Friday, February 10, 2012

Quickpost: Disassociating the Key From a TrueCrypt System Disk


Didier stevens on his blog has a nice post on Disassociating the key from a TrueCrypt system.

TrueCrypt allows for full disk encryption of a system disk. I use it on my Windows machines. You probably know that the TrueCrypt password you type is not the key. But it is, simply put, used to decrypt the master key that is in the volume header. On a system drive, the volume header is stored in the last sector of the first track of the encrypted system drive (TrueCrypt 7.0 or later). Usually, a track is 63 sectors long and a sector is 512 bytes long. So the volume header is in sector 62. When this header is corrupted or modified, you can no longer decrypt the disk, even with the correct password. You need to use the TrueCrypt Rescue Disk to restore the volume header. This rescue disk was created when you encrypted the disk. I’m using Tiny Hexer on the Universal Boot CD For Windows to erase the volume header (you can’t modify the volume header easily when you booted from the TrueCrypt system disk; using a live CD like UBCD4WIN is one possible workaround).


First I’m checking the geometry of the system drive with MBRWizard:



Take a look at the CHS (Cylinders Heads Sectors) value: S = 63 confirms that a track is 63 sectors long.


Then I open the system drive with Tiny Hexer (notice that the sector size is 512 bytes or 0×200 bytes):



I go to sector 62, the last sector of the first track:



It contains the volume header (an encrypted volume header has no recognizable patterns, it looks like random bytes):



Then I erase the volume header by filling the sector with zeroes and writing it back to disk:



And if you absolutely want to prevent recovery of this erased sector, write several times to it with random data.


Booting is no longer possible, even with the correct password. The TrueCrypt bootloader will tell you the password is incorrect:



One can say that I’ve created a TrueCrypt disk that requires 2-factor authentication. To decrypt this disk, you need 2 factors: the password and the corresponding TrueCrypt Rescue Disk.


First you need to boot from the TrueCrypt Rescue Disk, and select Repair Options (F8):



And then you write the volume header back to the system disk. Remark that the TrueCrypt Rescue Disk requires you to enter the password before it writes the volume header to the disk:



And now you can boot from the system disk with your password.


Use this method if you need to travel with or mail an encrypted system disk and want to be 100% sure there is no way to decrypt the drive while in transit. But don’t travel with the 2 factors on you, send the TrueCrypt Rescue Disk via another channel.


Remark: MBRWizard allows you to wipe sectors, but for whatever reason, it couldn’t successfully wipe sector 62 on my test machine.


Oh yeah, don’t forget to make a full backup before you attempt this technique ;-)




Video: DarkMarket

Video: DarkMarket: Author Misha Glenny was interviewed by broadcast journalist Charlie Rose recently. The majority of discussion was based on Misha's current book, DarkMarket: Cyberthieves, Cybercops and You.

The interview is 20 minutes long, a provides an excellent summary of the threats currently facing the Internet.

Misha Glenny, DarkMarket
Click to watch

On 08/02/12 At 01:50 PM

FatCat Auto SQLl Injector

This is an automatic SQL Injection tool called as FatCat , Use of FatCat for testing your web application and exploit your application more deeper. FatCat Features that help you to extract the Database information, Table information, and Column information from web application. Only If it is vulnerable to SQL Injection Vulnerability.


The user friendly GUI of FatCat and automatically detect the sql vulnerability and start exploiting vulnerability.

Features:


1) Normal SQL Injection

2) Double Query SQL Injection

Look forward to the below features in the next version:

1) WAF bypass

2) Cookie Header passing

3) Load File

4) Generating XSS from SQL

Requirement:

1) PHP Verison 5.3.0

2) Enable file_get_function

Download: http://code.google.com


Video Demo: http://dl.dropbox.com

IronWASP Securitybyte Edition Released

IronWASP (Iron Web application Advanced Security testing Platform) is an open source system for web application vulnerability testing. It is designed to be customizable to the extent where users can create their own custom security scanners using it. Though an advanced user with Python/Ruby scripting expertise would be able to make full use of the platform, a lot of the tool's features are simple enough to be used by absolute beginners.

IronWASP makes use of the following excellent Free/Open Source libraries:

Monday, February 6, 2012

Implementing DLP: Integration Priorities and Components

Implementing DLP: Integration Priorities and Components:

Although it might be obvious by now, the following charts show which DLP components integrated to which existing infrastructure you need based on your priorities. I’ve broken this out into three different images to make them more readable. Why images? Because i have to dump all this into a whitepaper later and building them in a spreadsheet and taking screenshots is a lot easier than mucking the HTML formatted charts.









Between this and our priorities post and chart you should have an excellent idea of where to start and how to organize your DLP deployment.



- Rich
(0) Comments

Monday, January 23, 2012

‘Citadel’ Trojan Touts Trouble-Ticket System

Underground hacker forums are full of complaints from users angry that a developer of some popular banking Trojan or bot program has stopped supporting his product, stranding buyers with buggy botnets. Now, the proprietors of a new ZeuS Trojan variant are marketing their malware as a social network that lets customers file bug reports, suggest and vote on new features in upcoming versions, and track trouble tickets that can be worked on by the developers and fellow users alike.


A screenshot of the Citadel botnet panel.


The ZeuS offshoot, dubbed Citadel and advertised on several members-only hacker forums, is another software-as-a-service malware development. Its target audience? Those frustrated with virus writers who decide that coding their next creation is more lucrative and interesting than supporting current clients.


“Its no secret that the products in our field — without support from the developers — result in a piece of junk on your hard drive. Therefore, the product should be improved according to the wishes of our customers,” Citadel’s developers claim in an online posting. “One problem is that you have probably experienced developers who ignore your instant messages, because there are many customers but there is only one developer.”


In the following excerpt, taken from a full description of Citadel’s innovations, the developers of this malware strain describe its defining feature as a social networking platform for malware users that is made available through a Web-based portal created by the malware itself.


“We have created for you a special system — call it the social network for our customers. Citadel CRM Store allows you to take part in product development in the following ways:


- Report bugs and other errors in software. All tickets are looked at by technical support you will receive a timely response to your questions. No more trying to reach the author via ICQ or Jabber.


-Each client has the right to create an unlimited number of applications within the system. Requests can contain suggestions on a new module or improvements of existing module. Such requests can be public or private.


-Each client has a right to vote on new ideas suggested by other members and offer his/her price for development of the enhancement/module. The decision is made by the developers on whether to go forward with certain enhancement or new module depending on the voting results.


-Each client has the right to comment on any application and talk to any member. Now it is going to be interesting for you to find partners and like-minded people and also to take active parts in discussions with the developers.


- You can see all stages of module development, if it is approved other members. We update the status and time to completion.



- You may pay a deposit, if module is approved (50%). After the deposit is paid by the members, the project starts moving forward, so that the money is paid directly to coders and there will be no laziness or inaction. Everything is clear: every stage of development is thoroughly shown.


-Easy jabber [instant message] notification of new member or developer comments, or the availability of new custom applications.


The Citadel store lets users file and track bug reports, and request and vote on new features.


Citadel may be the first notable progeny of ZeuS since the ZeuS source code was leaked online last year. The authors claim that it includes a number of bug fixes for the most recent ZeuS version, including full support for grabbing credentials from victims using Google Chrome. Also bundled with this update is a component that can record and transmit videos of the victim’s screen activity.


The basic Citadel package — a bot builder and botnet administration panel — retails for $2,399 + a $125 monthly “rent,” but some of its most innovative features are sold as a la carte add-ons. Among those is a $395 software module that allows botmasters to sign up for a service which automatically updates the bot malware to evade the last antivirus signatures. The updates are deployed via a separate Jabber instant message bot, and each update costs an extra $15.


Citadel also boasts a feature that hints at its creator’s location(s). According to the authors, if the malware detects that the victim’s machine is using a Russian or Ukrainian keyboard, it will shut itself down. This feature is almost certainly a hedge to keep the developers out of trouble: Authorities in those regions are far less likely to pursue the Trojan’s creators if there are no local victims.


The Citadel bot builder.


It will be interesting to see if these malware developers hold true to their word. The growth of a more real-time, user-driven and crowdsourced malicious software market would be a truly disturbing innovation. For now, the miscreants behind Citadel appear upbeat about their chances of ushering in such a reality.


“It’s very interesting for us to work with our clients,” they wrote in an online forum posting. “A lot of authors write in forums that they ‘support the product,’ but at the end the updates only come out once every three months or the author disappears forever. Problem is in author’s motivation. You support us, we support you. It is easy.”