Monday, July 30, 2012
PPTP VPN is Critically Vulnerable.
Moxie Marlinspike does it again. The eclectic hacker who previously brought you SSLStrip now has released (@ Defcon 20) a utility and advisory on cracking MSCHAPv2 which powers most PPTP VPN.
Get the code here: https://github.com/moxie0/chapcrack
Suggestion is to migrate to OpenVPN for a more secure VPN setup.
Also if your bored read some of his excellent stories
Tuesday, June 12, 2012
Friday, April 13, 2012
Looking for a localhost cacheing nameserver?
Back in the day I would use dnscache and sometimes even bind for local network or localhost cacheing recursive DNS. I was hoping there was a newer, better, faster and easier to setup / maintain solution in 2012....
I found unbound. http://unbound.net/
If you have a server that does tons of DNS lookups (think SIEM), then this is a must.
Debian/Ubuntu:
apt-get install unbound
Redhat/Centos:
yum install unbound
It's secure and listens only on 127.0.0.1 by default. How cool is that?
Lastly don't forget to update resolv.conf...
echo "nameserver 127.0.0.1" > /etc/resolv.conf
I found unbound. http://unbound.net/
If you have a server that does tons of DNS lookups (think SIEM), then this is a must.
Debian/Ubuntu:
apt-get install unbound
Redhat/Centos:
yum install unbound
It's secure and listens only on 127.0.0.1 by default. How cool is that?
Lastly don't forget to update resolv.conf...
echo "nameserver 127.0.0.1" > /etc/resolv.conf
Labels:
DNS Cache Poisoning,
DNS cacheing,
Linux,
SIEM,
sysadmin,
unbound
Thursday, April 12, 2012
Tuesday, April 3, 2012
ArcOSI 30 released
Added new sources, some parsing fixes and the feature to specify a custom port via command line. Currently only the python code is release but will compile the windows binary later today.
Download @ code.google.com/p/arcosi
-Greg
Download @ code.google.com/p/arcosi
-Greg
Wednesday, March 28, 2012
A little about MS12-020
Great history on the vulnerability by the original Italian researcher: http://aluigi.org/adv/ms12-020_leak.txt
He sold the bug to ZDI with a DoS POC, they reported to MS and the bug is suspected to have leaked through a MAPP partner to Chinese entity and surfaced as the rdpclient.exe
Small companies: Firewall off all remote access to 3389
Enterprise: Scan and test, deploy signatures, alert SOC and start monitoring campaign during lockdown efforts
Snort signatures (untested):
alert tcp any any -> $HOME_NET 3389 (msg:”Potential MS12-020 RDP DoS attempt – MaximumParatmers”; flow:to_server,established; content:”|03 00|”; depth:2; content:”|7f 65 82 01 94|”; distance:24; within:5; content:”|30 19|”; distance:9; within:2; content:”|30 19|”; distance:25; within:2;content:”|30 1c|”; distance:25; within:2; byte_test:1,=,255,2,relative; reference:cve,2012-0002; classtype:attempted-dos; sid:1000031; rev:1;)
alert tcp any any -> $HOME_NET 3389 (msg:”Potential MS12-020 RDP DoS attempt – MaximumParatmers”; flow:to_server,established; content:”|03 00|”; offset:0; depth:2;content:”|7f 65 82 01 94|”;distance:24;within:5;byte_jump:1,10,relative;byte_jump:1,1,relative;byte_test:1,=,255,4,relative; reference:cve,2012-0002; classtype:attempted-dos; sid:1000026;rev:1;priority:1;)
He sold the bug to ZDI with a DoS POC, they reported to MS and the bug is suspected to have leaked through a MAPP partner to Chinese entity and surfaced as the rdpclient.exe
Small companies: Firewall off all remote access to 3389
Enterprise: Scan and test, deploy signatures, alert SOC and start monitoring campaign during lockdown efforts
Snort signatures (untested):
alert tcp any any -> $HOME_NET 3389 (msg:”Potential MS12-020 RDP DoS attempt – MaximumParatmers”; flow:to_server,established; content:”|03 00|”; depth:2; content:”|7f 65 82 01 94|”; distance:24; within:5; content:”|30 19|”; distance:9; within:2; content:”|30 19|”; distance:25; within:2;content:”|30 1c|”; distance:25; within:2; byte_test:1,=,255,2,relative; reference:cve,2012-0002; classtype:attempted-dos; sid:1000031; rev:1;)
alert tcp any any -> $HOME_NET 3389 (msg:”Potential MS12-020 RDP DoS attempt – MaximumParatmers”; flow:to_server,established; content:”|03 00|”; offset:0; depth:2;content:”|7f 65 82 01 94|”;distance:24;within:5;byte_jump:1,10,relative;byte_jump:1,1,relative;byte_test:1,=,255,4,relative; reference:cve,2012-0002; classtype:attempted-dos; sid:1000026;rev:1;priority:1;)
Tuesday, August 30, 2011
Wireless fun with your Macbook
Since OSX Snow Leopard there is an Airport wireless API that allows some fun tricks but it takes some minor setup to use it properly...
First make sure you can easily run the new Airport API utility:
sudo ln -s /System/Library/PrivateFrameworks/Apple80211.framework/Versions/Current/Resources/airport /usr/sbin/airport
Now you have easy ability to scan and sniff packets:
airport scan
And the sexiest feature is to dump packets in monitor mode:
sudo -s airport sniff 11
Note that you still cannot actively inject and sniff without using a realtek USB wifi card.
To stop the airport utility from sniffing drop it into the background and kill the process ID:
ctrl+z
then
sudo -s killall airport
So what kind of attacks are possible without injection? Well any wireless traffic (non encrypted via WEP/WPA/HTTPS) on the channel your sniffing you can then read with a packet inspection tool like tcpdump which comes by default on your Mac. A pcap will be saved in the /tmp directory, simply read it in with tcpdump to see what fun you captured!
Gregs-MacBook-Air:tmp gregmartin$ ls /tmp |grep air
airportSniffmcg8L2.cap
To print the ASCII content of all HTTP traffic:
tcpdump -s0 -Anr /tmp/airportSniffmcg8L2.cap port 80
or
tcpdump -s0 -Anr /tmp/airportSniffmcg8L2.cap port 80 |grep -i pass
Here we see an Android phone at the Boingo wireless captive portal ready to log in!
Of course you can use any libpcap tool such as Wireshark to analyze the resulting file.
First make sure you can easily run the new Airport API utility:
sudo ln -s /System/Library/PrivateFrameworks/Apple80211.framework/Versions/Current/Resources/airport /usr/sbin/airport
Now you have easy ability to scan and sniff packets:
airport scan
And the sexiest feature is to dump packets in monitor mode:
sudo -s airport sniff 11
Note that you still cannot actively inject and sniff without using a realtek USB wifi card.
To stop the airport utility from sniffing drop it into the background and kill the process ID:
ctrl+z
then
sudo -s killall airport
So what kind of attacks are possible without injection? Well any wireless traffic (non encrypted via WEP/WPA/HTTPS) on the channel your sniffing you can then read with a packet inspection tool like tcpdump which comes by default on your Mac. A pcap will be saved in the /tmp directory, simply read it in with tcpdump to see what fun you captured!
Gregs-MacBook-Air:tmp gregmartin$ ls /tmp |grep air
airportSniffmcg8L2.cap
To print the ASCII content of all HTTP traffic:
tcpdump -s0 -Anr /tmp/airportSniffmcg8L2.cap port 80
or
tcpdump -s0 -Anr /tmp/airportSniffmcg8L2.cap port 80 |grep -i pass
Here we see an Android phone at the Boingo wireless captive portal ready to log in!
Of course you can use any libpcap tool such as Wireshark to analyze the resulting file.
Labels:
Cracking WIFI,
Security,
sniffing,
WIFI,
Wireless Security
Subscribe to:
Posts (Atom)