+ All Categories
Home > Documents > hacking from the restroom - dslrouter.sourceforge.netdslrouter.sourceforge.net/stuff/HTB/D2T1 -...

hacking from the restroom - dslrouter.sourceforge.netdslrouter.sourceforge.net/stuff/HTB/D2T1 -...

Date post: 07-Aug-2020
Category:
Upload: others
View: 0 times
Download: 0 times
Share this document with a friend
42
Transcript
Page 1: hacking from the restroom - dslrouter.sourceforge.netdslrouter.sourceforge.net/stuff/HTB/D2T1 - Bruno Goncalves - Hackin… · • hacking tools already done* • wi-fi connection
Page 2: hacking from the restroom - dslrouter.sourceforge.netdslrouter.sourceforge.net/stuff/HTB/D2T1 - Bruno Goncalves - Hackin… · • hacking tools already done* • wi-fi connection

hacking from the restroom

iBLISS

Page 3: hacking from the restroom - dslrouter.sourceforge.netdslrouter.sourceforge.net/stuff/HTB/D2T1 - Bruno Goncalves - Hackin… · • hacking tools already done* • wi-fi connection

introduction

Page 4: hacking from the restroom - dslrouter.sourceforge.netdslrouter.sourceforge.net/stuff/HTB/D2T1 - Bruno Goncalves - Hackin… · • hacking tools already done* • wi-fi connection

$ whoami!

•  Intrusion Analyst at iBLISS!•  Computer Engineer!•  Holds some certs !•  Over 10 years having fun/studying/working with security!

•  Spoken at ToorCon X (USA), H2HC IV and YSTS 2.0/3.0 (Brazil)!

Page 5: hacking from the restroom - dslrouter.sourceforge.netdslrouter.sourceforge.net/stuff/HTB/D2T1 - Bruno Goncalves - Hackin… · • hacking tools already done* • wi-fi connection

agenda

•  motivations

•  goal

•  why cellphones?

•  how?

•  demos

•  issues and concerns

•  conclusions

Page 6: hacking from the restroom - dslrouter.sourceforge.netdslrouter.sourceforge.net/stuff/HTB/D2T1 - Bruno Goncalves - Hackin… · • hacking tools already done* • wi-fi connection

motivations

-  pentest more than we used to do -  just 0days? -  unknown power in hands ha ha ha -  new market -  a lot of softwares -  utilize ur phone!

Page 7: hacking from the restroom - dslrouter.sourceforge.netdslrouter.sourceforge.net/stuff/HTB/D2T1 - Bruno Goncalves - Hackin… · • hacking tools already done* • wi-fi connection

cellphone myths

Page 8: hacking from the restroom - dslrouter.sourceforge.netdslrouter.sourceforge.net/stuff/HTB/D2T1 - Bruno Goncalves - Hackin… · • hacking tools already done* • wi-fi connection

goal

•  cellphones can do interesting stuffs

•  pentest platform? nah!

•  a lot of resources!!

Page 9: hacking from the restroom - dslrouter.sourceforge.netdslrouter.sourceforge.net/stuff/HTB/D2T1 - Bruno Goncalves - Hackin… · • hacking tools already done* • wi-fi connection

why cellphones?

Page 10: hacking from the restroom - dslrouter.sourceforge.netdslrouter.sourceforge.net/stuff/HTB/D2T1 - Bruno Goncalves - Hackin… · • hacking tools already done* • wi-fi connection
Page 11: hacking from the restroom - dslrouter.sourceforge.netdslrouter.sourceforge.net/stuff/HTB/D2T1 - Bruno Goncalves - Hackin… · • hacking tools already done* • wi-fi connection

little toys(1)

•  nokia e65

•  symbian s60 9.1

Page 12: hacking from the restroom - dslrouter.sourceforge.netdslrouter.sourceforge.net/stuff/HTB/D2T1 - Bruno Goncalves - Hackin… · • hacking tools already done* • wi-fi connection

little toys(2)

•  Ipod touch 2g

•  mac os x

Page 13: hacking from the restroom - dslrouter.sourceforge.netdslrouter.sourceforge.net/stuff/HTB/D2T1 - Bruno Goncalves - Hackin… · • hacking tools already done* • wi-fi connection

how??  

•  unix systems

•  sdk for everything!

•  ordinary tools can help

•  hacking tools already done*

•  wi-fi connection

Page 14: hacking from the restroom - dslrouter.sourceforge.netdslrouter.sourceforge.net/stuff/HTB/D2T1 - Bruno Goncalves - Hackin… · • hacking tools already done* • wi-fi connection

pentest steps

Page 15: hacking from the restroom - dslrouter.sourceforge.netdslrouter.sourceforge.net/stuff/HTB/D2T1 - Bruno Goncalves - Hackin… · • hacking tools already done* • wi-fi connection

information gathering

•  browsers

•  almost all clients (rdp, telnet, ftp, vnc, etc)

•  portscanners – simply done in any language

– nmap up and running!

Page 16: hacking from the restroom - dslrouter.sourceforge.netdslrouter.sourceforge.net/stuff/HTB/D2T1 - Bruno Goncalves - Hackin… · • hacking tools already done* • wi-fi connection

nmap running on iphone/ipod touch

Page 17: hacking from the restroom - dslrouter.sourceforge.netdslrouter.sourceforge.net/stuff/HTB/D2T1 - Bruno Goncalves - Hackin… · • hacking tools already done* • wi-fi connection

scanning

•  nikto for web (script languages alwyas works)

Page 18: hacking from the restroom - dslrouter.sourceforge.netdslrouter.sourceforge.net/stuff/HTB/D2T1 - Bruno Goncalves - Hackin… · • hacking tools already done* • wi-fi connection

exploiting

•  long concept

•  server-side & client-side

•  privilege escalation

•  in all we have our phones!

Page 19: hacking from the restroom - dslrouter.sourceforge.netdslrouter.sourceforge.net/stuff/HTB/D2T1 - Bruno Goncalves - Hackin… · • hacking tools already done* • wi-fi connection

exploiting(server-side)

•  metasploit

Page 20: hacking from the restroom - dslrouter.sourceforge.netdslrouter.sourceforge.net/stuff/HTB/D2T1 - Bruno Goncalves - Hackin… · • hacking tools already done* • wi-fi connection

exploiting (client-side)

•  creativity – pamp (portable apache + mysql + php)

– any exploit (mainly for browsers)

– social engineer and/or phishing

– our first demo!

Page 21: hacking from the restroom - dslrouter.sourceforge.netdslrouter.sourceforge.net/stuff/HTB/D2T1 - Bruno Goncalves - Hackin… · • hacking tools already done* • wi-fi connection

demo(1)

•  what: client-side attack

•  tools: pamp + telnet client + social engineer

•  vuln: ie7 uninitialized memory corruption

•  payload: bind port

•  toy: nokia e65

Page 22: hacking from the restroom - dslrouter.sourceforge.netdslrouter.sourceforge.net/stuff/HTB/D2T1 - Bruno Goncalves - Hackin… · • hacking tools already done* • wi-fi connection

privilege escalation

•  brute-force online – brute-force offline, necessary?

•  arp poisoning

•  sniffers

•  second demo

Page 23: hacking from the restroom - dslrouter.sourceforge.netdslrouter.sourceforge.net/stuff/HTB/D2T1 - Bruno Goncalves - Hackin… · • hacking tools already done* • wi-fi connection

demo(2)

•  what: mitm

•  tool: pirni

•  toy: ipod touch

Page 24: hacking from the restroom - dslrouter.sourceforge.netdslrouter.sourceforge.net/stuff/HTB/D2T1 - Bruno Goncalves - Hackin… · • hacking tools already done* • wi-fi connection

maintaining access

•  ssh daemon & client

•  Netcat

•  stunnel

Page 25: hacking from the restroom - dslrouter.sourceforge.netdslrouter.sourceforge.net/stuff/HTB/D2T1 - Bruno Goncalves - Hackin… · • hacking tools already done* • wi-fi connection

have someone ever seen that?

•  neopwn

•  http:///www.neopwn.com/

Page 26: hacking from the restroom - dslrouter.sourceforge.netdslrouter.sourceforge.net/stuff/HTB/D2T1 - Bruno Goncalves - Hackin… · • hacking tools already done* • wi-fi connection

what else?

Page 27: hacking from the restroom - dslrouter.sourceforge.netdslrouter.sourceforge.net/stuff/HTB/D2T1 - Bruno Goncalves - Hackin… · • hacking tools already done* • wi-fi connection

802.11 attacks

•  barbelo (wi-fi scanner) for symbian

•  mobile scanner (promiscuos mode) for windows mobile

•  silica & silica q from immunity (dumping and cracking)

Page 28: hacking from the restroom - dslrouter.sourceforge.netdslrouter.sourceforge.net/stuff/HTB/D2T1 - Bruno Goncalves - Hackin… · • hacking tools already done* • wi-fi connection

screenshots

Page 29: hacking from the restroom - dslrouter.sourceforge.netdslrouter.sourceforge.net/stuff/HTB/D2T1 - Bruno Goncalves - Hackin… · • hacking tools already done* • wi-fi connection

802.15 (bluetooth) attacks

•  bluetooth scanners and some exploits (bluesnarf, etc) – btbrowser & bloover for mobile (made

in java)

Page 30: hacking from the restroom - dslrouter.sourceforge.netdslrouter.sourceforge.net/stuff/HTB/D2T1 - Bruno Goncalves - Hackin… · • hacking tools already done* • wi-fi connection

screenshots

Page 31: hacking from the restroom - dslrouter.sourceforge.netdslrouter.sourceforge.net/stuff/HTB/D2T1 - Bruno Goncalves - Hackin… · • hacking tools already done* • wi-fi connection

what about imagination?

Page 32: hacking from the restroom - dslrouter.sourceforge.netdslrouter.sourceforge.net/stuff/HTB/D2T1 - Bruno Goncalves - Hackin… · • hacking tools already done* • wi-fi connection

rogue ap

•  joikuspot – same ssid, attack is ready

– user will not make diference (ad-hoc connection)

Page 33: hacking from the restroom - dslrouter.sourceforge.netdslrouter.sourceforge.net/stuff/HTB/D2T1 - Bruno Goncalves - Hackin… · • hacking tools already done* • wi-fi connection

sniffing keystrokes??

•  laser rox, i know that ‒ but cellphones as well !!

•  cellphones have microphones, right?

•  sounds into wood table?

•  daniele and andrea can give a shot! :D

Page 34: hacking from the restroom - dslrouter.sourceforge.netdslrouter.sourceforge.net/stuff/HTB/D2T1 - Bruno Goncalves - Hackin… · • hacking tools already done* • wi-fi connection

sms attacks

•  zane & luis did a great job about that!

•  manipulate pdus from cellphone (time economy)

•  t.a.f.t. - http://www.blackhat.com/presentations/bh-usa-09/LACKEY/BHUSA09-Lackey-AttackingSMS-SLIDES.pdf

Page 35: hacking from the restroom - dslrouter.sourceforge.netdslrouter.sourceforge.net/stuff/HTB/D2T1 - Bruno Goncalves - Hackin… · • hacking tools already done* • wi-fi connection

more?

Page 36: hacking from the restroom - dslrouter.sourceforge.netdslrouter.sourceforge.net/stuff/HTB/D2T1 - Bruno Goncalves - Hackin… · • hacking tools already done* • wi-fi connection

just develop!

•  sdks for everybody! – symbian, blackberry, windows mobile,

android, openmoko, iphone, more?

Page 37: hacking from the restroom - dslrouter.sourceforge.netdslrouter.sourceforge.net/stuff/HTB/D2T1 - Bruno Goncalves - Hackin… · • hacking tools already done* • wi-fi connection

issues and concerns

•  attacks just from inside?

•  qwerty always welcome ‒ virtual kbd from ipod rox too!

•  faster and better

•  even *jailbroken* phones limit us, openmoko and android may rule!

•  new gadgets, not just phone: zune hd

Page 38: hacking from the restroom - dslrouter.sourceforge.netdslrouter.sourceforge.net/stuff/HTB/D2T1 - Bruno Goncalves - Hackin… · • hacking tools already done* • wi-fi connection

conclusions

•  let’s think more in what we already have in hands

•  imagination make us better hackers!

•  each one make yours

Page 39: hacking from the restroom - dslrouter.sourceforge.netdslrouter.sourceforge.net/stuff/HTB/D2T1 - Bruno Goncalves - Hackin… · • hacking tools already done* • wi-fi connection

$ locate me

•  Contact: bruno.mphx2 *nospam* gmail.com

•  Linkedin: http://linkedin.com/in/brunogoliveira

•  Blog: http://g0thacked.wordpress.com/

•  IRC: #[email protected] •  Conferences around the globe (hope see you in H2HC)

Page 40: hacking from the restroom - dslrouter.sourceforge.netdslrouter.sourceforge.net/stuff/HTB/D2T1 - Bruno Goncalves - Hackin… · • hacking tools already done* • wi-fi connection

thanks!

•  organizers!!!

•  brazilian security friends (leo cavallari ‒ b0ss ;), spooker, bsdaemon, anderson ramos, coideloko, flambers, mr.billy, le, c4r0l, alan castro, bogus, zucco, etc)

Page 41: hacking from the restroom - dslrouter.sourceforge.netdslrouter.sourceforge.net/stuff/HTB/D2T1 - Bruno Goncalves - Hackin… · • hacking tools already done* • wi-fi connection

that’s all

Page 42: hacking from the restroom - dslrouter.sourceforge.netdslrouter.sourceforge.net/stuff/HTB/D2T1 - Bruno Goncalves - Hackin… · • hacking tools already done* • wi-fi connection

terima kasih


Recommended