At Troopers 2023, we gave a talk on how to attack DHL parcel tracking
information based on OSINT. Since we previously had an exemplary disclosure
process about this attack with DHL, Mr. Kiehne (from DHL) joined us to provide
interesting background information and insights on how they addressed our
findings.
We want to thank DHL and especially Mr. Kiehne for sharing those insights with
us at Troopers 2023. It is the ideal case, but still not common that
organizations talk openly about their actions and views on a disclosure process.
In symmetric-key cryptography, we typically distinguish two types of encryption
schemes: block ciphers and stream ciphers. Block ciphers divide a plaintext into
blocks of a fixed size (e.g., 64 or 128 bits) and encrypt one such block of data
as a whole. Stream ciphers, on the other hand, consider the plaintext as a
continuous stream of data. The stream cipher maintains an internal state and in
each step it outputs one bit or several bits and updates its internal state. The
output bit stream is then combined with the plaintext, usually using the XOR
operation. One advantage of stream ciphers is that their resource requirements
are lower than those of block ciphers in many application scenarios. This makes
them particularly useful in lightweight cryptography targeting resource
constrained devices such as low-cost RFID tags.
During the past year we had several projects where our target application used
Jasper Reports in some way. In a few of the
cases we found an API that offered to render a template along with some
arguments into a PDF file. This was done with the help of the Jasper Reports
Java library. Due to the way the library and the expression mechanism works,
this endpoint gave us the possibility to inject Java code and gain remote code
execution on the target systems.
The IMF Conference is the International Conference on IT Security Incident
Management & IT Forensics. This year it took place from May 23 to 24 in Munich.
The schedule lists
a lot of interesting talks.
One of the talks was my presentation on a paper about Ceph forensics, based on
my Master Thesis:
The concept of Software Defined Storage (SDS) has become very popular over the
last few years. It is used in public, private, and hybrid clouds to store
enterprise, private, and other kinds of data. Ceph is an
open-source software that implements an SDS stack.
In this blog post, we are sharing summaries of talks from the Hack in the Box
Conference in Amsterdam (HITBSecConf2023), the final HITB conference in
Amsterdam. Before we do that, however, we would like to extend a heartfelt thank
you to the organizers of the conference for putting together such an insightful
and engaging event.
Dr. Bramwell Brizendine – Windows Syscalls in Shellcode: Advanced Techniques for Malicious Functionality
The talk by Bramwell Brizendine covered the topic of syscall usage in shell
code. The general idea here is to hide from AV/EDR systems by not using APIs
such as CreateProcessA, which may be monitored, but to directly call into the
corresponding kernel functions. This can be accomplished for example with the
syscall CPU instruction (see 1, 2 and 3 for more information). While
this technique is not perfectly stealthy and can still be detected (e.g., with a
kernel driver), it circumvents at least inline-hooks in user space. Another
downside is the effort of building shell code that directly uses syscalls.
Besides more overhead in preparing everything for the syscall (for example
manually creating appropriate structs), the correct syscall ID must be gathered,
which can change between kernel versions.
I am going to disclose two bug classes I found a while ago in CheckPoint R77.30:
Two buffer overflows in the username (no shit) and HTTP method of a request to
the administrative UI pre-auth and some interesting injections into the TCL web
interface.
Let’s start with the TCL part. The web interface reacted pretty weird when a
payload contained a colon. Diving deeper into this it became clear that a colon
would actually cause an error from the TCL interpreter. By going down this
rabbit hole and learning some TCL (:D) you could see that injecting a colon
breaks some part of the application code, probably because colons are control
characters in TCL e.g. preceding a global variable in TCL (::MyVar) or
separating namespaces.
Process Hollowing is a technique used by various malware families (such as
FormBook, TrickBot and Agent Tesla) to hide their malicious code within a benign
appearing process. The typical workflow for setting up such a
hollowed process is as
follows:
Create a new process (victim) using a benign executable, in suspended state.
Unmap the executable from that process.
Allocate memory for the malicious executable at the address of the
previously mapped victim executable.
Write the malicious executable to the new memory area and potentially apply
relocations.
Adjust the entry point.
Resume process.
We will refer to this as the “normal” Process Hollowing workflow. There are also
variants of this technique, one being to not unmap the original executable and
to allocate the new memory somewhere else. We will call this one no-unmap. But
wait, why does malware not simply overwrite the existing executable but creates
a new memory area which stands out due to its characteristics? In this blog post
we will have a closer look at this overwrite approach but also on the no-unmap
method, their effects on analysis/detection tools and on some tricks to make the
detection harder. We are also releasing Proof of Concept implementations of all
mentioned tools/plugins (the links are at the end of this post).
Spymax is a mobile Remote Administration Tool (RAT) that enables an attacker to
control victims’ devices through an Android malware. Once the malware is
installed on a phone, the attacker can execute many attacks that highly impact
the confidentiality and integrity of the victim’s data, as well as the victim’s
privacy. It is powerful, widely available, and does not require root privileges
on the victim’s device. In this blogpost, I show the capabilities of this RAT
and analyze how its Android malware works.
Over the course of the last 2 years we performed vulnerability research on
several Endpoint Management & Monitoring Solutions. The results were already
partially presented in security advisories which were published on this blog
during the last two years. The advisories can be found here:
We also recently presented the results on
Troopers 2022.
Now the results have been published in a more in-depth manner in the form of a
technical whitepaper. The whitepaper can be found
here.