среда, 29 июля 2015 г.

Intercepter-NG 0.9.10 is out

Intro

С большим удовольствием хочу представить новую версию Intercepter-NG 0.9.10, которая, на мой взгляд, в значительной степени расширяет область применения инструмента. Данный обзор будет представлен не в виде сухого перечисления нововведений, а скорее как описание новых векторов атак вместе с рядом технических подробностей и элементами hack-story. Приступим…




суббота, 16 мая 2015 г.

Засвет на ТВ.

Ранее на BBC уже демонстрировалась Android версия Intercepter'а, сейчас показали, хоть и мельком, основной Intercepter под Windows на российском канале.

Москва24: СПЕЦИАЛЬНЫЙ РЕПОРТАЖ: "НИЧЕГО ПУБЛИЧНОГО"


На видео сотрудник Group-IB перехватывает сессии и прочий траф в публичной WiFi сети.



PS: на телефоне судя по всему тоже был запущен Intercepter, но в кадр экран телефона в полном виде не попал.

воскресенье, 4 января 2015 г.

Running intercepter-ng [console edition] on new iOS versions

I know there is a problem when you try to run old bin on new iphones\ipads, it gives 'illegal instruction' error . Today i found how to avoid it by patching 2 bytes:

# sed -i 's/\x00\x30\x93\xe4/\x00\x30\x93\xe5/g;s/\x00\x30\xd3\xe4/\x00\x30\xd3\xe5/g;' intercepter_ios

It's necessary only for one time and then it should runs just fine.

пятница, 12 декабря 2014 г.

Epic fail

The situation that lead me to write this post unhides some of the problems in information security world. Few days ago i received a message with a link to ZIMPERIUM's blog post with a loud statement that they discovered a "new type of attack technique" on the loose which allows to perform full-duplex ICMP Redirect attacks on the network called "DoubleDirect".

Sounds cool, because the classic ICMP Redirect attack allows only half-duplex data sniffing. My first reaction was laughter, because they reinvented the bicycle.
Indeed, it is not a *new* technique, because for the first time it was publicly disclosed by me 3 years ago and coded even earlier. Here’s the video of an old version of the Intercepter:



And it wasn't just a POC. More to that current version of Intercepter-NG allows to perform the attack that is called "DNS over ICMP MiTM" in a few mouse clicks.

The second reaction was like "omg, what are they talking about?!" The content of the post sounded so scary:

- We have identified that the traffic of the following services was redirected during the attacks on victim’s devices:
Google, Facebook, Twitter, Hotmail, Live.com, Naver.com (Korean) and others.

- We identified attacks across 31 countries ...

These statements may startle people who know nothing about technical part of described attack.
But don't be afraid, these guys will save the world with their wonderful software, be sure.

At last, the third reaction was sadness. It is really sad that news making resources widely distributed this little "sensation", even worse the so-called “security experts” supported the noise around that topic. No one mentioned that this shit is old as hell. That's what i call the fail of security world, no one even tried to check if this technique was done before. Only 3 keywords in google "dns icmp redirect" show up the video and point out to Intercepter-NG project.

What's the reason, lazyness?

I have always been quite a humble man and didn't try to make sensations out of nothing. In fact the DNS over ICMP MiTM is not that powerful to talk much about. It was discussed during PHDays'14 as a part of report about Intercepter-NG, but only in a few words, because it's not something special.

Although i got thousands of users all over the world, it seems i have to be more aggressive in making my tool popular, so that guys like Zimperium won't mess up big time again.


вторник, 23 сентября 2014 г.

О том, что осталось за кадром

В жизни каждого "правильного" исследователя всегда есть момент, когда ты берешься за что-то, что вероятно тебе нахрен не нужно практически, но крайне интересно с образовательной точки зрения. Интересно решать задачи для расширения кругозора и повышения собственной квалификации, особенно при наличии придурковатого состояния одержимости какой-то фантастической идеей. В моем случае одной из главных одержимостей в 2002 году было желание сделать то, чего еще не существовало, а если и существовало, то работало не так как я хотел, и конечно же было сделано не мной (damn it). Эта же одержимость сподвигла на создание интерцептера, но данный пост о совсем другом проекте. В то время я желал освоить ассемблер, т.к. это язык настоящих гуру и на тот момент идея о том, что настоящий хакер должен знать ассемблер, сидела в моем сознании довольно глубоко. Слепая замена jz на jnz,
сидя в softice конечно давала некие результаты на простых приложеинях, но хотелось большего. Ничего лучше, чем написание собственного дизассемблера, с целью разобраться в этой компьютерной магии, я не придумал. Опять же, дизассемблер дизассемблеру рознь. Простой листинг инструкций меня не устраивал, я хотел получить на выходе исходник, который можно было бы тут же собрать и получить рабочий бинарник, идентичный оригинальному. Не буду вдаваться в такие специфичные проблемы как отделение данных от кода и т.д., а просто покажу что в итоге получилось.

вторник, 29 июля 2014 г.

Running original Intercepter on Linux

Instruction updated!

[1]. Download WinPcap wrapper for Wine and libpcap-dev.

# wget http://sniff.su/wine_pcap_dlls.tar.gz
# apt-get install libpcap-dev

If you running i386 version of Kali goto [3].
---

[2]. On Kali x64 do the following commands.
# dpkg --add-architecture i386
# apt-get update
# apt-get install wine-bin:i386
# apt-get install tcpdump:i386

----

[3]. Copy dlls to wine libs.
# cp wpcap.dll.so /usr/lib/i386-linux-gnu/wine
# cp packet.dll.so /usr/lib/i386-linux-gnu/wine

[4]. Install winetricks.
# apt-get install winetricks
# winetricks cc580
# ethtool --offload  eth0  rx off  tx off

[5]. Download Intercepter-NG 0.9.9 and remove wpcap\packet dlls.
# rm wpcap.dll
# rm packet.dll
# wine Intercepter-NG.exe

Intercepter-NG 0.9.9

Вышла новая версия, которую теперь можно запустить под линуксом (Wine).

Главные нововведения это LDAP Relay и новый режим сетевого брутфорса паролей.

Полный список изменений:
+ LDAP Relay
+ Heartbleed exploit
+ Java injection
+ Plugin detector
+ Bruteforce Mode: FTP\IMAP\POP3\SMTP\SMB\SSH\LDAP\HTTP
+ TFTP\SMB2 resurrection
+ Telnet\Rsh\Rlogin\Rexec logging
+ PPTP\PPPoE: PAP\CHAP-MD5\MS-CHAP\MS-CHAPv2 Auth
+ PostgreSQL Plain\MD5 Auth
+ MS-SQL Server Auth
+ MongoDB Auth
+ Wine support
+ New skin
+ New skin