Matthias Deeg

@deeg
108 Followers
53 Following
86 Posts
Interested in IT and likes to see whether security assumptions in soft-, firm-, or hardware hold true when taking a closer look.
Websitehttps://deeg.xyz
Books Websitehttps://books.deeg.xyz
Twitterhttps://twitter.com/matthiasdeeg

I'm back home from the beautiful city of Bergamo and the awesome @nohatcon.

Today, we have published the security advisories concerning the Verbatim security update I was talking about on Saturday in my presentation "Your Security Update is Not Secure Enough".

Due to current events.
This 2x3 mm EEPROM chip is the smallest one I found so far in a product I took a closer look at.

You can also find a short blog article in German about this security issue here:
https://www.syss.de/pentest-blog/weitere-windows-rechteausweitung-ueber-razer-synapse-syss-2023-002

And of course there is also the corresponding security advisory SYSS-2023-002 for CVE-2022-47631:
https://www.syss.de/fileadmin/dokumente/Publikationen/Advisories/SYSS-2023-002.txt

#infosec #CyberSecurity #vulnerability

Weitere Windows-Rechteausweitung über Razer Synapse (SYSS-2023-002)

Ein Security Advisory von Senior IT Security Consultant Dr. Oliver Schwarz

And my DeepSec 2022 talk titled ‘The Story Continues: Hacking Some More “Secure” Portable Storage Devices’ is now also available online on Vimeo:

https://vimeo.com/780378554

The slides of my talk are available here:

https://www.deepsec.net/docs/Slides/2022/Hacking_More_Secure_Portable_Storage_Devices_Matthias_Deeg.pdf

#itsecurity #infosec #cybersecurity #hacking #talk #video #deepsec

DEEPSEC-2022-S13 . The Story Continues: Hacking Some More „Secure“ Portable Storage Devices . . . Matthias Deeg (SySS)

Encrypting sensitive data at rest has always been a good idea, especially when storing it on small, portable devices like external hard drives or USB flash drives.…

Vimeo

I wish you a happy and healthy new year 2023!

The DeepSec 2022 talk "We Are Sorry That Your Mouse Is Admin - Windows Privilege Escalation Through The Windows Co-installer" by my colleague Dr. Oliver Schwarz is now available online on Vimeo:

https://vimeo.com/780111753

The slides are available here:

https://www.deepsec.net/docs/Slides/2022/We_are_sorry_that_your_mouse_is_admin_Oliver_Schwarz.pdf

#itsecurity #infosec #cybersecurity #hacking #talk #video #deepsec

DEEPSEC-2022-S02 . We Are Sorry That Your Mouse Is Admin - Windows Privilege Escalation . . . Oliver Schwarz (SySS)

Device-specific co-installers have repeatedly allowed for Windows privilege escalation. Through Windows' plug'n'play concept, attackers don't…

Vimeo

I'm saying "auf Wiedersehen" to Vienna and am on may way back home from #DeepSec 2022.

Thanks to the DeepSec team (@deepsec) for having me again talking about my IT security research (this time "secure" portable storage devices).

I've met new people, learned new stuff, had great food, and really enjoyed my stay in Vienna.

Here are some impressions from my talk today: