To demonstrate, we will show you few case-studies, which in our opinion are a quintessence of  security by obscurity  - the most interesting examples from real-life financial industry software, which is a particularly risky business regarding security For More Information Please Visit  - https wwwsecuritybsidesorguk  </description><link>http://www.secuobs.com/revue/news/577772.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/577772.shtml</guid></item>
<item><title>Akamai met en garde contre une résurgence des attaques DDoS par réflexion au moyen d'un protocole de routage révolu</title><description>2015-07-20 10:26:53 - Global Security Mag Online : Akamai Technologies, Inc publie ce jour, via PLXsert  Prolexic Security Engineering   Research Team , une nouvelle alerte de cybersécurité La menace concerne l'utilisation croissante d'un protocole de routage révolu, RIPv1  Routing Information Protocol , pour des attaques par réflexion et par amplification Qu'est-ce que RIPv1   RIPv1 est un moyen rapide et facile de partager de manière dynamique des informations de routage sur un petit réseau multi-routeur Une requête type est envoyée par    - Malwares </description><link>http://www.secuobs.com/revue/news/577630.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/577630.shtml</guid></item>
<item><title>7591  OAuth 20 Dynamic Client Registration Protocol</title><description>2015-07-10 02:19:49 - New RFCs :  86KB  </description><link>http://www.secuobs.com/revue/news/576633.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/576633.shtml</guid></item>
<item><title>7592  OAuth 20 Dynamic Client Registration Management Protocol</title><description>2015-07-10 02:19:49 - New RFCs :  37KB  </description><link>http://www.secuobs.com/revue/news/576632.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/576632.shtml</guid></item>
<item><title>7574  Peer-to-Peer Streaming Peer Protocol  PPSPP </title><description>2015-07-10 01:08:44 - New RFCs :  203KB  </description><link>http://www.secuobs.com/revue/news/576622.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/576622.shtml</guid></item>
<item><title>Akamai Identifies Old Protocol in New DrDoS Attacks</title><description>2015-07-03 17:32:23 - LinuxSecurity.com   Latest News : LinuxSecuritycom  An old protocol found in SOHO routers may be responsible for recent DrDoS attacks, says the security steam at Akamai Akamai, through the company's Prolexic Security Engineering   Research Team  PLXsert , issued an alert today for an old protocol that could be used in Distributed Reflection Denial of Service attacks  DrDoS  attacks </description><link>http://www.secuobs.com/revue/news/576144.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/576144.shtml</guid></item>
<item><title>Attackers Revive Deprecated RIPv1 Routing Protocol in DDoS Attacks</title><description>2015-07-02 16:02:08 - LinuxSecurity.com   Latest News : LinuxSecuritycom  A long-deprecated-and aptly named-routing protocol, RIPv1, still has some life to it Hackers, since the middle of May, have been carrying out reflection- and amplification-style distributed denial of service attacks using home office and small business routers still running on the old protocol </description><link>http://www.secuobs.com/revue/news/576059.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/576059.shtml</guid></item>
<item><title> Rise in DDoS reflection attacks using abandoned routing protocol</title><description>2015-07-02 09:43:52 - Help Net Security : There's been an increase in the use of outdated Routing Information Protocol version one  RIPv1  for reflection and amplification attacks, according to Akamai RIPv1 is a fast, easy way to dynamica </description><link>http://www.secuobs.com/revue/news/576011.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/576011.shtml</guid></item>
<item><title>Sécurité   Amazon Web Services présente s2n, une nouvelle implémentation Open Source du protocole TLS</title><description>2015-07-01 17:40:22 - Global Security Mag Online : Amazon Web Services annonce la disponibilité de s2n, une nouvelle implémentation Open Source du protocole de chiffrement TLS Le chiffrement puissant a toujours fait partie des engagements d'Amazon Web Services et constitue une partie intégrante du protocole d'encodage TLS  anciennement appelé SSL  TLS est aujourd'hui utilisé par chaque API d'AWS et est également disponible pour les clients AWS utilisant Elastic Load Balancing  ELB , AWS Elastic Beanstalk, Amazon CloudFront, Amazon S3, Amazon RDS et    - Produits </description><link>http://www.secuobs.com/revue/news/575966.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/575966.shtml</guid></item>
<item><title>DDoS Attackers Exploiting '80s-Era Routing Protocol</title><description>2015-07-01 15:53:07 - LinuxSecurity.com   Latest News : LinuxSecuritycom  Latest wave of DDoS attacks abuses small office-home routers via the 27-year-old, outdated Routing Information Protocol Version 1  RIPv1  </description><link>http://www.secuobs.com/revue/news/575954.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/575954.shtml</guid></item>
<item><title>7612  Lightweight Directory Access Protocol  LDAP  Schema for Printer Services</title><description>2015-07-01 02:21:25 - New RFCs :  97KB  </description><link>http://www.secuobs.com/revue/news/575921.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/575921.shtml</guid></item>
<item><title>Starting to look at the XBox One Streaming Protocol</title><description>2015-06-24 15:03:34 - Reverse Engineering : submitted by voltagex  link   1 comment  </description><link>http://www.secuobs.com/revue/news/575272.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/575272.shtml</guid></item>
<item><title>The role of proxies and protocols in malware investigations</title><description>2015-06-23 16:47:08 - Security Bloggers Network : What is a proxy and what types of proxies exist  What protocol are used in the anonymization process  How does anonymity help with malware investigations  The post The role of proxies and protocols in malware investigations appeared first on We Live Se </description><link>http://www.secuobs.com/revue/news/575127.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/575127.shtml</guid></item>
<item><title>7586  The Scalable Address Resolution Protocol  SARP  for Large Data Centers</title><description>2015-06-22 21:26:11 - New RFCs :  43KB  </description><link>http://www.secuobs.com/revue/news/575003.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/575003.shtml</guid></item>
<item><title>7589  Using the NETCONF Protocol over Transport Layer Security  TLS  with Mutual X509 Authentication</title><description>2015-06-20 02:37:26 - New RFCs :  22KB  </description><link>http://www.secuobs.com/revue/news/574766.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/574766.shtml</guid></item>
<item><title>7590  Use of Transport Layer Security  TLS  in the Extensible Messaging and Presence Protocol  XMPP </title><description>2015-06-20 02:37:26 - New RFCs :  20KB  </description><link>http://www.secuobs.com/revue/news/574765.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/574765.shtml</guid></item>
<item><title>Vigilance - Apache HTTPD   déréférencement de pointeur NULL via mod_nw_sslc et protocolc, analysé le 14 04 2015</title><description>2015-06-14 11:38:18 - Vigilance   vulnérabilités publiques : Un attaquant peut forcer le déréférencement d'un pointeur NULL dans Apache httpd, afin de mener un déni de service </description><link>http://www.secuobs.com/revue/news/573977.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/573977.shtml</guid></item>
<item><title>OWASP AppSec California 2015 - Proactively defending your business against security protocol attacks and implementation flaws</title><description>2015-06-13 12:13:58 - SecurityTube.Net : Abstract  HTTPS SSL TLS has been under fire for years BEAST, CRIME, problems with the weakness of the CA system, problems with various versions of the protocol   and more   have plagued HTTPS to be less than satisfactory, at best, as a transport security protocol Some of the most popular algorithms used to secure communications are getting close to their end of life Proper protection of information in the upcoming years will require adoption of new technology and standards Recent enhancements in browsers have made encryption in transit over the web viable for the first time in history and it s imperative that everyone understand them This presentation will start by reviewing some of the most recent cases related to security protocols flaws and weaknesses of cryptografic standards that should be proactively phased out This pragmatic presentation will then discuss possible mitigations and their limitations, along with valuable implementation advice   Bio Cassio Goldschmidt is a globally recognized information security leader with strong background in both product and program-level security Outside work, Cassio is known for his contributions to Open Web Application Security Project  OWASP  , Software Assurance Forum for Excellence in Code  SAFECode , the Common Weakness Enumeration  CWE SysAdmin, Audit, Network, Security  SANS  Top 25 Most Dangerous Software Errors, along with contributing to the security education curriculum of numerous universities and industry certifications Cassio was one of the three finalist in the first  ISC ² Americas Information Security Leadership  ISLA  Awards 2011 in the Information Security Practitioner category and endowed with the special Community Service Star award during the same occasion In 2012 Cassio was one of the finalists of the first OWASP Web Application Security Person of the Year  WASPY  Awards Cassio holds a number of US patents and is an accomplished writer and presenter in the field of application security Cassio holds a bachelor degree in computer science from Pontificia Universidade Catolica do Rio Grande Do Sul, a masters degree in software engineering from Santa Clara University, and a masters of business administration from the University of Southern California Jim Manico authors and delivers developer security awareness training and has a 20 year history building software as a developer and architect Jim is also a global board member for the OWASP foundation where he helps drive the strategic vision for the organization He manages and participates in several OWASP projects, including the OWASP cheat sheet series and several secure coding projects For More Information Please Visit  - https 2015appseccaliforniaorg  </description><link>http://www.secuobs.com/revue/news/573925.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/573925.shtml</guid></item>
<item><title>7572  Interworking between the Session Initiation Protocol  SIP  and the Extensible Messaging and Presence Protocol  XMPP  Instant Messaging</title><description>2015-06-11 04:03:25 - New RFCs :  28KB  </description><link>http://www.secuobs.com/revue/news/573662.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/573662.shtml</guid></item>
<item><title>7573  Interworking between the Session Initiation Protocol  SIP  and the Extensible Messaging and Presence Protocol  XMPP  One-to-One Text Chat Sessions</title><description>2015-06-11 04:03:25 - New RFCs :  42KB  </description><link>http://www.secuobs.com/revue/news/573661.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/573661.shtml</guid></item>
<item><title>BSides Knoxville 2015 - Multipath TCP - Breaking Today's Networks with Tomorrow's Protocols</title><description>2015-06-02 18:42:37 - SecurityTube.Net : Catherine Pearce BSides Knoxville 2015 MultiPath TCP  MPTCP  is an extension to TCP that enables sessions to use multiple network endpoints and multiple network paths at the same time, and to change addresses in the middle of a connection MPTCP works transparently over most existing network infrastructure, yet very few security and network management tools can correctly interpret MPTCP streams With MPTCP network security is changed  how do you secure traffic when you can't see it all and when the endpoint addresses change in the middle of a connection  This session shows you how MPTCP breaks assumptions about how TCP works, and how it can be used to evade security controls We will also show tools and strategies for understanding and mitigating the risk of MPTCP-capable devices on a network For More Information Please Visit  - https bsidesknoxvillecom  http wwwirongeekcom iphp page videos bsidesknoxville2015 mainlist </description><link>http://www.secuobs.com/revue/news/572826.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/572826.shtml</guid></item>
<item><title>CrikeyCon  2015 - Fraser Tweedale - Let s Encrypt and the ACME protocol</title><description>2015-05-30 23:16:25 - SecurityTube.Net : Fraser works on Dogtag PKI and FreeIPA IdM in the employ of Red Hat He is passionate about functional programming, security and privacy and has strong feelings about the  un suitablility of JSON for crypto formats Securing public web servers with TLS is a complex process that involves  Pay   to a certificate authority Prove ownership of a domain  typically an ad-hoc manual procedure Request a certificate  many different request formats and enrolment protocols exist Configure the server to use the certificate  not as straightforward as it ought to be Is it any wonder so many sites remain unsecured  Let s Encrypt is an initiative to deliver TLS everywhere by establishing a free certificate authority and providing new tools to automate domain validation and certificate provisioning A mid-2015 launch is planned, the project being driven by the EFF, Mozilla, Akamai, Cisco and IdenTrust At the heart of Let s Encrypt is Automated Certificate Management Environment  ACME , a JSON-over-HTTPS protocol that defines validation challenges and responses, certificate issuance and revocation messages This talk will explain ACME, examine its strengths, weaknesses and limitations, and discuss client and server implementation considerations A live demo of the complete ACME workflow from domain validation to certificate installation and server reconfiguration will give the audience a taste of what it will be like to use ACME The talk will conclude with a look at possible future use cases and suggestions on how to contribute to the success of Let s Encrypt For More Information Please Visit - http crikeyconcom  </description><link>http://www.secuobs.com/revue/news/572517.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/572517.shtml</guid></item>
<item><title>7557  Extension Mechanism for the Babel Routing Protocol</title><description>2015-05-30 00:57:30 - New RFCs :  22KB  </description><link>http://www.secuobs.com/revue/news/572450.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/572450.shtml</guid></item>
<item><title>Thanks To the Montreal Protocol, We Avoided Severe Ozone Depletion</title><description>2015-05-28 04:33:35 - Slashdot  Your Rights Online : hypnosec writes  Scientists say the ozone layer is in good shape thanks to the Montreal Protocol, which has helped us avoid severe ozone depletion Research suggests that the Antarctic ozone hole would have been 40pourcents bigger by now if not for the international treaty  Our research confirms the importance of the Montreal Protocol and shows that we have already had real benefits We knew that it would save us from large ozone loss 'in the future', but in fact we are already past the point when things would have become noticeably worse,  lead author Professor Martyn Chipperfield, from the School of Earth   Environment at the University of Leeds, said in a press release  IMAGE   IMAGE  Share on Google  Read more of this story at Slashdot </description><link>http://www.secuobs.com/revue/news/572186.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/572186.shtml</guid></item>
<item><title>7564  PRECIS Framework  Preparation, Enforcement, and Comparison of Internationalized Strings in Application Protocols</title><description>2015-05-20 18:55:53 - New RFCs :  91KB  </description><link>http://www.secuobs.com/revue/news/571414.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/571414.shtml</guid></item>
<item><title>Logjam is latest security flaw to affect secure communication protocols</title><description>2015-05-20 16:44:37 - Symantec Connect   Security Response   Billets : Similar to FREAK, Logjam is a newly discovered attack that is focused on subverting secure communications on the internet  IMAGE  Read More </description><link>http://www.secuobs.com/revue/news/571389.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/571389.shtml</guid></item>
<item><title>7545  Protocol to Access White-Space  PAWS  Databases</title><description>2015-05-20 02:57:05 - New RFCs :  184KB  </description><link>http://www.secuobs.com/revue/news/571297.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/571297.shtml</guid></item>
<item><title>I reverse engineered the CS2D  Counter Strike 2D  serverlist protocol My second project in C</title><description>2015-05-18 20:01:13 - Reverse Engineering : submitted by gkbrk  link   comment  </description><link>http://www.secuobs.com/revue/news/571125.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/571125.shtml</guid></item>
<item><title>7540  Hypertext Transfer Protocol Version 2  HTTP 2 </title><description>2015-05-15 01:54:05 - New RFCs :  205KB  </description><link>http://www.secuobs.com/revue/news/570804.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/570804.shtml</guid></item>
<item><title>7509  RTP Control Protocol  RTCP  Extended Report  XR  for Post-Repair Loss Count Metrics</title><description>2015-05-13 23:51:09 - New RFCs :  23KB  </description><link>http://www.secuobs.com/revue/news/570659.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/570659.shtml</guid></item>
<item><title>7539  ChaCha20 and Poly1305 for IETF Protocols</title><description>2015-05-13 23:51:09 - New RFCs :  86KB  </description><link>http://www.secuobs.com/revue/news/570656.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/570656.shtml</guid></item>
<item><title>Weak Homegrown Crypto Dooms Open Smart Grid Protocol</title><description>2015-05-08 16:32:24 - LinuxSecurity.com   Latest News : LinuxSecuritycom  In the three years since its inception, the Open Smart Grid Protocol has found its way into more than four million smart meters and similar devices worldwide </description><link>http://www.secuobs.com/revue/news/570164.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/570164.shtml</guid></item>
<item><title>7507  TLS Fallback Signaling Cipher Suite Value  SCSV  for Preventing Protocol Downgrade Attacks</title><description>2015-04-25 01:06:02 - New RFCs :  17KB  This document defines a Signaling Cipher Suite Value  SCSV  that prevents protocol downgrade attacks on the Transport Layer Security  TLS  and Datagram Transport Layer Security  DTLS  protocols It updates RFCs 2246, 4346, 4347, 5246, and 6347 Server update considerations are included </description><link>http://www.secuobs.com/revue/news/568748.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/568748.shtml</guid></item>
<item><title>Return Path révèle que la sécurité des boîtes email mondiales s'intensifie grâce au protocole DMARC </title><description>2015-04-23 18:20:26 - Global Security Mag Online : Return Path vient de publier une première édition d'un   Baromètre du protocole DMARC  , sur l'adoption du protocole DMARC  Domain-based Message Authentification, Reporting and Conformance  par les entreprises à travers le monde en 2014 Depuis sa création en 2012, DMARC a été reconnu comme l'outil le plus performant pour lutter contre les tentatives d'usurpation d'identité  spoofing  et d'hameçonnage  phishing  A présent que son implémentation se poursuit, DMARC pourrait considérablement réduire    - Investigations </description><link>http://www.secuobs.com/revue/news/568557.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/568557.shtml</guid></item>
<item><title>IIS At Risk  The HTTP Protocol Stack Vulnerability</title><description>2015-04-22 11:31:39 - TrendLabs Security Intelligence Blog : Unpatched versions of Microsoft s Internet Information Services  IIS  web server are vulnerable to a remote denial of service attack that can prove to be very threatening if set against critical systems The vulnerability, which was fixed by Microsoft in MS15-034 as part of the April 2015 Patch Tuesday cycle, can trigger the blue screen of death or more commonly known as   Post from  Trendlabs Security Intelligence Blog - by Trend Micro IIS At Risk  The HTTP Protocol Stack Vulnerability </description><link>http://www.secuobs.com/revue/news/568258.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/568258.shtml</guid></item>
<item><title>Skype for Business Protocol Workloads Posters Available for Download</title><description>2015-04-14 15:45:03 - Security Bloggers Network : A new set of posters is available for download that provides technical protocol details for Skype for Business read more </description><link>http://www.secuobs.com/revue/news/567272.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/567272.shtml</guid></item>
<item><title>7496  Additional Policies for the Partially Reliable Stream Control Transmission Protocol Extension</title><description>2015-04-14 02:14:05 - New RFCs :  21KB  This document defines two additional policies for the Partially Reliable Stream Control Transmission Protocol  PR-SCTP  extension These policies allow limitation of the number of retransmissions and prioritization of user messages for more efficient usage of the send buffer </description><link>http://www.secuobs.com/revue/news/567200.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/567200.shtml</guid></item>
<item><title>7501  Terminology for Benchmarking Session Initiation Protocol  SIP  Devices  Basic Session Setup and Registration</title><description>2015-04-14 02:14:05 - New RFCs :  36KB  This document provides a terminology for benchmarking the Session Initiation Protocol  SIP  performance of devices Methodology related to benchmarking SIP devices is described in the companion methodology document  RFC 7502  Using these two documents, benchmarks can be obtained and compared for different types of devices such as SIP Proxy Servers, Registrars, and Session Border Controllers The term  performance  in this context means the capacity of the Device Under Test  DUT  to process SIP messages Media streams are used only to study how they impact the signaling behavior The intent of the two documents is to provide a normalized set of tests that will enable an objective comparison of the capacity of SIP devices Test setup parameters and a methodology are necessary because SIP allows a wide range of configurations and operational conditions that can influence performance benchmark measurements A standard terminology and methodology will ensure that benchmarks have consistent definitions and were obtained following the same procedures </description><link>http://www.secuobs.com/revue/news/567198.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/567198.shtml</guid></item>
<item><title>7502  Methodology for Benchmarking Session Initiation Protocol  SIP  Devices  Basic Session Setup and Registration</title><description>2015-04-14 02:14:05 - New RFCs :  40KB  This document provides a methodology for benchmarking the Session Initiation Protocol  SIP  performance of devices Terminology related to benchmarking SIP devices is described in the companion terminology document  RFC 7501  Using these two documents, benchmarks can be obtained and compared for different types of devices such as SIP Proxy Servers, Registrars, and Session Border Controllers The term  performance  in this context means the capacity of the Device Under Test  DUT  to process SIP messages Media streams are used only to study how they impact the signaling behavior The intent of the two documents is to provide a normalized set of tests that will enable an objective comparison of the capacity of SIP devices Test setup parameters and a methodology are necessary because SIP allows a wide range of configurations and operational conditions that can influence performance benchmark measurements </description><link>http://www.secuobs.com/revue/news/567197.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/567197.shtml</guid></item>
<item><title>Reverse engineering simple USB audio and MIDI protocol using the original Windows driver on Linux</title><description>2015-04-10 19:40:13 - Reverse Engineering : submitted by empanyc  link   comment  </description><link>http://www.secuobs.com/revue/news/566906.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/566906.shtml</guid></item>
<item><title>CrikeyCon 2015 - Fraser Tweedale - Let s Encrypt and the ACME protocol</title><description>2015-04-10 13:08:09 - SecurityTube.Net : Fraser works on Dogtag PKI and FreeIPA IdM in the employ of Red Hat He is passionate about functional programming, security and privacy and has strong feelings about the  un suitablility of JSON for crypto formats Securing public web servers with TLS is a complex process that involves  Pay   to a certificate authority Prove ownership of a domain  typically an ad-hoc manual procedure Request a certificate  many different request formats and enrolment protocols exist Configure the server to use the certificate  not as straightforward as it ought to be Is it any wonder so many sites remain unsecured  Let s Encrypt is an initiative to deliver TLS everywhere by establishing a free certificate authority and providing new tools to automate domain validation and certificate provisioning A mid-2015 launch is planned, the project being driven by the EFF, Mozilla, Akamai, Cisco and IdenTrust At the heart of Let s Encrypt is Automated Certificate Management Environment  ACME , a JSON-over-HTTPS protocol that defines validation challenges and responses, certificate issuance and revocation messages This talk will explain ACME, examine its strengths, weaknesses and limitations, and discuss client and server implementation considerations A live demo of the complete ACME workflow from domain validation to certificate installation and server reconfiguration will give the audience a taste of what it will be like to use ACME The talk will conclude with a look at possible future use cases and suggestions on how to contribute to the success of Let s Encrypt For More Information Please Visit  - http crikeyconcom  </description><link>http://www.secuobs.com/revue/news/566827.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/566827.shtml</guid></item>
<item><title>7401  Host Identity Protocol Version 2  HIPv2 </title><description>2015-04-09 23:09:54 - New RFCs :  302KB  This document specifies the details of the Host Identity Protocol  HIP  HIP allows consenting hosts to securely establish and maintain shared IP-layer state, allowing separation of the identifier and locator roles of IP addresses, thereby enabling continuity of communications across IP address changes HIP is based on a Diffie-Hellman key exchange, using public key identifiers from a new Host Identity namespace for mutual peer authentication The protocol is designed to be resistant to denial-of-service  DoS  and man-in-the-middle  MitM  attacks When used together with another suitable security protocol, such as the Encapsulating Security Payload  ESP , it provides integrity protection and optional encryption for upper-layer protocols, such as TCP and UDP </description><link>http://www.secuobs.com/revue/news/566774.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/566774.shtml</guid></item>
<item><title>7402  Using the Encapsulating Security Payload  ESP  Transport Format with the Host Identity Protocol  HIP </title><description>2015-04-09 23:09:54 - New RFCs :  87KB  This memo specifies an Encapsulating Security Payload  ESP  based mechanism for transmission of user data packets, to be used with the Host Identity Protocol  HIP  This document obsoletes RFC 5202 </description><link>http://www.secuobs.com/revue/news/566773.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/566773.shtml</guid></item>
<item><title> MitM, DoS bugs in Network Time Protocol squashed</title><description>2015-04-09 12:27:52 - Help Net Security : Two vulnerabilities affecting Network Time Protocol  NTP , which is used for synchronizing clocks of computer systems, have been patched and made available in the latest version of the protocol daemon </description><link>http://www.secuobs.com/revue/news/566639.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/566639.shtml</guid></item>
<item><title>Black Hat Europe 2014 -  Cellular Exploitation on a Global Scale  The Rise and Fall of the Control Protocol</title><description>2015-04-08 13:51:49 - SecurityTube.Net :  Since the introduction of the smart phone, the issue of control has entered a new paradigm Manufacturers and enterprises have claimed control over not just how your phone operates, but the software that is allowed to run on it However, few people know that service providers have a hidden and pervasive level of control over your device These hidden controls can be found in over 2 billion cellular devices worldwide Organizations have been quietly deploying these controls in smart phones, feature phones, basebands, laptops, embedded M2M devices, and even certain cars Someone with knowledge of these controls and the right techniques could potentially leverage them for cellular exploitation on a global scale We've reverse engineered embedded baseband and application space code We've torn apart the Over-the-Air communications and implemented our own code to speak the relevant protocols Layer by layer, we've deconstructed these hidden controls to learn how they work While performing this work, we've unearthed subtle flaws in how the communication is handled and implemented After understanding these flaws, we've written proof-of-concept exploits to demonstrate the true risk this software presents to the end user In this presentation, we will discuss and disclose how Over-the-Air code execution can be obtained on the major cellular platforms and networks  GSM CDMA LTE  Including but not limited to Android, iOS, Blackberry, and embedded M2M devices You will come away from this talk armed with detailed insight into these hidden control mechanisms as well as the tools to help assess and protect from the new threats this hidden attack surface presents These tools will include the ability to dynamically test proprietary system applications and simulate different aspects of a cellular environment  For More Information Please Visit  - https wwwblackhatcom eu-14  </description><link>http://www.secuobs.com/revue/news/566469.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/566469.shtml</guid></item>
<item><title>7497  Rate Measurement Test Protocol Problem Statement and Requirements</title><description>2015-04-06 23:54:38 - New RFCs :  31KB  This memo presents a problem statement for access rate measurement for test protocols to measure IP Performance Metrics  IPPM  Key rate measurement test protocol aspects include the ability to control packet characteristics on the tested path, such as asymmetric rate and asymmetric packet size </description><link>http://www.secuobs.com/revue/news/566245.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/566245.shtml</guid></item>
<item><title>7538  The Hypertext Transfer Protocol Status Code 308  Permanent Redirect </title><description>2015-04-06 23:54:38 - New RFCs :  11KB  This document specifies the additional Hypertext Transfer Protocol  HTTP  status code 308  Permanent Redirect  </description><link>http://www.secuobs.com/revue/news/566240.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/566240.shtml</guid></item>
<item><title> How I hacked into the Warface in-game protocol   Crytek FPS </title><description>2015-04-06 22:56:02 - Reverse Engineering : submitted by adriweb  link   1 comment  </description><link>http://www.secuobs.com/revue/news/566235.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/566235.shtml</guid></item>
<item><title>Troopers 15 - Julian Bangert - Tales of 6006 Protocols</title><description>2015-04-03 09:28:09 - SecurityTube.Net : Troopers 15 - Julian Bangert - Tales of 6006 Protocols For More Information Please Visit  - https wwwtroopersde troopers  </description><link>http://www.secuobs.com/revue/news/565901.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/565901.shtml</guid></item>
<item><title>7530  Network File System  NFS  Version 4 Protocol</title><description>2015-03-26 21:00:19 - New RFCs :  708KB  The Network File System  NFS  version 4 protocol is a distributed file system protocol that builds on the heritage of NFS protocol version 2  RFC 1094  and version 3  RFC 1813  Unlike earlier versions, the NFS version 4 protocol supports traditional file access while integrating support for file locking and the MOUNT protocol In addition, support for strong security  and its negotiation , COMPOUND operations, client caching, and internationalization has been added Of course, attention has been applied to making NFS version 4 operate well in an Internet environment </description><link>http://www.secuobs.com/revue/news/564983.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/564983.shtml</guid></item>
<item><title>7532  Namespace Database  NSDB  Protocol for Federated File Systems</title><description>2015-03-26 21:00:19 - New RFCs :  124KB  This document describes a file system federation protocol that enables file access and namespace traversal across collections of independently administered fileservers The protocol specifies a set of interfaces by which fileservers with different administrators can form a fileserver federation that provides a namespace composed of the file systems physically hosted on and exported by the constituent fileservers </description><link>http://www.secuobs.com/revue/news/564981.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/564981.shtml</guid></item>
<item><title>7533  Administration Protocol for Federated File Systems</title><description>2015-03-26 21:00:19 - New RFCs :  75KB  This document describes the administration protocol for a federated file system  FedFS  that enables file access and namespace traversal across collections of independently administered fileservers The protocol specifies a set of interfaces by which fileservers with different administrators can form a fileserver federation that provides a namespace composed of the file systems physically hosted on and exported by the constituent fileservers </description><link>http://www.secuobs.com/revue/news/564980.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/564980.shtml</guid></item>
<item><title>7480  HTTP Usage in the Registration Data Access Protocol  RDAP </title><description>2015-03-25 23:37:04 - New RFCs :  34KB  This document is one of a collection that together describes the Registration Data Access Protocol  RDAP  It describes how RDAP is transported using the Hypertext Transfer Protocol  HTTP  RDAP is a successor protocol to the very old WHOIS protocol The purpose of this document is to clarify the use of standard HTTP mechanisms for this application </description><link>http://www.secuobs.com/revue/news/564847.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/564847.shtml</guid></item>
<item><title>7481  Security Services for the Registration Data Access Protocol  RDAP </title><description>2015-03-25 23:37:04 - New RFCs :  29KB  The Registration Data Access Protocol  RDAP  provides  RESTful  web services to retrieve registration metadata from Domain Name and Regional Internet Registries This document describes information security services, including access control, authentication, authorization, availability, data confidentiality, and data integrity for RDAP </description><link>http://www.secuobs.com/revue/news/564846.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/564846.shtml</guid></item>
<item><title>7482  Registration Data Access Protocol  RDAP  Query Format</title><description>2015-03-25 23:37:04 - New RFCs :  42KB  This document describes uniform patterns to construct HTTP URLs that may be used to retrieve registration information from registries  including both Regional Internet Registries  RIRs  and Domain Name Registries  DNRs  using  RESTful  web access patterns These uniform patterns define the query syntax for the Registration Data Access Protocol  RDAP  </description><link>http://www.secuobs.com/revue/news/564845.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/564845.shtml</guid></item>
<item><title>7483  JSON Responses for the Registration Data Access Protocol  RDAP </title><description>2015-03-25 23:37:04 - New RFCs :  122KB  This document describes JSON data structures representing registration information maintained by Regional Internet Registries  RIRs  and Domain Name Registries  DNRs  These data structures are used to form Registration Data Access Protocol  RDAP  query responses </description><link>http://www.secuobs.com/revue/news/564844.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/564844.shtml</guid></item>
<item><title>7462  URNs for the Alert-Info Header Field of the Session Initiation Protocol  SIP </title><description>2015-03-25 17:47:13 - New RFCs :  95KB  The Session Initiation Protocol  SIP  supports the capability to provide a reference to a specific rendering to be used by the User Agent  UA  as an alerting signal  eg, a ring tone or ringback tone  when the user is alerted This is done using the Alert-Info header field However, the reference  typically a URL  addresses only a specific network resource with specific rendering properties There is currently no support for standard identifiers for describing the semantics of the alerting situation or the characteristics of the alerting signal, without being tied to a particular rendering To overcome these limitations and support new applications, a new family of URNs for use in Alert-Info header fields  and situations with similar requirements  is defined in this specification </description><link>http://www.secuobs.com/revue/news/564799.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/564799.shtml</guid></item>
<item><title>7463  Shared Appearances of a Session Initiation Protocol  SIP  Address of Record  AOR </title><description>2015-03-25 17:47:13 - New RFCs :  168KB  This document describes the requirements and implementation of a group telephony feature commonly known as Bridged Line Appearance  BLA  or Multiple Line Appearance  MLA , or Shared Call Line Appearance  SCA  When implemented using the Session Initiation Protocol  SIP , it is referred to as shared appearances of an Address of Record  AOR  since SIP does not have the concept of lines This feature is commonly offered in IP Centrex services and IP Private Branch Exchange  IPBX  offerings and is likely to be implemented on SIP IP telephones and SIP feature servers used in a business environment This feature allows several user agents  UAs  to share a common AOR, learn about calls placed and received by other UAs in the group, and pick up or join calls within the group This document discusses use cases, lists requirements, and defines extensions to implement this feature This specification updates RFCs 3261 and 4235 </description><link>http://www.secuobs.com/revue/news/564798.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/564798.shtml</guid></item>
<item><title>7492  Analysis of Bidirectional Forwarding Detection  BFD  Security According to the Keying and Authentication for Routing Protocols  KARP  Design Guidelines</title><description>2015-03-18 21:55:22 - New RFCs :  21KB  This document analyzes the Bidirectional Forwarding Detection  BFD  protocol according to the guidelines set forth in Section 42 of RFC 6518,  Keying and Authentication for Routing Protocols  KARP  Design Guidelines  </description><link>http://www.secuobs.com/revue/news/563970.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/563970.shtml</guid></item>
<item><title>Some IT staff at Victor Valley College return to work while security protocol breach investigation continues</title><description>2015-03-15 15:09:40 - Office of Inadequate Security : There s an update to the somewhat puzzling news report that the entire IT staff of Victor Valley College had been been </description><link>http://www.secuobs.com/revue/news/563489.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/563489.shtml</guid></item>
<item><title>Nimbus Protocol Enumeration with Nmap</title><description>2015-03-11 16:08:40 - Blog :    CA Unified Infrastructure Manager, previously known as Nimsoft, is a powerful IT monitoring solution that allows for management of numerous servers across a Nimsoft domain This solution communicates using a closed source protocol known as  nimbus  The complexity of a Nimsoft domain can be high, but the basic idea is to deploy Robots  the software agent  on all of the servers you want to be part of the Nimsoft domain in order to remotely manage them Additionally, the following terminology might help familiarise yourself with the solution  Domain - The Nimsoft domain is the logical descriptor that makes up many servers formed in a hierarchical structure The domain is made up of Hubs and Robots Robot - Every managed server that has Nimsoft installed on it will be known as a Robot The Robot manages all Probes that can be configured Hub - As part of a hierarchical architecture, a Hub is also a Robot but has the ability to manage child Robots in a tree-like structure A Hub manages a group of Robots and maintains central services Probe - The specific program created that runs on a Robot For example, there is a Hub probe that turns a Robot into a Hub Primary Hub - This is the first choice Hub for a given Robot A Robot can have many parent Hubs, and the Primary is where most messages get sent  For additional Nimsoft terminology see  http docsnimsoftcom prodhelp en_US Monitor 76 NimsoftMonitorGettingStartedGuide 1860724html  When a Robot is installed, the service listens on TCP port 48000 by default This high port is used for communication within the Nimsoft message bus, using the nimbus protocol The protocol is quite complex, but what we will be looking at is what might be revealed to an unauthenticated user on the local network I ve created an Nmap enumeration script that executes 4 commands with the nimbus protocol in order to gather as much relevant information as possible about the Nimsoft Robot and Domain    get_info - This command reveals details about the hostname, IP address, and Nimsoft domain In addition, the specific details on the operating system, including the Service Pack, and architecture are also disclosed    _status - This command is used to acquire the specific software version of the Robot running on the server, and includes specific details regarding the SSL implementation and version    gethub - This command can be used to map out the network and identify the Hub that the Robot is communicating with It also displays information such as the IP address and name of the Primary Hub It can be useful for mapping out a Nimsoft Domain and internal network    probe_checkin - This request is similar to the  gethub  request and reveals detailed information about the Robot including its name, SSL mode, and Hub information It also includes details of the Primary Hub Demonstration ------------- When this script is run against a target host running a Robot, Nmap is able to fingerprint the target server quite effectively The collected information includes     Operating system  including service pack     Server architecture    Server hostname    Nimsoft domain name    Nimsoft network information, including the IP addresses of the parent Hub and Primary Hub Below is an example run against Nimsoft Snap, the lightweight trial edition, running on Windows Server 2012 R2  I ve also successfully tested on Windows XP SP3, and Windows 7 SP1    nmap  script nimbus-info -n -Pn -p 48000 10200101 Starting Nmap 646   http nmaporg   at 2015-01-11 13 24 GMT Nmap scan report for 10200101 Host is up  000045s latency  PORT STATE SERVICE 48000 tcp open unknown  nimbus-info   status   name  NMS Robot Controller  company  CA  version  760  Build 7601097, Jun 12 2014   started  1420981880  restarted  0  connections  19  messages  1  libversion  601  32bit   libdate  Jun 12 2014  ssl_mode  0  ssl_cipher  DEFAULT  ssl_version  OpenSSL 100c 2 Dec 2010  gethub   name  win7  hubdomain  none  hubname   hubrobotname   hubip  101001  hubport  48002  phub_domain  none  phub_name   phub_robotname   phub_ip  101001  phub_port  48002  getinfo   robotname  win7  robotip  10200101  hubname   hubip  101001  domain  none  origin   source  Win7  robot_device_id  DF842C8209237C42AED75AB12  robot_mode  1  hubrobotname   log_level  0  log_file  controllerlog  license  0  requests  59  uptime  768  started  1420981878  os_major  Windows  os_minor  Windows 7 Enterprise Edition, 32-bit  os_version  617601  os_description  Service Pack 1 Build 7601  os_user1   os_user2   processor_type  Intel R  Core TM  i5-3230M CPU   260GHz  workdir  C Program Files Nimsoft  current_time  1420982646  access_0  0  access_1  0  access_2  0  access_3  0  access_4  0  timezone_diff  28800  timezone_name  Pacific Standard Time  spoolport  48001  last_inst_change  1411993600  probecheckin   domain  none  robotname  win7  ssl_mode  0  ssl_cipher  DEFAULT  robotip  10200101  hubdomain  none  hubname   hubrobotname   hubip  101001  hubport  48002  phub_domain  none  phub_name   phub_robotname   phub_ip  101001 _ phub_port  48002 MAC Address  08 00 27 51 82 B0  Cadmus Computer Systems  Nmap done  1 IP address  1 host up  scanned in 009 seconds Adding this Nmap script is quite simple It can be copied either to your local directory and executed there or to the Nmap scripts directory If you are running Kali, that is located within the  usr share nmap scripts directory Once this is finished, the new script will automatically be added when Nmap is executed with the  script argument For reference, the Nmap search path for executing script is as follows      datadir     NMAPDIR     nmap  not searched on Windows     the directory containing the nmap executable    the directory containing the nmap executable, followed by  share nmap    NMAPDATADIR    the current directory  See http nmaporg book nse-usagehtml for more information  The source code is available for download at the following URL  https githubcom GDSSecurity Nmap-Scripts tree master Nimsoft-Info Hopefully this was of interest and helps you on your nimbus network enumeration   IMAGE   IMAGE   IMAGE  </description><link>http://www.secuobs.com/revue/news/563017.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/563017.shtml</guid></item>
<item><title>7488  Port Control Protocol  PCP  Server Selection</title><description>2015-03-11 02:32:45 - New RFCs :  22KB  This document specifies the behavior to be followed by a Port Control Protocol  PCP  client to contact its PCP server s  when one or several PCP server IP addresses are configured </description><link>http://www.secuobs.com/revue/news/562917.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/562917.shtml</guid></item>
<item><title>7466  An Optimization for the Mobile Ad Hoc Network  MANET  Neighborhood Discovery Protocol  NHDP </title><description>2015-03-11 02:32:45 - New RFCs :  18KB  The link quality mechanism of the Mobile Ad Hoc Network  MANET  Neighborhood Discovery Protocol  NHDP  enables  ignoring  some 1-hop neighbors if the measured link quality from that 1-hop neighbor is below an acceptable threshold while still retaining the corresponding link information as acquired from the HELLO message exchange This allows immediate reinstatement of the 1-hop neighbor if the link quality later improves sufficiently </description><link>http://www.secuobs.com/revue/news/562913.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/562913.shtml</guid></item>
<item><title>PCI Set to Ban SSL Protocol</title><description>2015-03-09 19:13:51 - Security Bloggers Network : The PCI DSS is ready to ban SSL and TLS 10 and 11 in response to vulnerability disclosures The post PCI Set to Ban SSL Protocol appeared first on Anitian Blog </description><link>http://www.secuobs.com/revue/news/562701.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/562701.shtml</guid></item>
<item><title>7470  Conveying Vendor-Specific Constraints in the Path Computation Element Communication Protocol</title><description>2015-03-04 03:37:34 - New RFCs :  28KB  The Path Computation Element Communication Protocol  PCEP  is used to convey path computation requests and responses both between Path Computation Clients  PCCs  and Path Computation Elements  PCEs  and between cooperating PCEs In PCEP, the path computation requests carry details of the constraints and objective functions that the PCC wishes the PCE to apply in its computation </description><link>http://www.secuobs.com/revue/news/562018.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/562018.shtml</guid></item>
<item><title>7472  Internet Printing Protocol  IPP  over HTTPS Transport Binding and the 'ipps' URI Scheme</title><description>2015-03-04 03:37:34 - New RFCs :  37KB  This document defines the Internet Printing Protocol  IPP  over HTTPS transport binding and the corresponding 'ipps' URI scheme, which is used to designate the access to the network location of a secure IPP print service or a network resource managed by such a service </description><link>http://www.secuobs.com/revue/news/562016.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/562016.shtml</guid></item>
<item><title>Deepsec 2014 - MLD Considered Harmful - Breaking Another IPv6 Subprotocol</title><description>2015-02-27 07:18:29 - SecurityTube.Net : Enno Rey, Antonios Atlasis and Jayson Salazar  ERNW GmbH  presented flaws of the IPv6 protocol   Multicast Listener Discovery  MLD  and its successor, MLDv2, is a protocol of the IPv6 suite used by IPv6 routers for discovering multicast listeners on a directly attached link, much like IGMP is used in IPv4 Most of the modern Operating Systems  OS , like Windows, Linux and FreeBSD, not only come pre-configured with IPv6 enabled, but they also start-up by sending MLDv2 traffic, which is repeated periodically Despite of the out-of-the-box usage of MLDv2, it is one of the IPv6 protocols that have not be studied yet to a suitable extent, especially as far as its potential security implications are concerned These ones can vary from OS fingerprinting on the local-link by sniffing the wire passively, to amplified DoS attacks In this presentation, we will first study and analyse the default behaviour of some of the most popular OS During this study, we will examine whether the specific OS implementations conform to the security measures defined by the corresponding RFCs, and if not, what are the potential security implications Then, by diving into the specifications of the protocol, we will discuss potential security issues related with the design of MLD and how they can be exploited by attackers Finally, specific security mitigation techniques will be proposed to defend against them, which will allow us to to secure IPv6 networks to the best possible extend in the emerging IPv6 era There will be demos and a tool release  -  For More Information Please Visit - https wwwdeepsecnet  </description><link>http://www.secuobs.com/revue/news/561400.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/561400.shtml</guid></item>
<item><title>7458  Extensible Authentication Protocol  EAP  Attributes for Wi-Fi Integration with the Evolved Packet Core</title><description>2015-02-27 00:52:01 - New RFCs :  38KB  With Wi-Fi emerging as a crucial access network for mobile service providers, it has become important to provide functions commonly available in 3G and 4G networks in Wi-Fi access networks as well Such functions include Access Point Name  APN  Selection, multiple Packet Data Network  PDN  connections, and seamless mobility between Wi-Fi and 3G 4G networks </description><link>http://www.secuobs.com/revue/news/561382.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/561382.shtml</guid></item>
<item><title>NTLM Information Disclosure  Enhanced Protocol Support</title><description>2015-02-24 16:46:46 - Blog :    Expanding on our previous blog post detailing NTLM information disclosure over HTTP, we ve released six additional Nmap scripts to support this method among other common protocols that support NTLM authentication The new supported protocols include MS-SQL, SMTP, IMAP, POP3, NNTP, and Telnet Similar to the HTTP NTLM information disclosure script, these function with identical behavior and provide the same output The example below demonstrates usage of the MS-SQL script which leverages the MS-TDS protocol    nmap  p1433 1234  script ms-sql-ntlm-info Nmap scan report for 1234 Host is up  0040s latency  PORT STATE SERVICE VERSION 1433 tcp open ms-sql-s  ms-sql-ntlm-info   Target_Name  ACTIVEDB  NetBIOS_Domain_Name  ACTIVEDB  NetBIOS_Computer_Name  DB-TEST2  DNS_Domain_Name  somedomaincom  DNS_Computer_Name  db-test2somedomaincom  DNS_Tree_Name  somedomaincom _ Product_Version  61  Build 7601  Service Info  OS  Windows  CPE  cpe o microsoft windows Utilizing such information is useful for network reconnaissance as the information disclosed may be used as part of more complex attacks, such as leveraging domain information for brute forcing accounts, identifying internal hostnames during external to internal pivoting activities, or determining end-of-life operating systems These scripts have been tested against all current past versions of Microsoft SQL, SMTP, IMAP, POP3, NNTP, and Telnet The HTTP NTLM script  http-ntlm-infonse  has been committed into the Nmap source All other scripts have been submitted and are awaiting commitment The scripts along with documentation have been published on the GDS Github repository at the following location  https githubcom GDSSecurity Nmap-Scripts tree master NTLM-Info-Disclosure IMAGE   IMAGE   IMAGE  </description><link>http://www.secuobs.com/revue/news/560926.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/560926.shtml</guid></item>
<item><title>Visual Studio VSTFS protocol handler command injection</title><description>2015-02-12 11:18:00 - Billy  BK  Rios : Last week, someone told me that my blog was on the  LovelyHorse  list I ve always thought that I was the only person who cared about this blog, but I guess there is a lonely analyst out there that also cares  lonely analyst, this one is for you I reported an issue affecting Visual Studio 2012   </description><link>http://www.secuobs.com/revue/news/559264.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/559264.shtml</guid></item>
<item><title>Tor design proposals  how we make changes to our protocol</title><description>2015-02-08 08:21:50 - The Tor Blog blogs :     This post is likely to be interesting for folks who want to know how the Tor software is made  At the core of the Tor software lies the network protocol that Tor relays and clients use to talk to each other We try to make sure we have a good set of specification documents for the protocol at all times, so that other people can write compatible software that interoperates with Tor Once upon a time, we used to change these specification documents whenever we changed the software's behavior That didn't go well We would have changes in the spec that we had forgotten to make in the software, and tons of inline comments where we argued about whether a particular paragraph was a good idea So back in 2007, we introduced a lightweight change-proposal process  to make a change to the Tor protocol, you write up a little design document, and send it to the tor-dev mailing list Once it meets editorial quality, it can go into the proposals repository Once it's implemented, it can be merged into the spec There are a lot of proposals to look at, though The current set of open proposals has almost 100,000 words in it   That's almost half again as long as the Tor specs themselves  To help people navigate through this pile of design proposals, I started to write a regular  proposal status  email to explain what all of the open proposals are about Last year, however, I fell out of the habit Tonight, I've tried to fall back in  here's the latest proposal status writeup Below the cut, my summaries of the still-open proposals that have been added in the past couple of year -- and thanks to all the busy designers who have been working to think of ways to improve Tor  228 Cross-certifying identity keys with onion keys This proposal signs each server's identity key with its onion keys, to prove onion key ownership in the router descriptor It's not clear that this actually improves security, but it fixes an annoying gap in our key authentication I have it coded up in my  12498 branch, targeting 027  2 2015  229 Further SOCKS5 extensions Here's a nice idea for how we can support a new SOCKS5 protocol extension to relay information between clients and Tor, and between Tor and pluggable transports, more effectively It also adds some additional SOCKS5 error codes There are some open questions to answer  Trunnel  has an implementation of the protocol extension formats in its examples directory  2 2015  230 How to change RSA1024 relay identity keys  DRAFT  231 Migrating authority RSA1024 identity keys  DRAFT  Who remembers the OpenSSL  Heartbleed  vulnerability  These proposals I wrote try to explain safer mechanisms for a bunch of servers to migrate their RSA1024 identity keys at once I'm not sure we'll be able to build thee, though  implementating proposal 220 above seems cleverer to me  2 2015  232 Pluggable Transport through SOCKS proxy  OPEN  Arturo Filastò wrote this proposal for chaining pluggable transports which themselves need to go through proxies Seems potentially useful   2 2015  233 Making Tor2Web mode faster  OPEN  This one by Virgil, Fabio, and Giovanni describes a couple of ways that Tor2Web builds of Tor can save some circuit hops that they use today Potentially useful for Tor2Web  any implementation needs to be sure that it never changes the behavior of non-tor2web clients  2 2015  234 Adding remittance field to directory specification  OPEN  Virgil, Leif, and Rob added this proposal for relays to specify payment addresses for schemes that want to compensate relay operators for their use of bandwidth  2 2015  235 Stop assigning  and eventually supporting  the Named flag  DRAFT  This proposal is about removing the Named flag  Thanks to Sebastian Hahn for writing it  The rationale is that the naming system for relays never worked particularly well, and it had strange and hard-to-explain security properties We've implemented the key part of this already  directory authorities don't assign the Named flag any longer Next up will be removing client support for parsing and understanding it  2 2015  236 The move to a single guard node  OPEN  This proposal suggests that to limit client fingerprinting, and to limit opportunities for attacks, clients should use a single guard node, rotated infrequently This transition is in progress  we use a single guard node for circuit traffic now, but in order to make guards more long-lived, we need to adjust how they are chosen George has a patch for that as  9321, targetting inclusion into 026  Thanks to George Kadianakis and Nicholas Hopper for writing this one   2 2015  237 All relays are directory servers  OPEN  Matthew Finkel wrote this proposal to describe a transition to a world where Tor relays can be directory servers without having an open DirPort -- and eventually, where every relay can be a DirServer He has an implementation, possibly for 026 or 027, in ticket  12538  2 2015  238 Better hidden service stats from Tor relays  DRAFT  Here's an important one that needs many eyes George Kadianakis, David Goulet, Karsten Loesing, and Aaron Johnson wrote this to describe a mechanism for the tor network to securely produce aggregate hidden service usage statistics without exposing sensitive intermediate results This has an implementation in 026 and should probably be marked closed  2 2015  239 Consensus Hash Chaining  DRAFT  Here's the start of a good idea that Andrea Shepard wrote up  with some help from Nick  The idea is to make it hard even for a set of corrupt authorities  or authority-key-thieves  to make a personalized false consensus for a target user, by authenticating the whole sequence as a hash chain Others on tor-dev suggested improvements and had good questions  thanks, Leif and Sebastian G   2 2015  240 Early signing key revocation for directory authorities  DRAFT  This one is another Andrea Nick collaboration about certificate revocation for our most sensitive keys If an authority key needs to be replaced, it would be great to take the old one out of circulation as fast as possible Peter Palfrader on tor-dev had some ideas for making this better  2 2015  241 Resisting guard-turnover attacks  DRAFT  I wrote this one with good ideas from Aaron Johnson and Rob Jansen It describes a way to respond to an important class of attacks where an adversary kills off a targeted user's guards until the user has chosen a guard the attacker controls  See the  Sniper Attack  paper The defense is tricky, and if not done right, might lead clients to kick themselves off the network out of paranoia So, this proposal could use more analysis  2 2015  </description><link>http://www.secuobs.com/revue/news/558547.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/558547.shtml</guid></item>
<item><title>Wireshark 101  Hypertext Transfer Protocol - HakTip</title><description>2015-02-07 06:09:00 - Hak5  Xvid Large  :  Today on HakTip, Shannon explains Hypertext Transfer Protocol and packet headers in Wireshark </description><link>http://www.secuobs.com/revue/news/558460.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/558460.shtml</guid></item>
<item><title>7415  Session Initiation Protocol  SIP  Rate Control</title><description>2015-02-06 01:26:51 - New RFCs :  30KB  The prevalent use of the Session Initiation Protocol  SIP  in Next Generation Networks necessitates that SIP networks provide adequate control mechanisms to maintain transaction throughput by preventing congestion collapse during traffic overloads A loss-based solution to remedy known vulnerabilities of the SIP 503  Service Unavailable  overload control mechanism has already been proposed Using the same signaling, this document proposes a rate-based control scheme to complement the loss-based control scheme </description><link>http://www.secuobs.com/revue/news/558301.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/558301.shtml</guid></item>
<item><title>Hackerzvoice - Vladimir KATALOV - Cracking and analyzing iCloud protocols</title><description>2015-02-04 10:43:15 - SecurityTube.Net : Vladimir Katalov, He is the CEO, co-owner and co-founder of ElcomSoft CoLtd Born in 1969 and grew up in Moscow, Russia, he studied Applied Mathematics in Moscow Engineering-Physics Institute  State University  From 1987 to 1989, he was a sergeant in the Soviet Army Vladimir works in ElcomSoft from the very beginning  1990  and in 1997, he created the first program the password recovery software line has started from  Advanced ZIP Password Recovery Now he coordinates the software development process inside the company and develops strategic plans for future versions Vladimir regularly visits various IT security- related events, conferences and trainings all over the world He has shared his expertise through dozens of conference sessions Here is a non-exhaustive list of the events  TechnoSecurity, BlackHat, CEIC, Infosecurity Europe, Infosecurity Russia, Infosecurity Japan, IT Security Area  it-sa , European Police Congress, e-Crime, Troopers, EuroForensics, FT-Day, China Computer Forensic Conference, Interpolitex and so on He regularly presents on various events and also regularly runs IT security and computer forensics trainings both for foreign and inner  Russian  computer investigative committees and other organizations For More Information Please Visit - https hackerzvoicenet </description><link>http://www.secuobs.com/revue/news/557970.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/557970.shtml</guid></item>
<item><title>7414  A Roadmap for Transmission Control Protocol  TCP  Specification Documents</title><description>2015-02-03 07:51:35 - New RFCs :  128KB  This document contains a roadmap to the Request for Comments  RFC  documents relating to the Internet's Transmission Control Protocol  TCP  This roadmap provides a brief summary of the documents defining TCP and various TCP extensions that have accumulated in the RFC series This serves as a guide and quick reference for both TCP implementers and other parties who desire information contained in the TCP-related RFCs </description><link>http://www.secuobs.com/revue/news/557745.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/557745.shtml</guid></item>
<item><title>7442  Carrying Protocol Independent Multicast - Sparse Mode  PIM-SM  in Any-Source Multicast  ASM  Mode Trees over Multipoint LDP  mLDP </title><description>2015-02-03 07:51:35 - New RFCs :  23KB  When IP multicast trees created by Protocol Independent Multicast - Sparse Mode  PIM-SM  in Any-Source Multicast  ASM  mode need to pass through an MPLS domain, it may be desirable to map such trees to Point-to-Multipoint Label Switched Paths  P2MP LSPs  This document describes how to accomplish this in the case where such P2MP LSPs are established using Label Distribution Protocol  LDP  Extensions for P2MP and Multipoint-to-Multipoint LSPs  Multipoint LDP  mLDP  </description><link>http://www.secuobs.com/revue/news/557743.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/557743.shtml</guid></item>
<item><title>7449  Path Computation Element Communication Protocol  PCEP  Requirements for Wavelength Switched Optical Network  WSON  Routing and Wavelength Assignment</title><description>2015-02-03 07:51:35 - New RFCs :  25KB  This memo provides application-specific requirements for the Path Computation Element Communication Protocol  PCEP  for the support of Wavelength Switched Optical Networks  WSONs  Lightpath provisioning in WSONs requires a Routing and Wavelength Assignment  RWA  process From a path computation perspective, wavelength assignment is the process of determining which wavelength can be used on each hop of a path and forms an additional routing constraint to optical light path computation Requirements for PCEP extensions in support of optical impairments will be addressed in a separate document </description><link>http://www.secuobs.com/revue/news/557742.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/557742.shtml</guid></item>
<item><title>7451  Extension Registry for the Extensible Provisioning Protocol</title><description>2015-02-03 07:51:35 - New RFCs :  20KB  The Extensible Provisioning Protocol  EPP  includes features to add functionality by extending the protocol It does not, however, describe how those extensions are managed This document describes a procedure for the registration and management of extensions to EPP, and it specifies a format for an IANA registry to record those extensions </description><link>http://www.secuobs.com/revue/news/557740.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/557740.shtml</guid></item>
<item><title>Reverse Engineering the eQSO Protocol</title><description>2015-02-02 18:59:28 - Reverse Engineering : submitted by ReverseEngineerFox  link   comment  </description><link>http://www.secuobs.com/revue/news/557664.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/557664.shtml</guid></item>
<item><title>Nike FuelBand SE BLE Protocol Reversed</title><description>2015-01-30 12:42:46 - Reverse Engineering : submitted by evilsocket  link   comment  </description><link>http://www.secuobs.com/revue/news/557259.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/557259.shtml</guid></item>
<item><title>A Web Developer s Guide to Communication Protocols  SPI, I2C, UART, GPIO </title><description>2015-01-24 02:10:47 - adafruit industries blog : Kevin Sidwar made a great blog post targeted at someone without much electronics experience and explaining how common communication protocols for microprocessors work This is a great post to check out to understand things like the difference between SPI   I2C, or what kind of speed you might expect from various protocols Check it out for a clear   </description><link>http://www.secuobs.com/revue/news/556381.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/556381.shtml</guid></item>
<item><title>Wireshark 101  The Dynamic Host Configuration Protocol - HakTip</title><description>2015-01-23 21:06:29 - Hak5  Xvid Large  :  Today on HakTip, Shannon explains DHCP and how it relates to Wireshark </description><link>http://www.secuobs.com/revue/news/556348.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/556348.shtml</guid></item>
<item><title>7443  Application-Layer Protocol Negotiation  ALPN  Labels for Session Traversal Utilities for NAT  STUN  Usages</title><description>2015-01-23 06:09:11 - New RFCs :  9KB  Application-Layer Protocol Negotiation  ALPN  labels for Session Traversal Utilities for NAT  STUN  usages, such as Traversal Using Relays around NAT  TURN  and NAT discovery, are defined in this document to allow an application layer to negotiate STUN usages within the Transport Layer Security  TLS  connection ALPN protocol identifiers defined in this document apply to both TLS and Datagram Transport Layer Security  DTLS  </description><link>http://www.secuobs.com/revue/news/556190.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/556190.shtml</guid></item>
<item><title>Maligno Video Series - Network Communications - Protocols</title><description>2015-01-19 07:46:49 - SecurityTube.Net : 05 - Network Communications - Protocols Music  Wonder Cycle by Chris Zabriskie Maligno is an open source penetration testing tool written in Python that serves Metasploit payloads Download it from http wwwencriptono tools  </description><link>http://www.secuobs.com/revue/news/555279.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/555279.shtml</guid></item>
<item><title>Wireshark 101  User Datagram Protocol and Internet Control Message Protocol - HakTip</title><description>2015-01-16 21:44:38 - Hak5  Xvid Large  :  Today on HakTip, Shannon Morse explains the User Datagram Protocol and the Internet Control Message Protocol with Wireshark </description><link>http://www.secuobs.com/revue/news/555072.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/555072.shtml</guid></item>
<item><title>TCP proxy for analyzing text protocols</title><description>2015-01-15 01:04:13 - Reverse Engineering : submitted by maus80  link   comment  </description><link>http://www.secuobs.com/revue/news/554695.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/554695.shtml</guid></item>
<item><title>7416  A Security Threat Analysis for the Routing Protocol for Low-Power and Lossy Networks  RPLs </title><description>2015-01-06 00:06:25 - New RFCs :  92KB  This document presents a security threat analysis for the Routing Protocol for Low-Power and Lossy Networks  RPLs  The development builds upon previous work on routing security and adapts the assessments to the issues and constraints specific to low-power and lossy networks A systematic approach is used in defining and evaluating the security threats Applicable countermeasures are application specific and are addressed in relevant applicability statements </description><link>http://www.secuobs.com/revue/news/553160.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/553160.shtml</guid></item>
<item><title>31c3 - Cyber Necromancy - Reverse Engineering Dead Protocols</title><description>2015-01-05 18:08:47 - SecurityTube.Net : Reverse engineering is not all binaries and byte-code The black art also extends to networks and unobtainable game servers In this talk we go into the gruesome details of how we dug through the graveyards of console binaries and mausoleums of forgotten network protocols in order to stitch together the pieces necessary to bring our favorite game Metal Gear Online back to life We will be examining the process of reverse engineering the games custom network protocols in all angles from packet logs to low level disassembly of client code In this presentation we will be discussing the path we took to successfully develop our own private server for Metal Gear Online on the Sony PlayStation 2 and PlayStation 3 video game consoles Interestingly enough this was a private server that was developed after the original was already taken offline, so we did not have a live active server to help with the reverse engineering Due to this we ran into some issues but ultimately succeeded We believe that the details of the techniques that we used will prove useful for anyone attempting similar actions in the future The topics that we will discuss in this talk will cover a wide range of high and low level issues related to network protocol and binary reversing We will begin with an overall survey of the general problems faced by anyone attempting this type of work The talk will quickly delve from the high-level and simple issues into the more technical aspects of reverse engineering in the blind We will be including the techniques we used to determine the protocol and payload responses that the client was expecting Describing in detail how we honed in on common traits that we expected to see on the network, using open source knowledge and binary level reverse engineering of client code to determine the expected response We expect the attendees of this talk to walk away with knowledge that will help them in the future when working on similar projects or any activities related to protocol reverse engineering For More Information please visit - http eventscccde congress 2014 Fahrplan speakershtml </description><link>http://www.secuobs.com/revue/news/553104.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/553104.shtml</guid></item>
<item><title>The NSA Uses the Same Chat Protocol As Hackers</title><description>2014-12-30 00:36:44 - Slashdot  Your Rights Online : rossgneumann writes NSA documents obtained by Edward Snowden and reported on by Der Spiegel on Sunday reveal that the agency communicates internally with Jabber, an open source messaging service used by hackers and activists trying to skirt the NSA's internet surveillance dragnet A document outlining the NSA's Scarletfever program a  message driven cryptologic exploitation service  designed as part of the larger Longhaul initiative, a program that collects data and finds ways to break its encryption contains a curious point buried near the end   Jabber Chat Room  TBD   IMAGE   IMAGE  Share on Google  Read more of this story at Slashdot  IMAGE   IMAGE   IMAGE   IMAGE   IMAGE IMAGE  </description><link>http://www.secuobs.com/revue/news/552277.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/552277.shtml</guid></item>
<item><title>White hats do an NSA, figure out LIVE PHONE TRACKING via protocol vuln</title><description>2014-12-26 16:49:05 - LinuxSecurity.com   Latest News : LinuxSecuritycom  Security vulnerabilities in the SS7 phone-call routing protocol that allow mobile call and text message tracking will be revealed this weekend </description><link>http://www.secuobs.com/revue/news/551992.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/551992.shtml</guid></item>
<item><title>7420  Path Computation Element Communication Protocol  PCEP  Management Information Base  MIB  Module</title><description>2014-12-24 06:36:30 - New RFCs :  128KB  This memo defines a portion of the Management Information Base  MIB  for use with network management protocols in the Internet community In particular, it describes managed objects for modeling of the Path Computation Element Communication Protocol  PCEP  for communications between a Path Computation Client  PCC  and a Path Computation Element  PCE , or between two PCEs </description><link>http://www.secuobs.com/revue/news/551697.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/551697.shtml</guid></item>
<item><title>Sharp LC-70UD27U TV remote control protocol has some unexplained undocumented features  and some useful undocumented features, like showing a message on the screen </title><description>2014-12-23 18:59:30 - Reverse Engineering : submitted by Hixie  link   1 comment  </description><link>http://www.secuobs.com/revue/news/551644.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/551644.shtml</guid></item>
<item><title>Exploits for dangerous network time protocol vulnerabilities can compromise</title><description>2014-12-23 06:14:43 - Computer Security News :    Remote code execution vulnerabilities in the standard implementation of the network time protocol can be exploited by attackers to compromise servers, embedded devices and even critical infrastructure systems that run UNIX-like operating systems The flaws, which can be exploited by sending specially crafted packets to machines running a vulnerable version of the NTP daemon , pose a greater threat to systems where the service runs under a highly privileged user account such as root </description><link>http://www.secuobs.com/revue/news/551526.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/551526.shtml</guid></item>
<item><title>ICS-CERT  Remote Code Execution Flaw, Network Time Protocol</title><description>2014-12-22 18:21:26 - Security Bloggers Network : ntp_alarm_clockjpg Reports of newly discovered targeted attack code harshed our collective holiday mellow late last week, with the notification via the ICS CERT of flaws in the Network Time Protocol  in this case, prior to NTP version 428  The NTP 428 tarball is here, for folks that need to update their NTP deployments  NTP users are strongly urged to take immediate action to ensure that their NTP daemon is not susceptible to use in a reflected denial-of-service  DRDoS  attack Please see the NTP Security Notice for vulnerability and mitigation details, and the Network Time Foundation Blog for more information  January 2014    - via NTPorg </description><link>http://www.secuobs.com/revue/news/551464.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/551464.shtml</guid></item>
<item><title>Exploits for dangerous network time protocol vulnerabilities</title><description>2014-12-22 15:32:24 - LinuxSecurity.com   Latest News : LinuxSecuritycom  Remote code execution vulnerabilities in the standard implementation of the network time protocol  NTP  can be exploited by attackers to compromise servers, embedded devices and even critical infrastructure systems that run UNIX-like operating systems </description><link>http://www.secuobs.com/revue/news/551422.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/551422.shtml</guid></item>
<item><title>Wireshark 101  Transmission Control Protocol - HakTip</title><description>2014-12-18 20:59:22 - Hak5  Xvid Large  :  This week on HakTip, Shannon Morse explains the Transmission Control Protocol  or TCP  within Wireshark </description><link>http://www.secuobs.com/revue/news/550915.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/550915.shtml</guid></item>
<item><title>The Difference Between Wi-Fi Security Protocols  WPA2-AES vs WPA2-TKIP</title><description>2014-12-18 15:56:42 - LinuxSecurity.com   Latest News : LinuxSecuritycom  Setting up encryption on your wireless router is one of the most important things you can do for your network security, but your router probably offers various different options-WPA2-PSK  TKIP , WPA2-PSK  AES , and WPA2-PSK  TKIP AES  among the alphabet soup How-To Geek explains which one to choose for a faster, more secure home network </description><link>http://www.secuobs.com/revue/news/550866.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/550866.shtml</guid></item>
<item><title>Reverse Engineering the Speedtestnet Protocol</title><description>2014-12-15 22:22:18 - Reverse Engineering : submitted by gkbrk  link   comment  </description><link>http://www.secuobs.com/revue/news/550297.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/550297.shtml</guid></item>
<item><title>DefCamp 2014 - Cyber Necromancy  Reverse Engineering Dead Protocols</title><description>2014-12-11 12:34:09 - SecurityTube.Net : Matthew Halchyshak - Security Technician at Security Innovation in Bucharest, Romania on November 28th - 29th 2014 at DefCamp For More Information please visit - http defcampro  </description><link>http://www.secuobs.com/revue/news/549679.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/549679.shtml</guid></item>
<item><title>Digging into the APA102 Serial LED Protocol</title><description>2014-12-10 04:03:29 - Hackaday :     Tim  got his hands on some APA102 RGB LEDs, which are similar in function to the common WS2812 addressable LEDs seen in many projects we ve featured The advantage of APA102 LEDs is that they don t have the strict timing requirements of the WS2812 These LEDs are controlled with a SPI bus that can be clocked at any arbitrary rate, making them easy to use with pretty much any microcontroller or embedded system After working with the LEDs,  Tim  discovered that the LEDs function a bit differently than the datasheet led him to believe  Tim  controlled a strand of APA102 LEDs  read more </description><link>http://www.secuobs.com/revue/news/549316.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/549316.shtml</guid></item>
<item><title>FAQ  Vulnerability in the TLS 1x protocol</title><description>2014-12-09 23:22:45 - Security Bloggers Network : The following advisory was written by CSIRT Manager Mike Kun We are aware of a newly-announced vulnerability found by Adam Langley and Brian Smith in some implementations of the TLS 1x protocol that allows for a man-in-the-middle attack This can result </description><link>http://www.secuobs.com/revue/news/549292.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/549292.shtml</guid></item>
<item><title>The POODLE flaw returns, this time hitting TLS security protocol</title><description>2014-12-09 03:00:02 - Computer Security News :    Webmasters who patched their sites against a serious SSL flaw discovered in October will have to check them again Researchers have discovered that the vulnerability also affects implementations of the newer TLS protocol </description><link>http://www.secuobs.com/revue/news/549074.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/549074.shtml</guid></item>
<item><title>New Standards and Protocols Introduce Wireless Security Threats</title><description>2014-12-03 18:12:13 - Security Bloggers Network : When I hear the term  wireless security,  the first thing I think of is my 80211 Wi-Fi-enabled router, humming along with WPA2  and Wi-Fi Protected Setup disabled, naturally  There is a relatively low risk that anyone will be able to get to my data at least until it routes to the Internet What I like many of you, probably tend to forget about are the other, lesser known protocols and standards that can create a security nightmare Wireless network connections are precisely what the name implies  connectivity without a physical connection There are numerous types of wireless protocols and  </description><link>http://www.secuobs.com/revue/news/548340.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/548340.shtml</guid></item>
<item><title>Toorcon  San Diego  2014  - Cyber Necromancy  Reverse Engineering Dead Protocols</title><description>2014-12-03 07:38:28 - SecurityTube.Net : Reverse engineering is not always about understanding the binary  in our case it was about the network protocol used by a now dead online game Our attempts to resurrect the dead server with only a copy of the client application are what lead us into cyber necromancy In this talk we will go over the gruesome details of how we dug through the graveyards of console binaries and mausoleums of forgotten network protocols in order to piece together the necessary parts to bring our favorite game back to life For More Information please visit  - http toorconnet IMAGE  </description><link>http://www.secuobs.com/revue/news/548171.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/548171.shtml</guid></item>
<item><title>Virus Bulletin - Labelling spam through the analysis of protocol patterns</title><description>2014-11-26 13:31:16 - SecurityTube.Net : This presentation by Alexandru Trifan  Bitdefender  was delivered during VB2014 in Seattle, WA, USA The increasing volume of unsolicited commercial email has driven the anti-spam industry towards taking advantage of every aspect which can trim down unwanted messages from early stages to help reduce processing time and hence, system load This research paper aims to provide answers to the question 'in how many ways can you send an email ' Of course, in theory, all SMTP servers behave according to the relevant RFC, but this is not necessarily the case in practice Moreover, specific implementations behave differently, even if purportedly implementing the same set of rules We propose ways of fingerprinting the behaviour of various email-sending software The actual contents of the messages are ignored Instead, sending behaviour is analysed at the SMTP and TCP IP protocol levels to find distinguishing patterns Identification is based on several strategies including heuristics over packet sequence and length This is done with the purpose of identifying email messages that originate from botnets and isolating them from those that originate from various kinds of legitimate email servers This is possible due to the way in which spam bots work and due to the limitations to which they are constrained For More information please visit  - https wwwvirusbtncom index IMAGE  </description><link>http://www.secuobs.com/revue/news/547364.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/547364.shtml</guid></item>
<item><title>Protocol Snooping Digital Audio</title><description>2014-11-12 22:40:42 - Hackaday :    More and more clubs are going digital When you go out to hear a band, they re plugging into an ADC  analog-to-digital converter  box on stage, and the digitized audio data is transmitted to the mixing console over Ethernet This saves the venue having to run many audio cables over long distances, but it s a lot harder to hack on So  Michael  trained popular network analysis tools on his ProCo Momentum gear to see just what the data looks like  Michael s writeup of the process is a little sparse, but he name-drops all the components you d need to get the job   Read more </description><link>http://www.secuobs.com/revue/news/545171.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/545171.shtml</guid></item>
<item><title>ProtocoloTCPs0i0pcap</title><description>2014-11-11 21:36:38 - pcapr updates : by  cathy_093 tcp http, stp, tcp  500 packets, 425 KB  2339657   1921681154 http Continuation or non-HTTP traffic 2339657   1921681154 http Continuation or non-HTTP traffic 1921681154   2339657 tcp 18951  80  ACK  Seq 1 Ack 2921 Win 3564 Len 0 2339657   1921681154 http Continuation or non-HTTP traffic  </description><link>http://www.secuobs.com/revue/news/544897.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/544897.shtml</guid></item>
<item><title>7380  RTP Control Protocol  RTCP  Extended Report  XR  Block for MPEG2 Transport Stream  TS  Program Specific Information  PSI  Decodability Statistics Metrics Reporting</title><description>2014-11-07 02:38:19 - New RFCs :  22KB  An MPEG2 Transport Stream  TS  is a standard container format used in the transmission and storage of multimedia data Unicast multicast MPEG2 TS over RTP is widely deployed in IPTV systems This document defines an RTP Control Protocol  RTCP  Extended Report  XR  block that allows the reporting of MPEG2 TS decodability statistics metrics related to transmissions of MPEG2 TS over RTP The metrics specified in the RTCP XR block are related to Program Specific Information  PSI  carried in MPEG TS </description><link>http://www.secuobs.com/revue/news/544215.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/544215.shtml</guid></item>
<item><title>7383  Internet Key Exchange Protocol Version 2  IKEv2  Message Fragmentation</title><description>2014-11-07 02:38:19 - New RFCs :  46KB  This document describes a way to avoid IP fragmentation of large Internet Key Exchange Protocol version 2  IKEv2  messages This allows IKEv2 messages to traverse network devices that do not allow IP fragments to pass through </description><link>http://www.secuobs.com/revue/news/544214.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/544214.shtml</guid></item>
<item><title>7393  Using the Port Control Protocol  PCP  to Update Dynamic DNS</title><description>2014-11-07 02:38:19 - New RFCs :  29KB  This document focuses on the problems encountered when using dynamic DNS in address-sharing contexts  eg, Dual-Stack Lite  DS-Lite  and Network Address and Protocol Translation from IPv6 Clients to IPv4 Servers  NAT64  during IPv6 transition Both issues and possible solutions are documented in this memo </description><link>http://www.secuobs.com/revue/news/544213.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/544213.shtml</guid></item>
<item><title>7403  A Media-Based Traceroute Function for the Session Initiation Protocol  SIP </title><description>2014-11-07 02:38:19 - New RFCs :  15KB  SIP already provides the ability to perform hop-by-hop traceroute for SIP messages using the Max-Forwards header field to determine the reachability path of requests to a target A mechanism for media-loopback calls has also been defined separately, which enables test calls to be generated that result in media being looped back to the originator This document describes a means of performing hop-by-hop traceroute-style test calls using the media-loopback mechanism to test the media path when SIP sessions go through media-relaying back-to-back user agents  B2BUAs  </description><link>http://www.secuobs.com/revue/news/544212.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/544212.shtml</guid></item>
<item><title>Black Hat USA 2014 - Mobile  Cellular Exploitation on a Global Scale The Rise And Fall of the Control PROTOCOL</title><description>2014-11-05 06:17:04 - SecurityTube.Net : Since the introduction of the smart phone, the issue of control has entered a new paradigm Manufacturers and enterprises have claimed control over not just how your phone operates, but the software that is allowed to run on it However, few people know that Service Providers have a hidden and pervasive level of control over your device These hidden controls can be found in over 2 billion cellular devices worldwide Organizations have been quietly deploying these controls in smart phones, feature phones, basebands, laptops, embedded M2M devices, and even certain cars Someone with knowledge of these controls and the right techniques could potentially leverage them for cellular exploitation on a global scale We've reverse engineered embedded baseband and application space code We've torn apart the Over-the-Air communications and implemented our own code to speak the relevant protocols Layer by layer, we've deconstructed these hidden controls to learn how they work While performing this work we've unearthed subtle flaws in how the communication is handled and implemented After understanding these flaws, we've written proof-of-concept exploits to demonstrate the true risk this software presents to the end user In this presentation, we will discuss and disclose how Over-the-Air code execution can be obtained on the major cellular platforms and networks  GSM CDMA LTE  Including but not limited to Android, iOS, Blackberry, and Embedded M2M devices You will come away from this talk armed with detailed insight into these hidden control mechanisms We will also release open source tools to help assess and protect from the new threats this hidden attack surface presents These tools will include the ability to dynamically test proprietary system applications and simulate different aspects of a cellular environment For More Information Please visit   - http blackhatcom IMAGE  </description><link>http://www.secuobs.com/revue/news/543797.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/543797.shtml</guid></item>
<item><title>Thought experiment on protocols and noise</title><description>2014-11-04 20:13:50 - root labs rdist : I hesitate to call this an interview question because I don t think on-the-spot puzzle solving equates to a good engineering hire On the other hand, I try to explore some simple thought experiments with candidates that have a security background One of these involves a protocol that has messages authenticated by an HMAC There s a message   </description><link>http://www.secuobs.com/revue/news/543771.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/543771.shtml</guid></item>
<item><title>7384  Security Requirements of Time Protocols in Packet Switched Networks</title><description>2014-11-04 16:51:36 - New RFCs :  77KB  As time and frequency distribution protocols are becoming increasingly common and widely deployed, concern about their exposure to various security threats is increasing This document defines a set of security requirements for time protocols, focusing on the Precision Time Protocol  PTP  and the Network Time Protocol  NTP  This document also discusses the security impacts of time protocol practices, the performance implications of external security practices on time protocols, and the dependencies between other security services and time synchronization </description><link>http://www.secuobs.com/revue/news/543741.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/543741.shtml</guid></item>
<item><title>7387  A Framework for Ethernet Tree  E-Tree  Service over a Multiprotocol Label Switching  MPLS  Network</title><description>2014-11-04 16:51:36 - New RFCs :  28KB  This document describes an Ethernet-Tree  E-Tree  solution framework for supporting the Metro Ethernet Forum  MEF  E-Tree service over a Multiprotocol Label Switching  MPLS  network The objective is to provide a simple and effective approach to emulate E-Tree services in addition to Ethernet LAN  E-LAN  services on an existing MPLS network </description><link>http://www.secuobs.com/revue/news/543737.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/543737.shtml</guid></item>
<item><title>7296  Internet Key Exchange Protocol Version 2  IKEv2 </title><description>2014-11-04 16:51:36 - New RFCs :  346KB  This document describes version 2 of the Internet Key Exchange  IKE  protocol IKE is a component of IPsec used for performing mutual authentication and establishing and maintaining Security Associations  SAs  This document obsoletes RFC 5996, and includes all of the errata for it It advances IKEv2 to be an Internet Standard </description><link>http://www.secuobs.com/revue/news/543736.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/543736.shtml</guid></item>
<item><title>7390  Group Communication for the Constrained Application Protocol  CoAP </title><description>2014-11-04 16:51:36 - New RFCs :  104KB  The Constrained Application Protocol  CoAP  is a specialized web transfer protocol for constrained devices and constrained networks It is anticipated that constrained devices will often naturally operate in groups  eg, in a building automation scenario, all lights in a given room may need to be switched on off as a group  This specification defines how CoAP should be used in a group communication context An approach for using CoAP on top of IP multicast is detailed based on existing CoAP functionality as well as new features introduced in this specification Also, various use cases and corresponding protocol flows are provided to illustrate important concepts Finally, guidance is provided for deployment in various network topologies </description><link>http://www.secuobs.com/revue/news/543733.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/543733.shtml</guid></item>
<item><title>7395  An Extensible Messaging and Presence Protocol  XMPP  Subprotocol for WebSocket</title><description>2014-11-04 16:51:36 - New RFCs :  36KB  This document defines a binding for the Extensible Messaging and Presence Protocol  XMPP  over a WebSocket transport layer A WebSocket binding for XMPP provides higher performance than the current HTTP binding for XMPP </description><link>http://www.secuobs.com/revue/news/543731.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/543731.shtml</guid></item>
<item><title>7391  Forwarding and Control Element Separation  ForCES  Protocol Extensions</title><description>2014-11-04 16:51:36 - New RFCs :  48KB  Experience in implementing and deploying the Forwarding and Control Element Separation  ForCES  architecture has demonstrated the need for a few small extensions both to ease programmability and to improve wire efficiency of some transactions The ForCES protocol is extended with a table range operation and a new extension for error handling This document updates the semantics in RFCs 5810 and 7121 to achieve that end goal </description><link>http://www.secuobs.com/revue/news/543729.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/543729.shtml</guid></item>
<item><title>Black Hat USA 2014 - Network  Multipath TCP Breaking Today's Networks with Tomorrow's Protocols</title><description>2014-11-03 06:59:54 - SecurityTube.Net : MultiPath TCP  MPTCP  is an extension to TCP that enables sessions to use multiple network endpoints and multiple network paths at the same time, and to change addresses in the middle of a connection MPTCP works transparently over most existing network infrastructure, yet very few security and network management tools can correctly interpret MPTCP streams With MPTCP network security is changed  how do you secure traffic when you can't see it all and when the endpoint addresses change in the middle of a connection  This session shows you how MPTCP breaks assumptions about how TCP works, and how it can be used to evade security controls We will also show tools and strategies for understanding and mitigating the risk of MPTCP-capable devices on a network For More Information Please visit   - http blackhatcom IMAGE  </description><link>http://www.secuobs.com/revue/news/543516.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/543516.shtml</guid></item>
<item><title>Reverse engineering dead protocols</title><description>2014-10-31 03:22:20 - Reverse Engineering : submitted by 3nvisi0n  link   1 comment  </description><link>http://www.secuobs.com/revue/news/543282.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/543282.shtml</guid></item>
<item><title>La faille   Poodle   du protocole SSL 30 expliquée par GlobalSign</title><description>2014-10-20 16:41:04 - Global Security Mag Online : Mardi dernier, une nouvelle vulnérabilité dans le protocole SSL 30 a été découverte La faille POODLE  anagramme de Padding Oracle Downgraded Legacy Encryption  permet à des individus d'intercepter des informations cruciales dans les communications établies avec les serveurs qui reconnaissent encore SSL 30 Lors de son atelier aux Assises de la Sécurité en début de mois, GlobalSign mettait en garde contre la vulnérabilité de ce protocole Le contexte   Le problème n'est pas lié aux certificats SSL    - Vulnérabilités </description><link>http://www.secuobs.com/revue/news/541468.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/541468.shtml</guid></item>
<item><title>Alice Bob analyse la nouvelle vulnérabilité découverte par Google dans le protocole SSL 30 nommé POODLE</title><description>2014-10-20 16:41:04 - Global Security Mag Online : Une nouvelle faille de sécurité a été découverte par Google ce mardi 14 octobre 2014 au sein du protocole de sécurité SSL 30 La faille nommée POODLE  anagramme de Padding Oracle On Downgraded Legacy Encryption , permet à des individus d'intercepter des informations cruciales dans les communications établies avec les serveurs qui reconnaissent encore SSL 30 Le problème n'est pas lié aux certificats SSL directement mais à la version du protocole utilisé pour effectuer des transactions chiffrées,    - Vulnérabilités </description><link>http://www.secuobs.com/revue/news/541467.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/541467.shtml</guid></item>
<item><title>Derbycon 2014 - Protocol Me Maybe  How to Date SCADA</title><description>2014-10-17 09:22:40 - SecurityTube.Net : How to Date SCADA   Industrial Protocols have functions that allow for enumeration of device information A walk though how Digital Bond utilizes the underlying protocols of the Industrial Devices to figure out if the device is interesting enough to go on a second date with For More Information Please visit   - https wwwderbyconcom  http wwwirongeekcom iphp page videos derbycon4 mainlist IMAGE  </description><link>http://www.secuobs.com/revue/news/540871.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/540871.shtml</guid></item>
<item><title>Reversing the Symantec VIP Access Provisioning Protocol</title><description>2014-10-08 07:55:54 - Reverse Engineering : submitted by cyrozap  link   comment  </description><link>http://www.secuobs.com/revue/news/539065.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/539065.shtml</guid></item>
<item><title>Shellshock Vulnerabilities Proliferate, Affect More Protocols</title><description>2014-10-02 20:14:18 - TrendLabs Security Intelligence Blog : Since the initial discovery of the initial Shellshock vulnerability, more issues have been found in Bash This was not unexpected After the initial disclosure of Heartbleed, other vulnerabilities were found in OpenSSL This pattern is repeating itself with Shellshock and Bash Summary of Shellshock Currently, six CVEs have been assigned that are related to Shellshock   Post from  Trendlabs Security Intelligence Blog - by Trend Micro Shellshock Vulnerabilities Proliferate, Affect More Protocols </description><link>http://www.secuobs.com/revue/news/538225.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/538225.shtml</guid></item>
<item><title>Risky Links  Layers and Protocols of Internet of Everything Devices</title><description>2014-09-22 22:03:04 - TrendLabs Security Intelligence Blog : We see the  cool  when we wear or operate our smart TVs and watches and all other smart devices we own But are we aware of how the data is processed in these devices  And where does the data we get or the data that these devices transmit end up  Most, if not all, smart   Post from  Trendlabs Security Intelligence Blog - by Trend Micro Risky Links  Layers and Protocols of Internet of Everything Devices </description><link>http://www.secuobs.com/revue/news/536271.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/536271.shtml</guid></item>
<item><title>CVE-2014-6234  open_graph_protocol </title><description>2014-09-12 07:20:30 - National Vulnerability Database : Cross-site scripting  XSS  vulnerability in the Open Graph protocol  jh_opengraphprotocol  extension before 102 for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors </description><link>http://www.secuobs.com/revue/news/534578.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/534578.shtml</guid></item>

 </channel>
</rss>
