Showing posts with label snagg. Show all posts
Showing posts with label snagg. Show all posts

MiTM on VMware Server

Since a little more than year I've been researching on virtualization security, focusing on "real" issues - not the low level stuff which is unlikely to ever turn into an exploit in the real world.
Finally the company I work for rolled out a virtualization security service and people are releasing actual attacks on such infrastructures and it's time to join the party.

I'll start by releasing a very simple tool which is able to perform MITM against VMware Server Console. Isn't that trivial, you might wonder?
Well, as a matter of fact the tool is very simple and error prone: this alpha version is little more than a loop with a couple of connect which was first sketched by Snagg and which I then finished with my non-existant Python coding skills.

But, actually, there are a couple of facts which make this tool interesting.

Fact 1: VMware console will not check for the SSL certificate and won't even warn the user about a wrong certificate. Bad, very bad.

Fact 2: Most SSL MiTM tools will just fail in working with VMware Console since before the SSL connection is enstablished, an unencrypted line is sent through the socket in plaintext, effectively crashing any tool I know about.

Fact 3: The password is not actually sent in cleartext through the pipe. More on this in future posts.

You can grab the alchemic python solution here, but keep in mind that it is mightly unstable in the current version.

Mac Hacking Class and presentation at BH USA

Hey,

so a bit of advertisement for me.
I will do a training at Black Hat USA on Mac OS X hacking, I'm really looking forward to having you as students!
Register yourself here

The class will explain how to assess the security of Mac OS X from the ground up, including how to deal with heap and stack exploitation, Objective-C reversing, Mach API abusing, advanced payload writing and differences between iPhone and OSX exploitation.

Anyway if for whatever reason you can't attend my class(and in that case I'll be very sad), I'll speak with Charlie Miller at the Briefings. Here's the abstract

Snagg

iPhone, Mobile Security and Osx

Hey guys,

so back with some updates on my research. First of all I gave a talk with Charlie Miller on iPhone and OSX payloads at Black Hat Europe.
Here are a few links:
The slides will be available soon.

In May I'm going to join Jeff Moss and a bunch of really cool people in the next Black Hat webcast: Mobility and Security. I hope all of you will register and join the round table.

One last appointment, if anyone wants to meet, I'll be speaking at EuSecWest in London at the end of May.
Snagg

Let your Mach-o fly round-up

Hey all,

this is my first blog post for Nibblesec. So I decided to start from what I did in the last couple of months.
I was mainly involved in some research on OS X. Specifically a way to create a userland execve() on Mac OS X.
So if you are interested in it, here are a few links that might help you:

And finally a nice video I made on my technique and Safari.

I'll be speaking with Charlie Miller about In-memory attacks at Black Hat Europe 2009. I'm looking forward to meeting you there.

Snagg

3, 2, 1... In Mission

Hello Internet,
this is our first post, so stop wondering "who the hell are these NibbleSec guys".
We'll start answering a couple of questions.


  • We're not a commercial entity

  • We're not a ub3r3l33t black-hat crew

  • We're not a new initiative the internet really does not need


NibbleSec is just a label on a team of four friends who live in the Information Security world, and that's it.
We're going to use this blog as a launchpad for some of our researches, publishing tools and insights. There are plenty of similar blogs around the net, so here's our personal version.

We have some nice things in the oven, so stay tuned because we're going to serve a couple of hot dishes in a while!

Oh, we were almost forgetting this one: you might be interested in knowing who's behind NibbleSec.org !?
No problem, here you are: BlackFire, Daath, Ikki and Snagg.

See you soon in the next post!