Showing posts with label Hacking. Show all posts
Showing posts with label Hacking. Show all posts

Thursday, May 21, 2015

Security & Hacking: Android Factory Reset Failures

A somber research paper, "Security Analysis of Android Factory Resets" by Laurent Simon & Ross Anderson, describes multiple security issues for many makes, models, and versions of Android phones.

These issues impact many Android phones, unfortunately there is no single simple solution, though the authors suggest multiple mitigations.

Three security issues that caught my attention:

"In general, we found that devices in our sample logically sanitised all  bytes  requested  through  the ioctl command,  except  for one phone: the Google Nexus 4. This has an 6189744128Bdata partition, fully used by the file system. The last 16KB were  not  sanitised  and  fully  recoverable  about  20%  of  the time after a Factory Reset."

"We  found emails in 80% of our sample devices, but generally only a few per device"

"We recovered Google tokens in all devices with flawed Factory Reset, and the  master token 80% of the time."

The last one, with Google tokens would allow attacker to synchronize email or other accounts.  Enabling access to the current account!  Not limited to old (historical) data recovered on the Android device in attacker's possession.

I strongly recommend reading Security Analysis of Android Factory Resets.









Friday, February 6, 2015

Security & Hacking: 2 Factor list

Useful page that maintains a list of websites, companies, etc that offer Two Factor Authentication (aka 2FA).

https://twofactorauth.org/

In addition to basic list, they also provide links to documentation for those that provide 2FA, they also offer Twitter links to ask companies to add Two Factor.

Additional Links:

For more Blog posts click on Two Factor Authentication, Hacking, or Security labels.  Labels can be found at bottom left of every blog post, selected labels can be found in Label Cloud at left side of blog.


Wednesday, January 21, 2015

Monday, December 22, 2014

Monday, October 6, 2014

Nerd News: "Silk Road Lawyers Poke Holes in FBI’s Story"

Brian Krebs has an interesting article up,  http://krebsonsecurity.com/2014/10/silk-road-lawyers-poke-holes-in-fbis-story/, about the trial of alleged leader of Silk Road.

Short version, government's explanation for how they found the hidden servers appears to be BS.

This seems like they are hiding real way & means that they discovered the information.

Which, though IANAL, isn't legal as I understand it, in US Trials, there is a step called "Discovery" see http://www.americanbar.org/groups/public_education/resources/law_related_education_network/how_courts_work/discovery.html & http://en.wikipedia.org/wiki/Civil_discovery_under_United_States_federal_law.

So unlike TV or Movie Courtroom drama, there isn't surprise evidence introduced in the middle of the trial.

There are several reasons why information isn't supposed to be hidden during Discovery.

Discovery reduces wasting time, Judges generally have more cases than they can get to in any given time period, so as a practical matter, parties are encouraged to settle before Court date.

It also reduces some types of false testimony & evidence, or at least makes it easier to illuminate that it is occurring.


Friday, September 19, 2014

Security & Hacking: Apple iOS 8 & Data Extraction

People have been citing a statement on this page http://www.apple.com/privacy/government-information-requests/ as proof that with iOS 8 Apple can't extract data from devices secured with a passcode.

I don't think most people are reading Apple's statement with a critical enough mindset, here is last part of what Apple actually wrote about data extraction:

"So it's not technically feasible for us to respond to government warrants for the extraction of this data from devices in their possession running iOS 8."

The key part is "extraction of this data from devices in their [government] possession running iOS 8." Note my bolded emphasis.

What Apple is really saying, I think, is just like iOS 7 Apple needs devices in their possession to extract data, they can't do it remotely and didn't provide government agencies with the tools to do so either.

Here is a snippet from Apple's page Legal Process Guidelines U.S. Law EnforcementImportant Note, the original link "https://www.apple.com/legal/more-resources/law-enforcement/" to this information at Apple gets redirected to "https://www.apple.com/privacy/government-information-requests/" now, so if you don't have a copy of original page you will need to find cached version to verify:
 " I. Extracting Data from Passcode Locked iOS Devices
 Upon receipt of a valid search warrant, Apple can extract certain categories of active data from passcode locked iOS devices. Specifically, the user generated active files on an iOS device that are contained in Apple’s native apps and for which the data is not encrypted using the passcode (“user generated active files”), can be extracted and provided to law enforcement on external media. Apple can perform this data extraction process on iOS devices running iOS 4 or more recent versions of iOS. Please note the only categories of user generated active files that can be provided to law enforcement, pursuant to a valid search warrant, are: SMS, photos, videos, contacts, audio recording, and call history. Apple cannot provide: email, calendar entries, or any third-party App data." 

And from the FAQ section of that page:
"Can Apple provide me with the passcode of an iOS device that is currently locked?
No, Apple does not have access to a user’s passcode but may be able to extract some data from a locked device with a valid search warrant as described in the Guidelines."
So what it seems like to me, is that iOS 8 offers at best same protection as earlier versions, Apple can still extract data from from devices in their possession, though they worked hard to write a factually accurate statement that was misleading.

I also haven't noticed any comments about data from the coprocessor that tracks movement and other data on iPhone 5S and newer, even when phone is sleeping.


Additional Links of Interests:

Monday, August 11, 2014

Def Con 21: "Pentesting with an Army of Low-power Low-cost Devices"





Couldn't go to Def Con 22, waiting for vods to come out, so started watching some of the Def Con 21 Youtubes in the meanwhile.

I like this one about Pen Testing with cheap Arm devices by Dr. Philip Polstra aka Dr. Phil the Hacker his Twitter is ppolstra | https://twitter.com/ppolstra.

He uses the BeagleBoard Black as the starting point for his hardware.

Some useful links:
For new readers of my blog, I have labels at bottom left of every post & selected labels at left side of the blog to help find related posts.

These labels can be booked marked so you can just check topics your interested in, so for more posts like this you could click on:

Security & Hacking: The Matasano Crypto Challenges

Really cool the Matasano Crypto Challenges is "a collection of 48 exercises that demonstrate attacks on real-world crypto."

It's designed to teach real Crypto attacks by doing, great for improving the security of code you write, or to get an idea of what Pen Testing or malicious hacking involves.

Very good review, worth reading in it's own right here https://blog.pinboard.in/2013/04/the_matasano_crypto_challenges/

Note in the Pinboard review the original link for Matasano Crypto Challenges  didn't update for server move, current working link (I have correct link at top of this blog post of mine as well) is http://web.archive.org/web/20140213141638/http://www.matasano.com/articles/crypto-challenges/

Wednesday, June 11, 2014

Security & Hacking: Windows Patch Tuesday Reminder

In case you forgot, yesterday was patch Tuesday for Windows.

Some critical fixes in this patch, for quick details on Patch Tuesdays I always recommend Brian Krebs posts http://krebsonsecurity.com/2014/06/adobe-microsoft-push-critical-security-fixes-4/

Thursday, May 29, 2014

Snowden responds to email NSA released via ICON

I Blogged here about supposedly only email NSA could find where Snowden seemed to be following procedure for complaints, concerns, & whistle blowing.

I had more than one sad chuckle reading Snowden's response at The Washington Post http://www.washingtonpost.com/world/national-security/edward-snowden-responds-to-release-of-e-mail-by-us-officials/2014/05/29/95137e1c-e781-11e3-afc6-a1dd9407abcf_story.html

Like I speculated in my previous blog post, Snowden realized the official system wasn't designed to correct problems.

He states that in the article linked above.

But more telling, he mentions another specific correspondence that they certainly have:

"Today’s release is incomplete, and does not include my correspondence with the Signals Intelligence Directorate’s Office of Compliance, which believed that a classified executive order could take precedence over an act of Congress, contradicting what was just published. It also did not include concerns about how indefensible collection activities - such as breaking into the back-haul communications of major US internet companies - are sometimes concealed under E.O. 12333 to avoid Congressional reporting requirements and regulations."

Source for quote same as link at top http://www.washingtonpost.com/world/national-security/edward-snowden-responds-to-release-of-e-mail-by-us-officials/2014/05/29/95137e1c-e781-11e3-afc6-a1dd9407abcf_story.html

Sure sounds to me like Snowden's focus is to bring accountability to NSA & other agencies under the DNI http://en.wikipedia.org/wiki/Director_of_National_Intelligence.

I'd also suggest reading http://www.emptywheel.net/2014/05/29/snowdens-emailed-question-addresses-one-abuse-revealed-by-his-leaks/

TrueCrypt Alternatives

Updated:  Wanted to add https://www.grc.com/misc/truecrypt/truecrypt.htm green shaded box (scroll down a little) shows correspondence from devs of Truecrypt.

TL:DR Confirms that this was just an odd way of quitting.


****

For the couple people that might have missed drama with TrueCrypt see http://krebsonsecurity.com/2014/05/true-goodbye-using-truecrypt-is-not-secure/

TL:DR Looks like people(s) behind TrueCrypt are done supporting it & suggest people use something else, additionally version released with this information only decrypts previously encrypted data, won't encrypt.

In light of this situation, many people are looking for alternatives, best list I have found so far, though I know very little about the suggestions, is http://www.ghacks.net/2014/05/29/list-truecrypt-encryption-alternatives/

Security & Hacking: NSA & Snowden email correspondence

http://icontherecord.tumblr.com/post/87218708448/edward-j-snowden-email-inquiry-to-the-nsa-office is link for most recently released email, released by NSA, of correspondence between Snowden & Office of General Counsel.

[Edited to add:  Strange that they released this email, they claimed Snowden's emails were exempt from FOIA & that they didn't have records, because he was never a NSA or CSS employee? see https://www.muckrock.com/foi/united-states-of-america-10/edward-snowden-employeecontractor-reviewsagreements-5971/]

He asks for some clarification about Executive Orders, that they are of lesser authority than Federal Statues.

In addition to the email, IC On The Record states that they can't find any other evidence that Snowden was trying to fix problems through official procedures or channels.

Based on this statement:
"There are numerous avenues that Mr. Snowden could have used to raise other concerns or whistleblower allegations. We have searched for additional indications of outreach from him in those areas and to date have not discovered any engagements related to his claims."
It seems clear they (Executive Branch of Government) are continuing to portray Snowden as someone who refused to follow correct procedures and just wanted some personal gain or revenge.

That doesn't fit the facts very well.

Consider that Snowden turned over the document collection to the reporters that he had decided to trust.  And refused to dictate the agenda.

He certainly could have released fewer documents, or only documents that targeted what he wanted revenge against, or even had sold the documents.

He didn't do that.

Funny thing is, many of the claims of government officials & politicians have repeatedly been proven to be false by the documents released so far.

Not to mention court cases that had been denied because standing couldn't be proved until documents Snowden released were published by reporters.  Or in other words, Snowden enabled Courts to actually provide a check on Executive branch of government, including NSA, like they are supposed to do.

More on US Seperation of Powers:


More on IC On The Record, according to info on their site http://icontherecord.tumblr.com/post/58838654347/welcome-to-ic-on-the-recordCreated at the direction of the President of the United States, IC ON THE RECORD provides immediate, ongoing and direct access to factual information related to the lawful foreign surveillance activities carried out by the U.S. Intelligence Community

Despite that data, some still try to claim Snowden did this for fame/notoriety or out of spite.

I suppose that is possible based on the evidence we have so far, but it doesn't seem targeted, or focused, with that as a primary goal.

Also based on the pattern of denials by Government, followed by documentation that prove those denials false, I wouldn't be surprised if eventually, documentation surfaces showing that Snowden did attempt to resolve at least some issues through official means.

Need to remember that Snowden seems smart, one of the most frequent comments from people that meet him.

Note smart people tend to learn quickly, I doubt it would have taken many failures to fix things through official means for Snowden to realize the official means were designed to maintain status quo, not fix things.

Being a smart nerd, he would have then searched for some way to fix that problem.


Thursday, May 8, 2014

Security & Hacking: DEFCON 20 "Can You Track Me Now?"



DEFCON 20: Can You Track Me Now? Government And Corporate Surveillance Of Mobile Geo-Location Data

This was posted on Youtube November 22, 2012, so was well before Snowden release of information in May of 2013.

Main emphasis of this talk was tracking of cell phones.

But Christopher Soghoian briefly covers, at 31:05, that both Android (Google) & iOS (Apple) device encryption can be defeated by Google & Apple respectively.

This is a service they provide for Law Enforcement & other Government agencies.

Google can force a password reset for Android device, they don't require physical access.

Apple appears to use what Soghoian calls a "Master Skeleton key," they require departments to provide actual device (ie physical access).  They then provide unencrypted data on a CD, while device remains encrypted.

I wonder if they might actually need device to decrypt data with way devices since iPhone 4S & iPad 2 have been designed (they have hardware based encryption).

Entire video is worth watching, though it is rather long, they joke about having 3 different audience during the course of the talk.
 



Monday, May 5, 2014

Pen Testing: Pwnie Express new Nexus 5 based phone

1/13/15 Updated link to software download page due to changes on Pwnie Express site: new link to download page, confusingly labelled IMHO "Community" is  https://www.pwnieexpress.com/community/

XXXXXXX


Pwnie Express is a pretty awesome company, https://www.pwnieexpress.com/, you have probably heard of their Pwn Plug even if you don't recognize the company's name.

They have a new Pen Testing phone out called:  Pwn Phone 2014

Product link https://www.pwnieexpress.com/penetration-testing-vulnerability-assessment-products/sensors/pwn-phone-2014-penetration-testing-phone/

They aren't cheap, but Pwnie Express also provides free downloads for the entire software suite they use in their products.

It usually take a little time for new product's software to be added, but they already have software for 2014 Pwn Pad, Nexus 7 based, available.

Download [Updated link 1/13/15] https://www.pwnieexpress.com/community/ if you want to use your existing Nexus 7, they should have the Nexus 5 download available in near future as well.

The downloads for DIY are listed under "Community Editions & Legacy Product Downloads"

If I can find the time this week, I will also track down current hardware accessories they offer, & update this post or make post dealing with accessories.

Meanwhile you can view hardware accessories I listed for the 2013 Pwn Pad http://cliffsesportcorner.blogspot.com/2013/02/pen-testing-pwn-pad-by-pwnie-express.html.

Probably newer options available for some of those products, but those should work.

Just click following labels for more blog posts on Pwnie Express or Pen Testing, labels can be found at bottom left of every blog post, easy way to find similar or related content.

Select labels can also be found in label cloud at left side of Blog.

Friday, March 21, 2014

Security & Hacking: Ars article "Ancient Linux Servers"

Ars article "Ancient Linux Servers" http://arstechnica.com/security/2014/03/ancient-linux-servers-the-blighted-slum-houses-of-the-internet/, worth reading.

They reference Cisco blog post http://blogs.cisco.com/security/mass-compromise-of-the-obsolete/

In addition to the articles, I found many of the comments on the Ars article worth reading, though I suggest reading all of them, I have quoted a few of the best ones IMVHO.

Note I use brackets [] to indicate comments or links I have have inserted in original quote:

"Not updating systems is bad practice that too many admins still go by. When I came onboard with my current employer it took a great culture shift to get everybody to understand why security updates are so important. One year later and are update cycle is nearly perfected.

There is no excuse for this anymore. Virtualize your servers, snapshot VMs before making changes, update and revert if a problem occurs. Clone a VM and build a test environment to check before doing it in production. For every excuse there are established best practices and mitigation techniques to deal with them.
"
~http://arstechnica.com/security/2014/03/ancient-linux-servers-the-blighted-slum-houses-of-the-internet/?comments=1&post=26483315#comment-26483315

"I'm a Linux fan. Glad its around.

But, Linux made lots of headway as a cheap secure alternative to Microsoft. If I had a penny for every time someone said, "We'll be fine, it's a Linux box we're deploying on the internet and not a Microsoft server" ....

The thing is, like the Mac, Linux has been viewed as bulletproof. In 2007, I was working through the SANS 560 course and we utilized a publicly available kernel exploit for 2.6 to gain root. It was beautiful, just compile, run and BOOM, you were root. Linux was never bulletproof.

This is simply more (unnecessary) evidence that when we decide a platform is secure, we become complacent and end up in this situation. Anything with software should be treated as vulnerable as long as it has power and network connectivity.
"
~http://arstechnica.com/security/2014/03/ancient-linux-servers-the-blighted-slum-houses-of-the-internet/?comments=1&post=26483323#comment-26483323

SunnyD posted:
"Here's the problem when it comes to updating infrastructure systems like these for system administrators:

It's not a matter of security, it's a matter of "If it ain't broke, don't you even dare try to fix it."

If history as sysadmins has taught us nothing it's that the constant cycle of updates, especially on mission-critical machines, puts our job security on the lines. Especially when a lot of these machines are running custom code with dependencies that end up being the very security liabilities that get patched.
"
~http://arstechnica.com/security/2014/03/ancient-linux-servers-the-blighted-slum-houses-of-the-internet/?comments=1&post=26483235#comment-26483235

Responding directly to SunnyD's comment:

There is a concept for this, it's called "technical debt"[Cliff: Wikipedia Technical Debt]. I'm not saying it's any one person's fault, but it is a flawed system. Keeping pushing off the problem until you're painted into a corner."
~http://arstechnica.com/security/2014/03/ancient-linux-servers-the-blighted-slum-houses-of-the-internet/?comments=1&post=26483329#comment-26483329

There are also many comments from people that cover some of the real world limitations with implementing the best practices.

Though I am a long way from being an expert on computer & internet security, at best I'd consider myself an apprentice.

I think these exploits & the comments quoted above clearly illustrate that Linux has vulnerabilities like any OS, something I have been certain was true for some time.

But still felt troubled when I would see the oft repeated "Linux is more secure".

That always felt like simple security through obscurity, which we know is no security at all.

There are certainly different tradeoffs between operating systems, not sure more can be objectively claimed.

Except perhaps, that certain OS tend to be better fit for certain types of applications, but IMO that is just a restatement of the differing tradeoffs.

Should also be realized that smart hackers can certainly look at Best Practices as a starting point for attacks, so defenders certainly should as well.

Some Best Practices resources:

Tuesday, March 18, 2014

Security & Hacking: Windigo compromises 25+ thousand Unix & Linux servers

Detailed report for experts  http://www.welivesecurity.com/wp-content/uploads/2014/03/operation_windigo.pdf

More general audience article http://arstechnica.com/security/2014/03/10000-linux-servers-hit-by-malware-serving-tsunami-of-spam-and-exploits/

As anyone who is seriously into Computer Security or Hacking knows, it really doesn't matter what OS your running, they are all vulnerable to attacks.

Though staying patched & updated are critical regardless of OS, funny (scary) tidbit from the pdf was a few people browsing net with Windows 98, and at least one on Windows 95!

EEK!

Not that old is bad, but generally old means not maintained.


Tuesday, February 25, 2014

Apple releases Security patch for OS X vulnerability

Apple released security patch for OS X few hours ago

Link to Apple statement about patch http://support.apple.com/kb/HT6150

My understanding is the big problem, that was shared with iOS [see iOS 7.0.6 SSL/TLS problem for more on iOS issue ] only affected Mavericks, though I could certainly be in error on that, and this patch fixes more than that single issue.

Links to media comments about patch:



Saturday, February 22, 2014

Tuesday, November 12, 2013

Nerd News: TorGuard VPN with Chutzpah


Amusing and interesting article on Ars (though 4chan party van meme is used incorrectly) http://arstechnica.com/security/2013/11/how-one-site-beat-back-botnets-spammers-and-the-4chan-party-van/ about TorGuard, a VPN provider, http://torguard.net/.

Full disclosure:  I have not received any monetary or other compensation from TorGuard, though I am certainly interested in such, since I really admire their Chutzpah!

http://en.wikipedia.org/wiki/Chutzpah

Thursday, October 24, 2013

Security & Hacking: Xavier de Carné's "How I compiled TrueCrypt 7.1a for Win32 and matched the official binaries"

Good paper https://madiba.encs.concordia.ca/~x_decarn/truecrypt-binaries-analysis/ by Xavier de Carné (Twitter @xavier2dc or https://twitter.com/xavier2dc).

If your unfamiliar with the concerns about TrueCrypt, Xavier's "Challenges and implications" section concisely outlines those concerns.

Including the IsTrueCryptAuditedYet? project http://istruecryptauditedyet.com/ which I have blogged http://cliffsesportcorner.blogspot.com/2013/10/psa-truecrypt-audit-project.html

To see all my post on TrueCrypt, or to bookmark to easily check for new posts, click on the Truecrypt label.

Labels can be found at bottom left of every blog post and in Label cloud at left side of Blog.

Additional links from Xavier de Carné's paper: