In this post, I will introduce fpicker. Fpicker is a Frida-based
coverage-guided, mostly in-process, blackbox fuzzing suite. Its most significant
feature is the AFL++ proxy mode which enables blackbox in-process fuzzing with
AFL++ on platforms supported by Frida. In practice, this means that fpicker
enables fuzzing binary-only targets with AFL++ on potentially any system that is
supported by Frida. For example, it allows fuzzing a user-space application on
the iOS operating system, such as the Bluetooth daemon bluetoothd – which was
part of the original motivation to implement fpicker.
The Federal Office for Information Security (BSI) aims to sensitize
manufacturers and the public regarding security risks of networked medical
devices in Germany. In response to the often fatal security reports and press
releases of networked medical devices, the BSI initiated the project
Manipulation of Medical Devices (ManiMed) in 2019. In this project, a security
analysis of selected products is carried out through security assessments
followed by Coordinated Vulnerability Diclosure (CVD) processes. The project
report was published on December 31, 2020, and can be accessed on the BSI
website 1.
The Federal Office for Information Security (BSI) aims to sensitize
manufacturers and the public regarding security risks of networked medical
devices in Germany. In response to the often fatal security reports and press
releases of networked medical devices, the BSI initiated the project
Manipulation of Medical Devices (ManiMed) in 2019. In this project, a security
analysis of selected products is carried out through security assessments
followed by Coordinated Vulnerability Diclosure (CVD) processes. The project
report was published on December 31, 2020, and can be accessed on the BSI
website1.
The Federal Office for Information Security (BSI) aims to sensitize
manufacturers and the public regarding security risks of networked medical
devices in Germany. In response to the often fatal security reports and press
releases of networked medical devices, the BSI initiated the project
Manipulation of Medical Devices (ManiMed) in 2019. In this project, a security
analysis of selected products is carried out through security assessments
followed by Coordinated Vulnerability Diclosure (CVD) processes. The project
report was published on December 31, 2020, and can be accessed on the BSI
website1.
The Federal Office for Information Security (BSI) aims to sensitize
manufacturers and the public regarding security risks of networked medical
devices in Germany. In response to the often fatal security reports and press
releases of networked medical devices, the BSI initiated the project
Manipulation of Medical Devices (ManiMed) in 2019. In this project, a security
analysis of selected products is carried out through security assessments
followed by Coordinated Vulnerability Diclosure (CVD) processes. The project
report was published on December 31, 2020, and can be accessed on the BSI
website1/
The Federal Office for Information Security (BSI) aims to sensitize
manufacturers and the public regarding security risks of networked medical
devices in Germany. In response to the often fatal security reports and press
releases of networked medical devices, the BSI initiated the project
Manipulation of Medical Devices (ManiMed) in 2019. In this project, a security
analysis of selected products is carried out through security assessments
followed by Coordinated Vulnerability Diclosure (CVD) processes. The project
report was published on December 31, 2020, and can be accessed on the BSI
website1.
In the
last blog post,
we discussed how fuzzers determine the uniqueness of a crash. In this blog post,
we discuss how we can manually triage a crash and determine the root cause. As
an example, we use a heap-based buffer overflow I found in GNU readline 8.1 rc2,
which has been fixed in the newest release. We use GDB and rr for time-travel
debugging to determine the root cause of the bug.
NSX-T is a Software-Defined-Networking (SDN) solution of VMware which, as its
basic functionality, supports spanning logical networks across VMs on
distributed ESXi and KVM hypervisors. The central controller of the SDN is the
NSX-T Manager Cluster which is responsible for deploying the network
configurations to the hypervisor hosts.
This summer, I looked into the mechanism which is used to add new KVM hypervisor
nodes to the SDN via the NSX-T Manager. By tracing what happens on the KVM host,
I discovered that the KVM hypervisor got instructed to download the NSX-T
software packages from the NSX-T Manager via unencrypted HTTP and install them
without any verification. This enables a Man-in-the-Middle (MITM) attacker on
the network path to replace the downloaded packages with malicious ones and
compromise the KVM hosts.
Recently I discovered some vulnerabilities in
GNU Readline. These bugs
have been
fixed
in GNU Readline version 8.1.
The case of identifying the vulnerabilities was rather interesting. I wanted to
fuzz another program and wrote a quick harness to test if my setup works. This
test harness used GNU Readline to read input from stdin and passed the data
along to the function under test. I left the fuzzer running while I started to
improve the harness (which would also mean getting rid of GNU Readline as it is
relatively slow for the use-case at hand). However, AFL showed the first crashes
and upon inspection, the vulnerabilities where not in the code I actually wanted
to fuzz but in my systems GNU Readline.
With this blog post I am pleased to announce the publication of a new ERNW White
Paper [1]. The paper
is about severe vulnerabilities in an insulin pump we assessed during project
ManiMed and we are proud to publish this subset of the results today.
Manipulating Medical Devices
The German Federal Office for Information Security (BSI), in its role as the
Federal Cyber Security Authority in Germany, aims to sensitize manufacturers and
the public regarding security risks of networked medical devices. In response to
the often fatal security reports and press releases of networked medical
devices, the BSI initiated the project Manipulation of Medical Devices (ManiMed)
in 2019. In this project, a security analysis of selected products is carried
out through security assessments. In the context of this project, severe
vulnerabilities were identified during the assessment of the DANA Diabecare RS
system.