[01:02.600 --> 01:03.820] All right, everyone. [01:04.120 --> 01:05.340] Welcome to our next talk. [01:06.860 --> 01:09.310] Just a couple quick notes before we jump in the next talk. [01:09.720 --> 01:11.160] There was a schedule change. [01:11.460 --> 01:18.460] There was a talk scheduled at 10 o'clock tonight on social stenography that has been moved to tomorrow morning at 10 a.m. [01:19.530 --> 01:23.420] In its place, there will be a talk called Medical Advice to Security and Privacy Issues. [01:23.480 --> 01:25.240] He's not dead, Jim, not really. [01:25.560 --> 01:27.780] So that talk will be here at 10 p.m. tonight. [01:28.300 --> 01:29.820] Please come and see it. [01:29.880 --> 01:30.420] It would be great. [01:31.820 --> 01:33.420] A couple other notes. [01:33.680 --> 01:35.520] Thank you for wearing your mask throughout the show. [01:35.520 --> 01:36.660] We really appreciate it. [01:36.880 --> 01:43.080] It really helps us keep with our commitment to preserving our health and our sanity. [01:45.560 --> 01:47.120] Hackers Got Talent is tonight. [01:47.600 --> 01:50.280] So if you are interested, please go in. [01:50.400 --> 01:51.540] You don't need to sign up in advance. [01:51.740 --> 01:53.960] Just walk up and you can go in and participate. [01:55.720 --> 01:59.260] Lastly, workshops definitely need more helpers for today and for tomorrow. [01:59.430 --> 02:10.430] So if you're interested in being a volunteer and helping out in workshops, please go either to the info desk or try and find Mitch either through the Matrix Chat channel or find him walking around in person. [02:11.640 --> 02:18.840] Lastly, please mute your phone during the talk because the audio equipment is very sensitive and we want to make sure that we don't interrupt the talk. [02:19.320 --> 02:26.060] Our next talk is on the ransomware protection full of holes from Soya Aoyama. [02:26.340 --> 02:28.300] So with that, we'll pass you on to Soya. [02:28.500 --> 02:28.740] Enjoy. [02:39.960 --> 02:41.200] You're alive right now. [02:45.110 --> 02:46.130] You can go ahead. [02:57.920 --> 02:59.080] Soya Aoyama. [02:59.080 --> 02:59.080] Hello. [02:59.980 --> 03:11.460] I'm Soya Aoyama, Fujitsu System Integration Laboratory Limited and a founder and organizer of USAID Tokyo. [03:13.160 --> 03:22.780] Unfortunately, I could not go to New York because my boss did not allow me to travel. [03:22.780 --> 03:29.120] Now, it's 5 a.m. [03:29.580 --> 03:33.280] in Tokyo, so I'm very sleepy. [03:35.180 --> 03:35.860] Okay. [03:37.780 --> 03:46.060] Today, I will give a presentation entitled The Lansomware Protection Full of Horses. [03:52.560 --> 03:55.980] May 12, 2017. [03:55.980 --> 03:58.260] Do you remember? [04:01.950 --> 04:02.650] Yes. [04:03.290 --> 04:07.030] It's the Day of Cyber Attack by WannaCry. [04:08.870 --> 04:14.610] WannaCry caused tremendous damage all of the world. [04:20.150 --> 04:27.310] Microsoft has given one answer to ransomware represented by WannaCry. [04:33.910 --> 04:46.130] Microsoft has added a ransomware protection feature in the Windows 10 All Creators Update of the 2017 release. [04:48.070 --> 04:56.370] The new feature helps stop ransomware from accessing important files in real time. [04:56.370 --> 05:01.390] Even if NAMM somewhere infects the computer. [05:03.700 --> 05:13.400] When the feature enables its protect folder, allowing only authorized apps to access files. [05:19.970 --> 05:22.210] The foundation of Windows 10 All Creators. [05:22.210 --> 05:25.830] The foundation of Windows ransomware protection is controlled folder access. [05:27.830 --> 05:37.340] And consists of protected folders and allow an absolute control folder access. [05:38.920 --> 05:45.840] Note that controlled folder access is disabled by default. [05:47.780 --> 05:52.220] You need administrator privilege to enable it. [05:58.430 --> 06:07.330] Protected folders are folders that protect your files from being encrypted by ransomware. [06:08.850 --> 06:13.470] Here, you can add the folders you want to protect. [06:18.670 --> 06:29.780] However, the default protected folders such as documents or pictures are listed, even if you don't specify them. [06:35.250 --> 06:42.610] Allow an absolute control folder access are apps that can access protected folders. [06:42.610 --> 06:58.400] It says that apps determined by Microsoft as friendly are always allowed, but they are not listed by default. [07:03.940 --> 07:09.800] Unfortunately, Microsoft's ransomware protection is full of holes. [07:09.800 --> 07:17.240] So, many researchers are researching ways to bypass ransomware protection. [07:18.900 --> 07:27.040] This is the technique to exploit the inclusion of Office apps in the quietlist. [07:27.700 --> 07:34.380] And bypass control folder access using Office OLE objects. [07:39.560 --> 07:43.820] This is the technique to bypass control folder access using Office OLE objects. [07:43.820 --> 07:51.160] It says that writing the encrypted data from memory to a new file. [07:51.960 --> 07:58.900] And then using the rename code to replace the original file. [08:05.030 --> 08:20.650] This is the technique to bypass control folder access that takes advantage of the fact that security features are disabled when Windows when Windows start in safe mode. [08:27.070 --> 08:35.330] And my research, a technique to bypass control folder access using DLL injection. [08:37.070 --> 08:40.270] This is explained in detail. [08:46.180 --> 08:59.020] In 2018, when I was researching on ransomware protection, I found that File Explorer has access to protected folders. [09:03.780 --> 09:14.620] I used the computer object model hijacking to inject a Maisha's DLL into File Explorer. [09:16.620 --> 09:36.880] Because COM objects are managed in the registry, they can be hijacked by editing the registry to reference Maisha's payloads rather than legitimate COM objects. [09:41.550 --> 09:52.860] And the context menu handlers include a list of shell extensions used by File Explorer. [09:54.400 --> 10:01.200] I focused on this GUID in that list. [10:05.150 --> 10:17.170] If you search for this GUID in the registry, you will find it under CLSID. [10:18.650 --> 10:27.270] So this GUID is the CLSID that identifies the COM object. [10:29.350 --> 10:37.970] And the default value for MPROC server 32 is shell32.dll. [10:40.270 --> 10:50.910] If you can change this to Maisha's DLL, you can inject it into File Explorer. [10:50.910 --> 10:57.230] But you cannot change this directory. [10:58.370 --> 11:05.050] Because it's managed view of HKEYClassesRoot. [11:10.230 --> 11:26.930] As described in MSDN, the managed view of HKEYClassesRoot displays the managed value HKEYLocalMachine and HKEYCurrentUser. [11:27.950 --> 11:37.250] And if both have value, HKEYCurrentUser will take precedence. [11:43.060 --> 11:55.500] In the case of this CLSID, there is a value in HKEYLocalMachine, but not in HKEYCurrentUser. [11:57.100 --> 12:07.180] So, if you add the value to HKEYCurrentUser, you can change the value of HKEYClassesRoot. [12:13.580 --> 12:23.540] Write a command in a batch file to add the path of the Maisha's DLL to HKEYCurrentUser. [12:25.640 --> 12:30.260] The Start File Explorer, it will load the Maisha's DLL. [12:32.120 --> 12:41.220] The Maisha's DLL runs on the File Explorer process, so it can encrypt protected files. [12:41.220 --> 12:48.870] This completes the ransomware POC. [12:54.750 --> 13:13.490] Of course, I reported this research result to Microsoft, but they told me that this is not security vulnerability for following reasons. [13:18.500 --> 13:29.140] Precedents are predicated of the attacker having login access to the target's account already. [13:32.350 --> 13:42.210] Since you are only able to write to HKCU, you will not be able to affect other users. [13:45.220 --> 13:54.140] The author does not appear to be an escalation of privileges. [13:55.940 --> 13:57.020] And finally, [14:00.510 --> 14:09.150] it would appear that the attacker would not gain anything from this attack. [14:10.440 --> 14:12.680] Huh? [14:14.200 --> 14:19.180] The attacker would gain ransom from this attack. [14:21.280 --> 14:28.320] So, I have presented this research at several conferences. [14:32.750 --> 14:36.830] This is my previous research. [14:44.550 --> 15:01.650] Well, a Forbes article in 2021 introduced Windows 10 ransomware protection as effective in protecting against ransomware. [15:11.470 --> 15:20.370] As I thought my POC was still valid and could easily be encrypted. [15:22.150 --> 15:29.030] But just to be sure, I ran my POC on the latest Windows. [15:51.490 --> 15:55.030] Here is a video of the POC. [15:55.340 --> 15:59.790] I mentioned earlier running on Windows 11. [16:03.050 --> 16:11.350] Here, the image of the Echina is pre-saved in the iPictures folder. [16:13.010 --> 16:18.510] Next, open the ransomware protection setting screen. [16:27.670 --> 16:32.410] And enable control folder access. [16:39.400 --> 16:46.220] Learns patch files that have been successfully encrypted in the past. [16:53.580 --> 17:03.760] The program was blocked and the Echina is safe. [17:10.360 --> 17:24.180] Finally, a check of the block history shows that the control folder access protected the picture folder from the file explorer. [17:38.200 --> 17:45.240] As you can see, my previous exploitation is now no longer valid. [17:46.740 --> 17:56.520] Microsoft said, my report is not vulnerability, but they had secretly fixed it. [17:58.380 --> 18:09.200] I was so frustrated that I researched if there were any other holes in the ransomware protection. [18:17.510 --> 18:20.210] I checked the control folder access registry. [18:20.830 --> 18:30.110] And the list was empty for both hallowed applications and protected folders. [18:33.850 --> 18:48.710] The default protected folders such as documents and pictures, which we discussed in the first section, were not in protected folders. [18:52.420 --> 18:55.160] The default protected folders. [18:55.220 --> 18:57.620] The default protected folder is in another registry. [18:58.200 --> 19:01.940] And is in HKE current user. [19:03.180 --> 19:11.040] This means that folders protected by default can be changed with user privileges. [19:17.040 --> 19:25.980] When you actually check the property of picture folder, it says you can change. [19:27.160 --> 19:35.800] A good idea, but a bad idea for Microsoft, just pops into my head. [19:37.100 --> 19:45.180] What happens if you change the location of picture folder? [19:50.420 --> 19:52.920] Before I change the folder. [19:53.720 --> 19:58.800] Before I change the folder, files are protected and cannot be encrypted. [20:05.300 --> 20:17.920] But by change the folder, files in the original folder are not longer protected and should be able to be encrypted. [20:23.970 --> 20:26.910] I actually tried it. [20:46.150 --> 20:48.930] To execute a new batch file. [20:49.070 --> 20:49.190] Execute a new batch file. [20:51.870 --> 20:58.130] This time, reboot the system after changing the user folder. [20:59.530 --> 21:09.710] This is because the system needs a reboot to recognize the changes user folder. [21:11.290 --> 21:17.930] But rebooting takes a long time. [21:20.280 --> 21:22.200] And I hate it. [21:27.430 --> 21:29.330] A little bit more. [21:37.430 --> 21:42.350] Unfortunately, Microsoft does not rotate the Echina. [21:46.800 --> 21:51.380] Check the block history as before. [22:02.800 --> 22:07.840] There's nothing in the block history. [22:15.340 --> 22:20.540] Yes, I outfoxed Microsoft again. [22:21.760 --> 22:26.940] Microsoft missed simple things like this. [22:30.090 --> 22:31.210] Well... [22:31.210 --> 22:32.770] Ah, sorry. [22:34.390 --> 22:42.270] Well, don't you want to know Microsoft's reaction to this binary preview report? [22:49.420 --> 22:50.980] What a surprise. [22:51.580 --> 22:55.840] This time, it's just this one phrase. [22:58.100 --> 23:04.980] Because control folder access is a defense in-depth security feature. [23:07.260 --> 23:13.700] We cannot accept Microsoft to deal with the last web production issue. [23:15.440 --> 23:21.540] We need to inform many people about this issue. [23:21.540 --> 23:28.160] So, I created a POC that looks even more dangerous. [23:35.500 --> 23:42.440] I'm using the component object model hijacking method again. [23:43.240 --> 23:47.100] For injecting DLL into File Explorer. [23:49.020 --> 23:56.360] Actually, component object model hijacking can specify the network path. [23:57.460 --> 24:12.160] In other words, if you can write to the registry by exploiting any vulnerability, you can encrypt the file without sending DLL to the target. [24:21.530 --> 24:34.330] I used the CV 2018-3035 command injection vulnerability in this POC. [24:35.250 --> 24:41.150] This is the vulnerability about Apache Tika server. [25:04.980 --> 25:07.860] Now, let me show you. [25:11.490 --> 25:15.390] The ECNA is safe. [25:28.950 --> 25:34.210] Open the ransomware protection settings screen and [25:42.240 --> 25:46.180] enable the control folder access. [25:58.830 --> 26:02.990] Check the IP address and [26:13.030 --> 26:18.430] use it to execute the Tika server. [26:27.530 --> 26:30.230] From here. [26:31.150 --> 26:31.790] From here. [26:31.790 --> 26:32.390] The attacker. [26:34.690 --> 26:35.490] Curly to attack. [26:36.330 --> 26:37.110] The target. [26:40.750 --> 26:43.930] The measures DLL is on Curly. [26:51.900 --> 27:00.000] I created a Samba user using EDAD edit. [27:01.880 --> 27:06.320] And restart Samba already complete. [27:07.300 --> 27:08.460] Yeah. [27:14.250 --> 27:28.890] I created a shell that executes the Python scripts downloaded from ExplodeDB with arguments. [27:31.860 --> 27:42.000] The argument is a command to be executed on the target, which is a change and execute multiple times. [27:58.120 --> 28:03.680] Unfortunately, Microsoft could not protect the ECNA. [28:15.630 --> 28:16.310] Yes. [28:17.190 --> 28:21.150] I brilliantly encrypted files remotely. [28:22.630 --> 28:27.170] Will Microsoft secretly fix it again? [28:27.950 --> 28:30.090] Probably, yes. [28:30.090 --> 28:30.190] Yes. [28:38.630 --> 28:40.230] In summary. [28:41.510 --> 28:54.950] As you can see this time, I could encrypt the user data in a very easy and very useless way. [28:56.290 --> 29:05.390] It is so simple that anyone can easily imitate it. [29:05.790 --> 29:11.530] But please never create ransomware using this method. [29:14.080 --> 29:22.340] I think backup is the only way to protect your data from ransomware. [29:24.280 --> 29:30.500] I suggest that you always have a backup of your data. [29:36.460 --> 29:37.100] Okay. [29:37.420 --> 29:39.300] My presentation is over. [29:40.340 --> 29:41.140] Thank you. [29:47.460 --> 29:48.240] All right. [29:48.400 --> 29:49.380] Thank you so much, Soya. [29:49.720 --> 29:51.720] This is a chance for him to ask any questions. [29:51.720 --> 29:55.120] He can't directly hear your questions, but we can either have you... [29:55.120 --> 29:56.200] I can walk up to the mic. [29:56.360 --> 30:00.640] We can bring the mic around if anyone has a question, or you can relate to me and I'll relay it to him. [30:12.310 --> 30:15.830] So the question, Soya, is what was Microsoft's reaction... [30:16.330 --> 30:21.690] Or what was your reaction back to Microsoft from the email you received saying it wasn't a problem? [30:32.040 --> 30:33.520] Did you hear the question, Soya? [30:33.520 --> 30:35.700] Did [30:40.870 --> 30:41.510] you hear the question? [30:58.620 --> 30:58.760] Did you hear the question? [31:00.080 --> 31:01.480] Did you hear the question? [31:01.480 --> 31:05.560] So, Microsoft says, [31:12.980 --> 31:25.790] Microsoft is the same answer. [31:29.990 --> 31:31.550] Of course. [31:31.550 --> 31:32.970] Any other questions? [31:39.160 --> 31:39.820] All right. [31:39.980 --> 31:41.540] Well, thank you again for the talk, Soya. [31:41.620 --> 31:42.000] It was fascinating. [31:42.640 --> 31:44.420] And thank you, audience, for participating. [31:45.840 --> 31:49.400] And please come back for our next talk at the top of the hour. [31:49.640 --> 31:49.920] Right... [31:49.920 --> 31:51.040] What is our next one? [31:52.460 --> 31:56.440] Right to repair, fixing the DMCA, and legalizing tinkering. [31:56.440 --> 31:56.460] I have a .. this is what is the question? [31:56.460 --> 31:56.500] This is 95. [31:56.560 --> 31:57.460] It's the same...