So there was a pandemic, the whole world was under lockdown, and I got a bit
depressed.
I needed something new in my life, so I decided to take my favorite dog out for
a walk in the ATT&CK jungle to check out the newly added sub-techniques…
If you’re not familiar with ATT&CK and are wondering what this is all about, no
worries…
ATT&CK stands for Adversarial Tactics, Techniques & Common Knowledge.
It’s a treasure trove of information about real-life offensive tradecraft.
I like to see it as an open-source encyclopedia of corporate
post-exploitation.
There is a growing community around the project and more info keeps being added
to it.
[Check out
this post
by @LikeTheCoins if you want to know more]
Digital networking is already widespread in many areas of life. In the
healthcare industry, a clear trend towards networked devices is noticeable, so
that the number of high-tech medical devices in hospitals is steadily
increasing.
In this blog post, we want to elucidate a vulnerability we identified during the
security assessment of a patient monitor. The device sends HL7 v2.x messages,
such as observation results to HL7 v2.x capable electronic medical record (EMR)
systems. A user with malicious intent can tamper these messages. As HL7 v2.x is
a common medical communication standard, we also want to present how this kind
of vulnerability may be mitigated. The assessment was part of the BSI project
ManiMed, which we would like to present in the following section.
Nowadays, Bluetooth is an integral part of mobile devices. Smartphones
interconnect with smartwatches and wireless headphones. By default, most devices
are configured to accept Bluetooth connections from any
nearby unauthenticated device. Bluetooth packets are processed by the Bluetooth
chip (also called a controller), and then passed to the host (Android, Linux,
etc.). Both, the firmware on the chip and the host Bluetooth subsystem, are a
target for Remote Code Execution (RCE) attacks.
With the current situation, it’s not easy to find the right angle to start this
blog post, so I won’t even try… but with Troopers cancelled, my Bloodhound
workshop went down the drain, and I didn’t get a chance to meet or catch up with
all of you and share my latest BloodHound adventures. So I decided to write a
quick post to share all this…
As you might have heard, BloodHound 3 was released last month, so I thought it
was time to update the Dog Whisperers Handbook.
It’s basically a quick intro to BloodHound and Cypher, with a lot of links to
resources for further learning.
You can download the latest version
here. Hope you enjoy it.
We recently came across an issue when playing around with VMware NSX-T which not
anyone might be aware of when getting started with it. Because many of our
customers start with transitioning to NSX-T, we want to share this with you. In
short, the Distributed Firewall (DFW) of NSX-T can be easily bypassed in the
default configuration because it only works effectively if at the same time, the
SpoofGuard feature is enabled on all logical switch ports which is not the
case by default.
Lately, we came across a remote code execution in a Tomcat web service by
utilizing
Expression Language.
The vulnerable POST body field expected a number. When sending ${1+2} instead,
the web site included a Java error message about a failed conversion to
java.lang.Long from java.lang.String with value "3".
From that error message we learned a couple of things:
The application uses Java
We are able to execute EL expressions
Output from the EL engine is always returned as String
Whenever you are able to execute code within a Java Context, the most
interesting part is to check whether we can get a Runtime object and execute
arbitrary OS commands.
Attackers are everywhere. They are now on the cloud too! Attacking the most
popular cloud provider – AWS, requires the knowledge of how different services
are setup, what defences do we need to bypass, what service attributes can be
abused, where can information be leaked, how do I escalate privileges, what
about monitoring solutions that may be present in the environment and so on! We
try to answer these questions in our intense, hands-on scenario driven training
on attacking and subsequently defending against the attacks on AWS.
On November 3rd, 2019, we have reported a critical vulnerability affecting the
Android Bluetooth subsystem. This vulnerability has been assigned
CVE-2020-0022
and was now patched in the
latest security patch
from February 2020. The security impact is as follows:
On Android 8.0 to 9.0, a remote attacker within proximity can silently execute
arbitrary code with the privileges of the Bluetooth daemon as long as
Bluetooth is enabled. No user interaction is required and only the Bluetooth
MAC address of the target devices has to be known. For some devices, the
Bluetooth MAC address can be deduced from the WiFi MAC address. This
vulnerability can lead to theft of personal data and could potentially be used
to spread malware (Short-Distance Worm).
On Android 10, this vulnerability is not exploitable for technical reasons and
only results in a crash of the Bluetooth daemon.
Android versions even older than 8.0 might also be affected but we have not
evaluated the impact.
Users are strongly advised to install the latest available security patch from
February 2020. If you have no patch available yet or your device is not
supported anymore, you can try to mitigate the impact by some generic behavior
rules:
Did you know that in the ever evolving field of Web and Desktop apps, it turns
out these can all now be powered with JavaScript? You read that right:
JavaScript is now used to power both web apps (Node.js) as well as Desktop apps
(Electron). What could possibly go wrong?
So, the burning question is: how does this affect Web and Desktop app security?
If you want to find out, come to our training and you will experience this in a
100% hands-on fashion! 🙂
Once again, we are super excited to announce that Blackhoodie is happening at
Troopers 2020. This is the 3rd time that Blackhoodie is joining with Troopers.
As always, one of the main motivation for Blackhoodie is bringing more women
into reversing and other core security topics. So we would like to see more
women apply to the training slots. However, if you are not a woman and still
feel really excited about Blackhoodie, you are welcome to apply. The
registration is open now. Please hurry up and make your registration now. We
will close the registration once the seats are filled up with enough quality
submissions. We do have a very limited number of seats at this training site. So
we apologize in advance if we can’t accommodate everyone, even though we wish we
could!