<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Aten Labs &#187; hack</title>
	<atom:link href="http://atenlabs.com/blog/tag/hack/feed/" rel="self" type="application/rss+xml" />
	<link>http://atenlabs.com/blog</link>
	<description>San Diego&#039;s Premier IT Security Consultancy</description>
	<lastBuildDate>Wed, 29 Feb 2012 19:14:43 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>Android Phone = rogue access point!</title>
		<link>http://atenlabs.com/blog/android-phone-rogue-access-point/</link>
		<comments>http://atenlabs.com/blog/android-phone-rogue-access-point/#comments</comments>
		<pubDate>Thu, 22 Jul 2010 08:45:43 +0000</pubDate>
		<dc:creator>Dan Tentler</dc:creator>
				<category><![CDATA[insight]]></category>
		<category><![CDATA[review]]></category>
		<category><![CDATA[technology]]></category>
		<category><![CDATA[training]]></category>
		<category><![CDATA[802.11]]></category>
		<category><![CDATA[802.11a]]></category>
		<category><![CDATA[802.11b/g]]></category>
		<category><![CDATA[802.11n]]></category>
		<category><![CDATA[access]]></category>
		<category><![CDATA[audit]]></category>
		<category><![CDATA[auditing]]></category>
		<category><![CDATA[dan]]></category>
		<category><![CDATA[hack]]></category>
		<category><![CDATA[incredible]]></category>
		<category><![CDATA[pen]]></category>
		<category><![CDATA[penetration]]></category>
		<category><![CDATA[point]]></category>
		<category><![CDATA[rogue]]></category>
		<category><![CDATA[root]]></category>
		<category><![CDATA[tentler]]></category>
		<category><![CDATA[test]]></category>
		<category><![CDATA[testing]]></category>
		<category><![CDATA[viss]]></category>
		<category><![CDATA[vissago htc]]></category>
		<category><![CDATA[wifi]]></category>
		<category><![CDATA[wireless]]></category>

		<guid isPermaLink="false">http://atenlabs.com/blog/?p=167</guid>
		<description><![CDATA[So when I get a new phone, I immediately want to try to get as much access on it as possible (read: root it). Custom roms are wonderful, but in the case of the HTC Incredible I don&#8217;t think there are custom roms (yet). After I rooted my HTC Incredible I started doing searches in [...]]]></description>
			<content:encoded><![CDATA[<p>So when I get a new phone, I immediately want to try to get as much access on it as possible (read: root it). Custom roms are wonderful, but in the case of the HTC Incredible I don&#8217;t think there are custom roms (yet).</p>
<p>After I rooted my HTC Incredible I started doing searches in the market for interesting things. I found some neat wireless utilities, I found a file manager that lets you browse SMB fileshares on the lan (NEAT.), I found a packetsniffer, and some more interesting tools.</p>
<p>The light came on over my head when I realized &#8220;Wait, a packet sniffer AND a wireless access point? .. can .. I sniff.. the wifi with this?!&#8221;. As it turns out the answer is yes &#8211; it takes some fenagling, and if you do it in the wrong order one application stomps the other (I&#8217;ve already written the author of the packet capture application about this but have not gotten a response yet).</p>
<p>Here is a quick walkthrough on how to turn an HTC Incredible into a rogue wireless access point:</p>
<ol>
<li>Root the phone. This can be done by visiting <a href="http://unrevoked.com/recovery/" target="_blank">http://unrevoked.com/recovery/</a>, downloading the app, and running it.</li>
<li>Once the phone is rooted, go to the market, and install the wifi tether application: Be aware though, that with the HTC incredible there are additional steps to get this application to work (see their wiki page: <a href="http://code.google.com/p/android-wifi-tether/" target="_blank">http://code.google.com/p/android-wifi-tether/</a>)
<p style="text-align: center;"><a href="http://atenlabs.com/blog/wp-content/uploads/2010/07/wifi-tether.png"><img class="aligncenter size-medium wp-image-169" title="wifi-tether" src="http://atenlabs.com/blog/wp-content/uploads/2010/07/wifi-tether-180x300.png" alt="" width="180" height="300" /></a></p>
</li>
<li>Install the packet capture application. This also will need additional steps after the installation. (<a href="http://sites.google.com/site/androidarts/packet-sniffer" target="_blank">http://sites.google.com/site/androidarts/packet-sniffer</a>)</li>
<li>Once you have the packet sniffer installed, configure it to log to a file instead of a sql database. I wasn&#8217;t able to find the actual database this thing logs to, but the text file appears right at the root of the sdcard. It looks just like the &#8216;live&#8217; output though, which I don&#8217;t think is a proper format. It doesn&#8217;t log raw traffic at all.</li>
<li>Don&#8217;t start the sniffer or wifi tether yet &#8211; they must be configured beforehand.</li>
<li>Go back to wifi-tether and configure the SSID. Name it something which will attract people in search of free wifi. Linksys. Dlink. Netgear. 2WIRE858. The SSID of a target network, perhaps. Again, do not turn on tethering here yet.</li>
<li>Open up the packet sniffer again, and go to the &#8216;wifi capture&#8217; section, then enable the capture, and if you&#8217;d like, enable logging packets to the screen.</li>
<li>Hit the phones &#8216;home&#8217; button to exit without stopping the packet capture tool, and re-open the wifi tethering tool. Once in the tethering tool, enable tethering.</li>
<li>Hit home again, and go re open the packet capture tool. If anybody connects, wifi tether will tell you in the status bar at the top of the display, and you will start seeing arp traffic and dhcp traffic scroll in the live feed window as you would with any other packet sniffer.<br />
<a href="http://atenlabs.com/blog/wp-content/uploads/2010/07/capture1.png"><img class="aligncenter size-medium wp-image-168" title="capture1" src="http://atenlabs.com/blog/wp-content/uploads/2010/07/capture1-180x300.png" alt="" width="180" height="300" /></a></li>
</ol>
<p>There are several caveats to this though:</p>
<ol>
<li>This tool appears to not capture raw packets. You can do this from a terminal using TCPdump if you feel so inclined &#8211; the packet capture tool installation instructions have you install a new version of tcpdump. You should be able to use this to capture raw traffic and not just clear text</li>
<li>Packet capture has to be running before wifi tether &#8211; if you try to do it the other way around wifi tether will hang and you&#8217;ll have to kill it.</li>
<li>This will also capture all the traffic from your phone to the internet, so if you&#8217;re trying to do a bunch of stuff on your phone while running a rogue access point, it will  muddy your results.</li>
</ol>
<p>This has been a fairly simple howto &#8211; you creative types will easily be able to find more interesting things to do with this.</p>
<p>My wishlist after figuring this out? &#8211; An app that acts like airodump &#8211; I want to see clients probing for networks so that I can &#8220;give them what they want&#8221;. I also want this packet capture tool to log raw data, not just plaintext stuff.  Now that this is possible, I wish for tools like drifnet, dsniff, and others of that sort to become available on the android platform. The objective here would be to use this during a pen test as a tool to capture data, then bring it back to the labs for analysis.</p>
]]></content:encoded>
			<wfw:commentRss>http://atenlabs.com/blog/android-phone-rogue-access-point/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>How to steal Facebook Authentication cookies</title>
		<link>http://atenlabs.com/blog/how-to-steal-facebook-authentication-cookies/</link>
		<comments>http://atenlabs.com/blog/how-to-steal-facebook-authentication-cookies/#comments</comments>
		<pubDate>Thu, 17 Jun 2010 00:09:51 +0000</pubDate>
		<dc:creator>Dan Tentler</dc:creator>
				<category><![CDATA[insight]]></category>
		<category><![CDATA[review]]></category>
		<category><![CDATA[technology]]></category>
		<category><![CDATA[dan]]></category>
		<category><![CDATA[facebook]]></category>
		<category><![CDATA[hack]]></category>
		<category><![CDATA[hijacking]]></category>
		<category><![CDATA[how]]></category>
		<category><![CDATA[information]]></category>
		<category><![CDATA[lennox]]></category>
		<category><![CDATA[mrb0t]]></category>
		<category><![CDATA[nick]]></category>
		<category><![CDATA[penetration]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[session]]></category>
		<category><![CDATA[stealing]]></category>
		<category><![CDATA[tentler]]></category>
		<category><![CDATA[testing]]></category>
		<category><![CDATA[to]]></category>
		<category><![CDATA[viss]]></category>
		<category><![CDATA[vissago]]></category>

		<guid isPermaLink="false">http://atenlabs.com/blog/?p=136</guid>
		<description><![CDATA[How to hack a facebook account &#8211; or, basically how to hijack php sessions. Yes &#8211; this is old news &#8211; yes its a common vulnerability &#8211; but you get a better idea for what it is and how it works when things are explained in detail (with screenshots!). Before we begin, however, I want [...]]]></description>
			<content:encoded><![CDATA[<p>How to hack a facebook account &#8211; or, basically how to hijack php sessions. Yes &#8211; this is old news &#8211; yes its a common vulnerability &#8211; but you get a better idea for what it is and how it works when things are explained in detail (with screenshots!).</p>
<p>Before we begin, however, I want to re-emphasize that it is <strong>VERY EASY</strong> to protect yourself against this sort of attack. Facebook supports HTTPS, so when you browse facebook (or twitter for that matter) or if you have it bookmarked &#8211; please make sure you&#8217;re using <strong>HTTPS://</strong> rather than <strong>HTTP://</strong> in the URL at the very least, if not using a <a href="http://atenlabs.com/zipline">VPN solution</a> for further encryption. Also, if the &#8216;victim&#8217; logs out of facebook, the attackers session becomes invalid &#8211; so it&#8217;s a good practice to actually log out of facebook and log back in again rather than using the &#8216;remember me&#8217; checkbox.</p>
<p>Facebook like many sites operates using authentication cookies. Their auth cookies contain a variety of information, but for our purposes this is irrelevant. Here is a sanitized cookie for reference:</p>
<p><code>Cookie: datr=1276721606-b7f94f977295759399293c5b0767618dc02111ede159a827030fc; lsd=Xesut; lxe=greg.evans%40****************; c_user=100001230367821; lo=wl9fcGXMhPfoT4bAhKFP3Q; lxs=1; sct=1276721745; xs=a615cfe596448194d6e2a8d062a90e4e</code></p>
<p>You can see the &#8216;lxe&#8217; field is the login. We haven&#8217;t done any further research into what the various other fields mean, but using facebook without any kind of security you&#8217;re both leaking the email address used for your login and the session cookie.</p>
<p>First thing you&#8217;ll want to do is fire up your favorite packet capture application. For this example we&#8217;ve used Wireshark:</p>
<p><a href="http://atenlabs.com/blog/wp-content/uploads/2010/06/wireshark1.jpg"><img src="http://atenlabs.com/blog/wp-content/uploads/2010/06/wireshark1-300x180.jpg" alt="" title="wireshark1" width="300" height="180" class="aligncenter size-medium wp-image-151" /></a></p>
<p>Next, set the filter in the top left to &#8221; <strong>http.cookie contains &#8220;datr&#8221;</strong> &#8220;. This should show you only packets captured which contain the cookie we&#8217;re looking for. You can see that in this screenshot we&#8217;ve already captured a cookie.</p>
<p><a href="http://atenlabs.com/blog/wp-content/uploads/2010/06/wireshark2.jpg"><img src="http://atenlabs.com/blog/wp-content/uploads/2010/06/wireshark2-300x140.jpg" alt="" title="wireshark2" width="300" height="140" class="aligncenter size-medium wp-image-150" /></a></p>
<p>Once you&#8217;ve found a suitable cookie, you can copy it into the buffer by right clicking on the cookie line, and clicking Copy -> Bytes (Printable Text Only)<br />
<a href="http://atenlabs.com/blog/wp-content/uploads/2010/06/wireshark3.jpg"><img src="http://atenlabs.com/blog/wp-content/uploads/2010/06/wireshark3-300x139.jpg" alt="" title="wireshark3" width="300" height="139" class="aligncenter size-medium wp-image-149" /></a></p>
<p>Next you&#8217;ll want to open up firefox. You&#8217;ll need both <a href="https://addons.mozilla.org/en-US/firefox/addon/748/">greasemonkey</a> and the <a href="http://dustint.com/archives/12">cookieinjector script</a>.</p>
<p>Simply browse to facebook &#8211; make sure you are not logged in:</p>
<p><a href="http://atenlabs.com/blog/wp-content/uploads/2010/06/firefox.jpg"><img src="http://atenlabs.com/blog/wp-content/uploads/2010/06/firefox-300x175.jpg" alt="" title="firefox" width="300" height="175" class="aligncenter size-medium wp-image-156" /></a></p>
<p>Hit ALT-C to bring up the cookie injector dialog box:</p>
<p><a href="http://atenlabs.com/blog/wp-content/uploads/2010/06/firefox2.jpg"><img src="http://atenlabs.com/blog/wp-content/uploads/2010/06/firefox2-300x175.jpg" alt="" title="firefox2" width="300" height="175" class="aligncenter size-medium wp-image-155" /></a></p>
<p>Then paste in the cookie!</p>
<p><a href="http://atenlabs.com/blog/wp-content/uploads/2010/06/firefox3.jpg"><img src="http://atenlabs.com/blog/wp-content/uploads/2010/06/firefox3-300x175.jpg" alt="" title="firefox3" width="300" height="175" class="aligncenter size-medium wp-image-154" /></a></p>
<p>Hit refresh and &#8211; VIOLA! you&#8217;re now logged in as your victim! Now this doesn&#8217;t give you access to their credentials, this is about the equivalent to walking up to their workstation while they&#8217;re away from their desk and using facebook. </p>
<p><a href="http://atenlabs.com/blog/wp-content/uploads/2010/06/firefox4.jpg"><img src="http://atenlabs.com/blog/wp-content/uploads/2010/06/firefox4-300x175.jpg" alt="" title="firefox4" width="300" height="175" class="aligncenter size-medium wp-image-153" /></a></p>
<p>Neat huh? Pretty easy too. I smiled big when we demo&#8217;ed the attack in our lab &#8211; its old, sure, but being successful is always a good feeling!</p>
<p><em>P.S: This isnt REALLY Gregory Evans account. We setup this account because .. well.. the name was available! We thought it was in good taste as the No #1 hacker&#8217;s twitter feed got hacked the other day, <a href="http://attrition.org/errata/charlatan/gregory_evans/ligatt06/">his site is riddled with XSS exploits</a>, and his book is copypasta from a variety of certification exam prep books. Thanks to <a href="http://whoneedscrypto.ordonomicon.net/">Nick</a> and <a href="http://blog.skeptikal.org/">mckt</a> for the work and tootilage, respectively. No noobs were harmed in the making of this film.</em></p>
]]></content:encoded>
			<wfw:commentRss>http://atenlabs.com/blog/how-to-steal-facebook-authentication-cookies/feed/</wfw:commentRss>
		<slash:comments>31</slash:comments>
		</item>
		<item>
		<title>Twitter, DNS, the &#8220;Iranian cyber army&#8221; and panic &#8211; an analysis</title>
		<link>http://atenlabs.com/blog/twitter-dns-the-iranian-cyber-army-and-panic-an-analysis/</link>
		<comments>http://atenlabs.com/blog/twitter-dns-the-iranian-cyber-army-and-panic-an-analysis/#comments</comments>
		<pubDate>Fri, 18 Dec 2009 08:44:45 +0000</pubDate>
		<dc:creator>Dan Tentler</dc:creator>
				<category><![CDATA[insight]]></category>
		<category><![CDATA[rants]]></category>
		<category><![CDATA[technology]]></category>
		<category><![CDATA[capture]]></category>
		<category><![CDATA[captured]]></category>
		<category><![CDATA[dns]]></category>
		<category><![CDATA[ettiquite]]></category>
		<category><![CDATA[hack]]></category>
		<category><![CDATA[hacked]]></category>
		<category><![CDATA[password]]></category>
		<category><![CDATA[poison]]></category>
		<category><![CDATA[poisoned]]></category>
		<category><![CDATA[sensationalism]]></category>
		<category><![CDATA[sensationalist]]></category>
		<category><![CDATA[theft]]></category>
		<category><![CDATA[twitter]]></category>

		<guid isPermaLink="false">http://atenlabs.com/blog/?p=85</guid>
		<description><![CDATA[Status.twitter.com tells us that DNS records were overwritten temporarily tonight by attackers to redirect HTTP traffic to another host that was originally destined for twitter.com. With the information that I know now (12:40am, 12/18): The host which contained the landing page was hosted with bluehost. This tells us a few things They didn&#8217;t have the [...]]]></description>
			<content:encoded><![CDATA[<p>Status.twitter.com tells us that DNS records were overwritten temporarily tonight by attackers to redirect HTTP traffic to another host that was originally destined for twitter.com.</p>
<p>With the information that I know now (12:40am, 12/18):</p>
<p>The host which contained the landing page was hosted with bluehost. This tells us a few things</p>
<ul>
<li>They didn&#8217;t have the infrastructure to do packet captures, or credential theft. Bluehost does shared hosting.</li>
<li>Any attempt to do so would have thrown TONS of SSL errors, and very likely DDoS&#8217;ed the server hosting the landing page. (Twitter had HUNDREDS of servers, these guys had 1.). All of your twitter apps would have thrown errors, or flat out stopped working.</li>
<li>Twitters security infrastructure was left untouched, and was not a target of the attack.</li>
</ul>
<p>I&#8217;ve been watching twitter scroll with sensationalism and panic, people yelling &#8220;OH GOD TWITTER GOT HACKED EVERYONE CHANGE YOUR PASSWORDS NOW&#8221;.</p>
<p>Please &#8211; don&#8217;t do that.</p>
<p>Its going to make everyones job harder who have to work on this situation, it incites panic and causes people to prematurely flip out and do things they probably shouldn&#8217;t do.</p>
<p>I&#8217;ve had to deal with this in the past &#8211; people throwing their arms in the air and screaming about passwords being compromised when they in fact weren&#8217;t. It did not end well.</p>
<p>Please &#8211; think before you hit send.</p>
]]></content:encoded>
			<wfw:commentRss>http://atenlabs.com/blog/twitter-dns-the-iranian-cyber-army-and-panic-an-analysis/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>Hacking without computers</title>
		<link>http://atenlabs.com/blog/hacking-without-computers/</link>
		<comments>http://atenlabs.com/blog/hacking-without-computers/#comments</comments>
		<pubDate>Wed, 13 May 2009 20:08:34 +0000</pubDate>
		<dc:creator>Dan Tentler</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[hack]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[ipod]]></category>
		<category><![CDATA[itouch]]></category>
		<category><![CDATA[metasploit]]></category>
		<category><![CDATA[ms08-067]]></category>
		<category><![CDATA[msf]]></category>
		<category><![CDATA[touch]]></category>

		<guid isPermaLink="false">http://atenlabs.com/blog/?p=40</guid>
		<description><![CDATA[I&#8217;ve mentioned to folks before that &#8220;security isn&#8217;t what you think it is&#8221;. Every device is suspect, even printers. Here&#8217;s an example video I&#8217;ve made demonstrating how an attacker can gain an administrative shell on an XP box using an iPod Touch and Metasploit. This video is best viewed in high-def.]]></description>
			<content:encoded><![CDATA[<p>I&#8217;ve mentioned to folks before that &#8220;security isn&#8217;t what you think it is&#8221;. Every device is suspect, even <a href="http://www.theregister.co.uk/2006/04/06/hp_printer_security_vuln/" target="_blank">printers</a>. Here&#8217;s an example video I&#8217;ve made demonstrating how an attacker can gain an administrative shell on an XP box using an iPod Touch and Metasploit. This video is best viewed in high-def.</p>
<p><center><br />
<object width="560" height="340"><param name="movie" value="http://www.youtube.com/v/RJziHh8zay4&#038;hl=en&#038;fs=1"></param><param name="allowFullScreen" value="true"></param><param name="allowscriptaccess" value="always"></param><embed src="http://www.youtube.com/v/RJziHh8zay4&#038;hl=en&#038;fs=1" type="application/x-shockwave-flash" allowscriptaccess="always" allowfullscreen="true" width="560" height="340"></embed></object><br />
</center></p>
]]></content:encoded>
			<wfw:commentRss>http://atenlabs.com/blog/hacking-without-computers/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
	</channel>
</rss>

