As you might have read,
I recently had a closer look at how easy it actually is to become part of an IoT Botnet.
To start a further discussion and share some of my findings I gave a quick
overview at the recent Dayton Security Summit. The Mirai
Botnet was supposed to be one of the case studies here. But the way things go if
one starts diving into code…I eventually gave an overview of how the Mirai Bot
actually works and what it does. As such: Here a quick summary of the Mirai
Botnet bot.
As described in my previous post,
KrebsonSecurity.com was attacked by a major DDoS attack.
Reaching between 620Gbps and 660Gbps it was the largest documented DDoS attack
so far. The attack seemingly resulted from a Botnet called Mirai. Shortly after
the attack, a
post on hackforums
claimed to contain the actual source code of just this botnet.
The source code consists of
three projects: The bot itself with its CnC server and a loader component.
Brian Butterly
How to Become Part of an IoT Botnet
I suppose there are many people out there who want to achieve a greater good, fight evil corp and “show those guys”. So why not set a statement and become part of a botnet? #Irony!!! Of course I suppose (hope) that none of you actually want to be part of something like an IoT botnet, but joining could in theory be dead easy. So quite a while back I bought a dead cheap WiFi camera for use at home. It was kind of just as insecure as I had expected, so it got it’s own VLAN and stuff and here is why….
Continue reading Continue readingNotes on Hijacking GSM/GPRS Connections
As shown in previous blogposts we regularly work with GSM/GPRS basestations for
testing devices with cellular uplinks
or to simply run a
private network during TROOPERS.
Here the core difference between a random TROOPERS attendee and a device we want
to hack is the will to join our network, or not! While at the conference we hand
out own SIM cards which accept the TROOERPS GSM network as their “home network”
some device need to be pushed a little bit.
Every SIM card has it’s own home network, which is encoded in the fist five
(European standard) or six (North American standard) digits of its IMSI –
International Subscriber Number. The first three digits are the MCC, the Mobile
Country Code, the next two/three the MNC, Mobile Network Code. International
network overview are publicly available and for example
can be found >here<.
For instance, Germany has the MCC 262 and Vodafone Germany uses MNC 02. So a SIM
card with an IMSI starting with 26202 belongs to them.
Sticking to the settings in its own SIM card a device will always prefer to
connect to it’s own home network above all others. If the home network is not
available it will usually go for the strongest signal. To protect users from
unnecessary costs, an operator will usually add certain rules to prevent the
device from connecting to other networks in the same country. So if you’re an O2
customer in Germany, visit a shopping center and only have reception for a
T-Mobile cell, your phone will not directly jump into this network, even though
it’s the strongest signal source.
A Trip to Hannover Messe
Once every few years I decide to head to Hannover and attend Hannover Messe, probably the largest industrial trade fair in Germany and apparently on of the most important in the world. As this year’s main topic was “Industrie 4.0” I simply could not resist to go out on a hunt for new and interesting (secure) smart connected magic! And trust me, I was not disappointed – here’s a few of my impressions.
Continue reading Continue readingTroopers 16 USB Condom
At times with many many digitally transmittable diseases, protection might be more important than ever. When connecting your smartphone to a rogue charger, or a foreign smartphone to your own laptop, you never now what will happen. You never know what data crosses the lines. But there is help: A USB condom!
As the Troopers 16 Badge was a neat integrated device, we had the challenge to identify something to be soldered for our attendees. The past has shown, that soldering rocks and all of our attendees, all of you, really enjoy it! After some looking around and roaming the Internet, we decided to go for a simple device, which would protect you and your devices in a hostile world. A slim PCB, which will protect your phone when having to connect it to some unknown charger or for situations when “a mate” just wants to connect his/her phone to your laptop for “charging purposes”.
Continue reading Continue readingTroopers 16 – Taking the Badge to yet Another Level!
Real men used to wear pink pagers, but that’s the past and recently it was time
for Troopers 16. Meaning: Real Troopers wear awesome Badges! And, from the
feedback we got, they did!
Troopers might be over, but the era of the TR16 Badge is seemingly just
beginning. As such, here’s a quick insight into the badge!
To start, this is the first of (at least) three blogposts covering the badge. As
we’re currently in the middle of stripping and cleaning our source code
repository, this post now will not cover the firmware. The stripping is not
about hiding something, but as we used an Open Source
RTOS our repo
currently contains modules, which are for completely other architectures.
In addition we needed a few workarounds while getting the badge up and running
for the conference, following our own hacking sessions, there will be a
dedicated post concerned with hardware modifications and hacks which can be
performed.
Damn Vulnerable Safe
A while back Stefan and I held a little crash course/orientation run on hardware hacking at a German Fachhochschule. Planning to use something “real” we went for a simple electronic safe with a bunch of different vulnerabilities. I guess most security guys who spend a fair amount of time in hotels will understand this choice. As we needed something we could rely on would break, we stripped the device and swapped the original electronics for our own. The result was the “Damn Vulnerable Safe”.
Continue reading Continue readingWelcome to Brazil!
Welcome to Brazil!
“Welcome to Brazil”, I think, turned to being the most used statement during the past Hackers to Hackers Conference in Sao Paulo. It was used as the main reaction to every speech taking moment, and there were a lot of those! To honor the moments and give you a quick insight into was what going on in Sao Paulo, here is a quick summary of the overall event and our own contribution.
Continue reading Continue readingHackRF meets PortaPack H1
Today we received a few ShareBrained Technology – PortaPack H1 to use with our HackRFs. Having done a first few minutes of scanning, I just wanted to give you a quick overview of its features and potential…
After having had Michael Ossmann in for a few workshops with his Jawbreaker and HackRF One we have used the HackRF on multiple occasions. No matter if research projects or actual customer projects, the HackRF has always been of great help. As we mainly use it on laptops, we’ve got certain constraints concerning its portability when wanting to do some quick mobile scanning. Although there are a few solutions for tablets and smartphones, they haven’t been quite able to convince all of us. So a while back we decided to keep an eye on the PortaPack and have been since been waiting for its release.
Continue reading Continue readingApple iOS PIN Bruteforce
Over the past few weeks, multiple news sites have covered some mystical approach to bruteforce PINs on Apple iOS devices. All articles cover a black box called IP Box, the fact that PINs can be broken and that sometimes the automatic wipe after 10 failed tries can be circumvented. Sadly, as often, the what is described but not the how……
This blog post will give you a simple overview of both the practical attacks and the vulnerabilities behind them. Although the Headings don’t quite give away the content, the post starts with a simple PIN bruteforce against iOS 7.x and then goes over to a more advanced attack on iOS 8.x and a few technical details on the “black box”.
Continue reading Continue reading