35
Bringing Sexy Back Breaking in with Style…

Bringing Sexy Back - DEF CON · Bringing Sexy Back Breaking in with Style ... Boring? We have two ways pen testing can be interesting, easy, and surprisingly successful. 1. iPhone

  • Upload
    others

  • View
    2

  • Download
    0

Embed Size (px)

Citation preview

Page 1: Bringing Sexy Back - DEF CON · Bringing Sexy Back Breaking in with Style ... Boring? We have two ways pen testing can be interesting, easy, and surprisingly successful. 1. iPhone

Bringing Sexy BackBreaking in with Style…

Page 2: Bringing Sexy Back - DEF CON · Bringing Sexy Back Breaking in with Style ... Boring? We have two ways pen testing can be interesting, easy, and surprisingly successful. 1. iPhone

Pentest? Really?!?!• Pentest has betting getting a bad rap lately• The demand hasn’t dropped off…• Testers hate doing it because its boring

Page 3: Bringing Sexy Back - DEF CON · Bringing Sexy Back Breaking in with Style ... Boring? We have two ways pen testing can be interesting, easy, and surprisingly successful. 1. iPhone

Why is pentesting boring?

Its seldom about 0day, its most about lame php bugs or password cracking…

Page 4: Bringing Sexy Back - DEF CON · Bringing Sexy Back Breaking in with Style ... Boring? We have two ways pen testing can be interesting, easy, and surprisingly successful. 1. iPhone

Why is pentesting boring?

Customers don’t understand them. I once was hired to do a pen test on a Class C that had

nothing on it.

Page 5: Bringing Sexy Back - DEF CON · Bringing Sexy Back Breaking in with Style ... Boring? We have two ways pen testing can be interesting, easy, and surprisingly successful. 1. iPhone

Why is pentesting boring?

Watching scanners run is boring…

Page 6: Bringing Sexy Back - DEF CON · Bringing Sexy Back Breaking in with Style ... Boring? We have two ways pen testing can be interesting, easy, and surprisingly successful. 1. iPhone

Where is the excitement?

This can’t be it, there must be more to this than some scanners, password crackers, and out of date software. Where is the mystery, the

intrigue, the fun stuff?

Page 7: Bringing Sexy Back - DEF CON · Bringing Sexy Back Breaking in with Style ... Boring? We have two ways pen testing can be interesting, easy, and surprisingly successful. 1. iPhone

Boring?

We have two ways pen testing can be interesting, easy, and surprisingly

successful.

Page 8: Bringing Sexy Back - DEF CON · Bringing Sexy Back Breaking in with Style ... Boring? We have two ways pen testing can be interesting, easy, and surprisingly successful. 1. iPhone

1. iPhone in a box.

Page 9: Bringing Sexy Back - DEF CON · Bringing Sexy Back Breaking in with Style ... Boring? We have two ways pen testing can be interesting, easy, and surprisingly successful. 1. iPhone

iPhone in a box is simple• Step 1 – Get a Box• Step 2 – Put your iPhone in a Box• Step 3 – Mail the box

Page 10: Bringing Sexy Back - DEF CON · Bringing Sexy Back Breaking in with Style ... Boring? We have two ways pen testing can be interesting, easy, and surprisingly successful. 1. iPhone

Step 1 – Get a box

Page 11: Bringing Sexy Back - DEF CON · Bringing Sexy Back Breaking in with Style ... Boring? We have two ways pen testing can be interesting, easy, and surprisingly successful. 1. iPhone

• Get a box.– We used the original iPhone box.– It doesn’t look very suspicious– And it’s the perfect size for everything we

need to fit inside.

Page 12: Bringing Sexy Back - DEF CON · Bringing Sexy Back Breaking in with Style ... Boring? We have two ways pen testing can be interesting, easy, and surprisingly successful. 1. iPhone

Step 2 - Put your iPhone in the box

Page 13: Bringing Sexy Back - DEF CON · Bringing Sexy Back Breaking in with Style ... Boring? We have two ways pen testing can be interesting, easy, and surprisingly successful. 1. iPhone

All the materials…

Page 14: Bringing Sexy Back - DEF CON · Bringing Sexy Back Breaking in with Style ... Boring? We have two ways pen testing can be interesting, easy, and surprisingly successful. 1. iPhone

Battery problems?• The iPhone will last a day or so if it is on

constantly and scanning.• Batteries to the Rescue!

– APC makes mobile batteries…

Page 15: Bringing Sexy Back - DEF CON · Bringing Sexy Back Breaking in with Style ... Boring? We have two ways pen testing can be interesting, easy, and surprisingly successful. 1. iPhone

Battery Problems?• We have found that with a fully charged

battery an iPhone can run for 5 days with activity.

Page 16: Bringing Sexy Back - DEF CON · Bringing Sexy Back Breaking in with Style ... Boring? We have two ways pen testing can be interesting, easy, and surprisingly successful. 1. iPhone

Back to the box…• The default box has enough room for the

phone, the battery, and the cables..• It requires some cutting of plastic

– Easy to do with any knife

Page 17: Bringing Sexy Back - DEF CON · Bringing Sexy Back Breaking in with Style ... Boring? We have two ways pen testing can be interesting, easy, and surprisingly successful. 1. iPhone

Cutting, Cutting, Cutting

Page 18: Bringing Sexy Back - DEF CON · Bringing Sexy Back Breaking in with Style ... Boring? We have two ways pen testing can be interesting, easy, and surprisingly successful. 1. iPhone

All done…

Page 19: Bringing Sexy Back - DEF CON · Bringing Sexy Back Breaking in with Style ... Boring? We have two ways pen testing can be interesting, easy, and surprisingly successful. 1. iPhone

Now for the plastic…

Page 20: Bringing Sexy Back - DEF CON · Bringing Sexy Back Breaking in with Style ... Boring? We have two ways pen testing can be interesting, easy, and surprisingly successful. 1. iPhone

Fits like a glove!

Page 21: Bringing Sexy Back - DEF CON · Bringing Sexy Back Breaking in with Style ... Boring? We have two ways pen testing can be interesting, easy, and surprisingly successful. 1. iPhone

Disable the autolock and poweroff..

Page 22: Bringing Sexy Back - DEF CON · Bringing Sexy Back Breaking in with Style ... Boring? We have two ways pen testing can be interesting, easy, and surprisingly successful. 1. iPhone

Box built, now what?

Page 23: Bringing Sexy Back - DEF CON · Bringing Sexy Back Breaking in with Style ... Boring? We have two ways pen testing can be interesting, easy, and surprisingly successful. 1. iPhone

Configure the iPhone• Jailbreak the iPhone• Install SSH and the BSD subsystems…• Install tcpdump, APLogger, and anything

else you might use…• Do some custom stuff…

Page 24: Bringing Sexy Back - DEF CON · Bringing Sexy Back Breaking in with Style ... Boring? We have two ways pen testing can be interesting, easy, and surprisingly successful. 1. iPhone

What is custom?• How it connects to you…

– You can’t SSH to the phones IP address…– So you can have it connect to you…– Write a program that behaves like shellcode

• Starting a process with a shell• Redirect standard in and out to a shell• Connect to a predetermined address at

specific time intervals • You can use Netcat to list on the receiving

host.

Page 25: Bringing Sexy Back - DEF CON · Bringing Sexy Back Breaking in with Style ... Boring? We have two ways pen testing can be interesting, easy, and surprisingly successful. 1. iPhone

• This process is croned to run every hour on the hour.

• When you get a connection you are inside the network!

• Manually do scans and connect to access points/Other machines.

Page 26: Bringing Sexy Back - DEF CON · Bringing Sexy Back Breaking in with Style ... Boring? We have two ways pen testing can be interesting, easy, and surprisingly successful. 1. iPhone

Set it all up and seal the box up…

Page 27: Bringing Sexy Back - DEF CON · Bringing Sexy Back Breaking in with Style ... Boring? We have two ways pen testing can be interesting, easy, and surprisingly successful. 1. iPhone

Step 3 – Mail the box

Page 28: Bringing Sexy Back - DEF CON · Bringing Sexy Back Breaking in with Style ... Boring? We have two ways pen testing can be interesting, easy, and surprisingly successful. 1. iPhone
Page 29: Bringing Sexy Back - DEF CON · Bringing Sexy Back Breaking in with Style ... Boring? We have two ways pen testing can be interesting, easy, and surprisingly successful. 1. iPhone

Demo of iPhone connection software

Page 30: Bringing Sexy Back - DEF CON · Bringing Sexy Back Breaking in with Style ... Boring? We have two ways pen testing can be interesting, easy, and surprisingly successful. 1. iPhone

2. Phish for it…

Page 31: Bringing Sexy Back - DEF CON · Bringing Sexy Back Breaking in with Style ... Boring? We have two ways pen testing can be interesting, easy, and surprisingly successful. 1. iPhone

• The easiest way to break in to Windows is to ask nicely…

• A good phisihing site isn’t after passwords…• Installing software is far more useful.

Page 32: Bringing Sexy Back - DEF CON · Bringing Sexy Back Breaking in with Style ... Boring? We have two ways pen testing can be interesting, easy, and surprisingly successful. 1. iPhone

• There has been a number of vulnerable ActiveX controls lately that allow for the download and execution of arbitrary programs.

• An ActiveX control like this could great benefit a test

Page 33: Bringing Sexy Back - DEF CON · Bringing Sexy Back Breaking in with Style ... Boring? We have two ways pen testing can be interesting, easy, and surprisingly successful. 1. iPhone

• Grab a CMS, configure it to look like a benefit management company.

• Configure the main page to prompt visitors to install a “secure” ActiveX control.

• Download and install the trojan.• Safeguards have to be put in place

– It can’t infect any site visitor– The trojan has to delete itself and the ActiveX

control after a period of time.– Log everything on the victim machine…

Page 34: Bringing Sexy Back - DEF CON · Bringing Sexy Back Breaking in with Style ... Boring? We have two ways pen testing can be interesting, easy, and surprisingly successful. 1. iPhone

Pen Phising Demo

Page 35: Bringing Sexy Back - DEF CON · Bringing Sexy Back Breaking in with Style ... Boring? We have two ways pen testing can be interesting, easy, and surprisingly successful. 1. iPhone

Thank you.http://erratasec.blogspot.com

http://www.erratasec.com