← back to blog // article

LeHack 2023 // Kernel panic

Last week, I had the incredible opportunity to participate in the 2023 edition of the LeHack: kernel panic cybersecurity conference held at the Cité des sciences et de l’industrie in Paris, I was thrilled to dive into a world of cutting-edge knowledge and expertise in cybersecurity.

The conference was organized into four distinct sections:

  • Conferences: These took place in the main amphitheater, where renowned experts and thought leaders shared their insights and discoveries in the realm of cybersecurity.

  • Osint Village: Situated in a secondary room, the Osint Village hosted conferences centered around open-source intelligence, providing valuable insights into this crucial field.

  • Workshops: Workshops were held either in the hall or in smaller tertiary rooms, offering hands-on learning opportunities and interactive sessions.

  • Hardware/IoT Area: Focusing on the intersection of cybersecurity and the Internet of Things, this area explored the unique challenges and solutions related to securing connected devices.

In addition to the enriching conference sessions, many prominent companies had their stands set up in the hall, seeking to recruit talent and engage in networking opportunities. Some of the standout booths included Synacktiv, OWN Security, Orange Cyberdefense, Mozilla, HackTheBox, 2600 school, DGSE, ANSSI, Crowdsec, XMCO, and many more. Exploring these stands provided an excellent chance to interact with industry professionals, learn about cutting-edge products and services, and collect a plethora of goodies like keychains, pins, and stickers.

Between attending sessions and exploring the exhibition hall, my friends, colleagues, and I took moments to decompress and relax. We indulged in coffee, beer, and even engaged in lively matches of babyfoot to unwind and share our insights from the conference.

Now, let me share with you a breakdown of the exciting events that unfolded over the two days of the conference:

Friday Morning

The morning began with a warm and welcoming opening keynote address. The speaker expressed their gratitude to all the attendees and set the tone for the rest of the conference, emphasizing the importance of collaboration and knowledge-sharing in the cybersecurity community.

Later, from 11:45 a.m. to 12:30 p.m., I attended a captivating session titled “LAMBDA MALWARE: The Hidden Threat in Excel Spreadsheets.” This talk was presented by Yonatan Baum and Daniel Wolfman, two experts well-versed in the intricacies of malware analysis and detection.

The presentation delved into the sophisticated techniques employed by cybercriminals, focusing on the utilization of XLM 4.0 macros in Excel as droppers. The speakers shed light on the concept of “lambda functions,” which served as a means to obfuscate the code interpreted at runtime, evading static detection methods. It was fascinating to learn how attackers leverage these dynamic lambda functions to bypass traditional security measures.

Furthermore, the speakers discussed the anti-forensic measures that can be implemented dynamically with lambda functions. They highlighted examples such as sandbox detection and RAM availability checks, demonstrating how cybercriminals adapt their malicious payloads to evade detection. It was a stark reminder of the constant cat-and-mouse game between security professionals and threat actors in the cybersecurity landscape.

The session provided valuable insights into the ever-evolving tactics employed by malware authors, emphasizing the importance of staying vigilant and employing dynamic analysis techniques to detect and mitigate emerging threats.

Friday Afternoon

Prototype Pollution and Where to Find Them

Presented by BitK and SakiiR from YesWeHack

Introduction to a new tool called ppfinder: https://github.com/yeswehack/pp-finder Prototype pollution is a vulnerability commonly found in JavaScript applications. By manipulating the prototype inheritance feature in JavaScript, attackers can introduce malicious properties into an object’s prototype chain, leading to unexpected behavior and potential code execution. The speakers shed light on the nature of this vulnerability and its varying impacts on complex applications.

Server Parasitizing for Fun and Profit

Presented by Damien Cauquil from VirtualLabs

The session explored how servers and web applications can be manipulated or parasitized to store and retrieve data without detection. Examples were provided, such as uploading different data disguised as images on platforms like Imgur. Additionally, the presenter showcased the creation of a file that served as both a PNG and a PDF, highlighting the concept of a polyglot file. The talk emphasized the need to be aware of potential misuse of server and web technologies to protect against such attacks.

Hardcore OSINT: Reversing Social Media Mechanisms

Presented by Dmitry Danilov (a.k.a SOXOJ)

The session focused on exploiting the features and mechanisms of social media platforms to gather additional data during open-source intelligence (OSINT) investigations. Attendees learned techniques to extract valuable information from social networks, showcasing the power of OSINT in the realm of cybersecurity.

Practical Threat Hunting: Straight Facts and Substantial Impacts

Presented by Neil R. Wyler (a.k.a. Grifter)

The talk cut through the noise surrounding threat hunting and provided practical insights into what truly matters. The speaker emphasized that the concepts and techniques behind effective threat hunting aren’t new or overly complex. By focusing on what’s valuable, prioritizing results, and leveraging existing knowledge, organizations can develop efficient threat hunting programs.

DPAPI - Don’t Put Administration Passwords In

Presented by Thomas Seigneuret and Pierre-Alexandre Vandewoestyne from Login Sécurité

The presentation shed light on the DPAPI (Data Protection API) in Windows operating systems. The speakers explained how developers can use the DPAPI to securely store user secrets without delving into complex cryptography. However, from an offensive perspective, the DPAPI can be an interesting target for attackers seeking to extract secrets and further compromise a system. The talk covered the theoretical aspects of DPAPI, its practical exploitation, real-world scenarios, and the countermeasures that can be implemented to limit its impact.

Physical Intrusion for Fun and Profit

Presented by Anthony Boens

This session focused on physical intrusion techniques and lockpicking in various forms. The presenter discussed how auditors encounter physical barriers during penetration testing missions and showcased various methods to overcome these obstacles. Techniques such as lockpicking, including zip and rake methods, and the use of an electric lock pick gun were demonstrated. The presentation also touched on non-lockpicking techniques for opening doors, such as using a radio, PTT passes, and the “shimming” technique. Additionally, the speaker explored the topic of signal manipulation, demonstrating signal replay attacks using the Flipper Zero device.

As the afternoon came to a close, the LeHack VIP attendees had the opportunity to participate in an exclusive evening event. It was a perfect opportunity to network with fellow professionals

Saturday Morning

On the second day of LeHack, which was a Saturday (01/07/2023), the morning started with another set of intriguing talks and presentations. Here are the notes from the Saturday morning sessions:

ADDS Persistence - A piece of advice: burn everything

Presented by Charlie Bromberg (a.k.a Shutdown) and Volker Carstein

The presentation was highly technical and not accessible to everyone due to its elevated level of complexity. The speakers, Shutdown and Volker, managed to captivate the audience with their engaging delivery and infused humor with refined jokes. The talk delved into the topic of persistence in Active Directory Domain Service (ADDS), exploring various techniques that attackers can use to persist for years in an IT system. The presentation covered the following topics:

  • ADDS Persistence Techniques: Skeleton Key, Golden GMSA, AdminSDHolder, KRBTGT Delegation, and SID History.

  • AD CS Persistence Techniques: Golden Certificates, Stolen CA, Rogue CA, and Evil ACEs.

The speakers emphasized the importance of understanding and mitigating these persistence techniques in an AD environment, as attackers can take advantage of them to maintain access and control.

The audience had the opportunity to access the presentation slides through the following links provided during the talk:

Saturday Afternoon

The Saturday afternoon sessions continued with a diverse range of talks and workshops. Here are the notes from the afternoon sessions:

Cryptocurrency & NFT Osint: Introduction to web3/Ethereum profiling & deanonymization

Presented by Patrick Ventuzelo and Tanguy Laucournet from Fuzzing Labs

The talk focused on exploring the intricacies of blockchain, cryptocurrencies, and NFTs from an OSINT perspective. It aimed to demystify how these technologies operate and discuss relevant OSINT techniques. Key points covered during the talk:

  • Explanation of concepts such as blockchain, cryptocurrencies, blenders/mixers, and NFTs.

  • Techniques for tracing transactions in cryptocurrencies.

  • Discussion on money laundering and its connection to cryptocurrencies.

  • A spotlight on the “Tornado Cash” project.

The presentation delved into real-world use cases, including how OSINT can be used to profile public personalities, identify victims of scams, and deanonymize users of Tornado Cash. Attendees gained comprehensive insights into the dynamic intersection of blockchain technology and OSINT.

Workshop : Lockpicking with Association des Crocheteurs de France

A hands-on workshop focused on lockpicking techniques for doors and padlocks. Conducted by the Association des Crocheteurs de France.

Workshop : DMARC Policy and Phishing by Spoofing

The workshop began with a demonstration of spoofing due to a frequently overlooked DMARC policy. It then transitioned into discussing phishing, including various techniques such as using non-ASCII domains, SPF, and DKIM. The session explained how to implement and add DMARC and SPF to a domain. The workshop also covered conducting a phishing campaign using tools like Gophish and a simple Postfix server.

Replacing Win32API for Process Injection

Presented by Yoann Dequeker (a.k.a. Otterhacker) from Wavestone

This talk focused on injecting processes without relying on traditional IoCs such as the VirtualAlloc, WriteProcessMemory, and CreateRemoteThread functions. Key points covered during the talk:

  • Example usage of the side effect of LoadLibraryA to allocate memory.

  • Hijacking process execution flow instead of using CreateRemoteThread.

  • Hooking DLL APIs of a process.

  • Explanation of terms like “code cave” and the “syscall breakpoint” technique.

The Q&A session included a comparison with the “process injection: Mockingjay” technique. Here is an article that discusses the Mockingjay technique: Mockingjay: A New Process Injection Technique Evading EDR Detection

The talk highlighted how process injection techniques can execute malicious payloads without the users’ or defense tools’ knowledge. It also discussed how solutions like EDR have impacted the reliability of these techniques. The presentation aimed to present a method that combines various techniques, such as Module Stomping, threadless injection, and HWBP (Hardware Breakpoints), to bypass EDR hooks.

How EDRs Work and How to Bypass Them

Presented by Processus, a YouTube content creator.

The presenter discussed various techniques to bypass EDR protections, such as AMSI, Sysmon, DLL Hooking, and ETW. Some of the key points covered during the talk were:

  • DLL unhooking: Overwriting the memory of a DLL.

  • Hell’s Gate

  • Halo’s Gate

  • Tartarus’ Gate

  • ETW

  • Minifilters

  • Protected Process Ligh

The presenter’s goal was to provide a comprehensive understanding of these protections, the talk aimed to cover the following topics:

  • Process Hollowing and PE Injection

  • AMSI Bypass

  • .NET Reflection

  • DLL Unhooking

  • Sysmon unloading

  • ETW Patching

Conclusion

In conclusion, attending to “LeHack” conference has been an exceptional experience for me. It was my first time participating, and I thoroughly enjoyed the technically intriguing presentations. I feel that I have learned a tremendous amount and have discovered numerous new topics to explore further in the field of cybersecurity.

One aspect that I particularly appreciated was the opportunity to see many familiar faces among the attendees. From my colleagues at work to my close friends and fellow hackers on my CTF team, I was always surrounded by people whose company I enjoyed during each conference. It was a pleasure to have engaging discussions and share knowledge with them.

Moreover, I had the pleasure of meeting individuals whom I had previously only known through online interactions, and whom I admired for their work and dedication in the cybersecurity field. Meeting them in person was truly delightful and served as motivation for my own journey in cybersecurity. Some notable encounters included “shutdown,” a YouTube content creator and Head of Pentest at Capgemini, as well as “Processus thief,” another prominent YouTube personality. Additionally, I had the opportunity to connect with the Hack The Box staff, including roadrunner and her friends, as well as rayanlecat, a young and well-known hacker recognized for their contributions to the cybersecurity community in France.

Attending physical events like this allows one to realize that the cybersecurity community in France is small but incredibly welcoming. It is always a pleasure to reunite with familiar faces at different events, and over time, these recurring encounters build strong bonds. It creates a sense of belonging to a tight-knit family united by a shared passion for cybersecurity.

Overall, the LeHack conference has left a lasting impression on me. The technical depth of the presentations, the connections made with like-minded individuals, and the sense of community within the cybersecurity realm have all contributed to an enriching and fulfilling experience. I look forward to attending future events and continuing my journey in this fascinating field.