Veröffentlichungen der SySS GmbH von 2007 bis heute>Publications of the SySS GmbH

Publications of the SySS GmbH in English

Deactivating Endpoint Protection Software in an Unauthorized Manner

When analyzing Endpoint Protection software like antivirus or firewall software, Senior IT-Security Consultant Matthias Deeg  detected a way in which it was possible to bypass the password-based authentication for unloading Trend Micro OfficeScan as a limited user.  

He has published his research results in an article:

Date of Publication: June 18, 2012

SySS Cracks Yet Another USB Flash Drive

Senior IT-Security Consultant Matthias Deeg  found a severe security issue in the USB flash drive ThumbDrive CRYPTO from Trek Technology which makes it possible to gain unauthorized access to all protected data on the USB mass storage device. 

He has published his research results in an article:

Date of Publication: February 11, 2011

Privilege Escalation via Anti-Virus Software

Senior IT-Security Consultant Matthias Deeg found a severe security issue in the software component McAfee Security Agent when doing an analysis of the anti-virus software McAfee VirusScan Enterprise.

This security issue enables attackers to escalate their privileges in corporate networks.
He has summarized his results in a paper which you can download here:

 Date of Publication: January 26th, 2011

 

SySS Spies Out Data on iPhones

SySS team member Christian Eichelmann has found a way to spy out data of  smartphones like the Apple iPhone 3GS.

Look into his report and see how he managed to do it:

Date of Publishing: February 3rd, 2010

SySS Cracks Hardware-Encrypted USB Flash Drive from SanDisk

Matthias Deeg, member of the SySS team has found a way to crack a hardware-encrypted and FIPS-certified USB Flash Drive from the vendor SanDisk.

You can download the paper with his research results here:

Date of Publication: December 18th, 2009.

Concept of a Professional Code of Ethics for Penetration Testers

Author 

Sebastian Schreiber

Medium 

Datenschutz und Datensicherheit DuD

Edition

4/2009

Document

Article

In this article Sebastian Schreiber draws a possible professional code of ethics for penetration testers and builds up his argumentation why it is essential for penetration testers to have a well-founded professional codex.