[00:00.000 --> 00:03.460] This is the Pentop North, the smaller room up there. [00:04.340 --> 00:11.800] We're also one hour late, and the main change we're making there is the telephone pioneer talk is going to move to 10 p.m. [00:12.520 --> 00:16.180] instead of 8 p.m. [00:16.380 --> 00:22.040] And the way, the reason why we did that was it lets us use that whole space for the social engineering panel, all right? [00:22.200 --> 00:23.600] So I apologize if that's confusing. [00:23.880 --> 00:29.180] Grab me if I walk by and you want me to repeat anything, and we're trying to get the word out about the schedule. [00:29.180 --> 00:31.680] I'd also like to apologize to the fellow I cut off at the end. [00:31.900 --> 00:40.060] We were just over time, and I needed to try to help us stay on schedule, because that's probably the only way we can effectively get from room to room. [00:40.220 --> 00:41.720] So I apologize to everyone involved. [00:42.420 --> 00:43.920] All right, so are we set to go? [00:44.720 --> 00:45.380] Is this live? [00:46.220 --> 00:46.760] Okay, we're good. [00:46.800 --> 00:47.200] You can hear me? [00:47.220 --> 00:47.600] Everyone hear me? [00:47.760 --> 00:48.000] All right. [00:49.020 --> 00:49.920] You can still hear me? [00:51.960 --> 00:52.280] Hello? [00:52.620 --> 00:53.620] Well, maybe a little higher. [00:55.160 --> 00:55.480] Hello? [00:55.780 --> 00:57.340] All right, let's go ahead and jump into the next talk. [00:57.600 --> 00:57.900] Okay. [00:59.500 --> 01:01.860] If I start speaking, I'll just the volume as we got it. [01:02.020 --> 01:02.920] Okay, let people fire. [01:03.100 --> 01:03.580] How about now? [01:03.900 --> 01:04.380] Can you hear me now? [01:05.900 --> 01:06.220] Hello? [01:06.860 --> 01:07.020] Hello? [01:07.260 --> 01:07.580] Testing? [01:07.820 --> 01:08.180] Can you hear me? [01:08.380 --> 01:09.580] Only when you talk at it. [01:10.560 --> 01:10.880] Okay. [01:12.240 --> 01:13.380] Let me hold on to it then. [01:15.140 --> 01:15.860] Okay, where are we? [01:20.840 --> 01:21.160] Okay. [01:53.790 --> 01:54.110] Hello? [01:55.250 --> 01:55.570] Sorry. [01:56.870 --> 01:57.190] Can't... [01:57.190 --> 01:58.090] Oh, yeah. [01:58.390 --> 01:58.690] Okay. [02:04.340 --> 02:04.660] Yeah. [02:06.380 --> 02:06.820] Okay. [02:07.040 --> 02:07.120] Sorry. [02:07.300 --> 02:07.520] Testing. [02:07.640 --> 02:08.180] Can you hear me? [02:08.360 --> 02:08.840] It works? [02:09.100 --> 02:09.320] Okay. [02:09.460 --> 02:09.640] We're good. [02:15.480 --> 02:15.920] Okay. [02:16.140 --> 02:16.700] How about that? [02:20.290 --> 02:20.730] Yeah. [02:20.890 --> 02:20.970] Okay. [02:22.050 --> 02:22.490] So... [02:22.490 --> 02:23.270] Sorry. [02:29.530 --> 02:29.970] Hello? [02:30.810 --> 02:30.890] Hello? [02:36.670 --> 02:38.770] Give the talk and don't figure it out. [02:41.110 --> 02:41.570] Okay. [02:42.490 --> 02:43.170] All right. [02:43.590 --> 02:44.450] What slide is it? [02:44.550 --> 02:45.030] Sorry, one second. [02:45.170 --> 02:45.890] Content slide. [02:46.190 --> 02:47.010] Okay, contents. [02:47.810 --> 02:49.250] Sorry, my notes are allowed to sink. [02:49.350 --> 02:53.030] I didn't actually get the entire memory talk from earlier. [02:53.890 --> 02:54.350] Yeah. [02:54.350 --> 02:54.430] Yeah. [02:57.610 --> 02:58.010] Okay. [02:59.010 --> 02:59.490] All right. [02:59.670 --> 03:00.510] My name is Jimmy Shy. [03:00.650 --> 03:02.770] I work with McAfee Antivirus. [03:03.010 --> 03:04.270] I work in the mobile division. [03:05.950 --> 03:06.450] Where's those? [03:07.650 --> 03:08.830] Let me get to my slides here. [03:09.850 --> 03:17.930] The talk is going to be on the state of mobile rootkits and botnets and pretty much things that we're seeing that are actually out in the wild. [03:17.930 --> 03:19.410] Not just the theoretical things. [03:20.030 --> 03:25.090] This is proof of concepts, actual infectors, viruses, pretty much everything. [03:29.730 --> 03:30.350] I'm sorry. [03:30.410 --> 03:33.070] My notes are on one screen and the screen's in a different location. [03:34.170 --> 03:34.390] Right. [03:34.530 --> 03:34.670] Okay. [03:34.890 --> 03:35.390] Is it still overview? [03:39.250 --> 03:39.970] Who we are. [03:40.550 --> 03:41.190] Oh, okay. [03:41.310 --> 03:41.670] It's going. [03:41.810 --> 03:42.170] It's going. [03:42.550 --> 03:43.710] I'm about one slide down. [03:44.330 --> 03:45.570] Could you tell me which this one is? [03:45.710 --> 03:46.210] Who we are. [03:46.410 --> 03:46.770] Who we are. [03:47.050 --> 03:47.450] Okay. [03:48.510 --> 03:48.910] Right. [03:48.910 --> 03:49.370] Thank you. [03:50.250 --> 03:59.010] So I work with a team of researchers who work at mobile devices like mobile phones, PDAs, pretty much anything mobile, whatnot, we deal with it. [03:59.190 --> 04:04.550] And we also work with a lot of mobile network operators, you know, carriers, things like that. [04:08.210 --> 04:08.650] Sorry. [04:11.030 --> 04:11.470] Okay. [04:12.490 --> 04:15.450] First section is basically mobile malware. [04:16.710 --> 04:18.790] And this is a slide, a pie chart, right? [04:18.790 --> 04:19.650] Is that what we're looking at? [04:19.810 --> 04:20.270] Next slide. [04:20.770 --> 04:21.130] Okay. [04:21.350 --> 04:21.690] I'm sorry. [04:23.610 --> 04:24.650] Oh, it's not going down. [04:25.690 --> 04:26.210] Very sorry. [04:28.230 --> 04:29.090] Is that the pie chart? [04:29.370 --> 04:29.870] In the wild. [04:30.410 --> 04:31.230] That was the pie chart. [04:31.350 --> 04:32.150] That's the pie chart. [04:32.310 --> 04:32.450] Okay. [04:32.590 --> 04:32.650] Yeah. [04:32.790 --> 04:33.350] Do I have my... [04:34.010 --> 04:36.210] Let me see if I have the laser pointer. [04:37.030 --> 04:37.690] Somewhere around here. [04:39.270 --> 04:39.630] Sorry. [04:39.630 --> 04:41.050] That's right. [04:41.150 --> 04:42.130] They said go this way, right? [04:44.690 --> 04:45.050] Right. [04:45.350 --> 04:46.310] So that would have been better that way. [04:47.090 --> 04:47.830] Sorry about that. [04:49.110 --> 04:49.550] Very good. [04:50.250 --> 04:50.410] Hello. [04:54.450 --> 04:55.790] Use the mic on the stand. [04:56.230 --> 04:56.550] Yeah. [04:56.710 --> 04:57.090] It's like... [04:57.090 --> 04:57.670] I was actually... [04:57.670 --> 04:58.650] I can't actually see the slides. [04:58.810 --> 04:59.030] I'm sorry. [04:59.150 --> 05:00.470] It's a specific slide I'm looking for. [05:01.170 --> 05:06.110] So this is actually a rundown of pretty much all the mobile malware we've seen in the last four or five years. [05:07.030 --> 05:07.750] What was that? [05:07.850 --> 05:08.210] The laser? [05:09.210 --> 05:09.650] Okay. [05:09.950 --> 05:16.230] This big section here is basically Symbian malware for the Series 60 and 2nd edition and 3rd edition. [05:16.670 --> 05:18.890] Series 60 is the one made... [05:18.890 --> 05:23.630] Or most of the Nokia phones in the last maybe three to eight years or whatever. [05:23.770 --> 05:24.470] Eight to six years. [05:25.190 --> 05:28.670] And the Series 60 3rd edition is like the newer version that has more security and whatnot. [05:30.030 --> 05:35.190] Essentially, this layout where you see most of it's Symbian and the rest is Java and Windows and so forth. [05:35.390 --> 05:41.350] That actually matches the layout of smartwares sales worldwide in general, pretty much. [05:41.990 --> 05:43.490] I mean, this is what we've seen. [05:44.010 --> 05:46.150] We have what's been affected with... [05:46.150 --> 05:46.750] Oh. [05:50.910 --> 05:51.170] Yeah. [05:52.690 --> 05:53.210] Hello. [05:59.260 --> 05:59.780] Right. [05:59.980 --> 06:08.000] So other platforms like Android and iPhone, they haven't had as many sales as your Java phones, your Symbian phones, and your Windows phones. [06:08.120 --> 06:08.640] Well, not really. [06:08.640 --> 06:12.800] Windows phones, but most of these phones in general, so you won't see as much malware on that chart. [06:13.240 --> 06:20.140] But that's pretty much real samples we've seen in the world that we've gotten from customers, we've gotten from actual locations, things we've actually looked at and actually have played with. [06:20.540 --> 06:21.000] Taken apart. [06:21.220 --> 06:21.620] Turn apart. [06:21.780 --> 06:21.900] You know. [06:22.500 --> 06:22.880] Detect. [06:25.960 --> 06:27.040] That didn't change, did it? [06:27.200 --> 06:27.560] It won't. [06:27.860 --> 06:28.180] Right. [06:29.720 --> 06:30.120] Okay. [06:30.240 --> 06:31.240] This next slide here... [06:31.240 --> 06:31.760] Hold on a second. [06:32.600 --> 06:33.900] Let me sync up with that. [06:34.360 --> 06:34.800] Yeah. [06:34.940 --> 06:39.200] My notes are actually separate from the slides in here, from the side that's on the screen. [06:39.960 --> 06:40.820] Hold on a second here. [06:40.960 --> 06:42.060] Slide eight right now. [06:42.120 --> 06:42.700] Slide eight. [06:44.720 --> 06:45.160] Uh... [06:45.160 --> 06:45.400] Sorry. [06:45.540 --> 06:45.700] Okay. [06:45.880 --> 06:46.200] So, yeah. [06:46.280 --> 06:53.580] This is a chart basically of our comparison of malware between PCs and mobile devices, mobile phones. [06:54.900 --> 06:58.380] Basically, we've got Trojans, we've got viruses, we've got, what's the other one? [06:59.500 --> 06:59.900] Spyware. [07:00.180 --> 07:00.840] Yeah, spyware. [07:01.060 --> 07:03.920] Pretty much everything you see on a PC, you see on a mobile phone. [07:04.040 --> 07:05.860] We've got examples of all of those things. [07:06.220 --> 07:08.020] We're not really going to be talking about any of those. [07:08.140 --> 07:10.100] That's the bulk of what we've seen out there. [07:10.420 --> 07:11.100] Real stuff. [07:12.000 --> 07:16.340] We will be talking about what's possible with Bumblebee Kids mobile... [07:17.860 --> 07:21.240] Sorry, I can't actually see my notes, but I'll have a second here. [07:22.240 --> 07:23.280] Move on to the next part. [07:24.240 --> 07:25.120] I think this is the... [07:25.120 --> 07:26.200] It says mobile... [07:26.200 --> 07:26.700] Trends? [07:26.820 --> 07:27.220] Is that right? [07:29.620 --> 07:30.260] Oh, crap. [07:30.420 --> 07:30.740] That's right. [07:30.900 --> 07:31.200] One more. [07:31.900 --> 07:32.300] Trends, right? [07:36.620 --> 07:37.260] Ah, yes. [07:37.380 --> 07:37.500] Good. [07:38.100 --> 07:38.280] Good. [07:38.340 --> 07:39.060] Then we're going to write the texture. [07:41.020 --> 07:41.640] Ah, yeah. [07:42.760 --> 07:43.020] Okay. [07:43.120 --> 07:45.520] This is the thing with arrows and pictures and whatnot? [07:45.520 --> 07:46.060] Yes. [07:46.360 --> 07:46.940] Yeah, okay. [07:48.700 --> 07:49.200] All right. [07:49.340 --> 07:51.020] This is the lifecycle of mobile malware. [07:51.900 --> 07:54.360] Anytime it hits a new platform, it goes through a certain cycle. [07:54.980 --> 08:04.420] There's the R&D cycle where skilled researchers and malware authors and other people who know what they're doing figure out ways to make newer and newer proof of concepts. [08:04.600 --> 08:05.960] They learn the platform, basically. [08:06.180 --> 08:07.240] They learn the APIs. [08:07.460 --> 08:08.240] They learn what's possible. [08:08.340 --> 08:09.280] They learn what they can get away with. [08:09.740 --> 08:10.380] All these things. [08:10.420 --> 08:11.240] That's the R&D section. [08:11.940 --> 08:16.840] From there, it generally goes to a section where you have the reuse section. [08:17.400 --> 08:18.980] You notice all the bugs look alike over there? [08:19.860 --> 08:20.260] Yeah. [08:20.420 --> 08:22.000] That's basically the ScriptKitty cycle. [08:22.220 --> 08:29.840] That stage in the cycle where somebody has come up with something like 2980 or one of those other zines, virus zines. [08:29.920 --> 08:31.820] Someone's come up with some kind of major example. [08:32.070 --> 08:41.480] And other people say, oh, let's take the source code that they provided and let's go change a few variable names, change a few strings, and you get, like, basically a dozen variants of the exact same thing. [08:42.580 --> 08:44.400] And then after you've got the... [08:44.400 --> 08:51.020] After the original writers, the ones who actually do the actual creation, once they're getting used to it, what they do is then say, okay, now let's make some money from this. [08:51.620 --> 08:53.310] And that would be the profit-taking section. [08:53.430 --> 08:54.620] This is roughly the cycle. [08:54.720 --> 08:55.900] You get used to a new platform. [08:56.000 --> 08:57.020] You learn what you can do with it. [08:57.330 --> 08:59.050] You learn how to void detection and whatnot. [08:59.050 --> 09:00.810] And then you see how to make money from this thing. [09:01.550 --> 09:06.280] And that's not too, too common in, in, uh, in mobile malware. [09:06.780 --> 09:11.570] I mean, the whole, uh, sweep key section, that, that takes up a lot of those 700 variants at the beginning. [09:12.100 --> 09:17.000] That's a lot, a lot of, a lot of, uh, copies and replacements and things of that nature. [09:17.920 --> 09:18.980] Uh, okay. [09:19.140 --> 09:20.050] This would be definitions. [09:21.550 --> 09:22.500] Okay, I think I got it. [09:25.240 --> 09:27.880] Out of sync, uh, this would be partners. [09:28.080 --> 09:28.680] Thank you very much. [09:29.080 --> 09:32.440] Right, so botnets basically are, they were like, pretty much came from UNIX. [09:32.580 --> 09:34.080] They were, uh, essentially away from an attacker. [09:34.210 --> 09:37.120] And once they, they've taken over your system, they say, what do we do next, right? [09:37.710 --> 09:39.500] We've, uh, how do we maintain root? [09:39.580 --> 09:40.720] How do we maintain super user access? [09:40.860 --> 09:41.960] How do we maintain administrator access? [09:42.380 --> 09:43.400] Same concept, every time. [09:43.640 --> 09:45.040] It's basically a kit that lets you keep root. [09:45.740 --> 09:46.680] Uh, where was it next? [09:47.660 --> 09:49.300] Right, so basically, what's rootkit for? [09:49.440 --> 09:52.400] It's for evasion, for detection, so that no one knows the attacker's there. [09:52.880 --> 10:00.710] I mean, you have rigged binaries, you have rigged, uh, scripts that'll hide logins, and then it'll, it'll not show that files have been modified, things like that. [10:02.600 --> 10:05.960] And, right, so, and also they reduce whatever security you would have had. [10:06.120 --> 10:11.300] So, it basically makes sure you have a hole left in, or a backdoor left in the system, or on the system. [10:11.300 --> 10:15.360] And then also newer ones, especially on Windows or not, they do self-protection. [10:15.440 --> 10:17.080] They make sure that you can't remove them easily. [10:17.480 --> 10:20.440] So, you're built in, you have, uh, uh, sorry, what was I talking about? [10:21.660 --> 10:22.380] Ah, rootkits. [10:22.880 --> 10:23.380] Uh, no. [10:23.620 --> 10:24.300] Am I telling you the right one? [10:24.480 --> 10:24.520] Yes. [10:25.140 --> 10:25.500] Botnets. [10:25.600 --> 10:26.100] That's one back. [10:27.140 --> 10:27.840] There we go. [10:28.260 --> 10:28.620] Botnets. [10:28.710 --> 10:29.660] I'm giving the wrong slide again. [10:30.640 --> 10:30.880] Right. [10:31.280 --> 10:33.080] So, it, uh, botnets are pretty straightforward. [10:33.240 --> 10:35.340] You got, uh, it's a client-server kind of network thingy. [10:35.820 --> 10:48.360] Where, uh, the clients are, instead of being, like, your normal, uh, okay, this is a proper shipment box and has all clean software, you basically infect the system and say, okay, we've infected your system, and these are all ours, and they're controlled by, [10:48.380 --> 10:51.300] uh, uh, the, the command-and-control server. [10:51.620 --> 10:56.160] Command-and-control can be either, uh, one server, or it can be complicated, it can be, like, uh, massive, redundant servers. [10:56.520 --> 10:57.460] It can be tons of different things. [10:58.440 --> 10:59.800] And, uh, what's the other thing? [11:01.000 --> 11:05.940] And, uh, and they're good for doing attacks against other, uh, other targets, you know, denial of service, things like that. [11:06.940 --> 11:13.620] And, uh, depending on how complex you have them, right, uh, they may even share many things with, uh, rootkits. [11:13.840 --> 11:17.080] You know, like, if it's self-evasion, protection, similar things like that. [11:17.420 --> 11:20.260] Uh, speed definitions again. [11:20.580 --> 11:21.700] Back to the rootkits. [11:22.980 --> 11:23.820] Okay, right. [11:24.020 --> 11:32.620] Once again, same thing, that they were used to, again, take control of the system and make sure that your system is being, um, that you can still get back in again once you've broken in. [11:32.620 --> 11:34.160] That's what the attacker is out for. [11:35.300 --> 11:36.900] Uh, let's look at something else. [11:38.220 --> 11:39.080] Uh, okay. [11:39.940 --> 11:40.860] It's really small. [11:41.780 --> 11:42.040] Right. [11:42.820 --> 11:43.780] Uh, first section. [11:43.960 --> 11:44.660] Mobile rootkits. [11:44.820 --> 11:46.960] These are, uh, let's start with the precursors. [11:47.140 --> 11:47.740] Is that right? [11:48.580 --> 11:48.960] Yes. [11:49.220 --> 11:49.960] Yeah, okay, good. [11:50.140 --> 11:52.200] Okay, so, this one. [11:52.300 --> 11:53.140] Yes, Commware. [11:53.240 --> 11:57.820] Commware was a really complex malware written for C-Mean Series 60 funds. [11:58.080 --> 12:00.700] It was written by a Russian fellow who goes by the handle Elodor. [12:01.180 --> 12:03.740] He released, like, new versions every six months or so. [12:04.280 --> 12:08.480] Uh, so, A and B were, like, the first few, few, few, uh, sorry, first two variants. [12:08.960 --> 12:14.800] The really only notable thing about them is that they, they tried to, uh, basically delete other malware that was existing at the time. [12:14.800 --> 12:19.500] Like we had, like, the Kabir worm or some other, uh, virus that went on, on the device. [12:19.840 --> 12:21.120] He would say, okay, we know where those files are. [12:21.240 --> 12:21.800] Let's go delete them. [12:22.000 --> 12:24.460] So, it's one malware author attacking other malware authors. [12:24.540 --> 12:25.660] That was the first two versions. [12:26.180 --> 12:28.440] Then he changed it up in the next version C. [12:28.700 --> 12:34.680] He added more self-protection and evasion features, uh, encryption, uh, was it deleting files? [12:35.060 --> 12:36.000] A few other things. [12:36.640 --> 12:40.840] And then D, he stepped it all the way up and he said, now let's go attack, uh, antivirus itself. [12:41.940 --> 12:45.580] And that was, at the time, the most complex malware for Symbian fonts. [12:46.740 --> 12:51.320] And it, it, it was, uh, it wasn't quite a, uh, what's that command again? [12:52.320 --> 12:53.620] Sorry, I'm on, uh, rootkit. [12:53.720 --> 13:00.080] So, it, it, it had almost everything you need for rootkit except actually giving you more access, I guess, because since it was just a pure malware. [13:00.300 --> 13:03.620] But it provided all the other features, protection, evasion, all these things. [13:04.300 --> 13:07.820] Um, then we have InfoJack. [13:09.020 --> 13:09.420] Okay. [13:09.540 --> 13:13.240] InfoJack was, uh, almost the same thing for Windows, uh, mobile fonts. [13:13.440 --> 13:16.920] So, you have a complex malware that does a whole bunch of things to protect itself. [13:17.140 --> 13:20.100] It sort itself on a, on a, on the memory card so it can reinstall itself. [13:20.500 --> 13:22.340] It, it also did something really interesting. [13:22.780 --> 13:25.780] With, it was all to the, uh, uh, alter registry setting. [13:25.900 --> 13:31.460] It allowed you to silently install, uh, silently install a application that was downloaded from a server. [13:31.840 --> 13:34.460] That server actually wasn't active by the time we got the samples. [13:34.460 --> 13:36.780] So they, they shut down whatever the command and critical server was. [13:37.040 --> 13:40.240] So we never actually got, did the hack to work itself on the phone. [13:40.860 --> 13:42.340] But it was the same kind of thing. [13:42.480 --> 13:44.380] So first on scene being a precursor to rootkits. [13:45.100 --> 13:48.160] And then on Windows Mobile a precursor to a proper rootkit. [13:49.720 --> 13:55.820] Okay, uh, this should be actual rootkits. [13:56.220 --> 13:56.660] Yes? [13:57.180 --> 13:59.160] Well then this is a picture of a Linux device inside there. [13:59.620 --> 14:01.440] Okay, that, that's an open MoCo device. [14:01.620 --> 14:09.660] These are Linux phones with that, run Linux and they're like, they give you an API to basically say, okay, you want to make phone calls, you want to do whatever you want and design your own phone or whatnot. [14:10.000 --> 14:12.120] That's what the open MoCo device was. [14:12.640 --> 14:24.200] So, uh, recently a team at Rutgers, this is, uh, a big threat at all, um, they put together a bunch of, uh, four Linux, uh, sorry, loadable kernel modules for, uh, for Linux. [14:24.200 --> 14:27.060] That did a bunch of, hold on, sorry, got my notes here. [14:28.080 --> 14:29.760] Uh, yeah, they performed a bunch of attacks. [14:30.100 --> 14:40.440] Um, right, so the reason they went, they went with, uh, open MoCo over, say, some other kind of Linux device or another phone was because they had, I think, about 45 of them or something lying around. [14:40.580 --> 14:41.940] They said, okay, we gotta do something with these things. [14:42.400 --> 14:43.320] Literally, that's what they said. [14:43.340 --> 14:44.640] We have to do something with these things. [14:45.140 --> 14:52.840] And they decided, okay, we're gonna see, right, Linux, uh, sorry, loadable kernel modules because kernel mode evades user detection. [14:52.980 --> 14:54.160] So they said, let's try this out. [14:54.860 --> 15:04.500] And, uh, because you might have seen on other phones that, uh, in user mode, you can, you can listen to phone calls, listen to the, what do you call it, uh, send SMS, things like in user mode. [15:04.740 --> 15:16.860] They said, people in the future will be trying to attack actual phones with, uh, a kernel mode code so that you didn't void, uh, antivirus or rootkit detection or minimal detection. [15:17.900 --> 15:23.180] That was an actual, actual product data or actual set of four things they released at a conference. [15:23.560 --> 15:33.820] So that's basically, instead of the previous, like, CommWarrior, InfoJack, uh, any of the other 700 malware there, this is something created by actual security researchers at Rutgers University. [15:34.260 --> 15:36.040] That's a real, real rootkit. [15:37.020 --> 15:40.420] But of course, uh, a rootkit doesn't actually get you on the system necessarily. [15:40.740 --> 15:52.980] This assumes that you're actually, that you've gotten some way, you have an exploit, you have some vulnerability you've found, and you've found some way to get yourself on the device, other than simply having the user install it on the device, which is the social engineering attack, [15:53.100 --> 15:55.860] but it's pretty much what Trojan horses do. [15:56.040 --> 15:57.420] You know, it's not overly complicated. [15:57.800 --> 16:02.520] It's a lot more difficult to do this than, say, I don't know, something else. [16:02.700 --> 16:04.640] But it's a common attack and it's used often. [16:05.700 --> 16:08.140] Uh, this is, uh, botnets? [16:11.550 --> 16:12.010] Okay. [16:12.790 --> 16:13.250] Sorry. [16:14.910 --> 16:15.370] Okay. [16:16.050 --> 16:16.770] There we go. [16:17.190 --> 16:17.590] That one. [16:18.670 --> 16:19.130] Okay. [16:19.570 --> 16:20.090] All right. [16:20.190 --> 16:21.150] So this is another one. [16:21.350 --> 16:23.850] This is, uh, a so-called future attack. [16:24.210 --> 16:25.390] Um, right. [16:25.510 --> 16:32.070] So future mobile rootkits will probably do something like this, where they update the entire OS itself or replace the bootloader. [16:32.210 --> 16:34.250] This is a valid project, of course. [16:34.390 --> 16:41.310] It's written by an iPhone dev team developing other guys who work on jailbreaks and working on developing apps for them unofficially. [16:42.090 --> 16:46.930] Uh, it, it, it, it, it, it's replaced the whole whatever you had there before. [16:47.010 --> 16:52.130] You have now a, uh, a bootloader that will do a boot between Android and the iPhone OS. [16:52.350 --> 16:53.810] Or the jailbroken iPhone OS. [16:54.470 --> 16:57.930] And so, I mean, this is what the new future attacks will be looking like. [16:57.930 --> 17:03.130] Instead of saying, okay, we're going to just install a few software or install this, or have the people install something. [17:03.550 --> 17:05.290] You'll be going to have to flash the whole thing. [17:05.390 --> 17:06.910] Flash the entire phone with something else entirely. [17:07.290 --> 17:07.910] Excuse me. [17:08.390 --> 17:08.850] Okay. [17:08.850 --> 17:09.190] Okay. [17:15.420 --> 17:15.880] Sorry. [17:17.460 --> 17:18.060] All right. [17:18.440 --> 17:19.900] Uh, rootkits. [17:20.600 --> 17:23.960] Uh, this should be botnets. [17:24.990 --> 17:25.440] Okay. [17:26.010 --> 17:30.180] Um, this is a slide of, uh, OSX, I think, IPH pony. [17:30.800 --> 17:31.270] Right. [17:31.420 --> 17:31.700] Okay. [17:31.860 --> 17:38.860] This is, uh, this was done by a really, uh, software developer, I think was in, uh, Sweden, uh, named Nicholas Serio. [17:39.540 --> 17:45.230] He, he decided, uh, okay, so we have people who write malware, they need jailbroken phones, he needs a lot of different things. [17:45.440 --> 17:50.140] This thing doesn't require a jailbroken phone because all it does is use legitimate Apple-approved APIs. [17:50.420 --> 17:52.580] Meaning, you could get into an, into the app store. [17:53.530 --> 17:54.680] I mean, that's what it was for. [17:55.120 --> 17:58.660] He said, okay, we can use these things and I can still get a whole bunch of information off your phone. [17:58.660 --> 17:59.840] What can you get? [18:00.420 --> 18:12.600] Um, you can get, basically, uh, stuff you have in Safari and YouTube, like, uh, previously visited links, uh, bookmarks, not sure about passwords, and, uh, best of all, the keyboard cache. [18:12.750 --> 18:17.770] The keyboard cache on an iPhone, it's, you, you, you all have, some of you have iPhones, it has an onboard keyboard. [18:18.270 --> 18:25.930] The keyboard cache basically is a cache of every character and every word, everything you've typed on that phone, passwords, et cetera. [18:25.930 --> 18:27.880] You're, uh, you get the concept, right? [18:27.950 --> 18:35.080] It's, uh, all the text you ever typed on the, on the on-screen keyboard, into whatever box, whatever secure box, password box you think you're typing in, it's all in there. [18:35.170 --> 18:36.120] It's like a whole bunch of text. [18:36.360 --> 18:42.140] You grab that for a bunch of words about, or just grab two and look through, and you'll run into pretty much everything. [18:42.300 --> 18:46.790] And that's done from an app that isn't, uh, doesn't require a jailbroken phone, doesn't require anything else. [18:46.880 --> 18:49.600] All it needs is to install it on there. [18:50.030 --> 18:52.100] Once again, this guy is, uh, just a regular developer. [18:52.210 --> 18:58.430] He didn't actually release this app, but he did present at, I think, Black Hat, uh, DC, was it, uh, in February? [18:58.800 --> 18:59.800] A few months ago. [19:00.950 --> 19:02.600] It was initially for a user group thing. [19:02.710 --> 19:06.100] He said, okay, let me show a couple of my local user group and see, look at this app. [19:06.290 --> 19:11.880] And I got a bunch of coverage, and then they invited him, or he got accepted at Black Hat DC, and he came and he showed it off a little bit more. [19:12.870 --> 19:16.340] Uh, that's still a precursor because it never actually hit the app store. [19:16.510 --> 19:20.470] He never actually submitted it into the store and said, okay, we're gonna put this into the store and say, everyone can use this. [19:20.620 --> 19:20.900] No. [19:21.430 --> 19:22.250] He didn't do that. [19:22.580 --> 19:23.190] Uh, next one. [19:23.290 --> 19:24.250] This is a picture of Rick Astley. [19:25.510 --> 19:25.900] Yeah. [19:26.120 --> 19:26.430] Okay. [19:26.690 --> 19:28.380] Uh, is anyone familiar with the iKey worm? [19:29.620 --> 19:30.430] A few people. [19:30.530 --> 19:30.730] Okay. [19:31.080 --> 19:33.140] Um, let me run through the, the whole storyline there. [19:33.380 --> 19:47.190] Uh, so jailbroken iPhones, they, they let you have access to the phone occasionally, depending on how you installed the, or jail broke the phone and installed additional software on there, third-party software, you, you might have installed the SSH daemon on there so that you could, [19:47.320 --> 19:52.380] like, SSH into your phone and say, I can copy files over, copy files back, do whatever you want on the phone, right? [19:52.790 --> 19:53.800] On a jailbroken phone. [19:54.010 --> 20:00.580] So, a lot of, uh, the vulnerability here is that, uh, all these phones have the same, uh, root password. [20:01.290 --> 20:04.900] I mean, so it's not actually, uh, the jail beginning to cause the vulnerability. [20:05.080 --> 20:06.710] The phones always had that same root password. [20:06.710 --> 20:10.470] It's just now you have access to it because you have the SSH daemon installed on the phone. [20:10.640 --> 20:12.620] So you log in with root and boom, you've got access. [20:13.060 --> 20:29.030] So, uh, a few months before this, uh, version C of the, of this, uh, iKeworm and the downloader and so forth, before this, there was another guy, he, he was in, in the Netherlands, and he, he, he, this, uh, this teenager basically said, okay, all these jailbroken phones have the same, [20:29.030 --> 20:29.790] same root password. [20:30.380 --> 20:33.620] What if I, I log, log into them, SSH into them? [20:33.620 --> 20:37.530] Um, like, cause, cause apparently the network in the Netherlands is accessible. [20:37.710 --> 20:38.670] I think it was T-Mobile's network. [20:39.100 --> 20:44.040] Uh, you could actually go from any device or, and log into any other device on the network. [20:44.470 --> 20:54.470] So if you had an, uh, jailbroken iPhone and you had SSH just enabled on your phone, and, of course, you knew the root password, which is common knowledge, but I'm gonna mention it, Google. [20:55.060 --> 21:01.360] Um, the, if you have all those three things, you can log in and do whatever you want on the phone, cause you have root. [21:02.030 --> 21:08.620] What he did was, uh, the, the initial, initial guy, he put up a, he changed the, uh, the, what's it called, the background image. [21:09.110 --> 21:15.880] So when you hit, like, uh, end call or whatever, or hit the power button, and you, whatever, whatever that thing is that comes up there, the background image. [21:16.890 --> 21:17.560] Okay, wallpaper. [21:17.770 --> 21:19.710] It has a, I forgot the actual name of the file. [21:19.950 --> 21:22.190] But yeah, whatever your wallpaper is. [21:22.340 --> 21:24.170] He changed it out for a, a warning sign. [21:24.270 --> 21:28.380] It said, okay, send me five euros, and that'll tell you how to, how to secure your phone, because it's open to hackers now. [21:29.030 --> 21:33.620] I'm like, okay, you could change your password, of course, but not everyone knows that you can change your password on the iPhone. [21:33.900 --> 21:37.670] Even if you have jailbroken, you have SSH, that doesn't mean you knew what you were doing when you put it in there. [21:38.080 --> 21:39.120] It could have been done automatically. [21:39.320 --> 21:40.400] There are packages to do that for you. [21:40.930 --> 21:47.510] So he, he put this out there, and he tried to get away, or collect, uh, five euros from everyone in the Netherlands, or whatnot, who had a jailbroken iPhone. [21:47.870 --> 21:56.560] And then the authorities got caught up with him, and then he had to change his tune, and they put up a link to his website instead, saying, go to visit this link, and then it'll give you some kind of, say, change password. [21:56.980 --> 22:06.020] The, the, the whole point is, that brought, brought to the forefront that, jailbroken iPhones have an accessible, uh, I mean, they have the same, same password, unless you change it, right? [22:06.190 --> 22:11.620] So, somebody decided, the author of the IQ worm, A and B versions, uh, not this one. [22:12.240 --> 22:16.060] He also released a source code to that for about two, two, one or two days. [22:16.190 --> 22:17.480] I forget the exact time, time window there. [22:17.860 --> 22:20.460] So, he had no hand in writing, uh, version C. [22:20.920 --> 22:26.210] Version A and B, all they do is replace the background with Rick Astley, and iKey will never give you up, right? [22:27.100 --> 22:32.840] So, that went through the, it, uh, sorry, it, what's it doing? [22:33.080 --> 22:35.670] It's, it's, it's, it's on the network, it's on your, your mobile phone. [22:35.980 --> 22:41.950] He was scanning, uh, the worm scans the network for devices that have SSH on them, and log, tries to log into them. [22:42.260 --> 22:43.840] Because they're probably jailbroken iPhones. [22:44.240 --> 22:49.720] So, it goes through there, switches out the, switches out the background image, and moves on to another phone. [22:49.880 --> 22:51.460] And just keeps going, scanning and going. [22:51.600 --> 22:52.430] That's, that's A and B. [22:53.020 --> 22:56.900] Uh, and C is a little, slightly modified version. [23:01.640 --> 23:03.160] One second, let me check my notes here. [23:03.780 --> 23:05.600] Um, okay, yeah. [23:06.120 --> 23:07.420] This is the one that did a little bit more. [23:07.500 --> 23:11.520] This is the actual, um, um, so-called iPhone botnet version. [23:12.080 --> 23:19.020] And that's what the, why it's in quotes, is because, um, I mean, once again, a botnet is supposed to take commands from a command and control server, or some kind of control period. [23:19.020 --> 23:23.020] You send commands to the thing, to the various clients, and they're supposed to do something for you. [23:23.240 --> 23:25.860] You know, denial service, spamming, whatever, giving me information. [23:26.340 --> 23:28.340] Okay, it does kind of try to take information. [23:28.660 --> 23:31.800] Um, okay, well, I forget exactly what it took. [23:31.960 --> 23:35.280] But, because the actual sample doesn't actually work as is. [23:35.480 --> 23:41.360] They claim it did scan various devices, but what he did was modify the iKey A and B worm that was actually scanning on its own. [23:41.640 --> 23:44.520] So it actually, it sent out a package of files. [23:44.520 --> 23:50.940] That was a script and a few other things to copy things on the phone and steal your SMS messages. [23:51.160 --> 23:52.160] A bunch of things throughout the queue. [23:52.740 --> 23:53.960] And it didn't actually do that. [23:54.240 --> 23:59.300] And the most interesting part was that it added a host file to your phone. [23:59.720 --> 24:10.320] A host file that had one entry that said, I think it was, I'm not going to mention the bank, it replaces the bank's, I guess its mobile banking address with a server under control of the author. [24:11.020 --> 24:22.340] And so, the other portion, the IPH downloader, that is the one that actually tries to download the, whatever, the separate second stage, the other shellcode, whatever was on that other server. [24:22.560 --> 24:28.840] That server was a server in China that was, I'm sorry, in Japan, that was shut down and it wasn't, I think they closed it down very, very quickly. [24:28.840 --> 24:30.500] So, that never actually got anywhere. [24:30.880 --> 24:37.220] And there were no, there weren't any big losses from that host file replacement. [24:37.520 --> 24:39.020] It was basically a phishing attempt. [24:39.500 --> 24:44.740] You know, we send out the address, you come to our server, and you enter your login details on your iPhone. [24:44.820 --> 24:46.480] You say, okay, yeah, this is a good site. [24:46.540 --> 24:47.800] It's a proper site for the bank. [24:48.540 --> 24:50.060] And it didn't quite get that far. [24:50.620 --> 24:56.660] But that was an actual, the closest we got to an actual widespread botnet on iPhones. [24:57.300 --> 24:58.560] Once again, jailbroken iPhones. [24:58.700 --> 25:00.500] Anyone with a regular, an iPhone is not jailbroken yet. [25:00.800 --> 25:01.520] You couldn't log in. [25:01.620 --> 25:03.040] You couldn't do half of the things this guy tried to do. [25:04.110 --> 25:07.120] So, those are attempts on real phones. [25:07.220 --> 25:09.160] These are precursor to botnets on an iPhone. [25:13.580 --> 25:13.940] Okay. [25:15.210 --> 25:16.640] This is Symbian worm. [25:17.560 --> 25:17.920] Okay. [25:18.710 --> 25:23.780] This is the, you might have heard in the news recently about a bunch of Symbian botnets, one out of China. [25:23.780 --> 25:26.820] This is basically one in the same category. [25:27.200 --> 25:28.460] They all work very similarly. [25:29.120 --> 25:30.500] It's kind of interesting what they do. [25:30.920 --> 25:31.900] Let me get the notes. [25:33.240 --> 25:33.640] Right. [25:33.840 --> 25:34.020] Sorry. [25:34.200 --> 25:34.920] They're really small. [25:35.820 --> 25:36.060] Okay. [25:36.280 --> 25:41.840] So, this worm is on Symbian third edition, Series 60 third edition. [25:41.920 --> 25:44.360] This is the latest version of the Nokia phones that have Symbian running on them. [25:44.580 --> 25:50.260] It was much more secure than Series 60 second edition, which was the one with CommWarrior, which had everyone infected. [25:50.360 --> 25:52.680] Kabir had worms, had all kinds of malware, right? [25:52.840 --> 25:55.920] Like hundreds and hundreds of different things on Series 60 second edition. [25:56.420 --> 26:02.840] So, they came out with a new version that was a lot more secure, had like permissions, had signed applications, had a bunch of different things. [26:02.980 --> 26:06.820] You could still install, if you wanted, on an unsigned application on a Symbian third edition phone. [26:07.200 --> 26:08.740] But generally, if it's signed, it was good. [26:09.200 --> 26:12.160] This was an app, this Sexy View Worm XMJTC. [26:12.300 --> 26:16.960] We call XMJTC named after the company name because it's signed, it's by the developer. [26:16.960 --> 26:18.980] That guy's probably a pretty bad guy, right? [26:20.000 --> 26:22.720] Regardless, it had a life certificate. [26:22.900 --> 26:26.180] It wasn't like, you know, one of those expensive ones, you get all the verification ones. [26:26.260 --> 26:30.900] This was one of the cheaper ones that said, okay, yes, I'm probably pretty good. [26:30.980 --> 26:31.900] We haven't really checked it out. [26:32.080 --> 26:35.260] And even Symbian said, we haven't fully checked out this thing. [26:35.420 --> 26:38.320] It's sort of their minimal signed certificate thing. [26:38.580 --> 26:39.600] Not the full one. [26:41.690 --> 26:42.680] What does it do again? [26:43.450 --> 26:43.800] Sorry. [26:45.580 --> 26:53.580] Okay, so other than sending out SMS to other people, like basically phishing other people, it wasn't really what you call a full botnet. [26:53.700 --> 27:05.840] I mean, if you, for a real botnet, like on a PC where we have hundreds and thousands of hosts, I'm sorry, hundreds of thousands of clients, or zombies, botnets, bots, whatever you want to call them, it was pretty targeted. [27:05.840 --> 27:07.980] I mean, to install it, it has to be signed. [27:08.160 --> 27:10.140] So, in general, it has to be signed. [27:10.440 --> 27:16.240] It was signed as a certificate, but that certificate can be revoked by Nokia Symbian whenever they see something bad. [27:16.420 --> 27:17.220] They can pull that. [27:17.500 --> 27:18.300] They pull the certificate. [27:18.760 --> 27:19.840] That's one thing that happened. [27:20.140 --> 27:23.620] The other thing is, the command and control server was one server. [27:23.820 --> 27:25.480] So that server tended to die quickly. [27:26.260 --> 27:29.840] Including the ones on other Symbian worms that you might have heard about, or Symbian botnets recently. [27:29.980 --> 27:30.800] It's the same concept. [27:30.920 --> 27:31.840] They have one server. [27:32.000 --> 27:32.820] It's one attack. [27:32.820 --> 27:39.800] The only thing that changes is the name of the developer, the name of the developer, or the name of the company, or whatever it is. [27:39.900 --> 27:42.580] He just changes the name, he gets a new certificate, and says, oh, let's send it out again. [27:43.100 --> 27:46.740] That makes you have a target attack possibly. [27:46.920 --> 27:49.400] You target a specific person, you're saying to a few dozen people you know. [27:49.880 --> 27:52.940] Even with sending an SMS, you're sending people in the phone book. [27:53.120 --> 27:54.700] People they know, people who know you. [27:54.920 --> 28:03.260] It's more like you targeted, say, an executive in a company who has a Symbian phone or a Nokia phone, and you went after that one person and everyone they know, meaning executive staff. [28:03.440 --> 28:04.660] People would probably be in their phone book. [28:05.340 --> 28:06.360] It's that kind of thing. [28:06.600 --> 28:09.700] But not a full-on botnet that you can use for other things. [28:09.820 --> 28:12.820] It's not distributed computing, which is basically what botnet is supposed to be, right? [28:13.300 --> 28:21.860] You know, we're not calculating things, we're not phishing other people, or doing this large distributed denial of services, or wasting a lot of money or whatnot. [28:22.060 --> 28:22.620] None of that. [28:23.190 --> 28:24.600] It's just a really targeted attack. [28:25.360 --> 28:30.700] Those are the closest to actual attacks, but it's still what I'd call a... I'm sorry, is that a precursor? [28:31.880 --> 28:33.960] I'm sorry, what's the next picture here? [28:36.560 --> 28:38.960] Okay, okay, so this should be the actual one then. [28:40.180 --> 28:41.560] And let me see what that is. [28:42.260 --> 28:42.660] Badmonkey. [28:43.240 --> 28:44.460] Badmonkey, okay, okay. [28:45.060 --> 28:47.000] Badmonkey is an actual botnet... [28:47.000 --> 28:49.140] Okay, let me go back for a second. [28:49.320 --> 28:51.460] All those previous ones are written by malware authors. [28:51.840 --> 28:54.620] Except for the iPhone spyware that was not actually released. [28:55.240 --> 28:56.080] Pretty much all of them are that. [28:56.080 --> 29:03.280] These actual ones, the actual botnets, are different ones created by computer security researchers. [29:04.620 --> 29:05.300] Oh, sorry. [29:06.300 --> 29:07.300] What's that previous line? [29:10.160 --> 29:10.980] Badmonkey, badmonkey. [29:11.820 --> 29:13.060] Okay, you want to see the previous one? [29:13.340 --> 29:13.460] What's that? [29:13.800 --> 29:15.880] No, you're going forward by accident. [29:16.040 --> 29:17.020] Okay, sorry, thank you. [29:17.100 --> 29:18.540] I had my notes here and I've got that up there. [29:19.140 --> 29:21.700] Okay, right, so both of those... [29:21.700 --> 29:23.760] Let me start with the WeatherFist first. [29:24.520 --> 29:26.780] WeatherFist was an app released on the Android market. [29:27.000 --> 29:28.460] So it's like, okay, it's a real app. [29:28.620 --> 29:31.380] It lets you go to the Weather Underground website and check the weather for your area. [29:31.700 --> 29:38.100] It looks up your phone number to convert it to a zip code and, hey, let's send you to the page on Weather Underground that tells you the weather in your local area. [29:38.580 --> 29:39.260] Awesome tool, right? [29:39.380 --> 29:40.500] They had a whole bunch of downloads. [29:40.500 --> 29:44.840] This is a tool written by the two researchers at Tipping Point Digital Vaccine Labs. [29:45.000 --> 29:46.620] They do basically vulnerability research over there. [29:47.140 --> 29:48.940] So they said, okay, let's see if we can make it... [29:48.940 --> 29:54.380] Their reasoning behind it was, let's see if we can make a botnet app and send it out like a legitimate... [29:54.380 --> 29:56.420] This guy's a legitimate app and see what can happen. [29:56.860 --> 29:59.380] Right, so WeatherFist was the cleanest app. [29:59.460 --> 30:05.140] All it ever did was take your, I think, your phone number, do an MD5 hashing and send it over to their server. [30:05.380 --> 30:06.280] They have no idea what it is. [30:06.340 --> 30:06.940] All they have is a hash. [30:06.940 --> 30:09.120] But it was basically a proof of concept to say they can do that. [30:09.680 --> 30:12.500] But they also made another conversion, WeatherFistBadMonkey. [30:12.740 --> 30:14.360] This was never actually publicly released. [30:14.460 --> 30:18.120] But it is their more fancy, full-featured real botnet. [30:19.280 --> 30:20.840] WeatherFistBadMonkey, that did a little bit more. [30:21.780 --> 30:22.620] What else did you grab? [30:24.100 --> 30:25.920] It actually took commands. [30:26.300 --> 30:27.920] They did it multi-platform on top of that. [30:28.020 --> 30:29.680] Not just Android, also Android and iPhone. [30:30.280 --> 30:36.020] But since they were doing botnets, they didn't actually put it into the iPhone app store or the Android market. [30:36.020 --> 30:43.760] They said, let's put it into alternative third-party markets, like SlideMe on Android and Cydia on the iPhone. [30:43.900 --> 30:45.960] So you needed a jailbroken phone on the iPhone. [30:46.340 --> 30:52.640] And Android, you could install what you like if you set a setting for third-party applications in your settings. [30:54.100 --> 30:57.320] So the BadMonkey version, it grabs your... [30:57.320 --> 30:58.620] Sorry, what did it actually grab? [30:58.720 --> 31:04.480] It did actually take commands like sending emails out to them, you know, spamming. [31:05.160 --> 31:07.880] Performing distributed denial of service attacks. [31:08.160 --> 31:14.400] And best of all, the client on, I think, iPhones at least, to provide a reverse shell into the phone. [31:15.450 --> 31:17.680] So, you know, it's a nice, nice thing. [31:17.860 --> 31:20.960] You thought, I'm going to go check the weather in New York or whatever. [31:21.100 --> 31:22.340] You know, what's the weather today, right? [31:22.710 --> 31:25.040] Boom, they're on your phone and whatever else you've got on there. [31:26.220 --> 31:27.200] That was a kind of a thing. [31:27.300 --> 31:29.120] It was just a proof of concept to say it can be done. [31:29.760 --> 31:35.080] And it can be done, but not necessarily on anything that isn't on a stock phone yet. [31:35.880 --> 31:36.720] That's close to that. [31:37.150 --> 31:38.780] What can be done on a stock phone? [31:39.480 --> 31:40.480] This is the other one, right? [31:41.420 --> 31:42.300] The Eclipse Rootstrap? [31:42.520 --> 31:42.840] Yeah. [31:43.040 --> 31:44.020] An Eclipse Strap? [31:44.240 --> 31:46.340] Okay, this is a proof of concept done by John Oberheide. [31:46.460 --> 31:47.440] He's at cybersecurity now. [31:48.520 --> 31:59.480] He did research on how do I put together the pieces you'd need if you were trying to actually build your own botnet now and your own takeover phone and maintain control of the thing and partially rootkitting it. [32:00.740 --> 32:03.000] This app was initially Rootstrap. [32:03.120 --> 32:04.740] It was designed to, like, load on the phone. [32:04.740 --> 32:19.640] The original Rootstrap application is just a regular Android app with barely any GUI that downloads files from his control server that says, okay, we have actual ARM binaries that you can run on the phone, meaning shellcode, exploits. [32:19.840 --> 32:24.780] He had one exploit for a bug that affected Android phones before they patched it. [32:25.840 --> 32:30.560] I think 90% of phones are patched, so it's not really effective and he didn't actually release the code anywhere. [32:31.300 --> 32:33.900] But he rebuilt the thing so it actually downloads code. [32:34.260 --> 32:36.920] You can, of course, update that code because it's a downloader. [32:37.710 --> 32:41.000] The key is, who's going to download some boring application that says Rootstrap? [32:41.520 --> 32:45.460] So he did some minimal covering up and said, let's turn it into an application, a game or something or whatever. [32:45.680 --> 32:47.220] He said, let's make it a Twilight preview app. [32:47.820 --> 32:49.780] It was right before the Eclipse came out, right? [32:49.920 --> 32:52.360] So he said, oh, okay, that'll get people downloading, right? [32:52.440 --> 32:54.600] You'll notice the second window is a bunch of comments. [32:55.370 --> 33:00.900] But basically, the people who actually did download it, fans of the Eclipse, I'm guessing, who said, this is a horrible app. [33:00.900 --> 33:02.040] It has like one or two pictures. [33:02.480 --> 33:03.860] You know, like you grab... [33:03.860 --> 33:07.500] I'm pretty sure you grab it just from the trailer poster or something. [33:07.900 --> 33:08.220] Boom. [33:08.440 --> 33:09.160] Here's your app. [33:09.460 --> 33:09.800] Go. [33:10.740 --> 33:12.100] He's still got about 200 downloads. [33:12.320 --> 33:13.620] So, I mean, hey, it works. [33:13.800 --> 33:19.600] It's, once again, social engineering that actually targets the user instead of the system itself. [33:19.600 --> 33:28.460] And the point about this whole experiment was to say, you can get portions of what your infrastructure for your botnet on the phone already. [33:28.780 --> 33:29.580] So you gain control of the phone. [33:29.700 --> 33:31.020] You have some trusted software. [33:31.140 --> 33:31.540] It's on the phone. [33:31.640 --> 33:32.760] Let's need to solve whatever I want on it. [33:33.120 --> 33:34.240] And it was in the market. [33:34.460 --> 33:35.820] I think Google pulled the... [33:35.820 --> 33:36.920] Asked him to pull the app. [33:37.000 --> 33:37.560] He pulled the app. [33:37.700 --> 33:39.840] And then they used their remote uninstalled software. [33:39.940 --> 33:45.680] That's only for apps that are installed in the Android market to basically nuke the application. [33:45.680 --> 33:46.580] So you can't get any more. [33:46.880 --> 33:48.600] And if you had it installed, they took it off. [33:49.100 --> 33:49.820] Which is nice. [33:50.950 --> 33:55.700] But I think it was a few days until he did the talk at... [33:55.700 --> 33:56.080] I forget. [33:56.360 --> 33:57.860] It was RSI, I believe. [33:59.390 --> 33:59.720] Summercon. [33:59.800 --> 34:00.140] Summercon. [34:00.160 --> 34:00.400] That's right. [34:00.600 --> 34:03.020] Summercon, which was about a month or so ago. [34:03.500 --> 34:04.320] Maybe a little less. [34:05.360 --> 34:06.200] That was here too, right? [34:06.280 --> 34:06.440] New York? [34:07.140 --> 34:07.300] Yeah. [34:07.880 --> 34:08.940] So really recently, right? [34:10.220 --> 34:11.920] Until then, nobody knew. [34:12.440 --> 34:12.920] Do you want to download? [34:13.100 --> 34:13.940] I mean, that's a lot of things. [34:14.220 --> 34:16.100] But, of course, it wasn't a real target attack. [34:16.100 --> 34:21.600] And with phones, you can't really get the same range you can with a PC or Windows or whatnot. [34:22.300 --> 34:24.280] I mean, it's a thing like that. [34:25.980 --> 34:26.720] One second. [34:27.640 --> 34:28.900] A little lost where I am here. [34:32.870 --> 34:33.270] Okay. [34:35.590 --> 34:35.990] Yeah. [34:36.310 --> 34:36.710] Questions? [34:37.030 --> 34:37.410] Comments? [34:37.490 --> 34:39.330] That's pretty much all from my examples and whatnot. [34:39.430 --> 34:41.990] What can be done on the phone and what possibly could be done? [34:42.550 --> 34:44.510] Does anybody have any questions about any of these things? [34:44.570 --> 34:46.010] Or what's feasible? [34:51.650 --> 34:53.430] Can you talk about mitigation for a little bit? [34:53.630 --> 34:56.310] I have, you know, executives that have phones that concern me. [34:56.930 --> 34:57.670] Executives with phones? [34:57.970 --> 34:58.210] Okay. [34:58.270 --> 34:58.830] That's a good one. [34:59.170 --> 35:00.330] Are they using BlackBerrys? [35:01.330 --> 35:02.070] BlackBerrys, iPhones. [35:04.070 --> 35:04.330] Okay. [35:04.430 --> 35:05.390] Just in general mitigation. [35:06.530 --> 35:07.470] I mean, that's the thing. [35:07.550 --> 35:11.850] If you're using a smartphone like a BlackBerry or an iPhone or Android, three different things. [35:12.510 --> 35:13.810] BlackBerry has a lot of device controls. [35:13.970 --> 35:17.330] I haven't covered any of these spy words that have been created for BlackBerrys. [35:18.170 --> 35:19.890] Because it's really out of scope for this talk. [35:20.070 --> 35:27.730] But mitigation for BlackBerrys, if you have BlackBerry Enterprise Server, you can have your IT department lock down the device and control a whole lot of different aspects of the device. [35:27.730 --> 35:29.990] You're not really going to face more trouble with BlackBerry. [35:30.390 --> 35:32.590] Because you can really lock those things down. [35:34.230 --> 35:36.610] iPhone, mitigation, don't jailbreak it. [35:36.990 --> 35:38.610] I mean, really? [35:38.950 --> 35:43.230] There's not much you're going to be doing with a phone that needs to be jailbroken for the executive especially. [35:44.170 --> 35:46.050] But if they do, I can't help you there. [35:48.410 --> 35:53.390] Android, Android's a big market and it depends. [35:54.930 --> 35:56.330] Don't download Eclipse apps. [35:57.050 --> 35:57.530] You know? [35:57.650 --> 36:00.490] Don't download things that don't have enough reviews. [36:00.710 --> 36:02.430] I mean, similar things with the markets. [36:02.690 --> 36:05.050] I mean, there's not the whole... [36:06.430 --> 36:08.990] It's sort of the thing like, why do we need any protection at all? [36:09.070 --> 36:11.230] Why do we need things that protect us from anything? [36:11.430 --> 36:13.590] Because sometimes even good sense... [36:13.590 --> 36:14.710] It was right before the movie. [36:14.790 --> 36:15.810] How did we know it wasn't real? [36:16.310 --> 36:16.590] You know? [36:16.790 --> 36:17.730] Right before the movie. [36:18.390 --> 36:19.210] It came out... [36:19.210 --> 36:20.530] It's got to be a real app, right? [36:20.530 --> 36:22.370] I mean, some things you can't really do. [36:23.110 --> 36:23.670] It depends. [36:24.150 --> 36:24.890] I mean, other than... [36:25.210 --> 36:26.710] I'm not gonna tell you about products or anything. [36:26.870 --> 36:27.690] Don't talk about any of those. [36:28.430 --> 36:33.010] Other than security software, it's mainly what you do with the phone or how you deal with the phone. [36:33.350 --> 36:34.290] Don't do dangerous things. [36:34.670 --> 36:35.510] Don't download software. [36:35.590 --> 36:36.390] Don't download wares. [36:36.570 --> 36:39.310] Don't download things and places where you don't know where they came from. [36:39.470 --> 36:40.350] You don't know where the sources are. [36:41.190 --> 36:41.310] Yeah. [36:41.310 --> 36:43.350] Just the same ones you do on a PC. [36:44.550 --> 36:45.030] Next. [36:46.190 --> 36:54.230] You mentioned a lot of applications that almost got out or almost are, you know, in production and real stock OSs. [36:54.270 --> 36:56.430] Almost in the wild or something similar like that? [36:56.530 --> 36:56.670] Yeah. [36:56.950 --> 37:01.170] I'm familiar with Apple development just because... [37:01.170 --> 37:04.910] and they do a pretty thorough job of testing an app before it goes on the store. [37:04.910 --> 37:05.630] Mm-hmm. [37:05.890 --> 37:10.270] Have you done or have you seen analysis of apps that... [37:10.270 --> 37:16.450] or heard stories of apps that almost got there or been consulted about any of that work? [37:16.590 --> 37:18.290] Yeah, I did a talk about that... [37:18.290 --> 37:18.890] What was it? [37:19.410 --> 37:19.710] Sorry. [37:19.890 --> 37:22.710] Get Canceled West about spyware and things on the iPhone. [37:24.390 --> 37:29.450] Not necessarily botnets, but spyware is like a big problem on the iPhone. [37:29.910 --> 37:33.530] There are a bunch of online games that they take more information from you than necessary. [37:33.530 --> 37:36.690] They take your phone number, they take your... I'm sorry, is it 10? [37:36.910 --> 37:37.270] 15. [37:37.410 --> 37:38.110] 15, thank you. [37:38.590 --> 37:38.730] Sorry. [37:39.410 --> 37:40.530] They do different things. [37:42.670 --> 37:51.050] Sorry, on the iPhone, the online games and things like that, where you think you're getting something clean and they're taking personally identifiable information. [37:51.550 --> 37:53.310] In the U.S., maybe that's not such a big thing. [37:53.370 --> 37:54.710] Other places, that's important. [37:54.990 --> 37:57.870] You can't just take people's phone numbers without their permission without telling them. [37:58.750 --> 37:59.810] That's actually gotten out there. [37:59.890 --> 38:02.050] Those who have been there, there's a site, I forget what it's called exactly. [38:02.050 --> 38:04.810] I think it's iPhone Phone Home or something. [38:04.910 --> 38:05.610] Something similar to that. [38:05.690 --> 38:12.150] It's a blog and it has a listing and then a host file that tells you, avoid these apps or use this host file to make sure that the app doesn't phone home. [38:12.670 --> 38:13.890] Might be iPhone Phone Home. [38:14.250 --> 38:16.210] I forget the exact name of that in that place. [38:16.910 --> 38:17.190] But yeah. [38:18.370 --> 38:22.510] But actual rootkits and botnets, only what we've seen here were what I've presented here. [38:22.510 --> 38:29.870] There hasn't been anything that's gotten out there through the iPhone market app store process yet. [38:30.130 --> 38:33.830] But there could be many other privacy infringing applications out there. [38:33.970 --> 38:34.770] That's hard to detect. [38:37.050 --> 38:40.670] Have you seen any attacks on Mego or Mimo? [38:40.670 --> 38:44.730] On the Linux for Nokia and N900s? [38:45.170 --> 38:45.350] Yes. [38:45.650 --> 38:47.610] Remember the slide about the Rutgers University? [38:48.570 --> 38:56.910] That team is actually working on, or they're talking of, reporting all their work that they've pulled on the OpenMoco open platform towards the N900. [38:57.290 --> 39:05.890] There's even a distribution for the N900 for the Neopone sort of mobile backtrack software that has Aircrack, has a bunch of tools on it. [39:05.890 --> 39:10.030] But that distribution, it was originally on an OpenMoco phone. [39:10.330 --> 39:12.330] They're now porting it to the N900 also. [39:12.450 --> 39:16.330] And I think they're about to release it sometime this month before DEFCON, possibly next week. [39:17.110 --> 39:18.030] At least that's what they're claiming. [39:18.610 --> 39:26.250] But they've done all the work to put the drivers over to, I'm assuming, the base, the actual Mimo Linux. [39:26.610 --> 39:31.330] Mego is the combination of Linux Mobile and, I believe, Mimo together. [39:31.670 --> 39:33.070] I forget which Mobile Linux. [39:33.190 --> 39:34.550] There are actually quite a few Mobile Linux groups. [39:34.550 --> 39:35.770] This is, I think, the Intel one. [39:36.030 --> 39:40.590] Yeah, the Intel one with Nokia's version of this whole mix. [39:41.970 --> 39:42.130] Mobile. [39:42.350 --> 39:42.350] Mobile. [39:42.430 --> 39:42.530] Okay. [39:42.950 --> 39:44.390] See, there are quite a few. [39:45.090 --> 39:45.690] There's Limo. [39:45.830 --> 39:46.130] There's Mobile. [39:46.370 --> 39:47.190] There's a ton of them. [39:47.310 --> 39:47.650] You know what I mean? [39:47.730 --> 39:48.690] And they keep changing names. [39:49.290 --> 39:49.810] But yeah. [39:50.650 --> 39:52.170] You say that attacks on them, right? [39:54.690 --> 39:55.050] It's... [39:55.490 --> 39:57.950] Here's the thing about the rootkits and whatnot. [39:58.170 --> 39:59.510] The rootstrap technique. [40:00.310 --> 40:01.750] John Oberheide mentioned that, yes. [40:01.890 --> 40:02.030] Okay. [40:02.750 --> 40:04.330] We know there are a bunch of... [40:04.330 --> 40:06.070] By itself, it doesn't do anything by itself. [40:06.150 --> 40:07.450] He admits it doesn't do anything by itself. [40:07.590 --> 40:08.630] But it's Linux. [40:08.870 --> 40:14.130] Obviously, there are previous escalation exploits that may not have been patching the current kernel they're using on the phone. [40:14.130 --> 40:17.130] And he says mobile phones don't necessarily... [40:17.710 --> 40:25.610] Mobile carriers and mobile manufacturers don't necessarily upgrade the kernel as often as, say, Red Hat or Ubuntu or Debian or anybody. [40:25.970 --> 40:29.670] Any PC or server OS, right? [40:29.730 --> 40:31.610] They're not upgrading at the same time. [40:31.810 --> 40:32.730] I mean, at the same rate. [40:33.090 --> 40:35.970] So, you have the potential for holes in them. [40:36.450 --> 40:37.670] And people could be doing it. [40:37.750 --> 40:39.450] But anyone who's actually targeting them? [40:40.010 --> 40:40.810] Not really. [40:40.930 --> 40:41.410] It's actually... [40:41.410 --> 40:45.270] There aren't that many devices being sold in comparison to, say, your average iPhone. [40:45.590 --> 40:47.630] And they're selling millions of units of iPhones. [40:48.470 --> 40:50.250] An N900 or similar? [40:50.670 --> 40:51.330] Not that many. [40:51.410 --> 40:52.550] Not in the same range. [40:52.710 --> 40:54.230] It's not their biggest money maker for Nuki. [40:54.270 --> 40:55.850] It's not the largest number of devices they're selling. [40:57.890 --> 41:02.430] I was wondering about non-jailbroken iPhones. [41:02.790 --> 41:06.830] Because your talk seemed to imply that they were extremely secure. [41:06.830 --> 41:11.730] That basically, to attack them, you would have to go through Apple's App Store. [41:12.270 --> 41:13.610] And they'd probably pull you. [41:13.790 --> 41:17.930] But do you expect to see people finding more vulnerabilities? [41:18.390 --> 41:21.770] A certain class of things are secure in the App Store. [41:21.850 --> 41:24.270] That's the whole point of their API restrictions. [41:24.590 --> 41:27.910] To not allow you to access certain things like, would it allow you to put together a rootkit? [41:28.510 --> 41:29.490] No, probably not. [41:29.590 --> 41:30.910] Not to the App Store. [41:31.110 --> 41:33.790] But things like stealing information, like the keyboard cache. [41:33.930 --> 41:35.610] It's accessible from public APIs, right? [41:36.170 --> 41:37.970] I mean, it has all your passwords in it. [41:38.110 --> 41:40.710] So, I mean, they can get to you still. [41:40.870 --> 41:43.790] But actual something that will let them completely, totally own your phone? [41:44.550 --> 41:46.130] Not necessarily from the App Store. [41:47.330 --> 41:50.290] Unless you can find a vulnerability on the phone, which we've seen in the past. [41:51.190 --> 41:54.810] Like attacking the, I think it's the comm center on the iPhone. [41:55.010 --> 41:55.830] You can target that. [41:56.610 --> 41:59.630] Colin Mellner and Charlie Miller did that at Defcon last year. [41:59.750 --> 42:00.110] Oh, no, sorry. [42:00.270 --> 42:03.030] Black App last year, where they fuzzed... [42:03.030 --> 42:04.010] Is it... [42:04.010 --> 42:04.130] Sorry? [42:05.270 --> 42:06.030] Sorry, how much time? [42:06.850 --> 42:07.410] Oh, sorry. [42:07.470 --> 42:07.670] Thank you. [42:08.130 --> 42:08.210] Okay. [42:08.950 --> 42:10.750] Right, so they fuzzed both of them. [42:10.850 --> 42:13.470] They took different techniques of fuzzing the comm center. [42:13.870 --> 42:16.330] Basically, what they ended up with was a bunch of vulnerabilities. [42:16.530 --> 42:19.510] I think one real one that did a DOS on the phone. [42:19.510 --> 42:26.650] But assuming you kept that up and not just did it just so you could get bugs to show at a conference. [42:26.870 --> 42:28.290] Because really, they don't have all the time in the world. [42:28.350 --> 42:30.630] They have to bang for the buck, right, for a security researcher, right? [42:31.290 --> 42:36.590] But for a dedicated attacker who has time and hands, possibly they could find something. [42:36.750 --> 42:38.390] But that's completely theoretical. [42:39.570 --> 42:42.750] It's not like a, oh, no, we're going to die thing, no. [42:46.030 --> 42:46.870] I have two questions. [42:47.010 --> 42:51.750] One of them was in the slide you had where you guys were collecting a lot of malware that was on phones. [42:52.150 --> 42:53.630] Like, how do you generally find that? [42:53.730 --> 42:57.470] I mean, I feel like it would be really not obvious that your phone would have malware on it. [42:57.870 --> 42:58.430] I don't know. [42:58.590 --> 42:58.710] Well, yeah. [42:58.850 --> 43:00.490] See, that's why Symbian is that large. [43:01.510 --> 43:02.910] It's mainly installable software. [43:03.050 --> 43:04.190] People see, okay, stuff's up. [43:04.370 --> 43:04.910] It's not quite... [43:04.910 --> 43:05.590] Things aren't quite working. [43:05.710 --> 43:06.230] Something's running. [43:07.530 --> 43:09.190] Because Symbian is actually a pretty good platform. [43:09.330 --> 43:12.730] It came originally from PalmTops handles, you know, like the Scion series. [43:13.150 --> 43:13.990] That was the... [43:13.990 --> 43:15.090] It was the opposite for that. [43:15.170 --> 43:18.050] There was a community that said, okay, we have a bunch of tools to handle a computer. [43:18.250 --> 43:19.130] We have task managers. [43:19.130 --> 43:20.370] We have process viewers. [43:20.590 --> 43:20.670] Okay. [43:20.930 --> 43:21.930] They saw what was running. [43:22.070 --> 43:23.070] They saw things aren't working well. [43:23.690 --> 43:28.810] A lot of these initial software things that weren't commonware, that weren't trying to evade detection, they showed up. [43:28.990 --> 43:31.070] So, I mean, a lot of these ones, they show up. [43:31.150 --> 43:31.890] They weren't trying very hard. [43:32.090 --> 43:34.990] And the other ones, like commonware, he didn't just reach in a while. [43:35.010 --> 43:38.270] He sent it to AV companies and he made sure people noticed it. [43:38.350 --> 43:42.470] I mean, the guys are very good in that original mobile cycle and all that. [43:43.350 --> 43:46.590] They'd like people to know that they've done something because they put a lot of work into it. [43:46.930 --> 43:54.170] But the other target attacks, like the Sympian one, the Chinese one, the Sexy Worm one, that looks a lot more targeted. [43:54.250 --> 43:55.650] It looks like they don't want anyone to know at all. [43:55.770 --> 43:58.690] That one would not have been caught unless it was submitted to people. [43:58.950 --> 44:00.110] Meaning customers submitted anything. [44:00.230 --> 44:01.270] Something's very wrong with that phone. [44:01.310 --> 44:01.830] Take a look at it. [44:02.170 --> 44:02.650] That kind of thing. [44:03.110 --> 44:03.330] All right. [44:03.450 --> 44:12.750] And the other one was, is there any, I mean, being from McAfee, I guess you're probably the right person to ask, but is there any development towards like antivirus type of host-based firewall? [44:12.990 --> 44:14.150] I mean, things like that for a phone? [44:14.930 --> 44:16.070] That was another talk. [44:16.990 --> 44:17.390] Yeah. [44:19.310 --> 44:20.670] It's possible to do it on the phone. [44:20.770 --> 44:25.970] We do things on the various platforms, like once again Sympian because it's the largest. [44:27.050 --> 44:30.690] Windows Mobile, because also they had a big, big high profile there. [44:32.050 --> 44:38.730] And then there are things like for the iPhone, which I don't think anyone has done for a proper approved one from Apple for an iPhone because they're not actually releasing the... [44:38.730 --> 44:39.750] Forget rootkits. [44:39.830 --> 44:43.290] We don't have security APIs for that to allow us to do it without doing what it is. [44:43.750 --> 44:45.930] But yeah, I mean, there are products coming out all the time. [44:46.190 --> 44:47.250] And it's possible. [44:47.470 --> 44:48.330] I'm not really talking about that. [44:48.610 --> 44:48.730] Yeah. [44:49.630 --> 44:53.710] Oh, I'm just wondering, since you work for McAfee, like how big the system is for the honeypots? [44:53.810 --> 44:54.470] Do you run for the phones? [44:55.190 --> 44:55.390] Nah. [44:56.770 --> 44:58.510] That comes under the thing that we don't actually talk about. [44:58.590 --> 45:00.750] I mean, if you know how big a honeypot is, no one looks for it. [45:00.750 --> 45:01.410] Yeah. [45:01.490 --> 45:03.370] No, we don't actually do the same kind of thing like that. [45:03.710 --> 45:06.090] Because with the mobile device, it's a little harder. [45:07.390 --> 45:10.830] A honeypot makes sense on a PC because you have so much disk space, you have so much memory. [45:11.210 --> 45:17.210] You can just put out an entire machine to it or a VM or whatever on their phone or even a user's phone. [45:17.350 --> 45:19.530] I mean, people already complain about antivirus on a PC. [45:19.690 --> 45:21.050] You want all that on your phone? [45:21.690 --> 45:24.590] I mean, all the AV companies are doing that on mobile devices. [45:24.730 --> 45:28.950] They have to rewrite their stuff to work from the ground up on a limited use device. [45:29.130 --> 45:31.770] No one is saying, okay, we're going to take whatever we have on the PC and put it right on there. [45:31.990 --> 45:32.670] No one's saying that. [45:32.910 --> 45:33.050] Nah. [45:33.350 --> 45:33.570] Yeah. [45:35.850 --> 45:36.210] Sorry. [45:36.290 --> 45:42.410] Don't people put simulators for the phones in the IP space of the carrier and use them as honeypots? [45:43.030 --> 45:43.390] Okay. [45:43.450 --> 45:44.610] You mean like a full simulator? [45:44.870 --> 45:45.170] Yeah. [45:45.330 --> 45:51.490] I mean, the existing simulator that was written by the manufacturer, you can run it on non-mobile hardware. [45:52.370 --> 45:52.810] Yeah. [45:52.910 --> 45:53.950] Or something similar to that. [45:54.110 --> 45:57.990] I think there's a company that actually lets you handle the actual device. [45:58.090 --> 45:58.730] And here's what... [45:58.730 --> 45:59.050] Really? [45:59.150 --> 46:02.870] There aren't that many actual manufactured type of simulators. [46:03.070 --> 46:05.270] I mean, a full emulator. [46:05.390 --> 46:06.350] Not really a simulator, you mean, right? [46:06.510 --> 46:08.070] And aren't there things like little... [46:08.070 --> 46:15.810] You know, Little Snitch, for example, for the Mac, tells you when you're opening a connection to an unexpected location, some app is doing that. [46:16.490 --> 46:22.710] And, you know, it would be nice to have that for the mobile platform, although the UI might be confusing to the user. [46:22.710 --> 46:25.530] Right, but I mean, something like that is running all the time to tell you what's going on. [46:25.930 --> 46:27.990] It just has to trap outbound connections. [46:28.270 --> 46:28.530] Right. [46:28.750 --> 46:30.230] And when apps start phoning home... [46:30.230 --> 46:33.230] But I mean, as a separate product, I mean, it would be... [46:33.230 --> 46:35.470] They can account, what does it work with other products we have on the phone? [46:35.470 --> 46:41.990] Do the carriers look for, since they control those networks, do they look for hygiene on the part of their clients? [46:42.150 --> 46:46.150] And when they see bot activity, they start telling people about it? [46:46.770 --> 46:48.330] They've monitored their network very closely. [46:48.330 --> 46:52.170] So they know when someone's doing something, you know, for a tax thing, they're telecos, right? [46:52.430 --> 46:52.570] Yeah. [46:52.630 --> 46:53.710] They know what's going on in their network. [46:53.830 --> 46:55.170] But I don't think they actually... [46:55.170 --> 46:59.710] I don't think we ever received like a big warning, except for something like Convoy, which actually got released on the network. [47:00.170 --> 47:01.650] And so we know about that. [47:01.650 --> 47:06.550] But in general, they don't like to advertise that kind of thing. [47:06.650 --> 47:12.870] I mean, they're very close, tied up close, you know, they don't talk about those things outside of the telco, about those things. [47:12.970 --> 47:14.670] I mean, the telco security department probably knows what's going on. [47:15.010 --> 47:18.510] Talked to some guy at Sprint at DEFCON, and they even knew what the hell was going on, you know? [47:18.590 --> 47:20.890] But, you know, they're not telling anyone else, you know. [47:21.050 --> 47:22.970] And then they'll talk to people who've actually attacked a network. [47:23.010 --> 47:23.830] Okay, oh yeah, we'll talk to you. [47:23.970 --> 47:27.290] But they won't tell you someone's attacked a network and say, what do we do about this? [47:28.010 --> 47:28.190] Yeah. [47:31.090 --> 47:34.770] As far as the honeypots, how about Android for x86? [47:35.230 --> 47:36.030] Have you played with that? [47:37.410 --> 47:41.410] Android for x86 or Android for the... that's the port to x86, right? [47:42.010 --> 47:43.470] Yes, there's a port to... [47:43.470 --> 47:47.710] Or the QMU emulator that runs on various platform... well, x86 mainly. [47:48.590 --> 47:49.070] Both. [47:49.810 --> 47:50.650] Two different things. [47:50.650 --> 47:58.110] One is QMU running in ARM, so it is the phone pretty much as... well, running on a PC, so it's probably faster than an actual device. [47:58.850 --> 48:00.630] And the other one would be a port to x86. [48:00.710 --> 48:01.510] I haven't seen that yet. [48:01.650 --> 48:04.370] I know I've heard of it, but I haven't actually looked in depth at that. [48:04.830 --> 48:07.630] I think they're saying that's for, I think, pads. [48:07.990 --> 48:09.530] Actual Android pads, not actual phones. [48:09.530 --> 48:11.090] So, not as much. [48:11.750 --> 48:12.850] And it does help. [48:12.970 --> 48:13.950] I mean, having emulator... [48:13.950 --> 48:14.730] We don't actually... [48:14.730 --> 48:15.550] Haven't had it before. [48:15.710 --> 48:21.430] Like with Symbian, I think until maybe two or three years ago, we didn't actually have debuggers on the phone until then. [48:21.610 --> 48:22.530] There wasn't support for it. [48:22.590 --> 48:23.690] Then they had the... [48:23.690 --> 48:28.950] I think Nokia purchased Code Warrior, and then they ported the debug step, and then we had actual debuggers on the phone. [48:29.370 --> 48:30.110] It was a lot of... [48:30.110 --> 48:33.530] You had to actually test on device and see what's it doing in a contained environment. [48:33.610 --> 48:35.210] You couldn't say, okay, that's just dope. [48:35.210 --> 48:35.970] You know? [48:36.130 --> 48:36.950] Look what's on the phone. [48:37.750 --> 48:38.390] You couldn't. [48:38.610 --> 48:39.290] Until recently. [48:39.490 --> 48:39.570] You know? [48:40.110 --> 48:41.930] We didn't have the same tools that they had if they were manufactured. [48:42.150 --> 48:45.250] Manufacturing wasn't interested in testing security, because they had to get the product out the door. [48:45.690 --> 48:49.370] They can't do the same kind of fussing or whatnot on product as they can on anything else. [48:49.590 --> 48:50.450] They don't have the same window. [48:51.170 --> 48:51.850] I mean, yeah. [48:52.210 --> 48:55.830] Even T-Mobile, when the G1 first came out, I think they released a full patch. [48:55.910 --> 48:57.930] It took like 50 megabytes, like one week. [48:58.230 --> 49:00.870] And then they had to do one the week after, so they did it over the air. [49:01.290 --> 49:02.570] I mean, just to patch it back. [49:02.650 --> 49:03.390] I think it was Charlie Miller's bug. [49:03.390 --> 49:04.610] The one that did the... [49:04.610 --> 49:05.870] I think it was the browser bug. [49:06.570 --> 49:09.610] And so, I mean, it's not that easy for phone companies to do the same thing. [49:10.110 --> 49:11.510] It needs to be done pretty much from... [49:11.510 --> 49:13.630] In fact, you have to put whatever you're going to put in when you build a device. [49:13.970 --> 49:15.730] And after that, it's iffy. [49:21.550 --> 49:35.550] So, I'm curious about two related things now that we've seen a lot on the PCs, which are there's lots of man-in-the-middle attacks, spoofing of trusted sources, and at the same time, web browser vulnerabilities. [49:36.310 --> 49:52.650] And I'm curious as to whether this type of thing could be an alternate method of installing malware on the phone, basically by bypassing the App Store altogether, either breaking part of the browser, which lets you execute arbitrary code or spoofing. [49:52.650 --> 49:54.790] That was actually done on iPhones earlier. [49:55.390 --> 49:58.210] I think it was version one or one point something or whatever. [49:58.550 --> 49:59.070] Maybe it was versions. [49:59.490 --> 50:00.150] It might have been two. [50:00.370 --> 50:01.650] I forget exactly what it is. [50:02.190 --> 50:04.210] Like the app tab vulnerability, this was a... [50:04.210 --> 50:06.030] I think it was an image file. [50:06.450 --> 50:07.410] I can't remember the extension at the moment. [50:08.010 --> 50:10.170] There was a vulnerability in the library that handles the image file. [50:10.430 --> 50:14.810] And basically, you visit the website in Safari and click the button and boom. [50:14.950 --> 50:15.610] You're like... [50:15.610 --> 50:17.630] They loaded the jailbreak and they loaded the files. [50:17.710 --> 50:18.510] They loaded the city on there. [50:18.910 --> 50:21.670] So, it's theoretically possible, but it's getting harder to do. [50:21.670 --> 50:29.030] If you follow the iPhone jailbreaking team and the dev team and the jailbreakers, they follow through and they look for vulnerabilities all the time. [50:29.170 --> 50:31.530] And they do find vulnerabilities that allow them to do the jailbreak. [50:31.750 --> 50:34.190] But it's not being exploited as common. [50:34.390 --> 50:39.030] The people who actually know enough to do that, generally aren't writing exploits widespread. [50:39.270 --> 50:42.110] I mean, also because the work... [50:43.310 --> 50:45.170] It's not as easy because the window's smaller. [50:45.430 --> 50:50.150] As soon as the jailbreakers release the jailbreak, Apple's going to find out what went down and how do we patch that. [50:50.150 --> 50:51.690] And you have a new game start. [50:52.170 --> 50:53.950] So, you could kind of do it. [50:54.030 --> 50:55.570] And it's technically possible. [50:55.810 --> 50:57.890] But we're not seeing it happen a lot. [50:58.570 --> 51:01.650] I mean, similar to the whole thing with the iPhone and... [51:02.810 --> 51:03.770] Okay, thank you. [51:04.090 --> 51:04.510] Okay, sorry. [51:04.570 --> 51:05.090] Last minute. [51:06.110 --> 51:08.810] We're not seeing it as much on the iPhone. [51:08.810 --> 51:11.850] Because, I mean, the closest thing was what happened in the Netherlands. [51:12.550 --> 51:15.330] And then the iKey or... [51:16.070 --> 51:16.750] Sorry, what was it? [51:16.890 --> 51:17.450] R-Roll-C. [51:17.610 --> 51:20.590] That attempts to break the jailbreaking phones and whatnot. [51:20.690 --> 51:21.150] Jailbreaking phones. [51:21.450 --> 51:24.230] But nothing actually goes after a phone with, say, unknown vulnerability. [51:24.430 --> 51:25.690] Because they don't really last as long. [51:25.890 --> 51:28.330] And I'm guessing it would have to be a very targeted attack. [51:28.430 --> 51:30.150] Not something you blast out there. [51:30.250 --> 51:30.750] Because you lose it. [51:31.290 --> 51:32.730] I mean, it's hard to get it. [51:32.810 --> 51:34.690] And then it's even harder to say, okay, I'm going to use it. [51:35.430 --> 51:36.630] It takes a lot more resources. [51:36.630 --> 51:40.270] I'm not seeing a wide switch at a PC level kind of thing happening. [51:41.010 --> 51:41.070] There. [51:41.790 --> 51:41.870] Yeah. [51:42.450 --> 51:43.090] But it's feasible. [51:46.070 --> 51:46.590] Sorry. [51:46.910 --> 51:47.570] Any more questions? [51:48.610 --> 51:49.130] No? [51:50.770 --> 51:51.290] Okay. [51:51.630 --> 51:51.890] Thank you. [51:51.970 --> 51:52.510] Thank you very much. [52:08.660 --> 52:09.800] Thank you very much.