This is a write-up about how to use Frida to dump
documents from a process after they have been loaded and decrypted. It’s a
generic and very effective approach demonstrated on a piece of software from
North Korea.
Some time ago we received an ISO file which was a dump of a CD-ROM from North
Korea. The only information we got was that it included a document viewer and
various PDF documents. I started to dump the content of the ISO in order to
analyze what the reader was actually doing by mounting it:
Python has reached a defacto standard in exploit development lifecycles and most
of the proof of concept tools you’ll find out there are written in Python
(besides the metasploit framework, which is written in Ruby). Python allows to
write scripts handling with remote services, fiddling with binary data and
interacting with C libraries (or Java in case of Jython/.Net in IronPython) in a
fast and easy way. The huge standard library with it’s “battery included”
principle removes some of the dependency hell known from other
frameworks/languages. I want to share some of my python coding experiences with
you, and maybe this could give some helpful tips for your future work, to make
the world a bit safer 🙂 (PS: most of the examples are written in Python 3.x or
compatible to both Python branches).
In the course of a recent penetration test, we came across an Image validation
vulnerability in Django when using the
Python-Imaging-Library (PIL) which we
want to explain in this post.
Everybody who doesn’t know what Django and/or
the PIL is:
Django is a framework to create web applications with Python (comparable to
Rails or Zend). The PIL is a powerful standard python library which provides a
toolset to modify, display and verify images of many different formats.
With HTML 5 the current web development moves from server side generated content
and layout to client side generated. Most of the so called HTML5 powered
websites use JavaScript and CSS for generating beautiful looking and responsive
user experiences. This ultimately leads to the point were developers want to
include or request third-party resources. Unfortunately all current browsers
prevent scripts to request external resources through a security feature called
the Same-Origin-Policy. This policy specifies that client side code could only
request resources from the domain being executed from. This means that a script
from example.com can not load a resource from google.com via
AJAX(XHR/XmlHttpRequest).
In a .NET environment WCF services can use the proprietary WCF binary XML
protocol described
here.
Microsoft uses this protocol to save some time parsing the transmitted XML data.
If you have to (pen-) test such services, it would be nice to read (and modify)
the communication between (for example) clients and servers. One possibility is
Fiddler.
Fiddler’s strengths include its extensibility and its WCF binary plugins. Sadly,
these plugins can only decode and display the binary content as XML text.
One of our favorite tools for conducting penetration tests (especially, but not
only, web application tests) is
Portswiggers’s Burp Suite. Burp
allows to extend its features by writing own plugins. But because Burp is
written in Java, it only supports Java classes as plugins. Additionally, Burp
only allows to use one plugin at the same time which has to be loaded on
start-up.
Now we have written a Burp-Python proxy (called pyBurp) which adds some
features to the plugin system: