A
quick update on the workshop we’ve just finished at
Hack in the Box 2012 Amsterdam:
Due
to popular demand we decided to bring the slides online without wasting any more
time. The official website of the conference is currently experiencing some
problems due to high interest in all the stuff what was released in the last two
days. Great conference!
Update #1: Slides are available for download
here.
In the course of our ongoing
cloud security research,
we’re continuously thinking about potential attack vectors against public cloud
infrastructures. Approaching this enumeration from an external customer’s
(speak: attacker’s 😉 ) perspective, there are the following possibilities to
communicate with and thus send malicious input to typical cloud infrastructures:
Management interfaces
Guest/hypervisor interaction
Network communication
File uploads
As there are already several successful exploits against management interfaces
(e.g.
here
and here) and
guest/hypervisor interaction (see for example
this one; yes,
this is the funny one with that ridiculous recommendation “Do not allow
untrusted users access to your virtual machines.” ;-)), we’re focusing on the
upload of files to cloud infrastructures in this post. According to our
experience with major Infrastructure-as-a-Service (IaaS) cloud providers, the
most relevant file upload possibility is the deployment of already existing
virtual machines to the provided cloud infrastructure. However, since a quick
additional research shows that most of those allow the upload of VMware-based
virtual machines and, to the best of our knowledge, the VMware virtualization
file format was not analyzed as for potential vulnerabilities yet, we want to
provide an analysis of the relevant file types and present resulting attack
vectors.
Hi @all,
today im releasing a new version of our famous fuzzing framework, dizzy. The
version counts 0.6 by now and youll get some brand new features!
see the CHANGELOG:
v0.6:
– ssl support
– server side fuzzing mode
– command output
– new dizz funktions: lambda_length, csum, lambda_csum, lambda2_csum
– recursive mutation mode
– new dizz objects: fill
– new interaction objects: null_dizz
– reconnect option
– additional fuzzing values
SQL injection attacks have been well known for a long time and many people think
that developers should have fixed these issues years ago, but doing web
application pentests almost all the time, we have a slightly different view.
Many SQL injection problems potentially remain undetecteddue to a lack of
proper test methodology, so we would like to share our approach and experience
and help others in identifying these issues.
In march 2012 Microsoft announced a critical vulnerability
(Microsoft Security Bulletin MS12-020)
related to RDP that affects all windows operating systems and allows remote code
execution. A lot of security professionals are expecting almost the same impact
as with MS08-067 (the conficker vulnerability) and that it will be only a matter
of time, until we will spot reliable exploits in the wild. Only a few days later
an exploit, working for all unpatched windows versions was released, so it seems
that they were right ;-), but of course no one will run an exploit without
investigating the code. So lets have a look into the exploit Code.
Lately there have been some rumors on the full-disclosure mailing list referring
to a blogpost of Hatforce about a new method to bypass the PIN/password lock on
Android Gingerbread phones.
The approach was to boot into the Recovery Mode and execute a reset to factory
state. The ideal result should be a reliable wipe of the /data partition.
However, the author managed to recover data after the wiping process. This has
been stated as a method on extracting sensitive date without knowing the actual
pin or passcode.
This is a guest post by the SAP security expert Juan Pablo Perez-Etchegoyen,
CTO of Onapsis. Enjoy reading:
At Onapsis we are continuously researching in the ERP
security field to identify the risks that ERP systems and business-critical
applications are exposed to. This way we help customers and vendors to increase
their security posture and mitigate threats that may be affecting their most
important platform: the one that stores and manages their business’ crown
jewels.
Hi everyone,
it’s me again with another story of a toll fraud incident at one of our
customers (not the same as
the last time
of course ;-)).
The story began basically like the last one: We received a call with an urgent
request to help investigating a toll fraud issue. Like the last time I visited
the site in order to get an idea on what was going on exactly. The customer has
a VoIP deployment consisting of the whole UC Suite Cisco offers: Call Manager,
Unity Connection for the voice mailboxes, Cisco based Voice-Gateways and of
course, IP phones.
Visual Voicemail (VVM) is a common feature of phone providers which allows
accessing the good old voice-mailbox through the phone’s visual interface. In
contrast to the classical voicemail approach, VVM allows intuitive navigation
through voice-messages without dealing with an automated voice which tells you
about message count and possible options. However, this implies the need of
actually loading the messages of missed calls on the phone. The VVM-app displays
missed calls and downloads corresponding messages which have been left by the
initial caller. The software comes with your iPhone and is not intended for
uninstallation. However, providers have to support it and will have to activate
it for supporting clients. This feature is available on iPhones since August
2009 and became available on BlackBerrys and few Nokia phones later. Android
doesn’t implement VVM in general. However some telecommunication providers offer
their own apps to add this feature. Since version 4.0, Android offers an
official Voicemail Provider API enabling better integration for the mobile OS.
One of our customers called us recently and asked for some support in
investigating a toll fraud issue they encountered in one of their sites. Their
telecommunications provider had contacted them informing them that they had
accumulated a bill of 30.000€ over the last ten days.
Without knowing anything more specific, I drove to the affected site to get the
whole picture.
They have a VoIP deployment based on Cisco Unified Communications Manager (CUCM,
aka Call Manager) as Call Agent. The CUCM is connected via a H.323 trunk to a
Cisco 2911 ISR G2 which is acting as a voice gateway. The ISR has a primary rate
ISDN (PRI) Interface which is connected to the PBX of the telco. Furthermore
they use a feature called Direct-inward Dial (DID) or Direct Dial-in (DDI) which
is offered by Telco’s to enable calling parties to dial directly to an extension
on a PBX or voice gateway.