We’re sometimes approached with the question “Which IPv6 mailing lists do you
guys read/subscribe to?” – here’s a quick overview of the main ones guys like
Christopher, Patrick, Rafael, Antonios and myself are periodically lurking at,
to discuss IPv6 (network|security) related stuff with other practitioners and
to learn from them:
during our BlackHat US 2014 talk titled
“Evasion of High-End IPS Devices in the Age of IPv6”,
among others we discussed a Snort preprocessor rule (116:456) which, when
enabled (not the case by default), triggers an alert when an IPv6 datagram with
nine (9) or more IPv6 Extension Headers is used (such a header was used by us to
evade Snort). However, we mentioned that:
RA Guard Evasion is well-known in the IPv6 “circles”; there is
RFC 7113 Advice for IPv6 Router
Advertisement Guard (RA-Guard) and many interesting blog-posts like this
one here,
here,
and this excellent write-up
here that discuss
this issue.
Moreover, as Jim Smalls states in his comprehensive
“IPv6 Attacks and Countermeasures”
presentation given at the
North American IPv6 Summit 2013,
DHCPv6 Guard or a corresponding IPv6 ACL can stop a DHCPv6 Rogue Servers, but
(only?) for non-malicious/non-fragmented DHCPv6 packets (slide 35). However, at
that time there wasn’t any known attack tool in the wild that had the
fragmentation evasion built in.
Most of you are probably aware of the recently discovered/-closed severe ntpd
vulnerabilities (CVE-2014-9293, CVE-2014-9294, CVE-2014-9295, CVE-2014-9296, see
also
the initial ntp.org security notice).
Some days ago the Project Zero team at Google published a blog post
“Finding and exploiting ntpd vulnerabilities”
with additional details. In this one they mentioned a seemingly minor but quite
important detail: on a default OS X installation one of the built-in protection
mechanisms of ntpd (that is the restriction to process certain packets only if
they are sourced on the local machine) can easily be circumvented by sending
IPv6 packets with a spoofed source address of ::1 (the equivalent to 127.0.0.1
in IPv4 which would be discarded by the kernel once received from an external
source).
Happy new year and all the best for 2015 to everybody!
Here’s the next round of Troopers15 talks (all the others can be found
here):
===
Marion Marschalek & Moti Joseph: The Wallstreet of Windows Binaries
FIRST TIME MATERIAL
Synopsis: Nowadays common ways to find exploitable vulnerabilities include
but are not limited to fuzzing, static and dynamic analysis and patch reversing.
All common approaches have advantages and limits. Fuzzers tend to only find a
limited number of bugs, depending on the sophistication of the fuzzer which is
indirectly dependent on the development time invested. Reverse engineering a
binary for finding bugs, regardless whether statically or with a debugger, is
tedious and requires a lot of time and expertise.
As we are lazy bastards, we refuse to do all the work by hand and brain. And, as
we are greedy bastards, we want a maximum scope of vulnerabilities we can cover
and not be limited to what we see from a fuzzers perspective.
So as you know – in general the lazy greedy bastards have the better ideas. We
present you with our idea, which is built after the model of the Wallstreet. We
built a tool which weighs the value of a function in a Windows binary as the
Wallstreet values a stock; the value telling us the likability of a function to
be exploitable.
The Wallstreet technique works with two different evaluation methods, for once
the likability that a function is vulnerable and also the likability that it is
exploitable.
We collect indicators, which help us evaluate that a specific function is
potentially vulnerable. Such could be a present memory allocation or conversion
function, a lacking sanitization check or a suspicious pattern in the
functionname such as ‘create’, ‘convert’ or ‘set’. A combination of these and a
handful more indicators lets us calculate what we call the speculation value.
For the validation of the exploitability we traverse the call tree of a
suspicious candidate, to verify its accessibility in an automated way. Only
functions which we can influence as an attacker are interesting for us; thus we
rate these accessible functions with a price-to-earnings value. Finally putting
speculation value and price-to-earnings value in context, we evaluate a function
with either ‘buy’ if we believe it comes with an exploitable vulnerability, or
with ‘sell’ when we are certain it is not interesting to us. No worries, the
presentation will not contain advanced mathematical equations.
Our tool parses binaries and persists all the gathered information to a
database, from where we can retrieve highly suspicious functions in an automated
way. Without getting our hands dirty, that is. And because we are lazy bastards
who like colors, a lot, we use visuals to make evaluation even easier. The tool
is dubbed Wallstreet, free after the most famous stock market on the planet. It
is based on Python, C and SQLite and will be released under the WTFPL license
(http://www.wtfpl.net/). Also, there will be demos 😀
Wrapping it up, this presentation shows an easy to use approach which makes the
complicated topic of binary exploitation more accessible. Wallstreet of Windows
Binaries provides beginners with better understanding of the challenges and
practitioners with a hands-on tool.
As we promised some days ago here’s the fourth round of Troopers15 talks (the
first three can be found here). We really
can’t wait for the con ourselves 😉 !
Arrigo Triulzi: Pneumonia, Shardan, Antibiotics and Nasty MOV: a Dead Hand’s
Tale FIRST TIME MATERIAL
Synopsis: Starting in the 80’s we will discuss the influence of nuclear weapons
on the design of an ITsec “Dead Hand” system for a security practitioner, how it
merged with research into firmware backdoors and microcode modification and
finally triggered when instead of enjoying Summer pneumonia struck unannounced,
or rather, announced by the Dead Hand via Twitter.
After we recently released the
“Linux IPv6 Hardening Guide”
we got a number of suggestions “could you pls provide a similar document for
$OS?” (btw: thanks to you all for the overwhelming interest in the Linux
document and the active discussion of ip6tables rule approaches on the
ipv6hackers mailing list).
Hence Antonios thankfully decided to put together a list of configuration steps
for Windows servers. It
can be found here.
Once more we’d like to emphasize that the approach described is only suited for
very specific environments with high security requirements and an associated
ratio of “generous operational resources”. From our perspective this guide is
intended mostly to serve as a source of inspiration (“what could be done”) and
for documentation purposes (“how to do it”). Everything described should be
carefully tested in your specific environment.
For example, we were recently involved in IPv6 security planning in an
organization where the Windows guys (completely legitimately) came up with a
stance of “before we fully accept and ratify the strategy and policy just
discussed, we’d like to get feedback from Microsoft, if we still have full
support once we follow this path”.
As we promised some days ago here’s the third round of Troopers15 speakers
(first
one here,
second
here).
It’s going to be awesome!
Andreas Lindh: Defender Economics FIRST
TIME MATERIAL
Synopsis: There are a lot of preconceptions about defense, the most prevalent
one probably the “defenders dilemma” in which it is stated that an attacker only
needs to find one weakness to compromise a network while a defender needs to
defend all of them. While this may be true in a technical sense, things become a
lot more complicated once you apply real world considerations. Preconceptions
like this are often the foundation on which risk management and ultimately
defense strategies are based, something that has led to a number of false but
generally accepted assumptions about attackers and their capabilities, and how
to defend against them.
This talk will discuss the capabilities, and more importantly the limitations,
of different types of attackers. Using the ancient wisdom of the Teenage Mutant
Ninja Turtles, the speaker will explain how knowledge of an attacker’s
limitations can be leveraged to raise the cost of attack, something that will
tip the scale in the defenders favor. The speaker will also explain how
different defensive measures will affect different types of attackers, how they
are likely to react to them, and in the end how to get them to hopefully move on
to another target.
We were recently approached by a customer asking us for support along the lines
of “do you have any recommendations as for strict hardening of IPv6 parameters
on Linux systems?”. It turned out that the systems in question process quite
sensitive data and are located in certain, not too big network segments with
very high security requirements.
They indicated they were willing to spend significant operational resources on
“securely configuring them”. So Antonios deciced to write a small hardening
guide for IPv6 on Linux, mostly focusing on manual configuration of pretty much
everything (including neighbor cache entries 😉 with accompanying deactivation
of all automatic mechanisms, together with ip6tables based local packet
filtering.
The document
can be found here.
We just released a white paper authored by
Antonios Atlasis that provides an
overview which pentesting tools currently support IPv6 and how to (still) use
them if that’s not the case. It can be found
in our newsletter section.