Security Advisories
- oss-2022-03: LibreOffice: Weak Master Keys (CVE-2022-26307)
- oss-2022-02: LibreOffice: Static Initialization Vector Allows to Recover Passwords for Web Connections Without Knowing the Master Password (CVE-2022-26306)
- oss-2022-01: LibreOffice: Execution of Untrusted Macros Due to Improper Certificate Validation (CVE-2022-26305)
- oss-2019-03: CCU3 ise GmbH HTTP-Server v2.0 bufferoverflow with possible remote code execution (CVE-2019-10122)
- oss-2019-02: CCU3 web logout does not invalidate sessionIDs (CVE-2019-10120)
- oss-2019-01: CCU3 web login authentication may be fully disabled because of broken authorization (CVE-2019-10119)
- oss-2018-01: Homematic eq-3 CCU3 web login authentication may be fully disabled (CVE-2019-10121)
- oss-2017-02: The password for the project protection of the Schneider Modicon TM221CE16R is hard-coded and cannot be changed (CVE-2017-7574).
- oss-2017-01: The password for the application protection of the Schneider Modicon TM221CE16R can be retrieved without authentication. Subsequently the application may be arbitrarily downloaded, uploaded and modified (CVE-2017-7575).
- oss-2016-23: Local DoS: Local DoS: Linux Kernel EXT4 Error Handling (EXT4 calling panic())
- oss-2016-22: Local DoS: Linux Kernel EXT4 Memory Corruption / SLAB-Out-of-Bounds Read
- oss-2016-21: Local DoS: Linux Kernel Nullpointer Dereference via keyctl. (CVE-2016-8650)
- oss-2016-20: Know-How and Copy Protection may be circumvented on S7-1200 version 1 through 3. (CVE-2016-2846)
- oss-2016-19: Epson WorkForce multi-function printers do not use signed firmware images and allow unauthorized malicious firmware-updates
- oss-2016-18: Multiple Local RedHat Enterprise Linux DoS – RHEL 7.1 Kernel crashes on invalid USB device descriptors (ati_remote2 driver) (CVE-2016-2185)
- oss-2016-17: Local RedHat Enterprise Linux DoS – RHEL 7.1 Kernel crashes (multiple free) on invalid USB device descriptors (snd-usb-audio driver) (CVE-2016-2184)
- oss-2016-16: Local RedHat Enterprise Linux DoS – RHEL 7.1 Kernel crashes on invalid USB device descriptors (snd-usb-audio driver) (CVE-2016-2184)
- oss-2016-15: Local RedHat Enterprise Linux DoS – RHEL 7.1 Kernel crashes on invalid USB device descriptors (iowarrior driver) (CVE-2016-2188)
- oss-2016-14: Local RedHat Enterprise Linux DoS – RHEL 7.1 Kernel crashes on invalid USB device descriptors (gtco driver) (CVE-2016-2187)
- oss-2016-13: Local RedHat Enterprise Linux DoS – RHEL 7.1 Kernel crashes on invalid USB device descriptors (powermate driver) (CVE-2016-2186)
- oss-2016-12: Local RedHat Enterprise Linux DoS – RHEL 7.1 Kernel crashes on invalid USB device descriptors (digi_acceleport driver) (CVE-2016-3140)
- oss-2016-11: Multiple Local RedHat Enterprise Linux DoS – RHEL 7.1 Kernel crashes on invalid USB device descriptors (wacom driver) (CVE-2016-3139)
- oss-2016-10: Local RedHat Enterprise Linux DoS – RHEL 7.1 Kernel crashes on invalid USB device descriptors (visor treo_attach driver) (CVE-2016-2782)
- oss-2016-9: Local RedHat Enterprise Linux DoS – RHEL 7.1 Kernel crashes on invalid USB device descriptors (visor clie_5_attach driver) (CVE-2015-7566)
- oss-2016-8: Local RedHat Enterprise Linux DoS – RHEL 7.1 Kernel crashes on invalid USB device descriptors (mct_u232_m8 driver) (CVE-2016-3136)
- oss-2016-7: Local RedHat Enterprise Linux DoS – RHEL 7.1 Kernel crashes on invalid USB device descriptors (cypress_m8 driver) (CVE-2016-3137)
- oss-2016-6: Local RedHat Enterprise Linux DoS – RHEL 7.1 Kernel crashes on invalid USB device descriptors (cdc_acm driver) (CVE-2016-3138)
- oss-2016-5: Local RedHat Enterprise Linux DoS – RHEL 7.1 Kernel crashes on invalid USB device descriptors (aiptek driver) (CVE-2015-7515)
- oss-2016-4: Local Microsoft Windows 7 / 8 / 10 Buffer Overflow via Third-Party USB-Driver (ser2co64.sys)
- oss-2016-3: Fehlerhafte Integritätssicherung bei Winkhaus Bluesmart Schließanlagen mit Hitag S Transponder
- oss-2016-2: Weak authentication in NXP Hitag S transponder allows an attacker to read, write and clone any tag
- oss-2016-1: Fehlerhafte Integritätssicherung bei Uhlmann & Zacher Clex prime Schließanlage mit 125 kHz EM4450 Transpondern
- oss-2015-4: Local RedHat Enterprise Linux DoS – RHEL 7 Kernel crashes on invalid USB device descriptors (usbvision driver) (CVE-2015-7833)
- oss-2015-3: Remote Permanent LoV (Loss of View) in Mitsubishi Melsec FX3G-24M PLC (CVE-2015-3938).
- oss-2015-2: Attacker can perform a CSRF attack S7-1200 PLCs (CVE-2015-5698).
- oss-2015-1: Attacker can redirect users to untrusted websites on S7-1200 PLCs (CVE-2015-1048).
- oss-2014-2: XSS and HTML Injection in S7-1200 PLC (CVE-2014-2908, CVE-2014-2909).
- oss-2014-1: An Attacker can trigger the defect mode via HTTPS in S7-1200 PLCs (CVE-2014-2258)
- oss-2004-1: KAME IKE Daemon Racoon does not verify RSA Signatures (CVE-2004-0155)
Vorträge
Blackhat Briefings
Chaos Communication Congress
CheckMK Konferenz
DFN-CERT
- 2024: Tutorium : E-Mail Security
- 2024: Technische Aspekte der TR-03108 Version 2.0
- 2023: LibreOffice – Aber sicher!
- 2022: Tutorium : Last ten years of security - Lessons learned
- 2021: Tutorium : DNS und was man damit machen kann (nicht mehr online verfügbar)
- 2018: Android Security (nicht mehr online verfügbar)
- 2017: Sichere Virtualisierung mit KVM (nicht mehr online verfügbar)
- 2017: Compromising Multifunction Printers: A Case Study of Epson MFP Security (nicht mehr online verfügbar)
- 2017: Tutorium Schwachstellenmanagement mit OpenVAS 9 - Best Practices (nicht mehr online verfügbar)
- 2016: Der CAOS Stick – Crash any OS (Nicht mehr online verfügbar)
- 2016: Angriffsverfahren auf 125kHz Transponder für Zutrittskontrollsysteme (nicht mehr online verfügbar)
- 2015: ICShell - SCADA Pentesting made simple (nicht mehr online verfügbar)
- 2014: Typische IT-Sicherheitsprobleme in Industriesteuerungen und deren Eindämmung mit Hilfe von OpenSource Software (nicht mehr online verfügbar)
- 2014: UEFI Secure Boot und alternative Betriebssysteme (nicht mehr online verfügbar)
- 2007: Sicherheit für virtuelle Systeme mit Xen (nicht mehr online verfügbar)
- 2006: OpenSource Firewall Lösungen - Ein Vergleich (nicht mehr online verfügbar)
BSI IT-Grundschutztag
4SICS. Stockholm, Schweden.
World Intelligent Manufacturing Summit. Nanjing, China.
LinuxTag
Chemnitzer Linuxtage
GUUG FFG
GUUG Linux Congress
IT Sicherheitskonferenz Stralsund
SANS
- SANS Conference 2001 Baltimore: Linux Firewalls
- SANS Conference 2002 Orlando: Implementing Interoperable Virtual Private Networks using Open Source
Bücher
- Intrusion Detection für Linux-Server, Markt & Technik Verlag, 2003.
- VPN mit Linux 1. Auflage, Addison Wesley 2004
- Intrusion Detection und Prevention mit Snort 2 & Co., Addison Wesley, 2005.
- Linux Firewalls mit iptables & Co., Addison Wesley 2006
- SELinux & AppArmor, Addison Wesley 2008
- VPN mit Linux 2. Auflage, Addison Wesley 2010
- Linux Firewalls 2. Auflage, Addison Wesley 2011
- KVM für die Server-Virtualisierung, Addison Wesley 2012
Artikel
c’t
iX
Linuxmagazin
Weitere
BSI Studien
Master- und Bachelorarbeiten