A cute byproduct of the .Net framework rootkit development that has been going on is a new little child called 'frameSafe'. The first ever (to my knowledge) framework rootkit detection kit. Currently, no research for identification is being done (but the .Net sploit packages will be detected). The base idea is to secure the set of libraries needed for the tool to run by resigning them and including them in the release (this prevents the framework based tool from being injected). Next, the tool hashes a known good set of framework dlls (prior to distribution to the world (this is the inhouse step)).
Once those .Net Framework dll's are hashed and signed, the hashes are then placed in a descriptive manifest along with dll version number, and whether or not a native DLL should exist in the non JIT native images location. The ILASM output of the dll is also hashed and signed into this manifest. Now we have a hashed/signed snapshot of the framework assemblies and layout. The tool can then be used to scan for changes in the framework, and if detected - do a comparison of the current IL and the stored(good) IL. This will get us a snippet of ASM that can help us in determining the version of a specific infection (within reason).
So that's it, expect a release of the first version to sourceforge in a week or so.
Monday, September 28, 2009
Sunday, September 6, 2009
WCF Raping, teh fun and teh Glory
WCF getting pushed like crack in a schoolyard? Yes... How secure is it? Well, don't you know? Of course not... nobody fucking does... lets take a look, shall we....
So .net-sploit 1.0 has shown us the beauty of RootKits for the managed .net framework. It is possible to modify the .Net Framework in such a way that a managed code rookit can be hiddenly indefinately from detection (until the framework is completely ripped/reinstalled). Knowing this, we can begin to attack the WCF stack from a code- injection standpoint for affected systems with the assurance (within reason) of permanent residence. To assure our unilateral attendance period goes unnoticed, calling back home...etc from and infected PC may not be the smartest choice. Sometimes, you just want the infect PC's to give up some goodies without you having to ask too much from system. Therein lies the principle of the MITM (Man In The Middle Attack) attack. You are not part of the affected stack, but you are part of the communication stream. A WCF 'from the wire alone' sniffing is what I am working at... Kerberos is what I am fighting against for the secure streams. Maybe... just maybe... I can infect a PC with something that forcefully downgrades a Kerberos session to say something like... o, I dunno... NTLM. That would suck, especially if you noted things like 'Only use kerberos' in the configuration of all endpoints to ensure this 3rd party MITM attack doesn't occurr...
Only if....well, that WAS true.
The first attack I am using is a design flaw in how WCF secures its communications. To prevent MITM attacks on the WCF transport stacks, the transport sessions rely upon Kerberos encryption to ensure a 3rd party isn't checking in. I am not He-Man, nor do I aspire to wield an unstoppable sword, but I can infect any PC in the communication stream (client or server) via an exploit (if no auth exists) - better if I pick up creds and attack, but a bootstrapping bot bit of shellcode and some IL tricks, and then my resident rootkit can perform a bit of magic to the SPN fields of any Kerberos call. These calls verify the hosts you are speaking to are not spoofed, however, we can 'in an encapsulated layer' automagically downgrade from Kerberos to NTLM auth and hashing without notice to any parent layers on either client or server. This works, I have a POC in hand.
Now the MITM is possible to occurr, and do so in a MITM friendly environment outside the realm of current RootKit detection technology. So this a a brief synopsis of where I am at (I can spoof a WCF server even when kerberos auth is turned on, without changing the endpoints).
There are a few things I am working out for all of this to be a success, but they simply only take time. If you are interested in getting some more information, or to get your SVN action going email me for more info. (like the code repository and such).
So .net-sploit 1.0 has shown us the beauty of RootKits for the managed .net framework. It is possible to modify the .Net Framework in such a way that a managed code rookit can be hiddenly indefinately from detection (until the framework is completely ripped/reinstalled). Knowing this, we can begin to attack the WCF stack from a code- injection standpoint for affected systems with the assurance (within reason) of permanent residence. To assure our unilateral attendance period goes unnoticed, calling back home...etc from and infected PC may not be the smartest choice. Sometimes, you just want the infect PC's to give up some goodies without you having to ask too much from system. Therein lies the principle of the MITM (Man In The Middle Attack) attack. You are not part of the affected stack, but you are part of the communication stream. A WCF 'from the wire alone' sniffing is what I am working at... Kerberos is what I am fighting against for the secure streams. Maybe... just maybe... I can infect a PC with something that forcefully downgrades a Kerberos session to say something like... o, I dunno... NTLM. That would suck, especially if you noted things like 'Only use kerberos' in the configuration of all endpoints to ensure this 3rd party MITM attack doesn't occurr...
Only if....well, that WAS true.
The first attack I am using is a design flaw in how WCF secures its communications. To prevent MITM attacks on the WCF transport stacks, the transport sessions rely upon Kerberos encryption to ensure a 3rd party isn't checking in. I am not He-Man, nor do I aspire to wield an unstoppable sword, but I can infect any PC in the communication stream (client or server) via an exploit (if no auth exists) - better if I pick up creds and attack, but a bootstrapping bot bit of shellcode and some IL tricks, and then my resident rootkit can perform a bit of magic to the SPN fields of any Kerberos call. These calls verify the hosts you are speaking to are not spoofed, however, we can 'in an encapsulated layer' automagically downgrade from Kerberos to NTLM auth and hashing without notice to any parent layers on either client or server. This works, I have a POC in hand.
Now the MITM is possible to occurr, and do so in a MITM friendly environment outside the realm of current RootKit detection technology. So this a a brief synopsis of where I am at (I can spoof a WCF server even when kerberos auth is turned on, without changing the endpoints).
There are a few things I am working out for all of this to be a success, but they simply only take time. If you are interested in getting some more information, or to get your SVN action going email me for more info. (like the code repository and such).
Tuesday, August 25, 2009
DefCon 17 Errata
Alright, DC17 has come and gone. In it's wake many vendors cringed, or crumbled. It was a blast, sans the 110 degree temps, 0 percent humidity, and 2k ft elevation. 13 parties in 3 nights took its toll, man my ConFu needs practice.
This year I talked about a tool during the EFF speech I have been building called the Windows Services RapeKit. It is a nasty little package that discerns WCF and WebServices communication and provides an interface where you can play with these services during runtime from a remote machine.
Next year I will be doing a talk about the final build of the tool at the SkyTalks 09 and hopefully EFF again. I have to get with Pyro about the talks for next year... but stay tuned. A beta version of my tool will be ready for a community preview sometime in the end of September. Hopefully we can get the dc504 guys over this side of the lake to hit some beer on a Saturday for that release.
Meetings...
Well, alot of our folks are remote ATM or won't be always able to come in for Sunday meetings, but Saturdays may be free. Feel free to post some stuff on the forums if you have a better day and time than the last Saturday of the month.
This year I talked about a tool during the EFF speech I have been building called the Windows Services RapeKit. It is a nasty little package that discerns WCF and WebServices communication and provides an interface where you can play with these services during runtime from a remote machine.
Next year I will be doing a talk about the final build of the tool at the SkyTalks 09 and hopefully EFF again. I have to get with Pyro about the talks for next year... but stay tuned. A beta version of my tool will be ready for a community preview sometime in the end of September. Hopefully we can get the dc504 guys over this side of the lake to hit some beer on a Saturday for that release.
Meetings...
Well, alot of our folks are remote ATM or won't be always able to come in for Sunday meetings, but Saturdays may be free. Feel free to post some stuff on the forums if you have a better day and time than the last Saturday of the month.
Thursday, June 18, 2009
Request for Contribution - Hacking Games
Want to test your hacking skillset? Want to test other's skillset? We are building a DC225 Challenge area that will have a multi-level online hacking game, as well as a place for you guys to post your own.
Login and post your comments here with what "challenge" idea's you may have, the types of games you would want to test/play, areas of competition that you may have in mind.
Be looking at Dc225.com for more info.
Login and post your comments here with what "challenge" idea's you may have, the types of games you would want to test/play, areas of competition that you may have in mind.
Be looking at Dc225.com for more info.
Saturday, May 23, 2009
A protocol of protocols. Hiding yourself in the noise...
Alright, so I have been involved in a lot of remoting++ (WCF Net.Tcp stack). I have also had a bit of rootkit development along with a taste of NIPDS/SIPDS evasion study.... the result was the bastard child of a rootkit and the [pick your agency] having a god like baby - using protocols as a systematic, pre-referenced structured table with return types. Create 8 endpoints and assign them for bit 0 - 7. Have them all report to a super-strucutre that responds to each received event from each of the hosts. Take their key value from the collection and generate a byte. Use that byte to call to a collection and get that key. Execute the delegate at that location (key=byte, value=delegate(C#) or function pointer(C)). The return type would be anticipate by a shared command table (SCT) which was bootstrap gen'd on build for that target. Instant, unstoppable - undetectable rootkit - or bullshit? And why?
Thursday, May 14, 2009
About DC225
What is DC225?
DC225 is the local DefCon group for Baton Rouge/Lafayette/Lake Charles. We accept anyone wanting to learn, and especially those wanting to share. School is always open here.
We meet every 3rd Sunday (click "Join/Members" at dc225.com to find out where) to discuss anything related to advancing technology and its understanding among group members (primary focus is on security - but that means that any other technical discipline more than likely applies... you aren't going to root someone on your own if you can't code...)
What we are not:
Script Kiddies
How is it run?
Its pretty fucking simple - we act as a group. If someone doesn't like something the group decides - no big deal, no one is forced to do anything. You can't get kicked out- no one has the authority (and I am sure no one would care enough anyway). You can be silenced on the forums for flaming, etc...
So why have it?
Most of us know one another, and need another reason to drink and talk shop - and I am sure everyone would like to learn a little con-fu every once in a while.
We will be arranging a group trip to DefCon 17 (Vegas) on July 29 - Aug 4. Rooms are 89 bucks a night and sleep 4 on the beds, and I am sure it could sleep a total somewhere around 16 if you use the bathtub :). Overall it is cheap - and one hell of a party.
DC225 is the local DefCon group for Baton Rouge/Lafayette/Lake Charles. We accept anyone wanting to learn, and especially those wanting to share. School is always open here.
We meet every 3rd Sunday (click "Join/Members" at dc225.com to find out where) to discuss anything related to advancing technology and its understanding among group members (primary focus is on security - but that means that any other technical discipline more than likely applies... you aren't going to root someone on your own if you can't code...)
What we are not:
Script Kiddies
How is it run?
Its pretty fucking simple - we act as a group. If someone doesn't like something the group decides - no big deal, no one is forced to do anything. You can't get kicked out- no one has the authority (and I am sure no one would care enough anyway). You can be silenced on the forums for flaming, etc...
So why have it?
Most of us know one another, and need another reason to drink and talk shop - and I am sure everyone would like to learn a little con-fu every once in a while.
We will be arranging a group trip to DefCon 17 (Vegas) on July 29 - Aug 4. Rooms are 89 bucks a night and sleep 4 on the beds, and I am sure it could sleep a total somewhere around 16 if you use the bathtub :). Overall it is cheap - and one hell of a party.
Subscribe to:
Posts (Atom)