A Recap of OffensiveCon 2022 in Berlin
Looking Back at OffensiveCon 2022 in Berlin
Two members of our team had the opportunity to attend the 4th edition of OffensiveCon, the international conference dedicated to offensive security, held in Berlin on February 4–5, 2022.
The event brought together around 1,200 attendees and featured 15 presentations delivered by some of the world's leading offensive security researchers. The main topics focused on vulnerability research, advanced exploitation techniques, and cutting-edge offensive security methodologies.
What is OffensiveCon?
OffensiveCon Berlin is a highly technical international cybersecurity conference exclusively dedicated to offensive security.
Its mission is to bring together the global ethical hacking community through in-depth technical presentations, hands-on training sessions, and knowledge sharing among renowned security researchers.
The conference focuses on topics such as vulnerability discovery, advanced exploitation techniques, reverse engineering, and offensive security research. The event consists of a single-track conference over two full days, complemented by specialized technical training sessions held before the conference.
Two members of the Ethical Hacking team within Proximus NXT's Cybersecurity Department attended the event and share below some highlights from two of the presentations.
Spotlight on James Forshaw's Talk:
"These Are My Principals, If You Don't Like Them, I Have Others."
James Forshaw, security researcher at Google Project Zero, presented research demonstrating that Kerberos authentication relaying remains possible even when NTLM has been disabled.
As experienced penetration testers, this presentation particularly resonated with us. During internal security assessments, we frequently encounter overly permissive network protocols that make relay attacks possible within enterprise environments. Such techniques can be used, among other things, to impersonate legitimate users across a network.
This remains a highly relevant topic, especially since Microsoft has indicated that this behavior is considered a feature rather than a vulnerability and is therefore unlikely to be patched.
In this particular case, there is no straightforward software fix. James Forshaw provided several recommendations for administrators regarding the protocols involved in his demonstrations.
From our perspective, one key takeaway is that organizations should regularly conduct internal penetration tests to identify these weaknesses before they can be exploited during a real attack.
Detection tools can also be configured to identify the behavioral patterns associated with authentication relay attacks. Proximus NXT supports organizations in both assessing their infrastructures and implementing effective detection capabilities.
Spotlight on Radek Domanski & Pedro Ribeiro's Talk:
"Pwn2Own'ing Your Router over the Internet"
Security researchers and reverse engineers Radek Domanski and Pedro Ribeiro presented their research on attacks targeting the Internet-facing interfaces of consumer and small business routers.
Compromising a router requires different techniques depending on whether the target is the WAN (Wide Area Network) interface or the internal LAN (Local Area Network) interfaces. Although WAN interfaces are generally more secure and expose very few services, the researchers successfully demonstrated six fully functional exploits during the annual Pwn2Own competition, renowned for uncovering zero-day vulnerabilities.
Most of these vulnerabilities resulted in Remote Code Execution (RCE), allowing attackers to obtain the highest privileges on targeted devices and, in some cases, install persistent backdoors that survive factory resets.
Once such exploits become publicly available, they can be valuable tools for ethical hackers conducting external penetration tests on client infrastructures. They enable realistic attack simulations and help assess the effectiveness of security controls deployed behind Internet-facing routers.
Unfortunately, the same information also becomes available to cybercriminals, increasing the global attack surface.
At the time of the presentation, Cisco had already released a security patch addressing the disclosed vulnerabilities, and organizations were strongly encouraged to apply it without delay.
Over recent years, attacks exploiting Internet-exposed services have become increasingly common. Consequently, organizations must not only patch vulnerable systems but also investigate whether attackers have already established persistence within their environments.
To address these challenges, Proximus NXT has established a dedicated CSIRT (Computer Security Incident Response Team). Throughout 2021 alone, the team responded to dozens of incidents involving similar attack scenarios.
The presentation concluded with a live demonstration of CVE-2022-20699, showcasing the exploit in action against a vulnerable Cisco router.
Conclusion
Covering a broad range of highly technical topics centered around vulnerability research and exploitation, OffensiveCon Berlin 2022 once again proved to be an outstanding event for offensive security professionals.
The conference provided valuable insights into emerging attack techniques, fostered discussions with leading experts, and offered an excellent overview of the evolving cybersecurity landscape across Europe.
Our team returned with fresh knowledge, new ideas, and practical techniques that continue to strengthen the cybersecurity services delivered by Proximus NXT.
We are already looking forward to the next edition of OffensiveCon.