Overview
One of the more advanced tactics for encryption, particularly when the subject wants to throw some complexity/difficulty into the mix is the use of multiple factor authentication/encryption.
Typical encryption systems use passwords and/or certificates for encryption. One of the weaknesses in this strategy is that these can be guessed or obtained in relatively simple ways.
Passwords are a relative novelty these days.. at least in the sense that a vast majority of people use them insecurely or fail to properly manage/use them correctly. Passwords (particularly cognitive ones) can be a pain to crack when properly used. Hash extraction and hybrid attacks can significantly reduce time in this area.
Passwords shouldn't be considered secure by themselves. Combining them with other methods significantly improve their viability and security.
Salting passwords is a good start. Significantly difficult salting increases time, but once again... passwords are merely a time/resources tradeoff. They're still crackable, it just takes more time.
There are a few strategies to sufficiently deter or otherwise protect that encrypted data. I'm going to go over two particularly nefarious ones.
Keyfiles
Keyfiles are files that can be used to aid in encryption/decryption. Without a dissertation on this subject, just think of them as an additional "password." They're key materials that are "added" in to the encryption process as an additional control.
Keyfiles can be anything. Common ones are pictures, documents, etc. As securing your data requires storage of that file, this makes it an easier proposition for the attacker. If I can find it, I can try it. A general rule for password cracking/attacking is "the more complex it is, the higher likelihood that it's being stored insecurely and unencrypted, just in case."
Where do I get one?
Hiding in plain sight is a great tactic, particularly when you can virtually guarantee your file will be overlooked.
Forensic examiners are trained to look for anomalies. They're also trained to heavily filter things that appear irrelevant or unresponsive. System files are frequently discarded or filtered out because they clutter up your view.
Enter system files
System files, particularly ones that do not frequently change are a great candidate. You can virtually guarantee that some of these files will remain static over a long period of time. Additionally, the fact that the key file is on MANY computers and widely available in an emergency, they make a great alternative.
This is the difference between "lab" and "practical." In the lab, using a file like this is trivial. In the lab, you have unlimited time and materials. In practical terms, most examiners are over-worked. They miss things. "No one would ever do this." or "I have xxxx files to review.. key locked encryption is very difficult to crack and I wouldn't know where to start." The process of breaking this is tedious. They just don't have the time to invest.
For the person who wants to "stay secure", the management of this key is easy. Memorize the version number, what file you used and grab the matching distribution. It won't show up in most forensic suites and if you do it right, you can avoid the forensic footprints you leave behind.. or at least reduce them. Better yet, the keyfile is sitting out there in a jam.
Bad guys also filter out irrelevant files. If I'm inside a system, I'm on a clock. Throwing up a hail mary like this takes time.. plus you still need the original password. System files are nearly universally filtered out or discarded. Once again, doing it right.. you can make it look like a normal system file access. They need to stay quiet, not draw attention and exfiltrate the data for further attacks. If you're using a system file to encrypt, they may not figure it out. They're looking in the wrong place.
Granted, it's not perfect, but it significantly increases the time and resources needed. The process of cracking in this manner is extremely tedious and time consuming.
You can alter or play with things to make this a little more difficult as well. Using a hex editor or performing minor, manual file changes that you know about can also work as a good tactic. This will change the file hash and set off some alarms. The idea is to stay stealthy and not leave footprints.
Text Files
One of the interesting things about text files is that they don't contain file headers. One of the hiccups that you encounter is file hash analysis/comparison or obvious alterations/accesses of files. A text file is just raw text.
Applying this concept to keyfiles will drive an attacker crazy. It also leaves few traces and can sufficiently obfuscate or disguise your intent. Another interesting facet is that you can recreate this file anytime, anywhere and quickly. If you lose the original key materials, you just have to ensure it matches the original.
So, how do you go about it?
Glad you asked!
Password encrypt your data and use a text file as a key file.
Memorize the text you entered or the sourcing of it. (Doing this on your computer will leave obvious trails either in your file system, allocation table, journal or internet history. Be smart.)
For example, type out a long sentence or use innocuous looking text. A passage from a book, your grocery list, a bunch of code phrases.
Use this as your keyfile and immediately scrub it afterwards. If you need to look at your encrypted materials again, simply recreate from scratch. You've eliminated errors/alterations, scrubbed any evidence that you used it and gave the bad guy an entire filesystem (devoid of the actual keyfile) to crack.
Granted, in a "lab" or with sufficient resources, this is still crackable. In a practical sense, it's exceedingly difficult. You've given someone millions of files to try ALONG WITH A PASSWORD. This is effectively impossible to nearly every attacker (short of a nation-state or excellent cryptographer.)
There are a number of complications to this. If the file is small, on a windows system, it will end up being a resident file. It can end up in the journal, shadow volume or even in file slack. Making this file more than 1k can fix some of these issues. If you overwrite, make sure you're looking at all places it could potentially show up. I won't give up the forensics side of this and exactly how this can occur.
(This is not a posting on how to commit computer crime and hide your tracks.)
You can extend this out to include cloud based files or common pages. Internet archives, innocuous online content and other sources can provide this as well. HTML files work well, just make sure it's retrievable and static. Once again, remember that this can show up in your file system and history.
Making the file content appear innocuous or trivial is key if you can't remove all traces. Done the right way, it's nearly impossible. As always, practice good opsec.
Following these steps can really muck this process up for an attacker. There are a number of other novel ways to do this. I'll probably expound upon this in the future.
Showing posts with label metadata. Show all posts
Showing posts with label metadata. Show all posts
Friday, January 5, 2018
Extremely Evil Encryption - Tactics for advanced encryption protections.
Sunday, September 21, 2014
"Policy of Truth" - Indirect Network Mapping via Metadata Extraction and Document Farming
http://open.spotify.com/track/3lOnZLx6U6jI2UH5vLnBOu
You had something to hide, should've hidden shouldn't you?
Metadata is probably the single most devastating information gathering method you will ever be exposed to. The most jarring facts about it are:
1. It's easy to fix.
Most of the time, it's simply a click (maybe 2 or 3) to scrub. It's really that easy.
2. You and your users are giving me all of the information I need to compromise your assets
When you see what you're giving away, your jaw will drop.
3. It's remarkably "low-tech."
I teach this in 5 minutes, any person could do it.
4. You've allowed search engines to do the hard work.
In fact, you and your users have probably directed a search engine to index it and expose you.
5. It's so valuable, even your favorite 3-letter agencies are collecting it!
Utah Data Center -- http://en.wikipedia.org/wiki/Utah_Data_Center
What does that tell you?
It's just time to pay the price, for not listening to advice...
You've been told your entire life about metadata. You probably use it everyday. In fact, most economies are built upon it.
Credit reporting.
Aren't you careful about what shows up on your credit report? Aren't you extremely vigilant about who gets to see your credit report? Aren't you pounded daily about how important it is to every facet of your life?
Credit reports = metadata.
Getting the picture?
Metadata is "data about the data." It describes the information you are looking at, not the information itself. Most entry-level information security folks have a hard time wrapping their head around that or the fact that in most cases, the metadata itself is more valuable than the data it describes.
If you're a criminal and you're relatively sharp, you're going to obfuscate or encode your communications. Odds are, short of having an incredible toolset or knowledge about the targets, it's incredibly difficult to decrypt or decipher what two parties are talking about.
Say you're organizing a heist or are part of a larger criminal organization and I'm investigating you. I have little to no idea what your activities are, but I have a feeling you're "planning something big." I'm going to start monitoring your phone calls. You're speaking in code to someone else, but you're doing it frequently. I can start building from there.
Who you're talking to, how long you're talking to them, how frequently it's occurring and who they are talking to is all important. I'm not going to figure your code out, if you're doing it correctly. However, I can gather a lot of useful information from watching. It may be the only information I have to go on.
I start watching you and your friends. I find out you are going to the same places; that you're buying guns, ammunition, bolt cutters, ski masks, two used cars, one of those folks is in deep gambling debt and happens to work as a teller at a bank.
Do I need to know what you're talking about to start figuring out what you're up to? Probably not.
You have already assumed from that scenario that I'm probably describing a bank heist. You took my description of something, aggregated and inferred from the facts provided and drawn a pretty solid conclusion.
That's all metadata farming and extraction. You've been doing it your entire life.
It's too late to change events, it's time to face the consequence
There are literally thousands of methods and attacks that can be created and used against you.
I'm going to keep it simple. I'll delve into other methods at another time.
What you're going to see is how through a few simple search strings, your own website, and the files your user publicly posted are enough to destroy your organization.
ON TOP OF THAT, getting rid of it is near impossible.
Google Hacking and your website
Google is a powerful tool. You probably already know this. What you probably weren't aware of is the list of google operators and what they are capable of.
https://support.google.com/websearch/answer/136861?hl=en
Google provides some operators for the saavy user or programmer to leverage. We're primarily concerned in this post with these:
filetype:
site:
cache:
info:
Filetype will give you ONLY file extensions which match your query. If you wanted ONLY docx files (Microsoft Word 2007 and newer), it would only present those in your search.
Site will restrict your site to a certain site or domain.
Cache will return the cache of a site you point it at. Google maintains an voluminous cache of pages it has visited.
Info will give you a list of information about the site, where it's linked to, etc. An entry point to some of the terms above, along with some other useful bits.
Let's build from a simple search.
filetype:docx

The first few results are garbage or likely viruses.
We're concerned with the ones that are not and are pointed out above.
At this point, we can open up a tool like FOCA and extract the relevant metadata.
FOCA is a tool for metadata profiling of networks and organizations.
(http://www.informatica64.com/DownloadFOCA/)
FOCA builds profiles of networks and assets based on extracted metadata. It does *much* more than digesting PDF and Office docs, it's well worth the download.
FOCA has extracted some very useful information for us.

From this, I have a good profile to work with:
Richard Lawhern and Red are usernames on this machine. The machine uses Office 2007 and was created in 2012.
Let's go back to our search.
We can now use a separate operand to make our search more powerful.
filetype:docx site:lawhern.org

Now, this site only has 2 DOCX files on it and I'll extract the metadata from the other.

Once again, we get Office 2007 and Red as a username. At this point, you can start digging in further on the site and this user to start profiling them. Odds are, you're going to start mining a lot more information.
I picked this example mainly because there's not too much information to be found but made for a quick display. The point is that this can be done passively and completely outside of your realm of control.
Consider this:
1. It is very likely that you do not control or host your website. As someone who worked for several hosting companies, I will tell you that it's also very likely that no one is looking at the logs or they're not looking often enough. The logs that are generated for your average webhost are MASSIVE and they tend to look at them after an incident. You're trusting an unknown party to keep a watch on things for you. Bad idea.
2. If you do this correctly, there is absolutely no way they can tell that the attacker is doing anything "wrong." The attacker is just looking at documents. The attacker is farming google for links, clicking for docs and leaving. This is normal behavior or it is spread across multiple hosts. This is hard to correlate without a subpoena for logs, a decent investigator and quite bit of time (and money.)
3. You may have little or no control over who is posting your documents and files to the page. This is usually a marketing function. Others may have the ability to upload files, depending on your organization. Are all of those users trained on how to remove metadata from files? If they are, do you think they are actually doing it?
4. If you started today and scrubbed all metadata and trained your users to do so, several webcaches (including Google and Archive.org) will require manual removal, even if they honor your request. You would need to find every copy of your files on the internet and replace/delete them.
5. All of the documents with metadata that can be found may not be hosted by you at all! Users send out PDF, JPG, PNG, DOCX, PPTX, etc. files to others via email, public postings, client documents that are posted to their websites, etc.
What is going to irritate you more than anything is that this is a remarkably easy problem to fix.
Consider this:
Right click the file, Select PROPERTIES, then DETAILS.

See that little link that says "Remove Properties and Personal Information"?

The user can select which field to remove or create a copy with it scrubbed. This has to be done EACH time it is saved or the metadata will be repopulated. PDF's written by Adobe Acrobat are a little different, but actually easier. Adobe embeds a lot of information in their files, they're probably my favorite to use. Most files need to have this done to them before public distribution.
How do I get traction with my user base?
It may be a pain to the user but my strategy for this is simple, I make it personal.
If they do not want to comply, have them supply personal files or find their postings on the internet. Better yet, retrieve a picture they've posted publicly or on social media. Extract the metadata. You can likely extract the following:
1. GPS data of where the photo was taken
2. The type and name of their phone/tablet/camera (if it was a mobile device)
3. Time/Date of picture
4. Tagging information
5. If it was edited with Photoshop, Paint, etc., you can tell them about their home computer
This tends to have some serious weight. Many users are laissez-faire about their habits as custodians of their own data but are very protective, in particular, they really hate the tech folks or executives having knowledge about their private lives*.
*I have zero interest in people's private lives and I have personal ethics about preserving privacy. I don't want to know anything about the people I work with. Period. It's awkward, it's creepy and you as an IT or InfoSec person have a personal duty to protect your users. You can not abuse the power and knowledge that you have been given. It's a serious job requiring discretion and trust. Without either, you're going to have a very difficult career.
That being said, I don't care about appearing to wear a black hat into work when I walk in the door. Sometimes, you have to throw yourself on the grenade of dislike to protect your assets. I'm not advocating being hated or even encouraging it. Far from it! You have to build trust and a good relationship with your users. They are your human firewall. They are your last line of defense. Fear, Uncertainty and Doubt are poor sales tactics, but great motivators. Sometimes you need the "right tool" for the "right job" and when it comes to this, the fear tactic motivates well.
I'll cover more on metadata extraction, farming and public information gathering. Sites like LinkedIn, Monster, Craigslist, ARIN and DNSSTUFF are amazing for mapping a target without much effort.
You had something to hide, should've hidden shouldn't you?
Metadata is probably the single most devastating information gathering method you will ever be exposed to. The most jarring facts about it are:
1. It's easy to fix.
Most of the time, it's simply a click (maybe 2 or 3) to scrub. It's really that easy.
2. You and your users are giving me all of the information I need to compromise your assets
When you see what you're giving away, your jaw will drop.
3. It's remarkably "low-tech."
I teach this in 5 minutes, any person could do it.
4. You've allowed search engines to do the hard work.
In fact, you and your users have probably directed a search engine to index it and expose you.
5. It's so valuable, even your favorite 3-letter agencies are collecting it!
Utah Data Center -- http://en.wikipedia.org/wiki/Utah_Data_Center
What does that tell you?
It's just time to pay the price, for not listening to advice...
You've been told your entire life about metadata. You probably use it everyday. In fact, most economies are built upon it.
Credit reporting.
Aren't you careful about what shows up on your credit report? Aren't you extremely vigilant about who gets to see your credit report? Aren't you pounded daily about how important it is to every facet of your life?
Credit reports = metadata.
Getting the picture?
Metadata is "data about the data." It describes the information you are looking at, not the information itself. Most entry-level information security folks have a hard time wrapping their head around that or the fact that in most cases, the metadata itself is more valuable than the data it describes.
If you're a criminal and you're relatively sharp, you're going to obfuscate or encode your communications. Odds are, short of having an incredible toolset or knowledge about the targets, it's incredibly difficult to decrypt or decipher what two parties are talking about.
Say you're organizing a heist or are part of a larger criminal organization and I'm investigating you. I have little to no idea what your activities are, but I have a feeling you're "planning something big." I'm going to start monitoring your phone calls. You're speaking in code to someone else, but you're doing it frequently. I can start building from there.
Who you're talking to, how long you're talking to them, how frequently it's occurring and who they are talking to is all important. I'm not going to figure your code out, if you're doing it correctly. However, I can gather a lot of useful information from watching. It may be the only information I have to go on.
I start watching you and your friends. I find out you are going to the same places; that you're buying guns, ammunition, bolt cutters, ski masks, two used cars, one of those folks is in deep gambling debt and happens to work as a teller at a bank.
Do I need to know what you're talking about to start figuring out what you're up to? Probably not.
You have already assumed from that scenario that I'm probably describing a bank heist. You took my description of something, aggregated and inferred from the facts provided and drawn a pretty solid conclusion.
That's all metadata farming and extraction. You've been doing it your entire life.
It's too late to change events, it's time to face the consequence
There are literally thousands of methods and attacks that can be created and used against you.
I'm going to keep it simple. I'll delve into other methods at another time.
What you're going to see is how through a few simple search strings, your own website, and the files your user publicly posted are enough to destroy your organization.
ON TOP OF THAT, getting rid of it is near impossible.
Google Hacking and your website
Google is a powerful tool. You probably already know this. What you probably weren't aware of is the list of google operators and what they are capable of.
https://support.google.com/websearch/answer/136861?hl=en
Google provides some operators for the saavy user or programmer to leverage. We're primarily concerned in this post with these:
filetype:
site:
cache:
info:
Filetype will give you ONLY file extensions which match your query. If you wanted ONLY docx files (Microsoft Word 2007 and newer), it would only present those in your search.
Site will restrict your site to a certain site or domain.
Cache will return the cache of a site you point it at. Google maintains an voluminous cache of pages it has visited.
Info will give you a list of information about the site, where it's linked to, etc. An entry point to some of the terms above, along with some other useful bits.
Let's build from a simple search.
filetype:docx
The first few results are garbage or likely viruses.
We're concerned with the ones that are not and are pointed out above.
At this point, we can open up a tool like FOCA and extract the relevant metadata.
FOCA is a tool for metadata profiling of networks and organizations.
(http://www.informatica64.com/DownloadFOCA/)
FOCA builds profiles of networks and assets based on extracted metadata. It does *much* more than digesting PDF and Office docs, it's well worth the download.
FOCA has extracted some very useful information for us.
From this, I have a good profile to work with:
Richard Lawhern and Red are usernames on this machine. The machine uses Office 2007 and was created in 2012.
Let's go back to our search.
We can now use a separate operand to make our search more powerful.
filetype:docx site:lawhern.org
Now, this site only has 2 DOCX files on it and I'll extract the metadata from the other.
Once again, we get Office 2007 and Red as a username. At this point, you can start digging in further on the site and this user to start profiling them. Odds are, you're going to start mining a lot more information.
I picked this example mainly because there's not too much information to be found but made for a quick display. The point is that this can be done passively and completely outside of your realm of control.
Consider this:
1. It is very likely that you do not control or host your website. As someone who worked for several hosting companies, I will tell you that it's also very likely that no one is looking at the logs or they're not looking often enough. The logs that are generated for your average webhost are MASSIVE and they tend to look at them after an incident. You're trusting an unknown party to keep a watch on things for you. Bad idea.
2. If you do this correctly, there is absolutely no way they can tell that the attacker is doing anything "wrong." The attacker is just looking at documents. The attacker is farming google for links, clicking for docs and leaving. This is normal behavior or it is spread across multiple hosts. This is hard to correlate without a subpoena for logs, a decent investigator and quite bit of time (and money.)
3. You may have little or no control over who is posting your documents and files to the page. This is usually a marketing function. Others may have the ability to upload files, depending on your organization. Are all of those users trained on how to remove metadata from files? If they are, do you think they are actually doing it?
4. If you started today and scrubbed all metadata and trained your users to do so, several webcaches (including Google and Archive.org) will require manual removal, even if they honor your request. You would need to find every copy of your files on the internet and replace/delete them.
5. All of the documents with metadata that can be found may not be hosted by you at all! Users send out PDF, JPG, PNG, DOCX, PPTX, etc. files to others via email, public postings, client documents that are posted to their websites, etc.
What is going to irritate you more than anything is that this is a remarkably easy problem to fix.
Consider this:
Right click the file, Select PROPERTIES, then DETAILS.
See that little link that says "Remove Properties and Personal Information"?
The user can select which field to remove or create a copy with it scrubbed. This has to be done EACH time it is saved or the metadata will be repopulated. PDF's written by Adobe Acrobat are a little different, but actually easier. Adobe embeds a lot of information in their files, they're probably my favorite to use. Most files need to have this done to them before public distribution.
How do I get traction with my user base?
It may be a pain to the user but my strategy for this is simple, I make it personal.
If they do not want to comply, have them supply personal files or find their postings on the internet. Better yet, retrieve a picture they've posted publicly or on social media. Extract the metadata. You can likely extract the following:
1. GPS data of where the photo was taken
2. The type and name of their phone/tablet/camera (if it was a mobile device)
3. Time/Date of picture
4. Tagging information
5. If it was edited with Photoshop, Paint, etc., you can tell them about their home computer
This tends to have some serious weight. Many users are laissez-faire about their habits as custodians of their own data but are very protective, in particular, they really hate the tech folks or executives having knowledge about their private lives*.
*I have zero interest in people's private lives and I have personal ethics about preserving privacy. I don't want to know anything about the people I work with. Period. It's awkward, it's creepy and you as an IT or InfoSec person have a personal duty to protect your users. You can not abuse the power and knowledge that you have been given. It's a serious job requiring discretion and trust. Without either, you're going to have a very difficult career.
That being said, I don't care about appearing to wear a black hat into work when I walk in the door. Sometimes, you have to throw yourself on the grenade of dislike to protect your assets. I'm not advocating being hated or even encouraging it. Far from it! You have to build trust and a good relationship with your users. They are your human firewall. They are your last line of defense. Fear, Uncertainty and Doubt are poor sales tactics, but great motivators. Sometimes you need the "right tool" for the "right job" and when it comes to this, the fear tactic motivates well.
I'll cover more on metadata extraction, farming and public information gathering. Sites like LinkedIn, Monster, Craigslist, ARIN and DNSSTUFF are amazing for mapping a target without much effort.
Labels:
client side exploitation,
digital forensics,
FOCA,
forensics,
information security,
InfoSec,
intelligence gathering,
investigations,
metadata,
network defense,
passive information gathering,
penetration testing,
pentesting,
vulnerability assessment
Subscribe to:
Posts (Atom)