Friday, July 18, 2014

Change your password gamers

A quick note for all you online gamers out there. If you play online games, MMO's, etc and have for a while you probably have joined a fair number of online gaming boards over the years. Guild after guild most likely, plus alliance after alliance if you play EVE. A good number of those sites are running VBulletin software. If you game a lot you probably recognize a VBulletin site without even having to scroll down to the bottom and see the logo and are happy to see it and not a less friendly free forum site. Well there is a new SQLi attack for the 5.X branch of that software and the people who found it said they will release the code in the wild soon. The official announcement is here: http://www.vbulletin.com/forum/forum/vbulletin-announcements/vbulletin-announcements_aa/4097503-security-patch-release-for-vbulletin-5-0-4-5-0-5-5-1-0-5-1-1-and-5-1-2

It should be noticed this isn't the first SQLi attack found in this software over the years. But I have a feeling this one is going to be used a lot so I'm giving this warning.

For those who don't know, a SQLi attack allows people to collect data from the database the site uses to store things like, say, your username and password. VBulletin by default stores passwords using an MD5 hash and a 3 character salt. If you don't know what that means, just know it means it is easy to crack and get your password, especially weak ones. No biggie right? Well ask yourself...

On any of these numerous sites you signed up to over the years (god help EVE players they probably can't even find all the old alliance ones), how easy it is for someone to find the game or games you play and the username you use to login with? If you are good your login name is nowhere on any of these sites for most games and your account names aren't the same or a single character off from them. Some games like ESO are idiotic and force you to tell everyone your login name however. If by chance you play ESO or one of your character's name is also your login name for a game and you give that name up in posts or signatures or profiles in forums all over the Internet, ask yourself this. Did you use the same password on one or more game forum that you use to login to the game with? If so, you are either going to spend some time changing passwords, or learn a life lesson the hard way when your account is banned for gold selling or something and when you finally get it unbanned you have nothing even your characters are deleted,

Think about it. You should never use game password on forum sites, ever, ever, ever. And changing 1 character at the end isn't clever enough not to get figured out btw.

So if you are freaking right now do this:
1. Stop using your character name as your login name where you can help it (ESO aside that was a bad move on their part)
2. Never use passwords for games on any other website
3. Go change all your game passwords

If you share passwords you likely don't have a system and/or password manager. Here is some final advice.
Come up with a system to help you remember passwords without sharing them. Like incorporating part of the same of the site into the password.
Use a password manager. Here are three I like:
LastPass: Web plugin cross platform. My current option due to the cross platform, free
KeePass: Good stand alone one for Windows, I found it annoying on the Mac, free
PINs: Good stand alone on for Windows, older now but still good and doesn't need an install. The password file and the exe is all you need and it works so it is 100% portable, but Windows only, free
 

Thursday, July 17, 2014

It is time for DEF CON to grow up

I've been putting this blog post off for a while and I've read a few others like it while I've been putting it off so I almost didn't bother. But I think I have something slightly different to say so I decided it was worth it. Let me start from the beginning. DEF CON is special to me. DEF CON 8 was pure magic in my life, that was my first one and it changed my life. I've been to every one since except for one due to the birth of my child which was poor planing on my part. So what I say is with love and real feedback.

At DEF CON 8 it was also my first trip to Vegas. All the half dressed women walking around some handing out floppy disk with nude pics of themselves on them was part of the Vegas experience to me. I loved it. But that was a long time ago. I recently had to explain to a good female friend of mine that was wanting to go to DEF CON that it was probably a bad idea. I did it by explaining in detail how Hacker Jeopardy worked. Oh..she said. Then I had to explain that a good number of con goers have limited social skills and it would be highly likely for her to get stared at and inappropriately propositioned during the con and the Goons would almost certainly ignore any complaints about it. She decided not to go, which I thought was wise.

That conversation got me wondering, do I want my daughter to go when she is old enough? I've always wanted that since I had kids but the more I think of it, the more the answer is no, unless the con grows up. It will be a world she will be unfamiliar with and I don't want to expose it to her in that way. In short, DEF CON's attitude about women is roughly based on a young white male's attitude was roughly 20 years ago.

So, it is past time for DEF CON to grow up. It is no more appropriate for DEF CON to still have 20 year old attitudes about women then it would be for say a southern country club to still have 50 year old attitudes about race. There should be no objectifying women in any official event, which would include no striping in Hacker Jeopardy. Women and men not wearing enough cloths should be asked to leave until fully dressed. Goon's should be trained to not only deal with inappropriate and unwanted advances and comments properly but should look for them and act upon them even if the victim doesn't complain since the problem is already well known. That should hopefully set the tone and change the culture and after a year or two the Goon's could back off a bit.

I don't think any of this will happen. That said my plan this year is to skip Black Hat and go to B-Sides Vegas instead. I plan to go to DEF CON but I don't plan to spend a dime on anything but a badge. Not a huge protest I know, but it is a start and like I said, DEF CON is special to me. I'll see how things go. If nothing changes this year and there is nothing to make me thing it will be different next year, I probably won't be going back to DEF CON after this year until I hear they have changed. There is no reason to put up with it anymore. B-Sides in many cities are great and DerbyCon is great.

I recommend everyone else that goes think about this as well and if it matters to you start making your voices heard and stop going if they don't listen. Times are different, we can skip DEF CON without missing out and I'm starting to think we should.

Monday, November 4, 2013

Obfy Talk at B-Sides DFW

First let me say B-Sides DFW was a lot of fun.  DFW seems to have a good security community and they come together and put on a nice con.  I also got to hang out with my co-worker @integgroll who lives down there and @HackerHuntress who flew down there from Chicago land like myself.  And finally I got to hang out with my old boss @Network232 and I finally got a chance to see his talk.  Overall, good time and a good con.

Now many asked me for my slides on my Obfy Talk.  There isn't much to them since it was mostly a demo.  I Demo's using Obfy to gain access to a windows workstation running a popular current corporate AV software package and showed that same AV package detect and delete the same payload when built normally using only Metasploit tools.

For those who wanted them, there are my slides.
 Obfy Talk Slides

Friday, October 4, 2013

Obfy Update and News

I updated Obfy so it now makes an rc file for you to match the payload you created assuming you didn't select a custom file.  So now if you use Obfy to create a payload, you can run msfconsole -r obfy.rc and the listener to handle the payload will be setup for you.

Also, I'm giving a demo of Obfy at B-Sides DFW on Nov 1st.  If you are there say hi.  I don't know if the talks will be filmed but if they are I'll post a link to it.

Saturday, August 31, 2013

Update to kaliupdate.sh

I totally revamped my kali update script.  From looking at the activity here and my github page, that is the thing most people seem to be using.  It requires switches now.  So ./kaliupdate.sh -a does everything, or you can select just -p to update the packages and MSF but not wait for things to compile, etc.  I also testing the script on a fresh Kali install and I noticed packages were missing required to compile nmap.  I must have had those installed and didn't notice.  I fixed that so now /opt/nmap-svn/nmap will really run.  Although the packaged version on Kali is pretty current so I almost never run it anyway.  But have the most current scripts in the /opt/nmap-svn/scripts directory does come in handy.

So put if fresh like this:
git clone https://github.com/secjohn/kali-scripts.git

Or if you have it already go into the kali-scripts directory and run:
git pull

Then run the script and the help will tell you what switches to use.

I hope you like it.

Wednesday, August 28, 2013

Crypter support for Obfy


If you are following along at home, you now know that crypter http://nullsecurity.net/tools/binary.html is great.  And you followed along here to get it working with smbexec: http://secjohn.blogspot.com/2013/08/encrypting-payloads-with-smbexec-on.html

And of course you saw my post on Obfy here and are using it too right?  http://secjohn.blogspot.com/2013/08/introducing-obfy.html

Well then you are in luck.  I just added crypter support to Obfy as well.  So if you follow the directions in my encrypting payloads with smbexec post and compile crypter.exe and run updatedb so the locate command finds it, Obfy will now see it and ask you if you want to use it on the payload you just made.  If you say yes you will get two exe files, the original one and the one put through crypter.  Have fun testing each out.

The updated version of the script can be found here: https://github.com/secjohn/obfy
If you used git to download it originally as in git clone https://github.com/secjohn/obfy.git then simply running git pull in the obfy directory will get you up to date.

Tuesday, August 27, 2013

Fake AP on Kali Linux

At the time of this post there is a lot of wrong information on how to setup a fake AP on Kali Linux.  This seems to be mostly because Kali Linux uses the isc-dhcp-server package and not dhcp3.  Right now SET’s fake AP doesn’t work due to this.  I’m sure that will be fixed soon, @dave_rel1k puts a lot of effort into that tool which is why it is so great.  But for right now, it doesn’t work for setting up a fake AP.  So if you google around you find videos about Websploit like this one: http://www.youtube.com/watch?v=DXGj2vxdzvo

Well that doesn’t work either for the same reason.  How frustrating is that?  I found two tools that do work with some setup.  Easy-Creds and PwnSTAR.  While both worked I decided I liked Easy-Creds better but I’ll help you get both going now.

Easy-Creds:

Setup:
Check the github page and see if Brav0Hax added the install.sh script there yet https://github.com/brav0hax/easy-creds.  If so, download everything from github.  If there is no install.sh file download the tarball from there: http://sourceforge.net/projects/easy-creds/files/easy-creds-v3.7.3.tar.gz/download.  Untar the file and run the install.sh script.

Two things will fail but that is OK.  First, it tries to install and older version of lilssl, no worries.  The other is the dhcp3 server.  So manually run apt-get install isc-dhcp-server.  Now in case you played with dhpc3 or another script that I mentioned above, make sure there is no /etc/dhcp3 directory.  If there is delete it or things won’t work.  The directory isc-dhcp-server uses is /etc/dhcp and there is a dhcpd.conf file in there, that is the one you will use.

Now download the current version of the easy-creds.sh script from github https://github.com/brav0hax/easy-creds and copy if over the version that you installed with install.sh (probably /opt/easy-creds/easy-creds.sh).

Run updatedb one last time for good luck.

The cool thing about this install script is it always setups FreeRADIUS-WPE for you all automated, which is another whole blog post.

Now run the script.    Pick option 1 and then 4, and then 7:

Note: the version at the top is 3.8-dev.  If you are running something older things won’t work.

I found if you don’t do this the AP you setup is a bit flaky and karmetasploit won’t work, and you want that to work now don’t you?  Finally, in the Prerequisites & Configurations menu select 5 and add at0 to the INTERFACES in the file it opens up as so:


Remember to save the file when you exit.  Now you are ready to go.

Create a Fake AP:
Simply pick FakeAP Attacks from the main menu, select the one you want, and fill in the info it asks for.  In almost all cases its example is exactly what you want to use.  It is as easy as that. The Static attack will setup an AP with a name that you set, if you are testing it that is the easiest to use for a test so you can connect to it and make sure everything is working.  The EvilTwin will simply respond to whatever clients ask for, which is probably what you want to do for real, but can be harder to test.
Brov0Hax has some good videos for this tool, here is a good one for setting up the Static AP:

PwnSTAR:

Setup:
First, do everything I just told you to do in the setup of Easy-Creds.  That is right, that tool’s setup automates things and it is all the same requirements.  So if you skipped that tool, go back and start from the beginning. 

Next, run Eterm, select Background, Pixmap, None.  Then Eterm, Save Them Settings and Save User Settings.  You may not have to do this, but for me the Eterm pop up windows all had messed up backgrounds that made it impossible for me to read the text.  It was crazy annoying, if that happens to you, that is how you fix it.

I also recommend reading the README.txt as well.

Create a Fake AP:
Run the script and pick and option and go through the menu.  It is almost that easy since you set things up for Easy-Creds:
Now there is one catch, when you see this:

You just lost your Internet connection.  In another windows bring it back up and don’t move on until you can ping google.com or things won’t work.  I found I just needed to do a dhclient eth0 and everything was all fixed.  I don’t know why this happens.


Conclusion:


Both tools do slightly different things.  Easy-Creds has the handy install script which helps a lot with setting things up for both tools and it doesn’t kill your LAN connection like PwnSTAR does. The one thing PwnSTAR does that Easy-Creds doesn’t is it offers a “Both” option for Evil Twin where it will both broadcast a specific SSID and respond to whatever the client ask for.  I like that.  Easy-Creds looks like it is one or the other only.  Other than that Easy-Creds seems cleaner and seems to work more consistently.  Overall that is the tool I would recommend you use right now.  I’m sure SET and Websploit will update their tools as well before too long and they will start working again.  Until then, you now know what to do.