Showing posts with label infiltrate. Show all posts
Showing posts with label infiltrate. Show all posts

Monday, March 18, 2013

WIN at CBC

I win at the demo-run of Immunity Web Hacking class today. Who want to try to be "superuser" ? 



Monday, March 4, 2013

Infiltrate Preview - Stephen Watt Keynote


A common public misconception is that "real punishment" begins and ends with a prison sentence, that a sentence of probation is little more than a strong warning, and that the period of probation that usually follows incarceration is something like a fast-scrolling trailer at the end of a two hour movie: a formality of a coda that can be easily dismissed.

Similarly, anybody who's grown up watching detective and courtroom dramas on TV can be forgiven for assuming that only a strong cache of incontrovertible evidence can seal a conviction. We're so used to hearing stories of criminals evading the law through technicalities like botched Miranda Rights readings and search warrants that we might expect any prosecutor must have an airtight case to prevent a sharp defense attorney from poking holes in it.

Unfortunately for the real-life defendant, these are often little more than legal myths. Lost in these assumptions is the understanding that a prison sentence of any length is sandwiched between a very costly pre-trial period and term of supervised release. Pre-trial is often characterized by a combination of unemployment and impossibly high legal expenses (going with the "free services" of a public defender is usually folly if not done as a last resort). The post-trial period can be remarkably restrictive, ensuring that a return to a former standard of living is nearly impossible until completion, all the while encouraging recidivism or re-incarceration for petty probation violations.

If all that sounds pretty daunting, imagine that you decide to take the road less traveled and be the rare defendant that does NOT cooperate with federal authorities (who by some tallies have a near-99% conviction rate), and rat out their friends. Confident in the fact that there can't possibly be a shred of hard forensic evidence showing you to be involved in any illegal activity, you remain scared and apprehensive, but reasonably certain of your ability to prevail in the face of any manufactured legal adversity...

... But. You're naive because you're not some career criminal and this is your first scrape with the law. Hell, you've never even had a lawyer before. A crash course in reality ensues. First, you learn about the government's favorite criminal fishing net: conspiracy. You learn that highly circumstantial evidence that merely links yourself to other co-defendants in close personal relationships can be used as "convincing" evidence of criminal involvement. You learn that as a member of a conspiracy, once you have engaged in the slightest possible activity to further that conspiracy, you are immediately and fully legally responsible for all the actions of every single other participant in the conspiracy.

You learn how charges in white collar criminal cases can easily be compounded so that now, as a first time offender, you're looking at a federal sentencing guideline of life in prison. You get a plea offer. It's capped at 5 years. You know you won't die in a cell if you go to trial and lose, but you have no idea what the intermediate compromise between 5 years and life might be. Could a guilty verdict mean 7 years? 10? How long will the trial take? How much money will it cost? If there's international co-defendants, will your trial be delayed until they're extradited?

Is a jury really a jury of your peers? Can they be trusted to decide your fate based on highly technical evidence that is beyond the understanding of the average person? A judge might be more intellectually capable of absorbing the facts, but is it worth risking a bias towards guilt that typically accompanies a lengthy career in jurisprudence? If IRC or instant messenger logs are part of the evidence, is there a possibility that sarcastic or jocular comments in no way related to criminal wrongdoing might poison judge or jury against the defendant? What is the likelihood that dark or sarcastic humor will be used against the criminal defendant to shore up the case? Or exaggeration of the implications or maliciousness of specific technical actions? Spoiler alert: It's very high, especially when the prosecutor assigned to your case is a notoriously dirty fighter with a body count attached to his name.

Fuck it. You're going to get locked up. It might take you a couple of years to get from the day federal law enforcement raided your home with riot gear and automatic weapons to the point where  you pass through a prison metal detector at intake. During that time, you will be fired, and you won't work. You won't be allowed to use a computer to work, and you won't even be allowed to use one to update your resume. But prison should be relaxed right? It's just a camp for white collar criminals.
Maybe. Maybe not. It's not impossible that you could end up 3,000 miles away from home in a concrete bunker with no windows to the outside world, or physical access outdoors. Or to a library. Or any educational services. Oh, and knee deep in child pornographers.

Even so, prison might be the most relaxing bit of your entire journey. At least in prison you know that there's nothing you can do to increase your net worth or help your family solve its generous share of personal problems. You couldn't begin the frustrating search for employment as a convicted felon even if you wanted to. So you kick back, gnaw on BOP-issued corn dogs, and read the Clive Cussler novels on the book cart.

It seems that by probation you should feel like you've made it to to the top of a giant hill, exhausted and relieved to be near exiting The System and going back to being an inconspicuous member of society. Now remember that because you didn't snitch on anybody, you've incurred the wrath of every authority figure involved in this entire process. A line of communication has been established from the investigators and prosecutors through the Bureau of Prisons and  all the way to the probation department. And your life will be made that much more difficult because you refused to compromise your integrity in order to make things "easier" for all parties involved.

Just like any other convicted felon, you'll find out what it's like to be treated like a pariah. If you're a skilled professional, your unsavory background will make you even less appealing to prospective employers. If you have a fine or restitution to pay back, you will start to do so while earning wages that are likely a fraction of your former level of compensation. And then there will be the question of technology. Wanna take videos of your cat to upload to Youtube? That might be difficult, depending on if and what kind of smartphone you're permitted to use. Very likely, you'll have government-selected malware installed on your laptop. It'll bring your system to a crawl, and you'll be forced to pay monthly fees for that privilege. You'll be using Windows only and since the nature of state-sponsored surveillance on probationers is completely opaque, what software you are or are not permitted to run is completely arbitrary. For the course of supervised release, you will struggle not only against a presumptive and unforgiving society, but a law enforcement agency that will not actively facilitate your reintegration into it.

This is my story, and in several ways it is the story of many others.

Perhaps more unique to my circumstances is how for 10 profitless hours of work helping a friend, I ended up indebted to the sum of almost $200 million, locked away from the light of day in federal prison for nearly two years.

I underwent court-advised psychiatric evaluation for suspected sociopathy because I liked quoting Fight Club. And a chunk of my life was flushed away because, in the words of my judge , I was to be made an example due to the high visibility of my case. Had I deliberately fashioned myself as a more sympathetic victim, perhaps my case would have prompted more public outrage. As we saw recently with Aaron Swartz, when the actions of litigators are left unchecked over the course of a career, the most aggressive legal measures will be undertaken lightly and with impunity, and can sometimes have tragic consequences.

There is an unspoken camaraderie that bonds all people who have seen themselves the targets of federal indictment. That realization first struck me when I saw my name listed as the adversary of my own country in the infamous "United States v." heading that graces the top of so many legal documents. Unfortunately, that rivalry neither begins nor ends in a court of law, and the case title itself is a scarlet letter that brands a convict until his dying days. Some have chosen the most final means possible to avoid this distinction. I wear this badge without shame, and stand to share my experience with others.

-- Stephen Watt

Monday, February 25, 2013

VisualSploit 2.0

Immunity is well known for its product base that is designed to help the lives and duties as network professionals, security auditors and penetration testers much easier.  However one of the lesser known features of CANVAS is VisualSploit.

VisualSploit is a learning utility that we created specifically for our popular Unethical Hacking training course that we conduct at INFILTRATE.

I have been an instructor of this course for a few years now so I have been in a position to see how a lot of people consume, assimilate and digest topics such as buffer overflows, memory corruption, debugging and assembly and the conclusion of this analysis is that these topics are best illustrated with simple, visual tools.  This way the students can walk away with a solid understanding of what happens before, during and after a buffer overflow.

VisualSploit is that simple, visual tool.  I decided to create VisualSploit v2.0 for a few reasons but topping the list is because I was paying close attention to how the tool could be improved to make sure the students got the most out of training and learning about these topics.

The new VisualSploit v2.0 web interface




During the Unethical Hacking course we teach you everything you need to know about assembly in order to write an exploit for buffer overflows.  With the help of VisualSploit you can literally go from analyzing the crash in Immunity Debugger to a working exploit/proof of concept in a matter of minutes because no programming is required.  VisualSploit behind the scenes just builds a CANVAS exploit for you which means that everything you build will be available to you as a regular exploit module the next time you start up CANVAS.  You're welcome.

This visual and hands-on method of teaching and learning about buffer overflows is very effective.  I have yet to encounter a student who didn't have that "ah-ha!" moment where it all clicked and they were able to finish writing the more challenging (and fun) exploits for real-world applications by the end of the course.

So come join me in April during the INFILTRATE edition of the Unethical Hacking class.  It will be fun and educational but more importantly you get to break stuff.

- @MarkWuergler


Friday, February 8, 2013

Infiltrate Preview - The Chameleon: A cellphone-based USB impersonator.

If you've ever been part of a Call For Papers committee you know that the information provided in the submission's abstract is generally vague and ambiguous. A talk could be a total Fail or THE talk that will define your conference and ensure it will return next year. That's why we ask for a draft version of the research and involve our technical team in asking questions and vetting submissions.

As an attendee of a conference you of course have to decide which conferences to attend. Immediate financial costs, scheduling time off, logistical details, these are all headache inducing aspects of going to a conference. You read a vague abstract on a conference website but you are not allowed to ask questions. You understand the Windows 8 heap, but does this presenter really know what they're talking about or will this be a waste of your time? In the past folks have had to base their attendance decision on how well the conference has been reviewed in the past (reviews which are sometimes are paid for by the organizers) and on speaker reputation (another criteria used by CFP committee).

At Infiltrate, we like you, heck we understand you because we've gone through that ourselves. So in order to change this annoying process in the infosec community, we're offering something different :). We are encouraging our selected speakers to be guest bloggers here, to provide more in depth information on their topics and to field questions.

The ball is now in your court, the shoe on your foot, the ace is in your sleeve. As an attendee you should take the time to research the subject and try to get the most out of each of each talk. We generally like to brag that our audience poses the most difficult questions to presenters, let's try to keep that up! Without further ado:




Matias Soler on:

The Chameleon: A cellphone-based USB impersonator

Fuzzing or auditing USB stuff has been around for a while but doing it from the device's perspective is a relatively unexplored area. This is mostly because of the complications that are involved in pretending to be a USB device to attack a USB host. The simplest method involves some hackish modifications on QEMU, where you can write a driver for QEMU for your emulated device and it will appear as real to the virtualized OS.

Unfortunately you cannot run everything interesting inside a virtual machine (think smart TVs, music centers, etc), and even if you could operating systems may behave differently on real hardware. And even more important your real target probably won't be inside QEMU.

Travis Goddspeed has done an amazing job on building a small device with two USB ports that will solve this problem. One end goes to your computer and the other one to the target machine. By using python he is able to control the device such that it will appear as a real USB gadget to the target. Although this is awesome, building this device requires building the PCB and more importantly SMD soldering skills (that I don't have).

So our goal was to build a device that allowed us to quickly prototype USB gadgets and make it easy to assemble. We decided to use a Teensy board, which it's not much more that an AVR micro controller with built-in USB support. All the basic components needed to work, a USB boot-loader so you can reprogram it using this port and of course it had to come pre-assembled :)


Things we love about this board:
  • Is a small board with a relatively powerful microprocessor
  • This processor has built-in USB controller
  • Has a handy bootloader that allows for programming the microprocessor via USB very easily
The Teensy's USB controller is managed entirely by setting and reading a couple of specific registers which makes life wonderfully simple. For example, sending data from the device to the host would be something like this:

There are lots on examples on the Internet about using this device to emulate different USB gadgets such as: keyboards, mice, mass storage, etc. Although there are some drawbacks:

  • There is no easy way to debug: You can always send data trough USB, but you will be interfering with the emulation
  • You have to code in C/C++
  • For each test you need to recompile and re-flash.

The last issue too may not seem very important but when you are doing hundreds of tests it adds a lot of time overhead. Also if you are testing on real hardware, you will need to unplug the Teensy and connect it to your development machine for reprogramming.

So what we did was instead of emulating the whole Gadget on the Teensy, we just use it as a proxy. And this proxy is controlled from a Python script where all the USB logic was implemented. This allow us to move all the complexity of coding USB stuff from the hardware device to the host side, using python code which is much more friendly. We also designed our library in layers so the upper layers do not depend on our actual hardware this gives us the ability to port the library to different hardware if needed.

For this we needed another communication channel from the Teensy to our development computer, so we added a generic USB-Serial adapter connected to the host's serial port:

  • USB device that emulates a serial port on the host
  • RX and TX outputs are in TTL level
  • 0v to 0.8v = 0
  • 2.2v to 5v = 1
  • Native support on Linux



Now the developer's computer communicates via the USB-serial line to the Teensy, where it can interact with the USB controller. On the other side the Target machine is connected directly to the USB port of our device.


We built a very basic firmware for the Teensy that reads commands from the serial line and based on the value received it will either read or write a register from the USB controller. The first byte transmitted either from the host to the Teensy or from the Teensy to the host has the following format:


Where opcodes can be SET_REGISTER, READ_REGISTER or PING, and the register value is 5 bits that represent what register will be read or written to. In the case of a SET_REGISTER operation a second byte is sent indicating the value that should be written to the register. In the case of READ_REGISTER the value will be returned by the Teensy to the host.

PING is just for debugging, a PING_REPLY is answered every time we send this request and lets us know if some part of the chain has died. Just to be more clear here is part of the firmware code (it has been trimmed so it can fit nicely on the blog post):




And finally here's what it looks like on my desk:



As you can see the device is very simple to build, just need to attach tree wires and it's done!

The firmware is also very simple, but the whole complexity is moved to Python on the host side, where you need to understand and handle almost raw USB requests.

Despite all the good features of this project, it has its limitations. When you are emulating stuff that requires a lot of data transfers, like USB-storage for example, it results are pretty slow. The bottleneck right now is the serial line, although some improvements can be made to the protocol like handling bulk data transfers instead of byte by byte, it will at most double the speed which is still not enough.

At this point we were forced to look for new alternatives and we decided to move to using a Cellphone as the base hardware. Surprisingly a cellphone is a perfect platform for this task, they have powerful processors, big screens, Wi-Fi and more important a guest-capable USB controller. In particular we have chosen Samsung S2, as it is very popular and relatively easy to replace the kernel.

If you want to see more on this new approach you should came to Infiltrate and see my talk, "Chameleon, a cellphone-based USB impersonator" :)

~ Matias Soler

@gnuler