In one of the last pentests we’ve found an epmd (Erlang port mapper daemon)
listening on a target system (tcp/4369). It is used to coordinate distributed
erlang instances, but also can lead to a RCE, given one knows the so called
“authentication cookie”. Usually, this cookie is located in ~/.erlang.cookie and
is generated by erlang at the first start. If not modified or set manually it is
a random string [A:Z] with a length of 20 characters. If an attacker gains
this cookie, a RCE is quite easy – as I like to describe below.
While running some SS7 pentests last year, I developed a small tool automating
some of the well-known SS7 attack cases. Today I’m releasing the first version
of ss7MAPer, a SS7MAP (pen-)testing
toolkit.
The toolkit is build upon the
Osmocom SS7 stack and implements
some basic MAP messages. At its current state tests against the
HLR are ready for use,
in future versions tests against
VLR,
MSC and
SMSC will follow.
The source code of the tool is published on
github, feel free to use and extend.
I wrote a small python script that extracts the content from Alcatel .tim
firmware files. It took some time staring at hex values, as well as a fair
amount of guess work to figure out the file format.
All .tim files start with a common header, containing the TiMOS version string,
the build string, the used compression algorithm and the number of segments
included in the file. The common header is followed by a header for each segment
in the file. The segment header contains values like the name of the segment,
the beginning of the segment in the image file, the size of the segment,
compressed as well as extracted, a checksum of the decompressed data and also
the base address and entry point of the data in the routers memory. A segment
header can look like this:
There has been, again, some development within the loki domain. Today I’m going
to write about the latest module added to the suite, a module for decoding and
cracking Cisco’s TACACS+.
TACACS is the Terminal Access Controller Access-Control System, a protocol for
handling remote user authentication and central access control. It originated in
1984 and was used in the old Unix world. TACACS+ is a related protocol developed
by Cisco Systems and is widely used for AAA (Authentication, Authorization,
Accounting) on IOS based devices. It was released as an
open standard in 1993 (and
expired in 1998 by the way ;-)).
I’m back from London where I gave a talk about security evaluation of
proprietary network protocols. I had a great time at
InfoSecurity Intelligent Defence
and BSides London, many thanks for
inviting me and giving me the opportunity to speak to so much nice people.
Find the abstract and the download link to the slides after the break.
Even in the time of Cloud-based security tools, behavior- and machine
learning-based APT detection and colorful security appliances, a lot of
vulnerabilities are still buried deep within the protocol layers. For security
researchers it is quite a challenge to find those in well documented protocols
(take SSL for an example), and when it comes to proprietary protocols, the bar
is raised even (significantly) higher. This keynote will show that there is
still an urgent need for security evaluation on (undocumented) network
protocols, discuss war stories on protocol fails, and also give an
introduction into the methodology of protocol reversing and how those protocol
fails could have been avoided.
Recently we started playing around with Cisco’s virtual router, the CSR 1000V,
while doing some protocol analysis. We found Cisco offering an BIN file for
download (alternatively there is an ISO file which contains a GRUB boot loader
and the BIN file, or an OVA file which contains a virtual machine description
and the ISO file) and file(1) identifies it as DOS executable:
$ file csr1000v-universalk9.03.12.00.S.154-2.S-std.SPA.bin
csr1000v-universalk9.03.12.00.S.154-2.S-std.SPA.bin: DOS executable (COM)
We didn’t manage to get the file running, neither in a (Free-)DOS environment,
nor in a wine virtual DOS environment, except using the boot loader from the ISO
file. So we became curious as for the structure and ingredients of the file.
As we continue our research in the 3GPP protocol world, there is a new tool for
you to play with. It is called s1ap_enum and thats also what it does 😉
The tool itself is written in erlang, as i found no other free ASN.1 parser that
is able to parse those fancy 3GPP protocol specs. It connects to an MME on
sctp/36412 and tries to initiate a S1AP session by sending an S1SetupRequest
PDU. To establish a S1AP session with an MME the right MCC and MNC are needed in
the PLMNIdentity. The tool tries to guess the right MCC/MNC combinations. It
comes with a preset of known MCC/MNC pairs from
mcc-mnc.com, but can try all other combinations as
well.
Within the last months I had some time to work on my code and today I’m
releasing some of that: a new version of dizzy as well as two new loki modules.
Dizzy is able to use neighbor
travis’ facedancer
to emulate a client device. Two fuzzing modes are available for USB descriptor
fuzzing and USB endpoint fuzzing.
Here is an example cmd to start usb configuration descriptor fuzzing:
Its been a long time, since i released the last version of pytacle, but now the
time has come. Here is alpha2 with some new features:
– Support of RTLSDR sticks
– Possibility to scan for cells around you
– Changed the code to generate real KCs (but as nobody noticed the wrong KCs i
guess you were good with the others 😉
Im also planning to address hopping channels in the future, but ive not made it
far enough in my DSP lecture, yet 😉