TIME

NEPAL QATAR BELFAST, UK MALAYSIA DUBAI

Friday, January 19, 2024

Bypass Hardware Firewalls

This is just a collection of links about my DEF CON 22 presentation, and the two tools I released:

Slides:
http://www.slideshare.net/bz98/defcon-22-bypass-firewalls-application-white-lists-secure-remote-desktops-in-20-seconds

Tools:
https://github.com/MRGEffitas/Write-into-screen
https://github.com/MRGEffitas/hwfwbypass

Presentation video from Hacktivity:
https://www.youtube.com/watch?v=KPJBckmhtZ8

Technical blog post:
https://blog.mrg-effitas.com/bypass-hardware-firewalls-def-con-22/

Have fun!




Related articles

WHY WE DO HACKING?

Purpose of Hacking?
. Just for fun
.Show-off
.Steal important information 
.Damaging the system
.Hampering Privacy
.Money Extortion 
.System Security Testing
.To break policy compliance etc

More articles


  1. New Hack Tools
  2. Hack Tools Download
  3. Pentest Tools Find Subdomains
  4. Pentest Tools For Android
  5. Termux Hacking Tools 2019
  6. Pentest Tools Website
  7. Hacking Tools For Windows
  8. Free Pentest Tools For Windows
  9. Hacking Tools Software
  10. Hacking Tools Software
  11. What Is Hacking Tools
  12. Best Pentesting Tools 2018
  13. Pentest Tools For Windows
  14. Hacker Tools 2020
  15. Ethical Hacker Tools
  16. Ethical Hacker Tools
  17. Hacker Tools Github
  18. Easy Hack Tools
  19. Hacking Tools 2019
  20. Pentest Tools For Android
  21. Hack Apps
  22. Pentest Tools Alternative
  23. Hacking Tools Download
  24. Pentest Tools Windows
  25. Beginner Hacker Tools
  26. Hacking Tools Windows
  27. Pentest Tools Online
  28. Hack Tools
  29. Hacking Tools Online
  30. Hack Tools 2019
  31. Pentest Tools Review
  32. Pentest Tools Android
  33. Pentest Tools Subdomain
  34. Hack Apps
  35. Hack Tools Online
  36. Hacker Tools Hardware
  37. Android Hack Tools Github
  38. Beginner Hacker Tools
  39. Hack Tools Github
  40. Hacker Tools 2019
  41. Hack Website Online Tool
  42. Hack Apps
  43. Hack Tools Github
  44. Pentest Tools Apk
  45. Hacker Hardware Tools
  46. Hacking Apps
  47. Hacker Search Tools
  48. Hack Tools Online
  49. Ethical Hacker Tools
  50. Hacking Tools 2020
  51. Physical Pentest Tools
  52. Hacking App
  53. Pentest Tools Android
  54. Usb Pentest Tools
  55. Pentest Tools Port Scanner
  56. Hacking Tools 2020
  57. Computer Hacker
  58. Hack App
  59. Hacker Tools 2020
  60. Hacking Tools For Pc
  61. Best Hacking Tools 2019
  62. Nsa Hack Tools
  63. Tools 4 Hack
  64. Hacker Tools Windows
  65. Hacker Tools Apk
  66. Hack Apps
  67. Top Pentest Tools
  68. Hack And Tools
  69. Hacker Hardware Tools
  70. Hacking Tools For Pc
  71. Hacking Tools For Pc
  72. Hacker Tools Software
  73. Pentest Tools Website Vulnerability
  74. Game Hacking
  75. Hacking Tools Windows
  76. Hack Tools For Windows
  77. Hacking Tools Windows 10
  78. Pentest Tools For Android
  79. Hacker Tools 2019
  80. Hack And Tools
  81. Underground Hacker Sites
  82. Hacker Tools For Pc
  83. Hacker Tools For Ios
  84. Hacking Tools Software
  85. Pentest Tools Website Vulnerability
  86. Hacker Tools Apk Download
  87. Termux Hacking Tools 2019
  88. Hacking Tools 2020
  89. Hacker Tools Linux
  90. Hacker Hardware Tools
  91. Termux Hacking Tools 2019
  92. Hacker Search Tools
  93. Pentest Tools For Windows
  94. Usb Pentest Tools
  95. Pentest Tools Website Vulnerability
  96. Pentest Tools For Android
  97. Hacker Search Tools
  98. Hack Apps
  99. Pentest Tools Windows
  100. Best Hacking Tools 2019
  101. Hackers Toolbox
  102. Nsa Hack Tools
  103. Pentest Tools For Android
  104. Hacking App
  105. Hack Tools For Games
  106. Hack Tools
  107. Easy Hack Tools
  108. Pentest Tools For Android
  109. Best Pentesting Tools 2018
  110. Tools 4 Hack
  111. Hacker Tools For Windows
  112. Pentest Tools Android
  113. Github Hacking Tools
  114. Hacker Tools For Mac
  115. Beginner Hacker Tools
  116. Pentest Tools For Android
  117. Hacker Tool Kit
  118. Hacker Tools Windows
  119. Hacking Tools For Windows 7
  120. Pentest Tools For Windows
  121. Hack Tools Online
  122. Beginner Hacker Tools
  123. Hack Tool Apk No Root
  124. Hacking Tools For Pc
  125. Hacker Techniques Tools And Incident Handling
  126. Usb Pentest Tools
  127. Pentest Tools For Windows
  128. Hacker Tools Software
  129. Hacking Tools For Windows Free Download
  130. Hacking Tools Kit
  131. Pentest Tools Framework
  132. Hacker Tools Free Download
  133. Pentest Tools For Ubuntu
  134. Top Pentest Tools

Why (I Believe) WADA Was Not Hacked By The Russians

Disclaimer: This is my personal opinion. I am not an expert in attribution. But as it turns out, not many people in the world are good at attribution. I know this post lacks real evidence and is mostly based on speculation.



Let's start with the main facts we know about the WADA hack, in chronological order:


1. Some point in time (August - September 2016), the WADA database has been hacked and exfiltrated
2. August 15th, "WADA has alerted their stakeholders that email phishing scams are being reported in connection with WADA and therefore asks its recipients to be careful"  https://m.paralympic.org/news/wada-warns-stakeholders-phishing-scams
3. September 1st, the fancybear.net domain has been registered
   Domain Name: FANCYBEAR.NET    ...    Updated Date: 18-sep-2016    Creation Date: 01-sep-2016
 
4. The content of the WADA hack has been published on the website
5. The @FancyBears and @FancyBearsHT Twitter accounts have been created and started to tweet on 12th September, reaching out to journalists
6. 12th September, Western media started headlines "Russia hacked WADA"
7. The leaked documents have been altered, states WADA https://www.wada-ama.org/en/media/news/2016-10/cyber-security-update-wadas-incident-response


The Threatconnect analysis

The only technical analysis on why Russia was behind the hack, can be read here: https://www.threatconnect.com/blog/fancy-bear-anti-doping-agency-phishing/

After reading this, I was able to collect the following main points:

  1. It is Russia because Russian APT groups are capable of phishing
  2. It is Russia because the phishing site "wada-awa[.]org was registered and uses a name server from ITitch[.]com, a domain registrar that FANCY BEAR actors recently used"
  3. It is Russia because "Wada-arna[.]org and tas-cass[.]org were registered through and use name servers from Domains4bitcoins[.]com, a registrar that has also been associated with FANCY BEAR activity."
  4. It is Russia, because "The registration of these domains on August 3rd and 8th, 2016 are consistent with the timeline in which the WADA recommended banning all Russian athletes from the Olympic and Paralympic games."
  5. It is Russia, because "The use of 1&1 mail.com webmail addresses to register domains matches a TTP we previously identified for FANCY BEAR actors."

There is an interesting side-track in the article, the case of the @anpoland account. Let me deal with this at the end of this post.

My problem with the above points is that all five flag was publicly accessible to anyone as TTP's for Fancy Bear. And meanwhile, all five is weak evidence. Any script kittie in the world is capable of both hacking WADA and planting these false-flags.

A stronger than these weak pieces of evidence would be:

  • Malware sharing same code attributed to Fancy Bear (where the code is not publicly available or circulating on hackforums)
  • Private servers sharing the IP address with previous attacks attributed to Fancy Bear (where the server is not a hacked server or a proxy used by multiple parties)
  • E-mail addresses used to register the domain attributed to Fancy Bear
  • Many other things
For me, it is quite strange that after such great analysis on Guccifer 2.0, the Threatconnect guys came up with this low-value post. 


The fancybear website

It is quite unfortunate that the analysis was not updated after the documents have been leaked. But let's just have a look at the fancybear . net website, shall we?

Now the question is, if you are a Russian state-sponsored hacker group, and you are already accused of the hack itself, do you create a website with tons of bears on the website, and do you choose the same name (Fancy Bear) for your "Hack team" that is already used by Crowdstrike to refer to a Russian state-sponsored hacker group? Well, for me, it makes no sense. Now I can hear people screaming: "The Russians changed tactics to confuse us". Again, it makes no sense to change tactics on this, while keeping tactics on the "evidence" found by Threatconnect.

It makes sense that a Russian state-sponsored group creates a fake persona, names it Guccifer 2.0, pretends Guccifer 2.0 is from Romania, but in the end it turns out Guccifer 2.0 isn't a native Romanian speaker. That really makes sense.

What happens when someone creates this fancybear website for leaking the docs, and from the Twitter account reaches out to the media? Journalists check the website, they see it was done by Fancy Bear, they Bing Google this name, and clearly see it is a Russian state-sponsored hacker group. Some journalists also found the Threatconnect report, which seems very convincing for the first read. I mean, it is a work of experts, right? So you can write in the headlines that the hack was done by the Russians.

Just imagine an expert in the USA or Canada writing in report for WADA:
"the hack was done by non-Russian, but state-sponsored actors, who planted a lot of false-flags to accuse the Russians and to destroy confidence in past and future leaks". Well, I am sure this is not a popular opinion, and whoever tries this, risks his career. Experts are human, subject to all kinds of bias.

The Guardian

The only other source I was able to find is from The Guardian, where not just one side (it was Russia) was represented in the article. It is quite unfortunate that both experts are from Russia - so people from USA will call them being not objective on the matter. But the fact that they are Russian experts does not mean they are not true ...

https://www.theguardian.com/sport/2016/sep/15/fancy-bears-hackers--russia-wada-tues-leaks

Sergei Nikitin:
"We don't have this in the case of the DNC and Wada hacks, so it's not clear on what basis conclusions are being drawn that Russian hackers or special services were involved. It's done on the basis of the website design, which is absurd," he said, referring to the depiction of symbolically Russian animals, brown and white bears, on the "Fancy Bears' Hack Team" website.

I don't agree with the DNC part, but this is not the topic of conversation here.

Alexander Baranov:
"the hackers were most likely amateurs who published a "semi-finished product" rather than truly compromising information. "They could have done this more harshly and suddenly," he said. "If it was [state-sponsored] hackers, they would have dug deeper. Since it's enthusiasts, amateurs, they got what they got and went public with it.""

The @anpoland side-track

First please check the tas-cas.org hack https://www.youtube.com/watch?v=day5Aq0bHsA  , I will be here when you finished it. This is a website for "Court of Arbitration for Sport's", and referring to the Threatconnect post, "CAS is the highest international tribunal that was established to settle disputes related to sport through arbitration. Starting in 2016, an anti-doping division of CAS began judging doping cases at the Olympic Games, replacing the IOC disciplinary commission." Now you can see why this attack is also discussed here.


  • My bet is that this machine was set-up for these @anpoland videos only. Whether google.ru is a false flag or it is real, hard to decide. It is interesting to see that there is no google search done via google.ru, it is used only once. 
  • The creator of the video can't double click. Is it because he has a malfunctioning mouse? Is it because he uses a virtualization console, which is near-perfect OPSEC to hide your real identity? My personal experience is that using virtualization consoles remotely (e.g. RDP) has very similar effects to what we can see on the video. 
  • The timeline of the Twitter account is quite strange, registered in 2010
  • I agree with the Threatconnect analysis that this @anpoland account is probably a faketivist, and not an activist. But who is behind it, remains a mystery. 
  • Either the "activist" is using a whonix-like setup for remaining anonymous, or a TOR router (something like this), or does not care about privacy at all. Looking at the response times (SQLmap, web browser), I doubt this "activist" is behind anything related to TOR. Which makes no sense for an activist, who publishes his hack on Youtube. People are stupid for sure, but this does not add up. It makes sense that this was a server (paid by bitcoins or stolen credit cards or whatever) rather than a home computer.
For me, this whole @anpoland thing makes no sense, and I think it is just loosely connected to the WADA hack. 

The mysterious Korean characters in the HTML source

There is another interesting flag in the whole story, which actually makes no sense. When the website was published, there were Korean characters in HTML comments. 



When someone pointed this out on Twitter, these Korean HTML comments disappeared:
These HTML comments look like generated HTML comments, from a WYSIWYG editor, which is using the Korean language. Let me know if you can identify the editor.

The Russians are denying it

Well, what choice they have? It does not matter if they did this or not, they will deny it. And they can't deny this differently. Just imagine a spokesperson: "Previously we have falsely denied the DCC and DNC hacks, but this time please believe us, this wasn't Russia." Sounds plausible ...

Attribution

Let me sum up what we know:

It makes sense that the WADA hack was done by Russia, because:

  1. Russia being almost banned from the Olympics due to doping scandal, it made sense to discredit WADA and US Olympians
  2. There are multiple(weak) pieces of evidence which point to Russia
It makes sense that the WADA hack was not done by  Russia, because: 
  1. By instantly attributing the hack to the Russians, the story was more about to discredit Russia than discrediting WADA or US Olympians.
  2. In reality, there was no gain for Russia for disclosing the documents. Nothing happened, nothing changed, no discredit for WADA. Not a single case turned out to be illegal or unethical.
  3. Altering the leaked documents makes no sense if it was Russia (see update at the end). Altering the leaked documents makes a lot of sense if it was not Russia. Because from now on, people can always state "these leaks cannot be trusted, so it is not true what is written there". It is quite cozy for any US organization, who has been hacked or will be hacked. If you are interested in the "Russians forging leaked documents" debate, I highly recommend to start with this The Intercept article
  4. If the Korean characters were false flags planted by the Russians, why would they remove it? If it had been Russian characters, I would understand removing it.
  5. All evidence against Russia is weak, can be easily forged by even any script kittie.

I don't like guessing, but here is my guess. This WADA hack was an operation of a (non-professional) hackers-for-hire service, paid by an enemy of Russia. The goal was to hack WADA, leak the documents, modify some contents in the documents, and blame it all on the Russians ...

Questions and answers

  • Was Russia capable of doing this WADA hack? Yes.
  • Was Russia hacking WADA? Maybe yes, maybe not.
  • Was this leak done by a Russian state-sponsored hacker group? I highly doubt that.
  • Is it possible to buy an attribution-dice where all six-side is Russia? No, it is sold-out. 

To quote Patrick Gray: "Russia is the new China, and the Russians ate my homework."©

Let me know what you think about this, and please comment. 

Related word

  1. Underground Hacker Sites
  2. Hack Tools Mac
  3. Hacking Tools For Games
  4. Termux Hacking Tools 2019
  5. How To Make Hacking Tools
  6. Pentest Tools Open Source
  7. Hacking Tools Software
  8. Computer Hacker
  9. Hak5 Tools
  10. Hack Rom Tools
  11. Hacking Tools For Mac
  12. Hacker Tools For Windows
  13. Hacker Tools Windows
  14. Pentest Tools Github
  15. Hack Tools
  16. Hacker Tool Kit
  17. Pentest Tools Tcp Port Scanner
  18. Hacker Tools Mac
  19. Hack Tools Download
  20. Pentest Tools Android
  21. How To Make Hacking Tools
  22. Hacker Tools For Windows
  23. Pentest Tools
  24. Physical Pentest Tools
  25. Physical Pentest Tools
  26. Hack Tools For Games
  27. Hacker Tools Windows
  28. Pentest Tools Subdomain
  29. Bluetooth Hacking Tools Kali
  30. Hack Apps
  31. Hack Tools Github
  32. Hacking Tools Name
  33. Hacker Tools Hardware
  34. Hacker Tools 2019
  35. Wifi Hacker Tools For Windows
  36. Hacking Tools Online
  37. Android Hack Tools Github
  38. Hacking Tools For Windows Free Download
  39. Hacker Tools Linux
  40. Hacking Tools Mac
  41. Pentest Tools Review
  42. Beginner Hacker Tools
  43. Bluetooth Hacking Tools Kali
  44. Hack Apps
  45. Hacker Techniques Tools And Incident Handling
  46. Hacking App
  47. Hacking Tools Github
  48. Pentest Automation Tools
  49. Pentest Box Tools Download
  50. Pentest Tools Android
  51. Pentest Tools Online
  52. Hacking Tools And Software
  53. Hacker Search Tools
  54. Hack Rom Tools
  55. Pentest Tools Open Source
  56. Hacking Tools And Software
  57. Hack Tools For Windows
  58. Hak5 Tools
  59. Hack Tools For Mac
  60. Hacking Tools Software
  61. Tools 4 Hack
  62. Hacking Tools For Mac
  63. Nsa Hack Tools Download
  64. Top Pentest Tools
  65. Best Hacking Tools 2020
  66. Pentest Tools Apk
  67. Hacking Tools 2019
  68. Pentest Tools Linux
  69. Hacker Tools Free
  70. Pentest Tools Review
  71. Hacking Tools Windows
  72. Black Hat Hacker Tools
  73. Hacking Tools Windows
  74. Hacking Tools For Pc
  75. Nsa Hack Tools
  76. Hack Tools For Ubuntu
  77. Best Hacking Tools 2020
  78. Hacking Tools For Games
  79. Hacker Tools 2020
  80. Hacker Hardware Tools
  81. Tools For Hacker
  82. Hacker Tools Github
  83. Hack Tools
  84. Hacker Tools Hardware
  85. Hacker Tools
  86. What Is Hacking Tools
  87. Hack Tools
  88. Hack Tools For Windows
  89. Hack Apps
  90. Hack Tool Apk
  91. Hacking Tools
  92. Hacker Tools Online
  93. Top Pentest Tools
  94. Pentest Tools Nmap
  95. Hack Tools For Pc
  96. Hacker Tools Software
  97. Hacker Tools Hardware
  98. Free Pentest Tools For Windows
  99. Hack Tool Apk
  100. Nsa Hack Tools Download
  101. Hacking App
  102. Pentest Tools For Mac
  103. Hackrf Tools
  104. Pentest Tools Website
  105. Physical Pentest Tools
  106. Tools 4 Hack
  107. Hacking Tools Free Download
  108. Usb Pentest Tools
  109. Nsa Hack Tools
  110. Computer Hacker
  111. Hacker Tools
  112. Hacking Tools And Software
  113. Hack Tools Github
  114. Hacker Tools Github
  115. Hacking Tools Windows 10
  116. Github Hacking Tools
  117. Hackrf Tools
  118. Hack Tools 2019
  119. Hacking Tools Free Download
  120. Best Hacking Tools 2019
  121. Growth Hacker Tools
  122. Pentest Tools Subdomain
  123. Hacking App
  124. Termux Hacking Tools 2019
  125. Pentest Tools Website Vulnerability
  126. Hacker Security Tools
  127. Hack Rom Tools
  128. Hacker Tools Online
  129. Hackrf Tools
  130. How To Make Hacking Tools
  131. Hacker Tools Mac
  132. Hacker Security Tools
  133. Kik Hack Tools
  134. Pentest Tools For Ubuntu
  135. Pentest Tools For Mac
  136. Hack And Tools
  137. Hacking Tools For Beginners
  138. Hacking Tools Usb
  139. Game Hacking
  140. Hacks And Tools
  141. Pentest Tools Website Vulnerability
  142. Hack Tools For Ubuntu