sábado, 29 de agosto de 2020

NcN 2015 CTF - theAnswer Writeup


1. Overview

Is an elf32 static and stripped binary, but the good news is that it was compiled with gcc and it will not have shitty runtimes and libs to fingerprint, just the libc ... and libprhrhead
This binary is writed by Ricardo J Rodrigez

When it's executed, it seems that is computing the flag:


But this process never ends .... let's see what strace say:


There is a thread deadlock, maybe the start point can be looking in IDA the xrefs of 0x403a85
Maybe we can think about an encrypted flag that is not decrypting because of the lock.

This can be solved in two ways:

  • static: understanding the cryptosystem and programming our own decryptor
  • dynamic: fixing the the binary and running it (hard: antidebug, futex, rands ...)


At first sight I thought that dynamic approach were quicker, but it turned more complex than the static approach.


2. Static approach

Crawling the xrefs to the futex, it is possible to locate the main:



With libc/libpthread function fingerprinting or a bit of manual work, we have the symbols, here is the main, where 255 threads are created and joined, when the threads end, the xor key is calculated and it calls the print_flag:



The code of the thread is passed to the libc_pthread_create, IDA recognize this area as data but can be selected as code and function.

This is the thread code decompiled, where we can observe two infinite loops for ptrace detection and preload (although is static) this antidebug/antihook are easy to detect at this point.


we have to observe the important thing, is the key random?? well, with the same seed the random sequence will be the same, then the key is "hidden" in the predictability of the random.

If the threads are not executed on the creation order, the key will be wrong because is xored with the th_id which is the identify of current thread.

The print_key function, do the xor between the key and the flag_cyphertext byte by byte.


And here we have the seed and the first bytes of the cypher-text:



With radare we can convert this to a c variable quickly:


And here is the flag cyphertext:


And with some radare magics, we have the c initialized array:


radare, is full featured :)

With a bit of rand() calibration here is the solution ...



The code:
https://github.com/NocONName/CTF_NcN2k15/blob/master/theAnswer/solution.c





3. The Dynamic Approach

First we have to patch the anti-debugs, on beginning of the thread there is two evident anti-debugs (well anti preload hook and anti ptrace debugging) the infinite loop also makes the anti-debug more evident:



There are also a third anti-debug, a bit more silent, if detects a debugger trough the first available descriptor, and here comes the fucking part, don't crash the execution, the execution continues but the seed is modified a bit, then the decryption key will not be ok.





Ok, the seed is incremented by one, this could be a normal program feature, but this is only triggered if the fileno(open("/","r")) > 3 this is a well known anti-debug, that also can be seen from a traced execution.

Ok, just one byte patch,  seed+=1  to  seed+=0,   (add eax, 1   to add eax, 0)

before:


after:



To patch the two infinite loops, just nop the two bytes of each jmp $-0



Ok, but repairing this binary is harder than building a decryptor, we need to fix more things:

  •  The sleep(randInt(1,3)) of the beginning of the thread to execute the threads in the correct order
  •  Modify the pthread_cond_wait to avoid the futex()
  • We also need to calibrate de rand() to get the key (just patch the sleep and add other rand() before the pthread_create loop
Adding the extra rand() can be done with a patch because from gdb is not possible to make a call rand() in this binary.

With this modifications, the binary will print the key by itself. 

Related word


  1. Pentest Tools For Mac
  2. How To Install Pentest Tools In Ubuntu
  3. How To Hack
  4. Hacker Tools Hardware
  5. Hack Tools For Ubuntu
  6. Hacking Tools 2020
  7. Tools 4 Hack
  8. Hacking Tools Windows 10
  9. Hacker Tools Hardware
  10. Pentest Tools Open Source
  11. Hackrf Tools
  12. Hack Tool Apk
  13. Pentest Tools Android
  14. Hacking Tools For Windows 7
  15. Easy Hack Tools
  16. Ethical Hacker Tools
  17. Hacker Security Tools
  18. Hack And Tools
  19. Hacker Techniques Tools And Incident Handling
  20. Pentest Tools Port Scanner
  21. Nsa Hacker Tools
  22. Android Hack Tools Github
  23. Tools For Hacker
  24. Hacker Tools Github
  25. Hackers Toolbox
  26. Pentest Tools Linux
  27. Hacking Tools Name
  28. Kik Hack Tools
  29. Hacker Tools List
  30. Nsa Hack Tools
  31. Hacker Tools 2020
  32. Beginner Hacker Tools
  33. Game Hacking
  34. How To Hack
  35. Github Hacking Tools
  36. Hacker Tools For Windows
  37. Wifi Hacker Tools For Windows
  38. Hacker Tools Software
  39. Hacking Tools Download
  40. Pentest Tools Github
  41. Hack Tool Apk
  42. Tools For Hacker
  43. Hacker Tools Hardware
  44. Hack Apps
  45. Hack App
  46. Hack Tools Github
  47. Hack Website Online Tool
  48. World No 1 Hacker Software
  49. Pentest Box Tools Download
  50. Pentest Automation Tools
  51. Beginner Hacker Tools
  52. Pentest Tools Online
  53. Hacking Tools Pc
  54. Hacking Apps
  55. Pentest Tools Bluekeep
  56. Hacking Tools Download
  57. Pentest Tools Windows
  58. How To Make Hacking Tools
  59. Hacking Tools For Windows 7
  60. Pentest Tools Tcp Port Scanner
  61. Pentest Tools Windows
  62. Hackers Toolbox
  63. Hacking Tools Mac
  64. Hacking Tools Pc
  65. Tools 4 Hack
  66. What Is Hacking Tools
  67. Hacker Techniques Tools And Incident Handling
  68. Hacking Tools Name
  69. Hack Tool Apk No Root
  70. Hacker Tools Free Download
  71. Hack Tools
  72. Hacker Tools Free Download
  73. Github Hacking Tools
  74. Hacking Tools 2019
  75. Pentest Reporting Tools
  76. Hacking Tools For Games
  77. Hack Tools For Windows
  78. Underground Hacker Sites
  79. Android Hack Tools Github
  80. Hacker Hardware Tools
  81. Hacking Tools For Kali Linux
  82. Pentest Tools Find Subdomains
  83. Hacker Tools Hardware
  84. Hacking Tools Windows
  85. Hacking Tools Online
  86. Hacking Tools For Kali Linux
  87. Pentest Tools Android
  88. Hacking Tools Windows
  89. Hack Rom Tools
  90. Pentest Tools Port Scanner
  91. What Are Hacking Tools
  92. Pentest Tools Open Source
  93. World No 1 Hacker Software
  94. Hack Tools 2019
  95. Hackers Toolbox
  96. How To Hack
  97. Top Pentest Tools
  98. Hack Apps
  99. Github Hacking Tools
  100. Hacking Tools For Windows Free Download
  101. Hack Tools
  102. Hack Tools For Windows
  103. Pentest Tools Bluekeep
  104. Hacking App
  105. Hack Rom Tools
  106. Hacking Tools Pc
  107. Pentest Tools Android
  108. Pentest Tools Kali Linux
  109. Hacker Tools Linux
  110. Hacker Tools Online
  111. Hacker
  112. Hack Tools For Mac
  113. Pentest Tools Bluekeep
  114. Pentest Tools Website Vulnerability
  115. World No 1 Hacker Software
  116. Hacking Tools Kit
  117. Hack Tools
  118. Nsa Hack Tools Download
  119. Easy Hack Tools
  120. Hack Tools Online
  121. Hack Tools Github
  122. Hacking Tools Kit
  123. Physical Pentest Tools
  124. Hack Tools For Pc
  125. Hacking Tools For Kali Linux
  126. Hacker Tools For Ios
  127. Android Hack Tools Github
  128. Best Hacking Tools 2020
  129. Underground Hacker Sites
  130. World No 1 Hacker Software
  131. Hack Tools For Pc
  132. How To Install Pentest Tools In Ubuntu
  133. Usb Pentest Tools
  134. Hacking Tools
  135. Pentest Tools Github
  136. How To Make Hacking Tools
  137. Hacker Tools Free Download
  138. Best Hacking Tools 2019
  139. Hacking Tools Pc
  140. Install Pentest Tools Ubuntu
  141. Pentest Tools Open Source
  142. Nsa Hack Tools
  143. Hacker Tools Free
  144. Pentest Tools For Windows
  145. Hacker Tools Apk Download
  146. Underground Hacker Sites
  147. Hack Tools Github
  148. Hacking Tools Windows
  149. Hacking Tools Mac
  150. Hackers Toolbox
  151. Hacking Tools Hardware
  152. Hack Tools
  153. Hack Tool Apk
  154. Termux Hacking Tools 2019
  155. Pentest Tools List
  156. Hack Tools Pc
  157. Pentest Tools For Ubuntu
  158. Hack Tools 2019
  159. Hack Website Online Tool
  160. Easy Hack Tools
  161. Hack Tools For Mac
  162. Hacking Tools For Pc
  163. Pentest Tools Free
  164. Hacker Tools For Ios
  165. Hacker Tools Windows

SANS SEC575 Mentor Class

Hi everyone,

Great news! I will be mentoring SANS 575: Mobile Device Security and Ethical Hacking in Luxembourg on Thursday evenings 18:00-20:00, starting from January 15, 2015.

Mentor classes are special, 10 week-format SANS classroom sessions that give the students time to absorb and master the same material with the guidance of a trained security professional.

Students receive all the same course materials used at SANS conferences and study at a more leisurely pace, so students will have:
  • Hardcopy set of SANS course books
  • Mentor Program study materials
  • Weekly Mentor led sessions
Prior to the weekly Mentor-led classroom sessions, students study SANS course material at their own pace. Each week, students meet with other professionals in their hometown area and the SANS mentor, who leads topical discussions pointing out the most salient features of the weekly material studied, provides hands-on demonstrations, and answer questions. The Mentor's goal is to help student's grasp the more difficult material, master the exercises, demonstrate the tools and prepare for GIAC certification.

On SANS SEC575, we will learn about mobile device infrastructures, policies and management, we will see the security models of the different platforms, like the data storage and file system architecture. We will also see how to unlock, root and jailbreak mobile devices in order to prepare them for data extraction and further testing. In the second half of the course, we will learn how to perform static and dynamic mobile application analysis, the usage of automated application analysis tools and how to manipulate application behavior. Last but not least, we will see how to perform mobile penetration testing that includes fingerprinting mobile devices, wireless network probing and scanning, attacking wireless infrastructures, using network manipulation attacks and attacks against mobile applications and back-end applications.

For more info, here is the link for the class: http://www.sans.org/mentor/class/sec575-luxembourg-15jan2015-david-szili
My Mentor bio: http://www.sans.org/mentor/bios#david-szili 

Information on the class, special discounts and applying for the class: szili_(dot)_david_(at)_hotmail_(dot)_com

Additional info can be also found at: https://www.sans.org/mentor
Some special price is also available for this course. A few examples: http://www.sans.org/mentor/specials

Best regards,
David

Such low price. Very SANS. Much learning. Wow!

Related news

viernes, 28 de agosto de 2020

Ask And You Shall Receive



I get emails from readers asking for specific malware samples and thought I would make a mini post about it.

Yes, I often obtain samples from various sources for my own research.

 I am sometimes too lazy/busy to post them but don't mind sharing.
If you are looking for a particular sample, feel free to ask. I might have it.

Send MD5 (several or few samples). I cannot provide hundreds/thousands of samples or any kind of feeds. If you ask for a particular family, I might be able to help if I already have it.

Unfortunately, I do not have time to do homework for students and provide very specific sets for malware with specific features as well as guarantee the C2s are still active.  Send your MD5(s) or at least malware family and I check if I have it :) If i have it, I will either send you or will post on the blog where you can download.

If you emailed me in the past and never got an answer, please remind me. Sometimes emails are long with many questions and I flag them to reply to later, when I have time and they get buried or I forget. It does not happen very often but accept my apologies if it happened to you.

Before you ask, check if it is already available via Contagio or Contagio Mobile.
1. Search the blog using the search box on the right side
2. Search here https://www.mediafire.com/folder/b8xxm22zrrqm4/BADINFECT
3. Search here https://www.mediafire.com/folder/c2az029ch6cke/TRAFFIC_PATTERNS_COLLECTION
4. Search here https://www.mediafire.com/folder/78npy8h7h0g9y/MOBILEMALWARE

Cheers,  Mila

Related links


Social Engineering Pentest Professional(SEPP) Training Review

Intro:
I recently returned from the new Social Engineering training provided by Social-Engineer.org in the beautiful city of Seattle,WA, a state known for sparkly vampires, music and coffee shop culture.  As many of you reading this article, i also read the authors definitive book Social Engineering- The art of human hacking and routinely perform SE engagements for my clients. When i heard that the author of the aforementioned book was providing training i immediately signed up to get an in person glance at the content provided in the book. However, i was pleasantly surprised to find the course covered so much more then what was presented in the book.

Instructors:



I wasn't aware that there would be more then one instructor and was extremely happy with the content provided by both instructors. Chris and Robin both have a vast amount of knowledge and experience in the realm of social engineering.  Each instructor brought a different angle and use case scenario to the course content. Robin is an FBI agent in charge of behavioral analysis and uses social engineering in his daily life and work to get the results needed to keep our country safe. Chris uses social engineering in his daily work to help keep his clients secure and provides all sorts of free learning material to the information security community through podcasts and online frameworks.



Course Material and Expectation: 
I originally thought that the material covered in class would be a live reiteration of the material covered in Chris's book. However, I couldn't have been more wrong !!  The whole first day was about reading yourself and other people, much of the material was what Robin uses to train FBI agents in eliciting information from possible terrorist threats. Each learning module was based on live demo's, nightly labs, and constant classroom interaction. Each module was in depth and the level of interaction between students was extremely useful and friendly. I would say the instructors had as much fun as the students learning and sharing social techniques and war stories.
The class was heavily made up of ways to elicit personal and confidential information in a way that left the individuatial "Happier for having met you".  Using language, body posture and social truisms as your weapon to gather information, not intended for your ears, but happily leaving the tongue of your target.
Other class activities and materials included an in depth look at micro expressions with labs and free extended learning material going beyond the allotted classroom days.  Also break out sessions which focused on creating Phone and Phishing scripts to effectively raise your rate of success. These sessions were invaluable at learning to use proper language techniques on the phone and in email to obtain your objectives.

Nightly Missions/Labs: 
If you think that you are going to relax at night with a beer. Think again!! You must ensure that your nights are free, as you will be going on missions to gain information from live targets at venues of your choice.  Each night you will have a partner and a mission to gain certain information while making that persons day better then it started.  The information  you are requested to obtain will change each night and if done properly you will notice all of the material in class starting to unfold.. When you get to body language training you will notice which targets are open and when its best to go in for the kill. You will see interactions change based on a persons change in posture and facial expressions. Each day you will take the new techniques you have learned and put them into practice. Each morning you have to report your findings to the class..
During my nightly labs i obtained information such as door codes to secured research facilities, information regarding secret yet to be released projects.  On the lighter side of things i obtained much personal information from my targets along with phone numbers and invitations for further hangouts and events. I made many new friends inside and outside of class.
There were also labs within the confines of the classroom such as games used to solidify your knowledge and tests to figure out what kind of learner you are. Technical labs on the use of information gathering tools and ways to use phone and phishing techniques to your advantage via linguistically and technologically. Essentially the class was about 60% interaction and labs.


Proof it works:
After class i immediately had a phishing and phone based contract at my current employment. I used the email and phone scripts that we created in class with 100% click rate and 100% success in phone elicitation techniques. Gaining full unfettered access to networks through phone and email elicitation and interaction. Although I do generally have a decent SE success rate, my rates on return are now much higher and an understanding of what works and what doesn't, and why are much more refined.


Conclusion and Certification:
I paid for this class out of pocket, including all expenses, hotels, rentals cars and planes etc etc. I would say that the class was worth every penny in which i paid for it. Many extras were given including black hat passes, extended training from notable sources and continued interaction from instructors after class ended. I would highly recommend this class to anyone looking for a solid foundation in social engineering or a non technical alternative to training.  You will learn a lot, push yourself in new ways and have a blast doing it. However I did not see any sparkly vampires while in seattle.... Twilight lied to me LOL
The certification is a 48 hour test in which you will utilize your knowledge gained technologically and socially to breach a company.I am not going to give away to much information about the certification as i haven't taken it yet and I do not want to misspeak on the subject. However I will say that social-engineer.org has done an excellent job at figuring out a way to include Real World Social Engineering into a test with verifiable proof of results. I am going to take my test in a couple weeks and it should be a blast!!!

Thanks and I hope this review is helpful to all those looking for SE training.  I had a blast :) :)

Related posts


  1. Hacker Search Tools
  2. How To Make Hacking Tools
  3. Hacking Tools For Windows
  4. Growth Hacker Tools
  5. Underground Hacker Sites
  6. Best Hacking Tools 2019
  7. Hacker Tools For Ios
  8. Hacking Tools For Pc
  9. Nsa Hack Tools Download
  10. Hacker Tools For Mac
  11. Hacker Tools 2019
  12. Tools 4 Hack
  13. Hacking Tools Kit
  14. Hack Tools For Pc
  15. Physical Pentest Tools
  16. Beginner Hacker Tools
  17. New Hack Tools
  18. Pentest Tools Github
  19. Pentest Tools Bluekeep
  20. Hacker Tools Linux
  21. Hack Tools For Pc
  22. Pentest Tools Online
  23. World No 1 Hacker Software
  24. Hacking App
  25. Tools 4 Hack
  26. Hacker Tools Free
  27. Hacker Tools Mac
  28. Hacking Tools For Beginners
  29. Hacker Hardware Tools
  30. New Hacker Tools
  31. Hacker Tools Online
  32. Hack Tool Apk No Root
  33. Hacking Tools
  34. Best Hacking Tools 2020
  35. Hacker Tool Kit
  36. Hacker Tools List
  37. Hacker Search Tools
  38. Hack Tools For Games
  39. Pentest Tools Find Subdomains
  40. Hacking Tools Windows 10
  41. Hacker Tools
  42. Hacking Tools Usb
  43. Pentest Tools Github
  44. Black Hat Hacker Tools
  45. Hacking Tools Kit
  46. Pentest Tools Apk
  47. Hacker Tools 2020
  48. Blackhat Hacker Tools
  49. Hacker Tools Free Download
  50. Hack Tools For Ubuntu
  51. World No 1 Hacker Software
  52. Hacking Tools For Windows
  53. Black Hat Hacker Tools
  54. Android Hack Tools Github
  55. Wifi Hacker Tools For Windows
  56. Hacker Tools 2019
  57. Pentest Reporting Tools
  58. Hack Tools
  59. Hacking Tools Windows
  60. Pentest Tools For Mac
  61. Hacking Tools Mac
  62. Hack Rom Tools
  63. Pentest Tools Kali Linux
  64. Pentest Reporting Tools
  65. Hacker Tools List
  66. Pentest Tools For Mac
  67. Hacking Tools Kit
  68. Bluetooth Hacking Tools Kali
  69. Hacker Tools Software
  70. Hacker Tools Online
  71. Hak5 Tools
  72. What Are Hacking Tools
  73. Hack App
  74. Hack Rom Tools
  75. Underground Hacker Sites
  76. Pentest Tools
  77. Tools For Hacker
  78. Hack Tools 2019
  79. Hacking Tools For Games
  80. Best Hacking Tools 2019
  81. Hack And Tools
  82. Hacker Tools Windows
  83. Hacking Tools Software
  84. Hacking Tools Windows 10
  85. Hacker Tools Linux
  86. Hacking Tools Github
  87. Pentest Tools Nmap
  88. Pentest Tools Online
  89. Hack Tools
  90. Black Hat Hacker Tools
  91. Hacker Techniques Tools And Incident Handling
  92. New Hack Tools
  93. World No 1 Hacker Software
  94. Pentest Tools Tcp Port Scanner
  95. Hacker Search Tools
  96. Hacker Tools For Ios
  97. Pentest Tools Bluekeep
  98. Free Pentest Tools For Windows
  99. Pentest Tools Linux
  100. Hack Tools For Ubuntu
  101. Growth Hacker Tools
  102. Pentest Tools Alternative
  103. Ethical Hacker Tools
  104. Pentest Tools For Android
  105. Pentest Tools For Ubuntu
  106. Hacker Tools Online
  107. Hack Tools For Mac
  108. Hacker Tools Online
  109. Hacker Hardware Tools
  110. Pentest Tools List
  111. Hacker Tools Apk
  112. Hacking Tools Pc
  113. Pentest Tools Android
  114. Hacking Tools And Software
  115. Hacking Tools Windows
  116. Hacking Tools Mac
  117. Pentest Tools Review
  118. Hack Tools
  119. What Are Hacking Tools
  120. Pentest Tools For Android
  121. Hack Tools Mac
  122. Hacking Tools For Windows
  123. Hacking Tools For Mac
  124. Hacking Tools For Windows Free Download
  125. Pentest Automation Tools
  126. Hack Tools For Pc
  127. Install Pentest Tools Ubuntu
  128. Hacking Tools Name
  129. Hacking Tools For Beginners
  130. Pentest Tools For Android
  131. Hacking Tools For Windows 7
  132. Nsa Hacker Tools
  133. Hack Tools Download
  134. Pentest Tools Tcp Port Scanner
  135. Hack Tools For Games
  136. Hacking Tools Hardware
  137. Game Hacking
  138. Top Pentest Tools
  139. Hacker Tools For Pc
  140. Hacker Search Tools
  141. Hacker Tools
  142. Hack Tools For Pc
  143. Pentest Tools List
  144. Hacking Tools Name
  145. Nsa Hacker Tools
  146. Hack And Tools
  147. Physical Pentest Tools
  148. Hacking Tools Online
  149. Growth Hacker Tools
  150. Android Hack Tools Github
  151. Hacks And Tools
  152. Tools For Hacker
  153. Pentest Tools Download
  154. Hacker Tools 2019
  155. Hacker Security Tools
  156. Pentest Tools Port Scanner
  157. Pentest Tools Framework
  158. Pentest Tools Review
  159. Hacker Hardware Tools
  160. Hacker Tools Hardware
  161. Pentest Tools Android
  162. Hacking Tools For Games
  163. Pentest Tools Bluekeep
  164. Hacker Techniques Tools And Incident Handling
  165. Hacker Tools For Mac
  166. Hacker Tools Github
  167. Hacking Tools 2020
  168. Usb Pentest Tools
  169. Free Pentest Tools For Windows
  170. Hack Tools Pc