innovaphone fixed several vulnerabilities in two
VoIP products that we disclosed a while ago. The affected products are the
Linux Application Platform
and the
IPVA.
Unfortunately, the release notes are not public (yet?) and the vendor does not
include information about the vulnerabilities for the Linux Application
Platform. Therefore, we decided to publish some more technical details for the
issues.
Multiple Vulnerabilities in Linux Application Platform
The Linux Application Platform was affected by three vulnerabilities that could
be chained to get full root access to a target system. However, the initial
access vector is only exploitable by authenticated users. The vulnerabilities
have been identified on the Linux Application Platform V10 SR41. According to
the vendor they have been fixed in
V10 SR57.
Lately, I’ve experienced some weird Pidgin crashes when I
was copy&pasting into chat windows. The strange part was: I didn’t even know
what triggered the crash because I actually didn’t know what was in my clipboard
at this exact point. This is a quick write-up of how I investigated the issue
and some interesting properties I found out about clipboards.
Everything started with a document that I was editing in a Windows VM in
Microsoft Word. At some point, I wanted to copy some lines of the document and
paste it into a Pidgin chat window on my Linux host system. As I did this, I
noticed that when I pasted the data into the chat window it included a lot of
white spaces. I thought something went wrong and just tried to delete it by
pressing CTRL+A (to mark everything) and press BACKSPACE. But this caused Pidgin
(2.13.0-5 on Arch Linux) to close with a segfault and created a core dump.
This is a write-up about how to use Frida to dump
documents from a process after they have been loaded and decrypted. It’s a
generic and very effective approach demonstrated on a piece of software from
North Korea.
Some time ago we received an ISO file which was a dump of a CD-ROM from North
Korea. The only information we got was that it included a document viewer and
various PDF documents. I started to dump the content of the ISO in order to
analyze what the reader was actually doing by mounting it:
Lately I’ve been analyzing a .NET binary that was quite interesting. It was a
portable binary that shipped without any third-party dependencies. I started
looking at the .NET assembly with ILSpy and noticed that there was not that much
code that ILSpy found and there were a lot of references to classes/methods that
were neither in the classes identified by ILSpy nor were they part of the .NET
framework.
At some point I was going through everything that ILSpy displayed about the
binary, including the resources which were looking very interesting:
In various scenarios it might be helpful or even required to have a statically
compiled version of Nmap available. This applies to e.g. scenarios where only
limited user privileges are available and installing anything to the system
might not be desirable.
For such cases I’ve started to create recipes to build such binaries. Similar
projects are already available on GitHub, but there are several reasons why I
chose to create my own tools:
The 11th USENIX Workshop on Offensive Technologies (WOOT17) took place the last
two days in Vancouver. Some colleagues and I had the chance to attend and enjoy
the presentations of all accepted papers of this rather small, single-track
co-located USENIX event. Unfortunately, the talks have not been recorded.
However, all the papers should be available on the
website. It’s worth
taking a look at all of the papers, but these are some presentations that we’ve
enjoyed:
Last friday Florian and me attended the
6th No-Spy Conference in Stuttgart, Germany. We
gave a talk about surveillance and censorship on modern devices in North Korea
and discussed various aspects with the attendees. The atmosphere was very
welcoming and we had some nice discussions about various topics which allowed us
to better clarify some things. The slides are available
here.
Users of the KNX, a standard
for home automation bus systems, may already have come across KNXnet/IP (also
known as EIBnet/IP): It is an extension for KNX that defines Ethernet as a
communication medium for KNX which allows communication with KNX buses over IP
driven networks. Additionally, it enables one to couple multiple bus
installations over IP gateways, or so called KNXnet/IP gateways.
In the course of some KNX related research we’ve had access to various KNXnet/IP
gateways from different vendors, most of them coupled in a lab setup for testing
purposes. The typical tools used for such tasks are
ETS, the
professional software developed by the creators of KNX (proprietary, test
licenses available) and
eibd, an open source
implementation of the KNX standard developed by the TU Vienna.
Some of us had the pleasure to visit this year’s REcon in
Montreal, Canada. Unfortunately, work caught us just when we arrived back in
Germany, so I haven’t had time to sit down and write down a few words so far.
However, we think that what we’ve experienced at REcon is worth writing about.
The overall quality of the speakers and talks were very nice. What really amazed
me was the art work of REcon:
Recently I’ve started some research on MikroTik’s RouterOS, the operating system
that ships with RouterBOARD devices. As I’m running such a device myself, one
day I got curious about security vulnerabilities that have been reported on the
operating system and the running services as it comes with tons of
features. Searching
for known vulnerabilities in RouterOS on Google doesn’t really yield a lot of
recent security related stuff. So I thought, there is either a lack of (public)
research or maybe it is super secure… 🙂