First day at hack.lu. Three of us kicked the conference
off with the ARM IoT Firmware Emulation workshop by
Saumil. The goal of this workshop was not
so much to write exploits or to pwn boxes but to learn how to build a beneficial
research environment by emulating the hardware of a Linux based IoT device to
run its firmware in order to run analysis and tests.
First step is to obtain the firmware. This could be done by dumping it directly
from the device or by downloading firmware images from the vendor. In order to
dump the firmware from the device one has to obtain access to the underlying
system which is usually done by finding the serial console on the hardware since
this one often exposes an unauthenticated root shell. I think there is enough
documentation online on how to identify and connect to a serial console so I
won’t cover the details here. It’s also covered in Saumil’s
slides
in detail. Having the bootup logs from this console will be helpful later
though. While talking about baud rates for the serial console Saumil made a
great pun I don’t want to withhold: “Most common is baud rate 115200. If you
find a console with baud rate 9600 you are in fact talking to an acoustic
coupler. That’s not an IoT device, it rather belongs to a museum.”
Hey there, for those of you that roll your eyes when writing the nth Information
Disclosure Finding in a report, here is a short story of how such information
helped compromising a system.
In a recent penetration we found a hidden debug page which disclosed information
about internal parameters. Along with database connection strings and key
material there was a username and a user home parameter disclosed on said debug
page.
Hi everybody,
This is the second entry in our research diary on IP cameras. If you haven’t
done so yet, you should read the first entry in advance. This time we focused
more on analysis and exploitation.
Another entry vector
After running a vulnerability scan on both devices, it was revealed that the
M1033 has multiple buffer overflow vulnerabilities (CVE-2012-5958 to
CVE-2012-5965), which are readily exploitable via Metasploit. This gave us
another shell (in addition to the root shell mentioned in the last post), though
this time it was not a root shell. By using the find command, we searched for
executables having the setuid or setgid bit set. We hoped to use one of
those to escalate privileges. To do so yourself add the parameter -perm -4000
to find and it will search for files having the setuid bit set. If you try
that on your own unix-like device, for example it should yield /bin/passwd
which is perfectly reasonable as you’re able to change your password without
being root.
A few months ago I had the opportunity to visit this year’s Black Hat in Las
Vegas. Due to a few weeks of vacation following the conference here are my
delayed 2 cents (part 1)
Troopers16 has been over for quite a while now, but because sharing is caring,
we would like to give you some more insight and share some gems that happened
over the 2 days of us running a small/medium sized enterprise in mid-west Russia
as part of the well received FishBowl side story.
Technology wise the whole infrastructure of FishBowl, as well as the Cyber
Emergency Response Team, was hosted on one FreeBSD machine with exception of the
challenge scoreboard which was on site only, hence conference network only.
The C.E.R.T. web site was static web site using the jekyll
engine. FishBowl on the other hand required some dynamic web magic which is why
we choose to use the flask framework. For the
FishBowl web design we simply helped ourselves with the styles of the
Troopers web site, who of you noticed? 😉
All web related stuff was reverse proxied by an nginx to
provide a common layer of technology even though every venture was segregated
into its own FreeBSD jail environment.
For mail a simple postfix setup was set up. Having a proper mail server for such
»shenanigans« turned out to be very enjoyable, but more on that later.
Two weeks ago we had a great time at
Day-Con VI. Enno, Matthias, Rene, Frank and
me traveled to Dayton, OH to give workshops and presentations. We started a
tough week full of workshops on Tuesday where
Rene gave a deep inside look into the world of security on current mobile
platforms. Matthias discussed security problems and possible design patterns of
cloud environments in his Cloud & Virtualization Security Workshop before he
gave a first insight into the world of reverse engineering on Wednesday. Frank
and me taught the basics of hacking and pentesting in the
PacketWars bootcamp (comparable to the one at
TROOPERS),
preparing the participants for the
PacketWars on Saturday. Obviously we were
not the only ones having a
great time
😉
In our last series of posts regarding the VMDK file inclusion attack, we focused
on read access
and
prerequisites
for the attack, but avoided stating too much about potential write access. But
as we promised to cover write access in the course of our future research, the
following post will describe our latest research results.
First of all, the same
prerequisites
(which will be refined a little bit more later on) as for read access must be
fulfilled and the same
steps have to
be performed in order to carry out the attack successfully. If that is the case,
there are several POIs (Partitions Of Interest) on a ESXi hypervisor that are
interesting to include: