Header

Fri, 10 Aug 2007

F(inally )ull Release of BlackHat/Defcon Timing Stuff..
@

The slides | tool | paper from BlackHat07/DefCon07 have been posted online for your wget'ing pleasure.

More details on squeeza (the tool) can be found on the squeeza page, but in a nutshell is a sql injection tool that uses Metasploits concept of splitting exploit/payloads/etc with SQL Injection attacks. Current modules are written for MS-SQL server but include functionality for (user defined sql queries, some db schema enumeration, command execution, file-transfer, db_info) and the information is returned (channel selection) via one of (application error messages, DNS, Timing). The modularity'ness means that these all mix and match - I.e. if you write a module to "extract data from all tables that look like username*", the results would be available on any of the available channels.. (Its a pretty neat tool.. and saved our bacon more than once) So check it out, and send feedback to research@sensepost.com

The Paper / Slides (the paper really needs a touch of updating) cover the data exfiltration via DNS/Timing but also goes into a not-so-well-known attack dubbed Cross Site Request Timing. Since page load times (and other page activities) can be timed across the domains it ends up being a niceĀ  way to kick the same origin policy in the shins. (we know the world really doesnt need another acronym related to X.S* but couldnt resist!)

If nothing else, in its current guise the attack should let a popular page (one thats been reddit'ed / Slashdotted) make use of its visitors for a distributed brute force attack on web applications that track session-state through the URL/POST body..

Visio pic of the attack in action (courtesy of Nick our Visio Ninja)(click images for full size)

dxsrt.png
"

and the example we demo'd during the talk was a brute force attack on a time-leaky login page:

dxsrt1.png
"

Check out the paper / slides* and send us feedback...

(*Sadly in pdf, the slides do not play our embedded hampster .mp4.. so when u get to slide 40 please surf to http://youtube.com/watch?v=a1Y73sPHKxw )

Blog
Video
Research
QotW
Categories
about:us (28)
blog (9)
build-it (1)
cloud (9)
community (13)
conferences (53)
crypto (3)
fail (3)
foos (1)
fun (50)
goodbye (1)
Hope? (2)
howto (8)
imsojaded (2)
infosec-soapies (25)
infrastructure (3)
local (2)
mac (15)
management (4)
materials (3)
mindless-politics (4)
mindmaps (1)
PCI (2)
post-it (1)
privacy (5)
programming (5)
public (256)
qo[w|m|?] (5)
README (1)
real-world (13)
research (31)
reversing (4)
security-fyi (8)
security-news (6)
silly-yammerings (19)
tech-toys (3)
time-waster (6)
tin-foil-hat (6)
tools (39)
training (13)
tricks (1)
Uncategorized (3)
vendors (6)
videos (6)
vulnerability (4)
wasc (1)
webapps (6)
web_x.0 (2)
writing-advice (1)
zen-hacking (6)
Archives
March 2010 (3)
Feburary 2010 (2)
January 2010 (3)
December 2009 (4)
November 2009 (4)
October 2009 (3)
September 2009 (5)
August 2009 (9)
July 2009 (1)
June 2009 (5)
May 2009 (4)
April 2009 (10)
March 2009 (13)
Feburary 2009 (12)
January 2009 (11)
December 2008 (9)
November 2008 (8)
October 2008 (5)
September 2008 (5)
August 2008 (6)
July 2008 (6)
June 2008 (6)
May 2008 (2)
April 2008 (3)
March 2008 (7)
Feburary 2008 (12)
January 2008 (9)
December 2007 (8)
November 2007 (4)
October 2007 (9)
September 2007 (14)
August 2007 (18)
July 2007 (13)
June 2007 (17)
May 2007 (2)
July 2006 (1)
April 2006 (1)
August 2005 (1)
June 2005 (1)
May 2005 (2)
Archives
Conditions of use Privacy statement
Top of Page Legal stuff