PSW #787 – Vlad Gostomelsky
Full Audio
View Show IndexSegments
1. Penetration Stories From The Trenches – Vlad Gostomelsky – PSW #787
Penetration Tester stories, dumb and funny stuff that's crazier than movies.
Segment Resources: https://www.cyberpointllc.com/index.php https://www.cyberpointllc.com/srt.php
Announcements
Our teams from Security Weekly and SC Media were onsite at RSA Conference 2023 delivering in-depth reporting, analysis and interviews from the conference. If you were unable to join us in person, or didn't manage to catch our video livestream from Broadcast Alley, you can access all of our RSAC 2023 coverage at https://securityweekly.com/rsac.
Guest
Vlad is a driven security researcher with a passion for securing technology that makes civilized life possible. He is particularly focused on automotive security, satellite systems security, SCADA systems supporting the critical infrastructure and wireless networks. He specializes in the intersection of physical and network security. He has worked on DARPA projects, established and LED penetration testing teams for Fortune 50 organizations, performed incident response and forensics on sensitive production systems within controlled environments, reverse engineered security devices, and participated in countless red team engagements for banks, critical infrastructure, pharmaceutical companies, law firms and research organizations. Vlad has spoken at various security conferences including BSides, DEFCON, BlackHat, HOPE, and ShmooCon. Vlad was a board member for NYC OWASP and remains committed to the security community working together to improve the security posture through developer education, end user training, peer- reviewed code and rigorous standardized testing methodologies.
Hosts
2. Plain Text Keystrokes, WPBT, One Packet Exploits, & Sock Puppets! – PSW #787
In the security news: keystroke logs are stored in plain-text (and other atrocities in software used in schools), WPBT is the gift that keeps on giving and this time it's Gigabyte, PCI DSS 4.0 (drink!), immutable linux desktops, one packet exploits, neat linux malware, sock puppets, a must read new book about hacks, why SMB why?, boot girls, exposing customers....data, cracking GSM, you MUST use 2fa (not should, must), old wine in a new bottle, lab grown "meat", malicious bookmarks, and ChatGPT's secret reading list! All that and more on this episode of Paul’s Security Weekly.
Announcements
Join us at an upcoming Official Cyber Security Summit in a city near you! This series of one-day, invitation-only, executive level conferences are designed to educate senior cyber professionals on the latest threat landscape. We are pleased to offer our listeners $100 off admission when you use code SecWeek23 to register. Visit securityweekly.com/cybersecuritysummit to learn more and register today!
Hosts
- 1. Trusted publishing: a new benchmark for packaging security
- 2. Find My AirTag – The Hacker Factor Blog
- 3. Technical Advisory – Multiple Vulnerabilities in Faronics Insight
There is a list of 11 vulnerabilities in this software that is described as: "Faronics Insight is a feature rich software platform which is deployed on premises in schools. The application enables teachers to administer, control and interact with student devices.". This is one of the vulnerabilities: "Keystroke Logs Are Stored in Plaintext in a World Readable Directory"
- 4. Supply Chain Risk from Gigabyte App Center Backdoor – Eclypsium
WPBT is the gift that keeps on giving (for attackers and pen testers, anyhow).
- 5. PCI DSS 4.0: How to Delight the Auditors
Just for Jeff
- 6. Ubuntu Details Initial Plans For Immutable Linux Desktop With Ubuntu Core & Snaps – Phoronix
- 7. Google Nest Hub Teardown
"The main SOC is an Amlogic S905D3G, a 4-core A55-based SoC. The important chips are meticulously documented, and it’s a fascinating look inside a device common in many people’s homes. One chip that’s of note is the BGT60TR13C, otherwise known as Project Soli. It is an 8x10mm chip that uses radar to detect movement with sub-millimeter accuracy." - Some hardware reversing for you all.
- 8. CVE-2023-28771-PoC
If you want to try it out for yourself, in a lab, or with permission, of course.
- 9. CVE-2023-28771
"CVE-2023-28771 is an unauthenticated command injection vulnerability affecting the WAN interface of several Zyxel network devices, as reported by TRAPA Security." - How about a one-packet UDP exploit that gives you root? Love it.
- 10. secimport
"secimport is production-oriented sandbox toolkit. It traces your code, and runs an executable that allows only the same syscalls per module." - I like the concept, but fear this may cause a wide-variety of other issues.
- 11. Critical Barracuda 0-day was used to backdoor networks for 8 months
Neat features in the malware: "Malware identified to date includes packages tracked as Saltwater, Seaside, and Seaspy. Saltwater is a malicious module for the SMTP daemon (bsmtpd) that the Barracuda ESG uses. The module contains backdoor functionality that includes the ability to upload or download arbitrary files, execute commands, and provide proxy and tunneling capabilities. Seaside is an x64 executable in ELF (executable and linkable format), which stores binaries, libraries, and core dumps on disks in Linux and Unix-based systems. It provides a persistence backdoor that poses as a legitimate Barracuda Networks service and establishes itself as a PCAP filter for capturing data packets flowing through a network and performing various operations."
- 12. Blog – What if we had the SockPuppet vulnerability in iOS 16? – Apple Security Research
"The SockPuppet vulnerability was a use-after-free in the XNU kernel's in6_pcbdetach() function that was reachable through a series of socket-related syscalls." - Apple believes that iOS 16 is resilient to this style of attack. Amazing post!
- 13. Announcing The BlueHat Podcast: Listen and Subscribe Now!
I am going to check this out and let you all know what I think.
- 14. PyPI enforces 2FA authentication to prevent maintainers’ account takeover
"The attacker doesn’t care if they get you from a widely used or a niche project, just that they got you." - I get both sides of this, I think in the end though, this is the right decision given the level of malicious packages today.
- 15. Microsoft found a new bug that allows bypassing SIP root restrictions in macOS
- 16. Is cybersecurity an unsolvable problem?
Didn't even have to read that far into the article to realize I MUST read this book: "The book is a lively, engaging read filled with fascinating stories and colorful characters: the infamous Bulgarian hacker known as Dark Avenger, whose identity is still unknown; Cameron LaCroix, a 16-year-old from south Boston notorious for hacking into Paris Hilton's Sidekick II in 2005; Paras Jha, a Rutgers student who designed the "Mirai botnet"—apparently to get out of a calculus exam—and nearly destroyed the Internet in 2016 when he hacked Minecraft; and of course, the titular Fancy Bear hack by Russian military intelligence that was so central to the 2016 presidential election. " - The book is "(https://www.amazon.com/dp/0374601178/?ots=1&tag=arstech20-20)[Fancy Bear Goes Phishing: The Dark History of the Information Age, in Five Extraordinary Hacks]" by Scott J. Shapiro
- 17. Hackers Win $105,000 for Reporting Critical Security Flaws in Sonos One Speakers
"On the speaker, there exists a daemon named anacapad that handles all Sonos-specific functions, including accessing music services, LED control, and audio playback. The vulnerability exists in the way anacapad handles SMBv2 replies from a server, specifically in the smb2_process_query_directory_fixed() function that processes query directory reply data." - Curious what goes into the decision to use SMB here...
- 1. Atlanta’s anonymous Boot Girls will remove the boot on your car wheel for $50
- 2. Toyota: Car location data of 2 million customers exposed for ten years
- 3. Zyxel Issues Critical Security Patches for Firewall and VPN Products
- 4. CVE-2023-28771-PoC/CVE-2023-28771-poc.py at main · BenHays142/CVE-2023-28771-PoC
- 5. GUAC 0.1 Beta: Google’s Breakthrough Framework for Secure Software Supply Chains
- 6. A Video Demonstration on Cracking a GSM Capture File
- 7. China Hacks US Critical Networks in Guam, Raising Cyberwar Fears
- 8. TikTok Creators’ Financial Info, Social Security Numbers Have Been Stored In China
- 1. A new OAuth vulnerability may impact hundreds of online services
A critical API redirect vulnerability in the Expo application development framework puts OAuth and other services using the framework at risk of credential leakage. The issue was detected by researchers from Salt Labs; Expo developers have fixed the vulnerability.
The issue was in the deprecated proxy authentication options, which removed the need for deep links in apps for authentication. Homework: Ensure you're not using deprecated functions...
- 2. Securing PyPI accounts via Two-Factor Authentication – The Python Package Index
The Python Package Index (PyPI) will require all project and maintainer accounts to employ two-factor authentication (2FA) by the end of this year. PyPI recommends using a security device or an authentication app. In the lead-up to the deadline, PyPI will begin limiting access to certain site functionality to those using 2FA; PyPI may also begin imposing the requirement on certain users and projects before the end of the year.
- 3. OneMain pays $4.5M after ignored security flaws caused data breaches
OneMain Financial has agreed to pay a $4.25 million penalty to the New York Department of Financial Services (DFS) for security issues detected during a DFS audit focused on OneMain’s cybersecurity policies and procedures between January 2017 and March 2020. According to NY DFS, “OneMain failed to effectively manage third-party service provider risk, manage access privileges, and maintain a formal application security development methodology, significantly increasing the company’s vulnerability to cybersecurity events.”
- 4. CISO Criminalization, Vague Cyber Disclosure Rules Create Angst for Security Teams
Solar Winds Chief Information Security Officer (CISO) Tim Brown told Dark Reading that CISOs want clear rules about breach disclosure. Former Uber CISO Joe Sullivan was sentenced to three years’ probation in addition to a $50,000 fine; the judge in the case made it clear that the next time a similar case comes before him, he will be far less lenient. The US Federal Trade Commission’s (FTC) breach disclosure rules along with the tangle of regulations, executive orders, state laws, and legal precedent complicate disclosure decisions. Brown suggests that CISOs would benefit from a law much like the Sarbanes-Oxley Act, which provides a framework for financial reporting regulations for chief financial officers (CFOs).
- 5. Sports Warehouse Fined $300,000 Over Payment Card Data Theft
New York’s attorney general has fined Sports Warehouse $300,000 for failing to adequately protect consumer data. The online sports gear retailer will also revamp its cybersecurity program. Sports Warehouse systems were breached in September 2021; the company was alerted to the incident by third parties in October of that year. The attacker brute-forced Sports Warehouse’s server authentication and accessed a server that was protected with only a static password. That server contained unencrypted customer data, including payment card information, dating back to 2002.
- 6. Old Wine in the New Bottle: Mirai Variant Targets Multiple IoT Devices
Researchers from Palo Alto’s Unit 42 have detected a malware campaign that uses Mirai variant IZ1H9 to target IoT devices. The threat actors are targeting Linux-based servers and networking devices through four known vulnerabilities: a Tenda G103 command injection vulnerability (CVE-2023-27076); a LB-Link command injection vulnerability (CVE-2023-26801); a DCN DCBI-Netlog-LAB remote code execution vulnerability (CVE-2023-26802); and a Zyxel remote code execution vulnerability.
- 7. Practicefirst pays New York $550K after patching failure leads to 2020 breach
Medical management company Practicefirst will pay a fine of $550,000 to the state of New York for failing to adequately protect patient data. The company failed to update their software in a timely manner, resulting in the theft of data affecting 1.2 million individuals, more than 428,000 of whom reside in New York. Practicefirst violated both the Heath Insurance Portability and Accountability Act (HIPAA) and New York state laws.
- 8. GitLab Critical Security Release: 16.0.1
GitLab has released version 16.0.1 for both GitLab Community Edition (CE) and GitLab Enterprise Edition (EE). The newest version fixes a critical path traversal vulnerability that could be exploited to read arbitrary files without authenticating. The issue affects GitLab CE/EE version 16.0.0; older versions are not affected.
- 9. Bridgestone CISO: Lessons From Ransomware Attack Include Acting, Not Thinking
In February 2022, tire manufacturer Bridgestone was the target of a ransomware attack that took its North American operations offline for days. Bridgestone America Chief Information Security Officer (CISO) Tom Corridon said his most important piece of advice is to determine who makes which decisions in a crisis before one occurs. Corridon also noted that breaches can generate an atmosphere of openness to changes that can help avoid another incident.
- 1. This free VPN leaked data from millions of users online – find out if you’re affected
A researcher discovered a publicly exposed database linked with the SuperVPN app containing 133 GB of data, including personal user information such as IP location, servers used and Unique App User ID numbers as well as details about user online activities, device model, operating system and refund requests. It has over 100 million downloads worldwide across the Google and Apple app stores.
- 2. SCIENTISTS DISCOVER MIND-BLOWING PROCESS TO RECYCLE OLD SOLAR PANELS: ‘UNTIL NOW IT MADE ECONOMIC SENSE TO JUST DUMP [THEM]
Solar panels contain valuable materials that could be used to make new panels, but those materials are difficult to separate. The new process uses an ordinary kitchen microwave with added heat-proofing to selectively heat the panel’s silicon components while leaving the glass, plastic, and aluminum intact. The method was successful and much more energy-efficient than using a traditional furnace to do the same.
- 3. Cyberweapon manufacturers plot to stay on the right side of US
The Israeli start-up Paragon Solutions decided, before courting a single customer, to get the Americans on their side. The US Drug Enforcement and Administration Agency is among the top customers for Paragon’s signature product nicknamed Graphite. The malware surreptitiously pierces the protections of modern smartphones and evades the encryption of messaging apps like Signal or WhatsApp, sometimes harvesting the data from cloud backups — much like Pegasus does.
- 4. New Study Is Extremely Embarrassing for Lab-Grown Meat
The environmental impact of lab-grown meat is between four and 25 times greater than the average for beef products sold in stores, because they must purify growth media to pharmaceutical levels. The switch to food-grade media is proving extremely difficult.
- 5. China Is Flirting With AI Catastrophe
Due to Beijing’s lax approach toward technological hazards and its chronic mismanagement of crises, the danger of AI accidents is most severe in China. Risks include crashing markets with AI-powered trading, developing bioweapons, and defective AI systems crashing critical infrastructure. hereas the United States government and Silicon Valley are many years into a backlash against a “move fast and break things” mentality, China’s tech companies and government still pride themselves on embracing that ethos. This is because the Chinese government historically covers up disasters so people are unaware of their impact, such as the nuclear tests before 2000 which led to the premature deaths of nearly 200,000 citizens.
- 6. Discord Admins Hacked by Malicious Bookmarks
A number of Discord communities focused on cryptocurrency have been hacked this past month after their administrators were tricked into running malicious Javascript code disguised as a Web browser bookmark. The bookmark is actually a clever snippet of Javascript that quietly grabs the user’s Discord token and sends it to the scammer’s website. The attacker then loads the stolen token into their own browser session and (usually late at night after the admins are asleep) posts an announcement with a crypto scam.
- 7. Google’s encryption-breaking Magic Compose AI proves iPhone shouldn’t support RCS messaging
Google, to compete with Apple's iMessage, settled on RCS, a new standard that replaces SMS on Android devices. The Magic Compose AI feature that Google is building into Messages breaks encryption by sending messages back to Google’s servers. This breaks end-to-end encryption (E2EE), despite Google's claims to the contrary.
- 8. ‘I do not think ethical surveillance can exist’: Rumman Chowdhury on accountability in AI
"Moral outsourcing" applies the logic of sentience and choice to AI, allowing technologists to effectively reallocate responsibility for the products they build onto the products themselves. “You would never say ‘my racist toaster’ or ‘my sexist laptop’...And yet we use these modifiers in our language about artificial intelligence. And in doing so we’re not taking responsibility for the products that we build.” She is working on a red-teaming event for Def Con's AI Village.
- 9. ChatGPT’s secret reading list
The inner workings of the large language models at the heart of a chatbot are a black box; the datasets they're trained on are so critical to their functioning that their creators consider the information a proprietary secret. To figure out what GPT-4 has read, researchers quizzed it on its knowledge of various books, as if it were a high-school English student. What's most surprising is how much science fiction and fantasy GPT-4 has been raised on. The list is staggering: J.R.R. Tolkien, Ray Bradbury, William Gibson, Orson Scott Card, Philip K. Dick, Margaret Atwood, "A Game of Thrones," even "The Hitchhiker's Guide to the Galaxy."
- 10. Hackers Win $105,000 for Reporting Critical Security Flaws in Sonos One Speakers
This is a success story of bug bounties. The four flaws allowed network-adjacent attackers to execute arbitrary code and access sensitive information. The flaws were reported in Dec, 2022, the researchers were paid at Pwn2Own, and the products were patched.
- 11. Is cybersecurity an unsolvable problem?
Law philosopher Scott Shapiro says there is no permanent solution to the cybersecurity problem. "Cybersecurity is not a primarily technological problem that requires a primarily engineering solution...It is a human problem that requires an understanding of human behavior." That's his mantra throughout the book: "Hacking is about humans."
- 12. EU tells Twitter ‘you can run but you can’t hide’ from disinformation policy
European Commissioner Thierry Breton told the world this weekend that Twitter had pulled out of the EU's voluntary Code of Practice against disinformation, but warned it has "obligations" anyway. "You can run but you can't hide...fighting disinformation will be [a] legal obligation under [the Digital Services Act] as of August 25. Our teams will be ready for enforcement." Requirements include watching out for systemic risks ranging from how illegal content and disinformation can be amplified on their services, to protection of minors online and their mental health.
- 13. Researchers from UC Berkeley Introduce Gorilla: A Finetuned LLaMA-based Model that Surpasses GPT-4 on Writing API Calls
LLMs like GPT-4 struggle to generate precise input arguments and frequently recommend inappropriate API calls. Gorilla is a finetuned LLaMA-based model that beats GPT-4 in terms of producing API calls. Its capabilities enable the reduction of problems related to hallucination and reliability.
- 14. Blood Pressure Monitoring at Your Fingertips: Super Low-Cost Smartphone Attachment
Engineers have developed a low-cost, user-friendly clip and smartphone app for blood pressure monitoring. The clip, which costs less than a dollar to produce, works without needing calibration and offers an affordable alternative to traditional blood pressure monitoring methods.
- 15. Unprecedented Transmission Speeds – Scientists Develop New Quantum Key Distribution System
Scientists have crafted a quantum key distribution (QKD) system, allowing for the transmission of secure keys at unprecedented speeds. Unlike current communication protocols that rely on computational complexity for security, QKD’s security is founded on the principles of physics. It can accurately produce and encode photons at a record speed of up to 2.5 GHz.
- 16. ‘I feel constantly watched’: the employees working under surveillance
Monitoring software makes an activity score, a percentage calculated by the arbitrary measure of how much the worker types and moves her mouse. A poll by the Trades Union Congress (TUC) in 2022 found that 60% of employees had experienced tracking in the last year. Excessive monitoring harms workers and can be counterproductive for companies too.
- 17. Cyberweapon manufacturers plot to stay on the right side of US
In the summer of 2019, as Paragon Solutions was building one the world’s most potent cyberweapons, the company made a prescient decision: before courting a single customer, best get the Americans on their side. The Israeli start-up had watched local rival NSO Group, makers of the controversial Pegasus spyware, fall foul of the Biden administration and be blacklisted in the US. So Paragon sought guidance from top American advisers, secured funding from US venture capital groups and eventually scored a marquee client that eludes its competition: the US government.
- 18. Reducing Stored IP Data in PyPI
A few months ago we started exploring what it would take to remove the concept of IP addresses from our stack, and retain the ability to safely manage the platform. Pretty much every request to PyPI is served via our CDN partner, Fastly. Now we use a hashed IP address instead of the plaintext IP.