Hacking Articles Tips Tricks Videos Tutorials
467 subscribers
65.7K photos
15 videos
157 files
131K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
Hacking Articles Tips Tricks Videos Tutorials
Black Hat Ethical Hacking Bug in Millions of Flawed IoT Devices Lets Attackers Eavesdrop https://www.blackhatethicalhacking.com/wp-content/uploads/2017/11/black-hat-locks-and-electronics.jpg Bug in Millions of Flawed IoT Devices Lets Attackers EavesdropPost…
ives an example of how it works: The figure below shows a typical device registration process and client connection on the Kalay network. In this example, a user remotely accesses their home network’s Kalay-enabled camera on a mobile app from a remote network: for example, a user would view their home camera’s feed while in a coffee shop or on a mobile phone network https://media.threatpost.com/wp-content/uploads/sites/103/2021/08/17103055/Kalay-flow-e1629210749791.jpg Kalay flow. Source: Mandiant. How Many Devices Are Affected? Impossible to SayTo get a high-level view of the scope of potentially affected products and companies, researchers pointed to ThroughTek’s advertising, which boasts of supporting upwards of 83 million active devices and more than 1.1 billion monthly connections on the platform. ThroughTek also supports 250 systems-on-a-chip (SOCs): the microchips that contain all the necessary electronic circuits and parts for small consumer electronic devices, such as smartphones or wearable computers.

Mandiant said that affected Kalay products include IoT camera manufacturers, smart baby monitors, and Digital Video Recorder (DVR) products.

Researchers noted that this ThroughTek bug is worse than the critical Nozomi Networks vulnerability disclosed in May: a bug that was already quite severe in that it laid open millions of connected cameras, leaving them prey to having remote attackers get at camera feeds. But besides eavesdropping, this latest Kalay vulnerability means that devices could be remotely controlled by people who have no business tinkering with other people’s baby monitors, webcams or other IoT gadgets, Mandiant said.

“This latest vulnerability allows attackers to communicate with devices remotely,” researchers explained. “As a result, further attacks could include actions that would allow an adversary to remotely control affected devices and could potentially lead to remote code execution.”
See Also: Offensive Security Tool: Warcannon How the Bug WorksMandiant determined that the problem lies in the device registration process, which requires only a device’s 20-byte, uniquely assigned identifier – which they refer to as a UID – to access the network. Mandiant’s testing showed that, typically, the UID is provided by a Kalay-enabled client, such as a mobile app, from a web API hosted by the company that markets and sells a given device.

In order to exploit the vulnerability, an attacker would need both deep knowledge of the Kalay protocol and the ability to generate and send messages. They’d also have to get their hands on those Kalay UIDs, which they could wriggle away via “social engineering or other vulnerabilities in APIs or services that return Kalay UIDs,” the researchers said. As an alternative, Mandiant also investigated brute forcing ThroughTek UIDs, but researchers said that it sucked up too much time and resources.

After they get their hands on the UIDs, an attacker could take over the associated, affected devices. With some knowledge of the Kalay protocol, they’d be able to re-register the UID, overwriting the existing Kalay device on the Kalay servers. Then, whenever the legitimate owner tries to access the device, the UID will be directed to the attacker, in effect leading to hijacking of the connection.

As Mandiant director Jake Valletta told Wired, the legitimate device owner would experience a few seconds of lag, but that’s the only difference that would be apparent from their perspective.

After that, the attacker can continue with the connection process in order to steal the device owner’s username and password. The figure below shows what happens when both a victimized device and a malicious device with the same UID exist on the network: Namely, the malicious registration overwrites the existing registration and force the legitimate device’s connections to be re-routed to the attacker’s device. https://media.threatpost.com/wp-co[...]

___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
ives an example of how it works: The figure below shows a typical device registration process and client connection on the Kalay network. In this example, a user remotely accesses their home network’s Kalay-enabled camera on a mobile app from a remote network:…
ntent/uploads/sites/103/2021/08/17113113/capturing-credentials-e1629214353657.png Attacker exploiting device personation vulnerability to capture credentials. Source: Mandiant.
After that, a threat actor can remotely connect to the victimized device, access audio/visual data and execute remote procedure calls (RPC), Mandiant said. Due to vulnerabilities in the device-implemented RPC interface, this can then lead to “fully remote and complete device compromise,” researchers described. Their enumeration of what makes this possible: “Mandiant observed that the binaries on IoT devices processing Kalay data typically ran as the privileged user root and lacked common binary protections such as Address Space Layout Randomization (“ASLR”), Platform Independent Execution (“PIE”), stack canaries, and NX bits.”

The figure below shows a hypothetical attack using the captured Kalay credentials to stage yet another attack by abusing the vulnerabilities in the Kalay RPC interface: https://media.threatpost.com/wp-content/uploads/sites/103/2021/08/17114402/Screen-Shot-2021-08-17-at-11.43.08-AM-e1629215096109.png See Also: Hacking Stories: Andrian Lamo – The ‘homeless’ HackerMandiant isn’t releasing public exploit code, but it did provide the video below, which demonstrates a proof of concept for CVE-2021-28372. How to Address the BugMandiant “strongly recommends” that companies using the Kalay platform follow the following guidance from ThroughTek and Mandiant:

* If the implemented SDK is below version 3.1.10, upgrade the library to version 3.3.1.0 or version 3.4.2.0 and enable the Authkey and Datagram Transport Layer Security (DTLS) features provided by the Kalay platform.
* If the implemented SDK is version 3.1.10 and above, enable Authkey and DTLS.
* Review security controls in place on APIs or other services that return Kalay unique identifiers (UIDs).
* Hardening features such as ASLR, PIE, NX, and stack canaries should be enabled on all binaries processing Kalay data and RPC functions should be treated as untrusted and sanitized appropriately.
* IoT device manufactures should apply stringent controls around web APIs used to obtain Kalay UIDs, usernames, and passwords to minimize an attacker’s ability to harvest sensitive materials needed to access devices remotely. Failure to protect web APIs which return valid Kalay UIDs could allow an attacker to compromise a large number of devices.

Mandiant thanked ThroughTek and CISA for their cooperation and support with releasing the advisory and for their “commitment to securing IoT devices globally.”
Source: threatpost.com (Click Link)Recent News* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/08/Steam-logo-90x90.jpg Critical Valve Bug Lets Gamers Add Unlimited Funds to Steam Wallets1 day ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/08/tmobile-header-90x90.webp Hacker claims to steal data of 100 million T-mobile customers2 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/08/depositphotos_40325161-stock-photo-microsoft-building-90x90.jpg Microsoft Warns: Another Unpatched PrintNightmare Zero-Day5 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/08/crypto-hack-90x90.jpg Crypto Hack Earned Crooks $600 Million6 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/08/msft-microsoft-logo-2-3-90x90.webp Actively Exploited Windows Zero-Day Gets a Patch1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/08/botnet-90x90.jpg Auth Bypass Bug Exploited, Affecting Millions of Routers1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/08/cisco-patch-90x90.png Critical Cisco Bug in VPN Routers Allows Remote Takeover1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/08/delete-telegram-message-e1628177080[...]

___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
ntent/uploads/sites/103/2021/08/17113113/capturing-credentials-e1629214353657.png Attacker exploiting device personation vulnerability to capture credentials. Source: Mandiant. After that, a threat actor can remotely connect to the victimized device, access…
885-90x90.jpg MacOS Flaw in Telegram Retrieves Deleted Messages2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/08/spam-call-90x90.jpg Black Hat: ‘I’m Calling About Your Car Warranty’, aka PII Hijinx2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/08/Google-Chrome-Browser-Management-90x90.png Bugs in Chrome’s JavaScript engine can lead to powerful exploits. This project aims to stop them2 weeks ago
style="display:block; text-align:center;"
data-ad-layout="in-article"
data-ad-format="fluid"
data-ad-client="ca-pub-6620833063853657"
data-ad-slot="4517761481">
The post Bug in Millions of Flawed IoT Devices Lets Attackers Eavesdrop first appeared on Black Hat Ethical Hacking.

___________________________
@hacking_Attack
@Hacking_Video
Access control vulnerabilities Mindmap

Hello, Hackers & Enthusiasts X0rby7e here, In this article, you will get a mindmap for Access control vulnerabilities.
Read more...
SIEM (Security and Event Management)

Security Information and Event Management (SIEM) is performed in four stages. Data is accumulated in the form of logs and threat…Continue reading on Medium »
Read more...
Install EyeWitness on Kali Linux

EyeWitness — is designed to take screenshots of websites provide some server header info, and identify default credentials if known.Continue reading on Medium »
Read more...
Access control vulnerabilities Mindmap

Hello, Hackers & Enthusiasts X0rby7e here, In this article, you will get a mindmap for Access control vulnerabilities.Continue reading on InfoSec Write-ups »
Read more...
AuraBorealisApp - Do You Know What's In Your Python Packages? A Tool For Visualizing Python Package Registry Security Audit Data

AuraBorealis is a web application for visualizing anomalous and potentially malicious code in Python package registries. It uses security audit data produced by scanning the Python Package Index (PyPI) via Aura, a static analysis designed for large scale security auditing of Python packages. The current tool is a proof-of-concept, and includes some live Aura data, as well as some mockup data for demo purposes. Current features include: Scanning the entire python package registry to: List packages with the highest number of security warnings, sorted by Aura warning type List packages sorted by the total and unique count of warnings List packages by their overall severity score Displaying security warnings for an individual package, sorted by criticality Visualize the line numbers and lines of code in files generating security warnings for a specific package Compare two packages for security warningsInstructions Turn on your VPN (at IQT) Clone the repository. git clone https://github.com/IQTLabs/AuraBorealisApp.git Navigate to aura-borealis-flask-app directory. cd aura-borealis-flask-app Install dependencies. pip install -r requirements.txt Run the app. python app.py Navigate to the URL http://0.0.0.0:7000/ via a browser. Feature Roadmap Compare a package to a benchmark profile of packages of similar purpose for security warnings Compare different versions of the same package for security warnings List packages that have changes in their warnings and/or severity score between two dates Ability to scan an internal package/registry that's not public on PyPI Display an analysis of permissions (does this package make a network connection? Does this package require OS-level library permissions?) Contact Information jmeyers@iqt.org (John Speed Meyers, IQT Labs, Secure Code Reuse project lead). The lead developer and creator of Aura is Martin Carnogusky of sourcecode.ai. Related Work IQT blog post on secure code reuse IQT blog posts on typosquatting and preventing typosquatting via pypi-scan USENIX article on "Counting Broken Links: A Quant's View of Software Supply Chain Security" IQT open source dataset on known software supply chain compromises Download AuraBorealisApp
Read more...

___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
Photo
KitPloit - PenTest Tools!
AuraBorealisApp - Do You Know What's In Your Python Packages? A Tool For Visualizing Python Package Registry Security Audit Data

http://4.bp.blogspot.com/-l967QEd6tCY/YRvF0ewhS3I/AAAAAAAAqjs/8Y2EYMTm3n0IQg-kc_EiMU5wH_dZeaKpQCK4BGAYYCw/w640-h358/AuraBorealisApp_1_auraborealis_homepage_ui-755385.png

AuraBorealis is a web application for visualizing anomalous and potentially malicious code in Python package registries. It uses security audit data produced by scanning the Python Package Index (PyPI) via Aura, a static analysis designed for large scale security auditing of Python packages. The current tool is a proof-of-concept, and includes some live Aura data, as well as some mockup data for demo purposes.

Current features include:

*
Scanning the entire python package registry to:

* List packages with the highest number of security warnings, sorted by Aura warning type
* List packages sorted by the total and unique count of warnings
* List packages by their overall severity score

*
Displaying security warnings for an individual package, sorted by criticality

*
Visualize the line numbers and lines of code in files generating security warnings for a specific package

*
Compare two packages for security warnings
Instructions

Turn on your VPN (at IQT)

Clone the repository.

git clone https://github.com/IQTLabs/AuraBorealisApp.git

Navigate to aura-borealis-flask-app directory.

cd aura-borealis-flask-app

Install dependencies.

pip install -r requirements.txt

Run the app.

python app.py

Navigate to the URL http://0.0.0.0:7000/via a browser.

Feature Roadmap

* Compare a package to a benchmark profile of packages of similar purpose for security warnings
* Compare different versions of the same package for security warnings
* List packages that have changes in their warnings and/or severity score between two dates
* Ability to scan an internal package/registry that's not public on PyPI
* Display an analysis of permissions (does this package make a network connection? Does this package require OS-level library permissions?)

Contact Information

jmeyers@iqt.org (John Speed Meyers, IQT Labs, Secure Code Reuse project lead).

The lead developer and creator of Aura is Martin Carnogusky of sourcecode.ai.

Related Work

* IQT blog post on secure code reuse
* IQT blog posts on typosquatting and preventing typosquatting via pypi-scan
* USENIX article on "Counting Broken Links: A Quant's View of Software Supply Chain Security"
* IQT open source dataset on known software supply chain compromises
Download AuraBorealisApp

___________________________
@hacking_Attack
@Hacking_Video