[00:00.000 --> 00:01.920] ...developed a framework for those vulnerabilities. [00:02.420 --> 00:06.380] She calls it the smartphone penetration testing framework. [00:07.160 --> 00:10.320] Georgia came up here from Alabama to present this information to you. [00:10.640 --> 00:12.180] I want to introduce Georgia Weidman. [00:13.040 --> 00:13.580] Thank you. [00:20.710 --> 00:21.870] Okay, he was close. [00:22.050 --> 00:27.670] I actually came up from Mississippi, but, you know, that whole south area, they're all about the same. [00:27.810 --> 00:29.290] No one's ever heard of them or been there. [00:29.290 --> 00:31.010] So yeah, I'm Georgia. [00:31.270 --> 00:32.190] It's dark in here. [00:32.330 --> 00:35.790] I can't see you, but hopefully you can see me and everyone can hear me. [00:36.050 --> 00:38.670] This is the smartphone pen-test framework. [00:39.150 --> 00:41.070] It does not yet have a cool name. [00:41.190 --> 00:45.490] That's its only name right now is SPF, which I think sounds like sunscreen. [00:45.910 --> 00:50.790] So if you can think of a cool name for it, that's just the name I gave DARPA. [00:50.970 --> 00:52.390] By all means, come up to me after. [00:52.710 --> 00:57.750] I'm releasing it technically at Black Hat in a couple weeks, so hopefully I'll have a cool name by then. [00:57.750 --> 00:59.290] But I'm crowdsourcing it. [00:59.390 --> 01:01.730] So if you think of anything, do let me know. [01:03.730 --> 01:06.150] So first off, I want to say I love DARPA. [01:06.410 --> 01:09.730] This whole project is the product of the Cyber Fast Track grant. [01:09.970 --> 01:13.070] And I'll talk more about Cyber Fast Track at the end of the talk. [01:13.470 --> 01:16.810] But basically, this allowed me to, one, quit my job. [01:16.890 --> 01:19.390] Because my job said, well, we own everything you do. [01:19.390 --> 01:21.250] And I didn't really like that very much. [01:21.250 --> 01:28.550] So this actually allowed me to quit the job and work full time for myself and start my own company, which has been oddly lucrative. [01:28.830 --> 01:30.450] You should all start your own company. [01:30.690 --> 01:33.570] It's oddly not hard to make money doing the kind of things we do. [01:33.730 --> 01:34.670] Everybody needs it. [01:34.870 --> 01:36.450] So love to DARPA. [01:36.770 --> 01:41.570] Now I get to say I'm CEO and not junior pin tester number 9921. [01:42.070 --> 01:43.950] So love, love, love to DARPA. [01:45.870 --> 01:46.610] All right. [01:46.990 --> 01:48.530] So the problem at hand. [01:49.350 --> 01:52.050] Naturally, we have smartphones at work. [01:52.230 --> 01:54.990] Everybody wants to be able to put their smartphones on the network. [01:55.210 --> 02:04.070] Bringing our smartphones just to work and not having them attached to the network and attached to, like, the email server and such, that's not such a big problem. [02:04.250 --> 02:11.110] But once we start putting our emails and our company files on them and they can communicate to all of our nice servers and things. [02:11.310 --> 02:12.950] And I forgot to take out my laser pointer. [02:15.990 --> 02:17.510] Because I'm going to need that later. [02:17.710 --> 02:19.330] Except I can't really reach the screen. [02:19.690 --> 02:20.210] Eh, kind of. [02:20.430 --> 02:20.750] Okay. [02:20.970 --> 02:21.370] Anyway. [02:21.610 --> 02:29.110] So we have our smartphones and our CEO says, I would like to put my iPhone or my Android or my iPad or my Blackberry on the network. [02:29.450 --> 02:31.530] Well, we're used to putting devices on the network. [02:31.810 --> 02:34.750] We're really good at monitoring traffic in and out of the network. [02:34.890 --> 02:36.610] We've been doing this for a long time. [02:36.610 --> 02:38.570] We've pretty much got that down pat. [02:38.850 --> 02:42.090] What we don't like, however, is out-of-band communication. [02:42.270 --> 02:44.690] We generally frown on that. [02:44.850 --> 02:52.530] We don't like to not know where all of our traffic is going, what information is going out to some other entity. [02:52.710 --> 02:55.670] We don't like that very much in corporate security. [02:56.050 --> 02:58.710] However, that's kind of how smartphones work. [02:58.930 --> 03:06.550] They attach to their own mobile network, which we, as the security team at a company, we're not really able to monitor that so much. [03:06.730 --> 03:09.610] Whereas we can monitor things going through our network. [03:09.610 --> 03:11.850] We can see every packet if we want to. [03:12.070 --> 03:15.750] We can't really see what's going on, say, with AT&T or T-Mobile. [03:15.950 --> 03:22.450] And all of that data could theoretically be going out over that out-of-band communication. [03:22.910 --> 03:24.550] That's just the nature of the smartphone. [03:26.470 --> 03:29.290] So what are our smartphones actually doing in our workplace? [03:29.570 --> 03:31.450] These are a few of the things I've seen them do. [03:31.930 --> 03:33.590] One, of course, they access our data. [03:33.870 --> 03:35.190] They store our company emails. [03:35.490 --> 03:45.890] And it's great to have company emails on your smartphone, particularly if you work from home and you want to pretend you're actually sitting at the desk working when you're actually, you know, out at the beach. [03:46.030 --> 03:47.370] Your emails are coming in. [03:47.470 --> 03:48.890] You can respond to your boss. [03:48.910 --> 03:50.170] You can respond to clients. [03:50.370 --> 03:51.550] You can still get your work done. [03:51.690 --> 03:52.270] It's awesome. [03:52.270 --> 03:53.210] Everybody loves it. [03:53.290 --> 03:54.470] I'd hate to see it go away. [03:54.710 --> 03:57.190] But think about the things you put in those emails. [03:57.810 --> 03:59.730] I've got my reports. [03:59.990 --> 04:00.470] I've got... [04:00.470 --> 04:04.270] I'm talking back and forth with my coworkers about, well, I found this on this server. [04:04.850 --> 04:06.530] Can you help me out with this? [04:06.690 --> 04:13.210] And talking back and forth about information that probably my clients would not enjoy just seeing out there in the world. [04:13.450 --> 04:15.650] And again, it can all go out out of bound. [04:16.190 --> 04:19.230] A lot of us, we connect to our VPNs via the smartphone. [04:19.230 --> 04:22.010] So, any credentials we've got on there for the VPN. [04:22.270 --> 04:24.790] They've got some pretty good VPN software for the smartphone. [04:25.050 --> 04:31.110] But still, anything that's stored on the smartphone, any communication from the smartphone, is theoretically at risk. [04:32.130 --> 04:37.010] And I've also seen them generate the actual one-time passwords to log into the VPNs and such. [04:37.170 --> 04:40.010] So, the software to do that is sitting there on the smartphone. [04:40.010 --> 04:42.410] So, if it's on the smartphone again. [04:42.790 --> 04:47.790] So, once again, you might be able to have somebody steal your one-time passwords or generate them themselves. [04:48.990 --> 04:51.850] So, all things that we need to work on, I think. [04:53.630 --> 04:55.850] So, some of the threats against the smartphones. [04:56.870 --> 04:57.710] Malicious apps. [04:57.830 --> 04:59.450] We've seen a lot of that in the news. [04:59.770 --> 05:02.210] There's always a malicious app, particularly with the Android. [05:02.510 --> 05:03.850] But don't forget about the iPhone. [05:04.250 --> 05:07.630] Charlie Miller, for instance, did get a malicious app onto the iPhone store. [05:07.630 --> 05:08.490] It does happen. [05:08.670 --> 05:09.770] It is a little harder. [05:10.030 --> 05:13.810] I think the reason we see more of it with Android is because it's so much easier. [05:13.970 --> 05:14.750] Why take the time? [05:15.050 --> 05:23.930] There was a really good talk where I went through why they think monetarily we're seeing the attacks we are, why we're not seeing more attacks on the smartphones. [05:23.930 --> 05:31.910] It's just because there's more browsers that are IE or Firefox than there are mobile Safari or your Android browser. [05:32.130 --> 05:35.910] So, monetarily, if you're going to pop browsers, you'll get more that way. [05:35.910 --> 05:39.330] But as more smartphones go out, I think that's going to change. [05:39.450 --> 05:40.610] We're going to see a lot more attacks. [05:41.610 --> 05:43.430] So, you download an app. [05:43.570 --> 05:44.790] Your users download an app. [05:44.890 --> 05:46.370] Especially if it's bring your own device. [05:46.630 --> 05:50.210] Good luck trying to get them not to bring down any app they want. [05:50.890 --> 05:52.710] They're not going to like that very much. [05:53.070 --> 05:57.910] So, any app that they pull down, even if you have stuff in place to try and stop them. [05:57.910 --> 06:03.790] Again, I've done a lot of talks where users just... or people in the audience raise their hand and say, I can get past those systems. [06:03.870 --> 06:07.790] You just have to rename the super user file and it'll get through anything at my work. [06:08.070 --> 06:12.250] So, we can't really trust anything that's in place to try and stop these things. [06:12.770 --> 06:14.690] So, malicious apps happen. [06:15.170 --> 06:18.410] A big example that showed up in the news was the droid dream attack. [06:18.410 --> 06:19.990] That was a while ago. [06:20.190 --> 06:20.890] But there's been more. [06:21.070 --> 06:21.830] Steals your data. [06:22.030 --> 06:23.230] Remotely controls your phone. [06:23.590 --> 06:25.250] So, anything that's on there is suspect. [06:25.770 --> 06:28.010] Every time you download an app, this could happen. [06:28.330 --> 06:30.530] Particularly with the Android, with the permission model. [06:30.710 --> 06:33.850] Where basically you just say, okay, you may exploit my phone now. [06:34.370 --> 06:35.790] It's quite easy. [06:36.310 --> 06:40.710] So, what if your employees have a malicious Angry Birds add-on? [06:40.850 --> 06:41.690] They have Angry Birds. [06:41.790 --> 06:42.450] Of course they do. [06:42.630 --> 06:46.330] You wouldn't be able to keep your employees if they weren't allowed to have Angry Birds. [06:46.330 --> 06:49.850] So, they download an add-on that says they're going to get special levels. [06:50.330 --> 06:51.630] And what if it's malicious? [06:51.890 --> 06:53.210] What if it steals their data? [06:54.110 --> 06:55.210] What can you do then? [06:55.350 --> 06:56.310] How can you stop this? [06:58.170 --> 06:59.590] Software bugs happen too. [06:59.990 --> 07:07.050] Just about every jailbreak on the iPhone 4.0 and above has started with an issue in Mobile Safari. [07:07.430 --> 07:11.090] Because it's allowed to run unsigned code and nothing else pretty much is. [07:11.310 --> 07:12.730] And yet we still jailbreak it. [07:12.730 --> 07:18.830] So, like any other software, your software that comes on your smartphones has bugs in it too that can be exploited. [07:19.130 --> 07:23.050] Your apps have bugs, particularly when they're written by third party developers. [07:23.630 --> 07:29.790] You know, you don't have to take a security development course in order to sign up for any of the app stores. [07:30.030 --> 07:33.650] They do not make you take a test to prove you know how to do secure development. [07:33.910 --> 07:35.850] You just pay your money and sign up. [07:36.670 --> 07:37.950] Kernels also have bugs. [07:37.950 --> 07:41.370] Our smartphone kernels are generally just Linux kernels. [07:41.530 --> 07:43.170] We know our Linux kernels have bugs. [07:44.010 --> 07:46.490] Smart phone development is pretty much the same. [07:46.670 --> 07:47.950] It's going to have the same issues. [07:48.130 --> 07:55.210] A lot of the cases you can just port a kernel exploit over from just regular Linux to say Android. [07:55.510 --> 07:56.670] It's not much of a port. [07:56.870 --> 08:00.050] It's the same kind of vulnerability because it's a Linux kernel underneath it all. [08:00.050 --> 08:10.010] So all of this can be exploited if our users aren't completely up to date or there's a zero day on any of that software or an app, then they're vulnerable. [08:10.310 --> 08:15.270] We see this happen all the time, particularly with Android when it doesn't actually update a lot of our users. [08:15.550 --> 08:21.130] If you have an Android phone, if you have an older Android phone, for instance, I did my first research on a G1. [08:21.370 --> 08:22.630] I still have the G1. [08:22.810 --> 08:26.610] It's never gotten anything past 1.6, so it's vulnerable to everything. [08:27.250 --> 08:34.010] I recently broke one of my phones and went and bought a Burn phone, just a little Android phone at Best Buy, a prepaid one. [08:34.190 --> 08:38.670] It came with Android 2.3, so Gingerbread, Gingerbreak. [08:39.010 --> 08:39.690] Oh, how nice. [08:39.910 --> 08:46.290] So people are going and buying these and it's not pushing out updates to anyone, so definitely this could happen. [08:46.550 --> 08:49.330] So people bring their own devices into your workplace. [08:49.810 --> 08:51.630] Are they up to date completely? [08:51.950 --> 08:52.730] Question mark. [08:54.650 --> 08:55.570] Social engineering. [08:55.570 --> 08:58.890] Some of you may have gotten that text message from Target. [08:59.090 --> 09:00.450] I actually got it on my iPhone. [09:00.990 --> 09:02.310] I'm going to pull it up and see what it says. [09:04.790 --> 09:05.350] Okay. [09:05.590 --> 09:06.590] It says, congratulations. [09:06.590 --> 09:10.990] Your entry into last month's drawing won a free $1,000 Target gift card. [09:11.490 --> 09:14.890] Enter this number at target.com slash blah, blah, blah. [09:15.890 --> 09:19.510] But it's target.com dot something else dot biz. [09:19.510 --> 09:25.030] So, I mean, me as a person who does this, I would think, oh, social engineering attack. [09:25.290 --> 09:32.930] But as someone as a pin tester who does a lot of phishing attacks, and they're not always particularly good phishing attacks, and it's surprising how well they do. [09:33.170 --> 09:42.970] For instance, a couple of weeks ago I did one and it actually went to spam on the company mail server, which of course I was blamed for, but I still managed to get about five users' credentials. [09:43.210 --> 09:44.690] So they had to pull it out of spam. [09:44.950 --> 09:48.430] It said in their outlook, this is possibly a phishing attack. [09:48.670 --> 09:50.050] Please don't click anything. [09:50.430 --> 09:51.810] So they got it out of spam. [09:51.810 --> 09:52.850] They saw that warning. [09:53.010 --> 09:53.950] They clicked on it anyways. [09:54.150 --> 09:55.070] They put in their credentials. [09:56.530 --> 09:58.450] So, they say social engineering is dead. [09:58.630 --> 09:59.790] I don't know what they're talking about. [10:00.050 --> 10:04.110] And once you start doing it on the smartphone, even users who are like, okay, it's an email. [10:04.250 --> 10:05.270] I know about this. [10:05.370 --> 10:06.430] I don't know who this is from. [10:06.890 --> 10:08.210] I shouldn't click on this. [10:08.370 --> 10:10.490] They get a text message with a link in it. [10:10.570 --> 10:11.470] Oh, it's a text message. [10:11.570 --> 10:12.850] How can text hurt you? [10:13.970 --> 10:14.850] Well, it can. [10:14.870 --> 10:16.590] And this probably got a lot of users. [10:16.730 --> 10:18.930] By the time I got it, the page had already been taken down. [10:18.930 --> 10:21.990] But I'm sure they got a lot of people there for that. [10:22.210 --> 10:27.570] I'm sure it had a nice browser exploit that would hit all my phones because I don't update them. [10:27.830 --> 10:28.850] Why would I do that? [10:29.450 --> 10:30.550] Nobody else does either. [10:30.770 --> 10:33.570] So, we can download our malicious apps. [10:33.750 --> 10:35.790] We can open a browser that has an exploit. [10:36.010 --> 10:37.310] We can put our credentials in. [10:37.450 --> 10:39.650] The same sorts of problems we see on the PCs. [10:40.450 --> 10:41.970] Same sorts of phishing attacks. [10:42.130 --> 10:43.490] We're starting to see them here. [10:43.710 --> 10:49.550] The thing about smartphones is with the SMS, and I think this is why it's going to be the definite future of spam. [10:50.030 --> 10:55.170] Spam filtering in email is actually getting pretty good as seen with my phishing attack that went to spam. [10:55.550 --> 10:59.510] It's really annoying for someone who's trying to do phishing attacks. [10:59.890 --> 11:02.110] But think about with SMS. [11:02.570 --> 11:04.590] Is there any spam filtering for SMS? [11:05.030 --> 11:05.450] No. [11:05.810 --> 11:10.610] Unless I specifically block a specific number, I'm going to get that SMS. [11:10.610 --> 11:17.810] So, I think if I were some big cyber mogul type who wanted to send out spam, I would start moving on to the SMSs. [11:18.390 --> 11:20.750] Because I can pretty much guarantee they're going to get there. [11:21.170 --> 11:22.530] So, I think that's the future. [11:22.730 --> 11:24.130] And we don't really have anything in place. [11:24.390 --> 11:29.990] And I've yet to see a security awareness policy that goes over SMS yet, or anything else with the smartphones. [11:30.190 --> 11:32.030] It's like, don't click on things in your email. [11:32.250 --> 11:32.790] The end. [11:32.910 --> 11:34.010] And we see how well that works. [11:34.290 --> 11:35.910] So, whole new ball game here. [11:38.910 --> 11:39.350] Jailbreaking. [11:40.190 --> 11:46.250] A lot of our clients say, we don't allow users to jailbreak their phones and be on the environment. [11:46.470 --> 11:56.930] I go and give a talk and then someone raises their hand and says, if I rename the super user file to SU1, my company's checks don't see it. [11:57.050 --> 11:58.410] I get on the network just fine. [11:58.830 --> 12:07.270] So, people are going to jailbreak as long as smartphones require us to jailbreak to get all of the functionality that we want out of our devices. [12:07.270 --> 12:08.690] People are going to jailbreak them. [12:08.970 --> 12:14.010] People are going to go out to the Internet and look up jailbreak my iPhone. [12:14.330 --> 12:16.590] Which may take them to God knows what site. [12:16.910 --> 12:22.390] We know there are plenty of jailbreaks that have their source code available that are perfectly good. [12:22.590 --> 12:33.310] But even if it is available, how does the end user who can't read C code or hexadecimal or anything like that, how are they going to know? [12:33.310 --> 12:40.090] So, you go to jailbreakme.com but it's spelled wrong and you download a jailbreak and it indeed does jailbreak your phone. [12:40.490 --> 12:41.770] But what else does it do? [12:41.950 --> 12:45.190] You've basically clicked yes and said, please exploit my phone. [12:46.270 --> 12:50.710] So, you've basically given them permission to do whatever malicious thing they want. [12:50.830 --> 12:55.510] Once you're root on any of the smartphones, well, it's harder on the iPhone as I found out. [12:55.690 --> 12:58.170] But if you're root, now you can do stuff. [12:58.170 --> 12:59.430] All sorts of stuff. [12:59.630 --> 13:06.270] If you've seen any of my previous research, I did some nasty stuff with baseband level botnets by rooting the phone. [13:06.510 --> 13:09.210] So, anybody who jailbreaks, they go to a malicious site. [13:09.490 --> 13:11.090] God knows what they're going to get on there. [13:11.370 --> 13:14.110] A shim that's seeing all of their traffic going in and out. [13:14.290 --> 13:15.350] That's all of your emails. [13:16.390 --> 13:19.350] And GSM traffic is not very well encrypted. [13:19.990 --> 13:23.570] So, you drop them back to 2G and game's over. [13:23.910 --> 13:26.850] So, what else is our jailbreaking program actually doing? [13:27.070 --> 13:31.390] Once you get a jailbroken user in your environment, game's pretty much over. [13:31.870 --> 13:34.150] So, the question is, are we able to stop it or not? [13:34.290 --> 13:39.430] I don't really think there's any way right now to be able to say, there's no jailbroken users in my environment. [13:40.830 --> 13:45.350] So, my question at the end of all that and what I felt wasn't really being addressed. [13:45.350 --> 13:47.090] So, I'm a pen-tester by trade. [13:47.210 --> 13:49.570] That's what I do most of the time. [13:49.850 --> 13:52.610] And then my clients are like, okay, we have all these smartphones. [13:52.890 --> 13:57.050] We've allowed people to bring in our Androids and our iPhones and whatnot into the environment. [13:57.350 --> 13:58.710] I'd like to test them too. [13:59.190 --> 14:01.490] What's the security posture of these smartphones? [14:01.830 --> 14:04.750] And me and all the other pen-testers say, well, I don't really know. [14:04.890 --> 14:07.810] There's not really anything I can do to tell you one way or another. [14:08.570 --> 14:10.150] So, there are the smartphones. [14:10.390 --> 14:11.750] How do I assess the threat? [14:12.490 --> 14:14.210] So, I was kind of at a loss. [14:15.010 --> 14:16.610] So, what's out there now for this? [14:16.750 --> 14:22.510] You can actually do a lot of cool pen-testing from the smartphone, which my stuff gets kind of grouped in with that, because there's a difference. [14:22.650 --> 14:26.330] I'm actually pen-testing the smartphone, whereas pen-testing from the smartphone. [14:26.570 --> 14:36.930] An example of one of those tools, the Z-Anti, it lets you run like InMap and all other sorts of things from your smartphone, which again, if you're at the beach and want to do your work, that's awesome. [14:37.470 --> 14:38.650] Props to those developers. [14:39.510 --> 14:45.690] There's also a smartphone tool live CD, so it's like backtrack except for smartphones, so it has everything all set up. [14:45.890 --> 14:49.890] And if you've ever tried to install pen-testing tools, you can see why those are useful. [14:50.130 --> 14:53.410] Having it already set up for you, you don't have to download any dependencies. [14:54.190 --> 15:00.770] I'm sure users of my tool will be glad to see that on one of these as well, because they don't have to download the Perl dependencies. [15:00.770 --> 15:01.870] It'll just work. [15:02.330 --> 15:05.190] So that was actually another DARPA project, the Mobisec. [15:05.350 --> 15:06.310] So that's pretty cool. [15:07.390 --> 15:08.910] Pen-testing smartphone apps. [15:08.990 --> 15:10.450] There's been a lot of work on that. [15:10.650 --> 15:13.250] So we get a third-party app or we wrote an app. [15:13.370 --> 15:15.830] Can we test whether it's secure or not? [15:16.150 --> 15:19.890] Does it, if it's Android, does it expose data over its open interfaces? [15:20.670 --> 15:25.370] Does it insecurely store things, for instance, on the SD card? [15:25.610 --> 15:28.090] So there's a tool called Mercury that does that. [15:28.230 --> 15:28.930] There's a few others. [15:28.930 --> 15:30.990] There's been a lot of work in that area. [15:31.230 --> 15:38.250] But what I haven't seen is actually just pen-testing the smartphone devices, just for the issues, the same sort of issues we see on our PCs. [15:38.590 --> 15:40.470] Do we have a default SSH password? [15:40.750 --> 15:41.990] Are we not up to date? [15:42.350 --> 15:49.530] Are we able to socially engineer people into clicking on my links, downloading apps, things like that? [15:49.650 --> 15:52.850] I didn't really find that there was anything out there to do that. [15:52.950 --> 15:55.690] So that's the problem I wanted to solve with this. [15:56.470 --> 16:00.290] Actually, the real story is I went to a conference in Cali, Columbia. [16:00.670 --> 16:03.430] Like, not Columbia, South Carolina, but Columbia, the country. [16:03.810 --> 16:09.830] And the Navy down there approached me and wanted me to write really malicious software that would definitely make me lose my passport. [16:10.090 --> 16:11.290] So, of course, I said no. [16:11.510 --> 16:12.830] But then I thought about it. [16:12.930 --> 16:17.270] And I was like, you know, if I did this from a non-malicious standpoint, more as a pin tester. [16:17.550 --> 16:22.230] If I did, like, the same sort of things, they wanted basically a tool that would exploit devices. [16:22.470 --> 16:23.490] Like, they don't know how to use it. [16:23.590 --> 16:25.850] So they just click yes, and it'll go exploit everything. [16:26.190 --> 16:28.190] So they can spy on their entire country. [16:28.570 --> 16:30.390] Which, governments never do that, do they? [16:31.830 --> 16:32.190] Yeah. [16:32.510 --> 16:38.490] So I thought, well, if I could do something like this, kind of like a Metasploit for smartphones, it could be really cool. [16:38.490 --> 16:41.570] So, thank you, Colombian Navy, for giving me this great idea. [16:44.890 --> 16:46.350] So, structure the framework. [16:46.650 --> 16:48.150] This picture isn't all that great. [16:50.890 --> 16:51.290] Whatever. [16:51.590 --> 16:51.750] Okay. [16:51.990 --> 16:53.430] So, we've got the server. [16:53.710 --> 16:57.490] Basically, it has, like, one big server, or we can have multiple ones. [16:57.590 --> 16:58.930] You can run it all on one machine. [16:58.930 --> 17:00.310] It's kind of like Metasploit. [17:00.390 --> 17:03.510] We can put it all over the place, or we can just run it all together. [17:03.810 --> 17:06.370] It's got a database where it keeps information. [17:06.870 --> 17:08.650] It's got a couple of interfaces. [17:08.870 --> 17:11.650] So, we can actually control this from our smartphones. [17:11.970 --> 17:17.450] It has a smartphone app that will allow us to, from our smartphone, actually interact with the framework. [17:18.290 --> 17:24.010] That's really cool, because a lot of what we do with this framework, obviously, is going to be over the modem. [17:24.130 --> 17:25.590] So, we actually need a modem. [17:25.710 --> 17:31.790] So, you can either plug in a USB modem to it, to the machine you're using, or just connect it to a smartphone. [17:31.790 --> 17:36.070] So, you put in a prepaid SIM if you don't want to tell your clients your actual number. [17:36.070 --> 17:43.070] So, you just put in a SIM, attach it to the framework, and then it'll actually use the modem in the phone to do our mobile modem attacks. [17:44.130 --> 17:45.830] We can just run it from... [17:45.830 --> 17:49.690] We have a console and a GUI, so you can run it from your laptops or your workstations. [17:50.450 --> 17:53.430] And what we're going to be after is the red phones. [17:53.430 --> 17:58.630] We want to assess and possibly exploit the smartphones in the environment. [17:58.630 --> 18:00.870] So, we want to turn them red. [18:01.030 --> 18:04.510] So, we actually have some post-exploitation agents for them as well. [18:04.670 --> 18:14.650] If we do exploit someone, we can install an agent and then, for instance, tell it to take a picture or gather data off of it or make it do stuff on our behalf. [18:15.270 --> 18:20.830] Try and do post-exploitation, like privilege escalation, so it'll run some of the known attacks. [18:20.830 --> 18:24.410] Like, for Android, it runs Rage Against the Cage and things like that. [18:24.530 --> 18:27.050] So, to see if they're vulnerable to those as well. [18:29.470 --> 18:31.790] So, the first thing we have is the framework console. [18:32.010 --> 18:35.830] If you've used the social engineer toolkit, it kind of looks like that. [18:35.990 --> 18:47.430] It's very menu-based, which I kind of want to turn it more into, like, MSF console instead of being menu-based, because clicking through all those menus 100 times a day like I do when I'm testing it gets a little annoying. [18:47.970 --> 18:49.710] So, but we will look at it. [18:49.710 --> 18:52.550] We're going to do some demos, but it looks a lot like set, I think. [18:52.850 --> 18:54.730] But, of course, it has different options. [18:55.310 --> 19:01.630] This is all Perl-based, so if you have Perl on your machine, it has a couple of extra packages you have to download. [19:01.950 --> 19:04.470] But, other than that, it just runs in Perl. [19:05.190 --> 19:06.330] It works fine. [19:06.710 --> 19:08.250] Just out of the box, pretty much. [19:09.910 --> 19:11.930] We also have a GUI, thanks to my mom. [19:12.230 --> 19:14.930] My mom's a much better GUI programmer than I am. [19:15.210 --> 19:18.610] So, she made a nice GUI for us, so we'll look at that as well. [19:18.610 --> 19:24.950] It has all of the same functionality, except we can just click in little boxes and click go, and it'll do it. [19:25.150 --> 19:27.090] So, this is all web-based. [19:27.310 --> 19:31.050] Again, you just have to have Perl in your web server, and it will run. [19:31.870 --> 19:34.610] And so, if you're having a problem with it, that's probably why. [19:35.350 --> 19:38.610] Mod Perl is not as easy to install as I once thought. [19:39.290 --> 19:41.710] If you've ever tried to do it, you're smarter than me. [19:42.370 --> 19:46.170] So, but like Xampt or something, just comes with Perl in it. [19:46.290 --> 19:48.290] So, you can just run it out of the box with Xampt. [19:48.990 --> 19:53.030] And then, we've got cool things like boxes that we can fill in, and we click attach. [19:53.430 --> 19:55.710] And it does everything for us without the menu base. [19:55.930 --> 19:59.810] So, if your users really like GUIs, then this is something they can use. [20:01.430 --> 20:02.550] I also have an app. [20:03.210 --> 20:05.190] Right now, I only have one for Android. [20:05.510 --> 20:06.810] I'm in development for the others. [20:07.050 --> 20:10.990] But we have an app that actually allows you, again, to attach to the framework. [20:11.270 --> 20:14.650] You can use that modem that's in the smartphone to do your attacks. [20:14.890 --> 20:16.490] And you can actually launch attacks. [20:17.970 --> 20:20.330] A lot of the same functionality, not all of it. [20:20.470 --> 20:27.630] Like, for instance, you can't clear the database from inside of the smartphone app, because that would detach the app, and that would not be very good, I think. [20:27.630 --> 20:31.650] So, a subset of the things you can do with the actual framework. [20:31.650 --> 20:33.150] You can actually do from the app. [20:34.710 --> 20:36.950] So, for instance, browser exploits. [20:37.250 --> 20:41.330] We can just have it run the WebKit exploit right here from the smartphone. [20:41.610 --> 20:42.470] And it will try. [20:42.630 --> 20:49.830] You just tell it where to go, and it will do nasty things to that browser, if it is vulnerable, and actually push a shell back to the framework. [20:51.830 --> 20:57.210] So, what we can actually test for right now, we just have a subset of things in each of these categories. [20:57.710 --> 21:04.230] I'm still in the DARPA process, so I'm basically doing a couple things in each category, and then I'm just going to add more and more. [21:04.470 --> 21:07.590] There's a lot of issues with smartphones, so this could get pretty big. [21:07.870 --> 21:12.870] So, we can test remote vulnerabilities on the smartphone, if there are remote exploits on any of them. [21:13.370 --> 21:17.170] That's, of course, in our modern day platforms, a little bit harder to do. [21:18.050 --> 21:22.670] You know, Windows 7, I don't believe it has that many remote vulnerabilities either. [21:24.370 --> 21:29.410] But, for instance, the default SSH password on the jailbroken iPhone, it tests for that. [21:29.570 --> 21:31.030] That's a remote exploit. [21:31.170 --> 21:36.170] Certainly, you log in with this login and password, and it gives you root access. [21:37.070 --> 21:39.390] That's a remote exploit if I ever saw one. [21:39.590 --> 21:40.350] So, it can do that. [21:40.990 --> 21:42.150] Client-side vulnerabilities. [21:42.150 --> 21:49.050] So, it'll put up a malicious web page that tries to exploit you, the same way we see with any other browser exploitation. [21:49.070 --> 21:50.450] I just ported it in here. [21:50.670 --> 21:51.770] You tell it to do that. [21:51.870 --> 21:58.270] It puts up the web page, and then it sends a text message to the user of that phone that you want to test, saying, hey, this is a cool page. [21:58.270 --> 21:59.570] Go look at it with the link. [21:59.710 --> 22:00.310] They open it. [22:00.350 --> 22:01.710] It tries to exploit their browser. [22:01.930 --> 22:04.570] If they're vulnerable, it pushes a shell back to the framework. [22:05.290 --> 22:06.790] It also does social engineering. [22:07.290 --> 22:10.290] It can do a couple of different text messages. [22:10.290 --> 22:12.810] It'll tell you, again, to open a cool page. [22:12.810 --> 22:16.230] It will tell you to open or to download a cool app. [22:16.530 --> 22:17.950] Not very sophisticated yet. [22:18.090 --> 22:20.110] Surely, we need better than this is a cool app. [22:20.390 --> 22:22.830] But for demo purposes, that works. [22:23.510 --> 22:25.230] And also, local vulnerabilities. [22:25.370 --> 22:30.970] So, it will, if you exploit it, will let you run privilege escalation against the phones as well. [22:31.170 --> 22:34.110] So, something like Rage Against the Cage, it will see if it works. [22:34.210 --> 22:35.690] Right now, it just drops the privileges. [22:35.690 --> 22:40.450] I'm going to put more stuff in there to do post-exploitation, I suppose. [22:40.670 --> 22:43.090] But right now, it just says, yes, the root worked. [22:43.230 --> 22:44.950] And drops the privileges and goes on. [22:45.190 --> 22:46.810] It's not particularly malicious. [22:48.310 --> 22:51.550] So, an example of our remote vulnerability. [22:51.890 --> 22:53.230] Again, that's our jailbroken iPhones. [22:53.670 --> 22:56.910] By default, they all have the same SSH password, Alpine. [22:56.910 --> 22:57.970] So, it just... [22:57.970 --> 22:59.810] You give it an IP address to test. [22:59.990 --> 23:01.190] It tries to log into it. [23:01.330 --> 23:04.270] And if it is successful, it will actually install an agent on there. [23:04.390 --> 23:07.830] So, it will allow you to now do post-exploitation on it. [23:07.970 --> 23:09.610] And then it records to the database. [23:09.610 --> 23:10.870] Did it work or did it not? [23:11.230 --> 23:12.810] So, it will either fail or succeed. [23:12.970 --> 23:15.850] If there's no SSH there, it will fail, obviously. [23:16.090 --> 23:16.930] It will try and log in. [23:17.030 --> 23:19.370] And if they have changed their password, it will fail. [23:19.950 --> 23:22.650] But if it is, in fact, vulnerable, which mine is. [23:22.770 --> 23:27.070] And I'm pretty sure, like, when you guys see the demo, you're going to see the IP address of my iPhone. [23:27.290 --> 23:30.830] And I'm pretty sure I'm not going to have iPhone software by the end of this talk. [23:30.970 --> 23:34.910] So, all of you can just get on my network, which, oddly enough, does not have a password. [23:35.190 --> 23:39.230] So, all of you can get on my network and have at it with my iPhone. [23:39.470 --> 23:42.830] So, because it is, in fact, vulnerable, we're going to show that. [23:44.190 --> 23:48.030] So, I'm pretty sure I'll have to wipe it out, if it even turns on by the end of the talk. [23:48.030 --> 23:50.510] So that is your goal, is to wipe out my iPhone. [23:50.730 --> 23:51.670] Show how awesome you are. [23:51.750 --> 23:53.830] It is version 4.3 even. [23:53.930 --> 23:54.830] So this should be easy. [23:55.070 --> 23:56.010] We're at a hacker con. [23:56.210 --> 23:57.070] Take out my iPhone. [23:58.890 --> 24:00.570] Client-side vulnerability example. [24:01.050 --> 24:08.450] So again, smartphone browsers, smartphone PDF viewers, they're all vulnerable to things as well, just like any other platform. [24:09.070 --> 24:15.430] For instance, the first jailbreak against iOS 4 was... it started with a browser exploit. [24:15.430 --> 24:23.770] It was a PDF issue in Mobile Safari, and comics got really famous for it, because Apple said, no one will exploit this phone. [24:23.910 --> 24:25.310] You can't run unsigned code. [24:25.470 --> 24:27.470] But of course, the browser can run unsigned code. [24:27.490 --> 24:30.850] It has to run whatever the web page out there tells it to. [24:31.030 --> 24:33.950] And Mobile Safari, that's written by Apple. [24:33.950 --> 24:37.890] We know that it's not malicious, so you just open up a malicious page in it. [24:38.310 --> 24:41.410] Oops, no more safe smartphone. [24:41.410 --> 24:45.430] And then we do a kernel exploit, and that's how you get root. [24:46.130 --> 24:48.270] So, same things work here on our smartphones. [24:48.590 --> 24:57.170] So, if our users, if we can get them to surf to a malicious page, we can possibly exploit their browser, and that could possibly lead to root, even. [24:57.570 --> 25:00.930] So, are the smartphone browsers in your organization vulnerable? [25:01.310 --> 25:04.290] I don't really know of any way to test that, rather than let's see. [25:04.290 --> 25:08.430] Let's see if users will, one, click on just anything, which we know they do. [25:08.730 --> 25:09.510] So, yeah. [25:09.990 --> 25:11.830] And let's see if it actually gets a shell. [25:12.230 --> 25:14.010] That's how we do pin testing. [25:15.750 --> 25:23.870] So, for the social engineering, basically, SMS is, I think, the new email for spam and phishing attacks, and definitely will be more and more so. [25:24.230 --> 25:27.030] This target SMS kind of tells me it's true. [25:27.030 --> 25:30.190] It's not the first one I've gotten, but that one was pretty widespread. [25:30.450 --> 25:31.350] A lot of people got it. [25:32.330 --> 25:36.470] So, open a website or download this app. [25:36.710 --> 25:37.830] Will our users do it? [25:37.930 --> 25:38.790] I think probably. [25:39.010 --> 25:49.890] Like, for instance, T-Mobile keeps sending me this thing where it's like, because you're a premium handset user, which I don't even know what that means, you're a premium handset user, so you can download this security app. [25:51.770 --> 25:53.470] And it's in a third-party app store. [25:53.590 --> 25:55.590] It's like T-Mobile's app store for the Android. [25:55.590 --> 26:06.450] So, I'm sure it's really T-Mobile, but they're not really helping the problem, because I can send an SMS that says that, because you are a premium customer, you can now download this awesome security app, and it's going to exploit you. [26:07.310 --> 26:08.630] So, I can do that. [26:08.750 --> 26:09.670] Anybody can do that. [26:09.870 --> 26:11.170] So, yeah. [26:12.330 --> 26:14.410] We'll see if our users actually respond to this. [26:14.530 --> 26:15.150] So, I can send this. [26:15.230 --> 26:17.290] You give me a list of numbers in your organization. [26:17.590 --> 26:20.610] I'll send out things like this to it and see who responds. [26:24.050 --> 26:24.850] Local example. [26:24.850 --> 26:27.650] So, again, our smartphones have our kernel vulnerabilities. [26:27.910 --> 26:28.950] They're just Linux kernels. [26:29.190 --> 26:30.990] Doing secure development is hard. [26:31.090 --> 26:33.390] A lot harder than my job of exploiting it. [26:33.570 --> 26:36.070] So, keep your kernels up to date. [26:36.330 --> 26:37.210] But who really does? [26:37.930 --> 26:38.770] I don't. [26:39.330 --> 26:41.950] So, jail breaks use this. [26:42.310 --> 26:43.590] Malicious apps use this. [26:43.750 --> 26:45.910] Droid Dream ran Rage Against the Cage. [26:45.910 --> 26:49.470] I've read the source code of Droid Dream. [26:49.750 --> 26:53.830] And really, all they did was take Z4 root and port it in. [26:53.870 --> 26:55.750] So, it's exactly the same code. [26:55.950 --> 27:10.610] So, it's really a lot of the people who are making malicious apps are just taking jailbreak apps and putting them in there behind some nice-looking code that either, I guess, it had games and then it had, like, adult website ads and things. [27:10.610 --> 27:16.330] So, pick your poison about what interesting app you want to download and then it will start exploiting you. [27:16.490 --> 27:19.910] So, if you're vulnerable to a known issue, which since update... [27:19.910 --> 27:22.090] I never thought I'd say anything nice about Microsoft. [27:22.630 --> 27:30.550] But, you know, when Patch Tuesday happens, all my computers, they restarted in the morning and now they're up to date. [27:30.790 --> 27:31.490] That's the default. [27:32.170 --> 27:34.010] Not so much with my smartphones, really. [27:34.130 --> 27:36.150] They are starting to push all of them over the air. [27:36.150 --> 27:41.050] It used to be you had to plug in the iPhone and I don't update my iTunes library very often. [27:41.270 --> 27:42.990] They are pushing it over the air now. [27:43.170 --> 27:43.950] Same with Blackberry. [27:44.470 --> 27:47.370] So, Android was originally the only one that pushed it over the air. [27:47.590 --> 27:50.370] But now they're the worst because they never push out their updates. [27:50.510 --> 27:56.830] If you're not Nexus One, Nexus S, or any other Google platform, good luck getting your updates in a reasonable amount of time. [27:57.070 --> 28:02.930] They have to port the Android to the platform in question and it could take forever. [28:03.230 --> 28:05.450] And if you've got an older phone, you may never get it. [28:05.450 --> 28:07.090] So, you're going to be vulnerable forever. [28:08.090 --> 28:10.570] I recently jail broke somebody's phone for them. [28:10.730 --> 28:12.470] They were going to pay me 20 bucks or something. [28:12.650 --> 28:14.010] I was like, oh, this is going to be hard. [28:14.090 --> 28:16.110] I'm going to have to get one of the newer jail breaks. [28:16.290 --> 28:16.990] I open it up. [28:17.230 --> 28:18.330] Android 2.1. [28:18.590 --> 28:20.030] It's like, okay, I can do this. [28:20.310 --> 28:21.770] This is quite simple. [28:22.330 --> 28:25.730] They just never got updates and your end users don't think about stuff like this. [28:25.930 --> 28:26.730] It's a phone. [28:27.090 --> 28:27.910] I have a picture. [28:28.030 --> 28:29.970] I should have put it in the presentation. [28:30.190 --> 28:33.690] It's a phone I actually saw in Columbia from like the 1800s. [28:33.690 --> 28:36.570] It's like one step up from two cups in a string. [28:36.770 --> 28:39.410] That's what most users see when they see a smart phone. [28:39.530 --> 28:40.970] They're like, oh, it makes calls. [28:41.170 --> 28:43.610] And then it does all this other cool stuff too to make my life easier. [28:43.810 --> 28:45.410] They don't really think of it as a computer. [28:47.130 --> 28:51.230] And then the stuff that's currently in there for post exploitation, it can get a command shell. [28:51.590 --> 28:56.330] A lot of stuff with like the browsers, you're not root yet, so you can't install things yet. [28:56.330 --> 28:57.770] So you get a command shell. [28:57.910 --> 29:00.830] And from there you can start doing post exploitation to try and get root. [29:01.730 --> 29:06.610] I do have an app based agent, so I install an app that has functionality in it for... [29:06.610 --> 29:07.490] that has different payloads. [29:08.090 --> 29:14.830] So I can just send it like an SMS or over HTTP and tell it, please send a SMS message to this other person. [29:15.010 --> 29:16.090] And it'll do that for me. [29:16.250 --> 29:18.850] Or please run this privilege escalation attempt. [29:18.890 --> 29:19.650] And it will do that. [29:20.970 --> 29:24.270] Or please send me all of your SMSs that you've ever received. [29:24.410 --> 29:25.250] And it will do that. [29:25.590 --> 29:27.030] Please send me all your contacts. [29:27.410 --> 29:28.210] It'll do that. [29:28.730 --> 29:32.930] So definitely still in the works, but this is what I have now. [29:33.210 --> 29:34.390] How are we doing on time? [29:34.650 --> 29:34.770] Good. [29:35.590 --> 29:37.050] So now we get to do some demos. [29:37.250 --> 29:43.470] And I said I was going to do this all live and I'm going to try, but I did actually chicken out this morning and make videos. [29:43.730 --> 29:49.530] So if anything fails, I've learned a lot about smartphone emulators in this project. [29:49.530 --> 29:52.670] And I have learned that they have bugs, crazy bugs. [29:52.890 --> 29:54.590] There's a lot of things wrong with the emulators. [29:54.930 --> 30:03.530] And particularly since the SMS actually goes over the network instead of being SMS, if it just doesn't arrive in a reasonable amount of time, they just never get it. [30:03.670 --> 30:05.030] So that's really bad for demos. [30:05.350 --> 30:06.850] So these demos could fail. [30:07.050 --> 30:08.130] It does work. [30:08.250 --> 30:10.370] But we have videos in case it doesn't. [30:10.930 --> 30:15.590] But we're actually going to look at a few of the interfaces and have it do a few things. [30:18.430 --> 30:19.150] All right. [30:20.090 --> 30:23.890] So this laptop belongs to DARPA and they didn't give me much memory. [30:23.910 --> 30:27.070] So I actually have my Mac mini over here doing a lot of the heavy lifting. [30:28.150 --> 30:29.790] But let me start up my emulators. [30:30.490 --> 30:33.450] If I leave them alive too long, they hang. [30:33.830 --> 30:35.510] So I didn't want to leave them on. [30:38.050 --> 30:42.190] So start up one that's going to have the Android app on it. [30:43.270 --> 30:45.430] And start up one that's going to have the agent. [30:45.770 --> 30:47.990] And start up one that's going to be our third victim. [30:50.130 --> 30:54.700] So four gigs of memory can hardly run three emulators. [30:55.410 --> 30:57.110] So we'll do the best we can. [31:08.380 --> 31:12.680] While those are starting up, come over here to my other guide. [31:17.780 --> 31:19.780] So this will actually run on Backtrack. [31:19.940 --> 31:26.140] The only problem with running it on Backtrack, that's of course where I wanted to run it, is that the Apache server does not have mod Perl. [31:26.340 --> 31:28.560] So it just seemed a lot easier to just... [31:28.560 --> 31:30.500] This is Ubuntu and I put XAMS on it. [31:30.600 --> 31:32.520] So it's just going to run off that web server. [31:33.700 --> 31:38.200] But otherwise, all it needs is Perl with a couple of add-ons. [31:38.200 --> 31:42.380] It has to have expect and it has to have a DBI connection. [31:42.720 --> 31:44.180] So database to MySQL. [31:44.620 --> 31:47.680] So I've just got the MySQL database running here. [31:47.960 --> 31:49.860] So you can kind of like move it out. [31:49.980 --> 31:52.260] You can have it all on one machine or... [31:52.260 --> 31:56.300] Because it's the emulators that are the memory problem, not the framework itself. [31:56.300 --> 32:03.400] So if you're actually exploiting real phones and not emulators, then you would have no trouble running it on just your normal laptop. [32:03.400 --> 32:05.420] But you can also spread it out. [32:05.580 --> 32:09.560] So I've got the database here on the regular laptop. [32:09.880 --> 32:11.680] I've got the actual framework over here. [32:11.860 --> 32:15.700] And then I need to move the emulators over there too, because it has 16 gigs of RAM. [32:16.900 --> 32:18.640] Oh, please start up. [32:19.080 --> 32:19.400] Okay. [32:22.660 --> 32:24.040] So I just... [32:24.040 --> 32:26.680] If I go do an LS, I've just got all of this. [32:26.800 --> 32:29.780] And the source code for this is being released in a couple of weeks at Black Hat. [32:29.900 --> 32:30.720] So this will be online. [32:30.880 --> 32:31.540] You can download it. [32:31.660 --> 32:33.200] It's going to be BSD licensed. [32:33.200 --> 32:35.320] So you can use it however you want. [32:37.140 --> 32:38.340] But basically, yeah. [32:39.840 --> 32:41.600] So I'll just start up framework.pearl. [32:42.560 --> 32:49.580] And welcome to the smartphone pen-test framework, version 0.1, which basically means if it fails, just send me a bug report and I'll fix it. [32:49.820 --> 32:51.360] Because this is initial release. [32:51.620 --> 32:53.740] So things could go wrong, possibly. [32:54.000 --> 32:55.400] So we have a few options. [32:56.600 --> 32:59.320] A good one to do to start is just to clear the database. [32:59.320 --> 33:02.940] I was doing a lot of testing, so I have all sorts of nonsense in my database. [33:03.380 --> 33:05.780] It says, do you really want to destroy all your data? [33:05.880 --> 33:07.420] Because it's going to take everything out of the database. [33:07.700 --> 33:08.340] I say yes. [33:08.480 --> 33:10.400] And it just recreates my database for me. [33:10.560 --> 33:13.380] So I've got a nice clear database for us to work with. [33:16.790 --> 33:17.150] Okay. [33:17.290 --> 33:18.690] We're trying to see live emulators. [33:20.550 --> 33:21.010] Let's see. [33:21.230 --> 33:22.410] I just got a text. [33:22.690 --> 33:26.270] Your entry in our drawing won a free $500 gift card. [33:26.370 --> 33:26.570] Really? [33:26.830 --> 33:28.290] I just got another Target won? [33:28.530 --> 33:29.350] On stage? [33:31.310 --> 33:37.030] Anybody want to go to www.target.com.tvtz.biz? [33:37.130 --> 33:38.430] I'm not online, or I would. [33:38.530 --> 33:39.310] We'd see what it did. [33:39.750 --> 33:40.190] So yeah. [33:40.530 --> 33:42.050] They say I want a gift card. [33:43.890 --> 33:46.990] My code is 601, so if you'd like a $1,000... [33:46.990 --> 33:47.930] No, this one's $500. [33:47.930 --> 33:49.350] I didn't win as much this time. [33:49.470 --> 33:53.090] But there's a $500 gift card if you'd like it. [33:53.290 --> 33:56.190] So by all means, if you want it, go get it. [33:56.270 --> 33:59.070] I wouldn't go to it from a smartphone though, probably. [33:59.490 --> 33:59.870] But maybe. [34:00.410 --> 34:01.450] It's too bad these aren't online. [34:01.570 --> 34:03.350] We'd go to it from the emulator and see what it did. [34:05.050 --> 34:06.330] That'd be a good demo, right? [34:07.250 --> 34:11.010] Or actually, Jimmy Shaw's gonna do a mobile malware in a couple hours. [34:11.210 --> 34:11.870] He can go to this. [34:11.970 --> 34:12.830] I'll give him the link. [34:14.390 --> 34:14.870] All right. [34:15.010 --> 34:17.190] So I've actually already got the framework app. [34:17.330 --> 34:23.070] This is our controlled by our pin tester phone, Ice Cream 2. [34:23.650 --> 34:27.390] So I start up my app, and I want to actually attach it to the framework. [34:29.150 --> 34:33.730] So I have option 4 attached to a mobile modem. [34:33.910 --> 34:35.010] So I have a couple options. [34:35.170 --> 34:36.690] I can search for an attached modem. [34:36.830 --> 34:37.290] So if you... [34:37.290 --> 34:39.490] It only supports certain USB modems. [34:39.630 --> 34:40.490] They're all a little different. [34:40.650 --> 34:42.710] But it can actually use a USB modem. [34:42.750 --> 34:47.110] You just put a SIM card in it, and it'll attach to that and use that for the mobile modem. [34:47.170 --> 34:51.270] Or we can just attach it to our smartphone app, and it will use that modem. [34:52.050 --> 34:53.290] So that's what I want. [34:53.610 --> 34:54.810] I tell it the phone number. [34:58.630 --> 35:00.170] I tell it the control key. [35:00.410 --> 35:05.070] So just to make sure all of the data going back and forth is actually from the framework. [35:05.350 --> 35:06.890] It can be any seven digit key. [35:07.050 --> 35:08.810] Key key one is easy to type. [35:08.950 --> 35:10.410] So that's what I use for demos. [35:11.210 --> 35:12.750] And a URL path. [35:13.130 --> 35:14.530] So I'll just call it hope demo. [35:15.150 --> 35:18.010] So just where it's going to communicate on the web server. [35:18.250 --> 35:19.410] It asks me, is that correct? [35:19.430 --> 35:20.250] I say yes. [35:20.250 --> 35:20.330] Yes. [35:20.530 --> 35:23.630] And it waits for the app to show up. [35:26.030 --> 35:30.090] So I just need to give it the IP of the web server where it's going to check in. [35:31.150 --> 35:39.350] So, of course, this is all local, but you could do it on a Internet facing interface and do this over the Internet too. [35:40.510 --> 35:43.290] So we just need to put in the same parameters. [35:43.290 --> 35:45.430] So hope demo and the same key. [35:46.030 --> 35:49.070] And it kind of does a little TCP connection for us. [35:50.290 --> 35:51.450] And it connected. [35:54.130 --> 35:55.450] So, yay, connected. [35:56.710 --> 35:57.150] And... [35:57.150 --> 35:58.130] So let's see. [35:58.250 --> 35:59.470] What things can we do with this? [36:00.430 --> 36:01.850] We could run a remote attack. [36:01.850 --> 36:04.450] So here's where I'm going to show you the IP address of my iPhone. [36:04.690 --> 36:06.950] But let me finish the demo before you wipe it out. [36:08.190 --> 36:08.850] All right. [36:10.250 --> 36:10.690] So... [36:11.650 --> 36:13.690] God, you guys have already killed it, haven't you? [36:14.490 --> 36:15.190] Somebody did. [36:15.470 --> 36:17.470] My iPhone is like, I don't want to work now. [36:17.650 --> 36:18.450] Somebody killed it. [36:18.890 --> 36:21.130] Well, I think it's still on the network, so we'll see. [36:21.790 --> 36:23.590] Run a remote attack, number five. [36:25.030 --> 36:26.990] Test for the default SSH password. [36:27.730 --> 36:34.230] I just need to give it the IP address, which if it's actually on, that's its IP address. [36:35.610 --> 36:37.130] Yes, it's still on the network. [36:37.570 --> 36:41.050] It would not have seen root at such and such as password otherwise. [36:41.290 --> 36:41.890] So now you know. [36:45.570 --> 36:48.090] And, of course, like anything I write, it takes a minute. [36:52.140 --> 36:53.820] Okay, somebody just attacked it. [36:53.880 --> 36:54.980] My iPhone just went down. [36:56.340 --> 36:57.660] Connection reset by fear. [36:58.100 --> 36:59.240] All right, that's why we have videos. [37:03.390 --> 37:08.210] I knew I couldn't trust you guys to let me wait until after the demo before you started attacking my stuff. [37:08.210 --> 37:09.290] What am I talking about? [37:09.390 --> 37:09.970] This is hope. [37:10.310 --> 37:11.410] This isn't black hat. [37:13.470 --> 37:15.730] All right, remote attack.mp4. [37:15.730 --> 37:16.970] Let me turn down the sound. [37:17.150 --> 37:19.750] My boyfriend would not stop talking while I was making these. [37:25.580 --> 37:28.300] All right, so demo fail number one. [37:28.560 --> 37:35.740] The last time I did this, people waterboarded me for every demo I did incorrectly, so we can go outside and do that afterwards if you like. [37:47.620 --> 37:48.440] Thanks, guys. [37:48.620 --> 37:49.860] You guys killed my iPhone. [37:50.240 --> 37:51.940] I guess I told you to, so. [37:58.570 --> 38:06.190] So what it's actually doing is it's trying Alpine to log in, and once that works, not very good resolution, is it? [38:06.730 --> 38:16.410] But what it does is it sees if Alpine works, and then if it does, it SFTPs into it and uploads an agent, iPhone.deb, and installs it. [38:16.930 --> 38:21.170] And if it works, it says, indeed, it is vulnerable, and it did install an agent. [38:21.350 --> 38:22.910] So there's now an agent on that iPhone. [38:23.090 --> 38:25.550] Well, there's nothing on this iPhone except a picture of a cat. [38:25.750 --> 38:28.190] I don't even have little apps now. [38:28.430 --> 38:28.930] Good job. [38:29.070 --> 38:30.410] Somebody in this room is really good. [38:32.670 --> 38:34.330] Seriously, my iPhone's just gone. [38:34.870 --> 38:36.590] Yes, clap for whoever that was. [38:38.670 --> 38:40.450] So I can tell my customers. [38:40.730 --> 38:43.070] They're like, oh, iPhone's not scary. [38:43.270 --> 38:44.810] iPhone's not vulnerable to anything. [38:44.950 --> 38:49.230] I'd be like, well, I went on stage and showed them my IP address, and they just destroyed it. [38:49.570 --> 38:51.950] So, yes. [38:52.310 --> 38:53.810] And I gave you a little help there. [38:53.910 --> 38:56.150] That was iPhone 4.3, mind you. [38:56.330 --> 38:59.250] But still, a lot of your users probably have that. [38:59.510 --> 39:01.550] So you can go tell your users as well. [39:01.550 --> 39:03.830] Yes, it is exploitable on stage. [39:05.950 --> 39:06.710] All right. [39:07.030 --> 39:08.370] Let's do a demo that works. [39:10.950 --> 39:12.770] We just hit zero to go back. [39:13.030 --> 39:15.270] Let's run a social engineering attack. [39:15.730 --> 39:19.410] Let's make sure all of our emulators want to respond to SMSs. [39:20.250 --> 39:21.950] So this is our guy with the agent. [39:22.990 --> 39:24.170] Should already be on. [39:24.310 --> 39:25.690] But we don't need the agent right now. [39:26.050 --> 39:28.010] And this is going to be our victim. [39:32.240 --> 39:32.780] All right. [39:32.960 --> 39:35.700] So run a social engineering or client-side attack. [39:35.880 --> 39:36.500] Number six. [39:36.860 --> 39:38.820] I want to do a client-side shell. [39:40.160 --> 39:42.800] Currently, my only one in there is that web kit against Android. [39:42.980 --> 39:44.220] But we can, of course, put more in. [39:44.360 --> 39:45.780] It's just a little module to run it. [39:45.880 --> 39:47.820] So we just port in more exploits. [39:47.820 --> 39:49.200] And it will give us more options. [39:51.360 --> 39:52.760] So I want to put it somewhere. [39:53.280 --> 39:54.720] Demo for hope one. [39:56.180 --> 39:57.620] Give it a file name. [39:58.460 --> 40:00.380] Demo for hope dot HTML. [40:01.220 --> 40:03.720] And it will actually put that on the web server for us. [40:03.720 --> 40:05.560] And phone number to attack. [40:13.000 --> 40:17.800] And then if everything works correctly, we should get a text message over here. [40:19.060 --> 40:20.600] Android keyboard doesn't work. [40:20.840 --> 40:21.380] That's nice. [40:24.740 --> 40:25.660] There we go. [40:25.940 --> 40:28.460] So what actually happens is it used the mobile modem. [40:28.540 --> 40:31.600] If you have more than one mobile modem attached, it will give you an option. [40:31.600 --> 40:34.080] Do you want to use list of mobile modems? [40:34.300 --> 40:37.980] So it actually sent it from my 5554. [40:37.980 --> 40:42.220] So it used that mobile modem inside of the smartphone that I attached to. [40:42.420 --> 40:43.700] So one of these down here. [40:43.960 --> 40:44.680] To send it. [40:45.180 --> 40:46.420] And it's, here's the link. [40:46.520 --> 40:47.320] This is a cool page. [40:47.460 --> 40:48.200] Please go to this. [40:48.420 --> 40:50.720] So I, naturally, as a user, I'm like, oh, cool. [40:50.840 --> 40:51.760] Free stuff from Target. [40:53.520 --> 40:58.580] And then it's actually going to go to that page, which has the WebKit exploit. [40:58.580 --> 41:03.840] Which, again, is, like most browser exploits, not 100% awesome all the time. [41:03.840 --> 41:05.420] Because it actually has to heap spray. [41:05.720 --> 41:07.120] So we'll see if it works. [41:08.440 --> 41:10.800] And it does take a minute to heap spray it. [41:10.920 --> 41:12.120] Especially in an emulator. [41:12.980 --> 41:15.720] So, basically, once the browser dies, we'll see that it worked. [41:19.520 --> 41:20.740] You can do it. [41:28.820 --> 41:30.080] Come on, die, browser. [41:30.200 --> 41:30.520] Die. [41:30.820 --> 41:31.120] Die. [41:34.610 --> 41:35.390] There we go. [41:35.830 --> 41:36.150] Alright. [41:36.350 --> 41:37.250] So the browser died. [41:37.450 --> 41:38.650] So chances are it worked. [41:40.650 --> 41:42.330] No, it didn't get a shell. [41:42.550 --> 41:43.270] That's unfortunate. [41:43.510 --> 41:44.130] Let's try again. [41:54.900 --> 41:56.700] At least one of my demos has to work. [41:56.820 --> 41:57.800] I never do live demos. [41:57.960 --> 41:59.600] I have the excuse of having smartphones. [41:59.860 --> 42:01.860] It's like holding a camera over the smartphone and things. [42:01.960 --> 42:02.620] That's really hard. [42:02.920 --> 42:03.860] I'm like, I'll just use emulators. [42:04.520 --> 42:05.480] And I can do live demos. [42:08.620 --> 42:11.840] But I did not sacrifice anything to the demo gods this morning. [42:11.840 --> 42:13.120] I obviously should have. [42:14.320 --> 42:15.040] There we go. [42:15.160 --> 42:15.360] Alright. [42:15.360 --> 42:17.260] So it sees that it was... [42:17.260 --> 42:17.540] It just... [42:17.540 --> 42:19.320] Right now, it just closes the shell. [42:19.500 --> 42:21.720] But we can have it give the shell to the user as well. [42:22.120 --> 42:23.880] So, basically, it just opens the shell. [42:24.020 --> 42:24.800] Runs one command. [42:24.960 --> 42:25.780] It says UID. [42:26.120 --> 42:28.920] So, since we're the web browser, we are. [42:29.700 --> 42:31.280] We are app number two. [42:31.460 --> 42:34.060] Which is the browser on this Android emulator. [42:34.260 --> 42:36.800] And then it just closes the shell and says, yes, they were vulnerable. [42:37.660 --> 42:39.120] So, we did have a demo work. [42:39.240 --> 42:40.080] On the second try. [42:40.400 --> 42:40.840] But still. [42:41.280 --> 42:41.680] Yeah. [42:42.900 --> 42:45.100] My first live demo that's ever worked. [42:46.200 --> 42:46.800] All right. [42:47.000 --> 42:47.460] So, let's see. [42:47.560 --> 42:48.640] What else can we do with this? [42:48.820 --> 42:49.660] Let's do... [42:49.660 --> 42:51.220] Attach it to an actual agent. [42:52.380 --> 42:54.660] I'm just going to attach it to one that's already deployed. [42:59.510 --> 43:01.370] I'll just give it the agent's phone number. [43:02.150 --> 43:07.130] The phone number of the controller, which is going to be my mobile modem. [43:08.470 --> 43:09.570] The URL path. [43:09.770 --> 43:10.870] So, where it checks in. [43:10.990 --> 43:13.350] This is all hard-coded in the agent itself. [43:13.350 --> 43:15.090] Like inside of Eclipse. [43:16.870 --> 43:17.190] And all of that. [43:17.310 --> 43:19.550] I want a Mac Mini when this is all over. [43:20.870 --> 43:22.450] And then again, a control key. [43:22.590 --> 43:24.350] Which again, can be any seven digit key. [43:25.390 --> 43:26.910] It doesn't have to be key key one. [43:27.070 --> 43:28.590] It doesn't have to be the same as... [43:28.590 --> 43:31.450] That's the same thing we used for the smartphone app. [43:31.670 --> 43:36.070] But again, it can be different just as long as it's the same in the agent and in the framework. [43:36.070 --> 43:38.170] And then we tell it the platform. [43:38.170 --> 43:39.850] This is going to be Android based. [43:40.190 --> 43:41.530] So, yes, this is correct. [43:43.470 --> 43:45.170] Let's make sure our agent is running. [43:45.390 --> 43:46.530] It should have started. [43:47.570 --> 43:48.850] But let's just make sure. [43:49.170 --> 43:49.290] Yep. [43:49.590 --> 43:49.770] Okay. [43:51.070 --> 43:52.330] And then let's see. [43:52.470 --> 43:54.170] So, we can send commands to our agent. [43:55.170 --> 43:57.310] So, we currently only have one agent attached. [43:57.450 --> 43:59.430] So, we can send an SMS. [43:59.430 --> 44:01.290] So, we can send an SMS to somebody else. [44:01.410 --> 44:04.630] We can have it take a picture and upload it to us. [44:05.290 --> 44:07.370] That doesn't work on every version of Android. [44:07.670 --> 44:12.190] Or if it doesn't have a camera, it'll fail nicely and tell you what the error is. [44:12.390 --> 44:17.970] We can get all the contacts from it, which doesn't work on emulators, but will work on your regular phone. [44:18.170 --> 44:19.410] We can get the SMS database. [44:19.610 --> 44:24.070] I currently have it just getting the last 10 SMSs, because that's a really big file. [44:24.610 --> 44:27.330] And it can do a privilege escalation attack against it. [44:27.770 --> 44:29.690] So, let's do take a picture. [44:30.670 --> 44:31.890] And delivery method. [44:31.890 --> 44:36.430] We can either have it send over the mobile modem or have it send over HTTP. [44:36.950 --> 44:41.490] So, that web address where we told it to check in at that IP address. [44:41.770 --> 44:44.510] And then, like Android Agent 1, that's where it's checking in. [44:44.630 --> 44:45.690] So, let's just do HTTP. [44:45.690 --> 44:46.930] We haven't seen that yet. [44:47.550 --> 44:49.250] And then that's all going to run in the background. [44:49.250 --> 44:52.110] And we'll look at the database and see if it works in a minute. [44:52.470 --> 44:53.390] It does... [44:53.390 --> 44:57.150] We can't have the agents and things check in every couple seconds. [44:57.150 --> 44:58.530] All right, I've got 10 minutes. [44:58.790 --> 45:00.690] That's good, because I don't have time for questions. [45:00.970 --> 45:04.130] We can't have it check in all the time, because that'll run down your battery. [45:04.370 --> 45:05.790] That's what botnets run into. [45:06.150 --> 45:09.450] If you're checking in, like, every second, we see stuff start to die. [45:09.610 --> 45:11.770] And users hate it when their batteries run down. [45:11.910 --> 45:14.410] So, I actually have it checking in every 30 seconds right now. [45:18.950 --> 45:21.010] So, again, we do zero to get back. [45:21.810 --> 45:23.050] Few information gathered. [45:24.170 --> 45:25.450] Like, right now it has nothing. [45:25.530 --> 45:28.230] Hopefully, in a second, it will have picture location. [45:29.150 --> 45:33.850] I want to show you a couple things with the app before we run out of time. [45:33.850 --> 45:36.370] So, we can do a lot of the same things from the app itself. [45:37.390 --> 45:42.650] We can run our remote attacks, which obviously we can't do, because I don't have an iPhone right now. [45:43.170 --> 45:43.790] Thank you. [45:46.270 --> 45:48.530] So, it's just menu-based here. [45:48.750 --> 45:52.050] Again, I'm not a graphical user interface designer by any means. [45:52.190 --> 45:54.550] So, by all means, write me and say, God, your stuff sucks. [45:54.710 --> 45:55.430] Please change it. [45:57.830 --> 45:59.490] Again, client-side and social engineering. [45:59.490 --> 46:01.450] We can run these here as well. [46:01.570 --> 46:03.790] I'm just going to use the mobile modem, actually, on the device. [46:03.910 --> 46:04.690] Makes it even easier. [46:04.830 --> 46:05.450] One less step. [46:05.450 --> 46:06.610] It doesn't have to send it here. [46:06.710 --> 46:08.790] It just has to send information back to the server. [46:08.790 --> 46:10.750] So, we can direct download. [46:11.610 --> 46:13.310] Tell it which one to download. [46:14.490 --> 46:16.370] So, the same stuff here. [46:17.010 --> 46:20.010] We can also send commands to an agent. [46:21.010 --> 46:23.690] Let's see if we got our picture back. [46:26.450 --> 46:27.690] Still didn't work. [46:28.650 --> 46:29.630] Demo fail number two. [46:33.960 --> 46:38.260] We can, like, send commands to an agent here. [46:38.500 --> 46:40.520] So, like, for instance, if I want to send an SMS. [46:41.020 --> 46:43.280] I just send it to the number I want to send it to. [46:48.010 --> 46:49.190] And then the message. [46:53.640 --> 46:55.520] And then we get... [46:55.520 --> 46:57.500] And this time, it's from the actual agent. [46:57.740 --> 47:02.080] We saw before that it actually came from 5554, which was the... [47:03.540 --> 47:05.020] That's our Android app. [47:05.140 --> 47:06.480] But these actually came from the agent. [47:06.680 --> 47:10.820] So, I was on 5554 doing this. [47:11.000 --> 47:14.640] And then it actually sent it to the agent and told it to send an SMS to someone else. [47:14.780 --> 47:18.280] So, it looks like to our third phone that it came from the infected phone. [47:18.780 --> 47:20.820] So, remote control there. [47:20.960 --> 47:22.360] So, we at least saw it do something. [47:22.560 --> 47:23.040] That's nice. [47:23.500 --> 47:24.160] All right. [47:24.460 --> 47:28.040] So, now, I want to show you the actual... [47:30.320 --> 47:31.720] Actually, I have to tell it where to go. [47:32.760 --> 47:33.480] Five minutes. [47:33.800 --> 47:34.080] All right. [47:34.320 --> 47:35.240] So, we'll look at it. [47:35.920 --> 47:37.420] And that's really all we'll do. [47:37.780 --> 47:38.900] So, this is... [47:38.900 --> 47:40.560] It has all the same functionality. [47:40.860 --> 47:43.580] We just click on things and tell it to do stuff. [47:44.240 --> 47:46.480] Like, take picture, delivery method. [47:46.740 --> 47:49.400] If we select SMS, it wants to choose a mobile modem. [47:49.480 --> 47:50.500] We currently have one. [47:51.280 --> 47:53.060] You can view information gathered. [47:54.740 --> 47:55.140] Which... [47:55.140 --> 47:56.540] There really shouldn't be anything in it. [47:56.800 --> 47:57.200] Except... [47:57.200 --> 47:58.580] We see, like... [47:58.580 --> 48:00.000] We saw our client side work. [48:00.180 --> 48:01.600] We did see that it got WebKit. [48:01.820 --> 48:03.800] And when we ran our remote exploit, it failed. [48:03.880 --> 48:05.100] Because you guys killed my iPhone. [48:05.340 --> 48:07.040] So, it found that that did not work. [48:07.180 --> 48:09.480] And it currently doesn't have any data on the agents. [48:11.160 --> 48:11.560] But... [48:11.560 --> 48:12.220] It's that. [48:13.400 --> 48:15.280] So, it does all of the same functionality. [48:15.620 --> 48:17.080] So, I have five minutes left. [48:17.160 --> 48:18.100] So, I want to take questions. [48:18.280 --> 48:19.120] But one last thing. [48:19.120 --> 48:23.360] I want to talk very, very briefly about Cyber Fast Track. [48:26.640 --> 48:28.720] Future of the project, there's going to be more stuff. [48:29.140 --> 48:30.520] DARPA Cyber Fast Track. [48:30.840 --> 48:31.920] It's open until August. [48:32.120 --> 48:33.080] I believe the end of August. [48:33.300 --> 48:35.100] Basically, they give you money to do research. [48:35.340 --> 48:37.220] You keep all the intellectual property rights. [48:37.500 --> 48:39.740] They get government purpose rights so they can use it. [48:39.900 --> 48:42.640] But in my case, I'm just releasing this open source. [48:42.860 --> 48:44.720] And they pay me a lot of money to do so. [48:44.860 --> 48:45.580] And it's really awesome. [48:45.580 --> 48:51.760] So, if you have a project that you're working on or would like to work on, I definitely encourage you to look up DARPA Cyber Fast Track. [48:52.240 --> 48:54.280] And that's contact data for me. [48:54.680 --> 48:56.240] I have business cards and things. [48:56.240 --> 48:57.040] Come see me after. [48:57.180 --> 49:00.240] And I can take a couple questions before they run me off the stage. [49:01.240 --> 49:02.380] But I can't see you. [49:02.480 --> 49:03.560] So, just shout out, I guess. [49:03.720 --> 49:04.200] Ah, there we go. [49:05.120 --> 49:05.560] All right. [49:05.620 --> 49:06.140] Any questions? [49:13.510 --> 49:13.830] Yeah. [49:14.110 --> 49:17.210] So, you can go see the mic or we can be done. [49:17.390 --> 49:18.370] And you can come see me after. [49:18.510 --> 49:20.150] I hate to go up and ask questions too. [49:20.330 --> 49:21.470] But again, this will be released. [49:21.590 --> 49:22.730] It's on the Black Hat CD. [49:22.950 --> 49:23.930] So, if you're going to Black Hat. [49:24.130 --> 49:25.610] But then I'm just going to throw it up on GitHub. [49:25.910 --> 49:28.090] So, this will be available after Black Hat to everyone. [49:28.450 --> 49:30.110] So, please do download it and use it. [49:30.330 --> 49:32.610] Again, you can use emulators if you don't have the smartphones. [49:33.370 --> 49:36.370] Have you talked to Backtrack about including it on Backtrack? [49:36.710 --> 49:39.450] Have I talked to Backtrack about including it? [49:39.490 --> 49:39.950] I have not. [49:40.090 --> 49:42.470] I have talked to the people at Movisec about including it. [49:42.470 --> 49:46.990] But I'm hoping to get it on the next version of Backtrack as well. [49:48.670 --> 49:49.390] Anything else? [49:49.730 --> 49:51.070] Well, thank you all for coming. [49:52.310 --> 49:53.050] It's early. [49:53.050 --> 49:53.870] I'm surprised. [49:54.390 --> 49:55.310] Why are you awake? [49:56.170 --> 49:59.590] I guess it will be tomorrow after all the parties that no one will be up until noon. [50:00.290 --> 50:01.730] Well, maybe it was a good slot. [50:01.730 --> 50:05.870] When she's with them and I'm gonna meet them right now. [50:06.710 --> 50:09.250] Homies, don't bring your girl to meet me. [50:09.370 --> 50:09.690] Cause no. [50:10.310 --> 50:12.910] Baby, don't bring your girlfriend to eat. [50:13.130 --> 50:13.410] Cause no. [50:13.930 --> 50:17.750] Please believe it unless your game is tight and you trust her.