I was at the hack.lu conference in Luxembourg this year and attended the fuzzing
workshop, held by René Freingruber from
SEC Consult. I have been curious about this topic
for some years now, but besides doing some manual fuzzing and web-fuzzing, I
never looked into the whole topic that much.
The workshop lasted for around four hours. Before the workshop started each
student got two VMs (Linux/Windows) where everything necessary was already set
up. The VMs included 23 exercises, with step-by-step explanations, source code
and exploits. René started out with an introduction to fuzzing, listing popular
fuzzers and showing an example on how to fuzz with
afl.
Matthias and I
had the pleasure to give a talk at the H2HC2018 in
São Paulo, Brazil about attacking VMware NSX. The talk is an introduction to
VMware NSX for security researchers, and it discusses possible attack vectors
including the management, controlling, and data exchange planes. We demonstrated
how to prepare a fuzzing and debugging setup for the ESXi kernel and the kernel
modules. It should be noted that Olli was also
supporting the research.
The slides can be found
here.
First day at hack.lu. Three of us kicked the conference
off with the ARM IoT Firmware Emulation workshop by
Saumil. The goal of this workshop was not
so much to write exploits or to pwn boxes but to learn how to build a beneficial
research environment by emulating the hardware of a Linux based IoT device to
run its firmware in order to run analysis and tests.
First step is to obtain the firmware. This could be done by dumping it directly
from the device or by downloading firmware images from the vendor. In order to
dump the firmware from the device one has to obtain access to the underlying
system which is usually done by finding the serial console on the hardware since
this one often exposes an unauthenticated root shell. I think there is enough
documentation online on how to identify and connect to a serial console so I
won’t cover the details here. It’s also covered in Saumil’s
slides
in detail. Having the bootup logs from this console will be helpful later
though. While talking about baud rates for the serial console Saumil made a
great pun I don’t want to withhold: “Most common is baud rate 115200. If you
find a console with baud rate 9600 you are in fact talking to an acoustic
coupler. That’s not an IoT device, it rather belongs to a museum.”
At this years ARES conference, Jonas Plum (Siemens) and me (Andreas Dewald, ERNW
Research GmbH) published a paper
about the forensic analysis of APFS, file system internals and presented
different methodologies for file recovery. We also publicly released a tool
implementing our presented approaches, called
afro (APFS file recovery).
APFS is the file system for Apple devices that is used by default on all current
iOS mobile devices, as well as macOS since High Sierra, and is thus currently
rolled out on a large number of devices. By using afro, we evaluated and
compared the different approaches amongst each other and identified the method
that so far delivers the best results and compared it to photorec. This showed
that AFRO outperforms photorec on the evaluated APFS dataset. In the
presentations of this research we were often asked if other tools like Blackbags
Blacklight do not already support this recovery process. So, we decided to
compare the file recovery capabilities of BlackLight and afro. We wanted to
compare afro to the sleuth kit as well, as at the DFRWS conference it was
discussed about
adding APFS Support to The Sleuthkit Framework,
but no implementations are public yet.
We recently identified security issues in the UNIFY OpenScape Desk Phone CP600
HFA software. We disclosed the vulnerabilities to Unify, as a fix is now
provided we want to give a brief overview of the vulnerability affecting the web
interface.
We were able to identify the following vulnerabilities in the Web interface of
the telephone:
Command Injection in Picture Delete function of OpenScape Desk Phone Webportal
Unauthenticated Arbitrary File Access in the OpenScape Desk Phone Webportal
Memory Corruption in the OpenScape Desk Phone Webservice
Missing Hardening of the OpenScape Desk Phone Webservice Binary
Cross Site Request Forgery Missing in the OpenScape Desk Phone Webservice
Inspiriert durch die erfolgreichen Round-Table-Diskussionen der
Troopers-Konferenz freuen wir uns, Ihnen heute mit dem Incident Analysis and
Digital Forensics Summit 2018, eine weitere Veranstaltung in einer Reihe zu
Trend-Themen im Bereich der IT-Sicherheit vorzustellen.
Die Veranstaltung beginnt am Morgen mit einem Eröffnungsvortrag von Thomas
Schreck (Chairman of the Board des internationalen CERT Verbunds FIRST), gefolgt
von Fallstudien und Vorträgen durch weitere Referenten aus der Industrie und
Strafverfolgung.
For those who never heard of Sitefinity before, it is an ASP.NET-based Web
Content Management System (WCMS), which is used to deploy and manage
applications as other CMS‘s do. A bitter quick glance at Sitefinity and its
advantages can be found in
this overview.
Delving into the core of this blog post, recently I had the opportunity to look
at Sitefinity WCMS in which I found two reflectedCross Site Scripting
(XSS)
(CVE-2018-17053 and CVE-2018-17056), a* stored
XSS*
(CVE-2018-17054)
and an arbitrary file upload
(CVE-2018-17055)
vulnerabilities.
Recently, I had some time to play around with HEVD
[1], an
extremly vulnerable Windows driver available for 32-bit and 64-bit systems.
Since exploits for all vulnerabilities of the 32-bit variant are publically
available, I was wondering why this is not the case for the 64-bit version,
especially for the pool corruption and UAF vulnerabilities.
After digging around a bit, it turned out that the reason is the following. HEVD
uses a “special” sized object which is improperly handled such that a
Use-After-Free vulnerability arises.
I have the pleasure to announce the Active Directory Security Summit 2018 at
13^(th). of November of 2018. The summit covers current Active Directory
security related topics such as challenging tasks of hybrid Active Directory
operations as well as new security best practices and some ‘evergreens’ – Admin
Tiering implementations (what about Exchange and DNS…??), ESAE operations etc.
😉
The primary objective of the Active Directory Security Summit is to bring
experts together:
A while ago, we had to scan a mass amount of IPs within a project for a
customer. While it’s feasible to read the whole output of a Nmap scan if you
have just a few alive hosts, this was not possible anymore for this mass amount
of systems. We’ve started with a
masscan to scan all 2^16 ports
of the IP ranges and wanted to perform a more precise analysis of the alive
hosts (which had responded to at least one SYN packet) with Nmap. The result of
this scan grew to nearly a hundred megabyte and we now had to do an analysis of
which ports we had to look deeper into and which are intended to be open.