<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
	>

<channel>
	<title>©атсн²² (in)sесuяitу &#187; Conference</title>
	<atom:link href="http://blog.c22.cc/category/conference/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.c22.cc</link>
	<description>Because we&#039;re damned if we do, and we&#039;re damned if we don&#039;t!</description>
	<lastBuildDate>Thu, 11 Mar 2010 14:31:33 +0000</lastBuildDate>
	<generator>http://wordpress.com/</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<cloud domain='blog.c22.cc' port='80' path='/?rsscloud=notify' registerProcedure='' protocol='http-post' />
<image>
		<url>http://www.gravatar.com/blavatar/1b6c05a022094e3a7342e6b645c9cfce?s=96&#038;d=http://s2.wp.com/i/buttonw-com.png</url>
		<title>©атсн²² (in)sесuяitу &#187; Conference</title>
		<link>http://blog.c22.cc</link>
	</image>
	<atom:link rel="search" type="application/opensearchdescription+xml" href="http://blog.c22.cc/osd.xml" title="©атсн²² (in)sесuяitу" />
	<atom:link rel='hub' href='http://blog.c22.cc/?pushpress=hub'/>
		<item>
		<title>Shnooowcon &#8211; What the Washington snow teaches us about InfoSec</title>
		<link>http://blog.c22.cc/2010/02/11/shnooowcon/</link>
		<comments>http://blog.c22.cc/2010/02/11/shnooowcon/#comments</comments>
		<pubDate>Thu, 11 Feb 2010 15:57:01 +0000</pubDate>
		<dc:creator>ChrisJohnRiley</dc:creator>
				<category><![CDATA[Conference]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Shmoocon]]></category>
		<category><![CDATA[Snowcon]]></category>
		<category><![CDATA[Washington]]></category>

		<guid isPermaLink="false">http://c22blog.wordpress.com/?p=1260</guid>
		<description><![CDATA[Unlike the snow in Washington, Shmoocon has come and gone. What an experience&#8230; People always said it was a one of the best conferences to attend, and now I know why. Everybody there was friendly, knowledgable and certainly up for a party. Just the right kind of environment to learn something new, meet new faces [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.c22.cc&blog=1599597&post=1260&subd=c22blog&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<div id="attachment_1259" class="wp-caption alignleft" style="width: 225px"><a href="http://c22blog.files.wordpress.com/2010/02/photo1.jpg"><img class="size-medium wp-image-1259" style="border:5px;margin:5px;" title="photo.jpg" src="http://c22blog.files.wordpress.com/2010/02/photo1.jpg?w=215&#038;h=161" alt="Jayson was no bikini model, but he did his best" width="215" height="161" /></a><p class="wp-caption-text">Jayson was no bikini model, but he did his best</p></div>
<p>Unlike the snow in Washington, Shmoocon has come and gone. What an experience&#8230; People always said it was a one of the best conferences to attend, and now I know why. Everybody there was friendly, knowledgable and certainly up for a party. Just the right kind of environment to learn something new, meet new faces and catchup with others. Still, as I sit on a plane winging its way back to Austria, I can&#8217;t help but think about the total chaos caused by the Washington snow.</p>
<p>If you were anywhere near Washington the last few days you can&#8217;t fail but to have been effected by the snow storms and the resulting aftermath. As you can imagine, it was a source of much discussion at Shmoocon, especially for me and Benny (<a title="@security4all" href="http://twitter.com/security4all" target="_blank">@security4all</a>), as we were booked into a hotel 10 minutes walk from the conference. That&#8217;s 10 minutes without the snow <img src='http://s.wordpress.com/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' /> </p>
<p>In among these discussions, an idea came up that intrigued me. If you think about it, the snow wasn&#8217;t the real problem. After all, lots of countries get this kind of snowfall on a regular basis. Personally, I deal with this kind of thing for ~4 months of the year back home in Austria. So what was the problem? what caused all this disruption? The problem was that Washington wasn&#8217;t prepared to deal with the issues that came up as a result of the snow. There was nobody to clear the streets, the airports couldn&#8217;t clear the runways, and the metro lines were blocked. This is all normal stuff, and if it snows regularly, you&#8217;ve got response plans in place. Everybody knows their roles, and does them well. In Washington, this kind of snow is such a rare occurence, that nobody knew what to do. At least that&#8217;s how it appeared from the point of view of an onlooker. There just wasn&#8217;t enough people ready to deal with things in a timely manner. Those that were ready didn&#8217;t have the resources or experience to deal with things quickly and well.</p>
<div id="attachment_1261" class="wp-caption alignright" style="width: 160px"><a href="http://c22blog.files.wordpress.com/2010/02/photo2.jpg"><img class="size-thumbnail wp-image-1261" style="border:5px;margin:5px;" title="photo2" src="http://c22blog.files.wordpress.com/2010/02/photo2.jpg?w=150&#038;h=112" alt="Gotta love regedit" width="150" height="112" /></a><p class="wp-caption-text">Gotta love regedit</p></div>
<p>You can&#8217;t fail but see the connection to many of issues we face in information security. Some companies have a incident handling plan in place, others don&#8217;t. Everybody gets hit by a security breach sooner of later. How fast your company recovers is all about doing the work now, and not hoping that you can just work it out when it hits. If you&#8217;re left scrambling around at 3am, like we saw in Washington, then you&#8217;ve already lost the battle. Without planning your resources are going to waste. I saw people on the streets of Washington at 3am, shoveling snow off the pathways. Normally I&#8217;d applaud that. After all it was a quick response and it was pro-active. Clear the streets before the morning. However, it was still snowing as hard as before, so for every inch that was cleared, another 2 inches of snow were still to come. Add to that the fact that 10 or even 20 people with shovels aren&#8217;t going to make a dent in the amount of snow. A typical case of having  the right tool for the right job&#8230; or in this case, not having the right tool.</p>
<p>This is typical knee-jerk reaction to an issue. Get out there as quick as you can and clear it up. Still, what can you achieve if the cause of the problem <em>(in this case snow)</em> still isn&#8217;t resolved. If an attacker got into your servers, you wouldn&#8217;t start rebuilding them before you&#8217;d plugged the hole used to exploit them. It&#8217;s a vicious circle, that won&#8217;t stop until you plan for what could, and eventually will happen. Worse still, in Washington, they knew it was coming before hand, an advantage you won&#8217;t often get when it comes to attacks. I could draw analogies here to an IDS warning you of attack attempts, but I think you get my point here. I don&#8217;t know who first said it, but <strong>&#8220;If you fail to plan, you plan to fail&#8221;</strong>.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/c22blog.wordpress.com/1260/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/c22blog.wordpress.com/1260/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/c22blog.wordpress.com/1260/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/c22blog.wordpress.com/1260/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/c22blog.wordpress.com/1260/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/c22blog.wordpress.com/1260/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/c22blog.wordpress.com/1260/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/c22blog.wordpress.com/1260/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/c22blog.wordpress.com/1260/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/c22blog.wordpress.com/1260/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.c22.cc&blog=1599597&post=1260&subd=c22blog&ref=&feed=1" />]]></content:encoded>
			<wfw:commentRss>http://blog.c22.cc/2010/02/11/shnooowcon/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
	
		<media:content url="" medium="image">
			<media:title type="html">ChrisJohnRiley</media:title>
		</media:content>

		<media:content url="http://c22blog.files.wordpress.com/2010/02/photo1.jpg?w=300" medium="image">
			<media:title type="html">photo.jpg</media:title>
		</media:content>

		<media:content url="http://c22blog.files.wordpress.com/2010/02/photo2.jpg?w=150" medium="image">
			<media:title type="html">photo2</media:title>
		</media:content>
	</item>
		<item>
		<title>ShmooCon</title>
		<link>http://blog.c22.cc/2010/01/29/shmoocon/</link>
		<comments>http://blog.c22.cc/2010/01/29/shmoocon/#comments</comments>
		<pubDate>Fri, 29 Jan 2010 14:48:34 +0000</pubDate>
		<dc:creator>ChrisJohnRiley</dc:creator>
				<category><![CDATA[Conference]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Shmoocon]]></category>

		<guid isPermaLink="false">http://blog.c22.cc/?p=1248</guid>
		<description><![CDATA[Well, after the rush of 26C3 in Berlin, I&#8217;m back traveling again. This time it&#8217;s Shmoocon over the pond in Washington DC. It&#8217;s my first time attending this particular conference, but I&#8217;ve heard nothing but good things about it for a long while now. I like the fact that it&#8217;s more of a small intimate [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.c22.cc&blog=1599597&post=1248&subd=c22blog&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<p><a href="http://c22blog.files.wordpress.com/2010/01/shmoocon.jpg"><img class="alignleft size-full wp-image-1249" style="border:10px none;margin:10px;" title="shmoocon" src="http://c22blog.files.wordpress.com/2010/01/shmoocon.jpg?w=377&#038;h=62" alt="" width="377" height="62" /></a>Well, after the rush of 26C3 in Berlin, I&#8217;m back traveling again. This time it&#8217;s <a title="http://www.shmoocon.org/" href="http://www.shmoocon.org/" target="_blank">Shmoocon</a> over the pond in Washington DC. It&#8217;s my first time attending this particular conference, but I&#8217;ve heard nothing but good things about it for a long while now. I like the fact that it&#8217;s more of a small intimate conference, and compared with the chaos that was 26C3, that will be a nice change. After all, you know a conference is too big if you can walk around for 4 days and only see your work colleague twice. Still, I digress. That happens a lot it seems&#8230;.</p>
<p>Along with the usual conference stuff, I&#8217;ll also be taking part in the <a title="http://www.podcastersmeetup.com/" href="http://www.podcastersmeetup.com/" target="_blank">Podcasters meetup</a> on Saturday night and taking part in the Core Security technical panel. If I can make some last-minute arrangements, I&#8217;ll have some <a title="Eurotrash Security Podcast" href="http://www.eurotrashsecurity.eu" target="_blank">Eurotrash Security </a>stickers with me to give away. I will also be trying to do some quick on-site interviews for the podcast, but will have to do some sound checks to see if it&#8217;s possible.</p>
<p>I&#8217;ve been working on a list of new people to meet when at the conference, it&#8217;s by no means complete, but it&#8217;s a start. If you&#8217;re not on the list, don&#8217;t take offense, shoot me a message here or on <a title="@ChrisJohnRiley" href="http://twitter.com/ChrisJohnRiley" target="_blank">Twitter</a> and we&#8217;ll see what can be done.</p>
<ul>
<li><a title="http://twitter.com/mubix" href="http://twitter.com/mubix" target="_blank">Mubix</a> (Rob Fuller)</li>
<li><a title="http://twitter.com/tkrabec" href="http://twitter.com/tkrabec" target="_blank">Tkrabec</a> (Tim Krabec)</li>
<li><a title="http://twitter.com/andrewsmhay" href="http://twitter.com/andrewsmhay" target="_blank">Andrewsmhay</a> (Andrew Hay)</li>
<li><a title="http://twitter.com/wikidsystems" href="http://twitter.com/wikidsystems" target="_blank">WikidSystems</a> (Nick Owen)</li>
<li><a title="http://twitter.com/bug_bear" href="http://twitter.com/bug_bear" target="_blank">Bug_Bear</a></li>
<li><a title="BIOSShadow" href="BIOSShadow" target="_blank">BIOSShadow</a> (Jacob Kuehndorf)</li>
<li><a title="http://twitter.com/geekgrrl" href="http://twitter.com/geekgrrl" target="_blank">Geekgrrl</a> (Melissa)</li>
<li><a title="http://twitter.com/grecs" href="http://twitter.com/grecs" target="_blank">grecs</a></li>
<li><a title="http://twitter.com/masontech" href="http://twitter.com/masontech" target="_blank">Masontech</a> (Andrew Mason)</li>
<li><a href="http://twitter.com/nathanhamiel">Nathanhamiel</a> (Nathan Hamiel)</li>
<li><a href="http://twitter.com/gdead">Gdead</a> (Bruce Potter)</li>
<li><a title="http://twitter.com/vincentkadmon" href="http://twitter.com/vincentkadmon" target="_blank">Vincentkadmon</a> (Georgia Weidman)</li>
<li><a title="www.hak5.org" href="www.hak5.org" target="_blank">HAK5</a> Crew</li>
<li>&#8230;.</li>
</ul>
<p>It&#8217;s always hard to pick what talks are must-see, but I&#8217;ve picked a couple out that I&#8217;ll be trying to attend.</p>
<h3><a href="http://www.shmoocon.org/presentations-all.html#p2pinfo">Information disclosure via P2P networks: Why stealing an identity via Gnutella is like clubbing baby seals</a> (Larry Pesce, Mick Douglas)</h3>
<p style="padding-left:30px;">I saw Larry talk a little about this at Defcon, but I&#8217;m looking forward to the whole thing. I don&#8217;t think organisations think enough about this kind of data exposure, and people should be building this into the &#8220;data exposure&#8221; testing regime for their company  (if they&#8217;re doing it at all).</p>
<h3><a href="http://www.shmoocon.org/presentations-all.html#smartphone">The New World of Smartphone Security &#8211; What Your iPhone Disclosed About You</a> (Trevor Hawthorn)</h3>
<p style="padding-left:30px;">I&#8217;ve been getting more and more interested in iPhone (in)security recently. So hopefully this talk will give me some motivation to finish my own research into iPhone profile security.</p>
<h3><a href="http://www.shmoocon.org/presentations-all.html#zombies">Social Zombies II: Your Friends Need More Brains</a> (Tom Eston,   Kevin Johnson, Robin Wood)</h3>
<p style="padding-left:30px;">After the first version of the talk (at Defcon last year) this update should be fun. Plus Tom was the one who came to the rescue and got me a ticket, Kevin has to autograph my <a title="SANS GWAPT" href="http://www.giac.org/certifications/security/GWAPT.php" target="_blank">GWAPT</a> certificate and Robin is just a great guy&#8230;.</p>
<h3><a href="http://www.shmoocon.org/presentations-all.html#srsly">GSM: SRSLY?</a> (Chris Paget,  Karsten Nohl)</h3>
<p style="padding-left:30px;">I missed this presentation at 26C3 as the room was full, so I hope that the rerun will be just as interesting. Plus, more information was forthcoming about A5/3 cipher&#8230; Oh, and Karten promised to come on Eurotrash, so I need to remind him <img src='http://s.wordpress.com/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' /> </p>
<h3><a href="http://www.shmoocon.org/presentations-all.html#extended">Exposed | More: Attacking the Extended Web</a> (Nathan Hamiel)</h3>
<p style="padding-left:30px;">Gotta love Web Application penetration testing !!!</p>
<h3><a href="http://www.shmoocon.org/presentations-all.html#traitor">The Friendly Traitor: Our Software Wants to Kill Us</a> (Kevin Johnson, Mike Poor)</h3>
<p style="padding-left:30px;">I haven&#8217;t seen Mike since a SANS conference in 2008 (Amsterdam) so it&#8217;ll be nice to say hi again&#8230;. Plus, anytime you can see Mike talk, it&#8217;s a WIN.</p>
<p>Anyway, I hope to see you there&#8230;.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/c22blog.wordpress.com/1248/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/c22blog.wordpress.com/1248/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/c22blog.wordpress.com/1248/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/c22blog.wordpress.com/1248/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/c22blog.wordpress.com/1248/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/c22blog.wordpress.com/1248/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/c22blog.wordpress.com/1248/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/c22blog.wordpress.com/1248/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/c22blog.wordpress.com/1248/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/c22blog.wordpress.com/1248/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.c22.cc&blog=1599597&post=1248&subd=c22blog&ref=&feed=1" />]]></content:encoded>
			<wfw:commentRss>http://blog.c22.cc/2010/01/29/shmoocon/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
	
		<media:content url="" medium="image">
			<media:title type="html">ChrisJohnRiley</media:title>
		</media:content>

		<media:content url="http://c22blog.files.wordpress.com/2010/01/shmoocon.jpg" medium="image">
			<media:title type="html">shmoocon</media:title>
		</media:content>
	</item>
		<item>
		<title>26C3: Cryptographically Secure ? (lightning talk)</title>
		<link>http://blog.c22.cc/2009/12/30/26c3-cryptographically-secure-lightning-talk/</link>
		<comments>http://blog.c22.cc/2009/12/30/26c3-cryptographically-secure-lightning-talk/#comments</comments>
		<pubDate>Wed, 30 Dec 2009 12:01:50 +0000</pubDate>
		<dc:creator>ChrisJohnRiley</dc:creator>
				<category><![CDATA[Conference]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[26C3]]></category>
		<category><![CDATA[encryption]]></category>
		<category><![CDATA[PoC]]></category>
		<category><![CDATA[SanDisk]]></category>

		<guid isPermaLink="false">http://c22blog.wordpress.com/?p=1220</guid>
		<description><![CDATA[Cryptographically Secure ?
Cracking FIPS-Certified USB Flash Drives
Lightning talk &#8211; PoC &#8211; Matthias Deeg
Demo is performed using a SanDisk Cruzer Enterprise (FIPS Edition), however is possible on other devices.

Small mistakes often have a big impact, especially when it comes to complex devices.

USB FDU &#8211; (USB Flash Drive Unlocker)
The demo PoC tool was able to unlock the [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.c22.cc&blog=1599597&post=1220&subd=c22blog&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<p><strong>Cryptographically Secure ?</strong><br />
<em>Cracking FIPS-Certified USB Flash Drives</em><br />
<span style="color:#660000;">Lightning talk &#8211; PoC &#8211; </span><span style="color:#660000;"><em>Matthias Deeg</em></span></p>
<p>Demo is performed using a SanDisk Cruzer Enterprise (FIPS Edition), however is possible on other devices.</p>
<ul>
<li>Small mistakes often have a big impact, especially when it comes to complex devices.</li>
</ul>
<p>USB FDU &#8211; (USB <strong>F</strong>lash <strong>D</strong>rive <strong>U</strong>nlocker)</p>
<p>The demo PoC tool was able to unlock the device (make it so that any arbitrary password works) within a few seconds. A number of vendors have already patched this issue and provided updates for their devices (see Links below).</p>
<p>Currently the PoC isn&#8217;t publicly available.</p>
<p><span style="color:#000000;"><em>Links :</em></span></p>
<ul>
<li>Cryptographically Secure Paper (<a href="http://www.syss.de/fileadmin/ressources/040_veroeffentlichungen/dokumente/SySS_knackt_SanDisk_USB-Stick.pdf" target="_blank">DE</a>)</li>
<li>Papers (<a href="http://www.syss.de/fileadmin/ressources/040_veroeffentlichungen/dokumente/SySS_knackt_SanDisk_USB-Stick.pdf" target="_blank">SanDisk</a>, <a href="http://www.syss.de/fileadmin/ressources/040_veroeffentlichungen/dokumente/SySS_knackt_Kingston_USB-Stick.pdf" target="_blank">Kingston</a>) (DE)</li>
<li>SanDisk Security bulletin (<a href="http://www.sandisk.com/business-solutions/enterprise/technical-support/security-bulletin-december-2009" target="_blank">LINK</a>)</li>
<li>http://www.syss.de (DE)</li>
</ul>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/c22blog.wordpress.com/1220/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/c22blog.wordpress.com/1220/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/c22blog.wordpress.com/1220/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/c22blog.wordpress.com/1220/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/c22blog.wordpress.com/1220/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/c22blog.wordpress.com/1220/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/c22blog.wordpress.com/1220/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/c22blog.wordpress.com/1220/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/c22blog.wordpress.com/1220/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/c22blog.wordpress.com/1220/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.c22.cc&blog=1599597&post=1220&subd=c22blog&ref=&feed=1" />]]></content:encoded>
			<wfw:commentRss>http://blog.c22.cc/2009/12/30/26c3-cryptographically-secure-lightning-talk/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="" medium="image">
			<media:title type="html">ChrisJohnRiley</media:title>
		</media:content>
	</item>
		<item>
		<title>26C3: secuBT &#8211; Hacking the hackers with User-Space Virtualization</title>
		<link>http://blog.c22.cc/2009/12/30/26c3-secubt-hacking-the-hackers-with-user-space-virtualization/</link>
		<comments>http://blog.c22.cc/2009/12/30/26c3-secubt-hacking-the-hackers-with-user-space-virtualization/#comments</comments>
		<pubDate>Wed, 30 Dec 2009 11:15:43 +0000</pubDate>
		<dc:creator>ChrisJohnRiley</dc:creator>
				<category><![CDATA[Conference]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[26C3]]></category>
		<category><![CDATA[exploitation]]></category>
		<category><![CDATA[secuBT]]></category>

		<guid isPermaLink="false">http://c22blog.wordpress.com/?p=1217</guid>
		<description><![CDATA[secuBT &#8211; Hacking the hackers with User-Space Virtualization
In the age of coordinated malware distribution and zero-day exploits security becomes ever more important. This paper presents secuBT, a safe execution framework for the execution of untrusted binary code based on the fastBT dynamic binary translator.
Aim: To visualize and encapsulate running programs to guard and protect the [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.c22.cc&blog=1599597&post=1217&subd=c22blog&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<p><strong>secuBT &#8211; Hacking the hackers with User-Space Virtualization</strong></p>
<blockquote><p>In the age of coordinated malware distribution and zero-day exploits security becomes ever more important. This paper presents secuBT, a safe execution framework for the execution of untrusted binary code based on the fastBT dynamic binary translator.</p></blockquote>
<p><strong>Aim</strong>: To visualize and encapsulate running programs to guard and protect the computer system<img class="event-image alignright" style="margin:6px;" src="http://events.ccc.de/congress/2009/Fahrplan/images/event-3515-128x128.png" alt="" width="128" height="128" /></p>
<p><strong>Problem</strong></p>
<ul>
<li>programs can execute any system call</li>
<li>Security vulnerabilities can be used to execute unintended system calls</li>
<li>Patches are a reactive form of dealing with the problem</li>
</ul>
<p><strong>Solution</strong></p>
<p><strong></strong>User-space virtualization encapsulates a running program</p>
<ul>
<li>Executed code is checked and validated</li>
<li>Code can be wrapped or modified</li>
<li>System calls can be controlled</li>
</ul>
<p>User-space virtualization is implemented through Dynamic Binary Translation</p>
<ul>
<li>secuBT implements a User-Space sandbox</li>
<li>Dynamic BT used for virtualization layer</li>
<li>System calls interposition framework &#8211; Checks and validates system calls, implements checks to avoid breakout</li>
</ul>
<p><strong>Static vs Dynamic translation</strong></p>
<p>Static reads the binary, reassembles it into a new binary after processing &#8211; This is prone to issues, but is quicker<br />
Dynamic translates all code as it gets executed &#8211; This is slightly slower, but improves compatibility</p>
<p>Dynamic Translation implements two levels of code execution:</p>
<ul>
<li>&#8216;Privileged&#8217; code of BT library</li>
<li>Translated and cached user code</li>
</ul>
<p>When performing translation the following checks are made:</p>
<ul>
<li>All instructions are checked</li>
<li>All (direct and indirect) jump targets are verified</li>
<li>All system calls are verified</li>
</ul>
<p><strong>Security hardening</strong></p>
<ul>
<li>Enforce NX-bit</li>
<li>Check ELF headers, regions, and rights</li>
<li>Protect internal data structures (<em>mprotect</em>)</li>
<li>Check and verify (valid) return addresses</li>
<li>Check and verify indirect control transfers</li>
</ul>
<p><strong>System Call Interposition Framework</strong></p>
<p>Guards and rewrites all system calls through sysenter &amp; INT 80 redirection to a validation function</p>
<p>The validation function can reimplement the syscall in user-space (allows fake responses or return a value as desired)</p>
<p>This allows a specific set of permitted syscalls to be defined, and unwanted syscalls can be blocked.<br />
<strong><br />
Overhead</strong> &#8211; 7% only using Binary Translation,  increasing to 9% with all security implementations in place</p>
<p><strong>What does secuBT protect ?</strong></p>
<ul>
<li>Heap and stack based overflow</li>
<li>Return to libc style attacks</li>
<li>Overwriting the return instruction pointer (using shadow stack)</li>
</ul>
<p>More information can be found at the following locations :</p>
<ul>
<li>http://events.ccc.de/congress/2009/Fahrplan/events/3515.en.html</li>
<li>secuBT paper (<a href="http://events.ccc.de/congress/2009/Fahrplan/attachments/1430_secuBT.pdf" target="_blank">PDF</a>)</li>
<li>secuBT project page (<a href="http://nebelwelt.net/projects/secuBT" target="_blank">link</a>)</li>
</ul>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/c22blog.wordpress.com/1217/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/c22blog.wordpress.com/1217/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/c22blog.wordpress.com/1217/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/c22blog.wordpress.com/1217/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/c22blog.wordpress.com/1217/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/c22blog.wordpress.com/1217/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/c22blog.wordpress.com/1217/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/c22blog.wordpress.com/1217/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/c22blog.wordpress.com/1217/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/c22blog.wordpress.com/1217/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.c22.cc&blog=1599597&post=1217&subd=c22blog&ref=&feed=1" />]]></content:encoded>
			<wfw:commentRss>http://blog.c22.cc/2009/12/30/26c3-secubt-hacking-the-hackers-with-user-space-virtualization/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="" medium="image">
			<media:title type="html">ChrisJohnRiley</media:title>
		</media:content>

		<media:content url="http://events.ccc.de/congress/2009/Fahrplan/images/event-3515-128x128.png" medium="image" />
	</item>
		<item>
		<title>26C3: Optimised to fail &#8211; Card readers for online banking</title>
		<link>http://blog.c22.cc/2009/12/29/26c3-optimised-to-fail-card-readers-for-online-banking/</link>
		<comments>http://blog.c22.cc/2009/12/29/26c3-optimised-to-fail-card-readers-for-online-banking/#comments</comments>
		<pubDate>Tue, 29 Dec 2009 17:10:36 +0000</pubDate>
		<dc:creator>ChrisJohnRiley</dc:creator>
				<category><![CDATA[Conference]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[26C3]]></category>
		<category><![CDATA[Banks]]></category>
		<category><![CDATA[CAP]]></category>
		<category><![CDATA[Chip & PIN]]></category>
		<category><![CDATA[Smart Cards]]></category>

		<guid isPermaLink="false">http://c22blog.wordpress.com/?p=1214</guid>
		<description><![CDATA[Card readers for online banking

The Chip Authentication Programme (CAP) has been introduced by banks
in Europe to deal with the soaring losses due to online banking fraud.
A handheld reader is used together with the customer&#8217;s debit card to
generate one-time codes for both login and transaction authentication.
The CAP protocol is not public, and was rolled out without [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.c22.cc&blog=1599597&post=1214&subd=c22blog&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<p><strong>Card readers for online banking<br />
</strong></p>
<blockquote><p>The Chip Authentication Programme (CAP) has been introduced by banks<br />
in Europe to deal with the soaring losses due to online banking fraud.<br />
A handheld reader is used together with the customer&#8217;s debit card to<br />
generate one-time codes for both login and transaction authentication.<br />
The CAP protocol is not public, and was rolled out without any public<br />
scrutiny. We reverse engineered the UK variant of card readers and<br />
smart cards and here provide the first public description of the<br />
protocol. We found numerous design errors, which could be exploited by<br />
criminals.</p>
<div class="description">
<p>Banks throughout Europe are now issuing hand-held smart card readers<br />
to their customers. These are used, along with the customer&#8217;s bank<br />
card, for performing online banking transactions. In this talk I will<br />
describe how we reversed-engineered the cryptographic protocol used by<br />
these readers, using some custom-designed smart card analysis hardware.<br />
We discovered several flaws in this protocol, which could be exploited<br />
by criminals (and some already are). This talk will explain what<br />
vulnerabilities exist, and what the impact on customers could be.</p>
</div>
</blockquote>
<p><img class="event-image alignright" style="margin:7px;" src="http://events.ccc.de/congress/2009/Fahrplan/images/event-3657-128x128.png" alt="" width="128" height="128" /></p>
<p>Online banking fraud has increased 185% between 2007 and 2008.</p>
<p>Simple fraud techniques dominate due to poor overall security and awareness :</p>
<ul>
<li>Phishing emails</li>
<li>Keyboard loggers</li>
</ul>
<p>Some common security measures that UK banks have implemented :</p>
<ul>
<li>On-Screen keyboards</li>
<li>Picture passwords</li>
<li>Device fingerprinting (using HTTP header information to track and block)</li>
<li>One-time-passwords/iTAN</li>
</ul>
<p>All of these are bypassable in one way or another. Whether it&#8217;s through MitM style attacks, of faking headers.<strong> </strong>Commonly however Man in the Browser attacks are used, as it offers a complete control over the victim&#8217;s machine. What the victim sees, isn&#8217;t what they send/receive.</p>
<p>To combat this, the response must be bound to the transaction to be authorised. Various methods have been implemented, including several UK banks that are now using hardware based challenge/response for authorisation of transactions. These devices conform to the EMV specification v4.2</p>
<ul>
<li>Customer enters PIN</li>
<li>Customer enters transaction details</li>
<li>Reader displays authorisation code</li>
<li>Customer enters code into the browser</li>
<li>Bank verifies the authorisation code in the background</li>
</ul>
<p>How this protocol works is a closed box.</p>
<p>By building a smart card snooper (based on the Xilinx FPGA development board from Opal Kelly) it was possible to discover information about the underlying protocols.</p>
<ul>
<li>Protocol very similar to EMV (used for smartcard payments in Europe)</li>
<li>Looks like a transaction but cancelled at the last stage</li>
<li>Contains 2 data items not listed in the EMV specification</li>
</ul>
<p><strong>Changing some data</strong></p>
<p>By modifying specific pieces of data and leaving others the same, it was possible to observe the reaction of the device. By flipping 1 bit, sometimes the transaction failed, other times the resulting code was different.</p>
<ul>
<li>The authentication code comes from the cryptogram generated by the card at the end of the transaction</li>
<li>The mysterious tag 9f56 was a ‘bit filter’ which selects which bits from the cryptogram are used for the response</li>
<li>The filtered cryptogram is then converted to decimal</li>
</ul>
<p>It was found that there were no cryptographic secrets within the device itself. This means that a software implementation was easy to achieve (a number are available).</p>
<p><strong>Useability failures aid fraudsters</strong></p>
<p>The different banks use varied features of the devices. This leads to confusion where a fraudster can fool a user into using the device in a way that the input is what the fraudster wants and not what the bank expects.</p>
<p><strong>Nonce is small or absent</strong></p>
<ul>
<li>No nonce in Barclays variant, so response stays valid</li>
<li>Only a 4 digit nonce with Natwest (weak 100 guesses = 63% success rate)</li>
</ul>
<p>Fake point of sales devices can get responses in advance.</p>
<p><strong>CAP readers help muggers &#8211; </strong>CAP readers can be used to check if the PIN number is correct or not.<br />
<strong>Supply chain infiltration</strong> &#8211; In the past chip &amp; pin terminals with GSM modules have already been found in the wild. The control of CAP readers is significantly less controlled.</p>
<p><strong>What does this mean for customers</strong></p>
<ul>
<li>CAP is far better than existing UK systems</li>
<li>Authentication codes are dynamic</li>
<li>Authentication codes are bound to transaction</li>
</ul>
<p>However, banks are now claiming that any transaction using this process <span style="text-decoration:underline;">must</span> have been authorised by the user. This means that if you are a victim of fraud, the bank will probably deny your claims. Currently ~20% of claims are turned down.</p>
<p>Recent attempts to test this in court failed, with the Bank winning (Halifax). The evidence provided by the bank was simply a log file showing that the transaction was chip read (04 in the log).</p>
<p><strong>HHD 1.3</strong></p>
<p>Standard from ZKA, Germany</p>
<p>Stronger than UK CAP, but more user input required</p>
<ul>
<li>Many more modes</li>
<li>Mode number alters meaningful prompts</li>
<li>Up to 7 digit nonce</li>
<li>Nonce, and mode number are included in MAC</li>
<li>PIN verification</li>
</ul>
<p><strong>Other solutions</strong></p>
<ul>
<li>Flicker TAN &#8211; Device reads information from a flickering animation (using sensors)</li>
<li>USB connected readers &#8211; Require drivers, so could be an issue without Admin permissions</li>
<li>Cronto PhotoTAN &#8211; Uses a 2D barcode read by a mobile phone application (uses a cryptographic key to prevent MitM)</li>
</ul>
<p>More information can be found on the <a href="http://events.ccc.de/congress/2009/Fahrplan/events/3657.en.html" target="_blank">CCC wiki</a>. Access to the slides (<a href="http://events.ccc.de/congress/2009/Fahrplan/attachments/1494_Murdoch_OptimisedToFail.pdf" target="_blank">PDF</a>)<strong><br />
</strong></p>
<ul>
<li>http://www.lightbluetouchpaper.org</li>
<li>http://www.cronto.com/</li>
</ul>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/c22blog.wordpress.com/1214/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/c22blog.wordpress.com/1214/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/c22blog.wordpress.com/1214/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/c22blog.wordpress.com/1214/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/c22blog.wordpress.com/1214/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/c22blog.wordpress.com/1214/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/c22blog.wordpress.com/1214/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/c22blog.wordpress.com/1214/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/c22blog.wordpress.com/1214/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/c22blog.wordpress.com/1214/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.c22.cc&blog=1599597&post=1214&subd=c22blog&ref=&feed=1" />]]></content:encoded>
			<wfw:commentRss>http://blog.c22.cc/2009/12/29/26c3-optimised-to-fail-card-readers-for-online-banking/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
	
		<media:content url="" medium="image">
			<media:title type="html">ChrisJohnRiley</media:title>
		</media:content>

		<media:content url="http://events.ccc.de/congress/2009/Fahrplan/images/event-3657-128x128.png" medium="image" />
	</item>
		<item>
		<title>26C3: Playing with the GSM RF interface</title>
		<link>http://blog.c22.cc/2009/12/29/26c3-playing-with-the-gsm-rf-interface/</link>
		<comments>http://blog.c22.cc/2009/12/29/26c3-playing-with-the-gsm-rf-interface/#comments</comments>
		<pubDate>Tue, 29 Dec 2009 15:40:13 +0000</pubDate>
		<dc:creator>ChrisJohnRiley</dc:creator>
				<category><![CDATA[Conference]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[26C3]]></category>
		<category><![CDATA[DoS]]></category>
		<category><![CDATA[GSM]]></category>
		<category><![CDATA[OpenBTS]]></category>

		<guid isPermaLink="false">http://c22blog.wordpress.com/?p=1211</guid>
		<description><![CDATA[Doing tricks with a mobile phone
This talk will show what can be done by taking control of the GSM RF part of a mobile phone, for example performing a DoS attack to the GSM network or using the phone as a sniffing device.
If the RF hardware of a mobile phone can be controlled, lots of [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.c22.cc&blog=1599597&post=1211&subd=c22blog&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<p class="subtitle"><strong>Doing tricks with a mobile phone</strong></p>
<blockquote><p>This talk will show what can be done by taking control of the GSM RF part of a mobile phone, for example performing a DoS attack to the GSM network or using the phone as a sniffing device.</p>
<p>If the RF hardware of a mobile phone can be controlled, lots of things are possible, for example:</p></blockquote>
<div class="description">
<blockquote>
<ul>
<li>Sending continuous Channel Request which can lead to a huge load for a GSM cell and could be considered as a DoS attack to the GSM network.</li>
<li>Use a mobile phone as a cheap GSM receiver for sniffing the air traffic somehow similar to what can be done with the USRP.</li>
</ul>
</blockquote>
</div>
<p><strong>Motivation for playing with GSM</strong></p>
<p>The GSM network has been in use in Germany since 1992 and hasn&#8217;t been well researched until recently. It was always the case that access to GSM equipment was restricted. Now the game has changed. Second hand GSM equipment is easily available, OpenBTS, OpenBCS, etc&#8230;. the documentation behind GSM is also now public (but is very extensive)</p>
<p><strong>OpenBTS</strong></p>
<ul>
<li>Hardware based on USRP</li>
<li>Air Interface (Um) is a software defined radio</li>
<li>Does not model classic GSM architecture, but uses a direct Um-to-SIP</li>
</ul>
<p><strong>OpenBCS</strong></p>
<ul>
<li>Implements the Abis protocol plus MSC/MSC/HLR</li>
<li>Supports the Siemens BS11 microBTS</li>
<li>Supports ip.access nanoBTS</li>
<li>Used to run the 26C3 network using 4 nanoBTS units</li>
</ul>
<p>The nanoBTS is much smaller and more modern than the 10 year old Siemens BS11 unit.</p>
<p><strong>Airprobe</strong></p>
<ul>
<li>Passively sniff the GSM Air Interface</li>
<li>Based on USRP and GNU Radio</li>
<li>Analyze protocols with Wireshark</li>
</ul>
<p><strong>What about an &#8220;open&#8221; phone</strong></p>
<ul>
<li>Project Blacksphere for Nokia DCT3 phone &#8211; No longer active ?</li>
<li>TSM30, based on the TI Calypso GSM chipset &#8211; source code available on the internet
<ul>
<li>Can be used to sniff the air traffic</li>
<li>Could be used to perform DoS on the GSM network</li>
</ul>
</li>
<li>Openmoko GTA01/02: GSM modem based on TI Calypso
<ul>
<li>The software is open-source, but the GSM modem is still closed</li>
</ul>
</li>
<li>Future plans: Take a GSM RF-Transceiver and Baseband chip, connect it to a DSP/FPGA board
<ul>
<li>Truly open</li>
<li>Very long term</li>
</ul>
</li>
</ul>
<p><strong>TSM30</strong></p>
<ul>
<li>Spanish phone (about 6 years old)</li>
<li>GSM, GPRS, WAP</li>
<li>TI Calypso chipset &#8211; leaked documents can be found</li>
<li>Firmware is written in C &#8211; no source code for the DSP</li>
</ul>
<p><strong>Sniffing the air traffic</strong></p>
<p>The TSM30 provides the chance to extract digitally converted traffic, however issues of extracting the data (1 MByte per second) from the phone need to be worked out. As there is no fast data transfer this is currently an issue. Tests with 1 second of audio have been tested and work as expected.</p>
<p><strong>DoS Attack</strong></p>
<ul>
<li>By sending continuous RASH requests you can use up available channels on the BTS</li>
<li>Makes it difficult for phones to access the cell</li>
<li>Phones might switch to another cell</li>
<li>Useful for specifically targeting a location, but not a general wide-spread DoS</li>
<li>No 100% guarantee</li>
<li>Theory known for sometime, but never demonstrated</li>
<li>Even a phone without a SIM can perform the attack</li>
<li>Hard to track</li>
<li>Protection against the attack would require a complete rewrite of how GSM functions</li>
</ul>
<p>One useful purpose for the attack, is performing a DoS against the cell and implement a rogue point to capture user information when phones attempt to register to another available BTS.</p>
<p>A demonstration of the DoS using the 25C6 conference GSM network (nanoBTS and OpenBTS)</p>
<p>More information can be found on the <a href="http://events.ccc.de/congress/2009/Fahrplan/events/3608.en.html" target="_blank">CCC wiki</a>.</p>
<div class="abstract"></div>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/c22blog.wordpress.com/1211/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/c22blog.wordpress.com/1211/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/c22blog.wordpress.com/1211/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/c22blog.wordpress.com/1211/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/c22blog.wordpress.com/1211/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/c22blog.wordpress.com/1211/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/c22blog.wordpress.com/1211/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/c22blog.wordpress.com/1211/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/c22blog.wordpress.com/1211/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/c22blog.wordpress.com/1211/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.c22.cc&blog=1599597&post=1211&subd=c22blog&ref=&feed=1" />]]></content:encoded>
			<wfw:commentRss>http://blog.c22.cc/2009/12/29/26c3-playing-with-the-gsm-rf-interface/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
	
		<media:content url="" medium="image">
			<media:title type="html">ChrisJohnRiley</media:title>
		</media:content>
	</item>
		<item>
		<title>26C3: DECT (part II)</title>
		<link>http://blog.c22.cc/2009/12/29/26c3-dect-part-ii/</link>
		<comments>http://blog.c22.cc/2009/12/29/26c3-dect-part-ii/#comments</comments>
		<pubDate>Tue, 29 Dec 2009 13:58:51 +0000</pubDate>
		<dc:creator>ChrisJohnRiley</dc:creator>
				<category><![CDATA[Conference]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[26C3]]></category>
		<category><![CDATA[cryptography]]></category>
		<category><![CDATA[DECT]]></category>
		<category><![CDATA[DSAA]]></category>
		<category><![CDATA[DSC]]></category>

		<guid isPermaLink="false">http://c22blog.wordpress.com/?p=1207</guid>
		<description><![CDATA[Last years talk on DECT (in)security was one of the highlights of my
conference. It also prompted me to grab one of the com-on-air cards and
start playing with DECT a little more. Hopefully this talk gives me
some more fun things to play with in 2010.
What has changed in DECT security after one year
&#8220;This talk will provide [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.c22.cc&blog=1599597&post=1207&subd=c22blog&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<p>Last years talk on DECT (in)security was one of the highlights of my<br />
conference. It also prompted me to grab one of the com-on-air cards and<br />
start playing with DECT a little more. Hopefully this talk gives me<br />
some more fun things to play with in 2010.</p>
<p><strong>What has changed in DECT security after one year</strong></p>
<p>&#8220;This talk will provide an update on the security of encrypted DECT<br />
calls (using the DSC cipher), which can currently not be broken by<br />
passive eavesdropping. We will also show what has been done so far to<br />
improve DECT security and what you can do to get a secure DECT system&#8221;</p>
<p>GSM cellphones have a lot in common with in-house cordless telephones. The security of both devices were designed by the same group of people, with only a few years between them. They share a number of the same issues as a result.</p>
<p>Communication within the industry has been a lot better with DECT insecurities however, and plans are being discussed on how to make things more secure. The same cannot  be said however for GSM issues.</p>
<p><strong>DECT overview</strong></p>
<ul>
<li>Standard for short range portable phones</li>
<li>Frequency 1,9 Ghz</li>
<li>Range up to 300 meters</li>
<li>invented in 1992</li>
<li>more than 670,000,000 devices</li>
</ul>
<p><strong>Standard of security &#8211; 1 year ago</strong></p>
<p>DECT uses two proprietary protocols</p>
<ul>
<li>DSAA: DECT Standard Authentication Algorithm</li>
<li>DSC: DECT Standard cipher</li>
<li>Both are <span style="text-decoration:underline;">OPTIONAL</span>!</li>
</ul>
<p>There are devices in the market the do not use authentication or encrypt.</p>
<p>Project deDECTed.org in 2007/8 jointly worked on disclosing DECT security</p>
<ul>
<li>Reversing DSAA</li>
<li>Partial Reversing of DSC</li>
<li>Attacks on DSAA, PRNGs and DECT itself</li>
<li>Open-source sniffer for DECT PCMCIA card</li>
</ul>
<p>This culminated in the talk at 25C3 to disclose the vulnerabilities and raise awareness. This talk invoked public interest, resulting in extensive media coverage, and the implementation of a DECT stack for Linux (Patrick McHardy). DECT vendors, BSI and other security companies started engaging with deDECTed.org. The first consumer phones with improves security appear in early 2009 (shortly after the 25C3 talk). These looked to fix some of the more serious issues. Some firmware upgradable phones were also provided with upgrades.</p>
<p><strong>Open implementation of DECT</strong></p>
<ul>
<li>PCMCIA Type III card now supported</li>
<li>Additional support for audio codecs</li>
<li>Better audio quality</li>
</ul>
<p><strong>New research</strong></p>
<p>DSC was reverse engineered</p>
<ul>
<li>Similar to A5/1</li>
<li>4 LFSRs, 3 irregularly clocked</li>
<li>Output combiner with 1 bit memory</li>
<li>40 Blank rounds &#8211; Largest weakness found</li>
</ul>
<p>DSC can be accessed from the SC14421&#8217;s firmware</p>
<p>The level of access granted by the D_WRS state allowed for complete control and debugging of the encryption process. This meant that, like the Legic prime talk, a reverse engineering was possible without the need to look at the silicon. However, they still did, as it was fun.</p>
<p>A5/1 is stronger tan DSC in only one dimension &#8211;&gt; in A5/1 there are 100 pre-cipher rounds, compared in only 40 in DSC.</p>
<p>This appears to be a tweak implemented by engineers to improve speed. However this 1 flaw causes serious issues with the encryption and makes it significantly weaker than A5/1. Without this change, the encryption would be significantly better than A5/1 in every way (see slides for a full breakdown)</p>
<p><strong>DSC Cryptanalysis</strong></p>
<ul>
<li>Imagine all the registers would be regularly clocked</li>
<li>The internal state would be a linear combination of IV and key bits</li>
<li>Two consecutive bits of output cut down the key space by half</li>
<li>You can repeat that !</li>
<li><span style="text-decoration:underline;">However</span>, LFSR&#8217;s are clocked irregularly</li>
</ul>
<p>The use of irregular clocking makes it a lot more secure. However&#8230;</p>
<p>You can guess the number of clocks correctly (for 1 register, chances are 12%, for all 3 registers, the chances are 0,2%, which may seem low, but is significant). Access to 500,000 different keystreams reveals the key in 1 day on a PC  using a fast GPU. Full details of this attack will be released mid-January at a Cryptographic conference.</p>
<p><strong>Using the C-Channel (A-Field)</strong> (to gather keystream data)</p>
<p>A-Field is ony encrypted when C-Channel data is present</p>
<p>The base station is responsible for updating the handset through C-Channel data. The C-Channel transports :</p>
<ul>
<li>Dial Strings</li>
<li>Display updates</li>
<li>Keys pressed on the numpad</li>
<li>RSS newsfeeds</li>
</ul>
<p>This provides lots of guessable plaintext, and can provide the 500,000 required keystreams with in 24h.</p>
<p><strong>Using the B-Field</strong> (to gather keystream data)</p>
<p>B-Field transports voice data</p>
<ul>
<li>Very hard to guess, except if there is silence or the B-Field is unused</li>
<li>Mute one end of the communication !</li>
</ul>
<p>3 hours silence is enough to generate the required data.</p>
<p><strong>Other Problems</strong></p>
<ul>
<li>DSC key only depends on random numbers sent by the FP</li>
<li>Phones create guessable B-fields</li>
<li>&#8230;</li>
</ul>
<p><strong>Countermeasures</strong></p>
<p>For the user :</p>
<ul>
<li>Restrict to short calls</li>
<li>Avoid silence</li>
</ul>
<p>For the manufacturer :</p>
<ul>
<li>change the key during the call</li>
<li>Avoid guessable content in C-Channel</li>
<li>Replace the algorithm</li>
</ul>
<p><strong>Next Generation of the DECT standard</strong></p>
<ul>
<li>ETSI and the DECT forum are now working on a new standard</li>
<li>deDECTed helped where possible</li>
<li>Changes will be made in two stages &#8211; Short-Term fixes, Longer-Term redesign</li>
<li>The new standards DSAA2, DSC2 will be openly published and use established algorithms</li>
</ul>
<p>Where possible, firmware updates will be made available to fix some issues (such as re-keying, forced encryption, &#8230;)</p>
<p>A set of security requirements will be standardized in spring 2010. Phones implementing this will be certified.</p>
<p>More information can we found :</p>
<ul>
<li>http://events.ccc.de/congress/2009/Fahrplan/events/3648.en.html</li>
<li>https://dedected.org</li>
<li>http://www.dect.org/news.aspx?id=52 &#8211;&gt; DECT Forum press statement</li>
</ul>
<p>Some publications released in 2009 in regards to DECT security :</p>
<ul>
<li>&#8220;Security of Digital Enhanced Cordless Telecommunications&#8221; by Alexandra Mengele (<a href="http://www.cdc.informatik.tu-darmstadt.de/reports/reports/Alexandra_Mengele.diplom.pdf" target="_blank">PDF</a>)</li>
<li>&#8220;An efficient FPGA Implementation for an DECT Brute-Force Attack Scenario&#8221; by Kei Ogata (<a href="http://doi.ieeecomputersociety.org/10.1109/ICWMC.2009.20" target="_blank">Article</a>)</li>
</ul>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/c22blog.wordpress.com/1207/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/c22blog.wordpress.com/1207/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/c22blog.wordpress.com/1207/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/c22blog.wordpress.com/1207/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/c22blog.wordpress.com/1207/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/c22blog.wordpress.com/1207/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/c22blog.wordpress.com/1207/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/c22blog.wordpress.com/1207/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/c22blog.wordpress.com/1207/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/c22blog.wordpress.com/1207/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.c22.cc&blog=1599597&post=1207&subd=c22blog&ref=&feed=1" />]]></content:encoded>
			<wfw:commentRss>http://blog.c22.cc/2009/12/29/26c3-dect-part-ii/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="" medium="image">
			<media:title type="html">ChrisJohnRiley</media:title>
		</media:content>
	</item>
		<item>
		<title>26C3: SCCP Hacking &#8211; Attacking SS7 &amp; SIGTRAN applications</title>
		<link>http://blog.c22.cc/2009/12/28/26c3-sccp-hacking-attacking-ss7-sigtran-applications/</link>
		<comments>http://blog.c22.cc/2009/12/28/26c3-sccp-hacking-attacking-ss7-sigtran-applications/#comments</comments>
		<pubDate>Mon, 28 Dec 2009 22:52:38 +0000</pubDate>
		<dc:creator>ChrisJohnRiley</dc:creator>
				<category><![CDATA[Conference]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[26C3]]></category>
		<category><![CDATA[GSM]]></category>
		<category><![CDATA[SS7]]></category>
		<category><![CDATA[Telco]]></category>

		<guid isPermaLink="false">http://c22blog.wordpress.com/?p=1205</guid>
		<description><![CDATA[One step further and mapping the phone system
SS7 is no longer the walled garden where people cannot inject traffic. SS7 was designed for reliability, with multiple systems  designed to take the load of failed servers. Access to the SS7 network was originally restricted to peering partners. It is now the target for fraudsters (SMS fraud), [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.c22.cc&blog=1599597&post=1205&subd=c22blog&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<p><strong>One step further and mapping the phone system</strong></p>
<p>SS7 is no longer the walled garden where people cannot inject traffic. SS7 was designed for reliability, with multiple systems  designed to take the load of failed servers. Access to the SS7 network was originally restricted to peering partners. It is now the target for fraudsters (SMS fraud), and government agencies.</p>
<p><strong>Why do we have SS7 ?</strong></p>
<p>Blame Steve Jobs / Steve Wozniak and the creation of the bluebox. With inband signalling, hackers took advantage of the telephone system. Seizing a trunk without tracing was a big problem. SS7 was designed to move the signalling away from the voice network. However this is all history.</p>
<p>One part of the SS7 system is the LIG (Legal Interception Gateway ?) &#8211;&gt; usually not owned by the telco. Installed by 3rd parties to give access to the system for law enforcement.</p>
<p>OpenBTS and OpnBSC are making research into this area possible.</p>
<p>Using External APIs to HLR, it has been demonstrated how it&#8217;s possible to locate IMSI within the SS7 network.</p>
<p>The underlying technology is moving towards IP based solutions &#8211;&gt; This is good for us, we know IP already</p>
<p>Important SS7 protocols :</p>
<ul>
<li>MTP (Message Transfer Protocol) Layers 1-3</li>
<li>ISUP (Integrated Servics Digital Network)</li>
<li>SCCP (Signaling Control Connection Part)</li>
<li>TCAP (Transaction Capabilities Application Part)</li>
<li>MAP (Mobile Application Part)</li>
<li>INAP (Intelligent Network Application Part)</li>
</ul>
<p>Entry points in an SS7 network :</p>
<ul>
<li>Peer relationship between operators</li>
<li>STP connectivity</li>
<li>SIGTRAN protocols</li>
<li>VAS systems e.g. SMSC, IN</li>
<li>Signaling Gateways, MGW</li>
<li>SS7 Service providers (GRX, IPX)</li>
<li>GTT translation</li>
<li>ISDN terminals</li>
<li>GSM phones</li>
<li>LIG (Legal Interception Gateway)</li>
<li>3G Femtocell</li>
<li>SIP encapsulation</li>
</ul>
<p>These entries points offer a range of access posibilities, and limitations. Without access directly into the core SS7 network, attacks will be limited depending on the provider.</p>
<p><strong>SIGTRAN protocol: M3UA Protocol Adaptation Layer</strong></p>
<p>SIGTRAN gives us the opportunity to work with something more familiar.</p>
<p>Like TCP/IP, but with slight differences, including spoofing and DoS protections &#8211;&gt; RFC4960</p>
<p>By adapting typical scanning methods used in TCP/IP environments, you can scan for services. The tools SCTPscan tool is now included in many Linux distributions, including Backtrack. When sending SCTP init packets, no answer usually means a peering port has been found. Usually an ABORT reply is sent. By scanning addresses, close to the official SMSC, you can often find test systems that may not be correctly connected to systems such as billing systems !</p>
<p>Protections are less about filtering, and more that a valid route isn&#8217;t know. Once you have a route, you can connect to other systems.</p>
<p>In order to get a valid list of SPC codes, you can scan, or buy the full list from the ITU for under €30</p>
<p>When dealing with SPC formats, there are a variety of differing formats.</p>
<ul>
<li>ss7calc &#8211;&gt; open-source tool available from p1sec.com</li>
</ul>
<p><strong>Attack examples :</strong></p>
<ul>
<li>IAM attack: Capacity DoS &#8211;&gt; Similar to SIP flooding</li>
<li>REL attack: Targeted Call release &#8211;&gt; Terminate a users conversation</li>
<li>SRI attack: Tracking of users</li>
<li>HLR attack: Fake location update &#8211;&gt; redirect calls to another country, until phone reboot</li>
<li>&#8230;.</li>
</ul>
<p><strong>FemtoCell</strong></p>
<ul>
<li>Node B in users home. Establishes an IPsec tunnel, SIGTRAN</li>
<li>Hardware based on Linux</li>
<li>ARM hardware</li>
<li>Very insecure</li>
<li>&gt; Unaudited software</li>
<li>&gt; Global settings for IPsec tunnel</li>
<li>&gt; Injection of RANAP and SS7 traffic into the core network</li>
</ul>
<p><strong>Tools and things to help</strong></p>
<ul>
<li>SCTPscan &#8211; Bridging support, instream scanning</li>
<li>ss7calc</li>
<li>7Bone &#8211; Open Research SS7 Backbone</li>
<li>P1sec SIGTRANalyzer (SS7 and SIGTRAN vuln scanning, Commercial pruduct)</li>
</ul>
<p><span style="color:#660000;">SS7 is not closed anymore !</span></p>
<p>For more information, check the following links :</p>
<ul>
<li>http://events.ccc.de/congress/2009/Fahrplan/events/3555.en.html</li>
<li>http://www.p1sec.com/corp/wp-content/uploads/2009/10/Attacking-SS7-2009-Philipe-Langlois-P1security-h2hc-v8.pdf</li>
<li>http://www.p1security.com</li>
<li>http://www.blackhat.com/html/bh-europe-07/bh-eu-07-speakers.html#Langlois</li>
<li>SCTPscan &#8211;&gt; http://media.frnog.org/FRnOG_10/FRnOG_10-2.pdf</li>
<li>SCTPscan Video &#8211;&gt; http://www.dailymotion.com/video/x2nq3d_frnog-10-philippe-langlois-sctpscan_tech</li>
</ul>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/c22blog.wordpress.com/1205/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/c22blog.wordpress.com/1205/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/c22blog.wordpress.com/1205/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/c22blog.wordpress.com/1205/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/c22blog.wordpress.com/1205/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/c22blog.wordpress.com/1205/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/c22blog.wordpress.com/1205/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/c22blog.wordpress.com/1205/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/c22blog.wordpress.com/1205/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/c22blog.wordpress.com/1205/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.c22.cc&blog=1599597&post=1205&subd=c22blog&ref=&feed=1" />]]></content:encoded>
			<wfw:commentRss>http://blog.c22.cc/2009/12/28/26c3-sccp-hacking-attacking-ss7-sigtran-applications/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
	
		<media:content url="" medium="image">
			<media:title type="html">ChrisJohnRiley</media:title>
		</media:content>
	</item>
		<item>
		<title>26C3: Legic Prime &#8211; Obscurity in Depth</title>
		<link>http://blog.c22.cc/2009/12/28/26c3-legic-prime-obscurity-in-depth/</link>
		<comments>http://blog.c22.cc/2009/12/28/26c3-legic-prime-obscurity-in-depth/#comments</comments>
		<pubDate>Mon, 28 Dec 2009 21:51:29 +0000</pubDate>
		<dc:creator>ChrisJohnRiley</dc:creator>
				<category><![CDATA[Conference]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[26C3]]></category>
		<category><![CDATA[Legic]]></category>
		<category><![CDATA[RFID]]></category>

		<guid isPermaLink="false">http://c22blog.wordpress.com/?p=1203</guid>
		<description><![CDATA[LEGIC Prime is the older (1992) of the two high security RFID solutions offered by the Legic company (the other being Advant &#8211; released in 2004).
The Legic Prime is primarily used for high security access systems, but is also used in some payment situations, such as company cafeteria payments.

Shrouded in a cloud of closed-ness and [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.c22.cc&blog=1599597&post=1203&subd=c22blog&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<p><img class="alignright" style="margin:6px 8px;" src="http://www.maxicard.de/aktuelles/LEGIC_Logo_Internet.jpg" alt="" width="250" height="61" />LEGIC Prime is the older (1992) of the two high security RFID solutions offered by the Legic company (the other being Advant &#8211; released in 2004).</p>
<p>The Legic Prime is primarily used for high security access systems, but is also used in some payment situations, such as company cafeteria payments.</p>
<ul>
<li>Shrouded in a cloud of closed-ness and exclusivity</li>
<li>Compared to MiFare: much harder to get cards and readers</li>
<li>This secrecy is marketed as a security feature</li>
</ul>
<p>Token structure is hierarchical: a token can only create objects with higher nesting level than its own. This allowed Legic to have resellers each permitted to write a nesting level for each customer and so forth.</p>
<p>Attacks were implemented using the Proxmark 3.</p>
<p>* <span style="color:#660000;">Note</span>: I&#8217;m not even going to try and take notes on the reverse engineering of the Legic protocol. Again, the slides and video are a good idea if you want more information.</p>
<p>When reverse engineering the protocol there were a lot of instances where things appeared to be returned in a strange order. This could possibly be used as an obfuscation to hinder decoding of the protocol.</p>
<p>By simply sending commands it is possible to read all segments, even the read protected areas. This code is now in the Proxmark SVN and should allow reading of data from the LEGIC Prime cards. It was also possible to overwrite data by simple brute-forcing the CRC for that data location, until the correct value was found (or calculated from previously held data &#8211; i.e. the UID).</p>
<p>This was all achieved without even looking at the silicon to reverse engineer the crypto functions.</p>
<p>&#8220;We did find something crypto looking, but too small to be cryptographically secure&#8221; &#8211; the state was found to be only 15bits, easily reversible, but not needed (brute-force). No key input &#8211;&gt; not technically an encryption</p>
<p>A number of additional, and easier, attacks on the CRC functions where also discovered allowing you to spoof any card, including the master card (the card permitted to write other cards for a company).</p>
<p>The write command is also susceptible to the same CRC issue previously seen. This allows write to the card as desired.</p>
<p>By sniffing the communication between a card and reader it is possible to recreate the card in an emulated environment. When playing with the emulated card was found that Bytes 5 and 6 could only be decremented to prevent a user raising privileges. However with a blank card, this value is set to maximum and is possible to decrement it to the desired value.</p>
<ul>
<li>Byte 5 controls the token type (IAM, SAM, GAM)</li>
<li>Byte 6 controls the stamp length (along with Byte 7)</li>
<li>&#8230;</li>
</ul>
<p>Data on the card is further obfuscated. The data is XORd with a secret value. This value turns out to be the CRC of the UID (which is stored on the card!).</p>
<p><strong>Root problems</strong></p>
<ul>
<li>No Keys (no key management, no card authentication, no reader authentication
<ul>
<li>Spoofing, skimming</li>
<li>Segments can be created out of thin air</li>
<li>Master token can be created out of thin air</li>
</ul>
</li>
<li>No authorisation necessary for master token use, master token not inherently necessary for segment creation
<ul>
<li>cloneable</li>
</ul>
</li>
</ul>
<p><strong>Software released:</strong> Reader emulation<br />
<strong>Not released:</strong> Card emulation, full protocol &#8211;&gt; however reverse engineering is not hard, so <span style="text-decoration:underline;">upgrade ASAP</span></p>
<p>Please upgrade, but not to HID!</p>
<p>For more information :</p>
<ul>
<li>http://events.ccc.de/congress/2009/Fahrplan/events/3709.en.html</li>
<li>http://www.legic.com/en/legic_prime.html</li>
</ul>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/c22blog.wordpress.com/1203/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/c22blog.wordpress.com/1203/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/c22blog.wordpress.com/1203/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/c22blog.wordpress.com/1203/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/c22blog.wordpress.com/1203/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/c22blog.wordpress.com/1203/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/c22blog.wordpress.com/1203/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/c22blog.wordpress.com/1203/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/c22blog.wordpress.com/1203/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/c22blog.wordpress.com/1203/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.c22.cc&blog=1599597&post=1203&subd=c22blog&ref=&feed=1" />]]></content:encoded>
			<wfw:commentRss>http://blog.c22.cc/2009/12/28/26c3-legic-prime-obscurity-in-depth/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
	
		<media:content url="" medium="image">
			<media:title type="html">ChrisJohnRiley</media:title>
		</media:content>

		<media:content url="http://www.maxicard.de/aktuelles/LEGIC_Logo_Internet.jpg" medium="image" />
	</item>
		<item>
		<title>26C3: Defending the poor</title>
		<link>http://blog.c22.cc/2009/12/28/26c3-defending-the-poor/</link>
		<comments>http://blog.c22.cc/2009/12/28/26c3-defending-the-poor/#comments</comments>
		<pubDate>Mon, 28 Dec 2009 20:40:34 +0000</pubDate>
		<dc:creator>ChrisJohnRiley</dc:creator>
				<category><![CDATA[Conference]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[26C3]]></category>
		<category><![CDATA[Adobe]]></category>
		<category><![CDATA[Blitzableiter]]></category>
		<category><![CDATA[Flash Player]]></category>

		<guid isPermaLink="false">http://c22blog.wordpress.com/?p=1199</guid>
		<description><![CDATA[Not sure how I managed to miss this on the first look at the schedule, but I almost missed this one. FX usually talks about IOS, but this time he&#8217;s turning his focus on Flash applications, and how to defend them. Certainly a turn-up for the books   Fx&#8217;s first talk concentrating on pure [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.c22.cc&blog=1599597&post=1199&subd=c22blog&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<p>Not sure how I managed to miss this on the first look at the schedule, but I almost missed this one. FX usually talks about IOS, but this time he&#8217;s turning his focus on Flash applications, and how to defend them. Certainly a turn-up for the books <img src='http://s.wordpress.com/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' />  Fx&#8217;s first talk concentrating on pure defense. Nick Farr pulled off a pretty passable standup comedy act before the talk. There&#8217;s a career in show biz for him somewhere I&#8217;m sure <img src='http://s.wordpress.com/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' /> </p>
<p><strong>Defending the poor:</strong> <em>Countering Flash Exploits</em></p>
<p><img class="alignleft" style="margin:5px;" src="http://www.adobe.com/macromedia/style_guide/logos/flash_enabled/images/flash_enabled_logo_vertical.jpg" alt="" width="97" height="159" />Research was motivated by the BSI project (in late 2008) that reviewed the current state of Rich Internet Applications. Flash was shown to be lagging behind in regards to security, and no easy solution could be found. So how do we solve the problems ?</p>
<p>Who cares about flash security ?</p>
<ul>
<li>People who don&#8217;t want to get owned when surfing pr0n</li>
<li>Apple user running PowerPc (no more updates)</li>
<li>Website operators (Flash adverts, &#8230;)</li>
</ul>
<p>The common link between RIA environments (Flash, Silverlight/moonlight, JavaFX) is the plug-in based implementation. The majority of systems run flash, with Siverlight a long long long distant second.</p>
<p><strong>The Flash security model</strong></p>
<p>Primarily relies on the virtual machine runtime environment for sealing off access from the RIA code to the native machine. Permission decisions are based on so-called sandboxes. Generally Flash code can access local or remote resources, but should be restricted to one or the other.</p>
<p>Security Focus lists about 40 Flash vulnerabilities for the Flash player.</p>
<p><strong>Attacks using Flash</strong></p>
<p><strong></strong>Other than memory corruption and client-side attacks, Flash is used for a range of other attacks :<strong><br />
</strong></p>
<ul>
<li>Flash has been used to perform DNS rebinding</li>
<li>targeting exploits by using Flash to perform client-side enumeration</li>
<li>Clickjacking style attacks</li>
<li>Sending additional HTTP headers (UPNP, CSRF Attacks)</li>
<li>Appending HTML/JavaScript to Flash files</li>
<li>Forwarding users / redirection (most commonly seen)</li>
</ul>
<p><strong>Flash Malware examples</strong></p>
<ul>
<li>SWF .AdJack/Gnida</li>
<li>CVE 2007-0071 Exploit</li>
<li>SWF/TrojanDownloader</li>
<li>&#8230;.</li>
</ul>
<p>AV scanners appear to have issues detecting these threats if the malware is uncompressed. This could mean that AV scanners are not detecting the actual malware, but only packed strings or the packer itself.</p>
<p><strong>Adobe Virtual Machines</strong></p>
<p>The flash player actually contains <strong>2</strong> virtual machines<br />
AVM1 is a historically grown weakly typed stack machine with support for object orientated code<br />
AVM2 is a ECMA-262 (JavaScript) stack machine with a couple of modifications to increase strangeness. Programmed in ActionScript 3.</p>
<p><strong>History of AVM1<br />
</strong></p>
<ul>
<li>First Scripting appears in SWF 3</li>
<li>SWF 4 introduces the AVM</li>
<li>SWF 5 introduces typed variables on the stack</li>
<li>SWF 6 fixes SWF 5</li>
<li>SWF 7 brings more OOP &#8211; Finally introduced exception handling !</li>
<li>SWF 8 never happened</li>
<li>SWF 9 already brings the AVM2 into the format</li>
<li>SWF 10 current</li>
</ul>
<p>The whole thing is backwards compatible. Many security tools do not check ALL the code, and concentrate on the DoAction tags.</p>
<p><strong>Desgin Weaknesses in AVM1</strong><br />
The byte offset in branch instructions allow for:</p>
<ul>
<li>jumps into the middle of other instructions</li>
<li>jumping outside of code blocks</li>
</ul>
<p>The order of code execution appears to be non-deterministic</p>
<ul>
<li>Depends on a number of variables including how far an object it on the y axis !</li>
</ul>
<p><strong>Comparison to AVM2</strong></p>
<ul>
<li>Designed to make everything better</li>
<li>Spec not been updated since 2007</li>
<li>The &#8220;reference implementation&#8221; called Tamarin is not open-source</li>
<li>Format specification uses 30bit length fields to prevent integer overflows</li>
</ul>
<p><strong>Considerations for the defense approach</strong></p>
<p>There are two main attack types to defend against</p>
<ul>
<li>Malformed SWF files that cause memory corruption</li>
<li>Well formed SWF files that use the player API for evilness</li>
</ul>
<p>Instrumentation of the player is bound to fail<br />
Nobody wants to write a new flash player from the ground up</p>
<p><strong>Solution &#8211; Normalization through Recreation</strong></p>
<ul>
<li>Safely parsing the complete SWF file, strictly checking the standards</li>
<li>&#8230;.</li>
</ul>
<p>A Flash File Parser (coded in c# to allow for .Net and mono support) &#8211;&gt; Blitzableiter</p>
<p>This will protect against possible malformed attacks, but not against SWF files performing simple redirections. In order to protect against this, you can use emulation to interpret the actions. This however is flawed, as the Flash player isn&#8217;t easy to predict, and the emulation could take a different direction to the player.</p>
<p>By performing runtime analysis, you can (for example) ensure that the same origin checks are imposed on functions that could result in the browser being forwarded (i.e ActionGetURL2). By patching the code, you can then open the SWF in the player without worrying about the user being forwarded to another site without warning.</p>
<p>This solution is trivial, but needs to be done as the Flash player doesn&#8217;t do these checks.</p>
<p><strong>Blitzableiter</strong></p>
<ul>
<li>Features a full AVM1 assembler</li>
<li>Supports all 100 documented AVM1 instructions</li>
<li>Support for variable name</li>
<li>AVM2 not yet supported</li>
</ul>
<p>In testing 82% of the test set ran correctly once being run through the engine. However the code inflation is currently at 224% of the original, which needs to get fixed. Timings are roughly 1 second additional wait for the whole process.</p>
<p>There is still work to be done to fix issues with some Flash compilers output (youtube is an example).</p>
<p>The tool can&#8217;t do anything about (yet) :</p>
<ul>
<li>Heap Spraying</li>
<li>Flash API overflows</li>
</ul>
<p>The Blitzableiter tool is open-source allowing others to check the code and find bugs. It will also allow others to integrate the features (into web browser extensions, Proxy filters, or file upload filters). Also so that Flash developers can test their own code. The code has been released under the GPLv3.</p>
<ul>
<li>http://www.adobe.com/devnet/flashplayer/</li>
<li>http://blitzableiter.recurity.com</li>
<li>http://blitzableiter.recurity.com/projects/show/blitzableiter</li>
</ul>
<p>* <span style="color:#993300;">Note</span>: These are my notes from the talk. As always, it&#8217;s not possible to get every piece of fine detail. I&#8217;d suggest catching the video as soon as it&#8217;s made available.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/c22blog.wordpress.com/1199/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/c22blog.wordpress.com/1199/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/c22blog.wordpress.com/1199/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/c22blog.wordpress.com/1199/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/c22blog.wordpress.com/1199/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/c22blog.wordpress.com/1199/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/c22blog.wordpress.com/1199/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/c22blog.wordpress.com/1199/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/c22blog.wordpress.com/1199/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/c22blog.wordpress.com/1199/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.c22.cc&blog=1599597&post=1199&subd=c22blog&ref=&feed=1" />]]></content:encoded>
			<wfw:commentRss>http://blog.c22.cc/2009/12/28/26c3-defending-the-poor/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
	
		<media:content url="" medium="image">
			<media:title type="html">ChrisJohnRiley</media:title>
		</media:content>

		<media:content url="http://www.adobe.com/macromedia/style_guide/logos/flash_enabled/images/flash_enabled_logo_vertical.jpg" medium="image" />
	</item>
	</channel>
</rss>