Showing posts with label Infosec. Show all posts
Showing posts with label Infosec. Show all posts

Friday, 2 March 2012

OWASP Galway Begins!

Ok, this is a very short post as I am a tad busy, but, as of today (Friday, March Second, 2012), Galway (Ireland) has its own OWASP chapter setup by infodox!

Meetings are being prepared, as are workshops, talks and such, so watch this space for updates!

I will post links to its wiki/blog/etc later on today :)

check out OWASP stuff at OWASP.ORG

Monday, 6 February 2012

Denial of Service Attacks, Layer 7

This is a brief reposted post (one I wrote ages back) on how Layer 7, or "Application Layer" Denial of Service Attacks work.

Application Layer DoS attacks are a newer form of DoS attack. They work by not simply flooding/saturating the servers bandwidth, but by attacking a specific service, or application, running on the server. They often require far less bandwidth to accomplish, and are far more "efficient" an attack method. No massive botnets are required for an attacker to be able to effectively take out the target service.

I first got interested in Layer 7 DoS after realizing that LOIC and such "packet flooders" were essentially next to useless. TCP flooding was bandwidth intensive and required either a horde of fools, a large botnet, or a fucking huge datapipe to accomplish (a few cheap VPS's, however, made the job easier...). Sure, you could use spoofing and such attacks to enhance your "firepower", but when up against *big* targets with fairly impressive filtering, you were essentially wasting resources.

For those of you unfamiliar with Layer 7 DoS attacks, have a read of this paper from OWASP - it was what gave me my head start in understanding it all.
Layer 7 DoS - OWASP

Now. Onward to the "attack techniques". The series I wrote on DoS attacks was all about explaining what attack methods are used where, and seeing as the only edits done in this repost were a quick spellcheck and this comment, I do not plan on editing very much else. Yes, I am lazy.

HTTP GET DoS / SlowLoris Attack.
Wikipedia on Slowloris
Original page explaining it

Now, first off, list of affected target webservers:

  • Apache 2.x 
  • Apache 1.x
  • dhttpd
  • GoAhead WebServer
  • WebSense "block pages" (unconfirmed)
  • Trapeze Wireless Web Portal (unconfirmed)
  • Verizon's MI424-WR FIOS Cable modem (unconfirmed)
  • Verizon's Motorola Set-Top Box (port 8082 and requires auth - unconfirmed)
  • BeeWare WAF (unconfirmed)
  • Deny All WAF (unconfirmed) 
All of these are (according to RSnake), affected by the SlowLoris technique.

How it works is simple, it asks the server to wait. The server, being nice, waits. It does this simulating over9000 clients. The server keeps on waiting, being nice. Server dies, pretty much.

Now, to the interesting part. Attack Tools.
Original Slow Loris
TOR Loris - SlowLoris w/ Multiple TOR Proxies
PyLoris - Python SlowLoris
In Development: FluxLoris (Rapid SOCKS switching SlowLoris implementation)

HTTP POST DoS Attack (SlowPost)
This one was inspired by the OWASP paper I referred to above, and we released a PoC tool to exploit the bug around Christmas 2010. I worked on developing the tool and learned a LOT. Basically you are uploading (POST-ing) data to the server and saying "Hey, you! I am on a laggy connect! Please wait!". The server waits... And waits... You keep the connection open.
You do this with a literal shitload of threads.

It requires bugger all bandwidth and has a very destructive effect, rendering most webservers 404-ed within a few minutes.

So, here was our initial PoC tool:
POST-it v1

We had a more "lethal" variant but it is lost long ago, maybe some day I will dig it up and re-implement it, but given current climate, no point.

Now, onward, there are far better attack tools!
SlowPost by NEC - This one is VERY nice. Uses Proxy lists to anonymize the attack. Was written by the current mantainer of the "LOIC" package I believe.

OWASP HTTP POST DoS - This one is from OWASP, and seems to be moreso for testing.

R U Dead Yet - This one is considered the "industry standard" for HTTP POST DoS attacks. It works. Most of the time. I know of some unusual errors it has thrown in the past, but it has TOR support.

And finally, the well known and loved TORSHAMMER . This one is incredibly effective, known to drop servers within minutes. Anecdotal evidence has it one guy on a DSL line took out a bunch of Iranian government websites for a half hour a year or so ago, and then ate the Libyan .gov servers for second helpings! It works fairly reliably, and uses TOR.

There are a great deal of other attack tools out there exploiting these weaknesses, but the best bet (for now) to avoid the embarassment of someone taking you down a peg with some of these is to use the NGINX platform for a webserver. It works fairly well and seems to just blatantly ignore these attacks.

Further Reading...
Testing Webservers for Slow HTTP Attacks
http://en.wikipedia.org/wiki/Denial-of-service_attack
http://www.acunetix.com/blog/web-security-zone/articles/http-post-denial-service/
http://www.us-cert.gov/cas/tips/ST04-015.html
http://isc.sans.edu/diary.html?storyid=6601
http://www.funtoo.org/wiki/Slowloris_DOS_Mitigation_Guide
http://www.checkpoint.com/defense/advisories/public/announcement/071409-slowloris-dos-attack.html
http://www.bullten.com/what-is-slowiris-ddos-attack-and-how-to-mitigate-its-effect/

Wednesday, 1 February 2012

Bricked!

Ok, so I did SOMETHING wrong with SVN and broke 2 of my SVN repos. I also seem to have broken several other things on my computer, so its time for the infamous rm -rf and restart.

I will be documenting every thing I change, I am starting with XUbuntu 10.04 and will be turning it into a bit of a pentesting distro. Compiling lots of shit from source, apt-getting lots of other shit, and generally fucking about until it works.

If you are looking for nice information on making your own PT distro, watch this space. I will be logging every last thing I do, from the MetaSploit Install to compiling nmap, and it may be interesting to some of you :)

Seeing as I focus a lot on Wireless and Web App testing you will see a lot of focus on those applications, and on making MSF work from source.

Hope you find it useful and interesting - I will be doing it all over the next few hours :D

Monday, 30 January 2012

Web Application Backdoors Collection: v2.0

This is the SVN for web app backdoors. As I find em, I add em. I also try purge dupes time to time, but have not yet got a good method of doing so just yet.

I also plan to eventually analyse them for backdoors, so if you find a backdoor in one please mail me so I can mark it as backdoored.

Finally, I take NO RESPONSIBILITY WHATSOEVER for ANY use of this collection, it is designed for educational purposes and so you AV people can write signatures for this shit.

So SVN UP!!

Web Shell Collection

Sunday, 22 January 2012

802.11 Race Condition Exploitation

802.11 Race Condition Exploitation

This post is about the Race Condition Exploitation method for "hijacking" WiFi clients.

Basically how it works is, the client sends a GET request for whatever. You respond with a 301 redirect to your content.

How you do this is by sniffing the traffic, and when you see a GET you inject a 301 to the client and a FIN or RST to the AP. You essentially pretend to be the access point for a second.

SO far there are several variants out there, including a Metasploit module. It can be found in auxiliary/spoof/wifi/airpwn

The technique was originally demoed by "toast" at DEFCON 12, and used to replace images with shock porn like Goatse or Tubgirl.

Some links of interest...

http://evilscheme.org/defcon/
http://airpwn.sourceforge.net/Airpwn.html
http://sourceforge.net/projects/airpwn/
http://securitysumo.wordpress.com/2008/04/22/running-airpwn/

Aaaaand some video...



So naturally, I wondered. I can inject images and javascript... So what about executables? (you see where I am going...)

Then I found someone else was doing this exact thing with updates. Hijacking them ala airpwn. Their tool is named "IPPON", and is very interesting, albeit buggy as fuck. If you can make it work, please god message me!

Here be their presentation from DEFCON 17, and their code!
http://www.slideshare.net/itzikk/ippondefcon17
http://code.google.com/p/ippon-mitm/

Now on to the best of the bunch (IMO). RCX. Developed by Melchi Salins, it allows you to do *anything*, is written in Python using SCAPY, and generally is fucking BADASS! With it, you can redirect ANYTHING to ANYTHING.

http://rcx.sourceforge.net/rcx.html

Coming Soon... The RCX config file for mass update hijacking!

##

Ok. Comments were asking for how to install AirPwn in Ubuntu 10.04/Back Track 5.

Here is how it is SUGGESTED to do it...

http://www.timashley.me/node/718


Now I found the second part of that (install lorcon + airpwn) did not work for me. So... I did things a bit differently.

Check out this LaunchPad: https://launchpad.net/~nagos/+archive/ppa?field.series_filter= 

Now, I simply grabbed the .deb files for Airpwn and Liblorcon from there.
Install Liblorcon FIRST. Then Airpwn.

However, this PPA should work fine also: ppa:nagos/ppa

It just didn't work for me :P

Friday, 13 January 2012

MITM w/ ARP Toxin and Driftnet - Video + Tool

Quick into video about using ARP Toxin to preform MITM attacks, with extra fun involvin' using Driftnet to sniff images sent across the network.



Code is here -- Sauce Code

Bug reports and suggestions welcome!
Video made for CampusCon :D

Thursday, 5 January 2012

Collection of web app backdoors (v1)

This is a collection of the common PHP (and ASP if I find them) backdoors used by malicious hackers to take over servers.
I am NOT responsible for your use of this!


Warning: There is every possibility these backdoors may be backdoored. I am going to eventually sort them into two folders - backdoored backdoors and clean backdoors. Then I can sit back and watch y'all go apeshit at some skiddies who backdoor their backdoors :D


Download the list here...Web Backdoors