Showing posts with label take. Show all posts
Showing posts with label take. Show all posts
Friday, March 31, 2017
Saturday, March 4, 2017
Not So Random Numbers Take Two
Not So Random Numbers Take Two

How can we get mt_rand seed via PHPSESSID?
PHPSESSID is generated this way:
md5( client IP . timestamp . microseconds1 . php_combined_lcg() )
- client IP is known to the attacker;
- timestamp is known through Date HTTP-header;
- microseconds1 a value from 0 to 1000000;
- php_combined_lcg() an example value is 0.12345678.
To generate php_combined_lcg(), two seeds are used:
S1 = timestamp XOR (microseconds2 << 11)
S2 = pid XOR (microseconds3 << 11)
- timestamp is the same;
- microseconds2 is greater than microseconds1 (when the first time measurement was made) by 03;
- pid is the id of the current process (032768, 102432768 on Unix);
- microseconds3 is greater than microseconds2 by 14.
The greatest entropy is contained in microseconds1, however with the use of two techniques it can be substantially reduced.
Adversarial Time Synchronization
The technique is aimed at sending pairs of requests so that to determine the moment when the second in the Date HTTP header changes.
HTTP/1.1 200 OK
Date: Wed, 08 Aug 2012 06:05:14 GMT
HTTP/1.1 200 OK
Date: Wed, 08 Aug 2012 06:05:15 GMT
If it happened, the microseconds between our requests zeroed. By sending requests with dynamic delays it is possible to synchronize local value of microseconds with the server one.
Request Twins
The principle of this technique is simple. The attacker needs to send two requests: the first one to reset their own password and the second one to reset that of an administrator. The gap between microseconds will be minimal.
To sum up, an MD5 PHPSESSID hash is bruteforced for microseconds, the deltas of subsequent time measurements, and pid. As for pid, the authors have not mentioned such a great helper as Apache server-status which reveals among other information the pids of the processes which serve the requests.
To realize the bruteforce, a module for the popular program PasswordsPro has been initially created. However, this solution made it impossible to take into account the positive linear correlation between deltas of microseconds, so it bruteforced the full range of values. The speed was about 12 million hashes per second.
That is why we created our own GUI application for this task.

The speed is about 16 million hashes per second, seed calculation takes less than an hour on 3.2 GHz Quad Core i5.
Having pid and php_combined_lcg one can compute the seed used in mt_rand. It is generated this way:
(timestamp x pid) XOR (106 x php_combined_lcg())
Besides, php_combined_lcg is used as additional entropy for the uniqid function (if it is called with the second argument being true).
So, if a web application uses standard PHP sessions, it is possible to obtain the random numbers generated via mt_rand(), rand(), and uniqid().
How can we get mt_rand seed through one of the random numbers leakage?
The seed used for mt_rand is an unsigned integer 2^32. If a random number leaked, it is possible to get the seed using PHP itself and rainbow tables. It takes less than 10 minutes.
The scripts to generate rainbow tables, search the seed, and ready-made tables are available here: http://www.gat3way.eu/poc/mtrt/

What to look for in the code?
All the mt_rand(), rand(), uniqid(), shuffle(), lcg_value(), etc. The only secure function is openssl_random_pseudo_bytes(), but it is rarely used in web applications. The main ways of defense against such attacks are the following:
- MySQL function RAND() it can be also predicted though.
- Suhosin patch does not patch mt_srand, srand. The Suhosin extension should also be installed.
- /dev/urandom the securest way.

Arseny Reutov
Timur Yunusov
Dmitry Nagibin
Available link for download
Sunday, February 12, 2017
New Android Vulnerable Hackers To Take Over Your Phone
New Android Vulnerable Hackers To Take Over Your Phone

This time Everything is Affected!
Yet another potentially dangerous vulnerability has reportedly been disclosed in the Googles mobile operating system platform Android.
Android has been hit by a number of security flaws this month, including:
- Stagefright vulnerability that affects 950 Million Android devices worldwide
- A critical mediaserver vulnerability that threatened to crash more than 55 percent of Android devices
- Another critical flaw (CVE-2015-3842) discovered last week, affected almost all the versions of Android devices
The security flaw gives hacker ability to spy on Android smartphone owners, steal login credentials, install malware, and many more, according to the latest research conducted by the researchers at thePennsylvania State University and FireEye.
How the Attack Works?
According to security researchers, the flaw could be exploited to lure the victim into unwittingly handing over their login details into a spoofed user interface, controlled by a hacker, when an Android user starts an app.
The device owner wont at all be aware that they are typing their sensitive details into a malicious software program masquerading as a legit Android app.
The researchers published their research in a paper titled, "Towards Discovering and Understanding Task Hijacking in Android" [PDF], which they presented at the USENIX Security 15 conference in Washington DC last week.
The study explained practical details of how multitasking within Android differs from multitasking within desktop operating systems that focused on what happens when an app or multiple apps run in one or multiple processes simultaneously creating Multi-Tasks.
Multitasking in Android allows us to gain advantage in a way:
- By being able to switch between the apps
- Apps being able to maintain their state in the background
- Easy task or app switching
Task Hijacking Attacks on Large Scale
Android task management mechanism is threatened by severe security risks. When maltreated, these convenient multitasking features can backfire and initiate task hijacking attacks on a vast scale.
The researchers analyzed more than 6.8 Million apps from multiple Android app stores and found that the task hijacking flaw is prevalent in all apps. Since many Android apps depend on "the current multitasking design, defeating task hijacking is not easy."
The researchers also claimed that the vulnerability can impersonate the user interface of the app, which is controlled by the attacker on the other hand.
You can watch the video to find the quick overview of the vulnerability.
This is just one scenario where the attacker is deploying phishing attack on Android users, and gaining their privacy credentials.
Yet More to Come
There can be instances where the users can be the victims of Ransomware, Distributed Denial of Service (DDoS) attacks and other cyber attacks.
The five security researchers Peng Liu and Chuangang Ren from the Pennsylvania State University, and Yulong Zhang, Tao Wei and Hui Xue from FireEye involved in the research reported the security hole to the Android team.
"We appreciate this theoretical research as it makes Androids security stronger," said a Google spokeswoman.
You are safe as; as Google said that customers are protected from hijacking and phishing attacks withAndroids Verify Apps and Safety Net features.
Also, you can keep yourself safe by installing apps from trusted sources and keeping your safety completely with you.
Available link for download
Subscribe to:
Posts (Atom)