sábado, 2 de maio de 2020

Ep 24: The State Of The Podcast Is Live!

Ep 24: The State of the Podcast

https://soundcloud.com/user-989538417/episode-24-the-state-of-the-podcast

The Veteran Wargamer is brought to you by Kings Hobbies and Games
https://www.facebook.com/Special-Artizan-Service-Miniatures-1791793644366746/

Join the conversation at https://theveteranwargamer.blogspot.com, email theveteranwargamer@gmail.com, Twitter @veteranwargamer



Other companies we mentioned:
Meeples and Miniatures https://meeples.wordpress.com/
Wargaming Recon http://wargamingrecon.com/
Ludology/Game Tek http://www.ludology.libsyn.com/
The D6 Generation http://www.thed6generation.com/

Military Justice Podcast http://www.militaryjusticepodcast.com/
The Weirick - @podcastmj

Music courtesy bensound.com. Recorded with zencastr.com. Edited with Audacity. Make your town beautiful; get a haircut.

sexta-feira, 1 de maio de 2020

Shadow Of The Comet – Won!

Written by limbeck

And so we arrive at the final showdown. The town itself is cleansed from the four families that were working to bring their evil plans to fruition, but all is not yet clear in the skies over Illsmouth. NARACKAMUS is still alive and the comet's passing is tonight. I have a lot of work still ahead of me and not enough time.

In the end of the previous post, Dr COBBLE gave me a message and a warning. The message was from Mr UNDERHOUSE, who was requesting my help. The warning was about Sgt. BRAGGS, who considered me responsible for last night's carnage (and with good reasons I will add). So, I need to go to the post office without running into BRAGGS.


Or Miss PICOTT, but that seems impossible.
Outside of Dr COBBLE's house is Miss PICOTT, who is seriously distressed about previous night's events and is also looking for her niece. She also tries to play matchmaker once again, but I avoid the commitment. Still, it won't hurt to pay a visit to her niece. I know where she lives after all.

It seems that BRAGGS is indeed after me. I have to go directly to the post office. If I go to the Mayor's barn for example, he follows me and arrests me. I cannot completely get rid of him myself. When I enter the post office I speak to a distressed Ms GUILDCHRIST at the counter and Sgt BRAGGS arrives. I take him upstairs to meet Mr UNDERHOUSE, who jumps to my rescue when I fumble for a response on my whereabouts. UNDERHOUSE even places suspicion on the bartender, ZEKE, who apparently ratted me out. BRAGGS leaves in anger to find him.

After that, UNDERHOUSE gives me a note speaking about a sacred bow, with an arrow and feather that I need to find. NATAWANGA, a local Native American can help me, but his location in the forest is unknown, but the feather and stick will find him. The note from him says that the bow is where the fire lives at the accursed family's youngest member. The accursed family is probably the HAMBLETONS and I think CURTIS is the youngest. In that case, I have to go to his place again. Before I leave, UNDERHOUSE hands me the feather and wishes me luck.


And reminds me of my biggest enemy

On my way to CURTIS's place, I note that JUGG's house is again open for visitors, so I go in. One of the butterflies is missing from the case. The label says it is the one mentioned in the book of rituals. I will need to find it. Naturally, it is not in the house.

I meet BISHOP outside CURTIS's house. He informs me that HAMBLETON is not inside and he is probably with GREENWOOD. I saw them together the previous day, but when I go to GREENWOOD's house, nobody is there. I come back to CURTIS's place.

The door to his house is locked, but there is a stick lying outside. I pick it up and I manage to remove the bar that was from the INSIDE. How on earth did CURTIS get out and then lock his door? Or lock his door and then get out? I will think about that later. For the time, I just use the pin from the locket to pick the lock and get inside.


I suppose this answers my previous questions

Yes, CURTIS is definitely dead. He was killed brutally and left hanging from his legs to dry. As I inspect the crime scene, I notice some moccasin tracks on the dusty floor and, in good detecting practice, I add my footprints as well. Maybe I should get going, but first I need the bow and arrow. As predicted, the bow is under the fireplace. The arrow was under a loose floorboard I had noticed in my first visit. Feeling really sorry for CURTIS, who really did not deserve any of this, I leave quietly to find NATAWANGA.

The note NATAWANGA gave to UNDERHOUSE said that the feather will fly to him. I don't know how or where to use it, so I start wondering around the forest trying to use the feather and even the arrow and the bow. I wasted some time here, also partly to my carelessness. I had understood that I needed the feather for the arrow, but I had misread the instructions. I just needed to use the feather. It was a bit frustrating anyway, as I had to be in a specific spot in the forest, without any other clue, where I could put the feather on a stump. Then, a crow came and picked it up and I turned into a white crow and flew to NATAWANGA's hut.


Clearly, turning into a white crow and back messed up my perceptive abilities

NATAWANGA asks me a number of questions to which I answer correctly. NARACKAMUS's tribe: Mic Macs, He Who Howls in the Night: Yog Sothoth, Year BOLESKINE observed the comet: 1834, Sign of the four families: Star, Name of undersea monstrosity: Dagon.

Once I pass the quiz, he gives me some advice on how to kill NARACKAMUS. He hides in "the eye that is set deep in the earth" and I need fire born of the earth to defeat him with my bow and arrow. My Journal agrees that these are indeed too many riddles. He also gave me a pot of red paint and his ring. I am turning into a well sought out bachelor. The ring has no stone, so I must find one.

The eye set deep in the earth seems a lot like the well. Let's see if the well is anything more than a changing screen.


Quite spacious

As expected, I can climb down in the well and arrive at an underground river. Now, if I may say, a well so close to the sea would not need to be so deep to reach water and the water would be brackish at best, but I'll play along.

When I reach the bottom, if I try to walk on the bank, I reach a place where the wild water carries me away and I drown. If, however, I throw the pail with paint that NATAWANGA gave me, the water calms and I can cross. In the next cavern is a set of cans. One is empty, but the others hold acid, tar and nitroglycerin. I assume that this is what "fire from earth" comes about. And I also think it will be a brute force puzzle, because all these are associated with fire, or at least a burning sensation. Acid can cause chemical burns, tar can burn if set on fire and nitroglycerin, well, it just needs a good shake!

I start with the empty can and the can of acid, as they are the first on the line. In the next cavern, I pick two flints. A bit later, I drown in a pool. Next time, I avoid the pool and move south, into NARACKAMUS's inner chamber. I can do nothing and he explodes me to death. This repeats a few times. Apparently my can of acid or tar or nitroglycerin are not fire from earth enough.


If I carried the nitroglycerin with me, I could blow up the whole town

I am sure the empty can is part of the solution, so I start clicking around. I die many times in the pool until I find the correct spot again and I fill in the can with naphtha.

Would it hurt you Infogrames to add a bit of FEEDBACK when I push L? I can see what is in the room, so tell me what it is! If I drown in a pool of liquid, I can definitely see there is liquid. And if I randomly use my empty can to get naphtha, I should know that this is naphtha. Or at least tell me that "You get a very particular odour in this room. Smells like naphtha / petroleum". I could figure out the rest. Rant over.

With naphtha in my possession, I use it immediately as I enter the next chamber (N. immediately recognises the smell. See game?). Then I use the flints to set it on fire and then again the bow and arrow to kill NARACKAMUS. Victory?


I know that Lovecraft was not big on dialogues, but this line could do with some more work

We have not won of course. I have yet to see the comet. After I kill NARACKAMUS, Lord BOLESKINE's apparition appears and tells me I have to stop Dagon from being set free. His temple is on an island off the coast of Illsmouth, so I need a boat to get there. Maybe BISHOP has one? Before I leave, I pick up two gems, a turqoise and an aquamarine, and the butterfly stolen from JUGG's house from next to NARACKAMUS's throne. Then I leave. And die a couple more times on the way.

I get to the port and see a boat and BISHOP, so I naturally speak to him. After a few attempts, during which he gets frustrated and refuses to talk to me until I leave and enter again, I persuade him to lend me his boat, which I then use to travel to the island.


Insert Monkey Island music

On the island, there is a fallen head from a statue, which has two gems as eyes, a ruby and an emerald. I naturally pocket both. Then I try to enter the temple and I get stuck because of the obligatory...


Frustrating sliding puzzle!

I wonder if there some secret agreement among mystery adventure game designers that they should include sliding tile puzzles in their games? I understand it is easy to program and implement, but it adds frustration and artificially lengthens the game. It is not fun. I enjoy such puzzles, but in the abstract.

Anyway, inside the temple is a grotesque mound of stone which could well be a statue of Dagon or Jabba the Hutt. On the floor there are several slabs with signs carved on them. There are some gems as well set in the walls and as the statue's eyes. I cannot really look at anything, so, once again, I don't know what I should be interacting with.

I find out that I can interact with the gems and the statue's eyes. I try one gem at random and am electrocuted. I try with a ruby, and this time a beam is emitted from it and is reflected around the cave. It could be trying to form a sing, but, if so, it is incomplete. I suppose I should be doing something about it. As I am thinking, a creature breaks through the belly of the statue and kills me.


Too many deaths to count

I spend some time on this puzzle. I do not have much time once I climb down. I die a few times trying to find the solution. It turns out that I had to hold the aquamarine gem and walk on the slab with the correct sign. The creature then bursts into fire and I run out in slow motion to jump ahead of an explosion, Hollywood style. Again, it is a clever puzzle in retrospect. I think there was a clue in one of the books at JUGG's library, speaking about sitting on the sign, but it again seemed a bit unclear to me.

Moving on, Lord BOLESKINE reappears to give me some half solution again. I need to let the currents lead me to my next stop, in which I have to single-handedly stop Cthulhu himself. And he gave me his ring and said something about our green land (I assume England) in the BOLESKINE family moto.

At Cthulhu's island or sandbank, the cave is too dark. Fortunately, I have been carrying my lantern almost since the beginning. The lantern, which immediately runs out of oil and leaves me in the dark, at the mercy of the creatures that roam the caves.


Actual game footage!

I feel I am in a dead-end, because I cannot refill it. If only I had something that burns. Yes... you guessed it: Napthta. Why would I refill the can after I killed the sorcerer? So I reload from before beating Dagon and head down to the well again to collect that precious liquid.

Now, when I run out of oil in the caves, I can use the can of naphtha to refill. Unfortunately, I find myself in another obstacle course. This time I have to slip past the monsters that roam the two rooms that I must cross. It takes a few tries because there is only so much space between the creatures. I don't know how hard it would be in the CD-ROM version.

When I succeed, I find an altar to Cthulhu and the WEBSTERS, mother and son, tied on a pole and in dire need of help. Cthulhu is sapping their energy and if I do not do something quickly, he will join us. I cannot untie the prisoners so I must stop them. Fumbling around with my stuff, I see that I can put the emerald (green gem) on BOLESKINE's ring. I also use my can of acid on a weird slab on the ground and I reveal a diamond. As soon as I pick this up, Cthulhu starts sucking the life out of the WEBSTERS and tentacles appear. I die a couple of times, as I am too slow thinking what to do. In the end, I use the turquoise (I think) on NATAWANGA's ring and put them on one after another. Cthulhu is banished and I have some free squid for my dinner.


By your powers combined, I am Captain Planet. Or not

I must also say that I like that scene above and give credit where it is due.

I let the WEBSTERS find their own way out and I stay behind to have a chat with Lord BOLESKINE. He says that the way I came in is blocked (I hope after the WEBSTERS got out) and that I need to go to the stone circle quickly and definitely take a photo of the comet. Does he work for my employer? I get out of the caves and I have to look again for the secret passage that takes me out of the collapsed cave and directly at the stone circle.

The last sequence is relatively straightforward and satisfying as far as puzzles go. I can take my time to set up my tripod, put the camera on it, check the butterfly to note the colours on its wings and then place it on my camera. I then put the magnifying glass (my sonic screwdriver) on the camera and add the lantern. Four coloured beams appear and hit 4 stones, leaving a coloured mark, red, green, white and blue. Once I finish, I unwrap the photographic plates and use them on the camera to take photos of the comet. As the comet passes, it leaves a fragment. I am sure astrogeologists would give an arm and a leg to just look at it, but I pick it up and put it on the white spot, which symbolises air. I do the same with diamond (green – earth), flint pieces (red – fire), aquamarine (blue-water). Everything else is technically a cutscene. I say the ritual and Yog Sothoth is banished.


Thank god I didn't have to type the words myself

I am now in the closing cutscene with limited control. In my room I have already packed my stuff and head to port to board the steamer home. Outside Dr COBBLE's house, BAGGS shows me the door not so kindly and lets me know that he had locked ZEKE in just in case. I think he did well, considering the quality of his beer.

At the port, I am greeted by the whole town, or what's left of it, and treated to a warm goodbye. In the last scene, I sit at Mr GRIFFITH's office and get to recount my story once again, looking too sane for it to be true.


Can I go away now?

So, we reach the end of a game, which played almost perfectly like a Lovecraftian short story, though not so much for the main character as for the player. But more on that on our Rating post, which will follow soon.

Session time: 3:00
Total time: 13:10

Sanity lost: 60 from making the acquaintance of the Ancient ones (20 each from Dagon, Cthulhu and Yog Sothoth)
Total sanity lost: 97 (Iäää Iäää FHTAGN!)

domingo, 26 de abril de 2020

How To Crack A Password

What is Password Cracking?

Password cracking is the process of attempting to gain Unauthorized access to restricted systems using common passwords or algorithms that guess passwords. In other words, it's an art of obtaining the correct password that gives access to a system protected by an authentication method.

Password cracking employs a number of techniques to achieve its goals. The cracking process can involve either comparing stored passwords against word list or use algorithms to generate passwords that match

How to crack password of an Application

In this Tutorial, we will introduce you to the common password cracking techniques and the countermeasures you can implement to protect systems against such attacks.

Topics covered in this tutorial

What is password strength?

Password strength is the measure of a password's efficiency to resist password cracking attacks. The strength of a password is determined by;

  • Length: the number of characters the password contains.
  • Complexity: does it use a combination of letters, numbers, and symbol?
  • Unpredictability: is it something that can be guessed easily by an attacker?

Let's now look at a practical example. We will use three passwords namely

1.  password

2.  password1

3.  #password1$

 For this example, we will use the password strength indicator of Cpanel when creating passwords. The images below show the password strengths of each of the above-listed passwords.

How to crack password of an Application

Note: the password used is password the strength is 1, and it's very weak.

How to crack password of an Application

Note: the password used is password1 the strength is 28, and it's still weak.

How to crack password of an Application

Note: The password used is #password1$ the strength is 60 and it's strong.

The higher the strength number, better the password.

Let's suppose that we have to store our above passwords using md5 encryption. We will use an online md5 hash generator to convert our passwords into md5 hashes.

 The table below shows the password hashes

PasswordMD5 HashCpanel Strength Indicator
password5f4dcc3b5aa765d61d8327deb882cf991
password17c6a180b36896a0a8c02787eeafb0e4c28
#password1$29e08fb7103c327d68327f23d8d9256c60


 We will now use http://www.md5this.com/ to crack the above hashes. The images below show the password cracking results for the above passwords.

How to crack password of an Application

How to crack password of an Application

How to crack password of an Application

As you can see from the above results, we managed to crack the first and second passwords that had lower strength numbers. We didn't manage to crack the third password which was longer, complex and unpredictable. It had a higher strength number.

Password cracking techniques

There are a number of techniques that can be used to crack passwords. We will describe the most commonly used ones below;

  • Dictionary attack– This method involves the use of a wordlist to compare against user passwords.
  • Brute force attack– This method is similar to the dictionary attack. Brute force attacks use algorithms that combine alpha-numeric characters and symbols to come up with passwords for the attack. For example, a password of the value "password" can also be tried as p@$$word using the brute force attack.
  • Rainbow table attack– This method uses pre-computed hashes. Let's assume that we have a database which stores passwords as md5 hashes. We can create another database that has md5 hashes of commonly used passwords. We can then compare the password hash we have against the stored hashes in the database. If a match is found, then we have the password.
  • Guess– As the name suggests, this method involves guessing. Passwords such as qwerty, password, admin, etc. are commonly used or set as default passwords. If they have not been changed or if the user is careless when selecting passwords, then they can be easily compromised.
  • Spidering– Most organizations use passwords that contain company information. This information can be found on company websites, social media such as facebook, twitter, etc. Spidering gathers information from these sources to come up with word lists. The word list is then used to perform dictionary and brute force attacks.

Spidering sample dictionary attack wordlist

1976 <founder birth year>

smith jones <founder name>

acme <company name/initials>

built|to|last <words in company vision/mission>

golfing|chess|soccer <founders hobbies

Password cracking tool

These are software programs that are used to crack user passwords. We already looked at a similar tool in the above example on password strengths. The website www.md5this.com uses a rainbow table to crack passwords. We will now look at some of the commonly used tools

John the Ripper

John the Ripper uses the command prompt to crack passwords. This makes it suitable for advanced users who are comfortable working with commands. It uses to wordlist to crack passwords. The program is free, but the word list has to be bought. It has free alternative word lists that you can use. Visit the product website http://www.openwall.com/john/ for more information and how to use it.

Cain & Abel

Cain & Abel runs on windows. It is used to recover passwords for user accounts, recovery of Microsoft Access passwords; networking sniffing, etc. Unlike John the Ripper, Cain & Abel uses a graphic user interface. It is very common among newbies and script kiddies because of its simplicity of use. Visit the product website http://www.softpedia.com/get/Security/Decrypting-Decoding/Cain-and-Abel.shtml for more information and how to use it.

Ophcrack

Ophcrack is a cross-platform Windows password cracker that uses rainbow tables to crack passwords. It runs on Windows, Linux and Mac OS. It also has a module for brute force attacks among other features. Visit the product website http://ophcrack.sourceforge.net/  for more information and how to use it.

Password Cracking Counter Measures

  • An organization can use the following methods to reduce the chances of the passwords been cracked
  • Avoid short and easily predicable passwords
  • Avoid using passwords with predictable patterns such as 11552266.
  • Passwords stored in the database must always be encrypted. For md5 encryptions, its better to salt the password hashes before storing them. Salting involves adding some word to the provided password before creating the hash.
  • Most registration systems have password strength indicators, organizations must adopt policies that favor high password strength numbers.

Hacking Activity: Hack Now!

In this practical scenario, we are going to crack Windows account with a simple passwordWindows uses NTLM hashes to encrypt passwords. We will use the NTLM cracker tool in Cain and Abel to do that.

Cain and Abel cracker can be used to crack passwords using;

  • Dictionary attack
  • Brute force
  • Cryptanalysis

We will use the dictionary attack in this example. You will need to download the dictionary attack wordlist here 10k-Most-Common.zip

For this demonstration, we have created an account called Accounts with the password qwerty on Windows 7.

How to crack password of an Application

Password cracking steps

  • Open Cain and Abel, you will get the following main screen

How to crack password of an Application

  • Make sure the cracker tab is selected as shown above
  • Click on the Add button on the toolbar.

How to crack password of an Application

  • The following dialog window will appear

How to crack password of an Application

  • The local user accounts will be displayed as follows. Note the results shown will be of the user accounts on your local machine.

How to crack password of an Application

  • Right click on the account you want to crack. For this tutorial, we will use Accounts as the user account.

How to crack password of an Application

  • The following screen will appear

How to crack password of an Application

  • Right click on the dictionary section and select Add to list menu as shown above
  • Browse to the 10k most common.txt file that you just downloaded

How to crack password of an Application

  • Click on start button
  • If the user used a simple password like qwerty, then you should be able to get the following results.

How to crack password of an Application

  • Note: the time taken to crack the password depends on the password strength, complexity and processing power of your machine.
  • If the password is not cracked using a dictionary attack, you can try brute force or cryptanalysis attacks.

Summary

  • Password cracking is the art of recovering stored or transmitted passwords.
  • Password strength is determined by the length, complexity, and unpredictability of a password value.
  • Common password techniques include dictionary attacks, brute force, rainbow tables, spidering and cracking.
  • Password cracking tools simplify the process of cracking passwords.
@EVERYTHING NT
Related posts

Save Your Cloud: Gain Root Access To VMs In OpenNebula 4.6.1


In this post, we show a proof-of-concept attack that gives us root access to a victim's VM in the Cloud Management Platform OpenNebula, which means that we can read and write all its data, install software, etc. The interesting thing about the attack is, that it allows an attacker to bridge the gap between the cloud's high-level web interface and the low-level shell-access to a virtual machine.

Like the latest blogpost of this series, this is a post about an old CSRF- and XSS-vulnerability that dates back to 2014. However, the interesting part is not the vulnerability itself but rather the exploit that we were able to develop for it.

An attacker needs the following information for a successful attack.
  • ID of the VM to attack
    OpenNebula's VM ID is a simple global integer that is increased whenever a VM is instantiated. The attacker may simply guess the ID. Once the attacker can execute JavaScript code in the scope of Sunstone, it is possible to use OpenNebula's API and data structures to retrieve this ID based on the name of the desired VM or its IP address.
  • Operating system & bootloader
    There are various ways to get to know a VMs OS, apart from simply guessing. For example, if the VM runs a publicly accessible web server, the OS of the VM could be leaked in the HTTP-Header Server (see RFC 2616). Another option would be to check the images or the template the VM was created from. Usually, the name and description of an image contains information about the installed OS, especially if the image was imported from a marketplace.
    Since most operating systems are shipped with a default bootloader, making a correct guess about a VMs bootloader is feasible. Even if this is not possible, other approaches can be used (see below).
  • Keyboard layout of the VM's operating system
    As with the VMs bootloader, making an educated guess about a VM's keyboard layout is not difficult. For example, it is highly likely that VMs in a company's cloud will use the keyboard layout of the country the company is located in.

Overview of the Attack

The key idea of this attack is that neither Sunstone nor noVNC check whether keyboard related events were caused by human input or if they were generated by a script. This can be exploited so that gaining root access to a VM in OpenNebula requires five steps:
  1. Using CSRF, a persistent XSS payload is deployed.
  2. The XSS payload controls Sunstone's API.
  3. The noVNC window of the VM to attack is loaded into an iFrame.
  4. The VM is restarted using Sunstone's API.
  5. Keystroke-events are simulated in the iFrame to let the bootloader open a root shell.

Figure 1: OpenNebula's Sunstone Interface displaying the terminal of a VM in a noVNC window.

The following sections give detailed information about each step.

Executing Remote Code in Sunstone

In Sunstone, every account can choose a display language. This choice is stored as an account parameter (e.g. for English LANG=en_US). In Sunstone, the value of the LANG parameter is used to construct a <script> tag that loads the corresponding localization script. For English, this creates the following tag:
<script src="locale/en_US/en_US.js?v=4.6.1" type="text/javascript"></script>
Setting the LANG parameter to a different string directly manipulates the path in the script tag. This poses an XSS vulnerability. By setting the LANG parameter to LANG="onerror=alert(1)//, the resulting script tag looks as follows:
<script src="locale/"onerror=alert(1)///"onerror=alert(1)//.js?v=4.6.1" type="text/javascript"></script>
For the web browser, this is a command to fetch the script locale/ from the server. However, this URL points to a folder, not a script. Therefore, what the server returns is no JavaScript. For the browser, this is an error, so the browser executes the JavaScript in the onerror statement: alert(1). The rest of the line (including the second alert(1)) is treated as comment due to the forward slashes.

When a user updates the language setting, the browser sends an XMLHttpRequest of the form
{ "action" : { "perform" : "update", "params" : { "template_raw" : "LANG=\"en_US\"" } }}
to the server (The original request contains more parameters. Since these parameters are irrelevant for the technique, we omitted them for readability.). Forging a request to Sunstone from some other web page via the victim's browser requires a trick since one cannot use an XMLHttpRequest due to restrictions enforced by the browser's Same-Origin-Policy. Nevertheless, using a self-submitting HTML form, the attacker can let the victim's browser issue a POST request that is similar enough to an XMLHttpRequest so that the server accepts it.

An HTML form field like
<input name='deliver' value='attacker' />
is translated to a request in the form of deliver=attacker. To create a request changing the user's language setting to en_US, the HTML form has to look like
<input name='{"action":{"perform":"update","params":{"template_raw":"LANG' value='\"en_US\""}}}' />
Notice that the equals sign in LANG=\"en_US\" is inserted by the browser because of the name=value format.

Figure 2: OpenNebula's Sunstone Interface displaying a user's attributes with the malicious payload in the LANG attribute.

Using this trick, the attacker sets the LANG parameter for the victim's account to "onerror=[remote code]//, where [remote code] is the attacker's exploit code. The attacker can either insert the complete exploit code into this parameter (there is no length limitation) or include code from a server under the attacker's control. Once the user reloads Sunstone, the server delivers HTML code to the client that executes the attacker's exploit.

Prepare Attack on VM

Due to the overwritten language parameter, the victim's browser does not load the localization script that is required for Sunstone to work. Therefore, the attacker achieved code execution, but Sunstone breaks and does not work anymore. For this reason, the attacker needs to set the language back to a working value (e.g. en_US) and reload the page in an iFrame. This way Sunstone is working again in the iFrame, but the attacker can control the iFrame from the outside. In addition, the attack code needs to disable a watchdog timer outside the iFrame that checks whether Sunstone is correctly initialized.

From this point on, the attacker can use the Sunstone API with the privileges of the victim. This way, the attacker can gather all required information like OpenNebula's internal VM ID and the keyboard layout of the VM's operating system from Sunstone's data-structures based on the name or the IP address of the desired VM.

Compromising a VM

Using the Sunstone API the attacker can issue a command to open a VNC connection. However, this command calls window.open, which opens a new browser window that the attacker cannot control. To circumvent this restriction, the attacker can overwrite window.open with a function that creates an iFrame under the attacker's control.

Once the noVNC-iFrame has loaded, the attacker can send keystrokes to the VM using the dispatchEvent function. Keystrokes on character keys can be simulated using keypress events. Keystrokes on special keys (Enter, Tab, etc.) have to be simulated using pairs of keydown and keyup events since noVNC filters keypress events on special keys.

Getting Root Access to VM

To get root access to a VM the attacker can reboot a victim's VM using the Sunstone API and then control the VM's bootloader by interrupting it with keystrokes. Once the attacker can inject commands into the bootloader, it is possible to use recovery options or the single user mode of Linux based operating systems to get a shell with root privileges. The hardest part with this attack is to get the timing right. Usually, one only has a few seconds to interrupt a bootloader. However, if the attacker uses the hard reboot feature, which instantly resets the VM without shutting it down gracefully, the time between the reboot command and the interrupting keystroke can be roughly estimated.

Even if the bootloader is unknown, it is possible to use a try-and-error approach. Since the variety of bootloaders is small, one can try for one particular bootloader and reset the machine if the attack was unsuccessful. Alternatively, one can capture a screenshot of the noVNC canvas of the VM a few seconds after resetting the VM and determine the bootloader.

A video of the attack can be seen here. The browser on the right hand side shows the victim's actions. A second browser on the left hand side shows what is happening in OpenNebula. The console window on the bottom right shows that there is no user-made keyboard input while the attack is happening.



Appeared:
  • Cyber Space (Computer Security).
  • Terror Security (Computer Security).
  • National Cyber Security Services.

Brief Introduction
  • Tishna is useful in Banks, Private Organisations and Ethical hacker personnel for legal auditing.
  • It serves as a defense method to find as much as information possible for gaining unauthorised access and intrusion.
  • With the emergence of more advanced technology, cybercriminals have also found more ways to get into the system of many organizations.
  • Tishna software can audit, servers and web behaviour.
  • Tishna can perform Scanning & Enumeration as much as possible of target.
  • It's first step to stop cyber criminals by securing your Servers and Web Application Security.
  • Tishna is false positive free, when there is something it will show no matter what, if it is not, it will give blank results rather error.

Developer

Support to the coder
   You can sponsor and support via BTC.
   The bitcoin address: 3BuUYgEgsRuEra4GwqNVLKnDCTjLEDfptu
qr code

Read more


Quando eu te falei em amor

Quando os meus olhos te tocaram
Eu senti que encontrara
A outra, metade de mim
Tive medo de acordar
Como se vivesse um sonho
Que não pensei em realizar
E a força do desejo
Faz me chegar perto de ti

Quando eu te falei em amor
Tu sorriste para mim
E o mundo ficou bem melhor
Quando eu te falei em amor
Nos sentimos os dois
Que o amanha vem depois
E não no fim

Estas linhas que hoje escrevo
São do livro da memória
Do que eu sinto por ti
E tudo o que tu me das
É parte da história que eu ainda não vivi
E a força do desejo
Faz me chegar de ti

Quando eu te falei em amor
Tu sorriste para mim
E o mundo ficou bem melhor
Quando eu te falei em amor
Nos sentimos os dois
Que o amanha vem depois e não no fim

André Sardet

Collide

The dawn is breaking
A light shining through
You're barely waking
And I'm tangled up in you
Yeah

But I'm open, you're closed
Where I follow, you'll go
I worry I won't see your face
Light up again

Even the best fall down sometimes
Even the wrong words seem to rhyme
Out of the doubt that fills my mind
I somehow find, you and I collide

I'm quiet, you know
You make a first impression
I've found I'm scared to know
I'm always on your mind

Even the best fall down sometimes
Even the stars refuse to shine
Out of the back you fall in time
I somehow find, you and I collide

Don't stop here
I've lost my place
I'm close behind

Even the best fall down sometimes
Even the wrong words seem to rhyme
Out of the doubt that fills your mind

You finally find, you and I collide
You finally find You and I collide
You finally findYou and I collide

Howie Day


Everything

You're a falling star, You're the get away
car.

You're the line in the sand when I go too
far.

You're the swimming pool, on an August day.
And You're the perfect thing to see.

And you play it coy, but it's kinda cute.
Ah, When you smile at me you know exactly what you
do.

Baby don't pretend, that you don't know it's
true.

Cause you can see it when I look at you.

And in this crazy life, and through these crazy
times

It's you, it's you, You make me sing.
You're every line, you're every word, you're
everything.


You're a carousel, you're a wishing well,
And you light me up, when you ring my bell.
You're a mystery, you're from outer space,
You're every minute of my everyday.

And I can't believe, uh that I'm your man,
And I get to kiss you baby just because I
can.

Whatever comes our way, ah we'll see it
through,

And you know that's what our love can do.

And in this crazy life, and through these crazy
times

It's you, it's you, You make me sing
You're every line, you're every word, you're
everything.


So, La, La, La, La, La, La, La
So, La, La, La, La, La, La, La

And in this crazy life, and through these crazy
times

It's you, it's you, You make me sing.
You're every line, you're every word, you're
everything.

You're every song, and I sing along.
Cause you're my everything.
yeah, yeah

So, La, La, La, La, La, La, La
So, La, La, La, La, La, La, La

Michael Bublé