After seeing
Christopher’s post I
decided to create a proof using GNS3 and Virtualbox.
The aim is to perform the exact attacking using Antonios Atlasis’
Chiron tools and run a Wireshark packet
capture to prove the hop limit drops below 255.
The following topology is used in GNS3:
The
routers used are Cisco C372 and the machine labled Ubuntu is running 14.04 LTS
Ubuntu Desktop, default installation. F0/0 is on the right and F0/1 is on the
left.
Welcome back to the radare2 reversing tutorials. If you’ve missed the intro, you
can find it here.
The last time you got the challenge01 binary and your goal was to find the
password for the login. Let’s see how the application looks like:
$ ./challenge01
##################################
# Challenge 1 #
# #
# (c) 2016 Timo Schmid #
##################################
Enter Password: test
Wrong!
The first and simplest step would be to look for strings inside the binary. We
could do this either by using the unix utility strings or the binary analyzing
binary from radare rabin2:
Just a few days ago I had a blast again at this year’s Black Hat. Some of the
talks were really worth listening to, so I wanted to point them out and give a
short summary.
They had the last slot at the last day of Black Hat which resulted in a kind of
empty room, but in my opinion it was an awesome talk and I even had the pleasure
to meet these two guys at our ERNW dinner.
In a recent assessment, we had to evaluate how Microsoft’s System Management
Server (SMS) certificate management solution (CMS) stores and handles
certificates. This question came up because sensitive, encrypted user
certificates were to be stored in the SMS CMS. Due to the sensitivity of the
handled certificates, we assessed the protection capabilities of the certificate
management solution against extraction attempts from a local attacker with
administrative privileges.
How did we do it?
We determined a five steps approach to gain access to the certificates and be
able to decrypt the accessed certificate material:
As some of you may know, there is a “new” reverse engineering toolkit out there
which tries to compete with IDA Pro in terms of reverse engineering. I’m talking
about radare2, a framework for reversing,
patching, debugging and exploiting.
It has large scripting capabilities, runs on all major plattforms (Android,
GNU/Linux, [Net|Free|Open]BSD, iOS, OSX, QNX, w32, w64, Solaris, Haiku,
FirefoxOS and even on your pebble smartwatch 😉 ) and is free.
Most of you that are pentesters may have already tested plenty of webservices
using SOAP (Simple Object Access Protocol)* *for communication. Typically,
such SOAP messages are transferred over HTTP (Hypertext Transfer Protocol) and
are encapsulated in XML (*Extensible Markup Language*). Microsoft has developed
different representations of this protocols to reduce the network load. As these
representations/protocols aren’t really covered by typical tools out there, this
post will show you some of them, and a proxy which can be used to simplify the
testing.
I won’t be in Vegas for Black Hat this year as there’s a direct conflict with
one of my kids’ birthdays, but I thought one or another reader might find it
helpful to get some inspiration as for selecting the talks to catch (not least
as there’s so many interesting ones). I hence decided to quickly write this
post.
Here’s my would-be schedule for the first day (second day to follow, maybe, in
another post), under the assumption to attend exactly one talk per slot. I could
give a longer rationale per talk than the one below, based on several (mostly
technical) factors, but this is just about providing suggestions in a brief
form.
Disclaimer: I was on the
BH guest review board this year so
I might be biased in some cases.
this blog post is about Server Side Template Injections for the Apache
Freemarker Template Engine, how to detect them, how to craft an exploit and what
countermeasures can be implemented. Server Side Template Injections are critical
because they often allow even Remote Code Execution, like the exploit of Apache
OFBiz 13.07.03 that triggered this post in the first place. It is fair to note,
that the exploit of Apache OFBiz requires a valid session with the server, but
often this is just an inconvenience for an attacker.
Ever got a backdoor installed on your computer by your beloved mouse? Here’s the
story of a poor mouse that got really, really sick.
Agent “Danger Mouse”
Do you remember the times where people put Teensy-boards and USB hubs in their
mouses? [Chris? ;)] Their aim was to attach an additional
Human Interface Device
(HID, like keyboards or mouses) with some payload in kind of e.g. keystrokes or
mouse movements. Also, there are devices available like the USB Rubber Ducky in
the housing of a USB thumb drive.
The principle is easy: The tools are using a programmable microcontroller with
the capability to emulate USB HID. That’s it. Just program your board of choice
with the payload fitting your needs and plug it in at the target computer. The
latter will recognize it as a keyboard/mouse and the payload-keystrokes will be
entered.
But why should external hardware be used? Many modern gaming peripherals provide
functions to store macros on them, including enough onboard memory for little
payloads.
In the context of a customer project, we examined a new variant of the Locky
ransomware. As in the meantime stated by a law enforcement agency, this has been
part of a large wave of attacks hitting various enterprises in the night from
Tuesday (2016-07-26) to Wednesday.
As an initial attack vector, the attackers use emails with an attachment that
probably even uses a 0day exploit, that enables the payload to be executed
already when displayed in the MS Outlook preview.