[+] Wayc0de's Blog[+]

29/08/11

24 August 2011 | 2,803 views Stealing ATM Pin Numbers Using Thermal Imaging Cameras

Now this is a really neat bit of hardware hacking, it’s been a while since we’ve reported on any kind of ATM Skimming or ATM Hacking stories.

You may remember back in November 2010 – European Banks Seeing New Wave Of ATM Skimming or way back in 2008 when Pro ATM Hacker ‘Chao’ Gives Out ATM Hacking Tips.

The latest is this neat hack that came out of a method outlined by Michal Zalewski back in 2005:
Cracking safes with thermal imaging

Security researchers have found that thermal cameras can be combined with computer algorithms to automate the process of stealing payment card data processed by automatic teller machines.

At the Usenix Security Symposium in San Francisco last week, the researchers said the technique has advantages over more common ATM skimming methods that use traditional cameras to capture the PINs people enter during transactions. That’s because customers often obscure a camera’s view with their bodies, either inadvertently or on purpose. What’s more, it can take a considerable amount of time for crooks to view the captured footage and log the code entered during each session.
 Thermal imaging can vastly improve the process by recovering the code for some time after each PIN is entered. Their output can also be processed by an algorithm that automates the process of translating it into the secret code.

The hack works extremely efficiently on ATMs using plastic keypads, it will not work on metal keypads and this method works up to 60 seconds after you’ve used the ATM.

I’m not sure about you guys but all the ATMs I’ve seen here are using metal keypads, so it wouldn’t work too well over here.
Either way it’s a fairly cool hack and I’m glad to see, so far there’s no proof of thieves using it in the wild.
The findings expand on 2005 research from Michal Zalewski, who is now a member of Google’s security team. The Usenix presenters tested the technique laid out by Zalewski on 21 subjects who used 27 randomly selected PINs and found the rate of success varied depending on variables including the types of keypads and the subjects’ body temperature.

“In summary, while we document that post-hoc thermal imaging attacks are feasible and automatable, we also find that the window of vulnerability is far more modest than some feared and that there are simple counter-measures (i.e., deploying keypads with high thermal conductivity) that can shrink this vulnerability further still,” the researchers wrote.
I wonder if we’ll see a spate of real life attacks based around this technique now the paper has been published publicly.

You can grab the paper discussing the technique here: Heat of the Moment: Characterizing the Efficacy of Thermal Camera-Based Attacks [PDF].

nb : darknet Read More...

26/08/11

Was this the email that took down RSA?

A spear phishing email that has surfaced in a security database looks like it may have been the one to hit RSA

"I forward this file to you for review. Please open and view it."

As a ploy to get a hapless EMC recruiter to open up a booby-trapped Excel spreadsheet, it may not be the most sophisticated piece of work. But researchers at F-Secure believe that it was enough to break into one of the most respected computer security companies on the planet, and a first step in a complex attack that ultimately threatened the security of major U.S. defense contractors including Lockheed Martin, L-3, and Northrop Grumman.

[ Learn how to greatly reduce the threat of malicious attacks with InfoWorld's Insider Threat Deep Dive PDF special report. | Stay up to date on the latest security developments with InfoWorld's Security Central newsletter. ]

The email was sent on March 3 and uploaded to VirusTotal a free service used to scan suspicious messages, on March 19, two days after RSA went public with the news that it had been hacked in one of the worst security breaches ever.

Researchers at F-Secure, the company that discovered the message Monday, believe that it was very likely the message that led to the RSA compromise. If true, the finding sheds light on the kind of trickery, called social engineering by security pros, it takes to break into a major security company.

F-Secure antimalware analyst Timo Hirvonen discovered the email message buried in the millions of submissions stored in this crowd-sourced database of malicious or potentially malicious files. VirusTotal lets computer users upload a suspicious file, say an Excel spreadsheet that might be infected, and have it scanned by over 40 of the world's top antivirus companies. In return for the free scan, the AV vendors get to examine the files, making the service a great way of learning about malicious software after the fact.

Hirvonen had been searching VirusTotal's database for the RSA attack file ever since RSA acknowledged that it had been compromised. The hackers had sent two different phishing emails to small groups of company employees over a two day period, but nobody outside of RSA and its parent company EMC knew the full contents of those messages. It wasn't even clear if they were included in VirusTotal's data.

RSA has released some details about the attack, but Hirvonen's find is a first look at just what it took to get an EMC employee to open that dangerous attachment.

"The email was crafted well enough to trick one of the employees to retrieve it from their Junk mail folder, and open the attached Excel file," wrote RSA Head of New Technologies Uri Rivner in the April 1 blog posting that laid out most of what RSA has said publicly about the email. "It was a spreadsheet titled "2011 Recruitment plan.xls."

Hirvonen didn't know for sure he'd find the email in VirusTotal, but he thought that there was a chance that someone at RSA had uploaded to see what it was. Searching for the 2011 Recruitment Plan spreadsheet yielded nothing, however.

But this month Hirvonen finished up a data analysis tool that allowed him to find his needle in the Virus Total haystack. His technique: he scoured the data for flash objects -- software written to run in Adobe's Flash Player -- that looked like they may have been used in the RSA attack. RSA had previously said that the hackers used software that took advantage of a bug in Adobe Flash and offered some technical details on the attack.

 "It was a difficult one to find," Hirvonen said. "We had to work really hard to find it."

With his new tool, Hirvonen quickly discovered a Microsoft Outlook .msg file. When he opened it up, he knew he was onto something. Inside was a message that had been spoofed to look like it had come from recruiting website Beyond.com. "I forward this file to you for review. Please open and view it," the message read. The subject: "2011 Recruitment plan." The attachment: an Excel spreadsheet entitled "2011 Recruitment plan.xls"

Looking closer, Hirvonen found that the file seemed to match RSA's description in possible every way. The Excel file contained the same Flash attack code; It used the same remote control software, called Poison Ivy, and it tried to connect to the same Internet address as RSA's attacker.

The email was sent to EMC employees, apparently in the human resources department, and looked like it came from webmaster@beyond.com, a generic address from a website that has listed EMC jobs in the past. But that was a spoofed address, Hirvonen said. In reality the email wasn't sent from the Beyond.com servers.
F-Secure believes that it's one of the two spearphishing emails used to target RSA.

In the past, RSA characterized the hacking incident as an "extremely sophisticated cyber attack," but if this is indeed the email used to break in, it illustrates a guiding principle of these cyber espionage attacks -- the hackers will use anything that works, even simple tricks. If they fail, they will try again and again until they break through.

The key, security experts say, is in spotting the attackers and keeping them from moving around the network once they've broken in.

Reached Thursday, EMC's RSA Security group was reluctant to say anything about the message. RSA wouldn't say if there were any differences between Hirvonen's email and the one that compromised the company. The company wouldn't confirm that it was the one that got the attackers in, either. "Can we validate that this is the actual email?" said RSA spokeswoman Helen Stefan. "No."

If this was the attack that wedged open RSA's security, it wasn't as sophisticated as others have been, said Alex Stamos, a partner with iSec Partners, a security consultancy that is part of NCC Group. "That's a pretty embarrassing example for RSA," he said. "It tells you that in any reasonably sized company, including a security company, there's someone who will do something really dumb."

By Robert McMillan Read More...

Researchers Discover File Used to Hack RSA

Researchers at anti-malware company F-Secure say they have found the actual infected Excel file that was used in the attack on RSA earlier this year, eventually forcing the company to replace millions of its SecurID tokens. The Outlook email message containing the malicious file apparently was uploaded to Virustotal in March and the researchers dug it out this week.

If the message and attachment that F-Secure researcher Timo Hirvonen found is indeed the same one used in the RSA attack--and the file name and description do fit what RSA has said publicly--then neither the attack nor the message's social engineering tactics appear to very sophisticated. The subject line of the email is "2011 Recruitment Plan" and the Excel attachment had the same name. The email appeared to come from the address "webmaster [at] beyond dot com", a job recruitment site.

The email itself contains just one line of text, which in the grand tradition of phishers everywhere, is in fourth-grade English:

"I forward this file to you for review. Please open and view it." That's the entire contents of the message. Once the victim double-clicked on the Excel file, it opened a spreadsheet with no real contents other than the malicious Flash object that then exploited a Flash vulnerability. The exploit then plants the Poison Ivy backdoor on the machine and the attack is over.

"After this, Poison Ivy connects back to it's server at good.mincesur.com. The domain mincesur.com has been used in similar espionage attacks over an extended period of time. Once the connection is made, the attacker has full remote access to the infected workstation. Even worse, it has full access to network drives that the user can access. Apparently the attackers were able to leverage this vector further until they gained access to the critical SecurID data they were looking for," F-Secure Chief Research Officer Mikko Hyponnen wrote in a blog post. 

A Virustotal employee said on Twitter Friday morning that the same file, albeit with a different name, was submitted to the malware-checking service by a separate user, as well.
The details of the RSA attack and the message used to execute it show how difficult it can be to prevent intrusions, even when they involve relatively simplistic tactics. RSA officials have said that the message was sent to four of its employees and it was in fact caught by the company's spam filters. However, one of the targeted employees pulled the email from the spam folder, opened it and opened the attachment. That's just simple human error, which was then combined with a Flash zero-day vulnerability to compromise RSA and its SecurID product.

"The attack email does not look too complicated. In fact, it's very simple. However, the exploit inside Excel was a zero-day at the time and RSA could not have protected against it by patching their systems," Hyponnen wrote. "The email wasn't advanced. The backdoor they dropped wasn't advanced. But the exploit was advanced. And the ultimate target of the attacker was advanced. If somebody hacks a security vendor just to gain access to their customers systems, we'd say the attack is advanced, even if some of the interim steps weren't very complicated."
Read More...

MIT researchers craft defense against wireless man-in-middle attacks

Protocol can detect message tampering essential to these exploits

MIT researchers have devised a protocol to flummox man-in-the-middle attacks against wireless networks. The all-software solution lets wireless radios automatically pair without the use of passwords and without relying on out-of-band techniques such as infrared or video channels.

Dubbed Tamper-evident pairing, or TEP, the technique is based on understanding how man-in-the-middle attacks tamper with wireless messages, and then detects and in some cases blocks the tampering. The researchers suggest that TEP could have detected the reported but still unconfirmed cellular man-in-the-middle attack that unfolded at the Defcon conference earlier this month in Las Vegas.

[ Learn how to greatly reduce the threat of malicious attacks with InfoWorld's Insider Threat Deep Dive PDF special report. ]

MORE RESEARCH: With SSL, who can you really trust?

TEP was devised by a quartet of MIT researchers: Shyamnath Gollakota, Nabeel Ahmed, Nickolaik Zeldovich and Dina Katabi, all with the Department of Electrical Engineering and Computer Science. Their research paper, "Secure in-band wireless pairing," was presented at the recent Usenix Security Symposium and MIT has its own story about the research online.

The group says TEP can be used to protect communications between devices, or between devices and base stations or access points, for any type of wireless connection.

Today, two wireless devices create a secure channel by swapping cryptographic keys, typically using what's known as the Diffie-Hellman Exchange. DHE is a cryptographic protocol designed to let two parties who don't know each other agree on a shared secret cryptographic key over an unsecured channel. Then, they use the key to encrypt their exchanges. (More on recent recognitions for Whitfield Diffie and Martin Hellman)
But Diffie-Hellman suffers from a well-known problem: An attacker inserts himself between the two parties and, for each one, pretends to be the other, sending each one his own Diffie-Hellman message. Both parties end up sharing their secret key with the attacker, who then has full access to the communications between them.

Passwords can be used to block such attacks, but there are problems. On public networks, users often have the same password. Other networks are protected with very weak passwords, or with none at all. Some use such standards as the Wi-Fi Alliance's Wi-Fi Protected Setup or Bluetooth's simple wireless pairing, a kind of push-button approach to secure connections. But these, too, are based on the Diffie-Hellman Exchange and remain vulnerable to the man-in-the-middle attack.

Another solution is to use "non-wireless" or out-of-band channels, such as audio or infrared, to authenticate and secure the channel. But these, the researchers say, can be costly and hard to adapt to small, resource-constrained wireless devices.

TEP begins by analyzing how an attacker mounts a man-in-the-middle exploit: In every case, the researchers say, the attack involves tampering with wireless messages. The researchers say they've identified these tampering techniques and can detect when they're being used. "Since we can [now] detect tampering, we can [now] trust messages which are untampered with," according to the group's Usenix presentation.

An attacker can tamper with a wireless message in three ways: by altering a message sent by one party to match his own Diffie-Hellman key; by hiding the fact that Party A has sent a message at all; and by blocking a message from being sent. TEP is designed to defang each of these tampering techniques.

It does this by compelling Party A to follow its message transmission with another: a pattern of energy "pulses" and "silences." Party A's wireless radio computes a hash of the original message, creating a sequence of ones and zeros. For each one, the radio sends a random packet; for each zero, it sends nothing -- it's silent. This combined pattern is unique to the original message.

If the attacker alters the contents of Party A's message, he, too, has to follow up with a new "silence pattern" that corresponds to the altered contents. But the two silence patterns will be different: The attacker "cannot generate silence" from Party A's "one bits." Party B can detect that difference and in effect refuse the connection offered by the attacker.

The second type of tampering is when a man-in-the-middle attacker hides Party A's transmission simply be sending its own packets and creating a collision with it. Party B sees this as a known and common event and ignores the attempted transmission by Party A.

TEP counters this by adding an unusually long, and random, synchronization packet to Party A's transmission. The packet length in effect causes it to "stand out" as not being a collision. Party B looks for these unusually long energy periods and treats them as an attempt by another party to pair with it. The attacker can't hide it by generating collisions, and if he sends his own long packet, Party B can detect it as an "unusual message."

The third tampering technique involves an attacker blocking transmissions by occupying continuously the radio channel, in effect, not giving Party A the chance to "talk" to Party B. TEP counters this by having Party A's radio time out after a known interval and transmit its message even if the channel is occupied.
"Thus we have a [transmit] message which can't be altered, hidden, or prevented without being detected at the receivers," say the MIT researchers.

But there's a potential flaw in this approach, as they note: TEP uses silent periods to authenticate communications. Other Wi-Fi devices listening on the channel would assume the silences mean the channel is open, and attempt their own transmission in keeping with the 802.11 protocol. To prevent this, TEP uses an optional mechanism in 802.11, called "clear to send" or CTS, which is a frame that reserves the channel for a given transmitter. Other Wi-Fi devices seeing the CTS frame would hold off on transmitting until Party A completes its hash transmission.

Having created this "tamper evident message," the MIT team created a protocol to implement it as part of setting up a secure wireless pairing between radios, riding on top of the push-button technique adopted via the Wi-Fi Alliance. Party A sends out a request message using the TEP primitive; Party B must reply using the same primitive within 120 seconds. If Party A receives only one reply in that time frame, and via TEP detects no tampering, the pairing goes forward.

But if an attacker tries to insert himself between the two parties, two things can happen to frustrate his attempt. First, Party A sees two replies to the original request, one from Party B and one from the attacker, and refuses to connect. Second, if the attacker tries to tamper with the Party B's reply message, TEP lets Party A detect the tampering and, again, refuse to connect.

The researchers streamlined this entire process of exchanging tamper-evident messages in order to set up a secure channel. They say that the hash and the longer synchronization packet add less than 23 milliseconds of overhead to the transmission.

 nb : infoworld & John Cox

 

Read More...

Scariest IPv6 attack scenarios

As IPv6 picks up, so too is the number of attacks that target known vulnerabilities in the protocol

Experts are reporting a rise in the number of attacks that take advantage of known vulnerabilities of IPv6, a next-generation addressing scheme that is being adopted across the Internet. IPv6 replaces the Internet's main communications protocol, which is known as IPv4.

Salient Federal Solutions, a Fairfax, Va., IT engineering firm, is reporting real-world incidents of IPv6 attacks based on the emerging protocol's tunneling capabilities, routing headers, DNS broadcasting and rogue routing announcements. The company asserts that all of these threats can be eliminated with the use of IPv6-enabled deep packet inspection tools, which it and other network vendors sell.

[ Find out how to block the viruses, worms, and other malware that threaten your business, with hands-on advice from InfoWorld's expert contributors in InfoWorld's "Malware Deep Dive" PDF guide. ]

"We definitely see these attacks, we just can't say where we are seeing them," says Lisa Donnan, who leads Salient's Cyber Security Center of Excellence. Salient Federal Solutions purchased IPv6 consulting and training firm Command Information in March.

The No. 1 attack that Salient Federal is seeing is the result of so much IPv6 traffic being tunneled across IPv4 networks, particularly using the Teredo mechanism that is built into both Microsoft Windows Vista and Windows 7. This vulnerability with IPv6-over-IPv4 tunneling has been known for at least five years, but it is still being exploited.

"IPv6 tunneling gives attackers a green light to penetrate networks," says Jeremy Duncan, senior director and IPv6 network architect for Salient Federal Systems.

BACKGROUND: Invisible IPv6 traffic poses serious network threat

Duncan is concerned about uTorrent, which is an IPv6-capable freeware client for the BitTorrent peer-to-peer protocol that's used to share large files such as music and movies. Duncan says uTorrent runs very well over Teredo, and that the BitTorrent community is discovering IPv6 as a way of avoiding network congestion controls that are used by ISPs to manage BitTorrent traffic on IPv4 networks.

Duncan says it is also easy for users of Vuze, another BitTorrent application, to prefer IPv6 over IPv4.
"BitTorrent users are discovering that they won't have throttled traffic with IPv6," Duncan says. "This is an issue for the carriers. They won't be able to throttle back the IPv6 traffic because they're not inspecting it."

Salient Federal says it is also seeing attacks with IPv6's Type 0 Routing Header, which is a feature of IPv6 that allows a network operator to identify routers along the path that it wants packets to take. The Internet Engineering Task Force recommended in 2007 that this feature of IPv6 be disabled due to the potential for its use in denial-of-service attacks, calling the threat "particularly serious."

Nonetheless, Salient Federal is seeing Routing Header Type 0 attacks on IPv6 production networks that it monitors. For example, Command Information traced this type of attack to one of its own border routers that was no longer in operation. The attack originated from a research network in China. Had it been a successful attack, it would have allowed the Chinese hacker to send malicious traffic from Command Information's compromised border router to other networks.

"Network managers have to turn this feature off in their routers," Duncan says. "This capability was shipped with all Cisco routers by default a few years ago. The newer routers have turned this feature off; the problem is with older routers."

Another IPv6-related threat comes from the way the Internet's DNS system broadcasts so-called Quad A records that are used by IPv6. Duncan says Quad A queries are present on every network that the company is monitoring, even though many of those networks are not supporting IPv6 traffic.

When Quad A queries are being broadcast, this indicates that some nodes on the network are IPv6-enabled and can then be targeted with an IPv6-based attack. Because the network itself doesn't support IPv6, it's likely that the network manager is not monitoring IPv6 traffic with deep packet inspection tools.
Duncan refers to IPv4 networks that broadcast Quad-A records as "the loaded gun."

"When companies have IPv6-enabled machines but not IPv6 enabled, hackers know that the network management for IPv6 is lacking," Duncan says. "They can easily flood the organization's mail servers with spam that contains malware. All they need is one user with elevated privileges to open one spam message with malware, and that malware can open IPv6 in a tunnel through the firewall."

Duncan points out that he hasn't seen the Quad-A vulnerability being exploited yet, but he believes it is a significant threat for enterprises.

"We haven't seen this exact exploit, but we have seen a lot of IPv6 tunneled traffic that is not being inspected," Duncan says. "Every enterprise could have tens of thousands of Quad A records being broadcast.... The solution is to lock down IPv6 if you're not using it and to use deep packet inspection."

Finally, Salient Federal is reporting that it is seeing rogue router advertisements for IPv6, although the company admits that it hasn't seen a malicious actor sending them. Rogue router announcements are a threat that the IETF warned against in February, pointing out that this vulnerability could be used for denial-of-service or man-in-the-middle attacks.

This threat comes from the fact that IPv6-enabled workstations are always listening for router announcements due to the autoconfiguration features of IPv6. However, these workstations can be fooled by fake announcements due to network administrator errors or hacking attacks. Rogue routing announcements for IPv6 are being seen in both wireless and wired networks.

"Enterprises need to deploy a fix like Cisco's RA Guard on their switches and router, but then you need to have IPv6 enabled on your core," Duncan says. "You also need to use deep packet inspection in your core."

Duncan urges companies to implement IPv6 on their networks and to put appropriate security controls such as deep packet inspection in place so that they can manage IPv6-related vulnerabilities.

"Enterprises need to make sure that their security vendors can protect against these specific IPv6 vulnerabilities,'' he says. He urges companies to get their systems and network engineers trained in IPv6 and to develop an IPv6 cybersecurity plan.

Duncan says that enterprise network managers are gaining in awareness of IPv6 but that they aren't focused enough on the related security issues. "There's not as much focus on IPv6 security as there is with IPv4 security," he says.

Donnan says this is a worry because U.S. companies are vulnerable to IPv6 attacks sent by countries such as China.

"There is state-sponsored hacker activity, and they are very savvy about IPv6," Donnan says.
Carriers and enterprises are migrating to IPv6 because the Internet is running out of addresses using IPv4. The free pool of unassigned IPv4 addresses expired in February, and in April the Asia Pacific region ran out of all but a few IPv4 addresses being held in reserve for startups. The American Registry for Internet Numbers, which doles out IP addresses to network operators in North America, says it will deplete its supply of IPv4 addresses this fall.

IPv4 uses 32-bit addresses and can support 4.3 billion devices connected directly to the Internet, but IPv6 uses 128-bit addresses and can connect up a virtually unlimited number of devices: 2 to the 128th power. IPv6 offers the promise of faster, less-costly Internet services than the alternative, which is to extend the life of IPv4 using network address translation devices.

Read more about lan and wan in Network World's LAN & WAN section.

nb : akamai.infoworld

 

Read More...