amphion forum 2013: what to do about attacks against mdms

43
Amphion Forum 2013 Practical Attacks Against Popular MDM Solutions (and What Can We Do About It) Michael Shaulov CEO, Co-Founder

Upload: lacoon-mobile-security

Post on 09-Jun-2015

907 views

Category:

Technology


0 download

TRANSCRIPT

Page 1: Amphion Forum 2013: What to Do About Attacks Against MDMs

Amphion Forum 2013 Practical Attacks Against Popular MDM Solutions (and What Can We Do About It)

Michael Shaulov CEO, Co-Founder

Page 2: Amphion Forum 2013: What to Do About Attacks Against MDMs

Agenda

l  About Lacoon

l  Your Data

l  Exploits to target enterprise data on mobile devices

l  Your Information

l  Point & click mobile remote access Trojans

l  Your Life

l  Mobile device Trojans as a service (M-TaaS)

l  Hacking iOS devices?

Page 3: Amphion Forum 2013: What to Do About Attacks Against MDMs

Lacoon Mobile Security

l  Founded by mobile security experts from the Defense and

Security industries

l  Serving the Fortune-1000

l  Cutting edge research team

l  Partnerships with leading mobile operators

l  Well-funded and backed by security industry veterans and

Index Ventures

Page 4: Amphion Forum 2013: What to Do About Attacks Against MDMs

Why to Hack Mobile Devices?

Page 5: Amphion Forum 2013: What to Do About Attacks Against MDMs

BYOD and Corporate Mobility

“More than

60% of organizations enable BYOD”

Gartner, Inc. October 2012

Page 6: Amphion Forum 2013: What to Do About Attacks Against MDMs

Mobile Devices: Attractive Attack Target

Eavesdropping

Extracting contact lists, call &text logs

Tracking location

Infiltrating internal LANs

Snooping on corporate emails and application data

Page 7: Amphion Forum 2013: What to Do About Attacks Against MDMs

Enterprise Mobile Data Protection Solutions?

Page 8: Amphion Forum 2013: What to Do About Attacks Against MDMs

Enterprise Security & Data Protection Solutions

l  Mobile Device Management (MDM)

l  Secure Containers

l  Wrappers

l  VDI

Page 9: Amphion Forum 2013: What to Do About Attacks Against MDMs

YOUR DATA

Page 10: Amphion Forum 2013: What to Do About Attacks Against MDMs

Hacking Enterprise Data on Mobile

Devices

Page 11: Amphion Forum 2013: What to Do About Attacks Against MDMs

What is a Secure Container?

Page 12: Amphion Forum 2013: What to Do About Attacks Against MDMs

MDMs and Secure Containers

3 features:

l  Encrypt business data l  Encrypt communications to the

business l  Detect Jailbreak / Rooting of

devices

Page 13: Amphion Forum 2013: What to Do About Attacks Against MDMs

Difficulty to Hack?

or Cost of Attack?

Page 14: Amphion Forum 2013: What to Do About Attacks Against MDMs
Page 15: Amphion Forum 2013: What to Do About Attacks Against MDMs

12 Hours | 1000 USD

Page 16: Amphion Forum 2013: What to Do About Attacks Against MDMs

Attack Demo

Page 17: Amphion Forum 2013: What to Do About Attacks Against MDMs

Step 1: Infect the device

Page 18: Amphion Forum 2013: What to Do About Attacks Against MDMs

Step 2: Install a Backdoor / aka Rooting

Administrative Every process can run as an administrative (root) user if it is able to triggr a vulnerability in the OS

Vulnerability Each Android device had/ has a public vulnerability

Exploit Detection mechanisms don’t look at apps that exploit the vulnerability

Page 19: Amphion Forum 2013: What to Do About Attacks Against MDMs

Step 3: Bypass Containerization

Jo, yjod od sm r,so;

Storage

Page 20: Amphion Forum 2013: What to Do About Attacks Against MDMs

Jo, yjod od sm r,so;

Storage

Step 3: Bypass Containerization

Page 21: Amphion Forum 2013: What to Do About Attacks Against MDMs

Jo, yjod od sm r,so;

Hi, This is an email

Storage Memory

Step 3: Bypass Containerization

Page 22: Amphion Forum 2013: What to Do About Attacks Against MDMs

Jo, yjod od sm r,so;

Hi, This is an email

Storage Memory

Exfiltrate information

Step 3: Bypass Containerization

Page 23: Amphion Forum 2013: What to Do About Attacks Against MDMs

How Many Privilege Escalation Exploits are Out There?

Date Name Affected Devices 12/2012 Exynos Most Samsung

Devices (Galaxy S2/3, Note…)

6/2013 MasterKey 1

All devices

8/2013 MasterKey 2

All devices

11/2013 MasterKey 3 All devices

11/2013 V-Root All devices, bypass SEAndroid…

Page 24: Amphion Forum 2013: What to Do About Attacks Against MDMs

How Many Privilege Escalation Exploits are Out There?

Date Name Affected Devices 12/2012 Exynos Most Samsung

Devices (Galaxy S2/3, Note…)

6/2013 MasterKey 1

All devices

8/2013 MasterKey 2

All devices

11/2013 MasterKey 3 All devices

11/2013 V-Root All devices, bypass SEAndroid…

Page 25: Amphion Forum 2013: What to Do About Attacks Against MDMs

YOUR INFORMATION

Page 26: Amphion Forum 2013: What to Do About Attacks Against MDMs

Mobile Remote Access Trojans

(mRATs)

Page 27: Amphion Forum 2013: What to Do About Attacks Against MDMs
Page 28: Amphion Forum 2013: What to Do About Attacks Against MDMs

Point & Click | Free (0 USD)

Page 29: Amphion Forum 2013: What to Do About Attacks Against MDMs

AndroRAT – Point & Click mRAT Generator

l  Injects polymorphic mobile remote access Trojan to any

Android application

l  Released as Open Source on Nov 2012

l  https://github.com/DesignativeDave/androrat

l  Forked many times

l  Available on many dark forums

Page 30: Amphion Forum 2013: What to Do About Attacks Against MDMs

AndroRAT Demo

Page 31: Amphion Forum 2013: What to Do About Attacks Against MDMs

YOUR LIFE

Page 32: Amphion Forum 2013: What to Do About Attacks Against MDMs

Mobile Device Trojans as a

Service (M-TaaS)

Page 33: Amphion Forum 2013: What to Do About Attacks Against MDMs
Page 34: Amphion Forum 2013: What to Do About Attacks Against MDMs

Read the Manual | 60 USD per Year

Page 35: Amphion Forum 2013: What to Do About Attacks Against MDMs

Commercial mobile surveillance tools

Page 36: Amphion Forum 2013: What to Do About Attacks Against MDMs

mSpy Demo

Page 37: Amphion Forum 2013: What to Do About Attacks Against MDMs

Survey: Cellular Network 2M Subscribers Sampling: 650K

Infection rates:

June 2013:

1 / 1000 devices

Page 38: Amphion Forum 2013: What to Do About Attacks Against MDMs

Survey: Cellular Network 2M Subscribers Sampling: 650K

Page 39: Amphion Forum 2013: What to Do About Attacks Against MDMs

Infect a non-JB iOS 7 iPhone with

a mRAT?

Page 40: Amphion Forum 2013: What to Do About Attacks Against MDMs

Current Solutions in Use to Protect Mobility

Page 41: Amphion Forum 2013: What to Do About Attacks Against MDMs

http://www.lacoon.com/hand-of-thief-hot-moves-its-way-to-android/

Anti Virtual Machine - “the best way to infect the user is by placing the malware on Google Play”

Page 42: Amphion Forum 2013: What to Do About Attacks Against MDMs

Lacoon MobileFortress – Behavior-based Detection & Mitigation

Malware Analysis

Threat Intelligence

Vulnerability Research

Application Behavioral

Analysis

Device Behavioral

Analysis

Multi-Layer Mitigation

Page 43: Amphion Forum 2013: What to Do About Attacks Against MDMs

Thank You. Contact details: www.lacoon.com [email protected] Twitter: @LacoonSecurity