--- English ---
Following my previous fast analysis of Orange Hadopi Binary, I continued and made a presentation out of what I found.
I planned to present my work at NDH 2010 but due to time constraints it was of course impossible.
Disclaimer : This presentation is here only for informing people. Anyway, the servlet has been taken down for some time now.
I'll post the little scripts which were used for farming IP and the one I made for geolocating later in the week.
Anyway hope you enjoy it ;) ,
m_101
--- Français ---
A la suite de ma rapide analyse précédente sur le logiciel d'Orange, j'ai décidé d'en faire une présentation de ce que j'ai trouver.
J'avais prévu de présenter mon travail à la NDH 2010 mais due à des contraintres de temps (j'avais de toute manière prévu ce cas), c'était bien sur impossible.
Avertissement : Cette présentation n'a été faite qu'à un but d'information! Le servlet d'Orange a de toute manière été désactivé dû aux failles du logiciel.
Je posterais les scripts qui ont été utilisés pour farmer les IP et celui que j'utilise pour la geoip.
J'espère que ça va vous plaire.
m_101
- link : Orange Hadopi Hacking (OpenOffice.Org)
- link : Orange Hadopi Hacking (PowerPoint)
lundi 21 juin 2010
dimanche 20 juin 2010
[FR] NDH 2010 : Bilan
Deuxième NDH pour ma part, ils ont vraiment fait du bon travail et l'évènement est encore mieux que l'année dernière.
Félicitation à Sysdream, aux organisateurs et à tout ceux qui ont rendu possible cet évènement!
On est arrivé à la péniche de la NDH aux alentours de 15h pour parler, boire des bières et rencontrer des personnes de la communauté.
C'était génial! Vraiment marrant et surprenant de voir à quoi ressemblait chacun in real life ;).
Les gens ont commencé à faire la queue aux alentours de 16h. Une fois sur le bateau, nous étions accueilli par une fouille de sac (anti bouteille d'eau, bière, etc) puis par le badge (visiteur ou challenger) et 5 tickets de consos (sandwich, boissons, etc).
Badge visiteur
Badge challenger
Si j'ai 2 badges, ça s'explique par le CTF bien entendu, j'en parle un peu plus bas.
La plupart des conferences qui m'intéressais, je les ais vu en streaming, donc ça c'est plutôt fini en grosse réunion dans un super bar avec des amis ;) .
La plupart des confs étaient de bonnes qualité.
La conférence de GeoHot a été au délà de mes espérances. C'était vraiment intéressant de voir du hack hardware associé au software. Il a parlé des systèmes embarqués au niveau sécurité (Nokia 1661, iPhone et PS3).
Ce qui était surtout super c'était le temps que GeoHot a pris pour répondre aux questions (même celles sans grand intérêt), prendre des photos et parler aux gens.
Concernant le CTF, j'étais vraiment pas préparé et je n'avais pas vraiment prévu de participer (si ce n'est au challenge public). Par la force des choses, j'ai intégré l'équipe Beerware pour remplacer un ami. J'ai donc obtenu un badge challenger à la dernière minute ;).
Le CTF était à mon sens assez frustrant car dès la validation d'un challenge, plus aucune équipe ne pouvait la valider, il fallait être plus rapide que les autres (comme toujours dans ce genre d'épreuves). On a trouvé des failles et les exploits qui vont avec mais pas validable dû à cet raison.
La plupart des challenges qu'on a vu était orienté WEB, autant dire que ce n'était pas du tout mon domaine pour ma part. Les web services étaient coder en C et en Python. Dans le web service en C il y a un buffer overflow (sur d1g1tal y'avait par contre un format string). Les épreuves étaient variées tout de même : reversing, stéganographie, forensics, crypto, etc.
Pendant TOUTE la durée du challenge, il y avait du DOS à gogo, perso j'étais déconnecté toute les 5-10 minutes.
Sur les VM, il y a avait mine de rien pas mals de ports ouverts (et donc de services tournants) :
* VM Windows 2003 Server
VM Debian (Lenny) Linux :
J'ai également trouvé des machines de management en sweepant le sous-réseau sur lequel on était (on avait pas le droit de les attaquer sous peine de ban du CTF bien entendu):
J'avais d'autres scans aussi mais je les ais pas gardé.
J'avouerais qu'on a été plutôt chanceux pour ce CTF, on a évité la grosse vague de DDOS au début du challenge. Ca a duré pendant tout le challenge mais surtout à la fin (perte de 6000 points environ en 5 minutes ...), ça nous a descendu de la première place à la deuxième place.
Les résultats de mi parcours (aux alentours de 5:55 du matin) :
Le CTF s'est achevé à 6:45 du matin.
Les vainqueurs :
1st : WWFamous
2nd: Beerware
3rd : Kowalski
Nous avons ensuite reçu nos récompenses :
Un trophée
Un certificat de participation au CTF :
Et notre prix (formation ECSP - EC-Council Certified Secure Programmer) :
Par ailleurs, je comptais présenter mon analyse du logiciel d'Orange en prévision d'HADOPI, je n'ai évidemment pas pu la donner pour des raisons de temps (c'était de toute manière prévisible).
Je mettrais online les slides ce soir.
Dans son ensemble, cette NDH était une pure réussite et assez fun!
A l'année prochaine j'espère ;).
m_101
Pour les Francophones : Je posterais sûrement une partie en Français pour la suite comme on me l'a fait remarqué ;).
- Un meilleur résumé : http://www.lestutosdenico.com/evenements/nuit-du-hack-2010-compte-rendu
Félicitation à Sysdream, aux organisateurs et à tout ceux qui ont rendu possible cet évènement!
On est arrivé à la péniche de la NDH aux alentours de 15h pour parler, boire des bières et rencontrer des personnes de la communauté.
C'était génial! Vraiment marrant et surprenant de voir à quoi ressemblait chacun in real life ;).
Les gens ont commencé à faire la queue aux alentours de 16h. Une fois sur le bateau, nous étions accueilli par une fouille de sac (anti bouteille d'eau, bière, etc) puis par le badge (visiteur ou challenger) et 5 tickets de consos (sandwich, boissons, etc).
Badge visiteur
Badge challenger
Si j'ai 2 badges, ça s'explique par le CTF bien entendu, j'en parle un peu plus bas.
La plupart des conferences qui m'intéressais, je les ais vu en streaming, donc ça c'est plutôt fini en grosse réunion dans un super bar avec des amis ;) .
La plupart des confs étaient de bonnes qualité.
La conférence de GeoHot a été au délà de mes espérances. C'était vraiment intéressant de voir du hack hardware associé au software. Il a parlé des systèmes embarqués au niveau sécurité (Nokia 1661, iPhone et PS3).
Ce qui était surtout super c'était le temps que GeoHot a pris pour répondre aux questions (même celles sans grand intérêt), prendre des photos et parler aux gens.
Concernant le CTF, j'étais vraiment pas préparé et je n'avais pas vraiment prévu de participer (si ce n'est au challenge public). Par la force des choses, j'ai intégré l'équipe Beerware pour remplacer un ami. J'ai donc obtenu un badge challenger à la dernière minute ;).
Le CTF était à mon sens assez frustrant car dès la validation d'un challenge, plus aucune équipe ne pouvait la valider, il fallait être plus rapide que les autres (comme toujours dans ce genre d'épreuves). On a trouvé des failles et les exploits qui vont avec mais pas validable dû à cet raison.
La plupart des challenges qu'on a vu était orienté WEB, autant dire que ce n'était pas du tout mon domaine pour ma part. Les web services étaient coder en C et en Python. Dans le web service en C il y a un buffer overflow (sur d1g1tal y'avait par contre un format string). Les épreuves étaient variées tout de même : reversing, stéganographie, forensics, crypto, etc.
Pendant TOUTE la durée du challenge, il y avait du DOS à gogo, perso j'étais déconnecté toute les 5-10 minutes.
Sur les VM, il y a avait mine de rien pas mals de ports ouverts (et donc de services tournants) :
* VM Windows 2003 Server
Nmap scan report for 192.168.3.x2 Host is up (0.00099s latency). Not shown: 984 closed ports PORT STATE SERVICE 25/tcp open smtp 80/tcp open http 135/tcp open msrpc 139/tcp open netbios-ssn 445/tcp open microsoft-ds 1025/tcp open NFS-or-IIS 1026/tcp open LSA-or-nterm 1027/tcp open IIS 1028/tcp open unknown 1029/tcp open ms-lsa 3306/tcp open mysql 3389/tcp open ms-term-serv 6666/tcp open irc 8080/tcp open http-proxy 12345/tcp open netbus 31337/tcp open Elite Device type: general purpose Running: Microsoft Windows 2003 OS details: Microsoft Windows Server 2003 SP1 or SP2, Microsoft Windows Server 2003 SP2 Network Distance: 1 hop
VM Debian (Lenny) Linux :
Nmap scan report for 192.168.3.73 Host is up (0.00097s latency). Not shown: 988 closed ports PORT STATE SERVICE 22/tcp open ssh 80/tcp open http 82/tcp open xfer 113/tcp open auth 1234/tcp open hotline 2000/tcp filtered cisco-sccp 6666/tcp open irc 8080/tcp open http-proxy 8081/tcp open blackice-icecap 8083/tcp open unknown 8084/tcp open unknown 8090/tcp open unknown Device type: general purpose Running: Linux 2.6.X OS details: Linux 2.6.15 - 2.6.27 Network Distance: 1 hop
J'ai également trouvé des machines de management en sweepant le sous-réseau sur lequel on était (on avait pas le droit de les attaquer sous peine de ban du CTF bien entendu):
Nmap scan report for dashboard.ndh2010.com (192.168.3.160) Host is up (0.00053s latency). Not shown: 997 closed ports PORT STATE SERVICE 22/tcp open ssh 80/tcp open http 3306/tcp open mysql Device type: general purpose Running: Linux 2.6.X OS details: Linux 2.6.15 - 2.6.27 Network Distance: 1 hop Nmap scan report for 192.168.3.161 Host is up (0.00055s latency). Not shown: 994 closed ports PORT STATE SERVICE 22/tcp open ssh 111/tcp open rpcbind 902/tcp open iss-realsecure 8009/tcp open ajp13 8222/tcp open unknown 8333/tcp open unknown Device type: general purpose Running: Linux 2.6.X OS details: Linux 2.6.18 - 2.6.27 Network Distance: 1 hop Nmap scan report for 192.168.3.162 Host is up (0.00059s latency). Not shown: 996 closed ports PORT STATE SERVICE 22/tcp open ssh 80/tcp open http 111/tcp open rpcbind 3306/tcp open mysql Device type: general purpose Running: Linux 2.6.X OS details: Linux 2.6.15 - 2.6.27 Network Distance: 1 hop Nmap scan report for pfsense-1.ndh2010.com (192.168.3.254) Host is up (0.00074s latency). Not shown: 997 filtered ports PORT STATE SERVICE 22/tcp open ssh 53/tcp open domain 443/tcp open https Warning: OSScan results may be unreliable because we could not find at least 1 open and 1 closed port Device type: general purpose Running (JUST GUESSING) : Linux 2.6.X (91%) Aggressive OS guesses: Linux 2.6.29 (91%) No exact OS matches for host (test conditions non-ideal).
J'avais d'autres scans aussi mais je les ais pas gardé.
J'avouerais qu'on a été plutôt chanceux pour ce CTF, on a évité la grosse vague de DDOS au début du challenge. Ca a duré pendant tout le challenge mais surtout à la fin (perte de 6000 points environ en 5 minutes ...), ça nous a descendu de la première place à la deuxième place.
Les résultats de mi parcours (aux alentours de 5:55 du matin) :
Le CTF s'est achevé à 6:45 du matin.
Les vainqueurs :
1st : WWFamous
2nd: Beerware
3rd : Kowalski
Nous avons ensuite reçu nos récompenses :
Un trophée
Un certificat de participation au CTF :
Et notre prix (formation ECSP - EC-Council Certified Secure Programmer) :
Par ailleurs, je comptais présenter mon analyse du logiciel d'Orange en prévision d'HADOPI, je n'ai évidemment pas pu la donner pour des raisons de temps (c'était de toute manière prévisible).
Je mettrais online les slides ce soir.
Dans son ensemble, cette NDH était une pure réussite et assez fun!
A l'année prochaine j'espère ;).
m_101
Pour les Francophones : Je posterais sûrement une partie en Français pour la suite comme on me l'a fait remarqué ;).
- Un meilleur résumé : http://www.lestutosdenico.com/evenements/nuit-du-hack-2010-compte-rendu
[EN] NDH 2010 : Results!
Second NDH for me and it got even better than last year!
Kudos to Sysdream, HZV, the organizers and all the people who made this event be possible.
We arrived at the NDH boat around 15PM and starting to talk, drink beers and meeting people we only knew virtually on IRC.
It was pretty awesome, we were surprised at how each others looks like but a it was pleasant surprise anyway.
Around 16PM, people started to queue up to enter the boat, we were greeted with 5 tickets for sandwiches or drinks (beeers! :) ).
And a pass depending on wheter you were a speaker, a guest or a challenger.
Guest badge
Challenger badge :
If I have two badges, it's because of the CTF ... more on that a little bit later.
I saw most of the conferences I was interested in in streaming so it was pretty much more like a huge bar with friends :) .
The talks were pretty much of good quality.
GeoHot talk was awesome, I was impressed by the "coolness" of the guy ... I mean, taking time to answer questions (even dumb ones), take pictures with the ones who want it and talk after the conference.
I wasn't prepared at all for the CTF as I didn't really intended to participate (and I was smoking dead and tired ><) but due to circonstances I had to replace a friend of ours in Beerware team. So I grabbed a Challenger Badge at the last minute ;).
The challenge was pretty much frustrating since as soon as a challenge is validated, no more teams can validate it. So we found some loophole and solutions but submitted them after the firsts so we couldn't validate some of the challenges.
Most of the challenges we saw were Web Based with some customs servers written (in Python and C). The C server had a buffer overflow in it. Did some reversing, steganography, forensics, crypto and others stuffs as well.
During the whole challenge there were DOS, I was disconnected every 5-10 minutes.
We had quite some opened ports :
* Windows 2003 Server VM
Debian (Lenny) Linux VM :
There were also some management servers I found while sweeping the sub-network (didn't have any rights to touch them or ban from the CTF) :
I didn't keep the other scans though.
We were quite lucky on this one, we avoided the first massive wave of DDOS. We got DOS during the whole challenge and particularly at the end (-6000 points in 5 minutes at some point), it got us downgraded from 1st to 2nd. Bye bye miami :(.
So the mid-results (was aroung 5:55AM) :
The CTF stopped at 6:45AM.
Final results :
1st : WWFamous
2nd: Beerware
3rd : Kowalski
We then received our prizes :
Our cup
The CTF participation certificate :
And our prize (ECSP - EC-Council Certified Secure Programmer formation) :
By the way, due to time limitation, I couldn't talk about my analysis on Orange HADOPI Software v1.
I will post my slides tonight as soon as I come back to my place ;).
Overall the NDH 2010 was pretty successful and enjoyable :) .
See you next year I hope.
Cheers,
m_101
For French speakers : I will post a French version as soon as I can.
- A better recume : http://www.lestutosdenico.com/evenements/nuit-du-hack-2010-compte-rendu
Kudos to Sysdream, HZV, the organizers and all the people who made this event be possible.
We arrived at the NDH boat around 15PM and starting to talk, drink beers and meeting people we only knew virtually on IRC.
It was pretty awesome, we were surprised at how each others looks like but a it was pleasant surprise anyway.
Around 16PM, people started to queue up to enter the boat, we were greeted with 5 tickets for sandwiches or drinks (beeers! :) ).
And a pass depending on wheter you were a speaker, a guest or a challenger.
Guest badge
Challenger badge :
If I have two badges, it's because of the CTF ... more on that a little bit later.
I saw most of the conferences I was interested in in streaming so it was pretty much more like a huge bar with friends :) .
The talks were pretty much of good quality.
GeoHot talk was awesome, I was impressed by the "coolness" of the guy ... I mean, taking time to answer questions (even dumb ones), take pictures with the ones who want it and talk after the conference.
I wasn't prepared at all for the CTF as I didn't really intended to participate (and I was smoking dead and tired ><) but due to circonstances I had to replace a friend of ours in Beerware team. So I grabbed a Challenger Badge at the last minute ;).
The challenge was pretty much frustrating since as soon as a challenge is validated, no more teams can validate it. So we found some loophole and solutions but submitted them after the firsts so we couldn't validate some of the challenges.
Most of the challenges we saw were Web Based with some customs servers written (in Python and C). The C server had a buffer overflow in it. Did some reversing, steganography, forensics, crypto and others stuffs as well.
During the whole challenge there were DOS, I was disconnected every 5-10 minutes.
We had quite some opened ports :
* Windows 2003 Server VM
Nmap scan report for 192.168.3.x2 Host is up (0.00099s latency). Not shown: 984 closed ports PORT STATE SERVICE 25/tcp open smtp 80/tcp open http 135/tcp open msrpc 139/tcp open netbios-ssn 445/tcp open microsoft-ds 1025/tcp open NFS-or-IIS 1026/tcp open LSA-or-nterm 1027/tcp open IIS 1028/tcp open unknown 1029/tcp open ms-lsa 3306/tcp open mysql 3389/tcp open ms-term-serv 6666/tcp open irc 8080/tcp open http-proxy 12345/tcp open netbus 31337/tcp open Elite Device type: general purpose Running: Microsoft Windows 2003 OS details: Microsoft Windows Server 2003 SP1 or SP2, Microsoft Windows Server 2003 SP2 Network Distance: 1 hop
Debian (Lenny) Linux VM :
Nmap scan report for 192.168.3.73 Host is up (0.00097s latency). Not shown: 988 closed ports PORT STATE SERVICE 22/tcp open ssh 80/tcp open http 82/tcp open xfer 113/tcp open auth 1234/tcp open hotline 2000/tcp filtered cisco-sccp 6666/tcp open irc 8080/tcp open http-proxy 8081/tcp open blackice-icecap 8083/tcp open unknown 8084/tcp open unknown 8090/tcp open unknown Device type: general purpose Running: Linux 2.6.X OS details: Linux 2.6.15 - 2.6.27 Network Distance: 1 hop
There were also some management servers I found while sweeping the sub-network (didn't have any rights to touch them or ban from the CTF) :
Nmap scan report for dashboard.ndh2010.com (192.168.3.160) Host is up (0.00053s latency). Not shown: 997 closed ports PORT STATE SERVICE 22/tcp open ssh 80/tcp open http 3306/tcp open mysql Device type: general purpose Running: Linux 2.6.X OS details: Linux 2.6.15 - 2.6.27 Network Distance: 1 hop Nmap scan report for 192.168.3.161 Host is up (0.00055s latency). Not shown: 994 closed ports PORT STATE SERVICE 22/tcp open ssh 111/tcp open rpcbind 902/tcp open iss-realsecure 8009/tcp open ajp13 8222/tcp open unknown 8333/tcp open unknown Device type: general purpose Running: Linux 2.6.X OS details: Linux 2.6.18 - 2.6.27 Network Distance: 1 hop Nmap scan report for 192.168.3.162 Host is up (0.00059s latency). Not shown: 996 closed ports PORT STATE SERVICE 22/tcp open ssh 80/tcp open http 111/tcp open rpcbind 3306/tcp open mysql Device type: general purpose Running: Linux 2.6.X OS details: Linux 2.6.15 - 2.6.27 Network Distance: 1 hop Nmap scan report for pfsense-1.ndh2010.com (192.168.3.254) Host is up (0.00074s latency). Not shown: 997 filtered ports PORT STATE SERVICE 22/tcp open ssh 53/tcp open domain 443/tcp open https Warning: OSScan results may be unreliable because we could not find at least 1 open and 1 closed port Device type: general purpose Running (JUST GUESSING) : Linux 2.6.X (91%) Aggressive OS guesses: Linux 2.6.29 (91%) No exact OS matches for host (test conditions non-ideal).
I didn't keep the other scans though.
We were quite lucky on this one, we avoided the first massive wave of DDOS. We got DOS during the whole challenge and particularly at the end (-6000 points in 5 minutes at some point), it got us downgraded from 1st to 2nd. Bye bye miami :(.
So the mid-results (was aroung 5:55AM) :
The CTF stopped at 6:45AM.
Final results :
1st : WWFamous
2nd: Beerware
3rd : Kowalski
We then received our prizes :
Our cup
The CTF participation certificate :
And our prize (ECSP - EC-Council Certified Secure Programmer formation) :
By the way, due to time limitation, I couldn't talk about my analysis on Orange HADOPI Software v1.
I will post my slides tonight as soon as I come back to my place ;).
Overall the NDH 2010 was pretty successful and enjoyable :) .
See you next year I hope.
Cheers,
m_101
For French speakers : I will post a French version as soon as I can.
- A better recume : http://www.lestutosdenico.com/evenements/nuit-du-hack-2010-compte-rendu
jeudi 17 juin 2010
Nuit du Hack 2010 - Night Da Hack 2010
Ready? Ready? Ready?
Let's Go!
Hacking is a whole art, science, culture, call it whatever you like, hackers are unique people but as all people, we all need to meet and see each other in real life.
Night Da Hack is a French hacking event hosted in Paris on a boat! It will receive quite some nice talks and guests.
Here is the talks program :
After that, from midnight till 7AM, there will be a CTF.
Constesters will have to protect their virtual server and hack the other servers.
As every year, the challenge is kept secret, but as usual the categories won't change I guess :
- reversing
- exploitation
- bruteforcing authentification
- web hacking
- etc
What kind of OS? We sure don't know but I bet that will all the ROP, DEP Bypass, SEHOP and other papers on the latest Windows protections, it's possible that Windows Server 2008 might be there :) .
For Linux, latest version? What distribution? We'll see.
There aren't anymore any tickets for this conference but it was really really cheap for what it is :
- Basic pack : 25€ (ticket)
- Premium pack : 50€ (ticket + cap + tshirt)
I wonder if they happen to accept last minute talks but I doubt that .... even though they would, I might not even have time to write one :(.
Hope to see you there for those of whom who have their tickets :) .
m_101
- link : Night Da Hack
Let's Go!
Hacking is a whole art, science, culture, call it whatever you like, hackers are unique people but as all people, we all need to meet and see each other in real life.
Night Da Hack is a French hacking event hosted in Paris on a boat! It will receive quite some nice talks and guests.
Here is the talks program :
| Time Slot | Track 1 | Track 2 |
| 17h-17h30 | Security vulnerabilities disclosure, challenges and risks (Jérome Hennecart / Raphael Rault) | Unix Malwares (Julien Reveret) |
| 17h45-18h15 | Security vulnerabilities disclosure, challenges and risks II | XeeK : XSS Easy Exploitation Kernel (Emilien Girault) |
| 18h30-19h | Evolution IT (Gael THEROND) | GPGPU and its implications on security of encryption systems (Lucas Fernandez) |
| 19h15-19h45 | HZVault (Majinboo) | Antivirus Security is a failure (Stefan Leberre) |
| 20h-21h | Cracking the Playstation 3 (GeoHotz) | Cracking the Playstation 3 (GeoHotz) |
| 21h15-21h45 | xdbg, an open-source disassembler and debugger (Christophe Devine) | Virtualisation & security (Emanuel Istace) |
| 22h-23h | Advanced Mac OS X Physical Memory Analysis (Matthieu Suiche) | Advanced Mac OS X Physical Memory Analysis (Matthieu Suiche) |
| 23h15-23h45 | Stack Smashing Protector (Paul Rascagneres - RootBSD) | Advanced lockpicking techniques (Cocolitos / Mr. Jack) |
After that, from midnight till 7AM, there will be a CTF.
Constesters will have to protect their virtual server and hack the other servers.
As every year, the challenge is kept secret, but as usual the categories won't change I guess :
- reversing
- exploitation
- bruteforcing authentification
- web hacking
- etc
What kind of OS? We sure don't know but I bet that will all the ROP, DEP Bypass, SEHOP and other papers on the latest Windows protections, it's possible that Windows Server 2008 might be there :) .
For Linux, latest version? What distribution? We'll see.
There aren't anymore any tickets for this conference but it was really really cheap for what it is :
- Basic pack : 25€ (ticket)
- Premium pack : 50€ (ticket + cap + tshirt)
I wonder if they happen to accept last minute talks but I doubt that .... even though they would, I might not even have time to write one :(.
Hope to see you there for those of whom who have their tickets :) .
m_101
- link : Night Da Hack
dimanche 13 juin 2010
Fast analysis of Orange Hadopi Executable
I've read Bluetouff article here. From that point, I decided to take a rapid look at how is that possible?
Be careful, this must be considered as a MALWARE!
For starters, the installer is packed with UPX but it doesn't need any serial for the installation to take place. The serial is only there to activate the software.
After installing the software, you get a bunch of executables :
- cdtsvc.exe : service of download control
- cdtsvc64.exe : same as cdtsvc.exe but for 64 bits
- cdtupd.exe : probably the executable for checking updates
It seems that none of the executables are packed or whatsoever.
Just analyzing cdtsvc.exe, I got quite a bunch of informations on the executable itself.
Looking at C string references and unicode strings, you get to have those informations :
The author of the software is named jbroutin, chances are that his last name is Broutin. It clearly show HADOPI projects and using Visual Studio 2008.
Looking at the code, we can confirm that he's using C++ or some other kind of oriented object langage (there are lots of get() and set()).
Nordnet contacted Bluetouff so the URL makes sense. It might be the URL for the Java Applet Bluetouff was talking about. I just can't imagine the damage it could be done injecting code in it.
For the RSA Key, I don't know what it's for for now. The RSA Key shown here is encoded using Base64 for those who were asking themselves.
Looking more, we see stuffs like these :
Ok we now know that we really are dealing with some HADOPI crap.
going further :
No wonder that Bluetouff get to have a lot of informations using Wireshark ...
We haven't even looked at the code yet that we have quite some infos ...
Cross-referencing the string with "HTTP/1.0" we land in a subroutine at address 0x405574.
This routine seems to construct some kind of URLs and make a request with it.
Looking at where it's called from, you get a bunch of function but at the top is 0x4027EB. This seems to be the main routine which set up the service and stuffs.
I look at one of the functions that called directly 0x405574 and there was 0x406991 : this function seems to check for some kind of updates and licence check too but I dunno, what would be cdtupd.exe then?
From 0x406991 I got this sequence of numbers :
I don't know about the first two (they might be OID, reverse DNS, or something else).
For the second groups, they look like IPs.
I tried to have a DNS query with all of thoses, but I only get an answer for 33.1.1.1 :
I also found some strange stuffs by cross referencing an API called CreateToolhelp32Snapshot() . I landed in routine 0x40C225, why the hell is the software going around all the processes?
I didnt dig further but it seems strange to me.
That's all I got for today, it took me around 20 minutes to get all that ... what about the people who spent hours on this? They might already have a clone or something else entirely.
m_101
- link : Orange HADOPI Software
- link : Installed files
Be careful, this must be considered as a MALWARE!
For starters, the installer is packed with UPX but it doesn't need any serial for the installation to take place. The serial is only there to activate the software.
After installing the software, you get a bunch of executables :
- cdtsvc.exe : service of download control
- cdtsvc64.exe : same as cdtsvc.exe but for 64 bits
- cdtupd.exe : probably the executable for checking updates
It seems that none of the executables are packed or whatsoever.
Just analyzing cdtsvc.exe, I got quite a bunch of informations on the executable itself.
Looking at C string references and unicode strings, you get to have those informations :
Path : C:\\Documents and Settings\\jbroutin\\Mes documents\\Visual Studio 2008\\Projects\\ddp-hadopi\\hadopi-client-gui\\trunk\\Release\\cdtsvc.pdb RSA Key : BgIAAACkAABSU0ExAAQAAAEAAQCzLXpRE/3Y3n9F1lf2wlRsQGzgs4gfBRNj/PmPArxOtJ1Z1ra8bTktvDCyLsImEc12d6DvVeYsAIgjMZNxQqczzhEla7ZAXQXOOBo38ZUZot961pXx76GCRMAfAYz2S3O79bBGCtJ5wh3UcmvAUcEmdqLzFebBw7Ef+qxyfgamyw== URL : http://update-cdt.nordnet.fr/hadopi-server-technical-ws-1
The author of the software is named jbroutin, chances are that his last name is Broutin. It clearly show HADOPI projects and using Visual Studio 2008.
Looking at the code, we can confirm that he's using C++ or some other kind of oriented object langage (there are lots of get() and set()).
Nordnet contacted Bluetouff so the URL makes sense. It might be the URL for the Java Applet Bluetouff was talking about. I just can't imagine the damage it could be done injecting code in it.
For the RSA Key, I don't know what it's for for now. The RSA Key shown here is encoded using Base64 for those who were asking themselves.
Looking more, we see stuffs like these :
hadopi
Ok we now know that we really are dealing with some HADOPI crap.
going further :
HTTP/1.0 [...] Content-Type: application/x-www-form-urlencoded
No wonder that Bluetouff get to have a lot of informations using Wireshark ...
We haven't even looked at the code yet that we have quite some infos ...
Cross-referencing the string with "HTTP/1.0" we land in a subroutine at address 0x405574.
This routine seems to construct some kind of URLs and make a request with it.
Looking at where it's called from, you get a bunch of function but at the top is 0x4027EB. This seems to be the main routine which set up the service and stuffs.
I look at one of the functions that called directly 0x405574 and there was 0x406991 : this function seems to check for some kind of updates and licence check too but I dunno, what would be cdtupd.exe then?
From 0x406991 I got this sequence of numbers :
0.2.1.1.3 0.2.1.3.2 33.1.1.1 33.2.1.3 33.2.2.1 33.2.1.2
I don't know about the first two (they might be OID, reverse DNS, or something else).
For the second groups, they look like IPs.
I tried to have a DNS query with all of thoses, but I only get an answer for 33.1.1.1 :
m_101@m_101:~$ nslookup 33.1.1.1 Server: 192.168.1.1 Address: 192.168.1.1#53 Non-authoritative answer: *** Can't find 1.1.1.33.in-addr.arpa.: No answer Authoritative answers can be found from: 33.in-addr.arpa origin = CON1R.NIPR.MIL mail addr = DANIEL\.KNOPPS.DISA.MIL serial = 2010061101 refresh = 10800 retry = 900 expire = 1209600 minimum = 10800
I also found some strange stuffs by cross referencing an API called CreateToolhelp32Snapshot() . I landed in routine 0x40C225, why the hell is the software going around all the processes?
I didnt dig further but it seems strange to me.
That's all I got for today, it took me around 20 minutes to get all that ... what about the people who spent hours on this? They might already have a clone or something else entirely.
m_101
- link : Orange HADOPI Software
- link : Installed files
Decoding vigenère
I was reading Simon Singh book "The Code Book" when I stumbled accross Vigenère, I had time so I decided to code something to break Vigenère.
Here I'll present the method used to break Vigenère and release the code. The code is incomplete! I didn't code the decoding routine completeoy since I realize that decoding Vigenère is useless nowadays and I did the most interesting part : the kasisky algorithm.
The main interest of Vigenère code breaking is about elaborating the needed algorithms.
Vigenère code breaking go as follow :
- Find the key size using kasisky examination or index of coincidence
- Frequency analysis on each subtext : nbSubtext = szKey
I chose to use the kasisky examination for searching the key size.
I elaborated a recursive algorithm to build my dictionnary of ALL possible words of any size in the crypted text using a binary tree.
The algorithm steps are as follow :
The pseudo code is iterative.
The recursive algorithm is in dict_word_add().
With a 512 bytes word, you have more than 130k possible words all uniques, no duplicates.
We track offsets, and counts of each words
After finding the key size, we do a frequency analysis of each subtext.
The only part missing to have a complete Vigenère code breaking is a reliable (and simple) algorithm to shift the frequencies to match. When that's done, you have the correspondance between the characters and can thus decode the ciphered text without the key.
In the sources I present, I sorted the frequencies in order to show them on screen. It isn't a step of the decoding.
There is a mitigation against Vigenère code breaking, use a key as long as the text, or the Vernam Code which is more commonly known as the one time pad code. The problem with one time pad code is the management and distribution of keys.
The code isn't clean at all but I release it for interested people as if I don't, it will be forgotten in my hard drive.
Hope you enjoy it.
m_101
- Source code : http://rapidshare.com/files/398364832/cryptanalysis.tar.gz.html
MD5: CF5BA403FB9D9106FDF51D5AEB33C526
Here I'll present the method used to break Vigenère and release the code. The code is incomplete! I didn't code the decoding routine completeoy since I realize that decoding Vigenère is useless nowadays and I did the most interesting part : the kasisky algorithm.
The main interest of Vigenère code breaking is about elaborating the needed algorithms.
Vigenère code breaking go as follow :
- Find the key size using kasisky examination or index of coincidence
- Frequency analysis on each subtext : nbSubtext = szKey
I chose to use the kasisky examination for searching the key size.
I elaborated a recursive algorithm to build my dictionnary of ALL possible words of any size in the crypted text using a binary tree.
The algorithm steps are as follow :
begin
size = 1
begin loop_word_size
begin loop_word_add
dict_word_add (crypted, szWord)
crypted = crypted + 1
goto loop_word_add as long as we aren't at end of crypted
size = size + 1
goto loop_word_size as long as size != szCrypted
The pseudo code is iterative.
The recursive algorithm is in dict_word_add().
With a 512 bytes word, you have more than 130k possible words all uniques, no duplicates.
We track offsets, and counts of each words
After finding the key size, we do a frequency analysis of each subtext.
The only part missing to have a complete Vigenère code breaking is a reliable (and simple) algorithm to shift the frequencies to match. When that's done, you have the correspondance between the characters and can thus decode the ciphered text without the key.
In the sources I present, I sorted the frequencies in order to show them on screen. It isn't a step of the decoding.
There is a mitigation against Vigenère code breaking, use a key as long as the text, or the Vernam Code which is more commonly known as the one time pad code. The problem with one time pad code is the management and distribution of keys.
The code isn't clean at all but I release it for interested people as if I don't, it will be forgotten in my hard drive.
Hope you enjoy it.
m_101
- Source code : http://rapidshare.com/files/398364832/cryptanalysis.tar.gz.html
MD5: CF5BA403FB9D9106FDF51D5AEB33C526
mercredi 2 juin 2010
BuKoG KeyGenMe #1
Today, I ate some little keygenme, quite interesting in fact for how it was conceived.
First of all, since it's level 2 :
- no packer
- no obfuscator
- no protections but serial checking
It was pretty straightforward to find the serial checking routine. It's located in DialogFunc().
From there, we just need to identify username and serial fields using manual boron tagging.
After that, stumble upon an interesting routine :
As we can see, it's wrapping a call to some routine, which is in fact the serial checking routine.
Why is this wrapped? We'll see that later ;) .
Anyway, the serial checking routine is as followed :
Having identified the username and serial buffers previously, it's get a lot easier.
We see that the return address depend on the last byte of the following operation : hash(username) - hash(serial) .
Since a byte contains 256 values, it means that we'll have 256 return values too.
We don't need to launch the crackme yet. Static analysis is a bit harder but way more challenging :) .
So we called serial_check_wrapper() located at address 0x004010FB.
We should return to 0x00401100 after the serial_check() routine but since we modify the last byte, it never happens.
The address we return should be of the form : 0x004011XX where XX is our modified byte.
Looking after the serial_check_wrapper() routine, we see a bunch of returns and an interesting line around 0x00401113.
So 255 out of 256 we get the "Wrong Serial" message.
Before making the keygen, we need to analyse the hash() function.
The hash function is as follow :
We can see here that it's using some array.
Where is it generated?
We can easily try to locate it using cross referencing, it happens that only hash() use it.
Let's see the data section. Just before the used array, there is an hInstance variable.
Cross referencing it, happens to land us in a CRC32 802.3 routine :
The idenfitication process of this function went through reversing and searching about that magic number : 0x0EDB88320.
So we have all we need for a keygen :
- hash() use crc32 802.3 table
- serial_check() returns to 0x004011XX
- XX must be equal to 0x13 if we want correct message
- (hash(username) - hash(serial)) & 0xFF must be equal to 0x13
Using all this, I used the bruteforce approach. I only bruteforce the first 1000 numbers but it's enough.
Here is the keygen :
Hope you enjoyed this small snack :) .
m_101
- link : BuKoG KeyGenMe #1
First of all, since it's level 2 :
- no packer
- no obfuscator
- no protections but serial checking
It was pretty straightforward to find the serial checking routine. It's located in DialogFunc().
From there, we just need to identify username and serial fields using manual boron tagging.
After that, stumble upon an interesting routine :
.text:004010FB serial_check_wrapper proc near ; CODE XREF: DialogFunc+93 .text:004010FB call serial_check .text:00401100 retn .text:00401100 serial_check_wrapper endp
As we can see, it's wrapping a call to some routine, which is in fact the serial checking routine.
Why is this wrapped? We'll see that later ;) .
Anyway, the serial checking routine is as followed :
.text:00401200 serial_check proc near ; CODE XREF: serial_check_wrapper .text:00401200 push offset username .text:00401205 call hash .text:0040120A push eax .text:0040120B push offset serial .text:00401210 call hash .text:00401215 pop ebx .text:00401216 sub ebx, eax .text:00401218 mov [ebp-8], bl ; change return address .text:0040121B mov eax, 0 .text:00401220 retn .text:00401220 serial_check endp
Having identified the username and serial buffers previously, it's get a lot easier.
We see that the return address depend on the last byte of the following operation : hash(username) - hash(serial) .
Since a byte contains 256 values, it means that we'll have 256 return values too.
We don't need to launch the crackme yet. Static analysis is a bit harder but way more challenging :) .
So we called serial_check_wrapper() located at address 0x004010FB.
We should return to 0x00401100 after the serial_check() routine but since we modify the last byte, it never happens.
The address we return should be of the form : 0x004011XX where XX is our modified byte.
Looking after the serial_check_wrapper() routine, we see a bunch of returns and an interesting line around 0x00401113.
So 255 out of 256 we get the "Wrong Serial" message.
Before making the keygen, we need to analyse the hash() function.
The hash function is as follow :
.text:00401247 hash proc near ; CODE XREF: serial_check+5 .text:00401247 ; serial_check+10 .text:00401247 .text:00401247 str = dword ptr 8 .text:00401247 .text:00401247 push ebp .text:00401248 mov ebp, esp .text:0040124A mov eax, 0FFFFFFFFh .text:0040124F mov esi, [ebp+str] .text:00401252 xor edx, edx .text:00401254 .text:00401254 loc_401254: ; CODE XREF: hash+2D .text:00401254 mov ebx, eax .text:00401256 shr ebx, 8 .text:00401259 mov ecx, eax .text:0040125B and ecx, 0FFh .text:00401261 mov dl, [esi] .text:00401263 cmp dl, 0 .text:00401266 jz short loc_401276 .text:00401268 xor edx, ecx .text:0040126A xor ebx, dword_4030CC[edx*4] .text:00401271 mov eax, ebx .text:00401273 inc esi .text:00401274 jmp short loc_401254 .text:00401276 ; --------------------------------------------------------------------------- .text:00401276 .text:00401276 loc_401276: ; CODE XREF: hash+1F .text:00401276 xor eax, 0FFFFFFFFh .text:00401279 leave .text:0040127A retn 4 .text:0040127A hash endp
We can see here that it's using some array.
Where is it generated?
We can easily try to locate it using cross referencing, it happens that only hash() use it.
Let's see the data section. Just before the used array, there is an hInstance variable.
Cross referencing it, happens to land us in a CRC32 802.3 routine :
.text:00401221 crc32_ieee8023 proc near ; CODE XREF: start .text:00401221 mov ecx, 100h .text:00401226 mov edx, 0EDB88320h .text:0040122B .text:0040122B loc_40122B: ; CODE XREF: crc32_ieee8023+23 .text:0040122B lea eax, [ecx-1] .text:0040122E push ecx .text:0040122F mov ecx, 8 .text:00401234 .text:00401234 loc_401234: ; CODE XREF: crc32_ieee8023:loc_40123A .text:00401234 shr eax, 1 .text:00401236 jnb short loc_40123A .text:00401238 xor eax, edx .text:0040123A .text:0040123A loc_40123A: ; CODE XREF: crc32_ieee8023+15 .text:0040123A loop loc_401234 .text:0040123C pop ecx .text:0040123D mov hInstance[ecx*4], eax .text:00401244 loop loc_40122B .text:00401246 retn .text:00401246 crc32_ieee8023 endp
The idenfitication process of this function went through reversing and searching about that magic number : 0x0EDB88320.
So we have all we need for a keygen :
- hash() use crc32 802.3 table
- serial_check() returns to 0x004011XX
- XX must be equal to 0x13 if we want correct message
- (hash(username) - hash(serial)) & 0xFF must be equal to 0x13
Using all this, I used the bruteforce approach. I only bruteforce the first 1000 numbers but it's enough.
Here is the keygen :
// BuKoBG Keygenme #1 #include#include // crc32 unsigned int* crc32 (unsigned int polynom) { unsigned short int carry; int i, j; size_t n; unsigned int *crc32_table; n = 256; crc32_table = calloc (n, sizeof(*crc32_table)); if (!crc32_table) return NULL; for (i = n - 1; i >= 0; i--) { crc32_table[i] = i; for (j = 7; j >= 0; j--) { carry = crc32_table[i] & 1; crc32_table[i] >>= 1; if (carry) crc32_table[i] ^= polynom; } } return crc32_table; } // hash unsigned int hash (unsigned char *str, size_t len) { size_t i, index; unsigned int hashed = -1, *hashtable; // check pointers if (!str || !len) return -1; // generate crc32 IEEE 802.3 table hashtable = crc32(0xedb88320); // generate serial i = 0; index = 0; while (str[i] && i < len) { index = str[i] ^ (hashed & 0xff); hashed = (hashed >> 8) ^ hashtable[index]; ++i; } hashed ^= -1; // clean up free(hashtable); return hashed; } // keygen unsigned int keygen (unsigned char *username, size_t userlen) { unsigned int hash1, hash2, key = -1, licence, serial; unsigned char serial_str[4] = {0}; size_t seriallen = 4; hash1 = hash (username, userlen); // bruteforce serial for (licence = 0, serial = 0; (licence & 0xff) != 0x13; serial++) { // convert integer to string snprintf(serial_str, seriallen, "%03u", serial); hash2 = hash (serial_str, seriallen); licence = hash1 - hash2; } return --serial; } int main (int argc, char *argv[]) { unsigned char username[256] = {0}; unsigned int serial; size_t len = 256; printf("Username : "); gets(username); serial = keygen (username, len); // limit search to first 1000 numbers if (serial < 1000) printf("\nSerial : %03u\n", serial); else printf("No serial found\n"); return 0; }
Hope you enjoyed this small snack :) .
m_101
- link : BuKoG KeyGenMe #1
vendredi 28 mai 2010
BratAlarm's Just a little crackme
It's been some time since I updated my blog but today I got bored and reversed a very little crackme.
It is the BratAlarm "Just a little crackme" that I'm going to talk about.
It was a bit interesting in the sense that you need to have basic mathematics knowledge.
Basic maths knowledge
Complex numbers are used throughout the whole keygenme to generate the serial.
Complex number basic operations used are the following :
multiplication : (a, b) * (c, d) = (a*c - b*d, b*c + a*d) = (a + i*b) * (c + i*d)
addition : (a, b) + (c, d) = (a + c, b + d) = (a + i*b) + (c + i*d)
Where is the serial checking and generation located?
First of all, this keygenme wasn't packed nor obfuscated in any sort so it was pretty simple to find out
where the interesting parts are :
- API analysis : DialogBoxParamA
- Strings
Using these twos clues, we can extract the fact that everything happens in DialogFunc() and that it is using complex numbers.
How is the serial generated then?
First we need to know what's the serial pattern.
From the following disassembly :
We can safely say that the serial is of some form like that :
AAAAAAAA-BBBBBBBB-CCCCCCCC-DDDDDDDD
The serial is generated in many parts :
* Get username
* Generate serial
- Do a checksum of the string and use it to generate a real and imaginary part, you get Za
- Use some magic to generate a value for a second complex number, you get Zb
- Then we must resolve some equation to get the serial
These are the functions needed to create the serial :
- strsum() : a checksum using all the characters in a string
- str2num() : Convert hexdigit in ASCII to the number form
- gen_magic() : Generate some value using a magic number and the string
The checksum function :
The generation of first number C1 :
Magic happens!
Generation of C2 :
str2num()
Now going to check the serial generation part.
It is done in two routines :
* First routine
So we have this :
Za = SP2 + C3 * SP1 + C3 * C3
* Second routine
We obtain this :
Zb = (C1 + C3)*(C2 + C3)
Next the serial is checked as followed :
Za = Zb
SP2 + C3 * SP1 + C3 * C3 = (C1 + C3)*(C2 + C3)
SP2 + C3 * SP1 + C3 * C3 = C1 * C2 + C1 * C3 + C3 * C2 + C3 * C3
SP2 + C3 * SP1 + C3 * C3 = C1 * C2 + C3 * (C1 + C2) + C3 * C3
SP2 + C3 * SP1 = C1 * C2 + C3 * (C1 + C2)
Using identification, we can see that :
SP1 = C1 + C2
SP2 = C1 * C2
Here is the C source for the keygen :
We don't need to reconstruct source code from keygenme but here it is for those who didn't follow :
Hope you enjoyed reading this small tutorial.
Happy reversing,
m_101
- link : Just a Little Crackme
It is the BratAlarm "Just a little crackme" that I'm going to talk about.
It was a bit interesting in the sense that you need to have basic mathematics knowledge.
Basic maths knowledge
Complex numbers are used throughout the whole keygenme to generate the serial.
Complex number basic operations used are the following :
multiplication : (a, b) * (c, d) = (a*c - b*d, b*c + a*d) = (a + i*b) * (c + i*d)
addition : (a, b) + (c, d) = (a + c, b + d) = (a + i*b) + (c + i*d)
Where is the serial checking and generation located?
First of all, this keygenme wasn't packed nor obfuscated in any sort so it was pretty simple to find out
where the interesting parts are :
- API analysis : DialogBoxParamA
- Strings
Using these twos clues, we can extract the fact that everything happens in DialogFunc() and that it is using complex numbers.
How is the serial generated then?
First we need to know what's the serial pattern.
From the following disassembly :
.text:00401129 mov serial_part1_real, eax .text:0040112E add edi, 9 .text:00401131 mov byte ptr [edi+8], 0 .text:00401135 push edi .text:00401136 call str2num .text:0040113B mov serial_part1_imaginary, eax .text:00401140 add edi, 9 .text:00401143 mov byte ptr [edi+8], 0 .text:00401147 push edi .text:00401148 call str2num .text:0040114D mov serial_part2_real, eax .text:00401152 add edi, 9 .text:00401155 mov byte ptr [edi+8], 0 .text:00401159 push edi .text:0040115A call str2num .text:0040115F mov serial_part2_imaginary, eax
We can safely say that the serial is of some form like that :
AAAAAAAA-BBBBBBBB-CCCCCCCC-DDDDDDDD
The serial is generated in many parts :
* Get username
* Generate serial
- Do a checksum of the string and use it to generate a real and imaginary part, you get Za
- Use some magic to generate a value for a second complex number, you get Zb
- Then we must resolve some equation to get the serial
These are the functions needed to create the serial :
- strsum() : a checksum using all the characters in a string
- str2num() : Convert hexdigit in ASCII to the number form
- gen_magic() : Generate some value using a magic number and the string
The checksum function :
.text:004010B5 strsum: ; CODE XREF: DialogFunc+91 .text:004010B5 mov dl, [esi] .text:004010B7 add eax, edx .text:004010B9 inc esi .text:004010BA test edx, edx .text:004010BC jnz short strsum
The generation of first number C1 :
.text:004010BE mov ComplexNumber1_real, eax ; Re(C1) .text:004010C3 dec eax .text:004010C4 imul eax, 3 .text:004010C7 mov ComplexNumber1_imaginary, eax ; Im(C1)
Magic happens!
.text:004010D8 gen_magic2: ; CODE XREF: DialogFunc+B7 j .text:004010D8 mov dl, [esi] .text:004010DA xor eax, edx .text:004010DC rol eax, 5 .text:004010DF inc esi .text:004010E0 test edx, edx .text:004010E2 jnz short gen_magic2
Generation of C2 :
.text:004010E4 xor edx, edx .text:004010E6 mov ecx, 7A69h .text:004010EB div ecx .text:004010ED mov ComplexNumber2_real, edx ; Re(C2) .text:004010F3 and eax, 0FFFh .text:004010F8 mov ComplexNumber2_imaginary, eax ; Im(C2)
str2num()
.text:004012C5 str2num proc near ; CODE XREF: DialogFunc+F9 p .text:004012C5 ; DialogFunc+10B p ... .text:004012C5 .text:004012C5 arg_0 = dword ptr 8 .text:004012C5 .text:004012C5 push ebp .text:004012C6 mov ebp, esp .text:004012C8 pusha .text:004012C9 xor eax, eax .text:004012CB xor edx, edx .text:004012CD mov ecx, 8 .text:004012D2 mov esi, [ebp+arg_0] .text:004012D5 .text:004012D5 loc_4012D5: ; CODE XREF: str2num+28 j .text:004012D5 mov dl, [esi] .text:004012D7 test dl, dl .text:004012D9 jz short loc_4012EF .text:004012DB sub dl, 30h ; '0' .text:004012DE cmp dl, 0Ah .text:004012E1 jb short loc_4012E6 .text:004012E3 sub dl, 7 ; hex digit part .text:004012E6 .text:004012E6 loc_4012E6: ; CODE XREF: str2num+1C j .text:004012E6 shl eax, 4 .text:004012E9 or eax, edx .text:004012EB inc esi .text:004012EC dec ecx .text:004012ED jnz short loc_4012D5 .text:004012EF .text:004012EF loc_4012EF: ; CODE XREF: str2num+14 j .text:004012EF mov [ebp+arg_0], eax .text:004012F2 popa .text:004012F3 mov eax, [ebp+arg_0] .text:004012F6 leave .text:004012F7 retn 4 .text:004012F7 str2num endp
Now going to check the serial generation part.
It is done in two routines :
* First routine
.text:004011F1 gen_serial_part1 proc near ; CODE XREF: DialogFunc+15C .text:004011F1 .text:004011F1 ComplexResult2 = byte ptr -10h .text:004011F1 ComplexResult1 = byte ptr -8 .text:004011F1 ComplexResult = dword ptr 8 .text:004011F1 ComplexNumber = dword ptr 0Ch .text:004011F1 .text:004011F1 push ebp .text:004011F2 mov ebp, esp .text:004011F4 add esp, 0FFFFFFF0h .text:004011F7 pusha .text:004011F8 mov edi, [ebp+ComplexResult] .text:004011FB mov esi, [ebp+ComplexNumber] .text:004011FE lea ebx, [ebp+ComplexResult1] .text:00401201 lea ecx, [ebp+ComplexResult2] .text:00401204 push esi .text:00401205 push esi .text:00401206 push ebx .text:00401207 call complex_multiply .text:0040120C push offset serial_part1_real .text:00401211 push esi .text:00401212 push ecx .text:00401213 call complex_multiply .text:00401218 push ecx .text:00401219 push ebx .text:0040121A push edi .text:0040121B call complex_add .text:00401220 push offset serial_part2_real .text:00401225 push edi .text:00401226 push edi .text:00401227 call complex_add .text:0040122C popa .text:0040122D leave .text:0040122E retn 8 .text:0040122E gen_serial_part1 endp
So we have this :
Za = SP2 + C3 * SP1 + C3 * C3
* Second routine
.text:00401231 gen_serial_part2 proc near ; CODE XREF: DialogFunc+16B .text:00401231 .text:00401231 ComplexResult2 = byte ptr -10h .text:00401231 ComplexResult1 = byte ptr -8 .text:00401231 ComplexResult = dword ptr 8 .text:00401231 ComplexNumber = dword ptr 0Ch .text:00401231 .text:00401231 push ebp .text:00401232 mov ebp, esp .text:00401234 add esp, 0FFFFFFF0h .text:00401237 pusha .text:00401238 mov edi, [ebp+ComplexResult] .text:0040123B mov esi, [ebp+ComplexNumber] .text:0040123E lea ebx, [ebp+ComplexResult1] .text:00401241 lea ecx, [ebp+ComplexResult2] .text:00401244 push offset ComplexNumber1_real .text:00401249 push esi .text:0040124A push ebx .text:0040124B call complex_add .text:00401250 push offset ComplexNumber2_real .text:00401255 push esi .text:00401256 push ecx .text:00401257 call complex_add .text:0040125C push ecx .text:0040125D push ebx .text:0040125E push edi .text:0040125F call complex_multiply .text:00401264 popa .text:00401265 leave .text:00401266 retn 8 .text:00401266 gen_serial_part2 endp
We obtain this :
Zb = (C1 + C3)*(C2 + C3)
Next the serial is checked as followed :
Za = Zb
SP2 + C3 * SP1 + C3 * C3 = (C1 + C3)*(C2 + C3)
SP2 + C3 * SP1 + C3 * C3 = C1 * C2 + C1 * C3 + C3 * C2 + C3 * C3
SP2 + C3 * SP1 + C3 * C3 = C1 * C2 + C3 * (C1 + C2) + C3 * C3
SP2 + C3 * SP1 = C1 * C2 + C3 * (C1 + C2)
Using identification, we can see that :
SP1 = C1 + C2
SP2 = C1 * C2
Here is the C source for the keygen :
#include <stdlib.h>
#include <stdio.h>
struct complex_t {
// real part
int real;
// imaginary part
int i;
};
// complex number multiplication
struct complex_t* complex_multiply (struct complex_t **result,
struct complex_t *complex1,
struct complex_t *complex2)
{
// check pointer validity
if (!result || !complex1 || !complex2)
return NULL;
// check pointer validity
if (!*result)
*result = malloc(sizeof(**result));
// we calculate the real part
(*result)->real = complex1->real * complex2->real - complex1->i * complex2->i;
// we calculate the imaginary part
(*result)->i = complex1->i * complex2->real + complex1->real * complex2->i;
// result = (a+bi)*(c+di) = (a*c - b*d) + (b*c + a*d)i
return *result;
}
// complex number addition
struct complex_t* complex_add (struct complex_t **result,
struct complex_t *complex1,
struct complex_t *complex2)
{
// check pointer validity
if (!result || !complex1 || !complex2)
return NULL;
// check pointer validity
if (!*result)
*result = malloc(sizeof(**result));
// we calculate the real part
(*result)->real = complex1->real + complex2->real;
// we calculate the imaginary part
(*result)->i = complex1->i + complex2->i;
// result = (a+bi)+(c+di) = (a+c) + (b+d)i
return *result;
}
unsigned int strsum (unsigned char *str, size_t len) {
size_t i;
int sum;
// check pointers
if (!str || !len)
return -1;
// sum
for (i = 0, sum = 0; *str && i < len; i++)
sum += str[i];
return sum;
}
unsigned int rol32 (unsigned int val, size_t shift) {
shift = shift % 32;
return (val << shift) | (val >> (32 - shift));
}
int gen_magic (unsigned char *str, size_t len) {
unsigned int magic = 0x12345678;
unsigned char byte;
// check pointers
if (!str || !len)
return -1;
// magic happen
do {
byte = *str;
magic ^= byte;
magic = rol32(magic, 5);
++str;
} while (byte);
return magic;
}
struct complex_t** keygen (unsigned char *name, size_t len) {
unsigned int magic;
struct complex_t c1, c2;
struct complex_t *s1 = NULL, *s2 = NULL, **serial;
// compute Za and Zb
c1.real = strsum(name, len);
c1.i = (c1.real - 1) * 3;
magic = gen_magic(name, len);
c2.real = magic % 0x7a69;
c2.i = (magic / 0x7a69) & 0xfff;
// compute serial part 1
s1 = complex_add (&s1, &c1, &c2);
// compute serial part 2
s2 = complex_multiply (&s2, &c1, &c2);
// show complex numbers
printf ("(a, b) : (%x, %x)\n", c1.real, c1.i);
printf ("(c, d) : (%x, %x)\n", c2.real, c2.i);
// show serial calculations
printf ("Serial part 1 = (a+c, b+d)\n");
printf ("Serial part 2 = (a*c - b*d, b*c + a*d)\n");
// show serial
printf ("serial : %08X-%08X-%08X-%08X\n", s1->real, s1->i, s2->real, s2->i);
return serial;
}
int main (int argc, char *argv[]) {
unsigned char *username;
username = calloc (1, 128);
// ask username
printf ("Please input username\n");
gets(username);
// show serial
keygen (username, 128);
return 0;
}
We don't need to reconstruct source code from keygenme but here it is for those who didn't follow :
// keygenme
int keygenme (unsigned char *name, size_t len) {
unsigned int magic;
struct complex_t *ctmp1 = NULL, *ctmp2 = NULL;
struct complex_t c1, c2, c3;
struct complex_t userserial_part1, userserial_part2;
struct complex_t *serial_part1 = NULL, *serial_part2 = NULL;
// part 1
//
c1.real = strsum (name, len);
c1.i = (c1.real - 1) * 3;
//
magic = gen_magic(name, len);
c2.real = magic % 0x7a69;
c2.i = (magic / 0x7a69) & 0xfff;
//
c3.real = 3;
c3.i = 0x4e1f;
//
userserial_part1.real = str2num(name, 8);
userserial_part1.i = str2num(name + 9, 8);
userserial_part2.real = str2num(name + 18, 8);
userserial_part2.i = str2num(name + 27, 8);
// we generate part 1
ctmp1 = complex_multiply (&ctmp1, &c3, &c3);
ctmp2 = complex_multiply (&ctmp2, &c3, &userserial_part1);
serial_part1 = complex_add (&serial_part1, ctmp1, ctmp2);
serial_part1 = complex_add (&serial_part1, serial_part1, &userserial_part2);
// we generate part 2
complex_add (&ctmp1, &c3, &c1);
complex_add (&ctmp2, &c3, &c2);
serial_part2 = complex_multiply (&serial_part2, ctmp2, ctmp1);
return 0;
}
Hope you enjoyed reading this small tutorial.
Happy reversing,
m_101
- link : Just a Little Crackme
dimanche 25 avril 2010
Unpacking the boot.img
Hi!
Today, I will speaking a bit about Android boot.img.
I've been wondering what it is that makes the Android phones go root.
In facts, my theory was the following : we only need su to get root.
To check that, I coded a boot.img unpacker. The link to download it is below.
The boot.img format is defined in this kernel file : android/system/core/mkbootimg/bootimg.h.
With this, we can code a decent unpacker.
The packer would be about using mkbootimg but i don't need it for now.
What I basically did to get to see what make a Nexus One get rooted it to compared the original boot.img to the corresponding SuperBoot boot.img.
What I saw is the following :
Well, we can clearly see that some property are there to unlock a security and enable permanent USB Debugging mode.
More over, only the job is done in the superboot directory which contains :
- su
- superboot.sh
- Superboot.apk
Hell yeah, seems like my theory hold ;) .
- HOWTO: Unpack, Edit, and Re-Pack Boot Images
- Superboot - rooting the Nexus One
- Original Nexus One images
- m_101 GIT repository
Today, I will speaking a bit about Android boot.img.
I've been wondering what it is that makes the Android phones go root.
In facts, my theory was the following : we only need su to get root.
To check that, I coded a boot.img unpacker. The link to download it is below.
The boot.img format is defined in this kernel file : android/system/core/mkbootimg/bootimg.h.
/* ** +-----------------+ ** | boot header | 1 page ** +-----------------+ ** | kernel | n pages ** +-----------------+ ** | ramdisk | m pages ** +-----------------+ ** | second stage | o pages ** +-----------------+ ** ** n = (kernel_size + page_size - 1) / page_size ** m = (ramdisk_size + page_size - 1) / page_size ** o = (second_size + page_size - 1) / page_size ** ** 0. all entities are page_size aligned in flash ** 1. kernel and ramdisk are required (size != 0) ** 2. second is optional (second_size == 0 -> no second) ** 3. load each element (kernel, ramdisk, second) at ** the specified physical address (kernel_addr, etc) ** 4. prepare tags at tag_addr. kernel_args[] is ** appended to the kernel commandline in the tags. ** 5. r0 = 0, r1 = MACHINE_TYPE, r2 = tags_addr ** 6. if second_size != 0: jump to second_addr ** else: jump to kernel_addr */
With this, we can code a decent unpacker.
The packer would be about using mkbootimg but i don't need it for now.
What I basically did to get to see what make a Nexus One get rooted it to compared the original boot.img to the corresponding SuperBoot boot.img.
What I saw is the following :
diff -ru original/default.prop rooted/default.prop --- original/default.prop 2010-04-25 11:58:52.143574246 +0200 +++ rooted/default.prop 2010-04-25 11:59:12.373574922 +0200 @@ -1,7 +1,7 @@ # # ADDITIONAL_DEFAULT_PROPERTIES # -ro.secure=1 +ro.secure=0 ro.allow.mock.location=0 -ro.debuggable=0 -persist.service.adb.enable=0 +ro.debuggable=1 +persist.service.adb.enable=1 diff -ru original/init.rc rooted/init.rc --- original/init.rc 2010-04-25 11:58:52.163574413 +0200 +++ rooted/init.rc 2010-04-25 11:59:12.393586264 +0200 @@ -230,6 +230,11 @@ ## Daemon processes to be run by init. ## +service superboot /system/bin/sh /superboot/superboot.sh + user root + group root + oneshot + service console /system/bin/sh console Only in rooted/: superboot
Well, we can clearly see that some property are there to unlock a security and enable permanent USB Debugging mode.
More over, only the job is done in the superboot directory which contains :
- su
- superboot.sh
- Superboot.apk
Hell yeah, seems like my theory hold ;) .
- HOWTO: Unpack, Edit, and Re-Pack Boot Images
- Superboot - rooting the Nexus One
- Original Nexus One images
- m_101 GIT repository
samedi 24 avril 2010
HTC Desire
Hi!
I finally have a smartphone! Got my HTC desire yesterday, of course I couldn't wait to play with it a bit. It's pretty dazzling to think that it has a 1Ghz CPU and 576MB of RAM, crazy specs for a phone.
It's pretty straightforward to use, but there still is a lot of apps to have on it I guess : nmap, aircrack-ng, metasploit, maltego like, scapy, etc.
I was happy as hell to have it but got disappointed very fast to see that most of these tools weren't there or couldn't be launched because of some missing dependencies (ruby, python etc).
For Ruby, there was the Ruboto IRB shell, which seems to be a JRuby port (yeah java isn't that multiplateform afterall), but it doesn't seem to manage folders.
So I searched for another one and stumbled upon ASE - Android Scripting Environment, haven't tried it yet, gotta have to, more on this later.
With smartphone, mean communicating device, and the problem with the phone rates is that having all ports unlocked is expensive as hell, it's 10€ more compared to only having web (80, 443) and mail port (pop or imap? or maybe both dunno). It means that we would just need to have some kind of tunneling server to bypass the restriction and go anywhere we want to go.
Lucky i have WiFi where i am.
Since i'm kind of interested in security and like having a hackable device, I was asking myself if we could play with network routes, modules, etc ... we just can't ... or maybe we can ;) .
I found frustrating to not really own the phone, yeah we aren't root, just normal users.
So I looked a bit at the different steps needed to completely own the phone. There are like tons of tutorials as how to do it ... but all the same programs, we don't know that much about the root hack image itself (Superboot thingy).
Anyway, I found some cool work about it, the steps looks something like this :
- unlock bootloader
- put the rooted boot.img on sd card
- launch in bootloader mode
- choose fastboot
- rooted
I didn't have to unlock my phone since it already was. The only manipulation to do to unlock are these :
- Connect your phone in USB Debugging mode
- user@computer$ fastboot oem unlock
That's it, you unlocked the bootloader.
There was an elevation privilege exploit some months ago but it got fixed but now it seems. The root hack is now about flashing the bootloader.
The recovery image hack isn't necessary but useful if you wanna make a backup of your rom and play a bit more with custom roms.
The last thing to note is that the HTC Desire is pretty similar to the Nexus One so it shouldn't be too different for rooting it either.
For now it's only my theory I extrapolated from the doc' i read. So the goal would be to make a rooted boot.img and we'll have the key to the kingdom.
Anyway, I was thinking of building some kernel and stuffs from source but I didn't managed it yet. Got to look if it isn't some sort of cross compilation problem.
More over, when the phone is rooted, my guess would that it might be easier to hook stuffs in the system to better analyze it.
For now, I'm searching for an original HTC Desire firmware before I work more on a root hack for it.
That's all for today.
Sources :
- Why root?
- How to unlock the bootloader on your Nexus One
- Superboot
- Android Scripting Environment
- Obsolete android elevation privilege exploit
- Build CyanogenMod from source
- HOWTO: Unpack, Edit, and Re-Pack Boot Images
- Install_Custom_ROM
- Amon_RA Recovery image
- How to gain root access on your HTC Hero
I finally have a smartphone! Got my HTC desire yesterday, of course I couldn't wait to play with it a bit. It's pretty dazzling to think that it has a 1Ghz CPU and 576MB of RAM, crazy specs for a phone.
It's pretty straightforward to use, but there still is a lot of apps to have on it I guess : nmap, aircrack-ng, metasploit, maltego like, scapy, etc.
I was happy as hell to have it but got disappointed very fast to see that most of these tools weren't there or couldn't be launched because of some missing dependencies (ruby, python etc).
For Ruby, there was the Ruboto IRB shell, which seems to be a JRuby port (yeah java isn't that multiplateform afterall), but it doesn't seem to manage folders.
So I searched for another one and stumbled upon ASE - Android Scripting Environment, haven't tried it yet, gotta have to, more on this later.
With smartphone, mean communicating device, and the problem with the phone rates is that having all ports unlocked is expensive as hell, it's 10€ more compared to only having web (80, 443) and mail port (pop or imap? or maybe both dunno). It means that we would just need to have some kind of tunneling server to bypass the restriction and go anywhere we want to go.
Lucky i have WiFi where i am.
Since i'm kind of interested in security and like having a hackable device, I was asking myself if we could play with network routes, modules, etc ... we just can't ... or maybe we can ;) .
I found frustrating to not really own the phone, yeah we aren't root, just normal users.
So I looked a bit at the different steps needed to completely own the phone. There are like tons of tutorials as how to do it ... but all the same programs, we don't know that much about the root hack image itself (Superboot thingy).
Anyway, I found some cool work about it, the steps looks something like this :
- unlock bootloader
- put the rooted boot.img on sd card
- launch in bootloader mode
- choose fastboot
- rooted
I didn't have to unlock my phone since it already was. The only manipulation to do to unlock are these :
- Connect your phone in USB Debugging mode
- user@computer$ fastboot oem unlock
That's it, you unlocked the bootloader.
There was an elevation privilege exploit some months ago but it got fixed but now it seems. The root hack is now about flashing the bootloader.
The recovery image hack isn't necessary but useful if you wanna make a backup of your rom and play a bit more with custom roms.
The last thing to note is that the HTC Desire is pretty similar to the Nexus One so it shouldn't be too different for rooting it either.
For now it's only my theory I extrapolated from the doc' i read. So the goal would be to make a rooted boot.img and we'll have the key to the kingdom.
Anyway, I was thinking of building some kernel and stuffs from source but I didn't managed it yet. Got to look if it isn't some sort of cross compilation problem.
More over, when the phone is rooted, my guess would that it might be easier to hook stuffs in the system to better analyze it.
For now, I'm searching for an original HTC Desire firmware before I work more on a root hack for it.
That's all for today.
Sources :
- Why root?
- How to unlock the bootloader on your Nexus One
- Superboot
- Android Scripting Environment
- Obsolete android elevation privilege exploit
- Build CyanogenMod from source
- HOWTO: Unpack, Edit, and Re-Pack Boot Images
- Install_Custom_ROM
- Amon_RA Recovery image
- How to gain root access on your HTC Hero
Inscription à :
Articles
(
Atom
)


