blackops - the cadence group · cadence blackops goals: •provide an entertaining forum to discuss...

16
BlackOps Q4 2014

Upload: others

Post on 06-Jul-2020

1 views

Category:

Documents


0 download

TRANSCRIPT

Page 1: BlackOps - The Cadence Group · Cadence BlackOps Goals: •Provide an entertaining forum to discuss emerging threats and new security technology •Facilitate access to others’

BlackOpsQ4 2014

Page 2: BlackOps - The Cadence Group · Cadence BlackOps Goals: •Provide an entertaining forum to discuss emerging threats and new security technology •Facilitate access to others’

What am I doing here?

Cadence BlackOps Goals:

• Provide an entertaining forum to

discuss emerging threats and new

security technology

• Facilitate access to others’ knowledge

and discuss current, real-world issues

• Eat

• Win prizes

• Death by PowerPoint

Cadence BlackOps: Q4 2014

Page 3: BlackOps - The Cadence Group · Cadence BlackOps Goals: •Provide an entertaining forum to discuss emerging threats and new security technology •Facilitate access to others’

Who is this guy?

Cadence BlackOps: Q4 2014

Erich Ficker (burnd0wn)

• Industrialist, philanthropist, bicyclist

• Cadence Pen Test Team Lead

• Interests: Taco Bell breakfast,

hardware hacking, WiFi

shenanigans, cars

• @eficker

[email protected]

• CISSP, GPEN, CEH

Page 4: BlackOps - The Cadence Group · Cadence BlackOps Goals: •Provide an entertaining forum to discuss emerging threats and new security technology •Facilitate access to others’

For Today

Software Vulnerabilities• MS14-060 / CVE-2014-4114: Windows OLE Could Does Allow

Remote Code Execution

• How

• Demo

• Defense

Hardware / Physical Security• The death of the door badge

• What?!

• Demo

• Defense

QA / Open Floor Discussion

Cadence BlackOps: Q4 2014

Page 5: BlackOps - The Cadence Group · Cadence BlackOps Goals: •Provide an entertaining forum to discuss emerging threats and new security technology •Facilitate access to others’

The new vulnerability discovery process

Fuzz application

Examine output for

unexpected behavior

Vulnerability Found!

Validate with Proof-

of-concept code

2

The Age of VLogos

Make up catchy

nickname and of

course LOGO!

No vulns are real

without this step

1 3

Cadence BlackOps: Q4 2014

Page 6: BlackOps - The Cadence Group · Cadence BlackOps Goals: •Provide an entertaining forum to discuss emerging threats and new security technology •Facilitate access to others’

Targets

• Microsoft OLE

• Allows content pulled from

outside sources (SMB share)

• No warnings or boxes to click

through

Not Sand or a Worm

• Sandworm is actually a

group, not a vulnerability

• Still somehow got a logo

• Still can dominate your

organization

Cadence BlackOps: Q4 2014

AKA MS14-060 / CVE-2014-4114

Page 7: BlackOps - The Cadence Group · Cadence BlackOps Goals: •Provide an entertaining forum to discuss emerging threats and new security technology •Facilitate access to others’

Cadence BlackOps: Q4 2014

AKA MS14-060 / CVE-2014-4114

Proof of Concept Steps:

• Generate .ppsx file with python script

• Create a public SMB share with two

files output by script

• Setup listener for connect-back

• Deliver .ppsx to target

• Profit!

Page 8: BlackOps - The Cadence Group · Cadence BlackOps Goals: •Provide an entertaining forum to discuss emerging threats and new security technology •Facilitate access to others’

Cadence BlackOps: Q4 2014

AKA MS14-060 / CVE-2014-4114

DEMO

Page 9: BlackOps - The Cadence Group · Cadence BlackOps Goals: •Provide an entertaining forum to discuss emerging threats and new security technology •Facilitate access to others’

Cadence BlackOps: Q4 2014

AKA MS14-060 / CVE-2014-4114

Howto: Defense

•MS Released patch on 14 OctPATCH

!

•Egress filtering / monitoring

•This is hard

•It takes work

•Can be very effective

0-day defens

e

NOPE!Anti-virus

Page 10: BlackOps - The Cadence Group · Cadence BlackOps Goals: •Provide an entertaining forum to discuss emerging threats and new security technology •Facilitate access to others’

Physical Insecurity

Cadence BlackOps: Q4 2014

Long-range RFID card badge thievery

• Utilizes standard hardware

• Exploits expected behavior

• Runs on batteries, very portable

• Trivial deployment to MiTM

• Grabs cards at up to 3 feet

Page 11: BlackOps - The Cadence Group · Cadence BlackOps Goals: •Provide an entertaining forum to discuss emerging threats and new security technology •Facilitate access to others’

Targets

• IT staff with data center / room

access

• Anyone else

Parts List

• HID MaxiProx $120 Ebay

• Arduino $20

• PCB (optional) $30

• Sdcard breakout $15

• Display (optional) $20

• Various resistors,

capacitors, voltage reg,

batteries, etc.: $20

Cadence BlackOps: Q4 2014

Page 12: BlackOps - The Cadence Group · Cadence BlackOps Goals: •Provide an entertaining forum to discuss emerging threats and new security technology •Facilitate access to others’

Cadence BlackOps: Q4 2014

DEMO

Page 13: BlackOps - The Cadence Group · Cadence BlackOps Goals: •Provide an entertaining forum to discuss emerging threats and new security technology •Facilitate access to others’

Cadence BlackOps: Q4 2014

Now we have the card, so what?

• Enter RFIDler

• $130 riftrecon.com

• Beta grade

• Will emulate / copy any 125-

134KHz

• A bit finicky, but gets it done

Page 14: BlackOps - The Cadence Group · Cadence BlackOps Goals: •Provide an entertaining forum to discuss emerging threats and new security technology •Facilitate access to others’

Cadence BlackOps: Q4 2014

Howto: Defense

• Human Security

• Expensive

• FalliblePeople

• Reactive only

• Can thwart attacks if actively monitored (see point 1)CCTV

• Good addition

• Always a good idea

• [Sidenote – Google 2 factor]

2nd

Factor

Page 15: BlackOps - The Cadence Group · Cadence BlackOps Goals: •Provide an entertaining forum to discuss emerging threats and new security technology •Facilitate access to others’

Q&A

• General questions about topics in this presentation

• Other topics or questions for the group at large

Cadence BlackOps: Q4 2014

• Next time: Q1 2015 – February-ish

• Topic suggestions, interested in

presenting (let’s talk)

FREE STUFF!!

Page 16: BlackOps - The Cadence Group · Cadence BlackOps Goals: •Provide an entertaining forum to discuss emerging threats and new security technology •Facilitate access to others’

www.theCadenceGroup.com

http://www.linkedin.com/company/the-cadence-group

801.554.9881

[email protected]

Contact Us

Erich Ficker

[email protected]

@eficker