Robert Merget(@ic0nz1) 's Twitter Profile Photo

Do you like crypto? Are you interested in new attack techniques? Then this is something for you: We present raccoon-attack.com a novel cryptographic vulnerability in the SPECIFICATION of TLS Credits: Marcus Brinkmann, Nimrod Aviram, juraj somorovsky, Johannes Mittmann Jörg Schwenk

Do you like crypto? Are you interested in new attack techniques? Then this is something for you: We present raccoon-attack.com a novel cryptographic vulnerability in the SPECIFICATION of TLS Credits: @lambdafu, @NimrodAviram, @jurajsomorovsky, Johannes Mittmann @JoergSchwenk
account_circle
Christian(@CheariX) 's Twitter Profile Photo

Do you want to learn how to break PDF security?

Come to the PDF Attack session ACM CCS 2024 in Kings Balmoral

I'll give the talk at 11am on breaking PDF signature followed by Fabian @[email protected]'s talk on breaking PDF encryption.

/cc vladislav mladenov Martin Grothe Jens Müller Sebastian Schinzel @[email protected] Jörg Schwenk

Do you want to learn how to break PDF security?

Come to the PDF Attack session @acm_ccs in Kings Balmoral

I'll give the talk at 11am on breaking PDF signature followed by @Murgi's talk on breaking PDF encryption.

/cc @v_mladenov @ashitaka007 @jensvoid @seecurity @JoergSchwenk
account_circle
Christian(@CheariX) 's Twitter Profile Photo

ODF Documents can be protected with a digital signature.
What can go wrong?
Find out in Simon's USENIX Security talk (Track 1, 9:40):

Oops... Code Execution and Content Spoofing: The First Comprehensive Analysis of OpenDocument Signatures

Joint work w vladislav mladenov+Jörg Schwenk

ODF Documents can be protected with a digital signature.
What can go wrong?
Find out in Simon's @USENIXSecurity talk (Track 1, 9:40):

Oops... Code Execution and Content Spoofing: The First Comprehensive Analysis of OpenDocument Signatures

Joint work w @v_mladenov+@JoergSchwenk
account_circle
Jens Müller(@jensvoid) 's Twitter Profile Photo

New paper 'Johnny, you are fired! – Spoofing OpenPGP and S/MIME Signatures in Emails' at USENIX Security '19. Joint work with Jens Müller Marcus Brinkmann Damian Poddebniak hanno Sebastian Schinzel @[email protected] juraj somorovsky Jörg Schwenk | PDF: github.com/RUB-NDS/Johnny… | Artifacts: github.com/RUB-NDS/Johnny…

New paper 'Johnny, you are fired! – Spoofing OpenPGP and S/MIME Signatures in Emails' at USENIX Security '19. Joint work with @jensvoid @lambdafu @dues__ @hanno @seecurity @jurajsomorovsky @JoergSchwenk | PDF: github.com/RUB-NDS/Johnny… | Artifacts: github.com/RUB-NDS/Johnny…
account_circle
Roman Dodin(@ntdvps) 's Twitter Profile Photo

We started to receive questions from customers regarding this CVE and on the surface, it sounded quite scary.
Patches done to almost every SSH server out there, but no mention of Network OSes.
So I decided to help researchers Fabian Bäumer Marcus Brinkmann and Jörg Schwenk by assessing

We started to receive questions from customers regarding this CVE and on the surface, it sounded quite scary.
Patches done to almost every SSH server out there, but no mention of Network OSes.
So I decided to help researchers @TrueSkrillor @lambdafu and @JoergSchwenk by assessing
account_circle
Jörg Schwenk(@JoergSchwenk) 's Twitter Profile Photo

This attack complements previous research on the security of SSH because it considers both the handshake and the BPP encryption layer.

account_circle
Philipp Nieting(@Kavakuo) 's Twitter Profile Photo

Finally we can share TLS-Anvil. It started two years ago as my master thesis and is now part of USENIX 22. What a cool journey! Thanks for seeing so much potential in the project and all the work that went into it! Marcel Maehren Robert Merget juraj somorovsky Jörg Schwenk Sven Hebrok

account_circle
Christian(@CheariX) 's Twitter Profile Photo

Insecure Features in PDFs.

We analyzed legitimate PDF features leading to 1. Denial of Service 2. Information Disclosure 3. Data Manipulation 4. and Code Execution (NDSS'21 Paper).

web-in-security.blogspot.com/2021/01/insecu…

/cc Jens Müller Dominik Noss, vladislav mladenov, Jörg Schwenk

account_circle
Paul Rösler(@roeslpa) 's Twitter Profile Photo

New technical report on interoperable messaging:
Jörg Schwenk and I wrote a comprehensive study for the @BNetzA (German Network Agency) to investigate how security for interoperable messaging can be preserved. We also take the short timeline of the European DMA into account.

account_circle