On Saturday, April 26 Microsoft announced that Internet Explorer version 6 until version 11 is under potential risk against drive-by attacks from malicious websites, regardless of the underlying Microsoft operating system and the associated memory protection features integrated with the operating system. Microsoft has assigned CVE-2014-1776 to this unknown use-after-free vulnerability, which in the worst case could allow remote code execution if a user views a specially crafted website. If an attacker successfully exploits this vulnerability, s/he will gain the same rights and privileges as the current user (once again, activated User Account Control [UAC] helps keeping privileges of the user low).
Continue reading Continue readingASCII Protocol Scheme Generator
As we historically have a strong connection to network technologies (not surprising, given the “NW” in “ERNW” stands for “Networks”), I developed a small script to create RFC-style ASCII representations of protocol schemes. The following listing shows an example created for a fictitious protocol:
0 1 2 3
0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1
+---------------------------------------------------------------+
| type | id |
+---------------------------------------------------------------+
| flags | reserved |
+---------------------------------------------------------------+
| payload |
+---------------------------------------------------------------+
Continue reading Continue reading
Bruting Android Pins
Hi there,
a few weeks ago I held a talk at UnFUCK, a small University con from students for students. I had decided to give a short talk on “Owning Stuff via USB” aka how to use our TR14 Badge! During the preparations and while building my demos, I tested my new USB RubberDucky. One rather “trivial” demo was actually to use it as a keyboard on an Android phone.
Android has been able to use the
USB OTG features for
quite a while now, where most people enjoy being able to connect a USB stick to
a phone, some others might have already used a keyboard on a tablet. OTG enables
a USB device to play master and hence connect two USB devices to each other. For
this the fifth PIN on a micro USB cable is used (it’s simply pulled down to
ground). To be able to use USB OTG you both need a special cable (micro USB to
female USB A) and a master device with all the necessary drivers. Depending on
the Android device and the client (USB stick/HDD, keyboard) you want to connect
you might need a rooted phone.When trying the RubberDucky on Android for the
first time, I had a S3, a Nexus 4, a Nexus 5 and an SE Xperia Z1. All of these
devices detected the Ducky as a keyboard and I was able to write stuff on the
phone. But I hadn’t aimed at “just typing text”, I wanted to type numbers or
rather PINs –> One can use the external keyboard while unlocking the device.
The Ducky’s user guide contains an example script for bruteforcing PINs on
Android. But how?
Just type!
Hackito Ergo Sum 2014
Greetings from Heidelberg to Paris,
and thanks for a great time at HES14! A nice venue (a museum), sweet talks and stacks of spirit carried us through the three day con. It all set off with a keynote byTROOPERs veteran Edmond ‘bigezy’ Rogers, who stuck to a quite simple principle: “People do stupid things” and I guess every single one of you has quite a few examples for that on offer. Next to every speaker referenced that statement at some point during her/his talk. Furthermore we presented an updated version of our talk LTE vs. Darwin, covering our research of security in LTE networks and potential upcoming problems.
Continue reading Continue readingA TROOPER’s Keyboard, part2
Greetings fellow TROOPERs,
TROOPERS14 has come to an end, and it’s finally time to let you have a go at the Badge’s source code. As promised, it was slightly modified and extended, to show you the full potential of your new gadget. I’ve added some nice payloads from Nikhil Mittal and a few own ones. Above that, for those who took their parts for soldering home, I’ve also added a few quick instructions on how to do the soldering.
Continue reading Continue readingA TROOPER’s Keyboard
Greetings from the Print Media Academy in Heidelberg. Just in time for TROOPERS14, I’ve got the great honor to present this years badge!
Being a TROOPER is tough: You need to know loads of information, learn even more and be able to work fast.
This year we decided to increase your efficiency and speed when collecting data from computer systems and, let’s say, hacking them! Your newest gadget is based on a plain Arduino Leonardo, modded with one of our famous shields. After adding a few LEDs and buttons, it will power up to full functionality.
Continue reading Continue readingHow to Own a Router – Fritz!Box AVM Vulnerability Analysis
The below post was originally written on February 9th as a little educational exercise & follow-up to my BinDiff post. (This research was actually triggered by a relative asking about that strange Fritz!Box vulnerability he heard about on the radio). Once we realized the full potential of the bug we decided against publishing the post and contacted several parties instead. Amongst others this contributed to the German BSI press release. Given the cat is out of the bag now anyway, we see no reason to hold it back. We will further take this as an opportunity to lay out our basic vulnerability disclosure principles in a future post. This topic will also be discussed in the panel “Ethics of Security Work & Research” at Troopers
Continue reading Continue readingHow to use Intel AMT and have some fun with Mainboards
I recently got in contact with
Intel AMT
for the first time. Surely I had heard about it, knew it was “dangerous”, it was
kind of exploitable and had to be deactivated. But I hadn’t actually seen it
myself. Well, now I have, and I simply love it and you will probably, too (and
don’t forget: love and hate are very very close to each other 😉 )
The following blogpost will be a set of features and instructions on how to own
a device with an unconfigured copy of Intel AMT without using any complicated
hacks or the famous magic!
The Three Billion Dollar App – Some Notes on My Upcoming Troopers Talk
This is a guest post from Vladimir Wolstencroft from our friends of
aura information security
==================================================================
Mobile messaging applications have been occupying people’s attention and it seems to be all the latest news. Perhaps I should have called my presentation the 19 Billion dollar app but at the time of writing and research I thought the proposed 3 Billion dollar amount for SnapChat was a little ludicrous, who could have known that would have been just a drop in the ocean.
Continue reading Continue readingA Short Teaser on My New IPv6 Testing Framework
This is a guest post from Antonios Atlasis
Hi,
my name is Antonios and I am an independent IT Security Researcher from Greece. One of my latest “hobbies” is IPv6 and its potential insecurities so, please let me talk to you about my latest experience on this.
This week, I had the opportunity to work together with the ERNW guys at their premises. They had built an IPv6 lab that included several commercial IPv6 security devices (firewalls, IDS/IPS and some high-end switches) and they kindly offered their lab to me to play with (thank you guys 🙂 – I always liked …expensive toys). The goal of this co-operation was two-fold: First, to test my new (not yet released) IPv6 pen-testing tool and secondly, to try to find out any IPv6-related security or operational issues on these devices (after all, they all claim that they are “IPv6-Ready”, right?).
Continue reading Continue reading